VLDB 2026 Research / reviewers in the wild / expert
Gunes Acar
dblp:136/8452
· DBLP profile ↗
20ranked-venue papers
7as first author
12since 2021 · last 2026
0000-0002-1621-8333ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 7 first-author · 10 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Editors' IntroductionabstractEditors' Introduction, Issue 1 of PoPETs Volume 2026 Gunes Acar, Rob Jansen |
Proc. Priv. Enhancing Technol. | 1 |
| 2026 | Editors' IntroductionabstractEditors' Introduction, Issue 2 of PoPETs Volume 2026 Gunes Acar, Rob Jansen |
Proc. Priv. Enhancing Technol. | 1 |
| 2026 | Editors' IntroductionabstractEditors' Introduction, Issue 3 of PoPETs Volume 2026 Gunes Acar, Rob Jansen |
Proc. Priv. Enhancing Technol. | 1 |
| 2026 | Editors' IntroductionabstractEditors' Introduction, Issue 4 of PoPETs Volume 2026 Gunes Acar, Rob Jansen |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | WhisperTest: A Voice-Control-based Library for iOS UI AutomationabstractDynamic analysis and UI automation are essential for scalable detection of privacy leaks, vulnerabilities, and malicious code in mobile apps. While the Android ecosystem offers a variety of tools, options for iOS apps are limited and require either access to the app source code or jailbreaking the test device. To address this gap, we introduce WhisperTest, an open-source iOS UI automation library that operates without jailbreaking. WhisperTest is based on a newly designed approach that leverages Apple's Voice Control accessibility feature to interact with app or system UIs via text-to-speech. During interactions, WhisperTest monitors the device system logs in real time and scrapes the UI via screenshots and accessibility audits to recover app state changes. We demonstrate WhisperTest's capabilities through a diverse set of tasks, including a web privacy measurement and a fully-automated dynamic analysis of 200 child-directed iOS apps. To overcome the challenges of automating apps with diverse UI designs, WhisperTest optionally integrates multimodal large language models to reason about context and interact with system permission prompts, consent dialogs, subscription prompts, and age gates. Our exploratory analysis of children's apps uncovers widespread use of third-party tracking, limited recognition of user consent, and unencrypted HTTP requests. Overall, we show that WhisperTest enables scalable dynamic analysis of iOS applications across diverse tasks, contributing to a safer and more transparent mobile ecosystem. Zahra Moti, Tom Janssen-Groesbeek, Steven Monteiro, Andrea Continella, Gunes Acar |
CCS | 5 |
| 2025 | Referrer Policy: Implementation and CircumventionabstractThe Referrer Policy (RP) standard makes it possible for websites to control how much information will be shared in the Referer [sic] header. In this study, we investigate the implementation and circumvention of the Referrer Policy standard across 27,750 distinct websites and over 100K pages from three vantage points: the United States, Singapore and the Netherlands. Our findings reveal that 48.38% of websites implement document-wide referrer policies, and 13.39% apply element-specific referrer policies. The majority of the sites (43.81\%) use the Referrer-Policy HTTP response header to set a document-wide policy, while 11.09% use HTML meta tags. Even on websites with restrictive referrer policies, scripts can access the full page URL and exfiltrate it --- which we label as a referrer policy circumvention. We identified RP circumventions on 77.20% of websites often carried out by third-party advertising and analytics scripts, including Google Analytics, Facebook, and TikTok Pixel. While the ability to manage referrer information and the adoption of more privacy-focused default policies represent positive gains for user privacy, the widespread circumvention of these measures by third-party script remains to be a problem. We recommend implementing technical measures to restrict script access in order to address this privacy and security issue. Luqman Zagi, Zahra Moti, Gunes Acar |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Staying at the Roach Motel: Cross-Country Analysis of Manipulative Subscription and Cancellation FlowsabstractSubscribing to online services is typically a straightforward process, but cancelling them can be arduous and confusing — causing many to resign and continue paying for services they no longer use. Making the cancellation process intentionally difficult is recognized as a dark pattern called Roach Motel. This paper characterizes the subscription and cancellation flows of popular news websites from four different countries, and discusses them in the context of recent regulatory changes. We study the design features that make it difficult to cancel a subscription and find several cancellation flows that feature intentional barriers, such as forcing users to call a representative or type in a phrase. Further, we find many subscription flows that do not adequately inform users about recurring charges. Our results point to a growing need for effective regulation of designs that trick, coerce, or manipulate users into paying for subscriptions they do not want. Ashley Sheil, Gunes Acar, Hanna Schraffenberger, Raphaël Gellert, David Malone |
CHI | 2 |
| 2024 | Targeted and Troublesome: Tracking and Advertising on Children's WebsitesabstractOn the modern web, trackers and advertisers frequently construct and monetize users’ detailed behavioral profiles without consent. Despite various studies on web tracking mechanisms and advertisements, there has been no rigorous study focusing on websites targeted at children. To address this gap, we present a measurement of tracking and (targeted) advertising on websites directed at children. Motivated by the lack of a comprehensive list of child-directed (i.e., targeted at children) websites, we first build a multilingual classifier based on web page titles and descriptions. Applying this classifier to over two million pages from the Common Crawl dataset, we compile a list of two thousand child-directed websites. Crawling these sites from five vantage points, we measure the prevalence of trackers, fingerprinting scripts, and advertisements. Our crawler detects ads displayed on child-directed websites and determines if ad targeting is enabled by scraping ad disclosure pages whenever available. Our results show that around 90% of child-directed websites embed one or more trackers, and about 27% contain targeted advertisements—a practice that should require verifiable parental consent. Next, we identify improper ads on child-directed websites by developing an ML pipeline that processes both images and text extracted from ads. The pipeline allows us to run semantic similarity queries for arbitrary search terms, revealing ads that promote services related to dating, weight loss, and mental health, as well as ads for sex toys and flirting chat services. Some of these ads feature repulsive, sexually-explicit and highly-inappropriate imagery. In summary, our findings indicate a trend of non-compliance with privacy regulations and troubling ad safety practices among many advertisers and child-directed websites. To ensure the protection of children and create a safer online environment, regulators and stakeholders must adopt and enforce more stringent measures. Keywords – online tracking, advertising, children, privacy Zahra Moti, Asuman Senol, Hamid Bostani, Frederik J. Zuiderveen Borgesius, Veelasha Moonsamy, Arunesh Mathur, Gunes Acar |
SP | 7 |
| 2022 | Leaky Forms: A Study of Email and Password Exfiltration Before Form Submission
Asuman Senol, Gunes Acar, Mathias Humbert, Frederik J. Zuiderveen Borgesius |
USENIX Security Symposium | 2 |
| 2022 | From "Onion Not Found" to Guard Discovery
Lennart Oldenburg, Gunes Acar, Claudia Díaz |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Privacy Policies over Time: Curation and Analysis of a Million-Document DatasetabstractAutomated analysis of privacy policies has proved a fruitful research direction, with developments such as automated policy summarization, question answering systems, and compliance detection. Prior research has been limited to analysis of privacy policies from a single point in time or from short spans of time, as researchers did not have access to a large-scale, longitudinal, curated dataset. To address this gap, we developed a crawler that discovers, downloads, and extracts archived privacy policies from the Internet Archive's Wayback Machine. Using the crawler and following a series of validation and quality control steps, we curated a dataset of 1,071,488 English language privacy policies, spanning over two decades and over 130,000 distinct websites. Our analyses of the data paint a troubling picture of the transparency and accessibility of privacy policies. By comparing the occurrence of tracking-related terminology in our dataset to prior web privacy measurements, we find that privacy policies have consistently failed to disclose the presence of common tracking technologies and third parties. We also find that over the last twenty years privacy policies have become even more difficult to read, doubling in length and increasing a full grade in the median reading level. Our data indicate that self-regulation for first-party websites has stagnated, while self-regulation for third parties has increased but is dominated by online advertising trade associations. Finally, we contribute to the literature on privacy regulation by demonstrating the historic impact of the GDPR on privacy policies. Ryan Amos, Gunes Acar, Eli Lucherini, Mihir Kshirsagar, Arvind Narayanan, Jonathan R. Mayer |
WWW | 2 |
| 2021 | The CNAME of the Game: Large-scale Analysis of DNS-based Tracking EvasionabstractAbstract Online tracking is a whack-a-mole game between trackers who build and monetize behavioral user profiles through intrusive data collection, and anti-tracking mechanisms that are deployed as browser extensions, DNS resolvers, or built-in to the browser. As a response to pervasive and opaque online tracking, more and more users adopt anti-tracking measures to preserve their privacy. Consequently, as the information that trackers can gather on users is being curbed, some trackers are looking for ways to evade these protections. In this paper we report on a large-scale longitudinal evaluation of an anti-tracking evasion scheme that leverages CNAME records to include tracker resources in a same-site context, which effectively bypasses anti-tracking measures that rely on fixed hostname-based block lists. Using historical HTTP Archive data we find that this tracking scheme is rapidly gaining traction, especially among high-traffic websites. Furthermore, we report on several privacy and security issues inherent to the technical setup of CNAME-based tracking that we detected through a combination of automated and manual analyses. We find that some trackers are using the technique against the Safari browser, which is known to include strict anti-tracking configurations. Our findings show that websites using CNAME trackers must take extra precautions to avoid leaking sensitive information to third parties. Yana Dimova, Gunes Acar, Lukasz Olejnik, Wouter Joosen, Tom van Goethem |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | No boundaries: data exfiltration by third parties embedded on web pagesabstractAbstract We investigate data exfiltration by third-party scripts directly embedded on web pages. Specifically, we study three attacks: misuse of browsers’ internal login managers, social data exfiltration, and whole-DOM exfiltration. Although the possibility of these attacks was well known, we provide the first empirical evidence based on measurements of 300,000 distinct web pages from 50,000 sites. We extend OpenWPM’s instrumentation to detect and precisely attribute these attacks to specific third-party scripts. Our analysis reveals invasive practices such as inserting invisible login forms to trigger autofilling of the saved user credentials, and reading and exfiltrating social network data when the user logs in via Facebook login. Further, we uncovered password, credit card, and health data leaks to third parties due to wholesale collection of the DOM. We discuss the lessons learned from the responses to the initial disclosure of our findings and fixes that were deployed by the websites, browser vendors, third-party libraries and privacy protection tools. Gunes Acar, Steven Englehardt, Arvind Narayanan |
Proc. Priv. Enhancing Technol. | 1 |
| 2019 | Watching You Watch: The Tracking Ecosystem of Over-the-Top TV Streaming DevicesabstractThe number of Internet-connected TV devices has grown significantly in recent years, especially Over-the-Top ("OTT") streaming devices, such as Roku TV and Amazon Fire TV. OTT devices offer an alternative to multi-channel television subscription services, and are often monetized through behavioral advertising. To shed light on the privacy practices of such platforms, we developed a system that can automatically download OTT apps (also known as channels), and interact with them while intercepting the network traffic and performing best-effort TLS interception. We used this smart crawler to visit more than 2,000 channels on two popular OTT platforms, namely Roku and Amazon Fire TV. Our results show that tracking is pervasive on both OTT platforms, with traffic to known trackers present on 69% of Roku channels and 89% of Amazon Fire TV channels. We also discover widespread practice of collecting and transmitting unique identifiers, such as device IDs, serial numbers, WiFi MAC addresses and SSIDs, at times over unencrypted connections. Finally, we show that the countermeasures available on these devices, such as limiting ad tracking options and adblocking, are practically ineffective. Based on our findings, we make recommendations for researchers, regulators, policy makers, and platform/app developers. Hooman Mohajeri Moghaddam, Gunes Acar, Ben Burgess, Arunesh Mathur, Danny Yuxing Huang, Nick Feamster, Edward W. Felten, Prateek Mittal, Arvind Narayanan |
CCS | 2 |
| 2019 | Dark Patterns at Scale: Findings from a Crawl of 11K Shopping WebsitesabstractDark patterns are user interface design choices that benefit an online service by coercing, steering, or deceiving users into making unintended and potentially harmful decisions. We present automated techniques that enable experts to identify dark patterns on a large set of websites. Using these techniques, we study shopping websites, which often use dark patterns to influence users into making more purchases or disclosing more information than they would otherwise. Analyzing ~53K product pages from ~11K shopping websites, we discover 1,818 dark pattern instances, together representing 15 types and 7 broader categories. We examine these dark patterns for deceptive practices, and find 183 websites that engage in such practices. We also uncover 22 third-party entities that offer dark patterns as a turnkey solution. Finally, we develop a taxonomy of dark pattern characteristics that describes the underlying influence of the dark patterns and their potential harm on user decision-making. Based on our findings, we make recommendations for stakeholders including researchers and regulators to study, mitigate, and minimize the use of these patterns. Arunesh Mathur, Gunes Acar, Michael Friedman, Eli Lucherini, Jonathan R. Mayer, Marshini Chetty, Arvind Narayanan |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2018 | The Web's Sixth Sense: A Study of Scripts Accessing Smartphone SensorsabstractWe present the first large-scale measurement of smartphone sensor API usage and stateless tracking on the mobile web. We extend the OpenWPM web privacy measurement tool to develop OpenWPM-Mobile, adding the ability to emulate plausible sensor values for different smartphone sensors such as motion, orientation, proximity and light. Using OpenWPM-Mobile we find that one or more sensor APIs are accessed on 3695 of the top 100K websites by scripts originating from 603 distinct domains. We also detect fingerprinting attempts on mobile platforms, using techniques previously applied in the desktop setting. We find significant overlap between fingerprinting scripts and scripts accessing sensor data. For example, 63% of the scripts that access motion sensors also engage in browser fingerprinting. To better understand the real-world uses of sensor APIs, we cluster JavaScript programs that access device sensors and then perform automated code comparison and manual analysis. We find a significant disparity between the actual and intended use cases of device sensor as drafted by W3C. While some scripts access sensor data to enhance user experience, such as orientation detection and gesture recognition, tracking and analytics are the most common use cases among the scripts we analyzed. We automated the detection of sensor data exfiltration and observed that the raw readings are frequently sent to remote servers for further analysis. Finally, we evaluate available countermeasures against the misuse of sensor APIs. We find that popular tracking protection lists such as EasyList and Disconnect commonly fail to block most tracking scripts that misuse sensors. Studying nine popular mobile browsers we find that even privacy-focused browsers, such as Brave and Firefox Focus, fail to implement mitigations suggested by W3C, which includes limiting sensor access from insecure contexts and cross-origin iframes. We have reported these issues to the browser vendors. Anupam Das 0001, Gunes Acar, Nikita Borisov, Amogh Pradeep |
CCS | 2 |
| 2017 | How Unique is Your .onion?: An Analysis of the Fingerprintability of Tor Onion ServicesabstractRecent studies have shown that Tor onion (hidden) service websites are particularly vulnerable to website fingerprinting attacks due to their limited number and sensitive nature. In this work we present a multi-level feature analysis of onion site fingerprintability, considering three state-of-the-art website fingerprinting methods and 482 Tor onion services, making this the largest analysis of this kind completed on onion services to date. Rebekah Overdorf, Marc Juarez, Gunes Acar, Rachel Greenstadt, Claudia Díaz |
CCS | 3 |
| 2014 | The Web Never Forgets: Persistent Tracking Mechanisms in the WildabstractWe present the first large-scale studies of three advanced web tracking mechanisms - canvas fingerprinting, evercookies and use of "cookie syncing" in conjunction with evercookies. Canvas fingerprinting, a recently developed form of browser fingerprinting, has not previously been reported in the wild; our results show that over 5% of the top 100,000 websites employ it. We then present the first automated study of evercookies and respawning and the discovery of a new evercookie vector, IndexedDB. Turning to cookie syncing, we present novel techniques for detection and analysing ID flows and we quantify the amplification of privacy-intrusive tracking practices due to cookie syncing. Gunes Acar, Christian Eubank, Steven Englehardt, Marc Juarez, Arvind Narayanan, Claudia Díaz |
CCS | 1 |
| 2014 | A Critical Evaluation of Website Fingerprinting AttacksabstractRecent studies on Website Fingerprinting (WF) claim to have found highly effective attacks on Tor. However, these studies make assumptions about user settings, adversary capabilities, and the nature of the Web that do not necessarily hold in practical scenarios. The following study critically evaluates these assumptions by conducting the attack where the assumptions do not hold. We show that certain variables, for example, user's browsing habits, differences in location and version of Tor Browser Bundle, that are usually omitted from the current WF model have a significant impact on the efficacy of the attack. We also empirically show how prior work succumbs to the base rate fallacy in the open-world scenario. We address this problem by augmenting our classification method with a verification step. We conclude that even though this approach reduces the number of false positives over 63\%, it does not completely solve the problem, which remains an open issue for WF attacks. Marc Juarez, Sadia Afroz 0001, Gunes Acar, Claudia Díaz, Rachel Greenstadt |
CCS | 3 |
| 2013 | FPDetective: dusting the web for fingerprintersabstractIn the modern web, the browser has emerged as the vehicle of choice, which users are to trust, customize, and use, to access a wealth of information and online services. However, recent studies show that the browser can also be used to invisibly fingerprint the user: a practice that may have serious privacy and security implications. Gunes Acar, Marc Juarez, Nick Nikiforakis, Claudia Díaz, Seda Gurses, Frank Piessens, Bart Preneel |
CCS | 1 |