Murtuza Jadliwala

dblp:09/5967 · DBLP profile ↗
← Back
50ranked-venue papers
7as first author
24since 2021 · last 2026
0000-0001-9316-1943ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 30 · 5 first-author · 16 since 2021Computer networks · 7 · 2 first-author · 2 since 2021Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 OverHear: Headphone Based Multi-Sensor Keystroke Inference
Raveen Wijewickrama, Maryam Abbasihafshejani, Anindya Maiti, Murtuza Jadliwala
ACNS (3)4
2026 Optimus: A Robust Defense Framework for Mitigating Toxicity while Fine-Tuning Conversational AI
abstract
Customizing Large Language Models (LLMs) on untrusted datasets poses severe risks of injecting toxic behaviors. In this work, we introduce Optimus, a novel defense framework designed to mitigate fine-tuning harms while preserving conversational utility. Unlike existing defenses that rely heavily on precise toxicity detection or restrictive filtering, Optimus addresses the critical challenge of ensuring robust mitigation even when toxicity classifiers are imperfect or biased. Optimus integrates a training-free toxicity classification scheme that repurposes the safety alignment of commodity LLMs, and employs a dual-strategy alignment process combining synthetic ''healing data'' with Direct Preference Optimization (DPO) to efficiently steer models toward safety. Extensive evaluations demonstrate that Optimus mitigates toxicity even when relying on extremely biased classifiers (with up to 85% degradation in Recall). Optimus outperforms the state-of-the-art defense StarDSS and exhibits strong resilience against adaptive adversarial and jailbreak attacks. Our source code and datasets are available at https://github.com/secml-lab-vt/Optimus
Aravind Cheruvu, Shravya Kanchi, Sifat Muhammad Abdullah, Nicholas Ka-Shing Kong, Danfeng Yao, Murtuza Jadliwala, Bimal Viswanath
CODASPY6
2026 ADVISE: Adversarial Invisible Steganography for Event-data
Aaditya Arunkumar Khant, Raveen Wijewickrama, Murtuza Jadliwala
EuroS&P3
2026 Prompt and Circumstances: Evaluating the Efficacy of Human Prompt Inference in AI-Generated Art
Khoi Trinh, Scott Seidenberger, Joseph Spracklen, Raveen Wijewickrama, Bimal Viswanath, Murtuza Jadliwala, Anindya Maiti
EvoMUSART6
2026 Linguistic Hooks: Investigating The Role of Language Triggers in Phishing Emails Targeting African Refugees and Students
abstract
Phishing and sophisticated email-based social engineering attacks disproportionately affect vulnerable populations, such as refugees and immigrant students. However, these groups remain understudied in cybersecurity research. This gap in understanding, coupled with their exclusion from broader security and privacy policies, increases their susceptibility to phishing and widens the digital security divide between marginalized and non-marginalized populations. To address this gap, we first conducted digital literacy workshops with newly resettled African refugee populations (n = 48) in the US to improve their understanding of how to safeguard sensitive and private information. Following the workshops, we conducted a real-world phishing deception study using carefully designed emails with linguistic cues for three participant groups: a subset of the African US-refugees recruited from the digital literacy workshops (n = 19), African immigrant students in the US (n = 142), and a control group of monolingual US-born students (n = 184). Our findings indicate that while digital literacy training for refugees improves awareness of safe cybersecurity practices, recently resettled African US-refugees still face significant challenges due to low digital literacy skills and limited English proficiency. This often leads them to ignore or fail to recognize phishing emails as phishing. Both African immigrant students and US-born students showed greater caution, though instances of data disclosure remained prevalent across groups. Our findings highlight, irrespective of literacy, the need to be trained to think critically about digital security. We conclude by discussing how the security and privacy community can better include marginalized populations in policy making and offer recommendations for designing equitable, inclusive cybersecurity initiatives.
Mythili Menon, Nisha Vinayaga-Sureshkanth, Alec Schon, Kaitlyn S. Hemberger, Murtuza Jadliwala
Proc. Priv. Enhancing Technol.5
2025 A Picture is Worth a Thousand Prompts? Efficacy of Iterative Human-Driven Prompt Refinement in Image Regeneration Tasks
abstract
With AI-generated content becoming widespread across digital platforms, it is important to understand how such content is inspired and produced. This study explores the underexamined task of image regeneration, where a human operator iteratively refines prompts to recreate a specific target image. Unlike typical image generation, regeneration begins with a visual reference. A key challenge is whether existing image similarity metrics (ISMs) align with human judgments and can serve as useful feedback in this process. We conduct a structured user study to evaluate how iterative prompt refinement affects similarity to target images and whether ISMs reflect the improvements perceived by human observers. Our results show that prompt adjustments significantly improve alignment, both subjectively and quantitatively, highlighting the potential of iterative workflows in enhancing generative image quality.
Khoi Trinh, Scott Seidenberger, Raveen Wijewickrama, Murtuza Jadliwala, Anindya Maiti
IJCAI4
2025 VoiceRadar: Voice Deepfake Detection using Micro-Frequency and Compositional Analysis
Kavita Kumari, Maryam Abbasihafshejani, Alessandro Pegoraro, Phillip Rieger, Kamyar Arshi, Murtuza Jadliwala, Ahmad-Reza Sadeghi
NDSS6
2025 Spiking Neural Networks in Vertical Federated Learning: Performance Trade-Offs
abstract
Federated machine learning enables model training across multiple participants while preserving data privacy. Vertical Federated Learning (VFL) handles scenarios in which participants have different feature sets for the same samples. Although Spiking Neural Networks (SNNs) offer efficiency advantages over Artificial Neural Networks (ANNs), their applicability in a VFL scenario remains unexplored. This paper examines SNNs in VFL, implementing and evaluating two architectures-with and without model splitting- using CIFAR-10 and CIFAR-100 datasets with VGG9 and ResNet models. The evaluation results show that SNNs achieve an accuracy comparable to that of ANNs in VFL while being significantly more energy efficient.
Maryam Abbasihafshejani, Anindya Maiti, Murtuza Jadliwala
NOMS3
2025 LightShed: Defeating Perturbation-based Image Copyright Protections
Hanna Foerster, Sasha Behrouzi, Phillip Rieger, Murtuza Jadliwala, Ahmad-Reza Sadeghi
USENIX Security Symposium4
2025 We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
Joseph Spracklen, Raveen Wijewickrama, A. H. M. Nazmus Sakib, Anindya Maiti, Bimal Viswanath, Murtuza Jadliwala
USENIX Security Symposium6
2025 ScooterID: Posture-Based Continuous User Identification From Mobility Scooter Rides
abstract
Mobility scooters serve as a powerful last-mile transportation tool for people with mobility challenges. Given the unique riding behavior and posture of mobility scooter riders, such user-specific mobility scooter ride data has tremendous potential towards the design of continuous user identification and authentication mechanisms. However, there have been no prior research efforts in the literature exploring this unique modality for the design of continuous user identification techniques. To address this gap, this paper proposesScooterID, the first framework which employs rider posture data collected from cameras on mobility scooters to continuously identify (and authenticate) users/riders. As part of this framework, a machine learning based model comprising of a spatio-temporal Graph Convolutional Network and a body-part-informed encoder is designed to effectively capture a user’s subtle upper-body movements during mobility scooter rides into discriminating embedding vectors. These embeddings can then be used to reliably and continuously identify and authenticate users/riders. Experiments with real-world mobility scooter ride data show thatScooterIDachieves high levels of authentication accuracy with few enrollment video samples.ScooterIDalso performs efficiently on resource-constrained devices (e.g., Raspberry Pis) and is robust against adversarial perturbations to authentication inputs.
Devan Shah, Ruoqi Huang, Nisha Vinayaga-Sureshkanth, Tingting Chen 0001, Murtuza Jadliwala
IEEE Trans. Mob. Comput.5
2024 Rider Posture-Based Continuous Authentication with Few-Shot Learning for Mobility Scooters (Student Abstract)
abstract
Current practice of mobility scooter user authentication using physical keys and traditional password-based one-time security mechanisms cannot meet the needs of many mobility scooter riders, especially senior citizens having issues in recalling memory. Now seamless authentication approaches are needed to provide ongoing protection for mobility scooters against takeovers and unauthorized access. Existing continuous authentication techniques do not work well in a mobility scooter setting due to issues such as user comfort, deployment cost and enrollment time, among others. In that direction, our contributions in this research effort are two-fold: (i) we propose a novel system that incorporates advances in few-shot learning, hierarchical processing, and contextual embedding to establish continuous authentication for mobility scooter riders using only posture data. This security system, trained on data collected from real mobility scooter riders, demonstrates quick enrollment and easy deployability, while successfully serving as an unobtrusive first layer of security. (ii) we provide to the research community the largest publicly available repository of mobility scooter riders' body key-points data to enable further research in this direction.
Devan Shah, Ruoqi Huang, Tingting Chen 0001, Murtuza Jadliwala
AAAI4
2024 MirageFlow: A New Bandwidth Inflation Attack on Tor
Christoph Sendner, Jasper Stang, Alexandra Dmitrienko, Raveen Wijewickrama, Murtuza Jadliwala
NDSS5
2024 An Analysis of Recent Advances in Deepfake Image Detection in an Evolving Threat Landscape
abstract
Deepfake or synthetic images produced using deep generative models pose serious risks to online platforms. This has triggered several research efforts to accurately detect deepfake images, achieving excellent performance on publicly available deepfake datasets. In this work, we study 8 state-of-the-art detectors and argue that they are far from being ready for deployment due to two recent developments. First, the emergence of lightweight methods to customize large generative models, can enable an attacker to create many customized generators (to create deepfakes), thereby substantially increasing the threat surface. We show that existing defenses fail to generalize well to such user-customized generative models that are publicly available today. We discuss new machine learning approaches based on content-agnostic features, and ensemble modeling to improve generalization performance against user-customized models. Second, the emergence of vision foundation models—machine learning models trained on broad data that can be easily adapted to several downstream tasks—can be misused by attackers to craft adversarial deepfakes that can evade existing defenses. We propose a simple adversarial attack that leverages existing foundation models to craft adversarial samples without adding any adversarial noise, through careful semantic manipulation of the image content. We highlight the vulnerabilities of several defenses against our attack, and explore directions leveraging advanced foundation models and adversarial training to defend against this new threat.
Sifat Muhammad Abdullah, Aravind Cheruvu, Shravya Kanchi, Taejoong Chung, Peng Gao 0008, Murtuza Jadliwala, Bimal Viswanath
SP6
2024 De-anonymizing VR Avatars using Non-VR Motion Side-channels
abstract
Virtual Reality (VR) technology offers an immersive audio-visual experience to users through which they can interact with a digitally represented 3D space (i.e., a virtual world) using a headset device. By (visually) transporting users from their physical world to realistic virtual spaces, VR systems enable interactive and true-to-life versions of traditional applications such as gaming, remote conferencing and virtual tourism. However, VR applications also present significant user-privacy challenges. This paper studies a new type of privacy threat targeting VR users which attempts to connect their activities visible in the virtual world to their physical state sensed in the real world. Specifically, this paper analyzes the feasibility of carrying out a de-anonymization or identification attack on VR users by correlating visually observed movements of users' avatars in the virtual world with some auxiliary data (e.g., motion sensor data from mobile/wearable devices) representing their context/state in the physical world. To enable this attack, the paper proposes a novel framework which first employs a learning-based activity classification approach to translate the disparate visual movement data and motion sensor data into an activity-vector to ease comparison, followed by a filtering and identity ranking phase outputting an ordered list of potential identities corresponding to the target visual movement data. A comprehensive empirical evaluation of the proposed framework is conducted to study the feasibility of such a de-anonymization attack.
Mohd Sabra, Nisha Vinayaga-Sureshkanth, Ari Sharma, Anindya Maiti, Murtuza Jadliwala
WISEC5
2023 BayBFed: Bayesian Backdoor Defense for Federated Learning
abstract
Federated learning (FL) is an emerging technology that allows participants to jointly train a machine learning model without sharing their private data with others. However, FL is vulnerable to poisoning attacks such as backdoor attacks. Consequently, a variety of defenses have recently been proposed, which have primarily utilized intermediary states of the global model (i.e., logits) or distance of the local models (i.e., L2−norm) with respect to the global model to detect malicious backdoors in FL. However, as these approaches directly operate on client updates (or weights), their effectiveness depends on factors such as clients’ data distribution or the adversary’s attack strategies. In this paper, we introduce a novel and more generic backdoor defense framework, called BayBFed, which proposes to utilize probability distributions over client updates to detect malicious updates in FL: BayBFed computes a probabilistic measure over the clients’ updates to keep track of any adjustments made in the updates, and uses a novel detection algorithm that can leverage this probabilistic measure to efficiently detect and filter out malicious updates. Thus, it overcomes the shortcomings of previous approaches that arise due to the direct usage of client updates; nevertheless, our probabilistic measure will include all aspects of the local client training strategies. BayBFed utilizes two Bayesian NonParametric (BNP) extensions: (i) a Hierarchical Beta-Bernoulli process to draw a probabilistic measure given the clients’ updates, and (ii) an adaptation of the Chinese Restaurant Process (CRP), referred by us as CRP-Jensen, which leverages this probabilistic measure to detect and filter out malicious updates. We extensively evaluate our defense approach on five benchmark datasets: CIFAR10, Reddit, IoT intrusion detection, MNIST, and FMNIST, and show that it can effectively detect and eliminate malicious updates in FL without deteriorating the benign performance of the global model.
Kavita Kumari, Phillip Rieger, Hossein Fereidooni, Murtuza Jadliwala, Ahmad-Reza Sadeghi
SP4
2023 Feasibility Analysis for Sybil Attacks in Shard-Based Permissionless Blockchains
abstract
Committee-based permissionless blockchain approaches overcome single leader consensus protocols’ scalability issues by partitioning the outstanding transaction set into shards and selecting multiple committees to process these transactions in parallel. However, by design, shard-based blockchain solutions are vulnerable to Sybil attacks. An adversary with enough computational/hash power can easily manipulate the consensus protocol by generating multiple valid node identifiers/IDs (i.e., multiple Sybil committee members).Despite the straightforward nature of these attacks, they have not been systematically investigated. This article fills this research gap by analyzing Sybil attacks in shard-based consensus of proof-of-work blockchain systems. Specifically, we provide a detailed analysis for Elastico, one of the prominent shard-based blockchain models. We show that the proof-of-work technique used for ID generation in the initial phase of such protocols is vulnerable to Sybil attacks when an adversary (could be a group of colluding nodes) possesses enough hash power. We analytically derive conditions for two different Sybil attacks and perform numerical simulations to validate our theoretical results under various parameters. Further, we utilize the BlockSim simulator to validate our mathematical computation, and results confirm the correctness of the analysis.
Tayebeh Rajab, Alvi Ataur Khalil, Mohammad Hossein Manshaei, Mohammad Ashiqur Rahman, Mohammad Dakhilalian, Maurice Ngouen, Murtuza Jadliwala, A. Selcuk Uluagac
Distributed Ledger Technol. Res. Pract.7
2022 Background Buster: Peeking through Virtual Backgrounds in Online Video Calls
abstract
Video calling applications such as Zoom and Skype have become the preferred medium for both personal and professional communications. One feature in these applications that has gained prominence is the virtual background feature, which enables users to conceal their background by blending in a virtual image or video in place of the real background, thus providing users with background and contextual privacy. However, this feature is not robust enough, and depending on the target user’s activities, movement and accessories worn during the call, portions of the user’s background could leak which can then be reconstructed to reveal significant portions of the user’s real background, and other contextual information related to the real background. This paper conducts an investigative analysis of the background privacy provided by the virtual background feature in video calling applications by designing a novel background reconstruction framework, and using it to reveal users’ real background. By means a large dataset of call videos, collected from human subject participants and in the wild, a comprehensive evaluation of the proposed framework and related privacy attacks under a variety of different experimental parameters is then carried out. Results from these evaluations show that significant leakage of background information is feasible under certain conditions, rendering the feature ineffective in protecting privacy and giving users a false sense of security.
Mohd Sabra, Anindya Maiti, Murtuza Jadliwala
DSN3
2022 On Algorand Transaction Fees: Challenges and Mechanism Design
abstract
Algorand is a public proof-of-stake (PoS) blockchain with a throughput of 750 MB of transactions per hour, 125 times more than Bitcoin. While the throughput of Algorand depends on the participation of most of its nodes, rational nodes may behave selfishly and not cooperate with others. To encourage nodes to participate in the consensus protocol, Algorand rewards nodes in each round. However, currently Algorand does not pay transaction fees to participating nodes, rather storing it for future use. In this paper, we show that this current approach of Algorand motivates selfish block proposers to increase their profits by creating empty blocks. Such selfish behavior reduces the throughput of Algorand. Therefore, the price of Algo will decrease in the long run. Because of this price reduction, nodes will leave Algorand, compromising its security. Moreover, lack of an appropriate mechanism to pay fees to participants causes additional issues, such as lack of transparency, centralization, and inability of nodes to prioritize transactions. To overcome this challenge, we design a perfectly competitive market and propose an algorithm for computing optimal transaction fees and block size in Algorand We also propose an algorithm that reduces the cost of Algorand, without compromising its security. We further simulate the Algorand network and show how the optimal transaction fee and block size can be calculated in practice.
Maryam Abbasi, Mohammad Hossein Manshaei, Mohammad Ashiqur Rahman, Kemal Akkaya, Murtuza Jadliwala
ICC5
2022 An Investigative Study on the Privacy Implications of Mobile E-scooter Rental Apps
abstract
E-scooter rental services have significantly expanded the micromobility paradigm of short-distance urban and suburban transportation since their inception in 2017. Service providers around the world have followed a common rental model wherein customers (i.e., riders or users) download and install a mobile application for locating (finding) and renting e-scooters. Unlike many other app categories, e-scooter rental apps require a set of privacy-sensitive user data as a functional requirement. Unfortunately, privacy-related questions such as how much user data is being collected by these apps, is user data being safely handled once acquired, and with whom the collected user data is being shared are not readily known to customers. Answering such questions can be critical for users in determining which e-scooter rental services are sufficiently trustworthy per their personal privacy preferences. In this paper, we conduct a comprehensive analysis of e-scooter rental apps to answer these and other research questions related to user data collection, third-party involvement, usefulness of privacy policies, and evolution of user data management by different e-scooter apps/services over time. Our findings will create awareness among consumers vis-à-vis the data they share with service providers in return for the received e-scooter rental service, and it can also evoke more accountability and transparency from service providers towards their efforts and processes on protecting consumer privacy.
Nisha Vinayaga-Sureshkanth, Raveen Wijewickrama, Anindya Maiti, Murtuza Jadliwala
WISEC4
2021 Zoom on the Keystrokes: Exploiting Video Calls for Keystroke Inference Attacks
Mohd Sabra, Anindya Maiti, Murtuza Jadliwala
NDSS3
2021 Acoustics to the Rescue: Physical Key Inference Attack Revisited
Soundarya Ramesh, Rui Xiao 0002, Anindya Maiti, Jong Taek Lee, Harini Ramprasad, Ananda Kumar, Murtuza Jadliwala, Jun Han 0001
USENIX Security Symposium7
2021 Write to know: on the feasibility of wrist motion based user-authentication from handwriting
abstract
The popularity of smart wrist wearable technology (e.g., smart-watches) has rejuvenated the exploration of dynamic biometric-based authentication techniques that employ sensor data from these devices. Despite the progress demonstrated by the scientific community, research in this area has not successfully transitioned to practice, and we are yet to see a mainstream user-authentication product based on a dynamic biometric such as handwriting/hand gestures captured using commercial wrist wearables. This work undertakes an investigative analysis to further explore why that is the case. We accomplish this by studying the feasibility and practical deployability of handwriting-based authentication techniques in the literature that utilize motion sensors on-board wrist wearables. We conduct this analysis by replicating four state-of-the-art and representative handwriting-based authentication schemes that employ wrist motion data, in order to test their viability in realistic hand-writing/gesture scenarios. By using data collected from actual human subjects in an unconstrained fashion, we comparatively evaluate the performance of these schemes with well-defined usability and security metrics. Our experimental results show that some of the tested schemes perform considerably well in practice, and are promising. However, they do suffer from several practical user-dependent and technique-specific challenges that act as roadblocks towards their wide-scale adoption in mainstream applications.
Raveen Wijewickrama, Anindya Maiti, Murtuza Jadliwala
WISEC3
2021 TangleCV: A Distributed Ledger Technique for Secure Message Sharing in Connected Vehicles
abstract
Connected vehicles are set to define the future of transportation; however, this upcoming technology continues to be plagued with serious security risks. If these risks are not addressed in a timely fashion, then they could threaten the adoption and success of this promising technology. This article deals with a specific class of attacks in connected vehicles, namely tampering attacks caused due to compromise of on-board sensors. Current centralized solutions that employ trusted infrastructure to protect against adversarial manipulation of information cannot validate the correctness of the shared data and do not scale well. To overcome these issues, decentralized protection mechanisms by means of blockchain technology have emerged as a promising research direction. However, current permission-less, linear blockchain-based solutions have low transaction performance and high computational cost, thereby making it difficult to adopt them for security in connected vehicles. In this article, we present TangleCV, a directed acyclic graph–based distributed ledger technique for connected vehicles to address data tampering threats in connected vehicular networks. We describe new validation steps, tip selection strategies, and cumulative weight definition for TangleCV that not only meets the timing constraints of the connected vehicular networks but also secures the network against threats due to tampering attacks. We describe how the reputation of the network is established in TangleCV using trust factors calculated on the basis of ability, integrity, and benevolence of the nodes in the network. We present numerical results that demonstrate that the average value of the time to first approval decreases by more than 70% as the network evolves from a low load to a high load in the case of the nearest neighbor strategy. We observe that more than 60% of the nodes are approved in a low-load network and this number increases to 80% in a high-load network for the nearest neighbor strategy. The standard deviation of error measurements for nodes experiencing tampering attack is around 60% higher as compared to nodes that do not experience such an attack.
Heena Rathore, Abhay Samant, Murtuza Jadliwala
ACM Trans. Cyber Phys. Syst.3
2020 On Incentive Compatible Role-Based Reward Distribution in Algorand
abstract
Algorand is a recent, open-source public or permissionless blockchain system that employs a novel proof-of-stake Byzantine consensus protocol to efficiently scale the distributed transaction agreement problem to billions of users. Despite its promise, one relatively understudied aspect of this protocol has been the incentive compatibility of its reward sharing approach, without which cooperation among rational network users cannot be guaranteed, resulting in protocol failure. This paper is the first attempt to address this problem. By carefully modeling the participation costs and rewards received within a strategic interaction scenario in Algorand, we first show that even a small number of non-participating users (due to insufficiency of the expected incentives) can result in the network failing to append new transaction blocks. We further show that this effect, which was observed in simulations, can be formalized by means of a game-theoretic model that realistically captures the strategic interactions between users in Algorand. Specifically, we formally prove that mutual cooperation under the currently proposed reward sharing approach in Algorand is not a Nash equilibrium. To remedy this, we propose a novel reward sharing approach for Algorand and formally show that it is incentive-compatible, i.e., it can guarantee cooperation within a group of selfish users. Extensive numerical and Algorand simulation results further confirm our analytical findings. Moreover, these results show that for a given distribution of stakes in the network, our reward sharing approach can guarantee cooperation with a significantly smaller reward per round.
Mahdi Fooladgar, Mohammad Hossein Manshaei, Murtuza Jadliwala, Mohammad Ashiqur Rahman
DSN3
2019 deWristified: handwriting inference using wrist-based motion sensors revisited
abstract
Several recent research efforts have shown that privacy of handwritten information is vulnerable to inference threats that employ zero-permission motion sensors commonly found on wrist-wearables (e.g., smart watches and fitness bands) as information side-channels. While the adversary model in these earlier efforts have been reasonable and the proposed inference (or threat) frameworks themselves are practical and have technical merit, the related empirical evaluations suffer from several significant shortcomings, such as, use of specialized sensor hardware and highly constrained or restrictive experimental procedures, to name a few. As a result, it is hard to estimate the practical feasibility of these threats from existing research results in the literature, and thus, the extent to which end-users must be concerned about the possibility of such attacks in real-life. To answer the above question, this paper replicates some of the well-known wrist motion-based handwriting inference frameworks in the literature in order to (re)evaluate their success or accuracy in natural, unrestricted handwriting scenarios and settings by employing commercially available wrist-wearables. The results of these extensive replication and (re)evaluation studies highlight several characteristics in motion data corresponding to natural handwriting scenarios, which were either not observed or ignored by earlier efforts, and contribute to poor inference accuracy of the corresponding frameworks. In summary, accurate and practical handwriting inference using motion data (side-channeled) from consumer-grade wrist-wearables is difficult primarily due to unique and/or inconsistent handwriting behavior observed in natural writing.
Raveen Wijewickrama, Anindya Maiti, Murtuza Jadliwala
WiSec3
2018 Towards Inferring Mechanical Lock Combinations using Wrist-Wearables as a Side-Channel
abstract
Wrist-wearables such as smartwatches and fitness bands are equipped with a variety of high-precision sensors that support novel contextual and activity-based applications. The presence of a diverse set of on-board sensors, however, also expose an additional attack surface which, if not adequately protected, could be potentially exploited to leak private user information. In this paper, we investigate the feasibility of a new attack that takes advantage of a wrist-wearable's motion sensors to infer input on mechanical devices typically used to secure physical access, for example, combination locks. We outline an inference framework that attempts to infer a lock's unlock combination from the wrist motion captured by a smartwatch's gyroscope sensor, and uses a probabilistic model to produce a ranked list of likely unlock combinations. We conduct a thorough empirical evaluation of the proposed framework by employing unlocking-related motion data collected from human subject participants in a variety of controlled and realistic settings. Evaluation results from these experiments demonstrate that motion data from wrist-wearables can be effectively employed as a side-channel to significantly reduce the unlock combination search-space of commonly found combination locks, thus compromising the physical security provided by these locks.
Anindya Maiti, Ryan Heard, Mohd Sabra, Murtuza Jadliwala
WISEC4
2018 Side-Channel Inference Attacks on Mobile Keypads Using Smartwatches
abstract
Smartwatches enable many novel applications and are fast gaining popularity. However, the presence of a diverse set of onboard sensors provides an additional attack surface to malicious software and services on these devices. In this paper, we investigate the feasibility of key press inference attacks on handheld numeric touchpads by using smartwatch motion sensors as a side-channel. We consider different typing scenarios, and propose multiple attack approaches to exploit the characteristics of the observed wrist movements for inferring individual key presses. Experimental evaluation using commercial off-the-shelf smartwatches and smartphones show that key press inference using smartwatch motion sensors is not only fairly accurate, but also comparable with similar attacks using smartphone motion sensors. Additionally, hand movements captured by a combination of both smartwatch and smartphone motion sensors yields better inference accuracy than either device considered individually.
Anindya Maiti, Murtuza Jadliwala, Jibo He, Igor Bilogrevic
IEEE Trans. Mob. Comput.2
2017 Measuring Anonymity of Pseudonymized Data After Probabilistic Background Attacks
abstract
There is clear demand among organizations for sharing their data for mining and other purposes without compromising the privacy of individual objects contained in the data. Pseudonymization is a simple, yet widely employed technique for sanitizing such data prior to its release; it replaces identifying names in the data by pseudonyms. Well-known metrics already exist in the literature for measuring the amount of anonymity still contained in some pseudonymized data in the aftermath of an infeasibility background attack. While the need for a metric for the much wider and more realistic class of probabilistic background attacks has also been well identified, currently no such metric exists. We fulfill that long identified need by presenting two metrics, an approximate and a more exact one, for measuring anonymity in pseudonymized data in the wake of a probabilistic attack. These metrics are rather intractable, thus impractical to employ in real-life situations. Therefore, we also develop an efficient heuristic for our superior metric, and show the remarkable accuracy of our heuristic. Our metrics and heuristic assist a data owner in evaluating the safety level of pseudonymized data against probabilistic attacks before making a decision on its release.
Rajiv Bagai, Nafia Malik, Murtuza Jadliwala
IEEE Trans. Inf. Forensics Secur.3
2017 Seer Grid: Privacy and Utility Implications of Two-Level Load Prediction in Smart Grids
abstract
We propose “Seer Grid”, a novel two-level energy consumption prediction framework for smart grids, aimed to decrease the trade-off between privacy requirements (of the customer) and data utility requirements (of the energy company (EC)). The first-level prediction at the household level is performed by each smart meter (SM), and the predicted energy consumption pattern (instead of the actual energy usage data) is reported to a cluster head (CH). Then, a second-level prediction at the neighborhood level is done by the CH which predicts the energy spikes in the neighborhood or cluster and shares it with the EC. Our two-level prediction mechanism is designed such that it preserves the correlation between the predicted and actual energy consumption patterns at the cluster level and removes this correlation in the predicted data communicated by each SM to the CH. This maintains the usefulness of the cluster-level energy consumption data communicated to the EC, while preserving the privacy of the household-level energy consumption data against the CH (and thus the EC). Our evaluation results show that Seer Grid is successful in hiding private consumption patterns at the household-level while still being able to accurately predict energy consumption at the neighborhood-level.
Arash Boustani, Anindya Maiti, Sina Yousefian Jazi, Murtuza Jadliwala, Vinod Namboodiri
IEEE Trans. Parallel Distributed Syst.4
2016 Smartwatch-Based Keystroke Inference Attacks and Context-Aware Protection Mechanisms
abstract
Wearable devices, such as smartwatches, are furnished with state-of-the-art sensors that enable a range of context-aware applications. However, malicious applications can misuse these sensors, if access is left unaudited. In this paper, we demonstrate how applications that have access to motion or inertial sensor data on a modern smartwatch can recover text typed on an external QWERTY keyboard. Due to the distinct nature of the perceptible motion sensor data, earlier research efforts on emanation based keystroke inference attacks are not readily applicable in this scenario. The proposed novel attack framework characterizes wrist movements (captured by the inertial sensors of the smartwatch worn on the wrist) observed during typing, based on the relative physical position of keys and the direction of transition between pairs of keys. Eavesdropped keystroke characteristics are then matched to candidate words in a dictionary. Multiple evaluations show that our keystroke inference framework has an alarmingly high classification accuracy and word recovery rate. With the information recovered from the wrist movements perceptible by a smartwatch, we exemplify the risks associated with unaudited access to seemingly innocuous sensors (e.g., accelerometers and gyroscopes) of wearable devices. As part of our efforts towards preventing such side-channel attacks, we also develop and evaluate a novel context-aware protection framework which can be used to automatically disable (or downgrade) access to motion sensors, whenever typing activity is detected.
Anindya Maiti, Oscar Armbruster, Murtuza Jadliwala, Jibo He
AsiaCCS3
2016 A machine-learning based approach to privacy-aware information-sharing in mobile social networks
Igor Bilogrevic, Kévin Huguenin, Berker Agir, Murtuza Jadliwala, Maria Gazaki, Jean-Pierre Hubaux
Pervasive Mob. Comput.4
2015 Optimal resource allocation in Cognitive Smart Grid Networks
abstract
Taking advantage of information and communication technologies, the power industry is moving towards the next generation power grid, the smart grid. This information-based power grid is expected to change the way electricity is generated, distributed, and transmitted to the consumers by enhancing the reliability, efficiency, sustainability, and economics of the grid. However, due to the high volume and high granularity of the data generated by smart electricity meters, careful planning and management of this communication network is necessary. Given the large scale future deployment of smart grid, utility companies face possible network capacity constraints. Due to this scarcity, an efficient spectrum allocation is often difficult, thus resulting in low overall bandwidth utilization in Smart Grid Networks (SGN). Hence, an efficient utilization of this communication network should be studied. Cognitive Radio Networks (CRN) enable Secondary Users (SU) to coexist with existing network infrastructures. Cognitive Smart Grid Networks (CSGN) use CRN to optimize resource allocation in SGNs. However, efficient utilization of available channel bandwidth by SUs, without interfering with the Primary Users (PU), remains an important open problem in CSGN. In this paper, we focus on CSGN as the Secondary Network (SN), coexisting with a Primary Network, and outlining the applicability of Code Division Multiple Access for overcoming the low Number of SUs (NSU) in SN. We propose a novel resource allocation technique to improve NSU in CSGN by using a specific kind of Orthogonal Chip Sequence (OCS) allocation in spread spectrum communications for SU transmissions. By means of extensive simulations and analysis, we show that our technique improves NSU on SN (or CSGNs) significantly.
Arash Boustani, Murtuza Jadliwala, Hyuck M. Kwon, Navid Alamatsaz
CCNC2
2014 AgSec: Secure and efficient CDMA-based aggregation for smart metering systems
abstract
Security and privacy concerns in the future power grid have recently received tremendous focus from security advocates. Most existing security mechanisms utilize cryptographic techniques that are computationally expensive and bandwidth intensive. However, aggregating the large outputs of these cryptographic algorithms has not been considered thoroughly. Smart Grid Networks (SGN) generally have limitations on bandwidth, network capacity and energy. Hence, utilizing data aggregation algorithms, the limited bandwidth can be efficiently utilized. Most of the aggregation algorithms use statistical functions such as minimum, maximum, and average. before transmitting data over the network. Existing aggregation algorithms, in SGNs, are generally expensive in terms of communication overhead, processing load and delay. However, our proposed CDMA-based data aggregation method provides access to all the data of all the smart meters in the root node, which in this case is the Utility Center, while keeping the smart metering data secure. The efficiency of the proposed method is confirmed by mathematical analysis.
Navid Alamatsaz, Arash Boustani, Murtuza Jadliwala, Vinod Namboodiri
CCNC3
2014 LocJam: A novel jamming-based approach to secure localization in wireless networks
abstract
Location discovery is an essential service in modern wireless consumer devices such as smartphones and mobile PCs. Existing anchor or base station-based positioning systems work well in non-hostile scenarios, but their accuracy suffers in the presence of cheating anchors. Securing location discovery in these positioning systems is an important, and still open, research problem. Earlier research efforts in this direction have mainly focused on either efficient detection and elimination of cheating anchors or on localization in the presence of cheating anchors. Proposals on localization in the presence of cheating anchors fail to perform well in the presence of a large number of cheating anchors, whereas, the issue of elimination of cheating anchors (once detected) has not been clearly addressed in techniques that focus on detection and elimination of cheating anchors. In this paper, we present a novel and deterministic strategy for securing anchor-based location discovery. Our technique employs a novel CDMA-based jamming strategy to eliminate (the effect of) cheating anchors during localization. We validate the performance of our proposal under various adversarial strengths and operating scenarios by means of extensive simulations.
Arash Boustani, Navid Alamatsaz, Murtuza Jadliwala, Vinod Namboodiri
CCNC3
2014 Social Puzzles: Context-Based Access Control in Online Social Networks
abstract
The increasing popularity of online social networks (OSNs) is spawning new security and privacy concerns. Currently, a majority of OSNs offer very naive access control mechanisms that are primarily based on static access control lists (ACL) or policies. But as the number of social connections grow, static ACL based approaches become ineffective and unappealing to OSN users. There is an increased need in social-networking and data-sharing applications to control access to data based on the associated context (e.g., event, location, and users involved), rather than solely on data ownership and social connections. Surveillance is another critical concern for OSN users, as the service provider may further scrutinize data posted or shared by users for personal gains (e.g., targeted advertisements), for use by corporate partners or to comply with legal orders. In this paper, we introduce a novel paradigm of context-based access control in OSNs, where users are able to access the shared data only if they have knowledge of the context associated with it. We propose two constructions for context-based access control in OSNs: the first is based on a novel application of Shamir's secret sharing scheme, whereas the second makes use of an attribute-based encryption scheme. For both constructions, we analyze their security properties, implement proof-of-concept applications for Facebook and empirically evaluate their functionality and performance. Our empirical measurements show that the proposed constructions execute efficiently on standard computing hardware, as well as, on portable mobile devices.
Murtuza Jadliwala, Anindya Maiti, Vinod Namboodiri
DSN1
2014 Privacy-Preserving Optimal Meeting Location Determination on Mobile Devices
abstract
Equipped with state-of-the-art smartphones and mobile devices, today's highly interconnected urban population is increasingly dependent on these gadgets to organize and plan their daily lives. These applications often rely on current (or preferred) locations of individual users or a group of users to provide the desired service, which jeopardizes their privacy; users do not necessarily want to reveal their current (or preferred) locations to the service provider or to other, possibly untrusted, users. In this paper, we propose privacy-preserving algorithms for determining an optimal meeting location for a group of users. We perform a thorough privacy evaluation by formally quantifying privacy-loss of the proposed approaches. In order to study the performance of our algorithms in a real deployment, we implement and test their execution efficiency on Nokia smartphones. By means of a targeted user-study, we attempt to get an insight into the privacy-awareness of users in location-based services and the usability of the proposed solutions.
Igor Bilogrevic, Murtuza Jadliwala, Vishal Joneja, Kübra Kalkan, Jean-Pierre Hubaux, Imad Aad
IEEE Trans. Inf. Forensics Secur.2
2013 Adaptive information-sharing for privacy-aware mobile social networks
abstract
Personal and contextual information are increasingly shared via mobile social networks. Users' locations, activities and their co-presence can be shared easily with online "friends", as their smartphones already access such information from embedded sensors and storage. Yet, people usually exhibit selective sharing behavior depending on contextual attributes, thus showing that privacy, utility, and usability are paramount to the success of such online services. In this paper, we present SPISM, a novel information-sharing system that decides (semi-)automatically whether to share information with others, whenever they request it, and at what granularity. Based on active machine learning and context, SPISM adapts to each user's behavior and it predicts the level of detail for each sharing decision, without revealing any personal information to a third-party. Based on a personalized survey about information sharing involving 70 participants, our results provide insight into the most influential features behind a sharing decision. Moreover, we investigate the reasons for the users' decisions and their confidence in them. We show that SPISM outperforms other kinds of global and individual policies, by achieving up to 90% of correct decisions.
Igor Bilogrevic, Kévin Huguenin, Berker Agir, Murtuza Jadliwala, Jean-Pierre Hubaux
UbiComp4
2013 Optimizing mix-zone coverage in pervasive wireless networks
abstract
Location privacy is a major concern in pervasive networks where static device identifiers enable malicious eavesdroppers to continuously track users and their movements. In order to prevent such identifier-based tracking, devices could coordinate regular identifier change operations in special areas called mix-zones. Although mix-zones provide spatio-temporal de-correlation between old and new identifiers, depending on the position of the mix-zone, identifier changes can generate a substantial inconvenience (or “cost”) to the users in terms of lost communications and increased energy consumption. In this paper, we address this trade-off between privacy and cost by studying the problem of determining an optimal set of mix-zones such that the degree of mixing in the network is maximized and the overall network-wide mixing cost is minimized. We follow a graph-theoretic approach and model the optimal mixing problem as a generalization of the vertex cover problem, called the Mix Cover (MC) problem. We propose three approximation algorithms for the MC problem and derive a lower bound on the solution quality guaranteed by them. Additionally, we outline two other heuristics for solving the MC problem. These heuristics are simple, but do not provide any guarantees on the solution quality. By means of extensive empirical evaluation using real data, we compare the performance and solution quality of these algorithms. The combinatorics-based approach used in this work enables us to study the feasibility of determining optimal mix-zones regularly and under dynamic network conditions.
Murtuza Jadliwala, Igor Bilogrevic, Jean-Pierre Hubaux
J. Comput. Secur.1
2013 Privacy of Community Pseudonyms in Wireless Peer-to-Peer Networks
Julien Freudiger, Murtuza Jadliwala, Jean-Pierre Hubaux, Valtteri Niemi, Philip Ginzboorg
Mob. Networks Appl.2
2012 Track Me If You Can: On the Effectiveness of Context-based Identifier Changes in Deployed Mobile Networks
Laurent Bindschaedler, Murtuza Jadliwala, Igor Bilogrevic, Imad Aad, Philip Ginzboorg, Valtteri Niemi, Jean-Pierre Hubaux
NDSS2
2011 Privacy-preserving activity scheduling on mobile devices
abstract
Progress in mobile wireless technology has resulted in the increased use of mobile devices to store and manage users' personal schedules. Users also access popular context-based services, typically provided by third-party providers, by using these devices for social networking, dating and activity-partner searching applications. Very often, these applications need to determine common availabilities among a set of user schedules. The privacy of the scheduling operation is paramount to the success of such applications, as often users do not want to share their personal schedules with other users or third-parties. Previous research has resulted in solutions that provide privacy guarantees, but they are either too complex or do not fit well in the popular user-provider operational model. In this paper, we propose practical and privacy-preserving solutions to the server-based scheduling problem. Our novel algorithms take advantage of the homomorphic properties of well-known cryptosystems in order to privately compute common user availabilities. We also formally outline the privacy requirements in such scheduling applications and we implement our solutions on real mobile devices. The experimental measurements and analytical results show that the proposed solutions not only satisfy the privacy properties but also fare better, in regard to computation and communication efficiency, compared to other well-known solutions.
Igor Bilogrevic, Murtuza Jadliwala, Jean-Pierre Hubaux, Imad Aad, Valtteri Niemi
CODASPY2
2011 Optimizing Mixing in Pervasive Networks: A Graph-Theoretic Perspective
Murtuza Jadliwala, Igor Bilogrevic, Jean-Pierre Hubaux
ESORICS1
2011 Privacy in Mobile Computing for Location-Sharing-Based Services
Igor Bilogrevic, Murtuza Jadliwala, Kübra Kalkan, Jean-Pierre Hubaux, Imad Aad
PETS2
2011 Privacy-triggered communications in pervasive social networks
abstract
Pervasive social networks extend traditional social networking by enabling users to share information in a peer-to-peer fashion using their wireless mobile devices. Contrary to traditional online social networks, privacy protection in such networks depends heavily on users' context (time, location, activity, etc.) and their sensitivity to the shared data and context. Existing privacy-preserving mechanisms do not adapt well to different data, context and user sensitivities. In this work, we follow a fresh approach for privacy preservation, called privacy-triggered communications; it allows users in such pervasive networks to dynamically regulate their communications based on their context and on the evolution of their privacy in that context. Our initial results show that this is a feasible strategy for privacy management in pervasive social networking scenarios.
Murtuza Jadliwala, Julien Freudiger, Imad Aad, Jean-Pierre Hubaux, Valtteri Niemi
WOWMOM1
2011 Meetings through the cloud: Privacy-preserving scheduling on mobile devices
Igor Bilogrevic, Murtuza Jadliwala, Praveen Kumar 0003, Sudeep Singh Walia, Jean-Pierre Hubaux, Imad Aad, Valtteri Niemi
J. Syst. Softw.2
2010 Secure Distance-Based Localization in the Presence of Cheating Beacon Nodes
abstract
Secure distance-based localization in the presence of cheating beacon (or anchor) nodes is an important problem in mobile wireless ad hoc and sensor networks. Despite significant research efforts in this direction, some fundamental questions still remain unaddressed: In the presence of cheating beacon nodes, what are the necessary and sufficient conditions to guarantee a bounded error during a two-dimensional distance-based location estimation? Under these necessary and sufficient conditions, what class of localization algorithms can provide this error bound? In this paper, we attempt to answer these and other related questions by following a careful analytical approach. Specifically, we first show that when the number of cheating beacon nodes is greater than or equal to a given threshold, there do not exist any two-dimensional distance-based localization algorithms that can guarantee a bounded error. Furthermore, when the number of cheating beacons is below this threshold, we identify a class of distance-based localization algorithms that can always guarantee a bounded localization error. Finally, we outline three novel distance-based localization algorithms that belong to this class of bounded error localization algorithms. We verify their accuracy and efficiency by means of extensive simulation experiments using both simple and practical distance estimation error models.
Murtuza Jadliwala, Sheng Zhong 0002, Shambhu J. Upadhyaya, Chunming Qiao, Jean-Pierre Hubaux
IEEE Trans. Mob. Comput.1
2009 Towards a theory for securing time synchronization in wireless sensor networks
abstract
Time synchronization in highly distributed wireless systems like sensor and ad hoc networks is extremely important in order to maintain a consistent notion of time throughout the network and to support the various timing-based applications. But, cheating behavior by the participating nodes in the network can severely jeopardize the accuracy of the associated time synchronization process. Despite recent advances in this direction, a key fundamental question still remains unanswered: Is it theoretically feasible to secure distributed time synchronization protocols, given complete (or global) time and time difference information in the network?
Murtuza Jadliwala, Qi Duan, Shambhu J. Upadhyaya, Jinhui Xu 0001
WISEC1
2008 Towards a Theory of Robust Localization Against Malicious Beacon Nodes
abstract
Localization in the presence of malicious beacon nodes is an important problem in wireless networks. Although significant progress has been made on this problem, some fundamental theoretical questions still remain unanswered: in the presence of malicious beacon nodes, what are the necessary and sufficient conditions to guarantee a bounded error during 2-dimensional location estimation? Under these necessary and sufficient conditions, what class of localization algorithms can provide that error bound? In this paper, we try to answer these questions. Specifically, we show that, when the number of malicious beacons is greater than or equal to some threshold, there is no localization algorithm that can have a bounded error. Furthermore, when the number of malicious beacons is below that threshold, we identify a class of localization algorithms that can ensure that the localization error is bounded. We also outline two algorithms in this class, one of which is guaranteed to finish in polynomial time (in the number of beacons providing information) in the worst case, while the other is based on a heuristic and is practically efficient. For completeness, we also extend the above results to the 3-dimensional case. Experimental results demonstrate that our solution has very good localization accuracy and computational efficiency.
Sheng Zhong 0002, Murtuza Jadliwala, Shambhu J. Upadhyaya, Chunming Qiao
INFOCOM2
2007 ASFALT: A Simple Fault-Tolerant Signature-based Localization Technique for Emergency Sensor Networks
abstract
We consider the problem of robust node deployment and fault-tolerant localization in wireless sensor networks for emergency and first response applications. Signature-based localization algorithms are a popular choice for use in such applications due to the non-uniform nature of the sensor node deployment. But, random destruction/disablement of sensor nodes in such networks adversely affects the deployment strategy as well as the accuracy of the corresponding signature-based localization algorithm. In this paper, we first model the phenomenon of sensor node destruction as a non-homogeneous Poisson process and derive a robust and efficient strategy for sensor node deployment based on this model. Next, we outline a protocol, called Group Selection Protocol, that complements current signature-based algorithms by reducing localization errors even when some nodes in a group are destroyed. Finally, we propose a novel yet simple localization technique, ASFALT, that improves the efficiency of the localization process by combining the simplicity of range-based schemes with the robustness of signature-based ones. Simulation experiments are conducted to verify the performance of the proposed algorithms.
Murtuza Jadliwala, Shambhu J. Upadhyaya, Manik Taneja
SRDS1