| 2011 | Verified Security for Browser Extensions. | Arjun Guha, Matthew Fredrikson, Benjamin Livshits, Nikhil Swamy |
| 2011 | RePriv: Re-imagining Content Personalization and In-browser Privacy. | Matthew Fredrikson, Benjamin Livshits |
| 2011 | Preventing Sybil Attacks by Privilege Attenuation: A Design Principle for Social Network Systems. | Philip W. L. Fong |
| 2011 | The Complexity of Intransitive Noninterference. | Sebastian Eggert, Ron van der Meyden, Henning Schnoor, Thomas Wilke |
| 2011 | Cryptography in the Web: The Case of Cryptographic Design Flaws in ASP.NET. | Thai Duong, Juliano Rizzo |
| 2011 | Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection. | Brendan Dolan-Gavitt, Tim Leek, Michael Zhivich, Jonathon T. Giffin, Wenke Lee |
| 2011 | "You Might Also Like: " Privacy Risks of Collaborative Filtering. | Joseph A. Calandrino, Ann Kilzer, Arvind Narayanan, Edward W. Felten, Vitaly Shmatikov |
| 2011 | OpenConflict: Preventing Real Time Map Hacks in Online Games. | Elie Bursztein, Mike Hamburg, Jocelyn Lagarenne, Dan Boneh |
| 2011 | The Failure of Noise-Based Non-continuous Audio Captchas. | Elie Bursztein, Romain Beauxis, Hristo S. Paskov, Daniele Perito, Celine Fabry, John C. Mitchell |
| 2011 | Mobile Security Catching Up? Revealing the Nuts and Bolts of the Security of Mobile Devices. | Michael Becher, Felix C. Freiling, Johannes Hoffmann, Thorsten Holz, Sebastian Uellenbeck, Christopher Wolf |
| 2011 | A Formalization of the Security Features of Physical Functions. | Frederik Armknecht, Roel Maes, Ahmad-Reza Sadeghi, Franois-Xavier Standaert, Christian Wachsmann |
| 2010 | A Practical Attack to De-anonymize Social Network Users. | Gilbert Wondracek, Thorsten Holz, Engin Kirda, Christopher Kruegel |
| 2010 | TaintScope: A Checksum-Aware Directed Fuzzing Tool for Automatic Software Vulnerability Detection. | Tielei Wang, Tao Wei, Guofei Gu, Wei Zou |
| 2010 | HyperSafe: A Lightweight Approach to Provide Lifetime Hypervisor Control-Flow Integrity. | Zhi Wang, Xuxian Jiang |
| 2010 | Tamper Evident Microprocessors. | Adam Waksman, Simha Sethumadhavan |
| 2010 | Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. | Robin Sommer, Vern Paxson |
| 2010 | On the Incoherencies in Web Browser Access Control Policies. | Kapil Singh, Alexander Moshchuk, Helen J. Wang, Wenke Lee |
| 2010 | All You Ever Wanted to Know about Dynamic Taint Analysis and Forward Symbolic Execution (but Might Have Been Afraid to Ask). | Edward J. Schwartz, Thanassis Avgerinos, David Brumley |
| 2010 | A Symbolic Execution Framework for JavaScript. | Prateek Saxena, Devdatta Akhawe, Steve Hanna, Feng Mao, Stephen McCamant, Dawn Song |
| 2010 | Towards Static Flow-Based Declassification for Legacy and Untrusted Programs. | Bruno P. S. Rocha, Sruthi Bandhakavi, Jerry den Hartog, William H. Winsborough, Sandro Etalle |
| 2010 | Investigation of Triangular Spamming: A Stealthy and Efficient Spamming Technique. | Zhiyun Qian, Zhuoqing Morley Mao, Yinglian Xie, Fang Yu |
| 2010 | Bootstrapping Trust in Commodity Computers. | Bryan Parno, Jonathan M. McCune, Adrian Perrig |
| 2010 | SCiFI - A System for Secure Face Identification. | Margarita Osadchy, Benny Pinkas, Ayman Jarrous, Boaz Moskovich |
| 2010 | Reflections on the 30th Anniversary of the IEEE Symposium on Security and Privacy. | Peter G. Neumann, Matt Bishop, Sean Peisert, Marv Schaefer |
| 2010 | Chip and PIN is Broken. | Steven J. Murdoch, Saar Drimer, Ross J. Anderson, Mike Bond |