VLDB 2026 Research / reviewers in the wild / expert
Marc Röschlin
dblp:121/9557 · also Marc Roeschlin
· DBLP profile ↗
16ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0003-0519-9066ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 2 first-author · 7 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Finding Phones Fast: Low-Latency and Scalable Monitoring of Cellular Communications in Sensitive AreasabstractThe widespread availability of cellular devices introduces new threat vectors that allow users or attackers to bypass security policies and physical barriers and bring unauthorized devices into sensitive areas. These threats can arise from user non-compliance or deliberate actions aimed at data exfiltration/infiltration via hidden devices, drones, etc. We identify a critical gap in this context: the absence of low-latency systems for high-quality and instantaneous monitoring of cellular transmissions. Such low-latency systems are crucial to allow for timely detection, decision (e.g., geofencing or localization), and disruption of unauthorized communication in sensitive areas. Operator-based monitoring systems, built for purposes such as people counting or tracking, lack real-time capability, require cooperation across multiple operators, and thus are hard to deploy. Operator-independent monitoring approaches proposed in the literature either lack low-latency capabilities or do not scale. We propose WaveTag, the first low-latency, operator-independent, and scalable system designed to monitor 5G and LTE connections across all operators prior to any user data transmission. WaveTag consists of several downlink receivers and a distributed network of uplink receivers that measure both downlink protocol information and uplink signal characteristics at multiple locations to gain a detailed spatial image of uplink signals. WaveTag then aggregates the recorded information, processes it, and provides a decision about the connection before the UE completes connection establishment. To evaluate WaveTag, we deployed it in the context of geofencing, where WaveTag was able to determine whether the signals originate from inside or outside of an area within 2.3 ms of the initial base station-to-device message, therefore enabling prompt and targeted suppression of communication before any Martin Kotuliak, Simon Erni, Jakub Polák, Marc Röschlin, Richard Baker 0008, Ivan Martinovic, Srdjan Capkun |
WISEC | 4 |
| 2023 | EdgeTDC: On the Security of Time Difference of Arrival Measurements in CAN Bus Systems
Marc Röschlin, Giovanni Camurati, Pascal Brunner, Mridula Singh, Srdjan Capkun |
NDSS | 1 |
| 2022 | AdaptOver: adaptive overshadowing attacks in cellular networksabstractIn cellular networks, attacks on the communication link between a mobile device and the core network significantly impact privacy and availability. Up until now, fake base stations have been required to execute such attacks. Since they require a continuously high output power to attract victims, they are limited in range and can be easily detected both by operators and dedicated apps on users' smartphones. Simon Erni, Martin Kotuliak, Patrick Leu, Marc Röschlin, Srdjan Capkun |
MobiCom | 4 |
| 2022 | V-Range: Enabling Secure Ranging in 5G Wireless Networks
Mridula Singh, Marc Röschlin, Aanjhan Ranganathan, Srdjan Capkun |
NDSS | 2 |
| 2022 | LTrack: Stealthy Tracking of Mobile Phones in LTE
Martin Kotuliak, Simon Erni, Patrick Leu, Marc Röschlin, Srdjan Capkun |
USENIX Security Symposium | 4 |
| 2022 | Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging
Patrick Leu, Giovanni Camurati, Alexander Heinrich, Marc Röschlin, Claudio Anliker, Matthias Hollick, Srdjan Capkun, Jiska Classen |
USENIX Security Symposium | 4 |
| 2021 | Security of Multicarrier Time-of-Flight RangingabstractOFDM is a widely used modulation scheme. It transmits data over multiple subcarriers in parallel, which provides high resilience against frequency-dependent channel drops (fading) and achieves high throughput. Due to the proliferation of OFDM-enabled devices and the increasing need for location information, the research community has suggested using OFDM symbols for secure (time-of-flight) distance measurements. However, a consequence of relying on multiple subcarriers is long symbols (time-wise). This makes OFDM systems not a natural fit for secure ranging, as long symbols allow an attacker longer observation and reaction times to mount a so-called early-detect/late-commit attack. Despite these concerns, a recent standardization effort (IEEE 802.11az [5]) envisions the use of OFDM-based signals for secure ranging. This paper lays the groundwork for analyzing OFDM time-of-flight measurements and studies the security guarantees of OFDM-based ranging against a physical-layer attacker. We use BPSK and 4-QAM, the most robust configurations, as examples to present a strategy that increases the chances for early-detecting the transmitted symbols. Our theoretical analysis and simulations show that such OFDM systems are vulnerable to early-detection/late-commit attacks, irrespective of frame length and number of subcarriers. We identify the underlying causes and explore a possible countermeasure, consisting of orthogonal noise and randomized phase. Patrick Leu, Martin Kotuliak, Marc Röschlin, Srdjan Capkun |
ACSAC | 3 |
| 2021 | Security analysis of IEEE 802.15.4z/HRP UWB time-of-flight distance measurementabstractIEEE 802.15.4z, a standard for Ultra-Wide Band (UWB) secure distance measurement, was adopted in 2020 and the chips that implement this standard are already deployed in mobile phones and in the automotive industry (for Passive Keyless Entry and Start). The standard specifies two different modes---LRP and HRP. Whereas the security of LRP mode has been analyzed, there is no publicly available security analysis of the HRP mode, which is used in different chips like NXP Trimension SR150/SR040, Samsung smartphones, and U1 chip deployed in Apple iPhones. Mridula Singh, Marc Röschlin, Ezzat Zalzala, Patrick Leu, Srdjan Capkun |
WISEC | 2 |
| 2020 | Message Time of Arrival Codes: A Fundamental Primitive for Secure Distance MeasurementabstractSecure distance measurement and therefore secure Time-of-Arrival (ToA) measurement is critical for applications such as contactless payments, passive-keyless entry and start systems, and navigation systems. This paper initiates the study of Message Time of Arrival Codes (MTACs) and their security. MTACs represent a core primitive in the construction of systems for secure ToA measurement. By surfacing MTACs in this way, we are able for the first time to formally define the security requirements of physical-layer measures that protect ToA measurement systems against attacks. Our viewpoint also enables us to provide a unified presentation of existing MTACs (such as those proposed in distance-bounding protocols and in a secure distance measurement standard) and to propose basic principles for protecting ToA measurement systems against attacks that remain unaddressed by existing mechanisms. We also use our perspective to systematically explore the tradeoffs between security and performance that apply to all signal modulation techniques enabling ToA measurements. Patrick Leu, Mridula Singh, Marc Röschlin, Kenneth G. Paterson, Srdjan Capkun |
SP | 3 |
| 2019 | Analysis of Reflexive Eye Movements for Fast Replay-Resistant Biometric AuthenticationabstractEye tracking devices have recently become increasingly popular as an interface between people and cons-umer-grade electronic devices. Due to the fact that human eyes are fast, responsive, and carry information unique to an individual, analyzing person’s gaze is particularly attractive for rapid biometric authentication. Unfortunately, previous proposals for gaze-based authentication systems either suffer from high error rates or requires long authentication times. We build on the fact that some eye movements can be reflexively and predictably triggered and develop an interactive visual stimulus for elicitation of reflexive eye movements that support the extraction of reliable biometric features in a matter of seconds, without requiring any memorization or cognitive effort on the part of the user. As an important benefit, our stimulus can be made unique for every authentication attempt and thus incorporated in a challenge-response biometric authentication system. This allows us to prevent replay attacks, which are possibly the most applicable attack vectors against biometric authentication. Using a gaze tracking device, we build a prototype of our system and perform a series of systematic user experiments with 30 participants from the general public. We thoroughly analyze various system parameters and evaluate the performance and security guarantees under several different attack scenarios. The results show that our system matches or surpasses existing gaze-based authentication methods in achieved equal error rates (6.3%) while achieving significantly lower authentication times (5s). Ivo Sluganovic, Marc Röschlin, Kasper Bonne Rasmussen, Ivan Martinovic |
ACM Trans. Priv. Secur. | 2 |
| 2018 | Device Pairing at the Touch of an Electrode
Marc Röschlin, Ivan Martinovic, Kasper Bonne Rasmussen |
NDSS | 1 |
| 2017 | Broken Hearted: How To Attack ECG Biometrics
Simon Eberz, Nicola Paoletti, Marc Röschlin, Andrea Patanè, Marta Z. Kwiatkowska, Ivan Martinovic |
NDSS | 3 |
| 2017 | Pulse-Response: Exploring Human Body Impedance for Biometric RecognitionabstractBiometric characteristics are often used as a supplementary component in user authentication and identification schemes. Many biometric traits, both physiological and behavioral, offering a wider range of security and stability, have been explored. We propose a new physiological trait based on the human body’s electrical response to a square pulse signal, called pulse-response , and analyze how this biometric characteristic can be used to enhance security in the context of two example applications: (1) an additional authentication mechanism in PIN entry systems and (2) a means of continuous authentication on a secure terminal. The pulse-response biometric recognition is effective because each human body exhibits a unique response to a signal pulse applied at the palm of one hand and measured at the palm of the other. This identification mechanism integrates well with other established methods and could offer an additional layer of security, either on a continuous basis or at log-in time. We build a proof-of-concept prototype and perform experiments to assess the feasibility of pulse-response for biometric authentication. The results are very encouraging, achieving an equal error rate of 2% over a static dataset and 9% over a dataset with samples taken over several weeks. We also quantize resistance to attack by estimating individual worst-case probabilities for zero-effort impersonation in different experiments. Ivan Martinovic, Kasper Bonne Rasmussen, Marc Röschlin, Gene Tsudik |
ACM Trans. Priv. Secur. | 3 |
| 2016 | Using Reflexive Eye Movements for Fast Challenge-Response AuthenticationabstractEye tracking devices have recently become increasingly popular as an interface between people and consumer-grade electronic devices. Due to the fact that human eyes are fast, responsive, and carry information unique to an individual, analyzing person's gaze is particularly attractive for effortless biometric authentication. Unfortunately, previous proposals for gaze-based authentication systems either suffer from high error rates, or require long authentication times. Ivo Sluganovic, Marc Röschlin, Kasper Bonne Rasmussen, Ivan Martinovic |
CCS | 2 |
| 2015 | Misbehavior in Bitcoin: A Study of Double-Spending and AccountabilityabstractBitcoin is a decentralized payment system that relies on Proof-of-Work (PoW) to resist double-spending through a distributed timestamping service. To ensure the operation and security of Bitcoin, it is essential that all transactions and their order of execution are available to all Bitcoin users. Unavoidably, in such a setting, the security of transactions comes at odds with transaction privacy. Motivated by the fact that transaction confirmation in Bitcoin requires tens of minutes, we analyze the conditions for performing successful double-spending attacks against fast payments in Bitcoin, where the time between the exchange of currency and goods is short (in the order of a minute). We show that unless new detection techniques are integrated in the Bitcoin implementation, double-spending attacks on fast payments succeed with considerable probability and can be mounted at low cost. We propose a new and lightweight countermeasure that enables the detection of double-spending attacks in fast transactions. In light of such misbehavior, accountability becomes crucial. We show that in the specific case of Bitcoin, accountability complements privacy. To illustrate this tension, we provide accountability and privacy definition for Bitcoin, and we investigate analytically and empirically the privacy and accountability provisions in Bitcoin. Ghassan Karame, Elli Androulaki, Marc Röschlin, Arthur Gervais, Srdjan Capkun |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2014 | Authentication Using Pulse-Response Biometrics
Kasper Bonne Rasmussen, Marc Röschlin, Ivan Martinovic, Gene Tsudik |
NDSS | 2 |