The 35th USENIX Security Symposium (USS), scheduled to take place next week in Baltimore, Maryland, has recorded an unprecedented number of paper submissions, reaching approximately 3,030 valid papers across two cycles. This marks a significant increase from the previous year's total of around 2,400 submissions. While the rise in submissions is partly attributed to the growing availability of AI tools, conference organizers report that instances of abuse have been minimal due to proactive defensive measures.
Ben Stock, a tenured faculty member at the CISPA Helmholtz Center for Information Security and USS program co-chair, noted that this growth mirrors a broader trend within the security community. He pointed to the Network and Distributed System Security Symposium (NDSS), which saw its paper submissions jump from 694 in 2024 to 1,311 in 2025, and then to 1,481 this year. Stock indicated that the USS program committee was scaled in anticipation of this increase.
A paper published in April, titled "More Versus Better: Artificial Intelligence, Incentives, and the Emerging Crisis in Peer Review," found that since the release of ChatGPT in 2022, major academic journals have experienced a 42 percent increase in submission volume. In response to the proliferation of large language models (LLMs), the USS organizers, including Stock and co-chair Elissa Redmiles, an assistant professor of computer science at Georgetown University, detailed their strategies in the USENIX Security '26 transparency report, issued in January.
The report highlighted an "alarming trend of AI usage in key areas of the scientific process" and outlined actions taken against two specific violations: the inclusion of non-existent or "hallucinated" references, and the use of AI in the paper review process. After identifying and rejecting a paper with fabricated references, the organizers developed tools to extract references from submitted PDFs, query established sources like DBLP and arXiv, and manually verify invalid citations.
Papers containing three or more hallucinated references were rejected. This policy impacted 21 out of 1,181 submissions in the first round, representing 1.78 percent. Stock clarified that while they could not definitively confirm these were AI-generated, such papers were deemed problematic and rejected. The report also noted over 100 additional papers with at least one unconfirmed reference, but these were not further investigated to avoid overburdening staff, acknowledging potential false positives from minor discrepancies.
Conference organizers explicitly prohibit the use of AI for bibliography preparation, emphasizing the importance of halting this trend to preserve scientific integrity. However, limited AI use for refining human-written text is generally permitted, extending to reviewers, with specific limitations.
While no dedicated AI policy was established for reviewers, program committee members were explicitly informed that using AI services to write reviews is not allowed, primarily due to confidentiality concerns. The USS identified a small number of cases where there was sufficient confidence that AI was used in reviews. In these instances, appropriate actions were taken, including the removal of five out of 496 affected reviewers from the committee and allowing affected authors to resubmit their papers.
Despite these measures, Stock stated that there is no evidence to suggest that AI-generated submissions have become a significant challenge for the security community. He acknowledged, however, that AI might have been used in parts of some submissions.






