| 2026 | Networking | New Trains, Same Rails: Fingerprinting Cryptocurrency Software via Network Requests. | Muhammad Muzammil, Oleksii Starov, Zane Ma, Nick Nikiforakis |
| 2025 | CCS | The Power to Never Be Wrong: Evasions and Anachronistic Attacks Against Web Archives. | Robin Kirchner, Chris Tsoukaladelis, Martin Johns, Nick Nikiforakis |
| 2025 | CCS | What Gets Measured Gets Managed: Mitigating Supply Chain Attacks with a Link Integrity Management System. | Johnny So, Michael Ferdman, Nick Nikiforakis |
| 2025 | CCS | A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global Trends. | Shakhzod Yuldoshkhujaev, Mijin Jeon, Doowon Kim, Nick Nikiforakis, Hyungjoon Koo |
| 2025 | RAID | Uncontained Danger: Quantifying Remote Dependencies in Containerized Applications. | Chris Tsoukaladelis, Roberto Perdisci, Nick Nikiforakis |
| 2025 | WWW | The Poorest Man in Babylon: A Longitudinal Study of Cryptocurrency Investment Scams. | Muhammad Muzammil, Abisheka Pitumpe, Xigao Li, Amir Rahmati, Nick Nikiforakis |
| 2024 | ACSAC | Ready or Not, Here I Come: Characterizing the Security of Prematurely-public Web Applications. | Brian Kondracki, Michael Ferdman, Nick Nikiforakis |
| 2024 | ACSAC | Harnessing Multiplicity: Granular Browser Extension Fingerprinting through User Configurations. | Konstantinos Solomos, Nick Nikiforakis, Jason Polakis |
| 2024 | DIMVA | Knocking on Admin's Door: Protecting Critical Web Applications with Deception. | Billy Tsouvalas, Nick Nikiforakis |
| 2024 | IMC | Panning for gold.eth: Understanding and Analyzing ENS Domain Dropcatching. | Muhammad Muzammil, Zhengyu Wu, Aruna Balasubramanian, Nick Nikiforakis |
| 2024 | NDSS | Like, Comment, Get Scammed: Characterizing Comment Scams on Media Platforms. | Xigao Li, Amir Rahmati, Nick Nikiforakis |
| 2024 | Networking | Secrets are Forever: Characterizing Sensitive File Leaks on IPFS. | Zhengyu Wu, Brian Kondracki, Nick Nikiforakis, Aruna Balasubramanian |
| 2024 | SP | The Times They Are A-Changin': Characterizing Post-Publication Changes to Online News. | Chris Tsoukaladelis, Brian Kondracki, Niranjan Balasubramanian, Nick Nikiforakis |
| 2024 | SP | Manufactured Narratives: On the Potential of Manipulating Social Media to Politicize World Events. | Chris Tsoukaladelis, Nick Nikiforakis |
| 2023 | NDSS | Navigating Murky Waters: Automated Browser Feature Testing for Uncovering Tracking Vectors. | Mir Masood Ali, Binoy Chitale, Mohammad Ghasemisharif, Chris Kanich, Nick Nikiforakis, Jason Polakis |
| 2023 | NDSS | Double and Nothing: Understanding and Detecting Cryptocurrency Giveaway Scams. | Xigao Li, Anurag Yepuri, Nick Nikiforakis |
| 2023 | WWW | Scan Me If You Can: Understanding and Detecting Unwanted Vulnerability Scanning. | Xigao Li, Babak Amin Azad, Amir Rahmati, Nick Nikiforakis |
| 2023 | WWW | The More Things Change, the More They Stay the Same: Integrity of Modern JavaScript. | Johnny So, Michael Ferdman, Nick Nikiforakis |
| 2022 | CCS | Escaping the Confines of Time: Continuous Browser Extension Fingerprinting Through Ephemeral Modifications. | Konstantinos Solomos, Panagiotis Ilia, Nick Nikiforakis, Jason Polakis |
| 2022 | NDSS | The Droid is in the Details: Environment-aware Evasion of Android Sandboxes. | Brian Kondracki, Babak Amin Azad, Najmeh Miramirkhani, Nick Nikiforakis |
| 2022 | WWW | Verba Volant, Scripta Volant: Understanding Post-publication Title Changes in News Outlets. | Xingzhi Guo, Brian Kondracki, Nick Nikiforakis, Steven Skiena |
| 2022 | SP | Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust. | Johnny So, Najmeh Miramirkhani, Michael Ferdman, Nick Nikiforakis |
| 2021 | AsiaCCS | Click This, Not That: Extending Web Authentication with Deception. | Timothy Barron, Johnny So, Nick Nikiforakis |
| 2021 | CCS | Catching Transparent Phish: Analyzing and Detecting MITM Phishing Toolkits. | Brian Kondracki, Babak Amin Azad, Oleksii Starov, Nick Nikiforakis |
| 2021 | NDSS | To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media. | Beliz Kaleli, Brian Kondracki, Manuel Egele, Nick Nikiforakis, Gianluca Stringhini |
| 2021 | WWW | Where are you taking me?Understanding Abusive Traffic Distribution Systems. | Janos Szurdi, Meng Luo, Brian Kondracki, Nick Nikiforakis, Nicolas Christin |
| 2021 | SP | Good Bot, Bad Bot: Characterizing Automated Browsing Activity. | Xigao Li, Babak Amin Azad, Amir Rahmati, Nick Nikiforakis |
| 2020 | CCS | You've Changed: Detecting Malicious Browser Extensions through their Update Deltas. | Nikolaos Pantelaios, Nick Nikiforakis, Alexandros Kapravelos |
| 2020 | DIMVA | Web Runner 2049: Evaluating Third-Party Anti-bot Services. | Babak Amin Azad, Oleksii Starov, Pierre Laperdrix, Nick Nikiforakis |
| 2020 | DIMVA | Short Paper - Taming the Shape Shifter: Detecting Anti-fingerprinting Browsers. | Babak Amin Azad, Oleksii Starov, Pierre Laperdrix, Nick Nikiforakis |
| 2020 | NDSS | Complex Security Policy? A Longitudinal Analysis of Deployed Content Security Policies. | Sebastian Roth, Timothy Barron, Stefano Calzavara, Nick Nikiforakis, Ben Stock |
| 2020 | SP | Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile Browsers. | Brian Kondracki, Assel Aliyeva, Manuel Egele, Jason Polakis, Nick Nikiforakis |
| 2019 | CCS | Purchased Fame: Exploring the Ecosystem of Private Blog Networks. | Tom van Goethem, Najmeh Miramirkhani, Wouter Joosen, Nick Nikiforakis |
| 2019 | DIMVA | Morellian Analysis for Browsers: Making Web Authentication Stronger with Canvas Fingerprinting. | Pierre Laperdrix, Gildas Avoine, Benoit Baudry, Nick Nikiforakis |
| 2019 | NDSS | Time Does Not Heal All Wounds: A Longitudinal Analysis of Security-Mechanism Support in Mobile Browsers. | Meng Luo, Pierre Laperdrix, Nima Honarmand, Nick Nikiforakis |
| 2019 | RAID | Now You See It, Now You Don't: A Large-scale Analysis of Early Domain Deletions. | Timothy Barron, Najmeh Miramirkhani, Nick Nikiforakis |
| 2019 | WWW | Unnecessarily Identifiable: Quantifying the fingerprintability of browser extensions due to bloat. | Oleksii Starov, Pierre Laperdrix, Alexandros Kapravelos, Nick Nikiforakis |
| 2018 | WWW | Panning for gold.com: Understanding the Dynamics of Domain Dropcatching. | Najmeh Miramirkhani, Timothy Barron, Michael Ferdman, Nick Nikiforakis |
| 2018 | WWW | Exposing Search and Advertisement Abuse Tactics and Infrastructure of Technical Support Scammers. | Bharat Srinivasan, Athanasios Kountouras, Najmeh Miramirkhani, Monjur Alam, Nick Nikiforakis, Manos Antonakakis, Mustaque Ahamad |
| 2018 | WWW | Betrayed by Your Dashboard: Discovering Malicious Campaigns via Web Analytics. | Oleksii Starov, Yuchen Zhou, Xiao Zhang, Najmeh Miramirkhani, Nick Nikiforakis |
| 2017 | ACSAC | Picky Attackers: Quantifying the Role of System Properties on Intruder Behavior. | Timothy Barron, Nick Nikiforakis |
| 2017 | CCS | Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse. | Panagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen, Rosa Romero Gmez, Nikolaos Pitropakis, Nick Nikiforakis, Manos Antonakakis |
| 2017 | CCS | Hindsight: Understanding the Evolution of UI Vulnerabilities in Mobile Browsers. | Meng Luo, Oleksii Starov, Nima Honarmand, Nick Nikiforakis |
| 2017 | CCS | The Wolf of Name Street: Hijacking Domains Through Their Nameservers. | Thomas Vissers, Timothy Barron, Tom van Goethem, Wouter Joosen, Nick Nikiforakis |
| 2017 | NDSS | Dial One for Scam: A Large-Scale Analysis of Technical Support Scams. | Najmeh Miramirkhani, Oleksii Starov, Nick Nikiforakis |
| 2017 | WWW | What's in a Name?: Understanding Profile Name Reuse on Twitter. | Enrico Mariconti, Jeremiah Onaolapo, Syed Sharique Ahmad, Nicolas Nikiforou, Manuel Egele, Nick Nikiforakis, Gianluca Stringhini |
| 2017 | WWW | Extended Tracking Powers: Measuring the Privacy Diffusion Enabled by Browser Extensions. | Oleksii Starov, Nick Nikiforakis |
| 2017 | SP | Spotless Sandboxes: Evading Malware Analysis Systems Using Wear-and-Tear Artifacts. | Najmeh Miramirkhani, Mahathi Priya Appini, Nick Nikiforakis, Michalis Polychronakis |
| 2017 | SP | XHOUND: Quantifying the Fingerprintability of Browser Extensions. | Oleksii Starov, Nick Nikiforakis |
| 2016 | NDSS | It's Free for a Reason: Exploring the Ecosystem of Free Live Streaming Services. | M. Zubair Rafique, Tom van Goethem, Wouter Joosen, Christophe Huygens, Nick Nikiforakis |
| 2016 | WWW | No Honor Among Thieves: A Large-Scale Analysis of Malicious Web Shells. | Oleksii Starov, Johannes Dahse, Syed Sharique Ahmad, Thorsten Holz, Nick Nikiforakis |
| 2015 | CCS | The Clock is Still Ticking: Timing Attacks in the Modern Web. | Tom van Goethem, Wouter Joosen, Nick Nikiforakis |
| 2015 | CCS | Drops for Stuff: An Analysis of Reshipping Mule Scams. | Shuang Hao, Kevin Borgolte, Nick Nikiforakis, Gianluca Stringhini, Manuel Egele, Michael Eubanks, Brian Krebs, Giovanni Vigna |
| 2015 | CCS | Maneuvering Around Clouds: Bypassing Cloud-based Security Providers. | Thomas Vissers, Tom van Goethem, Wouter Joosen, Nick Nikiforakis |
| 2015 | NDSS | Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse. | Pieter Agten, Wouter Joosen, Frank Piessens, Nick Nikiforakis |
| 2015 | NDSS | Parking Sensors: Analyzing and Detecting Parked Domains. | Thomas Vissers, Wouter Joosen, Nick Nikiforakis |
| 2015 | WWW | PriVaricator: Deceiving Fingerprinters with Little White Lies. | Nick Nikiforakis, Wouter Joosen, Benjamin Livshits |
| 2014 | CCS | Monkey-in-the-browser: malware and vulnerabilities in augmented browsing script markets. | Steven Van Acker, Nick Nikiforakis, Lieven Desmet, Frank Piessens, Wouter Joosen |
| 2014 | CCS | Clubbing Seals: Exploring the Ecosystem of Third-party Security Seals. | Tom van Goethem, Frank Piessens, Wouter Joosen, Nick Nikiforakis |
| 2014 | WWW | Stranger danger: exploring the ecosystem of ad-based URL shortening services. | Nick Nikiforakis, Federico Maggi, Gianluca Stringhini, M. Zubair Rafique, Wouter Joosen, Christopher Kruegel, Frank Piessens, Giovanni Vigna, Stefano Zanero |
| 2013 | CCS | FPDetective: dusting the web for fingerprinters. | Gunes Acar, Marc Juarez, Nick Nikiforakis, Claudia Daz, Seda F. Grses, Frank Piessens, Bart Preneel |
| 2013 | CCS | TabShots: client-side detection of tabnabbing attacks. | Philippe De Ryck, Nick Nikiforakis, Lieven Desmet, Wouter Joosen |
| 2013 | DIMVA | HeapSentry: Kernel-Assisted Protection against Heap Overflows. | Nick Nikiforakis, Frank Piessens, Wouter Joosen |
| 2013 | WWW | Bitsquatting: exploiting bit-flips for fun, or profit? | Nick Nikiforakis, Steven Van Acker, Wannes Meert, Lieven Desmet, Frank Piessens, Wouter Joosen |
| 2013 | SP | Cookieless Monster: Exploring the Ecosystem of Web-Based Device Fingerprinting. | Nick Nikiforakis, Alexandros Kapravelos, Wouter Joosen, Christopher Kruegel, Frank Piessens, Giovanni Vigna |
| 2012 | CCS | FlashOver: automated discovery of cross-site scripting vulnerabilities in rich internet applications. | Steven Van Acker, Nick Nikiforakis, Lieven Desmet, Wouter Joosen, Frank Piessens |
| 2012 | CCS | FlowFox: a web browser with flexible and precise information flow control. | Willem De Groef, Dominique Devriese, Nick Nikiforakis, Frank Piessens |
| 2012 | CCS | You are what you include: large-scale evaluation of remote javascript inclusions. | Nick Nikiforakis, Luca Invernizzi, Alexandros Kapravelos, Steven Van Acker, Wouter Joosen, Christopher Kruegel, Frank Piessens, Giovanni Vigna |
| 2012 | DAIS | Serene: Self-Reliant Client-Side Protection against Session Fixation. | Philippe De Ryck, Nick Nikiforakis, Lieven Desmet, Frank Piessens, Wouter Joosen |
| 2012 | RAID | DEMACRO: Defense against Malicious Cross-Domain Requests. | Sebastian Lekies, Nick Nikiforakis, Walter Tighzert, Frank Piessens, Martin Johns |
| 2012 | SEC | HyperForce: Hypervisor-enForced Execution of Security-Critical Code. | Francesco Gadaleta, Nick Nikiforakis, Jan Tobias Mhlberg, Wouter Joosen |
| 2012 | WISTP | Recent Developments in Low-Level Software Security. | Pieter Agten, Nick Nikiforakis, Raoul Strackx, Willem De Groef, Frank Piessens |
| 2011 | ACSAC | RIPE: runtime intrusion prevention evaluator. | John Wilander, Nick Nikiforakis, Yves Younan, Mariam Kamkar, Wouter Joosen |
| 2010 | DIMVA | HProxy: Client-Side Detection of SSL Stripping Attacks. | Nick Nikiforakis, Yves Younan, Wouter Joosen |
| 2010 | ICISS | ValueGuard: Protection of Native Applications against Data-Only Buffer Overflows. | Steven Van Acker, Nick Nikiforakis, Pieter Philippaerts, Yves Younan, Frank Piessens |