Workshop Overview
The International Workshop on Firmware Testing and Analysis (FTA 2026) brings together researchers and practitioners to advance the state of the art in testing, security analysis, verification, and maintenance of firmware — the low-level software that powers laptops, desktop computers, servers, embedded systems, IoT devices, industrial controllers, and critical infrastructure. A firmware program is embedded in non-volatile storage on a computer’s motherboard. It controls how a computing device starts its boot process and interacts with its operating system after power-on.
Firmware poses unique challenges for security testing, analysis, and maintenance: It operates with minimal hardware abstractions, interacts directly with peripherals, and is often subject to resource constraints, real-time requirements, and long deployment lifetimes. Moreover, many firmware vulnerabilities can become persistent across system reboots. Also, in many cases, physical access to the devices would be required to mitigate threats. Finally, many mitigation efforts are challenging and may damage the computing device or impair some of its functionality. Research and development in this area must be significantly boosted to ensure that sophisticated cyberattacks, including Advanced Persistent Threats (APT), can be prevented, detected, and mitigated in a timely manner.
Additionally, Artificial Intelligence (AI) plays a key role on both the attackers’ side and the security experts’ front. The state of the art in Machine Learning, namely, pretrained Large Language Models (LLMs), such as the Claude models from Anthropic and the GPT models from OpenAI, is fundamentally transforming the cybersecurity landscape. FTA is interested in any contributions and discussions on firmware testing, analysis, and maintenance. We are particularly interested in the Unified Extensible Firmware Interface (UEFI), an open standard for specifying the architecture of computing system firmware. When it comes to UEFI, the UEFI Forum (https://uefi.org) and the TianoCore open-source software community (https://github.com/tianocore) play significant roles. The TianoCore community maintains reference implementations of various components of the UEFI specification, for example, EDK II. This has resulted in a vibrant and mature Open-Source Ecosystem (OSE) that has had a significant impact on global security, safety, and privacy. A recent $1.2M project (2025-2027) sponsored by the U.S. National Science Foundation (NSF), named TianoShield (https://tianoshield.github.io/home), aims to enhance the state of security of the TianoCore OSE and improve its overall open-source development process and practices. FTA is organized as part of TianoShield’s efforts to exploit and disseminate the technologies and create synergies. FTA 2026 will report on improvements, new results, and open problems in protecting the TianoCore OSE by using the TianoShield project as an anchor, while welcoming contributions from other participants and stakeholders in the firmware world.
After the successful organization of the International Workshop on Firmware Security Vulnerabilities (FirmVuln26) at VulnCon26 in Scottsdale, Arizona, USA, in April 2026, we are pleased to provide another dedicated venue for sharing novel techniques, tools, and empirical insights in this increasingly important area at the FTA 2026 Workshop at ISSTA 2026.
Keynote Talk
Title: Securing UEFI in the Age of AI: The Forgotten Footholds
Sub-title: Persistence, trust chains, firmware invisibility, and why AI-era infrastructure raises the stakes for platform integrity
Speaker: Vijay Sarvepalli, Principal Engineer, CERT Division, Software Engineering Institute (SEI) at Carnegie Mellon University (CMU), PA, USA

Abstract: UEFI quietly underpins the trust model of modern computing, yet remains one of the least understood and least monitored software layers in the stack. As AI systems increasingly depend on trusted hardware initialization, provisioning, and teardown, firmware becomes an even more attractive foothold for advanced adversaries seeking persistence and invisibility beneath the operating system. This keynote explores enduring UEFI attack surfaces, from chain-of-trust failures to NVRAM misuse, and examines why modern AI-driven security research still struggles to meaningfully analyze firmware ecosystems. The talk concludes with a call to action for both the firmware and AI security communities to better protect the foundations of trusted compute.
Keywords: UEFI, firmware, chain-of-trust, persistence, AI-era hardware, AI-assisted vulnerability research, invisible attacks, persistence.
Speaker Bio: Vijay Sarvepalli currently serves as Principal Engineer of the CERT Division of Carnegie Mellon University’s (CMU’s) Software Engineering Institute (SEI). Vijay is a seasoned professional with extensive expertise in software architecture, cybersecurity, and enterprise systems. As Principal Architect at the CERT Division of Carnegie Mellon University’s Software Engineering Institute, he focuses on advancing software architecture practices with a particular emphasis on enhancing cybersecurity.
Other Talks
The other talks listed below consist of paper presentations and oral presentations. The talks that include the organizers’ (co-chairs’) names are oral presentations. These are accepted by the PC to be presented in the FTA 2026 workshop but are not published in the proceedings, according to the ACM SIGSOFT policy (https://www2.sigsoft.org/policies/pcpolicy/) that does not allow the work of organizers to be published in the workshop proceedings.
The Day at a Glance
Monday, October 5, 2026
9:00 am - 10:00 am: Session 1 - Welcome by the organizers and the keynote talk on “Securing UEFI in the Age of AI: The Forgotten Footholds” by Vijay Sarvepalli, Software Engineering Institute (SEI) at Carnegie Mellon University (CMU), PA, USA
45-minute keynote speech with 10-15 minutes Q&A
10:00 am - 10:30 am: AM coffee break
10:30 am - 12:00 pm: Session 2 - Research Talks
20-25 minute talk with about 5 minutes Q&A, session chair: Laura Baird, University of Colorado Colorado Springs (UCCS)
-
10:30 am - 11:00 am: Verification of Protocol Compliance by Symbolic Execution
-
11:00 am -11:30 am: TianoForge: An Automated Bug Triage Approach for the TianoCore UEFI Firmware Development Community
-
11:30 am – 12:00 pm: IAIA: Interrupt-Aware Index Analysis
12:00 pm - 1:00 pm: Lunch break
1:00 pm - 2:00 pm: Session 3 - Industry panel, moderated by Edhaya Chandran, Arm
Panelists: Tim Lewis (Insyde Software) and Dong Wei (Arm, President of the UEFI Forum)
2:00 pm - 3:00 pm: Session 4 - Industry & Tools
20-25 minute talk with about 5 minutes Q&A, session chair: Nazanin Siavash, University of Colorado Colorado Springs (UCCS)
- 2:00 pm - 2:30 pm: Tooling for Repeatable Generation of SBOMs for EDK2-Based Firmware
- 2:30 pm - 3:00 pm: SPIDER4TianoCore: Enhancing Patch Propagation for the TianoCore UEFI Firmware Development Ecosystem
3:00 pm - 3:30 pm: PM coffee break
3:30 pm - 5:00 pm: Session 5 - Other Talks & Closing
10-minute talk with about 5 minutes Q&A, session chair: Mingjie Shen, Purdue University
- 3:30 pm - 3:45 pm: An Empirical Study of the TianoCore Community
- 3:45 pm - 4:00 pm: Firmware-Specific Security Guidelines
- 4:00 pm - 4:15 pm: Enhancing Bug Report Templates in the TianoCore UEFI Firmware Development Community
- 4:15 pm - 4:30 pm: From Silicon to Boot Code: Extending Automated Program Repair to Firmware-Layer Security Workarounds
- 4:30 pm - 4:45 pm: Meeting NSA’s “Guidance for Managing UEFI Secure Boot"
- 4:45 pm - 5:00 pm: Closing
Highlights
TianoForge: An Automated Bug Triage Approach for the TianoCore UEFI Firmware Development Community
Nazanin Siavash, Terrance E. Boult, Armin Moin
Meeting NSA’s “Guidance for Managing UEFI Secure Boot”
Kevin D. Davis
Enhancing Bug Report Templates in the TianoCore UEFI Firmware Development Community
Laura Baird, Neelesh Reddybattula, Nazanin Siavash, Terrance E. Boult, Armin Moin
Verification of Protocol Compliance by Symbolic Execution
Xing-Hua Peng, Pai H. Chou
From Silicon to Boot Code: Extending Automated Program Repair to Firmware-Layer Security Workarounds
Maisha Mastora, Dean Sullivan
Tooling for Repeatable Generation of SBOMs for EDK2-Based Firmware
Alvin Chen, Daniel Chang, Tim Lewis
SPIDER4TianoCore: Enhancing Patch-Propagation for the TianoCore UEFI Firmware Development Ecosystem
Laura Baird, Devin Haggitt, Terrance E. Boult, Aravind Machiry, Armin Moin
Firmware-Specific Security Guidelines
Tim Lewis
An Empirical Study of the TianoCore Community
Nazanin Siavash, Connor Everett Glosner, Ayushi Sharma, Bianca Trinkenreich, Terrance E. Boult, Aravind Machiry, Armin Moin
IAIA: Interrupt-Aware Index Analysis for SSD Firmware
Hyeongseo Yoo, Kwangkeun Yi
This program is tentative and subject to change.
Mon 5 OctDisplayed time zone: Pacific Time (US & Canada) change
08:30 - 10:00 | Session 1: Keynote TalkFTA at Grand Ballroom Salons C Chair(s): Armin Moin Purdue University, Aravind Machiry Purdue University Keynote talk by Vijay Sarvepalli, Principal Engineer, CERT division, Software Engineering Institute (SEI), Carnegie Mellon University (CMU), USA Title: Securing UEFI in the Age of AI: The Forgotten Footholds Sub-title: Persistence, trust chains, firmware invisibility, and why AI-era infrastructure raises the stakes for platform integrity. Keywords: UEFI, firmware, chain-of-trust, persistence, AI-era hardware, AI-assisted vulnerability research, invisible attacks, persistence. Time: 45 minutes plus 15 minutes Q&A Abstract: UEFI quietly underpins the trust model of modern computing, yet remains one of the least understood and least monitored software layers in the stack. As AI systems increasingly depend on trusted hardware initialization, provisioning, and teardown, firmware becomes an even more attractive foothold for advanced adversaries seeking persistence and invisibility beneath the operating system. This keynote explores enduring UEFI attack surfaces, from chain-of-trust failures to NVRAM misuse, and examines why modern AI-driven security research still struggles to meaningfully analyze firmware ecosystems. The talk concludes with a call to action for both the firmware and AI security communities to better protect the foundations of trusted compute. Speaker Bio: Vijay Sarvepalli currently serves as Principal Engineer of CERT division of Carnegie Mellon University’s Software Engineering Institute. Vijay is a seasoned professional with extensive expertise in software architecture, cybersecurity, and enterprise systems. As Principal Architect at the CERT Division of CMU’s SEI, he focuses on advancing software architecture practices with a particular emphasis on enhancing cybersecurity. | ||
10:30 - 12:00 | |||
10:30 30mTalk | Verification of Protocol Compliance by Symbolic Execution FTA DOI | ||
11:00 30mTalk | TianoForge: An Automated Bug Triage Approach for the TianoCore UEFI Firmware Development Community FTA Nazanin Siavash University of Colorado Colorado Springs (UCCS), Terrance E. Boult University of Colorado Colorado Springs (UCCS), Armin Moin Purdue University | ||
11:30 30mTalk | IAIA: Interrupt-Aware Index Analysis for SSD Firmware FTA Hyeongseo Yoo Seoul National University; Samsung Electronics, Kwangkeun Yi Seoul National University DOI | ||
13:30 - 15:00 | |||
13:30 90mTalk | Tooling for Repeatable Generation of SBOMs for EDK2-Based Firmware FTA DOI | ||
13:30 90mTalk | SPIDER4TianoCore: Enhancing Patch-Propagation for the TianoCore UEFI Firmware Development Ecosystem FTA Laura Baird University of Colorado Colorado Springs (UCCS), Devin Haggitt University of Colorado Colorado Springs (UCCS), Terrance E. Boult University of Colorado Colorado Springs (UCCS), Aravind Machiry Purdue University, Armin Moin Purdue University | ||
15:30 - 17:00 | |||
15:30 90mTalk | An Empirical Study of the TianoCore Community FTA Nazanin Siavash University of Colorado Colorado Springs (UCCS), Connor Everett Glosner Purdue University, Ayushi Sharma Purdue University, Bianca Trinkenreich Colorado State University, Terrance E. Boult University of Colorado Colorado Springs (UCCS), Aravind Machiry Purdue University, Armin Moin Purdue University | ||
15:30 90mTalk | Firmware-Specific Security Guidelines FTA Tim Lewis Insyde Software DOI | ||
15:30 90mTalk | Enhancing Bug Report Templates in the TianoCore UEFI Firmware Development Community FTA Laura Baird University of Colorado Colorado Springs (UCCS), Neelesh Reddybattula University of Colorado Colorado Springs (UCCS), Nazanin Siavash University of Colorado Colorado Springs (UCCS), Terrance E. Boult University of Colorado Colorado Springs (UCCS), Armin Moin Purdue University | ||
15:30 90mTalk | From Silicon to Boot Code: Extending Automated Program Repair to Firmware-Layer Security Workarounds FTA DOI | ||
15:30 90mTalk | Meeting NSA’s “Guidance for Managing UEFI Secure Boot” FTA Kevin D. Davis Insyde Software DOI | ||
Unscheduled Events
| Not scheduled Talk | Securing UEFI in the Age of AI: The Forgotten Footholds (Keynote) FTA Vijay Sarvepalli Carnegie Mellon University DOI |
Talks
Call for Papers
Topics of Interest
Topics of interest include, but are not limited to:
- Automated static and dynamic firmware testing and analysis tools;
- AI-assisted firmware testing and analysis;
- (AI-enhanced) firmware maintenance and evolution;
- (AI-assisted) firmware security vulnerability detection and/or mitigation;
- Empirical studies, surveys, case studies, and lessons learned from the industry;
- Open reference datasets and benchmarks that enable future research in this area.
Submission Guidelines
Paper Categories
FTA 2026 accepts five categories of submissions:
- Technical Papers / Research Papers / Surveys (up to 18 pages + 2 pages for references): Original research contributions presenting novel techniques, tools, substantial empirical findings, or surveys.
- Industry & Experience Reports (up to 12 pages + 2 pages for references): Practical experiences, lessons learned, and case studies from industrial firmware development or analysis.
- Short Papers / New Ideas and Emerging Results / Work-in-Progress (up to 8 pages + 2 pages for references): Preliminary results, emerging novel and ground-breaking ideas that lack full validation, or position statements.
- Tool papers (up to 5 pages + 2 pages for references): Tool demonstrations
- Extended Abstracts (up to 4 pages, including references): These will accompany posters presented at the workshop’s poster session. Accepted extended abstracts will be published in the proceedings.
Formatting
- Submissions must use the ACM Master Article template (acmart).
- LaTeX authors should use \documentclass[acmsmall,screen,review,anonymous]{acmart}. Note that this is a single-column format.
- Papers must be written in English and submitted as a PDF.
- All submissions will be reviewed double-blind; author names and affiliations must be omitted.
- Except for extended abstracts, which must be 4 pages, including all references; for other submission types, references do not count toward the page limit, and 2 extra pages are allowed for references.
- The above-mentioned page limits include space for all content, such as appendices, figures, and tables.
- Authors must comply with all ACM policies, including the policies on the use of generative AI. See https://www.acm.org/publications/policies/frequently-asked-questions.
- Submissions that do not adhere to the guidelines may be desk-rejected without review.
Submission System
Papers must be submitted via HotCRP at https://fta26.hotcrp.com before the submission deadline.
Publication
All accepted papers will be made Open Access by ACM. Article processing charges may apply. See https://www.acm.org/publications/openaccess.
Presentation
At least one author of every accepted paper must register for the workshop and present the work in person. Otherwise, the submission may be withdrawn and not published in the proceedings. FTA 2026 is an in-person event.
Websites
- Workshop Website: https://conf.researchr.org/home/splash-issta-2026/fta-2026
- TianoShield Project Website: https://tianoshield.github.io/home/events
Contact
For questions about the workshop or submissions, please contact the organizers at: moin@purdue.edu and amachiry@purdue.edu
Acknowledgments
The FTA 2026 workshop is sponsored by ACM and uses SIGPLAN’s standard submission and reviewing terms. Moreover, this event is organized as part of the TianoShield project, which is supported by the U.S. National Science Foundation (NSF) under Grant No. 2534021. Any opinions, findings, conclusions, or recommendations expressed in this event are those of the authors/speakers and do not necessarily reflect the views of the NSF.
Results (28)
Terrance E. BoultBoult, Terrance E. University of Colorado Colorado Springs (UCCS)United States |
Edhaya ChandranChandran, Edhaya ArmUnited States |
Daniel ChangChang, Daniel Insyde SoftwareTaiwan |
Alvin ChenChen, Alvin Insyde SoftwareTaiwan |
Pai H. ChouChou, Pai H. National Tsing Hua UniversityTaiwan |
Kevin D. DavisDavis, Kevin D. Insyde SoftwareUnited States |
Maisha MastoraMastora, Maisha University of New HampshireUnited States |
Alex MatrosovMatrosov, Alex AnthropicUnited States |
Armin MoinMoin, Armin Purdue UniversityUnited States |
Xing-Hua PengPeng, Xing-Hua National Tsing Hua UniversityTaiwan |
Ayushi SharmaSharma, Ayushi Purdue University |
Nazanin SiavashSiavash, Nazanin University of Colorado Colorado Springs (UCCS)United States |
Dean SullivanSullivan, Dean University of New HampshireUnited States |
Bianca TrinkenreichTrinkenreich, Bianca Colorado State UniversityUnited States |
Hyeongseo YooYoo, Hyeongseo Seoul National University; Samsung ElectronicsRepublic of Korea |