MADWeb 2026
We're less than a month out from the MADWeb 2026 submission deadline! We look forward to seeing your exciting work!
We invite both full and work-in-progress papers. Consider submitting and help spread the word!
π
Deadline: Dec 11, 2025 (AoE)
π Submit: madweb26.hotcrp.com
17.11.2025 21:30 β π 1 π 3 π¬ 0 π 0
There are a lot more details to our approach, including several open problems. If youβre interested in learning more, we encourage you to read the paper (arxiv.org/pdf/2403.04960)! You can also catch Yuhao's talk about IsolateGPT at NDSS next week in San Diego!
18.02.2025 20:50 β π 0 π 0 π¬ 0 π 0
GitHub - llm-platform-security/SecGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems
An Execution Isolation Architecture for LLM-Based Agentic Systems - llm-platform-security/SecGPT
We are excited to announce that IsolateGPT will appear at NDSS 25. To foster follow-up research, we release our code (github.com/llm-platform...). Also as @llamaindex.bsky.social Pack (llamahub.ai/l/llama-pack...). Lead by Yuhao Wu w/ @franziroesner.bsky.social @yoshikohno.bsky.social & Ning Zhang
18.02.2025 20:50 β π 0 π 3 π¬ 1 π 0
Our evaluation demonstrates that it is indeed feasible to isolate execution in LLM agentic computing paradigm: it mitigated security and privacy issues without loss of functionality and its performance overhead is under 30% for 2/3rd of tested queries
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
IsolateGPT runs individual tools in isolated containers, to ensure that tools cannot interact with components outside of their execution environments. Then to enable interaction between sandboxed tools, it allows apps to exchange messages only via a central trustworthy module
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
Our security architecture, named IsolateGPT, tackles these challenges. IsolateGPT assumes an LLM-based digital assistant that supports third-party tools for tasks, such as online shopping, email management, etc. and aims to secure adversarial manipulations between tools
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
Access control & isolation have existed in prior systems but their application to LLM computing paradigm is non-trivial: isolated environments need to be securely provided access to broader system context, & secure interfaces need to be defined for natural language interactions
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
To that end, our research has focused on adapting systems security principles in improving the security of LLM integrations and LLM-based agentic systems. We recently explored the feasibility of access control and isolation in improving the security of LLM interfacing with tools
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Today's LLMs are susceptible to prompt injections, jailbreaks, and other attacks that allow adversaries to overwrite a model's original instructions with their own malicious prompts.
While there is a serious emphasis on making LLMs robust, e.g., training LLMs to prioritize privileged instructions openai.com/index/the-in..., we believe that tried and-tested systems security principles have not been given similar attention in securing LLM integrations
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
These issues can manifest in conventional computing systems where LLMs are getting deeply integrated, such as OSs and mobile apps, and also in agentic systems (or AI agents) which interface with various tools and content on the internet
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
Fundamentally the key issue is that LLMs load instructions from various sources (system, user, tools) in a shared context window where without safeguards, LLMs treat them with the same privileges
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
At a high level, the interfacing between system components in determined at runtime based on instructions from system components β which can be untrustworthy, malicious, or compromised β such as tools developed by third-party services or arbitrary content hosted on the internet
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
While this execution paradigm has the potential to fundamentally transform computing, there are serious security, privacy, and safety risks!
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
For example if a user prompts their LLM-based personal assistant to download and store email attachments in a cloud drive, the LLM can predict the necessary interfacing between email and cloud drive tools to carry out the task
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
LLMs have enabled a new computing paradigm, where the system relies on ML models to resolve user queries expressed in natural language! In this paradigm, new features can be implemented via natural language specs, without requiring explicit implementation from software developers
18.02.2025 20:50 β π 0 π 0 π¬ 1 π 0
Privacy | 2024 | The Web Almanac by HTTP Archive
Privacy chapter of the 2024 Web Almanac covers the adoption and impact of online tracking, privacy preference signals, and browser initiatives for a privacy-friendlier web.
The Privacy chapter was written by a cornucopia of experts: Yash Vekaria, Benjamin Standaert, @maxostapenko.com , Abdul Haddi Amjad,
Yana Dimova, Shaoor Munir, Chris BΓΆttger, and Umar Iqbal
almanac.httparchive.org/en/2024/priv...
Catch up on for the latest on a very important topic for the web!
10.12.2024 11:28 β π 0 π 1 π¬ 1 π 0
Chief Privacy Officer; lawyer; technologist; expat; filmmaker(?). Believer in the Oxford comma.
computer security person. former helpdesk
PhD student at University of California, Santa Cruz working on Security, Privacy, and Human Factors.
https://momodawoud.github.io/
Assistant Professor @ University of New Mexico. Security and Privacy.
Tenured Researcher @Inria
USENIX Security Artifact Evaluation Co-Chair 2025 & 2026
Web Security & Privacy: JavaScript (in)security, browser extensions
https://aurore54f.github.io
Asst. Prof. @ ASU | PI @ the http://HappyResearchLab.com | PhD from
UIUC
Secure Human-AI Interaction, Human Factors in Sec
Design, Code and things in between!
I make the internet fasterβbecause buffering is evil. Assoc Prof
@UIC. PhD @Purdue. Ex-NVIDIA chip tinkerer. Your MacBook Air might run my chip.
phd βͺ@ucdavis | web privacy and security researcher
https//www.yashvekaria.com/
I get unreasonably excited about Chicago, cybersecurity, education, and local impact.
https://kaytwo.org
Professor of EECS @UC Irvine. Privacy and Networking Researchers. Director of @ProperData. athinagroup.eng.uci.edu/athina/. Opinions my own.
Assistant Professor of Computer Science @University of Arizona. I study emerging systems and software security problems. Views are mine.
A LLN - large language Nathan - (RL, RLHF, society, robotics), athlete, yogi, chef
Writes http://interconnects.ai
At Ai2 via HuggingFace, Berkeley, and normal places
Welcome to the Bluesky account for the ACM Internet Measurement Conference (IMC)!
Join us in Karlsruhe, Germany, Nov 03β06, 2026.
Details: https://conferences.sigcomm.org/imc/2026/
Managed by the ACM IMC 2026 publicity chair.
Brown Computer Science / Brown University || BootstrapWorld || Pyret || Racket
I'm unreasonably fascinated by, delighted by, and excited about #compsci #education #cycling #cricket and the general human experience.
Professor at UW; Researcher at Meta. LMs, NLP, ML. PNW life.
Professor at UC Riverside, head of spalab.cs.ucr.edu
Home: emilianodc.com
Internet measurement, tech policy, and privacy researcher. Asst. Prof. at UIowa.