
Stefan Marksteiner is a Senior Scientist at AIT's Center for Digital Safety & Security, focusing on Security Assurance Engineering — the systematic, evidence-based verification that systems are secure before deployment. Research areas include formal protocol verification, automata learning, model-based security testing, and AI-driven test generation from TARA threat models. Current work extends this to LLM-based test script generation with formal verification via CFG-to-Rebeca model checking pipelines — bridging risk identification and threat detection with rigorous assurance methodology across formal methods, safety/security co-engineering, and critical infrastructure protection. Active in EU-funded research (Horizon Europe, KDT JU, Chips JU).
Previously, he served as Technology Scout for the Cybersecurity domain at AVL List GmbH (~11k employees), where he led research activities and project coordination for automotive cybersecurity across the business segment. Before that, he was a Key Researcher at JOANNEUM RESEARCH's Competence Group Cyber Security and Defence.
He holds a PhD in Computer Science from Mälardalen University ("Formal Methods-Based Security Testing Utilizing Threat Modeling, Automata Learning, and Model Checking", supervised by Marjan Sirjani and Mikael Sjödin and examined by a committee of leading European researchers, including Dave Sands (Chalmers), Mattias Nyberg (KTH), and Mahsa Varshosaz (IT University Copenhagen), with Prof. Mariëlle Stoelinga as opponent), a preceding licentiate (examined by Mohammad Reza Mousavi (King’s College London), Bengt Jonsson (Uppsala University), and Martin Törngren (KTH)), as well as a Master's with distinction in IT Technologies & Business Informatics ("Securing IPsec with Quantum Key Distribution"). He has published 40+ scientific papers and filed 5 patent applications (4 granted, 1 pending).
Having in total almost 25 years of ICT security experience, his certifications include Certified Ethical Hacker and ISO 27001 Information Security Manager. He is a member of ISO TC 22/SC 32/WG 11 (the working group responsible for ISO/SAE 21434), IEEE, ACM, and SAE, and serves as a scientific reviewer for journals and conferences. He is a Technical Expert Evaluator for the European Commission's Chips JU research programme, and lectured on computer networks at FH Campus02 University of Applied Sciences (2019–2024).
Main research focus:
- Cybersecurity Testing
- Test case generation
- Security standards
- Automotive systems
- Network protocols
- Applying formal methods to cybersecurity analysis
STAF: Leveraging LLMs for Automated Attack Tree-Based Security Test Generation (Nov 2025) Tanmay Khule , Stefan Marksteiner, Jose Alguindigue , Hannes Fuchs , Sebastian Fischmeister , Apurva Narayan 23rd ESCAR Europe 2025 (ESCAR EUROPE'25)
Formal Methods-Based Security Testing Utilizing Threat Modeling, Automata Learning, and Model Checking (Oct 2025) Stefan Marksteiner
Actors for Timing Analysis of Distributed Redundant Controllers (Sep 2025) Marjan Sirjani, Edward Lee, Zahra Moezkarimi, Bahman Pourvatan , Bjarne Johansson, Stefan Marksteiner, Alessandro Papadopoulos Gul Aga Festschrift (GulFest)
Learning single and compound-protocol automata and checking behavioral equivalences (Apr 2025) Stefan Marksteiner, David Schögler , Marjan Sirjani, Mikael Sjödin International Journal on Software Tools for Technology Transfer (STTT)
Black-box protocol testing using Rebeca and Automata Learning (Mar 2025) Stefan Marksteiner, Mikael Sjödin Marjan Festschrift (part of FSEN 2025) (MarjanFest)
AVATAR: Autonomous Vehicle Assessment through Testing of Adversarial Patches in Real-time (Aug 2024) Abhijith Sharma , Apurva Narayan , Nasser Lashgarian Azad , Sebastian Fischmeister , Stefan Marksteiner IEEE Transactions on Intelligent Vehicles (T-IV)