Yan Shoshitaishvili announced as keynote speaker
Yan Shoshitaishvili, Associate Professor at Arizona State University, will give the keynote talk "From A Decade of Binary Analysis to A Year of Agentic Slop!"
Modern cyber operations undergo rapid changes due to the integration of autonomous, language-model-driven agents. In offensive operations, agentic systems automate penetration testing, red-team activities, and end-to-end network intrusion campaigns. Frontier models demonstrate high performance on public benchmarks. Conversely, cyber defense increasingly relies on autonomous agents for real-time threat detection, automated mitigation, and active countermeasure deployment. This co-evolution creates a complex adversarial environment where autonomous offensive models directly interact with adaptive defensive systems.
Despite these rapid capabilities, agentic architectures exhibit critical operational vulnerabilities. Offensive models are frequently trained on narrow, repetitive public corpora, which induce predictable statistical behaviors. Consequently, these agents remain vulnerable to targeted defensive deceptions, prompt exfiltration, and operational security failures. Similarly, automated defensive systems face challenges regarding evasion, input manipulation, and model poisoning. Traditional static evaluation environments fail to replicate these dynamic, model-on-model interactions. Therefore, a systematic analysis of both offensive limitations and defensive capabilities is essential to ensure the robustness of cyber operations.
The Workshop on Agentic AI in Offensive and Defensive Cyber Operations (AIDC) provides a specialized forum to address these emergent challenges. The goal of AIDC is to bring together researchers, practitioners, and policymakers from academia, industry, and government to advance the theory, methodology, and practice of agentic security. By establishing a shared space for adversarial AI specialists and cybersecurity operational experts, the workshop intends to transition the community from isolated model evaluations toward holistic, dynamic, and resilient systems design.
Yan Shoshitaishvili, Associate Professor at Arizona State University, will give the keynote talk "From A Decade of Binary Analysis to A Year of Agentic Slop!"
AIDC solicits original contributions on a broad range of topics, which include but are not limited to:
Regular technical papers: Up to 12 pages excluding references and appendices.
Short position papers or work-in-progress (WIP) papers: Up to 6 pages, excluding references and appendices. Short papers are suitable for position papers or original works whose descriptions fit within 6 pages. WIP papers are suitable for original yet incomplete work that is looking for middle-stage feedback from the community.
AIDC uses the official ACSAC HotCRP submission system.
We welcome submissions from industry practitioners and professionals with non-academic backgrounds. If you develop practical offensive or defensive systems and wish to publish your applied research in an academic venue, we encourage you to submit your work to AIDC 2026.
We invite submissions of tutorial proposals that emphasize the live demonstration of agentic systems in offensive and defensive cyber operations. We seek demonstration-driven sessions. In these sessions, presenters must show how their autonomous offensive or defensive systems operate in practice. Tutorials should align with the core themes of the AIDC workshop.
Each tutorial submission will undergo a review process to evaluate relevance, originality, and feasibility. Accepted tutorials will receive a 30-minute to 45-minute time slot during the workshop. Presenters must devote a significant portion of this time to live demonstrations, audience questions, and interactive exploration.
We will host a Lightning Talks session at the AIDC workshop. We request concise, 5-minute in-person presentations on topics of immediate interest to the agentic security community.
Please note that lightning talks are not intended for self-promotion or commercial advertisement. Presenters must share concepts, methodologies, or findings that apply broadly and initiate meaningful discussions. Presenters must focus on the research or system. They must avoid promoting products, services, or organizations. We require presenters to avoid sales pitches, advertisements, and excessive emphasis on personal or corporate achievements. We will strictly enforce the time limit for all presentations.
Lightning Talk submission form
Please submit your Lightning Talk title and abstract, maximum of 200 words, for full consideration via the Lightning Talk submission form. We will publish the accepted abstracts on the workshop website.
All accepted papers will be published by IEEE. Abstracts for lightning talks and tutorials will be available on the AIDC webpage but will not be published by IEEE.
At least one author of each accepted submission (paper, lightning talk, or tutorial) must register for the workshop and present their work. Simultaneous submission of the same work to multiple venues or the submission of previously published work is strictly prohibited.
Please register for the workshop through the ACSAC registration page. You must select the appropriate box on the conference registration form to include the AIDC Workshop fee.
If you require a visa, please plan ahead to ensure sufficient processing time. To begin the visa application process, please review the instructions provided at the conference website.
Authors must follow the ACSAC AI Usage Policy for all workshop submissions.
Associate Professor at Arizona State University
From A Decade of Binary Analysis to A Year of Agentic Slop!
Yan Shoshitaishvili is an Associate Professor at Arizona State University, where he pursues parallel passions of cybersecurity research, real-world impact, and education. His research focuses on automated program analysis and vulnerability detection techniques. Aside from publishing dozens of research papers in top academic venues, Yan led Shellphish's participation in the DARPA Cyber Grand Challenge, achieving the creation of a fully autonomous hacking system that won third place in the competition, and helps guide Shellphish toward the final event of the successor competition, the AI Cyber Challenge.
Underpinning much of his research is angr, the open-source program analysis framework created by Yan and his collaborators. This framework has powered hundreds of research papers, helped find thousands of security bugs, and continues to be used in research labs and companies around the world.
When he is not doing research, Yan participates in the enthusiast, educational, and policy cybersecurity communities. He is a Captain Emeritus of Shellphish, one of the oldest ethical hacking groups in the world, and a founder of the Order of the Overflow, with whom he ran DEF CON CTF, the "world championship" of cybersecurity competitions, from 2018 through 2021. In order to inspire students to pursue cybersecurity (and, ultimately, compete at DEF CON!), Yan created pwn.college, an open practice-makes-perfect learning platform that is revolutionizing cybersecurity education for aspiring hackers around the world. He continues to develop novel approaches to cybersecurity workforce development in his role as Director of the American Cybersecurity Education Institute and has helped advise government policy through CISA's Technical Advisory Council.
To Be Announced