1st Workshop on Meta-Science in AI Security Research

MIRROR : Meta-science in AI Security Research — Reflection, Oversight, and Rigor

May 3, 2027·Reykjavík, Iceland·co-located with IEEE SaTML 2027

“The first principle is that you must not fool yourself — and you are .”
— Richard Feynman, Cargo Cult Science (1974)

Why a mirror

AI security is good at finding flaws in other people’s claims. Turning that scrutiny on ourselves is harder.

Our community has made real progress, and much of it came from refusing to take claims at face value. Yet defenses that looked robust have repeatedly fallen to adaptive attacks. Privacy evaluations have measured the average case when the worst case was the point. Datasets have carried biases and label errors into reported results. Small slips like these can go unnoticed all the way from data collection to the conclusions in a paper.

In most fields, a slip like that is just a wasted result. In security, adversaries go looking for any gap between claimed and actual robustness, so the slip becomes a false sense of security. Other sciences have long studied how incentives and habits shape which findings get published and trusted. AI security is starting to ask the same questions, mostly in scattered papers. MIRROR is a place to ask them together.

Looking backward

What have we gotten wrong? Audits of past practice: pitfalls, broken evaluations, threat models that didn’t hold, and the negative results that never got published.

Looking forward

How do we get it right the first time? Evaluation protocols, reproducible artifacts, data and label quality, and responsible disclosure, built in before mistakes happen.

Looking inward

How do we actually do research? Finding signal in a flood of papers, communicating ideas clearly, and the changing role of LLMs in ideation, writing, and peer review.

Moments of reflection

Meta-science is research about research. Here is what it has already changed.

Topics of interest

We welcome talks on meta-science and meta-research in secure and trustworthy ML, including:

  • Domain-specific dos and don’ts

    Common pitfalls across the ML pipeline, and those specific to individual domains.

  • Reproducibility and replicability

    Artifact availability, dataset and benchmark decay, reproducibility crises in trustworthy ML.

  • Threat model assumptions

    Defining realistic and tight threat models; adaptive attacks.

  • AI in the research process

    LLM reliability, LLM-assisted experimentation and review, pitfalls unique to LLM-centric research.

  • Publication bias and negative results

    The value, and under-publication, of failed defenses, null results, and non-replications.

  • Ethics and responsible disclosure

    Ethical review processes tailored to adversarial and security research.

  • Data and label quality

    Sampling bias, label inaccuracy, spurious correlations, dataset transparency.

  • Science of security

    Positions on what security research should focus on.

  • Peer review and evaluation practices

    Reviewer incentives, novelty bias, and reforming review in security venues.

  • Peer review and AI

    Using AI reliably in review, and detecting its misuse.

  • Cross-community comparisons

    What ML security can learn from meta-research in clinical trials, systems research, HCI, and beyond.

  • Science of doing research

    Where to look for ideas, deciding what matters in a sea of papers, presenting work.

Call for lightning talks

Seen something the field should talk about? Give a lightning talk.

  • Have you run into the same methodological flaw in five papers this year?
  • Have you tried to reproduce a result and failed, or watched a benchmark quietly decay?
  • Do you review papers and suspect some were written by agents?
  • Have you noticed academia’s priorities drifting away from what practitioners need?

Then you already have a talk. MIRROR invites short talks that surface observations, pitfalls, positions, or lessons learned, so the community can learn from them before repeating them. Early-career and senior researchers, industry practitioners, reviewers, and policy makers are all welcome.

Already published a paper on one of these topics? You’re welcome to submit an abstract about it too.

Important dates

All deadlines are 23:59 AoE.

  1. Submission deadline
  2. Acceptance notification
  3. Workshop

Program

A half-day of reflection: one keynote, lightning talks, and a panel.

Battista Biggio

Keynote

Battista Biggio

University of Cagliari, Italy

Talk title to be announced

Battista Biggio is a Full Professor at the University of Cagliari, research co-director of sAIferLab, and co-founder of Pluribus One. His team was among the first to formalize attacks on machine learning models as optimization problems and to demonstrate evasion and poisoning attacks against them. His paper Poisoning Attacks against Support Vector Machines received the 2022 ICML Test of Time Award, and his Wild Patterns papers looked back on a decade of adversarial machine learning, an early example of the field reflecting on itself. He is an IEEE Fellow and an IAPR Fellow.

Schedule tentative

Times are local Reykjavík time (UTC+0).

  1. Opening remarks
  2. KeynoteBattista Biggio, University of Cagliari
  3. Coffee break
  4. Lightning talksSelected from the call for talks
  5. Panel discussionBest practices for conducting and evaluating ML security research. Panelists to be announced.
  6. Closing remarks
  7. Informal meetupAn open, low-pressure space to keep the conversation going

Organizers

The people holding the mirror