Computer Science EN.601.438/638
Theory of Differential Privacy
Fall 2026 | 3 credits | EQ | CSCI-THRY
Course Info
Instructor
Lydia Zakynthinou
lzakynthinou@jhu.edu
Office hours: Mon 12-1p or by appointment
Office hours location: Mt. Washington SE313
Teaching Assistant
Songtao Mao
smao13@jhu.edu
Office hours: Fri 1-2:30p or by appointment
Office hours location: on zoom
Meetings
MW 4:30-5:45p, Krieger 180
Textbook
There is no official textbook, but recommended books are:
- Cynthia Dwork and Aaron Roth, The Algorithmic Foundations of Differential Privacy, Foundations and Trends in Theoretical Computer Science, 2014.
- Salil Vadhan, The Complexity of Differential Privacy, Tutorials on the Foundations of Cryptography, Springer, 2017.
- Multiple Authors, Ferdinando Fioretto and Pascal Van Hentenryck (editors), Differential Privacy in Artificial Intelligence, From Theory to Practice, 2025.
Course Information
This course is an introduction to differential privacy as a foundational framework for reasoning about privacy in data analysis. Students will develop a principled understanding of why privacy risks arise when privacy is not an explicit design objective and how differential privacy enables formal, provable guarantees.
We will build on the algorithmic toolkit and statistical techniques for designing and analyzing differentially private methods, and study fundamental tradeoffs and lower bounds that characterize the limits of privacy.
Similar courses include Jonathan Ullman and Adam Smith's course at BU/NEU, Gautam Kamath's course at Waterloo.
Prerequisites
Students should be comfortable writing mathematical proofs involving algorithms, probability, and linear algebra. Introduction to Algorithms (601.433/633) satisfies this requirement; comparable theory coursework may be accepted with instructor approval.
Course Topics
- Privacy attacks; motivation for provable privacy.
- Differential privacy: definitions, variants, composition.
- Core mechanisms and algorithmic techniques, including Laplace, Gaussian, Exponential, and Binary Tree mechanisms.
- Differentially private optimization and machine learning, including DP-SGD, amplification by subsampling, and factorization mechanisms.
- Techniques beyond global sensitivity, including local sensitivity and propose-test-release.
- Fundamental limits and lower bounds, including fingerprinting and packing lower bounds.
- Advanced topics may include differentially private approaches for graphs, high-dimensional statistics, PAC learning, and connections between differential privacy and other trustworthy machine learning desiderata.
Course Expectations & Grading
In-class participation is required. There will be 3 homework assignments and a final project. The final grade will be computed based on the following weights:
- Homeworks: 50%
- Final Project: 30%
- Participation: 20%
Late assignments: each student has 4 late days (i.e. 96 hours) to use on homework assignments, not projects, over the course of the semester. Once late days are used, additional late submissions will not be accepted. If something serious comes up, contact the instructor as soon as possible to discuss options.
Collaboration and AI use: Please see the syllabus for course policies on collaboration, use of generative AI, and academic integrity.
Course Platforms
Schedule
Topics and readings will be updated on the course webpage as the semester progresses.
| Lecture | Date | Topic | Resources | Deliverables |
|---|---|---|---|---|
| DP Fundamentals | ||||
| 1 | Aug 31 | Motivation and Introduction to Differential Privacy | Lecture notes, Probability Review by A. Nikolov | |
| 2 | Sept 2 | Differential Privacy, Randomized Response, and the Laplace Mechanism | Lecture notes, DR Ch. 3.2-3.3 | |
| 3 | Sept 9 | Properties of Differential Privacy and Report Noisy Max | Lecture notes, DR Ch. 3.3-3.5 | |
| 4 | Sept 14 | Approximate Differential Privacy and the Gaussian Mechanism | ||
| 5 | Sept 16 | Advanced Composition | ||
| 6 | Sept 21 | Exponential Mechanism | ||
| 7 | Sept 23 | Sparse Vector Technique | HW1 out | |
| Linear Queries | ||||
| 8 | Sept 28 | Linear Query Release, Synthetic Data, and SmallDB | ||
| 9 | Sept 30 | Private Multiplicative Weights | ||
| 10 | Oct 5 | Factorization | HW1 due | |
| 11 | Oct 7 | Binary Tree Mechanism | HW2 out | |
| Privacy Accounting and Optimization | ||||
| 12 | Oct 12 | Rényi DP, zCDP, and Privacy Accounting | ||
| 13 | Oct 14 | DP-SGD and Amplification by Subsampling | ||
| 14 | Oct 19 | DP-FTRL and Correlated Noise | HW2 due | |
| 15 | Oct 21 | Amplification by Iteration | HW3 out; Projects out | |
| Private Statistical Estimation Beyond Global Sensitivity | ||||
| 16 | Oct 26 | Local Sensitivity and Propose-Test-Release | ||
| 17 | Oct 28 | Private Mean Estimation Beyond Global Sensitivity | ||
| 18 | Nov 2 | Subsample-and-Aggregate and FriendlyCore | HW3 due | |
| 19 | Nov 4 | Stable Estimators for High-Dimensional Statistics | ||
| 20 | Nov 9 | Robustness-to-Privacy and Inverse Sensitivity | ||
| 21 | Nov 11 | Packing Lower Bounds for Private Estimation | Proposals due | |
| 22 | Nov 16 | Fingerprinting Lower Bounds for Private Estimation | ||
| Connections and Special Topics | ||||
| 23 | Nov 18 | Local and Shuffle Models of Differential Privacy | ||
| 24 | Nov 30 | Differential Privacy, Adaptive Data Analysis and Generalization | ||
| 25 | Dec 2 | Differential Privacy and PAC Learning | ||
| 26 | Dec 7 | Project Presentations | ||
| 27 | Dec 9 | Project Presentations | ||
| Dec 17 | Final report due | |||