EDBT 2026 Demo / reviewers in the wild / expert
Alwin Maier
dblp:165/5503
· DBLP profile ↗
5ranked-venue papers
2as first author
1since 2021 · last 2024
0009-0009-6102-5424ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Systems and software security · 92% Security and privacy of machine learning · 8% | |
| Software engineering, system software, and programming languages
2 papers |
Empirical software engineering · 74% Program analysis · 26% |
Topics — the 9 heaviest of 10, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
0.5 | 2 | 2016 | Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit Platforms · CCS 2016 Automatic Inference of Search Patterns for Taint-Style Vulnerabilities · IEEE Symposium on Security and Privacy 2015 |
Empirical software engineering › mining software repositories › source-code mining
code authorship attribution |
0.4 | 1 | 2019 | Misleading Authorship Attribution of Source Code using Adversarial Learning · USENIX Security Symposium 2019 |
Systems and software security › vulnerability discovery
integer overflow vulnerabilities |
0.2 | 1 | 2016 | Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit Platforms · CCS 2016 |
Systems and software security
memory safety |
0.2 | 1 | 2016 | Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit Platforms · CCS 2016 |
Systems and software security › information flow tracking
taint analysis |
0.2 | 1 | 2015 | Automatic Inference of Search Patterns for Taint-Style Vulnerabilities · IEEE Symposium on Security and Privacy 2015 |
Security and privacy of machine learning
adversarial machine learning |
0.1 | 1 | 2019 | Misleading Authorship Attribution of Source Code using Adversarial Learning · USENIX Security Symposium 2019 |
Systems and software security
exploitation |
0.1 | 1 | 2016 | Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit Platforms · CCS 2016 |
Program analysis › program representation
code property graph |
0.1 | 1 | 2015 | Automatic Inference of Search Patterns for Taint-Style Vulnerabilities · IEEE Symposium on Security and Privacy 2015 |
Program analysis
static analysis |
0.1 | 1 | 2015 | Automatic Inference of Search Patterns for Taint-Style Vulnerabilities · IEEE Symposium on Security and Privacy 2015 |
Methods — techniques the papers use, named apart from their topics
adversarial learning · 0.8code property graph traversal · 0.4empirical study · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | On the Role of Pre-trained Embeddings in Binary Code AnalysisabstractDeep learning has enabled remarkable progress in binary code analysis. In particular, pre-trained embeddings of assembly code have become a gold standard for solving analysis tasks, such as measuring code similarity or recognizing functions. These embeddings are capable of learning a vector representation from unlabeled code. In contrast to natural language processing, however, label information is not scarce for many tasks in binary code analysis. For example, labeled training data for function boundaries, optimization levels, and argument types can be easily derived from debug information provided by a compiler. Consequently, the main motivation of embeddings does not transfer directly to binary code analysis. Alwin Maier, Felix Weißberg, Konrad Rieck |
AsiaCCS | 1 |
| 2019 | TypeMiner: Recovering Types in Binary Programs Using Machine Learning
Alwin Maier, Hugo Gascon, Christian Wressnegger, Konrad Rieck |
DIMVA | 1 |
| 2019 | Misleading Authorship Attribution of Source Code using Adversarial Learning
Erwin Quiring, Alwin Maier, Konrad Rieck |
USENIX Security Symposium | 2 |
| 2016 | Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit PlatformsabstractSubtle flaws in integer computations are a prime source for exploitable vulnerabilities in system code. Unfortunately, even code shown to be secure on one platform can be vulnerable on another, making the migration of code a notable security challenge. In this paper, we provide the first study on how code that works as expected on 32-bit platforms can become vulnerable on 64-bit platforms. To this end, we systematically review the effects of data model changes between platforms. We find that the larger width of integer types and the increased amount of addressable memory introduce previously non-existent vulnerabilities that often lie dormant in program code. We empirically evaluate the prevalence of these flaws on the source code of Debian stable ("Jessie") and 200 popular open-source projects hosted on GitHub. Moreover, we discuss 64-bit migration vulnerabilities that have been discovered as part of our study, including vulnerabilities in Chromium, the Boost C++ Libraries, libarchive, the Linux Kernel, and zlib. Christian Wressnegger, Fabian Yamaguchi, Alwin Maier, Konrad Rieck |
CCS | 3 |
| 2015 | Automatic Inference of Search Patterns for Taint-Style VulnerabilitiesabstractTaint-style vulnerabilities are a persistent problem in software development, as the recently discovered "Heart bleed" vulnerability strikingly illustrates. In this class of vulnerabilities, attacker-controlled data is passed unsanitized from an input source to a sensitive sink. While simple instances of this vulnerability class can be detected automatically, more subtle defects involving data flow across several functions or project-specific APIs are mainly discovered by manual auditing. Different techniques have been proposed to accelerate this process by searching for typical patterns of vulnerable code. However, all of these approaches require a security expert to manually model and specify appropriate patterns in practice. In this paper, we propose a method for automatically inferring search patterns for taint-style vulnerabilities in C code. Given a security-sensitive sink, such as a memory function, our method automatically identifies corresponding source-sink systems and constructs patterns that model the data flow and sanitization in these systems. The inferred patterns are expressed as traversals in a code property graph and enable efficiently searching for unsanitized data flows -- across several functions as well as with project-specific APIs. We demonstrate the efficacy of this approach in different experiments with 5 open-source projects. The inferred search patterns reduce the amount of code to inspect for finding known vulnerabilities by 94.9% and also enable us to uncover 8 previously unknown vulnerabilities. Fabian Yamaguchi, Alwin Maier, Hugo Gascon, Konrad Rieck |
IEEE Symposium on Security and Privacy | 2 |