2026 cohorts are now open across all programs · See the programs
Professional certificationCAIS-01

Certified Professional in AI Security

Two months · Red team and blue team · Live labs

An intensive two-month programme that turns cybersecurity professionals into AI security specialists — teaching the attacks first, because a defence you have never had to get past is not a defence you can trust.

8 wk
Program length
2
Red and blue team
5+
Security toolkits
20
Seats per cohort
Security engineer working at a server rack
Live lab — adversarial robustness testing
Programme overview

Attack it, then defend it

Eight components structure the programme, from threat modelling across the ML lifecycle through hands-on adversarial attacks and the defences that stop them.

Offensive security masterclass
Hands-on adversarial attack techniques and red team methodologies.
Practical attack portfolio
Execute simulated adversarial attacks, then build the defensive frameworks.
Industry-standard tooling
Adversarial Robustness Toolbox, CleverHans, Foolbox, ModelScan and more.
CTF and red team training
AI-focused Capture The Flag competitions and structured red team exercises.
World-class faculty
Former AI security researchers and penetration testing specialists.
Career acceleration support
Dedicated career services for a highly specialized and under-supplied role.
Who this program is for

Three entry profiles

Security professionals at a technical seminar
Faculty-led cohort instruction
Cybersecurity professionals
  • Security engineers specializing in AI and ML defence
  • Penetration testers expanding to AI attack vectors
  • Security analysts adding AI threat intelligence
  • Incident responders handling AI security breaches
Technical and leadership roles
  • Security architects designing AI security strategy
  • CISO teams building enterprise AI defences
  • MLOps engineers securing ML pipelines
  • AI developers building inherently secure systems
Advanced specialists
  • Red team specialists targeting AI systems
  • Blue team defenders protecting ML models
  • Government and defence security professionals
  • Threat researchers studying AI vulnerabilities
Why Heisenberg

The Institute in numbers

|ψ⟩ = α|0⟩ + β|1⟩
50+
Partners
Universities, research institutes, and AI companies across academia and industry.
8 wk
Hands-on labs
Attack simulation and defence implementation against live models.
18
Industry experts
Practitioners shaping curriculum design and providing mentorship.
Skill acquisition
Faster mastery through guided practice and immediate application.
24/7
Learning access
Always-available platform and a community of peers, mentors, and alumni.
Applied training

Learn AI security by breaking real models

Every offensive technique is executed in a lab against a working model, and every defensive module is measured against the attacks from the phase before it. Nothing is taught as theory that can be demonstrated as practice.

Attack simulation portfolio — penetration tests and adversarial campaigns you can show an employer.
Defensive frameworks — adversarial training, input transformation, watermarking and runtime monitoring.
Red and blue team exercises — AI-focused CTF competitions run against the cohort's own hardened models.
Participant working through a lab exercise
Cohort at an industry session
Learning path

Structured in three phases

Eight weeks: threat modelling, then offensive red team technique, then the defensive strategies and model hardening that answer them.

PHASE 01 · WEEKS 1–2
Foundations and threat modelling
  • ML lifecycle security: vulnerabilities from collection to inference
  • AI threat taxonomy across integrity, confidentiality and availability
  • Enterprise-level AI security risk assessment and threat modelling
  • The tool ecosystem: ART, CleverHans, Foolbox and test environments
  • Threat intelligence: attacker motivation, capability and attack surface
PHASE 02 · WEEKS 3–5
Offensive — red team technique
  • Adversarial evasion: FGSM, C&W, PGD and advanced perturbation
  • Data poisoning and backdoor attacks on training pipelines
  • Model extraction and inversion: IP theft and data reconstruction
  • Generative AI attacks: prompt injection, jailbreaking, LLM manipulation
  • Membership inference and training-data extraction
  • Custom attack development and systematic AI penetration testing
PHASE 03 · WEEKS 6–8
Defensive — hardening and response
  • Adversarial training, gradient masking and input transformation
  • Data security: anomaly detection, source verification, feature stores
  • Model IP protection: watermarking, fingerprinting, usage detection
  • Runtime monitoring: baselines, drift detection, anomaly alerting
  • Secure inference: API security, container hardening, secrets management
  • Differential privacy, federated learning and homomorphic encryption
  • AI incident response playbooks for attacks, failures and breaches
Certification

A credential earned against live models

Successful completion confers the Certified Professional in AI Security credential from the Heisenberg Institute.

Certified Professional in AI Security (CAIS)
Validates hands-on expertise in adversarial attack, model hardening and AI defence.
Attack simulation portfolio
Documented penetration tests and security frameworks built during the programme.
Elite career positioning
For AI security engineer, ML security architect and red team specialist roles.
CAIS certificate issued by the Heisenberg Institute
Security professional reviewing programme requirements
Eligibility

A selective intake of 20

This is an advanced programme. Phase 2 begins executing attacks in week three, which assumes you already understand the security fundamentals underneath them.

  • Statement of purpose demonstrating genuine interest in AI security and career goals
  • Five or more years of experience in information security or a related field, or
  • A bachelor's degree — or final-year standing — with an average of 50% or higher in cyber security or a related field, or
  • CISA, CISSP or CISM certification
Intake schedule

Monthly cohort commencement

The programme admits a cohort every month. Places are capped, so applying early is the surest way to secure the cohort you want.

All classes are held online only, owing to the high volume of applications. Live sessions run on Saturday and Sunday, 1:30–4:30 PM GMT.
Cohort
Application closes
Program starts
Status
CohortAugust 2026 Cohort
Application closesAugust 1, 2026
Program startsAugust 25, 2026
StatusClosed
CohortSeptember 2026 Cohort
Application closesSeptember 1, 2026
Program startsSeptember 25, 2026
StatusOpen
CohortOctober 2026 Cohort
Application closesOctober 1, 2026
Program startsOctober 25, 2026
StatusUpcoming
CohortNovember 2026 Cohort
Application closesNovember 1, 2026
Program startsNovember 25, 2026
StatusUpcoming
CohortDecember 2026 Cohort
Application closesDecember 1, 2026
Program startsDecember 25, 2026
StatusUpcoming
Programme fee
$1,499USD · full programme

Flexible payment options and corporate sponsorship support are available — contact the admissions team for details.

Bonus: the programme is delivered as live online masterclasses on Fridays and Saturdays, with recorded sessions and virtual lab access for everything you miss.
Your fee includes
  • Certified Professional in AI Security (CAIS) certification, awarded by the Heisenberg Institute for AI and Quantum Computing
  • Offensive and defensive masterclasses — live expert-led training in adversarial attack, model poisoning and ML system defence
  • A real-world attack simulation portfolio: penetration tests and security frameworks built against live AI and ML systems
Frequently asked questions

Before you apply

Are classes held online or on campus?
Online only. Live masterclasses run on Fridays and Saturdays, with recorded sessions and virtual lab access, so a missed session does not cost you the lab.
When do cohorts begin?
Cohorts commence every month. Applications close on the 1st and classes begin on the 25th. Applicants are encouraged to apply six to eight weeks ahead of the deadline.
Do I need an existing security background?
Yes. Phase 2 starts executing adversarial attacks in week three. Candidates typically arrive with five or more years in information security, a cyber security degree, or a CISA, CISSP or CISM certification.
Do I need machine learning experience as well?
Not to the depth of an ML engineer. Phase 1 covers the ML lifecycle from a security perspective, which is enough to attack and defend the systems in phases 2 and 3.
Are the attacks run against real models?
Yes — in an isolated lab environment provided by the Institute, against models the cohort trains. Techniques are never exercised against third-party systems.
What is the weekly workload?
Eight weeks is compressed. Expect the weekend sessions plus lab work during the week, with the CTF and red team exercises running across phases 2 and 3.
Are flexible payment options available?
Yes. Flexible payment plans and corporate sponsorship support are available — contact the admissions team for details.