| 2025 | SEC | You Still have to Study On the Security of LLM Generated Code. | Andreas Schaad, Stefan Gtz, Dominik Binder |
| 2020 | DBSEC | ML-Supported Identification and Prioritization of Threats in the OVVL Threat Modelling Tool. | Andreas Schaad, Dominik Binder |
| 2019 | SACMAT | CloudProtect - A Cloud-based Software Protection Service. | Andreas Schaad, Bjrn Grohmann, Oliver Winzenried |
| 2017 | SECRYPT | Short Paper: Industrial Feasibility of Private Information Retrieval. | Angela Jschke, Bjrn Grohmann, Frederik Armknecht, Andreas Schaad |
| 2015 | SACMAT | Initial Encryption of large Searchable Data Sets using Hadoop. | Feng Wang, Mathias Kohler, Andreas Schaad |
| 2014 | SACMAT | Optimized and controlled provisioning of encrypted outsourced data. | Andreas Schaad, Anis Bkakria, Florian Kerschbaum, Frdric Cuppens, Nora Cuppens-Boulahia, David Gross-Amblard |
| 2013 | CCS | Adjustably encrypted in-memory column-store. | Florian Kerschbaum, Patrick Grofig, Isabelle Hang, Martin Hrterich, Mathias Kohler, Andreas Schaad, Axel Schrpfer, Walter Tighzert |
| 2013 | DBSEC | Optimal Re-encryption Strategy for Joins in Encrypted Databases. | Florian Kerschbaum, Martin Hrterich, Patrick Grofig, Mathias Kohler, Andreas Schaad, Axel Schrpfer, Walter Tighzert |
| 2013 | ICISS | An Encrypted In-Memory Column-Store: The Onion Selection Problem. | Florian Kerschbaum, Martin Hrterich, Mathias Kohler, Isabelle Hang, Andreas Schaad, Axel Schrpfer, Walter Tighzert |
| 2013 | SACMAT | Secure benchmarking in the cloud. | Axel Schrpfer, Andreas Schaad, Florian Kerschbaum, Heiko Boehm, Joerg Jooss |
| 2012 | SAC | Security and safety of assets in business processes. | Ganna Monakova, Achim D. Brucker, Andreas Schaad |
| 2012 | SAC | TAM | Andreas Schaad, Mike Borozdin |
| 2012 | SACMAT | Automating architectural security analysis. | Andreas Schaad, Alexandr Garaga |
| 2011 | SACMAT | Visualizing security in business processes. | Ganna Monakova, Andreas Schaad |
| 2009 | ICIW | A Secure Comparison Technique for Tree Structured Data. | Mohammad Ashiqur Rahaman, Yves Roudier, Andreas Schaad |
| 2009 | ISI | Practical privacy-preserving protocols for criminal investigations. | Florian Kerschbaum, Andreas Schaad, Debmalya Biswas |
| 2009 | SEC | Ontology-Based Secure XML Content Distribution. | Mohammad Ashiqur Rahaman, Yves Roudier, Philip Miseldine, Andreas Schaad |
| 2009 | SERVICES | Document-Based Dynamic Workflows: Towards Flexible and Stateful Services. | Mohammad Ashiqur Rahaman, Yves Roudier, Andreas Schaad |
| 2008 | ACSAC | ProActive Access Control for Business Process-Driven Environments. | Mathias Kohler, Andreas Schaad |
| 2008 | EDOC | Distributed Access Control For XML Document Centric Collaborations. | Mohammad Ashiqur Rahaman, Yves Roudier, Andreas Schaad |
| 2008 | RE | Supporting Evidence-Based Compliance Evaluation for Partial Business Process Outsourcing Scenarios. | Philip Miseldine, Ulrich Flegel, Andreas Schaad |
| 2008 | SACMAT | Task-based entailment constraints for basic workflow patterns. | Christian Wolter, Andreas Schaad, Christoph Meinel |
| 2007 | BPM | Modeling of Task-Based Authorization Constraints in BPMN. | Christian Wolter, Andreas Schaad |
| 2007 | IPCCC | Classification Model for Access Control Constraints. | Mathias Kohler, Christian Liesegang, Andreas Schaad |
| 2007 | ICWS | SOAP-based Secure Conversation and Collaboration. | Mohammad Ashiqur Rahaman, Andreas Schaad |
| 2007 | WISE | Collaboration for Human-Centric eGovernment Workflows. | Khaled Gaaloul, Franois Charoy, Andreas Schaad, Hannah Lee |
| 2007 | WISE | A Framework for Evidence Lifecycle Management. | Andreas Schaad |
| 2007 | WISE | Deriving XACML Policies from Business Process Models. | Christian Wolter, Andreas Schaad, Christoph Meinel |
| 2006 | DBSEC | From Business Process Choreography to Authorization Policies. | Philip Robinson, Florian Kerschbaum, Andreas Schaad |
| 2006 | SACMAT | Security in enterprise resource planning systems and service-oriented architectures. | Andreas Schaad |
| 2006 | SACMAT | A model-checking approach to analysing organisational controls in a loan origination process. | Andreas Schaad, Volkmar Lotz, Karsten Sohr |
| 2005 | DBSEC | Revocation of Obligation and Authorisation Policy Objects. | Andreas Schaad |
| 2005 | ICSE | XacT: a bridge between resource management and access control in multi-layered applications. | Maarten Rits, Benjamin De Boe, Andreas Schaad |
| 2005 | SAC | A case study of separation of duty properties in the context of the Austrian "eLaw" process. | Andreas Schaad, Pascal Spadone, Helmut Weichsel |
| 2004 | DBSEC | An Extended Analysis of Delegating Obligations. | Andreas Schaad |
| 2004 | SAC | Separation, review and supervision controls in the context of a credit application process: a case study of organisational control principles. | Andreas Schaad, Jonathan D. Moffett |
| 2003 | SACMAT | An administration concept for the enterprise role-based access control model. | Axel Kern, Andreas Schaad, Jonathan D. Moffett |
| 2002 | ACSAC | A Framework for Organisational Control Principles. | Andreas Schaad, Jonathan D. Moffett |
| 2002 | SACMAT | Observations on the role life-cycle in the context of enterprise security management. | Axel Kern, Martin Kuhlmann, Andreas Schaad, Jonathan D. Moffett |
| 2002 | SACMAT | A lightweight approach to specification and analysis of role-based access control extensions. | Andreas Schaad, Jonathan D. Moffett |
| 2001 | ACSAC | Detecting Conflicts in a Role-Based Delegation Model. | Andreas Schaad |
| 2001 | SACMAT | The role-based access control system of a European bank: a case study and discussion. | Andreas Schaad, Jonathan D. Moffett, Jeremy Jacob |