VLDB 2026 Research / reviewers in the wild / expert
Rishab Nithyanand
dblp:35/8412
· DBLP profile ↗
30ranked-venue papers
5as first author
14since 2021 · last 2026
0000-0002-1280-1353ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 4 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 8 · 1 first-author · 7 since 2021Databases, data management, data science and information retrieval · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Multi-Stakeholder Vulnerability Notifications in the Ad-Tech Supply ChainabstractOnline advertising relies on a complex and opaque supply chain that involves multiple stakeholders, including advertisers, publishers, and ad-networks, each with distinct and sometimes conflicting incentives. Recent research has demonstrated the existence of ad-tech supply chain vulnerabilities such as dark pooling, where low-quality publishers bundle their ad inventory with higher-quality ones to mislead advertisers. We investigate the effectiveness of vulnerability notification campaigns aimed at mitigating dark pooling. Prior research on vulnerability notifications have primarily explored single-stakeholder contexts, leaving multi-stakeholder scenarios understudied. There is limited attention to complex multi-stakeholder supply chain ecosystems such as ad-tech supply chain, where resolving vulnerabilities often requires coordinated action across entities with misaligned incentives and interdependent roles. We address this gap by implementing the first online advertising supply chain vulnerability notification pipeline to systematically evaluate the responsiveness of various stakeholders in ad-tech supply chain, including publishers, ad-networks, and advertisers to vulnerability notifications by academics and activists. Our nine-month long automated multi-stakeholder notification study shows that notifications are an effective method for reducing dark pooling vulnerabilities in the online advertising ecosystem, especially when targeted towards ad-networks. Further, the sender reputation does not impact responses to notifications from activists and academics in a statistically different way. Overall, our research fosters industry-scale solution to combat ad inventory fraud and fosters future research on feasibility of multi-stakeholder vulnerability notifications in other supply chain ecosystems. Yash Vekaria, Rishab Nithyanand, Zubair Shafiq |
EuroS&P | 2 |
| 2026 | On the Suitability of LLM-Driven Agents for Dark Pattern AuditsabstractAs LLM-driven agents begin to autonomously navigate the web, their ability to interpret and respond to manipulative interface design becomes critical. A fundamental question that emerges is: can such agents reliably recognize patterns of friction, misdirection, and coercion in interface design (i.e., dark patterns)? We study this question in a setting where the workflows are consequential: website portals associated with the submission of CCPA-related data rights requests. These portals operationalize statutory rights, but they are implemented as interactive interfaces whose design can be structured to facilitate, burden, or subtly discourage the exercise of those rights. We design and deploy an LLM-driven auditing agent capable of end-to-end traversal of rights-request workflows, structured evidence gathering, and classification of potential dark patterns. Across a set of 456 data broker websites, we evaluate: (1) the ability of the agent to consistently locate and complete request flows, (2) the reliability and reproducibility of its dark pattern classifications, and (3) the conditions under which it fails or produces poor judgments. Our findings characterize both the feasibility and the limitations of using LLM-driven agents for scalable dark pattern auditing. Yash Vekaria, Rishab Nithyanand |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | Searching for Affirmation: How Partisan Audiences on Google Search Induce an Abortion-Related Filter Bubble EffectabstractThe evolution of information-seeking processes, driven by search engines like Google, has reshaped how people access and interact with information. This paper examines how individuals' pre-existing attitudes on polarizing topics, such as the legality of abortion, influence their engagement with modern information-seeking processes. Recruiting participants from an undergraduate population of a university we use a mixed-methods study involving surveys and information-seeking tasks focused on the legality of abortion, this work offers five key insights. First, individuals with opposing abortion-related attitudes receive different search results. Second, the vocabulary used when formulated search queries differs significantly across opposing attitudes. Third, this difference in query vocabulary has a significant effect on the search results. Fourth, this effect remains consistent, though reduced, when personalization is removed from the process. Finally, Google Search returns search results that align with users' pre-existing attitudes, thereby reinforcing those attitudes. Taken together, these findings reveal a critical relationship between human biases, partisan audiences, and algorithmic processes. Specifically, our findings underscore how search platforms such as Google Search, which play a crucial role in the modern information-seeking process, contribute to information polarization. Hussam Habib, Ryan Stoldt, Andrew High, Brian Ekdale, Ashley M. Peterson, Katy Biddle, Javie Ssozi, Rishab Nithyanand |
Proc. ACM Hum. Comput. Interact. | 8 |
| 2024 | C3PA: An Open Dataset of Expert-Annotated and Regulation-Aware Privacy Policies to Enable Scalable Regulatory Compliance AuditsabstractMaaz Bin Musa, Steven M. Winston, Garrison Allen, Jacob Schiller, Kevin Moore, Sean Quick, Johnathan Melvin, Padmini Srinivasan, Mihailis E. Diamantis, Rishab Nithyanand. Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing. 2024. Maaz Bin Musa, Steven M. Winston, Garrison Allen, Jacob Schiller, Sean Quick, Johnathan Melvin, Padmini Srinivasan, Mihailis Diamantis, Rishab Nithyanand |
EMNLP | 10 |
| 2024 | How Audit Methods Impact Our Understanding of YouTube's Recommendation SystemsabstractComputational audits of social media websites have generated data that forms the basis of our understanding of the problematic behaviors of algorithmic recommendation systems. Focusing on YouTube, this paper demonstrates that conducting audits to make specific inferences about the underlying content recommendation system is more methodologically challenging than one might expect. Obtaining scientifically valid results requires considering many methodological decisions, and each of these decisions incurs costs. For example, should an auditor use logged-in YouTube accounts while gathering recommendations to ensure more accurate inferences from the collected data? We systematically explore the impact of this and many other decisions and make important discoveries about the methodological choices that impact YouTube’s recommendations. Assessed together, our research suggests auditing configurations that can be used by researchers and auditors to reduce economic and computing costs, without sacrificing inference quality and accuracy. Sarmad Chandio, Muhammad Daniyal Pirwani Dar, Rishab Nithyanand |
ICWSM | 3 |
| 2024 | The Inventory is Dark and Full of Misinformation: Understanding Ad Inventory Pooling in the Ad-Tech Supply ChainabstractAd-tech enables publishers to programmatically sell their ad inventory to millions of demand partners through a complex supply chain. The complexity and opacity of the ad-tech supply chain can be exploited by low-quality publishers (e.g., misinformation websites) to deceptively monetize their ad inventory. To combat such deception, the ad-tech industry has developed transparency standards and brand safety products. In this paper, we show that these developments still fall short of preventing deceptive monetization. Specifically, we focus on how publishers can exploit the ad-tech supply chain, subvert ad-tech transparency standards, and undermine brand safety protections by pooling their ad inventory with unrelated sites. This type of deception is referred to as "dark pooling." Our study shows that dark pooling is commonly employed by misinformation publishers on various major ad exchanges, and allows misinformation publishers to deceptively sell their ad inventory to reputable brands. Our work suggests the need for improved vetting of ad exchange supply partners, the adoption of new ad-tech transparency standards that enable end-to-end validation of the ad-tech supply chain, and the widespread deployment of independent audits like ours. Yash Vekaria, Rishab Nithyanand, Zubair Shafiq |
SP | 2 |
| 2023 | The Morbid Realities of Social Media: An Investigation into the Narratives Shared by the Deceased Victims of COVID-19abstractSocial media platforms have had considerable impact on the real world especially during the Covid-19 pandemic. Problematic narratives related to Covid-19 might have caused significant impact on the population specifically due to its association with dangerous beliefs such as anti-vaccination and Covid denial. In this work, we study a unique dataset of Facebook posts by users who shared and believed in such narratives before succumbing to Covid-19 often resulting in death. We aim to characterize the dominant themes and sources present in the victim's posts along with identifying the role of the platform in handling deadly narratives. Our analysis reveals the overwhelming politicization of Covid-19 through the prevalence of anti-government themes propagated by right-wing political and media ecosystem. Furthermore, we highlight the efforts of Facebook's implementation of soft moderation actions intended to warn users of misinformation. Results from this study bring insights into the responsibility of political elites in shaping public discourse and the platform's role in dampening the reach of harmful narratives. Hussam Habib, Rishab Nithyanand |
ICWSM | 2 |
| 2023 | Glowing in the Dark: Uncovering IPv6 Address Discovery and Scanning Strategies in the Wild
Hammas Bin Tanveer, Rachee Singh, Paul Pearce, Rishab Nithyanand |
USENIX Security Symposium | 4 |
| 2022 | When Are Cache-Oblivious Algorithms Cache Adaptive? A Case Study of Matrix Multiplication and Sorting
Arghya Bhattacharya, Abiyaz Chowdhury, Helen Xu 0001, Rathish Das, Rezaul Alam Chowdhury, Rob Johnson 0001, Rishab Nithyanand, Michael A. Bender |
ESA | 7 |
| 2022 | Are Proactive Interventions for Reddit Communities Feasible?
Hussam Habib, Maaz Bin Musa, Fareed Zaffar, Rishab Nithyanand |
ICWSM | 4 |
| 2022 | Exploring the Magnitude and Effects of Media Influence on Reddit Moderation
Hussam Habib, Rishab Nithyanand |
ICWSM | 2 |
| 2022 | Paying Attention to the Algorithm Behind the Curtain: Bringing Transparency to YouTube's Demonetization AlgorithmsabstractYouTube has long been a top-choice destination for independent video content creators to share their work. A large part of YouTube's appeal is owed to its practice of sharing advertising revenue with qualifying content creators through the YouTube Partner Program (YPP). In recent years, changes to the monetization policies and the introduction of algorithmic systems for making monetization decisions have been a source of controversy and tension between content creators and the platform. There have been numerous accusations suggesting that the underlying monetization algorithms engage in preferential treatment of larger channels and effectively censor minority voices by demonetizing their content. In this paper, we conduct a measurement of the YouTube monetization algorithms. We begin by measuring the incidence rates of different monetization decisions and the time taken to reach them. Next, we analyze the relationships between video content, channel popularity and these decisions. Finally, we explore the relationship between demonetization and a channel's view growth rate. Taken all together, our work suggests that demonetization after a video is publicly listed is not a common occurrence, the characteristics of the process are associated with channel size and (in unexplainable ways) video topic, and demonetization appears to have a harsh influence on the growth rate of smaller channels. We also highlight the challenges associated with conducting large-scale algorithm audits such as ours and make an argument for more transparency in algorithmic decision-making. Arun Dunna, Katherine A. Keith, Ethan Zuckerman, Narseo Vallina-Rodriguez, Brendan T. O'Connor 0001, Rishab Nithyanand |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2022 | Making a Radical Misogynist: How Online Social Engagement with the Manosphere Influences Traits of RadicalizationabstractThe algorithms and the interactions facilitated by online platforms have been used by radical groups to recruit vulnerable individuals to their cause. This has resulted in the sharp growth of violent events and deteriorating online discourse. The Manosphere, a collection of radical anti-feminist communities, is one such group that has attracted attention due to its rapid growth and increasingly violent real-world outbursts. In this paper, we examine the social engagements between Reddit users who have participated in feminist discourse and the Manosphere communities on Reddit to understand the process of development of traits associated with the adoption of extremist ideologies. By using existing research on the psychology of radicalization we track how specific types of social engagement with the Manosphere influence the development of traits associated with radicalization. Our findings show that: (1) participation, even by the simple act of joining the Manosphere, has a significant influence on the language and outlook traits of a user, (2) Manosphere elites are extremely effective propagators of radical traits and cause their increase even outside the Manosphere, and (3) community perception can heavily influence a user's behavior. Finally, we examine how our findings can help draft community and platform moderation policies to help mitigate the problem of online radicalization. Hussam Habib, Padmini Srinivasan, Rishab Nithyanand |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | ATOM: Ad-network TomographyabstractData sharing between online trackers and advertisers is a key component in online behavioral advertising. This sharing can be facilitated through a variety of processes, including those not observable to the user’s browser. The unobservability of these processes limits the ability of researchers and auditors seeking to verify compliance with recent regulations (e.g., CCPA and CDPA) which require complete disclosure of data sharing partners. Unfortunately, the applicability of existing techniques to make inferences about unobservable data sharing relationships is limited due to their dependence on protocol- or case-specific artifacts of the online behavioral advertising ecosystem (e.g., they work only when client-side header bidding is used for ad delivery or when advertisers perform ad retargeting). As behavioral advertising technologies continue to evolve rapidly, the availability of these artifacts and the effectiveness of transparency solutions dependent on them remain ephemeral. In this paper, we propose a generalizable technique, called ATOM, to infer data sharing relationships between online trackers and advertisers. ATOM is different from prior approaches in that it is universally applicable — i.e., independent of ad delivery protocols or availability of artifacts. ATOM leverages the insight that by the very nature of behavioral advertising, ad creatives themselves can be used to infer data sharing between trackers and advertisers — after all, the topics and brands showcased in an ad are dependent on the data available to the advertiser. Therefore, by selectively blocking trackers and monitoring changes in the characteristics of ad creatives delivered by advertisers, ATOM is able to identify data sharing relationships between trackers and advertisers. The relationships discovered by our implementation of ATOM include those not found using prior approaches and are validated by external sources. Maaz Bin Musa, Rishab Nithyanand |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | Extortion or Expansion? An Investigation into the Costs and Consequences of ICANN's gTLD Experiments
Shahrooz Pouryousef, Muhammad Daniyal Pirwani Dar, Suleman Ahmad, Phillipa Gill, Rishab Nithyanand |
PAM | 5 |
| 2020 | Apophanies or Epiphanies? How Crawlers Impact Our Understanding of the WebabstractData generated by web crawlers has formed the basis for much of our current understanding of the Internet. However, not all crawlers are created equal and crawlers generally find themselves trading off between computational overhead, developer effort, data accuracy, and completeness. Therefore, the choice of crawler has a critical impact on the data generated and knowledge inferred from it. In this paper, we conduct a systematic study of the trade-offs presented by different crawlers and the impact that these can have on various types of measurement studies. We make the following contributions: First, we conduct a survey of all research published since 2015 in the premier security and Internet measurement venues to identify and verify the repeatability of crawling methodologies deployed for different problem domains and publication venues. Next, we conduct a qualitative evaluation of a subset of all crawling tools identified in our survey. This evaluation allows us to draw conclusions about the suitability of each tool for specific types of data gathering. Finally, we present a methodology and a measurement framework to empirically highlight the differences between crawlers and how the choice of crawler can impact our understanding of the web. Suleman Ahmad, Muhammad Daniyal Pirwani Dar, Fareed Zaffar, Narseo Vallina-Rodriguez, Rishab Nithyanand |
WWW | 5 |
| 2020 | Inferring Tracker-Advertiser Relationships in the Online Advertising Ecosystem using Header BiddingabstractAbstract Online advertising relies on trackers and data brokers to show targeted ads to users. To improve targeting, different entities in the intricately interwoven online advertising and tracking ecosystems are incentivized to share information with each other through client-side or server-side mechanisms. Inferring data sharing between entities, especially when it happens at the server-side, is an important and challenging research problem. In this paper, we introduce Kashf: a novel method to infer data sharing relationships between advertisers and trackers by studying how an advertiser’s bidding behavior changes as we manipulate the presence of trackers. We operationalize this insight by training an interpretable machine learning model that uses the presence of trackers as features to predict the bidding behavior of an advertiser. By analyzing the machine learning model, we can infer relationships between advertisers and trackers irrespective of whether data sharing occurs at the client-side or the server-side. We are able to identify several server-side data sharing relationships that are validated externally but are not detected by client-side cookie syncing. John Cook, Rishab Nithyanand, Zubair Shafiq |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Apps, Trackers, Privacy, and Regulators: A Global Study of the Mobile Tracking Ecosystem
Abbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Mark Allman, Christian Kreibich, Phillipa Gill |
NDSS | 2 |
| 2017 | A Churn for the Better: Localizing Censorship using Network-level Path Churn and Network TomographyabstractRecent years have seen the Internet become a key vehicle for citizens around the globe to express political opinions and organize protests. This fact has not gone unnoticed, with countries around the world repurposing network management tools (e.g., URL filtering products) and protocols (e.g., BGP, DNS) for censorship. Previous work has focused on identifying how censorship is performed. However, there is no major studies to identify, at a global scale, the networks responsible for performing censorship. Also, repurposing network products for censorship can have unintended international impact, which we refer to as "censorship leakage". While there have been anecdotal reports of censorship leakage, there has yet to be a systematic study of censorship leakage at a global scale. Shinyoung Cho, Rishab Nithyanand, Abbas Razaghpanah, Phillipa Gill |
CoNEXT | 2 |
| 2017 | Characterizing the Nature and Dynamics of Tor Exit Blocking
Rachee Singh, Rishab Nithyanand, Sadia Afroz 0001, Paul Pearce, Michael Carl Tschantz, Phillipa Gill, Vern Paxson |
USENIX Security Symposium | 2 |
| 2016 | Games without Frontiers: Investigating Video Games as a Covert ChannelabstractThe Internet has become a critical communication infrastructure for citizens to organize protests and express dissatisfaction with their governments. This fact has not gone unnoticed, with governments clamping down on this medium via censorship, and circumvention researchers working to stay one step ahead. In this paper, we explore video games as a new avenue for covert channels. Two features make video games attractive for use as a cover protocol in censorship circumvention tools: First, games within a genre share many common features. Second, there are many different games, each with their own protocols and server infrastructures. These features allow circumvention tool developers to build a single framework that can be adapted to work with many different games within a genre; therefore allowing quick response to censor created blockades. In addition, censored users can diversify their covert communications across many different games, making it difficult for a censor to respond by simply blocking a single covert channel. We demonstrate the feasibility of this approach by implementing our circumvention scheme over three real-time strategy games (including two best-selling closed-source games). We evaluate the security of our system prototype, Castle, by quantifying its resilience to a censor-adversary, similarity to real game traffic, and ability to avoid common pitfalls in covert channel design. We use our prototype to demonstrate that our approach can provide the throughput necessary for bootstrapping higher bandwidth channels and also the transfer of textual data, such as web articles, e-mail, SMS messages, and tweets, which are commonly used to organize political actions. Bridger Hahn, Rishab Nithyanand, Phillipa Gill, Rob Johnson 0001 |
EuroS&P | 2 |
| 2016 | Measuring and Mitigating AS-level Adversaries Against Tor
Rishab Nithyanand, Oleksii Starov, Phillipa Gill, Adva Zair, Michael Schapira |
NDSS | 1 |
| 2014 | A Systematic Approach to Developing and Evaluating Website Fingerprinting DefensesabstractFingerprinting attacks have emerged as a serious threat against privacy mechanisms, such as SSL, Tor, and encrypting tunnels. Researchers have proposed numerous attacks and defenses, and the Tor project now includes both network- and browser-level defenses against these attacks, but published defenses have high overhead, poor security, or both. Xiang Cai, Rishab Nithyanand, Tao Wang 0012, Rob Johnson 0001, Ian Goldberg 0001 |
CCS | 2 |
| 2014 | Effective Attacks and Provable Defenses for Website Fingerprinting
Tao Wang 0012, Xiang Cai, Rishab Nithyanand, Rob Johnson 0001, Ian Goldberg 0001 |
USENIX Security Symposium | 3 |
| 2013 | Can Jannie verify? Usability of display-equipped RFID tags for security purposesabstractThe recent emergence of RFID tags capable of performing public key operations enables a number of new applications in commerce (e.g., RFID-enabled credit cards) and security (e.g., ePassports and access-control badges). While the use of public key cryptography in RFID tags mitigates many difficult security issues, certain important usability-related issues remain, particularly when RFID tags are used for financial transactions or bearer identification. In this paper, we focus exclusively on techniques with user involvement for secure user-to-tag authentication, transaction verification, reader expiration and revocation checking, as well as pairing of RFID tags with other personal devices. Our approach is based on two factors: (1) recent advances in hardware and manufacturing have made it possible to mass-produce inexpensive passive display-equipped RFID tags, and (2) high-end RFID tags used in financial transactions or identification are attended by a human user (typically, their owner). Our techniques rely on user involvement coupled with on-tag displays to achieve better security and privacy. Since user acceptance is a crucial factor in this context, we conducted comprehensive user studies to assess usability of all considered methods. This paper reports on our findings. Alfred Kobsa, Rishab Nithyanand, Gene Tsudik, Ersin Uzun |
J. Comput. Secur. | 2 |
| 2011 | Poster: making the case for intrinsic personal physical unclonable functions (IP-PUFs)
Rishab Nithyanand, Radu Sion, John Solis |
CCS | 1 |
| 2011 | Usability of Display-Equipped RFID Tags for Security Purposes
Alfred Kobsa, Rishab Nithyanand, Gene Tsudik, Ersin Uzun |
ESORICS | 2 |
| 2011 | User-aided reader revocation in PKI-based RFID systemsabstractRecent emergence of RFID tags capable of performing public key operations motivates new RFID applications, including electronic travel documents, identification cards and payment instruments. In this context, public key certificates form the cornerstone of the overall system security. In this paper , we argue that one of the prominent challenges is how to handle revocation and expiration checking of RFID reader certificates. This is an important issue considering that these high-end RFID tags are geared for applications such as e-documents and contactless payment instruments. Furthermore, the problem is unique to public key-based RFID systems, since a passive RFID tag has no clock and thus cannot use (time-based) off-line methods. In this paper, we address the problem of reader certificate expiration and revocation in PKI-based RFID systems. We begin by observing an important distinguishing feature of personal RFID tags used in authentication, access control or payment applications – the involvement of a human user. We take advantage of the user's awareness and presence to construct a simple, efficient, secure and (most importantly) feasible solution. We evaluate the usability and practical security of our solution via user studies and discuss its feasibility. Rishab Nithyanand, Gene Tsudik, Ersin Uzun |
J. Comput. Secur. | 1 |
| 2010 | Readers Behaving Badly - Reader Revocation in PKI-Based RFID Systems
Rishab Nithyanand, Gene Tsudik, Ersin Uzun |
ESORICS | 1 |
| 2010 | Groupthink: usability of secure group association for wireless devicesabstractA fairly common modern setting entails users, each in possession of a personal wireless device, wanting to communicate securely, via their devices. If these users (and their devices) have no prior association, a new security context must be established. In order to prevent potential attacks, the initial context (association) establishment process must involve only the intended devices and their users. Rishab Nithyanand, Nitesh Saxena, Gene Tsudik, Ersin Uzun |
UbiComp | 1 |