CMSC818I: Advanced Topics in Computer Systems; Large Language Models, Security, and Privacy

Classroom: IRB 2107 Class hours: Monday and Wednesday, 3:30pm - 4:45pm

Instructor: Yizheng Chen Email: yzchen@umd.edu Office Hours: Monday 4:45 - 5:45pm, in IRB 5224

TA: Abhinav Rao Email: asura@umd.edu Office Hours: Wednesday 12pm - 1pm, in IRB 5112

Lectures

Date Topic Paper
08/31 Introduction Syllabus
09/02 Background, Prompt Injection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Defeating Prompt Injections by Design
09/07 Labor Day
09/09 LLM Memorization and Data Leakage BenchChecker: Assessing the Credibility of Bug-Fixing Benchmarks for LLMs
09/14 Secure Code Generation Give LLMs a Security Course: Securing Retrieval-Augmented Code Generation via Knowledge Injection
09/16 Secure Code Generation Securing Retrieval-Augmented Code Generation via Contextual Knowledge Injection: A Case for Embedded IoT Applications
09/21 Privacy Agent Tools Orchestration Leaks More: Dataset, Benchmark, and Mitigation
09/23 Privacy Privacy Reasoning in Ambiguous Contexts
09/28 Agent Tool Use Les Dissonances: Cross-Tool Harvesting and Polluting in Pool-of-Tools Empowered LLM Agents
09/30 Agent Tool Use AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
10/05 Package Hallucinations We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
10/07 Package Hallucinations Evaluating Inference-Time Defenses Against Package Hallucination in LLM-Generated Code
10/12 Fall Break
10/14 Model Backdoor Your Compiler is Backdooring Your Model: Understanding and Exploiting Compilation Inconsistency Vulnerabilities in Deep Learning Compilers
10/19 Vulnerability Detection Patch-Guided Vulnerability Detection: Extracting Java API Security Rules via Attack–Defense Cross-Analysis
10/19 Midterm Project Report Due
10/21 RL for Fuzzing Specializing Language Models for Textual Fuzzing via Reinforcement Learning
10/26 Vibe-Coded Applications Understanding the (In)Security of Vibe-Coded Applications
10/28 Agentic Workflow Comment and Control: Hijacking Agentic Workflows via Context-Grounded Evolution
11/02 Malicious agent skills Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware
11/04 Malicious agent skills No Attack Required: Semantic Fuzzing for Specification Violations in Agent Skills
11/09 Agent Social Network WeClawArena: An Auditable Sandbox and Benchmark for Cross-User Agents Collaboration and Security in Human-Centered Agent Networks
11/11 Agent Social Network “Humans welcome to observe”: A First Look at the Agent Social Network Moltbook
11/16 Evolving Coding Agents Your Agent May Misevolve: Emergent Risks in Self-evolving LLM Agents
11/18 Evolving Coding Agents EVOMAL: Self-Poisoning in Self-Evolving Coding Agents
11/23 Thanksgiving break
11/25 Thanksgiving break
11/30 Project Presentation
12/02 Project Presentation
12/07 Project Presentation
12/09 Project Presentation
12/14 Final Project Report Due