A workshop at ESORICS 2026, 17th of September 2026 in Rome, Italy.
The HS3 workshop seeks to share experience, tools and methodology on hardware-assisted software security. We are looking forward to submissions that propose new architectures offering better resilience against software attacks. These architectures should rely on hardware-based security mechanisms to protect the software stack. One of the challenges is to formally specify and verify the security guarantees offered by such architectures and to better assess the security guarantees provided by existing hardware architectures against software attacks, especially attacks against micro-architecture. This can be achieved by identifying new vulnerabilities using reverse engineering, fuzzing or other attack approaches. The goal of the HS3 workshop is to provide a forum for researchers and practitioners from academia, industry and government that work on hardware-assisted software security. HS3 2025 has a special theme on “Hardware-Supported Software Security for AI Systems”.
Combining software and hardware aspects to consider new software attacks is becoming increasingly important. For example, hardware vulnerabilities such as Spectre or Meltdown can be exploited purely by software attacks. Such attacks can be executed remotely and do not require physical access to the targeted hardware platform. On the other hand, hardware features can be used to better detect and respond to traditional software attacks, such as memory corruption. Therefore, it is necessary to study the security of software/hardware interfaces in terms of attacks and defences.
The purpose of the HS3 workshop is to share experience, tools and methodology on hardware-assisted software security. On one hand, we need to propose new architectures offering better resilience against software attacks. These architectures should rely on hardware-based security mechanisms to protect the software stack. One of the challenges is to formally specify and verify the security guarantees offered by such architectures. On the other hand, we also need to assess better the security guarantees provided by existing hardware architectures against software attacks, especially attacks against micro-architecture. This can be achieved by identifying new vulnerabilities using reverse engineering, fuzzing or other attack approaches. The goal of the HS3 workshop is to provide a forum for researchers and practitioners from academia, industry and government that work on hardware-assisted software security.
As Artificial Intelligence (AI) systems become more deeply integrated into critical sectors, including healthcare, education, manufacturing, and mobility, these systems become high-value targets for cyber attacks. At the same time, hardware vendors rise to the challenge and provide, e.g., Trusted Execution and and Confidential Computing infrastructure on GPUs or other AI-targeting hardware. For this year’s edition of the HS3 workshop, we want to encourage submissions that investigate questions regarding hardware-supported security approaches for AI systems and low-level attacks against, and attack mitigations for AI systems, specifically if these involve (micro-)architectural aspects of the execution environment. HS3 will not accept general papers on AI security and we suggest that authors working on these topics submit their work to AI-themed workshops at ESORICS instead.
Topics of interest include, but are not limited, to the following
HS3 2026 is co-located with the 31st European Symposium on Research in Computer Security in Rome, Italy. The workshop will take place right after the main conference, on the 17th of September 2026.
A plain-text version of this Call for Papers is available.
There are two categories of submissions:
All papers must be written in English and describe original work that has not been published or submitted elsewhere. The submission category (regular paper, short paper, special theme) should be clearly indicated. Members of the The Program Committee will fully review all submissions. Papers will be published by Springer in the Lecture Notes in Computer Science (LNCS) series as workshop post-proceedings of ESORICS 2026. Contact the Program Chairs if you do not want your short paper to appear in the proceedings.
Papers must be typeset in LaTeX using the LNCS template. Failure to adhere to the page limit and formatting requirements can be grounds for rejection. Well-marked appendices do not count into the page limit; PC members are also not required to consider material presented in appendices when reviewing submissions. We will clarify the constraints for including appendices in camera-ready papers closer to the camera-ready deadline and after discussion with the workshop chairs and the publisher. We follow the ESORICS Call for Papers regarding anonymity of submissions and do not require papers to be anonymised. Anonymised submissions are, however, welcome at HS3.
Paper must be submitted through the ESORICS EasyChair website; select the “HS3” track toindicate that you are submitting to this workshop: https://easychair.org/conferences/?conf=esorics2026
For accepted papers, authors must agree with Springer LNCS copyright and at least one author must attend the workshop.
You find registration information on the ESORICS 2026 website: https://sites.google.com/di.uniroma1.it/esorics2026/attend/registration; a complete workshop schedule is also available there.
| 09:00 | Joint Workshop Keynote |
| Josep Domingo Ferrer: Does machine learning compromise the privacy of training data? Short Bio: Josep Domingo-Ferrer received BSc-MSc and PhD degrees in Computer Science (Universitat Autònoma de Barcelona), a BSc-MSc in Mathematics (UNED), and an MA in Philosophy (Université de Paris Nanterre). He is a University Professor of Computer Science and an ICREA-Acadèmia Research Professor at Universitat Rovira i Virgili in Tarragona, Catalonia, where he also leads CYBERCAT (Center for Cybersecurity Research of Catalonia). His research interests include privacy, data security, trustworthy machine learning, and ethics in information technology. He is an IEEE Fellow, an ACM Distinguished Scientist, an elected member of Academia Europaea, an elected member of the International Statistical Institute, a Fellow of Institut d’Estudis Catalans (Catalan national academy), and a Chevalier (Knight) dans l’Ordre des Palmes Académiques (France). Abstract: Machine learning (ML) models are often trained on personal or otherwise sensitive data. For example, ML models are trained on health data supplied by smartphones or sensitive data coming from IoT sensors. In several jurisdictions, the legal framework for the publication and disclosure of personal data is being extended to ML. This is based on the implicit assumption that disclosing a trained ML model poses a similar privacy risk to the personal data used to train it as directly publishing those data. However, with a trained model, it is necessary to carry out a privacy attack to draw inferences from the training data. In this talk, I examine the main families of privacy attacks against predictive and generative ML, including membership inference attacks (MIAs), property inference attacks, and reconstruction attacks. This analysis shows that most of these attacks appear to be less effective in the real world than might be suggested by a prima facie interpretation of the relevant literature. The talk will conclude by highlighting the role of privacy attacks to assess machine unlearning for privacy, and the potential clash between machine unlearning and blockchain-recorded ML. |
|
| 10:00 | Coffee Break |
| 10:30 | HS3 Welcome and Opening Remarks |
| 10:35 | Session 1: Side-Channel Attacks & Discovery |
| 10:35 | Eyal Hadad and Mordechai Guri. Shape and Substance: Dual-Layer Side-Channel Attacks on Local Vision-Language Models |
| 10:45 | Abla Smahi and Jan Tobias Muehlberg. SoK: Software-Controlled Side Channels in LLM Inference |
| 10:55 | Nathanaël Simon, Maria Mushtaq and Ludovic Apvrille. RLeak: Hybrid Reinforcement Learning Guided Fuzzing Framework for RISC-V Vulnerability Timing Side-Channel Discovery |
| 11:05 | Questions & Discussion |
| 11:20 | Session 2: Measurement, Detection & Evaluation Methodologies |
| 11:20 | Adam Henault, Camille Monière, Philippe Tanguy and Vianney Lapôtre. Statistical Analysis of HPC Filtering: Towards Reliable Use in Security |
| 11:30 | Clément Médart, Pierre Graux, Clémentine Maurice and Gilles Grimaud. PerfCT: Detecting Constant-Time Violations Using Hardware Performance Counters |
| 11:40 | Damien Jauvart and Aurélien Vasselle. Evaluating the Security of Open-Source Cryptographic Libraries Against Physical Attacks: An End-to-End Study on Botan |
| 11:50 | Questions & Discussion |
| 12:05 | Session 3: Trust & Cryptographic Hardware |
| 12:05 | Michał Wroński, Łukasz Dzierzkowski, Mateusz Leśniak and Ewa Syta. A Universal Weierstrass Engine for Hardware-Supported Quantum Cryptanalysis of RSA, DH, and ECC |
| 12:15 | Julian Funk, Matti Schulze, Patrick Sieber, Manuel Vögele, Jonas Röckl and Tilo Müller. Solving Attestation Fragility: A Software-Based Trust Anchor for Agile Confidential VMs |
| 12:25 | Questions & Discussion |
| 12:30 | Lunch |
| 13:50 | Session 4: Short Papers and Works in Progress |
| 13:50 | Leslie Fifanon, Pierre Wilke, Damien Courousse, Mathieu Jan and Guillaume Hiet. WIP: Formalizing Fault Injection at the Microarchitectural Level |
| 14:00 | Guillaume Didier. Hardware-Software Defence Idea: Data-flow Assertion Instructions |
| 14:10 | Joshua Byun, Jennie Hill, Ian Roessle, Dane Brown, Owens Walker and Aidan Guiney. WiP: Towards a Dynamic, Hardware-Agnostic Ransomware Detection System Using Hardware Performance Counters |
| 14:20 | Questions & Discussion |
| 14:30 | Open Discussion |
| 14:45 | Closing Remarks & Rapid Evacuation of the Workshop Room |
Yuko Hara, CNRS, France (co-chair)
Pierre Wilke, CentraleSupélec/Inria