WISTP 2027 — 15th International Conference on Information Security Theory and Practice
Djerba, Tunisia · 19–21 March 2027 · Hybrid · Single track
Proceedings published by Springer in the Lecture Notes in Computer Science (LNCS) series.
The 15th WISTP International Conference on Information Security Theory and Practice is actively soliciting original submissions from academia and industry. The conference welcomes research papers across the full range of theoretical and practical dimensions of security and privacy, and gives particular prominence in 2027 to the cybersecurity of large language models and agentic AI — systems that now hold credentials, invoke tools, and act on the networks and embedded infrastructure WISTP has studied since 2007.
The conference also encourages submissions that include experimental studies of fielded systems, explore the application of security technology, highlight successful system implementations, and share valuable lessons learned. Submissions from other communities — including law, business and policy — that bring a distinct perspective on technological issues are equally welcome.
Hybrid by design. Every session is streamed, and every accepted paper may be presented remotely and live, in its own slot, with real questions and discussion — not a pre-recorded video played to an empty room. A documented visa refusal is never treated as a no-show. If you cannot travel to Djerba, for visa, funding or personal reasons, you are still explicitly encouraged to submit.
Prospective authors are invited to submit original, previously unpublished work reporting on novel and significant research contributions, ongoing research projects, experimental results and recent developments related to, but not limited to, the following topics.
Cybersecurity of Large Language Models and Agentic AI
Large Language Model Security
- Prompt Injection, Direct and Indirect, Including Multimodal and Cross-Document Vectors
- Jailbreaking, Guardrail Bypass and Automated Red-Teaming
- Alignment Robustness, Safety Degradation through Fine-Tuning, and Sleeper-Agent Backdoors
- System Prompt Extraction and Confidentiality of Model Context
- Training Data Memorisation, Extraction and Membership Inference in Language Models
- Model Stealing, Distillation Attacks and Output Watermarking
- Machine Unlearning and Erasure in Deployed Models
- Retrieval-Augmented Generation: Knowledge Base Poisoning, Context Integrity and Provenance
- Security of LLM-Generated Code, Hallucinated Dependencies and Package Squatting
- Confidential and Privacy-Preserving Inference
- Evaluation, Benchmarking and Assurance of Guardrails
- Model Supply Chain: Weight Provenance, Malicious Models and Unsafe Serialisation
Agentic AI Security
- Agent Hijacking, Goal Manipulation and Confused-Deputy Attacks
- Tool Poisoning and Malicious Tool or Skill Descriptions
- Persistent Memory Poisoning and Long-Horizon State Corruption
- Security of Agent Interoperability Protocols (Model Context Protocol, Agent-to-Agent, Tool Use)
- Sandboxing, Confinement and Least Privilege for Tool-Using, Code-Executing and Computer-Use Agents
- Identity, Delegation, Authorisation and Capability Tokens for Non-Human Actors
- Multi-Agent Trust, Collusion, Emergent Behaviour and Cascading Failure
- Human Oversight, Approval Mechanisms and Interruptibility
- Observability, Audit Trails and Forensics of Agent Actions
- Autonomous Offensive Security and Autonomous Defence
- Agentic Supply Chain: Plugins, Skills, Extensions and Marketplaces
- Accountability, Liability and Assurance of Agentic Deployments
Security and Privacy in Artificial Intelligence
- Adversarial Machine Learning (Evasion, Poisoning, Backdoor Attacks)
- AI/ML Model Security and Robustness
- Privacy-Preserving Machine Learning (Differential Privacy, Homomorphic Encryption, Secure Multi-Party Computation)
- Federated Learning Security and Privacy (Gradient Leakage, Secure Aggregation, Byzantine-Robust FL)
- Explainability and Trust in AI Security Decisions
- Large Language Model Security and Misuse
- Security of AI-Enabled Autonomous Systems
- Data Poisoning and Training Data Integrity
- Model Extraction, Inversion and Membership Inference Attacks
- AI Governance, Accountability and Regulatory Compliance
- Generative AI Risks (Deepfakes, Synthetic Identity, Prompt Injection)
- AI Supply Chain Security
Security and Privacy in Smart Devices
- Biometrics and National ID Cards
- Embedded Systems Security and TPMs
- Interplay of TPMs and Smart Cards
- Mobile Code Security
- Mobile Devices Security
- Mobile Malware
- Mobile OS Security Analysis
- RFID Systems
- Smart Cards
- Smart Devices Applications
- Wireless Sensor Nodes
- On-Device AI and Edge Inference Security
- On-Device Language Models: Weight Confidentiality, Attestation and Integrity
- Trusted Execution Environments for Model, Prompt and Context Confidentiality
- Agentic Assistants Holding Operating System, Accessibility or Payment Privileges
- Side-Channel and Fault Attacks on Neural Accelerators and NPUs
- Generative Presentation Attacks and Deepfake Spoofing of Biometric Systems
- LLM-Assisted Malware Analysis and Detection on Mobile Platforms
Security and Privacy in Networks
- Ad Hoc Networks
- Content-Centric Networks
- Delay-Tolerant Networks
- Domestic Networks
- GSM/GPRS/UMTS Systems
- Peer-to-Peer Networks
- Security Issues in Mobile and Ubiquitous Networks
- Sensor Networks: Campus Area, Body Area, Sensor and Metropolitan Area Networks
- Vehicular Networks
- Wireless Communication: Bluetooth, NFC, WiFi, WiMAX and others
- AI-Based Network Anomaly Detection
- Security of AI-Optimised Network Protocols
- Security of Agent-to-Agent Communication and Tool-Invocation Protocols
- Side Channels in Encrypted LLM and Agent Traffic (Token Timing and Length Leakage)
- LLM-Driven Protocol Analysis, Fuzzing and Specification Inference
- Agentic and Intent-Based Network Management: Trust and Failure Containment
- Abuse and Denial of Service by Autonomous Crawlers and Agent Swarms
- Federated and Distributed Training of Language Models over Constrained Networks
- AI-Native Functions in 5G/6G and Open RAN
Security and Privacy in Architectures, Protocols, Policies, Systems and Applications
- BYOD Contexts
- Big Data Management
- Cloud Systems
- Critical Infrastructure (e.g. for Medical or Military Applications)
- Crowdsourcing
- Cyber-Physical Systems
- Data and Computation Integrity
- Digital Rights Management (DRM)
- Distributed Systems
- Grid Computing
- Identity and Trust Management
- Information Assurance
- Information Filtering
- Internet of Things
- Intrusion Detection
- Lightweight Cryptography
- Localisation Systems (Tracking of People and Goods)
- M2M (Machine to Machine), H2M (Human to Machine) and M2H (Machine to Human)
- Mobile Commerce
- Multimedia Applications
- Public Administration and Governmental Services
- Privacy-Enhancing Technologies
- Secure Self-Organisation and Self-Configuration
- Security Models, Architectures and Protocols: for Identification and Authentication, Access Control, Data Protection
- Security Policies (Human-Computer Interaction and Human Behaviour Impact)
- Security Measurements
- Smart Cities
- Social Networks
- Systems Controlling Industrial Processes
- AI in Critical Infrastructure Security
- AI in Cyber-Physical Systems
- Trustworthy AI for Smart Cities
- LLM and Agentic Systems in Critical Infrastructure and Industrial Control
- Agentic Workflows in Cloud and Distributed Systems: Isolation and Blast-Radius Control
- Identity and Access Management for Non-Human and Autonomous Actors
- Security of AI-Assisted Software Development and CI/CD Pipelines
- LLM-Assisted Threat Intelligence, Detection Engineering and Digital Forensics
- Automated Social Engineering, Phishing and Influence Operations at Scale
- Regulatory Compliance for AI and Agentic Systems
- Trust, Reputation and Contract Models for Autonomous Agents
- Transactional and Payment-Capable Agents: Authorisation and Fraud
Important dates
| Milestone | Date |
|---|---|
| Paper submission | 9 December 2026 |
| Notification of acceptance | 9 February 2027 |
| Camera-ready version | 28 February 2027 |
| Conference | 19–21 March 2027 |
All deadlines are 23:59 Anywhere on Earth. Full schedule.
Submitting
Reviewing is double-blind and papers must follow the Springer LNCS format. Please read the submission guidelines before submitting. Papers are submitted through EDAS.
