RAISE, co-located with ESORICS 2026, aims to bring together researchers and practitioners from academia, industry, and public institutions to discuss recent advances and open challenges in the design, deployment, evaluation, and protection of AI-based cybersecurity systems. The workshop focuses on understanding the security properties, limitations, and failure modes of AI-based components as they are designed and operated in realistic security environments, not in isolation, and at scale.
RAISE welcomes contributions that critically analyze how AI-based cybersecurity mechanisms fail, degrade, or are exploited in practice, as well as work that explores how AI can be reliably and securely leveraged to strengthen cybersecurity systems under real-world operational constraints. Both defensive and offensive perspectives are within scope, provided that they are grounded in realistic threat models, deployment assumptions, and system constraints. The workshop particularly encourages submissions from industrial practitioners and applied researchers, whose insights are essential for understanding operational realities, system integration challenges, and real-world trade-offs. In addition to traditional research papers, we explicitly welcome experience reports, empirical studies, preliminary results, and negative or unexpected findings that shed light on the gap between academic assumptions and operational reality.
Topics of interest include but are not limited to:
Submissions must be written in English and provided in PDF format, using the Springer LNCS template.
We invite submissions in the following categories:
Accepted full papers may be extended up to 16 pages in the camera-ready version to accommodate reviewer feedback and will be included in the Springer Lecture Notes in Computer Science (LNCS) workshop proceedings. Non-archival papers may include previously published or concurrently submitted work and will not be included in the proceedings.
Beyond methodological novelty, RAISE strongly encourages submissions that emphasize practical relevance, deployment considerations, reproducibility, and system integration. Shorter submissions are welcome and will not be penalized if they clearly convey valuable insights, lessons learned, or practical experience. The workshop places emphasis on substance and relevance rather than paper length.
All submissions will undergo a double-blind peer-review process and will be reviewed by at least two members of the Program Committee.
Submission link: https://easychair.org/my/conference?conf=esorics2026
(select the "Workshop on Real-world AI Security and Engineering for Cybersecurity Systems" track).
The following is the tentative program of the workshop and is subject to change.
| 13:50 – 14:40 | Shared keynote by Giovanni Apruzzese (Reykjavík University, Iceland) |
| 14:50 – 15:00 | Welcome and workshop introduction. |
| 15:00 – 15:10 | Signed, Fresh, and Wrong: Cross-Verifier Disagreement in AI-Agent Evidence over X-Road |
| 15:10 – 15:20 | Multi-Modal Social Bot Detection Without Graph Data at Inference Time |
| 15:20 – 15:40 | Coffee break. |
| 15:40 – 15:50 | Crossing the Cyber Divide: Sim-to-Sim and Sim-to-Real Transfer for RL Agents |
| 15:50 – 16:00 | Attacking LLMs with Low-Resource Languages: A Multilingual Evaluation of Small Open-Weight Models |
| 16:00 – 16:10 | Enhancing Linux Privilege Escalation Attack Capabilities of Local LLM Agents |
| 16:10 – 16:20 | Automating Attack Graph Construction for Agentic Pentesting: Towards Neuro-Symbolic Vulnerability Hunting |
| 16:20 – 16:30 | Stopping Is Not Containing: Measuring Post-Stop Residual State in AI-Agent Systems |
| 16:30 – 17:20/17:30 | Q&A and panel discussion. |
Each paper is allocated a 10-minute slot: 8 minutes for presentation + 2 minutes for questions. Presenter names will be added once confirmed.
Criminal IP, operated by AI SPERA, provides decision-ready threat intelligence and TI-powered attack surface management solutions to security teams worldwide. By continuously scanning the global internet, Criminal IP delivers actionable visibility into malicious indicators, exposed assets, and attacker behavior.
We thank AI SPERA for supporting the workshop and helping advance research on real-world AI security and engineering for cybersecurity systems.