VLDB 2026 Research / reviewers in the wild / expert
Aisha I. Ali-Gombe
dblp:214/9435
· DBLP profile ↗
21ranked-venue papers
5as first author
13since 2021 · last 2026
0000-0002-2563-0557ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 5 first-author · 13 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The privacy cost of fun: A measurement study of user data exposure in tiktok mini-games
Sideeq Bello, Lamine Noureddine, Babangida Bappah, Aisha I. Ali-Gombe |
Comput. Secur. | 4 |
| 2026 | Disclosure Divergence: Measuring Privacy Policy and Data Safety Misalignment at ScaleabstractWith the rapid growth of mobile applications, user data privacy has become an increasing concern. While privacy policies describe how apps collect and share data, platforms such as Google Play provide Data Safety labels intended to summarize these practices. Because these disclosure channels are declared separately, they may present inconsistent representations of app data practices, creating uncertainty for users and regulators. In this work, we conducted a large-scale empirical study of disclosure consistency across 6,051 Android apps. Using an LLM-based extraction framework and a unified schema over 14 Google Play data categories and two operations (collection and sharing), we measure per-app and per-category consistency and introduce a sensitivity-weighted risk score that emphasizes high-risk data types. We find that misalignment disproportionately affects sensitive categories such as personal information and device identifiers, with sharing disclosures exhibiting lower consistency than collection disclosures. Elevated privacy risk is concentrated in app categories associated with persistent monitoring and communication. Overall, our findings highlight structural gaps in current disclosure mechanisms and underscore the need for stronger verification and greater transparency in platform-level privacy reporting. Mst. Eshita Khatun, Lamine Noureddine, Sideeq Bello, Aisha I. Ali-Gombe |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | AndroByte: LLM-Driven Privacy Analysis through Bytecode Summarization and Dynamic Dataflow Call Graph GenerationabstractWith the exponential growth in mobile applications, protecting user privacy has become even more crucial. Android applications are often known for collecting, storing, and sharing sensitive user information such as contacts, location, camera, and microphone data, often without the user's clear consent or awareness, raising significant privacy risks and exposure. In the context of privacy assessment, dataflow analysis is particularly valuable for identifying data usage and potential leaks. Traditionally, this type of analysis has relied on formal methods, heuristics, and rule-based matching. However, these techniques are often complex to implement and prone to errors, such as taint explosion for large programs. Moreover, most existing Android dataflow analysis methods depend heavily on predefined list of sinks, limiting their flexibility and scalability. To address the limitations of these existing techniques, we propose AndroByte, an AI-driven privacy analysis tool that leverages the reasoning of a large language model (LLM) on bytecode summarization to dynamically generate accurate and explainable dataflow call graphs from static code analysis. AndroByte achieves a significant Fß-Score of 89% in generating dynamic dataflow call graphs on the fly, outperforming the effectiveness of traditional tools like FlowDroid and Amandroid in leak detection without relying on predefined propagation rules or sink lists. Moreover, AndroByte's iterative bytecode summarization provides comprehensive and explainable insights into dataflow and leak detection, achieving high, quantifiable scores based on the G-Eval metric. Mst. Eshita Khatun, Lamine Noureddine, Zhiyong Sui, Aisha I. Ali-Gombe |
ACSAC | 4 |
| 2025 | REx86: A Local Large Language Model for Assisting in x86 Assembly Reverse EngineeringabstractReverse engineering (RE) of x86 binaries is indis- pensable for malware and firmware analysis, but remains slow due to stripped metadata and adversarial obfuscation. Large Language Models (LLMs) offer potential for improving RE efficiency through automated comprehension and commenting, but cloud-hosted, closed-weight models pose privacy and security risks and cannot be used in closed-network facilities. We evaluate parameter-efficient fine-tuned local LLMs for assisting with x86 RE tasks in these settings. Eight open-weight models across the CodeLlama, Qwen2.5-Coder, and CodeGemma series are fine-tuned on a custom curated dataset of 5,981 x 86 assembly examples. We evaluate them quantitatively and identify the fine-tuned Qwen2.5-Coder-7B as the top performer, which we name REx86. REx86 reduces test-set cross-entropy loss by 64.2% and improves semantic cosine similarity against ground truth by 20.3% over its base model. In a limited user case study (n=43), REx86 significantly enhanced line-level code understanding (p = 0.031) and increased the correct-solve rate from 31% to 53% (p = 0.189), though the latter did not reach statistical significance. Qualitative analysis shows more accurate, concise comments with fewer hallucinations. REx86 delivers state-of-the-art assistance in x86 RE among local, open-weight LLMs. Our findings demonstrate the value of domain-specific fine-tuning, and highlight the need for more commented disassembly data to further enhance LLM performance in RE. REx86, its dataset, and LoRA adapters are publicly available at https://github.com/dlea8/REx86 and https://zenodo.org/records/15420461. Darrin Lea, James Ghawaly, Golden G. Richard III, Aisha I. Ali-Gombe, Andrew Case |
ACSAC | 4 |
| 2025 | Exploring Runtime Evolution in Android: A Cross-Version Analysis and Its Implications for Memory ForensicsabstractUserland memory forensics has become a critical component of smartphone investigations and incident response, enabling the recovery of volatile evidence such as deleted messages from end-to-end encrypted apps and cryptocurrency transactions. However, these forensics tools, particularly on Android, face significant challenges in adapting to different versions and maintaining reliability over time due to the constant evolution of low-level structures critical for evidence recovery and reconstruction. Structural changes, ranging from simple offset modifications to complete architectural redesigns, pose substantial maintenance and adaptability issues for forensic tools that rely on precise structure interpretation. Thus, this paper presents the first systematic study of Android Runtime (ART) structural evolution and its implications for memory forensics. We conduct an empirical analysis of critical Android runtime structures, examining their evolution across six versions for four different architectures. Our findings reveal that over $73.2 \%$ of structure members underwent positional changes, significantly affecting the adaptability and reliability of memory forensic tools. Further analysis of core components such as Runtime, Thread, and Heap structures highlights distinct evolution patterns and their impact on critical forensic operations, including thread state enumeration, memory mapping, and object reconstruction. These results demonstrate that traditional approaches relying on static structure definitions and symbol-based methods, while historically reliable, are increasingly unsustainable on their own. We recommend that memory forensic tools in general and Android in particular evolve toward hybrid approaches that retain the validation strength of symbolic methods while integrating automated structure inference, version-aware parsing, and redundant analysis strategies. These adaptations are essential for sustaining effective and trustworthy forensic capabilities amidst rapidly evolving runtime environments. Babangida Bappah, Lauren G. Bristol, Lamine Noureddine, Sideeq Bello, Umar Farooq 0002, Aisha I. Ali-Gombe |
RAID | 6 |
| 2024 | Enhancing privacy policy comprehension through Privacify: A user-centric approach using advanced language models
Justin Woodring, Katherine Perez, Aisha I. Ali-Gombe |
Comput. Secur. | 3 |
| 2023 | I've Got You, Under My Skin: Biohacking Augmentation Implant Forensics
Steven Seiden 0002, Ibrahim M. Baggili, Aisha I. Ali-Gombe |
ICDF2C (2) | 3 |
| 2023 | SWMAT: Mel-frequency cepstral coefficients-based memory fingerprinting for IoT devicesabstractThe increasing sophistication in computing capability and sensing technologies have continued to drive the design, development, and growth of the smart technologies commonly known as the IoTs. Nonetheless, the rise and spread of malware in this ecosystem is a pressing societal concern that requires immediate attention. In this paper, we propose a novel technique called Sound Wave Memory Analysis Technique (SWMAT), for fingerprinting IoT devices by converting their dynamic memory traces into sound wave signals using a lossless transformation function from which a unique set of determinable features called Mel Frequency Cepstral Coefficients (MFCCs) are extracted. The overarching objective of this research is to explore offline the effectiveness of using features from memory-encoded sound wave signals for fingerprinting and detecting abnormal changes in IoT devices, which potentially can provide an excellent technique for an on-device Host-Based Intrusion Detection System. Our SWMAT scores the similarity between two sequences of MFCCs using a Dynamic Time Warping distance measure . To evaluate our approach, we developed multiple IoT testbeds and generated 125 MFCC sequences from 20 benign and 5 infected IoT applications . Our results showed that the MFCC features, when leveraged as fingerprints for both Intra and Inter-app similarity, can uniquely distinguish an IoT process and can detect when an IoT process has been hijacked and/or is modified by another malicious code . Furthermore, this empirical result shows our technique’s similarity detection accuracy to be ≈ 95%. Ramyapandian Vijayakanthan, Irfan Ahmed 0001, Aisha I. Ali-Gombe |
Comput. Secur. | 3 |
| 2022 | I Don't Know Why You Need My Data: A Case Study of Popular Social Media Privacy PoliciesabstractData privacy, a critical human right, is gaining importance as new technologies are developed, and the old ones evolve. In mobile platforms such as Android, data privacy regulations require developers to communicate data access requests using privacy policy statements (PPS). This case study cross-examines the PPS in popular social media (SM) apps --- Facebook and Twitter --- for features of language ambiguity, sensitive data requests, and whether the statements tally with the data requests made in the Manifest file. Subsequently, we conduct a comparative analysis between the PPS of these two apps to examine trends that may constitute a threat to user data privacy. Elizabeth Miller, Md. Rashedur Rahman, Moinul Hossain, Aisha I. Ali-Gombe |
CODASPY | 4 |
| 2022 | Transforming Memory Image to Sound Wave Signals for an Effective IoT FingerprintingabstractAs the need and adaptation for smart environments continue to rise, owing mainly to the evolution in IoT technology's processing and sensing capabilities, the security community must contend with increasing attack surfaces on our network, critical systems, and infrastructures. Thus, developing an effective fingerprint to deal with some of these threats is of paramount importance. As such, in this paper, we explored the use of memory snapshots for effective dynamic process-level fingerprints. Our technique transforms a memory snapshot into a sound wave signal, from which we then retrieve their distinctive Mel-Frequency Cepstral Coefficients (MFCC) features as unique process-level identifiers. The evaluation of this proposed technique on our dataset demonstrated that MFCC-based fingerprints generated from the same IoT process memory at different times exhibit much stronger similarities than those acquired from different IoT process spaces. Ramyapandian Vijayakanthan, Irfan Ahmed 0001, Aisha I. Ali-Gombe |
CODASPY | 3 |
| 2022 | Intent-aware Permission Architecture: A Model for Rethinking Informed Consent for Android Apps
Md. Rashedur Rahman, Elizabeth Miller, Moinul Hossain, Aisha I. Ali-Gombe |
ICISSP | 4 |
| 2021 | Object Allocation Pattern as an Indicator for Maliciousness - An Exploratory AnalysisabstractTraditionally, Android malware is analyzed using static or dynamic analysis. Although static techniques are often fast; however, they cannot be applied to classify obfuscated samples or malware with a dynamic payload. In comparison, the dynamic approach can examine obfuscated variants but often incurs significant runtime overhead when collecting every important malware behavioral data. This paper conducts an exploratory analysis of memory forensics as an alternative technique for extracting feature vectors for an Android malware classifier. We utilized the reconstructed per-process object allocation network to identify distinguishable patterns in malware and benign application. Our evaluation results indicate the network structural features in the malware category are unique compared to the benign dataset, and thus features extracted from the remnant of in-memory allocated objects can be utilized for robust Android malware classification algorithm. Adamu Hussaini, Bassam Zahran, Aisha I. Ali-Gombe |
CODASPY | 3 |
| 2021 | IIoT-ARAS: IIoT/ICS Automated Risk Assessment System for Prediction and PreventionabstractAs IT/OT convergence continues to evolve, the traditionally isolated ICS/OT systems are increasingly exposed to a myriad of online and offline threats. Although IIoT enhances the reachability in ICS, improved data analytics, ensuring ease of access and decision making, it unwittingly opens the ICS environment to attackers. The design of IIoT introduces multiple entry points to an isolated system, which is used to protect itself via air-gapping and risk avoidance strategies. This study explores a comprehensive mapping of threats and risks for IT/OT convergence. Additionally, we propose IIoT-ARAS - an automated risk assessment system based on OCTAVE Allegro and ISO/IEC 27030 methodologies. The design of IIoT-ARAS is aimed to be agentless, with minimum interruptions to the OT environment. Furthermore, the system performs automated regular asset inventory checks, threshold optimization, probability computation, risk evaluations, and contingency plan configuration. Bassam Zahran, Adamu Hussaini, Aisha I. Ali-Gombe |
CODASPY | 3 |
| 2020 | App-Agnostic Post-Execution Semantic Analysis of Android In-Memory Forensics ArtifactsabstractOver the last decade, userland memory forensics techniques and algorithms have gained popularity among practitioners, as they have proven to be useful in real forensics and cybercrime investigations. These techniques analyze and recover objects and artifacts from process memory space that are of critical importance in investigations. Nonetheless, the major drawback of existing techniques is that they cannot determine the origin and context within which the recovered object exists without prior knowledge of the application logic. Aisha I. Ali-Gombe, Alexandra Tambaoan, Angela Gurfolino, Golden G. Richard III |
ACSAC | 1 |
| 2020 | Hooktracer: Automatic Detection and Analysis of Keystroke Loggers Using Memory Forensics
Andrew Case, Ryan D. Maggio, Md Firoz-Ul-Amin, Mohammad M. Jalalzai, Aisha I. Ali-Gombe, Mingxuan Sun 0001, Golden G. Richard III |
Comput. Secur. | 5 |
| 2019 | DroidScraper: A Tool for Android In-Memory Object Recovery and Reconstruction
Aisha I. Ali-Gombe, Sneha Sudhakaran, Andrew Case, Golden G. Richard III |
RAID | 1 |
| 2018 | Tipped Off by Your Memory Allocator: Device-Wide User Activity Sequencing from Android Memory Images
Rohit Bhatia, Brendan Saltaformaggio, Seung Jei Yang, Aisha I. Ali-Gombe, Xiangyu Zhang 0001, Dongyan Xu, Golden G. Richard III |
NDSS | 4 |
| 2018 | Toward a more dependable hybrid analysis of android malware using aspect-oriented programming
Aisha I. Ali-Gombe, Brendan Saltaformaggio, J. Ramanujam, Dongyan Xu, Golden G. Richard III |
Comput. Secur. | 1 |
| 2016 | AspectDroid: Android App Analysis SystemabstractThe growing threat to user privacy related to Android applications (apps) has tremendously increased the need for more reliable and accessible app analysis systems. This paper presents AspectDroid, an application-level system designed to investigate Android applications for possible unwanted activities. AspectDroid is comprised of app instrumentation, automated testing and containment systems. By using static bytecode instrumentation, The growing threat to user privacy related to Android applications (apps) has tremendously increased the need for more reliable and accessible app analysis systems. This paper presents AspectDroid, an application-level system designed to investigate Android applications for possible unwanted activities. AspectDroid is comprised of app instrumentation, automated testing and containment systems. By using static bytecode instrumentation, AspectDroid weaves monitoring code into an existing application and provides data flow and sensitive API usage as well as dynamic instrumentation capabilities. The newly repackaged app is then executed either manually or via an automated testing module. Finally, the flexible containment provided by AspectDroid adds a layer of protection so that malicious activities can be prevented from affecting other devices. The accuracy score of AspectDroid when tested on 105 DroidBench corpus shows it can detect tagged data with 95.29\%. We further tested our system on 100 real malware families from the Drebin dataset \cite{drebin2014}. The result of our analysis showed AspectDroid incurs approximately 1MB average total memory size overhead and 5.9\% average increase in CPU-usage. Aisha I. Ali-Gombe, Irfan Ahmed 0001, Golden G. Richard III, Vassil Roussev |
CODASPY | 1 |
| 2016 | Don't Touch that Column: Portable, Fine-Grained Access Control for Android's Native Content ProvidersabstractAndroid applications access native SQLite databases through their Universal Resource Identifiers (URIs), exposed by the Content provider library. By design, the SQLite engine used in the Android system does not enforce access restrictions on database content nor does it log database accesses. Instead, Android enforces read and write permissions on the native providers through which databases are accessed via the mandatory applications permissions system. This system is very coarse grained, however, and can allow applications far greater access to sensitive data than a user might intend. Aisha I. Ali-Gombe, Golden G. Richard III, Irfan Ahmed 0001, Vassil Roussev |
WISEC | 1 |
| 2015 | Robust Fingerprinting for Relocatable CodeabstractRobust fingerprinting of executable code contained in a memory image is a prerequisite for a large number of security and forensic applications, especially in a cloud environment. Prior state of the art has focused specifically on identifying kernel versions by means of complex differential analysis of several aspects of the kernel code implementation. Irfan Ahmed 0001, Vassil Roussev, Aisha I. Ali-Gombe |
CODASPY | 3 |