Editor's Picks

Best Talks at 34th USENIX Security Symposium (USENIX Security '25)

Hand-picked from in-depth reviewer verdicts — the top 12 talks from this conference. Skip the noise, find the signal.

← All talks at 34th USENIX Security Symposium (USENIX Security '25)

  1. 1

    On the Proactive Generation of Unsafe Images From Text-To-Image Models Using Benign Prompts

    Yixin Wu

    This distinguished paper from USENIX Security 2025 presents a novel, scalable methodology to identify compromised SSH (Secure Shell) servers across the Internet. Authored by researchers from the Max Planck Institute for Informatics and Delft University of Technology, the work…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway MUST SEE ★★★★★
  2. 2

    Beyond Exploit Scanning: A Functional Change-Driven Approach to Remote Software Version Identification

    Jinsong Chen

    This groundbreaking paper from ETH Zurich introduces **Branch Predictor Race Conditions (BPRC)**, a novel class of microarchitectural vulnerabilities that undermine hardware-enforced mitigations against **Spectre v2** attacks on all recent Intel CPUs. The research, which earned…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway MUST SEE ★★★★★
  3. 3

    DeepFold: Efficient Multilinear Polynomial Commitment from Reed-Solomon Code and Its Application to Zero-knowledge Proofs

    Yanpei Guo

    This article delves into the critical security vulnerabilities discovered in **integration platforms** that leverage **OAuth 2.0** for **account linking**. The paper, authored by Kaixuan Luo and Xianbo Wang from The Chinese University of Hong Kong, alongside Pui Ho Adonis Fung…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway MUST SEE ★★★★★
  4. 4

    Narrowbeer: A Practical Replay Attack Against the Widevine DRM

    Florian Roudot

    The proliferation of Large Language Models (LLMs) into mainstream applications has introduced a new frontier for cybersecurity research, particularly concerning their inherent vulnerabilities. This paper introduces **LLMmap**, a groundbreaking first-generation active…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  5. 5

    Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis

    Yuxi Ling

    This technical article delves into the research presented in "Narrowbeer: A Practical Replay Attack Against the Widevine DRM," a paper by Florian Roudot and Mohamed Sabt from IRISA, Univ Rennes, and CNRS, presented at USENIX Security. The work investigates the security of…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  6. 6

    LLMxCPG: Context-Aware Vulnerability Detection Through Code Property Graph-Guided Large Language Models

    Ahmed Lekssays

    The ubiquitous ZIP file format, a foundational component for everything from office documents and Android applications to Java archives and browser extensions, harbors a pervasive and under-explored security vulnerability: **semantic gaps** between its numerous parsing…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  7. 7

    Deanonymizing Ethereum Validators: The P2P Network Has a Privacy Issue

    Lioba Heimbach

    Intel Trust Domain Extensions (**TDX**) represent the second generation of Trusted Execution Environments (TEEs), designed to protect entire virtual machines (VMs), known as trust domains (TDs), from a potentially malicious host system. While TDX aims to provide robust memory…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  8. 8

    "I'm regretting that I hit run": In-situ Assessment of Potential Malware

    Brandon Lit

    This article delves into "FLOP: Breaking the Apple M3 CPU via False Load Output Predictions," a significant research paper presented at USENIX Security. The work, authored by Jason Kim, Jalen Chuang, and Daniel Genkin from Georgia Tech, and Yuval Yarom from Ruhr University…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  9. 9

    Whispering Under the Eaves: Protecting User Privacy Against Commercial and LLM-powered Automatic Speech Recognition Systems

    Weifei Jin

    This groundbreaking research introduces **nRootTag**, a novel attack method that weaponizes Apple's ubiquitous Find My network to maliciously track Bluetooth-enabled devices, transforming them into de facto **AirTags** without requiring root privileges. Presented by researchers…

    0 Dr. Zero STRONG ACCEPT ★★★★☆ H Heather Calloway MUST SEE ★★★★★
  10. 10

    AudioMarkNet: Audio Watermarking for Deepfake Speech Detection

    Wei Zong

    This paper introduces **ChoiceJacking**, a novel family of USB-based attacks that effectively bypass the existing mitigations against **JuiceJacking** attacks, which were discovered about a decade ago. JuiceJacking exploits the dual-purpose nature of mobile device USB ports…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  11. 11

    How Transparent is Usable Privacy and Security Research? A Meta-Study on Current Research Transparency Practices

    Jan H. Klemmer

    The "ECC.fail" paper presents a groundbreaking study on the persistent hardware vulnerability known as **Rowhammer**, specifically targeting server platforms equipped with **DDR4 ECC memory**. Historically, Rowhammer attacks, which allow an attacker to flip bits in memory…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  12. 12

    My ZIP isn't your ZIP: Identifying and Exploiting Semantic Gaps Between ZIP Parsers

    Yufan You

    In this compelling talk from USENIX Security, Yufan You presented groundbreaking research on **semantic gaps** in **ZIP file format** parsing, revealing a widespread and critical vulnerability across numerous applications and systems. The core premise is deceptively simple yet…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway SOLID ★★★☆☆