Some of my thoughts, filtered slightly for public consumption.

USENIX Security '25 Round-up

I was fortunate to attend USENIX Security '25 this past week. My primary interest these days is in LLMs, so I mostly stuck to Track 3, which focused on LLM-related security work.

Some overall takeaways from the conference:

I want to highlight some of the papers presented that I found most interesting. Note that there were quite a few talks on topics that I don't find interesting myself, so I'm a bad judge of which papers someone interested in the topic would like:

I abbreviate the titles of papers here since otherwise this would read like a conference schedule, but you can mentally rewrite these in the style of The DOMino Effect: Detecting and Exploiting DOM Clobbering Gadgets via Concolic Execution with Symbolic DOM (actual paper at this conference) if you'd like.

Practical Impact

Understanding Model Misbehavior

Prompt Injection

I've written about Prompt Injection before, and it was well-represented at the conference.

Stealing Training Data

Messing with Providers

These were not the most technically sophisticated papers, but who doesn't enjoy messing with our new AI overlords?

Just Cool

Other Posts