THINK FIRST·CODE LATER

CPS 4301

Software Engineering

Engineering software in the age of AI — from requirements to operation

Chapters
14
Questions
420
Labs
84
Your progress
0 · 0% correct

About this course

The study of the software development process from initial requirements analysis through the operation and maintenance of the final system. The course covers the organization of software development projects, verification and validation of systems, security and privacy, legal aspects of software development, and sustainable computing.

It is taught for the age of AI. Assistants and agents now write code in seconds; the engineering questions remain — what should be built, how do we know it is right, safe and fair, and who is responsible when it runs in the real world? Throughout the course, students learn to use AI where it helps and to verify everything it produces.

Focus

  • Foundations — why software projects fail, essential vs. accidental complexity, process models from waterfall to DevOps
  • Requirements — discovering real needs, user stories and acceptance criteria, precise and testable specifications
  • Project and design — estimation, planning and risk; architecture and design for change; code quality and working with AI assistants
  • Verification and validation — test design, coverage, mutation and property-based testing, and the evaluation of AI features
  • Security, privacy and law — threat modeling and secure coding, privacy engineering (PIPL, GDPR, FERPA), licences, liability, AI regulation and professional ethics
  • Operation and evolution — deployment, monitoring and incidents, maintenance and technical debt, green software and accessibility, and the future of software engineering with AI

Learning objectives

By the end of the course, students will be able to:

  1. Explain the software lifecycle and choose and justify a development process for a given project and its risks.
  2. Elicit, specify and prioritize requirements — including accuracy and policy requirements for AI features — and keep them traceable.
  3. Estimate, plan and organize a team project, and manage its risks.
  4. Design a maintainable architecture that isolates change and failure, and record decisions in architecture decision records.
  5. Write clean code, review code critically — including AI-generated code — and refactor safely.
  6. Design and automate tests at every level, measure their strength, and evaluate non-deterministic AI features.
  7. Identify security threats and privacy risks and design controls against them, including prompt injection.
  8. Recognize the legal and ethical dimensions of software — intellectual property, licences, liability, regulation — and apply a professional code of ethics.
  9. Operate, maintain and evolve a system reliably and sustainably, and define how AI may be used responsibly in each engineering activity.

Teaching approach

Verify, then trust. The course treats AI as a powerful but fallible teammate: useful for removing routine work, never a substitute for understanding, verification and responsibility.

  • One running case study — StudyBuddy, a course-help app with an AI tutor for university students. Every chapter applies its ideas to the same system, so requirements, design, testing, security, privacy, law and operations connect into one engineering picture.
  • An "AI angle" in every chapter: what AI changes in that activity, where it fails, and how to check its output.
  • Clear rules for AI use by activity — not allowed, allowed with conditions, or required (as in "critique the AI" exercises where students find the flaws in AI-generated requirements, code or tests).
  • Programming labs turn engineering ideas into working tools (traceability checkers, test generators, resilience patterns, security and privacy checks), each tested automatically.
  • Studio labs are realistic engineering tasks — threat models, impact assessments, postmortems, architecture decisions — with complete model answers.
  • Team practice: the concepts are designed to be applied in a semester-long team project built in iterations, with reviews, automated tests and a documented decision trail.

Course content

Open a chapter to read its review, then practise with its question bank.

Foundations

  1. Chapter 1 · Week 1

    Software Engineering in the Age of AI

    programming vs. engineering, famous failures, essential vs. accidental complexity, lifecycle activities, quality attributes, AI coding assistants, the StudyBuddy case

    0/30 answered
  2. Chapter 2 · Week 2

    Software Process Models

    waterfall, V-model, incremental and spiral development, Agile Manifesto, Scrum, Kanban and WIP limits, Little's law, DevOps and continuous delivery, DORA metrics, choosing a process, AI in the workflow

    0/30 answered

Requirements

  1. Chapter 3 · Week 3

    Requirements Engineering I: Discovering Needs

    requirements vs. design, functional and non-functional requirements, stakeholders, elicitation techniques, interviews, user stories and INVEST, acceptance criteria (Given/When/Then), personas, story mapping and MVP, Kano model, AI in elicitation

    0/30 answered
  2. Chapter 4 · Week 4

    Requirements Engineering II: Specifying and Managing

    qualities of a good requirement, ambiguity and weak words, EARS templates, measurable quality requirements, SRS documents vs. backlogs, MoSCoW prioritization, traceability, change management, requirements validation, precision and recall for AI features

    0/30 answered

Project and Design

  1. Chapter 5 · Week 5

    Organizing a Software Project

    scope/time/cost/quality, team roles and structures, Conway's law, Brooks's law and communication paths, estimation (cone of uncertainty, planning poker, velocity, three-point/PERT, COCOMO), planning and critical path, risk management, Git workflow and code review, psychological safety and bus factor, AI in project management

    0/30 answered
  2. Chapter 6 · Week 6

    Architecture and Design for Change

    architecture as hard-to-change decisions, coupling and cohesion, information hiding, SOLID and dependency inversion, layered/MVC/client-server/event-driven styles, modular monolith vs. microservices, quality attributes and tactics (timeouts, retries, circuit breaker, caching), architecture decision records, designing around AI components (provider abstraction, RAG, guardrails)

    0/30 answered
  3. Chapter 7 · Week 7

    Code Quality and Working with AI Assistants

    readability and naming, code smells, refactoring in small safe steps, cyclomatic complexity, static analysis, error handling and defensive programming, prompting as specification, failure modes of AI-generated code, hallucinated packages, reviewing AI code, coding agents

    0/30 answered

Verification and Validation

  1. Chapter 8 · Week 8

    Verification and Validation I: Testing Fundamentals

    error/fault/failure, test cases and oracles, test levels and the test pyramid, equivalence partitioning, boundary value analysis, decision tables, state-transition testing, statement and branch coverage, JUnit 5 and Arrange-Act-Assert, FIRST, test doubles, TDD, AI-generated tests

    0/30 answered
  2. Chapter 9 · Week 10

    Verification and Validation II: Beyond Unit Tests

    integration strategies and contract tests, system testing (load, performance percentiles, usability), acceptance, alpha/beta and A/B tests, regression testing and CI pipelines, flaky tests, mutation testing, property-based and metamorphic testing, inspections, design by contract, formal methods, evaluating AI features (golden sets, groundedness, LLM-as-judge, red-teaming)

    0/30 answered

Security, Privacy and Law

  1. Chapter 10 · Week 11

    Security Engineering

    CIA triad, Saltzer and Schroeder's principles, defense in depth, secure development lifecycle, threat modeling with STRIDE, OWASP Top 10, injection, broken access control, password storage, secrets, input validation, software supply chain (Log4Shell, xz, SBOM), security testing (SAST, DAST, SCA, fuzzing), AI-specific threats (prompt injection, insecure output handling, excessive agency)

    0/30 answered
  2. Chapter 11 · Week 12

    Privacy Engineering

    security vs. privacy, personal and sensitive data, contextual integrity, data-protection principles, PIPL, GDPR, FERPA, Privacy by Design, data inventory, minimization, retention, pseudonymization vs. anonymization, re-identification and k-anonymity, differential privacy, data-subject rights, impact assessments, privacy of AI features (prompts, providers, cross-border transfer, automated decisions)

    0/30 answered
  3. Chapter 12 · Week 13

    Legal Aspects and Professional Ethics

    copyright, patents, trade secrets and trademarks for software, ownership of student and employee work, open-source licences (MIT, BSD, Apache 2.0, LGPL, MPL, GPL, AGPL) and compatibility, Creative Commons, AI-generated code and copyright, contracts, warranties and liability, EU AI Act and China's generative-AI rules, computer-misuse law, ACM/IEEE Software Engineering Code of Ethics, ethical cases (Volkswagen), fairness of AI in education

    0/30 answered

Operation and Evolution

  1. Chapter 13 · Week 14

    Operation, Maintenance and Sustainable Computing

    deployment strategies (blue-green, canary, feature flags, rollback), observability (logs, metrics, traces, golden signals), SLI/SLO/SLA and error budgets, incident response and blameless postmortems, maintenance types, Lehman's laws, technical debt, legacy modernization (strangler fig, characterization tests), green software (energy, carbon awareness, SCI, AI footprint), accessibility (WCAG), social and technical sustainability

    0/30 answered
  2. Chapter 14 · Week 15

    The Future of Software Engineering with AI

    history of automation in programming, coding agents and benchmarks (SWE-bench), levels of AI autonomy, spec-driven development, verification as the bottleneck, guardrails for agents, risks at scale (comprehension debt, deskilling, security, concentration, energy), lasting skills, course synthesis and the StudyBuddy retrospective

    0/30 answered
Labs

84 labs with model answers

56 programming labs and 28 studio labs (written engineering tasks). Work out your own answer first, then compare.