| 2026 | SP | Secret State Leakage Attacks and Their Impacts on EMV Contactless Payment Apps. | Jesse Chen, Rubin Yuchan Yang, Ahmad Musa, Syed Rafiul Hussain, Omar Chowdhury, Sazzadur Rahaman |
| 2026 | TACAS | Automatically Tightening Access Control Policies with Restricter. | Ka Lok Wu, Christa Jenkins, Scott D. Stoller, Omar Chowdhury |
| 2025 | CHI | SeQR: A User-Friendly and Secure-by-Design Configurator for Enterprise Wi-Fi. | S. Mahmudul Hasan, Che Wei Tu, Md. Endadul Hoque, Omar Chowdhury, Sze Yiu Chau |
| 2025 | SP | Saecred: A State-Aware, Over-the-Air Protocol Testing Approach for Discovering Parsing Bugs in SAE Handshake Implementations of COTS Wi-Fi Access Points. | Muhammad Daniyal Pirwani Dar, Robert Lorch, Aliakbar Sadeghi, Vincenzo Sorcigli, Hlose Gollier, Cesare Tinelli, Mathy Vanhoef, Omar Chowdhury |
| 2025 | SOSP | AutoMan: Facilitating Verified Distributed Systems Development Through Automatic Code Generation and Manual Optimizations. | Zihao Zhang, Ti Zhou, Christa Jenkins, Omar Chowdhury, Shuai Mu |
| 2024 | CCS | State Machine Mutation-based Testing Framework for Wireless Communication Protocols. | Syed Md. Mukit Rashid, Tianwei Wu, Kai Tu, Abdullah Al Ishtiaq, Ridwanul Hasan Tanvir, Yilu Dong, Omar Chowdhury, Syed Rafiul Hussain |
| 2024 | RAID | A Comprehensive, Automated Security Analysis of the Uptane Automotive Over-the-Air Update Framework. | Robert Lorch, Daniel Larraz, Cesare Tinelli, Omar Chowdhury |
| 2024 | SP | ARMOR: A Formally Verified Implementation of X.509 Certificate Chain Validation. | Joyanta Debnath, Christa Jenkins, Yuteng Sun, Sze Yiu Chau, Omar Chowdhury |
| 2023 | FMCAD | CRV: Automated Cyber-Resiliency Reasoning for System Design Models. | Daniel Larraz, Robert Lorch, Moosa Yahyazadeh, M. Fareed Arif, Omar Chowdhury, Cesare Tinelli |
| 2022 | IMC | Demystifying the presence of cellular network attacks and misbehaviors. | Mitziu Echeverria, Omar Chowdhury |
| 2021 | CCS | On Re-engineering the X.509 PKI with Executable Specification for Better Implementation Guarantees. | Joyanta Debnath, Sze Yiu Chau, Omar Chowdhury |
| 2021 | CCS | All your Credentials are Belong to Us: On Insecure WPA2-Enterprise Configurations. | Man Hong Hue, Joyanta Debnath, Kin Man Leung, Li Li, Mohsen Minaei, M. Hammad Mazhar, Kailiang Xian, Md. Endadul Hoque, Omar Chowdhury, Sze Yiu Chau |
| 2021 | CCS | Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular Devices. | Syed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury, Elisa Bertino |
| 2021 | CCS | Morpheus: Bringing The (PKCS) One To Meet the Oracle. | Moosa Yahyazadeh, Sze Yiu Chau, Li Li, Man Hong Hue, Joyanta Debnath, Sheung Chiu Ip, Chun Ngai Li, Md. Endadul Hoque, Omar Chowdhury |
| 2021 | NDSS | PHOENIX: Device-Centric Cellular Network Protocol Monitoring using Runtime Verification. | Mitziu Echeverria, Zeeshan Ahmed, Bincheng Wang, M. Fareed Arif, Syed Rafiul Hussain, Omar Chowdhury |
| 2020 | ACNS | When TLS Meets Proxy on Mobile. | Joyanta Debnath, Sze Yiu Chau, Omar Chowdhury |
| 2020 | FMCAD | SYSLITE: Syntax-Guided Synthesis of PLTL Formulas from Finite Traces. | M. Fareed Arif, Daniel Larraz, Mitziu Echeverria, Andrew Reynolds, Omar Chowdhury, Cesare Tinelli |
| 2020 | RV | PatrIoT: Policy Assisted Resilient Programmable IoT System. | Moosa Yahyazadeh, Syed Rafiul Hussain, Md. Endadul Hoque, Omar Chowdhury |
| 2019 | ACSAC | Opening Pandora's box through ATFuzzer: dynamic analysis of AT interface for Android smartphones. | Imtiaz Karim, Fabrizio Cicala, Syed Rafiul Hussain, Omar Chowdhury, Elisa Bertino |
| 2019 | CCS | 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network Protocol. | Syed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury, Elisa Bertino |
| 2019 | NDSS | Analyzing Semantic Correctness with Symbolic Execution: A Case Study on PKCS#1 v1.5 Signature Verification. | Sze Yiu Chau, Moosa Yahyazadeh, Omar Chowdhury, Aniket Kate, Ninghui Li |
| 2019 | NDSS | Privacy Attacks to the 4G and 5G Cellular Paging Protocols Using Side Channel Information. | Syed Rafiul Hussain, Mitziu Echeverria, Omar Chowdhury, Ninghui Li, Elisa Bertino |
| 2019 | SACMAT | Expat: Expectation-based Policy Analysis and Enforcement for Appified Smart-Home Platforms. | Moosa Yahyazadeh, Proyash Podder, Md. Endadul Hoque, Omar Chowdhury |
| 2018 | ACSAC | Why Johnny Can't Make Money With His Contents: Pitfalls of Designing and Implementing Content Delivery Apps. | Sze Yiu Chau, Bincheng Wang, Jianxiong Wang, Omar Chowdhury, Aniket Kate, Ninghui Li |
| 2018 | NDSS | LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTE. | Syed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa Bertino |
| 2018 | SACMAT | How Inadequate Specification, Buggy Implementation, and Deficient Platform-Support Hinder Security. | Omar Chowdhury |
| 2018 | SecureComm | Adaptive Deterrence of DNS Cache Poisoning. | Sze Yiu Chau, Omar Chowdhury, Victor E. Gonsalves, Huangyi Ge, Weining Yang, Sonia Fahmy, Ninghui Li |
| 2017 | DSN | Analyzing Operational Behavior of Stateful Protocol Implementations for Detecting Semantic Bugs. | Md. Endadul Hoque, Omar Chowdhury, Sze Yiu Chau, Cristina Nita-Rotaru, Ninghui Li |
| 2017 | SP | SymCerts: Practical Symbolic Execution for Exposing Noncompliance in X.509 Certificate Validation Implementations. | Sze Yiu Chau, Omar Chowdhury, Md. Endadul Hoque, Huangyi Ge, Aniket Kate, Cristina Nita-Rotaru, Ninghui Li |
| 2016 | CCS | On the Security and Usability of Segment-based Visual Cryptographic Authentication Protocols. | Tianhao Wang, Huangyi Ge, Omar Chowdhury, Hemanta K. Maji, Ninghui Li |
| 2016 | CCS | An Empirical Study of Mnemonic Sentence-based Password Generation Strategies. | Weining Yang, Ninghui Li, Omar Chowdhury, Aiping Xiong, Robert W. Proctor |
| 2016 | SACMAT | Tri-Modularization of Firewall Policies. | Haining Chen, Omar Chowdhury, Ninghui Li, Warut Khern-am-nuai, Suresh Chari, Ian M. Molloy, Youngja Park |
| 2015 | CCS | Equivalence-based Security for Querying Encrypted Databases: Theory and Application to Privacy Policy Audits. | Omar Chowdhury, Deepak Garg, Limin Jia, Anupam Datta |
| 2015 | RV | A Case Study on Runtime Monitoring of an Autonomous Research Vehicle (ARV) System. | Aaron Kane, Omar Chowdhury, Anupam Datta, Philip Koopman |
| 2014 | CAV | Temporal Mode-Checking for Runtime Monitoring of Privacy Policies. | Omar Chowdhury, Limin Jia, Deepak Garg, Anupam Datta |
| 2013 | SACMAT | Privacy promises that can be kept: a policy analysis method with application to the HIPAA privacy rule. | Omar Chowdhury, Andreas Gampe, Jianwei Niu, Jeffery von Ronne, Jared Bennatt, Anupam Datta, Limin Jia, William H. Winsborough |
| 2012 | SACMAT | Ensuring authorization privileges for cascading user obligations. | Omar Chowdhury, Murillo Pontual, William H. Winsborough, Ting Yu, Keith Irwin, Jianwei Niu |
| 2011 | SACMAT | On the management of user obligations. | Murillo Pontual, Omar Chowdhury, William H. Winsborough, Ting Yu, Keith Irwin |
| 2010 | CCS | Toward practical authorization-dependent user obligation systems. | Murillo Pontual, Omar Chowdhury, William H. Winsborough, Ting Yu, Keith Irwin |