Workshop on
Explainable AI and Security
July 6th, 2026 in Lisbon, Portugal
co-located with the 11th IEEE European Symposium on Security and Privacy

Keynotes

Barbara Hammer, University of Bielefeld

Barbara researches theory and algorithms in machine learning and their application for technical systems and the life sciences, including explainability and learning with drift. She is extremely well embedded in the ML community, serving on the review board for machine learning of the German Research Foundation (DFG), the selection committee for fellowships of the Alexander von Humboldt Foundation and the Scientific Directorate of Schloss Dagstuhl. She will share her expertise on explainability and when to trust an explanation.

Konrad Rieck, TU Berlin & BIFOLD

Konrad's research revolves around computer security and machine learning, developing novel methods for detecting computer attacks, analyzing malicious software and discovering security vulnerabilities. In particular, in the scope of the latter, he has recently used Explainable AI to improve task solving performance. His works is regularly published at top computer security venues including IEEE S&P, USENIX Security, ACM CCS, and ISOC NDSS.

Junqi Jiang, J.P. Morgan Trustworthy AI Center of Excellence

Junqi works on Trustworthy AI focusing on robust explainable AI and robust counterfactual explanations in particular. He works on these topics in both traditional machine learning for tabular data and large language models (LLM) for textual data. He publishes his work at top venues like NeurIPS, ICLR, AAAI, IJCAI and is well-embedded in the machine learning community.

Programme

The following times are in UTC+0.

09:30–10:00 Opening and Welcome
10:00–11:00 Keynote 1
When to trust an explanation?
Barbara Hammer, University of Bielefeld
Explainable AI (XAI) aims at the integration, extension, or substitution of otherwise black-box machine learning models by components, which are comprehensible for humans. Albeit many XAI methods exist, it is unclear, what information exactly they reveal, why different methods lead to different results, and in which sense humans can trust the results. Within the talk, I will give an example how XAI technologies can be used in applications relating to critical infrastructures first, more specifically, I will demonstrate how it generates fingerprints to deal with faults in water distribution systems in an intuitive and human-understandable way. Afterwards, I will have a look at vulnerabilities, such as attacks on XAI methods and limited plausibility. Finally, I will have a glimpse at their limitations which exist despite their foundation in exact mathematical models as offered by Shapley values, for example. One challenge is given by the fact that popular feature relevance measures, for example, often target single features, hence too simplistic basic components. I will discuss extensions which also take feature interactions into account, this way offering more reliable results and extending applicability to modern self-supervised multimodal models.
11:00–11:30 Coffee Break
11:30-12:45 Paper Session
Adversarial Malware Can Be Both Evasive and Deceiving: a Gradient-based Attack Against Prediction and Explainability in Windows PE Malware Detection
Authors: Luca Lobascio (Università degli Studi di Bari Aldo Moro, IMT School for Advanced Studies Lucca), Giuseppina Andresini (Università degli Studi di Bari Aldo Moro, CINI Consorzio Interuniversitario Nazionale per l'Informatica Bari), Annalisa Appice (Università degli Studi di Bari Aldo Moro, CINI Consorzio Interuniversitario Nazionale per l'Informatica Bari), and Donato Malerba (Università degli Studi di Bari Aldo Moro, CINI Consorzio Interuniversitario Nazionale per l'Informatica Bari).
Contamination-Robust Anomaly Detection under Weak Supervision with Explainable Representations
Authors: Guowei Wu (Dalian University of Technology), Huanqi Tu (Dalian University of Technology), Xuyun Zhang (Macquarie University), and Lin Yao (Dalian University of Technology).
XplainCVSS: Interpretable Machine Learning for Explainable CVSS Vulnerability Severity Prediction
Authors: Christopher Beddies (Technical University of Applied Sciences Wildau), Stefan Kubica (Technical University of Applied Sciences Wildau), Bernd Heimer (Technical University of Applied Sciences Wildau), and Bernd Eylert (Technical University of Applied Sciences Wildau).
Towards Explaining Classification Models in Security with Sparse Autoencoders
Authors: Nils Ole Breuer (TU Wien), Lorenz Linhardt (Technische Universität Berlin, BIFOLD), Philipp Normann (TU Wien), and Daniel Arp (TU Wien).
12:45–13:45 Lunch
13:45–15:00 Keynote 2
Towards (Mis)Understanding Learning-Based Vulnerability Discovery
Konrad Rieck, TU Berlin & BIFOLD
The days of unknown security bugs seem to be numbered. Learning-based approaches to vulnerability discovery achieve remarkable results in practice. Yet, we do not really know why or how. In this talk, I look back on five years of trying to understand how machine learning operates in vulnerability discovery. Starting from post-hoc explanations and their limitations, I move forward to causal analysis of LLM predictions. Both perspectives paint a mixed picture: AI genuinely discovers bugs, yet with far less reasoning than one might expect. This leaves explainable AI in an uncomfortable position, suggesting that the answers we seek lie not inside the model, but in the data, context, and tools it uses.
15:00–15:30 Coffee Break
15:30–16:30 Keynote 3
Robust Counterfactual Explanations in Machine Learning and Beyond
Junqi Jiang, J.P. Morgan Trustworthy AI Center of Excellence
Counterfactual explanations (CEs) have become a central paradigm in explainable AI, identifying the minimum changes to an input that would lead a machine learning model to produce a different outcome. When such explanations are communicated to individuals affected by an automated decision as actionable guidance for obtaining a more favourable result, they give rise to the closely related notion of algorithmic recourse. Much attention has gone to making CEs valid (flipping the model prediction), proximal (close to the original input), plausible (lying within the data manifold), and diverse (offering meaningfully different alternatives), but a more fundamental property is often overlooked: robustness. Recourse recommendations are of little use if they get easily invalidated by small changes in their generation pipeline, such as routine model retraining, small differences between similar individuals, or the existence of equally accurate competing models. This talk will trace a line of work that formally characterises robustness of CEs and turns it into provable guarantees, spanning robustness to model changes, input changes, and model multiplicity, along with tools to generate and benchmark robust CEs. Finally, these same underpinning principles (explanation, consistency, and reliability under perturbation) extend naturally into the era of large language models, raising open challenges for building AI systems that stay trustworthy when the world around them shifts.
16:30–17:30 Discussion Panel
17:30– Closing remarks

Call for Papers

Important Dates

  • Registration deadline: February 16th, 2026 (AoE, UTC-12)
  • Paper submission deadline: January 29th February 26th, 2026 (AoE, UTC-12)
  • Acceptance notification: March 18th 26th, 2026 (AoE, UTC-12)
  • Camera ready due: April 23rd, 2026
  • Workshop day: July 6th, 2026

Overview

The XAISEC Workshop aims to bridge the computer security and the machine-learning communities at the intersection of Explainable AI (XAI) and security. Naturally, the security community utilizes XAI to address computer security tasks, such as malware detection, vulnerability discovery, and even the detection of attacks against AI. However, both communities also work on the security and robustness of XAI—unfortunately, largely independently of each other. In light of the close collaboration (and success stories) in the field of "adversarial machine learning" during the past decade, this observation is not only a curiosity but a missed opportunity.

Scope of Papers

We invite the ML and Security communities to submit papers on either using Explainable AI for computer security tasks or the security of Explainable AI. Submission are expected to have 6 pages excl. references and well-marked appendices.

Topics of Interest

Topics of interest include but are not limited to:

  • Innovative applications of XAI for computer security and the analysis of the security of AI models
  • Robustness analysis of XAI
  • Vulnerabilities of XAI
  • Novel explanation techniques that are more robust (to attacks)
  • New datasets, benchmarks and challenges to assess the security and robustness of AI and XAI

Submission Guidelines

Papers must be submitted as a single PDF document, must be anonymous (double-blind review) and written in English language, and shall not exceed 6 pages body text with unlimited additional pages for references and appendices. Reviewers are not expected to read the appendices while deciding whether to accept or reject the paper. Moreover, submissions must be typeset in LaTeX in A4 format (not "US Letter") using the IEEE conference proceeding template we supply. Please do not use other IEEE templates.

Submissions must not substantially overlap with papers that have been published or that are simultaneously submitted to a journal or conference with proceedings. Also, authors should refer to their previous work in the third person. Accepted papers will be published in IEEE Xplore. One author of each accepted paper is required to attend the workshop and present the paper for it to be included in the proceedings.

Proactive Prevention of Harm

We expect authors to carefully consider and address the potential harms associated with carrying out their research, as well as the potential negative consequences that could stem from publishing their work. Failure to adequately discuss such potential harms within the body of the submission may result in rejection of a submission, regardless of its quality and scientific value.

Open Science Expectations

In line with the main conference, our expectation is that researchers will maximize the scientific and community value of their work by making it as open as possible. This means that, by default, all of the code, data, and other materials (such as survey instruments) needed to reproduce your work described in an accepted paper will be released publicly under an open source license. Sometimes it is not possible to share work this openly, such as when it involves malware samples, data from human subjects that must be protected, or proprietary data obtained under agreement that precludes publishing the data itself. All submissions are encouraged to include a clear statement on Data Availability that explains how the artifacts needed to reproduce their work will be shared, or an explanation of why they will not be shared.

AI Guidelines

The use of AI-generated content (including but not limited to text, figures, images, and code) shall be disclosed in the acknowledgments section. At the time of submission, the acknowledgments do not count towards the page limit. The AI system used shall be identified, and specific sections of the article that use AI-generated content shall be identified and accompanied by a brief explanation regarding the level at which the AI system was used to generate the content. The use of AI systems for editing and grammar enhancement is common practice and, as such, is generally outside the intent of the above policy. In this case, disclosure as noted above is not required, but recommended.

Submission Site

All accepted submissions must be presented at the workshop as posters. One author of each accepted paper is required to attend the workshop and present the paper for it to be included in the proceedings.

Submission link: https://submission.intellisec.de/xaisec-2026.

For any questions, please contact one the workshop organizers at

Committee

Workshop Chairs

Program Committee

  • Achyut Hegde, Karlsruhe Institute of Technology
  • Alessandro Erba, Karlsruhe Institute of Technology
  • Alexander Warnecke, Databricks
  • André Artelt, Bielefeld University
  • Antonio Rago, King's College London
  • Daniel Arp, TU Wien
  • Dilyara Bareeva, Fraunhofer Heinrich Hertz Institute HHI
  • Giovanni Apruzzese, University of Liechtenstein
  • Giuseppina Andresini, Università degli Studi di Bari Aldo Moro
  • Hubert Baniecki, Warsaw University of Technology
  • Luca Marzari, University of Verona
  • Mario D'Onghia, University College London
  • Maximilian Noppel, Karlsruhe Institute of Technology
  • Nidhi Rastogi, Rochester Institute of Technology
  • Sanghamitra Dutta, University of Maryland College Park