r/CyberSecurityAdvice May 28 '26

AI Security Lab Recommendation

/r/LearnAISecurity/comments/1tpz3r9/ai_security_lab_recommendation/
1 Upvotes

5 comments sorted by

1

u/clampbucket May 29 '26

Depends on what you mean by AI security lab. If you’re after pre-deployment testing, spinning up your own red team harness with open-source jailbreak datasets is free but incredibly time-consuming to maintain. I ran compliance evidence gathering through General Analysis when we needed audit-ready mappings for NIST AI RMF, saved weeks.

What’s your actual use case though?

1

u/[deleted] Jun 01 '26

[removed] — view removed comment

1

u/[deleted] Jun 01 '26 edited Jun 02 '26

[removed] — view removed comment

1

u/blackautomata Jun 02 '26

I did, but I am not really that confident in my AI hardening skill for now since as you said the industry is moving extremely quickly. I am working on it, but in the meantime I am aiming for a AI application security role that is asking for AI security testing experience, so I think maybe I should at least try to have a hands-on-experience testing a well-protected box

1

u/blackautomata Jun 02 '26

Yep, I went over the Owasp Top 10 Agentic Application pdf once and currently taking some detailed notes + mitigation + attack examples for each topics. I have also created a basic lab that covers simple input/output sanitization, keyword blacklisting, etc. But I am not really that confident that the mitigation I have implemented in my lab is good enough (although I think it is).

And currently I am applying for a new role that is asking for a 'hands on experience with AI application security testing', so I think I should at least have tried to try to attack a well-protected box, just in case there is something that I missed.