CS 4501-003: Data Privacy

Back to the course homepage

Fall 2026 syllabus | Planning draft | Updated August 25, 2026

This page is the working syllabus for Fall 2026. Before it becomes the official first-day version, the instructor will confirm office hours, assignment dates, letter-grade thresholds, and assignment logistics. Changes will be dated and communicated through Canvas.

Course information

Item Details
Course CS 4501-003, Special Topics in Computer Science: Data Privacy
Instructor Tianhao Wang
Email tianhao@virginia.edu
Meetings Tuesdays and Thursdays, 2:00-3:15 PM
Classroom Olsson Hall 011
Term August 25-December 8, 2026
Office hours To be confirmed before the first day of class; appointments will also be available
Public course site tianhao.wang/f26-dataprivacy
Canvas canvas.its.virginia.edu/courses/190753

Canvas is the authoritative source for announcements, release bundles, submissions, grades, and any date changes. The public site contains the durable course description, schedule, assignment structure, and policies.

Use Canvas Inbox or email for questions involving grades, accommodations, or other private matters.

Course description

How can we use data to build useful systems without exposing the people behind the data? This course studies concrete privacy attacks, practical defenses, and the engineering contracts that connect privacy claims to data, code, configuration, accounting, and tests.

We begin with privacy attacks, then study ML security threats and defenses before returning to anonymization and its limits. We then develop differential privacy and privacy-utility trade-offs, private machine learning, synthetic data, and privacy-enhancing technologies including secure multi-party computation, homomorphic encryption, trusted execution environments, and oblivious RAM. The course is designed for undergraduates with the preparation listed below and emphasizes technical judgment, reproducible evidence, and clear communication rather than graduate-level novelty.

Learning objectives

By the end of the course, students should be able to:

  1. distinguish major privacy attacks and evaluate whether an experiment supports a claimed privacy failure;
  2. formulate threat models, protected units, adjacency relations, and release boundaries for data and machine-learning systems;
  3. explain and apply differential privacy mechanisms, composition, privacy accounting, and privacy-utility analysis;
  4. trace a privacy claim through sampling, optimization, preprocessing, configuration, code, and tests;
  5. design and evaluate an innovative, scoped privacy contribution using reproducible evidence; and
  6. communicate conclusions, uncertainty, residual risks, and the role of AI assistance in technical work.

Background and preparation

This course is open to all undergraduates who have the following preparation:

Required background:

No prior coursework in privacy, cybersecurity, machine learning, cryptography, or AI is required.

At UVA, CS 3710 (Introduction to Cybersecurity) is especially useful preparation for threat modeling and attacks. CS 4774 (Machine Learning) also connects to parts of the material. Neither is a prerequisite.

The optional readiness self-check illustrates the programming, probability, and ML ideas used in the first weeks. It is ungraded, does not determine eligibility to enroll, and includes guidance for reviewing any gaps.

How the course works

The course combines four forms of work:

Guest lectures will connect course mechanisms to industry privacy practice and recent academic work. Their topics and speakers will be updated on the course schedule as they are confirmed. Students should expect to read short technical material before selected meetings and to work with small CPU-compatible code bundles outside class.

Assessment and grading

Component Weight Basis
Labs 40% Four labs worth 10% each; selected labs use hidden cases and Lab 2 uses a direct arena
Project 30% Project pitch 10%, proposal 5%, poster/demo 10%, final report 5%
Quizzes 20% Two individual, in-class, closed-book paper quizzes at 10% each
Exit surveys / check-ins 10% Short individual Canvas submissions graded for completion
Total 100%  

Final grades use the UVA grading basis. Exact letter-grade thresholds will be added before this draft becomes the official syllabus.

Labs

All labs are completed individually. They deliberately use different work products: a privacy-attack runner, a two-agent secret-arena submission, a regression-tested library extension, and a private-computation artifact with an oral check.

Selected labs use instructor-only hidden cases in addition to visible tests; the number and mix of those cases are not announced. Lab 2 uses direct two-agent matches with a separate hidden utility evaluator. Arena rankings are feedback, not winner-take-all grades; course points use fixed criteria and instructor baselines. Some instances are intentionally clean or contain insufficient evidence, so a correct abstention can receive full credit.

Lab Weight Release week Due week
Privacy Attack Warm-up 10% 3 5
Two-Agent Secret Arena 10% 5 9
DP Library Extension Challenge 10% 9 12
Compute Without Seeing 10% 12 15

Private materials are distributed through Canvas; any course Drive link will be posted there. Raw notebooks, instances, hidden cases, evaluator files, solutions, and grading files are not published on the public site.

Project

The project contributes 30%. Its topic and method remain open, but it must make an innovative privacy contribution. Students may build a system or focused tool, develop an attack or defense, create a privacy monitor or auditor, or complete a research project whose primary artifact is a paper. Teams of up to 2 are allowed; individual projects may use a narrower scope.

Projects may build on existing papers, libraries, and code, but a reproduction, routine comparison, literature review, mechanical port, or incremental extension alone does not satisfy the requirement. Innovation may come from a new capability, attack, defense, measurement, system boundary, interaction, or research insight. Publication-level novelty is not required, but the proposal must explain what becomes newly possible, measurable, or defensible relative to a meaningful baseline.

The project has no leaderboard, arena, or required peer attack. The in-class project pitch occurs in Week 7, the written proposal serves as a progress and scope checkpoint in Week 10, and the poster/demo and final report are due in Week 16. See the milestone guide and project rubric.

Quizzes

Both quizzes are completed individually during class on paper. They are closed book and closed notes; computers, phones, AI tools, and other electronic aids may not be used. Each quiz combines short foundation and application questions with longer reasoning questions that ask students to certify, refute, or qualify a claim using code, data, or a system description. An instructor-supplied formula sheet and a practice set will be provided before each quiz. The covered topics and any other permitted basic supplies will be announced in advance.

The planned coverage follows the revised lecture schedule:

Guest lectures and optional readings are not part of these quiz scopes. If lectures move again, the announced scope will reflect material actually covered with time to prepare.

Students with an approved absence will receive an equivalent makeup arrangement. The makeup may use different examples while assessing the same skills.

Exit surveys and check-ins

Short individual exit surveys and check-ins submitted through Canvas contribute 10%. They ask students to record a conclusion, identify a remaining question, interpret a small result, or check progress on a current lab or project. Each submission receives credit for timely, good-faith completion.

Materials and technology

No required textbook or paid AI subscription is planned. Readings, starter environments, and private assignment bundles will be supplied through Canvas; any course Drive link will be posted there. The public site lists optional books, courses, software, and current AI access options.

UVA students currently have no-additional-cost access to Gemini and NotebookLM and Copilot Chat. Eligible U.S. college students may also claim OpenAI’s 2026 student offer for four free months of ChatGPT Plus by October 31, 2026; it requires student verification and a payment method and renews at the regular monthly price unless canceled. UVA RC GenAI provides Kimi K2.5 to eligible Research Computing users, but RC currently restricts that service to research rather than ordinary class assignments.

Students need regular access to a computer that can run Python and a web browser. Required lab paths are designed for CPU execution with pinned environments. If access to hardware, software, or an assigned format creates a barrier, contact the instructor early so that an equivalent path can be arranged.

Generative AI

Generative AI may be used for brainstorming, debugging, code explanation, and polishing unless an assignment says otherwise. It does not replace technical ownership.

Collaboration and academic integrity

Labs, quizzes, and Canvas exit surveys/check-ins are individual. Projects may be completed individually or in teams of up to 2. High-level discussion across the class is welcome, but students may not share lab code, completed tables, polished written answers, arena submissions, or private arena feedback. Every submission must identify permitted collaborators; project teams must include a contribution statement where required.

Students are expected to follow the University Honor Code and its guidance on academic fraud. Uncertainty about permitted collaboration or AI use should be resolved with the instructor before submission.

Late work, regrades, and attendance

The full course policy provides the detailed collaboration, regrade, project-contribution, and career-related travel rules.

Accessibility and academic accommodations

The goal is a learning environment that is accessible and usable by all students. Students who anticipate a barrier in course materials, technology, assessment format, or participation should contact the instructor.

Section 6 of UVA policy PROV-008: Teaching Courses for Academic Credit governs academic accommodations for disability, pregnancy, and religion. Students should use the official process for disability-related accommodations, pregnancy-related accommodations, or religious accommodations and contact the instructor as early as possible.

UVA’s official policies address discrimination and harassment, retaliation, and sexual and gender-based misconduct. The instructor and any TAs are Responsible Employees under HRM-040. The official EOCR syllabus statement explains current reporting obligations and confidential resources; reports may be submitted through Just Report It.

Key dates and changes

Date Course plan
August 25 First class
September 8 Privacy attacks completed
September 10 ML security begins; Lab 1 released
September 17 Poisoning, backdoors, and ML security defenses
September 22 No class: break
September 24 Anonymization, linkage, and k-anonymity; Lab 1 due and Lab 2 released
September 29 Differential privacy: definitions
October 1 Differential privacy (continued)
October 6 No class: Fall Reading Days
October 8 In-class project pitch presentations
October 13 Guest lecture: TEEs and confidential LLM serving
October 15 Quiz 1
October 22 Lab 2 due and Lab 3 released
October 29 Project proposal
November 3 No class: Election Day
November 12 Lab 3 due and Lab 4 released
November 17 Guest lecture: oblivious RAM (ORAM)
November 19 Quiz 2
November 24 Homomorphic encryption and private computation; Lab 4 oral-check window
November 25-29 Thanksgiving recess
December 1 Guest lecture: privacy in industry
December 3 Privacy applications and review; Lab 4 due
December 8 Poster/demo session, last class, and final report

Local DP, zero-knowledge proofs, verifiable computation, and network privacy are optional extensions rather than scheduled core lectures. The schedule reflects security material completed September 17, anonymization beginning September 24, and DP definitions introduced September 29 and continued October 1; September 22 is a break. December 3 is a flexible session for applications, unfinished material, and review. Guest lectures, quizzes, and lab and project deadlines are unchanged.

The full schedule is tentative. Exact deadlines will appear in Canvas. Changes after the start of the term will be communicated in writing and will not place required deadlines during scheduled University recess.