CSE 291: LLM Security Autumn 2025
Lectures:
Monday/Wednesday 3:00pm-4:20pm CSE 2154
Instructor:
Earlence Fernandes Office hours: Tuesdays 4pm to 5pm, CSE 3244
Class Resources:
- Submissions on HotCRP
- Lecture schedule, readings, and course policies on this web page
Grading:
70%: Course Research Project
20%: Participation (see details below)
10%: Final Project Presentation
Course Overview
This is an advanced graduate level course on Large Language Model Security.
LLM Security is a new research area (emerged over the past 4 years). Learning
the material requires a graduate-level understanding of Machine Learning, some mathematical
maturity and an undergraduate-level understanding of computer security (if you've taken CSE 127, you
should be well prepared). We will read a mix of classic ML security papers and
newer LLM security papers. Our goal is to
illustrate research challenges and solutions. It is not designed to be a tutorial course,
but rather to give students the context to understand current LLM security
research and evaluate their interest in the field. The course will examine
both the defensive and offensive side of the field, but with a heavy emphasis
on attacks because that's the current state of the field. At the conclusion of
the course, the students will have the foundation to conduct research in
LLM security.
Note to undergrad and professional MS students: This course is research heavy.
It is unlike other courses you've encountered in your career where there are
a fixed set of topics with exams and specific skills to learn. Rather, we will
be reading papers and discussing/analyzing those papers. Your primary performance
will be based on your ability to formulate and tackle research problems in LLM Security.
A quick way to judge whether taking this course is beneficial for your learning is to
read a sample paper and ask yourself, "would I be interested in writing such a paper myself?"
Attendance Considerations
This is an in person class. Please do not come to class or exams if you are sick. I will handle requests for remote attendance on a case-by-case basis and I may not grant all requests.
Schedule
Note: Contents more than 1 week into the future is subject to minor changes.
Research Project
You will work on projects in groups of 1-3. The goal of the project is to conduct original research in LLM/ML Security and Privacy. You are encouraged to come up with your own project idea, but we have a few ideas that are well-scoped for a quarter project. Talk with me to scope out a project. The project will require a 1-page project proposal containing: (1) What problem you are tackling; (2) Why that problem is worth tackling; (3) The expected contributions to the science of computer security. This will be due by the second or third week of the quarter. At the end of the quarter, you are expected to turn in a short research paper (max 6 pages; two column format) and give a 15 minute talk. We will have periodic status updates to help you stay on track. The project is 70% of your course grade. I recommend that you take this seriously from the start. I especially value projects that are publication-worthy.
Participation
Class sessions will be structured as a discussion-based meeting. The primary mechanism for discussion is through cold calls, which are random calls to students to answer questions. These questions are a mix of testing comprehension of the reading material as well as getting students talking and discussing the topics in each paper. Remember that in research, there is no single "right" or "wrong" answer; there are only answers that have trade-offs along various dimensions. Your goal in participating is to think through the nuances of the question and the possible answers. You get 3 "passes" over the quarter where you can skip the question. If you skip, you must explain why. The expectation is that you will have read the papers in advance. There will not be any cold calls for the first class.
By taking this course, you implicitly agree to abide by the UCSD policies on Integrity of Scholarship and Student Conduct. See the Academic Integrity Support for Remote Learning. University rules on integrity of scholarship and code of conduct are taken seriously and will be enforced.