member image

I am a tenure-track faculty at CISPA Helmholtz Center for Information Security. With my group, we research on multiple aspects of the security of modern web applications.

Areas of interest:

  • Web security, security testing, and automated vulnerability analysis
  • ML/AI for security testing

Research

Current interests

Vulnerability Detection and Analysis:

  • Web application scanners (Black Widow [IEEE SP 2021], jAEk [RAID 2015])
  • Cross-site request forgery (Same-site [Oakland 2022], JAW [Usenix 2021], Web frameworks [RAID 2021], Deemon [ACM CSS 2017])
  • Server-side requests (Link previews [NDSS 2020], SSR abuse [RAID 2016])
  • Backdoors and hidden features [IEEE SP 2020]
  • Web API security [NDSS 2019]
  • Logic vulnerabilities [NDSS 2014]

Web Platform Security:

  • Web enclaves and trusted user I/O path (Fidelius [IEEE SP 2019])
  • Internet core services security (Who controls the Internet [WWW 2017], the Great Cannon [WOOT 2015])

Security of ML-based Systems:

  • Attacking perceptual ad-blocking [CCS 2019]
  • Detection of adversarial physical attacks [IEEE DLS 2020]

Service

  • PC member at Usenix Security (2022, 2021, 2020, 2019), IEEE S&P (2022, 2021), ACM CCS (2021, 2020, 2018), IEEE Euro S&P (2022, 2020), ACSAC (2021, 2020, 2019, 2018, 2017), ACM AsiaCCS (2021, 2020, 2019), The Web Conference WWW (2021, 2020), DIMVA (2021, 2020), EuroSec (2021, 2020, 2019), ISC (2019), CARDS (2019), Usenix WOOT (2018), ACM CCS Poster (2016), IWCC (2016, 2015), DEPEND (2016, 2015), WTMC (2016), STAST (2014), NBiS (2014)
  • General co-chair for IEEE Euro S&P (2020)
  • PC co-chair for SECTEST2015
  • Usenix Security invited talks committee (2021, 2019)
  • Publicity chair for ACM CCS (2017)
  • Publication chair for DIMVA (2021)
  • Reviewer for ACM Computing Surveys, IEEE Transactions on Cloud Computing (TCC), and Transactions on Dependable and Secure Computing (TDSC)

Contact