This webpage is an attempt to assemble a ranking of top-cited papers from the area of computer security. The ranking has been created based on citations of papers published at top security conferences. More details are available here.
Top 100 papers from 1980 to 2023 ⌄
1
Nicholas Carlini and David A. Wagner: Towards Evaluating the Robustness of Neural Networks. IEEE Symposium on Security and Privacy, 2017
Vipul Goyal, Omkant Pandey, Amit Sahai, and Brent Waters: Attribute-based encryption for fine-grained access control of encrypted data. ACM Conference on Computer and Communications Security (CCS), 2006
Mihir Bellare and Phillip Rogaway: Random Oracles are Practical: A Paradigm for Designing Efficient Protocols. ACM Conference on Computer and Communications Security (CCS), 1993
Laurent Eschenauer and Virgil D. Gligor: A key-management scheme for distributed sensor networks. ACM Conference on Computer and Communications Security (CCS), 2002
Martín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang: Deep Learning with Differential Privacy. ACM Conference on Computer and Communications Security (CCS), 2016
Dawn Xiaodong Song, David A. Wagner, and Adrian Perrig: Practical Techniques for Searches on Encrypted Data. IEEE Symposium on Security and Privacy, 2000
Haowen Chan, Adrian Perrig, and Dawn Xiaodong Song: Random Key Predistribution Schemes for Sensor Networks. IEEE Symposium on Security and Privacy, 2003
Nicolas Papernot, Patrick D. McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami: The Limitations of Deep Learning in Adversarial Settings. IEEE European Symposium on Security and Privacy, 2016
Giuseppe Ateniese, Randal C. Burns, Reza Curtmola, Joseph Herring, Lea Kissner, Zachary N. J. Peterson, and Dawn Xiaodong Song: Provable data possession at untrusted stores. ACM Conference on Computer and Communications Security (CCS), 2007
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov: Membership Inference Attacks Against Machine Learning Models. IEEE Symposium on Security and Privacy, 2017
Yao Liu, Michael K. Reiter, and Peng Ning: False data injection attacks against state estimation in electric power grids. ACM Conference on Computer and Communications Security (CCS), 2009
Nicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami: Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks. IEEE Symposium on Security and Privacy, 2016
Alessandro Acquisti and Ralph Gross: Imagined Communities: Awareness, Information Sharing, and Privacy on the Facebook. International Symposium on Privacy Enhancing Technologies (PETS), 2006
Reza Curtmola, Juan A. Garay, Seny Kamara, and Rafail Ostrovsky: Searchable symmetric encryption: improved definitions and efficient constructions. ACM Conference on Computer and Communications Security (CCS), 2006
Stephanie Forrest, Alan S. Perelson, Lawrence Allen, and Rajesh Cherukuri: Self-nonself discrimination in a computer. IEEE Symposium on Security and Privacy, 1994
Stephanie Forrest, Steven A. Hofmeyr, Anil Somayaji, and Thomas A. Longstaff: A Sense of Self for Unix Processes. IEEE Symposium on Security and Privacy, 1996
Thomas Ristenpart, Eran Tromer, Hovav Shacham, and Stefan Savage: Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds. ACM Conference on Computer and Communications Security (CCS), 2009
Ahmed E. Kosba, Andrew Miller, Elaine Shi, Zikai Wen, and Charalampos Papamanthou: Hawk: The Blockchain Model of Cryptography and Privacy-Preserving Smart Contracts. IEEE Symposium on Security and Privacy, 2016
Ari Juels and Burton S. Kaliski Jr.: Pors: proofs of retrievability for large files. ACM Conference on Computer and Communications Security (CCS), 2007
Donggang Liu and Peng Ning: Establishing pairwise keys in distributed sensor networks. ACM Conference on Computer and Communications Security (CCS), 2003
Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom: Spectre Attacks: Exploiting Speculative Execution. IEEE Symposium on Security and Privacy, 2019
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart: Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures. ACM Conference on Computer and Communications Security (CCS), 2015
Daniel Arp, Michael Spreitzenbarth, Malte Hubner, Hugo Gascon, and Konrad Rieck: DREBIN: Effective and Explainable Detection of Android Malware in Your Pocket. Network and Distributed System Security Symposium (NDSS), 2014
Wenliang Du, Jing Deng, Yunghsiang S. Han, and Pramod K. Varshney: A pairwise key pre-distribution scheme for wireless sensor networks. ACM Conference on Computer and Communications Security (CCS), 2003
Kallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H. Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth: Practical Secure Aggregation for Privacy-Preserving Machine Learning. ACM Conference on Computer and Communications Security (CCS), 2017
James Newsome and Dawn Xiaodong Song: Dynamic Taint Analysis for Automatic Detection, Analysis, and SignatureGeneration of Exploits on Commodity Software. Network and Distributed System Security Symposium (NDSS), 2005
Crispin Cowan, Calton Pu, Dave Maier, Heather Hintony, Jonathan Walpole, Peat Bakke, Steve Beattie, Aaron Grier, Perry Wagle, and Qian Zhang: StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks. USENIX Security Symposium, 1998
Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak N. Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, and Stefan Savage: Experimental Security Analysis of a Modern Automobile. IEEE Symposium on Security and Privacy, 2010
Eli Ben-Sasson, Alessandro Chiesa, Christina Garman, Matthew Green, Ian Miers, Eran Tromer, and Madars Virza: Zerocash: Decentralized Anonymous Payments from Bitcoin. IEEE Symposium on Security and Privacy, 2014
Tal Garfinkel and Mendel Rosenblum: A Virtual Machine Introspection Based Architecture for Intrusion Detection. Network and Distributed System Security Symposium (NDSS), 2003
Steven M. Bellovin and Michael Merritt: Encrypted key exchange: password-based protocols secure against dictionary attacks. IEEE Symposium on Security and Privacy, 1992
Manos Antonakakis, Tim April, Michael Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J. Alex Halderman, Luca Invernizzi, Michalis Kallitsis, Deepak Kumar, Chaz Lever, Zane Ma, Joshua Mason, Damian Menscher, Chad Seaman, Nick Sullivan, Kurt Thomas, and Yi Zhou: Understanding the Mirai Botnet. USENIX Security Symposium, 2017
Loi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena, and Aquinas Hobor: Making Smart Contracts Smarter. ACM Conference on Computer and Communications Security (CCS), 2016
Martín Abadi and Andrew D. Gordon: A Calculus for Cryptographic Protocols: The Spi Calculus. ACM Conference on Computer and Communications Security (CCS), 1997
Ian T. Foster, Carl Kesselman, Gene Tsudik, and Steven Tuecke: A Security Architecture for Computational Grids. ACM Conference on Computer and Communications Security (CCS), 1998
Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, and Tadayoshi Kohno: Comprehensive Experimental Analyses of Automotive Attack Surfaces. USENIX Security Symposium, 2011
Adrienne Porter Felt, Erika Chin, Steve Hanna, Dawn Song, and David A. Wagner: Android permissions demystified. ACM Conference on Computer and Communications Security (CCS), 2011
Giuseppe Ateniese, Kevin Fu, Matthew Green, and Susan Hohenberger: Improved Proxy Re-Encryption Schemes with Applications to Secure Distributed Storage. Network and Distributed System Security Symposium (NDSS), 2005
Wenke Lee, Salvatore J. Stolfo, and Kui W. Mok: A Data Mining Framework for Building Intrusion Detection Models. IEEE Symposium on Security and Privacy, 1999
Blaise Gassend, Dwaine E. Clarke, Marten van Dijk, and Srinivas Devadas: Silicon physical random functions. ACM Conference on Computer and Communications Security (CCS), 2002
Hovav Shacham: The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86). ACM Conference on Computer and Communications Security (CCS), 2007
Oleg Sheyner, Joshua W. Haines, Somesh Jha, Richard Lippmann, and Jeannette M. Wing: Automated Generation and Analysis of Attack Graphs. IEEE Symposium on Security and Privacy, 2002
Christina Warrender, Stephanie Forrest, and Barak A. Pearlmutter: Detecting Intrusions using System Calls: Alternative Data Models. IEEE Symposium on Security and Privacy, 1999
Robin Sommer and Vern Paxson: Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. IEEE Symposium on Security and Privacy, 2010
C. Christopher Erway, Alptekin Küpçü, Charalampos Papamanthou, and Roberto Tamassia: Dynamic provable data possession. ACM Conference on Computer and Communications Security (CCS), 2009
J. Alex Halderman, Seth D. Schoen, Nadia Heninger, William Clarkson, William Paul, Joseph A. Calandrino, Ariel J. Feldman, Jacob Appelbaum, and Edward W. Felten: Lest We Remember: Cold Boot Attacks on Encryption Keys. USENIX Security Symposium, 2008
Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart: Stealing Machine Learning Models via Prediction APIs. USENIX Security Symposium, 2016
Arthur Gervais, Ghassan O. Karame, Karl Wüst, Vasileios Glykantzis, Hubert Ritzdorf, and Srdjan Capkun: On the Security and Performance of Proof of Work Blockchains. ACM Conference on Computer and Communications Security (CCS), 2016
Weilin Xu, David Evans, and Yanjun Qi: Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. Network and Distributed System Security Symposium (NDSS), 2018
Patrice Godefroid, Michael Y. Levin, and David A. Molnar: Automated Whitebox Fuzz Testing. Network and Distributed System Security Symposium (NDSS), 2008
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K. Reiter: Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition. ACM Conference on Computer and Communications Security (CCS), 2016
Reiner Sailer, Xiaolan Zhang, Trent Jaeger, and Leendert van Doorn: Design and Implementation of a TCG-based Integrity Measurement Architecture. USENIX Security Symposium, 2004
Cristian Cadar, Vijay Ganesh, Peter M. Pawlowski, David L. Dill, and Dawson R. Engler: EXE: automatically generating inputs of death. ACM Conference on Computer and Communications Security (CCS), 2006
Matthew G. Schultz, Eleazar Eskin, Erez Zadok, and Salvatore J. Stolfo: Data Mining Methods for Detection of New Malicious Executables. IEEE Symposium on Security and Privacy, 2001
Joseph Bonneau, Andrew Miller, Jeremy Clark, Arvind Narayanan, Joshua A. Kroll, and Edward W. Felten: SoK: Research Perspectives and Challenges for Bitcoin and Cryptocurrencies. IEEE Symposium on Security and Privacy, 2015
Qian Wang, Cong Wang, Jin Li, Kui Ren, and Wenjing Lou: Enabling Public Verifiability and Data Dynamics for Storage Security in Cloud Computing. European Symposium on Research in Computer Security (ESORICS), 2009
Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg: Meltdown: Reading Kernel Memory from User Space. USENIX Security Symposium, 2018
Rafail Ostrovsky, Amit Sahai, and Brent Waters: Attribute-based encryption with non-monotonic access structures. ACM Conference on Computer and Communications Security (CCS), 2007
William Enck, Machigar Ongtang, and Patrick D. McDaniel: On lightweight mobile phone application certification. ACM Conference on Computer and Communications Security (CCS), 2009
Adrian Perrig, Ran Canetti, J. D. Tygar, and Dawn Xiaodong Song: Efficient Authentication and Signing of Multicast Streams over Lossy Channels. IEEE Symposium on Security and Privacy, 2000
Richard Lippmann, Robert K. Cunningham, David J. Fried, Isaac Graf, Kris R. Kendall, Seth E. Webster, and Marc A. Zissman: Results of the DARPA 1998 Offline Intrusion Detection Evaluation. International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 1999
Kevin D. Bowers, Ari Juels, and Alina Oprea: HAIL: a high-availability and integrity layer for cloud storage. ACM Conference on Computer and Communications Security (CCS), 2009
Ari Juels, Ronald L. Rivest, and Michael Szydlo: The blocker tag: selective blocking of RFID tags for consumer privacy. ACM Conference on Computer and Communications Security (CCS), 2003
Joseph Bonneau, Cormac Herley, Paul C. van Oorschot, and Frank Stajano: The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes. IEEE Symposium on Security and Privacy, 2012
Hovav Shacham, Matthew Page, Ben Pfaff, Eu-Jin Goh, Nagendra Modadugu, and Dan Boneh: On the effectiveness of address-space randomization. ACM Conference on Computer and Communications Security (CCS), 2004
Ian Miers, Christina Garman, Matthew Green, and Aviel D. Rubin: Zerocoin: Anonymous Distributed E-Cash from Bitcoin. IEEE Symposium on Security and Privacy, 2013
Loi Luu, Viswesh Narayanan, Chaodong Zheng, Kunal Baweja, Seth Gilbert, and Prateek Saxena: A Secure Sharding Protocol For Open Blockchains. ACM Conference on Computer and Communications Security (CCS), 2016
Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov: Exploiting Unintended Feature Leakage in Collaborative Learning. IEEE Symposium on Security and Privacy, 2019
Ke Wang and Salvatore J. Stolfo: Anomalous Payload-Based Network Intrusion Detection. International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2004
Miguel E. Andrés, Nicolás Emilio Bordenabe, Konstantinos Chatzikokolakis, and Catuscia Palamidessi: Geo-indistinguishability: differential privacy for location-based systems. ACM Conference on Computer and Communications Security (CCS), 2013