The 16th International Symposium on Cyberspace Safety and Security
Macau, China
| August 3-5, 2026
After a rigorous peer-review process, a total of 49 papers have been accepted for presentation at CSS 2026. The list of accepted papers (in no particular order) is shown below.
| No. | Authors | Title |
|---|---|---|
| 1 | Guangkai Jiang and Yuchen Shi | A Game-Theoretic Defense against Membership Inference Attacks |
| 2 | Fangchen Xu, Juncheng Tong, Huijie Yang, Xinyu Li and Quanrun Li | A Lightweight Anonymous Authentication and Key Agreement Protocol for Wearable Devices Using PUF |
| 3 | Zehan Li, Xuemeng Zhai, Hangyu Hu, Jiandong Liang and Guangmin Hu | A Privacy-by-Design Heterogeneous Graph Reasoning for Cross-Entity Stance Inference |
| 4 | Kaijie Ma | A Safety-Enhanced Retrieval-Augmented Generation Framework with Risk-Aware Retrieval and Lightweight Validation |
| 5 | Sijia Li, Jianwei Liu, Hua Guo and Haojia Qi | A Secure and Lightweight Authentication and Key Agreement Protocol Against Ephemeral Secret Leakage Attacks for the Internet of Drones |
| 6 | Honggang Wei, Chuanhao Jing and Yu Fu | A Transformer-Based Multi-Modal Feature Fusion Enhanced DenseNet for Medical Image Classification |
| 7 | Xiang Zhou, Shuai Zhou and Mingyu Zhu | A White-Box Jailbreak Defense Method for LLMs Based on Semantic Probe Conflict |
| 8 | Liu Yunqiang | Add character noise to the network side channel |
| 9 | Xiang Zhang, Feng Wang, Qingxuan Luo, Xinghua Li, Wenqi Duan and Yuantao Wang | Adversarially Consistent Representation Learning: A Unified Regularization Framework for Robust Deep Models |
| 10 | Wang Yian, Liu Zhen and Wang Yajie | Agent Card Module Security Analysis and Vulnerability Discovery: A Review of A2A Protocol Security Research |
| 11 | Xiaowei Zhang, Shigang Liu, Jun Zhang and Yang Xiang | ArchVul: Architecture-Aware Hybrid RAG for Vulnerability Detection in Enterprise Java |
| 12 | Yufeng Pan, Yonghai Wang and Gengshen Wu | Beyond Explicit Decoding: An Implicit Tracing Framework Based on TS-Mark Watermarks and GTD-Net Tracer Datasets |
| 13 | Hailin Yang and Huajie Chen | Bias-Corrected Momentum and Dynamic Step Bounding for Transferable Re-ID Attacks |
| 14 | Lingzhu Li, Xiaoying Jia, Cong Peng and Zhiyan Xu | Certificateless Privacy-Preserving Integrity Auditing and Sanitizable Data Sharing for Cloud-Based Electronic Medical Records |
| 15 | Aniello Castiglione, Jacopo Gennaro Esposito, Vincenzo Loia, Michele Nappi, Chiara Pero and Florin Pop | Combating Visual Disinformation: A Post-Quantum Cryptographic Framework for Image and Metadata Integrity |
| 16 | Qiang Li, Rongqi Jing and Qianwen Sun | Cyber Insurance Forensics and Attribution in the Encrypted Ecosystem: A GNN-based Non-decrypting Traffic Analysis Approach |
| 17 | Xuanyi Qi, Huinan Zhang, Kai Li, Tiansi Li and Hongyi Liu | Decentralized Multi-UAV Coordination for Robust Scheduling in Dynamic Environments |
| 18 | Ming Zhang and Minghao Wang | Design and Implementation of a Lightweight Model Federated Unlearning Framework for Resource-Constrained Edge Devices |
| 19 | Wenjun Huang, Zixiao Kong, Yingtian Sun and Rui Huang | Distributed AoI-aware AI-driven Anomaly Detection for Secure Service Function Chains in 6G Networks |
| 20 | Xu Xin | DSER: Generative Image Detection Based on Dual-Space Reconstruction Error |
| 21 | Xinbo Fu and Lefeng Zhang | Dual-Channel Fine-Grained Reinforcement Unlearning: Integrating Reward Shaping and State Perturbation for Selective Forgetting |
| 22 | Xun Zhang, Hengzhu Liu, Haoyuan Chen, Wenbin Shen and Qiyu Chen | Dual-SU: Sequential Unlearning via Influence Localization and Representation Perturbation |
| 23 | Zihou Zhao, Huiqiang Chen and Tianqing Zhu | Fair Learning without Semantic Demographic Attributes via Curvature-Based Optimization |
| 24 | Guidong Zhang, Mai Ye, Xin Liu, Donglan Liu, Hao Yu, Bing Su and Hongyi Liu | Federated Learning-Based Multi-Source Time Series Fusion for Forecasting |
| 25 | Mingze Sun, Hui Sun, Yubo Wang and Dong Xu | GAU: A Data-free Black-box Adversarial Unlearning Framework via Generative Model |
| 26 | Zonglin Zhu, Qiming Wang and Chunxiao Zhang | Graded Detection Against Multi-Turn Jailbreak Attacks |
| 27 | Zi Xie | Hadoop MapReduce-based “People You May Know” Friend Recommendation |
| 28 | William Mengyang Wu, Weicheng Xing, Xuhan Zuo, Minghao Wang and Tianqing Zhu | Information-Limited Login Oracles: Reducing Feedback Leakage for Online Password Guessing |
| 29 | Xi Luo, Baoru Li, Lihua Yin, Haoqin Chen, Yingkai Fan and Naqin Zhou | KQHA: An Adaptive Dynamic Auto-Scaling Controller |
| 30 | Yizhao Zhou, Xinyu Chen, Li Kuang, Jia-Nan Liu, Fengjun Xiao, Lijian Mao, Bangjie Tang, Heng Jin and Yingjie Xia | LitePriv: A Lightweight On-chip Real-Time Privacy Protection Method for IoT Time Series |
| 31 | Hongxue Chen, Tianjian Liu, Yiwen Xia and Pengrui Liu | LLM-Driven Formal Verification for Safety-Critical Railway Control Systems |
| 32 | Jialin Li, Minfeng Qi, Lefeng Zhang, Yaxuan Xiong, Zhe Sun and Tianqing Zhu | MA-HGAT: Multi-Agent Heterogeneous Graph Attention Network for Smart Contract Logical Vulnerability Detection |
| 33 | Weicheng Xing, Mengyang Wu, Jenny Wang, Jacko Feng and Bo Liu | MaxSim Hijack: Poisoning Multimodal RAG with Token-Aligned Patch Allocation |
| 34 | Qinyuan Wang, Ming Liu, Kewen Liao, Guangyan Huang, Y. Neil Qu, Bruce Gu and Longxiang Gao | Multi-Source Representation Learning for Federated and Privacy-Preserving Emotion Recognition |
| 35 | Jin Wei, Siyu Zhang, Yuchang Mo, Yunfei Li and Mirlan Chynybaev | On the Vulnerability of Cross-Modal Symmetry in Multimodal AIGC Systems |
| 36 | Sihui Wu and Yilin Yang | SafeRendering: Harnessing Attention for Prohibited Concept Removal Autoregressive Models |
| 37 | Qiang Li and Sheng Wen | Safety Modeling and Verification of Perception-Enhanced Autonomous Train Control Systems Using Timed Automata |
| 38 | Peng Yu, Yuzhu Wang, Yu Chen, Qing Ye and Mingwu Zhang | SAML: A Secure Anti-Money Laundering Scheme with Multi-Client Functional Encryption |
| 39 | Yingxian Chang, Xin Liu, Donglan Liu, Fuhui Zhao, Fangzhe Zhang and Hongyi Liu | SemDC: A Semi-supervised Anomaly Detection Approach for Time Series with Redundant Variates via Dimension Complement |
| 40 | Leyang Zhang and Qi Zhong | SHRED: Unified Adaptive Subspace Purification Defense Against Deep Hashing Backdoor Attacks |
| 41 | Fangzhe Zhang, Hao Zhang, Rui Wang, Fuhui Zhao, Mai Ye, Yourong Li and Hongyi Liu | SMA-AD: Self-Supervised Margin-Aware Multivariate Time Series Anomaly Detection |
| 42 | Wang Yixiang and Zhu Congcong | SMART: SMT-Augmented Multi-Agent Reasoning for Travel |
| 43 | Amarjot Singh Atwal, Yang Xiang, Prem Prakash Jayaraman and Xiaoning Du | SoK: Application-Layer Denial-of-Service in OCPP-Based EV Charging: Denial Pathways, Observability Regimes, and Evidence Gaps |
| 44 | Aniello Castiglione, Davide De Angelis, Alessia Maffei, Alberto Moccardi, Chiara Pero and Zhiyuan Tan | The Light at the End of the (TLS) Tunnel: Dynamic Cryptographic and Protocol-Downgrade Analysis of Web Traffic |
| 45 | Xu Xin | The TDIS Framework: Automated Synthesis of Adversarial Descriptions to Jailbreak LLM Tool Use |
| 46 | Haoyuan Huang | TL-FSGW: A Hybrid Text Watermarking Framework for Large Language Models with Frame Synchronization and Adaptive Skipping |
| 47 | 一和 赵 and Cong Cong Zhu | TrustScore: Risk-Aware Framework for LLM Hallucination Detection |
| 48 | Shanjie Xu, Jingyu Wang, Xin Liu, Yuhui Jin, Honglei Yao and Hongyi Liu | VAAD: A Variate-Aware Method for Multivariate Time-Series Anomaly Detection |
| 49 | Junrui Li, Heng Xu and Jie Xi | Visual Feedback-Based Prompt Pollution Attack on Large Language Model-Driven Intelligent Systems: A Case Study with Smart Car Platform |