Taha Gharaibeh

dblp:353/3989 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0001-7407-2304ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Liar, Liar, Headset on Fire: Understanding the Effects of Deception Attacks on Decision-Making in a Mixed Reality Game
abstract
We examine the impact of deception in Mixed Reality (MR), focusing on how subversive elements affect user behavior and decision-making. In a controlled experiment with 250 participants playing a Whac-A-Mole MR game, we introduced three types of deception attacks: (1) a Physiological Spoofing Attack intended to foster false beliefs about bodily state; (2) a Gaslighting Attack that evokes false interpretations about bodily state by inducing doubt; and (3) a Disinformation Attack that presents false information by mimicking game- and system-level notifications to influence decision-making. We measured the effects on game performance, cognitive load, and behavioral responses. Results reveal that Physiological Spoofing and Gaslighting Attacks led to behavioral adjustments, though these effects diminished over time. Alternatively, false information presented in the Disinformation Attack adversely influenced decision-making. Our findings highlight the vulnerability of MR users to deception attacks and emphasize the need for adaptive security measures to mitigate these risks.
Ali Teymourian, Taha Gharaibeh, Ibrahim M. Baggili, Andrew M. Webb 0001
CHI2
2025 SoK: Come Together - Unifying Security, Information Theory, and Cognition for a Mixed Reality Deception Attack Ontology & Analysis Framework
Ali Teymourian, Andrew M. Webb 0001, Taha Gharaibeh, Arushi Ghildiyal, Ibrahim M. Baggili
USENIX Security Symposium3
2024 Give Me Steam: A Systematic Approach for Handling Stripped Symbols in Memory Forensics of the Steam Deck
abstract
The Steam Deck, developed by Valve, combines handheld gaming with desktop functionality, creating unique challenges for digital forensics due to its Linux-based SteamOS and its stripped symbol tables. This research addresses how to conduct reliable memory forensics on the Steam Deck. Employing the Linux Memory Extractor (LiME) and Volatility 3, we acquire and analyze volatile memory, a process complicated by Steam’s stripped symbol table that obscures forensic reconstruction of memory structures. Our approach reconstructs these symbols and adapts forensic tools to the Steam Deck’s architecture. Our results include the successful generation and validation of symbol tables and the patching of profiles to align with system configurations. During gameplay, we observed a significant increase in platform-related and game-related processes, highlighting the system’s dynamic operation while gaming. These findings contribute to improving forensic methodologies for similar Linux-based devices, enhancing our capability to extract valuable forensic data from modern gaming consoles.
Ruba Alsmadi, Taha Gharaibeh, Andrew M. Webb 0001, Ibrahim M. Baggili
ARES2
2024 Don't, Stop, Drop, Pause: Forensics of CONtainer CheckPOINTs (ConPoint)
abstract
In the rapidly evolving landscape of cloud computing, containerization technologies such as Docker and Kubernetes have become instrumental in deploying, scaling, and managing applications. However, these containers pose unique challenges for memory forensics due to their ephemeral nature. As memory forensics is a crucial aspect of incident response, our work combats these challenges by developing a deeper understanding of the containers, leading to the development of a novel, scalable tool for container memory forensics. Through experimental and computational analyses, our work investigates the forensic capabilities of container checkpoints, which capture a container’s state at a specific moment in time. We introduce ConPoint, a tool created for the collection of these checkpoints. We focused on three primary research questions: What is the most forensically sound approach for checkpointing a container’s memory and filesystem?, How long does the volatile memory evidence reside in memory?, and How long does the checkpoint process take on average to complete? Our approach successfully captured checkpoints and retrieved artifacts generated at runtime from container checkpoints. We found that digital evidence in a container’s volatile memory can persist during idle states, yet gradually diminishes over time and is entirely lost when the container shuts down. Our experiments determined the average time for checkpointing a container to be 0.537 seconds by acquiring a total of (n = 45) checkpoints from containers running different databases. The proposed work demonstrates the pragmatic feasibility of implementing checkpointing as an overarching strategy for container memory forensics and incident response.
Taha Gharaibeh, Steven Seiden 0002, Mohamed Abouelsaoud, Elias Bou-Harb, Ibrahim M. Baggili
ARES1
2024 Forensic Analysis of Artifacts from Microsoft's Multi-Agent LLM Platform AutoGen
abstract
Innovations in technology bring new challenges that need to be addressed, especially in the field of technical artifact discovery and analysis that enables digital forensic practitioners. Digital forensic analysis of these innovations is a constant challenge for digital investigators. In the rapidly evolving landscape of Artificial Intelligence (AI), keeping up with the digital forensic analysis of each new tool is a difficult task. New, advanced Large Language Model (LLM)s can produce human-like artifacts because of their complex textual processing capabilities. One of the newest innovations is a multi-agent Large Language Model (LLM) framework by Microsoft called AutoGen. AutoGen enables the creation of a team of specialist Large Language Model (LLM)-backed agents where the agents "chat" with each other to plan, iterate, and determine when a given task is complete. Typically one of the agents represents the human user while the other agents work autonomously after the human gives each agent a responsibility on the team. Thus, from a digital forensics perspective, it is necessary to determine which artifacts are created by the human user and which artifacts are created by the autonomous agents. Analysis in this work indicates that the current implementation of AutoGen has little in artifacts for attribution outside of particular memory artifacts, yet has strong indicators of usage in disk and network artifacts. Our research provides the initial account on the digital artifacts of the Large Language Model (LLM) technology AutoGen and first artifact examination for a Large Language Model (LLM) framework.
Clinton Walker, Taha Gharaibeh, Ruba Alsmadi, Cory Lloyd Hall, Ibrahim M. Baggili
ARES2