K-INFO
HU
EN
Login

Security of Machine Learning 

A gépi tanulás biztonsága
A tantárgyleírás hatályossága
Hatályosság kezdete:
2026. March 21.
Hatályosság vége:
Subject name (Hungarian, English)
A gépi tanulás biztonsága
Security of Machine Learning 
Subject code BMEVIHIMB09
Subject type
Training Level
Course types and hours (weekly/semester)
Course type lecture tutorial laboratory
hours (weekly) 2 1 0
type (linked/independent) derived course
Assessment type vizsga
Credits 5
Subject coordinator
DR. Ács Gergely
position: egyetemi docens
Responsible department
Hálózati Rendszerek és Szolgáltatások Tanszék
Faculty Villamosmérnöki és Informatikai Kar
Subject website
Primary curriculum type
Direct prerequisites – Strong prerequisite none
Direct prerequisites – Weak prerequisite none
Direct prerequisites – Parallel prerequisite none
Direct prerequisites – Milestone prerequisite none
Direct prerequisites – Exclusion none

Objectives

Programme

Lecture Topics
1.    Overview of Machine Learning Security – Confidentiality, Integrity, Availability (CIA), motivational examples, legal background, risk-based approaches.
2.    Decision Manipulation 1 – Attack models, white-box attacks (FGSM, CW, Saliency maps), physical attacks.
3.    Decision Manipulation 2 – Black-box attacks, transferability of adversarial samples.
4.    Decision Manipulation 3 – Defenses (adversarial training, provable robustness, deep k-NN).
5.    Poisoning Attacks (Untargeted Data Poisoning) – Defenses (label flipping, anomaly detection).
6.    Poisoning Attacks (Targeted Data Poisoning) – Feature collision, Witches' Brew, defenses (sample weighting).
7.    Backdoors in Machine Learning Models – Defenses (Neural Cleanse).
8.    Trojan Attacks Against Machine Learning Models
9.    Availability Attacks – Black-box and white-box sponge constructions.
10.    Training Data Reconstruction – Attack models, model inversion.
11.    Membership Attacks – Active and passive attacks, gradient-based, score-based, label-based attacks.
12.    Defenses Against Membership Attacks – Differential privacy (DP-SGD, PATE), regularization.
13.    Model Stealing and Defenses – Model watermarking, inference from training datasets, fingerprinting models.
14.    Exploiting Explainability and Federated Learning Security – Secure aggregation, Byzantine problems, KRUM.

Exercise/Lab Topics
1.    Adversarial Examples and Model Robustness Auditing 1 – White-box attacks.
2.    Adversarial Examples and Model Robustness Auditing 2 – Black-box attacks.
3.    Untargeted Data Poisoning and Defenses 1 – Label flipping.
4.    Targeted Data Poisoning and Defenses 1 – STRIP.
5.    Generating Backdoors in Models and Defenses – BadNets, Neural Cleanse.
6.    Membership and Reconstruction Attacks, Privacy Auditing 1 – Model inversion, gradient-based attacks, differential privacy.
7.    Membership Attacks and Privacy Auditing 2 – Score-based and label-based attacks, regularization as defense.

 

The course aims to provide insights into the security challenges of machine learning and related systems. It covers the theoretical foundations and practical methods of various attacks against machine learning algorithms and their defense mechanisms. Additionally, through exercises and assignments, it introduces students to the privacy auditing of machine learning models.

Learning outcomes

Ez a tantárgy a KKK rendeletben meghatározott, következő kompetenciák fejlesztését szolgálja:

Knowledge

No learning outcomes recorded.

Skills

No learning outcomes recorded.

Attitudes

No learning outcomes recorded.

Autonomy and responsibility

No learning outcomes recorded.

Oktatási módszertan

•    Lectures •    Classroom Exercises •    Independent Work (Homework Assignments)

Tanulástámogató anyagok

Online források
•    Online reading materials assigned for lectures (book chapters, research papers, blogs).

Recommended preliminary knowledge for completing the subject

Knowledge type competencies
(azon előzetes ismeretek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
The course builds on knowledge of Artificial Intelligence.
Skill type competencies
(azon előzetes képességek és készségek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
nincs
Recommended (non-compulsory) preliminary competencies
(azon ajánlott (nem kötelező) előzetesen megszerzendő kompetenciák összessége, amelyek jelentősen hozzájárulnak a tantárgy eredményes teljesítéséhez)
The course builds on knowledge of Artificial Intelligence.
General rules
Requirements: During the Semester •    1 Midterm Exam (ZH) •    2 Homework Assignments To pass, both the midterm and each homework must be successfully completed. A minimum of 40% of the maximum score must be achieved in each. •    The midterm exam does not contribute to the final grade. •    Each homework is worth a maximum of 25 points (total: 50 points). A minimum of 10 points per homework is required. •    Homework scores contribute to the final grade. During the Exam Period •    Written Exam •    A minimum of 40% of the total exam score is required to pass. •    The exam is worth a maximum of 50 points. •    A minimum of 20 points is required to pass. Final Grade Calculation Total points: P = V + HF1 + HF2, where: •    V = Exam score (max: 50) •    HF1 & HF2 = Homework scores (max: 50) Grade    Points Required Excellent (5)    P ≥ 85 Good (4)    P ≥ 70 Satisfactory (3)    P ≥ 55 Pass (2)    P ≥ 40 Fail (1)    P < 40 Additional possibilities: •    The midterm exam can be retaken once if failed or missed. •    Homework assignments must be submitted within the semester. Exact deadlines are announced in the first week. •    Late homework submissions are allowed within 1 extra week but with a 15% point deduction.
Assessment methods
In-term assessments

No detailed assessments provided.

Weight of in-term assessments

No weights provided.

Exam-period assessments

No detailed assessments provided.

Weight of exam elements

No weights provided.

Grade calculation

No grade thresholds provided.

Attendance requirements

No attendance requirements provided.

Rules for retake and resubmission

Not provided.

Short description

Not provided.

Detailed description
IMSc program: •    Independent processing of assigned research papers based on predefined questions. •    Exam questions related to the analyzed papers. •    Optional extra homework assignments. IMSc points: •    Up to 15 IMSc points for additional homework. •    Up to 10 IMSc points for research paper analysis and presentation in the exam.
Recommended courses
Artificial Intelligence, Analysis 1-2
Workload to complete the subject

No workload breakdown provided.

Validity of subject requirements
Requirements valid from:
Requirements valid until:
Curriculum placement

No curriculum placements recorded for this subject version.