Weekly Activities

Every content week comes with a four-part engagement pack, in addition to the week’s lab and quiz. These activities are practiced in class or assigned as short homework — your instructor will announce each week’s mode on Canvas.

📘 New to these tools? The Student Guides walk you step by step through Google Colab, Hacker101, CTFd, CISA tabletops, and the course readings - how to get in and how to finish each activity. Keep the matching guide open while you work.

🚩 CTFd Challenge

One capture-the-flag challenge per week on the course CTFd server, solvable with Colab and a browser. Difficulty and points ramp up all semester. Flags look like CIS350{...}.

🎲 CISA Mini-Tabletop

A 15-minute incident-response scenario adapted from the CISA Tabletop Exercise Packages, played in small groups with timed injects.

🧑‍💻 Hacker101 Lesson

A short assigned lesson or CTF level from Hacker101 with guided questions connecting it to the week's course concepts.

💬 Packback Discussion

Two open-ended curiosity prompts on the week's theme. Post one question or response before Wednesday's class.

⚖️ Ethics reminder: every hands-on security activity in this course is performed only in the sandboxed environments we provide (course CTFd, Hacker101's intentionally vulnerable apps, tabletop discussion). Applying these techniques to systems you don't own or aren't authorized to test is illegal and a violation of the academic integrity policy.

Graded Weekly Activities (Slides + Worksheets)

Each content week has a graded, 20-point in-class activity with a PowerPoint deck and a student worksheet (PDF). Download links live on each week’s lecture-notes page. Activities are aligned to the official lecture schedule below.

Week Lecture topic Activity Platform
1 Welcome to Cybersecurity Python & Colab Tutorial + Weak Password Storage & Authentication Colab + Hacker101
2 Data, the Fuel of AI Data Exposure & Privacy Violations Hacker101
3 Supervised Learning Phishing & Social Engineering Hacker101
4 Regression & Model Evaluation Cost-Benefit Trade-Off Under Pressure CISA Tabletop
5 Unsupervised Learning + Exam 1 Anomaly Detector False Alarms CISA Tabletop
6 Unsupervised: Finding Hidden Patterns Intrusion Detection & Anomaly Analysis Hacker101
7 Semi-Supervised & Reinforcement When to Request Manual Labels CISA Tabletop
8 Threats from the Inside: Attackers Use AI Evade the Filter: Adversarial Email CTFd
9 Spring Break / Exam 2 (no activity)
10 Adversarial Examples & Data Poisoning Craft Adversarial Examples to Fool a Classifier CTFd
11 Prompt Injection & LLM Security Prompt Injection: Break & Defend an LLM Assistant CTFd
12 AI Ethics, Bias, Fairness & Governance Fairness Audit Response CISA Tabletop
13 Privacy in ML + Exam 3 Membership Inference Attack CTFd
14 Trustworthy & Responsible AI AI Incident Response: Biased Hiring System CISA Tabletop
15 Advanced Topics & Course Wrap-Up Domain Adaptation with Limited Labels CTFd
16 Final Q&A & Exam Preparation Responsible AI Governance Board Meeting CISA Tabletop

Each activity is 20 points, runs 30-40 minutes, and connects to that week's lecture and lab. Three additional activities (feature engineering, bias auditing, federated learning) are kept as optional supplements in the course repository.

Capture the Flag Challenges

Five hands-on CTF challenges run on the course CTFd server. Each is a self-contained Google Colab sandbox (nothing to install, no data leaves your browser). Perform the attack and the notebook prints a flag like CIS350{...} that you submit on CTFd for points.

🚩 Rules of engagement: every challenge is an intentionally vulnerable toy model or mock assistant built only for this course. Attack only the provided sandbox — applying these techniques to any system you do not own or are not authorized to test is illegal and an academic-integrity violation.
Week Challenge Category Pts Starter
8 Evade the Filter Evasion 15 Colab starter
10 One Pixel Too Far Adversarial ML 20 Colab starter
11 Jailbreak the Helpdesk Bot LLM Security 20 Colab starter
13 Were You in the Data Privacy 20 Colab starter
15 The Aging Malware Detector Robustness 20 Colab starter

Upload a starter to Google Colab (File -> Upload notebook), work through the TODO cells, and run the check cell to reveal your flag. Instructor setup and challenge briefs live in the course repository under ctfd/.

Week-by-Week Packs

The four-part engagement packs below are a separate, optional catalog (their week numbering predates the finalized lecture schedule shown above). Complete pack details (CTFd scenarios, tabletop injects, Hacker101 resources, Packback prompts) are documented in Engagement Packs Reference. Packs are posted on Canvas as each week is released.

Quick Reference

Week Focus CTFd Difficulty Tabletop Scenario
1 Security Basics Easy (10 pts) Phishing Campaign Response
2 Features & Labels Easy (10 pts) Data Quality Incident
3 Classifiers Medium (15 pts) False-Positive Filter Tuning
4 Evaluation Metrics Medium (15 pts) Cost-Benefit Decision
5 Feature Engineering Medium (15 pts) Feature Bottleneck
6 Clustering & Anomaly Medium (15 pts) Anomaly Detector False Alarms
7 Semi-Supervised Medium (15 pts) When to Label Data
8 Adversarial ML Hard (20 pts) Adversarial Attack Response
10 Fairness & Bias Hard (20 pts) Fairness Audit Response
12 Privacy & DP Hard (20 pts) Privacy Breach Response
13 Federated Learning Hard (20 pts) Compromised Aggregator
14 Incident Response Hard (20 pts) Biased Hiring Model Incident
15 Transfer Learning Hard (20 pts) Deployment to New Domain
16 Responsible AI Hard (20 pts) Governance Board Meeting

Week 9: Spring Break / Exam (no activities)
Week 11: Combined with Week 12 Lab 11 (privacy content)

Each pack reinforces that week’s lab work and connects lecture concepts to real-world incident scenarios, hands-on security challenges, and ethics-driven discussions.