EDBT 2026 Demo / reviewers in the wild / expert
Richard Baker 0008
dblp:13/4585-8
· DBLP profile ↗
10ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-8215-1053ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Finding Phones Fast: Low-Latency and Scalable Monitoring of Cellular Communications in Sensitive AreasabstractThe widespread availability of cellular devices introduces new threat vectors that allow users or attackers to bypass security policies and physical barriers and bring unauthorized devices into sensitive areas. These threats can arise from user non-compliance or deliberate actions aimed at data exfiltration/infiltration via hidden devices, drones, etc. We identify a critical gap in this context: the absence of low-latency systems for high-quality and instantaneous monitoring of cellular transmissions. Such low-latency systems are crucial to allow for timely detection, decision (e.g., geofencing or localization), and disruption of unauthorized communication in sensitive areas. Operator-based monitoring systems, built for purposes such as people counting or tracking, lack real-time capability, require cooperation across multiple operators, and thus are hard to deploy. Operator-independent monitoring approaches proposed in the literature either lack low-latency capabilities or do not scale. We propose WaveTag, the first low-latency, operator-independent, and scalable system designed to monitor 5G and LTE connections across all operators prior to any user data transmission. WaveTag consists of several downlink receivers and a distributed network of uplink receivers that measure both downlink protocol information and uplink signal characteristics at multiple locations to gain a detailed spatial image of uplink signals. WaveTag then aggregates the recorded information, processes it, and provides a decision about the connection before the UE completes connection establishment. To evaluate WaveTag, we deployed it in the context of geofencing, where WaveTag was able to determine whether the signals originate from inside or outside of an area within 2.3 ms of the initial base station-to-device message, therefore enabling prompt and targeted suppression of communication before any Martin Kotuliak, Simon Erni, Jakub Polák, Marc Röschlin, Richard Baker 0008, Ivan Martinovic, Srdjan Capkun |
WISEC | 5 |
| 2025 | GLaDoS: Location-aware Denial-of-Service of Cellular Networks
Simon Erni, Martin Kotuliak, Richard Baker 0008, Ivan Martinovic, Srdjan Capkun |
USENIX Security Symposium | 3 |
| 2023 | Brokenwire : Wireless Disruption of CCS Electric Vehicle Charging
Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic |
NDSS | 2 |
| 2022 | Signal Injection Attacks against CCD Image SensorsabstractSince cameras have become a crucial part in many safety-critical systems and applications, such as autonomous vehicles and surveillance, a large body of academic and non-academic work has shown attacks against their main component --- the image sensor. However, these attacks are limited to coarse-grained and often suspicious injections because light is used as an attack vector. Furthermore, due to the nature of optical attacks, they require the line-of-sight between the adversary and the target camera. Sebastian Köhler 0005, Richard Baker 0008, Ivan Martinovic |
AsiaCCS | 2 |
| 2022 | Demo: End-to-End Wireless Disruption of CCS EV ChargingabstractThe shift from vehicles with internal combustion engines (ICE) to fully Electric Vehicles (EVs) is happening at a rapid pace. To be competitive with ICEs and ensure a smooth rollout, the charging process of EVs needs to be as fast and convenient as possible. Modern DC fast-charging standards achieve this by implementing a high-level charging communication (HLC), which enables a safe, efficient, and convenient charging experience. Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic |
CCS | 2 |
| 2021 | They See Me Rollin': Inherent Vulnerability of the Rolling Shutter in CMOS Image SensorsabstractIn this paper, we describe how the electronic rolling shutter in CMOS image sensors can be exploited using a bright, modulated light source (e.g., an inexpensive, off-the-shelf laser), to inject fine-grained image disruptions. We demonstrate the attack on seven different CMOS cameras, ranging from cheap IoT to semi-professional surveillance cameras, to highlight the wide applicability of the rolling shutter attack. We model the fundamental factors affecting a rolling shutter attack in an uncontrolled setting. We then perform an exhaustive evaluation of the attack’s effect on the task of object detection, investigating the effect of attack parameters. We validate our model against empirical data collected on two separate cameras, showing that by simply using information from the camera’s datasheet the adversary can accurately predict the injected distortion size and optimize their attack accordingly. We find that an adversary can hide up to 75% of objects perceived by state-of-the-art detectors by selecting appropriate attack parameters. We also investigate the stealthiness of the attack in comparison to a naïve camera blinding attack, showing that common image distortion metrics can not detect the attack presence. Therefore, we present a new, accurate and lightweight enhancement to the backbone network of an object detector to recognize rolling shutter attacks. Overall, our results indicate that rolling shutter attacks can substantially reduce the performance and reliability of vision-based intelligent systems. Sebastian Köhler 0005, Giulio Lovisotto, Simon Birnbach, Richard Baker 0008, Ivan Martinovic |
ACSAC | 4 |
| 2021 | #PrettyFlyForAWiFi: Real-world Detection of Privacy Invasion Attacks by DronesabstractDrones are becoming increasingly popular for hobbyists and recreational use. But with this surge in popularity comes increased risk to privacy as the technology makes it easy to spy on people in otherwise-private environments, such as an individual’s home. An attacker can fly a drone over fences and walls to observe the inside of a house, without having physical access. Existing drone detection systems require specialist hardware and expensive deployment efforts, making them inaccessible to the general public. In this work, we present a drone detection system that requires minimal prior configuration and uses inexpensive commercial off-the-shelf hardware to detect drones that are carrying out privacy invasion attacks. We use a model of the attack structure to derive statistical metrics for movement and proximity that are then applied to received communications between a drone and its controller. We test our system in real-world experiments with two popular consumer drone models mounting privacy invasion attacks using a range of flight patterns. We are able both to detect the presence of a drone and to identify which phase of the privacy attack was in progress while being resistant to false positives from other mobile transmitters. For line-of-sight approaches using our kurtosis-based method, we are able to detect all drones at a distance of 6 m, with the majority of approaches detected at 25 m or farther from the target window without suffering false positives for stationary or mobile non-drone transmitters. Simon Birnbach, Richard Baker 0008, Simon Eberz, Ivan Martinovic |
ACM Trans. Priv. Secur. | 2 |
| 2019 | Losing the Car Keys: Wireless PHY-Layer Insecurity in EV Charging
Richard Baker 0008, Ivan Martinovic |
USENIX Security Symposium | 1 |
| 2018 | EMPower: Detecting Malicious Power Line Networks from EM Emissions
Richard Baker 0008, Ivan Martinovic |
SEC | 1 |
| 2017 | Wi-Fly?: Detecting Privacy Invasion Attacks by Consumer Drones
Simon Birnbach, Richard Baker 0008, Ivan Martinovic |
NDSS | 2 |