Building Secure and Responsible LLM Applications Training Course
LLM application security entails the discipline of designing, building, and maintaining safe, trustworthy, and policy-compliant systems that leverage large language models.
This instructor-led, live training (available online or onsite) is designed for intermediate to advanced AI developers, architects, and product managers who wish to identify and mitigate risks associated with LLM-powered applications, such as prompt injection, data leakage, and unfiltered output. Participants will learn to incorporate security controls like input validation, human-in-the-loop oversight, and output guardrails.
By the conclusion of this training, participants will be able to:
- Grasp the core vulnerabilities inherent in LLM-based systems.
- Apply secure design principles to the architecture of LLM applications.
- Utilise tools such as Guardrails AI and LangChain for validation, filtering, and ensuring safety.
- Integrate techniques like sandboxing, red teaming, and human-in-the-loop review into production-grade pipelines.
Format of the Course
- Interactive lectures and discussions.
- Ample exercises and practical practice.
- Hands-on implementation within a live-lab environment.
Course Customization Options
- To request customized training for this course, please contact us to arrange.
Course Outline
Overview of LLM Architecture and Attack Surface
- How LLMs are built, deployed, and accessed via APIs
- Key components in LLM app stacks (e.g., prompts, agents, memory, APIs)
- Where and how security issues arise in real-world use
Prompt Injection and Jailbreak Attacks
- What is prompt injection and why it’s dangerous
- Direct and indirect prompt injection scenarios
- Jailbreaking techniques to bypass safety filters
- Detection and mitigation strategies
Data Leakage and Privacy Risks
- Accidental data exposure through responses
- PII leaks and model memory misuse
- Designing privacy-conscious prompts and retrieval-augmented generation (RAG)
LLM Output Filtering and Guarding
- Using Guardrails AI for content filtering and validation
- Defining output schemas and constraints
- Monitoring and logging unsafe outputs
Human-in-the-Loop and Workflow Approaches
- Where and when to introduce human oversight
- Approval queues, scoring thresholds, fallback handling
- Trust calibration and role of explainability
Secure LLM App Design Patterns
- Least privilege and sandboxing for API calls and agents
- Rate limiting, throttling, and abuse detection
- Robust chaining with LangChain and prompt isolation
Compliance, Logging, and Governance
- Ensuring auditability of LLM outputs
- Maintaining traceability and prompt/version control
- Aligning with internal security policies and regulatory needs
Summary and Next Steps
Requirements
- A foundational understanding of large language models and prompt-based interfaces
- Experience in building LLM applications using Python
- Familiarity with API integrations and cloud-based deployments
Audience
- AI developers
- Application and solution architects
- Technical product managers working with LLM tools
Need help picking the right course?
southafrica@nobleprog.co.za or +27 (0)10 005 5793