0x00401000 entry function · 0 xrefs

SoftSec Lab
Software Security Research


We study how software fails and build systems that find, explain, and prevent vulnerabilities. Our work centers on fuzzing, program analysis, binary security, and the empirical foundations of security research.

We are a research group within the CISPA Helmholtz Center for Information Security located in Saarbrücken, Germany.

0x004012a0 loc_research 3 directions

What we work on

Research Directions

Our research focuses on three connected areas:

1

Fuzzing & Automated Vulnerability Discovery

New fuzzing strategies for hard targets, including browsers, closed-source binaries, network services, or web applications. We rethink how inputs are generated and mutated. Our goal? To find bugs before attackers do.

2

Program Analysis & Binary Security

We develop program analysis techniques that reason about software, its behavior, and security properties — from source code to stripped binaries. Our work spans understanding what code does, why it fails, and what an attacker can do with that failure.

3

Empirical Security Science

Good security research requires more than good tools. We take a meta-scientific view and examine whether empirical evaluations can be trusted, how we determine the impact of our research in practice, and reflect on our vulnerability disclosure practices.

0x00401860 loc_pubs loop header · 2 xrefs

Our work

Publications

2026
Hongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi, Moritz Schloegel, Tiffany Bao, Ruoyu Wang, Adam Doupé, Zhiqiang Lin, Yan Shoshitaishvili
James Mattei, Andrew Lin, Jasper Geer, Jie Hu, Moritz Schloegel, Tiffany Bao, Daniel Votipka
Nico Schiller, Nils Bars, Moritz Schloegel, Thorsten Holz
THEMIS: Context-Aware Grey-box Fuzzing for WordPress Plugins
Matteo Leonelli, David Dewes, Thorsten Holz
Hui Jun Tay, Souradip Nath, Arvind S Raj, Abhay Bhat, Ishan Bansal, Audrey Dutcher, Moritz Schloegel, Adam Doupé, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang
Kyle Zeng, Moritz Schloegel, Christopher Salls, Adam Doupé, Ruoyu Wang, Yan Shoshitaishvili, Tiffany Bao
2025
Florian Schweins, Moritz Schloegel, Moritz Bley, Nico Schiller, Thorsten Holz
Nils Bars, Lukas Bernhard, Moritz Schloegel, Thorsten Holz
Moritz Bley, Tobias Scharnowski, Simon Wörner, Moritz Schloegel, Thorsten Holz
Moritz Schloegel, Daniel Klischies, Simon Koch, David Klein, Lukas Gerlach, Malte Wessels, Leon Trampert, Martin Johns, Mathy Vanhoef, Michael Schwarz, Thorsten Holz, Jo Van Bulck
IUBIK: Isolating User Bytes in Commodity Operating System Kernels via Memory Tagging Extensions
Marius Momeu, Alexander J Gaidis, Jasper von der Heidt, Vasileios P Kemerlis
Johannes Willbold, Tobias Cloosters, Simon Wörner, Felix Buchmann, Moritz Schloegel, Lucas Davi, Thorsten Holz
Nico Schiller, Xinyi Xu, Lukas Bernhard, Nils Bars, Moritz Schloegel, Thorsten Holz
2024
Lukas Bernhard, Nico Schiller, Moritz Schloegel, Nils Bars, Thorsten Holz
Nils Bars, Moritz Schloegel, Nico Schiller, Lukas Bernhard, Thorsten Holz
Joschua Schilling, Andreas Wendler, Philipp Görz, Nils Bars, Moritz Schloegel, Thorsten Holz
Emre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars, Philipp Görz, Xinyi Xu, Thorsten Holz
Felix Weißberg, Jonas Möller, Tom Ganz, Erik Imgrund, Lukas Pirch, Lukas Seidel, Moritz Schloegel, Thorsten Eisenhofer, Konrad Rieck
Minimum Requirements for Space System Cybersecurity — Ensuring Cyber Access to Space
Gregory Falco, others
Johannes Willbold, Moritz Schloegel, Robin Bisping, Martin Strohmeier, Thorsten Holz, Vincent Lenders
Moritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard, Tobias Scharnowski, Addison Crump, Arash Ale Ebrahim, Nicolai Bissantz, Marius Muench, Thorsten Holz
Johannes Willbold, Moritz Schloegel, Florian Göhler, Tobias Scharnowski, Nils Bars, Simon Wörner, Nico Schiller, Thorsten Holz
2023
Nils Bars, Moritz Schloegel, Tobias Scharnowski, Nico Schiller, Thorsten Holz
Tobias Scharnowski, Simon Wörner, Felix Buchmann, Nils Bars, Moritz Schloegel, Thorsten Holz
Daniel Klischies, Moritz Schloegel, Tobias Scharnowski, Mikhail Bogodukhov, David Rupprecht, Veelasha Moonsamy
Johannes Willbold, Moritz Schloegel, Manuel Vögele, Maximilian Gerhardt, Thorsten Holz, Ali Abbasi
Nico Schiller, Merlin Chlosta, Moritz Schloegel, Nils Bars, Thorsten Eisenhofer, Tobias Scharnowski, Felix Domke, Lea Schönherr, Thorsten Holz
2022
Lukas Bernhard, Tobias Scharnowski, Moritz Schloegel, Tim Blazytko, Thorsten Holz
Tobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson, Marius Muench, Giovanni Vigna, Christopher Kruegel, Thorsten Holz, Ali Abbasi
Moritz Schloegel, Tim Blazytko, Moritz Contag, Cornelius Aschermann, Julius Basler, Thorsten Holz, Ali Abbasi
2021
Moritz Schloegel, Tim Blazytko, Julius Basler, Fabian Hemmer, Thorsten Holz
2020
Tim Blazytko, Moritz Schloegel, Cornelius Aschermann, Ali Abbasi, Joel Frank, Simon Wörner, Thorsten Holz
2019
Tim Blazytko, Cornelius Aschermann, Moritz Schloegel, Ali Abbasi, Sergej Schumilo, Simon Wörner, Thorsten Holz
0x00401b40 loc_team struct team[]
0x00401cc0 loc_news latest

Latest

News

Jul 2026 "SoK: A Modularized Framework for Symbolic Execution and Application for Usable Tool Design" receives a Distinguished Paper Award at ACM SecDev 2026.
May 2026 "Responsible Disclosure is a Two-Way Street" receives a Distinguished Paper Award at IEEE S&P 2026.
Nov 2025 "Empirical Security Analysis of Software-based Fault Isolation" wins a Distinguished Paper Award at ACM CCS 2025.
Aug 2025 "Confusing Value with Enumeration: Studying the Use of CVEs in Academia" wins a Distinguished Paper Award at USENIX Security 2025.
Aug 2024 DarthShader receives a Distinguished Artifact Award at ACM CCS 2024.
May 2024 "SoK: Prudent Evaluation Practices for Fuzzing" receives a Distinguished Paper Award at IEEE S&P 2024.
Aug 2023 Fuzztruction wins a Distinguished Paper Award and the Internet Defense Prize Runner-up at USENIX Security 2023.
May 2023 Space Odyssey wins a Distinguished Paper Award at IEEE S&P 2023.
0x00401e20 loc_join if (interested)

Join the group

Open Positions

Interested in joining our lab as a PhD student or Postdoc? While we have no formally advertised positions at the moment, we are always interested in hearing from strong candidates. Ideally, you have strong grades and a background in low-level security (for example, experience with reverse engineering or exploitation) or a strong track record in the field of systems security.

We also offer a broad range of internship opportunities.

If you are interested in joining us, please reach out with a brief introduction and your CV to moritz.schloegel@cispa.de.

0x00401ee0 loc_contact

Get in touch

Contact

Email

Moritz Schloegel

moritz.schloegel@cispa.de

Address

CISPA Helmholtz Center for Information Security

Stuhlsatzenhaus 5

66123 Saarbrücken, Germany