A reading list for breaking (and fixing) AI systems
A curated index of papers, tools, and talks on adversarial attacks, model theft, and AI agent security—essentially a field guide to everything that can go wrong once you deploy machine learning.

What it does This is an “awesome list”—a hand-maintained index of research papers, code repositories, videos, and slide decks covering the security of AI systems. It catalogs adversarial examples, evasion and poisoning attacks, model extraction, and newer concerns like LLM agent vulnerabilities and supply-chain risks for AI skills.
The interesting bit The list spans from foundational 2014 papers (Goodfellow’s seminal adversarial examples work) through to 2025 preprints on backbone LLM security in AI agents. That decade-plus arc makes it useful for tracing how academic curiosity hardened into practical attack surface. The icon-based categorization (research, code, video, slides) is a small but genuine time-saver.
Key highlights
- Covers adversarial examples, evasion attacks, poisoning, model inversion, and feature-selection vulnerabilities
- Includes tooling:
CleverHans,Foolbox,DeepFool, plus newer entries like agent security scannerClawMoatand confidential deployment frameworkdstack - Recently expanded to LLM-specific risks: prompt injection, jailbreaks, memory poisoning, and agent skill supply-chain verification (
SkillFortify) - Links to canonical talks (Ian Goodfellow at Stanford, DEF CON 25 on evading next-gen AV)
- Inspired by and cross-referenced with earlier adversarial-ML and ML-for-cybersecurity lists
Caveats
- Curation appears sporadic: heavy 2016–2018 research concentration, with only scattered newer additions
- No quality grading or annotation beyond type icons—signal-to-noise filtering is left to the reader
- Some links point to arXiv preprints that may have since been superseded or retracted
Verdict Worth bookmarking if you’re doing security research, red-teaming ML systems, or need to onboard a team to the adversarial-ML literature. Skip it if you want executable frameworks or curated tutorials—this is a bibliography with light organization, not a course.
Frequently asked
- What is DeepSpaceHarbor/Awesome-AI-Security?
- A curated index of papers, tools, and talks on adversarial attacks, model theft, and AI agent security—essentially a field guide to everything that can go wrong once you deploy machine learning.
- Is Awesome-AI-Security open source?
- Yes — DeepSpaceHarbor/Awesome-AI-Security is an open-source project tracked on heatdrop.
- How popular is Awesome-AI-Security?
- DeepSpaceHarbor/Awesome-AI-Security has 1.6k stars on GitHub.
- Where can I find Awesome-AI-Security?
- DeepSpaceHarbor/Awesome-AI-Security is on GitHub at https://github.com/DeepSpaceHarbor/Awesome-AI-Security.