VLDB 2026 Research / reviewers in the wild / expert
Nguyen Phong Hoang
dblp:179/2240
· DBLP profile ↗
14ranked-venue papers
6as first author
11since 2021 · last 2026
0000-0002-9868-3318ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 5 first-author · 9 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | More Space, Less Privacy? Measuring the Effectiveness of IP-based Website Fingerprinting in IPv6abstractDespite the widespread adoption of domain name encryption protocols (e.g., DoH, DoT, and ECH), website fingerprinting attacks remain a significant threat to online privacy due to the visibility of IP connections that can be observed by network-level adversaries. This problem has been investigated in IPv4 thoroughly but remains largely unexplored in IPv6, where it is even more pronounced. From a design perspective, IPv6 offers a vastly larger address space, eliminating the need for virtual hosting and domain co-location -- practices prevalent in IPv4. These practices obscure several domains behind a single IPv4 address. The adoption of IPv6 can theoretically lead to more accurate fingerprinting based on IPv6 connections because each domain is now more likely to be resolved to a unique globally routable IPv6 address unlike IPv4. In this study, we systematically investigate the feasibility, accuracy, and privacy implications of IP-based website fingerprinting in IPv6 environments. Utilizing empirical data collected via active DNS measurements, Web crawling, and entropy-based analyses across half a million dual-stack websites, we conduct the largest evaluation of website fingerprinting in IPv6. We find that dual-stack websites that still have some IPv4-only dependencies are easier to fingerprint, achieving close to 94% accuracy on both IPv4 and IPv6. However, fingerprinting pure dual-stack websites is significantly harder: accuracy drops to 56% over IPv4 and 45% over IPv6. These results reveal distinct trends in hosting infrastructures and indicate that IPv6 itself does not inherently diminish privacy, contrary to existing concerns in the community. Rather, fingerprinting risk is shaped by how hosting providers deploy IPv6 and their choices regarding domain co-location. Sumeer Ahmad, Michalis Polychronakis, Theophilus Benson, Nguyen Phong Hoang |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Is Nobody There? Good! Globally Measuring Connection Tampering Without Responsive EndhostsabstractMany techniques have been introduced to measure network interference-tampering performed by nation-state censors or corporate firewalls to block unwanted traffic. How-ever, virtually all prior measurement techniques require some degree of participation from endpoints within each country of study: including VPNs, cloud providers, or volunteers willing to run measurement software on their personal devices at their own risk. However, such endpoints are not always available in all countries that tamper with connections, leaving many networks unmeasurable. In this paper, we present the first global, active, network interference measurements that require no participating end-points within any country of study. Our techniques extend two recent studies that use packet sequences that trigger network interference from outside the country of study by tricking middleboxes into believing a connection exists. Our system, Mint, generalizes and automates this approach-which had previously only been applied to two countries-to allow it to apply to the global IPv4 and IPv6 Internet. We use Mint to conduct the first global measurements of network interference without using any participating endpoints, and the first comprehensive scans of IPv6 interference. We show that we are able to measure networks, autonomous systems, and even entire countries that previous methods could not. We also present several case studies that highlight how our tool can be used to perform new measurement studies of network interference. Sadia Nourin, Erik C. Rye, Kevin Bock 0001, Nguyen Phong Hoang, Dave Levin |
SP | 4 |
| 2025 | IRBlock: A Large-Scale Measurement Study of the Great Firewall of Iran
Jonas Tai, Karthik Nishanth Sengottuvelavan, Peter Whiting, Nguyen Phong Hoang |
USENIX Security Symposium | 4 |
| 2024 | GFWeb: Measuring the Great Firewall's Web Censorship at Scale
Nguyen Phong Hoang, Jakub Dalek, Masashi Crete-Nishihata, Nicolas Christin, Vinod Yegneswaran, Michalis Polychronakis, Nick Feamster |
USENIX Security Symposium | 1 |
| 2024 | Automatic Generation of Web Censorship Probe ListsabstractDomain probe lists---used to determine which URLs to probe for Web censorship---play a critical role in Internet censorship measurement studies. Indeed, the size and accuracy of the domain probe list limits the set of censored pages that can be detected; inaccurate lists can lead to an incomplete view of the censorship landscape or biased results. Previous efforts to generate domain probe lists have been mostly manual or crowdsourced. This approach is time-consuming, prone to errors, and does not scale well to the ever-changing censorship landscape. In this paper, we explore methods for automatically generating probe lists that are both comprehensive and up-to-date for Web censorship measurement. We start from an initial set of 139,957 unique URLs from various existing test lists consisting of pages from a variety of languages to generate new candidate pages. By analyzing content from these URLs (i.e., performing topic and keyword extraction), expanding these topics, and using them as a feed to search engines, our method produces 119,255 new URLs across 35,147 domains. We then test the new candidate pages by attempting to access each URL from servers in eleven different global locations over a span of four months to check for their connectivity and potential signs of censorship. Our measurements reveal that our method discovered over 1,400 domains---not present in the original dataset---we suspect to be blocked. In short, automatically updating probe lists is possible, and can help further automate censorship measurements at scale. Jenny Tang, Léo Alvarez, Arjun Brar, Nguyen Phong Hoang, Nicolas Christin |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | Augmenting Rule-based DNS Censorship Detection at Scale with Machine LearningabstractThe proliferation of global censorship has led to the development of a plethora of measurement platforms to monitor and expose it. Censorship of the domain name system (DNS) is a key mechanism used across different countries. It is currently detected by applying heuristics to samples of DNS queries and responses (probes) for specific destinations. These heuristics, however, are both platform-specific and have been found to be brittle when censors change their blocking behavior, necessitating a more reliable automated process for detecting censorship. Jacob Alexander Markson Brown, Xi Jiang 0007, Van Hong Tran, Arjun Nitin Bhagoji, Nguyen Phong Hoang, Nick Feamster, Prateek Mittal, Vinod Yegneswaran |
KDD | 5 |
| 2023 | DeResistor: Toward Detection-Resistant Probing for Evasion of Internet Censorship
Abderrahmen Amich, Birhanu Eshete, Vinod Yegneswaran, Nguyen Phong Hoang |
USENIX Security Symposium | 4 |
| 2023 | Measuring and Evading Turkmenistan's Internet Censorship: A Case Study in Large-Scale Measurements of a Low-Penetration CountryabstractSince 2006, Turkmenistan has been listed as one of the few Internet enemies by Reporters without Borders due to its extensively censored Internet and strictly regulated information control policies. Existing reports of filtering in Turkmenistan rely on a handful of vantage points or test a small number of websites. Yet, the country’s poor Internet adoption rates and small population can make more comprehensive measurement challenging. With a population of only six million people and an Internet penetration rate of only 38%, it is challenging to either recruit in-country volunteers or obtain vantage points to conduct remote network measurements at scale. Sadia Nourin, Van Hong Tran, Xi Jiang 0007, Kevin Bock 0001, Nick Feamster, Nguyen Phong Hoang, Dave Levin |
WWW | 6 |
| 2022 | Measuring the Accessibility of Domain Name Encryption and Its Impact on Internet Filtering
Nguyen Phong Hoang, Michalis Polychronakis, Phillipa Gill |
PAM | 1 |
| 2021 | How Great is the Great Firewall? Measuring China's DNS Censorship
Nguyen Phong Hoang, Arian Akhavan Niaki, Jakub Dalek, Jeffrey Knockel, Pellaeon Lin, William R. Marczak, Masashi Crete-Nishihata, Phillipa Gill, Michalis Polychronakis |
USENIX Security Symposium | 1 |
| 2021 | Domain name encryption is not enough: privacy leakage via IP-based website fingerprintingabstractAlthough the security benefits of domain name encryption technologies such as DNS over TLS (DoT), DNS over HTTPS (DoH), and Encrypted Client Hello (ECH) are clear, their positive impact on user privacy is weakened by—the still exposed—IP address information. However, content delivery networks, DNS-based load balancing, co-hosting of different websites on the same server, and IP address churn, all contribute towards making domain–IP mappings unstable, and prevent straightforward IP-based browsing tracking. Nguyen Phong Hoang, Arian Akhavan Niaki, Phillipa Gill, Michalis Polychronakis |
Proc. Priv. Enhancing Technol. | 1 |
| 2020 | Assessing the Privacy Benefits of Domain Name EncryptionabstractAs Internet users have become more savvy about the potential for their Internet communication to be observed, the use of network traffic encryption technologies (e.g., HTTPS/TLS) is on the rise. However, even when encryption is enabled, users leak information about the domains they visit via DNS queries and via the Server Name Indication (SNI) extension of TLS. Two recent proposals to ameliorate this issue are DNS over HTTPS/TLS (DoH/DoT) and Encrypted SNI (ESNI). Nguyen Phong Hoang, Arian Akhavan Niaki, Nikita Borisov, Phillipa Gill, Michalis Polychronakis |
AsiaCCS | 1 |
| 2020 | ICLab: A Global, Longitudinal Internet Censorship Measurement PlatformabstractResearchers have studied Internet censorship for nearly as long as attempts to censor contents have taken place. Most studies have however been limited to a short period of time and / or a few countries; the few exceptions have traded off detail for breadth of coverage. Collecting enough data for a comprehensive, global, longitudinal perspective remains challenging.In this work, we present ICLab, an Internet measurement platform specialized for censorship research. It achieves a new balance between breadth of coverage and detail of measurements, by using commercial VPNs as vantage points distributed around the world. ICLab has been operated continuously since late 2016. It can currently detect DNS manipulation and TCP packet injection, and overt "block pages" however they are delivered. ICLab records and archives raw observations in detail, making retrospective analysis with new techniques possible. At every stage of processing, ICLab seeks to minimize false positives and manual validation.Within 53,906,532 measurements of individual web pages, collected by ICLab in 2017 and 2018, we observe blocking of 3,602 unique URLs in 60 countries. Using this data, we compare how different blocking techniques are deployed in different regions and/or against different types of content. Our longitudinal monitoring pinpoints changes in censorship in India and Turkey concurrent with political shifts, and our clustering techniques discover 48 previously unknown block pages. ICLab's broad and detailed measurements also expose other forms of network interference, such as surveillance and malware injection. Arian Akhavan Niaki, Shinyoung Cho, Zachary Weinberg, Nguyen Phong Hoang, Abbas Razaghpanah, Nicolas Christin, Phillipa Gill |
SP | 4 |
| 2018 | An Empirical Study of the I2P Anonymity Network and its Censorship Resistance
Nguyen Phong Hoang, Panagiotis Kintis, Manos Antonakakis, Michalis Polychronakis |
Internet Measurement Conference | 1 |