Keynotes

Delphine Longuet is a formal method research engineer at Thales cortAIx Labs. She obtained her Ph.D. from Université Evry-Val d'Essonne in 2007. We was an associate professor at Université Paris-Sud for 9 years, then she joined Thales in 2018. Her research interest are formal methods for the validation and verification of software. In Thales, she was co-leader of two projects on automated test generation, for Ada with AdaCore and for C with OCamlPro, with the aim of facilitating the industrial adoption of these techniques and tools.
Towards the industrial adoption of automated test generation techniques with SeaCoral
Formal methods have been successfully used to develop advanced test generation and vulnerability detection techniques but their adoption in industrial practice remains fragmented. In this talk, I will present SeaCoral, a novel open-source toolset for testing C programs, which aims to facilitate the industrial application of diverse testing and analysis tools by integrating them and making them collaborate within a single framework. I will present the different integrated tools and explain how SeaCoral makes them work together on the same code to produce tests to maximize a given code coverage criterion. Besides tests for coverage, a particular attention is paid to the detection of runtime errors, as potential sources of vulnerability, and to their reproducibility.
Language: English (subtitled in French)

Antoine Delignat-Lavaud is a security researcher in Azure Research’s Confidential Computing group, whose focus is to build the secure cloud of tomorrow with hardware-based trusted execution technology, ensuring that all privacy-sensitive data remains isolated, encrypted and integrity protected thorough its lifecycle. He leads efforts on protocols, platform services, and hardware design with partner silicon vendors to develop confidential AI offering verifiable confidentiality of models, prompts and responses.
The Real-World Challenges of Scaling Up Confidential Computing at Azure Scale
Operating confidential computing services introduces new challenges beyond traditional cloud security. Clients must verify not only service identity but its attested implementation, yet distributing and validating attestation evidence at scale remains complex. Service updates require coordinated changes to attestation policies, while dependencies on other services extend the trust chain across multiple attestable components. Attestation is not in itself sufficient for establishing trust without a lot of additional evidence about how binaries are built and what they consist of. There have been many successful side-channel attacks that have managed to extract data from hardware isolated TEEs. In this talk I will present some of the protocols, services and architecture Azure has developed to make confidential computing practical for complex real-world services.
Language: English (subtitled in French)