Skip to content

Introduction to Data Security Practicum

This course provides a comprehensive introduction to the security and privacy of machine learning systems. You will learn to attack, defend, and audit AI models through practical labs organized into 8 thematic modules.

Instructors & Staff

  • Instructor: Prof. Lendák Imre
  • Teaching Assistant: Ahmed F. Lagha

Lab Curriculum

Module Lab Topic Notebook
1. Foundations 1 DNN Training & Robust Model Baselines Open In Colab
2. Input Manipulation 2 Evasion Attacks (FGSM, PGD) Open In Colab
3. Data Poisoning 3a Label Flipping Attacks Open In Colab
3b Backdoor & Trigger Injection Open In Colab
4. Model Poisoning 4a Model Trojans & Supply Chain Attacks Open In Colab
4b Trojan Detection & Certified Defenses Open In Colab
5. Availability 5a Sponge Attacks & Resource Exhaustion Open In Colab
5b Sponge Attack Defenses Open In Colab
6. Confidentiality 6a Membership Inference Attacks Open In Colab
6b Model Inversion & Feature Reconstruction Open In Colab
7. Synthetic Data 7 Tabular Synthetic Data (VAE, GAN) Open In Colab
8. Defenses 8a Differential Privacy & DP-SGD Open In Colab
8b Federated Learning & Adversarial Training Open In Colab

Learning Outcomes

Skill Description
Understand Fundamental concepts of machine-learning security and privacy
Implement State-of-the-art attacks (Evasion, Poisoning, Inversion) in PyTorch
Evaluate Model robustness using quantitative metrics and certified bounds
Design Multi-layered defense strategies (DP, FL, Robust Training) for production
Generate Privacy-preserving synthetic data for sensitive domains (healthcare, finance)

References & Acknowledgments

  • unica-mlsec/mlsec — Prof. Battista Biggio (University of Cagliari)
  • Practical Data Privacy — Katharine Jarmul (O'Reilly, 2023)
  • Adversarial Machine Learning — Goodfellow, Biggio et al. (Cambridge University Press)