United We TransformCreate teamsGrade your agenda
Atlas/Events/USENIX Security
showcase or expo program agenda analysis

USENIX Security

This showcase or expo program in Academic / Research / Science shows 80 visible agenda rows from usenix.org and scores 43/100: a moderate design signal with incomplete evidence. The clearest public signals sit in Learning Transfer and Future-of-Work Fit; the main limits are Follow Through and Network Design. Visible mechanisms include Participant work, Feedback, Impact evidence, and Network design. Follow-through or tracking is at least visible enough to inspect, though causal proof still depends on stronger... A practical reading: For a reader, this is a useful but still incomplete public example: it reads as a showcase or expo program, with the strongest visible signal in learning transfer and future-of-work fit and the biggest open question around follow through and network design. The practical test is whether the published agenda connects the room to execution quality beyond the public agenda. This page is an original public-evidence analysis, not a copy of the source agenda or an endorsement of the event. The score places the visible agenda in the moderate design signal band. The strongest visible pillars are Learning Transfer, Future-of-Work Fit, and Problem Specificity; the thinnest visible pillars are Follow Through, Network Design, and Personalization. Visible mechanisms include Participant work, Feedback, Impact evidence, Network design, and Learning transfer. The extracted agenda preview includes 80 visible rows. The most common formats are Demo, Break, and Training; the most common inferred purposes are Showcase, Wellbeing, and Skill Building.

Primary source evidence: usenix.org ↗ · Archived copy (2026-06-21)

Eight-pillar fingerprint

Hover any pillar to see what it measures and, where it scored low, what the agenda is missing.

Participation Architecture?43
Participation Architecture - 43/100. Participant work, contribution, interaction, and alternatives to passive broadcast.
Follow Through?5
Follow Through - 5/100. Owners, dates, commitments, progress checks, and accountability after the room.Missing: Add named owners, dates, implementation checkpoints, and a visible post-event continuation path.
Problem Specificity?54
Problem Specificity - 54/100. A clear costly problem, objective, decision, or performance target.
Personalization?41
Personalization - 41/100. Role, path, goal, preparation, or connection tailoring for participants.Missing: Create role-based paths, prepared questions, tailored breakouts, or participant-specific next steps.
Network Design?38
Network Design - 38/100. Structured weak ties, bridge-building, mixers, and relationship persistence.Missing: Replace generic networking blocks with designed introductions, ask-offer exchanges, peer groups, or bridge-building rituals.
Learning Transfer?63
Learning Transfer - 63/100. Applied practice, feedback, workplace use, refreshers, and 30-90 day transfer.
Evidence Maturity?48
Evidence Maturity - 48/100. Baseline, comparison, follow-up, isolation, and attribution confidence.
Future-of-Work Fit?63
Future-of-Work Fit - 63/100. Value against time, hybrid reality, accessibility, AI, and meeting load.

Fix the gaps

Field-tested exercises matched to this agenda's weakest pillars, from the exercise library.

Agenda Preview

The actual agenda we captured. Every block is classified by format and purpose. Open any block to see how we read it; the colored edge shows whether it is participant work, broadcast, logistics, or a showcase.

Room vs wrapper

59 percent of the 80 classified blocks put participants to work; the rest broadcast, show, or handle logistics. That mix is what drives the participation score.

47
7
4
22
Participant workBroadcastShowcaseLogistics
all eventPoster SessionPoster SessionShowcase+
Format · ShowcasePoster SessionPresenters display work; attendees browse and ask questions. Some interaction, not structured work.
Evidence basisMediumRead from source
all eventCall for PostersPoster SessionShowcase+
Format · ShowcasePoster SessionPresenters display work; attendees browse and ask questions. Some interaction, not structured work.
Evidence basisMediumRead from source
7:00 am - 8:45 amContinental BreakfastMealWellbeing+
Format · LogisticsMealA pacing block. Can carry unstructured networking, not scored as participant work.
Evidence basisMediumRead from source
8:45 am - 9:30 amOpening Remarks and AwardsOpening RemarksOrientation+
Format · BroadcastOpening RemarksFraming or welcome from the stage. Orients the room, not participatory.
Evidence basisMediumRead from source
9:30 am - 10:00 amCoffee and Tea BreakBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
10:00 am - 11:30 amTrack 1UnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventDarren Shou is the Chief Strategy Officer at RSAC. Darren was previously CTO at Gen Digital (f.k.a NortonLifeLock) where he helped the company grow to over 500M users with innovative new products and integrating companies such as Avast and Avira. Prior to serving as CTO, Darren was in product development leadership roles at Symantec and Microsoft. He is a global keynote speaker, a contributor at WIRED, and has been featured in major media outlets such as the Wall Street Journal, Financial Times, and CNN.KeynoteThought Leadership+
Format · BroadcastKeynoteA featured talk from the stage. Builds awareness and energy, produces no participant output on its own.
Evidence basisMediumRead from source
all eventAI Red Teaming is a critical approach for uncovering these emerging threats, but manual testing alone cannot keep pace with GenAI's rapid development. Automation is essential for scalable, efficient, and adaptive red teaming efforts. In this talk, I will cover the fundamentals of AI Red Teaming, demonstrate how automated attacks can help identify ethical and security risks at scale, and explore how open-source AI red teaming tools are making these techniques more accessible. By proactively identifying vulnerabilities before AI systems are deployed, we can work together toward a safer and more ethical AI future.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventWe evaluate GradEscape on four datasets and three widely-used language models, benchmarking it against four state-of-the-art AIGT evaders. Experimental results demonstrate that GradEscape outperforms existing evaders in various scenarios, including with an 11B paraphrase model, while utilizing only 139M parameters. We have successfully applied GradEscape to two real-world commercial AIGT detectors. Our analysis reveals that the primary vulnerability stems from disparity in text expression styles within the training data. We also propose a potential defense strategy to mitigate the threat of AIGT evaders. We open-source our GradEscape for developing more robust AIGT detectors.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventLarge Language Models (LLMs) have demonstrated remarkable capabilities of generating texts resembling human language. However, they can be misused by criminals to create deceptive content, such as fake news and phishing emails, which raises ethical concerns. Watermarking is a key technique to address these concerns, which embeds a message (e.g., a bit string) into a text generated by an LLM. By embedding the user ID (represented as a bit string) into generated texts, we can trace generated texts to the user, known as content source tracing. The major limitation of existing watermarking techniques is that they achieve sub-optimal performance for content source tracing in real-world scenarios. The reason is that they cannot accurately or efficiently extract a long message from a generated text. We aim to address the limitations.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventBuilding on this observation, we propose a straightforward method to BOOST jailbreak attacks by appending eos tokens. Our systematic evaluation shows that this strategy significantly increases the attack success rate across 8 representative jailbreak techniques and 16 open-source LLMs, ranging from 2B to 72B parameters. Moreover, we develop a novel probing mechanism for commercial APIs and discover that major providers - such as OpenAI, Anthropic, and Qwen - do not filter eos tokens, making them similarly vulnerable. These findings highlight a hidden yet critical blind spot in existing alignment and content filtering approaches.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventSafety alignment has become an indispensable procedure to ensure the safety of large language models (LLMs), as they are reported to generate harmful, privacy-sensitive, and copy-righted content when prompted with adversarial instructions. Machine unlearning is a representative approach to establishing the safety of LLMs, enabling them to forget problematic training instances and thereby minimize their influence. However, no prior study has investigated the feasibility of adversarial unlearning - using seemingly legitimate unlearning requests to compromise the safety of a target LLM.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventLeveraging the tool we developed for rapid generation of crafted certificates and detection of DoS vulnerabilities, we successfully discovered 18 new vulnerabilities and identified 12 previously known CVEs across seven mainstream cryptographic libraries. Our findings demonstrate the effectiveness of exploiting and detecting DoS vulnerabilities via X.509 certificates, revealing that X.509DoS is a widespread threat that has not been well-studied previously. Our work also shows that strict adherence to textbooks or standards does not guarantee security, highlighting the need for cryptographic library developers to pay more attention to real-world considerations.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventEvaluation in widely used benchmark datasets, DARPA TC and OpTC, demonstrates TAPAS's effectiveness in providing fast, low-overhead online detection while maintaining similar detection accuracy to state-of-the-art methods. Our results show that TAPAS reduces storage requirements by up to 1806× and achieves 99.99% accuracy with an average detection time of 12.78 seconds per GB of audit data, validating its practicality for enterprise deployment with throughputs well above the enterprise requirement of 10^4KB/s.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventBlueGuard facilitates the creation of hardware-accelerated HGI applications and frees the CPU while providing performance isolation. As a beneficial side effect, BlueGuard is capable of introspecting even bare metal servers that are usually out of scope for VMI systems. Furthermore, BlueGuard abstracts the DPU accelerators and provides kernel bypassing, non-blocking memory access, and user-level threading to achieve µs-scale introspection latency. Finally, we introduce delta introspection to accelerate the detection of state changes with BlueGuard and demonstrate the ability to isolate infected machines on a network layer.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventThis paper introduces NÜWA, a novel static analysis technique that leverages constraint semantic inconsistencies to detect vulnerabilities in embedded systems. NÜWA achieves scalable and precise vulnerability discovery by addressing the challenges of identifying constraint semantics across diverse implementations and accurately extracting them. We implemented NÜWA and evaluated it using known vulnerability datasets, including 31 vulnerabilities from 13 vendors, and compared its performance to five state-of-the-art (SOTA) tools. NÜWA identified 18, 22, 6, 17, and 19 more vulnerabilities than the respective SOTA tools. Further analysis demonstrates that NÜWA effectively extracts constraints with minimal false positives. To date, NÜWA has uncovered 152 previously unknown vulnerabilities which are all confirmed by the developers, and 88 were assigned with CVE IDs.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
11:30 am - 1:00 pmLunch (on your own)MealWellbeing+
Format · LogisticsMealA pacing block. Can carry unstructured networking, not scored as participant work.
Evidence basisMediumRead from source
all eventAttackers regularly use SSH (Secure SHell) to compromise systems, e.g., via brute-force attacks, establishing persistence by deploying SSH public keys. This ranges from IoT botnets like Mirai, over loader and dropper systems, to the back-ends of malicious operations. Identifying compromised systems at the Internet scale would be a major break-through for combatting malicious activity by enabling targeted clean-up efforts.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventExposing the Guardrails: Reverse-Engineering and Jailbreaking Safety Filters in DALL·E Text-to-Image PipelinesBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventSpecifically, we demonstrate that these models are highly susceptible to DIFF2, a simple yet effective attack, which substantially diminishes their robustness assurance. Essentially, DIFF2 integrates a malicious diffusion-sampling process into the diffusion model, guiding inputs embedded with specific triggers toward an adversary-defined distribution while preserving the normal functionality for clean inputs. Our case studies on adversarial purification and robustness certification show that DIFF2 can significantly reduce both post-purification and certified accuracy across benchmark datasets and models, highlighting the potential risks of relying on pre-trained diffusion models as defensive tools. We further explore possible countermeasures, suggesting promising avenues for future research.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventOur results are significant: for the first time, we have demonstrated that attackers are indeed using Tor to conceal their identities while targeting cloudless IoT devices. Over a period of 12 months, TORCHLIGHT analyzed 26 TB of traffic, revealing 45 vulnerabilities, including 29 zero-day exploits with 25 CVE-IDs assigned (5 CRITICAL, 3 HIGH, 16 MEDIUM, and 1 LOW) and an estimated value of approximately $312,000. These vulnerabilities affect around 12.71 million devices across 148 countries, exposing them to severe risks such as information disclosure, authentication bypass, and arbitrary command execution. The findings have attracted significant attention, sparking widespread discussion in cybersecurity circles, reaching the top 25 on Hacker News, and generating over 190,000 views.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventThis work demonstrates that the Ethereum P2P network does not offer this anonymity. We present a methodology that enables any node in the network to identify validators hosted on connected peers and empirically verify the feasibility of our proposed method. Using data collected from four nodes over three days, we locate more than 15% of Ethereum validators in the P2P network. The insights gained from our deanonymization technique provide valuable information on the distribution of validators across peers, their geographic locations, and hosting organizations. We further discuss the implications and risks associated with the lack of anonymity in the P2P network and propose methods to help validators protect their privacy.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventIn this study, we systematically analyze security threats associated with 3D printing, focusing specifically on vulnerabilities caused by G-Code commands. We introduce attacks and attacker models that assume a less powerful adversary than traditionally considered, broadening the scope of potential security threats. Our findings show that even minimal access to the 3D printer can result in significant security breaches, such as unauthorized access to subsequent print jobs or persistent misconfiguration of the printer. We identify 278 potentially malicious G-Codes across the attack categories Information Disclosure, Denial of Service, and Model Manipulation. Our evaluation demonstrates the applicability of these attacks across various 3D printers and their firmware. Our findings underscore the need for a better standardization process of G-Codes and corresponding security best practices.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventInspired by the success of fingerprinting on traditional 2D printers, we introduce SIDE (Secure Information EmbeDding and Extraction), a novel fingerprinting framework tailored for 3D printing. SIDE addresses the adversarial challenges of 3D print forensics by offering both secure information embedding and extraction. First, through novel coding-theoretic techniques, SIDE is both~break-resilient and~loss-tolerant, enabling fingerprint recovery even if the adversary breaks the print into fragments and conceals a portion of them. Second, SIDE further leverages Trusted Execution Environments (TEE) to secure the fingerprint embedding process.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventWith 128 servers jointly generating a proof for a circuit of size 2^21 gates, the experiment demonstrates over 30x speedup and reduced RAM requirements compared to a local prover, while the witness is still private. Previous works were unable to achieve such savings in both time and memory efficiency. Moreover, our protocol performs well under various network conditions, making it practical for real-world applications.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
5:00 pm - 6:00 pmPoster Session and Happy HourPoster SessionShowcase+
Format · ShowcasePoster SessionPresenters display work; attendees browse and ask questions. Some interaction, not structured work.
Evidence basisMediumRead from source
all eventCheck out the cool new ideas and the latest preliminary work on display at the Poster Session and Happy Hour. Take advantage of the opportunity to mingle with colleagues who may share your area of interest while enjoying complimentary food and drinks. View the list of accepted posters.Poster SessionShowcase+
Format · ShowcasePoster SessionPresenters display work; attendees browse and ask questions. Some interaction, not structured work.
Evidence basisMediumRead from source
6:00 pm - 7:00 pmUSENIX 50th Anniversary CelebrationUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventLisa LeVasseur is the founder and director of Internet Safety Labs (ISL), a non-profit digital product safety testing organization. With degrees in Computer Science, Philosophy, and Business, Lisa has more than three decades in the tech industry, with expertise in software architecture, industry standards, and product management. A 2024-25 Technology and Human Rights Fellow at the Harvard Kennedy School's Carr-Ryan Center, Lisa's championing of digital product safety as a human right is gaining recognition as a necessary democratizing force for the digital age.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventDrawing on case studies covering text and image scraping, this presentation includes a validation study demonstrating how LLMs trained on intentionally "poisoned" content experience degraded performance, ultimately making large-scale crawling a net negative for data harvesters. Rather than relying on traditional blocking (which remains neutral to a crawler's value proposition) or CAPTCHA/puzzle approaches, this adversarial strategy focuses on reshaping the cost-benefit equation so that unscrupulous collection efforts yield poor results.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventLLM Security 2: Jailbreaking and Prompt StealingBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventTwinBreak: Jailbreaking LLM Security Alignments based on Twin PromptsBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventMachine learning is advancing rapidly, with applications bringing notable benefits, such as improvements in translation and code generation. Models like ChatGPT, powered by Large Language Models (LLMs), are increasingly integrated into daily life. However, alongside these benefits, LLMs also introduce social risks. Malicious users can exploit LLMs by submitting harmful prompts, such as requesting instructions for illegal activities. To mitigate this, models often include a security mechanism that automatically rejects such harmful prompts. However, they can be bypassed through LLM jailbreaks. Current jailbreaks often require significant manual effort, high computational costs, or result in excessive model modifications that may degrade regular utility.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventWe introduce TwinBreak, an innovative safety alignment removal method. Building on the idea that the safety mechanism operates like an embedded backdoor, TwinBreak identifies and prunes parameters responsible for this functionality. By focusing on the most relevant model layers, TwinBreak performs fine-grained analysis of parameters essential to model utility and safety. TwinBreak is the first method to analyze intermediate outputs from prompts with high structural and content similarity to isolate safety parameters. We present the TwinPrompt dataset containing 100 such twin prompts. Experiments confirm TwinBreak's effectiveness, achieving 89% to 98% success rates with minimal computational requirements across 16 LLMs from five vendors.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventExploiting Task-Level Vulnerabilities: An Automatic Jailbreak Attack and Defense Benchmarking for LLMsBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventPAPILLON: Efficient and Stealthy Fuzz Testing-Powered Jailbreaks for LLMsBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventWe evaluated PAPILLON on 7 representative LLMs and compared it with 5 state-of-the-art jailbreaking attack strategies. For proprietary LLM APIs, such as GPT-3.5 turbo, GPT4, and Gemini-Pro, PAPILLON achieves attack success rates of over 90%, 80%, and 74%, respectively, exceeding existing baselines by more than 60%. Additionally, PAPILLON can maintain high semantic coherence while significantly reducing the length of jailbreak prompts. When targeting GPT-4, PAPILLON can achieve over 78% attack success rate even with 100 tokens. Moreover, PAPILLON demonstrates transferability and is robust to state-of-the-art defenses. We will open-source our codes upon publication.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventGreat, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak AttackBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventSelfDefend: LLMs Can Defend Themselves against Jailbreaking in a Practical MannerBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventJailbreaking is an emerging adversarial attack that bypasses the safety alignment deployed in off-the-shelf large language models (LLMs) and has evolved into multiple categories: human-based, optimization-based, generation-based, and the recent indirect and multilingual jailbreaks. However, delivering a practical jailbreak defense is challenging because it needs to not only handle all the above jailbreak attacks but also incur negligible delays to user prompts, as well as be compatible with both open-source and closed-source LLMs.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventThis paper examines the fundamental components of modern Branch Prediction Units (BPUs) and investigates how resource sharing and contention affect two widely implemented but underdocumented features: Bias-Free Branch Prediction and Branch History Speculation. Our analysis demonstrates that these BPU features, while designed to enhance speculative execution efficiency through more accurate branch histories, can also introduce significant security risks. We show that these features can inadvertently modify the Branch History Buffer (BHB) update behavior and create new primitives that trigger malicious mis-speculations.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventThis discovery exposes previously unknown cross-privilege attack surfaces for Branch History Injection (BHI). Based on these findings, we present three novel attack primitives: two Spectre attacks, namely Spectre-BSE and Spectre-BHS , and a cross-privilege control flow side-channel attack called BiasScope. Our research identifies corresponding patterns of vulnerable control flows and demonstrates exploitation on multiple processors. Finally, Chimera is presented: an attack demonstrator based on eBPF for a variant of Spectre-BHS that is capable of leaking kernel memory contents at 24,628 bit/s.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventFLOP: Breaking the Apple M3 CPU via False Load Output PredictionsBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventTo bridge the ever-increasing gap between the fast execution speed of modern processors and the long latency of memory accesses, CPU vendors continue to introduce newer and more advanced optimizations. While these optimizations improve performance, research has repeatedly demonstrated that they may also have an adverse impact on security.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventTo evaluate the security impact of Apple's LVP implementation, we first investigate the implementation, identifying the conditions for prediction. We then show that although the LVP cannot directly predict 64-bit values (e.g., pointers), prediction of smaller-size values can be leveraged to achieve arbitrary memory access. Finally, we demonstrate end-to-end attack exploit chains that build on the LVP to obtain a 64-bit read primitive within the Safari and Chrome browsers.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventThis paper proposes GraphAce, an efficient secure two-party graph analysis framework, which adopts a distinct technical roadmap from existing solutions. We identify and address the security challenges when utilizing local graph data of parties, with the mixed primitives system of homomorphic encryption and secret sharing, and a novel ChaosTable data structure that protects privacy during cross-party computation. Consequently, GraphAce eliminates any network traffic related to the edges. For each iteration, it achieves low complexities of Theta( V ) communication, breaking the Omega( V + E ) lower bound of previous secure solutions, and Theta( V + E ) computation, which is the same as insecure methods.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventBreaking the Layer Barrier: Remodeling Private Transformer Inference with Hybrid CKKS and MPCBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventFinally, through experiments, we demonstrate that our approach produces tighter privacy lower bounds on common differentially private mechanisms while requiring significantly fewer observations. We also provide a case study illustrating that our method successfully detects privacy violations in flawed implementations of private algorithms.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventEvaluation on 30 applications demonstrates that FLASH achieves higher recall (with 30.8% lower false negative rate) and precision (with 25.9% lower false positive rate) than state-of-the-art methods, at the cost of limited overhead. Furthermore, FLASH detects a total of 90 new gadget chains and 10 existing CVEs. Leveraging the new gadget chains, FLASH uncovers 5 previously unknown exploitation methods of the vulnerabilities, which demonstrate a broader impact compared to previously known CVEs.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventRecent advances in privacy-preserving machine learning underscore the critical role of differential privacy (DP) in protecting individual data. However, the noise introduced during DP training often leads to significant performance degradation, creating a major challenge for differentially private machine learning (DPML).TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventTask-Oriented Training Data Privacy Protection for Cloud-based Model TrainingTrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventCloud-based model training presents significant privacy challenges, as users must upload personal data for training high-performance models. Once uploaded, this data goes beyond the user's control and could be misused for other purposes. Users need tools to control the usage scope of the uploaded training data, preventing unauthorized training without compromising authorized training. Unfortunately, existing solutions overlook this issue.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventTo demonstrate the potential of our approach, we present Predictive Response Optimization (PRO), a system based on reinforcement learning that utilizes available contextual information to predict future abuse and user-experience metrics conditioned on each possible action, and select actions that optimize a multi-dimensional tradeoff between abuse/harm and impact on user experience.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventWe deployed versions of PRO targeted at stopping automated activity on Instagram and Facebook. In both cases our experiments showed that PRO outperforms a baseline classification system, reducing abuse volume by 59% and 4.5% (respectively) with no negative impact to users. We also present several case studies that demonstrate how PRO can quickly and automatically adapt to changes in business constraints, system behavior, and/or adversarial tactics.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventTo demonstrate the practicality of our framework, we implement a PolySys attack engine in Python and apply it to state-of-the-art query recovery, data resolution, and query inference attacks on point and range multi-maps. Our results show that PolySys outperforms all existing attacks under identical assumptions, achieving up to 60× higher recovery rates in some scenarios. While scalability remains a challenge for larger datasets, PolySys represents a promising step toward a general-purpose framework for designing leakage attacks. We believe future work can further enhance its efficiency to scale to larger and more complex workloads.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventUnbalanced case: We present the first unbalanced enhanced PSU, which achieves sublinear communication complexity in the size of the large set. Experimental results demonstrate that the larger the difference between the two set sizes, the better our protocol performs. For unbalanced set sizes (2^10, 2^20) with single thread in 1Mbps bandwidth, our protocol requires only 2.322 MB of communication. Compared with the state-of-the-art enhanced PSU, there is 38.1x shrink in communication and roughly 17.6x speedup in the running time.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
12:30 pm - 2:00 pmSymposium LuncheonMealWellbeing+
Format · LogisticsMealA pacing block. Can carry unstructured networking, not scored as participant work.
Evidence basisMediumRead from source
all eventIn this paper, we present the discovery of the BGP Vortex, a configuration where just three legitimate BGP UPDATE messages can trigger persistent instability. We demonstrate that this vulnerability can be weaponized as an attack vector, potentially causing widespread Internet connectivity issues through router overload and forwarding loops. Crucially, a BGP Vortex cannot be prevented by existing security mechanisms such as BGPSEC or RPKI, because the protocol messages involved are legitimate. All major router implementations we could experiment with are susceptible to this threat.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventPanel: Winners of the 2025 USENIX Security Test of Time AwardPanelDeliberation+
Format · BroadcastPanelExperts discuss while the audience watches. Surfaces perspective but rarely creates participant work.
Evidence basisMediumRead from source
2:45 pm - 3:30 pmTrack 3UnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventWe propose a novel hallucination attack against MLLMs that exploits attention sink behaviors to trigger hallucinated content with minimal image-text relevance, posing a significant threat to critical downstream applications. Distinguished from previous adversarial methods that rely on fixed patterns, our approach generates dynamic, effective, and highly transferable visual adversarial inputs, without sacrificing the quality of model responses. Comprehensive experiments on 6 prominent MLLMs demonstrate the efficacy of our attack in compromising black-box MLLMs even with extensive mitigating mechanisms, as well as the promising results against cutting-edge commercial APIs, such as GPT-4o and Gemini 1.5. Our code is available at <https://huggingface.co/RachelHGF/Mirage-in-the-Eyes>.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventRetrieval-augmented generation (RAG) systems respond to queries by retrieving relevant documents from a knowledge database and applying an LLM to the retrieved documents. We demonstrate that RAG systems that operate on databases with untrusted content are vulnerable to denial-of-service attacks we call jamming. An adversary can add a single "blocker" document to the database that will be retrieved in response to a specific query and result in the RAG system not answering this query, ostensibly because it lacks relevant information or because the answer is unsafe.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventWe evaluate jamming attacks on several embeddings and LLMs and demonstrate that the existing safety metrics for LLMs do not capture their vulnerability to jamming. We then discuss defenses against blocker documents.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventWe identify three types of USB bus contention and design multiple side-channel attacks to infer user activities based on these contentions. These attacks can be launched from a virtual machine, a remote website, or a USB peripheral, as demonstrated in three distinct attack scenarios. By collecting I/O interval data using our probers, we can recover information such as web browsing history, camera-captured activities, and keystrokes with accuracies ranging from 85% to 99%. We evaluated 15 leading USB 3.x external hubs on the market, a USB 2.0 hub, and an internal hub, most of which are vulnerable to HubBub attacks. We have reported our findings to the relevant stakeholders.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventTo address these limitations, in this paper, we propose NEUROSCOPE, a novel data-driven approach based on dynamic analysis and machine learning to reverse engineer DNN binaries. This compiler-independent and code-feature-free approach enables NEUROSCOPE to support a larger variety of DNN binaries across different DNN compilers and hardware platforms, including binaries implementing DNN models using an interpreter-based approach. We demonstrate NEUROSCOPE's capability by using it to reverse engineer DNN binaries unsupported by previous approaches with high accuracy. Moreover, we showcase how NEUROSCOPE can reverse engineer a proprietary DNN binary compiled with a closed-source compiler and enable gray-box adversarial machine learning attacks.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventIn this paper, we demonstrate the FF mechanism of BSC is susceptible to attacks. In particular, we provide three different attacks, showing BSC fails to finalize blocks in constant time and may even simply fail to achieve liveness. We validate our results via extensive experimental analysis and meanwhile provide mitigation solutions.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventAt its core, Thunderdome relies on a committee of non-trusted watchtowers, known as wardens, who ensure that no honest party loses funds, even when offline, during the channel closure process. We introduce tailored incentive mechanisms to ensure that all participants follow the protocol's correct execution. Besides a traditional security proof that assumes an honest majority of the committee, we conduct a formal game-theoretic analysis to demonstrate the security of Thunderdome when all participants, including wardens, act rationally. We implement a proof of concept of Thunderdome on Ethereum to validate its feasibility and evaluate its costs. Our evaluation shows that deploying Thunderdome, including opening the underlying payment channel, costs approximately $15 (0.0089 ETH), while the worst-case cost for closing a channel is about $7 (0.004 ETH).DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventApple's Find My network, leveraging over a billion active Apple devices, is the world's largest device-locating network. We investigate the potential misuse of this network to maliciously track Bluetooth devices. We present nRootTag, a novel attack method that transforms computers into trackable "AirTags" without requiring root privileges. The attack achieves a success rate of over 90% within minutes at a cost of only a few US dollars. Or, a rainbow table can be built to search keys instantly. Subsequently, it can locate a computer in minutes, posing a substantial risk to user privacy and safety. The attack is effective on Linux, Windows, and Android systems, and can be employed to track desktops, laptops, smartphones, and IoT devices. Our comprehensive evaluation demonstrates nRootTag's effectiveness and efficiency across various scenarios.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventAutomated program repair (APR) techniques, which aim to triage and fix software bugs autonomously, have emerged as powerful tools against vulnerable code. Recent advancements in large language models (LLMs) have further shown promising results when applied to APR, especially on patch generation. However, without effective fault localization and patch validation, APR tools specialized in patching alone cannot handle a more practical and end-to-end setting - given a concrete input that triggers a vulnerability, how to patch the program without breaking existing tests?BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventThis paper systematically explores efficiency robustness of DDLSs, presenting the first comprehensive taxonomy of efficiency attacks. We categorize these attacks based on three dynamic behaviors: (i) attacks on dynamic computations per inference, (ii) attacks on dynamic inference iterations, and (iii) attacks on dynamic output production for downstream tasks. Through an in-depth evaluation, we analyze adversarial strategies that target DDLSs efficiency and identify key challenges in securing these systems. In addition, we investigate existing defense mechanisms, demonstrating their limitations against increasingly popular efficiency attacks and the necessity for novel mitigation strategies to secure future adaptive DDLSs.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventTo demonstrate the feasibility of our approach, we design, implement, and benchmark an anonymous reputation system with better-than-state-of-the-art performance and features, supporting asynchronous reputation updates, banning, and reputation-dependent rate limiting to better protect against Sybil attacks.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventTo demonstrate Verdict's expressiveness, we use Verdict's policy framework to implement the X.509 validation policies in Google Chrome, Mozilla Firefox, and OpenSSL, and formally prove that they conform to a subset of RFC requirements. We instantiate Verdict with each policy and show that Verdict matches the corresponding baseline's behavior and state-of-the-art performance on over ten million certificates from Certificate Transparency logs.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
5:30 pm - 7:00 pmSymposium ReceptionReceptionRelationship Building+
Format · LogisticsReceptionA social or hospitality block. Pacing and informal connection, not participant work.
Evidence basisMediumRead from source
7:00 pm - 8:00 pmOpen Forum with the Program Co-ChairsUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventWe employ formal verification to demonstrate that AKMA+ achieves key security and privacy objectives. We conduct extensive experiments demonstrating that AKMA+ incurs acceptable computational overhead, bandwidth costs, and UE battery consumption.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventMachine Learning (ML) models are vulnerable to membership inference attacks (MIAs), where an adversary aims to determine whether a specific sample was part of the model's training data. Traditional MIAs exploit differences in the model's output posteriors, but in more challenging scenarios (label-only scenarios) where only predicted labels are available, existing works directly utilize the shortest distance of samples reaching decision boundaries as membership signals, denoted as the shortestBD. However, they face two key challenges: low distinguishability between members and non-members due to sample diversity, and high query requirements stemming from direction diversity.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventTo overcome these limitations, we propose a novel label-only attack called DHAttack, designed for Higher performance and Higher stealth, focusing on the boundary distance of individual samples to mitigate the effects of sample diversity, and measuring this distance toward a fixed point to minimize query overhead. Empirical results demonstrate that DHAttack consistently outperforms other advanced attack methods. Notably, in some cases, DHAttack achieves more than an order of magnitude improvement over all baselines in terms of TPR @ 0.1% FPR with just 5 to 30 queries. Furthermore, we explore the reasons for DHAttack's success, and then analyze other crucial factors in the attack performance. Finally, we evaluate several defense mechanisms against DHAttack and demonstrate its superiority over all baseline attacks.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventRowhammer attacks are pervasive in client systems when launched natively. The biggest Rowhammer threat for such systems, however, lies in the browser. Our large-scale evaluation of browser-based Rowhammer attacks shows that they can only trigger bit flips on a small fraction of DRAM devices. Postponing refresh commands that trigger in-DRAM mitigations can boost the performance of Rowhammer attacks, but it has never been demonstrated in practice.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventRowhammer is a hardware vulnerability present in nearly all computer memory, allowing attackers to modify bits in memory without directly accessing them. While Rowhammer has been extensively studied on client and even mobile platforms, no successful Rowhammer attack has been demonstrated on server platforms using DDR4 ECC memory.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventTackling this challenge, in this paper we demonstrate the first end-to-end Rowhammer technique effective against Intel servers using Hynix DDR4 ECC memory. To that aim, we first characterize the Hynix implementation of Target Row Refresh (TRR) on server parts, demonstrating effective hammering patterns on both FPGA and Intel-based testing platforms with ECC disabled. We then reverse engineer Intel's ECC implementation on Skylake and Cascade Lake servers. We find that it has a coding distance of four, which often allows triggering incorrect ECC correction with just two bit flips.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source

The Full Reading

Why It Ranks This Way +

Calibrated from GES design 44/100 and verified 44/100 with no fourth-loop cap.

Reader Takeaway. For a reader, this is a useful but still incomplete public example: it reads as a showcase or expo program, with the strongest visible signal in learning transfer and future-of-work fit and the biggest open question around follow through and network design. The practical test is whether the published agenda connects the room to execution quality beyond the public agenda.

Strongest signals: Learning Transfer, Future-of-Work Fit, and Problem Specificity. Weakest signals: Follow Through, Network Design, and Personalization.

How This Agenda Could Improve +
  • Add named owners, dates, implementation checkpoints, and a visible post-event continuation path.
  • Replace generic networking blocks with designed introductions, ask-offer exchanges, peer groups, or bridge-building rituals.
  • Create role-based paths, prepared questions, tailored breakouts, or participant-specific next steps.

Fastest next move: Add named owners, dated next steps, and a visible continuation path before treating the event as outcome-ready.

Role-Specific Reading +

Event owner lens

Use this record to benchmark whether a comparable event makes the work after the room visible. The score is 43/100, so the next move is to benchmark the weakest pillars before repeating the format.

Sponsor lens

Look beyond exposure. Strong sponsor value would show qualified interaction, problem work, buyer learning, customer evidence, or follow-up. The practical sponsor move is to look for structured introductions, buyer-seller fit, and relationship persistence.

Designer lens

The agenda is useful as a pattern sample from usenix.org. Redesign attention should go first to the lowest-scoring pillars; in practice, turn the thinnest agenda blocks into participant work.

Executive lens

Treat the visible agenda as an operating plan. The executive move is to require owners, dates, and evidence before treating the event as strategic. If owners, proof, and follow-through are not visible, the public record does not yet prove strategic movement.

Aggregator lens

Treat the source URL as evidence, not decoration. The data-product move is to label the source boundary clearly before ranking the record before ranking or syndicating the record.

What GES Means Here +

The Gathering Effectiveness Score is a strict 0-100 public-evidence reading of the agenda across eight pillars. It rewards visible participant work, follow-through, transfer, network design, and proof mechanisms more than polish, speaker fame, attendance, or satisfaction.

Visible mechanisms: Participant work, Feedback, Impact evidence, Network design, Learning transfer, Personalization.

Evidence boundary: Scores reflect visible agenda/source evidence and should not be read as proof of causal event impact.

Limitations, Score Caps, and Review Flags +

Limitations

  • No baseline measurement is visible.

Score caps

  • No fourth-loop score cap applied.

Review flags

  • Satisfaction/NPS signal found, but it is excluded from effectiveness scoring.
Is this proof the event worked? +

No. This is a strict public-evidence reading of the agenda. Proof would require baseline, comparison, follow-up, attribution, and impact evidence beyond the listing.

What should a reader inspect first? +

Start with the source URL, then compare the eight pillar scores against the agenda rows. The biggest opportunities usually sit in follow-through, evidence maturity, and participant work.

Why publish weak records? +

Weak records are part of the map. They show where public agendas still describe sessions and speakers more often than outcomes, commitments, transfer, or proof.

How should I use the rows? +

Read the agenda rows as the visible design trace: formats, purposes, and evidence labels show what the public source made inspectable, not everything that happened in the room. This is a source-grounded interpretation of the public agenda record, not a copy of the source, and not an endorsement of the event.

Embed the verified badge +

This record is in the hand-verified gold set. Copy the snippet below to embed the verified badge on your own site.

<a href="https://unitedwetransform.com/events/evt_2025_usenix_security_usenix_org"><img src="https://unitedwetransform.com/badge/ges-verified.svg" alt="GES verified by United We Transform" height="40"></a>

Where To Go Next

Compare this agenda against other Academic / Research / Science events scored on the same eight pillars.