Host University
NYU Abu Dhabi

Cyber Reasoning Challenge 2026

Base Competition
Year
2026
Region
Eligibility

Current college or university students may compete. Teams consist of one to four students and may list one faculty or staff advisor. Each participant may compete on only one team.

CRC 2026 is open in the US-Canada and MENA regions. The competition is online.

Challenge Details

The Cyber Reasoning Challenge (CRC) is an AIxCC-style competition in which student teams design a cyber reasoning system (CRS) to find and patch vulnerabilities in real software targets. Unlike a traditional CTF, teams do not solve challenges by hand. Their CRS must autonomously discover a crashing proof of vulnerability and produce a patch that compiles, preserves the program’s intended behavior, and actually fixes the bug rather than hiding a single crash.

To keep the event focused on system design, we have used the evaluation infrastructure from Team Atlanta, the first-place team in DARPA’s AI Cyber Challenge. Teams therefore do not need to build the evaluation pipeline, scoring, or target-harnessing stack from scratch. They can spend their time on the CRS itself: how it searches, localizes, and repairs bugs.

We also provide a starter kit with two working CRS baseline (codex and claude code). Teams can run it out of the box to understand the workflow, then replace or extend the finder and patcher with their own components. 

Challenges use two scan modes. In a delta scan, the vulnerable change is provided as a diff. In a full scan, the complete vulnerable project is provided without a localization hint. The inaugural event focuses on C and C++ targets.

Rules
  • Teams consist of one to four current college or university students and may list one advisor. A participant may belong to only one team.
  • After a scored run begins, discovery and patching must be performed by the team’s submitted CRS. Human intervention is not allowed.
  • Teams may use fuzzers, static or dynamic analysis, language models, agent systems, and other legally obtained tools, and must follow the licenses and terms of those tools.
  • Use competition targets and infrastructure only for CRC@CSAW participation, research, and education. Do not attack competition infrastructure, other teams, external services, or systems outside the released challenge environment.
  • Submit only artifacts produced for the registered team. Do not include credentials, private keys, tokens, or personal data.
  • Do not disable the harness, tests, build system, or vulnerable feature to obtain a passing result. 
  • All participants must follow the CSAW Code of Conduct.
  • Organizer verification is authoritative. Organizers may reject a submission or disqualify a team for violating these rules.
Judging Criteria

Qualification and finals are points-based. Organizers verify submitted proofs of vulnerability and patches.

A proof receives credit when it crashes the vulnerable build, remains clean on the organizer’s corrected build, and matches the intended crash signature.

A patch receives credit only when it applies and compiles, passes the project’s functional tests, and actually fixes the bug.

The five highest-scoring teams provisionally qualify, subject to an integrity and reproducibility audit of the submitted system and artifacts. Organizer verification is the final authority. Tie-break details will be announced with the qualification materials.

Registration Guidelines

Register one response per team before the registration deadline. The team lead will receive official competition communications.

Registration form: https://docs.google.com/forms/d/e/1FAIpQLScyYxAInuka-A1ehkU9fKZ57NKgpFvhjLEDLJNV4oaBQEQFZg/viewform

After registering, you can join the CRC@CSAW Discord or watch the GitHub repository for announcements, starter-kit updates, and challenge releases.

Submission Guidelines

During qualification, each team runs its CRS on the official evaluation pipeline. After the run finishes, apply the official cleaning script so rebuildable work directories are removed, then upload the remaining result artifacts before the 48-hour round ends.

The cleaned package must include the official submitted proofs (hashed PoV blobs), the official submitted patches (one unified diff per discovered bug), run metadata, verification records, usage logs, and the agent trajectories needed for the integrity audit. Only proofs written to the official PoV submission output count. Internal candidates that were never submitted do not count. A patch is scored only for the bug that trial targeted.

Teams must also freeze a qualification branch of their CRS repository by the lock deadline. Later commits on that branch will be ignored. Organizers re-run that branch during the audit. The Google Drive folder and submission form will be released with the qualification challenges.

Timeline
Items
Team registration deadline
AoE
Qualification CRS lock
AoE
Qualification round begins
AoE
Qualification round ends
AoE
CRC@CSAW finals
AoE
Awards
1st
$500
2nd
$200
3rd
$100
Prize support is provided by Team Atlanta. We would also invite the top 3 teams to submit a paper describing their design and lessons learned from the challenge.
Organizers & Judges
Jiahao Yu
Organizer
NYU Abu Dhabi
Contest lead
Email
jy5951@nyu.edu
Photo of Jiahao Yu
Andrew Chin
Organizer
Georgia Institute of Technology, School of Cybersecurity and Privacy
Ph.D. student; Team Atlanta / OSS-CRS
Email
achin34@gatech.edu
Andrew Chin's Photo

Cyber Reasoning Challenge

Cyber Reasoning Challenge logo
Short Name
CRC
Autonomous vulnerability discovery and repair
Description

The Cyber Reasoning Challenge (CRC) is an AIxCC-style competition in which student teams design a cyber reasoning system (CRS) to find and patch vulnerabilities in real software targets. Unlike a traditional CTF, teams do not solve challenges by hand. Their CRS must autonomously discover a crashing proof of vulnerability and produce a patch that compiles, preserves the program’s intended behavior, and actually fixes the bug rather than hiding a single crash.

To keep the event focused on system design, we have used the evaluation infrastructure from Team Atlanta, the first-place team in DARPA’s AI Cyber Challenge. Teams therefore do not need to build the evaluation pipeline, scoring, or target-harnessing stack from scratch. They can spend their time on the CRS itself: how it searches, localizes, and repairs bugs.

We also provide a starter kit with two working CRS baseline (codex and claude code). Teams can run it out of the box to understand the workflow, then replace or extend the finder and patcher with their own components. 

Quantum Security Challenge

Quantum Security Challenge
Short Name
QSEC
Collapsing the wave function of quantum computing!
Description

Quantum computing is increasingly delivered as a hybrid computing service. A classical client builds a circuit; compiler and intermediate-representation layers rewrite it; a cloud scheduler selects physical resources; control and readout systems execute the job; and classical software interprets probabilistic results. Every transition creates a trust boundary.
Most quantum-security education focuses on the security implications and applications of quantum computing. QSec addresses the complementary question: how do we secure quantum computers, their architecture, and the quantum machine learning applications built on top of them?
In this competition, teams will attack and defend intentionally vulnerable quantum workflows. Challenges will cover cloud-job and result integrity, multi-tenant leakage, adversarial inputs, backdoors, model extraction, and attacks on aggregation and coordination mechanisms in quantum federated learning. The emphasis is on concrete security reasoning and reproducible exploits rather than on solving large quantum algorithms.
This track offers a hands-on and accessible approach to emerging quantum security challenges through practical attack-and-defense tasks with measurable outcomes.
 
A successful submission will include:

  1. Correct flags and checker receipts for each solved challenge.
  2. Reproducible exploit or defense artifacts, such as scripts, notebooks, patches, model files, or query logs.
  3. A concise write-up for each solved challenge explaining the threat model, vulnerability, exploit path, evidence, and recommended mitigation.
  4. A final presentation that synthesizes the team's approach, cross-layer insights, tool usage, and lessons learned.

Hack My Robot 2026

Base Competition
Year
2026
Region
Timeline
Items
Qualification Round and Registrations Start
EST
Region
Items
Qualification Round and Registrations Deadline
EST
Region
Items
Finalist Notification
EST
Region
Items
Finalists start receiving Robots
EST
Region
Items
Last date by which finalists receive Robots
EST
Region
Items
Final Demos and Presentations
EST
TBA
Organizers & Judges
Borja García de Soto
Organizer
Assistant Professor of Civil & Urban Engineering at NYUAD
Region
Borja García de Soto
Semih Sonkor
Organizer
Research Assistant at NYUAD
Email
semih.sonkor@nyu.edu
Region
Semih Sonkor
Samuel Prieto Ayllon
Organizer
Research Instrumentation Scientist
Region
Samuel Prieto Ayllon
Farshad Khorrami
Organizer
ECE Department
Professor at NYU Tandon
Region
Farshad Khorrami
Erika Parn
Organizer
Erika Parn
Aklile Mengiste
Organizer
Aklile Mengiste

Applied Research Competition 2026

Base Competition
Year
2026
Region
Timeline
Items
Paper Submission Deadline
EST
Finalist Notification
EST
Finals Starts
EST
Finals End
EST
Region
Organizers & Judges
Christina Pöpper
Organizer
Email
christina.poepper@nyu.edu
Region
Christina Pöpper
Ala Darabseh
Organizer
Email
ala.darabseh@nyu.edu
Region
Ala Darabseh
Salim Chouaki
Organizer
Email
sc11670@nyu.edu
Region
Salim Chouaki

Capture the Flag '25

Base Competition
Year
2025
Eligibility

CSAW CTF is designed for students who are trying to break into the field of security, as well as advanced students and industry professionals who want to practice their skills.

Open to all skill levels. Teams compete within their respective global regions.

Challenge Details

CSAW CTF is one of the oldest and biggest CTFs with 1216 teams with 1+ points in 2021. Designed as an entry-level, jeopardy-style CTF, this competition is for students who are trying to break into the field of security, as well as for advanced students and industry professionals who want to practice their skills.

CSAW CTF occurs over two rounds: a 48-hour Qualifying Round in September and a 36-hour Final Round in November.

Rules

Full detailed rules are available here.

Challenge writers who are associated with or alumni of active teams have recused themselves from playing in or supporting teams playing in CSAW CTF.

Judging Criteria

Jeopardy-style scoring. Teams earn points by solving challenges across standard CTF categories. The team with the most points at the end of each round advances. 

Top teams from the Qualifying Round are invited to the Final Round.

Registration Guidelines

Register via the CTF platform. Teams compete within their respective global regions. 

Contact csawctf@osiris.cyber.nyu.edu for registration questions.

Submission Guidelines

Challenges are submitted through the CTF platform during the competition window. Flags must be submitted in the correct format as specified per challenge. All submissions are final once entered.

Timeline
Items
48-hour Qualifying round begins
UTC
ONLINE
Qualifying Round Ends
UTC
ONLINE
Finalist Notification
EST
End of September
36-hour Final Round Begins
EST
Hybrid mode, region dependent
Final Round Ends
EST
Note
All times listed in UTC or EST as noted per event. Final Round format (online vs in-person) depends on region.
Awards
1st
US-Canada: Trophy + recognition; MENA: $1000 USD; India: 30,000 INR; Europe: €500; Mexico: Ethical Hacking Essentials Certificate (EC-Council)
2nd
US-Canada: Recognition; MENA: $500 USD; India: 15,000 INR; Europe: €300; Mexico: Learning Kali Linux Book
3rd
MENA: $250 USD; India: 8,000 INR; Europe: €200; Mexico: 1TB HDD
Prize amounts vary by region.
MENA prizes: 1st $1000, 2nd $500 USD.
India prizes: 1st 30,000 INR, 2nd 15,000 INR, 3rd 8,000 INR.
Europe prizes: 1st €500, 2nd €300, 3rd €200.
Winners
1st
University of Hawaii, Georgia Institute of Technology, Rochester Institute of Technology
Nathan Wong
Andrew Effenhauser
Allen Chang
Tanush Madanbhavi
2nd
Massachusetts Institute of Technology, Arizona State University, Northeastern University
Audrey Dutcher
Jennifer Miller
Xenia Dragon
Emmie Lum
3rd
University of Washington, University of California, Diablo Valley College
Ani Balaji
Chara
Kroot
Cope
Organizers & Judges
NYU OSIRIS Lab
Organizer
New York University
Global Lead
Email
csawctf@osiris.cyber.nyu.edu
Logo of OSIRIS Lab

BioHack 3D

Base Competition
Year
2025
Region
Eligibility

Undergraduates & Postgraduates. Teams of 2–4 members; cross-institution teams are allowed.

Challenge Details

An innovative hackathon at the frontier of AI, 3D printing, and biochip security. Participate in BioHack 3D and take on the challenge of designing AI-assisted authentication schemes for 3D-printed QR codes and melt-electrowritten fingerprints. Thanks to the stochastic nature of their fabrication, every print is physically unclonable, making them ideal for securing biochips and biomedical devices.

Your task:
- Work with datasets of fingerprints and QR codes provided by organizers
- Develop matching algorithms using minutiae point extraction, deep feature embeddings, and computer vision
- Propose robust authentication frameworks capable of resisting: counterfeiting, overbuilding, intellectual property theft and piracy, reverse engineering, and tampering

Rules

- Each team will compete from their own region — US/Canada teams compete within the US-Canada region only.
- Submissions must reflect your team's original creativity, insight, and technical effort.
- Finalist teams are responsible for arranging and covering their own transportation to the venue. Travel support will not be provided.
- Teams must submit a short technical report (template provided) and a 4–5 minute demo video.
- Preliminary teams must answer five open-ended questions covering: experience with 3D printing, AI/ML/DL expertise, and proposed attack/defense strategies.

Judging Criteria

- Strength of Authentication Frameworks – How well proposed schemes secure 3D-printed QR codes and melt-electrowritten fingerprints against counterfeiting, overbuilding, piracy, reverse engineering, and tampering.
- Stealth & Realism of Attack Strategies – Ingenuity in simulating potential threats and demonstrating adversarial compromise.
- AI Model Effectiveness – Performance of algorithms for minutiae extraction, matching, and verification (accuracy, precision, recall, robustness under noise/adversarial conditions).
- Novelty & Creativity – Originality in applying AI/ML/DL techniques to authentication and supply chain defense.
- Technical Report & Demo Video – Clarity, coherence, and justification of proposed methods supported by dataset evidence.
- Potential Real-World Impact – Practicality and scalability of solutions for securing future biochips and biomedical devices.

Registration Guidelines

- Eligibility: Undergraduates & Postgraduates
- Team Size: 2–4 members (cross-institution teams allowed)
- Selection: Rolling basis via registration form (qualifying round)
- Registration Deadline: October 12, 2025
- Note: Each team competes within their own region (US & Canada only for this region).

Submission Guidelines

Virtual Qualifying Round:
- Answer five open-ended questions demonstrating experience with 3D printing, AI/ML/DL expertise, and initial attack/defense ideas for biochip authentication.
- Top 5 teams advance to the in-person finals.

Final Round:
- Work with provided datasets of 3D-printed QR codes and melt-electrowritten fingerprints.
- Submit a short technical report (template provided by organizers).
- Submit a 4–5 minute demo video explaining your approach.
- Present live before a panel of global experts during CSAW'25.

Timeline
Items
Virtual Qualification Round Deadline
EST
Final Round (In-Person at NYU CCS)
EST
Results Announced & Prize Distribution
EST
Awards
1st
$500 Amazon Gift Card / Cash Prize
Winner of the US-Canada region
2nd
Certificate of Achievement
3rd
Certificate of Achievement
All finalists will receive the opportunity to visit NYU CCS during CSAW'25 to meet leading cybersecurity experts and experience other CSAW events. Certificates and plaques will be awarded to the top three spots.
Organizers & Judges
Ramesh Karri
Organizer
NYU Center for Cybersecurity (CCS)
Email
rk1330@nyu.edu
Region
Ramesh Karri
Navajit Singh Baban
Organizer
NYU Abu Dhabi Centre for Cybersecurity
Post Doc
Email
nsb359@nyu.edu
Region
Yong Rafael Song
Organizer
NYU Abu Dhabi
Program Head of Bioengineering; Professor of Mechanical Engineering and Bioengineering, NYU Abu Dhabi; Global Network Professor of Mechanical Engineering and Biomedical Engineering, NYU Tandon
Email
ys50@nyu.edu
Region
Yong Rafael Song
Dr. Urbi Chatterjee
Organizer
Department of Computer Science & Engineering, Indian Institute of Technology Kanpur
Assistant Professor
Email
urbic@cse.iitk.ac.in
Dr. Urbi Chatterjee

Applied Research Competition 2025

Base Competition
Year
2025
Region
Timeline
Items
Paper Submission Deadline
EST
Finalist Notification
EST
Items
Paper Submission Deadline
EST
Finalist Notification
EST
Region
Organizers & Judges
Mayank Dhiman
Judge
Notion
Head of Security Engineering
Mayank Dhiman
Christopher Hilinski
Judge
TIAA
Katrina Mouquin
Judge
Akamai
Konstantin Lazarev
Judge
GrayNoise
Ronald Jones
Judge
DTCC
Stephen Tong
Judge
Zellic
Stephen Tong
Yann Loisel
Judge
SiFive
Principal Security Architect
Region
Jeremy Dubeuf
Judge
ARM
Region
Victor Lomne
Judge
NinjaLab
Co-founder & Security Expert
Region
Guillaume Bouffard
Judge
National Cybersecurity Agency of France (ANSSI)
Embedded Systems Security Researcher
Region
Jean-Baptiste Bedrune
Judge
Ledger
Head of Security Research
Region
Bernard Kasser
Judge
STMicroelectronics
Region
Laurent Pion
Judge
Worldline France
Region

Agentic Automated CTF 2025

Base Competition
Year
2025
Challenge Details

This competition uses the NYU CTF Lite, a streamlined benchmark of 50 challenges spanning six categories, adapted from the original NYU CTF Bench. To support easy integration with LLM-based agents, all challenges are provided in the standardized NYU CTF Bench format, fully compatible with the nyuctf pypi package for loading and interacting with autonomous agent frameworks.

While the true flags are included in accompanying metadata .json files, agents must independently solve each challenge and verify that the extracted flag matches the ground truth—no hardcoded answers allowed. A baseline agent system is provided in this repository, allowing competitors to build upon it with their own enhancements.

To request an API Key, please email nyuctf@gmail.com with all team members’ name, email and affiliation.

Rules
  • Team Participation: Teams of up to 3 people are allowed. Individual participation is also possible, but teamwork is highly recommended.
  • ​Agentic Framework: Participants are encouraged to analyze the general patterns of the challenges to optimize their agentic systems to make it specific for CTF automation; however, the final solutions must be generated entirely by an autonomous, LLM-powered agent, with no human-in-the-loop during execution. Participants are allowed and encouraged to use any techniques applicable to building effective agentic AI systems, including but not limited to prompt engineering, multi-agent, tool-augmented reasoning, and retrieval-augmented generation (RAG). These techniques may be applied broadly or tailored to specific challenge categories, but must remain generalizable—challenge-specific hints or hardcoded solutions are strictly prohibited. All the prompts used for challenge solutions must not include direct solutions from human players from any source; each solution that violates this rule will not be counted as solved. Participants must supply their own API tokens or model deployments for use within their autonomous frameworks. Any agentic framework may be used—including doing enhancements on open-source agentic frameworks, or custom-building systems from scratch. These frameworks must support full automation and may integrate real-time or pre-installed cybersecurity tools such as apk2jar, apktool, Ghidra, Hopper, Burp Suite, and Wireshark. All aspects of model selection, tool configuration, and system design are open-ended and left to the discretion of the participants.
  • Model Requirements: Participants are free to use any language model architecture for their agentic systems, including models accessed via API service providers (e.g., OpenAI, Anthropic), self-hosted open-source models (e.g., LLaMA, Qwen), or custom fine-tuned variants. There are no restrictions on model size, origin, or hosting setup. However, all models must be free of contamination, meaning they must not have been trained on or contain leaked solutions or flags from the competition dataset. Any evidence of flag leakage or training contamination will result in disqualification.
  • Evaluation: will be based entirely on the number of challenges successfully solved by the autonomous agent. Each correctly solved challenge contributes to the team’s final score, with no partial credit. The accuracy of the extracted flag, as verified against the ground truth, is the sole criterion for success.
  • Submissions: For each solved CTF challenge, participants must submit the full trajectory generated by their autonomous agent, including the agent’s thoughts, actions, observations, and the final flag, in a machine-loadable format (e.g., JSON or structured log). The extracted flag must exactly match the ground-truth flag provided in the metadata. Manual editing or tampering of the agent outputs is strictly prohibited and will result in disqualification. In addition, participants must provide a well-documented Git repository containing the complete codebase of their agentic framework. Open-source is encouraged, but a private repository shared with the organizer is also doable. This repository should include all dependencies, configurations, and tools used, along with detailed technical documentation outlining the participant’s approach—such as prompting techniques, model usage, agent architecture, tool integration, and any other implementation details. If a custom or fine-tuned model is used, training code and model weights should also be provided for validation.
  • API Keys and Data: All competitors may request API keys from OpenAI, Anthropic, and Gemini from the organizer, with an initial combined budget of up to $100 in credits every month during the competition. This budget may be extended as needed. Requesting API keys will automatically register participants for the competition. All competitors are required to open-source the code and data used in their submissions.
Judging Criteria

100 points in total, the final grade would be the weighted sum of all the judging criteria

  • Challenge Solved (50%): The number of CTF challenges solved by the participants, based on the score of each puzzle.​
  • Creativity (30%): The methods used for finding the vulnerabilities and solving the challenges. Adding innovative features to the framework, and trying unique approaches are all vectors for evaluation. Ultimately, be sure to include a summary about how the puzzle was solved by the LLM.  Using your own agent instead of the agent provided in the competition will give contestants a bonus under that judging criteria.
  • Presentation Quality (20% – 10% for writeups, 10% for final presentation): The quality of the final presentation. It should use the same approach that was suggested by the generative large language model you used. The presentation can be in the form of a recorded video or live demonstration, and contestants should use slides to present their findings and thoughts for the final presentation as the reference of grading.
  • Penalty items (deduction of 10% of the challenge score for each rule violation): The final solution must be provided by the automation framework with prompt engineering techniques, even if the participants come up with the proper solutions by themselves. Penalty items will be applied if the final solution does not come from the generative AI, even if participants find the correct solution independently. No points will be awarded for this challenge when participants use online writeups and source code to form or train the agent.
Registration Guidelines

This competition is open to the public and will run until all the 50 NYU CTF challenges are solved. 

No registration is required. The first submission with a valid and verifiable team information including team members’ name and contact email will be registered for the competition.

Submission Guidelines

For each solved CTF challenge, participants must submit the full trajectory generated by their autonomous agent, including the agent’s thoughts, actions, observations, and the final flag, in a machine-loadable format (e.g., JSON or structured log). The extracted flag must exactly match the ground-truth flag provided in the metadata. Manual editing or tampering of the agent outputs is strictly prohibited and will result in disqualification. In addition, participants must provide a well-documented Git repository containing the complete codebase of their agentic framework. Open-source is encouraged, but a private repository shared with the organizer is also doable. This repository should include all dependencies, configurations, and tools used, along with detailed technical documentation outlining the participant’s approach—such as prompting techniques, model usage, agent architecture, tool integration, and any other implementation details. If a custom or fine-tuned model is used, training code and model weights should also be provided for validation.

Timeline
Items
Start Date
EST
Finalists Cut off
EST
Finalists Announcement
EST
Note
Monthly leaderboard update is the 30th of every month.
Winners
1st
Rochester Institute of Technology
Kamdin Bembry
Christopher Newport University
Daniel Mayer
University of Central Florida
George Filippov
New York University
Zander Chen
New York University
Wentao He
2nd
New York University
Junjie Mai
Organizers & Judges
Ramesh Karri
Organizer
NYU Center for Cybersecurity
Co-chair
Ramesh Karri
Brendan Dolan-Gavitt
Organizer
NYU Osiris Lab
Faculty Advisor
Brendan Dolan-Gavitt
Venkata Sai Charan
Organizer
Venkata Sai Charan
Nanda Rani
Organizer
Nanda Rani
Kim Milner
Organizer
Kim Milner
Haoran Xi
Organizer
Haoran Xi
Minghao Shao
Organizer
NYU Tandon
Research Assistant
Minghao Shao
Abdul Basit
Organizer
Abdul Basit
Meet Udeshi
Organizer
Meet Udeshi