Michiel Willocx

dblp:167/3576 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
9since 2021 · last 2025
0000-0003-0225-9705ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 1 first-author · 8 since 2021
YearPublicationVenuePosition
2025 Big Broker is Tracking You! A Privacy Assessment of Large-Scale Location Trace Datasets
abstract
Large-scale location trace datasets are being col-lected by data brokers and sold for significant financial gains. These datasets are collected continuously through background services in smartphone applications, typically without users' in-formed consent. While businesses leverage these data to derive valuable crowd insights, it raises profound privacy concerns for individuals. When such datasets fall into the hands of malicious actors, large-scale blackmail, coercion, and extortion schemes can be set up. This paper demonstrates the risks posed by large-scale location trace datasets, demonstrating how adversaries can exploit them to: (i) infer sensitive personal locations, such as home and workplace addresses, (ii) reveal the identity behind the traces, and (iii) construct social graphs by linking the location traces of multiple individuals. Our research is unique compared to related work in the sense that it is the first in-depth privacy assessment of five large-scale datasets purchased from two different data brokers that collect accurate location traces without informed consent on a continuous basis. Multiple experiments demonstrate the feasibility, magnitude and practical impact of diverse privacy attacks. Finally, we highlight realistic abuse scenarios, and propose solutions to mitigate these privacy concerns.
Kevin De Boeck, Jenno Verdonck, Michiel Willocx, Vincent Naessens
ACSAC3
2025 Advanced Strategies for Privacy Preserving Data Publishing to Improve Multi-class Classification
Tibo Laperre, Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Vincent Naessens
SEC (1)4
2024 Compromising anonymity in identity-reserved k-anonymous datasets through aggregate knowledge
abstract
Data processors increasingly rely on external data sources to improve strategic or operational decision taking. Data owners can facilitate this by releasing datasets directly to data processors or doing so indirectly via data spaces. As data processors often have different needs and due to the sensitivity of the data, multiple anonymized versions of an original dataset are often released. However, doing so can introduce severe privacy risks.
Kevin De Boeck, Jenno Verdonck, Michiel Willocx, Jorn Lapon, Vincent Naessens
ARES3
2024 Advanced methods for generalizing time and duration during dataset anonymization
abstract
Time is an often recurring quasi-identifying attribute in many datasets. Anonymizing such datasets requires generalizing the time attribute(s) in the dataset. Examples are start dates and durations, which are traditionally generalized leading to intervals that do not embrace the relation between time attributes. This paper presents advanced methods for creating generalization hierarchies for time data. We propose clustering-based and Mondrian-based techniques to construct generalization hierarchies. These approaches take into account the relation between different time attributes and are designed to improve the utility of the anonymized data. We implemented these methods and conducted a set of experiments comparing them to traditional generalization strategies. The results show that our proposed methods improve the utility of the data for both statistical analysis and machine learning applications. Our approach demonstrates a significant increase in hierarchy quality and configuration flexibility, demonstrating the potential of our advanced techniques over existing methods.
Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Vincent Naessens
ARES3
2024 Value for Money: An Experimental Comparison of Cloud Pricing and Performance
abstract
Organizations increasingly rely on cloud providers for computation intensive tasks. This study executes computation expensive experiments in five cloud environments with a substantial market share. More specifically, we selected the big three and two representative European counterparts. By means of the experiments, we aim at comparing and assessing their value for money with respect to computational intensive tasks. The paper focuses on three aspects with high interest of industrial stakeholders, namely (a) the impact of server location and time of day on performance, (b) the computational efficiency in relation to costs, and (c) a comparison between European service providers and the big three in the cloud space.
Michiel Willocx, Ilse Bohé, Vincent Naessens
CLOSER1
2023 Linux-based IoT Benchmark Generator For Firmware Security Analysis Tools
abstract
There is a growing interest of IoT manufacturers to incorporate firmware analysis tools in their development pipeline to evaluate the security of new embedded devices. This has the advantage of discovering security issues before the device is marketed. However, each device has its own design, including different architectures, services and communication protocols, programmed and configured in different programming languages. This diversity results in potentially complete categories of vulnerabilities discarded by the firmware security analysis tools. Hence, a positive outcome of such tools may result in incorrect conclusions.
Dairo de Ruck, Victor Goeman, Michiel Willocx, Jorn Lapon, Vincent Naessens
ARES3
2023 A hybrid anonymization pipeline to improve the privacy-utility balance in sensitive datasets for ML purposes
abstract
The modern world is data-driven. Businesses increasingly take strategic decisions based on customer data, and companies are founded with a sole focus of performing machine-learning driven data analytics for third parties. External data sources containing sensitive records are often required to build qualitative machine learning models and, hence, perform accurate and meaningful predictions. However, exchanging sensitive datasets is no sinecure. Personal data must be managed according to privacy regulation. Similarly, loss of strategic data can negatively impact the competitiveness of a company. In both cases, dataset anonymization can overcome the aforementioned obstacles.
Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Jorn Lapon, Vincent Naessens
ARES3
2022 Reviewing review platforms: a privacy perspective
abstract
Many tourists heavily rely on online review platforms for decisions with respect to food, visits and hotel bookings today. Review communities rigorously log all experiences on popular online platforms such as Google Maps, Tripadvisor and Yelp. However, many contributors are unaware that, along with experiences, a lot of sensitive information is often indirectly exposed to platform visitors. Examples are reviewer’s locations in the privacy sphere, age, medical information and financial status. Malicious entities could potentially employ this information in various ways, for example during extortion or targeted phishing attempts. This work outlines the potential risks for contributors on review platforms. The Google Maps review platform is applied as a prototypical example, with a special focus on predicting the reviewer’s home location. The accuracy of our predictions is assessed by relying on ground truth datasets. This paper further presents and evaluates strategies to tackle common problems.
Kevin De Boeck, Jenno Verdonck, Michiel Willocx, Jorn Lapon, Vincent Naessens
ARES3
2021 A clustering approach to anonymize locations during dataset de-identification
abstract
Companies increasingly rely on massive amounts of data for strategic decision making purposes. In order to optimize business intelligence, companies often try to enrich their models with datasets acquired from third parties. Datasets containing sensitive attributes must be anonymized before release. For large datasets containing microdata, an often applied anonymization technique is data generalization with the goal of achieving privacy metrics such as k-anonymity. Location is an often recurring yet strategic attribute in many use cases. Multiple strategies can be employed to obfuscate precise coordinates. For example, the most significant digits can be dropped or their value can be replaced by a ZIP code. While these methods might be useful in some applications, these approaches often result in too much information loss, undermining strategic decision making. This paper proposes a novel approach to anonymize location by means of clustering. Its feasibility is evaluated and compared to traditional techniques.
Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Jorn Lapon, Vincent Naessens
ARES3
2017 Security Analysis of Cordova Applications in Google Play
abstract
Mobile Cross-Platform Tools (CPTs) provide an alternative to native application development that allows mobile app developers to drastically reduce the development time and cost when targeting multiple platforms. They allow sharing a significant part of the application codebase between the implementations for the targeted platforms (e.g. Android, iOS, Windows Phone). Although CPTs provide significant benefits for developers, there can introduce several disadvantages. The CPT software layers and translation steps can impact the security of the produced applications. One of the most well-known and often-used CPTs is Cordova, formerly known as PhoneGap. Cordova has, over the years, taken several steps to reduce the attack surface and introduced several mechanisms that allow developers to increase the security of Cordova applications. This paper gives a statistical overview of the adoption of Cordova security best practices and mechanisms in Cordova applications downloaded from the Google Play Store. For the analysis, over a thousand Cordova application were downloaded. The research shows that the poor adoption of these mechanisms leads to a significant number of insecure Cordova applications.
Michiel Willocx, Jan Vossaert, Vincent Naessens
ARES1