Torsten Krauß

dblp:331/2127 · DBLP profile ↗
← Back
12ranked-venue papers
7as first author
12since 2021 · last 2026
0000-0003-0810-6646ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 7 first-author · 11 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 FLux: Covert Channels in FL through Transposed Training
abstract
Federated learning (FL) routinely exchanges model-derived signals (e.g., logits or updates) between clients and a server, creating an attractive substrate for covert communication — especially in settings where adversaries cannot rely on direct, out-of-band coordination. Existing FL covert channels often trade off capacity, reliability under aggregation, setup requirements, or operational stealth (e.g., needing extensive pre-shared state, warm-up rounds, or leaving persistent artifacts).
Alexandra Dmitrienko, Torsten Krauß, Yisroel Mirsky
AsiaCCS2
2026 Memory Backdoor Attacks on Neural Networks
Eden Luzon, Guy Amit, Roy Weiss, Torsten Krauß, Alexandra Dmitrienko, Yisroel Mirsky
NDSS4
2025 AuthentiSafe: Lightweight and Future-Proof Device-to-Device Authentication for IoT
Lukas Petzi, Torsten Krauß, Alexandra Dmitrienko, Gene Tsudik
AsiaCCS2
2025 Sibai: A Few-Shot Meta-Classifier for Poisoning Detection in Federated Learning
Melanie Gotz, Torsten Krauß, Alexandra Dmitrienko
ICCV2
2025 TwinBreak: Jailbreaking LLM Security Alignments based on Twin Prompts
Torsten Krauß, Hamid Dashtbani, Alexandra Dmitrienko
USENIX Security Symposium1
2024 Cloud-Based Machine Learning Models as Covert Communication Channels
abstract
While Machine Learning (ML) is one of the most promising technologies in our era, it is prone to a variety of attacks. One of them is covert channels, that enable two parties to stealthily transmit information through carriers intended for different purposes. Existing works only explore covert channels for federated ML. Thereby, communication is established among multiple entities that collaborate to train a model, while relying on access to model internals.
Torsten Krauß, Jasper Stang, Alexandra Dmitrienko
AsiaCCS1
2024 Automatic Adversarial Adaption for Stealthy Poisoning Attacks in Federated Learning
Torsten Krauß, Jan König, Alexandra Dmitrienko, Christian Kanzow
NDSS1
2024 CrowdGuard: Federated Backdoor Detection in Federated Learning
Phillip Rieger, Torsten Krauß, Markus Miettinen, Alexandra Dmitrienko, Ahmad-Reza Sadeghi
NDSS2
2024 Verify your Labels! Trustworthy Predictions and Datasets via Confidence Scores
Torsten Krauß, Jasper Stang, Alexandra Dmitrienko
USENIX Security Symposium1
2024 ClearStamp: A Human-Visible and Robust Model-Ownership Proof based on Transposed Model Training
Torsten Krauß, Jasper Stang, Alexandra Dmitrienko
USENIX Security Symposium1
2023 MESAS: Poisoning Defense for Federated Learning Resilient against Adaptive Attackers
abstract
Federated Learning (FL) enhances decentralized machine learning by safeguarding data privacy, reducing communication costs, and improving model performance with diverse data sources. However, FL faces vulnerabilities such as untargeted poisoning attacks and targeted backdoor attacks, posing challenges to model integrity and security. Preventing backdoors proves especially challenging due to their stealthy nature. Existing mitigation techniques have shown efficacy but often overlook realistic adversaries and diverse data distributions.
Torsten Krauß, Alexandra Dmitrienko
CCS1
2023 Security of NVMe Offloaded Data in Large-Scale Machine Learning
Torsten Krauß, Raphael Götz, Alexandra Dmitrienko
ESORICS (4)1