Skip to content
Cyber Science Lab
2025

The 2nd International Workshop on Autonomous Cybersecurity (AutonomousCyber 2025)

September 25, 2025 Université de Toulouse, Toulouse, France

Co-located with ESORICS 2025. 24 submissions, 7 accepted papers, proceedings published by Springer LNCS.

View proceedings & links

Overview

The 2nd edition of AutonomousCyber represents a significant milestone in advancing research and development in autonomous cybersecurity. Following the success of our inaugural event, AutonomousCyber 2024, at the 31st ACM Conference on Computer and Communications Security (ACM CCS 2024) on October 18, 2024, in Salt Lake City, U.S.A., this edition was hosted at ESORICS 2025, a premier venue for security and privacy research.

The evolution from AI-assisted security tools to fully autonomous cybersecurity systems is crucial as cyber threats become increasingly sophisticated. Unlike automation, true autonomy in cybersecurity involves continuous learning, self-improvement, and proactive threat mitigation. This workshop explored the latest advancements in self-reliant cybersecurity systems, integrating Artificial Intelligence (AI), Machine Learning (ML), Quantum Machine Learning (QML), and Reinforcement Learning (RL) in cybersecurity automation for proactive cyber defence.

Key characteristics of autonomous cybersecurity systems

  • Self-improving — unlike mere automation, autonomous cybersecurity applications can improve themselves without manual intervention, adapting to new threats and changes in the environment.
  • Continuous learning — autonomous cybersecurity systems continuously learn from new data, making these systems more resilient and adaptable.
  • Predictive capabilities — with autonomy, these systems not only react but also predict and prepare for potential future threats based on evolving patterns and behaviors.
  • Automatic customization and personalization — autonomous systems can tailor their responses and strategies based on specific network environments and threat models.

Topics of interest

Foundational and theoretical advances

  • Cognitive models for enhancing threat intelligence
  • Principles and theory of self-learning cybersecurity systems
  • Advances in QML for proactive cyber defence
  • Human–machine teaming for cyber resilience

Autonomous cybersecurity techniques & methods

  • AI-driven threat detection and mitigation algorithms
  • Development of simulators for testing autonomous security systems
  • Architectural innovations for adaptive and self-improving cybersecurity
  • Predictive modeling and proactive defense strategies

Practical applications and case studies

  • AI-based automated patch management and incident response
  • Autonomous digital forensics and independent security investigations
  • Real-world implementations and lessons learned from deployed autonomous security solutions

Ethical, legal, and operational considerations

  • Regulatory challenges of deploying autonomous cybersecurity systems
  • Ethical considerations in self-adaptive AI-driven cyber defenses
  • Continuous compliance monitoring with AI-driven systems

Programme — 25 September 2025

Held at Université de Toulouse in Toulouse, France, alongside ESORICS 2025.

Session 1 · 09:00–10:30

  • Welcome and Opening Remarks
  • Paper 1 — ACSE-Eval: Can LLMs threat model real-world cloud infrastructure? — Sarthak Munshi, Swapnil Pathak, Sonam Ghatode, Thenuga Priyadarshini, Dhivya Chandramouleeswaran, Ashutosh Rana
  • Paper 2 — Adversarial Evasion against Autonomous Cyber Defence Agents — Melanie Meijer, Sanyam Vyas, Vasilios Mavroudis, Marc Juarez
  • Paper 3 — Knowledge Retention for Generic Reinforcement Learning Policies in Autonomous Cyber Defence — Joshua Sylvester, Rogério de Lemos
  • Paper 4 — Automated Cyber Defence with Reinforcement Learning in Multi-Attack Environments — Joshua Sylvester, Rogério de Lemos

Coffee Break · 10:30–10:50

Session 2 · 10:50–12:20

  • Paper 5 — An Explainable Multimodal Framework for Phishing Attack Detection — Shokooh Khandan, Mohammadreza Tabatabaei, Ifeanyi Bryan Uzoatu, Olamide Jogunola, Yakubu Tsado, Tooska Dargahi
  • Paper 6 — Risk-Aware SOC Alert Handling in Adaptive Cyber Defense with Reinforcement Learning — Sajad Homayoun
  • Paper 7 — Leveraging Large Language Models in Post-Exploitation: Navigating the Cyber Kill Chain with AI-Driven Tactics — Dean Benson, Christo Panchev
  • Closing Remarks

Lunch Break · 12:20–13:50

Proceedings

The proceedings of AutonomousCyber 2025 were officially published by Springer LNCS: https://link.springer.com/book/10.1007/978-3-032-16165-9. The edition received 24 submissions, with 7 accepted papers, and attracted around 50 participants.

Committee

Workshop Chairs: Ali Dehghantanha, University of Guelph, Canada; Reza M. Parizi, Kennesaw State University, USA; Gregory Epiphaniou, University of Warwick, UK.

Publication Chair: Abbas Yazdinejad, University of Toronto, Canada.

Publicity Chairs: Tooska Dargahi, Manchester Metropolitan University, UK; Tao Li, City University of Hong Kong.

Program committee

  • Ehab Al-Shaer, Carnegie Mellon University, USA
  • Benjamin C. M. Fung, McGill University, Canada
  • Andy Applebaum, Apple Inc, USA
  • Melody Wolk, Apple Inc, USA
  • Patrick Dwyer, Apple Inc, USA
  • Vasilios Mavroudis, Alan Turing Institute, UK
  • Chris Hicks, Alan Turing Institute, UK
  • Z. Morley Mao, University of Michigan, USA
  • Derrick Sturisky, Quantum Computing Inc., USA
  • Mohammad Hamoudeh, King Fahad University of Petroleum and Minerals, Saudi Arabia
  • Malka Halgamuge, RMIT University, Australia
  • Andrew Hamilton, Cybriant, USA
  • Alireza Jolafai, Flinders University, Australia
  • Vasilis Katos, Bournemouth University, UK
  • Ryan K. L. Ko, University of Queensland St Lucia, Australia
  • Georgios Loukas, University of Greenwich, UK
  • Haider Al-Khateeb, Aston University, UK
  • Carsten Maple, University of Warwick, UK
  • Nick Pitropakis, Edinburgh Napier University, Scotland
  • Ahmad Ridley, Laboratory for Advanced Cybersecurity Research, USA
  • Ali Safaa Sadiq Al Shakarchi, Nottingham Trent University, UK
  • Jeff Schwartzentruber, eSentire Inc, ON, Canada
  • Andre Weimerskirch, Lear Corporation, USA
  • Kaiwen Zhang, École de technologie supérieure, Canada
  • Xiaojie Zhu, KAUST, Saudi Arabia
  • Venkata Gopi Kolla, Salesforce Inc, USA

Workshop history

The 1st edition of the AutonomousCyber workshop was held in conjunction with the 31st ACM Conference on Computer and Communications Security (ACM CCS 2024) on October 18, 2024, in Salt Lake City, U.S.A., attracting researchers and practitioners focusing on autonomous cybersecurity, AI-driven threat detection, and self-learning security mechanisms.

Sponsorship

Avaly.ai logo

Avaly.ai