Advanced Security
Advanced Security Topics · Fall 2026
Description
This course explores advanced and emerging topics in computer security. We will study recent research across a range of areas, with an emphasis on technically deep work and important new security problems. Rather than treating papers as isolated results, we will focus on their core technical ideas, assumptions, limitations, and the research questions they open up.
The course is discussion-oriented. Students are expected to read the assigned papers carefully and come to class prepared to explain, criticize, and reason about them. There is no assigned textbook.
Prerequisite
Security I or equivalent background is recommended. Please contact the instructor if you are unsure about preparation.
Class format
A typical 110-minute class will have four parts:
- Instructor introduction (about 10 minutes): framing the topic, connecting the readings, and highlighting the main questions for discussion.
- Two student presentations (about 60 minutes total): two focused 30-minute presentations, normally covering one assigned reading each.
- Break (about 10 minutes).
- Q&A and discussion (about 30 minutes): questions for the presenters, comparison across the readings, criticism, and open research problems.
Exception: the first class will be instructor-led and will not have student presentations.
Attendance
Attendance is mandatory. This is a discussion- and presentation-based course, so a significant part of the learning happens through in-class presentations, questions, and discussion and cannot be reproduced by simply reading the assigned papers afterward.
If you expect to miss a class, please notify the instructor as early as possible. Absences for medical reasons or other documented emergencies are excused. Other unavoidable absences should also be communicated in advance whenever possible; unexplained or repeatedly uncommunicated absences will affect the participation grade.
Student presentations
Each student presentation is approximately 30 minutes. Presentations should be concise and analytical. A useful structure is:
| Part | Approx. time | Goal |
|---|---|---|
| Problem / motivation | 3–4 min | What problem is the paper trying to solve, and why does it matter? |
| Core technical idea | 12–15 min | Explain the mechanism carefully, including the main technical details. |
| Evaluation / evidence | 5–6 min | What results support the claims, and which result matters most? |
| Critique | 3–4 min | Identify a substantive limitation, weak assumption, or missing experiment. |
| Research question | 2–3 min | What should someone do next? |
As a guideline, each 30-minute presentation should use roughly 25–30 substantive slides. Presenters are expected to go into technical depth rather than skim the paper, and must be able to answer questions about any claim on their slides.
Reading and participation
There are no weekly paper summaries. Everyone is expected to read the required paper before class and participate in discussion. Students may occasionally be called on to explain a paper's key assumption, strongest result, limitation, or an aspect they found unclear.
For selected classes, students may be asked to submit a single sentence before class—for example, the weakest assumption in the paper or one experiment they would add. These responses are intended as preparation for discussion rather than as miniature essays.
Quizzes
There will be two short in-class quizzes during the semester. Their purpose is to encourage students to keep up with the readings, lectures, and class attendance throughout the semester. The date of each quiz will be announced approximately one week in advance.
- Each quiz will be short and designed to be straightforward to grade.
- Questions will focus on important concepts, assumptions, threat models, and basic technical ideas—not obscure details.
- Questions will primarily be multiple choice, true/false with a brief justification, or one-phrase/one-sentence answers.
- No lengthy derivations.
- Quizzes are individual and completed without AI tools or other electronic assistance.
Use of AI tools
Students may use LLMs and other AI tools for reading assistance, brainstorming, presentation preparation, coding, and project work unless explicitly stated otherwise. The course will not attempt to distinguish AI-assisted prose from unaided prose.
However, students are responsible for everything they submit or present. In presentations and discussions, you must be able to explain and defend your claims, technical arguments, and proposed ideas. Material that a student cannot explain should be treated as material the student does not understand.
Project
The project should investigate a focused research question related to the course. A project may reproduce, break, extend, or reinterpret an idea from a paper; build a small system; perform a careful empirical study; or develop a formal or conceptual result. Suggested LLM-focused project themes and example directions are available on the Project Ideas page.
The project is intentionally lightweight in structure. There are three milestones:
- One-page proposal: problem, motivation, and intended approach. Due September 29 at 11:59 PM.
- Short midpoint presentation: what you tried, what happened, and what remains.
- Final report and presentation/demo: a concise account of the question, approach, evidence, and conclusions.
Negative results are acceptable. Projects are evaluated primarily on the quality of the question, technical understanding, methodology, and what was learned—not on whether a new system beats a baseline.
Grading
Each quiz is worth 10% of the final grade. Presentation grades emphasize technical understanding, judgment, criticism, and the ability to answer questions rather than slide polish.
Schedule
The detailed schedule and readings will be posted here before the semester.
| Week | Topic | Reading / notes |
|---|---|---|
| Sep 8 | Course introduction | Instructor-led overview; no student presentations. |
| Sep 15 | Automated Vulnerability Discovery I | Anthropic, Assessing Claude Mythos Preview's Cybersecurity Capabilities (2026); Abramovich et al., EnIGMA: Interactive Tools Substantially Assist LM Agents in Finding Security Vulnerabilities (ICML 2025). |
| Sep 22 | Automated Vulnerability Discovery II | VulnLLM-R: Specialized Reasoning LLM with Agent Scaffold for Vulnerability Detection; Anthropic, Discovering Cryptographic Weaknesses with Claude; Fluri et al., CryptanalysisBench: Can LLMs do Cryptanalysis? (2026). |
| Sep 29 | TBA | Topic and readings to be selected. |
| Oct 6 | TBA | Topic and readings to be selected. |
| Oct 13 | TBA | Topic and readings to be selected. |
| Oct 20 | TBA | Topic and readings to be selected. |
| Oct 27 | TBA | Topic and readings to be selected. |
| Nov 3 | No class — Election Day | University holiday; no classes held. |
| Nov 10 | TBA | Topic and readings to be selected. |
| Nov 17 | TBA | Topic and readings to be selected. |
| Nov 24 | TBA | Topic and readings to be selected. |
| Dec 1 | Project presentations | Final project presentations. |
| Dec 8 | Project presentations | Final project presentations. |