📚 Series: AI Red Teaming — Chapter 1

🏷️ Tags: LLM Fundamentals Tokenization Embeddings Attention Inference Pipeline AI Agents

⏱️ Level: Beginner → Intermediate

I came into AI security from web app pentesting and bug bounty, and honestly my first instinct was to treat an LLM like any other target — find the injection, pop a shell. It doesn't work like that, and this chapter is the mental reset that made everything after it click for me. If you skip the fundamentals you'll spend weeks throwing payloads that were never going to land. So bear with the theory here — every attack in the later chapters comes straight back to something on this page. 🧠


📌 What you'll get out of this one


1️⃣ First, the only AI history you need

Humans learn, understand, and decide. AI is our attempt to copy that in machines. You'll hear three tiers thrown around:

Type What it means Reality
Narrow AI (ANI) Great at one thing ✅ This is everything today — ChatGPT, Gemini, Claude
General AI (AGI) Human-level across tasks ❌ Not here yet
Super AI (ASI) Beyond human ❌ Sci-fi for now

💡 Keep this in your head: the thing you're attacking is narrow AI — a very confident pattern-matcher. It doesn't "understand" you. That single fact is why half our tricks work.

The lineage in one breath: ML (feed data, learn patterns) → deep learning (stacked neural layers) → NLP (make it handle language) → transformers (2017), the architecture that finally understood context and could process a whole sentence in parallel. LLMs are just big transformer models. If the LLM is Iron Man's suit, the transformer is the arc reactor. 🦾


2️⃣ 🔬 What's really going on inside (the part that matters)