AI Hacking 101: Learn to Exploit AI-Based Applications
The AI Hacking 101 live training teaches students how AI/LLM based applications such as customer facing chatbots are vulnerable to attackers.
The course focuses on demonstrating how to detect and exploit common AI vulnerabilities such as:
- Prompt Injection
- Sensitive Information Disclosure
- Improper Output Handling
- System Prompt Leakage
- Misinformation
- Excessive Agency
Not only will students learn about these exploits, but they will also spend hands-on time in a custom-built environment exploiting and uncovering these vulnerabilities.
The online lab features the TCM Vulnerable Chatbot, a customer service chatbot that can interact with customers’ tickets and improve its responses via Retrieval Augmented Generation (RAG) using the company’s knowledge base.
By the end of this training, students will have a better understanding of how AI based applications work and what makes them vulnerable to bad actors.
System Requirements
A computer with a stable internet connection. All labs will be cloud-based and accessible via a browser, no special software or hardware is required.
Prerequisites
A preliminary understanding of penetration testing methodology and AI fundamentals are suggested. It’s strongly suggested that students take the AI Fundamentals: 100 course (~4 hours) on the TCM Academy Free Tier prior to taking this course.
Black Friday Savings Are Here!
No code required- save 20% on live training classes when you register before December 1st, 2025.

Live, Instructor-Led
AI Hacking 101 Live Training
Details
8+ Hours of Live Online Instruction and CEU Credits
6+ Hours of On-Demand Training (12 Months Access)
1 PAPA Exam Attempt (12 Months Access)
Online Labs w/ Access Post Training
Private Cohort and Instructor Access
24/7/365 Course Support
Who Should Take the AI Hacking 101 Live Training?
AI Hacking 101 is an excellent class for technical personnel looking to understand the vulnerabilities and risks of this emerging technology. Attackers, defenders, and developers can all benefit from this class.
- Penetration testers looking to add AI/LLM pen testing to their tool kit
- Developers working with AI and LLM applications
- Defenders looking to understand AI risks and how they can impact their organizations
- Anyone interested in AI and its risks and dangers
Why Choose TCM Security Instructor-Led Training?
No Fluff, Practical Focus
Lab Access
Interactive, Small Group Setting
Post-Training Resources
You’ll have 12 months of access to on-demand training materials after the training ends.
Professional Development
Prepare for Certification Exams
Training Options for Organizations
Curriculum and Agenda
Prerequisites
A preliminary understanding of penetration testing methodology and AI fundamentals are suggested. It’s strongly suggested that students take the AI Fundamentals: 100 course (~4 hours) on the TCM Academy Free Tier prior to taking this course.
AI Hacking 101 Live Training Schedule
AI Fundamentals Review: A quick review of some of the fundamentals of AI such as how they operate and standard terms such as model parameters, temperature, top-p, inference, training, LLMs.
AI Threat Model: Discuss the threat actors, assets, adversary goals and attack surfaces for modern AI applications and the specific AI application used in the course
Reconnaissance, Model Mapping and Baseline Behavior and Fingerprinting: Demonstrate techniques for performing reconnaissance of AI applications with a specific focus on fingerprinting underlying AI models and their settings.
Prompt Injection and Jailbreaking: Demonstrate common techniques for prompt injection and jail breaking
Prompt Injection Tools and Resources: Show common tools and repositories of prompts used for prompt injection and jailbreaking
Bypassing Common Protections: Showcase how to bypass common protections for prompt injection such as input/output filtering
Testing for harmful output/hate speech/misinformation/off-topic content and resource drainage: Demonstrate tests for verifying the model responds correctly to requests for generating harmful or off-topic content or attempts to waste infra resources.
Data Exfiltration: Demonstrate how retrieval augmented generation works and vulnerabilities associated with it such as leakage of confidential material and PII.
RAG and Vector DB Attacks: Demonstrate attacks the focus on the retrieval of documents and the ticket base, showcase vector poisoning attacks.
Excessive Agency: Demonstrate how excessive agency in AI applications can be exploited and tested for.
*Curriculum is dependent on class skillset and other varying factors. Curriculum may change at the instructor’s discretion.
Request Live Training Reimbursement
Training doesn’t stop once you land a pentesting position. If your company offers a training budget or reimbursement for continuing education, consider using it on TCM Security live training and certifications! To make things easier, we’ve created a Training Budget Request Template—a customizable document designed to align your learning goals with your company’s objectives. Be sure to follow your company’s policies and procedures to increase the likelihood of your request being approved.
Frequently Asked Questions
What skill level should I have to take the training?
This class is aimed at beginners. However, students should have a preliminary understanding of penetration testing methodology and AI fundamentals. It’s strongly suggested that students take the AI Fundamentals: 100 course (~4 hours) on the TCM Academy Free Tier prior to taking this course.
How long is the training session?
The class runs for 8 hours starting at 9am and ending at 4pm ET. This includes lecture, hands-on labs, lunch, and breaks to work on the challenges.
What certification is included?
This training prepares you for the soon-to-be released Practical AI Pentesting Associate (PAPA) certification exam. Your purchase includes 6 months of access to the training materials and the exam attempt. Please note that certification vouchers purchased in a live training bundle do NOT include a free retake.
Do you offer any discounts?
Live trainings are not eligible for the student, educator, military, first responder discount because they are already discounted to include the certification voucher. We periodically offer sales and promotions. Join our email list or follow us on social media to be informed when sales begin.
Will my employer reimburse this training?
Maybe! If your organization has a training budget, this class is an excellent way to expand your security knowledge and gain knowledge that will help protect your organization’s data. Use our reimbursement template to help craft your training request to your manager.
Do you offer bulk discounts?
We do. If your organization would like to purchase several seats for your team members to participate in the training, please contact [email protected] for more information.
