| 2022 | IMC | No keys to the kingdom required: a comprehensive investigation of missing authentication vulnerabilities in the wild. | Manuel Karl, Marius Musch, Guoli Ma, Martin Johns, Sebastian Lekies |
| 2017 | CCS | Code-Reuse Attacks for the Web: Breaking Cross-Site Scripting Mitigations via Script Gadgets. | Sebastian Lekies, Krzysztof Kotowicz, Samuel Gro, Eduardo A. Vela Nava, Martin Johns |
| 2016 | CCS | CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security Policy. | Lukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur Janc |
| 2015 | CCS | From Facepalm to Brain Bender: Exploring Client-Side Cross-Site Scripting. | Ben Stock, Stephan Pfistner, Bernd Kaiser, Sebastian Lekies, Martin Johns |
| 2013 | CCS | 25 million flows later: large-scale detection of DOM-based XSS. | Sebastian Lekies, Ben Stock, Martin Johns |
| 2013 | RAID | Tamper-Resistant LikeJacking Protection. | Martin Johns, Sebastian Lekies |
| 2012 | ACSAC | BetterAuth: web authentication revisited. | Martin Johns, Sebastian Lekies, Bastian Braun, Benjamin Flesch |
| 2012 | RAID | DEMACRO: Defense against Malicious Cross-Domain Requests. | Sebastian Lekies, Nick Nikiforakis, Walter Tighzert, Frank Piessens, Martin Johns |
| 2011 | DIMVA | Biting the Hand That Serves You: A Closer Look at Client-Side Flash Proxies for Cross-Domain Requests. | Martin Johns, Sebastian Lekies |