VLDB 2026 Research / reviewers in the wild / expert
Shahryar Baki
dblp:181/5898
· DBLP profile ↗
6ranked-venue papers
4as first author
2since 2021 · last 2025
0000-0002-9814-9270ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Real-Time, Evidence-Based Alerts for Protection From Phishing AttacksabstractDespite two decades of research on automatic filtering systems, phishing attacks remain a serious problem. To alleviate risks from filtering failures, we design and evaluate the effectiveness of a new warning system on users’ susceptibility to phishing. Our proposed technique highlights key sentences based on an analysis of the persuasive techniques used. An online mixed-design study ($n=604$) shows that adding our highlighting technique outperforms existing warning solutions. It also identifies the relative efficacy of different appeals and the characteristics of susceptible users. Results show that adding our highlighting techniqueis useful even with false positives and false negatives. Inspired by this result, we propose an automatic warning generator. We created a small labeled dataset of suspicious sentences and used data augmentation. Our best models achieve F1 score of 99.95% in detecting phishing emails and 88% in detecting suspicious sentences. Shahryar Baki, Fatima Zahra Qachfar, Rakesh M. Verma, Ryan Kennedy, Daniel Jones 0003 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Sixteen Years of Phishing User Studies: What Have We Learned?abstractSeveral previous studies have investigated user susceptibility to phishing attacks. A thorough meta-analysis or systematic review is required to gain a better understanding of these findings and to assess the strength of evidence for phishing susceptibility of a subpopulation, e.g., older users. We aim to determine whether an effect exists; another aim is to determine whether the effect is positive or negative and to obtain a single summary estimate of the effect.OBJECTIVES:We systematically review the results of previous user studies on phishing susceptibility and conduct a meta-analysis.METHOD:We searched four online databases for English studies on phishing. We included all user studies in phishing detection and prevention, whether they proposed new training techniques or analyzed users’ vulnerability.FINDINGS:A careful analysis reveals some discrepancies between the findings. More than half of the studies that analyzed the effect ofagereported no statistically significant relationship between age and users’ performance. Some studies reported older people performed better while some reported the opposite. A similar finding holds for the gender difference. The meta-analysis shows: 1) a significant relationship between participants’ age and their susceptibility 2) females are more susceptible than males 3) users training significantly improves their detection ability. Shahryar Baki, Rakesh M. Verma |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Scam Augmentation and Customization: Identifying Vulnerable Users and Arming DefendersabstractWhy do "classical" attacks such as phishing, IRS scams, etc., still succeed? How do attackers increase their chances of success? How do people reason about scams and frauds they face daily? More research is needed on these questions, which is the focus of this paper. We take a well-known attack, viz. company representative fraud, and study several parameters that bear on its effectiveness with a between-subjects study. We also study the effectiveness of a coherent language generation technique in producing phishing emails. We give ample room for the participants to demonstrate their reasoning and strategies. Shahryar Baki, Rakesh M. Verma, Omprakash Gnawali |
AsiaCCS | 1 |
| 2020 | PhishBench 2.0: A Versatile and Extendable Benchmarking Framework for PhishingabstractWe describe version 2.0 of our benchmarking framework, PhishBench. With the addition of the ability to dynamically load features, metrics, and classifiers, our new and improved framework allows researchers to rapidly evaluate new features and methods for machine-learning based phishing detection. Researchers can compare under identical circumstances their contributions with numerous built-in features, ranking methods, and classifiers used in the literature with the right evaluation metrics. We will demonstrate PhishBench 2.0 and compare it against at least two other automated ML systems. Victor Zeng, Shahryar Baki, Rakesh M. Verma |
CCS | 3 |
| 2017 | Scaling and Effectiveness of Email Masquerade Attacks: Exploiting Natural Language GenerationabstractWe focus on email-based attacks, a rich field with well-publicized consequences. We show how current Natural Language Generation (NLG) technology allows an attacker to generate masquerade attacks on scale, and study their effectiveness with a within-subjects study. We also gather insights on what parts of an email do users focus on and how users identify attacks in this realm, by planting signals and also by asking them for their reasoning. We find that: (i) 17% of participants could not identify any of the signals that were inserted in emails, and (ii) Participants were unable to perform better than random guessing on these attacks. The insights gathered and the tools and techniques employed could help defenders in: (i) implementing new, customized anti-phishing solutions for Internet users including training next-generation email filters that go beyond vanilla spam filters and capable of addressing masquerade, (ii) more effectively training and upgrading the skills of email users, and (iii) understanding the dynamics of this novel attack and its ability of tricking humans. Shahryar Baki, Rakesh M. Verma, Arjun Mukherjee, Omprakash Gnawali |
AsiaCCS | 1 |
| 2016 | Mining the Web for Collocations: IR Models of Term Associations
Rakesh M. Verma, Vasanthi Vuppuluri, Arjun Mukherjee, Ghita Mammar, Shahryar Baki, Reed Armstrong |
CICLing (1) | 6 |