Pax

Secure By Dezign

Secure By Dezign is the AI Security Training Ground — a daily technical podcast for CISOs, security architects, and AI pentesters who refuse to be caught flat-footed by adversarial machine learning. Every episode dissects a real AI attack technique from first principles: the root vulnerability, step-by-step exploitation with working code, historical breaches, and actionable defenses you can deploy today. Topics include prompt injection, RAG poisoning, model inversion, adversarial ML, LLM jailbreaking, indirect prompt injection, agentic AI security, AI supply chain attacks, deepfake-powered BEC...

Author

Pax

Category

Technology

Podcast website

www.securebydezign.com

Latest episode

Apr 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Federated Learning Poisoning Weaponizing Collaborative Ai 18.03.2026

Episode 41: Federated Learning Poisoning Weaponizing Collaborative Ai

Attacking Ml Api Gateways Behavioral Drift Model Poisoning 18.03.2026

Episode 42: Attacking Ml Api Gateways Behavioral Drift Model Poisoning

Clean Label Poisoning Invisible Training Data Attack 17.03.2026

Episode 39: Clean Label Poisoning Invisible Training Data Attack

Backdoor Attacks Trojaned Neural Networks 17.03.2026

Episode 40: Backdoor Attacks Trojaned Neural Networks

Payload Splitting Bypassing Ai Filters 15.03.2026

Episode 38: Payload Splitting Bypassing Ai Filters

Multi-Turn Manipulation: The Slow Burn Attack That Bypasses Every Single-Turn Defense 13.03.2026

How attackers weaponize conversational context to make LLMs forget their guardrails across multi-turn interactions — and how to build defenses that persist across the full conversation window.

Token Smuggling: When Your Tokenizer Becomes the Attack Vector 12.03.2026

Exploiting the gap between human-readable text and machine tokenization to bypass every filter you've built. Covers homoglyph attacks, whitespace injection, and tokenizer-aware defenses.

Building Your AI Attack Lab: Local LLM Pentesting from Zero to Pwned 12.03.2026

Your airgapped playground for prompt injection, jailbreaking, and system prompt extraction. No API keys, no rate limits, no excuses. Complete setup and attack walkthrough with Ollama.

RAG Poisoning: Weaponizing Vector Databases to Hijack LLM Outputs 12.03.2026

Your trusted knowledge base is an injection surface — here's how attackers exploit it. Hands-on lab covering document poisoning, embedding manipulation, and retrieval hijacking.

Building Your Own Vulnerable AI Agent: A Complete LangChain + Ollama Attack Lab 12.03.2026

Set up a local LLM agent with dangerous tools, then systematically exploit it with tool injection, privilege escalation, memory hijacking, and DoS. Full hands-on lab walkthrough.

Invisible Commands: Visual Prompt Injection Against Multimodal LLMs 12.03.2026

When your image is the attack vector, every picture becomes a potential payload. Technical walkthrough of visual prompt injection against multimodal LLMs including GPT-4V and Gemini Vision.

Jailbreaking LLMs: The Art of Breaking AI Safety at Scale 11.03.2026

Why your carefully aligned model is one clever prompt away from chaos. Covers DAN variants, many-shot jailbreaking, adversarial suffixes, and the cat-and-mouse dynamics of safety alignment.

Budgeting for AI Security: Where CISOs Should Invest in 2026 10.03.2026

A strategic allocation framework for securing AI systems while demonstrating ROI to the board — including tooling prioritization, build vs. buy decisions, and budget defense strategies.

Indirect Prompt Injection: Weaponizing the Web Against Your AI 10.03.2026

When your LLM trusts external content, attackers don't need access to your users — they just need a webpage. Technical walkthrough of indirect prompt injection with real-world exploitation chains.

Securing AI Training Data Pipelines: A Practitioner's Guide to Protecting Your Model's Foundation 09.03.2026

Your model is only as trustworthy as the data that built it. A practitioner's guide to defending every stage of the ML data pipeline — from ingestion to labeling to preprocessing.

AI Vendor Risk Management: What CISOs Must Demand Before Signing the Contract 08.03.2026

The executive playbook for vetting AI suppliers in an era of opaque models and expanding attack surfaces. What contractual, technical, and audit controls CISOs must demand.

AI Security Posture Management: Navigating the Emerging Standards Landscape in 2026 07.03.2026

A practitioner's guide to implementing AI-SPM frameworks before regulatory mandates force your hand — covering emerging standards, tooling, and continuous posture assessment.

AI Model Watermarking and IP Protection: Defending Your Neural Networks from Theft 06.03.2026

Technical strategies for embedding, detecting, and enforcing ownership claims in production ML systems — including robustness testing against removal attacks.

AI Governance Frameworks: From Policy to Practice 05.03.2026

Building enforceable AI governance that survives first contact with production systems. Covers NIST AI RMF, EU AI Act, ISO 42001, and practical implementation strategies.

Prompt Injection Attacks on Enterprise AI Assistants: The Invisible Threat in Your LLM Deployments 04.03.2026

How adversaries weaponize natural language to compromise your most trusted AI systems. Comprehensive coverage of direct and indirect injection, RLHF evasion, and enterprise-grade defenses.

AI Model Supply Chain Poisoning: The Silent Threat Lurking in Your ML Pipeline 04.03.2026

How adversaries weaponize the trust you place in pre-trained models, datasets, and ML dependencies. Covers backdoor injection, dataset poisoning, and dependency confusion in the ML pipeline.

AI Shadow IT: The Invisible Threat Multiplier in Your Enterprise 04.03.2026

When employees bypass security to use ChatGPT, Claude, and dozens of other AI tools, they're not just breaking policy — they're creating attack surfaces you can't see. Here's how to find and fix them.

Agentic AI Security: When AI Agents Go Rogue and How to Stop Them 04.03.2026

Autonomous AI systems are rewriting the threat landscape. Deep-dive into agent hijacking, tool misuse, privilege escalation in multi-agent pipelines, and your survival guide for agentic deployments.

Federated Learning Security: When Collaboration Becomes Risk 04.03.2026

The distributed ML paradigm that promised privacy may be your biggest attack surface yet. Deep-dive into poisoning attacks against federated models, gradient inversion, and Byzantine fault tolerance.

The CISO's Guide to AI Risk: What Boards Are Really Asking (And How to Answer Them) 04.03.2026

Translating AI security threats into boardroom language that drives action and budget — with model answers to the toughest questions your board will ask in 2026.

Listen to the Secure By Dezign podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.