IIT Delhi - Certificate Programme in Cybersecurity & AI

Master cybersecurity and AI security, together. Built for professionals securing the modern enterprise. Most programmes teach one or the other. This one teaches both cybersecurity and AI security as one discipline.

banner image

About IIT Delhi

IIT Delhi: Legacy That Nurtures Excellence

India's Premier Technical Institution

Established in 1961 by an Act of Parliament, IIT Delhi is one of India's Institutes of National Importance. For over six decades, it has shaped engineers, researchers, and leaders who drive innovation across industry, academia, and policy worldwide.

National and Global Standing

Ranked #2 in India by NIRF 2025 (Ministry of Education) and ranked #118 as per QS World Rankings 2027.

Research That Drives Real-World Impact

Known for high-impact research and strong global citation performance, IIT Delhi plays a defining role in advancing artificial intelligence, cybersecurity, computing, and emerging technologies.

image

Cybersecurity Foundations To AI Security Mastery, Led by IIT Delhi CEP

Slide 1 of 1

100% Live Online, Faculty-Led Sessions

A Production-First Programme

5 Frontier Agentic Attack Surfaces

India Regulatory Depth

One Integrated Capstone + IEEE Report

Optional Campus Immersion at IIT Delhi

Certification

IIT Delhi: A Credential That Carries Weight

Recognised Academic Credential

Earn an e-Certificate of Completion from IIT Delhi CEP - the statutory body for issuing certificates at IIT Delhi. Tamper-proof e-Certificate downloadable from the CEP IIT Delhi portal. Verifiable by employers via QR code.

Academic Credibility with Industry Relevance

An IIT-issued credential that signals rigorous training and readiness for advanced AI security roles - from BFSI to GCC to consulting.

IIT Delhi Alumni Network Access

Connect with IIT Delhi's vast professional network of engineers, researchers, and leaders across technology and industry.

image

The Curriculum for Security Engineers Who Own the AI Layer. Design Systems, Defend AI, Ship to Production.

5

Modules

1

Capstone

78

Live Hours

Threat-first, build-second - You learn to attack AI systems before you defend them, so defences are principled, not reactive

MLSecOps & DevSecOps Pipelines - ModelScan, Sigstore, AI-BOM, OPA policy-as-code, Falco runtime detection. Production depth, not theory.

5 Frontier Agentic Attack Surfaces - Multimodal jailbreaks, MCP prompt injection, memory poisoning, toolcalling exploitation, model hub supply chain. Unique in India

India Regulatory Compliance (As Artifacts) - DPDP 2025, SEBI CSCRF 2024, RBI 2024 - you produce auditorready evidence packs, not concept overviews.

AI Security & Governance Frameworks - NIST AI RMF, ISO 42001, EU AI Act, FAIR Monte Carlo risk quantification presented as a board-level executive narrative.

Evaluation as Engineering Practice - Before/after robustness delta. PyRIT, Garak, PromptBench quantified outcomes. You measure, not just demo.

imagesrc

The Complete Curriculum

A Structured Path to AI Security Mastery

Foundations for AI and Cybersecurity

BRIDGE

2 weeks


Topics covered

Python for security automation: integrating NumPy, Pandas, and Jupyter with security data pipelines; API interactions for threat intelligence feeds

ML workflow integration: connecting model training to security evaluation; class imbalance strategies applied to phishing and malware datasets

Security tools setup: Wireshark, Nmap, Burp Suite basics, Kali Linux, Docker, Git workflow

Cloud integration: confirming console access across AWS/Azure/GCP; verifying IAM roles and permissions for subsequent module labs

MITRE ATT&CK introduction: SOC workflow understanding

Cybersecurity Foundations, Threat Modeling, and Threat Landscape

Module 1

3 weeks

Topics covered

Global and India threat landscape: APTs, ransomware, supply chain attacks, UPI fraud, digital arrest scams

MITRE ATT&CK framework deep-dive, cyber kill chain, threat intelligence fundamentals

Threat modeling (STRIDE): assets, trust boundaries, abuse cases, mitigation mapping

Identity attacks and defences: OAuth/OIDC flows, JWT misuse, session fixation, refresh token theft, SSO/SAML basics

Vulnerability management, CVSS 4.0, and security operations fundamentals

Skills acquired

AI/ML for Security and Detection Engineering

Module 2

5 weeks

Topics covered

Security data engineering: feature extraction from logs, handling extreme class imbalance

Machine learning for threat detection: malware classification, phishing detection, fraud detection

Security-grade evaluation: calibration, thresholding, cost-of-error analysis, failure modes

MLOps starter: experiment tracking, model registry basics, reproducibility discipline

Detection-as-code fundamentals: Sigma rule syntax, detection logic patterns mapped to ATT&CK

Detection testing: unit tests for rules, coverage analysis, and false positive analysis

SIEM architecture with Elastic Stack: focused log ingestion and correlation

Incident cockpit design: severity scoring, alert correlation, response recommendations

SOAR basics: playbook design principles and human-in-the-loop workflows

Optional self-paced: UEBA behavioural baselines; IR/forensics foundations

Adversarial ML, LLM Security, Agentic AI, and Frontier Attack Surfaces

Module 3

5 weeks

Topics covered

Agentic AI pipeline foundations: LangChain and LangGraph architecture, tool-calling patterns, MCP basics, agent memory, and decision chaining

Adversarial ML fundamentals: evasion, poisoning, and extraction attacks through MITRE ATLAS

OWASP LLM Top 10 (2025): Prompt Injection, Excessive Agency, Vector and Embedding Weaknesses

LLM security and secure RAG: prompt injection (direct and indirect), jailbreaking, data leakage, retrieval poisoning, and data exfiltration via retrieved documents

AI-specific incident response: model rollback, data poisoning forensics, and model integrity verification

LLM red teaming toolstack: PyRIT for automated red teaming, Garak for OWASP LLM Top 10 vulnerability scanning, and PromptBench for prompt robustness evaluation

Multimodal jailbreaks: Multi-Modal Linkage, perceptual transformation exploits, and Visual Scenario Hypnosis in vision-language models

Tool-calling exploitation: function call injection, tool chain exploitation, and parameter poisoning in agentic AI

MCP prompt injection: server-to-server trust override in Model Context Protocol environments

Memory poisoning: trigger-free single-shot poisoning via benign-looking content in long-context LLM agents

Model hub supply chain attacks: namespace hijacking, safetensors conversion exploitation, and detection tooling

MLSecOps, DevSecOps, and India Compliance

Module 4

4 weeks

Topics covered

Implement a DevSecOps + MLSecOps pipeline with policy-as-code enforcement (OPA), runtime detection (Falco), model signing (Sigstore), and AI-BOM generation (Apply)

Produce auditor-ready DPDP Rules 2025 compliance artifacts: breach notification workflow, Consent Manager integration, Data Fiduciary obligations checklist (Create)

Map an organisation's security controls to the SEBI CSCRF 2024 structured audit format, including RE classification tier assignment (Apply)

Document board-level IT risk accountability obligations under RBI Master Directions 2024 with a CERT-In notification playbook (Create)

AI Governance, Global Regulation, Risk Quantification, and Executive Communication

Module 5

4 weeks

Topics covered

AI governance frameworks: NIST AI RMF (Govern, Map, Measure, Manage) with artifact templates; ISO/IEC 42001 AI Management System controls and certification pathway; EU AI Act risk tier taxonomy mapped to NIST AI RMF categories

EU AI Act phased enforcement: Feb 2025 prohibitions active; Aug 2025 GPAI obligations; Aug 2026 high-risk AI (Annexes III/IV); India-facing implications for MNCs

Privacy engineering: privacy-by-design principles (ISO 29101) applied to AI systems; DPDP Rules 2025 mapping to privacy engineering controls

FAIR risk quantification: translating threat scenarios into financial loss distributions using Monte Carlo simulation; presenting output as a board narrative; risk appetite framing

AI ethics in security contexts: bias and fairness in threat detection models; dual-use dilemmas; explainability for forensics and regulatory auditability

Emerging threats and post-quantum readiness: AI-powered attacks, deepfake social engineering, synthetic media fraud detection in BFSI; NIST PQC standards (FIPS 203, 204, 205), hybrid systems, and migration planning

Build & Deploy an AI Security Solution

Capstone

3 weeks

Topics covered

The capstone is the programme's culminating deliverable. Each participant independently designs and builds a complete, production-grade AI security solution - ntegrating all modules - on a real problem they choose.

Projects are evaluated by a panel of IIT Delhi faculty on technical depth, real-world applicability, India regulatory alignment, responsible AI design, and quality of presentation.

Programme Coordinator

2

Instructors

THE CAPSTONE

Your Solution. Fully built. Rigorously defended.

Every programme ends with a submission. This one ends with a live IIT Delhi faculty panel - where you defend a complete AI security solution built from scratch, module by module, over 6 months.

6

Deliverables defended

3

Weeks of build + defend

78

Live hours

AI security threat model and attack surface map - STRIDE-based threat model with MITRE ATLAS mapping, trust boundaries, and a prioritised remediation roadmap

LLM red team engagement report - PyRIT, Garak, and PromptBench results with quantified before/after robustness delta and remediation evidence

Secure MLSecOps pipeline - live deployed - Production-grade CI/CD with ModelScan, Sigstore signing, AI-BOM, OPA policy-as-code, and Falco runtime detection

India regulatory compliance evidence pack - Auditor-ready artifacts for DPDP 2025, SEBI CSCRF 2024, and/or RBI Master Directions 2024

FAIR risk quantification + board narrative - Monte Carlo risk model translated into financial loss distributions with a board-level executive presentation

IEEE-format technical report - 8–12 page publishable-quality report documenting your solution, methodology, evaluation results, and findings

imagesrc

WHAT YOU WILL BUILD AND SHIP

Systems You Will Build & Ship

Not demos. Not slides. Every module ends with a working system artifact you have built, tested, and can deploy.

dots left
dots right
Image

What Will You Build?

See the practical work that has helped our learners land roles at top companies

Built for working professionals securing the modern enterprise

This programme is for professionals who already have technical depth in security or AI and need the other dimension - not for beginners.

Career Outcome

Roles this programme unlocks

AI Security Engineer

    LLM red teaming, adversarial ML defences, secure AI pipeline engineering

MLSecOps Engineer

    Secure CI/CD for AI, ModelScan, Sigstore, AI-BOM, policy-ascode

Detection Engineer

    ML-powered threat detection, Sigma rule authoring, SIEM engineering

AI GRC Manager

    NIST AI RMF, ISO 42001, DPDP 2025, SEBI CSCRF, EU AI Act compliance

AI Red Team Analyst

    Systematic LLM red team exercises, agentic attack surface evaluation

AI Security Architect

    FAIR risk quantification, board-level communication, AI governance leadership

Programme Fees & Instalment Schedule

    Total payable is approximately ₹1,40,000 + GST(18%) = ₹1,65,200.

    All Fees receipts will be issued by IIT Delhi CEP and can be downloaded from the CEP Portal.

Programme {Fees & Instalment Schedule}

Cybersecurity & AI Security

How To Apply

Eligibility

Bachelor's or Master's degree in with minimum 50% marks and familiarity with any programming language.  

upGrad Learner Support

Talk to our experts. We are available 7 days a week, 10 AM to 7 PM

text

Indian Nationals

text

Foreign Nationals