Juan Tapiador
Research
My main research interests are:
- Android security and privacy
- User tracking and sensitive information leaks via dead domains (PETS 2026), wireless-scanning SDKs (PETS 2025), WebViews (PETS 2025), custom permissions (TDSC 2024), smart-home appliances (IMC 2023), and system logs (USENIX Security 2023).
- Supply chain risks, including TLS customizations (EuroS&P 2025), software attribution challenges (TSE 2023), insecure OTA updates (S&P 2021), preinstalled software (S&P 2020), and characterization of Chinese app stores (IMC 2018).
- Malware
- Malware techniques, including AI-assisted polymorphic payload generation (2026), Android packers and code protectors (CSUR 2026), browser malware abusing CDP (EuroS&P 2023) and order-hijacking techniques (JIS 2019), optimization of code caves in PE binaries (COSE 2022), sandbox evasion via timing side-channels (ESORICS 2021), software complexity metrics in malware source code (TIFS 2019, RAID 2016), malware-family anti-classification techniques (ESWA 2018), hardware trojans (TRUDEVICE 2015), systematizing smartphone malware research (CS&T 2014), and stegomalware (Inscrypt 2014).
- Advanced analysis techniques, including LLMs for IOC extraction (2026), market vetting for malicious extensions (TSC 2026, SoftwareX 2025), identification of hidden behaviors using information flow analysis (ASIACCS 2017) and differential fault injection (TMC 2016, Computer 2014), methods for triggering targeted malware (ESORICS 2014), malware-family classification (ASIACCS 2019, ESWA 2014) and obfuscation detection (FGCS 2019).
- Cyberattacks
- Cyber threat intelligence, including threat actor naming (2025), disposable phone numbers (TMA 2023), inorganic engagement services (COSE 2023), open-source blocklists (TNSM 2021), domain classification services (IMC 2020), eWhoring attacks (IMC 2019), and threat intelligence sharing (CYCON 2013).
- Intrusion detection, including similarity metrics for provenance graphs (COSE 2025), anti-exploitation defenses for AVR microcontrollers (DIMVA 2016), automatic signature generation (COSE 2015), distributed attack detection (COMNET 2015, COMNET 2014), attacks against IDSs (TDSC 2015, JNCA 2014), detection of mimicry (COSE 2011) and web attacks (ISCC 2005, COSE 2004), and anomaly detection (COMCOM 2004, COMNET 2003, IWIA 2003).
Honors and awards
I have been fortunate to receive recognition for my work, including:
Outreach
My work has been featured in news outlets and specialist media, including:
-
Our PETS 2025 study on wireless-scanning SDKs was covered by El País.
- Our study on the fake engagement ecosystem was covered by El País, La Vanguardia, ABC, SER, Cybermagazine, and Tech Xplore.
- Our work on the evasion of information controls during the Ukraine war was covered by Fast Company.
- Our USENIX Security 2023 paper on sensitive data leaks in Android logs was covered by El País (English version here).
- Our IMC 2023 study on smart-home tracking was covered by El País, ABC, El Correo, COPE, and Onda Cero. My colleague and co-author of the study Joel Reardon was interviewed by CBC News Calgary.
-
Our IMC 2019 paper on eWhoring extortion attacks was covered by Wired and El País.
- Our IEEE S&P 2020 study on Android preinstalled software was covered by
Reuters,
The Times,
Le Figaro,
The Register,
Mozilla's Internet Health Report,
TechCrunch,
CPO Magazine,
ZDNet,
TechRadar,
El País (also here),
ABC,
Europa Press,
Cinco Días
La Vanguardia
La Razón
Público
El Economista
El Periódico
Telecinco
COPE,
RTVE (also here), and
TV3 (also here).
I've also been interviewed about the EU's proposed 2023 eIDAS reform (El Confidencial, Xataka, Newtral), EU digital identity wallets (El País and again
here), outages in global Internet services (El País), and encrypted phones (El País).
Other