Conference Description
Key Takeaways
- Research-focused workshop examining AI as both a defensive tool and an emerging attack surface in cybersecurity
- Covers prompt injection, adversarial machine learning, model poisoning, and AI agent security vulnerabilities
- Addresses trustworthy AI principles including explainability, robustness, fairness, and privacy preservation
- Explores standardisation efforts from ITU-T, ISO/IEC, ETSI, and NIST
- Designed for security engineers, AI researchers, SOC analysts, CISOs, academics, and policymakers
Introduction
The Workshop on Trustworthy and Secure AI for Cyber Defense brings together researchers, practitioners, and policymakers to examine the complex relationship between artificial intelligence and cybersecurity. Taking place as part of the 2026 IEEE Conference on Dependable and Secure Computing (DSC) at Fordham University in New York from October 9–11, 2026, the workshop addresses a fundamental tension in modern security operations: while AI systems offer powerful capabilities for threat detection and incident response, they simultaneously introduce novel vulnerabilities that adversaries are actively exploiting.
This dual nature of AI in cybersecurity has become increasingly urgent as organisations deploy large language models and foundation models across security-critical environments. The workshop provides a forum for examining both sides of this equation through original research, industrial case studies, and system demonstrations.
AI as a Defensive Capability and Attack Surface
The workshop’s technical programme spans two interconnected domains. The first examines how AI enhances cyber defence through automated threat detection, vulnerability analysis, incident response orchestration, and cyber resilience. These applications have matured significantly as machine learning models demonstrate effectiveness at identifying anomalous behaviour and accelerating security operations centre workflows.
The second domain addresses the security of AI systems themselves. As organisations integrate LLMs and AI agents into operational environments, new attack vectors have emerged that traditional security frameworks were not designed to address. Prompt injection attacks manipulate AI systems into executing unintended actions by embedding malicious instructions within seemingly benign inputs. Jailbreak techniques circumvent safety guardrails to extract sensitive information or generate harmful outputs. Adversarial machine learning exploits vulnerabilities in model training and inference, while model poisoning corrupts AI behaviour by manipulating training data.
These threats require security professionals to develop new evaluation methodologies and defensive strategies specifically tailored to AI system architectures.
Trustworthiness, Explainability, and Assurance
Beyond technical security, the workshop examines broader trustworthiness requirements for AI deployed in security-critical contexts. Explainability remains essential for security analysts who must understand why an AI system flagged particular activity as malicious or recommended specific response actions. Without interpretable outputs, security teams cannot effectively validate AI recommendations or maintain accountability in incident response.
Robustness ensures AI systems perform reliably under adversarial conditions rather than failing unpredictably when confronted with novel attack patterns. Privacy-preserving AI techniques address the challenge of training effective security models without exposing sensitive organisational data. Human-centred design principles ensure AI augments rather than replaces human judgement in high-stakes security decisions.
Standardisation and Governance Frameworks
The workshop dedicates significant attention to benchmarking and standardisation efforts currently underway across multiple international bodies. ITU-T, ISO/IEC, ETSI, and NIST have each initiated programmes to establish evaluation criteria, certification frameworks, and governance guidelines for AI in security applications. These efforts aim to provide organisations with consistent methodologies for assessing AI system security and trustworthiness before deployment.
Standardisation work also addresses the challenge of comparing AI security solutions across vendors and implementations, enabling more informed procurement decisions and establishing baseline security expectations for the industry.
Who Should Attend
The workshop serves professionals working at the intersection of AI and cybersecurity. Security engineers implementing AI-driven detection systems will find relevant research on adversarial robustness and evaluation methodologies. AI and machine learning researchers can engage with security-specific challenges that differ substantially from general AI safety concerns. SOC analysts and CISOs gain insight into emerging threats targeting AI infrastructure and strategies for secure deployment. Academic faculty and graduate students benefit from exposure to current research directions and collaboration opportunities. Representatives from standards bodies and government agencies can contribute to discussions shaping future governance frameworks.
Conclusion
As AI becomes embedded throughout cybersecurity operations, the need for rigorous security evaluation and trustworthiness assurance grows correspondingly. The Workshop on Trustworthy and Secure AI for Cyber Defense offers a research-driven forum for advancing both the defensive applications of AI and the security of AI systems themselves, contributing to the development of robust, transparent, and reliable AI technologies for cyber defence.

