diff --git a/website/docs/schedule/lectures.md b/website/docs/schedule/lectures.md
index faaf762..438f7ad 100644
--- a/website/docs/schedule/lectures.md
+++ b/website/docs/schedule/lectures.md
@@ -4,8 +4,8 @@
:----:|-------|:----------:|:-----------:|:-----:
|
**Differential Privacy**
| | |
9/4 | Course welcome
**Reading:** [*How to Read a Paper*](https://web.stanford.edu/class/ee384m/Handouts/HowtoReadPaper.pdf) | JH | - |
-9/6 | Basic private mechanisms
**Reading:** AFDP 3.2-4 | JH | - |
-9/9 | Composition and closure properties
**Reading:** AFDP 3.5 | JH | - | [Paper Signups](https://docs.google.com/spreadsheets/d/1hSbRy0mo3PjlozN0Ph1JkP5JwlRG8y7ukuCdorofncA/edit?usp=sharing)
+9/6 | Basic private mechanisms
**Reading:** [AFDP](https://www.cis.upenn.edu/~aaroth/Papers/privacybook.pdf) 3.2-4 | JH | - |
+9/9 | Composition and closure properties
**Reading:** [AFDP](https://www.cis.upenn.edu/~aaroth/Papers/privacybook.pdf) 3.5 | JH | - | [Signups](https://docs.google.com/spreadsheets/d/1hSbRy0mo3PjlozN0Ph1JkP5JwlRG8y7ukuCdorofncA/edit?usp=sharing) Due
9/11 | What does differential privacy actually mean?
**Reading:** [Lunchtime for Differential Privacy](https://github.com/frankmcsherry/blog/blob/master/posts/2016-08-16.md) | JH | - |
9/13 | Differentially private machine learning
**Reading:** [*On the Protection of Private Information in Machine Learning Systems: Two Recent Approaches*](https://arxiv.org/pdf/1708.08022)
**Reading:** [*Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data*](https://arxiv.org/pdf/1610.05755) | | |
| **Adversarial Machine Learning**
| |