Host University
NYU Tandon School of Engineering

Cyber Policy Competition

Description

The rapid adoption of artificial intelligence across the digital ecosystem has reshaped how software and systems are developed. Practices such as “vibe coding”, using AI code-generation tools without deep technical expertise, are spreading quickly. At the same time, adversaries are experimenting with data poisoning, inserting malicious or falsified information into training pipelines to compromise AI models. These dynamics accelerate innovation but also create unprecedented cybersecurity risks: insecure code proliferates, poisoned datasets enable hidden backdoors, and attackers may gain systemic advantage as AI shifts the offense-defense balance.

Compounding the challenge, leading experts suggest that AI systems may never be fully secure. If this is true, policymakers, industry leaders, and researchers must grapple with how to manage residual risks, foster resilience, and ensure accountability. Without clear policies, responsibility for failures often falls to end-users, an unsustainable arrangement in a hyperconnected world.

The imperative today is to design governance frameworks that acknowledge AI’s dual nature: a powerful enabler of cybersecurity, but also a vector for new vulnerabilities. The CSAW 2025 Cyber Policy Competition focuses on addressing these concerns, working toward policies that balance innovation with accountability, liability, and resilience in the age of AI.

Key areas to research in this cyber policy area include:​

1. AI Security and Liability

  • Market Dynamics: Examine how AI-assisted development (e.g., vibe coding) rewards speed and functionality at the expense of secure engineering practices.
  • Duty of Care: Discuss the responsibility of AI tool developers, dataset curators, and vendors toward consumers, businesses, and critical infrastructure providers.
  • Liability Shift: Propose mechanisms to shift responsibility from end-users to those who deploy or distribute vulnerable AI-enabled products or poisoned datasets.

2. Global Impact and Best Practices

  • Global Standards: Explore whether international norms or standards for AI system assurance and dataset provenance are feasible, and what they might look like.
  • Cross-Border Risks: Analyze the global implications of AI-driven offense-defense dynamics and the role of export controls, multilateral cooperation, and norms.

Open-Source AI in the Global Arena: Debate the opportunities and challenges of open-source models and datasets, especially around accountability and transparency.

Cyber Policy Competition

Capture the Flag

Description

CSAW CTF is one of the oldest and biggest CTFs with 1216 teams with 1+ points in 2021. Designed as an entry-level, jeopardy-style CTF, this competition is for students who are trying to break into the field of security, as well as for advanced students and industry professionals who want to practice their skills.

CSAW CTF occurs over two rounds: a Qualifying Round in September and a Final Round in November. 

Capture the Flag

BioHack 3D

Can You Fool the Deep-Learning QR-Code Authenticator?
Description

A trusted third party (TTP) uses a DL-based authentication system to decide whether a submitted melt-electrowritten QR code (MEW-QRC) is genuine.

The green route is the legitimate path: an authentic MEW-QRC is captured, submitted, and accepted.

The real question is what happens along the red and orange routes.

Can you manipulate, counterfeit, or strategically alter an MEW-QRC image so convincingly that the authenticator makes the wrong decision?

Your Mission

Think like an attacker. Challenge the AI. Find the weakness.

Your objective is to explore whether a forged or manipulated MEW-QRC can cross the authentication barrier and be incorrectly classified as genuine.

You may investigate how the system responds to:

  • subtle image manipulation and perturbations,
  • counterfeit or reconstructed MEW-QRC patterns,
  • changes in morphology, texture, orientation, or image quality,
  • physical and imaging variations that could confuse the authentication model.

The ultimate goal is simple:

Can you turn an attack route into an accepted authentication?

In other words:

Can you flip the outcome: make the X on the red route a ✓ and the ✓ on the orange path an X, as authenticated by the TTP?

Challenge Description
An illustration of the adversarial framework.

 

BioHACK3D challenges you to combine AI, computer vision, cybersecurity, and creative problem solving to probe the limits of a real physical-authentication problem.

Break the assumption. Challenge the model. Fool the authenticator.

BioHack 3D

Applied Research Competition

Description

This "Best Paper Award" assesses the top scholarly security research from the previous year. The focus of this competition is on research that has a practical impact.  With eligibility limited to already published papers or camera-ready papers, CSAW has a reputation for drawing some of the best security research worldwide. 

Applied Research

Agentic Automated CTF

It’s time to think a little differently about the capabilities of generative AI.
Description

With the rise of large language models (LLMs), AI systems are now capable of identifying software vulnerabilities and generating exploit code—skills that align closely with the goals of Capture the Flag (CTF) competitions, where participants solve security challenges to uncover hidden “flags.”

In this competition, your task is to build your own agentic AI to solve CTF challenges autonomously—that is, create or extend an AI agent powered by LLMs to analyze and exploit challenges without human intervention. You may either bring your own agent framework or enhance a provided baseline agent, with technical support available. Your agent can leverage LLMs, either API-based models such as GPT, Claude and Gemini, or open-source models deployed locally to navigate common CTF categories such as crypto, forensics, pwn, reverse, web, and misc.

A successful submission includes the full logs of prompts and model responses, along with a brief write-up describing your prompting strategies, agent enhancements, and system design choices.

Agentic Automated CTF

AI Hardware Attack Challenge

It’s time to think a little differently about the capabilities of generative AI for chip design
Description

Participating teams will be tasked with leveraging AI tools, such as LLMs, to insert and exploit hardware vulnerabilities and Trojans in hardware designs. These can include cryptographic accelerators, processors, communication IPs, etc.

AI Hardware Attack Challenge