| 2026 | CHI | From Discovery to Decisions: Archetypal Journeys of Mobile App Users and Their Implications on Privacy. | H. T. M. A. Riyadh, Divyanshu Bhardwaj, Maria Victoria Hellenthal, Alexander Hart, Katharina Krombholz, Sven Bugiel |
| 2025 | CHI | Permission Rationales in the Web Ecosystem: An Exploration of Rationale Text and Design Patterns. | Yusra Elbitar, Soheil Khodayari, Marian Harbach, Gianluca De Stefano, Balazs Csaba Engedy, Giancarlo Pellegrino, Sven Bugiel |
| 2025 | NDSS | The Power of Words: A Comprehensive Analysis of Rationales and Their Effects on Users' Permission Decisions. | Yusra Elbitar, Alexander Hart, Sven Bugiel |
| 2024 | SP | Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software Security. | Alfusainey Jallow, Michael Schilling, Michael Backes, Sven Bugiel |
| 2023 | FC | TALUS: Reinforcing TEE Confidentiality with Cryptographic Coprocessors. | Dhiman Chakraborty, Michael Schwarz, Sven Bugiel |
| 2023 | NDSS | A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites. | Sanam Ghorbani Lyastani, Michael Backes, Sven Bugiel |
| 2021 | NDSS | Bringing Balance to the Force: Dynamic Analysis of the Android Application Framework. | Abdallah Dawoud, Sven Bugiel |
| 2020 | ACSAC | Up2Dep: Android Tool Support to Fix Insecure Code Dependencies. | Duc Cuong Nguyen, Erik Derr, Michael Backes, Sven Bugiel |
| 2020 | SP | Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless Authentication. | Sanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes, Sven Bugiel |
| 2019 | CCS | Poster: Let History not Repeat Itself (this Time) - Tackling WebAuthn Developer Issues Early On. | Aftab Alam, Katharina Krombholz, Sven Bugiel |
| 2019 | CCS | simFIDO: FIDO2 User Authentication with simTPM. | Dhiman Chakraborty, Sven Bugiel |
| 2019 | NDSS | DroidCap: OS Support for Capability-based Permissions in Android. | Abdallah Dawoud, Sven Bugiel |
| 2019 | SAC | Secure multi-execution in Android. | Dhiman Chakraborty, Christian Hammer, Sven Bugiel |
| 2019 | SP | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & Privacy. | Duc Cuong Nguyen, Erik Derr, Michael Backes, Sven Bugiel |
| 2018 | SP | The Rise of the Citizen Developer: Assessing the Security Impact of Online App Generators. | Marten Oltrogge, Erik Derr, Christian Stransky, Yasemin Acar, Sascha Fahl, Christian Rossow, Giancarlo Pellegrino, Sven Bugiel, Michael Backes |
| 2017 | CCS | Keep me Updated: An Empirical Study of Third-Party Library Updatability on Android. | Erik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar, Michael Backes |
| 2017 | CCS | The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android. | Jie Huang, Oliver Schranz, Sven Bugiel, Michael Backes |
| 2017 | SP | Seamless In-App Ad Blocking on Stock Android. | Michael Backes, Sven Bugiel, Philipp von Styp-Rekowsky, Marvin WiBfeld |
| 2016 | CCS | Reliable Third-Party Library Detection in Android and its Security Applications. | Michael Backes, Sven Bugiel, Erik Derr |
| 2016 | CCS | R-Droid: Leveraging Android App Analysis with Static Slice Optimization. | Michael Backes, Sven Bugiel, Erik Derr, Sebastian Gerling, Christian Hammer |
| 2016 | CCS | POSTER: The ART of App Compartmentalization. | Michael Backes, Sven Bugiel, Jie Huang, Oliver Schranz |
| 2016 | SP | SoK: Lessons Learned from Android Security Research for Appified Software Platforms. | Yasemin Acar, Michael Backes, Sven Bugiel, Sascha Fahl, Patrick D. McDaniel, Matthew Smith |
| 2014 | ACSAC | Scippa: system-centric IPC provenance on Android. | Michael Backes, Sven Bugiel, Sebastian Gerling |
| 2014 | ACSAC | Android security framework: extensible multi-layered access control on Android. | Michael Backes, Sven Bugiel, Sebastian Gerling, Philipp von Styp-Rekowsky |
| 2013 | ACNS | Client-Controlled Cryptography-as-a-Service in the Cloud. | Sren Bleikertz, Sven Bugiel, Hugo Ideler, Stefan Nrnberger, Ahmad-Reza Sadeghi |
| 2012 | FC | Softer Smartcards - Usable Cryptographic Tokens with Secure Execution. | Franz Ferdinand Peter Brasser, Sven Bugiel, Atanas Filyanov, Ahmad-Reza Sadeghi, Steffen Schulz |
| 2012 | NDSS | Towards Taming Privilege-Escalation Attacks on Android. | Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Thomas Fischer, Ahmad-Reza Sadeghi, Bhargava Shastry |
| 2011 | CCS | Scalable trust establishment with software reputation. | Sven Bugiel, Lucas Vincenzo Davi, Steffen Schulz |
| 2011 | CCS | Poster: the quest for security against privilege escalation attacks on android. | Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Thomas Fischer, Ahmad-Reza Sadeghi, Bhargava Shastry |
| 2011 | CCS | Practical and lightweight domain isolation on Android. | Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Stephan Heuser, Ahmad-Reza Sadeghi, Bhargava Shastry |
| 2011 | CCS | AmazonIA: when elasticity snaps back. | Sven Bugiel, Stefan Nrnberger, Thomas Pppelmann, Ahmad-Reza Sadeghi, Thomas Schneider |
| 2010 | CCS | Implementing an application-specific credential platform using late-launched mobile trusted module. | Sven Bugiel, Jan-Erik Ekberg |
| 2009 | CCS | Trust in a small package: minimized MRTM software implementation for mobile secure environments. | Jan-Erik Ekberg, Sven Bugiel |