VLDB 2026 Research / reviewers in the wild / expert
Mathieu Cunche
dblp:94/3392
· DBLP profile ↗
38ranked-venue papers
5as first author
15since 2021 · last 2026
0000-0002-0066-8612ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 1 first-author · 11 since 2021Computer networks · 11 · 3 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | How Tough Is Location Anonymization? Re-identifying 100K Real-User Trajectories in JapanabstractMobility traces are among the most revealing forms of personal data, yet trajectory releases are often protected only by ad hoc transformations. We stress-test such practices on recently-released YJMob100K, an anonymized dataset of 100,000 user trajectories in Japan. First, we show that the applied protection leaves enough spatial and temporal structure to recover both the real-world geographic frame and the actual calendar timeline by exploiting density signatures, urban correlations, and temporal activity profiles. On top of this reconstruction, we quantify privacy risks through trajectory-level metrics that capture spatio-temporal k-anonymity, m-point unicity, home-work and multi-anchor uniqueness, and exposure to secluded and sensitive locations. These metrics reveal extensive re-identification surfaces: a small number of observations, anchors, or sensitive venues often suffices to uniquely pinpoint users or their social neighborhoods. Finally, we evaluate representative sanitization strategies: geo-indistinguishability, local differential privacy, and aggressive spatial de-structuring; and observe a consistent pattern: strong privacy parameters destroy downstream utility, while utility-preserving settings leave structural leakage largely intact. Overall, our findings show that current sanitization techniques are insufficient for large-scale mobility data, and they highlight the urgent need for trajectory-aware privacy mechanisms and stronger publication standards. Abhishek Kumar Mishra 0001, Mathieu Cunche, Héber Hwang Arcolezi |
AsiaCCS | 2 |
| 2026 | StateFi: Effectively Identifying Wi-Fi Devices through State TransitionsabstractRandomized MAC addresses aim to prevent passive device tracking, yet Wi-Fi management frames still leak structured behavioral patterns. Prior work has relied primarily on syntactic probe-request features such as Information Elements (IEs), sequence numbers (SEQ), or RSSI correlations, which degrade in dense environments and fail under aggressive randomization. We introduce StateFi, a fingerprinting framework that models device behavior as finite-state machines (FSMs), capturing both structural transition patterns and temporal execution logic. These FSMs are embedded into compact feature vectors that support efficient similarity computation and supervised classification. Across five heterogeneous campus environments, StateFi achieves 94-97% accuracy for in-network fingerprinting using full management-frame FSMs. With probe-only FSMs, it re-identifies devices under MAC randomization with up to 97% accuracy across large public datasets comprising more than a million frames. When looking at the discrimination accuracy of the model, StateFi reaches 98%, outperforming the strongest prior signature by up to 17 percentage points. These results demonstrate that FSM-level behavioral dynamics form a powerful and largely unmitigated side channel, stable enough to defeat randomization and expressive enough for robust, scalable device identification. Abhishek Kumar Mishra 0001, Mathieu Cunche |
WISEC | 2 |
| 2026 | From Lookup to Lockdown: DNS Guidelines for Securing IoT EcosystemsabstractThe Domain Name System (DNS) serves as a fundamental component of Internet infrastructure; however, its frequently overlooked role in consumer Internet of Things (IoT) ecosystems exposes significant security vulnerabilities and operational challenges. This paper analyzes DNS behavior in consumer IoT devices and reveals widespread inconsistencies that undermine operational efficiency, resilience, and security. We construct a representative testbed spanning a heterogeneous set of IoT devices and employ both passive traffic monitoring and active experimentation to identify vulnerabilities, including cache poisoning, predictable transaction IDs, non-randomized source ports, and limited adoption of secure DNS protocols such as DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and Domain Name System Security Extensions (DNSSEC). We observe erratic operational patterns, such as excessive querying, poor adherence to TTL values, and overreliance on hard-coded resolvers, that amplify exposure to fingerprinting and denial-of-service attacks. Our findings demonstrate a concerning lack of standardized DNS practices across the IoT ecosystem. We conclude by proposing actionable guidelines to harden DNS handling in IoT devices and improve security, interoperability, and network stability as the consumer IoT landscape continues to expand. Andrew Losty, Abhishek Kumar Mishra 0001, Mathieu Cunche, Anna Maria Mandalari |
IEEE Internet Things J. | 3 |
| 2026 | SoK: Mapping the Privacy Landscape of Geolocation EcosystemsabstractModern geolocation ecosystems rely on diverse technical solutions and architectures, often proprietary, making it difficult to develop a global understanding of the privacy implications of location data production. This challenge is particularly critical given the ubiquity of geolocation in modern digital infrastructures and the central role of location data in privacy concerns. Yet, existing work largely focuses on isolated case studies, resulting in a fragmented understanding of the privacy risks associated with location data production. In this work, we introduce an abstract model of geolocation ecosystems together with a systematic methodology for analyzing their privacy implications, which we apply to nine representative case studies spanning a broad range of architectures, from OS-level geolocation services to object-tracking platforms. This comparative analysis identifies structural design choices that significantly impact users' privacy and reveals common structural privacy risks across heterogeneous ecosystems, which reflect architectural design decisions rather than security vulnerabilities or poor system design. These findings, together with gaps identified in existing defense mechanisms, motivate research directions aimed at strengthening privacy in future geolocation architectures. Augustin Laouar, Paul Lachat, Loïc Desgeorges, Mathieu Cunche, Vincent Roca, Pascale Vicat-Blanc Primet, Francesco Bronzino |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | QRisk: Think Before You Scan QR Codes
Abhishek Kumar Mishra 0001, Guillaume Gagnon, Mathieu Cunche, Sébastien Gambs |
ARES (2) | 3 |
| 2025 | Efficiently linking LoRaWAN identifiers through multi-domain fingerprintingabstractLoRaWAN is a leading IoT technology worldwide, increasingly integrated into pervasive computing environments through a growing number of sensors in various industrial and consumer applications. Although its security vulnerabilities have been extensively explored in the recent literature, its ties to human activities warrant further privacy research. Existing device identification and activity inference attacks are only effective with a stable identifier. We find that the identifiers in LoRaWAN exhibit high variability, and more than half of the devices use them for less than a week. For the first time in the literature, we explore the feasibility of device fingerprinting in LoRaWAN, allowing long-term device linkage, i.e. associating various identifiers of the same device. We introduce a novel holistic fingerprint representation utilizing multiple domains, namely content, timing, and radio information, and present a machine learning-based solution for linking identifiers. Through a large-scale experimental evaluation based on real-world datasets containing up to 41 million messages, we study multiple scenarios, including an attacker with limited resources. We reach 0.98 linkage accuracy, underscoring the need for privacy-preserving measures. We showcase countermeasures including payload padding, random delays, and radio signal modulation, and conclude by assessing their impact on our fingerprinting solution. Samuel Pélissier, Abhishek Kumar Mishra 0001, Mathieu Cunche, Vincent Roca, Didier Donsez |
Pervasive Mob. Comput. | 3 |
| 2024 | Third Eye: Inferring the State of Your Smartphone Through Wi-FiabstractWi-Fi is one of the most notable and prevalent wireless technologies today. Smartphones and other Wi-Fi-enabled devices find nearby networks using management frames known as probe-requests. In this paper, we infer the state of smartphones by passively monitoring their transmitted probe-requests. We leverage the differential behaviour of probe-request bursts and their content, based on their device states such as active/static screen and Wi-Fi/power-saving mode ON/OFF. We use a Random Forest based approach that can successfully predict smartphone states just leveraging individual bursts. Based on an evaluation using a real-world dataset of more than 200 smartphones (having a variety of operating systems), with ground truth data available, we show that our model reliably predicts states with accuracy ≥ 98%. Abhishek Kumar Mishra 0001, Mathieu Cunche |
LCN | 2 |
| 2024 | Enhancing IoT Privacy: Why DNS-over-HTTPS Alone Falls Short?abstractRecent years have seen widespread adoption of consumer Internet of Things (IoT) devices, offering diverse benefits to end-users, from smart homes to healthcare monitoring, but raising serious privacy concerns. To address this, securing efforts, such as encrypting DNS, have been proposedIn this paper, we study the effectiveness of such measures in the specific context of ensuring IoT privacy. We introduce a device identification attack against DNS-over-HTTPS-enabled IoT devices. We conduct more than 25,000 automated experiments across 6 public DNS resolvers and find that the proposed attack can identify devices via DNS-over-HTTPS (DoH) traffic with a 0.98 balanced accuracy. We point out padding as a mitigation technique that reduces identification by a significant 33%. Additionally, we find that half of the evaluated DNS resolvers do not adhere to the relevant specification, substantially compromising user privacy. Samuel Pélissier, Gianluca Anselmi, Abhishek Kumar Mishra 0001, Anna Maria Mandalari, Mathieu Cunche |
TrustCom | 5 |
| 2024 | Privacy-Preserving Pseudonyms for LoRaWANabstractLoRaWAN, a widely deployed LPWAN protocol, raises privacy concerns due to metadata exposure, particularly concerning the exploitation of stable device identifiers. For the first time in literature, we propose two privacy-preserving pseudonym schemes tailored for LoRaWAN: resolvable pseudonyms and sequential pseudonyms. We extensively evaluate their performance and applicability through theoretical analysis and simulations based on a large-scale real-world dataset of 71 million messages. We conclude that sequential pseudonyms are the best solution. Samuel Pélissier, Jan Aalmoes, Abhishek Kumar Mishra 0001, Mathieu Cunche, Vincent Roca, Didier Donsez |
WISEC | 4 |
| 2024 | RSSI-based attacks for identification of BLE devicesabstractInternational audience Guillaume Gagnon, Sébastien Gambs, Mathieu Cunche |
Comput. Secur. | 3 |
| 2023 | RSSI-Based Fingerprinting of Bluetooth Low Energy DevicesabstractBest paper award Guillaume Gagnon, Sébastien Gambs, Mathieu Cunche |
SECRYPT | 3 |
| 2023 | PEPPER: Precise Privacy-Preserving Contact Tracing with Cheap, BLE/UWB Capable TokensabstractContact Tracing (CT) is an old, recognized epi-demiological tool, and since a digital variant is now within reach, a variety of smartphone-based solutions have been rapidly developed and deployed since 2020, with mixed results and amid controversies. Yet, achieving reliable and effective digital CT at large scale is still an open problem. In this work, we contribute with an open source software platform on top of which various CT solutions can be quickly developed and tested. More specifically, we design PEPPER, which jointly leverages Bluetooth Low Energy (BLE) and Ultra Wide Band (UWB) radios for contact detection, combined with the DESIRE privacy-preserving CT protocol. We show that PEPPER+DESIRE can operate on cheap physical tokens based on low-power microcontrollers, opening new use-cases with less personal, potentially disposable devices, that could be more widely used. We also evaluate the complementarity of Bluetooth and UWB in this context, via experiments mimicking various scenarios relevant for CT. Compared to BLE-only CT, we show that UWB can decrease false negatives (e.g., in presence of human body occlusion), meaning that more actual contacts will be found, a key benefit from an epidemiological viewpoint. Our results suggest that, while PEPPER+DESIRE improves precision over state-of-the-art, further research is required to harness UWB-BLE synergy for CT in practice. To this end, our open source platform (which can run on an open-access testbed) provides a useful playground for the research community. François-Xavier Molina, Vincent Roca, Roudy Dagher, Emmanuel Baccelli, Nathalie Mitton, Antoine Boutet, Mathieu Cunche |
WoWMoM | 7 |
| 2022 | Device Re-identification in LoRaWAN through Messages LinkageabstractIn LoRaWAN networks, devices are identified by two identifiers: a globally unique and stable one called DevEUI, and an ephemeral and randomly assigned pseudonym called DevAddr. The association between those identifiers is only known by the network and join servers, and is not available to a passive eavesdropper. Samuel Pélissier, Mathieu Cunche, Vincent Roca, Didier Donsez |
WISEC | 2 |
| 2021 | No need to ask the Android: bluetooth-low-energy scanning without the location permissionabstractBluetooth-Low-Energy (BLE) scanning can be misused by applications to determine a device location. In order to prevent unconsented location tracking by applications, Android conditions the use of some BLE functions to the prior obtention of the location permission and the activation of the location setting. In this paper, we detail a vulnerability that allows applications to perform BLE scans without the location permission. We present another flaw allowing to bypass the active location requirement. Together those flaws allow an application to fully circumvent the location restrictions applying to BLE scanning. The presented vulnerability affects devices running Android 6 up to 11 and could be misused by application developers to track the location of users. This vulnerability has been disclosed to Google and assigned the CVE-2021-0328. Vincent Toubiana, Mathieu Cunche |
WISEC | 2 |
| 2021 | Privacy protection for Wi-Fi location positioning systems
Antoine Boutet, Mathieu Cunche |
J. Inf. Secur. Appl. | 2 |
| 2020 | Valkyrie: a generic framework for verifying privacy provisions in wireless networksabstractWireless communications integrated in connected devices can expose their users to tracking via the exposure of link layer identifiers (e.g. MAC addresses). To counter this threat, it has been proposed to replace those permanent identifiers with periodically changing random pseudonyms [17]. This practice, called address randomization has been progressively adopted by vendors [28, 36] and has even made its way to wireless standards [1, 35]. However, an effective implementation of address randomization requires more than periodically rotating the link layer identifier. Indeed, several works [8, 11, 12, 16, 27, 28, 36] identified issues with address randomization implementation, where in-frames counters and identifiers can undermine the anti-tracking measure. Guillaume Celosia, Mathieu Cunche |
WISEC | 2 |
| 2020 | Discontinued Privacy: Personal Data Leaks in Apple Bluetooth-Low-Energy Continuity ProtocolsabstractAbstract Apple Continuity protocols are the underlying network component of Apple Continuity services which allow seamless nearby applications such as activity and file transfer, device pairing and sharing a network connection. Those protocols rely on Bluetooth Low Energy (BLE) to exchange information between devices: Apple Continuity messages are embedded in the pay-load of BLE advertisement packets that are periodically broadcasted by devices. Recently, Martin et al. identified [1] a number of privacy issues associated with Apple Continuity protocols; we show that this was just the tip of the iceberg and that Apple Continuity protocols leak a wide range of personal information. In this work, we present a thorough reverse engineering of Apple Continuity protocols that we use to uncover a collection of privacy leaks. We introduce new artifacts, including identifiers, counters and battery levels, that can be used for passive tracking, and describe a novel active tracking attack based on Handoff messages. Beyond tracking issues, we shed light on severe privacy flaws. First, in addition to the trivial exposure of device characteristics and status, we found that HomeKit accessories betray human activities in a smarthome. Then, we demonstrate that AirDrop and Nearby Action protocols can be leveraged by passive observers to recover e-mail addresses and phone numbers of users. Finally, we exploit passive observations on the advertising traffic to infer Siri voice commands of a user. Guillaume Celosia, Mathieu Cunche |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | Saving private addresses: an analysis of privacy issues in the bluetooth-low-energy advertising mechanismabstractThe Bluetooth Low Energy (BLE) protocol is being included in a growing number of connected objects such as fitness trackers and headphones. As part of the service discovery mechanism of BLE, devices announce themselves by broadcasting radio signals called advertisement packets that can be collected with off-the-shelf hardware and software. To avoid the risk of tracking based on those messages, BLE features an address randomization mechanism that substitutes the device address with random temporary pseudonyms, called Private addresses. Guillaume Celosia, Mathieu Cunche |
MobiQuitous | 2 |
| 2019 | Himiko: A human interface for monitoring and inferring knowledge on bluetooth-low-energy objects: demoabstractThe Bluetooth Low Energy (BLE) protocol is being included in a growing number of connected objects such as smartphones, fitness trackers, headphones and smartwatches. As part of the service discovery mechanism of BLE, devices announce themselves by broadcasting radio signals called advertisement packets that can be collected with off-the-shelf hardware and software. To avoid the risk of tracking based on those messages, BLE features an address randomization mechanism that substitutes the device MAC address with random temporary pseudonyms. However, the payload of the advertisement packet still contains fields that can hamper the randomization mechanism by exposing counters and static identifiers. In addition to defeating the randomization mechanism, some of these fields can leak sensitive attributes of the owner such as his medical condition. Guillaume Celosia, Mathieu Cunche |
WiSec | 2 |
| 2018 | Detecting smartphone state changes through a Bluetooth based timing attackabstractBluetooth is a popular wireless communication technology that is available on most mobile devices. Although Bluetooth includes security and privacy preserving mechanisms, we show that a Bluetooth harmless inherent request-response mechanism can taint users privacy. More specifically, we introduce a timing attack that can be triggered by a remote attacker in order to infer information about a Bluetooth device state. By observing the L2CAP layer ping mechanism timing variations, it is possible to detect device state changes, for instance when the device goes in or out of the locked state. Our experimental results show that change point detection analysis of the timing allows to detect device state changes with a high accuracy. Finally, we discuss applications and countermeasures. Guillaume Celosia, Mathieu Cunche |
WISEC | 2 |
| 2018 | Privacy-preserving Wi-Fi AnalyticsabstractAbstract As communications-enabled devices are becoming more ubiquitous, it becomes easier to track the movements of individuals through the radio signals broadcasted by their devices. Thus, while there is a strong interest for physical analytics platforms to leverage this information for many purposes, this tracking also threatens the privacy of individuals. To solve this issue, we propose a privacy-preserving solution for collecting aggregate mobility patterns while satisfying the strong guarantee of ε-differential privacy. More precisely, we introduce a sanitization mechanism for efficient, privacy-preserving and non-interactive approximate distinct counting for physical analytics based on perturbed Bloom filters called Pan-Private BLIP. We also extend and generalize previous approaches for estimating distinct count of events and joint events (i.e., intersection and more generally t-out-of-n cardinalities). Finally, we evaluate expirementally our approach and compare it to previous ones on real datasets. Mohammad Alaggan, Mathieu Cunche, Sébastien Gambs |
Proc. Priv. Enhancing Technol. | 2 |
| 2016 | Why MAC Address Randomization is not Enough: An Analysis of Wi-Fi Network Discovery MechanismsabstractWe present several novel techniques to track (unassociated) mobile devices by abusing features of the Wi-Fi standard. This shows that using random MAC addresses, on its own, does not guarantee privacy. First, we show that information elements in probe requests can be used to fingerprint devices. We then combine these fingerprints with incremental sequence numbers, to create a tracking algorithm that does not rely on unique identifiers such as MAC addresses. Based on real-world datasets, we demonstrate that our algorithm can correctly track as much as 50% of devices for at least 20 minutes. We also show that commodity Wi-Fi devices use predictable scrambler seeds. These can be used to improve the performance of our tracking algorithm. Finally, we present two attacks that reveal the real MAC address of a device, even if MAC address randomization is used. In the first one, we create fake hotspots to induce clients to connect using their real MAC address. The second technique relies on the new 802.11u standard, commonly referred to as Hotspot 2.0, where we show that Linux and Windows send Access Network Query Protocol (ANQP) requests using their real MAC address. Mathy Vanhoef, Célestin Matte, Mathieu Cunche, Leonardo S. Cardoso, Frank Piessens |
AsiaCCS | 3 |
| 2016 | Enhanced recursive Reed-Muller erasure decodingabstractRecent work have shown that Reed-Müller (RM) codes achieve the erasure channel capacity. However, this performance is obtained with maximum-likelihood decoding which can be costly for practical applications. In this paper, we propose an encoding/decoding scheme for Reed-Müller codes on the packet erasure channel based on Plotkin construction. We present several improvements over the generic decoding. They allow, for a light cost, to compete with maximum-likelihood decoding performance, especially on high-rate codes, while significantly outperforming it in terms of speed. Alexandre Soro, Jérôme Lacan, Vincent Roca, Valentin Savin, Mathieu Cunche |
ISIT | 5 |
| 2016 | DEMO: Panoptiphone: How Unique is Your Wi-Fi Device?abstractMAC address randomization in Wi-Fi-enabled devices has recently been adopted to prevent passive tracking of mobile devices. However, Wi-Fi frames still contain fields that can be used to fingerprint devices and potentially allow tracking. Panoptiphone is a tool inspired by the web browser fingerprinting tool Panopticlick [2], which aims to show the identifying information that can be found in the frames broadcast by a Wi-Fi-enabled device. Information is passively collected from devices that have their Wi-Fi interface enabled, even if they are not connected to an access point. Panoptiphone uses this information to create a fingerprint of the device and empirically evaluate its uniqueness among a database of fingerprints. The user is then shown how much identifying information its device is leaking through Wi-Fi and how unique it is. Célestin Matte, Mathieu Cunche |
WISEC | 2 |
| 2016 | Defeating MAC Address Randomization Through Timing AttacksabstractMAC address randomization is a common privacy protection measure deployed in major operating systems today. It is used to prevent user-tracking with probe requests that are transmitted during IEEE 802.11 network scans. We present an attack to defeat MAC address randomization through observation of the timings of the network scans with an off-the-shelf Wi-Fi interface. This attack relies on a signature based on inter-frame arrival times of probe requests, which is used to group together frames coming from the same device although they use distinct MAC addresses. We propose several distance metrics based on timing and use them together with an incremental learning algorithm in order to group frames. We show that these signatures are consistent over time and can be used as a pseudo-identifier to track devices. Our framework is able to correctly group frames using different MAC addresses but belonging to the same device in up to 75% of the cases. These results show that the timing of 802.11 probe frames can be abused to track individual devices and that address randomization alone is not always enough to protect users against tracking. Célestin Matte, Mathieu Cunche, Franck Rousseau, Mathy Vanhoef |
WISEC | 2 |
| 2015 | SSIDs in the wild: Extracting semantic information from WiFi SSIDsabstractWiFi networks are becoming increasingly ubiquitous. In addition to providing network connectivity, WiFi finds applications in areas such as indoor and outdoor localisation, home automation, and physical analytics. In this paper, we explore the semantics of one key attribute of a WiFi network, SSID name. Using a dataset of approximately 120,000 WiFi access points and their corresponding geo-locations, we use a set of similarity metrics to relate SSID names to known business venues such as cafes, theatres, and shopping centres. Such correlations can be exploited by an adversary who has access to smartphone users preferred networks lists to build an accurate profile of the user and thus can be a potential privacy risk to the users. Suranga Seneviratne, Fangzhou Jiang, Mathieu Cunche, Aruna Seneviratne |
LCN | 3 |
| 2015 | Device-to-identity linking attack using targeted wi-fi geolocation spoofingabstractToday, almost all mobile devices come equipped with Wi-Fi technology. Therefore, it is essential to thoroughly study the privacy risks associated with this technology. Recent works have shown that some Personally Identifiable Information (PII) can be obtained from the radio signals emitted by Wi-Fi equipped devices. However, most of the times, the identity of the subject of those pieces of information remains unknown and the Wi-Fi MAC address of the device is the only available identifier. In this paper, we show that it is possible for an attacker to get the identity of the subject. Célestin Matte, Jagdish Prasad Achara, Mathieu Cunche |
WISEC | 3 |
| 2014 | Censorship in the Wild: Analyzing Internet Filtering in SyriaabstractInternet censorship is enforced by numerous governments worldwide, however, due to the lack of publicly available information, as well as the inherent risks of performing active measurements, it is often hard for the research community to investigate censorship practices in the wild. Thus, the leak of 600GB worth of logs from 7 Blue Coat SG-9000 proxies, deployed in Syria to filter Internet traffic at a country scale, represents a unique opportunity to provide a detailed snapshot of a real-world censorship ecosystem. Abdelberi Chaabane, Terence Chen, Mathieu Cunche, Emiliano De Cristofaro, Arik Friedman, Mohamed Ali Kâafar |
Internet Measurement Conference | 3 |
| 2014 | Short paper: WifiLeaks: underestimated privacy implications of the access_wifi_state android permissionabstractOn Android, installing an application implies accepting the permissions it requests, and these permissions are then enforced at runtime. In this work, we focus on the privacy implications of the ACCESS_WIFI_STATE permission. For this purpose, we analyzed permissions of the 2700 most popular applications on Google Play and found that the ACCESS_WIFI_STATE permission is used by 41% of them. We then performed a static analysis of 998 applications requesting this permission and based on the results, chose 88 applications for dynamic analysis. Our analyses reveal that this permission is already used by some companies to collect user Personally Identifiable Information (PII). We also conducted an online survey to study users' perception of the privacy risks associated with this permission. This survey shows that users largely underestimate the privacy implications of this permission. As this permission is very common, most users are therefore potentially at risk. Jagdish Prasad Achara, Mathieu Cunche, Vincent Roca, Aurélien Francillon |
WISEC | 2 |
| 2014 | Linking wireless devices using information contained in Wi-Fi probe requests
Mathieu Cunche, Mohamed Ali Kâafar, Roksana Boreli |
Pervasive Mob. Comput. | 1 |
| 2013 | Private and resilient data aggregationabstractSensors are commonly deployed in hostile environment, and consequently a number of research works have focused on data aggregation schemes designed to be tolerant to attacks on sensor nodes. In parallel, schemes ensuring the confidentiality of sensor data have been proposed to address the emerging privacy concerns. We note that resilience against tampering attacks requires access to the sensor node's data, while in privacy-preserving systems this data must remain confidential. In this work, we aim to reconcile these two seemingly conflicting objectives. We present a novel private and resilient aggregation system, in which an aggregator combines the data collected from sensor nodes and forwards the resulting sum to an analyst. Our scheme protects the privacy of the users from both honest-but-curious aggregator and analyst, while enabling the filtering of fake data values using a Private Range Test protocol. Mathieu Cunche, Cédric Lauradoux, Marine Minier, Roksana Boreli |
LCN | 1 |
| 2013 | RS + LDPC-Staircase codes for the erasure channel: Standards, usage and performanceabstractApplication-Level Forward Erasure Correction (AL-FEC) codes are a key element of telecommunication systems. They are used to recover from packet losses when retransmission are not feasible and to optimize the large scale distribution of contents. In this paper we introduce Reed-Solomon/LDPC-Staircase codes, two complementary AL-FEC codes that have recently been recognized as superior to Raptor codes in the context of the 3GPP-eMBMS call for technology [1]. After a brief introduction to the codes, we explain how to design high performance codecs which is a key aspect when targeting embedded systems with limited CPU/battery capacity. Finally we present the performances of these codes in terms of erasure correction capabilities and encoding/decoding speed, taking advantage of the 3GPP-eMBMS results where they have been ranked first. Vincent Roca, Mathieu Cunche, Cedric Thienot, Jonathan Detchart, Jérôme Lacan |
WiMob | 2 |
| 2012 | Heterogeneous Secure Multi-Party Computation
Mentari Djatmiko, Mathieu Cunche, Roksana Boreli, Aruna Seneviratne |
Networking (2) | 2 |
| 2012 | I know who you will meet this evening! Linking wireless devices using Wi-Fi probe requestsabstractActive service discovery in Wi-Fi involves wireless stations broadcasting their Wi-Fi fingerprint, i.e. the SSIDs of their preferred wireless networks. The content of those Wi-Fi fingerprints can reveal different types of information about the owner. We focus on the relation between the fingerprints and the links between the owners. Our hypothesis is that social links between devices owners can be identified by exploiting the information contained in the fingerprint. More specifically we propose to consider the similarity between fingerprints as a metric, with the underlying idea: similar fingerprints are likely to be linked. We first study the performances of several similarity metrics on a controlled dataset and then apply the designed classifier to a dataset collected in the wild. Finally we discuss how Wi-Fi fingerprint can reveal informations on the nature of the links between users. This study is based on a dataset collected in Sydney, Australia, composed of fingerprints corresponding to more than 8000 devices. Mathieu Cunche, Mohamed Ali Kâafar, Roksana Boreli |
WOWMOM | 1 |
| 2010 | Analysis of Quasi-Cyclic LDPC codes under ML decoding over the erasure channelabstractIn this paper, we show that over the binary erasure channel, Quasi-Cyclic LDPC codes can efficiently accommodate the hybrid iterative/ML decoding. We demonstrate that the quasi-cyclic structure of the parity-check matrix can be advantageously used in order to significantly reduce the complexity of the ML decoding. This is achieved by a simple row/column permutation that transforms a QC matrix into a pseudo-band form. Based on this approach, we propose a class of QC-LDPC codes with almost ideal error correction performance under the ML decoding, while the required number of row/symbol operations scales as k√k, where k is the number of source symbols. Mathieu Cunche, Valentin Savin, Vincent Roca |
ISITA | 1 |
| 2010 | Performance analysis of a high-performance real-time application with several AL-FEC schemesabstractReal-time streaming applications typically require minimizing packet loss and transmission delay so as to keep the best possible playback quality. From this point of view, IP datagram losses (e.g. caused by a congested router, or caused by a short term fading problem with wireless transmissions) have major negative impacts. Although Application Layer Forward Error Correction (AL-FEC) is a useful technique for protecting against packet loss, the playback quality is largely sensitive to the AL-FEC code/codec features and the way they are used. In this work, we consider three FEC schemes for the erasure channel: 2D parity check codes, Reed-Solomon over GF(28) codes, and LDPC-Staircase codes, all of them being currently standardized within IETF. We have integrated these FEC schemes in the FECFRAME framework, a framework that is also being standardized at IETF, and whose goal is to integrate AL-FEC schemes in real-time protocol stacks in a simple and flexible way. Then we modified the Digital Video Transport System (DVTS) high-performance real-time video streaming application so that it can benefit from FECFRAME in order to recover from transmission impairments. We then carried out several performance evaluations in order to identify, for a given loss rate, the optimal configuration in which DVTS performs the best. Kazuhisa Matsuzono, Jonathan Detchart, Mathieu Cunche, Vincent Roca, Hitoshi Asaeda |
LCN | 3 |
| 2009 | Adding Integrity Verification Capabilities to the LDPC-Staircase Erasure Correction CodesabstractFile distribution is becoming a key technology, in particular in large scale content broadcasting systems like DVB-H/SH. They largely rely on Application Level FEC codes (AL-FEC) in order to recover from transmission erasures. We believe that sooner or later, content integrity and source authentication security services will be required in these systems. In order to save the client terminal resources, which can be a handheld autonomous device, we have designed a hybrid system that merges the AL-FEC decoding and content integrity/source authentication services. More precisely our system can detect a random object corruption triggered by a deliberate attack with a probability close to 100% almost for free in terms of computation overhead. The case of intelligent corruptions is also addressed and counter measures proposed. Mathieu Cunche, Vincent Roca |
GLOBECOM | 1 |
| 2009 | Erasure Codes with a Banded Structure for Hybrid Iterative-ML DecodingabstractThis paper presents new FEC codes for the erasure channel, LDPC-Band, that have been designed so as to optimize a hybrid iterative-Maximum Likelihood (ML) decoding. Indeed, these codes feature simultaneously a sparse parity check matrix, which allows an efficient use of iterative LDPC decoding, and a generator matrix with a band structure, which allows fast ML decoding on the erasure channel. The combination of these two decoding algorithms leads to erasure codes achieving a very good trade-off between complexity and erasure correction capability. Alexandre Soro, Mathieu Cunche, Jérôme Lacan, Vincent Roca |
GLOBECOM | 2 |