Loading…
Tuesday, August 11
 

8:00am EDT

Continental Breakfast
Tuesday August 11, 2026 8:00am - 9:00am EDT
Tuesday August 11, 2026 8:00am - 9:00am EDT
Harborside Foyer

8:00am EDT

Badge Pickup
Tuesday August 11, 2026 8:00am - 6:00pm EDT
Tuesday August 11, 2026 8:00am - 6:00pm EDT
Convention Registration

9:00am EDT

You Have Been LaTeXpOsEd: A Large-Scale Systematic Analysis of Information Leakage in Preprint Archives Using Large Language Models
Tuesday August 11, 2026 9:00am - 9:20am EDT
Richard A. Dubniczky and Bertalan Borsos, Eötvös Loránd University; Tamas Bisztray, HUN-REN Sztaki; Norbert Tihanyi, Technology Innovation Institute In this work, we present the first large-scale security audit of the arXiv preprint repository, analyzing over 1.2 TB of data from 100,000 arXiv submissions to report on systemic sensitive information leakage. When authors upload submissions, they...
See More →
Tuesday August 11, 2026 9:00am - 9:20am EDT
Harborside Ballroom B

9:20am EDT

Are Neuro-Inspired Multi-Modal Vision-Language Models Resilient to Membership Inference Privacy Leakage?
Tuesday August 11, 2026 9:20am - 9:40am EDT
David Amebley and Sayanton Dibbo, The University of Alabama The growing deployment of multi-modal models (MMs) has introduced new attack vectors that can leak sensitive training data, leading to privacy leakage. This paper investigates black-box membership inference attack (MIA) privacy attack on multi-modal vision-language models (VLMs). State-of-the-art research analyzes privacy vulnerabilities...
See More →
Tuesday August 11, 2026 9:20am - 9:40am EDT
Harborside Ballroom B

9:40am EDT

LIMA: Defining, Benchmarking and Detecting Cross-Layer Vulnerabilities in LLM Inference Frameworks
Tuesday August 11, 2026 9:40am - 10:00am EDT
Sanjib Kumar Sen, Hannah Longoria, and Bozhen Liu, Texas A&M University - Corpus Christi Local Inference Frameworks (LIFs) such as llama.cpp, vLLM, Ollama, and LocalAI enable users to run large language models on their own hardware, avoiding data exposure to remote services. However, these frameworks often load community-shared model files that can carry malicious payloads. We define the...
See More →
Tuesday August 11, 2026 9:40am - 10:00am EDT
Harborside Ballroom B

10:00am EDT

OSS-CRS: Liberating AIxCC Cyber Reasoning Systems for Real-World Open-Source Security
Tuesday August 11, 2026 10:00am - 10:20am EDT
Andrew Chin, Georgia Institute of Technology; Dongkwan Kim, Microsoft; Yu-Fu Fu, Fabian Fleischer, and Youngjoon Kim, Georgia Institute of Technology; HyungSeok Han and Cen Zhang, Microsoft; Brian Junekyu Lee and Hanqing Zhao, Georgia Institute of Technology; Taesoo Kim, Georgia Institute of Technology and Microsoft DARPA's AI Cyber Challenge (AIxCC) showed that cyber reasoning systems (CRSs) can...
See More →
Tuesday August 11, 2026 10:00am - 10:20am EDT
Harborside Ballroom B

10:20am EDT

Coffee and Tea Break
Tuesday August 11, 2026 10:20am - 10:50am EDT
Tuesday August 11, 2026 10:20am - 10:50am EDT
Harborside Foyer

10:50am EDT

Defective by Design: Universal Recovery of All Widevine-Protected Content on Desktop Environments
Tuesday August 11, 2026 10:50am - 11:10am EDT
Florian Roudot and Mohamed Sabt, Univ Rennes, CNRS, IRISA Nowadays, streaming services, such as Netflix, rely on Digital Rights Management (DRM) systems to deliver their protected content. These systems aim to prevent piracy. Specifically, non-subscribers are prevented from accessing the content altogether, while subscribers are prevented from acquiring decrypted copies of the media to avoid...
See More →
Tuesday August 11, 2026 10:50am - 11:10am EDT
Harborside Ballroom B

11:10am EDT

Evading and Crashing Anti-Malware Solutions via Data Collection Overloading During Analysis Serialization
Tuesday August 11, 2026 11:10am - 11:30am EDT
Evgenios Gkritsis, Athens University of Economics and Business; Constantinos Patsakis, University of Piraeus and Information Management Systems Institute of Athena Research Centre; George Stergiopoulos, Athens University of Economics and Business Malware analysis systems, including dynamic-analysis sandboxes and digital forensics and incident response (DFIR) platforms, rely on telemetry pipelines...
See More →
Tuesday August 11, 2026 11:10am - 11:30am EDT
Harborside Ballroom B

11:30am EDT

Onelogon: Taking Over Active Directory Accounts via Netlogon
Tuesday August 11, 2026 11:30am - 11:50am EDT
Alexander Neff, Tobias Holl, and Kevin Borgolte, Ruhr University Bochum Microsoft's Active Directory (AD) is a critical component of the IT infrastructure of numerous enterprises. Thus, security vulnerabilities in AD can have dire consequences for the security posture of an organization's IT infrastructure. At the core of the AD architecture is the Netlogon Remote Protocol, which is used to...
See More →
Tuesday August 11, 2026 11:30am - 11:50am EDT
Harborside Ballroom B

11:50am EDT

SoK: The Constant Time Model
Tuesday August 11, 2026 11:50am - 12:10pm EDT
Billy Bob Brumley, Rochester Institute of Technology Constant time programming patterns is the primary defense against timing attacks on cryptographic implementations, yet what "constant time" means varies across academia and industry. This work systematizes constant time models and their evolution, identifies a recurring gap between what models protect and what specifications assume, and...
See More →
Tuesday August 11, 2026 11:50am - 12:10pm EDT
Harborside Ballroom B

12:10pm EDT

Luncheon
Tuesday August 11, 2026 12:10pm - 1:40pm EDT
Tuesday August 11, 2026 12:10pm - 1:40pm EDT
Harborside Ballroom A

1:40pm EDT

Invited Talk: A Dummy's Guide to Agentic Exploit Generation
Tuesday August 11, 2026 1:40pm - 2:10pm EDT
Connor Glosner, Purdue University Agentic AI has reduced the time between "I found a vulnerability" and "I have a working proof-of-concept", but that speed is only an asset if it comes with discipline. This talk walks through how LLM-driven agents can be wired into an exploit generation workflow: automating the tedious parts of testing, such as synthesis, payload iteration, and PoC scaffolding...
See More →
Tuesday August 11, 2026 1:40pm - 2:10pm EDT
Harborside Ballroom B

2:10pm EDT

Coffee and Tea Break
Tuesday August 11, 2026 2:10pm - 2:40pm EDT
Tuesday August 11, 2026 2:10pm - 2:40pm EDT
Harborside Foyer

2:40pm EDT

Protocol Prying: Systematic Vulnerability Research in the AirDrop and Android Quick Share Proximity Transfer Protocols
Tuesday August 11, 2026 2:40pm - 3:00pm EDT
Arash Ale Ebrahim and Nils Ole Tippenhauer, CISPA Helmholtz Center for Information Security Apple AirDrop and Google/Samsung Quick Share are proximity file-transfer protocols used by over five billion devices, yet their application-layer security properties remain largely unstudied because both stacks are proprietary and undocumented. Both protocols are reachable from wireless proximity without...
See More →
Tuesday August 11, 2026 2:40pm - 3:00pm EDT
Harborside Ballroom B

3:00pm EDT

Exploiting Android Apps with Counterfeit Art
Tuesday August 11, 2026 3:00pm - 3:20pm EDT
Rokhaya-Diamil Fall and Philipp Mao, EPFL; Martin Wagner, Asymmetric Research; Mathias Payer, EPFL Arbitrary file overwrite vulnerabilities are common in Android apps. However, the security impact of such vulnerabilities has so far been highly app-dependent. We present a new, app-agnostic, persistent technique that turns arbitrary file overwrites into code execution by targeting the...
See More →
Tuesday August 11, 2026 3:00pm - 3:20pm EDT
Harborside Ballroom B

3:20pm EDT

Practical Attacks on a Decentralized Secure Messenger Session
Tuesday August 11, 2026 3:20pm - 3:40pm EDT
Kota Urushigaki, The University of Osaka; Hayato Kimura, NICT and The University of Osaka; Atsushi Tanaka and Takanori Isobe, The University of Osaka Session is a widely deployed decentralized messenger application that emphasizes user anonymity and privacy through end-to-end encryption. Session currently employs its own uniquely designed messaging protocol, Session Protocol V1, having migrated...
See More →
Tuesday August 11, 2026 3:20pm - 3:40pm EDT
Harborside Ballroom B

3:40pm EDT

CATana: On the Dangers of SIM-Originating AT Commands
Tuesday August 11, 2026 3:40pm - 4:00pm EDT
Tomasz Lisowski, University of Birmingham; Kristian Covic, Fuzzware; Marius Muench, University of Birmingham Hostile SIMs have been discussed as an attack vector against Mobile Equipment (ME) connected to cellular networks. One main attack path are proactive commands sent from the SIM to the victim device. In this work, we examine the threats posed by the RUN AT command which are SIM-originating...
See More →
Tuesday August 11, 2026 3:40pm - 4:00pm EDT
Harborside Ballroom B

4:00pm EDT

SoK: Insecurity of Cellular Basebands
Tuesday August 11, 2026 4:00pm - 4:20pm EDT
Henri Carnot, Avantix and EURECOM; Aurélien Francillon, EURECOM Cellular basebands are critical components in mobile devices, enabling connectivity with cellular networks. Their notorious complexity, proprietary design, insufficient security hardening, and support for multiple generations of complex cellular protocols make them a prime target for attacks. Although billions of devices rely on...
See More →
Tuesday August 11, 2026 4:00pm - 4:20pm EDT
Harborside Ballroom B

4:20pm EDT

Closing Remarks
Tuesday August 11, 2026 4:20pm - 4:30pm EDT
Program Co-Chairs: Antonio Bianchi, Purdue University, and Jiska Classen, Hasso Plattner Institute
Tuesday August 11, 2026 4:20pm - 4:30pm EDT
Harborside Ballroom B

4:30pm EDT

Demo/Poster Session and Happy Hour
Tuesday August 11, 2026 4:30pm - 6:00pm EDT
A cornerstone of the USENIX WOOT Conference is to bring together academics and practitioners—hackers of all sorts—to discuss and share offensive security research. To help those conversations get started, WOOT '26 is hosting a Demo/Poster Session and Happy Hour featuring both new work as well as demos and posters from authors of accepted WOOT '26 papers. The list of accepted demos and...
See More →
Tuesday August 11, 2026 4:30pm - 6:00pm EDT
Harborside Ballroom C
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.