AI & Machine Learning
AI/ML Cybersecurity
Security for AI and machine learning systems: adversarial testing, secure ML pipelines and AI risk governance aligned with the NIST AI RMF.
Overview
Secure the AI your mission depends on.
AI and machine learning systems bring new attack surfaces: poisoned training data, manipulated models, prompt injection and leaked sensitive data. CDT tests AI systems the way adversaries attack them, engineers the pipelines and applications around them to be secure, and helps you manage AI risk so new capabilities can be authorized and fielded with confidence.
What's included
Capabilities
AI red teaming & adversarial testing
Prompt injection, jailbreaks, data poisoning, model evasion and model extraction tested by hand, with findings mapped to MITRE ATLAS.
Secure AI architecture
Machine learning pipelines, model and data supply chains, LLM applications and AI agents designed with access controls, guardrails and monitoring.
AI governance & risk
AI system inventories, risk assessments and policies aligned with the NIST AI Risk Management Framework, and AI systems carried through RMF authorization.
AI-enabled defense
Evaluation and integration of AI-enabled security tools for detection, triage and threat hunting, with their limits understood before you rely on them.
How we work
A proven, repeatable process.
-
1
Discover
We identify the use cases worth pursuing, the data available, and the security, compliance and operating constraints.
-
2
Design
Architecture, model selection and security are decided together, including where data and models can live.
-
3
Build
We develop, integrate and evaluate against the tasks that matter, with real users in the loop.
-
4
Secure & validate
Adversarial testing, guardrails and documentation prepare the system for authorization and real use.
-
5
Deploy & operate
We deploy to your environment, from cloud to air-gapped, and monitor, measure and improve it over time.
How is testing an AI system different from a penetration test?
AI systems can be attacked through their data and behavior as well as their infrastructure. Alongside conventional testing, we try to manipulate the model itself: injecting instructions, extracting training data or the model, and poisoning what it learns from.
Which frameworks do you use?
We map adversarial findings to MITRE ATLAS and the OWASP Top 10 for LLM Applications, and align governance and risk work with the NIST AI Risk Management Framework, so results fit into your existing RMF and compliance processes.
Related services
Often paired with
AI & Machine Learning
AI/ML Development & Engineering
LLM applications, retrieval, fine-tuning and machine learning systems, engineered, evaluated and deployed securely, from the cloud to air-gapped networks.
AI & Machine Learning
AI Agents & Skills Engineering
AI agents, tools and skills that take on real work, integrated with your systems, with guardrails, human oversight and the security of a production system.
Offensive Security & Assessment
Penetration Testing
Application, infrastructure, cloud and wireless testing that shows how an attacker could exploit your systems, before they do.
Let's talk
Let's talk about AI/ML cybersecurity.
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.