VLDB 2026 Research / reviewers in the wild / expert
Dogan Kesdogan
dblp:21/1324
· DBLP profile ↗
23ranked-venue papers
4as first author
5since 2021 · last 2026
0009-0003-6970-9544ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 3 first-author · 5 since 2021Software engineering, systems software and programming languages · 2Artificial intelligence and machine learning · 1Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Does Anonymity Love the Chat Groups?abstractInstant messaging is an integral part of daily communication, and users increasingly seek anonymous options to protect their privacy. Mix networks are a well-established approach for metadata protection, but current designs largely overlook the unique challenges of instant messaging, such as low-latency expectations, bursty interaction patterns, and group chats. In this work, we present the first systematic analysis of mix networks, and anonymization systems in general, for group messaging under realistic conditions. We introduce a novel group-identification attack that exploits co-occurrence patterns of recipients to infer group membership with high accuracy, even against a significantly weaker attacker model than these systems typically assume, a local observer. Our evaluation leverages real-world WhatsApp data and adapts it to better reflect realistic usage scenarios. Finally, we evaluate how defense strategies such as relaxing low latency requirements to allow for more delay options and cover traffic perform against this attack. Our findings reveal critical weaknesses in current designs and provide insights for improving anonymity in instant group messaging. Marc Roßberger, Dogan Kesdogan |
CODASPY | 2 |
| 2025 | Towards a Lightweight and Privacy-Friendly Architecture for Online Advertising
Maximilian Wittig, Dogan Kesdogan |
SEC (2) | 2 |
| 2023 | Effect of Group Based Synchronization on User Anonymity in Mix NetworksabstractIn so-called closed environments, the MIX network can theoretically provide perfect security, i.e. if perfect protection is envisaged, all senders and receivers should be perfectly synchronized and participate equally in each communication round of the MIX technique. In the context of open environments (e.g., the Internet), there is no synchronization between the participants and here the technique is vulnerable to known analyses such as (statistical) disclosure attacks. In short, the Mix technology is highly dependent on its application context in which it involves the participants. In this work, we study the effect of context in terms of synchronization rate, present two different synchronization approaches and evaluate their protection against disclosure attacks. Alperen Aksoy, Dogan Kesdogan |
ARES | 2 |
| 2023 | Detecting Web Tracking at the Network Layer
Maximilian Wittig, Dogan Kesdogan |
SEC | 2 |
| 2021 | DaRoute: Inferring trajectories from zero-permission smartphone sensorsabstractNowadays, smartphones are equipped with a multitude of sensors, including GPS, that enables location-based services. However, leakage or misuse of user locations poses a severe privacy threat, motivating operating systems to usually restrict direct access to these resources for applications. Nevertheless, this work demonstrates how an adversary can deduce sensitive location information by inferring a vehicle’s trajectory through inbuilt motion sensors collectible by zero-permission mobile apps. Therefore, the presented attack incorporates data from the accelerometer, the gyroscope, and the magnetometer. We then extract so-called path events from raw data to eventually match them against reference data from OpenStreetMap. At the example of real-world data from three different cities, several drivers, and different smartphones, we show that our approach can infer traveled routes with high accuracy within minutes while robust to sensor errors. Our experiments show that even for areas as large as approximately 4500 $\mathrm{k}\mathrm{m}^{2}$, the accuracy of detecting the correct route is as high as 87.14%, significantly outperforming similar approaches from Narain et al. and Waltereit et al. Christian Roth 0002, Thanh Dinh, Marc Roßberger, Dogan Kesdogan |
PST | 4 |
| 2020 | iTLM: A Privacy Friendly Crowdsourcing Architecture for Intelligent Traffic Light ManagementabstractVehicle-to-everything (V2X) interconnects participants in vehicular environments to exchange information. This enables a broad range of new opportunities. We propose a self learning traffic light system which uses crowdsoured information from vehicles in a privacy friendly manner to optimize the overall traffic flow. Our simulation, based on real world data, shows that the information gain vastly decreases waiting time at traffic lights eventually reducing CO2 emissions. A privacy analysis shows that our approach provides a significant level of k-anonymity even in low traffic scenarios. Christian Roth 0002, Mirja Nitschke, Matthias Hörmann, Dogan Kesdogan |
DATA | 4 |
| 2020 | Harmonized Group Mix for ITSabstractVehicle-to-Vehicle (V2V) communication is crucial for almost all future applications in the context of smart traffic, such as autonomous driving. However, while current standards like WAVE provide a technical platform for communication and management, they lack aspects of privacy for their participants. In this paper, we introduce a Harmonized Group Mix (HGM), an architecture suited to exchange information in ITS, compatible with current standards. HGM does not rely on expensive Road-Side-Units (RSUs) or complex organizational relationships to introduce a trust anchor but is built on the concept of peer-to-peer networks. Hence, our proposal does not require any changes to current environments and is eventually easy to deploy in the real world. Our proposed method provides k-anonymity using group signatures and splits trust between multiple parties. At the same time, the integrity of the system is preserved. We evaluate our approach using the simulation framework Veins. Our experiments show that HGM is feasible from a performance and privacy perspective in the given context. Mirja Nitschke, Christian Roth 0002, Christian Hoyer, Dogan Kesdogan |
ICISSP | 4 |
| 2017 | Towards a causality based analysis of anonymity protection in indeterministic mix systems
Dang Vinh Pham, Dogan Kesdogan |
Comput. Secur. | 2 |
| 2015 | Towards Relations Between the Hitting-Set Attack and the Statistical Disclosure Attack
Dang Vinh Pham, Dogan Kesdogan |
SEC | 2 |
| 2015 | Service composition with consideration of interdependent security objectives
Fatih Karatas, Lars Fischer 0002, Dogan Kesdogan |
Sci. Comput. Program. | 3 |
| 2013 | An Approach for Compliance-Aware Service Selection with Genetic Algorithms
Fatih Karatas, Dogan Kesdogan |
ICSOC | 2 |
| 2012 | GridPriv: A Smart Metering Architecture Offering k-AnonymityabstractOne of the key challenges to the practical realisation of the Smart Grid are the privacy implications of fine-grained Smart Metering data. We review the German BSI's Protection Profile for the Gateway of a Smart Metering System, a state of the art approach to practical Smart Metering privacy in Germany. Our analysis reveals several issues that can reduce the achieved anonymity and pseudonymity. Specifically, we investigate churning attacks which exploit processes inherent to the use of pseudonymised meter data and we quantify the attacks' effect. In addition, we introduce GridPriv an enhanced architecture that includes a non-trusted k-anonymity service and that addresses the challenges identified with the BSI's approach in a scalable, secure, and privacy-preserving way. Mark Stegelmann, Dogan Kesdogan |
TrustCom | 2 |
| 2012 | Using Distributed User Interfaces in Collaborative, Secure, and Privacy-Preserving Software EnvironmentsabstractIn complex, ad hoc constituted situations, people with different intentions, experiences, and expertise need or want to cooperate to cope with the domain-specific challenges they face. These situations can occur in both a professional and a leisure-life context. Cooperative systems providing enhanced interaction facilities in the user interface (e.g., direct manipulation techniques) could substantially support cooperation especially for geographically distributed cooperating participants. In many cases, sensitive information has to be shared in a common workspace requiring different handling procedures according to the different types of participants involved in these ad hoc processes. This article proposes the use of a common, multilaterally secure distributed user interface to support collaboration for distributed groups of process participants. The system combines a collaborative multipointer system with an anonymous credential security system to provide users with an easy way to share and access information securely, ensuring the privacy of sensitive information communicated in the course of ad hoc processes. Various scenarios representing contrary use cases from three different projects are introduced to derive typical requirements and to show the generality of the proposed system and its core components. Mohamed Bourimi, Thomas Barth, Dogan Kesdogan, Dhiah el Diehn I. Abou-Tair, Fabian Hermann, Simon Thiel |
Int. J. Hum. Comput. Interact. | 3 |
| 2011 | A Practical Complexity-Theoretic Analysis of Mix Systems
Dang Vinh Pham, Joss Wright, Dogan Kesdogan |
ESORICS | 3 |
| 2011 | Analyzing the Gold Star Scheme in a Split Tor Network
Benedikt Westermann, Pern Hui Chia, Dogan Kesdogan |
SecureComm | 3 |
| 2009 | A Combinatorial Approach for an Anonymity Metric
Dang Vinh Pham, Dogan Kesdogan |
ACISP | 2 |
| 2006 | TrustedPals: Secure Multiparty Computation Implemented with Smart Cards
Milan Fort, Felix C. Freiling, Lucia Draque Penso, Zinaida Benenson, Dogan Kesdogan |
ESORICS | 5 |
| 2006 | Fundamental Limits on the Anonymity Provided by the MIX TechniqueabstractThe MIX technique forms the basis of many popular services that offer anonymity of communication in open and shared networks such as the Internet. In this paper, fundamental limits on the anonymity provided by the MIX technique are found by considering two different settings. First, we consider an information theoretic setting to determine the extent of information inherent in observations of the traffic passing through the MIX. We show that if the size of sender anonymity sets is less than the total user population, the information contained in traffic observations is sufficient to deduce all communication relationships between senders and receivers using the MIX. More importantly, we show that even if every user sends a message in each communication round, it is possible to compromise the anonymity significantly. We precisely characterize the extent of compromised anonymity in each case. In the second setting, we assume that the attacker has unlimited computational resources and is free to choose any attack algorithm. We derive tight upper and lower bounds on the minimum number of observations required to deduce all recipient peer-partners of a targeted user. The analysis done in these two settings reveals many discrete mathematical structures inherent in anonymity sets, and the intuition gained from these structures can be used when designing or using a MIX based anonymity technique. Dogan Kesdogan, Dakshi Agrawal, Dang Vinh Pham, Dieter Rautenbach |
S&P | 1 |
| 2006 | Technical challenges of network anonymity
Dogan Kesdogan, Charles Palmer |
Comput. Commun. | 1 |
| 2003 | Probabilistic Treatment of MIXes to Hamper Traffic AnalysisabstractThe goal of anonymity providing techniques is to preserve the privacy of users, who has communicated with whom, for how long, and from which location, by hiding traffic information. This is accomplished by organizing additional traffic to conceal particular communication relationships and by embedding the sender and receiver of a message in their respective anonymity sets. If the number of overall participants is greater than the size of the anonymity set and if the anonymity set changes with time due to unsynchronized participants, then the anonymity technique becomes prone to traffic analysis attacks. We are interested in the statistical properties of the disclosure attack, a newly suggested traffic analysis attack on the MIXes. Our goal is to provide analytical estimates of the number of observations required by the disclosure attack and to identify fundamental (but avoidable) 'weak operational modes' of the MIXes and thus to protect users against a traffic analysis by the disclosure attack. Dakshi Agrawal, Dogan Kesdogan, Stefan Penz |
S&P | 2 |
| 1998 | How to Increase Security in Mobile Networks by Anomaly DetectionabstractThe increasing complexity of cellular radio networks yields new demands concerning network security. Especially the task of detecting, repulsing and preventing abuse both by in- and outsiders becomes more and more difficult. This paper deals with a relatively new technique that appears to be suitable for solving these issues, i.e. anomaly detection based on profiling mobile users. Mobility pattern generation and behavior prediction are discussed in depth, before a new model of anomaly detection that is based on the Bayes decision rule is introduced. Applying this model to mobile user profiles proves the feasibility of our approach. Finally, a special emphasis is put on discussing privacy aspects of anomaly detection. Roland Büschkes, Dogan Kesdogan, Peter Reichl |
ACSAC | 2 |
| 1998 | Distributed Temporary Pseudonyms: A New Approach for Protecting Location Information in Mobile Communication Networks
Dogan Kesdogan, Peter Reichl, Klaus Junghärtchen |
ESORICS | 1 |
| 1996 | Location management strategies increasing privacy in mobile communication
Dogan Kesdogan, Hannes Federrath, Anja Jerichow, Andreas Pfitzmann |
SEC | 1 |