VLDB 2026 Research / reviewers in the wild / expert
Sarah Radway
dblp:279/6398
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0003-2071-6682ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | More Modalities, More Problems: Examining User Understanding of The Meta Quest Permissions FrameworkabstractCompared with preceding consumer technologies, virtual reality (VR) requires extensive collection of sensitive biometric data. On the Meta Quest 2 (the most popular consumer headset), application access to sensitive data is mediated by a permissions system adapted from Android’s model. In this work, we examine how VR’s immersive nature necessitates new permissions considerations beyond preceding technology and current VR devices. We analyze the Meta Quest 2’s permissions system, identifying where it diverges from Android's user-facing behavior surrounding biometric data. We then investigate the implications of both conventional Android and novel Quest permission flows through an in-person VR interview study with 23 participants. We observe that many participants lacked awareness of how VR collects data or the extent of passive tracking in VR. Based on these findings, we offer recommendations for VR permissions models and suggest directions for future work. Sarah Radway, Matthew Soto, Suvi Lama, Carson Powers, Daniel Votipka |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | Amigo: Secure Group Mesh Messaging in Realistic Protest SettingsabstractDuring large-scale protests, a repressive government will often disable the Internet to thwart communication between protesters. Smartphone mesh networks, which route messages over short-range, possibly ephemeral, radio connections between nearby phones, allow protesters to communicate without relying on centralized Internet infrastructure. Unfortunately, prior work on providing secure communication in Internet shutdown settings fails to adequately consider protester needs. Previous attempts fail to support efficient private group communication (a crucial requirement for protests), and evaluate their solutions in network environments which fail to accurately capture link churn, physical spectrum contention, and the mobility models found in realistic protest settings. In this paper, we introduce Amigo, a novel mesh messaging system which supports group communication through a decentralized approach to continuous key agreement, and forwards messages using a novel routing protocol. Amigo is uniquely designed to handle the challenges of ad-hoc routing scenarios, where dynamic network topologies and node mobility make achieving key agreement nontrivial. Our extensive simulations reveal the poor scalability of prior approaches, the benefits of Amigo's protest-specific optimizations, and the challenges that still must be solved to scale secure mesh networks to protests with thousands of participants. David Inyangson, Sarah Radway, Tushar M. Jois, Nelly Fazio, James W. Mickens |
CCS | 2 |
| 2025 | Guillotine: Hypervisors for Isolating Malicious AIsabstractAs AI models become more embedded in critical sectors like finance, healthcare, and the military, their inscrutable behavior poses ever-greater risks to society. To mitigate this risk, we propose Guillotine, a hypervisor architecture for sandboxing powerful AI models---models that, by accident or malice, can generate existential threats to humanity. Although Guillotine borrows some well-known virtualization techniques, Guillotine must also introduce fundamentally new isolation mechanisms to handle the unique threat model posed by existential-risk AIs. For example, a rogue AI may try to introspect upon hypervisor software or the underlying hardware substrate to enable later subversion of that control plane; thus, a Guillotine hypervisor requires careful co-design of the hypervisor software and the CPUs, RAM, NIC, and storage devices that support the hypervisor software, to thwart side channel leakage and more generally eliminate mechanisms for AI to exploit reflection-based vulnerabilities. Beyond such isolation at the software, network, and microarchitectural layers, a Guillotine hypervisor must also provide physical fail-safes more commonly associated with nuclear power plants, avionic platforms, and other types of mission-critical systems. Physical fail-safes, e.g., involving electromechanical disconnection of network cables, or the flooding of a datacenter which holds a rogue AI, provide defense in depth if software, network, and microarchitectural isolation is compromised and a rogue AI must be temporarily shut down or permanently destroyed. James W. Mickens, Sarah Radway, Ravi Netravali |
HotOS | 2 |
| 2024 | An Investigation of US Universities' Implementation of FERPA Student Directory Policies and Student Privacy PreferencesabstractThe Family Education Rights and Privacy Act (FERPA) is intended to protect student privacy, but has not adapted well to current technology. We consider a special class of student data: directory information. Unlike other FERPA-controlled data, directory information (e.g., student names, contact information, university affiliation) can be shared publicly online or by request without explicit permission. Sarah Radway, Katherine Quintanilla, Cordelia Ludden, Daniel Votipka |
CHI | 1 |
| 2022 | Differential Privacy and Swapping: Examining De-Identification's Impact on Minority Representation and Privacy Preservation in the U.S. CensusabstractThere has been considerable controversy regarding the accuracy and privacy of de-identification mechanisms used in the U.S. Decennial Census. We theoretically and experimentally analyze two such classes of mechanisms, swapping and differential privacy, especially examining their effects on ethnoracial minority groups.We first prove that the expected error of queries made on swapped demographic datasets is greater in sub-populations whose racial distributions differ more from the racial distribution of the global population. We also prove that the probability that m unique entries exist in a sub-population shrinks exponentially as the sub-population size grows. These properties suggest that swapping, which prioritizes unique entries, will produce poor accuracy for minority groups.We then empirically analyze the impact of swapping and differential privacy on the accuracy and privacy of a demographic dataset. We evaluate accuracy in several ways, including methods that stress the effect on minority groups. We evaluate privacy by counting the number of re-identified entries in a simulated linkage attack. Finally, we explore the disproportionate presence of minority groups in identified entries.Our empirical lindings corroborate our theoretical results: for minority representation, the utility of differential privacy is comparable to the utility of swapping, while providing a stronger privacy guarantee. Swapping places a disproportionate privacy burden on minority groups, whereas an ε-differentially private mechanism is ε-differentially private for all subgroups. Miranda Christ, Sarah Radway, Steven M. Bellovin |
SP | 2 |