VLDB 2026 Research / reviewers in the wild / expert
Joachim Posegga
dblp:p/JPosegga
· DBLP profile ↗
39ranked-venue papers
3as first author
5since 2021 · last 2025
0000-0002-6468-809XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 1 since 2021Theory of computation · 4 · 1 first-authorComputer networks · 2 · 1 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Optimizing Code Embeddings and ML Classifiers for Python Source code Vulnerability DetectionabstractIn recent years, the growing complexity and scale of source code have rendered manual software vulnerability detection increasingly impractical. To address this challenge, automated approaches leveraging machine learning and code embeddings have gained substantial attention. This study investigates the optimal combination of code embedding techniques and machine learning classifiers for vulnerability detection in Python source code. We evaluate three embedding techniques, i.e., Word2Vec, CodeBERT, and GraphCodeBERT alongside two deep learning classifiers, i.e., Bidirectional Long Short-Term Memory (BiLSTM) networks and Convolutional Neural Networks (CNN). While CNN paired with GraphCodeBERT exhibits strong performance, the BiLSTM model using Word2Vec consistently achieves superior overall results. These findings suggest that, despite the advanced architectures of recent models like CodeBERT and GraphCodeBERT, classical embeddings such as Word2Vec, when used with sequence-based models like BiLSTM, can offer a slight yet consistent performance advantage. The study underscores the critical importance of selecting appropriate combinations of embeddings and classifiers to enhance the effectiveness of automated vulnerability detection systems, particularly for Python source code. Talaya Farasat, Joachim Posegga |
BDCAT | 2 |
| 2024 | Machine Learning Techniques for Python Source Code Vulnerability DetectionabstractSoftware vulnerabilities are a fundamental reason for the prevalence of cyber attacks and their identification is a crucial yet challenging problem in cyber security. In this paper, we apply and compare different machine learning algorithms for source code vulnerability detection specifically for Python programming language. Our experimental evaluation demonstrates that our Bidirectional Long Short-Term Memory (BiLSTM) model achieves a remarkable performance (average Accuracy = 98.6%, average F-Score = 94.7%, average Precision = 96.2%, average Recall = 93.3%, average ROC = 99.3%), thereby, establishing a new benchmark for vulnerability detection in Python source code. Talaya Farasat, Joachim Posegga |
CODASPY | 2 |
| 2024 | MQfilTTr: Strengthening Smart Home Privacy Through MQTT Traffic Manipulation
Henrich Christopher Pöhls, Sven Gebauer, Fabian Scharnböck, Korbinian Spielvogel, Joachim Posegga |
WISTP | 5 |
| 2023 | Poster: SmartX BGP BVT: A First Real-Time BGP Blackholing Visibility ToolabstractBGP Blackholing is an effective mitigation solution for networks to counter the frequent Distributed Denial of Service (DDoS) attacks. It enables to drop all network traffic that is directed towards a particular victim prefix under DDoS attack, ideally, as close to the source as possible. Despite its huge importance in the Internet, there is no tool available for the real-time visualization of BGP Blackholing activity. Visualization is one of the most powerful techniques for network operators to monitor network activity. From discovering successful network topology to expose anomalous behaviors in networks, easy-to-use visualizations are powerful weapons to capture important patterns on the Internet traffic[1, 5]. In this work, we propose a first real-time BGP Blackholing Visibility Tool (named as SmartX BGP-BVT) to detect and visualize community based BGP Blackholing on live BGP data. This tool will be helpful for network operators and researchers interested in BGP Blackholing service and DDoS mitigation in the Internet. Talaya Farasat, Muhammad Ahmad Rathore, Zeeshan Asim, Akmal Khan, Jongwon Kim 0001, Joachim Posegga |
IMC | 6 |
| 2023 | Machine Learning-based BGP Traffic PredictionabstractAccurate Internet traffic predictions can provide support to network operators for applications such as traffic engineering, bandwidth allocation, anomaly detection, etc. We apply and compare different forecasting techniques (traditional and machine learning-based techniques) on real BGP data that is collected from two well-known Internet exchange points (IXPs) to derive BGP future volume-based predictions. Our experimental evaluation shows that multivariate Bayesian Ridge outperforms all other forecasting techniques we consider. Through univariate LSTM, we are able to predict new BGP volume-based features. Furthermore, to study the impact of dataset size on BGP forecasting, we perform experiments on three BGP dataset sizes, i.e., Short (one-month), Medium (three-months), and Long (five-months) Periods. Our results show that the Short-Period BGP dataset seems to be sufficient for getting accurate predictions. We also present a use case study (forecast Google Leak anomaly) that supports our experimental evaluations. We provide our collected BGP datasets publically which will be helpful to perform further research experiments and analysis regarding BGP traffic predictions. Talaya Farasat, Muhammad Ahmad Rathore, Akmal Khan, Jongwon Kim 0001, Joachim Posegga |
TrustCom | 5 |
| 2018 | RAPID: Resource and API-Based Detection Against In-Browser MinersabstractDirect access to the system's resources such as the GPU, persistent storage and networking has enabled in-browser crypto-mining. Thus, there has been a massive response by rogue actors who abuse browsers for mining without the user's consent. This trend has grown steadily for the last months until this practice, i.e., CryptoJacking, has been acknowledged as the number one security threat by several antivirus companies. Juan D. Parra Rodriguez, Joachim Posegga |
ACSAC | 2 |
| 2018 | CSP & Co. Can Save Us from a Rogue Cross-Origin Storage Browser Network! But for How Long?abstractWe introduce a new browser abuse scenario where an attacker uses local storage capabilities without the website's visitor knowledge to create a network of browsers for persistent storage and distribution of arbitrary data. We describe how security-aware users can use mechanisms such as the Content Security Policy (CSP), sandboxing, and third-party tracking protection, i.e., CSP & Company, to limit the network's effectiveness. From another point of view, we also show that the upcoming Suborigin standard can inadvertently thwart existing countermeasures, if it is adopted. Juan D. Parra Rodriguez, Joachim Posegga |
CODASPY | 2 |
| 2018 | When Your Browser Becomes the Paper Boy - An Anonymous Browser Network
Juan D. Parra Rodriguez, Eduard Brehm, Joachim Posegga |
SEC | 3 |
| 2018 | Local Storage on Steroids: Abusing Web Browsers for Hidden Content Storage and Distribution
Juan D. Parra Rodriguez, Joachim Posegga |
SecureComm (2) | 2 |
| 2015 | Why Web Servers Should Fear Their Clients - Abusing Websockets in Browsers for DoS
Juan D. Parra Rodriguez, Joachim Posegga |
SecureComm | 2 |
| 2014 | PhishSafe: leveraging modern JavaScript API's for transparent and robust protectionabstractThe term "phishing" describes a class of social engineering attacks on authentication systems, that aim to steal the victim's authentication credential, e.g., the username and password. The severity of phishing is recognized since the mid-1990's and a considerable amount of attention has been devoted to the topic. However, currently deployed or proposed countermeasures are either incomplete, cumbersome for the user, or incompatible with standard browser technology. In this paper, we show how modern JavaScript API's can be utilized to build PhishSafe, a robust authentication scheme, that is immune against phishing attacks, easily deployable using the current browser generation, and requires little change in the end-user's interaction with the application. We evaluate the implementation and find that it is applicable to web applications with low efforts and causes no tangible overhead. Bastian Braun, Martin Johns, Johannes Köstler, Joachim Posegga |
CODASPY | 4 |
| 2014 | Ghostrail: Ad Hoc Control-Flow Integrity for Web Applications
Bastian Braun, Caspar Gries, Benedikt Petschkuhn, Joachim Posegga |
SEC | 4 |
| 2014 | A Trusted UI for the Mobile Web
Bastian Braun, Johannes Köstler, Joachim Posegga, Martin Johns |
SEC | 3 |
| 2013 | Scope of Security Properties of Sanitizable Signatures RevisitedabstractSanitizable signature schemes allow for altering signed data in a signer-controlled way by a semi-trusted third party. This is contrary to standard digital signature schemes, which do not permit any modifications by any party without invalidating the signature. Due to transparency, a strong privacy notion, outsiders cannot see if the signature for a message was created by the signer or by the semi-trusted party. Accountability allows the signer to prove to outsiders if a message was original or touched by the semi-trusted party. Currently, block-level accountability requires to drop transparency. We allow for accountability for sanitizable signatures with transparency on the block-level. Additionally, we generalize the concept of block-level properties to groups. This offers a even more fine-grained control and leads to more efficient schemes. We prove that group-level definitions imply both the block-level and message-level notions. We derive a provably secure construction, achieving our enhanced notions. A further modification of our construction achieves efficient group-level non-interactive public accountability. This construction only requires a constant amount of signature generations to achieve this property. Finally, we have implemented our constructions and the scheme introduced by Brzuska et al. at PKC '09 and provide a detailed performance analysis of our reference implementations. Hermann de Meer, Henrich Christopher Pöhls, Joachim Posegga, Kai Samelin |
ARES | 3 |
| 2013 | Malleable Signatures for Resource Constrained Platforms
Henrich Christopher Pöhls, Stefan Peters, Kai Samelin, Joachim Posegga, Hermann de Meer |
WISTP | 4 |
| 2013 | URANOS: User-Guided Rewriting for Plugin-Enabled ANdroid ApplicatiOn Security
Daniel Schreckling, Stephan Huber, Focke Höhne, Joachim Posegga |
WISTP | 4 |
| 2013 | Security and privacy for digital ecosystems
Ioannis G. Askoxylakis, Mark Manulis, Joachim Posegga |
Inf. Secur. Tech. Rep. | 3 |
| 2012 | On Structural Signatures for Tree Data Structures
Kai Samelin, Henrich Christopher Pöhls, Arne Bilzhause, Joachim Posegga, Hermann de Meer |
ACNS | 4 |
| 2012 | Redactable Signatures for Independent Removal of Structure and Content
Kai Samelin, Henrich Christopher Pöhls, Arne Bilzhause, Joachim Posegga, Hermann de Meer |
ISPEC | 4 |
| 2012 | Flexible Redactable Signature Schemes for Trees - Extended Security Model and Construction
Henrich Christopher Pöhls, Kai Samelin, Hermann de Meer, Joachim Posegga |
SECRYPT | 4 |
| 2012 | A User-Level Authentication Scheme to Mitigate Web Session-Based Vulnerabilities
Bastian Braun, Stefan Kucher, Martin Johns, Joachim Posegga |
TrustBus | 4 |
| 2012 | WebSand: Server-Driven Outbound Web-Application Sandboxing
Martin Johns, Joachim Posegga |
TrustBus | 2 |
| 2012 | Kynoid: Real-Time Enforcement of Fine-Grained, User-Defined, and Data-Centric Security Policies for Android
Daniel Schreckling, Joachim Posegga, Johannes Köstler, Matthias Schaff |
WISTP | 2 |
| 2011 | Sanitizable Signatures in XML Signature - Performance, Mixing Properties, and Revisiting the Property of Transparency
Henrich Christopher Pöhls, Kai Samelin, Joachim Posegga |
ACNS | 3 |
| 2009 | The OPL Access Control Policy Language
Christopher Alm, Ruben Wolf, Joachim Posegga |
TrustBus | 3 |
| 2008 | XSSDS: Server-Side Detection of Cross-Site Scripting AttacksabstractCross-site scripting (XSS) has emerged to one of the most prevalent type of security vulnerabilities. While the reason for the vulnerability primarily lies on the server-side, the actual exploitation is within the victim's Web browser on the client-side. Therefore, an operator of a Web application has only very limited evidence of XSS issues. In this paper, we propose a passive detection system to identify successful XSS attacks. Based on a prototypical implementation, we examine our approach's accuracy and verify its detection capabilities. We compiled a data-set of 500.000 individual HTTP request/response-pairs from 95 popular web applications for this, in combination with both real word and manually crafted XSS-exploits; our detection approach results in a total of zero false negatives for all tests, while maintaining an excellent false positive rate for more than 80% of the examined Web applications. Martin Johns, Björn Engelmann 0001, Joachim Posegga |
ACSAC | 3 |
| 2007 | Advances in smart cards
Josep Domingo-Ferrer, Joachim Posegga, Francesc Sebé, Vicenç Torra |
Comput. Networks | 2 |
| 2006 | Smartcard Firewalls Revisited
Henrich Christopher Pöhls, Joachim Posegga |
CARDIS | 2 |
| 2004 | Secure mobile business applications - framework, architecture and implementation
Thomas Walter 0001, Laurent Bussard, Yves Roudier, Jochen Haller, Roger Kilian-Kehr, Joachim Posegga |
Inf. Secur. Tech. Rep. | 6 |
| 2002 | Smart Cards in Interaction: Towards Trustworthy Digital Signatures
Roger Kilian-Kehr, Joachim Posegga |
CARDIS | 2 |
| 2000 | How to Turn a GSM SIM into a Web Server
Scott B. Guthery, Roger Kehr, Joachim Posegga |
CARDIS | 3 |
| 1999 | Java Bytecode Verification by Model Checking
David A. Basin, Stefan Friedrich 0001, Joachim Posegga, Harald Vogt |
CAV | 3 |
| 1998 | System Description: card TAP: The First Theorem Prover on a Smart Card
Rajeev Goré, Joachim Posegga, Andrew Slater, Harald Vogt |
CADE | 2 |
| 1998 | Byte Code Verification for Java Smart Card Based on Model Checking
Joachim Posegga, Harald Vogt |
ESORICS | 1 |
| 1995 | leanTAP: Lean Tableau-based Deduction
Bernhard Beckert, Joachim Posegga |
J. Autom. Reason. | 2 |
| 1995 | Automated Deduction with Shannon GraphsabstractBinary decision diagrams (BDDs) are a well-known tool for representing Boolean functions. We show how BDDs can be extended to full first-order logic by integrating means for representing quantifiers. The resulting structures are called Shannon graphs. A calculus based on these Shannon graphs is set up, and its soundness and completeness proofs are outlined. A comparison of deduction with first-order BDDs and semantic tableaux shows that both calculi are closely related. From a practical perspective, however, BDDs have advantages over tableaux: they provide a more compact representation, since BDDs can be understood as a linear, graphical representation of a fully expanded tableaux. Furthermore, BDDs represent not only the models of a formula, but also its counter-models: this offers a very efficient way to represent lemmata during the proof search. The last part of the paper introduces a compilation-based approach to implementing deduction systems based on Shannon graphs. The idea is to compile the graphs into programs that carry out the proof search at run time. Joachim Posegga, Peter H. Schmitt |
J. Log. Comput. | 1 |
| 1994 | leanTAP: Lean Tableau-Based Theorem Proving (Extended Abstract)
Bernhard Beckert, Joachim Posegga |
CADE | 2 |
| 1994 | BDDs and Automated Deduction
Jean Goubault-Larrecq, Joachim Posegga |
ISMIS | 2 |
| 1993 | Compiling Proof Search in Semantic Tableaux
Joachim Posegga |
ISMIS | 1 |