| 2019 | How Well Do My Results Generalize? Comparing Security and Privacy Survey Results from MTurk, Web, and Telephone Samples. | Elissa M. Redmiles, Sean Kross, Michelle L. Mazurek |
| 2019 | "Should I Worry?" A Cross-Cultural Examination of Account Security Incident Response. | Elissa M. Redmiles |
| 2019 | Formally Verified Cryptographic Web Applications in WebAssembly. | Jonathan Protzenko, Benjamin Beurdouche, Denis Merigoux, Karthikeyan Bhargavan |
| 2019 | A Smrgsbord of Typos: Exploring International Keyboard Layout Typosquatting. | Victor Le Pochat, Tom van Goethem, Wouter Joosen |
| 2019 | Analysis of the Susceptibility of Smart Home Programming Interfaces to End User Error. | Mitali Palekar, Earlence Fernandes, Franziska Roesner |
| 2019 | Beyond Credential Stuffing: Password Similarity Models Using Neural Networks. | Bijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas Ristenpart |
| 2019 | PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing Blacklists. | Adam Oest, Yeganeh Safaei, Adam Doup, Gail-Joon Ahn, Brad Wardman, Kevin Tyers |
| 2019 | Understanding the Security of ARM Debugging Features. | Zhenyu Ning, Fengwei Zhang |
| 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & Privacy. | Duc Cuong Nguyen, Erik Derr, Michael Backes, Sven Bugiel |
| 2019 | Drones' Cryptanalysis - Smashing Cryptography with a Flicker. | Ben Nassi, Raz Ben-Netanel, Adi Shamir, Yuval Elovici |
| 2019 | Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning. | Milad Nasr, Reza Shokri, Amir Houmansadr |
| 2019 | Security of GPS/INS Based On-road Location Tracking Systems. | Sashank Narain, Aanjhan Ranganathan, Guevara Noubir |
| 2019 | Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided Tracing. | Stefan Nagy, Matthew Hicks |
| 2019 | Feasibility of a Keystroke Timing Attack on Search Engines with Autocomplete. | John V. Monaco |
| 2019 | HOLMES: Real-Time APT Detection through Correlation of Suspicious Information Flows. | Sadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar, V. N. Venkatakrishnan |
| 2019 | Resident Evil: Understanding Residential IP Proxy as a Dark Service. | Xianghang Mi, Xuan Feng, Xiaojing Liao, Baojun Liu, XiaoFeng Wang, Feng Qian, Zhou Li, Sumayah A. Alrwais, Limin Sun, Ying Liu |
| 2019 | Exploiting Unintended Feature Leakage in Collaborative Learning. | Luca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly Shmatikov |
| 2019 | Self-Encrypting Deception: Weaknesses in the Encryption of Solid State Drives. | Carlo Meijer, Bernard van Gastel |
| 2019 | Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone Touchscreens. | Seita Maruyama, Satohiro Wakabayashi, Tatsuya Mori |
| 2019 | Deep in the Dark - Deep Learning-Based Malware Traffic Detection Without Expert Knowledge. | Gonzalo Marn, Pedro Casas, Germn Capdehourat |
| 2019 | IEC 60870-5-104 Network Characterization of a Large-Scale Operational Power Grid. | Kelvin Mai, Xi Qin, Neil Ortiz Silva, Alvaro A. Crdenas |
| 2019 | Reasoning Analytically about Password-Cracking Software. | Enze Liu, Amanda Nakanishi, Maximilian Golla, David Cash, Blase Ur |
| 2019 | DEEPSEC: A Uniform Platform for Security Analysis of Deep Learning Model. | Xiang Ling, Shouling Ji, Jiaxu Zou, Jiannan Wang, Chunming Wu, Bo Li, Ting Wang |
| 2019 | Defending Against Neural Network Model Stealing Attacks Using Deceptive Perturbations. | Taesung Lee, Benjamin Edwards, Ian M. Molloy, Dong Su |
| 2019 | Certified Robustness to Adversarial Examples with Differential Privacy. | Mathias Lcuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, Suman Jana |