Schedule

Empirical Security & Privacy, for Humans

By Mike Hicks

October 23, 2025

Jump to next class.

DateTopic / SpeakerReadings & handouts
Aug 26Introduction and syllabus
Aug 28Economic view of cybersecurity - Alex Gantman, VP Security Engineering, Qualcomm
Sep 2End users and cybersecurity
Sep 4Cybersecurity as a scientific pursuit - Cormac Herley, Principal Researcher, Microsoft
Sep 9Cybersecurity and risk assessment
Sep 11Passwords
Sep 16The business of attacks, and paying attackers for defense
Sep 18LLMs and their impact on cyberattacks
Sep 23Measuring secure software development practices
Sep 25Project pitchesIndividual students, or groups who wish to work together, should prepare project pitches. See the syllabus for details.
Sep 30Empirical evaluations: Fuzz testing
Oct 2Statistical tests: Pitfalls
Oct 7Threat modeling - Adam Shostack, Shostack Associates
Oct 9Fall break, no classProject proposals due. See the syllabus for details.
Oct 14Password managers, ethics of human studies
Oct 16What’s Still Missing in Static Analysis? A Decade-Long Journey - Mayur Naik, Prof of CIS @ UPennGuest lecture about static analysis technology (including for finding security bugs), the influence of LLMs on it, and how we measure progress.

Oct 21Building Security in Maturity Model (BSIMM)
Oct 23Economic investment in cybersecurity
Oct 28Usability: Privacy & Passwords
Oct 30Student: Noopur Bhatt
Nov 4Student: Jiayi Xin
Nov 6Student: Bharath Namboothiry
Nov 11Students: Davis Brown and Thia Richey
Nov 13Student: Lucia Kulzer
Nov 18Student: Ali Shirzad
Nov 20Student: Zhiyao Tang
Nov 25TG week: No class
Nov 27TG week: No class
Dec 2Final project presentations
Dec 4Final project presentations
Posted on:
October 23, 2025
Length:
5 minute read, 1064 words
See Also: