| 2023 | CCS | Finding All Cross-Site Needles in the DOM Stack: A Comprehensive Methodology for the Automatic XS-Leak Detection in Web Browsers. | Dominik Trevor No, Lukas Knittel, Christian Mainka, Marcus Niemietz, Jrg Schwenk |
| 2022 | SP | On the Security of Parsing Security-Relevant HTTP Headers in Modern Browsers. | Hendrik Siewert, Martin Kretschmer, Marcus Niemietz, Juraj Somorovsky |
| 2021 | CCS | XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web Browsers. | Lukas Knittel, Christian Mainka, Marcus Niemietz, Dominik Trevor No, Jrg Schwenk |
| 2017 | CANS | Out of the Dark: UI Redressing and Trustworthy Events. | Marcus Niemietz, Jrg Schwenk |
| 2015 | ESORICS | Waiting for CSP - Securing Legacy Web Applications with JSAgents. | Mario Heiderich, Marcus Niemietz, Jrg Schwenk |
| 2014 | CCS | Guardians of the Clouds: When Identity Providers Fail. | Andreas Mayer, Marcus Niemietz, Vladislav Mladenov, Jrg Schwenk |
| 2012 | CCS | Scriptless attacks: stealing the pie without touching the sill. | Mario Heiderich, Marcus Niemietz, Felix Schuster, Thorsten Holz, Jrg Schwenk |