VLDB 2026 Research / reviewers in the wild / expert
Christian Weinert
dblp:157/4432
· DBLP profile ↗
23ranked-venue papers
1as first author
11since 2021 · last 2026
0000-0003-4906-6871ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 1 first-author · 11 since 2021Artificial intelligence and machine learning · 2Software engineering, systems software and programming languages · 2Graphics, computer vision, multimedia, augmented reality and games · 2Systems, architecture and hardware · 1Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Outsourced Private Set Intersection
Sophie Hawkes, Christian Weinert |
ACNS (1) | 2 |
| 2025 | Concretely Efficient Private Set Union via Circuit-Based PSI
Gowri R. Chandran, Thomas Schneider 0003, Maximilian Stillger, Christian Weinert |
AsiaCCS | 4 |
| 2025 | On Algebraic Homomorphic Encryption and Its Applications to Doubly-Efficient PIR
Hiroki Okada 0001, Rachel Player, Simon Pohmann, Christian Weinert |
EUROCRYPT (6) | 4 |
| 2024 | Towards Practical Doubly-Efficient Private Information Retrieval
Hiroki Okada 0001, Rachel Player, Simon Pohmann, Christian Weinert |
FC (2) | 4 |
| 2023 | Scaling Mobile Private Contact Discovery to Billions of Users
Laura Hetz, Thomas Schneider 0003, Christian Weinert |
ESORICS (1) | 3 |
| 2023 | Contact Discovery in Mobile Messengers: Low-cost Attacks, Quantitative Analyses, and Efficient MitigationsabstractContact discovery allows users of mobile messengers to conveniently connect with people in their address book. In this work, we demonstrate that severe privacy issues exist in currently deployed contact discovery methods and propose suitable mitigations. Our study of three popular messengers (WhatsApp, Signal, and Telegram) shows that large-scale crawling attacks are (still) possible. Using an accurate database of mobile phone number prefixes and very few resources, we queried 10 % of US mobile phone numbers for WhatsApp and 100 % for Signal. For Telegram, we find that its API exposes a wide range of sensitive information, even about numbers not registered with the service. We present interesting (cross-messenger) usage statistics, which also reveal that very few users change the default privacy settings. Furthermore, we demonstrate that currently deployed hashing-based contact discovery protocols are severely broken by comparing three methods for efficient hash reversal. Most notably, we show that with the password cracking tool “JTR,” we can iterate through the entire worldwide mobile phone number space in < 150 s on a consumer-grade GPU. We also propose a significantly improved rainbow table construction for non-uniformly distributed input domains that is of independent interest. Regarding mitigations, we most notably propose two novel rate-limiting schemes: our incremental contact discovery for services without server-side contact storage strictly improves over Signal’s current approach while being compatible with private set intersection, whereas our differential scheme allows even stricter rate limits at the overhead for service providers to store a small constant-size state that does not reveal any contact information. Christoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko, Thomas Schneider 0003 |
ACM Trans. Priv. Secur. | 2 |
| 2021 | LLVM-Based Circuit Compilation for Practical Secure Computation
Tim Heldmann, Thomas Schneider 0003, Christian Weinert, Hossein Yalame |
ACNS (2) | 4 |
| 2021 | All the Numbers are US: Large-scale Abuse of Contact Discovery in Mobile Messengers
Christoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko, Thomas Schneider 0003 |
NDSS | 2 |
| 2021 | Improved Circuit Compilation for Hybrid MPC via Compiler Intermediate Representation
Daniel Demmler, Stefan Katzenbeisser 0001, Thomas Schneider 0003, Tom Schuster, Christian Weinert |
SECRYPT | 5 |
| 2021 | PrivateDrop: Practical Privacy-Preserving Authentication for Apple AirDrop
Alexander Heinrich, Matthias Hollick, Thomas Schneider 0003, Milan Stute, Christian Weinert |
USENIX Security Symposium | 5 |
| 2021 | AirCollect: efficiently recovering hashed phone numbers leaked via Apple AirDropabstractApple's file-sharing service AirDrop leaks phone numbers and email addresses by exchanging vulnerable hash values of the user's own contact identifiers during the authentication handshake with nearby devices. In a paper presented at USENIX Security'21, we theoretically describe two attacks to exploit these vulnerabilities and propose "PrivateDrop" as a privacy-preserving drop-in replacement for Apple's AirDrop protocol based on private set intersection. Alexander Heinrich, Matthias Hollick, Thomas Schneider 0003, Milan Stute, Christian Weinert |
WISEC | 5 |
| 2020 | RiCaSi: Rigorous Cache Side Channel Mitigation via Selective Circuit Compilation
Heiko Mantel, Lukas Scheidel, Thomas Schneider 0003, Alexandra Weber, Christian Weinert, Tim Weißmantel |
CANS | 5 |
| 2020 | Offline Model Guard: Secure and Private ML on Mobile DevicesabstractPerforming machine learning tasks in mobile applications yields a challenging conflict of interest: highly sensitive client information (e.g., speech data) should remain private while also the intellectual property of service providers (e.g., model parameters) must be protected. Cryptographic techniques offer secure solutions for this, but have an unacceptable overhead and moreover require frequent network interaction.In this work, we design a practically efficient hardware-based solution. Specifically, we build OFFLINE MODEL GUARD (OMG) to enable privacy-preserving machine learning on the predominant mobile computing platform ARM—even in offline scenarios. By leveraging a trusted execution environment for strict hardware-enforced isolation from other system components, OMG guarantees privacy of client data, secrecy of provided models, and integrity of processing algorithms. Our prototype implementation on an ARM HiKey 960 development board performs privacy-preserving keyword recognition using TensorFlow Lite for Microcontrollers in real time. Sebastian P. Bayerl, Tommaso Frassetto, Patrick Jauernig, Korbinian Riedhammer, Ahmad-Reza Sadeghi, Thomas Schneider 0003, Emmanuel Stapf, Christian Weinert |
DATE | 8 |
| 2020 | CryptoSPN: Privacy-Preserving Sum-Product Network InferenceabstractAI algorithms, and machine learning (ML) techniques in particular, are increasingly important to individuals' lives, but have caused a range of privacy concerns addressed by, e.g., the European GDPR. Using cryptographic techniques, it is possible to perform inference tasks remotely on sensitive client data in a privacy-preserving way: the server learns nothing about the input data and the model predictions, while the client learns nothing about the ML model (which is often considered intellectual property and might contain traces of sensitive data). While such privacy-preserving solutions are relatively efficient, they are mostly targeted at neural networks, can degrade the predictive accuracy, and usually reveal the network's topology. Furthermore, existing solutions are not readily accessible to ML experts, as prototype implementations are not well-integrated into ML frameworks and require extensive cryptographic knowledge. In this paper, we present CryptoSPN, a framework for privacy-preserving inference of sum-product networks (SPNs). SPNs are a tractable probabilistic graphical model that allows a range of exact inference queries in linear time. Specifically, we show how to efficiently perform SPN inference via secure multi-party computation (SMPC) without accuracy degradation while hiding sensitive client and training information with provable security guarantees. Next to foundations, CryptoSPN encompasses tools to easily transform existing SPNs into privacy-preserving executables. Our empirical results demonstrate that CryptoSPN achieves highly efficient and accurate inference in the order of seconds for medium-sized SPNs. Amos Treiber, Alejandro Molina 0001, Christian Weinert, Thomas Schneider 0003, Kristian Kersting |
ECAI | 3 |
| 2019 | Mobile Private Contact Discovery at Scale
Daniel Kales, Christian Rechberger, Thomas Schneider 0003, Matthias Senker, Christian Weinert |
USENIX Security Symposium | 5 |
| 2018 | Chameleon: A Hybrid Secure Computation Framework for Machine Learning ApplicationsabstractWe present Chameleon, a novel hybrid (mixed-protocol) framework for secure function evaluation (SFE) which enables two parties to jointly compute a function without disclosing their private inputs. Chameleon combines the best aspects of generic SFE protocols with the ones that are based upon additive secret sharing. In particular, the framework performs linear operations in the ring $\mathbbZ _2^l $ using additively secret shared values and nonlinear operations using Yao's Garbled Circuits or the Goldreich-Micali-Wigderson protocol. Chameleon departs from the common assumption of additive or linear secret sharing models where three or more parties need to communicate in the online phase: the framework allows two parties with private inputs to communicate in the online phase under the assumption of a third node generating correlated randomness in an offline phase. Almost all of the heavy cryptographic operations are precomputed in an offline phase which substantially reduces the communication overhead. Chameleon is both scalable and significantly more efficient than the ABY framework (NDSS'15) it is based on. Our framework supports signed fixed-point numbers. In particular, Chameleon's vector dot product of signed fixed-point numbers improves the efficiency of mining and classification of encrypted data for algorithms based upon heavy matrix multiplications. Our evaluation of Chameleon on a 5 layer convolutional deep neural network shows 133x and 4.2x faster executions than Microsoft CryptoNets (ICML'16) and MiniONN (CCS'17), respectively. M. Sadegh Riazi, Christian Weinert, Ebrahim M. Songhori, Thomas Schneider 0003, Farinaz Koushanfar |
AsiaCCS | 2 |
| 2018 | Large-Scale Privacy-Preserving Statistical Computations for Distributed Genome-Wide Association StudiesabstractWe present privacy-preserving solutions for Genome-Wide Association Studies (GWAS) based on Secure Multi-Party Computation (SMPC). Using SMPC, we protect the privacy of patients when medical institutes collaborate for computing statistics on genomic data in a distributed fashion. Previous solutions for this task lack efficiency and/or use inadequate algorithms that are of limited practical value. Concretely, we optimize and implement multiple algorithms for the χ^2 $-, G-, and P-test in the ABY framework (Demmler et al., NDSS»15) and evaluate them in a distributed GWAS scenario. Statistical tests generally require advanced mathematical operations. For operations that cannot be calculated in integer arithmetic, we make use of the existing IEEE 754 floating point arithmetic implementation in ABY (Demmler et al., CCS»15). To improve performance, we extend the mixed-protocol capabilities of ABY by optimizing and implementing the integer to floating point conversion protocols of Aliasgari et al.\ (NDSS»13), which may be of independent interest. Furthermore, we consider extended contingency tables for the χ^2$- and G-test that use codeword counts instead of counts for only two alleles, thereby allowing for advanced, realistic analyses. Finally, we consider an outsourcing scenario where two non-colluding semi-trusted third parties process secret-shared input data from multiple institutes. Our extensive evaluation shows, compared to the prior art of Constable et al.\ (BMC Medical Informatics and Decision Making»15), an improved run-time efficiency of the χ^2 $-test by up to factor 37x. We additionally demonstrate practicality in scenarios with millions of participants and hundreds of collaborating institutes. Christian Weinert, Thomas Schneider 0003, Kay Hamacher |
AsiaCCS | 2 |
| 2018 | Efficient Circuit-Based PSI via Cuckoo Hashing
Benny Pinkas, Thomas Schneider 0003, Christian Weinert, Udi Wieder |
EUROCRYPT (3) | 3 |
| 2018 | VoiceGuard: Secure and Private Speech ProcessingabstractWith the advent of smart-home devices providing voice-based interfaces, such as Amazon Alexa or Apple Siri, voice data is constantly transferred to cloud services for automated speech recognition or speaker verification.While this development enables intriguing new applications, it also poses significant risks: Voice data is highly sensitive since it contains biometric information of the speaker as well as the spoken words.This data may be abused if not protected properly, thus the security and privacy of billions of end-users is at stake.We tackle this challenge by proposing an architecture, dubbed VoiceGuard, that efficiently protects the speech processing task inside a trusted execution environment (TEE).Our solution preserves the privacy of users while at the same time it does not require the service provider to reveal model parameters.Our architecture can be extended to enable user-specific models, such as feature transformations (including fMLLR), i-vectors, or model transformations (e.g., custom output layers).It also generalizes to secure on-premise solutions, allowing vendors to securely ship their models to customers.We provide a proof-of-concept implementation and evaluate it on the Resource Management and WSJ speech recognition tasks isolated with Intel SGX, a widely available TEE implementation, demonstrating even real time processing capabilities. Ferdinand Brasser, Tommaso Frassetto, Korbinian Riedhammer, Ahmad-Reza Sadeghi, Thomas Schneider 0003, Christian Weinert |
INTERSPEECH | 6 |
| 2017 | MoPS: A Modular Protection Scheme for Long-Term StorageabstractCurrent trends in technology, such as cloud computing, allow outsourcing the storage, backup, and archiving of data. This provides efficiency and flexibility, but also poses new risks for data security. It in particular became crucial to develop protection schemes that ensure security even in the long-term, i.e. beyond the lifetime of keys, certificates, and cryptographic primitives. However, all current solutions fail to provide optimal performance for different application scenarios. Thus, in this work, we present MoPS, a modular protection scheme to ensure authenticity and integrity for data stored over long periods of time. MoPS does not come with any requirements regarding the storage architecture and can therefore be used together with existing archiving or storage systems. It supports a set of techniques which can be plugged together, combined, and migrated in order to create customized solutions that fulfill the requirements of different application scenarios in the best possible way. As a proof of concept we implemented MoPS and provide performance measurements. Furthermore, our implementation provides additional features, such as guidance for non-expert users and export functionalities for external verifiers. Christian Weinert, Denise Demirel, Martín Augusto Gagliotti Vigil, Matthias Geihs, Johannes Buchmann 0001 |
AsiaCCS | 1 |
| 2017 | CogniCrypt: supporting developers in using cryptographyabstractPrevious research suggests that developers often struggle using low-level cryptographic APIs and, as a result, produce insecure code. When asked, developers desire, among other things, more tool support to help them use such APIs. In this paper, we present CogniCrypt, a tool that supports developers with the use of cryptographic APIs. CogniCrypt assists the developer in two ways. First, for a number of common cryptographic tasks, CogniCrypt generates code that implements the respective task in a secure manner. Currently, CogniCrypt supports tasks such as data encryption, communication over secure channels, and long-term archiving. Second, CogniCrypt continuously runs static analyses in the background to ensure a secure integration of the generated code into the developer's workspace. This video demo showcases the main features of CogniCrypt: youtube.com/watch?v=JUq5mRHfAWY. Stefan Krüger, Sarah Nadi, Michael Reif, Karim Ali 0001, Mira Mezini, Eric Bodden, Florian Göpfert, Felix Günther 0001, Christian Weinert, Daniel Demmler, Ram Kamath |
ASE | 9 |
| 2015 | Integrity, authenticity, non-repudiation, and proof of existence for long-term archiving: A survey
Martín Augusto Gagliotti Vigil, Johannes Buchmann 0001, Daniel Cabarcas, Christian Weinert, Alexander Wiesmaier |
Comput. Secur. | 4 |
| 2014 | An efficient time-stamping solution for long-term digital archivingabstractLong-term archiving of digital data is necessary to meet many legal requirements. For example, hospitals in many countries must keep health records of patients for decades. Archiving usually relies on digital signatures and time-stamps to prove the security properties of archived data, such as integrity and proof of existence. Moreover, archived data often needs to be updated, e.g. a new prescription is added to a patient's record, but without compromising integrity and proof of existence. To date, a solution that guarantees integrity and proof of existence indefinitely and allows for updates on archived data is Content Integrity Service (CIS). In this paper, we introduce an improved version of CIS named Content Integrity Service with Skip Lists (CISS) that changes the time-stamping process of CIS by using two different types of time-stamps together with skip lists. We demonstrate that CISS outperforms CIS by analyzing the algorithms and running experiments in realistic scenarios. Martín Augusto Gagliotti Vigil, Christian Weinert, Denise Demirel, Johannes Buchmann 0001 |
IPCCC | 2 |