Call for Papers

New from last year

We have introduced some new additions compared to last year:

  • Introduced Abstract Registration Deadline
  • Requirement to release artifacts at submission, unless a valid reason is provided
  • Revised review process: introduced initial review phase (inspired by PETS), and Area Chairs to support the review process
  • Requirement for ORCID and Author Certification by the abstract registration deadline
  • Added section in CfP “Planning for growth in submissions”
  • Introduced clarifications on: scope of SoK papers, attendance policy, conflict of interest policy
  • “Best paper award” is now called “Distinguished paper award”; the “Major Revision” outcome is now called “Revision”

Areas of interest

IEEE SaTML expands upon the theoretical and practical understandings of vulnerabilities inherent to machine learning (ML), explores the robustness of learning algorithms and systems, and aids in developing a unified, coherent scientific community aiming to establish trustworthy machine learning. Topics of interest include (but are not limited to):

  • Novel attacks on machine learning
  • Novel defenses for machine learning
  • Secure and safe machine learning in practice
  • Verification of algorithms and systems
  • Machine learning system security
  • Privacy in machine learning
  • Forensic analysis of machine learning
  • Fairness and interpretability
  • Trustworthy machine learning in cybersecurity applications
  • Trustworthy data curation

Scope and Initial Review

SaTML is the home for work on safe and trustworthy machine learning, theoretical, empirical, or applied alike. The guidelines below explain what we look for at initial review (see “Reviewing Process”). If you are unsure whether your paper fits, ask the PC chairs before the abstract registration deadline.

  • We look for substantive engagement with safety and trustworthiness, developed throughout the paper rather than stated only in the introduction.
  • Theoretical contributions are welcome. A brief discussion of what the results imply for real systems or threat models could help reviewers place the work.
  • Empirical papers should make clear which safety or trustworthiness question the evaluation answers.
  • Papers whose only link to the area is incidental, such as using a particular dataset without engaging deeper into trustworthiness, are likely to be desk rejected.

Important dates

The main dates for SaTML 2027 are listed below. Please also see the "Planning for growth in submissions" section, which describes the circumstances under which this timeline may need to be adjusted.

  • Mandatory abstract registration deadline: Tue, Sep 22, 2026
    • Tentative non-blank title, tentative non-blank abstract, fixed authors, and fixed topics (bidding may start at abstract registration; hence, no substantial changes are allowed to abstract or title)
  • Paper submission deadline: Tue, Sep 29, 2026
    • Anonymized artifact(s) updated by: Fri, Oct 2, 2026
  • Early reject notification: Wed, Nov 4, 2026
  • Interactive discussion & revision phase: Wed, Nov 25, 2026 - Wed, Dec 9, 2026
  • Decision notification: Wed, Dec 16, 2026
    • Final artifacts (of accepted papers) on Zenodo due by: Thu, Jan 14, 2027
  • Revisions due by: Thu, Jan 21, 2027
  • Revision notification: Mon, Feb 1st, 2027
    • Final artifacts (of accepted revised papers) on Zenodo due by: camera-ready deadline
  • Camera-Ready Paper Submissions and Copyrights Due: mid-Feb 2027 (exact date TBC)
  • Conference dates: Early May, 2027

All deadlines are set to 11:59 PM AoE (Anywhere on Earth), which corresponds to UTC-12 time zone.

Submission categories

We solicit research papers, systematization of knowledge papers, and position papers:

  • Research Papers: These papers should present new work, evidence, or ideas related to secure and trustworthy machine learning. Submission must be up to 12 pages of body text. Research papers must be well-argued and worthy of publication and​ ​citation,​ ​on​ ​one of the​ ​topics listed​ ​above.​ See the “Areas of interest” section for more information on the scope of the CfP.

  • Systematization of Knowledge (SoK) Papers: These papers should either consolidate and clarify ideas in a major research area within secure and trustworthy machine learning or provide compelling evidence to support or challenge long-held beliefs in such areas. SoK papers go beyond simply summarizing previous research (as in a survey). They also include a thorough examination and analysis of existing approaches (in some cases, even experimentally), identify gaps and limitations, and offer insights or new perspectives on a major research area. For examples, please see the list of SoK papers at oaklandsok.github.io. Submissions must be up to 12 pages of body text.

    • SoK papers must include "SoK:" at the beginning of their title.
  • Position Papers: These papers should cover broader issues and visions related to secure and trustworthy machine learning, including open challenges, technical perspectives, educational aspects, societal impact, or notable research results. Submissions must be very well-argued and consist of 5 to 12 pages of body text.

    • Position papers must include "Position:" at the beginning of their title.

⚠️ "New Insights” HotCRP section: SoK and Position paper submissions will be required to summarize their "new insights" in a dedicated HotCRP submission field (e.g., 300 words), to support the initial review phase. For SoK papers, this field should highlight the novelty and significance of the insights derived from the systematization. For Position papers, it should summarize the key position(s), the prior assumptions they challenge, and the impact they may have on the community.

There is no limit on references and appendices. However, reviewers are not required to read appendices, and papers are assessed on the body text. Do not rely on an appendix to carry a claim that is central to the paper.

Submission information

All submissions must be received by 11:59 PM AoE (UTC-12) on the day of the deadline. The submission site is available here: Submission Link TBC

  • Policy against double submissions: Submitted papers must not substantially overlap with papers that have been published or accepted for publication, or that are simultaneously under submission to a journal, conference, or workshop with published proceedings. If the paper is already under review elsewhere, authors may still register the abstract at SaTML, but they must not submit the full paper unless that other submission has been resolved (rejected or withdrawn) by the SaTML paper submission deadline. Violations of this policy count as "double submission" and will be reported to IEEE.

  • ORCID: All authors MUST provide their ORCIDs through the profile page on HotCRP by the abstract registration deadline.

  • Author Certification: All authors MUST confirm the submission terms within HotCRP via the Author Certification field by the abstract registration deadline.

  • Double-blind review: SaTML follows a double-blind reviewing process. Submitted papers must be properly anonymized! They must (a) omit any reference to the authors' names or their institutions, and (b) cite the authors' own related work in the third person. It is important, however, to ensure that efforts to maintain anonymity do not compromise the quality of the submission or complicate the review process. Essential background references, for example, should not be omitted or anonymized. Even if a paper is anonymised, it should not make statements such as "our artifacts are already available as open source tools", as it may deanonymize them. In general, any material referenced in the paper should be anonymized, and de-anonymization through additional material such as artifacts are grounds for rejection. Please see this double-blind FAQ for the answers to many common concerns about double-blind reviewing.

  • Preprint/disclosure policy: Authors may choose to give talks about their work, post a preprint of the paper online, and disclose security vulnerabilities to vendors. However, authors should take care of avoiding behaviors that intentionally aim to inform reviewers of their identity (e.g., publicly advertising their work on social media), as such behaviors may lead to desk rejection of the paper. If in doubt, the authors should contact the PC chairs at pcchairs@satml.org.

  • Previous reviews: For papers that were previously rejected from another conference, authors must append prior reviews to their submission along with a description of how those reviews were addressed in the submission. The reviews must be anonymized, but otherwise unedited and complete. Authors are only required to include reviews from the last time the paper was submitted. Authors who try to circumvent this rule (e.g., by changing the title of the paper without significantly changing the contents) may have their papers rejected without further consideration, at the discretion of the PC chairs.

  • Open Science: All submissions must include an "Open Science" section immediately before the references, which does not count towards the page limit. In it, the authors should describe which artifacts they are releasing, or explain why sharing is not possible. We require all authors to share their artifacts within 3 days after the submission deadline, using a fully-anonymized repository (for example, https://anonymous.4open.science/). After this deadline, the artifact(s) needs to be accessible throughout the review process, and should not be edited. Any violation of the Open Science policy may result in desk rejection. Authors of accepted papers will be required to share their artifacts on https://zenodo.org (see “Important Dates”), and acceptance is conditional on their availability (unless a valid reason is provided). Chairs and reviewers may check that the artifacts are consistent with the claims made in the paper.

  • ⚠️Usage of AI/LLM: If any LLM was used, an "LLM usage considerations" section is required, placed after the Open Science section. See the dedicated section below (“Usage of LLMs”) for what it must contain.

  • Ethical Considerations: Each paper may optionally include an "Ethical Considerations" section, placed immediately before the references. This section does not count towards the page limit. In this section, the authors may discuss if they believe the work poses any ethical risk and the steps that are taken to mitigate such risk, also referring to ethics frameworks such as those offered by the Menlo report. If the authors believe that their work does not pose any ethical considerations, this section is not necessary.

  • Submission template: Submissions must be a PDF file in two-column IEEE proceedings style. That is, authors must use \documentclass[conference]{IEEEtran} when preparing their paper, with the default 10pt font size and page geometry. Using a different template, or modifying font size, margins, or spacing to fit more content, is grounds for desk rejection. The number of allowed pages for a submission depends on the submission category, see above.

Authors need to closely follow these rules and precisely adhere to the format guidelines. Failure to comply with these rules is grounds for rejection.

Usage of LLMs

Authors are permitted to use LLMs when preparing their paper. However, while the conference does not ban authors from using LLMs or researching their security and privacy properties, authors must (a) carefully consider their decision to use LLMs and (b) are required to disclose and motivate the use of LLMs in their submission. If the authors choose to use LLMs in their work, they must use a separate and well-marked section titled “LLM usage considerations” before the references (after Open Science), to make the relevant disclosures. This section will not count towards the page limit.

We ask that authors adhere to three key criteria with regards to their use of LLMs in the scientific process:

  • Accountability and Correctness: Human authors are ultimately responsible for all submitted content and results, ensuring their accuracy, originality, and integrity. Works submitted should constitute self-respecting work that respects the importance of scientific inquiry and integrity and respects the time and energy of reviewers. Authors are responsible for the thoroughness of their literature review and must determine relevant prior work and cite it to ensure proper credit. Upon submitting to SaTML 2027, authors acknowledge that they have reviewed all content that was generated by AI as if they had written it themselves, including text, code, experimental data, and references. Any violation to this policy which results in fabrications or hallucinations, including non-existing references or incorrect authors, invented claims, and falsified results is considered academic misconduct and might lead to the paper being desk rejected or other sanctions. Authors are encouraged to evaluate their submissions using the same open-source tools that we will use (e.g., https://hallucinator.science/). If the authors have used LLMs to improve their writing, they should state: ‘LLMs were used for editorial purposes in this manuscript, and all outputs were inspected by the authors to ensure accuracy and originality.’

  • Transparency: Second, authors should carefully reason about the implications of using LLMs in their work. If LLMs are integral to the paper’s methodology, their use should be explicitly detailed. Any idea generated by an LLM should be independently developed and validated by the authors. Furthermore, authors must elaborate on how they handled limitations introduced in their work by their use of LLMs. Such limitations could for instance include difficulties to obtain results that are reproducible when the LLM used is not open sourced.

  • Responsibility: Third, authors should take care to develop LLMs (and ML models in general) responsibly. Any data collection towards training models should take into account relevant ethical considerations such as consent and data holder rights, including intellectual property. Authors also have to justify the need for the environmental footprint of their experiments to achieve their goals and support their methodology. We recognize calculating such a footprint is a technical challenge in itself. We refer the authors to the work of Lacoste et al. but welcome to hear any other good references (pcchairs@satml.org). We emphasize that the goal here is not to calculate the exact footprint but rather explain experimental choices made as part of the scientific process (e.g., why was an LLM necessary, why was a particular model size selected, how the authors minimized the volume of queries made, which hardware was used to run experiments).

Failure to comply with these rules is grounds for desk rejection without further review of the submission. We note that generative AI technology is rapidly evolving. Authors are encouraged to reach out proactively to the PC chairs should they face uncertainties about the above rules or how they apply to their research.

Reviewing process

All submissions to the conference will be evaluated on their merits, particularly their relevance to the conference's areas of interest, novelty, quality of execution, and presentation.

To manage the reviewing load on PC members, SaTML implements a three-stage reviewing process: initial review, Round 1 reviews, and Round 2 reviews. Papers receiving a Revision decision will be invited to revise and will then be reviewed again.

This year, we are also appointing Area Chairs to help manage the submissions, by coordinating discussions and checking review quality. They can make recommendations for papers, but the final decisions remain up to the Program Chairs. Moreover, they will be a key part of the newly-introduced ‘Initial Review phase’.

⚠️ Initial Review Phase (new): Shortly after the submission deadline, the PC Chairs together with the Area Chairs will review each submission and may desk-reject papers that:

  • violate any of the submission guidelines, for example the anonymity requirements;
  • fall outside the scope and areas of interest listed above;
  • are clearly below the quality standard expected at SaTML.

The PC Chairs will make the final decisions on desk rejections after initial review. While we recognise that a decision taken without full reviews is disappointing for authors, we aim to provide a justification for authors to improve towards passing the bar next time. We consider initial review necessary: submission numbers continue to grow, and reviewer effort spent on papers with no realistic path to acceptance is effort taken away from the papers that have one. Authors who are uncertain whether their work falls within scope are welcome to contact the PC Chairs at pcchairs@satml.org before the abstract registration deadline.

Two review rounds: Papers passing initial review are initially assigned two reviewers (Round 1). If the PC Chairs conclude, on the basis of these initial reviews, that there is no path to acceptance at SaTML, the paper is early-rejected: no further reviews are assigned and the authors are notified that the paper will not be included in the conference. Then there will be a second review round (Round 2), after which the authors will have the chance to interactively discuss with reviewers (see “Author discussion phase” below).

LLMs: We are still considering whether and how to use LLMs as part of the reviewing process, e.g., to offer feedback to reviewers for possible factual errors in their reviews, or check rigour in the paper. In any case, we will make an opt-in flag in HotCRP so authors can decide whether we could process their papers with an LLM.

Interactive discussion & revision phase

SaTML will have a discussion period during which authors can exchange messages with reviewers, respond to their questions, and address their comments through direct changes to the paper. To facilitate this, we will use an anonymous communication feature to enable interaction between authors and reviewers. Authors should primarily focus on correcting factual errors in the reviews and answering specific questions posed by the reviewers. New research results may also be discussed if they help clarify open questions. More instructions will be sent to the authors at the beginning of the discussion phase.

Submission decisions

For each submission, one of the following decisions will be made:

  • Accept: Papers in this category will be accepted for publication in the proceedings and presentation at the conference. All accepted papers must submit a camera-ready copy by the corresponding deadline. The papers will be published in the IEEE Computer Society Digital Library, and authors are encouraged to also make them freely available via arXiv.

    • Note: Acceptance is conditional on artifact availability on zenodo.org (see “Open Science”), or a valid justification for why this is not possible.
  • Revision: A limited number of papers will be invited to submit a revision; such papers will receive a detailed summary of expectations for revision, in addition to standard reviewer comments. Requested changes may be textual, experimental, or a combination of both. Authors will have a limited time window to submit a revision after the notification is sent. The authors should clearly explain in a well-marked appendix how the revisions address the comments of the reviewers. The revised paper will then be re-evaluated, and either accepted or rejected. We will assign the same set of reviewers. Authors can choose to withdraw their paper and not submit a revision.

  • Reject: Papers in this category are declined for inclusion in the conference.

Conflicts of Interest policy

The conference requires cooperation from both authors and program committee members to ensure a fair review process. For this purpose, authors must report all program-committee members and chairs who, in their opinion, have a conflict of interest and therefore may not be able to provide an unbiased review.

Mandatory conflicts of interest to declare include the following people:

Advisor/Advisee

  • who was the advisor or advisee of an author at any time in the past

Recent Collaboration

  • with whom an author has published within the past 12 months
  • with whom an author had more than one publication in common within the past 24 months
  • with whom an author has had an active research collaboration within the past 12 months (including work-in-progress papers and funding applications)

Institutional

  • who shares an institutional affiliation with an author at the time of submission or within the 12 months before that (including secondary affiliations and consulting work)

Financial

  • who is a co-PI or holds a sub-award on the same grant or funding of an author in the last 12 months
  • who is affiliated with a party that provided research funding to an author in the last 12 months, including unrestricted gifts

Personal

  • with whom you have a close personal relationship

For any “Other” declared conflict, authors are required to explain the nature of the conflict to Program Chairs and the Area Chairs. The PC Chairs reserve the right to request further explanation and can remove non-mandatory conflicts at their discretion.

Program-committee members who have a genuine conflict of interest with a paper, including the Program and Area Chairs, will be excluded from evaluation and discussion of that paper. When a Program Chair is conflicted, the other Co-Chair will be responsible for managing that paper. When both Program Chairs are in conflict, an Area Chair will be appointed to handle the paper.

⚠️ A Special Note on “Fake Conflicts”: Declaring conflicts of interest to avoid certain (otherwise non-conflicting) PC members is not allowed and can constitute grounds for rejection. The PC Chairs reserve the right to request additional explanation for any declared conflict. If authors have concerns about the fair treatment of their submissions, they should instead contact the chairs and provide convincing arguments for any special consideration that they are requesting.

Area Chairs can author or co-author submissions. Program Chairs are not allowed to be authors or co-authors of any submissions.

Distinguished paper award

Outstanding paper(s) will be selected by the Program Committee, with input from the Steering Committee, for the distinguished paper award. The award will be announced at the conference. Distinguished paper awards are intended to highlight papers which significantly challenge the state of the art in research areas relevant to SaTML.

Attendance for accepted papers

⚠️ In-person presentations only: We are planning for all presentations at SaTML 2027 to take place in person at the conference. In this edition, we are not planning any remote or virtual presentation option. An accepted paper appears in the conference's formal IEEE proceedings on two conditions: at least one author registers (with the full non-student registration fee) by the specified registration deadline, and the paper is presented in person, on site. If none of the authors of a paper is able to attend, for example because of visa difficulties or other exceptional circumstances, the authors must inform the PC Chairs and the General Chair in advance and obtain approval. Exceptions are handled case by case. Where an exception is granted, the chairs may permit a non-author to present the paper on site (e.g., a colleague of the authors attending SaTML), or in rare cases allow the paper to be included without a presentation.

⚠️ Important: Papers with no registered author by the deadline, or that are not presented on site without prior approval, will not appear in the IEEE proceedings.

Planning for growth in submissions

SaTML has grown steadily along with the community it serves, and we expect that trend to continue. The Program Committee for 2027 is being sized to absorb a 2x increase over last year's submission volume, while preserving the timeline and review standards described above, and we will expand it further if abstract registration indicates that is necessary.

If submissions exceed even that, we may need to adjust parts of the process in order to protect review quality. In that case, we will consider one or more of the following:

  • Expanding the Program Committee once abstract registration gives us a firm picture of volume. If we do, we may ask authors to re-check their conflicts of interest against the updated committee, no later than 24 hours before the submission deadline.
  • Moving the early-reject notification to a later date.
  • Requiring authors of submitted papers to contribute to reviewing up to three papers, as is increasingly common at venues of large size. Failure from authors to submit such reviews may result in desk rejection of their paper(s).
  • Postponing decision notifications, and reducing revision window for the "Revision" timeline. Authors would still have the opportunity to revise their papers during the interactive discussion phase.

Abstract registration has been introduced precisely so that we can anticipate volume early and plan accordingly. We will confirm whether any of these measures are necessary before the early reject notification date and will communicate any changes to authors promptly. Authors who would prefer not to proceed under a revised timeline may withdraw their submission at that point, before any reviews have been released.

We would rather set out this contingency plan in advance than surprise anyone mid-cycle. We hope and expect that none of it will be needed.

If you have any questions, please email us at pcchairs@satml.org

Checklist

Authors should read and comply with the full CfP. We have drafted a brief checklist to help you double-check, but it may not capture every detail, so the full CfP takes precedence. If you think we have missed something important from the CfP in the checklist, we welcome your feedback at pcchairs@satml.org.