📖 Course Overview
The course is designed to provide an introductory yet technical understanding of the security vulnerabilities and threats that modern AI systems face, with a focus on deep neural networks and computer vision applications. Participants will explore key definitions and techniques for designing and implementing AI-based security attacks and safety threats while also gaining a foundational understanding of how to protect AI systems against them. A portion of the course will be devoted to hands-on laboratory sessions, where participants will implement attacks and countermeasures in practical deep neural network applications.
The main topics of the course are organized as follows:
- AI Foundations, Threat Modeling, and preliminaries
- Adversarial Attacks, Defenses, and Robust Training
- Poisoning Attacks, Backdoors, and Dataset Analysis
- Privacy Attacks and Distributed Learning
- Explainable, Fairness, and Ethical AI
- Security and Safety of large models and Agentic Systems
🛠️ Format & Exam
- Lectures: 30 hours (in-person, TECIP Institute, CNR Area, Pisa).
- Exam (3 CFU): Project/Research work + oral discussion.
To attend the course in the first semester of the 2026–2027 academic year, please fill out the following form: Course Registration Form.
A Microsoft Teams channel will be set up soon for feedback, questions, and announcements.
🗓️ Schedule (To be confirmed)
Scheduled lectures are showed in the following, while next dates and rooms will be confirmed soon.
-
Lecture 1 – AI Foundations & Threat Modeling – 3 November (14:00–17:00) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
-
Lecture 2 – Adversarial Attacks – 5 November (14:00–17:00) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
-
Lecture 3 – Defenses & Robust Training – 10 November (14:00–17:00) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
-
Lecture 4 – OOD Generalization & Detection – 12 November (14:00–17:00) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
-
Lecture 5 – Poisoning, Backdoors & Dataset Analysis – 24 November (14:00–17:00) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
-
Lecture 6 – Privacy Attacks & Distributed Learning Security – 26 November (14:00–17:00) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
-
Lecture 7 – Explainable, Fairness & Ethical AI – 1 December (14:00–17:00) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
-
Lecture 8 – LLM & VLM Foundations – 3 December (14:30–17:30) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
-
Lecture 9 – Safety, Steering & Jailbreak – 10 December (14:00–17:00) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
-
Lecture 10 – Security of Agentic Systems – 11 December (14:00–17:00) , PC Room, Tecip, Scuola Superiore Sant’Anna, Via Giuseppe Moruzzi 1
📂 Lectures
📬 Contact
giulio.rossolini@santannapisa.it