Christian Wressnegger

dblp:136/8406 · DBLP profile ↗
← Back
35ranked-venue papers
5as first author
20since 2021 · last 2026
0009-0007-1493-9552ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 27 · 5 first-author · 14 since 2021Artificial intelligence and machine learning · 5 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Chasing Shadows: Pitfalls in LLM Security Research
Jonathan Evertz, Niklas Risse, Nicolai Neuer, Andreas Müller 0025, Philipp Normann, Gaetano Sapia, Srishti Gupta 0004, Soumya Shaw, Devansh Srivastav, Christian Wressnegger, Erwin Quiring, Thorsten Eisenhofer, Daniel Arp, Lea Schönherr
NDSS11
2025 LeaX: Class-Focused Explanations for Locating Leakage in Learning-Based Profiling Attacks
Christian Wressnegger
ARES (2)2
2025 Two Sides of the Same Coin: Learning the Backdoor to Remove the Backdoor
abstract
The community has recently developed various training-time defenses to counter neural backdoors introduced through data poisoning. In light of the observation that a model learns poisonous samples responsible for the backdoor easier than benign samples, these approaches either use a fixed threshold of the training loss for splitting or iteratively learn a reference model as an oracle for identifying benign samples. In particular, the latter has proven effective for anti-backdoor learning. Our method, HARVEY, leverages a similar yet crucially different technique: learning an oracle for poisonous rather than benign samples. Learning a backdoored reference model is significantly easier than learning one on benign data. Consequently, we can identify poisonous samples much more accurately than related work identifies benign samples. This crucial difference enables near-perfect backdoor removal as we demonstrate in our evaluation. HARVEY substantially outperforms related approaches across attack types, datasets, and architectures, lowering the attack success rate to the very minimum at a negligible loss in natural accuracy.
Qi Zhao 0011, Christian Wressnegger
AAAI2
2025 Generalized Adversarial Code-Suggestions: Exploiting Contexts of LLM-based Code-Completion
Karl Rubel, Maximilian Noppel, Christian Wressnegger
AsiaCCS3
2025 Privacy from 5 PM to 6 AM: Tracking and Transparency Mechanisms in the HbbTV Ecosystem
abstract
Hybrid broadcast broadband television (HbbTV) is an evolving technology that connects linear TV with modern HTML5 applications, delivering extras like games, videos, and online shopping. However, its bidirectional transmission functionality raises privacy concerns, as it introduces new tracking methods for TV channels. While previous studies focused on security issues or user awareness of HbbTV privacy challenges, a detailed examination of the tracking and transparency mechanisms of the HbbTV ecosystem is still missing. This study fills this gap by extensively analyzing these features within the European HbbTV ecosystem, and in particular within German-language TV channels. We monitored more than 350 TV channels for over 400 hours, evaluating 1) prevalent HbbTV tracking methods, 2) consent notice prevalence and user interactions, and 3) privacy policy disclosures. Our findings indicate that the HbbTV tracking system operates independently of the Web, consent notices exploit system constraints to influence users, and privacy policies often do not align with actual data practices.
Christian Böttger, Henry Hosseini, Christine Utz, Nurullah Demir, Jan Hörnemann, Christian Wressnegger, Thomas Hupperich, Norbert Pohlmann, Matteo Große-Kampmann, Tobias Urban
DSN6
2025 DUMPLING: Fine-grained Differential JavaScript Engine Fuzzing
Liam Wachter, Julian Gremminger, Christian Wressnegger, Mathias Payer, Flavio Toffalini
NDSS3
2024 Model-Manipulation Attacks Against Black-Box Explanations
abstract
The research community has invested great efforts in developing explanation methods that can shed light on the inner workings of neural networks. Despite the availability of precise and fast, model-specific solutions ("white-box" explanations), practitioners often opt for model-agnostic approaches ("black-box" explanations). In this paper, we show that users must not rely on the faithfulness of black-box explanations even if requests verifiably originate from the model in question. We present Makrut, a model-manipulation attack against the popular model-agnostic, black-box explanation method LIME. Makrut exploits the discrepancy between soft and hard labels to mount different attacks. We (a) elicit uninformative explanations for the entire model, (b) "fairwash" an unfair model, that is, we hide the decisive features in the explanation, and (c) cause a specific explanation upon the presence of a trigger pattern implementing a neural backdoor. The feasibility of these attacks emphasizes the need for more trustworthy explanation methods.
Achyut Hegde, Maximilian Noppel, Christian Wressnegger
ACSAC3
2024 SoK: Explainable Machine Learning in Adversarial Environments
abstract
Modern deep learning methods have long been considered black boxes due to the lack of insights into their decision-making process. However, recent advances in explainable machine learning have turned the tables. Post-hoc explanation methods enable precise relevance attribution of input features for otherwise opaque models such as deep neural networks. This progression has raised expectations that these techniques can uncover attacks against learning-based systems such as adversarial examples or neural backdoors. Unfortunately, current methods are not robust against manipulations themselves. In this paper, we set out to systematize attacks against post-hoc explanation methods to lay the groundwork for developing more robust explainable machine learning. If explanation methods cannot be misled by an adversary, they can serve as an effective tool against attacks, marking a turning point in adversarial machine learning. We present a hierarchy of explanation-aware robustness notions and relate existing defenses to it. In doing so, we uncover synergies, research gaps, and future directions toward more reliable explanations robust against manipulations.
Maximilian Noppel, Christian Wressnegger
SP2
2024 A Large-Scale Study of Cookie Banner Interaction Tools and their Impact on Users' Privacy
abstract
Cookie notices (or cookie banners) are a popular mechanism for websites to provide (European) Internet users a tool to choose which cookies the site may set. Banner implementations range from merely providing information that a site uses cookies over offering the choice to accepting or denying all cookies to allowing fine-grained control of cookie usage. Users frequently get annoyed by the banner's pervasiveness as they interrupt ''natural'' browsing on the Web. As a remedy, different browser extensions have been developed to automate the interaction with cookie banners. In this work, we perform a large-scale measurement study comparing the effectiveness of extensions for ''cookie banner interaction.'' We configured the extensions to express different privacy choices (e.g., accepting all cookies, accepting functional cookies, or rejecting all cookies) to understand their capabilities to execute a user's preferences. The results show statistically significant differences in which cookies are set, how many of them are set, and which types are set---even for extensions that aim to implement the same cookie choice. Extensions for ''cookie banner interaction'' can effectively reduce the number of set cookies compared to no interaction with the banners. However, all extensions increase the tracking requests significantly except when rejecting all cookies.
Nurullah Demir, Tobias Urban, Norbert Pohlmann, Christian Wressnegger
Proc. Priv. Enhancing Technol.4
2023 Poster: Fooling XAI with Explanation-Aware Backdoors
abstract
The overabundance of learnable parameters in recent machine-learning models renders them inscrutable. Even their developers can not explain their exact inner workings anymore. For this reason, researchers have developed explanation algorithms to shed light on a model's decision-making process. Explanations identify the deciding factors for a model's decision. Therefore, much hope is set in explanations to solve problems like biases, spurious correlations, and more prominently attacks like neural backdoors.
Maximilian Noppel, Christian Wressnegger
CCS2
2023 Holistic Adversarially Robust Pruning
Qi Zhao 0011, Christian Wressnegger
ICLR2
2023 On the Similarity of Web Measurements Under Different Experimental Setups
Nurullah Demir, Jan Hörnemann, Matteo Große-Kampmann, Tobias Urban, Norbert Pohlmann, Thorsten Holz, Christian Wressnegger
IMC7
2023 Load-and-Act: Increasing Page Coverage of Web Applications
Nico Weidmann, Thomas Barber, Christian Wressnegger
ISC3
2023 Machine Unlearning of Features and Labels
Alexander Warnecke, Lukas Pirch, Christian Wressnegger, Konrad Rieck
NDSS3
2023 Disguising Attacks with Explanation-Aware Backdoors
abstract
Explainable machine learning holds great potential for analyzing and understanding learning-based systems. These methods can, however, be manipulated to present unfaithful explanations, giving rise to powerful and stealthy adversaries. In this paper, we demonstrate how to fully disguise the adversarial operation of a machine learning model. Similar to neural backdoors, we change the model’s prediction upon trigger presence but simultaneously fool an explanation method that is applied post-hoc for analysis. This enables an adversary to hide the presence of the trigger or point the explanation to entirely different portions of the input, throwing a red herring. We analyze different manifestations of these explanation-aware backdoors for gradient- and propagation-based explanation methods in the image domain, before we resume to conduct a red-herring attack against malware classification.
Maximilian Noppel, Lukas Peter, Christian Wressnegger
SP3
2023 Randomness is the Root of All Evil: More Reliable Evaluation of Deep Active Learning
abstract
Using deep neural networks for active learning (AL) poses significant challenges for the stability and the reproducibility of experimental results. Inconsistent settings continue to be the root causes for contradictory conclusions and in worst cases, for incorrect appraisal of methods. Our community is in search of a unified framework for exhaustive and fair evaluation of deep active learning. In this paper, we provide just such a framework, one which is built upon systematically fixing, containing and interpreting sources of randomness. We isolate different influence factors, such as neural-network initialization or hardware specifics, to assess their impact on the learning performance. We then use our framework to analyze the effects of basic AL settings, such as the query-batch size and the use of subset selection, and different datasets on AL performance. Our findings enable us to derive specific recommendations for the reliable evaluation of deep active learning, thus helping advance the community toward a more normative evaluation of results.
Yilin Ji, Daniel Kästner, Oliver Wirth, Christian Wressnegger
WACV4
2022 to Protect the Public Opinion Against New Types of Bots?
abstract
Automated accounts affect political discourse in online social networks and therefore pose a threat to public opinion. They manipulate the regular flow of discussions by, for example, spreading false news, polluting content, or changing the popularity of users/content. Meanwhile, 56% of online social network users express concern about online false news. Therefore, reliable detection of automated accounts, among other things, is crucial for protecting political discourse in our society. However, the task is complex and challenging. Recent studies show that state-of-the-art bot detection algorithms have severe generalization problems.In this paper, we study features for reliable generalized identification of bot behavior on Twitter. Therefore, we propose an ensemble model that combines multiple neural network architectures. In a preprocessing step, we vectorize tweet texts using BERTweet. Exploiting behavioral features, the model then uncovers patterns in the metadata via a feed-forward and a convolutional component and incorporates the vectorized tweet texts via a recurrent unit. Extensive Leave-One-Botnet-Out (LOBO) evaluations on 20 real-world bot data sets show state-of-the-art performance in all experiments and outperform related approaches in average and peak performance.
Jan Reubold, Stephan Escher, Christian Wressnegger, Thorsten Strufe
IEEE Big Data3
2022 Dos and Don'ts of Machine Learning in Computer Security
Daniel Arp, Erwin Quiring, Feargus Pendlebury, Alexander Warnecke, Fabio Pierazzi, Christian Wressnegger, Lorenzo Cavallaro, Konrad Rieck
USENIX Security Symposium6
2022 Reproducibility and Replicability of Web Measurement Studies
abstract
Web measurement studies can shed light on not yet fully understood phenomena and thus are essential for analyzing how the modern Web works. This often requires building new and adjusting existing crawling setups, which has led to a wide variety of analysis tools for different (but related) aspects. If these efforts are not sufficiently documented, the reproducibility and replicability of the measurements may suffer—two properties that are crucial to sustainable research. In this paper, we survey 117 recent research papers to derive best practices for Web-based measurement studies and specify criteria that need to be met in practice. When applying these criteria to the surveyed papers, we find that the experimental setup and other aspects essential to reproducing and replicating results are often missing. We underline the criticality of this finding by performing a large-scale Web measurement study on 4.5 million pages with 24 different measurement setups to demonstrate the influence of the individual criteria. Our experiments show that slight differences in the experimental setup directly affect the overall results and must be documented accurately and carefully.
Nurullah Demir, Matteo Große-Kampmann, Tobias Urban, Christian Wressnegger, Thorsten Holz, Norbert Pohlmann
WWW4
2021 LaserShark: Establishing Fast, Bidirectional Communication into Air-Gapped Systems
abstract
Physical isolation, so called air-gapping, is an effective method for protecting security-critical computers and networks. While it might be possible to introduce malicious code through the supply chain, insider attacks, or social engineering, communicating with the outside world is prevented. Different approaches to breach this essential line of defense have been developed based on electromagnetic, acoustic, and optical communication channels. However, all of these approaches are limited in either data rate or distance, and frequently offer only exfiltration of data. We present a novel approach to infiltrate data to air-gapped systems without any additional hardware on-site. By aiming lasers at already built-in LEDs and recording their response, we are the first to enable a long-distance (25 m), bidirectional, and fast (18.2 kbps in & 100 kbps out) covert communication channel. The approach can be used against any office device that operates LEDs at the CPU’s GPIO interface.
Niclas Kühnapfel, Stefan Preußler, Maximilian Noppel, Konrad Rieck, Christian Wressnegger
ACSAC6
2020 Evaluating Explanation Methods for Deep Learning in Security
abstract
Deep learning is increasingly used as a building block of security systems. Unfortunately, neural networks are hard to interpret and typically opaque to the practitioner. The machine learning community has started to address this problem by developing methods for explaining the predictions of neural networks. While several of these approaches have been successfully applied in the area of computer vision, their application in security has received little attention so far. It is an open question which explanation methods are appropriate for computer security and what requirements they need to satisfy. In this paper, we introduce criteria for comparing and evaluating explanation methods in the context of computer security. These cover general properties, such as the accuracy of explanations, as well as security-focused aspects, such as the completeness, efficiency, and robustness. Based on our criteria, we investigate six popular explanation methods and assess their utility in security systems for malware detection and vulnerability discovery. We observe significant differences between the methods and build on these to derive general recommendations for selecting and applying explanation methods in computer security.
Alexander Warnecke, Daniel Arp, Christian Wressnegger, Konrad Rieck
EuroS&P3
2019 Thieves in the Browser: Web-based Cryptojacking in the Wild
abstract
With the introduction of memory-bound cryptocurrencies, such as Monero, the implementation of mining code in browser-based JavaScript has become a worthwhile alternative to dedicated mining rigs. Based on this technology, a new form of parasitic computing, widely called cryptojacking or drive-by mining, has gained momentum in the web. A cryptojacking site abuses the computing resources of its visitors to covertly mine for cryptocurrencies. In this paper, we systematically explore this phenomenon. For this, we propose a 3-phase analysis approach, which enables us to identify mining scripts and conduct a large-scale study on the prevalence of cryptojacking in the Alexa 1 million websites. We find that cryptojacking is common, with currently 1 out of 500 sites hosting a mining script. Moreover, we perform several secondary analyses to gain insight into the cryptojacking landscape, including a measurement of code characteristics, an estimate of expected mining revenue, and an evaluation of current blacklist-based countermeasures.
Marius Musch, Christian Wressnegger, Martin Johns, Konrad Rieck
ARES2
2019 TypeMiner: Recovering Types in Binary Programs Using Machine Learning
Alwin Maier, Hugo Gascon, Christian Wressnegger, Konrad Rieck
DIMVA3
2019 New Kid on the Web: A Study on the Prevalence of WebAssembly in the Wild
Marius Musch, Christian Wressnegger, Martin Johns, Konrad Rieck
DIMVA2
2019 False Sense of Security: A Study on the Effectivity of Jailbreak Detection in Banking Apps
abstract
People increasingly rely on mobile devices for banking transactions or two-factor authentication (2FA) and thus trust in the security provided by the underlying operating system. Simultaneously, jailbreaks gain tremendous popularity among regular users for customizing their devices. In this paper, we show that both do not go well together: Jailbreaks remove vital security mechanisms, which are necessary to ensure a trusted environment that allows to protect sensitive data, such as login credentials and transaction numbers (TANs). We find that all but one banking app, available in the iOS App Store, can be fully compromised by trivial means without reverse-engineering, manipulating the app, or other sophisticated attacks. Even worse, 44% of the banking apps do not even try to detect jailbreaks, revealing the prevalent, errant trust in the operating system's security. This study assesses the current state of security of banking apps and pleads for more advanced defensive measures for protecting user data.
Ansgar Kellner, Micha Horlboge, Konrad Rieck, Christian Wressnegger
EuroS&P4
2018 ZOE: Content-Based Anomaly Detection for Industrial Control Systems
abstract
Due its complexity and a multitude of proprietary components, industrial control systems are an immanently difficult field of application for intrusion detection. Proprietary binary protocols and the lack of public specifications have forced the research community to move away from content-based detection to more abstract concepts. In this paper, we show that in contrast to prior belief the content of unknown binary protocols can very well be modeled. ZOE derives prototype models that are specific to individual types of messages in order to capture the characteristics of arbitrary binary protocols and enable detecting different forms of attacks as anomalies. In an evaluation based on 6 days of network traffic recorded at a large power plant (1,900 MW) with over 92,000 unique devices, we demonstrate that ZOE improves upon related approaches by up to an order of magnitude in detection performance, but also significantly decreases false positives.
Christian Wressnegger, Ansgar Kellner, Konrad Rieck
DSN1
2017 Automatically Inferring Malware Signatures for Anti-Virus Assisted Attacks
abstract
Although anti-virus software has significantly evolved over the last decade, classic signature matching based on byte patterns is still a prevalent concept for identifying security threats. Anti-virus signatures are a simple and fast detection mechanism that can complement more sophisticated analysis strategies. However, if signatures are not designed with care, they can turn from a defensive mechanism into an instrument of attack. In this paper, we present a novel method for automatically deriving signatures from anti-virus software and discuss how the extracted signatures can be used to attack sensible data with the aid of the virus scanner itself. To this end, we study the practicability of our approach using four commercial products and exemplary demonstrate anti-virus assisted attacks in three different scenarios.
Christian Wressnegger, Kevin Freeman, Fabian Yamaguchi, Konrad Rieck
AsiaCCS1
2017 Privacy Threats through Ultrasonic Side Channels on Mobile Devices
abstract
Device tracking is a serious threat to the privacy of users, as it enables spying on their habits and activities. A recent practice embeds ultrasonic beacons in audio and tracks them using the microphone of mobile devices. This side channel allows an adversary to identify a user's current location, spy on her TV viewing habits or link together her different mobile devices. In this paper, we explore the capabilities, the current prevalence and technical limitations of this new tracking technique based on three commercial tracking solutions. To this end, we develop detection approaches for ultrasonic beacons and Android applications capable of processing these. Our findings confirm our privacy concerns: We spot ultrasonic beacons in various web media content and detect signals in 4 of 35 stores in two European cities that are used for location tracking. While we do not find ultrasonic beacons in TV streams from 7 countries, we spot 234 Android applications that are constantly listening for ultrasonic beacons in the background without the user's knowledge.
Daniel Arp, Erwin Quiring, Christian Wressnegger, Konrad Rieck
EuroS&P3
2016 Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit Platforms
abstract
Subtle flaws in integer computations are a prime source for exploitable vulnerabilities in system code. Unfortunately, even code shown to be secure on one platform can be vulnerable on another, making the migration of code a notable security challenge. In this paper, we provide the first study on how code that works as expected on 32-bit platforms can become vulnerable on 64-bit platforms. To this end, we systematically review the effects of data model changes between platforms. We find that the larger width of integer types and the increased amount of addressable memory introduce previously non-existent vulnerabilities that often lie dormant in program code. We empirically evaluate the prevalence of these flaws on the source code of Debian stable ("Jessie") and 200 popular open-source projects hosted on GitHub. Moreover, we discuss 64-bit migration vulnerabilities that have been discovered as part of our study, including vulnerabilities in Chromium, the Boost C++ Libraries, libarchive, the Linux Kernel, and zlib.
Christian Wressnegger, Fabian Yamaguchi, Alwin Maier, Konrad Rieck
CCS1
2016 Comprehensive Analysis and Detection of Flash-Based Malware
Christian Wressnegger, Fabian Yamaguchi, Daniel Arp, Konrad Rieck
DIMVA1
2016 Harry: A Tool for Measuring String Similarity
abstract
Comparing strings and assessing their similarity is a basic operation in many application domains of machine learning, such as in information retrieval, natural language processing and bioinformatics. The practitioner can choose from a large variety of available similarity measures for this task, each emphasizing different aspects of the string data. In this article, we present Harry, a small tool specifically designed for measuring the similarity of strings. Harry implements over 20 similarity measures, including common string distances and string kernels, such as the Levenshtein distance and the Subsequence kernel. The tool has been designed with efficiency in mind and allows for multi-threaded as well as distributed computing, enabling the analysis of large data sets of strings. Harry supports common data formats and thus can interface with analysis environments, such as Matlab, Pylab and Weka.
Konrad Rieck, Christian Wressnegger
J. Mach. Learn. Res.2
2015 Pulsar: Stateful Black-Box Fuzzing of Proprietary Network Protocols
Hugo Gascon, Christian Wressnegger, Fabian Yamaguchi, Daniel Arp, Konrad Rieck
SecureComm2
2013 Chucky: exposing missing checks in source code for vulnerability discovery
abstract
Uncovering security vulnerabilities in software is a key for operating secure systems. Unfortunately, only some security flaws can be detected automatically and the vast majority of vulnerabilities is still identified by tedious auditing of source code. In this paper, we strive to improve this situation by accelerating the process of manual auditing. We introduce Chucky, a method to expose missing checks in source code. Many vulnerabilities result from insufficient input validation and thus omitted or false checks provide valuable clues for finding security flaws. Our method proceeds by statically tainting source code and identifying anomalous or missing conditions linked to security-critical objects.In an empirical evaluation with five popular open-source projects, Chucky is able to accurately identify artificial and real missing checks, which ultimately enables us to uncover 12 previously unknown vulnerabilities in two of the projects (Pidgin and LibTIFF).
Fabian Yamaguchi, Christian Wressnegger, Hugo Gascon, Konrad Rieck
CCS2
2013 Deobfuscating Embedded Malware Using Probable-Plaintext Attacks
Christian Wressnegger, Frank Boldewin, Konrad Rieck
RAID1
2012 Sally: a tool for embedding strings in vector spaces
Konrad Rieck, Christian Wressnegger, Alexander Bikadorov
J. Mach. Learn. Res.2