Overview
PLAS explores the use of programming language and program analysis techniques to improve software security across compilers, machine learning models, and smart contracts. It promotes speculative, forward-looking ideas and insightful discussions at the intersection of programming languages and security.
Invited Speaker
Accepted Papers
The list of accepted papers is given below
(or there: accepted papers with abstract).
The detailed program will be coming soon.
Long talks
|
LeanDY: Type-Based and Trace-Based Symbolic Protocol Verification in Lean
Simon Jeanteur and Lorenzo Veronese (TU Wien), Magdalena Solitro (Fondazione Bruno Kessler), Matteo Maffei (TU Wien) |
|
zkTAL: Verifying Memory Safety of Binaries via Type Checking in Zero Knowledge
Luís Pedro Félix Ferreirinha and Klaus v. Gleissenthall (Vrije Universteit Amsterdam) |
|
Formalizing and Securing Data Memory-Dependent Prefetchers
Jens Sprengers and Marton,Bognar (KU Leuven), Lesly-Ann Daniel (EURECOM), Frank,Piessens (KU Leuven) |
|
Constant-Gas Programming for Confidential Smart Contracts
Meng Xu (University of Waterloo) |
|
Data Layout Diversification as a Data-Only Attack Mitigation under Multi-Variant
Execution
Anton Schelfhout and Adriaan Jacobs and Stijn Volckaert (KU Leuven) |
|
Bob DyLean: A Framework for the Symbolic Analysis of Cryptographic Protocols in
Lean
Théophile Wallez and Cas Cremers (CISPA Helmholtz Center for Information Security) |
|
Pantomime: Constructive Leakage Proofs via Simulation
Robin Webbers (Vrije Universiteit Amsterdam), Robert Schenck (Northeastern University), Wind Wong and Kristina Sojakova and Klaus v. Gleissenthall (Vrije Universiteit Amsterdam) |
|
Triosecuris: Formally Verified Protection Against Speculative Control-Flow
Hijacking
Jonathan Baumann Yonghyun Kim (MPI-SP), Yan,Farba (MPI-SP and Ruhr University Bochum) Catalin Hritcu (MPI-SP), Julay Leatherman-Brooks (MPI-SP and Portland State University) |
|
Cerisier: a Program Logic for Attestation in a Capability Machine
June Rousseau (Aarhus University), Denis Carnier (KU Leuven), Thomas Van Strydonck (Fortanix), Steven Keuchel and Dominique Devriese (KU Leuven), Lars Birkedal (Aarhus University) |
Short talks
|
Toward Bridging The Gap Between Black-box Deobfuscation and Program
Synthesis
Grégoire Menguy and Vidal Attias and Nicolas Bellec and Sébastien Bardin (Université Paris-Saclay, CEA, List) |
|
From Cohesive Noninterference to Dynamic Policy Transport
Antonio Zegarelli and Niki Vazou (IMDEA Software Institute) |
|
RoTS: Right-on-Time Memory Safety for GPUs
Jonas Roels Adriaan Jacobs Stijn Volckaert (KU Leuven) |
|
Efficient Verification of Fault Injection Attack Protections at
Binary Level
Yanis Sellami and Frédéric Recoules and Noémie Bénard and Sébastien Bardin (CEA List & Université Paris-Saclay) |
|
Amarena: Reasoning about Local Capability Revocation
Using Logical Memory and Ghost Stacks
Youie Ly and Dominique Devriese (KU Leuven) |
|
Compartmentalization of Unmodified Rust Applications
Maxim Ritter von Onciul and Rüdiger Kapitza (Friedrich-Alexander-Universität Erlangen-Nürnberg) |
Scope
- Side-channel vulnerability detection and elimination
- Verification techniques applied to adversarial learning and smart contracts
- Software isolation (e.g., SFI, sandboxing)
- Compiler/runtime-based hardening and monitoring
- Program analysis, binary analysis, and fuzzing
- Security enforcement mechanisms
- Cryptographic protocol verification
- Information flow and access control
- Security in web, IoT, and cloud programming languages
Submission Guidelines
We invite both short papers and long papers. For short papers, we especially encourage the submission of position papers that are likely to generate lively discussion as well as short papers covering ongoing and future work.
- Full papers: There is no page limit on long papers. Papers in this category are expected to have relatively mature content. Papers that present promising preliminary and exploratory work, or recently published work are particularly welcome in this category. Long papers may receive longer talk slots at the workshop than short papers, depending on the number of accepted submissions.
- Short papers: should be at most 2 pages long, plus as many pages as needed for references. Papers that present radical, open-ended and forward-looking ideas are particularly welcome in this category. Authors submitting papers in this category must prepend the phrase "Short Paper:" to the title of the submitted paper.
The workshop has no published workshop proceedings and there is no restriction on paper format other than the page limits stated above. Presenting a paper (either short or long) at the workshop does not preclude submission to or publication in other venues that are before, concurrent, or after the workshop. Papers presented at the workshop will be made available to workshop participants only.
Please submit your submissions (in PDF format) via the following website: https://plas26.hotcrp.com. We follow a single-blind reviewing process, so you do not need to anonymize your submissions.
Important Dates
- Paper submission:
June 20, 2026 AoEJune 26, 2026 AoE - Author notification: August 7, 2026
- Workshop date: November 19
Program Committee
- Gilles Barthe (Max Planck Institute for Security and Privacy, Germany)
- Dominique Devriese (KU Leuven, Belgium)
- Joshua Gancher (Northeastern University, USA)
- Roberto Guanciale (KTH, Sweden)
- Limin Jia (Carnegie Mellon University, USA)
- Adrien Koutsos (Inria Paris, France) (co-chair)
- Robert Künnemann (CISPA Helmholtz Center for Information Security, Germany)
- Hamed Nemati (KTH, Sweden) (co-chair)
- Marco Patrignani (University of Trento, Italy)