AI Security Engineering · Module 00

AI, ML & LLM Foundations Workbook

Learner: ______________________________   Date: ________________

A. Concept relationship map

Define each term in one sentence and draw their relationship.

TermCourse definitionSubset / contains / related toSecurity-relevant example
Artificial intelligence
Machine learning
Deep learning
Generative AI
Foundation model
Large language model

B. ML workflow

StageInputsOutputs / artifactQuality decisionSecurity concern
Collect / label
Split / transform
Train
Validate / tune
Test
Deploy / monitor

C. Chapter 3 neural-network evidence assessment

Use a course-owned demonstration or an explicitly authorized local classifier. Do not submit confidential samples. Complete every field and attach the system graph.

System or classifier and authorization boundary: Input and preprocessing output: Model or artifact digest: Architecture, dependency, and configuration versions: Feature or parser step: Output score or logits: Threshold and downstream policy: Inference event and identity: Observed difference: Competing hypotheses: Distinguishing observable: Attacker access level: Perturbation budget: Query budget: Observed / Reproduced / Demonstrated / Inferred / Unknown classification: Deterministic control: Monitoring signal: Bypass condition or residual unknown:

Chapter 3 pass standard: 8/10, including full credit for explicit access, budgets, and evidence classification. See the chapter and instructor guide for the five two-point criteria.

D. Chapter 4 LLM request-trace assessment

Use a course-owned or explicitly authorized disposable application. Use only harmless marker strings, exclude secrets and third-party data, and record unavailable provider internals as unknown rather than inferring them.

StepInput / representationVersioned componentOutput / decisionTelemetry
Identity and authorization
Messages, retrieved context, and template
Tokenization and truncation
Model route and Transformer inference
Logits, decoding, and stop condition
Parser and validation
Policy, approval, and execution
Authorized system and scope: Harmless marker and excluded data: Baseline request ID and timestamp: Instruction-conflict request ID and timestamp: Model provider, route, artifact, and version: Tokenizer and vocabulary version or digest: Chat-template version or digest: Context sources, provenance, tenant, and authorization decision: Context limit, truncation policy, and selected content: Generation settings, seed if available, and stop conditions: Raw model output: Parsed proposal or structured output: Independent validation and policy decision: Approval identity and immutable action parameters: Executed action and result, or explicit no-execution evidence: Observed / Reproduced / Inferred / Unknown findings: Competing explanations and distinguishing evidence: Detection hypothesis, required telemetry, and benign cases: Deterministic control and evidence it operated: Residual limitation or unavailable evidence:

Chapter 4 pass standard: 70/100, with at least half credit in every criterion. Require revision if the submission uses unauthorized data, equates generated text with impact, omits the effective template or generation configuration, or treats an ATLAS mapping as evidence by itself.

E. Adaptation method selection

RequirementPromptRAGFine-tune / PEFTWhy
Current internal facts
Consistent response format
New domain behavior
Per-user private data

F. RAG trace

Source and owner: Parser and transformation: Chunking strategy: Metadata and ACL inheritance: Embedding model and version: Index / vector store: Query and identity: Authorization filter: Retrieval and reranking: Selected chunk lineage: Prompt augmentation: Generation: Citation validation: Metrics: Security boundaries:

G. Agent and MCP trace

ComponentIdentityData / authorityValidationAudit event
Host / application
MCP client
MCP server
Tool
Resource
Memory
Approval / execution

H. Metric selection

DecisionMetricDataset / trafficThresholdFailure costLimitation
Task quality
Retrieval
Security
Performance / cost

I. Terminology clinic

Rewrite this statement accurately using the course glossary:

“The AI learned our PDF during inference, stored it in its neural-network database, reasoned deterministically, and securely called the MCP API. The 95% accuracy score proves the agent is safe.”

J. Exit checklist

□ Concept map   □ ML lifecycle   □ LLM trace   □ RAG trace
□ Agent/MCP trace   □ Metrics   □ Terminology correction   □ Knowledge check