Computer Science EN.601.438/638
Theory of Differential Privacy
Fall 2026 | 3 credits | EQ | CSCI-THRY
Under construction/check back for updates.
Course Info
Instructor
Lydia Zakynthinou
lzakynthinou@jhu.edu
Office hours: Mon 2-3p or by appointment
Office hours location: Mt. Washington SE313
Teaching Assistant
TBD
Office hours: TBD
Office hours location: TBD
Meetings
MW 4:30-5:45p, Krieger 180
Textbook
There is no official textbook, but recommended books are:
- Cynthia Dwork and Aaron Roth, The Algorithmic Foundations of Differential Privacy, Foundations and Trends in Theoretical Computer Science, 2014. DOI
- Salil Vadhan, The Complexity of Differential Privacy, Tutorials on the Foundations of Cryptography, Springer, 2017. PDF
Course Information
This course is an introduction to differential privacy as a foundational framework for reasoning about privacy in data analysis. Students will develop a principled understanding of why privacy risks arise when privacy is not an explicit design objective and how differential privacy enables formal, provable guarantees.
We will build on the algorithmic toolkit and statistical techniques for designing and analyzing differentially private methods, and study fundamental tradeoffs and lower bounds that characterize the limits of privacy.
Similar courses include Jonathan Ullman and Adam Smith's course at BU/NEU, Gautam Kamath's course at Waterloo.
Prerequisites
Students should be comfortable writing mathematical proofs involving algorithms, probability, and linear algebra. Introduction to Algorithms (601.433/633) satisfies this requirement; comparable theory coursework may be accepted with instructor approval.
Course Topics
- Privacy attacks; motivation for provable privacy.
- Differential privacy: definitions, variants, composition.
- Core mechanisms and algorithmic techniques, including Laplace, Gaussian, Exponential, and Binary Tree mechanisms.
- Differentially private optimization and machine learning, including DP-SGD, amplification by subsampling, and factorization mechanisms.
- Techniques beyond global sensitivity, including local sensitivity and propose-test-release.
- Fundamental limits and lower bounds, including fingerprinting and packing lower bounds.
- Advanced topics may include differentially private approaches for graphs, high-dimensional statistics, PAC learning, and connections between differential privacy and other trustworthy machine learning desiderata.
Course Expectations & Grading
In-class participation is required. There will be 3-4 homework assignments and a final project. The final grade will be computed based on the following weights:
- Homeworks: 50%
- Final Project: 30%
- Participation: 20%
Late assignments: each student has 4 late days to use on homework assignments, not projects, over the course of the semester. Each late day extends the deadline by 24 hours. Once late days are used, additional late submissions will not be accepted. If something serious comes up, contact the instructor as soon as possible to discuss options.
Assignments
TBA
Online Resources
More relevant resources beside each lecture on the schedule.
Schedule
Topics and readings will be updated on the course webpage as the semester progresses.
| Lecture | Topic |
|---|---|
| DP Fundamentals | |
| 1 | Introduction, Attacks |
| 2 | Definition of DP, Randomized Response, Laplace Mechanism |
| 3 | Report Noisy Max, Sparse Vector Technique |
| 4 | Exponential Mechanism and Inverse Sensitivity |
| 5 | Group privacy, Post-processing, Composition |
| 6 | Approximate DP, Gaussian Mechanism |
| 7 | Advanced Composition |
| Linear Queries | |
| 8 | SmallDB (synthetic data v1) |
| 9 | Private MWU (synthetic data v2) |
| 10 | Binary Tree Mechanism |
| 11 | Factorization and Projection |
| Optimization | |
| 12 | Other notions: Rényi DP and zCDP |
| 13 | DP-SGD and Amplification by Subsampling |
| 14 | DP-FTRL |
| 15 | Amplification by Iteration |
| Private Statistical Estimation Beyond Global Sensitivity | |
| 16 | Local sensitivity, Propose-Test-Release |
| 17 | Stable Histograms, Smooth Sensitivity |
| 18 | FriendlyCore |
| 19 | Stable Estimators |
| 20 | Robustness to Privacy Transformation |
| 21 | Fingerprinting lower bounds |
| Additional Special Topics | |
| 22 | Local and shuffle model |
| 23 | Private PAC learning |
| 24 | DP and Generalization/Adaptive Data Analysis |
| 25 | Project Presentations |
| 26 | Project Presentations |