VLDB 2026 Research / reviewers in the wild / expert
Sebastian Köhler 0005
dblp:48/7416-5
· DBLP profile ↗
12ranked-venue papers
4as first author
12since 2021 · last 2026
0009-0000-7957-7766ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 4 first-author · 12 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SideDish: Low-Cost Anti-Spoofing Countermeasure for Satellite Data CommunicationsabstractSatellite systems are increasingly vulnerable to spoofing attacks at the physical layer, where adversaries use inexpensive radio equipment to interfere with and replace legitimate signals. While cryptographic countermeasures are common in other wireless systems, their adoption in new space programs is slow due to concerns about the associated implications on robustness, cost, weight, power, and the challenges of updating existing systems. In this paper we introduce SideDish, a novel anti-spoofing countermeasure that combines a secondary receiver colocated at the satellite receiver with decoded signal comparison to detect out-of-beam unauthentic interference. The system is retrofittable into existing ground station deployments, cheap by using only low-cost components, and is robust against denial of service attacks. We verify this through simulations and real-world experiments that show SideDish spatially constraints attackers by between 70-99.84% in the angular domain, even considering scattering effects of the primary antenna. Targeting SideDish to deny service is not feasible within practical constraints, requiring microsecond-order timing accuracy to overcome. Edd Salkield, Louis-Emile Ploix, Martin Strohmeier, Sebastian Köhler 0005, Simon Birnbach, Ivan Martinovic |
WISEC | 4 |
| 2026 | SatIQ: Extensible and Stable Satellite Authentication using Hardware FingerprintingabstractAs satellite systems become a greater part of critical infrastructure, they have become a significantly more appealing target for attacks. The availability of cheap off-the-shelf radio hardware has made signal spoofing and physical layer attacks more accessible than ever to a wide range of adversaries, from hobbyists to nation-state actors. Legacy systems are particularly vulnerable due to their lack of cryptographic security, and cannot be patched to support novel security measures. In this article, we use radio transmitter fingerprinting to authenticate satellite downlinks, using characteristics of the transmitter hardware expressed as impairments on the physical layer radio signal. Our SatIQ system employs a Siamese neural network and an autoencoder to extract an efficient encoding of message headers that preserves identifying information. We focus on high sample rate fingerprinting, making device fingerprints difficult to forge without similarly high sample rate transmitting hardware. We collected 10290000 messages from the Iridium satellite constellation at 25 MS/s, and demonstrate that the SatIQ model trained on this data maintains performance over time without retraining, and can be used on new transmitters with no impact on performance. We analyze the system’s robustness against weather and signal factors, and demonstrate its effectiveness under attack, achieving an Equal Error Rate of 0.072 and ROC AUC of 0.960. We conclude that our techniques are useful for building fingerprinting systems that are effective at authenticating satellite communication, maintain performance over time and across satellite replacement, and provide robustness against spoofing and replay by raising the required budget for attacks. Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
ACM Trans. Priv. Secur. | 2 |
| 2025 | Current Affairs: A Security Measurement Study of CCS EV Charging Deployments
Marcell Szakály, Sebastian Köhler 0005, Ivan Martinovic |
USENIX Security Symposium | 2 |
| 2025 | Ripple: Software-Only Detection of Signal Injection Attacks in Drone Temperature SensorsabstractSignal injection attacks pose a serious threat to systems that rely on sensor information to determine their behavior. Using such an attack, an attacker can remotely manipulate the values of a sensor by transmitting appropriately formed RF signals that induce a current in the sensor wires. For example, to manipulate the temperature sensor in a battery management system, to trigger thermal protection, and shut down the battery. While several defense mechanisms have been proposed, they all need additional hardware to work. In this paper, we present RIPPLE, a fully software-based detection mechanism that can reliably detect signal injection attacks against drone sensor systems. A software-only solution is a practical way to add protection to an existing fleet of drones, and it is a cost effective alternative to the existing proposals for new drones. Our detection mechanism exploits a physical layer property known as small-scale (fast) fading, which causes the wireless channel between the attacker and drone to change unpredictably. As a result, the power induced by the attacker's transmission will oscillate rapidly, whenever the drone is in motion. We show for the first time that this effect occurs even with extremely minimal motion, such as a drone hovering in place on a calm, windless day. This oscillation is used as the basis of our detection system. We conduct an in-depth evaluation of RIPPLE on drones in several different environments. Our results show that RIPPLE reliably detects signal injection attacks. Even for weak attacks, changing the temperature by as little as 2°C, and with a drone movement of only a few millimeters, we have a success rate of over 98%. The performance only improves with stronger attack signals or more movement. Milad Rezaee, Sebastian Köhler 0005, Kasper Bonne Rasmussen |
WISEC | 2 |
| 2025 | SpaceJam: Protocol-aware Jamming Attacks against Space CommunicationsabstractMotivated by the growing prevalence of increasingly advanced satellite jamming attacks, we introduce and systematically analyze protocol-aware jammers: the worst-case scenario that maximally exploits the protocol to deny service whilst remaining as difficult to detect as possible. This extends existing satellite jamming and anti-jamming literature, which to date considers only conventional jamming waveforms. We find that protocol-aware jammers are significantly more effective than conventional jammers against all major standardized satellite protocols, including when anti-jamming countermeasures in the form of interleaving and adaptive coding and modulation are employed. This performance is possible since current protocols have a cyclic and predictable nature. We assess the required capabilities in terms of synchronization, and show that many of these performance gains can be realized even by completely desynchronized jammers. We experimentally evaluate protocol-aware strategies against both a hardware and software receiver. The results show that over 15dB of performance gains over Gaussian jamming are possible against all tested satellite protocols. Furthermore, we find that the attack can be optimized in simulation and deployed against the hardware receiver without performance degradation. We conclude with a discussion of countermeasures, primarily at the protocol level, to improve the availability of these systems. Edd Salkield, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
WISEC | 2 |
| 2024 | Assault and Battery: Evaluating the Security of Power Conversion Systems Against Electromagnetic Injection AttacksabstractMany modern devices, including critical infrastructure, depend on the reliable operation of electrical power conversion systems. The small size and versatility of switched-mode power converters has led to their widespread use. While transformer-based systems passively convert voltage, switched-mode power converters have an actively controlled feedback loop that relies on accurate sensor measurements. Previous academic work has shown that many types of sensors are vulnerable to Intentional Electromagnetic Interference (IEMI) attacks, and it has been speculated that power converters are also susceptible.In this paper, we present the first detailed and practical evaluation of IEMI attacks against switched-mode power converters as a whole by manipulating the voltage and current sensors in their feedback loops. We develop a novel multi-frequency IEMI attack technique to effectively target devices with multiple sensors. We experimentally validate our theoretical predictions by analyzing multiple AC-DC and DC-DC converters, automotive-grade current sensors, dedicated battery chargers, and a real-world electric vehicle charger. Our attack is reliably effective at overcharging and permanently damaging Li-ion cells, and causing the EV charger to output 50 V more than it reports. Marcell Szakály, Sebastian Köhler 0005, Martin Strohmeier, Ivan Martinovic |
ACSAC | 2 |
| 2023 | Watch This Space: Securing Satellite Communication through Resilient Transmitter FingerprintingabstractDue to an increase in the availability of cheap off-the-shelf radio hardware, signal spoofing and replay attacks on satellite ground systems have become more accessible than ever. This is particularly a problem for legacy systems, many of which do not offer cryptographic security and cannot be patched to support novel security measures. Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
CCS | 2 |
| 2023 | Brokenwire : Wireless Disruption of CCS Electric Vehicle Charging
Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic |
NDSS | 1 |
| 2023 | Satellite Spoofing from A to Z: On the Requirements of Satellite Downlink Overshadowing AttacksabstractSatellite communications are increasingly crucial for telecommunications, navigation, and Earth observation. However, many widely used satellites do not cryptographically secure the downlink, opening the door for radio spoofing attacks. Recent developments in software-defined radio hardware have enabled attacks on wireless systems including GNSS, which can be effectively spoofed using only cheap hardware available off the shelf. However, these conclusions do not generalize well to other satellite systems such as high data rate backhauls or satellite-to-customer connections, where the spoofing requirements are currently unknown. In this paper, we present a systematic review of spoofing attacks against satellite downlink communications systems. We establish a threat model linking attack feasibility and impact to required budget through real-world experiments and channel simulations. Our results show that nearly all evaluated satellite systems were overshadowable at a distance of 1 km in the worst case, for a budget of ~2000 USD or less. We evaluate how key challenges surrounding modulation schemes, antenna directionality, and legitimate satellite signal strength can be overcome in practice through antenna sidelobe targeting, overshadowing, and automatic gain control takeover. We also show that, surprisingly, protocols designed to be more robust against channel noise are significantly less robust against an overshadowing attacker. We conclude with a discussion of physical-layer countermeasures specifically applicable to satellite systems which can not be cryptographically upgraded. Edd Salkield, Marcell Szakály, Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
WISEC | 4 |
| 2022 | Signal Injection Attacks against CCD Image SensorsabstractSince cameras have become a crucial part in many safety-critical systems and applications, such as autonomous vehicles and surveillance, a large body of academic and non-academic work has shown attacks against their main component --- the image sensor. However, these attacks are limited to coarse-grained and often suspicious injections because light is used as an attack vector. Furthermore, due to the nature of optical attacks, they require the line-of-sight between the adversary and the target camera. Sebastian Köhler 0005, Richard Baker 0008, Ivan Martinovic |
AsiaCCS | 1 |
| 2022 | Demo: End-to-End Wireless Disruption of CCS EV ChargingabstractThe shift from vehicles with internal combustion engines (ICE) to fully Electric Vehicles (EVs) is happening at a rapid pace. To be competitive with ICEs and ensure a smooth rollout, the charging process of EVs needs to be as fast and convenient as possible. Modern DC fast-charging standards achieve this by implementing a high-level charging communication (HLC), which enables a safe, efficient, and convenient charging experience. Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic |
CCS | 1 |
| 2021 | They See Me Rollin': Inherent Vulnerability of the Rolling Shutter in CMOS Image SensorsabstractIn this paper, we describe how the electronic rolling shutter in CMOS image sensors can be exploited using a bright, modulated light source (e.g., an inexpensive, off-the-shelf laser), to inject fine-grained image disruptions. We demonstrate the attack on seven different CMOS cameras, ranging from cheap IoT to semi-professional surveillance cameras, to highlight the wide applicability of the rolling shutter attack. We model the fundamental factors affecting a rolling shutter attack in an uncontrolled setting. We then perform an exhaustive evaluation of the attack’s effect on the task of object detection, investigating the effect of attack parameters. We validate our model against empirical data collected on two separate cameras, showing that by simply using information from the camera’s datasheet the adversary can accurately predict the injected distortion size and optimize their attack accordingly. We find that an adversary can hide up to 75% of objects perceived by state-of-the-art detectors by selecting appropriate attack parameters. We also investigate the stealthiness of the attack in comparison to a naïve camera blinding attack, showing that common image distortion metrics can not detect the attack presence. Therefore, we present a new, accurate and lightweight enhancement to the backbone network of an object detector to recognize rolling shutter attacks. Overall, our results indicate that rolling shutter attacks can substantially reduce the performance and reliability of vision-based intelligent systems. Sebastian Köhler 0005, Giulio Lovisotto, Simon Birnbach, Richard Baker 0008, Ivan Martinovic |
ACSAC | 1 |