Teaching Adversarial Thinking by Having Students Circumvent Exam Rules
摘要
This paper describes a live exercise in adversarial thinking, deployed as part of an advanced undergraduate module: Security of Real World Systems. Delivered as a mock exam, students must answer a single question given two weeks in advance: write the first sixty digits of \(\pi \) . We present a student attacker model, from which we construct a set of exam rules, all containing deliberate oversights. Students must analyse the rules for vulnerabilities, develop a solution, and successfully deploy it in a mock exam invigilated by the module team. We describe how we handled communication with students, invigilation, and marking such an exercise. We run an educational evaluation, categorise student solutions, and gauge student opinions on the exercises from feedback on the module, as well as a direct focus group. Finally, we discuss some more salient lessons from the exercise and how we might address them as we take our work forward.