Keynotes

The Web’s Messy Closet: Tracking “Benign-but-Buggy” Threats Across Contexts, Runtimes, and Borders

Shubham Agarwal, Max Planck Institute for Security and Privacy

Abstract: While the Web security researchers and practitioners have made massive strides in hardening frameworks and blocking malicious intent, a critical gap remains between how we design secure systems and how they behave at runtime. What happens when the threats and vulnerabilities we encounter stem not from malice, but from the trusted, well-meaning and benign applications we often trust and rely on?


In this talk, we present an ecosystemic inquiry into the overlooked landscape of benign-but-buggy browser extensions that inadvertently compromise the foundational pillars of cybersecurity – confidentiality, integrity, and availability. These client-side risks, however, do not materialize in isolation; their true impact is realized when they interact with live Web applications across different execution contexts and geographic locations. In other words, the very tools meant to enhance user experiences often act as accidental adversaries to application security and user privacy. In this talk, we discuss how a multi-dimensional perspective allows us to chart this complex terrain, and the architectural and human-centric challenges that arise when building defenses that are resilient by design.

Dr. Shubham Agarwal is a Scientific Researcher at the Max Planck Institute for Security and Privacy, Germany. His research focuses on web security, data privacy, and the human and organizational factors that shape security and privacy decisions in practice. He received his Ph.D. from the CISPA Helmholtz Center for Information Security and is recognized for his work on large-scale web application security and privacy engineering.

Keynote

The Systems Security Approach to AI Agents

Earlence Fernandes, University of California, San Diego

Abstract: TBA


Dr. Earlence Fernandes is an Assistant Professor of Computer Science and Engineering at UC San Diego and a leading researcher in AI and systems security. His research focuses on securing emerging technologies, including AI systems, IoT, cyber-physical systems, and mixed reality platforms. He is the recipient of the NSF CAREER Award, Google Research Scholar Award, and multiple best paper awards, and his work has influenced both industry practice and public policy in cybersecurity.

Keynote

Flipping Bits in GPUs for Fun and Profit

Gururaj Saileshwar, University of Toronto

Abstract: GPUs form the foundation of modern AI infrastructure. But what happens when the hardware itself cannot be trusted? In this talk, I will show how a single bit flip in GPU memory, induced via Rowhammer, can silently corrupt an AI model or even let an attacker seize control of an entire system.

This threat is real. While Rowhammer has long been known on CPU memory, with GPUHammer (USENIX Security ’25) we show for the first time that it also affects modern GPUs with GDDR6 memory, where a single bit flip degrades popular DNNs to near-zero accuracy. Moreover, with GPUBreach (S&P ’26), we show that a targeted bit flip in GPU page tables not only lets an attacker steal or tamper with ML models, but also escalate to root privileges on the host. I will discuss the industry response to these attacks and the broader lesson: AI systems are only as secure as the hardware beneath them, demanding a cross-layer approach to securing these systems. I will conclude with approaches to eliminating these vulnerabilities at minimal overhead.


Dr. Gururaj Saileshwar is an Assistant Professor of Computer Science at the University of Toronto and a leading researcher in hardware and systems security. His research addresses emerging threats in computer architecture, including microarchitectural attacks, Rowhammer vulnerabilities, and the security of AI and GPU computing systems. He is the recipient of several prestigious research awards, including the IEEE S&P Distinguished Paper Award, HPCA Best Paper Award, and IEEE HOST Best Ph.D. Dissertation Award.

Keynote

TBA

Somesh Jha, University of Wisconsin

Abstract: TBA


Dr. Somesh Jha is the Lubar Professor of Computer Sciences at the University of Wisconsin–Madison. His research lies at the intersection of cybersecurity, formal methods, and artificial intelligence, with current interests in adversarial machine learning, trustworthy AI, and privacy. He is internationally recognized for his foundational contributions to software and systems security and for advancing the security and reliability of next-generation intelligent systems.

Keynote

Page last updated on: Aug 16, 2026

Views: 82