Loading…
Venue: Harborside Ballroom B clear filter
arrow_back View All Dates
Monday, August 10
 

9:00am EDT

Opening Remarks and Awards
Monday August 10, 2026 9:00am - 9:15am EDT
Program Co-Chairs: Antonio Bianchi, Purdue University, and Jiska Classen, Hasso Plattner Institute
Monday August 10, 2026 9:00am - 9:15am EDT
Harborside Ballroom B

9:15am EDT

Keynote: Click Here to Hack Your Target: A Perspective on the Past, Present, and Future of Mercenary Spyware
Monday August 10, 2026 9:15am - 10:00am EDT
Bill Marczak, Senior Researcher at The Citizen Lab


The mercenary spyware industry sells hacking tools and services to governments, purportedly to fight crime and terrorism. In some cases, the products are used this way. However, all too often, this powerful technology is abused to spy on dissidents, journalists, and political opposition. Despite bug-fixes, security mitigations, threat intelligence work, government regulations, and even sanctions, the industry's efforts continue apace, to the detriment of civil society. My talk will highlight the cat-and-mouse game between the mercenary spyware industry and the defenders, explaining the state of play, how we got here, and what the future may hold.


https://www.usenix.org/conference/woot26/keynote
Monday August 10, 2026 9:15am - 10:00am EDT
Harborside Ballroom B

10:30am EDT

HotWire: Real-World Impersonation and Discharge Attacks on Electric Vehicle Charging Systems
Monday August 10, 2026 10:30am - 10:50am EDT
Kuan Yu Chen, National Taiwan University of Science and Technology; Md Hasan Shahriar, Virginia Tech; Wen Wei Li and Shi Cho Cha, National Taiwan University of Science and Technology; Wenjing Lou, Virginia Tech


Electric vehicle (EV) charging infrastructures continue to depend heavily on the legacy DIN 70121 protocol, which lacks cryptographic authentication and exposes critical control messages in plaintext. Although prior studies have noted conceptual weaknesses, the feasibility and impact of practical, end-to-end attacks against real charging ecosystems remain insufficiently understood. We present HotWire, a systematic security analysis of DIN 70121 and the first demonstration of two practical, production-grade exploits: (i) unauthorized Autocharge activation via identifier impersonation, and (ii) unauthorized energy extraction through protocol-driven battery-state manipulation. In the first attack, an adversary replays a captured EV identifier (EVCCID) to initiate fraudulent Autocharge sessions on commercial networks using a low-cost hardware toolkit. Our experiments show that attackers can repeatedly obtain full charging sessions commonly valued at 35–45 without triggering existing fraud-detection mechanisms. In the second attack, we exploit insecure battery management system (BMS) state transitions by injecting protocol-compliant voltage claims, inducing controlled forced discharge, and enabling persistent energy loss. Furthermore, we validate these attacks across production vehicles and multiple public charging networks using a physical hardware-in-the-loop testbed, revealing widespread trust in protocol state over physical verification. We release open-source auditing tools and describe responsible disclosure outcomes, which have already prompted firmware updates and additional authentication safeguards by several vendors.


https://www.usenix.org/conference/woot26/presentation/chen
Monday August 10, 2026 10:30am - 10:50am EDT
Harborside Ballroom B

10:50am EDT

Real-Time Compromise: Investigating RTC Security in Consumer IoT
Monday August 10, 2026 10:50am - 11:10am EDT
Victor Goeman, Tom Cordemans, Christoph Sanders, Jorn Lapon, and Vincent Naessens, DistriNet, KU Leuven


Real-time communication (RTC) is increasingly adopted in the Internet of Things (IoT), enabling interactive capabilities in smart cameras, home assistants, and industrial devices. However, the security of RTC in IoT remains poorly understood. Unlike standardized WebRTC deployments on the web, IoT implementations are heterogeneous, employing either proprietary protocols or custom WebRTC stacks.

To address this heterogeneity, we present RTCInspect, an open-source framework for automated analysis of RTC traffic to detect protocol and cryptographic weaknesses. Using this framework, we conducted, to our knowledge, the first comparative security study of 21 real-world applications, spanning 11 consumer IoT devices and 10 major web platforms.

Our findings reveal a divide between the security practices of WebRTC in web applications and IoT devices. Web applications mainly rely on WebRTC and adhere to security best practices, although many still depend on centralized trust models. In contrast, IoT devices exhibit weaknesses, including unencrypted signaling, exposing long-term credentials, and mismanagement of certificates and keys, enabling Manin-the-Middle (MITM) attacks.

By exposing these weaknesses and releasing an automated analysis tool, our study offers both a security overview for RTC systems and practical support for developers and researchers.


https://www.usenix.org/conference/woot26/presentation/goeman
Monday August 10, 2026 10:50am - 11:10am EDT
Harborside Ballroom B

11:10am EDT

DisARMed: Attacking ARM TrustZone from Userspace with Memory Aliasing
Monday August 10, 2026 11:10am - 11:30am EDT
Jacqueline Henes, Matthew Bowden, and Mihai Ordean, University of Birmingham; David Oswald, Durham University


Modern systems security relies on memory isolation mechanisms like trusted execution environments and kernel privilege separation to enforce strong isolation boundaries. However, many of these mechanisms place implicit trust in system memory, leaving them open to hardware attacks on external DRAM. In this paper, we introduce DisARMed, an attack on ARM processors that exploits memory aliasing techniques from userspace, compromising both the Linux kernel and ARM TrustZone. We demonstrate for the first time that memory aliasing attacks are practical for adversaries that do not have access to the kernel. We additionally implement and evaluate a mitigation for DisARMed, using a lightweight alias detection mechanism. Our solution has minimal impact on boot time of about one second. Finally, we discuss the wider applicability of DisARMed, considering other relevant potential attack vectors, applicable memory massaging techniques, and security mechanisms that may be affected.


https://www.usenix.org/conference/woot26/presentation/henes
Monday August 10, 2026 11:10am - 11:30am EDT
Harborside Ballroom B

11:30am EDT

Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla
Monday August 10, 2026 11:30am - 11:50am EDT
Evangelos Bitsikas, Jason Veara, and Aanjhan Ranganathan, Northeastern University


Modern connected vehicles rely on persistent LTE connectivity to enable remote diagnostics, over-the-air (OTA) updates, and safety-relevant services. While mobile network vulnerabilities are well documented in the smartphone ecosystem, their impact in safety-relevant automotive settings remains insufficiently examined. We conduct a black-box case study of LTE security in Tesla's Model 3 and Cybertruck, revealing systemic protocol weaknesses and architectural misconfigurations in connected vehicles. We find that Tesla's telematics stack is susceptible to IMSI catching, rogue base station hijacking, and insecure fallback mechanisms that may silently degrade service availability. Furthermore, legacy control-plane configurations allow for silent SMS injection and broadcast message spoofing without driver awareness. While the vulnerabilities are grounded in Tesla, this case study suggests broader implications for connected-vehicle telematics and for regulatory frameworks such as ISO/SAE 21434 and UN R155/R156, which assume secure, traceable, and resilient telematics in modern vehicles.


https://www.usenix.org/conference/woot26/presentation/bitsikas
Monday August 10, 2026 11:30am - 11:50am EDT
Harborside Ballroom B

11:50am EDT

SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode
Monday August 10, 2026 11:50am - 12:10pm EDT
Antonis Louka and Jo Van Bulck, DistriNet, KU Leuven


System Management Mode (SMM) is a highly privileged execution mode present in x86 processors since the early 1990s. With full control over hardware and system memory, SMM has long been a prime target for powerful attacks and persistent rootkits, including cases linked to nation-state adversaries. However, despite widespread deployment and unlike other x86 isolation mechanisms such as Intel SGX and AMD SEV, SMM has received relatively little academic attention, with insights primarily scattered across industry disclosures and hacker community contributions.

We present the first comprehensive systematization of SMM attack research, covering over two decades of work. We consolidate architectural details, trace the evolution of hardware and the firmware ecosystem, and introduce an extensible taxonomy of attack vectors. Organizing the landscape into three eras, we highlight a shift from configuration-based exploits to sophisticated software vulnerabilities and the growing importance of automated analysis tools. Finally, we identify knowledge gaps, outline research priorities, and distill lessons transferable to privileged firmware beyond x86.


https://www.usenix.org/conference/woot26/presentation/louka
Monday August 10, 2026 11:50am - 12:10pm EDT
Harborside Ballroom B

1:40pm EDT

SEMSAN: a Configurable Sanitizer for Detecting System-Level Semantic Bugs
Monday August 10, 2026 1:40pm - 2:00pm EDT
Moritz Sanft and Flavio Toffalini, Ruhr-Universität Bochum


During software testing, analysts use sanitizers like ASan and UBSan to effectively detect memory corruption and undefined behavior. However, existing sanitizers cannot detect semantic bugs. These vulnerabilities arise from incorrect program environment interactions that lead to formally valid but unintended system states. Semantic bugs, which include path traversals, command injections, and arbitrary file writes, require tedious manual analysis to identify.

We present SEMSAN, a generic framework to identify semantic bugs during testing. SEMSAN enables analysts to define Sanitizer Primitives, which are small programs that monitor kernel events and validate security invariants at runtime. SEMSAN provides high-level utilities for inspecting filesystem metadata, process credentials, and namespace configurations, enabling the expression of complex invariants without low-level kernel knowledge. Our eBPF-based implementation integrates seamlessly with coverage-guided fuzzers while introducing negligible runtime overhead on production workloads.

We evaluate SEMSAN through both micro- and macro-benchmarks, successful reproduction of ten known CVEs, and real-world deployment. Macro-benchmarks on Apache and PostgreSQL demonstrate less than 1% overhead, while micro-benchmarks show 3--20% overhead in worst-case scenarios with continuous sanitizer triggering. SEMSAN discovered five previously unknown vulnerabilities, including privilege escalations in Git and Docker, a 21-year-old path traversal in ViewVC, and a remote code execution in Grafana. All vulnerabilities were responsibly disclosed and are either patched or in the process of being patched.


https://www.usenix.org/conference/woot26/presentation/sanft
Monday August 10, 2026 1:40pm - 2:00pm EDT
Harborside Ballroom B

2:00pm EDT

FuzzBT: Holistic-State-Guided Fuzzing for Bluetooth Host Stack in Kernels
Monday August 10, 2026 2:00pm - 2:20pm EDT
Sungwoo Kim, Purdue University; Hui Peng, Google, Inc.; Imtiaz Karim, The University of Texas at Dallas; Ruoyu Wu, Purdue University; Jianliang Wu, Simon Fraser University; Elisa Bertino, Purdue University; Mathias Payer, EPFL; Dave (Jing) Tian, Purdue University


Bluetooth is both pervasive and vulnerable, yet fuzzing Bluetooth is challenging. While research on Bluetooth fuzzing has advanced to emulate Bluetooth devices and generate effective inputs for controllers, the host stack has been overlooked. The host stack is responsible for issuing commands to controllers, providing API abstractions for user applications, establishing logical links for asynchronous connections, and multiplexing channels. Thus, a systematic approach to identifying vulnerabilities in a Bluetooth host stack is required, but still lacking.

The primary challenges in testing the Bluetooth host stack are (1) configuration diversity and (2) statefulness. The host stack can be configured with over 3,000 options, each of which may introduce configuration-specific bugs. Also, the host stack state is inherently complex because multiple protocols comprise it. To address the aforementioned challenges, we design FuzzBT, a state-guided fuzzer that adopts (1) configuration iteration and (2) stack-level state exploration. Specifically, we iterate over configurations across fuzzing campaigns and explore each configuration's unique logic using configuration-aware seeds extracted from the source code via concolic execution. For stack-level state, we aggregate the states of individual protocols via compiler instrumentation. We applied FuzzBT to two Bluetooth host stack implementations, the Linux and Zephyr kernels, and identified 18 previously unknown bugs with 9 CVEs.


https://www.usenix.org/conference/woot26/presentation/kim
Monday August 10, 2026 2:00pm - 2:20pm EDT
Harborside Ballroom B

2:20pm EDT

Squeezing Juicy Variant Bugs Out of Modern Browsers
Monday August 10, 2026 2:20pm - 2:40pm EDT
Han Zheng, EPFL; Flavio Toffalini, Ruhr-Universität Bochum; Qiang Liu and Mathias Payer, EPFL


Complex software systems, like web browsers, integrate multiple tightly-coupled components. While code reviews and fuzzing enhance code quality, eliminating all bugs remains infeasible due to large-scale projects, unpredictable cross-context interactions, and complex cross-domain dependencies. This dire situation calls for an approach that scales to this unprecedented complexity.

Inspired by informal variant analysis developed by the hacker community, we create GRAPE, a structured approach that supports analysts in writing rules to detect bugs. By focusing on code patterns, GRAPE scales effectively to large-scale code projects. Moreover, our novel variant bug model enables analysis of cross-context interactions and exploitability verification using existing bug reports, eliminating the need for cross-domain dependencies. GRAPE represents the first systematic approach to variant analysis, introducing principles for variant pattern development.

We implement a prototype of GRAPE, which scans the entire Chromium code base in only 12 minutes. GRAPE discovered 24 new bugs, with four assigned CVEs and 17, 500 USD in rewards from Chrome’s Vulnerability Rewards Program. These discoveries impact modern web browser and security-critical complex software like OpenSSL. Beyond browsers, GRAPE uncovered three logic bugs in VSCode and Azure Data Studio, one of which received a CVE from Microsoft.


https://www.usenix.org/conference/woot26/presentation/zheng
Monday August 10, 2026 2:20pm - 2:40pm EDT
Harborside Ballroom B

2:40pm EDT

SoK: Multi-Layer Indirect Call Analysis in the Real World
Monday August 10, 2026 2:40pm - 3:00pm EDT
Yufei Du, Georgia Institute of Technology; Vasileios P. Kemerlis, Brown University; Michalis Polychronakis, Stony Brook University; Fabian Monrose, Georgia Institute of Technology


Call graph analysis is foundational to a wide range of security-critical applications. A central requirement for these applications is the precise and sound identification of indirect call targets. Of late, type-based indirect call analysis (which matches address-taken functions and code pointers based on their types) has become a widely adopted solution for meeting that requirement. While scalable and nominally sound, traditional type-based analyses suffer from limited precision. In response, multi-layer type analysis was proposed as a remedy, augmenting type information with additional layers of reasoning to improve precision while retaining scalability and soundness. However, the complexity of these techniques has fueled an ongoing debate regarding both their practical precision gains and soundness guarantees in real-world settings.

In this work, we present the first systematic study of multi-layer type-based indirect call analysis, by evaluating the precision and soundness of five state-of-the-art multi-layer analysis techniques. Our study reveals a gap between the design of such techniques and their actual implementations, causing incomplete results with many indirect-call target sets missing or empty. In addition, our soundness experiments demonstrate that compiler optimizations cause every multi-layer approach to fall short of soundness. Furthermore, we conduct a case study to demonstrate that for control-flow integrity---one of the most popular downstream security applications of call graph analysis---existing multi-layer type-based techniques fall short in preventing attacks that exploit type collisions.


https://www.usenix.org/conference/woot26/presentation/du
Monday August 10, 2026 2:40pm - 3:00pm EDT
Harborside Ballroom B

3:30pm EDT

Swarm in EM Hay: Particle Swarm-Guided Probe Placement for EM SCA
Monday August 10, 2026 3:30pm - 3:50pm EDT
Dev Mehta, Seyedmohammad Nouraniboosjin, Maryam S. Safa, Shahin Tajik, and Fatemeh Ganji, Worcester Polytechnic Institute


Despite decades of research in electromagnetic (EM) side-channel analysis (SCA), practical attacks still require manual effort and domain expertise to identify informative probe locations on target devices. Existing approaches rely heavily on exhaustive grid scanning or handcrafted alignment, limiting attack scalability and realism. In this work, we present the first automated and adaptive EM SCA framework that uses particle swarm optimization (PSO) to navigate the probe. Particles are guided by mutual information (MI) leakage maps, enabling efficient recovery of secret-dependent emissions. We introduce a novel application of the Nyström approximation to accelerate MI estimation across EM trace windows, allowing real-time swarm guidance without full kernel computations. Unlike prior work, our method requires no leakage templates, manual tuning, or alignment assistance—enabling automated attacks with minimal assumptions. We validate our framework on both microcontroller and FPGA platforms running AES-128. PSO-guided scanning identifies high-leakage points faster than grid search and reduces the number of traces required for successful CPA-based key recovery by up to a factor of 16, i.e., saving tens of thousands of traces.


https://www.usenix.org/conference/woot26/presentation/mehta
Monday August 10, 2026 3:30pm - 3:50pm EDT
Harborside Ballroom B

3:50pm EDT

Breaking Infrared Recapture Detection: Optical-Synthesis Attacks and Depth-Aware In-Sensor Countermeasures
Monday August 10, 2026 3:50pm - 4:10pm EDT
Tetsu Ishizue, The University of Electro-Communications; Sara Rampazzi, University of Florida; Takeshi Sugawara, University of Electro-Communications


This paper presents a novel optical-synthesis attack and defense methodology for recaptured image detection systems that rely on infrared (IR) depth sensors. We first introduce SynthIR, which evades detection by independently manipulating the views of the RGB camera and the IR depth sensor across different optical spectra through an inexpensive optical filter that splits and recombines different colors of light. We validate the attack on portrait scenarios by constructing paired RGB images and physical 3D objects that bypass state-of-the-art detection methods, either using low-cost cardboard objects or by generating images geometrically consistent with a target 3D object without requiring precise alignment. The attack further generalizes to multi-frame video scenarios and, when applied to printed images rather than monitors, successfully circumvents both depth-based and image-only recapture detectors. To address the fundamental limitations of these IR-based two-sensor approaches, we propose a new defense pipeline based on dual-pixel image sensors, already deployed in modern smartphone cameras, which capture RGB and stereo images within the same optical spectrum. Our method estimates a depth map from the stereo pair and verifies its consistency with the RGB image, enabling robust recapture detection. Our experimental results demonstrate that the proposed defense detects all recaptured images without falsely rejecting any genuine images.


https://www.usenix.org/conference/woot26/presentation/ishizue
Monday August 10, 2026 3:50pm - 4:10pm EDT
Harborside Ballroom B

4:10pm EDT

PowerHooK: Enabling Software-Based Power Side Channels against AMD SEV Technologies via Transient-Execution Replay
Monday August 10, 2026 4:10pm - 4:30pm EDT
Mathias Oberhuber, Martin Unterguggenberger, and Martin Wistauder, Graz University of Technology; Andreas Kogler, Graz University of Technology Alumni; Rishub Nagpal and Stefan Mangard, Graz University of Technology


Confidential computing technologies, such as AMD SEV, enable secure execution of cloud workloads on shared physical hardware. AMD SEV technologies implement the VM trust model through AMD SEV-ES, encrypting memory and CPU register state, and AMD SEV-SNP, providing integrity protection for VM memory. While AMD SEV provides heavy-weight architectural isolation, it remains unclear whether it is susceptible to power side channels.

In this paper, we present PowerHooK, a new attack on AMD SEV technologies that enables software-based power side channels by speculatively replaying victim code paths via transient execution. Specifically, we repurpose page-fault-based transient replay to establish a transient-execution replay hook for power measurements. PowerHooK allows a malicious hypervisor to re-execute vulnerable victim code paths, thereby enabling continuous collection of power traces, reducing significant system noise. This capability allows the attacker to perform power analysis attacks on denoised datasets.

We demonstrate PowerHooK’s methodology by recovering AES key bytes across all AMD SEV defenses. Here, the attacker only needs to consider 1320 samples to perform a CPA on AES-NI executed in AMD SEV-SNP running in an experimental setting. We systematically analyze architectural, speculative, and transient power leakage across different AMD CPU generations and evaluate how AMD’s virtualization levels affect PowerHooK. Moreover, we present a real-world AES key byte recovery attack targeting VM-isolated cloud workers that run OpenSSL's constant-cycle AES-NI CBC implementation. Thereby, we demonstrate that transient replay gadgets are present in the OpenSSL library, showcasing that PowerHooK effectively enables the extraction of secrets.


https://www.usenix.org/conference/woot26/presentation/oberhuber
Monday August 10, 2026 4:10pm - 4:30pm EDT
Harborside Ballroom B

4:30pm EDT

Flash [Re]Loaded: Body Bias Injection on Flash Memory
Monday August 10, 2026 4:30pm - 4:50pm EDT
Valentin Huber and Marc Schink, Fraunhofer AISEC, Technical University of Munich (TUM)


Body bias injection (BBI) has received attention as a technique to induce transient faults in digital logic, yet its impact on non-volatile memory (NVM) remains largely unexplored. In this work, we present the first in-depth security analysis of BBI targeting embedded flash memory, the predominant NVM technology used in microcontrollers. We introduce a novel method to program flash cells in powered-off state using BBI, in contrast to existing techniques, such as laser or UV radiation, which are limited to erasing cells. Furthermore, we propose a new BBI technique that uses DC biases to manipulate flash memory read operations. We provide a detailed electrical model that explains the physical mechanisms underlying the induced faults and demonstrate the feasibility of the attacks by reactivating the debug interfaces of two microcontrollers. Based on these findings, we conclude by discussing potential countermeasures.


https://www.usenix.org/conference/woot26/presentation/huber
Monday August 10, 2026 4:30pm - 4:50pm EDT
Harborside Ballroom B
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -