VLDB 2026 Research / reviewers in the wild / expert
Enze Liu 0001
dblp:249/3123-1
· DBLP profile ↗
14ranked-venue papers
7as first author
12since 2021 · last 2026
0000-0003-4288-8485ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 3 first-author · 5 since 2021Security and privacy · 6 · 4 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From "Be Careful" to "Here's Why": Investigating User Reasoning with Context-Specific SMS Scam Warnings
Elijah Robert Bouma-Sims, Enze Liu 0001, Alexandra Xinran Li, Lorrie Faith Cranor |
SP | 2 |
| 2026 | Lost in Translation: Text Message Spoofing via Email
Sumanth Rao, Ye Shu, Stefan Savage, Aaron Schulman, Geoffrey M. Voelker, Enze Liu 0001 |
SP | 6 |
| 2025 | Somesite I Used To Crawl: Awareness, Agency and Efficacy in Protecting Content Creators From AI CrawlersabstractThe success of generative AI relies heavily on training on data scraped through extensive crawling of the Internet, a practice that has raised significant copyright, privacy, and ethical concerns. While few measures are designed to resist a resource-rich adversary determined to scrape a site, crawlers can be impacted by a range of existing tools such as robots.txt, NoAI meta tags, and active crawler blocking by reverse proxies. In this work, we seek to understand the ability and efficacy of today's networking tools to protect content creators against AI-related crawling. For targeted populations like human artists, do they have the technical knowledge and agency to utilize crawler blocking tools such as robots.txt, and can such tools be effective? Using large scale measurements and a targeted user study of 203 professional artists, we find strong demand for tools like robots.txt, but significantly constrained by critical hurdles in technical awareness, agency in deploying them, and limited efficacy against unresponsive crawlers. We further test and evaluate network level crawler blockers provided by reverse proxies. Despite relatively limited deployment today, they offer stronger protections against AI crawlers, but still come with their own set of limitations. Enze Liu 0001, Elisa Luo, Shawn Shan, Geoffrey M. Voelker, Ben Y. Zhao, Stefan Savage |
IMC | 1 |
| 2025 | Poster: When Blocks Go Missing: The Timeliness and Trustworthiness of Blockchain RPC ProvidersabstractContrary to blockchain's trustless vision, most applications built atop blockchain require trust in third-party Remote Procedure Call (RPC) providers. Applications rely on these RPC providers to be performant (announce new blocks timely) and reliable (no missing blocks/transactions) to provide good user experience and security guarantees. In this paper, we perform the first large-scale, longitudinal study to evaluate the timeliness and trustworthiness of 16 RPC providers for BNB Smart Chain (BSC) across 6 223 blocks and 123 773 transactions. We identify significant variability: some providers are inconsistent, miss valid blocks/transactions, or are seconds slower than others. Our findings suggest that the implicit trust assumptions are often violated, which may leave users confused and even vulnerable to attacks. Ye Shu, Deian Stefan, Stefan Savage, Geoffrey M. Voelker, Enze Liu 0001 |
IMC | 5 |
| 2024 | Give and Take: An End-To-End Investigation of Giveaway Scam Conversion RatesabstractThe Internet's combination of low communication cost, global reach, and functional anonymity has allowed fraudulent scam volumes to reach new heights. Designing effective interventions requires first understanding the context: how scammers reach potential victims, the earnings they make, and any potential bottlenecks for durable interventions. In this short paper, we focus on these questions in the context of cryptocurrency giveaway scams, where victims are tricked into irreversibly transferring funds to scammers under the pretense of even greater returns. Combining data from Twitter (also known as X), YouTube and Twitch livestreams, landing pages, and cryptocurrency blockchains, we measure how giveaway scams operate at scale. We find that 1 in 1000 scam tweets, and 4 in 100,000 livestream views, net a victim, and that scammers managed to extract nearly $4.62 million from just hundreds of victims during our measurement window. Enze Liu 0001, George Kappos, Eric Mugnier, Luca Invernizzi, Stefan Savage, David Tao, Kurt Thomas, Geoffrey M. Voelker, Sarah Meiklejohn |
IMC | 1 |
| 2024 | Unfiltered: Measuring Cloud-based Email Filtering BypassesabstractEmail service has increasingly been outsourced to cloud-based providers and so too has the task of filtering such messages for potential threats. Thus, customers will commonly direct that their incoming email is first sent to a third-party email filtering service (e.g., Proofpoint or Barracuda) and only the "clean" messages are then sent on to their email hosting provider (e.g., Gmail or Microsoft Exchange Online). However, this loosely coupled approach can, in theory, be bypassed if the email hosting provider is not configured to only accept messages that arrive from the email filtering service. In this paper we demonstrate that such bypasses are commonly possible. We document a multi-step methodology to infer if an organization has correctly configured its email hosting provider to guard against such scenarios. Then, using an empirical measurement of edu and com domains as a case study, we show that 80% of such organizations making use of popular cloud-based email filtering services can be bypassed in this manner. We also discuss reasons that lead to such misconfigurations and outline challenges in hardening the binding between email filtering and hosting providers. Sumanth Rao, Enze Liu 0001, Grant Ho, Geoffrey M. Voelker, Stefan Savage |
WWW | 2 |
| 2024 | NewsGuesser: Using Curiosity to Reduce Selective ExposureabstractSelective exposure has long been a concern of HCI researchers as it can lead to ideological polarization and distrust in society. Efforts have tried to reduce selective exposure online by serving diversified news content, but their effectiveness has been limited by users' lack of motivation to engage with the diverse content offered. To address this, we design the NewsGuesser system, which leverages the insight that curiosity can prompt motivation and engagement, by asking readers to guess the source of their news. In interviews with 40 participants, balanced for partisan affiliation, we use NewsGuesser as a probe tool to explore how guessing affects their perceptions of selective exposure. Participants struggled with the guessing game, which revealed a misalignment between users' expectations of different news sources and reality. Faced with the visualizations of the (often inaccurate) guessing results, participants were able to reflect on their own biases and selective exposure. In a number of cases, the guessing process changed participants' impressions of news organizations and some expressed an interest in engaging with more diverse news sources. While many also found the guessing game frustrating, the system and interview results suggest a number of new directions for designing social media and news media platforms. Hengyuan Zhang 0001, Enze Liu 0001, Kristen Vaccaro |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2023 | Forward Pass: On the Security Implications of Email Forwarding Mechanism and PolicyabstractThe critical role played by email has led to a range of extension protocols (e.g., SPF, DKIM, DMARC) designed to protect against the spoofing of email sender domains. These protocols are complex as is, but are further complicated by automated email forwarding — used by individual users to manage multiple accounts and by mailing lists to redistribute messages. In this paper, we explore how such email forwarding and its implementations can break the implicit assumptions in widely deployed anti-spoofing protocols. Using large-scale empirical measurements of 20 email forwarding services (16 leading email providers and four popular mailing list services), we identify a range of security issues rooted in forwarding behavior and show how they can be combined to reliably evade existing anti-spoofing controls. We further show how these issues allow attackers to not only deliver spoofed email messages to prominent email providers (e.g., Gmail, Microsoft Outlook, and Zoho), but also reliably spoof email on behalf of tens of thousands of popular domains including sensitive domains used by organizations in government (e.g., state.gov), finance (e.g., transunion.com), law (e.g., perkinscoie.com) and news (e.g., washingtonpost.com) among others. Enze Liu 0001, Gautam Akiwate, Mattijs Jonker, Ariana Mirian, Grant Ho, Geoffrey M. Voelker, Stefan Savage |
EuroS&P | 1 |
| 2023 | Understanding the Viability of Gmail's Origin Indicator for Identifying the Sender
Enze Liu 0001, Alex Bellon, Grant Ho, Geoffrey M. Voelker, Stefan Savage, Imani N. S. Munyaka |
SOUPS | 1 |
| 2023 | No Privacy Among Spies: Assessing the Functionality and Insecurity of Consumer Android Spyware AppsabstractConsumer mobile spyware apps covertly monitor a user's activities (i.e., text messages, phone calls, e-mail, location, etc.) and transmit that information over the Internet to support remote surveillance. Unlike conceptually similar apps used for state espionage, so-called "stalkerware" apps are mass-marketed to consumers on a retail basis and expose a far broader range of victims to invasive monitoring. Today the market for such apps is large enough to support dozens of competitors, with individual vendors reportedly monitoring hundreds of thousands of phones. However, while the research community is well aware of the existence of such apps, our understanding of the mechanisms they use to operate remains ad hoc. In this work, we perform an in-depth technical analysis of 14 distinct leading mobile spyware apps targeting Android phones. We document the range of mechanisms used to monitor user activity of various kinds (e.g., photos, text messages, live microphone access) — primarily through the creative abuse of Android APIs. We also discover previously undocumented methods these apps use to hide from detection and to achieve persistence. Additionally, we document the measures taken by each app to protect the privacy of the sensitive data they collect, identifying a range of failings on the part of spyware vendors (including privacy-sensitive data sent in the clear or stored in the cloud with little or no protection). Enze Liu 0001, Sumanth Rao, Sam Havron, Grant Ho, Stefan Savage, Geoffrey M. Voelker, Damon McCoy |
Proc. Priv. Enhancing Technol. | 1 |
| 2021 | Who's got your mail?: characterizing mail service provider usageabstractE-mail has long been a critical component of daily communication and the core medium for modern business correspondence. While traditionally e-mail service was provisioned and implemented independently by each Internet-connected organization, increasingly this function has been outsourced to third-party services. As with many pieces of key communications infrastructure, such centralization can bring both economies of scale and shared failure risk. In this paper, we investigate this issue empirically --- providing a large-scale measurement and analysis of modern Internet e-mail service provisioning. We develop a reliable methodology to better map domains to mail service providers. We then use this approach to document the dominant and increasing role played by a handful of mail service providers and hosting companies over the past four years. Finally, we briefly explore the extent to which nationality (and hence legal jurisdiction) plays a role in such mail provisioning decisions. Enze Liu 0001, Gautam Akiwate, Mattijs Jonker, Ariana Mirian, Stefan Savage, Geoffrey M. Voelker |
Internet Measurement Conference | 1 |
| 2021 | Home is where the hijacking is: understanding DNS interception by residential routersabstractDNS interception --- when a user's DNS queries to a target resolver are intercepted en route and forwarded to a different resolver --- is a phenomenon of concern to both researchers and Internet users because of its implications for security and privacy. While the prevalence of DNS interception has received some attention, less is known about where in the network interception takes place. We introduce methods to identify where DNS interception occurs and who the interceptors may be. We identify when interception is performed before the query exits the ISP, and even when it is performed by the Customer Premises Equipment (CPE) in the user's own home. We believe that these techniques are vital in the light of the ongoing debate concerning the value of privacy-enhancing DNS transport. Audrey Randall, Enze Liu 0001, Ramakrishna Padmanabhan, Gautam Akiwate, Geoffrey M. Voelker, Stefan Savage, Aaron Schulman |
Internet Measurement Conference | 2 |
| 2020 | Trufflehunter: Cache Snooping Rare Domains at Large Public DNS ResolversabstractThis paper presents and evaluates Trufflehunter, a DNS cache snooping tool for estimating the prevalence of rare and sensitive Internet applications. Unlike previous efforts that have focused on small, misconfigured open DNS resolvers, Trufflehunter models the complex behavior of large multi-layer distributed caching infrastructures (e.g., such as Google Public DNS). In particular, using controlled experiments, we have inferred the caching strategies of the four most popular public DNS resolvers (Google Public DNS, Cloudflare Quad1, OpenDNS and Quad9). The large footprint of such resolvers presents an opportunity to observe rare domain usage, while preserving the privacy of the users accessing them. Using a controlled testbed, we evaluate how accurately Trufflehunter can estimate domain name usage across the U.S. Applying this technique in the wild, we provide a lower-bound estimate of the popularity of several rare and sensitive applications (most notably smartphone stalkerware) which are otherwise challenging to survey. Audrey Randall, Enze Liu 0001, Gautam Akiwate, Ramakrishna Padmanabhan, Geoffrey M. Voelker, Stefan Savage, Aaron Schulman |
Internet Measurement Conference | 2 |
| 2019 | Reasoning Analytically about Password-Cracking SoftwareabstractA rich literature has presented efficient techniques for estimating password strength by modeling password-cracking algorithms. Unfortunately, these previous techniques only apply to probabilistic password models, which real attackers seldom use. In this paper, we introduce techniques to reason analytically and efficiently about transformation-based password cracking in software tools like John the Ripper and Hashcat. We define two new operations, rule inversion and guess counting, with which we analyze these tools without needing to enumerate guesses. We implement these techniques and find orders-of-magnitude reductions in the time it takes to estimate password strength. We also present four applications showing how our techniques enable increased scientific rigor in optimizing these attacks' configurations. In particular, we show how our techniques can leverage revealed password data to improve orderings of transformation rules and to identify rules and words potentially missing from an attack configuration. Our work thus introduces some of the first principled mechanisms for reasoning scientifically about the types of password-guessing attacks that occur in practice. Enze Liu 0001, Amanda Nakanishi, Maximilian Golla, David Cash, Blase Ur |
IEEE Symposium on Security and Privacy | 1 |