CS 4630 Defense Against The Dark Arts
University of Virginia · Fall 2026

Defense Against the Dark Arts

Meetings
Tue / Thu · 3:30 – 4:45 PM
Room
Thornton Hall E304
Prereq
CS 3710
LMS
Canvas

Staff

RoleNameOfficeOffice hoursEmail
Co-instructor Wajih Ul Hassan Rice Hall 522 Thursdays 9:00–10:30 AM hassan@virginia.edu
Co-instructor Muhammad Shoaib Rice Hall 425 Thursdays 12:00–12:30 PM, Fridays 12:00–1:00 PM ewe4gy@virginia.edu
Teaching Assistant Rui Zhao Rice Hall 425 Thursdays 11:30 AM – 12:00 PM, Fridays 1:00–2:00 PM dkw7xn@virginia.edu

Syllabus

1. What this course is

You will learn to attack systems so that you can defend them. We work at the level where security actually breaks: the stack frame, the parser, the browser origin, the audit log, and the AI agent that has been handed your credentials. The course is organized in four modules:

01
Systems & Software Security
x86 architecture, buffer overflows, format strings, ROP, control-flow integrity, malware, fuzzing, and the mitigations that actually ship in 2026.
02
Web Security
The same-origin policy, sessions and cookies, XSS, CSRF, SQL injection.
03
Threat Detection & Forensics
Intrusion detection, system auditing, forensic analysis, data provenance, incident reconstruction, threat-rule evasion, and tamper-evident logging.
04
AI Systems Security
The LLM and agent threat model, prompt injection, why the published defenses keep falling, jailbreaking, tool/MCP security, and AI as an offensive instrument.

Not covered: cryptography, privacy, cryptocurrency, hardware security. Take a CS 4501/6501 offering for those.

2. Prerequisites

CS 3710 is required. You must arrive able to:

If you cannot do these three things, this course will not be a productive use of your semester.

3. Learning objectives

By the end you should be able to:

  1. Take an unfamiliar binary and determine, with a debugger, whether and how it can be made to do something it wasn't meant to do.
  2. Write a working exploit for a memory-corruption bug and explain precisely which mitigation would have stopped it.
  3. Find and exploit the standard web vulnerability classes, and patch them correctly.
  4. Reason about an AI-integrated system's threat model — identify where untrusted input meets privilege, and say what an attacker gets.
  5. Reconstruct what happened on a compromised machine from its artifacts.
  6. Judge a security claim. Read a paper or a vendor blog that says "we reduced attack success to near zero" and know what question to ask next.

4. Grading

Every assignment A1–A5 is worth 10%, split evenly: 5% for the code you submit (AI-OK) and 5% for a short oral about it (NO-AI). The two halves are graded separately — a weak oral does not lower your code score, and a strong code submission does not lift your oral. A6 is a bonus — no oral, and it sits on top of the 100% rather than inside it.

25%
Assignment code
A1–A5 · 5% each
AI-OK
25%
Assignment orals
A1–A5 · 5% each
NO-AI
20%
Quizzes
5 × 20 min · in class · lowest dropped
NO-AI
30%
Final exam
Modules 1–4 · on paper · Fri Dec 11, 9–11 AM
NO-AI

The assignment measures what you can build with all available tools. The oral, in a later week, measures what you understand without them. Here’s the rhythm of one assignment:

Week N
Assignment released
The deadline
Submit your code
AI-OK
A later week
Short oral evaluation
NO-AI

A0 is a required pass/fail onboarding gate and carries no points. What it gates is access: every assignment after it assumes the signed pledge and the environment A0 sets up. Skipping it doesn’t cost you points directly — it costs you A1.Quizzes (20%). There are 5, each 15 minutes, on paper, closed-resource. A quiz runs at the start of class and the lecture follows it — plan to be there on time. Every quiz is announced in advance and marked on the calendar below; each badge lists the lectures it covers by number — Quiz 2 · Lec#7,8,9,10,11,12,13 is quizzed on the seven lectures labelled Lec#7 through Lec#13 in the calendar.

Your lowest quiz is dropped, so 4 count at 5% each. If you miss a quiz, that is the one you drop — there is nothing to arrange and nothing to document. Miss a second one and it scores zero, barring a documented emergency.

The final exam (30%) is cumulative over all four modules. It is an individual, closed-resource, AI-free assessment written on paper and completed in person: Friday, December 11, 9:00–11:00 AM.

The per-assignment code / oral breakdown is on the Assignments page.

5. Policies

Late work

Assignments may be submitted up to two days late. Each started day costs 10 percentage points off that assignment’s score: a 92 becomes an 82 one day late and a 72 two days late. A day means a started 24-hour period after that assignment’s deadline, so ten minutes late is one day late. After 48 hours we do not accept the work. A missed quiz is simply the one you drop — nothing to arrange. Oral evaluations and the final exam cannot be made up except for documented emergencies; if something stops you attending, tell us as soon as you reasonably can. Advance notice is expected when circumstances allow — we know they don’t always.

Ethics pledge

See the ethics pledge. You must sign it in A0 before you receive the course materials and VM access.

Collaboration

All assignments are individual. You may discuss concepts with anyone. You may not read, copy, or transcribe another student’s solution. Cite every source you use, including AI, in AI-USE.txt — what counts as adequate disclosure is spelled out in the AI policy.

Artificial intelligence

See the AI policy. The short version: AI is unrestricted on assignments provided you disclose it, and absent from oral evaluations, quizzes, and the final exam. Disclosure is never penalized. Non-disclosure is the violation.

Recording

Lectures are not recorded this semester.

6. Materials

No required textbook.


This schedule is subject to change. Check back often; major changes are announced in class.

Calendar

TuesdayThursdayFriday
Aug 25
Lec#1:Introduction & the Security Mindset
Aug 27
Lec#2:Authentication
01Systems & Software SecuritySept 1 – Oct 8
Sept 1
Lec#3:IA-32 Architecture
A0 out
Sept 3
Lec#4:Buffer Overflow I
Sept 4
A0 dueA1 out
Sept 8
Lec#5:Buffer Overflow II
Sept 10
Lec#6:Format String Vulnerabilities
Sept 15
Lec#7:Return-Oriented Programming
Quiz 1 · Lec#3,4,5,6
Sept 17
Lec#8:Control-Flow Integrity
A1 due
Sept 18
A2 out
Sept 22
Lec#9:Malware
Sept 24
Lec#10:Fuzzing & Memory Safety
Sept 25
Sept 29
Lec#11:Supply Chain Security MS
Oct 1
Lec#12:Code Obfuscation & Anti-Analysis
A2 due
Oct 2
A3 out
Oct 6
Fall Reading Days (Oct 3–6)
No class
Oct 8
Lec#13:Co-Residency and Side Channel Attacks
02Web SecurityOct 13 – Oct 22
Oct 13
Lec#14:The Web & the Same-Origin Policy MS
Quiz 2 · Lec#7,8,9,10,11,12,13A3 dueA4 out
Oct 15
Lec#15:Cookies, Sessions & CSRF MS
Oct 16
Oct 20
Lec#16:Cross-Site Scripting MS
Oct 22
Lec#17:SQL Injection & CAPTCHAs MS
Oct 23
03Threat Detection & ForensicsOct 27 – Nov 12
Oct 27
Lec#18:Intrusion Detection
Quiz 3 · Lec#14,15,16,17
Oct 29
Lec#19:IDS & System Auditing MS
Nov 3
Election Day
No class
Nov 5
Lec#20:Threat Rule Evasion MS
A5 out
Nov 10
Lec#21:Data Provenance & Forensics
Nov 12
Lec#22:Tamper-evident Logging
Nov 13
04AI Systems SecurityNov 17 – Dec 8
Nov 17
Lec#23:The LLM & Agent Threat Model
Nov 19
Lec#24:Prompt Injection — and why the defenses keep failing MS
A5 dueA6 out
Nov 24
Lec#25:Jailbreaking Techniques
Quiz 4 · Lec#18,19,20,21,22
Nov 26
Thanksgiving recess (Nov 25–29)
No class
Dec 1
Lec#26:Agents, Tools & MCP · AI as an offensive instrument
Dec 3
Lec#27:Red Teaming
A6 due
Dec 4
Dec 8
Lec#28:Wrap-up & final-exam logistics
Quiz 5 · Lec#23,24,25,26,27
Dec 11 9:00–11:00 AM
EXAMFinal Exam — Modules 1–4
Final · 30%

Each assignment's out and due dates are in the calendar above. The oral follows in a later week; its calendar tag marks the last day that round can be taken.

MS marks a session presented by Muhammad Shoaib.