| 2025 | AAAI | APIRL: Deep Reinforcement Learning for REST API Fuzzing. | Myles Foley, Sergio Maffeis |
| 2025 | ACSAC | Clouseau: A Hierarchical Multi-Agent Approach for Autonomous Attack Investigation. | Abdullah Aldaihan, Fahad Alotaibi, Sergio Maffeis |
| 2025 | CCS | Deep Learning from Imperfectly Labeled Malware Data. | Fahad Alotaibi, Euan Goodbrand, Sergio Maffeis |
| 2025 | CCS | Poster: Randomness Unmasked: Towards Reproducible and Fair Evaluation of Shift-Aware Deep Learning NIDS. | Lucy Steele, Fahad Alotaibi, Sergio Maffeis |
| 2024 | RAID | Mateen: Adaptive Ensemble Learning for Network Anomaly Detection. | Fahad M. Alotaibi, Sergio Maffeis |
| 2024 | SEC | Rasd: Semantic Shift Detection and Adaptation for Network Intrusion Detection. | Fahad M. Alotaibi, Sergio Maffeis |
| 2022 | IJCNN | VulBERTa: Simplified Source Code Pre-Training for Vulnerability Detection. | Hazim Hanif, Sergio Maffeis |
| 2022 | TrustCom | Haxss: Hierarchical Reinforcement Learning for XSS Payload Generation. | Myles Foley, Sergio Maffeis |
| 2021 | SAC | Hawk-Eye: holistic detection of APT command and control domains. | Almuthanna Alageel, Sergio Maffeis |
| 2021 | SAC | DeepTective: detection of PHP vulnerabilities using hybrid graph neural networks. | Rishi Rabheru, Hazim Hanif, Sergio Maffeis |
| 2020 | TrustCom | Adversarial Attacks on Time-Series Intrusion Detection for Industrial Control Systems. | Giulio Zizzo, Chris Hankin, Sergio Maffeis, Kevin Jones |
| 2019 | DAC | Adversarial Machine Learning Beyond the Image Domain. | Giulio Zizzo, Chris Hankin, Sergio Maffeis, Kevin Jones |
| 2018 | RTCSA | CPS-MT: A Real-Time Cyber-Physical System Monitoring Tool for Security Research. | Martn Barrre, Chris Hankin, Angelo Barboni, Giulio Zizzo, Francesca Boem, Sergio Maffeis, Thomas Parisini |
| 2015 | ISSTA | BrowserAudit: automated testing of browser security features. | Charlie Hothersall-Thomas, Sergio Maffeis, Chris Novakovic |
| 2014 | ECOOP | An Executable Formal Semantics of PHP. | Daniele Filaretti, Sergio Maffeis |
| 2014 | POPL | A trusted mechanised JavaScript specification. | Martin Bodin, Arthur Charguraud, Daniele Filaretti, Philippa Gardner, Sergio Maffeis, Daiva Naudziuniene, Alan Schmitt, Gareth Smith |
| 2012 | POPL | Towards a program logic for JavaScript. | Philippa Gardner, Sergio Maffeis, Gareth David Smith |
| 2010 | SP | Object Capabilities and Isolation of Untrusted Web Applications. | Sergio Maffeis, John C. Mitchell, Ankur Taly |
| 2009 | ESORICS | Isolating JavaScript with Filters, Rewriting, and Wrappers. | Sergio Maffeis, John C. Mitchell, Ankur Taly |
| 2008 | APLAS | An Operational Semantics for JavaScript. | Sergio Maffeis, John C. Mitchell, Ankur Taly |
| 2008 | ESORICS | Code-Carrying Authorization. | Sergio Maffeis, Martn Abadi, Cdric Fournet, Andrew D. Gordon |
| 2005 | ESOP | A Type Discipline for Authorization Policies. | Cdric Fournet, Andrew D. Gordon, Sergio Maffeis |
| 2001 | SAS | An Abstract Interpretation Framework for Analysing Mobile Ambients. | Francesca Levi, Sergio Maffeis |