VLDB 2026 Research / reviewers in the wild / expert
Lieven Desmet
dblp:51/1256
· DBLP profile ↗
27ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0001-5155-7472ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 2 first-author · 6 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AI've Got a Bad Feeling About This: A Privacy Threat Modeling Framework for GenAI
Qianying Liao, Jonah Bellemans, Laurens Sion, Dmitrii Usynin, Xuebing Zhou, Dimitri Van Landuyt, Lieven Desmet, Wouter Joosen |
SOUPS | 8 |
| 2026 | Evaluating Design Decisions and Bias Resistance for Passive DNS-Based Domain Rankings
Victor Le Pochat, Simon Fernandez, Samaneh Tajalizadehkhoob, Lieven Desmet, Andrzej Duda, Wouter Joosen, Maciej Korczynski |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | Partnërka in Crime: Characterizing Deceptive Affiliate Marketing Offers
Victor Le Pochat, Cameron Ballard, Lieven Desmet, Wouter Joosen, Damon McCoy, Tobias Lauinger |
PAM | 3 |
| 2025 | Shiny Shells, Rusty Cores: A Crowdsourced Security Evaluation of Integrated Web Browsers
Gertjan Franken, Pieter Claeys, Tom van Goethem, Lieven Desmet |
SOUPS | 4 |
| 2025 | Gamified or Glorified? A systematic review of serious games for security & privacy in the SDLC
Jonah Bellemans, Dimitri Van Landuyt, Laurens Sion, Lieven Desmet |
Inf. Softw. Technol. | 4 |
| 2024 | Bad Design Smells in Benchmark NIDS DatasetsabstractSynthetically generated benchmark datasets are vitally important for machine learning and network intrusion research. When producing intrusion datasets for research, providers make complex, subtle and sometimes unwary decisions that can affect data utility. Unfortunately, examining network data is difficult, so these decisions are rarely audited. We perform an in-depth manual analysis of seven highly-cited benchmark datasets, discovering six suspect design patterns, which we term ‘data design smells’. We formulate six heuristics to measure the prevalence of these issues. These design choices, if not properly accounted for, can introduce severe experimental bias, which we demonstrate with four concrete examples. We then conduct a systematic impact analysis of the wider literature that relies on these datasets. Our results suggest that bad design smells correlate with poor data diversity, murky labelling and poorly-defined generalisation criteria. Worryingly, we find that improper usage of these datasets can weaken their utility as benchmarks which, in turn, biases downstream intrusion detection research. We conclude with some recommendations for using and creating NIDS datasets to help alleviate these issues. Robert Flood, Gints Engelen, David Aspinall 0001, Lieven Desmet |
EuroS&P | 4 |
| 2023 | A Bug's Life: Analyzing the Lifecycle and Mitigation Process of Content Security Policy Bugs
Gertjan Franken, Tom van Goethem, Lieven Desmet, Wouter Joosen |
USENIX Security Symposium | 3 |
| 2022 | Captcha me if you can: Imitation Games with Reinforcement LearningabstractSince their inception, Captchas have been widely used as reverse Turing tests for combating bot proliferation on the web. This has resulted in an arms race between bot developers that automate Captcha solvers and Captcha services that adjust the challenges accordingly or come up with new ones altogether. Ultimately, older generations could be bypassed consistently, and thus in the third version of reCAPTCHA, Google offers zero user friction. The intent in the new system is not only to avoid interrupting user experience but to also obfuscate the nature of the challenge itself, being much less prominent than a text or image recognition task. We introduce a methodology that learns through interaction how to evade detection, while collecting and analyzing reCAPTCHA v3 scores over fifteen months and various web environments. With reinforcement learning as the backbone, we build models that can simulate human-like web browsing behaviour by using the returned score as an informative signal. Our study exposes an important vulnerability: while the score is influenced by a multitude of undisclosed factors, it is easily accessible and it enables adversaries to learn and perfect evasive models. Notably, we demonstrate that our automation models, which integrate general web browsing capabilities, transfer between websites with an evasion rate up to 99.6%. Ilias Tsingenopoulos, Davy Preuveneers, Lieven Desmet, Wouter Joosen |
EuroS&P | 3 |
| 2019 | Premadoma: an operational solution for DNS registries to prevent malicious domain registrationsabstractDNS is one of the most essential components of the Internet, mapping domain names to the IP addresses behind almost every online service. Domain names are therefore also a fundamental tool for attackers to quickly locate and relocate their malicious activities on the Internet. In this paper, we design and evaluate Premadoma, a solution for DNS registries to predict malicious intent well before a domain name becomes operational. In contrast to blacklists, which only offer protection after some harm has already been done, this system can prevent domain names from being used before they can pose any threats. We advance the state of the art by leveraging recent insights into the ecosystem of malicious domain registrations, focusing explicitly on facilitators employed for bulk registration and similarity patterns in registrant information. We thoroughly evaluate the proposed prediction model's performance and adaptability on an 11 month testing set, and address complex and domain-specific dataset challenges. Moreover, we have successfully deployed Premadoma in the production environment of the .eu ccTLD registry to detect and prevent malicious registrations, and have contributed to the take down of 58,966 registrations in 2018. Jan Spooren, Thomas Vissers, Peter Janssen, Wouter Joosen, Lieven Desmet |
ACSAC | 5 |
| 2017 | Exploring the Ecosystem of Malicious Domain Registrations in the .eu TLD
Thomas Vissers, Jan Spooren, Pieter Agten, Dirk Jumpertz, Peter Janssen, Marc Van Wesemael, Frank Piessens, Wouter Joosen, Lieven Desmet |
RAID | 9 |
| 2016 | Advanced or Not? A Comparative Study of the Use of Anti-debugging and Anti-VM Techniques in Generic and Targeted Malware
Christophe Huygens, Lieven Desmet, Wouter Joosen |
SEC | 3 |
| 2014 | Monkey-in-the-browser: malware and vulnerabilities in augmented browsing script marketsabstractWith the constant migration of applications from the desktop to the web, power users have found ways of enhancing web applications, at the client-side, according to their needs. Steven Van Acker, Nick Nikiforakis, Lieven Desmet, Frank Piessens, Wouter Joosen |
AsiaCCS | 3 |
| 2014 | Soundsquatting: Uncovering the Use of Homophones in Domain Squatting
Nick Nikiforakis, Marco Balduzzi, Lieven Desmet, Frank Piessens, Wouter Joosen |
ISC | 3 |
| 2014 | Preface
Lieven Desmet, Martin Johns, Benjamin Livshits, Andrei Sabelfeld |
J. Comput. Secur. | 1 |
| 2013 | TabShots: client-side detection of tabnabbing attacksabstractAs the web grows larger and larger and as the browser becomes the vehicle-of-choice for delivering many applications of daily use, the security and privacy of web users is under constant attack. Phishing is as prevalent as ever, with anti-phishing communities reporting thousands of new phishing campaigns each month. In 2010, tabnabbing, a variation of phishing, was introduced. In a tabnabbing attack, an innocuous-looking page, opened in a browser tab, disguises itself as the login page of a popular web application, when the user's focus is on a different tab. The attack exploits the trust of users for already opened pages and the user habit of long-lived browser tabs. Philippe De Ryck, Nick Nikiforakis, Lieven Desmet, Wouter Joosen |
AsiaCCS | 3 |
| 2013 | A Dangerous Mix: Large-Scale Analysis of Mixed-Content Websites
Nick Nikiforakis, Christophe Huygens, Lieven Desmet |
ISC | 4 |
| 2013 | Bitsquatting: exploiting bit-flips for fun, or profit?abstractOver the last fifteen years, several types of attacks against domain names and the companies relying on them have been observed. The well-known cybersquatting of domain names gave way to typosquatting, the abuse of a user's mistakes when typing a URL in her browser's address bar. Recently, a new attack against domain names surfaced, namely bitsquatting. In bitsquatting, an attacker leverages random bit-errors occurring in the memory of commodity computers and smartphones, to redirect Internet traffic to attacker-controlled domains. Nick Nikiforakis, Steven Van Acker, Wannes Meert, Lieven Desmet, Frank Piessens, Wouter Joosen |
WWW | 4 |
| 2012 | JSand: complete client-side sandboxing of third-party JavaScript without browser modificationsabstractThe inclusion of third-party scripts in web pages is a common practice. A recent study has shown that more than half of the Alexa top 10000 sites include scripts from more than 5 different origins. However, such script inclusions carry risks, as the included scripts operate with the privileges of the including website. Pieter Agten, Steven Van Acker, Yoran Brondsema, Phu H. Phung, Lieven Desmet, Frank Piessens |
ACSAC | 5 |
| 2012 | FlashOver: automated discovery of cross-site scripting vulnerabilities in rich internet applicationsabstractThe last fifteen years have transformed the Web in ways that would seem unimaginable to anyone of the "few" Internet users of the year 1995 [8]. What began as a simple set of protocols and mechanisms facilitating the exchange of static documents between remote computers is now an everyday part of billions' of users life, technical and non-technical alike. The sum of a user's daily experience is composed of open standards, such as HTML, JavaScript and Cascading Style Sheets as well as proprietary plugins, such as Adobe's Flash [1] and Microsoft's Silverlight [6]. Steven Van Acker, Nick Nikiforakis, Lieven Desmet, Wouter Joosen, Frank Piessens |
AsiaCCS | 3 |
| 2012 | Serene: Self-Reliant Client-Side Protection against Session Fixation
Philippe De Ryck, Nick Nikiforakis, Lieven Desmet, Frank Piessens, Wouter Joosen |
DAIS | 3 |
| 2012 | A Security Analysis of Emerging Web Standards - HTML5 and Friends, from Specification to Implementation
Philippe De Ryck, Lieven Desmet, Frank Piessens, Wouter Joosen |
SECRYPT | 2 |
| 2011 | WebJail: least-privilege integration of third-party components in web mashupsabstractIn the last decade, the Internet landscape has transformed from a mostly static world into Web 2.0, where the use of web applications and mashups has become a daily routine for many Internet users. Web mashups are web applications that combine data and functionality from several sources or components. Ideally, these components contain benign code from trusted sources. Unfortunately, the reality is very different. Web mashup components can misbehave and perform unwanted actions on behalf of the web mashup's user. Steven Van Acker, Philippe De Ryck, Lieven Desmet, Frank Piessens, Wouter Joosen |
ACSAC | 3 |
| 2011 | Automatic and Precise Client-Side Protection against CSRF Attacks
Philippe De Ryck, Lieven Desmet, Wouter Joosen, Frank Piessens |
ESORICS | 2 |
| 2011 | Deploy, Adjust and Readjust: Supporting Dynamic Reconfiguration of Policy Enforcement
Gabriela Gheorghe, Bruno Crispo, Roberto Carbone, Lieven Desmet, Wouter Joosen |
Middleware | 4 |
| 2008 | Security-by-contract on the .NET platform
Lieven Desmet, Wouter Joosen, Fabio Massacci, Pieter Philippaerts, Frank Piessens, Ida Sri Rejeki Siahaan, Dries Vanoverberghe |
Inf. Secur. Tech. Rep. | 1 |
| 2008 | Provable Protection against Web Application Vulnerabilities Related to Session Data DependenciesabstractWeb applications are widely adopted and their correct functioning is mission critical for many businesses. At the same time, Web applications tend to be error prone and implementation vulnerabilities are readily and commonly exploited by attackers. The design of countermeasures that detect or prevent such vulnerabilities or protect against their exploitation is an important research challenge for the fields of software engineering and security engineering. In this paper, we focus on one specific type of implementation vulnerability, namely, broken dependencies on session data. This vulnerability can lead to a variety of erroneous behavior at runtime and can easily be triggered by a malicious user by applying attack techniques such as forceful browsing. This paper shows how to guarantee the absence of runtime errors due to broken dependencies on session data in Web applications. The proposed solution combines development-time program annotation, static verification, and runtime checking to provably protect against broken data dependencies. We have developed a prototype implementation of our approach, building on the JML annotation language and the existing static verification tool ESC/Java2, and we successfully applied our approach to a representative J2EE-based e-commerce application. We show that the annotation overhead is very small, that the performance of the fully automatic static verification is acceptable, and that the performance overhead of the runtime checking is limited. Lieven Desmet, Pierre Verbaeten, Wouter Joosen, Frank Piessens |
IEEE Trans. Software Eng. | 1 |
| 2004 | The DiPS+ Software Architecture for Self-healing Protocol StacksabstractResearch domains such as active networks, ad-hoc networks, ubiquitous computing, pervasive computing, grid computing, and sensor networks, clearly show that computer networks will become more complex and heterogeneous. In many cases, central management and control of the network are far from trivial since both the topology and the connected devices change rapidly in such highly dynamic environments, while load circumstances may vary arbitrarily. The software architecture in a node needs to support flexibility. We have developed an architecture tailored to protocol stack software that allows customizing internal resource management in order to handle overload conditions gracefully. We show that the investment in explicit support for modularity and architectural constraints pays off: the paper elaborates on a case study in which dynamic adaptation of access control behavior leads to significant performance improvements. Sam Michiels, Lieven Desmet, Wouter Joosen, Pierre Verbaeten |
WICSA | 2 |