VLDB 2026 Research / reviewers in the wild / expert
Frank Li 0001
dblp:53/10825 · also Frank H. Li
· DBLP profile ↗
40ranked-venue papers
5as first author
24since 2021 · last 2025
0000-0003-2242-048XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 31 · 3 first-author · 20 since 2021Computer networks · 6 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Sea of Cyber Threats: Maritime Cybersecurity from the Perspective of MarinersabstractMaritime systems, including ships and ports, are critical components of global infrastructure, essential for transporting over 80% of the world's goods and supporting internet connectivity. However, these systems face growing cybersecurity threats, as shown by recent attacks disrupting Maersk, one of the world's largest shipping companies, causing widespread impacts on international trade. The unique challenges of the maritime environment--such as diverse operational conditions, extensive physical access points, fragmented regulatory frameworks, and its deeply interconnected structure--require maritime-specific cybersecurity research. Despite the sector's importance, maritime cybersecurity remains underexplored, leaving significant gaps in understanding its challenges and risks. To address these gaps, we investigate how maritime system operators perceive and navigate cybersecurity challenges within this complex landscape. We conducted a user study comprising surveys and semi-structured interviews with 21 officer-level mariners. Participants reported direct experiences with shipboard cyber-attacks, including GPS spoofing and logistics-disrupting ransomware, demonstrating the real-world impact of these threats. Our findings reveal systemic and human-centric issues, such as training poorly aligned with maritime needs, insufficient detection and response tools, and serious gaps in mariners' cybersecurity understanding. Our contributions include a categorization of threats identified by mariners and recommendations for improving maritime security, including better training, response protocols, and regulation. These insights aim to guide future research and policy to strengthen the resilience of maritime systems. Anna Raymaker, Akshaya Kumar, Miuyin Yong Wong, Ryan Pickren, Animesh Chhotaray, Frank Li 0001, Saman A. Zonouz, Raheem A. Beyah |
CCS | 6 |
| 2025 | The Challenges and Opportunities with Cybersecurity Regulations: A Case Study of the US Electric Power SectorabstractIn various industries, cybersecurity regulations have been enacted in an effort to drive improvements to organizational security postures. Despite the prominent influence of these regulations, there has been limited prior investigation of how organizations engage with these regulations and the challenges that they face. Assessing these factors is vital for understanding the impact of cybersecurity regulations in practice and how to enhance them moving forward. Sena Sahin, Burak Sahin, Robin Berthier, Katherine R. Davis 0001, Saman A. Zonouz, Frank Li 0001 |
CCS | 6 |
| 2025 | Was This You? Investigating the Design Considerations for Suspicious Login Notifications
Sena Sahin, Burak Sahin, Frank Li 0001 |
NDSS | 3 |
| 2025 | Understanding IPv6 Aliases and Detection Methods
Mert Erdemir, Frank Li 0001, Paul Pearce |
PAM | 2 |
| 2025 | Evaluating Privacy Policies under Modern Privacy Laws At Scale: An LLM-Based Automated Approach
Qinge Xie, Karthik Ramakrishnan, Frank Li 0001 |
USENIX Security Symposium | 3 |
| 2024 | Unmasking the Security and Usability of Password MaskingabstractPassword masking, a practice where passwords are obscured during entry, is widely adopted for online authentication. However, its merits have been debated for over a decade, with questions about its security benefits and concerns about its usability impact. Yet to date, masking has received limited prior exploration. Suood Alroomi, Sena Sahin, Frank Li 0001 |
CCS | 4 |
| 2024 | Release the Hounds! Automated Inference and Empirical Security Evaluation of Field-Deployed PLCs Using Active Network Data
Ryan Pickren, Animesh Chhotaray, Frank Li 0001, Saman A. Zonouz, Raheem A. Beyah |
CCS | 3 |
| 2024 | Whatcha Lookin' At: Investigating Third-Party Web Content in Popular Android AppsabstractOver 65% of web traffic originates from mobile devices. However, much of this traffic is not from mobile web browsers but rather from mobile apps displaying web content. Android's WebView has been a common way for apps to display web content, but it entails security and privacy concerns, especially for third-party content. Custom Tabs (CTs) are a more recent and recommended alternative. Dhruv Kuchhal, Karthik Ramakrishnan, Frank Li 0001 |
IMC | 3 |
| 2024 | A First Look at NAT64 Deployment In-The-Wild
Amanda Hsu, Frank Li 0001, Paul Pearce, Oliver Gasser |
PAM (1) | 2 |
| 2024 | Crawling to the Top: An Empirical Evaluation of Top List Use
Qinge Xie, Frank Li 0001 |
PAM (1) | 2 |
| 2024 | I Experienced More than 10 DeFi Scams: On DeFi Users' Perception of Security Breaches and Countermeasures
Jun-Ho Huh, HyungSeok Han, Jaehyuk Lee, Jihae Ahn, Frank Li 0001, Hyoungshick Kim, Taesoo Kim |
USENIX Security Symposium | 6 |
| 2024 | 6Sense: Internet-Wide IPv6 Scanning and its Security Applications
Grant Williams, Mert Erdemir, Amanda Hsu, Shraddha Bhat, Abhishek Bhaskar, Frank Li 0001, Paul Pearce |
USENIX Security Symposium | 6 |
| 2024 | Arcanum: Detecting and Evaluating the Privacy Risks of Browser Extensions on Web Pages and Web Content
Qinge Xie, Manoj Vignesh Kasi Murali, Paul Pearce, Frank Li 0001 |
USENIX Security Symposium | 4 |
| 2023 | Measuring Website Password Creation Policies At ScaleabstractResearchers have extensively explored how password creation policies influence the security and usability of user-chosen passwords, producing evidence-based policy guidelines. However, for web authentication to improve in practice, websites must actually implement these recommendations. To date, there has been limited investigation into what password creation policies are actually deployed by sites. Existing works are mostly dated and all studies relied on manual evaluations, assessing a small set of sites (at most 150, skewed towards top sites). Thus, we lack a broad understanding of the password policies used today. In this paper, we develop an automated technique for inferring a website's password creation policy, and apply it at scale to measure the policies of over 20K sites, over two orders of magnitude (~135x) more sites than prior work. Our findings identify the common policies deployed, potential causes of weak policies, and directions for improving authentication in practice. Ultimately, our study provides the first large-scale understanding of password creation policies on the web. Suood Alroomi, Frank Li 0001 |
CCS | 2 |
| 2023 | Evaluating the Security Posture of Real-World FIDO2 DeploymentsabstractFIDO2 is a suite of protocols that combines the usability of local authentication (e.g., biometrics) with the security of public-key cryptography to deliver passwordless authentication. It eliminates shared authentication secrets (i.e., passwords, which could be leaked or phished) and provides strong security guarantees assuming the benign behavior of the client-side protocol components. Dhruv Kuchhal, Muhammad Saad 0001, Adam Oest, Frank Li 0001 |
CCS | 4 |
| 2023 | Investigating the Password Policy Practices of Website AdministratorsabstractPasswords are the de facto standard for online authentication today, and will likely remain so for the foreseeable future. As a consequence, the security community has extensively explored how users behave with passwords, producing recommendations for password policies that promote password security and usability for users. However, it is the website administrators who must adopt such recommendations to enact improvements to online authentication in practice. To date, there has been limited investigation of how web administrators manage password policies for their sites. To improve online authentication at scale, we must understand the factors behind this specific population’s behaviors and decisions, and how to help administrators deploy more secure password policies.In this paper, we explore how web administrators determine the password policies that they employ, what considerations impact a policy’s evolution, and what challenges administrators encounter when managing a site’s policy. To do so, we conduct an online survey and in-depth semi-structured interviews with 11 US-based web administrators with direct experience managing website password policies. Through our qualitative study, we identify a small set of key factors driving the majority of password policy decisions, and barriers that inhibit administrators from enacting policies that are more aligned with modern guidelines. Moving forward, we propose directions for future research and community action that may help administrators manage password policies more effectively. Sena Sahin, Suood Abdulaziz Al-Roomi, Tara Poteat, Frank Li 0001 |
SP | 4 |
| 2023 | A Large-Scale Measurement of Website Login Policies
Suood Abdulaziz Al-Roomi, Frank Li 0001 |
USENIX Security Symposium | 2 |
| 2022 | Building an Open, Robust, and Stable Voting-Based Domain Top List
Qinge Xie, Shujun Tang, Qingran Lin, Baojun Liu 0002, Hai-Xin Duan, Frank Li 0001 |
USENIX Security Symposium | 7 |
| 2022 | A View into YouTube View FraudabstractSocial media platforms are driven by user engagement metrics. Unfortunately, such metrics are susceptible to manipulation and expose the platforms to abuse. Video view fraud is a unique class of fake engagement abuse on video-sharing platforms, such as YouTube, where the view count of videos is artificially inflated. There exists limited research on such abuse, and prior work focused on automated or bot-driven approaches. In this paper, we explore organic or human-driven approaches to view fraud, conducting a case study on a long-running YouTube view fraud campaign operated on a popular free video streaming service, 123Movies. Before 123Movies users are allowed to access a stream on the service, they must watch an unsolicited YouTube video displayed as a pre-roll advertisement. Due to 123Movies’ popularity, this activity drives large-scale YouTube view fraud. In this study, we reverse-engineer how 123Movies distributes these YouTube videos as pre-roll advertisements, and track the YouTube videos involved over a 9-month period. For a subset of these videos, we monitor their view counts and metrics for their respective YouTube channels over the same period. Our analysis reveals the characteristics of YouTube channels and videos participating in this view fraud, as well as the efficacy of such view fraud efforts. Ultimately, our study provides empirical grounding on organic YouTube view fraud. Dhruv Kuchhal, Frank Li 0001 |
WWW | 2 |
| 2022 | Cleaning the NVD: Comprehensive Quality Assessment, Improvements, and Analyses
Afsah Anwar, Ahmed Abusnaina, Songqing Chen, Frank Li 0001, David Mohaisen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password AuthenticationabstractTo enhance the usability of password authentication, typo-tolerant password authentication schemes permit certain deviations in the user-supplied password, to account for common typographical errors yet still allow the user to successfully log in. In prior work, analysis by Chatterjee et al. demonstrated that typo-tolerance indeed notably improves password usability, yet (surprisingly) does not appear to significantly degrade authentication security. In practice, major web services such as Facebook have employed typo-tolerant password authentication systems. In this paper, we revisit the security impact of typo-tolerant password authentication. We observe that the existing security analysis of such systems considers only password spraying attacks. However, this threat model is incomplete, as password authentication systems must also contend with credential stuffing and tweaking attacks. Factoring in these missing attack vectors, we empirically re-evaluate the security impact of password typo-tolerance using password leak datasets, discovering a significantly larger degradation in security. To mitigate this issue, we explore machine learning classifiers that predict when a password's security is likely affected by typo-tolerance. Our resulting models offer various suitable operating points on the functionality-security tradeoff spectrum, ultimately allowing for partial deployment of typo-tolerant password authentication, preserving its functionality for many users while reducing the security risks. Sena Sahin, Frank Li 0001 |
CCS | 2 |
| 2021 | Knock and talk: investigating local network communications on websitesabstractModern webpages are amalgamations of resources requested from various public Internet services. In principle though, webpages can also request resources from localhost and devices in the LAN, providing a degree of internal network access to external entities. Prior work has demonstrated how this access can be used for supporting web attacks, particularly for profiling and fingerprinting users. Dhruv Kuchhal, Frank Li 0001 |
Internet Measurement Conference | 2 |
| 2021 | Who you gonna call?: an empirical evaluation of website security.txt deploymentabstractThe security.txt proposed standard allows organizations to define how security researchers should disclose security issues. While it is still proceeding through the final stages of standardization, major online services have already adopted the standard (such as Google, Facebook, LinkedIn, and Github). In this work, we conduct an empirical investigation into how websites are deploying security.txt. We first monitor security.txt adoption over a 15-month period, identifying the level of deployment for top websites. We also characterize the information being provided through security.txt and issues present in the provided data. Ultimately, our analysis sheds light on how the security.txt mechanism manifests in practice and its implications for vulnerability reporting, particularly for large-scale automated notification campaigns. Tara Poteat, Frank Li 0001 |
Internet Measurement Conference | 2 |
| 2021 | Deep Entity Classification: Abusive Account Detection for Online Social Networks
Teng Xu 0009, Gerard Goossen, Huseyin Kerem Cevahir, Sara Khodeir, Yingyezhe Jin, Frank Li 0001, Shawn Shan, David Mandell Freeman, Paul Pearce |
USENIX Security Symposium | 6 |
| 2020 | Towards A User-Level Understanding of IPv6 BehaviorabstractIP address classification and clustering are important tools for security practitioners in understanding attacks and employing proactive defenses. Over the past decade, network providers have begun transitioning from IPv4 to the more flexible IPv6, and a third of users now access online services over IPv6. However, there is no reason to believe that the properties of IPv4 addresses used for security applications should carry over to IPv6, and to date there has not yet been a large-scale study comparing the two protocols at a user (as opposed to a client or address) level. Frank Li 0001, David Mandell Freeman |
Internet Measurement Conference | 1 |
| 2020 | Shim Shimmeny: Evaluating the Security and Privacy Contributions of Link Shimming in the Modern Web
Frank Li 0001 |
USENIX Security Symposium | 1 |
| 2018 | Didn't You Hear Me? - Towards More Successful Web Vulnerability Notifications
Ben Stock, Giancarlo Pellegrino, Frank Li 0001, Michael Backes 0001, Christian Rossow |
NDSS | 3 |
| 2017 | A Large-Scale Empirical Study of Security PatchesabstractGiven how the "patching treadmill" plays a central role for enabling sites to counter emergent security concerns, it behooves the security community to understand the patch development process and characteristics of the resulting fixes. Illumination of the nature of security patch development can inform us of shortcomings in existing remediation processes and provide insights for improving current practices. In this work we conduct a large-scale empirical study of security patches, investigating more than 4,000 bug fixes for over 3,000 vulnerabilities that affected a diverse set of 682 open-source software projects. For our analysis we draw upon the National Vulnerability Database, information scraped from relevant external references, affected software repositories, and their associated security fixes. Leveraging this diverse set of information, we conduct an analysis of various aspects of the patch development life cycle, including investigation into the duration of impact a vulnerability has on a code base, the timeliness of patch development, and the degree to which developers produce safe and reliable fixes. We then characterize the nature of security fixes in comparison to other non-security bug fixes, exploring the complexity of different types of patches and their impact on code bases. Frank Li 0001, Vern Paxson |
CCS | 1 |
| 2017 | Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsabstractIn this paper, we present the first longitudinal measurement study of the underground ecosystem fueling credential theft and assess the risk it poses to millions of users. Over the course of March, 2016--March, 2017, we identify 788,000 potential victims of off-the-shelf keyloggers; 12.4 million potential victims of phishing kits; and 1.9 billion usernames and passwords exposed via data breaches and traded on blackmarket forums. Using this dataset, we explore to what degree the stolen passwords---which originate from thousands of online services---enable an attacker to obtain a victim's valid email credentials---and thus complete control of their online identity due to transitive trust. Drawing upon Google as a case study, we find 7--25% of exposed passwords match a victim's Google account. For these accounts, we show how hardening authentication mechanisms to include additional risk signals such as a user's historical geolocations and device profiles helps to mitigate the risk of hijacking. Beyond these risk metrics, we delve into the global reach of the miscreants involved in credential theft and the blackhat tools they rely on. We observe a remarkable lack of external pressure on bad actors, with phishing kit playbooks and keylogger capabilities remaining largely unchanged since the mid-2000s. Kurt Thomas, Frank Li 0001, Ali Zand, Jacob Barrett, Juri Ranieri, Luca Invernizzi, Yarik Markov, Oxana Comanescu, Vijay Eranti, Angelique Moscicki, Dan Margolis, Vern Paxson, Elie Bursztein |
CCS | 2 |
| 2017 | MiniCrypt: Reconciling Encryption and Compression for Big Data StoresabstractWe propose MiniCrypt, the first key-value store that reconciles encryption and compression without compromising performance. At the core of MiniCrypt is an observation on data compressibility trends in key-value stores, which enables grouping key-value pairs into small key packs, together with a set of distributed systems techniques for retrieving, updating, merging and splitting encrypted packs. Our evaluation shows that MiniCrypt compresses data by as much as 4 times with respect to the vanilla key-value store, and can increase the server's throughput by up to two orders of magnitude by fitting more data in main memory. Wenting Zheng, Frank Li 0001, Raluca A. Popa, Ion Stoica, Rachit Agarwal 0001 |
EuroSys | 2 |
| 2017 | Target generation for internet-wide IPv6 scanningabstractFast IPv4 scanning has enabled researchers to answer a wealth of new security and measurement questions. However, while increased network speeds and computational power have enabled comprehensive scans of the IPv4 address space, a brute-force approach does not scale to IPv6. Systems are limited to scanning a small fraction of the IPv6 address space and require an algorithmic approach to determine a small set of candidate addresses to probe. In this paper, we first explore the considerations that guide designing such algorithms. We introduce a new approach that identifies dense address space regions from a set of known "seed" addresses and generates a set of candidates to scan. We compare our algorithm 6Gen against Entropy/IP---the current state of the art---finding that we can recover between 1--8 times as many addresses for the five candidate datasets considered in the prior work. However, during our analysis, we uncover widespread IP aliasing in IPv6 networks. We discuss its effect on target generation and explore preliminary approaches for detecting aliased regions. Austin Murdock, Frank Li 0001, Paul Bramsen, Zakir Durumeric, Vern Paxson |
Internet Measurement Conference | 2 |
| 2017 | Augur: Internet-Wide Detection of Connectivity DisruptionsabstractAnecdotes, news reports, and policy briefings collectively suggest that Internet censorship practices are pervasive. The scale and diversity of Internet censorship practices makes it difficult to precisely monitor where, when, and how censorship occurs, as well as what is censored. The potential risks in performing the measurements make this problem even more challenging. As a result, many accounts of censorship begin-and end-with anecdotes or short-term studies from only a handful of vantage points. We seek to instead continuously monitor information about Internet reachability, to capture the onset or termination of censorship across regions and ISPs. To achieve this goal, we introduce Augur, a method and accompanying system that utilizes TCP/IP side channels to measure reachability between two Internet locations without directly controlling a measurement vantage point at either location. Using these side channels, coupled with techniques to ensure safety by not implicating individual users, we develop scalable, statistically robust methods to infer network-layer filtering, and implement a corresponding system capable of performing continuous monitoring of global censorship. We validate our measurements of Internet-wide disruption in nearly 180 countries over 17 days against sites known to be frequently blocked, we also identify the countries where connectivity disruption is most prevalent. Paul Pearce, Roya Ensafi, Frank Li 0001, Nick Feamster, Vern Paxson |
IEEE Symposium on Security and Privacy | 3 |
| 2017 | Global Measurement of DNS Manipulation
Paul Pearce, Ben Jones, Frank Li 0001, Roya Ensafi, Nick Feamster, Nicholas Weaver, Vern Paxson |
USENIX Security Symposium | 3 |
| 2016 | You've Got Vulnerability: Exploring Effective Vulnerability Notifications
Frank Li 0001, Zakir Durumeric, Jakub Czyz, Mohammad Karami, Michael D. Bailey, Damon McCoy, Stefan Savage, Vern Paxson |
USENIX Security Symposium | 1 |
| 2016 | Remedying Web Hijacking: Notification Effectiveness and Webmaster ComprehensionabstractAs miscreants routinely hijack thousands of vulnerable web servers weekly for cheap hosting and traffic acquisition, security services have turned to notifications both to alert webmasters of ongoing incidents as well as to expedite recovery. In this work we present the first large-scale measurement study on the effectiveness of combinations of browser, search, and direct webmaster notifications at reducing the duration a site remains compromised. Our study captures the life cycle of 760,935 hijacking incidents from July, 2014--June, 2015, as identified by Google Safe Browsing and Search Quality. We observe that direct communication with webmasters increases the likelihood of cleanup by over 50% and reduces infection lengths by at least 62%. Absent this open channel for communication, we find browser interstitials---while intended to alert visitors to potentially harmful content---correlate with faster remediation. As part of our study, we also explore whether webmasters exhibit the necessary technical expertise to address hijacking incidents. Based on appeal logs where webmasters alert Google that their site is no longer compromised, we find 80% of operators successfully clean up symptoms on their first appeal. However, a sizeable fraction of site owners do not address the root cause of compromise, with over 12% of sites falling victim to a new attack within 30 days. We distill these findings into a set of recommendations for improving web security and best practices for webmasters. Frank Li 0001, Grant Ho, Eric Kuan, Yuan Niu, Lucas Ballard, Kurt Thomas, Elie Bursztein, Vern Paxson |
WWW | 1 |
| 2014 | Consequences of Connectivity: Characterizing Account Hijacking on TwitterabstractIn this study we expose the serious large-scale threat of criminal account hijacking and the resulting damage incurred by users and web services. We develop a system for detecting large-scale attacks on Twitter that identifies 14 million victims of compromise. We examine these accounts to track how attacks spread within social networks and to determine how criminals ultimately realize a profit from hijacked credentials. We find that compromise is a systemic threat, with victims spanning nascent, casual, and core users. Even brief compromises correlate with 21% of victims never returning to Twitter after the service wrests control of a victim's account from criminals. Infections are dominated by social contagions---phishing and malware campaigns that spread along the social graph. These contagions mirror information diffusion and biological diseases, growing in virulence with the number of neighboring infections. Based on the severity of our findings, we argue that early outbreak detection that stems the spread of compromise in 24 hours can spare 70% of victims. Kurt Thomas, Frank Li 0001, Chris Grier, Vern Paxson |
CCS | 2 |
| 2014 | The Matter of HeartbleedabstractThe Heartbleed vulnerability took the Internet by surprise in April 2014. The vulnerability, one of the most consequential since the advent of the commercial Internet, allowed attackers to remotely read protected memory from an estimated 24--55% of popular HTTPS sites. In this work, we perform a comprehensive, measurement-based analysis of the vulnerability's impact, including (1) tracking the vulnerable population, (2) monitoring patching behavior over time, (3) assessing the impact on the HTTPS certificate ecosystem, and (4) exposing real attacks that attempted to exploit the bug. Furthermore, we conduct a large-scale vulnerability notification experiment involving 150,000 hosts and observe a nearly 50% increase in patching by notified hosts. Drawing upon these analyses, we discuss what went well and what went poorly, in an effort to understand how the technical community can respond more effectively to such events in the future. Zakir Durumeric, James Kasten, David Adrian, J. Alex Halderman, Michael D. Bailey, Frank Li 0001, Nicholas Weaver, Johanna Amann, Jethro G. Beekman, Mathias Payer, Vern Paxson |
Internet Measurement Conference | 6 |
| 2013 | Data-Confined HTML5 Applications
Devdatta Akhawe, Frank Li 0001, Warren He, Prateek Saxena, Dawn Song |
ESORICS | 2 |
| 2013 | An Ideal-Security Protocol for Order-Preserving EncodingabstractOrder-preserving encryption - an encryption scheme where the sort order of ciphertexts matches the sort order of the corresponding plaintexts - allows databases and other applications to process queries involving order over encrypted data efficiently. The ideal security guarantee for order-preserving encryption put forth in the literature is for the ciphertexts to reveal no information about the plaintexts besides order. Even though more than a dozen schemes were proposed, all these schemes leak more information than order. This paper presents the first order-preserving scheme that achieves ideal security. Our main technique is mutable ciphertexts, meaning that over time, the ciphertexts for a small number of plaintext values change, and we prove that mutable ciphertexts are needed for ideal security. Our resulting protocol is interactive, with a small number of interactions. We implemented our scheme and evaluated it on microbenchmarks and in the context of an encrypted MySQL database application. We show that in addition to providing ideal security, our scheme achieves 1 - 2 orders of magnitude higher performance than the state-of-the-art order-preserving encryption scheme, which is less secure than our scheme. Raluca A. Popa, Frank Li 0001, Nickolai Zeldovich |
IEEE Symposium on Security and Privacy | 2 |
| 2011 | Privacy and accountability for location-based aggregate statisticsabstractA significant and growing class of location-based mobile applications aggregate position data from individual devices at a server and compute aggregate statistics over these position streams. Because these devices can be linked to the movement of individuals, there is significant danger that the aggregate computation will violate the location privacy of individuals. This paper develops and evaluates PrivStats, a system for computing aggregate statistics over location data that simultaneously achieves two properties: first, provable guarantees on location privacy even in the face of any side information about users known to the server, and second, privacy-preserving accountability (i.e., protection against abusive clients uploading large amounts of spurious data). PrivStats achieves these properties using a new protocol for uploading and aggregating data anonymously as well as an efficient zero-knowledge proof of knowledge protocol we developed from scratch for accountability. We implemented our system on Nexus One smartphones and commodity servers. Our experimental results demonstrate that PrivStats is a practical system: computing a common aggregate (e.g., count) over the data of 10,000 clients takes less than 0.46 s at the server and the protocol has modest latency (0.6 s) to upload data from a Nexus phone. We also validated our protocols on real driver traces from the CarTel project. Raluca A. Popa, Andrew J. Blumberg, Hari Balakrishnan, Frank Li 0001 |
CCS | 4 |