Security Papers from the 2020s

This webpage is an attempt to assemble a ranking of top-cited security papers from the 2020s. The ranking has been created based on citations of papers published at top security conferences. More details are available here.

Top-cited papers from 2025 ⌄

  1. 1
    Jan Lauinger, Jens Ernstberger, Andreas Finkenzeller, and Sebastian Steinhorst:
    Janus: Fast Privacy-Preserving Data Provenance For TLS.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    13 cites at Google Scholar
    1115% above average of year
    Visited: Jan-2025
    Paper: DOI
  2. 2
    Jayshree Sarathy and Salil P. Vadhan:
    Analyzing the Differentially Private Theil-Sen Estimator for Simple Linear Regression.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    10 cites at Google Scholar
    835% above average of year
    Visited: Jan-2025
    Paper: DOI
  3. 3
    Cong Zuo, Shangqi Lai, Shi-Feng Sun, Xingliang Yuan, Joseph K. Liu, Jun Shao, Huaxiong Wang, Liehuang Zhu, and Shujie Cui:
    Searchable Encryption for Conjunctive Queries with Extended Forward and Backward Privacy.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    7 cites at Google Scholar
    554% above average of year
    Visited: Dec-2024
    Paper: DOI
  4. 4
    Ismat Jarin, Yu Duan, Rahmadi Trimananda, Hao Cui, Salma Elmalaki, and Athina Markopoulou:
    BehaVR: User Identification Based on VR Sensor Data.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    4 cites at Google Scholar
    274% above average of year
    Visited: Jan-2025
    Paper: DOI
  5. 5
    Ghous Amjad, Kevin Yeo, and Moti Yung:
    RSA Blind Signatures with Public Metadata.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    4 cites at Google Scholar
    274% above average of year
    Visited: Jan-2025
    Paper: DOI
  6. 6
    Christopher Harth-Kitzerow, Ajith Suresh, Yongqin Wang, Hossein Yalame, Georg Carle, and Murali Annavaram:
    High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network Settings.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    3 cites at Google Scholar
    180% above average of year
    Visited: Dec-2024
    Paper: DOI
  7. 7
    Sayan Biswas, Mathieu Even, Anne-Marie Kermarrec, Laurent Massoulié, Rafael Pires, Rishi Sharma, and Martijn de Vos:
    Noiseless Privacy-Preserving Decentralized Learning.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    2 cites at Google Scholar
    87% above average of year
    Visited: Jan-2025
    Paper: DOI
  8. 8
    Fredrik Meisingseth and Christian Rechberger:
    SoK: Computational and Distributed Differential Privacy for MPC.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    1 cites at Google Scholar
    -7% below average of year
    Visited: Jan-2025
    Paper: DOI
  9. 9
    Fredrik Meisingseth, Christian Rechberger, and Fabian Schmid:
    Practical Two-party Computational Differential Privacy with Active Security.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    1 cites at Google Scholar
    -7% below average of year
    Visited: Jan-2025
    Paper: DOI
  10. 10
    Florine W. Dekker, Zekeriya Erkin, and Mauro Conti:
    Topology-Based Reconstruction Prevention for Decentralised Learning.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2025
    1 cites at Google Scholar
    -7% below average of year
    Visited: Jan-2025
    Paper: DOI

Top-cited papers from 2024 ⌄

  1. 1
    Xinyue Shen, Zeyuan Chen, Michael Backes, Yun Shen, and Yang Zhang:
    "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models.
    ACM Conference on Computer and Communications Security (CCS), 2024
    372 cites at Google Scholar
    11451% above average of year
    Visited: Jan-2025
    Paper: DOI
  2. 2
    Gelei Deng, Yi Liu, Yuekang Li, Kailong Wang, Ying Zhang, Zefeng Li, Haoyu Wang, Tianwei Zhang, and Yang Liu:
    MASTERKEY: Automated Jailbreaking of Large Language Model Chatbots.
    Network and Distributed System Security Symposium (NDSS), 2024
    189 cites at Google Scholar
    5769% above average of year
    Visited: Dec-2024
    Paper: DOI
  3. 3
    Nicholas Carlini, Matthew Jagielski, Christopher A. Choquette-Choo, Daniel Paleka, Will Pearce, Hyrum S. Anderson, Andreas Terzis, Kurt Thomas, and Florian Tramèr:
    Poisoning Web-Scale Training Datasets is Practical.
    IEEE Symposium on Security and Privacy (S&P), 2024
    179 cites at Google Scholar
    5458% above average of year
    Visited: Jan-2025
    Paper: DOI
  4. 4
    Zeyang Sha, Yicong Tan, Mingjie Li, Michael Backes, and Yang Zhang:
    ZeroFake: Zero-Shot Detection of Fake Images Generated and Edited by Text-to-Image Generation Models.
    ACM Conference on Computer and Communications Security (CCS), 2024
    147 cites at Google Scholar
    4465% above average of year
    Visited: Jan-2025
    Paper: DOI
  5. 5
    Ruijie Meng, Martin Mirchev, Marcel Böhme, and Abhik Roychoudhury:
    Large Language Model guided Protocol Fuzzing.
    Network and Distributed System Security Symposium (NDSS), 2024
    96 cites at Google Scholar
    2881% above average of year
    Visited: Jan-2025
    Paper: DOI
  6. 6
    Yuchen Yang, Bo Hui, Haolin Yuan, Neil Gong, and Yinzhi Cao:
    SneakyPrompt: Jailbreaking Text-to-image Generative Models.
    IEEE Symposium on Security and Privacy (S&P), 2024
    61 cites at Google Scholar
    1794% above average of year
    Visited: Dec-2024
    Paper: DOI
  7. 7
    Zhiyuan Yu, Xiaogeng Liu, Shunning Liang, Zach Cameron, Chaowei Xiao, and Ning Zhang:
    Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models.
    USENIX Security Symposium, 2024
    48 cites at Google Scholar
    1390% above average of year
    Visited: Jan-2025
    Paper: DOI
  8. 8
    Hojjat Aghakhani, Wei Dai, Andre Manoel, Xavier Fernandes, Anant Kharkar, Christopher Kruegel, Giovanni Vigna, David Evans, Ben Zorn, and Robert Sim:
    TrojanPuzzle: Covertly Poisoning Code-Suggestion Models.
    IEEE Symposium on Security and Privacy (S&P), 2024
    38 cites at Google Scholar
    1080% above average of year
    Visited: Jan-2025
    Paper: DOI
  9. 9
    Xinlei He, Savvas Zannettou, Yun Shen, and Yang Zhang:
    You Only Prompt Once: On the Capabilities of Prompt Learning on Large Language Models to Tackle Toxic Content.
    IEEE Symposium on Security and Privacy (S&P), 2024
    38 cites at Google Scholar
    1080% above average of year
    Visited: Dec-2024
    Paper: DOI
  10. 10
    Mingxun Zhou, Andrew Park, Wenting Zheng, and Elaine Shi:
    Piano: Extremely Simple, Single-Server PIR with Sublinear Server Computation.
    IEEE Symposium on Security and Privacy (S&P), 2024
    37 cites at Google Scholar
    1049% above average of year
    Visited: Dec-2024
    Paper: DOI

Top-cited papers from 2023 ⌄

  1. 1
    Nicholas Carlini, Jamie Hayes, Milad Nasr, Matthew Jagielski, Vikash Sehwag, Florian Tramèr, Borja Balle, Daphne Ippolito, and Eric Wallace:
    Extracting Training Data from Diffusion Models.
    USENIX Security Symposium, 2023
    578 cites at Google Scholar
    4571% above average of year
    Visited: Jan-2025
    Paper: DOI
  2. 2
    Hammond Pearce, Benjamin Tan, Baleegh Ahmad, Ramesh Karri, and Brendan Dolan-Gavitt:
    Examining Zero-Shot Vulnerability Repair with Large Language Models.
    IEEE Symposium on Security and Privacy (S&P), 2023
    302 cites at Google Scholar
    2341% above average of year
    Visited: Jan-2025
    Paper: DOI
  3. 3
    Linyi Li, Tao Xie, and Bo Li:
    SoK: Certified Robustness for Deep Neural Networks.
    IEEE Symposium on Security and Privacy (S&P), 2023
    202 cites at Google Scholar
    1532% above average of year
    Visited: Jan-2025
    Paper: DOI
  4. 4
    Shawn Shan, Jenna Cryan, Emily Wenger, Haitao Zheng, Rana Hanocka, and Ben Y. Zhao:
    Glaze: Protecting Artists from Style Mimicry by Text-to-Image Models.
    USENIX Security Symposium, 2023
    191 cites at Google Scholar
    1444% above average of year
    Visited: Dec-2024
    Paper: DOI
  5. 5
    Nils Lukas, Ahmed Salem, Robert Sim, Shruti Tople, Lukas Wutschitz, and Santiago Zanella Béguelin:
    Analyzing Leakage of Personally Identifiable Information in Language Models.
    IEEE Symposium on Security and Privacy (S&P), 2023
    183 cites at Google Scholar
    1379% above average of year
    Visited: Dec-2024
    Paper: DOI
  6. 6
    Yi Zeng, Minzhou Pan, Hoang Anh Just, Lingjuan Lyu, Meikang Qiu, and Ruoxi Jia:
    Narcissus: A Practical Clean-Label Backdoor Attack with Limited Information.
    ACM Conference on Computer and Communications Security (CCS), 2023
    177 cites at Google Scholar
    1330% above average of year
    Visited: Nov-2024
    Paper: DOI
  7. 7
    Maurice Weber, Xiaojun Xu, Bojan Karlas, Ce Zhang, and Bo Li:
    RAB: Provable Robustness Against Backdoor Attacks.
    IEEE Symposium on Security and Privacy (S&P), 2023
    177 cites at Google Scholar
    1330% above average of year
    Visited: Nov-2024
    Paper: DOI
  8. 8
    Neil Perry, Megha Srivastava, Deepak Kumar, and Dan Boneh:
    Do Users Write More Insecure Code with AI Assistants?
    ACM Conference on Computer and Communications Security (CCS), 2023
    168 cites at Google Scholar
    1258% above average of year
    Visited: Jan-2025
    Paper: DOI
  9. 9
    Liyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos, Zhipeng Wang, Ye Wang, Kaihua Qin, Roger Wattenhofer, Dawn Song, and Arthur Gervais:
    SoK: Decentralized Finance (DeFi) Attacks.
    IEEE Symposium on Security and Privacy (S&P), 2023
    163 cites at Google Scholar
    1217% above average of year
    Visited: Dec-2024
    Paper: DOI
  10. 10
    Alexander Warnecke, Lukas Pirch, Christian Wressnegger, and Konrad Rieck:
    Machine Unlearning of Features and Labels.
    Network and Distributed System Security Symposium (NDSS), 2023
    155 cites at Google Scholar
    1153% above average of year
    Visited: Dec-2024
    Paper: DOI

Top-cited papers from 2022 ⌄

  1. 1
    Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramèr:
    Membership Inference Attacks From First Principles.
    IEEE Symposium on Security and Privacy (S&P), 2022
    668 cites at Google Scholar
    2499% above average of year
    Visited: Dec-2024
    Paper: DOI
  2. 2
    Hammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt, and Ramesh Karri:
    Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code Contributions.
    IEEE Symposium on Security and Privacy (S&P), 2022
    434 cites at Google Scholar
    1589% above average of year
    Visited: Dec-2024
    Paper: DOI
  3. 3
    Daniel Arp, Erwin Quiring, Feargus Pendlebury, Alexander Warnecke, Fabio Pierazzi, Christian Wressnegger, Lorenzo Cavallaro, and Konrad Rieck:
    Dos and Don'ts of Machine Learning in Computer Security.
    USENIX Security Symposium, 2022
    415 cites at Google Scholar
    1515% above average of year
    Visited: Jan-2025
    Paper: DOI
  4. 4
    Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang:
    Dynamic Backdoor Attacks Against Machine Learning Models.
    IEEE European Symposium on Security and Privacy (EuroS&P), 2022
    338 cites at Google Scholar
    1215% above average of year
    Visited: Jan-2025
    Paper: DOI
  5. 5
    Virat Shejwalkar, Amir Houmansadr, Peter Kairouz, and Daniel Ramage:
    Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated Learning.
    IEEE Symposium on Security and Privacy (S&P), 2022
    312 cites at Google Scholar
    1114% above average of year
    Visited: Jan-2025
    Paper: DOI
  6. 6
    Kaihua Qin, Liyi Zhou, and Arthur Gervais:
    Quantifying Blockchain Extractable Value: How dark is the forest?
    IEEE Symposium on Security and Privacy (S&P), 2022
    304 cites at Google Scholar
    1083% above average of year
    Visited: Dec-2024
    Paper: DOI
  7. 7
    Thien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame, Helen Möllering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, Azalia Mirhoseini, Shaza Zeitouni, Farinaz Koushanfar, Ahmad-Reza Sadeghi, and Thomas Schneider:
    FLAME: Taming Backdoors in Federated Learning.
    USENIX Security Symposium, 2022
    302 cites at Google Scholar
    1075% above average of year
    Visited: Jan-2025
    Paper: DOI
  8. 8
    Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, and Reza Shokri:
    Enhanced Membership Inference Attacks against Machine Learning Models.
    ACM Conference on Computer and Communications Security (CCS), 2022
    243 cites at Google Scholar
    846% above average of year
    Visited: Dec-2024
    Paper: DOI
  9. 9
    Zhicong Huang, Wen-jie Lu, Cheng Hong, and Jiansheng Ding:
    Cheetah: Lean and Fast Secure Two-Party Deep Neural Network Inference.
    USENIX Security Symposium, 2022
    225 cites at Google Scholar
    776% above average of year
    Visited: Dec-2024
    Paper: DOI
  10. 10
    Theresa Stadler, Bristena Oprisanu, and Carmela Troncoso:
    Synthetic Data - Anonymisation Groundhog Day.
    USENIX Security Symposium, 2022
    220 cites at Google Scholar
    756% above average of year
    Visited: Dec-2024
    Paper: DOI

Top-cited papers from 2021 ⌄

  1. 1
    Nicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom B. Brown, Dawn Song, Úlfar Erlingsson, Alina Oprea, and Colin Raffel:
    Extracting Training Data from Large Language Models.
    USENIX Security Symposium, 2021
    1721 cites at Google Scholar
    3769% above average of year
    Visited: Nov-2024
    Paper: DOI
  2. 2
    Lucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hengrui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot:
    Machine Unlearning.
    IEEE Symposium on Security and Privacy (S&P), 2021
    866 cites at Google Scholar
    1847% above average of year
    Visited: Dec-2024
    Paper: DOI
  3. 3
    Xiaoyu Cao, Minghong Fang, Jia Liu, and Neil Zhenqiang Gong:
    FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping.
    Network and Distributed System Security Symposium (NDSS), 2021
    626 cites at Google Scholar
    1307% above average of year
    Visited: Dec-2024
    Paper: DOI
  4. 4
    Virat Shejwalkar and Amir Houmansadr:
    Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning.
    Network and Distributed System Security Symposium (NDSS), 2021
    449 cites at Google Scholar
    909% above average of year
    Visited: Dec-2024
    Paper: DOI
  5. 5
    Xiaoyi Chen, Ahmed Salem, Dingfan Chen, Michael Backes, Shiqing Ma, Qingni Shen, Zhonghai Wu, and Yang Zhang:
    BadNL: Backdoor Attacks against NLP Models with Semantic-preserving Improvements.
    Annual Computer Security Applications Conference (ACSAC), 2021
    394 cites at Google Scholar
    786% above average of year
    Visited: Jan-2025
    Paper: DOI
  6. 6
    Lorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy, and Markus Schofnegger:
    Poseidon: A New Hash Function for Zero-Knowledge Proof Systems.
    USENIX Security Symposium, 2021
    392 cites at Google Scholar
    781% above average of year
    Visited: Dec-2024
    Paper: DOI
  7. 7
    Liwei Song and Prateek Mittal:
    Systematic Evaluation of Privacy Risks of Machine Learning Models.
    USENIX Security Symposium, 2021
    380 cites at Google Scholar
    754% above average of year
    Visited: Dec-2024
    Paper: DOI
  8. 8
    Xiaojun Xu, Qi Wang, Huichen Li, Nikita Borisov, Carl A. Gunter, and Bo Li:
    Detecting AI Trojans Using Meta Neural Analysis.
    IEEE Symposium on Security and Privacy (S&P), 2021
    355 cites at Google Scholar
    698% above average of year
    Visited: Dec-2024
    Paper: DOI
  9. 9
    Eugene Bagdasaryan and Vitaly Shmatikov:
    Blind Backdoors in Deep Learning Models.
    USENIX Security Symposium, 2021
    348 cites at Google Scholar
    682% above average of year
    Visited: Jan-2025
    Paper: DOI
  10. 10
    Ellis Fenske, Dane Brown, Jeremy Martin, Travis Mayberry, Peter Ryan, and Erik C. Rye:
    Three Years Later: A Study of MAC Address Randomization In Mobile Devices And When It Succeeds.
    Proceedings on Privacy Enhancing Technologies (PoPETS), 2021
    321 cites at Google Scholar
    622% above average of year
    Visited: Jan-2025
    Paper: DOI

Top-cited papers from 2020 ⌄

  1. 1
    Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong:
    Local Model Poisoning Attacks to Byzantine-Robust Federated Learning.
    USENIX Security Symposium, 2020
    1296 cites at Google Scholar
    1848% above average of year
    Visited: Jan-2025
    Paper: DOI
  2. 2
    Vale Tolpegin, Stacey Truex, Mehmet Emre Gursoy, and Ling Liu:
    Data Poisoning Attacks Against Federated Learning Systems.
    European Symposium on Research in Computer Security (ESORICS), 2020
    870 cites at Google Scholar
    1208% above average of year
    Visited: Jan-2025
    Paper: DOI
  3. 3
    Jianbo Chen, Michael I. Jordan, and Martin J. Wainwright:
    HopSkipJumpAttack: A Query-Efficient Decision-Based Attack.
    IEEE Symposium on Security and Privacy (S&P), 2020
    825 cites at Google Scholar
    1140% above average of year
    Visited: Dec-2024
    Paper: DOI
  4. 4
    Marcel Keller:
    MP-SPDZ: A Versatile Framework for Multi-Party Computation.
    ACM Conference on Computer and Communications Security (CCS), 2020
    556 cites at Google Scholar
    736% above average of year
    Visited: Dec-2024
    Paper: DOI
  5. 5
    Philip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li, Xueyuan Zhao, Iddo Bentov, Lorenz Breidenbach, and Ari Juels:
    Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus Instability.
    IEEE Symposium on Security and Privacy (S&P), 2020
    548 cites at Google Scholar
    724% above average of year
    Visited: Dec-2024
    Paper: DOI
  6. 6
    Pratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, and Raluca Ada Popa:
    Delphi: A Cryptographic Inference Service for Neural Networks.
    USENIX Security Symposium, 2020
    528 cites at Google Scholar
    694% above average of year
    Visited: Dec-2024
    Paper: DOI
  7. 7
    James Henry Bell, Kallista A. Bonawitz, Adrià Gascón, Tancrède Lepoint, and Mariana Raykova:
    Secure Single-Server Aggregation with (Poly)Logarithmic Overhead.
    ACM Conference on Computer and Communications Security (CCS), 2020
    454 cites at Google Scholar
    582% above average of year
    Visited: Dec-2024
    Paper: DOI
  8. 8
    Matthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin, and Nicolas Papernot:
    High Accuracy and High Fidelity Extraction of Neural Networks.
    USENIX Security Symposium, 2020
    435 cites at Google Scholar
    554% above average of year
    Visited: Dec-2024
    Paper: DOI
  9. 9
    Dingfan Chen, Ning Yu, Yang Zhang, and Mario Fritz:
    GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative Models.
    ACM Conference on Computer and Communications Security (CCS), 2020
    431 cites at Google Scholar
    548% above average of year
    Visited: Jan-2025
    Paper: DOI
  10. 10
    Kit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck, Daniel Gruss, and Frank Piessens:
    Plundervolt: Software-based Fault Injection Attacks against Intel SGX.
    IEEE Symposium on Security and Privacy (S&P), 2020
    420 cites at Google Scholar
    531% above average of year
    Visited: Dec-2024
    Paper: DOI