VLDB 2026 Research / reviewers in the wild / expert
Anne Borcherding
dblp:233/8373
· DBLP profile ↗
7ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0002-8144-2382ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Show Me What You Got: Vulnerabilities of Industrial Components Revealed by Automated Blackbox Testingabstract240 Anne Borcherding, Mark Giraud, Laura Tzigiannis |
ICISSP (2) | 1 |
| 2025 | Bringing Light into the Darkness: Leveraging Hidden Markov Models for Blackbox FuzzingabstractSecuring the network interfaces of industrial control systems is essential for protecting critical infrastructure like water treatment plants and nuclear centrifuges from potential attacks. A key strategy to mitigate risks of successful attacks involves identifying and closing vulnerabilities exploitable through network interfaces using testing techniques such as fuzzing. While established techniques exist for graybox fuzzing, which assume access to system binaries, industrial components often require blackbox testing due to the use of third-party components and regulatory constraints. We propose Palpebratum, an approach that leverages Hidden Markov Models to approximate missing information in blackbox test scenarios. We evaluate Palpebratum’s performance in terms of code coverage, comparing it with two baseline blackbox fuzzers and the graybox fuzzer AFLnwe. Our results demonstrate that Palpebratum significantly outperforms one blackbox fuzzer, achieving an average of 4,379.33 basic blocks compared to 4,307.60 (p-value < 0.001). For the second blackbox fuzzer, Palpebratum achieves comparable coverage but with only half the number of test cases, demonstrating effectiveness despite the Hidden Markov Model’s overhead. These findings suggest that Palpebratum enhances blackbox test case generation and emphasizes the importance of an efficient implementation to offset the added overhead. Anne Borcherding, Mark Giraud, Johannes Häring |
AST | 1 |
| 2024 | Fuzz Wars: The Voltage Awakens - Voltage-Guided Blackbox Fuzzing on FPGAsabstractThe growing complexity and size of hardware designs necessitates novel, scalable approaches to verification, as latent bugs and security flaws have devastating impact. This is especially critical since bugs in hardware designs cannot be patched after manufacturing. Currently, dynamic verification is the predominant methodology for detecting hardware design flaws, where detection efficiency is primarily determined by the choice of (random) inputs to the design under test. More elaborate recent methods adapt principles from greybox software fuzzing to achieve high coverage in short time. However, these existing greybox methods rely on heavy instrumentation or software conversion, which requires access to the design source code. Fuzing of blackbox hardware designs has only been possible with random, undirected input generation up until now, which requires a long time to cover the majority of possible hardware states. In this work, we propose FUZZ-E, a novel scalable method for coverage-guided hardware design fuzzing, where coverage is indirectly estimated through on-chip voltage measurements on FPGAs. The side-channel-based FUZZ-E approach enables testing blackbox hardware designs without requiring access to any internal signals. We provide an extensive analysis of the correlation between hardware design coverage and voltage fluctuations, and show how FUZZ-E significantly reduces the verification time required to achieve desirable design coverage. Mark Giraud, Anne Borcherding, Jonas Krautter, Philipp Nenninger, Mehdi Baradaran Tahoori |
VTS | 3 |
| 2023 | SWaTEval: An Evaluation Framework for Stateful Web Application Testingabstract430 Anne Borcherding, Nikolay Penkov, Mark Giraud, Jürgen Beyerer |
ICISSP | 1 |
| 2022 | Towards a Better Understanding of Machine Learning based Network Intrusion Detection Systems in Industrial NetworksabstractIt is crucial in an industrial network to understand how and why a intrusion detection system detects, classifies, and reports intrusions. With the ongoing introduction of machine learning into the research area of intrusion detection, this understanding gets even more important since the used systems often appear as a black-box for the user and are no longer understandable in an intuitive and comprehensible way. We propose a novel approach to understand the internal characteristics of a machine learning based network intrusion detection system. This approach includes methods to understand which data sources the system uses, to evaluate whether the system uses linear or non-linear classification approaches, and to find out which underlying machine learning model is implemented in the system. Our evaluation on two publicly available industrial datasets shows that the detection of the data source and the differentiation between linear and non-linear models is possible with our approach. In addition, the identification of the underlying machine learning model can be accomplished with statistical significance for non-linear models. The information made accessible by our approach helps to develop a deeper understanding of the functioning of a network intrusion detection system, and contributes towards developing transparent machine learning based intrusion detection approaches. Anne Borcherding, Lukas Feldmann, Markus Karch, Ankush Meshram, Jürgen Beyerer |
ICISSP | 1 |
| 2022 | Cluster Crash: Learning from Recent Vulnerabilities in Communication StacksabstractTo ensure functionality and security of network stacks in industrial device, thorough testing is necessary. This includes blackbox network fuzzing, where fields in network packets are filled with unexpected values to test the device’s behavior in edge cases. Due to resource constraints, the tests need to be efficient and such the input values need to be chosen intelligently. Previous solutions use heuristics based on vague knowledge from previous projects to make these decisions. We aim to structure existing knowledge by defining Vulnerabil- ity Anti-Patterns for network communication stacks based on an analysis of the recent vulnerability groups Ripple20, Amnesia:33, and Urgent/11. For our evaluation, we implement fuzzing test scripts based on the Vulnerability Anti-Patterns and run them against 8 industrial device from 5 different device classes. We show (I) that similar vulnerabilities occur in implementations of the same protocol as well as in different protocols, (II) that similar vulnerabilities also spread over different device classes, and (III) that test scripts based on the Vulnerability Anti-Patterns help to identify these vulnerabilities. Anne Borcherding, Philipp Takacs, Jürgen Beyerer |
ICISSP | 1 |
| 2019 | Design of an Example Network Protocol for Security Tests Targeting Industrial Automation SystemsabstractEmerging concepts like Industrial Internet of Things (IIOT) and Industrie 4.0 require Industrial Automation and Control Systems (IACS) to be connected via networks and even to the Internet. These connections raise the importance of security for those devices enormously. Security testing for IACS aims at searching for vulnerabilities which can be utilized by attackers from the network. Once discovered, those gaps should be closed with patches before they can get exploited. Different tools utilized for this kind of security testing are dealing with network protocols. In practice, they suffer from peculiarities being present in common industrial automation protocols like OPC UA and Profinet IO. This paper tries to improve the situation by providing an extensive overview of network packet structures and network protocol behavior. Based on this analysis, an example protocol has been developed. The idea behind this artificial network protocol is that tools which are able to handle all the specialties of this protocol, are able to handle every imaginable protocol. Finally, those tools can be used to conduct exhaustive security tests for IACS. Steffen Pfrang, Mark Giraud, Anne Borcherding, David Meier, Jürgen Beyerer |
ICISSP | 3 |