EDBT 2026 Demo / reviewers in the wild / expert
Pascal Tippe
dblp:378/5753
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2026
0009-0009-3199-7193ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Operationalizing the Motivated Intruder: A Codebook-Guided Inference Framework for Semantic Input Privacy in LLMsabstractThe integration of LLMs into professional and personal workflows creates a semantic leakage vector, where sensitive data is exposed through contextual quasi-identifiers rather than explicit identifiers. We demonstrate that conventional syntactic sanitization (Regex/NER) is fundamentally insufficient for this threat model. To address this, we propose a codebook-guided privacy gateway, an architecture that operationalizes the GDPR's motivated intruder test into executable chain-of-thought logic. We evaluate this framework using a high-fidelity reference model to isolate logical validity from hardware constraints, validating results against a multi-stage human-annotated ground truth ($N=127$) to eliminate model-preference bias. Our findings are threefold. First, deductive inference outperforms pattern matching: the gateway achieves a 90% risk neutralization rate for trade secrets, significantly outperforming baseline methods which neutralize less than 5%. Second, privacy is a compute-bound task: sanitization efficacy correlates linearly ($r=0.985$) with chain-of-thought token volume, mapping a significant inference gap in current local models on consumer-grade hardware. Third, we identify the semantic coupling limit: a structural boundary in technical domains where robust privacy and high utility are mutually exclusive. This study establishes that effective input sanitization requires a shift from deterministic filtering to probabilistic, deductive inference. Michael Maximilian Grötzner, Pascal Tippe |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | Evaluating Argon2 Adoption and Effectiveness in Real-World Software
Pascal Tippe, Michael P. Berner |
ARES (2) | 1 |
| 2025 | Security Vulnerabilities in AI-Generated Code: A Large-Scale Analysis of Public GitHub Repositories
Maximilian Schreiber, Pascal Tippe |
ICICS (3) | 2 |
| 2025 | Detecting and Attributing Tor-Obfuscated Malware Communications Through Traffic FingerprintingabstractAs malware authors increasingly adopt anonymity networks like Tor to obfuscate Command & Control communications and evade detection, defenders face the challenge of distinguishing malicious from benign traffic in an environment designed for privacy.This study investigates whether malware traffic routed through Tor can still be identified despite the network's encryption, packet normalization, and routing obfuscation mechanisms.Using a controlled empirical setup, we executed 13 diverse malware samples spanning 10 families, generating 693 Tor-obfuscated traffic traces.Through feature engineering focusing on statistical, temporal, and burst characteristics, and leveraging machine learning classifiers, we demonstrate that malware retains distinct traffic patterns even within anonymized environments.Our classifiers achieved up to 89.9 % accuracy in identifying malware families, highlighting the persistence of identifiable temporal and statistical characteristics.These findings demonstrate that malware fingerprinting remains feasible even in anonymized environments, providing actionable insights for defenders and privacy-preserving approaches for detecting malicious activity.However, our results also underscore potential fingerprinting risks for anonymity systems like Tor, prompting a need for stronger traffic normalization techniques.This study bridges the gap between malware analysis and anonymity research, offering a foundation to balance user privacy with effective threat detection. Pascal Tippe, Adrian Tippe, Jörg Keller 0001 |
IH&MMSec | 1 |
| 2024 | Onion Services in the Wild: A Study of Deanonymization AttacksabstractTor, the leading anonymization network, routes traffic over multiple relays to ensure client anonymity. Its Onion Services allow users to host services within the Tor network without revealing their location. While these techniques are crucial for users in authoritarian regimes and whistleblowers, they are also exploited by criminals. This paper diverges from the common focus on the technical vulnerabilities of the Tor protocol and instead explores the practical aspects of deanonymizing Onion Service users and operators. Despite Tor's robust security mechanisms, human errors in its usage and operation frequently lead to deanonymization. This study models law enforcement agencies as powerful attackers and evaluates documents from 136 court cases to determine investigative methods. We find that investigators employ different methods depending on the offense, with user mistakes being the dominant angle. Technical attacks, though comparatively rare, are highly effective and can potentially impact a large number of users simultaneously. Attacks on the well-researched Tor protocol are exceptionally rare, but their impact is even more significant. We argue that the human aspect of using Tor is the most critical deanonymization angle and that tailored guidelines for ethical users can help protect them from oppressive retaliation while still enabling the prosecution of criminal activity. Pascal Tippe, Adrian Tippe |
Proc. Priv. Enhancing Technol. | 1 |