SSR 2026 will feature four invited speakers. Two invited talks are scheduled for December 14 and two for December 15. Each invited talk is scheduled for one hour, including questions and discussion.

Formerly with MITRE Corporation
Invited Talk: Everyday Rigor for Designing Protocols
Email: joshua.guttman@gmail.com

Postdoctoral Scholar, Stanford University
Dr. Min Wu is a postdoctoral scholar working with Prof. Clark Barrett in the Department of Computer Science at Stanford University. She is also affiliated with the Stanford Center for AI Safety and the Stanford Center for Automated Reasoning. She received her PhD in Computer Science from the University of Oxford under the supervision of Prof. Marta Kwiatkowska. Her research aims to develop AI systems—particularly those used in high-stakes applications—that are verifiably safe and trustworthy.
Invited Talk: Safe and Trustworthy AI with Verifiable Guarantees
In this talk, Dr. Min Wu will present her work on developing safe and trustworthy AI systems with verifiable guarantees, situated at the intersection of AI and formal methods. I’ll begin with a brief overview of my research scope, then highlight two key areas: (1) formal explainable AI to promote trustworthiness, and (2) robustness guarantees to enhance AI safety. In the first part, She’ll discuss how we use neural network verification techniques to compute optimal verified explanations for deep neural networks, and how these explanations can be applied to evaluate trustworthiness in real-world scenarios—such as an autonomous aircraft taxiing application developed in collaboration with Stanford AeroAstro and NASA. In the second part, She’ll introduce a game-based verification framework that computes the maximum safe radius of neural networks to quantify their robustness. Notably, the concept of “safe radius” has been adopted by ISO and IEC in their newly established standard ISO/IEC TR 5469:2024 Artificial Intelligence – Functional Safety and AI Systems. She will conclude with a discussion of future research directions.
Email: minwu@stanford.edu
Founder, Hacker Factor Solutions
Dr. Krawetz of Hacker Factor (hackerfactor.com) specializes in non-traditional computer forensics, media analysis, online profiling, networking, and computer security. His research focuses on anti-anonymity technologies, methods to mitigate digital abuses, and media provenance.
Invited Talk: Provenance Under Pressure: Stress-Testing C2PA, SEAL, and Related Solutions
Media fraud is pervasive across all industries, from insurance and banking to legal evidence, political propaganda, and medical records. Addressing it requires identifying how the media was created, how it was handled, and the ability to detect forgery attempts. This talk examines the full landscape of provenance solutions, including text labels, visible and invisible watermarks, perceptual hashes, media forensics, and digital signatures. This presentation assesses what each solution promises and where each falls short.
The presentation stress-tests existing solutions, including C2PA (Coalition for Content Provenance and Authentication, the digital-signature standard championed by Adobe, Microsoft, Google, and other major tech companies). Through demonstrations and real-world case studies, the talk exposes critical vulnerabilities: X.509 certificates that can be spoofed or purchased cheaply, trusted timestamps that can be freely replaced or backdated, ignored revocation mechanisms, inconsistent validator results, and a conformance framework that systematically deflects accountability onto vendors and end users. While the cryptography is sound, the trust model is not.
The talk also reviews an alternative to C2PA: SEAL (Secure Evidence Attribution Label). SEAL offers a DNS-based signing approach modeled on the proven DKIM email standard. Unlike C2PA, SEAL provides non-repudiation, false-attribution prevention, revocation support, and compliance with Federal Rules of Evidence — all while remaining lightweight enough for embedded and streaming use cases.
Identifying provenance is a difficult problem. The session concludes that existing technologies vary from minimalistic labels to security theater, with only a few focused solutions that actually address parts of the problem. Unfortunately, adopting fundamentally flawed solutions, such as C2PA or TrustMark, introduces more problems than it attempt to solve. Often, simpler and well-understood mechanisms that address parts of the provenance problem serve the field better.

CEO, SL5 Task Force; DPhil Student in AI Security, University of Oxford
Invited Talk: Standards and Best Practice for AI Safety
Email: lisa@sl5.org