VLDB 2026 Research / reviewers in the wild / expert
Eric Wagner 0003
dblp:27/918-3
· DBLP profile ↗
19ranked-venue papers
10as first author
16since 2021 · last 2026
0000-0003-3211-1015ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 8 first-author · 13 since 2021Computer networks · 5 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Deep Dive into Wormhole Attacks in Underwater Acoustic Communication: From Theory to Practiceabstract256 Luisa Lux, Eric Wagner 0003, Konrad Wolsing, Ulrike Meyer |
WISEC | 3 |
| 2026 | Seldom: An Anonymity Network with Selective DeanonymizationabstractWhile anonymity networks such as Tor provide invaluable privacy guarantees to society, they also enable all kinds of criminal activities. Consequently, many blameless citizens shy away from protecting their privacy using such technology for fear of being associated with criminals. To grasp the potential for alternative privacy protection for those users, we design Seldom , an anonymity network with integrated selective deanonymization that disincentivizes criminal activity. Seldom enables law enforcement agencies to selectively access otherwise anonymized identities of misbehaving users while providing technical guarantees preventing these access rights from being misused. Seldom further ensures translucency , as each access request is approved by a trustworthy consortium of impartial entities and eventually disclosed to the public (without interfering with ongoing investigations). To demonstrate Seldom ’s feasibility and applicability, we base our implementation on Tor, the most widely used anonymity network. Our evaluation indicates minimal latency, processing, and bandwidth overheads compared to Tor; Seldom ’s main costs stem from storing flow records and encrypted identities. With at most 636 TB of storage required in total to retain the encrypted identifiers of a Tor-sized network for two years, Seldom provides a practical and deployable technical solution to the inherent problem of criminal activities in anonymity networks. As such, Seldom sheds new light on the potentials and limitations when integrating selective deanonymization into anonymity networks. Eric Wagner 0003, Roman Matzutt, Martin Henze |
ACM Trans. Priv. Secur. | 1 |
| 2025 | Sherlock: A Dataset for Process-aware Intrusion Detection Research on Power Grid Networks: Dataset Paperabstract419 Eric Wagner 0003, Lennart Bader, Konrad Wolsing, Martin Serror |
CODASPY | 1 |
| 2025 | Caiba: Multicast Source Authentication for CAN Through Reactive Bit FlippingabstractController Area Networks (CANs) are the back-bone for reliable intra-vehicular communication. Recent cyberattacks have, however, exposed the weaknesses of CAN, which was designed without any security considerations in the 1980s. Current efforts to retrofit security via intrusion detection or message authentication codes are insufficient to fully secure CAN as they cannot adequately protect against masquerading attacks, where a compromised communication device, a so-called electronic control units, imitates another device. To remedy this situation, multicast source authentication is required to reliably identify the senders of messages. In this paper, we present Caiba, a novel multicast source authentication scheme specifically designed for communication buses like CAN. Caiba relies on an authenticator overwriting authentication tags on-the-fly, such that a receiver only reads a valid tag if not only the integrity of a message but also its source can be verified. To integrate Caiba into CAN, we devise a special message authentication scheme and a reactive bit overwriting mechanism. We achieve interoperability with legacy CAN devices, while protecting receivers implementing the AUTOSAR SecOC standard against masquerading attacks without communication overhead or verification delays. Eric Wagner 0003, Frederik Basels, Till Zimmermann, Klaus Wehrle, Martin Henze |
EuroS&P | 1 |
| 2025 | MAC Aggregation over Lossy Channels in DTLS 1.3abstractAggregating Message Authentication Codes (MACs) promises to save valuable bandwidth in resource-constrained environments. The idea is simple: Instead of appending an authentication tag to each message in a communication stream, the integrity protection of multiple messages is aggregated into a single tag. Recent studies postulate, e.g., based on simulations, that these benefits also spread to wireless, and thus lossy, scenarios despite each lost packet typically resulting in the loss of integrity protection information for multiple messages. In this paper, we investigate these claims in a real deployment. Therefore, we first design a MAC aggregation extension for the Datagram Transport Layer Security (DTLS) 1.3 protocol. Afterward, we extensively evaluate the performance of MAC aggregation on a complete communication protocol stack on embedded hardware. We find that MAC aggregation can indeed increase goodput by up to 50 % and save up to 17 % of energy expenditure for the transmission of short messages, even in lossy channels. Eric Wagner 0003, David Heye, Klaus Wehrle, Martin Serror |
ICNP | 1 |
| 2025 | GeCos Replacing Experts: Generalizable and Comprehensible Industrial Intrusion Detection
Konrad Wolsing, Eric Wagner 0003, Luisa Lux, Klaus Wehrle, Martin Henze |
USENIX Security Symposium | 2 |
| 2024 | When and How to Aggregate Message Authentication Codes on Lossy Channels?
Eric Wagner 0003, Martin Serror, Klaus Wehrle, Martin Henze |
ACNS (2) | 1 |
| 2024 | Madtls: Fine-grained Middlebox-aware End-to-end Security for Industrial CommunicationabstractIndustrial control systems increasingly rely on middlebox functionality such as intrusion detection or in-network processing. However, traditional end-to-end security protocols interfere with the necessary access to in-flight data. While recent work on middlebox-aware end-to-end security protocols for the traditional Internet promises to address the dilemma between end-to-end security guarantees and middleboxes, the current state-of-the-art lacks critical features for industrial communication. Most importantly, industrial settings require fine-grained access control for middleboxes to truly operate in a least-privilege mode. Likewise, advanced applications even require that middleboxes can inject specific messages (e.g., emergency shutdowns). Meanwhile, industrial scenarios often expose tight latency and bandwidth constraints not found in the traditional Internet. As the current state-of-the-art misses critical features, we propose Middlebox-aware DTLS (Madtls), a middlebox-aware end-to-end security protocol specifically tailored to the needs of industrial networks. Madtls provides bit-level read and write access control of middleboxes to communicated data with minimal bandwidth and processing overhead, even on constrained hardware. Eric Wagner 0003, David Heye, Martin Serror, Ike Kunze, Klaus Wehrle, Martin Henze |
AsiaCCS | 1 |
| 2023 | One IDS Is Not Enough! Exploring Ensemble Learning for Industrial Intrusion Detection
Konrad Wolsing, Dominik Kus, Eric Wagner 0003, Jan Pennekamp, Klaus Wehrle, Martin Henze |
ESORICS (2) | 3 |
| 2023 | Retrofitting Integrity Protection into Unused Header Fields of Legacy Industrial ProtocolsabstractIndustrial networks become increasingly interconnected, which opens the floodgates for cyberattacks on legacy networks designed without security in mind. Consequently, the vast landscape of legacy industrial communication protocols urgently demands a universal solution to integrate security features retroactively. However, current proposals are hardly adaptable to new scenarios and protocols, even though most industrial protocols share a common theme: Due to their progressive development, previously important legacy features became irrelevant and resulting unused protocol fields now offer a unique opportunity for retrofitting security. Our analysis of three prominent protocols shows that headers offer between 36 and 63 bits of unused space. To take advantage of this space, we designed the REtrofittable ProtEction Library (RePeL), which supports embedding authentication tags into arbitrary combinations of unused header fields. We show that RePeL incurs negligible overhead beyond the cryptographic processing, which can be adapted to hit performance targets or fulfill legal requirements. Eric Wagner 0003, Nils Rothaug, Konrad Wolsing, Lennart Bader, Klaus Wehrle, Martin Henze |
LCN | 1 |
| 2022 | Can Industrial Intrusion Detection Be SIMPLE?
Konrad Wolsing, Lea Thiemt, Christian van Sloun, Eric Wagner 0003, Klaus Wehrle, Martin Henze |
ESORICS (3) | 4 |
| 2022 | Scalable and Privacy-Focused Company-Centric Supply Chain ManagementabstractBlockchain technology promises to overcome trust and privacy concerns inherent to centralized information sharing. However, current decentralized supply chain management systems do either not meet privacy and scalability requirements or require a trustworthy consortium, which is challenging for increasingly dynamic supply chains with constantly changing participants. In this paper, we propose CCChain, a scalable and privacy-aware supply chain management system that stores all information locally to give companies complete sovereignty over who accesses their data. Still, tamper protection of all data through a permissionless blockchain enables on-demand tracking and tracing of products as well as reliable information sharing while affording the detection of data inconsistencies. Our evaluation confirms that CCChain offers superior scalability in comparison to alternatives while also enabling near real-time tracking and tracing for many, less complex products. Eric Wagner 0003, Roman Matzutt, Jan Pennekamp, Lennart Bader, Irakli Bajelidze, Klaus Wehrle, Martin Henze |
ICBC | 1 |
| 2022 | Network Attacks Against Marine Radar Systems: A Taxonomy, Simulation Environment, and DatasetabstractShipboard marine radar systems are essential for safe navigation, helping seafarers perceive their surroundings as they provide bearing and range estimations, object detection, and tracking. Since onboard systems have become increasingly digitized, interconnecting distributed electronics, radars have been integrated into modern bridge systems. But digitization increases the risk of cyberattacks, especially as vessels cannot be considered air-gapped. Consequently, in-depth security is crucial. However, particularly radar systems are not sufficiently protected against harmful network-level adversaries. Therefore, we ask: Can seafarers believe their eyes? In this paper, we identify possible attacks on radar communication and discuss how these threaten safe vessel operation in an attack taxonomy. Furthermore, we develop a holistic simulation environment with radar, complementary nautical sensors, and prototypically implemented cyberattacks from our taxonomy. Finally, leveraging this environment, we create a comprehensive dataset (RadarPWN) with radar network attacks that provides a foundation for future security research to secure marine radar communication. Konrad Wolsing, Antoine Saillard, Eric Wagner 0003, Christian van Sloun, Ina Berenice Fink, Mari Schmidt, Klaus Wehrle, Martin Henze |
LCN | 4 |
| 2022 | IPAL: Breaking up Silos of Protocol-dependent and Domain-specific Industrial Intrusion Detection SystemsabstractThe increasing interconnection of industrial networks exposes them to an ever-growing risk of cyber attacks. To reveal such attacks early and prevent any damage, industrial intrusion detection searches for anomalies in otherwise predictable communication or process behavior. However, current efforts mostly focus on specific domains and protocols, leading to a research landscape broken up into isolated silos. Thus, existing approaches cannot be applied to other industries that would equally benefit from powerful detection. To better understand this issue, we survey 53 detection systems and find no fundamental reason for their narrow focus. Although they are often coupled to specific industrial protocols in practice, many approaches could generalize to new industrial scenarios in theory. To unlock this potential, we propose IPAL, our industrial protocol abstraction layer, to decouple intrusion detection from domain-specific industrial protocols. After proving IPAL’s correctness in a reproducibility study of related work, we showcase its unique benefits by studying the generalizability of existing approaches to new datasets and conclude that they are indeed not restricted to specific domains or protocols and can perform outside their restricted silos. Konrad Wolsing, Eric Wagner 0003, Antoine Saillard, Martin Henze |
RAID | 2 |
| 2022 | Take a Bite of the Reality Sandwich: Revisiting the Security of Progressive Message Authentication CodesabstractMessage authentication guarantees the integrity of messages exchanged over untrusted channels. However, to achieve this goal, message authentication considerably expands packet sizes, which is especially problematic in constrained wireless environments. To address this issue, progressive message authentication provides initially reduced integrity protection that is often sufficient to process messages upon reception. This reduced security is then successively improved with subsequent messages to uphold the strong guarantees of traditional integrity protection. However, contrary to previous claims, we show in this paper that existing progressive message authentication schemes are highly susceptible to packet loss induced by poor channel conditions or jamming attacks. Thus, we consider it imperative to rethink how authentication tags depend on the successful reception of surrounding packets. To this end, we propose R2-D2, which uses randomized dependencies with parameterized security guarantees to increase the resilience of progressive authentication against packet loss. To deploy our approach to resource-constrained devices, we introduce SP-MAC, which implements R2-D2 using efficient XOR operations. Our evaluation shows that SP-MAC is resilient to sophisticated network-level attacks and operates as resources-conscious and fast as existing, yet insecure, progressive message authentication schemes. Eric Wagner 0003, Martin Henze |
WISEC | 1 |
| 2022 | BP-MAC: Fast Authentication for Short MessagesabstractResource-constrained devices increasingly rely on wireless communication for the reliable and low-latency transmission of short messages. However, especially the implementation of adequate integrity protection of time-critical messages places a significant burden on these devices. We address this issue by proposing BP-MAC, a fast and memory-efficient approach for computing message authentication codes based on the well-established Carter-Wegman construction. Our key idea is to offload resource-intensive computations to idle phases and thus save valuable time in latency-critical phases, i.e., when new data awaits processing. Therefore, BP-MAC leverages a universal hash function designed for the bitwise preprocessing of integrity protection to later only require a few XOR operations during the latency-critical phase. Our evaluation on embedded hardware shows that BP-MAC outperforms the state-of-the-art in terms of latency and memory overhead, notably for small messages, as required to adequately protect resource-constrained devices with stringent security and latency requirements. Eric Wagner 0003, Martin Serror, Klaus Wehrle, Martin Henze |
WISEC | 1 |
| 2020 | Facilitating Protocol-independent Industrial Intrusion Detection SystemsabstractCyber-physical systems are increasingly threatened by sophisticated attackers, also attacking the physical aspect of systems. Supplementing protective measures, industrial intrusion detection systems promise to detect such attacks. However, due to industrial protocol diversity and lack of standard interfaces, great efforts are required to adapt these technologies to a large number of different protocols. To address this issue, we identify existing universally applicable intrusion detection approaches and propose a transcription for industrial protocols to realize protocol-independent semantic intrusion detection on top of different industrial protocols. Konrad Wolsing, Eric Wagner 0003, Martin Henze |
CCS | 2 |
| 2020 | QWIN: Facilitating QoS in Wireless Industrial Networks Through Cooperation
Martin Serror, Eric Wagner 0003, René Glebke, Klaus Wehrle |
Networking | 2 |
| 2018 | Secure Low Latency Communication for Constrained Industrial IoT ScenariosabstractThe emerging Internet of Things (IoT) promises value-added services for private and business applications. However, especially the industrial IoT often faces tough communication latency boundaries, e.g., to react to production errors, realize human-robot interaction, or counter fluctuations in smart grids. Simultaneously, devices must apply security measures such as encryption and integrity protection to guard business secrets and prevent sabotage. As security processing requires significant time, the goals of secure communication and low latency contradict each other. Especially on constrained IoT devices, which are equipped with cheap, low-power processors, the overhead for security processing aggregates to a primary source of latency. We show that antedated encryption and data authentication with templates enables IoT devices to meet both, security and low latency requirements. These mechanisms offload significant security processing to a preprocessing phase and thus decrease latency during actual transmission by up to 75.9 %. Thereby they work for well-established security-proven standard ciphers. Jens Hiller, Martin Henze, Martin Serror, Eric Wagner 0003, Jan Niklas Richter, Klaus Wehrle |
LCN | 4 |