| 2023 | CCS | Compact Frequency Estimators in Adversarial Environments. | Sam A. Markelon, Mia Filic, Thomas Shrimpton |
| 2022 | AsiaCCS | SMS OTP Security (SOS): Hardening SMS-Based Two Factor Authentication. | Christian Peeters, Christopher Patton, Imani N. S. Munyaka, Daniel Olszewski, Thomas Shrimpton, Patrick Traynor |
| 2022 | SP | Hardening Circuit-Design IP Against Reverse-Engineering Attacks. | Animesh Chhotaray, Thomas Shrimpton |
| 2022 | SP | Security Foundations for Application-Based Covert Communication Channels. | James K. Howes IV, Marios Georgiou, Alex J. Malozemoff, Thomas Shrimpton |
| 2021 | ACML | Beyond L | Hadi Abdullah, Muhammad Sajidur Rahman, Christian Peeters, Cassidy Gibson, Washington Garcia, Vincent Bindschaedler, Thomas Shrimpton, Patrick Traynor |
| 2020 | CRYPTO | Quantifying the Security Cost of Migrating Protocols to Practice. | Christopher Patton, Thomas Shrimpton |
| 2019 | CCS | A Hybrid Approach to Secure Function Evaluation using SGX. | Joseph I. Choi, Dave (Jing) Tian, Grant Hernandez, Christopher Patton, Benjamin Mood, Thomas Shrimpton, Kevin R. B. Butler, Patrick Traynor |
| 2019 | CCS | Probabilistic Data Structures in Adversarial Environments. | David Clayton, Christopher Patton, Thomas Shrimpton |
| 2019 | CRYPTO | Security in the Presence of Key Reuse: Context-Separable Interfaces and Their Applications. | Christopher Patton, Thomas Shrimpton |
| 2018 | CCS | Partially Specified Channels: The TLS 1.3 Record Layer without Elision. | Christopher Patton, Thomas Shrimpton |
| 2018 | CCS | Mitigating Risk while Complying with Data Retention Laws. | Luis Vargas, Gyan Hazarika, Rachel Culpepper, Kevin R. B. Butler, Thomas Shrimpton, Doug Szajda, Patrick Traynor |
| 2017 | CCS | Standardizing Bad Cryptographic Practice: A Teardown of the IEEE Standard for Protecting Electronic-design Intellectual Property. | Animesh Chhotaray, Adib Nahiyan, Thomas Shrimpton, Domenic Forte, Mark Tehranipoor |
| 2017 | CRYPTO | Hedging Public-Key Encryption in the Real World. | Alexandra Boldyreva, Christopher Patton, Thomas Shrimpton |
| 2016 | ASIACRYPT | Salvaging Weak Security Bounds for Blockcipher-Based Constructions. | Thomas Shrimpton, R. Seth Terashima |
| 2016 | CRYPTO | A Modular Treatment of Cryptographic APIs: The Symmetric-Key Case. | Thomas Shrimpton, Martijn Stam, Bogdan Warinschi |
| 2015 | CCS | Seeing through Network-Protocol Obfuscation. | Liang Wang, Kevin P. Dyer, Aditya Akella, Thomas Ristenpart, Thomas Shrimpton |
| 2015 | EuroCrypt | A Provable-Security Analysis of Intel's Secure Key RNG. | Thomas Shrimpton, R. Seth Terashima |
| 2014 | CCS | Formatted Encryption Beyond Regular Languages. | Daniel Luchaup, Thomas Shrimpton, Thomas Ristenpart, Somesh Jha |
| 2014 | EuroCrypt | Reconsidering Generic Composition. | Chanathip Namprempre, Phillip Rogaway, Thomas Shrimpton |
| 2013 | ASIACRYPT | A Modular Framework for Building Variable-Input-Length Tweakable Ciphers. | Thomas Shrimpton, R. Seth Terashima |
| 2013 | CCS | Protocol misidentification made easy with format-transforming encryption. | Kevin P. Dyer, Scott E. Coull, Thomas Ristenpart, Thomas Shrimpton |
| 2012 | CRYPTO | Tweakable Blockciphers with Beyond Birthday-Bound Security. | Will Landecker, Thomas Shrimpton, R. Seth Terashima |
| 2012 | SP | Peek-a-Boo, I Still See You: Why Efficient Traffic Analysis Countermeasures Fail. | Kevin P. Dyer, Scott E. Coull, Thomas Ristenpart, Thomas Shrimpton |
| 2011 | ASIACRYPT | Tag Size Does Matter: Attacks and Proofs for the TLS Record Protocol. | Kenneth G. Paterson, Thomas Ristenpart, Thomas Shrimpton |
| 2011 | EuroCrypt | Careful with Composition: Limitations of the Indifferentiability Framework. | Thomas Ristenpart, Hovav Shacham, Thomas Shrimpton |
| 2010 | ASIACRYPT | Random Oracles with(out) Programmability. | Marc Fischlin, Anja Lehmann, Thomas Ristenpart, Thomas Shrimpton, Martijn Stam, Stefano Tessaro |
| 2010 | FSE | Attacking the Knudsen-Preneel Compression Functions. | Onur zen, Thomas Shrimpton, Martijn Stam |
| 2009 | EuroCrypt | Salvaging Merkle-Damgrd for Practical Applications. | Yevgeniy Dodis, Thomas Ristenpart, Thomas Shrimpton |
| 2008 | ICALP | Building a Collision-Resistant Compression Function from Non-compressing Primitives. | Thomas Shrimpton, Martijn Stam |
| 2007 | ASIACRYPT | Seven-Property-Preserving Iterated Hashing: ROX. | Elena Andreeva, Gregory Neven, Bart Preneel, Thomas Shrimpton |
| 2007 | ASIACRYPT | How to Build a Hash Function from Any Collision-Resistant Function. | Thomas Ristenpart, Thomas Shrimpton |
| 2006 | EuroCrypt | A Provable-Security Treatment of the Key-Wrap Problem. | Phillip Rogaway, Thomas Shrimpton |
| 2005 | EuroCrypt | On the Impossibility of Highly-Efficient Blockcipher-Based Hash Functions. | John Black, Martin Cochran, Thomas Shrimpton |
| 2004 | FSE | Cryptographic Hash-Function Basics: Definitions, Implications, and Separations for Preimage Resistance, Second-Preimage Resistance, and Collision Resistance. | Phillip Rogaway, Thomas Shrimpton |
| 2002 | CRYPTO | Black-Box Analysis of the Block-Cipher-Based Hash-Function Constructions from PGV. | John Black, Phillip Rogaway, Thomas Shrimpton |
| 2002 | CRYPTO | Threshold Password-Authenticated Key Exchange. | Philip D. MacKenzie, Thomas Shrimpton, Markus Jakobsson |