2026
- Riccardo Preatoni, Christian Scholz, Jens-Rene Giesen, Alessandro Brighente, Lucas Davi and Mauro Conti: Beyond Theft: How Underestimated Smart Contract Vulnerabilities Enable Extortionware. In: Proc. of 21st International Conference on Availability, Reliability and Security (ARES '26), Springer, Linköping, Sweden, aug 2026.
- Oussama Draissi and Lucas Davi: Bento: Fine-Grained Memory Isolation for COTS WebAssembly Binaries. In: Proc. of 35th ACM Web Conference 2026 (WWW '26), Association for Computing Machinery (ACM), Dubai, United Arab Emirates, apr 2026. [DOI]
- Christian Niesler, Christian Scholz and Lucas Davi: MPUsh: Applying Security Hotpatches Instead Of MPU Barriers. In: Proc. of 2nd Constructive Approaches for SeCurity Analysis and Design of Embedded systems Conference (CASCADE'26), Springer, Regensburg, Germany, mar 2026.
- Pascal Winkler, Christian Scholz, Jens-Rene Giesen, Noah Kappert and Lucas Davi: Fuzzing Cross-Chain Vulnerabilities with BridgeFuzz. In: 19th European Workshop on Systems Security (EuroSec), Volume 2026, , Edinburgh, Schottland, UK, 2026.
- Pascal Winkler, Jens-Rene Giesen, Oussama Draissi, Federico Badaloni, Sebastian Holler, Clara Schneidewind and Lucas Davi: Lessons: Brigade as a Defense Against Real-World DeFi Bridge Exploits. In: Proc. of 24th International Conference on Applied Cryptography and Network Security (ACNS), , Stony Brook, USA, 2026.
- Christian Niesler, Christian Scholz, Nils Hannappel and Lucas Davi: Co-Guard: Guarding Safety-Critical Embedded Devices in Emergencies. In: Proc. of 2nd Constructive Approaches for SeCurity Analysis and Design of Embedded systems Conference (CASCADE'26), Springer, Regensburg, Germany, 2026.
- Tobias Cloosters, Pascal Winkler, Jens-Rene Giesen, Ghassan Karame and Lucas Davi: SscRex: Practical Symbolic Execution of Solana Smart Contracts. In: Proc. of 23rd International Conference of Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA), Springer, Chania, Greece, 2026.
2025
- Jens-Rene Giesen, Christian Scholz and Lucas Davi: Poster: Code HarvETHter: Corpus-Driven Decompilation of Ethereum Smart Contracts. In: Proc. of the 32th ACM SIGSAC Conference on Computer & Communications Security (CCS), ACM, Taipeh, Taiwan, nov 2025.
- Oussama Draissi, Tobias Cloosters, David Klein, Michael Rodler, Marius Musch, Martin Johns and Lucas Davi: Wemby’s Web: Hunting for Memory Corruption in WebAssembly. In: ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA), Association for Computing Machinery (ACM), Trondheim, Norway, 34. Edition, jun 2025. [DOI]
- David Paaßen, Jens-Rene Giesen and Lucas Davi: Targeted Fuzzing for Unsafe Rust Code: Leveraging Selective Instrumentation. In: Proc. of 29th International Conference on Evaluation and Assessment in Software Engineering (EASE), , jun 2025.
- Philipp Mackensen, Christian Niesler, Roberto Blanco, Lucas Davi and Veelasha Moonsamy: KINTSUGI : Secure Hotpatching for Code-Shadowing Real-Time Embedded Systems. In: Proc. of 34th USENIX Security Symposium, , jun 2025.
- Johannes Willbold, Tobias Cloosters, Simon Wörner, Felix Buchmann, Moritz Schloegel, Lucas Davi and Thorsten Holz: Space RadSim: Binary-Agnostic Fault Injection to Evaluate Cosmic Radiation Impact on Exploit Mitigation Techniques in Space. In: Proc. of IEEE Symposium on Security and Privacy (S&P), , may 2025.
- Jens-Rene Giesen, Sebastien Andreina, Michael Rodler, Ghassan Karame and Lucas Davi: HCC: A Language-Independent Hardening Contract Compiler for Smart Contracts. In: Proc. of 23rd International Conference on Applied Cryptography and Network Security (ACNS), Springer, Munich, Germany, 2025.
2024
- Sebastien Andreina, Tobias Cloosters, Lucas Davi, Jens-Rene Giesen, Marco Gutfleisch, Ghassan Karame, Alena Naiakshina and Houda Naji: Defying the Odds: Solana’s Unexpected Resilience in Spite of the Security Challenges Faced by Developers. In: Proc. of the 31th ACM SIGSAC Conference on Computer & Communications Security (CCS), ACM, Salt Lake City, USA, oct 2024.
- Kilian Demuth Sebastian Linsner, Lucas Davi Sebastian Surminski and Christian Reuter: Building Trust in Remote Attestation Through Transparency – A Qualitative User Study on Observable Attestation.Behaviour & Information Technology, jun 2024, 1-21. [DOI]
- Tobias Cloosters, Oussama Draissi, Johannes Willbold, Thorsten Holz and Lucas Davi: Memory Corruption at the Border of Trusted Execution.IEEE Security & Privacy, Volume 2024, apr 2024, 2-11. [DOI]
2023
- Sven Smolka, Jens-Rene Giesen, Pascal Winkler, Oussama Draissi, Lucas Davi, Ghassan Karame and Klaus Pohl: Fuzz on the Beach: Fuzzing Solana Smart Contracts. In: Proc. of the 30th ACM SIGSAC Conference on Computer & Communications Security (CCS), ACM, Copenhagen, Denmark, nov 2023.
- Jan Philipp Thoma, Christian Niesler, Dominic Funke, Gregor Leander, Pierre Mayr, Nils Pohl, Lucas Davi and Tim Güneysu: ClepsydraCache - Preventing Cache Attacks with Time-Based Evictions. In: Proc. of 32nd USENIX Security Symposium, , Anaheim, CA, aug 2023.
- Michael Rodler, David Paaßen, Wenting Li, Lukas Bernhard, Thorsten Holz, Ghassan Karame and Lucas Davi: EF/CF: High Performance Smart Contract Fuzzing for Exploit Generation. In: Proc. of 8th IEEE European Symposium on Security and Privacy (EuroSP), , jul 2023.
- Sebastian Surminski, Christian Niesler, Lucas Davi and Ahmad-Reza Sadeghi: DMA'n'Play: Practical Remote Attestation Based on Direct Memory Access. In: Proc. of 21st International Conference on Applied Cryptography and Network Security (ACNS), , Kyoto, Japan, jun 2023.
- Sebastian Surminski, Christian Niesler, Sebastian Linsner, Lucas Davi and Christian Reuter: SCAtt-man: Side-Channel-Based Remote Attestation for Embedded Devices that Users Understand. In: Proc. of the 13th ACM Conference on Data and Application Security and Privacy (CODASPY), Volume 2023, ACM, Charlotte, NC, United States, apr 2023.
2022
- Tobias Cloosters, David Paaßen, Jianqiang Wang, Oussama Draissi, Patrick Jauernig, Emmanuel Stapf, Lucas Davi and Ahmad-Reza Sadeghi: RiscyROP: Automated Return-Oriented Programming Attacks on RISC-V and ARM64. In: Proc. of the 25th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2022), , Limassol, Cyprus, oct 2022. [DOI]
- Jens-Rene Giesen, Sebastien Andreina, Michael Rodler, Ghassan O. Karame and Lucas Davi: Tutorial: Analyzing, Exploiting, and Patching Smart Contracts in Ethereum. In: Proc. of 7th IEEE Secure Development Conference (SecDev), , oct 2022.
- Tobias Cloosters, Sebastian Surminski, Gerrit Sangel and Lucas Davi: SALSA: SGX Attestation for Live Streaming Applications. In: Proc. of 7th IEEE Secure Development Conference (SecDev), IEEE, oct 2022. [DOI]
- Tobias Cloosters, Johannes Willbold, Thorsten Holz and Lucas Davi: SGXFuzz: Efficiently Synthesizing Nested Structures for SGX Enclave Fuzzing. In: Proc. of 31st USENIX Security Symposium, , aug 2022.
- Lukas Bernhard, Michael Rodler, Thorsten Holz and Lucas Davi: xTag: Mitigating Use-After-Free Vulnerabilities via Software-Based Pointer Tagging on Intel x86-64. In: Proc. of 7th IEEE European Symposium on Security and Privacy, , jun 2022.
2021
- Sebastian Surminski, Christian Niesler, Ferdinand Brasser, Lucas Davi and Ahmad-Reza Sadeghi: RealSWATT: Remote Software-based Attestation for Embedded Devices under Realtime Constraints. In: Proc. of the 28th ACM SIGSAC Conference on Computer and Communications Security (CCS), Volume 2021, ACM, New York, USA, nov 2021. [DOI]
- David Paaßen, Sebastian Surminski, Michael Rodler and Lucas Davi: My Fuzzer Beats Them All! Developing a Framework for Fair Evaluation and Comparison of Fuzzers. In: Proc. of 26th European Symposium on Research in Computer Security, Volume 2021, Springer International Publishing, Darmstadt, oct 2021.
- Michael Rodler, Wenting Li, Ghassan O. Karame and Lucas Davi: EVMPatch: Timely and Automated Patching of Ethereum Smart Contracts. In: Proc. of 30th USENIX Security Symposium, USENIX Association, Vancouver, B.C., Canada, aug 2021.
- Christian Niesler, Sebastian Surminski and Lucas Davi: HERA: Hotpatching of Embedded Real-time Applications. In: Proc. of 28th Network and Distributed System Security Symposium (NDSS), , feb 2021. [DOI]
- Ilia Polian, Frank Altmann, Tolga Arul, Christian Boit, Ralf Brederlow, Lucas Davi, Rolf Drechsler, Nan Du, Thomas Eisenbarth, Tim Güneysu, Sascha Hermann, Matthias Hiller, Rainer Leupers, Farhad Merchant, Thomas Mussenbrock, Stefan Katzenbeisser, Akash Kumar, Wolfgang Kunz, Thomas Mikolajick, Vivek Pachauri, Jean-Pierre Seifert, Frank Sill Torres and Jens Trommer: Nano Security: From Nano-Electronics to Secure Systems. In: 24th Design, Automation & Test in Europe Conference & Exhibition (DATE), , feb 2021. [DOI]
2020
- Tobias Cloosters, Michael Rodler and Lucas Davi: TeeRex: Discovery and Exploitation of Memory Corruption Vulnerabilities in SGX Enclaves. In: Proc. of 29th USENIX Security Symposium, , aug 2020.
- Sridhar Adepu, Ferdinand Brasser, Luis Garcia, Michael Rodler, Lucas Davi, Ahmad-Reza Sadeghi and Saman Zonouz: Control Behavior Integrity for Distributed Cyber-Physical Systems. In: 11th IEEE/ACM Conference on Cyber-Physical Systems (ICCPS'20), , apr 2020.
2019
- Ghada Dessouky, Shaza Zeitouni, Ahmad Ibrahim, Lucas Davi and Ahmad-Reza Sadeghi: CHASE: A Configurable Hardware-Assisted Security Extension for Real-Time Systems. In: Proc. of 38th International Conference On Computer Aided Design (ICCAD), , nov 2019.
- Lucas Davi, Denis Hatebur, Maritta Heisel and Roman Wirtz: Combining Safety and Security in Autonomous Cars Using Blockchain Technologies. In: 2nd International Workshop on Safety, securiTy, and pRivacy In automotiVe systEms (STRIVE), , sep 2019.
- Michael Rodler, Wenting Li, Ghassan Karame and Lucas Davi: Sereum: Protecting Existing Smart Contracts Against Re-Entrancy Attacks. In: Proc. of 26th Network and Distributed System Security Symposium (NDSS), , feb 2019.
- Sebastian Surminski, Michael Rodler and Lucas Davi: Poster: Automated Evaluation of Fuzzers. In: Proc. of 26th Network and Distributed System Security Symposium (NDSS), , feb 2019.
2018
- Ferdinand Brasser, Lucas Davi, Abhijitt Dhavlle, Tommaso Frassetto, Sai Manoj Pudukotai Dinakarrao, Setareh Rafatirad, Ahmad-Reza Sadeghi, Avesta Sasan, Hossein Sayadi, Shaza Zeitouni and Houman Homayoun: Advances and Throwbacks in Hardware-assisted Security. In: Proc. of IEEE International Conference on Compilers, Architecture, and Synthesis for Embedded Systems, IEEE, oct 2018.
- Andrea Biondo, Mauro Conti, Lucas Davi, Tommaso Frassetto and Ahmad-Reza Sadeghi: The Guard's Dilemma: Efficient Code-Reuse Attacks Against Intel SGX. In: Proc. of 27th USENIX Security Symposium, , aug 2018.
- Yier Jin, Dean Sullivan, Orlando Arias, Ahmad-Reza Sadeghi and Lucas Davi: Hardware Control Flow Integrity. In: Per Larsen and Ahmad-Reza Sadeghi (eds.): The Continuing Arms Race: Code-Reuse Attacks and Defenses, Association for Computing Machinery and Morgan & Claypool, jun 2018, 181-210. [DOI]
- David Gens, Simon Schmitt, Lucas Davi and Ahmad-Reza Sadeghi: K-Miner: Uncovering Memory Corruption in Linux. In: Proc. of 25th Annual Network & Distributed System Security Symposium (NDSS), , feb 2018.
- Christian Moldovan Sebastian Surminski and Tobias Hoßfeld: Practical QoE Evaluation of Adaptive Video Streaming. In: Kai-Steffen Hielscher Reinhard German and Udo R. Krieger (eds.): Measurement, Modelling and Evaluation of Computing Systems, Springer International Publishing, Cham, jan 2018, 283-292.
2017
- Jannik Pewny, Philipp Koppe, Lucas Davi and Thorsten Holz: Breaking and Fixing Destructive Code Read Defenses. In: Proc. of 33nd Annual Computer Security Applications Conference (ACSAC), , dec 2017.
- Sebastian Surminski, Florian Metzger, Tobias Hoßfeld and Poul E. Heegaard.Traffic of the Future: Modeling IoT Traffic Patterns.Technical report,ITG Fachtagung "Zukunft der Netze 2017", sep 2017.
- Thomas Nyman, Jan-Erik Ekberg, Lucas Davi and N. Asokan: CFI CaRE: Hardware-supported Call and Return Enforcement for Commercial Microcontrollers. In: Proc. of 20th International Symposium on Research on Attacks, Intrusions and Defenses (RAID 2017), , sep 2017.
- Christian Moldovan Sebastian Surminski and Tobias Hoßfeld: Saving Bandwidth by Limiting the Buffer Size in HTTP Adaptive Streaming. In: Udo R. Krieger, Thomas C. Schmidt and Andreas Timm Giel (eds.): MMBnet 2017 - Proceedings of the 9th GI/ITG Workshop „Leistungs-, Verlässlichkeits- und Zuverlässigkeitsbewertung von Kommunikationsnetzen und Verteilten Systemen“ , University of Bamberg Press , Hamburg 1 , aug 2017 , 5-21. [DOI]
- Ferdinand Brasser, Lucas Davi, David Gens, Christopher Liebchen and Ahmad-Reza Sadeghi: CAn’t Touch This: Software-only Mitigation against Rowhammer Attacks targeting Kernel Memory. In: Proc. of 26th USENIX Security Symposium, , aug 2017.
- Tobias Hoßfeld Sebastian Surminski.Accurate Noise Measurement Using Crowdsensing.Technical report,Crowdsourcing and IoT Summer School, jul 2017.
- Ghada Dessouky, Shaza Zeitouni, Thomas Nyman, Andrew Paverd, Lucas Davi, Patrick Koeberl, N. Asokan and Ahmad-Reza Sadeghi: LO-FAT: Low-Overhead Control Flow ATtestation in Hardware. In: Proc. of 54th Design Automation Conference (DAC), , jun 2017.
- Christian Moldovan, Florian Metzger, Sebastian Surminski, Tobias Hoßfeld and Valentin Burger: Viability of Wi-Fi Caches in an Era of HTTPS Prevalence. In: Ieee Communications Society, Institute Of Electrical, Institute of Electrical Electronics Engineers and Electronics Engineers (eds.): IEEE ICC'17: Bridging People, Communities, and Cultures, , Paris, France, may 2017.
- Lucas Davi, David Gens, Christopher Liebchen and Ahmad-Reza Sadeghi: PT-Rand: Practical Mitigation of Data-only Attacks against Page Tables. In: Proc. of 24th Annual Network & Distributed System Security Symposium (NDSS), , feb 2017.
- Robert Rudd, Richard Skowyra, David Bigelow, Veer Dedhia, Thomas Hobson, Stephen Crane, Christopher Liebchen, Per Larsen, Lucas Davi, Michael Franz, Ahmad-Reza Sadeghi and Hamed Okhravi: Address Oblivious Code Reuse: On the Effectiveness of Leakage Resilient Diversity. In: Proc. of 24th Annual Network & Distributed System Security Symposium (NDSS), , feb 2017.
2016
- Dean Sullivan, Orlando Arias, Lucas Davi, Ahmad-Reza Sadeghi and Yier Jin: Towards a Policy-Agnostic Control-Flow Integrity Implementation. In: Black Hat Europe, , nov 2016.
- Tigist Abera, Nadarajah Asokan, Lucas Davi, Jan-Erik Ekberg, Thomas Nyman, Andrew Paverd, Ahmad-Reza Sadeghi and Gene Tsudik: C-FLAT: Control-Flow Attestation for Embedded Systems Software. In: Proc. of 23rd ACM Conference on Computer and Communications Security (CCS), , oct 2016. [DOI]
- Luke Deshotels, Razvan Deaconescu, Mihai Chiroiu, Lucas Davi, William Enck and Ahmad-Reza Sadeghi: SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles. In: Proc. of 23rd ACM Conference on Computer and Communications Security (CCS), , oct 2016. [DOI]
- Tigist Abera, Nadarajah Asokan, Lucas Davi, Farinaz Koushanfar, Andrew Praverd, Gene Tsudik and Ahmad-Reza Sadeghi: Invited - Things, Trouble, Trust: On Building Trust in IoT Systems. In: Proc. of 53rd Design Automation Conference (DAC), , jun 2016. [DOI]
- Julian Lettner, Benjamin Kollenda, Andrei Homescu, Per Larsen, Felix Schuster, Lucas Davi, Ahmad-Reza Sadeghi, Thorsten Holz and Michael Franz: Subversive-C: Abusing and Protecting Dynamic Message Dispatch. In: Proc. of USENIX Annual Technical Conference (ATC), , jun 2016.
- Dean Sullivan, Orlando Arias, Lucas Davi, Per Larsen, Ahmad-Reza Sadeghi and Yier Jin: Strategy Without Tactics: Policy-Agnostic Hardware-Enhanced Control-Flow Integrity. In: Proc. of 53rd Design Automation Conference (DAC), , jun 2016. [DOI]
- Stephen McLaughlin, Charalambos Konstantinou, Xueyang Wang, Lucas Davi, Ahmad-Reza Sadeghi, Michail Maniatakos and Ramesh Karri: The Cybersecurity Landscape in Industrial Control Systems.Proceedings of the IEEE, Volume 104, mar 2016, 1039-1057. [DOI]
- Kjell Braden, Stephen Crane, Lucas Davi, Michael Franz, Per Larsen, Christopher Liebchen and Ahmad-Reza Sadeghi: Leakage-Resilient Layout Randomization for Mobile Devices. In: Proc. of 23rd Annual Network & Distributed System Security Symposium (NDSS), , feb 2016.
2015
- Lucas Davi and Ahmad-Reza Sadeghi: Building Secure Defenses Against Code-Reuse Attacks , Springer International Publishing, dec 2015. [DOI]
- Per Larsen, Stefan Brunthaler, Lucas Davi, Ahmad-Reza Sadeghi and Michael Franz: Automated Software Diversity , Morgan & Claypool, dec 2015. [DOI]
- Mauro Conti, Stephen Crane, Lucas Davi, Michael Franz, Per Larsen, Christopher Liebchen, Marco Negro, Mohaned Qunaibit and Ahmad-Reza Sadeghi: Losing Control: On the Effectiveness of Control-Flow Integrity under Stack Attacks. In: Proc. of 22nd ACM Conference on Computer and Communications Security (CCS), , oct 2015. [DOI]
- Stephen Crane, Stijn Volckaert, Felix Schuster, Christopher Liebchen, Per Larsen, Lucas Davi, Ahmad-Reza Sadeghi, Thorsten Holz, Bjorn De Sutter and Michael Franz: It’s a TRAP: Table Randomization and Protection against Function Reuse Attacks. In: Proc. of 22nd ACM Conference on Computer and Communications Security (CCS), , oct 2015. [DOI]
- Stephen Crane, Christopher Liebchen, Andrei Homescu, Lucas Davi, Per Larsen, Ahmad-Reza Sadeghi, Stefan Brunthaler and Michael Franz: Return to Where? You Can’t Exploit What You Can’t Find. In: Black Hat USA, , aug 2015.
- Orlando Arias, Lucas Davi, Matthias Hanreich, Yier Jin, Patrick Koeberl, Debayan Paul, Ahmad-Reza Sadeghi and Dean Sullivan: HAFIX: Hardware-Assisted Flow Integrity Extension. In: Proc. of 52nd Design Automation Conference (DAC), , jun 2015. [DOI]
- Stephen Crane, Christopher Liebchen, Andrei Homescu, Lucas Davi, Per Larsen, Ahmad-Reza Sadeghi, Stefan Brunthaler and Michael Franz: Readactor: Practical Code Randomization Resilient to Memory Disclosure. In: Proc. of 36th IEEE Symposium on Security and Privacy (Oakland), , may 2015. [DOI]
- Felix Schuster, Thomas Tendyck, Christopher Liebchen, Lucas Davi, Ahmad-Reza Sadeghi and Thorsten Holz: Counterfeit Object-oriented Programming: On the Difficulty of Preventing Code Reuse Attacks in C++ Applications. In: Proc. of 36th IEEE Symposium on Security and Privacy (Oakland), , may 2015. [DOI]
- Mihai Bucicoiu, Lucas Davi, Razvan Deaconescu and Ahmad-Reza Sadeghi: XiOS: Extended Application Sandboxing on iOS. In: Proc. of 10th ACM Symposium on Information, Computer and Communications Security (ASIACCS), , apr 2015. [DOI]
- Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi, Kevin Snow and Fabian Monrose: Isomeron: Code Randomization Resilient to (Just-In-Time) Return-Oriented Programming. In: Proc. of 22nd Annual Network & Distributed System Security Symposium (NDSS), , feb 2015.
- Ahmad-Reza Sadeghi, Lucas Davi and Per Larsen: Securing Legacy Software against Real-World Code-Reuse Exploits: Utopia, Alchemy, or Possible Future?. In: Proc. of 10th ACM Symposium on Information, Computer and Communications Security (ASIACCS), , 2015. [DOI]
2014
- Lucas Davi, Daniel Lehmann, Ahmad-Reza Sadeghi and Fabian Monrose: Stitching the Gadgets: On the Ineffectiveness of Coarse-Grained Control-Flow Integrity Protection. In: Proc. of 23rd USENIX Security Symposium, , aug 2014.
- Lucas Davi, Daniel Lehmann and Ahmad-Reza Sadeghi: The Beast is in Your Memory: Return-Oriented Programming Attacks Against Modern Control-Flow Integrity Protection Techniques. In: Black Hat USA, , aug 2014.
- Lucas Davi, Patrick Koeberl and Ahmad-Reza Sadeghi: Hardware-Assisted Fine-Grained Control-Flow Integrity: Towards Efficient Protection of Embedded Systems Against Software Exploitation. In: Proc. of 51st Design Automation Conference (DAC) - Special Session: Trusted Mobile Embedded Computing, , jun 2014. [DOI]
- Lucas Davi, Daniel Lehmann, Ahmad-Reza Sadeghi and Fabian Monrose.Stitching the Gadgets: On the Ineffectiveness of Coarse-Grained Control-Flow Integrity Protection.Technical report TUD-CS-2014-0800,, apr 2014.
2013
- N. Asokan, Lucas Davi, Alexandra Dmitrienko, Stephan Heuser, Kari Kostiainen, Elena Reshetova and Ahmad-Reza Sadeghi: Mobile Platform Security , Morgan & Claypool, dec 2013. [DOI]
- Thomas Eder, Michael Rodler, Dieter Vymazal and Markus Zeilinger: ANANAS - A Framework for Analyzing Android Applications.Availability, Reliability and Security (ARES), 2013 Eighth International Conference on, nov 2013. [DOI]
- Blaine Stancill, Kevin Snow, Nathan Otterness, Fabian Monrose, Lucas Davi and Ahmad-Reza Sadeghi: Check My Profile: Leveraging Static Analysis for Fast and Accurate Detection of ROP Gadgets. In: Proc. of 16th Research in Attacks, Intrusions and Defenses (RAID) Symposium, , oct 2013. [DOI]
- Kevin Snow, Lucas Davi, Alexandra Dmitrienko, Christopher Liebchen, Fabian Monrose and Ahmad-Reza Sadeghi: Just-In-Time Code Reuse: The More Things Change, the More They Stay the Same. In: Black Hat USA, , aug 2013.
- Lucas Davi, Alexandra Dmitrienko, Stefan Nürnberger and Ahmad-Reza Sadeghi: Gadge Me If You Can: Secure and Efficient Ad-hoc Instruction-Level Randomization for x86 and ARM. In: Proc. of 8th ACM Symposium on Information, Computer and Communications Security (ASIACCS), , may 2013. [DOI]
- Kevin Snow, Lucas Davi, Alexandra Dmitrienko, Christopher Liebchen, Fabian Monrose and Ahmad-Reza Sadeghi: Just-In-Time Code Reuse: On the Effectiveness of Fine-Grained Address Space Layout Randomization. In: Proc. of 34th IEEE Symposium on Security and Privacy (Oakland), , may 2013. [DOI]
- Tim Werthmann, Ralf Hund, Lucas Davi, Ahmad-Reza Sadeghi and Thorsten Holz: PSiOS: Bring Your Own Privacy & Security to iOS Devices. In: Proc. of 8th ACM Symposium on Information, Computer and Communications Security (ASIACCS), , 2013. [DOI]
2012
- Lucas Davi, Alexandra Dmitrienko, Christopher Liebchen and Ahmad-Reza Sadeghi: Over-the-air Cross-Platform Infection for Breaking mTAN-based Online Banking Authentication. In: BlackHat Abu Dhabi, , dec 2012.
- Lucas Davi, Alexandra Dmitrienko, Stefan Nürnberger and Ahmad-Reza Sadeghi: XIFER: A Software Diversity Tool Against Code-Reuse Attacks. In: Proc. of 4th ACM International Workshop on Wireless of the Students, by the Students, for the Students (S3), , aug 2012.
- Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Thomas Fischer, Ahmad-Reza Sadeghi and Bhargava Shastry: Towards Taming Privilege-Escalation Attacks on Android. In: Proc. of 19th Annual Network & Distributed System Security Symposium (NDSS), , feb 2012.
- Lucas Davi, Alexandra Dmitrienko, Manuel Egele, Thomas Fischer, Thorsten Holz, Ralf Hund, Stefan Nürnberger and Ahmad-Reza Sadeghi: MoCFI: A Framework to Mitigate Control-Flow Attacks on Smartphones. In: Proc. of 19th Annual Network & Distributed System Security Symposium (NDSS), , feb 2012.
2011
- Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Thomas Fischer, Ahmad-Reza Sadeghi and Bhargava Shastry: POSTER: The Quest for Security against Privilege Escalation Attacks on Android. In: Proc. of 18th ACM Conference on Computer and Communications Security (CCS), , oct 2011. [DOI]
- Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Stephan Heuser, Ahmad-Reza Sadeghi and Bhargava Shastry: Practical and Lightweight Domain Isolation on Android. In: Proc. of 1st ACM Workshop on Security and Privacy in Mobile Devices (SPSM), , oct 2011. [DOI]
- Sven Bugiel, Lucas Davi and Steffen Schulz: Scalable Trust Establishment with Software Reputation. In: Proc. of 6th ACM Workshop on Scalable Trusted Computing (STC), , oct 2011. [DOI]
- Lucas Davi, Alexandra Dmitrienko, Manuel Egele, Thomas Fischer, Thorsten Holz, Ralf Hund, Stefan Nürnberger and Ahmad-Reza Sadeghi: POSTER: Control-Flow Integrity for Smartphones. In: Proc. of 18th ACM Conference on Computer and Communications Security (CCS), , oct 2011. [DOI]
- Lucas Davi, Alexandra Dmitrienko, Christoph Kowalski and Marcel Winandy: Trusted Virtual Domains on OKL4: Secure Information Sharing on Smartphones. In: Proc. of 6th ACM Workshop on Scalable Trusted Computing (STC), , oct 2011. [DOI]
- Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Thomas Fischer and Ahmad-Reza Sadeghi.XManDroid: A New Android Evolution to Mitigate Privilege Escalation Attacks.Technical report TR-2011-04,, apr 2011.
- Lucas Davi, Ahmad-Reza Sadeghi and Marcel Winandy: ROPdefender: A Detection Tool to Defend Against Return-Oriented Programming Attacks. In: Proc. of 6th ACM Symposium on Information, Computer and Communications Security (ASIACCS), , mar 2011. [DOI]
2010
- Stephen Checkoway, Lucas Davi, Alexandra Dmitrienko, Ahmad-Reza Sadeghi, Hovav Shacham and Marcel Winandy: Return-Oriented Programming without Returns. In: Proc. of 17th ACM conference on Computer and Communications Security (CCS), , oct 2010. [DOI]
- Lucas Davi, Alexandra Dmitrienko, Ahmad-Reza Sadeghi and Marcel Winandy: Privilege Escalation Attacks on Android. In: Proc. of 13th Information Security Conference (ISC), , oct 2010. [DOI]
- Lucas Davi, Alexandra Dmitrienko Ahmad-Reza Sadeghi and Marcel Winandy.Return-Oriented Programming without Returns on ARM.Technical report HGI-TR-2010-002,, jul 2010.
- Lucas Davi, Ahmad-Reza Sadeghi and Marcel Winandy.ROPdefender: A Detection Tool to Defend Against Return-Oriented Programming Attacks.Technical report HGI-TR-2010-001,, mar 2010.
2009
- Lucas Davi, Ahmad-Reza Sadeghi and Marcel Winandy: Dynamic integrity measurement and attestation: Towards defense against return-oriented programming attacks. In: Proc. of 4th ACM Workshop on Scalable Trusted Computing (STC), , sep 2009. [DOI]
- : . In: , , .