CHAPTER 01 25 MIN READ BEGINNER

AI and ML Foundations for Security

"AI" shows up in every vendor pitch, every SOC tooling roadmap, and every headline about the next phishing wave, usually without anyone pausing to define it. This chapter builds that shared vocabulary: what AI, machine learning, deep learning, and large language models actually mean, how they relate to each other, and where each one already lives in the security stack. Everything in the rest of this module, from AI-powered phishing to LLM application security to building an AI security program, sits on top of the distinctions made here.

AI terminologymachine learning typeslarge language modelswhy AI matters for defenders
Before you start: This chapter assumes no prior machine learning or data science background. If you can read a phishing report and understand what a false positive is, you have everything you need. The goal is vocabulary and mental models, not math.

What "AI" Actually Means in a Security Context

"AI" gets used as a catch-all for anything that feels automated or clever, which is exactly why the word has stopped being useful on its own. In practice, the term covers a set of nested, overlapping ideas, and knowing which one a vendor or a headline is actually pointing at changes how you should read the claim.

TermWhat it meansHow it relates
Artificial intelligence (AI)Broadest label: any system that performs a task normally associated with human judgment, from flagging a suspicious login to writing a paragraph.A goal, not a specific technique. Even a rules engine blocking known-bad IPs is arguably a primitive AI by the loosest definitions.
Machine learning (ML)The dominant technique for building AI today. Instead of a human writing explicit rules, the system learns patterns from data and predicts on data it has never seen.Subset of AI. Almost everything marketed as "AI" in a security product is ML underneath.
Deep learningUses layered neural networks, loosely inspired by the brain, to learn more complex patterns than older ML techniques could handle.Subset of ML. What made modern image recognition, speech transcription, and language modeling practical.
Large language models (LLMs)Models trained on enormous amounts of text that learn to predict and generate language.Subset of deep learning. Sits behind chat assistants, AI-written phishing emails, and SOC copilots.
The distinction that matters most for this module:
  • Classifier / detector models take an input and output a judgment: malicious or benign, spam or legitimate, anomalous or normal. This style of ML has been inside antivirus engines, EDR platforms, and spam filters for well over a decade. It doesn't create anything, it decides.
  • Generative models, including LLMs and image or voice generators, take a prompt and produce new content: text, code, images, cloned audio. This is the newer, faster-moving category, and it's the one driving most of the current "AI changes everything" conversation.

Keep that split in mind as you move through this module: Chapter 2 is almost entirely about generative AI misused by attackers, while Chapters 4 and 5 use both flavors together, classifiers for detection, generative models for summarization and copiloting. Conflating the two is how you end up either dismissing a real new risk as "just spam filters again" or panicking about a threat model that doesn't actually apply.

Types of ML Relevant to Security Work

You don't need to build models to work in security, just enough vocabulary to read a vendor datasheet critically. Three categories cover almost everything you'll encounter.

ML typeHow it learnsNeeds labeled data?Typical security use
Supervised learningTrained on examples a human already labeled (this file is malware, this email is phishing), then applies that pattern to new data.YesMalware classification, phishing email detection
Unsupervised learningLooks for structure, clusters, or outliers in the data on its own, no labels involved.NoUEBA baselining, anomaly and outlier detection
Reinforcement learningTakes actions in an environment and gets rewarded or penalized for the outcome, refining behavior over many iterations.No (reward signal instead)Autonomous/agentic decision-making systems
Worth knowing:
  • A supervised model is only as good as its training labels, which is why "training data" comes up constantly in any serious conversation about model reliability.
  • UEBA tools are noisy when first deployed because the unsupervised baseline hasn't stabilized yet; they typically quiet down over the following weeks.
  • Reinforcement learning is the least common of the three in day-to-day security tooling, but it shows up in agentic systems making a sequence of decisions rather than a single classification.

The payoff: when a vendor claims "our platform uses AI to detect zero-day threats," you can ask a sharper question, supervised on what labeled dataset, or unsupervised against what baseline? The answer usually tells you more than the marketing copy does.

Where AI Already Sits in the Security Stack

A common misconception: that AI in security started with chat-based assistants. It didn't, ML-driven detection has quietly powered mainstream security tooling for over a decade. What's genuinely new is generative AI, both as something attackers now have cheap access to and as a new category of assistant inside the SOC.

WhereAI/ML techniqueWhat it does
EDR / antivirus behavioral detectionSupervised classifierScores files and process behavior against patterns learned from labeled malware and benign samples
SIEM UEBA modulesUnsupervised anomaly detectionBaselines normal user/host behavior and flags statistical deviations
Email security / spam filtersSupervised classifierScores incoming mail for phishing and spam indicators
SOC copilots and chat-based assistantsGenerative (LLM)Summarizes alerts, drafts queries, explains findings in natural language
Automated malware triage / sandbox reportingMix of classifier and generativeClassifies sample behavior and generates a human-readable summary of the analysis

Classifier and anomaly-detection ML does quiet background work across nearly every security product already in use. Generative AI is the new layer on top, mostly an interface that reads, writes, and explains rather than decides. Both matter, but they are not the same risk or the same opportunity.

Why This Matters Now for Defenders

If AI has been in security tooling for a decade, why does it suddenly deserve an eight-chapter module? Because generative AI changed the economics on three fronts at roughly the same time, and none of them are optional to understand.

FrontWhat changedCovered in
OffenseCheap, scalable access to fluent personalized phishing, synthetic voice for vishing, faster malware iteration, on-demand pretexts. Not new attack categories, just a sharply lower cost and skill floor.Chapter 2
DefenseNew SOC tooling: faster alert triage, incident timeline summarization, hunting queries drafted from plain language, reduced analyst toil.Chapters 4 and 5
Your own AI systemsLLM-integrated apps, copilots, and agents are now infrastructure with their own attack surface: prompt injection, data leakage, over-permissioned agents taking actions they shouldn't.Chapters 3, 6, and 7
Scope of this module:
  • This is not a data science course. You will not train a model or write Python for gradient descent.
  • This is not a prompt-engineering course. Prompting technique is a means to an end here, not the subject.
  • This module teaches the security implications of AI, from both the offense side (what attackers can now do) and the defense side (what defenders can now do, and what they now have to protect).

Module Roadmap

Here's what the remaining seven chapters cover, in order. Each one builds on the vocabulary from this chapter.

2
AI-Powered Threats
How attackers use generative AI for phishing, malware development, and social engineering at scale.
→
3
Prompt Injection & LLM Application Security
How LLM-integrated applications get attacked, and the defenses that actually hold up.
→
4
AI in the SOC (Detection & Triage)
Copilots, alert triage assistants, and where AI genuinely reduces analyst toil.
→
5
AI-Augmented Threat Hunting & Detection Engineering
Using AI to accelerate hunting hypotheses and detection content development.
6
Securing AI/ML Systems
Model theft, AI supply chain risk, MLOps security, and RAG/vector database risk.
→
7
AI Governance, Risk & Compliance
Policy, risk frameworks, and the compliance landscape shaping how organizations adopt AI.
→
8
Building an AI Security Program
Pulling the previous seven chapters into an actual program: people, process, and priorities.

Key Takeaways

  • AI, ML, deep learning, and LLMs are nested, overlapping terms, not separate technologies. LLMs are a product of deep learning, which is a subset of ML, which is a technique for building AI.
  • The distinction that matters most: classifier/detector models judge (malicious vs. benign), generative models create (text, images, audio). AI-powered threats are mostly about generative AI abuse; AI in detection uses both.
  • Supervised learning needs labeled data (malware classifiers), unsupervised learning finds structure without labels (UEBA baselining), and reinforcement learning is less common but relevant to agentic systems.
  • ML-driven detection has been in EDR, antivirus, SIEM UEBA, and spam filters for over a decade. Generative AI is the genuinely new layer, mostly as an interface rather than a decision-maker.
  • AI changes the picture for defenders on three fronts at once: attackers have cheaper access to generative AI, defenders have new AI-assisted tooling, and the organization's own AI systems are a new attack surface to secure.

Knowledge Check

Click an answer to reveal the explanation.

A vendor says their EDR platform uses "AI" to detect malware, and separately, their SOC assistant uses "AI" to summarize incidents. What's the key technical distinction between these two uses?

Classifier/detector models output a judgment on existing input (malicious or benign), which is what malware detection needs. Generative models produce new content, like a natural-language summary, which is what a copilot needs. Both can be built on ML, but they solve fundamentally different problems.

A SIEM's UEBA module flags a user account as anomalous after it starts logging in from an unusual location at unusual hours, without anyone ever telling the system what "malicious login behavior" looks like in advance. Which type of machine learning does this describe?

UEBA baselining is the classic example of unsupervised learning in security tooling. No one labels each historical login as "normal" or "malicious" ahead of time; the model finds structure in the behavior data itself and flags statistical outliers against that self-built baseline.

Which statement best captures why this module treats "AI in security" as more than just a story about generative AI and chatbots?

Supervised and unsupervised ML have quietly powered mainstream security tooling for well over ten years. What's new with the recent AI wave is generative AI, both as an attacker capability and as a SOC assistant layer. Understanding that history keeps you from either overstating how novel "AI in security" is or underestimating what generative AI specifically changes.