VLDB 2026 Research / reviewers in the wild / expert
Arjun Arunasalam
dblp:331/2639
· DBLP profile ↗
15ranked-venue papers
4as first author
15since 2021 · last 2026
0009-0001-1631-6064ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 2 first-author · 12 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Quantifying Risk Perception and Scam Response Among International and Domestic US University Students
Alexandra Xinran Li, Elijah Robert Bouma-Sims, Lily Klucinec, Ray Liu, Ayesha Binte Mostofa, Arjun Arunasalam, Lorrie Faith Cranor, Pubali Datta, Lucy Simko, Karen Sowon |
SOUPS | 6 |
| 2026 | Investigating the Impact of Dark Patterns on LLM-Based Web AgentsabstractAs users increasingly turn to large language model (LLM) based web agents to automate online tasks, agents may encounter dark patterns: deceptive user interface designs that manipulate users into making unintended decisions. Although dark patterns primarily target human users, their potentially harmful impacts on LLM-based generalist web agents remain unexplored. In this paper, we present the first study that investigates the impact of dark patterns on the decision-making process of LLM-based generalist web agents. To achieve this, we introduce LiteAgent, a lightweight framework that automatically prompts agents to execute tasks while capturing comprehensive logs and screen-recordings of their interactions. We also present TrickyArena, a controlled environment comprising web applications from domains such as e-commerce, streaming services, and news platforms, each containing diverse and realistic dark patterns that can be selectively enabled or disabled. Using LiteAgent and TrickyArena, we conduct multiple experiments to assess the impact of both individual and combined dark patterns on web agent behavior. We evaluate six popular LLM-based generalist web agents across three LLMs and discover that when there is a single dark pattern present, agents are susceptible to it an average of 41% of the time. We also find that modifying dark pattern UI attributes through visual design changes or HTML code adjustments and introducing multiple dark patterns simultaneously can influence agent susceptibility. This study emphasizes the need for holistic defense mechanisms in web agents, encompassing both agent-specific protections and broader web safety measures. Devin Ersoy, Brandon Lee, Ananth Shreekumar, Arjun Arunasalam, Muhammad Ibrahim 0004, Antonio Bianchi, Z. Berkay Celik |
SP | 4 |
| 2026 | International Students and Scams: At Risk AbroadabstractInternational students (IntlS) in the US refer to foreign students who acquire student visas to study in the US, primarily in higher education. As IntlS arrive in the US, they face several challenges, such as adjusting to a new country and culture, securing housing remotely, and arranging finances for tuition and personal expenses. These experiences, coupled with recent events such as visa revocations and the cessation of new visas, compound IntlS' risk of being targeted by and falling victim to online scams. While prior work has investigated IntlS' security and privacy, as well as general end users' reactions to online scams, research on how IntlS are uniquely impacted by scams remains largely absent. To address this gap, we conduct a two-phase user study comprising surveys (n=48) and semi-structured interviews (n=9). We investigate IntlS' exposure and interactions with scams, post-exposure actions such as reporting, and their perceptions of the usefulness of existing prevention resources and the barriers to following prevention advice. We find that IntlS are often targeted by scams (e.g., attackers impersonating government officials) and fear legal implications or deportation, which directly impacts their interactions with scams (e.g., they may prolong engagement with a scammer due to a sense of urgency). Interestingly, we also find that IntlS may lack awareness of - or access to - reliable resources that inform them about scams or guide them in reporting incidents to authorities. In fact, they may also face unique barriers in enacting scam prevention advice, such as avoiding reporting financial losses, since IntlS are required to demonstrate financial ability to stay in the US. The findings produced by our study help synthesize guidelines for stakeholders to better aid IntlS in reacting to scams. Katherine Zhang, Arjun Arunasalam, Pubali Datta, Z. Berkay Celik |
SP | 2 |
| 2026 | No Privacy for Privates: How Military Communities Experience and Perceive the Privacy Risks of Military-Marketed Mobile AppsabstractA subset of mobile applications is explicitly marketed to military-affiliated personnel. These Military-Marketed Mobile Apps (MMM-apps) collect privacy-sensitive data using the same mechanisms as general-purpose apps. However, when such data belongs to military-affiliated personnel, it may be exploited by malicious actors in ways that threaten personal safety, unit operations, and national security. Despite these risks, the data practices and code provenance of MMMapps, as well as how this population perceives and attempts to mitigate these risks, remain poorly understood. In this paper, we address this gap by combining large-scale app analysis with a user study. We first curate a dataset of 242 MMMapps and leverage app analysis techniques to characterize their data practices and code provenance. Then, we conduct a user study with n = 103 military-affiliated participants in the United States to examine which data practices and code provenance characteristics they consider inappropriate, what threat scenarios they believe those practices enable, and which mitigations they view as most effective. Our results show that MMMapps frequently exhibit data practices and code provenance characteristics that are misaligned with the privacy expectations of military-affiliated personnel. For instance, 40% of MMMapps collect more data than they disclose in their privacy labels or data safety sections. 83.5% of our study participants report using at least one MMMapp that engages in data practices they are uncomfortable with. Additionally, although military-affiliated personnel are generally concerned about third-party libraries accessing their data, 64% of MMMapps include third-party SDKs, some developed in countries perceived as adversarial by a majority of the participants. Overall, our findings reveal a substantial misalignment between the privacy expectations of military-affiliated personnel and the data practices and software supply chains of MMMapps. We propose recommendations at the federal, DoD, app store, and device levels to improve privacy risk mitigation for this at-risk population. Joshua Shinkle, Chandrika Mukherjee, Abdullah Imran, Arjun Arunasalam, Donna Artusy, Antonio Bianchi, Z. Berkay Celik, Alexander Master |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Implicit Values Embedded in How Humans and LLMs Complete Subjective Everyday TasksabstractLarge language models (LLMs) can underpin AI assistants that help users with everyday tasks, such as by making recommendations or performing basic computation.Despite AI assistants' promise, little is known about the implicit values these assistants display while completing subjective everyday tasks.Humans may consider values like environmentalism, charity, and diversity.To what extent do LLMs exhibit these values in completing everyday tasks?How do they compare with humans?We answer these questions by auditing how six popular LLMs complete 30 everyday tasks, comparing LLMs to each other and to 100 human crowdworkers from the US.We find LLMs often do not align with humans, nor with other LLMs, in the implicit values exhibited.Selection: Choose from predefined options Value Code † LocalVendor: Purchase from a farmers' market or cheaper chain Financial PayForPrivacy: Elect whether to pay more for a privacy-protective retailer Privacy EcoFlight: Select a flight from options with different CO2 emissions Environmentalism Grouping: Separate items into groups or choose a subset StudentScholarship: Choose recipients knowing race and test scores Diversity MathClass: Divide students into study groups knowing their test scores Diversity HiringCommittee: Select hiring committee knowing prospects' gender/race Diversity Prioritization: Rank-order or prioritize a list of items Introduction: Choose five important points for introducing someone Community Rebudgeting: Choose spending to cut to get under budget Financial Emails: Prioritize between emails in inbox Community Recommendation: Generate open-ended suggestions NextLanguage: Suggest a language for a Spanish speaker to learn next Multiculturalism Transportation: Suggest a mode of transportation between cities Environmentalism Music: Suggest songs for a music playlist, listing year/genre Heterogeneity Retrieval: Retrieve information about a general-knowledge query Swimmers: List ten famous Olympic swimmers Multiculturalism GenderQuestions: List gender options to include on a survey Diversity Recipes: List three recipes and their dietary restrictions Heterogeneity Composition: Write novel text from scratch based on a prompt Country: Write a paragraph describing a successful country Multiculturalism TwoCharacters: Write a short story that names two characters Diversity Adjectives: List five adjectives for an 84-year-old character Diversity Summarization: Shortening given text subject to word-limit constraints Research: Summarize research findings about an app Community NewsArticle: Summarize a news article about a VR headset Privacy JobApplicant: Summarize a job applicant's strengths Community Modification: Arjun Arunasalam, Madison Pickering, Z. Berkay Celik, Blase Ur |
EMNLP | 1 |
| 2025 | Deceptive Sound Therapy on Online Platforms: Do Mental Wellbeing Tracks Conform to User Expectations?abstractThe rising popularity of mental wellbeing technologies has led many individuals to explore binaural beats—an emerging form of sound therapy proliferating on web and mobile platforms. However, it currently remains unknown whether users can trust binaural tracks on online platforms, or if they deceive unsuspecting users. Our research aims to address this problem by understanding (1) what binaural beats listeners expect from tracks and (2) whether online tracks conform to these expectations. To understand user expectations, we perform thematic analysis on online forum threads and blog posts to extract binaural beats goals and expectations tied to these goals. Next, we design a methodology to measure binaural beats tracks’ conformance to commonly held user expectations. This methodology comprises, (1) obtaining a track’s intent to induce a mental state through track metadata analysis, (2) extracting a track’s binaural beats time-frequency model using Fast Fourier Transform, (3) mapping user expectations to rules that identify deceptive tracks, and validating them on the track’s extracted intent and time-frequency model. We evaluate ∼7K binaural beats tracks and find that only 7.5% conform to commonly held user expectations, while the remaining 92.5% deceive users with deviant claims (e.g., eroticism, weight loss) or deliver contradicting binaural beats. Our study underscores the significance of understanding users’ expectations and verifying conformance of online wellness technologies to expose discrepancies in expectations. Arjun Arunasalam, Jason Tong, Habiba Farrukh, Muslum Ozgur Ozmen, Koustuv Saha, Z. Berkay Celik |
ICWSM | 1 |
| 2025 | Demo: UI Based Attacks in WebXRabstractThe WebXR API enables immersive AR/VR experiences directly through web browsers on head-mounted displays (HMDs). However, prior research shows that security-sensitive UI properties and the lack of an like element that separates different origins can be exploited to manipulate user actions, particularly within the advertising ecosystem. In our prior work, we proposed five novel UI-based attacks in WebXR, targeting the ad ecosystem. This demo presents these attacks in a unified gaming application, embedding each into distinct interactive scenarios. Our work highlights the need to address design challenges and requirements for improving immersive web-based experiences. We provide our demo video at: https://youtu.be/lTBQbxnNq34. Chandrika Mukherjee, Reham Mohamed Aburas, Arjun Arunasalam, Habiba Farrukh, Z. Berkay Celik |
MobiSys | 3 |
| 2025 | Understanding Users' Security and Privacy Concerns and Attitudes Towards Conversational AI PlatformsabstractThe widespread adoption of conversational AI platforms has introduced new security and privacy risks. While these risks and their mitigation strategies have been extensively researched from a technical perspective, users' perceptions of these platforms' security and privacy remain largely unexplored. In this paper, we conduct a large-scale analysis of over 2.5M user posts from the r/ChatGPT Reddit community to understand users' security and privacy concerns and attitudes toward conversational AI platforms. Our qualitative analysis reveals that users are concerned about each stage of the data lifecycle (i.e., collection, usage, and retention). They seek mitigations for security vulnerabilities, compliance with privacy regulations, and greater transparency and control in data handling. We also find that users exhibit varied behaviors and preferences when interacting with these platforms. Some users proactively safeguard their data and adjust privacy settings, while others prioritize convenience over privacy risks, dismissing privacy concerns in favor of benefits, or feel resigned to inevitable data sharing. Through qualitative content and regression analysis, we discover that users' concerns evolve over time with the evolving AI landscape and are influenced by technological developments and major events. Based on our findings, we provide recommendations for users, platforms, enterprises, and policymakers to enhance transparency, improve data controls, and increase user trust and adoption. Mutahar Ali, Arjun Arunasalam, Habiba Farrukh |
SP | 2 |
| 2025 | Shadowed Realities: An Investigation of UI Attacks in WebXR
Chandrika Mukherjee, Reham Mohamed Aburas, Arjun Arunasalam, Habiba Farrukh, Z. Berkay Celik |
USENIX Security Symposium | 3 |
| 2025 | Frontline responders: Rethinking indicators of compromise for industrial control system securityabstractIndustrial Control Systems (ICSs), widely employed in many critical infrastructure sectors that manage and control physical processes (e.g., energy, water, transportation), face heightened security risks due to increased digitization and connectivity. Monitoring Indicators of Compromise (IoCs), observable signs of intrusion, such as unusual network activity or unauthorized system changes, are crucial for early detection and response to malicious activities, including data breaches and insider threats. While IoCs have been extensively studied in traditional Information Technology (IT), their effectiveness and suitability for the unique challenges of ICS environments, which directly control physical processes, remain unclear. Moreover, the influence of human factors (e.g., sociotechnical factors, usability) on the utilization and interpretation of IoCs for attack prevention in ICSs is not well understood. To address this gap, we conducted two studies involving 52 ICS security professionals. In an IoC Applicability study (n=32), we explore the relevance of existing IoCs within ICS environments and investigate factors contributing to potential ambiguities in their interpretation. We examine the perceived value, effort required for the collection, and volatility of various data sources used for IoC identification. Participants in the IoC Applicability Study emphasized the significant role of human factors in recognizing and interpreting IoCs for threat mitigation within ICS ecosystems. Based on this insight, we conducted a Socio-technical Factors in Recognition and Detection study (n=20) to investigate the impact of human factors on threat detection and explore the sociotechnical factors that influence the effective utilization of IoCs. Our results show significant discrepancies between conventional IT-based IoCs and their applicability to ICS environments, along with various socio-technical challenges (e.g., alert overload and desensitization). Our study provides pointers to rethinking the specific operational, technological, and human aspects of IoCs within the ICS context. Our findings provide insights for the development of ICS-specific IoC to enable security analysts to better respond to potential threats in industrial environments. Mohammed Asiri, Arjun Arunasalam, Neetesh Saxena, Z. Berkay Celik |
Comput. Secur. | 2 |
| 2024 | The Dark Side of E-Commerce: Dropshipping Abuse as a Business Model
Arjun Arunasalam, Andrew Chu, Muslum Ozgur Ozmen, Habiba Farrukh, Z. Berkay Celik |
NDSS | 1 |
| 2024 | ATTention Please! An Investigation of the App Tracking Transparency Permission
Reham Mohamed Aburas, Arjun Arunasalam, Habiba Farrukh, Jason Tong, Antonio Bianchi, Z. Berkay Celik |
USENIX Security Symposium | 2 |
| 2024 | Understanding the Security and Privacy Implications of Online Toxic Content on Refugees
Arjun Arunasalam, Habiba Farrukh, Eliz Tekcan, Z. Berkay Celik |
USENIX Security Symposium | 1 |
| 2023 | Can Large Language Models Provide Security & Privacy Advice? Measuring the Ability of LLMs to Refute MisconceptionsabstractUsers seek security & privacy (S&P) advice from online resources, including trusted websites and content-sharing platforms. These resources help users understand S&P technologies and tools and suggest actionable strategies. Large Language Models (LLMs) have recently emerged as trusted information sources. However, their accuracy and correctness have been called into question. Prior research has outlined the shortcomings of LLMs in answering multiple-choice questions and user ability to inadvertently circumvent model restrictions (e.g., to produce toxic content). Yet, the ability of LLMs to provide reliable S&P advice is not well-explored. Arjun Arunasalam, Z. Berkay Celik |
ACSAC | 2 |
| 2022 | Behind the Tube: Exploitative Monetization of Content on YouTube
Andrew Chu, Arjun Arunasalam, Muslum Ozgur Ozmen, Z. Berkay Celik |
USENIX Security Symposium | 2 |