EDBT 2026 Demo / reviewers in the wild / expert
Pascal Wichmann
dblp:57/10919
· DBLP profile ↗
6ranked-venue papers
5as first author
6since 2021 · last 2025
0000-0002-8969-4277ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Rendering-Aware Reinforcement Learning for Vector Graphics GenerationabstractScalable Vector Graphics (SVG) offer a powerful format for representing visual designs as interpretable code. Recent advances in vision-language models (VLMs) have enabled high-quality SVG generation by framing the problem as a code generation task and leveraging large-scale pretraining. VLMs are particularly suitable for this task as they capture both global semantics and fine-grained visual patterns, while transferring knowledge across vision, natural language, and code domains. However, existing VLM approaches often struggle to produce faithful and efficient SVGs because they never observe the rendered images during training. Although differentiable rendering for autoregressive SVG code generation remains unavailable, rendered outputs can still be compared to original inputs, enabling evaluative feedback suitable for reinforcement learning (RL). We introduce Reinforcement Learning from Rendering Feedback, an RL method that enhances SVG generation in autoregressive VLMs by leveraging feedback from rendered SVG outputs. Given an input image, the model generates SVG roll-outs that are rendered and compared to the original image to compute a reward. This visual fidelity feedback guides the model toward producing more accurate, efficient, and semantically coherent SVGs. \method significantly outperforms supervised fine-tuning, addressing common failure modes and enabling precise, high-quality SVG generation with strong structural understanding and generalization. Juan A. Rodríguez, Abhay Puri, Rishav Pramanik, Aarash Feizi, Pascal Wichmann, Arnab Kumar Mondal, Mohammad Reza Samsami, Rabiul Awal, Perouz Taslakian, Spandana Gella, Sai Rajeswar, David Vázquez 0001, Christopher Joseph Pal, Marco Pedersoli |
NeurIPS | 6 |
| 2023 | SecPassInput: Towards Secure Memory and Password Handling in Web Applications
Pascal Wichmann, August See, Hannes Federrath |
SEC | 1 |
| 2023 | WebAppAuth: An Architecture to Protect from Compromised First-Party Web Servers
Pascal Wichmann, Sam Ansari, Hannes Federrath, Jens Lindemann 0001 |
SECRYPT | 1 |
| 2022 | Web Cryptography API: Prevalence and Possible Developer MistakesabstractIn this paper, we analyze mistakes that web developers can make when using the Web Cryptography API. We evaluate the impact of the uncovered mistakes and discuss how they can be prevented. Furthermore, we derive best practices from these mistakes to provide guidance to developers. To assess the relevance of the Web Cryptography API, we empirically evaluate how prevalently it is used by popular web applications on the Internet and in GitHub repositories, finding that only a small proportion of web applications use it. The most widely used operation by far is the generation of cryptographically secure random values, which was not possible in browser-based JavaScript prior to the Web Cryptography API. Pascal Wichmann, Maximilian Blochberger, Hannes Federrath |
ARES | 1 |
| 2022 | FileUploadChecker: Detecting and Sanitizing Malicious File Uploads in Web Applications at the Request LevelabstractImproper handling of file uploads in web applications induces threats to the application and its users. In this paper, we propose FileUploadChecker, a server-side tool to automatically detect potentially malicious file uploads in web applications and reject or sanitize malicious content in files. FileUploadChecker works transparently on the web request level, using the middleware concept of web frameworks. Thus, FileUploadChecker can be deployed without modifications to the code of existing web applications, for example, if it is infeasible for server administrators to maintain patches to the underlying software or if proprietary software cannot be patched. Pascal Wichmann, Alexander Groddeck, Hannes Federrath |
ARES | 1 |
| 2021 | Detection of Brute-Force Attacks in End-to-End Encrypted Network TrafficabstractNetwork intrusion detection systems (NIDSs) can detect attacks in network traffic. However, the increasing ratio of encrypted connections on the Internet restricts their ability to observe such attacks. This paper proposes a completely passive method that allows to detect brute-force attacks in encrypted traffic without the need to decrypt it. For that, we propose five novel metrics for attack detection which quantify metadata like packet size or packet timing. Pascal Wichmann, Matthias Marx, Hannes Federrath, Mathias Fischer 0001 |
ARES | 1 |