EDBT 2026 Demo / reviewers in the wild / expert
Martin Kotuliak
dblp:265/6132
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0002-5833-4447ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Finding Phones Fast: Low-Latency and Scalable Monitoring of Cellular Communications in Sensitive AreasabstractThe widespread availability of cellular devices introduces new threat vectors that allow users or attackers to bypass security policies and physical barriers and bring unauthorized devices into sensitive areas. These threats can arise from user non-compliance or deliberate actions aimed at data exfiltration/infiltration via hidden devices, drones, etc. We identify a critical gap in this context: the absence of low-latency systems for high-quality and instantaneous monitoring of cellular transmissions. Such low-latency systems are crucial to allow for timely detection, decision (e.g., geofencing or localization), and disruption of unauthorized communication in sensitive areas. Operator-based monitoring systems, built for purposes such as people counting or tracking, lack real-time capability, require cooperation across multiple operators, and thus are hard to deploy. Operator-independent monitoring approaches proposed in the literature either lack low-latency capabilities or do not scale. We propose WaveTag, the first low-latency, operator-independent, and scalable system designed to monitor 5G and LTE connections across all operators prior to any user data transmission. WaveTag consists of several downlink receivers and a distributed network of uplink receivers that measure both downlink protocol information and uplink signal characteristics at multiple locations to gain a detailed spatial image of uplink signals. WaveTag then aggregates the recorded information, processes it, and provides a decision about the connection before the UE completes connection establishment. To evaluate WaveTag, we deployed it in the context of geofencing, where WaveTag was able to determine whether the signals originate from inside or outside of an area within 2.3 ms of the initial base station-to-device message, therefore enabling prompt and targeted suppression of communication before any Martin Kotuliak, Simon Erni, Jakub Polák, Marc Röschlin, Richard Baker 0008, Ivan Martinovic, Srdjan Capkun |
WISEC | 1 |
| 2025 | Detecting IMSI-Catchers by Characterizing Identity Exposing Messages in Cellular Traffic
Tyler Tucker, Nathaniel Bennett, Martin Kotuliak, Simon Erni, Srdjan Capkun, Kevin R. B. Butler, Patrick Traynor |
NDSS | 3 |
| 2025 | GLaDoS: Location-aware Denial-of-Service of Cellular Networks
Simon Erni, Martin Kotuliak, Richard Baker 0008, Ivan Martinovic, Srdjan Capkun |
USENIX Security Symposium | 2 |
| 2022 | AdaptOver: adaptive overshadowing attacks in cellular networksabstractIn cellular networks, attacks on the communication link between a mobile device and the core network significantly impact privacy and availability. Up until now, fake base stations have been required to execute such attacks. Since they require a continuously high output power to attract victims, they are limited in range and can be easily detected both by operators and dedicated apps on users' smartphones. Simon Erni, Martin Kotuliak, Patrick Leu, Marc Röschlin, Srdjan Capkun |
MobiCom | 2 |
| 2022 | LTrack: Stealthy Tracking of Mobile Phones in LTE
Martin Kotuliak, Simon Erni, Patrick Leu, Marc Röschlin, Srdjan Capkun |
USENIX Security Symposium | 1 |
| 2021 | Security of Multicarrier Time-of-Flight RangingabstractOFDM is a widely used modulation scheme. It transmits data over multiple subcarriers in parallel, which provides high resilience against frequency-dependent channel drops (fading) and achieves high throughput. Due to the proliferation of OFDM-enabled devices and the increasing need for location information, the research community has suggested using OFDM symbols for secure (time-of-flight) distance measurements. However, a consequence of relying on multiple subcarriers is long symbols (time-wise). This makes OFDM systems not a natural fit for secure ranging, as long symbols allow an attacker longer observation and reaction times to mount a so-called early-detect/late-commit attack. Despite these concerns, a recent standardization effort (IEEE 802.11az [5]) envisions the use of OFDM-based signals for secure ranging. This paper lays the groundwork for analyzing OFDM time-of-flight measurements and studies the security guarantees of OFDM-based ranging against a physical-layer attacker. We use BPSK and 4-QAM, the most robust configurations, as examples to present a strategy that increases the chances for early-detecting the transmitted symbols. Our theoretical analysis and simulations show that such OFDM systems are vulnerable to early-detection/late-commit attacks, irrespective of frame length and number of subcarriers. We identify the underlying causes and explore a possible countermeasure, consisting of orthogonal noise and randomized phase. Patrick Leu, Martin Kotuliak, Marc Röschlin, Srdjan Capkun |
ACSAC | 2 |