AI and ML Foundations for Security
"AI" shows up in every vendor pitch, every SOC tooling roadmap, and every headline about the next phishing wave, usually without anyone pausing to define it. This chapter builds that shared vocabulary: what AI, machine learning, deep learning, and large language models actually mean, how they relate to each other, and where each one already lives in the security stack. Everything in the rest of this module, from AI-powered phishing to LLM application security to building an AI security program, sits on top of the distinctions made here.
What "AI" Actually Means in a Security Context
"AI" gets used as a catch-all for anything that feels automated or clever, which is exactly why the word has stopped being useful on its own. In practice, the term covers a set of nested, overlapping ideas, and knowing which one a vendor or a headline is actually pointing at changes how you should read the claim.
| Term | What it means | How it relates |
|---|---|---|
| Artificial intelligence (AI) | Broadest label: any system that performs a task normally associated with human judgment, from flagging a suspicious login to writing a paragraph. | A goal, not a specific technique. Even a rules engine blocking known-bad IPs is arguably a primitive AI by the loosest definitions. |
| Machine learning (ML) | The dominant technique for building AI today. Instead of a human writing explicit rules, the system learns patterns from data and predicts on data it has never seen. | Subset of AI. Almost everything marketed as "AI" in a security product is ML underneath. |
| Deep learning | Uses layered neural networks, loosely inspired by the brain, to learn more complex patterns than older ML techniques could handle. | Subset of ML. What made modern image recognition, speech transcription, and language modeling practical. |
| Large language models (LLMs) | Models trained on enormous amounts of text that learn to predict and generate language. | Subset of deep learning. Sits behind chat assistants, AI-written phishing emails, and SOC copilots. |
- Classifier / detector models take an input and output a judgment: malicious or benign, spam or legitimate, anomalous or normal. This style of ML has been inside antivirus engines, EDR platforms, and spam filters for well over a decade. It doesn't create anything, it decides.
- Generative models, including LLMs and image or voice generators, take a prompt and produce new content: text, code, images, cloned audio. This is the newer, faster-moving category, and it's the one driving most of the current "AI changes everything" conversation.
Keep that split in mind as you move through this module: Chapter 2 is almost entirely about generative AI misused by attackers, while Chapters 4 and 5 use both flavors together, classifiers for detection, generative models for summarization and copiloting. Conflating the two is how you end up either dismissing a real new risk as "just spam filters again" or panicking about a threat model that doesn't actually apply.
Types of ML Relevant to Security Work
You don't need to build models to work in security, just enough vocabulary to read a vendor datasheet critically. Three categories cover almost everything you'll encounter.
| ML type | How it learns | Needs labeled data? | Typical security use |
|---|---|---|---|
| Supervised learning | Trained on examples a human already labeled (this file is malware, this email is phishing), then applies that pattern to new data. | Yes | Malware classification, phishing email detection |
| Unsupervised learning | Looks for structure, clusters, or outliers in the data on its own, no labels involved. | No | UEBA baselining, anomaly and outlier detection |
| Reinforcement learning | Takes actions in an environment and gets rewarded or penalized for the outcome, refining behavior over many iterations. | No (reward signal instead) | Autonomous/agentic decision-making systems |
- A supervised model is only as good as its training labels, which is why "training data" comes up constantly in any serious conversation about model reliability.
- UEBA tools are noisy when first deployed because the unsupervised baseline hasn't stabilized yet; they typically quiet down over the following weeks.
- Reinforcement learning is the least common of the three in day-to-day security tooling, but it shows up in agentic systems making a sequence of decisions rather than a single classification.
The payoff: when a vendor claims "our platform uses AI to detect zero-day threats," you can ask a sharper question, supervised on what labeled dataset, or unsupervised against what baseline? The answer usually tells you more than the marketing copy does.
Where AI Already Sits in the Security Stack
A common misconception: that AI in security started with chat-based assistants. It didn't, ML-driven detection has quietly powered mainstream security tooling for over a decade. What's genuinely new is generative AI, both as something attackers now have cheap access to and as a new category of assistant inside the SOC.
| Where | AI/ML technique | What it does |
|---|---|---|
| EDR / antivirus behavioral detection | Supervised classifier | Scores files and process behavior against patterns learned from labeled malware and benign samples |
| SIEM UEBA modules | Unsupervised anomaly detection | Baselines normal user/host behavior and flags statistical deviations |
| Email security / spam filters | Supervised classifier | Scores incoming mail for phishing and spam indicators |
| SOC copilots and chat-based assistants | Generative (LLM) | Summarizes alerts, drafts queries, explains findings in natural language |
| Automated malware triage / sandbox reporting | Mix of classifier and generative | Classifies sample behavior and generates a human-readable summary of the analysis |
Classifier and anomaly-detection ML does quiet background work across nearly every security product already in use. Generative AI is the new layer on top, mostly an interface that reads, writes, and explains rather than decides. Both matter, but they are not the same risk or the same opportunity.
Why This Matters Now for Defenders
If AI has been in security tooling for a decade, why does it suddenly deserve an eight-chapter module? Because generative AI changed the economics on three fronts at roughly the same time, and none of them are optional to understand.
| Front | What changed | Covered in |
|---|---|---|
| Offense | Cheap, scalable access to fluent personalized phishing, synthetic voice for vishing, faster malware iteration, on-demand pretexts. Not new attack categories, just a sharply lower cost and skill floor. | Chapter 2 |
| Defense | New SOC tooling: faster alert triage, incident timeline summarization, hunting queries drafted from plain language, reduced analyst toil. | Chapters 4 and 5 |
| Your own AI systems | LLM-integrated apps, copilots, and agents are now infrastructure with their own attack surface: prompt injection, data leakage, over-permissioned agents taking actions they shouldn't. | Chapters 3, 6, and 7 |
- This is not a data science course. You will not train a model or write Python for gradient descent.
- This is not a prompt-engineering course. Prompting technique is a means to an end here, not the subject.
- This module teaches the security implications of AI, from both the offense side (what attackers can now do) and the defense side (what defenders can now do, and what they now have to protect).
Module Roadmap
Here's what the remaining seven chapters cover, in order. Each one builds on the vocabulary from this chapter.
Key Takeaways
- AI, ML, deep learning, and LLMs are nested, overlapping terms, not separate technologies. LLMs are a product of deep learning, which is a subset of ML, which is a technique for building AI.
- The distinction that matters most: classifier/detector models judge (malicious vs. benign), generative models create (text, images, audio). AI-powered threats are mostly about generative AI abuse; AI in detection uses both.
- Supervised learning needs labeled data (malware classifiers), unsupervised learning finds structure without labels (UEBA baselining), and reinforcement learning is less common but relevant to agentic systems.
- ML-driven detection has been in EDR, antivirus, SIEM UEBA, and spam filters for over a decade. Generative AI is the genuinely new layer, mostly as an interface rather than a decision-maker.
- AI changes the picture for defenders on three fronts at once: attackers have cheaper access to generative AI, defenders have new AI-assisted tooling, and the organization's own AI systems are a new attack surface to secure.
Knowledge Check
Click an answer to reveal the explanation.
A vendor says their EDR platform uses "AI" to detect malware, and separately, their SOC assistant uses "AI" to summarize incidents. What's the key technical distinction between these two uses?
A SIEM's UEBA module flags a user account as anomalous after it starts logging in from an unusual location at unusual hours, without anyone ever telling the system what "malicious login behavior" looks like in advance. Which type of machine learning does this describe?
Which statement best captures why this module treats "AI in security" as more than just a story about generative AI and chatbots?