| 2025 | CCS | Finding SSH Strict Key Exchange Violations by State Learning. | Fabian Bumer, Marcel Maehren, Marcus Brinkmann, Jrg Schwenk |
| 2025 | CCS | On the Security of SSH Client Signatures. | Fabian Bumer, Marcus Brinkmann, Maximilian Radoy, Jrg Schwenk, Juraj Somorovsky |
| 2023 | CCS | Finding All Cross-Site Needles in the DOM Stack: A Comprehensive Methodology for the Automatic XS-Leak Detection in Web Browsers. | Dominik Trevor No, Lukas Knittel, Christian Mainka, Marcus Niemietz, Jrg Schwenk |
| 2022 | CCS | DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On. | Louis Jannett, Vladislav Mladenov, Christian Mainka, Jrg Schwenk |
| 2021 | CCS | XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web Browsers. | Lukas Knittel, Christian Mainka, Marcus Niemietz, Dominik Trevor No, Jrg Schwenk |
| 2021 | NDSS | Processing Dangerous Paths - On Security and Privacy of the Portable Document Format. | Jens Mller, Dominik Noss, Christian Mainka, Vladislav Mladenov, Jrg Schwenk |
| 2021 | SP | Breaking the Specification: PDF Certification. | Simon Rohlmann, Vladislav Mladenov, Christian Mainka, Jrg Schwenk |
| 2020 | ACNS | Powerless Security. | Stefan Hoffmann, Jens Mller, Jrg Schwenk, Gerd Bumiller |
| 2020 | CCS | Mitigation of Attacks on Email End-to-End Encryption. | Jrg Schwenk, Marcus Brinkmann, Damian Poddebniak, Jens Mller, Juraj Somorovsky, Sebastian Schinzel |
| 2020 | PKC | Flexible Authenticated and Confidential Channel Establishment (fACCE): Analyzing the Noise Protocol Framework. | Benjamin Dowling, Paul Rsler, Jrg Schwenk |
| 2020 | PKC | Privacy-Preserving Authenticated Key Exchange and the Case of IKEv2. | Sven Schge, Jrg Schwenk, Sebastian Lauer |
| 2019 | ACNS | Re: What's Up Johnny? - Covert Content Attacks on Email End-to-End Encryption. | Jens Mller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel, Jrg Schwenk |
| 2019 | CCS | Practical Decryption exFiltration: Breaking PDF Encryption. | Jens Mller, Fabian Ising, Vladislav Mladenov, Christian Mainka, Sebastian Schinzel, Jrg Schwenk |
| 2019 | CCS | 1 Trillion Dollar Refund: How To Spoof PDF Signatures. | Vladislav Mladenov, Christian Mainka, Karsten Meyer zu Selhausen, Martin Grothe, Jrg Schwenk |
| 2018 | RAID | PostScript Undead: Pwning the Web with a 35 Years Old Language. | Jens Mller, Vladislav Mladenov, Dennis Felsch, Jrg Schwenk |
| 2017 | ACNS | Simple Security Definitions for and Constructions of 0-RTT Key Exchange. | Britta Hale, Tibor Jager, Sebastian Lauer, Jrg Schwenk |
| 2017 | CANS | Out of the Dark: UI Redressing and Trustworthy Events. | Marcus Niemietz, Jrg Schwenk |
| 2017 | CCS | SECRET: On the Feasibility of a Secure, Efficient, and Collaborative Real-Time Web Editor. | Dennis Felsch, Christian Mainka, Vladislav Mladenov, Jrg Schwenk |
| 2017 | ESORICS | DOMPurify: Client-Side Protection Against XSS and Markup Injection. | Mario Heiderich, Christopher Spth, Jrg Schwenk |
| 2017 | SP | SoK: Exploiting Network Printers. | Jens Mller, Vladislav Mladenov, Juraj Somorovsky, Jrg Schwenk |
| 2016 | CANS | Breaking PPTP VPNs via RADIUS Encryption. | Matthias Horst, Martin Grothe, Tibor Jager, Jrg Schwenk |
| 2015 | CCS | How Private is Your Private Cloud?: Security Analysis of Cloud Control Interfaces. | Dennis Felsch, Mario Heiderich, Frederic Schulz, Jrg Schwenk |
| 2015 | CCS | On the Security of TLS 1.3 and QUIC Against Weaknesses in PKCS#1 v1.5 Encryption. | Tibor Jager, Jrg Schwenk, Juraj Somorovsky |
| 2015 | ESORICS | AdIDoS - Adaptive and Intelligent Fully-Automatic Detection of Denial-of-Service Weaknesses in Web Services. | Christian Altmeier, Christian Mainka, Juraj Somorovsky, Jrg Schwenk |
| 2015 | ESORICS | Waiting for CSP - Securing Legacy Web Applications with JSAgents. | Mario Heiderich, Marcus Niemietz, Jrg Schwenk |
| 2015 | ESORICS | Practical Invalid Curve Attacks on TLS-ECDH. | Tibor Jager, Jrg Schwenk, Juraj Somorovsky |
| 2015 | PKC | One-Round Key Exchange with Strong Security: An Efficient and Generic Construction in the Standard Model. | Florian Bergsma, Tibor Jager, Jrg Schwenk |
| 2015 | SERVICES | Semi-automated Fuzzy MCDM and Lattice Solutions for WS-Policy Intersection. | Abeer Elsafie, Jrg Schwenk |
| 2014 | ACNS | New Modular Compilers for Authenticated Key Exchange. | Yong Li, Sven Schge, Zheng Yang, Christoph Bader, Jrg Schwenk |
| 2014 | CCS | Multi-Ciphersuite Security of the Secure Shell (SSH) Protocol. | Florian Bergsma, Benjamin Dowling, Florian Kohlar, Jrg Schwenk, Douglas Stebila |
| 2014 | CCS | Your Software at my Service: Security Analysis of SaaS Single Sign-On Solutions in the Cloud. | Christian Mainka, Vladislav Mladenov, Florian Feldmann, Julian Krautwald, Jrg Schwenk |
| 2014 | CCS | Guardians of the Clouds: When Identity Providers Fail. | Andreas Mayer, Marcus Niemietz, Vladislav Mladenov, Jrg Schwenk |
| 2014 | ESORICS | Modelling Time for Authenticated Key Exchange Protocols. | Jrg Schwenk |
| 2014 | PKC | On the Security of the Pre-shared Key Ciphersuites of TLS. | Yong Li, Sven Schge, Zheng Yang, Florian Kohlar, Jrg Schwenk |
| 2014 | TrustCom | TTPCookie: Flexible Third-Party Cookie Management for Increasing Online Privacy. | Ashar Javed, Christian Merz, Jrg Schwenk |
| 2014 | WISA | Systematically Breaking Online WYSIWYG Editors. | Ashar Javed, Jrg Schwenk |
| 2013 | CCS | mXSS attacks: attacking well-secured web-applications by using innerHTML mutations. | Mario Heiderich, Jrg Schwenk, Tilman Frosch, Jonas Magazinius, Edward Z. Yang |
| 2013 | ICWS | A New Approach towards DoS Penetration Testing on Web Services. | Andreas Falkenberg, Christian Mainka, Juraj Somorovsky, Jrg Schwenk |
| 2013 | WISA | Towards Elimination of Cross-Site Scripting on Mobile Versions of Web Applications. | Ashar Javed, Jrg Schwenk |
| 2013 | WISA | SoK: Lessons Learned from SSL/TLS Attacks. | Christopher Meyer, Jrg Schwenk |
| 2012 | CCS | Scriptless attacks: stealing the pie without touching the sill. | Mario Heiderich, Marcus Niemietz, Felix Schuster, Thorsten Holz, Jrg Schwenk |
| 2012 | CLOSER | XSpRES - Robust and Effective XML Signatures for Web Services. | Christian Mainka, Meiko Jensen, Luigi Lo Iacono, Jrg Schwenk |
| 2012 | CLOSER | Making XML Signatures Immune to XML Signature Wrapping Attacks. | Christian Mainka, Meiko Jensen, Luigi Lo Iacono, Jrg Schwenk |
| 2012 | CLOSER | SeC2: Secure Mobile Solution for Distributed Public Cloud Storages. | Juraj Somorovsky, Christopher Meyer, Thang Tran, Mohamad Sbeiti, Jrg Schwenk, Christian Wietfeld |
| 2012 | CRYPTO | On the Security of TLS-DHE in the Standard Model. | Tibor Jager, Florian Kohlar, Sven Schge, Jrg Schwenk |
| 2012 | ICISC | Sometimes It's Better to Be STUCK! SAML Transportation Unit for Cryptographic Keys. | Christopher Meyer, Florian Feldmann, Jrg Schwenk |
| 2012 | ProvSec | Strongly Authenticated Key Exchange Protocol from Bilinear Groups without Random Oracles. | Zheng Yang, Jrg Schwenk |
| 2012 | SERVICES | Penetration Testing Tool for Web Services Security. | Christian Mainka, Juraj Somorovsky, Jrg Schwenk |
| 2012 | SERVICES | Technical Analysis of Countermeasures against Attack on XML Encryption - or - Just Another Motivation for Authenticated Encryption. | Juraj Somorovsky, Jrg Schwenk |
| 2011 | CCS | All your clouds are belong to us: security analysis of cloud management interfaces. | Juraj Somorovsky, Mario Heiderich, Meiko Jensen, Jrg Schwenk, Nils Gruschka, Luigi Lo Iacono |
| 2010 | ASIACRYPT | Generic Compilers for Authenticated Key Exchange. | Tibor Jager, Florian Kohlar, Sven Schge, Jrg Schwenk |
| 2010 | FC | Attacking of SmartCard-Based Banking Applications with JavaScript-Based Rootkits. | Daniel Bumeyer, Felix Grbert, Jrg Schwenk, Christoph Wegener |
| 2010 | FC | A CDH-Based Ring Signature Scheme with Short Signatures and Public Keys. | Sven Schge, Jrg Schwenk |
| 2010 | LCN | Group key agreement performance in wireless mesh networks. | Andreas Noack, Jrg Schwenk |
| 2010 | SERVICES | Streaming-Based Verification of XML Signatures in SOAP Messages. | Juraj Somorovsky, Meiko Jensen, Jrg Schwenk |
| 2009 | ASIACRYPT | On the Analysis of Cryptographic Assumptions in the Generic Ring Model. | Tibor Jager, Jrg Schwenk |
| 2009 | GI | Sicherheitsanalyse von Kreditkarten am Beispiel von EMV. | Christopher Wolf, Jrg Schwenk, Zidu Wang |
| 2009 | ICWS | Analysis of Signature Wrapping Attacks and Countermeasures. | Sebastian Gajek, Meiko Jensen, Lijun Liao, Jrg Schwenk |
| 2009 | LCN | Group key agreement for wireless mesh networks. | Andreas Noack, Jrg Schwenk |
| 2008 | ACISP | Enforcing User-Aware Browser-Based Mutual Authentication with Strong Locked Same Origin Policy. | Sebastian Gajek, Mark Manulis, Jrg Schwenk |
| 2008 | CCS | Provably secure browser-based user-aware mutual authentication over TLS. | Sebastian Gajek, Mark Manulis, Ahmad-Reza Sadeghi, Jrg Schwenk |
| 2008 | ESORICS | A Browser-Based Kerberos Authentication Scheme. | Sebastian Gajek, Tibor Jager, Mark Manulis, Jrg Schwenk |
| 2008 | ICICS | A Novel Solution for End-to-End Integrity Protection in Signed PGP Mail. | Lijun Liao, Jrg Schwenk |
| 2008 | ProvSec | Universally Composable Security Analysis of TLS. | Sebastian Gajek, Mark Manulis, Olivier Pereira, Ahmad-Reza Sadeghi, Jrg Schwenk |
| 2008 | ProvSec | On the Equivalence of Generic Group Models. | Tibor Jager, Jrg Schwenk |
| 2007 | ICCSA | Provably Secure Framework for Information Aggregation in Sensor Networks. | Mark Manulis, Jrg Schwenk |
| 2007 | IWSEC | On Security Models and Compilers for Group Key Exchange Protocols. | Emmanuel Bresson, Mark Manulis, Jrg Schwenk |
| 2006 | ISPEC | Linkable Democratic Group Signatures. | Mark Manulis, Ahmad-Reza Sadeghi, Jrg Schwenk |
| 2005 | ISPEC | Visual Spoofing of SSL Protected Web Sites and Effective Countermeasures. | Andr Adelsbach, Sebastian Gajek, Jrg Schwenk |
| 1996 | EuroCrypt | Public Key Encryption and Signature Schemes Based on Polynomials over Zn. | Jrg Schwenk, Jrg Eisfeld |