VLDB 2026 Research / reviewers in the wild / expert
Siamak F. Shahandashti
dblp:s/SFShahandashti · also Siamak Fayyaz Shahandashti
· DBLP profile ↗
23ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0002-5284-6847ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 5 first-author · 8 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Empowering Stakeholders with Participatory Auditing of Predictive AI: Perspectives from End-Users and Decision Subjects without AI ExpertiseabstractArtificial intelligence (AI) applications have become ubiquitous in their impact on individuals and society, highlighting a crucial need for their responsible development. Recent research has called for participatory AI auditing, empowering individuals without AI expertise to audit AI applications throughout the entire AI development pipeline. Our work focuses on investigating how to support these kinds of auditors through participatory AI auditing tools and processes. We conducted a series of co-design workshops, using two health-related predictive AI applications as examples. Our results show that participants wanted to be part of AI audits, and were insightful in identifying the potential impacts of applications, but needed to be assisted in conducting audits, especially how to measure impacts. Importantly, participants provided examples of impacts not considered in current risk/harm taxonomies. Our findings provide implications for the design of tools and processes to empower everyone to contribute to responsible AI development in the future. Patrizia Di Campli San Vito, Evangelia Fringi, Penny S. Johnston, Leonardo C. T. Bezerra, Marios Aristodemou, Siamak F. Shahandashti, Emily O'Hara, Laura Fiona Whyte, Mark Wong, Ayah Soufan, Yashar Moshfeghi, Simone Stumpf |
CHI | 6 |
| 2025 | Cuckoo's Nest: An Ultra-Lightweight DoS-resilient Bitcoin Mempool
Hina Binte Haq, Syed Taha Ali, Siamak F. Shahandashti |
ICBC | 3 |
| 2025 | Minoritised Ethnic People's Security and Privacy Concerns and Responses towards Essential Online Services
Aunam Quyoum, Mark Wong, Sebati Ghosh, Siamak F. Shahandashti |
SOUPS | 4 |
| 2024 | The Emperor is Now Clothed: A Secure Governance Framework for Web User Authentication Through Password Managers
Ali Cherry, Konstantinos Barmpis, Siamak F. Shahandashti |
ICICS (2) | 3 |
| 2024 | A Subexponential Quantum Algorithm for the Semidirect Discrete Logarithm Problem
Christopher Battarbee, Delaram Kahrobaei, Ludovic Perret, Siamak F. Shahandashti |
PQCrypto (1) | 4 |
| 2023 | The Effect of Length on Key Fingerprint Verification Security and UsabilityabstractIn applications such as end-to-end encrypted instant messaging, secure email, and device pairing, users need to compare key fingerprints to detect impersonation and adversary-in-the-middle attacks. Key fingerprints are usually computed as truncated hashes of each party’s view of the channel keys, encoded as an alphanumeric or numeric string, and compared out-of-band, e.g. manually, to detect any inconsistencies. Previous work has extensively studied the usability of various verification strategies and encoding formats, however, the exact effect of key fingerprint length on the security and usability of key fingerprint verification has not been rigorously investigated. We present a 162-participant study on the effect of numeric key fingerprint length on comparison time and error rate. While the results confirm some widely-held intuitions such as general comparison times and errors increasing significantly with length, a closer look reveals interesting nuances. The significant rise in comparison time only occurs when highly similar fingerprints are compared, and comparison time remains relatively constant otherwise. On errors, our results clearly distinguish between security non-critical errors that remain low irrespective of length and security critical errors that significantly rise, especially at higher fingerprint lengths. A noteworthy implication of this latter result is that Signal / WhatsApp key fingerprints provide a considerably lower level of security than usually assumed. Dan Turner, Siamak F. Shahandashti, Helen Petrie |
ARES | 2 |
| 2023 | SPDH-Sign: Towards Efficient, Post-quantum Group-Based Signatures
Christopher Battarbee, Delaram Kahrobaei, Ludovic Perret, Siamak F. Shahandashti |
PQCrypto | 4 |
| 2021 | Accept All: The Landscape of Cookie Banners in Greece and the UK
Georgios Kampanos, Siamak F. Shahandashti |
SEC | 2 |
| 2021 | Formal modelling and security analysis of bitcoin's payment protocol
Paolo Modesti, Siamak F. Shahandashti, Patrick McCorry, Feng Hao 0001 |
Comput. Secur. | 2 |
| 2020 | Revisiting Security Vulnerabilities in Commercial Password Managers
Michael Carr, Siamak F. Shahandashti |
SEC | 2 |
| 2020 | SEAL: Sealed-Bid Auction Without AuctioneersabstractWe propose the first auctioneer-free sealed-bid auction protocol with a linear computation and communication complexity O(c), c being the bit length of the bid price. Our protocol, called Self-Enforcing Auction Lot (SEAL), operates in a decentralized setting, where bidders jointly compute the maximum bid while preserving the privacy of losing bids. In our protocol, we do not require any secret channels between participants. All operations are publicly verifiable; everyone including third-party observers is able to verify the integrity of the auction outcome. Upon learning the highest bid, the winner comes forward with a proof to prove that she is the real winner. Based on the proof, everyone is able to check if there is only one winner or there is a tie. While our main protocol works with the first-price sealed-bid, it can be easily extended to support the second-price sealed-bid (also known as the Vickrey auction), revealing only the winner and the second highest bid, while keeping the highest bid and all other bids secret. To the best of our knowledge, this work establishes to date the best computation and communication complexity for sealed-bid auction schemes without involving any auctioneer. Samiran Bag, Feng Hao 0001, Siamak F. Shahandashti, Indranil Ghosh Ray |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Analyzing and Patching SPEKE in ISO/IECabstractSimple password exponential key exchange (SPEKE) is a well-known password authenticated key exchange protocol that has been used in Blackberry phones for secure messaging and Entrust's TruePass end-to-end web products. It has also been included into international standards such as ISO/IEC 11770-4 and IEEE P1363.2. In this paper, we analyze the SPEKE protocol as specified in the ISO/IEC and IEEE standards. We identify that the protocol is vulnerable to two new attacks: an impersonation attack that allows an attacker to impersonate a user without knowing the password by launching two parallel sessions with the victim, and a key-malleability attack that allows a man-in-the-middle to manipulate the session key without being detected by the end users. Both attacks have been acknowledged by the technical committee of ISO/IEC SC 27 and ISO/IEC 11770-4 revised as a result. We propose a patched SPEKE called P-SPEKE and present a formal analysis in the Applied Pi Calculus using ProVerif to show that the proposed patch prevents both attacks. The proposed patch has been included into the latest revision of ISO/IEC 11770-4 published in 2017. Feng Hao 0001, Roberto Metere, Siamak F. Shahandashti, Changyu Dong |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | Texture to the Rescue: Practical Paper Fingerprinting Based on Texture PatternsabstractIn this article, we propose a novel paper fingerprinting technique based on analyzing the translucent patterns revealed when a light source shines through the paper. These patterns represent the inherent texture of paper, formed by the random interleaving of wooden particles during the manufacturing process. We show that these patterns can be easily captured by a commodity camera and condensed into a compact 2,048-bit fingerprint code. Prominent works in this area (Nature 2005, IEEE S8P 2009, CCS 2011) have all focused on fingerprinting paper based on the paper “surface.” We are motivated by the observation that capturing the surface alone misses important distinctive features such as the noneven thickness, random distribution of impurities, and different materials in the paper with varying opacities. Through experiments, we demonstrate that the embedded paper texture provides a more reliable source for fingerprinting than features on the surface. Based on the collected datasets, we achieve 0% false rejection and 0% false acceptance rates. We further report that our extracted fingerprints contain 807 degrees of freedom (DoF), which is much higher than the 249 DoF with iris codes (that have the same size of 2,048 bits). The high amount of DoF for texture-based fingerprints makes our method extremely scalable for recognition among very large databases; it also allows secure usage of the extracted fingerprint in privacy-preserving authentication schemes based on error correction techniques. Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001 |
ACM Trans. Priv. Secur. | 2 |
| 2016 | Towards Bitcoin Payment Networks
Patrick McCorry, Malte Möser, Siamak F. Shahandashti, Feng Hao 0001 |
ACISP (1) | 3 |
| 2016 | DRE-ip: A Verifiable E-Voting Scheme Without Tallying Authorities
Siamak F. Shahandashti, Feng Hao 0001 |
ESORICS (2) | 1 |
| 2016 | TouchSignatures: Identification of user touch actions and PINs based on mobile sensor data via JavaScript
Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001 |
J. Inf. Secur. Appl. | 3 |
| 2015 | TouchSignatures: Identification of User Touch Actions based on Mobile Sensors via JavaScriptabstractConforming to the recent W3C specifications (www.w3.org/TR/orientation-event), modern mobile web browsers generally allow JavaScript code in a web page to access motion and orientation sensor data without the user's permission. The associated risks to user privacy are however not considered in W3C specifications. In this work, for the first time, we show how user privacy can be compromised using device motion and orientation sensor data available in-browser, despite the fact that the data rate is 5 to 10 times slower than what is attainable in-app. We examine different browsers on the Android and iOS platforms and study their policies in granting permissions to JavaScript code with respect to access to motion and orientation sensor data and identify multiple vulnerabilities. Based on our findings, we propose TouchSignatures, implementation of an attack in which malicious JavaScript code on an inactive tab listens to such sensor data measurements. Based on these streams, TouchSignatures is able to distinguish the user's touch actions (e.g., tap, scroll, hold, and zoom) on an active tab, allowing the remote website to learn the client-side user activities. Finally, we demonstrate the practicality of this attack by collecting real-world user data and reporting high success rates using our proof-of-concept implementation. Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao 0001 |
AsiaCCS | 3 |
| 2015 | Reconciling user privacy and implicit authentication for mobile devices
Siamak F. Shahandashti, Reihaneh Safavi-Naini, Nashad Ahmed Safa |
Comput. Secur. | 1 |
| 2014 | Privacy-Preserving Implicit Authentication
Nashad Ahmed Safa, Reihaneh Safavi-Naini, Siamak F. Shahandashti |
SEC | 3 |
| 2012 | Adaptive CCA Broadcast Encryption with Constant-Size Secret Keys and Ciphertexts
Duong Hieu Phan, David Pointcheval, Siamak F. Shahandashti, Mario Strefler |
ACISP | 3 |
| 2012 | Private Fingerprint Matching
Siamak F. Shahandashti, Reihaneh Safavi-Naini, Philip Ogunbona |
ACISP | 1 |
| 2009 | Generic constructions for universal designated-verifier signatures and identitybased signatures from standard signaturesabstractThe authors give a generic construction for universal (mutli) designated-verifier signature schemes from a large class of signature schemes, referred to as Class ℂ. The resulting schemes are efficient and have two important properties. Firstly, they are provably DV-unforgeable, non-transferable and also non-delegatable. Secondly, the signer and the designated verifier can independently choose their cryptographic settings. The authors also propose a generic construction for (hierarchical) identity-based signature schemes from any signature scheme in ℂ and prove that the construction is secure against adaptive chosen message and identity attacks. The authors discuss possible extensions of our constructions to identity-based ring signatures and identity-based designated-verifier signatures from any signature in ℂ. Finally, the authors show that it is possible to combine the above constructions to obtain signatures with combined functionalities. Siamak F. Shahandashti, Reihaneh Safavi-Naini |
IET Inf. Secur. | 1 |
| 2007 | Concurrently-secure credential ownership proofsabstractWe address the case in credential systems where a credential owner wants to show her credential to a verifier without taking the risk that the ability to prove ownership of the same (and any other) credential is transferred to the verifier. We define credential ownership proof protocols for credentials signed by standard signature schemes. We also propose proper security definitions for the protocol, aiming to protect the security of both the credential issuer and the credential owner against concurrent attacks. We give two generic constructions of credential ownership proofs based on identity-based encryption and identity-based identification schemes. Furthermore, we show that signatures with credential ownership proofs are equivalent to identity-based identification schemes, in the sense that any secure construction of each implies a secure construction of the other. Finally, we show that the GQ identification protocol yields an efficient credential ownership proof for credentials signed by the RSA-FDH signature scheme of Bellare and Rogaway and prove the protocol concurrently-secure. Siamak F. Shahandashti, Reihaneh Safavi-Naini, Joonsang Baek |
AsiaCCS | 1 |