VLDB 2026 Research / reviewers in the wild / expert
Seda Gurses
dblp:85/1005 · also Seda F. Gürses
· DBLP profile ↗
8ranked-venue papers
1as first author
5since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The PET Paradox: How Amazon Instrumentalises PETs in Sidewalk to Entrench Its Infrastructural PowerabstractPrivacy engineers originally conceptualised Privacy Enhancing Technologies (PETs) to pursue data minimisation, purpose limitation, and trust minimisation (avoiding single points of failure); thereby curbing corporate and state power over people. Through a review of Google and Apple applications, and an in-depth case study of cloud connectivity service Amazon Sidewalk, we show how companies with concentrated power over computational infrastructures implement PETs with paradoxical effects. These companies can deploy PETs on large swaths of devices – a huge benefit – while introducing new capabilities and expanding their control over devices, OSes, and applications. In doing so, these companies increase their informational, market and infrastructural power. To reveal how these paradoxes come to be, we apply a broader framework including how the design of PETs impacts (1) information flows, (2) consumer privacy, (3) infrastructural companies’ control over consumer devices, and (4) business-to-business (B2B) and -government (B2G) relationships implicated by these; focussing on (3) and (4). We analyse the consequences for information, market and infrastructural power asymmetries, that affect consumers, businesses, and governments, and shape the future implementation of PETs. For the Google and Apple cases, we rely on desk research. For our case study into Amazon Sidewalk, we conduct elite interviews with 8 of the 16 adopting manufacturers. We triangulate results with Amazon’s (technical) documentation and marketing as well as grey literature. We conclude by discussing how we should expand PET design and evaluation processes to avoid the paradoxical outcomes that these infrastructural players bring to being. Thijmen van Gend, Donald Jay Bertulfo, Seda Gurses |
Proc. Priv. Enhancing Technol. | 3 |
| 2023 | Back-to-the-Future Whois: An IP Address Attribution Service for Working with Historic DatasetsabstractAbstract Researchers and practitioners often face the issue of having to attribute an IP address to an organization. For current data this is comparably easy, using services like whois or other databases. Similarly, for historic data, several entities like the RIPE NCC provide websites that provide access to historic records. For large-scale network measurement work, though, researchers often have to attribute millions of addresses. For current data, Team Cymru provides a bulk whois service which allows bulk address attribution. However, at the time of writing, there is no service available that allows historic bulk attribution of IP addresses. Hence, in this paper, we introduce and evaluate our ‘Back-to-the-Future whois’ service, allowing historic bulk attribution of IP addresses on a daily granularity based on CAIDA Routeviews aggregates. We provide this service to the community for free, and also share our implementation so researchers can run instances themselves. Florian Streibelt, Martina Lindorfer, Seda Gurses, Carlos Gañán, Tobias Fiebig |
PAM | 3 |
| 2023 | Heads in the Clouds? Measuring Universities' Migration to Public Clouds: Implications for Privacy & Academic FreedomabstractWith the emergence of remote education and work in universities due to COVID-19, the 'zoomification' of higher education, i.e., the migration of universities to the clouds, reached the public discourse. Ongoing discussions reason about how this shift will take control over students' data away from universities, and may ultimately harm the privacy of researchers and students alike. However, there has been no comprehensive measurement of universities' use of public clouds and reliance on Software-as-a-Service offerings to assess how far this migration has already progressed. We perform a longitudinal study of the migration to public clouds among universities in the U.S. and Europe, as well as institutions listed in the Times Higher Education (THE) Top100 between January 2015 and October 2022. We find that cloud adoption differs between countries, with one cluster (Germany, France, Austria, Switzerland) showing a limited move to clouds, while the other (U.S., U.K., the Netherlands, THE Top100) frequently outsources universities' core functions and services---starting long before the COVID-19 pandemic. We attribute this clustering to several socio-economic factors in the respective countries, including the general culture of higher education and the administrative paradigm taken towards running universities. We then analyze and interpret our results, finding that the implications reach beyond individuals' privacy towards questions of academic independence and integrity. Tobias Fiebig, Seda Gurses, Carlos Gañán, Erna Kotkamp, Fernando A. Kuipers, Martina Lindorfer, Menghua Prisse, Taritha Sari |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Technology, equity and social justice roundtableabstractOnly a summary overview is provided. This roundtable discussion, sponsored by a SSHRC Connection Grant, brings together four international faculty members from a range of academic and industry backgrounds in engineering and social sciences to discuss how they engage with equity and social justice issues in their work, focusing specifically on methodology and how students and young professionals can approach these issues. Ansari will describe his current efforts to decolonize design research in the university community, in particular through the _Decolonising Design_ platform. Gürses will discuss her ongoing work in the field of Privacy Engineering, which focuses on designing, implementing, adapting, and evaluating theories, methods, techniques, and tools to systematically capture and address privacy issues in the development of sociotechnical systems. Hoffman will focus on a novel and timely intervention into Data Ethics: Feminist Data Ethics, which engages with the ethical implications of data’s production, circulation, application, and storage. Sloane will highlight the critical importance of responsible AI design and governance, interdisciplinary opportunities for researchers to develop and implement tools to engage with responsible innovation, innovation in AI procurement, and AI auditing. Ahmed Ansari, Anna Lauren Hoffmann, Seda Gurses, Mona Sloane, Mark A. Vasquez, Zach Pearl |
ISTAS | 3 |
| 2021 | CrowdNotifier: Decentralized Privacy-Preserving Presence TracingabstractAbstract There is growing evidence that SARS-CoV-2 can be transmitted beyond close proximity contacts, in particular in closed and crowded environments with insufficient ventilation. To help mitigation efforts, contact tracers need a way to notify those who were present in such environments at the same time as infected individuals. Neither traditional human-based contact tracing powered by handwritten or electronic lists, nor Bluetooth-enabled proximity tracing can handle this problem efficiently. In this paper, we propose CrowdNotifier, a protocol that can complement manual contact tracing by efficiently notifying visitors of venues and events with SARS-CoV-2-positive attendees. We prove that CrowdNotifier provides strong privacy and abuse-resistance, and show that it can scale to handle notification at a national scale. Wouter Lueks, Seda Gurses, Michael Veale, Edouard Bugnion, Marcel Salathé, Kenneth G. Paterson, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2013 | FPDetective: dusting the web for fingerprintersabstractIn the modern web, the browser has emerged as the vehicle of choice, which users are to trust, customize, and use, to access a wealth of information and online services. However, recent studies show that the browser can also be used to invisibly fingerprint the user: a practice that may have serious privacy and security implications. Gunes Acar, Marc Juarez, Nick Nikiforakis, Claudia Díaz, Seda Gurses, Frank Piessens, Bart Preneel |
CCS | 5 |
| 2013 | Requirements engineering within a large-scale security-oriented research project: lessons learnedabstractRequirements engineering has been recognized as a fundamental phase of the software engineering process. Nevertheless, the elicitation and analysis of requirements are often left aside in favor of architecture-driven software development. This tendency, however, can lead to issues that may affect the success of a project. This paper presents our experience gained in the elicitation and analysis of requirements in a large-scale security-oriented European research project, which was originally conceived as an architecture-driven project. In particular, we illustrate the challenges that can be faced in large-scale research projects and consider the applicability of existing best practices and off-the-shelf methodologies with respect to the needs of such projects. We then discuss how those practices and methods can be integrated into the requirements engineering process and possibly improved to address the identified challenges. Finally, we summarize the lessons learned from our experience and the benefits that a proper requirements analysis can bring to a project. Seda Gurses, Magali Seguran, Nicola Zannone |
Requir. Eng. | 1 |
| 2010 | A comparison of security requirements engineering methods
Benjamin Fabian, Seda Gurses, Maritta Heisel, Thomas Santen, Holger Schmidt 0001 |
Requir. Eng. | 2 |