2026 cohorts are now open across all programs · See the programs
Professional certificationCAIS-01

Certified Professional in AI Security

Two months · Red team and blue team · Live labs

An intensive two-month programme that turns cybersecurity professionals into AI security specialists — teaching the attacks first, because a defence you have never had to get past is not a defence you can trust.

8 wk
Program length
2 wk
Capstone project
2
Red and blue team
5+
Security toolkits
Security engineer working at a server rack
Live lab — adversarial robustness testing
Programme overview

Attack it, then defend it

Eight components structure the programme, from threat modelling across the ML lifecycle through hands-on adversarial attacks and the defences that stop them.

Offensive security masterclass
Hands-on adversarial attack techniques and red team methodologies.
Practical attack portfolio
Execute simulated adversarial attacks, then build the defensive frameworks.
Industry-standard tooling
Adversarial Robustness Toolbox, CleverHans, Foolbox, ModelScan and more.
CTF and red team training
AI-focused Capture The Flag competitions and structured red team exercises.
World-class faculty
Former AI security researchers and penetration testing specialists.
Career acceleration support
Dedicated career services for a highly specialized and under-supplied role.
Who this program is for

Three entry profiles

Security professionals at a technical seminar
Faculty-led cohort instruction
Cybersecurity professionals
  • Security engineers specializing in AI and ML defence
  • Penetration testers expanding to AI attack vectors
  • Security analysts adding AI threat intelligence
  • Incident responders handling AI security breaches
Technical and leadership roles
  • Security architects designing AI security strategy
  • CISO teams building enterprise AI defences
  • MLOps engineers securing ML pipelines
  • AI developers building inherently secure systems
Advanced specialists
  • Red team specialists targeting AI systems
  • Blue team defenders protecting ML models
  • Government and defence security professionals
  • Threat researchers studying AI vulnerabilities
Tech AI Magazine badge — Best Places to Study AI
Recognition

Best Places to Study AI

Tech AI Magazine has recognized the Heisenberg Institute for AI and Quantum Computing in its Best Places to Study AI listing.

What you get

Why Heisenberg

What the Institute puts behind every candidate it admits.

Global faculty and experts
Learn from leading AI researchers and industry experts across multiple domains.
Hands-on practice
Live labs and an assessed capstone that leave you with a documented portfolio of your own work.
Job assistance
Resume building, mock interviews, interview preparation, career guidance, and job connections and updates.
Flexible payment options
Instalments and flexible payment plans — talk to the admissions team.
Faculty

Who teaches the CAIS programme

People who attack and defend these systems for a living — adversarial machine learning on one side, red teaming on the other. Select a name to read their profile.

Beyond the programme team, a global faculty of practitioners, researchers and technology enablers teaches across the Institute, and every cohort also meets visiting CEOs, CAIOs and AI researchers. All of them are named in the Faculty Directory 2026.

By the numbers

The Institute in numbers

|ψ⟩ = α|0⟩ + β|1⟩
5
Programmes
Five certifications, from a two-month foundation to two six-month flagships.
8 wk
Hands-on labs
Attack simulation and defence implementation against live models.
18
Industry experts
Practitioners shaping curriculum design and providing mentorship.
Skill acquisition
Faster mastery through guided practice and immediate application.
24/7
Learning access
Always-available platform and a community of peers, mentors, and alumni.
Applied training

Learn AI security by breaking real models

Every offensive technique is executed in a lab against a working model, and every defensive module is measured against the attacks from the phase before it. Nothing is taught as theory that can be demonstrated as practice.

Attack simulation portfolio — penetration tests and adversarial campaigns you can show an employer.
Defensive frameworks — adversarial training, input transformation, watermarking and runtime monitoring.
Red and blue team exercises — AI-focused CTF competitions run against the cohort's own hardened models.
Participant working through a lab exercise
Cohort at an industry session
The journey

Attack it, then defend it — in six stages

The order is the argument: you cannot harden a system you have never taken apart.

The six stages of the CAIS programme, from threat modelling to certification
01
AI security and threat modelling
Understand vulnerabilities across the ML lifecycle, AI threat taxonomy, attack surfaces and enterprise risk assessment.
02
Adversarial attacks
Learn adversarial evasion techniques, including FGSM, C&W, PGD and advanced perturbation methods.
03
AI red team operations
Execute data poisoning, backdoor attacks, model extraction, inversion and AI penetration testing.
04
Generative AI security
Test AI systems against prompt injection, jailbreaking, LLM manipulation and training-data extraction.
05
Defensive hardening
Build defences using adversarial training, anomaly detection, model protection, runtime monitoring and secure inference.
06
CAIS certification and portfolio
Graduate with the Certified Professional in AI Security (CAIS) credential and a documented attack simulation portfolio.
Tools ecosystem

The tools you will actually use

Seven groups of tooling — the offensive toolkit, the defensive one, and the monitoring stack that tells you which is winning.

The CAIS tools ecosystem, in seven groups
AI security and threat modelling
Python · Jupyter · scikit-learn · NetworkX · MITRE ATLAS · NIST AI RMF
Adversarial attacks
PyTorch · TensorFlow · Foolbox · ART · CleverHans · OpenCV · NumPy · SciPy · Matplotlib · scikit-image
AI red team operations
MITRE ATT&CK · OWASP · STRIDE · DeepStrike · Adversarial Robustness Toolbox · TextAttack · TensorFlow Privacy · OpenAI Evals
Model extraction and inversion
Trickster · Copycat · Knockoff Nets · OpenBox · GraKeL · SHAP · LIME · Captum · DeepExplainer
Security testing and assessment
Kali Linux · Burp Suite · Nmap · Wireshark · Metasploit · Ghidra · IDA Pro · Radare2 · YARA · Volatility
Defence and mitigation
RobustBench · DeepRobust · IBM AIF360 · Microsoft Fairlearn · TensorFlow Federated · differential privacy · homomorphic encryption · model hardening
Monitoring, detection and response
Prometheus · Grafana · ELK Stack · Wazuh · TheHive · Cortex · Snyk · OpenTelemetry · MISP · Slack · Jira
Certification

A credential earned against live models

Successful completion confers the Certified Professional in AI Security credential from the Heisenberg Institute.

Certified Professional in AI Security (CAIS)
Validates hands-on expertise in adversarial attack, model hardening and AI defence.
Attack simulation portfolio
Documented penetration tests and security frameworks built during the programme.
Elite career positioning
For AI security engineer, ML security architect and red team specialist roles.
CAIS certificate issued by the Heisenberg Institute
Alumni voices

In their own words

Graduates of the CAIS programme on what changed for them.

I come from cybersecurity, so I initially thought AI security would be fairly straightforward to pick up. It wasn’t. I started watching videos about prompt injection, adversarial attacks and model security, but everything felt very fragmented. CAIS helped me understand how these risks fit into the bigger AI system. I finally had a framework instead of a list of attacks.
DennyCybersecurity Engineer · United States
I had a good understanding of traditional application security but very little practical experience securing AI systems. That was becoming a problem because more of the systems I was working with were starting to include AI. CAIS helped me understand the differences and, importantly, gave me practical ways to think about securing these systems.
SarahSecurity Architect · United Kingdom
My issue was that most of the AI security material I found was either very academic or just a quick demo of an attack. CAIS was different because we looked at the attack and then had to think about how to defend against it. That made the concepts stick much better for me.
MohammedDevSecOps Engineer · Germany
I had probably watched too many videos on LLM security before joining. Every video had a new vulnerability and after a while it was difficult to tell what was actually important. CAIS gave me a structured view of the AI attack surface. It helped me stop thinking about individual vulnerabilities and start thinking about the whole system.
ElbaApplication Security Engineer · Canada
I joined because AI was increasingly coming into conversations with our security team and I didn’t want to be the person who only understood the traditional security side. CAIS gave me enough technical depth to understand how AI systems can fail and how the security approach needs to change. That has already been useful in my work.
Choo WeinInformation Security Manager · Singapore
I had done quite a bit of self-learning before CAIS, but there was no real sequence to it. I would learn about one attack, then another, then read something about model security and go down another rabbit hole. The program gave me the structure I was missing. It also made me much more comfortable discussing AI security with engineering teams.
ReyenaSecurity Consultant · Switzerland
The biggest thing I took away from CAIS was the attacker mindset. I was used to looking at systems from a defensive perspective. Learning to think about how someone would actually try to manipulate or attack an AI system changed the way I look at these architectures. It made AI security feel much more tangible.
MaheshCybersecurity Lead · Australia
Intake schedule

Monthly cohort commencement

The programme admits a cohort every month. Applying early is the surest way to secure the cohort you want.

All classes are held online only, owing to the high volume of applications. Live sessions run on Saturday and Sunday, 1:30–4:30 PM GMT.
Cohort
Application closes
Program starts
Status
CohortAugust 2026 Cohort
Application closesAugust 1, 2026
Program startsAugust 25, 2026
StatusClosed
CohortSeptember 2026 Cohort
Application closesSeptember 1, 2026
Program startsSeptember 25, 2026
StatusOpen
CohortOctober 2026 Cohort
Application closesOctober 1, 2026
Program startsOctober 25, 2026
StatusUpcoming
CohortNovember 2026 Cohort
Application closesNovember 1, 2026
Program startsNovember 25, 2026
StatusUpcoming
CohortDecember 2026 Cohort
Application closesDecember 1, 2026
Program startsDecember 25, 2026
StatusUpcoming
Programme fee
$1,499USD · full programme

Flexible payment options and corporate sponsorship support are available — contact the admissions team for details.

Bonus: the programme is delivered as live online masterclasses on Fridays and Saturdays, with recorded sessions and virtual lab access for everything you miss.
Your fee includes
  • Certified Professional in AI Security (CAIS) certification, awarded by the Heisenberg Institute for AI and Quantum Computing
  • Offensive and defensive masterclasses — live expert-led training in adversarial attack, model poisoning and ML system defence
  • A real-world attack simulation portfolio: penetration tests and security frameworks built against live AI and ML systems
Frequently asked questions

Before you apply

Are classes held online or on campus?
Online only. Live masterclasses run on Fridays and Saturdays, with recorded sessions and virtual lab access, so a missed session does not cost you the lab.
When do cohorts begin?
Cohorts commence every month. Applications close on the 1st and classes begin on the 25th. Applicants are encouraged to apply six to eight weeks ahead of the deadline.
Do I need an existing security background?
Yes. Phase 2 starts executing adversarial attacks in week three. Candidates typically arrive with five or more years in information security, a cyber security degree, or a CISA, CISSP or CISM certification.
Do I need machine learning experience as well?
Not to the depth of an ML engineer. Phase 1 covers the ML lifecycle from a security perspective, which is enough to attack and defend the systems in phases 2 and 3.
Are the attacks run against real models?
Yes — in an isolated lab environment provided by the Institute, against models the cohort trains. Techniques are never exercised against third-party systems.
What is the weekly workload?
Eight weeks is compressed. Expect the weekend sessions plus lab work during the week, with the CTF and red team exercises running across phases 2 and 3.
Are flexible payment options available?
Yes. Flexible payment plans and corporate sponsorship support are available — contact the admissions team for details.