VLDB 2026 Research / reviewers in the wild / expert
Matteo Große-Kampmann
dblp:273/9536
· DBLP profile ↗
15ranked-venue papers
0as first author
14since 2021 · last 2026
0000-0001-9127-969XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 5 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Seeing Data Rights: Understanding of Pictograms and Color Cues for Privacy and Complex Data Practices
Kira Mennerich, Mia Catharina Chrambach, Maya Laura Gohres, Omed Abed, Patrick-Benjamin Bök, Matteo Große-Kampmann |
ACISP (3) | 6 |
| 2026 | When LLMs Give Voting Advice: Bias, Coherence, and Educational Risk
Omed Abed, Rabia Basri, Patrick-Benjamin Bök, Matteo Große-Kampmann |
AIED (6) | 4 |
| 2026 | Evaluating Large Language Models as Domain-Specific Retrieval Agents: A Study on Cybersecurity Challenge Benchmarks
Omed Abed, Md. Samiul Haque, Patrick-Benjamin Bök, Matteo Große-Kampmann |
ECIR (2) | 4 |
| 2026 | Performance of RISC-V SoCs for Secure Edge Applications: A Benchmark-Driven Analysis
Fabian Bas, Matteo Große-Kampmann, Patrick-Benjamin Bök |
IWCMC | 2 |
| 2026 | Performance Evaluation of AI-based Live Siren Detection on Smartphones in Vehicular Scenarios
Adrian Paus, Matteo Große-Kampmann, Patrick-Benjamin Bök |
IWCMC | 2 |
| 2025 | Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations Across Different Industries
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Tobias Urban, Matteo Große-Kampmann |
AsiaCCS | 5 |
| 2025 | Privacy from 5 PM to 6 AM: Tracking and Transparency Mechanisms in the HbbTV EcosystemabstractHybrid broadcast broadband television (HbbTV) is an evolving technology that connects linear TV with modern HTML5 applications, delivering extras like games, videos, and online shopping. However, its bidirectional transmission functionality raises privacy concerns, as it introduces new tracking methods for TV channels. While previous studies focused on security issues or user awareness of HbbTV privacy challenges, a detailed examination of the tracking and transparency mechanisms of the HbbTV ecosystem is still missing. This study fills this gap by extensively analyzing these features within the European HbbTV ecosystem, and in particular within German-language TV channels. We monitored more than 350 TV channels for over 400 hours, evaluating 1) prevalent HbbTV tracking methods, 2) consent notice prevalence and user interactions, and 3) privacy policy disclosures. Our findings indicate that the HbbTV tracking system operates independently of the Web, consent notices exploit system constraints to influence users, and privacy policies often do not align with actual data practices. Christian Böttger, Henry Hosseini, Christine Utz, Nurullah Demir, Jan Hörnemann, Christian Wressnegger, Thomas Hupperich, Norbert Pohlmann, Matteo Große-Kampmann, Tobias Urban |
DSN | 9 |
| 2025 | MobileSniper: Towards Automated Penetration Testing of 5G Campus Networks and IoT Infrastructuresabstract5G technology introduces new security challenges that require advanced penetration testing tools. This paper presents MobileSniper, an open-source tool specifically designed to address the unique vulnerabilities in 5G networks, particularly in campus and enterprise environments, while extending its applicability to the emerging domain of IoT security and privacy. MobileSniper leverages a modular architecture to integrate with popular security frameworks like Nmap and Nessus, incorporating 5G-specific functionalities such as service enumeration, network function detection, and PCAP analysis. In addition, the tool has been adapted to meet the security and privacy demands of IoT ecosystems, addressing threats related to device authentication, data encryption, and privacy breaches. Designed to identify vulnerabilities in critical 5G components—such as the Radio Access Network (RAN) and Core Network—MobileSniper focuses on issues like protocol manipulation and network slicing exploitation. Results from real-world tests demonstrate the tool’s compatibility across operating systems, expandability, and reliability under stress. The paper also discusses future enhancements, including automated attack modules and specialized vulnerability scanners, to further improve the tool’s capabilities for securing 5G infrastructures and IoT networks. Tim Barsch, Anna Triesch, Matteo Große-Kampmann |
IWCMC | 3 |
| 2025 | 5G Under Siege: A Comprehensive Guide to Threats and Penetration Testing in 5G Campus NetworksabstractThis paper provides a comprehensive guide for conducting penetration tests in fifth generation (5G) networks, particularly in campus environments, to enhance security of these networks. While 5G technology advances areas such as the Internet of Things (IoT), autonomous systems, and smart cities, its complex, virtualized, and open architecture also introduces new security risks. The paper outlines methods for identifying vulnerabilities in key 5G components, including the Radio Access Network (RAN), Core Network, and User Equipment (UE), to address emerging threats such as protocol manipulation or user tracking. This paper analyzes the current scientific literature and evaluates whether attacks can be used in a penetration-testing scenario. We identify current attacks and tools and consider them multidimensional regarding STRIDE threats and violations of the security dimensions. We release an extended version of MITRE Enterprise ATT&CK that contains our identified data. Anna Triesch, Tim Barsch, Veelasha Moonsamy, Matteo Große-Kampmann |
IWCMC | 4 |
| 2025 | Understanding Regional Filter Lists: Efficacy and ImpactabstractFilter lists are used by various users, tools, and researchers to identify tracking technologies on the Web. These lists are created and maintained by dedicated communities. Aside from popular blocking lists (e.g., EasyList), the communities create region-specific blocklists that account for trackers and ads that are only common in these regions. The lists aim to keep the size of a general blocklist minimal while protecting users against region-specific trackers. In this paper, we perform a large-scale Web measurement study to understand how different region-specific filter lists (e.g., a blocklist specifically designed for French users) protect users when visiting websites. We define three privacy scenarios to understand when and how users benefit from these regional lists and what effect they have in practice. The results show that although the lists differ significantly, the number of rules they contain is unrelated to the number of blocked requests. We find that the lists' overall efficacy varies notably. Filter lists also do not meet the expectation that they increase user protection in the regions for which they were designed. Finally, we show that the majority of the rules on the lists were not used in our experiment and that only a fraction of the rules would provide comparable protection for users. Christian Böttger, Nurullah Demir, Jan Hörnemann, Bhupendra Acharya, Norbert Pohlmann, Thorsten Holz, Matteo Große-Kampmann, Tobias Urban |
Proc. Priv. Enhancing Technol. | 7 |
| 2024 | Self-promotion with a chance of warnings: Exploring Cybersecurity Communication Among Government Institutions on LinkedInabstractKnowledge about threats and countermeasures is essential for adequate protection in digital societies. Three government agencies from Germany (Federal Office for Information Security, BSI), the United Kingdom (National Cyber Security Centre, NCSC), and the United States (Cybersecurity and Infrastructure Security Agency, CISA) all have the legal mandate to inform the public about threats and countermeasures. However, no systematic analysis of their communication strategies has been conducted. To close this gap, we conducted an exploratory content analysis. We developed a LinkedIn crawler to download all posts from the three government agencies in 2023. Based on this data set, we did a high-level exploratory analysis of 2,410 posts. We analyzed length, engagement (i.e., number of likes, shares, comments), and media types used as attachments. Afterwards, for March, 188 posts were analyzed using the Protection Motivation Theory (PMT) as a theoretical, analytical framework for risk communication. We find that the NCSC used PMT elements the most and managed to do so while posting the shortest posts in comparison. We furthermore identified thematic differences between the authorities. For example, the NCSC most frequently publishes information on cybersecurity risks without a current reason, while the BSI, like the CISA, frequently communicates on (scientific) publications apart from its self-marketing. Alexander Johannes Wilke, Jan Magnus Nold, Oskar Braun, Florian Meißner, Matteo Große-Kampmann |
MUM | 5 |
| 2023 | On the Similarity of Web Measurements Under Different Experimental Setups
Nurullah Demir, Jan Hörnemann, Matteo Große-Kampmann, Tobias Urban, Norbert Pohlmann, Thorsten Holz, Christian Wressnegger |
IMC | 3 |
| 2022 | Reproducibility and Replicability of Web Measurement StudiesabstractWeb measurement studies can shed light on not yet fully understood phenomena and thus are essential for analyzing how the modern Web works. This often requires building new and adjusting existing crawling setups, which has led to a wide variety of analysis tools for different (but related) aspects. If these efforts are not sufficiently documented, the reproducibility and replicability of the measurements may suffer—two properties that are crucial to sustainable research. In this paper, we survey 117 recent research papers to derive best practices for Web-based measurement studies and specify criteria that need to be met in practice. When applying these criteria to the surveyed papers, we find that the experimental setup and other aspects essential to reproducing and replicating results are often missing. We underline the criticality of this finding by performing a large-scale Web measurement study on 4.5 million pages with 24 different measurement setups to demonstrate the influence of the individual criteria. Our experiments show that slight differences in the experimental setup directly affect the overall results and must be documented accurately and carefully. Nurullah Demir, Matteo Große-Kampmann, Tobias Urban, Christian Wressnegger, Thorsten Holz, Norbert Pohlmann |
WWW | 2 |
| 2022 | "We may share the number of diaper changes": A Privacy and Security Analysis of Mobile Child Care ApplicationsabstractMobile child care management applications can help child care facilities, preschools, and kindergartens to save time and money by allowing their employees to speed up everyday child care tasks using mobile devices. Such apps often allow child care workers to communicate with parents or guardians, sharing their children’s most private data (e. g., activities, photos, location, developmental aspects, and sometimes even medical information). To offer these services, child care apps require access to very sensitive data of minors that should never be shared over insecure channels and are subject to restrictive privacy laws. This work analyzes the privacy and security of 42 Android child care applications and their cloud-backends using a combination of static and dynamic analysis frameworks, configuration scanners, and inspecting their privacy policies. The results of our analysis show that while children do not use these apps, they can leak sensitive data about them. Alarming are the findings that many third-party (tracking) services are embedded in the applications and that adversaries can access personal data by abusing vulnerabilities in the applications. We hope our work will raise awareness about the privacy risks introduced by these applications and that regulatory authorities will focus more on these risks in the future. Moritz Gruber, Christian Höfig, Maximilian Golla, Tobias Urban, Matteo Große-Kampmann |
Proc. Priv. Enhancing Technol. | 5 |
| 2020 | Plenty of Phish in the Sea: Analyzing Potential Pre-attack Surfaces
Tobias Urban, Matteo Große-Kampmann, Dennis Tatang, Thorsten Holz, Norbert Pohlmann |
ESORICS (2) | 2 |