Felix Mächtle

dblp:346/4790 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
7since 2021 · last 2026
0009-0009-2431-0322ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Trace Gadgets: Minimizing Code Context for Machine Learning-Based Vulnerability Prediction
abstract
As the number of web applications and API endpoints exposed to the Internet continues to grow, so does the number of exploitable vulnerabilities. Manually identifying such vulnerabilities is tedious. Meanwhile, static security scanners tend to produce many false positives. While machine learning-based approaches are promising, they typically perform well only in scenarios where training and test data are closely related. A key challenge for ML-based vulnerability detection is providing suitable and concise code context, as excessively long contexts negatively affect the code comprehension capabilities of machine learning models, particularly smaller ones. This work introduces Trace Gadgets, a novel code representation that minimizes code context by removing non-related code. Trace Gadgets precisely capture the statements that cover the path to the vulnerability. As input for ML models, Trace Gadgets provide a minimal but complete context, thereby improving the detection performance. Moreover, we collect a large-scale dataset generated from real-world applications with manually curated labels to further improve the performance of ML-based vulnerability detectors. Our results show that state-of-the-art machine learning models perform best when using Trace Gadgets compared to previous code representations, surpassing the detection capabilities of industry-standard static scanners such as GitHub's CodeQL by at least 4% on a fully unseen dataset. By applying our framework to real-world applications, we identify and report previously unknown vulnerabilities in widely deployed software.
Felix Mächtle, Nils Loose, Tim Schulz, Florian Sieck, Jan-Niclas Serr, Ralf Möller 0001, Thomas Eisenbarth 0001
AsiaCCS1
2026 Prompt Pirates Need a Map: Stealing Seeds helps Stealing Prompts
abstract
Diffusion models have significantly advanced text-to-image generation, enabling the creation of highly realistic images and videos conditioned on textual prompts and seeds. Given the considerable intellectual and economic value embedded in such prompts, prompt theft poses a critical security and privacy concern. In this paper, we investigate prompt stealing attacks targeting diffusion models. We reveal that previous optimization-based prompt recovery methods are fundamentally limited as they do not account for the initial random noise used during image generation. Motivated by this observation, we show that the underlying random seed is uniquely identifiable in both image- and video-based diffusion models, enabling reliable seed recovery across modalities. We identify and exploit a noise-generation vulnerability (CWE-339), prevalent in major image-generation frameworks. Through a large-scale empirical analysis conducted on images shared via the popular platform CivitAI, we demonstrate that approximately 95% of these images' seed values can be effectively brute-forced in 8.5 minutes per image. Leveraging the recovered seed, we propose PromptPirate, an optimization-based approach for prompt stealing comprising two variants. The first variant achieves the strongest reconstruction performance, surpassing state-of-the-art methods by 8-11% in LPIPS similarity. The second, more computationally efficient variant attains slightly lower reconstruction quality but still outperforms prior work, enabling practical prompt stealing at a cost of $0.26-$0.35 per image. Furthermore, we introduce straightforward countermeasures that render seed stealing, and thus optimization-based prompt stealing, ineffective. We have disclosed our findings responsibly to address this critical vulnerability.
Felix Mächtle, Ashwath Shetty, Jonas Sander, Nils Loose, Sören Pirk, Thomas Eisenbarth 0001
AsiaCCS1
2026 SWAT: Improvements to the Symbolic Executor (Competition Contribution)
Nils Loose, Florian Sieck, Felix Mächtle, Thomas Eisenbarth 0001
TACAS (2)3
2026 DASA: Fully Gradient-Based Program Analysis (Competition Contribution)
Felix Mächtle, Jan-Niclas Serr, Nils Loose, Thomas Eisenbarth 0001
TACAS (2)1
2025 OCEAN: Open-World Contrastive Authorship Identification
Felix Mächtle, Jan-Niclas Serr, Nils Loose, Jonas Sander, Thomas Eisenbarth 0001
ACNS (2)1
2024 SWAT: Modular Dynamic Symbolic Execution for Java Applications using Dynamic Instrumentation (Competition Contribution)
abstract
Abstract SWAT is a novel dynamic symbolic execution engine for Java applications utilizing dynamic instrumentation. SWAT’s unique modular design facilitates flexible communication between its symbolic explorer and executor using HTTP endpoints, thus enhancing adaptability to diverse application scenarios. The symbolic executor’s ability to attach to Java applications enables efficient constraint generation and path exploration. SWAT employs JavaSMT for constraint generation and ASM for bytecode instrumentation, ensuring robust performance. SWAT’s efficacy is evaluated in the Java Track of SV-COMP 2024, achieving fourth place.
Nils Loose, Felix Mächtle, Florian Sieck, Thomas Eisenbarth 0001
TACAS (3)2
2023 Madvex: Instrumentation-Based Adversarial Attacks on Machine Learning Malware Detection
Nils Loose, Felix Mächtle, Claudius Pott, Volodymyr Bezsmertnyi, Thomas Eisenbarth 0001
DIMVA2