| 2025 | ESORICS | Transparency and Consent Challenges in mHealth Apps: An Interdisciplinary Study of Privacy Policies, Data Sharing, and Dark Patterns. | Mehrdad Bahrini, Alexander Herbst, Merle Freye, Matthias Kohn, Karsten Sohr, Rainer Malaka |
| 2024 | SACMAT | Pairing Human and Artificial Intelligence: Enforcing Access Control Policies with LLMs and Formal Specifications. | Carlos E. Rubio-Medrano, Akash Kotak, Wenlu Wang, Karsten Sohr |
| 2023 | ESORICS | Machine Learning for SAST: A Lightweight and Adaptable Approach. | Lorenz Hther, Karsten Sohr, Bernhard J. Berger, Hendrik Rothe, Stefan Edelkamp |
| 2022 | NordiCHI | It's Long and Complicated! Enhancing One-Pager Privacy Policies in Smart Home Applications. | Mehrdad Bahrini, Nima Zargham, Alexander Wolff, Dennis-Kenji Kipker, Karsten Sohr, Rainer Malaka |
| 2021 | SCAM | [Engineering] eNYPD - Entry Points Detector Jakarta Server Faces Use Case. | Rodrigue Wete Nguempnang, Bernhard J. Berger, Karsten Sohr |
| 2021 | TrustBus | A Category-Based Framework for Privacy-Aware Collaborative Access Control. | Denis Obrezkov, Karsten Sohr, Rainer Malaka |
| 2020 | SCAM | Static Extraction of Enforced Authorization Policies SeeAuthz. | Bernhard J. Berger, Rodrigue Wete Nguempnang, Karsten Sohr, Rainer Koschke |
| 2019 | CHI | HappyPermi: Presenting Critical Data Flows in Mobile Application to Raise User Security Awareness. | Mehrdad Bahrini, Nina Wenig, Marcel Meissner, Karsten Sohr, Rainer Malaka |
| 2019 | SACMAT | Towards Effective Verification of Multi-Model Access Control Properties. | Bernhard J. Berger, Christian Maeder, Rodrigue Wete Nguempnang, Karsten Sohr, Carlos E. Rubio-Medrano |
| 2019 | SCAM | The Architectural Security Tool Suite - ARCHSEC. | Bernhard J. Berger, Karsten Sohr, Rainer Koschke |
| 2016 | MODELS | Integrating UML/OCL Derived Properties into Validation and Verification Processes. | Frank Hilken, Marcel Schuster, Karsten Sohr, Martin Gogolla |
| 2013 | COMPSAC | Verifying Access Control Properties with Design by Contract: Framework and Lessons Learned. | Carlos E. Rubio-Medrano, Gail-Joon Ahn, Karsten Sohr |
| 2013 | MODELS | UML/OCL based Design and Analysis of Role-Based Access Control Policies. | Oliver Hofrichter, Martin Gogolla, Karsten Sohr |
| 2012 | SEC | An Approach to Detecting Inter-Session Data Flow Induced by Object Pooling. | Bernhard J. Berger, Karsten Sohr |
| 2011 | SAC | Software security aspects of Java-based mobile phones. | Karsten Sohr, Tanveer Mustafa, Adrian Nowak |
| 2010 | EUC | Secure Mobile Business Information Processing. | Nicolai Kuntze, Roland Rieke, Gnther Diederich, Richard Sethmann, Karsten Sohr, Tanveer Mustafa, Kai-Oliver Detken |
| 2010 | ICSE | Towards formal specification and verification of a role-based authorization engine using JML. | Tanveer Mustafa, Michael Drouineaud, Karsten Sohr |
| 2010 | IDEAL | Typed Linear Chain Conditional Random Fields and Their Application to Intrusion Detection. | Carsten Elfers, Mirko Horstmann, Karsten Sohr, Otthein Herzog |
| 2008 | ACSAC | Enforcing Role-Based Access Control Policies in Web Services with UML and OCL. | Karsten Sohr, Tanveer Mustafa, Xinyu Bao, Gail-Joon Ahn |
| 2006 | SACMAT | A model-checking approach to analysing organisational controls in a loan origination process. | Andreas Schaad, Volkmar Lotz, Karsten Sohr |
| 2005 | ESORICS | Specification and Validation of Authorisation Constraints Using UML and OCL. | Karsten Sohr, Gail-Joon Ahn, Martin Gogolla, Lars Migge |
| 2005 | ICSE | Articulating and enforcing authorisation policies with UML and OCL. | Karsten Sohr, Gail-Joon Ahn, Lars Migge |
| 2005 | SAC | Formal specification of role-based security policies for clinical information systems. | Karsten Sohr, Michael Drouineaud, Gail-Joon Ahn |
| 2003 | TIME | A temporal-logic extension of role-based access control covering dynamic separation of duties. | Till Mossakowski, Michael Drouineaud, Karsten Sohr |