| 2011 | Gaming security by obscurity. | Dusko Pavlovic |
| 2011 | Security and privacy considerations in digital death. | Michael E. Locasto, Michael Massimi, Peter DePasquale |
| 2011 | Public security: simulations need to replace conventional wisdom. | Kay Hamacher, Stefan Katzenbeisser |
| 2011 | Applying problem-structuring methods to problems in computer security. | Peter Gutmann |
| 2011 | Sherlock holmes' evil twin: on the impact of global inference for online privacy. | Gerald Friedland, Gregor Maier, Robin Sommer, Nicholas Weaver |
| 2011 | Towards a formal model of accountability. | Joan Feigenbaum, Aaron D. Jaggard, Rebecca N. Wright |
| 2011 | Position paper: why are there so many vulnerabilities in web applications? | Wenliang Du, Karthick Jayaraman, Xi Tan, Tongbo Luo, Steve J. Chapin |
| 2011 | The security cost of cheap user interaction. | Rainer Bhme, Jens Grossklags |
| 2011 | Resilience is more than availability. | Matt Bishop, Marco M. Carvalho, Richard Ford, Liam M. Mayron |
| 2011 | A multi-word password proposal (gridWord) and exploring questions about science in security research and usable security evaluation. | Kemal Bicakci, Paul C. van Oorschot |
| 2010 | A billion keys, but few locks: the crisis of web single sign-on. | San-Tsai Sun, Yazan Boshmaf, Kirstie Hawkey, Konstantin Beznosov |
| 2010 | Ontological semantic technology for detecting insider threat and social engineering. | Victor Raskin, Julia M. Taylor, Christian Hempelmann |
| 2010 | A stealth approach to usable security: helping IT security managers to identify workable security solutions. | Simon E. Parkin, Aad P. A. van Moorsel, Philip Inglesant, Martina Angela Sasse |
| 2010 | Would a 'cyber warrior' protect us: exploring trade-offs between attack and defense of information systems. | Tyler Moore, Allan Friedman, Ariel D. Procaccia |
| 2010 | This is your data on drugs: lessons computer security can learn from the drug war. | David Molnar, Serge Egelman, Nicolas Christin |
| 2010 | Why is there no science in cyber science?: a panel discussion at NSPW 2010. | Roy A. Maxion, Thomas A. Longstaff, John McHugh |
| 2010 | The pervasive trust foundation for security in next generation networks. | Leszek Lilien, Adawia Al-Alawneh, Lotfi Ben Othmane |
| 2010 | E unibus pluram: massive-scale software diversity as a defense mechanism. | Michael Franz |
| 2010 | To boldly go where invention isn't secure: applying security entrepreneurship to secure systems design. | Shamal Faily, Ivan Flechais |
| 2010 | On-line privacy and consent: a dialogue, not a monologue. | Lizzie Coles-Kemp, Elahe Kani-Zabihi |
| 2010 | A risk management process for consumers: the next step in information security. | Andr van Cleeff |
| 2010 | VM-based security overkill: a lament for applied systems security research. | Sergey Bratus, Michael E. Locasto, Ashwin Ramaswamy, Sean W. Smith |
| 2010 | Relationships and data sanitization: a study in scarlet. | Matt Bishop, Justin Cummins, Sean Peisert, Anhad Singh, Bhume Bhumiratana, Deborah A. Agarwal, Deborah A. Frincke, Michael A. Hogarth |
| 2010 | On information flow for intrusion detection: what if accurate full-system dynamic information flow tracking was possible? | Mohammed I. Al-Saleh, Jedidiah R. Crandall |
| 2009 | Quantified security is a weak hypothesis: a critical survey of results and assumptions. | Vilhelm Verendel |