VLDB 2026 Research / reviewers in the wild / expert
Andreas Finkenzeller
dblp:229/0082
· DBLP profile ↗
10ranked-venue papers
5as first author
10since 2021 · last 2025
0000-0003-3866-3769ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 2 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Sensor Fusion Desynchronization AttacksabstractEnvironmental perception and 3D object detection are key factors for advancing autonomous driving and require robust security measures to ensure optimal performance and safety. However, established methods often focus only on protecting the involved data and overlook synchronization and timing aspects, which are equally crucial for ensuring profound system security. For instance, multi-modal sensor fusion techniques for object detection can be affected by input desynchronization resulting from random communication delays or malicious cyber attacks, as these techniques combine various sensor inputs to extract shared features present in their data streams simultaneously. Current research acknowledges the importance of temporal alignment in this context. However, the presented studies typically assume genuine system behavior and neglect the potential threat of malicious attacks, as the suggested solutions lack strategies to prevent intentional data misalignment. Additionally, they do not adequately address how sensor input desynchronization affects fusion performance in depth. This paper investigates how desynchronization attacks impact sensor fusion algorithms for 3D object detection. We evaluate how varying sensor delays affect the detection performance and link our findings to the internal architecture of the sensor fusion algorithms and the influence of specific traffic scenarios and their dynamics. We compiled four datasets covering typical traffic scenarios for our empirical evaluation and tested them on four representative fusion algorithms. Our results show that all evaluated algorithms are vulnerable to input desynchronization, as the performance declines with increasing sensor delays, highlighting the existing lack of resilience to desynchronization attacks. Furthermore, we observe that the Light Detection and Ranging (LiDAR) sensor is significantly more susceptible to delays than the camera. Finally, our experiments indicate that the chosen fusion architecture correlates with the system’s resilience against desynchronization, as our results demonstrate that the early fusion approach provides greater robustness than others. Andreas Finkenzeller, Andrew Roberts, Mauro Bellone, Olaf Maennel, Mohammad Hamad, Sebastian Steinhorst |
ECRTS | 1 |
| 2025 | Flexpoch: Feature-rich 64-bit DateTime EncodingabstractThe 32-bit Unix time, which is commonly used in computer systems, will overflow on 2038-01-19. Extending the format to 64 bit would allow to count seconds for 584 billion years but misses the opportunity to add features, such as sub-second precision or relative time encoding, which are useful for a universal datetime encoding.We propose and implement Flexpoch, a versatile 64-bit time encoding that is compatible with Unix time, has a high range of 21 thousand years, supports leap seconds and timezone offsets, and offers multiple precisions from 119 ns to millennia while being highly resource-efficient. Emanuel Regnath, Andreas Finkenzeller, Sebastian Steinhorst |
FDL | 2 |
| 2025 | Janus: Fast Privacy-Preserving Data Provenance For TLSabstractWeb users can gather data from secure endpoints and demonstrate the provenance of sensitive data to any third party by using privacy-preserving TLS oracles. In practice, privacy-preserving TLS oracles remain limited and cannot verify larger, sensitive data sets. In this work, we introduce new optimizations for TLS oracles, which enhance the efficiency of selectively verifying the provenance of confidential web data. The novelty of our work is a construction which secures an honest verifier zero-knowledge proof system in the asymmetric privacy setting while retaining security against malicious adversaries. Concerning TLS 1.3 in the one round-trip time (1-RTT) mode, we propose a new, optimized garble-then-prove paradigm in a security setting with malicious adversaries. Our improvements reach new performance benchmarks and facilitate a practical deployment of privacy-preserving TLS oracles in web browsers. Jan Lauinger, Jens Ernstberger, Andreas Finkenzeller, Sebastian Steinhorst |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | Securing the Precision Time Protocol with SDN-enabled Cyclic Path Asymmetry AnalysisabstractHigh-precision time synchronization is a vital prerequisite for many modern applications and technologies, including Smart Grids, Time-sensitive Networking (TSN), and 5G networks. Although the Precision Time Protocol (PTP) can accomplish this requirement in trusted environments, it becomes unreliable in the presence of specific cyber attacks. Mainly, time delay attacks pose the highest threat to the protocol, enabling attackers to diverge targeted clocks undetected. With the increasing danger of cyber attacks, especially against critical infrastructure, there is a great demand for effective countermeasures to secure both time synchronization and the applications that depend on it. However, current solutions are not sufficiently capable of mitigating sophisticated delay attacks. For example, they lack proper integration into the PTP protocol, scalability, or sound evaluation with the required microsecond-level accuracy. This work proposes an approach to detect and counteract delay attacks against PTP, which is based on cyclic path asymmetry measurements over redundant paths. We leverage Software-defined Networking (SDN) capabilities to dynamically find these redundant paths in arbitrary networks, recommend new links to increase the network’s security, and ensure deterministic routing. Furthermore, we show how path redundancy can be utilized to reveal and mitigate undesirable asymmetries on the synchronization path that cause the malicious clock divergence. Moreover, we propose PTPsec, a secure PTP protocol, and its implementation based on the latest IEEE 1588-2019 standard. With PTPsec, we advance the conventional PTP to support reliable delay attack detection and mitigation. We validate our approach in software simulations and on a hardware testbed, which includes an attacker capable of performing static and incremental delay attacks at a microsecond precision. Our experimental results show that the proposed approach is scalable, and all attack scenarios can be reliably detected and mitigated with minimal detection time. Andreas Finkenzeller, Arne Fucks, Emanuel Regnath, Mohammad Hamad, Sebastian Steinhorst |
ACM Trans. Cyber Phys. Syst. | 1 |
| 2024 | PTPsec: Securing the Precision Time Protocol Against Time Delay Attacks Using Cyclic Path Asymmetry AnalysisabstractHigh-precision time synchronization is a vital prerequisite for many modern applications and technologies, including Smart Grids, Time-Sensitive Networking (TSN), and 5G networks. Although the Precision Time Protocol (PTP) can accomplish this requirement in trusted environments, it becomes unreliable in the presence of specific cyber attacks. Mainly, time delay attacks pose the highest threat to the protocol, enabling attackers to diverge targeted clocks undetected. With the increasing danger of cyber attacks, especially against critical infrastructure, there is a great demand for effective countermeasures to secure both time synchronization and the applications that depend on it. However, current solutions are not sufficiently capable of mitigating sophisticated delay attacks. For example, they lack proper integration into the PTP protocol, scalability, or sound evaluation with the required microsecond-level accuracy. This work proposes an approach to detect and counteract delay attacks against PTP based on cyclic path asymmetry measurements over redundant paths. For that, we provide a method to find redundant paths in arbitrary networks and show how this redundancy can be exploited to reveal and mitigate undesirable asymmetries on the synchronization path that cause the malicious clock divergence. Furthermore, we propose PTPsec, a secure PTP protocol and its implementation based on the latest IEEE 1588-2019 standard. With PTPsec, we advance the conventional PTP to support reliable delay attack detection and mitigation. We validate our approach on a hardware testbed, which includes an attacker capable of performing static and incremental delay attacks at a microsecond precision. Our experimental results show that all attack scenarios can be reliably detected and mitigated with minimal detection time. Andreas Finkenzeller, Oliver Butowski, Emanuel Regnath, Mohammad Hamad, Sebastian Steinhorst |
INFOCOM | 1 |
| 2024 | REACT: Autonomous intrusion response system for intelligent vehicles
Mohammad Hamad, Andreas Finkenzeller, Michael Kühr, Andrew Roberts, Olaf Maennel, Vassilis Prevelakis, Sebastian Steinhorst |
Comput. Secur. | 2 |
| 2023 | Simutack - An Attack Simulation Framework for Connected and Autonomous VehiclesabstractWith the ongoing efforts toward autonomous driving, modern vehicles become increasingly digital and smart. Hence, the vehicle architecture including smart sensors, ECUs, and in-vehicle communication also faces new challenges to satisfy the ever-changing safety and security requirements. The complexity of the system naturally exposes many attack surfaces that demand for sound security solutions to protect the vehicle from potential intrusions. State-of-the-art approaches such as intrusion detection and intrusion response systems require lots of training and testing against various attack scenarios. However, implementing such attacks in real environments is difficult, expensive, and involves many legal and safety considerations. With Simutack, we present an open-source attack simulation framework that is capable of generating realistic attack scenarios for comprehensive security testing in the automotive development process. The framework integrates several classes of attacks, for instance, smart sensor attacks, V2X attacks, and attacks targeting the in-vehicle networks, which are all among the most commonly exploited attack vectors. We evaluate three common attack scenarios that showcase the applicability and capabilities of our work. In each scenario, the generated attack data is processed and returned to the simulation to visualize the attack’s effect on the vehicle and its environment. Furthermore, a custom autopilot application demonstrates the attack’s impact on autonomous driving systems. Andreas Finkenzeller, Anshu Mathur, Jan Lauinger, Mohammad Hamad, Sebastian Steinhorst |
VTC2023-Spring | 1 |
| 2023 | SEEMQTT: Secure End-to-End MQTT-Based Communication for Mobile IoT Systems Using Secret Sharing and Trust DelegationabstractThe publish/subscribe (Pub/Sub) model offers a communication scheme that is appropriate for a variety of mobile Internet of Things (IoT) systems (e.g., autonomous vehicles). In most of these systems, ensuring the end-to-end (E2E) security of exchanged information is a critical requirement. However, the Pub/Sub scheme lacks appropriate mechanisms to ensure the E2E security, even when state-of-the-art solutions, such as transport layer security (TLS) or attribute-based encryption (ABE), were adopted. These solutions either do not offer E2E security or are infeasible to be adopted in mobile IoT systems with resource-constrained platforms. In this article, we propose a framework, so-called SEEMQTT, to ensure secure E2E Pub/Sub-based communication for mobile IoT systems. Our solution allows the publisher to encrypt the published messages and control which subscribers can decrypt these messages without violating the decoupling requirement of the Pub/Sub model. Our solution leverages multiple honest-but-curious KeyStores to store secret shares generated from a secret key using a secret sharing scheme. The links between the publisher and every KeyStores are secured using identity-based encryption (IBE). The publisher uses the secret key to encrypt published messages. Trust delegation is used to authorize certain subscribers to access these shares and consequently decrypt the published messages. We provide an Arduino-based library that implements our proposed protocol. Also, we perform an extensive performance evaluation using real IoT hardware. Experimental results show that adopting our proposed solution, SEEMQTT, makes E2E security for mobile IoT systems feasible. Mohammad Hamad, Andreas Finkenzeller, Hangmao Liu, Jan Lauinger, Vassilis Prevelakis, Sebastian Steinhorst |
IEEE Internet Things J. | 2 |
| 2022 | Attack Data Generation Framework for Autonomous Vehicle SensorsabstractDriving scenarios of autonomous vehicles combine many data sources with new networking requirements in highly dynamic system setups. To keep security mechanisms applicable to new application fields in the automotive domain, our work introduces a security framework to generate, attack, and validate realistic data sets at rest and in transit. Concerning realistic data sets, our framework leverages autonomous driving simulators as well as static data sets of vehicle sensors. A configurable networking setup enables flexible data encapsulation to perform and validate networking attacks on data in transit. We validate our results with intrusion detection algorithms and simulation environments. Generated data sets and configurations are reproducible, portable, storable, and support iterative security testing of scenarios. Jan Lauinger, Andreas Finkenzeller, Henrik Lautebach, Mohammad Hamad, Sebastian Steinhorst |
DATE | 2 |
| 2022 | Feasible Time Delay Attacks Against the Precision Time ProtocolabstractTime synchronization in packet-switched networks has evolved into an indispensable prerequisite for many modern applications. In addition to high accuracy demands, also reliability and security are evermore of great concern. Despite the proposal of supplementary security concepts in the past years such as the four prongs in Annex P of the IEEE 1588 standard, available protocols are still vulnerable to time delay attacks. In this paper, we propose multiple methods to implement realistic delay attacks and verify the feasibility on a hardware testbed. Furthermore, we perform a risk analysis to evaluate the actual threat of delay attacks in practical applications. Our analysis shows that time delay attacks still pose a great threat to current systems and further research is required to find sound countermeasures. Andreas Finkenzeller, Thomas Wakim, Mohammad Hamad, Sebastian Steinhorst |
GLOBECOM | 1 |