# Workshop 1: Introduction and Fundamentals in AI

> A foundational tour of artificial intelligence and the security, privacy, and ethical questions that follow it into every industry that adopts it.

## Overview

Workshop 1 sets the groundwork for the entire SecureAI program. Before we study specific attacks and defenses in later workshops, we need a shared understanding of what AI systems are, how they learn from data, where they are being deployed, and why their data-driven nature introduces security, privacy, and ethical risks that traditional software does not face.

This workshop introduces the core concepts of artificial intelligence, cybersecurity, and privacy while creating awareness of the potential risks and ethical considerations that come with deploying AI in the real world. By the end, you will understand how AI systems are used across different industries, the benefits and risks those systems carry, and the fundamental security and privacy challenges organizations must address when they adopt AI. These themes recur throughout the remaining eleven workshops, so treat this session as the map for everything that follows.

Workshop 1 is delivered as an expert panel. Five guests from industry and academia share real-world perspectives on how different sectors use AI, how bias and discriminatory outcomes can arise, and why responsible AI development and deployment matter.

## Workshop Video

This session does not have a recorded video. Work through the reading below.

In this panel, the speakers draw on their industry and research experience to discuss:

- **Industry applications and use cases** - how organizations across sectors deploy AI, the problems it solves, and why security approaches must be tailored to each domain rather than applied one-size-fits-all.
- **Bias and fairness challenges** - how bias emerges in AI systems, how it is detected, and real strategies teams use to keep outcomes fair across demographic groups.
- **Privacy and data security** - how sensitive information can leak through model predictions or attacks, and how to protect data across the machine learning lifecycle.
- **Regulatory landscape** - how evolving rules such as GDPR, CCPA, and the EU AI Act shape AI deployment, and how organizations prepare for compliance.
- **Responsible AI and governance** - the organizational structures, ethics reviews, and cross-functional collaboration needed to oversee AI systems responsibly.

### Panelists

Bringing together distinguished experts from leading technology companies, cybersecurity firms, and academia, our panel offers a rich blend of real-world experience and cutting-edge research spanning AI implementation across industries, bias and fairness in machine learning, privacy and data security, and governance for responsible AI.

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/saad.png" alt="Muhammad Saad" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Muhammad Saad</h4>
  <p><strong>PayPal</strong> | Senior Research Scientist</p>
  <p>Muhammad Saad is a Senior Research Scientist at Paypal. He is interested in advancing the security and privacy of the internet through applied research, with a focus on distributed systems security, web and network security, privacy-enhancing technologies, and social engineering attacks. His experience spans both industry and academia, where he has acquired skills in measurements and modeling, big data analytics, machine learning, and formal analysis.</p>
</div>

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/abusnaina.png" alt="Ahmed Abusnaina" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Ahmed Abusnaina</h4>
  <p><strong>Meta</strong> | Machine Learning Research Scientist</p>
  <p>Ahmed Abusnaina is a Machine Learning Research Scientist at Meta. At Meta, his work revolves around social graphs user understanding, pattern recognition, and robust signal processing. Before joining Meta, he obtained his Ph.D. in Computer Science (Security Research) from the University of Central Florida. His dissertation focused on introducing robust machine learning applications in malware detection, image recognition, and anomaly detection domains.</p>
</div>

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/mclachlan.png" alt="Jon McLachlan" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Jon McLachlan</h4>
  <p><strong>YSecurity</strong> | Co-founder & Security Leader</p>
  <p><a href="https://www.linkedin.com/in/jon-mclachlan/" rel="noopener" target="_blank"><u>Jon McLachlan</u></a> co-founded <a href="https://ysecurity.io/" rel="noopener" target="_blank"><u>YSecurity</u></a> and hosts <a href="https://open.spotify.com/show/5lK5ZeozOPsZD4cR0Ii5pM?si=b8b458923f9c43f6" rel="noopener" target="_blank"><u>The Security Podcast of Silicon Valley</u></a>. With a history of roles at Apple, Pure Storage, Robinhood, and startups like UnifyId, he has led diverse security teams across various sectors. His approach prioritizes creativity, professional growth, and the human aspect of security. He holds a Master's in Computer Science from the University of Minnesota, specializing in product security and privacy. Jon is passionate about integrating diversity and inclusion into team building and security practices, especially in AI.</p>
</div>

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/Mohammed_Abuhamad.png" alt="Mohammed Abuhamad" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Mohammed Abuhamad</h4>
  <p><strong>Loyola University Chicago</strong> | Assistant Professor</p>
  <p>Mohammed Abuhamad is an assistant professor of Computer Science at <a href="https://www.luc.edu/" rel="noopener" target="_blank"><u>Loyola University Chicago</u></a>. He received a Ph.D. degree in Computer Science from the <a href="https://www.ucf.edu/" rel="noopener" target="_blank"><u>University of Central Florida</u></a> (UCF) in 2020. He also received a Ph.D. degree in Electrical and Computer Engineering from <a href="http://inha.ac.kr/" rel="noopener" target="_blank"><u>INHA University</u></a>, (Incheon, Republic of Korea) in 2020. He received a Master degree in Information Technology (Artificial Intelligence) from the <a href="https://www.ukm.my/" rel="noopener" target="_blank"><u>National University of Malaysia</u></a>, (Bangi, Malaysia) in 2013.</p>
  <p>He is interested in AI/Deep-Learning-based Information Security, especially Software and Mobile/IoT Security. He is also interested in Machine Learning-based Applications and Adversarial Machine Learning. He has published several peer-reviewed research papers in top-tier conferences and journals such as ACM CCS, PoPETS, IEEE ICDCS, and IEEE IoT-J.</p>
</div>

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/Eric_Chan-Tin.png" alt="Eric Chan-Tin" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Eric Chan-Tin</h4>
  <p><strong>Loyola University Chicago</strong> | Associate Professor & Center Director</p>
  <p>Eric Chan-Tin is an associate professor in the Department of Computer Science, the Director for the Center of Cybersecurity, and the Director of the Fellowship Office at Loyola University Chicago. He is the PI for the NSA/DHS Center of Academic Excellence in Cyber Defense at Loyola University Chicago. He teaches mostly programming and cybersecurity courses. His research is broadly on network/computer security and privacy/anonymity. His research has been funded by the NSF, DoD, NSA, and various companies. He also organizes the Loyola cybersecurity club and coaches student teams to participate in cybersecurity competitions.</p>
  <p>Previously, he was an associate professor in the CS Department at Oklahoma State University. He received his Ph.D. degree from the University of Minnesota in 2011 under the supervision of Dr. Nick Hopper and his B.A. from Macalester College in 2006. His research areas are in network security, distributed systems, privacy, and anonymity. He has published over 30 peer-reviewed papers, including publications at conferences and journals such as ACM CCS, NDSS, ACM TISSEC, and IEEE TIFS. He has also previously worked as a Helpdesk consultant and software engineer at Guidewire and Retek (now Oracle).</p>
</div>

## Learning Objectives

After completing this workshop, you will be able to:

- Explain the core concepts of artificial intelligence, including machine learning, deep learning, and neural networks, and how they enable systems to learn patterns from data.
- Describe why cybersecurity and privacy matter for AI systems, and how breaches or misuse create consequences for individuals and organizations.
- Recognize the risks and vulnerabilities introduced by AI deployment, including both technical security issues and the potential for malicious misuse.
- Discuss the ethical dimensions of AI, particularly fairness, bias, and the potential for discriminatory outcomes.
- Identify how AI is applied across different industries and how sector-specific requirements shape security and privacy approaches.
- Appreciate why responsible AI development must integrate security, privacy, and ethics throughout the entire system lifecycle rather than treating them as afterthoughts.

## Theoretical Background

### What Is Artificial Intelligence?

Artificial intelligence is the field of computer science focused on building systems that perform tasks normally requiring human intelligence: learning from experience, recognizing patterns, understanding language, making data-driven decisions, and responding to complex situations. AI systems span a wide spectrum, from simple rule-based programs that follow explicit instructions to deep neural networks that process vast amounts of information and learn layered, increasingly abstract representations.

### Machine Learning, Deep Learning, and Neural Networks

It helps to see these three terms as nested rather than interchangeable. Artificial intelligence is the broad goal; machine learning is the dominant approach to reaching it today; deep learning is a powerful subset of machine learning; and neural networks are the models that make deep learning work.

| Term | What it means | Relationship |
|------|---------------|--------------|
| **Artificial Intelligence (AI)** | Any technique that lets machines perform tasks associated with human intelligence. | The broadest field. |
| **Machine Learning (ML)** | Systems that improve at a task by learning patterns from data instead of being explicitly programmed. | A subset of AI. |
| **Deep Learning (DL)** | ML using multi-layered neural networks to learn hierarchical representations of data. | A subset of ML. |
| **Neural Networks** | Models of interconnected layers of simple units ("neurons") that transform inputs into outputs. | The core building block of deep learning. |

A machine learning model learns patterns from training data and then applies those patterns to make predictions or decisions on new, unseen data. Deep learning extends this by stacking many layers, so that early layers capture simple features (such as edges in an image) and later layers combine them into complex concepts (such as faces or objects). This capacity to learn hierarchical representations is what powers modern applications from image recognition to natural language processing.

A further distinction that matters for security is the difference between the two broad families of models:

- **Predictive (discriminative) models** learn a decision boundary or a mapping from inputs to output labels or values. Classification and regression are typical examples. (Clustering and other unsupervised methods, which group data without labeled outputs, form a separate family.)
- **Generative models** learn the underlying distribution of the training data and can produce new samples with similar properties. Generative adversarial networks (GANs), large language models (LLMs), and diffusion models are examples.

Most of the hands-on labs in this program target predictive models, but the same threat concepts increasingly apply to generative systems as well.

### AI Applications Across Industries

Organizations in nearly every sector now deploy AI to solve business problems and improve operations. Understanding these applications provides essential context: the security and privacy stakes, and the harm caused by a failure, differ sharply from one domain to another.

| Industry | Representative AI uses | Why the stakes are high |
|----------|------------------------|-------------------------|
| **Healthcare** | Diagnosis support, drug discovery, treatment planning, patient monitoring | Errors and data exposure directly affect patient safety and highly sensitive records. |
| **Finance** | Fraud detection, credit scoring, risk evaluation, algorithmic trading | Decisions affect access to capital; adversaries are well funded and motivated. |
| **Retail** | Recommendation systems, customer service, demand forecasting | Heavy reliance on personal behavioral data raises privacy concerns. |
| **Manufacturing** | Quality control, predictive maintenance, supply-chain optimization | Failures can halt production or create physical safety risks. |
| **Government** | Public services, security screening, administrative automation | Decisions affect rights and access to services at scale. |

The same underlying technology can therefore carry very different risk profiles depending on where it is used, which is why AI security cannot be a single fixed checklist.

### The Security and Privacy Landscape for AI

AI systems face security challenges that stem directly from their data-driven nature. Because a model's behavior is learned from data rather than hand-coded, an adversary who can influence the data, the model, or the inputs at prediction time can influence the system's behavior. Despite the remarkable progress of AI and ML, these technologies remain vulnerable to attacks that can cause serious, sometimes spectacular, failures.

It is useful to think about *where* along the machine learning lifecycle an attacker can act. Broadly, attacks target either the **data** (training data, or the inputs supplied at prediction time) or the **model** itself. Later workshops go deep on each of these; the table below is an intro-level map of the categories you will encounter.

| Attack category | When it happens | What the attacker does | Primary concern |
|-----------------|-----------------|------------------------|-----------------|
| **Data poisoning** | Training time | Inserts or alters training samples to corrupt what the model learns | Integrity / Availability |
| **Model poisoning** | Training time | Tampers with the model or its parameters during training | Integrity / Availability |
| **Evasion (adversarial examples)** | Deployment time | Crafts small input perturbations that fool a deployed model | Integrity |
| **Model extraction** | Deployment time | Steals a proprietary model by querying it repeatedly | Confidentiality |
| **Privacy / inference attacks** | Deployment time | Recovers information about the training data (e.g., membership or property inference, reconstruction) | Confidentiality |

These categories map onto the classic security triad, adapted for AI:

- **Availability** - keeping the system working and usable (undermined by poisoning that degrades overall performance or by energy-and-latency attacks).
- **Integrity** - keeping predictions correct and trustworthy (undermined by evasion and targeted poisoning).
- **Confidentiality** - keeping the model and its training data private (undermined by extraction and inference attacks).

An attacker's reach is shaped by their **capabilities** (what they can control: training data, the model, test inputs, labels, source code, or query access) and their **knowledge** of the system, which ranges from full white-box access to limited black-box query access. Workshop 2 formalizes this into a complete threat-model vocabulary, and Workshops 3 through 6 implement specific attacks and defenses in code. This taxonomy of attacks on predictive AI systems follows the framework described in the NIST report on adversarial machine learning (NIST AI 100-2e2023).

One more point distinguishes AI security from traditional software security: the interconnected nature of modern deployments means the compromise of one AI system can cascade through the dependent systems and organizations that rely on its outputs.

### Ethics, Bias, and Fairness

AI systems make and shape decisions that affect individuals and society, so their ethical dimension is inseparable from their technical one. Bias in training data can produce discriminatory outcomes that perpetuate or even amplify historical inequalities. A lack of transparency makes it hard for affected people to understand why a decision was made about them, which is especially serious in consequential domains such as employment, credit, healthcare, and criminal justice. Without appropriate oversight and accountability, AI systems can cause unintended harm to individuals or groups.

Responsible AI therefore requires balancing innovation and efficiency against fairness, transparency, accountability, and legal requirements. Bias is not only a social concern; it is also a quality and reliability problem, since a model that performs unevenly across groups is, by definition, not performing correctly for everyone. Workshop 7 returns to bias and fairness in depth, including hands-on mitigation techniques.

## Hands-on Lab

Workshop 1 is a panel session and has no lab notebook. The hands-on labs begin in Workshop 2, where you will implement and detect adversarial attacks in code. If you plan to run those labs, use the setup guidance on the [program landing page](../index.md) to prepare Python and Jupyter locally or to get ready to use Google Colab.

## Key Takeaways

- AI is increasingly central to operations and innovation across every industry, creating significant opportunities alongside meaningful risks.
- Machine learning and deep learning are data-driven: models learn behavior from data, which is precisely why data, models, and inputs all become attack surfaces.
- Security threats to AI fall into recognizable categories, poisoning, evasion, extraction, and privacy inference, that map onto availability, integrity, and confidentiality.
- Security and privacy must be built into the AI lifecycle from the start, not bolted on afterward.
- Fairness, transparency, and accountability are essential to building AI that users and society can trust.
- Meeting these challenges is inherently cross-functional, spanning technical, business, legal, and ethical expertise.

## Additional Resources

- **Slide deck - Adversarial Machine Learning and Threat Models (PDF):** [`SecAI_Workshop01_MohamadAbuhammed.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop02/slides/SecAI_Workshop01_MohamadAbuhammed.pdf) - a primer on attack surfaces, the CIA triad for AI, and the attack taxonomy. It also previews the threat-model material covered in Workshop 2. *(Note: the file is stored under `Workshop02/slides/`.)*
- **NIST AI 100-2e2023 - Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations** - the authoritative reference behind the attack taxonomy introduced above: [doi.org/10.6028/NIST.AI.100-2e2023](https://doi.org/10.6028/NIST.AI.100-2e2023).
- **Goodfellow, Shlens & Szegedy (2015), "Explaining and Harnessing Adversarial Examples"** - the foundational paper on adversarial examples and the FGSM attack: [arxiv.org/abs/1412.6572](https://arxiv.org/abs/1412.6572).
- **NIST AI Risk Management Framework (AI 100-1)** - a widely used framework for governing AI risk responsibly: [nist.gov/itl/ai-risk-management-framework](https://www.nist.gov/itl/ai-risk-management-framework).
- **[Program Resource Library](../resources.md)** - shared papers, tools, and datasets for the full workshop series.

## Next Steps

Continue to [Workshop 2: AI and Threat Models](../Workshop02/AI_and_Threat_Models.md), where the intro-level attack concepts from this session are formalized into a complete threat-model vocabulary and put into practice in the first hands-on lab.
