Host University
NYU Tandon School of Engineering

Applied Research Competition 2026

Base Competition
Year
2026
Timeline
Items
Submission Deadline
AoE
Submit your paper by the end of day, Anytime on Earth (AoE).
Reviews complete
Program committee reviews conclude.
Finalists notified
All authors, finalists and non-finalists, receive their decision by email.
Travel confirmed
Transportation to and from NYU and accommodation throughout the competition are confirmed for the ten invited student presenters.
In-person presentations
EST
Ten student authors present before a panel of industry judges and academics at NYU Brooklyn.
Best Paper Awards
EST
Best Paper Awards for technical and social impact are announced at the closing ceremony.
Region
Note
Center for Cybersecurity
370 Jay Street, 10th Floor
Brooklyn, NY

Wed, Nov 11: Arrive in NYC.
Thu, Nov 12: Attend NYU events, talks, and career fair; poster setup at 4 PM.
Fri, Nov 13: Poster setup before 9 AM; session begins at 9 AM; judges arrive at 12 PM; judging runs until 3 PM; take down posters at 5 PM.
Sat, Nov 14: Best Paper Awards announced at the 9 AM closing ceremony.

Only in-person presentations are allowed. Bring a 36 × 24 inch landscape, not portrait, printed poster; use graphics and avoid too many words. Judges evaluate technical impact and social impact. No computer, demos, or slides are needed.
Eligibility
  1. The paper concerns the design, application, implementation, or exploitation of security technologies.
  2. The research is already used in practice or has clear potential to be used in practice.
  3. The paper was published or camera-ready between September 1, 2025 and July 31, 2026 at IEEE Security & Privacy 2026, USENIX Security 2026, SOUPS 2026, ACM CCS 2025, NDSS 2026, IMC 2025, CSCW 2025, PETS 2026, IMWUT/UbiComp 2025, or ACM CHI 2026. Work published elsewhere may also be submitted when it meets the remaining criteria, though the listed venues may receive preference in the event of a tie.
  4. At least one author is a student enrolled at a university in Canada, Mexico, or the United States as of November 1, 2026, and is available to present the work in person at NYU on November 13, 2026.
Judging Criteria

Practitioners, academics, and industry experts assess the real-world impact of eligible submissions:

  1. Technical Impact
  2. Social Impact
Submission Guidelines

Submit one PDF of the published or camera-ready paper, retaining the original publication venue template. Review is single-blind: reviewers can see author names; authors do not see reviewer names.

Not running this year in (regions)
Organizers & Judges
Rameen Mahmood
Organizer
Center for Cybersecurity, NYU
PhD Student
Region
Grace McGrath
Organizer
Center for Cybersecurity, NYU
PhD Student
Region
Danny Huang
Organizer
Center for Cybersecurity, NYU
Faculty
Region

AI Hardware Attack Challenge 2026

Base Competition
Year
2026
Timeline
Items
Preliminary Competition Phase Release
EST
Preliminary Phase Due
EST
Finalists Announced
EST
Final Challenge Released @ CSAW
EST
Final Challenge Due & Teams Present
EST
Eligibility

This year's competition is running only in the US-Canada region. Teams must consist of currently-enrolled students at universities.

Challenge Details

In this year's competition, teams are challenged to use generative AI to both insert hardware Trojans into FPGA-targeted hardware designs as well as demonstrate exploits for these new Trojans. The target of this competition is the Hackster board from Calico Computer, an education-focused device which includes an application microprocessor, an FPGA, and additional peripherals aimed at hardware security education.

Teams will need to reverse-engineer the FPGA bitstream provided for the Hackster board and use that, along with basic integration documentation and tests, to determine how the hardware design works and add a Trojan to it.

A preliminary qualifying round of the competition will take place across two weeks, from 18 September to 2 October. Finalists will be selected by 4 October. These teams will be brought to New York to attend CSAW in-person. The final challenge will be given at CSAW and will take place over 24 hours, where teams will be given access to the physical Hackster boards to both demonstrate their preliminary Trojans and complete the final challenge on the hardware.

Rules

All hardware and exploits must be created by generative AI. Deterministic tools may be used alongside the AI, but no human may write the actual hardware design for the Trojan or exploit demonstration.

Judging Criteria

A full judging rubric will be found on the competition's GitHub repo once the challenge has formally released.

Registration Guidelines

Teams may consist of the following:

  • Up to 4 students
  • One advisor (can be a graduate student advising undergraduates, or a professor advising graduate students)

Register here.

Resources
Awards
1st
Hackster Board
2nd
Hackster Board
3rd
Hackster Board
Not running this year in (regions)
Organizers & Judges
Jason Blocklove
Organizer
NYU
Competition Designer and Organizer
Email
jason.blocklove@nyu.edu
Region
Jason Blocklove

Hack3D 2025

Base Competition
Year
2025
Timeline
Items
Registration Deadline
EST
Qualification Round
EST
October 6 - 7, 2025
Finalist Notification
EST
Final Round
EST
November 5 - 6, 2025
Final Presentations
EST
Winners
1st
New York University
Jason Blocklove
MD Raz
Khaled Al Mutawa
2nd
Ansys Inc.
Balavignesh Vemparala Narayana Murthy
Yuzhao Zhou
Ohio State University
Fadwa Azakri
Md Shahneoug Shuvo
3rd
Texas A&M University
Caleb Norton
Seyed Ali Ghazi Asgar
Organizers & Judges
Abhijit Chakraborty
Judge
Abhijit Chakraborty
Yan Lu
Judge
Yan Lu
Chrys Koomson
Judge
Chrys Koomson
Vikas Varshney
Judge
Vikas Varshney
Nikhil Gupta
Organizer
NYU Tandon, Department of Mechanical and Aerospace Engineering
Nikhil Gupta

BioHack 3D 2026

Base Competition
Year
2026
Timeline
Items
Registration & Qualifying Round Deadline
EST
BioHACK3D Final Round
EST
In Person at NYU Abu Dhabi and NYU-CCS
Results Announcement & Prize Distribution
EST
Region
Challenge Details

Think Like an Attacker. Challenge a Deep-Learning QR-Code Authenticator.

BioHACK3D 2026 puts you against an AI-powered physical-authentication system built to recognize genuine melt-electrowritten QR codes (MEW-QRCs).

Your Challenge

Explore the authentication pipeline, probe its weaknesses, and determine how robust the DL-based verifier really is.

  • Work with MEW-QRC image datasets provided by the organizers. 
  • Examine the microscopic and morphological features that drive authentication. 
  • Apply ideas from computer vision, image processing, AI/ML/DL, and adversarial learning
  • Investigate how image manipulation, counterfeiting, cloning, noise, deformation, or other physical and imaging variations may influence the verifier. 
  • Develop a creative and realistic strategy for challenging the DL-based authentication decision
  • Evaluate your approach in terms of attack effectiveness, computational cost, latency, scalability, and practical feasibility

The Goal

Can you find a weakness in the authentication pipeline and exploit it convincingly enough to challenge the AI's decision?

Bring your computer-vision skills, adversarial-ML ideas, cybersecurity mindset, and creativity to BioHACK3D 2026.

Find the weakness. Challenge the model. Test the limits of AI-powered physical authentication.

Have your solution evaluated by experts in AI, 3D printing, biochip security, and cyber-physical systems.

Rules
  • Each team will compete within its designated region — MENA (UAE Only) or US & Canada
  • Submissions must reflect the team’s original creativity, technical insight, and effort
  • Teams will work with the MEW-QRC datasets and challenge information provided by the organizers
  • The objective is to investigate the supplied DL-based authentication pipeline and develop a technically convincing strategy for challenging its authentication decision. 
  • Finalist teams must submit a short technical report using the provided template and a 4–5-minute demonstration video/online presentation
  • Finalist teams are responsible for arranging and covering their own transportation to the respective CSAW venue. Travel support will not be provided.
Judging Criteria
  • Attack Effectiveness - How successfully does the proposed strategy challenge the DL-based MEW-QRC authenticator? As part of the evaluation, the judges will act as the Trusted Third Party (TTP) and test the submitted modified, manipulated, or counterfeit MEW-QRC images using the organizers’ DL-based authentication framework. Performance will be judged by the extent to which the submitted samples can influence the authenticator toward an incorrect acceptance decision. 

  • Technical Soundness - Are the attack methodology, assumptions, experiments, and conclusions technically well justified? 

  • Stealth & Realism - How plausible is the proposed attack under realistic imaging, computational, and physical constraints? 

  • AI/Computer-Vision Innovation - Creative use of AI/ML/DL, computer vision, image processing, adversarial methods, or related techniques. 

  • Experimental Evidence - Quality of the results and dataset-based evidence demonstrating the effectiveness and limitations of the proposed approach. 

  • Practical Feasibility - Consideration of computational cost, latency, scalability, resources, and deployability of the attack strategy. 

  • Novelty & Creativity - Originality of the team's approach to identifying and exploiting weaknesses in the authentication pipeline. 

  • Technical Report & Demonstration - Clarity, coherence, reproducibility, and quality of the final report, presentation, and demonstration.

Registration Guidelines
  • Eligibility: Undergraduate and Postgraduates 
  • Team Size: 2–4 members; cross-institution teams are allowed 
  • Selection: Qualifying round conducted through the BioHACK3D registration form 
  • Registration Deadline: October 7, 2026 
  • Regional Participation: Teams compete within their respective region — MENA (UAE teams only) or US & Canada 
Submission Guidelines

Qualifying Round

  • Complete the technical questions provided in the registration form. 
  • Demonstrate your understanding of MEW-QRCs, computer vision, AI/ML/DL, physical authentication, and relevant security threats
  • Selected teams will advance to the BioHACK3D 2026 Final Round

Final Round

  • Finalist teams will receive the competition dataset and detailed challenge instructions. 
  • Develop and evaluate a strategy for challenging the DL-based MEW-QRC authentication system
  • Generate or modify MEW-QRC images according to the competition rules. 
  • The submitted challenge images will be tested by the organizers/judges acting as the Trusted Third Party (TTP) using the organizers’ DL-based authenticator. 
  • Submit a short technical report describing the approach, methodology, experiments, and results. 
  • Present the solution before an expert judging panel at the respective CSAW 2026 venue.
Awards
1st
$500 Amazon Gift Card / Cash Prize
Prizes will be awarded separately in each region.
2nd
Certificate of Achievement + Plaque
Prizes will be awarded separately in each region
3rd
Certificate of Achievement + Plaque
Prizes will be awarded separately in each region
All finalists will have the opportunity to participate in CSAW 2026 at their respective venues, interact with experts in cybersecurity, AI, and biochip security, and experience other CSAW competitions and activities.
Certificates will be awarded to the top three teams in each region.
Organizers & Judges
Ramesh Karri
Organizer
NYU Center for Cybersecurity (CCS)
Email
rk1330@nyu.edu
Region
Ramesh Karri
Navajit Singh Baban
Organizer
NYU Abu Dhabi Center for Cybersecurity (NYUAD-CCS) and Center for Translational Medical Devices (NYUAD-CENTMED)
Associate Research Scientist
Email
nsb359@nyu.edu
Region
Navajit Singh Baban
Yong Rafael Song
Organizer
NYU Abu Dhabi
Program Head of Bioengineering; Professor of Mechanical Engineering and Bioengineering, NYU Abu Dhabi; Global Network Professor of Mechanical Engineering and Biomedical Engineering, NYU Tandon
Email
ya50@nyu.edu
Region
Yong Rafael Song
Dr. Urbi Chatterjee
Organizer
Department of Computer Science & Engineering, Indian Institute of Technology Kanpur
Assistant Professor
Email
urbic@cse.iitk.ac.in
Dr. Urbi Chatterjee
Neelofar Hassan
Organizer
Indian Institute of Technology Kanpur and NYU Tandon School of Engineering
Joint PhD Student in Computer Science and Engineering
Email
nh2814@nyu.edu
Region
Neelofar Hassan
Prithwish Basu Roy
Organizer
NYU Tandon School of Engineering and NYU Abu Dhabi
Ph.D. Candidate; Research Assistant
Email
pb2718@nyu.edu
Region
Prithwish Basu Roy
Akashdeep Saha
Organizer
NYU Abu Dhabi Center for Cybersecurity (NYUAD-CCS)
Postdoctoral Associate
Email
as19360@nyu.edu
Region
Akashdeep Saha
Lovnish Julka
Organizer
NYU Abu Dhabi
Rising Senior studying Computer Science and Mathematics
Email
lj2410@nyu.edu
Region
Lovnish Julka
Rashik Chand
Organizer
NYU Tandon School of Engineering and NYU Abu Dhabi
Global PhD Fellow in Biomedical Engineering
Email
rc4400@nyu.edu
Region
Rashik Chand
Muhammad Abdullah Hanif
Organizer
NYU Abu Dhabi Center for Cybersecurity (NYUAD-CCS)
Postdoctoral Associate
Email
mh6117@nyu.edu
Region
Muhammad Abdullah Hanif
Gopinathan Janarthanan
Organizer
New York University Abu Dhabi
Research Scientist
Email
gj2180@nyu.edu
Region
Gopinathan Janarthanan
Sukanta Bhattacharjee
Organizer
IIT Guwahati, Computer Science and Engineering
Assistant Professor
Email
sukantab@iitg.ac.in
Region
Sukanta Bhattacharjee
Vijayavenkataraman Sanjairaj
Organizer
NYU Abu Dhabi
Assistant Professor
Email
vs89@nyu.edu
Region
Vijayavenkataraman Sanjairaj
Sarani Bhattacharya
Organizer
IIT Kharagpur, Computer Science and Engineering
Assistant Professor
Email
sarani@cse.iitkgp.ac.in
Sarani Bhattacharya
Soumyadyuti Ghosh
Organizer
NYU Abu Dhabi Center for Cybersecurity
Postdoctoral Associate
Email
sg8466@nyu.edu
Region
Soumyadyuti Ghosh

Cyber Reasoning Challenge 2026

Base Competition
Year
2026
Timeline
Items
Team registration deadline
AoE
Qualification CRS lock
AoE
Qualification round begins
AoE
Qualification round ends
AoE
CRC@CSAW finals
AoE
Eligibility

Current college or university students may compete. Teams consist of one to four students and may list one faculty or staff advisor. Each participant may compete on only one team.

CRC 2026 is open in the US-Canada and MENA regions. The competition is online.

Challenge Details

The Cyber Reasoning Challenge (CRC) is an AIxCC-style competition in which student teams design a cyber reasoning system (CRS) to find and patch vulnerabilities in real software targets. Unlike a traditional CTF, teams do not solve challenges by hand. Their CRS must autonomously discover a crashing proof of vulnerability and produce a patch that compiles, preserves the program’s intended behavior, and actually fixes the bug rather than hiding a single crash.

To keep the event focused on system design, we have used the evaluation infrastructure from Team Atlanta, the first-place team in DARPA’s AI Cyber Challenge. Teams therefore do not need to build the evaluation pipeline, scoring, or target-harnessing stack from scratch. They can spend their time on the CRS itself: how it searches, localizes, and repairs bugs.

We also provide a starter kit with two working CRS baseline (codex and claude code). Teams can run it out of the box to understand the workflow, then replace or extend the finder and patcher with their own components. 

Challenges use two scan modes. In a delta scan, the vulnerable change is provided as a diff. In a full scan, the complete vulnerable project is provided without a localization hint. The inaugural event focuses on C and C++ targets.

Rules
  • Teams consist of one to four current college or university students and may list one advisor. A participant may belong to only one team.
  • After a scored run begins, discovery and patching must be performed by the team’s submitted CRS. Human intervention is not allowed.
  • Teams may use fuzzers, static or dynamic analysis, language models, agent systems, and other legally obtained tools, and must follow the licenses and terms of those tools.
  • Use competition targets and infrastructure only for CRC@CSAW participation, research, and education. Do not attack competition infrastructure, other teams, external services, or systems outside the released challenge environment.
  • Submit only artifacts produced for the registered team. Do not include credentials, private keys, tokens, or personal data.
  • Do not disable the harness, tests, build system, or vulnerable feature to obtain a passing result. 
  • All participants must follow the CSAW Code of Conduct.
  • Organizer verification is authoritative. Organizers may reject a submission or disqualify a team for violating these rules.
Judging Criteria

Qualification and finals are points-based. Organizers verify submitted proofs of vulnerability and patches.

A proof receives credit when it crashes the vulnerable build, remains clean on the organizer’s corrected build, and matches the intended crash signature.

A patch receives credit only when it applies and compiles, passes the project’s functional tests, and actually fixes the bug.

The five highest-scoring teams provisionally qualify, subject to an integrity and reproducibility audit of the submitted system and artifacts. Organizer verification is the final authority. Tie-break details will be announced with the qualification materials.

Registration Guidelines

Register one response per team before the registration deadline. The team lead will receive official competition communications.

Registration form: https://docs.google.com/forms/d/e/1FAIpQLScyYxAInuka-A1ehkU9fKZ57NKgpFvhjLEDLJNV4oaBQEQFZg/viewform

After registering, you can join the CRC@CSAW Discord or watch the GitHub repository for announcements, starter-kit updates, and challenge releases.

Submission Guidelines

During qualification, each team runs its CRS on the official evaluation pipeline. After the run finishes, apply the official cleaning script so rebuildable work directories are removed, then upload the remaining result artifacts before the 48-hour round ends.

The cleaned package must include the official submitted proofs (hashed PoV blobs), the official submitted patches (one unified diff per discovered bug), run metadata, verification records, usage logs, and the agent trajectories needed for the integrity audit. Only proofs written to the official PoV submission output count. Internal candidates that were never submitted do not count. A patch is scored only for the bug that trial targeted.

Teams must also freeze a qualification branch of their CRS repository by the lock deadline. Later commits on that branch will be ignored. Organizers re-run that branch during the audit. The Google Drive folder and submission form will be released with the qualification challenges.

Awards
1st
$600
2nd
$300
3rd
$100
Prize support is provided by Team Atlanta. We would also invite the top 3 teams to submit a paper describing their design and lessons learned from the challenge.
Organizers & Judges
Jiahao Yu
Organizer
NYU Abu Dhabi
Contest lead
Email
jy5951@nyu.edu
Photo of Jiahao Yu
Andrew Chin
Organizer
Georgia Institute of Technology, School of Cybersecurity and Privacy
Ph.D. student; Team Atlanta / OSS-CRS
Email
achin34@gatech.edu
Andrew Chin's Photo

Cyber Reasoning Challenge

Autonomous vulnerability discovery and repair
Description

The Cyber Reasoning Challenge (CRC) is an AIxCC-style competition in which student teams design a cyber reasoning system (CRS) to find and patch vulnerabilities in real software targets. Unlike a traditional CTF, teams do not solve challenges by hand. Their CRS must autonomously discover a crashing proof of vulnerability and produce a patch that compiles, preserves the program’s intended behavior, and actually fixes the bug rather than hiding a single crash.

To keep the event focused on system design, we have used the evaluation infrastructure from Team Atlanta, the first-place team in DARPA’s AI Cyber Challenge. Teams therefore do not need to build the evaluation pipeline, scoring, or target-harnessing stack from scratch. They can spend their time on the CRS itself: how it searches, localizes, and repairs bugs.

We also provide a starter kit with two working CRS baseline (codex and claude code). Teams can run it out of the box to understand the workflow, then replace or extend the finder and patcher with their own components. 

Cyber Reasoning Challenge logo
Short Name
CRC

Quantum Security Challenge

Collapsing the wave function of quantum computing!
Description

Quantum computing is increasingly delivered as a hybrid computing service. A classical client builds a circuit; compiler and intermediate-representation layers rewrite it; a cloud scheduler selects physical resources; control and readout systems execute the job; and classical software interprets probabilistic results. Every transition creates a trust boundary.
Most quantum-security education focuses on the security implications and applications of quantum computing. QSec addresses the complementary question: how do we secure quantum computers, their architecture, and the quantum machine learning applications built on top of them?
In this competition, teams will attack and defend intentionally vulnerable quantum workflows. Challenges will cover cloud-job and result integrity, multi-tenant leakage, adversarial inputs, backdoors, model extraction, and attacks on aggregation and coordination mechanisms in quantum federated learning. The emphasis is on concrete security reasoning and reproducible exploits rather than on solving large quantum algorithms.
This track offers a hands-on and accessible approach to emerging quantum security challenges through practical attack-and-defense tasks with measurable outcomes.
 
A successful submission will include:

  1. Correct flags and checker receipts for each solved challenge.
  2. Reproducible exploit or defense artifacts, such as scripts, notebooks, patches, model files, or query logs.
  3. A concise write-up for each solved challenge explaining the threat model, vulnerability, exploit path, evidence, and recommended mitigation.
  4. A final presentation that synthesizes the team's approach, cross-layer insights, tool usage, and lessons learned.
Quantum Security Challenge
Short Name
QSEC