VLDB 2026 Research / reviewers in the wild / expert
Erwin Quiring
dblp:149/3695
· DBLP profile ↗
15ranked-venue papers
6as first author
8since 2021 · last 2026
0009-0004-7170-1274ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 6 first-author · 7 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Chasing Shadows: Pitfalls in LLM Security Research
Jonathan Evertz, Niklas Risse, Nicolai Neuer, Andreas Müller 0025, Philipp Normann, Gaetano Sapia, Srishti Gupta 0004, Soumya Shaw, Devansh Srivastav, Christian Wressnegger, Erwin Quiring, Thorsten Eisenhofer, Daniel Arp, Lea Schönherr |
NDSS | 12 |
| 2025 | Black-Box Forgery Attacks on Semantic Watermarks for Diffusion ModelsabstractIntegrating watermarking into the generation process of latent diffusion models (LDMs) simplifies detection and attribution of generated content. Semantic watermarks, such as Tree-Rings and Gaussian Shading, represent a novel class of watermarking techniques that are easy to implement and highly robust against various perturbations. However, our work demonstrates a fundamental security vulnerability of semantic watermarks. We show that attackers can leverage unrelated models, even with different latent spaces and architectures (UNet vs DiT), to perform powerful and realistic forgery attacks. Specifically, we design two watermark forgery attacks. The first imprints a targeted watermark into real images by manipulating the latent representation of an arbitrary image in an unrelated LDM to get closer to the latent representation of a watermarked image. We also show that this technique can be used for watermark removal. The second attack generates new images with the target watermark by inverting a watermarked image and re-generating it with an arbitrary prompt. Both attacks just need a single reference image with the target watermark. Overall, our findings question the applicability of semantic watermarks by revealing that attackers can easily forge or remove these watermarks under realistic conditions.Github: https://github.com/and-mill/semantic-forgery Andreas Müller 0025, Denis Lukovnikov, Jonas Thietke, Asja Fischer, Erwin Quiring |
CVPR | 5 |
| 2025 | Intriguing Properties of Adversarial ML Attacks in the Problem Space [Extended Version]abstractRecent research efforts on adversarial machine learning (ML) have investigated problem-space attacks, focusing on the generation of real evasive objects in domains where, unlike images, there is no clear inverse mapping to the feature space (e.g., software). However, the design, comparison, and real-world implications of problem-space attacks remain underexplored. This article makes three major contributions. Firstly, we propose a general formalization for adversarial ML evasion attacks in the problem-space, which includes the definition of a comprehensive set of constraints on available transformations, preserved semantics, absent artifacts, and plausibility. We shed light on the relationship between feature space and problem space, and we introduce the concept of side-effect features as the by-product of the inverse feature-mapping problem. This enables us to define and prove necessary and sufficient conditions for the existence of problem-space attacks. Secondly, building on our general formalization, we propose a novel problem-space attack on Android malware that overcomes past limitations in terms of semantics and artifacts. We have tested our approach on a dataset with 150K Android apps from 2016 and 2018 which show the practical feasibility of evading a state-of-the-art malware classifier along with its hardened version. Thirdly, we explore the effectiveness of adversarial training as a possible approach to enforce robustness against adversarial samples, evaluating its effectiveness on the considered machine learning models under different scenarios. Our results demonstrate that “adversarial-malware as a service” is a realistic threat, as we automatically generate thousands of realistic and inconspicuous adversarial applications at scale, where on average it takes only a few minutes to generate an adversarial instance. Jacopo Cortellazzi, Erwin Quiring, Daniel Arp, Feargus Pendlebury, Fabio Pierazzi, Lorenzo Cavallaro |
ACM Trans. Priv. Secur. | 2 |
| 2024 | AI-Generated Faces in the Real World: A Large-Scale Case Study of Twitter Profile ImagesabstractRecent advances in the field of generative artificial intelligence (AI) have blurred the lines between authentic and machine-generated content, making it almost impossible for humans to distinguish between such media. One notable consequence is the use of AI-generated images for fake profiles on social media. While several types of disinformation campaigns and similar incidents have been reported in the past, a systematic analysis has been lacking. Jonas Ricker, Dennis Assenmacher, Thorsten Holz, Asja Fischer, Erwin Quiring |
RAID | 5 |
| 2024 | I still know it's you! On Challenges in Anonymizing Source CodeabstractThe source code of a program not only defines its semantics but also contains subtle clues that can identify its author. Several studies have shown that these clues can be automatically extracted using machine learning and allow for determining a program's author among hundreds of programmers. This attribution poses a significant threat to developers of anti-censorship and privacy-enhancing technologies, as they become identifiable and may be prosecuted. An ideal protection from this threat would be the anonymization of source code. However, neither theoretical nor practical principles of such an anonymization have been explored so far. In this paper, we tackle this problem and develop a framework for reasoning about code anonymization. We prove that the task of generating a 𝑘-anonymous program—a program that cannot be attributed to one of 𝑘 authors—is not computable in the general case. As a remedy, we introduce a relaxed concept called 𝑘-uncertainty, which enables us to measure the protection of developers. Based on this concept, we empirically study candidate techniques for anonymization, such as code normalization, coding style imitation, and code obfuscation. We find that none of the techniques provides sufficient protection when the attacker is aware of the anonymization. While we observe a notable reduction in attribution performance on real-world code, a reliable protection is not achieved for all developers. We conclude that code anonymization is a hard problem that requires further attention from the research community. Micha Horlboge, Erwin Quiring, Roland Meyer 0001, Konrad Rieck |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | On the Detection of Image-Scaling Attacks in Machine LearningabstractImage scaling is an integral part of machine learning and computer vision systems. Unfortunately, this preprocessing step is vulnerable to so-called image-scaling attacks where an attacker makes unnoticeable changes to an image so that it becomes a new image after scaling. This opens up new ways for attackers to control the prediction or to improve poisoning and backdoor attacks. While effective techniques exist to prevent scaling attacks, their detection has not been rigorously studied yet. Consequently, it is currently not possible to reliably spot these attacks in practice. Erwin Quiring, Andreas Müller 0025, Konrad Rieck |
ACSAC | 1 |
| 2023 | No more Reviewer #2: Subverting Automatic Paper-Reviewer Assignment using Adversarial Learning
Thorsten Eisenhofer, Erwin Quiring, Jonas Möller, Doreen Riepel, Thorsten Holz, Konrad Rieck |
USENIX Security Symposium | 2 |
| 2022 | Dos and Don'ts of Machine Learning in Computer Security
Daniel Arp, Erwin Quiring, Feargus Pendlebury, Alexander Warnecke, Fabio Pierazzi, Christian Wressnegger, Lorenzo Cavallaro, Konrad Rieck |
USENIX Security Symposium | 2 |
| 2020 | Adversarial Preprocessing: Understanding and Preventing Image-Scaling Attacks in Machine Learning
Erwin Quiring, David Klein 0001, Daniel Arp, Martin Johns, Konrad Rieck |
USENIX Security Symposium | 1 |
| 2019 | On the Security and Applicability of Fragile Camera Fingerprints
Erwin Quiring, Matthias Kirchner, Konrad Rieck |
ESORICS (1) | 1 |
| 2019 | Misleading Authorship Attribution of Source Code using Adversarial Learning
Erwin Quiring, Alwin Maier, Konrad Rieck |
USENIX Security Symposium | 1 |
| 2018 | Forgotten Siblings: Unifying Attacks on Machine Learning and Digital WatermarkingabstractMachine learning is increasingly used in securitycritical applications, such as autonomous driving, face recognition, and malware detection. Most learning methods, however, have not been designed with security in mind and thus are vulnerable to different types of attacks. This problem has motivated the research field of adversarial machine learning that is concerned with attacking and defending learning methods. Concurrently, a separate line of research has tackled a very similar problem: In digital watermarking, a pattern is embedded in a signal in the presence of an adversary. As a consequence, this research field has also extensively studied techniques for attacking and defending watermarking methods. The two research communities have worked in parallel so far, unnoticeably developing similar attack and defense strategies. This paper is a first effort to bring these communities together. To this end, we present a unified notation of blackbox attacks against machine learning and watermarking. To demonstrate its efficacy, we apply concepts from watermarking to machine learning and vice versa. We show that countermeasures from watermarking can mitigate recent model-extraction attacks and, similarly, that techniques for hardening machine learning can fend off oracle attacks against watermarks. We further demonstrate a novel threat for watermarking schemes based on recent deep learning attacks from adversarial learning. Our work provides a conceptual link between two research fields and thereby opens novel directions for improving the security of both, machine learning and digital watermarking. Erwin Quiring, Daniel Arp, Konrad Rieck |
EuroS&P | 1 |
| 2018 | Privacy-Enhanced Fraud Detection with Bloom Filters
Daniel Arp, Erwin Quiring, Tammo Krueger, Stanimir Dragiev, Konrad Rieck |
SecureComm (1) | 2 |
| 2017 | Privacy Threats through Ultrasonic Side Channels on Mobile DevicesabstractDevice tracking is a serious threat to the privacy of users, as it enables spying on their habits and activities. A recent practice embeds ultrasonic beacons in audio and tracks them using the microphone of mobile devices. This side channel allows an adversary to identify a user's current location, spy on her TV viewing habits or link together her different mobile devices. In this paper, we explore the capabilities, the current prevalence and technical limitations of this new tracking technique based on three commercial tracking solutions. To this end, we develop detection approaches for ultrasonic beacons and Android applications capable of processing these. Our findings confirm our privacy concerns: We spot ultrasonic beacons in various web media content and detect signals in 4 of 35 stores in two European cities that are used for location tracking. While we do not find ultrasonic beacons in TV streams from 7 countries, we spot 234 Android applications that are constantly listening for ultrasonic beacons in the background without the user's knowledge. Daniel Arp, Erwin Quiring, Christian Wressnegger, Konrad Rieck |
EuroS&P | 2 |
| 2014 | On the combination of randomized thresholds and non-parametric boundaries to protect digital watermarks against sensitivity attacksabstractWith unlimited access to a watermark detector, an attacker can use sensitivity attacks to remove the watermark of a digital medium. Randomized detectors and non-parametric decision boundaries are two ways of defending the watermark against these attacks. However, both approaches have their vulnerabilities when used individually. The first enables working with the randomized region boundary. The second still provides reliable information. This paper presents a combination of these two approaches to overcome their shortcomings. We develop a detector that has a randomized region with non-parametric outer boundaries. To empirically evaluate our combination, we apply two attack algorithms: Kalker's attack and Blind Newton Sensitivity Attack. The combination is more effective than the non-parametric boundary alone and comparable with using only the randomized threshold. In addition, we increase security by preventing attacks against the outer boundaries. Erwin Quiring, Pascal Schöttle |
IH&MMSec | 1 |