| 2019 | NDSS | Distinguishing Attacks from Legitimate Authentication Traffic at Scale. | Cormac Herley, Stuart E. Schechter |
| 2016 | ASIACRYPT | Balloon Hashing: A Memory-Hard Function Providing Provable Protection Against Sequential Attacks. | Dan Boneh, Henry Corrigan-Gibbs, Stuart E. Schechter |
| 2015 | SOUPS | Learning Assigned Secrets for Unlocking Mobile Devices. | Stuart E. Schechter, Joseph Bonneau |
| 2014 | SOUPS | Harder to Ignore? Revisiting Pop-Up Fatigue and Approaches to Prevent It. | Cristian Bravo-Lillo, Lorrie Faith Cranor, Saranga Komanduri, Stuart E. Schechter, Manya Sleeper |
| 2013 | FC | The Importance of Being Earnest [In Security Warnings]. | Serge Egelman, Stuart E. Schechter |
| 2013 | SOUPS | Your attention please: designing security-decision UIs to make genuine risks harder to ignore. | Cristian Bravo-Lillo, Saranga Komanduri, Lorrie Faith Cranor, Robert W. Reeder, Manya Sleeper, Julie S. Downs, Stuart E. Schechter |
| 2012 | CCS | Operating system framed in case of mistaken identity: measuring the success of web-based spoofing attacks on OS password-entry dialogs. | Cristian Bravo-Lillo, Lorrie Faith Cranor, Julie S. Downs, Saranga Komanduri, Stuart E. Schechter, Manya Sleeper |
| 2012 | FC | It's Not Stealing If You Need It: A Panel on the Ethics of Performing Research Using Public Data of Illicit Origin. | Serge Egelman, Joseph Bonneau, Sonia Chiasson, David Dittrich, Stuart E. Schechter |
| 2012 | SOUPS | Goldilocks and the | Eiji Hayashi, Oriana Riva, Karin Strauss, A. J. Bernheim Brush, Stuart E. Schechter |
| 2011 | CCS | These aren't the droids you're looking for: retrofitting android to protect data from imperious applications. | Peter Hornyack, Seungyeop Han, Jaeyeon Jung, Stuart E. Schechter, David Wetherall |
| 2011 | HotOS | Privacy Revelations for Web and Mobile Apps. | David Wetherall, David R. Choffnes, Ben Greenstein, Seungyeop Han, Peter Hornyack, Jaeyeon Jung, Stuart E. Schechter, Xiao Sophia Wang |
| 2010 | ISCA | Use ECP, not ECC, for hard failures in resistive memories. | Stuart E. Schechter, Gabriel H. Loh, Karin Strauss, Doug Burger |
| 2009 | CHI | Can I borrow your phone?: understanding concerns when sharing mobile phones. | Amy K. Karlson, A. J. Bernheim Brush, Stuart E. Schechter |
| 2009 | CHI | It's not what you know, but who you know: a social approach to last-resort authentication. | Stuart E. Schechter, Serge Egelman, Robert W. Reeder |
| 2009 | NSPW | Laissez-faire file sharing: access control designed for individuals at the endpoints. | Maritza L. Johnson, Steven M. Bellovin, Robert W. Reeder, Stuart E. Schechter |
| 2009 | SP | It's No Secret. Measuring the Security and Reliability of Authentication via "Secret" Questions. | Stuart E. Schechter, A. J. Bernheim Brush, Serge Egelman |
| 2009 | SOUPS | It's no secret: measuring the security and reliability of authentication via 'secret' questions. | Stuart E. Schechter, A. J. Bernheim Brush, Serge Egelman |
| 2009 | SOUPS | It's not what you know, but who you know: a social approach to last-resort authentication. | Stuart E. Schechter, Serge Egelman, Robert W. Reeder |
| 2009 | SOUPS | 1 + 1 = you: measuring the comprehensibility of metaphors for configuring backup authentication. | Stuart E. Schechter, Robert W. Reeder |
| 2007 | SP | The Emperor's New Security Indicators. | Stuart E. Schechter, Rachna Dhamija, Andy Ozment, Ian Fischer |
| 2006 | NDSS | Inoculating SSH Against Address Harvesting. | Stuart E. Schechter, Jaeyeon Jung, Will Stockwell, Cynthia D. McLain |
| 2004 | RAID | Fast Detection of Scanning Worm Infections. | Stuart E. Schechter, Jaeyeon Jung, Arthur W. Berger |
| 2003 | FC | How Much Security Is Enough to Stop a Thief?: The Economics of Outsider Theft via Computer Systems and Networks. | Stuart E. Schechter, Michael D. Smith |
| 1999 | FC | Anonymous Authentication of Membership in Dynamic Groups. | Stuart E. Schechter, Todd Parnell, Alexander J. Hartemink |