~/learn

learning.path

A dual major: Autonomous Robotics (the Builder) and Cyber-Physical & Hardware Security (the Breaker). You do not choose between building and breaking. You earn both, on one shared foundation, so each makes the other better.

Laid out like a degree plan: a shared core, the two majors advancing in an interleaved sequence, then a capstone that fuses them. Self-paced and free to follow. Last verified September 2026.

01 how it works

Five rules, one method

  1. 01

    Follow the units in order

    Each unit is a checkpoint. Finish a unit's primary course before moving to the next unit.

  2. 02

    Primary first

    In every unit, do the PRIMARY course first, then the THEN item. SUPPLEMENT items are optional: use them for extra depth or when you are stuck. Do not do all of them.

  3. 03

    Both majors advance together

    Each unit says exactly what to do next in both the Builder and the Breaker track, and the NEXT line points to the following unit.

  4. 04

    Respect the pacing rule

    Never run more than two heavy foundations at once, and never start a course that fights another for the same mental slot before you need it. The order already respects this. Trust it.

  5. 05

    A unit is done when you can prove it

    Not when the video ends. It is done when you have built something, broken something, and can show the evidence.

the method, every unit

  1. MODEL
  2. SIMULATE
  3. BUILD
  4. INSTRUMENT
  5. BREAK
  6. HARDEN
  7. PROVE

02 the map

Two lanes, one machine

The shared core feeds both lanes. The Builder lane carries the middle units, the Breaker lane attaches to real targets as they appear, and the two fuse at Unit 9. Each bar shows the rough workload split.

03 course order

Each major on one page

Flip between the two majors to see the whole sequence at a glance.

null@pack: ~/learn/order

# builder: autonomous robotics, in order

  1. 01 Dartmouth C
  2. 02 LearnCpp
  3. 03 CMake
  4. 04 Georgia Tech Electronics
  5. 05 Arm Embedded Systems
  6. 06 STM32CubeIDE
  7. 07 FreeRTOS
  8. 08 ST Motor Control 1 + 2
  9. 09 Fusion CAD
  10. 10 Statics
  11. 11 KiCad
  12. 12 Modern Robotics
  13. 13 MIT 2.14 Control
  14. 14 ROS 2
  15. 15 Gazebo
  16. 16 ros2_control
  17. 17 ETH Autonomous Mobile Robots
  18. 18 Estimator from scratch
  19. 19 SLAM Toolbox
  20. 20 Nav2
  21. 21 Columbia Computer Vision
  22. 22 CS231n
  23. 23 Secure embedded design
  24. 24 Safe Autonomy
  25. 25 Capstone

# breaker: cyber-physical + hardware security, in order

  1. 01 Your own C failures + GDB
  2. 02 pwn.college Computing 101
  3. 03 RET2 FOSE
  4. 04 Selective pwn.college reps + Ghidra
  5. 05 Hextree hardware/firmware
  6. 06 Selective ROP / allocator reps
  7. 07 Controller + sensor + timing fault tests
  8. 08 ROS graph + network mapping
  9. 09 RET2 ARM Exploitation
  10. 10 ROS 2 security
  11. 11 STM32 secure boot + update
  12. 12 Full robot assessment
  13. 13 Permanent regression suite

04 the units

Eleven checkpoints

Work them in order. Every unit ends with a fused project and an exit gate: pass the gate, then advance both majors together.

unit 00shared corestart here

C & Memory

Start condition Start here. Nothing required.

Learn C properly, including how memory really works. It is the shared foundation for embedded systems, robotics, and exploitation alike.

builder

  1. Finish the full seven-course specialization. Official overview (opens in a new tab).

  2. Course 2. Start here.

  3. Continue immediately after Course 2.

  4. Slow down here. This is the bridge into embedded systems and exploitation.

  5. Focus on structs, enums, binary representation, and interfaces.

  6. Become comfortable living in a shell.

  7. Multi-file programs, files, libraries, Linux tools, Make.

breaker

Before Course 4: use only your own C programs. Compile with AddressSanitizer (opens in a new tab), debug with GDB (opens in a new tab), deliberately create a local fixed-buffer bug, watch it crash, inspect the stack, and then fix it.

After Course 4: begin pwn.college Computing 101 (opens in a new tab) at only 2 to 3 hours per week while Dartmouth stays primary. It is pwn.college's current replacement for its old Assembly Crash Course.

Computing 101 order

  1. Your First Program
  2. Computer Memory
  3. The Stack
  4. Nibbling on Numbers
  5. Software Introspection
  6. Output and Input
  7. Control Flow
  8. Endian Escapades
  9. Assembly Assortment
  10. The Stack, Revisited
  11. Numbers as Strings
  12. Debugging Refresher

Postpone Building a Web Server; it is not required for the low-level path yet.

fused project

Build a binary sensor-packet parser in C: header, sensor ID, timestamp, payload length, payload, checksum, strict length validation, file logging, and tests. After Course 4, inspect its memory in GDB and deliberately test malformed input.

exit gate

Without notes, explain pointer, address, dereference, array layout, struct layout, stack vs heap, allocation and free, segmentation fault, and why an unbounded copy is dangerous. Set a GDB breakpoint, inspect variables and memory, and explain a crash.

next

Unit 1. Begin modern C++ and finish pwn.college Computing 101 in parallel.

unit 01shared core

Modern C++ + Toolchain + Architecture

Start condition Dartmouth courses 1 to 7 complete.

Become fluent across source → compiler → ELF → debugger → disassembly. That single bridge serves ROS 2, firmware, reverse engineering, and exploitation.

builder

breaker

Finish pwn.college Computing 101 (opens in a new tab) first. Do not jump directly into advanced exploitation.

Then install Ghidra (opens in a new tab) from the official project and work through its Getting Started guide (opens in a new tab).

When you are using Ghidra weekly, buy or keep The Ghidra Book, 2nd Edition (opens in a new tab) (March 2026) and use it beside real binaries instead of trying to memorize it.

At the end of this unit, do not begin a second broad pwn.college track as your main course. Your next formal Breaker course is RET2 Fundamentals of Software Exploitation (opens in a new tab). Do not start RET2 ARM yet.

fused project

Rewrite the Unit 0 sensor pipeline in modern C++ with CMake, unit tests, ASan/UBSan, and debug and optimized builds. Then reverse your own optimized binary in Ghidra and recover the parser, the key data structures, and the control flow.

exit gate

You move comfortably through C++ source → CMake → object/ELF → readelf/objdump → GDB → Ghidra → mental reconstruction of the source.

next

Unit 2. Builder moves into electronics and embedded ARM; Breaker begins RET2 FOSE as the primary exploit-development course.

unit 02interleaved

Electronics + Embedded ARM

Start condition Unit 1 exit gate passed.

Connect software to voltage, current, peripherals, registers, interrupts, and real ARM hardware before introducing motors.

builder

  1. Voltage and current, resistors, capacitors, diodes, transistors, op-amps, and practical circuit reasoning before PCB work.

  2. Updated May 2026. Hands-on embedded work on an ST Nucleo F401RE.

  3. GPIO, interrupts, timers and PWM, ADC and DMA, USART, and FreeRTOS exposure in the STM32 ecosystem.

  4. Read alongside your hardware work for architecture, debugging, constraints, interfaces, and embedded design habits.

  5. Later depth on Cortex-M, interrupts, GPIO, timers, serial, power, and TrustZone concepts.

breaker

FOSE teaches 64-bit Linux exploit development in a deliberate progression: C review, x86-64 reverse engineering, memory corruption, shellcoding, stack cookies, return-oriented programming, an IoT mission, ASLR, heap exploitation, other bug classes, race conditions, and a final mission. RET2 expects working C and Python, familiarity with Linux, ELF, and GDB, and some low-level exposure. The earlier units provide exactly that.

Work through FOSE sequentially. Do not rush to ARM just because your Builder hardware is ARM. The point of FOSE is to make the general workflow natural before you specialize in an architecture. While you progress, keep opening your own STM32 firmware in Ghidra so reverse engineering stays tied to systems you built.

Breaker sequence

  1. Dartmouth C
  2. Computing 101
  3. RET2 FOSE
  4. Selective pwn.college reps
  5. Firmware/hardware security
  6. RET2 ARM (later)

Do not subscribe to Hextree yet unless you have already done enough MCU work to probe a physical target. Formal hardware work begins next unit.

fused project

STM32 firmware samples a real I2C or SPI sensor, timestamps it, places readings in a ring buffer, and transmits the Unit 0/1 packet format over UART. Your C++ host app decodes and logs it. Reverse the compiled firmware in Ghidra and identify your strings, your parser, and the peripheral-related functions.

exit gate

Explain sensor electrical output → MCU peripheral/register → interrupt/DMA → C variable → packet bytes → UART → host program. Read basic ARM/Thumb disassembly without treating it as random text.

next

Unit 3. Add RTOS structure, motors, and formal hardware work.

unit 03interleaved

RTOS + Motors + Hardware Hacking

Start condition Working STM32 sensor firmware and basic ARM/Ghidra literacy.

builder

First learn FreeRTOS on the MCU you already understand. Use FreeRTOS (opens in a new tab) and its official docs (opens in a new tab) to learn tasks, queues, mutexes and semaphores, scheduling, priorities, timing, watchdogs, and priority-inversion concepts. Keep Making Embedded Systems beside this work.

  1. Build a simple brushed-DC (or equivalent) encoder loop first

    Measure velocity, command PWM, implement PI/PID, log the error.

  2. The ST motor-control workflow and BLDC/FOC exposure.

  3. Only after the simple loop feels intuitive. Deeper BLDC/PMSM and FOC work.

breaker

Finish pwn.college Reverse Engineering (opens in a new tab).

Now start Hextree Foundational (opens in a new tab) and prioritize its hardware and firmware material. This is the right point to subscribe, because you finally have a real bench and embedded targets.

Buy or keep the Hardware Hacking Handbook companion resources (opens in a new tab) as your structured reference for UART, JTAG/SWD, SPI flash, side channels, and physical debug interfaces.

Add firmware-analysis tools only when a real image needs them: unblob (opens in a new tab), EMBA (opens in a new tab), and the OneKey hands-on firmware workshop (opens in a new tab).

fused project

Build a motor + encoder controller with a fixed-rate control task, PWM, telemetry, an explicit fault state, a command timeout, and a watchdog safe-stop. Then enumerate debug access, inspect the firmware, fuzz the command parser in a software harness, send malformed commands on the bench, and prove malformed input cannot cause uncontrolled motion.

exit gate

Trace command → parser → RTOS task → controller → PWM → power stage → motor torque → encoder → measured state → next cycle, and identify at least five places where an accidental or intentional failure could enter the chain.

next

Unit 4. Design the plant: mechanics, CAD, PCB, and power; then begin formal robotics math and control.

unit 04interleaved

The Plant: Mechanics, CAD, PCB, Power

Start condition Unit 3 motor and control bench works.

Stop treating mechanics, power, and PCB layout as modules somebody else solved, while preparing mathematically for serious robotics.

builder

Mechanical and CAD. Start with the official Autodesk Fusion: Learn Fusion for CAD in 90 Minutes (opens in a new tab) (updated January 2026), then Autodesk's Self-Paced Learning for Fusion (opens in a new tab): sketches, constraints, parametric parts, assemblies, motion, drawings, and 3D-printable design.

Then Georgia Tech: Engineering Mechanics / Statics (opens in a new tab), followed by Mechanics of Materials I (opens in a new tab). You are not becoming a mechanical engineer; you need force, torque, moments, friction, center of mass, shafts and bearings, fasteners, gearing, traction, stiffness, and failure intuition.

PCB design. As of September 2026, learn on the KiCad 10 docs: Getting Started in KiCad (opens in a new tab) and KiCad Learning Resources (opens in a new tab). For a paid structured build afterwards, there is Fedevel: KiCad for Makers (opens in a new tab).

Board progression

  1. Sensor breakout
  2. Small MCU board
  3. Power-aware control board
  4. Robot carrier/control board

Learn decoupling, current return paths, ESD and reverse-polarity protection, connector selection, motor-noise isolation, current sensing, power-tree design, cable and strain relief, ERC/DRC, BOM, and manufacturing outputs.

breaker

Keep one pwn.college session per week. Use your own PCB as the review target: identify SWD/JTAG/UART exposure, which buses carry commands, reset behavior, flash protections, fault points, and how physical access changes the risk picture.

Only after basic Hextree/hardware work should you begin ChipWhisperer Getting Started (opens in a new tab). Do not buy fault-injection equipment without a specific experiment.

fused project

Build the physical differential-drive base: motors, encoders, drivers, your own control/carrier PCB, battery, fuse, hard E-stop, current and battery monitoring, a high-level compute mount, and sensor mounts. Calculate torque, gear ratio, peak current, runtime, and stopping assumptions before construction, then measure the real values.

exit gate

Explain why the chassis, gearing, power tree, PCB, connectors, and safety stop are designed as they are, and identify the physical exposure those choices create.

next

Unit 5. Robotics mathematics and feedback control become the dominant subject.

unit 05interleaved

Robotics Math + Feedback Control

Start condition Unit 4 math-readiness check passed. No new major security course here.

builder

Control sequence

  1. Physical model
  2. Transfer-function intuition
  3. PID / PI
  4. Frequency response
  5. Stability
  6. State space
  7. Observer intuition
  8. Discrete control

breaker

Maintain pwn.college skills lightly. The main Breaker work is now controlled tests of algorithm assumptions: sensor delay, dropped samples, a biased encoder, an incorrect sample period, actuator saturation, command timeout, and scheduler jitter. Plot what happens and find the boundary where performance becomes unsafe or unstable.

fused project

simulated DC motor → real velocity loop → real position loop → simulated cart-pole → mobile-robot heading controller → path tracking. Every run logs target, state estimate, error, actuator command, and actual sample timing.

exit gate

You can derive and explain a controller instead of tuning numbers blindly. Coordinate transforms and robot kinematics are readable. You can state what assumptions make the controller valid and show what happens when they are violated.

next

Unit 6. ROS 2 becomes central only now.

unit 06interleaved

ROS 2 + Simulation + Observability

Start condition Control and robotics fundamentals from Unit 5 are stable.

builder

  1. CLI, workspaces and colcon, C++/Python nodes, topics, services, actions, parameters, custom interfaces, launch, tf2, testing, URDF, RViz, rosbag2, QoS, lifecycle and composition, real-time concepts.

  2. Do not build new work around Gazebo Classic.

  3. Hardware interfaces, the controller manager, differential-drive controller concepts, timing and error handling, simulated vs physical hardware.

Use C++ for production-style robot nodes when practical; use Python for experiments, analysis, tests, and tooling.

breaker

Reconnaissance only. Map your own ROS graph before trying to secure it: which nodes publish commands, which topics carry sensor and state data, which services and actions change behavior, which processes cross the network, what discovery reveals, and what happens when a node disappears. Capture your own lab traffic and relate network messages to robot behavior.

Full SROS 2 hardening is deliberately postponed until Unit 9.

fused project

Build a digital twin: the same high-level interface controls either simulated hardware or your physical base. Record and replay missions with rosbag2. Maintain an architecture diagram of every node, topic, action, service, transform, controller, hardware interface, MCU link, and physical actuator.

exit gate

One command launches a reproducible robot stack, you can explain every interface and frame, and you record enough telemetry to investigate failures instead of guessing.

next

Unit 7. State estimation, SLAM, and navigation.

unit 07interleaved

Estimation, Localization, SLAM, Navigation

Start condition Simulated and physical ROS interfaces are working.

builder

Use the current ETH Zürich: Autonomous Mobile Robots, Spring 2026 (opens in a new tab) as the course model: mobile-robot kinematics, perception, probabilistic environment modeling, localization, mapping, and navigation. Some of its content is institution-gated, so pair it with one of these texts:

Implement these yourself in Python first

  1. Scalar Kalman filter
  2. Small 2D estimator
  3. Wheel odometry
  4. IMU-bias experiment
  5. EKF

Learn covariance, Gaussian models, Bayes, least squares, observability, and timestamp alignment. Then use SLAM Toolbox (opens in a new tab) and Nav2 (opens in a new tab): start with the Nav2 quickstart (opens in a new tab), then the first-time robot setup guide (opens in a new tab), so TF, URDF, odometry, IMU and lidar, EKF, mapping, localization, footprint, costmaps, planners, controllers, and behavior trees all connect.

breaker

Create a repeatable test suite for delayed sensor data, stale TF, missing lidar, biased odometry, bad timestamps, packet loss, false obstacles, estimator reset, and network interruption. For every test record: time-to-detection → unsafe behavior before detection → recovery → residual risk.

fused project

The robot maps a controlled environment, saves the map, localizes, receives a goal, plans, avoids obstacles, recovers from one defined failure, and logs the whole mission. Replay one fault and explain it quantitatively.

exit gate

Answer: What does my robot believe about its state, why does it believe that, how uncertain is the estimate, and what happens when one information source lies?

next

Unit 8. Perception and edge autonomy.

unit 08interleaved

Perception + Edge Compute

Start condition Autonomous navigation already works with simpler sensing.

builder

breaker

Test poor lighting, motion blur, occlusion, incorrect camera calibration, dropped frames, sensor latency, depth holes, false detections, and out-of-distribution scenes. First understand ordinary failure before labeling everything an adversarial-ML problem.

fused project

Build an autonomous behavior that genuinely depends on perception, for example detect target → estimate pose/location → navigate → stop within tolerance → verify the target still exists. Measure accuracy, latency, FPS, compute use, false positives, and failure cases.

exit gate

Explain photons → camera → calibration → image/features/model → estimated state/object → planning decision → physical action, including uncertainty and latency.

next

Unit 9. The Breaker major becomes primary.

unit 09fusion

Cyber-Physical Security

Start condition A complete enough robot stack that attacks and mitigations have physical meaning.

The Breaker major becomes primary: about 65% Breaker, 35% Builder and hardening.

builder

  1. Firmware confidentiality, integrity and authenticity, secure bootloader construction, and secure firmware update. The hands-on course uses the NUCLEO-G071RB (opens in a new tab).

  2. Secure Boot and Secure Firmware Update, plus TrustZone-related work on supported boards.

breaker

Because FOSE already covered the core progression, use the pwn.college Program Security dojo (opens in a new tab) selectively here to close remaining gaps in ROP, allocator misuse, and program exploitation, rather than repeating a whole second curriculum. See also its Program Exploitation module (opens in a new tab).

Only now buy and start RET2 Fundamentals of ARM Exploitation (opens in a new tab): x86-64 fundamentals in FOSE first, then architecture-specific ARM. RET2 expects prior reversing and exploitation familiarity plus C, Python, GDB, ELF, and Linux. See RET2 pricing (opens in a new tab), and check academic pricing if you are eligible.

Continue firmware work with Ghidra (opens in a new tab), unblob (opens in a new tab), EMBA (opens in a new tab), QEMU where appropriate, fuzzing harnesses, and Hextree's hardware material.

ROS 2 communications security. Work through the ROS 2 Lyrical tutorial index (opens in a new tab), the hands-on Examining network traffic (opens in a new tab) tutorial, and the DDS-Security integration design (opens in a new tab). Learn identity, PKI, authentication, permissions, enclaves, access control, encryption, strict vs permissive behavior, and least privilege. Re-check your actual middleware when you arrive.

fused project

Run a full assessment of your own isolated robot. At least one finding must produce a real architectural improvement (command authorization, restricted ROS permissions, secure update, a safer parser, a debug policy, watchdog isolation, or an independent stop) and a permanent regression test.

exit gate

Your report reads like an engineering assessment rather than a CTF diary. You connect a technical failure to its physical consequence and prove the mitigation changes the risk.

next

Unit 10. Safe autonomy, HIL, and the release-grade capstone.

unit 10fusion

Safe Autonomy, HIL, Reliability, Capstone

Start condition The Unit 9 hardening loop is functioning.

builder

Use the current UIUC ECE 484: Principles of Safe Autonomy, Fall 2026 (opens in a new tab) as the course model: perception, modeling, motion planning, control, simulation, and safety analysis. If formal enrollment is available, the online listing (opens in a new tab) is the structured option; otherwise use the public syllabus and reproduce the work on your own robot.

Study system-theoretic safety with MIT's free STPA Handbook materials (opens in a new tab), and learn basic FMEA as the component-level complement.

Verification ladder: every critical behavior climbs it

  1. Unit test
  2. Algorithm simulation
  3. Integrated simulation
  4. SIL
  5. HIL
  6. Bench
  7. Controlled field test
  8. Fault injection
  9. Regression test

breaker

Fault injection is now a regression discipline. Every failure you fix becomes a permanent test. The mature question is no longer only can I compromise it? but can the architecture stay safe when a component is wrong or compromised?

capstone

The capstone above: one robot, two tiers, a full evidence package, and a versioned release.

exit gate

GRADUATE when you can take an unfamiliar autonomous machine and decompose it into mission, environment, plant, mechanics, power, actuators, sensors, embedded controller, buses, timing, estimation, control, middleware, planning, perception, network, trust boundaries, hazards, attack surfaces, and mitigations, and validate that reasoning with code, instruments, simulation, reversing, and physical tests.

next

Electives: take any of the domain-transfer modules, drones first.

05 after the capstone

Electives

Domain-transfer modules, in any order (drones first). Each reuses your core. None is a new degree.

06 spend schedule

Buy it when it is the bottleneck

This exists to stop you buying the whole laboratory before you have the knowledge to use it.

Unit 0Nothing majorYour computer is enough. Finish C.
Unit 1A Tour of C++ (opens in a new tab) if you want a physical reference; The Ghidra Book 2e (opens in a new tab) once Ghidra becomes weeklyBooks now reinforce work you are actually doing.
Unit 2NUCLEO-F401RE (opens in a new tab), breadboard, components, multimeter, basic logic analyzer; Making Embedded Systems 2e (opens in a new tab)Your first real embedded bench.
Unit 3Motor + encoder and a suitable driver; Hardware Hacking Handbook resources (opens in a new tab); start Hextree (opens in a new tab)You now have meaningful embedded targets.
Unit 4Soldering and rework capability, calipers, PCB fabrication, access to 3D printing; an oscilloscope if your measurements now justify itYou are designing the plant and your own boards.
Units 6 to 8Higher-level robot compute, lidar or depth camera, expensive sensorsWait until your stack defines the requirement; the hardware will improve before you get here.
Unit 9RET2 ARM (opens in a new tab) and any course-specific STM32 security board such as the NUCLEO-G071RB (opens in a new tab)Only now have you met the prerequisites and have a cyber-physical target worth securing.

Do not subscribe to paid resources months before their unit. Spend when the course becomes the immediate bottleneck.

07 weekly operating model

A 15-hour week

On a normal 15-hour week, use the unit's weighting instead of forcing a 50/50 split. With only 8 hours, reduce the hours, not the standards, and do not compensate by adding more simultaneous courses.

Builder-heavy unit

  • 8h Builder study
  • 3h Builder lab / project
  • 2h Breaker work
  • 2h Integration / debugging

Balanced unit

  • 5h Builder study
  • 3h Builder lab
  • 4h Breaker study / lab
  • 3h Fused project

Breaker-heavy unit

  • 7h Breaker course / lab
  • 3h Security assessment
  • 3h Builder hardening
  • 2h Docs + regression tests

08 continuous

Runs the whole way

Finish both majors and they stop being two tracks. They become one complete way of seeing a machine: how it works, and where it breaks.