| 2016 | Algorithmic Transparency via Quantitative Input Influence: Theory and Experiments with Learning Systems. | Anupam Datta, Shayak Sen, Yair Zick |
| 2016 | DroidScribe: Classifying Android Malware Based on Runtime Behavior. | Santanu Kumar Dash, Guillermo Suarez-Tangil, Salahuddin J. Khan, Kimberly Tam, Mansour Ahmadi, Johannes Kinder, Lorenzo Cavallaro |
| 2016 | Browser History Stealing with Captive Wi-Fi Portals. | Adrian Dabrowski, Georg Merzdovnik, Nikolaus Kommenda, Edgar R. Weippl |
| 2016 | Grammatical Inference and Machine Learning Approaches to Post-Hoc LangSec. | Sheridan S. Curley, Richard E. Harang |
| 2016 | Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed Authentication. | Cas Cremers, Marko Horvat, Sam Scott, Thyla van der Merwe |
| 2016 | A Hybrid Framework for Data Loss Prevention and Detection. | Elisa Costante, Davide Fauri, Sandro Etalle, Jerry den Hartog, Nicola Zannone |
| 2016 | SoK: Verifiability Notions for E-Voting Protocols. | Vronique Cortier, David Galindo, Ralf Ksters, Johannes Mller, Tomasz Truderung |
| 2016 | Is Anybody Home? Inferring Activity From Smart Home Network Traffic. | Bogdan Copos, Karl N. Levitt, Matt Bishop, Jeff Rowe |
| 2016 | A Critical Analysis of Privacy Design Strategies. | Michael Colesky, Jaap-Henk Hoepman, Christiaan Hillen |
| 2016 | Following Devil's Footprints: Cross-Platform Analysis of Potentially Harmful Libraries on Android and iOS. | Kai Chen, Xueqiang Wang, Yi Chen, Peng Wang, Yeonjoon Lee, XiaoFeng Wang, Bin Ma, Aohui Wang, Yingjun Zhang, Wei Zou |
| 2016 | Shreds: Fine-Grained Execution Units with Private Memory. | Yaohui Chen, Sebassujeen Reymondjohnson, Zhichuang Sun, Long Lu |
| 2016 | Oblivious Mechanisms in Differential Privacy: Experiments, Conjectures, and Open Questions. | Chien-Lun Chen, Ranjan Pal, Leana Golubchik |
| 2016 | MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era. | Qi Alfred Chen, Eric Osterweil, Matthew Thomas, Zhuoqing Morley Mao |
| 2016 | Ecology-Based DoS Attack in Cognitive Radio Networks. | Shin-Ming Cheng, Pin-Yu Chen |
| 2016 | pASSWORD tYPOS and How to Correct Them Securely. | Rahul Chatterjee, Anish Athayle, Devdatta Akhawe, Ari Juels, Thomas Ristenpart |
| 2016 | Hold and Sign: A Novel Behavioral Biometrics for Smartphone User Authentication. | Attaullah Buriro, Bruno Crispo, Filippo Del Frari, Konrad S. Wrona |
| 2016 | Detection of Mobile Malware: An Artificial Immunity Approach. | James Brown, Mohd Anwar, Gerry V. Dozier |
| 2016 | Obstacles to Transparency in Privacy Engineering. | Kiel Brennan-Marquez, Daniel Susser |
| 2016 | Hunting Bugs with Lvy Flight Foraging. | Konstantin Bttinger |
| 2016 | Dedup Est Machina: Memory Deduplication as an Advanced Exploitation Vector. | Erik Bosman, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida |
| 2016 | Synthesizing Plausible Privacy-Preserving Location Traces. | Vincent Bindschaedler, Reza Shokri |
| 2016 | Downgrade Resilience in Key-Exchange Protocols. | Karthikeyan Bhargavan, Christina Brzuska, Cdric Fournet, Matthew Green, Markulf Kohlweiss, Santiago Zanella-Bguelin |
| 2016 | High-Speed Inter-Domain Fault Localization. | Cristina Basescu, Yue-Hsun Lin, Haoming Zhang, Adrian Perrig |
| 2016 | DataTags, Data Handling Policy Spaces and the Tags Language. | Michael Bar-Sinai, Latanya Sweeney, Merc Crosas |
| 2016 | Staying Secure and Unprepared: Understanding and Mitigating the Security Risks of Apple ZeroConf. | Xiaolong Bai, Luyi Xing, Nan Zhang, XiaoFeng Wang, Xiaojing Liao, Tongxin Li, Shi-Min Hu |