Jens Grossklags

dblp:28/3855 · DBLP profile ↗
← Back
83ranked-venue papers
5as first author
39since 2021 · last 2026
0000-0003-1093-1282ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 47 · 2 first-author · 18 since 2021Human-computer interaction and ubiquitous computing · 20 · 1 first-author · 15 since 2021Artificial intelligence and machine learning · 9 · 1 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-author · 3 since 2021Computer networks · 3Software engineering, systems software and programming languages · 3 · 2 since 2021Theory of computation · 2 · 1 first-author
YearPublicationVenuePosition
2026 Investigating How Types of Data Associated With Smart Home Devices Influence Privacy Concerns and Perceived Benefits
abstract
Domestic appliances and objects are increasingly augmented with data-driven “smart” capabilities. Such Smart Home Devices (SHDs) may receive data directly from users, observe their surroundings with sensors, or infer/predict information through computation. We conducted a scenario-based questionnaire study across multiple regions to investigate user perceptions and expectations regarding the handling of these three types of data associated with SHDs. We systematically varied the scenarios across participants to examine whether the level of ambiguity in the description of an SHD influences user perceptions and expectations regarding its data-handling operations. The study included four SHDs that differed in complexity (two complex and two simple) as a within-subjects treatment. We found that reducing ambiguity in describing SHD operations fosters greater user understanding while increasing privacy concerns about data handling, with notable variations in effects across data types, device complexity, and region. Our findings can be applied to enhance user awareness and control of data handling in the SHD context and inform SHD-specific data protection regulation.
Sameer Patil 0001, Tom Wenzel, Jens Grossklags
CHI3
2026 Timestamps Unchained: Toward Secure Distance-Bounding on Commodity Wi-Fi Hardware
abstract
Distance-bounding protocols provide strong security guarantees, yet their secure realization depends on high-precision physical-layer timestamping of signal transmission and reception. In principle, modern commodity IEEE 802.11 chipsets fulfill these technical requirements. However, distance-bounding research and experimentation on Wi-Fi remain severely limited, as the required high-precision timestamping functionality on 802.11 hardware is tightly coupled to fixed protocol exchanges (e.g., FTM) implemented in closed-source firmware. This restricts the freedom of open research.
Maximilian von Tschirschnitz, Daniel von Kirschten, Viktor Boskovski, Simon Neuenhausen, Jens Grossklags
WISEC5
2026 Unlocking personal data from online services: user studies on data export experiences and data transfer scenarios
abstract
In recent years, online services have started to make personal data of users more accessible by offering dedicated ways of exporting data. The introduction of download portals is associated with increasing demands by privacy regulations regarding the rights of users, such as the Right of Access (Art. 15) and the Right to Data Portability (Art. 20) of the European Union’s General Data Protection Regulation (GDPR). These rights aim to empower users by increasing their control over the personal data that online services hold about them. They allow users to export their personal data and thereby gain insights on the scope of personal data held by the services and to transfer this data to other services. However, until now, little is known about how users experience and evaluate the process of accessing and exporting their data and how it impacts individual-level factors such as privacy-related attitudes (i.e. attitudes regarding sharing personal data, perceived control over data, and using privacy-protective strategies). In this paper, we report the results of an online survey with an experimental condition (N = 728) and a second online survey (N = 817) where participants from two university courses were asked to request real data exports from online services and inspect the exported data afterward. We find that inspecting exported personal data has a statistically significant positive effect on users’ privacy-related attitudes. However, users perceive limited usefulness in switching scenarios where personal data is transferred to a new substitutional service and rather prefer to use the data at multiple complementary services.
Emmanuel Syrmoudis, Robert Luzsa, Yvonne Ehrlich, Dennis Agidigbi, Kai Kirsch, Danny Rudolf, Daniel Schlaeger, Joelle Weber, Jens Grossklags
Hum. Comput. Interact.9
2026 Analyzing Societal Awareness and Perception of Digital Fingerprinting and Fingerprinting Countermeasures
abstract
We explore societal awareness and perceptions related to digital fingerprinting, a stateless tracking technology increasingly used for online security, advertising, and fraud prevention, as well as to countermeasures designed to mitigate its impact. Despite its widespread application, user awareness of fingerprinting remains significantly lower compared to other tracking mechanisms, such as third-party cookies. To deepen our understanding of user perceptions, we conducted a study surveying 734 participants to assess their knowledge of fingerprinting, acceptance of its use across different applications (cybersecurity, law enforcement, user experience), and their reactions to browsing inconveniences introduced by countermeasures. Countermeasures examined include privacy-focused browsers (e.g., Tor), browser extensions, and spoofing tools. While these solutions vary in effectiveness, they often compromise usability, resulting in issues such as website breakages and prolonged CAPTCHA challenges. Privacy-conscious users demonstrated greater tolerance for such disruptions, whereas others prioritized convenience over protection.
Pascal Schramm, Emmanuel Syrmoudis, Alexandros Markou, Jens Grossklags
Proc. Priv. Enhancing Technol.4
2025 Eliciting Change Towards Better Virtual Worlds: A Workshop Process to Foster Ethical Reflection in Creative Technology Design Processes
abstract
The concept of the metaverse, recently re-emerging in public discourse, is viewed by some as the internet's next evolutionary stage, while others regard it as a dubious promise of a future where physical and digital worlds merge seamlessly. As the metaverse takes shape, it is crucial to question whether its design will embody the values of the societies it aims to serve.
Michel Hohendanner, Chiara Ullstein, Axel Böttcher, Paul Gong, Jens Grossklags
Creativity & Cognition5
2025 Initiating the Global AI Dialogues: Laypeople Perspectives on the Future Role of genAI in Society from Nigeria, Germany and Japan
Michel Hohendanner, Chiara Ullstein, Bukola Abimbola Onyekwelu, Amelia Katirai, Jun Kuribayashi, Olusola Babalola, Arisa Ema, Jens Grossklags
CHI8
2025 Bridging Perspectives for Socially Sustainable AI: What People Across 12 Countries Think about genAI and FPT, and What Policymakers Want to Know Their Opinions On
Chiara Ullstein, Michel Hohendanner, Simeon Emilov Ivanov, Georgi Tsipov, Jens Grossklags
COMPASS6
2025 Micro Machines, Macro Visions: Experts' Visions and Laypeoples' Perceptions of Social Futures With In-Body Cybernetic Avatars
abstract
Cybernetic avatars (CAs) play a key role in Japan’s vision for Society 5.0 – a society where cyberspace and the physical world are closely intertwined to address social challenges. In-body cybernetic avatars, a sub-category, are remote-controlled micro-/nano-scale avatars or robots operating inside organisms, such as the human body. To explore future applications and implications of interactions with these technologies, we conducted an expert workshop (N = 16) in Japan. Experts co-created visions of a desirable future related to in-body CAs, identifying types of interactions, benefits, and potential risks. In a second study, we engaged an international student audience (N = 174) with three expert-developed scenarios to assess non-expert perceptions beyond Japan. We find that non-experts responded positively to all three types of in-body CA interactions. In addition, our study contributes to a better understanding of potential benefits and risks of in-body CAs from experts’ perspectives and sheds light on which factors are perceived as most impactful by non-experts.
Michel Hohendanner, Chiara Ullstein, Mena Mesenhöller, Hirotaka Osawa, Jens Grossklags
HAI5
2025 Rediscovering Method Confusion in Proposed Security Fixes for Bluetooth
Maximilian von Tschirschnitz, Ludwig Peuckert, Moritz Buhl, Jens Grossklags
NDSS4
2025 More Than Just Functional: LLM-as-a-Critique for Efficient Code Generation
abstract
Large language models (LLMs) have demonstrated remarkable progress in generating functional code, leading to numerous AI-based coding program tools. However, their reliance on the perplexity objective during both training and inference primarily emphasizes functionality, often at the expense of efficiency—an essential consideration for real-world coding tasks. Perhaps interestingly, we observed that well-trained LLMs inherently possess knowledge about code efficiency, but this potential remains underutilized with standard decoding approaches. To address this, we design strategic prompts to activate the model’s embedded efficiency understanding, effectively using LLMs as \textit{efficiency critiques} to guide code generation toward higher efficiency without sacrificing—and sometimes even improving—functionality, all without the need for costly real code execution. Extensive experiments on benchmark datasets (EffiBench, HumanEval+) across multiple representative code models demonstrate up to a 70.6\% reduction in average execution time and a 13.6\% decrease in maximum memory usage, highlighting the computational efficiency and practicality of our approach compared to existing alternatives.
Derui Zhu, Dingfan Chen, Jinfu Chen 0002, Jens Grossklags, Alexander Pretschner, Weiyi Shang
NeurIPS4
2024 A Longitudinal Analysis of Corporate Data Portability Practices Across Industries
abstract
Lock-in practices of online services hinder consumers from switching frictionlessly to a competitor once they are unsatisfied with the company’s service offering, privacy practices, or philosophy. The right to data portability (RtDP) is one of the strongest measures introduced by recent privacy regulations to unlock continuously collected user data from centralized silos of market leaders. Introducing the obligation to provide means of data transfers between services, it aims to establish decentralized online markets and to foster competition. In this longitudinal study comprising a unique dataset of 129 online services over three consecutive years, we are the first to provide evidence on the development of the effectiveness of the EU’s RtDP. Astonishingly, only 16% of services could provide a compliant data export in all years, with services from the industries Entertainment and Travel performing worst. Overall, Finance & Insurance and Social Networks & Messaging include the services with the highest compliance rates. Regarding the usefulness of data portability, our analysis unveils that data export scope and data import options have stagnated between 2020 and 2022. Further, we are able to show that online services with a high presence of third-party trackers are less compliant and ready to export data from their systems. Lastly, our regression analyses show that service popularity significantly increases format compliance, export scope, and import options. This suggests that competitors to incumbents still perceive the regulation more as a bureaucratic burden than a unique opportunity to attract new consumers and their data.
Emmanuel Syrmoudis, Stefan Mager, Jens Grossklags
ACSAC3
2024 Social Scoring Systems for Behavioral Regulation: An Experiment on the Role of Transparency in Determining Perceptions and Behaviors
abstract
Recent developments in artificial intelligence research have advanced the spread of automated decision-making (ADM) systems used for regulating human behaviors. In this context, prior work has focused on the determinants of human trust in and the legitimacy of ADM systems, e.g., when used for decision support. However, studies assessing people's perceptions of ADM systems used for behavioral regulation, as well as the effect on behaviors and the overall impact on human communities are largely absent. In this paper, we experimentally investigate people's behavioral adaptations to, and their perceptions of an institutionalized decision-making system, which resembled a social scoring system. Using social scores as incentives, the system aimed at ensuring mutual fair treatment between members of experimental communities. We explore how the provision of transparency affected people’s perceptions, behaviors, as well as the well-being of the communities. While a non-transparent scoring system led to disparate impacts both within as well as across communities, transparency helped people develop trust in each other, create wealth, and enabled them to benefit from the system in a more uniform manner. A transparent system was perceived as more effective, procedurally just, and legitimate, and led people to rely more strongly on the system. However, transparency also made people strongly discipline those with a low score. This suggests that social scoring systems that precisely disclose past behaviors may also impose significant discriminatory consequences on individuals deemed non-compliant.
Carmen Loefflad, Mo Chen 0003, Jens Grossklags
AIES (1)3
2024 PrivAuditor: Benchmarking Data Protection Vulnerabilities in LLM Adaptation Techniques
abstract
Large Language Models (LLMs) are recognized for their potential to be an important building block toward achieving artificial general intelligence due to their unprecedented capability for solving diverse tasks. Despite these achievements, LLMs often underperform in domain-specific tasks without training on relevant domain data. This phenomenon, which is often attributed to distribution shifts, makes adapting pre-trained LLMs with domain-specific data crucial. However, this adaptation raises significant privacy concerns, especially when the data involved come from sensitive domains. In this work, we extensively investigate the privacy vulnerabilities of adapted (fine-tuned) LLMs and benchmark privacy leakage across a wide range of data modalities, state-of-the-art privacy attack methods, adaptation techniques, and model architectures. We systematically evaluate and pinpoint critical factors related to privacy leakage. With our organized codebase and actionable insights, we aim to provide a standardized auditing tool for practitioners seeking to deploy customized LLM applications with faithful privacy assessments.
Derui Zhu, Dingfan Chen, Xiongfei Wu, Jiahui Geng, Zhuo Li 0021, Jens Grossklags, Lei Ma 0003
NeurIPS6
2024 Metaverse Perspectives from Japan: A Participatory Speculative Design Case Study
abstract
Currently, the development of the metaverse lies in the hands of industry. Citizens have little influence on this process. Instead, to do justice to the pluralism of (digital) societies, we should strive for an open discourse including many different perspectives on the metaverse and its core technologies such as AI. We utilize a participatory speculative design (PSD) approach to explore Japanese citizens' perspectives on future metaverse societies, as well as social and ethical implications. Our contributions are twofold. Firstly, we demonstrate the effectiveness of PSD in engaging citizens in critical discourse on emerging technologies like the metaverse by presenting our workshop framework and participants' processes. Secondly, we identify key themes from participants' perspectives, providing insights for culturally sensitive design and development of virtual environments. Our analysis shows that participants imagine the metaverse to have the potential to solve a variety of societal issues; for example, breaking down barriers of physical environments for communication, social interaction, crisis preparation, and political participation, or tackling identity-related issues. Regarding future metaverse societies, participants' imaginations raise critical questions about human-AI relations, technical solutionism, politics and technology, globalization and local cultures, and immersive technologies. We discuss implications and contribute to expanding conversations on metaverse developments.
Michel Hohendanner, Chiara Ullstein, Dohjin Miyamoto, Emma Fukuwatari Huffman, Gudrun Socher, Jens Grossklags, Hirotaka Osawa
Proc. ACM Hum. Comput. Interact.6
2024 Vulnerabilities of Data Protection in Vertical Federated Learning Training and Countermeasures
abstract
Vertical federated learning (VFL) is an increasingly popular, yet understudied, collaborative learning technique. In VFL, features and labels are distributed among different participants allowing for various innovative applications in business domains, e.g., online marketing. When deploying VFL, training data (labels and features) from each participant ought to be protected; however, very few studies have investigated the vulnerability of data protection in the VFL training stage. In this paper, we propose a posterior-difference-based data attack,VFLRecon, reconstructing labels and features to examine this problem. Our experiments show that standard VFL is highly vulnerable to serious privacy threats, with reconstruction achieving up to 92% label accuracy and 0.05 feature MSE, compared to our baseline with 55% label accuracy and 0.19 feature MSE. Even worse, this privacy risk remains during standard operations (e.g., encrypted aggregation) that appear to be safe. We also systematically analyze data leakage risks in the VFL training stage across diverse data modalities (i.e., tabular data and images), different training frameworks (i.e., with or without encryption techniques), and a wide range of training hyperparameters. To mitigate this risk, we design a novel defense mechanism,VFLDefender, dedicated to obfuscating the correlation between bottom model changes and labels (features) during training. The experimental results demonstrate thatVFLDefenderprevents reconstruction attacks during standard encryption operations (around 17% more effective than standard encryption operations).
Derui Zhu, Jinfu Chen 0002, Xuebing Zhou, Weiyi Shang, Ahmed E. Hassan, Jens Grossklags
IEEE Trans. Inf. Forensics Secur.6
2023 RandCompile: Removing Forensic Gadgets from the Linux Kernel to Combat its Analysis
abstract
Recently proposed tools such as LogicMem, Katana, and AutoProfile enable a fine-grained inspection of the operating system’s memory. They provide insights that were previously only available for Linux machines specifically instrumented for cooperation with virtual machine introspection frameworks. An overly controlling cloud operator can now regularly deep-inspect VMs under their control.
Fabian Franzen, Andreas Chris Wilhelmer, Jens Grossklags
ACSAC3
2023 The Effectiveness of Security Interventions on GitHub
abstract
In 2017, GitHub was the first online open source platform to show security alerts to its users. It has since introduced further security interventions to help developers improve the security of their open source software. In this study, we investigate and compare the effects of these interventions. This offers a valuable empirical perspective on security interventions in the context of software development, enriching the predominantly qualitative and survey-based literature landscape with substantial data-driven insights. We conduct a time series analysis on security-altering commits covering the entire history of a large-scale sample of over 50,000 GitHub repositories to infer the causal effects of the security alert, security update, and code scanning interventions. Our analysis shows that while all of GitHub's security interventions have a significant positive effect on security, they differ greatly in their effect size. By comparing the design of each intervention, we identify the building blocks that worked well and those that did not. We also provide recommendations on how practitioners can improve the design of their interventions to enhance their effectiveness.
Felix Fischer 0001, Jonas Höbenreich, Jens Grossklags
CCS3
2023 Bug Hunters' Perspectives on the Challenges and Benefits of the Bug Bounty Ecosystem
Omer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali, Jens Grossklags, Michelle L. Mazurek, Daniel Votipka, Aron Laszka
USENIX Security Symposium5
2023 The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and Firefox
abstract
Recently, bug-bounty programs have gained popularity and become a significant part of the security culture of many organizations. Bug-bounty programs enable organizations to enhance their security posture by harnessing the diverse expertise of crowds of external security experts (i.e., bug hunters). Nonetheless, quantifying the benefits of bug-bounty programs remains elusive, which presents a significant challenge for managing them. Previous studies focused on measuring their benefits in terms of the number of vulnerabilities reported or based on the properties of the reported vulnerabilities, such as severity or exploitability. However, beyond these inherent properties, the value of a report also depends on the probability that the vulnerability would be discovered by a threat actor before an internal expert could discover and patch it. In this paper, we present a data-driven study of the Chromium and Firefox vulnerability-reward programs. First, we estimate the difficulty of discovering a vulnerability using the probability of rediscovery as a novel metric. Our findings show that vulnerability discovery and patching provide clear benefits by making it difficult for threat actors to find vulnerabilities; however, we also identify opportunities for improvement, such as incentivizing bug hunters to focus more on development releases. Second, we compare the types of vulnerabilities that are discovered internally vs. externally and those that are exploited by threat actors. We observe significant differences between vulnerabilities found by external bug hunters, internal security teams, and external threat actors, which indicates that bug-bounty programs provide an important benefit by complementing the expertise of internal teams, but also that external hunters should be incentivized more to focus on the types of vulnerabilities that are likely to be exploited by threat actors.
Soodeh Atefi, Amutheezan Sivagnanam, Afiya Ayman, Jens Grossklags, Aron Laszka
WWW4
2023 The Unsung Heroes of Facebook Groups Moderation: A Case Study of Moderation Practices and Tools
abstract
Volunteer moderators have the power to shape society through their influence on online discourse. However, the growing scale of online interactions increasingly presents significant hurdles for meaningful moderation. Furthermore, there are only limited tools available to assist volunteers with their work. Our work aims to meaningfully explore the potential of AI-driven, automated moderation tools for social media to assist volunteer moderators. One key aspect is to investigate the degree to which tools must become personalizable and context-sensitive in order to not just delete unsavory content and ban trolls, but to adapt to the millions of online communities on social media mega-platforms that rely on volunteer moderation. In this study, we conduct semi-structured interviews with 26 Facebook Group moderators in order to better understand moderation tasks and their associated challenges. Through qualitative analysis of the interview data, we identify and address the most pressing themes in the challenges they face daily. Using interview insights, we conceptualize three tools with automated features that assist them in their most challenging tasks and problems. We then evaluate the tools for usability and acceptance using a survey drawing on the technology acceptance literature with 22 of the same moderators. Qualitative and descriptive analyses of the survey data show that context-sensitive, agency-maintaining tools in addition to trial experience are key to mass adoption by volunteer moderators in order to build trust in the validity of the moderation technology.
Tina Kuo, Alicia Hernani, Jens Grossklags
Proc. ACM Hum. Comput. Interact.3
2023 Breaking the Silence: Investigating Which Types of Moderation Reduce Negative Effects of Sexist Social Media Content
abstract
Sexist content is widespread on social media and can reduce women's psychological well-being and their willingness to participate in online discourse, making it a societal issue. To counter these effects, social media platforms employ moderators. To date, little is known about the effectiveness of different forms of moderation in creating a safe space and their acceptance, in particular from the perspective of women as members of the targeted group and users in general (rather than perpetrators). In this research, we propose that some common forms of moderation can be systematized along two facets of visibility, namely visibility of sexist content and of counterspeech. In an online experiment (N = 839), we manipulated these two facets and tested how they shaped social norms, feelings of safety, and intent to participate, as well as fairness, trustworthiness, and efficacy evaluations. In line with our predictions, deletion of sexist content - i.e., its invisibility - and (public) counterspeech - i.e., its visibility - against visible sexist content contributed to creating a safe space. Looking at the underlying psychological mechanism, we found that these effects were largely driven by changes in what was perceived normative in the presented context. Interestingly, deletion of sexist content was judged as less fair than counterspeech against visible sexist content. Our research contributes to a growing body of literature that highlights the importance of norms in creating safer online environments and provides practical implications for moderators for selecting actions that can be effective and accepted.
Julia Sasse, Jens Grossklags
Proc. ACM Hum. Comput. Interact.2
2023 Distributed GAN-Based Privacy-Preserving Publication of Vertically-Partitioned Data
abstract
In the era of big data, user data are often vertically partitioned and stored at different local parties. Exploring the data from all the local parties would enable data analysts to gain a better understanding of the user population from different perspectives. However, the publication of vertically-partitioned data faces a dilemma: on the one hand, the original data cannot be directly shared by local parties due to privacy concerns; on the other hand, independently privatizing the local datasets before publishing may break the potential correlation between the cross-party attributes and lead to a significant utility loss. Prior solutions compute the privatized multivariate distributions of different attribute sets for constructing a synthetic integrated dataset. However, these algorithms are only applicable for low-dimensional structured data and may suffer from large utility loss with the increase in data dimensionality. Following the idea of synthetic data generation, we propose VertiGAN, the first framework based on a generative adversarial network (GAN) for publishing vertically-partitioned data with privacy protection. The framework adopts a GAN model comprised of one multi-output global generator and multiple local discriminators. The generator is collaboratively trained by the server and local parties to learn the distribution of all parties' local data and is used to generate a high-utility synthetic integrated dataset on the server side. Additionally, we apply differential privacy (DP) during the training process to ensure strict privacy guarantees for the local data. We evaluate the framework's performance on a number of real-world datasets containing 68--1501 classification attributes and show that our framework is more capable of capturing joint distributions and cross-attribute correlations compared to statistics-based baseline algorithms. Moreover, with a privacy guarantee of epsilon=8, our framework achieves around a 2%~15% improvement in classification accuracy compared to the baseline algorithms. Extensive experimental results demonstrate the capability and efficiency of our framework in synthesizing vertically-partitioned data while striking a satisfactory utility-privacy balance.
Xuebing Zhou, Jens Grossklags
Proc. Priv. Enhancing Technol.4
2022 Ordinary People as Moral Heroes and Foes: Digital Role Model Narratives Propagate Social Norms in China's Social Credit System
abstract
The Chinese Social Credit System (SCS) is a digital sociotechnical credit system that rewards and sanctions economic and social behaviors of individuals and companies. As a complex and transformative digital credit system, the SCS uses digital communication channels to inform the Chinese public about behaviors that lead to reward or sanction. Since 2017, the Chinese government has been publishing "blameworthy" and "praiseworthy" role model narratives of ordinary Chinese citizens on its central SCS information platform creditchina.gov.cn. Across many cultures, role model narratives are a known instrument to convey "appropriate" and "inappropriate" social norms. Using a directed content analysis methodology, we study the SCS-specific social norms embedded in 100 "praiseworthy" and 100 "blameworthy" role model narratives published on creditchina.gov.cn. "Blameworthy" role model narratives stress social norms associated with an "immoral" SCS identity label termed "Lao Lai" - a "moral foe" that fails to repay debt. SCS role model narratives familiarize Chinese society with SCS-specific measures such as digital surveillance, public shaming, and disproportionate punishment. Our study makes progress towards understanding how a state-run sociotechnical credit system combines digital tools with culturally familiar customs to propagate "blameworthy" and "praiseworthy" identities.
Mo Chen 0003, Severin Engelmann, Jens Grossklags
AIES3
2022 Social Media Profiling Continues to Partake in the Development of Formalistic Self-Concepts. Social Media Users Think So, Too
abstract
Social media platforms generate user profiles to recommend informational resources including targeted advertisements. The technical possibilities of user profiling methods go beyond the classification of individuals into types of potential customers. They enable the transformation of implicit identity claims of individuals into explicit declarations of identity. As such, a key ethical challenge of social media profiling is that it stands in contrast with people's ability to self-determine autonomously, a core principle of the right to informational self-determination.
Severin Engelmann, Valentin Scheibe, Fiorella Battaglia, Jens Grossklags
AIES4
2022 Closing Pandora's Box on Naver: Toward Ending Cyber Harassment
Nam Gu Kang, Tina Kuo, Jens Grossklags
ICWSM3
2022 Katana: Robust, Automated, Binary-Only Forensic Analysis of Linux Memory Snapshots
abstract
The development and research of tools for forensically analyzing Linux memory snapshots have stalled in recent years as they cannot deal with the high degree of configurability and fail to handle security advances like structure layout randomization. Existing tools such as Volatility and Rekall require a pre-generated profile of the operating system, which is not always available, and can be invalidated by the smallest source code or configuration changes in the kernel.
Fabian Franzen, Tobias Holl, Manuel Andreas, Julian Kirsch, Jens Grossklags
RAID5
2022 A Multi-Region Investigation of the Perceptions and Use of Smart Home Devices
abstract
Smart Home Devices are household objects and appliances that are augmented with network connectivity and interactive capabilities. However, the benefits and conveniences of such augmentation are tempered by corresponding increases in privacy and security threats. Studies of user perceptions of these threats and user practices for addressing them are limited mostly to specific devices and/or small samples from a single region. To address this gap, we compared perceptions and practices of people in three geographic regions regarding privacy and security matters related to Smart Home Devices. Across these regions, we found differences in perceived regulatory protection and other regional factors. Our findings suggest that a co-evolution of the design and public policy related to Smart Home Devices could enhance privacy protection and drive increased adoption of these devices.
Patrick Bombik, Tom Wenzel, Jens Grossklags, Sameer Patil 0001
Proc. Priv. Enhancing Technol.3
2022 Privacy-Preserving High-dimensional Data Collection with Federated Generative Autoencoder
abstract
Abstract Business intelligence and AI services often involve the collection of copious amounts of multidimensional personal data. Since these data usually contain sensitive information of individuals, the direct collection can lead to privacy violations. Local differential privacy (LDP) is currently considered a state-ofthe-art solution for privacy-preserving data collection. However, existing LDP algorithms are not applicable to high-dimensional data; not only because of the increase in computation and communication cost, but also poor data utility. In this paper, we aim at addressing thecurse-of-dimensionalityproblem in LDP-based high-dimensional data collection. Based on the idea of machine learning and data synthesis, we propose DP-Fed-Wae, an efficient privacy-preserving framework for collecting high-dimensional categorical data. With the combination of a generative autoencoder, federated learning, and differential privacy, our framework is capable of privately learning the statistical distributions of local data and generating high utility synthetic data on the server side without revealing users’ private information. We have evaluated the framework in terms of data utility and privacy protection on a number of real-world datasets containing 68–124 classification attributes. We show that our framework outperforms the LDP-based baseline algorithms in capturing joint distributions and correlations of attributes and generating high-utility synthetic data. With a local privacy guarantee ∈ = 8, the machine learning models trained with the synthetic data generated by the baseline algorithm cause an accuracy loss of 10% ~ 30%, whereas the accuracy loss is significantly reduced to less than 3% and at best even less than 1% with our framework. Extensive experimental results demonstrate the capability and efficiency of our framework in synthesizing high-dimensional data while striking a satisfactory utility-privacy balance.
Xuebing Zhou, Jens Grossklags
Proc. Priv. Enhancing Technol.3
2022 Comprehensive Analysis of Privacy Leakage in Vertical Federated Learning During Prediction
abstract
Abstract Vertical federated learning (VFL), a variant of federated learning, has recently attracted increasing attention. An active party having the true labels jointly trains a model with other parties (referred to as passive parties ) in order to use more features to achieve higher model accuracy. During the prediction phase, all the parties collaboratively compute the predicted confidence scores of each target record and the results will be finally returned to the active party. However, a recent study by Luo et al . [28] pointed out that the active party can use these confidence scores to reconstruct passive-party features and cause severe privacy leakage. In this paper, we conduct a comprehensive analysis of privacy leakage in VFL frameworks during the prediction phase. Our study improves on previous work [28] regarding two aspects. We first design a general gradient-based reconstruction attack framework that can be flexibly applied to simple logistic regression models as well as multi-layer neural networks. Moreover, besides performing the attack under the white-box setting, we give the first attempt to conduct the attack under the black-box setting. Extensive experiments on a number of real-world datasets show that our proposed attack is effective under different settings and can achieve at best twice or thrice of a reduction of attack error compared to previous work [28]. We further analyze a list of potential mitigation approaches and compare their privacy-utility performances. Experimental results demonstrate that privacy leakage from the confidence scores is a substantial privacy risk in VFL frameworks during the prediction phase, which cannot be simply solved by crypto-based confidentiality approaches. On the other hand, processing the confidence scores with information compression and randomization approaches can provide strengthened privacy protection.
Xuebing Zhou, Jens Grossklags
Proc. Priv. Enhancing Technol.3
2022 Leave No Data Behind - Empirical Insights into Data Erasure from Online Services
abstract
Privacy regulations such as the General Data Protection Regulation (GDPR) of the European Union promise to empower users of online services and to strengthen competition in online markets. Its Article 17, the Right to Erasure (Right to be Forgotten), is part of a set of user rights that aim to give users more control over their data by allowing them to switch between services more easily and to delete their data from the old service. In our study, we investigated the data deletion practices of a sample of 90 online services. In a twostage process, we first request the erasure of our data and analyze to what extent public data (e.g., posts on a social network) remains accessible in a non-anonymized format. More than six months later, we request information on our data using Right of Access requests under Art. 15 GDPR to find out if and what data remains. Our results show that a majority of services perform data erasures without observable breaches of the provisions of Art. 17 GDPR. At 27%, the share of non-compliant services is not negligible; in particular, we observe differences between requests submitted using a dedicated button and formal requests under Art. 17 GDPR.
Eduard Rupp, Emmanuel Syrmoudis, Jens Grossklags
Proc. Priv. Enhancing Technol.3
2022 SignDS-FL: Local Differentially Private Federated Learning with Sign-based Dimension Selection
abstract
Federated Learning (FL) [ 31 ] is a decentralized learning mechanism that has attracted increasing attention due to its achievements in computational efficiency and privacy preservation. However, recent research highlights that the original FL framework may still reveal sensitive information of clients’ local data from the exchanged local updates and the global model parameters. Local Differential Privacy (LDP), as a rigorous definition of privacy, has been applied to Federated Learning to provide formal privacy guarantees and prevent potential privacy leakage. However, previous LDP-FL solutions suffer from considerable utility loss with an increase of model dimensionality. Recent work [ 29 ] proposed a two-stage framework that mitigates the dimension-dependency problem by first selecting one “important” dimension for each local update and then perturbing the dimension value to construct the sparse privatized update. However, the framework may still suffer from utility loss because of the insufficient per-stage privacy budget and slow model convergence. In this article, we propose an improved framework, SignDS-FL , which shares the concept of dimension selection with Reference [ 29 ], but saves the privacy cost for the value perturbation stage by assigning random sign values to the selected dimensions. Besides using the single-dimension selection algorithms in Reference [ 29 ], we propose an Exponential Mechanism-based Multi-Dimension Selection algorithm that further improves model convergence and accuracy. We evaluate the framework on a number of real-world datasets with both simple logistic regression models and deep neural networks. For training logistic regression models on structured datasets, our framework yields only a \( \sim \) 1%–2% accuracy loss in comparison to a \( \sim \) 5%–15% decrease of accuracy for the baseline methods. For training deep neural networks on image datasets, the accuracy loss of our framework is less than \( 8\% \) and at best only \( 2\% \) . Extensive experimental results show that our framework significantly outperforms the previous LDP-FL solutions and enjoys an advanced utility-privacy balance.
Xuebing Zhou, Jens Grossklags
ACM Trans. Intell. Syst. Technol.3
2021 Blacklists and Redlists in the Chinese Social Credit System: Diversity, Flexibility, and Comprehensiveness
abstract
The Chinese Social Credit System (SCS) is a novel digital socio-technical credit system. The SCS aims to regulate societal behavior by reputational and material devices. Scholarship on the SCS has offered a variety of legal and theoretical perspectives. However, little is known about its actual implementation. Here, we provide the first comprehensive empirical study of digital blacklists (listing "bad" behavior) and redlists (listing "good" behavior) in the Chinese SCS. Based on a unique data set of reputational blacklists and redlists in 30 Chinese provincial-level administrative divisions (ADs), we show the diversity, flexibility, and comprehensiveness of the SCS listing infrastructure. First, our results demonstrate that the Chinese SCS unfolds in a highly diversified manner: we find differences in accessibility, interface design and credit information across provincial-level SCS blacklists and redlists. Second, SCS listings are flexible. During the COVID-19 outbreak, we observe a swift addition of blacklists and redlists that helps strengthen the compliance with coronavirus-related norms and regulations. Third, the SCS listing infrastructure is comprehensive. Overall, we identify 273 blacklists and 154 redlists across provincial-level ADs. Our blacklist and redlist taxonomy highlights that the SCS listing infrastructure prioritizes law enforcement and industry regulations. We also identify redlists that reward political and moral behavior. Our study substantiates the enormous scale and diversity of the Chinese SCS and puts the debate on its reach and societal impact on firmer ground. Finally, we initiate a discussion on the ethical dimensions of data-driven research on the SCS.
Severin Engelmann, Mo Chen 0003, Lorenz Dang, Jens Grossklags
AIES4
2021 The Effect of Google Search on Software Security: Unobtrusive Security Interventions via Content Re-ranking
abstract
Google Search is where most developers start their Web journey looking for code examples to reuse. It is highly likely that code that is linked to the top results will be among those candidates that find their way into production software. However, as a large amount of secure and insecure code has been identified on the Web, the question arises how the providing webpages are ranked by Google and whether the ranking has an effect on software security. We investigate how secure and insecure cryptographic code examples from Stack Overflow are ranked by Google Search. Our results show that insecure code ends up in the top results and is clicked on more often. There is at least a 22.8% chance that one out of the top three Google Search results leads to insecure code. We introduce security-based re-ranking, where the rank of Google Search is updated based on the security and relevance of the provided source code in the results. We tested our re-ranking approach and compared it to Google's original ranking in an online developer study. Participants that used our modified search engine to look for help online submitted more secure and functional results, with statistical significance. In contrast to prior work on helping developers to write secure code, security-based re-ranking completely eradicates the requirement for any action performed by developers. Our intervention remains completely invisible, and therefore the probability of adoption is greatly increased. We believe security-based re-ranking allows Internet-wide improvement of code security and prevents the far-reaching spread of insecure code found on the Web.
Felix Fischer 0001, Yannick Stachelscheid, Jens Grossklags
CCS3
2021 DeepMemory: Model-based Memorization Analysis of Deep Neural Language Models
abstract
The neural network model is having a significant impact on many real-world applications. Unfortunately, the increasing popularity and complexity of these models also amplifies their security and privacy challenges, with privacy leakage from training data being one of the most prominent issues. In this context, prior studies proposed to analyze the abstraction behavior of neural network models, e.g., RNN, to understand their robustness. However, the existing research rarely addresses privacy breaches caused by memorization in neural language models. To fill this gap, we propose a novel approach, DeepMemory, that analyzes memorization behavior for a neural language model. We first construct a memorization-analysis-oriented model, taking both training data and a neural language model as input. We then build a semantic first-order Markov model to bind the constructed memorization-analysis-oriented model to the training data to analyze memorization distribution. Finally, we apply our approach to address data leakage issues associated with memorization and to assist in dememorization. We evaluate our approach on one of the most popular neural language models, the LSTM-based language model, with three public datasets, namely, WikiText-103, WMT2017, and IWSLT2016. We find that sentences in the studied datasets with low perplexity are more likely to be memorized. Our approach achieves an average AUC of 0.73 in automatically identifying data leakage issues during assessment. We also show that with the assistance of DeepMemory, data breaches due to memorization of neural language models can be successfully mitigated by mutating training data without reducing the performance of neural language models.
Derui Zhu, Jinfu Chen 0002, Weiyi Shang, Xuebing Zhou, Jens Grossklags, Ahmed E. Hassan
ASE5
2021 iTOP: Automating Counterfeit Object-Oriented Programming Attacks
abstract
Exploiting a program requires a security analyst to manipulate data in program memory with the goal to obtain control over the program counter and to escalate privileges. However, this is a tedious and lengthy process as: (1) the analyst has to massage program data such that a logical reliable data passing chain can be established, and (2) depending on the attacker goal certain in-place fine-grained protection mechanisms need to be bypassed. Previous work has proposed various techniques to facilitate exploit development. Unfortunately, none of them can be easily used to address the given challenges. This is due to the fact that data in memory is difficult to be massaged by an analyst who does not know the peculiarities of the program as the attack specification is most of the time only textually available, and not automated at all.
Paul Muntean 0001, Richard Viehoever, Zhiqiang Lin 0001, Gang Tan, Jens Grossklags, Claudia Eckert 0001
RAID5
2021 Method Confusion Attack on Bluetooth Pairing
abstract
Bluetooth provides encryption, authentication, and integrity protection of its connections. These protection mechanisms require that Bluetooth devices initially establish trust on first use through a process called pairing. Throughout this process, multiple alternative pairing methods are supported.In this paper, we describe a design flaw in the pairing mechanism of Bluetooth. This flaw permits two devices to perform pairing using differing methods. While successfully interacting with each other, the devices are not aware of the Method Confusion. We explain how an attacker can cause and abuse this Method Confusion to mount a Method Confusion Attack. In contrast to other attacks targeting the pairing method, our attack applies even in Bluetooth’s highest security mode and cannot be mitigated in the protocol. Through the Method Confusion Attack, an adversary can infiltrate the secured connection between the victims and intercept all traffic.Our attack is successful in practically relevant scenarios. We implemented it as an end-to-end Proof of Concept for Bluetooth Low Energy and tested it with off-the-shelf smartphones, a smartwatch and a banking device. Furthermore, we performed a user study where none of the 40 participants noticed the ongoing attack, and 37 (92.5%) of the users completed the pairing process. Finally, we propose changes to the Bluetooth specification that immunize it against our attack.
Maximilian von Tschirschnitz, Ludwig Peuckert, Fabian Franzen, Jens Grossklags
SP4
2021 Won't You Think of Others?: Interdependent Privacy in Smartphone App Permissions
abstract
The ever increasing amount of data on smartphones often contains private information of others that people interact with via the device. As a result, one user's decisions regarding app permissions can expose the information of other parties. However, research typically focuses on consequences of privacy-related decisions only for the user who makes the decisions. Work on the impact of these decisions on the privacy of others is still relatively scant. We fill this gap with an online study that extends prior work on interdependent privacy in social networking sites to the context of smartphone permissions. Our findings indicate that people typically give less consideration to the implications of their actions for the privacy of others compared to the impact on themselves. However, we found that priming people with information that features others can help reduce this discrepancy. We apply this insight to offer suggestions for enhancing permission-specification interfaces and system architectures to accommodate interdependent privacy.
Maximilian Marsch, Jens Grossklags, Sameer Patil 0001
Proc. ACM Hum. Comput. Interact.2
2021 Data Portability between Online Services: An Empirical Analysis on the Effectiveness of GDPR Art. 20
abstract
Abstract Data portability regulation has promised that individuals will be easily able to transfer their personal data between online service providers. Yet, after more than two years of an active privacy regulation regime in the European Union, this promise is far from being fulfilled. Given the lack of a functioning infrastructure for direct data portability between multiple providers, we investigate in our study how easily an individual could currently make use of an indirect data transfer between providers. We define such porting as a two-step transfer: firstly, requesting a data export from one provider, followed secondly by the import of the obtained data to another provider. To answer this question, we examine the data export practices of 182 online services, including the top one hundred visited websites in Germany according to the Alexa ranking, as well as their data import capabilities. Our main results show that high-ranking services, which primarily represent incumbents of key online markets, provide significantly larger data export scope and increased import possibilities than their lower-ranking competitors. Moreover, they establish more thorough authentication of individuals before export. These first empirical results challenge the theoretical literature on data portability, according to which, it would be expected that incumbents only complied with the minimal possible export scope in order to not lose exclusive consumer data to market competitors free-of-charge. We attribute the practices of incumbents observed in our study to the absence of an infrastructure realizing direct data portability.
Emmanuel Syrmoudis, Stefan Mager, Sophie Kuebler-Wachendorff, Paul Pizzinini, Jens Grossklags, Johann Kranz
Proc. Priv. Enhancing Technol.5
2021 IntRepair: Informed Repairing of Integer Overflows
abstract
Integer overflows have threatened software applications for decades. Thus, in this paper, we propose a novel technique to provide automatic repairs of integer overflows inCsource code. Our technique, based on static symbolic execution, fusesdetection,repair generationandvalidation. This technique is implemented in a prototype namedIntRepair. We appliedIntRepairto 2,052Cprograms (approx. 1 million lines of code) contained in SAMATE's Juliet test suite and 50 synthesized programs that range up to 20 KLOC. Our experimental results show thatIntRepairis able to effectively detect integer overflows and successfully repair them, while only increasing the source code (LOC) and binary (Kb) size by around 1 percent, respectively. Further, we present the results of a user study with 30 participants which shows thatIntRepairrepairs are more than 10x efficient as compared to manually generated code repairs.
Paul Muntean 0001, Martin Monperrus, Jens Grossklags, Claudia Eckert 0001
IEEE Trans. Software Eng.4
2020 ρFEM: Efficient Backward-edge Protection Using Reversed Forward-edge Mappings
abstract
In this paper, we propose reversed forward-edge mapper (ρFEM), a Clang/LLVM compiler-based tool, to protect the backward edges of a program’s control flow graph (CFG) against runtime control-flow hijacking (e.g., code reuse attacks). It protects backward-edge transfers in C/C++ originating from virtual and non-virtual functions by first statically constructing a precise virtual table hierarchy, with which to form a precise forward-edge mapping between callees and non-virtual calltargets based on precise function signatures, and then checks each instrumented callee return against the previously computed set at runtime. We have evaluated ρFEM using the Chrome browser, NodeJS, Nginx, Memcached, and the SPEC CPU2017 benchmark. Our results show that ρFEM enforces less than 2.77 return targets per callee in geomean, even for applications heavily relying on backward edges. ρFEM’s runtime overhead is less than 1% in geomean for the SPEC CPU2017 benchmark and 3.44% in geomean for the Chrome browser.
Paul Muntean 0001, Matthias Neumayer, Zhiqiang Lin 0001, Gang Tan, Jens Grossklags, Claudia Eckert 0001
ACSAC5
2020 An Empirical Study of Android Security Bulletins in Different Vendors
abstract
Mobile devices encroach on almost every part of our lives, including work and leisure, and contain a wealth of personal and sensitive information. It is, therefore, imperative that these devices uphold high security standards. A key aspect is the security of the underlying operating system. In particular, Android plays a critical role due to being the most dominant platform in the mobile ecosystem with more than one billion active devices and due to its openness, which allows vendors to adopt and customize it. Similar to other platforms, Android maintains security by providing monthly security patches and announcing them via the Android security bulletin. To absorb this information successfully across the Android ecosystem, impeccable coordination by many different vendors is required.
Sadegh Farhang, Mehmet Bahadir Kirdan, Aron Laszka, Jens Grossklags
WWW4
2020 Assessing the current state of information security policies in academic organizations
abstract
Purpose Colleges and universities across the USA have seen data breaches and intellectual property theft rise at a heightened rate over the past several years. An integral step in the first line of defense against various forms of attacks are (written) security policies designed to prescribe the construction and function of a technical system, while simultaneously guiding the actions of individuals operating within said system. Unfortunately, policy analysis is an insufficiently discussed topic in many academic communities with very little research being conducted in this space. Design/methodology/approach This work aims to assess the current state of information security policies by analyzing in-use policies from 200 universities and colleges in the USA with the goal of identifying important features and general attributes of these documents. The authors accomplish this through a series of analyzes designed to examine the language and construction of these policies. Findings To summarize high-level results, the authors found that only 54 per cent of the top 200 universities had publicly accessible information security policies, and the policies that were examined lacked consistency with little shared source material. The authors also found that the tonal makeup of these policies lacked a great deal of emotion, but contained a high amount of tentative or ambiguous language leading toward policies that could be viewed as “unclear.” Originality/value This work is an extension of a paper that was presented at ECIS 2018. The authors have added additional analyzes including a cross-policy content and tonal analysis to strengthen the findings and implications of this work for the wider research audience.
Jake Weidman, Jens Grossklags
Inf. Comput. Secur.2
2020 An Analysis of the Current State of the Consumer Credit Reporting System in China
abstract
Abstract The Chinese Social Credit System (SCS), known as the first national digitally-implemented credit rating system, consists of two parallel arms: a government-run and a commercial one. The government-run arm of the SCS, especially efforts to blacklist and redlist individuals and organizations, has attracted significant attention worldwide. In contrast, the commercial part has been less often in the public spotlight except for discussions about Zhima Credit. The commercial arm of the SCS, also referred to as the Consumer Credit Reporting System (CCRS), has been under development for about two decades and took a major step forward in 2015 when 8 companies were granted permission to implement pilot consumer credit reporting programs. This development fundamentally increased the reach and impact of the SCS due to these companies’ sizable customer base and access to vast troves of consumer-related information. In this paper, we first map the Chinese CCRS to understand the actors in the credit reporting ecosystem. Then, we study 13 consumer credit reporting companies to examine how they collect and use personal information. Based on the findings, we discuss the relationship between the CCRS and the SCS including the changes in the power relationships between the government, consumer credit reporting companies and Chinese citizens.
Mo Chen 0003, Jens Grossklags
Proc. Priv. Enhancing Technol.2
2019 Analyzing control flow integrity with LLVM-CFI
abstract
Control-flow hijacking attacks are used to perform malicious computations. Current solutions for assessing the attack surface after a control flow integrity (CFI) policy was applied can measure only indirect transfer averages in the best case without providing any insights w.r.t. the absolute calltarget reduction per callsite, and gadget availability. Further, tool comparison is underdeveloped or not possible at all. CFI has proven to be one of the most promising protections against control flow hijacking attacks, thus many efforts have been made to improve CFI in various ways. However, there is a lack of systematic assessment of existing CFI protections.
Paul Muntean 0001, Matthias Neumayer, Zhiqiang Lin 0001, Gang Tan, Jens Grossklags, Claudia Eckert 0001
ACSAC5
2019 How reliable is the crowdsourced knowledge of security implementation?
abstract
Stack Overflow (SO) is the most popular online Q&A site for developers to share their expertise in solving programming issues. Given multiple answers to a certain question, developers may take the accepted answer, the answer from a person with high reputation, or the one frequently suggested. However, researchers recently observed that SO contains exploitable security vulnerabilities in the suggested code of popular answers, which found their way into security-sensitive high-profile applications that millions of users install every day. This observation inspires us to explore the following questions: How much can we trust the security implementation suggestions on SO? If suggested answers are vulnerable, can developers rely on the community's dynamics to infer the vulnerability and identify a secure counterpart? To answer these highly important questions, we conducted a comprehensive study on security-related SO posts by contrasting secure and insecure advice with the community-given content evaluation. Thereby, we investigated whether SO's gamification approach on incentivizing users is effective in improving security properties of distributed code examples. Moreover, we traced the distribution of duplicated samples over given answers to test whether the community behavior facilitates or prevents propagation of secure and insecure code suggestions within SO. We compiled 953 different groups of similar security-related code examples and labeled their security, identifying 785 secure answer posts and 644 insecure answer posts. Compared with secure suggestions, insecure ones had higher view counts (36,508 vs. 18,713), received a higher score (14 vs. 5), and had significantly more duplicates (3.8 vs. 3.0) on average. 34% of the posts provided by highly reputable so-called trusted users were insecure. Our findings show that based on the distribution of secure and insecure code on SO, users being laymen in security rely on additional advice and guidance. However, the community-given feedback does not allow differentiating secure from insecure choices. The reputation mechanism fails in indicating trustworthy users with respect to security questions, ultimately leaving other users wandering around alone in a software security minefield.
Mengsu Chen, Felix Fischer 0001, Na Meng 0001, Xiaoyin Wang, Jens Grossklags
ICSE5
2019 Enemy At the Gateways: Censorship-Resilient Proxy Distribution Using Game Theory
Milad Nasr, Sadegh Farhang, Amir Houmansadr, Jens Grossklags
NDSS4
2019 Stack Overflow Considered Helpful! Deep Learning Security Nudges Towards Stronger Cryptography
Felix Fischer 0001, Huang Xiao, Ching-Yu Kao, Yannick Stachelscheid, Benjamin Johnson 0001, Danial Razar, Paul Fawkesley, Nat Buckley, Konstantin Böttinger, Paul Muntean 0001, Jens Grossklags
USENIX Security Symposium11
2019 EnTrust: Regulating Sensor Access by Cooperating Programs via Delegation Graphs
Giuseppe Petracca, Yuqiong Sun, Ahmad Atamli-Reineh, Patrick D. McDaniel, Jens Grossklags, Trent Jaeger
USENIX Security Symposium5
2019 On Sharing Intentions, and Personal and Interdependent Privacy Considerations for Genetic Data: A Vignette Study
abstract
Genetics and genetic data have been the subject of recent scholarly work, with significant attention paid towards understanding consent practices for the acquisition and usage of genetic data as well as genetic data security. Attitudes and perceptions concerning the trustworthiness of governmental institutions receiving test-taker data have been explored, with varied findings, but no robust models or deterministic relationships have been established that account for these differences. These results also do not explore in detail the perceptions regarding other types of organizations (e.g., private corporations). Further, considerations of privacy interdependence arising from blood relative relationships have been absent from the conversation regarding the sharing of genetic data. This paper reports the results from a factorial vignette survey study in which we investigate how variables of ethnicity, age, genetic markers, and association of data with the individual's name affect the likelihood of sharing data with different types of organizations. We also investigate elements of personal and interdependent privacy concerns. We document the significant role these factors have in the decision to share or not share genetic data. We support our findings with a series of regression analyses.
Jake Weidman, William Aurite, Jens Grossklags
IEEE ACM Trans. Comput. Biol. Bioinform.3
2018 Take It or Leave It: A Survey Study on Operating System Upgrade Practices
abstract
Software upgrades play a pivotal role in enhancing software performance, and are a critical component of resolving software bugs and patching security issues. However, consumers' eagerness to upgrade to the newest operating system is often tempered after release. In this paper, we focus on the upgrade perceptions and practices of users utilizing Microsoft Windows, with particular consideration given to the current upgrade cycle to Windows 10, which was, for a time, offered at no monetary cost to many users. To better understand the relevant factors for upgrade decisions, we deployed a structured survey, including several open-ended questions to add additional depth. We collected data from 239 Microsoft Windows users and utilized qualitative and quantitative methods to analyze user upgrade practices. Important themes include how to best notify users of upcoming upgrade opportunities, how users perceive privacy issues associated with OS upgrade decisions, and whether security constitutes a significant decision-making factor. We also explore how end-of-life dates, indicating the end of support by the vendor, are perceived by users.
Sadegh Farhang, Jake Weidman, Mohammad Mahdi Kamani, Jens Grossklags, Peng Liu 0005
ACSAC4
2018 CastSan: Efficient Detection of Polymorphic C++ Object Type Confusions with LLVM
Paul Muntean 0001, Sebastian Würl, Jens Grossklags, Claudia Eckert 0001
ESORICS (1)3
2018 τCFI: Type-Assisted Control Flow Integrity for x86-64 Binaries
Paul Muntean 0001, Gang Tan, Zhiqiang Lin 0001, Jens Grossklags, Claudia Eckert 0001
RAID5
2018 Special Issue on the Economics of Security and Privacy: Guest Editors' Introduction
abstract
This editorial introduces the special issue on the economics of security and privacy.
Rainer Böhme, Richard Clayton 0001, Jens Grossklags, Katrina Ligett, Patrick Loiseau, Galina Schwartz
ACM Trans. Internet Techn.3
2018 On the Assessment of Systematic Risk in Networked Systems
abstract
In a networked system, the risk of security compromises depends not only on each node’s security but also on the topological structure formed by the connected individuals, businesses, and computer systems. Research in network security has been exploring this phenomenon for a long time, with a variety of modeling frameworks predicting how many nodes we should expect to lose, on average, for a given network topology, after certain types of incidents. Meanwhile, the pricing of insurance contracts for risks related to information technology (better known as cyber-insurance) requires determining additional information, for example, the maximum number of nodes we should expect to lose within a 99.5% confidence interval. Previous modeling research in network security has not addressed these types of questions, while research on cyber-insurance pricing for networked systems has not taken into account the network’s topology. Our goal is to bridge that gap, by providing a mathematical basis for the assessment of systematic risk in networked systems. We define a loss-number distribution to be a probability distribution on the total number of compromised nodes within a network following the occurrence of a given incident, and we provide a number of modeling results that aim to be useful for cyber-insurers in this context. We prove NP-hardness for the general case of computing the loss-number distribution for an arbitrary network topology but obtain simplified computable formulas for the special cases of star topologies, ER-random topologies, and uniform topologies. We also provide a simulation algorithm that approximates the loss-number distribution for an arbitrary network topology and that appears to converge efficiently for many common classes of topologies. Scale-free network topologies have a degree distribution that follows a power law and are commonly found in real-world networks. We provide an example of a scale-free network in which a cyber-insurance pricing mechanism that relies naively on incidence reporting data will fail to accurately predict the true risk level of the entire system. We offer an alternative mechanism that yields an accurate forecast by taking into account the network topology, thus highlighting the lack/importance of topological data in security incident reporting. Our results constitute important steps toward the understanding of systematic risk and help to contribute to the emergence of a viable cyber-insurance market.
Aron Laszka, Benjamin Johnson 0001, Jens Grossklags
ACM Trans. Internet Techn.3
2017 I Like It, but I Hate It: Employee Perceptions Towards an Institutional Transition to BYOD Second-Factor Authentication
abstract
The continued acceptance of enhanced security technologies in the private sector, such as two-factor authentication, has prompted significant changes of organizational security practices. While past work has focused on understanding how users in consumer settings react to enhanced security measures for banking, email, and more, little work has been done to explore how these technological transitions and applications occur within organizational settings. Moreover, while many corporations have invested significantly to secure their networks for the sake of protecting valuable intellectual property, academic institutions, which also create troves of intellectual property, have fallen behind in this endeavor.
Jake Weidman, Jens Grossklags
ACSAC2
2017 VaultIME: Regaining User Control for Password Managers Through Auto-Correction
Le Guan, Sadegh Farhang, Yu Pu, Pinyao Guo, Jens Grossklags, Peng Liu 0005
SecureComm5
2017 Valuating Friends' Privacy: Does Anonymity of Sharing Personal Data Matter?
Yu Pu, Jens Grossklags
SOUPS2
2017 AWare: Preventing Abuse of Privacy-Sensitive Sensors via Operation Bindings
Giuseppe Petracca, Ahmad Atamli-Reineh, Yuqiong Sun, Jens Grossklags, Trent Jaeger
USENIX Security Symposium4
2016 Sharing Is Caring, or Callous?
Yu Pu, Jens Grossklags
CANS2
2016 Banishing Misaligned Incentives for Validating Reports in Bug-Bounty Platforms
Aron Laszka, Mingyi Zhao, Jens Grossklags
ESORICS (2)3
2016 Towards a Model on the Factors Influencing Social App Users' Valuation of Interdependent Privacy
abstract
Abstract In the context of third-party social apps, the problem of interdependency of privacy refers to users making app adoption decisions which cause the collection and utilization of personal information of users’ friends. In contrast, users’ friends have typically little or no direct influence over these decision-making processes. We conduct a conjoint analysis study with two treatment conditions which vary the app data collection context (i.e., to which degree the functionality of the app makes it necessary for the app developer to collect friends’ information). Analyzing the data, we are able to quantify the monetary value which app users place on their friends’ and their own personal information in each context. Combining these valuations with the responses to a comprehensive survey, we apply structural equation modeling (SEM) analysis to investigate the roles of privacy concern, its antecedents, as well as app data collection context to work towards a model of interdependent privacy for the scenario of third-party social app adoption. We find that individuals’ past experiences regarding privacy invasions are negatively associated with their trust for third-party social apps’ proper handling of their personal information, which in turn influences their concerns for their own privacy associated with third-party social apps. In addition, positive effects of users’ privacy knowledge on concerns for their own privacy and concerns for friends’ privacy regarding app adoption are partially supported. These privacy concerns are further found to affect how users value their own and their friends’ personal information. However, we are unable to support an association between users’ online social capital and their concerns for friends’ privacy. Nor do we have enough evidence to show that treatment conditions moderate the association between the concern for friends’ personal information and the value of such information in app adoption contexts.
Yu Pu, Jens Grossklags
Proc. Priv. Enhancing Technol.2
2015 An Empirical Study of Web Vulnerability Discovery Ecosystems
abstract
In recent years, many organizations have established bounty programs that attract white hat hackers who contribute vulnerability reports of web systems. In this paper, we collect publicly available data of two representative web vulnerability discovery ecosystems (Wooyun and HackerOne) and study their characteristics, trajectory, and impact. We find that both ecosystems include large and continuously growing white hat communities which have provided significant contributions to organizations from a wide range of business sectors. We also analyze vulnerability trends, response and resolve behaviors, and reward structures of participating organizations. Our analysis based on the HackerOne dataset reveals that a considerable number of organizations exhibit decreasing trends for reported web vulnerabilities. We further conduct a regression study which shows that monetary incentives have a significantly positive correlation with the number of vulnerabilities reported. Finally, we make recommendations aimed at increasing participation by white hats and organizations in such ecosystems.
Mingyi Zhao, Jens Grossklags, Peng Liu 0005
CCS2
2015 A Game-Theoretic Study on Non-monetary Incentives in Data Analytics Projects with Privacy Implications
abstract
The amount of personal information contributed by individuals to digital repositories such as social network sites has grown substantially. The existence of this data offers unprecedented opportunities for data analytics research in various domains of societal importance including medicine and public policy. The results of these analyses can be considered a public good which benefits data contributors as well as individuals who are not making their data available. At the same time, the release of personal information carries perceived and actual privacy risks to the contributors. Our research addresses this problem area. In our work, we study a game-theoretic model in which individuals take control over participation in data analytics projects in two ways: 1) individuals can contribute data at a self-chosen level of precision, and 2) individuals can decide whether they want to contribute at all (or not). From the analyst's perspective, we investigate to which degree the research analyst has flexibility to set requirements for data precision, so that individuals are still willing to contribute to the project, and the quality of the estimation improves. We study this tradeoffs scenario for populations of homogeneous and heterogeneous individuals, and determine Nash equilibrium that reflect the optimal level of participation and precision of contributions. We further prove that the analyst can substantially increase the accuracy of the analysis by imposing a lower bound on the precision of the data that users can reveal.
Michela Chessa, Jens Grossklags, Patrick Loiseau
CSF2
2015 Should Cyber-Insurance Providers Invest in Software Security?
abstract
Insurance is based on the diversifiability of individual risks: if an insurance provider maintains a large portfolio of customers, the probability of an event involving a large portion of the customers is negligible. However, in the case of cyber-insurance, not all risks are diversifiable due to software monocultures. If a vulnerability is discovered in a widely used software product, it can be used to compromise a multitude of targets until it is eventually patched, leading to a catastrophic event for the insurance provider. To lower their exposure to non-diversifiable risks, insurance providers may try to influence the security of widely used software products in their customer population, for example, through vulnerability reward programs. We explore the proposal that insurance providers should take a proactive role in improving software security, and provide evidence that this approach is viable for a monopolistic provider. We develop a model which captures the supply and demand sides of insurance, provide computational complexity results on the provider’s investment decisions, and propose different heuristic investment strategies. We demonstrate that investments can reduce non-diversifiable risks and can lead to a more profitable cyber-insurance market. Finally, we detail the relative merits of the different heuristic strategies with numerical results.
Aron Laszka, Jens Grossklags
ESORICS (1)2
2014 How many down?: toward understanding systematic risk in networks
abstract
The systematic risk of a networked system depends to a large extent on its topology. In this paper, we explore this dependency using a model of risk propagation from the literature on interdependent security games. Our main area of focus is on the number of nodes that go down after an attack takes place. We develop a simulation algorithm to study the effects of such attacks on arbitrary topologies, and apply this simulation to scale-free networks. We investigate by graphical illustration how the outcome distribution of such networks exhibits correlation effects that increase the likelihood of losing more nodes at once -- an effect having direct applications to cyber-insurance.
Benjamin Johnson 0001, Aron Laszka, Jens Grossklags
AsiaCCS3
2014 How Task Familiarity and Cognitive Predispositions Impact Behavior in a Security Game of Timing
abstract
This paper addresses security and safety choices that involve a decision on the timing of an action. Examples of such decisions include when to check log files for intruders and when to monitor financial accounts for fraud or errors. To better understand how performance in timing-related security situations is shaped by individuals' cognitive predispositions, we effectively combine survey measures with economic experiments. Two behavioral experiments are presented in which the timing of online security actions is the critical decision-making factor. The feedback modality in the decision-environment is varied between visual feedback with history (Experiment 1), and temporal feedback without history (Experiment 2). Using psychometric scales, we study the role of individual difference variables, specifically risk propensity and need for cognition. The analysis is based on the data from over 450 participants. We find that risk propensity is not a hindrance in timing tasks. Participants of average risk propensity generally benefit from a reflective disposition (high need for cognition), particularly when visual feedback is given. Overall, participants benefit from need for cognition, however, in the more difficult, temporal-estimation task, this requires familiarity with the task.
Jens Grossklags, David Reitter
CSF1
2014 The Complexity of Estimating Systematic Risk in Networks
abstract
This risk of catastrophe from an attack is a consequence of a network's structure formed by the connected individuals, businesses and computer systems. Understanding the likelihood of extreme events, or, more generally, the probability distribution of the number of compromised nodes is an essential requirement to provide risk-mitigation or cyber-insurance. However, previous network security research has not considered features of these distributions beyond their first central moments, while previous cyber-insurance research has not considered the effect of topologies on the supply side. We provide a mathematical basis for bridging this gap: we study the complexity of computing these loss-number distributions, both generally and for special cases of common real-world networks. In the case of scale-free networks, we demonstrate that expected loss alone cannot determine the riskiness of a network, and that this riskiness cannot be naively estimated from smaller samples, which highlights the lack/importance of topological data in security incident reporting.
Benjamin Johnson 0001, Aron Laszka, Jens Grossklags
CSF3
2014 Social Status and the Demand for Security and Privacy
Jens Grossklags, Nigel J. Barradale
Privacy Enhancing Technologies1
2014 Secure Team Composition to Thwart Insider Threats and Cyber-Espionage
abstract
We develop a formal nondeterministic game model for secure team composition to counter cyber-espionage and to protect organizational secrets against an attacker who tries to sidestep technical security mechanisms by offering a bribe to a project team member. The game captures the adversarial interaction between the attacker and the project manager who has a secret she wants to protect but must share with a team of individuals selected from within her organization. Our interdisciplinary work is important in the face of the multipronged approaches utilized by well-motivated attackers to circumvent the fortifications of otherwise well-defended targets.
Aron Laszka, Benjamin Johnson 0001, Pascal Schöttle, Jens Grossklags, Rainer Böhme
ACM Trans. Internet Techn.4
2013 An online experiment of privacy authorization dialogues for social applications
abstract
Several studies have documented the constantly evolving privacy practices of social networking sites and users' misunderstandings about them. Researchers have criticized the interfaces to "configure" privacy preferences as opaque, uninformative, and ineffective. The same problems have also plagued the constant growth of third-party applications and their troubling privacy authorization dialogues. In this paper, we report the results of an experimental study examining the limitations of current privacy authorization dialogues on Facebook as well as four new designs which we developed based on the Fair Information Practice Principles (FIPPs). Through an online experiment with 250 users, we study and document the effectiveness of installation-time configuration and awareness-enhancing interface changes.
Jens Grossklags
CSCW2
2013 Managing the Weakest Link - A Game-Theoretic Approach for the Mitigation of Insider Threats
Aron Laszka, Benjamin Johnson 0001, Pascal Schöttle, Jens Grossklags, Rainer Böhme
ESORICS4
2013 Bitspotting: Detecting Optimal Adaptive Steganography
Benjamin Johnson 0001, Pascal Schöttle, Aron Laszka, Jens Grossklags, Rainer Böhme
IWDW4
2013 Trading Agent Kills Market Information - Evidence from Online Social Lending
Rainer Böhme, Jens Grossklags
WINE2
2013 Mitigating Covert Compromises - A Game-Theoretic Model of Targeted and Non-Targeted Covert Attacks
Aron Laszka, Benjamin Johnson 0001, Jens Grossklags
WINE3
2011 The security cost of cheap user interaction
abstract
Human attention is a scarce resource, and lack thereof can cause severe security breaches. As most security techniques rely on considerate human intervention in one way or another, this resource should be consumed economically. In this context, we postulate the view that every false alarm or unnecessary user interaction imposes a negative externality on all other potential consumers of this chunk of attention. The paper identifies incentive problems that stimulate overconsumption of human attention in security applications. It further outlines a lump-of-attention model, devised against the backdrop of established theories in the behavioral sciences, and discusses incentive mechanisms to fix the misallocation problem in security notification, for instance the idea of a Pigovian tax on attention consumption.
Rainer Böhme, Jens Grossklags
NSPW2
2010 Are Security Experts Useful? Bayesian Nash Equilibria for Network Security Games with Limited Information
Benjamin Johnson 0001, Jens Grossklags, Nicolas Christin, John C.-I. Chuang
ESORICS2
2008 Security and insurance management in networks with heterogeneous agents
abstract
Computer users express a strong desire to prevent attacks and to reduce the losses from computer and information security breaches. However, security compromises are common and widespread and highly damaging. Next to attackers' increased sophistication, a root cause for the harm inflicted is that users often fail to optimally protect their resources or to recover gracefully from a security breach.
Jens Grossklags, Nicolas Christin, John C.-I. Chuang
EC1
2008 Secure or insure?: a game-theoretic analysis of information security games
abstract
Despite general awareness of the importance of keeping one's system secure, and widespread availability of consumer security technologies, actual investment in security remains highly variable across the Internet population, allowing attacks such as distributed denial-of-service (DDoS) and spam distribution to continue unabated. By modeling security investment decision-making in established (e.g., weakest-link, best-shot) and novel games (e.g., weakest-target), and allowing expenditures in self-protection versus self-insurance technologies, we can examine how incentives may shift between investment in a public good (protection) and a private good (insurance), subject to factors such as network size, type of attack, loss probability, loss magnitude, and cost of technology. We can also characterize Nash equilibria and social optima for different classes of attacks and defenses. In the weakest-target game, an interesting result is that, for almost all parameter settings, more effort is exerted at Nash equilibrium than at the social optimum. We may attribute this to the "strategic uncertainty" of players seeking to self-protect at just slightly above the lowest protection level.
Jens Grossklags, Nicolas Christin, John C.-I. Chuang
WWW1
2007 Noticing notice: a large-scale experiment on the timing of software license agreements
abstract
Spyware is an increasing problem. Interestingly, many programs carrying spyware honestly disclose the activities of the software, but users install the software anyway. We report on a study of software installation to assess the effectiveness of different notices for helping people make better decisions on which software to install. Our study of 222 users showed that providing a short summary notice, in addition to the End User License Agreement (EULA), before the installation reduced the number of software installations significantly. We also found that providing the short summary notice after installation led to a significant number of uninstalls. However, even with the short notices, many users installed the program and later expressed regret for doing so. These results, along with a detailed analysis of installation, regret, and survey data about user behaviors informs our recommendations to policymakers and designers for assessing the "adequacy" of consent in the context of software that exhibits behaviors associated with spyware.
Nathaniel Good, Jens Grossklags, Deirdre K. Mulligan, Joseph A. Konstan
CHI2
2006 Software agents and market (in) efficiency: a human trader experiment
abstract
This paper studies how software agents influence the market behavior of human traders. Software agents with a passive arbitrage-seeking strategy are introduced in a double auction market experiment with human subjects in the laboratory. As a treatment variable, the influence of information on the existence of software agents is investigated. We found that common knowledge about the presence of software agents triggers more efficient market prices when the programmed strategy was employed, whereas an effect of the information condition on behavioral variables could not be observed. When controlling for information on software agents' participation, the introduction of software agents results in lower market efficiency
Jens Grossklags
IEEE Trans. Syst. Man Cybern. Part C1
2005 Stopping spyware at the gate: a user study of privacy, notice and spyware
abstract
Spyware is a significant problem for most computer users. The term "spyware" loosely describes a new class of computer software. This type of software may track user activities online and offline, provide targeted advertising and/or engage in other types of activities that users describe as invasive or undesirable.While the magnitude of the spyware problem is well documented, recent studies have had only limited success in explaining the broad range of user behaviors that contribute to the proliferation of spyware. As opposed to viruses and other malicious code, users themselves often have a choice whether they want to install these programs.In this paper, we discuss an ecological study of users installing five real world applications. In particular, we seek to understand the influence of the form and content of notices (e.g., EULAs) on user's installation decisions.Our study indicates that while notice is important, notice alone may not be enough to affect users' decisions to install an application. We found that users have limited understanding of EULA content and little desire to read lengthy notices. Users found short, concise notices more useful, and noticed them more often, yet they did not have a significant effect on installation for our population. When users were informed of the actual contents of the EULAs to which they agreed, we found that users often regret their installation decisions.We discovered that regardless of the bundled content, users will often install an application if they believe the utility is high enough. However, we discovered that privacy and security become important factors when choosing between two applications with similar functionality. Given two similar programs (e.g. KaZaA and Edonkey), consumers will choose the one they believe to be less invasive and more stable. We also found that providing vague information in EULAs and short notices can create an unwarranted impression of increased security. In these cases, it may be helpful to have a standardized format for assessing the possible options and trade-offs between applications.
Nathaniel Good, Rachna Dhamija, Jens Grossklags, David Thaw, Steven Aronowitz, Deirdre K. Mulligan, Joseph A. Konstan
SOUPS3
2003 Resilient Data-Centric Storage in Wireless Ad-Hoc Sensor Networks
Abhishek Ghose 0002, Jens Grossklags, John C.-I. Chuang
Mobile Data Management2
2001 E-privacy in 2nd generation E-commerce: privacy preferences versus actual behavior
abstract
As electronic commerce environments become more and more interactive, privacy is a matter of increasing concern. Many surveys have investigated households' privacy attitudes and concerns, revealing a general desire among Internet users to protect their privacy. To complement these questionnaire-based studies, we conducted an experiment in which we compared self-reported privacy preferences of 171 participants with their actual disclosing behavior during an online shopping episode. Our results suggest that current approaches to protect online users' privacy, such as EU data protection regulation or P3P, may face difficulties to do so effectively. This is due to their underlying assumption that people are not only privacy conscious, but will also act accordingly. In our study, most individuals stated that privacy was important to them, with concern centering on the disclosure of different aspects of personal information. However, regardless of their specific privacy concerns, most participants did not live up to their self-reported privacy preferences. As participants were drawn into the sales dialogue with an anthropomorphic 3-D shopping bot, they answered a majority of questions, even if these were highly personal. Moreover, different privacy statements had no effect on the amount of information disclosed; in fact, the mentioning of EU regulation seemed to cause a feeling of 'false security'. The results suggest that people appreciate highly communicative EC environments and forget privacy concerns once they are 'inside the Web'.
Sarah Spiekermann, Jens Grossklags, Bettina Berendt
EC2