VLDB 2026 Research / reviewers in the wild / expert
Simon Birnbach
dblp:192/7553 · also Simon B. Birnbach
· DBLP profile ↗
14ranked-venue papers
4as first author
11since 2021 · last 2026
0000-0002-2275-7026ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 10 since 2021Computer networks · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VET Your Agent: Towards Host-Independent Autonomy via Verifiable Execution TracesabstractRecent advances in large language models (LLMs) have enabled a new generation of autonomous agents that operate over sustained periods and manage sensitive resources on behalf of users. Trusted for their ability to act without direct oversight, such agents are increasingly considered in high-stakes domains including financial management, dispute resolution, and governance. Yet in practice, agents execute on infrastructure controlled by a host, who can tamper with models, inputs, or outputs, undermining any meaningful notion of autonomy. We address this gap by introducing VET (Verifiable Execution Traces), a formal framework that achieves host-independent authentication of agent outputs and takes a step toward host-independent autonomy. Central to VET is the Agent Identity Document (AID), which specifies an agent's configuration together with the proof systems required for verification. VET is compositional: it supports multiple proof mechanisms, including trusted hardware, succinct cryptographic proofs, and notarized TLS transcripts (Web Proofs). We implement VET for an API-based LLM agent and evaluate our instantiation on realistic workloads. We find that for today's black-box, secret-bearing API calls, Web Proofs appear to be the most practical choice, with overhead typically under 3$\times$ compared to direct API calls, while for public API calls, a lower-overhead TEE Proxy is often sufficient. As a case study, we deploy a verifiable trading agent that produces proofs for each decision and composes Web Proofs with a TEE Proxy. Our results demonstrate that practical, host-agnostic authentication is already possible with current technology, laying the foundation for future systems that achieve full host-independent autonomy. Artem Grigor, Christian Schröder de Witt, Simon Birnbach, Ivan Martinovic |
AsiaCCS | 3 |
| 2026 | SideDish: Low-Cost Anti-Spoofing Countermeasure for Satellite Data CommunicationsabstractSatellite systems are increasingly vulnerable to spoofing attacks at the physical layer, where adversaries use inexpensive radio equipment to interfere with and replace legitimate signals. While cryptographic countermeasures are common in other wireless systems, their adoption in new space programs is slow due to concerns about the associated implications on robustness, cost, weight, power, and the challenges of updating existing systems. In this paper we introduce SideDish, a novel anti-spoofing countermeasure that combines a secondary receiver colocated at the satellite receiver with decoded signal comparison to detect out-of-beam unauthentic interference. The system is retrofittable into existing ground station deployments, cheap by using only low-cost components, and is robust against denial of service attacks. We verify this through simulations and real-world experiments that show SideDish spatially constraints attackers by between 70-99.84% in the angular domain, even considering scattering effects of the primary antenna. Targeting SideDish to deny service is not feasible within practical constraints, requiring microsecond-order timing accuracy to overcome. Edd Salkield, Louis-Emile Ploix, Martin Strohmeier, Sebastian Köhler 0005, Simon Birnbach, Ivan Martinovic |
WISEC | 5 |
| 2026 | SatIQ: Extensible and Stable Satellite Authentication using Hardware FingerprintingabstractAs satellite systems become a greater part of critical infrastructure, they have become a significantly more appealing target for attacks. The availability of cheap off-the-shelf radio hardware has made signal spoofing and physical layer attacks more accessible than ever to a wide range of adversaries, from hobbyists to nation-state actors. Legacy systems are particularly vulnerable due to their lack of cryptographic security, and cannot be patched to support novel security measures. In this article, we use radio transmitter fingerprinting to authenticate satellite downlinks, using characteristics of the transmitter hardware expressed as impairments on the physical layer radio signal. Our SatIQ system employs a Siamese neural network and an autoencoder to extract an efficient encoding of message headers that preserves identifying information. We focus on high sample rate fingerprinting, making device fingerprints difficult to forge without similarly high sample rate transmitting hardware. We collected 10290000 messages from the Iridium satellite constellation at 25 MS/s, and demonstrate that the SatIQ model trained on this data maintains performance over time without retraining, and can be used on new transmitters with no impact on performance. We analyze the system’s robustness against weather and signal factors, and demonstrate its effectiveness under attack, achieving an Equal Error Rate of 0.072 and ROC AUC of 0.960. We conclude that our techniques are useful for building fingerprinting systems that are effective at authenticating satellite communication, maintain performance over time and across satellite replacement, and provide robustness against spoofing and replay by raising the required budget for attacks. Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
ACM Trans. Priv. Secur. | 3 |
| 2025 | RingAuth: User Authentication Using a Smart Ring
Jack Sturgess, Simon Birnbach, Simon Eberz, Ivan Martinovic |
SECRYPT | 2 |
| 2025 | SpaceJam: Protocol-aware Jamming Attacks against Space CommunicationsabstractMotivated by the growing prevalence of increasingly advanced satellite jamming attacks, we introduce and systematically analyze protocol-aware jammers: the worst-case scenario that maximally exploits the protocol to deny service whilst remaining as difficult to detect as possible. This extends existing satellite jamming and anti-jamming literature, which to date considers only conventional jamming waveforms. We find that protocol-aware jammers are significantly more effective than conventional jammers against all major standardized satellite protocols, including when anti-jamming countermeasures in the form of interleaving and adaptive coding and modulation are employed. This performance is possible since current protocols have a cyclic and predictable nature. We assess the required capabilities in terms of synchronization, and show that many of these performance gains can be realized even by completely desynchronized jammers. We experimentally evaluate protocol-aware strategies against both a hardware and software receiver. The results show that over 15dB of performance gains over Gaussian jamming are possible against all tested satellite protocols. Furthermore, we find that the attack can be optimized in simulation and deployed against the hardware receiver without performance degradation. We conclude with a discussion of countermeasures, primarily at the protocol level, to improve the availability of these systems. Edd Salkield, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
WISEC | 3 |
| 2023 | Watch This Space: Securing Satellite Communication through Resilient Transmitter FingerprintingabstractDue to an increase in the availability of cheap off-the-shelf radio hardware, signal spoofing and replay attacks on satellite ground systems have become more accessible than ever. This is particularly a problem for legacy systems, many of which do not offer cryptographic security and cannot be patched to support novel security measures. Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
CCS | 3 |
| 2023 | BeeHIVE: Behavioral Biometric System Based on Object Interactions in Smart Environments
Klaudia Krawiecka, Simon Birnbach, Simon Eberz, Ivan Martinovic |
SECRYPT | 2 |
| 2023 | Satellite Spoofing from A to Z: On the Requirements of Satellite Downlink Overshadowing AttacksabstractSatellite communications are increasingly crucial for telecommunications, navigation, and Earth observation. However, many widely used satellites do not cryptographically secure the downlink, opening the door for radio spoofing attacks. Recent developments in software-defined radio hardware have enabled attacks on wireless systems including GNSS, which can be effectively spoofed using only cheap hardware available off the shelf. However, these conclusions do not generalize well to other satellite systems such as high data rate backhauls or satellite-to-customer connections, where the spoofing requirements are currently unknown. In this paper, we present a systematic review of spoofing attacks against satellite downlink communications systems. We establish a threat model linking attack feasibility and impact to required budget through real-world experiments and channel simulations. Our results show that nearly all evaluated satellite systems were overshadowable at a distance of 1 km in the worst case, for a budget of ~2000 USD or less. We evaluate how key challenges surrounding modulation schemes, antenna directionality, and legitimate satellite signal strength can be overcome in practice through antenna sidelobe targeting, overshadowing, and automatic gain control takeover. We also show that, surprisingly, protocols designed to be more robust against channel noise are significantly less robust against an overshadowing attacker. We conclude with a discussion of physical-layer countermeasures specifically applicable to satellite systems which can not be cryptographically upgraded. Edd Salkield, Marcell Szakály, Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
WISEC | 5 |
| 2022 | Haunted House: Physical Smart Home Event Verification in the Presence of Compromised SensorsabstractIn this article, we verify physical events using data from an ensemble of smart home sensors. This approach both protects against event sensor faults and sophisticated attackers. To validate our system’s performance, we set up a “smart home” in an office environment. We recognize 22 event types using 48 sensors over the course of two weeks. Using data from the physical sensors, we verify the event stream supplied by the event sensors to detect both masking and spoofing attacks. We consider three threat models: a zero-effort attacker, an opportunistic attacker, and a sensor-compromise attacker who can arbitrarily modify live sensor data. For spoofed events, we achieve perfect classification for 9 out of 22 events and achieve a 0% false alarm rate at a detection rate exceeding 99.9% for 15 events. For 11 events the majority of masking attacks can be detected without causing any false alarms. We also show that even a strong opportunistic attacker is inherently limited to spoofing few select events and that doing so involves lengthy waiting periods. Finally, we demonstrate the vulnerability of a single-classifier system to compromised sensor data and introduce a more secure approach based on sensor fusion. Simon Birnbach, Simon Eberz, Ivan Martinovic |
ACM Trans. Internet Things | 1 |
| 2021 | They See Me Rollin': Inherent Vulnerability of the Rolling Shutter in CMOS Image SensorsabstractIn this paper, we describe how the electronic rolling shutter in CMOS image sensors can be exploited using a bright, modulated light source (e.g., an inexpensive, off-the-shelf laser), to inject fine-grained image disruptions. We demonstrate the attack on seven different CMOS cameras, ranging from cheap IoT to semi-professional surveillance cameras, to highlight the wide applicability of the rolling shutter attack. We model the fundamental factors affecting a rolling shutter attack in an uncontrolled setting. We then perform an exhaustive evaluation of the attack’s effect on the task of object detection, investigating the effect of attack parameters. We validate our model against empirical data collected on two separate cameras, showing that by simply using information from the camera’s datasheet the adversary can accurately predict the injected distortion size and optimize their attack accordingly. We find that an adversary can hide up to 75% of objects perceived by state-of-the-art detectors by selecting appropriate attack parameters. We also investigate the stealthiness of the attack in comparison to a naïve camera blinding attack, showing that common image distortion metrics can not detect the attack presence. Therefore, we present a new, accurate and lightweight enhancement to the backbone network of an object detector to recognize rolling shutter attacks. Overall, our results indicate that rolling shutter attacks can substantially reduce the performance and reliability of vision-based intelligent systems. Sebastian Köhler 0005, Giulio Lovisotto, Simon Birnbach, Richard Baker 0008, Ivan Martinovic |
ACSAC | 3 |
| 2021 | #PrettyFlyForAWiFi: Real-world Detection of Privacy Invasion Attacks by DronesabstractDrones are becoming increasingly popular for hobbyists and recreational use. But with this surge in popularity comes increased risk to privacy as the technology makes it easy to spy on people in otherwise-private environments, such as an individual’s home. An attacker can fly a drone over fences and walls to observe the inside of a house, without having physical access. Existing drone detection systems require specialist hardware and expensive deployment efforts, making them inaccessible to the general public. In this work, we present a drone detection system that requires minimal prior configuration and uses inexpensive commercial off-the-shelf hardware to detect drones that are carrying out privacy invasion attacks. We use a model of the attack structure to derive statistical metrics for movement and proximity that are then applied to received communications between a drone and its controller. We test our system in real-world experiments with two popular consumer drone models mounting privacy invasion attacks using a range of flight patterns. We are able both to detect the presence of a drone and to identify which phase of the privacy attack was in progress while being resistant to false positives from other mobile transmitters. For line-of-sight approaches using our kurtosis-based method, we are able to detect all drones at a distance of 6 m, with the majority of approaches detected at 25 m or farther from the target window without suffering false positives for stationary or mobile non-drone transmitters. Simon Birnbach, Richard Baker 0008, Simon Eberz, Ivan Martinovic |
ACM Trans. Priv. Secur. | 1 |
| 2019 | Peeves: Physical Event Verification in Smart HomesabstractWith the rising availability of smart devices (e.g., smart thermostats, lights, locks, etc.), they are increasingly combined into "smart homes". A key component of smart homes are event sensors that report physical events (such as doors opening or the light turning on) which can be triggered automatically by the system or manually by the user. However, data from these sensors are not always trustworthy. Both faults in the event sensors and involvement of active attackers can lead to reporting of events that did not physically happen (event spoofing). This is particularly critical, as smart homes can trigger event chains (e.g., turning the radiator off when a window is opened) without involvement of the user. The goal of this paper is to verify physical events using data from an ensemble of sensors (such as accelerometers or air pressure sensors) that are commonly found in smart homes. This approach both protects against event sensor faults and sophisticated attackers. In order to validate our system's performance, we set up a "smart home" in an office environment. We recognize 22 event types using 48 sensors over the course of two weeks. Using data from the physical sensors, we verify the event stream supplied by the event sensors. We consider two threat models: a zero-effort attacker who spoofs events at arbitrary times and an opportunistic attacker who has access to a live stream of sensor data to better time their attack. We achieve perfect classification for 9 out of 22 events and achieve a 0% false alarm rate at a detection rate exceeding 99.9% for 15 events. We also show that even a strong opportunistic attacker is inherently limited to spoofing few select events and that doing so involves lengthy waiting periods. Simon Birnbach, Simon Eberz, Ivan Martinovic |
CCS | 1 |
| 2017 | Wi-Fly?: Detecting Privacy Invasion Attacks by Consumer Drones
Simon Birnbach, Richard Baker 0008, Ivan Martinovic |
NDSS | 1 |
| 2014 | Towards a statistical network calculus - Dealing with uncertainty in arrivalsabstractThe stochastic network calculus (SNC) has become an attractive methodology to derive probabilistic performance bounds. So far the SNC is based on (tacitly assumed) exact probabilistic assumptions about the arrival processes. Yet, in practice, these are only true approximately-at best. In many situations it is hard, if possible at all, to make such assumptions a priori. A more practical approach would be to base the SNC operations on measurements of the arrival processes (preferably even on-line). In this paper, we develop this idea and incorporate measurements into the framework of SNC taking the further uncertainty resulting from estimation errors into account. This is a crucial step towards a statistical network calculus (StatNC) eventually lending itself to a self-modelling operation of networks with a minimum of a priori assumptions. In numerical experiments, we are able to substantiate the novel opportunities by StatNC. Michael A. Beck, Sebastian A. Henningsen, Simon Birnbach, Jens B. Schmitt |
INFOCOM | 3 |