| 2026 | AsiaCCS | Kitten or Panda? Measuring the Specificity of Threat Group Behaviors in Public CTI Knowledge Bases. | Aakanksha Saha, Martina Lindorfer, Juan Caballero |
| 2025 | ESORICS | The Polymorphism Maze: Understanding Diversities and Similarities in Malware Families. | Antonino Vitale, Simone Aonzo, Savino Dambra, Nanda Rani, Lorenzo Ippolito, Platon Kotzias, Juan Caballero, Davide Balzarotti |
| 2025 | NDSS | Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams. | Platon Kotzias, Michalis Pachilakis, Javier Aldana-Iuit, Juan Caballero, Iskander Snchez-Rola, Leyla Bilge |
| 2025 | NDSS | All your (data)base are belong to us: Characterizing Database Ransom(ware) Attacks. | Kevin van Liebergen, Gibran Gmez, Srdjan Matic, Juan Caballero |
| 2023 | ACSAC | Domain and Website Attribution beyond WHOIS. | Silvia Sebastin, Raluca-Georgia Diugan, Juan Caballero, Iskander Snchez-Rola, Leyla Bilge |
| 2023 | CCS | Decoding the Secrets of Machine Learning in Malware Classification: A Deep Dive into Datasets, Feature Extraction, and Model Performance. | Savino Dambra, Yufei Han, Simone Aonzo, Platon Kotzias, Antonino Vitale, Juan Caballero, Davide Balzarotti, Leyla Bilge |
| 2023 | CCS | Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and Coverage. | Gibran Gmez, Kevin van Liebergen, Juan Caballero |
| 2023 | DIMVA | A Deep Dive into the VirusTotal File Feed. | Kevin van Liebergen, Juan Caballero, Platon Kotzias, Chris Gates |
| 2022 | CCS | Watch Your Back: Identifying Cybercrime Financial Relationships in Bitcoin through Back-and-Forth Exploration. | Gibran Gmez, Pedro Moreno-Sanchez, Juan Caballero |
| 2022 | SCAM | On the Usage of Programming Languages in the iOS Ecosystem. | Daniel Domnguez-lvarez, Alessandra Gorla, Juan Caballero |
| 2021 | VTC | Data Provenance in Vehicle Data Chains. | Daniel Wilms, Carsten Stcker, Juan Caballero |
| 2021 | SP | How Did That Get In My Phone? Unwanted App Distribution on Android Devices. | Platon Kotzias, Juan Caballero, Leyla Bilge |
| 2020 | ACSAC | AVclass2: Massive Malware Tag Extraction from AV Labels. | Silvia Sebastin, Juan Caballero |
| 2020 | CCS | Towards Attribution in Mobile Markets: Identifying Developer Account Polymorphism. | Silvia Sebastin, Juan Caballero |
| 2020 | NDSS | Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks. | Avinash Sudhodanan, Soheil Khodayari, Juan Caballero |
| 2019 | NDSS | Mind Your Own Business: A Longitudinal Study of Threats and Vulnerabilities in Enterprises. | Platon Kotzias, Leyla Bilge, Pierre-Antoine Vervier, Juan Caballero |
| 2018 | CCS | BCD: Decomposing Binary Code Into Components Using Graph-Based Clustering. | Vishal Karande, Swarup Chandra, Zhiqiang Lin, Juan Caballero, Latifur Khan, Kevin W. Hamlen |
| 2018 | CCS | K-Hunt: Pinpointing Insecure Cryptographic Keys from Execution Traces. | Juanru Li, Zhiqiang Lin, Juan Caballero, Yuanyuan Zhang, Dawu Gu |
| 2018 | IMC | Coming of Age: A Longitudinal Study of TLS Deployment. | Platon Kotzias, Abbas Razaghpanah, Johanna Amann, Kenneth G. Paterson, Narseo Vallina-Rodriguez, Juan Caballero |
| 2017 | NDSS | Dissecting Tor Bridges: A Security Evaluation of their Private and Public Infrastructures. | Srdjan Matic, Carmela Troncoso, Juan Caballero |
| 2017 | SP | A Lustrum of Malware Network Communication: Evolution and Insights. | Chaz Lever, Platon Kotzias, Davide Balzarotti, Juan Caballero, Manos Antonakakis |
| 2016 | ACSAC | RevProbe: detecting silent reverse proxies in malicious server infrastructures. | Antonio Nappa, Rana Faisal Munir, Irfan Khan Tanoli, Christian Kreibich, Juan Caballero |
| 2016 | RAID | A Look into 30 Years of Malware Development from a Software Metrics Perspective. | Alejandro Calleja, Juan E. Tapiador, Juan Caballero |
| 2016 | RAID | AVclass: A Tool for Massive Malware Labeling. | Marcos Sebastin, Richard Rivera, Platon Kotzias, Juan Caballero |
| 2015 | CCS | Certified PUP: Abuse in Authenticode Code Signing. | Platon Kotzias, Srdjan Matic, Richard Rivera, Juan Caballero |
| 2015 | CCS | CARONTE: Detecting Location Leaks for Deanonymizing Tor Hidden Services. | Srdjan Matic, Platon Kotzias, Juan Caballero |
| 2015 | OOPSLA | Ayudante: identifying undesired variable interactions. | Irfan Ul Haq, Juan Caballero, Michael D. Ernst |
| 2015 | SP | The Attack of the Clones: A Study of the Impact of Shared Code on Vulnerability Patching. | Antonio Nappa, Richard Johnson, Leyla Bilge, Juan Caballero, Tudor Dumitras |
| 2014 | ACSAC | Network dialog minimization and network dialog diffing: two novel primitives for network security applications. | M. Zubair Rafique, Juan Caballero, Christophe Huygens, Wouter Joosen |
| 2014 | CCS | AUTOPROBE: Towards Automatic Active Malicious Server Probing Using Dynamic Binary Analysis. | Zhaoyan Xu, Antonio Nappa, Robert Baykov, Guangliang Yang, Juan Caballero, Guofei Gu |
| 2014 | ESORICS | SigPath: A Memory Graph Based Approach for Program Data Introspection and Modification. | David I. Urbina, Yufei Gu, Juan Caballero, Zhiqiang Lin |
| 2014 | IMC | WhoWas: A Platform for Measuring Web Deployments on IaaS Clouds. | Liang Wang, Antonio Nappa, Juan Caballero, Thomas Ristenpart, Aditya Akella |
| 2014 | NDSS | CyberProbe: Towards Internet-Scale Active Detection of Malicious Servers. | Antonio Nappa, Zhaoyan Xu, M. Zubair Rafique, Juan Caballero, Guofei Gu |
| 2013 | CCS | Cross-platform malware: write once, infect everywhere. | Martina Lindorfer, Matthias Neumayr, Juan Caballero, Christian Platzer |
| 2013 | DIMVA | Driving in the Cloud: An Analysis of Drive-by Download Operations and Abuse Reporting. | Antonio Nappa, M. Zubair Rafique, Juan Caballero |
| 2013 | RAID | FIRMA: Malware Clustering and Network Signature Generation with Mixed Network Behaviors. | M. Zubair Rafique, Juan Caballero |
| 2012 | CCS | Manufacturing compromise: the emergence of exploit-as-a-service. | Chris Grier, Lucas Ballard, Juan Caballero, Neha Chachra, Christian J. Dietrich, Kirill Levchenko, Panayiotis Mavrommatis, Damon McCoy, Antonio Nappa, Andreas Pitsillidis, Niels Provos, M. Zubair Rafique, Moheeb Abu Rajab, Christian Rossow, Kurt Thomas, Vern Paxson, Stefan Savage, Geoffrey M. Voelker |
| 2012 | ISSTA | Undangle: early detection of dangling pointers in use-after-free and double-free vulnerabilities. | Juan Caballero, Gustavo Grieco, Mark Marron, Antonio Nappa |
| 2011 | SP | Differential Slicing: Identifying Causal Execution Differences for Security Applications. | Noah M. Johnson, Juan Caballero, Kevin Zhijie Chen, Stephen McCamant, Pongsin Poosankam, Daniel Reynaud, Dawn Song |
| 2010 | CCS | Input generation via decomposition and re-stitching: finding bugs in Malware. | Juan Caballero, Pongsin Poosankam, Stephen McCamant, Domagoj Babic, Dawn Song |
| 2010 | NDSS | Binary Code Extraction and Interface Identification for Security Applications. | Juan Caballero, Noah M. Johnson, Stephen McCamant, Dawn Song |
| 2009 | CCS | Dispatcher: enabling active botnet infiltration using automatic protocol reverse-engineering. | Juan Caballero, Pongsin Poosankam, Christian Kreibich, Dawn Xiaodong Song |
| 2009 | RAID | Towards Generating High Coverage Vulnerability-Based Signatures with Protocol-Level Constraint-Guided Exploration. | Juan Caballero, Zhenkai Liang, Pongsin Poosankam, Dawn Song |
| 2009 | SP | Secure Content Sniffing for Web Browsers, or How to Stop Papers from Reviewing Themselves. | Adam Barth, Juan Caballero, Dawn Song |
| 2008 | ICISS | BitBlaze: A New Approach to Computer Security via Binary Analysis. | Dawn Xiaodong Song, David Brumley, Heng Yin, Juan Caballero, Ivan Jager, Min Gyung Kang, Zhenkai Liang, James Newsome, Pongsin Poosankam, Prateek Saxena |
| 2008 | NDSS | Would Diversity Really Increase the Robustness of the Routing Infrastructure against Software Defects? | Juan Caballero, Theocharis Kampouris, Dawn Song, Jia Wang |
| 2007 | CCS | Polyglot: automatic extraction of protocol message format using dynamic binary analysis. | Juan Caballero, Heng Yin, Zhenkai Liang, Dawn Xiaodong Song |
| 2007 | DIMVA | Distributed Evasive Scan Techniques and Countermeasures. | Min Gyung Kang, Juan Caballero, Dawn Xiaodong Song |
| 2007 | NDSS | Fig: Automatic Fingerprint Generation. | Shobha Venkataraman, Juan Caballero, Pongsin Poosankam, Min Gyung Kang, Dawn Xiaodong Song |
| 2006 | HOTNETS | Black Box Anomaly Detection: Is It Utopian?. | Shobha Venkataraman, Juan Caballero, Dawn Song, Avrim Blum, Jennifer Yates |