BioHack 3D

Can You Fool the Deep-Learning QR-Code Authenticator?
Description

A trusted third party (TTP) uses a DL-based authentication system to decide whether a submitted melt-electrowritten QR code (MEW-QRC) is genuine.

The green route is the legitimate path: an authentic MEW-QRC is captured, submitted, and accepted.

The real question is what happens along the red and orange routes.

Can you manipulate, counterfeit, or strategically alter an MEW-QRC image so convincingly that the authenticator makes the wrong decision?

Your Mission

Think like an attacker. Challenge the AI. Find the weakness.

Your objective is to explore whether a forged or manipulated MEW-QRC can cross the authentication barrier and be incorrectly classified as genuine.

You may investigate how the system responds to:

  • subtle image manipulation and perturbations,
  • counterfeit or reconstructed MEW-QRC patterns,
  • changes in morphology, texture, orientation, or image quality,
  • physical and imaging variations that could confuse the authentication model.

The ultimate goal is simple:

Can you turn an attack route into an accepted authentication?

In other words:

Can you flip the outcome: make the X on the red route a ✓ and the ✓ on the orange path an X, as authenticated by the TTP?

Challenge Description
An illustration of the adversarial framework.

 

BioHACK3D challenges you to combine AI, computer vision, cybersecurity, and creative problem solving to probe the limits of a real physical-authentication problem.

Break the assumption. Challenge the model. Fool the authenticator.

BioHack 3D

BioHack 3D 2026

Challenge Details

Think Like an Attacker. Challenge a Deep-Learning QR-Code Authenticator.

BioHACK3D 2026 puts you against an AI-powered physical-authentication system built to recognize genuine melt-electrowritten QR codes (MEW-QRCs).

Your Challenge

Explore the authentication pipeline, probe its weaknesses, and determine how robust the DL-based verifier really is.

  • Work with MEW-QRC image datasets provided by the organizers. 
  • Examine the microscopic and morphological features that drive authentication. 
  • Apply ideas from computer vision, image processing, AI/ML/DL, and adversarial learning
  • Investigate how image manipulation, counterfeiting, cloning, noise, deformation, or other physical and imaging variations may influence the verifier. 
  • Develop a creative and realistic strategy for challenging the DL-based authentication decision
  • Evaluate your approach in terms of attack effectiveness, computational cost, latency, scalability, and practical feasibility

The Goal

Can you find a weakness in the authentication pipeline and exploit it convincingly enough to challenge the AI's decision?

Bring your computer-vision skills, adversarial-ML ideas, cybersecurity mindset, and creativity to BioHACK3D 2026.

Find the weakness. Challenge the model. Test the limits of AI-powered physical authentication.

Have your solution evaluated by experts in AI, 3D printing, biochip security, and cyber-physical systems.

Rules
  • Each team will compete within its designated region — MENA (UAE Only) or US & Canada
  • Submissions must reflect the team’s original creativity, technical insight, and effort
  • Teams will work with the MEW-QRC datasets and challenge information provided by the organizers
  • The objective is to investigate the supplied DL-based authentication pipeline and develop a technically convincing strategy for challenging its authentication decision. 
  • Finalist teams must submit a short technical report using the provided template and a 4–5-minute demonstration video/online presentation
  • Finalist teams are responsible for arranging and covering their own transportation to the respective CSAW venue. Travel support will not be provided.
Judging Criteria
  • Attack Effectiveness - How successfully does the proposed strategy challenge the DL-based MEW-QRC authenticator? As part of the evaluation, the judges will act as the Trusted Third Party (TTP) and test the submitted modified, manipulated, or counterfeit MEW-QRC images using the organizers’ DL-based authentication framework. Performance will be judged by the extent to which the submitted samples can influence the authenticator toward an incorrect acceptance decision. 

  • Technical Soundness - Are the attack methodology, assumptions, experiments, and conclusions technically well justified? 

  • Stealth & Realism - How plausible is the proposed attack under realistic imaging, computational, and physical constraints? 

  • AI/Computer-Vision Innovation - Creative use of AI/ML/DL, computer vision, image processing, adversarial methods, or related techniques. 

  • Experimental Evidence - Quality of the results and dataset-based evidence demonstrating the effectiveness and limitations of the proposed approach. 

  • Practical Feasibility - Consideration of computational cost, latency, scalability, resources, and deployability of the attack strategy. 

  • Novelty & Creativity - Originality of the team's approach to identifying and exploiting weaknesses in the authentication pipeline. 

  • Technical Report & Demonstration - Clarity, coherence, reproducibility, and quality of the final report, presentation, and demonstration.

Registration Guidelines
  • Eligibility: Undergraduate and Postgraduates 
  • Team Size: 2–4 members; cross-institution teams are allowed 
  • Selection: Qualifying round conducted through the BioHACK3D registration form 
  • Registration Deadline: October 7, 2026 
  • Regional Participation: Teams compete within their respective region — MENA (UAE teams only) or US & Canada 
Submission Guidelines

Qualifying Round

  • Complete the technical questions provided in the registration form. 
  • Demonstrate your understanding of MEW-QRCs, computer vision, AI/ML/DL, physical authentication, and relevant security threats
  • Selected teams will advance to the BioHACK3D 2026 Final Round

Final Round

  • Finalist teams will receive the competition dataset and detailed challenge instructions. 
  • Develop and evaluate a strategy for challenging the DL-based MEW-QRC authentication system
  • Generate or modify MEW-QRC images according to the competition rules. 
  • The submitted challenge images will be tested by the organizers/judges acting as the Trusted Third Party (TTP) using the organizers’ DL-based authenticator. 
  • Submit a short technical report describing the approach, methodology, experiments, and results. 
  • Present the solution before an expert judging panel at the respective CSAW 2026 venue.
Timeline
Items
Registration & Qualifying Round Deadline
EST
BioHACK3D Final Round
EST
In Person at NYU Abu Dhabi and NYU-CCS
Results Announcement & Prize Distribution
EST
Region
Awards
1st
$500 Amazon Gift Card / Cash Prize
Prizes will be awarded separately in each region.
2nd
Certificate of Achievement + Plaque
Prizes will be awarded separately in each region
3rd
Certificate of Achievement + Plaque
Prizes will be awarded separately in each region
All finalists will have the opportunity to participate in CSAW 2026 at their respective venues, interact with experts in cybersecurity, AI, and biochip security, and experience other CSAW competitions and activities.
Certificates will be awarded to the top three teams in each region.
Organizers & Judges
Ramesh Karri
Organizer
NYU Center for Cybersecurity (CCS)
Email
rk1330@nyu.edu
Region
Ramesh Karri
Navajit Singh Baban
Organizer
NYU Abu Dhabi Center for Cybersecurity (NYUAD-CCS) and Center for Translational Medical Devices (NYUAD-CENTMED)
Associate Research Scientist
Email
nsb359@nyu.edu
Region
Navajit Singh Baban
Yong Rafael Song
Organizer
NYU Abu Dhabi
Program Head of Bioengineering; Professor of Mechanical Engineering and Bioengineering, NYU Abu Dhabi; Global Network Professor of Mechanical Engineering and Biomedical Engineering, NYU Tandon
Email
ya50@nyu.edu
Region
Yong Rafael Song
Dr. Urbi Chatterjee
Organizer
Department of Computer Science & Engineering, Indian Institute of Technology Kanpur
Assistant Professor
Email
urbic@cse.iitk.ac.in
Dr. Urbi Chatterjee
Neelofar Hassan
Organizer
Indian Institute of Technology Kanpur and NYU Tandon School of Engineering
Joint PhD Student in Computer Science and Engineering
Email
nh2814@nyu.edu
Region
Neelofar Hassan
Prithwish Basu Roy
Organizer
NYU Tandon School of Engineering and NYU Abu Dhabi
Ph.D. Candidate; Research Assistant
Email
pb2718@nyu.edu
Region
Prithwish Basu Roy
Akashdeep Saha
Organizer
NYU Abu Dhabi Center for Cybersecurity (NYUAD-CCS)
Postdoctoral Associate
Email
as19360@nyu.edu
Region
Akashdeep Saha
Lovnish Julka
Organizer
NYU Abu Dhabi
Rising Senior studying Computer Science and Mathematics
Email
lj2410@nyu.edu
Region
Lovnish Julka
Rashik Chand
Organizer
NYU Tandon School of Engineering and NYU Abu Dhabi
Global PhD Fellow in Biomedical Engineering
Email
rc4400@nyu.edu
Region
Rashik Chand
Muhammad Abdullah Hanif
Organizer
NYU Abu Dhabi Center for Cybersecurity (NYUAD-CCS)
Postdoctoral Associate
Email
mh6117@nyu.edu
Region
Muhammad Abdullah Hanif
Gopinathan Janarthanan
Organizer
New York University Abu Dhabi
Research Scientist
Email
gj2180@nyu.edu
Region
Gopinathan Janarthanan
Sukanta Bhattacharjee
Organizer
IIT Guwahati, Computer Science and Engineering
Assistant Professor
Email
sukantab@iitg.ac.in
Region
Sukanta Bhattacharjee
Vijayavenkataraman Sanjairaj
Organizer
NYU Abu Dhabi
Assistant Professor
Email
vs89@nyu.edu
Region
Vijayavenkataraman Sanjairaj
Sarani Bhattacharya
Organizer
IIT Kharagpur, Computer Science and Engineering
Assistant Professor
Email
sarani@cse.iitkgp.ac.in
Sarani Bhattacharya
Soumyadyuti Ghosh
Organizer
NYU Abu Dhabi Center for Cybersecurity
Postdoctoral Associate
Email
sg8466@nyu.edu
Region
Soumyadyuti Ghosh

Previous editions