UMBC logo

CMSC 491/691 Applied AI for Cybersecurity

Through paper readings, class discussions, and a course project, this course explores the application of AI to various domains of cybersecurity.

InstructorProf. Clement Fung
MeetsTues & Thurs, 9:30-10:45 AM
LocationEngineering, Room 231

Overview

📢 Page is still under construction; details are tentative.

Course Description

This course focuses on the intersection of two trends:
  1. Computing technology is ubiquitous. Banks, transportation networks, power grids, social media, and even the internet itself all rely on complex computer algorithms, systems, and infrastructure. As the world continues to become more and more interconnected, it becomes increasingly important to ensure that these systems operate correctly, even in the presence of malicious actors.
  2. Since computing technology is used and deployed across many contexts, the data collected and generated by such systems has also become ubiquitous. AI, which has become increasingly prevalent and powerful, brings the potential to leverage such data for automated insights to help improve cybersecurity. In particular, such data can be used to help defend and secure computing technology from adversaries (and often, such data can help adversaries too).
This course covers topics at the intersection of AI and cybersecurity, with a focus on how AI can be applied to improve the cybersecurity of modern computing systems. This course covers the intersection of AI with a broad selection of cybersecurity topics, such as network security, systems security, usable security, and more. To do so, this course will involve reading, reviewing, and discussing recent research papers in each of these respective areas. This course provides a general overview of AI and cybersecurity research, and serves as a foundation for those looking to do research in these areas.

Learning Objectives

After completing this course, students should be able to:

Logistics

The class will meet Tuesdays and Thursdays from 9:30am-10:45am in Engineering 231.

Classes primarily consist of two types: "Lectures", which will be led by the instructor and focus on covering background topics, and "Discussions", which will be led by students and consist of discussions of recent research papers in AI and cybersecurity. Before each "Discussion" session, students are expected to read the assigned research papers, write and submit reviews for these papers, and lead or participate in in-class discussions about these research papers.

The course will include two homework assignments. These homework assignments will consist of lightweight coding tasks and will focus on background topics covered in lectures during the first half of the course. The goal is to help students familiarize themselves with code implementations for AI and cybersecurity before they start working on their course projects.

This course also contains a project component. Students will be expected to form small teams (requirements on team sizes TBD) and conduct a small research project in the areas of AI and cybersecurity. When reasonable, students are encouraged to build on the contributions of research papers covered in class for their projects.

Grading

Tentatively, final grades will be weighted by the following components:

Course Schedule

Course schedule is tentative. If there are any topics that seem of particular interest, I will try to incorporate them into the schedule.

The first half of the class will roughly focus on the fundamentals and applications. Classes will cover the basics of AI, cybersecurity, and how AI is used across various applications. The second half of the class will focus on implications of AI: topics such as usability, secure AI, and the rise of LLMs will be covered.
Date Topic Reading Notes
Aug 25 Course Introduction —
Aug 27 Lecture: Background on Cybersecurity —
Sept 1 Lecture: Background on AI/ML —
Sept 3 Lecture: Research Papers and Reviews —
Sept 8 Discussion: Best Practices for ML + Cybersecurity —
Sept 10 Lecture: AI for Network Security —
Sept 15 Discussion: AI for Network Security —
Sept 17 Lecture: AI for Software Security —
Sept 22 Discussion: AI for Software Security —
Sept 24 Lecture: AI for Cyber-Physical Systems (CPS) Security —
Sept 29 Discussion: AI for CPS Security —
Oct 1 Discussion: Usable Security —
Oct 6 Discussion: Malware Detection —
Oct 8 Discussion: Web and Application Security —
Oct 13 No Class - Fall Recess —
Oct 15 Activity: Project Brainstorming and Team Matching —
Oct 20 Activity: Project Meetings —
Oct 22 Discussion: LLMs and Agents —
Oct 27 Discussion: LLMs and Agents II —
Oct 29 Lecture: Explainable AI (XAI) —
Nov 3 Discussion: XAI for Security —
Nov 5 Lecture: Attacking ML —
Nov 10 Activity: Midpoint Presentations —
Nov 12 Discussion: Attacking ML (Inference) —
Nov 17 Discussion: Attacking ML (Privacy) —
Nov 19 Discussion: Attacking ML (Supply Chain) —
Nov 24 No Class - Class Recess —
Nov 26 No Class - Thanksgiving —
Dec 1 Discussion: Human Factors —
Dec 3 Discussion: Organizational Factors —
Dec 8 Final Project Presentations —

Helpful links