EDBT 2026 Demo / reviewers in the wild / expert
Adrian Dabrowski
dblp:138/2614
· DBLP profile ↗
22ranked-venue papers
6as first author
13since 2021 · last 2025
0000-0002-0340-6204ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 5 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AirTag-Facilitated Stalking Protection: Evaluating Unwanted Tracking Notifications and Tracker Locating Features
Dañiel Gerhardt, Matthias Fassl, Carolyn Guthoff, Adrian Dabrowski, Katharina Krombholz |
USENIX Security Symposium | 4 |
| 2025 | Poster: SIMulator: SIM Tracing on a (Pico-)BudgetabstractSIM tracing - the ability to inspect, modify, and relay communication between a SIM card and modem - has become a significant technique in cellular network research. It enables essential security- and development-related applications such as fuzzing communication interfaces, extracting session keys, monitoring hidden SIM activity (e.g., proactive SIM commands or over-the-air updates), and facilitating scalable, distributed measurement platforms through SIM reuse. Traditionally, achieving these capabilities has relied on specialized hardware, which can pose financial and logistical burdens for researchers, particularly those new to the field. Gabriel K. Gegenhuber, Philipp É. Frenzel, Adrian Dabrowski |
WISEC | 3 |
| 2024 | Usable Authentication in Virtual Reality: Exploring the Usability of PINs and Gestures
H. T. M. A. Riyadh, Divyanshu Bhardwaj 0001, Adrian Dabrowski, Katharina Krombholz |
ACNS (3) | 3 |
| 2024 | Mental Models, Expectations and Implications of Client-Side Scanning: An Interview Study with ExpertsabstractClient-Side Scanning (CSS) is discussed as a potential solution to contain the dissemination of child sexual abuse material (CSAM). A significant challenge associated with this debate is that stakeholders have different interpretations of the capabilities and frontiers of the concept and its varying implementations. In this paper, we explore stakeholders’ understandings of the technology and the expectations and potential implications in the context of CSAM by conducting and analyzing 28 semi-structured interviews with a diverse sample of experts. We identified mental models of CSS and the expected challenges. Our results show that CSS is often a preferred solution in the child sexual abuse debate due to the lack of an alternative. Our findings illustrate the importance of further interdisciplinary discussions to define and comprehend the impact of CSS usage on society, particularly vulnerable groups such as children. Divyanshu Bhardwaj 0001, Carolyn Guthoff, Adrian Dabrowski, Sascha Fahl, Katharina Krombholz |
CHI | 3 |
| 2024 | In Focus, Out of Privacy: The Wearer's Perspective on the Privacy Dilemma of Camera GlassesabstractThe rising popularity of camera glasses challenges societal norms of recording bystanders and thus requires efforts to mediate privacy preferences. We present the first study on the wearers’ perspectives and explore privacy challenges associated with wearing camera glasses when bystanders are present. We conducted a micro-longitudinal diary study (N = 15) followed by exit interviews with existing users and people without prior experience. Our results show that wearers consider the currently available privacy indicators ineffective. They believe the looks and interaction design of the glasses conceal the technology from unaware people. Due to the lack of effective privacy-mediating measures, wearers feel emotionally burdened with preserving bystanders’ privacy. We furthermore elicit how this sentiment impacts their usage of camera glasses and highlight the need for technical and non-technical solutions. Finally, we compare the wearers’ and bystanders’ perspectives and discuss the design space of a future privacy-preserving ecosystem for wearable cameras. Divyanshu Bhardwaj 0001, Alexander Ponticello, Shreya Tomar, Adrian Dabrowski, Katharina Krombholz |
CHI | 4 |
| 2024 | Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi Deployments
Gabriel K. Gegenhuber, Florian Holzbauer, Philipp É. Frenzel, Edgar R. Weippl, Adrian Dabrowski |
USENIX Security Symposium | 5 |
| 2023 | Perceptions of Distributed Ledger Technology Key Management - An Interview Study with Finance ProfessionalsabstractKey management is an integral part of using distributed ledger technology (DLT). Previous work has primarily focused on key management for single-user scenarios on Bitcoin. Over the last decade, DLT has evolved to commercial and financial sectors; for example, a new German law allows the trading of a variety of financial securities via DLT. Instead of a single-user paradigm, financial institutions follow a multi-user paradigm. Combining multi-user key management with single-user key management solutions leads to unique challenges with usability and security. We extend current research through a two-stage qualitative interview study with 13 finance professionals. We investigate how the technical reality contrasts with perceptions of key management practices in corporate financial organizations. Our interdisciplinary study shows, among other things, that DLT does not meet real-world requirements in this particular domain. Moreover, it introduces additional challenges in terms of authentication and auditing. Our findings suggest that corporate financial institutions strongly support the adoption of blockchain solutions. However, to comply with regulatory and operational requirements, they face additional usability and security challenges, e.g., authentication and access control. Better mechanisms or novel design approaches are required to cover professional environments. This includes how multiple users can access the same assets and approve joint transactions. Carolyn Guthoff, Simon Anell, Johann Hainzinger, Adrian Dabrowski, Katharina Krombholz |
SP | 4 |
| 2023 | MobileAtlas: Geographically Decoupled Measurements in Cellular Networks for Security and Privacy Research
Gabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl, Adrian Dabrowski |
USENIX Security Symposium | 4 |
| 2023 | Investigating Verification Behavior and Perceptions of Visual Digital Certificates
Dañiel Gerhardt, Alexander Ponticello, Adrian Dabrowski, Katharina Krombholz |
USENIX Security Symposium | 3 |
| 2023 | To Cloud or not to Cloud: A Qualitative Study on Self-Hosters' Motivation, Operation, and Security Mindset
Lea Gröber, Rafael Mrowczynski, Nimisha Vijay, Daphne A. Muller, Adrian Dabrowski, Katharina Krombholz |
USENIX Security Symposium | 5 |
| 2023 | Investigating Security Folklore: A Case Study on the Tor over VPN PhenomenonabstractUsers face security folklore in their daily lives in the form of security advice, myths, and word-of-mouth stories. Using a VPN to access the Tor network, i.e., Tor over VPN, is an interesting example of security folklore because of its inconclusive security benefits and its occurrence in pop-culture media. Following the Theory of Reasoned Action, we investigated the phenomenon with three studies: (1) we quantified the behavior on real-world Tor traffic and measured a prevalence of 6.23%; (2) we surveyed users' intentions and beliefs, discovering that they try to protect themselves from the Tor network or increase their general security; and (3) we analyzed online information sources, suggesting that perceived norms and ease-of-use play a significant role while behavioral beliefs about the purpose and effect are less crucial in spreading security folklore. We discuss how to communicate security advice effectively and combat security misinformation and misconceptions. Matthias Fassl, Alexander Ponticello, Adrian Dabrowski, Katharina Krombholz |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | PKRU-safe: automatically locking down the heap between safe and unsafe languagesabstractAfter more than twenty-five years of research, memory safety violations remain one of the major causes of security vulnerabilities in real-world software. Memory-safe languages, like Rust, have demonstrated that compiler technology can assist developers in writing efficient low-level code without the risk of memory corruption. However, many memory-safe languages still have to interface with unsafe code to some extent, which opens up the possibility for attackers to exploit memory-corruption vulnerabilities in the unsafe part of the system and subvert the safety guarantees provided by the memory-safe language. Paul Kirth, Mitchel Dickerson, Stephen Crane, Per Larsen, Adrian Dabrowski, David Gens, Yeoul Na, Stijn Volckaert, Michael Franz |
EuroSys | 5 |
| 2021 | On the Usability of Authenticity Checks for Hardware Security Tokens
Katharina Pfeffer, Alexandra Mai, Adrian Dabrowski, Matthias Gusenbauer, Philipp Schindler, Edgar R. Weippl, Michael Franz, Katharina Krombholz |
USENIX Security Symposium | 3 |
| 2020 | BinRec: dynamic binary lifting and recompilationabstractBinary lifting and recompilation allow a wide range of install-time program transformations, such as security hardening, deobfuscation, and reoptimization. Existing binary lifting tools are based on static disassembly and thus have to rely on heuristics to disassemble binaries. Anil Altinay, Joseph Nash, Taddeus Kroes, Prabhu Rajasekaran, Dixin Zhou, Adrian Dabrowski, David Gens, Yeoul Na, Stijn Volckaert, Cristiano Giuffrida, Herbert Bos, Michael Franz |
EuroSys | 6 |
| 2019 | Measuring Cookies and Web Privacy in a Post-GDPR World
Adrian Dabrowski, Georg Merzdovnik, Johanna Ullrich, Gerald Sendera, Edgar R. Weippl |
PAM | 1 |
| 2018 | Proof-of-Blackouts? How Proof-of-Work Cryptocurrencies Could Affect Power Grids
Johanna Ullrich, Nicholas Stifter, Aljosha Judmayer, Adrian Dabrowski, Edgar R. Weippl |
RAID | 4 |
| 2017 | Grid Shock: Coordinated Load-Changing Attacks on Power Grids: The Non-Smart Power Grid is Vulnerable to Cyber Attacks as WellabstractElectric power grids are among the largest human-made control structures and are considered as critical infrastructure due to their importance for daily life. When operating a power grid, providers have to continuously maintain a balance between supply (i.e., production in power plants) and demand (i.e., power consumption) to keep the power grid's nominal frequency of 50 Hz or alternatively 60 Hz. Power consumption is forecast by elaborated models including multiple parameters like weather, season, and time of the day; they are based on the premise of many small consumers averaging out their energy consumption spikes. Adrian Dabrowski, Johanna Ullrich, Edgar R. Weippl |
ACSAC | 1 |
| 2016 | The Messenger Shoots Back: Network Operator Based IMSI Catcher Detection
Adrian Dabrowski, Georg Petzl, Edgar R. Weippl |
RAID | 1 |
| 2014 | Towards a Hardware Trojan Detection CycleabstractIntentionally inserted malfunctions in integrated circuits, referred to as Hardware Trojans, have become an emerging threat. Recently, the scientific community started to propose technical approaches to mitigate the threat of unspecified and potentially malicious functionality. However, these detection and prevention mechanisms are still hardly integrated in the industry's Hardware development life cycles. We therefore propose in this work a secure hardware development life cycle that assembles methods from trustworthy software engineering. In addition to full traceability from specification to implementation, and down to each gate, we introduce a feedback detection cycle that systematically escorts every single step of the development process. To do so, we integrate different detection methods for each development phase that are derived from a common knowledge base. Adrian Dabrowski, Heidelinde Hobel, Johanna Ullrich, Katharina Krombholz, Edgar R. Weippl |
ARES | 1 |
| 2014 | IMSI-catch me if you can: IMSI-catcher-catchersabstractIMSI Catchers are used in mobile networks to identify and eavesdrop on phones. When, the number of vendors increased and prices dropped, the device became available to much larger audiences. Self-made devices based on open source software are available for about US$ 1,500. Adrian Dabrowski, Nicola Pianta, Thomas Klepp, Martin Mulazzani, Edgar R. Weippl |
ACSAC | 1 |
| 2014 | Tag Detection for Preventing Unauthorized Face Image Processing
Alberto Escalada Jimenez, Adrian Dabrowski, Noboru Sonehara, Juan Manuel Montero-Martínez, Isao Echizen |
IWDW | 2 |
| 2013 | Framework Based on Privacy Policy Hiding for Preventing Unauthorized Face Image ProcessingabstractWe put forward a framework to address a problem created by the rapidly spreading use of imaging devices and related to involuntarily or unintentionally photographed individuals: their pictures can accumulate additional meta information via face recognition systems and can be manually tagged via social networks and publishing platforms. With this framework a user can express his/her picture privacy policy in a machine readable format and (to some extent) automatically enforce it. An easily understandable flag system is used to define restrictions on picture usage and link ability. This policy is encoded in an unobtrusive way into wardrobe patterns and accessory designs with almost no impact on apparel appearance or social interaction. Adrian Dabrowski, Edgar R. Weippl, Isao Echizen |
SMC | 1 |