UMBC logo

CMSC 491/691 Applied AI for Cybersecurity

Through paper readings, class discussions, and a course project, this course explores the application of AI to various domains of cybersecurity.

InstructorProf. Clement Fung
MeetsTues & Thurs, 9:30-10:45 AM
LocationEngineering, Room 231

Overview

Course Description

This course focuses on the intersection of two trends:
  1. Computing technology is ubiquitous. Banks, transportation networks, power grids, social media, and even the internet itself all rely on complex computer algorithms, systems, and infrastructure. As the world continues to become more and more interconnected, it becomes increasingly important to ensure that these systems operate correctly, even in the presence of malicious actors.
  2. Since computing technology is used and deployed across many contexts, the data collected and generated by such systems has also become ubiquitous. AI, which has become increasingly prevalent and powerful, brings the potential to leverage such data for automated insights to help improve cybersecurity. In particular, such data can be used to help defend and secure computing technology from adversaries (and often, such data can help adversaries too).
This course covers topics at the intersection of AI and cybersecurity, with a focus on how AI can be applied to improve the cybersecurity of modern computing systems. This course covers the intersection of AI with a broad selection of cybersecurity topics, such as network security, systems security, usable security, and more. To do so, this course will involve reading, reviewing, and discussing recent research papers in each of these respective areas. This course provides a general overview of AI and cybersecurity research, and serves as a foundation for those looking to do research in these areas.

Learning Objectives

After completing this course, students should be able to:

Logistics

The class will meet Tuesdays and Thursdays from 9:30am-10:45am in Engineering 231.

Classes primarily consist of two types: "Lectures", which will be led by the instructor and focus on covering background topics, and "Discussions", which will be led by students and consist of discussions of recent research papers in AI and cybersecurity. Before each "Discussion" session, students are expected to read the assigned research papers, write and submit reviews for these papers, and lead or participate in in-class discussions about these research papers.

The course will include two homework assignments. These homework assignments will consist of lightweight coding tasks and will focus on background topics covered in lectures during the first half of the course. The goal is to help students familiarize themselves with code implementations for AI and cybersecurity before they start working on their course projects.

This course also contains a project component. Students will be expected to form small teams of 2-4 members and conduct a small research project in the areas of AI and cybersecurity. When reasonable, students are encouraged to build on the contributions of research papers covered in class for their projects.

Grading

Tentatively, final grades will be weighted by the following components:

Course Schedule

📢 Course schedule is tentative. If there are any topics that seem of particular interest, I will try to incorporate them into the schedule.

The first half of the class will roughly focus on the fundamentals and applications. Classes will cover the basics of AI, cybersecurity, and how AI is used across various applications. The second half of the class will focus on implications of AI: topics such as usability, secure AI, and the rise of LLMs will be covered.
Date Topic Notes
Aug 25 Course Introduction
Aug 27 Lecture: Background on Cybersecurity
Sept 1 Lecture: Background on AI/ML
Sept 3 Lecture: Research Papers and Reviews
Sept 8 Discussion: Best Practices for ML + Cybersecurity
Sept 10 Discussion: Network Security HW1 out (Sept 11)
Sept 15 Discussion: Software Security
Sept 17 Discussion: Web and Application Security
Sept 22 Discussion: Smart Home Security
Sept 24 Discussion: Cyber-Physical Systems (CPS) Security HW1 due (Sept 25)
HW2 out (Sept 25)
Sept 29 Discussion: Scams and Phishing
Oct 1 Discussion: Authentication
Oct 6 Discussion: LLMs and Agents
Oct 8 Activity: Project Brainstorming and Team Matching HW2 due (Oct 9)
Oct 13 No Class - Fall Recess
Oct 15 Discussion: Humans vs AI
Oct 20 Activity: Meet with Project Teams Project Proposals due (Oct 21)
Oct 22 Lecture: Explainable AI (XAI) for Security
Oct 27 Discussion: XAI for Security
Oct 29 Lecture: Attacking ML and AI
Nov 3 Discussion: Attacking ML (Inference)
Nov 5 Discussion: Attacking ML (Supply Chain)
Nov 10 Activity: Midpoint Presentations
Nov 12 Discussion: Attacking ML (Privacy)
Nov 17 Discussion: Human Factors Challenges
Nov 19 Discussion: Organizational Challenges
Nov 24 No Class - Class Recess
Nov 26 No Class - Thanksgiving
Dec 1 Final Project Presentations
Dec 3 Final Project Presentations
Dec 8 Course Closing Project Reports due (TBA; during exams period)

Policies


Attendance and Remote Participation

In-class attendance is strongly encouraged. For students that require special accommodations, we will accommodate remote participation for lectures, discussions, and activities. (Details TBD)

Late Submissions

Due dates and times for homework assignments and paper reviews are firm. If you anticipate any issues, please discuss with me sufficiently advance. Otherwise, late submissions will be penalized by 25% for each day they are late.

Accommodations for Students

If you have a disability and have an accommodations letter from the Office of Disability Access and Resources (DAR), I encourage you to discuss your accommodations and needs with me as early in the semester as possible. I will work with you to ensure that accommodations are provided as appropriate. If you suspect that you may have a disability and would benefit from accommodations but are not yet registered with DAR, I encourage you to contact them. More information can be found here: https://sds.umbc.edu/

Academic Integrity

This course has a zero tolerance policy on plagiarism and cheating. UMBC's policy on academic integrity will be strictly enforced: https://academicconduct.umbc.edu/

The use of generative AI tools for completing homework assignments and paper reviews is strongly discouraged. When appropriate, the use of generative AI tools for projects may be permitted; please contact the instructor to discuss.

Wellness

The expected workload for this course is 12 hours per week, although the workload may vary week-to-week based on deliverables. Please make sure you plan accordingly and stay ahead of the course materials. If you have any concerns or questions about the course or its materials, the course instruction team is available at regular office hours to help address any concerns. We are here to help. If you or anyone you know is experiencing high academic stress, we strongly encourage you to seek support with Retriever Integrated Health: https://health.umbc.edu/counseling-services/counseling/

Diversity

This course has a zero tolerance policy on bias, discrimination, and misconduct. Any discrimination or misconduct on the basis of race, gender, sexuality, religion, socioeconomic status, etc. will not be tolerated. Please refer to the university policy for more information: https://ecr.umbc.edu/discrimination-policy/