CSE 291: LLM Security Autumn 2025


Lectures:

  Monday/Wednesday 3:00pm-4:20pm CSE 2154

Instructor:

  Earlence Fernandes   Office hours: Tuesdays 4pm to 5pm, CSE 3244

Class Resources:
Grading:

  70%: Course Research Project
  20%: Participation (see details below)
  10%: Final Project Presentation


Course Overview

This is an advanced graduate level course on Large Language Model Security. LLM Security is a new research area (emerged over the past 4 years). Learning the material requires a graduate-level understanding of Machine Learning, some mathematical maturity and an undergraduate-level understanding of computer security (if you've taken CSE 127, you should be well prepared). We will read a mix of classic ML security papers and newer LLM security papers. Our goal is to illustrate research challenges and solutions. It is not designed to be a tutorial course, but rather to give students the context to understand current LLM security research and evaluate their interest in the field. The course will examine both the defensive and offensive side of the field, but with a heavy emphasis on attacks because that's the current state of the field. At the conclusion of the course, the students will have the foundation to conduct research in LLM security.
Note to undergrad and professional MS students: This course is research heavy. It is unlike other courses you've encountered in your career where there are a fixed set of topics with exams and specific skills to learn. Rather, we will be reading papers and discussing/analyzing those papers. Your primary performance will be based on your ability to formulate and tackle research problems in LLM Security. A quick way to judge whether taking this course is beneficial for your learning is to read a sample paper and ask yourself, "would I be interested in writing such a paper myself?"


Attendance Considerations

This is an in person class. Please do not come to class or exams if you are sick. I will handle requests for remote attendance on a case-by-case basis and I may not grant all requests.


Schedule

Note: Contents more than 1 week into the future is subject to minor changes.


Research Project

You will work on projects in groups of 1-3. The goal of the project is to conduct original research in LLM/ML Security and Privacy. You are encouraged to come up with your own project idea, but we have a few ideas that are well-scoped for a quarter project. Talk with me to scope out a project. The project will require a 1-page project proposal containing: (1) What problem you are tackling; (2) Why that problem is worth tackling; (3) The expected contributions to the science of computer security. This will be due by the second or third week of the quarter. At the end of the quarter, you are expected to turn in a short research paper (max 6 pages; two column format) and give a 15 minute talk. We will have periodic status updates to help you stay on track. The project is 70% of your course grade. I recommend that you take this seriously from the start. I especially value projects that are publication-worthy.


Participation

Class sessions will be structured as a discussion-based meeting. The primary mechanism for discussion is through cold calls, which are random calls to students to answer questions. These questions are a mix of testing comprehension of the reading material as well as getting students talking and discussing the topics in each paper. Remember that in research, there is no single "right" or "wrong" answer; there are only answers that have trade-offs along various dimensions. Your goal in participating is to think through the nuances of the question and the possible answers. You get 3 "passes" over the quarter where you can skip the question. If you skip, you must explain why. The expectation is that you will have read the papers in advance. There will not be any cold calls for the first class.

By taking this course, you implicitly agree to abide by the UCSD policies on Integrity of Scholarship and Student Conduct. See the Academic Integrity Support for Remote Learning. University rules on integrity of scholarship and code of conduct are taken seriously and will be enforced.