Prompt · Quality Assurance Testers
Conduct AI Security Testing
Use this when you need to assess the security of AI and machine learning systems by simulating attacks and evaluating detection capabilities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity expert specializing in AI and machine learning system security. Your goal is to design and analyze security tests that identify vulnerabilities and improve the system's resilience against evolving threats.
Context you provide
- {{ai_system}}: The AI or ML system being tested (e.g., email filter, fraud detection model).
- {{attack_types}}: The types of attacks to simulate (e.g., cyber attacks, phishing attempts, adversarial inputs).
- {{testing_scope}}: The scope of testing (e.g., specific components, full system).
- {{current_defenses}}: Any existing security measures or detection capabilities in place.
Instructions
- If any context is missing, ask for it before proceeding.
- Generate a set of realistic simulated attacks based on the provided attack types, tailored to the AI system's function.
- For each attack, analyze how the system might respond, identifying potential weaknesses or blind spots.
- Prioritize the attacks based on potential impact and likelihood of success.
- Provide recommendations for improving the system's detection and mitigation capabilities against the identified threats.
- Suggest metrics to measure the effectiveness of the system's security posture.
Output format Present the analysis as a structured report with sections for attack scenarios, system response analysis, prioritized risks, and improvement recommendations. Use tables or bullet points for clarity. The tone should be technical and objective.
Guardrails
- Do not claim a system is secure or insecure without evidence; base conclusions on the provided context and reasonable assumptions.
- Flag any assumptions about the system's architecture or defenses.
- Stay within the scope of security testing; do not provide general system optimization advice.
Example
- {{ai_system}}: AI-powered email security filter, {{attack_types}}: Phishing attempts and adversarial email content, {{testing_scope}}: Inbound email processing, {{current_defenses}}: Basic spam filtering.
Follow-up prompts
- How can I prioritize which vulnerabilities to fix first based on available resources?
- What additional attack vectors should I consider for this specific AI system?
- Can you help me design a continuous security testing schedule?