We are pleased to announce the 2026 CyLab Partners Conference!
All main events and presentations will be held on the Carnegie Mellon University Campus in the Rangos Ballroom at the Jared L. Cohon University Center.
The CyLab Annual Partners Conference highlights the latest research in security and privacy with an interactive forum between faculty, students, and industry. We are excited to welcome our guests back to campus for this year’s two-day event, which will include more than 30 faculty and student presentations. All sessions will consist of brief talks, followed by active dialogue with our attendees.
Attendance is limited to invited guests, representatives of CyLab's partners, and CMU CyLab faculty, staff, and students.
If you have any questions regarding the 2026 CyLab Partners Conference, please contact Isabelle Glassmith at iglassmi@andrew.cmu.edu.
For information on hotels and transportation please see our "Visiting CyLab" page.
Not a CyLab partner? Learn how your company can benefit from becoming one. Contact the Senior Director of Partnerships, Michael Lisanti, at mlisanti@cmu.edu or 412-268-1870.
Agenda
Agenda subject to change
Day 1: Tuesday, October 20, 2026 (EDT)
8:00 a.m. - 9:00 a.m. - Breakfast and Registration
9:00 a.m. - 9:15 a.m. – Welcome and Opening Remarks
9:15 a.m. - 10:05 a.m. – Session I: The AI Cyber Challenge
Moderator: Lujo Bauer
- Vyas Sekar: Tech Talk: How AI is Reshaping Cybersecurity
- Vyas Sekar and Lea Kissner, Chief Information Security Officer and Vice President at LinkedIn: Panel Session
- Lujo Bauer and Vyas Sekar: Cyber Autonomy Initiative overview
AI-driven cyber offensive capabilities are advancing rapidly, as demonstrated by high-profile industry events including OpenAI’s agent containment breach on Hugging Face, Anthropic’s disclosures on sandbox escapes and zero-day discovery via Claude Mythos (Project Glasswing), and emerging threat research from Meta on open-weights misuse. At the same time, system size and complexity continue to increase as autonomous agentic workflows are deployed into enterprise environments.
In this environment, classical approaches to defending our critical infrastructures and cloud-scale systems that rely on human timescales for exploration, detection, and mitigation will become increasingly inadequate. To defend our digital and cyber physical infrastructures, cybersecurity defenses will have to be autonomous or semi-autonomous systems operating at machine timescales - we call this Cyber Autonomy.
In this session, we will briefly recap the trends and advances at the intersection of AI and security. With this context, we will have a panel discussion and open dialogue on the open foundational technical, practical, and deployment challenges that we need to address in terms of AI systems, compute systems, human AI systems, and “evals” for such capabilities at scale. Finally, we will discuss the foundational research, educational pathways, and policy frameworks needed to prepare government and industry for machine-timescale defense.
10:05 a.m. - 10:27 a.m. – Break
10:27 a.m. - 11:51 a.m. – Session II: Generative AI and ML (Part 1)
Moderator: Osman Yağan
- Lujo Bauer: Privacy and helpfulness in LLM responses to privacy-sensitive scenarios
- Yorie Nakahira: Safe and Adaptive Autonomy: Uncertainty, Language, and Multiagent Interactions
- Mohamed Farag: Hallucination Detection in RAG Systems using Unified Risk Calibration
- Matt Walsh: Secure AI Design with STPA-SEC
- Sarah Cen: Auditing AI Under Information-Resource Constraints
- Wenting Zheng: Provably Undetectable Multi-Agent Collusion
11:51 a.m. - 1:15 p.m. – Lunch and Student Poster Session
1:15 p.m. - 2:39 p.m. – Session III: Generative AI and ML (Part 2)
Moderator: Sarah Cen
- Caroline Hu: Towards Understanding How LLMs Fail at Vulnerability Analysis
- Lei Li: Is Vibe Coding Safe? Benchmarking Vulnerability of Agent-Generated Software Code
- Osman Yağan: Cost-aware LLM routing for Online Incident Detection
- Giulia Fanti: Rethinking Internet Monetization in the Age of AI
- Norman Sadeh: Security and Privacy in the Age of Agentic AI
- Steven Wu: The Agentic Garden of Forking Paths
2:39 p.m. - 3:00 p.m. – Break
3:00 p.m. - 4:00 p.m. – Session IV: Crypto and Blockchain
Moderator: Bryan Parno
- Afonso Tinoco: Oblivious RAM
- Fraser Brown: Compilation for Proofs
- Nicolas Christin: Telegram as Cybercriminal Infrastructure
- Gregory Touhill: Preparing for Q-Day
4:00 p.m. - 4:47 p.m. – Session V: Partnerships and Initiatives
Moderator: Michael Lisanti
- CyLab Partnership Program Updates: Chelsea Cavlovic
- CyLab Venture Network: Michael Lisanti
- CyLab Robotics Security and Privacy Initiative: Limin Jia
- CMU Secure Blockchain Initiative: Ariel Zetlin-Jones
- CyLab Security Academy: Secure the Future: Megan Kearns
- AI Was Good, People Were Better: Lessons from Five Consecutive eCTF Championships: Hanan Hibshi
- Security and Privacy Undergraduate Research (SPUR) Fellows: Mentoring the Next Generation of Security and Privacy Researchers: Joshua Sunshine
4:47 p.m. - 4:50 p.m. – End-of-day remarks
5:15 p.m. - 7:45 p.m. – Dinner at The Porch
Day 2: Wednesday, October 21, 2026 (EDT)
8:00 a.m. - 9:00 a.m.– Breakfast and Registration
9:00 a.m. - 9:05 a.m. – Opening remarks
9:05 a.m. - 9:30 a.m. – CyLab Distinguished Alumni Award Presentation
Moderator: Joseph Calandrino
- Lea Kissner (Distinguished Alumni Award honoree): From Silicon to Signals: Driving Full-Stack Security Through Incentive Engineering
9:30 a.m. - 10:23 a.m. – Session VI: Privacy and Public Policy
Moderator: Hana Habib
- Yanzi Lin: What Adults Will (and Won’t) Do to Prove Their Age: Empirical Evidence from a Deceptive Web Experiment
- Anne Connell: How to Design a Privacy Risk Framework for AI Systems
- Joseph Calandrino: The Market for Counterfeit Digital Documents
10:23 a.m. - 10:53 a.m. – Break
10:53 a.m. - 11:53 a.m. – Session VII: Software Security
Moderator: Riccardo Paccagnella
- Will Klieber: Using LLMs to Adjudicate Static-Analysis Alerts
- Joshua Sunshine: BorrowSanitizer: Securing Rust Across Foreign Function Boundaries
- Bryan Parno: Reducing the Cost of Provably Secure Code with Verus + AI
- Lyndsi Hughes: Silent Sentinel - a Tool for Performing Software Profiling and Analyzing Dynamic Behavior
11:53 a.m. - 1:15 p.m. – Lunch and Student Poster Session
1:15 p.m. - 2:20 p.m. – Session VIII: Software and Hardware Security
Moderator: Limin Jia
- Ruben Martins: Runtime Security Monitoring for Coding Agents
- Dimitrios Skarlatos: Full Spectrum Information Flow Types
- Riccardo Paccagnella: Mitigating Hertzbleed with Formal Leakage Guarantees
- Sarah Scheffler: Private and Verifiable IDs, Attributes and Credentials
2:20 p.m. - 3:20 p.m. – Session IX: Usability
Moderator: Lorrie Cranor
- Jessica Hammer: Building Institutional Resilience with Cybersecurity Games
- Alexandra Li: Human / Browser Agent Robustness: Indirect Prompt Injection Against Humans and Agents
- Hana Habib: Supporting Practitioners' Understanding of LLM Privacy Risks
- Yuvraj Agarwal: BuildingChat: Enabling User Interactions with General-Purpose Sensing Infrastructure for Buildings
3:20 p.m. - 3:25 p.m. – Closing remarks
3:25 p.m. - 4:30 p.m. – Networking
Special thanks to our program committee: Lorrie Cranor, Lujo Bauer, Osman Yağan, Michael Lisanti, Isabelle Glassmith, Beth Bucher, Michael Cunningham, Ashley Bon, and Danyel Kusbit.