VLDB 2026 Research / reviewers in the wild / expert
Pithayuth Charnsethikul
dblp:285/1872
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Navigating Social Media Privacy: Awareness, Preferences, and DiscoverabilityabstractSocial media platforms provide various privacy settings, which users can adjust to fit their privacy needs. Platforms claim that this is sufficient – users have power to accept the default settings they like, and change those they do not like. In this paper, we seek to quantify user awareness of, preferences around and ability to adjust social media privacy settings. We conduct an online survey of 541 participants across six different social media platforms: Facebook, Instagram, X, LinkedIn, TikTok, and Snapchat. We focus on nine privacy settings that are commonly available across these platforms, and evaluate participants’ preferences for privacy, awareness of the privacy settings and ability to locate them. We find that default settings are ill-aligned with user preferences – 92% of participants prefer at least one of the privacy options to be more private than the default. We further find that users are generally not aware of privacy settings, and struggle to find them. 80% of participants have never seen at least one privacy setting, and 79% of participants rated at least one setting as hard to find. We also find that the fewer privacy settings a user has seen, the harder for them to locate those settings, and the higher the level of privacy they desire. Additionally, we find that there are significant differences in privacy setting preferences and usability across different user age groups and across platforms. Older users are more conservative about their privacy, they have seen significantly fewer privacy settings, and they spend significantly more time locating them than younger users. On some platforms, like LinkedIn, users opt for higher visibility, while on others they prefer more privacy. Some platforms, like TikTok, make it significantly easier for users to locate privacy settings. Based on our findings, we provide recommendations on default values and how to improve usability of privacy settings on social media. Pithayuth Charnsethikul, Almajd Zunquti, Gale M. Lucas, Jelena Mirkovic |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | AMON-SENSS: Scalable and Accurate Detection of Volumetric DDoS Attacks at ISPsabstractDistributed Denial of Service (DDoS) attacks continue to be a severe threat to the Internet, and have been evolving both in traffic volume and in sophistication. While many attack detection approaches exist, few of them provide easily interpretable and actionable network-level signatures. Further, most tools are either not scalable or are prohibitively expensive, and thus are not broadly available to network operators. We bridge this gap by proposing AMON-SENSS, an open-source system for scalable, accurate DDoS detection and signature generation in large networks. AMON-SENSS employs hash-based binning with multiple bin layers for scalability, observes traffic at multiple granularities, and deploys traffic volume and traffic asymmetry change-point detection techniques to identify attacks. It proactively devises network-level attack signatures, which can be used to filter attack traffic. We evaluate AMON-SENSS against two commercial defense systems, using 37 days of real traffic from a mid-size Internet Service Provider (ISP). We find that our proposed approach exhibits superior performance in terms of accuracy, detection time and network signature quality over commercial alternatives. AMON-SENSS is deployable today, it is free, and requires no hardware or routing changes. Rajat Tandon, Pithayuth Charnsethikul, Michael G. Kallitsis, Jelena Mirkovic |
GLOBECOM | 2 |
| 2022 | Old but Gold: Prospecting TCP to Engineer and Live Monitor DNS Anycast
Giovane Cesar Moreira Moura, John S. Heidemann, Wes Hardaker, Pithayuth Charnsethikul, Jeroen Bulten, João M. Ceron, Cristian Hesselman |
PAM | 4 |
| 2022 | I know what you did on Venmo: Discovering privacy leaks in mobile social paymentsabstractVenmo is a US-based mobile social payments platform. Each Venmo transaction requires a “payment note”, a brief memo. By default, these memos are visible to all other Venmo users. Using three data sets of Venmo transactions, which span 8 years and a total of 389 M transactions with over 22.5 M unique users, we quantify the extent of private data leaks from public transaction notes. To quantify the leaks, we develop a classification framework SENMO, that uses BERT and regular expressions to classify public transaction notes as sensitive or non-sensitive. We find that 41 M notes (10.5%) leak some sensitive information such as health condition, political orientation and drug/alcohol consumption involving 8.5 M (37.8%) users. We further find that users seek privacy by making their notes private, inconspicuous or cryptic. However, the large increase in Venmo’s user base means that the number of users whose privacy is publicly exposed has grown substantially. Finally, the privacy of a user who transacts with a group on Venmo can be reduced or eliminated through the actions of other users. We find that this happens to around half of Alcoholics Anonymous, gambling and biker gang group members. Our findings strongly suggest that public-by-default payment information puts many users at risk of unintended privacy leaks. Rajat Tandon, Pithayuth Charnsethikul, Ishank Arora, Dhiraj Murthy, Jelena Mirkovic |
Proc. Priv. Enhancing Technol. | 2 |