Maryam Mehrnezhad

dblp:162/1901 · DBLP profile ↗
← Back
11ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0002-4223-6885ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 4 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 AXECC: Benchmarking the Privacy and Accessibility Impact of Browser Extensions
abstract
Browser extensions are commonly used to improve the browsing experience and accessibility. However, installing extensions naturally increases the user’s risk. This work presents AXECC , a novel framework for measuring the impact of web tracking and accessibility. The AXECC framework includes static, dynamic, and accessibility analyses across multiple web pages. We utilise the AXECC framework to analyse the web tracking and accessibility impact in the wild on 21k real-world extensions collected from the Chrome Web Store. In our analysis, we identify that 15.97% of extensions (with more than 600M users) perform a type of third–party tracking in the first 60 seconds after loading. These results are highly correlated with the extension category and are consistent across different web pages. Furthermore, we find that a small number of extensions (with 65M users) alter the accessibility of a web page when browsing, and these alterations are often complex and involve more tracking. Our work reveals a significant privacy risk from web tracking within popular browser extensions, often intertwined with complex accessibility alterations.
James M. Clarke, Maryam Mehrnezhad, Ehsan Toreini
ACM Trans. Priv. Secur.2
2025 PhotonKey: A key pairing system for IoT resource and input constrained devices using light sensors
abstract
IoT environments are in need of key pairing protocols capable of operating within the unique constraints present, namely storage , processing , input , and power . In this paper, we present PhotonKey , a system designed to facilitate the generation of identical cryptographic keys for two resource and input-constrained IoT devices. These keys are derived from the devices’ individual observations of a public light event. Our contributions also extend to a custom, cost-effective hardware solution termed a ‘Synchronisation Machine’, which introduces synchronous rotation patterns to the light-sensing-capable devices during data collection with mechanical precision. This hardware solution serves the dual purpose of facilitating data collection and reducing adversarial capabilities. We evaluate the performance of our system using a large dataset comprising over 1000 samples, far surpassing the scale seen in related works. Finally, we demonstrate PhotonKey’s ability to produce statistically random bit-streams and achieve 0% equal error rates, even in the face of an ‘impossibly well-performing’ adversary.
Danté Gray, Maryam Mehrnezhad
J. Inf. Secur. Appl.2
2023 Intimate Data: Exploring Perceptions of Privacy and Privacy-Seeking Behaviors Through the Story Completion Method
Diana P. Moniz, Maryam Mehrnezhad, Teresa Almeida
INTERACT (3)2
2022 "I feel invaded, annoyed, anxious and I may protect myself": Individuals' Feelings about Online Tracking and their Protective Behaviour across Gender and Country
Kovila P. L. Coopamootoo, Maryam Mehrnezhad, Ehsan Toreini
USENIX Security Symposium2
2022 User Privacy Concerns in Commercial Smart Buildings
abstract
Smart buildings are socio-technical systems that bring together building systems, IoT technology and occupants. A multitude of embedded sensors continually collect and share building data on a large scale which is used to understand and streamline daily operations. Much of this data is highly influenced by the presence of building occupants and could be used to monitor and track their location and activities. The combination of open accessibility to smart building data and the rapid development and enforcement of data protection legislation such as the GDPR and CCPA make the privacy of smart building occupants a concern. Until now, little if any research exists on occupant privacy in work-based or commercial smart buildings. This paper addresses this gap by conducting two user studies ( N = 81 and N = 40) on privacy concerns and preferences about smart buildings. The first study explores the perception of the occupants of a state-of-the-art commercial smart building, and the latter reflects on the concerns and preferences of a more general user group who do not use this building. Our results show that the majority of the participants are not familiar with the types of data being collected, that it is subtly related to them (only 19.75% of smart building residents (occupants) and 7.5% non-residents), nor the privacy risks associated with it. After being informed more about smart buildings and the data they collect, over half of our participants said that they would be concerned with how occupancy data is used. These findings show that despite the more public environment, there are similar levels of privacy concerns for some sensors to those living in smart homes. The participants called for more transparency in the data collection process and beyond, which means that better policies and regulations should be in place for smart building data.
Scott Harper, Maryam Mehrnezhad, John C. Mace
J. Comput. Secur.2
2022 How Can and Would People Protect From Online Tracking?
abstract
Abstract Online tracking is complex and users find it challenging to protect themselves from it. While the academic community has extensively studied systems and users for tracking practices, the link between the data protection regulations, websites’ practices of presenting privacy-enhancing technologies (PETs), and how users learn about PETs and practice them is not clear. This paper takes a multidimensional approach to find such a link. We conduct a study to evaluate the 100 top EU websites, where we find that information about PETs is provided far beyond the cookie notice. We also find that opting-out from privacy settings is not as easy as opting-in and becomes even more difficult (if not impossible) when the user decides to opt-out of previously accepted privacy settings. In addition, we conduct an online survey with 614 participants across three countries (UK, France, Germany) to gain a broad understanding of users’ tracking protection practices. We find that users mostly learn about PETs for tracking protection via their own research or with the help of family and friends. We find a disparity between what websites offer as tracking protection and the ways individuals report to do so. Observing such a disparity sheds light on why current policies and practices are ineffective in supporting the use of PETs by users.
Maryam Mehrnezhad, Kovila P. L. Coopamootoo, Ehsan Toreini
Proc. Priv. Enhancing Technol.1
2021 Caring for Intimate Data in Fertility Technologies
abstract
Fertility tracking applications are technologies that collect sensitive information about their users i.e. reproductive potential. For many, these apps are an affordable solution when trying to conceive or managing their pregnancy. However, intimate data are not only collected but also shared beyond users knowledge or consent. In this paper, we explore the privacy risks that can originate from the mismanagement, misuse, and misappropriation of intimate data, which are entwined in individual life events and in public health issues such as abortion and (in)fertility. We look at differential vulnerabilities to enquire data’s vulnerability and that of ‘data subjects’. We introduce the General Data Protection Regulation (GDPR) and how it addresses fertility data. We evaluate the privacy of 30 top ‘fertility apps’ through their privacy notices and tracking practices. Lastly, we discuss the regulations and fertility data as critical to the future design of tracking technologies and privacy rights.
Maryam Mehrnezhad, Teresa Almeida
CHI1
2021 The OpBench Ethereum opcode benchmark framework: Design, implementation, validation and experiments
Amjad Aldweesh, Maher Alharby, Maryam Mehrnezhad, Aad P. A. van Moorsel
Perform. Evaluation3
2019 SSR'19: The 5th Conference on Security Standardisation Research
abstract
The 5th conference on Security Standardisation Research (SSR'19) is in London, UK, on 11 November 2019, co-located with the ACM Conference on Computer and Communications Security 2019 (CCS'19). This conference aims to provide a preferred venue for the discussion of all topics related to security standardisation, covering both theory and practice. This year's program includes two invited keynote addresses to shed light on security standardisation from both industrial and academic perspectives, a panel discussion on blockchain standardisation and the presentation of seven original research papers selected from twenty submissions. The SSR'19 Conference Proceedings are available in the ACM DL at: https://dl.acm.org/citation.cfm?id=3338500.
Maryam Mehrnezhad, Thyla van der Merwe, Feng Hao 0001
CCS1
2016 TouchSignatures: Identification of user touch actions and PINs based on mobile sensor data via JavaScript
Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001
J. Inf. Secur. Appl.1
2015 TouchSignatures: Identification of User Touch Actions based on Mobile Sensors via JavaScript
abstract
Conforming to the recent W3C specifications (www.w3.org/TR/orientation-event), modern mobile web browsers generally allow JavaScript code in a web page to access motion and orientation sensor data without the user's permission. The associated risks to user privacy are however not considered in W3C specifications. In this work, for the first time, we show how user privacy can be compromised using device motion and orientation sensor data available in-browser, despite the fact that the data rate is 5 to 10 times slower than what is attainable in-app. We examine different browsers on the Android and iOS platforms and study their policies in granting permissions to JavaScript code with respect to access to motion and orientation sensor data and identify multiple vulnerabilities. Based on our findings, we propose TouchSignatures, implementation of an attack in which malicious JavaScript code on an inactive tab listens to such sensor data measurements. Based on these streams, TouchSignatures is able to distinguish the user's touch actions (e.g., tap, scroll, hold, and zoom) on an active tab, allowing the remote website to learn the client-side user activities. Finally, we demonstrate the practicality of this attack by collecting real-world user data and reporting high success rates using our proof-of-concept implementation.
Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001
AsiaCCS1