The 17th ACM Conference on Data and Application Security and Privacy

(ACM CODASPY 2027)

June 14 – 17, 2027

Fort Collins, Colorado, USA

Call for Papers

CODASPY 2027 is the 17th ACM Conference on Data and Application Security and Privacy.

Data and applications security and privacy has rapidly expanded as a research field with many important challenges to be addressed. The goal of the ACM Conference on Data and Applications Security (CODASPY) is to discuss novel, exciting research topics in data and application security and privacy, and to lay out directions for further research and development in this area.

The conference seeks submissions from diverse communities, including corporate and academic researchers, open-source projects, standardization bodies, governments, system and security administrators, software engineers and application domain experts. Topics of interest include, but are not limited to:

In addition to the regular research paper track, CODASPY 2027 will also feature dataset and tool paper, bluesky, and SoK tracks, as detailed below.

Submitted papers must not substantially overlap with papers that have been published or that are simultaneously submitted to a journal, conference or workshop. Simultaneous submission of the same work is not allowed.

All submissions should be made electronically at https://codaspy27.hotcrp.com/


Instructions for Research Paper Authors

Submissions must be at most 12 pages in double-column ACM "sigconf" format (as specified at ACM Proceedings Template). Submissions must be anonymized and avoid obvious self-references. Only PDF files will be accepted. Submissions not meeting these guidelines will be rejected without review.


Instructions for Dataset/Tool Paper Authors

This track will provide a unique venue for researchers and practitioners to make available and citable their work done to achieve datasets or tools relevant in the security and privacy domain. Papers accepted in this track have to describe the available datasets or reporting on the design and implementation of application security and privacy tools. Datasets / tools must pass the artifacts evaluation test during the review process.

Artifacts could include

Artifacts can be standalone artifacts as a dataset/tools papers or part of a research paper.

Submissions must be at most 6 pages in double-column ACM "sigconf" format (as specified at ACM Proceedings Template) and must include "Data/Toolset paper" as a subtitle. Submissions must be anonymized and avoid obvious self-references. Only PDF files will be accepted. Submissions not meeting these guidelines will be rejected without review.


Instructions for BlueSky Paper Authors (Invitation Only)

The BlueSky Track invites the research community to present visionary propositions that within a foreseeable future could inspire impactful directions and compelling new research opportunities for the cybersecurity community. BlueSky papers are intended to present ambitious and visionary ideas with the potential to redefine the future of security research. Unlike conventional research papers, they emphasize emerging opportunities, new problem spaces, and transformative research agendas. Authors are encouraged to move beyond existing methods, technologies, and datasets, offering creative, forward-thinking perspectives that may challenge established assumptions and spark paradigm-shifting advances. Submissions should promote bold, visionary thinking and novel research directions aligned with the conference themes.

Submissions must be at most 10 pages in double-column ACM "sigconf" format (as specified at ACM Proceedings Template) and must include "Bluesky" as a subtitle. Submissions are not required to be anonymous but will be reviewed by the PC, holding similar standards as other tracks. Only PDF files will be accepted. Submissions not meeting these guidelines will be rejected without review.


Instructions for SoK Paper Authors (Invitation Only)

Papers that focus on the systematization of knowledge (i.e., SoK papers) are within the scope of CODASPY, particularly if they provide new insights and compelling evidence. Papers in this track will be reviewed based on their treatment of existing work and value to the community, and not based on any new research results they may contain. Such papers go beyond summarizing previous research (like in surveys); they also include a thorough examination and analysis of existing approaches, identify gaps and limitations, offer insights or new perspectives on a given, major research area, and may also involve new experiments to replicate and compare previous solutions.

Submissions must be at most 15 pages in double-column ACM "sigconf" format (as specified at ACM Proceedings Template) and must include "Systematization of Knowledge" as a subtitle. Submissions are not required to be anonymous but will be reviewed by the PC, holding similar standards as other tracks. Only PDF files will be accepted. Submissions not meeting these guidelines will be rejected without review.


Additional Submission Instructions

Note that, for all papers (except SoK), the page limits above include the main body and references. Submissions can also include up to 2 additional pages of appendices. The appendices should only be used to add information that might help reviewers, such as additional figures/tables/proofs/etc. They are not compulsory reading for reviewers, so the paper should be self-contained and understandable without appendices.

By submitting your article to an ACM Publication, you are hereby acknowledging that you and your co-authors are subject to all ACM Publications Policies, including ACM's new Publications Policy on Research Involving Human Participants and Subjects. Alleged violations of this policy or any ACM Publications Policy will be investigated by ACM and may result in a full retraction of your paper, in addition to other potential penalties, as per ACM Publications Policy.

Please ensure that you and your co-authors obtain an ORCID ID, so you can complete the publishing process for your accepted paper. ACM has been involved in ORCID from the start and we have recently made a commitment to collect ORCID IDs from all of our published authors. We are committed to improve author discoverability, ensure proper attribution and contribute to ongoing community efforts around name normalization; your ORCID ID will help in these efforts.


Ethics and Open Science Statements

Authors submitting to CODASPY 2027 are highly encouraged to include Ethics and Open Science statements in their submissions. The ethics statement should discuss ethical aspects of the work, including but not limited to real-world implications of the research on system and user security as well as measures that the authors have taken to ensure ethical conduct throughout their work (e.g., responsible disclosure and review of research protocols by ethics boards). The open science statement should describe how the authors intend to enable future research to build on their work and facilitate reproducibility (e.g., by open-sourcing code and data with clear instructions to recreate key results from the paper). Each of these statements may be added as an unnumbered section (i.e., \section*{Ethics Statement} and \section*{Open Science Statement}), after the references, at the beginning of the appendix. Note that these statements are not mandatory, but they can help address certain concerns reviewers and readers might have, such as ones concerning research integrity or other violations of ACM's policies.


Policy on AI-Generated Content

Please refer to the ACM policy on Authorship.


ACM Open Access

Important update on ACMs new open access publishing model for 2027 ACM Conferences!

The ACM Open program is designed to help institutions actively support Open Access publishing. Starting January 1, 2026, ACM has fully transitioned to Open Access. All ACM publications, including those from ACM-sponsored conferences, will be 100% Open Access. To be included in ACM Open, the corresponding author must be affiliated with a participating institution. A list of all ACM Open participating institutions can be found here. For APC-eligible articles, including research papers, short papers, and survey papers, where none of the authors are currently affiliated with a participating institution, an Article Processing Charge (APC) will be required.

To support authors and institutions that are still adapting to ACM's Open Access publishing model, the ACM Council has approved subsidized APC rates for 2027. Authors whose institutions are not yet participating in ACM Open will pay a discounted rate of $500 (ACM/SIG Members) or $750 (Non-Members). We encourage authors to help bring their institutions into ACM Open during 2027, as ACM's temporary APC subsidy is scheduled to end after this year.

Please note that ACM is not lowering APC pricing. Rather, ACM is providing a one-year subsidy for 2027 that reduces APC pricing for authors whose institutions are not yet participating in ACM Open. 2027 will be the final year of this subsidy and in the future APC pricing will be based on the actual cost of publishing and hosting articles in the ACM Digital Library. It is possible that APC prices will go up or down in the future.


Important Dates

All dates are Anywhere on Earth (AoE). See also Important Dates.


Organization

Program Co-Chairs

General Chair

Organizing Committee