EDBT 2026 Demo / reviewers in the wild / expert
Jonas Sander
dblp:340/3952
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2026
0009-0007-9402-823XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Prompt Pirates Need a Map: Stealing Seeds helps Stealing PromptsabstractDiffusion models have significantly advanced text-to-image generation, enabling the creation of highly realistic images and videos conditioned on textual prompts and seeds. Given the considerable intellectual and economic value embedded in such prompts, prompt theft poses a critical security and privacy concern. In this paper, we investigate prompt stealing attacks targeting diffusion models. We reveal that previous optimization-based prompt recovery methods are fundamentally limited as they do not account for the initial random noise used during image generation. Motivated by this observation, we show that the underlying random seed is uniquely identifiable in both image- and video-based diffusion models, enabling reliable seed recovery across modalities. We identify and exploit a noise-generation vulnerability (CWE-339), prevalent in major image-generation frameworks. Through a large-scale empirical analysis conducted on images shared via the popular platform CivitAI, we demonstrate that approximately 95% of these images' seed values can be effectively brute-forced in 8.5 minutes per image. Leveraging the recovered seed, we propose PromptPirate, an optimization-based approach for prompt stealing comprising two variants. The first variant achieves the strongest reconstruction performance, surpassing state-of-the-art methods by 8-11% in LPIPS similarity. The second, more computationally efficient variant attains slightly lower reconstruction quality but still outperforms prior work, enabling practical prompt stealing at a cost of $0.26-$0.35 per image. Furthermore, we introduce straightforward countermeasures that render seed stealing, and thus optimization-based prompt stealing, ineffective. We have disclosed our findings responsibly to address this critical vulnerability. Felix Mächtle, Ashwath Shetty, Jonas Sander, Nils Loose, Sören Pirk, Thomas Eisenbarth 0001 |
AsiaCCS | 3 |
| 2026 | BarkBeetle: Stealing Decision Tree Models with Fault InjectionabstractMachine learning (ML) models—particularly decision trees (DTs)—are widely adopted across various domains due to their interpretability and efficiency. However, as ML models become increasingly integrated into privacy-sensitive applications, concerns about their confidentiality have grown—particularly in light of emerging threats such as model extraction and fault injection attacks. Assessing the vulnerability of DTs under such attacks is therefore important. In this work, we present BarkBeetle, a novel model extraction attack that leverages fault injection to recover internal structural information of DT models under black-box settings. BarkBeetle employs a bottom-up recovery strategy that uses targeted fault injection at specific nodes to efficiently infer feature splits and threshold values. Our proof-of-concept implementation demonstrates that BarkBeetle requires significantly fewer queries and recovers more structural information compared to prior state-of-the-art approaches, when evaluated on DTs trained with public UCI datasets. To validate its practical feasibility, we implement BarkBeetle on a Raspberry Pi RP2350 microcontroller and perform fault injections using the Faultier voltage glitching tool. As BarkBeetle targets general DT models, we also provide an in-depth discussion on its applicability to a broader range of tree-based applications, including data stream classification, DT model variants, and tree-based cryptography schemes. Qifan Wang 0003, Jonas Sander, Minmin Jiang, Thomas Eisenbarth 0001, David Oswald |
AsiaCCS | 2 |
| 2025 | OCEAN: Open-World Contrastive Authorship Identification
Felix Mächtle, Jan-Niclas Serr, Nils Loose, Jonas Sander, Thomas Eisenbarth 0001 |
ACNS (2) | 4 |