| 2022 | Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust. | Johnny So, Najmeh Miramirkhani, Michael Ferdman, Nick Nikiforakis |
| 2022 | On the Security of Parsing Security-Relevant HTTP Headers in Modern Browsers. | Hendrik Siewert, Martin Kretschmer, Marcus Niemietz, Juraj Somorovsky |
| 2022 | Effective Seed Scheduling for Fuzzing with Graph Centrality Analysis. | Dongdong She, Abhishek Shah, Suman Jana |
| 2022 | Model Stealing Attacks Against Inductive Graph Neural Networks. | Yun Shen, Xinlei He, Yufei Han, Yang Zhang |
| 2022 | Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated Learning. | Virat Shejwalkar, Amir Houmansadr, Peter Kairouz, Daniel Ramage |
| 2022 | Invisible Finger: Practical Electromagnetic Interference Attack on Touchscreen-based Electronic Devices. | Haoqi Shan, Boyi Zhang, Zihao Zhan, Dean Sullivan, Shuo Wang, Yier Jin |
| 2022 | Private Approximate Nearest Neighbor Search with Sublinear Communication. | Sacha Servan-Schreiber, Simon Langowski, Srinivas Devadas |
| 2022 | Concept-based Adversarial Attacks: Tricking Humans and Classifiers Alike. | Johannes Schneider, Giovanni Apruzzese |
| 2022 | DABANGG: A Case for Noise Resilient Flush-Based Cache Attacks. | Anish Saxena, Biswabandan Panda |
| 2022 | Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management Devices. | Takayuki Sasaki, Akira Fujita, Carlos Hernandez Gan, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
| 2022 | Certified Parsing of Dependent Regular Grammars. | John Sarracino, Gang Tan, Greg Morrisett |
| 2022 | Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion. | Preethi Santhanam, Hoang Dang, Zhiyong Shan, Iulian Neamtiu |
| 2022 | Journey to the Center of the Cookie Ecosystem: Unraveling Actors' Roles and Relationships. | Iskander Snchez-Rola, Matteo Dell'Amico, Davide Balzarotti, Pierre-Antoine Vervier, Leyla Bilge |
| 2022 | Measuring Developers' Web Security Awareness from Attack and Defense Perspectives. | Merve Sahin, Tolga nl, Cdric Hbert, Lynsay A. Shepherd, Natalie Coull, Colin McLean |
| 2022 | TrollMagnifier: Detecting State-Sponsored Troll Accounts on Reddit. | Mohammad Hammas Saeed, Shiza Ali, Jeremy Blackburn, Emiliano De Cristofaro, Savvas Zannettou, Gianluca Stringhini |
| 2022 | SYMBEXCEL: Automated Analysis and Understanding of Malicious Excel 4.0 Macros. | Nicola Ruaro, Fabio Pagani, Stefano Ortolani, Christopher Kruegel, Giovanni Vigna |
| 2022 | AirTag of the Clones: Shenanigans with Liberated Item Finders. | Thomas Roth, Fabian Freyer, Matthias Hollick, Jiska Classen |
| 2022 | SNARKBlock: Federated Anonymous Blocklisting from Hidden Common Input Aggregate Proofs. | Michael Rosenberg, Mary Maller, Ian Miers |
| 2022 | Wobfuscator: Obfuscating JavaScript Malware via Opportunistic Translation to WebAssembly. | Alan Romano, Daniel Lehmann, Michael Pradel, Weihang Wang |
| 2022 | Publicly Accountable Robust Multi-Party Computation. | Marc Rivinius, Pascal Reisert, Daniel Rausch, Ralf Ksters |
| 2022 | SecFloat: Accurate Floating-Point meets Secure 2-Party Computation. | Deevashwer Rathee, Anwesh Bhattacharya, Rahul Sharma, Divya Gupta, Nishanth Chandran, Aseem Rastogi |
| 2022 | DeepSteal: Advanced Model Extractions Leveraging Efficient Weight Stealing in Memories. | Adnan Siraj Rakin, Md Hafizul Islam Chowdhuryy, Fan Yao, Deliang Fan |
| 2022 | Practical EMV Relay Protection. | Andreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu, Liqun Chen |
| 2022 | Quantifying Blockchain Extractable Value: How dark is the forest? | Kaihua Qin, Liyi Zhou, Arthur Gervais |
| 2022 | You Can't Protect What You Don't Understand: Characterizing an Operational Gas SCADA Network. | Xi Qin, Martin Rosso, Alvaro A. Crdenas, Sandro Etalle, Jerry den Hartog, Emmanuele Zambon |