VLDB 2026 Research / reviewers in the wild / expert
Anupam Das 0001
dblp:84/5118-1
· DBLP profile ↗
47ranked-venue papers
10as first author
29since 2021 · last 2026
0000-0002-8961-9963ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 34 · 8 first-author · 22 since 2021Computer networks · 6 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cross-Boundary Mobile Tracking: Exploring Java-to-JavaScript Information Diffusion in WebViews
Sohom Datta, Michalis Diamantaris, Ahsan Zafar, Junhua Su, Anupam Das 0001, Iasonas Polakis, Alexandros Kapravelos |
NDSS | 5 |
| 2026 | PriVA-C: Defending Voice Assistants from Fingerprinting AttacksabstractVoice assistants have become ubiquitous, yet they remain vulnerable to network traffic fingerprinting attacks that can expose sensitive user information. Existing defenses either impose high overheads or fail against advanced attacks. This paper addresses these issues by introducing and evaluating PriVA-C, a fingerprinting defense mechanism tailored specifically for voice assistants. Unlike prior approaches that treat voice assistant traffic as generic web traffic, we analyze its unique characteristics to design a more effective defense. Our approach prioritizes limiting information leakage rather than targeting specific attack vectors, achieving a significant reduction in attacker accuracy from 89% to 13%. We also propose a more practically deployable version of our defense, which protects only traffic directed to the primary voice assistant domain, reducing attacker accuracy to 19%. We implement a functional prototype using the Alexa SDK, conduct user testing, and assess its performance using real network traffic. Our results demonstrate that our proposed defense effectively mitigates fingerprinting attacks while maintaining low overhead and preserving the user experience. Dilawer Ahmed, Aafaq Sabir, Ahsan Zafar, Anupam Das 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2026 | Privacy by Voice: Designing Usable Privacy Notices for the Voice InterfaceabstractWith the increasing prevalence of voice interfaces, such as smart home assistants, conversational AI, and AR/VR systems, the need for effective privacy and consent mechanisms is more critical than ever. We conducted a mixed-methods study to address the challenges of ensuring effective consent for voice-based data sharing. Through interviews with voice assistant users (n=21), we identify five key design and contextual factors for effective privacy notices: context, control flow, modality, timing, and the voice used for notice delivery. We then prototyped these notices and performed a within-subject user study (n=160) to identify preferred notice designs. We found that the voice used for delivery and timing of the notice are the most critical factors influencing user preferences, with participants favoring notices delivered in the default app voice before data is requested. To our knowledge, this is the first study to design privacy notices specifically for voice-based data sharing in voice interfaces. Our findings contribute valuable insights to the privacy design literature and provide actionable guidance for developers working on emerging voice-driven platforms. Aafaq Sabir, Abhinaya S. B., Dilawer Ahmed, Anupam Das 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2026 | Detecting Stealthy Web Bots: A Behavioral Analysis Framework for OpenWPM AutomationabstractNowadays, Web bots are used extensively for tasks like search engine indexing and security assessments, but they can also facilitate malicious activities such as ad fraud and data theft and many more. However, existing approaches are unable to detect more advanced bots, such as those driven by Selenium or OpenWPM, which can conceal their browser fingerprint and imitate human browsing behaviors. In this paper, we propose a novel technique for identifying advanced bots, specifically those using OpenWPM, through behavioral analysis. Our approach considers four browsing behaviors, including mouse movement, mouse click, keystroke, and scrolling. We employ an ensemble of lightweight classification models trained on behavioral features, which are augmented using unsupervised clustering in a novel way to enhance detection performance. The detection system is designed in a modular fashion, making it resilient to missing behavioral data and independent of platform-specific features or tasks, enabling generalizability across diverse web platforms. The proposed approach achieves an F1-score of 98.8%, presenting a promising solution for detecting OpenWPM bots and other human-mimicking bots with improved precision. Md. Mahedi Hasan Rigan, Md. Shohrab Hossain, Anupam Das 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Same Script, Different Behavior: Characterizing Divergent JavaScript Execution Across Different Device Platforms
Ahsan Zafar, Junhua Su, Sohom Datta, Alexandros Kapravelos, Anupam Das 0001 |
CCS | 5 |
| 2025 | Analyzing Ad Prevalence, Characteristics, and Compliance in Alexa SkillsabstractWith the rapid adoption of smart voice assistants like Amazon Alexa and the potential for more growth with large language model-powered assistants, as well as the introduction of “advertising ID” within Alexa, it is inevitable that advertisements (ads) will become prevalent on such platforms if not already. Although Alexa permits third-party developers to include ads within voice apps (known as “skills”) and enables targeted advertisement through ad identifiers, Alexa also lists an ad policy that restricts ads within skill responses, notifications, or reminders except in defined cases. However, it remains unclear whether all developers comply with these policies or attempt to bypass vetting processes to publish noncompliant ads. This paper presents the first large-scale analysis of advertising on the Alexa platform, examining ad prevalence, characteristics, and adherence to platform policies. We introduce an automated ad detection method using a fine-tuned large language model (LLM) with 88.92% accuracy and, using chain-of-thought (CoT) prompting, achieve 94.52% accuracy in identifying potential policy-violating ads. Analyzing 45,477 Alexa skills, we find that 13.58% include ads or promotional content, with themes such as travel and entertainment. Notably, some ads come from skills by Amazon-promoted agencies like “Vixen Labs” while others are generated by agencies solely focused on voice assistant platforms, such as “Skilled Creative.” Our model identifies approximately 29.18% of ads as possible policy violations. We reported our findings to Amazon, resulting in a bug bounty reward. The proposed system aims to enhance Alexa's vetting by automatically flagging potential ad violations and demonstrates how fine-tuned LLMs can support policy enforcement on voice platforms. Aafaq Sabir, Abhinaya S. B., Dilawer Ahmed, Anupam Das 0001 |
SP | 4 |
| 2025 | Assessing Compliance in Digital Advertising: A Deep Dive into Acceptable Ads StandardsabstractOnline ads provide essential revenue for millions of websites but often disrupt user experience.To address this, browser extensions emerged to block intrusive ads, prompting the creation of the Acceptable Ads Standards to balance user choice and monetization.The Acceptable Ads Standards, initiated by the Acceptable Ads Committee, seek a balance between user experience and ad effectiveness, allowing certain non-intrusive ads defined by size, placement, and type limitations.This paper analyzes the compliance of digital advertisements with the Acceptable Ads standards by examining 10,000 popular domains intersecting Tranco's top 100K and the Acceptable Ads exception list.Our findings reveal that nearly 10% of these sites display non-compliant ads on landing pages, exposing design flaws in the exception list that allow publishers to bypass size and format restrictions.We propose enhancements to the exception list to better uphold user experience and ad integrity. Ahsan Zafar, Anupam Das 0001 |
WWW | 2 |
| 2025 | "What are they gonna do with my data?": Privacy Expectations, Concerns, and Behaviors in Virtual RealityabstractThe immersive nature of Virtual Reality (VR) and its reliance on sensory devices like head-mounted displays introduce privacy risks to users. While earlier research has explored users' privacy concerns within VR environments, less is known about users' comprehension of VR data practices and protective behaviors; the expanding VR market and technological progress also necessitate a fresh evaluation. We conducted semi-structured interviews with 20 VR users, showing their diverse perceptions regarding the types of data collected and their intended purposes. We observed privacy concerns in three dimensions: institutional, social, and device-specific. Our participants sought to protect their privacy through considerations when selecting the device, scrutinizing VR apps, and selective engagement in different VR interactions. We contrast our findings with observations from other technologies and ecosystems, shedding light on how VR has altered the privacy landscape for end-users. We further offer recommendations to alleviate users' privacy concerns, rectify misunderstandings, and encourage the adoption of privacy-conscious behaviors. Abhinaya S. B., Abhishri Agrawal, Yaxing Yao, Yixin Zou, Anupam Das 0001 |
Proc. Priv. Enhancing Technol. | 5 |
| 2025 | Detecting Smart Home Device Activities Using Packet-Level Signatures From Encrypted TrafficabstractDespite the significant benefits of the widespread adoption of smart home Internet of Things (IoT) devices, these devices are known to be vulnerable to active and passive attacks. Existing literature has demonstrated the ability to infer the activities of these devices by analyzing their network traffic. In this study, we introduce a packet-based signature generation and detection system that can identify specific events associated with IoT devices by extracting simple features from raw encrypted network traffic. Unlike existing techniques that depend on specific time windows, our approach automatically determines the optimal number of packets to generate unique signatures, making it more resilient to network jitters. We evaluate the effectiveness, uniqueness, and correctness of our signatures by training and testing our system using four public datasets and an emulated dataset with varying network delays, verifying known signatures and discovering new ones. Our system achieved an average recall and precision of 98-99% and 98-100%, respectively, demonstrating the effectiveness and feasibility of using packet-level signatures to detect IoT device activities. Mohammad Shamim Ahsan, Md. Shohrab Hossain, Anupam Das 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Automated Generation of Behavioral Signatures for Malicious Web Campaigns
Shaown Sarker, William Melicher, Oleksii Starov, Anupam Das 0001, Alexandros Kapravelos |
ISC (2) | 4 |
| 2024 | JSHint: Revealing API Usage to Improve Detection of Malicious JavaScript
Shaown Sarker, Kasimir Schulz, Aleksandr Nahapetyan, Anupam Das 0001, Alexandros Kapravelos |
ISC (2) | 4 |
| 2024 | Privacy Measurement of Physical Attributes on Voice AnonymityabstractVarious methods have been proposed for protecting the speaker's identity while preserving speech intelligibility. However, existing studies fail to consider the overall tradeoff between speech utility, speaker verification, and inference of voice physical attributes, such as emotion, age, accent, and gender. we propose a tradeoff metric to encapsulate voice biometrics as well as different voice attributes, to study the feasibility of applying cutting-edge voice anonymization solutions to achieve the optimum tradeoff between privacy protection and speech utility. Shaohu Zhang, Zhouyu Li, Anupam Das 0001 |
MobiCom | 3 |
| 2024 | Understanding Parents' Perceptions and Practices Toward Children's Security and Privacy in Virtual RealityabstractRecent years have seen a sharp increase in the number of underage users in virtual reality (VR), where security and privacy (S&P) risks such as data surveillance and self-disclosure in social interaction have been increasingly prominent. Prior work shows children largely rely on parents to mitigate S&P risks in their technology use. Therefore, understanding parents’ S&P knowledge, perceptions, and practices is critical for identifying the gaps for parents, technology designers, and policymakers to enhance children’s S&P. While such empirical knowledge is substantial in other consumer technologies, it remains largely unknown in the context of VR. To address the gap, we conducted in-depth semi-structured interviews with 20 parents of children under the age of 18 who use VR at home. Our findings highlight parents generally lack S&P awareness due to the perception that VR is still in its infancy. To protect their children’s interactions with VR, parents currently primarily rely on active strategies such as verbal education about S&P. Passive strategies such as using parental controls in VR are not commonly used among our interviewees, mainly due to their perceived technical constraints. Parents also highlight that a multi-stakeholder ecosystem must be established towards more S&P support for children in VR. Based on the findings, we propose actionable S&P recommendations for critical stakeholders, including parents, educators, VR companies, and governments. Jiaxun Cao, Abhinaya S. B., Anupam Das 0001, Pardis Emami Naeini |
SP | 3 |
| 2024 | Enabling Developers, Protecting Users: Investigating Harassment and Safety in VR
Abhinaya S. B., Aafaq Sabir, Anupam Das 0001 |
USENIX Security Symposium | 3 |
| 2024 | Connecting the Dots: Tracing Data Endpoints in IoT DevicesabstractSmart home devices are constantly exchanging data with a variety of remote endpoints. This data encompasses diverse information, from device operation and status to sensitive user information like behavioral usage patterns. However, there is a lack of transparency regarding where such data goes and with whom it is potentially shared. This paper investigates the diverse endpoints that smart home Internet-of-Things (IoT) devices contact to better understand and reason about the IoT backend infrastructure, thereby providing insights into potential data privacy risks. We analyze data from 5,413 users and 25,123 IoT devices using the IoT Inspector, an open-source application allowing users to monitor traffic from smart home devices on their networks. First, we develop semi-automated techniques to map remote endpoints to organizations and their business types to shed light on their potential relationships with IoT end products. We discover that IoT devices contact more third or support-party domains than first-party domains. We also see that the distribution of contacted endpoints varies based on the user's location and across vendors manufacturing similar functional devices, where some devices are more exposed to third parties than others. Our analysis also reveals the major organizations providing backend support for IoT smart devices and provides insights into the temporal evolution of cross-border data-sharing practices. Md. Jakaria, Danny Yuxing Huang, Anupam Das 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2023 | Comparative Privacy Analysis of Mobile BrowsersabstractOnline trackers are invasive as they track our digital footprints, many of which are sensitive in nature, and when aggregated over time, they can help infer intricate details about our lifestyles and habits. Although much research has been conducted to understand the effectiveness of existing countermeasures for the desktop platform, little is known about how mobile browsers have evolved to handle online trackers. With mobile devices now generating more web traffic than their desktop counterparts, we fill this research gap through a large-scale comparative analysis of mobile web browsers. We crawl 10K valid websites from the Tranco list on real mobile devices. Our data collection process covers both popular generic browsers (e.g., Chrome, Firefox, and Safari) as well as privacy-focused browsers (e.g., Brave, Duck Duck Go, and Firefox-Focus). We use dynamic analysis of runtime execution traces and static analysis of source codes to highlight the tracking behavior of invasive fingerprinters. We also find evidence of tailored content being served to different browsers. In particular, we note that Firefox Focus sees altered script code, whereas Brave and Duck Duck Go have highly similar content. To test the privacy protection of browsers, we measure the responses of each browser in blocking trackers and advertisers and note the strengths and weaknesses of privacy browsers. To establish ground truth, we use well-known block lists, including EasyList, EasyPrivacy, Disconnect and WhoTracksMe and find that Brave generally blocks the highest number of content that should be blocked as per these lists. Focus performs better against social trackers, and Duck Duck Go restricts third-party trackers that perform email-based tracking. Ahsan Zafar, Anupam Das 0001 |
CODASPY | 2 |
| 2023 | Speaker Orientation-Aware Privacy Control to Thwart Misactivation of Voice AssistantsabstractSmart home voice assistants (VAs) such as Amazon Echo and Google Home have become popular because of the convenience they provide through voice commands. VAs continuously listen to detect the wake command and send the subsequent audio data to the manufacturer-owned cloud service for processing to identify actionable commands. However, research has shown that VAs are prone to replay attack and accidental activations when the wake words are spoken in the background (either by a human or played through a mechanical speaker). Existing privacy controls are not effective in preventing such misactivations. This raises privacy and security concerns for the users as their conversations can be recorded and relayed to the cloud without their knowledge. Recent studies have shown that the visual gaze plays an important role when interacting with conservation agents such as VAs, and users tend to turn their heads or body toward the VA when invoking it. In this paper, we propose a device-free, non-obtrusive acoustic sensing system called HeadTalk to thwart the misactivation of VAs. The proposed system leverages the user's head direction information and verifies that a human generates the sound to minimize accidental activations. Our extensive evaluation shows that HeadTalk can accurately infer a speaker's head orientation with an average accuracy of 96.14% and distinguish human voice from a mechanical speaker with an equal error rate of 2.58%. We also conduct a user interaction study to assess how users perceive our proposed approach compared to existing privacy controls. Our results suggest that HeadTalk can not only enhance the security and privacy controls for VAs but do so in a usable way without requiring any additional hardware. Shaohu Zhang, Aafaq Sabir, Anupam Das 0001 |
DSN | 3 |
| 2023 | INSPIRE: Instance-Level Privacy-Pre Serving Transformation for Vehicular Camera VideosabstractThe wide spread of vehicular cameras has raised broad privacy concerns. Ubiquitous vehicular cameras capture bystanders like people or cars nearby without their awareness. To address privacy concerns, most existing works either blur out direct identifiers such as vehicle license plates and human faces, or obfuscate whole video frames. However, the former solution is vulnerable to re-identification attacks based on general features, and the latter severely impacts utility of the transformed videos. In this paper, we propose an INStance-level PrIvacy-pREserving (INSPIRE) video transformation framework for vehicular camera videos. INSPIRE leverages deep neural network models to detect and replace sensitive object instances in vehicular videos with their non-existent counterparts. We design INSPIRE as a modular framework to enable flexible customization of protected instance categories and their protection modules. An implementation of INSPIRE focused on protecting people and cars is described, which we tested on six re-identification datasets and three real-world vehicular video datasets to evaluate its privacy protection and utility preservation capability. Results show that INSPIRE can thwart 97% of re-identification attacks for people and cars while maintaining a 0.75 object detection mean average precision on transformed instances. We also demonstrate experimentally that INSPIRE is robust against model inversion attacks. Compared to solutions that provide comparable privacy protection, INSPIRE achieves relatively 1.76 times higher counting accuracy and 31.61% higher object detection mean average precision. Zhouyu Li, Ruozhou Yu, Anupam Das 0001, Shaohu Zhang, Huayue Gu, Fangtong Zhou, Aafaq Sabir, Dilawer Ahmed, Ahsan Zafar |
ICCCN | 3 |
| 2023 | Spying through Your Voice Assistants: Realistic Voice Command Fingerprinting
Dilawer Ahmed, Aafaq Sabir, Anupam Das 0001 |
USENIX Security Symposium | 3 |
| 2023 | VoicePM: A Robust Privacy Measurement on Voice AnonymityabstractVoice-based human-computer interaction has become pervasive in laptops, smartphones, home voice assistants, and Internet of Thing (IoT) devices. However, voice interaction comes with security and privacy risks. Numerous privacy-preserving measures have been proposed for hiding the speaker's identity while maintaining speech intelligibility. However, existing works do not consider the overall tradeoff between speech utility, speaker verification, and inference of voice attributes, including emotional state, age, accent, and gender. In this study, we first develop a tradeoff metric to capture voice biometrics as well as different voice attributes. We then propose VoicePM, a robust Voice Privacy Measurement framework, to study the feasibility of applying different state-of-the-art voice anonymization solutions to achieve the optimum tradeoff between privacy and utility. We conduct extensive experiments using anonymization approaches covering signal processing, voice synthesis, voice conversion, and adversarial techniques on three speech datasets that include both English and Chinese speakers to showcase the effectiveness and feasibility of VoicePM. Shaohu Zhang, Zhouyu Li, Anupam Das 0001 |
WISEC | 3 |
| 2022 | Hey Alexa, Who Am I Talking to?: Analyzing Users' Perception and Awareness Regarding Third-party Alexa SkillsabstractThe Amazon Alexa voice assistant provides convenience through automation and control of smart home appliances using voice commands. Amazon allows third-party applications known as skills to run on top of Alexa to further extend Alexa’s capability. However, as multiple skills can share the same invocation phrase and request access to sensitive user data, growing security and privacy concerns surround third-party skills. In this paper, we study the availability and effectiveness of existing security indicators or a lack thereof to help users properly comprehend the risk of interacting with different types of skills. We conduct an interactive user study (inviting active users of Amazon Alexa) where participants listen to and interact with real-world skills using the official Alexa app. We find that most participants fail to identify the skill developer correctly (i.e., they assume Amazon also develops the third-party skills) and cannot correctly determine which skills will be automatically activated through the voice interface. We also propose and evaluate a few voice-based skill type indicators, showcasing how users would benefit from such voice-based indicators. Aafaq Sabir, Evan Lafontaine, Anupam Das 0001 |
CHI | 3 |
| 2022 | Analyzing the Impact and Accuracy of Facebook Activity on Facebook's Ad-Interest Inference ProcessabstractSocial media platforms like Facebook have become increasingly popular for serving targeted ads to their users. This has led to increased privacy concerns due to the lack of transparency regarding how ads are matched against each user profile. Facebook infers user interests through their activities and targets ads based on those interests. Although Facebook provides explanations for why a particular interest is inferred about a user, there is still a gap in understanding what activities lead to interest inferences and the extent to which the sentiment or context of activities is considered in inferring interests. To obtain insights into how Facebook generates interests from a user's Facebook activities, we performed controlled experiments by creating new accounts and systematically executing numerous planned activities. This enabled us to make causal inferences about activities that lead to generating specific interests, many of which were not representative of actual user preferences. We also evaluated which activities resulted in interests and found that very naive activities, such as only viewing/scrolling through a page, lead to an interest inference. We found 33.22% of the inferred interests were inaccurate or irrelevant. We further evaluated the interest inference explanations provided by Facebook and found that these explanations were too generalized and, at times, misleading. To understand if our findings hold for a large and diverse sample, we conducted a user study where we recruited 146 participants (through Amazon Mechanical Turk) from different regions of the world to evaluate the accuracy of interests inferred by Facebook. We developed a browser extension to extract data from their own Facebook accounts and ask questions based on such data. Our participants reported a similar range (29%) of inaccuracy as observed in our controlled experiments. We also found that most of our participants were unaware of the availability of Facebook's ad preference manager, interest inference process, and even interest explanations. Aafaq Sabir, Evan Lafontaine, Anupam Das 0001 |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | Analyzing the Feasibility and Generalizability of Fingerprinting Internet of Things DevicesabstractAbstract In recent years, we have seen rapid growth in the use and adoption of Internet of Things (IoT) devices. However, some loT devices are sensitive in nature, and simply knowing what devices a user owns can have security and privacy implications. Researchers have, therefore, looked at fingerprinting loT devices and their activities from encrypted network traffic. In this paper, we analyze the feasibility of fingerprinting IoT devices and evaluate the robustness of such fingerprinting approach across multiple independent datasets — collected under different settings. We show that not only is it possible to effectively fingerprint 188 loT devices (with over 97% accuracy), but also to do so even with multiple instances of the same make-and-model device. We also analyze the extent to which temporal, spatial and data-collection-methodology differences impact fingerprinting accuracy. Our analysis sheds light on features that are more robust against varying conditions. Lastly, we comprehensively analyze the performance of our approach under an open-world setting and propose ways in which an adversary can enhance their odds of inferring additional information about unseen devices (e.g., similar devices manufactured by the same company). Dilawer Ahmed, Anupam Das 0001, Fareed Zaffar |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Understanding the Privacy Implications of Adblock Plus's Acceptable AdsabstractTargeted advertisement is prevalent on the Web. Many privacy-enhancing tools have been developed to thwart targeted advertisement. Adblock Plus is one such popular tool, used by millions of users on a daily basis, to block unwanted ads and trackers. Adblock Plus uses EasyList and EasyPrivacy, the most prominent and widely used open-source filters, to block unwanted web contents. However, Adblock Plus, by default, also enables an exception list to unblock web requests that comply with specific guidelines defined by the Acceptable Ads Committee. Any publisher can enroll into the Acceptable Ads initiative to request the unblocking of web contents. Adblock Plus in return charges a licensing fee from large entities, who gain a significant amount of ad impressions per month due to participation in the Acceptable Ads initiative. However, the privacy implications of the default inclusion of the exception list has not been well studied, especially as it can unblock not only ads, but also trackers (e.g., unblocking contents otherwise blocked by EasyPrivacy). Ahsan Zafar, Aafaq Sabir, Dilawer Ahmed, Anupam Das 0001 |
AsiaCCS | 4 |
| 2021 | Privacy during Pandemic: A Global View of Privacy Practices around COVID-19 AppsabstractA large number of mobile phone applications have been built and deployed to combat COVID-19, offering various services to users, including virus information, contact tracing, and symptom monitoring among others. At the same time, the privacy and security vulnerabilities of user data over these apps have become a big concern in many places. To examine this issue, we conducted a mixed-method study with a combined approach of app analysis and an online survey to understand the privacy vulnerabilities of such apps and get an overview of user perceptions around this issue. In addition, we considered the notion of privacy in two different socio-economic contexts (Global North and Global South) to specify similarities and differences in app-specific privacy functionalities (data practices, functional requirements, regulations, etc.) and identify factors that impacted users’ decision to use such apps (such as trust, preferences, concerns, motivations, etc.). Thus, this paper presents two diverse sets of opinions from these two geographic regions (including 27 countries), which provide a broader understanding of how the privacy concerns around COVID-19 are connected to various economic, political, and social factors. Furthermore, our analysis of 39 apps provides a deep insight into what many COVID-19 apps are lacking to ensure proper privacy practices and how those issues are entangled with various contextual challenges. Tanusree Sharma, Md. Mirajul Islam, Anupam Das 0001, S. M. Taiabul Haque, Syed Ishtiaque Ahmed |
COMPASS | 3 |
| 2021 | A 2-FA for home voice assistants using inaudible acoustic signalabstractVoice assistants have been shown to be vulnerable to replay attacks, impersonation attacks and inaudible voice commands. Existing defenses do not provide a practical solution as they either rely on external hardware or work under very constrained settings. We introduce a hand gesture-based authentication system for smart home voice assistants called HandLock, which uses built-in microphones and speakers to generate and sense inaudible acoustic signals to detect the presence of a known hand gesture. Our proposed approach can act as a second-factor authentication (2-FA) for performing specific sensitive operations like confirming online purchases through voice assistants. The experiments involving 45 participants show that HandLock can achieve on average 96.51% true-positive-rate at the expense of 0.82% false-acceptance-rate. Shaohu Zhang, Anupam Das 0001 |
MobiCom | 2 |
| 2021 | Hey Alexa, is this Skill Safe?: Taking a Closer Look at the Alexa Skill Ecosystem
Christopher Lentzsch, Sheel Jayesh Shah, Benjamin Andow, Martin Degeling, Anupam Das 0001, William Enck |
NDSS | 5 |
| 2021 | HandLock: Enabling 2-FA for Smart Home Voice Assistants using Inaudible Acoustic SignalabstractThe use of voice-control technology has become mainstream and is growing worldwide. While voice assistants provide convenience through automation and control of home appliances, the open nature of the voice channel makes voice assistants difficult to secure. As a result voice assistants have been shown to be vulnerable to replay attacks, impersonation attacks and inaudible voice commands. Existing defenses do not provide a practical solution as they either rely on external hardware (e.g., motion sensors) or work under very constrained settings (e.g., holding the device close to a user’s mouth). We introduce the concept of using a gesture-based authentication system for smart home voice assistants called HandLock, which uses built-in microphones and speakers to generate and sense inaudible acoustic signals to detect the presence of a known (i.e., authorized) hand gesture. Our proposed approach can act as a second-factor authentication (2-FA) for performing specific sensitive operations like confirming online purchases through voice assistants. Through extensive experiments involving 45 participants, we show that HandLock can achieve on average 96.51% true-positive-rate (TPR) at the expense of 0.82% false-acceptance-rate (FAR). We perform a comprehensive analysis of HandLock under various settings to showcase its accuracy, stability, resilience to attacks, and usability. Our analysis shows that HandLock can not only successfully thwart impersonation attacks, but can do so while incurring very low overheads and is compatible with modern voice assistants. Shaohu Zhang, Anupam Das 0001 |
RAID | 2 |
| 2021 | "Did you know this camera tracks your mood?": Understanding Privacy Expectations and Preferences in the Age of Video AnalyticsabstractAbstract Cameras are everywhere, and are increasingly coupled with video analytics software that can identify our face, track our mood, recognize what we are doing, and more. We present the results of a 10-day in-situ study designed to understand how people feel about these capabilities, looking both at the extent to which they expect to encounter them as part of their everyday activities and at how comfortable they are with the presence of such technologies across a range of realistic scenarios. Results indicate that while some widespread deployments are expected by many (e.g., surveillance in public spaces), others are not, with some making people feel particularly uncomfortable. Our results further show that individuals’ privacy preferences and expectations are complicated and vary with a number of factors such as the purpose for which footage is captured and analyzed, the particular venue where it is captured, and whom it is shared with. Finally, we discuss the implications of people’s rich and diverse preferences on opt-in or opt-out rights for the collection and use (including sharing) of data associated with these video analytics scenarios as mandated by regulations. Because of the user burden associated with the large number of privacy decisions people could be faced with, we discuss how new types of privacy assistants could possibly be configured to help people manage these decisions. Shikun Zhang, Yuanyuan Feng, Lujo Bauer, Lorrie Faith Cranor, Anupam Das 0001, Norman M. Sadeh |
Proc. Priv. Enhancing Technol. | 5 |
| 2018 | The Web's Sixth Sense: A Study of Scripts Accessing Smartphone SensorsabstractWe present the first large-scale measurement of smartphone sensor API usage and stateless tracking on the mobile web. We extend the OpenWPM web privacy measurement tool to develop OpenWPM-Mobile, adding the ability to emulate plausible sensor values for different smartphone sensors such as motion, orientation, proximity and light. Using OpenWPM-Mobile we find that one or more sensor APIs are accessed on 3695 of the top 100K websites by scripts originating from 603 distinct domains. We also detect fingerprinting attempts on mobile platforms, using techniques previously applied in the desktop setting. We find significant overlap between fingerprinting scripts and scripts accessing sensor data. For example, 63% of the scripts that access motion sensors also engage in browser fingerprinting. To better understand the real-world uses of sensor APIs, we cluster JavaScript programs that access device sensors and then perform automated code comparison and manual analysis. We find a significant disparity between the actual and intended use cases of device sensor as drafted by W3C. While some scripts access sensor data to enhance user experience, such as orientation detection and gesture recognition, tracking and analytics are the most common use cases among the scripts we analyzed. We automated the detection of sensor data exfiltration and observed that the raw readings are frequently sent to remote servers for further analysis. Finally, we evaluate available countermeasures against the misuse of sensor APIs. We find that popular tracking protection lists such as EasyList and Disconnect commonly fail to block most tracking scripts that misuse sensors. Studying nine popular mobile browsers we find that even privacy-focused browsers, such as Brave and Firefox Focus, fail to implement mitigations suggested by W3C, which includes limiting sensor access from insecure contexts and cross-origin iframes. We have reported these issues to the browser vendors. Anupam Das 0001, Gunes Acar, Nikita Borisov, Amogh Pradeep |
CCS | 1 |
| 2018 | Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site Scripting
William Melicher, Anupam Das 0001, Mahmood Sharif, Lujo Bauer, Limin Jia 0001 |
NDSS | 2 |
| 2018 | Every Move You Make: Exploring Practical Issues in Smartphone Motion Sensor Fingerprinting and CountermeasuresabstractAbstract The ability to track users’ activities across different websites and visits is a key tool in advertising and surveillance. The HTML5 DeviceMotion interface creates a new opportunity for such tracking via fingerprinting of smartphone motion sensors. We study the feasibility of carrying out such fingerprinting under real-world constraints and on a large scale. In particular, we collect measurements from several hundred users under realistic scenarios and show that the state-of-the-art techniques provide very low accuracy in these settings. We then improve fingerprinting accuracy by changing the classifier as well as incorporating auxiliary information. We also show how to perform fingerprinting in an open-world scenario where one must distinguish between known and previously unseen users. We next consider the problem of developing fingerprinting countermeasures; we evaluate the usability of a previously proposed obfuscation technique and a newly developed quantization technique via a large-scale user study. We find that both techniques are able to drastically reduce fingerprinting accuracy without significantly impacting the utility of the sensors in web applications. Anupam Das 0001, Nikita Borisov, Edward Chou |
Proc. Priv. Enhancing Technol. | 1 |
| 2018 | Enabling Live Video Analytics with a Scalable and Privacy-Aware FrameworkabstractWe show how to build the components of a privacy-aware, live video analytics ecosystem from the bottom up, starting with OpenFace, our new open-source face recognition system that approaches state-of-the-art accuracy. Integrating OpenFace with interframe tracking, we build RTFace, a mechanism for denaturing video streams that selectively blurs faces according to specified policies at full frame rates. This enables privacy management for live video analytics while providing a secure approach for handling retrospective policy exceptions. Finally, we present a scalable, privacy-aware architecture for large camera networks using RTFace and show how it can be an enabler for a vibrant ecosystem and marketplace of privacy-aware video streams and analytics services. Brandon Amos, Anupam Das 0001, Padmanabhan Pillai, Norman M. Sadeh, Mahadev Satyanarayanan |
ACM Trans. Multim. Comput. Commun. Appl. | 3 |
| 2017 | Every Move You Make: Tracking Smartphone Users through Motion SensorsabstractOnline users are increasingly being subjected to privacy-invasive tracking across the web for advertisement and surveillance purposes, using IP addresses, cookies, and browser fingerprinting. As web browsing activity shifts to mobile platforms such as smartphones, traditional browser fingerprinting techniques become less effective due to ephemeral IP addresses and uniform software-base. However, device fingerprinting using built-in sensors offers a new avenue for attack. In this talk, I will describe how motion sensors such as accelerometer and gyroscope, embedded in smartphones, can be exploited to track users online. Next, I will discuss the practical aspects of this attack and how it can be used to track users across different sessions under natural web browsing settings. Finally, I will talk about usable countermeasures that we have developed to protect users against such fingerprinting techniques. Anupam Das 0001 |
IH&MMSec | 1 |
| 2017 | Password correlation: Quantification, evaluation and applicationabstractIn this paper, we study the correlation between passwords across different datasets which quantitatively explains the success of existing training-based password cracking techniques. We also study the correlation between a user's password and his/her social profile. This enabled us to develop the first social profile-aware password strength meter, namely SociaLShield. Our quantification techniques and SocialShield have meaningful implications to system administrators, users, and researchers, e.g., helping them quantitatively understand the threats posed by a password leakage incident, defending against emerging profile-based password attacks, and facilitating the research of countermeasures against existing and newly developed training-based password attacks. We validate our proposed quantification techniques and SocialShield through extensive experiments by leveraging real-world leaked passwords. Experimental results demonstrate that our quantification techniques are accurate in measuring correlation among different leaked datasets and that although SocialShield is light-weight, it is effective in defending against profile-based password attacks. Shouling Ji, Shukun Yang, Anupam Das 0001, Xin Hu 0001, Raheem A. Beyah |
INFOCOM | 3 |
| 2017 | A Scalable and Privacy-Aware IoT Service for Live Video AnalyticsabstractWe present OpenFace, our new open-source face recognition system that approaches state-of-the-art accuracy. Integrating OpenFace with inter-frame tracking, we build RTFace, a mechanism for denaturing video streams that selectively blurs faces according to specified policies at full frame rates. This enables privacy management for live video analytics while providing a secure approach for handling retrospective policy exceptions. Finally, we present a scalable, privacy-aware architecture for large camera networks using RTFace. Brandon Amos, Anupam Das 0001, Padmanabhan Pillai, Norman M. Sadeh, Mahadev Satyanarayanan |
MMSys | 3 |
| 2017 | Mining on Someone Else's Dime: Mitigating Covert Mining Operations in Clouds and Enterprises
Rashid Tahir, Muhammad Huzaifa, Anupam Das 0001, Mohammad Ahmad, Carl A. Gunter, Fareed Zaffar, Matthew Caesar 0001, Nikita Borisov |
RAID | 3 |
| 2017 | Some Recipes Can Do More Than Spoil Your Appetite: Analyzing the Security and Privacy Risks of IFTTT RecipesabstractThe use of end-user programming, such as if-this-then-that (IFTTT), is becoming increasingly common. Services like IFTTT allow users to easily create new functionality by connecting arbitrary Internet-of-Things (IoT) devices and online services using simple if-then rules, commonly known as recipes. However, such convenience at times comes at the cost of security and privacy risks for end users. To gain an in-depth understanding of the potential security and privacy risks, we build an information-flow model to analyze how often IFTTT recipes involve potential integrity or secrecy violations. Our analysis finds that around 50% of the 19,323 unique recipes we examined are potentially unsafe, as they contain a secrecy violation, an integrity violation, or both. We next categorize the types of harm that these potentially unsafe recipes can cause to users. After manually examining a random selection of potentially unsafe recipes, we find that recipes can not only lead to harms such as personal embarrassment but can also be exploited by an attacker, e.g., to distribute malware or carry out denial-of-service attacks. The use of IoT devices and services like IFTTT is expected only to grow in the near future; our analysis suggests users need to be both informed about and protected from these emerging threats to which they could be unwittingly exposing themselves. Milijana Surbatovich, Jassim Aljuraidan, Lujo Bauer, Anupam Das 0001, Limin Jia 0001 |
WWW | 4 |
| 2016 | Tracking Mobile Web Users Through Motion Sensors: Attacks and Defenses
Anupam Das 0001, Nikita Borisov, Matthew Caesar 0001 |
NDSS | 1 |
| 2015 | Defending Tor from Network Adversaries: A Case Study of Network Path PredictionabstractAbstract The Tor anonymity network has been shown vulnerable to traffic analysis attacks by autonomous systems (ASes) and Internet exchanges (IXes), which can observe different overlay hops belonging to the same circuit. We evaluate whether network path prediction techniques provide an accurate picture of the threat from such adversaries, and whether they can be used to avoid this threat. We perform a measurement study by collecting 17.2 million traceroutes from Tor relays to destinations around the Internet. We compare the collected traceroute paths to predicted paths using state-of-the-art path inference techniques. We find that traceroutes present a very different picture, with the set of ASes seen in the traceroute path differing from the predicted path 80% of the time. We also consider the impact that prediction errors have on Tor security. Using a simulator to choose paths over a week, our traceroutes indicate a user has nearly a 100% chance of at least one compromise in a week with 11% of total paths containing an AS compromise and less than 1% containing an IX compromise when using default Tor selection. We find modifying the path selection to choose paths predicted to be safe lowers total paths with an AS compromise to 0.14% but still presents a 5–11% chance of at least one compromise in a week while making 5% of paths fail, with 96% of failures due to false positives in path inferences. Our results demonstrate more measurement and better path prediction is necessary to mitigate the risk of AS and IX adversaries to Tor. Joshua Juen, Aaron Johnson 0001, Anupam Das 0001, Nikita Borisov, Matthew Caesar 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2014 | Do You Hear What I Hear?: Fingerprinting Smart Devices Through Embedded Acoustic ComponentsabstractThe widespread use of smart devices gives rise to privacy concerns. Fingerprinting smart devices can jeopardize privacy by allowing remote identification without user awareness. We study the feasibility of using microphones and speakers embedded in smartphones to uniquely fingerprint individual devices. During fabrication, subtle imperfections arise in device microphones and speakers, which induce anomalies in produced and received sounds. We exploit this observation to fingerprint smartphones through playback and recording of audio samples. We explore different acoustic features and analyze their ability to successfully fingerprint smartphones. Our experiments show that not only is it possible to fingerprint devices manufactured by different vendors but also devices that have the same maker and model; on average we were able to accurately attribute 98% of all recorded audio clips from 50 different Android smartphones. Our study also identifies the prominent acoustic features capable of fingerprinting smart devices with a high success rate, and examines the effect of background noise and other variables on fingerprinting accuracy. Anupam Das 0001, Nikita Borisov, Matthew Caesar 0001 |
CCS | 1 |
| 2014 | Re3: relay reliability reputation for anonymity systemsabstractTo conceal user identities, Tor, a popular anonymity system, forwards traffic through multiple relays. These relays, however, are often unreliable, leading to a degraded user experience. Worse yet, malicious relays may strategically introduce deliberate failures to increase their chance of compromising anonymity. In this paper we propose a reputation system that profiles the reliability of relays in an anonymity system based on users' past experience. A particular challenge is that an observed failure in an anonymous communication cannot be uniquely attributed to a single relay. This enables an attack where malicious relays can target a set of honest relays in order to drive down their reputation. Our system defends against this attack in two ways. Firstly, we use an adaptive exponentially-weighted moving average (EWMA) that ensures malicious relays adopting time-varying strategic behavior obtain low reputation scores over time. Secondly, we propose a filtering scheme based on the evaluated reputation score that can effectively discard relays involved in such attacks. We use probabilistic analysis, simulations, and real-world experiments to validate our reputation system. We show that the dominant strategy for an attacker is to not perform deliberate failures, but rather maintain a high quality of service. Our reputation system also significantly improves the reliability of path construction even in the absence of attacks. Finally, we show that the benefits of our reputation system can be realized with a moderate number of observations, making it feasible for individual clients to perform their own profiling, rather than relying on an external entity. Anupam Das 0001, Nikita Borisov, Prateek Mittal, Matthew Caesar 0001 |
AsiaCCS | 1 |
| 2014 | The Tangled Web of Password Reuse
Anupam Das 0001, Joseph Bonneau, Matthew Caesar 0001, Nikita Borisov, XiaoFeng Wang 0001 |
NDSS | 1 |
| 2013 | PnP: improving web browsing performance over tor using web resource prefetch-and-pushabstractTor is a widely used network for anonymous communication. Its users frequently experience large communication delays, due to the high user-to-relay ratio, the bandwidth-intensive BitTorrent transfers of a small fraction of the user base, and the inherent latencies from routing traffic through multiple relay hops scattered around the world. These delays significantly degrade the user experience of web browsing, a dominant use of Tor. Giang T. K. Nguyen, Xun Gong 0001, Anupam Das 0001, Nikita Borisov |
CCS | 3 |
| 2012 | SecuredTrust: A Dynamic Trust Computation Model for Secured Communication in Multiagent SystemsabstractSecurity and privacy issues have become critically important with the fast expansion of multiagent systems. Most network applications such as pervasive computing, grid computing, and P2P networks can be viewed as multiagent systems which are open, anonymous, and dynamic in nature. Such characteristics of multiagent systems introduce vulnerabilities and threats to providing secured communication. One feasible way to minimize the threats is to evaluate the trust and reputation of the interacting agents. Many trust/reputation models have done so, but they fail to properly evaluate trust when malicious agents start to behave in an unpredictable way. Moreover, these models are ineffective in providing quick response to a malicious agent's oscillating behavior. Another aspect of multiagent systems which is becoming critical for sustaining good service quality is the even distribution of workload among service providing agents. Most trust/reputation models have not yet addressed this issue. So, to cope with the strategically altering behavior of malicious agents and to distribute workload as evenly as possible among service providers; we present in this paper a dynamic trust computation model called "SecuredTrust.” In this paper, we first analyze the different factors related to evaluating the trust of an agent and then propose a comprehensive quantitative model for measuring such trust. We also propose a novel load-balancing algorithm based on the different factors defined in our model. Simulation results indicate that our model compared to other existing models can effectively cope with strategic behavioral change of malicious agents and at the same time efficiently distribute workload among the service providing agents under stable condition. Anupam Das 0001, Mohammad Mahfuzul Islam |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2010 | A novel feedback based fast adaptive trust model for P2P networksabstractPeer-to-peer (P2P) networks have shown great potentials in providing a wide range of services starting from simple file sharing to distributed computing. However, P2P systems present ominous threats due to its anonymous and dynamic nature. One feasible way to minimize the threats is to evaluate the trust and reputation of the interacting peers. Trust models have often been deployed in determining the trust of peers in the network with the view to avoiding the malicious ones. Most of the existing trust models can successfully isolate malicious peers when the peers behave in a predictable way while others even fail to do so. On the other hand, these models suffer greatly when peers start to behave in a unpredictable way. Moreover, these models are ineffective in providing quick response to a peer's dynamic personality. To cope with such strategically altering behavior we present in this paper, a feedback based fast adaptive trust model which takes into account various factors in computing the trust of peers including recent trend, historical trend, sudden deviation of trust and so on. Simulations show that our model compared to other existing models can effectively identify and isolate the dynamic behavioral change of malicious peers. Anupam Das 0001, Mohammad Mahfuzul Islam |
LCN | 1 |
| 2008 | Permutation Free Encoding Technique for Evolving Neural Networks
Anupam Das 0001, Md. Shohrab Hossain, Saeed Muhammad Abdullah, Rashed Ul Islam |
ISNN (1) | 1 |