Güliz Seray Tuncay

dblp:118/3426 · DBLP profile ↗
← Back
19ranked-venue papers
7as first author
12since 2021 · last 2026
0009-0003-5472-141XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 3 first-author · 9 since 2021Computer networks · 4 · 4 first-authorDatabases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A First Look at the Mobile Driving License (mDL) Standard and its Real-world Usage
Zeyu Lei, Güliz Seray Tuncay, Abdullah Imran, Z. Berkay Celik, Antonio Bianchi
AsiaCCS2
2026 Uncovering Relationships Between Android Developers, User Privacy, and Developer Willingness to Reduce Fingerprinting Risks
abstract
The major mobile platforms, Android and iOS, have introduced changes that restrict user tracking to improve user privacy, yet apps continue to covertly track users via device fingerprinting. We study the opportunity to improve this dynamic with a case study on mobile fingerprinting that evaluates developers’ perceptions of how well platforms protect user privacy and how developers perceive platform privacy interventions. Specifically, we study developers’ willingness to make changes to protect users from fingerprinting and how developers consider trade-offs between user privacy and developer effort. We do this via a survey of 246 Android developers, presented with a hypothetical Android change that protects users from fingerprinting at the cost of additional developer effort.
Alex Berke, Güliz Seray Tuncay, Michael A. Specter, Mihai Christodorescu
CHI2
2026 Investigating Developers' Usage and Perception of Trusted Execution Environment Features in Android
Abdullah Imran, Güliz Seray Tuncay, René Mayrhofer, Antonio Bianchi
EuroS&P2
2026 The Clone Strikes Back: Efficient Vulnerable Code Detection in Custom Android-based Systems
Esteban Luques, Carlo Mazzocca, Güliz Seray Tuncay, A. Selcuk Uluagac
EuroS&P3
2026 Unveiling the Global Landscape of Android Security Updates
abstract
Android is the world's leading mobile operating system, with over three billion active devices. Detecting vulnerabilities and ensuring timely patch deployment are critical to maintaining security. The Android Open Source Project (AOSP) has enhanced the transparency of security updates through Security Patch Levels. However, challenges related to update speed and availability persist. In 2022, Google reported that half of the zero-day vulnerabilities discovered in the wild were variations of vulnerabilities that had already been patched. Recent research mainly highlights delays in update distribution, often attributing them to fragmentation and focusing primarily on flagship devices or limited time-frames. Our approach takes a device-centric perspective to investigate Android update patterns, analyzing 567K security update records from 2014 to 2024, covering 904 distinct devices from six key Original Equipment Manufacturers (OEMs) across 98 countries. Our extensive analysis revealed notable differences in update release timing across OEMs, device types, and regions. Our study also examines documented vulnerabilities and weaknesses, while assessing OEM compliance with Android security guidelines. Our study shows that$\sim$89.7% of vulnerabilities on unpatched Android devices are exploitable without user interaction and with low attack complexity. We also identified delays linked to fragmentation and OEM-specific challenges, and provide actionable insights for improvement.
Haiyun Deng, Güliz Seray Tuncay, Abbas Acar, Esteban Luques, Harun Oz, Ahmet Aris, A. Selcuk Uluagac
IEEE Trans. Dependable Secur. Comput.2
2025 ScopeVerif: Analyzing the Security of Android's Scoped Storage via Differential Analysis
Zeyu Lei, Güliz Seray Tuncay, Beatrice Carissa Williem, Z. Berkay Celik, Antonio Bianchi
NDSS2
2025 Ransomware Over Modern Web Browsers: A Novel Strain and a New Defense Mechanism
abstract
Ransomware is an increasingly prevalent form of malware targeting end-users, governments, and businesses. As it has evolved, adversaries added new capabilities to their arsenal. We propose a next-generation browser-based ransomware, RøB , which performs its malicious actions via web technologies, File System Access API (FSA) and WebAssembly (Wasm). RøB uses this API through the victims’ browsers; hence, it does not require the victims to download and install malicious binaries. We performed extensive evaluations with three different OSs, 23 file formats, 29 distinct directories, five cloud providers, and four antivirus solutions. Our evaluations show that RøB can encrypt various types of files in the local and cloud-integrated directories, external storage devices, and network-shared folders of victims. Our experiments also reveal that popular cloud solutions, Box Individual and Apple iCloud can be severely affected by RøB . Moreover, we conducted tests with commercial antivirus software such as AVG, Avast, Kaspersky, and Malware Bytes that perform sensitive directory and suspicious behavior monitoring against ransomware. We verified that RøB can evade these antivirus software and encrypt victim files. Moreover, existing ransomware detection solutions in the literature also cannot be a remedy against RøB due to its distinct features. Therefore, in this paper, we also propose RøBguard , a new detection system for RøB -like attacks. RøBguard monitors the web applications that use the FSA API via function hooking and uses a machine learning classifier to detect RøB -like attacks. We implemented a proof of concept version of RøBguard and our evaluation results show that RøBguard can detect RøB -like browser-based ransomware attacks effectively. We also provide future research directions that should be addressed in this domain.
Harun Oz, Güliz Seray Tuncay, Ahmet Aris, Abbas Acar, Leonardo Babun, A. Selcuk Uluagac
ACM Trans. Web2
2024 50 Shades of Support: A Device-Centric Analysis of Android Security Updates
Abbas Acar, Güliz Seray Tuncay, Esteban Luques, Harun Oz, Ahmet Aris, A. Selcuk Uluagac
NDSS2
2024 Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables
abstract
Wearable devices are becoming increasingly important, helping us stay healthy and connected. There are a variety of app-based wearable platforms that can be used to manage these devices. The apps on wearable devices often work with a companion app on users’ smartphones. The wearable device and the smartphone typically use two separate permission models that work synchronously to protect sensitive data. However, this design creates an opaque view of the management of permission-protected data, resulting in over-privileged data access without the user’s explicit consent. In this paper, we performed the first systematic analysis of the interaction between the Android and Wear OS permission models. Our analysis is two-fold. First, through taint analysis, we showed that cross-device flows of permission-protected data happen in the wild, demonstrating that 28 apps (out of the 150 we studied) on Google Play have sensitive data flows between the wearable app and its companion app. We found that these data flows occur without the users’ explicit consent, introducing the risk of violating user expectations. Second, we conducted an in-lab user study to assess users’ understanding of permissions when subject to cross-device communication (n = 63). We found that 66.7% of the users are unaware of the possibility of cross-device sensitive data flows, which impairs their understanding of permissions in the context of wearable devices and puts their sensitive data at risk. We also showed that users are vulnerable to a new class of attacks that we call cross-device permission phishing attacks on wearable devices. Lastly, we performed a preliminary study on other watch platforms (i.e., Apple’s watchOS, Fitbit, Garmin OS) and found that all these platforms suffer from similar privacy issues. As countermeasures for the potential privacy violations in cross-device apps, we suggest improvements in the system prompts and the permission model to enable users to make better-informed decisions, as well as on app markets to identify malicious cross-device data flows.
Doguhan Yeke, Muhammad Ibrahim 0004, Güliz Seray Tuncay, Habiba Farrukh, Abdullah Imran, Antonio Bianchi, Z. Berkay Celik
SP3
2024 (In)Security of File Uploads in Node.js
abstract
File upload is a critical feature incorporated by a myriad of web applications in an effort to enable users to share and manage their files conveniently. It has been used in many useful services such as file-sharing and social media. While file upload is an essential component of web applications, the lack of rigorous checks on the file name, type, and content of the uploaded files can result in security issues, often referred to as Unrestricted File Upload (UFU). In this study, we analyze the (in)security of popular file upload libraries and real-world applications in the Node.js ecosystem. To automate our analysis, we propose and implement NodeSEC- a tool designed to analyze file upload insecurities in Node.js applications and libraries. NodeSEC generates unique payloads and thoroughly evaluates the application's file upload security against 13 distinct UFU-type attacks. Utilizing NodeSEC, we analyze the most popular file upload libraries and real-world applications in the Node.js ecosystem. Our analysis results reveal that some real-world web applications are vulnerable to UFU attacks and disclose serious security bugs in file upload libraries. As of this writing, we received 19 CVEs and two US-CERT cases for the security issues that we reported. Our findings provide strong evidence that dynamic features of Node.js applications introduce security shortcomings and that web developers should be cautious when implementing file upload features in their applications. Finally, combining our responsible disclosure experience and root cause analysis, we identified the main causes of significant security weaknesses in file uploads in Node.js.
Harun Oz, Abbas Acar, Ahmet Aris, Güliz Seray Tuncay, Amin Kharraz, A. Selcuk Uluagac
WWW4
2023 Evaluating User Behavior in Smartphone Security: A Psychometric Perspective
Hsiao-Ying Huang, Soteris Demetriou, Muhammad Hassan 0005, Güliz Seray Tuncay, Carl A. Gunter, Masooda N. Bashir
SOUPS4
2023 RøB: Ransomware over Modern Web Browsers
Harun Oz, Ahmet Aris, Abbas Acar, Güliz Seray Tuncay, Leonardo Babun, A. Selcuk Uluagac
USENIX Security Symposium4
2020 See No Evil: Phishing for Permissions with False Transparency
Güliz Seray Tuncay, Jingyu Qian, Carl A. Gunter
USENIX Security Symposium1
2018 Resolving the Predicament of Android Custom Permissions
Güliz Seray Tuncay, Soteris Demetriou, Karan Ganju, Carl A. Gunter
NDSS1
2016 Draco: A System for Uniform and Fine-grained Access Control for Web Code on Android
abstract
In-app embedded browsers are commonly used by app developers to display web content without having to redirect the user to heavy-weight web browsers. Just like the conventional web browsers, embedded browsers can allow the execution of web code. In addition, they provide mechanisms (viz., JavaScript bridges) to give web code access to internal app code that might implement critical functionalities and expose device resources. This is intrinsically dangerous since there is currently no means for app developers to perform origin-based access control on the JavaScript bridges, and any web code running in an embedded browser is free to use all the exposed app and device resources. Previous work that addresses this problem provided access control solutions that work only for apps that are built using hybrid frameworks. Additionally, these solutions focused on protecting only the parts of JavaScript bridges that expose permissions-protected resources. In this work, our goal is to provide a generic solution that works for all apps that utilize embedded web browsers and protects all channels that give access to internal app and device resources. Towards realizing this goal, we built Draco, a uniform and fine-grained access control framework for web code running on Android embedded browsers (viz., WebView). Draco provides a declarative policy language that allows developers to define policies to specify the desired access characteristics of web origins in a fine-grained fashion, and a runtime system that dynamically enforces the policies. In contrast with previous work, we do not assume any modifications to the Android operating system, and implement Draco in the Chromium Android System WebView app to enable seamless deployment. Our evaluation of the the Draco runtime system shows that Draco incurs negligible overhead, which is in the order of microseconds.
Güliz Seray Tuncay, Soteris Demetriou, Carl A. Gunter
CCS1
2014 Poster: SaveAlert: an efficient and scalable sensor-driven danger detection system
abstract
SaveAlert is an adaptive framework for crowd-monitoring and danger-detection using off-the-shelf smartphones and other peripherals such as smartwatches. It is a system that provides users with an increased awareness of their surroundings by detecting and notifying them of impending danger, by relying only on sensor data collected from the users. Our framework's novelty is in how it performs efficient sensor data collection from potentially a large number of people by limiting the disturbance and stress on the existing Wi-Fi and cellular infrastructure. To the best of our knowledge, this is the first crowd-monitoring framework that takes advantage of peer-to-peer connections to perform local aggregation to alleviate the stress on existing infrastructures for better scalability and efficiency.
Güliz Seray Tuncay, Kirill Varshavskiy, Robin Kravets, Klara Nahrstedt
MobiCom1
2014 Demo: SaveAlert: design for a sensor-driven CrowdWatch danger detection system
abstract
SaveAlert is an adaptive framework for danger-detection using existing devices such as off-the-shelf smartphones and smartwatches. The framework can be extended to different sensors that could trigger distress signals to notify nearby users of potentially dangerous situations.
Güliz Seray Tuncay, Kirill Varshavskiy, Robin Kravets
MobiSys1
2013 Participant recruitment and data collection framework for opportunistic sensing: a comparative analysis
abstract
Opportunistic sensing is a novel approach that exploits the sensing capabilities offered by smartphones and users' mobility to sense large scale areas without requiring the deployment of sensors in-situ. In this work, we propose a novel framework for fully distributed, opportunistic sensing which coherently integrates two main components that operate in DTN mode: i. participant recruitment and ii. data collection. We evaluate our approach by considering alternative implementations of the framework, and by measuring their performance via extensive trace-based simulations. Our results show how the performances of the considered protocols vary, depending on the particular scenario, and suggest guidelines for future development of distributed opportunistic sensing systems.
Güliz Seray Tuncay, Giacomo Benincasa, Ahmed Helmy
MobiCom1
2012 Autonomous and distributed recruitment and data collection framework for opportunistic sensing
abstract
People-centric sensing is a novel apporach that exploits the sensing capabilities offered by smartphones and the mobility of users to sense large scale areas without requiring the deployment of sensors in-situ. Given the ubiquitous nature of smartphones, people-centric sensing is a viable and efficient solution for crowdsourcing data. In this work, we propose a fully distributed, opportunistic sensing framework that involves two main components which both work in an ad hoc fashion: Recruitment and Data Collection. We analyzed the feasibility of our distributed approach for both components through preliminary simulations. The results show that our recruitment method is able to select 66% of the nodes that are appropriate for the sensing activity and 88% of the messages sent by these selected nodes reach the sink by using our data collection method.
Güliz Seray Tuncay, Giacomo Benincasa, Ahmed Helmy
MobiCom1