Mainack Mondal

dblp:87/8324 · DBLP profile ↗
← Back
37ranked-venue papers
6as first author
26since 2021 · last 2026
0000-0003-4317-0184ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 3 first-author · 11 since 2021Human-computer interaction and ubiquitous computing · 14 · 3 first-author · 9 since 2021Databases, data management, data science and information retrieval · 9 · 7 since 2021Artificial intelligence and machine learning · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Computer networks · 3 · 2 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Learning Faster with Better Tokens: Parameter-Efficient Vocabulary Adaptation for Specialized Text Summarization
abstract
Large language models pretrained on generaldomain corpora often exhibit tokenization inefficiencies when applied to specialized domains.Although continual pretraining for domain adaptation partially alleviate performance degradation, it does not resolve the fundamental vocabulary mismatch.To address this gap, we introduce a targeted parameterefficient domain adaptation approach that combines vocabulary adaptation with pretraining for LLM-based text summarization.Our unified framework augments pretrained tokenizers with domain-specific tokens while selectively replacing under-trained and unreachable tokens to limit parameter growth.We evaluate our approach on Llama-3.1-8B and Qwen2.5-7Bacross legal and medical summarization tasks on a challenge-oriented evaluation protocol focused on expert-driven text and summaries which typically has higher concentration of over-fragmented Out-of-Vocabulary (OOV) words.The vocabulary adaptation algorithm enhances the overall quality of the summarization model by improving semantic similarity between the generated summaries and their references.In addition, the adapted model produces summaries that incorporate more appropriate novel and domain-specific words, leading to improved coherence, relevance, and faithfulness.We further observe that our proposed approach significantly reduce training time by 35 -55% over continual pretraining and reduce parameter counts up to 37% w.r.t expansion-only methods.We make codebase publicly available 1 .
Gunjan Balde, Soumyadeep Roy, Mainack Mondal, Niloy Ganguly
ACL (1)3
2026 "To Pay or Not to Pay?": Understanding User Decision-Making and Influence of Nudges in UPI Apps
abstract
In response to increasing social engineering attacks, Unified Payments Interface (UPI) apps have implemented a variety of nudges to deter users from responding to fraudulent payment requests. We conducted a scenario-based semi-structured interview study with 46 Indian participants who tested the impact of various user interface nudges to help them discern a mixture of fraudulent and non-fraudulent payment scenarios. Our study revealed a multi-stage de cision-making process: participants relied on a digital literacy and security concern-based risk assessment, which is further influenced by their trust in the recipient as well as the perceived need of the financial transaction. Our results demonstrate that while most nudges help to combat fraudulent transactions, participants perceived “badges” (a nudge signaling the trustworthiness of the receiver) to be most effective in combating fraud. We conclude with concrete recommendations for current and future UPI developers.
Nandini Bajaj, Shiladitya De, Kshitiz Sharma, Xinru Page, Bart P. Knijnenburg, Mainack Mondal
AsiaCCS6
2026 "You Have Been Selected as the Winner": Characterizing User-Reported Scams on TikTok
Smirity Kaushik, Kyle Beadle, Gauri Nayak, Madelyn Sanfilippo, Mainack Mondal, Yang Wang 0005, Sai Teja Peddinti, Yixin Zou
SOUPS5
2026 Cultivating a Tech-Safety Mindset using Game-Based Learning for Defending against Technology-Facilitated Abuse
abstract
Technology-facilitated abuse (TFA) has become increasingly common as abusers exploit everyday technologies to monitor and harass others, mainly their intimate partners. Preventing TFA requires not only reactive technical support but proactively cultivating protective mindsets --- awareness of personal vulnerability, recognition of threat severity, and confidence to implement defensive strategies --- before abuse escalates. Yet no research has developed educational tools grounded in behavior change theory specifically for technology-facilitated abuse prevention. We address this gap with BeSafe, a narrative-driven visual novel game grounded in Protection Motivation Theory (PMT) and designed to shift how users perceive and respond to TFA threats. Through a study with 198 participants across six platform contexts, we assessed both knowledge acquisition and changes in PMT constructs: perceived vulnerability, perceived severity, self-efficacy, and fear arousal. Our results show that BeSafe produced significant knowledge gains alongside meaningful shifts in protection motivation. Participants with prior exposure to online abuse showed substantially greater gains across both knowledge and motivation measures. Many participants reported intentions to review privacy settings and share protective strategies with others, indicating motivation to act on what they learned. Our findings demonstrate that game-based interventions can cultivate digital safety mindsets, offering a scalable, proactive complement to existing reactive support services.
Majed Almansoori, Chirag Ghosh, Sarita Singh, Rahul Chatterjee 0001, Mainack Mondal
Proc. Priv. Enhancing Technol.5
2025 A House Divided: How U.S. Politics Could Shape Contact-Tracing Adoption in Future Pandemics
Garrett Smith, Kirsten Chapman, Tzu-Yu Weng, Haijing Hao, Mainack Mondal, Staci Smith, Yunan Chen 0001, Xinru Page
CHI5
2025 FNoDe: Faulty Node Detection in Microservices Architecture
Harsh Borse, Utkalika Satpathy, Mainack Mondal, Bivas Mitra
DaWaK3
2025 MicroSuggest: Kernel-Aware Microservice Decomposition
Harsh Borse, Utkalika Satpathy, Mainack Mondal, Bivas Mitra
DaWaK3
2025 SysResolve: Study on In-Context LLM Generation of Resolution Scripts
Harsh Borse, Utkalika Satpathy, Mainack Mondal, Bivas Mitra
DEXA (1)3
2025 "Strangers in a new culture see only what they know": Evaluating Effectiveness of GPT-4 Omni for Detecting Cross-Cultural Communication Norm Violations
abstract
Cross-cultural communication often results in misaligned norms and expectations, leading to misunderstandings or harm.As the internet increasingly facilitates cross-cultural communication online, such misalignments also increase.However, there is an opportunity to use Large Language Models (LLMs) to detect such misunderstandings and assist in addressing them.To that end, this study investigates whether cross-cultural norm violations can be detected and mitigated using popular LLMs.Using a set of carefully constructed cross-cultural communication scenarios, half of which present norm violations, we test the ability of OpenAI's GPT-4 Omni (GPT-4o) model to identify cross-cultural communication norm violations.We find that GPT-4o classification accuracy varies by the stated age, gender, and nationality of the communicators described in the scenarios, suggesting a lack of fairness and a potential cultural gap in GPT-4o's detection.
Tzu-Yu Weng, Hanna AlZughbi, Isaac Rabago, Erin Arévalo Chaves, Erik Vagil, Nancy Fulda, Erin Ash, Mainack Mondal, Bart P. Knijnenburg, Xinru Page
UMAP8
2025 "I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages
Rajdeep Ghosh 0005, Shiladitya De, Mainack Mondal
USENIX Security Symposium3
2024 "I Know I'm Being Observed: " Video Interventions to Educate Users about Targeted Advertising on Facebook
abstract
Recent work explores how to educate and encourage users to protect their online privacy. We tested the efficacy of short videos for educating users about targeted advertising on Facebook. We designed a video that utilized an emotional appeal to explain risks associated with targeted advertising (fear appeal), and which demonstrated how to use the associated ad privacy settings (digital literacy). We also designed a version of this video which additionally showed the viewer their personal Facebook ad profile, facilitating personal reflection on how they are currently being profiled (reflective learning). We conducted an experiment (n = 127) in which participants watched a randomly assigned video and measured the impact over the following 10 weeks. We found that these videos significantly increased user engagement with Facebook advertising preferences, especially for those who viewed the reflective learning content. However, those who only watched the fear appeal content were more likely to disengage with Facebook as a whole.
Garrett Smith, Sarah Carson, Rhea G. Vengurlekar, Stephanie Morales, Yun-Chieh Tsai, Rachel George, Josh Bedwell, Trevor Jones, Mainack Mondal, Norman Makoto Su, Bart P. Knijnenburg, Xinru Page
CHI9
2024 The Web of Abuse: A Comprehensive Analysis of Online Resource in the Context of Technology-Enabled Intimate Partner Surveillance
abstract
Previous research has shown that abusers in an intimate relationship can find plenty of technical advice, tools, and how-to guides online for covertly conducting intimate partner surveillance (IPS). However, it is unclear what resources survivors seeking to defend themselves against IPS can use. To address this gap, we first conducted a survey-based study with 63 survivors recruited via Prolific to understand what resources survivors rely on. We showed that 45% utilized online resources for assistance, with 67% of them relying on search engines. We then conducted a systematic survey of the results obtained via Google search engine to identify resources available for survivors. We found that the resources survivors can find online contain poor, inaccurate, and unactionable advice. They are hard to understand and do not help mitigate IPS. To investigate whether the lack of useful resources is solely experienced by survivors, we also crawled resources that abusers will find online. We found that abusers can easily find resources recommending spyware apps and hidden devices and often explicitly promoting IPS. We also compared the understandability and actionability of the resources using an adopted Patient Education Materials Assessment Tool (PEMAT) score. We concluded that resources available to abusers are significantly more understandable and actionable than those available to survivors.
Majed Almansoori, Mazharul Islam 0002, Saptarshi Ghosh 0001, Mainack Mondal, Rahul Chatterjee 0001
EuroS&P4
2024 URCD: Unsupervised Root Cause Detection in Microservices Architecture with HGAN
abstract
The shift from monolithic services to microservices brings modularity and elasticity, but detecting faults and anomalies is challenging due to diverse data and evolving technology. The heterogeneous nature of this data complicates the analysis of anomaly signatures across various dimensions. Given the continuous evolution of this technology, exhaustively learning from historical data poses difficulties. To address these challenges, we present URCD, a solution designed to identify and localize faults or anomalies at the application and service level. Remarkably, URCD achieves this without explicit training on faulty data. Our approach integrates heterogeneous microservice data into a bidirectional weighted graph, leveraging a sophisticated Hyper Graph Attention Network (HGAN) model to process heterogeneous data logs generated by microservices. Our evaluation shows the optimal performance of URCD while detecting root cause of anomalies.
Harsh Borse, Utkalika Satapathy, Mainack Mondal, Bivas Mitra
ICDCS3
2024 MEDVOC: Vocabulary Adaptation for Fine-tuning Pre-trained Language Models on Medical Text Summarization
Gunjan Balde, Soumyadeep Roy, Mainack Mondal, Niloy Ganguly
IJCAI3
2024 "I just hated it and I want my money back": Data-driven Understanding of Mobile VPN Service Switching Preferences in The Wild
Rohit Raj, Mridul Newar, Mainack Mondal
USENIX Security Symposium3
2023 MASCARA : Systematically Generating Memorable And Secure Passphrases
abstract
Passwords are the most common mechanism for authenticating users online. However, studies have shown that users find it difficult to create and manage secure passwords. To that end, passphrases are often recommended as a usable alternative to passwords, which would potentially be easy to remember and hard to guess. However, as we show, user-chosen passphrases fall short of being secure, while state-of-the-art machine-generated passphrases are difficult to remember.
Avirup Mukherjee, Kousshik Murali, Shivam Kumar Jha, Niloy Ganguly, Rahul Chatterjee 0001, Mainack Mondal
AsiaCCS6
2023 Uncovering Impact of Mental Models towards Adoption of Multi-device Crypto-Wallets
abstract
Cryptocurrency users saw a sharp increase in different types of crypto wallets in the past decade. However, the emerging multi-device wallets, even with improved security guarantees over their single-device counterparts, are yet to receive proportionate adoption. This work presents a data-driven investigation into the perceptions of users towards multi-device wallets, using a survey of 357 crypto-wallet users. Our results revealed two significant groups among our participants-Newbies and Non-newbies. Our follow-up qualitative analysis, after educating, revealed a gap between the mental model for these participants and actual security guarantees. Furthermore, we investigated preferred default settings for crypto-wallets across our participants over different key-share distribution settings of multi-device wallets-the threat model considerations affected user preferences, signifying a need for contextualizing default settings. We identified concrete, actionable design avenues for future multi-device wallet developers to improve adoption.
Easwar Vivek Mangipudi, Udit Desai, Mohsen Minaei, Mainack Mondal, Aniket Kate
CCS4
2023 "Dummy Grandpa, Do You Know Anything?": Identifying and Characterizing Ad Hominem Fallacy Usage in the Wild
abstract
Today, participating in discussions on online forums is extremely commonplace and these discussions have started rendering a strong influence on the overall opinion of online users. Naturally, twisting the flow of the argument can have a strong impact on the minds of naive users, which in the long run might have socio-political ramifications, for example, winning an election or spreading targeted misinformation. Thus, these platforms are potentially highly vulnerable to malicious players who might act individually or as a cohort to breed fallacious arguments with a motive to sway public opinion. Ad hominem arguments are one of the most effective forms of such fallacies. Although a simple fallacy, it is effective enough to sway public debates in offline world and can be used as a precursor to shutting down the voice of opposition by slander. In this work, we take a first step in shedding light on the usage of ad hominem fallacies in the wild. First, we build a powerful ad hominem detector based on transformer architecture with high accuracy (F1 more than 83%, showing a significant improvement over prior work), even for datasets for which annotated instances constitute a very small fraction. We then used our detector on 265k arguments collected from the online debate forum – CreateDebate. Our crowdsourced surveys validate our in-the-wild predictions on CreateDebate data (94% match with manual annotation). Our analysis revealed that a surprising 31.23% of CreateDebate content contains ad hominem fallacy, and a cohort of highly active users post significantly more ad hominem to suppress opposing views. Then, our temporal analysis revealed that ad hominem argument usage increased significantly since the 2016 US Presidential election, not only for topics like Politics, but also for Science and Law. We conclude by discussing important implications of our work to detect and defend against ad hominem fallacies.
Utkarsh Patel, Animesh Mukherjee 0001, Mainack Mondal
ICWSM3
2023 MDAP: Module Dependency based Anomaly Prediction
Harsh Borse, Bikash Sahoo, Prateek Chanda, Soumik Sinha, Mainack Mondal, Bivas Mitra
Comput. Commun.5
2023 A Tale of Two Cultures: Comparing Interpersonal Information Disclosure Norms on Twitter
abstract
We present an exploration of cultural norms surrounding online disclosure of information about one's interpersonal relationships (such as information about family members, colleagues, friends, or lovers) on Twitter. The literature identifies the cultural dimension of individualism versus collectivism as being a major determinant of offline communication differences in terms of emotion, topic, and content disclosed. We decided to study whether such differences also occur online in context of Twitter when comparing tweets posted in an individualistic (U.S.) versus a collectivist (India) society. We collected more than 2 million tweets posted in the U.S. and India over a 3 month period which contain interpersonal relationship keywords. A card-sort study was used to develop this culturally-sensitive saturated taxonomy of keywords that represent interpersonal relationships (e.g., ma, mom, mother). Then we developed a high-accuracy interpersonal disclosure detector based on dependency-parsing (F1-score: 86%) to identify when the words refer to a personal relationship of the poster (e.g., "my mom" as opposed to "a mom"). This allowed us to identify the 400K+ tweets in our data set which actually disclose information about the poster's interpersonal relationships. We used a mixed methods approach to analyze these tweets (e.g., comparing the amount of joy expressed about one's family) and found differences in emotion, topic, and content disclosed between tweets from the U.S. versus India. Our analysis also reveals how a combination of qualitative and quantitative methods are needed to uncover these differences; Using just one or the other can be misleading. This study extends the prior literature on Multi-Party Privacy and provides guidance for researchers and designers of culturally-sensitive systems.
Mainack Mondal, Anju Punuru, Tyng-Wen Cheng, Kenneth Vargas, Chaz Gundry, Nathan S. Driggs, Noah Schill, Nathaniel Carlson, Josh Bedwell, Jaden Q. Lorenc, Isha Ghosh, Yao Li 0006, Nancy Fulda, Xinru Page
Proc. ACM Hum. Comput. Interact.1
2022 Understanding the Impact of Awards on Award Winners and the Community on Reddit
abstract
Non-financial incentives in the form of awards often act as a driver of positive reinforcement and elevation of social status in the offline world. The elevated social status results in people becoming more active, aligning to a change in the communities' expectations. However, the impact in terms of longevity of social influence and community acceptance of leaders of these incentives in the form of awards are not well-understood in the online world. Our work aims to shed light on the impact of these awards on the awardee and the community. We focus on three large subreddits with a snapshot of 219K posts and 5.8 million comments contributed by 88K Reddit users who received 14,146 awards. Our work establishes that the behaviour of awardees change statistically significantly for a short time after getting an award; however, the change is ephemeral since the awardees return to their pre-award behaviour within days. Additionally, via a user survey, we identified a long-lasting impact of awards-we found that the community's stance softened towards awardees.
Avinash Tulasi, Mainack Mondal, Arun Balaji Buduru, Ponnurangam Kumaraguru
ASONAM2
2022 Winds of Change: Impact of COVID-19 on Vaccine-Related Opinions of Twitter Users
Soham Poddar, Mainack Mondal, Janardan Misra, Niloy Ganguly, Saptarshi Ghosh 0001
ICWSM2
2022 Empirical Understanding of Deletion Privacy: Experiences, Expectations, and Measures
Mohsen Minaei, Mainack Mondal, Aniket Kate
USENIX Security Symposium2
2022 Understanding and Improving Usability of Data Dashboards for Simplified Privacy Control of Voice Assistant Data
Vandit Sharma, Mainack Mondal
USENIX Security Symposium2
2021 Perceptions of Retrospective Edits, Changes, and Deletion on Social Media
Günce Su Yilmaz, Fiona Gasaway, Blase Ur, Mainack Mondal
ICWSM4
2021 Deceptive Deletions for Protecting Withdrawn Posts on Social Media Platforms
Mohsen Minaei, S. Chandra Mouli, Mainack Mondal, Bruno Ribeiro 0001, Aniket Kate
NDSS3
2019 Moving Beyond Set-It-And-Forget-It Privacy Settings on Social Media
abstract
When users post on social media, they protect their privacy by choosing an access control setting that is rarely revisited. Changes in users' lives and relationships, as well as social media platforms themselves, can cause mismatches between a post's active privacy setting and the desired setting. The importance of managing this setting combined with the high volume of potential friend-post pairs needing evaluation necessitate a semi-automated approach. We attack this problem through a combination of a user study and the development of automated inference of potentially mismatched privacy settings. A total of 78 Facebook users reevaluated the privacy settings for five of their Facebook posts, also indicating whether a selection of friends should be able to access each post. They also explained their decision. With this user data, we designed a classifier to identify posts with currently incorrect sharing settings. This classifier shows a 317% improvement over a baseline classifier based on friend interaction. We also find that many of the most useful features can be collected without user intervention, and we identify directions for improving the classifier's accuracy.
Mainack Mondal, Günce Su Yilmaz, Noah Hirsch, Mohammad Taha Khan, Michael Tang, Christopher Tran 0001, Chris Kanich, Blase Ur, Elena Zheleva
CCS1
2019 Oh, the Places You've Been! User Reactions to Longitudinal Transparency About Third-Party Web Tracking and Inferencing
abstract
Internet companies track users' online activity to make inferences about their interests, which are then used to target ads and personalize their web experience. Prior work has shown that existing privacy-protective tools give users only a limited understanding and incomplete picture of online tracking. We present Tracking Transparency, a privacy-preserving browser extension that visualizes examples of long-term, longitudinal information that third-party trackers could have inferred from users' browsing. The extension uses a client-side topic modeling algorithm to categorize pages that users visit and combines this with data about the web trackers encountered over time to create these visualizations. We conduct a longitudinal field study in which 425 participants use one of six variants of our extension for a week. We find that, after using the extension, participants have more accurate perceptions of the extent of tracking and also intend to take privacy-protecting actions.
Ben Weinshel, Miranda Wei, Mainack Mondal, Euirim Choi, Shawn Shan, Claire Dolin, Michelle L. Mazurek, Blase Ur
CCS3
2019 Lethe: Conceal Content Deletion from Persistent Observers
abstract
Abstract Most social platforms offer mechanisms allowing users to delete their posts, and a significant fraction of users exercise this right to be forgotten. However, ironically, users’ attempt to reduce attention to sensitive posts via deletion, in practice, attracts unwanted attention from stalkers specifically to those (deleted) posts. Thus, deletions may leave users more vulnerable to attacks on their privacy in general. Users hoping to make their posts forgotten face a “damned if I do, damned if I don’t” dilemma. Many are shifting towards ephemeral social platform like Snapchat, which will deprive us of important user-data archival. In the form of intermittent withdrawals, we present, Lethe, a novel solution to this problem of (really) forgetting the forgotten. If the next-generation social platforms are willing to give up the uninterrupted availability of non-deleted posts by a very small fraction, Lethe provides privacy to the deleted posts over long durations. In presence of Lethe, an adversarial observer becomes unsure if some posts are permanently deleted or just temporarily withdrawn by Lethe; at the same time, the adversarial observer is overwhelmed by a large number of falsely flagged undeleted posts. To demonstrate the feasibility and performance of Lethe, we analyze large-scale real data about users’ deletion over Twitter and thoroughly investigate how to choose time duration distributions for alternating between temporary withdrawals and resurrections of non-deleted posts. We find a favorable trade-off between privacy, availability and adversarial overhead in different settings for users exercising their right to delete. We show that, even against an ultimate adversary with an uninterrupted access to the entire platform, Lethe offers deletion privacy for up to 3 months from the time of deletion, while maintaining content availability as high as 95% and keeping the adversarial precision to 20%.
Mohsen Minaei, Mainack Mondal, Patrick Loiseau, Krishna P. Gummadi, Aniket Kate
Proc. Priv. Enhancing Technol.2
2016 Analyzing the Targets of Hate in Online Social Media
Leandro Araújo, Mainack Mondal, Denzil Correa, Fabrício Benevenuto, Ingmar Weber
ICWSM2
2016 Forgetting in Social Media: Understanding and Controlling Longitudinal Exposure of Socially Shared Data
Mainack Mondal, Johnnatan Messias, Saptarshi Ghosh 0001, Krishna P. Gummadi, Aniket Kate
SOUPS1
2015 The Many Shades of Anonymity: Characterizing Anonymous Social Media Content
Denzil Correa, Leandro Araújo, Mainack Mondal, Fabrício Benevenuto, Krishna P. Gummadi
ICWSM3
2014 Deep Twitter diving: exploring topical groups in microblogs at scale
abstract
We present a semantic methodology to identify topical groups in Twitter on a large number of topics, each consisting of users who are experts on or interested in a specific topic. Early studies investigating the nature of Twitter suggest that it is a social media platform consisting of a relatively small section of elite users, producing information on a few popular topics such as media, politics, and music, and the general population consuming it. We show that this characterization ignores a rich set of highly specialized topics, ranging from geology, neurology, to astrophysics and karate - each being discussed by their own topical groups. We present a detailed characterization of these topical groups based on their network structures and tweeting behaviors. Analyzing these groups on the backdrop of the common identity and bond theory in social sciences shows that these groups exhibit characteristics of topical-identity based groups, rather than social-bond based ones.
Parantapa Bhattacharya, Saptarshi Ghosh 0001, Juhi Kulshrestha, Mainack Mondal, Muhammad Bilal Zafar, Niloy Ganguly, Krishna P. Gummadi
CSCW4
2014 Understanding and Specifying Social Access Control Lists
Mainack Mondal, Yabing Liu, Bimal Viswanath, Krishna P. Gummadi, Alan Mislove
SOUPS1
2012 Defending against large-scale crawls in online social networks
abstract
Thwarting large-scale crawls of user profiles in online social networks (OSNs) like Facebook and Renren is in the interest of both the users and the operators of these sites. OSN users wish to maintain control over their personal information, and OSN operators wish to protect their business assets and reputation. Existing rate-limiting techniques are ineffective against crawlers with many accounts, be they fake accounts (also known as Sybils) or compromised accounts of real users obtained on the black market.
Mainack Mondal, Bimal Viswanath, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove, Ansley Post
CoNEXT1
2012 Canal: scaling social network-based Sybil tolerance schemes
abstract
There has been a flurry of research on leveraging social networks to defend against multiple identity, or Sybil, attacks. A series of recent works does not try to explicitly identify Sybil identities and, instead, bounds the impact that Sybil identities can have. We call these approaches Sybil tolerance; they have shown to be effective in applications including reputation systems, spam protection, online auctions, and content rating systems. All of these approaches use a social network as a credit network, rendering multiple identities ineffective to an attacker without a commensurate increase in social links to honest users (which are assumed to be hard to obtain). Unfortunately, a hurdle to practical adoption is that Sybil tolerance relies on computationally expensive network analysis, thereby limiting widespread deployment.
Bimal Viswanath, Mainack Mondal, Krishna P. Gummadi, Alan Mislove, Ansley Post
EuroSys2
2011 Limiting large-scale crawls of social networking sites
abstract
Online social networking sites (OSNs) like Facebook and Orkut contain personal data of millions of users. Many OSNs view this data as a valuable asset that is at the core of their business model. Both OSN users and OSNs have strong incentives to restrict large scale crawls of this data. OSN users want to protect their privacy and OSNs their business interest. Traditional defenses against crawlers involve rate- limiting browsing activity per user account. These defense schemes, however, are vulnerable to Sybil attacks, where a crawler creates a large number of fake user accounts. In this paper, we propose Genie, a system that can be deployed by OSN operators to defend against Sybil crawlers. Genie is based on a simple yet powerful insight: the social network itself can be leveraged to defend against Sybil crawlers. We first present Genie's design and then discuss how Genie can limit crawlers while allowing browsing of user profiles by normal users.
Mainack Mondal, Bimal Viswanath, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove, Ansley Post
SIGCOMM1