VLDB 2026 Research / reviewers in the wild / expert
Vincent Naessens
dblp:51/866
· DBLP profile ↗
27ranked-venue papers
2as first author
11since 2021 · last 2025
0000-0002-9255-4902ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 2 first-author · 9 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Big Broker is Tracking You! A Privacy Assessment of Large-Scale Location Trace DatasetsabstractLarge-scale location trace datasets are being col-lected by data brokers and sold for significant financial gains. These datasets are collected continuously through background services in smartphone applications, typically without users' in-formed consent. While businesses leverage these data to derive valuable crowd insights, it raises profound privacy concerns for individuals. When such datasets fall into the hands of malicious actors, large-scale blackmail, coercion, and extortion schemes can be set up. This paper demonstrates the risks posed by large-scale location trace datasets, demonstrating how adversaries can exploit them to: (i) infer sensitive personal locations, such as home and workplace addresses, (ii) reveal the identity behind the traces, and (iii) construct social graphs by linking the location traces of multiple individuals. Our research is unique compared to related work in the sense that it is the first in-depth privacy assessment of five large-scale datasets purchased from two different data brokers that collect accurate location traces without informed consent on a continuous basis. Multiple experiments demonstrate the feasibility, magnitude and practical impact of diverse privacy attacks. Finally, we highlight realistic abuse scenarios, and propose solutions to mitigate these privacy concerns. Kevin De Boeck, Jenno Verdonck, Michiel Willocx, Vincent Naessens |
ACSAC | 4 |
| 2025 | Advanced Strategies for Privacy Preserving Data Publishing to Improve Multi-class Classification
Tibo Laperre, Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Vincent Naessens |
SEC (1) | 5 |
| 2024 | Compromising anonymity in identity-reserved k-anonymous datasets through aggregate knowledgeabstractData processors increasingly rely on external data sources to improve strategic or operational decision taking. Data owners can facilitate this by releasing datasets directly to data processors or doing so indirectly via data spaces. As data processors often have different needs and due to the sensitivity of the data, multiple anonymized versions of an original dataset are often released. However, doing so can introduce severe privacy risks. Kevin De Boeck, Jenno Verdonck, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 5 |
| 2024 | Advanced methods for generalizing time and duration during dataset anonymizationabstractTime is an often recurring quasi-identifying attribute in many datasets. Anonymizing such datasets requires generalizing the time attribute(s) in the dataset. Examples are start dates and durations, which are traditionally generalized leading to intervals that do not embrace the relation between time attributes. This paper presents advanced methods for creating generalization hierarchies for time data. We propose clustering-based and Mondrian-based techniques to construct generalization hierarchies. These approaches take into account the relation between different time attributes and are designed to improve the utility of the anonymized data. We implemented these methods and conducted a set of experiments comparing them to traditional generalization strategies. The results show that our proposed methods improve the utility of the data for both statistical analysis and machine learning applications. Our approach demonstrates a significant increase in hierarchy quality and configuration flexibility, demonstrating the potential of our advanced techniques over existing methods. Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Vincent Naessens |
ARES | 4 |
| 2024 | Value for Money: An Experimental Comparison of Cloud Pricing and PerformanceabstractOrganizations increasingly rely on cloud providers for computation intensive tasks. This study executes computation expensive experiments in five cloud environments with a substantial market share. More specifically, we selected the big three and two representative European counterparts. By means of the experiments, we aim at comparing and assessing their value for money with respect to computational intensive tasks. The paper focuses on three aspects with high interest of industrial stakeholders, namely (a) the impact of server location and time of day on performance, (b) the computational efficiency in relation to costs, and (c) a comparison between European service providers and the big three in the cloud space. Michiel Willocx, Ilse Bohé, Vincent Naessens |
CLOSER | 3 |
| 2024 | Demo: Backdoor Through the Front Door: Demonstrating Security Flaws in the Eufy EcosystemabstractAs Internet of Things (IoT) devices become increasingly integrated into modern homes, ensuring their security is critical to safeguarding personal privacy and home networks. This demonstration reveals significant security vulnerabilities within Eufy's smart home ecosystem, including weak key derivation mechanisms and inadequate network isolation. These weaknesses allow an attacker to compromise not only the Eufy devices but also the entire home network, posing a broader risk to connected systems and sensitive data. Our demo underscores the urgent need for stronger security measures in IoT ecosystems, illustrating how flaws in edge devices can jeopardize the safety of modern smart homes and their broader infrastructures. Victor Goeman, Tom Cordemans, Dairo de Ruck, Jorn Lapon, Vincent Naessens |
SEC | 5 |
| 2023 | IoT Security Seminar: Raising Awareness and Sharing Critical KnowledgeabstractThe security of the Internet of Things (IoT) devices has become a major concern as the number of connected devices continues to increase. Despite this concern, there is a lack of training opportunities to educate IoT developers on security measures. While there are ample ICT and Network Management courses for developers, there is a lack of security courses scoped for this audience. One of the reasons is that raising cybersecurity awareness and increasing the security expertise of developers presents a significant challenge due to the complexity of IoT security. Victor Goeman, Dairo de Ruck, Ilse Bohé, Jorn Lapon, Vincent Naessens |
ARES | 5 |
| 2023 | Linux-based IoT Benchmark Generator For Firmware Security Analysis ToolsabstractThere is a growing interest of IoT manufacturers to incorporate firmware analysis tools in their development pipeline to evaluate the security of new embedded devices. This has the advantage of discovering security issues before the device is marketed. However, each device has its own design, including different architectures, services and communication protocols, programmed and configured in different programming languages. This diversity results in potentially complete categories of vulnerabilities discarded by the firmware security analysis tools. Hence, a positive outcome of such tools may result in incorrect conclusions. Dairo de Ruck, Victor Goeman, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 5 |
| 2023 | A hybrid anonymization pipeline to improve the privacy-utility balance in sensitive datasets for ML purposesabstractThe modern world is data-driven. Businesses increasingly take strategic decisions based on customer data, and companies are founded with a sole focus of performing machine-learning driven data analytics for third parties. External data sources containing sensitive records are often required to build qualitative machine learning models and, hence, perform accurate and meaningful predictions. However, exchanging sensitive datasets is no sinecure. Personal data must be managed according to privacy regulation. Similarly, loss of strategic data can negatively impact the competitiveness of a company. In both cases, dataset anonymization can overcome the aforementioned obstacles. Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 5 |
| 2022 | Reviewing review platforms: a privacy perspectiveabstractMany tourists heavily rely on online review platforms for decisions with respect to food, visits and hotel bookings today. Review communities rigorously log all experiences on popular online platforms such as Google Maps, Tripadvisor and Yelp. However, many contributors are unaware that, along with experiences, a lot of sensitive information is often indirectly exposed to platform visitors. Examples are reviewer’s locations in the privacy sphere, age, medical information and financial status. Malicious entities could potentially employ this information in various ways, for example during extortion or targeted phishing attempts. This work outlines the potential risks for contributors on review platforms. The Google Maps review platform is applied as a prototypical example, with a special focus on predicting the reviewer’s home location. The accuracy of our predictions is assessed by relying on ground truth datasets. This paper further presents and evaluates strategies to tackle common problems. Kevin De Boeck, Jenno Verdonck, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 5 |
| 2021 | A clustering approach to anonymize locations during dataset de-identificationabstractCompanies increasingly rely on massive amounts of data for strategic decision making purposes. In order to optimize business intelligence, companies often try to enrich their models with datasets acquired from third parties. Datasets containing sensitive attributes must be anonymized before release. For large datasets containing microdata, an often applied anonymization technique is data generalization with the goal of achieving privacy metrics such as k-anonymity. Location is an often recurring yet strategic attribute in many use cases. Multiple strategies can be employed to obfuscate precise coordinates. For example, the most significant digits can be dropped or their value can be replaced by a ZIP code. While these methods might be useful in some applications, these approaches often result in too much information loss, undermining strategic decision making. This paper proposes a novel approach to anonymize location by means of clustering. Its feasibility is evaluated and compared to traditional techniques. Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 5 |
| 2019 | Trustworthiness Assessment of Web Applications: Approach and Experimental Study using Input Validation Coding PracticesabstractThe popularity of web applications and their world-wide use to support business critical operations raised the interest of hackers on exploiting security vulnerabilities to perform malicious operations. Fostering trust calls for assessment techniques that provide indicators about the quality of a web application from a security perspective. This paper studies the problem of using coding practices to characterize the trustworthiness of web applications from a security perspective. The hypothesis is that applying feasible security practices results in applications having a reduced number of unknown vulnerabilities, and can therefore be considered more trustworthy. The proposed approach is instantiated for the concrete case of input validation practices, and includes a Quality Model to compute trustworthiness scores that can be used to compare different applications or different code elements in the same application. Experimental results show that the higher scores are obtained for more secure code, suggesting that it can be used in practice to characterize trustworthiness, also providing guidance to compare and/or improve the security of web applications. Cristiano Inácio Lemes, Vincent Naessens, Marco Vieira |
ISSRE | 2 |
| 2017 | Security Analysis of Cordova Applications in Google PlayabstractMobile Cross-Platform Tools (CPTs) provide an alternative to native application development that allows mobile app developers to drastically reduce the development time and cost when targeting multiple platforms. They allow sharing a significant part of the application codebase between the implementations for the targeted platforms (e.g. Android, iOS, Windows Phone). Although CPTs provide significant benefits for developers, there can introduce several disadvantages. The CPT software layers and translation steps can impact the security of the produced applications. One of the most well-known and often-used CPTs is Cordova, formerly known as PhoneGap. Cordova has, over the years, taken several steps to reduce the attack surface and introduced several mechanisms that allow developers to increase the security of Cordova applications. This paper gives a statistical overview of the adoption of Cordova security best practices and mechanisms in Cordova applications downloaded from the Google Play Store. For the analysis, over a thousand Cordova application were downloaded. The research shows that the poor adoption of these mechanisms leads to a significant number of insecure Cordova applications. Michiel Willocx, Jan Vossaert, Vincent Naessens |
ARES | 3 |
| 2017 | Security Evaluation of Cyber-Physical Systems Using Automatically Generated Attack Trees
Laurens Lemaire, Jan Vossaert, Bart De Decker, Vincent Naessens |
CRITIS | 4 |
| 2016 | Symmetric key infrastructure for authenticated key establishment between resource constrained nodes and powerful devicesabstractAbstract This paper presents a generic lightweight solution for authentication between powerful devices and resource constrained nodes. The approach is validated through the architectural design of multiple applications in different domains. The paper further discusses variants that might increase the usability of the approach in different settings. More precisely, the solution is tuned for open systems, closed systems and hierarchically structured systems. Further, two use cases are presented in which the open system and closed system approach is applied. Copyright © 2011 John Wiley & Sons, Ltd. Jan Vossaert, Jorn Lapon, Bart De Decker, Vincent Naessens |
Secur. Commun. Networks | 4 |
| 2015 | Privacy-Preserving Public Transport Ticketing System
Milica Milutinovic, Koen Decroix, Vincent Naessens, Bart De Decker |
DBSec | 3 |
| 2014 | Trusted Computing to Increase Security and Privacy in eID Authentication
Jan Vossaert, Jorn Lapon, Bart De Decker, Vincent Naessens |
SEC | 4 |
| 2014 | inShopnito: An Advanced yet Privacy-Friendly Mobile Shopping ApplicationabstractMobile Shopping Applications (MSAs) are rapidly gaining popularity. They enhance the shopping experience, by offering customized recommendations or incorporating customer loyalty programs. Although MSAs are quite effective at attracting new customers and binding existing ones to a retailer's services, existing MSAs have several shortcomings. The data collection practices involved in MSAs and the lack of transparency thereof are important concerns for many customers. This paper presents inShopnito, a privacy-preserving mobile shopping application. All transactions made in inShopnito are unlinkable and anonymous. However, the system still offers the expected features from a modern MSA. Customers can take part in loyalty programs and earn or spend loyalty points and electronic vouchers. Furthermore, the MSA can suggest personalized recommendations even though the retailer cannot construct rich customer profiles. These profiles are managed on the smartphone and can be partially disclosed in order to get better, customized recommendations. Finally, we present an implementation called inShopnito, of which the security and performance is analyzed. In doing so, we show that it is possible to have a privacy-preserving MSA without having to sacrifice practicality. Andreas Put, Italo Dacosta, Milica Milutinovic, Bart De Decker, Stefaan Seys, Faysal Boukayoua, Vincent Naessens, Kris Vanhecke, Toon De Pessemier, Luc Martens |
SERVICES | 7 |
| 2012 | Privacy-Preserving Mechanisms for Organizing Tasks in a Pervasive eHealth System
Milica Milutinovic, Vincent Naessens, Bart De Decker |
SEC | 2 |
| 2011 | Structure Preserving CCA Secure Encryption and Applications
Jan Camenisch, Kristiyan Haralambiev, Markulf Kohlweiss, Jorn Lapon, Vincent Naessens |
ASIACRYPT | 5 |
| 2010 | PriMan : A Privacy-Preserving Identity Framework
Kristof Verslype, Pieter Verhaeghe, Jorn Lapon, Vincent Naessens, Bart De Decker |
DBSec | 4 |
| 2010 | Performance Analysis of Accumulator-Based Revocation Mechanisms
Jorn Lapon, Markulf Kohlweiss, Bart De Decker, Vincent Naessens |
SEC | 4 |
| 2010 | Building advanced applications with the Belgian eIDabstractAbstract The Belgian Electronic Identity Card (eID) was introduced in 2002. The card enables Belgian citizens to digitally prove their identity and to sign electronic documents. Today, only a limited number of citizens really use the card in electronic applications. An important reason is the lack of killer functionality and killer applications. This paper presents two reusable extensions to the Belgian eID technology that opens up new opportunities for application developers. First, a secure and ubiquitously accessible remote storage service is presented. Second, it is shown how the eID card can be used to issue new certificates. The feasibility and reusability of both extensions are validated through the development of several applications in different domains. Copyright © 2010 John Wiley & Sons, Ltd. Jorn Lapon, Vincent Naessens, Bram Verdegem, Pieter Verhaeghe, Bart De Decker |
Secur. Commun. Networks | 2 |
| 2009 | Security and Privacy Improvements for the Belgian eID Technology
Pieter Verhaeghe, Jorn Lapon, Bart De Decker, Vincent Naessens, Kristof Verslype |
SEC | 4 |
| 2008 | A Privacy-Preserving Ticketing System
Kristof Verslype, Bart De Decker, Vincent Naessens, Girma Nigusse, Jorn Lapon, Pieter Verhaeghe |
DBSec | 3 |
| 2006 | A Methodology for Designing Controlled Anonymous Applications
Vincent Naessens, Bart De Decker |
SEC | 1 |
| 2005 | Accountable Anonymous E-Mail
Vincent Naessens, Bart De Decker, Liesje Demuynck |
SEC | 1 |