IEEE S&P 2027 — 48th IEEE Symposium on Security and Privacy
by IEEE Computer Society Technical Community on Security and Privacy
"Oakland" moves to Montreal — top-tier security research with three AI-security workshops.
About This Event
The 48th IEEE Symposium on Security and Privacy, long known as "Oakland", runs 17-20 May 2027 in Montreal, Canada, with the main symposium on 17-19 May and the workshop day on 20 May. It is chaired by Adam Aviv (George Washington University), with vice chair Daniel Zappala (Brigham Young University) and program chairs Michelle Mazurek (University of Maryland) and Nicolas Papernot (University of Toronto, Vector Institute and Google DeepMind), and is sponsored by the IEEE Computer Society's Technical Community on Security and Privacy in cooperation with the International Association for Cryptologic Research. The call solicits applied cryptography, network and cloud security, malware analysis, formal verification and privacy-enhancing technologies, and names four machine-learning areas outright: confidentiality and privacy in ML systems, integrity and availability of ML systems, novel attacks on ML systems, and verifying the security and privacy properties of ML algorithms.
Key Dates & Deadlines
- Cycle 1 — notification of acceptance
- Cycle 1 — shepherd submission deadline
- Cycle 1 — camera-ready deadline
- Cycle 2 — abstract registration deadline
- Cycle 2 — paper submission deadline
- Cycle 2 — early-reject notification
- Cycle 2 — reviews released to authors
- Cycle 2 — rebuttal text due
- Cycle 2 — notification of acceptance
- Cycle 2 — shepherd submission deadline
- Cycle 2 — camera-ready deadline
At a Glance
- Date
- May 17–20, 2027
- Location
- Montreal, Canada
- Format
- In-Person
- Event Type
- Conference
- Status
- Upcoming
- Pricing
- Paid
- Organizer
- IEEE Computer Society Technical Community on Security and Privacy
- Added
- Aug 23, 2026
- Updated
- Aug 23, 2026
Topics & Focus Areas
Who Should Attend
- ✓CISOs
- ✓Heads of AI security
- ✓Security architects
- ✓Privacy engineering leads
- ✓Application and product security researchers
- ✓Trust and safety leaders
Why Attend
Oakland is where the attacks your AI platform will face in two years get published today: the 2027 call names novel attacks on ML systems and the verification of ML security properties as first-class topics, and the workshop day carries SAGAI on secure agents for generative AI plus AVID on assurance and verification of AI development. For a CISO, a head of AI security or a privacy engineering lead, four days in Montreal is the earliest reliable read on adversarial ML, agent security and privacy-enhancing technology — from the researchers who will publish both the disclosures and the defences — with the adversarial-ML community's leading names running the programme.
Event Features
- ✓SAGAI — Secure Agents for Generative Artificial Intelligence workshop
- ✓AVID — affiliated Workshop on Assurance and Verification of AI Development
- ✓ArtSec — Workshop on Artwork Security and Provenance in the Age of AI
- ✓LangSec — the 12th Workshop on Language-theoretic Security
- ✓ConPro (Technology and Consumer Protection), CyberBio, MetaCRiSP and Data4SoftSec workshops
- ✓Two submission cycles a year with an early-reject stage and an interactive rebuttal period
What Makes This Unique
- ★The programme is co-chaired by Nicolas Papernot (University of Toronto, Vector Institute, Google DeepMind), a principal author in adversarial machine learning — AI security is structural here, not a bolted-on track.
- ★The 20 May workshop day carries three AI-specific workshops: SAGAI on secure agents for generative AI, the affiliated AVID on assurance and verification of AI development, and ArtSec on artwork security and provenance in the age of AI.
- ★Two review cycles per year with an early-reject stage and an interactive rebuttal period, so the accepted set reflects current work rather than year-old submissions.
- ★Run in cooperation with the International Association for Cryptologic Research, which pulls in the applied-cryptography community alongside systems security.
- ★The 2027 edition moves to Montreal, putting the symposium in a different research ecosystem from its long-running Bay Area base.
Industries Represented
Pricing Details
Registration rates for IEEE S&P 2027 are not published as of 23 August 2026 — the site currently carries the calls for papers and the workshop line-up only. Note that the main symposium runs 17-19 May with a separately-scheduled workshop day on 20 May, so a full trip is four days.
Organizer
IEEE Computer Society Technical Community on Security and Privacy
ieee-security.org/Frequently Asked
- When is IEEE S&P 2027?
- IEEE S&P 2027 takes place May 17–20, 2027 in Montreal, Canada.
- Where is IEEE S&P 2027 held?
- IEEE S&P 2027 is held in Montreal, Canada. The event format is in-person.
- What is the IEEE S&P 2027 submission deadline?
- The next IEEE S&P 2027 deadline is cycle 1 — notification of acceptance on Sep 11, 2026. Remaining dates: Cycle 1 — shepherd submission deadline — Oct 2, 2026; Cycle 1 — camera-ready deadline — Oct 16, 2026; Cycle 2 — abstract registration deadline — Nov 10, 2026; Cycle 2 — paper submission deadline — Nov 17, 2026; Cycle 2 — early-reject notification — Jan 18, 2027; Cycle 2 — reviews released to authors — Feb 11, 2027; Cycle 2 — rebuttal text due — Feb 16, 2027; Cycle 2 — notification of acceptance — Mar 5, 2027; Cycle 2 — shepherd submission deadline — Mar 26, 2027; Cycle 2 — camera-ready deadline — Apr 8, 2027.
- How much does IEEE S&P 2027 cost?
- IEEE S&P 2027 is paid. Registration rates for IEEE S&P 2027 are not published as of 23 August 2026 — the site currently carries the calls for papers and the workshop line-up only. Note that the main symposium runs 17-19 May with a separately-scheduled workshop day on 20 May, so a full trip is four days.
- Who should attend IEEE S&P 2027?
- IEEE S&P 2027 is aimed at CISOs, Heads of AI security, Security architects, Privacy engineering leads, Application and product security researchers, Trust and safety leaders.
- What topics does IEEE S&P 2027 cover?
- IEEE S&P 2027 covers AI and machine learning security, Adversarial machine learning, Agent security, Privacy-enhancing technologies, Applied cryptography, Network and cloud security, Malware analysis, Formal verification of secure systems.
Sources
This page was written from 4 sources, 1 on domains other than sp2027.ieee-security.org.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Events
Hot Chips 2026 (HC38) — A Symposium on High Performance Chips
Where chip architects disclose next-generation AI silicon in technical detail
Ray Summit 2026
The open-source Ray and vLLM communities, together for the first time
CrowdStrike Fal.Con 2026
Securing the AI Revolution
LEAP 2026
Saudi Arabia's national technology event, in its Year of AI