- Book Chapter
- 10.1007/978-3-658-50744-2_10
Zwischenergebnis
- Jan 01, 2026
- Annika Selzer
Publications from 2021 to 2026
Showing 10 of 138 papers
Zwischenergebnis
Quantifizierung der Implementierungskosten
Not Discrete Enough: On the Inherent Insecurity of dTPMs for Measured Boot
Datenschutz in Metaversen
Metaversen bieten vielfältige Einsatzmöglichkeiten vor allem in den Bereichen der Kommunikation, Zusammenarbeit und Unterhaltung sowie durch neue Geschäftsmodelle und Bildungsmöglichkeiten, wovon die in Metaversen agierenden Unternehmen und Nutzer profitieren können. Neben diesen Chancen ist die Nutzung von Metaversen aber auch mit diversen Risiken für die Nutzer verbunden. Insbesondere im Datenschutzrecht ergeben sich dabei neue rechtliche Herausforderungen. In Metaversen besteht häufig das Problem der mangelnden Transparenz der Datenverarbeitungsvorgänge. Zahlreiche Akteure in Metaversen verarbeiten kontinuierlich große Mengen an Daten, darunter befinden sich auch personenbezogene Daten der Nutzer. Die Menge und die Komplexität der Verarbeitungsvorgänge wirft deshalb Fragen auf, insbesondere hinsichtlich der Rolle der jeweiligen beteiligten Akteure, deren datenschutzrechtlichen Verantwortlichkeiten sowie den Rechtsgrundlagen für die verschiedenen Verarbeitungsvorgänge. Dieser Beitrag soll daher beleuchten, wie sich die datenschutzrechtlichen Verantwortlichkeiten nach der DSGVO in den komplexen Strukturen von Metaversen bestimmen lassen. Zudem wird untersucht, auf welche konkreten Rechtsgrundlagen sich typische Datenverarbeitungsszenarien stützen lassen. Ziel ist es, konkrete Handlungsempfehlungen für die Einhaltung datenschutzrechtlicher Vorgaben zu formulieren.
Read moreTerminator: Enabling Efficient Fuzzing of Closed-Source GUI Programs by Automatic Coverage-Guided Termination
When fuzzing a proprietary file-processing program, one typically executes the whole program repeatedly with sampled input files, and distinguishes between normal and abnormal termination. While this works well for many command-line utilities, it is more complicated for programs that usually do not terminate after input file processing. Many real-world applications are examples of such programs, in particular, those with a graphical user interface (GUI), such as image editors, media players and document viewers. In these cases, the fuzzer has to define the scope of the execution and forcefully terminate the program under test.In order to efficiently fuzz test file-processing programs with a GUI, a standard approach is to define a dedicated testing harness, which executes the file processing in isolation and strips irrelevant program parts. However, this either requires the source code of the program or an expert’s effort in reverse engineering. Alternative approaches work on the unmodified binary of the program, and use a heuristic to decide when the input processing is likely done. For example, one can terminate the program after a fixed timeout or once its CPU usage has dropped below a threshold. We show that these heuristics, while simple to implement, are inefficient and ineffective.We present Terminator, a fully-automated approach to facilitate efficient fuzzing of closed-source file-processing programs with a GUI. Terminator modifies the binary of the program under test so that it automatically terminates when code coverage stops increasing without user interaction. Consequently, Terminator (1) ensures that the program terminates soon after the input processing instead of waiting for user interaction, and, at the same time, (2) prevents premature termination during input processing. We show that Terminator outperforms the timeout and CPU usage heuristics and significantly increases fuzzing efficiency.
Read moreMADPromptS: Unlocking Zero-Shot Morphing Attack Detection with Multiple Prompt Aggregation
Face Morphing Attack Detection (MAD) is a critical challenge in face recognition security, where attackers can fool systems by interpolating the identity information of two or more individuals into a single face image, resulting in samples that can be verified as belonging to multiple identities by face recognition systems. While multimodal foundation models (FMs) like CLIP offer strong zero-shot capabilities by jointly modeling images and text, most prior works on FMs for biometric recognition have relied on fine-tuning for specific downstream tasks, neglecting their potential for direct, generalizable deployment. This work explores a pure zero-shot approach to MAD by leveraging CLIP without any additional training or fine-tuning, focusing instead on the design and aggregation of multiple textual prompts per class. By aggregating the embeddings of diverse prompts, we better align the model's internal representations with the MAD task, capturing richer and more varied cues indicative of bona-fide or attack samples. Our results show that prompt aggregation substantially improves zero-shot detection performance, demonstrating the effectiveness of exploiting foundation models' built-in multimodal knowledge through efficient prompt engineering.
Read moreFormal Verification of Autonomous Cyber Defense for Abstraction of Critical Network Scenarios
Autonomous Cyber Defense (ACD) systems require formal guarantees to ensure their reliability and effectiveness in protecting critical network infrastructures. This paper presents a formal verification approach for an abstraction of the Cyber Autonomy Gym for Experimentation (CAGE) Challenge 4 cybersecurity scenario using probabilistic model checking with Probabilistic Symbolic Model Checker (PRISM). We develop a comprehensive multi-zone enterprise network model that captures red-team attack strategies, cross-zone infiltration, and defensive mechanisms. Due to computational complexity and state explosion challenges, we implement a curriculum learning approach, starting with red-only agent models to understand attack behaviors before progressing to adversarial blue-red scenarios. Our methodology aims to prove the feasibility of formal verification for autonomous cyber defense validation, providing probabilistic guarantees for network security properties and establishing a foundation for future multi-agent formal verification frameworks. Our results demonstrate over eight selected scenarios that near-optimal blue policies achieve perfect service degradation prevention while revealing fundamental scalability limits with state spaces growing exponentially from a single-zone model to complete multi-zone scenarios.
Read moreMetaverse – eine Datenschutzfalle?
Compliance Made Practical: Translating the EU AI Act into Implementable Security Actions
The EU AI Act, along with emerging regulations in other countries, mandates that AI systems meet security requirements to prevent risks associated with AI misuse and vulnerabilities. However, for practitioners, defining and achieving a secure AI system is complex and context-dependent, posing challenges in understanding what actions they need to take and when they are sufficient. ISO/IEC TR 24028/29 and ENISA Securing Machine Learning Algorithms offer a comprehensive framework for AI security, aligning with the EU AI Act's requirements by addressing risks, threats, and mitigation strategies. However, for practical implementation, these reports lack hands-on guidance. Industry resources like the OWASP AI Exchange and OWASP LLM Top 10 fill this gap by providing accessible, actionable insights for securing AI systems effectively. This paper addresses the question of responsibility in AI risk mitigation, especially for companies utilizing pretrained or off-the-shelf models. We want to clarify how companies can practically comply with the upcoming ISO 27090 and ensure compliance with the EU AI Act through actionable security strategies tailored to this prevalent use case.
Read moreAutomated Monitoring of Stolen Cultural Artifacts on Online Marketplaces
Tracking and identifying stolen cultural artifacts on online marketplaces is a daunting task that has to be accomplished through manual search. In this paper, an automated monitoring tool is developed to track and identify stolen cultural goods on targeted online sales platforms. In case of theft, the original owner can upload descriptive keywords and photos of the stolen objects to start monitoring tasks to track and identify the stolen objects on targeted online marketplaces and get alerted when identical or highly similar objects appear on the monitored sales platforms. The technical challenges posed by automated monitoring are addressed by proposed advanced crawling and image feature extraction and matching solutions. With the support of proposed novel techniques, the developed monitoring tool can efficiently and effectively monitor stolen artifacts on online marketplaces, significantly reducing the manual inspection effort.
Read more