| 2026 | NDSS | Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation Implementations. | Jan Drescher, David Klein, Martin Johns |
| 2025 | ACSAC | Uncovering Bigger Truths: Deobfuscating PHP with Phoebe. | Manuel Karl, Simon Koch, David Klein, Martin Johns |
| 2025 | CCS | In the DOM We Trust: Exploring the Hidden Dangers of Reading from the DOM on the Web. | Jan Drescher, Sepehr Mirzaei, Soheil Khodayari, David Klein, Thomas Barber, Martin Johns, Giancarlo Pellegrino |
| 2025 | CCS | The Power to Never Be Wrong: Evasions and Anachronistic Attacks Against Web Archives. | Robin Kirchner, Chris Tsoukaladelis, Martin Johns, Nick Nikiforakis |
| 2025 | SP | The Importance of Being Earnest: Shedding Light on Johnny's (False) Sense of Privacy. | Wirawan Agahari, Alexandra Dirksen, Martin Johns, Mark de Reuver, Tobias Fiebig |
| 2025 | SP | "Sorry for Bugging you so much." Exploring Developers' Behavior Towards Privacy-Compliant Implementation. | Stefan Albert Horstmann, Sandy Hong, David Klein, Raphael Serafini, Martin Degeling, Martin Johns, Veelasha Moonsamy, Alena Naiakshina |
| 2024 | NSPW | Don't Patch the Researcher, Patch the Game: A Systematic Approach for Responsible Research via Federated Ethics Boards. | Alexandra Dirksen, Sebastian Giessler, Hendrik Erz, Martin Johns, Tobias Fiebig |
| 2024 | SP | Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials. | David Klein, Martin Johns |
| 2023 | CCS | General Data Protection Runtime: Enforcing Transparent GDPR Compliance for Existing Applications. | David Klein, Benny Rolle, Thomas Barber, Manuel Karl, Martin Johns |
| 2023 | CCS | Poster: The Risk of Insufficient Isolation of Database Transactions in Web Applications. | Simon Koch, Malte Wessels, David Klein, Martin Johns |
| 2023 | NDSS | FUZZILLI: Fuzzing for JavaScript JIT Compiler Vulnerabilities. | Samuel Gro, Simon Koch, Lukas Bernhard, Thorsten Holz, Martin Johns |
| 2022 | ACSAC | Accept All Exploits: Exploring the Security Impact of Cookie Banners. | David Klein, Marius Musch, Thomas Barber, Moritz Kopmann, Martin Johns |
| 2022 | AsiaCCS | Server-Side Browsers: Exploring the Web's Hidden Attack Surface. | Marius Musch, Robin Kirchner, Max Boll, Martin Johns |
| 2022 | IMC | No keys to the kingdom required: a comprehensive investigation of missing authentication vulnerabilities in the wild. | Manuel Karl, Marius Musch, Guoli Ma, Martin Johns, Sebastian Lekies |
| 2021 | NDSS | Who's Hosting the Block Party? Studying Third-Party Blockage of CSP and SRI. | Marius Steffens, Marius Musch, Martin Johns, Ben Stock |
| 2020 | SAC | Raccoon: automated verification of guarded race conditions in web applications. | Simon Koch, Tim Sauer, Martin Johns, Giancarlo Pellegrino |
| 2020 | SAC | Hybrid taint analysis for Java EE. | Florian D. Loch, Martin Johns, Martin Hecker, Martin Mohr, Gregor Snelting |
| 2019 | CCS | ScriptProtect: Mitigating Unsafe Third-Party JavaScript Practices. | Marius Musch, Marius Steffens, Sebastian Roth, Ben Stock, Martin Johns |
| 2019 | DIMVA | New Kid on the Web: A Study on the Prevalence of WebAssembly in the Wild. | Marius Musch, Christian Wressnegger, Martin Johns, Konrad Rieck |
| 2019 | NDSS | Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the Wild. | Marius Steffens, Christian Rossow, Martin Johns, Ben Stock |
| 2017 | CCS | Code-Reuse Attacks for the Web: Breaking Cross-Site Scripting Mitigations via Script Gadgets. | Sebastian Lekies, Krzysztof Kotowicz, Samuel Gro, Eduardo A. Vela Nava, Martin Johns |
| 2017 | CCS | Deemon: Detecting CSRF with Dynamic Analysis and Property Graphs. | Giancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes, Christian Rossow |
| 2016 | CCS | POSTER: Mapping the Landscape of Large-Scale Vulnerability Notifications. | Ben Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns, Michael Backes |
| 2016 | SAC | Ensuring endpoint authenticity in WebRTC peer-to-peer communication. | Willem De Groef, Deepak Subramanian, Martin Johns, Frank Piessens, Lieven Desmet |
| 2015 | CCS | From Facepalm to Brain Bender: Exploring Client-Side Cross-Site Scripting. | Ben Stock, Stephan Pfistner, Bernd Kaiser, Sebastian Lekies, Martin Johns |
| 2015 | SAC | LogSec: adaptive protection for the wild wild web. | Bastian Braun, Korbinian Pauli, Joachim Posegga, Martin Johns |
| 2014 | CCS | Protecting users against XSS-based password manager abuse. | Ben Stock, Martin Johns |
| 2014 | SEC | A Trusted UI for the Mobile Web. | Bastian Braun, Johannes Kstler, Joachim Posegga, Martin Johns |
| 2013 | CCS | 25 million flows later: large-scale detection of DOM-based XSS. | Sebastian Lekies, Ben Stock, Martin Johns |
| 2013 | DIMVA | PreparedJS: Secure Script-Templates for JavaScript. | Martin Johns |
| 2013 | RAID | Tamper-Resistant LikeJacking Protection. | Martin Johns, Sebastian Lekies |
| 2012 | ACSAC | BetterAuth: web authentication revisited. | Martin Johns, Sebastian Lekies, Bastian Braun, Benjamin Flesch |
| 2012 | RAID | DEMACRO: Defense against Malicious Cross-Domain Requests. | Sebastian Lekies, Nick Nikiforakis, Walter Tighzert, Frank Piessens, Martin Johns |
| 2012 | TrustBus | A User-Level Authentication Scheme to Mitigate Web Session-Based Vulnerabilities. | Bastian Braun, Stefan Kucher, Martin Johns, Joachim Posegga |
| 2012 | TrustBus | WebSand: Server-Driven Outbound Web-Application Sandboxing. | Martin Johns, Joachim Posegga |
| 2011 | ACSAC | Smart metering de-pseudonymization. | Marek Jawurek, Martin Johns, Konrad Rieck |
| 2011 | DIMVA | Biting the Hand That Serves You: A Closer Look at Client-Side Flash Proxies for Cross-Domain Requests. | Martin Johns, Sebastian Lekies |
| 2011 | ICST | Scanstud: A Methodology for Systematic, Fine-Grained Evaluation of Static Analysis Tools. | Martin Johns, Moritz Jodeit |
| 2011 | SAC | Reliable protection against session fixation attacks. | Martin Johns, Bastian Braun, Michael Schrank, Joachim Posegga |
| 2008 | ACSAC | XSSDS: Server-Side Detection of Cross-Site Scripting Attacks. | Martin Johns, Bjrn Engelmann, Joachim Posegga |
| 2007 | DIMVA | Protecting the Intranet Against "JavaScript Malware" and Related Attacks. | Martin Johns, Justus Winter |
| 2007 | SAC | SMask: preventing injection attacks in web applications by approximating automatic data/code separation. | Martin Johns, Christian Beyerlein |
| 2006 | ESORICS | SessionSafe: Implementing XSS Immune Session Handling. | Martin Johns |