12th International Conference on Software Security (ICSS 2026)
November 27 ~ 28, 2026, Zurich, Switzerland
Scope & Topics
12th International Conference on Software Security (ICSS 2026) is traditionally, security in software has been thought to be something that can be easily added on as a patch, post-development, and sometimes even after the deployment of the software. According to the US-Computer Emergency Readiness Team (US-CERT), “most successful attacks result from targeting and exploiting known, non-patched software vulnerabilities and insecure software configurations, many of which are introduced during design and code.” Hence, it is imperative that secure design, coding and testing principles as well as deployment and maintenance are thoroughly embedded in the software development lifecycle. At the same time, software security is very inter-disciplinary, as software is being developed for a variety of applications – web, Internet, database, single and distributed computer systems, etc.
Authors are solicited to contribute to the Conference by submitting articles that illustrate research results, projects, surveying works and industrial experiences that describe significant advances in the following areas, but are not limited to.
Topics of interest include, but are not limited to, the following
- Software Security Attacks and Solutions
- Software Threats and Vulnerabilities
- Risk Analysis for Software Security
- Measurements and Metrics for Software Security
- Static and Dynamic Code Analysis for Software Security
- Hybrid Program Analysis
- Binary Analysis and Reverse Engineering
- Automated Vulnerability Discovery
- LLM Based Static and Dynamic Analysis
- Validation, Verification and Testing for Software Security
- Formal Verification for Software Security
- Fuzzing and Mutation Testing
- Runtime Verification
- Synthetic Test Case Generation
- Cryptography for Software Security
- Post Quantum Cryptography
- Secure Protocol Design
- Key Management and Secret Handling
- Firewalls and Intrusion Detection/Prevention Systems for Software Security
- Runtime Application Self Protection
- Behavior Based Threat Detection
- Secure Software Development Lifecycle
- Secure Coding Standards and Their Implementation
- Principles and Models for Secure Software Design
- DevSecOps and CI/CD Security
- LLM Driven Secure Code Generation
- Software Supply Chain Security
- SBOM and Dependency Security
- Package Manager Security
- Security of Open Source Software
- Supply Chain Attack Forensics
- Backdoor Detection in Build Pipelines
- Malicious Dependency Injection
- LLM Supply Chain Attacks
- Virtualization and Cloud Computing for Software Security
- Container and Kubernetes Security
- Microservices and Serverless Security
- Secure Multi Tenant Isolation
- Micro VM Security
- WASM Runtime Security
- Multi Cloud Security
- Cross Cloud Identity Threats
- Cloud Hopping Attack Detection
- Trusted Execution Environments (TEE)
- Secure Enclave Programming
- Confidential Computing Security
- Software Security for Wireless and Mobile Applications
- Software Security for IoT and Embedded Systems
- Software Security for Web and Internet Applications
- API Security
- Browser Security
- Prompt Level Malware
- AI/ML Security
- Poisoning and Evasion Attacks
- Model Extraction and Inference Attacks
- LLM Security and Jailbreak Defense
- Secure AI Pipelines
- LLM Assisted Vulnerability Discovery
- LLM Induced Logic Flaws
- AI Generated Dependency Risks
- LLM Driven Autonomous Exploit Generation
- Autonomous Security Systems
- Self Healing Software
- AI Driven Code Repair
- Autonomous Secure Coding Agents
- Autonomous Patch Deployment Agents
- Self Evolving Security Policies
- AI Driven Zero Day Response Systems
- Software Penetration and Protection
- Exploit Development
- Red Teaming
- Bug Bounty Automation
- Software Security for Database Systems
- Secure Transaction Processing
- Data Integrity and Tamper Resistance
- Software Security for Distributed Systems
- Consensus and Fault Tolerance Security
- Secure Distributed Programming Models
- Security of Distributed AI Pipelines
- Secure Multi Agent AI Systems
- Memory Safe Language Migration
- Rust Security Patterns
- Memory Safety Verification
- Security Telemetry and Observability
- Secure Logging Pipelines
- Anomaly Driven Software Monitoring
- Software Security for CPS
- Safety Security Co Design
- Real Time Secure Software
- Robotic Software Security
- Autonomous Vehicle Software Threats
- Secure Robot Control Software
- Passkey Software Security
- FIDO2 Software Threats
- Identity Bound Software Exploits
- Quantum Hybrid Software Security
- Quantum Accelerated Exploit Detection
- Quantum Enhanced Secure Compilation
- Digital Twin Software Security
- Twin Driven Attack Simulation
- Secure Twin Synchronization Software
- Synthetic Data Security
- AI Generated Testbed Security
- Secure Synthetic Dataset Validation
- Security Governance
- Compliance and Regulatory Security
- Security Policy Engineering
Paper Submission
Authors are invited to submit papers through the conference Submission System by August 30, 2026 . Submissions must be original and should not have been published previously or be under consideration for publication while being evaluated for this conference. The proceedings of the conference will be published by The proceedings of the conference will be published by Computer Science Conference Proceedings in Computer Science & Information Technology (CS & IT) series (Confirmed).
Selected papers from ICSS 2026, after further revisions, will be published in the special issue of the following journals.
Important Dates
| Submission Deadline | : | August 30, 2026 |
| Authors Notification | : | October 24, 2026 |
| Final Manuscript Due | : | October 31, 2026 |
Co - Located Event
***** The invited talk proposals can be submitted to icss@acity2026.org