USENIX Security paper submissions hit 3,030 as chairs tighten AI checks
USENIX Security scaled review for a record 3,030 submissions and targeted unverifiable citations and AI-written reviews.
By Renata Fuchs · Policy Reporter
· 3 min read
USENIX Security paper submissions reached about 3,030 valid entries for its 2026 conference, up from roughly 2,400 a year earlier, according to program co-chair Ben Stock. The conference has expanded its program committee and added narrow integrity checks aimed at bogus citations and AI-written peer reviews, rather than trying to identify every use of generative AI.
The volume is split between about 1,280 submissions in the first cycle and 1,750 in the second, Stock told The Register. USENIX Security uses two submission deadlines, as the conference’s accepted-papers page confirms. The 2026 event is scheduled to take place in Baltimore.
The increase is about 26% using the rounded totals supplied by Stock. He said the rise was expected and should not be treated as proof that AI is producing a flood of security papers. As a comparison, he pointed to NDSS, where submissions rose from 694 in 2024 to 1,311 in 2025 and 1,481 in 2026.
How is USENIX Security handling AI-related paper submissions?
Its approach focuses on failures that can be checked. A USENIX Security ’26 transparency report, described by The Register, said organizers built tooling to pull citations from submitted PDFs, query databases including DBLP and arXiv, and manually verify references that appear invalid.
The stated enforcement line is three or more nonexistent references. The conference rejected 21 of 1,181 first-cycle submissions under that rule, or 1.78%, according to the report. Stock said organizers could not establish that the repeated false citations were generated by AI, but judged the papers unsuitable for review.
More than 100 additional papers had at least one citation reviewers could not verify. Organizers did not pursue those cases further because some could result from spelling variations or missing records, and because a broader investigation would add to staff workload. That choice makes the system a triage mechanism, not a comprehensive detector of AI-assisted writing.
The conference permits limited use of AI to polish text written by people, according to the reported policy. It draws a line at using AI to assemble bibliographies, where invented citations can make a paper’s literature review unreliable.
Why are AI-written reviews prohibited?
Stock said program-committee members were told not to use AI services to write reviews, particularly because submitted papers are confidential. When organizers found a small number of cases in which they were sufficiently confident that AI had been used, five of 496 reviewers were told to stop participating. Authors affected by those reviewers could resubmit.
Stock said USENIX Security has not found evidence that fully AI-generated submissions have become a significant problem for the security-research community. AI may still have been used in portions of papers, a distinction that leaves the conference policing verifiable misconduct rather than attempting to ban assistance tools outright.
This story draws on original reporting from The Register.