| 2023 | "It's up to the Consumer to be Smart": Understanding the Security and Privacy Attitudes of Smart Home Users on Reddit. | Jingjie Li, Kaiwen Sun, Brittany Skye Huff, Anna Marie Bierley, Younghyun Kim, Florian Schaub, Kassem Fawaz |
| 2023 | Fashion Faux Pas: Implicit Stylistic Fingerprints for Bypassing Browsers' Anti-Fingerprinting Defenses. | Xu Lin, Frederico Araujo, Teryl Taylor, Jiyong Jang, Jason Polakis |
| 2023 | Evaluating Password Composition Policy and Password Meters of Popular Websites. | Kyungchan Lim, Joshua H. Kang, Matthew Dixson, Hyungjoon Koo, Doowon Kim |
| 2023 | When and Why Do People Want Ad Targeting Explanations? Evidence from a Four-Week, Mixed-Methods Field Study. | Hao-Ping (Hank) Lee, Jacob Logas, Stephanie S. Yang, Zhouyu Li, Nat M. Barbosa, Yang Wang, Sauvik Das |
| 2023 | SoK: Taxonomy of Attacks on Open-Source Software Supply Chains. | Piergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier Barais |
| 2023 | BayBFed: Bayesian Backdoor Defense for Federated Learning. | Kavita Kumari, Phillip Rieger, Hossein Fereidooni, Murtuza Jadliwala, Ahmad-Reza Sadeghi |
| 2023 | DISV: Domain Independent Semantic Validation of Data Files. | Ashish Kumar, Bill Harris, Gang Tan |
| 2023 | DevIOus: Device-Driven Side-Channel Attacks on the IOMMU. | Taehun Kim, Hyeongjin Park, Seokmin Lee, Seunghee Shin, Junbeom Hur, Youngjoo Shin |
| 2023 | "How technical do you get? I'm an English teacher": Teaching and Learning Cybersecurity and AI Ethics in High School. | Zachary Kilhoffer, Kyrie Zhixuan Zhou, Firmiana Wang, Fahad Tamton, Yun Huang, Pilyoung Kim, Tom Yeh, Yang Wang |
| 2023 | It's (DOM) Clobbering Time: Attack Techniques, Prevalence, and Defenses. | Soheil Khodayari, Giancarlo Pellegrino |
| 2023 | Low-Cost Privilege Separation with Compile Time Compartmentalization for Embedded Systems. | Arslan Khan, Dongyan Xu, Dave Jing Tian |
| 2023 | EC: Embedded Systems Compartmentalization via Intra-Kernel Isolation. | Arslan Khan, Dongyan Xu, Dave Jing Tian |
| 2023 | On the Pitfalls of Security Evaluation of Robust Federated Learning. | Momin Ahmad Khan, Virat Shejwalkar, Amir Houmansadr, Fatima M. Anwar |
| 2023 | Divergent Representations: When Compiler Optimizations Enable Exploitation. | Andreas D. Kellas, Alan Cao, Peter Goodman, Junfeng Yang |
| 2023 | "We are a startup to the core": A qualitative interview study on the security and privacy development practices in Turkish software startups. | Dilara Keklloglu, Yasemin Acar |
| 2023 | Breaking Security-Critical Voice Authentication. | Andre Kassis, Urs Hengartner |
| 2023 | BLEDiff: Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations. | Imtiaz Karim, Abdullah Al Ishtiaq, Syed Rafiul Hussain, Elisa Bertino |
| 2023 | Automatically Detecting Variability Bugs Through Hybrid Control and Data Flow Analysis. | Kelly Kaoudis, Henrik Brodin, Evan Sultanik |
| 2023 | Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style Vulnerability. | Mingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo, Jianwei Hou, V. N. Venkatakrishnan, Yinzhi Cao |
| 2023 | CSI:Rowhammer - Cryptographic Security and Integrity against Rowhammer. | Jonas Juffinger, Lukas Lamster, Andreas Kogler, Maria Eichlseder, Moritz Lipp, Daniel Gruss |
| 2023 | WaVe: a verifiably secure WebAssembly sandboxing runtime. | Evan Johnson, Evan Laufer, Zijie Zhao, Dan Gohman, Shravan Narayan, Stefan Savage, Deian Stefan, Fraser Brown |
| 2023 | Finding Specification Blind Spots via Fuzz Testing. | Ru Ji, Meng Xu |
| 2023 | PLA-LiDAR: Physical Laser Attacks against LiDAR-based 3D Object Detection in Autonomous Vehicle. | Zizhi Jin, Xiaoyu Ji, Yushi Cheng, Bo Yang, Chen Yan, Wenyuan Xu |
| 2023 | AEM: Facilitating Cross-Version Exploitability Assessment of Linux Kernel Vulnerabilities. | Zheyue Jiang, Yuan Zhang, Jun Xu, Xinqian Sun, Zhuang Liu, Min Yang |
| 2023 | AEM: Facilitating Cross-Version Exploitability Assessment of Linux Kernel Vulnerabilities. | Zheyue Jiang, Yuan Zhang, Jun Xu, Xinqian Sun, Zhuang Liu, Min Yang |