VLDB 2026 Research / reviewers in the wild / expert
Pablo Picazo-Sanchez
dblp:131/9757
· DBLP profile ↗
17ranked-venue papers
7as first author
7since 2021 · last 2024
0000-0002-0303-3858ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 first-author · 4 since 2021Systems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 3 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | FakeX: A Framework for Detecting Fake Reviews of Browser ExtensionsabstractBrowser extensions boost user experience on the web. Similarly to smartphone app stores, browsers like Chrome distribute browser extensions via their Web Store, enabling a thriving market of third-party developed extensions. The Web Store incorporates a user review system to help users decide which extensions to install. Unfortunately, the open nature of the review system is subject to reputation manipulation. As browser vendors fight reputation manipulation, attackers employ more sophisticated methods to stay under the radar. Focusing on fake reviews, we identify several techniques attackers use: fake accounts, disjoint sets of fake accounts for different extensions, automation of generated reviews, and focusing on reviews rather than ratings. We present FakeX, a framework to detect fake reviews by focusing on inference from review metadata. FakeX employs five distinct methods, including temporal distribution analysis, relationship clustering, and ratio-based assessments, to unveil patterns indicative of fake reviews. Evaluation of over 1.7 million reviews reveals the effectiveness of FakeX in identifying hundreds of fake review campaigns. Furthermore, our investigation of these fake reviews uncovers 86 malicious extensions, mounting attacks that range from data-stealing to monetization, impacting over 64 million users. In addition, we collaborate with Adblock Plus and Avast to demonstrate FakeX in action, expanding a seed list of newly detected malicious extensions to discover a further 16 malicious extensions with millions of users, where, in some cases, attackers tried to improve malicious code. Eric Olsson 0001, Benjamin Eriksson, Pablo Picazo-Sanchez, Lukas Andersson, Andrei Sabelfeld |
AsiaCCS | 3 |
| 2024 | Analysing the impact of ChatGPT in researchabstractAbstract Large Language Models (LLMs) are a type of machine learning that handles a wide range of Natural Language Processing (NLP) scenarios. Recently, in December 2022, a company called OpenAI released ChatGPT, a tool that, within a few months, became the most representative example of LLMs, automatically generating unique and coherent text on many topics, summarising and rewriting it, or even translating it to other languages. ChatGPT originated some controversy in academia since students can generate unique text for writing assessments being sometimes extremely difficult to distinguish whether it comes from ChatGPT or a person. In research, some journals specifically banned ChatGPT in scientific papers. However, when used correctly, it becomes a powerful tool to rewrite, for instance, scientific papers and, thus, deliver researchers’ messages in a better way. In this paper, we conduct an empirical study of the impact of ChatGPT in research. We downloaded the abstract of over 45,000 papers from over 300 journals from Dec 2022 and Feb 2023 belonging to different research editorials. We use four of the most known ChatGPT detection tools and conclude that ChatGPT played a role in around 10% of the papers published in every editorial, showing that authors from different fields have rapidly adopted such a tool in their research. Pablo Picazo-Sanchez, Lara Ortiz-Martin |
Appl. Intell. | 1 |
| 2023 | Clipaha: A Scheme to Perform Password Stretching on the ClientabstractPassword security relies heavily on the choice of password by the user but also on the one-way hash functions used to protect stored passwords. To compensate for the increased computing power of attackers, modern password hash functions like Argon2, have been made more complex in terms of computational power and memory requirements. Nowadays, the computation of such hash functions is performed usually by the server (or authenticator) instead of the client. Therefore, constrained Internet of Things devices cannot use such functions when authenticating users. Additionally, the load of computing such functions may expose servers to denial of service attacks. In this work, we discuss client-side hashing as an alternative. We propose Clipaha, a client-side hashing scheme that allows using high-security password hashing even on highly constrained server devices. Clipaha is robust to a broader range of attacks compared to previous work and covers important and complex usage scenarios. Our e valuation discusses critical aspects involved in client-side hashing. We also provide an implementation of Clipaha in the form of a web library 1 and benchmark the library on different systems to understand its mixed JavaScript and WebAssembly approach’s limitations. Benchmarks show that our library is 50% faster than similar libraries and can run on some devices where previous work fails. Francisco Blas Izquierdo Riera, Magnus Almgren, Pablo Picazo-Sanchez, Christian Rohner |
ICISSP | 3 |
| 2023 | IBE.js: A Framework for Instrumenting Browser Extensions
Elvira Moreno-Sanchez, Pablo Picazo-Sanchez |
ICSOFT | 2 |
| 2022 | No Signal Left to Chance: Driving Browser Extension Analysis by Download PatternsabstractBrowser extensions are popular small applications that allow users to enrich their browsing experience. Yet browser extensions pose security concerns because they can leak user data and maliciously act on behalf of the user. Because malicious behavior can manifest dynamically, detecting malicious extensions remains a challenge for the research community, browser vendors, and web application developers. This paper identifies download patterns as a useful signal for analyzing browser extensions. We leverage machine learning for clustering extensions based on their download patterns, confirming at a large scale that many extensions follow strikingly similar download patterns. Our key insight is that the download pattern signal can be used for identifying malicious extensions. To this end, we present a novel technique to detect malicious extensions based on the public number of downloads in the Chrome Web Store. This technique fruitfully combines machine learning with security analysis, showing that the download patterns signal can be used to both directly spot malicious extensions and as input to subsequent analysis of suspicious extensions. We demonstrate the benefits of our approach on a dataset from a daily crawl of the Web Store over 6 months to track the number of downloads. We find 135 clusters and identify 61 of them to have at least 80% malicious extensions. We train our classifier and run it on a test set of 1,212 currently active extensions in the Web Store successfully detecting 326 extensions as malicious solely based on downloads. Further, we show that by combining this signal with code similarity analysis, using the 326 as a seed, we find an additional 6,579 malicious extensions. Pablo Picazo-Sanchez, Benjamin Eriksson, Andrei Sabelfeld |
ACSAC | 1 |
| 2022 | DeDup.js: Discovering Malicious and Vulnerable Extensions by Detecting DuplicationabstractBrowser extensions are popular web applications that users install in modern browsers to enrich the user experience on the web. It is common for browser extensions to include static resources in the form of HTML, CSS, fonts, images, and JavaScript libraries. Unfortunately, the state of the art is that each extension ships its own version of a given resource. This paper presents DeDup.js, a framework that incorporates similarity analysis for achieving two goals: detecting potentially malicious extensions during the approval process, and given an extension as input, DeDup.js discovers similar extensions. We downloaded three snapshots of the Google Chrome Web Store during one year totaling more than 422k browser extensions and conclude that over 50% of the static resources are shared among the extensions. By implementing an instance of DeDup.js, we detect more than 7k extensions that should not have been published and were later deleted. Also, we discover more than 1k malicious extensions still online that send user's queries to external servers without the user's knowledge. Finally, we show the potential of DeDup.js by analyzing a set extensions part of CacheFlow, a recently discovered attack. We detect 53 malicious extensions of which 36 Google has already taken down and the rest are investigated. Pablo Picazo-Sanchez, Maximilian Algehed, Andrei Sabelfeld |
ICISSP | 1 |
| 2022 | Semantic Attribute-Based Encryption: A framework for combining ABE schemes with semantic technologies
Hamed Arshad, Christian Johansen, Olaf Owe, Pablo Picazo-Sanchez, Gerardo Schneider |
Inf. Sci. | 4 |
| 2020 | HMAC and "Secure Preferences": Revisiting Chromium-Based Browsers Security
Pablo Picazo-Sanchez, Gerardo Schneider, Andrei Sabelfeld |
CANS | 1 |
| 2020 | Are the Interpulse Intervals of an ECG signal a good source of entropy? An in-depth entropy analysis based on NIST 800-90B recommendation
Lara Ortiz-Martin, Pablo Picazo-Sanchez, Pedro Peris-Lopez |
Future Gener. Comput. Syst. | 2 |
| 2020 | A collaborative access control framework for online social networks
Hanaa Alshareef, Raúl Pardo, Gerardo Schneider, Pablo Picazo-Sanchez |
J. Log. Algebraic Methods Program. | 4 |
| 2019 | Latex Gloves: Protecting Browser Extensions from Probing and Revelation Attacks
Alexander Sjösten, Steven Van Acker, Pablo Picazo-Sanchez, Andrei Sabelfeld |
NDSS | 3 |
| 2019 | Feasibility analysis of Inter-Pulse Intervals based solutions for cryptographic token generation by two electrocardiogram sensors
Lara Ortiz-Martin, Pablo Picazo-Sanchez, Pedro Peris-Lopez, Juan Tapiador, Gerardo Schneider |
Future Gener. Comput. Syst. | 2 |
| 2018 | \mathsf HIKE : Walking the Privacy Trail
Elena Pagnin, Carlo Brunetta, Pablo Picazo-Sanchez |
CANS | 3 |
| 2018 | Migrating Monitors + ABE: A Suitable Combination for Secure IoT?
Gordon J. Pace, Pablo Picazo-Sanchez, Gerardo Schneider |
ISoLA (4) | 2 |
| 2017 | Secure Photo Sharing in Social Networks
Pablo Picazo-Sanchez, Raúl Pardo, Gerardo Schneider |
SEC | 1 |
| 2015 | Weaknesses of fingerprint-based mutual authentication protocolabstractAbstract The Internet of Things is an emerging paradigm, which is used to link physical objects with Internet. One of the most common ways of communicating and identifying objects on Internet of Things is using Radio Frequency IDentification (RFID) systems between different objects. Researchers have focused on developing improvements of RFID authentication protocols that stave off privacy threats and well‐known security problems. Recently, Khor et al. have proposed a new authentication protocol that conforms to the Electronic Product Code Class‐1 Generation‐2 standard (ISO/IEC 18000‐6C for RFID systems). In this paper, we show the vulnerabilities of this authentication protocol concerning to full disclosure, impersonation, traceability, de‐synchronization, and Denial‐of‐Service attacks. These attacks make the protocol unfeasible to introduce it with an adequate security and sufficient privacy protection level. Finally, we present a new protocol, called Fingerprint+ protocol, which is based on ISO/IEC 9798‐2 and ISO/IEC 18000‐6C and whose security is formally verified using BAN logic. Copyright © 2014 John Wiley & Sons, Ltd. Pablo Picazo-Sanchez, Lara Ortiz-Martin, Pedro Peris-Lopez, Nasour Bagheri |
Secur. Commun. Networks | 1 |
| 2013 | Cryptanalysis of the RNTS system
Pablo Picazo-Sanchez, Lara Ortiz-Martin, Pedro Peris-Lopez, Julio César Hernández Castro |
J. Supercomput. | 1 |