Conference Description
Key Takeaways
- Fourth annual workshop focused on securing machine learning systems against adversarial threats and operational failures
- Co-located with IEEE ACSAC 2026, bringing together academic researchers and industry practitioners
- Covers adversarial machine learning, data poisoning defences, machine unlearning, and federated learning security
- Addresses growing regulatory and operational demands for explainable, accountable, and certifiable AI systems
- Designed for security professionals, AI engineers, researchers, and technical architects
Introduction
The 4th ARTMAN Workshop convenes in Los Angeles on 8 December 2026 as a co-located event with IEEE ACSAC 2026, the Annual Computer Security Applications Conference. This research-focused workshop brings together academic and industry professionals working at the intersection of artificial intelligence, machine learning, cybersecurity, and privacy. As organisations accelerate their deployment of AI-driven systems across critical infrastructure, healthcare, finance, and autonomous technologies, the need for systematic approaches to securing these systems has become increasingly urgent.
The workshop’s dual emphasis on resilience and trustworthiness reflects a maturing understanding within the security community that AI systems must not only resist attacks but also maintain predictable, reliable behaviour under adverse conditions. This distinction matters because traditional security models often fail to account for the unique vulnerabilities introduced by machine learning pipelines, where threats can emerge from training data, model architecture, or inference processes.
About This Event
ARTMAN Workshop operates as an in-person, technical forum featuring keynote presentations and peer-reviewed paper sessions. The event receives partial support from the GRIFIN project and benefits from its association with IEEE ACSAC, one of the established venues for applied computer security research. By co-locating with ACSAC, the workshop provides attendees access to a broader community of security researchers while maintaining its specialised focus on machine learning security challenges.
Adversarial Threats and Data-Centric Attacks
A significant portion of the workshop programme addresses adversarial machine learning, an area of research concerned with how attackers can manipulate AI systems through carefully crafted inputs or corrupted training data. Adversarial examples—inputs designed to cause misclassification—represent one category of threat, but the workshop also examines more insidious attacks including data poisoning and backdoor insertion during model training.
These threats pose particular challenges because they can be difficult to detect through conventional testing. A poisoned model may perform normally on standard benchmarks while exhibiting malicious behaviour only when triggered by specific inputs. The workshop explores both offensive techniques and corresponding defensive strategies, including anomaly detection, failure prediction, and incident diagnosis methodologies.
Building Trustworthy and Explainable Systems
Beyond attack resistance, the workshop addresses the broader challenge of establishing trust in intelligent systems. This encompasses interpretability, explainability, accountability, transparency, and fairness—qualities increasingly demanded by regulators and enterprise adopters alike. The European Union’s AI Act and similar regulatory frameworks worldwide have elevated these concerns from academic interest to compliance requirements for many organisations.
The workshop examines robustness and security evaluation methodologies, including testing, simulation, verification, validation, and certification approaches. These systematic evaluation frameworks help organisations demonstrate that their AI systems meet defined security and reliability standards, a capability that becomes essential as AI moves into regulated industries.
Privacy Protection and Sustainable AI
Machine unlearning represents an emerging research area with direct privacy implications. As data protection regulations grant individuals the right to have their data deleted, organisations face the technical challenge of removing the influence of specific training examples from deployed models without complete retraining. The workshop explores approaches to this problem alongside related privacy-preserving techniques.
Sustainable AI topics include federated learning security, privacy-aware knowledge distillation, and the development of robust smaller models. These approaches address practical constraints around computational resources and data governance while maintaining security properties—a balance that matters for edge deployments and privacy-sensitive applications.
Who Should Attend
The workshop serves researchers and practitioners across multiple disciplines. Academic attendees typically work in AI/ML, computer security, or privacy research. Industry participants include security engineers, AI/ML engineers, system architects, and technical leads responsible for deploying machine learning systems in production environments. Risk assessors and compliance professionals seeking to understand the technical foundations of AI security evaluation will also find relevant material.
The technical depth assumes familiarity with machine learning fundamentals and security concepts, making this most suitable for professionals already working in these domains rather than those seeking introductory coverage.

