获奖论文

四大安全会议历年最佳论文、杰出论文与 Distinguished Paper 汇总。

分组依据:

IEEE S&P

Distinguished Paper Award52

  • Enter, Exit, Page Fault, Leak: Testing Isolation Boundaries for Microarchitectural Leaks2026
  • Your Compiler is Backdooring Your Model: Understanding and Exploiting Compilation Inconsistency Vulnerabilities in Deep Learning Compilers2026
  • Demystifying and Exploiting ASLR on NVIDIA GPUs2026
  • Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization2026
  • Nebula: Proving machine executions via folding schemes2026
  • LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations Centres2026
  • Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical Risks2026
  • Lost in Translation: Text Message Spoofing via Email2026
  • BreakFAST: Confused Deputy Attack on Infinity Fabric to Break AMD SEV-SNP2026
  • Weighted Batched Threshold Encryption with Applications to Mempool Privacy2026
  • TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities2026
  • GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer2026
  • Responsible Disclosure is a Two-Way Street: Empirically Measuring the Responsible Disclosure Contract in the Firmware Ecosystem2026
  • Goldilocks and the Three P-States: Mitigating Hertzbleed with Formal Leakage Guarantees2026
  • COBBL: Dynamic Constraint Generation for SNARKs2025
  • Transport Layer Obscurity: Circumventing SNI Censorship on the TLS Layer2025
  • Follow My Flow: Unveiling Client-Side Prototype Pollution Gadgets from One Million Real-World Websites2025
  • CipherSteal: Stealing Input Data from TEE-Shielded Neural Networks with Ciphertext Side Channels2025
  • Characterizing Robocalls with Multiple Vantage Points2025
  • Verifiable Boosted Tree Ensembles2025
  • Breaking the Barrier: Post-Barrier Spectre Attacks2025
  • Unveiling Security Vulnerabilities in Git Large File Storage Protocol2025
  • The Inadequacy of Similarity-based Privacy Metrics: Privacy Attacks against “Truly Anonymous” Synthetic Datasets2025
  • Empc: Effective Path Prioritization for Symbolic Execution with Path Cover2025
  • SLAP: Data Speculation Attacks via Load Address Prediction on Apple Silicon2025
  • Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications2025
  • DataSentinel: A Game-Theoretic Detection of Prompt Injection Attacks2025
  • BENZENE: A Practical Root Cause Analysis System with an Under-Constrained State Mutation2024
  • Shedding Light on CVSS Scoring Inconsistencies: A User-Centric Study on Evaluating Widespread Security Vulnerabilities2024
  • False negative - that one is going to kill you." - Understanding Industry Perspectives of Static Analysis based Security Testing2024
  • The Great Request Robbery: An Empirical Study of Client-side Request Hijacking Vulnerabilities on the Web2024
  • SoK: Prudent Evaluation Practices for Fuzzing2024
  • SoK: Unintended Interactions among Machine Learning Defenses and Risks2024
  • From Virtual Touch to Tesla Command: Unlocking Unauthenticated Control Chains From Smart Glasses for Vehicle Takeover2024
  • From Chatbots to Phishbots?: Phishing Scam Generation in Commercial Large Language Models2024
  • WESEE: Using Malicious #VC Interrupts to Break AMD SEV-SNP2024
  • MEGA: Malleable Encryption Goes Awry2023
  • Weak Fiat-Shamir Attacks on Modern Proof Systems2023
  • Typing High-Speed Cryptography against Spectre v12023
  • Practically-exploitable Cryptographic Vulnerabilities in Matrix2023
  • Red Team vs. Blue Team: A Real-World Hardware Trojan Detection Case Study Across Four Modern CMOS Technology Generations2023
  • It"s (DOM) Clobbering Time: Attack Techniques, Prevalence, and Defenses2023
  • The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web2023
  • WaVe: a verifiably secure WebAssembly sandboxing runtime2023
  • Characterizing Everyday Misuse of Smart Home Devices2023
  • Not Yet Another Digital ID: Privacy-preserving Humanitarian Aid Distribution2023
  • In Eighty Percent of the Cases, I Select the Password for Them": Security and Privacy Challenges, Advice, and Opportunities at Cybercafes in Kenya2023
  • Space Odyssey: An Experimental Software Security Analysis of Satellites2023
  • Four Attacks and a Proof for Telegram2022
  • Asleep at the Keyboard? Assessing the Security of GitHub Copilot’s Code Contributions2022
  • Invisible Finger: Practical Electromagnetic Interference Attack on Touchscreen-based Electronic Devices2022
  • Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software Projects2022

Test of Time Award26

  • A Comparison of Commercial and Military Computer Security Policies2026
  • The Chinese Wall Security Policy2026
  • De-anonymizing Social Networks2026
  • Dissecting Android Malware: Characterization and Evolution2026
  • The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes2026
  • Towards Making Systems Forget with Machine Unlearning2025
  • CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization2025
  • Modeling and Discovering Vulnerabilities with Code Property Graphs2024
  • Zerocash: Decentralized Anonymous Payments from Bitcoin2024
  • Pinocchio: Nearly Practical Verifiable Computation2023
  • Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms2023
  • Unleashing Mayhem on Binary Code2022
  • Click Trajectories: End-to-End Analysis of the Spam Value Chain2022
  • SCION: Scalability, Control, and Isolation On Next-Generation Networks2022
  • Password Cracking Using Probabilistic Context-Free Grammars2021
  • Native Client: A Sandbox for Portable, Untrusted x86 Native Code2021
  • Quantifying Location Privacy2021
  • A Sense of Self for Unix Processes2020
  • Cryptovirology: Extortion-Based Security Threats and Countermeasures2020
  • Decentralized Trust Management2020
  • Analysis of a Denial of Service Attack on TCP2020
  • Efficient Authentication and Signing of Multicast Streams Over Lossy Channels2020
  • Practical Techniques for Searches on Encrypted Data2020
  • Distributed Detection of Node Replication Attacks in Sensor Networks2020
  • Experimental Security Analysis of a Modern Automobile2020
  • Outside the Closed World: On Using Machine Learning for Network Intrusion Detection2020

AI-Selected "Best" Poster Award1

  • GlucOS: A secure, safe and extensible system for automated insulin delivery2024

Best Paper Award3

  • Compositional Security for Reentrant Applications2021
  • Hardware-Software Contracts for Secure Speculation2021
  • TRRespass: Exploiting the Many Sides of Target Row Refresh2020

Best Poster Award1

  • Private Information Leakage from Polygenic Risk Scores2025

Best Student Paper Award3

  • CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in Phishing2021
  • They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and Websites2021
  • Can Voters Detect Malicious Manipulation of Ballot Marking Devices?2020

Best Practical Paper Award2

  • The EMV Standard: Break, Fix, Verify2021
  • An Analysis of Pre-installed Android Software2020

Best Screenplay Award1

  • Hear "No Evil", See "Kenansville": Efficient and Transferable Black-Box Attacks on Speech Recognition and Voice Identification Systems2021

Best Film Editing Award1

  • Good Bot, Bad Bot: Characterizing Automated Browsing Activity2021

Best Video Award1

  • Reading Between the Lines: An Extensive Evaluation of the Security and Privacy Implications of EPUB Reading Systems2021