VLDB 2026 Research / reviewers in the wild / expert
Raj Vardhan
dblp:125/3550
· DBLP profile ↗
4ranked-venue papers
1as first author
3since 2021 · last 2023
0000-0001-5808-0718ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | #DM-Me: Susceptibility to Direct Messaging-Based ScamsabstractIn an emerging scam on social media platforms, cyber-miscreants are luring users into sending them a direct-message (DM) and are subsequently exploiting the messaging channel. We term this attack approach as the DM-Me scam. We report on a survey of 214 MTurk participants, in which we make the first effort to systematically study the susceptibility of users in falling victim to DM-Me scams. We find that most participants chose to send a direct message to at least one scammer, and made such choices more than half the time. This susceptibility can be attributed to the misplaced trust in scammers and the lack of negative consequences foreseen by participants in messaging accounts that they do not fully trust. Interestingly, our results also suggest that women mostly from the 31-40 age-group and who predominantly use Instagram a few times a week are less susceptible than men to financial DM-Me scams as they appear to face more discomfort in initiating a conversation with unfamiliar accounts for such services. We conclude with future research directions in mitigating the risks posed by DM-Me scammers, specifically by developing reliable indicators to aid users in assessing the trustworthiness of an account. Raj Vardhan, Alok Chandrawal, Phakpoom Chinprutthiwong, Yangyong Zhang, Guofei Gu |
AsiaCCS | 1 |
| 2023 | Do Users Really Know Alexa? Understanding Alexa Skill Security IndicatorsabstractAmazon Alexa’s booming third-party skill market has grown from 160 to 100,000 skills within three years. In this work, we make the first effort in demystifying the Alexa skill permission system by studying its security indicators. Our user study results show that most of the surveyed Alexa users did not understand the security implications of interacting with third parties via Alexa’s voice user interface (VUI). Despite the potential risks of undesired resource sharing, more than two-thirds of the surveyed Alexa users considered third-party skills safe because they think these skills are Alexa- or Amazon-owned applications. Together with other uncovered deficiencies of skill security indicator designs, our study indicates a pressing need for a paradigm shift in designing security indicators for VUI systems. Yangyong Zhang, Raj Vardhan, Phakpoom Chinprutthiwong, Guofei Gu |
AsiaCCS | 2 |
| 2021 | The Service Worker Hiding in Your Browser: The Next Web Attack Target?abstractIn recent years, service workers are gaining attention from both web developers and attackers due to the unique features they provide. Recent findings have shown that an attacker can register a malicious service worker to take advantage of the victim such as by turning the victim’s device into a crypto-currency miner. However, the possibility of benign service workers being leveraged is not well studied. Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Yangyong Zhang, Guofei Gu |
RAID | 2 |
| 2020 | Security Study of Service Worker Cross-Site ScriptingabstractNowadays, modern websites are utilizing service workers to provide users with app-like functionalities such as offline mode and push notifications. To handle such features, the service worker is equipped with special privileges including HTTP traffic manipulation. Thus, it is designed with security as a priority. However, we find that many websites introduce a questionable practice that can jeopardize the security of a service worker. Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Guofei Gu |
ACSAC | 2 |