Anindya Maiti

dblp:98/8971 · DBLP profile ↗
← Back
21ranked-venue papers
4as first author
15since 2021 · last 2026
0000-0001-6461-2805ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 3 first-author · 11 since 2021Systems, architecture and hardware · 3 · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 OverHear: Headphone Based Multi-Sensor Keystroke Inference
Raveen Wijewickrama, Maryam Abbasihafshejani, Anindya Maiti, Murtuza Jadliwala
ACNS (3)3
2026 Prompt and Circumstances: Evaluating the Efficacy of Human Prompt Inference in AI-Generated Art
Khoi Trinh, Scott Seidenberger, Joseph Spracklen, Raveen Wijewickrama, Bimal Viswanath, Murtuza Jadliwala, Anindya Maiti
EvoMUSART7
2025 Why You've Got Mail: Evaluating Inbox Privacy Implications of Email Marketing Practices in Online Apps and Services
abstract
This study explores the widespread perception that personal data, such as email addresses, may be shared or sold without informed user consent, investigating whether these concerns are reflected in actual practices of popular online services and apps. Over the course of a year, we collected and analyzed the source, volume, frequency, and content of emails received by users after signing up for the 150 most popular online services and apps across various sectors. By examining patterns in email communications, we aim to identify consistent strategies used across industries, including potential signs of third-party data sharing. This analysis provides a critical evaluation of how email marketing tactics may intersect with data-sharing practices, with important implications for consumer privacy and regulatory oversight. Our study findings, conducted post-CCPA and GDPR, indicate that while no unknown third-party spam email was detected, internal and authorized third-party email marketing practices were pervasive, with companies frequently sending promotional and CRM emails despite opt-out preferences. The framework established in this work is designed to be scalable, allowing for continuous monitoring, and can be extended to include a more diverse set of apps and services for broader analysis, ultimately contributing to transparency in email address privacy practices.
Scott Seidenberger, Oluwasijibomi Ajisegiri, Noah Pursell, Fazil Raja, Anindya Maiti
CODASPY5
2025 EtherBee: A Global Dataset of Ethereum Node Performance Measurements Coupled with Honeypot Interactions and Full Network Sessions
Scott Seidenberger, Anindya Maiti
ICBC2
2025 MagnetDB: A Longitudinal Torrent Discovery Dataset with IMDb-Matched Movies and TV Shows
abstract
BitTorrent remains a prominent channel for illicit distribution of copyrighted material, yet the supply side of such content remains understudied. We introduce MagnetDB, a longitudinal dataset of torrents discovered through the BitTorrent DHT between 2018 and 2024, containing more than 28.6 million torrents and metadata of more than 950 million files. While our primary focus is on enabling research based on the supply of pirated movies and TV shows, the dataset also encompasses other legitimate and illegitimate torrents. By applying IMDb-matching and annotation to movie and TV show torrents, MagnetDB facilitates detailed analyses of pirated content evolution in the BitTorrent network. Researchers can leverage MagnetDB to examine distribution trends, subcultural practices, and the gift economy within piracy ecosystems. Through its scale and temporal scope, MagnetDB presents a unique opportunity for investigating the broader dynamics of BitTorrent and advancing empirical knowledge on digital piracy.
Scott Seidenberger, Noah Pursell, Anindya Maiti
ICWSM3
2025 A Picture is Worth a Thousand Prompts? Efficacy of Iterative Human-Driven Prompt Refinement in Image Regeneration Tasks
abstract
With AI-generated content becoming widespread across digital platforms, it is important to understand how such content is inspired and produced. This study explores the underexamined task of image regeneration, where a human operator iteratively refines prompts to recreate a specific target image. Unlike typical image generation, regeneration begins with a visual reference. A key challenge is whether existing image similarity metrics (ISMs) align with human judgments and can serve as useful feedback in this process. We conduct a structured user study to evaluate how iterative prompt refinement affects similarity to target images and whether ISMs reflect the improvements perceived by human observers. Our results show that prompt adjustments significantly improve alignment, both subjectively and quantitatively, highlighting the potential of iterative workflows in enhancing generative image quality.
Khoi Trinh, Scott Seidenberger, Raveen Wijewickrama, Murtuza Jadliwala, Anindya Maiti
IJCAI5
2025 Spiking Neural Networks in Vertical Federated Learning: Performance Trade-Offs
abstract
Federated machine learning enables model training across multiple participants while preserving data privacy. Vertical Federated Learning (VFL) handles scenarios in which participants have different feature sets for the same samples. Although Spiking Neural Networks (SNNs) offer efficiency advantages over Artificial Neural Networks (ANNs), their applicability in a VFL scenario remains unexplored. This paper examines SNNs in VFL, implementing and evaluating two architectures-with and without model splitting- using CIFAR-10 and CIFAR-100 datasets with VGG9 and ResNet models. The evaluation results show that SNNs achieve an accuracy comparable to that of ANNs in VFL while being significantly more energy efficient.
Maryam Abbasihafshejani, Anindya Maiti, Murtuza Jadliwala
NOMS2
2025 We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
Joseph Spracklen, Raveen Wijewickrama, A. H. M. Nazmus Sakib, Anindya Maiti, Bimal Viswanath, Murtuza Jadliwala
USENIX Security Symposium4
2024 De-anonymizing VR Avatars using Non-VR Motion Side-channels
abstract
Virtual Reality (VR) technology offers an immersive audio-visual experience to users through which they can interact with a digitally represented 3D space (i.e., a virtual world) using a headset device. By (visually) transporting users from their physical world to realistic virtual spaces, VR systems enable interactive and true-to-life versions of traditional applications such as gaming, remote conferencing and virtual tourism. However, VR applications also present significant user-privacy challenges. This paper studies a new type of privacy threat targeting VR users which attempts to connect their activities visible in the virtual world to their physical state sensed in the real world. Specifically, this paper analyzes the feasibility of carrying out a de-anonymization or identification attack on VR users by correlating visually observed movements of users' avatars in the virtual world with some auxiliary data (e.g., motion sensor data from mobile/wearable devices) representing their context/state in the physical world. To enable this attack, the paper proposes a novel framework which first employs a learning-based activity classification approach to translate the disparate visual movement data and motion sensor data into an activity-vector to ease comparison, followed by a filtering and identity ranking phase outputting an ordered list of potential identities corresponding to the target visual movement data. A comprehensive empirical evaluation of the proposed framework is conducted to study the feasibility of such a de-anonymization attack.
Mohd Sabra, Nisha Vinayaga-Sureshkanth, Ari Sharma, Anindya Maiti, Murtuza Jadliwala
WISEC4
2022 Background Buster: Peeking through Virtual Backgrounds in Online Video Calls
abstract
Video calling applications such as Zoom and Skype have become the preferred medium for both personal and professional communications. One feature in these applications that has gained prominence is the virtual background feature, which enables users to conceal their background by blending in a virtual image or video in place of the real background, thus providing users with background and contextual privacy. However, this feature is not robust enough, and depending on the target user’s activities, movement and accessories worn during the call, portions of the user’s background could leak which can then be reconstructed to reveal significant portions of the user’s real background, and other contextual information related to the real background. This paper conducts an investigative analysis of the background privacy provided by the virtual background feature in video calling applications by designing a novel background reconstruction framework, and using it to reveal users’ real background. By means a large dataset of call videos, collected from human subject participants and in the wild, a comprehensive evaluation of the proposed framework and related privacy attacks under a variety of different experimental parameters is then carried out. Results from these evaluations show that significant leakage of background information is feasible under certain conditions, rendering the feature ineffective in protecting privacy and giving users a false sense of security.
Mohd Sabra, Anindya Maiti, Murtuza Jadliwala
DSN2
2022 Wireless and Mobile Security Research and Teaching in the Post-Pandemic World
abstract
The COVID-19 pandemic disrupted many aspects of our lives at a global scale. This includes the disruption of the research and teaching we perform within the security and privacy community. As the pandemic is weaning off, the lessons learnt during the pandemic can be very valuable in the future, both for navigating pandemic-like situations, and for accommodating greater inclination towards remote work and education. In this panel, international experts with various professional backgrounds and different points of view will discuss the impact they faced over the last two years, such as halting (or starting) specific research problems due to pandemic-related restrictions, unique challenges in deploying new experiments and how they overcame them, and finding novel ways to facilitate social events like conferences and hackathons.
Anindya Maiti, Ahmad-Reza Sadeghi, Gabriela F. Ciocarlie, Patrick Tague
WISEC1
2022 An Investigative Study on the Privacy Implications of Mobile E-scooter Rental Apps
abstract
E-scooter rental services have significantly expanded the micromobility paradigm of short-distance urban and suburban transportation since their inception in 2017. Service providers around the world have followed a common rental model wherein customers (i.e., riders or users) download and install a mobile application for locating (finding) and renting e-scooters. Unlike many other app categories, e-scooter rental apps require a set of privacy-sensitive user data as a functional requirement. Unfortunately, privacy-related questions such as how much user data is being collected by these apps, is user data being safely handled once acquired, and with whom the collected user data is being shared are not readily known to customers. Answering such questions can be critical for users in determining which e-scooter rental services are sufficiently trustworthy per their personal privacy preferences. In this paper, we conduct a comprehensive analysis of e-scooter rental apps to answer these and other research questions related to user data collection, third-party involvement, usefulness of privacy policies, and evolution of user data management by different e-scooter apps/services over time. Our findings will create awareness among consumers vis-à-vis the data they share with service providers in return for the received e-scooter rental service, and it can also evoke more accountability and transparency from service providers towards their efforts and processes on protecting consumer privacy.
Nisha Vinayaga-Sureshkanth, Raveen Wijewickrama, Anindya Maiti, Murtuza Jadliwala
WISEC3
2021 Zoom on the Keystrokes: Exploiting Video Calls for Keystroke Inference Attacks
Mohd Sabra, Anindya Maiti, Murtuza Jadliwala
NDSS2
2021 Acoustics to the Rescue: Physical Key Inference Attack Revisited
Soundarya Ramesh, Rui Xiao 0002, Anindya Maiti, Jong Taek Lee, Harini Ramprasad, Ananda Kumar, Murtuza Jadliwala, Jun Han 0001
USENIX Security Symposium3
2021 Write to know: on the feasibility of wrist motion based user-authentication from handwriting
abstract
The popularity of smart wrist wearable technology (e.g., smart-watches) has rejuvenated the exploration of dynamic biometric-based authentication techniques that employ sensor data from these devices. Despite the progress demonstrated by the scientific community, research in this area has not successfully transitioned to practice, and we are yet to see a mainstream user-authentication product based on a dynamic biometric such as handwriting/hand gestures captured using commercial wrist wearables. This work undertakes an investigative analysis to further explore why that is the case. We accomplish this by studying the feasibility and practical deployability of handwriting-based authentication techniques in the literature that utilize motion sensors on-board wrist wearables. We conduct this analysis by replicating four state-of-the-art and representative handwriting-based authentication schemes that employ wrist motion data, in order to test their viability in realistic hand-writing/gesture scenarios. By using data collected from actual human subjects in an unconstrained fashion, we comparatively evaluate the performance of these schemes with well-defined usability and security metrics. Our experimental results show that some of the tested schemes perform considerably well in practice, and are promising. However, they do suffer from several practical user-dependent and technique-specific challenges that act as roadblocks towards their wide-scale adoption in mainstream applications.
Raveen Wijewickrama, Anindya Maiti, Murtuza Jadliwala
WISEC2
2019 deWristified: handwriting inference using wrist-based motion sensors revisited
abstract
Several recent research efforts have shown that privacy of handwritten information is vulnerable to inference threats that employ zero-permission motion sensors commonly found on wrist-wearables (e.g., smart watches and fitness bands) as information side-channels. While the adversary model in these earlier efforts have been reasonable and the proposed inference (or threat) frameworks themselves are practical and have technical merit, the related empirical evaluations suffer from several significant shortcomings, such as, use of specialized sensor hardware and highly constrained or restrictive experimental procedures, to name a few. As a result, it is hard to estimate the practical feasibility of these threats from existing research results in the literature, and thus, the extent to which end-users must be concerned about the possibility of such attacks in real-life. To answer the above question, this paper replicates some of the well-known wrist motion-based handwriting inference frameworks in the literature in order to (re)evaluate their success or accuracy in natural, unrestricted handwriting scenarios and settings by employing commercially available wrist-wearables. The results of these extensive replication and (re)evaluation studies highlight several characteristics in motion data corresponding to natural handwriting scenarios, which were either not observed or ignored by earlier efforts, and contribute to poor inference accuracy of the corresponding frameworks. In summary, accurate and practical handwriting inference using motion data (side-channeled) from consumer-grade wrist-wearables is difficult primarily due to unique and/or inconsistent handwriting behavior observed in natural writing.
Raveen Wijewickrama, Anindya Maiti, Murtuza Jadliwala
WiSec2
2018 Towards Inferring Mechanical Lock Combinations using Wrist-Wearables as a Side-Channel
abstract
Wrist-wearables such as smartwatches and fitness bands are equipped with a variety of high-precision sensors that support novel contextual and activity-based applications. The presence of a diverse set of on-board sensors, however, also expose an additional attack surface which, if not adequately protected, could be potentially exploited to leak private user information. In this paper, we investigate the feasibility of a new attack that takes advantage of a wrist-wearable's motion sensors to infer input on mechanical devices typically used to secure physical access, for example, combination locks. We outline an inference framework that attempts to infer a lock's unlock combination from the wrist motion captured by a smartwatch's gyroscope sensor, and uses a probabilistic model to produce a ranked list of likely unlock combinations. We conduct a thorough empirical evaluation of the proposed framework by employing unlocking-related motion data collected from human subject participants in a variety of controlled and realistic settings. Evaluation results from these experiments demonstrate that motion data from wrist-wearables can be effectively employed as a side-channel to significantly reduce the unlock combination search-space of commonly found combination locks, thus compromising the physical security provided by these locks.
Anindya Maiti, Ryan Heard, Mohd Sabra, Murtuza Jadliwala
WISEC1
2018 Side-Channel Inference Attacks on Mobile Keypads Using Smartwatches
abstract
Smartwatches enable many novel applications and are fast gaining popularity. However, the presence of a diverse set of onboard sensors provides an additional attack surface to malicious software and services on these devices. In this paper, we investigate the feasibility of key press inference attacks on handheld numeric touchpads by using smartwatch motion sensors as a side-channel. We consider different typing scenarios, and propose multiple attack approaches to exploit the characteristics of the observed wrist movements for inferring individual key presses. Experimental evaluation using commercial off-the-shelf smartwatches and smartphones show that key press inference using smartwatch motion sensors is not only fairly accurate, but also comparable with similar attacks using smartphone motion sensors. Additionally, hand movements captured by a combination of both smartwatch and smartphone motion sensors yields better inference accuracy than either device considered individually.
Anindya Maiti, Murtuza Jadliwala, Jibo He, Igor Bilogrevic
IEEE Trans. Mob. Comput.1
2017 Seer Grid: Privacy and Utility Implications of Two-Level Load Prediction in Smart Grids
abstract
We propose “Seer Grid”, a novel two-level energy consumption prediction framework for smart grids, aimed to decrease the trade-off between privacy requirements (of the customer) and data utility requirements (of the energy company (EC)). The first-level prediction at the household level is performed by each smart meter (SM), and the predicted energy consumption pattern (instead of the actual energy usage data) is reported to a cluster head (CH). Then, a second-level prediction at the neighborhood level is done by the CH which predicts the energy spikes in the neighborhood or cluster and shares it with the EC. Our two-level prediction mechanism is designed such that it preserves the correlation between the predicted and actual energy consumption patterns at the cluster level and removes this correlation in the predicted data communicated by each SM to the CH. This maintains the usefulness of the cluster-level energy consumption data communicated to the EC, while preserving the privacy of the household-level energy consumption data against the CH (and thus the EC). Our evaluation results show that Seer Grid is successful in hiding private consumption patterns at the household-level while still being able to accurately predict energy consumption at the neighborhood-level.
Arash Boustani, Anindya Maiti, Sina Yousefian Jazi, Murtuza Jadliwala, Vinod Namboodiri
IEEE Trans. Parallel Distributed Syst.2
2016 Smartwatch-Based Keystroke Inference Attacks and Context-Aware Protection Mechanisms
abstract
Wearable devices, such as smartwatches, are furnished with state-of-the-art sensors that enable a range of context-aware applications. However, malicious applications can misuse these sensors, if access is left unaudited. In this paper, we demonstrate how applications that have access to motion or inertial sensor data on a modern smartwatch can recover text typed on an external QWERTY keyboard. Due to the distinct nature of the perceptible motion sensor data, earlier research efforts on emanation based keystroke inference attacks are not readily applicable in this scenario. The proposed novel attack framework characterizes wrist movements (captured by the inertial sensors of the smartwatch worn on the wrist) observed during typing, based on the relative physical position of keys and the direction of transition between pairs of keys. Eavesdropped keystroke characteristics are then matched to candidate words in a dictionary. Multiple evaluations show that our keystroke inference framework has an alarmingly high classification accuracy and word recovery rate. With the information recovered from the wrist movements perceptible by a smartwatch, we exemplify the risks associated with unaudited access to seemingly innocuous sensors (e.g., accelerometers and gyroscopes) of wearable devices. As part of our efforts towards preventing such side-channel attacks, we also develop and evaluate a novel context-aware protection framework which can be used to automatically disable (or downgrade) access to motion sensors, whenever typing activity is detected.
Anindya Maiti, Oscar Armbruster, Murtuza Jadliwala, Jibo He
AsiaCCS1
2014 Social Puzzles: Context-Based Access Control in Online Social Networks
abstract
The increasing popularity of online social networks (OSNs) is spawning new security and privacy concerns. Currently, a majority of OSNs offer very naive access control mechanisms that are primarily based on static access control lists (ACL) or policies. But as the number of social connections grow, static ACL based approaches become ineffective and unappealing to OSN users. There is an increased need in social-networking and data-sharing applications to control access to data based on the associated context (e.g., event, location, and users involved), rather than solely on data ownership and social connections. Surveillance is another critical concern for OSN users, as the service provider may further scrutinize data posted or shared by users for personal gains (e.g., targeted advertisements), for use by corporate partners or to comply with legal orders. In this paper, we introduce a novel paradigm of context-based access control in OSNs, where users are able to access the shared data only if they have knowledge of the context associated with it. We propose two constructions for context-based access control in OSNs: the first is based on a novel application of Shamir's secret sharing scheme, whereas the second makes use of an attribute-based encryption scheme. For both constructions, we analyze their security properties, implement proof-of-concept applications for Facebook and empirically evaluate their functionality and performance. Our empirical measurements show that the proposed constructions execute efficiently on standard computing hardware, as well as, on portable mobile devices.
Murtuza Jadliwala, Anindya Maiti, Vinod Namboodiri
DSN2