In brief

  • Defensive limits and mitigations: Iterative pruning of deep neural networks introduces a tradeoff that increases vulnerability to membership inference attacks, while in IoT environments, exclusive-use pairing creates side-channels that enable tracking despite address randomization.
  • Assisted and automated analysis: Empirical observation of reverse engineers shows LLMs successfully narrow the gap between novices and experts but struggle to provide similar value to experienced practitioners.
  • Measuring abuse: Measurement studies on consumer DNS and automated app-store crawlers highlight the scale of user exposure to credential-theft phishing campaigns targeting cryptocurrency assets and broader online scams.

CtPhishCapture: Uncovering Credential-Theft-Based Phishing Scams Targeting Cryptocurrency Wallets

  • Presents an automated framework that detects credential-theft phishing campaigns against cryptocurrency wallets by scanning both web and app stores, extracting interaction sequences to find impersonated domains and altered APKs.
  • The pipeline uses a dynamic crawler simulating wallet interactions (such as mnemonic phrase imports and password setups) and compares structural DOM changes and network requests to identify credential exfiltration paths to attacker-controlled servers.
  • Applying the system in the wild surfaced 6,051 live phishing websites and 148 malicious apps targeting 15 major crypto wallets; the system cannot identify phishing vectors that rely solely on smart contract approvals or transaction signing without credential entry.

Jiang, H., Zhang, Z., Li, X., Li, Y., Zhou, A., Wu, C., Hou, M., Zhang, J., Li, Z., Tsinghua University, Baidu Inc., Nankai University, Zhongguancun Laboratory. “CtPhishCapture: Uncovering Credential-Theft-Based Phishing Scams Targeting Cryptocurrency Wallets.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/ctphishcapture-uncovering-credential-theft-based-phishing-scams-targeting-cryptocurrency-wallets/

Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams

  • A longitudinal measurement study that monitors DNS traffic from a major consumer security product to quantify real-world exposure to tech support, cryptocurrency, and phishing scams.
  • The pipeline intersects 14.8 billion daily DNS requests from 44 million users with a ground-truth dataset of 46,000 known scam domains to track victim encounters, measuring a 1.2% daily encounter rate among the monitored population.
  • The methodology measures exposure at the DNS resolution layer but cannot observe post-resolution behaviour or determine whether users actively engaged with the scams or simply loaded them via background requests.

Kotzias, P., Pachilakis, M., Iuit, J. A., Caballero, J., Sanchez-Rola, I., Bilge, L., Norton Research Group, University of Crete, IMDEA Software Institute. “Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/ctrlaltdeceive-quantifying-user-exposure-to-online-scams/

cwPSU: Efficient Unbalanced Private Set Union via Constant-weight Codes

  • Proposes a Private Set Union (PSU) protocol optimized for unbalanced sets, where one party holds a significantly larger dataset than the other, by utilizing constant-weight codes to reduce communication overhead.
  • The protocol design minimizes the communication rounds required for set union operations while preventing either party from learning elements outside the computed intersection.

Abstract only — full text not retrieved.

Li, Q., Bian, S., Li, H., Xidian University, Beihang University. “cwPSU: Efficient Unbalanced Private Set Union via Constant-weight Codes.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/cwpsu-efficient-unbalanced-private-set-union-via-constant-weight-codes/

Dataset Reduction and Watermark Removal via Self-supervised Learning for Model Extraction Attack

  • Describes a model extraction framework, SSLExtraction, designed to replicate black-box deep learning models while simultaneously evading watermarks embedded in the victim model’s prediction behaviour.
  • The technique uses a greedy random walk over feature spaces generated by self-supervised learning to select queries; because the watermarks manifest as outliers in the learned feature space, the method omits them from the query set used to train the stolen model.
  • Evaluating the attack against six watermarking schemes, the authors report reducing query counts by up to 50% compared to baseline extraction methods while successfully suppressing the watermark verification rates below the detection threshold.

Luan, H., Tan, X., Li, Z., Dai, J., Sun, X., Chen, P., Fudan University, Worcester Polytechnic Institute, Shandong University, Purple Mountain Laboratories. “Dataset Reduction and Watermark Removal via Self-supervised Learning for Model Extraction Attack.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/dataset-reduction-and-watermark-removal-via-self-supervised-learning-for-model-extraction-attack/

Deanonymizing Device Identities via Side-channel Attacks in Exclusive-use IoTs & Mitigation

  • Identifies a side-channel in exclusive-use wireless communication (such as BLE and Wi-Fi pairing) where the observable traffic patterns between two paired devices leak their trust relationship, allowing attackers to track devices despite address randomization.
  • The attack, named IDBleed, exploits the boolean side-channel created when a peripheral device accepts or rejects connections based on its pairing state; an attacker who identifies a known device can trace its paired companion by observing which randomized addresses trigger the exclusive-use communication flow.
  • The authors propose an Anonymization Layer mitigation that standardizes connection request handling to eliminate the side-channel, measuring a 2% overhead in power consumption and connection latency during evaluation on smartphone and PC platforms.

Ellis, C., Zhang, Y., Jangid, M. K., Zhao, S., Lin, Z., The Ohio State University, Drexel University. “Deanonymizing Device Identities via Side-channel Attacks in Exclusive-use IoTs & Mitigation.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/deanonymizing-device-identities-via-side-channel-attacks-in-exclusive-use-iots-mitigation/

Decompiling the Synergy: An Empirical Study of Human–LLM Teaming in Software Reverse Engineering

  • An empirical study measuring the impact of LLM assistance on human performance in software reverse engineering, observing 48 participants across 109 hours of instrumented workflows.
  • The results show that LLMs disproportionately benefit novices, increasing their comprehension rate by 98% to match expert baselines, while providing little measurable comprehension gain to experts.
  • The assistance accelerated triage of known algorithms by a factor of 2.4 and improved artifact recovery (such as identifying symbols and types) by at least 66%, though the study also catalogued instances of harmful hallucinations and ineffective suggestions during complex tasks.

Basque, Z. L., Doria, S., Soneji, A., Gibbs, W., Doupé, A., Shoshitaishvili, Y., Losiouk, E., Wang, R., Aonzo, S., Arizona State University, University of Padua, EURECOM. “Decompiling the Synergy: An Empirical Study of Human–LLM Teaming in Software Reverse Engineering.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/decompiling-the-synergy-an-empirical-study-of-human-llm-teaming-in-software-reverse-engineering/

Defending Against Membership Inference Attacks on Iteratively Pruned Deep Neural Networks

  • Identifies that iterative model pruning techniques—used to compress deep neural networks while preserving utility—increase model memorization, making the resulting models significantly more vulnerable to membership inference attacks than their unpruned counterparts.
  • Proposes a framework, WeMem, that mitigates this memorization by adapting to factors like data reuse and inherent memorability during the pruning process, providing better privacy-utility tradeoffs than defenses designed solely for unpruned models.

Abstract only — full text not retrieved.

Shang, J., Wang, J., Wang, K., Liu, J., Jiang, N., Armanuzzaman, M., Zhao, Z., Beijing Jiaotong University, Beijing University of Technology, Northeastern University. “Defending Against Membership Inference Attacks on Iteratively Pruned Deep Neural Networks.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/defending-against-membership-inference-attacks-on-iteratively-pruned-deep-neural-networks/

Delay-allowed Differentially Private Data Stream Release

  • Proposes a framework for releasing differentially private data streams that introduces an intentional, bounded delay to improve accuracy by enabling look-ahead optimizations rather than enforcing strict real-time constraints.
  • The system employs group-based and order-based optimizations alongside a sensitivity truncation mechanism that collectively reduce the scale of noise added for event-level privacy guarantees.
  • In experiments on a data stream of 18,319 items, permitting a delay of 10 timestamps allowed the approach to achieve up to a 30× improvement in accuracy over zero-delay baseline methods.

Li, X., Qin, Z., Ren, K., Gong, C., Feng, S., Hong, Y., Wang, T., University of Virginia, Zhejiang University, University of Connecticut. “Delay-allowed Differentially Private Data Stream Release.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/delay-allowed-differentially-private-data-stream-release/