Fall 2026 syllabus | Planning draft | Updated August 25, 2026
| Item | Details |
|---|---|
| Course | CS 4501-003, Special Topics in Computer Science: Data Privacy |
| Instructor | Tianhao Wang |
| tianhao@virginia.edu | |
| Meetings | Tuesdays and Thursdays, 2:00-3:15 PM |
| Classroom | Olsson Hall 011 |
| Term | August 25-December 8, 2026 |
| Office hours | To be confirmed before the first day of class; appointments will also be available |
| Public course site | tianhao.wang/f26-dataprivacy |
| Canvas | canvas.its.virginia.edu/courses/190753 |
Canvas is the authoritative source for announcements, release bundles, submissions, grades, and any date changes. The public site contains the durable course description, schedule, assignment structure, and policies.
Use Canvas Inbox or email for questions involving grades, accommodations, or other private matters.
How can we use data to build useful systems without exposing the people behind the data? This course studies concrete privacy attacks, practical defenses, and the engineering contracts that connect privacy claims to data, code, configuration, accounting, and tests.
We begin with privacy attacks, then study ML security threats and defenses before returning to anonymization and its limits. We then develop differential privacy and privacy-utility trade-offs, private machine learning, synthetic data, and privacy-enhancing technologies including secure multi-party computation, homomorphic encryption, trusted execution environments, and oblivious RAM. The course is designed for undergraduates with the preparation listed below and emphasizes technical judgment, reproducible evidence, and clear communication rather than graduate-level novelty.
By the end of the course, students should be able to:
This course is open to all undergraduates who have the following preparation:
Required background:
No prior coursework in privacy, cybersecurity, machine learning, cryptography, or AI is required.
At UVA, CS 3710 (Introduction to Cybersecurity) is especially useful preparation for threat modeling and attacks. CS 4774 (Machine Learning) also connects to parts of the material. Neither is a prerequisite.
The optional readiness self-check illustrates the programming, probability, and ML ideas used in the first weeks. It is ungraded, does not determine eligibility to enroll, and includes guidance for reviewing any gaps.
The course combines four forms of work:
Guest lectures will connect course mechanisms to industry privacy practice and recent academic work. Their topics and speakers will be updated on the course schedule as they are confirmed. Students should expect to read short technical material before selected meetings and to work with small CPU-compatible code bundles outside class.
| Component | Weight | Basis |
|---|---|---|
| Labs | 40% | Four labs worth 10% each; selected labs use hidden cases and Lab 2 uses a direct arena |
| Project | 30% | Project pitch 10%, proposal 5%, poster/demo 10%, final report 5% |
| Quizzes | 20% | Two individual, in-class, closed-book paper quizzes at 10% each |
| Exit surveys / check-ins | 10% | Short individual Canvas submissions graded for completion |
| Total | 100% |
Final grades use the UVA grading basis. Exact letter-grade thresholds will be added before this draft becomes the official syllabus.
All labs are completed individually. They deliberately use different work products: a privacy-attack runner, a two-agent secret-arena submission, a regression-tested library extension, and a private-computation artifact with an oral check.
Selected labs use instructor-only hidden cases in addition to visible tests; the number and mix of those cases are not announced. Lab 2 uses direct two-agent matches with a separate hidden utility evaluator. Arena rankings are feedback, not winner-take-all grades; course points use fixed criteria and instructor baselines. Some instances are intentionally clean or contain insufficient evidence, so a correct abstention can receive full credit.
| Lab | Weight | Release week | Due week |
|---|---|---|---|
| Privacy Attack Warm-up | 10% | 3 | 5 |
| Two-Agent Secret Arena | 10% | 5 | 9 |
| DP Library Extension Challenge | 10% | 9 | 12 |
| Compute Without Seeing | 10% | 12 | 15 |
Private materials are distributed through Canvas; any course Drive link will be posted there. Raw notebooks, instances, hidden cases, evaluator files, solutions, and grading files are not published on the public site.
The project contributes 30%. Its topic and method remain open, but it must make an innovative privacy contribution. Students may build a system or focused tool, develop an attack or defense, create a privacy monitor or auditor, or complete a research project whose primary artifact is a paper. Teams of up to 2 are allowed; individual projects may use a narrower scope.
Projects may build on existing papers, libraries, and code, but a reproduction, routine comparison, literature review, mechanical port, or incremental extension alone does not satisfy the requirement. Innovation may come from a new capability, attack, defense, measurement, system boundary, interaction, or research insight. Publication-level novelty is not required, but the proposal must explain what becomes newly possible, measurable, or defensible relative to a meaningful baseline.
The project has no leaderboard, arena, or required peer attack. The in-class project pitch occurs in Week 7, the written proposal serves as a progress and scope checkpoint in Week 10, and the poster/demo and final report are due in Week 16. See the milestone guide and project rubric.
Both quizzes are completed individually during class on paper. They are closed book and closed notes; computers, phones, AI tools, and other electronic aids may not be used. Each quiz combines short foundation and application questions with longer reasoning questions that ask students to certify, refute, or qualify a claim using code, data, or a system description. An instructor-supplied formula sheet and a practice set will be provided before each quiz. The covered topics and any other permitted basic supplies will be announced in advance.
The planned coverage follows the revised lecture schedule:
Guest lectures and optional readings are not part of these quiz scopes. If lectures move again, the announced scope will reflect material actually covered with time to prepare.
Students with an approved absence will receive an equivalent makeup arrangement. The makeup may use different examples while assessing the same skills.
Short individual exit surveys and check-ins submitted through Canvas contribute 10%. They ask students to record a conclusion, identify a remaining question, interpret a small result, or check progress on a current lab or project. Each submission receives credit for timely, good-faith completion.
No required textbook or paid AI subscription is planned. Readings, starter environments, and private assignment bundles will be supplied through Canvas; any course Drive link will be posted there. The public site lists optional books, courses, software, and current AI access options.
UVA students currently have no-additional-cost access to Gemini and NotebookLM and Copilot Chat. Eligible U.S. college students may also claim OpenAI’s 2026 student offer for four free months of ChatGPT Plus by October 31, 2026; it requires student verification and a payment method and renews at the regular monthly price unless canceled. UVA RC GenAI provides Kimi K2.5 to eligible Research Computing users, but RC currently restricts that service to research rather than ordinary class assignments.
Students need regular access to a computer that can run Python and a web browser. Required lab paths are designed for CPU execution with pinned environments. If access to hardware, software, or an assigned format creates a barrier, contact the instructor early so that an equivalent path can be arranged.
Generative AI may be used for brainstorming, debugging, code explanation, and polishing unless an assignment says otherwise. It does not replace technical ownership.
Labs, quizzes, and Canvas exit surveys/check-ins are individual. Projects may be completed individually or in teams of up to 2. High-level discussion across the class is welcome, but students may not share lab code, completed tables, polished written answers, arena submissions, or private arena feedback. Every submission must identify permitted collaborators; project teams must include a contribution statement where required.
Students are expected to follow the University Honor Code and its guidance on academic fraud. Uncertainty about permitted collaboration or AI use should be resolved with the instructor before submission.
The full course policy provides the detailed collaboration, regrade, project-contribution, and career-related travel rules.
The goal is a learning environment that is accessible and usable by all students. Students who anticipate a barrier in course materials, technology, assessment format, or participation should contact the instructor.
Section 6 of UVA policy PROV-008: Teaching Courses for Academic Credit governs academic accommodations for disability, pregnancy, and religion. Students should use the official process for disability-related accommodations, pregnancy-related accommodations, or religious accommodations and contact the instructor as early as possible.
UVA’s official policies address discrimination and harassment, retaliation, and sexual and gender-based misconduct. The instructor and any TAs are Responsible Employees under HRM-040. The official EOCR syllabus statement explains current reporting obligations and confidential resources; reports may be submitted through Just Report It.
| Date | Course plan |
|---|---|
| August 25 | First class |
| September 8 | Privacy attacks completed |
| September 10 | ML security begins; Lab 1 released |
| September 17 | Poisoning, backdoors, and ML security defenses |
| September 22 | No class: break |
| September 24 | Anonymization, linkage, and k-anonymity; Lab 1 due and Lab 2 released |
| September 29 | Differential privacy: definitions |
| October 1 | Differential privacy (continued) |
| October 6 | No class: Fall Reading Days |
| October 8 | In-class project pitch presentations |
| October 13 | Guest lecture: TEEs and confidential LLM serving |
| October 15 | Quiz 1 |
| October 22 | Lab 2 due and Lab 3 released |
| October 29 | Project proposal |
| November 3 | No class: Election Day |
| November 12 | Lab 3 due and Lab 4 released |
| November 17 | Guest lecture: oblivious RAM (ORAM) |
| November 19 | Quiz 2 |
| November 24 | Homomorphic encryption and private computation; Lab 4 oral-check window |
| November 25-29 | Thanksgiving recess |
| December 1 | Guest lecture: privacy in industry |
| December 3 | Privacy applications and review; Lab 4 due |
| December 8 | Poster/demo session, last class, and final report |
Local DP, zero-knowledge proofs, verifiable computation, and network privacy are optional extensions rather than scheduled core lectures. The schedule reflects security material completed September 17, anonymization beginning September 24, and DP definitions introduced September 29 and continued October 1; September 22 is a break. December 3 is a flexible session for applications, unfinished material, and review. Guest lectures, quizzes, and lab and project deadlines are unchanged.
The full schedule is tentative. Exact deadlines will appear in Canvas. Changes after the start of the term will be communicated in writing and will not place required deadlines during scheduled University recess.