Professor and Chair of Computer Science and Engineering at the University of Michigan
Title: Advances and Challenges in securing AI-based systems.
Date: 9:00-9:50, Sep. 14, 2026.
Abstract: Agentic computing is proving to be a transformative technology in many fields by accelerating scientific advances and assisting with decision-making. But, AI models are known to hallucinate, can be manipulated via adversarial inputs, and potentially leak data. At the same time, safeguards are being added to models via post-training alignment, improved pre-training, and using guard models. We look at the evolution of security in this transformative field and identify several challenges that remain in making these systems more secure. A key point is that advances in systems security must go hand-in-hand with attempts to achieve better security-related alignment of AI-based models.
Biography: Atul Prakash is a Professor and the Richard H. Orenstein Division Chair of Computer Science and Engineering at the University of Michigan. His research focuses on computer systems security, the security and privacy of machine learning models, and trustworthy computing infrastructures, with his group known for identifying weaknesses in machine learning models — including a widely cited demonstration that stickers placed on physical traffic signs can fool state-of-the-art image classifiers, work that inspired the DARPA GARD program. He received his Bachelor of Technology in Electrical Engineering from the Indian Institute of Technology Delhi, and his PhD in Computer Science from the University of California, Berkeley. He joined the University of Michigan as an Assistant Professor in 1989, became an Associate Professor in 1995, and has been a Full Professor since 2001; he was appointed Division Chair of Computer Science and Engineering in 2024. He has also served as a Visiting Research Scientist at IBM, Gesellschaft für Mathematik und Datenverarbeitung, and Google. Among his honors are the Distinguished Practical Paper Award at the IEEE Symposium on Security and Privacy (2016), the EECS Outstanding Achievement Award (2017), and the Best Paper Award at the IEEE Cybersecurity Development Conference (2018).
Find his publications and citation record on Google Scholar: Google Scholar Profile.
Mathematician at U.S. Naval Research Laboratory
Title: Securing Website Identity with Contextual Trust
Date: 9:00-9:50, Sep. 15, 2026.
Abstract: Multiple approaches have been implemented for website identities that associate meaningful identifiers (e.g., domain names) with self-authenticating identifiers, (e.g., onion addresses). While these approaches have advantages over relying on traditional certificates alone, identifier association itself is subject to blocking, hijack, very accurate fingerprinting, and other types of surveillance and manipulation. Consequently, access to a relevant website itself is similarly vulnerable. We will review some of these attacks published over the last decade and ongoing work on two approaches to self-authenticating meaningful identity (SAMI): associating a registered domain name with an onion address (onion association) and associating an atproto handle with a decentralized identifier (DID association), as well as their combination in a single identity. Finally, we will discuss grounding secure identity association in contextual trust, wherein trusting attestations of identity relies on contextual relevance of an attestor (a government, a corporation, a community, a trade association, an individual, etc.) to the identity rather than relying only on structural authority, for example as embodied in the traditional centralized infrastructure.
Biography: Paul Syverson---inventor of onion routing, creator of Tor, author of one book on logic and over one hundred refereed papers, chair of many security and privacy conferences---possesses multiple advanced degrees in philosophy and mathematics, multiple Test of Time awards, and an origami magic rabbit folded for him by Gus Simmons. Paul is a founder of the Privacy Enhancing Technologies Symposium and the ACM Workshop on Privacy in the Electronic Society. He is an EFF Pioneer, an ACM Fellow, was named one of the 100 top global thinkers by Foreign Policy magazine, and was among Okta's inaugural Identity 25 list of global pioneers and leaders in identity management. During almost four decades as Mathematician at the U.S. Naval Research Laboratory he has also been a visiting scholar at institutions in the U.S. and Europe. Find his publications and citation record on Google Scholar: https://scholar.google.com/citations?user=QDnC2nAAAAAJ&hl=en
Find his publications and citation record on Google Scholar: Google Scholar Profile.
Professor of Computer Science at ETH Zürich, Adjunct Professor of ECE at CMU, CyLab Fellow.
Title: Secure and Predictable High-Performance Connectivity for AI Training and Inference.
Date: 9:00-9:50, Sep. 16, 2026.
Abstract: SCION, a next-generation Internet architecture, already introduces capabilities that are difficult to achieve on today's Internet: cryptographically secured routing through AS certificates and full path validation, resilience against routing convergence attacks, guaranteed bandwidth through Hummingbird reservations, and path-aware networking that offers in many cases over a hundred of end-to-end path choices between communicating endpoints.
The next evolutionary step is to move from path awareness to path intelligence. By continuously evaluating available paths using metrics such as latency, jitter, packet loss, throughput, and reliability, we enhance SCION to predict path quality and enable the application to automatically select the path that best matches an application's requirements. For instance, real-time applications such as voice and video prioritize low latency and jitter, while bulk data transfers and AI workloads demand maximum throughput and predictable bandwidth. SCION enables application-specific routing that optimizes performance, reliability, or security.
These capabilities are particularly relevant for modern AI infrastructures. Large-scale AI training and distributed inference depend on high-performance, predictable network connectivity across data centers. By combining intelligent path selection with Hummingbird's bandwidth guarantees, SCION provides the foundation for a new generation of AI-ready networks that deliver secure, resilient, and application-aware connectivity.
Biography: Adrian Perrig (born 1972) is a Swiss computer science researcher and professor at ETH Zurich, leading the Network Security research group. His research focuses on networking and systems security, and specifically on the design of a secure next-generation internet architecture. He received his BSc in Computer Engineering from EPFL in 1997, and his MS and PhD from Carnegie Mellon University in 1998 and 2001, respectively. From 2002 to 2012, he was a Professor of Electrical and Computer Engineering, Engineering and Public Policy, and Computer Science (courtesy) at Carnegie Mellon University, becoming a Full Professor in 2009. From 2007 to 2012, he served as the technical director for Carnegie Mellon's Cybersecurity Laboratory (CyLab). Since 2013, he has been a Professor at ETH Zurich, leading the Network Security Group, whose research revolves around building secure and robust network systems, with a particular focus on the design, development, and deployment of the SCION Internet architecture. During his career, he has received numerous awards and distinctions for his contributions to computer and network security, including being named a Fellow of the Association for Computing Machinery (ACM) in 2017 and receiving four IEEE Symposium on Security and Privacy Test of Time Awards.
Find his publications and citation record on Google Scholar: Google Scholar Profile.