Oct 11–14, 2026 · Lancaster, UK

The 29th International Symposium on Research in Attacks, Intrusions and Defenses.

Conference Program


October 11, 2026 (Sunday)

09:00 - 17:00

Arriving Day Arriving Day

October 12, 2026 (Monday)

09:00 - 09:30

Remarks Opening Remarks

09:30 - 10:30

Keynote: TBD

At: TBD

Chair: TBD

Description: TBD

About Speaker: TBD

10:30 - 11:00

Coffee Icon Break

11:00 - 12:00

Session 1A:
Web Security & Phishing

At: TBD

Chair: TBD

224. Phishing the Phishers with SpecularNet: Hierarchical Graph Autoencoding for Reference-Free Web Phishing Detection

473. Clouding the Mirror: Stealthy Prompt Injection Attacks Targeting LLM-based Phishing Detection

628. Exploiting Unsafe Rendering in LLM-Powered Workflow Platforms

Session 1B:
IoT & Network Systems

At: TBD

Chair: TBD

95. Cherry-Picking Bits: Enabling Key Reconstruction on Resource-Constrained Devices using SRAM PUFs

285. Effective Handling of Erroneous Executions of Automation Rules on Multiple Platform Smart Home IoT Systems

786. FragStrike: A Memory-Exhaustion Attack against Tor Nodes via Heap Fragmentation

12:00 - 13:30

Lunch Break Lunch Break

13:30 - 14:50

Session 2A:
Program Analysis & Reverse Engineering

At: TBD

Chair: TBD

216. Function Name Recovery via Self-Transformative and Variable-Enrichment Approaches

421. ObfuscationGT: A Comprehensive Evaluation of Disassembler Accuracy and Coverage on Obfuscated Code

799. Waslr: Fine-Grained Memory Randomization for WebAssembly

871. 0xELF: Reverse Engineering Framework for Flexo-Generated Weird Machines

Session 2B:
Cyber-Physical & Industrial Control Systems

At: TBD

Chair: TBD

174. Patronus: Real-Time Authentication of Industrial Control Systems Communication via Process-Aware Certificates

287. Unveiling Operator-Induced Vulnerabilities in OCPP: From Deployment Misconfigurations to Message-Processing Exploits

222. CANdy: Backward-Compatible CAN Message Authentication via Sub-Bit Injection on Commercial Controllers

479. DEFFSM: Deployable and Explainable Fuzzy Finite State Machine for Anomaly Detection of Time-Series Data

14:50 - 15:30

Coffee Icon Break

15:30 - 16:50

Session 3A:
Systems & Kernel Security

At: TBD

Chair: TBD

8. Sentinel: An Isolation Framework for Security Services on TrustZone

55. vSECvma: A Formally Verified Linux Kernel Protection Framework

131. Firefly: High-Performance Transient Execution Attack Defenses for In-Kernel Sandboxes

319. Too Private to Tell: Practical Token Theft Attacks on Apple Intelligence

Session 3B:
Threat Intelligence & Intrusion Detection

At: TBD

Chair: TBD

16. STINER: Automated Extraction of Strategic Cyber Threat Intelligence from X

90. Sometimes Less is More: A Minimalist Approach to Neighborhood-level Provenance-based Intrusion Detection

557. Grounded in Knowledge, Guided by Reason: Automated Fake Cyber Threat Intelligence Detection via Knowledge-Augmented LLM Rationales

821. No Data? No Problem: Synthesizing Security Graphs for Better Intrusion Detection

17:00 - 17:40

Poster Session

At: TBD

Chair: TBD

TBD. TBD

18:00 - 20:00

Banquet Banquet

October 13, 2026 (Tuesday)

09:00 - 10:00

Keynote: TBD

At: TBD

Chair: TBD

Description: TBD

About Speaker: TBD

10:00 - 10:30

Coffee Icon Break

10:30 - 11:30

Session 4A:
Adversarial Machine Learning

At: TBD

Chair: TBD

139. Democratizing False Positives Filtering Through Learning Assisted Reasoning

513. Merge Now, Regret Later: The Hidden Cost of Model Merging Is Adversarial Transferability

516. How ViT Backdoors Affect Post-Hoc Explanations and What this Means for XAI-based Defenses

Session 4B:
Network & Distributed Systems Security

At: TBD

Chair: TBD

405. Effective and Efficient Threat Hunting with Small Language Models

610. Finding a Needle in a Haystack: Index Poisoning and Mitigation in IPFS DHT

717. ShadowICS: Detecting OT Sandboxes via Passive Industrial Traffic Monitoring

12:00 - 13:30

Lunch Break Lunch Break

13:30 - 14:50

Session 5A:
LLM Safety & Robustness

At: TBD

Chair: TBD

19. CoT-GraphPoison: A Novel Poisoning Attack Targeting Chain-of-Reasoning in GraphRAG

36. DYNASHIELD: A Black-Box Moving Target Defense for LLMs via Dynamic Decoding Customization

249. Release-Time Safety Is Not Deployment-Time Safety in Agentic LLMs

286. aiXamine: Unified Black-Box Evaluation of Cross-Dimensional Trade-offs in LLM Safety, Security, and Privacy

Session 5B:
Hardware & Architecture Security

At: TBD

Chair: TBD

410. A Covert Channel via Scheduler-Driven Core Migration on Hybrid CPUs

63. Lightweight Detection of Electromagnetic Signal Injection Attacks on Image Sensors

703. Devlore: Device Interrupt Protection for Confidential VMs

710. Reverse Engineering and Systematic Evaluation of Prefetcher-Based Security Vulnerabilities in Commercial RISC-V Processors

14:50 - 15:30

Coffee Icon Break

15:30 - 16:50

Session 6A:
Malware Detection & Analysis

At: TBD

Chair: TBD

2. Concept Drifts, Detector Evolves: Malware Detection Made Easy with LLMalware

91. Smoke and Mirrors: Systematic OT Malware Elicitation

94. AndroTruth: A Reliable Benchmark Android Malware Dataset Derived from Technical Expert Reports

309. Small, Free, and Effective: Orchestrating Open-Weight Small Language Models to Outperform Single LLM for Malware Analysis

Session 6B:
Software Supply Chain Security

At: TBD

Chair: TBD

56. Supply Chain Insecurity: Exposing Vulnerabilities in iOS Dependency Management Systems

266. Where Patches Stall: Ecosystem-Level Constraint Policies, Not Upstream Health, Covary with Supply Chain Propagation

315. Vulnerability Evolution and the Promise of Automated Gatekeeping in Open-Source Software

360. Adversarial Python Package Generation via Piggybacking with Large Language Models

18:00 - 20:00

Dinner Buffet Buffet Dinner

October 14, 2026 (Wednesday)

08:30 - 09:50

Session 7A:
Software Vulnerability & Code Repair

At: TBD

Chair: TBD

281. mono: Is Source Code Enough for Verification? Stratifying Patch-Mined Vulnerability Fixes by Context Sufficiency

352. Prism: A Multi-Team Orchestration of LLM Agents for Automatic Program Repair

453. Focus on What Matters: Fisher-Guided Adaptive Multimodal Fusion for Vulnerability Detection

648. To WASM or Not to WASM: Evaluation of Browser Fingerprinting Defenses Under WASM based Obfuscation

Session 7B:
Machine Learning Defenses & Backdoors

At: TBD

Chair: TBD

84. Hidden Threats in a Single Round: Backdoor Attack on One-Shot Federated Learning

335. Backdooring Acoustic Foundation Models for Physically Realizable Triggers

368. CARIS: Layer-to-Neuron Local Repair for Deep Neural Networks

391. UDPU: Unlabeled Data Purification and Unlearning for Backdoor Defense

10:00 - 10:30

Coffee Icon Break

11:00 - 12:00

Session 8A:
Anomaly Detection & Honeypots

At: TBD

Chair: TBD

436. VR-Themis: A Scalable Framework for Virtual Reality Application Clone Detection

823. Beyond the Blank Slate: Typed Operating System State for Cross-Session Consistency in LLM-Powered Honeypots

831. CANDLe : Discerning Deep Learning Methods for CAN Bus Intrusion Detection via a Reproducible and Extensible Benchmarking Framework

Session 8B:
Session 8B: Usable Security & Human Factors

At: TBD

Chair: TBD

26. VersaPSE: Versatile Password Strength Evaluation Using Continual Learning

126. Caught on Camera: Toward Evaluating and Defending On-screen Deepfakes With Mobile and Wearable Camera Devices

494. Understanding the Impact of AI Code Assistants on Security API Usage: An Empirical Study

944. "It Seems Like an Advertisement": Attention, Interpretation, and Response to Mobile Antivirus Warnings

12:00 - 14:30

Conversation Icon Closing Ceremony & Social Networking