Data Privacy (Fall 2026)

Course overview

This course asks how we can build useful data and AI systems without exposing the people behind them. For three real privacy failures and the defenses that answer them, see Why take this course?.

Who should enroll?

This course is open to all undergraduates.

Required preparation:

Helpful UVA courses, but not prerequisites:

No prior coursework in privacy, cybersecurity, machine learning, cryptography, or AI is required.

The optional readiness self-check gives a concrete picture of the programming, probability, and ML ideas used at the start of the course. It is ungraded and is not an enrollment requirement.

Course info

Announcements and assignment updates appear in Canvas. Use Canvas Inbox or email for questions that involve grades, accommodations, or other private matters.

Grading

Schedule

Week Tue Thu Milestones
01Aug 24-28

Course introduction

Privacy definitions and attack taxonomy

Readiness check
02Aug 31-Sep 4

Extraction and memorization

Membership inference and attack evaluation

03Sep 7-11

Privacy attacks: conclusions and discussion

Security notions and adversarial ML overview

Lab 1 out
04Sep 14-18

Adversarial examples and robustness

Poisoning and backdoor threats

05Sep 21-25

No class: September 22

ML security defenses and LLM agent privacy surfaces

Lab 1 due · Lab 2 out
06Sep 28-Oct 2

Anonymization, linkage, and k-anonymity

Differential privacy: definitions and sensitivity

07Oct 5-9

No class: Fall Reading Days

Project pitch presentations

Project pitch
08Oct 12-16

Guest lecture: TEEs and confidential LLM serving

Closed-book paper Quiz 1

Quiz 1
09Oct 19-23

Laplace and Gaussian mechanisms

Composition, privacy accounting, and private selection

Lab 2 due · Lab 3 out
10Oct 26-30

Private learning: DP-SGD

PETs and symmetric-key cryptography: hashes and MACs

Project proposal
11Nov 2-6

No class: Election Day

Public-key cryptography and Diffie-Hellman

12Nov 9-13

RSA, digital signatures, and timing attacks

Secure multiparty computation: garbled circuits and oblivious transfer

Lab 3 due · Lab 4 out
13Nov 16-20

Guest lecture: oblivious RAM (ORAM)

Closed-book paper Quiz 2

Quiz 2
14Nov 23-27

MPC: secret sharing and security models

No class: Thanksgiving recess

15Nov 30-Dec 4

Guest lecture: privacy in industry

Homomorphic encryption and private computation

Lab 4 due
16Dec 7-11

Poster/demo session and course recap

No class: finals period

Poster/demo · Final report

More resources

AI access

Courses

Core differential privacy

Broader privacy, systems, and machine learning

Tutorials and practical guidance

Software

Lab and course libraries

Additional libraries

Books

Cryptography & MPC

Differential privacy