VLDB 2026 Research / reviewers in the wild / expert
Urs Hengartner
dblp:04/6136
· DBLP profile ↗
51ranked-venue papers
12as first author
13since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 32 · 4 first-author · 12 since 2021Human-computer interaction and ubiquitous computing · 12 · 4 first-author · 1 since 2021Computer networks · 7 · 2 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tracking for Good: Finding Behavioral Biometrics on the Web using Static Taint Analysis
Aswad Tariq, Alexandru Bara, Urs Hengartner |
SACMAT | 3 |
| 2026 | Sharing Digital Devices is Normal and Cultural: Privacy and Security Challenges in Collectivist Immigrant Households
S. Shanza, Ameemah Humayun, Urs Hengartner, Leah Zhang-Kennedy |
SOUPS | 3 |
| 2026 | Uncovering robot joint-level controller actions from encrypted network traffic: Empirical attacks and information-theoretic boundsabstractThis study examines the privacy risks associated with the teleoperation of robots controlled via encrypted network communications. From the perspective of a network eavesdropper, we explore the potential to infer sensitive robotic actions by analyzing traffic metadata, such as packet timing, size, and direction. We investigate this threat using a smartphone’s Inertial Measurement Unit (IMU) to control a collaborative robotic arm via three joint-level modalities—position, velocity, and torque—to perform four distinct actions. First, empirical traffic analysis demonstrates that an adversary can identify robot actions with high accuracy using standard machine learning classifiers. Second, to determine whether the remaining classification errors stem from empirical model limitations or the structural constraints of the physical protocols, we apply a classifier-agnostic information-theoretic evaluation. Using mutual information, we derive Bayes optimal accuracy bounds and show that torque control leaks more deterministic information than suggested by empirical models, while velocity inherently exposes less information. Third, by prototyping a traffic padding defense, we evaluate the limitations of standard obfuscation against these structural leakages. Our findings highlight the necessity of information-theoretic bounds in privacy research and inform the design of secure robotic teleoperation APIs. Diogo Barradas, Urs Hengartner, Yue Hu 0001 |
Comput. Secur. | 3 |
| 2025 | On the Feasibility of Fingerprinting Collaborative Robot Network Traffic
Diogo Barradas, Urs Hengartner, Yue Hu 0001 |
ARES (1) | 3 |
| 2025 | DiffBreak: Is Diffusion-Based Purification Robust?abstractDiffusion-based purification (DBP) has become a cornerstone defense against adversarial examples (AEs), regarded as robust due to its use of diffusion models (DMs) that project AEs onto the natural data manifold. We refute this core claim, theoretically proving that gradient-based attacks effectively target the DM rather than the classifier, causing DBP's outputs to align with adversarial distributions. This prompts a reassessment of DBP's robustness, accrediting it two critical factors: inaccurate gradients and improper evaluation protocols that test only a single random purification of the AE. We show that when accounting for stochasticity and resubmission risk, DBP collapses. To support this, we introduce DiffBreak, the first reliable toolkit for differentiation through DBP, eliminating gradient mismatches that previously further inflated robustness estimates. We also analyze the current defense scheme used for DBP where classification relies on a single purification, pinpointing its inherent invalidity. We provide a statistically grounded majority-vote (MV) alternative that aggregates predictions across multiple purified copies, showing partial but meaningful robustness gain. We then propose a novel adaptation of an optimization method against deepfake watermarking, crafting systemic perturbations that defeat DBP even under MV, challenging DBP's viability. Andre Kassis, Urs Hengartner, Yaoliang Yu |
NeurIPS | 2 |
| 2025 | Uncovering Robot Joint-Level Controller Actions from Encrypted Network Traffic
Diogo Barradas, Urs Hengartner, Yue Hu 0001 |
SEC (1) | 3 |
| 2025 | UnMarker: A Universal Attack on Defensive Image WatermarkingabstractReports regarding the misuse of Generative AI (GenAI) to create deepfakes are frequent. Defensive watermarking enables GenAI providers to hide fingerprints in their images and use them later for deepfake detection. Yet, its potential has not been fully explored. We present UnMarker— the first practical universal attack on defensive watermarking. Unlike existing attacks, UnMarker requires no detector feedback, no unrealistic knowledge of the watermarking scheme or similar models, and no advanced denoising pipelines that may not be available. Instead, being the product of an in-depth analysis of the watermarking paradigm revealing that robust schemes must construct their watermarks in the spectral amplitudes, UnMarker employs two novel adversarial optimizations to disrupt the spectra of watermarked images, erasing the watermarks. Evaluations against SOTA schemes prove UnMarker's effectiveness. It not only defeats traditional schemes while retaining superior quality compared to existing attacks but also breaks semantic watermarks that alter an image's structure, reducing the best detection rate to 43% and rendering them useless. To our knowledge, UnMarker is the first practical attack on semantic watermarks, which have been deemed the future of defensive watermarking. Our findings show that defensive watermarking is not a viable defense against deepfakes, and we urge the community to explore alternatives. Andre Kassis, Urs Hengartner |
SP | 2 |
| 2024 | SHRIMPS: A framework for evaluating multi-user, multi-modal implicit authentication systems
Jiayi Chen 0001, Urs Hengartner, Hassan Khan 0002 |
Comput. Secur. | 2 |
| 2024 | MRAAC: A Multi-stage Risk-aware Adaptive Authentication and Access Control Framework for AndroidabstractAdaptive authentication enables smartphones and enterprise apps to decide when and how to authenticate users based on contextual and behavioral factors. In practice, a system may employ multiple policies to adapt its authentication mechanisms and access controls to various scenarios. However, existing approaches suffer from contradictory or insecure adaptations, which may enable attackers to bypass the authentication system. Besides, most existing approaches are inflexible and do not provide desirable access controls. We design and build a multi-stage risk-aware adaptive authentication and access control framework (MRAAC), which provides the following novel contributions: Multi-stage: MRAAC organizes adaptation policies in multiple stages to handle different risk types and progressively adapts authentication mechanisms based on context, resource sensitivity, and user authenticity. Appropriate access control: MRAAC provides libraries to enable sensitive apps to manage the availability of their in-app resources based on MRAAC’s risk awareness. Extensible: While existing proposals are tailored to cater to a single use case, MRAAC supports a variety of use cases with custom risk models. We exemplify these advantages of MRAAC by deploying it for three use cases: an enhanced version of Android Smart Lock, guest-aware continuous authentication, and corporate app for BYOD. We conduct experiments to quantify the CPU, memory, latency, and battery performance of MRAAC. Our evaluation shows that MRAAC enables various stakeholders (device manufacturers, enterprise and secure app developers) to provide complex adaptive authentication workflows on COTS Android with low processing and battery overhead. Jiayi Chen 0001, Urs Hengartner, Hassan Khan 0002 |
ACM Trans. Priv. Secur. | 2 |
| 2023 | Investigating Membership Inference Attacks under Data DependenciesabstractTraining machine learning models on privacy-sensitive data has become a popular practice, driving innovation in ever-expanding fields. This has opened the door to new attacks that can have serious privacy implications. One such attack, the Membership Inference Attack (MIA), exposes whether or not a particular data point was used to train a model. A growing body of literature uses Differentially Private (DP) training algorithms as a defence against such attacks. However, these works evaluate the defence under the restrictive assumption that all members of the training set, as well as non-members, are independent and identically distributed. This assumption does not hold for many real-world use cases in the literature. Motivated by this, we evaluate membership inference with statistical dependencies among samples and explain why DP does not provide meaningful protection (the privacy parameter$\epsilon$scales with the training set size$n$) in this more general case. We conduct a series of empirical evaluations with off-the-shelf MIAs using training sets built from real-world data showing different types of dependencies among samples. Our results reveal that training set dependencies can severely increase the performance of MIAs, and therefore assuming that data samples are statistically independent can significantly underestimate the performance of MIAs. Thomas Humphries, Simon Oya, Lindsey Tulloch, Matthew Rafuse, Ian Goldberg 0001, Urs Hengartner, Florian Kerschbaum |
CSF | 6 |
| 2023 | Breaking Security-Critical Voice AuthenticationabstractVoice authentication (VA) has recently become an integral part in numerous security-critical operations, such as bank transactions and call center conversations. The vulnerability of automatic speaker verification systems (ASVs) to spoofing attacks instigated the development of countermeasures (CMs), whose task is to differentiate between bonafide and spoofed speech. Together, ASVs and CMs form today’s VA systems and are being advertised as an impregnable access control mechanism. We develop the first practical attack on spoofing countermeasures, and demonstrate how a malicious actor may efficiently craft audio samples against these defenses. Previous adversarial attacks against VA have been mainly designed for the whitebox scenario, which assumes knowledge of the system’s internals, or requires large query and time budgets to launch target-specific attacks. When attacking a security-critical system, these assumptions do not hold. Our attack, on the other hand, targets common points of failure that all spoofing countermeasures share, making it real-time, model-agnostic, and completely blackbox without the need to interact with the target to craft the attack samples. The key message from our work is that CMs mistakenly learn to distinguish between spoofed and bonafide audio based on cues that are easily identifiable and forgeable. The effects of our attack are subtle enough to guarantee that these adversarial samples can still bypass the ASV as well and preserve their original textual contents. These properties combined make for a powerful attack that can bypass security-critical VA in its strictest form, yielding success rates of up to 99% with only 6 attempts. Finally, we perform the first targeted, over-telephony-network attack on CMs, bypassing several known challenges and enabling a variety of potential threats, given the increased use of voice biometrics in call centers. Our results call into question the security of modern VA systems and urge users to rethink their trust in them, in light of the real threat of attackers bypassing these measures to gain access to their most valuable resources. Andre Kassis, Urs Hengartner |
SP | 2 |
| 2023 | Revisiting the Security of Biometric Authentication Systems Against Statistical AttacksabstractThe uniqueness of behavioral biometrics (e.g., voice or keystroke patterns) has been challenged by recent works. Statistical attacks have been proposed that infer general population statistics and target behavioral biometrics against a particular victim. We show that despite their success, these approaches require several attempts for successful attacks against different biometrics due to the different nature of overlap in users’ behavior for these biometrics. Furthermore, no mechanism has been proposed to date that detects statistical attacks. In this work, we propose a new hypervolumes-based statistical attack and show that unlike existing methods, it (1) is successful against a variety of biometrics, (2) is successful against more users, and (3) requires fewest attempts for successful attacks. More specifically, across five diverse biometrics, for the first attempt, on average our attack is 18 percentage points more successful than the second best (37% vs. 19%). Similarly, for the fifth attack attempt, on average our attack is 18 percentage points more successful than the second best (67% vs. 49%). We propose and evaluate a mechanism that can detect the more devastating statistical attacks. False rejects in biometric systems are common, and by distinguishing statistical attacks from false rejects, our defense improves usability and security. The evaluation of the proposed detection mechanism shows its ability to detect on average 94% of the tested statistical attacks with an average probability of 3% to detect false rejects as a statistical attack. Given the serious threat posed by statistical attacks to biometrics that are used today (e.g., voice), our work highlights the need for defending against these attacks. Sohail Habib, Hassan Khan 0002, Andrew Hamilton-Wright, Urs Hengartner |
ACM Trans. Priv. Secur. | 4 |
| 2021 | PUPy: A Generalized, Optimistic Context Detection Framework for Implicit AuthenticationabstractDevices like smartphones and laptops employ some form of user authentication to ensure that access to confidential data by the wrong user is avoided. Implicit authentication aims to limit the number of explicit authentications that a user is subjected to by using passive approaches to authenticate the user. Context detection frameworks aim to reduce explicit authentications by disabling explicit authentication entirely when appropriate. Since explicit and implicit authentication are not mutually exclusive, we can also use context detection frameworks to decide whether explicit or implicit authentication should be used when authentication is required. We present a novel context detection framework, PUPy, that uses sensed context data to infer and make available three values–privacy, unfamiliarity, and proximity–allowing clients of our framework, like authentication services, to better adapt to different contexts. As opposed to existing work, our context detection framework is based on an optimistic approach to context detection. Our assumption is that the absence of data, like the inability to detect nearby people or devices, can be taken as a sign that a context is safe. Such an optimistic approach may provide less security than a pessimistic approach, but provides a significantly improved user experience due to reducing the number of explicit authentications. We provide an Android implementation of the framework, including an API that allows other developers to contribute modules to the system. We also conduct a statistical analysis of our framework based on a large real-world dataset. We find that PUPy compares favourably to existing works, permitting a 77.2% reduction in the number of explicit authentications. Matthew Rafuse, Urs Hengartner |
PST | 2 |
| 2020 | Chaperone: Real-time Locking and Loss Prevention for Smartphones
Jiayi Chen 0001, Urs Hengartner, Hassan Khan 0002, Mohammad Mannan |
USENIX Security Symposium | 2 |
| 2020 | Mimicry Attacks on Smartphone Keystroke AuthenticationabstractKeystroke behaviour-based authentication employs the unique typing behaviour of users to authenticate them. Recent such proposals for virtual keyboards on smartphones employ diverse temporal, contact, and spatial features to achieve over 95% accuracy. Consequently, they have been suggested as a second line of defense with text-based password authentication. We show that a state-of-the-art keystroke behaviour-based authentication scheme is highly vulnerable against mimicry attacks. While previous research used training interfaces to attack physical keyboards, we show that this approach has limited effectiveness against virtual keyboards. This is mainly due to the large number of diverse features that the attacker needs to mimic for virtual keyboards. We address this challenge by developing an augmented reality-based app that resides on the attacker’s smartphone and leverages computer vision and keystroke data to provide real-time guidance during password entry on the victim’s phone. In addition, we propose an audiovisual attack in which the attacker overlays transparent film printed with spatial pointers on the victim’s device and uses audio cues to match the temporal behaviour of the victim. Both attacks require neither tampering or installing software on the victim’s device nor specialized hardware. We conduct experiments with 30 users to mount over 400 mimicry attacks. We show that our methods enable an attacker to mimic keystroke behaviour on virtual keyboards with little effort. We also demonstrate the extensibility of our augmented reality-based technique by successfully mounting mimicry attacks on a swiping behaviour-based continuous authentication system. Hassan Khan 0002, Urs Hengartner, Daniel Vogel 0001 |
ACM Trans. Priv. Secur. | 2 |
| 2019 | AppVeto: mobile application self-defense through resource access vetoabstractModern mobile operating systems such as Android and Apple iOS allow apps to access various system resources, with or without explicit user permission. Running multiple concurrent apps is also commonly supported, although the OS generally maintains strict separation between apps. However, an app can still get access to another app's private information, such as the user input, through numerous side-channels, mostly enabled by having access to permissioned or permission-less (sometimes even unrelated) resources, e.g., inferring keystroke and swipe gestures from a victim app via the accelerometer or gyroscope. Current mobile OSes do not empower an app to defend itself from such implicit interference from other apps; few exceptions exist such as blocking screenshot captures in Android. We propose a general mechanism for apps to defend themselves from any unwanted implicit or explicit interference from other concurrently running apps. Our AppVeto solution enables an app to easily configure its requirements for a safe environment; a foreground app can request the OS to disallow access---i.e., to enable veto powers---to selected side-channel-prone resources to all other running apps for a certain (short) duration, e.g., no access to the accelerometer during password input. In a sense, we enable a finer-grained access control policy than the current runtime permission model, and delegate the responsibility of the resource access decision (for vetoing) from users to app developers. We implement AppVeto on Android using the Xposed framework, without changing Android APIs. Furthermore, we show that AppVeto imposes negligible overhead, while being effective against several well-known side-channel attacks. Tousif Osman, Mohammad Mannan, Urs Hengartner, Amr M. Youssef |
ACSAC | 3 |
| 2018 | Evaluating Attack and Defense Strategies for Smartphone PIN Shoulder SurfingabstractWe evaluate the efficacy of shoulder surfing defenses for PIN-based authentication systems. We find tilting the device away from the observer, a widely adopted defense strategy, provides limited protection. We also evaluate a recently proposed defense incorporating an "invisible pressure component" into PIN entry. Contrary to earlier claims, our results show this provides little defense against malicious insider attacks. Observations during the study uncover successful attacker strategies for reconstructing a victim's PIN when faced with a tilt defense. Our evaluations identify common misconceptions regarding shoulder surfing defenses, and highlight the need to educate users on how to safeguard their credentials from these attacks. Hassan Khan 0002, Urs Hengartner, Daniel Vogel 0001 |
CHI | 2 |
| 2018 | Augmented Reality-based Mimicry Attacks on Behaviour-Based Smartphone AuthenticationabstractWe develop an augmented reality-based app that resides on the attacker's smartphone and leverages computer vision and raw input data to provide real-time mimicry attack guidance on the victim's phone. Our approach does not require tampering or installing software on the victim's device, or specialized hardware. The app is demonstrated by attacking keystroke dynamics, a method leveraging the unique typing behaviour of users to authenticate them on a smartphone, which was previously thought to be hard to mimic. In addition, we propose a low-tech AR-like audiovisual method based on spatial pointers on a transparent film and audio cues. We conduct experiments with 31 participants and mount over 400 attacks to show that our methods enable attackers to successfully bypass keystroke dynamics for 87% of the attacks after an average mimicry training of four minutes. Our AR-based method can be extended to attack other input behaviour-based biometrics. While the particular attack we describe is relatively narrow, it is a good example of using AR guidance to enable successful mimicry of user behaviour---an approach of increasing concern as AR functionality becomes more commonplace. Hassan Khan 0002, Urs Hengartner, Daniel Vogel 0001 |
MobiSys | 2 |
| 2016 | Targeted Mimicry Attacks on Touch Input Based Implicit Authentication SchemesabstractTouch input implicit authentication (``touch IA'') employs behavioural biometrics like touch location and pressure to continuously and transparently authenticate smartphone users. We provide the first ever evaluation of targeted mimicry attacks on touch IA and show that it fails against shoulder surfing and offline training attacks. Based on experiments with three diverse touch IA schemes and 256 unique attacker-victim pairs, we show that shoulder surfing attacks have a bypass success rate of 84% with the majority of successful attackers observing the victim's behaviour for less than two minutes. Therefore, the accepted assumption that shoulder surfing attacks on touch IA are infeasible due to the hidden nature of some features is incorrect. For offline training attacks, we created an open-source training app for attackers to train on their victims' touch data. With this training, attackers achieved bypass success rates of 86%, even with only partial knowledge of the underlying features used by the IA scheme. Previous work failed to find these severe vulnerabilities due to its focus on random, non-targeted attacks. Our work demonstrates the importance of considering targeted mimicry attacks to evaluate the security of an implicit authentication scheme. Based on our results, we conclude that touch IA is unsuitable from a security standpoint. Hassan Khan 0002, Urs Hengartner, Daniel Vogel 0001 |
MobiSys | 2 |
| 2016 | Ask Me Again But Don't Annoy Me: Evaluating Re-authentication Strategies for Smartphones
Lalit Agarwal, Hassan Khan 0002, Urs Hengartner |
SOUPS | 3 |
| 2016 | Shatter: Using Threshold Cryptography to Protect Single Users with Multiple DevicesabstractThe average computer user is no longer restricted to one device. They may have several devices and expect their applications to work on all of them. A challenge arises when these applications need the cryptographic private key of the devices' owner. Here the device owner typically has to manage keys manually with a "keychain" app, which leads to private keys being transferred insecurely between devices -- or even to other people. Even with intuitive synchronization mechanisms, theft and malware still pose a major risk to keys. Phones and watches are frequently removed or set down, and a single compromised device leads to the loss of the owner's private key, a catastrophic failure that can be quite difficult to recover from. Erinn Atwater, Urs Hengartner |
WISEC | 2 |
| 2016 | Special Issue on Security and Privacy in Mobile Clouds
Sherman S. M. Chow, Urs Hengartner, Joseph K. Liu, Kui Ren 0001 |
Pervasive Mob. Comput. | 2 |
| 2016 | On the Privacy Implications of Location SemanticsabstractAbstract Mobile users increasingly make use of location-based online services enabled by localization systems. Not only do they share their locations to obtain contextual services in return (e.g., ‘nearest restaurant’), but they also share, with their friends, information about the venues (e.g., the type, such as a restaurant or a cinema) they visit. This introduces an additional dimension to the threat to location privacy: location semantics, combined with location information, can be used to improve location inference by learning and exploiting patterns at the semantic level (e.g., people go to cinemas after going to restaurants). Conversely, the type of the venue a user visits can be inferred, which also threatens her semantic location privacy. In this paper, we formalize this problem and analyze the effect of venue-type information on location privacy. We introduce inference models that consider location semantics and semantic privacy-protection mechanisms and evaluate them by using datasets of semantic check-ins from Foursquare, totaling more than a thousand users in six large cities. Our experimental results show that there is a significant risk for users’ semantic location privacy and that semantic information improves inference of user locations. Berker Agir, Kévin Huguenin, Urs Hengartner, Jean-Pierre Hubaux |
Proc. Priv. Enhancing Technol. | 3 |
| 2015 | Leading Johnny to Water: Designing for Usability and Trust
Erinn Atwater, Cecylia Bocovich, Urs Hengartner, Ed Lank, Ian Goldberg 0001 |
SOUPS | 3 |
| 2015 | Usability and Security Perceptions of Implicit Authentication: Convenient, Secure, Sometimes Annoying
Hassan Khan 0002, Urs Hengartner, Daniel Vogel 0001 |
SOUPS | 2 |
| 2014 | POSTER: When and How to Implicitly Authenticate Smartphone UsersabstractPossession of modern smartphones is becoming increasingly ubiquitous, and with this rise in usage comes a rise in the amount of sensitive data being stored on them. Despite this, the high-frequency, low-duration nature of the average smartphone session makes passwords or PIN-locks even less usable than in the desktop context. To combat these issues, implicit authentication (IA) schemes can be developed and deployed to smartphones. IA schemes continuously authenticate users by profiling their behaviour using the variety of sensors prevalent on the phones, such as touchscreens and accelerometers. When a non-owner acquires the device and attempts to access sensitive data on it, the IA scheme recognizes the difference in behaviour and automatically ejects the attacker from the system. In particularly sensitive contexts, IA schemes can also be deployed as a secondary defence mechanism on top of explicit authentication, providing layered security in the event of, for example, a shoulder-surfing attack compromising the device's PIN or an operating system vulnerability allowing its bypass. In this work, we evaluate existing proposals for IA schemes using different behavioural feature sets, and evaluate them against real-world data to show when they are (and are not) useful. We have implemented them in an easily extensible open source framework for the Android operating system called Itus, which allows other researchers to iteratively improve on the existing mechanisms for performing IA. Itus performs IA at the app level, which we have shown allows app developers to selectively protect sensitive data while decreasing the impact on battery life and device performance, and at the same time obtaining better detection accuracy for the IA scheme being invoked. Aaron Atwater, Hassan Khan 0002, Urs Hengartner |
CCS | 3 |
| 2014 | pTwitterRec: a privacy-preserving personalized tweet recommendation frameworkabstractTwitter is one of the most popular Online Social Networks (OSNs) nowadays. Twitter users retrieve information from other users by subscribing to their tweets. Twitter users, especially those who have many followees, may receive hundreds or even thousands of tweets daily. Currently, all tweets are shown to users in chronological order. Consequently, a Twitter user may accidentally overlook useful and interesting tweets because the user is overwhelmed by the huge volume of uninteresting tweets. Researchers in the recommendation system community have proposed using recommendation techniques such as collaborative filtering to predict users' preference of tweets and highlight those tweets in which users are most likely to be interested. At the same time, while OSNs such as Twitter have enabled people to conveniently share information and interact with each other online, OSN users are getting increasingly concerned about their online privacy. Researchers in the security community have proposed using techniques such as encrypted tweets to protect users' privacy. In this paper, we propose a privacy-preserving personalized tweet recommendation framework, pTwitterRec, in a Twitter-like social network where users' tweets are hidden from the OSN provider. pTwitterRec provides users with personalized tweet recommendations while keeping users' tweets and interests hidden from the OSN provider as well as other unauthorized entities. pTwitterRec splits the tweet recommendation task between the provider and a semi-trusted third party, so that neither can derive users' sensitive information alone while working together to provide users with personalized tweet recommendations. We implement a prototype and demonstrate through evaluation that pTwitterRec incurs tolerable overhead on today's smartphones. Bisheng Liu, Urs Hengartner |
AsiaCCS | 2 |
| 2014 | Itus: an implicit authentication framework for androidabstractSecurity and usability issues with pass-locks on mobile devices have prompted researchers to develop implicit authentication (IA) schemes, which continuously and transparently authenticate users using behavioural biometrics. Contemporary IA schemes proposed by the research community are challenging to deploy, and there is a need for a framework that supports: different behavioural classifiers, given that different apps have different requirements; app developers using IA without becoming domain experts; and real-time classification on resource-constrained mobile devices. We present Itus, an IA framework for Android that allows the research community to improve IA schemes incrementally, while allowing app developers to adopt these improvements at their own pace. Hassan Khan 0002, Aaron Atwater, Urs Hengartner |
MobiCom | 3 |
| 2014 | TPC welcome welcome message from the technical program chairsabstractA warm welcome to the Twelfth Annual IEEE International Conference on Pervasive Computing and Communications (PerCom 2014). We are pleased to introduce the technical program of the conference which this year includes 25 papers representing high-quality research conducted over a broad spectrum of topics related to pervasive computing. George Roussos, Urs Hengartner, Shin'ichi Konomi, Kay Römer |
PerCom | 2 |
| 2014 | A Comparative Evaluation of Implicit Authentication Schemes
Hassan Khan 0002, Aaron Atwater, Urs Hengartner |
RAID | 3 |
| 2013 | Privacy-preserving social recommendations in geosocial networksabstractGeosocial networks like Foursquare have enabled people to conveniently share their whereabouts with their friends online, such as sharing check-ins at visited venues. This information could be utilized by recommender systems to improve the recommendation accuracy, known as social recommendations. However, incorporating social context into recommender systems introduces new privacy threats to users. We design a framework to achieve the benefits of social recommendations while preserving the privacy of social relations and considering the business interests of the service provider (SP). Namely, we propose that each user manages social relations locally and participates in computing social recommendations without revealing social relations to the SP and without the SP revealing proprietary information to a user. In addition, we identify three classes of inference attacks where the SP may infer the existence of social relations by monitoring users' individual check-in histories. Furthermore, we propose using private check-ins to defend against such attacks. Finally, we conduct a comprehensive performance evaluation over large-scale real-world datasets. The results suggest that the proposed privacy-preserving framework is feasible on a smart phone and only slightly affects the overall performance of recommender systems. Bisheng Liu, Urs Hengartner |
PST | 2 |
| 2011 | Privacy-preserving matchmaking For mobile social networking secure against malicious usersabstractThe success of online social networking and of mobile phone services has resulted in increased attention to mobile social networking. Matchmaking is a key component of mobile social networking. It notifies users of nearby people who fulfil some criteria, such as having shared interests, and who are therefore good candidates for being added to a user's social network. Unfortunately, the existing matchmaking approaches are troublesome from a privacy point of view. One approach has users' smartphones broadcast their owners' personal information to nearby devices. This approach reveals more personal information than necessary. The other approach requires a trusted server that participates in each matchmaking operation. Namely, the server knows the interests and current location of each user and performs matchmaking based on this information. This approach allows the server to track users. This paper proposes a privacy-preserving matchmaking protocol for mobile social networking that lets a potentially malicious user learn only the interests (or some other traits) that he has in common with a nearby user, but no other interests. In addition, the protocol is distributed and does not require a trusted server that can track users or that needs to be involved in each matchmaking operation. We present an implementation and evaluation of our protocol on Nexus One smartphones and demonstrate that the protocol is practical. Urs Hengartner |
PST | 2 |
| 2010 | VeriPlace: a privacy-aware location proof architectureabstractRecently, there has been a dramatic increase in the number of location-based services, with services like Foursquare or Yelp having hundreds of thousands of users. A user's location is a crucial factor for enabling these services. Many services rely on users to correctly report their location. However, if there is an incentive, users might lie about their location. A location proof architecture enables users to collect proofs for being at a location and services to validate these proofs. It is essential that this proof collection and validation does not violate user privacy. We introduce VeriPlace, a location proof architecture with user privacy as a key design component. In addition, VeriPlace can detect cheating users who collect proofs for places where they are not located. We also present an implementation and a performance evaluation of VeriPlace and its integration with Yelp. Wanying Luo, Urs Hengartner |
GIS | 2 |
| 2010 | Achieving Efficient Query Privacy for Location Based Services
Femi G. Olumofin, Piotr K. Tysowski, Ian Goldberg 0001, Urs Hengartner |
Privacy Enhancing Technologies | 4 |
| 2009 | A Distributed k-Anonymity Protocol for Location PrivacyabstractTo benefit from a location-based service, a person must reveal her location to the service. However, knowing the person's location might allow the service to re-identify the person. Location privacy based on k-anonymity addresses this threat by cloaking the person's location such that there are at least k - 1 other people within the cloaked area and by revealing only the cloaked area to a location-based service. Previous research has explored two ways of cloaking: First, have a central server that knows everybody's location determine the cloaked area. However, this server needs to be trusted by all users and is a single point of failure. Second, have users jointly determine the cloaked area. However, this approach requires that all users trust each other, which will likely not hold in practice. We propose a distributed approach that does not have these drawbacks. Our approach assumes that there are multiple servers, each deployed by a different organization. A user's location is known to only one of the servers (e.g., to her cellphone provider), so there is no single entity that knows everybody's location. With the help of cryptography, the servers and a user jointly determine whether the k-anonymity property holds for the user's area, without the servers learning any additional information, not even whether the property holds. A user learns whether the k-anonymity property is satisfied and no other information. The evaluation of our sample implementation shows that our distributed k-anonymity protocol is sufficiently fast to be practical. Moreover, our protocol integrates well with existing infrastructures for location-based services, as opposed to the previous research. Ge Zhong, Urs Hengartner |
PerCom | 2 |
| 2008 | Location privacy based on trusted computing and secure loggingabstractMany operators of cellphone networks now offer location-based services to their customers, whereby an operator often outsources service provisioning to a third-party provider. Since a person's location could reveal sensitive information about the person, the operator must ensure that the service provider processes location information about the operator's customers in a privacy-preserving way. So far, this assurance has been based on a legal contract between the operator and the provider. However, there has been no technical mechanism that lets the operator verify whether the provider adheres to the privacy policy outlined in the contract. We propose an architecture for location-based services based on Trusted Computing and Secure Logging that provides such a technical mechanism. Trusted Computing lets an operator query the configuration of a location-based service. The operator will hand over location information to the service only if the service is configured such that the service provider cannot get access to location information using software-based attacks. This includes passive attacks, where the provider monitors information flowing into and out of its service, and active attacks, where the provider modifies or injects customer queries to the service. We introduce several requirements that must be satisfied by a location-based service to defend against passive attacks. Furthermore, we present Secure Logging, an auditing mechanism to defend against active attacks. Urs Hengartner |
SecureComm | 1 |
| 2008 | Panic Passwords: Authenticating under Duress
Jeremy Clark, Urs Hengartner |
HotSec | 2 |
| 2007 | Hiding Location Information from Location-Based ServicesabstractIn many existing location-based services, a service provider becomes aware of the location of its customers and can, maybe inadvertently, leak this information to unauthorized entities. To avoid this information leak, the provider should be able to offer its services such that the provider does not learn any information about its customers' location. We present an architecture that provides this property and show that the architecture is powerful enough to support existing location- based services. Our architecture exploits trusted computing and private information retrieval. With the help of trusted computing, we ensure that a location-based service operates as expected by a customer and that information about the customer's location becomes inaccessible to a location-based service upon a compromise of the service. With the help of private information retrieval, we avoid that a service provider learns a customer's location by observing which of its location-specific information is being accessed. Urs Hengartner |
MDM | 1 |
| 2007 | Louis, Lester and Pierre: Three Protocols for Location Privacy
Ge Zhong, Ian Goldberg 0001, Urs Hengartner |
Privacy Enhancing Technologies | 3 |
| 2006 | Avoiding Privacy Violations Caused by Context-Sensitive ServicesabstractThe increasing availability of information about people's context makes it possible to deploy context-sensitive services, where access to resources provided or managed by a service is limited depending on a person's context. For example, a location-based service can require an individual to be at a particular location in order to let the individual use a printer or learn her friends' location. However, constraining access to a resource based on confidential information about a person's context could result in privacy violations. For instance, if access is constrained based on a person's location, granting or rejecting access will provide information about this person's location and could violate the person's privacy. We introduce an access-control algorithm that avoids privacy violations caused by context-sensitive services. Our algorithm exploits the concepts of access-rights graphs, which represent all the information that needs to be collected in order to make a context-sensitive access decision. Moreover, we introduce hidden constraints, which keep some of this information secret and thus allow for more flexible access control. We present a distributed, certificate-based access-control architecture for context-sensitive services that avoids privacy violations, a sample implementation, and a performance evaluation Urs Hengartner, Peter Steenkiste |
PerCom | 1 |
| 2006 | Exploiting information relationships for access control in pervasive computing
Urs Hengartner, Peter Steenkiste |
Pervasive Mob. Comput. | 1 |
| 2006 | Avoiding privacy violations caused by context-sensitive services
Urs Hengartner, Peter Steenkiste |
Pervasive Mob. Comput. | 1 |
| 2005 | Exploiting Information Relationships for Access ControlabstractPervasive computing environments offer a multitude of information services that provide potentially complex types of information. Therefore, when running access control for sensitive information, these environments need to take relationships between information into account. Other approaches to relationship-aware access control (e.g., based on semantic Web rule engines) are often expensive and based on a centralized design. In this paper, we identify three types of information relationships (bundling-based, combination-based, and granularity-based) that are common and important in pervasive computing, and we integrate support for them in distributed, certificate-based access control architecture. In our approach, access control is fully distributed while sophisticated rule engines can still be used to deal with more complex access control cases. To demonstrate the feasibility of our design, we give a complexity analysis of the architecture and a performance analysis of a prototype implementation Urs Hengartner, Peter Steenkiste |
PerCom | 1 |
| 2005 | Exploiting Hierarchical Identity-Based Encryption for Access Control to Pervasive Computing InformationabstractAccess control to confidential information in pervasive computing environments is challenging for multiple reasons: First, a client requesting access might not know which access rights are necessary in order to be granted access to the requested information. Second, access control must support flexible access rights that include context-sensitive constraints. Third, pervasive computing environments consist of a multitude of information services, which makes simple management of access rights essential. We discuss the shortcomings of existing access-control schemes that rely on either clients presenting a proof of access to a service or services encrypting information before handing the information over to a client. We propose a proofbased access-control architecture that employs hierarchical identity-based encryption in order to enable services to inform clients of the required proof of access in a covert way, without leaking information. Furthermore, we introduce an encryption-based access-control architecture that exploits hierarchical identity-based encryption in order to deal with multiple, hierarchical constraints on access rights. We present an example implementation of our proposed architectures and discuss the performance of this implementation. Urs Hengartner, Peter Steenkiste |
SecureComm | 1 |
| 2005 | Access control to people location informationabstractUbiquitous computing uses a variety of information for which access needs to be controlled. For instance, a person's current location is a sensitive piece of information that only authorized entities should be able to learn. Several challenges arise in the specification and implementation of policies controlling access to location information. For example, there can be multiple sources of location information. The sources can be within different administrative domains, which might allow different entities to specify policies, and policies need to be flexible. We address these issues in our design of a distributed access control mechanism for a people location system. Our design encodes policies as digital certificates, which enables decentralized storage of policies. We also present an algorithm for the discovery of distributed certificates. Furthermore, we discuss several privacy issues and show how our design addresses them. To show feasibility of our design, we built an example implementation based on SPKI/SDSI certificates. Using measurements, we quantify the influence of access control on query processing time. We also discuss trade-offs between RSA-based and DSA-based signature schemes for digital certificates. Urs Hengartner, Peter Steenkiste |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2004 | Implementing access control to people location informationabstractUbiquitous computing uses a variety of information for which access needs to be controlled. For instance, a person's current location is a sensitive piece of information, which only authorized entities should be able to learn. Several challenges arise in the specification and implementation of policies controlling access to location information. For example, there can be multiple sources of location information, the sources can be within different administrative domains, different administrative domains might allow different entities to specify policies, and policies need to be flexible. We address these issues in our design of an access control mechanism for a people location system. Our design encodes policies as digital certificates. We present an example implementation based on SPKI/SDSI certificates. Using measurements, we quantify the influence of access control on query processing time. We also discuss trade-offs between RSA-based and DSA-based signature schemes for digital certificates. Urs Hengartner, Peter Steenkiste |
SACMAT | 1 |
| 2003 | Access Control to Information in Pervasive Computing Environments
Urs Hengartner, Peter Steenkiste |
HotOS | 1 |
| 2002 | Detection and analysis of routing loops in packet tracesabstractRouting loops are caused by inconsistencies in routing state among a set of routers. They occur in perfectly engineered networks, and have a detrimental effect on performance. They impact end-to-end performance through increased packet loss and delay for packets caught in the loop, and through increased link utilization and corresponding delay and jitter for packets that traverse the link but are not caught in the loop.Using packet traces from a tier-1 ISP backbone, we first explain how routing loops manifest in packet traces. We characterize routing loops in terms of the packet types caught in the loop, the loop sizes, and the loop durations. Finally, we analyze the impact of routing loops on network performance in terms of loss and delay. Urs Hengartner, Sue B. Moon, Richard Mortier, Christophe Diot |
Internet Measurement Workshop | 1 |
| 2001 | A Secure, Publisher-Centric Web Caching InfrastructureabstractThe current Web caching infrastructure, though it has a number of performance benefits for clients and network providers, does not meet publishers' requirements. We argue that to satisfy these requirements, caches should be enhanced in both the data and control planes. In the data plane, caches will dynamically generate content for clients by running code provided by publishers. In the control plane, caches will return logs of client accesses to publishers. In this paper, we introduce Gemini, a system which has both of these capabilities, and discuss two of its key components: security and incremental deployment. Since Gemini caches are deeply involved in content preparation and logging, ensuring that they perform correctly is vital. Traditional end-to-end security mechanisms are not sufficient to protect clients and publishers, so we introduce a new security model which consists of two pieces: an authorization mechanism and a verification mechanism. The former allows a publisher to authorize a set of caches to run its code and serve its content, while the latter allows clients and publishers to probabilistically verify that authorized caches are operating correctly. Because it is unrealistic to assume that Gemini caches will be deployed everywhere simultaneously, we have designed the system to be incrementally deployable and to coexist with legacy clients, caches, and servers. Finally, we describe our implementation of Gemini and present preliminary performance results. Andy Myers, John C.-I. Chuang, Urs Hengartner, Yinglian Xie, Weiqiang Zhuang, Hui Zhang 0001 |
INFOCOM | 3 |
| 2000 | TCP Vegas RevisitedabstractThe innovative techniques of TCP Vegas have been the subject of much debate in recent years. Several studies have reported that TCP Vegas provides better performance than TCP Reno. However, the question of which of the new techniques are responsible for the impressive performance gains remains unanswered so far. This paper presents a detailed performance evaluation of TCP Vegas. By decomposing TCP Vegas into the various novel mechanisms proposed and assessing the effect of each of these mechanisms on performance, we show that the reported performance gains are achieved primarily by TCP Vegas's new techniques for slow start and congestion recovery. TCP Vegas's innovative congestion avoidance mechanism is shown to have only a minor influence on throughput. Furthermore, we find that the congestion avoidance mechanism exhibits fairness problems even if all competing connections operate with the same round trip time. Urs Hengartner, Jürg Bolliger, Thomas R. Gross |
INFOCOM | 1 |
| 1999 | Bandwidth Modeling for Network-Aware ApplicationsabstractNetwork-aware applications attempt to adjust their resource demands in response to changes in resource availability. E.g., if a server maintains a connection to a client, the server may want to adjust the amount of data sent to the client based on the effective bandwidth realized for the connection. Information about current and future network performance is therefore crucial for an adaptive application. This paper discusses three aspects of the coupling of applications and networks: (1) a network-aware application needs timely information about the status of the network; (2) a simple bandwidth estimation technique performs reasonably well for TCP-Reno connections without timeouts; (3) enhancements proposed to TCP-Reno to reduce the number of timeouts (i.e., SACKs and its variants) increase the bandwidth but also improve the accuracy of bandwidth estimators developed by other researchers. The empirical observations reported in this paper are based on an in-vivo experiment in the Internet. Over a 6-month period, we logged the micro dynamics of random connections between a set of selected hosts. These results are encouraging for the developer of a network-aware application since they provide evidence that a simple widening of the interface between applications and network (protocol) may provide the information that allows an application to successfully adapt to changes in resource availability. Jürg Bolliger, Thomas R. Gross, Urs Hengartner |
INFOCOM | 3 |