Call for Papers

The CSET Workshop will be held on Monday, December 7, 2026, in conjunction with the 2026 Annual Computer Security Applications Conference (ACSAC), which will be located in Los Angeles, CA.

Important Dates:

  • Paper submissions due: September 10, 2026
  • Notification to authors: October 20, 2026
  • Final paper files due: November 15, 2026
  • Workshop: Monday, December 7, 2026

Overview

For 19 years, the Workshop on Cyber Security Experimentation and Test (CSET) has been an important and lively space for discussing all-encompassing cybersecurity topics related to reliability, validity, reproducibility, transferability, ethics, and scalability—in practice, in research, and in education. Submissions are particularly encouraged to employ a scientific approach to cybersecurity and demonstrably grow community resources.

Invited Topics

For CSET '26, we solicit exciting work across a broad range of areas relevant to security and privacy. A list of topics of interest (broadly interpreted):

  • Cybersecurity research methods: designing and conducting large and complex system evaluations in the context of cybersecurity, i.e., experiences and discussions of qualitative and quantitative methods, what are the models and tools that facilitate research.
  • Measurement and metrics: measurement required to understand performance and optimization of cybersecurity systems and defining appropriate metrics, i.e., valid metrics, test cases, and benchmarks; effectiveness of metrics in evaluation, impact of measurement on evaluation.
  • Data sets: collection, analysis, and interpretation of data for cybersecurity, i.e., what makes good data sets and how do we compare data sets, methods to collect, generate, or derive new ones, historical impact of a dataset.
  • Experimental infrastructure: testbeds, simulations, emulations, and virtualizations, i.e., designing, orchestrating, and deploying testbeds, tools for improving testbed operation and maintenance, usage, and impact studies of experimentation infrastructure.
  • Education: surveys, tools, and techniques for cybersecurity education and training, i.e., evaluating and presenting educational approaches to cybersecurity, approaches that leverage datasets, utilize testbeds, apply experiential learning principles, or promote awareness of research methods and sound measurement approaches.
  • High-consequence cyber systems: rigorous experimental methodologies, i.e., appropriate design of experiments, parameter sampling strategies, quantifying uncertainties with confidence intervals, ensuring reproducibility, and validating models.
  • Ethics in cybersecurity: tussle between security and privacy, i.e., experiences balancing stakeholder considerations, participant privacy, frameworks for evaluating the ethics of cybersecurity experiments, and illustrative experiment samples for ethical conduct that upholds the code outlined in [1].
  • Evaluating real-world security controls: measurements of deployed security frameworks, i.e., evaluation methodologies for real-world security performance, user-related characteristics (behavior, demographics) modeling, cybersecurity, and social media.

Proceedings

CSET 2026 proceedings will be published through IEEE Computer Society.

Sharing Research Artifacts

CSET is focused on advancing the state-of-the-art and the state-of-the-practice in cybersecurity in practice, research, and education. Authors are strongly encouraged to share artifacts whenever possible in order to enable transparency (e.g., analysis or validation) and to facilitate the accumulation of resources for the cybersecurity community. Sharing will be taken into account by reviewers; however, it is not a requirement for acceptance. If the research presented in a paper produced research artifacts (e.g., code, data), authors should include in the paper an artifact-sharing statement describing whether some or all of the artifacts will be made available to the community, and if so, how they will be shared (e.g., website). This statement should be present during both submission and in the final version of the paper.

Submission Length Options

Page length limits vary by the type of submission:

  • Short Paper: Submissions must be no longer than four pages. Short papers should provide enough context and background for the reader to understand the contribution. We envision that short papers will be preliminary work or extended work papers, but this is not a hard requirement.
  • Long Paper: Submissions must be no longer than eight pages. We envision that long papers will be the more traditional type of CSET research paper, but this is not a hard requirement.

Submissions should use the IEEE conference template. The page length limits include the space allowed for all tables and figures. References, LLM Usage Statement, and appendices are excluded from page limits; reviewers are not required to view the appendices when evaluating submissions.

Usage of LLMs

Authors may use large language models (LLMs) and other generative AI tools when preparing their submissions. However, all use must be disclosed, and authors bear full responsibility for the correctness, originality, and integrity of their work. Undisclosed or irresponsible use of LLMs is grounds for desk rejection. If LLMs are used, authors must include a separate, clearly marked section titled "LLM Usage Statement" at the end of the paper. This section does not count towards the page limit.

We ask authors to adhere to three key criteria regarding the use of LLMs:

Originality: Authors are responsible for the entire content of their paper, including all text, tables, and figures. While tools may be used for writing, all content must be accurate and original to ensure the integrity of the research process. If LLMs were used for editorial purposes, authors must state: "LLMs were used for editorial purposes in this manuscript, and all outputs were inspected by the authors to ensure accuracy and originality."

Transparency: Authors must carefully consider the implications of using LLMs in their research. If LLMs are integral to the methodology, their use must be described explicitly. Any approach or method generated by an LLM must be validated by the authors. Authors must also discuss limitations introduced by the use of LLMs, for example, challenges in reproducibility when the underlying model is not openly available.

Responsibility: Authors must ensure that LLMs and other generative AI tools are developed and used responsibly. Data collection for training and inference must respect ethical considerations such as consent, data ownership, bias, and intellectual property rights. Authors are also encouraged to be mindful of the environmental footprint of their experiments and to consider it in relation to their research goals and methodology.

Failure to comply with these requirements is grounds for desk rejection without further review. As generative AI technology evolves rapidly, authors are encouraged to contact the PC chairs if they have questions about these guidelines or their application. Please refer to the conference AI Policy on Usage of LLMs at: https://www.acsac.org/2026/submissions/ai/.

Submission Types

During the submission process, authors will be asked to categorize their submission as either a research paper, position paper, experience paper, preliminary work paper, or extended work paper. While reviewers can see this categorization, the review process for all submission types will be identical. For all submissions, the program committee will give greater weight to papers that lend themselves to interactive discussion among workshop attendees.

  • Research Paper: make a novel contribution in line with one of the topics of interest.
  • Position Paper: discuss new or provocative ideas of interest to the CSET community.
  • Experience Paper: describe activities and recount lessons learned (e.g., from experiments or deployments) that might help researchers in the future.
  • Preliminary Work Paper: describe early results from interesting and new ideas. We anticipate that such works-in-progress papers may eventually be extended as full papers for publication at a conference.
  • Extended Work Paper: expand upon unpublished aspects of a previous work (published in any venue). We welcome papers that provide a compelling addition to a previously developed approach, method, tool, measurement, benchmark, data set, simulation/emulation, evaluation results, etc. Note that submissions in this category can extend the work of others (e.g., using a previously published tool in a new way). Submissions in this category should clearly explain which sections are novel compared to prior work.

Anonymization and the Review Process

The review process will be double-blind; all submissions should be anonymized so as not to reveal the authors’ names or affiliations during the review process. Papers that are not properly anonymised or do not follow the IEEE Conference Template will be desk-rejected.

Ethics & Human Subjects

Submissions that have potential ethical implications must include a section on ethics. Any submission that introduces research or results related to human subjects (including their data) must include a statement on its review by the appropriate institutional review boards.

Respectful and Inclusive Terminology

Please refer to the ACM’s list of charged terminology and use alternatives in your submissions.

Submitting

All anonymized papers must be submitted in PDF format via the submission system https://cset.submit.acsac.org/. Please do not email submissions.

Submissions must be generated using the double-column IEEE format (see template available at https://www.ieee.org/conferences/publishing/templates.html). LaTeX submissions must use the IEEEtran.cls version 1.8b template with the \documentclass[conference,compsoc]{IEEEtran} documentclass option. Papers should be formatted for US letter (not A4).

Attending the Workshop

If you are interested in attending, please check off the appropriate box on the conference registration form and add in the CSET Workshop fee.

For accepted papers, at least one author must register and attend. If needed, please plan ahead to allow sufficient time for your visa request to be processed. To start the process, please read the information found on the conference website at https://www.acsac.org/visa.

Further Notes

At least one author from every accepted paper must register for the workshop and present the paper. Fraud and dishonesty are prohibited, including: simultaneous submission of the same work to multiple venues, submission of previously published work, and plagiarism. Papers accompanied by nondisclosure agreement forms will not be considered.

Committees

Please see the Committees page.

Sponsored by

-->

CSET'26

Designed by BootstrapMade