EDBT 2026 Demo / reviewers in the wild / expert
Florian Draschbacher
dblp:350/7967
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2025
0000-0002-3477-1511ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Don't Stop Receiving: Ensuring Availability of Critical Services on Compromised Mobile DevicesabstractThe developers of critical networked applications currently relied on kernel-level protections to ensure the timely delivery of critical messages like Wireless Emergency Alert (WEA) or multi-factor authentication (MFA) notifications. However, the increasing complexity of mobile operating system kernels and network stacks increases the attack surface for adversaries to exploit. In this paper, we introduce a system which safeguards network availability for critical mobile applications against powerful attackers. We achieve this by using the Trusted Execution Environment (TEE) found in most mobile devices to host minimal network drivers. Further, we utilize Trusted I/O to ensure that critical messages reach the end-user even if the device’s kernel is compromised. To demonstrate the feasibility of our approach, we provide a PoC implementation that mimics multi-factor authentication. Our Evaluation demonstrates that latency for all applications is reduced by around $21 \%$ on a representative mobile platform (ARM Cortex A9), though a significant throughput performance is observed. Tom Van Eyck, Stefan More, Florian Draschbacher, Sam Michiels, Danny Hughes 0001 |
NCA | 3 |
| 2025 | ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago
Florian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan Mangard |
USENIX Security Symposium | 1 |
| 2025 | The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel Vulnerabilities
Lukas Maar, Florian Draschbacher, Lorenz Schumm, Ernesto Martínez García, Stefan Mangard |
USENIX Security Symposium | 2 |
| 2024 | Manifest Problems: Analyzing Code Transparency for Android Application BundlesabstractIn 2018, Google introduced a new app distribution format called AAB (Android Application Bundle), which replaced APK (Android Package) as the required format for all new app submissions to Google Play in 2021. Apps are still delivered to end users as APK files, but they are now generated and signed on the app store operator’s infrastructure. Most crucially, this change requires developers to hand over their APK signing key to the app store operator, enabling them to arbitrarily manipulate apps prior to delivery to end users. To address this, Google has introduced the Code Transparency scheme to verify the integrity of APKs generated from AAB files. However, due to the lack of independent studies, the exact security properties of Code Transparency remain unclear.In this paper, we present the first comprehensive analysis of the security of Code Transparency and the AAB format. We thoroughly investigate the design and implementation of the Code Transparency scheme, discussing in detail the technical possibilities attackers have for manipulating apps that use it. Additionally, we conduct a large-scale study on AAB and Code Transparency in practice. To this end, we evaluate the prevalence of both technologies among 3.5 million real-world apps, analyze their susceptibility to our attacks, and carry out a case study that demonstrates the practical security implications of attacks on Code Transparency.Our analyses indicate that Code Transparency suffers from severe design and implementation flaws that allow app store operators to execute code in the context of any app without disturbing its Code Transparency signature. Florian Draschbacher, Lukas Maar |
ACSAC | 1 |
| 2024 | Defects-in-Depth: Analyzing the Integration of Effective Defenses against One-Day Exploits in Android Kernels
Lukas Maar, Florian Draschbacher, Lukas Lamster, Stefan Mangard |
USENIX Security Symposium | 2 |
| 2023 | A2P2 - An Android Application Patching Pipeline Based On Generic ChangesetsabstractInspecting and manipulating runtime behavior of Android applications is a common need in mobile security research. However, existing tools lack a holistic application-agnostic approach. They either require changes to be manually adapted to each target application, or they focus exclusively on executable code parts, neglecting the key role the application manifest and resources play in the Android ecosystem. This limits their use for research purposes, where a specific series of modifications on various app components frequently has to be applied to a whole body of applications. Florian Draschbacher |
ARES | 1 |
| 2023 | CryptoShield - Automatic On-Device Mitigation for Crypto API Misuse in Android ApplicationsabstractMisuse of cryptographic APIs remains one of the most common flaws in Android applications. The complexity of cryptographic APIs frequently overwhelms developers. This can lead to mistakes that leak sensitive user data to trivial attacks. Despite herculean efforts by platform provider Google, countermeasures introduced so far were not successful in preventing these flaws. Users remain at risk until an effective systemic mitigation has been found. Florian Draschbacher, Johannes Feichtner |
AsiaCCS | 1 |