Skip to Content
AI Under Attack
book

AI Under Attack

by Kris Kimmerle, David Okeyode
June 2026
Intermediate
478 pages
12h 25m
English
Packt Publishing

Overview

Built on Fortune 500 experience, this guide delivers hands-on methods to secure generative AI with extensive coverage of RAG, agents, prompt injection, data pipelines, Zero Trust, and sustainable programs. Includes the AI Under Attack Practitioner Toolkit, featuring chapter-specific Field Artifacts for real-world AI security practice.

Key Features

  • Defend LLMs, RAG, and autonomous agents against prompt injection, jailbreaks, and tool abuse
  • Apply Zero Trust architecture to AI agents with tool access, memory, and goal-directed reasoning
  • Run AI governance and red teaming programs aligned to NIST AI RMF, ISO 42001, and OWASP for LLMs
  • Purchase of the print or Kindle book includes a free PDF eBook

Book Description

Contrary to general AI texts or cybersecurity books with limited AI coverage, this guide offers a comprehensive dive into securing the generative AI ecosystem.

It moves through four parts: Foundations establishes why AI security is fundamentally different, covering threat modeling, attack surfaces, and core defense principles. Attacks provides deep technical examination of prompt injection, memory and context abuse, RAG system vulnerabilities, agent exploitation techniques, training data poisoning, and AI red teaming methodology. Building Secure AI Systems covers infrastructure and MLOps hardening, secure application and API design, defensive prompt engineering, guardrails with human oversight, supply chain integrity, and Zero Trust architecture for agents. Running AI Security Programs addresses governance, risk and compliance frameworks, security engineering practices, security operations, and building sustainable organizational capabilities. Throughout, you will gain access to practical insights and structured approaches applicable to real-world scenarios.

By the end, you will be able to design, implement, and maintain security programs for generative AI, defend against advanced threats, communicate risks to stakeholders, and establish governance ensuring secure, compliant operations across the lifecycle.

What you will learn

  • Identify AI-specific risks and clearly communicate them to business teams
  • Defend models, data, RAG, and agents from threats like poisoning, prompt injection, jailbreaking, and data exfiltration
  • Design resilient cloud/MLOps with Zero Trust, supply chain security, and isolation
  • Build secure APIs, apps, and agents with strong auth, validation, and safe tool use
  • Apply AI-focused GRC, alignment checks, bias mitigation, monitoring, and incident response
  • Translate complex concepts into actionable steps, using threat intel and collaboration for lasting security

Who this book is for

This book is for mid- to senior-level cybersecurity professionals, security architects, and tech leaders managing risks in generative AI deployments. It’s also valuable for early-career practitioners, AI/ML engineers, red teamers, DevSecOps, governance specialists, compliance officers, and product stakeholders with foundational cybersecurity knowledge. Readers should have basic familiarity with security concepts, some exposure to cloud platforms (AWS, Azure, or GCP), and a fundamental grasp of AI/ML, though no prior AI security expertise is required.

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Securing AI Using Zero Trust Principles

Securing AI Using Zero Trust Principles

Cindy Green-Ortiz, Zig Zsiga, Saskia Laura Schröer
Practical AI Security

Practical AI Security

Harriet Farlow

Publisher Resources

ISBN: 9781806119936