Lisbon, July 6 - 10, 2026

11th IEEE European Symposium on Security and Privacy

About the Keynote Speakers


Srini Devadas

PAC Privacy and Automatic Black-Box Privatization

Srini Devadas

Srini Devadas is the Webster Professor of EECS at the Massachusetts Institute of Technology, where he has been on the faculty since 1988. His current research interests are in computer architecture, computer security, and applied cryptography.

In 2021, he received the IEEE Cybersecurity Award for Practice, and the ACM SIGSAC Award for Outstanding Innovation for his work on secure hardware. He is a Fellow of the ACM and IEEE.

He is a MacVicar Faculty Fellow and an Everett Moore Baker teaching award recipient, considered MIT's two highest undergraduate teaching honours.

Abstract: We present a recently-proposed privacy definition, termed Probably Approximately Correct (PAC) Privacy. PAC Privacy characterizes the information-theoretic hardness to recover sensitive data given arbitrary information disclosure/leakage during/after any processing. Unlike the classic cryptographic definition and Differential Privacy (DP), which consider the adversarial (input-independent) worst case, PAC Privacy is a simulatable metric that quantifies the instance-based impossibility of inference. An automatic analysis and proof generation framework is developed: security parameters can be produced with arbitrarily high confidence via Monte-Carlo simulation for any black-box data processing oracle. We discuss applications of PAC Privacy to side-channel defense, machine learning, and database analytics. We show a post-training algorithm for Large Language Models that can achieve perfect resistance against membership inference attacks on the sensitive training set. We conclude with describing current limitations and remaining challenges.


Sofía Celi

Cryptography we want, Cryptography we're given: lessons from analysing and breaking the systems we deploy

Sofía Celi

Sofía Celi is a Senior Cryptography Researcher at Brave, specializing in privacy-enhancing technologies, post-quantum cryptography, and secure communication systems. She is a member of the Advisory Council at the Open Technology Fund (OTF) and holds leadership roles within the IETF, IRTF, and W3C. Sofía has also provided expert consultations for the United Nations and human rights organizations.

As a co-founder of Criptolatinos and Women in Cryptography, Sofía is committed to fostering diversity in cryptography and security. She is actively engaged in the academic community, serving as a member of the Latincrypt Steering Committee, Publicity Co-Chair of the PETS Symposium, IACR ePrint Co-Editor, and IEEE Security & Privacy Ethics Co-Chair.

Sofía has received two Distinguished Paper Awards at IEEE S&P and NDSS, was a runner-up for the Best Paper Award at ESORICS and for the Pwnie Award.

Abstract: As a community, we often adopt cryptography for mostly two very different reasons. First, because sometimes we need and want it: end-to-end encryption for systems like Matrix, where it is built from the bottom up because users and communities need ways to safely send messages. Second, and, increasingly, we are given it (systems to attest identity in zero-knowledge, age verification or proof of personhood), which are often required and deployed from the top down, not because communities explicitly asked for them but because policy demands some property.

In this talk, we will examine systems from those two worlds by analysing and breaking them in theory and in practice: the practically-exploitable flaws in the Matrix protocol, soundness failures in zero-knowledge attestation (zkAttest), and weaknesses in ZK-based login (zkLogin). The aim of analysing is not only to show how the systems break, but to ask why they were proposed in the first place and what their failures have in common. Concretely, cryptography we need and want tends to fail in ways we can find and fix; cryptography we are given tends to fail structurally, because it fails to ask its societal implications, the needs of communities and the overall environment and requirements in which it lives. The deeper cost, then, is not technical but societal: it quietly determines who is trusted, who is attested, and who is left out: choices rarely examined before a system ships, and that tend to fall hardest on those with the least say in it. In this talk, we will argue that we need cryptography and systems grounded in the needs of communities and the environment in which they live.