Jasper Stang

dblp:295/8221 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
7since 2021 · last 2024
0009-0005-0329-5849ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 7 since 2021
YearPublicationVenuePosition
2024 Cloud-Based Machine Learning Models as Covert Communication Channels
abstract
While Machine Learning (ML) is one of the most promising technologies in our era, it is prone to a variety of attacks. One of them is covert channels, that enable two parties to stealthily transmit information through carriers intended for different purposes. Existing works only explore covert channels for federated ML. Thereby, communication is established among multiple entities that collaborate to train a model, while relying on access to model internals.
Torsten Krauß, Jasper Stang, Alexandra Dmitrienko
AsiaCCS2
2024 MirageFlow: A New Bandwidth Inflation Attack on Tor
Christoph Sendner, Jasper Stang, Alexandra Dmitrienko, Raveen Wijewickrama, Murtuza Jadliwala
NDSS2
2024 Large-Scale Study of Vulnerability Scanners for Ethereum Smart Contracts
abstract
Ethereum smart contracts, which are autonomous decentralized applications on the blockchain that manage assets often exceeding millions of dollars, have become primary targets for cyberattacks. In 2023 alone, such vulnerabilities led to substantial financial losses exceeding a billion US dollars. To counter these threats, various tools have been developed by academic and commercial entities to detect and mitigate vulnerabilities in smart contracts. Our study investigates the gap between the effectiveness of existing security scanners and the vulnerabilities that still persist in practice. We compiled four distinct datasets for this analysis. The first dataset comprises 77,219 source codes extracted directly from the blockchain, while the second includes over 4 million bytecodes obtained from Ethereum Mainnet and testnets. The other two datasets consist of nearly 14,000 manually annotated smart contracts and 373 smart contracts verified through audits, providing a foundation for a rigorous ground truth analysis on bytecode and source code. Using the unlabeled datasets, we conducted a comprehensive quantitative evaluation of 18 vulnerability scanners, revealing considerable discrepancies in their findings. Our analysis of the ground truth datasets indicated poor performance across all the tools we tested. This study unveils the reasons for poor performance and underscores that the current state of the art for smart contract security falls short in effectively addressing open problems, highlighting that the challenge of effectively detecting vulnerabilities remains a significant and unresolved issue.
Christoph Sendner, Lukas Petzi, Jasper Stang, Alexandra Dmitrienko
SP3
2024 Verify your Labels! Trustworthy Predictions and Datasets via Confidence Scores
Torsten Krauß, Jasper Stang, Alexandra Dmitrienko
USENIX Security Symposium2
2024 ClearStamp: A Human-Visible and Robust Model-Ownership Proof based on Transposed Model Training
Torsten Krauß, Jasper Stang, Alexandra Dmitrienko
USENIX Security Symposium2
2023 Smarter Contracts: Detecting Vulnerabilities in Smart Contracts with Deep Transfer Learning
Christoph Sendner, Huili Chen, Hossein Fereidooni, Lukas Petzi, Jan König, Jasper Stang, Alexandra Dmitrienko, Ahmad-Reza Sadeghi, Farinaz Koushanfar
NDSS6
2021 RIP StrandHogg: a practical StrandHogg attack detection method on Android
abstract
StrandHogg vulnerabilities affect Android's multitasking system and threaten up to 90% of Android platforms, which translates to millions of affected users. Existing countermeasures require modification of the OS, have usability drawbacks, or are limited to the detection of certain attack versions. In this work, we aim to develop a generic, efficient, and usability-friendly attack detection method, which does not require OS modifications and can be employed by apps installed on any vulnerable Android platform. To achieve our goal, we analyze StrandHogg attack techniques and develop two countermeasures, one using Machine Learning and the other one using ActivityCounter - a reliable attack indicator, which we could synthetically engineer. Our first approach achieves an average F1 score of 92% across all attack variations, while ActivityCounter shows superior performance and efficiently detects all attack versions without false positives. ActivityCounter is the first solution without practical limitations, which can be easily deployed in practice and protect millions of affected users.
Jasper Stang, Alexandra Dmitrienko, Sascha Roth
WISEC1