EDBT 2026 Demo / reviewers in the wild / expert
Tobias Lauinger
dblp:00/3175
· DBLP profile ↗
26ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0002-5779-0643ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 5 first-author · 6 since 2021Computer networks · 6 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Analyzing Social Media Claims regarding Youth Online Safety Features to Identify Problem Areas and Communication Gaps CSCW005abstractSocial media platforms have faced increasing scrutiny over whether and how they protect youth online. While online risks to children have been well-documented by prior research, how social media platforms communicate about these risks and their efforts to improve youth safety have not been holistically examined. To fill this gap, we analyzed N = 352 press releases and safety-related blogs published between 2019 and 2024 by four platforms popular among youth: YouTube, TikTok, Meta (Facebook and Instagram), and Snapchat. Leveraging both inductive and deductive qualitative approaches, we developed a comprehensive framework of seven problem areas where risks arise, and social media platforms claim to address these risks through various online safety features. Our analysis revealed uneven emphasis across problem areas, with most communications focused on Content Exposure and Interpersonal Communication, whereas less emphasis was placed on Content Creation, Data Access, and Platform Access. Additionally, we identified three problematic communication practices related to their described safety features, including discrepancies between feature implementation and availability, unclear or inconsistent explanations of safety feature operation, and a lack of evidence regarding the effectiveness of safety features in mitigating risks once implemented. Based on these findings, we discuss the communication gaps between risks and the described safety features, as well as the tensions in achieving transparency in platform communication. Our analysis of platform communication informs guidelines for responsibly communicating about youth safety features. Renkai Ma, Dominique Geißler, Stefan Feuerriegel, Tobias Lauinger, Damon McCoy, Pamela J. Wisniewski |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2025 | Partnërka in Crime: Characterizing Deceptive Affiliate Marketing Offers
Victor Le Pochat, Cameron Ballard, Lieven Desmet, Wouter Joosen, Damon McCoy, Tobias Lauinger |
PAM | 6 |
| 2025 | Characterizing the Usability and Usefulness of U.S. Ad Transparency SystemsabstractOnline targeted ads are those shown only to certain users based on interests, demographics, or behaviors. Because targeted ads raise many privacy concerns, many platforms provide ad transparency systems (ATSs) to inform users about this practice. To better understand what current ATSs are communicating to users—and how—we first taxonomized the design and content of 22 of the most popular English-language websites' ATSs as presented to users in the United States. We found substantial differences across ATSs in both the prevalence of transparency-enhancing features (e.g., whether they show users what has been inferred about them) and the presentation of information (e.g., the terminology used, where settings are located). Across all platforms, however, we observed consistent ambiguity about what data is used to target ads and the actual impact of altering settings. To gauge how these different design choices impact users, we conducted an online user study in which 198 participants used their own account to explore the ATS of one of eight representative platforms. We found that many of the questions participants hoped the ATS would answer remained unanswered after exploring the ATS. More broadly, participants found current ATSs simultaneously complex and lacking key details. We pinpoint ATS design decisions that best support users. Kevin Bryson 0002, Arthur Borem, Phoebe Moh, Omer Akgul, Laura Edelson, Tobias Lauinger, Michelle L. Mazurek, Damon McCoy, Blase Ur |
SP | 6 |
| 2025 | Tracker Installations Are Not Created Equal: Understanding Tracker Configuration of Form Data CollectionabstractTargeted advertising is fueled by the comprehensive tracking of users' online activity. As a result, advertising companies, such as Google and Meta, encourage website administrators to not only install tracking scripts on their websites but configure them to automatically collect users' Personally Identifying Information (PII). In this study, we aim to characterize how Google and Meta's trackers can be configured to collect PII data from web forms. We first perform a qualitative analysis of how third parties present form data collection to website administrators in the documentation and user interface. We then perform a measurement study of 40,150 websites to quantify the prevalence and configuration of Google and Meta trackers. Our results reveal that both Meta and Google encourage the use of form data collection and include inaccurate statements about hashing PII as a privacy-preserving method. Additionally, we find that Meta includes configuring form data collection as part of the basic setup flow. Our large-scale measurement study reveals that while Google trackers are more prevalent than Meta trackers (72.6% vs. 28.2% of websites), Meta trackers are configured to collect form data more frequently (11.6% vs. 62.3%). Finally, we identify sensitive finance and health websites that have installed trackers that are likely configured to collect form data PII in violation of Meta and Google policies. Our study highlights how tracker documentation and interfaces can potentially play a role in users' privacy through the configuration choices made by the website administrators who install trackers. Julia B. Kieserman, Athanasios Andreou, Chris Geeng, Tobias Lauinger, Damon McCoy |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | More and Scammier Ads: The Perils of YouTube's Ad Privacy SettingsabstractWhen users disable online ad personalization, they might be anticipating to see fewer ads that are "relevant" to them as a trade-off for more privacy. In this paper, we show that the tradeoff can go much further than this intuition. We conducted controlled experiments on YouTube in Australia, Canada, Ireland, the United Kingdom, and the United States to investigate the impact of disabling ad personalization on the quantity and quality of ads that users receive. Through experiments where emulated users with different ad privacy settings watched sequences of 400 videos, we show that disabling ad personalization can lead to the user being shown as much as 1.30 times more pre-roll ads than the default (least private) setting. More concerning is that in our experiments, the proportion of predatory ads increased 2.69 times compared to the default setting, from 2.5% to 8.7% of ads. This result highlights that certain user demographics (in this case, privacy-conscious users) can be exposed to significantly higher rates of predatory ads, and suggests that the platform's efforts to curb such ads are still falling short. Cat Mai, Bruno Coelho, Julia B. Kieserman, Lexie Matsumoto, Kyle Spinelli, Eric Yang, Athanasios Andreou, Rachel Greenstadt, Tobias Lauinger, Damon McCoy |
Proc. Priv. Enhancing Technol. | 9 |
| 2023 | Propaganda Política Pagada: Exploring U.S. Political Facebook Ads en EspañolabstractIn 2021, the U.S. Hispanic population totaled 62.5 million people, 68% of whom spoke Spanish in their homes. To date, it is unclear which political advertisers address this audience in their preferred language, and whether they do so differently than for English-speaking audiences. In this work, we study differences between political Facebook ads in English and Spanish during 2020, the latest U.S. presidential election. Political advertisers spent $ 1.48 B in English, but only $ 28.8 M in Spanish, disproportionately little compared to the share of Spanish speakers in the population. We further find a lower proportion of election-related advertisers (which additionally are more liberal-leaning than in the English set), and a higher proportion of government agencies in the set of Spanish ads. We perform multilingual topic classification, finding that the most common ad topics in English were also present in Spanish, but to a different extent, and with a different composition of advertisers. Thus, Spanish speakers are served different types of ads from different types of advertisers than English speakers, and in lower amounts; these results raise the question of whether political communication through Facebook ads may be inequitable and effectively disadvantaging the sizeable minority of Spanish speakers in the U.S. population. Bruno Coelho, Tobias Lauinger, Laura Edelson, Ian Goldstein, Damon McCoy |
WWW | 2 |
| 2022 | An Audit of Facebook's Political Ad Policy Enforcement
Victor Le Pochat, Laura Edelson, Tom van Goethem, Wouter Joosen, Damon McCoy, Tobias Lauinger |
USENIX Security Symposium | 6 |
| 2022 | Conspiracy Brokers: Understanding the Monetization of YouTube Conspiracy TheoriesabstractConspiracy theories are increasingly a subject of research interest as society grapples with their rapid growth in areas such as politics or public health. Previous work has established YouTube as one of the most popular sites for people to host and discuss different theories. In this paper, we present an analysis of monetization methods of conspiracy theorist YouTube creators and the types of advertisers potentially targeting this content. We collect 184,218 ad impressions from 6,347 unique advertisers found on conspiracy-focused channels and mainstream YouTube content. We classify the ads into business categories and compare their prevalence between conspiracy and mainstream content. We also identify common offsite monetization methods. In comparison with mainstream content, conspiracy videos had similar levels of ads from well-known brands, but an almost eleven times higher prevalence of likely predatory or deceptive ads. Additionally, we found that conspiracy channels were more than twice as likely as mainstream channels to use offsite monetization methods, and 53% of the demonetized channels we observed were linking to third-party sites for alternative monetization opportunities. Our results indicate that conspiracy theorists on YouTube had many potential avenues to generate revenue, and that predatory ads were more frequently served for conspiracy videos. Cameron Ballard, Ian Goldstein, Pulak Mehta, Genesis Smothers, Kejsi Take, Victoria Zhong, Rachel Greenstadt, Tobias Lauinger, Damon McCoy |
WWW | 8 |
| 2021 | A large-scale characterization of online incitements to harassment across platformsabstractAttack strategies used by online harassers have evolved over time to inflict increasing harm to their targets. In addition to scaling harassment through incitement and coordination, online communities that commonly engage in harassment are likely a source of "innovation" for harassment attack strategies. We use the incitements or calls to harassment posted by members of these communities as a lens through which to holistically measure and understand this ecosystem. We create a filtering pipeline to discover 14,679 incitements to harassment within four large-scale data sets of messages and posts that span multiple platforms. Max Aliapoulios, Kejsi Take, Prashanth Ramakrishna, Daniel Borkan, Beth Goldberg, Jeffrey S. Sorensen, Anna Turner, Rachel Greenstadt, Tobias Lauinger, Damon McCoy |
Internet Measurement Conference | 9 |
| 2021 | Understanding engagement with U.S. (mis)information news sources on FacebookabstractFacebook has become an important platform for news publishers to promote their work and engage with their readers. Some news pages on Facebook have a reputation for consistently low factualness in their reporting, and there is concern that Facebook allows their misinformation to reach large audiences. To date, there is remarkably little empirical data about how often users "like," comment and share content from news pages on Facebook, how user engagement compares between sources that have a reputation for misinformation and those that do not, and how the political leaning of the source impacts the equation. In this work, we propose a methodology to generate a list of news publishers' official Facebook pages annotated with their partisanship and (mis)information status based on third-party evaluations, and collect engagement data for the 7.5 M posts that 2,551 U.S. news publishers made on their pages during the 2020 U.S. presidential election. We propose three metrics to study engagement (1) across the Facebook news ecosystem, (2) between (mis)information providers and their audiences, and (3) with individual pieces of content from (mis)information providers. Our results show that misinformation news sources receive widespread engagement on Facebook, accounting for 68.1% of all engagement with far-right news providers, followed by 37.7 % on the far left. Individual posts from misinformation news providers receive consistently higher median engagement than non-misinformation in every partisanship group. While most prevalent on the far right, misinformation appears to be an issue across the political spectrum. Laura Edelson, Minh-Kha Nguyen, Ian Goldstein, Oana Goga, Damon McCoy, Tobias Lauinger |
Internet Measurement Conference | 6 |
| 2021 | Swiped: Analyzing Ground-truth Data of a Marketplace for Stolen Debit and Credit Cards
Max Aliapoulios, Cameron Ballard, Rasika Bhalerao, Tobias Lauinger, Damon McCoy |
USENIX Security Symposium | 4 |
| 2020 | Understanding Incentivized Mobile App Installs on Google Play Storeabstract"Incentivized" advertising platforms allow mobile app developers to acquire new users by directly paying users to install and engage with mobile apps (e.g., create an account, make in-app purchases). Incentivized installs are banned by the Apple App Store and discouraged by the Google Play Store because they can manipulate app store metrics (e.g., install counts, appearance in top charts). Yet, many organizations still offer incentivized install services for Android apps. In this paper, we present the first study to understand the ecosystem of incentivized mobile app install campaigns in Android and its broader ramifications through a series of measurements. We identify incentivized install campaigns that require users to install an app and perform in-app tasks targeting manipulation of a wide variety of user engagement metrics (e.g., daily active users, user session lengths) and revenue. Our results suggest that these artificially inflated metrics can be effective in improving app store metrics as well as helping mobile app developers to attract funding from venture capitalists. Our study also indicates lax enforcement of the Google Play Store's existing policies to prevent these behaviors. It further motivates the need for stricter policing of incentivized install campaigns. Our proposed measurements can also be leveraged by the Google Play Store to identify potential policy violations. Shehroze Farooqi, Álvaro Feal, Tobias Lauinger, Damon McCoy, Zubair Shafiq, Narseo Vallina-Rodriguez |
Internet Measurement Conference | 3 |
| 2020 | What's in an Exploit? An Empirical Analysis of Reflected Server XSS Exploitation Techniques
Ahmet Salih Buyukkayhan, Can Gemicioglu, Tobias Lauinger, Alina Oprea, William K. Robertson, Engin Kirda |
RAID | 3 |
| 2020 | A Security Analysis of the Facebook Ad LibraryabstractActors engaged in election disinformation are using online advertising platforms to spread political messages. In response to this threat, online advertising networks have started making political advertising on their platforms more transparent in order to enable third parties to detect malicious advertisers. We present a set of methodologies and perform a security analysis of Facebook's U.S. Ad Library, which is their political advertising transparency product. Unfortunately, we find that there are several weaknesses that enable a malicious advertiser to avoid accurate disclosure of their political ads. We also propose a clustering-based method to detect advertisers engaged in undeclared coordinated activity. Our clustering method identified 16 clusters of likely inauthentic communities that spent a total of over four million dollars on political advertising. This supports the idea that transparency could be a promising tool for combating disinformation. Finally, based on our findings, we make recommendations for improving the security of advertising transparency on Facebook and other platforms. Laura Edelson, Tobias Lauinger, Damon McCoy |
SP | 2 |
| 2019 | Getting Under Alexa's Umbrella: Infiltration Attacks Against Internet Top Domain Lists
Walter Rweyemamu, Tobias Lauinger, Christo Wilson, William K. Robertson, Engin Kirda |
ISC | 2 |
| 2019 | Clustering and the Weekend Effect: Recommendations for the Use of Top Domain Lists in Security Research
Walter Rweyemamu, Tobias Lauinger, Christo Wilson, William K. Robertson, Engin Kirda |
PAM | 2 |
| 2018 | From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop
Tobias Lauinger, Ahmet Salih Buyukkayhan, Abdelberi Chaabane, William K. Robertson, Engin Kirda |
Internet Measurement Conference | 1 |
| 2018 | Large-Scale Analysis of Style Injection by Relative Path OverwriteabstractRelative Path Overwrite (RPO) is a recent technique to inject style directives into sites even when no style sink or markup injection vulnerability is present. It exploits differences in how browsers and web servers interpret relative paths (i.e., path confusion) to make a HTML page reference itself as a stylesheet; a simple text injection vulnerability along with browsers» leniency in parsing CSS resources results in an attacker»s ability to inject style directives that will be interpreted by the browser. Even though style injection may appear less serious a threat than script injection, it has been shown that it enables a range of attacks, including secret exfiltration. In this paper, we present the first large-scale study of the Web to measure the prevalence and significance of style injection using RPO. Our work shows that around 9% of the sites in the Alexa Top 10,000 contain at least one vulnerable page, out of which more than one third can be exploited. We analyze in detail various impediments to successful exploitation, and make recommendations for remediation. In contrast to script injection, relatively simple countermeasures exist to mitigate style injection. However, there appears to be little awareness of this attack vector as evidenced by a range of popular Content Management Systems (CMSes) that we found to be exploitable. Sajjad Arshad, Seyed Ali Mirheidari, Tobias Lauinger, Bruno Crispo, Engin Kirda, William K. Robertson |
WWW | 3 |
| 2017 | Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the Web
Tobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William K. Robertson, Christo Wilson, Engin Kirda |
NDSS | 1 |
| 2017 | Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers
Tobias Lauinger, Abdelberi Chaabane, Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William K. Robertson |
USENIX Security Symposium | 1 |
| 2016 | WHOIS Lost in Translation: (Mis)Understanding Domain Name Expiration and Re-Registration
Tobias Lauinger, Kaan Onarlioglu, Abdelberi Chaabane, William K. Robertson, Engin Kirda |
Internet Measurement Conference | 1 |
| 2014 | Why Is CSP Failing? Trends and Challenges in CSP Adoption
Michael Weissbacher, Tobias Lauinger, William K. Robertson |
RAID | 2 |
| 2013 | Clickonomics: Determining the Effect of Anti-Piracy Measures for One-Click Hosting
Tobias Lauinger, Martin Szydlowski, Kaan Onarlioglu, Gilbert Wondracek, Engin Kirda, Christopher Krügel |
NDSS | 1 |
| 2013 | Holiday Pictures or Blockbuster Movies? Insights into Copyright Infringement in User Uploads to One-Click File Hosters
Tobias Lauinger, Kaan Onarlioglu, Abdelberi Chaabane, Engin Kirda, William K. Robertson, Mohamed Ali Kâafar |
RAID | 1 |
| 2012 | Paying for Piracy? An Analysis of One-Click Hosters' Controversial Reward Schemes
Tobias Lauinger, Engin Kirda, Pietro Michiardi |
RAID | 1 |
| 2008 | Embracing the Peer Next Door: Proximity in KademliaabstractAt present, the probability of selecting "the peer next door"' as an overlay neighbour in Kademlia is fairly small. Prior research has been concerned with reducing the lookup latency by means of proximity neighbour and route selection, but focused on recursive routing algorithms. This work leverages location data about peers and extends Kademlia's iterative routing algorithm to reduce cross-network traffic at the level of the distributed hash table. Evaluation with real-world measurement data gives evidence that locality of traffic tends to reduce lookup latencies as well. In turn, mechanisms that aim at reducing lookup latencies do not necessarily reduce cross-network traffic to the same extent. Sebastian Kaune, Tobias Lauinger, Aleksandra Kovacevic 0001, Konstantin Pussep |
Peer-to-Peer Computing | 2 |