SPLASH 2026
Sun 4 - Fri 9 October 2026 Oakland, California, United States
co-located with SPLASH/ISSTA 2026

This program is tentative and subject to change.

Wed 7 Oct 2026 14:42 - 15:00 at Junior Ballroom 1&2 - Security and Information Flow Chair(s): Mae Milano

Today, most software is developed by leveraging existing packages, allowing developers to accelerate development. The proliferation of package dependencies creates a target-rich environment for malicious actors to inject malware, steal sensitive information, or cause destruction. Such supply-chain attacks constantly threaten package ecosystems such as Cargo, NPM, and Maven.

In this paper, we explore how to fight against such attacks by leveraging effect systems. While effect systems predict the behavior of software components, there is a practical gap between a programming language with an effect system and a programming language ecosystem that can use such effects to thwart attacks. To close this gap, we introduce a notion of effect-safe package upgrade and develop an effect-aware package manager that enforces safety through effect lock files.

We extend the Flix programming language and its compiler toolchain with an effect-aware package manager. We introduce the notion of secure, trusted, and unsafe packages to control access to the Java Class Library and Java Virtual Machine. We evaluate the usefulness of the proposed effect-aware package manager with a case study of 51 supply-chain attacks from the ``Backstabbers Knife Collection'' corpus of malware. The study suggests that 48 of these attacks are likely preventable with our proposed effect-aware package manager.

This program is tentative and subject to change.

Wed 7 Oct

Displayed time zone: Pacific Time (US & Canada) change

13:30 - 15:00
Security and Information FlowOOPSLA at Junior Ballroom 1&2
Chair(s): Mae Milano Princeton University
13:30
18m
Talk
(Dis)Proving Spectre Security with Speculation-Passing Style
OOPSLA
Santiago Arranz Olmos Max Planck Institute for Security and Privacy, Gilles Barthe MPI-SP; IMDEA Software Institute, Lionel Blatter Max Planck Institute for Security and Privacy, Xingyu Xie MPI-SP, Zhiyuan Zhang MPI-SP
13:48
18m
Talk
Decompiling for Constant-Time Analysis
OOPSLA
Santiago Arranz Olmos Max Planck Institute for Security and Privacy, Gilles Barthe MPI-SP; IMDEA Software Institute, Lionel Blatter Max Planck Institute for Security and Privacy, Youcef Bouzid ENS Paris-Saclay, Sören van der Wall TU Braunschweig, Zhiyuan Zhang MPI-SP
14:06
18m
Talk
Sound Enforcement of Dynamic Release Information Flow Policy
OOPSLA
Jeffrey Ching Duke University, Danfeng Zhang Duke University
14:24
18m
Talk
A Type System for Optimizing Dynamic IFC
OOPSLA
Daniel Galán Pascual ETH Zurich, François Hublet ETH Zurich, Srđan Krstić ETH Zürich, Roman Fischer ETH Zurich, Colin Pfingstl ETH Zurich, David Basin ETH Zurich
14:42
18m
Talk
Fighting Supply Chain Attacks with Effect Systems
OOPSLA
Magnus Madsen Aarhus University, Andreas Stenbæk Larsen Aarhus University, Jakob Schneider Villumsen Aarhus University, Aslan Askarov Aarhus University