| 2026 | EACL | Adversarial Decoding: Generating Readable Documents for Adversarial Objectives. | Collin Zhang, Tingwei Zhang, Vitaly Shmatikov |
| 2026 | SP | Adversarial Hubness in Multi-Modal Retrieval. | Tingwei Zhang, Fnu Suya, Rishi D. Jha, Collin Zhang, Vitaly Shmatikov |
| 2024 | CCS | Mithridates: Auditing and Boosting Backdoor Resistance of Machine Learning Pipelines. | Eugene Bagdasarian, Vitaly Shmatikov |
| 2024 | EMNLP | Extracting Prompts by Inverting LLM Outputs. | Collin Zhang, John X. Morris, Vitaly Shmatikov |
| 2024 | ICLR | Language Model Inversion. | John X. Morris, Wenting Zhao, Justin T. Chiu, Vitaly Shmatikov, Alexander M. Rush |
| 2023 | EMNLP | Text Embeddings Reveal (Almost) As Much As Text. | John X. Morris, Volodymyr Kuleshov, Vitaly Shmatikov, Alexander M. Rush |
| 2023 | SP | Telepath: A Minecraft-based Covert Communication System. | Zhen Sun, Vitaly Shmatikov |
| 2022 | SP | Spinning Language Models: Risks of Propaganda-As-A-Service and Countermeasures. | Eugene Bagdasaryan, Vitaly Shmatikov |
| 2020 | AISTATS | How To Backdoor Federated Learning. | Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, Vitaly Shmatikov |
| 2020 | EMNLP | Adversarial Semantic Collisions. | Congzheng Song, Alexander M. Rush, Vitaly Shmatikov |
| 2020 | ICLR | Overlearning Reveals Sensitive Attributes. | Congzheng Song, Vitaly Shmatikov |
| 2020 | SP | Humpty Dumpty: Controlling Word Meanings via Corpus Poisoning. | Roei Schuster, Tal Schuster, Yoav Meri, Vitaly Shmatikov |
| 2019 | KDD | Auditing Data Provenance in Text-Generation Models. | Congzheng Song, Vitaly Shmatikov |
| 2019 | SP | Exploiting Unintended Feature Leakage in Collaborative Learning. | Luca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly Shmatikov |
| 2018 | CCS | Situational Access Control in the Internet of Things. | Roei Schuster, Vitaly Shmatikov, Eran Tromer |
| 2017 | CCS | Using Program Analysis to Synthesize Sensor Spoofing Attacks. | Ivan Pustogarov, Thomas Ristenpart, Vitaly Shmatikov |
| 2017 | CCS | Machine Learning Models that Remember Too Much. | Congzheng Song, Thomas Ristenpart, Vitaly Shmatikov |
| 2017 | HotOS | Why Your Encrypted Database Is Not Secure. | Paul Grubbs, Thomas Ristenpart, Vitaly Shmatikov |
| 2017 | SP | Membership Inference Attacks Against Machine Learning Models. | Reza Shokri, Marco Stronati, Congzheng Song, Vitaly Shmatikov |
| 2016 | CCS | Breaking Web Applications Built On Top of Encrypted Data. | Paul Grubbs, Richard McPherson, Muhammad Naveed, Thomas Ristenpart, Vitaly Shmatikov |
| 2016 | NDSS | What Mobile Ads Know About Mobile Users. | Sooel Son, Daehyeok Kim, Vitaly Shmatikov |
| 2016 | NSDI | Earp: Principled Storage, Sharing, and Protection for Mobile Apps. | Yuanzhong Xu, Tyler Hunt, Youngjin Kwon, Martin Georgiev, Vitaly Shmatikov, Emmett Witchel |
| 2016 | WACV | Can we still avoid automatic face detection? | Michael J. Wilber, Vitaly Shmatikov, Serge J. Belongie |
| 2015 | CCS | Privacy-Preserving Deep Learning. | Reza Shokri, Vitaly Shmatikov |
| 2015 | WWW | Rethinking Security of Web-Based System Applications. | Martin Georgiev, Suman Jana, Vitaly Shmatikov |
| 2015 | WWW | No Escape From Reality: Security and Privacy of Augmented Reality Browsers. | Richard McPherson, Suman Jana, Vitaly Shmatikov |
| 2014 | NDSS | Breaking and Fixing Origin-Based Access Control in Hybrid Web/Mobile Application Frameworks. | Martin Georgiev, Suman Jana, Vitaly Shmatikov |
| 2014 | NDSS | No Direction Home: The True Cost of Routing Around Decoys. | Amir Houmansadr, Edmund L. Wong, Vitaly Shmatikov |
| 2014 | SP | Using Frankencerts for Automated Adversarial Testing of Certificate Validation in SSL/TLS Implementations. | Chad Brubaker, Suman Jana, Baishakhi Ray, Sarfraz Khurshid, Vitaly Shmatikov |
| 2013 | CCS | Diglossia: detecting code injection attacks with precision and efficiency. | Sooel Son, Kathryn S. McKinley, Vitaly Shmatikov |
| 2013 | KDD | Privacy-preserving data exploration in genome-wide association studies. | Aaron Johnson, Vitaly Shmatikov |
| 2013 | NDSS | Fix Me Up: Repairing Access-Control Bugs in Web Applications. | Sooel Son, Kathryn S. McKinley, Vitaly Shmatikov |
| 2013 | NDSS | The Postman Always Rings Twice: Attacking and Defending postMessage in HTML5 Websites. | Sooel Son, Vitaly Shmatikov |
| 2013 | NSDI | πBox: A Platform for Privacy-Preserving Apps. | Sangmin Lee, Edmund L. Wong, Deepak Goel, Mike Dahlin, Vitaly Shmatikov |
| 2013 | SP | The Parrot Is Dead: Observing Unobservable Network Communications. | Amir Houmansadr, Chad Brubaker, Vitaly Shmatikov |
| 2013 | SP | A Scanner Darkly: Protecting User Privacy from Perceptual Applications. | Suman Jana, Arvind Narayanan, Vitaly Shmatikov |
| 2012 | CCS | The most dangerous code in the world: validating SSL certificates in non-browser software. | Martin Georgiev, Subodh Iyengar, Suman Jana, Rishita Anubhai, Dan Boneh, Vitaly Shmatikov |
| 2012 | OSDI | Eternal Sunshine of the Spotless Machine: Protecting Privacy with Ephemeral Channels. | Alan M. Dunn, Michael Z. Lee, Suman Jana, Sangman Kim, Mark Silberstein, Yuanzhong Xu, Vitaly Shmatikov, Emmett Witchel |
| 2012 | SP | Abusing File Processing in Malware Detectors for Fun and Profit. | Suman Jana, Vitaly Shmatikov |
| 2012 | SP | Memento: Learning Secrets from Process Footprints. | Suman Jana, Vitaly Shmatikov |
| 2011 | DSN | Get off my prefix! the need for dynamic, gerontocratic policies in inter-domain routing. | Edmund L. Wong, Vitaly Shmatikov |
| 2011 | OOPSLA | RoleCast: finding missing security checks when you do not know what checks are. | Sooel Son, Kathryn S. McKinley, Vitaly Shmatikov |
| 2011 | PLDI | SAFERPHP: finding semantic vulnerabilities in PHP applications. | Sooel Son, Vitaly Shmatikov |
| 2011 | PLDI | A security policy oracle: detecting security holes using multiple API implementations. | Varun Srivastava, Michael D. Bond, Kathryn S. McKinley, Vitaly Shmatikov |
| 2011 | SP | "You Might Also Like: " Privacy Risks of Collaborative Filtering. | Joseph A. Calandrino, Ann Kilzer, Arvind Narayanan, Edward W. Felten, Vitaly Shmatikov |
| 2011 | SP | TxBox: Building Secure, Efficient Sandboxes with System Transactions. | Suman Jana, Donald E. Porter, Vitaly Shmatikov |
| 2010 | NSDI | Airavat: Security and Privacy for MapReduce. | Indrajit Roy, Srinath T. V. Setty, Ann Kilzer, Vitaly Shmatikov, Emmett Witchel |
| 2010 | PLDI | Efficient, context-sensitive detection of real-world semantic attacks. | Michael D. Bond, Varun Srivastava, Kathryn S. McKinley, Vitaly Shmatikov |
| 2010 | SecureComm | The Hitchhiker's Guide to DNS Cache Poisoning. | Sooel Son, Vitaly Shmatikov |
| 2009 | FC | Privacy-Preserving Classifier Learning. | Justin Brickell, Vitaly Shmatikov |
| 2009 | SP | De-anonymizing Social Networks. | Arvind Narayanan, Vitaly Shmatikov |
| 2008 | KDD | The cost of privacy: destruction of data-mining utility in anonymized data publishing. | Justin Brickell, Vitaly Shmatikov |
| 2008 | SP | Towards Practical Privacy for Genomic Computation. | Somesh Jha, Louis Kruger, Vitaly Shmatikov |
| 2008 | SP | Robust De-anonymization of Large Sparse Datasets. | Arvind Narayanan, Vitaly Shmatikov |
| 2007 | CCS | Privacy-preserving remote diagnostics. | Justin Brickell, Donald E. Porter, Vitaly Shmatikov, Emmett Witchel |
| 2007 | EuroCrypt | Efficient Two-Party Secure Computation on Committed Inputs. | Stanislaw Jarecki, Vitaly Shmatikov |
| 2007 | NSDI | dFence: Transparent Network-based Denial of Service Mitigation. | Ajay Mahimkar, Jasraj Dange, Vitaly Shmatikov, Harrick M. Vin, Yin Zhang |
| 2007 | PODC | Truth in advertising: lightweight verification of route integrity. | Edmund L. Wong, Praveen Balasubramanian, Lorenzo Alvisi, Mohamed G. Gouda, Vitaly Shmatikov |
| 2007 | SIGCOMM | Security against probe-response attacks in collaborative intrusion detection. | Vitaly Shmatikov, Ming-Hsiu Wang |
| 2006 | ESORICS | Timing Analysis in Low-Latency Mix Networks: Attacks and Defenses. | Vitaly Shmatikov, Ming-Hsiu Wang |
| 2006 | KDD | Efficient anonymity-preserving data collection. | Justin Brickell, Vitaly Shmatikov |
| 2006 | NSPW | Large-scale collection and sanitization of network security data: risks and challenges. | Phillip A. Porras, Vitaly Shmatikov |
| 2005 | ASIACRYPT | Privacy-Preserving Graph Algorithms in the Semi-honest Model. | Justin Brickell, Vitaly Shmatikov |
| 2005 | CCS | Towards computationally sound symbolic analysis of key exchange protocols. | Prateek Gupta, Vitaly Shmatikov |
| 2005 | CCS | Obfuscated databases and group privacy. | Arvind Narayanan, Vitaly Shmatikov |
| 2005 | CCS | Fast dictionary attacks on passwords using time-space tradeoff. | Arvind Narayanan, Vitaly Shmatikov |
| 2005 | FC | Probabilistic Escrow of Financial Transactions with Cumulative Threshold Disclosure. | Stanislaw Jarecki, Vitaly Shmatikov |
| 2005 | ICALP | Probabilistic Polynomial-Time Semantics for a Protocol Security Logic. | Anupam Datta, Ante Derek, John C. Mitchell, Vitaly Shmatikov, Mathieu Turuani |
| 2004 | ESOP | Decidable Analysis of Cryptographic Protocols with Products and Modular Exponentiation. | Vitaly Shmatikov |
| 2004 | EuroCrypt | Handcuffing Big Brother: an Abuse-Resilient Transaction Escrow Scheme. | Stanislaw Jarecki, Vitaly Shmatikov |
| 2003 | CONCUR | Contract Signing, Optimism, and Advantage. | Rohit Chadha, John C. Mitchell, Andre Scedrov, Vitaly Shmatikov |
| 2003 | LICS | Intruder Deductions, Constraint Solving and Insecurity Decision in Presence of Exclusive or. | Hubert Comon-Lundh, Vitaly Shmatikov |
| 2001 | CCS | Constraint solving for bounded-process cryptographic protocol analysis. | Jonathan K. Millen, Vitaly Shmatikov |
| 2000 | FC | Analysis of Abuse-Free Contract Signing. | Vitaly Shmatikov, John C. Mitchell |
| 2000 | NDSS | Analysis of a Fair Exchange Protocol. | Vitaly Shmatikov, John C. Mitchell |
| 1999 | ECOOP | A Core Calculus of Classes and Mixins. | Viviana Bono, Amit Patel, Vitaly Shmatikov |