| Semester | Winter 2025 |
| Course type | Block Seminar |
| Lecturer | Prof. Dr. Wressnegger |
| Audience | Informatik Master & Bachelor |
| Credits | 4 ECTS |
| Room | 148, Building 50.34 |
| Language | English |
| Link | TBA |
| Registration | TBA |
This seminar is concerned with different aspects of adversarial machine learning. Next to the use of machine learning for security, also the security of machine learning algorithms is essential in practice. For a long time, machine learning has not considered worst-case scenarios and corner cases as those exploited by an adversarial nowadays.
The module introduces students to the recently extremely active field of attacks against machine learning and teaches them to work up results from recent research. To this end, the students will read up on a sub-field, prepare a seminar report, and present their work at the end of the term to their colleagues.
Topics include but are not limited to adversarial examples, model stealing, and membership inferences against large language models or text-to-image generative models.
| Date | Step |
| Mon, 27. Oct, 14:00–15:30 | Kick-off & Topic presentation |
| Wed, 29. Oct, 11:59 (noon) | Send topic selection(assignment happens till 15:00) |
| Thu, 30. Oct, 11:59 (noon) | Officially register for assigned topic (missed opportunities will be reassigned to waiting list till 15:00) |
| Mon, 03. Nov, 14:00–15:30 | Optional unit on "How to Ace the Seminar" |
| Tue, 04. Nov | Arrange appointments with assistant |
| Mon, 17. Nov - Tue, 18. Nov | 1st individual meeting (Provide first overview and ToC) |
| Mon, 15. Dec - Tue, 16. Dec | 2nd individual meeting (Feedback on draft report) |
| Mo, 12. Jan | Submit final paper |
| Mon, 26. Jan | Submit review for fellow students |
| Tue, 27. Jan, 14:00–18:00 | PC discussion meeting |
| Tue, 10. Feb | Submit camera-ready version of your paper |
| Thu, 19. Feb, 11:30–17:15 | Presentation at final colloquium |
News about the seminar, potential updates to the schedule, and additional material are distributed using the course's matrix room. Moreover, matrix enables students to discuss topics and solution approaches.
You find the link to the matrix room on ILIAS.
Every student may choose one of the following topics. For each of these, we additionally provide recent top-tier publications that serve as the basis for the seminar report. For the seminar and your final report, you should not merely summarize these papers, but try to go beyond and arrive at your own conclusions.