
An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.
Train. Break. Defend. AI Systems.
An open-source platform for AI security training, red/blue teaming, CTF, benchmarking, and research. Runs 100% locally. No cloud, no paid APIs, no data leaves your machine.
GPU is optional. Ollama runs on CPU but inference will be slow without one.
git clone https://github.com/sonuoffsec/DVAP
cd DVAP
cp .env.example .env
docker compose up -d
Open http://localhost:8080 once all containers are healthy. First run takes 30-60 seconds.
DVAP is an open-source AI security research, training, benchmarking, and red teaming platform designed to help security professionals, AI engineers, researchers, students, and organizations understand how modern AI systems fail and how to defend them.
Built for the AI era, DVAP provides intentionally vulnerable AI applications, agents, RAG systems, MCP integrations, and domain-specific environments that can be attacked, analyzed, benchmarked, and secured.
Unlike cloud-based AI playgrounds, DVAP runs entirely on your machine.
No cloud. No subscriptions. No API costs. No vendor lock-in.
Modern AI applications introduce entirely new attack surfaces:
Yet there is no single platform that allows researchers to safely learn, practice, benchmark, and validate these attacks in one place.
DVAP aims to become the definitive open-source platform for AI security education, research, and experimentation.
| DVAP | DVWA | HackTheBox | Gandalf (Lakera) | Blog Posts / Papers | |
|---|---|---|---|---|---|
| AI-specific vulnerabilities | Yes | No | Partial | Partial | Yes (theory only) |
| Local, no cloud | Yes | Yes | No | No | N/A |
| 15 dedicated AI labs | Yes | No | No | No | No |
| LLM benchmark engine | Yes | No | No | No | No |
| CTF with flags | Yes | Yes | Yes | No | No |
| OWASP LLM Top 10 coverage | Full | No | Partial | Partial | Varies |
| MITRE ATLAS mapping | Yes | No | No | No | Varies |
| Report generation | Yes | No | No | No | No |
| Research workspace | Yes | No | No | No | No |
| Agent and MCP security | Yes | No | No | No | No |
| Free and open source | Yes | Yes | Partial | No | Yes |
DVAP is one of the first platforms to combine hands-on AI attack labs, local LLM benchmarking, CTF challenges, and professional reporting in a single self-hosted environment.
AI Security Labs 15 intentionally vulnerable labs covering real-world AI attack techniques.
Research Workspace Inspect prompts, memory, tool calls, retrieved documents, agent actions, and attack chains.
Security Benchmarking Evaluate local and external models against AI security attack suites.
Capture The Flag (CTF) Learn AI security through guided challenges, flags, hints, and walkthroughs.
Reporting Engine Generate professional findings and benchmark reports mapped to OWASP LLM Top 10, MITRE ATLAS, CWE, and CVSS.
100% Local Run everything on your own machine. Your prompts, data, findings, and experiments never leave your environment.

⚗️ AI Security Labs 15 containerized vulnerable AI environments across every major attack class |
🚩 CTF Challenges Flags, hints, and walkthroughs mapped to OWASP LLM Top 10 and MITRE ATLAS |
📊 Benchmark Center Evaluate local LLMs against prompt injection, jailbreak, and data exfiltration suites |
🔬 Research Workspace Full trace recording of prompts, memory, tool calls, and agent behavior |