PhD Proposal: A Multi-Stakeholder Qualitative Analysis of the Current and Future Role of AI in Security and Privacy Education
The rapid adoption of artificial intelligence (AI) is reshaping how novice and professional developers learn and practice security and privacy (S&P) skills. However, there is limited empirical understanding of how AI influences the development of foundational security competencies, particularly among students at the undergraduate level. This work investigates how AI is impacting S&P skill acquisition and how educational curricula should be updated to better prepare S&P students to become professionals in the AI era.
I begin by presenting findings from interviews with undergraduate students and professors who have taken or taught a S&P class, characterizing their perceptions and usage of LLMs. Building on these insights, I extend my investigation to security professionals to better understand how LLMs are reshaping expectations for skills and workplace practices. Drawing on these qualitative findings, I design an AI-integrated teaching method aimed at supporting the development of core S&P competencies needed for success in a security career while integrating AI as a learning tool. I evaluate the AI-integrated teaching method through a controlled experimental study, measuring its effectiveness in improving learners’ ability to reason about security problems, identify vulnerabilities, and apply best practices.
This work contributes (1) an understanding of students’ and instructors’ perceptions and use of AI in the S&P classroom, (2) an understanding of security professionals’ perceptions and use of AI in the S&P workforce, and (3) a validated approach for integrating AI into S&P curricula to better prepare students for the workforce. These findings carry implications for the design of security curricula and the integration of AI tools in computing education more broadly, offering guidance to key stakeholders, including educators and LLM designers.