VLDB 2026 Research / reviewers in the wild / expert
Igor Bilogrevic
dblp:52/8356
· DBLP profile ↗
28ranked-venue papers
12as first author
6since 2021 · last 2025
0000-0002-9301-3091ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 6 first-author · 4 since 2021Computer networks · 5 · 1 first-authorHuman-computer interaction and ubiquitous computing · 5 · 3 first-authorDatabases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Byte by Byte: Unmasking Browser Fingerprinting at the Function Level using V8 Bytecode TransformersabstractBrowser fingerprinting enables persistent cross-site user tracking via subtle techniques that often evade conventional defenses or cause website breakage when script-level blocking countermeasures are applied. Addressing these challenges requires detection methods offering both function-level precision to minimize breakage and inherent robustness against code obfuscation and URL manipulation. Pouneh Nikkhah Bahrami, Dylan Cutler, Igor Bilogrevic |
CCS | 3 |
| 2025 | Beyond the Crawl: Unmasking Browser Fingerprinting in Real User InteractionsabstractBrowser fingerprinting is a pervasive online tracking technique used increasingly often for profiling and targeted advertising. Prior research on the prevalence of fingerprinting heavily relied on automated web crawls, which inherently struggle to replicate the nuances of human-computer interactions. This raises concerns about the accuracy of current understandings of real-world fingerprinting deployments. As a result, this paper presents a user study involving 30 participants over 10 weeks, capturing telemetry data from real browsing sessions across 3,000 top-ranked websites. Our evaluation reveals that automated crawls miss almost half (45%) of the fingerprinting websites encountered by real users. This discrepancy mainly stems from the crawlers' inability to access authentication-protected pages, circumvent bot detection, and trigger fingerprinting scripts activated by specific user interactions. We also identify potential new fingerprinting vectors present in real user data but absent from automated crawls. Finally, we evaluate the effectiveness of federated learning for training browser fingerprinting detection models on real user data, yielding improved performance than models trained solely on automated crawl data. Meenatchi Sundaram Muthu Selva Annamalai, Emiliano De Cristofaro, Igor Bilogrevic |
WWW | 3 |
| 2024 | FP-Fed: Privacy-Preserving Federated Detection of Browser Fingerprinting
Meenatchi Sundaram Muthu Selva Annamalai, Igor Bilogrevic, Emiliano De Cristofaro |
NDSS | 2 |
| 2024 | Don't Interrupt Me - A Large-Scale Study of On-Device Permission Prompt Quieting in Chrome
Marian Harbach, Igor Bilogrevic, Enrico Bacis, Serena Chen, Ravjit Uppal, Andy Paicu, Elias Klim, Meggyn Watkins, Balazs Engedy |
NDSS | 2 |
| 2024 | The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting BehaviorabstractBrowser fingerprinting is often associated with cross-site user tracking, a practice that many browsers (e.g., Safari, Brave, Edge, Firefox, and Chrome) want to block. However, less is publicly known about its uses to enhance online safety, where it can provide an additional security layer against service abuses (e.g., in combination with CAPTCHAs) or during user authentication. To the best of our knowledge, no fingerprinting defenses deployed thus far consider this important distinction when blocking fingerprinting attempts, so they might negatively affect website functionality and security. Asuman Senol, Alisha Ukani, Dylan Cutler, Igor Bilogrevic |
WWW | 4 |
| 2021 | "Shhh...be quiet!" Reducing the Unwanted Interruptions of Notification Permission Prompts on Chrome
Igor Bilogrevic, Balazs Engedy, Judson L. Porter III, Nina Taft, Kamila Hasanbega, Andrew Paseltiner, Hwi Kyoung Lee, Edward Jung, Meggyn Watkins, P. J. McLachlan, Jason James |
USENIX Security Symposium | 1 |
| 2020 | A Study on the Use of Checksums for Integrity Verification of Web DownloadsabstractApp stores provide access to millions of different programs that users can download on their computers. Developers can also make their programs available for download on their websites and host the program files either directly on their website or on third-party platforms, such as mirrors. In the latter case, as users download the software without any vetting from the developers, they should take the necessary precautions to ensure that it is authentic. One way to accomplish this is to check that the published file’s integrity verification code—the checksum—matches that (if provided) of the downloaded file. To date, however, there is little evidence to suggest that such a process is effective. Even worse, very few usability studies about it exist. In this article, we provide the first comprehensive study that assesses the usability and effectiveness of the manual checksum verification process. First, by means of an in-situ experiment with 40 participants and eye-tracking technology, we show that the process is cumbersome and error-prone. Second, after a 4-month-long in-the-wild experiment with 134 participants, we demonstrate how our proposed solution—a Chrome extension that verifies checksums automatically—significantly reduces human errors, improves coverage, and has only limited impact on usability. It also confirms that, sadly, only a tiny minority of websites that link to executable files in our sample provide checksums (0.01%), which is a strong call to action for web standards bodies, service providers, and content creators to increase the use of file integrity verification on their properties. Alexandre Meylan, Mauro Cherubini, Bertil Chapuis, Mathias Humbert, Igor Bilogrevic, Kévin Huguenin |
ACM Trans. Priv. Secur. | 5 |
| 2019 | Reducing Permission Requests in Mobile AppsabstractUsers of mobile apps sometimes express discomfort or concerns with what they see as unnecessary or intrusive permission requests by certain apps. However encouraging mobile app developers to request fewer permissions is challenging because there are many reasons why permissions are requested; furthermore, prior work [25] has shown it is hard to disambiguate the purpose of a particular permission with high certainty. Sai Teja Peddinti, Igor Bilogrevic, Nina Taft, Martin Pelikan, Úlfar Erlingsson, Pauline Anthonysamy, Giles Hogben |
Internet Measurement Conference | 2 |
| 2018 | Towards Usable Checksums: Automating the Integrity Verification of Web Downloads for the MassesabstractInternet users can download software for their computers from app stores (e.g., Mac App Store and Windows Store) or from other sources, such as the developers' websites. Most Internet users in the US rely on the latter, according to our representative study, which makes them directly responsible for the content they download. To enable users to detect if the downloaded files have been corrupted, developers can publish a checksum together with the link to the program file; users can then manually verify that the checksum matches the one they obtain from the downloaded file. In this paper, we assess the prevalence of such behavior among the general Internet population in the US (N=2,000), and we develop easy-to-use tools for users and developers to automate both the process of checksum verification and generation. Specifically, we propose an extension to the recent W3C specification for sub-resource integrity in order to provide integrity protection for download links. Also, we develop an extension for the popular Chrome browser that computes and verifies checksums of downloaded files automatically, and an extension for the WordPress CMS that developers can use to easily attach checksums to their remote content. Our in situ experiments with 40participants demonstrate the usability and effectiveness issues of checksums verification, and shows user desirability for our extension. Mauro Cherubini, Alexandre Meylan, Bertil Chapuis, Mathias Humbert, Igor Bilogrevic, Kévin Huguenin |
CCS | 5 |
| 2018 | A Predictive Model for User Motivation and Utility Implications of Privacy-Protection Mechanisms in Location Check-InsabstractLocation check-ins contain both geographical and semantic information about the visited venues. Semantic information is usually represented by means of tags (e.g., “restaurant”). Such data can reveal some personal information about users beyond what they actually expect to disclose, hence their privacy is threatened. To mitigate such threats, several privacy protection techniques based on location generalization have been proposed. Although the privacy implications of such techniques have been extensively studied, the utility implications are mostly unknown. In this paper, we propose a predictive model for quantifying the effect of a privacy-preserving technique (i.e., generalization) on the perceived utility of check-ins. We first study the users' motivations behind their location check-ins, based on a study targeted at Foursquare users (N 1/4 77). We propose a machine-learning method for determining the motivation behind each check-in, and we design a motivation-based predictive model for the utility implications of generalization. Based on the survey data, our results show that the model accurately predicts the fine-grained motivation behind a check-in in [43%] of the cases and in [63%] of the cases for the coarse-grained motivation. It also predicts, with a mean error of [0.52] (on a scale from 1 to 5), the loss of utility caused by semantic and geographical generalization. This model makes it possible to design of utility-aware, privacy-enhancing mechanisms in location-based online social networks. It also enables service providers to implement locationsharing mechanisms that preserve both the utility and privacy for their users. Kévin Huguenin, Igor Bilogrevic, Joana Soares Machado, Stefan Mihaila, Reza Shokri, Italo Dacosta, Jean-Pierre Hubaux |
IEEE Trans. Mob. Comput. | 2 |
| 2018 | Side-Channel Inference Attacks on Mobile Keypads Using SmartwatchesabstractSmartwatches enable many novel applications and are fast gaining popularity. However, the presence of a diverse set of onboard sensors provides an additional attack surface to malicious software and services on these devices. In this paper, we investigate the feasibility of key press inference attacks on handheld numeric touchpads by using smartwatch motion sensors as a side-channel. We consider different typing scenarios, and propose multiple attack approaches to exploit the characteristics of the observed wrist movements for inferring individual key presses. Experimental evaluation using commercial off-the-shelf smartwatches and smartphones show that key press inference using smartwatch motion sensors is not only fairly accurate, but also comparable with similar attacks using smartphone motion sensors. Additionally, hand movements captured by a combination of both smartwatch and smartphone motion sensors yields better inference accuracy than either device considered individually. Anindya Maiti, Murtuza Jadliwala, Jibo He, Igor Bilogrevic |
IEEE Trans. Mob. Comput. | 4 |
| 2017 | Exploring decision making with Android's runtime permission dialogs using in-context surveys
Bram Bonné, Sai Teja Peddinti, Igor Bilogrevic, Nina Taft |
SOUPS | 3 |
| 2016 | "If You Put All The Pieces Together...": Attitudes Towards Data Combination and Sharing Across Services and CompaniesabstractOnline services often rely on processing users' data, which can be either provided directly by the users or combined from other services. Although users are aware of the latter, it is unclear whether they are comfortable with such data combination, whether they view it as beneficial for them, or the extent to which they believe that their privacy is exposed. Through an online survey (N=918) and follow-up interviews (N=14), we show that (1) comfort is highly dependent on the type of data, type of service and on the existence of a direct relationship with a company, (2) users have a highly different opinion about the presence of benefits for them, irrespectively of the context, and (3) users perceive the combination of online data as more identifying than data related to offline and physical behavior (such as location). Finally, we discuss several strategies for companies to improve upon these issues. Igor Bilogrevic, Martin Ortlieb |
CHI | 1 |
| 2016 | A machine-learning based approach to privacy-aware information-sharing in mobile social networks
Igor Bilogrevic, Kévin Huguenin, Berker Agir, Murtuza Jadliwala, Maria Gazaki, Jean-Pierre Hubaux |
Pervasive Mob. Comput. | 1 |
| 2016 | SecureRun: Cheat-Proof and Private Summaries for Location-Based ActivitiesabstractActivity-tracking applications, where people record and upload information about their location-based activities (e.g., the routes of their activities), are increasingly popular. Such applications enable users to share information and compete with their friends on activity-based social networks but also, in some cases, to obtain discounts on their health insurance premiums by proving they conduct regular fitness activities. However, they raise privacy and security issues: the service providers know the exact locations of their users; the users can report fake location information, for example, to unduly brag about their performance. In this paper, we present SecureRun, a secure privacy-preserving system for reporting location-based activity summaries (e.g., the total distance covered and the elevation gain). SecureRun is based on a combination of cryptographic techniques and geometric algorithms, and it relies on existing Wi-Fi access-point networks deployed in urban areas. We evaluate SecureRun by using real data-sets from the FON hotspot community networks and from the Garmin Connect activity-based social network, and we show that it can achieve tight (up to a median accuracy of more than 80 percent) verifiable lower-bounds of the distance covered and of the elevation gain, while protecting the location privacy of the users with respect to both the social network operator and the access point network operator(s). The results of our online survey, targeted at RunKeeper users recruited through the Amazon Mechanical Turk platform, highlight the lack of awareness and significant concerns of the participants about the privacy and security issues of activity-tracking applications. They also show a good level of satisfaction regarding SecureRun and its performance. Anh Pham, Kévin Huguenin, Igor Bilogrevic, Italo Dacosta, Jean-Pierre Hubaux |
IEEE Trans. Mob. Comput. | 3 |
| 2015 | Predicting Users' Motivations behind Location Check-Ins and Utility Implications of Privacy Protection MechanismsabstractAuthor(s): Igor Bilogrevic, Kevin Huguenin, Stefan Mihaila, Reza Shokri, Jean-Pierre Hubaux Download: Paper (PDF) Date: 7 Feb 2015 Document Type: Briefing Papers Additional Documents: Slides Associated Event: NDSS Symposium 2015 Abstract: Location check-ins contain both geographical and semantic information about the visited venues, in the form of tags (e.g., “restaurant”). Such data might reveal some … Continued Igor Bilogrevic, Kévin Huguenin, Stefan Mihaila, Reza Shokri, Jean-Pierre Hubaux |
NDSS | 1 |
| 2014 | What's the Gist? Privacy-Preserving Aggregation of User Profiles
Igor Bilogrevic, Julien Freudiger, Emiliano De Cristofaro, Ersin Uzun |
ESORICS (2) | 1 |
| 2014 | Secure and private proofs for location-based activity summaries in urban areasabstractActivity-based social networks, where people upload and share information about their location-based activities (e.g., the routes of their activities), are increasingly popular. Such systems, however, raise privacy and security issues: The service providers know the exact locations of their users; the users can report fake location information in order to, for example, unduly brag about their performance. In this paper, we propose a secure privacy-preserving system for reporting location-based activity summaries (e.g., the total distance covered and the elevation gain). Our solution is based on a combination of cryptographic techniques and geometric algorithms, and it relies on existing Wi-Fi access-point networks deployed in urban areas. We evaluate our solution by using real data sets from the FON community networks and from the Garmin Connect activity-based social network, and we show that it can achieve tight (up to a median accuracy of 76%) verifiable lower-bounds of the distance covered and of the elevation gain, while protecting the location privacy of the users with respect to both the social network operator and the access-point network operator(s). Anh Pham, Kévin Huguenin, Igor Bilogrevic, Jean-Pierre Hubaux |
UbiComp | 3 |
| 2014 | Privacy-Preserving Optimal Meeting Location Determination on Mobile DevicesabstractEquipped with state-of-the-art smartphones and mobile devices, today's highly interconnected urban population is increasingly dependent on these gadgets to organize and plan their daily lives. These applications often rely on current (or preferred) locations of individual users or a group of users to provide the desired service, which jeopardizes their privacy; users do not necessarily want to reveal their current (or preferred) locations to the service provider or to other, possibly untrusted, users. In this paper, we propose privacy-preserving algorithms for determining an optimal meeting location for a group of users. We perform a thorough privacy evaluation by formally quantifying privacy-loss of the proposed approaches. In order to study the performance of our algorithms in a real deployment, we implement and test their execution efficiency on Nokia smartphones. By means of a targeted user-study, we attempt to get an insight into the privacy-awareness of users in location-based services and the usability of the proposed solutions. Igor Bilogrevic, Murtuza Jadliwala, Vishal Joneja, Kübra Kalkan, Jean-Pierre Hubaux, Imad Aad |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Adaptive information-sharing for privacy-aware mobile social networksabstractPersonal and contextual information are increasingly shared via mobile social networks. Users' locations, activities and their co-presence can be shared easily with online "friends", as their smartphones already access such information from embedded sensors and storage. Yet, people usually exhibit selective sharing behavior depending on contextual attributes, thus showing that privacy, utility, and usability are paramount to the success of such online services. In this paper, we present SPISM, a novel information-sharing system that decides (semi-)automatically whether to share information with others, whenever they request it, and at what granularity. Based on active machine learning and context, SPISM adapts to each user's behavior and it predicts the level of detail for each sharing decision, without revealing any personal information to a third-party. Based on a personalized survey about information sharing involving 70 participants, our results provide insight into the most influential features behind a sharing decision. Moreover, we investigate the reasons for the users' decisions and their confidence in them. We show that SPISM outperforms other kinds of global and individual policies, by achieving up to 90% of correct decisions. Igor Bilogrevic, Kévin Huguenin, Berker Agir, Murtuza Jadliwala, Jean-Pierre Hubaux |
UbiComp | 1 |
| 2013 | Optimizing mix-zone coverage in pervasive wireless networksabstractLocation privacy is a major concern in pervasive networks where static device identifiers enable malicious eavesdroppers to continuously track users and their movements. In order to prevent such identifier-based tracking, devices could coordinate regular identifier change operations in special areas called mix-zones. Although mix-zones provide spatio-temporal de-correlation between old and new identifiers, depending on the position of the mix-zone, identifier changes can generate a substantial inconvenience (or “cost”) to the users in terms of lost communications and increased energy consumption. In this paper, we address this trade-off between privacy and cost by studying the problem of determining an optimal set of mix-zones such that the degree of mixing in the network is maximized and the overall network-wide mixing cost is minimized. We follow a graph-theoretic approach and model the optimal mixing problem as a generalization of the vertex cover problem, called the Mix Cover (MC) problem. We propose three approximation algorithms for the MC problem and derive a lower bound on the solution quality guaranteed by them. Additionally, we outline two other heuristics for solving the MC problem. These heuristics are simple, but do not provide any guarantees on the solution quality. By means of extensive empirical evaluation using real data, we compare the performance and solution quality of these algorithms. The combinatorics-based approach used in this work enables us to study the feasibility of determining optimal mix-zones regularly and under dynamic network conditions. Murtuza Jadliwala, Igor Bilogrevic, Jean-Pierre Hubaux |
J. Comput. Secur. | 2 |
| 2012 | Track Me If You Can: On the Effectiveness of Context-based Identifier Changes in Deployed Mobile Networks
Laurent Bindschaedler, Murtuza Jadliwala, Igor Bilogrevic, Imad Aad, Philip Ginzboorg, Valtteri Niemi, Jean-Pierre Hubaux |
NDSS | 3 |
| 2011 | Privacy-preserving activity scheduling on mobile devicesabstractProgress in mobile wireless technology has resulted in the increased use of mobile devices to store and manage users' personal schedules. Users also access popular context-based services, typically provided by third-party providers, by using these devices for social networking, dating and activity-partner searching applications. Very often, these applications need to determine common availabilities among a set of user schedules. The privacy of the scheduling operation is paramount to the success of such applications, as often users do not want to share their personal schedules with other users or third-parties. Previous research has resulted in solutions that provide privacy guarantees, but they are either too complex or do not fit well in the popular user-provider operational model. In this paper, we propose practical and privacy-preserving solutions to the server-based scheduling problem. Our novel algorithms take advantage of the homomorphic properties of well-known cryptosystems in order to privately compute common user availabilities. We also formally outline the privacy requirements in such scheduling applications and we implement our solutions on real mobile devices. The experimental measurements and analytical results show that the proposed solutions not only satisfy the privacy properties but also fare better, in regard to computation and communication efficiency, compared to other well-known solutions. Igor Bilogrevic, Murtuza Jadliwala, Jean-Pierre Hubaux, Imad Aad, Valtteri Niemi |
CODASPY | 1 |
| 2011 | Optimizing Mixing in Pervasive Networks: A Graph-Theoretic Perspective
Murtuza Jadliwala, Igor Bilogrevic, Jean-Pierre Hubaux |
ESORICS | 2 |
| 2011 | Privacy in Mobile Computing for Location-Sharing-Based Services
Igor Bilogrevic, Murtuza Jadliwala, Kübra Kalkan, Jean-Pierre Hubaux, Imad Aad |
PETS | 1 |
| 2011 | OREN: Optimal revocations in ephemeral networks
Igor Bilogrevic, Mohammad Hossein Manshaei, Maxim Raya, Jean-Pierre Hubaux |
Comput. Networks | 1 |
| 2011 | Meetings through the cloud: Privacy-preserving scheduling on mobile devices
Igor Bilogrevic, Murtuza Jadliwala, Praveen Kumar 0003, Sudeep Singh Walia, Jean-Pierre Hubaux, Imad Aad, Valtteri Niemi |
J. Syst. Softw. | 1 |
| 2010 | Optimal revocations in ephemeral networks: A game-theoretic framework
Igor Bilogrevic, Mohammad Hossein Manshaei, Maxim Raya, Jean-Pierre Hubaux |
WiOpt | 1 |