Marc Roßberger

dblp:252/7937 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2026
0009-0000-7067-9432ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Does Anonymity Love the Chat Groups?
abstract
Instant messaging is an integral part of daily communication, and users increasingly seek anonymous options to protect their privacy. Mix networks are a well-established approach for metadata protection, but current designs largely overlook the unique challenges of instant messaging, such as low-latency expectations, bursty interaction patterns, and group chats. In this work, we present the first systematic analysis of mix networks, and anonymization systems in general, for group messaging under realistic conditions. We introduce a novel group-identification attack that exploits co-occurrence patterns of recipients to infer group membership with high accuracy, even against a significantly weaker attacker model than these systems typically assume, a local observer. Our evaluation leverages real-world WhatsApp data and adapts it to better reflect realistic usage scenarios. Finally, we evaluate how defense strategies such as relaxing low latency requirements to allow for more delay options and cover traffic perform against this attack. Our findings reveal critical weaknesses in current designs and provide insights for improving anonymity in instant group messaging.
Marc Roßberger, Dogan Kesdogan
CODASPY1
2021 DaRoute: Inferring trajectories from zero-permission smartphone sensors
abstract
Nowadays, smartphones are equipped with a multitude of sensors, including GPS, that enables location-based services. However, leakage or misuse of user locations poses a severe privacy threat, motivating operating systems to usually restrict direct access to these resources for applications. Nevertheless, this work demonstrates how an adversary can deduce sensitive location information by inferring a vehicle’s trajectory through inbuilt motion sensors collectible by zero-permission mobile apps. Therefore, the presented attack incorporates data from the accelerometer, the gyroscope, and the magnetometer. We then extract so-called path events from raw data to eventually match them against reference data from OpenStreetMap. At the example of real-world data from three different cities, several drivers, and different smartphones, we show that our approach can infer traveled routes with high accuracy within minutes while robust to sensor errors. Our experiments show that even for areas as large as approximately 4500 $\mathrm{k}\mathrm{m}^{2}$, the accuracy of detecting the correct route is as high as 87.14%, significantly outperforming similar approaches from Narain et al. and Waltereit et al.
Christian Roth 0002, Thanh Dinh, Marc Roßberger, Dogan Kesdogan
PST3