3rd ACCSS Security & AI Workshop
Organised by the ACCSS Working Group on AI & Security, this event brings together researchers at the intersection of security/privacy and artificial intelligence to foster innovation and share cutting-edge ideas, experiences, and collaboration opportunities.
A key feature of this year’s edition will be breakout sessions on topics collected from the community, enabling focused discussions and collaborative exchange on emerging challenges. Participants are also invited to submit abstracts for short talks/posters to present their work and engage with peers in an open and interactive setting.
When registering, you will have the opportunity to suggest topics for the breakout sessions, helping shape the conversation.
Details
- Date: 24th September 2026
- Location: CVD Apeldoorn (Wapenrustlaan 11, 7321 DL Apeldoorn)
- Registration: Register here
- Program: View the programme
Keynote Speakers
Marten van Dijk — CWI and VU Amsterdam
Talk Title: PACZero is the answer where DP-SGD fails to give significant privacy guarantees
Abstract: The Differential Privacy (DP) framework has been extensively used by industry to market adherence to data privacy regulations of services and applications. The reported classical (eps,delta)-DP guarantees for services/applications based on complex learning tasks trained on (potentially) private data turn out to only prove that a successful interference attack is at least as hard as solving a simplified hypothesis testing problem which has a significant advantage over random guessing (the latter is equivalent to ideal privacy). This advantage turns out to be very large for complex learning tasks. In fact no significant privacy guarantee is given by the reported DP guarantees. Even though these reported DP guarantees are vacuous, non-vacuous (or stronger) DP guarantees are not chosen since these require considerably more noise and therefore will severely degrade the model’s utility. This translates the reported DP guarantees into a psychological sales trick, which even some researchers use in their research papers (likely benign due to their lack of understanding of what the DP framework actually stands for). We note that the added DP mechanism may actually provide a form of privacy, however, this can only be heuristically demonstrated by evaluating a benchmark suite of Membership Inference Attacks (MIAs). We will explain recent theoretical results on the impossibility and possibility of using DP-SGD for training a neural network with significant DP guarantees. This leads to the question whether we may want to redefine the privacy framework so that it still captures the class of MIA attacks that we want to protect against in our practical setting as well as providing a proof technique that leads to strong privacy guarantees. The PAC Privacy framework provides such an alternative and we show a new ZO-SGD approach (for training neural networks), coined PACZero, that offers strong privacy guarantees.
About:Marten van Dijk founded and leads the Computer Security research group at CWI and is an IEEE Fellow for his expertise in secure processor design and encrypted calculations. Notable achievements include the creation of Aegis, a groundbreaking secure processor, and the development of influential protocols like ‘Path ORAM’ and ‘Fully Homomorphic Encryption over the Integers.’ Van Dijk is the recipient of the IEEE CS (Computer Society) Edward J. McCluskey Technical Achievement Award 2023 and the IEEE & ACM A. Richard Newton Technical Impact Award in Electronic Design Automation 2015. He has won several test-of-time awards (HPCA 2025, CCS 2023 and Intel 2022; as well as a most frequently cited paper award 2000-2009 Symposium on VLSI Circuits 2017, and an inclusion in the “25 years of International Conference on Supercomputing” 2014).
Fatih Turkmen — University of Groningen
Talk Title: Privacy Leakage Across the AI Stack: From Memorization and Retrieval to Hardware
Abstract: AI systems can expose sensitive information through multiple components of their increasingly complex computational stack. This talk examines privacy leakage across three layers of modern AI systems: model's memory, external knowledge, and hardware implementation. First, I will talk about memorization in large language models (LLMs), showing that sensitive training information can remain extractable (even) when models are augmented with external context through retrieval-augmented generation (RAG). Second, we move beyond model parameters to the private data stores used by multi-modal RAG systems, demonstrating how adaptive interactions can enable the extraction of information from external knowledge sources. Finally, we examine privacy at the hardware level through model inversion in memristive spiking neural networks, showing that hardware non-idealities and reliability conditions can alter information leakage and that predictive accuracy alone does not capture privacy exposure. Together, I would like the audience to leave with this: AI privacy cannot be assessed by examining the trained model in isolation. Meaningful privacy evaluation must consider the entire deployed AI system—from what is encoded in model parameters, to the data sources it accesses, to the hardware on which it executes.
About: Fatih Turkmen is an Associate Professor at the University of Groningen, where he has been affiliated since 2019. His research focuses on the security and privacy of/with AI systems, privacy-enhancing technologies, as well as formal and empirical approaches to security analysis of software and hardware. He has extensive experience in designing and developing decentralized security solutions, particularly in contexts involving processing of sensitive data (e.g., genomic data) or access to services. More recently, his work has expanded into the security and privacy challenges of neuromorphic systems (often associated with in-memory computing). His research explores key questions such as: What are the security and privacy vulnerabilities in software and hardware implementations of neuromorphic systems and how do ML attacks transfer to such systems? In this context, he investigates vulnerabilities across both software and hardware, drawing on techniques from machine learning security, side-channel analysis, and fuzz testing. He has contributed to several national and international research initiatives in these domains, including the Dutch LESSEN project. He serves as an editor for the International Journal of Information Security (IJIS), was General Chair of the 26th Information Security Conference (ISC), and regularly serves in program committees of leading security and privacy conferences such as CCS, PETs, and SACMAT.
Programme
| Time | Activity | Speaker |
|---|---|---|
| 9:30–10:00 | Walk-in | |
| 10:00–10:10 | Welcome | |
| 10:10–11:10 | Keynote: PACZero is the answer where DP-SGD fails to give significant privacy guarantees | Marten van Dijk |
| 11:10–11:30 | Coffee + posters | |
| 11:30–11:45 | Talk: The Geometry of Memorization: When Better Generalization Increases Privacy Risk | Andrea Agiollo |
| 11:45–12:00 | Talk: Unpacking Forged-Origin BGP Hijack Inferences | Ebrima Jaw |
| 12:00–12:15 | Talk: Do we really need them? A user perspective on provenance graphs for attack artifact discovery in alert investigation | Aditya Bharadwaj |
| 12:15–13:15 | Lunch | |
| 13:15–14:15 | Keynote: Privacy Leakage Across the AI Stack: From Memorization and Retrieval to Hardware | Fatih Turkmen |
| 14:15–14:35 | Coffee + posters | |
| 14:35–15:45 | Breakout sessions + Panel discussion | |
| 15:45– | Drinks & Bitterballen + posters | |
Organizers
TU Eindhoven
k.tuma@tue.nl
TU Delft
m.khosla@tudelft.nl
University of Twente
t.s.vanede@utwente.nl