Weekly Activities
Every content week comes with a four-part engagement pack, in addition to the week’s lab and quiz. These activities are practiced in class or assigned as short homework — your instructor will announce each week’s mode on Canvas.
🚩 CTFd Challenge
One capture-the-flag challenge per week on the course CTFd server,
solvable with Colab and a browser. Difficulty and points ramp up all
semester. Flags look like CIS350{...}.
🎲 CISA Mini-Tabletop
A 15-minute incident-response scenario adapted from the CISA Tabletop Exercise Packages, played in small groups with timed injects.
🧑💻 Hacker101 Lesson
A short assigned lesson or CTF level from Hacker101 with guided questions connecting it to the week's course concepts.
💬 Packback Discussion
Two open-ended curiosity prompts on the week's theme. Post one question or response before Wednesday's class.
Graded Weekly Activities (Slides + Worksheets)
Each content week has a graded, 20-point in-class activity with a PowerPoint deck and a student worksheet (PDF). Download links live on each week’s lecture-notes page. Activities are aligned to the official lecture schedule below.
| Week | Lecture topic | Activity | Platform |
|---|---|---|---|
| 1 | Welcome to Cybersecurity | Python & Colab Tutorial + Weak Password Storage & Authentication | Colab + Hacker101 |
| 2 | Data, the Fuel of AI | Data Exposure & Privacy Violations | Hacker101 |
| 3 | Supervised Learning | Phishing & Social Engineering | Hacker101 |
| 4 | Regression & Model Evaluation | Cost-Benefit Trade-Off Under Pressure | CISA Tabletop |
| 5 | Unsupervised Learning + Exam 1 | Anomaly Detector False Alarms | CISA Tabletop |
| 6 | Unsupervised: Finding Hidden Patterns | Intrusion Detection & Anomaly Analysis | Hacker101 |
| 7 | Semi-Supervised & Reinforcement | When to Request Manual Labels | CISA Tabletop |
| 8 | Threats from the Inside: Attackers Use AI | Evade the Filter: Adversarial Email | CTFd |
| 9 | Spring Break / Exam 2 | (no activity) | — |
| 10 | Adversarial Examples & Data Poisoning | Craft Adversarial Examples to Fool a Classifier | CTFd |
| 11 | Prompt Injection & LLM Security | Prompt Injection: Break & Defend an LLM Assistant | CTFd |
| 12 | AI Ethics, Bias, Fairness & Governance | Fairness Audit Response | CISA Tabletop |
| 13 | Privacy in ML + Exam 3 | Membership Inference Attack | CTFd |
| 14 | Trustworthy & Responsible AI | AI Incident Response: Biased Hiring System | CISA Tabletop |
| 15 | Advanced Topics & Course Wrap-Up | Domain Adaptation with Limited Labels | CTFd |
| 16 | Final Q&A & Exam Preparation | Responsible AI Governance Board Meeting | CISA Tabletop |
Capture the Flag Challenges
Five hands-on CTF challenges run on the course CTFd server. Each is a self-contained Google
Colab sandbox (nothing to install, no data leaves your browser). Perform the attack and the
notebook prints a flag like CIS350{...} that you submit on CTFd for points.
| Week | Challenge | Category | Pts | Starter |
|---|---|---|---|---|
| 8 | Evade the Filter | Evasion | 15 | Colab starter |
| 10 | One Pixel Too Far | Adversarial ML | 20 | Colab starter |
| 11 | Jailbreak the Helpdesk Bot | LLM Security | 20 | Colab starter |
| 13 | Were You in the Data | Privacy | 20 | Colab starter |
| 15 | The Aging Malware Detector | Robustness | 20 | Colab starter |
Week-by-Week Packs
Quick Reference
| Week | Focus | CTFd Difficulty | Tabletop Scenario |
|---|---|---|---|
| 1 | Security Basics | Easy (10 pts) | Phishing Campaign Response |
| 2 | Features & Labels | Easy (10 pts) | Data Quality Incident |
| 3 | Classifiers | Medium (15 pts) | False-Positive Filter Tuning |
| 4 | Evaluation Metrics | Medium (15 pts) | Cost-Benefit Decision |
| 5 | Feature Engineering | Medium (15 pts) | Feature Bottleneck |
| 6 | Clustering & Anomaly | Medium (15 pts) | Anomaly Detector False Alarms |
| 7 | Semi-Supervised | Medium (15 pts) | When to Label Data |
| 8 | Adversarial ML | Hard (20 pts) | Adversarial Attack Response |
| 10 | Fairness & Bias | Hard (20 pts) | Fairness Audit Response |
| 12 | Privacy & DP | Hard (20 pts) | Privacy Breach Response |
| 13 | Federated Learning | Hard (20 pts) | Compromised Aggregator |
| 14 | Incident Response | Hard (20 pts) | Biased Hiring Model Incident |
| 15 | Transfer Learning | Hard (20 pts) | Deployment to New Domain |
| 16 | Responsible AI | Hard (20 pts) | Governance Board Meeting |
Week 9: Spring Break / Exam (no activities)
Week 11: Combined with Week 12 Lab 11 (privacy content)
Each pack reinforces that week’s lab work and connects lecture concepts to real-world incident scenarios, hands-on security challenges, and ethics-driven discussions.