Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Dan Borges & David Campbell

Rating No ratings yet

AI systems have moved beyond generating text into taking action. They're in production. They query internal data, make API calls, and interact with other production systems, often with more access than most humans get. AI systems aren't deterministic; they reason, adapt, and operate on untrusted input in ways that traditional security models simply weren't designed for. This creates new vulnerabilities and shifts the entire control surface. This book is about that shift. In AI Security Engineering, Dan Borges and David Campbell show you how to rethink security for AI systems built on retrieval pipelines, persistent memories, and agents that take action. Drawing from real-world adversarial testing and production deployments, they focus on how these systems actually fail: prompt injection that turns inputs into instructions, poisoned retrieval that corrupts decisions at runtime, and agents that quietly accumulate more authority than intended. Rather than relying on the model to do the right thing you'll learn how to design systems that constrain what AI systems are allowed to do, enforce least privilege at the capability level, and build architecture that can observe, interrupt, and contain failures when they happen.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# AI Security Engineering: Securing Agentic Systems in Production ## 【One-Line Pitch】 A practical security engineering handbook for teams deploying AI agents, retrieval pipelines, and memory systems in production—showing how classic infosec principles apply to systems that reason, adapt, and act on untrusted input. Essential reading for security engineers, AI platform teams, and anyone responsible for production AI systems. ## 【Book Arc】 - **Opening (~0%–9%)**: Frames the core problem—AI systems have moved from text generation to taking actions in production, querying internal data, making API calls, and interacting with other systems. The authors position this as a shift in the entire control surface, requiring security thinking beyond traditional models. - **Early (~9%–19%)**: Establishes the foundational security principles that will guide the rest of the book. Draws on "First Principle Reasoning" from Rick Howard's work, boiling infosec down to fundamental truths that can be applied abstractly to new problems. Introduces the concept of untrusted input as the first core principle. - **Early (~19%–34%)**: Builds out the core security framework—covering identity (authentication and authorization), trust boundaries, control decay, and defense in depth. Each principle is stated explicitly and connected to AI system design. The authors emphasize that these are timeless issues, noting access control remains the number one OWASP Top 10 issue in 2025. - **Middle (~34%–47%)**: Applies the principles to modern AI-specific threats. Covers the ratcheting increase in tool and agent permissions, supply chain attacks (including the novel "Slopsquatting" attack on AI-hallucinated dependencies), and the critical need for observation and telemetry through centralized logging. ## 【Key Takeaways】 - **Untrusted input is the foundational principle** (Early): "Treat all external input as potentially malicious until validated within the intended context." This extends classic web security categories—SQL injection, XSS, command injection—to AI systems where inputs become instructions. The principle scales from traditional apps to prompt injection threats. - **Identity requires both authentication and authorization** (Early): The BIC model (Behavior, Identity, Control) frames access decisions as requiring "verified identity and explicit authorization before actions are permitted." This is especially critical for AI agents that may accumulate permissions beyond what operators intend. - **Trust boundaries are the map for security controls** (Early): A trust boundary is where assumptions about identity, behavior, permissions, or security guarantees change. Mapping these boundaries is a prerequisite to designing effective controls—every sensitive data fetch or profile access needs an explicit authority check, ideally implemented in common middleware. - **Security control decay is inevitable** (Early): Like "bit rot," security technologies lose effectiveness over time as surrounding technologies evolve. The 2026 infosec landscape shows an explosion in exploit development aided by AI. The mitigation is staggering layered controls rather than relying on any single solution. - **Defense in depth means engineering acceptable losses** (Early–Middle): Drawing from military strategy and Bruce Schneier's "Process of Security," the principle states: "Security improves when independent controls overlap such that failure of one does not produce a total failure of the control set." Attackers only need one mistake caught by defenders. - **Least privilege must be enforced at the capability level** (Middle): The industry is seeing a "ratcheting increase in tool and agent permissions," prompting frameworks like MiniScope, AgentScope, and NanoClaw. AI agents should be rate-limited and tightly controlled, not given broad access by default. - **AI-generated code creates new supply chain risks** (Middle): "Slopsquatting" weaponizes hallucinated dependency names—attackers typosquat packages that AI models invent. Reviewing software bills of materials, using automated scanners, and monitoring dependencies is more critical than ever as AI coding assistants embed errors into the attack surface. - **You cannot secure what you cannot observe** (Middle): "Systems require sufficient telemetry to distinguish intended behavior from anomalous behavior." Centralized logging with data normalization is a core pillar of security engineering, enabling incident understanding, evidence collection, and compromise investigation. ## 【Reading Tips】 - **Deep-read the Early chapters (~9%–34%)**: The security principles laid out here—untrusted input, identity, trust boundaries, control decay, defense in depth, least privilege—form the conceptual toolkit used throughout the rest of the book. These are the mental models you'll apply to AI-specific problems. - **Skim the front matter (~0%–9%)**: Standard O'Reilly boilerplate (copyright, contact info, code example usage). The GitHub repo mentioned will be active later; check it for code examples and exercises. - **Pay special attention to the stated principles**: Each principle is explicitly formulated (e.g., "Treat all external input as potentially malicious..."). These are designed to be memorable and applicable—consider writing them down as your own security checklist. - **Note the 2026 context**: The book is written with awareness of the current AI-assisted exploit landscape. This isn't theoretical—the authors reference real frameworks (MiniScope, AgentScope, NanoClaw) and real attack patterns (Slopsquatting) emerging in production. - **Expect practical application in later chapters**: The excerpts cover foundational theory and threat framing. The book's promise is architecture-level guidance—constraining what AI systems can do, enforcing least privilege, and building observable, interruptible, containable systems. Later chapters should deliver on this. ## 【Coverage Limits】 This guide covers the foundational security principles and threat landscape framing from the opening and early-middle portions of the book (approximately the first 47%). The excerpts do not cover the later chapters' specific architectural patterns, implementation details, or case studies for securing agentic systems—those will require reading the full book. ##
Page 3
ditions are also available for most titles (https://oreilly.com). For more information, contact our corporate/institutional sales department: 800-998-9938 or...
View in text
Page 11
ial impact due to a cyber event over the next three years.”. That is great, but it doesn’t give us any mental models or tools to actually reduce negative cyb...
View in text
Page 14
er the next several years, however, the environment evolved. New microservices were deployed, third-party integrations were added, and development teams requ...
View in text
Page 19
ries of dark rooms, or even a series of connected buildings. In these buildings there are tons of boxes of information, but you need access to the rooms and ...
View in text
Excerpt 5
the situation plans and controls may be subject to various regulatory frameworks, so why not factor those into the planning stage early. Large projects may a...
View in text
Excerpt 6
and inefficient unless the information being fed to them is carefully organized. Research on long-context performance has repeatedly shown that models do not...
View in text
Excerpt 7
advise colleagues against purely AI generated code. I find that AI generated code, if left unchecked, becomes increasingly hard for humans to contribute to o...
View in text
Excerpt 8
through adversarial inputs. Claude Code’s harness natively introduces these HITL controls as part of their default tool suite, but it gives the user the opti...
View in text
Tags
AI categories
CybersecurityBackendCloud Native
Publish Year: 2027
Language: English
File Format: PDF
File Size: 3.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…