VLDB 2026 Research / reviewers in the wild / expert
Christopher Ellis
dblp:26/7995
· DBLP profile ↗
5ranked-venue papers
4as first author
3since 2021 · last 2026
0000-0002-7760-1846ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Access Granted, Privacy Lost: Formalizing & Quantifying the Hidden Anonymity Risks of Exclusive-Use SystemsabstractExclusive-use systems emit binary interaction signals through core functions such as authentication, presence updates, and message submissions. Although sparse and encrypted, these signals reflect user-specific behavior and, when linked over time, can erode anonymity. Because each credential or device is uniquely tied to an individual, even minimal activity patterns can enable re-identification and behavioral inference, posing a hidden but persistent privacy risk. We present a formal framework that models this leakage by digitizing interaction outcomes into multidimensional binary signals and quantifying anonymity degradation using entropy-based Quantitative Information Flow (QIF), Bayes vulnerability, and indistinguishability games. To generalize the threat, we introduce a taxonomy spanning attacker capabilities, observation methods, and types of information leaked. After discovering these signals from network analysis of Microsoft Teams, we produce a simulation case study with varying user activity profiles, demonstrating that content-agnostic signals alone enable a passive adversary to achieve 54.7% Top-1 and 89.1% Top-3 re-identification accuracy in a 16-user pool, with mean entropy losses of approximately 1.2 bits (about 30% of the 4-bit anonymity space), and worst-case reductions exceeding 2.4 bits. Additional analyses of WhatsApp traffic and the IDBleed BLE relay attack highlight broader applicability. Our results show that binary observables long treated as benign can systematically compromise anonymity, establishing a cross-domain framework for formalizing, quantifying, and classifying privacy loss in exclusive-use systems. This framework further enables defenders to formally model exclusive-use systems and quantitatively evaluate the privacy impact of proposed mitigations using entropy and vulnerability-based metrics. Christopher Ellis, Zhiqiang Lin 0001 |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | Deanonymizing Device Identities via Side-channel Attacks in Exclusive-use IoTs & Mitigation
Christopher Ellis, Yue Zhang 0025, Mohit Kumar Jangid, Shixuan Zhao 0002, Zhiqiang Lin 0001 |
NDSS | 1 |
| 2022 | Replay (Far) Away: Exploiting and Fixing Google/Apple Exposure Notification Contact TracingabstractDigital contact tracing offers significant promise to help reduce the spread of SARS-CoV-2 and other viruses. Google and Apple joined together in 2020 to create the Google/Apple Exposure Notification (GAEN) framework to determine encounters with anonymous users later diagnosed COVID-19 positive. However, as GAEN lacks geospatial awareness, it is susceptible to geographically distributed replay attacks. Anonymous, low-cost, crowd-sourced replay attack networks deployed by malicious actors (or far away nation-state attackers) who utilize malicious (or innocent) users’ smartphones to capture and replay GAEN advertisements can drastically increase false-positive rates even in areas that otherwise exhibit low positivity rates. In response to this powerful replay attack, we introduce GAEN+ , a solution that enhances GAEN with geospatial awareness while maintaining user privacy, and demonstrate its ability to effectively prevent geographically distributed replay attacks. Christopher Ellis, Haohuang Wen, Zhiqiang Lin 0001, Anish Arora |
Proc. Priv. Enhancing Technol. | 1 |
| 2017 | The Ark: a customizable web-based data management tool for health and medical researchabstractSummary: The Ark is an open-source web-based tool that allows researchers to manage health and medical research data for humans and animals without specialized database skills or programming expertise. The system provides data management for core research information including demographic, phenotype, biospecimen and pedigree data, in addition to supporting typical investigator requirements such as tracking participant consent and correspondence, whilst also being able to generate custom data exports and reports. The Ark is 'study generic' by design and highly configurable via its web interface, allowing researchers to tailor the system to the specific data management requirements of their study. Availability and Implementation: Source code for The Ark can be obtained freely from the website https://github.com/The-Ark-Informatics/ark/ . The source code can be modified and redistributed under the terms of the GNU GPL v3 license. Documentation and a pre-configured virtual appliance can be found at the website http://sphinx.org.au/the-ark/ . Contact: [email protected]. Supplementary information: Supplementary data are available at Bioinformatics online. Adrian C. Bickerstaffe, Thilina Ranaweera, Travis Endersby, Christopher Ellis, Sanjay Maddumarachchi, George E. Gooden, Eric K. Moses, Alex W. Hewitt, John L. Hopper |
Bioinform. | 4 |
| 2013 | Exploring the Trade-off Between Accuracy and Observational Latency in Action Recognition
Christopher Ellis, Syed Zain Masood, Marshall F. Tappen, Joseph J. LaViola Jr., Rahul Sukthankar |
Int. J. Comput. Vis. | 1 |