The 16th International Symposium on Cyberspace Safety and Security
Macau, China
| August 3-5, 2026
CSS 2026 will be held on August 3–5, 2026 in Macau, China. The programme below is provisional and subject to change.
The booklet contains the welcome message, committees, keynote abstracts, full paper sessions and venue information.
| Time | Room | Session |
|---|---|---|
| Day 1 Aug 3, 2026 | ||
| 08:30-18:00 | Foyer | Registration |
| 09:10-09:30 | Room 24+25 | Opening Ceremony |
| 09:30-10:00 | Room 24+25 | Keynote 1 Robert Deng |
| 10:00-10:30 | Foyer | Coffee Break & Poster Session 1 |
| 10:30-11:00 | Room 24+25 | Keynote 2 Xiaosong Zhang |
| 11:00-11:30 | Room 24+25 | Keynote 3 Aniello Castiglione |
| 11:30-13:00 | Room 24+25 | CSS Oral Session 1: LLM Safety & Jailbreak Defense |
| 13:00-14:00 | Room 2+3 | Lunch |
| 14:00-15:30 | Room 24+25 | CSS Oral Session 2: Trustworthy & Fair Machine Learning |
| 15:30-16:00 | Foyer | Coffee Break & Poster Session 2 |
| 16:00-18:00 | Room 24+25 | CSS Oral Session 3: Machine Unlearning / Safety-Critical & Autonomous Systems |
| 16:00-18:00 | Room 26 | CSS Oral Session 4: Time-Series Anomaly Detection & Forecasting |
| Day 2 Aug 4, 2026 | ||
| 08:30-18:00 | Foyer | Registration |
| 09:00-09:30 | Room 24+25 | Keynote 4 Jianwei Liu |
| 09:30-10:00 | Room 24+25 | Keynote 5 Shengke Zeng |
| 10:00-10:30 | Foyer | Coffee Break & Poster Session 3 |
| 10:30-11:00 | Room 24+25 | Keynote 6 Chiara Pero |
| 11:00-12:30 | Room 24+25 | CSS Oral Session 5: AIGC & Multimodal Security |
| 12:30-14:00 | Room 2+3 | Lunch |
| 14:00-15:30 | Room 24+25 | CSS Oral Session 6: Authentication, Cryptography & Protocols |
| 15:30-16:00 | Foyer | Coffee Break & Poster Session 4 |
| 16:00-17:30 | Room 24+25 | CSS Oral Session 7: Vulnerability Detection & Network Security |
| 16:00-17:30 | Room 26 | CSS Oral Session 8: Privacy-Preserving Learning & Applications / ASR Session: Agentic & 6G Network Security |
| 18:30-21:00 | Lisboeta Macau | Banquet |
| Day 3 Aug 5, 2026 | ||
| 08:00-12:00 | Technical Visit & Cultural Tour | |
Day 1 · Aug 3, 2026 · 11:30–13:00 · Room 24+25
| #32 | The TDIS Framework: Automated Synthesis of Adversarial Descriptions to Jailbreak LLM Tool Use |
| #68 | Visual Feedback-Based Prompt Pollution Attack on Large Language Model-Driven Intelligent Systems: A Case Study with Smart Car Platform |
| #70 | A Safety-Enhanced Retrieval-Augmented Generation Framework with Risk-Aware Retrieval and Lightweight Validation |
| #85 | Graded Detection Against Multi-Turn Jailbreak Attacks |
| #95 | TrustScore: Risk-Aware Framework for LLM Hallucination Detection |
| #99 | A White-Box Jailbreak Defense Method for LLMs Based on Semantic Probe Conflict |
Day 1 · Aug 3, 2026 · 14:00–15:30 · Room 24+25
| #8 | Bias-Corrected Momentum and Dynamic Step Bounding for Transferable Re-ID Attacks |
| #22 | Adversarially Consistent Representation Learning: A Unified Regularization Framework for Robust Deep Models |
| #43 | SHRED: Unified Adaptive Subspace Purification Defense Against Deep Hashing Backdoor Attacks |
| #45 | MaxSim Hijack: Poisoning Multimodal RAG with Token-Aligned Patch Allocation |
| #47 | A Game-Theoretic Defense against Membership Inference Attacks |
| #61 | Fair Learning without Semantic Demographic Attributes via Curvature-Based Optimization |
Day 1 · Aug 3, 2026 · 16:00–18:00 · Room 24+25
| #10 | GAU: A Data-free Black-box Adversarial Unlearning Framework via Generative Model |
| #13 | Design and Implementation of a Lightweight Model Federated Unlearning Framework for Resource-Constrained Edge Devices |
| #27 | Dual-Channel Fine-Grained Reinforcement Unlearning: Integrating Reward Shaping and State Perturbation for Selective Forgetting |
| #44 | Dual-SU: Sequential Unlearning via Influence Localization and Representation Perturbation |
| #2 | Decentralized Multi-UAV Coordination for Robust Scheduling in Dynamic Environments |
| #11 | LLM-Driven Formal Verification for Safety-Critical Railway Control Systems |
| #23 | Safety Modeling and Verification of Perception-Enhanced Autonomous Train Control Systems Using Timed Automata |
| #46 | KQHA: An Adaptive Dynamic Auto-Scaling Controller |
Day 1 · Aug 3, 2026 · 16:00–18:00 · Room 26
| #29 | SMA-AD: Self-Supervised Margin-Aware Multivariate Time Series Anomaly Detection |
| #30 | SemDC: A Semi-supervised Anomaly Detection Approach for Time Series with Redundant Variates via Dimension Complement |
| #49 | VAAD: A Variate-Aware Method for Multivariate Time-Series Anomaly Detection |
| #51 | Federated Learning-Based Multi-Source Time Series Fusion for Forecasting |
| #62 | LitePriv: A Lightweight On-chip Real-Time Privacy Protection Method for IoT Time Series |
Day 2 · Aug 4, 2026 · 11:00–12:30 · Room 24+25
| #15 | Beyond Explicit Decoding: An Implicit Tracing Framework Based on TS-Mark Watermarks and GTD-Net Tracer Datasets |
| #33 | DSER: Generative Image Detection Based on Dual-Space Reconstruction Error |
| #41 | TL-FSGW: A Hybrid Text Watermarking Framework for Large Language Models with Frame Synchronization and Adaptive Skipping |
| #50 | SafeRendering: Harnessing Attention for Prohibited Concept Removal Autoregressive Models |
| #60 | On the Vulnerability of Cross-Modal Symmetry in Multimodal AIGC Systems |
| #77 | A Transformer-Based Multi-Modal Feature Fusion Enhanced DenseNet for Medical Image Classification |
Day 2 · Aug 4, 2026 · 14:00–15:30 · Room 24+25
| #3 | A Lightweight Anonymous Authentication and Key Agreement Protocol for Wearable Devices Using PUF |
| #31 | Information-Limited Login Oracles: Reducing Feedback Leakage for Online Password Guessing |
| #93 | SAML: A Secure Anti-Money Laundering Scheme with Multi-Client Functional Encryption |
| #107 | The Light at the End of the (TLS) Tunnel: Dynamic Cryptographic and Protocol-Downgrade Analysis of Web Traffic |
| #113 | Combating Visual Disinformation: A Post-Quantum Cryptographic Framework for Image and Metadata Integrity |
| #123 | A Secure and Lightweight Authentication and Key Agreement Protocol Against Ephemeral Secret Leakage Attacks for the Internet of Drones |
Day 2 · Aug 4, 2026 · 16:00–17:30 · Room 24+25
| #9 | MA-HGAT: Multi-Agent Heterogeneous Graph Attention Network for Smart Contract Logical Vulnerability Detection |
| #14 | Add character noise to the network side channel |
| #65 | Certificateless Privacy-Preserving Integrity Auditing and Sanitizable Data Sharing for Cloud-Based Electronic Medical Records |
| #82 | Cyber Insurance Forensics and Attribution in the Encrypted Ecosystem: A GNN-based Non-decrypting Traffic Analysis Approach |
| #83 | ArchVul: Architecture-Aware Hybrid RAG for Vulnerability Detection in Enterprise Java |
| #118 | SoK: Application-Layer Denial-of-Service in OCPP-Based EV Charging: Denial Pathways, Observability Regimes, and Evidence Gaps |
Day 2 · Aug 4, 2026 · 16:00–17:30 · Room 26
| #21 | Hadoop MapReduce-based “People You May Know” Friend Recommendation |
| #36 | SMART: SMT-Augmented Multi-Agent Reasoning for Travel |
| #69 | A Privacy-by-Design Heterogeneous Graph Reasoning for Cross-Entity Stance Inference |
| #78 | Multi-Source Representation Learning for Federated and Privacy-Preserving Emotion Recognition |
Day 2 · Aug 4, 2026 · 16:00–17:30 · Room 26
| #71 | Agent Card Module Security Analysis and Vulnerability Discovery: A Review of A2A Protocol Security Research |
| #92 | Distributed AoI-aware AI-driven Anomaly Detection for Secure Service Function Chains in 6G Networks |