Course
Digicomp Code VAIGAS
Vertex AI and Generative AI Security («VAIGAS»)
Course facts
- Establishing foundational knowledge of Vertex AI and its security challenges
- Implementing identity and access control measures to restrict access to Vertex AI resources
- Configuring encryption strategies and protecting sensitive information
- Enabling logging, monitoring, and alerting for real-time security oversight of Vertex AI operations
- Identifying and mitigating unique security threats associated with generative AI
- Applying testing techniques to validate and secure generative AI model responses
- Implementing best practices for securing data sources and responses within Retrieval-Augmented Generation (RAG) systems
- Establishing foundational knowledge of AI Safety
Tailored for AI practitioners and security engineers, it provides targeted knowledge and hands-on skills to navigate and adopt AI safely and effectively. Participants will gain practical insights and develop a security-conscious approach, ensuring a secure and responsible integration of gen AI within their organization.
1 Introduction to Vertex AI Security Principles
- Google Cloud Security
- Vertex AI components
- Vertex AI Security concerns
- Review Google Cloud Security fundamentals
- Establish a foundational understanding of Vertex AI
- Enumerate the security concerns related to Vertex AI features and components
- Lab: Vertex AI: Training and Serving a Custom Model
2 Identity and Access Management (IAM) in Vertex AI
- Overview of IAM in Google Cloud
- Control access with Identity Access Management
- Simplify permission using organization hierarchies and policies
- Use service accounts for least privileged access
- Lab: Service Accounts and Roles: Fundamentals
3 Data Security and Privacy
- Data encryption
- Protecting Sensitive Data
- VPC Service Controls
- Disaster recovery planning
- Configure encryption at rest and in-transit
- Encrypt data using customer-managed encryption keys
- Protect sensitive data using the Data Loss Prevention service
- Prevent exfiltration of data using VPC Service Controls
- Architect systems with disaster recovery in mind
- Lab: Getting Started with Cloud KMS
- Lab: Creating a De-identified Copy of Data in Cloud Storage
4 Securing Vertex AI Endpoints and model deployment
- Network security
- Securing model endpoints
- Deploy ML models using model endpoints
- Secure model endpoints
- Lab: Configuring Private Google Access and Cloud NAT
5 Monitoring and logging in Vertex AI
- Logging
- Monitoring
- Write to and analyze logs
- Set up monitoring and alerting
6 Security risks in generative AI applications
- Overview of gen AI security risks
- Overview of AI Safety
- Prompt security
- LLM safeguards
- Identify security risks specific to LLMs and gen AI applications
- Understand methods for mitigating prompt hacking and injection attacks
- Explore the fundamentals of securing generative AI models and applications
- Introduce fundamentals of AI Safety
- Lab: Safeguarding with Vertex AI Gemini API
- Lab: Gen AI & LLM Security for Developers
7 Testing and evaluating generative AI model responses
- Testing generative AI model responses
- Evaluating model responses
- Fine-Tuning LLMs
- Implement best practices for testing model responses
- Apply techniques for improving response security in gen AI applications
- Lab: Measure Gen AI Performance with the Generative AI Evaluation Service
- Lab: Unit Testing Generative AI Applications
8 Securing Retrieval-Augmented Generation (RAG) systems
- Fundamentals of Retrieval-Augmented Generation
- Security in RAG systems
- Understand RAG architecture and security implications
- Implement best practices for grounding and securing data sources in RAG systems
- Lab: Multimodal Retrieval Augmented Generation (RAG) using the Vertex AI Gemini API
- Lab: Introduction to Function Calling with Gemini
AI practitioners, security professionals, and cloud architects
Fundamental knowledge of machine learning, in particular generative AI, and basic understanding of security on Google Cloud.
Products
- Vertex AI
- Gemini
- Cloud IAM
- Cloud VPC
- Cloud KMS
- Cloud Operations
- Sensitive Data Protection