VLDB 2026 Research / reviewers in the wild / expert
Marcel Busch
dblp:204/4058
· DBLP profile ↗
11ranked-venue papers
5as first author
8since 2021 · last 2026
0009-0007-6632-7355ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 5 first-author · 8 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SYSYPHUZZ: the Pressure of More Coverage
Zezhong Ren, Han Zheng 0006, Zhiyao Feng, Qinying Wang, Marcel Busch, Yuqing Zhang 0001, Chao Zhang 0008, Mathias Payer |
NDSS | 5 |
| 2026 | TÄMU: Emulating Trusted Applications at the (GlobalPlatform)-API Layer
Philipp Mao, Marcel Busch, Mathias Payer |
SP | 3 |
| 2025 | Hercules Droidot and the murder on the JNI Express
Luca Di Bartolomeo, Philipp Mao, Yu-Jye Tung, Jessy Ayala, Samuele Doria, Paolo Celada, Marcel Busch, Joshua Garcia, Eleonora Losiouk, Mathias Payer |
USENIX Security Symposium | 7 |
| 2025 | NASS: Fuzzing All Native Android System Services with Interface Awareness and Coverage
Philipp Mao, Marcel Busch, Mathias Payer |
USENIX Security Symposium | 2 |
| 2024 | Spill the TeA: An Empirical Study of Trusted Application Rollback Prevention on Android Smartphones
Marcel Busch, Philipp Mao, Mathias Payer |
USENIX Security Symposium | 1 |
| 2024 | GlobalConfusion: TrustZone Trusted Application 0-Days by Design
Marcel Busch, Philipp Mao, Mathias Payer |
USENIX Security Symposium | 1 |
| 2024 | EL3XIR: Fuzzing COTS Secure Monitors
Christian Lindenmeier, Mathias Payer, Marcel Busch |
USENIX Security Symposium | 3 |
| 2023 | TEEzz: Fuzzing Trusted Applications on COTS Android DevicesabstractSecurity and privacy-sensitive smartphone applications use trusted execution environments (TEEs) to protect sensitive operations from malicious code. By design, TEEs have privileged access to the entire system but expose little to no insight into their inner workings. Moreover, real-world TEEs enforce strict format and protocol interactions when communicating with trusted applications (TAs), which prohibits effective automated testing.TEEzz is the first TEE-aware fuzzing framework capable of effectively fuzzing TAs in situ on production smartphones, i.e., the TA runs in the encrypted and protected TEE and the fuzzer may only observe interactions with the TA but has no control over the TA’s code or data. Unlike traditional fuzzing techniques, which monitor the execution of a program being fuzzed and view its memory after a crash, TEEzz only requires a limited view of the target. TEEzz overcomes key limitations of TEE fuzzing (e.g., lack of visibility into the executed TAs, proprietary exchange formats, and value dependencies of interactions) by automatically attempting to infer the field types and message dependencies of the TA API through its interactions, designing state- and type-aware fuzzing mutators, and creating an in situ, on-device fuzzer.Due to the limited availability of systematic fuzzing research for TAs on commercial-off-the-shelf (COTS) Android devices, we extensively examine existing solutions, explore their limitations, and demonstrate how TEEzz improves the state-of-the-art. First, we show that general-purpose kernel driver fuzzers are ineffective for fuzzing TAs. Then, we establish a baseline for fuzzing TAs using a ground-truth experiment. We show that TEEzz outperforms other blackbox fuzzers, can improve greybox approaches (if TAs source code is available), and even outperforms greybox approaches for stateful targets. We found 13 previously unknown bugs in the latest versions of OPTEE TAs in total, out of which TEEzz is the only fuzzer to trigger three. We also ran TEEzz on popular phones and found 40 unique bugs for which one CVE was assigned so far. Marcel Busch, Aravind Machiry, Chad Spensky, Giovanni Vigna, Christopher Krügel, Mathias Payer |
SP | 1 |
| 2020 | Memory corruption attacks within Android TEEs: a case study based on OP-TEEabstractMany security-critical services on mobile devices rely on Trusted Execution Environments (TEEs). However, due to the proprietary and locked-down nature of TEEs, the available information about these systems is scarce. In recent years, we have witnessed several exploits targeting all major commercially used TEEs, which raises questions about the capabilities of TEEs to provide the expected integrity and confidentiality guarantees. In this paper, we evaluate the exploitability of TEEs by analyzing common flaws from the perspective of an adversary. We provide multiple vulnerable TEE applications for OP-TEE, a reference implementation for TEEs, and elaborate on the steps necessary for their exploitation on an Android system. Our vulnerable examples are inspired by real-world exploits seen in-the-wild on commercially used TEEs. With this work, we provide developers and researchers with introductory knowledge to realistically assess the capabilities of TEEs. For these purposes, we also make our examples publicly available. Fabian Fleischer 0001, Marcel Busch, Phillip Kuhrt |
ARES | 2 |
| 2020 | Make Remote Forensic Investigations Forensic Again: Increasing the Evidential Value of Remote Forensic Investigations
Marcel Busch, Florian Nicolai, Fabian Fleischer 0001, Christian Rückert, Christoph Safferling, Felix C. Freiling |
ICDF2C | 1 |
| 2017 | A Cloud-Based Compilation and Hardening Platform for Android AppsabstractSoftware piracy in general and repackaged apps with attached malware in particular pose serious threats for the Android ecosystem. In this paper, we present a cloud-compilation approach enabling sophisticated hardening of apps for non-rooted stock Android. Our design is based on off-device ahead-of-time compilation made possible by the Android Runtime (ART). Due to an installer-stub-based second-stage delivery, we stay compatible to established app store distribution processes. We argue with a significant gain in security for our approach, since an adversary's toolbox is usually aimed at exploiting the type-information-rich bytecode shipped with apps, which is stripped to a large extent and almost entirely useless for reverse engineering attacks. We confirm the gain in security by comparing the output of popular reverse engineering tools for original and stripped versions of 695 real-world apps in our test set. In average 81.5 % of an app's bytecode is no longer of use to reverse engineers. Complementing existing protection approaches, we propose a platform that can integrate bytecode-targeting protection solutions and offers binary-targeting hooks to incorporate advanced protection measures for ahead-of-time compiled apps. Our evaluation shows a negligible performance impact at runtime and demonstrates the approach's compatibility on our test set. Marcel Busch, Mykolai Protsenko, Tilo Müller |
ARES | 1 |