CS 459/659 - Privacy, Cryptography, Network and Data Security - Fall 2026
Syllabus
| Instructor | Urs Hengartner | |
| urs.hengartner@uwaterloo.ca | ||
| TAs | Alim Dhanani | |
| Lucas Fenaux | ||
| Anais Huang | ||
| Lecture times and location | Tuesdays and Thursdays 8:30-9:50am in MC 2054 | |
| Office Hours | ||
| Instructor: | Tuesdays 11:00am-12:00pm in DC 3526 or in course Teams channel | |
| TAs: | Assignment dependent, see released assignment. | |
Course Description
This course provides an introduction to data privacy and security, using cryptography and related techniques in networks, distributed systems, and data science. It examines how data and meta-data can be protected at rest, in transit, and during computation. Students completing this course should be able to use and deploy data security and privacy protection technologies in networks and (distributed) data science environments. In layman terms, this course shows you how to benefit from the Internet and machine learning and still preserve individuals' privacy.
Learning outcomes: By the end of this course students should be able to:- • Evaluate the use of cryptography to protect data assets in storage, transit, and use
- • Analyze security and privacy threats to data assets, including the privacy level of various data release mechanisms, privacy-utility trade-offs, and statistical inference attacks to infer sensitive information
- • Evaluate the use of network security hardware and software to protect data assets in transit and use.
- • Compare various network security mechanisms, and articulate their advantages and limitations.
- • Understand data-driven attacks on machine learning systems
Course Outline
Foundation - Protected at rest:- • Intro security/privacy
- • Ethics/policy relevant to this course
- • Basics of cryptography
- • Symmetric encryption
- • Hash functions, MAC
- • Public key encryption (RSA)
- • Semantic security, etc.
- • Network Security Primer: Firewalls, Intrusion Detection, Honeypots
- • Authentication Failures: Spoofs (IP, user ids), rerouting attacks (DNS, etc.)
- • Authentication Primer (Needham-Schroeder/Kerberos, SAML, etc.), PAKE
- • PKI, DH, DNSSEC
- • Confidentiality Failures: Snooping, Web tracking (cookies), fingerprinting
- • TLS, VPN, WPA2
- • Tor, Mixes, Secure email and messaging (Signal, PGP, etc.)
- • Traffic analysis
- • Network covert channels
- • Data Security: Inference attacks (leakage from function output, background information, side channels)
- • k-Anonymity, l-diversity, (t-plausibility)
- • Differential privacy (Laplace, etc.)
- • Private machine learning
- • Homomorphic encryption
- • Intro to MPC, PSI, PIR
Grading Scheme
Grades for this course will be calculated as follows:
| 45% | Homework assignments (15%, 15%, 15%) |
| 25% | Midterm (held in class) |
| 30% | Final assessment (during exam season) |
For graduate students: the above scaled to 80% + 20% research paper
Midterm and Final Assessment: These assessments are written-only (no programming) but may cover any material taught until each assessment's date. If a student misses the midterm with valid documentation, its weight will be shifted to the final exam. Final grades will be available after the end of term through LEARN.
Assignments:
The three assignments are meant to be completed individually. The assignments are based on a mix of theory (written) and practical (programming) exercises. Students will leverage the knowledge and techniques presented in the lectures for completing the assignments.
The assignments are due at 3:00 pm Eastern Time on their respective due dates. Please start working on the assignments in advance of the deadlines. Late submissions for Assignments 1, 2, and 3 will be accepted only up to 48 hours after the due date. Multiple assignments can be submitted late, including the last one. There is no penalty for accepted late submissions. Assignments can be submitted multiple times, and the last one will be used for marking. Course personnel will not give assistance for assignments after their due dates, so you are encouraged to respect the due date.
Remarking Policy:
If you have an assignment that you would like to have reappraised, please please email the TA responsible for the assignment. Include a clear justification for your claims. The appeals deadline is one week after the respective graded item is first made available. If your appeal is concerned with a simple calculation error, please see the TA(s) during their office hours.
Late/Missed Content:
Please see the Faculty's Absence declarations for the different types of absences and the declaration requirements.
For short-term absences (and other types of absences lasting at most 48 hours) that happen before an assignment's due date, students can take advantage of the automatic 48-hour, no-penalty grace period (see above). No further extensions will be granted.
For short-term absences (and other types of absences lasting at most 48 hours) during an assignment's automatic 48-hour, no-penalty grace period, no further extensions will be granted.
For absences lasting more than 48 hours, students should contact the instructor(s) as soon as possible and present valid justification.
If a student misses the midterm, the midterm's weight is shifted to the final assessment to take place during exam season. Missing the midterm requires valid justification (e.g., short-term absence, VOC forms).
Research Paper (CS 659):
Students registered in CS 659 must write either a research survey or replication study paper on a topic related to data security or privacy. In writing your survey paper, you must become familiar with the research literature relevant to your topic. In performing a replication study, you must understand the work you are replicating. Your focus should be on academic venues, such as the USENIX Security Symposium, ACM CCS, IEEE Symposium on Security and Privacy, Privacy Enhancing Technologies Symposium (PETS), or the NDSS Symposium.
Your topic must be approved in advance by the instructors before you submit your full paper at the end of term. Your proposal should be one page in length. In case of a survey paper, it should include at least 10 references, preferably including (but not limited to) papers from the aforementioned venues. In case of a replication study, it should mention the work to be replicated, again preferably including (but not limited to) papers from the aforementioned venues and including a testing plan. Email your proposal to the instructor by Oct 27.
Your survey paper should be a summary of past and current work on your topic, as well as an overview of known open problems and potential future directions in the area. You should provide a concise summary of work, emphasizing major accomplishments, rather than a detailed accounting of individual pieces of research activity. You should draw conclusions about the work (that AI could not perform). Your replication study should provide an independent implementation of the work or at least determine ways to ensure that the original implementation is free of implementation faults. It should evaluate on (some of) the same and additional data sets either confirming or extending the results of the original work. You should focus on cases, e.g., parameter settings, that may reveal additional insight to the replicated work. Email your final paper to the instructor by Dec 8.
Your proposal and paper should be formatted in the two-column ACM proceedings format, using one of the ACM SIG Proceedings Templates. Your paper should not be longer than six pages (excluding references). The ACM templates include headings for “Categories and Subject Descriptors”, “General Terms”, and “Keywords”, which you do not need to use.
Textbooks
There is no required textbook. Additional readings may be assigned, and will appear on the course website. Readings marked as mandatory contain required material for the course. You must read these mandatory readings.Communication
Please direct all communication to the course Piazza discussion forum. This includes questions about materials in lectures, assignments, and general logistics.
It is your responsibility to keep up with all course-related information posted to LEARN, the Piazza forum, and the course website.
Etiquette:
Please go through your peers' and the instructor(s)/TAs' notes or comments, before posting a question. If question doesn't exist and it involves private content (query about grades, partial progress towards solution), then create a private question that is only visible to the instructor(s) and TAs. (The instructor(s) or TAs may make a private question public, possibly after editing it, if they decide that it is of general interest.) Otherwise, in general, create a public one so that your peers can benefit too. Tag your question with the appropriate folder for the assignment, etc.Email:
Important course information will be posted on the course website and/or on Piazza, but may also be sent to your uwaterloo.ca email address. For personal matters, such as an illness, please email the instructor(s) directly. We will only reply back to email from your uwaterloo.ca email address, for privacy rules.Generative AI
This course includes the independent development and practice of specific skills, such as deriving mathematical formulas and writing code. Therefore, the use of Generative artificial intelligence (GenAI) trained using large language models (LLM) or other methods to produce text, images, music, or code, like Chat GPT, DALL-E, or GitHub CoPilot, is discouraged but not prohibited in this class. Work produced with the assistance of AI tools must disclose that and how AI has been used (including the exact tool and prompt to generate the outputs). The way how AI has been used will be taken into account when determining your grade.
You should be prepared to show your work. To demonstrate your learning, you should keep your rough notes, including sources, research notes, brainstorming, drafting notes and prompts. You may be asked to submit these notes along with earlier drafts of your work, either through saved drafts or saved versions of a document. If the undisclosed use of GenAI is suspected where not permitted, you may be asked to meet with your instructor or TA to provide explanations to support the submitted material as being your original work. If you cannot sufficiently support your work, academic misconduct allegations may be brought to the Associate Dean.
In addition, you should be aware that the legal/copyright status of generative AI inputs and outputs is unclear. More information is available from the Copyright Advisory Committee.
Students are encouraged to reach out to campus supports if they need help with their coursework including:
- •Student Success Office for help with skills like notetaking and time management
- •Writing and Communication Centre for assignments with writing or presentations
- •AccessAbility Services for documented accommodations
- •Library for research-based assignment