VLDB 2026 Research / reviewers in the wild / expert
Adam J. Aviv
dblp:94/1554
· DBLP profile ↗
67ranked-venue papers
10as first author
36since 2021 · last 2026
0000-0002-3792-2485ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 54 · 9 first-author · 30 since 2021Human-computer interaction and ubiquitous computing · 10 · 7 since 2021Systems, architecture and hardware · 2Computer networks · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Re-Examining the Examiners: Changes in Privacy and Security Perceptions of Exam ProctoringabstractWith the shift to remote learning during the COVID-19 pandemic, educators turned to remote exam proctoring software to support integrity for online tests. However, due to the mechanisms used to surveil test-takers, these systems come with significant privacy and security tradeoffs. At the height of the pandemic, Balash et al. (SOUPS ’21) found that test-takers had privacy concerns with remote proctoring but acquiesced due to a number of factors. We investigate how perceptions have changed four years later. To gain a fuller perspective on how users experience these tools now, we replicate Balash et al.’s study with 127 participants who have experienced exam proctoring. We found a significant shift in favor of proctoring software, with greater acceptance of all monitoring methods compared to 2020. This is likely due to the convenience of remote exams and a growing resignation to privacy trade-offs. We discuss these implications and suggest future directions. Adryana Hutchinson, Elaine Ly, Collins W. Munyendo, Adam J. Aviv |
CHI | 4 |
| 2026 | SoK: Mapping Threats to Defenses in Online Survey Fraud
Shiza Ali, Wellington Esposito Barbosa, Matthias Fassl, Aditi Ganapathi, Jaron Mink, Adam J. Aviv |
SOUPS | 6 |
| 2026 | Toward Inclusive Security and Privacy for Deaf and Hard-of-Hearing People: A Community-Based Interview Study
Mindy Tran, Xinru Tang, Adryana Hutchinson, Adam J. Aviv, Yixin Zou |
SP | 4 |
| 2026 | "Because I didn't touch these and even don't know why I should to change these": Why App Developers Do (Not) Update Apple's Privacy LabelsabstractApple introduced app-based privacy labels in 2020 to improve apps' communication of their data practices. However, most developers appear to treat privacy labels as a ``set-once'' mechanism. To better understand the dynamics of this system, we first analyzed a four-year longitudinal dataset of Apple's Privacy Label. Next, we conducted an email survey of developers who have changed (or not changed) their privacy labels during this period, and finally, performed follow-up interviews with developers from each group. We find that only 51,364 apps (less than 6%) over this period have made any changes to their privacy labels, many of them changing their initial 'Do Not Collect' label to more refined classification. From the emails and interviews, the ``black box'' of third-party data practice may lead developers to underreport their app's data practices. Many developers reported that privacy labels are a valuable marketing tool for promoting their apps as privacy-friendly. Privacy labels may appear stable not necessarily because practices are stable, but because ambiguity encourages minimal or optimistic disclosure. To improve privacy label maintenance, we recommend enhanced transparency mechanisms for third-party libraries, stronger workflow integration, and platform support that guides developers and strengthens users' control. Arwa Alsahdi, Monica Kodwani, Matthias Fassl, Chris Kanich, Adam J. Aviv |
Proc. Priv. Enhancing Technol. | 6 |
| 2025 | Reimagining Wearable-Based Digital Contact Tracing: Insights from Kenya and Côte d'Ivoire
Kavous Salehzadeh Niksirat, Collins W. Munyendo, Onicio Batista Leal Neto, Muswagha Katya, Cyrille Kouassi, Kevin Ochieng, Angoa Georgina, Bernard Olayo, Jean-Philippe Barras, Ciro Cattuto, Adam J. Aviv, Carmela Troncoso |
CHI | 11 |
| 2025 | Mirror Mirror on the Wall, which APK Mirror Site is the Largest of Them All?
Neal Keating, Wellington Esposito Barbosa, Leo Phan, Viraj Prakash, Gianluca Stringhini, Adam J. Aviv |
IMC | 6 |
| 2025 | Safety Perceptions of Generative AI Conversational Agents: Uncovering Perceptual Differences in Trust, Risk, and Fairness
Jan Tolsdorf, Alan F. Luo, Monica Kodwani, Junho Eum, Mahmood Sharif, Michelle L. Mazurek, Adam J. Aviv |
SOUPS | 7 |
| 2025 | "You Have to Ignore the Dangers": User Perceptions of the Security and Privacy Benefits of WhatsApp ModsabstractWhatsApp is the most popular social messaging platform, and modified versions (or “mods”) of the official WhatsApp are increasingly popular. Mods advertise additional features and customization. However, some of these features, e.g., retaining deleted messages and statuses, enable mod users to subvert the privacy of others, and have the potential for seri-ous security and privacy implications. In this study, we explore user perspectives of WhatsApp mods through an interview study$(n=20)$of mod users in Kenya, one of the countries with the highest WhatsApp mod usage. Many turned to WhatsApp mods for their “advanced” features to protect themselves (e.g., “anti-delete” for legal liability), while others admitted to using mod features to hide their behavior or to stalk others. To understand how users' expectations of WhatsApp mods align with the apps' behavior, we identify and analyze 13 instances of the most common mod (GB WhatsApp). While WhatsApp mods contained the features they claimed to offer, some participants incorrectly believed that features currently available in the official app only existed in mods. Additionally, several mods were significantly over-permissioned compared to the official WhatsApp, despite participants believing that they requested the same permissions as the official app. While almost half of participants indicated they trust mods more than the official WhatsApp, we found two mods contained malware. The use of WhatsApp mods poses risks to mod users and those they communicate with, but also empowers users in ways that the official app does not. We caution developers and mod users to do their due diligence before using or distributing mods. Collins W. Munyendo, Kentrell Owens, Faith Strong, Adam J. Aviv, Tadayoshi Kohno, Franziska Roesner |
SP | 5 |
| 2025 | "It's been Lovely Watching you": Institutional Decision-Making on Online Proctoring SoftwareabstractUniversities have adopted remote proctoring software to maintain academic integrity during invigilated online exams. The use of this software, however, has raised privacy, security, and ethical concerns, including surveillance of students' bedrooms, processing of student data, and racially biased monitoring. Additionally, this software can require substantial local computer permissions. Prior work has explored student and educator perceptions and use of this software, but there remains a gap in understanding how senior administrators decide to adopt (or not adopt) these tools at an institutional level. This paper presents the results of interviews with 20 university administrators from the U.S. and Australia towards understanding how and why their universities decided to centrally adopt (or not adopt) remote proctoring software. We find that academic governance processes included senior administrators, legal, and IT teams, even during the rush at the start of the COVID-19 pandemic, but that students were sometimes structurally excluded from the process of adoption. We explore how administrators weighed the need for academic integrity against competing concerns about privacy, security, ethics, and long-term operational issues like cost. We find that universities adopted remote proctoring despite concerns about privacy and security, sometimes attempting to mitigate these concerns. As academia continues to explore hybrid learning, our research can guide institutions in the adoption of Educational Technologies and the assessment of student learning. Elisa Shioji, Ani Meliksetyan, Lucy Simko, Ryan Watkins, Adam J. Aviv, Shaanan Cohney |
SP | 5 |
| 2025 | How Researchers De-Identify Data in Practice
Wentao Guo 0005, Paige Pepitone, Adam J. Aviv, Michelle L. Mazurek |
USENIX Security Symposium | 3 |
| 2024 | A Qualitative Analysis of Practical De-Identification GuidesabstractDe-identifying microdata is necessary yet difficult. Myriad techniques exist, which reduce risk and preserve utility to varying, often unclear extents. We conducted a thematic analysis of 38 online de-identification guides for practitioners, to understand what content they contain and how they are designed to support decision-making and execution. We highlight trends and differences between guides, and we find some concerning patterns, including inconsistent definitions of key terms, gaps in coverage of threats to de-identification, and areas for improvement in usability. We identify directions for future research and suggest changes to de-identification guidance in order to better support practitioners in conducting effective de-identification. Wentao Guo 0005, Aditya Kishore, Adam J. Aviv, Michelle L. Mazurek |
CCS | 3 |
| 2024 | "Modern problems require modern solutions": Community-Developed Techniques for Online Exam Proctoring EvasionabstractCOVID-19 caused an abrupt shift towards remote learning, and along with it, an increased adoption of remote, online proctoring technology to both dissuade and identify academic dishonesty (i.e., cheating). This shift also came with significant discontent from students who took to online platforms to both express their displeasure with remote proctoring and the methods they used for evading monitoring methods, essentially discussing _hacks_ to subvert the software and cheat on exams. In this paper, we seek to understand both the methods this online community shares for evading online proctoring and why they do so. Through qualitative analysis of social media videos (n=137) and comments (n=4,297) on YouTube and TikTok, we find both non-technical (e.g., sticky-notes) and deeply technical (e.g., custom virtual machines) methods of evading proctoring. The online videos, as well as the active comment sections, provide an important window into both an (unethical) desire to cheat but also the development of a security mindset. Many see proctoring software as invasive surveillance technology, and the discussion and sharing of methods to subvert it have similar tones to that of the hacker/tinkerer communities who also seek to share their experiences of subverting technology, for fun and profit. We conclude with lessons for the security and privacy community about evading online exam proctoring, as well as a conversation about fairness and equity in proctoring design. Lucy Simko, Adryana Hutchinson, Alvin Isaac, Evan Fries, Micah Sherr, Adam J. Aviv |
CCS | 6 |
| 2024 | Honesty is the Best Policy: On the Accuracy of Apple Privacy Labels Compared to Apps' Privacy PoliciesabstractApple introduced privacy labels in Dec. 2020 as a way for developers to report the privacy behaviors of their apps. While Apple does not validate labels, they also require developers to provide a privacy policy, which offers an important comparison point. In this paper, we fine-tuned BERT-based language models to extract privacy policy features for 474,669 apps on the iOS App Store, comparing the output to the privacy labels. We identify discrepancies between the policies and the labels, particularly as they relate to data collected linked to users. We find that 228K apps' privacy policies may indicate data collection linked to users than what is reported in the privacy labels. More alarming, a large number (97%) of the apps with a Data Not Collected privacy label have a privacy policy indicating otherwise. We provide insights into potential sources for discrepancies, including the use of templates and confusion around Apple's definitions and requirements. These results suggest that significant work is still needed to help developers more accurately label their apps. Our system can be incorporated as a first-order check to inform developers when privacy labels are possibly misapplied. Mir Masood Ali, David G. Balash, Monica Kodwani, Chris Kanich, Adam J. Aviv |
Proc. Priv. Enhancing Technol. | 5 |
| 2024 | How Does Connecting Online Activities to Advertising Inferences Impact Privacy Perceptions?abstractData dashboards are designed to help users manage data collected about them. However, prior work showed that exposure to some dashboards, notably Google’s My Activity dashboard, results in significant decreases in perceived concern and increases in perceived benefit from data collection, contrary to expectations. We theorize that this result is due to the fact that data dashboards currently do not sufficiently “connect the dots” of the data food chain, that is, by connecting data collection with the use of that data. To evaluate this, we designed a study where participants assigned advertising interest labels to their own real activities, effectively acting as a behavioral advertising engine to “connect the dots.” When comparing pre- and post-labeling task responses, we find no significant difference in concern with Google’s data collection practices, which indicates that participants’ priors are maintained after more exposure to the data food chain (differing from prior work), suggesting that data dashboards that offer deeper perspectives of how data collection is used have potential. However, these gains are offset when participants are exposed to their true interest labels inferred by Google. Concern for data collection dropped significantly as participants viewed Google’s labeling as generic compared to their own more specific labeling. This presents a possible new paradox that must be overcome when designing data dashboards, the generic paradox, which occurs when users misalign individual, generic inferences from collected data as benign compared to the totality and specificity of many generic inferences made about them. Florian Farke, David G. Balash, Maximilian Golla, Adam J. Aviv |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | Encouraging Users to Change Breached Passwords Using the Protection Motivation TheoryabstractWe draw on the Protection Motivation Theory (PMT) to design interventions that encourage users to change breached passwords. Our online experiment ( \(n=1{,}386\) ) compared the effectiveness of a threat appeal (highlighting the negative consequences after passwords were breached) and a coping appeal (providing instructions on changing the breached password) in a 2 \(\times\) 2 factorial design. Compared to the control condition, participants receiving the threat appeal were more likely to intend to change their passwords, and participants receiving both appeals were more likely to end up changing their passwords. Participants’ password change behaviors are further associated with other factors, such as their security attitudes (SA-6) and time passed since the breach, suggesting that PMT-based interventions are useful but insufficient to fully motivate users to change their passwords. Our study contributes to PMT’s application in security research and provides concrete design implications for improving compromised credential notifications. Yixin Zou, Khue Le, Peter Mayer 0001, Alessandro Acquisti, Adam J. Aviv, Florian Schaub |
ACM Trans. Comput. Hum. Interact. | 5 |
| 2023 | Poster: Longitudinal Measurement of the Adoption Dynamics in Apple's Privacy Label EcosystemabstractThis work reports on a large scale, longitudinal analysis of the adoption dynamics of privacy labels in the iOS App Store, measuring this first-of-its kind ecosystem as it reaches maturity over two and a half years after launching in December 2020. The motivation is to shed light on the factors affecting the shifts in privacy labels and provide insights into how and when an app's label changes. By collecting nearly weekly snapshots of over 1.6 million apps for over a year, we analyze the dynamics of privacy label adoption and the accuracy of reported labels. Our analysis of 74.5% of apps having labels after two years provides important context into this mature ecosystem where labels are becoming the standard. However, we find compelling evidence that labels may not fully capture behavior, as 28.9% of apps indicate no data collection and distributions differ between voluntary versus mandatory adoptions. Once set, labels rarely change but additions reflect more data collection. In addition to our measurement, we also plan to release a new (and growing) data set that can be used by future researchers. David G. Balash, Mir Masood Ali, Monica Kodwani, Xiaoyuan Wu, Chris Kanich, Adam J. Aviv |
CCS | 6 |
| 2023 | "I just stopped using one and started using the other": Motivations, Techniques, and Challenges When Switching Password ManagersabstractThis paper explores what motivates password manager (PM) users in the US to switch from one PM to another, the techniques they employ when switching, and challenges they encounter throughout. Through a screener (n = 412) followed by a main survey (n = 54), we find that browser-based PMs are the most widely used, with most of these users motivated to use the PM due to convenience. Unfortunately, password reuse remains high. Most participants that switch PMs do so for usability reasons, but are also motivated by cost, as third-party PMs' full suite of features often require a subscription fee. Some PM-switchers are also motivated by recent security breaches, such as what was reported at LastPass in the Fall of 2022, with some participants losing trust in LastPass and PMs generally as a result. Those that switch mostly employ manual techniques of moving their passwords, e.g., copying and pasting their credentials from their previous to their new PM, despite most PMs offering ways to automatically transfer credentials in bulk across PMs. Assistance during the switching process is limited, with less than half of participants that switched receiving guidance during the switching process. From these findings, we make recommendations to PMs that can improve their overall user experience and use, including eliciting and acting on regular feedback from users as well as making PM settings more easily reachable and customizable by end-users. Collins W. Munyendo, Peter Mayer 0001, Adam J. Aviv |
CCS | 3 |
| 2023 | "In Eighty Percent of the Cases, I Select the Password for Them": Security and Privacy Challenges, Advice, and Opportunities at Cybercafes in KenyaabstractCybercafes remain a popular way to access the Internet in the developing world as many users still lack access to personal computers. Coupled with the recent digitization of government services, e.g. in Kenya, many users have turned to cybercafes to access essential services. Many of these users may have never used a computer, and face significant security and privacy issues at cybercafes. Yet, these challenges as well as the advice offered remain largely unexplored. We investigate these challenges along with the security advice and support provided by the operators at cybercafes in Kenya through n = 36 semi-structured interviews (n = 14 with cybercafe managers and n = 22 with customers). We find that cybercafes serve a crucial role in Kenya by enabling access to printing and government services. However, most customers face challenges with computer usage as well as security and usability challenges with account creation and password management. As a workaround, customers often rely on the support and advice of cybercafe managers who mostly direct them to use passwords that are memorable, e.g. simply using their national ID numbers or names. Some managers directly manage passwords for their customers, with one even using the same password for all their customers. These results suggest the need for more awareness about phone-based password managers, as well as a need for computer training and security awareness among these users. There is also a need to explore security and privacy advice beyond Western peripheries to support broader populations. Collins W. Munyendo, Yasemin Acar, Adam J. Aviv |
SP | 3 |
| 2023 | Educators' Perspectives of Using (or Not Using) Online Exam Proctoring
David G. Balash, Elena Korkes, Miles Grant, Adam J. Aviv, Rahel A. Fainchtein, Micah Sherr |
USENIX Security Symposium | 4 |
| 2023 | Awareness, Intention, (In)Action: Individuals' Reactions to Data BreachesabstractData breaches are prevalent. We provide novel insights into individuals’ awareness, perception, and responses to breaches that affect them through two online surveys: a main survey (n= 413) in which we presented participants with up to three breaches that affected them, and a follow-up survey (n= 108) in which we investigated whether the main study participants followed through with their intentions to act. Overall, 73% of participants were affected by at least one breach, but participants were unaware of 74% of breaches affecting them. Although some reported intention to take action, most participants believed the breach would not impact them. We also found a sizable intention-behavior gap. Participants did not follow through with their intention when they were apathetic about breaches, considered potential costs, forgot, or felt resigned about taking action. Our findings suggest that breached organizations should be held accountable for more proactively informing and protecting affected consumers. Peter Mayer 0001, Yixin Zou, Byron Lowens, Hunter A. Dyer, Khue Le, Florian Schaub, Adam J. Aviv |
ACM Trans. Comput. Hum. Interact. | 7 |
| 2022 | User Perceptions of the Privacy and Usability of Smart DNSabstractSmart DNS (SDNS) services enable their users to avoid geographic restrictions to content (i.e., geoblocking) with minimal internet quality of service overhead. While previous research has shown that usage of SDNS has numerous associated privacy risks, the security and privacy perceptions of users of SDNS are unexplored. In this paper, we perform a survey of n = 63 SDNS users, finding that many have limited understandings both of how these systems work and their overall security/privacy properties. As a result, many users put undue trust in purveyors of SDNS services and in the security they provide. Rahel A. Fainchtein, Adam J. Aviv, Micah Sherr |
ACSAC | 2 |
| 2022 | User Perceptions of Five-Word PasswordsabstractHuman-chosen passwords are often short, selected non-uniformly, and thus, susceptible to automated guessing attacks. To help users to select more secure but memorable passwords, experts have recommended the use of passphrases of multiple words or phrases. In this paper, we explore a strategy for passphrase selection, so-called five-word passwords, where users are assigned five random words for a passphrase. Such a password composition policy was recently adopted at Georgetown University in December 2020. Through a two-part online survey (n = 150 and n = 116), participants selected a five-word password under different conditions. We find that computer-generated five-word passwords are more diverse and likely more secure than five-word passwords users select themselves. While all cases of five-word passwords are likely more secure than a human-generated, traditional password, participants expressed misconceptions regarding the security of five-word passwords (and passwords generally). Five-word passwords also appear to negatively impact usability, only 39.7 % of participants successfully recalled their password after two weeks. While five-word passwords offer improvements for security, more outreach is needed to explain their security benefits and reduce usability burdens. Xiaoyuan Wu, Collins W. Munyendo, Eddie Cosic, Genevieve A. Flynn, Olivia Legault, Adam J. Aviv |
ACSAC | 6 |
| 2022 | Users Can Deduce Sensitive Locations Protected by Privacy Zones on Fitness Tracking AppsabstractFitness tracking applications allow athletes to record and share their exercises online, including GPS routes of their activities. However, sharing mobility data potentially raises real-world privacy and safety risks. One strategy to mitigate that risk is a “Privacy Zone,” which conceals portions of the exercise routes that fall within a certain radius of a user-designated sensitive location. A pressing concern is whether privacy zones are an effective deterrent against common attackers, such as a bike thief that carefully scrutinizes online exercise activities in search of their next target. Further, little is known about user perceptions of privacy zones or how they fit into the broader landscape of available privacy precautions. Jaron Mink, Amanda Rose Yuile, Uma Pal, Adam J. Aviv, Adam Bates 0001 |
CHI | 4 |
| 2022 | "Desperate Times Call for Desperate Measures": User Concerns with Mobile Loan Apps in KenyaabstractThe usage of mobile loan applications has proliferated in developing countries. This is due to the ease and speed in which they disburse small loans to users, compared to traditional financial institutions, such as banks, that only offer similar loans based on existing customer relationship or collateral. As mobile loan apps are a relatively new industry, these apps are mostly unregulated and therefore tend to charge extremely high interest rates. Further, they collect and sometimes misuse sensitive user data through the course of verifying customers and ensuring loan repayment, such as users’ contacts and SMS communications through the mobile device permission system. Yet, the reasons for usage as well as privacy concerns with these mobile loan apps in the developing world, and specifically in Kenya, remain largely unexplored. To investigate mobile loan apps, we conducted semi-structured interviews (n = 20) with loan app users in Kenya, and we find that most users generally have privacy concerns, particularly regarding access to their phones’ contacts. However, they often overlook these concerns as this outweighs their need to procure loans. At the same time, we find that users struggle to understand the use of permissions by these mobile loan apps (and mobile apps generally), confirming prior research on comprehension of Android permissions. Our results highlight privacy risks, concerns and behavior with the emerging mobile loan app marketplace in the developing world, and we offer recommendations that can help protect their users’ security and privacy, including the need for transparent communication by these apps on how they collect, use and secure their users’ data. Collins W. Munyendo, Yasemin Acar, Adam J. Aviv |
SP | 3 |
| 2022 | Security and Privacy Perceptions of Third-Party Application Access for Google Accounts
David G. Balash, Xiaoyuan Wu, Miles Grant, Irwin Reyes, Adam J. Aviv |
USENIX Security Symposium | 5 |
| 2022 | Why Users (Don't) Use Password Managers at a Large Educational Institution
Peter Mayer 0001, Collins W. Munyendo, Michelle L. Mazurek, Adam J. Aviv |
USENIX Security Symposium | 4 |
| 2022 | "The Same PIN, Just Longer": On the (In)Security of Upgrading PINs from 4 to 6 Digits
Collins W. Munyendo, Philipp Markert, Alexandra Nisenoff, Miles Grant, Elena Korkes, Blase Ur, Adam J. Aviv |
USENIX Security Symposium | 7 |
| 2021 | Improving Signal's Sealed Sender
Ian Martiny, Gabriel Kaptchuk, Adam J. Aviv, Daniel S. Roche, Eric Wustrow |
NDSS | 3 |
| 2021 | Are Privacy Dashboards Good for End Users? Evaluating User Perceptions and Reactions to Google's My Activity
Florian Farke, David G. Balash, Maximilian Golla, Markus Dürmuth, Adam J. Aviv |
USENIX Security Symposium | 5 |
| 2021 | "Now I'm a bit angry: " Individuals' Awareness, Perception, and Responses to Data Breaches that Affected Them
Peter Mayer 0001, Yixin Zou, Florian Schaub, Adam J. Aviv |
USENIX Security Symposium | 4 |
| 2021 | Why Older Adults (Don't) Use Password Managers
Hirak Ray, Flynn Wolf, Ravi Kuber, Adam J. Aviv |
USENIX Security Symposium | 4 |
| 2021 | Strategies and Perceived Risks of Sending Sensitive Documents
Noel Warford, Collins W. Munyendo, Ashna Mediratta, Adam J. Aviv, Michelle L. Mazurek |
USENIX Security Symposium | 4 |
| 2021 | Security Obstacles and Motivations for Small Businesses from a CISO's Perspective
Flynn Wolf, Adam J. Aviv, Ravi Kuber |
USENIX Security Symposium | 2 |
| 2021 | Holes in the Geofence: Privacy Vulnerabilities in "Smart" DNS ServicesabstractSmart DNS (SDNS) services advertise access to geofenced content (typically, video streaming sites such as Netflix or Hulu) that is normally inaccessible unless the client is within a prescribed geographic region. SDNS is simple to use and involves no software installation. Instead, it requires only that users modify their DNS settings to point to an SDNS resolver. The SDNS resolver “smartly” identifies geofenced domains and, in lieu of their proper DNS resolutions, returns IP addresses of proxy servers located within the geofence. These servers then transparently proxy traffic between the users and their intended destinations, allowing for the bypass of these geographic restrictions. Rahel A. Fainchtein, Adam J. Aviv, Micah Sherr, Stephen Ribaudo, Armaan Khullar |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | "Warn Them" or "Just Block Them"?: Investigating Privacy Concerns Among Older and Working Age AdultsabstractAbstract Prior work suggests that older adults are less aware of potential digital privacy risks compared to younger groups. We seek to expand on these findings by using drawmetrics with 20 older adults (60+) to visualize their experiences with digital privacy via drawing sessions. We further compared older adults with 20 adults of working age (18-59) with the goal of identifying both overlapping concerns and key differences that may be missed when viewing each group in isolation. We extended our evaluation with a survey with questions and themes derived from open-coding of the drawn images and confirmed three key differences between the age groups. These include older adults perceiving a greater threat from using online banking and e-commerce compared to working age adults, older adults exhibiting greater levels of concern about global scale threats, and working age adults showing more privacy-related concern regarding social media. Our findings can be used to potentially tailor applications to better accommodate privacy concerns for older adults. Hirak Ray, Flynn Wolf, Ravi Kuber, Adam J. Aviv |
Proc. Priv. Enhancing Technol. | 4 |
| 2021 | On the Security of Smartphone Unlock PINsabstractIn this article, we provide the first comprehensive study of user-chosen four- and six-digit PINs ( n =1705) collected on smartphones with participants being explicitly primed for device unlocking. We find that against a throttled attacker (with 10, 30, or 100 guesses, matching the smartphone unlock setting), using six-digit PINs instead of four-digit PINs provides little to no increase in security and surprisingly may even decrease security. We also study the effects of blocklists, where a set of “easy to guess” PINs is disallowed during selection. Two such blocklists are in use today by iOS, for four digits (274 PINs) as well as six digits (2,910 PINs). We extracted both blocklists and compared them with six other blocklists, three for each PIN length. In each case, we had a small (four-digit: 27 PINs; six-digit: 29 PINs), a large (four-digit: 2,740 PINs; six-digit: 291,000 PINs), and a placebo blocklist that always excluded the first-choice PIN. For four-digit PINs, we find that the relatively small blocklist in use today by iOS offers little to no benefit against a throttled guessing attack. Security gains are only observed when the blocklist is much larger. In the six-digit case, we were able to reach a similar security level with a smaller blocklist. As the user frustration increases with the blocklists size, developers should employ a blocklist that is as small as possible while ensuring the desired security. Based on our analysis, we recommend that for four-digit PINs a blocklist should contain the 1,000 most popular PINs to provide the best balance between usability and security and for six-digit PINs the 2,000 most popular PINs should be blocked. Philipp Markert, Daniel V. Bailey, Maximilian Golla, Markus Dürmuth, Adam J. Aviv |
ACM Trans. Priv. Secur. | 5 |
| 2020 | Double Patterns: A Usable Solution to Increase the Security of Android Unlock PatternsabstractAndroid unlock patterns are still commonly used, and roughly 25% of the respondents to our study use a pattern when unlocking their phone. Despite security issues, the design of the patterns have remained unchanged. We propose Double Patterns (DPatts), a natural advancement on Android unlock patterns that maintains the core design but instead of selecting a single pattern, a user selects two patterns entered one-after-the-other super-imposed on the same 3x3 grid. We evaluated DPatts for both security and usability through an online study (n = 634) with three treatments: a control a first pattern entry blocklist, and a blocklist for both patterns. We find that in all settings, user chosen DPatts are more secure than traditional patterns based on standard guessability metrics, more similar to that of 4-/6-digit PINs, and even more difficult to guess for a simulated attacker. Users express positive sentiments in qualitative feedback, particularly those who currently (or previously) used Android unlock patterns, and overall, participants found the DPatts interface quite usable, with high recall retention and comparable entry times to traditional patterns. In particular, current Android pattern users, the target population for DPatts, reported SUS scores in the 80th percentile and high perceptions of security and usability in responses to open- and closed-questions. Based on these findings, we would recommend adding DPatts as an advancement to Android patterns, much like allowing for added PIN length. Timothy J. Forman, Adam J. Aviv |
ACSAC | 2 |
| 2020 | Widely Reused and Shared, Infrequently Updated, and Sometimes Inherited: A Holistic View of PIN Authentication in Digital Lives and BeyondabstractPersonal Identification Numbers (PINs) are widely used as an access control mechanism for digital assets (e.g., smartphones), financial assets (e.g., ATM cards), and physical assets (e.g., locks for garage doors or homes). Using semi-structured interviews (n=35), participants reported on PIN usage for different types of assets, including how users choose, share, inherit, and reuse PINs, as well as behaviour following the compromise of a PIN. We find that memorability is the most important criterion when choosing a PIN, more so than security or concerns of reuse. Updating or changing a PIN is very uncommon, even when a PIN is compromised. Participants reported sharing PINs for one type of asset with acquaintances but inadvertently reused them for other assets, thereby subjecting themselves to potential risks. Participants also reported using PINs originally set by previous homeowners for physical devices (e.g., alarm or keypad door entry systems). While aware of the risks of not updating PINs, this did not always deter participants from using inherited PINs, as they were often missing instructions on how to update them. Given the expected increase in PIN-protected assets (e.g., loyalty cards, smart locks, and web apps), we provide suggestions and future research directions to better support users with multiple digital and non-digital assets and more secure human-device interaction when utilizing PINs. Hassan Khan 0002, Jason Ceci, Jonah Stegman, Adam J. Aviv, Rozita Dara 0001, Ravi Kuber |
ACSAC | 4 |
| 2020 | This PIN Can Be Easily Guessed: Analyzing the Security of Smartphone Unlock PINsabstractWe provide the first comprehensive study of user-chosen 4- and 6-digit PINs (n = 1220) collected on smartphones with participants being explicitly primed for device unlocking. We find that against a throttled attacker (with 10, 30, or 100 guesses, matching the smartphone unlock setting), using 6-digit PINs instead of 4-digit PINs provides little to no increase in security, and surprisingly may even decrease security. We also study the effects of blacklists, where a set of "easy to guess" PINs is disallowed during selection. Two such blacklists are in use today by iOS, for 4-digits (274 PINs) as well as 6-digits (2910 PINs). We extracted both blacklists compared them with four other blacklists, including a small 4-digit (27 PINs), a large 4-digit (2740 PINs), and two placebo blacklists for 4- and 6-digit PINs that always excluded the first-choice PIN. We find that relatively small blacklists in use today by iOS offer little or no benefit against a throttled guessing attack. Security gains are only observed when the blacklists are much larger, which in turn comes at the cost of increased user frustration. Our analysis suggests that a blacklist at about 10 % of the PIN space may provide the best balance between usability and security. Philipp Markert, Daniel V. Bailey, Maximilian Golla, Markus Dürmuth, Adam J. Aviv |
SP | 5 |
| 2019 | "Pretty Close to a Must-Have": Balancing Usability Desire and Security Concern in Biometric AdoptionabstractWe report on a qualitative inquiry among security-expert and non-expert mobile device users about the adoption of biometric authentication using semi-structured interviews(n=38, 19/19 expert/non-expert). Security experts more readily adopted biometrics than non-experts but also harbored greater distrust towards its use for sensitive transactions,feared biometric signature compromise, and in some cases distrusted newer facial recognition methods. Both groups harbored misconceptions, such as misunderstanding of the functional role of biometrics in authentication, and were about equally likely to have stopped using biometrics due to usability. Implications include the need for tailored training for security-informed advocates, better design for device sharing and co-registration, and consideration for usability needs in work environments. Refinement of these features would remove perceived obstacles to ubiquitous computing among the growing population of mobile technology users sensitized to security risk. Flynn Wolf, Ravi Kuber, Adam J. Aviv |
CHI | 3 |
| 2019 | rORAM: Efficient Range ORAM with O(log2 N) Locality
Anrin Chakraborti, Adam J. Aviv, Seung Geol Choi, Travis Mayberry, Daniel S. Roche, Radu Sion |
NDSS | 2 |
| 2018 | Comparing Video Based Shoulder Surfing with Live SimulationabstractWe analyze the claims that video recreations of shoulder surfing attacks offer a suitable alternative and a baseline, as compared to evaluation in a live setting. We recreated a subset of the factors of a prior video-simulation experiment conducted by Aviv et al. (ACSAC 2017), and model the same scenario using live participants (n = 36) instead (i.e., the victim and attacker were both present). The live experiment confirmed that for Android's graphical patterns video simulation is consistent with the live setting for attacker success rates. However, both 4- and 6-digit PINs demonstrate statistically significant differences in attacker performance, with live attackers performing as much 1.9x better than in the video simulation. The security benefits gained from removing feedback lines in Android's graphical patterns are also greatly diminished in the live setting, particularly under multiple attacker observations, but overall, the data suggests that video recreations can provide a suitable baseline measure for attacker success rate. However, we caution that researchers should consider that these baselines may greatly underestimate the threat of an attacker in live settings. Adam J. Aviv, Flynn Wolf, Ravi Kuber |
ACSAC | 1 |
| 2018 | Turboflow: information rich flow record generation on commodity switchesabstractFine-grained traffic flow records enable many powerful applications, especially in combination with telemetry systems that supports high coverage, i.e., of every link and at all times. Current solutions, however, make undesirable trade-offs between infrastructure cost and information richness. Switches that generate flow records, e.g., NetFlow switches, are a low cost solution but current designs sacrifice information richness, e.g., by sampling. Information rich alternatives rely heavily on servers, which increases cost to the point that they are impractical for high coverage. In this paper, we present the design, implementation, and evaluation of TurboFlow, a flow record generator for programmable switches that does not compromise on either cost or information richness. TurboFlow produces fine- grained and unsampled flow records with custom features entirely at the switch without relying on any support from external servers. This is a challenge given high traffic rates and the limitations of switch hardware. To overcome, we decompose the flow record generation algorithm and optimize it for the heterogeneous processors in programmable switches. We show that with this design, TurboFlow can support multi-terabit workloads on readily available commodity switches to enable information rich monitoring with high coverage. John Sonchack, Adam J. Aviv, Eric Keller, Jonathan M. Smith |
EuroSys | 2 |
| 2018 | Scaling Hardware Accelerated Network Monitoring to Concurrent and Dynamic Queries With *Flow
John Sonchack, Oliver Michel, Adam J. Aviv, Eric Keller, Jonathan M. Smith |
USENIX ATC | 3 |
| 2018 | An empirical study examining the perceptions and behaviours of security-conscious users of mobile authenticationabstractThe purpose of this study is to better understand, from an explorative qualitative perspective, the motivations and practices of highly security-conscious users of mobile authentication, and their underlying mental models of those behaviours. Mobile authentication studies have largely overlooked the mindset of these users in the upper bound of security experience, who have considered their behaviour in terms of detailed knowledge of mobile authentication risk. Twenty IT professionals who self-identified as security-conscious mobile device users, many with decades of intensive security-specific experience, were interviewed for this study regarding their opinions and experiences with mobile device authentication and security. These users described usability and situational impairment issues, as well as a deep concern for their identity and data security arising from highly contextual combinations of distrust towards underlying technologies and situational risk. Derived implications for development of security methods adapted to these informed perspectives are discussed and will be the basis for follow-on research comparing these findings with everyday users. Flynn Wolf, Ravi Kuber, Adam J. Aviv |
Behav. Inf. Technol. | 3 |
| 2018 | "It's all about the start" classifying eyes-free mobile authentication techniques
Flynn Wolf, Adam J. Aviv, Ravi Kuber |
J. Inf. Secur. Appl. | 2 |
| 2018 | A Video-based Attack for Android Pattern LockabstractPattern lock is widely used for identification and authentication on Android devices. This article presents a novel video-based side channel attack that can reconstruct Android locking patterns from video footage filmed using a smartphone. As a departure from previous attacks on pattern lock, this new attack does not require the camera to capture any content displayed on the screen. Instead, it employs a computer vision algorithm to track the fingertip movement trajectory to infer the pattern. Using the geometry information extracted from the tracked fingertip motions, the method can accurately infer a small number of (often one) candidate patterns to be tested by an attacker. We conduct extensive experiments to evaluate our approach using 120 unique patterns collected from 215 independent users. Experimental results show that the proposed attack can reconstruct over 95% of the patterns in five attempts. We discovered that, in contrast to most people’s belief, complex patterns do not offer stronger protection under our attacking scenarios. This is demonstrated by the fact that we are able to break all but one complex patterns (with a 97.5% success rate) as opposed to 60% of the simple patterns in the first attempt. We demonstrate that this video-side channel is a serious concern for not only graphical locking patterns but also PIN-based passwords, as algorithms and analysis developed from the attack can be easily adapted to target PIN-based passwords. As a countermeasure, we propose to change the way the Android locking pattern is constructed and used. We show that our proposal can successfully defeat this video-based attack. We hope the results of this article can encourage the community to revisit the design and practical use of Android pattern lock. Guixin Ye, Zhanyong Tang, Dingyi Fang, Xiaojiang Chen, Willy Wolff, Adam J. Aviv, Zheng Wang 0001 |
ACM Trans. Priv. Secur. | 6 |
| 2017 | Towards Baselines for Shoulder Surfing on Mobile AuthenticationabstractGiven the nature of mobile devices and unlock procedures, unlock authentication is a prime target for credential leaking via shoulder surfing, a form of an observation attack. While the research community has investigated solutions to minimize or prevent the threat of shoulder surfing, our understanding of how the attack performs on current systems is less well studied. In this paper, we describe a large online experiment (n = 1173) that works towards establishing a baseline of shoulder surfing vulnerability for current unlock authentication systems. Using controlled video recordings of a victim entering in a set of 4- and 6-length PINs and Android unlock patterns on different phones from different angles, we asked participants to act as attackers, trying to determine the authentication input based on the observation. We find that 6-digit PINs are the most elusive attacking surface where a single observation leads to just 10.8% successful attacks (26.5% with multiple observations). As a comparison, 6-length Android patterns, with one observation, were found to have an attack rate of 64.2% (79.9% with multiple observations). Removing feedback lines for patterns improves security to 35.3% (52.1% with multiple observations). This evidence, as well as other results related to hand position, phone size, and observation angle, suggests the best and worst case scenarios related to shoulder surfing vulnerability which can both help inform users to improve their security choices, as well as establish baselines for researchers. Adam J. Aviv, John T. Davin, Flynn Wolf, Ravi Kuber |
ACSAC | 1 |
| 2017 | Perceptions of Mobile Device Authentication Mechanisms by Individuals who are BlindabstractThis paper describes an exploratory study focusing on the methods of mobile authentication currently utilized by individuals who are blind. Perceptions of security are discussed, along with the trade-offs with usability and accessibility. A tactile aid for a mobile authentication interface was introduced to participants to obtain preliminary feedback on its design. The aid was found to offer promise for supporting orientation, which could be used support novice users, and provide assistance when the mobile device must be used privately in public spaces. Flynn Wolf, Ravi Kuber, Adam J. Aviv |
ASSETS | 3 |
| 2017 | Deterministic, Stash-Free Write-Only ORAMabstractWrite-Only Oblivious RAM (WoORAM) protocols provide privacy by encrypting the contents of data and also hiding the pattern of write operations over that data. WoORAMs provide better privacy than plain encryption and better performance than more general ORAM schemes (which hide both writing and reading access patterns), and the write-oblivious setting has been applied to important applications of cloud storage synchronization and encrypted hidden volumes. In this paper, we introduce an entirely new technique for Write-Only ORAM, called DetWoORAM. Unlike previous solutions, DetWoORAM uses a deterministic, sequential writing pattern without the need for any "stashing" of blocks in local state when writes fail. Our protocol, while conceptually simple, provides substantial improvement over prior solutions, both asymptotically and experimentally. In particular, under typical settings the DetWoORAM writes only 2 blocks (sequentially) to backend memory for each block written to the device, which is optimal. We have implemented our solution using the BUSE (block device in user-space) module and tested DetWoORAM against both an encryption only baseline of dm-crypt and prior, randomized WoORAM solutions, measuring only a 3x-14x slowdown compared to an encryption-only baseline and around 6x-19x speedup compared to prior work. Daniel S. Roche, Adam J. Aviv, Seung Geol Choi, Travis Mayberry |
CCS | 2 |
| 2017 | ObliviSync: Practical Oblivious File Backup and Synchronization
Adam J. Aviv, Seung Geol Choi, Travis Mayberry, Daniel S. Roche |
NDSS | 1 |
| 2016 | Managing Cloud Storage ObliviouslyabstractConsumers want to ensure that their enterprise data is stored securely and obliviously on the cloud, such that the data objects or their access patterns are not revealed to anyone, including the cloud provider, in the public cloud environment. We have created a detailed ontology describing the oblivious cloud storage models and role based access controls that should be in place to manage this risk. We have developed an algorithm to store cloud data using oblivious data structure defined in this paper. We have also implemented the ObliviCloudManager application that allows users to manage their cloud data by validating it before storing it in an oblivious data structure. Our application uses role-based access control model and collection based document management to store and retrieve data efficiently. Cloud consumers can use our system to define policies for storing data obliviously and manage storage on untrusted cloud platforms even if they are unfamiliar with the underlying technology and concepts of oblivious data structures. Vaishali Narkhede, Karuna P. Joshi, Adam J. Aviv, Seung Geol Choi, Daniel S. Roche, Tim Finin |
CLOUD | 3 |
| 2016 | Timing-based reconnaissance and defense in software-defined networks
John Sonchack, Anurag Dubey, Adam J. Aviv, Jonathan M. Smith, Eric Keller |
ACSAC | 3 |
| 2016 | Enabling Practical Software-defined Networking Security Applications with OFX
John Sonchack, Jonathan M. Smith, Adam J. Aviv, Eric Keller |
NDSS | 3 |
| 2016 | A Practical Oblivious Map Data Structure with Secure Deletion and History IndependenceabstractWe present a new oblivious RAM that supports variable-sized storage blocks (vORAM), which is the first ORAM to allow varying block sizes without trivial padding. We also present a new history-independent data structure (a HIRB tree) that can be stored within a vORAM. Together, this construction provides an efficient and practical oblivious data structure (ODS) for a key/value map, and goes further to provide an additional privacy guarantee as compared to prior ODS maps: even upon client compromise, deleted data and the history of old operations remain hidden to the attacker. We implement and measure the performance of our system using Amazon Web Services, and the single-operation time for a realistic database (up to 256K entries) is less than 1 second. This represents a 100x speed-up compared to the current best oblivious map data structure (which provides neither secure deletion nor history independence) by Wang et al. (CCS 14). Daniel S. Roche, Adam J. Aviv, Seung Geol Choi |
IEEE Symposium on Security and Privacy | 2 |
| 2016 | Exploring large scale security system reproducibility with the LESS simulatorabstractMany network security systems analyze large scale data collected from multiple collaborating domains or aggregated network vantage points. Scale is clearly beneficial for these systems, however it also makes them difficult to design and test. Large scale data sets can be difficult to acquire and may not contain important meta-information (e.g. ground truth). Further, their limited availability can make it extremely difficult to understand how well experimental results would reproduce in different conditions, or at different networks. In this article, we discuss using simulation to overcome these challenges. We present an augmented version of LESS, our recently proposed agent based simulator for evaluating large scale network security systems. LESS uses publicly available data sets and high level parameters to generate synthetic traffic that models large scale, multi-network scenarios. Essentially, LESS allows researchers to “scale up” the data and statistics about networks and attacks that they have access to, so that they can be used to test large scale network security systems. Researchers can also tune LESS’s high level parameters to better understand the sensitivities of their systems, and the reproducibility of their results. The version of LESS that we discuss in this article is extended to allow researchers to study an additional factor of system performance related to reproducibility: deployment location; by modeling the global Internet topology at the Autonomous System level. We demonstrate the applicability and benefits of LESS by tuning it with publicly available traces and then using generated records to reproduce and extend results from several recently proposed large scale security systems. In new experiments, we use LESS to study how deployment location affects large scale security systems. Our results demonstrate that LESS can evoke realistic performance from these systems with minimal tuning and provide insight into the network and topological factors that may affect the reproducibility of their evaluations. John Sonchack, Adam J. Aviv |
J. Comput. Secur. | 2 |
| 2015 | Is Bigger Better? Comparing User-Generated Passwords on 3x3 vs. 4x4 Grid Sizes for Android's Pattern UnlockabstractAndroid's graphical authentication mechanism requires users to unlock their devices by "drawing" a pattern that connects a sequence of contact points arranged in a 3x3 grid. Prior studies demonstrated that human-generated 3x3 patterns are weak (CCS'13); large portions can be trivially guessed with sufficient training. An obvious solution would be to increase the grid size to increase the complexity of chosen patterns. In this paper we ask the question: Does increasing the grid size increase the security of human-generated patterns? We conducted two large studies to answer this question, and our analysis shows that for both 3x3 and 4x4 patterns, there is a high incidence of repeated patterns and symmetric pairs (patterns that derive from others based on a sequence of flips and rotations), and many 4x4 patterns are expanded versions of 3x3 patterns. Leveraging this information, we developed an advanced guessing algorithm and used it to quantified the strength of the patterns using the partial guessing entropy. We find that guessing the first 20% (G0.2) of patterns for both 3x3 and 4x4 can be done as efficiently as guessing a random 2-digit PIN. While guessing larger portions of 4x4 patterns (G0.5) requires 2-bits more entropy than guessing the same ratio of 3x3 patterns, it remains on the order of cracking random 3-digit PINs. Of the patterns tested, our guessing algorithm successful cracks 15% of 3x3 patterns within 20 guesses (a typical phone lockout) and 19% of 4x4 patterns within 20 guesses; however, after 50,000 guesses, we correctly guess 95.9% of 3x3 patterns but only 66.7% of 4x4 patterns. While there may be some benefit to expanding the grid size to 4x4, we argue the majority of patterns chosen by users will remain trivially guessable and insecure against broad guessing attacks. Adam J. Aviv, Devon Budzitowski, Ravi Kuber |
ACSAC | 1 |
| 2015 | POSTER: OFX: Enabling OpenFlow Extensions for Switch-Level Security ApplicationsabstractNetwork Security applications that run on Software Defined Networks (SDNs) often need to analyze and process traffic in advanced ways. Existing approaches to adding such functionality to SDNs suffer from either poor performance, or poor deployability. In this paper, we propose and benchmark OFX: an OpenFlow extension framework that provides a better tradeoff between performance and deployability for SDN security applications by allowing them to dynamically install software modules onto network switches. John Sonchack, Adam J. Aviv, Eric Keller, Jonathan M. Smith |
CCS | 2 |
| 2015 | Cross-domain collaboration for improved IDS rule set selection
John Sonchack, Adam J. Aviv, Jonathan M. Smith |
J. Inf. Secur. Appl. | 2 |
| 2014 | Understanding visual perceptions of usability and security of Android's graphical password patternabstractThis paper reports the results of a user study of the Android graphical password system using an alternative survey methodology, pairwise preferences, that requests participants to select between pairs of patterns indicating either a security or usability preference. By carefully selecting password pairs to isolate a visual feature, a visual perception of usability and security of different features can be measured. We conducted a large IRB-approved survey using pairwise preferences which attracted 384 participants on Amazon Mechanical Turk. Analyzing the results, we find that visual features that can be attributed to complexity indicated a stronger perception of security, while spatial features, such as shifts up/down or left/right are not strong indicators for security or usability. We extended and applied the survey data by building logistic models to predict perception preferences by training on features used in the survey and other features proposed in related work. The logistic model accurately predicted preferences above 70%, twice the rate of random guessing, and the strongest feature in classification is password distance, the total length of all lines in the pattern, a feature not used in the online survey. This result provides insight into the internal visual calculus of users when comparing choices and selecting visual passwords, and the ultimate goal of this work is to leverage the visual calculus to design systems where inherent perceptions for usability coincides with a known metric of security. Adam J. Aviv, Dane Fichter |
ACSAC | 1 |
| 2014 | LESS Is More: Host-Agent Based Simulator for Large-Scale Evaluation of Security Systems
John Sonchack, Adam J. Aviv |
ESORICS (2) | 2 |
| 2014 | Privacy-aware message exchanges for HumaNets
Adam J. Aviv, Matt Blaze, Micah Sherr, Jonathan M. Smith |
Comput. Commun. | 1 |
| 2012 | Practicality of accelerometer side channels on smartphonesabstractModern smartphones are equipped with a plethora of sensors that enable a wide range of interactions, but some of these sensors can be employed as a side channel to surreptitiously learn about user input. In this paper, we show that the accelerometer sensor can also be employed as a high-bandwidth side channel; particularly, we demonstrate how to use the accelerometer sensor to learn user tap- and gesture-based input as required to unlock smartphones using a PIN/password or Android's graphical password pattern. Using data collected from a diverse group of 24 users in controlled (while sitting) and uncontrolled (while walking) settings, we develop sample rate independent features for accelerometer readings based on signal processing and polynomial fitting techniques. In controlled settings, our prediction model can on average classify the PIN entered 43% of the time and pattern 73% of the time within 5 attempts when selecting from a test set of 50 PINs and 50 patterns. In uncontrolled settings, while users are walking, our model can still classify 20% of the PINs and 40% of the patterns within 5 attempts. We additionally explore the possibility of constructing an accelerometer-reading-to-input dictionary and find that such dictionaries would be greatly challenged by movement-noise and cross-user training. Adam J. Aviv, Benjamin Sapp, Matt Blaze, Jonathan M. Smith |
ACSAC | 1 |
| 2012 | Privacy-Aware Message Exchanges for Geographically Routed Human Movement Networks
Adam J. Aviv, Micah Sherr, Matt Blaze, Jonathan M. Smith |
ESORICS | 1 |
| 2010 | Spam mitigation using spatio-temporal reputations from blacklist historyabstractIP blacklists are a spam filtering tool employed by a large number of email providers. Centrally maintained and well regarded, blacklists can filter 80+% of spam without having to perform computationally expensive content-based filtering. However, spammers can vary which hosts send spam (often in intelligent ways), and as a result, some percentage of spamming IPs are not actively listed on any blacklist. Blacklists also provide a previously untapped resource of rich historical information. Leveraging this history in combination with spatial reasoning, this paper presents a novel reputation model (PreSTA), designed to aid in spam classification. In simulation on arriving email at a large university mail system, PreSTA is capable of classifying up to 50% of spam not identified by blacklists alone, and 93% of spam on average (when used in combination with blacklists). Further, the system is consistent in maintaining this blockage-rate even during periods of decreased blacklist performance. PreSTA is scalable and can classify over 500,000 emails an hour. Such a system can be implemented as a complementary blacklist service or used as a first-level filter or prioritization mechanism on an email server. Andrew G. West, Adam J. Aviv, Insup Lee 0001 |
ACSAC | 2 |
| 2010 | Evading Cellular Data Monitoring with Human Movement Networks
Adam J. Aviv, Micah Sherr, Matt Blaze, Jonathan M. Smith |
HotSec | 1 |
| 2007 | SSARES: Secure Searchable Automated Remote Email StorageabstractThe increasing centralization of networked services places user data at considerable risk. For example, many users store email on remote servers rather than on their local disk. Doing so allows users to gain the benefit of regular backups and remote access, but it also places a great deal of unwarranted trust in the server. Since most email is stored in plaintext, a compromise of the server implies the loss of confidentiality and integrity of the email stored therein. Although users could employ an end-to-end encryption scheme (e.g., PGP), such measures are not widely adopted, require action on the sender side, only provide partial protection (the email headers remain in the clear), and prevent the users from performing some common operations, such as server-side search. To address this problem, we present secure searchable automated remote email storage (SSARES), a novel system that offers a practical approach to both securing remotely stored email and allowing privacy-preserving search of that email collection. Our solution encrypts email (the headers, body, and attachments) as it arrives on the server using public-key encryption. SSARES uses a combination of identity based encryption and bloom filters to create a searchable index. This index reveals little information about search keywords and queries, even against adversaries that compromise the server. SSARES remains largely transparent to both the sender and recipient. Adam J. Aviv, Michael E. Locasto, Shaya Potter, Angelos D. Keromytis |
ACSAC | 1 |