VLDB 2026 Research / reviewers in the wild / expert
Thomas Hupperich
dblp:24/11104
· DBLP profile ↗
18ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0002-4981-9522ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 4 since 2021Computer networks · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Reinforcement learning and movement prediction for adaptive routing in opportunistic networksabstractOpportunistic Networks are a type of mobile ad-hoc network in intermittent communication environments, allowing nodes to exchange data whenever they come into contact, making them particularly useful in areas with disruptions or limited infrastructure. Efficient routing is crucial for these networks and is required to adapt to dynamic topology changes. We propose a novel Spray-Learn-Wait routing protocol, utilizing clustering-based movement prediction and reinforcement learning to optimize the data exchange between nodes. Compared to established protocols like Epidemic, First Contact, and ProPHET, message delivery probability may be increased while reducing the network overhead ratio and the number of dropped messages. The protocol follows the principle of minimal data sharing within a network to meet sustainability and privacy requirements. Frederick Schindlegger, Thomas Hupperich |
Comput. Networks | 2 |
| 2025 | Privacy from 5 PM to 6 AM: Tracking and Transparency Mechanisms in the HbbTV EcosystemabstractHybrid broadcast broadband television (HbbTV) is an evolving technology that connects linear TV with modern HTML5 applications, delivering extras like games, videos, and online shopping. However, its bidirectional transmission functionality raises privacy concerns, as it introduces new tracking methods for TV channels. While previous studies focused on security issues or user awareness of HbbTV privacy challenges, a detailed examination of the tracking and transparency mechanisms of the HbbTV ecosystem is still missing. This study fills this gap by extensively analyzing these features within the European HbbTV ecosystem, and in particular within German-language TV channels. We monitored more than 350 TV channels for over 400 hours, evaluating 1) prevalent HbbTV tracking methods, 2) consent notice prevalence and user interactions, and 3) privacy policy disclosures. Our findings indicate that the HbbTV tracking system operates independently of the Web, consent notices exploit system constraints to influence users, and privacy policies often do not align with actual data practices. Christian Böttger, Henry Hosseini, Christine Utz, Nurullah Demir, Jan Hörnemann, Christian Wressnegger, Thomas Hupperich, Norbert Pohlmann, Matteo Große-Kampmann, Tobias Urban |
DSN | 7 |
| 2024 | Utilizing blockchains in opportunistic networks for integrity and confidentialityabstractOpportunistic networks (OppNets) are usually a set of smart, wearable, and portable devices or entities with mobility that connect wirelessly without requiring infrastructure. Such a network is of great importance in data transmission, particularly in incidents and disasters, whether man-made or natural. However, message integrity and confidentiality are of concern when it deals with vital and physiological data transmission with strict privacy regulations. In this work, we offered a structure to classify messages based on their priority in different queues. Furthermore, due to the decentralized architecture of OppNets, we proposed a blockchain-based structure for providing security for high-priority messages. It contains three sequences of functional blocks with a light and simplified implementation that makes it suitable for battery-powered wearable devices that are limited in energy consumption and computational units. The simulation results showed that by increasing the number of nodes in the network, the average of the changes in block sizes are neglectable which addresses the computation bottleneck. Furthermore, we analyzed the performance of the proposed structure in terms of message delivery and network overhead compared with Epidemic and Prophet routing algorithms. These results indicated advancing the overall performance of the proposed algorithm. Samaneh Rashidibajgan, Thomas Hupperich |
Blockchain Res. Appl. | 2 |
| 2024 | A Bilingual Longitudinal Analysis of Privacy Policies Measuring the Impacts of the GDPR and the CCPA/CPRAabstractPrivacy policies are the main mechanism for websites to describe their practices in collecting and processing visitors' personal data. Their format and content are subject to legal requirements that have changed due to recent new privacy regulations including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and California Privacy Rights Act (CPRA). Studying how privacy policies are adapted to such regulatory change can help identify shortcomings in implementing the law and inform future legislatory initiatives. Existing work in this area mostly studied effects of the GDPR on privacy policies or the "Do Not Sell My Personal Information" link mandated by the CCPA. Methodologically, insights were mainly drawn from English-language privacy policies using keyword-based analyses or machine learning classifiers. In this work, we address this research gap and conduct a bilingual study of privacy policies in English and German that investigates the effects of the GDPR and CCPA/CPRA on privacy policy content, using established methods from corpus linguistics that are language-independent and do not rely on keyword lists or classifiers that may date quickly. We find that, unlike for the GDPR, the CCPA's requirements were not yet widely implemented when it first became enforceable but only with its amendment, the CPRA. Before that, websites used more than 60 variants of the "Do Not Sell" link instead of the mandated wording and did not prominently reference individual rights granted by the CCPA/CPRA. While companies outside California and the US did adapt their disclosures to the CCPA/CPRA, this was limited to English-language policies and did not spill over to policies in German. For GDPR enforcement, we find websites to increasingly rely on legitimate interests to justify data collection, raising concerns whether individuals' interests in the privacy of their personal information are still sufficiently considered. Henry Hosseini, Christine Utz, Martin Degeling, Thomas Hupperich |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | On DDoS Attacks as an Expression of Digital Protest in the Russo-Ukrainian War 2022abstractIn February 2022, a new escalation of the Russo-Ukrainian war began in Europe. While certain events were foreshadowing an escalation, the Russian troops moved to the territory of Ukraine on February 24th. Later on the same day, the hacktivism collective “Anonymous” stated to be in a cyber war with the Russian government and called for support by overloading specific Russian web servers. Since the beginning of this escalation, we observe these servers and measure their availability. In this paper, we investigate whether the downtimes of these servers correlate to the calls of “Anonymous” and what changes were made to these servers. It is inevitable to discuss whether such actions – usually seen as attacks on service availability – should be seen as an expression of digital protest. Thomas Hupperich |
ISNCC | 1 |
| 2022 | Discovering Vulnerabilities and Patches for Open Source Security
Tamara Gunkel, Thomas Hupperich |
ICSOFT | 2 |
| 2022 | Automated Search for Leaked Private Keys on the Internet: Has Your Private Key Been Pwned?
Henry Hosseini, Julian Rengstorf, Thomas Hupperich |
ICSOFT | 3 |
| 2022 | A Tale of Two Regulatory Regimes: Creation and Analysis of a Bilingual Privacy Policy CorpusabstractOver the past decade, researchers have started to explore the use of NLP to develop tools aimed at helping the public, vendors, and regulators analyze disclosures made in privacy policies. With the introduction of new privacy regulations, the language of privacy policies is also evolving, and disclosures made by the same organization are not always the same in different languages, especially when used to communicate with users who fall under different jurisdictions. This work explores the use of language technologies to capture and analyze these differences at scale. We introduce an annotation scheme designed to capture the nuances of two new landmark privacy regulations, namely the EU’s GDPR and California’s CCPA/CPRA. We then introduce the first bilingual corpus of mobile app privacy policies consisting of 64 privacy policies in English (292K words) and 91 privacy policies in German (478K words), respectively with manual annotations for 8K and 19K fine-grained data practices. The annotations are used to develop computational methods that can automatically extract “disclosures” from privacy policies. Analysis of a subset of 59 “semi-parallel” policies reveals differences that can be attributed to different regulatory regimes, suggesting that systematic analysis of policies using automated language technologies is indeed a worthwhile endeavor. Siddhant Arora, Henry Hosseini, Christine Utz, Vinayshekhar Bannihatti Kumar, Tristan Dhellemmes, Abhilasha Ravichander, Peter Story, Jasmine Mangat, Rex Chen, Martin Degeling, Thomas B. Norton, Thomas Hupperich, Shomir Wilson, Norman M. Sadeh |
LREC | 12 |
| 2021 | Secure and privacy-preserving structure in opportunistic networks
Samaneh Rashidibajgan, Thomas Hupperich, Robin Doss, Anna Förster |
Comput. Secur. | 2 |
| 2021 | Unifying Privacy Policy DetectionabstractAbstract Privacy policies have become a focal point of privacy research. With their goal to reflect the privacy practices of a website, service, or app, they are often the starting point for researchers who analyze the accuracy of claimed data practices, user understanding of practices, or control mechanisms for users. Due to vast differences in structure, presentation, and content, it is often challenging to extract privacy policies from online resources like websites for analysis. In the past, researchers have relied on scrapers tailored to the specific analysis or task, which complicates comparing results across different studies. To unify future research in this field, we developed a toolchain to process website privacy policies and prepare them for research purposes. The core part of this chain is a detector module for English and German, using natural language processing and machine learning to automatically determine whether given texts are privacy or cookie policies. We leverage multiple existing data sets to refine our approach, evaluate it on a recently published longitudinal corpus, and show that it contains a number of misclassified documents. We believe that unifying data preparation for the analysis of privacy policies can help make different studies more comparable and is a step towards more thorough analyses. In addition, we provide insights into common pitfalls that may lead to invalid analyses. Henry Hosseini, Martin Degeling, Christine Utz, Thomas Hupperich |
Proc. Priv. Enhancing Technol. | 4 |
| 2020 | On the Usefulness of User Nudging and Strength Indication Concerning Unlock Pattern SecurityabstractStrong passwords rely on complexity and length, no matter if text-based or of any other type. For text-based passwords, there are many established methods to measure complexity while for graphical passwords, e.g., unlock patterns on mobile devices, it is still an open question what criteria can be used to describe complexity. Also, users tend to choose a stronger password if the strength of their password is visualized. We conduct a user study on the helpfulness of strength indication and user nudging regarding unlock patterns. Participants create such graphical passwords under carefully specified circumstances, e.g., practical nudges on how to improve their password's security. We show that the choice of a strong password does not rely on being tech-savvy and users with different technical backgrounds can be helped by visualizations of a graphical password strength as well as by hints on how to improve it. Most users even perceive this as a helpful feature. Thomas Hupperich, Katharina Dassel |
TrustCom | 1 |
| 2020 | Opportunistic Tracking in Cyber-Physical SystemsabstractCyber-Physical Systems raise a new dimension of security concerns as they open up the opportunity for attackers to affect a real-world environment. These systems are often applied in specific environments with special requirements and a common issue is to keep track of movements in a mobile system, e.g., involving autonomous robots, drones or sensory I/O devices. In Opportunistic Networks, nodes are usually mobile, forwarding messages from one device to another, not relying on external infrastructure like WiFi. Due to compact and convenient wearability, the nodes of an OppNet might be used to detect the absence and presence of devices or even people in an area where classical networks may not be reliable enough. In this paper, we combine opportunistic network technology with cyber-physical systems and propose a reliable routing algorithm for nodes tracking. Our real-world setup implements hardware sensor tags to evaluate the algorithm in a state-of-the-art environment. Efficiency and performance are compared with established algorithms i. e., Epidemic and Prophet, in terms of latency, network overhead, as well as message delivery probability, and to evaluate the algorithm's scalability, we simulate the tracking in a huge environment. Samaneh Rashidibajgan, Thomas Hupperich, Robin Doss, Lei Pan 0002 |
TrustCom | 2 |
| 2018 | An Empirical Study on Online Price DifferentiationabstractPrice differentiation describes a marketing strategy to determine the price of goods on the basis of a potential customer's attributes like location, financial status, possessions, or behavior. Several cases of online price differentiation have been revealed in recent years. For example, different pricing based on a user's location was discovered for online office supply chain stores and there were indications that offers for hotel rooms are priced higher for Apple users compared to Windows users at certain online booking websites. One potential source for & relevant distinctive features are system fingerprints, i.e., a technique to recognize users' systems by identifying unique attributes such as the source IP address or system configuration. In this paper, we shed light on the ecosystem of pricing at online platforms and aim to detect if and how such platform providers make use of price differentiation based on digital system fingerprints. We designed and implemented an automated price scanner capable of disguising itself as an arbitrary system, leveraging real-world system fingerprints, and searched for price differences related to different features (e.g., user location, language setting, or operating system). This system allows us to explore price differentiation cases and identify those characteristic features of a system that may influence a product's price. Thomas Hupperich, Dennis Tatang, Nicolai Wilkop, Thorsten Holz |
CODASPY | 1 |
| 2016 | Leveraging Sensor Fingerprinting for Mobile Device Authentication
Thomas Hupperich, Henry Hosseini, Thorsten Holz |
DIMVA | 1 |
| 2016 | Use the Force: Evaluating Force-Sensitive Authentication for Mobile Devices
Katharina Krombholz, Thomas Hupperich, Thorsten Holz |
SOUPS | 2 |
| 2015 | On the Robustness of Mobile Device Fingerprinting: Can Mobile Users Escape Modern Web-Tracking Mechanisms?abstractClient fingerprinting techniques enhance classical cookie-based user tracking to increase the robustness of tracking techniques. A unique identifier is created based on characteristic attributes of the client device, and then used for deployment of personalized advertisements or similar use cases. Whereas fingerprinting performs well for highly customized devices (especially desktop computers), these methods often lack in precision for highly standardized devices like mobile phones. Thomas Hupperich, Davide Maiorca, Marc Kührer, Thorsten Holz, Giorgio Giacinto |
ACSAC | 1 |
| 2015 | Going Wild: Large-Scale Classification of Open DNS ResolversabstractSince several years, millions of recursive DNS resolvers are-deliberately or not-open to the public. This, however, is counter-intuitive, since the operation of such openly accessible DNS resolvers is necessary in rare cases only. Furthermore, open resolvers enable both amplification DDoS and cache snooping attacks, and can be abused by attackers in multiple other ways. We thus find open recursive DNS resolvers to remain one critical phenomenon on the Internet. Marc Kührer, Thomas Hupperich, Jonas Bushart, Christian Rossow, Thorsten Holz |
Internet Measurement Conference | 2 |
| 2014 | Exit from Hell? Reducing the Impact of Amplification DDoS Attacks
Marc Kührer, Thomas Hupperich, Christian Rossow, Thorsten Holz |
USENIX Security Symposium | 2 |