Fall 2026 syllabus | Planning draft | Updated August 20, 2026
| Item | Details |
|---|---|
| Course | CS 4501-003, Special Topics in Computer Science: Data Privacy |
| Instructor | Tianhao Wang |
| Meetings | Tuesdays and Thursdays, 2:00-3:15 PM |
| Classroom | Olsson Hall 011 |
| Term | August 25-December 8, 2026 |
| Office hours | To be confirmed before the first day of class; appointments will also be available |
| Public course site | tianhao.wang/f26-dataprivacy |
| Canvas | canvas.its.virginia.edu/courses/190753 |
Canvas is the authoritative source for announcements, release bundles, submissions, grades, and any date changes. The public site contains the durable course description, schedule, assignment structure, and policies.
How can we use data to build useful systems without exposing the people behind the data? This course studies concrete privacy attacks, practical defenses, and the engineering contracts that connect privacy claims to data, code, configuration, accounting, and tests.
We begin with extraction, membership inference, linkage, and reconstruction. We then develop differential privacy and privacy-utility trade-offs, private machine learning, synthetic data, and privacy-enhancing technologies including secure multi-party computation, homomorphic encryption, trusted execution environments, and network privacy tools. The course is designed for advanced undergraduates and emphasizes technical judgment, reproducible evidence, and clear communication rather than graduate-level novelty.
By the end of the course, students should be able to:
Required background:
Prior coursework in machine learning, security, cryptography, or data science is recommended but not required. No prior experience with differential privacy, LLM training, privacy research, or advanced cryptography is assumed.
The course combines five forms of work:
Planned asynchronous class work appears explicitly on the course schedule. Students should expect to read short technical material before selected meetings and to work with small CPU-compatible code bundles outside class.
| Component | Weight | Basis |
|---|---|---|
| Audit labs | 30% | Three labs at 10% each; code, evidence, repair, regression tests, and transfer |
| Project | 25% | Topic check-in 5%, proposal 5%, poster/demo 5%, final report 10% |
| Individual oral defense | 10% | Technical ownership, evidence, changed requirement, and residual-risk reasoning |
| Quizzes | 20% | Two individual in-class quizzes on foundations and core mechanisms |
| Exit tickets and participation | 10% | Short check-ins, audit studios, and the formative project break exchange |
| Reading warm-ups | 5% | Short individual preparation for selected readings |
| Total | 100% |
Final grades use the UVA grading basis. Exact letter-grade thresholds will be added before this draft becomes the official syllabus.
Labs may be completed in teams of 2 or individually. Each lab asks students to build a small baseline, determine whether an assigned privacy contract holds, repair or guard the relevant code path, add a regression test, and transfer the analysis to a changed setting. Some instances are intentionally clean or contain insufficient evidence; grades do not reward luck in finding an unknown bug.
Lab bundles and hidden tests are distributed privately through Canvas or the course Drive. Raw notebooks, mutation mappings, solutions, and grading files are not published on the public site.
| Lab | Tool | Release week | Due week |
|---|---|---|---|
| Training contract audit | Opacus | 6 | 9 |
| Step accounting patch | JAX Privacy | 9 | 12 |
| Synthetic release audit | Google DPSynth | 11 | 14 |
The project contributes 25% and develops through Build, Break, Repair, and Transfer. Projects may reproduce and extend prior work, compare privacy methods, or build a small privacy-aware system. Novel research is not required. Teams of up to 2 are allowed; individual projects may use a narrower scope.
The topic check-in occurs in Week 7, the proposal in Week 10, the formative break exchange in Week 13, poster/demo sessions in Week 15, and the final report in Week 16. See the milestone guide and project rubric.
Each student completes a 5-10 minute conversation about one submitted lab artifact and one project decision. The defense may be scheduled during a designated class period or through a mutually arranged office-hour appointment; the final format and an equivalent option for students who cannot use an office-hour appointment will be announced in Canvas. Students may open their own submitted artifacts but may not use external AI assistance during the defense. No slides are required, and students are not expected to locate an unknown bug on the spot.
No required textbook or paid AI subscription is currently planned. Readings, starter environments, and private assignment bundles will be supplied through Canvas or the course Drive. The public site lists optional books, courses, and software references.
Students need regular access to a computer that can run Python and a web browser. Required lab paths are designed for CPU execution with pinned environments. If access to hardware, software, or an assigned format creates a barrier, contact the instructor early so that an equivalent path can be arranged.
Generative AI may be used for brainstorming, debugging, code explanation, and polishing unless an assignment says otherwise. It does not replace technical ownership.
Labs and projects may be completed in teams of up to 2. Quizzes, reading warm-ups, exit tickets, and the oral defense are individual. High-level discussion across teams is welcome, but students may not share code, completed tables, or polished written answers across teams. Every submission must identify collaborators and, where required, include a contribution statement.
Students are expected to follow the University Honor Code and its guidance on academic fraud. Uncertainty about permitted collaboration or AI use should be resolved with the instructor before submission.
The full course policy governs collaboration, regrades, project contributions, accommodations, respectful conduct, and career-related travel.
The goal is a learning environment that is accessible and usable by all students. Students who anticipate a barrier in course materials, technology, assessment format, or participation should contact the instructor. Students seeking disability-related accommodations should also work with the Student Disability Access Center.
UVA provides reasonable academic accommodations when disability, pregnancy, or sincerely held religious belief conflicts with course requirements. Requests should be made as early as possible. Questions about pregnancy or religious accommodations may be directed to the Office for Equal Opportunity and Civil Rights.
The course follows UVA policies prohibiting discrimination, harassment, and retaliation. Support, confidential resources, and reporting options are linked from the full course policy.
| Date | Course plan |
|---|---|
| August 25 | First class |
| September 22 | Planned asynchronous course work |
| October 6 | No class: Fall Reading Days |
| October 13 and 15 | Planned asynchronous course work |
| November 3 | No class: Election Day |
| November 17 and 19 | Planned asynchronous course work |
| November 25-29 | Thanksgiving recess |
| December 1 and 3 | Poster/demo sessions |
| December 8 | Last class and final report |
The full schedule is tentative. Exact deadlines will appear in Canvas. Changes after the start of the term will be communicated in writing and will not place required deadlines during scheduled University recess.