VLDB 2026 Research / reviewers in the wild / expert
Christoph Sendner
dblp:275/3798
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0003-3766-783XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 8 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RESTing-LLAMA: Large Language Model based REST API FuzzingabstractRecent advances in Large Language Models (LLMs) have introduced new opportunities in software engineering, cybersecurity, and automated testing. Despite this progress, their application to security fuzzing, particularly for REST APIs, remains largely underexplored. Fuzzing remains a fundamental technique for discovering software vulnerabilities through malformed inputs, but traditional fuzzers often struggle to interact effectively with modern REST APIs due to a lack of semantic understanding needed to generate meaningful request sequences. Yet, existing automated fuzzing approaches frequently fail to uncover vulnerabilities due to their inability to use the APIs correctly. We introduce RESTing-LLAMA, a fully automated and end-to-end fuzzing framework that operates in a black-box setting and leverages LLMs to guide the fuzzing process. By extracting semantic information from OpenAPI specifications and natural language documentation, RESTing-LLAMA generates meaningful and well-structured input sequences that align with real-world API behavior. In our evaluation on fifteen real-world APIs, RESTing-LLAMA uncovered 11 vulnerabilities, including one previously unknown vulnerability, while matching or outperforming state-of-the-art fuzzers. It achieved a 34% false positive rate compared to 45% for the next best fuzzer, while requiring 4.4x fewer requests, highlighting the significant improvement in input quality. Varun Gadey, Christoph Sendner, Keven Zimmermann, Alexandra Dmitrienko |
AsiaCCS | 2 |
| 2026 | Automated Code Annotation with LLMs for Establishing TEE Boundaries
Varun Gadey, Melanie Gotz, Christoph Sendner, Sampo Sovio, Alexandra Dmitrienko |
NDSS | 3 |
| 2025 | Impact Analysis of Sybil Attacks in the Tor Network
Christoph Sendner, Dominik Schreider, Alexandra Dmitrienko |
SEC (2) | 1 |
| 2024 | MirageFlow: A New Bandwidth Inflation Attack on Tor
Christoph Sendner, Jasper Stang, Alexandra Dmitrienko, Raveen Wijewickrama, Murtuza Jadliwala |
NDSS | 1 |
| 2024 | Large-Scale Study of Vulnerability Scanners for Ethereum Smart ContractsabstractEthereum smart contracts, which are autonomous decentralized applications on the blockchain that manage assets often exceeding millions of dollars, have become primary targets for cyberattacks. In 2023 alone, such vulnerabilities led to substantial financial losses exceeding a billion US dollars. To counter these threats, various tools have been developed by academic and commercial entities to detect and mitigate vulnerabilities in smart contracts. Our study investigates the gap between the effectiveness of existing security scanners and the vulnerabilities that still persist in practice. We compiled four distinct datasets for this analysis. The first dataset comprises 77,219 source codes extracted directly from the blockchain, while the second includes over 4 million bytecodes obtained from Ethereum Mainnet and testnets. The other two datasets consist of nearly 14,000 manually annotated smart contracts and 373 smart contracts verified through audits, providing a foundation for a rigorous ground truth analysis on bytecode and source code. Using the unlabeled datasets, we conducted a comprehensive quantitative evaluation of 18 vulnerability scanners, revealing considerable discrepancies in their findings. Our analysis of the ground truth datasets indicated poor performance across all the tools we tested. This study unveils the reasons for poor performance and underscores that the current state of the art for smart contract security falls short in effectively addressing open problems, highlighting that the challenge of effectively detecting vulnerabilities remains a significant and unresolved issue. Christoph Sendner, Lukas Petzi, Jasper Stang, Alexandra Dmitrienko |
SP | 1 |
| 2023 | Smarter Contracts: Detecting Vulnerabilities in Smart Contracts with Deep Transfer Learning
Christoph Sendner, Huili Chen, Hossein Fereidooni, Lukas Petzi, Jan König, Jasper Stang, Alexandra Dmitrienko, Ahmad-Reza Sadeghi, Farinaz Koushanfar |
NDSS | 1 |
| 2023 | Contact Discovery in Mobile Messengers: Low-cost Attacks, Quantitative Analyses, and Efficient MitigationsabstractContact discovery allows users of mobile messengers to conveniently connect with people in their address book. In this work, we demonstrate that severe privacy issues exist in currently deployed contact discovery methods and propose suitable mitigations. Our study of three popular messengers (WhatsApp, Signal, and Telegram) shows that large-scale crawling attacks are (still) possible. Using an accurate database of mobile phone number prefixes and very few resources, we queried 10 % of US mobile phone numbers for WhatsApp and 100 % for Signal. For Telegram, we find that its API exposes a wide range of sensitive information, even about numbers not registered with the service. We present interesting (cross-messenger) usage statistics, which also reveal that very few users change the default privacy settings. Furthermore, we demonstrate that currently deployed hashing-based contact discovery protocols are severely broken by comparing three methods for efficient hash reversal. Most notably, we show that with the password cracking tool “JTR,” we can iterate through the entire worldwide mobile phone number space in < 150 s on a consumer-grade GPU. We also propose a significantly improved rainbow table construction for non-uniformly distributed input domains that is of independent interest. Regarding mitigations, we most notably propose two novel rate-limiting schemes: our incremental contact discovery for services without server-side contact storage strictly improves over Signal’s current approach while being compatible with private set intersection, whereas our differential scheme allows even stricter rate limits at the overhead for service providers to store a small constant-size state that does not reveal any contact information. Christoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko, Thomas Schneider 0003 |
ACM Trans. Priv. Secur. | 3 |
| 2021 | All the Numbers are US: Large-scale Abuse of Contact Discovery in Mobile Messengers
Christoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko, Thomas Schneider 0003 |
NDSS | 3 |