| 2025 | AsiaCCS | Generalized Adversarial Code-Suggestions: Exploiting Contexts of LLM-based Code-Completion. | Karl Rubel, Maximilian Noppel, Christian Wressnegger |
| 2025 | KI | Makrut Attacks Against Black-Box Explanations. | Achyut Hegde, Maximilian Noppel, Christian Wressnegger |
| 2025 | KI | Exploiting Contexts of LLM-based Code-Completion. | Maximilian Noppel, Karl Rubel, Christian Wressnegger |
| 2025 | SP | Composite Explanation-Aware Attacks. | Maximilian Noppel, Christian Wressnegger |
| 2024 | ACSAC | Model-Manipulation Attacks Against Black-Box Explanations. | Achyut Hegde, Maximilian Noppel, Christian Wressnegger |
| 2024 | KI | A Brief Systematization of Explanation-Aware Attacks. | Maximilian Noppel, Christian Wressnegger |
| 2024 | SP | SoK: Explainable Machine Learning in Adversarial Environments. | Maximilian Noppel, Christian Wressnegger |
| 2023 | CCS | Poster: Fooling XAI with Explanation-Aware Backdoors. | Maximilian Noppel, Christian Wressnegger |
| 2023 | SP | Disguising Attacks with Explanation-Aware Backdoors. | Maximilian Noppel, Lukas Peter, Christian Wressnegger |
| 2021 | ACSAC | LaserShark: Establishing Fast, Bidirectional Communication into Air-Gapped Systems. | Niclas Khnapfel, Stefan Preuler, Maximilian Noppel, Thomas Schneider, Konrad Rieck, Christian Wressnegger |