EDBT 2026 Demo / reviewers in the wild / expert
Sergej Dechand
dblp:146/8228
· DBLP profile ↗
10ranked-venue papers
3as first author
1since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
8 papers |
Systems and software security · 64% Authentication and access control · 14% Usable security · 6% | |
| Software engineering, system software, and programming languages
4 papers |
Programming languages and type systems · 46% Empirical software engineering · 33% Compilers and program optimization · 11% |
Topics — the 17 heaviest of 22, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
1.2 | 2 | 2026 | Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem · SP 2026 VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code Audits · CCS 2015 |
Systems and software security › vulnerability discovery › fuzzing
coverage-guided fuzzing |
1.0 | 1 | 2026 | Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem · SP 2026 |
Systems and software security › vulnerability discovery
fuzzing |
1.0 | 1 | 2026 | Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem · SP 2026 |
Programming languages and type systems › object-oriented programming
java |
0.3 | 1 | 2026 | Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem · SP 2026 |
Authentication and access control
password authentication |
0.3 | 1 | 2017 | Why Do Developers Get Password Storage Wrong?: A Qualitative Usability Study · CCS 2017 |
Cryptographic primitives and cryptanalysis › hash functions
password hashing |
0.3 | 1 | 2017 | Why Do Developers Get Password Storage Wrong?: A Qualitative Usability Study · CCS 2017 |
Authentication and access control › password security
secure password storage |
0.3 | 1 | 2017 | Why Do Developers Get Password Storage Wrong?: A Qualitative Usability Study · CCS 2017 |
Systems and software security › reverse engineering
decompilation |
0.2 | 1 | 2016 | Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User Study · IEEE Symposium on Security and Privacy 2016 |
Systems and software security
reverse engineering |
0.2 | 1 | 2016 | Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User Study · IEEE Symposium on Security and Privacy 2016 |
Usable security
security tool usability |
0.2 | 1 | 2016 | Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User Study · IEEE Symposium on Security and Privacy 2016 |
Cryptographic protocols and secure computation
secure messaging |
0.2 | 1 | 2015 | SoK: Secure Messaging · IEEE Symposium on Security and Privacy 2015 |
Network security › secure communication › secure communication protocol
TLS |
0.2 | 1 | 2015 | To Pin or Not to Pin-Helping App Developers Bullet Proof Their TLS Connections · USENIX Security Symposium 2015 |
Empirical software engineering
mining software repositories |
0.2 | 1 | 2015 | VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code Audits · CCS 2015 |
Systems and software security
software supply chain security |
0.2 | 1 | 2014 | Hey, NSA: Stay Away from my Market! Future Proofing App Markets against Powerful Attackers · CCS 2014 |
Usable security › risk communication
security indicators |
0.1 | 1 | 2016 | An Empirical Study of Textual Key-Fingerprint Representations · USENIX Security Symposium 2016 |
Network security
anonymity networks |
0.1 | 1 | 2015 | SoK: Secure Messaging · IEEE Symposium on Security and Privacy 2015 |
Software maintenance and evolution
code review |
0.1 | 1 | 2015 | VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code Audits · CCS 2015 |
Methods — techniques the papers use, named apart from their topics
coverage-guided fuzzing · 2.0user study · 0.5semantics-preserving code transformation · 0.5support vector machine · 0.4code-metric analysis · 0.4qualitative usability study · 0.3transparency mechanism design · 0.2threat modeling · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem
Sergej Dechand, Tobias Wienand, Fabian Meumertzheim, Peter Samarin, Simon Resch, Khaled Yakdan, Thorsten Holz, Flavio Toffalini |
SP | 1 |
| 2019 | In Encryption We Don't Trust: The Effect of End-to-End Encryption to the Masses on User PerceptionabstractWith WhatsApp's adoption of the Signal Protocol as its default, end-to-end encryption by the masses happened almost overnight. Unlike iMessage, WhatsApp notifies users that encryption is enabled, explicitly informing users about improved privacy. This rare feature gives us an opportunity to study people's understandings and perceptions of secure messaging pre-and post-mass messenger encryption (pre/post-MME). To study changes in perceptions, we compared the results of two mental models studies: one conducted in 2015 pre-MME and one in 2017 post-MME. Our primary finding is that users do not trust encryption as currently offered. When asked about encryption in the study, most stated that they had heard of encryption, but only a few understood the implications, even on a high level. Their consensus view was that no technical solution to stop skilled attackers from getting their data exists. Even with a major development, such as WhatsApp rolling out end-to-end encryption, people still do not feel well protected by their technology. Surprisingly, despite WhatsApp's end-to-end security info messages and the high media attention, the majority of the participants were not even aware of encryption. Most participants had an almost correct threat model, but don't believe that there is a technical solution to stop knowledgeable attackers to read their messages. Using technology made them feel vulnerable. Sergej Dechand, Alena Naiakshina, Anastasia Danilova, Matthew Smith 0001 |
EuroS&P | 1 |
| 2017 | Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyabstractPasswords are still a mainstay of various security systems, as well as the cause of many usability issues. For end-users, many of these issues have been studied extensively, highlighting problems and informing design decisions for better policies and motivating research into alternatives. However, end-users are not the only ones who have usability problems with passwords! Developers who are tasked with writing the code by which passwords are stored must do so securely. Yet history has shown that this complex task often fails due to human error with catastrophic results. While an end-user who selects a bad password can have dire consequences, the consequences of a developer who forgets to hash and salt a password database can lead to far larger problems. In this paper we present a first qualitative usability study with 20 computer science students to discover how developers deal with password storage and to inform research into aiding developers in the creation of secure password systems. Alena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog, Sergej Dechand, Matthew Smith 0001 |
CCS | 5 |
| 2016 | Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User StudyabstractAnalysis of malicious software is an essential task in computer security, it provides the necessary understanding to devise effective countermeasures and mitigation strategies. The level of sophistication and complexity of current malware continues to evolve significantly, as the recently discovered "Regin" malware family strikingly illustrates. This complexity makes the already tedious and time-consuming task of manual malware reverse engineering even more difficult and challenging. Decompilation can accelerate this process by enabling analysts to reason about a high-level, more abstract from of binary code. While significant advances have been made, state-of-the-art decompilers still produce very complex and unreadable code and malware analysts still frequently go back to analyzing the assembly code. In this paper, we present several semantics-preserving code transformations to make the decompiled code more readable, thus helping malware analysts understand and combat malware. We have implemented our optimizations as extensions to the academic decompiler DREAM. To evaluate our approach, we conducted the first user study to measure the quality of decompilers for malware analysis. Our study includes 6 analysis tasks based on real malware samples we obtained from independent malware experts. We evaluate three decompilers: the leading industry decompiler Hex-Rays, the state-of-the-art academic decompiler DREAM, and our usability-optimized decompiler DREAM++. The results show that our readability improvements had a significant effect on how well our participants could analyze the malware samples. DREAM++ outperforms both Hex-Rays and DREAM significantly. Using DREAM++ participants solved 3x more tasks than when using Hex-Rays and 2x more tasks than when using DREAM. Khaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2016 | An Empirical Study of Textual Key-Fingerprint Representations
Sergej Dechand, Dominik Schürmann, Karoline Busse, Yasemin Acar, Sascha Fahl, Matthew Smith 0001 |
USENIX Security Symposium | 1 |
| 2015 | VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code AuditsabstractDespite the security community's best effort, the number of serious vulnerabilities discovered in software is increasing rapidly. In theory, security audits should find and remove the vulnerabilities before the code ever gets deployed. However, due to the enormous amount of code being produced, as well as a the lack of manpower and expertise, not all code is sufficiently audited. Thus, many vulnerabilities slip into production systems. A best-practice approach is to use a code metric analysis tool, such as Flawfinder, to flag potentially dangerous code so that it can receive special attention. However, because these tools have a very high false-positive rate, the manual effort needed to find vulnerabilities remains overwhelming. In this paper, we present a new method of finding potentially dangerous code in code repositories with a significantly lower false-positive rate than comparable systems. We combine code-metric analysis with metadata gathered from code repositories to help code review teams prioritize their work. The paper makes three contributions. First, we conducted the first large-scale mapping of CVEs to GitHub commits in order to create a vulnerable commit database. Second, based on this database, we trained a SVM classifier to flag suspicious commits. Compared to Flawfinder, our approach reduces the amount of false alarms by over 99 % at the same level of recall. Finally, we present a thorough quantitative and qualitative analysis of our approach and discuss lessons learned from the results. We will share the database as a benchmark for future research and will also provide our analysis tool as a web service. Henning Perl, Sergej Dechand, Matthew Smith 0001, Daniel Arp, Fabian Yamaguchi, Konrad Rieck, Sascha Fahl, Yasemin Acar |
CCS | 2 |
| 2015 | SoK: Secure MessagingabstractMotivated by recent revelations of widespread state surveillance of personal communication, many solutions now claim to offer secure and private messaging. This includes both a large number of new projects and many widely adopted tools that have added security features. The intense pressure in the past two years to deliver solutions quickly has resulted in varying threat models, incomplete objectives, dubious security claims, and a lack of broad perspective on the existing cryptographic literature on secure communication. In this paper, we evaluate and systematize current secure messaging solutions and propose an evaluation framework for their security, usability, and ease-of-adoption properties. We consider solutions from academia, but also identify innovative and promising approaches used "in-the-wild" that are not considered by the academic literature. We identify three key challenges and map the design landscape for each: trust establishment, conversation security, and transport privacy. Trust establishment approaches offering strong security and privacy features perform poorly from a usability and adoption perspective, whereas some hybrid approaches that have not been well studied in the academic literature might provide better trade-offs in practice. In contrast, once trust is established, conversation security can be achieved without any user involvement in most two-party conversations, though conversations between larger groups still lack a good solution. Finally, transport privacy appears to be the most difficult problem to solve without paying significant performance penalties. Nik Unger, Sergej Dechand, Joseph Bonneau, Sascha Fahl, Henning Perl, Ian Goldberg 0001, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2015 | To Pin or Not to Pin-Helping App Developers Bullet Proof Their TLS Connections
Marten Oltrogge, Yasemin Acar, Sergej Dechand, Matthew Smith 0001, Sascha Fahl |
USENIX Security Symposium | 3 |
| 2014 | Hey, NSA: Stay Away from my Market! Future Proofing App Markets against Powerful AttackersabstractMobile devices are evolving as the dominant computing platform and consequently application repositories and app markets are becoming the prevalent paradigm for deploying software. Due to their central and trusted position in the software ecosystem, coerced, hacked or malicious app markets pose a serious threat to user security. Currently, there is little that hinders a nation state adversary (NSA) or other powerful attackers from using such central and trusted points of software distribution to deploy customized (malicious) versions of apps to specific users. Due to intransparencies in the current app installation paradigm, this kind of attack is extremely hard to detect. Sascha Fahl, Sergej Dechand, Henning Perl, Felix Fischer 0001, Jaromir Smrcek, Matthew Smith 0001 |
CCS | 2 |
| 2014 | Quantifiable Run-Time Kernel Attack Surface Reduction
Anil Kurmus, Sergej Dechand, Rüdiger Kapitza |
DIMVA | 2 |