UNF Professional and Lifelong Learning
UNF Professional and Lifelong Learning · OffSec

Advanced AI Red Teaming AI-300 (OSAI) Training

LevelAdvanced
Duration5 Days
Experience3 yrs offensive security
Exam48-hour performance exam
Average Salary$140,895
LabsYes

Jacksonville professionals earn OffSec AI-300 (OSAI) through the University of North Florida's Professional and Lifelong Learning partnership with Applied Technology Academy. This is OffSec's advanced AI red-teaming course for attacking and exploiting AI systems, delivered live online or in person by ATA's practitioner instructors.

Coursework centers on prompt injection, model manipulation, AI supply-chain attacks and offensive testing of LLM-backed applications — the preparation Northeast Florida employers expect for advanced offensive practitioners moving into AI security. UNF PLL students get ATA's hands-on labs, unlimited mentoring and 5-star student support from first class to certification.

The UNF Professional and Lifelong Learning team handles enrollment — pick a session below or reach out and we'll map your schedule, funding and prep together.

Course Overview

The AI-300 (OSAI) is an enterprise-grade, hands-on offensive AI red teaming certification that proves your team can pressure-test LLMs and agent systems under realistic conditions. It is designed to develop practitioners who can think like adversaries in AI environments and keep pace as the threat landscape evolves. Core focus areas include offensive testing of LLMs and multi-agent systems; RAG compromise and control-surface abuse; AI supply-chain and infrastructure exploits; and post-exploitation with impact analysis that turns findings into real improvement. The certification culminates in a rigorous 48-hour exam built to validate real-world adaptability against novel AI attack surfaces.

Course Outline
  • OSAI is delivered as modular, self-paced online training, with instructor-led training available. Eleven lab-driven modules:
  • Module 1: Introduction to Red Teaming AI Systems
    • How artificial intelligence systems change the traditional attack surface: the core concepts of AI cybersecurity, how adversaries target AI-enabled environments, and where AI attacks sit in the red team lifecycle.
  • Module 2: Reconnaissance for AI Targets
    • Identify and map AI applications, machine learning components and model infrastructure inside a target environment, discovering AI assets, dependencies and exposed services without alerting defenders.
  • Module 3: Attacking AI Agents
    • Manipulate AI agents by abusing prompt instructions, memory systems and tool integrations, influencing autonomous AI applications while maintaining stealth.
  • Module 4: Attacking Multi-Agent Systems and A2A Protocols The architecture of multi-agent AI systems, and how adversaries exploit trust relationships between agents - message manipulation, agent impersonation and workflow corruption.
  • Module 5: Exploiting RAG Pipelines
    • How attackers compromise retrieval-augmented generation systems by poisoning knowledge sources and manipulating retrieval layers to control model outputs.
  • Module 6: Attacking Embeddings The role of embeddings in machine learning systems, with attacks such as embedding inversion and information extraction to recover sensitive data from AI models.
  • Module 7: Attacking Model Context Protocol and Tool Surfaces
    • How orchestration layers and AI tool-integration frameworks can be abused to escalate privileges or execute unintended actions within AI systems.
  • Module 8: Supply Chain Attacks on AI/ML Systems
    • Targeting the AI supply chain - datasets, model weights, adapters and dependencies - and the techniques used to introduce malicious artifacts before deployment.
  • Module 9: AI Infrastructure and Deployment Exploits
    • Vulnerabilities in AI infrastructure, including cloud AI platforms, model servers and containerized machine learning workloads.
  • Module 10: Threat Modeling for AI-Enabled Targets
    • Identifying high-value AI assets, trust boundaries and potential attack paths across complex AI environments.
  • Module 11: Assembling the Pieces - Capstone Red Team Engagement
    • A full-spectrum red team engagement against a realistic enterprise AI environment, simulating how adversaries compromise production AI systems.
Intended Audience

OSAI is built for practitioners who need to assess and pressure-test AI-enabled systems the way real adversaries do:

  • Red teamers and penetration testers expanding into AI
  • Security professionals tasked with evaluating AI-enabled systems
  • AI engineers who need to understand adversarial risk
  • Security teams building an internal AI red teaming capability
Prerequisites

This course and certification are not an introduction to AI, nor to AI penetration testing. Prior AI experience is not required, but we recommend familiarity with LLMs and some basic LLM pentesting methodology. Learners should also have solid general offensive-security fundamentals — OSCP or equivalent hands-on experience is recommended.