| 2025 | CHI | "Perfect is the Enemy of Good": The CISO's Role in Enterprise Security as a Business Enabler. | Kimberly Ruth, Veronica A. Rivera, Gautam Akiwate, Aurore Fass, Patrick Gage Kelley, Kurt Thomas, Zakir Durumeric |
| 2025 | IMC | $CookieGuard: $ Characterizing and Isolating the First-Party Cookie Jar. | Pouneh Nikkhah Bahrami, Aurore Fass, Zubair Shafiq |
| 2024 | AsiaCCS | What is in the Chrome Web Store? | Sheryl Hsu, Manda Tran, Aurore Fass |
| 2024 | CCS | Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and Interactions. | Shubham Agarwal, Aurore Fass, Ben Stock |
| 2023 | IMC | Cloud Watching: Understanding Attacks Against Cloud-Hosted Services. | Liz Izhikevich, Manda Tran, Michalis Kallitsis, Aurore Fass, Zakir Durumeric |
| 2022 | IMC | A world wide view of browsing the world wide web. | Kimberly Ruth, Aurore Fass, Jonathan Azose, Mark Pearson, Emma Thomas, Caitlin Sadowski, Zakir Durumeric |
| 2021 | CCS | DoubleX: Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale. | Aurore Fass, Dolire Francis Som, Michael Backes, Ben Stock |
| 2021 | DSN | Statically Detecting JavaScript Obfuscation and Minification Techniques in the Wild. | Marvin Moog, Markus Demmel, Michael Backes, Aurore Fass |
| 2019 | ACSAC | JStap: a static pre-filter for malicious JavaScript detection. | Aurore Fass, Michael Backes, Ben Stock |
| 2019 | CCS | HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTs. | Aurore Fass, Michael Backes, Ben Stock |
| 2018 | DIMVA | JaSt: Fully Syntactic Detection of Malicious (Obfuscated) JavaScript. | Aurore Fass, Robert P. Krawczyk, Michael Backes, Ben Stock |