2026 INTERSCT. Conference on cyber security of Internet-of-Things

Join us at #INTERSCT26, the 2026 INTERSCT. Conference on cyber security of Internet-of-Things on 24 June 2026 at Eindhoven University of Technology on our journey towards an Internet of secure things. During the morning program we focus on its "Design", "Defense", "Attack" and "Governance of Security & Privacy" work packages with presentations by Herbert Bos, Cristiano Giuffrida, Michel van Eeten, Erik Poll, Jerry den Hartog and others and during the afternoon we focus on a number of external factors that influence our cyber security and where invited speakers Damiano Bolzoni, Joe Kiniry, Erik Meijer, and Gül Akcaova will address issues on the future of 'cyber security of AI, AI for cyber security'.

2026 INTERSCT. Conference on cyber security of Internet-of-Things

Schedule changed

Please note that due to the strike of public transport in the Netherlands on 24 June 2026, the schedule of the event has been changed by starting one hour later.

ACCSS General Assembly meeting is NOT cancelled

Although we had to cancel two adjacent meetings, please note that the meeting of the ACCSS General Assembly will be held as planned. The meeting will be in the Reception Room as of 12:30.

Introduction

With the Internet-of-Things (IoT) we are seamlessly connecting the cyber and the physical worlds extending the risk area to safety requiring a broader perspective on security. IoT is turning out to be one of the weakest spots in our infrastructure. With billions and in the near future potentially trillions of devices, the security risks are growing at great rates. Our economic and societal forces are creating a perfect storm, a pervasive infrastructure of trillions of IoT devices which on one hand will oversee our lives and economy, and on the other hand will be completely unmanageable from a security perspective.

To compound the risk, IoT systems are often devised and engineered in places where we have no control on, and unless we want to basically surrender our digital sovereignty by only relying on foreign solutions for our national cyber security, we need to find a way to secure them regardless of provenance and built-in malicious intents.

We cannot secure something we cannot manage, we need to rethink the security paradigm, delegating part of the security management to the system that needs to autonomously adapt to the changing environment, while remaining under our supervision, and rethink accordingly all our security technologies. We need to be able to designdevelop and manufacture IoT systems-of-systems in a fundamentally different way enabling the overall system to become robustresilient and trustworthy, even in the presence of individual IoT devices that are insecure or even compromised in a Zero-trust environment and providing the right ecosystem for their wide adoption within industry. We actually need to be able to design, develop and manufacture new types of IoT devices with security-by-design, privacy-by-design, resilience-by-design and all by-default, robustness and resilience in mind; while continuously preserving all safety requirements, these devices must pro-actively manage their security, actively respond to attacks, recover from attacks, resume and restore themselves to a predefined level of operation following an attack etc.

During the 2026 INTERSCT. Conference on cyber security of Internet-of-Things, on 24 June 2026 at the Auditorium of Eindhoven University of Technology, we will address many of these issues with an impressive line-up of invited speakers, panelists, and moderators. In the morning there will be two series of parallel sessions related to recent and ongoing work in related to to the state-of-the-art of cyber security of Internet-of-Things, During the day there will also be various posters on display. In the afternoon there will be a series of plenary sessions related to upcoming and future developments in the cyber security of Internet-of-Things, with special attention to “cyber security of AI, AI for cyber security.” During the day there will also be ample opportunities for discussions and networking during the networking lunch and the networking reception.

Programme

Please refer to our Live Blog for the latest details.

09:30 - 10:15 Reception + Networking

 

10:15 - 10:15 Opening by prof. dr. Sandro Etalle

Sandro Etalle

Sandro Etalle

Eindhoven University of Technology

10:15 - 11:20 First series of parallel sessions

10:15 - 11:20 Session on WP2 ("Design")

Location: Blauwe Zaal

Moderated by dr. Erik Poll

Programme

  1. Introduction by Erik Poll (RU)
  2. Zahra Hatefi (TU/e) on “The Security Gap: 96% of IoT Repositories on GitHub Ignore Critical Security Concerns
  3. Leonard Tudorache (TU/e) on “Towards Secure IoT Deployments: A DSL and Digital Twin-Based Emulation Platform for Security Verification
  4. Francesco Pizzocolo (TNO) and Peter van Liesdonk (TNO) on “The Product Security Innovation Radar
Erik Poll

Erik Poll

Associate professor at Radboud University Nijmegen

Erik Poll will present an introduction to the objectives and (intermediate) results of WP2 (“Design”) and present some highlights from the revised state-of-the-art report.

Zahra Hatefi

Zahra Hatefi

Eindhoven University of Technology

Title

The Security Gap: 96% of IoT Repositories on GitHub Ignore Critical Security Concerns

Summary

The presentation will focus on investigating the security practices of open-source IoT projects hosted on GitHub, with particular attention to the integration of security mechanisms, vulnerability, and common attack types. The study aims to provide insights into the current security landscape of IoT software and identify opportunities for improving security in future IoT development.

Leonard Tudorache

Leonard Tudorache

Eindhoven University of Technology

Title

Towards Secure IoT Deployments: A DSL and Digital Twin-Based Emulation Platform for Security Verification

Summary

This presentation addresses the challenge of ensuring security throughout the entire IoT system lifecycle, from design-time protocol verification to runtime monitoring, by leveraging Digital Twins and emulation as a unified framework. We propose using emulated IoT environments to validate security properties before deployment, and to continuously simulate and monitor system behavior at runtime, closing the gap between formal verification and runtime operation.

Francesco Pizzocolo

Francesco Pizzocolo

TBO

Title

The Product Security Innovation Radar

Summary

The Brabant House of Cyber (BHoC) is a triple-helix cybersecurity program launched in January 2026, bringing together RTOs, industry, and government across the Brabant high-tech ecosystem. It’s organized around three pillars: talent, innovation, and resilience.
The Innovation Radar is the Pillar’s mechanism for deciding what the ecosystem should tackle together. The premise is that no single organization has full visibility into the shifting product security landscape (CRA, NIS2, software-intensive products, distributed supply chains), so priorities are set collectively rather than unilaterally. It works in three moves: scan emerging themes across the full product lifecycle, prioritize through structured dialogue with industry, research, and regulatory partners, and focus by selecting the highest joint-innovation-potential themes as the foundation for Phase 2.
The process is a structured co-creation funnel. The five domains that emerged are Secure Product Design, Secure Development, Supply Chain Security, Post-Deployment, and Governance, each holding specific themes.

10:15 - 11:20 Session on WP4 ("Attack")

Location: Lecture Hall 4

Moderated by prof. dr. ir. Herbert Bos and dr. Cristiano Giuffrida

Programme

  1. Introduction by Cristiano Giuffrida
  2. Ruida Zhou (VU) on “Structured Program Generation for CPU Fuzzing
  3. Jai Wientjes (TU/e) on “Characterizing Infrastructure-as-a-Service on Cybercrime Forums
  4. Dyon Goos (VU) on “BaseLLayer: Exploring the Layer-2 Attack Surface of Cellular Protocols
Herbert Bos

Herbert Bos

Full professor at Vrije Universiteit Amsterdam

Herbert Bos and Cristiano Giuffrida will present an introduction to the objectives and (intermediate) results of WP4 (“Attack”) and present some highlights from the revised state-of-the-art report.

Cristiano Giuffrida

Cristiano Giuffrida

Associate professor at Vrije Universiteit Amsterdam

Herbert Bos and Cristiano Giuffrida will present an introduction to the objectives and (intermediate) results of WP4 (“Attack”) and present some highlights from the revised state-of-the-art report.

Ruida Zhou

Ruida Zhou

Vrije Universiteit Amsterdam

Title

Structured Program Generation for CPU Fuzzing

Summary

Modern processors are susceptible to a variety of vulnerabilities that can be used to break the security guarantees of software and are notoriously difficult to patch. This has led to a growing interest in applying fuzzing techniques, which have proven effective on software, to CPU designs at the pre-silicon stage. However, CPU simulations are a very peculiar fuzzing target: they don’t “crash” on errors, they take ridiculously long to execute, and they accept a very specific type of input — programs. This requires developing new strategies that are tailored to this target.

In this talk, we discuss in particular the problem of generating complex, valid, and interesting programs as inputs for these fuzzers. While most current approaches use mutational fuzzing in the hope of generating interesting inputs, we explore the generational approach, which is fit for both pre- and post-silicon fuzzing.

Jai Wientjes

Jai Wientjes

Eindhoven University of Technology

Title

Characterizing Infrastructure-as-a-Service on Cybercrime Forums

Summary

We explore how Infrastructure-as-a-Service appears on cybercrime forums and how these services can be divided into different layers. We examine the products offered and their promoted capabilities, with a particular attention to the role of bulletproof hosting and what distinguishes it from other infrastructure services.

Dyon Goos

Dyon Goos

Vrije Universiteit Amsterdam

Title

BaseLLayer: Exploring the Layer-2 Attack Surface of Cellular Protocols

Summary

Mobile phones are integrated parts of today’s society. To connect to cellular services, they use specialized baseband processors that expose a large attack surface due to their wireless nature and support for multiple cellular generations. Over the last decade, security research has shown multiple previously unknown vulnerabilities originating from the latest cellular generation (5G) to even the earlier cellular generation (2G), potentially allowing for remote code execution.

Two prominent tools for vulnerability discovery are Over-The-Air testing and Firmware Emulation. However, as we will show, current state-of-the-art work tends to focus primarily on the upper layer (Layer-3) of the protocol stack, either completely ignoring the lower layers (Layer-1 and Layer-2) or only providing limited testing support.

In this talk, we will discuss the layered structure of cellular protocols and how BaseLLayer allows us to leverage the FirmWire emulator to inject into Layer-2 of these protocols. To illustrate the shortcomings of prior work we will use a real-life vulnerability found by BaseLLayer. Lastly, we will discuss how this approach allows us to simultaneously fuzz-test Layer-2 and Layer-3 baseband messages.

11:20 - 11:25 Break to change locations/sessions

11:25 - 12:30 Second series of parallel sessions

 

11:25 - 12:30 Session on WP3

Location: Lecture Hall 4

Moderated by dr. Jerry den Hartog

Programme

  1. Introduction by Jerry den Hartog (TU/e)
  2. Presentation by Roland van Rijswijk-Deij (UT) on “Understanding the state of IoT-specific vulnerabilities via CVE characterization with LLIoT
  3. Presentation by Iram Bibi (TU/e) on “IoT Attack Classification
  4. Presentation by Susanne Wulz (TU/e) on “A method for extracting knowledge from dark web messages
Jerry den Hartog

Jerry den Hartog

Eindhoven University of Technology

Jerry den Hartog will present an introduction to the objectives and (intermediate) results of WP3 (“Defence”) and present some highlights from the revised state-of-the-art report.

Roland van Rijswijk-Deij

Roland van Rijswijk-Deij

University of Twente

Title

Understanding the state of IoT-specific vulnerabilities via CVE characterization with LLIoT

Summary

This presentation goes into joint work with Tina Rezaei, Suzan Bayhan, Andrea Continella, and Jeroen van der Ham-de Vos on LLIOT, a novel and LLM-assisted approach for systematically and automatically distinguishing IoT-specific CVEs at a large scale.

Following the expansion of IoT systems, spanning from devices to cloud backends, reported IoT CVE vulnerabilities have increased at an alarming pace. Since most IoT attacks exploit known vulnerabilities, understanding known vulnerabilities is vital for defense and security research. In this work, we systematize the prior research on studying IoT vulnerabilities, revealing the absence of consistent IoT definitions, reliable and scalable classification methodologies, and high-quality IoT CVE datasets. To overcome these limitations, we design LLIoT, a novel and LLM-assisted approach that systematically and automatically distinguishes IoT-specific CVEs at large scale, enabling in-depth understanding of IoT vulnerabilities. First, leveraging the systematization knowledge from the literature, we derive a four-layer IoT ecosystem taxonomy and define classification criteria for distinguishing IoT CVEs. Then, using an expert-validated ground-truth dataset, we demonstrate that LLMs can reliably distinguish IoT from non-IoT CVEs with high accuracy of 95%, outperforming humans by avoiding cognitive errors and gaps in domain knowledge. Applying LLIoT to CVEs from 2013–2024, we build a dataset of 15,066 IoT specific vulnerabilities, of which 8,391 are newly classified with respect to previous datasets. Using this dataset, which we share with the research community for further research and reproducibility, we characterize how IoT vulnerabilities differ from traditional IT vulnerabilities. Upon our observation, we provide actionable recommendations for responsible stakeholders.

Iram Bibi

Iram Bibi

Eindhoven University of Technology

Title

IOT Attack Classification

Summary

This presentation goes into Enhancing IOT Attack Classification through domain generalization.
While their distributed and resource constrained nature adds to IoT networks vulnerability to attacks, their heterogeneity with varied hardware configuration, protocols, etc. leads to data in inconsistent formats, with distribution shift and class imbalance all challenging unified anomaly detection solutions. This work aims at a generalized solution to handle data from heterogeneous networks.

The widespread adoption of the Internet of Things (IoT) has revolutionized numerous industries such as healthcare, transportation, and smart homes. However, the rapid deployment of IoT systems and their limited resources, heterogeneity, and security measures make them highly vulnerable to a wide range of cyber-attacks. These attacks can lead to unauthorized access, data breaches, or even complete failure of the operation. IoT devices often generate a mix of high-frequency, low-volume, and event-driven data flows. This mix of traffic patterns contributes to variability, which can make it difficult to identify consistent attack patterns. In this paper, we benchmark three domain generalization algorithms named Group Distributionally Robust Optimization (GroupDRO), ANDMASK, and Mixup to show their generalization capability across different IoT attack datasets. We first transform IoT network traffic data, traditionally presented in tabular format, into images using the Image Generator for Tabular Data (IGTD) and DeepInsight techniques. This conversion process is designed to reveal the latent structures within the data. We perform extensive experimentation using various publicly available datasets, namely Kitsune, MUDScope, ToN_IoT, and IoT_23 focusing on the classification of DoS and scanning attacks. Overall performance is measured using metrics such as accuracy, precision, recall, f1 score, and execution time. The results demonstrate that the GroupDRO algorithm combined with the tabular-to-image conversion technique achieves moderate classification performance even in scenarios where the target domain differs significantly from the source domains, while also highlighting opportunities for further improvement.

Susanne Wulz

Susanne Wulz

Eindhoven University of Technology

Title

A method for extracting knowledge from dark web messages

Summary

This presentation goes into ongoing work on a pipeline for extracting named entities and constructing a knowledge graph from unstructured telegram dark web marketplace messages.

11:25 - 12:30 Session on WP5 ("Governance")

Location: Blauwe Zaal

Moderated by dr. Lorenzo Dalla Corte

Programme

  1. Introduction by Eleni Kosta (TiU) or Michel van Eeten (TUD)
  2. Mattis van ‘t Schip (RU) on “The Interdependence of Things: Digital product interdependencies and European cybersecurity law
  3. Annebel Smit (TUD) on “Not Everything That’s Possible Has Value: The Role of Security and Privacy in the Adoption of Smart Health Technologies in Primary Care
  4. Pratham Ajmera (TiU) and Alicja Kucharska (TiU) on “Complementarity or delegation: A study of the intersection between the AI Act and the Cyber Resilience Act
Lorenzo Dalla Corte

Lorenzo Dalla Corte

Tilburg University

Lorenzo Dalla Corte will present an introduction to the objectives and (intermediate) results of WP5 (“Governance”) and present some highlights from the revised state-of-the-art report.

Mattis van 't Schip

Mattis van 't Schip

Radboud University Nijmegen

Title

The Interdependence of Things: Digital product interdependencies and European cybersecurity law

Summary

Internet of Things devices are the sum of many parts. From cloud services to sensors to mobile applications, Internet of Things devices rely on a host of different technologies, resources, and hardware objects. In this presentation, I share how this interdependence not only shapes the production and functioning of IoT devices, but indeed manifests unique types of cybersecurity risks. I then approach these risks through recent European cybersecurity law.

Annebel Smit

Annebel Smit

Delft University of Technology

Title

Not Everything That’s Possible Has Value: The Role of Security and Privacy in the Adoption of Smart Health Technologies in Primary Care

Summary

This presentation is based on previous research on the adoption of digital health technologies in Dutch primary care. Through interviews with healthcare professionals and digital health marketers, the study explored how factors such as cost, system integration, security, and privacy influence decision-making around digital health tools and services. The findings suggest that trusted certification schemes often play an important role in how security and privacy are evaluated during adoption decisions.

Pratham Ajmera

Pratham Ajmera

Tilburg University

Title

Complementarity or delegation: A study of the intersection between the AI Act and the Cyber Resilience Act

Summary

Products with digital elements (PDEs) incorporating artificial intelligence (AI) are increasingly common. Examples include smart home devices, autonomous vehicles and medical devices with AI functionalities. These technologies raise regulatory concerns, due to their combination of a digital product and an AI system and the different approaches of applicable legal frameworks. In the European Union, PDEs are primarily regulated through the Cyber Resilience Act (CRA), which aims to strengthen the cybersecurity of PDEs in the EU market. The Artificial Intelligence Act (AI Act) aims to foster the development of safe, trustworthy and human-centric AI systems in the EU and it applies to AI systems embedded in PDEs, through its risk-based framework imposing obligations on providers and deployers of high-risk AI systems. Our article examines how the CRA and the AI Act approach cybersecurity and what it means from a regulatory standpoint. It also examines how the frameworks utilise conformity assessments, certifications and harmonised standards, when regulating PDEs with AI components, in the light of the provisions that aim to create a bridge between the frameworks and whether this overlap creates a framework of complementarity or delegation between the CRA and the AI Act.

Alicja Kucharska

Alicja Kucharska

Tilburg University

Title

Complementarity or delegation: A study of the intersection between the AI Act and the Cyber Resilience Act

Summary

See above

12:30 - 13:45 Lunch + Networking

13:45 - 14:30 Public Service Announcements

13:45 - 14:30 Public Service Announcements

Contributions by:

  • CSR by Herbert Bos
  • NWO by Sam Woldringh
  • NCSC on “Research and public-private partnerships in collaboration with the NCSC” by Iris Kartasasmita
  • NCC-NL on “European funding opportunities” by Folkwin Poelman
  • Digital Talent Nederland on “Secure-by-Talent: the driving force behind innovation and cyber resilience” by Alejandra Reynaldos
  • Digital Holland by Martijn Neef
  • Energy Innovation NL by Joline Frens

14:30 - 15:15 Invited Talk by Damiano Bolzoni (Kai) [Remote]

Damiano Bolzoni

Damiano Bolzoni

Kai, Co-founder and CTO

Title

AI for Cybersecurity defenses in the post-Mythos world

Summary

After the Mythos announcement organizations have been scrambling to understand what this means for their vulnerability management programs and how they can effectively operate at machine speed in the same way attackers can do. In this talk we will first discuss the actual impact of Mythos by stripping off all the PR buzz and then address how AI can be applied to vulnerability management programs.

Biography

Dr Damiano Bolzoni holds a PhD in AI applied to network cybersecurity. His career has tracked the full arc of modern AI, from early machine learning methods to the generative AI systems reshaping the industry today. Today, Damiano serves as CTO of Kai, where he leads the technical vision for a platform leveraging generative AI to automate the manual, repetitive workloads that burden cybersecurity teams.

15:15 - 16:00 Invited Talk by Gül Akcaova (SURF)

Gül Akcaova

Gül Akcaova

SURF, Lead Futurist

Title

Securing emerging “things” of the future

Summary

This talk will start with an overview of the cybersecurity trends from the SURF Tech Trends 2026, but are these trends enough to get a hold on the complexity in the field of cybersecurity? During the talk, the complexities of the future will unfold and emerging technologies, and the challenges, will be highlighted. Are we, and will we ever be, ready for the future of ‘cyber security of AI, AI for cyber security’?

Biography

Gül Akcaova is the lead futurist at SURF – the cooperative for ICT in (higher) education and research in the Netherlands, and the National Education & Research Network. She is fascinated by IT innovation in education and research and, in her role, examines how new technologies and emerging concepts affect education and research.

16:00 - 16:30 Break

16:00 - 16:45 Invited Talk by Erik Meijer (Leibniz Labs) [Remote]

Erik Meijer

Erik Meijer

Leibniz Labs, Research Scholar

Title

In Code They Act, In Proof We Trust

Summary

AI agents today execute on blind trust, and the failure modes are already in the headlines: a dealership chatbot agreeing to sell a $76,000 Chevy Tahoe for $1, a coding agent wiping a production database during a code freeze, an “agent skill” quietly installing a keylogger on a developer’s machine. These are not edge cases. They are the predictable consequence of allowing agents to act without any mechanical guarantee of correctness or safety.

Execution is irreversible. You cannot unsend a message, unwire a payment, or un-delete a database. In that regime, permitting an unsafe action costs far more than withholding a safe one, and thus the economically rational choice is to refuse to let agents act on unchecked intent alone.

Automind is an agent harness that enforces this discipline by construction. Before any action runs, the agent must submit its execution plan together with a machine-checkable proof of safety and correctness, written in Universalis, a literate logic programming language designed to be read by humans and verified by machines. A small, auditable checker decides whether the plan is allowed to execute.

By left-shifting the trust boundary, we no longer have to trust the agent’s proposal, or even its proof; only the checker. Policy compliance becomes a static property, established before the first side effect. We can finally demand formal proofs, not vibes, from the agents we deploy.

Biography

Erik Meijer brings a rare combination of technical expertise and people leadership to his latest quest to use formal methods to make agentic AI provably safe. As a renowned computer scientist, entrepreneur, and tech influencer, Meijer has made pioneering contributions to programming languages, compilers, cloud infrastructures, and AI throughout his tenures at Microsoft, Meta (Facebook), Utrecht University, and Delft University of Technology.

17:15 - 18:00 Invited Talk by Joe Kiniry (Sigil Logic)

Joe Kiniry

Joe Kiniry

Sigil Logic, CEO and Chief Scientist

Title

Correct-and-Secure-by-Construction, at Machine Speed: Provably-Secure Systems When Devices Outnumber Engineers a Million to One

Summary

The Internet of Things is no longer just cheap sensors built by firms without a cryptographer on  staff; it is now your car, your pacemaker, and your factory floor — and we have never had the engineers to secure any of it. Security-by-design has been the right answer for twenty years and an unaffordable one for nineteen: formal methods produced genuine assurance, but at a cost only aerospace, defense, and elections would pay. Over the past nine months that economics has inverted. I will describe what my team at Sigil Logic has watched first-hand — AI-driven formal methods and model-based engineering, the NINJA methodology embodied in our HOARDE platform, scaling from reviewing a coding agent line by line to trusting it with hundreds of hours of
rigorous engineering work between check-ins, producing hardware, firmware, and software that is correct and secure by construction and backed by machine-checkable evidence rather than hope. This sharpens the question that INTERSECT performers must reflect upon when moving past this research program: when organizations begin to use AI to build and defend our systems, and when we being to witness applied formal methods deployed at scale and at low cost, where should we
focus our research and engineering effort? I will close with a grand challenge for the field — What we should now build with this power?

Biography

Dr. Joseph Kiniry is the top world expert in rigorous engineering with applied formal methods and model-based engineering—what we call the NINJA methodology today. He has been on over one hundred program committees for top international venues. He has been a keynote speaker a dozens of those conferences as well. He is a Senior member of the IEEE and ACM. ‍

As of September, 2025, he is the co-founder, CEO, and Chief Scientist of Sigil Logic. Sigil Logic exists to bring the NINJA methodology—practical rigorous engineering with formal methods—to
the world. We empower engineers and organizations with AI-driven formal methods and model-based engineering tools that integrate seamlessly into their workflows, amplifying human capability, ensuring correctness and security, and making high-assurance systems achievable
for everyone.

He is also the Principled CEO and Chief Scientist of Free & Fair, a Galois spin-out focusing on high-assurance elections technologies and services. Free & Fair develops elections technologies whose security and architecture are reviewed by the world’s foremost experts in academia and industry. Free & Fair applies the same techniques used to solve problems relevant to national security for the U.S. federal government.

18:00 - 18:00 Closing

Sandro Etalle

Sandro Etalle

Eindhoven University of Technology, Scientific director of INTERSECT

18:00 - 19:15 Network reception

Event

Organiser

Venue

Map