COMS E6998

Advanced Security

Advanced Security Topics · Fall 2026

InstructorSuman Jana
OfficeMudd 412
Office hoursTBD
TATBD
Classroom253 Engineering Terrace
Class timeTuesday, 12:10 PM–2:00 PM
FormatLecture + student-led paper discussion

Description

This course explores advanced and emerging topics in computer security. We will study recent research across a range of areas, with an emphasis on technically deep work and important new security problems. Rather than treating papers as isolated results, we will focus on their core technical ideas, assumptions, limitations, and the research questions they open up.

The course is discussion-oriented. Students are expected to read the assigned papers carefully and come to class prepared to explain, criticize, and reason about them. There is no assigned textbook.

Prerequisite

Security I or equivalent background is recommended. Please contact the instructor if you are unsure about preparation.

Class format

A typical 110-minute class will have four parts:

  1. Instructor introduction (about 10 minutes): framing the topic, connecting the readings, and highlighting the main questions for discussion.
  2. Two student presentations (about 60 minutes total): two focused 30-minute presentations, normally covering one assigned reading each.
  3. Break (about 10 minutes).
  4. Q&A and discussion (about 30 minutes): questions for the presenters, comparison across the readings, criticism, and open research problems.

Exception: the first class will be instructor-led and will not have student presentations.

The goal is not paper summarization. Students should understand a paper well enough to identify what is essential, what assumptions it relies on, what is unconvincing, and what research question should come next.

Attendance

Attendance is mandatory. This is a discussion- and presentation-based course, so a significant part of the learning happens through in-class presentations, questions, and discussion and cannot be reproduced by simply reading the assigned papers afterward.

If you expect to miss a class, please notify the instructor as early as possible. Absences for medical reasons or other documented emergencies are excused. Other unavoidable absences should also be communicated in advance whenever possible; unexplained or repeatedly uncommunicated absences will affect the participation grade.

Student presentations

Each student presentation is approximately 30 minutes. Presentations should be concise and analytical. A useful structure is:

PartApprox. timeGoal
Problem / motivation3–4 minWhat problem is the paper trying to solve, and why does it matter?
Core technical idea12–15 minExplain the mechanism carefully, including the main technical details.
Evaluation / evidence5–6 minWhat results support the claims, and which result matters most?
Critique3–4 minIdentify a substantive limitation, weak assumption, or missing experiment.
Research question2–3 minWhat should someone do next?

As a guideline, each 30-minute presentation should use roughly 25–30 substantive slides. Presenters are expected to go into technical depth rather than skim the paper, and must be able to answer questions about any claim on their slides.

Reading and participation

There are no weekly paper summaries. Everyone is expected to read the required paper before class and participate in discussion. Students may occasionally be called on to explain a paper's key assumption, strongest result, limitation, or an aspect they found unclear.

For selected classes, students may be asked to submit a single sentence before class—for example, the weakest assumption in the paper or one experiment they would add. These responses are intended as preparation for discussion rather than as miniature essays.

Quizzes

There will be two short in-class quizzes during the semester. Their purpose is to encourage students to keep up with the readings, lectures, and class attendance throughout the semester. The date of each quiz will be announced approximately one week in advance.

Use of AI tools

Students may use LLMs and other AI tools for reading assistance, brainstorming, presentation preparation, coding, and project work unless explicitly stated otherwise. The course will not attempt to distinguish AI-assisted prose from unaided prose.

However, students are responsible for everything they submit or present. In presentations and discussions, you must be able to explain and defend your claims, technical arguments, and proposed ideas. Material that a student cannot explain should be treated as material the student does not understand.

We do not grade students on their ability to produce paper summaries. We care about technical understanding, judgment, criticism, and the ability to reason about security problems interactively.

Project

The project should investigate a focused research question related to the course. A project may reproduce, break, extend, or reinterpret an idea from a paper; build a small system; perform a careful empirical study; or develop a formal or conceptual result. Suggested LLM-focused project themes and example directions are available on the Project Ideas page.

The project is intentionally lightweight in structure. There are three milestones:

  1. One-page proposal: problem, motivation, and intended approach. Due September 29 at 11:59 PM.
  2. Short midpoint presentation: what you tried, what happened, and what remains.
  3. Final report and presentation/demo: a concise account of the question, approach, evidence, and conclusions.

Negative results are acceptable. Projects are evaluated primarily on the quality of the question, technical understanding, methodology, and what was learned—not on whether a new system beats a baseline.

Grading

40%Project
30%Presentation
20%Two quizzes
10%Participation

Each quiz is worth 10% of the final grade. Presentation grades emphasize technical understanding, judgment, criticism, and the ability to answer questions rather than slide polish.

Schedule

The detailed schedule and readings will be posted here before the semester.

WeekTopicReading / notes
Sep 8 Course introduction Instructor-led overview; no student presentations.
Sep 15 Automated Vulnerability Discovery I Anthropic, Assessing Claude Mythos Preview's Cybersecurity Capabilities (2026); Abramovich et al., EnIGMA: Interactive Tools Substantially Assist LM Agents in Finding Security Vulnerabilities (ICML 2025).
Sep 22 Automated Vulnerability Discovery II VulnLLM-R: Specialized Reasoning LLM with Agent Scaffold for Vulnerability Detection; Anthropic, Discovering Cryptographic Weaknesses with Claude; Fluri et al., CryptanalysisBench: Can LLMs do Cryptanalysis? (2026).
Sep 29TBATopic and readings to be selected.
Oct 6TBATopic and readings to be selected.
Oct 13TBATopic and readings to be selected.
Oct 20TBATopic and readings to be selected.
Oct 27TBATopic and readings to be selected.
Nov 3No class — Election DayUniversity holiday; no classes held.
Nov 10TBATopic and readings to be selected.
Nov 17TBATopic and readings to be selected.
Nov 24TBATopic and readings to be selected.
Dec 1Project presentationsFinal project presentations.
Dec 8Project presentationsFinal project presentations.