CSC 696I: Advanced Topics in Security

Fall 2026
Department of Computer Science
University of Arizona

Course Overview

(Note: This is a summarized syllabus; see the full version here.)

The goal of this graduate seminar is to learn more about research in the general field of computer security. We will review and critique research papers spanning current, important topics in security. Specific topics will be determined by the current literature and by instructor and student interest. Students will also strengthen research skills by conducting a research project on a security topic of their choice. Course communications will be done through D2L (and e-mail, as applicable).

Instructor
Prof. Quinn Burke
Office: 754 Gould-Simpson / E-mail: qkb@arizona.edu
Office hours: Monday 3:15-4:15 PM MST (or by appointment)
Lectures
701 Gould-Simpson
MW 2:00-3:15 PM MST
Prerequisites
Graduate major or minor in CSC. No formal course prerequisites; some background in computer security, operating systems, artificial intelligence, software engineering, and/or networking will be helpful.

Course Activities and Schedule

Most lectures will be discussion-based, covering 1-2 research papers per class. Students must submit conference-style paper reviews before class (via D2L). Students are expected to come to class having read the papers and be prepared to discuss and critique them (scope, motivation, methodology, strengths, weaknesses, evaluation, etc.). The instructor will facilitate discussion and provide additional background context for each module. Other lectures may consist of alternative research-based activities (e.g., artifact evaluation) and guest lectures. Note that this schedule may change during the semester based on class interest, invited guest lectures, and instructor travel. All changes will be announced by email as early as possible.

A number of sessions are reserved for student-led discussion, where a student will present the paper then facilitate discussion (much like a conference Program Chair) of the paper. Each student will present approximately twice over the semester (the exact number depends on class size).

Students will also complete a course project on a security topic of their choice, culminating in a short conference-style research report (any paper template is fine) and a final in-class presentation at the end of the semester. The project can be a security idea you have always wanted to pursue, a security angle on your current research, a reproduction study of a published work, etc. The only requirement is that it must intersect with security. The instructor will provide suggestions and feedback on project ideas, and students are encouraged to discuss their ideas with the instructor early in the semester. Detailed requirements for each project milestone are posted on D2L.

Week Notes
Introduction
1Aug 24Class intro & syllabus; how to read a paperStart thinking about project topics
Optional reading: How to Read a Paper, Mitzenmacher on Reading
Software Supply Chain Security
1Aug 26Supply Chain Attack TaxonomyOptional reading: Reflections on Trusting Trust
2Aug 31in-totoSep 2Reproducible BuildsStudent presentation signup
3Sep 7No class (Labor Day)Sep 9Pushed by Accident
4Sep 14Hypocrite CommitsSep 16Project brainstorming sessionBring a short written project idea (post to D2L the day before)
LLM & Agent Security
5Sep 21Agentic AI Threat LandscapeSep 23Indirect Prompt Injection
6Sep 28JailbrokenSep 30GCG Attack
7Oct 5IsolateGPTOct 7Lab: IsolateGPT implementationProject proposal due (Oct 7)
8Oct 12AgentDojoOct 14LLM App Data Collection
9Oct 19Extracting Training DataOct 21Poisoning Web-Scale Data
Systems Security
10Oct 26SGX ExplainedOct 28TDX Demystified
11Nov 2SGX.FailNov 4Project development sessionStatus report due (Nov 2)
12Nov 9NimbleNov 11No class (Veterans Day)
13Nov 16syncfs Side ChannelsNov 18Lab: measuring the syncfs channel
Web Security
14Nov 23Site IsolationNov 25CSP Is Dead
15Nov 30Silent SpringDec 2Cached and Confused
16Dec 7Online Tracking at ScaleDec 9Final project presentations
Finals
17Dec 14No class meetingFinal paper due (Dec 14)

Grading

Component Weight Description
Paper reviews 25% Grading based on paper reviews being submitted on time and containing structured critiques. The three lowest review scores are dropped, so no documentation is needed for a missed review. This applies to reviews only; in-class participation is graded separately, and you are still expected to attend and come prepared.
In-class participation 25% Grading based on students coming to lectures prepared with questions and discussion points, and engaging with other student critiques.
Paper presentations 20% Grading is based on student coverage of the assigned paper (motivation, scope, methodology, key results, and conclusions) and engagement with other students while leading the discussion.
Course project 30% A proposal, a mid-semester status report, and a final presentation and report, which together should form a self-contained research artifact. Requirements and the weight of each milestone are posted on D2L.

Ethics Statement

This course includes topics related to computer security. We may cover technologies whose abuse could infringe on the rights of others. As computer scientists, we rely on the ethical use of these technologies. Unethical use includes circumvention of any existing security mechanisms for any purpose, or the dissemination, promotion, or exploitation of vulnerabilities of these services. Any activity outside the letter or spirit of these guidelines will be reported to the proper authorities and may result in dismissal from the class and possibly more severe academic and legal sanctions.