Habiba Farrukh

dblp:222/5923 · DBLP profile ↗
← Back
20ranked-venue papers
3as first author
17since 2021 · last 2025
0000-0002-3582-5999ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 2 first-author · 14 since 2021Computer networks · 5 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Virtual Reality, Real Problems: A Longitudinal Security Analysis of VR Firmware
abstract
Virtual Reality (VR) technology is rapidly growing in recent years. VR devices such as Meta Quest 3 utilize numerous sensors to collect users' data to provide an immersive experience. Due to the extensive data collection and the immersive nature, the security of VR devices is paramount. Leading VR devices often adopt and customize Android systems, which makes them susceptible to both Android-based vulnerabilities and new issues introduced by VR-specific customizations (e.g., system services to support continuous head and hand tracking). While prior work has extensively examined the security properties of the Android software stack, how these security properties hold for VR systems remains unexplored. In this paper, we present the first comprehensive security analysis of VR firmware. We collect over 300 versions of VR firmware from two major vendors, Quest and Pico, and perform a longitudinal analysis across the kernel layer, the system binary and library layer, and the application layer. We have identified several security issues in these VR firmware, including missing kernel-level security features, insufficient binary hardening, inconsistent permission enforcement, and inadequate SELinux policy enforcement. Based on our findings, we synthesize recommendations for VR vendors to improve security and trust for VR devices. This paper will act as an important security resource for VR developers, users, and vendors, and will also direct future advancements in secure VR ecosystem
Vamsi Shankar Simhadri, Yichang Xiong, Habiba Farrukh, Xiaokuan Zhang
CCS3
2025 Deceptive Sound Therapy on Online Platforms: Do Mental Wellbeing Tracks Conform to User Expectations?
abstract
The rising popularity of mental wellbeing technologies has led many individuals to explore binaural beats—an emerging form of sound therapy proliferating on web and mobile platforms. However, it currently remains unknown whether users can trust binaural tracks on online platforms, or if they deceive unsuspecting users. Our research aims to address this problem by understanding (1) what binaural beats listeners expect from tracks and (2) whether online tracks conform to these expectations. To understand user expectations, we perform thematic analysis on online forum threads and blog posts to extract binaural beats goals and expectations tied to these goals. Next, we design a methodology to measure binaural beats tracks’ conformance to commonly held user expectations. This methodology comprises, (1) obtaining a track’s intent to induce a mental state through track metadata analysis, (2) extracting a track’s binaural beats time-frequency model using Fast Fourier Transform, (3) mapping user expectations to rules that identify deceptive tracks, and validating them on the track’s extracted intent and time-frequency model. We evaluate ∼7K binaural beats tracks and find that only 7.5% conform to commonly held user expectations, while the remaining 92.5% deceive users with deviant claims (e.g., eroticism, weight loss) or deliver contradicting binaural beats. Our study underscores the significance of understanding users’ expectations and verifying conformance of online wellness technologies to expose discrepancies in expectations.
Arjun Arunasalam, Jason Tong, Habiba Farrukh, Muslum Ozgur Ozmen, Koustuv Saha, Z. Berkay Celik
ICWSM3
2025 Demo: UI Based Attacks in WebXR
abstract
The WebXR API enables immersive AR/VR experiences directly through web browsers on head-mounted displays (HMDs). However, prior research shows that security-sensitive UI properties and the lack of an like element that separates different origins can be exploited to manipulate user actions, particularly within the advertising ecosystem. In our prior work, we proposed five novel UI-based attacks in WebXR, targeting the ad ecosystem. This demo presents these attacks in a unified gaming application, embedding each into distinct interactive scenarios. Our work highlights the need to address design challenges and requirements for improving immersive web-based experiences. We provide our demo video at: https://youtu.be/lTBQbxnNq34.
Chandrika Mukherjee, Reham Mohamed Aburas, Arjun Arunasalam, Habiba Farrukh, Z. Berkay Celik
MobiSys4
2025 Poster: PeekXR: Understanding Privacy Leakages from Eye Gaze in Extended Reality
abstract
Extended Reality (XR) headsets are increasingly integrating eye tracking for enhanced user experience, adaptive interfaces, and foveated rendering. However, this rich biometric signal introduces new privacy risks. In this work, we demonstrate that eye-tracking data collected by commercial XR devices can be exploited to infer sensitive user activity. We leverage users' gaze sequences captured while interacting with a VR app to classify the type of content a user is watching. Our results reveal that eye movements alone, without any video or audio context, carry enough information to accurately predict content categories. We discuss the implications of this threat and outline how eye tracking can potentially be used to fingerprint applications and user behavior. This work is a step towards exposing and mitigating emerging privacy threats in immersive systems.
Chuyang Peng, Mutahar Ali, Habiba Farrukh
MobiSys3
2025 Understanding Users' Security and Privacy Concerns and Attitudes Towards Conversational AI Platforms
abstract
The widespread adoption of conversational AI platforms has introduced new security and privacy risks. While these risks and their mitigation strategies have been extensively researched from a technical perspective, users' perceptions of these platforms' security and privacy remain largely unexplored. In this paper, we conduct a large-scale analysis of over 2.5M user posts from the r/ChatGPT Reddit community to understand users' security and privacy concerns and attitudes toward conversational AI platforms. Our qualitative analysis reveals that users are concerned about each stage of the data lifecycle (i.e., collection, usage, and retention). They seek mitigations for security vulnerabilities, compliance with privacy regulations, and greater transparency and control in data handling. We also find that users exhibit varied behaviors and preferences when interacting with these platforms. Some users proactively safeguard their data and adjust privacy settings, while others prioritize convenience over privacy risks, dismissing privacy concerns in favor of benefits, or feel resigned to inevitable data sharing. Through qualitative content and regression analysis, we discover that users' concerns evolve over time with the evolving AI landscape and are influenced by technological developments and major events. Based on our findings, we provide recommendations for users, platforms, enterprises, and policymakers to enhance transparency, improve data controls, and increase user trust and adoption.
Mutahar Ali, Arjun Arunasalam, Habiba Farrukh
SP3
2025 Scoop: Mitigation of Recapture Attacks on Provenance-Based Media Authentication
Yuxin (Myles) Liu, Habiba Farrukh, Ardalan Amiri Sani, Sharad Agarwal, Gene Tsudik
USENIX Security Symposium2
2025 Shadowed Realities: An Investigation of UI Attacks in WebXR
Chandrika Mukherjee, Reham Mohamed Aburas, Arjun Arunasalam, Habiba Farrukh, Z. Berkay Celik
USENIX Security Symposium4
2024 The Dark Side of E-Commerce: Dropshipping Abuse as a Business Model
Arjun Arunasalam, Andrew Chu, Muslum Ozgur Ozmen, Habiba Farrukh, Z. Berkay Celik
NDSS4
2024 Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables
abstract
Wearable devices are becoming increasingly important, helping us stay healthy and connected. There are a variety of app-based wearable platforms that can be used to manage these devices. The apps on wearable devices often work with a companion app on users’ smartphones. The wearable device and the smartphone typically use two separate permission models that work synchronously to protect sensitive data. However, this design creates an opaque view of the management of permission-protected data, resulting in over-privileged data access without the user’s explicit consent. In this paper, we performed the first systematic analysis of the interaction between the Android and Wear OS permission models. Our analysis is two-fold. First, through taint analysis, we showed that cross-device flows of permission-protected data happen in the wild, demonstrating that 28 apps (out of the 150 we studied) on Google Play have sensitive data flows between the wearable app and its companion app. We found that these data flows occur without the users’ explicit consent, introducing the risk of violating user expectations. Second, we conducted an in-lab user study to assess users’ understanding of permissions when subject to cross-device communication (n = 63). We found that 66.7% of the users are unaware of the possibility of cross-device sensitive data flows, which impairs their understanding of permissions in the context of wearable devices and puts their sensitive data at risk. We also showed that users are vulnerable to a new class of attacks that we call cross-device permission phishing attacks on wearable devices. Lastly, we performed a preliminary study on other watch platforms (i.e., Apple’s watchOS, Fitbit, Garmin OS) and found that all these platforms suffer from similar privacy issues. As countermeasures for the potential privacy violations in cross-device apps, we suggest improvements in the system prompts and the permission model to enable users to make better-informed decisions, as well as on app markets to identify malicious cross-device data flows.
Doguhan Yeke, Muhammad Ibrahim 0004, Güliz Seray Tuncay, Habiba Farrukh, Abdullah Imran, Antonio Bianchi, Z. Berkay Celik
SP4
2024 ATTention Please! An Investigation of the App Tracking Transparency Permission
Reham Mohamed Aburas, Arjun Arunasalam, Habiba Farrukh, Jason Tong, Antonio Bianchi, Z. Berkay Celik
USENIX Security Symposium3
2024 Understanding the Security and Privacy Implications of Online Toxic Content on Refugees
Arjun Arunasalam, Habiba Farrukh, Eliz Tekcan, Z. Berkay Celik
USENIX Security Symposium2
2024 Physical Side-Channel Attacks against Intermittent Devices
abstract
Intermittent (batteryless) devices operate solely using energy harvested from their environment. These devices turn on when they have energy and turn off during energy scarcity. Intermittent devices have recently become increasingly popular in smart buildings, manufacturing plants, and medical implantables as they eliminate the need for battery replacement and enable green computing. Despite their growing adoption in critical applications, the privacy implications of intermittent devices remain largely unexplored. In this paper, we introduce a novel remote side-channel attack. Our observation is that the network packet frequency of an intermittent device can be exploited to learn its turn-on/off patterns. From these patterns, we can infer the energy availability of a device, which reveals privacy-sensitive information about its operating environment, e.g., the presence or absence of individuals. To realize our attack, we develop a three-stage hierarchical inference framework that leverages the timestamped network packet sequence of intermittent devices. Our framework automatically extracts a set of temporal features from inter-packet-arrival timings. It then employs a series of models to uncover (1) whether a target intermittent device is present in the environment, (2) its energy harvester type (e.g., vibration or water flow), and (3) its energy availability conditions (e.g., high-vibration or no-vibration). To validate our attack effectiveness, we conduct experiments in two environments: a smart home and a miniature manufacturing plant equipped with three intermittent devices powered by solar energy, vibration, and temperature. By analyzing their energy availability patterns, we are able to infer user activities and presence in the smart home and the robot’s movement patterns in the manufacturing plant with an average accuracy of 85%. This sensitive information enables an adversary to launch domain-specific attacks, such as burglarizing a smart home when the user is asleep or timely tampering with plant sensors to cause maximum damage.
Muslum Ozgur Ozmen, Habiba Farrukh, Z. Berkay Celik
Proc. Priv. Enhancing Technol.2
2023 Evasion Attacks and Defenses on Smart Home Physical Event Verification
Muslum Ozgur Ozmen, Ruoyu Song 0001, Habiba Farrukh, Z. Berkay Celik
NDSS3
2023 One Key to Rule Them All: Secure Group Pairing for Heterogeneous IoT Devices
abstract
Pairing schemes establish cryptographic keys to secure communication among IoT devices. Existing pairing approaches that rely on trusted central entities, human interaction, or shared homogeneous context are prone to a single point of failure, have limited usability, and require additional sensors. Recent work has explored event timings observed by devices with heterogeneous sensing modalities as proof of co-presence for decentralized pairing. Yet, this approach incurs high pairing time, cannot pair sensors that sense continuous physical quantities and does not support group pairing, making it infeasible for many IoT deployments. In this paper, we design and develop IoTCupid, a secure group pairing system for IoT devices with heterogeneous sensing modalities, without requiring active user involvement. IoTCupid operates in three phases: (a) detecting events sensed by both instant and continuous sensors with a novel window-based derivation technique, (b) grouping the events through a fuzzy clustering algorithm to extract inter-event timings, and (c) establishing group keys among devices with identical inter-event timings through a partitioned group password-authenticated key exchange scheme. We evaluate IoTCupid in smart home and office environments with 11 heterogeneous devices and show that it effectively pairs all devices with only 2 group keys with a minimal pairing overhead.
Habiba Farrukh, Muslum Ozgur Ozmen, Faik Kerem Örs, Z. Berkay Celik
SP1
2023 LocIn: Inferring Semantic Location from Spatial Maps in Mixed Reality
Habiba Farrukh, Reham Mohamed Aburas, Aniket Nare, Antonio Bianchi, Z. Berkay Celik
USENIX Security Symposium1
2023 iSTELAN: Disclosing Sensitive User Information by Mobile Magnetometer from Finger Touches
abstract
We show a new type of side-channel leakage in which the built-in magnetometer sensor in Apple's mobile devices captures touch events of users. When a conductive material such as the human body touches the mobile device screen, the electric current passes through the screen capacitors generating an electromagnetic field around the touch point. This electromagnetic field leads to a sharp fluctuation in the magnetometer signals when a touch occurs, both when the mobile device is stationary and held in hand naturally. These signals can be accessed by mobile applications running in the background without requiring any permissions. We develop iSTELAN, a three-stage attack, which exploits this side-channel to infer users' application and touch data. iSTELAN translates the magnetometer signals to a binary sequence to reveal users' touch events, exploits touch event patterns to fingerprint the type of application a user is using, and models touch events to identify users' touch event types performed on different applications. We demonstrate the iSTELAN attack on 22 users while using 7 popular app types and show that it achieves an average accuracy of 90% for disclosing touch events, 74% for classifying application type used, and 73% for detecting touch event types.
Reham Mohamed Aburas, Habiba Farrukh, Yidong Lu, He Wang 0008, Z. Berkay Celik
Proc. Priv. Enhancing Technol.2
2022 SARA: Secure Android Remote Authorization
Abdullah Imran, Habiba Farrukh, Muhammad Ibrahim 0004, Z. Berkay Celik, Antonio Bianchi
USENIX Security Symposium2
2020 Towards Context Address for Camera-to-Human Communication
abstract
Although existing surveillance cameras can identify people, their utility is limited by the unavailability of any direct camera-to-human communication. This paper proposes a real-time end-to-end system to solve the problem of digitally associating people in a camera view with their smartphones, without knowing the phones' IP/MAC addresses. The key idea is using a person's unique "context features", extracted from videos, as its sole address. The context address consists of: motion features, e.g. walking velocity; and ambience features, e.g. magnetic trend and Wi-Fi signal strengths. Once receiving a broadcast packet from the camera, a user's phone accepts it only if its context address matches the phone's sensor data. We highlight three novel components in our system: (1) definition of discriminative and noise-robust ambience features; (2) effortless ambient sensing map generation; (3) a context feature selection algorithm to dynamically choose lightweight yet effective features which are encoded into a fixed-length header. Real-world and simulated experiments are conducted for different applications. Our system achieves a sending ratio of 98.5%, an acceptance precision of 93.4%, and a recall of 98.3% with ten people. We believe this is a step towards direct camera-to-human communication and will become a generic underlay to various practical applications.
Siyuan Cao, Habiba Farrukh, He Wang 0008
INFOCOM2
2020 FaceRevelio: a face liveness detection system for smartphones with a single front camera
abstract
Facial authentication mechanisms are gaining traction on smartphones because of their convenience and increasingly good performance of face recognition systems. However, mainstream systems use traditional 2D face recognition technologies, which are vulnerable to various spoofing attacks. Existing systems perform liveness detection via specialized hardware, such as infrared dot projectors and dedicated cameras. Although effective, such methods do not align well with the smartphone industry's desire to maximize screen space.
Habiba Farrukh, Reham Mohamed Aburas, Siyuan Cao, He Wang 0008
MobiCom1
2018 Video: Enabling Public Cameras to Talk to the Public
abstract
This video presents a real-time end-to-end system which enables cameras to send personalized messages to people in a public area without knowing any addresses of their mobile phones. For facilitating this communication, we solve the problem of digitally associating people in the camera view with their smartphones without prior knowledge of the phones' IP/MAC addresses. The system doesn't need any dedicated devices and doesn't request people to wear digital tags. It utilizes users' motion patterns and leverages the diversity in motion features as the address for communication. The cameras broadcast a message to all the phones in the camera view using the target's motion features as the destination. Then a user's phone can locally compare the "motion address" of the packet against its own sensor data and will accept the packet if it's a "good" match. To protect the privacy of users' sensor data, we keep the users' personal sensing data on their phones instead of asking them to upload the data to server. Moreover, to prevent users' walking behavior from being revealed to public, we transform the raw motion features via principal component analysis (PCA) while maintaining their distinguishing power. On the whole, our system achieves 98%, 95%, 90%, 90%, 87% matching correctness for 2, 4, 6, 8 and 10 users respectively.
Siyuan Cao, Habiba Farrukh, He Wang 0008
MobiSys2