Conference Program

The technical sessions of DBSec 2026 will take place over 3 days, from July 28 to July 30, 2026. All times are shown in Eastern Daylight Time (EDT). The conference is single-track. Presentation start times are shown in the first column.

Tuesday 28 July

EDT Session Chair
08:30 Registration
09:10 Opening
09:25 Session 1: AI Applications in Security and Privacy Rosario Giustolisi
09:25 Silent Fallbacks and Semantic Gaps: Evaluating the Functional Soundness of LLM-Generated Linux Password Policies
Vivek Vaidya, Aditya Patwardhan, Sudiksha Das and Ashish Kundu
09:50 “Room for more?”: Behavior Adaptive IoT Device-type Fingerprinting
Maxwel Bar-On, Bruhadeshwar Bezawada, Indrakshi Ray and Indrajit Ray
10:15 SecMate: Multi-Agent Adaptive Cybersecurity Troubleshooting with Tri-Context Personalization
Yair Meidan, Omri Haller, Yulia Moshan, Shahaf David, Dudu Mimran and Asaf Shabtai
10:35 Break (25 min)
11:00 Keynote Talk
Daniel Massey, National Science Foundation
Balaji Palanisamy
12:00 Lunch Break (60 min)
13:00 Session 2: Access Control & User Privacy Yair Meidan
13:00 Performance Analysis of Multi-Core ABAC Systems using an M/G/m Queue Model
Hunny Chandra, Karthikeya S M Yelisetty, Gaurav Madkaikar, Shamik Sural, Jaideep Vaidya and Vijayalakshmi Atluri
13:25 Integrating ABAC into PostgreSQL: A Trusted Execution Environment based Approach
Harshit Jain, Shamik Sural, Vijayalakshmi Atluri and Jaideep Vaidya
13:50 Formalizing Access Requests in IAM: Beyond Roles and Permissions
Alexander Puchta, Sebastian Groll and Günther Pernul
14:10 SCoPE: Cross-Platform Discovery and RAG-Driven Profiling of Public Personal Data
Stefano Cirillo, Giuseppe Polese, Giandomenico Solimando and Nicola Zannone
14:30 Break (25 min)
14:55 Session 3: Data Privacy and Cyberattacks Günther Pernul
14:55 Anonymous yet Verifiable Privacy-preserving Demand Response
Rosario Giustolisi, Emad Heydari Beni, Daniele Marletta and Maryam Sheikhi Garjan
15:20 DICS: Demographic-Invariant Cross-Synthesis Method for Privacy-Preservation in Speech Processing
Nishanth Chennagouni, Mashrafi Alam Kajol and Qiaoyan Yu
15:45 Identifying and Protecting Records at Risk for Membership Inference Attacks Against Synthetic Data
Nina Niederhametner and Rudolf Mayer
16:05 Where LLM-Assisted Cyberattacks Break Down: A Stage-Level Analysis of Workflow Execution Boundaries
Gabby Campos, Tam Nguyen, Chetraj Pandey, Prashnna K Gyawali and Robin Chataut
16:25 INFER: Insider Framework for Modeling Temporal Risk Escalation via Signal Integration
Christian Kengne, Nora Boulahia-Cuppens and Frederic Cuppens
16:45 DBSec Business Meeting

Wednesday 29 July

EDT Session Chair
08:30 Registration
09:00 Session 4: AI Security and Privacy R.K. Shyamasundar
09:00 IntraShuffler: A Privacy Preserving Framework for Heterogeneous DP Federated Learning
Farhin Farhad Riya, Olivera Kotevska and Jinyuan Sun
09:25 Improving SIEM Rules using Transformer-Based Rule Evasion Detection and Attribution
Valency Oscar Colaco, Simin Nadjm-Tehrani, Erik Nordström and Hannes Widéen
09:50 Differentially-Private Synthetic Visit Infilling with Transformers
Andrei Ouatu, Gabriel Ghinita and Razvan Rughinis
10:15 On Targeted Output Generation via Adversarial Reframing in Language Models
Shahnewaz Karim Sakib, Swati Kar and Anindya Bijoy Das
10:35 Coffee Break (25 min)
11:00 Keynote Talk
Sharad Mehrotra, University of California, Irvine
Pierangela Samarati
12:00 Lunch Break (60 min)
13:00 Panel: IFIP WG 11.3 Conferences: Status and Prospects
Moderator: Sushil Jajodia; Panelists: Vijay Atluri, Carl Landwehr, Pierangela Samarati, Ravi Sandhu, Bhavani Thuraisingham, Jaideep Vaidya
14:30 Break and Social Event
14:30 Instructions for Social Event
Megan Herceg, Local Arrangement Chair, George Mason University
14:45 Break (2 hours)
16:45 Departure for DC Tour
Bus departs from conference venue.
18:30 Dinner
20:30 Return to Arlington
Bus departs from restaurant.

Thursday 30 July

EDT Session Chair
09:10 Session 5: Data Security and Privacy Bruhadeshwar Bezawada
09:10 Dual Blind Indexes for Queryable Column-Level Encryption: A Two-Phase Pipeline with Quantifiable Leakage Bounds
Roberto Gallo
09:35 Anonymous Hierarchical Key Assignment Schemes
Roberta Cimorelli Belfiore, Alfredo De Santis, Anna Lisa Ferrara, Manuela Flores and Barbara Masucci
10:00 SOLSTICE: Optimising Verifiable Data Retrieval for Storage Nodes in Account-based Blockchains
Nhi Luu, Asish Balasundaram and Sushmita Ruj
10:25 Perfectly-Secure Graph-Based Distributed Secret Sharing Protocols
Alfredo De Santis, Anna Lisa Ferrara and Barbara Masucci
10:45 Break (20 min)
11:05 Session 6: Threats and Attacks Sushmita Ruj
11:05 A Novel Approach to SBOM Extraction from HTTP Messages in Identity Management Security Testing
Andrea Bisegna, Laura Cristiano, Pietro De Matteis, Eleonora Marchesini, Luca Piras and Silvio Ranise
11:30 In Sync or Sink? About Tactical Divides between Attackers and Defenders
Johannes Grill, Daniel Oberhofer, Philip Empl, Stefan Schönig and Günther Pernul
11:55 Towards Lightweight Reliability: Using Soft Prompts for Hallucination Mitigation in Large Language Models
S M Tahmid Siddiqui, Akib Jawad Ononto, Anoop Singhal and Latifur Khan
12:20 Lunch (50 min)
13:10 Session 7: Security of Large Language Models and Blockchains Barbara Masucci
13:10 Information Flow Control for Retrieval-Augmented LLM Chatbots
Md Fazle Rasul, Hamed Aghayarzadeh and Indrakshi Ray
13:35 BenchGuard: A Two-Layer Framework for Contamination-Aware Evaluation of LLM Vulnerability Detection
Adiba Mahmud, Yasmeen Rawajfih, Hossain Shahriar and Ross Arnold
13:55 Analysis of Fairness of Transaction Orders in Hedera and Classic Blockchains
Rudrapatna Shyamasundar
14:20 Data Poisoning in Longitudinal Local Differential Privacy: Attacks and Analysis
Antonio Alves Marreiras Neto, Héber Hwang Arcolezi and Javam de Castro Machado
14:45 Blurred Points, Clear Clusters: A Non-Interactive Framework for Locally Private Clustering
Tijbe van der Ende, Mina Alishahi and Clara Maathuis
15:05 Closing Remarks
15:15 Conference Ends