Events & News

ZISC organizes a number events. The annual ZISC Workshop brings together leading experts to present and discuss their latest research results on a chosen information security and privacy topics. The weekly ZISC Lunch Seminar presentations illustrate the research done at the affiliated research groups and invite exciting speakers from other research institutes and companies.

Latest News

Florian Tramèr receives USENIX Security Test of Time Award

A paper co-authored by ZISC faculty member Florian Tramèr has received a Test of Time Award at the 2026 USENIX Security Symposium, one of the world’s leading computer security conferences.

Published in 2016, Stealing Machine Learning Models via Prediction APIs demonstrated that attackers could reproduce the functionality of confidential machine-learning models simply by interacting with them through public prediction APIs—without access to the models’ parameters or training data.

The research helped establish the field of model stealing and model extraction attacks and has had a lasting impact on AI security. Its findings remain highly relevant as organisations increasingly provide machine-learning systems through online services and APIs.

The USENIX Test of Time Award recognises papers published ten years earlier that have made a lasting contribution to computer security research and practice. The paper was co-authored by Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter and Thomas Ristenpart, who are now professors at ETH Zurich, Yale University, Cornell Tech, Duke University and the University of Toronto, respectively.

Tramèr’s research continues to focus on the security, privacy and trustworthiness of AI systems. As head of ETH Zurich’s Secure and Private AI (SPY) Lab, he studies how AI systems can be attacked and how these vulnerabilities can be addressed through technical and regulatory safeguards.

Congratulations on this outstanding achievement!

Test-of-Time Award for D-INFK researchers

A research team from ETH Zurich’s Department of Computer Science (D-INFK) has received a Test-of-Time Award for work that has shaped the automated analysis of cryptographic protocols for more than a decade.

Image: D-INFK, ETH Zürich

Professor David Basin of ETH Zurich’s Department of Computer Science, Professor Cas Cremers, Dr Benedikt Schmidt and Dr Simon Meier have been honoured with a Test-of-Time Award at the 39th IEEE Computer Security Foundations Symposium (CSF’26). The award recognises their 2012 paper, “Automated Analysis of Diffie-Hellman Protocols and Advanced Security Properties”, and its lasting impact on the formal verification of cryptographic protocols. The Test-of-Time Award honours research papers that have demonstrated outstanding and enduring significance to their field. This year, the committee selected the paper as one of only two papers from the 659 papers published at CSF and its predecessor, CSFW, through 2026.

Automated analysis of cryptographic protocols

The award-winning paper introduced a general symbolic framework for the automated analysis of cryptographic protocols, with a particular focus on protocols that use modular exponentiation, such as Diffie-Hellman-based protocols. The researchers developed a formal modelling approach based on rewriting and expressed security properties using first-order formulas. A novel constraint-solving algorithm enables the automated analysis of protocols and can either establish that a protocol satisfies its specified security properties or identify a concrete witness demonstrating that a property can be violated – effectively providing an attack on the protocol. Technically, the approach combines ideas from equational unification and symbolic reasoning with techniques from strand spaces and proof normal forms. The researchers implemented the approach and demonstrated its effectiveness on challenging case studies, including the automated verification of the NAXOS protocol under a symbolic version of the eCK security model.

A lasting impact on the field

Since its publication, the work has influenced a range of subsequent developments in formal methods for security, particularly in the design of automated tools for the verification of cryptographic protocols. The techniques introduced in the paper have become an important reference point for automated reasoning about protocol security. The award also highlights the broader and lasting impact of research carried out by the D-INFK community in the field of formal security verification.

Congratulations on this outstanding accomplishment!

Read more here.

Two ERC grants for the ZISC faculty

Congratulations to the ZISC chair Srdjan Čapkun and to the ZISC faculty member Adrian Perrig on receiving European Research Council (ERC) Advanced Grants!

The European Research Council (ERC) Advanced Grants rank among the most prestigious research awards available to scientists at European universities. Through these grants, the ERC supports ambitious, high-risk research projects with the potential to push the frontiers of knowledge. Each grant provides up to €2.5 million (approximately CHF 2.3 million), with additional funding available where needed for major research infrastructure.

Awarded through an exceptionally competitive selection process based solely on scientific excellence, ERC Advanced Grants are both a significant source of research funding and a mark of personal distinction. They recognize researchers with outstanding scientific achievements and international leadership in their fields. Receiving an ERC Advanced Grant is often compared to reaching the Champions League final in football—a recognition reserved for those performing at the very highest level.

This is an outstanding achievement for the Department of Information Security and for ZISC!

14th call for proposals for the CYD fellowship

In order to promote research and innovation in cyber-defence, our partners EPFL and Cyber-Defence (CYD) Campus are now opening calls for different fellowship opportunities aimed at Master, Doctoral and Postdoctoral researchers as well as future entrepreneurs:

Doctoral Fellowships (up to 4 years plus 1-year potential extension): deadline on 19 August 2026 (17:00 CEST).

Distinguished Postdoctoral Fellowships (up to two years): deadline on 19 August 2026 (17:00 CEST).

Master Thesis Fellowships (6 months): open rolling call.

Proof of concept Fellowship (12 months): open rolling call.

An online applicant workshop will be held on 7 July 2026 (11:00-11:45 CEST). Please register here.

The CYD Fellowships are supported by armasuisse Science and Technology. For more information contact the EPFL Research Office (research@epfl.ch) or visit the CYD Fellowships website.

LLMs can deanonymize internet users at scale

A recent publication by the SPY Lab ask how good large language models are at re-identifying anonymous online users. This is a collaboration between Daniel Paleka, Joshua Swanson, Michael Aerni and Florian Tramèr from ETH Zurich’s Department of Computer Science (D-INFK), together with Simon Lermen (MATS) and Nicholas Carlini (Anthropic).

Although deanonymization is a decades-old idea, pseudonymous accounts on Reddit, Hacker News and similar forums have stayed largely safe — such attacks traditionally needed structured data or hours of manual investigation.

The main insight of the paper is that LLMs change the economics of deanonymization. It is previously known that LLMs can extract identity-relevant features from online comments. Our pipeline extends this to search for candidate matches across platforms, and reasons over them to confirm a match. LLM-based methods massively outperform classical ones, linking accounts to real people for less than $5 each. The takeaway: the more you post, the easier you are to unmask.

The findings received wide press coverage: the ETH D-INFK spotlight, plus Bloomberg, The Guardian, The Verge, El País, CyberScoop and Bruce Schneier internationally, and 20 Minuten, Tages-Anzeiger and Le Temps in Switzerland.