CS 239: System Security for AI Agents

Fall 2026


Instructor: Sam Kumar

Lecture: MW 2:00-4:00 PM, 5272 Boelter Hall

Office Hours: By appointment, 496B Engineering VI

Course announcements will posted on Piazza.


Course Description

This course will cover recent research on providing security and privacy properties for AI agents, with an emphasis on tool calls and their effects on external systems. Classes will focus primarily on in-depth discussion and analysis of recent research papers and industry systems. Some classes will focus on analyzing older systems research papers that present formative ideas, with a focus on whether they stood the test of time and why, to provide additional context for recent papers. Students will read assigned research papers and online materials, give presentations about one or more of the assigned readings, and complete a project.


Assignments

Grades will be assigned based on the following breakdown: 50% class participation (presentations and discussion), and 50% final project.

Course Format

This is a seminar course focused on reading and discussing research papers. Before coming to class, students should read the assigned research papers for that class. Each class will focus on student presentations and guided discussion of the readings. We will spend the remaining time on lecture or structured discussion in preparation for the next class.


Resources