VLDB 2026 Research / reviewers in the wild / expert
Primal Wijesekera
dblp:162/0214
· DBLP profile ↗
16ranked-venue papers
3as first author
5since 2021 · last 2025
0000-0002-8241-3102ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-authorComputer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ZeTFRi - A Zero Trust-Based Free Rider Detection Framework for Next Generation Federated Learning NetworksabstractWith the rapid expansion of next-generation networking, Internet of Things (IoT) devices have become central components of federated learning (FL) networks. FL offers a paradigm for distributed training machine learning models while preserving user data privacy. However, existing network security measures often struggle to identify legitimate contributors from opportunistic free riders within these networks. The Free Rider (FR) problem arises when participants seek to benefit from the FL processes without contributing. In particular, free riders are known to exist within or outside of the network, whereas outside free riders can hardly be identified. The Zero Trust model proposes an environment where no entity, including the network itself, is inherently trusted, providing a foundation to counter external threats seeking to exploit the network. This study proposes a novel framework strengthened by the Zero Trust model to identify external free riders in FL networks. Leveraging a Deep Autoencoding Gaussian Mixture Model (DAGMM)-based technique for internal free rider detection, our framework demonstrates superior performance in identifying free riders across various FR scenarios compared to current state-of-the-art solutions. Through our proposed framework and the principles of Zero Trust, we establish a robust security guarantee for FL networks, ensuring the integrity of the learning process. Shehan Edirimannage, Ibrahim Khalil 0001, Charith Elvitigala, Wathsara Daluwatta, Primal Wijesekera, Albert Y. Zomaya |
IEEE J. Sel. Areas Commun. | 5 |
| 2024 | R+R: Matrioska: A User-Centric Defense Against Virtualization-Based Repackaging Malware on AndroidabstractThe Android virtualization technique allows an app to create independent virtual environments running on top of the Android native one, where multiple apps can be executed simultaneously. While the technique has legitimate uses, attackers have identified ways to exploit it. According to the state-of-art, virtualization-based malware is a significant threat: researchers have found 71,303 malicious samples. Defence mechanisms have already been developed to find virtualization-based malware and to detect or prevent virtualization-based repackaging attacks.In this paper, we offer three key contributions. First, we experimentally evaluate the existing defence mechanisms by identifying their limitations and demonstrating how they can be bypassed. Second, we design and develop a new defence mechanism, called Matrioska, that overcomes the limitations of the state-of-art by detecting the intrinsic features of the virtualization technique. Third, we evaluate the effectiveness of Matrioska with respect to the state-of-art against two datasets of apps. Overall, Matrioska achieves a higher accuracy (99% vs. 71%) when searching for virtualization usage and a lower false positive (10 vs. 23) and false negative rate (14 vs. 39) when detecting a virtualization-based repackaging attack. Simone Zerbini, Samuele Doria, Primal Wijesekera, Serge Egelman, Eleonora Losiouk |
ACSAC | 3 |
| 2024 | QARMA-FL: Quality-Aware Robust Model Aggregation for Mobile CrowdsourcingabstractOver the past few years, the improved detection and processing features of Internet-of-Things (IoT) devices have opened the doors to several mobile crowdsourcing applications. Federated Learning (FL) is being seen as an attractive framework to address the data privacy concerns of mobile users in the context of crowdsourcing. In FL on a crowdsourcing platform, constructing an effective deep neural network (DNN) is challenging. This is primarily because the quality of the global model depends on the local model quality, which can vary greatly due to differences in the computational resources, data quantity, and data quality provided by each worker. To address these challenges, we propose QARMA-FL: Quality-aware robust model aggregation for federated learning in crowdsourcing applications, where we select the local model for aggregation based on its quality and performance. We also propose a model-quality-aware incentive mechanism to reward workers, based on their contribution to model training. Our model selection and incentive mechanism is capable of detecting Free Rider attacks, identifying workers who benefit from others contributions without contributing themselves. Most existing evaluations of FL in mobile crowdsourcing studies are not based on the real-world FL scenarios. Therefore, we evaluate QARMA-FL alongside a baseline FL model in a quantity-skew, non-IID data setup where different workers contribute varying amounts of data for model training. Our diverse experiments validated QARMA-FLs performance, demonstrating its ability to efficiently aggregate models in mobile crowdsourcing scenarios, reaching baseline results with a reduced worker participation by 40% to 60%. Shehan Edirimannage, Charith Elvitigala, Ibrahim Khalil 0001, Primal Wijesekera, Xun Yi |
IEEE Internet Things J. | 4 |
| 2023 | Lessons in VCR Repair: Compliance of Android App Developers with the California Consumer Privacy Act (CCPA)abstractThe California Consumer Privacy Act (CCPA) provides California residents with a range of enhanced privacy protections and rights. Our research investigated the extent to which Android app developers comply with the provisions of the CCPA that require them to provide consumers with accurate privacy notices and respond to "verifiable consumer requests" (VCRs) by disclosing personal information that they have collected, used, or shared about consumers for a business or commercial purpose. We compared the actual network traffic of 109 apps that we believe must comply with the CCPA to the data that apps state they collect in their privacy policies and the data contained in responses to "right to know" requests that we submitted to the app's developers. Of the 69 app developers who substantively replied to our requests, all but one provided specific pieces of personal data (as opposed to only categorical information). However, a significant percentage of apps collected information that was not disclosed, including identifiers (55 apps, 80%), geolocation data (21 apps, 30%), and sensory data (18 apps, 26%) among other categories. We discuss improvements to the CCPA that could help app developers comply with "right to know" requests and other related regulations. Nikita Samarin, Shayna Kothari, Zaina Siyed, Oscar Bjorkman, Reena Yuan, Primal Wijesekera, Noura Alomar, Jordan Fischer, Chris Jay Hoofnagle, Serge Egelman |
Proc. Priv. Enhancing Technol. | 6 |
| 2021 | Demo: Large Scale Analysis on Vulnerability Remediation in Open-source JavaScript ProjectsabstractGiven the widespread prevalence of vulnerabilities, remediation is a critical phase that every software project has to go through. When comparing the studies on understanding the security vulnerabilities in software, such as vulnerability discovery and patterns, there is a lack of studies on the vulnerability remediation phase. To address this, we have done a timeline analysis for 130 of the most dependent upon open source projects written in JavaScript language, hosted on GitHub to understand the nature and the lifetime of the vulnerabilities in those projects. We used a static code analyzer on 501K commits from the repositories to identify commits that introduced new vulnerabilities to the code and fixed existing vulnerabilities in the code. In 90% of the projects, we identified that a commit that fixed an existing vulnerability had introduced one or more new vulnerabilities into the code. On average, 16% of the commits intended to fix vulnerabilities have introduced one or more new vulnerabilities from the analyzed projects. We also found that 18% of the total vulnerabilities found in those projects have originated from a commit meant to fix an existing vulnerability, and 78% of those vulnerabilities could have been avoided of introduction if the developers were to use proper internal testing. Here, we demonstrate Sequza, a visualization tool to help organizations detect such instances at the earliest possible. Vinuri Bandara, Thisura Rathnayake, Nipuna Weerasekara, Charith Elvitigala, Kenneth Thilakarathna, Primal Wijesekera, Kasun De Zoysa, Chamath Keppitiyagama |
CCS | 6 |
| 2020 | Investigating MMM Ponzi Scheme on BitcoinabstractCybercriminals exploit cryptocurrencies to carry out illicit activities. In this paper, we focus on Ponzi schemes that operate on Bitcoin and perform an in-depth analysis of MMM, one of the oldest and most popular Ponzi schemes. Based on 423K transactions involving 16K addresses, we show that: (1) Starting Sep 2014, the scheme goes through three phases over three years. At its peak, MMM circulated more than 150M dollars a day, after which it collapsed by the end of Jun 2016. (2) There is a high income inequality between MMM members, with the daily Gini index reaching more than 0.9. The scheme also exhibits a zero-sum investment model, in which one member's loss is another member's gain. The percentage of victims who never made any profit has grown from 0% to 41% in five months, during which the top-earning scammer has made 765K dollars in profit. (3) The scheme has a global reach with 80 different member countries but a highly-asymmetrical flow of money between them. While India and Indonesia have the largest pairwise flow in MMM, members in Indonesia have received 12x more money than they have sent to their counterparts in India. Yazan Boshmaf, Charith Elvitigala, Husam Al Jawaheri, Primal Wijesekera, Mashael Al Sabah |
AsiaCCS | 4 |
| 2020 | Fix that Fix Commit: A real-world remediation analysis of JavaScript projectsabstractWhile there is a large body of work on understanding vulnerabilities in the wild, little has been done to understand the dynamics of the remediation phase of the development cycle. To this end, we have done a timeline analysis on 118K commits from 53 of the most used JavaScript projects from GitHub to understand the provenance and prevalence of vulnerabilities in those projects. We used a vulnerability detector (CodeQL) to filter commits that introduced vulnerabilities and the commits that fixed a prior vulnerability. We found that in 82% of the projects, a commit fixing a prior vulnerability, in turn, introduced one or more new vulnerabilities. Among those projects, on average, 18% of the commits intended to fix vulnerabilities, in turn, introduced one or more new vulnerabilities. We also found that 50% of the total vulnerabilities found in those projects originated from a commit meant to fix a prior vulnerability, and 78% of those vulnerabilities could have been avoided if they were to use proper internal testing. We provide critical insights into how proper internal testing can avoid a significant portion of vulnerabilities, increasing organizations' security posture. Vinuri Bandara, Thisura Rathnayake, Nipuna Weerasekara, Charith Elvitigala, Kenneth Thilakarathna, Primal Wijesekera, Chamath Keppitiyagama |
SCAM | 6 |
| 2020 | The Price is (Not) Right: Comparing Privacy in Free and Paid AppsabstractAbstract It is commonly assumed that “free” mobile apps come at the cost of consumer privacy and that paying for apps could offer consumers protection from behavioral advertising and long-term tracking. This work empirically evaluates the validity of this assumption by comparing the privacy practices of free apps and their paid premium versions, while also gauging consumer expectations surrounding free and paid apps. We use both static and dynamic analysis to examine 5,877 pairs of free Android apps and their paid counterparts for differences in data collection practices and privacy policies between pairs. To understand user expectations for paid apps, we conducted a 998-participant online survey and found that consumers expect paid apps to have better security and privacy behaviors. However, there is no clear evidence that paying for an app will actually guarantee protection from extensive data collection in practice. Given that the free version had at least one thirdparty library or dangerous permission, respectively, we discovered that 45% of the paid versions reused all of the same third-party libraries as their free versions, and 74% of the paid versions had all of the dangerous permissions held by the free app. Likewise, our dynamic analysis revealed that 32% of the paid apps exhibit all of the same data collection and transmission behaviors as their free counterparts. Finally, we found that 40% of apps did not have a privacy policy link in the Google Play Store and that only 3.7% of the pairs that did reflected differences between the free and paid versions. Catherine Han, Irwin Reyes, Álvaro Feal, Joel Reardon, Primal Wijesekera, Narseo Vallina-Rodriguez, Amit Elazari Bar On, Kenneth A. Bamberger, Serge Egelman |
Proc. Priv. Enhancing Technol. | 5 |
| 2019 | 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions System
Joel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On, Narseo Vallina-Rodriguez, Serge Egelman |
USENIX Security Symposium | 3 |
| 2019 | Privacy Attitudes of Smart Speaker UsersabstractAbstract As devices with always-on microphones located in people’s homes, smart speakers have significant privacy implications. We surveyed smart speaker owners about their beliefs, attitudes, and concerns about the recordings that are made and shared by their devices. To ground participants’ responses in concrete interactions, rather than collecting their opinions abstractly, we framed our survey around randomly selected recordings of saved interactions with their devices. We surveyed 116 owners of Amazon and Google smart speakers and found that almost half did not know that their recordings were being permanently stored and that they could review them; only a quarter reported reviewing interactions, and very few had ever deleted any. While participants did not consider their own recordings especially sensitive, they were more protective of others’ recordings (such as children and guests) and were strongly opposed to use of their data by third parties or for advertising. They also considered permanent retention, the status quo, unsatisfactory. Based on our findings, we make recommendations for more agreeable data retention policies and future privacy controls. Nathan Malkin, Joe Deatrick, Allen Tong, Primal Wijesekera, Serge Egelman, David A. Wagner 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2018 | Contextualizing Privacy Decisions for Better Prediction (and Protection)abstractModern mobile operating systems implement an ask-on-first-use policy to regulate applications' access to private user data: the user is prompted to allow or deny access to a sensitive resource the first time an app attempts to use it. Prior research shows that this model may not adequately capture user privacy preferences because subsequent requests may occur under varying contexts. To address this shortcoming, we implemented a novel privacy management system in Android, in which we use contextual signals to build a classifier that predicts user privacy preferences under various scenarios. We performed a 37-person field study to evaluate this new permission model under normal device usage. From our exit interviews and collection of over 5 million data points from participants, we show that this new permission model reduces the error rate by 75% (i.e., fewer privacy violations), while preserving usability. We offer guidelines for how platforms can better support user privacy decision making. Primal Wijesekera, Joel Reardon, Irwin Reyes, Lynn Tsai, Jung-Wei Chen, Nathaniel Good, David A. Wagner 0001, Konstantin Beznosov, Serge Egelman |
CHI | 1 |
| 2018 | "Won't Somebody Think of the Children?" Examining COPPA Compliance at ScaleabstractAbstract We present a scalable dynamic analysis framework that allows for the automatic evaluation of the privacy behaviors of Android apps. We use our system to analyze mobile apps’ compliance with the Children’s Online Privacy Protection Act (COPPA), one of the few stringent privacy laws in the U.S. Based on our automated analysis of 5,855 of the most popular free children’s apps, we found that a majority are potentially in violation of COPPA, mainly due to their use of thirdparty SDKs. While many of these SDKs offer configuration options to respect COPPA by disabling tracking and behavioral advertising, our data suggest that a majority of apps either do not make use of these options or incorrectly propagate them across mediation SDKs. Worse, we observed that 19% of children’s apps collect identifiers or other personally identifiable information (PII) via SDKs whose terms of service outright prohibit their use in child-directed apps. Finally, we show that efforts by Google to limit tracking through the use of a resettable advertising ID have had little success: of the 3,454 apps that share the resettable ID with advertisers, 66% transmit other, non-resettable, persistent identifiers as well, negating any intended privacy-preserving properties of the advertising ID. Irwin Reyes, Primal Wijesekera, Joel Reardon, Amit Elazari Bar On, Abbas Razaghpanah, Narseo Vallina-Rodriguez, Serge Egelman |
Proc. Priv. Enhancing Technol. | 2 |
| 2017 | Turtle Guard: Helping Android Users Apply Contextual Privacy Preferences
Lynn Tsai, Primal Wijesekera, Joel Reardon, Irwin Reyes, Serge Egelman, David A. Wagner 0001, Nathaniel Good, Jung-Wei Chen |
SOUPS | 2 |
| 2017 | The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesabstractCurrent smartphone operating systems regulate application permissions by prompting users on an ask-on-first-use basis. Prior research has shown that this method is ineffective because it fails to account for context: the circumstances under which an application first requests access to data may be vastly different than the circumstances under which it subsequently requests access. We performed a longitudinal 131-person field study to analyze the contextuality behind user privacy decisions to regulate access to sensitive resources. We built a classifier to make privacy decisions on the user's behalf by detecting when context has changed and, when necessary, inferring privacy preferences based on the user's past decisions and behavior. Our goal is to automatically grant appropriate resource requests without further user intervention, deny inappropriate requests, and only prompt the user when the system is uncertain of the user's preferences. We show that our approach can accurately predict users' privacy decisions 96.8% of the time, which is a four-fold reduction in error rate compared to current systems. Primal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon, Serge Egelman, David A. Wagner 0001, Konstantin Beznosov |
IEEE Symposium on Security and Privacy | 1 |
| 2016 | Decoupling data-at-rest encryption and smartphone locking with wearable devices
Ildar Muslukhov, San-Tsai Sun, Primal Wijesekera, Yazan Boshmaf, Konstantin Beznosov |
Pervasive Mob. Comput. | 3 |
| 2015 | Android Permissions Remystified: A Field Study on Contextual Integrity
Primal Wijesekera, Arjun Baokar, Ashkan Hosseini, Serge Egelman, David A. Wagner 0001, Konstantin Beznosov |
USENIX Security Symposium | 1 |