OPTIMIST Workshop '26
October 11, 2026 Antalya, Turkey
OPTIMIST is a forum for open, reproducible, and community-driven work in implementation security. We aim to make security evaluation more measurable, reusable, and comparable by gathering researchers, practitioners, tool developers, dataset creators, evaluators, and standardization stakeholders in a single forum.
🗓️ Tentative Program
| Time | Event |
|---|---|
| 9:00 - 9:15 | Welcome Remarks Aydin Aysu (NCSU), Fatemeh Ganji (WPI) and Patrick Schaumont (WPI) |
| 9:15 - 10:00 | Invited Talk 1: Nisha Jacob Kabakci (AISEC Fraunhofer) Trust the Design, Verify the Implementation: Security Testing in Open-Source Hardware |
| Session 1: Reproducible Evaluation of Secure Implementations (10:00 - 10:30) | |
| 10:00 | Hossein Abdinasibfar (Tampere University) and Antonis Michalas (Tampere University) HHE-ARENA: Reproducible Cross-Language Benchmarking for Hybrid Homomorphic Encryption |
| 10:15 | Quinten Norga (KU Leuven), Jesse De Meulemeester (KU Leuven), Frank Piessens (KU Leuven), Ingrid Verbauwhede (KU Leuven) and Marton Bognar (KU Leuven) EVAL-HD: Reproducible Hardware Cost Evaluation in Implementation Security |
| 10:30 | Coffee Break |
| Session 2: Side-Channel Analysis, from Assessment to Attack (11:00 - 12:30) | |
| 11:00 | Gijs Burghoorn (Radboud University), Ileana Buhan (Radboud University) and Lejla Batina (Radboud University) Vogls: A Fast Interactive Full-timing Simulator for Pre-silicon Power Side-Channel Analysis |
| 11:15 | Vojtěch Miškovský (CTU Prague), Petr Socha (CTU Prague), Adam Svehla (CTU Prague), Tomáš Přeučil (CTU Prague), David Pokorný (CTU Prague) and Martin Novotný (CTU Prague) TraceXpert: An integrated environment for side-channel data acquisition and analysis |
| 11:30 | Alain Magazin (Ledger, Sorbonne University) and Karim M. Abdellatif (Ledger) Open EM Side-Channel Dataset for ML-KEM (Kyber) Implementations |
| 11:45 | Jimmy Gammell (Purdue University) and Kaushik Roy (Purdue University) A Simple Transformer Pipeline for Full-Key Side-Channel Attacks on Uncropped Datasets |
| 12:00 | OPTIMIST Q&A: Moving Forward as a Community |
| 12:30 | Lunch Break |
| 13:30 - 14:30 | Invited Talk 2: Lennert Wouters (KU Leuven) and Ondřej Staníček (Tropic Square, CTU Prague) Open Samples, Open Findings: Fault Injection Evaluation of the TROPIC01 Secure Element |
| Session 3: Open Resources for Leakage Assessment (14:30 - 15:00) | |
| 14:30 | N Eswari Devi (SETS), Surya K (SETS), Renita J (SETS) and Suganya Annadurai (SETS) Open Datasets for Security Assessment of Cryptographic and AI Implementations |
| 14:45 | Aakash Chowdhury (University of Klagenfurt) An Open Artifact for Multivariate Leakage Detection |
| 15:00 | Coffee Break |
| Session 4: Hardware Design and Physical-Security Testing (15:30 - 16:00) | |
| 15:30 | Fatemeh Khojasteh Dana (WPI), Kyle Mitard (WPI), Saleh Khalaj Monfared (WPI), Mehmet Ali Cetin (WPI) and Shahin Tajik (WPI) TOPS: A Toolkit for Physical Security Testing of Hardware Sensors |
| 15:45 | Selim Kirbiyik (TU Graz), Maciej Czuprynko (TU Graz), Florian Krieger (TU Graz), Florian Hirner (TU Graz) and Sujoy Sinha Roy (TU Graz) LIMON: Large-Integer Montgomery Modular Multiplier Generator |
| 16:00 - 17:15 | Panel on From Platform to Ecosystem: Open Governance for Specializable Implementation Security with Jan Bělohoubek (Tropic Square and CTU Prague), |
| 17:15 - 17:30 | Closing Remarks |
🎤 Invited Speakers

Dr.-Ing. Nisha Jacob Kabakci studied electrical engineering in Bangalore and embedded systems at Università della Svizzera italiana in Lugano, complemented by a practical year in cryptography at Nanyang Technological University in Singapore. Since joining Fraunhofer AISEC, she has conducted research on the security of embedded systems with a focus on FPGAs, during which she completed her Ph.D. at the Technical University of Munich in 2020. She is currently Head of Department “Hardware Security – Physical Analysis and Countermeasures” at Fraunhofer AISEC.

Lennert Wouters is a hardware security researcher at COSIC, KU Leuven, specializing in embedded and connected devices. His work focuses on reverse engineering, physical attacks, and practical security analysis of real-world systems. His recent projects include developing a modchip for fault-injection attacks on a Starlink user terminal and uncovering vulnerabilities in Saflok hotel locks.

Ondřej Staníček is a PhD student at the Faculty of Information Technology, Czech Technical University in Prague, where he researches side-channel attacks, countermeasures, and the secure design of physical unclonable functions and true random number generators. He also teaches Hardware Security and Computer Structures and Architectures courses, and has studied abroad at the University of Ljubljana and at KU Leuven. Since August 2023, he has been working as a Security Expert at Tropic Square, where he has contributed to the specification, implementation, and security evaluation of the TROPIC01 open-source secure element. He is part of a team dedicated to shifting the semiconductor industry away from security by obscurity toward verifiable transparency, open-source hardware methodologies, and collaborative Coordinated Vulnerability Disclosure (CVD) processes.
🧑⚖️ Panelists

Jan Bělohoubek is an assistant professor at the Faculty of Information Technology, CTU in Prague, and the security team lead at Tropic Square s.r.o. His professional and research focus is the attack resistance of CMOS circuits, including side-channel-resistant design, verification of hardware side-channel attack countermeasures, and the implementation of robust security primitives. He is also passionate about open-source tools for hardware design and verification.

Siemen Dhooghe completed his Ph.D. at KU Leuven/COSIC under the supervision of Vincent Rijmen and Svetla Nikova. At Google, he serves as a hardware security analyst ("pen tester"), assessing Google's physical silicon infrastructure and custom chips against advanced hardware attacks.

Barış Ege is a Security Engineering professional based in Delft, the Netherlands, with extensive experience in hardware and implementation security evaluation. His work focuses on hardware security testing, side-channel analysis, fault injection, and cryptographic implementation assessment within high-assurance evaluation environments. He has been actively involved in the evaluation of secure products and the development of advanced security testing methodologies. Barış is particularly interested in the practical security of cryptographic systems and emerging challenges in hardware security and post-quantum cryptography.

Vincent van der Leest is Director Product Marketing for Security IP at Rambus, where he drives the go-to-market strategy, positioning, and outbound marketing for advanced hardware-based security solutions across semiconductor and data infrastructure applications. Based in the Netherlands, Vincent joined Rambus after previously managing Product & Solutions Marketing for Security IP at Synopsys, following its acquisition of Intrinsic ID. During his more than 14 years at Intrinsic ID, he held leadership roles spanning marketing, research, sales, and business development, helping establish the company as a pioneer in hardware security and physical unclonable function (PUF) technology. With deep expertise in hardware-based security and silicon-level root-of-trust technologies, Vincent has been instrumental in advancing protection mechanisms for semiconductors, AI systems, and IoT devices. Vincent holds a master’s degree in electrical engineering from Eindhoven University of Technology and is a co-author of several granted patents and scientific publications in the fields of security, PUFs, and coding theory.
📢 Call for Contributions
OPTIMIST considers open contributions in implementation security across the physical, microarchitectural, hardware, firmware, software, and system-level spectrum. This includes, for example, reproducible evaluation, interoperable workflows, open benchmarks, AI-enabled security methods, implementation security of AI systems, and post-quantum cryptography implementations.
Topics of interest include, but are not limited to:
- Open datasets for evaluation of implementation security testing methods, including methods to find sidechannel leakage and fault vulnerabilities at various abstraction levels, especially in new cryptographic standards and AI implementations;
- Open-source tools for measurement, analysis, verification, simulation, benchmarking, reverse engineering, artifact evaluation, and AI-enabled implementation-security workflows;
- Reference implementations in hardware and software, firmware libraries, AI accelerators, test platforms for reproducible security evaluation;
- Specifications, APIs, hardware interfaces, data formats, and documentation practices that support interoperable and reproducible security evaluation workflows;
- Standardization, certification, and benchmark-development efforts for implementation security evaluation;
- Case studies, demonstrations, and lessons learned from using open datasets, tools, platforms, specifications, or implementations;
OPTIMIST supports two presentation formats for accepted contributions.
- Talks and demos. 15-minute presentations or demos on one of the topics of interest listed above.
- Interactive discussions. 15-minute moderated sessions seeking feedback on, e.g., an open issue, proposed direction, specifications, or community need where discussion is the main goal rather than presentation of completed work.
✅ Selection Criteria
The program committee will select contributions based on fit with OPTIMIST and their potential to stimulate useful discussion among OPTIMIST attendees. Submissions will be evaluated based on one or more of the following criteria:
- Relevance to open and reproducible implementation security;
- Availability of open-source implementation;
- Clarity of the artifact, dataset, tool, interface, specification, or methodology;
- Potential to support comparison, benchmarking, reuse, or standardization;
- Quality of documentation, reproducibility support, and stated assumptions;
- Potential to stimulate discussion, collaboration, or community coordination;
📩 Submission Format
OPTIMIST welcomes archival and non-archival contributions. Each submission should clearly describe what will be presented and why it is relevant to OPTIMIST.
- For artifact submissions, authors should describe the artifact’s purpose, expected users, setup requirements, assumptions, limitations, and availability.
- For datasets, authors should additionally describe the collection procedure, metadata, intended use, known limitations, and possible evaluation tasks.
- For tools, authors should further describe the supported workflow, inputs and outputs, interfaces, reproducibility support, and comparison with related tools.
Submissions will undergo double-blind review. Submissions can use Anonymous Github for easy blinding of author names on existing repositories. After acceptance, authors may update the submission to include public, non-anonymous artifact links. Submissions should follow Springer’s Lecture Notes in Computer Science format and may be up to 5 pages, including references. Accepted contributions will be bundled and made available on the OPTIMIST website.
🤓 Organizers
- Aydin Aysu (North Carolina State University)
- Fatemeh Ganji (Worcester Polytechnic Institute)
- Patrick Schaumont (Worcester Polytechnic Institute)
😎 Technical Program Committee
- Karim M. Abdellatif (Ledger)
- Evan Apinis (zeroRISC)
- Ro Cammarota (University of California, Irvine)
- Gaëtan Cassiers (CryptoExperts & UCLouvain)
- Zhimin Chen (Tenstorrent)
- Helena Handschuh (SCI Semiconductor)
- Jan Jancar (Paderborn University)
- Emre Karabulut (Microsoft)
- Johann Knechtel (New York University, Abu Dhabi)
- Karel Kral (Google)
- Daniel Page (University of Bristol)
- Jade Philipoom (zeroRISC)
- Markku-Juhani O. Saarinen (Tampere University)
- Pascal Sasdrich (Ruhr-Universität Bochum)
- Peter Schwabe (Max Planck Institute for Security and Privacy & Radboud University)
- Mirjana Stojilovic (EPFL)
- Dean Sullivan (University of New Hampshire)
- Pirmin Vogel (lowRISC)
- Trevor Yap (Nanyang Technological University)
📅 Timeline
June 21, 2026— Submission deadline Extended to July 15, 2026!August 1, 2026— Acceptance Notifications Updated to August 21, 2026!August 15, 2026— Program Announcement Updated to August 21, 2026!