AI Security

Gain practical insights into AI security and risk. Learn how AI vulnerabilities can be exploited and discover effective strategies to protect AI infrastructure, systems and data.

Start your continuing education on 16 November 2026.

Factsheet

  • Degree/Certificate Short Advanced Studies (SAS) in AI Security
  • Duration 5 days
  • Schedule Week 47, 16.–20.11.2026
  • Application deadline Up to 1 month before the start of the course
  • ECTS credits 4 ECTS-Credits
  • Costs CHF 2’800
  • Teaching language English
  • Location Biel, Aarbergstrasse 46
  • School School of Engineering and Computer Science

Content + Structure

Students will receive a practical introduction and overview to the topic of AI security and risk.

Short Advanced Studies (SAS)

Short Advanced Studies (SAS) are courses that take 30 to 160 hours (1 to 9 ECTS – can be credited towards DAS or MAS). Participants acquire in-depth, industry-relevant insights and skills on current topics in a short space of time. Students who do not wish to take SAS competency assessments are awarded a course certificate (no ECTS in that case).

Do you have any questions?
FAQ: a short and handy guide to BFH’s Short Advanced Studies (SAS)​​​​​​​

Portrait

The adoption of artificial intelligence in business is growing rapidly, leading to new challenges and opportuni-ties in cyber security. This five-day course provides participants with an introduction to the skills needed in the field of AI security, incorporating academic papers, technical reports, and other relevant resources throughout the course. The curriculum is organized into five parts:

  1. Foundations: Participants will explore the AI lifecycle and understand the unique security challenges presented by its probabilistic nature.
  2. Threat Landscape: Strategies for penetration testing and defending AI models, and the complexities involved in “patching” them.
  3. Advanced AI Threats: Examination of sophisticated threats such as data poisoning and the im-plications of external connections via the Model Connection Protocol (MCP).
  4. AI & Security incidents: Overview of investigating incidents involving AI systems, and how AI systems can help security investigations.
  5. Governance and Human-AI Interaction: Discussion of the importance of policy, user dynamics, and the risks of over-reliance on AI, along with methods to enhance safety in human-AI interactions.

Career opportunities

  • AI Security Analyst: Assessing and mitigating security risks in AI systems.
  • AI Security Architect: Designing secure architectures for AI applications.
  • Data Scientist with a focus on Security: Integrating security best practices into machine learning workflows.
  • AI foundations and attack surface
  • AI threat Landscape
  • Attacking and defending AI models
  • AI & Security incidents
  • Governance and Human-AI Interaction

AI foundations and attack surface

  • AI fundamentals: Machine Learning, Deep Learning, and Generative AI. How LLMs predict the next to-ken, and why that matters for security.

  • “Black box” problem: Understanding non-determinism and the lack of explainability.
  • Attack surface: Where things go wrong: data poisoning, model theft, and supply chain vulnerabilities

AI threat Landscape

  • Adversarial Machine Learning (AML): How some noise can fool a classifier, and real-world impact on systems like autonomous vehicles.
  • LLM-Specific Threats: Prompt Injection and Jailbreaking, plus advanced techniques like the Crescendo Attack.
  • Intro to MCP: the standard that allows to connect AI models to external data and tools.
  • Examples of threats: prompt injection via data, the “Confused Deputy” problem.

Attacking and defending AI models

  • Why “patching” a model is hard? Look at the current state of defensive and offensive approaches.
  • Lab: workshop where students will try to “break” AI models with the techniques learned.

AI & Security incidents

  • How to investigate and detect a compromised model?
  • Analyzing prompt logs, model checksums, vector database states, and “thought chains”.
  • Leveraging AI for automating forensic tasks and accelerating analysis.

Governance and Human-AI Interaction

  • Security is also about policy, people, and how they interact with AI.
  • Why is it a problem if humans trust AI too much? How to design it for safety?

A multiple-choice test will be conducted to evaluate participants’ proficiency in the course material. Students who prefer not to provide proof of proficiency will still receive a course certificate upon completion.

Students who do not wish to provide proof of proficiency will receive a course certificate.

Andrea Palmieri
Threat Intelligence Analyst
Switch

Degree + Title

Short Advanced Studies (SAS) «AI Security»

Requirements + Admission

Find out which professionals this continuing education program is designed for and what requirements you need to bring with you.

Requirements

This course is designed for beginners in the field of AI security. Familiarity with basic AI concepts is assumed, AI security and risk knowledge is not required, but it will enhance understanding of the course content. Participants are expected to have:

  • Basic IT security knowledge: understanding of common web vulnerabilities and IT terminology
  • Basic AI knowledge: understanding of models and prompts
  • A laptop or notebook with internet access for course activities

Target audience

This course is designed for staff and managers in security, IT, and operations roles who are interested in the fundamentals of AI security. In addition, AI developers and project leaders can benefit. It is especially relevant for individuals with a technical background seeking to understand the current landscape of AI security practices.

Course guidance

Do you have questions about continuing education? We will be happy to answer your questions.

Course guidance

Choosing a basic or continuing education programme is an important decision when planning your professional career. We will be happy to answer your questions and clarify your personal requirements for the desired continuing education during an individual consultation.

Location + Infrastructure

These Short Advanced Studies are held on site at Aarbergstrasse 46 in Biel/Bienne.

Switzerland Innovation Park Biel/Bienne (SIPBB)

A location with many advantages

  • Classrooms within two minutes walking distance from Biel/Bienne railway station
  • Ideal train connections from Bern’s main railway station (every 15 minutes) and from Bern Wankdorf (every 30 minutes)
  • State-of-the-art infrastructure in the new SIPBB building
  • Various catering options in the immediate vicinity
  • Innovation and networking events

And that’s not all! Biel/Bienne is…

  • an innovation hotspot,
  • a university city,
  • an industrial and service city with numerous major players in the watchmaking, mechanical engineering, precision engineering and medical technology industries and major representatives of the communications and telecommunications sectors,
  • bordered by Lake Biel and its wide range of sports and leisure facilities,
  • a city that embodies bilingualism,
  • a town with a vibrant cultural life.

Biel Aarbergstrasse 46 (Switzerland Innovation Park Biel/Bienne)

Biel, Aarbergstrasse 46

Bern University of Applied Sciences

Engineering and Computer Science
Switzerland Innovation Park Biel/Bienne
Aarbergstrasse 46
CH 2503 Biel

Bern University of Applied Sciences

Engineering and Computer Science
Switzerland Innovation Park Biel/Bienne
Aarbergstrasse 46
CH 2503 Biel