| 2026 | CHI | "That's another doom I haven't thought about": A User Study on AI Labels as a Safeguard Against Image-Based Misinformation. | Sandra Hltervennhoff, Jonas Ricker, Maike M. Raphael, Charlotte Schwedes, Rebecca Weil, Asja Fischer, Thorsten Holz, Lea Schnherr, Sascha Fahl |
| 2026 | SP | Position Paper: Replication Crisis in Human-Centered Security Research-Are We There Yet? | Juliane Schmser, Jan-Ulrich Holtgrave, Florian Schaub, Sascha Fahl |
| 2026 | SOUPS | An Analysis of the Security, Usability, and Automation Capabilities of Password Update Processes on Top-Ranked Websites. | Alexander Krause, Jacques Suray, Lea Schmser, Marten Oltrogge, Oliver Wiese, Maximillian Golla, Sascha Fahl |
| 2025 | CCS | Poster: Computer Security Researchers' Experiences with Vulnerability Disclosures. | Harshini Sri Ramulu, Anna Lena Rotthaler, Jost Rossel, Rachel Gonzalez Rodriguez, Dominik Wermke, Sascha Fahl, Tadayoshi Kohno, Juraj Somorovsky, Yasemin Acar |
| 2025 | CCS | Competing for Attention: An Interview Study with Participants of Cryptography Competitions. | Ivana Trummov, Juliane Schmser, Nicolas Huaman, Sascha Fahl |
| 2025 | CHI | A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public Administrations. | Jan-Ulrich Holtgrave, Sabrina Klivan, Karola Marky, Sascha Fahl |
| 2025 | NDSS | Attributing Open-Source Contributions is Critical but Difficult: A Systematic Analysis of GitHub Practices and Their Impact on Software Supply Chain Security. | Jan-Ulrich Holtgrave, Kay Friedrich, Fabian Fischer, Nicolas Huaman, Niklas Busch, Jan H. Klemmer, Marcel Fourn, Oliver Wiese, Dominik Wermke, Sascha Fahl |
| 2025 | SP | Transparency in Usable Privacy and Security Research: Scholars' Perspectives, Practices, and Recommendations. | Jan H. Klemmer, Juliane Schmser, Byron M. Lowens, Fabian Fischer, Lea Schmser, Florian Schaub, Sascha Fahl |
| 2025 | SP | "It's Time. Time for Digital Security.": An End User Study on Actionable Security and Privacy Advice. | Anna Lena Rotthaler, Harshini Sri Ramulu, Lucy Simko, Sascha Fahl, Yasemin Acar |
| 2025 | SP | "I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIs. | Juliane Schmser, Philip Klostermeyer, Kay Friedrich, Sascha Fahl |
| 2025 | VRST | Towards Secure and Usable XR Authentication Schemes for Head-Mounted Displays: A Co-Creation Study with Experts. | Reyhan Dzgn, Philip Klostermeyer, Lena Swienty, Sascha Fahl, Karola Marky |
| 2024 | ACSAC | Passwords To-Go: Investigating Multifaceted Challenges for Password Managers in the Android Ecosystem. | Nicolas Huaman, Marten Oltrogge, Sabrina Klivan, Yannick Evers, Sascha Fahl |
| 2024 | CCS | Using AI Assistants in Software Development: A Qualitative Study on Security Practices and Concerns. | Jan H. Klemmer, Stefan Albert Horstmann, Nikhil Patnaik, Cordelia Ludden, Cordell Burton Jr., Carson Powers, Fabio Massacci, Akond Rahman, Daniel Votipka, Heather Richter Lipford, Awais Rashid, Alena Naiakshina, Sascha Fahl |
| 2024 | CCS | Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game Development. | Philip Klostermeyer, Sabrina Amft, Sandra Hltervennhoff, Alexander Krause, Niklas Busch, Sascha Fahl |
| 2024 | CHI | Mental Models, Expectations and Implications of Client-Side Scanning: An Interview Study with Experts. | Divyanshu Bhardwaj, Carolyn Guthoff, Adrian Dabrowski, Sascha Fahl, Katharina Krombholz |
| 2024 | CHI | Analyzing Security and Privacy Advice During the 2022 Russian Invasion of Ukraine on Twitter. | Juliane Schmser, Harshini Sri Ramulu, Noah Whler, Christian Stransky, Felix Bensmann, Dimitar Dimitrov, Sebastian Schellhammer, Dominik Wermke, Stefan Dietze, Yasemin Acar, Sascha Fahl |
| 2024 | SP | Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software Contributors. | Sabrina Amft, Sandra Hltervennhoff, Rebecca Panskus, Karola Marky, Sascha Fahl |
| 2023 | CCS | "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments. | Sabrina Amft, Sandra Hltervennhoff, Nicolas Huaman, Alexander Krause, Lucy Simko, Yasemin Acar, Sascha Fahl |
| 2023 | CCS | "Make Them Change it Every Week!": A Qualitative Exploration of Online Developer Advice on Usable and Secure Authentication. | Jan H. Klemmer, Marco Gutfleisch, Christian Stransky, Yasemin Acar, M. Angela Sasse, Sascha Fahl |
| 2023 | SP | It's like flossing your teeth: On the Importance and Challenges of Reproducible Builds for Software Supply Chain Security. | Marcel Fourn, Dominik Wermke, William Enck, Sascha Fahl, Yasemin Acar |
| 2023 | SP | "Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply Chain. | Dominik Wermke, Jan H. Klemmer, Noah Whler, Juliane Schmser, Harshini Sri Ramulu, Yasemin Acar, Sascha Fahl |
| 2023 | SOUPS | "Would You Give the Same Priority to the Bank and a Game? I Do Not!" Exploring Credential Management Strategies and Obstacles during Password Manager Setup. | Sabrina Amft, Sandra Hltervennhoff, Nicolas Huaman, Yasemin Acar, Sascha Fahl |
| 2023 | SOUPS | Privacy Mental Models of Electronic Health Records: A German Case Study. | Rebecca Panskus, Max Ninow, Sascha Fahl, Karola Marky |
| 2022 | SP | How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview Study. | Marco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar, M. Angela Sasse, Sascha Fahl |
| 2022 | SP | 27 Years and 81 Million Opportunities Later: Investigating the Use of Email Encryption for an Entire University. | Christian Stransky, Oliver Wiese, Volker Roth, Yasemin Acar, Sascha Fahl |
| 2022 | SP | Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software Projects. | Dominik Wermke, Noah Whler, Jan H. Klemmer, Marcel Fourn, Yasemin Acar, Sascha Fahl |
| 2022 | SOUPS | If You Can't Get Them to the Lab: Evaluating a Virtual Study Environment with Security Information Workers. | Nicolas Huaman, Alexander Krause, Dominik Wermke, Jan H. Klemmer, Christian Stransky, Yasemin Acar, Sascha Fahl |
| 2021 | SP | They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and Websites. | Nicolas Huaman, Sabrina Amft, Marten Oltrogge, Yasemin Acar, Sascha Fahl |
| 2021 | SOUPS | Never ever or no matter what: Investigating Adoption Intentions and Misconceptions about the Corona-Warn-App in Germany. | Maximilian Hring, Eva Gerlitz, Christian Tiefenau, Matthew Smith, Dominik Wermke, Sascha Fahl, Yasemin Acar |
| 2021 | SOUPS | On the Limited Impact of Visualizing Encryption: Perceptions of E2E Messaging Security. | Christian Stransky, Dominik Wermke, Johanna Schrader, Nicolas Huaman, Yasemin Acar, Anna Lena Fehlhaber, Miranda Wei, Blase Ur, Sascha Fahl |
| 2020 | CHI | Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIs. | Peter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha Fahl |
| 2020 | SOUPS | Cloudy with a Chance of Misconceptions: Exploring Users' Perceptions and Expectations of Security and Privacy in Cloud Office Suites. | Dominik Wermke, Nicolas Huaman, Christian Stransky, Niklas Busch, Yasemin Acar, Sascha Fahl |
| 2019 | CCS | (Un)informed Consent: Studying GDPR Consent Notices in the Field. | Christine Utz, Martin Degeling, Sascha Fahl, Florian Schaub, Thorsten Holz |
| 2018 | ACSAC | A Large Scale Investigation of Obfuscation Use in Google Play. | Dominik Wermke, Nicolas Huaman, Yasemin Acar, Bradley Reaves, Patrick Traynor, Sascha Fahl |
| 2018 | WWW | Your Secrets Are Safe: How Browsers' Explanations Impact Misconceptions About Private Browsing Mode. | Yuxi Wu, Panya Gupta, Miranda Wei, Yasemin Acar, Sascha Fahl, Blase Ur |
| 2018 | SP | The Rise of the Citizen Developer: Assessing the Security Impact of Online App Generators. | Marten Oltrogge, Erik Derr, Christian Stransky, Yasemin Acar, Sascha Fahl, Christian Rossow, Giancarlo Pellegrino, Sven Bugiel, Michael Backes |
| 2018 | SOUPS | Developers Deserve Security Warnings, Too: On the Effect of Integrated Security Advice on Cryptographic API Misuse. | Peter Leo Gorski, Luigi Lo Iacono, Dominik Wermke, Christian Stransky, Sebastian Mller, Yasemin Acar, Sascha Fahl |
| 2017 | CCS | Where the Wild Warnings Are: Root Causes of Chrome HTTPS Certificate Errors. | Mustafa Emre Acer, Emily Stark, Adrienne Porter Felt, Sascha Fahl, Radhika Bhargava, Bhanu Dev, Matt Braithwaite, Ryan Sleevi, Parisa Tabriz |
| 2017 | CCS | Keep me Updated: An Empirical Study of Third-Party Library Updatability on Android. | Erik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar, Michael Backes |
| 2017 | CCS | A Stitch in Time: Supporting Android Developers in WritingSecure Code. | Duc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes, Charles Weir, Sascha Fahl |
| 2017 | SP | Comparing the Usability of Cryptographic APIs. | Yasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel, Doowon Kim, Michelle L. Mazurek, Christian Stransky |
| 2017 | SP | Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application Security. | Felix Fischer, Konstantin Bttinger, Huang Xiao, Christian Stransky, Yasemin Acar, Michael Backes, Sascha Fahl |
| 2017 | SOUPS | Security Developer Studies with GitHub Users: Exploring a Convenience Sample. | Yasemin Acar, Christian Stransky, Dominik Wermke, Michelle L. Mazurek, Sascha Fahl |
| 2016 | SP | SoK: Lessons Learned from Android Security Research for Appified Software Platforms. | Yasemin Acar, Michael Backes, Sven Bugiel, Sascha Fahl, Patrick D. McDaniel, Matthew Smith |
| 2016 | SP | You Get Where You're Looking for: The Impact of Information Sources on Code Security. | Yasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim, Michelle L. Mazurek, Christian Stransky |
| 2015 | CCS | VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code Audits. | Henning Perl, Sergej Dechand, Matthew Smith, Daniel Arp, Fabian Yamaguchi, Konrad Rieck, Sascha Fahl, Yasemin Acar |
| 2015 | SP | SoK: Secure Messaging. | Nik Unger, Sergej Dechand, Joseph Bonneau, Sascha Fahl, Henning Perl, Ian Goldberg, Matthew Smith |
| 2014 | CCS | Why eve and mallory (also) love webmasters: a study on the root causes of SSL misconfigurations. | Sascha Fahl, Yasemin Acar, Henning Perl, Matthew Smith |
| 2014 | CCS | Hey, NSA: Stay Away from my Market! Future Proofing App Markets against Powerful Attackers. | Sascha Fahl, Sergej Dechand, Henning Perl, Felix Fischer, Jaromir Smrcek, Matthew Smith |
| 2014 | FC | You Won't Be Needing These Any More: On Removing Unused Certificates from Trust Stores. | Henning Perl, Sascha Fahl, Matthew Smith |
| 2013 | CCS | Rethinking SSL development in an appified world. | Sascha Fahl, Marian Harbach, Henning Perl, Markus Koetter, Matthew Smith |
| 2013 | FC | Hey, You, Get Off of My Clipboard - On How Usability Trumps Security in Android Password Managers. | Sascha Fahl, Marian Harbach, Marten Oltrogge, Thomas Muders, Matthew Smith |
| 2013 | FC | Sorry, I Don't Get It: An Analysis of Warning Message Texts. | Marian Harbach, Sascha Fahl, Polina Yakovleva, Matthew Smith |
| 2013 | SOUPS | On the ecological validity of a password study. | Sascha Fahl, Marian Harbach, Yasemin Acar, Matthew Smith |
| 2012 | CCS | Why eve and mallory love android: an analysis of android SSL (in)security. | Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith, Lars Baumgrtner, Bernd Freisleben |
| 2012 | CCS | Towards measuring warning readability. | Marian Harbach, Sascha Fahl, Thomas Muders, Matthew Smith |
| 2012 | PST | Towards privacy-preserving access control with hidden policies, hidden credentials and hidden decisions. | Marian Harbach, Sascha Fahl, Michael Brenner, Thomas Muders, Matthew Smith |
| 2012 | WWW | All our messages are belong to us: usable confidentiality in social networks. | Marian Harbach, Sascha Fahl, Thomas Muders, Matthew Smith |
| 2012 | TrustCom | Confidentiality as a Service - Usable Security for the Cloud. | Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith |
| 2012 | SOUPS | Helping Johnny 2.0 to encrypt his Facebook conversations. | Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith, Uwe Sander |
| 2011 | PDP | TrustBox: A Security Architecture for Preventing Data Breaches. | Matthias Schmidt, Sascha Fahl, Roland Schwarzkopf, Bernd Freisleben |