Anwar Hithnawi

dblp:122/5664 · DBLP profile ↗
← Back
23ranked-venue papers
5as first author
9since 2021 · last 2025
0009-0000-5603-1031ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 4 first-authorSecurity and privacy · 8 · 7 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 DPolicy: Managing Privacy Risks Across Multiple Releases with Differential Privacy
abstract
Differential Privacy (DP) has emerged as a robust framework for privacy-preserving data releases and has been successfully applied in high-profile cases, such as the 2020 US Census. However, in organizational settings, the use of DP remains largely confined to isolated data releases. This approach restricts the potential of DP to serve as a framework for comprehensive privacy risk management at an organizational level. Although one might expect that the cumulative privacy risk of isolated releases could be assessed using DP's compositional property, in practice, individual DP guarantees are frequently tailored to specific releases, making it difficult to reason about their interaction or combined impact. At the same time, less tailored DP guarantees, which compose more easily, also offer only limited insight because they lead to excessively large privacy budgets that convey limited meaning. To address these limitations, we present DPolicy, a system designed to manage cumulative privacy risks across multiple data releases using DP. Unlike traditional approaches that treat each release in isolation or rely on a single (global) DP guarantee, our system employs a flexible framework that considers multiple DP guarantees simultaneously, reflecting the diverse contexts and scopes typical of real-world DP deployments. DPolicy introduces a high-level policy language to formalize privacy guarantees, making traditionally implicit assumptions on scopes and contexts explicit. By deriving the DP guarantees required to enforce complex privacy semantics from these high-level policies, DPolicy enables fine-grained privacy risk management on an organizational scale. We implement and evaluate DPolicy, demonstrating how it mitigates privacy risks that can emerge without comprehensive, organization-wide privacy risk management.
Nicolas Küchler, Alexander Viand, Hidde Lycklama, Anwar Hithnawi
SP4
2025 CoVault: Secure, Scalable Analytics of Personal Data
Roberta De Viti, Isaac Sheff, Noemi Glaeser, Baltasar Dinis, Rodrigo Rodrigues 0001, Bobby Bhattacharjee, Anwar Hithnawi, Deepak Garg 0001, Peter Druschel
USENIX Security Symposium7
2024 Cohere: Managing Differential Privacy in Large Scale Systems
abstract
The need for a privacy management layer in today’s systems started to manifest with the emergence of new systems for privacy-preserving analytics and privacy compliance. As a result, many independent efforts have emerged that try to provide system support for privacy. Recently, the scope of privacy solutions used in systems has expanded to encompass more complex techniques such as Differential Privacy (DP). The use of these solutions in large-scale systems imposes new challenges and requirements. Careful planning and coordination are necessary to ensure that privacy guarantees are maintained across a wide range of heterogeneous applications and data systems. This requires new solutions for managing and allocating scarce and non-replenishable privacy resources. In this paper, we introduce Cohere, a new system that simplifies the use of DP in large-scale systems. Cohere implements a unified interface that allows heterogeneous applications to operate on a unified view of users’ data. In this work, we further address two pressing system challenges that arise in the context of real-world deployments: ensuring the continuity of privacy-based applications (i.e., preventing privacy budget depletion) and effectively allocating scarce shared privacy resources (i.e., budget) under complex preferences. Our experiments show that Cohere achieves a 6.4–28x improvement in utility compared to the state-of-the-art across a range of complex workloads.
Nicolas Küchler, Emanuel Opel, Hidde Lycklama, Alexander Viand, Anwar Hithnawi
SP5
2024 Holding Secrets Accountable: Auditing Privacy-Preserving Machine Learning
Hidde Lycklama, Alexander Viand, Nicolas Küchler, Christian Knabenhans, Anwar Hithnawi
USENIX Security Symposium5
2023 RoFL: Robustness of Secure Federated Learning
abstract
Even though recent years have seen many attacks exposing severe vulnerabilities in Federated Learning (FL), a holistic understanding of what enables these attacks and how they can be mitigated effectively is still lacking. In this work, we demystify the inner workings of existing (targeted) attacks. We provide new insights into why these attacks are possible and why a definitive solution to FL robustness is challenging. We show that the need for ML algorithms to memorize tail data has significant implications for FL integrity. This phenomenon has largely been studied in the context of privacy; our analysis sheds light on its implications for ML integrity. We show that certain classes of severe attacks can be mitigated effectively by enforcing constraints such as norm bounds on clients’ updates. We investigate how to efficiently incorporate these constraints into secure FL protocols in the single-server setting. Based on this, we propose RoFL, a new secure FL system that extends secure aggregation with privacy-preserving input validation. Specifically, RoFL can enforce constraints such as L2and L∞bounds on high-dimensional encrypted model updates.
Hidde Lycklama, Lukas Burkhalter, Alexander Viand, Nicolas Küchler, Anwar Hithnawi
SP5
2023 HECO: Fully Homomorphic Encryption Compiler
Alexander Viand, Patrick Jattke, Miro Haller, Anwar Hithnawi
USENIX Security Symposium4
2022 VF-PS: How to Select Important Participants in Vertical Federated Learning, Efficiently and Securely?
abstract
Vertical Federated Learning (VFL), that trains federated models over vertically partitioned data, has emerged as an important learning paradigm. However, existing VFL methods are facing two challenges: (1) scalability when # participants grows to even modest scale and (2) diminishing return w.r.t. # participants: not all participants are equally important and many will not introduce quality improvement in a large consortium. Inspired by these two challenges, in this paper, we ask: How can we select l out of m participants, where l ≪ m, that are most important?We call this problem Vertically Federated Participant Selection, and model it with a principled mutual information-based view. Our first technical contribution is VF-MINE—a Vertically Federated Mutual INformation Estimator—that uses one of the most celebrated algorithms in database theory—Fagin’s algorithm as a building block. Our second contribution is to further optimize VF-MINE to enable VF-PS, a group testing-based participant selection framework. We empirically show that vertically federated participation selection can be orders of magnitude faster than training a full-fledged VFL model, while being able to identify the most important subset of participants that often lead to a VFL model of similar quality.
Jiawei Jiang 0001, Lukas Burkhalter, Fangcheng Fu, Bolin Ding, Bo Du 0001, Anwar Hithnawi, Bo Li 0026, Ce Zhang 0001
NeurIPS6
2021 Zeph: Cryptographic Enforcement of End-to-End Data Privacy
Lukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh, Anwar Hithnawi
OSDI5
2021 SoK: Fully Homomorphic Encryption Compilers
abstract
Fully Homomorphic Encryption (FHE) allows a third party to perform arbitrary computations on encrypted data, learning neither the inputs nor the computation results. Hence, it provides resilience in situations where computations are carried out by an untrusted or potentially compromised party. This powerful concept was first conceived by Rivest et al. in the 1970s. However, it remained unrealized until Craig Gentry presented the first feasible FHE scheme in 2009.The advent of the massive collection of sensitive data in cloud services, coupled with a plague of data breaches, moved highly regulated businesses to increasingly demand confidential and secure computing solutions. This demand, in turn, has led to a recent surge in the development of FHE tools. To understand the landscape of recent FHE tool developments, we conduct an extensive survey and experimental evaluation to explore the current state of the art and identify areas for future development.In this paper, we survey, evaluate, and systematize FHE tools and compilers. We perform experiments to evaluate these tools’ performance and usability aspects on a variety of applications. We conclude with recommendations for developers intending to develop FHE-based applications and a discussion on future directions for FHE tools development.
Alexander Viand, Patrick Jattke, Anwar Hithnawi
SP3
2020 TimeCrypt: Encrypted Data Stream Processing at Scale with Cryptographic Access Control
Lukas Burkhalter, Anwar Hithnawi, Alexander Viand, Hossein Shafagh, Sylvia Ratnasamy
NSDI2
2020 Droplet: Decentralized Authorization and Access Control for Encrypted Data Streams
Hossein Shafagh, Lukas Burkhalter, Sylvia Ratnasamy, Anwar Hithnawi
USENIX Security Symposium4
2017 Secure Sharing of Partially Homomorphic Encrypted IoT Data
abstract
IoT applications often utilize the cloud to store and provide ubiquitous access to collected data. This naturally facilitates data sharing with third-party services and other users, but bears privacy risks, due to data breaches or unauthorized trades with user data. To address these concerns, we present Pilatus, a data protection platform where the cloud stores only encrypted data, yet is still able to process certain queries (e.g., range, sum). More importantly, Pilatus features a novel encrypted data sharing scheme based on re-encryption, with revocation capabilities and in situ key-update. Our solution includes a suite of novel techniques that enable efficient partially homomorphic encryption, decryption, and sharing. We present performance optimizations that render these cryptographic tools practical for mobile platforms. We implement a prototype of Pilatus and evaluate it thoroughly. Our optimizations achieve a performance gain within one order of magnitude compared to state-of-the-art realizations; mobile devices can decrypt hundreds of data points in a few hundred milliseconds. Moreover, we discuss practical considerations through two example mobile applications (Fitbit and Ava) that run Pilatus on real-world data.
Hossein Shafagh, Anwar Hithnawi, Lukas Burkhalter, Pascal Fischli, Simon Duquennoy
SenSys2
2016 CrossZig: Combating Cross-Technology Interference in Low-Power Wireless Networks
abstract
Low-power wireless devices suffer notoriously from Cross- Technology Interference (CTI). To enable co-existence, researchers have proposed a variety of interference mitigation strategies. Existing solutions, however, are designed to work with the limitations of currently available radio chips. In this paper, we investigate how to exploit physical layer properties of 802.15.4 signals to better address CTI. We present CrossZig, a cross-layer solution that takes advantage of physical layer information and processing to improve low-power communication under CTI. To this end, CrossZig utilizes physical layer information to detect presence of CTI in a corrupted packet and to apply an adaptive packet recovery which incorporates a novel cross-layer based packet merging and an adaptive FEC coding. We implement a prototype of CrossZig for the low-power IEEE 802.15.4 in a software-defined radio platform. We show the adaptability and the performance gain of CrossZig through experimental evaluation considering both micro-benchmarking and system performance under various interference patterns. Our results demonstrate that CrossZig can achieve a high accuracy in error localization (94.3% accuracy) and interference type identification (less than 5% error rate for SINR ranges below 3 dB). Moreover, our system shows consistent performance improvements under interference from various interfering technologies.
Anwar Hithnawi, Hossein Shafagh, James Gross, Simon Duquennoy
IPSN1
2016 Talos a Platform for Processing Encrypted IoT Data: Demo Abstract
abstract
Internet of Things (IoT) applications today often utilize the cloud to provide storage and ubiquitous access to collected data. Leaving such granular, sensitive, and personal data unprotected on the cloud and vulnerable to system breaches or curious administrators is critical. In this extended abstract, we present Talos [3], a framework that embraces the computational resources available in the cloud and exploits them for encrypted data processing (e.g., using partially homomorphic encryption schemes). We have developed Talos further to enable encrypted data sharing, such that users can securely share their homomorphically encrypted data with add-on services and other users. We demonstrate a prototype implementation of a real-world application utilizing Talos. Talos enables applications to efficiently store and interact with encrypted sensory data in the cloud. With our prototype application, we show that with Talos in place the user experience remains unchanged (i.e., response time below 1 s) although all operations over data in the cloud incorporate encrypted data processing. Moreover, we demonstrate how Talos can be smoothly integrated into IoT apps (currently supporting Contiki and Android). Hence, we hope to encourage the development of secure IoT applications on top of the Talos framework.
Hossein Shafagh, Lukas Burkhalter, Anwar Hithnawi
SenSys3
2015 TIIM: technology-independent interference mitigation for low-power wireless networks
abstract
The rise of heterogeneity in wireless technologies operating in the unlicensed bands has been shown to adversely affect the performance of low-power wireless networks. Cross-Technology Interference (CTI) is highly uncertain and raises the need for agile methods that assess the channel conditions and apply actions maximizing communication success. In this paper, we present TIIM, a lightweight Technology-Independent Interference Mitigation solution that detects, quantifies, and reacts to CTI in realtime. TIIM employs a lightweight machine learning classifier to (i) decide whether communication is viable over the interfered link, (ii) characterize the ambient conditions and apply the best coexistence mitigation strategy. We present an in-depth experimental characterization of the effect of CTI on 802.15.4 links, which motivated and influenced the design of TIIM. Our evaluation shows that TIIM, while exposed to extensive and heterogeneous interference, can achieve a total PRR improvement of 30% with an additional transmission overhead of 5.6%.
Anwar Hithnawi, Hossein Shafagh, Simon Duquennoy
IPSN1
2015 Poster: Towards Encrypted Query Processing for the Internet of Things
abstract
The Internet of Things (IoT) is envisioned to digitize the physical world, resulting in a digital representation of our proximate living space. The possibility of inferring privacy violating information from IoT data necessitates adequate security measures regarding data storage and communication. To address these privacy and security concerns, we introduce our system that stores IoT data securely in the Cloud database while still allowing query processing over the encrypted data. We enable this by encrypting IoT data with a set of cryptographic schemes such as order-preserving and partially homomorphic encryptions. To achieve this on resource-limited devices, our system relies on optimized algorithms that accelerate partial homomorphic and order-preserving encryptions by 1 to 2 orders of magnitude. Our early results show the feasibility of our system on low-power devices. We envision our system as an enabler of secure IoT applications.
Hossein Shafagh, Anwar Hithnawi, Andreas Droescher, Simon Duquennoy, Wen Hu 0001
MobiCom2
2015 Poster: Cross-Layer Optimization for Low-power Wireless Coexistence
abstract
We present a system that leverages physical layer features to combat Cross-Technology Interference (CTI) in low-power wireless networks. Our system incorporates: (i) a lightweight interference detection mechanism for low-power radios that recognizes the type of interference in the received signal, (ii) a lightweight error detection mechanism to estimate and characterize error patterns within interfered packets, and (iii) a CTI-aware protocol that dynamically adapts transmission and recovery mode to the current interference patterns. We implement a prototype of our system for the low-power IEEE 802.15.4 in software-defined radios (SDR). Our early results of the system components demonstrate that we can achieve a high accuracy in error detection and interference type identification. Moreover, we observed a significant performance improvement compared to the standard 802.15.4 systems without interference-awareness.
Anwar Hithnawi, Hossein Shafagh, Simon Duquennoy, James Gross
SenSys1
2015 Talos: Encrypted Query Processing for the Internet of Things
abstract
The Internet of Things, by digitizing the physical world, is envisioned to enable novel interaction paradigms with our surroundings. This creates new threats and leads to unprecedented security and privacy concerns. To tackle these concerns, we introduce Talos, a system that stores IoT data securely in a Cloud database while still allowing query processing over the encrypted data. We enable this by encrypting IoT data with a set of cryptographic schemes such as order-preserving and partially homomorphic encryption. In order to achieve this in constrained IoT devices, Talos relies on optimized algorithms that accelerate order-preserving and partially homomorphic encryption by 1 to 2 orders of magnitude. We assess the feasibility of Talos on low-power devices with and without cryptographic accelerators and quantify its overhead in terms of energy, computation, and latency. With a thorough evaluation of our prototype implementation, we show that Talos is a practical system that can provide a high level of security with a reasonable overhead. We envision Talos as an enabler of secure IoT applications.
Hossein Shafagh, Anwar Hithnawi, Andreas Droescher, Simon Duquennoy, Wen Hu 0001
SenSys2
2014 Poster Abstract: Low-Power Wireless Channel Quality Estimation in the Presence of RF Smog
abstract
Low-power wireless networks deployed in indoor environments inevitably encounter high-power Cross Technology Interference (CTI) from a wide range of wireless devices operating in the shared RF spectrum bands. This severely reduces the performance of such networks and possibly causes loss of connectivity, which affects their availability and drains their resources. In this work, to address the channel uncertainty, a consequence of CTI, we propose a novel channel metric that (i) harnesses the local knowledge of a node about the wireless channel to discern the presence of persistent high-power interferers, and (ii) assists the node in inferring its proximity to the dominant interference sources in the physical space. In order to motivate and validate the necessity of such a metric, we empirically characterize the impact of the interaction between high/low-power cross technology interferers and IEEE 802.15.4.
Anwar Hithnawi, Hossein Shafagh, Simon Duquennoy
DCOSS1
2014 Poster Abstract: Security Comes First, a Public-key Cryptography Framework for the Internet of Things
abstract
Novel Internet services are emerging around an increasing number of sensors and actuators in our surroundings, commonly referred to as smart devices. Smart devices, which form the backbone of the Internet of Things (IoT), enable alternative forms of user experience by means of automation, convenience, and efficiency. At the same time new security and safety issues arise, given the Internet-connectivity and the interaction possibility of smart devices with human's proximate living space. Hence, security is a fundamental requirement of the IoT design. In order to remain interoperable with the existing infrastructure, we postulate a security framework compatible to standard IP-based security solutions, yet optimized to meet the constraints of the IoT ecosystem. In this ongoing work, we first identify necessary components of an interoperable secure End-to-End communication while incorporating Public-key Cryptography (PKC). To this end, we tackle involved computational and communication overheads. The required components on the hardware side are the affordable hardware acceleration engines for cryptographic operations and on the software side header compression and long-lasting secure sessions. In future work, we focus on integration of these components into a framework and the evaluation of an early prototype of this framework.
Hossein Shafagh, Anwar Hithnawi
DCOSS2
2014 Poster: come closer: proximity-based authentication for the internet of things
abstract
This paper presents a proximity-based authentication approach for the Internet of Things (IoT) that works in-band by solely utilizing the wireless communication interface. The novelty of this approach lies in its reliance on ambient radio signals to infer proximity within about one second, and in its ability to expose imposters located several meters away. We identify relevant features sensed from the RF channel to establish a notion of proximity across co-located low-power devices. We introduce our proximity-based authentication protocol and show the feasibility of our approach with an early prototype using off-the-shelf 802.15.4 sensors and an evaluation conducted in a real-world environment.
Hossein Shafagh, Anwar Hithnawi
MobiCom2
2013 Exploiting physical layer information to mitigate cross-technology interference effects on low-power wireless networks
abstract
The proliferation of a wide range of wireless devices operating in the crowded 2.4 GHz ISM band is becoming a major challenge for emerging low-power wireless networks in indoor applications. Recent studies show that Cross Technology Interference (CTI) can significantly reduce the overall delivery ratio of such networks. CTI subsequently decreases the network performance and drains their scarce resources of radio spectrum and energy. In this work, we present the design and preliminary evaluation results of an energy-efficient packet recovery mechanism that exploits (i) physical layer information available by 802.15.4-compliant radios and (ii) time diversity of wireless channel, to mitigate cross technology interference effects on low-power wireless networks.
Anwar Hithnawi
SenSys1
2012 A receiver-based 802.11 rate adaptation scheme with On-Demand Feedback
abstract
Classical 802.11 rate adaptation algorithms rely on feedback from the receiver to correctly choose a sending rate, typically in the form of acknowledgments (ACKs). In the absence of such frames, novel techniques are required for rate selection. We present a novel On-Demand Feedback Rate Adaptation algorithm (OFRA) that works with ACK-less traffic. Feedback information is sent on-demand using a control frame to explicitly inform the transmitter about which bit rate to use on subsequent data frames. This approach guarantees standard conformity and exhibits fast and accurate bit rate adaptation at the cost of a modest overhead increase. We evaluate the performance of OFRA against various state-of-the-art rate adaptation schemes by means of simulations. If ACK frames are to be transmitted, OFRA performs better than related work in most considered scenarios, and on par in the others. In the absence of ACKs, OFRA provides large goodput gains under good channel conditions and comparable goodput in other situations.
Florian Schmidt 0002, Anwar Hithnawi, Oscar Puñal, James Gross, Klaus Wehrle
PIMRC2