EDBT 2026 Demo / reviewers in the wild / expert
Marc Juarez
dblp:129/8347 · also Marc Juárez, Marc Juárez Miró
· DBLP profile ↗
18ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0001-7657-9934ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The attention leak: Behavioral inference from temporal metadata in network trafficabstractHuman attention is a dynamic and limited resource, essential for navigating complex tasks and environments. In the digital age, this resource is increasingly strained by frequent task switching, driven by constant notifications and fragmented workflows. While the cognitive costs of task switching are well-documented, its implications for digital privacy remain underexplored. This study investigates a novel privacy threat: the inference of task switching from network traffic by network service providers. We demonstrate that behavioral signatures, such as task durations and switching patterns, can be extracted from temporal metadata, potentially revealing sensitive information about users’ cognitive states and habits. We introduce a machine learning-based approach to infer these patterns and empirically validate its effectiveness on network traffic traces. To counter this threat, we propose a mitigation strategy that obfuscates task-switching signals without substantially impacting network performance. Our findings bridge cognitive science and network security, highlighting a new dimension of privacy risk in modern digital infrastructures and offering practical pathways toward more privacy-preserving communication systems. Alejandro Donaire, Carlos Borrego, Marc Juarez |
J. Netw. Comput. Appl. | 3 |
| 2026 | Shift Your Shape: Correlating and Defending Mixnet Flows Based on Their ShapesabstractWhen the packet rate of flows in a mixnet depends on the amount of transferred data, it is possible to identify which flow entering is which flow exiting the mixnet based on their shapes. We present a passive shape-based flow correlation attack against state-of-the-art mixnet Nym and a systematic evaluation of countermeasures. Assuming an adversary controlling both the entry and exit gateway-requesters selected by users to access the public Internet through Nym, our attack's artificial neural network assigns correlation scores to flow pairs based on traffic distribution similarities to accurately distinguish paired from unpaired flow tuples. From data we collected on the live Nym mixnet, we generate$ \mathbf {45}$datasets and$ \mathbf {119}$testing scenarios for different defense configurations. After one minute of attacking flow pairs on default Nym, we achieve a PR-AUC of$ \mathbf {0.9998}$at a base rate of$ \mathbf {1.9 \times 10^{-4}}$paired flow tuples. However, (combinations of) the five evaluated defense strategies indicate that the right choice and scale of countermeasure(s) can offer meaningful protection. Our evaluation also informs on the resources overhead spent on defenses. We discuss steps a mixnet such as Nym can take to make our attack both less likely and less accurate. Lennart Oldenburg, Marc Juarez, Enrique Argones-Rúa, Claudia Díaz |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Rethinking the Role of Network Stacks for Website Fingerprinting DefensesabstractWhile encryption has become ubiquitous across the Internet, there is growing concern that website fingerprinting and other traffic analysis attacks could undermine the confidentiality guarantees encryption is meant to provide. Over the past decade, these attacks have become increasingly effective, highlighting the urgent need to deploy traffic obfuscation countermeasures. Although defenses have already been proposed in the literature, they remain inefficient partly because they are implemented at the application-level, which limits their control over packet sequences. This paper advocates for integrating packet sequence obfuscation support directly into host network stacks, where the fine-grained packet operations that defenses require can be effectively enforced. Elisaveta Lavrentieva, Marc Juarez, Michio Honda |
HotNets | 2 |
| 2025 | A Crack in the Bark: Leveraging Public Knowledge to Remove Tree-Ring Watermarks
Junhua Lin, Marc Juarez |
USENIX Security Symposium | 2 |
| 2024 | MixMatch: Flow Matching for Mixnet TrafficabstractMixnets provide communication anonymity against network adversaries by routing packets independently via multiple hops, delaying them artificially at each hop, and introducing cover traffic. We show that these features (particularly the use of cover traffic) significantly diminish the effectiveness of state-of-the-art flow correlation techniques developed to link the two ends of a Tor connection. In this work, we propose novel methods to determine whether a set of endpoints exchanges packets via a mixnet and demonstrate their effectiveness by applying them to the Nym mixnet. We consider Nym in both an idealized lab setup and the official live network, and propose and compare three classifiers to conduct flow matching on it. Our statistical classifier tests whether egress packet timestamps are consistent with ingress timestamps and the (known) routing delay characteristic of the mixnet. In contrast, our two deep learning (DL) classifiers learn to distinguish matched from unmatched flow pairs from collected datasets directly, rather than relying on priors that describe the delay distribution. All three classifiers use our flow merging technique, which enables testing a match for sets of communicating endpoints of any cardinality. Considering a use case where two observed endpoints communicate exclusively to exchange a file through Nym, we find that flow matching is fast and accurate in the idealized lab setup. If flow pairs are aligned using all network observations in a download, we achieve a TPR of circa 0.6 (DL) and 0.47 (statistical) at an FPR of 10^-2 after only processing 100 observations. We evaluate classifier performance under key variations of this setup: the absence of loop cover traffic, an increased or decreased average per-mix delay, larger communicating sets (three endpoints) with faster responders, and the presence of realistic network effects (live network). The classifiers' matching performance diminishes on the live network where packet losses and variable propagation delays exist, reducing DL TPR to circa 0.26 and statistical TPR to circa 0.28 at an FPR of 10^-2. Informed by the insights of our analyses, we outline countermeasures that can be deployed in mixnets such as Nym to mitigate flow matching threats. Lennart Oldenburg, Marc Juarez, Enrique Argones-Rúa, Claudia Díaz |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | Online Platforms and the Fair Exposure Problem under HomophilyabstractIn the wake of increasing political extremism, online platforms have been criticized for contributing to polarization. One line of criticism has focused on echo chambers and the recommended content served to users by these platforms. In this work, we introduce the fair exposure problem: given limited intervention power of the platform, the goal is to enforce balance in the spread of content (e.g., news articles) among two groups of users through constraints similar to those imposed by the Fairness Doctrine in the United States in the past. Groups are characterized by different affiliations (e.g., political views) and have different preferences for content. We develop a stylized framework that models intra- and inter-group content propagation under homophily, and we formulate the platform's decision as an optimization problem that aims at maximizing user engagement, potentially under fairness constraints. Our main notion of fairness requires that each group see a mixture of their preferred and non-preferred content, encouraging information diversity. Promoting such information diversity is often viewed as desirable and a potential means for breaking out of harmful echo chambers. We study the solutions to both the fairness-agnostic and fairness-aware problems. We prove that a fairness-agnostic approach inevitably leads to group-homogeneous targeting by the platform. This is only partially mitigated by imposing fairness constraints: we show that there exist optimal fairness-aware solutions which target one group with different types of content and the other group with only one type that is not necessarily the group's most preferred. Finally, using simulations with real-world data, we study the system dynamics and quantify the price of fairness. Jakob Schöffer, Alexander Ritchie, Keziah Naggita, Faidra Monachou, Jessica Finocchiaro, Marc Juarez |
AAAI | 6 |
| 2020 | Encrypted DNS -> Privacy? A Traffic Analysis Perspective
Sandra Deepthy Siby, Marc Juarez, Claudia Díaz, Narseo Vallina-Rodriguez, Carmela Troncoso |
NDSS | 2 |
| 2018 | Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningabstractWebsite fingerprinting enables a local eavesdropper to determine which websites a user is visiting over an encrypted connection. State-of-the-art website fingerprinting attacks have been shown to be effective even against Tor. Recently, lightweight website fingerprinting defenses for Tor have been proposed that substantially degrade existing attacks: WTF-PAD and Walkie-Talkie. In this work, we present Deep Fingerprinting (DF), a new website fingerprinting attack against Tor that leverages a type of deep learning called Convolutional Neural Networks (CNN) with a sophisticated architecture design, and we evaluate this attack against WTF-PAD and Walkie-Talkie. The DF attack attains over 98% accuracy on Tor traffic without defenses, better than all prior attacks, and it is also the only attack that is effective against WTF-PAD with over 90% accuracy. Walkie-Talkie remains effective, holding the attack to just 49.7% accuracy. In the more realistic open-world setting, our attack remains effective, with 0.99 precision and 0.94 recall on undefended traffic. Against traffic defended with WTF-PAD in this setting, the attack still can get 0.96 precision and 0.68 recall. These findings highlight the need for effective defenses that protect against this new attack and that could be deployed in Tor. Payap Sirinam, Mohsen Imani, Marc Juarez, Matthew Wright 0001 |
CCS | 3 |
| 2018 | Inside Job: Applying Traffic Analysis to Measure Tor from Within
Rob Jansen, Marc Juarez, Rafa Gálvez, Tariq Elahi, Claudia Díaz |
NDSS | 2 |
| 2018 | Automated Website Fingerprinting through Deep Learning
Vera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem, Wouter Joosen |
NDSS | 3 |
| 2017 | How Unique is Your .onion?: An Analysis of the Fingerprintability of Tor Onion ServicesabstractRecent studies have shown that Tor onion (hidden) service websites are particularly vulnerable to website fingerprinting attacks due to their limited number and sensitive nature. In this work we present a multi-level feature analysis of onion site fingerprintability, considering three state-of-the-art website fingerprinting methods and 482 Tor onion services, making this the largest analysis of this kind completed on onion services to date. Rebekah Overdorf, Marc Juarez, Gunes Acar, Rachel Greenstadt, Claudia Díaz |
CCS | 2 |
| 2017 | Website Fingerprinting Defenses at the Application LayerabstractAbstract Website Fingerprinting (WF) allows a passive network adversary to learn the websites that a client visits by analyzing traffic patterns that are unique to each website. It has been recently shown that these attacks are particularly effective against .onion sites, anonymous web servers hosted within the Tor network. Given the sensitive nature of the content of these services, the implications of WF on the Tor network are alarming. Prior work has only considered defenses at the client-side arguing that web servers lack of incentives to adopt countermeasures. Furthermore, most of these defenses have been designed to operate on the stream of network packets, making practical deployment difficult. In this paper, we propose two application-level defenses including the first server-side defense against WF, as .onion services have incentives to support it. The other defense is a lightweight client-side defense implemented as a browser add-on, improving ease of deployment over previous approaches. In our evaluations, the server-side defense is able to reduce WF accuracy on Tor .onion sites from 69.6% to 10% and the client-side defense reduces accuracy from 64% to 31.5%. Giovanni Cherubin, Jamie Hayes, Marc Juarez |
Proc. Priv. Enhancing Technol. | 3 |
| 2016 | Toward an Efficient Website Fingerprinting Defense
Marc Juarez, Mohsen Imani, Mike Perry, Claudia Díaz, Matthew Wright 0001 |
ESORICS (1) | 1 |
| 2014 | The Web Never Forgets: Persistent Tracking Mechanisms in the WildabstractWe present the first large-scale studies of three advanced web tracking mechanisms - canvas fingerprinting, evercookies and use of "cookie syncing" in conjunction with evercookies. Canvas fingerprinting, a recently developed form of browser fingerprinting, has not previously been reported in the wild; our results show that over 5% of the top 100,000 websites employ it. We then present the first automated study of evercookies and respawning and the discovery of a new evercookie vector, IndexedDB. Turning to cookie syncing, we present novel techniques for detection and analysing ID flows and we quantify the amplification of privacy-intrusive tracking practices due to cookie syncing. Gunes Acar, Christian Eubank, Steven Englehardt, Marc Juarez, Arvind Narayanan, Claudia Díaz |
CCS | 4 |
| 2014 | A Critical Evaluation of Website Fingerprinting AttacksabstractRecent studies on Website Fingerprinting (WF) claim to have found highly effective attacks on Tor. However, these studies make assumptions about user settings, adversary capabilities, and the nature of the Web that do not necessarily hold in practical scenarios. The following study critically evaluates these assumptions by conducting the attack where the assumptions do not hold. We show that certain variables, for example, user's browsing habits, differences in location and version of Tor Browser Bundle, that are usually omitted from the current WF model have a significant impact on the efficacy of the attack. We also empirically show how prior work succumbs to the base rate fallacy in the open-world scenario. We address this problem by augmenting our classification method with a verification step. We conclude that even though this approach reduces the number of false positives over 63\%, it does not completely solve the problem, which remains an open issue for WF attacks. Marc Juarez, Sadia Afroz 0001, Gunes Acar, Claudia Díaz, Rachel Greenstadt |
CCS | 1 |
| 2013 | FPDetective: dusting the web for fingerprintersabstractIn the modern web, the browser has emerged as the vehicle of choice, which users are to trust, customize, and use, to access a wealth of information and online services. However, recent studies show that the browser can also be used to invisibly fingerprint the user: a practice that may have serious privacy and security implications. Gunes Acar, Marc Juarez, Nick Nikiforakis, Claudia Díaz, Seda Gurses, Frank Piessens, Bart Preneel |
CCS | 2 |
| 2013 | A self-adaptive classification for the dissociating privacy agentabstractThis paper describes an extension of the Dissociating Privacy Agent (DisPA), which is a Privacy Enhancement Technology (PET) for web search. It is implemented as an add-on for Firefox that acts like a proxy between the user and the search engine. A fundamental part of DisPA is the classification of queries into a set of categories. Particularly, the taxonomy of the Open Directory Project (ODP) is used for this purpose. In this paper we briefly recall the internal operations of the agent, discuss the drawbacks of the current model and propose an improvement to overcome them. Marc Juarez, Vicenç Torra |
PST | 1 |
| 2013 | Toward a Privacy Agent for Information RetrievalabstractIn this paper, we tackle the private information retrieval (PIR) problem associated with the use of Internet search engines. We address the desire for a user to retrieve information from the Web without the search provider learning about it. Traditional PIR protocols present two main shortcomings for their application: (i) They assume cooperation by the database, which is not affordable for a real-world search engine like Google and (ii) their computational complexity is linear in the size of the database, which is unfeasible in the case of the Web. More recent approaches relax PIR conditions to overcome these limitations and present some level of privacy. Mostly, they aim to distort server logs regardless of the loss of information that is involved. Server logs are used by search engines for profiling and, thereby, provide personalized results. This becomes a user's need given the growth of the Web and can also be used for targeted advertising. This study focuses on a noncooperative agent for private search that considers profiling as valuable data used for both sides of the search process. It is based on the assumption that the user's identity is formed by the union of various areas of interests or facets. Managing the HTTP connections properly, submitted queries are mapped to different server logs according to these facets. The rationale is that these logs cannot be used for tracing the user while they are still helpful for profiling. We present a personalized query classification approach based on the user's browsing history and to provide empirical results; we developed an attacking algorithm against the agent that shows that the disclosure risk is reduced. Marc Juarez, Vicenç Torra |
Int. J. Intell. Syst. | 1 |