VLDB 2026 Research / reviewers in the wild / expert
Jack West
dblp:261/9547
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Analysis of Always-Listening Services on AndroidabstractAlways-listening services are a defining feature of modern Android, enabling capabilities such as keyword spotting, music recognition, and adaptive audio. Despite their ubiquity, these services remain opaque: users lack visibility into when audio is recorded, where it is processed, and how it's used. Their infrastructure encompasses specialized hardware, low-level system frameworks, machine learning models, and proprietary applications, making them challenging to analyze. We present the first systematic analysis of Android's always-listening ecosystem. We develop a reverse engineering approach that reconstructs the architecture, maps key functions through static analysis, and uses dynamic instrumentation to characterize runtime behaviors. Applying this methodology, we extract and analyze the machine learning models powering these services, uncover undocumented triggers for audio capture, and evaluate a new class of unintentional activations we call "local misactivations". We reveal that keyword spotting and music recognition models can misactivate up to 58 times per hour, capturing several seconds of audio each time without issuing notifications to the user. We further quantify the resource cost of these misactivations, showing that each event increases device power consumption by 18–81% over idle and consumes 305–454 ms of CPU time on the application processor. Our work highlights the need for greater transparency and user control for always-listening services on mobile devices. Leo Cao, Jack West, Kassem Fawaz |
MobiSys | 2 |
| 2025 | "Impressively Scary: ' Exploring User Perceptions and Reactions to Unraveling Machine Learning Models in Social Media ApplicationsabstractMachine learning models deployed locally on social media applications are used for features, such as face filters which read faces in-real time, and they expose sensitive attributes to the apps. However, the deployment of machine learning models, e.g., when, where, and how they are used, in social media applications is opaque to users. We aim to address this inconsistency and investigate how social media user perceptions and behaviors change once exposed to these models. We conducted user studies (N=21) and found that participants were unaware to both what the models output and when the models were used in Instagram and TikTok, two major social media platforms. In response to being exposed to the models' functionality, we observed long term behavior changes in 8 participants. Our analysis uncovers the challenges and opportunities in providing transparency for machine learning models that interact with local user data. Jack West, Bengisu Cagiltay, Shirley Zhang 0002, Kassem Fawaz, Suman Banerjee 0001 |
CHI | 1 |
| 2024 | A Picture is Worth 500 Labels: A Case Study of Demographic Disparities in Local Machine Learning Models for Instagram and TikTokabstractMobile apps have embraced user privacy by moving their data processing to the user’s smartphone. Advanced machine learning (ML) models, such as vision models, can now locally analyze user images to extract insights that drive several functionalities. Capitalizing on this new processing model of locally analyzing user images, we analyze two popular social media apps, TikTok and Instagram, to reveal (1) what insights vision models in both apps infer about users from their image and video data and (2) whether these models exhibit performance disparities with respect to demographics. As vision models provide signals for sensitive technologies like age verification and facial recognition, understanding potential biases in these models is crucial for ensuring that users receive equitable and accurate services.We develop a novel method for capturing and evaluating ML tasks in mobile apps, overcoming challenges like code obfuscation, native code execution, and scalability. Our method comprises ML task detection, ML pipeline reconstruction, and ML performance assessment, specifically focusing on demographic disparities. We apply our methodology to TikTok and Instagram, revealing significant insights. For TikTok, we find issues in age and gender prediction accuracy, particularly for minors and Black individuals. In Instagram, our analysis uncovers demographic disparities in extracting over 500 visual concepts from images, with evidence of spurious correlations between demographic features and certain concepts. Jack West, Lea Thiemt, Shimaa Ahmed, Maggie Bartig, Kassem Fawaz, Suman Banerjee 0001 |
SP | 1 |
| 2022 | Are You Really Muted?: A Privacy Analysis of Mute Buttons in Video Conferencing AppsabstractVideo conferencing apps (VCAs) make it possible for previously private spaces — bedrooms, living rooms, and kitchens — into semi-public extensions of the office. For the most part, users have accepted these apps in their personal space without much thought about the permission models that govern the use of their private data during meetings. While access to a device’s video camera is carefully controlled, little has been done to ensure the same level of privacy for accessing the microphone. In this work, we ask the question: what happens to the microphone data when a user clicks the mute button in a VCA? We first conduct a user study to analyze users’ understanding of the permission model of the mute button. Then, using runtime binary analysis tools, we trace raw audio flow in many popular VCAs as it traverses the app from the audio driver to the network. We find fragmented policies for dealing with microphone data among VCAs — some continuously monitor the microphone input during mute, and others do so periodically. One app transmits statistics of the audio to its telemetry servers while the app is muted. Using network traffic that we intercept en route to the telemetry server, we implement a proof-of-concept background activity classifier and demonstrate the feasibility of inferring the ongoing background activity during a meeting — cooking, cleaning, typing, etc. We achieved 81.9% macro accuracy on identifying six common background activities using intercepted outgoing telemetry packets when a user is muted. Yucheng Yang 0003, Jack West, George K. Thiruvathukal, Neil Klingensmith, Kassem Fawaz |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Moonshine: An Online Randomness Distiller for Zero-Involvement AuthenticationabstractContext-based authentication is a method for transparently validating another device's legitimacy to join a network based on location. Devices can pair with one another by continuously harvesting environmental noise to generate a random key with no user involvement. However, there are gaps in our understanding of the theoretical limitations of environmental noise harvesting, making it difficult for researchers to build efficient algorithms for sampling environmental noise and distilling keys from that noise. This work explores the information-theoretic capacity of context-based authentication mechanisms to generate random bit strings from environmental noise sources with known properties. Using only mild assumptions about the source process's characteristics, we demonstrate that commonly-used bit extraction algorithms extract only about 10% of the available randomness from a source noise process. We present an efficient algorithm to improve the quality of keys generated by context-based methods and evaluate it on real key extraction hardware. MOONSHINE is a randomness distiller which is more efficient at extracting bits from an environmental entropy source than existing methods. Our techniques nearly double the quality of keys as measured by the NIST test suite, producing keys that can be used in real-world authentication scenarios. Jack West, Kyuin Lee, Suman Banerjee 0001, Younghyun Kim 0001, George K. Thiruvathukal, Neil Klingensmith |
IPSN | 1 |