AI systems have moved beyond generating text into taking action. They're in production. They query internal data, make API calls, and interact with other production systems, often with more access than most humans get. AI systems aren't deterministic; they reason, adapt, and operate on untrusted input in ways that traditional security models simply weren't designed for. This creates new vulnerabilities and shifts the entire control surface. This book is about that shift. In AI Security Engineering, Dan Borges and David Campbell show you how to rethink security for AI systems built on retrieval pipelines, persistent memories, and agents that take action. Drawing from real-world adversarial testing and production deployments, they focus on how these systems actually fail: prompt injection that turns inputs into instructions, poisoned retrieval that corrupts decisions at runtime, and agents that quietly accumulate more authority than intended. Rather than relying on the model to do the right thing you'll learn how to design systems that constrain what AI systems are allowed to do, enforce least privilege at the capability level, and build architecture that can observe, interrupt, and contain failures when they happen.
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
# AI Security Engineering: Securing Agentic Systems in Production
## 【One-Line Pitch】
A practical security engineering handbook for teams deploying AI agents, retrieval pipelines, and memory systems in production—showing how classic infosec principles apply to systems that reason, adapt, and act on untrusted input. Essential reading for security engineers, AI platform teams, and anyone responsible for production AI systems.
## 【Book Arc】
- **Opening (~0%–9%)**: Frames the core problem—AI systems have moved from text generation to taking actions in production, querying internal data, making API calls, and interacting with other systems. The authors position this as a shift in the entire control surface, requiring security thinking beyond traditional models.
- **Early (~9%–19%)**: Establishes the foundational security principles that will guide the rest of the book. Draws on "First Principle Reasoning" from Rick Howard's work, boiling infosec down to fundamental truths that can be applied abstractly to new problems. Introduces the concept of untrusted input as the first core principle.
- **Early (~19%–34%)**: Builds out the core security framework—covering identity (authentication and authorization), trust boundaries, control decay, and defense in depth. Each principle is stated explicitly and connected to AI system design. The authors emphasize that these are timeless issues, noting access control remains the number one OWASP Top 10 issue in 2025.
- **Middle (~34%–47%)**: Applies the principles to modern AI-specific threats. Covers the ratcheting increase in tool and agent permissions, supply chain attacks (including the novel "Slopsquatting" attack on AI-hallucinated dependencies), and the critical need for observation and telemetry through centralized logging.
## 【Key Takeaways】
- **Untrusted input is the foundational principle** (Early): "Treat all external input as potentially malicious until validated within the intended context." This extends classic web security categories—SQL injection, XSS, command injection—to AI systems where inputs become instructions. The principle scales from traditional apps to prompt injection threats.
- **Identity requires both authentication and authorization** (Early): The BIC model (Behavior, Identity, Control) frames access decisions as requiring "verified identity and explicit authorization before actions are permitted." This is especially critical for AI agents that may accumulate permissions beyond what operators intend.
- **Trust boundaries are the map for security controls** (Early): A trust boundary is where assumptions about identity, behavior, permissions, or security guarantees change. Mapping these boundaries is a prerequisite to designing effective controls—every sensitive data fetch or profile access needs an explicit authority check, ideally implemented in common middleware.
- **Security control decay is inevitable** (Early): Like "bit rot," security technologies lose effectiveness over time as surrounding technologies evolve. The 2026 infosec landscape shows an explosion in exploit development aided by AI. The mitigation is staggering layered controls rather than relying on any single solution.
- **Defense in depth means engineering acceptable losses** (Early–Middle): Drawing from military strategy and Bruce Schneier's "Process of Security," the principle states: "Security improves when independent controls overlap such that failure of one does not produce a total failure of the control set." Attackers only need one mistake caught by defenders.
- **Least privilege must be enforced at the capability level** (Middle): The industry is seeing a "ratcheting increase in tool and agent permissions," prompting frameworks like MiniScope, AgentScope, and NanoClaw. AI agents should be rate-limited and tightly controlled, not given broad access by default.
- **AI-generated code creates new supply chain risks** (Middle): "Slopsquatting" weaponizes hallucinated dependency names—attackers typosquat packages that AI models invent. Reviewing software bills of materials, using automated scanners, and monitoring dependencies is more critical than ever as AI coding assistants embed errors into the attack surface.
- **You cannot secure what you cannot observe** (Middle): "Systems require sufficient telemetry to distinguish intended behavior from anomalous behavior." Centralized logging with data normalization is a core pillar of security engineering, enabling incident understanding, evidence collection, and compromise investigation.
## 【Reading Tips】
- **Deep-read the Early chapters (~9%–34%)**: The security principles laid out here—untrusted input, identity, trust boundaries, control decay, defense in depth, least privilege—form the conceptual toolkit used throughout the rest of the book. These are the mental models you'll apply to AI-specific problems.
- **Skim the front matter (~0%–9%)**: Standard O'Reilly boilerplate (copyright, contact info, code example usage). The GitHub repo mentioned will be active later; check it for code examples and exercises.
- **Pay special attention to the stated principles**: Each principle is explicitly formulated (e.g., "Treat all external input as potentially malicious..."). These are designed to be memorable and applicable—consider writing them down as your own security checklist.
- **Note the 2026 context**: The book is written with awareness of the current AI-assisted exploit landscape. This isn't theoretical—the authors reference real frameworks (MiniScope, AgentScope, NanoClaw) and real attack patterns (Slopsquatting) emerging in production.
- **Expect practical application in later chapters**: The excerpts cover foundational theory and threat framing. The book's promise is architecture-level guidance—constraining what AI systems can do, enforcing least privilege, and building observable, interruptible, containable systems. Later chapters should deliver on this.
## 【Coverage Limits】
This guide covers the foundational security principles and threat landscape framing from the opening and early-middle portions of the book (approximately the first 47%). The excerpts do not cover the later chapters' specific architectural patterns, implementation details, or case studies for securing agentic systems—those will require reading the full book.
##
Page 3
ditions are also available for most titles (https://oreilly.com). For more information, contact our corporate/institutional sales department: 800-998-9938 or...
ial impact due to a cyber event over the next three years.”. That is great, but it doesn’t give us any mental models or tools to actually reduce negative cyb...
er the next several years, however, the environment evolved. New microservices were deployed, third-party integrations were added, and development teams requ...
ries of dark rooms, or even a series of connected buildings. In these buildings there are tons of boxes of information, but you need access to the rooms and ...
the situation plans and controls may be subject to various regulatory frameworks, so why not factor those into the planning stage early. Large projects may a...
and inefficient unless the information being fed to them is carefully organized. Research on long-context performance has repeatedly shown that models do not...
advise colleagues against purely AI generated code. I find that AI generated code, if left unchecked, becomes increasingly hard for humans to contribute to o...
through adversarial inputs. Claude Code’s harness natively introduces these HITL controls as part of their default tool suite, but it gives the user the opti...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
AI Security Engineering (Dan Borges David Campbell)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
AI Security Engineering (Dan Borges David Campbell)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment