"This year's conference has received ~3,030 valid submissions (~1,280 in Cycle 1 and ~1,750 in Cycle 2)," explained Ben Stock, tenured faculty at the CISPA Helmholtz Center for Information Security and USS program co-chair.
Submission surge and how USENIX Security scaled
USENIX Security Symposium (USS) 2026 opened with an all-time high in submissions: roughly 3,030 valid papers across two cycles, up from about 2,400 the previous year. Program co-chair Ben Stock framed the increase as part of broader growth across the security research community, pointing to similar rises at NDSS — from 694 submissions in 2024 to 1,311 in 2025 and 1,481 in 2026 — and said the conference "scaled our Program Committee (PC) accordingly." The raw numbers forced an operational response: USS expanded reviewer capacity and modified intake processes to handle the heavier load.
Detecting hallucinated references: tools and thresholds
USS's transparency report, co-authored by Stock and Elissa Redmiles, explains the concrete toolchain the organizers deployed to hunt problematic citations. After rejecting a paper that contained nonexistent references, organizers built tooling to "extract references from the submitted PDFs, query well-known sources such as DBLP and arXiv, and manually confirm invalid references." Using that pipeline, the conference rejected submissions that contained three or more unconfirmable references; that rule affected 21 of 1,181 first-round submissions (1.78 percent).
The report also flags a larger set of borderline cases: more than 100 additional papers contained at least one reference that reviewers could not confirm. Acknowledging false positives — for instance, spelling variations or missing entries in queried databases — organizers "opted not to investigate these in order not to further burden staff." That restraint amounts to an operational triage: decisive action where evidence is clear, discretion where the cost of chasing ambiguity is high.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePolicy on AI in the review process and enforcement actions
USS has taken a clearer line on AI use in reviews than on its use in paper writing. The organizers told Program Committee members that "usage of [AI] services to write reviews is not permitted, in particular also because this violates confidentiality." Enforcement has been narrow but firm: of 496 reviewers, five were asked to cease participation after the organizers "detected a tiny number of cases where we have reached sufficient confidence that AI was used and took appropriate actions, including removal of the members from the PC and allowing affected authors to resubmit."
On submissions, the report draws a distinction between acceptable and unacceptable AI assistance. It notes that "limited use of AI to polish human-written text is expected," but draws the line at AI-assisted bibliography fabrication. The report states bluntly: "We believe that it is critical to halt this trend that threatens scientific integrity before it grows further." At the same time, Stock said the organizers "cannot say with certainty that these were AI-hallucinated" when rejecting papers for repeated nonexistent references.
Preserving trust: why USS is cautious about deep policing
The organizers explicitly balanced enforcement against overreach. The transparency report acknowledges the "alarming trend of AI usage in key areas of the scientific process," yet the conference intentionally limited investigation into uncertain cases to avoid overburdening staff and — importantly — to avoid eroding trust within the security research community. That calculus produced selective intervention: robust tooling and a clear rejection threshold for fabricated references, a prohibition on AI-written reviews, and measured restraint where evidence was ambiguous.
Stock summarized the stance: "We have not seen evidence that leads us to believe that AI generated submissions have become a significant challenge for the security community." He qualified that by noting the possibility that AI was used in parts of submissions without becoming a systemic problem.
What this means for security researchers, program committees, and authors
- Security researchers and reviewers: Expect stricter scrutiny of bibliographies and an explicit prohibition on using AI to draft reviews. Reviewers should avoid drafting reviews with LLMs, both to comply with confidentiality expectations and to avoid removal from the PC.
- Program committees and conference organizers: USS demonstrates a model of automated detection (PDF extraction, DBLP/arXiv queries) plus human confirmation and a toleration threshold to limit staff burden. Other conferences facing submission surges may replicate this selective tooling-and-threshold approach.
- Authors and submitters: Limited, careful use of AI to polish prose is tolerated, but creating or relying on nonexistent references is a rejection-risk behavior; three or more unconfirmable citations triggered automatic rejections in the first round.
The USENIX Security '26 approach illustrates a pragmatic middle path: invest in tooling to catch clear abuses, enforce confidentiality around reviews, but avoid exhaustive policing of every anomaly that might be a benign edge case. The conference's next public steps — whether to publish more granular guidance, expand automated checks, or adjust rejection thresholds — will determine whether this model scales as submissions keep rising.




