| 2025 | CCS | In the DOM We Trust: Exploring the Hidden Dangers of Reading from the DOM on the Web. | Jan Drescher, Sepehr Mirzaei, Soheil Khodayari, David Klein, Thomas Barber, Martin Johns, Giancarlo Pellegrino |
| 2025 | CHI | Permission Rationales in the Web Ecosystem: An Exploration of Rationale Text and Design Patterns. | Yusra Elbitar, Soheil Khodayari, Marian Harbach, Gianluca De Stefano, Balazs Csaba Engedy, Giancarlo Pellegrino, Sven Bugiel |
| 2025 | IMC | Exploration of the Dynamics of Buy and Sale of Social Media Accounts. | Mario Beluri, Bhupendra Acharya, Soheil Khodayari, Giada Stivala, Giancarlo Pellegrino, Thorsten Holz |
| 2025 | NDSS | Do (Not) Follow the White Rabbit: Challenging the Myth of Harmless Open Redirection. | Soheil Khodayari, Kai Glauber, Giancarlo Pellegrino |
| 2025 | NDSS | YuraScanner: Leveraging LLMs for Task-driven Web App Scanning. | Aleksei Stafeev, Tim Recktenwald, Gianluca De Stefano, Soheil Khodayari, Giancarlo Pellegrino |
| 2024 | SP | The Great Request Robbery: An Empirical Study of Client-side Request Hijacking Vulnerabilities on the Web. | Soheil Khodayari, Thomas Barber, Giancarlo Pellegrino |
| 2023 | SP | It's (DOM) Clobbering Time: Attack Techniques, Prevalence, and Defenses. | Soheil Khodayari, Giancarlo Pellegrino |
| 2022 | SP | The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite Cookies. | Soheil Khodayari, Giancarlo Pellegrino |
| 2021 | RAID | Where We Stand (or Fall): An Analysis of CSRF Defenses in Web Frameworks. | Xhelal Likaj, Soheil Khodayari, Giancarlo Pellegrino |
| 2020 | NDSS | Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks. | Avinash Sudhodanan, Soheil Khodayari, Juan Caballero |