(in Polish) Cyberprzestępczość w erze sztucznej inteligencji 2100-BW-L-D5CPES-CP
The course comprises three connected parts. The first introduces language models, image, audio and video generation, open and closed models, agentic tools, and the formulation and control of prompts. The second presents the conventional cybercrime environment: social engineering, offenders and APT groups, Internet subcultures, hidden networks, darknet markets, data leaks, cryptography and anonymisation. Each area is examined in relation to AI capabilities and limitations.
The third part concerns criminal and defensive uses of AI: deepfake and voice-cloning fraud, automated reconnaissance, support for cyberattacks, attacks on AI systems, incident detection and countermeasure planning. Students examine domestic and international crime relationships, distinguish source findings from attribution hypotheses and develop recommendations. Legal frameworks are discussed using primary legal texts, including their scope and application dates.
Student workload
Class attendance, including presentations and final assessment: 30 hours.
Reading and regular preparation: 6 hours.
Project preparation and documentation of individual contributions: 6 hours.
Preparation for the final assessment: 8 hours.
Total workload: 50 hours; 2 ECTS credits.
The workload uses approximately 25 hours per ECTS credit, in accordance with the WNPiSM guide. Presentations and assessment are included in the 30 contact hours and are not counted twice.
Course coordinators
Mode
Prerequisites (description)
Learning outcomes
W1–U4 identify course learning outcomes; K_W and K_U codes refer to the degree programme. The programme assigns three knowledge outcomes and four skills outcomes to this course.
W1 / K_W03: Characterises at an advanced level the internal-security problems and challenges associated with AI development and classifies its cybercrime applications.
W2 / K_W07: Explains at an advanced level the mechanisms, transformations and consequences of threats involving criminal AI use and attacks on AI systems, and methods of detecting and mitigating them.
W3 / K_W08: Explains at an advanced level relationships between local, national, regional and global threats, including APT groups, data flows and transnational criminal networks.
U1 / K_U02: Plans and organises a small analytical team's work, agrees task allocation, leads a selected analytical stage, and documents personal contributions and cooperation.
U2 / K_U03: Analyses a typical or atypical AI-related cybercrime case, compares countermeasures and justifies a solution while considering its limitations.
U3 / K_U04: Applies an analytical, cryptographic or privacy-protection tool to a specific task, documents the result and explains its security significance.
U4 / K_U07: Independently updates knowledge using reliable sources, compares earlier and more recent findings on AI and cybercrime, and applies them to an analytical problem.
Assessment criteria
Attendance and absences
Attendance is required. Two absences from two-hour meetings are permitted. Attendance carries no points and does not affect the grade. Absence does not waive learning outcomes or assessment submissions.
For absences beyond this allowance, students complete an individual task covering the missed material. An explanation or supporting document must be submitted within 14 days of returning to class. The replacement task is due within 14 days of being assigned, and before the course is assessed; justified exceptions are arranged individually.
Assessment components and pass requirements
Individual written final test: 60%; outcomes W1, W2 and W3.
Pair project with individual assessment of contributions and a practical task: 40%; outcomes U1, U2, U3 and U4.
A pass requires all of the following: at least 19/36 test points, at least 21/40 project points, the minimum for every outcome specified below, and compliance with formal requirements. The weighted total cannot compensate for failure to achieve an individual outcome.
Knowledge test
The test at meeting 15 lasts 45 minutes and contains 21 questions: 16 single-choice questions worth 1 point each and 5 open questions worth 4 points each. The maximum raw score is 36. Each open question specifies four answer elements; each correctly completed element receives 1 point. There are no negative points.
W1 / K_W03: 8 closed and 1 open question; maximum 12, minimum 6 points.
W2 / K_W07: 4 closed and 2 open questions; maximum 12, minimum 6 points.
W3 / K_W08: 4 closed and 2 open questions; maximum 12, minimum 6 points.
Overall: maximum 36, minimum 19 points.
Students work independently without notes, Internet access or AI tools. With integer points, 19/36 satisfies the requirement of at least 51%; each knowledge outcome additionally requires 6/12.
Pair project
The case study comprises a written analysis of at least six standard manuscript pages (at least 10,800 characters including spaces, excluding references and appendices) and an 8–10 minute presentation. Topics are selected from topics 12–14 or proposed by students and approved at least two weeks before presentation. The written work and appendices are submitted no later than the day before presentation, through the channel specified at the first meeting.
The analysis contains: (1) the event, actors, scale and consequences; (2) AI's role and stage of use; (3) mechanisms and evidence assessment; (4) attribution and legal context; (5) comparison of at least two countermeasures and a justified recommendation. At least three independent reliable sources, citations, a consistent APA reference list and limitations are required.
Each person documents their contribution to all four assessed areas. Each leads one stage of analysis; the pair records tasks, deadlines and agreements. Each performs a tool-based task associated with the project or exercises from topics 8 or 11, documenting its procedure and result. Each compares an older and a newer reliable source and explains how the update changes the analysis or recommendation.
Project criteria: four areas worth 0–10 points each.
U1 — organisation and cooperation: plan, task allocation, stage leadership, fulfilment of agreements, contribution documentation.
U2 — problem analysis: description and evidence, AI's role, mechanism explanation, comparison of solutions, recommendation.
U3 — practical task: tool selection, execution, correctness of result, reproducibility, interpretation of limitations.
U4 — updating knowledge: finding a source, credibility assessment, comparison over time, application of conclusions, identification of further needs.
Each of the five elements in an area receives 0–2 points: 0 — missing or incorrect; 1 — basic and correct but incomplete; 2 — complete, correct and justified. Each area requires at least 5/10 and the project at least 21/40 overall. U1 requires evidence of stage leadership and cooperation; U3 requires actual task execution; U4 requires application of updated knowledge. Each mandatory element must receive at least 1 point.
Grades are individual, based on the work, appendices, observed cooperation and the author's explanations. One member may deliver the presentation; the other documents their contribution and answers questions in writing or individually. The number of presentations or vaguely defined participation is not graded.
Final score and grading scale
W = 60 × (T / 36) + P, where T is the raw test score (0–36) and P the project score (0–40). W ranges from 0 to 100. Grades use the unrounded score; two decimal places may be shown for information.
W < 51: 2.0 (fail).
51 ≤ W < 61: 3.0 (satisfactory).
61 ≤ W < 71: 3.5 (satisfactory plus).
71 ≤ W < 81: 4.0 (good).
81 ≤ W < 91: 4.5 (good plus).
91 ≤ W ≤ 100: 5.0 (very good).
A pass requires all outcome minima and both component thresholds. Falling below any minimum results in a fail regardless of W.
Independent work and sources
Students identify quotations and sources, distinguish findings, hypotheses and AI-generated content, and are responsible for the accuracy of their submissions. Team assignments identify tasks and authorship. Students must not claim another person's findings or work as their own.
Exercises use openly and lawfully available sources and training materials. Personal data protection, data minimisation and copyright must be respected. Unauthorised access to systems or data and obtaining illegal content are not assignment requirements. Data-leak analysis uses public reports or anonymised training materials.
Use of artificial intelligence
Project preparation uses level 3 of the five-level scale in Annex 2 to Resolution 29/2025 of the WNPiSM Teaching Council: AI may help improve a student's own work, especially editing, language and clarity. Case analysis, source selection and conclusions remain the authors' independent work. Students retain the version produced before AI use and disclose the tool, date, scope and manner of use. AI-generated content must not replace their own analysis.
Designated exercises examining models and AI applications permit level 4: performing a partial task with AI and critically assessing the output. The output is identified as material for analysis, not the student's own finding. The final test uses level 1: no AI.
Feedback and resit
Students receive criterion scores and information about unachieved outcomes. One resit is available on a date set by the instructor in accordance with the academic calendar. Students retake a failed test with an equivalent set of questions or improve failed project areas, including required practical or cooperation tasks. The same outcomes, thresholds and criteria apply. Passed components are retained; the new score replaces the previous score for the reassessed component.
Practical placement
Not applicable.
Bibliography
Required readings apply only to the specified scope. Materials M comprise a presentation, instructions and a source package for each topic. The instructor provides them at least seven days before class; organisational materials are provided at the first meeting. Earlier publications establish the foundations and changes over time; current mechanisms are discussed using reports and materials for 2026/2027.
Required readings
C1. Europol. (2023). ChatGPT: The impact of Large Language Models on Law Enforcement. https://www.europol.europa.eu/publications-events/publications/chatgpt-impact-of-large-language-models-law-enforcement
Scope: pp. 3–6, LLM foundations and limitations; pp. 7–9, criminal applications; pp. 10–13, implications and recommendations. The report is analysed in its historical context.
C2. Microsoft Threat Intelligence. (2024, February 14). Staying ahead of threat actors in the age of AI. https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/
Scope: Forest Blizzard, Emerald Sleet and Crimson Sandstorm sections; findings are attributed to the report's authors.
C3. Microsoft Threat Intelligence. (2026, March 6). AI as tradecraft: How threat actors operationalize AI. https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/
Scope: introduction and the sections AI as an enabler for cyberattacks, Emerging trends, and Mitigation guidance for AI-enabled threats; comparison with C1 and C2.
C4. Council of Europe Convention on Cybercrime, Budapest, 23 November 2001 (ETS No. 185). https://www.coe.int/en/web/cybercrime/the-budapest-convention
Scope: Articles 2–11 and 23–25, offence categories and foundations of international cooperation.
C5. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence. https://eur-lex.europa.eu/eli/reg/2024/1689/oj?locale=pl
Scope: Articles 3, 5, 50 and 113, definitions, prohibited practices, transparency and application dates.
M. Mider, D. Course materials for 2026/2027: presentations, workshop instructions, case-analysis sheets and test materials.
Scope: modules corresponding to topics 1–15 in the “Zakres tematów” field.
Supplementary readings and sources
U1. Siwicki, M. (2013). Cyberprzestępczość. C.H. Beck. Conceptual and historical foundations; current law is established from legal texts.
U2. Mitnick, K. D., and Simon, W. L. (2002). The Art of Deception. Wiley. Classical social-engineering mechanisms; Polish edition: Sztuka podstępu, Helion.
U3. Europol. Internet Organised Crime Threat Assessment (IOCTA), successive editions: analyses of trends and criminal environments.
U4. Second Additional Protocol to the Convention on Cybercrime (CETS No. 224, 2022); Directive (EU) 2022/2555 (NIS 2); Polish Criminal Code provisions relevant to the cases analysed. Texts and the scope of provisions are included in M for topic 14.