VLDB 2026 Research / reviewers in the wild / expert
Erik Derr
dblp:180/8205
· DBLP profile ↗
7ranked-venue papers
1as first author
0since 2021 · last 2020
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
5 papers |
Web and mobile security · 66% Systems and software security · 21% Privacy and data protection · 12% | |
| Software engineering, system software, and programming languages
5 papers |
Software maintenance and evolution · 50% Empirical software engineering · 28% Operating systems · 22% |
Topics — the 13 heaviest of 15, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Web and mobile security
mobile security |
0.5 | 2 | 2017 | Keep me Updated: An Empirical Study of Third-Party Library Updatability on Android · CCS 2017 Reliable Third-Party Library Detection in Android and its Security Applications · CCS 2016 |
Web and mobile security › mobile security
android security |
0.5 | 2 | 2016 | On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification Analysis · USENIX Security Symposium 2016 Reliable Third-Party Library Detection in Android and its Security Applications · CCS 2016 |
Systems and software security
vulnerability discovery |
0.4 | 2 | 2018 | The Rise of the Citizen Developer: Assessing the Security Impact of Online App Generators · IEEE Symposium on Security and Privacy 2018 Reliable Third-Party Library Detection in Android and its Security Applications · CCS 2016 |
Privacy and data protection
mobile app privacy |
0.4 | 1 | 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & Privacy · IEEE Symposium on Security and Privacy 2019 |
Web and mobile security
mobile application security |
0.3 | 1 | 2018 | The Rise of the Citizen Developer: Assessing the Security Impact of Online App Generators · IEEE Symposium on Security and Privacy 2018 |
Web and mobile security › mobile security
android application security |
0.3 | 1 | 2017 | Keep me Updated: An Empirical Study of Third-Party Library Updatability on Android · CCS 2017 |
Software maintenance and evolution › software ecosystems
dependency management |
0.3 | 1 | 2017 | Keep me Updated: An Empirical Study of Third-Party Library Updatability on Android · CCS 2017 |
Systems and software security › software supply chain security
third-party library detection |
0.2 | 1 | 2016 | Reliable Third-Party Library Detection in Android and its Security Applications · CCS 2016 |
Operating systems › system security › operating system security
access control |
0.2 | 1 | 2016 | On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification Analysis · USENIX Security Symposium 2016 |
Empirical software engineering
mining software repositories |
0.2 | 2 | 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & Privacy · IEEE Symposium on Security and Privacy 2019 Keep me Updated: An Empirical Study of Third-Party Library Updatability on Android · CCS 2017 |
Empirical software engineering › mining software repositories
app store mining |
0.1 | 1 | 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & Privacy · IEEE Symposium on Security and Privacy 2019 |
Software maintenance and evolution
software ecosystems |
0.1 | 1 | 2018 | The Rise of the Citizen Developer: Assessing the Security Impact of Online App Generators · IEEE Symposium on Security and Privacy 2018 |
Software maintenance and evolution › software ecosystems
dependencies and software ecosystems |
0.1 | 1 | 2016 | Reliable Third-Party Library Detection in Android and its Security Applications · CCS 2016 |
Methods — techniques the papers use, named apart from their topics
static code analysis · 0.8regression analysis · 0.8natural language processing · 0.8static analysis · 0.7fingerprinting · 0.7dynamic analysis · 0.7empirical study · 0.6permission specification analysis · 0.5library profiling · 0.5code obfuscation resilience · 0.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2020 | Up2Dep: Android Tool Support to Fix Insecure Code DependenciesabstractThird-party libraries, especially outdated versions, can introduce and multiply security & privacy related issues to Android applications. While prior work has shown the need for tool support for developers to avoid libraries with security problems, no such a solution has yet been brought forward to Android. It is unclear how such a solution would work and which challenges need to be solved in realizing it. Duc Cuong Nguyen 0001, Erik Derr, Michael Backes 0001, Sven Bugiel |
ACSAC | 2 |
| 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & PrivacyabstractApplication markets streamline the end-users' task of finding and installing applications. They also form an immediate communication channel between app developers and their end-users in form of app reviews, which allow users to provide developers feedback on their apps. However, it is unclear to which extent users employ this channel to point out their security and privacy concerns about apps, about which aspects of apps users express concerns, and how developers react to such security- and privacy-related reviews. In this paper, we present the first study of the relationship between end-user reviews and security- & privacy-related changes in apps. Using natural language processing on 4.5M user reviews for the top 2,583 apps in Google Play, we identified 5,527 security and privacy relevant reviews (SPR). For each app version mentioned in the SPR, we use static code analysis to extract permission-protected features mentioned in the reviews. We successfully mapped SPRs to privacy-related changes in app updates in 60.77% of all cases. Using exploratory data analysis and regression analysis we are able to show that preceding SPR are a significant factor for predicting privacy-related app updates, indicating that user reviews in fact lead to privacy improvements of apps. Our results further show that apps that adopt runtime permissions receive a significantly higher number of SPR, showing that runtime permissions put privacy-jeopardizing actions better into users' minds. Further, we can attribute about half of all privacy-relevant app changes exclusively to third-party library code. This hints at larger problems for app developers to adhere to users' privacy expectations and markets' privacy regulations. Our results make a call for action to make app behavior more transparent to users in order to leverage their reviews in creating incentives for developers to adhere to security and privacy best practices, while our results call at the same time for better tools to support app developers in this endeavor. Duc Cuong Nguyen 0001, Erik Derr, Michael Backes 0001, Sven Bugiel |
IEEE Symposium on Security and Privacy | 2 |
| 2018 | The Rise of the Citizen Developer: Assessing the Security Impact of Online App GeneratorsabstractMobile apps are increasingly created using online application generators (OAGs) that automate app development, distribution, and maintenance. These tools significantly lower the level of technical skill that is required for app development, which makes them particularly appealing to citizen developers, i.e., developers with little or no software engineering background. However, as the pervasiveness of these tools increases, so does their overall influence on the mobile ecosystem's security, as security lapses by such generators affect thousands of generated apps. The security of such generated apps, as well as their impact on the security of the overall app ecosystem, has not yet been investigated. We present the first comprehensive classification of commonly used OAGs for Android and show how to fingerprint uniquely generated apps to link them back to their generator. We thereby quantify the market penetration of these OAGs based on a corpus of 2,291,898 free Android apps from Google Play and discover that at least 11.1% of these apps were created using OAGs. Using a combination of dynamic, static, and manual analysis, we find that the services' app generation model is based on boilerplate code that is prone to reconfiguration attacks in 7/13 analyzed OAGs. Moreover, we show that this boilerplate code includes well-known security issues such as code injection vulnerabilities and insecure WebViews. Given the tight coupling of generated apps with their services' backends, we further identify security issues in their infrastructure. Due to the blackbox development approach, citizen developers are unaware of these hidden problems that ultimately put the end-users sensitive data and privacy at risk and violate the user's trust assumption. A particular worrisome result of our study is that OAGs indeed have a significant amplification factor for those vulnerabilities, notably harming the health of the overall mobile app ecosystem. Marten Oltrogge, Erik Derr, Christian Stransky, Yasemin Acar, Sascha Fahl, Christian Rossow, Giancarlo Pellegrino, Sven Bugiel, Michael Backes 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2017 | Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidabstractThird-party libraries in Android apps have repeatedly been shown to be hazards to the users' privacy and an amplification of their host apps' attack surface. A particularly aggravating factor to this situation is that the libraries' version included in apps are very often outdated. Erik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar, Michael Backes 0001 |
CCS | 1 |
| 2016 | Reliable Third-Party Library Detection in Android and its Security ApplicationsabstractThird-party libraries on Android have been shown to be security and privacy hazards by adding security vulnerabilities to their host apps or by misusing inherited access rights. Correctly attributing improper app behavior either to app or library developer code or isolating library code from their host apps would be highly desirable to mitigate these problems, but is impeded by the absence of a third-party library detection that is effective and reliable in spite of obfuscated code. This paper proposes a library detection technique that is resilient against common code obfuscations and that is capable of pinpointing the exact library version used in apps. Libraries are detected with profiles from a comprehensive library database that we generated from the original library SDKs. We apply our technique to the top apps on Google Play and their complete histories to conduct a longitudinal study of library usage and evolution in apps. Our results particularly show that app developers only slowly adapt new library versions, exposing their end-users to large windows of vulnerability. For instance, we discovered that two long-known security vulnerabilities in popular libs are still present in the current top apps. Moreover, we find that misuse of cryptographic APIs in advertising libs, which increases the host apps' attack surface, affects 296 top apps with a cumulative install base of 3.7bn devices according to Play. To the best of our knowledge, our work is first to quantify the security impact of third-party libs on the Android ecosystem. Michael Backes 0001, Sven Bugiel, Erik Derr |
CCS | 3 |
| 2016 | R-Droid: Leveraging Android App Analysis with Static Slice OptimizationabstractToday's feature-rich smartphone apps intensively rely on access to highly sensitive (personal) data. This puts the user's privacy at risk of being violated by overly curious apps or libraries (like advertisements). Central app markets conceptually represent a first line of defense against such invasions of the user's privacy, but unfortunately we are still lacking full support for automatic analysis of apps' internal data flows and supporting analysts in statically assessing apps' behavior. In this paper we present a novel slice-optimization approach to leverage static analysis of Android applications. Building on top of precise application lifecycle models, we employ a slicing-based analysis to generate data-dependent statements for arbitrary points of interest in an application. As a result of our optimization, the produced slices are, on average, 49% smaller than standard slices, thus facilitating code understanding and result validation by security analysts. Moreover, by re-targeting strings, our approach enables automatic assessments for a larger number of use-cases than prior work. We consolidate our improvements on statically analyzing Android apps into a tool called R-Droid and conducted a large-scale data-leak analysis on a set of 22,700 Android apps from Google Play. R-Droid managed to identify a significantly larger set of potential privacy-violating information flows than previous work, including 2,157 sensitive flows of password-flagged UI widgets in 256 distinct apps. Michael Backes 0001, Sven Bugiel, Erik Derr, Sebastian Gerling, Christian Hammer 0001 |
AsiaCCS | 3 |
| 2016 | On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification Analysis
Michael Backes 0001, Sven Bugiel, Erik Derr, Patrick D. McDaniel, Damien Octeau, Sebastian Weisgerber |
USENIX Security Symposium | 3 |