Subject

Privacy, Security and Trust in Machine Learning Systems

1. Course Title Privacy, Security and Trust in Machine Learning Systems
Privacy, Security, and Trust in Machine Learning Systems
2. Code m23_w_055
3. Study Programme
4. Organizer of the study programme (unit, institute, department or division) Faculty of Computer Science and Engineering
5. Degree level (first, second, third cycle) Second cycle
6. Academic year / semester 9 / Winter
7. Number of ECTS credits 6
8. Teacher Riste Stojanov, Sasho Gramatikov
9. Prerequisites for enrolling in the course
10. Objectives of the course programme (competences) The goal of this course is to introduce the fundamental risks that arise when incorporating machine learning into software systems, and the attacks that can be used to compromise their integrity, security, and authority. In addition to attacks, strategies for protecting systems from these most common attacks will be examined. The second part of the course will address the challenges faced by the vast majority of systems that use machine learning, namely how to protect the privacy of the data used during their training. The final part of the course will focus on how to increase the trust in machine learning systems by reviewing techniques for explaining their results.
11. Course content Introduction to security dimensions, concepts, and methods. Security from the perspective of machine learning. Threats in machine learning solutions. Attacks on machine learning. Selection of an appropriate defense solution. Issues with trust in machine learning results and possible solutions.
12. Learning methods Lectures supported by slide presentations, interactive lectures, practical classes (using equipment and software packages), teamwork, case studies, guest lecturers, independent preparation and defence of a project assignment and seminar paper, and learning in an electronic environment (forums and consultations).
13. Total available time 6 ECTS x 30 hours = 180 hours
14. Distribution of available time 45 + 15 + 30 + 50 + 40 = 180 hours
15. Forms of teaching activities
15.1. Lectures - theoretical instruction 45 hours
15.2. Exercises (laboratory, auditory), seminars, teamwork 15 hours
16. Other forms of activities
16.1. Project assignments 50 hours
16.2. Independent assignments 30 hours
16.3. Home study 40 hours
17. Assessment method
17.1. Tests 45 points
17.2. Seminar paper / project (presentation: written and oral) 50 points
17.3. Activities and learning 10 points
17.4. Final exam 0 points
18. Grading criteria (points / grade)
up to 50 points5 (five) (F)
from 51 to 60 points6 (six) (E)
from 61 to 70 points7 (seven) (D)
from 71 to 80 points8 (eight) (C)
from 81 to 90 points9 (nine) (B)
from 91 to 100 points10 (ten) (A)
19. Requirement for obtaining a signature and taking the final exam completed activities
20. Language of instruction Macedonian and English
21. Method for monitoring the quality of teaching internal evaluation and survey mechanism
22. Literature
22.1. Required literature
1. J. Morris Chang, Di Zhuang, G. Dumindu Samaraweera | Privacy-Preserving Machine Learning | Manning | 2023
2. Jin Li, Ping Li, Zheli Liu, Xiaofeng Chen, Tong Li | Privacy-Preserving Machine Learning | Springer | 2022
3. Yevgeniy Vorobeychik, Murat Kantarcioglu | Adversarial Machine Learning | Springer | 2022
4. Anthony D. Joseph, Blaine Nelson, Benjamin I. P. Rubinstein, J. D. Tygar | Adversarial Machine Learning | Cambridge University Press | 2019
5. Tianqing Zhu, Gang Li, Wanlei Zhou, Philip S. Yu | Differential Privacy and Applications | Springer | 2017
6. Christoph Molnar | Interpretable Machine Learning | Leanpub | 2020
22.2. Additional literature
No. Author Title Publisher Year