Chapter 41
Prompt injection defence and AI security
The OWASP Top 10 for LLM applications, direct and indirect prompt injection, and data exfiltration. Building input screening in FastAPI, seeing why a blocklist alone is not enough, then layered defence: instructions kept apart from data, least-privilege tools and output validation.
40 minPython 3.12
Pro course
Python for AI Career is a Pro course
The OWASP Top 10 for LLM applications, direct and indirect prompt injection, and data exfiltration. Building input screening in FastAPI, seeing why a blocklist alone is not enough, then layered defence: instructions kept apart from data, least-privilege tools and output validation.
The Python course is free and complete — this course is not made of anything taken out of it. Every chapter of a Pro course runs the full six steps:
- Encounter — Meet the problem before the definition — what cannot be done without this.
- Understand — Build the mental model: what Python actually does, and why this way.
- Worked — A complete example with its real output — run, not imagined.
- Predict — Say what happens before running it. A wrong prediction teaches more than a right one.
- Apply — Write it and run it on your own machine. Reading it is not the same as doing it.
- Stretch — Ten questions from easy to hard. The last ones are difficult on purpose.