Abstract is missing.
- Message from General ChairsStefano Calzavara, Paolo Falcarin. [doi]
- Mitigating Information Leakage in Large Language Models: Evaluating the Impact of Code Obfuscation on Vulnerability DetectionBengü Gülay, Cemal Yilmaz 0001. 1-8 [doi]
- Bypassing Audio reCAPTCHA with Automatic Speech Recognition ModelsPaul Aubry, Juliette Devoivre, Damien Carron, Simon Fernandez, Andrzej Duda, Maciej Korczynski. 1-5 [doi]
- Admin/1423: On the Insecurity of Open-Source 5G Core Network Deployments in the WildKatharina Kohls. 1-5 [doi]
- Demystifying the Role of Rule-Based Detection in AI Systems for Windows Malware DetectionAndrea Ponte, Luca Demetrio, Luca Oneto, Ivan Tesfai Ogbu, Battista Biggio, Fabio Roli. 9-15 [doi]
- On the Effect of Ruleset Tuning and Data Imbalance on Explainable Network Security Alert Classifications: A Case-Study on DeepCASEKoen T. W. Teuwen, Sam Baggen, Emmanuele Zambon, Luca Allodi. 16-29 [doi]
- Democratizing Generic Malware UnpackingThorsten Jenke, Max Jens Ufer, Manuel Blatt, Leander Kohler, Elmar Padilla, Lilli Bruckschen. 30-38 [doi]
- Toward Automatically Generating User-Specific Recovery Procedures After Windows Malware InfectionsJerre Starink, Cassie Wanjun Xu, Andrea Continella. 39-47 [doi]
- A Unified Comparison of Tabular and Graph-Based Feature Representations in Machine Learning for Malware DetectionSamy Bettaieb, Serena Lucca, Charles-Henry Bertrand Van Ouytsel, Axel Legay, Etienne Rivière. 48-58 [doi]
- Do Fear the REAPIR: Adversarial Malware from API ReplacementLuke Kurlandski, Rayan Mosli, Yin Pan, Sirapat Thianphan, Matthew Wright 0001. 59-68 [doi]
- CTI-HAL: A Human-Annotated Dataset for Cyber Threat Intelligence AnalysisSofia Della Penna, Roberto Natella, Vittorio Orbinato, Lorenzo Parracino, Luciano Pianese. 69-78 [doi]
- The Dark Side of the Web: Towards Understanding Various Data Sources in Cyber Threat IntelligenceSaskia Laura Schröer, Noé Canevascini, Irdin Pekaric, Philine Widmer, Pavel Laskov. 79-89 [doi]
- Is this your USB? No, but Check this QR Code for a Free Meal! Assessing Awareness Against Dropped USBs and Malicious QR CodesJohannes Nordskov, Tyge Tiessen, Emmanouil Vasilomanolakis. 90-102 [doi]
- Decomposing Culture within Threat Actor Groups - Insights from the Conti Ransomware CollectiveKonstantinos Mersinas, Aimee Liu, Niki Panteli. 103-108 [doi]
- An Experimental Design to Investigate Attacker Actions on an Access-as-a-Service 'Criminal' PlatformRoy Ricaldi, Yasen Yalamov, Michele Campobasso, Luca Allodi, Hannah Kool, Asier Moneva, Eric Rutger Leukfeldt. 109-114 [doi]
- Port in a Storm: Iranian Cyber Operations and Chinese Strategic Interests in Middle Eastern Maritime InfrastructureCosimo Melella, Francesco Ferazza, Konstantinos Mersinas, Ricardo Lugo. 115-125 [doi]
- Yet Another Diminishing Spark: Low-Level Cyberattacks in the Israel-Gaza ConflictAnh V. Vu, Alice Hutchings, Ross J. Anderson. 126-131 [doi]
- LogoTrust: Leveraging BIMI to Build a Validated Dataset of Brands, Domain Names, and LogosYoussef Abyaa, Olivier Hureau, Andrzej Duda, Maciej Korczynski. 132-137 [doi]
- Hunting Review Bombs with BRIDGE - A Bipartite Graph Neural Network Approach to Abuse DetectionGonzalo Sobarzo Abufon, Juan Vanerio, Javier Bustos-Jiménez, Pedro Casas. 138-146 [doi]
- Intelligent Detection of Non-Essential IoT Traffic on the Home GatewayFabio Palmese, Anna Maria Mandalari, Hamed Haddadi, Alessandro E. C. Redondi. 147-152 [doi]
- Early-Stage Anomaly Detection: A Study of Model Performance on Complete vs. Partial FlowsAdrián Pekár, Richard Jozsa. 153-163 [doi]
- PPT-GNN: A Practical Pretrained Spatio-Temporal Graph Neural Network for Network SecurityLouis Van Langendonck, Ismael Castell-Uroz, Pere Barlet-Ros. 169-175 [doi]
- Tracing Vendors: A Middlebox-Centric Study of Network InterferenceBulut Ulukapi, Anna Sperotto, Ralph Holz. 176-186 [doi]
- One Does Not Simply Score a Website: Evaluating Website Security Scoring AlgorithmsDaan Vansteenhuyse, Victor Le Pochat, Gertjan Franken, Lieven Desmet. 187-194 [doi]
- Drifting Away: A Cyber-Security Study of Internet-Exposed OPC UA ServersRicardo Yaben, Emmanouil Vasilomanolakis. 195-202 [doi]
- RustiFlow: Bridging the Gap Between Security Research and Practice Using eBPF-Based Network Flow ExtractionMiel Verkerken, Matisse Callewaert, Laurens D'hooge, Tim Wauters, Bruno Volckaert, Filip De Turck. 203-216 [doi]
- CFA-Bench: Cybersecurity Forensic Llm Agent Benchmark and TestingFrancesco De Santis, Kai Huang, Rodolfo V. Valentim, Danilo Giordano, Marco Mellia, Zied Ben-Houidi, Dario Rossi 0001. 217-225 [doi]
- From Cluttered to Clustered: Addressing Privacy Threat Explosion through Automated ClusteringJonah Bellemans, Mario Raciti, Dimitri Van Landuyt, Laurens Sion, Giampaolo Bella, Lieven Desmet, Wouter Joosen. 231-241 [doi]
- Explaining and Visualizing Synthetic Data Quality Using Statistical DistancesJuko Yamamoto, Takayuki Miura, Rina Okada, Masanobu Kii, Atsunori Ichikawa. 242-250 [doi]
- Identification of Compositional Risks in Data Protection Impact Assessments and BeyondHenrik Graßhoff, Meiko Jensen, Malte Hansen, Nils Gruschka. 251-259 [doi]
- Formguard: Continuous Privacy Testing for Websites Using Automated Interaction ReplayTim Vlummens, Gunes Acar. 260-268 [doi]
- Right Here, Right Now: User Perceptions of In-Place Contextual Privacy OptionsFlorian Dehling, Jan Tolsdorf, Luigi Lo Iacono. 269-277 [doi]
- PILLAR: LINDDUN Privacy Threat Modeling Using LLMsMajid Mollaeefar, Andrea Bissoli, Dimitri Van Landuyt, Silvio Ranise. 278-286 [doi]
- Securing the Lane: Defences Against Patch Attacks on Autonomous Vehicle's Lane DetectionRomana Blazevic, Alexander Toch, Omar Veledar, Georg Macher. 287-295 [doi]
- Stop! Camera Spoofing Via the in-Vehicle IP NetworkDror Peri, Avishai Wool. 296-310 [doi]
- The Image Scaling Attack: Unveiling the Risks in Traffic Sign ClassificationAliza Reif, Tarek Stolz, Stjepan Picek, Oscar Hernán Ramírez-Agudelo, Michael Karl. 311-321 [doi]
- WiP: Concept Drift Management in Edge-AI for Autonomous VehiclesRohit Ravichandran, Mahshid Mehr Nezhad, Carsten Maple. 322-329 [doi]
- Self-Sovereign Identities for Software-Defined VehiclesChristian Prehofer. 329-334 [doi]
- CheckOCPP: Automatic OCPP Packet Dissection and Compliance CheckSoumaya Boussaha, Victor Fresno Gómez, Thomas Barber, Daniele Antonioli. 335-342 [doi]
- Avatar: Adversarial Vehicle Trajectory Attack Targeting Autonomous Driving PlannerJiadong Liu, Tatsuya Mori. 343-350 [doi]
- Work in Progress: Leveraging Large Language Models for Cybersecurity Compliance: A Pilot Study in ISO 27001 Audit PlanningAhmed Salman, Yara Alsiyat, Sadie Creese, Michael Goldsmith. 351-359 [doi]
- Tap, Pay, and Worry: Users' Perceptions of Contactless Payment Attacks Versus Technical FeasibilityMahshid Mehr Nezhad, Maryam Mehrnezhad, Timur Yunusov, Feng Hao 0001. 360-373 [doi]
- Work in Progress: Artificial Intelligence in Cybersecurity - Developing a Framework for Ethically Responsible PracticesNandshin Lehniger, Michael Kubach. 374-380 [doi]
- Work in Progress: Secure Deletion on Cloud - a Constant BattleKonstantina Fotari, François Dupressoir, Kopo Marvin Ramokapane. 381-387 [doi]
- Understanding How Privacy and Data Protection Perceptions Shape Nigerian Journalists' Use of AI Tools: A Work in ProgressOluwamayowa Tijani, Jamie Mahoney, Santosh Vijaykumar, James Nicholson. 388-394 [doi]
- Work in Progress: Effects of Enforcing International Law on Cyber Conflict Using WargamingAidan Marchildon, Ievgeniia Kuzminykh, Bogdan Ghita 0003. 395-400 [doi]
- An Early Experience With Confidential Computing Architecture for On-Device Model ProtectionSina Abdollahi, Mohammad Maheri, Sandra Deepthy Siby, Marios Kogias, Hamed Haddadi. 401-410 [doi]
- Proving Attributes About Confidential Compute Services with Validation and Endorsement ServicesAnjo Vahldiek-Oberwagner, Marcela S. Melara. 411-413 [doi]
- End-To-End Confidentiality with Sev-Snp Leveraging in-Memory StorageLorenzo Brescia, Iacopo Colonnelli, Valerio Schiavoni, Pascal Felber, Marco Aldinucci. 414-421 [doi]
- Enclave Application Cache for RISC-V KeystoneTakumu Umezawa, Akihiro Saiki, Keiji Kimura. 422-428 [doi]
- OPENCCA: An Open Framework to Enable Arm CCA ResearchAndrin Bertschi, Shweta Shinde. 429-434 [doi]
- Principled Symbolic Validation of Enclaves on Low-End MicrocontrollersGert-Jan Goossens, Jo Van Bulck. 435-447 [doi]
- Atlas: A Framework for ML Lifecycle Provenance & TransparencyMarcin Spoczynski, Marcela S. Melara, Sebastian Szyller. 448-461 [doi]
- Wait a Cycle: Eroding Cryptographic Trust in Low-End Tees via Timing Side ChannelsRuben Van Dijck, Marton Bognar, Jo Van Bulck. 462-470 [doi]
- Narrowing the Gap Between Tees Threat Model and Deployment StrategiesFilip Rezabek, Jonathan Passerat-Palmbach, Moe Mahhouk, Frieder Erdmann, Andrew Miller. 471-473 [doi]
- Decentralised Supply Chain Reputation: A Privacy and Self-Sovereign Identity PerspectiveAbubakar-sadiq Shehu, Steve Schneider. 474-484 [doi]
- Identity Threats and Where to Find Them: Mapping ITDR and MITRE ATT&CKVitali Serzantov, Erwin Kupris, Thomas Schreck. 485-495 [doi]
- Replication Study: Cross-Country Evaluation of the Recognition-Based Graphical Authentication Scheme in AR and VR EnvironmentsNaheem Noah, Peter Mayer 0001, Sanchari Das. 496-507 [doi]
- Security Requirements Classification by Means of Explainable Transformer ModelsLuca Petrillo, Fabio Martinelli, Antonella Santone, Francesco Mercaldo. 508-515 [doi]
- Towards Privacy-Preserving Revocation of Verifiable Credentials with Time-FlexibilityFrancesco Buccafurri, Carmen Licciardi. 516-521 [doi]
- HFuzz-Rb: Real-Time Roadblock Detection in Fuzz TestingSubhojeet Mukherjee, Ritesh Kumar Kalle. 522-529 [doi]
- A Review of Anti-Phishing Email Control Measures: Why we Need a Novel Digital Signature SchemeYe Li, Abu Barkat Ullah, Dat Tran 0001, Elisa Martínez Marroquín, Wanli Ma. 530-537 [doi]
- Are You Sure That is Secure? Assessing Organizations Security Readiness Via a Devsecops Maturity ModelAlessandro Brighente, Elisa Burato, Mauro Conti. 538-545 [doi]
- Sok: Zero Trust as a Strategy to Address Devsecops ChallengesAnita Nair, Serena Nicolazzo, Antonino Nocera, Rafidha Rehiman K. A., Vinod P. 0001. 546-554 [doi]
- Towards Continuous Risk Assessment and Conformance Checking of IdM DeploymentsAndrea Bisegna, Roberto Carbone, Laura Cristiano, Pietro De Matteis, Silvio Ranise. 555-560 [doi]
- Concept for Designing an ICS Testbed from a Penetration Testing PerspectiveSebastian Kraust, Peter Heller, Jürgen Mottok. 561-568 [doi]
- The OWApp Benchmark: An OWASP-Compliant Vulnerable Android App DatasetLuca Ferrari, Franceso Pagano, Luca Verderame, Alessio Merlo. 569-580 [doi]
- Covert BLE Data Exfiltration via Apple's Find My Network: A Malware Prototype and Defense StrategiesHosam Alamleh, Alessandro Cantelli Forti. 581-587 [doi]
- Real-World Study of the Security of Educational Test SystemsStefan Gast, Sebastian Daniel Felix, Alexander Steinmaurer, Jonas Juffinger, Daniel Gruss. 588-599 [doi]
- Statistical Evaluation of Entropy Accumulation in LinuxAlexandre Bouez, Joan Daemen, Bart Mennink. 600-612 [doi]
- Work-in-Progress: Optimizing Performance of User Revocation in Cryptographic Access Control with Trusted Execution EnvironmentsIon Andy Ditu, Stefano Berlato, Matteo Busi 0001, Roberto Carbone, Silvio Ranise. 613-618 [doi]
- From Edge to Cloud: Securing Distributed Containerized ApplicationsLuca Verderame, Giorgia Bolognesi, Enrico Pezzano, Massimiliano Rak, Alberto Falcone, Giacomo Benedetti, Massimo Guarascio 0001, Luca Caviglione, Roberto Carbone, Roberto Doriguzzi Corin, Maurizio Giacobbe, Giovanni Merlino, Antonio Puliafito, Massimiliano Baldo, Marino Miculan, Vincenzo Riccio, Massimo Ficco. 619-629 [doi]
- Cognitive Biases in Cyber Attacker Decision Making: Translating Behavioral Insights Into CybersecurityAnu Aggarwal, Maria José Ferreira, Palvi Aggarwal, Prashanth Rajivan, Cleotilde Gonzalez. 630-645 [doi]
- Towards Bio-Inspired Cyber-Deception: A Case Study of SSH and Telnet HoneypotsAnastasia Safargalieva, Emmanouil Vasilomanolakis. 646-655 [doi]
- Experience Paper: Uncovering a Privileged Insider Threat in ActionRaj Gopalakrishna, Rajaram Bhaskaran. 656-661 [doi]
- Position Paper: The Extended Pyramid of Pain: The Attacker's Nightmare EditionRaj Gopalakrishna, Rajaram Bhaskaran. 662-670 [doi]
- VelLMes: A High-Interaction AI-Based Deception FrameworkMuris Sladic, Veronica Valeros, Carlos Adrián Catania, Sebastián García. 671-679 [doi]
- A Case Study on the Use of Representativeness Bias as a Defense Against Adversarial Cyber ThreatsBriland Hitaj, Grit Denker, Laura Tinnel, Michael McAnally, Bruce DeBruhl, Nathan Bunting, Alex Fafard, Daniel Aaron, Richard D. Roberts, Joshua Lawson, Greg McCain, Dylan Starink. 680-689 [doi]
- Koney: A Cyber Deception Orchestration Framework for KubernetesMario Kahlhofer, Matteo Golinelli, Stefan Rass. 690-702 [doi]
- Detection of Reverse Engineering Activities Before the AttackPaolo Falcarin, Mirco Venerba, Matteo De Giorgi, Federica Sarro. 703-710 [doi]