USENIX Security handles record paper submissions as AI use spreads
#Cybersecurity

USENIX Security handles record paper submissions as AI use spreads

Lukas Brandt
Lukas Brandt
3 min read

USENIX Security received about 3,030 valid submissions for its 2026 symposium, up from about 2,400 the year before. Organizers used reference checks and reviewer safeguards to address AI-related risks without turning peer review into an AI detection exercise.

The 35th USENIX Security Symposium received about 3,030 valid paper submissions for its 2026 conference in Baltimore, Maryland, a 26% increase from the previous year.

Featured image

Ben Stock, a CISPA Helmholtz Center for Information Security faculty member and program co-chair, said the increase follows a broader rise in security research submissions. The Network and Distributed System Security Symposium received 1,481 submissions this year, compared with 694 in 2024 and 1,311 in 2025.

USENIX Security split its 2026 submissions across two review cycles. The first cycle drew about 1,280 papers, while the second drew about 1,750. Organizers expanded the program committee to handle the larger workload.

Reference checks target fabricated citations

Conference officials focused their AI safeguards on two identifiable threats: fabricated references in submitted papers and AI-written peer reviews.

The organizers published their approach in the USENIX Security 2026 transparency report, released in January between the two submission cycles. The process used software to extract references from submitted PDFs, query sources such as DBLP and arXiv, and flag citations for human review.

Organizers rejected papers with three or more references that they could not verify. That rule affected 21 of the 1,181 papers submitted during the first cycle, or 1.78% of the total.

More than 100 other papers contained at least one reference that reviewers could not confirm. Staff chose not to investigate those cases because spelling differences, incomplete records and missing citations could produce false positives.

Stock said the conference could not determine whether artificial intelligence created each invalid reference. The organizers still treated repeated nonexistent citations as a problem with the paper's research process.

The policy draws a clear line around bibliography preparation. Organizers allow limited AI assistance to polish human-written prose, but they reject fabricated citations because those references prevent readers from checking the research record.

Review confidentiality limits AI use

USENIX Security also told program committee members that they could not use AI services to write peer reviews. Reviewers handle confidential submissions, so sending paper text to an outside AI service can expose unpublished research.

Organizers did not create a separate AI rulebook for reviewers. Instead, they communicated the prohibition through the program committee process and investigated cases that produced enough evidence to support action.

The conference identified five reviewers among 496 committee members whose AI use reached that threshold. Organizers removed those reviewers and allowed affected authors to resubmit papers.

The response reflects a narrow compliance model. Conference staff checked specific signals that could damage the review process, then limited intervention when the evidence remained uncertain. That approach reduced the risk of fabricated citations and confidentiality breaches without requiring staff to inspect every paper for AI assistance.

Record volume changes the review burden

A 2026 study titled “More Versus Better: Artificial Intelligence, Incentives, and the Emerging Crisis in Peer Review” reported a 42% rise in submissions to major academic journals after ChatGPT launched in 2022. The study connects higher submission volume with the growing availability of AI tools, though USENIX Security officials do not view AI-generated submissions as a major challenge for the security research community.

The conference's numbers show the operational cost of that growth. A larger submission pool requires more reviewers, more reference checks and more time to resolve questionable cases. The organizers' two-cycle process and expanded committee address capacity, while targeted checks address the parts of AI use that threaten scientific integrity.

Researchers submitting to USENIX Security should verify every citation against a reliable scholarly source, keep confidential manuscripts away from external AI systems and treat AI text editing as a limited aid to human-written work. Reviewers face a stricter obligation: they must protect submission confidentiality and write their evaluations themselves.

USENIX Security will hold its 2026 symposium in Baltimore next week. The organizers' safeguards show how a major security conference is adapting its review process as paper volume and AI access rise together.

Comments

Loading comments...