| 2016 | ELAR: extremely lightweight auditing and repairing for cloud security. | Tran Phuong Thao, Kazumasa Omote |
| 2016 | Formal security analysis of smart embedded systems. | Farid Molazem Tabrizi, Karthik Pattabiraman |
| 2016 | Pileus: protecting user resources from vulnerable cloud services. | Yuqiong Sun, Giuseppe Petracca, Xinyang Ge, Trent Jaeger |
| 2016 | Trace-free memory data structure forensics via past inference and future speculations. | Pengfei Sun, Rui Han, Mingbo Zhang, Saman A. Zonouz |
| 2016 | Timing-based reconnaissance and defense in software-defined networks. | John Sonchack, Anurag Dubey, Adam J. Aviv, Jonathan M. Smith, Eric Keller |
| 2016 | Spicy: a unified deep packet inspection framework for safely dissecting all your data. | Robin Sommer, Johanna Amann, Seth Hall |
| 2016 | Theft-resilient mobile wallets: transparently authenticating NFC users with tapping gesture biometrics. | Babins Shrestha, Manar Mohamed, Sandeep Tamrakar, Nitesh Saxena |
| 2016 | An ultra-lightweight white-box encryption scheme for securing resource-constrained IoT devices. | Yang Shi, Wujing Wei, Zongjian He, Hongfei Fan |
| 2016 | Auror: defending against poisoning attacks in collaborative deep learning systems. | Shiqi Shen, Shruti Tople, Prateek Saxena |
| 2016 | Bootstrapping and maintaining trust in the cloud. | Nabil Schear, Patrick T. Cable II, Thomas M. Moyer, Bryan Richard, Robert Rudd |
| 2016 | Active Android malware analysis: an approach based on stochastic games. | Riccardo Sartea, Mila Dalla Preda, Alessandro Farinelli, Roberto Giacobazzi, Isabella Mastroeni |
| 2016 | VTPin: practical VTable hijacking protection for binaries. | Pawel Sarbinowski, Vasileios P. Kemerlis, Cristiano Giuffrida, Elias Athanasopoulos |
| 2016 | Metadata recovery from obfuscated programs using machine learning. | Aleieldin Salem, Sebastian Banescu |
| 2016 | EvilCoder: automated bug insertion. | Jannik Pewny, Thorsten Holz |
| 2016 | HERCULE: attack story reconstruction via community discovery on correlated log graph. | Kexin Pei, Zhongshu Gu, Brendan Saltaformaggio, Shiqing Ma, Fei Wang, Zhiwei Zhang, Luo Si, Xiangyu Zhang, Dongyan Xu |
| 2016 | RevProbe: detecting silent reverse proxies in malicious server infrastructures. | Antonio Nappa, Rana Faisal Munir, Irfan Khan Tanoli, Christian Kreibich, Juan Caballero |
| 2016 | Buffer overflow attack's power consumption signatures. | Samuel Bennett Moore, Mark Yampolskiy, Jacob Gatlin, Jeffrey Todd McDonald, Todd R. Andel |
| 2016 | Gametrics: towards attack-resilient behavioral authentication with simple cognitive games. | Manar Mohamed, Nitesh Saxena |
| 2016 | CASTLE: CA signing in a touch-less environment. | Stephanos Matsumoto, Samuel Steffen, Adrian Perrig |
| 2016 | Decomposition of MAC address structure for granular device inference. | Jeremy Martin, Erik C. Rye, Robert Beverly |
| 2016 | On the (in)security of the latest generation implantable cardiac defibrillators and how to secure them. | Eduard Marin, Dave Singele, Flavio D. Garcia, Tom Chothia, Rik Willems, Bart Preneel |
| 2016 | Comparing the effectiveness of commercial obfuscators against MATE attacks. | Ramya Manikyam, Jeffrey Todd McDonald, William R. Mahoney, Todd R. Andel, Samuel H. Russ |
| 2016 | VulPecker: an automated vulnerability detection system based on code similarity analysis. | Zhen Li, Deqing Zou, Shouhuai Xu, Hai Jin, Hanchao Qi, Jie Hu |
| 2016 | Inferring browser activity and status through remote monitoring of storage usage. | Hyungsub Kim, Sangho Lee, Jong Kim |
| 2016 | Cypider: building community-based cyber-defense infrastructure for android malware detection. | ElMouatez Billah Karbab, Mourad Debbabi, Abdelouahid Derhab, Djedjiga Mouheb |