Research Workloads

Workloads are the structured research tasks, labs and exercises running on OMEGA Core. Each workload produces documented findings — published in the Journal, reflected in the Research pages, and fed back into the platform as improved tooling, configuration or security controls.

Workloads are not tutorials. They are practical engineering investigations conducted on live infrastructure with real models, real data and real security implications.

In Progress

GIAC AI Platform Security (GAIPS) — 12-Week Lab Programme

July – September 2026

A structured twelve-week programme of hands-on security research aligned to the eight GAIPS knowledge domains. OMEGA Core is the practical lab environment throughout — all labs are conducted on the live platform, not against simulated or sandboxed systems. Findings are documented as they emerge.

Eight domains, twelve weeks. Each domain produces at least one documented lab finding.

01

AI and LLM Foundations

Capabilities, limitations and attack surfaces of generative AI systems. Model inventory, context windows, hallucination behaviour and prompt-level attack surface mapping.

02

AI Application Architecture

GenAI application security best practices, supply chain risk and integration-layer vulnerabilities. FastAPI surface assessment, model provenance audit.

03

AI Infrastructure Security

Security risks of hosting GenAI workloads. Container hardening, network exposure, least privilege across Docker stacks and Ollama LAN binding threat model.

04

AI Risk Management

Threat modelling methodologies and strategic risk planning. STRIDE/PASTA threat model for OMEGA Core. NIST AI RMF and EU AI Act risk classification applied to the platform.

05

Knowledge Augmentation and Retrieval

RAG architecture security, vector database risk and retrieval pipeline vulnerabilities. Indirect prompt injection via retrieval, Qdrant access controls, data poisoning evaluation.

06

Model Customisation and Alignment

Fine-tuning, moderation controls and alignment security. Modelfile system prompt evaluation, llama-guard3 safety classification, guardrail bypass research.

07

MLOps and Pipeline Security

Model lifecycle operations, data workflows and MLSecOps controls. Model pull-to-deploy pipeline audit, inventory API integrity, operator script security.

08

Agentic Systems and AI Integrations

Inter-agent communication, context management and protocol-level security. Tool use threat modelling, context injection, privilege escalation in agentic workflows.

Each workload produces documented evidence. Findings are published in theJournal as engineering notes. Model-specific observations appear on the relevant Research pages. Security assessments and architectural decisions are recorded as ADRs in the repository.