Host University
Indian Institute of Technology, Kanpur

Applied Research Competition 2026

Base Competition
Year
2026
Timeline
Items
Submission Deadline
AoE
Submit your paper by the end of day, Anytime on Earth (AoE).
Reviews complete
Program committee reviews conclude.
Finalists notified
All authors, finalists and non-finalists, receive their decision by email.
Travel confirmed
Transportation to and from NYU and accommodation throughout the competition are confirmed for the ten invited student presenters.
In-person presentations
EST
Ten student authors present before a panel of industry judges and academics at NYU Brooklyn.
Best Paper Awards
EST
Best Paper Awards for technical and social impact are announced at the closing ceremony.
Region
Note
Center for Cybersecurity
370 Jay Street, 10th Floor
Brooklyn, NY

Wed, Nov 11: Arrive in NYC.
Thu, Nov 12: Attend NYU events, talks, and career fair; poster setup at 4 PM.
Fri, Nov 13: Poster setup before 9 AM; session begins at 9 AM; judges arrive at 12 PM; judging runs until 3 PM; take down posters at 5 PM.
Sat, Nov 14: Best Paper Awards announced at the 9 AM closing ceremony.

Only in-person presentations are allowed. Bring a 36 × 24 inch landscape, not portrait, printed poster; use graphics and avoid too many words. Judges evaluate technical impact and social impact. No computer, demos, or slides are needed.
Eligibility
  1. The paper concerns the design, application, implementation, or exploitation of security technologies.
  2. The research is already used in practice or has clear potential to be used in practice.
  3. The paper was published or camera-ready between September 1, 2025 and July 31, 2026 at IEEE Security & Privacy 2026, USENIX Security 2026, SOUPS 2026, ACM CCS 2025, NDSS 2026, IMC 2025, CSCW 2025, PETS 2026, IMWUT/UbiComp 2025, or ACM CHI 2026. Work published elsewhere may also be submitted when it meets the remaining criteria, though the listed venues may receive preference in the event of a tie.
  4. At least one author is a student enrolled at a university in Canada, Mexico, or the United States as of November 1, 2026, and is available to present the work in person at NYU on November 13, 2026.
Judging Criteria

Practitioners, academics, and industry experts assess the real-world impact of eligible submissions:

  1. Technical Impact
  2. Social Impact
Submission Guidelines

Submit one PDF of the published or camera-ready paper, retaining the original publication venue template. Review is single-blind: reviewers can see author names; authors do not see reviewer names.

Not running this year in (regions)
Organizers & Judges
Rameen Mahmood
Organizer
Center for Cybersecurity, NYU
PhD Student
Region
Grace McGrath
Organizer
Center for Cybersecurity, NYU
PhD Student
Region
Danny Huang
Organizer
Center for Cybersecurity, NYU
Faculty
Region

AI Hardware Attack Challenge 2026

Base Competition
Year
2026
Timeline
Items
Preliminary Competition Phase Release
EST
Preliminary Phase Due
EST
Finalists Announced
EST
Final Challenge Released @ CSAW
EST
Final Challenge Due & Teams Present
EST
Eligibility

This year's competition is running only in the US-Canada region. Teams must consist of currently-enrolled students at universities.

Challenge Details

In this year's competition, teams are challenged to use generative AI to both insert hardware Trojans into FPGA-targeted hardware designs as well as demonstrate exploits for these new Trojans. The target of this competition is the Hackster board from Calico Computer, an education-focused device which includes an application microprocessor, an FPGA, and additional peripherals aimed at hardware security education.

Teams will need to reverse-engineer the FPGA bitstream provided for the Hackster board and use that, along with basic integration documentation and tests, to determine how the hardware design works and add a Trojan to it.

A preliminary qualifying round of the competition will take place across two weeks, from 18 September to 2 October. Finalists will be selected by 4 October. These teams will be brought to New York to attend CSAW in-person. The final challenge will be given at CSAW and will take place over 24 hours, where teams will be given access to the physical Hackster boards to both demonstrate their preliminary Trojans and complete the final challenge on the hardware.

Rules

All hardware and exploits must be created by generative AI. Deterministic tools may be used alongside the AI, but no human may write the actual hardware design for the Trojan or exploit demonstration.

Judging Criteria

A full judging rubric will be found on the competition's GitHub repo once the challenge has formally released.

Registration Guidelines

Teams may consist of the following:

  • Up to 4 students
  • One advisor (can be a graduate student advising undergraduates, or a professor advising graduate students)

Register here.

Resources
Awards
1st
Hackster Board
2nd
Hackster Board
3rd
Hackster Board
Not running this year in (regions)
Organizers & Judges
Jason Blocklove
Organizer
NYU
Competition Designer and Organizer
Email
jason.blocklove@nyu.edu
Region
Jason Blocklove

Cyber Reasoning Challenge

Autonomous vulnerability discovery and repair
Description

The Cyber Reasoning Challenge (CRC) is an AIxCC-style competition in which student teams design a cyber reasoning system (CRS) to find and patch vulnerabilities in real software targets. Unlike a traditional CTF, teams do not solve challenges by hand. Their CRS must autonomously discover a crashing proof of vulnerability and produce a patch that compiles, preserves the program’s intended behavior, and actually fixes the bug rather than hiding a single crash.

To keep the event focused on system design, we have used the evaluation infrastructure from Team Atlanta, the first-place team in DARPA’s AI Cyber Challenge. Teams therefore do not need to build the evaluation pipeline, scoring, or target-harnessing stack from scratch. They can spend their time on the CRS itself: how it searches, localizes, and repairs bugs.

We also provide a starter kit with two working CRS baseline (codex and claude code). Teams can run it out of the box to understand the workflow, then replace or extend the finder and patcher with their own components. 

Cyber Reasoning Challenge logo
Short Name
CRC

Applied Research Competition 2026

Base Competition
Year
2026
Timeline
Items
Paper Submission Deadline
EST
Finalist Notification
EST
Finals Starts
EST
Finals End
EST
Region
Not running this year in (regions)
Organizers & Judges
Christina Pöpper
Organizer
Email
christina.poepper@nyu.edu
Region
Christina Pöpper
Ala Darabseh
Organizer
Email
ala.darabseh@nyu.edu
Region
Ala Darabseh
Salim Chouaki
Organizer
Email
sc11670@nyu.edu
Region
Salim Chouaki

Capture the Flag 2025

Base Competition
Year
2025
Timeline
Items
48-hour Qualifying round begins
UTC
ONLINE
Qualifying Round Ends
UTC
ONLINE
Finalist Notification
EST
End of September
36-hour Final Round Begins
EST
Hybrid mode, region dependent
Final Round Ends
EST
Note
All times listed in UTC or EST as noted per event. Final Round format (online vs in-person) depends on region.
Eligibility

CSAW CTF is designed for students who are trying to break into the field of security, as well as advanced students and industry professionals who want to practice their skills.

Open to all skill levels. Teams compete within their respective global regions.

Challenge Details

CSAW CTF is one of the oldest and biggest CTFs with 1216 teams with 1+ points in 2021. Designed as an entry-level, jeopardy-style CTF, this competition is for students who are trying to break into the field of security, as well as for advanced students and industry professionals who want to practice their skills.

CSAW CTF occurs over two rounds: a 48-hour Qualifying Round in September and a 36-hour Final Round in November.

Rules

Full detailed rules are available here.

Challenge writers who are associated with or alumni of active teams have recused themselves from playing in or supporting teams playing in CSAW CTF.

Judging Criteria

Jeopardy-style scoring. Teams earn points by solving challenges across standard CTF categories. The team with the most points at the end of each round advances. 

Top teams from the Qualifying Round are invited to the Final Round.

Registration Guidelines

Register via the CTF platform. Teams compete within their respective global regions. 

Contact csawctf@osiris.cyber.nyu.edu for registration questions.

Submission Guidelines

Challenges are submitted through the CTF platform during the competition window. Flags must be submitted in the correct format as specified per challenge. All submissions are final once entered.

Awards
1st
US-Canada: Trophy + recognition; MENA: $1000 USD; India: 30,000 INR; Europe: €500; Mexico: Ethical Hacking Essentials Certificate (EC-Council)
2nd
US-Canada: Recognition; MENA: $500 USD; India: 15,000 INR; Europe: €300; Mexico: Learning Kali Linux Book
3rd
MENA: $250 USD; India: 8,000 INR; Europe: €200; Mexico: 1TB HDD
Prize amounts vary by region.
MENA prizes: 1st $1000, 2nd $500 USD.
India prizes: 1st 30,000 INR, 2nd 15,000 INR, 3rd 8,000 INR.
Europe prizes: 1st €500, 2nd €300, 3rd €200.
Winners
1st
University of Hawaii, Georgia Institute of Technology, Rochester Institute of Technology
Nathan Wong
Andrew Effenhauser
Allen Chang
Tanush Madanbhavi
2nd
Massachusetts Institute of Technology, Arizona State University, Northeastern University
Audrey Dutcher
Jennifer Miller
Xenia Dragon
Emmie Lum
3rd
University of Washington, University of California, Diablo Valley College
Ani Balaji
Chara
Kroot
Cope
Organizers & Judges
NYU OSIRIS Lab
Organizer
New York University
Global Lead
Email
csawctf@osiris.cyber.nyu.edu
Logo of OSIRIS Lab

Applied Research Competition 2025

Base Competition
Year
2025
Timeline
Items
Paper Submission Deadline
EST
Finalist Notification
EST
Items
Paper Submission Deadline
EST
Finalist Notification
EST
Region
Organizers & Judges
Mayank Dhiman
Judge
Notion
Head of Security Engineering
Mayank Dhiman
Christopher Hilinski
Judge
TIAA
Katrina Mouquin
Judge
Akamai
Konstantin Lazarev
Judge
GrayNoise
Ronald Jones
Judge
DTCC
Stephen Tong
Judge
Zellic
Stephen Tong
Yann Loisel
Judge
SiFive
Principal Security Architect
Region
Jeremy Dubeuf
Judge
ARM
Region
Victor Lomne
Judge
NinjaLab
Co-founder & Security Expert
Region
Guillaume Bouffard
Judge
National Cybersecurity Agency of France (ANSSI)
Embedded Systems Security Researcher
Region
Jean-Baptiste Bedrune
Judge
Ledger
Head of Security Research
Region
Bernard Kasser
Judge
STMicroelectronics
Region
Laurent Pion
Judge
Worldline France
Region

Agentic Automated CTF 2025

Base Competition
Year
2025
Timeline
Items
Start Date
EST
Finalists Cut off
EST
Finalists Announcement
EST
Note
Monthly leaderboard update is the 30th of every month.
Challenge Details

This competition uses the NYU CTF Lite, a streamlined benchmark of 50 challenges spanning six categories, adapted from the original NYU CTF Bench. To support easy integration with LLM-based agents, all challenges are provided in the standardized NYU CTF Bench format, fully compatible with the nyuctf pypi package for loading and interacting with autonomous agent frameworks.

While the true flags are included in accompanying metadata .json files, agents must independently solve each challenge and verify that the extracted flag matches the ground truth—no hardcoded answers allowed. A baseline agent system is provided in this repository, allowing competitors to build upon it with their own enhancements.

To request an API Key, please email nyuctf@gmail.com with all team members’ name, email and affiliation.

Rules
  • Team Participation: Teams of up to 3 people are allowed. Individual participation is also possible, but teamwork is highly recommended.
  • ​Agentic Framework: Participants are encouraged to analyze the general patterns of the challenges to optimize their agentic systems to make it specific for CTF automation; however, the final solutions must be generated entirely by an autonomous, LLM-powered agent, with no human-in-the-loop during execution. Participants are allowed and encouraged to use any techniques applicable to building effective agentic AI systems, including but not limited to prompt engineering, multi-agent, tool-augmented reasoning, and retrieval-augmented generation (RAG). These techniques may be applied broadly or tailored to specific challenge categories, but must remain generalizable—challenge-specific hints or hardcoded solutions are strictly prohibited. All the prompts used for challenge solutions must not include direct solutions from human players from any source; each solution that violates this rule will not be counted as solved. Participants must supply their own API tokens or model deployments for use within their autonomous frameworks. Any agentic framework may be used—including doing enhancements on open-source agentic frameworks, or custom-building systems from scratch. These frameworks must support full automation and may integrate real-time or pre-installed cybersecurity tools such as apk2jar, apktool, Ghidra, Hopper, Burp Suite, and Wireshark. All aspects of model selection, tool configuration, and system design are open-ended and left to the discretion of the participants.
  • Model Requirements: Participants are free to use any language model architecture for their agentic systems, including models accessed via API service providers (e.g., OpenAI, Anthropic), self-hosted open-source models (e.g., LLaMA, Qwen), or custom fine-tuned variants. There are no restrictions on model size, origin, or hosting setup. However, all models must be free of contamination, meaning they must not have been trained on or contain leaked solutions or flags from the competition dataset. Any evidence of flag leakage or training contamination will result in disqualification.
  • Evaluation: will be based entirely on the number of challenges successfully solved by the autonomous agent. Each correctly solved challenge contributes to the team’s final score, with no partial credit. The accuracy of the extracted flag, as verified against the ground truth, is the sole criterion for success.
  • Submissions: For each solved CTF challenge, participants must submit the full trajectory generated by their autonomous agent, including the agent’s thoughts, actions, observations, and the final flag, in a machine-loadable format (e.g., JSON or structured log). The extracted flag must exactly match the ground-truth flag provided in the metadata. Manual editing or tampering of the agent outputs is strictly prohibited and will result in disqualification. In addition, participants must provide a well-documented Git repository containing the complete codebase of their agentic framework. Open-source is encouraged, but a private repository shared with the organizer is also doable. This repository should include all dependencies, configurations, and tools used, along with detailed technical documentation outlining the participant’s approach—such as prompting techniques, model usage, agent architecture, tool integration, and any other implementation details. If a custom or fine-tuned model is used, training code and model weights should also be provided for validation.
  • API Keys and Data: All competitors may request API keys from OpenAI, Anthropic, and Gemini from the organizer, with an initial combined budget of up to $100 in credits every month during the competition. This budget may be extended as needed. Requesting API keys will automatically register participants for the competition. All competitors are required to open-source the code and data used in their submissions.
Judging Criteria

100 points in total, the final grade would be the weighted sum of all the judging criteria

  • Challenge Solved (50%): The number of CTF challenges solved by the participants, based on the score of each puzzle.​
  • Creativity (30%): The methods used for finding the vulnerabilities and solving the challenges. Adding innovative features to the framework, and trying unique approaches are all vectors for evaluation. Ultimately, be sure to include a summary about how the puzzle was solved by the LLM.  Using your own agent instead of the agent provided in the competition will give contestants a bonus under that judging criteria.
  • Presentation Quality (20% – 10% for writeups, 10% for final presentation): The quality of the final presentation. It should use the same approach that was suggested by the generative large language model you used. The presentation can be in the form of a recorded video or live demonstration, and contestants should use slides to present their findings and thoughts for the final presentation as the reference of grading.
  • Penalty items (deduction of 10% of the challenge score for each rule violation): The final solution must be provided by the automation framework with prompt engineering techniques, even if the participants come up with the proper solutions by themselves. Penalty items will be applied if the final solution does not come from the generative AI, even if participants find the correct solution independently. No points will be awarded for this challenge when participants use online writeups and source code to form or train the agent.
Registration Guidelines

This competition is open to the public and will run until all the 50 NYU CTF challenges are solved. 

No registration is required. The first submission with a valid and verifiable team information including team members’ name and contact email will be registered for the competition.

Submission Guidelines

For each solved CTF challenge, participants must submit the full trajectory generated by their autonomous agent, including the agent’s thoughts, actions, observations, and the final flag, in a machine-loadable format (e.g., JSON or structured log). The extracted flag must exactly match the ground-truth flag provided in the metadata. Manual editing or tampering of the agent outputs is strictly prohibited and will result in disqualification. In addition, participants must provide a well-documented Git repository containing the complete codebase of their agentic framework. Open-source is encouraged, but a private repository shared with the organizer is also doable. This repository should include all dependencies, configurations, and tools used, along with detailed technical documentation outlining the participant’s approach—such as prompting techniques, model usage, agent architecture, tool integration, and any other implementation details. If a custom or fine-tuned model is used, training code and model weights should also be provided for validation.

Winners
1st
Rochester Institute of Technology
Kamdin Bembry
Christopher Newport University
Daniel Mayer
University of Central Florida
George Filippov
New York University
Zander Chen
New York University
Wentao He
2nd
New York University
Junjie Mai
Organizers & Judges
Ramesh Karri
Organizer
NYU Center for Cybersecurity
Co-chair
Ramesh Karri
Brendan Dolan-Gavitt
Organizer
NYU Osiris Lab
Faculty Advisor
Brendan Dolan-Gavitt
Venkata Sai Charan
Organizer
Venkata Sai Charan
Nanda Rani
Organizer
Nanda Rani
Kim Milner
Organizer
Kim Milner
Haoran Xi
Organizer
Haoran Xi
Minghao Shao
Organizer
NYU Tandon
Research Assistant
Minghao Shao
Abdul Basit
Organizer
Abdul Basit
Meet Udeshi
Organizer
Meet Udeshi

AI Hardware Attack Challenge 2025

Base Competition
Year
2025
Timeline
Items
First challenge given
EST
Second challenge given
EST
All challenges due
EST
Finalists announced
EST
​Final challenge given
EST
Winners announced
EST
Note
Note: The challenges do not need to be completed within the month they are given, this is just when we are releasing them. We will also update a monthly leaderboard in this repository as the competition progresses. All teams will have up until the 1 October deadline to submit their challenges to earn points and be considered as a finalist team.
Challenge Details

Each challenge has its own details for the competition. Those details are given on the GitHub for this competition here.

Challenge 1: The first challenges will focus on leveraging generative AI to add hardware Trojans to an AES core. Three difficulties of challenge will be provided: easy, medium, and hard, with each worth increasing points. Teams can submit all three difficulties of challenge to earn the most points.

Judging Criteria

Each challenge will have its own rubric regarding how points can be awarded. Challenges will have their base functionality automatically graded, and manual judging will take place over the following days to ensure all rules were followed, as well as to award additional points for completing further objectives. These extra points will be awarded for each competition for things like “most creative use of AI”. Please refer to each challenge's rubric for how this will be done.

Each submission must also be fully open source, guidelines for this are here.

Registration Guidelines

Please fill out the registration Google Form to register your team. Teams must consist of:

  • Up to 4 student team members
  • One team advisor/mentor
Resources
Awards
1st
ChipWhisperer Side-Channel and Glitching Starter Pack*
3rd
Space on a future Tiny Tapeout
* Can also request space on Tiny Tapeout, amount of space and PCB quantity must be approximately equal to the original prize cost
Winners
1st
Indian Institute of Technology, Kanpur
Soham Panchal
Ananthan R
Jugal Pahuja
Ramya Rasika S R
2nd
University of New South Wales
Annie Qiu
Danny Tan
Xinzhang Chen
Zhongtai Zhang
3rd
New Mexico State University
Md Omar Faruque
Rensselaer Polytechnic Institute & University of Texas
Samit Shahnawaz Miftah
Amisha Srivastava
Swastik Bimal Bhattacharya
Sanjay Das
Hanpei Liu
Organizers & Judges
Jason Blocklove
Organizer
NYU
Global Student Lead
Jason Blocklove

Embedded Security Challenge

Description

ESC is an educational, research-oriented tournament aimed at hacking into the hardware of embedded systems. First run in 2008, it is the oldest hardware security competition in the world, and 2025 represents ESC's 18-year anniversary.

Past ESC competitions have focused on data exfiltration attacks against IoT devices, hacking the firmware of a RISC-V Wi-Fi access point and executing acoustic side channel on 3D printing devices.​

The 2025 ESC competition centers on side channel attacks (SCAs) and fault injection attacks (FIAs), techniques used to extract sensitive data from infrastructure-critical cyber physical systems. Participants will engage in a series of challenges that involve designing and executing these attacks, as well as investigating methods to defend against them. The ChipWhisperer Nano will serve as the target hardware platform, providing teams with a safe and controlled setting to showcase their expertise in launching and mitigating these advanced attack strategies.

The event comprises a qualification and a final/competition phase where teams will be able to explore several variations of fault injections and side channels, as well as suggest mitigations for the discovered exploits.

Embedded Security Challenge

Capture the Flag

Description

CSAW CTF is one of the oldest and biggest CTFs with 1216 teams with 1+ points in 2021. Designed as an entry-level, jeopardy-style CTF, this competition is for students who are trying to break into the field of security, as well as for advanced students and industry professionals who want to practice their skills.

CSAW CTF occurs over two rounds: a Qualifying Round in September and a Final Round in November. 

Capture the Flag