EDBT 2026 Demo / reviewers in the wild / expert
Ivo Sluganovic
dblp:130/3410
· DBLP profile ↗
9ranked-venue papers
4as first author
3since 2021 · last 2025
0000-0003-2483-7932ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 2 since 2021Computer networks · 2Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Stop the Clock - Counteracting Bias Exploited by Attackers through an Interactive Augmented Reality Phishing Training
Lorin Schöni, Martin Strohmeier, Ivo Sluganovic, Verena Zimmermann |
CHI | 3 |
| 2022 | WatchAuth: User Authentication and Intent Recognition in Mobile Payments using a SmartwatchabstractIn this paper, we show that the tap gesture, performed when a user ‘taps’ a smartwatch onto an NFC-enabled terminal to make a payment, is a biometric capable of implicitly authenticating the user and simultaneously recognising intent-to-pay. The proposed system can be deployed purely in software on the watch without requiring updates to payment terminals. It is agnostic to terminal type and position and the intent recognition portion does not require any training data from the user. To validate the system, we conduct a user study (n=16) to collect wrist motion data from users as they interact with payment terminals and to collect long-term data from a subset of them ($\mathrm{n}=9$) as they perform daily activities. Based on this data, we identify optimum gesture parameters and develop authentication and intent recognition models, for which we achieve EERs of 0.08 and 0.04, respectively. Jack Sturgess, Simon Eberz, Ivo Sluganovic, Ivan Martinovic |
EuroS&P | 3 |
| 2021 | SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial Perturbations
Giulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier, Ivan Martinovic |
USENIX Security Symposium | 3 |
| 2020 | Tap-Pair: Using Spatial Secrets for Single-Tap Device Pairing of Augmented Reality HeadsetsabstractAugmented Reality (AR) headsets, which allow for a realistic integration between the physical environment and virtual objects, are rapidly coming to customer and enterprise markets. This is largely because they enable a broad range of multi-user applications in which all participants experience the same augmentation of their natural surrounding. However, despite their increasing expansion, there currently exist no implemented methods for secure ad-hoc device pairing of multiple AR headsets. Given the importance of multi-user experiences for future applications of this technology, in this paper we propose two distinct ways to establish secure ad-hoc connections that rely only on typical user interactions in AR: gazing and tapping either at the location of a shared point on the wall or towards the user with whom one wants to connect. To show the feasibility and deployability of the proposed system to existing technology, we build a prototype of Tap-Pair, a system for ad-hoc pairing of AR headsets that is based on Password Authenticated Key Exchange protocols, requires only user interactions that are common in AR, and can be extended to more than two users. The experimental evaluation of the Tap-Pair prototype in a series of measurements at three different locations confirms the feasibility of our proposal, showing that the system built with currently available augmented reality headsets indeed achieves successful pairing in more than 90% of attempts, while keeping the probability of the attacker's success lower than 1e-3. Ivo Sluganovic, Mihael Liskij, Ante Derek, Ivan Martinovic |
CODASPY | 1 |
| 2019 | Analysis of Reflexive Eye Movements for Fast Replay-Resistant Biometric AuthenticationabstractEye tracking devices have recently become increasingly popular as an interface between people and cons-umer-grade electronic devices. Due to the fact that human eyes are fast, responsive, and carry information unique to an individual, analyzing person’s gaze is particularly attractive for rapid biometric authentication. Unfortunately, previous proposals for gaze-based authentication systems either suffer from high error rates or requires long authentication times. We build on the fact that some eye movements can be reflexively and predictably triggered and develop an interactive visual stimulus for elicitation of reflexive eye movements that support the extraction of reliable biometric features in a matter of seconds, without requiring any memorization or cognitive effort on the part of the user. As an important benefit, our stimulus can be made unique for every authentication attempt and thus incorporated in a challenge-response biometric authentication system. This allows us to prevent replay attacks, which are possibly the most applicable attack vectors against biometric authentication. Using a gaze tracking device, we build a prototype of our system and perform a series of systematic user experiments with 30 participants from the general public. We thoroughly analyze various system parameters and evaluate the performance and security guarantees under several different attack scenarios. The results show that our system matches or surpasses existing gaze-based authentication methods in achieved equal error rates (6.3%) while achieving significantly lower authentication times (5s). Ivo Sluganovic, Marc Röschlin, Kasper Bonne Rasmussen, Ivan Martinovic |
ACM Trans. Priv. Secur. | 1 |
| 2017 | HoloPair: Securing Shared Augmented Reality Using Microsoft HoloLensabstractAugmented Reality (AR) devices continuously scan their environment in order to naturally overlay virtual objects onto user's view of the physical world. In contrast to Virtual Reality, where one's environment is fully replaced with a virtual one, one of AR's "killer features" is co-located collaboration, in which multiple users interact with the same combination of virtual and real objects. Microsoft recently released HoloLens, the first consumer-ready augmented reality headset that needs no outside markers to achieve precise inside-out spatial mapping, which allows centimeter-scale hologram positioning. Ivo Sluganovic, Matej Serbec, Ante Derek, Ivan Martinovic |
ACSAC | 1 |
| 2017 | Implementing Prover-Side Proximity Verification for Strengthening Transparent AuthenticationabstractTransparent authentication schemes based on proximity verification over a wireless channel are susceptible to relay attacks. In recent literature several countermeasures have been proposed. However these come with drawbacks in terms of usability and deployability. In this demo, we show a prototype implementation of STASH, a scheme for securing transparent authentication schemes using prover-side proximity verification, presented at SECON 2017. Mika Juuti, Christian Vaas, Hans Liljestrand, Ivo Sluganovic, N. Asokan, Ivan Martinovic |
SECON | 4 |
| 2017 | STASH: Securing Transparent Authentication Schemes Using Prover-Side Proximity VerificationabstractTransparent authentication (TA) schemes are those in which a user's prover device authenticates him to a verifier without requiring explicit user interaction. By doing so, those schemes promise high usability and security simultaneously. Most TA implementations rely on the received signal strength as an indicator of the proximity of a user device (prover). However, such implicit proximity verification is not secure against an adversary who can relay messages over a larger distance. In this paper, we propose a novel approach for thwarting relay attacks on TA schemes: the prover permits access to authentication credentials only if it can confirm that it is near the verifier. We present STASH, a system for relay-resilient transparent authentication in which the prover does proximity verification by comparing its approach trajectory towards the intended verifier, with known authorized reference trajectories. Trajectories are measured using low-cost sensors commonly available on personal devices. By analyzing empirical data, collected using a STASH prototype, we demonstrate the security of STASH against a class of adversaries and its ease-of-use. STASH is efficient and can be easily integrated to complement existing TA schemes. Mika Juuti, Christian Vaas, Ivo Sluganovic, Hans Liljestrand, N. Asokan, Ivan Martinovic |
SECON | 3 |
| 2016 | Using Reflexive Eye Movements for Fast Challenge-Response AuthenticationabstractEye tracking devices have recently become increasingly popular as an interface between people and consumer-grade electronic devices. Due to the fact that human eyes are fast, responsive, and carry information unique to an individual, analyzing person's gaze is particularly attractive for effortless biometric authentication. Unfortunately, previous proposals for gaze-based authentication systems either suffer from high error rates, or require long authentication times. Ivo Sluganovic, Marc Röschlin, Kasper Bonne Rasmussen, Ivan Martinovic |
CCS | 1 |