VLDB 2026 Research / reviewers in the wild / expert
Carmela Troncoso
dblp:01/4825
· DBLP profile ↗
80ranked-venue papers
6as first author
31since 2021 · last 2026
0000-0002-2374-2248ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 69 · 5 first-author · 26 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Computer networks · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Evaluating Concept Filtering Defenses against Child Sexual Abuse Material Generation by Text-to-Image ModelsabstractWe evaluate the effectiveness of filtering child images from training datasets of text-to-image models to prevent model misuse to create child sexual abuse material (CSAM). First, we capture the complexity of preventing CSAM generation using a game-based security definition. Second, we show that current detection methods cannot remove all children from a dataset. Third, using an ethical proxy for CSAM (a child wearing glasses), we show that even when only a small percentage of child images are left in the training dataset after filtering, there exist prompting strategies that generate a child wearing glasses using only a few more queries than when the model is trained on the unfiltered data. Fine-tuning the filtered model on child images further reduces the additional query overhead. We also show that re-introducing a concept is possible via fine-tuning even if filtering is perfect. Our results show that current child filtering methods offer limited protection to closed-weight models and no protection to open-weight models, while reducing the generality of the model by hindering the generation of child-related concepts or changing their representation. We conclude by outlining challenges in conducting evaluations that establish robust evidence on the impact of concept filtering defenses for CSAM. Ana-Maria Cretu 0002, Klim Kireev, Amro Abdalla, Wisdom Obinna, Raphael Meier, Sarah Adel Bargal, Elissa M. Redmiles, Carmela Troncoso |
SP | 8 |
| 2026 | Website fingerprinting on Nym: Attacks and DefensesabstractWebsite fingerprinting (WF) enables a passive eavesdropper to infer which web page a client is visiting, even when communications are encrypted or anonymized. In this paper, we study the vulnerability to website fingerprinting of Nym, a mix network based on the Loopix design that enables users to browse the Web. We show that although Nym adds delays and cover traffic to change packet patterns compared to Tor, it still leaks features that website fingerprinting attacks can exploit in both closed‑ and open‑world settings. We carry out an in-depth analysis of the effectiveness of Nym's obfuscation mechanisms, originally designed to provide anonymity in messaging, in thwarting website fingerprinting. We show that mix delays, counterintuitively, not only fail to protect against website fingerprinting but actually make the attack more effective as the mix delays make it easier to distinguish incoming from outgoing packets. We also demonstrate that the current cover traffic strategy of Nym is not effective in thwarting website fingerprinting attacks unless it imposes a large overhead. To address these limitations, we design two new WF defenses based on Nym's existing obfuscation mechanisms that significantly reduce WF effectiveness. The first defense introduces cover traffic to match the bursty nature of real-world web traffic, reducing the F1 score to 0.39 (compared to 0.65 obtained by similar defenses applied on Tor) at moderate overhead increase. The second defense plummets the F1 score to 0.06 by channeling web traffic via Nym's constant traffic capabilities, at the cost of bandwidth. Eric Jollès, Simon Wicky, Ania M. Piotrowska, Harry Halpin, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 5 |
| 2026 | Humanitarian Aid Distribution with Privacy-Preserving Assessment CapabilitiesabstractIn times of crisis, humanitarian organizations bring aid to those affected (e.g., water, food, medical supplies, cash assistance). Prior works introduced privacy-preserving systems for digitizing the aid distribution process, increasing their efficiency and security. These solutions, by design, do not allow humanitarian organizations to collect metrics about the aid distribution process. Such assessments (e.g., the proportion of aid distributed to a minority) are crucial to enable the organizations to improve their operations, to perform their duty of care, and to enable transparency and accountability towards recipients, donors, and the public in general. In partnership with the International Committee of the Red Cross, we identify assessments relevant to humanitarian aid deployments and these assessments' security and privacy requirements. We introduce a generic framework that augments existing privacy-preserving humanitarian aid distributions with such assessments. This framework enables the collection of aggregate statistics about the aid distribution process without compromising the privacy of recipients, and without requiring any changes to the existing protocols. To realize our framework we introduce one-time functional encryption (1FE), for which we propose efficient realizations from standard cryptographic primitives. We design and implement two variants of our framework: a more efficient one, secure against semi-honest adversaries; and a more robust one, secure against malicious adversaries. We also introduce the novel notions of threat model agility and graceful degradation. These notions enable us to model the unstable environment of humanitarian aid distribution, where the capabilities of the adversary may change suddenly (e.g., when a militia takes over a region in conflict), invalidating the threat model under which the system was originally deployed. We believe these notions are of independent interest for other privacy-preserving applications deployed in unstable environments. Christian Knabenhans, Lucy Qin, Justinas Sukaitis, Vincent Graf Narbel, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 5 |
| 2025 | Reimagining Wearable-Based Digital Contact Tracing: Insights from Kenya and Côte d'Ivoire
Kavous Salehzadeh Niksirat, Collins W. Munyendo, Onicio Batista Leal Neto, Muswagha Katya, Cyrille Kouassi, Kevin Ochieng, Angoa Georgina, Bernard Olayo, Jean-Philippe Barras, Ciro Cattuto, Adam J. Aviv, Carmela Troncoso |
CHI | 12 |
| 2025 | A Telegram Dataset of Propaganda and its ModerationabstractMessaging applications like Telegram have evolved into de facto social networking platforms as they add features like broadcast channels and large groups. Yet, research on these aspects of Telegram is sparse compared to more traditional social media platforms. In this paper, we present a dataset of Telegram messages collected using the export API that returns channel histories, complemented by messages collected in real-time. This dual collection methodology allows us to label deleted messages, i.e., messages that are present in the real-time dataset but not the historical dataset. Additionally, we provide labels indicating whether messages have been sent by accounts belonging to one of two distinct propaganda networks. We provide experiments that show how this rich dataset of Telegram messages can be used to study moderation in Telegram, stances and trends on different topics, and to shed light on malicious behaviours present on Telegram. Finally, we outline other use cases where our dataset could help the research community better understand Telegram as a social network. Klim Kireev, Yevhen Mykhno, Carmela Troncoso, Rebekah Overdorf |
ICWSM | 3 |
| 2025 | A Low-Cost Privacy-Preserving Digital Wallet for Humanitarian Aid DistributionabstractHumanitarian organizations distribute aid to people affected by armed conflicts or natural disasters. Digitalization has the potential to increase the efficiency and fairness of aid-distribution systems, and recent work by Wang et al. has shown that these benefits are possible without creating privacy harms for aid recipients. However, their work only provides a solution for one particular aid-distribution scenario in which aid recipients receive a predefined set of goods. Yet, in many situations it is desirable to enable recipients to decide which items they need at each moment to satisfy their specific needs. We formalize these needs into functional, deployment, security, and privacy requirements, and design a privacy-preserving digital wallet for aid distribution. Our smart-card-based solution enables aid recipients to spend a predefined budget at different vendors to obtain the items that they need. We prove our solution's security and privacy properties, and show it is practical at scale. Eva Luvison, Sylvain Chatel, Justinas Sukaitis, Vincent Graf Narbel, Carmela Troncoso, Wouter Lueks |
SP | 5 |
| 2025 | On the Conflict Between Robustness and Learning in Collaborative Machine LearningabstractCollaborative Machine Learning (CML) allows participants to jointly train a machine learning model while keeping their training data private. In many scenarios where CML is seen as the solution to privacy issues, such as health-related applications, safety is also a primary concern. To ensure that CML processes produce models that output correct and reliable decisions even in the presence of potentially untrusted participants, researchers propose to use robust aggregators to filter out malicious contributions that negatively influence the training process. In this paper, we prove that the two prevalent forms of robust aggregators in the literature cannot eliminate the risk of compromise without preventing learning: in order to learn from collaboration, participants must always accept the risk of being the subject of harmful adversarial manipulation. Therefore, these robust aggregators are unsuitable for high-stake applications such as health-related or autonomous driving in which errors can result in physical harm. We empirically demonstrate the correctness of our theoretical findings on a selection of existing robust aggregators and relevant applications, including end-to-end results where we show that using existing robust aggregators can lead to an adversary can cause incorrect medical diagnosis or can cause self-driving cars to miss turns. Mathilde Raynal, Carmela Troncoso |
SP | 2 |
| 2025 | Double-Edged Shield: On the Fingerprintability of Customized Ad Blockers
Saiid El Hajj Chehade, Ben Stock, Carmela Troncoso |
USENIX Security Symposium | 3 |
| 2025 | Characterizing and Detecting Propaganda-Spreading Accounts on Telegram
Klim Kireev, Yevhen Mykhno, Carmela Troncoso, Rebekah Overdorf |
USENIX Security Symposium | 3 |
| 2024 | VERITAS: Plaintext Encoders for Practical Verifiable Homomorphic EncryptionabstractHomomorphic encryption has become a practical solution for protecting the privacy of computations on sensitive data. However, existing homomorphic encryption pipelines do not guarantee the correctness of the computation result in the presence of a malicious adversary. We propose two plaintext encodings compatible with state-of-the-art fully homomorphic encryption schemes that enable practical client-verification of homomorphic computations while supporting all the operations required for modern privacy-preserving analytics. Based on these encodings, we introduce VERITAS, a ready-to-use library for the verification of computations executed over encrypted data. VERITAS is the first library that supports the verification of any homomorphic operation. We demonstrate its practicality for various applications and, in particular, we show that it enables verifiability of homomorphic analytics with less than 3x computation overhead compared to the homomorphic encryption baseline. Sylvain Chatel, Christian Knabenhans, Apostolos Pyrgelis, Carmela Troncoso, Jean-Pierre Hubaux |
CCS | 4 |
| 2024 | Helium: Scalable MPC among Lightweight Participants and under Churn
Christian Mouchet, Sylvain Chatel, Apostolos Pyrgelis, Carmela Troncoso |
CCS | 4 |
| 2024 | The Fundamental Limits of Least-Privilege LearningabstractThe promise of least-privilege learning – to find feature representations that are useful for a learning task but prevent inference of any sensitive information unrelated to this task – is highly appealing. However, so far this concept has only been stated informally. It thus remains an open question whether and how we can achieve this goal. In this work, we provide the first formalisation of the least-privilege principle for machine learning and characterise its feasibility. We prove that there is a fundamental trade-off between a representation’s utility for a given task and its leakage beyond the intended task: it is not possible to learn representations that have high utility for the intended task but, at the same time, prevent inference of any attribute other than the task label itself. This trade-off holds regardless of the technique used to learn the feature mappings that produce these representations. We empirically validate this result for a wide range of learning techniques, model architectures, and datasets. Theresa Stadler, Bogdan Kulynych, Michael Gastpar, Nicolas Papernot, Carmela Troncoso |
ICML | 5 |
| 2024 | Attack-Aware Noise Calibration for Differential PrivacyabstractDifferential privacy (DP) is a widely used approach for mitigating privacy risks when training machine learning models on sensitive data. DP mechanisms add noise during training to limit the risk of information leakage. The scale of the added noise is critical, as it determines the trade-off between privacy and utility. The standard practice is to select the noise scale to satisfy a given privacy budget ε. This privacy budget is in turn interpreted in terms of operational attack risks, such as accuracy, sensitivity, and specificity of inference attacks aimed to recover
information about the training data records. We show that first calibrating the noise scale to a privacy budget ε, and then translating ε to attack risk leads to overly conservative risk assessments and unnecessarily low utility. Instead, we propose methods to directly calibrate the noise scale to a desired attack risk level, bypassing the step of choosing ε. For a given notion of attack risk, our approach significantly
decreases noise scale, leading to increased utility at the same level of privacy. We empirically demonstrate that calibrating noise to attack sensitivity/specificity, rather than ε, when training privacy-preserving ML models substantially improves model accuracy for the same risk level. Our work provides a principled and practical way to improve the utility of privacy-preserving ML without compromising on privacy. Bogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Flávio P. Calmon, Carmela Troncoso |
NeurIPS | 5 |
| 2024 | SINBAD: Saliency-informed detection of breakage caused by ad blockingabstractPrivacy-enhancing blocking tools based on filter-list rules tend to break legitimate functionality. Filter-list maintainers could benefit from automated breakage detection tools that allow them to proactively fix problematic rules before deploying them to millions of users. We introduce SINBAD, an automated breakage detector that improves the accuracy over the state of the art by 20%, and is the first to detect dynamic breakage and breakage caused by style-oriented filter rules. The success of SINBAD is rooted in three innovations: (1) the use of user-reported breakage issues in forums that enable the creation of a high-quality dataset for training in which only breakage that users perceive as an issue is included; (2) the use of ‘web saliency’ to automatically identify user-relevant regions of a website on which to prioritize automated interactions aimed at triggering breakage; and (3) the analysis of webpages via subtrees which enables fine-grained identification of problematic filter rules. Saiid El Hajj Chehade, Sandra Deepthy Siby, Carmela Troncoso |
SP | 3 |
| 2024 | Janus: Safe Biometric Deduplication for Humanitarian Aid DistributionabstractHumanitarian organizations provide aid to people in need. To use their limited budget efficiently, their distribution processes must ensure that legitimate recipients cannot receive more aid than they are entitled to. Thus, it is essential that recipients can register at most once per aid program.Taking the International Committee of the Red Cross’s aid distribution registration process as a use case, we identify the requirements to detect double registration without creating new risks for aid recipients. We then design Janus, which combines privacy-enhancing technologies with biometrics to prevent double registration in a safe manner. Janus does not create plaintext biometric databases and reveals only one bit of information at registration time (whether the user registering is present in the database or not). We implement and evaluate three instantiations of Janus based on secure multiparty computation (SMC) alone, a hybrid of somewhat homomorphic encryption and SMC, and trusted execution environments. We demonstrate that they support the privacy, accuracy, and performance needs of humanitarian organizations. We compare Janus with existing alternatives and show it is the first system that provides the accuracy our scenario requires while providing strong protection. Kasra Edalatnejad, Wouter Lueks, Justinas Sukaitis, Vincent Graf Narbel, Massimo Marelli, Carmela Troncoso |
SP | 6 |
| 2024 | Universal Neural-Cracking-Machines: Self-Configurable Password Models from Auxiliary DataabstractWe introduce the concept of "universal" password model—a password model that, once pre-trained, can automatically adapt its guessing strategy based on the target system. To achieve this, the model does not need to access any plaintext passwords from the target credentials. Instead, it exploits users’ auxiliary information, such as email addresses, as a proxy signal to predict the underlying password distribution.Specifically, the model uses deep learning to capture the correlation between the auxiliary data of a group of users (e.g., users of a web application) and their passwords. It then exploits those patterns to create a tailored password model for the target system at inference time. No further training steps, targeted data collection, or prior knowledge of the community’s password distribution is required.Besides improving over current password strength estimation techniques, the model enables any end-user (e.g., system administrators) to autonomously generate tailored password models for their systems without the often unworkable requirements of collecting suitable training data and fitting the underlying machine learning model. Ultimately, our framework enables the democratization of well-calibrated password models to the community, addressing a major challenge in the deployment of password security solutions at scale. Dario Pasquini, Giuseppe Ateniese, Carmela Troncoso |
SP | 3 |
| 2023 | Poster: Verifiable Encodings for Maliciously-Secure Homomorphic Encryption EvaluationabstractHomomorphic encryption has become a promising solution for protecting the privacy of computations on sensitive data. However, existing homomorphic encryption pipelines do not guarantee the correctness of the computation result in the presence of a malicious adversary. In this poster, we present two encodings compatible with state-of-the-art fully homomorphic encryption schemes that enable practical client-verification of homomorphic computations, while enabling all the operations required for modern privacy-preserving analytics. Based on these encodings, we introduce a ready-to-use library for the verification of any homomorphic operation executed over encrypted data. We demonstrate its practicality for various applications and, in particular, we show that it enables verifiability of some homomorphic analytics with less than 3 times overhead compared to the homomorphic encryption baseline. Sylvain Chatel, Christian Knabenhans, Apostolos Pyrgelis, Carmela Troncoso, Jean-Pierre Hubaux |
CCS | 4 |
| 2023 | PELTA - Shielding Multiparty-FHE against Malicious AdversariesabstractMultiparty fully homomorphic encryption (MFHE) schemes enable multiple parties to efficiently compute functions on their sensitive data while retaining confidentiality. However, existing MFHE schemes guarantee data confidentiality and the correctness of the computation result only against honest-but-curious adversaries. In this work, we provide the first practical construction that enables the verification of MFHE operations in zero-knowledge, protecting MFHE from malicious adversaries. Our solution relies on a combination of lattice-based commitment schemes and proof systems which we adapt to support both modern FHE schemes and their implementation optimizations. We implement our construction in PELTA. Our experimental evaluation shows that PELTA is one to two orders of magnitude faster than existing techniques in the literature. Sylvain Chatel, Christian Mouchet, Ali Utkan Sahin, Apostolos Pyrgelis, Carmela Troncoso, Jean-Pierre Hubaux |
CCS | 5 |
| 2023 | CookieGraph: Understanding and Detecting First-Party Tracking CookiesabstractAs third-party cookie blocking is becoming the norm in mainstream web browsers, advertisers and trackers have started to use first-party cookies for tracking. To understand this phenomenon, we conduct a differential measurement study with versus without third-party cookies. We find that first-party cookies are used to store and exfiltrate identifiers to known trackers even when third-party cookies are blocked. Shaoor Munir, Sandra Deepthy Siby, Umar Iqbal 0002, Steven Englehardt, Zubair Shafiq, Carmela Troncoso |
CCS | 6 |
| 2023 | Bayes Security: A Not So Average MetricabstractSecurity system designers favor worst-case security metrics, such as those derived from differential privacy (DP), due to the strong guarantees they provide. On the downside, these guarantees result in a high penalty on the system's performance. In this paper, we study Bayes security, a security metric inspired by the cryptographic advantage. Similarly to DP, Bayes security i) is independent of an adversary's prior knowledge, ii) it captures the worst-case scenario for the two most vulnerable secrets (e.g., data records); and iii) it is easy to compose, facilitating security analyses. Additionally, Bayes security iv) can be consistently estimated in a black-box manner, contrary to DP, which is useful when a formal analysis is not feasible; and v) provides a better utility-security trade-off in high-security regimes because it quantifies the risk for a specific threat model as opposed to threat-agnostic metrics such as DP. We formulate a theory around Bayes security, and we provide a thorough comparison with respect to well-known metrics, identifying the scenarios where Bayes Security is advantageous for designers. Konstantinos Chatzikokolakis 0001, Giovanni Cherubin, Catuscia Palamidessi, Carmela Troncoso |
CSF | 4 |
| 2023 | Adversarial Robustness for Tabular Data through Cost and Utility Awareness
Klim Kireev, Bogdan Kulynych, Carmela Troncoso |
NDSS | 3 |
| 2023 | Transferable Adversarial Robustness for Categorical Data via Universal Robust EmbeddingsabstractResearch on adversarial robustness is primarily focused on image and text data. Yet, many scenarios in which lack of robustness can result in serious risks, such as fraud detection, medical diagnosis, or recommender systems often do not rely on images or text but instead on tabular data. Adversarial robustness in tabular data poses two serious challenges. First, tabular datasets often contain categorical features, and therefore cannot be tackled directly with existing optimization procedures. Second, in the tabular domain, algorithms that are not based on deep networks are widely used and offer great performance, but algorithms to enhance robustness are tailored to neural networks (e.g. adversarial training).
In this paper, we tackle both challenges. We present a method that allows us to train adversarially robust deep networks for tabular data and to transfer this robustness to other classifiers via universal robust embeddings tailored to categorical data. These embeddings, created using a bilevel alternating minimization framework, can be transferred to boosted trees or random forests making them robust without the need for adversarial training while preserving their high accuracy on tabular data. We show that our methods outperform existing techniques within a practical threat model suitable for tabular data. Klim Kireev, Maksym Andriushchenko, Carmela Troncoso, Nicolas Flammarion |
NeurIPS | 3 |
| 2023 | On the (In)security of Peer-to-Peer Decentralized Machine LearningabstractIn this work, we carry out the first, in-depth, privacy analysis of Decentralized Learning—a collaborative machine learning framework aimed at addressing the main limitations of federated learning. We introduce a suite of novel attacks for both passive and active decentralized adversaries. We demonstrate that, contrary to what is claimed by decentralized learning proposers, decentralized learning does not offer any security advantage over federated learning. Rather, it increases the attack surface enabling any user in the system to perform privacy attacks such as gradient inversion, and even gain full control over honest users’ local model. We also show that, given the state of the art in protections, privacy-preserving configurations of decentralized learning require fully connected networks, losing any practical advantage over the federated setup and therefore completely defeating the objective of the decentralized approach. Dario Pasquini, Mathilde Raynal, Carmela Troncoso |
SP | 3 |
| 2023 | Not Yet Another Digital ID: Privacy-Preserving Humanitarian Aid DistributionabstractHumanitarian aid-distribution programs help bring physical goods to people in need. Traditional paper-based solutions to support aid distribution do not scale to large populations and are hard to secure. Existing digital solutions solve these issues, at the cost of collecting large amount of personal information. This lack of privacy can endanger recipients’ safety and harm their dignity. In collaboration with the International Committee of the Red Cross, we build a safe digital aid-distribution system. We first systematize the requirements such a system should satisfy. We then propose a decentralized solution based on the use of tokens that fulfills the needs of humanitarian organizations. It provides scalability and strong accountability, and, by design, guarantees the recipients’ privacy. We provide two instantiations of our design, on a smart card and on a smartphone. We formally prove the security and privacy properties of these solutions, and empirically show that they can operate at scale. Boya Wang, Wouter Lueks, Justinas Sukaitis, Vincent Graf Narbel, Carmela Troncoso |
SP | 5 |
| 2023 | Private Collection Matching ProtocolsabstractWe introduce Private Collection Matching (PCM) problems, in which a client aims to determine whether a collection of sets owned by a server matches their interests. Existing privacy-preserving cryptographic primitives cannot solve PCM problems efficiently without harming privacy. We propose a modular framework that enables designers to build privacy-preserving PCM systems that output one bit: whether a collection of server sets matches the client's set. The communication cost of our protocols scales linearly with the size of the client's set and is independent of the number of server elements. We demonstrate the potential of our framework by designing and implementing novel solutions for two real-world PCM problems: determining whether a dataset has chemical compounds of interest, and determining whether a document collection has relevant documents. Our evaluation shows that we offer a privacy gain with respect to existing works at a reasonable communication and computation cost. Kasra Edalatnejad, Mathilde Raynal, Wouter Lueks, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | Evaluating practical QUIC website fingerprinting defenses for the massesabstractWebsite fingerprinting (WF) is a well-known threat to users' web privacy. New Internet standards, such as QUIC, include padding to support defenses against WF. Previous work on QUIC WF only analyzes the effectiveness of defenses when users are behind a VPN. Yet, this is not how most users browse the Internet. In this paper, we provide a comprehensive evaluation of QUIC-padding-based defenses against WF when users directly browse the web, i.e., without VPNs, HTTPS proxies, or other tunneling protocols. We confirm previous claims that network-layer padding cannot provide effective protection against powerful adversaries capable of observing all traffic traces. We show that the claims hold even against adversaries with constraints on traffic visibility and processing power. We then show that the current approach to web development, in which the use of third-party resources is the norm, impedes the effective use of padding-based defenses as it requires first and third parties to coordinate in order to thwart traffic analysis. We show that even when coordination is possible, in most cases, protection comes at a high cost. Sandra Deepthy Siby, Ludovic Barman, Christopher A. Wood, Marwan Fayed, Nick Sullivan, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 6 |
| 2022 | Online Website Fingerprinting: Evaluating Website Fingerprinting Attacks on Tor in the Real World
Giovanni Cherubin, Rob Jansen, Carmela Troncoso |
USENIX Security Symposium | 3 |
| 2022 | WebGraph: Capturing Advertising and Tracking Information Flows for Robust Blocking
Sandra Deepthy Siby, Umar Iqbal 0002, Steven Englehardt, Zubair Shafiq, Carmela Troncoso |
USENIX Security Symposium | 5 |
| 2022 | Synthetic Data - Anonymisation Groundhog Day
Theresa Stadler, Bristena Oprisanu, Carmela Troncoso |
USENIX Security Symposium | 3 |
| 2022 | Disparate Vulnerability to Membership Inference AttacksabstractAbstract A membership inference attack (MIA) against a machine-learning model enables an attacker to determine whether a given data record was part of the model’s training data or not. In this paper, we provide an in-depth study of the phenomenon of disparate vulnerability against MIAs: unequal success rate of MIAs against different population subgroups. We first establish necessary and sufficient conditions for MIAs to be prevented, both on average and for population subgroups, using a notion of distributional generalization. Second, we derive connections of disparate vulnerability to algorithmic fairness and to differential privacy. We show that fairness can only prevent disparate vulnerability against limited classes of adversaries. Differential privacy bounds disparate vulnerability but can significantly reduce the accuracy of the model. We show that estimating disparate vulnerability by naïvely applying existing attacks can lead to overestimation. We then establish which attacks are suitable for estimating disparate vulnerability, and provide a statistical framework for doing so reliably. We conduct experiments on synthetic and real-world data finding significant evidence of disparate vulnerability in realistic settings. Bogdan Kulynych, Mohammad Yaghini, Giovanni Cherubin, Michael Veale, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | CrowdNotifier: Decentralized Privacy-Preserving Presence TracingabstractAbstract There is growing evidence that SARS-CoV-2 can be transmitted beyond close proximity contacts, in particular in closed and crowded environments with insufficient ventilation. To help mitigation efforts, contact tracers need a way to notify those who were present in such environments at the same time as infected individuals. Neither traditional human-based contact tracing powered by handwritten or electronic lists, nor Bluetooth-enabled proximity tracing can handle this problem efficiently. In this paper, we propose CrowdNotifier, a protocol that can complement manual contact tracing by efficiently notifying visitors of venues and events with SARS-CoV-2-positive attendees. We prove that CrowdNotifier provides strong privacy and abuse-resistance, and show that it can scale to handle notification at a national scale. Wouter Lueks, Seda Gurses, Michael Veale, Edouard Bugnion, Marcel Salathé, Kenneth G. Paterson, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 7 |
| 2020 | GenoShare: Supporting Privacy-Informed Decisions for Sharing Individual-Level Genetic Data
Jean Louis Raisaro, Juan Ramón Troncoso-Pastoriza, Yamane El-Zein, Mathias Humbert, Jacques Fellay, Carmela Troncoso, Jean-Pierre Hubaux |
AMIA | 6 |
| 2020 | Encrypted DNS -> Privacy? A Traffic Analysis Perspective
Sandra Deepthy Siby, Marc Juarez, Claudia Díaz, Narseo Vallina-Rodriguez, Carmela Troncoso |
NDSS | 5 |
| 2020 | DatashareNetwork: A Decentralized Privacy-Preserving Search Engine for Investigative Journalists
Kasra Edalatnejad, Wouter Lueks, Julien Pierre Martin, Soline Ledésert, Anne L'Hôte, Bruno Thomas, Laurent Girod, Carmela Troncoso |
USENIX Security Symposium | 8 |
| 2020 | VoteAgain: A scalable coercion-resistant voting system
Wouter Lueks, Iñigo Querejeta-Azurmendi, Carmela Troncoso |
USENIX Security Symposium | 3 |
| 2020 | Angel or Devil? A Privacy Study of Mobile Parental Control AppsabstractAbstract Android parental control applications are used by parents to monitor and limit their children’s mobile behaviour (e.g., mobile apps usage, web browsing, calling, and texting). In order to offer this service, parental control apps require privileged access to system resources and access to sensitive data. This may significantly reduce the dangers associated with kids’ online activities, but it raises important privacy concerns. These concerns have so far been overlooked by organizations providing recommendations regarding the use of parental control applications to the public. We conduct the first in-depth study of the Android parental control app’s ecosystem from a privacy and regulatory point of view. We exhaustively study 46 apps from 43 developers which have a combined 20M installs in the Google Play Store. Using a combination of static and dynamic analysis we find that: these apps are on average more permissions-hungry than the top 150 apps in the Google Play Store, and tend to request more dangerous permissions with new releases; 11% of the apps transmit personal data in the clear; 34% of the apps gather and send personal information without appropriate consent; and 72% of the apps share data with third parties (including online advertising and analytics services) without mentioning their presence in their privacy policies. In summary, parental control applications lack transparency and lack compliance with regulatory requirements. This holds even for those applications recommended by European and other national security centers. Álvaro Feal, Paolo Calciati, Narseo Vallina-Rodriguez, Carmela Troncoso, Alessandra Gorla |
Proc. Priv. Enhancing Technol. | 4 |
| 2020 | Tandem: Securing Keys by Using a Central Server While Preserving Privacy
Wouter Lueks, Brinda Hampiholi, Greg Alpár, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 4 |
| 2019 | PPML '19: Privacy Preserving Machine LearningabstractThe area of privacy preserving machine learning has been of growing importance in practice, which has lead to an increased interest in this topic in both academia and industry. We have witnessed this through numerous papers and systems published and developed in the recent years to address challenges in this area. The solutions proposed in this space leverage many different approaches and techniques coming from machine learning, cryptography, and security. Thus, the workshop aims to be a forum to unify different perspectives and start a discussion about the relative merits of each approach. It will also serve as a venue for networking people from different communities interested in this problem, and hopefully foster fruitful long-term collaboration. Borja Balle, Adrià Gascón, Olga Ohrimenko, Mariana Raykova 0001, Phillipp Schoppmann, Carmela Troncoso |
CCS | 6 |
| 2019 | Rethinking Location Privacy for Unknown Mobility BehaviorsabstractLocation Privacy-Preserving Mechanisms (LPPMs) in the literature largely consider that users' data available for training wholly characterizes their mobility patterns. Thus, they hardwire this information in their designs and evaluate their privacy properties with these same data. In this paper, we aim to understand the impact of this decision on the level of privacy these LPPMs may offer in real life when the users' mobility data may be different from the data used in the design phase. Our results show that, in many cases, training data does not capture users' behavior accurately and, thus, the level of privacy provided by the LPPM is often overestimated. To address this gap between theory and practice, we propose to use blank-slate models for LPPM design. Contrary to the hardwired approach, that assumes known users' behavior, blank-slate models learn the users' behavior from the queries to the service provider. We leverage this blank-slate approach to develop a new family of LPPMs, that we call Profile Estimation-Based LPPMs. Using real data, we empirically show that our proposal outperforms optimal state-of-the-art mechanisms designed on sporadic hardwired models. On non-sporadic location privacy scenarios, our method is only better if the usage of the location privacy service is not continuous. It is our hope that eliminating the need to bootstrap the mechanisms with training data and ensuring that the mechanisms are lightweight and easy to compute help fostering the integration of location privacy protections in deployed systems. Simon Oya, Carmela Troncoso, Fernando Pérez-González |
EuroS&P | 2 |
| 2019 | On (The Lack Of) Location Privacy in Crowdsourcing Applications
Spyros Boukoros, Mathias Humbert, Stefan Katzenbeisser 0001, Carmela Troncoso |
USENIX Security Symposium | 4 |
| 2019 | Editors' Introduction
Konstantinos Chatzikokolakis 0001, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | Editors' Introduction
Konstantinos Chatzikokolakis 0001, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | Editors' Introduction
Konstantinos Chatzikokolakis 0001, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | Editors' Introduction
Konstantinos Chatzikokolakis 0001, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | TARANET: Traffic-Analysis Resistant Anonymity at the Network LayerabstractModern low-latency anonymity systems, no matter whether constructed as an overlay or implemented at the network layer, offer limited security guarantees against traffic analysis. On the other hand, high-latency anonymity systems offer strong security guarantees at the cost of computational overhead and long delays, which are excessive for interactive applications. We propose TARANET, an anonymity system that implements protection against traffic analysis at the network layer, and limits the incurred latency and overhead. In TARANET's setup phase, traffic analysis is thwarted by mixing. In the data transmission phase, end hosts and ASes coordinate to shape traffic into constant-rate transmission using packet splitting. Our prototype implementation shows that TARANET can forward anonymous traffic at over 50 Gbps using commodity hardware. Chen Chen 0013, Daniele Enrico Asoni, Adrian Perrig, David Barrera 0003, George Danezis, Carmela Troncoso |
EuroS&P | 6 |
| 2018 | Knock Knock, Who's There? Membership Inference on Aggregate Location Data
Apostolos Pyrgelis, Carmela Troncoso, Emiliano De Cristofaro |
NDSS | 2 |
| 2018 | Editors' Introduction
Rachel Greenstadt, Damon McCoy, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 3 |
| 2018 | Editors' Introduction
Rachel Greenstadt, Damon McCoy, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 3 |
| 2018 | Editors' Introduction
Rachel Greenstadt, Damon McCoy, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 3 |
| 2018 | Editors' Introduction
Rachel Greenstadt, Damon McCoy, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 3 |
| 2017 | Back to the Drawing Board: Revisiting the Design of Optimal Location Privacy-preserving MechanismsabstractIn the last years we have witnessed the appearance of a variety of strategies to design optimal location privacy-preserving mechanisms, in terms of maximizing the adversary's expected error with respect to the users' whereabouts. In this work, we take a closer look at the defenses created by these strategies and show that, even though they are indeed optimal in terms of adversary's correctness, not all of them offer the same protection when looking at other dimensions of privacy. To avoid "bad" choices, we argue that the search for optimal mechanisms must be guided by complementary criteria. We provide two example auxiliary metrics that help in this regard: the conditional entropy, that captures an information-theoretic aspect of the problem; and the worst-case quality loss, that ensures that the output of the mechanism always provides a minimum utility to the users. We describe a new mechanism that maximizes the conditional entropy and is optimal in terms of average adversary error, and compare its performance with previously proposed optimal mechanisms using two real datasets. Our empirical results confirm that no mechanism fares well on every privacy criteria simultaneously, making apparent the need for considering multiple privacy dimensions to have a good understanding of the privacy protection a mechanism provides. Simon Oya, Carmela Troncoso, Fernando Pérez-González |
CCS | 2 |
| 2017 | Filter design for delay-based anonymous communicationsabstractIn this work, we address the problem of designing delay-based anonymous communication systems. We consider a timed mix where an eavesdropper wants to learn the communication pattern of the users, and study how the mix must delay the messages so as to increase the adversary's estimation error. We show the connection between this problem and a MIMO system where we want to design the coloring filter that worsens the adversary's estimation of the MIMO channel matrix. We obtain theoretical solutions for the optimal filter against short-term and long-term adversaries, evaluate them with experiments, and show how some properties of filters can be used in the implementation of timed mixes. This opens the door to the application of previously known filter design techniques to anonymous communication systems. Simon Oya, Fernando Pérez-González, Carmela Troncoso |
ICASSP | 3 |
| 2017 | Small DataabstractData is becoming increasingly personal. Individuals regularly interact with a wide variety of structured data, from SQLite databases on phones, to HR spreadsheets, to personal sensors, to open government data appearing in news articles. Although these workloads are important, many of the classical challenges associated with scale and Big Data do not apply. This panel brings together experts in a variety of fields to explore the new opportunities and challenges presented by "Small Data". Oliver Kennedy, D. Richard Hipp, Stratos Idreos, Amélie Marian, Arnab Nandi 0001, Carmela Troncoso, Eugene Wu 0002 |
ICDE | 6 |
| 2017 | Dissecting Tor Bridges: A Security Evaluation of their Private and Public Infrastructures
Srdjan Matic, Carmela Troncoso, Juan Caballero |
NDSS | 2 |
| 2017 | What Does The Crowd Say About You? Evaluating Aggregation-based Location PrivacyabstractAbstract Information about people’s movements and the locations they visit enables an increasing number of mobility analytics applications, e.g., in the context of urban and transportation planning, In this setting, rather than collecting or sharing raw data, entities often use aggregation as a privacy protection mechanism, aiming to hide individual users’ location traces. Furthermore, to bound information leakage from the aggregates, they can perturb the input of the aggregation or its output to ensure that these are differentially private. In this paper, we set to evaluate the impact of releasing aggregate location time-series on the privacy of individuals contributing to the aggregation. We introduce a framework allowing us to reason about privacy against an adversary attempting to predict users’ locations or recover their mobility patterns. We formalize these attacks as inference problems, and discuss a few strategies to model the adversary’s prior knowledge based on the information she may have access to. We then use the framework to quantify the privacy loss stemming from aggregate location data, with and without the protection of differential privacy, using two real-world mobility datasets. We find that aggregates do leak information about individuals’ punctual locations and mobility profiles. The density of the observations, as well as timing, play important roles, e.g., regular patterns during peak hours are better protected than sporadic movements. Finally, our evaluation shows that both output and input perturbation offer little additional protection, unless they introduce large amounts of noise ultimately destroying the utility of the data. Apostolos Pyrgelis, Carmela Troncoso, Emiliano De Cristofaro |
Proc. Priv. Enhancing Technol. | 2 |
| 2017 | Systematizing Decentralization and Privacy: Lessons from 15 Years of Research and DeploymentsabstractDecentralized systems are a subset of distributed systems where multiple authorities control different components and no authority is fully trusted by all. This implies that any component in a decentralized system is potentially adversarial. We revise fifteen years of research on decentralization and privacy, and provide an overview of key systems, as well as key insights for designers of future systems. We show that decentralized designs can enhance privacy, integrity, and availability but also require careful trade-offs in terms of system complexity, properties provided, and degree of decentralization. These trade-offs need to be understood and navigated by designers. We argue that a combination of insights from cryptography, distributed systems, and mechanism design, aligned with the development of adequate incentives, are necessary to build scalable and successful privacy-preserving decentralized systems. Carmela Troncoso, Marios Isaakidis, George Danezis, Harry Halpin |
Proc. Priv. Enhancing Technol. | 1 |
| 2017 | Privacy Games Along Location Traces: A Game-Theoretic Framework for Optimizing Location PrivacyabstractThe mainstream approach to protecting the privacy of mobile users in location-based services (LBSs) is to alter (e.g., perturb, hide, and so on) the users’ actual locations in order to reduce exposed sensitive information. In order to be effective, a location-privacy preserving mechanism must consider both the privacy and utility requirements of each user, as well as the user’s overall exposed locations (which contribute to the adversary’s background knowledge). In this article, we propose a methodology that enables the design of optimal user-centric location obfuscation mechanisms respecting each individual user’s service quality requirements, while maximizing the expected error that the optimal adversary incurs in reconstructing the user’s actual trace. A key advantage of a user-centric mechanism is that it does not depend on third-party proxies or anonymizers; thus, it can be directly integrated in the mobile devices that users employ to access LBSs. Our methodology is based on the mutual optimization of user/adversary objectives (maximizing location privacy versus minimizing localization error) formalized as a Stackelberg Bayesian game. This formalization makes our solution robust against any location inference attack, that is, the adversary cannot decrease the user’s privacy by designing a better inference algorithm as long as the obfuscation mechanism is designed according to our privacy games. We develop two linear programs that solve the location privacy game and output the optimal obfuscation strategy and its corresponding optimal inference attack. These linear programs are used to design location privacy--preserving mechanisms that consider the correlation between past, current, and future locations of the user, thus can be tuned to protect different privacy objectives along the user’s location trace. We illustrate the efficacy of the optimal location privacy--preserving mechanisms obtained with our approach against real location traces, showing their performance in protecting users’ different location privacy objectives. Reza Shokri, George Theodorakopoulos 0001, Carmela Troncoso |
ACM Trans. Priv. Secur. | 3 |
| 2016 | Design of Pool Mixes Against Profiling Attacks in Real ConditionsabstractCurrent implementations of high-latency anonymous communication systems are based on pool mixes. These tools act as routers that apply a random delay to the messages traversing them, making it hard for an eavesdropper to guess the correspondences between incoming and outgoing messages. This hides the identities of communicating partners in the network, but it does not prevent an adversary continuously monitoring the network from unveiling the communication profiles of the users. In this paper, we tackle the problem of designing the delay characteristic of pool mixes so as to maximize the protection of the users against profiling attacks. First, we propose a theoretical model for users' sending behavior which we validate using three real data sets of a different nature. Then, we use this model to perform a privacy analysis of the system and obtain the delay function of the mix, which is optimal in the sense of protecting the users. Since computing the delay characteristic of this optimal pool mix requires information about the users' behavior, we also propose a user-independent but less effective mix design. We evaluate these pool mixes, comparing them with one of the most studied existing designs, the binomial pool mix. Our experiments show that an adversary against our optimal design may need up to 30 times as long to achieve the same level of disclosure as for a binomial pool mix. Simon Oya, Fernando Pérez-González, Carmela Troncoso |
IEEE/ACM Trans. Netw. | 3 |
| 2014 | Do Dummies Pay Off? Limits of Dummy Traffic Protection in Anonymous Communications
Simon Oya, Carmela Troncoso, Fernando Pérez-González |
Privacy Enhancing Technologies | 2 |
| 2014 | A Least Squares Approach to the Static Traffic Analysis of High-Latency Anonymous Communication SystemsabstractMixes, relaying routers that hide the relation between incoming and outgoing messages, are the main building block of high-latency anonymous communication networks. A number of so-called disclosure attacks have been proposed to effectively deanonymize traffic sent through these channels. Yet, the dependence of their success on the system parameters is not well-understood. We propose the least squares disclosure attack (LSDA), in which user profiles are estimated by solving a least squares problem. We show that LSDA is not only suitable for the analysis of threshold mixes, but can be easily extended to attack pool mixes. Furthermore, contrary to previous heuristic-based attacks, our approach allows us to analytically derive expressions that characterize the profiling error of LSDA with respect to the system parameters. We empirically demonstrate that LSDA recovers users' profiles with greater accuracy than its statistical predecessors and verify that our analysis closely predicts actual performance. Fernando Pérez-González, Carmela Troncoso, Simon Oya |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Bayesian inference to evaluate information leakage in complex scenariosabstractCommon security evaluation methods require the estimation of the likelihood of a hidden state given an observation of the system. For instance: identifying the type of tampering on an image given the tampered file, identifying communication partner given an anonymous channel trace, identifying the location from where a service has been accessed given an obfuscated version of this location. In this talk we explore the suitability of Bayesian Inference techniques, specifically Markov Chain Monte Carlo methods, to evaluate information leakage in complex scenarios. Carmela Troncoso |
IH&MMSec | 1 |
| 2012 | Protecting location privacy: optimal strategy against localization attacksabstractThe mainstream approach to protecting the location-privacy of mobile users in location-based services (LBSs) is to alter the users' actual locations in order to reduce the location information exposed to the service provider. The location obfuscation algorithm behind an effective location-privacy preserving mechanism (LPPM) must consider three fundamental elements: the privacy requirements of the users, the adversary's knowledge and capabilities, and the maximal tolerated service quality degradation stemming from the obfuscation of true locations. We propose the first methodology, to the best of our knowledge, that enables a designer to find the optimal LPPM for a LBS given each user's service quality constraints against an adversary implementing the optimal inference algorithm. Such LPPM is the one that maximizes the expected distortion (error) that the optimal adversary incurs in reconstructing the actual location of a user, while fulfilling the user's service-quality requirement. We formalize the mutual optimization of user-adversary objectives (location privacy vs. correctness of localization) by using the framework of Stackelberg Bayesian games. In such setting, we develop two linear programs that output the best LPPM strategy and its corresponding optimal inference attack. Our optimal user-centric LPPM can be easily integrated in the users' mobile devices they use to access LBSs. We validate the efficacy of our game theoretic method against real location traces. Our evaluation confirms that the optimal LPPM strategy is superior to a straightforward obfuscation method, and that the optimal localization attack performs better compared to a Bayesian inference attack. Reza Shokri, George Theodorakopoulos 0001, Carmela Troncoso, Jean-Pierre Hubaux, Jean-Yves Le Boudec |
CCS | 3 |
| 2012 | Understanding Statistical Disclosure: A Least Squares Approach
Fernando Pérez-González, Carmela Troncoso |
Privacy Enhancing Technologies | 2 |
| 2012 | OB-PWS: Obfuscation-Based Private Web SearchabstractObfuscation-based private web search (OB-PWS) solutions allow users to search for information in the Internet while concealing their interests. The basic privacy mechanism in OB-PWS is the automatic generation of dummy queries that are sent to the search engine along with users' real requests. These dummy queries prevent the accurate inference of search profiles and provide query deniability. In this paper we propose an abstract model and an associated analysis framework to systematically evaluate the privacy protection offered by OB-PWS systems. We analyze six existing OB-PWS solutions using our framework and uncover vulnerabilities in their designs. Based on these results, we elicit a set of features that must be taken into account when analyzing the security of OB-PWS designs to avoid falling into the same pitfalls as previous proposals. Ero Balsa, Carmela Troncoso, Claudia Díaz |
IEEE Symposium on Security and Privacy | 2 |
| 2012 | A Metric to Evaluate Interaction Obfuscation in Online Social NetworksabstractOnline social networks (OSNs) have become one of the main communication channels in today's information society, and their emergence has raised new privacy concerns. The content uploaded to OSNs (such as pictures, status updates, comments) is by default available to the OSN provider, and often to other people to whom the user who uploaded the content did not intend to give access. A different class of concerns relates to sensitive information that can be inferred from the behavior of users. For example, the analysis of user interactions augments social network graphs with potentially privacy-sensitive details on the nature of social relations, such as the strength of user relationships. A solution to prevent such inferences is to automatically generate dummy interactions that obfuscate the real interactions between OSN users. Given an adversary that observes the obfuscated interactions, the goal is to prevent the adversary from recovering parameters of interest (e.g., relationships strength) that accurately describe the real user interactions. The design and evaluation of obfuscation strategies requires metrics that express the level of protection they would offer when deployed in a particular OSN with its underlying user interaction patterns. In this paper we propose mutual information as obfuscation metric. It measures the amount of information leaked by the (observable) obfuscated interactions in the system on the (concealed) real interactions between users. We show that the metric is suitable for comparing different obfuscation strategies, and flexible to accommodate different network topologies and user communication patterns. Obfuscation comes at the cost of network overhead, and the proposed metric contributes to enabling the optimization of strategies to achieve good levels of privacy protection at minimum overhead. We provide a detailed methodology to compute the metric and perform experiments that illustrate its suitability. Ero Balsa, Carmela Troncoso, Claudia Díaz |
Int. J. Uncertain. Fuzziness Knowl. Based Syst. | 2 |
| 2011 | PIR-Tor: Scalable Anonymous Communication Using Private Information Retrieval
Prateek Mittal, Femi G. Olumofin, Carmela Troncoso, Nikita Borisov, Ian Goldberg 0001 |
USENIX Security Symposium | 3 |
| 2011 | On the difficulty of achieving anonymity for Vehicle-2-X communication
Carmela Troncoso, Enrique Costa-Montenegro, Claudia Díaz, Stefan Schiffner |
Comput. Networks | 1 |
| 2011 | PriPAYD: Privacy-Friendly Pay-As-You-Drive InsuranceabstractPay-As-You-Drive insurance schemes are establishing themselves as the future of car insurance. However, their current implementations, in which fine-grained location data are sent to insurers, entail a serious privacy risk. We present PriPAYD, a system where the premium calculations are performed locally in the vehicle, and only aggregated data are sent to the insurance company, without leaking location information. Our design is based on well-understood security techniques that ensure its correct functioning. We discuss the viability of PriPAYD in terms of cost, security, and ease of certification. We demonstrate that PriPAYD is possible through a proof-of-concept implementation that shows how privacy can be obtained at a very reasonable extra cost. Carmela Troncoso, George Danezis, Eleni Kosta, Josep Balasch, Bart Preneel |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2010 | Drac: An Architecture for Anonymous Low-Volume Communications
George Danezis, Claudia Díaz, Carmela Troncoso, Ben Laurie |
Privacy Enhancing Technologies | 3 |
| 2010 | Impact of Network Topology on Anonymity and Overhead in Low-Latency Anonymity Networks
Claudia Díaz, Steven J. Murdoch, Carmela Troncoso |
Privacy Enhancing Technologies | 3 |
| 2010 | PrETP: Privacy-Preserving Electronic Toll Pricing
Josep Balasch, Alfredo Rial, Carmela Troncoso, Bart Preneel, Ingrid Verbauwhede, Christophe Geuens |
USENIX Security Symposium | 3 |
| 2010 | Scalable Anonymous Communication with Provable Security
Prateek Mittal, Nikita Borisov, Carmela Troncoso, Alfredo Rial |
HotSec | 3 |
| 2009 | The bayesian traffic analysis of mix networksabstractThis work casts the traffic analysis of anonymity systems, and in particular mix networks, in the context of Bayesian inference. A generative probabilistic model of mix network architectures is presented, that incorporates a number of attack techniques in the traffic analysis literature. We use the model to build an Markov Chain Monte Carlo inference engine, that calculates the probabilities of who is talking to whom given an observation of network traces. We provide a thorough evaluation of its correctness and performance, and confirm that mix networks with realistic parameters are secure. This approach enables us to apply established information theoretic anonymity metrics on complex mix networks, and extract information from anonymised traffic traces optimally. Carmela Troncoso, George Danezis |
CCS | 1 |
| 2009 | The Wisdom of Crowds: Attacks and Optimal Constructions
George Danezis, Claudia Díaz, Emilia Käsper, Carmela Troncoso |
ESORICS | 4 |
| 2009 | Vida: How to Use Bayesian Inference to De-anonymize Persistent Communications
George Danezis, Carmela Troncoso |
Privacy Enhancing Technologies | 2 |
| 2008 | A Framework for the Analysis of Mix-Based Steganographic File Systems
Claudia Díaz, Carmela Troncoso, Bart Preneel |
ESORICS | 2 |
| 2008 | On the Impact of Social Network Profiling on Anonymity
Claudia Díaz, Carmela Troncoso, Andrei Serjantov |
Privacy Enhancing Technologies | 2 |
| 2008 | Perfect Matching Disclosure Attacks
Carmela Troncoso, Benedikt Gierlichs, Bart Preneel, Ingrid Verbauwhede |
Privacy Enhancing Technologies | 1 |
| 2007 | Efficient Negative Databases from Cryptographic Hash Functions
George Danezis, Claudia Díaz, Sebastian Faust, Emilia Käsper, Carmela Troncoso, Bart Preneel |
ISC | 5 |
| 2007 | Two-Sided Statistical Disclosure Attack
George Danezis, Claudia Díaz, Carmela Troncoso |
Privacy Enhancing Technologies | 3 |