| 2026 | NDSS | Time and Time Again: Leveraging TCP Timestamps to Improve Remote Timing Attacks. | Vik Vanderlinden, Tom van Goethem, Mathy Vanhoef |
| 2025 | SOUPS | Shiny Shells, Rusty Cores: A Crowdsourced Security Evaluation of Integrated Web Browsers. | Gertjan Franken, Pieter Claeys, Tom van Goethem, Lieven Desmet |
| 2023 | ESORICS | Time Will Tell: Exploiting Timing Leaks Using HTTP Response Headers. | Vik Vanderlinden, Tom van Goethem, Mathy Vanhoef |
| 2023 | SP | Scripted Henchmen: Leveraging XS-Leaks for Cross-Site Vulnerability Detection. | Tom van Goethem, Iskander Snchez-Rola, Wouter Joosen |
| 2022 | AsiaCCS | SoK: Exploring Current and Future Research Directions on XS-Leaks through an Extended Formal Model. | Tom van Goethem, Gertjan Franken, Iskander Snchez-Rola, David Dworken, Wouter Joosen |
| 2022 | SP | Towards Improving the Deprecation Process of Web Features through Progressive Web Security. | Tom van Goethem, Wouter Joosen |
| 2021 | SP | Reading Between the Lines: An Extensive Evaluation of the Security and Privacy Implications of EPUB Reading Systems. | Gertjan Franken, Tom van Goethem, Wouter Joosen |
| 2020 | NDSS | A Practical Approach for Taking Down Avalanche Botnets Under Real-World Constraints. | Victor Le Pochat, Tim Van hamme, Sourena Maroofi, Tom van Goethem, Davy Preuveneers, Andrzej Duda, Wouter Joosen, Maciej Korczynski |
| 2019 | CCS | Purchased Fame: Exploring the Ecosystem of Private Blog Networks. | Tom van Goethem, Najmeh Miramirkhani, Wouter Joosen, Nick Nikiforakis |
| 2019 | CCS | Mobile Friendly or Attacker Friendly?: A Large-scale Security Evaluation of Mobile-first Websites. | Tom van Goethem, Victor Le Pochat, Wouter Joosen |
| 2019 | NDSS | Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. | Victor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski, Wouter Joosen |
| 2019 | PAM | Funny Accents: Exploring Genuine Interest in Internationalized Domain Names. | Victor Le Pochat, Tom van Goethem, Wouter Joosen |
| 2019 | SP | A Smrgsbord of Typos: Exploring International Keyboard Layout Typosquatting. | Victor Le Pochat, Tom van Goethem, Wouter Joosen |
| 2019 | USENIX | Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie Policies. | Gertjan Franken, Tom van Goethem, Wouter Joosen |
| 2018 | NDSS | Automated Website Fingerprinting through Deep Learning. | Vera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem, Wouter Joosen |
| 2017 | CCS | Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared Hosting. | Samaneh Tajalizadehkhoob, Tom van Goethem, Maciej Korczynski, Arman Noroozian, Rainer Bhme, Tyler Moore, Wouter Joosen, Michel van Eeten |
| 2017 | CCS | The Wolf of Name Street: Hijacking Domains Through Their Nameservers. | Thomas Vissers, Timothy Barron, Tom van Goethem, Wouter Joosen, Nick Nikiforakis |
| 2016 | NDSS | It's Free for a Reason: Exploring the Ecosystem of Free Live Streaming Services. | M. Zubair Rafique, Tom van Goethem, Wouter Joosen, Christophe Huygens, Nick Nikiforakis |
| 2015 | CCS | The Clock is Still Ticking: Timing Attacks in the Modern Web. | Tom van Goethem, Wouter Joosen, Nick Nikiforakis |
| 2015 | CCS | Maneuvering Around Clouds: Bypassing Cloud-based Security Providers. | Thomas Vissers, Tom van Goethem, Wouter Joosen, Nick Nikiforakis |
| 2014 | CCS | Clubbing Seals: Exploring the Ecosystem of Third-party Security Seals. | Tom van Goethem, Frank Piessens, Wouter Joosen, Nick Nikiforakis |