Isaac Griswold-Steiner

dblp:213/8679 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
2since 2021 · last 2021
0000-0002-1869-1001ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2021 A Wearables-Driven Attack on Examination Proctoring
abstract
Multiple choice questions are at the heart of many standardized tests and examinations at academic institutions allover the world. In this paper, we argue that recent advancements in sensing and human-computer interaction expose these types of questions to highly effective attacks that today’s proctor’s are simply not equipped to detect. We design one such attack based on a protocol of carefully orchestrated wrist movements combined with haptic and visual feedback mechanisms designed for stealthiness. The attack is done through collaboration between a knowledgeable student (i.e., a mercenary) and a weak student (i.e., the beneficiary) who depends on the mercenary for solutions. Through a combination of experiments and theoretical modeling, we show the attack to be highly effective. The paper makes the case for an outright ban on all tech gadgets inside examination rooms, irrespective of whether their usage appears benign to the plain eye.
Tasnia Ashrafi Heya, Abdul Serwadda, Isaac Griswold-Steiner, Richard Matovu
PST3
2021 Smartphone speech privacy concerns from side-channel attacks on facial biomechanics
Isaac Griswold-Steiner, Zachary LeFevre, Abdul Serwadda
Comput. Secur.1
2020 Defensive Charging: Mitigating Power Side-Channel Attacks on Charging Smartphones
abstract
Mobile devices are increasingly relied upon in user's daily lives. This dependence supports a growing network of mobile device charging hubs in public spaces such as airports. Unfortunately, the public nature of these hubs make them vulnerable to tampering. By embedding illicit power meters in the charging stations an attacker can launch power side-channel attacks aimed at inferring user activity on smartphones (e.g., web browsing or typing patterns). In this paper, we present three power side-channel attacks that can be launched by an adversary during the phone charging process. Such attacks use machine learning to identify unique patterns hidden in the measured current draw and infer information about a user's activity. To defend against these attacks, we design and rigorously evaluate two defense mechanisms, a hardware-based and software-based solution. The defenses randomly perturb the current drawn during charging thereby masking the unique patterns of the user's activities. Our experiments show that the two defenses force each one of the attacks to perform no better than random guessing. In practice, the user would only need to choose one of the defensive mechanisms to protect themselves against intrusions involving power draw analysis.
Richard Matovu, Abdul Serwadda, Argenis V. Bilbao, Isaac Griswold-Steiner
CODASPY4
2019 Prying into Private Spaces Using Mobile Device Motion Sensors
abstract
Human made structures are designed in a predictable manner, conforming to the expectations of those who use them. These underlying patterns lend themselves to repetition in the way people get between different locations. We investigated the feasibility of an attacker using motion sensor data against their target, with the objective of predicting where they move and what activities they engaged in. In this work, we show that the gyroscope and accelerometer can be used to drive a privacy attack that stealthily maps out a user's private space with high accuracy. In particular, we show that a mobile app with access to this data can leverage it to analyze a user's step execution dynamics, turn operations, and general body movement activities and then methodically combine this information to map out paths and landmarks in protected spaces, such as houses. Using a dataset of 26 users who executed a number of activities and a combination of classification, regression, and distance matching techniques, we show this privacy attack to generate maps whose Normalized Hausdorff Distance from the ground-truth is as low as 0.1159.
Zakery Fyke, Isaac Griswold-Steiner, Abdul Serwadda
PST2
2017 Handwriting watcher: A mechanism for smartwatch-driven handwriting authentication
abstract
Despite decades of research on automated handwriting authentication, there is yet to emerge an automated handwriting authentication application that breaks into the mainstream. In this paper, we argue that the burgeoning wearables market holds the key to a practical handwriting authentication app. With potential applications in online education, standardized testing and mobile banking, we present Handwriting Watcher, a mechanism which leverages a wrist-worn sensor-enabled device to authenticate a user's free handwriting. Through experiments capturing a wide range of writing scenarios, we show Handwriting Watcher attains mean error rates as low as 6.56% across the population. Our work represents a promising step towards a market-ready, generalized handwriting authentication system.
Isaac Griswold-Steiner, Richard Matovu, Abdul Serwadda
IJCB1