VLDB 2026 Research / reviewers in the wild / expert
Kassem Fawaz
dblp:97/535
· DBLP profile ↗
58ranked-venue papers
10as first author
33since 2021 · last 2026
0000-0002-4609-7691ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 30 · 6 first-author · 19 since 2021Artificial intelligence and machine learning · 9 · 8 since 2021Computer networks · 9 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Analysis of Always-Listening Services on AndroidabstractAlways-listening services are a defining feature of modern Android, enabling capabilities such as keyword spotting, music recognition, and adaptive audio. Despite their ubiquity, these services remain opaque: users lack visibility into when audio is recorded, where it is processed, and how it's used. Their infrastructure encompasses specialized hardware, low-level system frameworks, machine learning models, and proprietary applications, making them challenging to analyze. We present the first systematic analysis of Android's always-listening ecosystem. We develop a reverse engineering approach that reconstructs the architecture, maps key functions through static analysis, and uses dynamic instrumentation to characterize runtime behaviors. Applying this methodology, we extract and analyze the machine learning models powering these services, uncover undocumented triggers for audio capture, and evaluate a new class of unintentional activations we call "local misactivations". We reveal that keyword spotting and music recognition models can misactivate up to 58 times per hour, capturing several seconds of audio each time without issuing notifications to the user. We further quantify the resource cost of these misactivations, showing that each event increases device power consumption by 18–81% over idle and consumes 305–454 ms of CPU time on the application processor. Our work highlights the need for greater transparency and user control for always-listening services on mobile devices. Leo Cao, Jack West, Kassem Fawaz |
MobiSys | 3 |
| 2026 | Personalizing Agent Privacy Decisions via Logical EntailmentabstractPersonal large language model (LLM) agents increasingly perform tasks that require access to user data, raising concerns about appropriate data disclosure. We show that relying solely on LLMs to make data-sharing decisions is insufficient. Prompting LLMs to ground their decisions on contextual privacy norms fails to capture individual users’ privacy preferences, while providing prior user data-sharing decisions through in-context learning (ICL) leads to unreliable and opaque reasoning. To address these limitations, we propose ARIEL (Agentic Reasoning with Individualized Entailment Logic), a framework that combines LLMs with rule-based logic to enable structured, personalized privacy reasoning. The core mechanism of ARIEL determines whether a user’s prior decision on a data-sharing request logically entails the same decision for a new request. Experimental evaluations using advanced models and public datasets show that ARIEL reduces the F1 error rate for appropriate judgments by 40.6% compared to standard ICL-based reasoning, indicating that ARIEL is effective at correctly judging requests where the user would approve data sharing. These results demonstrate that integrating LLMs with logical entailment provides an effective and interpretable approach for automating personalized privacy decisions. James Flemings, Ren Yi, Octavian Suciu, Kassem Fawaz, Murali Annavaram, Marco Gruteser |
Proc. Priv. Enhancing Technol. | 4 |
| 2026 | WebSP-Eval: Evaluating Web Agents on Website Security and Privacy TasksabstractWeb agents automate browser tasks, ranging from simple form completion to complex workflows like ordering groceries. While current benchmarks evaluate general-purpose performance~(e.g., WebArena) or safety against malicious actions~(e.g., SafeArena), no existing framework assesses an agent's ability to successfully execute user-facing website security and privacy tasks, such as managing cookie preferences, configuring privacy-sensitive account settings, or revoking inactive sessions. To address this gap, we introduce WebSP-Eval, an evaluation framework for measuring web agent performance on website security and privacy tasks. WebSP-Eval comprises 1) a manually crafted task dataset of 200 task instances across 28 websites; 2) a robust agentic system supporting account and initial state management across runs using a custom Google Chrome extension; and 3) an automated evaluator. We evaluate a total of 8 web agent instantiations using state-of-the-art multimodal large language models, conducting a fine-grained analysis across websites, task categories, and UI elements. Our evaluation reveals that current models suffer from limited autonomous exploration capabilities to reliably solve website security and privacy tasks, and struggle with specific task categories and websites. Crucially, we identify stateful UI elements are a primary reason for agent failure, with toggles causing more than 45% task failure across many models. Guruprasad V. Ramesh, Asmit Nayak, Basieem Siddique, Kassem Fawaz |
Proc. Priv. Enhancing Technol. | 4 |
| 2026 | Reliable Heading Tracking for Pedestrian Road Crossing Prediction Using Commodity DevicesabstractPedestrian heading tracking enables applications in pedestrian navigation, traffic safety, and accessibility. Previous works, using inertial sensor fusion or machine learning, are limited in that they assume the phone is fixed in specific orientations, hindering their generalizability. We propose a new heading tracking algorithm, the Orientation-Heading Alignment (OHA), which leverages a key insight: people tend to carry smartphones in certain ways due to habits, such as swinging them while walking. For each smartphone attitude during this motion, OHA maps the smartphone orientation to the pedestrian heading and learns such mappings efficiently from coarse headings and smartphone orientations. To anchor our algorithm in a practical scenario, we apply OHA to a challenging task: predicting when pedestrians are about to cross the road to improve road user safety. In particular, using 755 hours of walking data collected since 2020 from 60 individuals, we develop a lightweight model that operates in real-time on commodity devices to predict road crossings. Our evaluation shows that OHA achieves 3.4 times smaller heading errors across nine scenarios than existing methods. Furthermore, OHA enables the early and accurate detection of pedestrian crossing behavior, issuing crossing alerts 0.35 seconds, on average, before pedestrians enter the road range. Yucheng Yang 0003, Kassem Fawaz |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | CPSIoTSec'25: The 7th Joint Workshop on CPS & IoT Security and PrivacyabstractThe 7th Joint Workshop on CPS & IoT Security and Privacy is set to take place in Taipei, Taiwan, on October 17, 2025, in conjunction with the ACM Conference on Computer and Communications Security (CCS'25). This workshop marks the amalgamation of two workshops held in 2019: one focused on the security and privacy of cyber-physical systems, while the other one centered on the security and privacy of IoT. The primary objective of this workshop is to create a collaborative forum that brings together academia, industry experts, and governmental entities, encouraging them to contribute cutting-edge research, share demonstrations or hands-on experiences, and engage in discussions. This year, our call for contributions encompassed a broad spectrum, including full research papers, work-in-progress submissions, and one-page abstracts. The workshop program includes nine full/short papers on the security and privacy of CPS/IoT, alongside one demo paper that presents a virtual cybersecurity testbed. Furthermore, the workshop will feature one distinguished keynote presentation by Prof. Daniel Xiapu Luo, a world-renowned expert in CPS security. The talk will offer deep insights on automotive cybersecurity. The complete CPSIoTSec'25 workshop proceedings are available at https://doi.org/10.1145/3733801 Kassem Fawaz, Daisuke Mashima |
CCS | 1 |
| 2025 | Automatically Detecting Online Deceptive PatternsabstractDeceptive patterns in digital interfaces manipulate users into making unintended decisions, exploiting cognitive biases and psychological vulnerabilities. These patterns have become ubiquitous on various digital platforms. While efforts to mitigate deceptive patterns have emerged from legal and technical perspectives, a significant gap remains in creating usable and scalable solutions. We introduce our AutoBot framework to address this gap and help web stakeholders navigate and mitigate online deceptive patterns. AutoBot accurately identifies and localizes deceptive patterns from a screenshot of a website without relying on the underlying HTML code. AutoBot employs a two-stage pipeline that leverages the capabilities of specialized vision models to analyze website screenshots, identify interactive elements, and extract textual features. Next, using a large language model, AutoBot understands the context surrounding these elements to determine the presence of deceptive patterns. We also use AutoBot, to create a synthetic dataset to distill knowledge from 'teacher' LLMs to smaller language models. Through extensive evaluation, we demonstrate AutoBot's effectiveness in detecting deceptive patterns on the web, achieving an F1-score of 0.93 in this task, underscoring its potential as an essential tool for mitigating online deceptive patterns. Asmit Nayak, Yash Wani, Shirley Zhang 0002, Rishabh Khandelwal, Kassem Fawaz |
CCS | 5 |
| 2025 | "Impressively Scary: ' Exploring User Perceptions and Reactions to Unraveling Machine Learning Models in Social Media ApplicationsabstractMachine learning models deployed locally on social media applications are used for features, such as face filters which read faces in-real time, and they expose sensitive attributes to the apps. However, the deployment of machine learning models, e.g., when, where, and how they are used, in social media applications is opaque to users. We aim to address this inconsistency and investigate how social media user perceptions and behaviors change once exposed to these models. We conducted user studies (N=21) and found that participants were unaware to both what the models output and when the models were used in Instagram and TikTok, two major social media platforms. In response to being exposed to the models' functionality, we observed long term behavior changes in 8 participants. Our analysis uncovers the challenges and opportunities in providing transparency for machine learning models that interact with local user data. Jack West, Bengisu Cagiltay, Shirley Zhang 0002, Kassem Fawaz, Suman Banerjee 0001 |
CHI | 5 |
| 2025 | Private Continual Counting of Unbounded StreamsabstractWe study the problem of differentially private continual counting in the unbounded setting where the input size $n$ is not known in advance. Current state-of-the-art algorithms based on optimal instantiations of the matrix mechanism cannot be directly applied here because their privacy guarantees only hold when key parameters are tuned to $n$. Using the common `doubling trick' avoids knowledge of $n$ but leads to suboptimal and non-smooth error. We solve this problem by introducing novel matrix factorizations based on logarithmic perturbations of the function $\frac{1}{\sqrt{1-z}}$ studied in prior works, which may be of independent interest. The resulting algorithm has smooth error, and for any $\alpha > 0$ and $t\leq n$ it is able to privately estimate the sum of the first $t$ data points with $O(\log^{2+2\alpha}(t))$ variance. It requires $O(t)$ space and amortized $O(\log t)$ time per round, compared to $O(\log(n)\log(t))$ variance, $O(n)$ space and $O(n \log n)$ pre-processing time for the nearly-optimal bounded-input algorithm of Henzinger et al. Empirically, we find that our algorithm's performance is also comparable to theirs in absolute terms: our variance is less than $1.5\times$ theirs for $t$ as large as $2^{24}$. Ben Jacobsen, Kassem Fawaz |
NeurIPS | 2 |
| 2025 | What Really is a Member? Discrediting Membership Inference via PoisoningabstractMembership inference tests aim to determine whether a particular data point was included in a language model's training set. However, recent works have shown that such tests often fail under the strict definition of membership based on exact matching, and have suggested relaxing this definition to include semantic neighbors as members as well. In this work, we show that membership inference tests are still *unreliable* under this relaxation - it is possible to poison the training dataset in a way that causes the test to produce incorrect predictions for a target point. We theoretically reveal a trade-off between a test’s accuracy and its robustness to poisoning. We also present a concrete instantiation of this poisoning attack and empirically validate its effectiveness. Our results show that it can degrade the performance of existing tests to well below random. Neal Mangaokar, Ashish Hooda, Bradley A. Malin, Kassem Fawaz, Somesh Jha, Atul Prakash 0001, Amrita Roy Chowdhury 0001 |
NeurIPS | 5 |
| 2025 | Abusability of Automation Apps in Intimate Partner Violence
Shirley Zhang 0002, Paul Chung, Jacob Vervelde, Nishant Korapati, Rahul Chatterjee 0001, Kassem Fawaz |
USENIX Security Symposium | 6 |
| 2024 | Limitations of Face Image GenerationabstractText-to-image diffusion models have achieved widespread popularity due to their unprecedented image generation capability. In particular, their ability to synthesize and modify human faces has spurred research into using generated face images in both training data augmentation and model performance assessments. In this paper, we study the efficacy and shortcomings of generative models in the context of face generation. Utilizing a combination of qualitative and quantitative measures, including embedding-based metrics and user studies, we present a framework to audit the characteristics of generated faces conditioned on a set of social attributes. We applied our framework on faces generated through state-of-the-art text-to-image diffusion models. We identify several limitations of face image generation that include faithfulness to the text prompt, demographic disparities, and distributional shifts. Furthermore, we present an analytical model that provides insights into how training data selection contributes to the performance of generative models. Our survey data and analytics code can be found online at https://github.com/wi-pi/Limitations_of_Face_Generation Harrison Rosenberg, Shimaa Ahmed, Guruprasad V. Ramesh, Kassem Fawaz, Ramya Korlakai Vinayak |
AAAI | 4 |
| 2024 | PRP: Propagating Universal Perturbations to Attack Large Language Model Guard-RailsabstractNeal Mangaokar, Ashish Hooda, Jihye Choi, Shreyas Chandrashekaran, Kassem Fawaz, Somesh Jha, Atul Prakash. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024. Neal Mangaokar, Ashish Hooda, Jihye Choi, Shreyas Chandrashekaran, Kassem Fawaz, Somesh Jha, Atul Prakash 0001 |
ACL (1) | 5 |
| 2024 | CPSIoTSec'24: Sixth Workshop on CPS&IoT Security and PrivacyabstractThe sixth Workshop on CPS & IoT Security and Privacy is set to take place in Salt Lake City, UT, USA, on October 18, 2024, in conjunction with the ACM Conference on Computer and Communications Security (CCS'24). This workshop marks the amalgamation of two workshops held in 2019: one focused on the security and privacy of cyber-physical systems, while the other one centered on the security and privacy of IoT. The primary objective of this workshop is to create a collaborative forum that brings together academia, industry experts, and governmental entities, encouraging them to contribute cutting-edge research, share demonstrations or hands-on experiences, and engage in discussions. This year, our call for contributions encompassed a broad spectrum, including full research papers, work-in-progress submissions, and one-page abstracts. The workshop program includes eight full-length papers on the security and privacy of CPS/IoT, alongside six shorter papers that present original or work-in-progress research. Furthermore, the workshop will feature one distinguished keynote presentation by Prof. Alvaro Cardenas, a world-renowned expert in CPS security. The talk will offer insights into how the state of CPS security has evolved since 2007. The complete CPSIoTSec'24 workshop proceedings are available at https://doi.org/10.1145/3658644.3691550. Kassem Fawaz, Magnus Almgren |
CCS | 1 |
| 2024 | I see an IC: A Mixed-Methods Approach to Study Human Problem-Solving Processes in Hardware Reverse EngineeringabstractTrust in digital systems depends on secure hardware, often assured through HRE. This work develops methods for investigating human problem-solving processes in HRE, an underexplored yet critical aspect. Since reverse engineers rely heavily on visual information, eye tracking holds promise for studying their cognitive processes. To gain further insights, we additionally employ verbal thought protocols during and immediately after HRE tasks: Concurrent and Retrospective Think Aloud. We evaluate the combination of eye tracking and Think Aloud with 41 participants in an HRE simulation. Eye tracking accurately identifies fixations on individual circuit elements and highlights critical components. Based on two use cases, we demonstrate that eye tracking and Think Aloud can complement each other to improve data quality. Our methodological insights can inform future studies in HRE, a specific setting of human-computer interaction, and in other problem-solving settings involving misleading or missing information. René Walendy, Steffen Becker 0003, Carina Wiesen, Malte Elson, Younghyun Kim 0001, Kassem Fawaz, Nikol Rummel, Christof Paar |
CHI | 8 |
| 2024 | Do Large Code Models Understand Programming Concepts? Counterfactual Analysis for Code PredicatesabstractLarge Language Models’ success in text generation has also made them better at code generation and coding tasks. While a lot of work has demonstrated their remarkable performance on tasks such as code completion and editing, it is still unclear as to why. We help bridge this gap by exploring to what degree auto-regressive models understand the logical constructs of the underlying programs. We propose Counterfactual Analysis for Programming Concept Predicates (CACP) as a counterfactual testing framework to evaluate whether Large Code Models understand programming concepts. With only black-box access to the model, we use CACP to evaluate ten popular Large Code Models for four different programming concepts. Our findings suggest that current models lack understanding of concepts such as data flow and control flow. Ashish Hooda, Mihai Christodorescu, Miltiadis Allamanis, Kassem Fawaz, Somesh Jha |
ICML | 5 |
| 2024 | A Picture is Worth 500 Labels: A Case Study of Demographic Disparities in Local Machine Learning Models for Instagram and TikTokabstractMobile apps have embraced user privacy by moving their data processing to the user’s smartphone. Advanced machine learning (ML) models, such as vision models, can now locally analyze user images to extract insights that drive several functionalities. Capitalizing on this new processing model of locally analyzing user images, we analyze two popular social media apps, TikTok and Instagram, to reveal (1) what insights vision models in both apps infer about users from their image and video data and (2) whether these models exhibit performance disparities with respect to demographics. As vision models provide signals for sensitive technologies like age verification and facial recognition, understanding potential biases in these models is crucial for ensuring that users receive equitable and accurate services.We develop a novel method for capturing and evaluating ML tasks in mobile apps, overcoming challenges like code obfuscation, native code execution, and scalability. Our method comprises ML task detection, ML pipeline reconstruction, and ML performance assessment, specifically focusing on demographic disparities. We apply our methodology to TikTok and Instagram, revealing significant insights. For TikTok, we find issues in age and gender prediction accuracy, particularly for minors and Black individuals. In Instagram, our analysis uncovers demographic disparities in extracting over 500 visual concepts from images, with evidence of spurious correlations between demographic features and certain concepts. Jack West, Lea Thiemt, Shimaa Ahmed, Maggie Bartig, Kassem Fawaz, Suman Banerjee 0001 |
SP | 5 |
| 2024 | Unpacking Privacy Labels: A Measurement and Developer Perspective on Google's Data Safety Section
Rishabh Khandelwal, Asmit Nayak, Paul Chung, Kassem Fawaz |
USENIX Security Symposium | 4 |
| 2024 | D4: Detection of Adversarial Diffusion Deepfakes Using Disjoint EnsemblesabstractDetecting diffusion-generated deepfake images remains an open problem. Current detection methods fail against an adversary who adds imperceptible adversarial perturbations to the deepfake to evade detection. In this work, we propose Disjoint Diffusion Deepfake Detection (D4), a deepfake detector designed to improve black-box adversarial robustness beyond de facto solutions such as adversarial training. D4 uses an ensemble of models over disjoint subsets of the frequency spectrum to significantly improve adversarial robustness. Our key insight is to leverage a redundancy in the frequency domain and apply a saliency partitioning technique to disjointly distribute frequency components across multiple models. We formally prove that these disjoint ensembles lead to a reduction in the dimensionality of the input subspace where adversarial deepfakes lie, thereby making adversarial deepfakes harder to find for black-box attacks. We then empirically validate the D4 method against several black-box attacks and find that D4 significantly outperforms existing state-of-the-art defenses applied to diffusion-generated deepfake detection. We also demonstrate that D4 provides robustness against adversarial deepfakes from unseen data distributions as well as unseen generative techniques. Ashish Hooda, Neal Mangaokar, Ryan Feng, Kassem Fawaz, Somesh Jha, Atul Prakash 0001 |
WACV | 4 |
| 2024 | Experimental Security Analysis of Sensitive Data Access by Browser ExtensionsabstractBrowser extensions offer a variety of valuable features and functionalities. They also pose a significant security risk if not properly designed or reviewed. Prior works have shown that browser extensions can access and manipulate data fields, including sensitive data such as passwords, credit card numbers, and Social Security numbers. In this paper, we present an empirical study of the security risks posed by browser extensions. Specifically, we first build a proof-of-concept extension that can steal sensitive user information. We find that the extension passes the Chrome Webstore review process. We then perform a measurement study on the top 10K website login pages to check if the extension access to password fields via JS. We find that none of the password fields are actively protected, and can be accessed using JS. Moreover, we found that 1K websites store passwords in plaintext in their page source, including popular websites like Google.com and Cloudflare.com. We also analyzed over 160K Chrome Web Store extensions for malicious behavior, finding that 28K have permission to access sensitive fields and 190 store password fields in variables. To analyze the behavioral workflow of the potentially malicious extensions, we propose an LLM-driven framework, Extension Reviewer. Finally, we discuss two countermeasures to address these risks: a bolt-on JavaScript package for immediate adoption by website developers allowing them to protect sensitive input fields, and a browser-level solution that alerts users when an extension accesses sensitive input fields. Our research highlights the urgent need for improved security measures to protect sensitive user information online. Asmit Nayak, Rishabh Khandelwal, Earlence Fernandes, Kassem Fawaz |
WWW | 4 |
| 2023 | Stateful Defenses for Machine Learning Models Are Not Yet Secure Against Black-box AttacksabstractRecent work has proposed stateful defense models (SDMs) as a compelling strategy to defend against a black-box attacker who only has query access to the model, as is common for online machine learning platforms. Such stateful defenses aim to defend against black-box attacks by tracking the query history and detecting and rejecting queries that are "similar" and thus preventing black-box attacks from finding useful gradients and making progress towards finding adversarial attacks within a reasonable query budget. Recent SDMs (e.g., Blacklight and PIHA) have shown remarkable success in defending against state-of-the-art black-box attacks. In this paper, we show that SDMs are highly vulnerable to a new class of adaptive black-box attacks. We propose a novel adaptive black-box attack strategy called Oracle-guided Adaptive Rejection Sampling (OARS) that involves two stages: (1) use initial query patterns to infer key properties about an SDM's defense; and, (2) leverage those extracted properties to design subsequent query patterns to evade the SDM's defense while making progress towards finding adversarial inputs. OARS is broadly applicable as an enhancement to existing black-box attacks - we show how to apply the strategy to enhance six common black-box attacks to be more effective against current class of SDMs. For example, OARS-enhanced versions of black-box attacks improved attack success rate against recent stateful defenses from almost 0% to to almost 100% for multiple datasets within reasonable query budgets. Ryan Feng, Ashish Hooda, Neal Mangaokar, Kassem Fawaz, Somesh Jha, Atul Prakash 0001 |
CCS | 4 |
| 2023 | "It's up to the Consumer to be Smart": Understanding the Security and Privacy Attitudes of Smart Home Users on RedditabstractSmart home technologies offer many benefits to users. Yet, they also carry complex security and privacy implications that users often struggle to assess and account for during adoption. To better understand users’ considerations and attitudes regarding smart home security and privacy, in particular how users develop them progressively, we conducted a qualitative content analysis of 4,957 Reddit comments in 180 security- and privacy-related discussion threads from /r/homeautomation, a major Reddit smart home forum. Our analysis reveals that users’ security and privacy attitudes, manifested in the levels of concern and degree to which they incorporate protective strategies, are shaped by multi-dimensional considerations. Users’ attitudes evolve according to changing contextual factors, such as adoption phases, and how they become aware of these factors. Further, we describe how online discourse about security and privacy risks and protections contributes to individual and collective attitude development. Based on our findings, we provide recommendations to improve smart home designs, support users’ attitude development, facilitate information exchange, and guide future research regarding smart home security and privacy. Kaiwen Sun 0001, Brittany Skye Huff, Anna Marie Bierley, Younghyun Kim 0001, Florian Schaub, Kassem Fawaz |
SP | 7 |
| 2023 | Tubes Among Us: Analog Attack on Automatic Speaker Identification
Shimaa Ahmed, Yash Wani, Ali Shahin Shamsabadi, Mohammad Yaghini, Ilia Shumailov, Nicolas Papernot, Kassem Fawaz |
USENIX Security Symposium | 7 |
| 2023 | Automated Cookie Notice Analysis and Enforcement
Rishabh Khandelwal, Asmit Nayak, Hamza Harkous, Kassem Fawaz |
USENIX Security Symposium | 4 |
| 2023 | Fairness Properties of Face Recognition and Obfuscation Systems
Harrison Rosenberg, Brian Tang, Kassem Fawaz, Somesh Jha |
USENIX Security Symposium | 3 |
| 2022 | CONFIDANT: A Privacy Controller for Social RobotsabstractAs social robots become increasingly prevalent in day-to-day environments, they will participate in conversations and appropriately manage the information shared with them. However, little is known about how robots might appropriately discern the sensitivity of information, which has major implications for human-robot trust. As a first step to address a part of this issue, we designed a privacy controller, Confidant, for conversational social robots, capable of using contextual metadata (e.g., sentiment, relationships, topic) from conversations to model privacy boundaries. Afterwards, we conducted two crowdsourced user studies. The first study ($n=174$) focused on whether a variety of human-human interaction scenarios were perceived as either private/sensitive or non-private/non-sensitive. The findings from our first study were used to generate association rules. Our second study ($n=95$) evaluated the effectiveness and accuracy of the privacy controller in human-robot interaction scenarios by comparing a robot that used our privacy controller against a baseline robot with no privacy controls. Our results demonstrate that the robot with the privacy controller outperforms the robot without the privacy controller in privacy-awareness, trustworthiness, and social-awareness. We conclude that the integration of privacy controllers in authentic human-robot conversations can allow for more trustworthy robots. This initial privacy controller will serve as a foundation for more complex solutions. Brian Tang, Dakota Sullivan, Bengisu Cagiltay, Varun Chandrasekaran, Kassem Fawaz, Bilge Mutlu |
HRI | 5 |
| 2022 | Rethinking Image-Scaling Attacks: The Interplay Between Vulnerabilities in Machine Learning SystemsabstractAs real-world images come in varying sizes, the machine learning model is part of a larger system that includes an upstream image scaling algorithm. In this paper, we investigate the interplay between vulnerabilities of the image scaling procedure and machine learning models in the decision-based black-box setting. We propose a novel sampling strategy to make a black-box attack exploit vulnerabilities in scaling algorithms, scaling defenses, and the final machine learning model in an end-to-end manner. Based on this scaling-aware attack, we reveal that most existing scaling defenses are ineffective under threat from downstream models. Moreover, we empirically observe that standard black-box attacks can significantly improve their performance by exploiting the vulnerable scaling procedure. We further demonstrate this problem on a commercial Image Analysis API with decision-based black-box attacks. Yue Gao 0011, Ilia Shumailov, Kassem Fawaz |
ICML | 3 |
| 2022 | On the Limitations of Stochastic Pre-processing DefensesabstractDefending against adversarial examples remains an open problem. A common belief is that randomness at inference increases the cost of finding adversarial inputs. An example of such a defense is to apply a random transformation to inputs prior to feeding them to the model. In this paper, we empirically and theoretically investigate such stochastic pre-processing defenses and demonstrate that they are flawed. First, we show that most stochastic defenses are weaker than previously thought; they lack sufficient randomness to withstand even standard attacks like projected gradient descent. This casts doubt on a long-held assumption that stochastic defenses invalidate attacks designed to evade deterministic defenses and force attackers to integrate the Expectation over Transformation (EOT) concept. Second, we show that stochastic defenses confront a trade-off between adversarial robustness and model invariance; they become less effective as the defended model acquires more invariance to their randomization. Future work will need to decouple these two effects. We also discuss implications and guidance for future research. Yue Gao 0011, Ilia Shumailov, Kassem Fawaz, Nicolas Papernot |
NeurIPS | 3 |
| 2022 | Towards More Robust Keyword Spotting for Voice Assistants
Shimaa Ahmed, Ilia Shumailov, Nicolas Papernot, Kassem Fawaz |
USENIX Security Symposium | 4 |
| 2022 | Experimental Security Analysis of the App Model in Business Collaboration Platforms
Yunang Chen, Yue Gao 0011, Nick Ceccio, Rahul Chatterjee 0001, Kassem Fawaz, Earlence Fernandes |
USENIX Security Symposium | 5 |
| 2022 | Are You Really Muted?: A Privacy Analysis of Mute Buttons in Video Conferencing AppsabstractVideo conferencing apps (VCAs) make it possible for previously private spaces — bedrooms, living rooms, and kitchens — into semi-public extensions of the office. For the most part, users have accepted these apps in their personal space without much thought about the permission models that govern the use of their private data during meetings. While access to a device’s video camera is carefully controlled, little has been done to ensure the same level of privacy for accessing the microphone. In this work, we ask the question: what happens to the microphone data when a user clicks the mute button in a VCA? We first conduct a user study to analyze users’ understanding of the permission model of the mute button. Then, using runtime binary analysis tools, we trace raw audio flow in many popular VCAs as it traverses the app from the audio driver to the network. We find fragmented policies for dealing with microphone data among VCAs — some continuously monitor the microphone input during mute, and others do so periodically. One app transmits statistics of the audio to its telemetry servers while the app is muted. Using network traffic that we intercept en route to the telemetry server, we implement a proof-of-concept background activity classifier and demonstrate the feasibility of inferring the ongoing background activity during a meeting — cooking, cleaning, typing, etc. We achieved 81.9% macro accuracy on identifying six common background activities using intercepted outgoing telemetry packets when a user is muted. Yucheng Yang 0003, Jack West, George K. Thiruvathukal, Neil Klingensmith, Kassem Fawaz |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | PriSEC: A Privacy Settings Enforcement Controller
Rishabh Khandelwal, Thomas Linden, Hamza Harkous, Kassem Fawaz |
USENIX Security Symposium | 4 |
| 2021 | Kalεido: Real-Time Privacy Control for Eye-Tracking Systems
Amrita Roy Chowdhury 0001, Kassem Fawaz, Younghyun Kim 0001 |
USENIX Security Symposium | 3 |
| 2021 | Face-Off: Adversarial Face ObfuscationabstractAbstract Advances in deep learning have made face recognition technologies pervasive. While useful to social media platforms and users, this technology carries significant privacy threats. Coupled with the abundant information they have about users, service providers can associate users with social interactions, visited places, activities, and preferences–some of which the user may not want to share. Additionally, facial recognition models used by various agencies are trained by data scraped from social media platforms. Existing approaches to mitigate associated privacy risks result in an imbalanced trade-off between privacy and utility. In this paper, we address this trade-off by proposing Face-Off, a privacy-preserving framework that introduces strategic perturbations to images of the user’s face to prevent it from being correctly recognized. To realize Face-Off, we overcome a set of challenges related to the black-box nature of commercial face recognition services, and the scarcity of literature for adversarial attacks on metric networks. We implement and evaluate Face-Off to find that it deceives three commercial face recognition services from Microsoft, Amazon, and Face++. Our user study with 423 participants further shows that the perturbations come at an acceptable cost for the users. Varun Chandrasekaran, Chuhan Gao, Brian Tang, Kassem Fawaz, Somesh Jha, Suman Banerjee 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2020 | Preech: A System for Privacy-Preserving Speech Transcription
Shimaa Ahmed, Amrita Roy Chowdhury 0001, Kassem Fawaz, Parameswaran Ramanathan |
USENIX Security Symposium | 3 |
| 2020 | The Privacy Policy Landscape After the GDPRabstractAbstract The EU General Data Protection Regulation (GDPR) is one of the most demanding and comprehensive privacy regulations of all time. A year after it went into effect, we study its impact on the landscape of privacy policies online. We conduct the first longitudinal, in-depth, and at-scale assessment of privacy policies before and after the GDPR. We gauge the complete consumption cycle of these policies, from the first user impressions until the compliance assessment. We create a diverse corpus of two sets of 6,278 unique English-language privacy policies from inside and outside the EU, covering their pre-GDPR and the post-GDPR versions. The results of our tests and analyses suggest that the GDPR has been a catalyst for a major overhaul of the privacy policies inside and outside the EU. This overhaul of the policies, manifesting in extensive textual changes, especially for the EU-based websites, comes at mixed benefits to the users. While the privacy policies have become considerably longer, our user study with 470 participants on Amazon MTurk indicates a significant improvement in the visual representation of privacy policies from the users’ perspective for the EU websites. We further develop a new workflow for the automated assessment of requirements in privacy policies. Using this workflow, we show that privacy policies cover more data practices and are more consistent with seven compliance requirements post the GDPR. We also assess how transparent the organizations are with their privacy practices by performing specificity analysis. In this analysis, we find evidence for positive changes triggered by the GDPR, with the specificity level improving on average. Still, we find the landscape of privacy policies to be in a transitional phase; many policies still do not meet several key GDPR requirements or their improved coverage comes with reduced specificity. Thomas Linden, Rishabh Khandelwal, Hamza Harkous, Kassem Fawaz |
Proc. Priv. Enhancing Technol. | 4 |
| 2019 | Velody: Nonlinear Vibration Challenge-Response for Resilient User AuthenticationabstractBiometrics have been widely adopted for enhancing user authentication, benefiting usability by exploiting pervasive and collectible unique characteristics from physiological or behavioral traits of human. However, successful attacks on "static" biometrics such as fingerprints have been reported where an adversary acquires users' biometrics stealthily and compromises non-resilient biometrics. Kassem Fawaz, Younghyun Kim 0001 |
CCS | 2 |
| 2019 | Privacy Protection for Audio Sensing Against Multi-Microphone AdversariesabstractAbstract Audio-based sensing enables fine-grained human activity detection, such as sensing hand gestures and contact-free estimation of the breathing rate. A passive adversary, equipped with microphones, can leverage the ongoing sensing to infer private information about individuals. Further, with multiple microphones, a beamforming-capable adversary can defeat the previously-proposed privacy protection obfuscation techniques. Such an adversary can isolate the obfuscation signal and cancel it, even when situated behind a wall. AudioSentry is the first to address the privacy problem in audio sensing by protecting the users against a multi-microphone adversary. It utilizes the commodity and audio-capable devices, already available in the user’s environment, to form a distributed obfuscator array. AudioSentry packs a novel technique to carefully generate obfuscation beams in different directions, preventing the multi-microphone adversary from canceling the obfuscation signal. AudioSentry follows by a dynamic channel estimation scheme to preserve authorized sensing under obfuscation. AudioSentry offers the advantages of being practical to deploy and effective against an adversary with a large number of microphones. Our extensive evaluations with commodity devices show that protects the user’s privacy against a 16-microphone adversary with only four commodity obfuscators, regardless of the adversary’s position. AudioSentry provides its privacy-preserving features with little overhead on the authorized sensor. Chuhan Gao, Kassem Fawaz, Sanjib Sur 0001, Suman Banerjee 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep Learning
Hamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub, Kang G. Shin, Karl Aberer |
USENIX Security Symposium | 2 |
| 2017 | Continuous Authentication for Voice AssistantsabstractVoice has become an increasingly popular User Interaction (UI) channel, mainly contributing to the current trend of wearables, smart vehicles, and home automation systems. Voice assistants such as Alexa, Siri, and Google Now, have become our everyday fixtures, especially when/where touch interfaces are inconvenient or even dangerous to use, such as driving or exercising. The open nature of the voice channel makes voice assistants difficult to secure, and hence exposed to various threats as demonstrated by security researchers. To defend against these threats, we present VAuth, the first system that provides continuous authentication for voice assistants. VAuth is designed to fit in widely-adopted wearable devices, such as eyeglasses, earphones/buds and necklaces, where it collects the body-surface vibrations of the user and matches it with the speech signal received by the voice assistant's microphone. VAuth guarantees the voice assistant to execute only the commands that originate from the voice of the owner. We have evaluated VAuth with 18 users and 30 voice commands and find it to achieve 97% detection accuracy and less than 0.1% false positive rate, regardless of VAuth's position on the body and the user's language, accent or mobility. VAuth successfully thwarts various practical attacks, such as replay attacks, mangled voice attacks, or impersonation attacks. It also incurs low energy and latency overheads and is compatible with most voice assistants. Huan Feng, Kassem Fawaz, Kang G. Shin |
MobiCom | 2 |
| 2016 | RT-OPEX: Flexible Scheduling for Cloud-RAN ProcessingabstractIt is cost-effective to process wireless frames on general purpose processors (GPPs) in place of dedicated hardware. Wireless operators are decoupling signal processing from basestations and implementing it in a cloud of compute resources, also known as a cloud-RAN (C-RAN). A C-RAN must meet the deadlines of processing wireless frames; for example, 3ms to transport, decode and respond to an LTE uplink frame. The design of baseband processing on these platforms is thus a major challenge for which various processing and real-time scheduling techniques have been proposed. In this paper, we implement a medium-scale C-RAN-type platform and conduct an in-depth analysis of its real-time performance. We find that the commonly used (e.g., partitioned) scheduling techniques for wireless frame processing are inefficient as they either over-provision resources or suffer from deadline misses. This inefficiency stems from the large variations in processing times due to fluctuations in wireless traffic. We present a new framework called RTOPEX, that leverages these variations and proposes a flexible approach for scheduling. RT-OPEX dynamically migrates parallelizable tasks to idle compute resources at runtime, reducing processing times and hence deadline misses at no additional cost. We implement and evaluate RT-OPEX on a commodity GPP platform using realistic cellular workload traces. Our results show that RT-OPEX achieves an order-of-magnitude improvement over existing C-RAN schedulers in meeting frame processing deadlines. Krishna C. Garikipati, Kassem Fawaz, Kang G. Shin |
CoNEXT | 2 |
| 2016 | Protecting Privacy of BLE Device Users
Kassem Fawaz, Kyu-Han Kim, Kang G. Shin |
USENIX Security Symposium | 1 |
| 2016 | Privacy vs. Reward in Indoor Location-Based ServicesabstractAbstract With the advance of indoor localization technology, indoor location-based services (ILBS) are gaining popularity. They, however, accompany privacy concerns. ILBS providers track the users’ mobility to learn more about their behavior, and then provide them with improved and personalized services. Our survey of 200 individuals highlighted their concerns about this tracking for potential leakage of their personal/private traits, but also showed their willingness to accept reduced tracking for improved service. In this paper, we propose PR-LBS (Privacy vs. Reward for Location-Based Service), a system that addresses these seemingly conflicting requirements by balancing the users’ privacy concerns and the benefits of sharing location information in indoor location tracking environments. PR-LBS relies on a novel location-privacy criterion to quantify the privacy risks pertaining to sharing indoor location information. It also employs a repeated play model to ensure that the received service is proportionate to the privacy risk. We implement and evaluate PR-LBS extensively with various real-world user mobility traces. Results show that PR-LBS has low overhead, protects the users’ privacy, and makes a good tradeoff between the quality of service for the users and the utility of shared location data for service providers. Kassem Fawaz, Kyu-Han Kim, Kang G. Shin |
Proc. Priv. Enhancing Technol. | 1 |
| 2015 | Anatomization and Protection of Mobile Apps' Location Privacy Threats
Kassem Fawaz, Huan Feng, Kang G. Shin |
USENIX Security Symposium | 1 |
| 2015 | LinkDroid: Reducing Unregulated Aggregation of App Usage Behaviors
Huan Feng, Kassem Fawaz, Kang G. Shin |
USENIX Security Symposium | 2 |
| 2015 | PBCOV: a property-based coverage criterion
Kassem Fawaz, Fadi A. Zaraket, Wes Masri, Hamza Harkous |
Softw. Qual. J. | 1 |
| 2015 | Replication enabled distributed cache invalidation method: replication enabled distributed cache management system for wireless mobile networksabstractAbstract This work proposes a replication scheme that is implemented on top of a previously proposed system for MANETs that cache submitted queries in special nodes, called query directories, and uses them to locate the data (responses) that are stored in the nodes that first request them, called caching nodes. The system, which was named distributed cache invalidation method (DCIM), includes client‐based mechanisms for keeping the cached data consistent with the data source. In this work, we extend DCIM to handle cache replicas inside the MANET. For this purpose, we utilize a push‐based approach within the MANET to propagate the server updates to replicas inside the network. The result is a hybrid approach that utilizes the benefits of pull approaches for client server communication and those of push approaches inside the network between the replicas. The approach is analyzed analytically, and the appropriate number of replicas is obtained, where it was concluded that full replication of the indices of data items at the query directory and two‐partial replication of the data items themselves makes most sense. Simulation results based on ns2 demonstrate the ability of the added replication scheme to lower delays and improve hit ration at the cost of mild increases in overhead traffic. Copyright © 2013 John Wiley & Sons, Ltd. Kassem Fawaz, Abdalla Artail, Rasha Al-Khansa, Hassan Artail, Haïdar Safa |
Wirel. Commun. Mob. Comput. | 1 |
| 2014 | Location Privacy Protection for Smartphone UsersabstractAs smartphones are increasingly used to run apps that provide users with location-based services, the users' location privacy has become a major concern. Existing solutions to this concern are deficient in terms of practicality, efficiency, and effectiveness. To address this problem, we design, implement, and evaluate LP-Guardian, a novel and comprehensive framework for location privacy protection for Android smartphone users. LP-Guardian's overcomes the shortcomings of existing approaches by addressing the tracking, profiling, and identification threats while maintaining app functionality. We have implemented and evaluated LP-Guardian's on Android 4.3.1. Our evaluation results show that LP-Guardian's effectively thwarts the privacy threats, without deteriorating the user's experience (less than 10% overhead in delay and energy). Also, LP-Guardian's privacy protection is shown to be achieved at a tolerable loss in app functionality. Kassem Fawaz, Kang G. Shin |
CCS | 1 |
| 2013 | Improving vehicular safety message delivery through the implementation of a cognitive vehicular network
Ali J. Ghandour, Kassem Fawaz, Hassan Artail, Marco Di Felice, Luciano Bononi |
Ad Hoc Networks | 2 |
| 2013 | DCIM: Distributed Cache Invalidation Method for Maintaining Cache Consistency in Wireless Mobile NetworksabstractThis paper proposes distributed cache invalidation mechanism (DCIM), a client-based cache consistency scheme that is implemented on top of a previously proposed architecture for caching data items in mobile ad hoc networks (MANETs), namely COACS, where special nodes cache the queries and the addresses of the nodes that store the responses to these queries. We have also previously proposed a server-based consistency scheme, named SSUM, whereas in this paper, we introduce DCIM that is totally client-based. DCIM is a pull-based algorithm that implements adaptive time to live (TTL), piggybacking, and prefetching, and provides near strong consistency capabilities. Cached data items are assigned adaptive TTL values that correspond to their update rates at the data source, where items with expired TTL values are grouped in validation requests to the data source to refresh them, whereas unexpired ones but with high request rates are prefetched from the server. In this paper, DCIM is analyzed to assess the delay and bandwidth gains (or costs) when compared to polling every time and push-based schemes. DCIM was also implemented using ns2, and compared against client-based and server-based schemes to assess its performance experimentally. The consistency ratio, delay, and overhead traffic are reported versus several variables, where DCIM showed to be superior when compared to the other systems. Kassem Fawaz, Hassan Artail |
IEEE Trans. Mob. Comput. | 1 |
| 2012 | A two-layer cache replication scheme for dense mobile ad hoc networksabstractThis paper proposes a data replication scheme implemented on top of a cooperative data caching architecture in MANETs that caches submitted queries in special nodes, called query directories (QDs), and uses them to locate data (responses) stored in the nodes that requested them, and called caching nodes (CNs). The QD entries are replicated according to a cost minimization model, and the actual data items are placed in nearby CNs. The proposed system is dynamic, as it adapts to topology changes and relocates replicas as necessary. The preliminary prototype of the proposed method is simulated using ns2 to assess its performance experimentally. Enhancements in performance in terms of lowered access delay and improved hit rates are reported, while maintaining a cap on overhead traffic. Kassem Fawaz, Hassan Artail |
GLOBECOM | 1 |
| 2012 | A Proxy-Based Architecture for Dynamic Discovery and Invocation of Web Services from Mobile DevicesabstractMobile devices are getting more pervasive, and it is becoming increasingly necessary to integrate web services into applications that run on these devices. We introduce a novel approach for dynamically invoking web service methods from mobile devices with minimal user intervention that only involves entering a search phrase and values for the method parameters. The architecture overcomes technical challenges that involve consuming discovered services dynamically by introducing a man-in-the-middle (MIM) server that provides a web service whose responsibility is to discover needed services and build the client-side proxies at runtime. The architecture moves to the MIM server energy-consuming tasks that would otherwise run on the mobile device. Such tasks involve communication with servers over the Internet, XML-parsing of files, and on-the-fly compilation of source code. We perform extensive evaluations of the system performance to measure scalability as it relates to the capacity of the MIM server in handling mobile client requests, and device battery power savings resulting from delegating the service discovery tasks to the server. Hassan Artail, Kassem Fawaz, Ali J. Ghandour |
IEEE Trans. Serv. Comput. | 2 |
| 2011 | Slow port scanning detectionabstractPort scanning is the most popular reconnaissance technique attackers use to discover services they can break into. Port scanning detection has received a lot of attention by researchers. However a slow port scan attack can deceive most of the existing Intrusion Detection Systems (IDS). In this paper, we present a new, simple, and efficient method for detecting slow port scans. Our proposed method is mainly composed of two phases: (1) a feature collection phase that analyzes network traffic and extracts the features needed to classify a certain IP as malicious or not. (2) A classification phase that divides the IPs, based on the collected features, into three groups: normal IPs, suspicious IPs and scanner IPs. The IPs our approach classify as suspicious are kept for the next (K) time windows for further examination to decide whether they represent scanners or legitimate users. Hence, this approach is different than the traditional approach used by IDSs that classifies IPs as either legitimate or scanners, and thus producing a high number of false positives and false negatives. A small Local Area Network was put together to test our proposed method. The experiments show the effectiveness of our proposed method in correctly identifying malicious scanners when both normal and slow port scan were performed using the three most common TCP port scanning techniques. Moreover, our method detects malicious scanners that are otherwise not detected using well known IDSs such as Snort. Mehiar Dabbagh, Ali J. Ghandour, Kassem Fawaz, Wassim El-Hajj, Hazem M. Hajj |
IAS | 3 |
| 2011 | Data delivery guarantees in congested Vehicular ad hoc networks using cognitive networksabstractThe Wireless Access in Vehicular Environments (WAVE) protocol stack is one of the most important protocols used to allocate spectrum for vehicular communication. In a previous work, we proved that WAVE does not provide sufficient spectrum for reliable exchange of safety information. More specifically, safety message delay is not acceptable and exceeds application requirements. In this paper, we propose a system that provides Data delivery guarantees using Cognitive networks principles in congested Vehicular ad hoc networks. We will refer to our system as DCV. Our goal is to ensure that all safety packets get generated and transmitted during the same interval. The system monitors the contention delay experienced by cars on the control channel where all safety packets should be transmitted. If the sensed contention delay exceeds delay threshold γ, the Road Side Unit (RSU) needs to increase the spectrum allocated to the control channel using cognitive networks. The RSU employs a feedback control design where additional bandwidth is added to drive the contention delay below the delay threshold γ used as reference input for the controller. Analysis and simulations indicate the effectiveness of the system in providing data delivery guarantees in vehicular networks and thus increasing safety measures on the road. Ali J. Ghandour, Kassem Fawaz, Hassan Artail |
IWCMC | 2 |
| 2011 | Extending the DSRC's control channel using cognitive networking concepts and Fuzzy LogicabstractWireless Access in Vehicular Environments (WAVE) protocol stack is the most important protocol used to allocate spectrum for vehicular communication. The capabilities of WAVE to provide reliable exchange of safety information are questionable. In a previous work, we suggested a system that employs cognitive networks principles to increase the spectrum allocated to the control channel (CCH) by the IEEE 802.11p amendment, where all safety information is transmitted. However, the decision making process implemented in that work does not differentiate between contention levels and does not relate precisely the measured contention to the amount of needed spectrum, which leads to an inefficient utilization of the white spectrum. In order to assign the minimum necessary additional bandwidth to relieve the contention, we suggest in this paper a new system that quantifies contention into multiple levels of severity based on Fuzzy Logic and maps additional spectrum correspondingly. Simulations show the effectiveness of the system in allocating the minimum needed bandwidth to relieve contention, without affecting other QoS parameters such as delay and number of untransmitted packets. Ali J. Ghandour, Kassem Fawaz, Hassan Artail, Ramsey F. Hamade |
PIMRC | 2 |
| 2011 | Fuzzy cognitive Vehicular Ad hoc NetworksabstractThe Wireless Access in Vehicular Environments (WAVE) protocol stack is one of the most important protocols proposed to standardize and allocate spectrum for vehicle-to-vehicle and vehicle-to-infrastructure communication. In a previous work, we proved that WAVE faces a spectrum scarcity problem which hinders reliable exchange of safety information. To overcome this problem, we proposed a system that applies cognitive networks principles to WAVE as to increase the spectrum allocated to the control channel (CCH) by the IEEE 802.11p amendment, where all safety information is transmitted. However, the decision making process in our previous work did not utilize the extra spectrum efficiently as it was not allocated according to the contention level experienced by the vehicle. In this paper, we suggest a system that employs a fuzzy logic system (FLS) to dynamically assign additional spectrum from the ISM band to the CCH. This system, which we call FCVANET, assigns the minimum necessary additional bandwidth to relieve the contention. The FLS takes as input 2 parameters, the message delay and the un-transmitted packets and utilizes a feedback loop. Our simulations show that the proposed system allocates bandwidth more efficiently in accordance with the contention level faced by the vehicles. The system succeeds to relieve contention by reducing delay and the number of un-transmitted packets. Ali J. Ghandour, Kassem Fawaz, Hassan Artail |
WiMob | 2 |
| 2009 | Indoor Propagation Effects on ToA Bias for Joint GNSS and Terrestrial Radio Based LocalizationabstractThe time based localization utilizing cellular communication networks has been investigated as a complementation to Global Navigation Satellite Systems (GNSS) for critical scenarios, like indoor or urban canyon areas. By suitable Hybrid Data Fusion (HDF) algorithms which combine the information from GNSS and terrestrial cellular networks, the estimated position accuracy can be improved. However, the wave propagation characteristics for joint GNSS and terrestrial mobile radio based localization as application has not been studied yet. Therefore, a measurement campaign for GNSS at 1.51 GHz and terrestrial radio at 5.2 GHz was performed. In this paper, an analysis of the outdoor to indoor channel for the joint localization as application is presented. It turns out to be that the Time of Arrival (ToA) bias, which is the difference between the geometric distance and the distance propagated by the first incoming wave, is depending on the elevation angle of incoming rays seen from the building to the transmitter. A comparison between two carrier frequencies is addressed. Wei Wang 0026, Thomas Jost, Christian Mensing, Armin Dammann, Kassem Fawaz |
VTC Spring | 5 |
| 2009 | CRUST: Implementation of clustering and routing functions for mobile ad hoc networks using reactive tuple-spaces
Hassan Artail, Rula Antoun, Kassem Fawaz |
Ad Hoc Networks | 3 |
| 2008 | A fast HTML web page change detection approach based on hashing and reducing the number of similarity computations
Hassan Artail, Kassem Fawaz |
Data Knowl. Eng. | 2 |