VLDB 2026 Research / reviewers in the wild / expert
Lukas Schmidt
dblp:207/7174
· DBLP profile ↗
5ranked-venue papers
2as first author
4since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Measuring Healthcare Data Leaks and Security Flaws at Internet ScaleabstractSystems that process medical data should be meticulously secured. Yet, network services in healthcare environments often fail to implement basic security measures. For example, previous studies showed that network segmentation flaws led to DICOM systems leaking millions of patient records. In addition to DICOM, healthcare facilities rely heavily on the HL7 and FHIR protocols to transmit data. For nine months, we operated a low-interaction honeypot for medical protocols. We found it was regularly scanned for DICOM but never for HL7 or FHIR, indicating that despite their widespread use and importance for patient data security, the security of these services remains underexplored. In this paper, we present the first large-scale study on HL7 and FHIR services and expand previous work on DICOM. Our large-scale Internet scans, covering the three major healthcare protocols across IPv4 and IPv6 address spaces, identify healthcare systems and uncover data leaks due to authentication flaws. Additionally, we scanned for deficiencies in TLS configurations of these services and known insecure healthcare software. In total, we found 2,841 healthcare services with authentication flaws. 94.4% of all exposed systems do not support transport encryption, and 1,373 systems have known software vulnerabilities, including those with potential for system takeover and CVSS scores up to 9.8. Overall, our study reveals an alarming state of cybersecurity in healthcare deployments, for which we discuss potential reasons and countermeasures. Finally, we report on the coordinated disclosure campaign we initiated to improve the security of patient data. Nico Brüggemann, Lukas Schmidt, Marvin Dölzer, Marius Brockhoff, Fabian Ising, Christoph Saatjohann, Sebastian Schinzel |
EuroS&P | 2 |
| 2025 | BreachHydra: Measuring the Resilience of an Underground Data Breach ForumabstractUnderground forums are thriving markets for illicit goods and services, such as data leaks. While these forums regularly come under the focus of criminal prosecution, often leading to platform shutdowns and the conviction of operators, successors emerge quickly. In this paper, we present a study of the underground forum BreachForums. BreachForums served as the successor to the popular RaidForums, survived several forum takedowns, and remained operational until June 2025. We perform the first public analysis of the leaked BreachForums database from 2022, and enrich our results with scraped data from the latest successor. This enables us to conduct a longitudinal study on the factors contributing to the forum’s resilience.We find that the operational security of forum users, particularly Key Users selling products and services, is generally strong, making their identification challenging. However, some users involved in data leak exchanges exhibit weak operational security, which may potentially allow law enforcement to track them. Moreover, our analysis reveals that takedown efforts have a limited impact on the availability of illegal data, as externally hosted leaks remain accessible and get reposted on successor platforms. We argue that law enforcement’s current focus on arresting forum operators seems insufficient, as new platforms continue to emerge. Marius Brockhoff, Lukas Schmidt, Fabian Ising, Sebastian Schinzel |
TrustCom | 2 |
| 2025 | Towards Automated and Robust Forensic Event ReconstructionabstractReconstructing past events in IT systems is a critical bottleneck in forensic investigations, consuming valuable time from investigators. It requires meticulous analysis of complex digital traces in an environment where attackers may try to erase traces. For example, deletion of digital artifacts is an anti-forensic technique used to jeopardize the success of forensic investigations.To address these challenges, we introduce Investigator Copilot, a novel framework that automates post-mortem event reconstruction using explainable machine learning. To overcome the general scarcity of datasets, Investigator Copilot replays realistic events on virtual machines, and creates datasets by extracting, normalizing and labeling traces from corresponding hard disks. Using these datasets, Investigator Copilot trains human-interpretable decision tree stumps that evaluate digital evidence and combines these binary classifiers in Forensic Forests. Forensic Forests utilize an adjusted voting scheme to provide robust event reconstruction even when faced with deleted evidence.We evaluate our approach by executing 2100 events on 50 virtual machines, training Forensic Forests and measuring their event reconstruction performance on previously unseen data. Our results demonstrate that tree-based classifiers perform exceedingly well in event reconstruction. When measuring reconstruction performance on manipulated evidence, we observe that Forensic Forests significantly outperform the state-of-the-art, which positions them as a valuable tool for investigators. Our findings indicate that automated frameworks such as Investigator Copilot can contribute to the efficiency and robustness of forensic analyses, and may save scarce resources of human investigators. Lukas Schmidt, Sebastian Schinzel |
TrustCom | 1 |
| 2025 | Don't get me wrong: How to apply deep visual interpretations to time series
Christoffer Löffler, Wei-Cheng Lai, Dario Zanca, Lukas Schmidt, Björn M. Eskofier, Christopher Mutschler |
Appl. Intell. | 4 |
| 2017 | TREM: a tool for mining timed regular specifications from system tracesabstractSoftware specifications are useful for software validation, model checking, runtime verification, debugging, monitoring, etc. In context of safety-critical real-time systems, temporal properties play an important role. However, temporal properties are rarely present due to the complexity and evolutionary nature of software systems. We propose Timed Regular Expression Mining (TREM) a hosted tool for specification mining using timed regular expressions (TREs). It is designed for easy and robust mining of dominant temporal properties. TREM uses an abstract structure of the property; the framework constructs a finite state machine to serve as an acceptor. TREM is scalable, easy to access/use, and platform independent specification mining framework. The tool is tested on industrial strength software system traces such as the QNX real-time operating system using traces with more than 1.5 Million entries. The tool demonstration video can be accessed here: youtu.be/cSd_aj3_LH8. Lukas Schmidt, Apurva Narayan, Sebastian Fischmeister |
ASE | 1 |