
Practical AI Security
A Hands-on Guide to Attacking, Defending, and Securing Modern AI Systems
The founder of an AI-security firm, with a PhD in adversarial machine learning, walks from how models fail to how they're exploited to how they're defended and audited, with over 30 hands-on Python demos.
As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.
- Authors
- Harriet Farlow
- Published
- 2026
- Publisher
- No Starch Press
- Pages
- 392
- Language
- English
Read this if
Security practitioners and ML engineers who need practical, hands-on grounding in attacking and defending AI systems rather than a survey of the field. Farlow has led AI-security assessments for Fortune 500s and government agencies, and the book is built from that assessment experience.
Skip this if
Readers who want a conceptual or policy-level introduction to AI risk; this is a hands-on technical guide with Python demos throughout, not an AI-governance primer. Also assumes baseline ML and security fundamentals rather than teaching either from zero.
Key takeaways
- First book in this catalog to treat AI/ML systems as a first-class attack surface in their own right, not a feature bolted onto traditional appsec.
- Structured around the full lifecycle: how models fail, how failures become exploits, then how to defend and audit against both.
- Over 30 hands-on Python demos keep the material concrete rather than theoretical — attacks and defenses you can actually run.
Notes
A genuinely new topic for this catalog, which otherwise has no dedicated AI-security title. Pairs with Malware Data Science and The Android Malware Handbook for the "ML applied to security" side, and with Designing Secure Software for readers thinking about how AI components fit into a broader secure-design practice.
What to read before
What to read before Practical AI Security →Advanced · 2020
Intelligence artificielle, cybersécurité et cyberdéfense
An academic examination of how artificial intelligence reshapes cybersecurity and cyberdefence — opportunities, threats and strategic implications — by France's most prolific cyberwar scholar.
Intermediate · 2021
Designing Secure Software
Loren Kohnfelder, the original PKI author, on how to weave security thinking through requirements, design, implementation and operations rather than bolt it on at the end.
Intermediate · 2008
Hacking: The Art of Exploitation
A from-first-principles tour of low-level exploitation that still teaches the mindset two decades later.
What to read next
What to read after Practical AI Security →Advanced · 2020
Intelligence artificielle, cybersécurité et cyberdéfense
An academic examination of how artificial intelligence reshapes cybersecurity and cyberdefence — opportunities, threats and strategic implications — by France's most prolific cyberwar scholar.
Advanced · 2017
Attacking Network Protocols
James Forshaw, Project Zero veteran, on how to capture, parse, and break protocols from the wire up to the application layer, with a strong focus on building reusable analysis tooling.
Advanced · 2020
Building Secure and Reliable Systems
Google's site-reliability and security teams jointly write down what it actually takes to build systems that are both safe and dependable, from threat models and design reviews to rollback culture and crisis response.
Explore similar books
Alternatives to Practical AI Security →Advanced · 2020
Intelligence artificielle, cybersécurité et cyberdéfense
An academic examination of how artificial intelligence reshapes cybersecurity and cyberdefence — opportunities, threats and strategic implications — by France's most prolific cyberwar scholar.
Advanced · 2024
Windows Security Internals
Forshaw takes apart the Windows security model from the SRM and access tokens up through Kerberos, with live PowerShell you can run against your own machine. The most authoritative single source on how Windows actually decides who can do what.
Advanced · 2023
Security Chaos Engineering
Kelly Shortridge and Aaron Rinehart on treating security as a property of complex adaptive systems: instead of preventing failure, you continuously simulate it, and design the organization to learn from each result.