VLDB 2026 Research / reviewers in the wild / expert
Maxime Veit
dblp:258/7113 · also Maxime Fabian Veit
· DBLP profile ↗
4ranked-venue papers
1as first author
3since 2021 · last 2026
0000-0001-8140-8953ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Development, Evaluation, and Implementation of SEQR - a Usable Secure QR Code ScannerabstractQR codes are widely used, but can become the vector of phishing attacks (QRishing). To support users, we systematically developed a usable secure QR code scanner, SEQR (Security Enhanced QR code scanner). We based the SEQR’s design on two systematic reviews: (i) of academic literature (2015–2025), identifying 96 papers on QRishing, and (ii) of the MITRE ATT&CK® Mobile repository, finding 36 QRishing techniques. From these two sources, we categorized 60 potential attacks, and divided them between those that SEQR addresses only at the technology level, and those where SEQR involves the users in the decision. We evaluated SEQR effectiveness in thwarting attacks in a between-subjects online study (n = 556), where SEQR achieved 93.35% correct answers, compared to 75.24% for the Apple iOS QR code scanner and 65.11% for the Samsung Android QR code scanner. We implemented SEQR as an open source Android application, available on GitHub. Mattia Mossano, Maxime Veit, Tobias Länge, Benjamin Berens, Filipo Sharevski, Melanie Volkamer |
CHI | 2 |
| 2026 | "I believe it's incredibly difficult to fight against this flood of spam": Towards enhancing strategies for creating effective vulnerability notificationsabstractIdentifying the most effective and scalable methods for notifying website owners about compromises or vulnerabilities remains an enduring challenge. Although some success factors have been identified, results regarding effective senders and notification framing are often inconsistent, and the understanding of how recipients perceive vulnerability notifications is still limited. Heading towards a better understanding, we conducted a 3 × 3 randomized controlled notification experiment, examining the impact of three distinct senders and three variations of notification framings for n = 581 compromised German websites. Our findings revealed a promising trend: receiving any notification significantly increased remediation compared to the absence of one. Remarkably, the choice of sender and framing played only a minor role in our notification experiment, which underscores the importance of notifying compromised websites and should motivate those who find vulnerabilities to take action. Yet, despite these encouraging results, a staggering 58% of the notified websites failed to remediate. To delve deeper into this phenomenon, we conducted follow-up interviews with 42 website owners who did not remediate their websites. The insights were revealing: while our notifications were delivered, many interviewees admitted they either overlooked or dismissed them as spam. This pattern persisted across different senders and framings, highlighting a critical challenge for future notification campaigns. Moving forward, future research should focus on finding ways to cut through the overwhelming amount of daily “spam” and explore strategies for how notifications can effectively convey their importance in recipients’ inboxes. Exploring strategies to raise the general awareness for cybersecurity, encouraging website owners to provide a security.txt, or providing additional assistance in the form of a self-service tool, are some proposals to increase remediation rates. We further recommend that future work should consider theories from communication science or psychology, e.g., Protection Motivation Theory (PMT) or the Elaboration-Likelihood Model, when designing notification campaigns. Anne Hennig, Maxime Veit, Leoni Schmidt-Enke, Fabian Neusser, Dominik Herrmann, Peter Mayer 0001 |
Comput. Secur. | 2 |
| 2025 | SoK: The past decade of user deception in emails and today's email clients' susceptibility to phishing techniquesabstractUser deception in emails is still one of the biggest security risks companies and end-users face alike. Attackers try to mislead their victims when assessing whether emails are dangerous to interact with, e.g., by using techniques based on dangerous links, dangerous attachments, or both. In this work, we present a systematic literature research of deception techniques discussed in the scientific literature of the last decade. We systematize the deception techniques, focusing on techniques that use misleading sender, link, and/or attachment information. We identify 23 deception techniques which we classify as either those that email clients should protect users against (13) and those that email clients cannot protect against and thus should be addressed in security awareness measures (10). We propose a security rating for the susceptibility of email clients to these 13 deception techniques and perform an empirical evaluation to analyze the susceptibility of seven representative email clients (web, mobile apps, desktop apps) to these deception techniques. The results of our evaluation indicate that most email clients are in need of improvement to defend against the deception techniques. Hardening email clients against these deception techniques is necessary to increase the resistance against them — without unnecessarily burdening users. Maxime Veit, Oliver Wiese, Fabian Ballreich, Melanie Volkamer, Douglas Engels, Peter Mayer 0001 |
Comput. Secur. | 1 |
| 2019 | TCP at 100 Gbit/s - Tuning, Limitations, Congestion ControlabstractLink capacities increase at an enormous pace, with 100 Gbit/s becoming standard in data centers, campus networks, and the Internet. These ever increasing data rates are challenging since end-system performance (esp. CPU performance) cannot keep up with the growth rates.Still, the TCP protocol and today's hardware are capable of transferring 100 Gbit/s with a single sender/receiver pair. However, extensive tuning is necessary down to manual interrupt configuration and corresponding CPU core pinning for the applications. A major issue is packet loss within the receiving end-system that cannot be prevented by TCP's flow control. This, in turn, affects TCP's default congestion control that interprets the losses as congestion signal. In this paper we show how to tune end-systems that are driven at their performance limits, what data rates are feasible, where the limitations are, and discuss the impact on and by TCP's congestion control. Mario Hock, Maxime Veit, Felix Neumeister, Roland Bless, Martina Zitterbart |
LCN | 2 |