VLDB 2026 Research / reviewers in the wild / expert
Charles V. Wright
dblp:82/4065
· DBLP profile ↗
18ranked-venue papers
10as first author
1since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 9 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
10 papers |
Privacy and data protection · 61% Cryptographic primitives and cryptanalysis · 21% Network security · 18% | |
| Databases, data mining, and information retrieval
1 paper |
Database system architecture and tuning · 100% |
Topics — the 17 heaviest of 18, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security
traffic analysis |
0.4 | 6 | 2009 | Traffic Morphing: An Efficient Defense Against Statistical Traffic Analysis · NDSS 2009 Spot Me if You Can: Uncovering Spoken Phrases in Encrypted VoIP Conversations · SP 2008 Language Identification of Encrypted VoIP Traffic: Alejandra y Roberto or Alice and Bob? · USENIX Security Symposium 2007 |
Privacy and data protection
image privacy |
0.4 | 1 | 2019 | Balancing Image Privacy and Usability with Thumbnail-Preserving Encryption · NDSS 2019 |
Privacy and data protection › image privacy
thumbnail-preserving encryption |
0.4 | 1 | 2019 | Balancing Image Privacy and Usability with Thumbnail-Preserving Encryption · NDSS 2019 |
Privacy and data protection
inference attack |
0.2 | 1 | 2016 | The Shadow Nemesis: Inference Attacks on Efficiently Deployable, Efficiently Searchable Encryption · CCS 2016 |
Cryptographic primitives and cryptanalysis
searchable encryption |
0.2 | 1 | 2016 | The Shadow Nemesis: Inference Attacks on Efficiently Deployable, Efficiently Searchable Encryption · CCS 2016 |
Database system architecture and tuning › database security
encrypted database |
0.2 | 1 | 2015 | Inference Attacks on Property-Preserving Encrypted Databases · CCS 2015 |
Cryptographic primitives and cryptanalysis › encryption
property-preserving encryption |
0.2 | 1 | 2015 | Inference Attacks on Property-Preserving Encrypted Databases · CCS 2015 |
Privacy and data protection
anonymization |
0.1 | 3 | 2008 | Playing Devil's Advocate: Inferring Sensitive Information from Anonymized Network Traces · NDSS 2007 Taming the Devil: Techniques for Evaluating Anonymized Network Data · NDSS 2008 On Web Browsing Privacy in Anonymized NetFlows · USENIX Security Symposium 2007 |
Cryptographic primitives and cryptanalysis
encryption |
0.1 | 1 | 2019 | Balancing Image Privacy and Usability with Thumbnail-Preserving Encryption · NDSS 2019 |
Privacy and data protection › inference attack
leakage-abuse attack |
0.1 | 1 | 2016 | The Shadow Nemesis: Inference Attacks on Efficiently Deployable, Efficiently Searchable Encryption · CCS 2016 |
Privacy and data protection › web privacy
browser privacy |
0.1 | 1 | 2007 | On Web Browsing Privacy in Anonymized NetFlows · USENIX Security Symposium 2007 |
Privacy and data protection › de-anonymization
deanonymization of network traces |
0.1 | 1 | 2007 | Playing Devil's Advocate: Inferring Sensitive Information from Anonymized Network Traces · NDSS 2007 |
Network security › traffic analysis › encrypted traffic analysis
encrypted traffic classification |
0.1 | 1 | 2006 | On Inferring Application Protocol Behaviors in Encrypted Network Traffic · J. Mach. Learn. Res. 2006 |
Network measurement and analytics
network traces |
0.0 | 2 | 2008 | Taming the Devil: Techniques for Evaluating Anonymized Network Data · NDSS 2008 Playing Devil's Advocate: Inferring Sensitive Information from Anonymized Network Traces · NDSS 2007 |
Network security › anonymity networks
traffic morphing |
0.0 | 1 | 2009 | Traffic Morphing: An Efficient Defense Against Statistical Traffic Analysis · NDSS 2009 |
Privacy and data protection
communication privacy |
0.0 | 1 | 2007 | Language Identification of Encrypted VoIP Traffic: Alejandra y Roberto or Alice and Bob? · USENIX Security Symposium 2007 |
Network measurement and analytics
traffic characterization |
0.0 | 1 | 2006 | On Inferring Application Protocol Behaviors in Encrypted Network Traffic · J. Mach. Learn. Res. 2006 |
Methods — techniques the papers use, named apart from their topics
frequency analysis · 0.4combinatorial optimization · 0.4statistical inference · 0.2evaluation techniques · 0.2packet size and timing features · 0.1machine learning classification · 0.1speech corpus analysis · 0.1netflow analysis · 0.1machine learning · 0.1inference attacks · 0.1inference attack · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | On the (Im)Practicality of Adversarial Perturbation for Image PrivacyabstractAbstract Image hosting platforms are a popular way to store and share images with family members and friends. However, such platforms typically have full access to images raising privacy concerns. These concerns are further exacerbated with the advent of Convolutional Neural Networks (CNNs) that can be trained on available images to automatically detect and recognize faces with high accuracy. Recently, adversarial perturbations have been proposed as a potential defense against automated recognition and classification of images by CNNs. In this paper, we explore the practicality of adversarial perturbation-based approaches as a privacy defense against automated face recognition. Specifically, we first identify practical requirements for such approaches and then propose two practical adversarial perturbation approaches – (i) learned universal ensemble perturbations (UEP), and (ii) k-randomized transparent image overlays (k-RTIO) that are semantic adversarial perturbations. We demonstrate how users can generate effective transferable perturbations under realistic assumptions with less effort. We evaluate the proposed methods against state-of-theart online and offline face recognition models, Clarifai.com and DeepFace, respectively. Our findings show that UEP and k-RTIO respectively achieve more than 85% and 90% success against face recognition models. Additionally, we explore potential countermeasures that classifiers can use to thwart the proposed defenses. Particularly, we demonstrate one effective countermeasure against UEP. Arezoo Rajabi, Rakesh Bobba, Mike Rosulek, Charles V. Wright, Wu-chi Feng |
Proc. Priv. Enhancing Technol. | 4 |
| 2019 | The Strength of Weak Randomization: Easily Deployable, Efficiently Searchable Encryption with Minimal LeakageabstractEfficiently searchable and easily deployable encryption schemes enable an untrusted, legacy service such as a relational database engine to perform searches over encrypted data. The ease with which such schemes can be deployed on top of existing services makes them especially appealing in operational environments where encryption is needed but it is not feasible to replace large infrastructure components like databases or document management systems. Unfortunately all previously known approaches for efficiently searchable and easily deployable encryption are vulnerable to inference attacks where an adversary can use knowledge of the distribution of the data to recover the plaintext with high probability. We present a new efficiently searchable, easily deployable database encryption scheme that is provably secure against inference attacks even when used with real, low-entropy data. We implemented our constructions in Haskell and tested databases up to 10 million records showing our construction properly balances security, deployability and performance. David Pouliot, Scott Griffy, Charles V. Wright |
DSN | 3 |
| 2019 | Balancing Image Privacy and Usability with Thumbnail-Preserving Encryption
Kimia Tajik, Akshith Gunasekaran, Rhea Dutta, Brandon Ellis, Rakesh Bobba, Mike Rosulek, Charles V. Wright, Wu-chi Feng |
NDSS | 7 |
| 2018 | Crypto Crumple Zones: Enabling Limited Access without Mass SurveillanceabstractGovernments around the world are demanding more access to encrypted data, but it has been difficult to build a system that allows the authorities some access without providing unlimited access in practice. In this paper, we present new techniques for maximizing user privacy in jurisdictions that require support for so-called "exceptional access" to encrypted data. In contrast to previous work on this topic (e.g., key escrow), our approach places most of the responsibility for achieving exceptional access on the government, rather than on the users or developers of cryptographic tools. As a result, our constructions are very simple and lightweight, and they can be easily retrofitted onto existing applications and protocols. Critically, we introduce no new third parties, and we add no new messages beyond a single new Diffie-Hellman key exchange in protocols that already use Diffie-Hellman. We present two constructions that make it possible— although arbitrarily expensive—for a government to recover the plaintext for targeted messages. First, our symmetric crumpling technique uses a hash-based proof of work to impose a linear cost on the adversary for each message she wishes to recover. Second, our public key abrasion method uses a novel application of Diffie-Hellman over modular arithmetic groups to create an extremely expensive puzzle that the adversary must solve before she can recover even a single message. Our initial analysis shows that we can impose an upfront cost in the range of $100M to several billion dollars and a linear cost between $1K-$1M per message. We show how our constructions can easily be adapted to common tools including PGP, Signal, SRTP, full-disk encryption, and file-based encryption. Charles V. Wright, Mayank Varia |
EuroS&P | 1 |
| 2016 | The Shadow Nemesis: Inference Attacks on Efficiently Deployable, Efficiently Searchable EncryptionabstractEncrypting Internet communications has been the subject of renewed focus in recent years. In order to add end-to-end encryption to legacy applications without losing the convenience of full-text search, ShadowCrypt and Mimesis Aegis use a new cryptographic technique called "efficiently deployable efficiently searchable encryption" (EDESE) that allows a standard full-text search system to perform searches on encrypted data. Compared to other recent techniques for searching on encrypted data, EDESE schemes leak a great deal of statistical information about the encrypted messages and the keywords they contain. Until now, the practical impact of this leakage has been difficult to quantify. David Pouliot, Charles V. Wright |
CCS | 2 |
| 2015 | Inference Attacks on Property-Preserving Encrypted DatabasesabstractMany encrypted database (EDB) systems have been proposed in the last few years as cloud computing has grown in popularity and data breaches have increased. The state-of-the-art EDB systems for relational databases can handle SQL queries over encrypted data and are competitive with commercial database systems. These systems, most of which are based on the design of CryptDB (SOSP 2011), achieve these properties by making use of property-preserving encryption schemes such as deterministic (DTE) and order- preserving encryption (OPE). In this paper, we study the concrete security provided by such systems. We present a series of attacks that recover the plaintext from DTE- and OPE-encrypted database columns using only the encrypted column and publicly-available auxiliary information. We consider well-known attacks, including frequency analysis and sorting, as well as new attacks based on combinatorial optimization. Muhammad Naveed 0001, Seny Kamara, Charles V. Wright |
CCS | 3 |
| 2015 | Thumbnail-Preserving Encryption for JPEGabstractWith more and more data being stored in the cloud, securing multimedia data is becoming increasingly important. Use of existing encryption methods with cloud services is possible, but makes many web-based applications difficult or impossible to use. In this paper, we propose a new image encryption scheme specially designed to protect JPEG images in cloud photo storage services. Our technique allows efficient reconstruction of an accurate low-resolution thumbnail from the ciphertext image, but aims to prevent the extraction of any more detailed information. This will allow efficient storage and retrieval of image data in the cloud but protect its contents from outside hackers or snooping cloud administrators. Experiments of the proposed approach using an online selfie database show that it can achieve a good balance of privacy, utility, image quality, and file size. Charles V. Wright, Wu-chi Feng, Feng Liu 0015 |
IH&MMSec | 1 |
| 2010 | Generating Client Workloads and High-Fidelity Network Traffic for Controllable, Repeatable Experiments in Computer Security
Charles V. Wright, Christopher Connelly, Timothy M. Braje, Jesse C. Rabek, Lee M. Rossey, Robert K. Cunningham |
RAID | 1 |
| 2010 | Uncovering Spoken Phrases in Encrypted Voice over IP ConversationsabstractAlthough Voice over IP (VoIP) is rapidly being adopted, its security implications are not yet fully understood. Since VoIP calls may traverse untrusted networks, packets should be encrypted to ensure confidentiality. However, we show that it is possible toidentify the phrases spoken within encrypted VoIP callswhen the audio is encoded using variable bit rate codecs. To do so, we train a hidden Markov model using only knowledge of the phonetic pronunciations of words, such as those provided by a dictionary, and search packet sequences for instances of specified phrases. Our approach does not require examples of the speaker’s voice, or even example recordings of the words that make up the target phrase. We evaluate our techniques on a standard speech recognition corpus containing over 2,000 phonetically rich phrases spoken by 630 distinct speakers from across the continental United States. Our results indicate that we can identify phrases within encrypted calls with an average accuracy of 50%, and with accuracy greater than 90% for some phrases. Clearly, such an attack calls into question the efficacy of current VoIP encryption standards. In addition, we examine the impact of various features of the underlying audio on our performance and discuss methods for mitigation. Charles V. Wright, Lucas Ballard, Scott E. Coull, Fabian Monrose, Gerald M. Masson |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2009 | Traffic Morphing: An Efficient Defense Against Statistical Traffic Analysis
Charles V. Wright, Scott E. Coull, Fabian Monrose |
NDSS | 1 |
| 2008 | Taming the Devil: Techniques for Evaluating Anonymized Network Data
Scott E. Coull, Charles V. Wright, Angelos D. Keromytis, Fabian Monrose, Michael K. Reiter |
NDSS | 2 |
| 2008 | Spot Me if You Can: Uncovering Spoken Phrases in Encrypted VoIP ConversationsabstractDespite the rapid adoption of Voice over IP (VoIP), its security implications are not yet fully understood. Since VoIP calls may traverse untrusted networks, packets should be encrypted to ensure confidentiality. However, we show that when the audio is encoded using variable bit rate codecs, the lengths of encrypted VoIP packets can be used to identify the phrases spoken within a call. Our results indicate that a passive observer can identify phrases from a standard speech corpus within encrypted calls with an average accuracy of 50%, and with accuracy greater than 90% for some phrases. Clearly, such an attack calls into question the efficacy of current VoIP encryption standards. In addition, we examine the impact of various features of the underlying audio on our performance and discuss methods for mitigation. Charles V. Wright, Lucas Ballard, Scott E. Coull, Fabian Monrose, Gerald M. Masson |
SP | 1 |
| 2007 | Playing Devil's Advocate: Inferring Sensitive Information from Anonymized Network Traces
Scott E. Coull, Charles V. Wright, Fabian Monrose, Michael P. Collins, Michael K. Reiter |
NDSS | 2 |
| 2007 | On Web Browsing Privacy in Anonymized NetFlows
Scott E. Coull, Michael P. Collins, Charles V. Wright, Fabian Monrose, Michael K. Reiter |
USENIX Security Symposium | 3 |
| 2007 | Language Identification of Encrypted VoIP Traffic: Alejandra y Roberto or Alice and Bob?
Charles V. Wright, Lucas Ballard, Fabian Monrose, Gerald M. Masson |
USENIX Security Symposium | 1 |
| 2006 | Using visual motifs to classify encrypted trafficabstractIn an effort to make robust traffic classification more accessible to human operators, we present visualization techniques for network traffic. Our techniques are based solely on network information that remains intact after application-layer encryption, and so offer a way to visualize traffic "in the dark". Our visualizations clearly illustrate the differences between common application protocols, both in their transient (i.e., time-dependent)and steady-state behavior. We show how these visualizations can be used to assist a human operator to recognize application protocols in unidentified traffic and to verify the results of an automated classifier via visual inspection. In particular, our preliminary results show that we can visually scan almost 45,000 connections in less than one hour and correctly identify known application behaviors. Moreover, using visualizations together with an automated comparison technique based on Dynamic Time Warping of the motifs, we can rapidly develop accurate recognizers for new or previously unknown applications. Charles V. Wright, Fabian Monrose, Gerald M. Masson |
VizSEC | 1 |
| 2006 | On Inferring Application Protocol Behaviors in Encrypted Network TrafficabstractSeveral fundamental security mechanisms for restricting access to network resources rely on the ability of a reference monitor to inspect the contents of traffic as it traverses the network. However, with the increasing popularity of cryptographic protocols, the traditional means of inspecting packet contents to enforce security policies is no longer a viable approach as message contents are concealed by encryption. In this paper, we investigate the extent to which common application protocols can be identified using only the features that remain intact after encryption---namely packet size, timing, and direction. We first present what we believe to be the first exploratory look at protocol identification in encrypted tunnels which carry traffic from many TCP connections simultaneously, using only post-encryption observable features. We then explore the problem of protocol identification in individual encrypted TCP connections, using much less data than in other recent approaches. The results of our evaluation show that our classifiers achieve accuracy greater than 90% for several protocols in aggregate traffic, and, for most protocols, greater than 80% when making fine-grained classifications on single connections. Moreover, perhaps most surprisingly, we show that one can even estimate the number of live connections in certain classes of encrypted tunnels to within, on average, better than 20%. Charles V. Wright, Fabian Monrose, Gerald M. Masson |
J. Mach. Learn. Res. | 1 |
| 2004 | HMM profiles for network traffic classificationabstractWe present techniques for building HMM profiles for network applications using only the packet-level information that remains intact and observable after encryption, namely, packet size and arrival time. Using less information than previously thought possible, we demonstrate classification accuracy close to that of other recent techniques, and show success in classifying a variety of common network applications as observed from real Internet traffic traces. Charles V. Wright, Fabian Monrose, Gerald M. Masson |
VizSEC | 1 |