VLDB 2026 Research / reviewers in the wild / expert
Saiid El Hajj Chehade
dblp:377/8780
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2025
0009-0008-1409-2379ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | 403 Forbidden? Ethically Evaluating Broken Access Control in the WildabstractIn the context of web applications, the most prevalent vulnerability, according to the OWASP Top Ten, is broken access control. As access control (AC) is implemented on the server side, not having access to the code in live systems limits the ability of researchers to study improper AC issues in the wild. While several works have identified vulnerabilities in open-source applications deployed in researcher-controlled environments, the problem has not been studied in the wild because of ethical and legal considerations to not leak unknowing users' data. We address this gap in research and present the Variable Swapping Framework (VSF), the first ethically sound and scalable black-box framework to test for improper AC patterns in the wild. VSF's design is the result of our indepth ethical stakeholder analysis and risk minimization while maximizing benefits in vulnerability detection. At its core, it relies on two accounts per site and swaps identifiers between them to access one account's resources with the other. On 100 web apps successfully tested, we find a total of 584 potential AC-sensitive HTTP endpoints, out of which 19 (across 7 sites) are exploitable flaws, which we disclosed responsibly. Saiid El Hajj Chehade, Florian Hantke, Ben Stock |
SP | 1 |
| 2025 | Double-Edged Shield: On the Fingerprintability of Customized Ad Blockers
Saiid El Hajj Chehade, Ben Stock, Carmela Troncoso |
USENIX Security Symposium | 1 |
| 2024 | SINBAD: Saliency-informed detection of breakage caused by ad blockingabstractPrivacy-enhancing blocking tools based on filter-list rules tend to break legitimate functionality. Filter-list maintainers could benefit from automated breakage detection tools that allow them to proactively fix problematic rules before deploying them to millions of users. We introduce SINBAD, an automated breakage detector that improves the accuracy over the state of the art by 20%, and is the first to detect dynamic breakage and breakage caused by style-oriented filter rules. The success of SINBAD is rooted in three innovations: (1) the use of user-reported breakage issues in forums that enable the creation of a high-quality dataset for training in which only breakage that users perceive as an issue is included; (2) the use of ‘web saliency’ to automatically identify user-relevant regions of a website on which to prioritize automated interactions aimed at triggering breakage; and (3) the analysis of webpages via subtrees which enables fine-grained identification of problematic filter rules. Saiid El Hajj Chehade, Sandra Deepthy Siby, Carmela Troncoso |
SP | 1 |