VLDB 2026 Research / reviewers in the wild / expert
Rahul Chatterjee 0001
dblp:03/9962
· DBLP profile ↗
44ranked-venue papers
5as first author
31since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 32 · 5 first-author · 22 since 2021Human-computer interaction and ubiquitous computing · 9 · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Trauma-Informed Digital Evidence Collection: A Design Inquiry into Evidence Practices for Technology-Facilitated Abuse in Intimate Partner ViolenceabstractTechnology-facilitated abuse (TFA) is a widespread and harmful dimension of interpersonal violence. Documenting TFA can unlock mitigative actions for survivors such as legal orders of protection, but existing documentation tools are insufficient. This paper considers whether a trauma-informed design approach could yield more effective methods for documenting TFA and how, concretely, to approach trauma-informed digital evidence collection. Toward this goal, we use trauma-informed methods to design a new tool, Sherloc, that helps identify and document TFA within tech clinic interventions. We evaluated Sherloc in feedback sessions with legal experts, then in a small pilot program in the U.S. From our design inquiry, we present novel guidelines for trauma-informed digital evidence collection. We call on HCI researchers to build on our work to envision trauma-informed methods of documenting TFA. Sophie Stephenson, Kyle Huang, David Youssef, Kayleigh Cowan, Rahul Chatterjee 0001 |
CHI | 6 |
| 2026 | BREAK-IT: Understanding Novice Approaches to an Attack Challenge TaskabstractWith increasing reliance on computing systems and the growing frequency of cybersecurity incidents, it is important for CS undergraduates to develop foundational security skills before entering professional roles. In particular, students should be able to recognize and reason about potential security vulnerabilities in software. However, existing approaches to integrating security into the CS curriculum often emphasize narrow areas such as secure coding or highly technical topics like cryptography or software security, rather than fostering a broader perception of security threats. In this paper, we examine how undergraduates conceptualize and identify security threats by analyzing how they attempt to find ''attacks'' in other students' code. We conducted a think-aloud study with 15 CS undergraduates at a US-based R1 institution who had no formal training in computer security. Participants analyzed peer-developed text-based video game implementations to identify potential vulnerabilities, drawing on their prior experience implementing a similar game in an earlier ''Build-It'' task. Our analysis shows that students employed systematic, hypothesis-driven strategies, including unit testing, edge-case exploration, and controlled experimentation, while also drawing on prior experiences both inside and outside the classroom. Although most students attempted to validate whether an attack was successful, several stopped after identifying a single vulnerability, leaving additional issues unexplored. Based on these findings, we offer recommendations for CS instructors and curriculum committees on integrating foundational security concepts into programming assignments to help students better recognize and reason about computer security threats. Michelle Jensen, Matthew Berland, Rahul Chatterjee 0001 |
ITiCSE (1) | 3 |
| 2026 | Cultivating a Tech-Safety Mindset using Game-Based Learning for Defending against Technology-Facilitated AbuseabstractTechnology-facilitated abuse (TFA) has become increasingly common as abusers exploit everyday technologies to monitor and harass others, mainly their intimate partners. Preventing TFA requires not only reactive technical support but proactively cultivating protective mindsets --- awareness of personal vulnerability, recognition of threat severity, and confidence to implement defensive strategies --- before abuse escalates. Yet no research has developed educational tools grounded in behavior change theory specifically for technology-facilitated abuse prevention. We address this gap with BeSafe, a narrative-driven visual novel game grounded in Protection Motivation Theory (PMT) and designed to shift how users perceive and respond to TFA threats. Through a study with 198 participants across six platform contexts, we assessed both knowledge acquisition and changes in PMT constructs: perceived vulnerability, perceived severity, self-efficacy, and fear arousal. Our results show that BeSafe produced significant knowledge gains alongside meaningful shifts in protection motivation. Participants with prior exposure to online abuse showed substantially greater gains across both knowledge and motivation measures. Many participants reported intentions to review privacy settings and share protective strategies with others, indicating motivation to act on what they learned. Our findings demonstrate that game-based interventions can cultivate digital safety mindsets, offering a scalable, proactive complement to existing reactive support services. Majed Almansoori, Chirag Ghosh, Sarita Singh, Rahul Chatterjee 0001, Mainack Mondal |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data ExportsabstractWhen survivors of technology-facilitated abuse (TFA) suspect someone has accessed their online accounts, they often rely on built-in account security interfaces (ASIs), such as trusted device lists within settings, to assess account compromise. However, these interfaces typically offer limited or ambiguous details about past account accesses and security-critical events. Under right of access provisions in data protection laws, users can request structured exports of their personal data from online services. In this study, we explore whether and how data exports can supplement ASIs to support compromise investigations, particularly in interpersonal threat contexts. We simulated four types of account compromise attacks across six popular platforms, analyzing the resulting data exports and ASIs. Our findings show that data exports consistently contain more granular login histories and richer device/network identifiers than interfaces. Some even link security-related actions (e.g., password changes) and other post-authentication activity to specific devices, offering forensic value for identifying compromise. We discuss usability and other practical challenges of using data exports during TFA interventions. Julia Nonnenkamp, Abhimanyu Dev Gupta, Rahul Chatterjee 0001 |
CCS | 4 |
| 2025 | Do CS Undergraduates Show Evidence of a Security Mindset without Formal Coursework? An Exploratory Qualitative Study
Michelle Jensen, Matthew Berland, Rahul Chatterjee 0001 |
ICER (1) | 3 |
| 2025 | Detecting Compromise of Passkey Storage on the Cloud
Mazharul Islam 0002, Sunpreet S. Arora, Rahul Chatterjee 0001, Ke Coby Wang |
USENIX Security Symposium | 3 |
| 2025 | Abusability of Automation Apps in Intimate Partner Violence
Shirley Zhang 0002, Paul Chung, Jacob Vervelde, Nishant Korapati, Rahul Chatterjee 0001, Kassem Fawaz |
USENIX Security Symposium | 5 |
| 2025 | A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat Models
Alaa Daffalla, Arkaprabha Bhattacharya, Jacob Wilder, Rahul Chatterjee 0001, Nicola Dell, Rosanna Bellini, Thomas Ristenpart |
USENIX Security Symposium | 4 |
| 2025 | Legal Evidence of Technology-Facilitated Abuse in Wisconsin: Surfacing Barriers Within and Beyond the CourtroomabstractAbusers routinely use technology to spy on and harass their targets. This harmful behavior is known as technology-facilitated abuse , or tech abuse. Survivors of tech abuse may turn to the legal system for safety and security, and to do so, they need evidence of tech abuse. However, prior work indicates challenges to collecting evidence of tech abuse and using it in legal proceedings. Thus, in this work, we study legal evidence used by survivors of tech abuse in Wisconsin, USA. We report on qualitative interviews and focus groups with 19 legal support providers who work with survivors seeking protective orders, divorces, and criminal charges. Our findings surface current practices that survivors and legal support providers use to prepare and present evidence of tech abuse in Wisconsin and the challenges they face. For example, survivors struggle to collect evidence of covert monitoring and surveillance. When they can collect evidence, it is often difficult to connect that evidence to the abuser due to the anonymous nature of many forms of tech abuse. In court, evidence of tech abuse is frequently challenged and vulnerable to objections and counter-evidence. And at the end of a proceeding, it's not uncommon for a judge to determine that the tech abuse does not meet the statutes. Informed by these results, we encourage CSCW and HCI researchers to work towards designing and deploying sociotechnical solutions that support survivors' use of evidence, in careful collaboration with advocates, legal experts, and survivors. Sophie Stephenson, Akhil Polamarasetty, Kyle Huang, David Youssef, Kayleigh Cowan, Rahul Chatterjee 0001 |
Proc. ACM Hum. Comput. Interact. | 7 |
| 2025 | Can Social Media Privacy and Safety Features Protect Targets of Interpersonal Attacks? A Systematic AnalysisabstractSocial media applications have benefited users in several ways, including ease of communication and quick access to information. However, they have also introduced several privacy and safety risks. These risks are particularly concerning in the context of interpersonal attacks, which are carried out by abusive friends, family members, intimate partners, co-workers, or even strangers. Evidence shows interpersonal attackers regularly exploit social media platforms to harass and spy on their targets. To help protect targets from such attacks, social media platforms have introduced several privacy and safety features. However, it is unclear how effective they are against interpersonal threats. In this work, we analyzed ten popular social media applications, identifying 100 unique privacy and safety features that provide controls across eight categories: discoverability, visibility, saving and sharing, interaction, self-censorship, content moderation, transparency, and reporting. We simulated 59 different attack actions by a persistent attacker — aimed at account discovery, information gathering, non-consensual sharing, and harassment — and found many were successful. Based on our findings, we proposed improvements to mitigate these risks. Majed Almansoori, Rahul Chatterjee 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | The Web of Abuse: A Comprehensive Analysis of Online Resource in the Context of Technology-Enabled Intimate Partner SurveillanceabstractPrevious research has shown that abusers in an intimate relationship can find plenty of technical advice, tools, and how-to guides online for covertly conducting intimate partner surveillance (IPS). However, it is unclear what resources survivors seeking to defend themselves against IPS can use. To address this gap, we first conducted a survey-based study with 63 survivors recruited via Prolific to understand what resources survivors rely on. We showed that 45% utilized online resources for assistance, with 67% of them relying on search engines. We then conducted a systematic survey of the results obtained via Google search engine to identify resources available for survivors. We found that the resources survivors can find online contain poor, inaccurate, and unactionable advice. They are hard to understand and do not help mitigate IPS. To investigate whether the lack of useful resources is solely experienced by survivors, we also crawled resources that abusers will find online. We found that abusers can easily find resources recommending spyware apps and hidden devices and often explicitly promoting IPS. We also compared the understandability and actionability of the resources using an adopted Patient Education Materials Assessment Tool (PEMAT) score. We concluded that resources available to abusers are significantly more understandable and actionable than those available to survivors. Majed Almansoori, Mazharul Islam 0002, Saptarshi Ghosh 0001, Mainack Mondal, Rahul Chatterjee 0001 |
EuroS&P | 5 |
| 2024 | "I really just leaned on my community for support": Barriers, Challenges and Coping Mechanisms Used by Survivors of Technology-Facilitated Abuse to Seek Social Support
Kate Walsh, Sanchari Das 0001, Rahul Chatterjee 0001 |
USENIX Security Symposium | 4 |
| 2024 | Scalable Metadata-Hiding for Privacy-Preserving IoT SystemsabstractModern cloud-based IoT services comprise an integrator service and several device vendor services. The vendor services enable users to remotely control their devices, while the integrator serves as a central intermediary, offering a unified interface for managing devices from different vendors. Although such a model is quite beneficial for IoT services to evolve quickly, it also creates a serious privacy concern: the vendor and integrator services observe all interactions between users and devices. Toward this, we propose Mohito, a privacy-preserving IoT system that hides such interactions from both the integrator and the vendors. In Mohito, we protect both the interaction data and the metadata, so that no one learns which user is communicating with which device. By utilizing oblivious key-value storage as a primitive and leveraging the unique communication graph of IoT services, we build a scalable protocol specialized in handling large concurrent traffic, a common demand in IoT systems. Our evaluation shows that Mohito can achieve up to 600x more throughput than the state-of-the-art general-purpose systems that provide similar security guarantees. Yunang Chen, David Heath 0001, Rahul Chatterjee 0001, Earlence Fernandes |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Compact: Approximating Complex Activation Functions for Secure ComputationabstractSecure multi-party computation (MPC) techniques can be used to provide data privacy when users query deep neural network (DNN) models hosted on a public cloud. State-of-the-art MPC techniques can be directly leveraged for DNN models that use simple activation functions (AFs) such as ReLU. However, these techniques are ineffective and/or inefficient for the complex and highly non-linear AFs used in cutting-edge DNN models. We present Compact, which produces piece-wise polynomial approximations of complex AFs to enable their efficient use with state-of-the-art MPC techniques. Compact neither requires nor imposes any restriction on model training and results in near-identical model accuracy. To achieve this, we design Compact with input density awareness, and use an application specific simulated annealing type optimization to generate computationally more efficient approximations of complex AFs. We extensively evaluate Compact on four different machine-learning tasks with DNN architectures that use popular complex AFs silu, gelu, and mish. Our experimental results show that Compact incurs negligible accuracy loss while being 2x-5x computationally more efficient than state-of-the-art approaches for DNN models with large number of hidden layers. Our work accelerates easy adoption of MPC techniques to provide user data privacy even when the queried DNN models consist of a number of hidden layers, and trained over complex AFs. Mazharul Islam 0002, Sunpreet S. Arora, Rahul Chatterjee 0001, Peter Rindal, Maliheh Shirvanian |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Camouflage: Utility-Aware Obfuscation for Accurate Simulation of Sensitive Program TracesabstractTrace-based simulation is a widely used methodology for system design exploration. It relies on realistic traces that represent a range of behaviors necessary to be evaluated, containing a lot of information about the application, its inputs and the underlying system on which it was generated. Consequently, generating traces from real-world executions risks leakage of sensitive information. To prevent this, traces can be obfuscated before release. However, this can undermine their ideal utility, i.e., how realistically a program behavior was captured. To address this, we propose Camouflage, a novel obfuscation framework, designed with awareness of the necessary architectural properties required to preserve trace utility , while ensuring secrecy of the inputs used to generate the trace. Focusing on memory access traces, our extensive evaluation on various benchmarks shows that camouflaged traces preserve the performance measurements of the original execution, with an average τ correlation of 0.66. We model input secrecy as an input indistinguishability problem and show that the average security loss is 7.8%, which is better than traces generated from the state-of-the-art. Asmita Pal, Keerthana Desai, Rahul Chatterjee 0001, Joshua San Miguel |
ACM Trans. Archit. Code Optim. | 3 |
| 2023 | MASCARA : Systematically Generating Memorable And Secure PassphrasesabstractPasswords are the most common mechanism for authenticating users online. However, studies have shown that users find it difficult to create and manage secure passwords. To that end, passphrases are often recommended as a usable alternative to passwords, which would potentially be easy to remember and hard to guess. However, as we show, user-chosen passphrases fall short of being secure, while state-of-the-art machine-generated passphrases are difficult to remember. Avirup Mukherjee, Kousshik Murali, Shivam Kumar Jha, Niloy Ganguly, Rahul Chatterjee 0001, Mainack Mondal |
AsiaCCS | 5 |
| 2023 | Towards Finding the Missing Pieces to Teach Secure Programming Skills to StudentsabstractResearch efforts tried to expose students to security topics early in the undergraduate CS curriculum. However, such efforts are rarely adopted in practice and remain less effective when it comes to writing secure code. In our prior work [18], we identified key issues with the how students code and grouped them into six themes: (a) Knowledge of C, (b) Understanding compiler and OS messages, (c) Utilization of resources, (d) Knowledge of memory, (e) Awareness of unsafe functions, and (f) Understanding of security topics. In this work, we aim to understand students' knowledge about each theme and how that knowledge affects their secure coding practices. Thus, we propose a modified SOLO taxonomy for the latter five themes. We apply the taxonomy to the coding interview data of 21 students from two US R1 universities. Our results suggest that most students have limited knowledge of each theme. We also show that scoring low in these themes correlates with why students fail to write secure code and identify possible vulnerabilities. Majed Almansoori, Jessica Lam, Elias Fang, Adalbert Gerald Soosai Raj, Rahul Chatterjee 0001 |
SIGCSE (1) | 5 |
| 2023 | Sneaky Spy Devices and Defective Detectors: The Ecosystem of Intimate Partner Surveillance with Covert Devices
Rose Ceccio, Sophie Stephenson, Varun Chadha, Danny Yuxing Huang, Rahul Chatterjee 0001 |
USENIX Security Symposium | 5 |
| 2023 | Araña: Discovering and Characterizing Password Guessing Attacks in Practice
Mazharul Islam 0002, Marina Sanusi Bohuk, Paul Chung, Thomas Ristenpart, Rahul Chatterjee 0001 |
USENIX Security Symposium | 5 |
| 2023 | "It's the Equivalent of Feeling Like You're in Jail": Lessons from Firsthand and Secondhand Accounts of IoT-Enabled Intimate Partner Abuse
Sophie Stephenson, Majed Almansoori, Pardis Emami Naeini, Rahul Chatterjee 0001 |
USENIX Security Symposium | 4 |
| 2023 | Abuse Vectors: A Framework for Conceptualizing IoT-Enabled Interpersonal Abuse
Sophie Stephenson, Majed Almansoori, Pardis Emami Naeini, Danny Yuxing Huang, Rahul Chatterjee 0001 |
USENIX Security Symposium | 5 |
| 2022 | Identifying Gaps in the Secure Programming Knowledge and Skills of StudentsabstractOften, security topics are only taught in advanced computer science (CS) courses. However, most US R1 universities do not require students to take these courses to complete an undergraduate CS degree. As a result, students can graduate without learning about computer security and secure programming practices. To gauge students' knowledge and skills of secure programming, we conducted a coding interview with 21 students from two R1 universities in the United States. All the students in our study had at least taken Computer Systems or an equivalent course. We then analyzed the students' approach to safe programming practices, such as avoiding unsafe functions like gets and strcpy, and basic security knowledge, such as writing code that assumes user inputs can be malicious. Our results suggest that students lack the key fundamental skills to write secure programs. For example, students rarely pay attention to details, such as compiler warnings, and often do not read programming language documentation with care. Moreover, some students' understanding of memory layout is cursory, which is crucial for writing secure programs. We also found that some students are struggling with even the basics of C programming, even though it is the main language taught in Computer Systems courses. Jessica Lam, Elias Fang, Majed Almansoori, Rahul Chatterjee 0001, Adalbert Gerald Soosai Raj |
SIGCSE (1) | 4 |
| 2022 | SoK: Authentication in Augmented and Virtual RealityabstractAugmented reality (AR) and virtual reality (VR) devices are emerging as prominent contenders to today’s personal computers. As personal devices, users will use AR and VR to store and access their sensitive data and thus will need secure and usable ways to authenticate. In this paper, we evaluate the state-of-the-art of authentication mechanisms for AR/VR devices by systematizing research efforts and practical deployments. By studying users’ experiences with authentication on AR and VR, we gain insight into the important properties needed for authentication on these devices. We then use these properties to perform a comprehensive evaluation of AR/VR authentication mechanisms both proposed in literature and used in practice. In all, we synthesize a coherent picture of the current state of authentication mechanisms for AR/VR devices. We draw on our findings to provide concrete research directions and advice on implementing and evaluating future authentication methods. Sophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes, Yuhang Zhao 0001, Rahul Chatterjee 0001 |
SP | 6 |
| 2022 | Gossamer: Securely Measuring Password-based Logins
Marina Sanusi Bohuk, Mazharul Islam 0002, Suleman Ahmad, Michael M. Swift, Thomas Ristenpart, Rahul Chatterjee 0001 |
USENIX Security Symposium | 6 |
| 2022 | Experimental Security Analysis of the App Model in Business Collaboration Platforms
Yunang Chen, Yue Gao 0011, Nick Ceccio, Rahul Chatterjee 0001, Kassem Fawaz, Earlence Fernandes |
USENIX Security Symposium | 4 |
| 2022 | Practical Data Access Minimization in Trigger-Action Platforms
Yunang Chen, Mohannad Alhanahnah, Andrei Sabelfeld, Rahul Chatterjee 0001, Earlence Fernandes |
USENIX Security Symposium | 4 |
| 2022 | Might I Get Pwned: A Second Generation Compromised Credential Checking Service
Bijeeta Pal, Mazharul Islam 0002, Marina Sanusi Bohuk, Nick Sullivan, Luke Valenta, Tara Whalen, Christopher A. Wood, Thomas Ristenpart, Rahul Chatterjee 0001 |
USENIX Security Symposium | 9 |
| 2022 | A Global Survey of Android Dual-Use Applications Used in Intimate Partner SurveillanceabstractIntimate partner violence (IPV) is a pervasive societal problem that affects millions of people around the world. IPV perpetrators increasingly weaponize digital technologies like mobile applications (“apps”) to spy on, monitor, and harass victims. Surveillance-capable apps can have legitimate use cases, for example, locating children, and are therefore easily available on various mobile app stores like the Google Play Store. Nevertheless, these applications are easily repurposed by abusers to track their victims. The problem of such dual-use apps in IPV is global. However, current understanding of the ecosystem of such apps is limited to English-language apps, potentially limiting its relevance to non-English speaking IPV survivors across the world. In this paper, we study the prevalence of dualuse applications found in 15 languages and 27 countries. We collected 51,868 unique apps in 2020 from the Google Play Store, using queries such as “track wife’s location.” Through a semi-manual analysis of a subset of these apps, we discovered 854 unique dualuse apps, and estimate that among the apps collected from Google Play, 3,988 are dual-use apps. We found notable differences in app search results, suggested queries, and marketed capabilities of dual-use apps across different languages. For instance, we identified that 18% of dual-use apps do not have an English description, and 28% could not be found using English queries. Google Play (cursorily) blocks certain queries referring explicitly to intimate partner surveillance (IPS) to discourage potential abusers, but the blocking efficacy varies across languages. For example, we found that 80% of explicit IPS queries for English are blocked, but none for Bengali, Chinese, Hindi, Malay, Thai, and Vietnamese. Thus, abusers fluent in those languages can evade such blocking with no effort. Majed Almansoori, Andrea Gallardo, Julio Poveda, Adil Ahmed, Rahul Chatterjee 0001 |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | Invisible Perturbations: Physical Adversarial Examples Exploiting the Rolling Shutter EffectabstractPhysical adversarial examples for camera-based computer vision have so far been achieved through visible artifacts — a sticker on a Stop sign, colorful borders around eyeglasses or a 3D printed object with a colorful texture. An implicit assumption here is that the perturbations must be visible so that a camera can sense them. By contrast, we contribute a procedure to generate, for the first time, physical adversarial examples that are invisible to human eyes. Rather than modifying the victim object with visible artifacts, we modify light that illuminates the object. We demonstrate how an attacker can craft a modulated light signal that adversarially illuminates a scene and causes targeted misclassifications on a state-of-the-art ImageNet deep learning model. Concretely, we exploit the radiometric rolling shutter effect in commodity cameras to create precise striping patterns that appear on images. To human eyes, it appears like the object is illuminated, but the camera creates an image with stripes that will cause ML models to output the attacker-desired classification. We conduct a range of simulation and physical experiments with LEDs, demonstrating targeted attack rates up to 84%. Athena Sayles, Ashish Hooda, Mohit Gupta 0001, Rahul Chatterjee 0001, Earlence Fernandes |
CVPR | 4 |
| 2021 | Textbook Underflow: Insufficient Security Discussions in Textbooks Used for Computer Systems CoursesabstractIntroductory computer science courses, such as Computer Systems, could be used to provide the first exposure to computer security to students. However, prior work has shown that, in the US's top R1 universities, computer systems courses are not taught with security in mind. It was also shown that students and instructors use unsafe functions in their code, leading to security vulnerabilities. In this paper, we focused on the textbooks used for computer systems courses. We analyzed the discussion of security topics and the use of unsafe functions in the thirteen textbooks used in the top 30 R1 universities in the US for teaching computer systems. We show that many textbooks do not discuss security at all, while some limit their discussion to "undefined behavior'', ignoring that opportunity to discuss potential security issues associated with the undefined behavior. Furthermore, textbooks that talk about security continue using unsafe functions throughout (though not necessarily in vulnerable ways but also without any warning or explanation). We also show that many textbooks do not warn about unsafe functions they use or teach how to use them safely. Majed Almansoori, Jessica Lam, Elias Fang, Adalbert Gerald Soosai Raj, Rahul Chatterjee 0001 |
SIGCSE | 5 |
| 2021 | Data Privacy in Trigger-Action SystemsabstractTrigger-action platforms (TAPs) allow users to connect independent web-based or IoT services to achieve useful automation. They provide a simple interface that helps end-users create trigger-compute-action rules that pass data between disparate Internet services. Unfortunately, TAPs introduce a large-scale security risk: if they are compromised, attackers will gain access to sensitive data for millions of users. To avoid this risk, we propose eTAP, a privacy-enhancing trigger-action platform that executes trigger-compute-action rules without accessing users’ private data in plaintext or learning anything about the results of the computation. We use garbled circuits as a primitive, and leverage the unique structure of trigger-compute-action rules to make them practical. We formally state and prove the security guarantees of our protocols. We prototyped eTAP, which supports the most commonly used operations on popular commercial TAPs like IFTTT and Zapier. Specifically, it supports Boolean, arithmetic, and string operations on private trigger data and can run 100% of the top-500 rules of IFTTT users and 93.4% of all publicly-available rules on Zapier. Based on ten existing rules that exercise a wide variety of operations, we show that eTAP has a modest performance impact: on average rule execution latency increases by 70 ms (55%) and throughput reduces by 59%. Yunang Chen, Amrita Roy Chowdhury 0001, Ruizhe Wang 0003, Andrei Sabelfeld, Rahul Chatterjee 0001, Earlence Fernandes |
SP | 5 |
| 2020 | How Secure are our Computer Systems Courses?abstractIntroductory computer systems courses teach students how a single program is executed inside a computer, providing them with their first exposure to the logical internals of computing systems. This is one of the first introductory courses where students can learn about security and the need for robust coding. However, currently, these courses are taught with a focus on functionality and efficiency only, ignoring security almost entirely. Majed Almansoori, Jessica Lam, Elias Fang, Kieran Mulligan, Adalbert Gerald Soosai Raj, Rahul Chatterjee 0001 |
ICER | 6 |
| 2019 | Multisketches: Practical Secure Sketches Using Off-the-Shelf Biometric Matching AlgorithmsabstractBiometric authentication is increasingly being used for large scale human authentication and identification, creating the risk of leaking the biometric secrets of millions of users in the case of database compromise. Powerful "fuzzy" cryptographic techniques for biometric template protection, such as secure sketches, could help in principle, but go unused in practice. This is because they would require new biometric matching algorithms with potentially much diminished accuracy. We introduce a new primitive called a multisketch that generalizes secure sketches. Multisketches can work with existing biometric matching algorithms to generate strong cryptographic keys from biometric data reliably. A multisketch works on a biometric database containing multiple biometrics --- e.g., multiple fingerprints --- of a moderately large population of users (say, thousands). It conceals the correspondence between users and their biometric templates, preventing an attacker from learning the biometric data of a user in the advent of a breach, but enabling derivation of user-specific secret keys upon successful user authentication. We design a multisketch over tenprints --- fingerprints of ten fingers --- called TenSketch. We report on a prototype implementation of TenSketch, showing its feasibility in practice. We explore several possible attacks against TenSketch database and show, via simulations with real tenprint datasets, that an attacker must perform a large amount of computation to learn any meaningful information from a stolen TenSketch database. Rahul Chatterjee 0001, M. Sadegh Riazi, Tanmoy Chowdhury, Emanuela Marasco, Farinaz Koushanfar, Ari Juels |
CCS | 1 |
| 2019 | Protocols for Checking Compromised CredentialsabstractTo prevent credential stuffing attacks, industry best practice now proactively checks if user credentials are present in known data breaches. Recently, some web services, such as HaveIBeenPwned (HIBP) and Google Password Checkup (GPC), have started providing APIs to check for breached passwords. We refer to such services as compromised credential checking (C3) services. We give the first formal description of C3 services, detailing different settings and operational requirements, and we give relevant threat models. One key security requirement is the secrecy of a user's passwords that are being checked. Current widely deployed C3 services have the user share a small prefix of a hash computed over the user's password. We provide a framework for empirically analyzing the leakage of such protocols, showing that in some contexts knowing the hash prefixes leads to a 12x increase in the efficacy of remote guessing attacks. We propose two new protocols that provide stronger protection for users' passwords, implement them, and show experimentally that they remain practical to deploy. Lucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan, Rahul Chatterjee 0001, Thomas Ristenpart |
CCS | 5 |
| 2019 | Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksabstractAttackers increasingly use passwords leaked from one website to compromise associated accounts on other websites. Such targeted attacks work because users reuse, or pick similar, passwords for different websites. We recast one of the core technical challenges underlying targeted attacks as the task of modeling similarity of human-chosen passwords. We show how to learn good password similarity models using a compilation of 1.4 billion leaked email, password pairs. Using our trained models of password similarity, we exhibit the most damaging targeted attack to date. Simulations indicate that our attack compromises more than 16% of user accounts in less than a thousand guesses, should one of their other passwords be known to the attacker and despite the use of state-of-the art countermeasures. We show via a case study involving a large university authentication service that the attacks are also effective in practice. We go on to propose the first-ever defense against such targeted attacks, by way of personalized password strength meters (PPSMs). These are password strength meters that can warn users when they are picking passwords that are vulnerable to attacks, including targeted ones that take advantage of the user's previously compromised passwords. We design and build a PPSM that can be compressed to less than 3 MB, making it easy to deploy in order to accurately estimate the strength of a password against all known guessing attacks. Bijeeta Pal, Tal Daniel, Rahul Chatterjee 0001, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 3 |
| 2019 | Clinical Computer Security for Victims of Intimate Partner Violence
Sam Havron, Diana Freed, Rahul Chatterjee 0001, Damon McCoy, Nicola Dell, Thomas Ristenpart |
USENIX Security Symposium | 3 |
| 2019 | "Is my phone hacked?" Analyzing Clinical Computer Security Interventions with Survivors of Intimate Partner ViolenceabstractIntimate partner abusers use technology to track, monitor, harass, and otherwise harm their victims, and prior work reports that victims have few resources for obtaining help with such attacks. This paper presents a qualitative analysis of data from a field study of an approach to helping survivors of intimate partner violence (IPV) with technology abuse. In this approach, called clinical computer security, a trained technologist performs a face-to-face consultation with an IPV survivor to help them understand and navigate technology issues. Findings from consultations with 31 survivors, as well as IPV professionals working on their behalf, uncovered a range of digital security and privacy vulnerabilities exacerbated by the nuanced social context of such abuse. In this paper we explore survivor experiences with, and reactions to, the consultations, discussing (1) the ways in which survivors present their tech concerns, (2) the cooperative work required to guide survivors towards understanding probable causes of tech insecurity, (3) survivors' reactions to the consultations, particularly when security vulnerabilities or spyware are discovered, and (4) the role we play as consultants and interventionists in the complex socio-technical systems involved in mitigating IPV. We conclude by discussing some of the broad ethical and sustainability challenges raised by our work, and provide design opportunities for tech platforms to better support survivors of IPV. Diana Freed, Sam Havron, Emily Tseng, Andrea Gallardo, Rahul Chatterjee 0001, Thomas Ristenpart, Nicola Dell |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2018 | The Spyware Used in Intimate Partner ViolenceabstractSurvivors of intimate partner violence increasingly report that abusers install spyware on devices to track their location, monitor communications, and cause emotional and physical harm. To date there has been only cursory investigation into the spyware used in such intimate partner surveillance (IPS). We provide the first in-depth study of the IPS spyware ecosystem. We design, implement, and evaluate a measurement pipeline that combines web and app store crawling with machine learning to find and label apps that are potentially dangerous in IPS contexts. Ultimately we identify several hundred such IPS-relevant apps. While we find dozens of overt spyware tools, the majority are "dual-use" apps - they have a legitimate purpose (e.g., child safety or anti-theft), but are easily and effectively repurposed for spying on a partner. We document that a wealth of online resources are available to educate abusers about exploiting apps for IPS. We also show how some dual-use app developers are encouraging their use in IPS via advertisements, blogs, and customer support services. We analyze existing anti-virus and anti-spyware tools, which universally fail to identify dual-use apps as a threat. Rahul Chatterjee 0001, Periwinkle Doerfler, Hadas Orgad, Sam Havron, Jackeline Palmer, Diana Freed, Karen Levy, Nicola Dell, Damon McCoy, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 1 |
| 2017 | The TypTop System: Personalized Typo-Tolerant Password CheckingabstractPassword checking systems traditionally allow login only if the correct password is submitted. Recent work on typo-tolerant password checking suggests that usability can be improved, with negligible security loss, by allowing a small number of typographical errors. Existing systems, however, can only correct a handful of errors, such as accidentally leaving caps lock on or incorrect capitalization of the first letter in a password. This leaves out numerous kinds of typos made by users, such as transposition errors, substitutions, or capitalization errors elsewhere in a password. Some users therefore receive no benefit from existing typo-tolerance mechanisms. Rahul Chatterjee 0001, Joanne Woodage, Yuval Pnueli, Anusha Chowdhury, Thomas Ristenpart |
CCS | 1 |
| 2017 | A New Distribution-Sensitive Secure Sketch and Popularity-Proportional Hashing
Joanne Woodage, Rahul Chatterjee 0001, Yevgeniy Dodis, Ari Juels, Thomas Ristenpart |
CRYPTO (3) | 2 |
| 2016 | pASSWORD tYPOS and How to Correct Them SecurelyabstractWe provide the first treatment of typo-tolerant password authentication for arbitrary user-selected passwords. Such a system, rather than simply rejecting a login attempt with an incorrect password, tries to correct common typographical errors on behalf of the user. Limited forms of typo-tolerance have been used in some industry settings, but to date there has been no analysis of the utility and security of such schemes. We quantify the kinds and rates of typos made by users via studies conducted on Amazon Mechanical Turk and via instrumentation of the production login infrastructure at Dropbox. The instrumentation at Dropbox did not record user passwords or otherwise change authentication policy, but recorded only the frequency of observed typos. Our experiments reveal that almost 10% of login attempts fail due to a handful of simple, easily correctable typos, such as capitalization errors. We show that correcting just a few of these typos would reduce login delays for a significant fraction of users as well as enable an additional 3% of users to achieve successful login. We introduce a framework for reasoning about typo-tolerance, and investigate the seemingly inherent tension here between security and usability of passwords. We use our framework to show that there exist typo-tolerant authentication schemes that can get corrections for "free": we prove they are as secure as schemes that always reject mistyped passwords. Building off this theory, we detail a variety of practical strategies for securely implementing typo-tolerance. Rahul Chatterjee 0001, Anish Athayle, Devdatta Akhawe, Ari Juels, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 1 |
| 2015 | Cracking-Resistant Password Vaults Using Natural Language EncodersabstractPassword vaults are increasingly popular applications that store multiple passwords encrypted under a single master password that the user memorizes. A password vault can greatly reduce the burden on a user of remembering passwords, but introduces a single point of failure. An attacker that obtains a user's encrypted vault can mount offline brute-force attacks and, if successful, compromise all of the passwords in the vault. In this paper, we investigate the construction of encrypted vaults that resist such offline cracking attacks and force attackers instead to mount online attacks. Our contributions are as follows. We present an attack and supporting analysis showing that a previous design for cracking-resistant vaults -- the only one of which we are aware -- actually degrades security relative to conventional password-based approaches. We then introduce a new type of secure encoding scheme that we call a natural language encoder (NLE). An NLE permits the construction of vaults which, when decrypted with the wrong master password, produce plausible-looking decoy passwords. We show how to build NLEs using existing tools from natural language processing, such as n-gram models and probabilistic context-free grammars, and evaluate their ability to generate plausible decoys. Finally, we present, implement, and evaluate a full, NLE-based cracking-resistant vault system called NoCrack. Rahul Chatterjee 0001, Joseph Bonneau, Ari Juels, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 1 |
| 2015 | The Pythia PRF Service
Adam Everspaugh, Rahul Chatterjee 0001, Samuel Scott, Ari Juels, Thomas Ristenpart |
USENIX Security Symposium | 2 |
| 2011 | MAESTRO: Making Art-Enabled Sketches through Randomized Operations
Subhro Roy, Rahul Chatterjee 0001, Partha Bhowmick, Reinhard Klette |
CAIP (1) | 2 |