Skip to main content
CYB-0334ExpertCurrent Intake
XAIHP

Xcademia AI Hacker Practitioner

8-Day Instructor-Led Programme

The XAIHP Certification Programme is the practitioner standard for offensive security professionals who red team AI systems, exploit LLM vulnerabilities, conduct adversarial machine learning attacks, and assess AI infrastructure security across enterprise and cloud AI deployments. Assessed on Day 8 through a supervised AI red team exercise against a live LLM application and ML pipeline. No MCQs. Completely uncontested in UK instructor-led format.

Duration

8 Days

Price

$7,495

Xcademia AI Hacker Practitioner
Duration
8 Days
Complete in 8 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

AI is being deployed at scale across enterprise, government, and critical infrastructure. Every LLM application has an attack surface. Every ML pipeline has trust assumptions that can be exploited. Every agentic AI system has an autonomy boundary that can be manipulated. The security practitioner who cannot assess these systems is increasingly irrelevant in 2026. XAIHP is built for offensive security professionals who want to extend their capability into the most underserved and fastest-growing attack surface in the industry.

Across eight instructor-led days, participants build AI offensive security capability from first principles: AI and ML system architecture for security professionals, prompt injection and jailbreaking techniques against production LLMs, indirect prompt injection in agentic AI systems, data poisoning and training data attacks, model extraction and membership inference, adversarial examples and evasion attacks, LLM application security testing methodology, AI infrastructure security assessment, and AI red team report production aligned to MITRE ATLAS and OWASP LLM Top 10.

On Day 8, participants conduct a supervised AI red team exercise against a deployed LLM application with RAG pipeline and agentic capabilities. They attempt prompt injection, indirect injection through documents, data exfiltration from the vector database, and privilege escalation through the agentic system. A senior practitioner observes methodology, technique selection, and report quality. XAIHP certificate and Practitioner Assessment Report issued together. Aligned with MITRE ATLAS, OWASP LLM Top 10, OWASP ML Security Top 10, NIST AI RMF, and EU AI Act security testing requirements.

Hands-On Learning

Live prompt injection attacks against GPT-4o class and open-source LLMs, jailbreaking technique development, RAG pipeline data extraction, adversarial example generation, model extraction experiments, and a supervised AI red team exercise on Day 8.

Mentor-Led Sessions

Mentor-led sessions examining real AI security incidents (Samsung ChatGPT data leak, Bing Sydney manipulation, prompt injection in production AI assistants), and how MITRE ATLAS techniques map to real AI attack campaigns.

Career-Ready Skills

Assess LLM applications, ML pipelines, and agentic AI systems for security vulnerabilities using structured red team methodology, and produce professional AI security assessment reports aligned to MITRE ATLAS and OWASP LLM Top 10.

Learning Outcomes

Conduct prompt injection and jailbreaking attacks against production LLM applications using OWASP LLM Top 10 methodology

Assess RAG pipeline security including vector database extraction, embedding poisoning, and indirect prompt injection through retrieved documents

Execute adversarial machine learning attacks including adversarial examples, data poisoning, and model extraction against real ML systems

Red team agentic AI systems to identify privilege escalation, tool-calling exploitation, and multi-agent trust assumption failures

Assess AI infrastructure security including LLM API, model registry, training infrastructure, and ML pipeline components

Produce professional AI red team reports aligned to MITRE ATLAS and OWASP LLM Top 10 with business impact communication

Prerequisites

1

Minimum 12 months in a penetration testing, security engineering, or offensive security role

2

Working knowledge of web application penetration testing and API security testing methodology

3

Basic Python familiarity for running adversarial ML attack scripts and automation tools

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • LLM architecture for security professionals: transformer models, context windows, and system prompt structure
  • RAG (Retrieval Augmented Generation) pipeline architecture: vector databases, embedding models, and retrieval security
  • Agentic AI system architecture: tool-calling, multi-agent orchestration, and autonomy boundaries
  • ML pipeline components: data ingestion, feature engineering, training, serving, and monitoring security surfaces
  • AI threat landscape: MITRE ATLAS taxonomy, real AI security incident case studies, and adversary motivation
Stage 5Final Capstone

Xcademia AI Hacker Practitioner — Capstone Project

On Day 8, participants receive access to a deployed LLM application built on a GPT-4o class model with a RAG pipeline, document processing capability, and agentic task execution. They attempt prompt injection, indirect injection through uploaded documents, vector database data extraction, system prompt exfiltration, and privilege escalation through the agentic system, producing a structured MITRE ATLAS-mapped AI red team report. The senior practitioner observes technique selection and assessment methodology throughout.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • MITRE ATLAS

    Global

    Adversarial Threat Landscape for AI Systems: primary AI red team technique taxonomy throughout all domains

  • OWASP LLM Top 10 2025

    Global

    LLM01 through LLM10: primary LLM application vulnerability taxonomy and assessment methodology

  • OWASP ML Security Top 10

    Global

    Machine learning security risks: assessment methodology for ML pipeline components

  • NIST AI RMF

    Global

    Map function: AI risk identification applied to offensive assessment findings throughout

  • EU AI Act Article 9

    Global

    Risk management system testing requirements for high-risk AI: assessment context throughout

  • NIST AI RMF Playbook

    Global

    Detailed subcategory actions: offensive assessment integration with defensive AI governance

  • Garak Framework

    Global

    Open-source LLM vulnerability scanner: automated red teaming tool covered in depth

  • Adversarial Robustness Toolbox

    Global

    IBM ART: adversarial ML attack and defence framework used throughout adversarial ML domain

Skills You'll Gain

Master these in-demand skills through hands-on practice

Prompt injection (direct and indirect)LLM jailbreakingRAG pipeline security testingAgentic AI red teamingAdversarial examples (FGSM/PGD)Data poisoning attacksModel extractionMITRE ATLAS mappingOWASP LLM Top 10Garak automated red teamingAI infrastructure security assessmentAI red team report writing

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

AI Red Team OperatorOffensive AI Security SpecialistSenior Penetration Tester (AI/ML)AI Security ResearcherML Security EngineerAI Governance Assessor
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

8 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$7,495+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised Xcademia AI Hacker Practitioner learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of Xcademia AI Hacker Practitioner, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

No UK training provider currently offers an instructor-led, practitioner-assessed AI offensive security programme covering prompt injection, adversarial ML, agentic AI red teaming, and AI infrastructure assessment at depth. What exists is either a one-day awareness session, an MCQ exam (CompTIA SecAI+), or generic AI ethics training. XAIHP is the first programme built for offensive security professionals who want to assess AI systems.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options