| 2012 | BetterAuth: web authentication revisited. | Martin Johns, Sebastian Lekies, Bastian Braun, Benjamin Flesch |
| 2012 | ThinAV: truly lightweight mobile cloud-based anti-malware. | Chris Jarabek, David Barrera, John Aycock |
| 2012 | Building better passwords using probabilistic techniques. | Shiva Houshmand, Sudhir Aggarwal |
| 2012 | Augmenting vulnerability analysis of binary code. | Sean Heelan, Agustin Gianni |
| 2012 | Towards network containment in malware analysis systems. | Mariano Graziano, Corrado Leita, Davide Balzarotti |
| 2012 | CodeShield: towards personalized application whitelisting. | Christopher S. Gates, Ninghui Li, Jing Chen, Robert W. Proctor |
| 2012 | SensorSift: balancing sensor data privacy and utility in automated face understanding. | Miro Enev, Jaeyeon Jung, Liefeng Bo, Xiaofeng Ren, Tadayoshi Kohno |
| 2012 | On automated image choice for secure and usable graphical passwords. | Paul Dunphy, Patrick Olivier |
| 2012 | TrueErase: per-file secure deletion for the storage data path. | Sarah M. Diesburg, Christopher R. Meyers, Mark J. Stanovich, Michael Mitchell, Justin Marshall, Julia Gould, An-I Andy Wang, Geoff Kuenning |
| 2012 | XIAO: tuning code clones at hands of engineers in practice. | Yingnong Dang, Dongmei Zhang, Song Ge, Chengyun Chu, Yingjun Qiu, Tao Xie |
| 2012 | Distributed application tamper detection via continuous software updates. | Christian S. Collberg, Sam Martin, Jonathan Myers, Jasvir Nagra |
| 2012 | TRESOR-HUNT: attacking CPU-bound encryption. | Erik-Oliver Blass, William Robertson |
| 2012 | Disclosure: detecting botnet command and control servers through large-scale NetFlow analysis. | Leyla Bilge, Davide Balzarotti, William K. Robertson, Engin Kirda, Christopher Kruegel |
| 2012 | Practicality of accelerometer side channels on smartphones. | Adam J. Aviv, Benjamin Sapp, Matt Blaze, Jonathan M. Smith |
| 2012 | Security economics: a personal perspective. | Ross J. Anderson |
| 2012 | Dissecting ghost clicks: ad fraud via misdirected human clicks. | Sumayah A. Alrwais, Alexandre Gerber, Christopher W. Dunn, Oliver Spatscheck, Minaxi Gupta, Eric Osterweil |
| 2012 | Trust engineering: rejecting the tyranny of the weakest link. | Susan D. Alexander |
| 2012 | JSand: complete client-side sandboxing of third-party JavaScript without browser modifications. | Pieter Agten, Steven Van Acker, Yoran Brondsema, Phu H. Phung, Lieven Desmet, Frank Piessens |
| 2011 | ASIDE: IDE support for web application security. | Jing Xie, Bill Chu, Heather Richter Lipford, John T. Melton |
| 2011 | RIPE: runtime intrusion prevention evaluator. | John Wilander, Nick Nikiforakis, Yves Younan, Mariam Kamkar, Wouter Joosen |
| 2011 | SEMAGE: a new image-based two-factor CAPTCHA. | Shardul Vikram, Yinan Fan, Guofei Gu |
| 2011 | A peel of onion. | Paul F. Syverson |
| 2011 | Don't Bump, Shake on It: the exploitation of a popular accelerometer-based smart phone exchange and its secure replacement. | Ahren Studer, Timothy Passaro, Lujo Bauer |
| 2011 | Security through amnesia: a software-based solution to the cold boot attack on disk encryption. | Patrick Simmons |
| 2011 | An empirical study of visual security cues to prevent the SSLstripping attack. | Dongwan Shin, Rodrigo Lopes |