Introduction to ML Security Research
Explore foundational machine learning security concepts focusing on system boundaries, threat modeling, and attack types. Understand how to distinguish adversarial behavior from ordinary errors and evaluate security claims. This lesson prepares you to build a structured threat model and assess defenses with an evidence-based approach, readying you for advanced ML security research.
We'll cover the following...
Prerequisites and learning outcomes
If you are looking for a comprehensive path into ML security, you are in the right place. This course is intended for developers, MLOps practitioners, and researchers who are new to security but already comfortable with how ML systems work, including training pipelines, model serving, and APIs. No prior security experience is required. Basic familiarity with threat modeling in traditional software security is helpful but entirely optional. We cover every security concept from the ground up and assume no prior security background.
By the end of this course, learners will be able to:
Draw a system boundary around an ML pipeline and write a structured, testable threat model for it.
Distinguish ordinary model error and distribution shift from deliberate adversarial behavior across poisoning, evasion, extraction, and privacy attacks.
Evaluate a security or robustness claim by its stated attacker assumptions, and design a defense-and-evaluation plan that survives adaptive scrutiny.
About this course
We designed this in-depth ML security curriculum to bridge the gap between ML fluency and security thinking. Spanning eight chapters, this course moves systematically from foundational threat-modeling discipline to a research-grade evaluation workflow.
We anchor every concept to one running system, an image-classification API, so learners build intuition through a single, consistent example rather than jumping between disconnected scenarios. The course is divided into three major phases:
The foundation (chapters 1 to 2): We establish how to think about an ML system as a security object. This covers system boundaries, the four core security objectives, life cycle tracing, and the threat-model template used throughout the rest of the course.
The attack taxonomy (chapters 3 to 6): We work through the full space of ML-specific attacks: training-time poisoning and backdoors, inference-time evasion, model extraction and privacy leakage, and the newer surface introduced by LLM and agentic systems, including their supply chain.
Defense and evaluation (chapters 7 to 8): We cover the discipline needed to tell a real defense from one that only looks effective. This includes defense mechanisms across the full stack, adaptive evaluation, and how to read and critique security research.
Preparing for security research
The course concludes with a capstone that asks you to produce a full threat model, attack map, and evaluation plan for a system of your choosing. Note that the capstone draws on every artifact built across the course: the life cycle trace from Chapter 1, the threat-model template from Chapter 2, the attack taxonomy from Chapters 3– 6, and the defense mechanisms from Chapter 7. This structure lets you build each skill in isolation before you combine them, which is often the best way to learn to reason about ML security like a researcher.
By the end of this curriculum, you will have a robust, evidence-based foundation in ML security. You will be ready to critique published defenses, evaluate vendor claims, and design your own security assessments with confidence.