AI Security Engineering · Module 00
AI, ML & LLM Foundations Workbook
Learner: ______________________________ Date: ________________
A. Concept relationship map
Define each term in one sentence and draw their relationship.
| Term | Course definition | Subset / contains / related to | Security-relevant example |
|---|---|---|---|
| Artificial intelligence | |||
| Machine learning | |||
| Deep learning | |||
| Generative AI | |||
| Foundation model | |||
| Large language model |
B. ML workflow
| Stage | Inputs | Outputs / artifact | Quality decision | Security concern |
|---|---|---|---|---|
| Collect / label | ||||
| Split / transform | ||||
| Train | ||||
| Validate / tune | ||||
| Test | ||||
| Deploy / monitor |
C. Chapter 3 neural-network evidence assessment
Use a course-owned demonstration or an explicitly authorized local classifier. Do not submit confidential samples. Complete every field and attach the system graph.
Chapter 3 pass standard: 8/10, including full credit for explicit access, budgets, and evidence classification. See the chapter and instructor guide for the five two-point criteria.
D. Chapter 4 LLM request-trace assessment
Use a course-owned or explicitly authorized disposable application. Use only harmless marker strings, exclude secrets and third-party data, and record unavailable provider internals as unknown rather than inferring them.
| Step | Input / representation | Versioned component | Output / decision | Telemetry |
|---|---|---|---|---|
| Identity and authorization | ||||
| Messages, retrieved context, and template | ||||
| Tokenization and truncation | ||||
| Model route and Transformer inference | ||||
| Logits, decoding, and stop condition | ||||
| Parser and validation | ||||
| Policy, approval, and execution |
Chapter 4 pass standard: 70/100, with at least half credit in every criterion. Require revision if the submission uses unauthorized data, equates generated text with impact, omits the effective template or generation configuration, or treats an ATLAS mapping as evidence by itself.
E. Adaptation method selection
| Requirement | Prompt | RAG | Fine-tune / PEFT | Why |
|---|---|---|---|---|
| Current internal facts | ||||
| Consistent response format | ||||
| New domain behavior | ||||
| Per-user private data |
F. RAG trace
G. Agent and MCP trace
| Component | Identity | Data / authority | Validation | Audit event |
|---|---|---|---|---|
| Host / application | ||||
| MCP client | ||||
| MCP server | ||||
| Tool | ||||
| Resource | ||||
| Memory | ||||
| Approval / execution |
H. Metric selection
| Decision | Metric | Dataset / traffic | Threshold | Failure cost | Limitation |
|---|---|---|---|---|---|
| Task quality | |||||
| Retrieval | |||||
| Security | |||||
| Performance / cost |
I. Terminology clinic
Rewrite this statement accurately using the course glossary:
J. Exit checklist
□ Concept map □ ML lifecycle □ LLM trace □ RAG trace
□ Agent/MCP trace □ Metrics □ Terminology correction □ Knowledge check