// Comparison

Practical AI Security vs Security Engineering: Which Should You Read?

Two cybersecurity books on Defensive, compared honestly: who each is for, what each does best, and which to read first.

Advanced
4/52026
Practical AI Security

A Hands-on Guide to Attacking, Defending, and Securing Modern AI Systems

Harriet Farlow

The founder of an AI-security firm, with a PhD in adversarial machine learning, walks from how models fail to how they're exploited to how they're defended and audited, with over 30 hands-on Python demos.

Advanced
5/52020
Security Engineering

A Guide to Building Dependable Distributed Systems

Ross Anderson

Ross Anderson's comprehensive textbook on the design of secure systems, covering protocols, access control, side channels, economics of security, and policy.

Read this if

Security practitioners and ML engineers who need practical, hands-on grounding in attacking and defending AI systems rather than a survey of the field. Farlow has led AI-security assessments for Fortune 500s and government agencies, and the book is built from that assessment experience.
Anyone who builds, audits, or governs systems where failure has real-world consequences: banking, healthcare, voting, telecom, defence. The single most important security book ever written, and the rare textbook that improves with each edition.

Skip this if

Readers who want a conceptual or policy-level introduction to AI risk; this is a hands-on technical guide with Python demos throughout, not an AI-governance primer. Also assumes baseline ML and security fundamentals rather than teaching either from zero.
Readers looking for a hands-on tooling guide or a quick certification primer. Anderson works at the systems and policy layer; if you need to learn how to use Burp, this is not it. The 1,200 pages also reward patient readers, not skimmers.

Key takeaways

  • First book in this catalog to treat AI/ML systems as a first-class attack surface in their own right, not a feature bolted onto traditional appsec.
  • Structured around the full lifecycle: how models fail, how failures become exploits, then how to defend and audit against both.
  • Over 30 hands-on Python demos keep the material concrete rather than theoretical — attacks and defenses you can actually run.
  • Most production failures are economic and organisational, not cryptographic: incentives shape outcomes far more than primitives.
  • Threat models from one domain (banking, telecom, military) generalize to the next once you know what to look for, and Anderson is the best in the field at showing you.
  • Side channels, supply chains, and policy are first-class engineering concerns, not footnotes.

How they compare

We rate Security Engineering higher (5/5 against 4/5 for Practical AI Security). For most readers, that means Security Engineering is the primary pick and Practical AI Security is a useful follow-up.

Both books target advanced-level readers, so the choice is about topic, not difficulty.

Practical AI Security and Security Engineering both cover Defensive, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics