It’s been a busy summer with lots of news:
Weizhou presented ANVIL: Anomaly-based Vulnerability Identification without Labelled Training Data at DIMVA 2026. ANVIL reframes vulnerability detection as anomaly detection, using large language models to identify unusual lines of code without labelled training data. It outperforms state-of-the-art supervised detectors and, when integrated with fuzzers, uncovered two previously unknown vulnerabilities.
Also, Kexin presented LDPKiT: Superimposing Remote Queries for Privacy-Preserving Distillation at IWAPS 2026, co-located with ARES. LDPKiT enables effective knowledge transfer from remotely hosted models while protecting sensitive user data through local differential privacy and a novel query-superimposition technique.
Finally a congratulations to Shaopen Lin, Yuqin Yan and Guozhen Ding on their presentation at Blackhat 2026 on GPUBreach. GPUBreach describes an attack that strings together a RowHammer attack on a GPU and a memory corruption vulnerability in GPU drivers to perform privilege escalation.
Congratulations to all of them!




