Program

Date Time Event
Fri 16 Oct 2026
Holiday Inn Munich – City Center
Room: Forum 7
SECUTE 1  ·  09:00 - 10:00  ·  Chair: Emanuele Iannone (Hamburg University of Technology)
09:00 - 09:10 Day Opening — Welcome
Emanuele Iannone, Hamburg University of Technology
09:10 - 10:00 Keynote
Jürgen Cito | TU Wien, Austria

Jürgen Cito is a Full Professor of Software Engineering at TU Wien, Austria. He received his PhD from the University of Zurich and was a postdoctoral researcher at MIT CSAIL. His research focuses on program analysis and AI-based software engineering, with a particular emphasis on autonomous systems for software development and security. His recent work investigates the capabilities and limitations of large language models in offensive security, including automated penetration testing and the ethical implications of dual-use AI systems.


Language Models as Penetration Testing Agents: Surprising Capabilities and Ethical Dimensions

Large language models (LLMs) have recently shown unexpectedly strong performance in offensive security tasks. In this talk, I present our work demonstrating their effectiveness in concrete scenarios such as privilege escalation and attacks on enterprise networks (e.g., Active Directory environments). To explain these results, we hypothesize why LLMs perform well in this domain and relate these hypotheses to our empirical study of how human penetration testers reason and operate in practice. Finally, I want to discuss the ethical dimension of automated penetration testing: Dual-use concerns have always been central to security research, but become more acute with increasing levels of autonomy. We examine how these concerns manifest in the context of LLM-based penetration testing, including questions around responsible disclosure, access, and the broader implications of commoditizing offensive capabilities.


SECUTE 2  ·  10:30 - 12:30  ·  Chair: Emanuele Iannone (Hamburg University of Technology)
10:30 - 10:45 Talk
"Using LLM Agents for Security Testing of Compiled Mobile Applications: A Case Study on a Real-World Compiled iOS App"
Fabian Scherf, Florian Magin (Fraunhofer SIT | ATHENE)
10:45 - 11:00 Talk
"The Role of Prompt Patterns in LLM-Based Smart Contract Vulnerability Detection"
Gerardo Iuliano, Dario Di Nucci (University of Salerno)
11:00 - 11:15 Talk
"AutoDriver: Purely Source-based Driver Generation for Standard Library Fuzzing Pipelines"
Vincent Ahlrichs, Florian Kasten, Jonas Bogenberger, Dieter Schuster, Julian Horsch (Fraunhofer AISEC)
11:15 - 11:30 Talk
"Artifacts to Actors: Assessing the Maturity of Software Supply Chain Security Measurement Practices"
Alexis Butler (Royal Holloway University of London), Dan O'Keeffe, Santanu Dash (University of Surrey)
11:30 - 11:40 Talk
"Sentry: Towards a Sound Dynamic Analysis Framework for Hybrid Android Applications"
Jyoti Prakash, Mathias Ransgaard Yde, Miguel Campusano, Abhishek Tiwari (University of Southern Denmark)
11:40 - 12:25 Meeting — The Present and Future of Software Security Testing (Live Collaborative Activity)
12:25 - 12:30 Day Closing — Closing
Emanuele Iannone, Hamburg University of Technology

Full program with up-to-date details also available on the ASE 2026 researchr page.