| 2026 | Catch Me If You Can: Detector-Resistant Evasion via Semantics-Preserving Command Re-Realization. | Muhammad Shoaib, Hare Sudhan Muthusamy, Tareq Alkhatib, Wajih Ul Hassan |
| 2026 | Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App Ecosystem. | Yizhe Shi, Zhemin Yang, Yifan Yang, Yunteng Yang, Min Yang |
| 2026 | PILOT: Command-Line Interface Fuzzing Via Path-Guided, Iterative Large Language Model Prompting. | Momoko Shiraishi, Yinzhi Cao, Takahiro Shinagawa |
| 2026 | Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-Demand Input Delivery. | Shandian Shen, Wei Zhou, Keming Zhao, Peng Liu, Chung Hwan Kim, Le Guan |
| 2026 | A Full Threshold NIST PQC-Compliant Framework for Distributed Trust in Federal Public Key Infrastructure. | Kiarash Sedghighadikolaei, Changqi Sun, Thang Hoang, Bechir Hamdaoui, Attila A. Yavuz |
| 2026 | Batch Me If You Can: Coverage-Guided RPKI Fuzzing at Scale. | Haya Schulmann, Niklas Vogel |
| 2026 | Position Paper: Replication Crisis in Human-Centered Security Research-Are We There Yet? | Juliane Schmser, Jan-Ulrich Holtgrave, Florian Schaub, Sascha Fahl |
| 2026 | CBUE: Conclusion Based Utility Evaluation for Differentially Private Categorical Data. | Furkan Sarikaya, Shaohua Lu, Johes Bater, Mark Hempstead |
| 2026 | Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control Systems. | Burak Sahin, David Oygenblik, Mingxuan Yao, Yizhi Huang, Brendan Saltaformaggio, Saman A. Zonouz |
| 2026 | GHost in the Shell: A GPU-to-Host Memory Attack and its Mitigation. | Sihyun Roh, Woohyuk Choi, Jaeyoung Chung, Yoochan Lee, Suhwan Song, Byoungyoung Lee |
| 2026 | What's in the Mandatory USENIX Security 2025 Ethics Sections? Results from a Meta-Analysis. | Rachel Gonzalez Rodriguez, Harshini Sri Ramulu, Yasemin Acar |
| 2026 | Searching for a Farang: Collective Security Among Women in Pattaya, Thailand. | Taylor Robinson, Rikke Bjerg Jensen |
| 2026 | SoK: After Decades of Web Tracker Detection, What's Next? | Wolf Rieder, Philip Raschke, Thomas Cory, Christian Ren Sechting, Aditya Kumar, Axel Kpper |
| 2026 | No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and Usage. | Tobias Reittinger, Gnther Pernul |
| 2026 | Fractal: An Operating System Designed for Microarchitecture Reverse Engineering. | Joseph Ravichandran, Mengjia Yan |
| 2026 | XDup: Privacy-Preserving Deduplication for Humanitarian Organizations Using Fuzzy PSI. | Tim Rausch, Sylvain Chatel, Wouter Lueks |
| 2026 | Verifiable PIR with Small Client Storage. | Mayank Rathee, Keewoo Lee, Raluca Ada Popa |
| 2026 | CHORUS: Secret Recovery with Ephemeral Client Committees. | Deevashwer Rathee, Emma Dauterman, Allison Li, Raluca Ada Popa |
| 2026 | Lost in Translation: Text Message Spoofing via Email. | Sumanth Rao, Ye Shu, Stefan Savage, Aaron Schulman, Geoffrey M. Voelker, Enze Liu |
| 2026 | Towards Enhanced Detection of Genetically Engineered Plasmids. | Felix Quintana, Ryan D. Doughty, Michael G. Nute, Lydia E. Kavraki, Todd J. Treangen |
| 2026 | VerfCNN, Optimal Complexity zkSNARK for Convolutional Neural Networks. | Wenjie Qu, Yanpei Guo, Yue Ying, Jiaheng Zhang |
| 2026 | Mechanized Safety and Liveness Proofs for the Mysticeti Consensus Protocol Under the LiDO-DAG Framework. | Longfei Qiu, Jingqi Xiao, Zhong Shao |
| 2026 | Knocking on the Front Door: An LLM-Guided Systematic Analysis of DNS Query Processing Vulnerabilities. | Yuqi Qiu, Xiang Li, Zheli Liu |
| 2026 | Keytar: Practical Keystroke Timing Attacks and Input Reconstruction. | Mufan Qiu, Lihsuan Chuang, Dohhyun Kim, Huaizhi Qu, Tianlong Chen, Andrew Kwong |
| 2026 | Defining Cyberbiosecurity by Biological Consequence. | Tia Pope |