VLDB 2026 Research / reviewers in the wild / expert
Narmeen Shafqat
dblp:211/4775
· DBLP profile ↗
8ranked-venue papers
2as first author
4since 2021 · last 2023
0000-0002-7562-1093ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 3Security and privacy · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Track You: A Deep Dive into Safety Alerts for Apple AirTagsabstractBluetooth-based item trackers have sparked apprehension over their potential misuse in harmful stalking and privacy violations. In response, manufacturers have implemented safety alerts to notify victims of extended tracking by unknown item trackers. In this study, we specifically investigate the anti-stalking mechanism of Apple's AirTag. We identify and analyze potential triggers of safety alerts that have not been examined in previous research, such as the local time, the victim's device model, AirTag's battery life, and the distance between the AirTag and the victim's device. Furthermore, we demonstrate a novel possibility of developing a stealthy cloned AirTag capable of tracking victims directly on the Find My app while circumventing safety alerts on the victim’s device. Our experiments demonstrate that, despite regular updates to the public key and MAC address, our cloned AirTag can provide real-time location updates even with a four months old key, thereby highlighting the challenges in designing a robust anti-stalking framework. Furthermore, we propose practical solutions to mitigate stalking risks from cloned AirTags and enhance the existing anti-stalking safeguards for AirTags. These suggestions seek to provide a foundation for similar Bluetooth-based item trackers to improve their anti-stalking protections while ensuring optimal tracking efficiency. We conducted rigorous experiments to validate our findings, ensuring their accuracy and reliability. Our evaluation highlights that safety alerts take over 8 hours to appear during the day and are more prompt during the night, particularly after 11 pm. Narmeen Shafqat, Nicole Gerzon, Maggie Van Nortwick, Victor Sun, Alan Mislove, Aanjhan Ranganathan |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | ZLeaks: Passive Inference Attacks on Zigbee Based Smart Homes
Narmeen Shafqat, Daniel J. Dubois, David R. Choffnes, Aaron Schulman, Dinesh Bharadia, Aanjhan Ranganathan |
ACNS | 1 |
| 2022 | Forensic analysis of image deletion applications
Maheen Fatima, Haider Abbas, Mian Muhammad Waseem Iqbal, Narmeen Shafqat |
Multim. Tools Appl. | 4 |
| 2021 | A Malware Evasion Technique for Auditing Android Anti-Malware SolutionsabstractIn the past few years, Android security is enhanced \nand state-of-the-art anti-malware tools have been introduced \nto counter Android malware. These tools use both static and \ndynamic analysis techniques to detect malicious applications. \nDespite these, the attack surface against Android phones has \nrisen exponentially and malware detection tools are failed to \ncounter sophisticated threats. Therefore, it is a need to audit \nand evaluate Anti Malware Solutions (AMTs). In our research, \nwe have analyzed various Android malware evasion techniques, \nalong with their pros and cons. Moreover, we conducted a detailed \ncomparison of existing anti-malware tools and measured their \nefficacy against the discussed evasion techniques. Finally, a more \nsophisticated anti-malware evasion technique is proposed that \nuses exhaustive obfuscation and remote code execution to audit \nstatic and dynamic detection capabilities of AMTs. The proposed \ntechnique is practically validated and results prove that it evades \nall known anti-malware solutions. This technique can be utilized \nby anti-malware solution providers for making their products \nmore resilient and powerful. Samrah Mirza, Haider Abbas, Waleed Bin Shahid, Narmeen Shafqat, Maria Grazia Fugini, Muhammad Zia |
WETICE | 4 |
| 2020 | Crowdsourcing Cybercrimes through Online ResourcesabstractCybercrime is referred to as aggressive, intentional act performed through electronic communications. In recent years, lack of awareness regarding technological advancements has paved the way for an intense increase in various types of aggressive cyber-attacks such as phishing, scamming, hacking etc. Under-reporting of cybercrimes serves as a major impediment in efficient and timely handling of cybercrimes, and hence can cause serious consequences. Manually staying informed regarding emerging cybersecurity threats is a time taking and laborious task, creating the need of developing robust systems that could efficiently report news related to cybercrimes. This requires development of information retrieval models to extract cybersecurity news belonging to different categories from various online resources. The focus of this research is to propose a model for detection of cyber offences reported on news articles and blogs. Further in order to analyze the authenticity of news obtained via news articles/blogs, a novel source verification model is proposed by investigating various authenticity parameters and assigning weightages to these parameters. Naila Amir, Rabia Latif, Narmeen Shafqat, Seemab Latif |
DeSE | 3 |
| 2020 | Integrated Security, Safety, and Privacy Risk Assessment Framework for Medical DevicesabstractThe substantial improvements and innovations in communication networks and bio-medical technologies have led to the adoption of networked medical devices due to which the attack surface has increased profoundly. Numerous devices in practice were designed and developed years ago without security measures. In such a scenario, the role of regulatory bodies has become evident. The Food and Drug Administration (FDA) validates and approves devices before commercialization. In contrast, the European Union (EU) follows a decentralized approach and Notified Bodies (NB) for assuring high standards, safety and quality of medical devices being marketed in Europe. Once the device has gone through stringent regulations including good manufacturing practices, Quality Management System (QMS), labeling, clinical tests, performance standards, adequate storage and packaging practices, a declaration of conformity will be granted, which is a legal binding document stating that the device is conformant with applicable European requirements and can be marketed in Europe. However, such regulations lack a systematic methodology to determine unified security, safety and privacy risk that eventually influence the health of patients. To cover these gaps, this research proposes Integrated Safety, Security, and Privacy (ISSP) Risk Assessment Framework to determine the risk level of the device and required security controls. It is, then applied to a case scenario of an infusion pump and further evaluated by comparing it with current standards and practices. The comparison shows that the framework provides a unified approach to consider different types of risks associated with devices. Tahreem Yaqoob, Haider Abbas, Narmeen Shafqat |
IEEE J. Biomed. Health Informatics | 3 |
| 2019 | Framework for Calculating Return on Security Investment (ROSI) for Security-Oriented Organizations
Tahreem Yaqoob, Azka Arshad, Haider Abbas, M. Faisal Amjad, Narmeen Shafqat |
Future Gener. Comput. Syst. | 5 |
| 2017 | Feasibility analysis for deploying national healthcare information system (NHIS) for PakistanabstractLack of healthcare infrastructure has caused millions of deaths in developing countries. People in such countries generally suffer from infectious diseases and are denied treatment at appropriate time or not warned about emerging epidemics. This mainly happens because of poor establishment of public health services, lack of access to health statistics and nonexistence of precise medical data. The deployment of e-health and specifically Electronic Health Record (EHR) system may help in upgrading and boosting healthcare in developing countries like Pakistan. This paper studies and compares different approaches taken by a group of countries from North America, Europe, Western Asia and Africa for developing and implementing a national EHR in the public health system. The foremost challenges highlighted in this paper are of integration, interoperability, trainings, awareness, standardization, funds, and legal framework, which would help in developing a National EHR system in Pakistan. A National Healthcare Information System (NHIS) is proposed for health sector of Pakistan. The proposed system will be capable of efficient storage, management and sharing of electronic health information of patients in Pakistan. NHIS will also help in conducting surveys and analysis of health statistics for future health planning. Tahreem Yaqoob, Faiza Mir, Haider Abbas, Waleed Bin Shahid, Narmeen Shafqat, M. Faisal Amjad |
Healthcom | 5 |