Specialty centers · Adversarial ML & AI Security

Two printable capstone briefs you can assign this term

Free AI Security briefs for a school-approved sandbox. Students pick a scoped class of failure, measure a defense, and write the incident note a security team would file — including what they refused to attempt. You run two checkpoints and score. SEC-04 and SEC-01 have single-brief PDFs; every brief is in the bank PDF; the other ten are full on the page. No account. No student data leaves your school.

Lab rule

School-approved sandbox only. No production systems, no classmates' accounts, no district tools that were not provisioned for this lab. Students document published failure classes — they do not publish payload cookbooks. Refusal is part of the grade.

Next steps

  1. Download or read the worked sample (SEC-04).
  2. Name the sandbox in writing before any student trials.
  3. If your center already has a project slot this year, answer one question — not a purchase.

How to run one

  • Students choose the brief. You name the sandbox in writing before trials.
  • Two scheduled checkpoints. Score with the six questions below.
  • Mentors are advisory and optional. If you cannot staff one, run the brief with a teacher and a rubric.
  • These briefs do not produce verified computer-science credit. No AI or CS course in Virginia does.
  1. R1. Is the question scoped to an approved target and a named attack class?
  2. R2. Could another student re-run the lab from the write-up — without a payload dump?
  3. R3. Is there an honest baseline, and did they measure a real defense delta?
  4. R4. Did they measure what matters, including false positives, and separate lab success from real-world threat?
  5. R5. Could a security lead or teacher act on the incident note in fifteen minutes?
  6. R6. Who is harmed if this leaves the lab, and what did the student refuse to do?

Free now: this brief bank, how to run, and the scoring questions on this page. Other specialty tracks also have live banks today.

Capstone Pack (optional): printable rubric kit, five C's evidence template, mentor briefing, and judge scorecard — when you want a defensible center run, not just a class assignment. How Capstone Pack fits the center program.

Featured briefs

SEC-04 · worked sample

Jailbreak, then report

In a school-approved sandbox, can you (1) reproduce one published class under controlled conditions, (2) show that a simple defense reduces success rate relative to an undefended baseline, and (3) write the incident note a security team would file — including what you refused to attempt?

SEC-01

Prompt injection catalog

Against a school-approved sandboxed assistant, can you (1) classify observed failures into a small published taxonomy, (2) measure how often each class succeeds under a fixed trial budget, and (3) show whether one boring defense actually reduces success rate — without pretending the catalog is complete or production-ready?

More briefs

Ten more scoped questions. Each is a full brief on its page and is included in the bank PDF above. Separate single-brief PDFs for these are not ready yet — use Print on the brief, or the bank PDF.

  1. SEC-02 · on pagePoison in the training setUsing a teacher-provisioned small-classifier lab (public toy dataset + an approved educational notebook or harness), can a small fraction of poisoned labels flip the model on a pre-specified trigger condition from a published paper’s description — and what happens to clean accuracy when it does?
  2. SEC-03 · on pageModel extraction on a budgetAgainst a school-approved black-box demo (local model wrapped as an API, or a lab endpoint the teacher names), how much of the observable behavior can a student match with a fixed query budget — and what does that imply for how a real API should be priced, rate-limited, or logged?
  3. SEC-05 · on pageDetection that is not theaterFor one attack class already named in SEC-01’s taxonomy (or a teacher-provided class list), can you design a detector whose false-positive cost on ordinary teacher prompts is explicit — and decide whether you would actually turn it on?
  4. SEC-06 · on pageSupply-chain model riskFor one third-party model or AI-feature vendor a school might actually consider (teacher approves the name), what can you verify from the public model card, terms, and dependency claims — and what must you take on faith?
  5. SEC-07 · on pageAdversarial examples that matterUsing a teacher-provisioned robustness lab (tiny vision or audio classifier + an approved educational evaluation tool), do small allowed perturbations change the decision — and is that threat realistic for a target you name (school camera, lab microphone, homework-scanner fantasy)?
  6. SEC-08 · on pageSecrets in the context windowOn a school-built RAG demo stuffed with fake sensitive documents (teacher provides the corpus: dummy IEPs, dummy passwords, dummy medical notes — all clearly synthetic), how often does the assistant reveal retrieved text it was told not to — and does a retrieval or output filter reduce that rate without wrecking useful answers?
  7. SEC-09 · on pageRed team tabletopFor a fictional (or teacher-approved hypothetical) AI feature launch at a school — attendance chatbot, tutoring copilot, or media-center search — can you run a tabletop, score the response, and produce an after-action brief a director could use?
  8. SEC-10 · on pagePolicy that survives contactTranslate one NIST AI RMF or OWASP LLM risk into a Monday-ready control a teacher in this building could follow — mapped onto language the division already has (AUP, volunteer rules, data-privacy), not a new 40-page AI policy.
  9. SEC-11 · on pageCyber Range crossoverWhat skills in this capstone map onto a current Virginia Cyber Range offering and/or CompTIA Security+ objective list — and what gap does the capstone fill that those lists do not?
  10. SEC-12 · on pageDefend your own prior workTake a model or assistant you already built (Applied ML brief, a class project, or a public baseline the teacher names) and apply one mitigation from SEC-01 or SEC-04’s defense menu. Does the original success metric survive, and does the attack-class success rate drop in the same sandbox rules as this track?

After you try a brief

Does your center already have a place for this work?

One question, not a purchase. Helps us know whether a free bank is enough or whether Capstone Pack instruments matter. Product or source issues stay on this page under Feedback.

All twelve tracks

Full brief banks for every specialty track are live today. See the specialty-centers overview for the pathway map.

Feedback

Source moved? Something unclear? Tell us here — you do not have to leave an email.

Optional email gets a confirmation. Please do not include student names.