Free, Original AI Red-Teaming Education
Learn to attack and defend AI systems through hands-on labs. 29 Reapers across 12 modules, from fundamentals to advanced exploitation.
What is Infirmary?
Infirmary is a free, open educational platform for learning AI security. Built by Xtrinel, it offers hands-on labs covering prompt injection, data poisoning, evasion attacks, privacy attacks, and agent exploitation.
The Reaperation
Infirmary's 29 labs are called Reapers. Each one teaches a specific attack technique through hands-on exploitation. Work through the Reaperation to master prompt injection, data poisoning, evasion attacks, and agent compromise.
Reapers span three difficulty levels: Easy (foundational concepts), Medium (multi-step attacks), and Hard (advanced exploitation chains). Each level builds on the last.
These are the same techniques VAAST and SentrinelNet are built to catch. Learn the attacker's playbook to defend effectively.
How VAAST and SentrinelNet Relate to the Curriculum
Many Infirmary labs can be solved manually with curl and notebooks. For those seeking faster iteration and automated testing, Xtrinel's offensive security tools integrate directly with the curriculum.
VAAST
Vulnerability Assessment for AI Security Testing
VAAST Free tier provides automated payload generation for prompt injection, encoding bypasses, and basic jailbreaks — covering techniques taught in Modules 4, 8, 9, and 10.
VAAST Pro adds the MCP Scanner for tool enumeration (Module 7), advanced RAG poisoning payloads (Module 4), and gradient-based evasion attack generation (Modules 9, 10).
Eight Offensive AI Security Agents
SentrinelNet's agents (Spectral, Crimson Hunter, Emerald Vaultkeeper, and others) are used in advanced labs to validate multi-step attack chains, privilege escalation paths, and agent-to-agent exploitation scenarios.
These agents map directly to Level 3 labs in Module 7 (Attacking AI - Application and System), providing real adversarial testing of hardened agent systems.
Infirmary labs remain free and fully functional without these tools. VAAST and SentrinelNet are optional accelerators for practitioners seeking automated workflows.
Learn more about VAAST and SentrinelNet →12 Curriculum Modules
Start with fundamentals and progress through advanced exploitation techniques
Fundamentals of AI
Build classifiers from scratch. Understand training loops, loss functions, backpropagation.
Applications of AI in InfoSec
Apply classifiers to security use cases: spam detection, anomaly detection, malware classification.
Introduction to Red Teaming AI
Overview of adversarial mindset for AI systems. Black-box vs white-box, threat models, attack surfaces.
Prompt Injection Attacks
Direct injection, role-play attacks, delimiter tricks, encoding obfuscation, RAG poisoning, escalation to RCE.
LLM Output Attacks
Force model to leak sensitive data from context, detect unintentional PII exposure.
AI Data Attacks
Label flipping, clean-label backdoors, supply-chain model poisoning. Training-time attacks.
Attacking AI - Application and System
RAG systems, agent architectures, tool/MCP abuse, privilege escalation, multi-step chains.
AI Evasion - Foundations
Understand local vs API models, deployment tradeoffs, why evasion matters.
AI Evasion - First-Order
Gradient-based adversarial examples (FGSM, I-FGSM, DeepFool) against white-box classifiers.
AI Evasion - Sparsity
Sparse perturbations (fewer pixels changed) using Jacobian saliency, ElasticNet.
AI Privacy
Membership inference attacks, DP-SGD as defense, privacy-accuracy tradeoff measurement.
AI Defense
Guardrail evasion techniques (obfuscation, homoglyphs), benchmark gaming, evaluation brittleness.
Ready to Start?
Sign in to track your progress and launch lab sessions