Ehsan Toreini

dblp:127/2330 · DBLP profile ↗
← Back
9ranked-venue papers
1as first author
4since 2021 · last 2026
0000-0002-5172-2957ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 1 first-author · 4 since 2021
YearPublicationVenuePosition
2026 AXECC: Benchmarking the Privacy and Accessibility Impact of Browser Extensions
abstract
Browser extensions are commonly used to improve the browsing experience and accessibility. However, installing extensions naturally increases the user’s risk. This work presents AXECC , a novel framework for measuring the impact of web tracking and accessibility. The AXECC framework includes static, dynamic, and accessibility analyses across multiple web pages. We utilise the AXECC framework to analyse the web tracking and accessibility impact in the wild on 21k real-world extensions collected from the Chrome Web Store. In our analysis, we identify that 15.97% of extensions (with more than 600M users) perform a type of third–party tracking in the first 60 seconds after loading. These results are highly correlated with the extension category and are consistent across different web pages. Furthermore, we find that a small number of extensions (with 65M users) alter the accessibility of a web page when browsing, and these alterations are often complex and involve more tracking. Our work reveals a significant privacy risk from web tracking within popular browser extensions, often intertwined with complex accessibility alterations.
James M. Clarke, Maryam Mehrnezhad, Ehsan Toreini
ACM Trans. Priv. Secur.3
2022 "I feel invaded, annoyed, anxious and I may protect myself": Individuals' Feelings about Online Tracking and their Protective Behaviour across Gender and Country
Kovila P. L. Coopamootoo, Maryam Mehrnezhad, Ehsan Toreini
USENIX Security Symposium3
2022 How Can and Would People Protect From Online Tracking?
abstract
Abstract Online tracking is complex and users find it challenging to protect themselves from it. While the academic community has extensively studied systems and users for tracking practices, the link between the data protection regulations, websites’ practices of presenting privacy-enhancing technologies (PETs), and how users learn about PETs and practice them is not clear. This paper takes a multidimensional approach to find such a link. We conduct a study to evaluate the 100 top EU websites, where we find that information about PETs is provided far beyond the cookie notice. We also find that opting-out from privacy settings is not as easy as opting-in and becomes even more difficult (if not impossible) when the user decides to opt-out of previously accepted privacy settings. In addition, we conduct an online survey with 614 participants across three countries (UK, France, Germany) to gain a broad understanding of users’ tracking protection practices. We find that users mostly learn about PETs for tracking protection via their own research or with the help of family and friends. We find a disparity between what websites offer as tracking protection and the ways individuals report to do so. Observing such a disparity sheds light on why current policies and practices are ineffective in supporting the use of PETs by users.
Maryam Mehrnezhad, Kovila P. L. Coopamootoo, Ehsan Toreini
Proc. Priv. Enhancing Technol.3
2021 Anti-Counterfeiting for Polymer Banknotes Based on Polymer Substrate Fingerprinting
abstract
Polymer banknotes are the trend for printed currency and have been adopted by more than fifty countries worldwide. However, over the past years, the quantity of polymer counterfeits has been increasing, so has the quality of counterfeits. This shows that the initial advantage of bringing a new polymer technology to fight against counterfeiting is reducing. To maintain one step ahead of counterfeiters, we propose a novel anti-counterfeiting technique called Polymer Substrate Fingerprinting (PSF). Our technique is built based on the observation that the opacity coating, a critical step during the production of polymer notes, is a stochastic manufacturing process, leaving uneven thickness in the coating layer and the random dispersion of impurities from the ink. The imperfections in the coating layer result in random translucent patterns when a polymer banknote is back-lit by a light source. We show these patterns can be reliably captured by a commodity negative-film scanner and processed into a compact fingerprint to uniquely identify each banknote. Using an extensive dataset of 6,200 sample images collected from 340 UK banknotes, we show that our method can reliably authenticate banknotes, and is robust against rough daily handling of banknotes. Furthermore, we show the extracted fingerprints contain around 900 bits of entropy, which makes it extremely scalable to identify every polymer note circulated globally. As compared with previous or existing anti-counterfeiting mechanisms for banknotes, our method has a distinctive advantage: it ensures that even in the extreme case when counterfeiters have procured the same printing equipment and ink as used by a legitimate government, counterfeiting banknotes remains infeasible because of the difficulty to replicate a stochastic manufacturing process.
Shen Wang 0008, Ehsan Toreini, Feng Hao 0001
IEEE Trans. Inf. Forensics Secur.2
2017 Erratum to "On the Privacy of Private Browsing - A Forensic Approach" [JISA 19/1(2014), 88-100]
Kiavash Satvat, Matthew Forshaw, Feng Hao 0001, Ehsan Toreini
J. Inf. Secur. Appl.4
2017 Texture to the Rescue: Practical Paper Fingerprinting Based on Texture Patterns
abstract
In this article, we propose a novel paper fingerprinting technique based on analyzing the translucent patterns revealed when a light source shines through the paper. These patterns represent the inherent texture of paper, formed by the random interleaving of wooden particles during the manufacturing process. We show that these patterns can be easily captured by a commodity camera and condensed into a compact 2,048-bit fingerprint code. Prominent works in this area (Nature 2005, IEEE S8P 2009, CCS 2011) have all focused on fingerprinting paper based on the paper “surface.” We are motivated by the observation that capturing the surface alone misses important distinctive features such as the noneven thickness, random distribution of impurities, and different materials in the paper with varying opacities. Through experiments, we demonstrate that the embedded paper texture provides a more reliable source for fingerprinting than features on the surface. Based on the collected datasets, we achieve 0% false rejection and 0% false acceptance rates. We further report that our extracted fingerprints contain 807 degrees of freedom (DoF), which is much higher than the 249 DoF with iris codes (that have the same size of 2,048 bits). The high amount of DoF for texture-based fingerprints makes our method extremely scalable for recognition among very large databases; it also allows secure usage of the extracted fingerprint in privacy-preserving authentication schemes based on error correction techniques.
Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001
ACM Trans. Priv. Secur.1
2016 TouchSignatures: Identification of user touch actions and PINs based on mobile sensor data via JavaScript
Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001
J. Inf. Secur. Appl.2
2015 TouchSignatures: Identification of User Touch Actions based on Mobile Sensors via JavaScript
abstract
Conforming to the recent W3C specifications (www.w3.org/TR/orientation-event), modern mobile web browsers generally allow JavaScript code in a web page to access motion and orientation sensor data without the user's permission. The associated risks to user privacy are however not considered in W3C specifications. In this work, for the first time, we show how user privacy can be compromised using device motion and orientation sensor data available in-browser, despite the fact that the data rate is 5 to 10 times slower than what is attainable in-app. We examine different browsers on the Android and iOS platforms and study their policies in granting permissions to JavaScript code with respect to access to motion and orientation sensor data and identify multiple vulnerabilities. Based on our findings, we propose TouchSignatures, implementation of an attack in which malicious JavaScript code on an inactive tab listens to such sensor data measurements. Based on these streams, TouchSignatures is able to distinguish the user's touch actions (e.g., tap, scroll, hold, and zoom) on an active tab, allowing the remote website to learn the client-side user activities. Finally, we demonstrate the practicality of this attack by collecting real-world user data and reporting high success rates using our proof-of-concept implementation.
Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001
AsiaCCS2
2014 On the privacy of private browsing - A forensic approach
Kiavash Satvat, Matthew Forshaw, Feng Hao 0001, Ehsan Toreini
J. Inf. Secur. Appl.4