VLDB 2026 Research / reviewers in the wild / expert
Javaria Ahmad
dblp:261/1490
· DBLP profile ↗
3ranked-venue papers
2as first author
3since 2021 · last 2024
0000-0001-6828-6154ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Eunomia: A Real-time Privacy Compliance Firewall for Alexa SkillsabstractVoice assistants (VAs), such as Amazon Alexa, are integrated with numerous smart home devices to process user requests using apps called skills. With their growing popularity, VAs also pose serious privacy concerns. Sensitive user data captured by VAs may be transmitted to third-party skills without users’ consent or knowledge about how their data is handled. Privacy policies are a standard medium to inform the users of the skills’ data practices. However, privacy policy compliance verification of such skills is challenging, since the source code is controlled by the skill developers, who can make arbitrary changes to the behaviors of the skill without being audited; hence, conventional defense mechanisms using static/dynamic code analysis can be easily evaded. In this paper, we present Eunomia, the first real-time privacy compliance firewall for Alexa skills. As the skills interact with the users, Eunomia hijacks and examines their communications from the skills to the users, and validates them against the published privacy policies that are parsed using a BERT-based policy analysis module. When non-compliant skill behaviors are detected, Eunomia stops the interaction and warns the user about the non-compliance. We evaluate Eunomia with 55,898 skills on Amazon skills store to demonstrate its effectiveness and to provide a privacy compliance landscape of Alexa skills. Javaria Ahmad, Fengjun Li, Razvan Beuran, Bo Luo |
ACSAC | 1 |
| 2022 | IoTPrivComp: A Measurement Study of Privacy Compliance in IoT Apps
Javaria Ahmad, Fengjun Li, Bo Luo |
ESORICS (2) | 1 |
| 2021 | You Are (not) Who Your Peers Are: Identification of Potentially Excessive Permission Requests in Android AppsabstractMillions of Android applications are now deployed on billions of smartphones and tablet devices. An enormous amount of users' private data are being collected and made accessible to such apps. Extensive research efforts have been devoted to smartphone app security. In particular, the current practice of the app markets and app security scanners is to ensure that the requested permissions are consistent with the used permissions. On the other hand, mobile apps need to seek consent from users to approve various permissions to access user information. However, users often blindly accept permission requests and apps start to abuse this mechanism. For example, a flashlight app may obtain users' locations and send them out to the server. As long as a permission is requested by the app developer and approved by the users, the state-of-art detection mechanisms will treat it as benign. In this paper, we ask the question “are the permission requests really necessary?” The question is difficult to answer because it is hard to autonomously “comprehend” whether a permission is needed for the functionality of the app. We take the first attempt to tackle this challenge by comparing an app's permission requests with its peer apps, i.e., apps with similar functionalities. An app that requests/uses significantly more permissions than its peers is considered potentially malicious that will require further investigation. With this idea, we design a statistical approach to identify potentially excessive permission requests and evaluate it with apps from Play Store. Experiment results and case studies show that the proposed mechanism could effectively identify highly suspicious apps, which request many permissions that are not relevant to their functionalities. Prashanthi Mallojula, Javaria Ahmad, Fengjun Li, Bo Luo |
TrustCom | 2 |