Assane Gueye

dblp:17/6507 · DBLP profile ↗
← Back
15ranked-venue papers
2as first author
9since 2021 · last 2026
0000-0001-6469-4716ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 6 · 6 since 2021Artificial intelligence and machine learning · 5 · 4 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 My Money, Your Name: Challenges and Workarounds in ID-Required Mobile Money in East Africa
Edith Luhanga, Karen Sowon, Lorrie Faith Cranor, Giulia Fanti, Conrad Tucker, Assane Gueye
CHI6
2025 Cookie Consent and Digital Privacy in Africa: An Analysis of Website Practices and Existing Regulatory Gaps
Joel Jefferson Musiime, Nana Ama Atombo-Sackey, Trevor Henry Chiboora, Lenah Chacha, Assane Gueye
COMPASS5
2025 Design and Evaluation of Privacy-Preserving Protocols for Agent-Facilitated Mobile Money Services in Kenya
Karen Sowon, Collins W. Munyendo, Lily Klucinec, Eunice Maingi, Gerald Suleh, Lorrie Faith Cranor, Giulia Fanti, Conrad Tucker, Assane Gueye
SOUPS9
2024 Demo: A Low-Cost Honeynet Infrastructure For Smishing Data Collection
abstract
Research on mobile money smishing is hindered, especially in the African context, as there is a lack of data. The absence of datasets and the fact that Mobile Network Operators don’t maintain such data pose a significant challenge. Additionally, the absence of a data collection infrastructure further complicates the data acquisition process. In response to this challenge, we developed a scalable and cost-effective honeynet infrastructure tailored for the efficient collection of organic Short Message Service (SMS) messages. The innovative approach involves harnessing the capabilities of Raspberry Pi units, USB multipliers, SIM cards from MNOs and GSM modems to create a scalable and adaptable solution. This aims to enhance smishing data collection, facilitating more efficient research into mobile money smishing.
Bernard Odartei Lamptey, Assane Gueye, Mohammed Seidu, Edith Luhanga, Karen Sowon
COMPASS2
2024 A Road map for the Democratization of Space-Based Communications
abstract
The Internet today is owned, managed and controlled by a heterogeneous mix of autonomous systems. As a result, there's no one single entity that holds the "Internet kill switch". However, for emerging Low-Earth Orbit satellite Internet services, few gatekeepers control access globally, going against the fundamental principle of the Internet as a distributed and decentralized system. While satellite Internet remains a small part of the Internet today, it is growing exponentially and is often the only connectivity option for regions that are sparsely populated, experience political instability, or are prone to natural disasters that are likely to damage equipment. We first discuss why the satellite Internet world is ripe for monopolies, global ownership, and vertical integration. We then lay out OpenSpace, an architectural roadmap for a more open and heterogeneous satellite Internet paradigm, where many players build, launch, and manage satellites that communicate, to collectively deliver a reliable Internet service. We also discuss several open problems and research challenges in making satellite Internet more interoperable and heterogeneous, facilitating accessibility for big and small firms alike.
Veronica Muriga, Swarun Kumar, Akshitha Sriraman, Assane Gueye
HotNets4
2024 Poster: Towards A Low-Cost Mobile Internet Measurement Infrastructure: An Initial Deployment in Africa
abstract
Africa lags behind in broadband connectivity and performance. The internet cost remains significantly higher compared to the Global North, and users experience network delays, availability issues, and slow speeds. Several studies demonstrated that measuring internet performance in Africa will provide a better understanding of the reasons underpinning poor broadband performance and ultimately driving substantial improvements. While internet measurement is critical on the continent, effective measurement requires robust infrastructure. We recognize that robust network measurement is expensive but need to be context-based and involve all the internet stakeholders from users to regulators to service providers and more. However, current measurement tools are mostly designed in the West and do not necessarily reflect Africa's broadband measurement challenges. To address this, we propose in this work a cost-effective and context-based mobile broadband measurement infrastructure.
Erick Semindu, Pamely Zantou, Eyerusalem Birhan, Semebia Y. Wurah, Theophilus Benson, Assane Gueye
IMC6
2024 The Role of User-Agent Interactions on Mobile Money Practices in Kenya and Tanzania
abstract
Digital financial services have catalyzed financial inclusion in Africa. Commonly implemented as a mobile wallet service referred to as mobile money (MoMo), the technology provides enormous benefits to its users, some of whom have long been unbanked. While the benefits of mobile money services have largely been documented, the challenges that arise—especially in the interactions between human stakeholders—remain relatively unexplored. In this study, we investigate the practices of mobile money users in their interactions with mobile money agents. We conduct 72 structured interviews in Kenya and Tanzania (n=36 per country). The results show that users and agents design workarounds in response to limitations and challenges that users face within the ecosystem. These include advances or loans from agents, relying on the user-agent relationships in place of legal identification requirements, and altering the intended transaction execution to improve convenience. Overall, the workarounds modify one or more of what we see as the core components of mobile money: the user, the agent, and the transaction itself. The workarounds pose new risks and challenges for users and the overall ecosystem. The results suggest a need for rethinking privacy and security of various components of the ecosystem, as well as policy and regulatory controls to safeguard interactions while ensuring the usability of mobile money.
Karen Sowon, Edith Luhanga, Lorrie Faith Cranor, Giulia Fanti, Conrad Tucker, Assane Gueye
SP6
2023 Evaluating Mobile Banking Application Security Posture Using the OWASP's MASVS Framework
abstract
In the context of financial gain, hackers are motivated to exploit vulnerabilities that could result in financial or data loss. Therefore, it is crucial for financial applications to undergo thorough testing to identify and address such vulnerabilities. Regrettably, many financial institutions neglect proper testing procedures and sometimes even fail to establish a suitable security release baseline. This report presents an analysis of 18 mobile applications, each belonging to a different financial institution in Africa. The selection of these applications was carefully executed, considering institutions of varying sizes, to enable a comparative assessment of security practices across different organizational scales. The assessment was conducted by evaluating the sampled applications against the Mobile Application Security Verification Standard v2.0. This is a set of checklists and guidelines by the Open Web Application Security Project (OWASP) used as a baseline for mobile application security. Due to the extensive nature of the project, the testing scope was limited to the application itself, as experienced by the end user. This included examining the application’s interaction with the back-end server and observing its behavior on the user’s mobile device. It is important to note that this report does not provide a comprehensive analysis, as it excludes the assessment of the server-side API and testing of business logic that requires elevated privileges within the application. Furthermore, a survey was conducted to gain insights into why developers may neglect baseline security thereby introducing potential vulnerabilities in mobile applications. The findings of this survey are also included in a short summary at the end of this document.
Trevor Henry Chiboora, Lenah Chacha, Theoneste Byagutangaza, Assane Gueye
COMPASS4
2023 Digital Public Goods Interoperability: A Low-Code Middleware Approach
abstract
Digital Public Goods (DPGs) play a vital role in achieving the United Nations’ Sustainable Development Goals (SDGs) in low-income and middle-income countries. However, the lack of interoperability among different DPGs could lead to duplication of efforts and/or lack of (inter)-functionality since one DPG is not able to benefit from the features of another. This paper illustrates the need for interoperability, the difficulty of retrofitting interoperability in the numerous mature DPG projects and introduces a middleware application as a solution. The middleware application is a lightweight, technology-agnostic, portable, and modular application which facilitates transactions between the integrating system and the integrated system. By customizing and deploying the middleware, integrating system developers can save time and costs, reducing barriers to prototyping and increasing the adoption rate of DPGs. Furthermore, developers do not need to provision or access a sandbox as the middleware supports mocking responses. A use case involving the integration of two DPGs, a digital identity system and a health information system, is illustrated. The paper also describes future enhancements to the generalizability of the middleware from 1-to-any to any-to-any as well as improving security resilience with WebAuthn and custom cyber-security hardening tools and procedures.
Andrew Amstrong Musoke, Jean Paul Nishimirwe, Nafiu Lawal, Assane Gueye
COMPASS4
2020 Measurements of the Most Significant Software Security Weaknesses
abstract
In this work, we provide a metric to calculate the most significant software security weaknesses as defined by an aggregate metric of the frequency, exploitability, and impact of related vulnerabilities. The Common Weakness Enumeration (CWE) is a well-known and used list of software security weaknesses. The CWE community publishes such an aggregate metric to calculate the ‘Most Dangerous Software Errors’. However, we find that the published equation highly biases frequency and almost ignores exploitability and impact in generating top lists of varying sizes. This is due to the differences in the distributions of the component metric values. To mitigate this, we linearize the frequency distribution using a double log function. We then propose a variety of other improvements, provide top lists of the most significant CWEs for 2019, provide an analysis of the identified software security weaknesses, and compare them against previously published top lists.
Carlos Cardoso Galhardo, Peter Mell, Irena Bojanova, Assane Gueye
ACSAC4
2020 A Suite of Metrics for Calculating the Most Significant Security Relevant Software Flaw Types
abstract
The Common Weakness Enumeration (CWE) is a prominent list of software weakness types. This list is used by vulnerability databases to describe the underlying security flaws within analyzed vulnerabilities. This linkage opens the possibility of using the analysis of software vulnerabilities to identify the most significant weaknesses that enable those vulnerabilities. We accomplish this through creating mashup views combining CWE weakness taxonomies with vulnerability analysis data. The resulting graphs have CWEs as nodes, edges derived from multiple CWE taxonomies, and nodes adorned with vulnerability analysis information (propagated from children to parents). Using these graphs, we develop a suite of metrics to identify the most significant weakness types (using the perspectives of frequency, impact, exploitability, and overall severity).
Peter Mell, Assane Gueye
COMPSAC2
2015 Defensive Resource Allocations with Security Chokepoints in IPv6 Networks
Assane Gueye, Peter Mell, Richard E. Harang, Richard J. La
DBSec1
2009 Iterative Node Deployment in an Unknown Environment
abstract
We consider the problem of deploying relay nodes to achieve connectivity with minimum cost in a sensor network of unknown radio propagation characteristics. For a network where a certain number of targets or sensing nodes have already been deployed in fixed and known positions, we aim at efficiently adding communication or relay nodes to guarantee connectivity with minimum cost, between any sensor node and a base station. The communication cost of a wireless link is defined as the expected number of retransmissions over that link and is modeled using an underlying Gaussian process (GP) between the nodes. We propose an iterative sensor deployment approach that learns the parameters of the underlying GP while deploying the additional nodes in the best positions possible at each step. Our deployment algorithm is more powerful with respect to the ones found in literature since: 1) we do not assume fixed communication range, i.e., we do not assume that nodes can perfectly communicate within a fixed range and will not communicate at all outside that range (this assumption is not realistic for the wireless channel); 2) we do not assume the existence of a pilot deployment aimed at learning the radio propagation characteristics because of the high cost of the deployment process and of the sensor nodes themselves.
Assane Gueye, Sinem Coleri Ergen, Alberto L. Sangiovanni-Vincentelli
GLOBECOM1
2008 A Convex Upper Bound on the Log-Partition Function for Binary Distributions
abstract
We consider the problem of bounding from above the log-partition function corresponding to second-order Ising models for binary distributions. We introduce a new bound, the cardinality bound, which can be computed via convex optimization. The corresponding error on the logpartition function is bounded above by twice the distance, in model parameter space, to a class of "standard" Ising models, for which variable inter-dependence is described via a simple mean field term. In the context of maximum-likelihood, using the new bound instead of the exact log-partition function, while constraining the distance to the class of standard Ising models, leads not only to a good approximation to the log-partition function, but also to a model that is parsimonious, and easily interpretable. We compare our bound with the log-determinant bound introduced by Wainwright and Jordan (2006), and show that when the l1 -norm of the model parameter vector is small enough, the latter is outperformed by the new bound.
Laurent El Ghaoui, Assane Gueye
NIPS2
2008 A novel approach to bottleneck analysis in networks
abstract
In this paper, we devise a novel method for bottleneck analysis of UDP networks based on the concept of network utility maximization. To determine the losses on the links in a UDP network, we propose an optimization problem (geometric program) for which we find and prove conditions under which it accurately determines the true losses. We further extend this analysis to stochastic rates using stochastic optimization techniques and provide a new metric to flag bottleneck links. This method does not rely on time-consuming packet-level simulations, but is instead based on robust mathematical models. Alternatively, one could determine the losses by solving a fixed point problem and extend it to random rates using a Monte Carlo simulation. However, lack of knowledge of convergence makes it difficult to predict the end of such simulations. Our method is more advantageous as it involves solving an optimization problem, the solution to which can be numerically determined to the desired accuracy. Also, compared to a black and white approach between worst-case analysis and average-case analysis, our method offers network managers the flexibility of choosing the shades of gray in between.
Nikhil Shetty, Assane Gueye, Jean C. Walrand
NOMS2