Majed Almansoori

dblp:272/3319 · DBLP profile ↗
← Back
10ranked-venue papers
7as first author
9since 2021 · last 2026
0000-0002-5298-7703ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 4 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Cultivating a Tech-Safety Mindset using Game-Based Learning for Defending against Technology-Facilitated Abuse
abstract
Technology-facilitated abuse (TFA) has become increasingly common as abusers exploit everyday technologies to monitor and harass others, mainly their intimate partners. Preventing TFA requires not only reactive technical support but proactively cultivating protective mindsets --- awareness of personal vulnerability, recognition of threat severity, and confidence to implement defensive strategies --- before abuse escalates. Yet no research has developed educational tools grounded in behavior change theory specifically for technology-facilitated abuse prevention. We address this gap with BeSafe, a narrative-driven visual novel game grounded in Protection Motivation Theory (PMT) and designed to shift how users perceive and respond to TFA threats. Through a study with 198 participants across six platform contexts, we assessed both knowledge acquisition and changes in PMT constructs: perceived vulnerability, perceived severity, self-efficacy, and fear arousal. Our results show that BeSafe produced significant knowledge gains alongside meaningful shifts in protection motivation. Participants with prior exposure to online abuse showed substantially greater gains across both knowledge and motivation measures. Many participants reported intentions to review privacy settings and share protective strategies with others, indicating motivation to act on what they learned. Our findings demonstrate that game-based interventions can cultivate digital safety mindsets, offering a scalable, proactive complement to existing reactive support services.
Majed Almansoori, Chirag Ghosh, Sarita Singh, Rahul Chatterjee 0001, Mainack Mondal
Proc. Priv. Enhancing Technol.1
2025 Can Social Media Privacy and Safety Features Protect Targets of Interpersonal Attacks? A Systematic Analysis
abstract
Social media applications have benefited users in several ways, including ease of communication and quick access to information. However, they have also introduced several privacy and safety risks. These risks are particularly concerning in the context of interpersonal attacks, which are carried out by abusive friends, family members, intimate partners, co-workers, or even strangers. Evidence shows interpersonal attackers regularly exploit social media platforms to harass and spy on their targets. To help protect targets from such attacks, social media platforms have introduced several privacy and safety features. However, it is unclear how effective they are against interpersonal threats. In this work, we analyzed ten popular social media applications, identifying 100 unique privacy and safety features that provide controls across eight categories: discoverability, visibility, saving and sharing, interaction, self-censorship, content moderation, transparency, and reporting. We simulated 59 different attack actions by a persistent attacker — aimed at account discovery, information gathering, non-consensual sharing, and harassment — and found many were successful. Based on our findings, we proposed improvements to mitigate these risks.
Majed Almansoori, Rahul Chatterjee 0001
Proc. Priv. Enhancing Technol.1
2024 The Web of Abuse: A Comprehensive Analysis of Online Resource in the Context of Technology-Enabled Intimate Partner Surveillance
abstract
Previous research has shown that abusers in an intimate relationship can find plenty of technical advice, tools, and how-to guides online for covertly conducting intimate partner surveillance (IPS). However, it is unclear what resources survivors seeking to defend themselves against IPS can use. To address this gap, we first conducted a survey-based study with 63 survivors recruited via Prolific to understand what resources survivors rely on. We showed that 45% utilized online resources for assistance, with 67% of them relying on search engines. We then conducted a systematic survey of the results obtained via Google search engine to identify resources available for survivors. We found that the resources survivors can find online contain poor, inaccurate, and unactionable advice. They are hard to understand and do not help mitigate IPS. To investigate whether the lack of useful resources is solely experienced by survivors, we also crawled resources that abusers will find online. We found that abusers can easily find resources recommending spyware apps and hidden devices and often explicitly promoting IPS. We also compared the understandability and actionability of the resources using an adopted Patient Education Materials Assessment Tool (PEMAT) score. We concluded that resources available to abusers are significantly more understandable and actionable than those available to survivors.
Majed Almansoori, Mazharul Islam 0002, Saptarshi Ghosh 0001, Mainack Mondal, Rahul Chatterjee 0001
EuroS&P1
2023 Towards Finding the Missing Pieces to Teach Secure Programming Skills to Students
abstract
Research efforts tried to expose students to security topics early in the undergraduate CS curriculum. However, such efforts are rarely adopted in practice and remain less effective when it comes to writing secure code. In our prior work [18], we identified key issues with the how students code and grouped them into six themes: (a) Knowledge of C, (b) Understanding compiler and OS messages, (c) Utilization of resources, (d) Knowledge of memory, (e) Awareness of unsafe functions, and (f) Understanding of security topics. In this work, we aim to understand students' knowledge about each theme and how that knowledge affects their secure coding practices. Thus, we propose a modified SOLO taxonomy for the latter five themes. We apply the taxonomy to the coding interview data of 21 students from two US R1 universities. Our results suggest that most students have limited knowledge of each theme. We also show that scoring low in these themes correlates with why students fail to write secure code and identify possible vulnerabilities.
Majed Almansoori, Jessica Lam, Elias Fang, Adalbert Gerald Soosai Raj, Rahul Chatterjee 0001
SIGCSE (1)1
2023 "It's the Equivalent of Feeling Like You're in Jail": Lessons from Firsthand and Secondhand Accounts of IoT-Enabled Intimate Partner Abuse
Sophie Stephenson, Majed Almansoori, Pardis Emami Naeini, Rahul Chatterjee 0001
USENIX Security Symposium2
2023 Abuse Vectors: A Framework for Conceptualizing IoT-Enabled Interpersonal Abuse
Sophie Stephenson, Majed Almansoori, Pardis Emami Naeini, Danny Yuxing Huang, Rahul Chatterjee 0001
USENIX Security Symposium2
2022 Identifying Gaps in the Secure Programming Knowledge and Skills of Students
abstract
Often, security topics are only taught in advanced computer science (CS) courses. However, most US R1 universities do not require students to take these courses to complete an undergraduate CS degree. As a result, students can graduate without learning about computer security and secure programming practices. To gauge students' knowledge and skills of secure programming, we conducted a coding interview with 21 students from two R1 universities in the United States. All the students in our study had at least taken Computer Systems or an equivalent course. We then analyzed the students' approach to safe programming practices, such as avoiding unsafe functions like gets and strcpy, and basic security knowledge, such as writing code that assumes user inputs can be malicious. Our results suggest that students lack the key fundamental skills to write secure programs. For example, students rarely pay attention to details, such as compiler warnings, and often do not read programming language documentation with care. Moreover, some students' understanding of memory layout is cursory, which is crucial for writing secure programs. We also found that some students are struggling with even the basics of C programming, even though it is the main language taught in Computer Systems courses.
Jessica Lam, Elias Fang, Majed Almansoori, Rahul Chatterjee 0001, Adalbert Gerald Soosai Raj
SIGCSE (1)3
2022 A Global Survey of Android Dual-Use Applications Used in Intimate Partner Surveillance
abstract
Intimate partner violence (IPV) is a pervasive societal problem that affects millions of people around the world. IPV perpetrators increasingly weaponize digital technologies like mobile applications (“apps”) to spy on, monitor, and harass victims. Surveillance-capable apps can have legitimate use cases, for example, locating children, and are therefore easily available on various mobile app stores like the Google Play Store. Nevertheless, these applications are easily repurposed by abusers to track their victims. The problem of such dual-use apps in IPV is global. However, current understanding of the ecosystem of such apps is limited to English-language apps, potentially limiting its relevance to non-English speaking IPV survivors across the world. In this paper, we study the prevalence of dualuse applications found in 15 languages and 27 countries. We collected 51,868 unique apps in 2020 from the Google Play Store, using queries such as “track wife’s location.” Through a semi-manual analysis of a subset of these apps, we discovered 854 unique dualuse apps, and estimate that among the apps collected from Google Play, 3,988 are dual-use apps. We found notable differences in app search results, suggested queries, and marketed capabilities of dual-use apps across different languages. For instance, we identified that 18% of dual-use apps do not have an English description, and 28% could not be found using English queries. Google Play (cursorily) blocks certain queries referring explicitly to intimate partner surveillance (IPS) to discourage potential abusers, but the blocking efficacy varies across languages. For example, we found that 80% of explicit IPS queries for English are blocked, but none for Bengali, Chinese, Hindi, Malay, Thai, and Vietnamese. Thus, abusers fluent in those languages can evade such blocking with no effort.
Majed Almansoori, Andrea Gallardo, Julio Poveda, Adil Ahmed, Rahul Chatterjee 0001
Proc. Priv. Enhancing Technol.1
2021 Textbook Underflow: Insufficient Security Discussions in Textbooks Used for Computer Systems Courses
abstract
Introductory computer science courses, such as Computer Systems, could be used to provide the first exposure to computer security to students. However, prior work has shown that, in the US's top R1 universities, computer systems courses are not taught with security in mind. It was also shown that students and instructors use unsafe functions in their code, leading to security vulnerabilities. In this paper, we focused on the textbooks used for computer systems courses. We analyzed the discussion of security topics and the use of unsafe functions in the thirteen textbooks used in the top 30 R1 universities in the US for teaching computer systems. We show that many textbooks do not discuss security at all, while some limit their discussion to "undefined behavior'', ignoring that opportunity to discuss potential security issues associated with the undefined behavior. Furthermore, textbooks that talk about security continue using unsafe functions throughout (though not necessarily in vulnerable ways but also without any warning or explanation). We also show that many textbooks do not warn about unsafe functions they use or teach how to use them safely.
Majed Almansoori, Jessica Lam, Elias Fang, Adalbert Gerald Soosai Raj, Rahul Chatterjee 0001
SIGCSE1
2020 How Secure are our Computer Systems Courses?
abstract
Introductory computer systems courses teach students how a single program is executed inside a computer, providing them with their first exposure to the logical internals of computing systems. This is one of the first introductory courses where students can learn about security and the need for robust coding. However, currently, these courses are taught with a focus on functionality and efficiency only, ignoring security almost entirely.
Majed Almansoori, Jessica Lam, Elias Fang, Kieran Mulligan, Adalbert Gerald Soosai Raj, Rahul Chatterjee 0001
ICER1