Faculty Projects
Modernizing Computer System Security Education for the LLM Era

Yan Chen headshot

Faculty

Yan Chen, CS

Amount Requested

$24,920

Summary

The past several decades have seen an explosion in concern for the security of information. Since 2005, I have offered Northwestern's major system-security courses, including the CS354 Computer System Security, in which students learn security from a hacker's perspective and complete more than a dozen challenging hands-on tasks using cutting-edge tools and techniques. The course has been consistently oversubscribed with almost 100 students.

The rise of large language models (LLMs) has fundamentally changed the landscape this course must prepare students for. LLMs now meaningfully amplify offensive capability: they accelerate reconnaissance, assist in reviewing code for vulnerabilities, scaffold exploit development, generate convincing phishing and social-engineering content, and lower the barrier to entry for attackers at every skill level. They equally transform defense, powering log triage, anomaly detection, automated secure-code review, and incident response. A security curriculum that does not account for these tools is already out of date. Just as importantly, students now carry LLMs on their own laptops, which means many of our existing labs can be completed superficially — without the underlying understanding they were designed to build. We must revise all lab materials to adapt to this change — both to teach students how attackers and defenders actually use LLMs today, and to redesign assignments so they remain rigorous and pedagogically meaningful in a world where AI assistance is universal.

I also serve as the faculty liaison for the student Computer Hacking (CTF) Club, and I am requesting continued support for its activities. The club competes in online capture-the-flag (CTF) competitions and in the Collegiate Cyber Defense Competition, advancing toward the Midwest Regional Collegiate Cyber Defense Competition (MWCCDC) through the Illinois state qualifying event. I regularly receive requests from both students and competition organizers to participate, but these events carry costs — registration fees for the qualifying event and meals during practice and competition sessions — that research grants typically do not cover.

Planned Activities/Investments

Revising the labs for the LLM era (core effort). I will hire my graduate student Yuhao Jiang, who knows both the course materials and the relevant tooling, to lead the redesign. The work includes:

  1. Audit and revise all ten labs and five projects to (a) incorporate how LLMs are used in real offensive and defensive workflows, and (b) restructure tasks so they require genuine understanding rather than answers an LLM can produce unaided.
  2. Add new LLM-focused modules, including LLM-assisted penetration testing and vulnerability discovery, the security of LLM-integrated applications (e.g., prompt injection, jailbreaks, data exfiltration), AI-enhanced phishing and its detection, and the responsible use of LLMs for secure code review and triage.
  3. Build an autograding server to grade assignments at scale, designed to evaluate understanding in ways that resist trivial LLM completion.
  4. Prepare videos and documentation teaching students to use the revised labs and the new LLM-related tooling.

Continued CTF Hacking Club support. As faculty liaison, I will continue to organize and mentor the club, recruit members from the security course, and enter teams in online CTF competitions and in the Collegiate Cyber Defense Competition. Our path runs through the Illinois state qualifier for the Midwest Regional Collegiate Cyber Defense Competition (MWCCDC). The requested support covers the registration fee for the qualifying event and meals for practice and competition sessions — costs that are not covered by research grants.

Impact

This project will significantly benefit Northwestern undergraduates:

  • Curriculum aligned with the current threat landscape. Students will graduate understanding how LLMs are used on both sides of security — a skill set in high demand that will distinguish them on the job market.
  • Rigorous, portable labs. Because the revised labs run on students' own machines, we can grow enrollment toward 100+ without new central infrastructure, while the redesigned autograder preserves educational integrity at scale. We expect to enroll 100+ students in the Computer System Security course.
  • A stronger CTF community. The Computer Hacking Club will remain the hub for students interested in cybersecurity. We will measure impact by club membership and by the number and results of the competitions entered, including the MWCCDC qualifier. Strong showings raise both student engagement and Northwestern's external visibility.

Deliverables

  • Revised, LLM-adapted Computer System Security course materials. All ten labs and five projects, containerized so students can run them on their own machines, together with the new LLM-focused modules, the autograding server, and supporting videos and documentation — enabling enrollment of 100+ students.
  • Sustained Computer Hacking (CTF) Club. Continued operation of the club under faculty-liaison support, with teams entered in online CTF competitions and in the Illinois state qualifier for the Midwest Regional Collegiate Cyber Defense Competition (MWCCDC).

Sustainability

I will use my own funds to maintain the teaching material evolution because it is very related to my own research.

Previous Project

With Murphy Society support in 2016, we modernized the Computer System Security teaching environment and launched the student hacking club. We migrated the course's aging lab environment onto a containerized platform, containerized the ten labs and five projects, converted legacy 32-bit labs to the 64-bit environment, stood up an autograding server, and produced documentation and videos so students could run the labs themselves. We also established the Computer Hacking (CTF) Club, which drew strong student interest and began competing in capture-the-flag events. Together, these investments expanded the course's capacity and created the foundation that the current proposal builds on — now revising the same labs for the LLM era and sustaining the club's competition activities.

Budget Overview

  1. Hire a graduate for one quarter to design and implement the lab infrastructure system:
    1. Stipend (including FB) + tuition = 12,748 + 4,672 = $17,420
  2. Cost to support the activities of Computer Hacking Club:
    1. Buy meals for 30 students when they participate in the cybersecurity competitions, which usually last at least 8 hours (i.e., we need to supply at least one meal): $25/student * 100 students = $2500. We plan to participate in at least two such competitions in the first couple of years. $2500*2 = $5000.
    2. Registration fee for Midwest Regional Collegiate Cyber Defense Competition (MRCCDC): $500
    3. Support students’ travel and meals to attend the MRCCDC competition. $200/student * 10 students = $2000.

Total Budget Amount: $24,920

Matching Funds

This project has committed matching support from two sources:

  • Department of Computer Science. The department has committed to purchase LLM access for its courses, including Computer System Security, ensuring students have the AI tools the revised labs require.
  • PI cost-share. I will contribute at least $2,000 from my NSF CSR project funds toward additional LLM access for the student to hire (Yuhao Jiang) to use for revising the labs.