{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T05:44:42Z","timestamp":1782798282565,"version":"3.54.5"},"reference-count":56,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T00:00:00Z","timestamp":1779321600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T00:00:00Z","timestamp":1779321600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,21]]},"DOI":"10.1109\/spw72489.2026.00031","type":"proceedings-article","created":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T19:38:32Z","timestamp":1782761912000},"page":"257-267","source":"Crossref","is-referenced-by-count":0,"title":["On the Mismatch of Disclosure Practices in Security and Privacy Research"],"prefix":"10.1109","author":[{"given":"Simon","family":"Koch","sequence":"first","affiliation":[{"name":"University of Innsbruck"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jannik","family":"Hartung","sequence":"additional","affiliation":[{"name":"TU Braunschweig"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rainer","family":"B\u00f6hme","sequence":"additional","affiliation":[{"name":"University of Innsbruck"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Klein","sequence":"additional","affiliation":[{"name":"Max Planck Institute for Security and Privacy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-006-9012-5"},{"key":"ref2","article-title":"Bamboozling Certificate Authorities with BGP","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Birge-Lee","year":"2018"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP60621.2024.00016"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3372115"},{"key":"ref5","article-title":"Automating Cookie Consent and GDPR Violation Detection","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Bollinger","year":"2022"},{"key":"ref6","article-title":"Automated large-scale analysis of cookie notice compliance","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Bouhoula","year":"2024"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560574"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3765034"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/2535813.2535818"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00022"},{"key":"ref11","article-title":"An Empirical Study of Vulnerability Rewards Programs","volume-title":"22nd USENIX Security Symposium (USENIX Security 13)","author":"Finifter","year":"2013"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29962-0_4"},{"key":"ref13","article-title":"Analyzing the AI nudification application ecosystem","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Gibson","year":"2025"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417289"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00018"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2025-0133"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833593"},{"key":"ref18","article-title":"RVFUZZER: Finding input validation bugs in robotic vehicles through control-guided testing","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Kim","year":"2019"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0119"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-68697-5_9"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0033"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0046"},{"key":"ref23","volume-title":"Kyle-Kyle and Peace-Maker. top4grep.","year":"2026"},{"key":"ref24","article-title":"Mining Node.js Vulnerabilities via Object Dependence Graph and Query","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Li","year":"2022"},{"key":"ref25","article-title":"ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS Detection","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Li","year":"2021"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23158"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00121"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24078"},{"key":"ref29","article-title":"Effective Notification Campaigns on the Web: A Matter of Trust, Framing, and Support","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Maass","year":"2021"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00076"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP63326.2025.00015"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2018-0025"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3634737.3661137"},{"key":"ref34","article-title":"Share First, Ask Later (or Never?) Studying Violations of GDPR\u2019s Explicit Consent in Android Apps","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Nguyen","year":"2021"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560564"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3545948.3545952"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2018-0030"},{"key":"ref38","volume-title":"Vulnerability disclosure cheat sheet","year":"2026"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2018-0021"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23413"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.14"},{"key":"ref42","article-title":"Confusing Value with Enumeration: Studying the Use of CVEs in Academia","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Schloegel","year":"2025"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24610"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.240388"},{"key":"ref45","article-title":"Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability Notification","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Stock","year":"2016"},{"key":"ref46","article-title":"Navigating cookie consent violations across the globe","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Tang","year":"2025"},{"key":"ref47","article-title":"FIXX: FInding eXploits from eXamples","volume-title":"USENIX Security Symposium (USENIX Sec)","author":"Thimmaiah","year":"2025"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0082"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00027"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24080"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0076"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485839"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623067"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560597"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00077"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616584"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy Workshops (SPW)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,21]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy Workshops (SPW)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573640\/11573382\/11573745.pdf?arnumber=11573745","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T05:13:56Z","timestamp":1782796436000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573745\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,21]]},"references-count":56,"URL":"https:\/\/doi.org\/10.1109\/spw72489.2026.00031","relation":{},"subject":[],"published":{"date-parts":[[2026,5,21]]}}}