AI Security Labs & CTFs
Hands-on practice environments for learning AI/LLM security through capture-the-flag challenges, vulnerable applications, and interactive labs.
Prompt Injection & Jailbreaking
Learn to identify and exploit prompt injection vulnerabilities
Gandalf by Lakera
FreeLakera
Classic LLM CTF where you must extract a secret password through escalating prompt injection techniques across 7 increasingly difficult levels.
Gandalf Agent Breaker
FreeLakera
Advanced version of Gandalf focusing on AI agent security. Exploit tool-using agents and multi-step reasoning vulnerabilities.
Prompt Airlines (Wiz)
FreeWiz
Navigate through a fictional airline booking system to exploit LLM vulnerabilities. Great for understanding real-world application contexts.
Tensor Trust
FreeTensor Trust
Competitive prompt injection arena where you both attack other players' prompts and defend your own. Learn offense and defense simultaneously.
GPT Prompt Attack
Free43z
Simple beginner-friendly prompt injection challenges. Perfect for those just starting their AI security journey.
HackMerlin
FreeHackMerlin
Interactive prompt injection challenges with a fantasy theme. Progress through different realms by defeating AI guardians.
Immersive Labs Prompt Injection
FreeImmersive Labs
Professional training platform with guided prompt injection exercises. Includes detailed explanations and learning objectives.
Comprehensive Testing Platforms
Full-featured platforms covering multiple vulnerability types
Dreadnode Crucible
FreeDreadnode
Advanced AI security testing platform with real-world scenarios. Covers prompt injection, data extraction, and more.
HackTheAgent
FreeHackTheAgent
Comprehensive platform for testing AI agent vulnerabilities. Includes tool abuse, privilege escalation, and memory attacks.
PortSwigger LLM Labs
FreePortSwigger
High-quality LLM security labs from the creators of Burp Suite. Professional-grade training with detailed solutions.
Gray Swan AI Arena
FreeGray Swan
Competition-style AI security challenges with cash prizes. Test your skills against other researchers.
RedTeam Arena
FreeRedTeam Arena
Crowdsourced red teaming platform where you can test LLMs and earn rewards for finding vulnerabilities.
RAG & Data Extraction
Labs focused on RAG security and data exfiltration techniques
MyLLMBank
FreeArcanum
Practice extracting sensitive financial data from a RAG-powered banking assistant. Learn about indirect prompt injection.
MyLLMDoc
FreeArcanum
Attack a document-processing LLM system. Extract confidential information from uploaded documents through the AI.
Self-Hosted Labs
Labs you can run locally for deeper learning and customization
OWASP FinBot CTF
FreeOWASP
Official OWASP vulnerable LLM application covering all OWASP LLM Top 10 vulnerabilities in a financial context.
Broken LLM Integration App
FreeCommunity
Intentionally vulnerable application demonstrating common LLM integration mistakes. Great for learning secure coding practices.
PwnGPT CTF
FreeCommunity
Python-based CTF environment for practicing prompt injection attacks. Easy to set up and customize.
PromptMe OWASP
FreeCommunity
Comprehensive vulnerable LLM application aligned with OWASP LLM Top 10. Includes both challenges and solutions.
Auto Parts CTF
FreeArcanum
CTF scenario involving an auto parts shop chatbot. Practice customer service AI exploitation.
Professional Secure AI Bot
FreeNSIDE
Test your skills against a hardened AI assistant. Learn what good defenses look like and how to bypass them.
New to AI Security?
Start with beginner-friendly labs like Gandalf or GPT Prompt Attack to learn the fundamentals of prompt injection. Progress to intermediate platforms like PortSwigger Labs for comprehensive training.