| 2025 | CCS | SecAlign: Defending Against Prompt Injection with Preference Optimization. | Sizhe Chen, Arman Zharmagambetov, Saeed Mahloujifar, Kamalika Chaudhuri, David A. Wagner, Chuan Guo |
| 2025 | ICDM | SeedAIchemy: LLM-Driven Seed Corpus Generation for Fuzzing. | Aidan Wen, Norah A. Alzahrani, Jingzhi Jiang, Andrew Joe, Karen Shieh, Andy Zhang, Basel Alomair, David A. Wagner |
| 2025 | ICSE | Vulnerability Detection with Code Language Models: How Far are We? | Yangruibo Ding, Yanjun Fu, Omniyyah Ibrahim, Chawin Sitawarin, Xinyun Chen, Basel Alomair, David A. Wagner, Baishakhi Ray, Yizheng Chen |
| 2025 | MODELS | openCAESAR Application to Power Balance Analysis in Early Space Mission Formulation. | Yuta Nakajima, Haruhi Katsumata, Daiki Tate, Yutaka Komatsu, Aaron Levitt, J. Steven Jenkins, Maged Elaasar, Nicolas F. Rouquette, David A. Wagner |
| 2025 | MODELS | Power of a Reasoner: Model Validation for SysML Model using openCAESAR. | Yuta Nakajima, Atsushi Wada, Yutaka Komatsu, Maged Elaasar, J. Steven Jenkins, David A. Wagner |
| 2025 | NAACL | Stronger Universal and Transferable Attacks by Suppressing Refusals. | David Huang, Avidan Shah, Alexandre Araujo, David A. Wagner, Chawin Sitawarin |
| 2024 | ESORICS | Jatmo: Prompt Injection Defense by Task-Specific Finetuning. | Julien Piet, Maha Alrashed, Chawin Sitawarin, Sizhe Chen, Zeming Wei, Elizabeth Sun, Basel Alomair, David A. Wagner |
| 2024 | ICLR | PubDef: Defending Against Transfer Attacks From Public Models. | Chawin Sitawarin, Jaewon Chang, David Huang, Wesson Altoyan, David A. Wagner |
| 2023 | ICCV | REAP: A Large-Scale Realistic Adversarial Patch Benchmark. | Nabeel Hingun, Chawin Sitawarin, Jerry Li, David A. Wagner |
| 2023 | ICLR | Part-Based Models Improve Adversarial Robustness. | Chawin Sitawarin, Kornrapat Pongmala, Yizheng Chen, Nicholas Carlini, David A. Wagner |
| 2023 | MODELS | openCAESAR: Balancing Agility and Rigor in Model-Based Systems Engineering. | Maged Elaasar, Nicolas Rouquette, David A. Wagner, Bentley Oakes, Abdelwahab Hamou-Lhadj, Mohammad Hamdaqa |
| 2023 | RAID | DiverseVul: A New Vulnerable Source Code Dataset for Deep Learning Based Vulnerability Detection. | Yizheng Chen, Zhoujie Ding, Lamya Alowain, Xinyun Chen, David A. Wagner |
| 2022 | ECCV | SLIP: Self-supervision Meets Language-Image Pre-training. | Norman Mu, Alexander Kirillov, David A. Wagner, Saining Xie |
| 2022 | ICML | Demystifying the Adversarial Robustness of Random Transformation Defenses. | Chawin Sitawarin, Zachary J. Golan-Strieb, David A. Wagner |
| 2022 | SOUPS | Runtime Permissions for Privacy in Proactive Intelligent Assistants. | Nathan Malkin, David A. Wagner, Serge Egelman |
| 2021 | CCS | Learning Security Classifiers with Verified Global Robustness Properties. | Yizheng Chen, Shiqi Wang, Yue Qin, Xiaojing Liao, Suman Jana, David A. Wagner |
| 2021 | CCS | SAT: Improving Adversarial Training via Curriculum-Based Loss Smoothing. | Chawin Sitawarin, Supriyo Chakraborty, David A. Wagner |
| 2021 | CCS | SEAT: Similarity Encoder by Adversarial Training for Detecting Model Extraction Attack Queries. | Zhanyuan Zhang, Yizheng Chen, David A. Wagner |
| 2020 | ACNS | Minority Reports Defense: Defending Against Adversarial Patches. | Michael McCoyd, Won Park, Steven Chen, Neil Shah, Ryan Roggenkemper, Minjune Hwang, Jason Xinyu Liu, David A. Wagner |
| 2020 | CCS | E-ABS: Extending the Analysis-By-Synthesis Robust Classification Model to More Complex Image Domains. | An Ju, David A. Wagner |
| 2020 | SP | Minimum-Norm Adversarial Examples on KNN and KNN based Models. | Chawin Sitawarin, David A. Wagner |
| 2020 | SP | Clipped BagNet: Defending Against Sticker Attacks with Clipped Bag-of-features. | Zhanyuan Zhang, Benson Yuan, Michael McCoyd, David A. Wagner |
| 2019 | NSPW | Privacy controls for always-listening devices. | Nathan Malkin, Serge Egelman, David A. Wagner |
| 2019 | SP | On the Robustness of Deep K-Nearest Neighbors. | Chawin Sitawarin, David A. Wagner |
| 2018 | CHI | Contextualizing Privacy Decisions for Better Prediction (and Protection). | Primal Wijesekera, Joel Reardon, Irwin Reyes, Lynn Tsai, Jung-Wei Chen, Nathan Good, David A. Wagner, Konstantin Beznosov, Serge Egelman |
| 2018 | ICML | Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. | Anish Athalye, Nicholas Carlini, David A. Wagner |
| 2018 | SP | Audio Adversarial Examples: Targeted Attacks on Speech-to-Text. | Nicholas Carlini, David A. Wagner |
| 2018 | SP | Background Class Defense Against Adversarial Examples. | Michael McCoyd, David A. Wagner |
| 2018 | WiMob | Inferring Phone Location State. | Steven Chen, Won Park, Joanna Yang, David A. Wagner |
| 2017 | CCS | Security and Machine Learning. | David A. Wagner |
| 2017 | CCS | Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods. | Nicholas Carlini, David A. Wagner |
| 2017 | SP | Towards Evaluating the Robustness of Neural Networks. | Nicholas Carlini, David A. Wagner |
| 2017 | SP | The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User Preferences. | Primal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon, Serge Egelman, David A. Wagner, Konstantin Beznosov |
| 2017 | SOUPS | Turtle Guard: Helping Android Users Apply Contextual Privacy Preferences. | Lynn Tsai, Primal Wijesekera, Joel Reardon, Irwin Reyes, Serge Egelman, David A. Wagner, Nathan Good, Jung-Wei Chen |
| 2016 | CCS | Attestation Transparency: Building secure Internet services for legacy clients. | Jethro G. Beekman, John L. Manferdelli, David A. Wagner |
| 2016 | CCS | Smart Locks: Lessons for Securing Commodity Internet of Things Devices. | Grant Ho, Derek Leung, Pratyush Mishra, Ashkan Hosseini, Dawn Song, David A. Wagner |
| 2016 | CCS | Securing Recognizers for Rich Video Applications. | Christopher Thompson, David A. Wagner |
| 2016 | SOUPS | Recovering High-Value Secrets with SGX and Social Authentication. | Nathan Malkin, Serge Egelman, David A. Wagner |
| 2015 | CCS | The Performance Cost of Shadow Stacks and Stack Canaries. | Thurston H. Y. Dang, Petros Maniatis, David A. Wagner |
| 2015 | CHI | Somebody's Watching Me?: Assessing the Effectiveness of Webcam Indicator Lights. | Rebecca S. Portnoff, Linda Naeun Lee, Serge Egelman, Pratyush Mishra, Derek Leung, David A. Wagner |
| 2014 | CCS | Are You Ready to Lock? | Serge Egelman, Sakshi Jain, Rebecca S. Portnoff, Kerwell Liao, Sunny Consolvo, David A. Wagner |
| 2014 | CHI | The effect of developer-specified explanations for permission requests on smartphone user behavior. | Joshua Tan, Khanh Nguyen, Michael Theodorides, Heidi Negrn-Arroyo, Christopher Thompson, Serge Egelman, David A. Wagner |
| 2013 | MEMOCODE | Symbolic software model validation. | Cynthia Sturton, Rohit Sinha, Thurston H. Y. Dang, Sakshi Jain, Michael McCoyd, Wei Yang Tan, Petros Maniatis, Sanjit A. Seshia, David A. Wagner |
| 2013 | SOUPS | When it's better to ask forgiveness than get permission: attribution mechanisms for smartphone resources. | Christopher Thompson, Maritza L. Johnson, Serge Egelman, David A. Wagner, Jennifer King |
| 2013 | WISA | Bifocals: Analyzing WebView Vulnerabilities in Android Applications. | Erika Chin, David A. Wagner |
| 2012 | CCS | I've got 99 problems, but vibration ain't one: a survey of smartphone users' concerns. | Adrienne Porter Felt, Serge Egelman, David A. Wagner |
| 2012 | CCS | Short paper: location privacy: user behavior in the field. | Drew Fisher, Leah Dorner, David A. Wagner |
| 2012 | CCS | Reducing attack surfaces for intra-application communication in android. | David Kantola, Erika Chin, Warren He, David A. Wagner |
| 2012 | CCS | AdDroid: privilege separation for applications and advertisers in Android. | Paul Pearce, Adrienne Porter Felt, Gabriel Nunez, David A. Wagner |
| 2012 | FMCAD | Verification with small and short worlds. | Rohit Sinha, Cynthia Sturton, Petros Maniatis, Sanjit A. Seshia, David A. Wagner |
| 2012 | SOUPS | Measuring user confidence in smartphone security and privacy. | Erika Chin, Adrienne Porter Felt, Vyas Sekar, David A. Wagner |
| 2012 | SOUPS | Android permissions: user attention, comprehension, and behavior. | Adrienne Porter Felt, Elizabeth Ha, Serge Egelman, Ariel Haney, Erika Chin, David A. Wagner |
| 2011 | CCS | Android permissions demystified. | Adrienne Porter Felt, Erika Chin, Steve Hanna, Dawn Song, David A. Wagner |
| 2011 | CCS | A survey of mobile malware in the wild. | Adrienne Porter Felt, Matthew Finifter, Erika Chin, Steve Hanna, David A. Wagner |
| 2011 | CCS | Diesel: applying privilege separation to database access. | Adrienne Porter Felt, Matthew Finifter, Joel Weinberger, David A. Wagner |
| 2011 | Mobisys | Analyzing inter-application communication in Android. | Erika Chin, Adrienne Porter Felt, Kate Greenwood, David A. Wagner |
| 2011 | SP | Defeating UCI: Building Stealthy and Malicious Hardware. | Cynthia Sturton, Matthew Hicks, David A. Wagner, Samuel T. King |
| 2010 | NDSS | Joe-E: A Security-Oriented Subset of Java. | Adrian Mettler, David A. Wagner, Tyler Close |
| 2010 | PLDI | Class properties for security review in an object-capability subset of Java: (short paper). | Adrian Mettler, David A. Wagner |
| 2010 | WWW | Fine-grained privilege separation for web applications. | Akshay Krishnamurthy, Adrian Mettler, David A. Wagner |
| 2009 | CCS | On voting machine design for verification and testability. | Cynthia Sturton, Susmit Jha, Sanjit A. Seshia, David A. Wagner |
| 2009 | NDSS | Conditioned-safe Ceremonies and a User Study of an Application to Web Authentication. | Chris Karlof, J. Doug Tygar, David A. Wagner |
| 2009 | SOUPS | Conditioned-safe ceremonies and a user study of an application to web authentication. | Chris Karlof, J. D. Tygar, David A. Wagner |
| 2008 | CCS | Verifiable functional purity in java. | Matthew Finifter, Adrian Mettler, Naveen Sastry, David A. Wagner |
| 2008 | FAST | Portably Solving File TOCTTOU Races with Hardness Amplification. | Dan Tsafrir, Tomer Hertz, David A. Wagner, Dilma Da Silva |
| 2008 | FSE | Algebraic and Slide Attacks on KeeLoq. | Nicolas T. Courtois, Gregory V. Bard, David A. Wagner |
| 2008 | ISORC | C++ Dynamic Cast in Autonomous Space Systems. | Damian Dechev, Rabi N. Mahapatra, Bjarne Stroustrup, David A. Wagner |
| 2008 | NSDI | A User Study Design for Comparing the Security of Registration Protocols. | Chris Karlof, J. Doug Tygar, David A. Wagner |
| 2007 | CCS | Dynamic pharming attacks and locked same-origin policies for web browsers. | Chris Karlof, Umesh Shankar, J. Doug Tygar, David A. Wagner |
| 2007 | IROS | Safety verification of a fault tolerant reconfigurable autonomous goal-based robotic control system. | Julia M. B. Braman, Richard M. Murray, David A. Wagner |
| 2007 | PLDI | Large-scale analysis of format string vulnerabilities in Debian Linux. | Karl Chen, David A. Wagner |
| 2007 | SP | Cryptanalysis of a Cognitive Authentication Scheme (Extended Abstract). | Philippe Golle, David A. Wagner |
| 2007 | TCC | From Weak to Strong Watermarking. | Nicholas Hopper, David Molnar, David A. Wagner |
| 2006 | CRYPTO | Cryptographic Protocols for Electronic Voting. | David A. Wagner |
| 2006 | EuroCrypt | Private Circuits II: Keeping Secrets in Tamperable Circuits. | Yuval Ishai, Manoj Prabhakaran, Amit Sahai, David A. Wagner |
| 2006 | PKC | Generic On-Line/Off-Line Threshold Signatures. | Chris Crutchfield, David Molnar, David Turner, David A. Wagner |
| 2006 | PLDI | Object capabilities for security. | David A. Wagner |
| 2006 | SP | Tamper-Evident, History-Independent, Subliminal-Free Data Structures on PROM Storage-or-How to Store Ballots on a Voting Machine (Extended Abstract). | David Molnar, Tadayoshi Kohno, Naveen Sastry, David A. Wagner |
| 2005 | ACSAC | Model Checking An Entire Linux Distribution for Security Violations. | Benjamin Schwarz, Hao Chen, David A. Wagner, Jeremy Lin, Wei Tu, Geoff Morrison, Jacob West |
| 2005 | ACSAC | Fault Attacks on Dual-Rail Encoded Systems. | Jason Waddle, David A. Wagner |
| 2005 | ICISC | The Program Counter Security Model: Automatic Detection and Removal of Control-Flow Side Channel Attacks. | David Molnar, Matt Piotrowski, David Schultz, David A. Wagner |
| 2005 | SMC | Data management in the mission data system. | David A. Wagner |
| 2005 | SecureComm | Security and Privacy Issues in E-passports. | Ari Juels, David Molnar, David A. Wagner |
| 2004 | CCS | Privacy and security in library RFID: issues, practices, and architectures. | David Molnar, David A. Wagner |
| 2004 | CCS | Cryptanalysis of a provably secure CRT-RSA algorithm. | David A. Wagner |
| 2004 | CHES | Towards Efficient Second-Order Power Analysis. | Jason Waddle, David A. Wagner |
| 2004 | FSE | The EAX Mode of Operation. | Mihir Bellare, Phillip Rogaway, David A. Wagner |
| 2004 | FSE | Towards a Unifying View of Block Cipher Cryptanalysis. | David A. Wagner |
| 2004 | NDSS | Model Checking One Million Lines of C Code. | Hao Chen, Drew Dean, David A. Wagner |
| 2004 | SENSYS | TinySec: a link layer security architecture for wireless sensor networks. | Chris Karlof, Naveen Sastry, David A. Wagner |
| 2004 | TACAS | A Class of Polynomially Solvable Range Constraints for Interval Analysis without Widenings and Narrowings. | Zhendong Su, David A. Wagner |
| 2004 | TCC | On Compressing Encrypted Data without the Encryption Key. | Mark Johnson, David A. Wagner, Kannan Ramchandran |
| 2003 | CHES | Hidden Markov Model Cryptanalysis. | Chris Karlof, David A. Wagner |
| 2003 | CRYPTO | Private Circuits: Securing Hardware against Probing Attacks. | Yuval Ishai, Amit Sahai, David A. Wagner |
| 2002 | CCS | MOPS: an infrastructure for examining security properties of software. | Hao Chen, David A. Wagner |
| 2002 | CCS | Mimicry attacks on host-based intrusion detection systems. | David A. Wagner, Paolo Soto |
| 2002 | CRYPTO | Tweakable Block Ciphers. | Moses D. Liskov, Ronald L. Rivest, David A. Wagner |
| 2002 | CRYPTO | A Generalized Birthday Problem. | David A. Wagner |
| 2002 | FSE | Multiplicative Differentials. | Nikita Borisov, Monica Chew, Robert Johnson, David A. Wagner |
| 2002 | FSE | Integral Cryptanalysis. | Lars R. Knudsen, David A. Wagner |
| 2002 | INFOCOM | Securing Wireless and Mobile Networks - Is It Possible? | Will Ivancic, David A. Wagner, Aviel D. Rubin, E. Paul Ratazzi, James P. G. Sterbenz |
| 2002 | SACMAT | Cool security trends. | Dawson R. Engler, Cynthia E. Irvine, Trent Jaeger, David A. Wagner |
| 2001 | CCS | A Cryptanalysis of the High-Bandwidth Digital Content Protection System. | Scott A. Crosby, Ian Goldberg, Robert Johnson, Dawn Xiaodong Song, David A. Wagner |
| 2001 | MOBICOM | Intercepting mobile communications: the insecurity of 802.11. | Nikita Borisov, Ian Goldberg, David A. Wagner |
| 2001 | SP | Intrusion Detection via Static Analysis. | David A. Wagner, Drew Dean |
| 2001 | SAS | Static Analysis and Software Assurance. | David A. Wagner |
| 2000 | ACISP | Security Weaknesses in a Randomized Stream Cipher. | Niels Ferguson, Bruce Schneier, David A. Wagner |
| 2000 | ASIACRYPT | Cryptanalysis of the Yi-Lam Hash. | David A. Wagner |
| 2000 | ASIACRYPT | Proofs of Security for the Unix Password Hashing Algorithm. | David A. Wagner, Ian Goldberg |
| 2000 | EuroCrypt | Advanced Slide Attacks. | Alex Biryukov, David A. Wagner |
| 2000 | FSE | Real Time Cryptanalysis of A5/1 on a PC. | Alex Biryukov, Adi Shamir, David A. Wagner |
| 2000 | FSE | Improved Cryptanalysis of Rijndael. | Niels Ferguson, John Kelsey, Stefan Lucks, Bruce Schneier, Michael Stay, David A. Wagner, Doug Whiting |
| 2000 | NDSS | A First Step Towards Automated Detection of Buffer Overrun Vulnerabilities. | David A. Wagner, Jeffrey S. Foster, Eric A. Brewer, Alexander Aiken |
| 2000 | SP | Practical Techniques for Searches on Encrypted Data. | Dawn Xiaodong Song, David A. Wagner, Adrian Perrig |
| 1999 | CRYPTO | Truncated Differentials and Skipjack. | Lars R. Knudsen, Matthew J. B. Robshaw, David A. Wagner |
| 1999 | FSE | Slide Attacks. | Alex Biryukov, David A. Wagner |
| 1999 | FSE | Mod n Cryptanalysis, with Applications Against RC5P and M6. | John Kelsey, Bruce Schneier, David A. Wagner |
| 1999 | FSE | The Boomerang Attack. | David A. Wagner |
| 1998 | CRYPTO | Building PRFs from PRPs. | Chris Hall, David A. Wagner, John Kelsey, Bruce Schneier |
| 1998 | ESORICS | Side Channel Cryptanalysis of Product Ciphers. | John Kelsey, Bruce Schneier, David A. Wagner, Chris Hall |
| 1998 | FC | Cryptanalysis of SPEED. | Chris Hall, John Kelsey, Bruce Schneier, David A. Wagner |
| 1998 | FSE | Cryptanalysis of TWOPRIME. | Don Coppersmith, David A. Wagner, Bruce Schneier, John Kelsey |
| 1998 | FSE | Cryptanalytic Attacks on Pseudorandom Number Generators. | John Kelsey, Bruce Schneier, David A. Wagner, Chris Hall |
| 1998 | FSE | Cryptanalysis of Some Recently-Proposed Multiple Modes of Operation. | David A. Wagner |
| 1998 | FSE | Differential Cryptanalysis of KHF. | David A. Wagner |
| 1997 | CRYPTO | Cryptanalysis of the Cellular Encryption Algorithm. | David A. Wagner, Bruce Schneier, John Kelsey |
| 1997 | ICICS | Related-key cryptanalysis of 3-WAY, Biham-DES, CAST, DES-X, NewDES, RC2, and TEA. | John Kelsey, Bruce Schneier, David A. Wagner |
| 1996 | CRYPTO | Key-Schedule Cryptanalysis of IDEA, G-DES, GOST, SAFER, and Triple-DES. | John Kelsey, Bruce Schneier, David A. Wagner |
| 1996 | NDSS | A "bump in the stack" encryptor for MS-DOS systems. | David A. Wagner, Steven M. Bellovin |
| 1993 | MASCOTS | A Testbed for Studying Parallel Programs and Parallel Execution Architectures. | Dirk Grunwald, Gary J. Nutt, Anthony M. Sloane, David A. Wagner, Benjamin G. Zorn |