AD&D 2026 Program

Friday, September 18, 2026

Session 1 — 09:00–10:30 – AI/LLM Deception & CTI

Room P1, Building CU037

Time Session
09:00–09:15 Welcome and Opening Remarks
09:15–09:35 Make the Adversary Spend More: Stateful Deception as a Cost-Exchange Primitive for AI-Era Cyber DefenseAlessandro Cantelli-Forti, Isabella Marasco, Hosam Alamleh, Giada Boschi, Michele Colajanni
09:35–09:55 Honey for the Agent: Cyber Deception and Behavioral Fingerprinting of LLM-Based AttackersDario Maddaloni, Anastasia Safargalieva, Emmanouil Vasilomanolakis
09:55–10:15 AdvancedShelLM: A Stateful Multi-Agent LLM Honeypot for SSH DeceptionMuris Sladić, Eman Alibalić, Veronica Valeros, Carlos Catania, Sebastian Garcia
10:15–10:30 Position Paper: Bridging Cyber Deception and CTI through STIX-Based Honeypot Log MappingKarina Elzer, Tillmann Angeli, Stylianos Malamas, Emmanouil Vasilomanolakis
10:30–10:50 Coffee Break

Session 2 — 10:50–12:20 – Honeypots, Honeynets & Human Decoys

Room P1, Building CU037

Time Session
10:50–11:10 HoneyPeople: When Decoys Talk BackClaudio Facchinetti, Daniele Santoro, Roberto Doriguzzi Corin, Domenico Siracusa
11:10–11:30 No Time for Harvesting: Deception-Assisted Attribution of IPv6 Address Leakage in the NTP PoolStefan Groser, Sajad Homayoun
11:30–11:50 Decoys Cannot Go Everywhere: Mapping the Deception Surface in MITRE ATT&CKVeronica Valeros, Carlos Catania, Viliam Lisý, Harm Griffioen
11:50–12:05 Position Paper: Development of an Automated Vulnerability Placement Framework for IaC-Based HoneynetsMarvin Sinnwell, Daniel Reti, Hans D. Schotten
12:05–12:20 Closing remarks and Open Discussion
12:20–13:50 Lunch

Session 3 — 13:50–14:40 – Keynote

Room 201, Building CU002

Time Session
13:50–14:40 Keynote: Misleading Large Language Models used (or misused) in Scientific Peer-Reviewing via Hidden Prompt-Injection Attacks - Giovanni Appruzzese
  Abstract: Large Language Models (LLMs) have revolutionized many aspects of our society. Many tasks encompassing document summarization or autonomous content generation can now benefit from the capabilities of LLMs. Among these, a domain in which LLMs are receiving incresing attention is that of scientific peer reviewing. Yet, usage of LLMs in this context must be done with due care: LLMs have certain blind spots which, if exploited, can lead to detrimental effects to the human requesting the service of an LLM. In this talk, I will outline the reasons why the author of a scientific paper may want to mislead an LLM tasked to review a given paper. Based on these reasons, I will then explain ways in which one can reach their goal via “hidden prompt injections”. Finally, I will discuss the results of a large-scale systematic analysis wherein we studied the impact of prompt-injection attacks against commercial LLMs (e.g., ChatGPT, Gemini). In doing so, I will also outline potential countermeasures—as well as counter-countermeasures. The takeaway is that blind reliance on LLMs for peer-review duties is strongly discouraged, and human oversight is still necessary.
  Bio: Giovanni Apruzzese is an Assistant Professor within the Department of Computer Science at Reykjavik University, Iceland. Prior to this, he was affiliated with the Hilti Chair of Data and Application Security at the University of Liechtenstein—first as a PostDoc and then as an Assistant Professor. He obtained the PhD in Information and Communication Technologies at the University of Modena and Reggio Emilia (Italy) in 2020. He authored over 50 peer-reviewed papers at internationally-recognized research venues. His research interests encompass a variety of themes, most of which revolve around cybersecurity and artificial intelligence, but he also appreciates topics within human-computer interaction. His primary expertise lies in network security and in phishing detection. Giovanni also puts a lot of effort in servicing the scientific community, and he was awarded numerous recognitions for his reviewing duties in leading computer-science venues. He is the General Chair of IEEE SaTML 2027, one of the PC Co-chairs of ACM AISec 2026, one of the PC Vice-chairs of USENIX Security 2026, and has been an Associate Editor for ACM TAISAP since 2025, and an Area Chair for NeurIPS since 2024. Due to his interest in reviewing and his servicing committments, he has also recently engaged in researching the usage of large-language models for scientific peer reviewing.
  Keynote in collaboration with HumSec, RAISE, and HotDiSec.