We are pleased to invite you to the second edition of the workshop on Foundations of Language Model Security: Theory, Practice, and Fundamental Limits (FLMSec). This full-day workshop will be co-located with NeurIPS 2026 in Paris.
Website: https://flmsec.github.io/
LLMs remain vulnerable to attacks such as prompt injections and data poisoning, yet continue to be deployed in complex systems without a clear understanding of why these vulnerabilities arise or how they connect to classical security concepts. At the model level, the lack of a hard separation between instructions and data exposes fundamental attack surfaces; at the system level, confused-deputy patterns and missing trust boundaries introduce further structural weaknesses. While recent work treats LLM security as a system design problem and has achieved provable security in specific settings, the field still lacks formal definitions comparable to differential privacy, and it remains unclear whether the security–utility trade-off seen in current defenses is fundamental or an artifact of current approaches. This workshop aims to consolidate existing knowledge and lay the foundations for future LLM security research by answering three questions:
Q1. Formalizing LLM security. How should LLM security be formalized? Is there an agreed-upon framework comparable to differential privacy for privacy guarantees? What role should theory play in building secure LLM systems?
Q2. Security in practice. Can we design evaluation methodologies that are reproducible and generalizable rather than fragile and hackable? What concrete steps can help escape unproductive cycles of attacks and defenses?
Q3. Fundamental limits of security. Is the security–utility trade-off exhibited by current defenses an artifact of their design, or a fundamental property of any system that achieves meaningful security? Where has provable security already been achieved, and what impossibility results exist?
CALL FOR SUBMISSIONS
We invite non-archival submissions of up to 8 pages (excluding references), formatted using the NeurIPS workshop template, on topics including but not limited to:
Formal frameworks and definitions for LLM security [Q1]
Secure-by-design LLM system architectures [Q1, Q2]
Provable security results and impossibility results for LLM-based systems [Q3]
Design of reproducible, generalizable evaluation methodologies [Q2]
The security–utility trade-off in current and future defenses [Q3]
Model- and system-level attacks and defenses (prompt injection, data poisoning, jailbreaks) situated within a principled security framework [Q1, Q2]
Multi-agent security and worst-case security guarantees [Q2, Q3]
Memorization and privacy in language models [Q1, Q3]
Compositional security: do component-level guarantees hold when models or agents are composed into larger systems? [Q3]
Submissions will be managed through OpenReview. All accepted papers will be presented as posters, with one to two selected for short talks and receiving best paper award. Previously published work is not eligible. In accordance with NeurIPS policy, individuals with a personal conflict of interest with any organizer may not submit. We recommend all authors register on OpenReview at least 2 weeks before the submission deadline.
Accepted work will join a program built around live discussion rather than talk density: following last year’s workshop, we will have five thematic blocks each consisting of a 45-minute keynote with a 30-minute breakout discussion in groups of 10–15, led by discussion chairs. Our keynote speakers are Christian Schroeder de Witt (University of Oxford), Reza Shokri (Google and NUS), Somesh Jha (University of Wisconsin–Madison), and Niloofar Mireshghallah (humans& and CMU). The program also includes a poster session, two spotlight contributed talks, and interactive demos from Julia Bazinska (Lakera AI) and Matthew Maisel (Sondera).
IMPORTANT DATES
All deadlines are 23:59 AoE (Anywhere on Earth).
Submissions open: July 23, 2026
Submission deadline: August 22, 2026
Reviewer bidding: August 22 – 25, 2026
Reviewing period: August 25 – September 25, 2026
Decisions: September 25 – 29, 2026
We look forward to your submissions and to welcoming you to Paris!
The FLMSec organizing committee (Egor Zverev, Maura Pintor, Ana-Maria Cretu, Santiago Zanella-Béguelin, Nicole Nichols, Pavel Laskov)