Published multiple papers and received several best paper and distinguished paper awards. For example:
- IEEE EuroS&P 2025 Best Paper Award: CHARON: Polyglot Code Analysis for Detecting Vulnerabilities in Scripting Languages Native Extensions
- CHI 2025 Best Paper Award: Permission Rationales in the Web Ecosystem: An Exploration of Rationale Text and Design Patterns
- IEEE SP ‘24 Distinguished Paper Award: The Great Request Robbery: An Empirical Study of Client-side Request Hijacking Vulnerabilities on the Web
- IEEE SP ‘23 2x Distinguished Paper Awards: It’s (DOM) Clobbering Time: Attack Techniques, Prevalence, and Defenses and The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web
Research Experience
Leads the Application Security research group, with research areas including autonomous vulnerability detection and analysis, security of the web platform and emerging technologies, and cyberattacks.
Background
Faculty at CISPA Helmholtz Center for Information Security, leading the Application Security (AppSec) research group. Research interests include web security and web application security, security of emerging technology (e.g., metaverse/WebXR), program analysis (e.g., dynamic/static, client and server), and ML/AI for program analysis.
Miscellany
Serves as a PC member or chair for multiple international conferences such as USENIX Security, IEEE S&P, ACM CCS, etc.