| 2016 | Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser Fingerprints. | Pierre Laperdrix, Walter Rudametkin, Benoit Baudry |
| 2016 | An Incremental Learner for Language-Based Anomaly Detection in XML. | Harald Lampesberger |
| 2016 | Hawk: The Blockchain Model of Cryptography and Privacy-Preserving Smart Contracts. | Ahmed E. Kosba, Andrew Miller, Elaine Shi, Zikai Wen, Charalampos Papamanthou |
| 2016 | Compliance Monitoring of Third-Party Applications in Online Social Networks. | Florian Kelbert, Alexander Fromm |
| 2016 | Verena: End-to-End Integrity Protection for Web Applications. | Nikolaos Karapanos, Alexandros Filios, Raluca Ada Popa, Srdjan Capkun |
| 2016 | Investigating Airplane Safety and Security Against Insider Threats Using Logical Modeling. | Florian Kammller, Manfred Kerber |
| 2016 | Cloak of Visibility: Detecting When Machines Browse a Different Web. | Luca Invernizzi, Kurt Thomas, Alexandros Kapravelos, Oxana Comanescu, Jean-Michel Picod, Elie Bursztein |
| 2016 | Data-Oriented Programming: On the Expressiveness of Non-control Data Attacks. | Hong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua, Prateek Saxena, Zhenkai Liang |
| 2016 | Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid Response. | Zhen Huang, Mariana D'Angelo, Dhaval Miyani, David Lie |
| 2016 | A Method for Verifying Privacy-Type Properties: The Unbounded Case. | Lucca Hirschi, David Baelde, Stphanie Delaune |
| 2016 | Cache Storage Channels: Alias-Driven Attacks and Verified Countermeasures. | Roberto Guanciale, Hamed Nemati, Christoph Baumann, Mads Dam |
| 2016 | On the Practicality of Cryptographically Enforcing Dynamic Access Control Policies in the Cloud. | William C. Garrison III, Adam Shull, Steven A. Myers, Adam J. Lee |
| 2016 | TriggerScope: Towards Detecting Logic Bombs in Android Applications. | Yanick Fratantonio, Antonio Bianchi, William K. Robertson, Engin Kirda, Christopher Kruegel, Giovanni Vigna |
| 2016 | Key Confirmation in Key Exchange: A Formal Treatment and Implications for TLS 1.3. | Marc Fischlin, Felix Gnther, Benedikt Schmidt, Bogdan Warinschi |
| 2016 | Research Report: Mitigating LangSec Problems with Capabilities. | Nathaniel Wesley Filardo |
| 2016 | Prepose: Privacy, Security, and Reliability for Gesture-Based Programming. | Lucas Silva Figueiredo, Benjamin Livshits, David Molnar, Margus Veanes |
| 2016 | Security Analysis of Emerging Smart Home Applications. | Earlence Fernandes, Jaeyeon Jung, Atul Prakash |
| 2016 | A Semi-Automated Methodology for Extracting Access Control Rules from the European Data Protection Directive. | Kaniz Fatema, Christophe Debruyne, Dave Lewis, Declan O'Sullivan, John P. Morrison, Abdullah-Al Mazed |
| 2016 | Caradoc: A Pragmatic Approach to PDF Parsing and Validation. | Guillaume Endignoux, Olivier Levillain, Jean-Yves Migeon |
| 2016 | From Privacy Impact Assessment to Social Impact Assessment. | Lilian Edwards, Derek McAuley, Laurence Diver |
| 2016 | Polymorphic Malware Detection Using Sequence Classification Methods. | Jake Drew, Tyler Moore, Michael Hahsler |
| 2016 | LAVA: Large-Scale Automated Vulnerability Addition. | Brendan Dolan-Gavitt, Patrick Hulin, Engin Kirda, Tim Leek, Andrea Mambretti, William K. Robertson, Frederick Ulrich, Ryan Whelan |
| 2016 | No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing Analysis. | Wenrui Diao, Xiangyu Liu, Zhou Li, Kehuan Zhang |
| 2016 | Privacy Harm Analysis: A Case Study on Smart Grids. | Sourya Joyee De, Daniel Le Mtayer |
| 2016 | Cinderella: Turning Shabby X.509 Certificates into Elegant Anonymous Credentials with the Magic of Verifiable Computation. | Antoine Delignat-Lavaud, Cdric Fournet, Markulf Kohlweiss, Bryan Parno |