Abhishek Kumar Mishra 0001

dblp:167/8911-1 · DBLP profile ↗
← Back
14ranked-venue papers
9as first author
14since 2021 · last 2026
0000-0003-1778-6794ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 5 first-author · 6 since 2021Security and privacy · 6 · 3 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 How Tough Is Location Anonymization? Re-identifying 100K Real-User Trajectories in Japan
abstract
Mobility traces are among the most revealing forms of personal data, yet trajectory releases are often protected only by ad hoc transformations. We stress-test such practices on recently-released YJMob100K, an anonymized dataset of 100,000 user trajectories in Japan. First, we show that the applied protection leaves enough spatial and temporal structure to recover both the real-world geographic frame and the actual calendar timeline by exploiting density signatures, urban correlations, and temporal activity profiles. On top of this reconstruction, we quantify privacy risks through trajectory-level metrics that capture spatio-temporal k-anonymity, m-point unicity, home-work and multi-anchor uniqueness, and exposure to secluded and sensitive locations. These metrics reveal extensive re-identification surfaces: a small number of observations, anchors, or sensitive venues often suffices to uniquely pinpoint users or their social neighborhoods. Finally, we evaluate representative sanitization strategies: geo-indistinguishability, local differential privacy, and aggressive spatial de-structuring; and observe a consistent pattern: strong privacy parameters destroy downstream utility, while utility-preserving settings leave structural leakage largely intact. Overall, our findings show that current sanitization techniques are insufficient for large-scale mobility data, and they highlight the urgent need for trajectory-aware privacy mechanisms and stronger publication standards.
Abhishek Kumar Mishra 0001, Mathieu Cunche, Héber Hwang Arcolezi
AsiaCCS1
2026 k-scale: k-Anonymizing Millions of Trajectories
abstract
Trajectory datasets collected by network operators and service providers offer detailed information about individual mobility and have wide application in business and research. However, managing such data raises privacy risks, as the unique movement patterns of individuals pose significant re-identification risks and make common countermeasures like pseudonymization ineffective. The privacy-preserving data publishing (PPDP) of trajectory datasets that maintains post-anonymization accuracy and truthfulness is an open problem -especially for large datasets with millions of records like those gathered by major actors in the telco ecosystem. We close this gap with k-scale, a framework that implements k-anonymity in massive mobile user trajectory datasets, removing uniqueness while safeguarding accuracy at the record level. Not only k-scale is the first model capable of scaling k-anonymization to a dataset of one million trajectories, but it does so while also outperforming state-of-the-art methods for trajectory data publishing in terms of preserved data quality, which we prove in real-world massive datasets and applications.
Abhishek Kumar Mishra 0001, Marco Fiore 0001
INFOCOM1
2026 StateFi: Effectively Identifying Wi-Fi Devices through State Transitions
abstract
Randomized MAC addresses aim to prevent passive device tracking, yet Wi-Fi management frames still leak structured behavioral patterns. Prior work has relied primarily on syntactic probe-request features such as Information Elements (IEs), sequence numbers (SEQ), or RSSI correlations, which degrade in dense environments and fail under aggressive randomization. We introduce StateFi, a fingerprinting framework that models device behavior as finite-state machines (FSMs), capturing both structural transition patterns and temporal execution logic. These FSMs are embedded into compact feature vectors that support efficient similarity computation and supervised classification. Across five heterogeneous campus environments, StateFi achieves 94-97% accuracy for in-network fingerprinting using full management-frame FSMs. With probe-only FSMs, it re-identifies devices under MAC randomization with up to 97% accuracy across large public datasets comprising more than a million frames. When looking at the discrimination accuracy of the model, StateFi reaches 98%, outperforming the strongest prior signature by up to 17 percentage points. These results demonstrate that FSM-level behavioral dynamics form a powerful and largely unmitigated side channel, stable enough to defeat randomization and expressive enough for robust, scalable device identification.
Abhishek Kumar Mishra 0001, Mathieu Cunche
WISEC1
2026 From Lookup to Lockdown: DNS Guidelines for Securing IoT Ecosystems
abstract
The Domain Name System (DNS) serves as a fundamental component of Internet infrastructure; however, its frequently overlooked role in consumer Internet of Things (IoT) ecosystems exposes significant security vulnerabilities and operational challenges. This paper analyzes DNS behavior in consumer IoT devices and reveals widespread inconsistencies that undermine operational efficiency, resilience, and security. We construct a representative testbed spanning a heterogeneous set of IoT devices and employ both passive traffic monitoring and active experimentation to identify vulnerabilities, including cache poisoning, predictable transaction IDs, non-randomized source ports, and limited adoption of secure DNS protocols such as DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and Domain Name System Security Extensions (DNSSEC). We observe erratic operational patterns, such as excessive querying, poor adherence to TTL values, and overreliance on hard-coded resolvers, that amplify exposure to fingerprinting and denial-of-service attacks. Our findings demonstrate a concerning lack of standardized DNS practices across the IoT ecosystem. We conclude by proposing actionable guidelines to harden DNS handling in IoT devices and improve security, interoperability, and network stability as the consumer IoT landscape continues to expand.
Andrew Losty, Abhishek Kumar Mishra 0001, Mathieu Cunche, Anna Maria Mandalari
IEEE Internet Things J.2
2025 QRisk: Think Before You Scan QR Codes
Abhishek Kumar Mishra 0001, Guillaume Gagnon, Mathieu Cunche, Sébastien Gambs
ARES (2)1
2025 Demo: Exploring Utility and Attackability Trade-offs in Local Differential Privacy
abstract
Local Differential Privacy (LDP) provides strong, formal privacy guarantees without requiring a trusted curator, making it a promising approach for privacy-preserving data collection and analysis. However, despite extensive research, practitioners may struggle to understand how to tune LDP parameters and anticipate the impact on data utility and attack risks for their specific scenarios. To address this gap, we demonstrate LDP-Toolbox, the first interactive, web-based toolbox (implemented in Python) that enables practical, analytical visualization of trade-offs between privacy loss (ε), utility loss, and vulnerability to attacks. The toolbox supports exploration of these trade-offs using real-world datasets from different domains; in this demonstration, we focus on discrete personal attributes and location-based scenarios. By providing intuitive, visual insights, LDP-Toolbox lowers the barrier to deploying LDP in real applications and helps bridge the gap between theoretical guarantees and practical adoption. The toolbox is open-source on PyPI (https://pypi.org/project/ldp-toolbox) and a video is available on our GitHub repository (https://github.com/hharcolezi/ldp-toolbox).
Haoying Zhang, Abhishek Kumar Mishra 0001, Héber Hwang Arcolezi
CCS2
2025 Efficiently linking LoRaWAN identifiers through multi-domain fingerprinting
abstract
LoRaWAN is a leading IoT technology worldwide, increasingly integrated into pervasive computing environments through a growing number of sensors in various industrial and consumer applications. Although its security vulnerabilities have been extensively explored in the recent literature, its ties to human activities warrant further privacy research. Existing device identification and activity inference attacks are only effective with a stable identifier. We find that the identifiers in LoRaWAN exhibit high variability, and more than half of the devices use them for less than a week. For the first time in the literature, we explore the feasibility of device fingerprinting in LoRaWAN, allowing long-term device linkage, i.e. associating various identifiers of the same device. We introduce a novel holistic fingerprint representation utilizing multiple domains, namely content, timing, and radio information, and present a machine learning-based solution for linking identifiers. Through a large-scale experimental evaluation based on real-world datasets containing up to 41 million messages, we study multiple scenarios, including an attacker with limited resources. We reach 0.98 linkage accuracy, underscoring the need for privacy-preserving measures. We showcase countermeasures including payload padding, random delays, and radio signal modulation, and conclude by assessing their impact on our fingerprinting solution.
Samuel Pélissier, Abhishek Kumar Mishra 0001, Mathieu Cunche, Vincent Roca, Didier Donsez
Pervasive Mob. Comput.2
2024 Third Eye: Inferring the State of Your Smartphone Through Wi-Fi
abstract
Wi-Fi is one of the most notable and prevalent wireless technologies today. Smartphones and other Wi-Fi-enabled devices find nearby networks using management frames known as probe-requests. In this paper, we infer the state of smartphones by passively monitoring their transmitted probe-requests. We leverage the differential behaviour of probe-request bursts and their content, based on their device states such as active/static screen and Wi-Fi/power-saving mode ON/OFF. We use a Random Forest based approach that can successfully predict smartphone states just leveraging individual bursts. Based on an evaluation using a real-world dataset of more than 200 smartphones (having a variety of operating systems), with ground truth data available, we show that our model reliably predicts states with accuracy ≥ 98%.
Abhishek Kumar Mishra 0001, Mathieu Cunche
LCN1
2024 Enhancing IoT Privacy: Why DNS-over-HTTPS Alone Falls Short?
abstract
Recent years have seen widespread adoption of consumer Internet of Things (IoT) devices, offering diverse benefits to end-users, from smart homes to healthcare monitoring, but raising serious privacy concerns. To address this, securing efforts, such as encrypting DNS, have been proposedIn this paper, we study the effectiveness of such measures in the specific context of ensuring IoT privacy. We introduce a device identification attack against DNS-over-HTTPS-enabled IoT devices. We conduct more than 25,000 automated experiments across 6 public DNS resolvers and find that the proposed attack can identify devices via DNS-over-HTTPS (DoH) traffic with a 0.98 balanced accuracy. We point out padding as a mitigation technique that reduces identification by a significant 33%. Additionally, we find that half of the evaluated DNS resolvers do not adhere to the relevant specification, substantially compromising user privacy.
Samuel Pélissier, Gianluca Anselmi, Abhishek Kumar Mishra 0001, Anna Maria Mandalari, Mathieu Cunche
TrustCom3
2024 Privacy-Preserving Pseudonyms for LoRaWAN
abstract
LoRaWAN, a widely deployed LPWAN protocol, raises privacy concerns due to metadata exposure, particularly concerning the exploitation of stable device identifiers. For the first time in literature, we propose two privacy-preserving pseudonym schemes tailored for LoRaWAN: resolvable pseudonyms and sequential pseudonyms. We extensively evaluate their performance and applicability through theoretical analysis and simulations based on a large-scale real-world dataset of 71 million messages. We conclude that sequential pseudonyms are the best solution.
Samuel Pélissier, Jan Aalmoes, Abhishek Kumar Mishra 0001, Mathieu Cunche, Vincent Roca, Didier Donsez
WISEC3
2024 Bleach: From WiFi probe-request signatures to MAC association
Abhishek Kumar Mishra 0001, Aline Carneiro Viana, Nadjib Achir
Ad Hoc Networks1
2023 Introducing benchmarks for evaluating user-privacy vulnerability in WiFi
abstract
WiFi-based crowdsensing is a major source of data in a variety of domains such as human-mobility, pollution-level estimation, and, opportunistic networks. MAC randomisation is a backbone for preserving user-privacy in WiFi, as devices change their identifiers (MAC addresses). MAC association frameworks in the literature are able to associate randomized MAC addresses with a device. Such frameworks facilitate the continuation and validity of works based on device-based identifiers. In this paper, we first question and verify the reliability of these frameworks with respect to the datasets (scenarios) used for their validation. Indeed, we observe a substantial discrepancy between the performances obtained by these frameworks when confronting them with different contextual environments. We identify that the device heterogeneity in the input scenario is privacy-preserving. Henceforth, we propose a novel metric: randomization complexity, capable of successfully catching the degree of randomization in evaluated datasets. Existing and new frameworks can thus be benchmarked using this metric to ensure their reliability for any datasets with similar or lower randomization complexities. Finally, we open discussions on the potential impact of the benchmarks in the domain of MAC randomization.
Abhishek Kumar Mishra 0001, Aline Carneiro Viana, Nadjib Achir
VTC2023-Spring1
2023 Do WiFi Probe-Requests Reveal Your Trajectory?
abstract
In this paper, we propose the first framework that introduces the concept of the user’s bounded trajectory. We propose to leverage the signal strength of users’ public WiFi probe requests collected from measurements of multiple deployed WiFi sniffers. First, we investigate and characterize errors in RSSI-based radial-distance (between the user and each sniffer) estimation. Then, we approximate such radial distances leverage and deduce bounds associated with a user’s position. Finally, we infer a user’s bounded trajectory using the spatiotemporal bounds of users’ locations over time. We guarantee the bounds to enclose a user in space and time, with 95% confidence and a 10% margin of error. Using real-world and large-scale synthetic datasets under heterogeneous contexts and wireless conditions, we infer trajectories with bounds’ width of less than 10m in 70% of cases with users’ inclusiveness close to 100%.
Abhishek Kumar Mishra 0001, Aline Carneiro Viana, Nadjib Achir
WCNC1
2021 Public Wireless Packets Anonymously Hurt You
abstract
With growing privacy concerns over the last decade, two of the most notable wireless technologies – i.e., BLE and WiFi – are being more and more investigated in terms of privacy vulnerabilities. In this paper, we explore this problem, prospect the related consequences, and alert the need for privacy-preserving public packets. We identify key flaws in the current design of public packets like beacons and probe requests. We discuss them as the cause of privacy issues that require the community’s attention. We address the flaws in detail and propose solutions that facilitate the devices to protect user privacy. We also give recommendations based on the findings to the standard.
Abhishek Kumar Mishra 0001, Aline Carneiro Viana, Nadjib Achir, Catuscia Palamidessi
LCN1