EDBT 2026 Demo / reviewers in the wild / expert
Stefan Köpsell
dblp:64/3482
· DBLP profile ↗
21ranked-venue papers
0as first author
16since 2021 · last 2026
0000-0002-0466-562XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 6 since 2021Computer networks · 4 · 4 since 2021Systems, architecture and hardware · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Secure Isac Waveform Design Framework Via Random Frequency and Pri AgilityabstractThis paper presents a novel framework for enhancing the security, data rate, and sensing performance of integrated sensing and communications (ISAC) systems. We employ a random frequency and pulse repetition interval (PRI) agility (RFPA) method for the waveform design, where the necessary random sequences are governed by shared secrets. These secrets, which can be pre-shared or generated via channel reciprocity, obfuscate critical radar parameters like Doppler frequency and pulse start times, thereby significantly impeding the ability to perform reconnaissance from a passive adversary without the secret key. To further introduce enhanced data throughput, we also introduce a hybrid information embedding scheme that integrates amplitude shift keying (ASK), phase shift keying (PSK), index modulation (IM), and spatial modulation (SM), for which a low-complexity sparse-matched filter receiver is proposed for accurate decoding with practical complexity. Finally, the excellent range-velocity resolution and clutter suppression of the proposed waveform are analyzed via the ambiguity function (AF). Ali Khandan Boroujeni, Hyeon Seok Rou, Ghazal Bagheri, Giuseppe Thadeu Freitas de Abreu, Stefan Köpsell, Kuranage Roche Rayan Ranasinghe, Rafael F. Schaefer |
WCNC | 5 |
| 2026 | VeriDP: Verifiable Differentially Private TrainingabstractStochastic Gradient Descent (SGD) is the foundation of modern machine learning (ML). In privacy-sensitive settings, gradients can reveal details about individual data points. Differential Privacy (DP) protects sensitive data during ML training by clipping gradients and adding calibrated Gaussian noise. However, existing frameworks assume semi-honest participants, which fails in adversarial or federated environments where malicious actors can bypass or alter the noise addition process, breaking privacy guarantees. We present VeriDP, a framework for verifiable differentially private training that cryptographically enforces and proves the correct execution of differentially private stochastic gradient descent (DP-SGD) in zero knowledge. VeriDP integrates Zero-Knowledge Proofs (ZKPs) with polynomial commitments, sumcheck and GKR-based proofs, and incrementally verifiable computation (IVC) to generate compact proofs of correct gradient computation, clipping, averaging, and Gaussian noise generation—without revealing private data or randomness. Unlike previous systems that only verify the final privacy budget, VeriDP enables per-iteration verifiability of each model update, providing strong privacy assurances even in adversarial settings. This establishes a novel and complete Zero-Knowledge Proof of Differentially Private Stochastic Gradient Descent (ZK-DPSGD), uniting differential privacy and verifiable computation for secure and auditable ML. Our evaluation shows that prover time increases linearly with the number of input samples, while both verifier time (2–5 ms) and proof size (3–4 KB) remain compact and effectively constant. Behzad Abdolmaleki, Amir R. Asadi, Vahid R. Asadi, Stefan Köpsell, Bhavish Mohee, Nahid Roustaeifar, Maryam Zarezadeh |
Proc. Priv. Enhancing Technol. | 4 |
| 2026 | Frequency Hopping Waveform Design for Secure Integrated Sensing and CommunicationsabstractWe introduce a comprehensive approach to enhance the security, privacy, and sensing capabilities of integrated sensing and communications (ISAC) systems by leveraging random frequency agility (RFA) and random pulse repetition interval agility (RPA) techniques. The combination of these techniques, which we collectively refer to as random frequency and pulse repetition interval agility (RFPA), with channel reciprocity-based key generation (CRKG) obfuscates both Doppler frequency and pulse repetition intervals (PRIs), significantly hindering passive adversaries’ ability to estimate radar parameters. In addition, a hybrid information embedding method integrating amplitude shift keying (ASK), phase shift keying (PSK), index modulation (IM), and spatial modulation (SM) is incorporated to significantly increase the system’s achievable bit rate. Next, a sparse-matched filter receiver design is proposed to efficiently decode the embedded information with a low bit error rate (BER). Finally, a novel RFPA-based secret generation scheme using CRKG enables secure code creation without a coordinating authority. The improved range and velocity estimation, and the reduced clutter effects achieved by the method, are demonstrated through the evaluation of the ambiguity function (AF) of the proposed waveforms. Ali Khandan Boroujeni, Giuseppe Thadeu Freitas de Abreu, Stefan Köpsell, Ghazal Bagheri, Kuranage Roche Rayan Ranasinghe, Rafael F. Schaefer |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | A Cloudy View on Trust Relationships of CVMs: How Confidential Virtual Machines are Falling Short in Public CloudabstractConfidential computing in the public cloud intends to safeguard workload privacy while outsourcing infrastructure management to a cloud provider. This is achieved by executing customer workloads within so called Trusted Execution Environments, such as Confidential Virtual Machines (CVMs), which protect them from unauthorised access by cloud administrators and privileged system software. At the core of confidential computing lies remote attestation—a mechanism that enables workload owners to verify the initial state of their workload and authenticate the underlying hardware. This paper critically examines the confidential computing offerings of market-leading cloud providers to assess whether they genuinely adhere to its core principles. We develop a taxonomy based on carefully selected criteria to systematically evaluate these offerings, enabling us to analyse the components responsible for remote attestation, the evidence provided at each stage, the extent of cloud provider influence and whether this undermines the threat model of confidential computing. Specifically, we investigate how CVMs are deployed in public cloud infrastructures, the extent to which customers can request and verify attestation evidence, and their ability to define and enforce configuration and attestation requirements. This analysis provides insight into whether confidential computing guarantees—namely confidentiality and integrity—are genuinely upheld. Our findings reveal that major cloud providers retain control over critical parts of the trusted software stack and, in some cases, intervene in the standard remote attestation process. This directly contradicts their claims of delivering confidential computing, as the model fundamentally excludes the cloud provider from the set of trusted entities. Jana Eisoldt, Anna Galanou, Andrey Ruzhanskiy, Nils Küchenmeister, Yewgenij Baburkin, Tianxiang Dai, Ivan Gudymenko, Stefan Köpsell, Rüdiger Kapitza |
ACSAC | 8 |
| 2025 | A New Privacy Modeling and Enhancement Methodology for JCAS-Enabled Railway Applications
Yevhen Zolotavkin, Prajnamaya Dass, Stefan Köpsell |
AINA (5) | 3 |
| 2025 | Formally-Verified Security Against Forgery of Remote Attestation Using SSProve
Sara Zain, Jannik Mähn, Stefan Köpsell, Sebastian Ertel |
ESORICS (2) | 3 |
| 2025 | Privacy Analysis and Enhancement for Joint Communication and Sensing ApplicationsabstractJoint Communication and Sensing (JCAS) technology is envisioned to become a part of many Cyber-Physical Systems (CPSs), further advancing essential capabilities provided to numerous applications in critical infrastructure. Due to the use of human-specific sensing data, JCAS systems are vulnerable to privacy threats, and there is no established method to assess the privacy of such systems efficiently. In this paper, we propose a new privacy assessment approach that quantitatively expresses the overall privacy of the JCAS-based system under consideration, for which privacy enhancements are then proposed. While we apply our approach to a railway JCAS-based CPS in this paper, it also applies to CPSs of other kinds. Yevhen Zolotavkin, Prajnamaya Dass, Stefan Köpsell |
IWCMC | 3 |
| 2025 | POTENTIAL: Privacy-Oriented Task Offloading via Context-Aware Risk Estimation in JCAS-Enabled Edge NetworksabstractJoint Communication and Sensing (JCAS) enables User Equipment (UE) to offload computational tasks to nearby peer devices or edge servers over context-aware wireless links. While this improves latency and resource utilization, the dual usage of the wireless spectrum for communication and environmental sensing introduces novel privacy risks, particularly for tasks involving location-sensitive or contextual data. This paper introduces a novel offloading framework that leverages real-time environmental information sensed by JCAS base stations to dynamically estimate the privacy risk associated with each offloading link. Based on these context-aware risk estimates, UE selects among local, Device-to-Device (D2D), or edge execution modes to minimize a composite cost function balancing privacy leakage and delay. A lightweight greedy scheduler is applied to solve the offloading decision problem efficiently under deadline constraints. Simulation results demonstrate that our method significantly reduces effective privacy leakage with negligible latency overhead, consistently outperforming context-agnostic baseline strategies. Mahshid Mehrabi, Vincent Latzko, Stefan Köpsell |
MSWiM | 3 |
| 2025 | Privacy Preserving Integrated Sensing and Communication Architecture for 6G Networks
Prajnamaya Dass, Yevhen Zolotavkin, Stefan Köpsell |
Networking | 3 |
| 2025 | LCM-RA: Secure and Attestation-Enabled Publish/Subscribe for Dynamic GroupsabstractThe role of trust in communication systems is critical in an interconnected world. Remote Attestation (RA) introduces a new paradigm to establish this trust, enabling communication systems to defend against new classes of attackers. In the context of distributed group communications in which communication partners join the network at runtime, existing solutions for network attestation are inadequate. They rely either on a central entity to facilitate joining of devices and/or network attestation, or on hardware features that are not present on the most common cryptoprocessors.To address this gap, a new network RA scheme is proposed in this work. This scheme includes two protocols: one for attesting communication partners upon network entry and another one for regular network attestation. Instead of a third-party verifier, the members of the network themselves act as verifiers in the system. The proposed protocol suite is integrated into LCMsec, an existing peer-to-peer Publish/Subscribe protocol in which trust was previously coupled to the possession of private keying material. A proof-of-concept implementation is assessed to show that the network attestation latency scales well with large group sizes. It is demonstrated that the protocol introduces little startup latency beyond the baseline introduced by the underlying attestation mechanism. Moritz Jasper, Stefan Köpsell |
VTC2025-Fall | 2 |
| 2025 | Optimal obfuscation of awareness messages: Improving users' unlinkability in Intelligent Transport Systems
Yevhen Zolotavkin, Yurii Baryshev, Jannik Mähn, Vitalii Lukichov, Stefan Köpsell |
Comput. Networks | 5 |
| 2025 | AlphaFL: Secure Aggregation with Malicious2 Security for Federated Learning against Dishonest MajorityabstractFederated learning (FL) proposes to train a global machine learning model across distributed datasets. However, the aggregation protocol as the core component in FL is vulnerable to well-studied attacks, such as inference attacks, poisoning attacks [71] and malicious participants who try to deviate from the protocol [24]. Therefore, it is crucial to achieve both malicious security and poisoning resilience from cryptographic and FL perspectives, respectively. Prior works either achieve incomplete malicious security [76], address issues by using expensive cryptographic tools [22, 59] or assume the availability of a clean dataset on the server side [32]. In this work, we propose AlphaFL, a two-server secure aggregation protocol achieving both malicious security in the universal composability (UC) framework [19] and poisoning resilience in FL (thus malicious2) against a dishonest majority. We design maliciously secure multi-party computation (MPC) protocols [24, 26, 48] and introduce an efficient input commitment protocol tolerating server-client collusion (dishonest majority). We also propose an efficient input commitment protocol for the non-collusion case (honest majority), which triples the efficiency in time and quadruples that in communication, compared to the state-of-the-art solution in MP-SPDZ [46]. To achieve poisoning resilience, we carry out 𝐿∞ and 𝐿2-Norm checks with a dynamic L_2-Norm bound by introducing a novel silent select protocol, which improves the runtime by at least two times compared to the classic select protocol. Combining these, AlphaFL achieves malicious2 security at a cost of 25% − 79% more runtime overhead than the state-of-the-art semi-malicious counterpart Elsa [76], with even less communication cost. Yufan Jiang, Maryam Zarezadeh, Tianxiang Dai, Stefan Köpsell |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | Improving Unlinkability in C-ITS: A Methodology For Optimal ObfuscationabstractIn this paper, we develop a new methodology to provide high assurance about privacy in Cooperative Intelligent Transport Systems (C-ITS). Our focus lies on vehicle-to-everything (V2X) communications enabled by Cooperative Awareness Basic Service. Our research motivation is developed based on the analysis of unlinkability provision methods indicating a lack of such methods. To address this, we propose a Hidden Markov Model (HMM) to express unlinkability for the situation two vehicles are communicating with a Roadside Unit (RSU) using Cooperative Awareness Messages (CAMs). Our HMM has labeled states specifying distinct origins of the CAMs observable by a passive attacker. We then establish that high assurance about the degree of uncertainty (e.g., entropy) about labeled states can be obtained for the attacker under the assumption that he knows actual positions of the vehicles (e.g., hidden states in HMM). We further demonstrate how unlinkability can be increased in C-ITS: we propose a joint probability distribution that both drivers must use to obfuscate their actual data jointly. This obfuscated data is then encapsulated in their CAMs. Finally, our findings are incorporated into an obfuscation algorithm whose complexity is linear in the number of discrete time steps in the HMM. Yevhen Zolotavkin, Yurii Baryshev, Vitalii Lukichov, Jannik Mähn, Stefan Köpsell |
ICISSP | 5 |
| 2023 | Secure and Dynamic Publish/Subscribe: LCMsecabstractWe propose LCMsec, a brokerless, decentralised Publish/Subscribe protocol. It aims to provide low-latency and high-throughput message-passing for IoT and automotive applications while providing much-needed security functionalities to combat emerging cyber-attacks in that domain. LCMsec is an extension for the Lightweight Communications and Marshalling (LCM) protocol. We extend this protocol by providing not only authenticated encryption of the messages in transit, but also a group discovery protocol inspired by the Raft consensus protocol. The Dutta-Barua group key agreement is used to agree upon a shared symmetric key among subscribers and publishers on a topic. By using a shared group key, we reduce the key agreement overhead and the number of message authentication codes (MACs) per message compared to existing proposals for secure brokerless Publish/Subscribe protocols, which establish a symmetric key between each publisher and subscriber and append multiple MACs to each message. Moritz Jasper, Stefan Köpsell |
VTC Fall | 2 |
| 2021 | How well can your car be tracked: Analysis of the European C-ITS pseudonym schemeabstractThe change of pseudonym certificates for message authentication is the standard approach for privacy-friendly V2X communication. It's crucial to use an effective and robust pseudonym changing scheme as the location privacy of vehicles relies strongly on it. Therefore, in this work we analyzed a pseudonym change strategy that is recommended by the European C-ITS platform and has good chances to be included in a future European standard. By simulating a realistic urban traffic scenario within Luxembourg, applying and attacking the pseudonym change strategy, we could evaluate the effectiveness of the scheme. Overall, linking pseudonyms with simple traffic statistics in a realistic city traffic scenario is more challenging than related work suggests. However, the consideration of additional static information from the V2X communication, such as length and width of the vehicle, enormously improves the linking of pseudonyms, and thus enables tracking of vehicles and generation of motion profiles. The level of location privacy is thereby particularly influenced by the number of vehicles in the vicinity and especially their properties, as well as, of course, by the observation capabilities of the attacker. Our results suggest that the introduction of VANETs, even with the C-ITS pseudonym scheme, enables the tracking of vehicles, and thus will decrease location privacy in the future. Stephan Escher, Markus Sontowski, Knut Berling, Stefan Köpsell, Thorsten Strufe |
VTC Spring | 4 |
| 2021 | Enabling and Optimizing MACsec for Industrial EnvironmentsabstractIndustry 4.0 will revolutionize industrial automation. Yet, future smart factories will not be created from scratch. They will rather evolve from existing legacy installations. Consequently, also industrial networks will evolve and the result will be a mixture of new and legacy components. This will make new security mechanisms necessary, that are specifically designed for this industrial use case. This work proposes modifications for MACsec [1], a new security protocol for protecting communication traffic. These modifications enable MACsec to work within future industrial settings, circumventing drawbacks introduced by legacy networking technologies. Furthermore, we managed to significantly increase the performance of MACsec. Tim Lackorzynski, Gregor Garten, Jan Sönke Huster, Stefan Köpsell, Hermann Härtig |
IEEE Trans. Ind. Informatics | 4 |
| 2020 | Enabling and Optimizing MACsec for Industrial Environments (Extended Abstract)abstractThe specifics of industrial networks make security mechanisms necessary, that are specifically designed for them. This work proposes two modifications for MACsec, a new security protocol for protecting layer 2 traffic: a new fragmentation mechanism enabling MACsec to work within future industrial networks, and the use of ciphers currently not standardised for MACsec, leading to a significant increase in the performance of MACsec. Tim Lackorzynski, Gregor Garten, Jan Sönke Huster, Stefan Köpsell, Hermann Härtig |
WFCS | 4 |
| 2019 | Towards Secure Communication for High-Density Longitudinal PlatooningabstractUsing V2X communication in platoons promises benefits regarding energy efficiency and fleet management. It is also a safety critical process with the potential to cause dangers to life and limb which needs to be secured against attackers. We propose two protocols for secure platoon communication and provide a comparative analysis of those protocols. Markus Sontowski, Stefan Köpsell, Thorsten Strufe, Christian Zimmermann 0002, Andreas Weinand, Hans D. Schotten, Norbert Bißmeyer |
VTC Fall | 2 |
| 2018 | Transparent Low-Latency Network Anonymisation for Mobile Devices
Martin Byrenheid, Stefan Köpsell, Alexander Naumenko, Thorsten Strufe |
SecureComm (1) | 2 |
| 2017 | SecureCloud: Secure big data processing in untrusted cloudsabstractWe present the SecureCloud EU Horizon 2020 project, whose goal is to enable new big data applications that use sensitive data in the cloud without compromising data security and privacy. For this, SecureCloud designs and develops a layered architecture that allows for (i) the secure creation and deployment of secure micro-services; (ii) the secure integration of individual micro-services to full-fledged big data applications; and (iii) the secure execution of these applications within untrusted cloud environments. To provide security guarantees, SecureCloud leverages novel security mechanisms present in recent commodity CPUs, in particular, Intel's Software Guard Extensions (SGX). SecureCloud applies this architecture to big data applications in the context of smart grids. We describe the SecureCloud approach, initial results, and considered use cases. Florian Kelbert, Franz Gregor, Rafael Pires 0001, Stefan Köpsell, Marcelo Pasin, Aurelien Havet, Valerio Schiavoni, Pascal Felber, Christof Fetzer, Peter R. Pietzuch |
DATE | 4 |
| 2010 | Trained to accept?: a field experiment on consent dialogsabstractA typical consent dialog was shown in 2 x 2 x 3 experimental variations to 80,000 users of an online privacy tool. We find that polite requests and button texts pointing to a voluntary decision decrease the probability of consent---in contrast to findings in social psychology. Our data suggests that subtle positive effects of polite requests indeed exist, but stronger negative effects of heuristic processing dominate the aggregated results. Participants seem to be habituated to coercive interception dialogs---presumably due to ubiquitous EULAs---and blindly accept terms the more their presentation resembles a EULA. Response latency and consultation of online help were taken as indicators to distinguish more systematic from heuristic responses. Rainer Böhme, Stefan Köpsell |
CHI | 2 |