VLDB 2026 Research / reviewers in the wild / expert
Daniel J. Dubois
dblp:69/7759
· DBLP profile ↗
24ranked-venue papers
7as first author
13since 2021 · last 2025
0000-0002-8115-898XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 6 since 2021Computer networks · 7 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Echoes of Privacy: Uncovering the Profiling Practices of Voice AssistantsabstractMany companies, including Google, Amazon, and Apple, offer voice assistants as a convenient solution for answering general voice queries and accessing their services. These voice assistants have gained popularity and can be easily accessed through various smart devices such as smartphones, smart speakers, smartwatches, and an increasing array of other devices. However, this convenience comes with potential privacy risks. For instance, while companies vaguely mention in their privacy policies that they may use voice interactions for user profiling, it remains unclear to what extent this profiling occurs and whether voice interactions pose greater privacy risks compared to other interaction modalities. In this paper, we conduct 1171 experiments involving 24530 queries with different personas and interaction modalities during 20 months to characterize how the three most popular voice assistants profile their users. We analyze factors such as labels assigned to users, their accuracy, the time taken to assign these labels, differences between voice and web interactions, and the effectiveness of profiling remediation tools offered by each voice assistant. Our findings reveal that profiling can happen without interaction, can be incorrect and inconsistent at times, may take several days or weeks to change, and is affected by the interaction modality. Tina Khezresmaeilzadeh, Elaine Zhu, Kiersten Grieco, Daniel J. Dubois, Konstantinos Psounis, David R. Choffnes |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | Poster: Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE)abstractTo transform cybersecurity and privacy research into a highly integrated, community-wide effort, researchers need a common, rich, representative research infrastructure that meets the needs across all members of the research community, and facilitates reproducible science. USC Information Sciences Institute and Northeastern University are meeting researcher needs, and have been funded by the NSF mid-scale research infrastructure program to build Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE). SPHERE research infrastructure will offer access to an unprecedented variety of user-configurable hardware, software, and network resources, it will offer six user portals geared toward different populations of users, and it will support reproducible research via a combination of infrastructure services and community engagement activities. Jelena Mirkovic, David M. Balenson, Brian Kocoloski, Geoff Lawler, Chris Tran, Joseph Barnes, Yuri Pradkin, Terry V. Benzel, Srivatsan Ravi, Ganesh Sankaran, Alba Regalado, David R. Choffnes, Daniel J. Dubois, Luis Garcia 0001 |
CCS | 13 |
| 2024 | Fair or Fare? Understanding Automated Transcription Error Bias in Social Media and Videoconferencing PlatformsabstractAs remote work and learning increases in popularity, individuals, especially those with hearing impairments or who speak English as a second language, may depend on automated transcriptions to participate in business, school, entertainment, or basic communication. In this work, we investigate the automated transcription accuracy of seven popular social media and videoconferencing platforms with respect to some personal characteristics of their users, including gender, age, race, first language, speech rate, F0 frequency, and speech readability. We performed this investigation on a new corpus of 194 hours of English monologues by 846 TED talk speakers. Our results show the presence of significant bias, with transcripts less accurate for speakers that are male or non-native English speakers. We also observe differences in accuracy among platforms for different types of speakers. These results indicate that, while platforms have improved their automatic captioning, much work remains to make captions accessible for a wider variety of speakers and listeners. Daniel J. Dubois, Nicole R. Holliday, Kaveh Waddell, David R. Choffnes |
ICWSM | 1 |
| 2024 | IoT Bricks Over v6: Understanding IPv6 Usage in Smart HomesabstractRecent years have seen growing interest and support for IPv6 in residential networks. While nearly all modern networking devices and operating systems support IPv6, it remains unclear how this basic support translates into higher-layer functionality, privacy, and security in consumer IoT devices. In this paper, we present the first comprehensive study of IPv6 usage in smart homes in a testbed equipped with 93 distinct, popular consumer IoT devices. We investigate whether and how they support and use IPv6, focusing on factors such as IPv6 addressing, configuration, DNS and destinations, and privacy and security practices. Tianrui Hu, Daniel J. Dubois, David R. Choffnes |
IMC | 2 |
| 2024 | SunBlock: Cloudless Protection for IoT Systems
Vadim Safronov, Anna Maria Mandalari, Daniel J. Dubois, David R. Choffnes, Hamed Haddadi 0001 |
PAM (2) | 3 |
| 2023 | Understanding Dark Patterns in Home IoT DevicesabstractInternet-of-Things (IoT) devices are ubiquitous, but little attention has been paid to how they may incorporate dark patterns despite consumer protections and privacy concerns arising from their unique access to intimate spaces and always-on capabilities. This paper conducts a systematic investigation of dark patterns in 57 popular, diverse smart home devices. We update manual interaction and annotation methods for the IoT context, then analyze dark pattern frequency across device types, manufacturers, and interaction modalities. We find that dark patterns are pervasive in IoT experiences, but manifest in diverse ways across device traits. Speakers, doorbells, and camera devices contain the most dark patterns, with manufacturers of such devices (Amazon and Google) having the most dark patterns compared to other vendors. We investigate how this distribution impacts the potential for consumer exposure to dark patterns, discuss broader implications for key stakeholders like designers and regulators, and identify opportunities for future dark patterns study. Monica Kowalczyk, Johanna Gunawan, David R. Choffnes, Daniel J. Dubois, Woodrow Hartzog, Christo Wilson |
CHI | 4 |
| 2023 | In the Room Where It Happens: Characterizing Local Communication and Threats in Smart HomesabstractThe network communication between Internet of Things (IoT) devices on the same local network has significant implications for platform and device interoperability, security, privacy, and correctness. Yet, the analysis of local home Wi-Fi network traffic and its associated security and privacy threats have been largely ignored by prior literature, which typically focuses on studying the communication between IoT devices and cloud end-points, or detecting vulnerable IoT devices exposed to the Internet. In this paper, we present a comprehensive and empirical measurement study to shed light on the local communication within a smart home deployment and its threats. We use a unique combination of passive network traffic captures, protocol honeypots, dynamic mobile app analysis, and crowdsourced IoT data from participants to identify and analyze a wide range of device activities on the local network. We then analyze these datasets to characterize local network protocols, security and privacy threats associated with them. Our analysis reveals vulnerable devices, insecure use of network protocols, and sensitive data exposure by IoT devices. We provide evidence of how this information is exfiltrated to remote servers by mobile apps and third-party SDKs, potentially for household fingerprinting, surveillance and cross-device tracking. We make our datasets and analysis publicly available to support further research in this area. Aniketh Girish, Tianrui Hu, Daniel J. Dubois, Srdjan Matic, Danny Yuxing Huang, Serge Egelman, Joel Reardon, Juan Tapiador, David R. Choffnes, Narseo Vallina-Rodriguez |
IMC | 4 |
| 2023 | BehavIoT: Measuring Smart Home IoT Behavior Using Network-Inferred Behavior ModelsabstractSmart home IoT platforms are typically closed systems, meaning that there is poor visibility into device behavior. Understanding device behavior is important not only for determining whether devices are functioning as expected, but also can reveal implications for privacy (e.g., surreptitious audio/video recording), security (e.g., device compromise), and safety (e.g., denial of service on a baby monitor). While there has been some work on identifying devices and a handful of activities, an open question is what is the extent to which we can automatically model the entire behavior of an IoT deployment, and how it changes over time, without any privileged access to IoT devices or platform messages. Tianrui Hu, Daniel J. Dubois, David R. Choffnes |
IMC | 2 |
| 2023 | Tracking, Profiling, and Ad Targeting in the Alexa Echo Smart Speaker EcosystemabstractSmart speakers collect voice commands, which can be used to infer sensitive information about users. Given the potential for privacy harms, there is a need for greater transparency and control over the data collected, used, and shared by smart speaker platforms as well as third party skills supported on them. To bridge this gap, we build a framework to measure data collection, usage, and sharing by the smart speaker platforms. We apply our framework to the Amazon smart speaker ecosystem. Our results show that Amazon and third parties, including advertising and tracking services that are unique to the smart speaker ecosystem, collect smart speaker interaction data. We also find that Amazon processes smart speaker interaction data to infer user interests and uses those inferences to serve targeted ads to users. Smart speaker interaction also leads to ad targeting and as much as 30X higher bids in ad auctions, from third party advertisers. Finally, we find that Amazon's and third party skills' data practices are often not clearly disclosed in their policy documents. Umar Iqbal 0002, Pouneh Nikkhah Bahrami, Rahmadi Trimananda, Hao Cui 0004, Alexander Gamero-Garrido, Daniel J. Dubois, David R. Choffnes, Athina Markopoulou, Franziska Roesner, Zubair Shafiq |
IMC | 6 |
| 2023 | Protected or Porous: A Comparative Analysis of Threat Detection Capability of IoT SafeguardsabstractConsumer Internet of Things (IoT) devices are increasingly common, from smart speakers to security cameras, in homes. Along with their benefits come potential privacy and security threats. To limit these threats a number of commercial services have become available (IoT safeguards). The safeguards claim to provide protection against IoT privacy risks and security threats. However, the effectiveness and the associated privacy risks of these safeguards remains a key open question. In this paper, we investigate the threat detection capabilities of IoT safeguards for the first time. We develop and release an approach for automated safeguards experimentation to reveal their response to common security threats and privacy risks. We perform thousands of automated experiments using popular commercial IoT safeguards when deployed in a large IoT testbed. Our results indicate not only that these devices may be ineffective in preventing risks, but also their cloud interactions and data collection operations may introduce privacy risks for the households that adopt them. Anna Maria Mandalari, Hamed Haddadi 0001, Daniel J. Dubois, David R. Choffnes |
SP | 3 |
| 2022 | ZLeaks: Passive Inference Attacks on Zigbee Based Smart Homes
Narmeen Shafqat, Daniel J. Dubois, David R. Choffnes, Aaron Schulman, Dinesh Bharadia, Aanjhan Ranganathan |
ACNS | 2 |
| 2021 | IoTLS: understanding TLS usage in consumer IoT devicesabstractConsumer IoT devices are becoming increasingly popular, with most leveraging TLS to provide connection security. In this work, we study a large number of TLS-enabled consumer IoT devices to shed light on how effectively they use TLS, in terms of establishing secure connections and correctly validating certificates, and how observed behavior changes over time. To this end, we gather more than two years of TLS network traffic from IoT devices, conduct active probing to test for vulnerabilities, and develop a novel blackbox technique for exploring the trusted root stores in IoT devices by exploiting a side-channel through TLS Alert Messages. We find a wide range of behaviors across devices, with some adopting best security practices but most being vulnerable in one or more of the following ways: use of old/insecure protocol versions and/or ciphersuites, lack of certificate validation, and poor maintenance of root stores. Specifically, we find that at least 8 IoT devices still include distrusted certificates in their root stores, 11/32 devices are vulnerable to TLS interception attacks, and that many devices fail to adopt modern protocol features over time. Our findings motivate the need for IoT manufacturers to audit, upgrade, and maintain their devices' TLS implementations in a consistent and uniform way that safeguards all of their network traffic. Muhammad Talha Paracha, Daniel J. Dubois, Narseo Vallina-Rodriguez, David R. Choffnes |
Internet Measurement Conference | 2 |
| 2021 | Blocking Without Breaking: Identification and Mitigation of Non-Essential IoT TrafficabstractAbstract Despite the prevalence of Internet of Things (IoT) devices, there is little information about the purpose and risks of the Internet traffic these devices generate, and consumers have limited options for controlling those risks. A key open question is whether one can mitigate these risks by automatically blocking some of the Internet connections from IoT devices, without rendering the devices inoperable. In this paper, we address this question by developing a rigorous methodology that relies on automated IoT-device experimentation to reveal which network connections (and the information they expose) are essential, and which are not. We further develop strategies to automatically classify network traffic destinations as either required (i.e., their traffic is essential for devices to work properly) or not, hence allowing firewall rules to block traffic sent to non-required destinations without breaking the functionality of the device. We find that indeed 16 among the 31 devices we tested have at least one blockable non-required destination, with the maximum number of blockable destinations for a device being 11. We further analyze the destination of network traffic and find that all third parties observed in our experiments are blockable, while first and support parties are neither uniformly required or non-required. Finally, we demonstrate the limitations of existing blocklists on IoT traffic, propose a set of guidelines for automatically limiting non-essential IoT traffic, and we develop a prototype system that implements these guidelines. Anna Maria Mandalari, Daniel J. Dubois, Roman Kolcun, Muhammad Talha Paracha, Hamed Haddadi 0001, David R. Choffnes |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | A Haystack Full of Needles: Scalable Detection of IoT Devices in the WildabstractConsumer Internet of Things (IoT) devices are extremely popular, providing users with rich and diverse functionalities, from voice assistants to home appliances. These functionalities often come with significant privacy and security risks, with notable recent large-scale coordinated global attacks disrupting large service providers. Thus, an important first step to address these risks is to know what IoT devices are where in a network. While some limited solutions exist, a key question is whether device discovery can be done by Internet service providers that only see sampled flow statistics. In particular, it is challenging for an ISP to efficiently and effectively track and trace activity from IoT devices deployed by its millions of subscribers---all with sampled network data. Said Jawad Saidi, Anna Maria Mandalari, Roman Kolcun, Hamed Haddadi 0001, Daniel J. Dubois, David R. Choffnes, Georgios Smaragdakis, Anja Feldmann |
Internet Measurement Conference | 5 |
| 2020 | FlowPrint: Semi-Supervised Mobile-App Fingerprinting on Encrypted Network Traffic
Thijs van Ede, Riccardo Bortolameotti, Andrea Continella, Daniel J. Dubois, Martina Lindorfer, David R. Choffnes, Maarten van Steen, Andreas Peter 0001 |
NDSS | 5 |
| 2020 | When Speakers Are All Ears: Characterizing Misactivations of IoT Smart SpeakersabstractAbstract Internet-connected voice-controlled speakers, also known as smart speakers, are increasingly popular due to their convenience for everyday tasks such as asking about the weather forecast or playing music. However, such convenience comes with privacy risks: smart speakers need to constantly listen in order to activate when the “wake word” is spoken, and are known to transmit audio from their environment and record it on cloud servers. In particular, this paper focuses on the privacy risk from smart speaker misactivations, i.e., when they activate, transmit, and/or record audio from their environment when the wake word is not spoken. To enable repeatable, scalable experiments for exposing smart speakers to conversations that do not contain wake words, we turn to playing audio from popular TV shows from diverse genres. After playing two rounds of 134 hours of content from 12 TV shows near popular smart speakers in both the US and in the UK, we observed cases of 0.95 misactivations per hour, or 1.43 times for every 10,000 words spoken, with some devices having 10% of their misactivation durations lasting at least 10 seconds. We characterize the sources of such misactivations and their implications for consumers, and discuss potential mitigations. Daniel J. Dubois, Roman Kolcun, Anna Maria Mandalari, Muhammad Talha Paracha, David R. Choffnes, Hamed Haddadi 0001 |
Proc. Priv. Enhancing Technol. | 1 |
| 2019 | Information Exposure From Consumer IoT Devices: A Multidimensional, Network-Informed Measurement ApproachabstractInternet of Things (IoT) devices are increasingly found in everyday homes, providing useful functionality for devices such as TVs, smart speakers, and video doorbells. Along with their benefits come potential privacy risks, since these devices can communicate information about their users to other parties over the Internet. However, understanding these risks in depth and at scale is difficult due to heterogeneity in devices' user interfaces, protocols, and functionality. Daniel J. Dubois, David R. Choffnes, Anna Maria Mandalari, Roman Kolcun, Hamed Haddadi 0001 |
Internet Measurement Conference | 2 |
| 2018 | Bug Fixes, Improvements, ... and Privacy Leaks - A Longitudinal Study of PII Leaks Across Android App Versions
Martina Lindorfer, Daniel J. Dubois, Ashwin Rao, David R. Choffnes, Narseo Vallina-Rodriguez |
NDSS | 3 |
| 2017 | How to Supercharge the Amazon T2: Observations and SuggestionsabstractCloud service providers adopt a credit system to allow users to obtain periods of performance bursts without additional cost. For example, the Amazon EC2 T2 instance offers low baseline performance and the capability to achieve short periods of high performance using CPU credits. Once a T2 instance is created and assigned some initial credits, while its CPU utilization is above the baseline threshold, there is a transient period where performance is boosted and the assigned CPU credits are used. After all credits are used, the maximum achievable performance drops to baseline. Credits accrue periodically, when the instance utilization is below the baseline threshold. This paper proposes a methodology to increase the performance benefits of T2 by seamlessly extending the duration of the transient period while maintaining high performance. This extension of the high performance transient period is combined with proactive migration to further take advantage of the initially assigned credits. We conduct experiments to demonstrate the benefits of this methodology for both single-tier and multi-tier applications. Feng Yan 0001, Lihua Ren, Daniel J. Dubois, Giuliano Casale, Jiawei Wen, Evgenia Smirni |
CLOUD | 3 |
| 2016 | Model-Driven Application Refactoring to Minimize Deployment Costs in Preemptible Cloud ResourcesabstractPerformance assessment of cloud-based applications requires new methodologies to deal with the complexity of software systems and the variability of cloud resources. In this paper, we address the problem of reducing the total costs for running cloud-based applications while fulfilling service-level objectives (SLOs). To this end, we define an approach to refactor a cloud application in such a way that, when it is deployed, it requires less computational capacity and therefore less resources. We experimented our approach on top of a modified optimal provisioning heuristic designed for preemptible cloud resources and the results show that it reduces deployment costs, up to 60% when compared to the same approach, but without model-driven application refactoring. Daniel J. Dubois, Catia Trubiani, Giuliano Casale |
CLOUD | 1 |
| 2015 | Mycocloud: Elasticity through Self-Organized Service Placement in Decentralized CloudsabstractWe present Mycocloud, a fully self-organized approach to service placement. Mycocloud supports service elasticity within a network of hosts with heterogeneous computational capacity. Mycocloud proposes a completely decentralized algorithm that continuously calculates the dynamic placement of different services on the host nodes, in response to the varying demand for each service, the churn and dynamism of the node set contributing resources to the system, and the changes in the overlay topology. Our simulation results show how Mycocloud provides good performance in terms of convergence rate, response time, system load and network traffic overhead. Daniel J. Dubois, Giuseppe Valetto, Donato Lucia, Elisabetta Di Nitto |
CLOUD | 1 |
| 2015 | Supporting heterogeneous networks and pervasive storage in mobile content-sharing middlewareabstractSharing digital content with others is now an important part of human social activities. Despite the increasing need to share, most sharing operations are not simple. Many applications are not interoperable with others, require an Internet connection, or require cumbersome configuration and coordination efforts. Our idea is to simplify digital content sharing on mobile devices by providing support for self-organizing heterogeneous networks and pervasive storage. That is, mobile devices can spontaneously connect to each other over a mixture of different available networks (e.g., 3G/4G, WiFi, Bluetooth, etc.) without requiring an explicit user action of network selection or mandatory Internet access. Moreover, indirect communication can be further augmented by pervasive storage. Mobile devices can store shared content on it, which can later be automatically downloaded by other devices in proximity, thus allowing location-based sharing with minimal coordination even when devices are not in the same location at the same time. This paper shows how these technologies can be incorporated into mobile content-sharing middleware to simplify sharing operations among mobile devices without any modification to commercially available devices or applications. In particular, (i) we provide an implementation of our approach as extension modules for existing content-sharing middleware, (ii) we present two example applications built on top of it, and (iii) we demonstrate our approach through experiments in representative situations. Daniel J. Dubois, Yosuke Bando, Konosuke Watanabe, Arata Miyamoto, Munehiko Sato, William Papper, V. Michael Bove Jr. |
CCNC | 1 |
| 2013 | ShAir: extensible middleware for mobile peer-to-peer resource sharingabstractShAir is a middleware infrastructure that allows mobile applications to share resources of their devices (e.g., data, storage, connectivity, computation) in a transparent way. The goals of ShAir are: (i) abstracting the creation and maintenance of opportunistic delay-tolerant peer-to-peer networks; (ii) being decoupled from the actual hardware and network platform; (iii) extensibility in terms of supported hardware, protocols, and on the type of resources that can be shared; (iv) being capable of self-adapting at run-time; (v) enabling the development of applications that are easier to design, test, and simulate. In this paper we discuss the design, extensibility, and maintainability of the ShAir middleware, and how to use it as a platform for collaborative resource-sharing applications. Finally we show our experience in designing and testing a file-sharing application. Daniel J. Dubois, Yosuke Bando, Konosuke Watanabe, Henry Holtzman |
ESEC/SIGSOFT FSE | 1 |
| 2013 | Understanding gamification mechanisms for software developmentabstractIn this paper we outline the idea to adopt gamification techniques to engage, train, monitor, and motivate all the players involved in the development of complex software artifacts, from the inception to the deployment and maintenance. The paper introduces the concept of gamification and proposes a research approach to understand how its principles may be successfully applied to the process of software development. Applying gamification to software engineering is not as straightforward as it may appear since it has to be casted to the peculiarities of this domain. Existing literature in the area has already recognized the possible use of such technology in the context of software development, however how to design and use gamification in this context is still an open question. This leads to several research challenges which are organized in a fascinating research agenda that is part of the contribution of this paper. Finally, to support the proposed ideas we present a preliminary experiment that shows the effect of gamification on the performance of students involved in a software engineering project. Daniel J. Dubois, Giordano Tamburrelli |
ESEC/SIGSOFT FSE | 1 |