AIINFRA 302: AI Security, Guardrails & Governance — Syllabus

Course description

This course prepares practitioners to secure, govern, and economically operate production LLM systems. Students assess real-world AI applications against the OWASP LLM Top 10, deploy layered guardrail and content-safety frameworks, and implement privacy, provenance, and supply-chain controls across the model lifecycle. The course closes with AI governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) and GPU inference FinOps, culminating in a capstone that ties security, governance, and cost optimization together into a single deployable system.

Contact hours

54 contact hours (3-unit equivalent), delivered over a 16-week term, approximately 3.4 hours/week. This is a non-credit course on the CDCP Certificate of Completion pathway.

Prerequisite

AIINFRA 301 (LLM applications, RAG, and deployment; AIINFRA 301 itself requires AIINFRA 300).

Course Learning Outcomes (CLOs)

By the end of this course, students will be able to:

  1. CLO1: Assess LLM applications against the OWASP LLM Top 10 (2025) and construct layered defenses against direct and indirect prompt injection, jailbreaks, and data leakage.
  2. CLO2: Deploy and configure production guardrail frameworks (NeMo Guardrails, Llama Guard 4, LLM Guard, Rebuff, and Presidio) to enforce input/output validation and PII redaction.
  3. CLO3: Implement AI security controls for data privacy, secrets and access management, model provenance, and supply-chain integrity across the model lifecycle.
  4. CLO4: Evaluate AI systems against the NIST AI RMF, ISO/IEC 42001, and EU AI Act, producing model cards, risk documentation, and bias and fairness assessments.
  5. CLO5: Calculate and optimize GPU inference economics using cost per 1,000 requests, spot and fractional GPUs, quantization, KV-cache tuning, and autoscaling to make build-vs-buy decisions.

Weekly schedule

Week Topic
01 AI Security Landscape and the LLM Threat Model
02 OWASP LLM Top 10 (2025) Deep Dive
03 Direct and Indirect Prompt Injection Attacks
04 Prompt Injection Defenses and Input Validation
05 Jailbreaks, Red-Teaming, and Adversarial Testing
06 Guardrails Frameworks: NeMo Guardrails and LLM Guard
07 Content Safety and Moderation with Llama Guard 4 and Rebuff
08 PII Protection with Presidio and Output Validation (Midterm)
09 Data Privacy, Secrets Management, and Access Control
10 Model Provenance and AI Supply-Chain Security
11 AI Governance Frameworks: NIST AI RMF, ISO/IEC 42001, and the EU AI Act
12 Responsible AI, Bias, Fairness, and Model Cards
13 GPU FinOps Foundations: Cost per 1,000 Requests and Right-Sizing
14 Fractional GPUs, MIG, Quantization, and KV-Cache Savings
15 Autoscaling Economics, Spot Instances, and Build-vs-Buy
16 Capstone Project & Course Review (Capstone)

Grading

Component Weight
Labs 40%
Discussions 10%
Weekly Quizzes 15%
Midterm 15%
Final Capstone 20%

Credit/No-Credit, 70% to pass.

Course policies

Academic integrity: Students are expected to submit their own work. Collaboration on concepts is encouraged, but labs, quizzes, the midterm, and the capstone must reflect individual understanding and effort. Submitting others' work as your own, or fabricating security assessments or governance documentation, constitutes a violation of the LACCD academic integrity policy and may result in a failing grade. Late work: Assignments are due as posted in Canvas. Late submissions are accepted up to 7 days after the due date with instructor notification; work submitted after that window may not be accepted absent documented extenuating circumstances. Contact your instructor as early as possible if you anticipate a delay. Responsible use of AI: This course is about securing and governing AI systems, so responsible, transparent use of AI tools in coursework is expected and modeled. Students may use AI assistants (including LLMs) to support learning, drafting, and debugging, but must disclose significant AI assistance on graded work and remain accountable for verifying accuracy, security, and originality of anything submitted. Accessibility: This course is committed to full inclusion of students with disabilities. Students needing accommodations should contact the campus Disabled Students Programs and Services (DSPS) office as early in the term as possible so that reasonable accommodations can be arranged. All course materials are designed to meet applicable accessibility standards; please notify the instructor of any barriers encountered.

Tools & materials

All tools are free or free-tier.


Week 01 · AI Security Landscape and the LLM Threat Model

Notion ID: 392c08fd-0278-8101-868f-d32dd45a7ca6 Notion URL: https://app.notion.com/p/392c08fd02788101868fd32dd45a7ca6