EDBT 2026 Demo / reviewers in the wild / expert
Pubali Datta
dblp:154/4512
· DBLP profile ↗
17ranked-venue papers
2as first author
8since 2021 · last 2026
0009-0005-2026-5465ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 1 first-author · 7 since 2021Computer networks · 2Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Quantifying Risk Perception and Scam Response Among International and Domestic US University Students
Alexandra Xinran Li, Elijah Robert Bouma-Sims, Lily Klucinec, Ray Liu, Ayesha Binte Mostofa, Arjun Arunasalam, Lorrie Faith Cranor, Pubali Datta, Lucy Simko, Karen Sowon |
SOUPS | 8 |
| 2026 | International Students and Scams: At Risk AbroadabstractInternational students (IntlS) in the US refer to foreign students who acquire student visas to study in the US, primarily in higher education. As IntlS arrive in the US, they face several challenges, such as adjusting to a new country and culture, securing housing remotely, and arranging finances for tuition and personal expenses. These experiences, coupled with recent events such as visa revocations and the cessation of new visas, compound IntlS' risk of being targeted by and falling victim to online scams. While prior work has investigated IntlS' security and privacy, as well as general end users' reactions to online scams, research on how IntlS are uniquely impacted by scams remains largely absent. To address this gap, we conduct a two-phase user study comprising surveys (n=48) and semi-structured interviews (n=9). We investigate IntlS' exposure and interactions with scams, post-exposure actions such as reporting, and their perceptions of the usefulness of existing prevention resources and the barriers to following prevention advice. We find that IntlS are often targeted by scams (e.g., attackers impersonating government officials) and fear legal implications or deportation, which directly impacts their interactions with scams (e.g., they may prolong engagement with a scammer due to a sense of urgency). Interestingly, we also find that IntlS may lack awareness of - or access to - reliable resources that inform them about scams or guide them in reporting incidents to authorities. In fact, they may also face unique barriers in enacting scam prevention advice, such as avoiding reporting financial losses, since IntlS are required to demonstrate financial ability to stay in the US. The findings produced by our study help synthesize guidelines for stakeholders to better aid IntlS in reacting to scams. Katherine Zhang, Arjun Arunasalam, Pubali Datta, Z. Berkay Celik |
SP | 3 |
| 2026 | CensorLess: Cost-Efficient Censorship Circumvention Through Serverless Cloud FunctionsabstractWith the increase in Internet censorship globally, various circumvention tools have been designed and developed. However, the monetary cost of these tools deeply impacts both user choice and the sustainability of provider operations. Recent developments in censorship circumvention research attempted to achieve cost efficiency by utilizing Infrastructure-as-a-Service (IaaS) spot instances as bridges, but still incurred substantial expenses related to network connectivity and instance maintenance. In this work, we present CensorLess, a circumvention proxy that leverages the unique benefits of serverless platforms. CensorLess comprises three components:a local proxy that manages client communication and enforces serverless security constraints, a function refresher that periodically regenerates bridges, and a live migration mechanism that maintains continuous connectivity. By design, CensorLess inherits key serverless properties, which are cost efficiency, ephemerality, scalability, concurrency, and high performance. Compared to existing low-cost, state-of-the-art circumvention techniques, CensorLess reduces operational costs by 97%, while simultaneously enabling robust censorship resistance by employing bridge rotation. Dayeon Kang, Jade Sheffey, Mingshi Wu, Pubali Datta, Amir Houmansadr |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | DrSec: Flexible Distributed Representations for Efficient Endpoint SecurityabstractThe increasing complexity of attacks has given rise to varied security applications tackling profound tasks, ranging from alert triage to attack reconstruction. Yet, security products, such as Endpoint Detection and Response, bring together applications that are developed in isolation, trigger many false positives, miss actual attacks, and produce limited labels useful in supervised learning schemes. To address these challenges, we propose DrSec—a system employing self-supervised learning to pre-train foundation language models (LMs) that ingest event-sequence data and emit distributed representations for processes. Once pre-trained, the LMs can be adapted to solve different downstream tasks with limited to no supervision, helping unify the currently fractured application ecosystem. We trained DrSec with two LM types on a real-world dataset containing ∼91M processes and ∼2.55B events, and tested it in three application domains. We found that DrSec enables accurate, unsupervised process identification; outperforms leading methods on alert triage to reduce alert fatigue (e.g., 75.11% vs. ≤64.31% precision-recall area under curve); and accurately learns expert-developed rules, allowing tuning incident detectors to control false positives and negatives. Mahmood Sharif, Pubali Datta, Andy Riddle, Kim Westfall, Adam Bates 0001, Vijay Ganti, Matthew Lentz, David Ott |
SP | 2 |
| 2024 | GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security PoliciesabstractServerless computing is supplanting past versions of cloud computing as the easiest way to rapidly prototype and deploy applications. However, the reentrant and ephemeral nature of serverless functions only exacerbates the challenge of correctly specifying security policies. Unfortunately, with role-based access control solutions like Amazon Identity and Access Management (IAM) already suffering from pervasive misconfiguration problems, the likelihood of policy failures in serverless applications is high. Isaac Polinsky, Pubali Datta, Adam Bates 0001, William Enck |
WWW | 2 |
| 2023 | Characterizing Everyday Misuse of Smart Home DevicesabstractExploration of Internet of Things (IoT) security often focuses on threats posed by external and technically-skilled attackers. While it is important to understand these most extreme cases, it is equally important to understand the most likely risks of harm posed by smart device ownership. In this paper, we explore how smart devices are misused — used without permission in a manner that causes harm — by device owners’ everyday associates such as friends, family, and romantic partners. In a preliminary characterization survey (n = 100), we broadly capture the kinds of unauthorized use and misuse incidents participants have experienced or engaged in. Then, in a prevalence survey (n = 483), we assess the prevalence of these incidents in a demographically-representative population. Our findings show that unauthorized use of smart devices is widespread (experienced by 43% of participants), and that misuse is also common (experienced by at least 19% of participants). However, highly individual factors determine whether these unauthorized use events constitute misuse. Through a focus on everyday abuses, this work sheds light on the most prevalent security and privacy threats faced by smart-home owners today. Phoebe Moh, Pubali Datta, Noel Warford, Adam Bates 0001, Nathan Malkin, Michelle L. Mazurek |
SP | 2 |
| 2022 | ALASTOR: Reconstructing the Provenance of Serverless Intrusions
Pubali Datta, Isaac Polinsky, Muhammad Adil Inam, Adam Bates 0001, William Enck |
USENIX Security Symposium | 1 |
| 2021 | SCIFFS: Enabling Secure Third-Party Security Analytics using Serverless ComputingabstractThird-party security analytics allow companies to outsource threat monitoring tasks to teams of experts and avoid the costs of in-house security operations centers. By analyzing telemetry data from many clients these services are able to offer enhanced insights, identifying global trends and spotting threats before they reach most customers. Unfortunately, the aggregation that drives these insights simultaneously risks exposing sensitive client data if it is not properly sanitized and tracked. In this work, we present SCIFFS, an automated information flow monitoring framework for preventing sensitive data exposure in third-party security analytics platforms. SCIFFS performs decentralized information flow control over customer data it in a serverless setting, leveraging the innate polyinstantiated nature of serverless functions to assure precise and lightweight tracking of data flows. Evaluating SCIFFS against a proof-of-concept security analytics framework on the widely-used OpenFaaS platform, we demonstrate that our solution supports common analyst workflows data ingestion, custom dashboards, threat hunting) while imposing just 3.87% runtime overhead on event ingestion and the overhead on aggregation queries grows linearly with the number of records in the database (e.g., 18.75% for 50,000 records and 104.27% for 500,000 records) as compared to an insecure baseline. Thus, SCIFFS not only establishes a privacy-respecting model for third-party security analytics, but also highlights the opportunities for security-sensitive applications in the serverless computing model. Isaac Polinsky, Pubali Datta, Adam Bates 0001, William Enck |
SACMAT | 2 |
| 2020 | Workflow Integration Alleviates Identity and Access Management in Serverless ComputingabstractAs serverless computing continues to revolutionize the design and deployment of web services, it has become an increasingly attractive target to attackers. These adversaries are developing novel tactics for circumventing the ephemeral nature of serverless functions, exploiting container reuse optimizations and achieving lateral movement by “living off the land” provided by legitimate serverless workflows. Unfortunately, the traditional security controls currently offered by cloud providers are inadequate to counter these new threats. Arnav Sankaran, Pubali Datta, Adam Bates 0001 |
ACSAC | 2 |
| 2020 | OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-layer Log Analysis
Wajih Ul Hassan, Mohammad A. Noureddine, Pubali Datta, Adam Bates 0001 |
NDSS | 3 |
| 2020 | Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted Execution
Riccardo Paccagnella, Pubali Datta, Wajih Ul Hassan, Adam Bates 0001, Christopher W. Fletcher, Jing (Dave) Tian |
NDSS | 2 |
| 2020 | Valve: Securing Function Workflows on Serverless Computing PlatformsabstractServerless Computing has quickly emerged as a dominant cloud computing paradigm, allowing developers to rapidly prototype event-driven applications using a composition of small functions that each perform a single logical task. However, many such application workflows are based in part on publicly-available functions developed by third-parties, creating the potential for functions to behave in unexpected, or even malicious, ways. At present, developers are not in total control of where and how their data is flowing, creating significant security and privacy risks in growth markets that have embraced serverless (e.g., IoT). Pubali Datta, Prabuddha Kumar, Tristan Morris, Michael Grace, Amir Rahmati, Adam Bates 0001 |
WWW | 1 |
| 2019 | Charting the Attack Surface of Trigger-Action IoT PlatformsabstractInternet of Things (IoT) deployments are becoming increasingly automated and vastly more complex. Facilitated by programming abstractions such as trigger-action rules, end-users can now easily create new functionalities by interconnecting their devices and other online services. However, when multiple rules are simultaneously enabled, complex system behaviors arise that are difficult to understand or diagnose. While history tells us that such conditions are ripe for exploitation, at present the security states of trigger-action IoT deployments are largely unknown. In this work, we conduct a comprehensive analysis of the interactions between trigger-action rules in order to identify their security risks. Using IFTTT as an exemplar platform, we first enumerate the space of inter-rule vulnerabilities that exist within trigger-action platforms. To aid users in the identification of these dangers, we go on to present iRuler, a system that performs Satisfiability Modulo Theories (SMT) solving and model checking to discover inter-rule vulnerabilities within IoT deployments. iRuler operates over an abstracted information flow model that represents the attack surface of an IoT deployment, but we discover in practice that such models are difficult to obtain given the closed nature of IoT platforms. To address this, we develop methods that assist in inferring trigger-action information flows based on Natural Language Processing. We develop a novel evaluative methodology for approximating plausible real-world IoT deployments based on the installation counts of 315,393 IFTTT applets, determining that 66% of the synthetic deployments in the IFTTT ecosystem exhibit the potential for inter-rule vulnerabilities. Combined, these efforts provide the insight into the real-world dangers of IoT deployment misconfigurations. Qi Wang 0017, Pubali Datta, Wei Yang 0013, Si Liu 0003, Adam Bates 0001, Carl A. Gunter |
CCS | 2 |
| 2015 | Demo: A Smart Framework for IoT Analytic Workflow DevelopmentabstractDeveloping analytical applications for IoT based on sensor signal processing tends to be complicated as applications are executed as sequence of steps comprising of multiple alternative algorithms, including suitable feature extraction modules depending on the goal of the application. Experience shows that developers spend considerable time and effort in performing feature extraction and dimensionality reduction. In this paper we propose a framework based on a relevant case study which allows developers to drag and drop algorithms to create a workflow chain, automatically select the most relevant signal features for the particular analytic application using a training data set to generate a model and deploy the model for use. The method reduces the effort and cost of development which is deemed highly important for the analytics industry. Dibyanshu Jaiswal, Pubali Datta, Sounak Dey, Himadri Sekhar Paul, Tanushyam Chattopadhyay, Avik Ghose, Arpan Pal 0001, Arijit Mukherjee |
SenSys | 2 |
| 2014 | An access point to device association technique for optimized data transfer in mobile gridsabstractIn a mobile grid computing framework where mobile devices are used as computing resources, minimizing the task offloading time remains an important issue. A task is an independent unit of execution consisting of a input data volume for execution and optionally a target-specific executable. We consider a mobile grid infrastructure where mobile devices are connected via Wi-Fi network and the grid infrastructure has a set of tasks (i.e. a set of data volumes) to be transferred to a subset of the mobile devices. In a Wi-Fi network, mobile devices usually associate themselves to the access points (APs) having the strongest radio signal. In this paper, we address the problem of AP activation (by frequency assignment) and association of AP with devices in the context of minimizing the overall data-transfer completion time. We present a constraint based formulation and also a heuristic as solutions. Simulations results are presented which contrast our proposed methods with some of the earlier works. Ansuman Banerjee, Himadri Sekhar Paul, Arijit Mukherjee, Pubali Datta, Sajal K. Das 0001 |
ICPADS | 4 |
| 2014 | Dual scheme phone: a user assisted mechanism to effectively run sensor analytics applications on smartphonesabstractIn recent times, many human-centric applications are being developed to leverage the diverse range of sensors present in Android smartphones. Smartphones are also being used as edge network gateways for fusing data from multiple sensors. These applications often run as background services and usuall Swarnava Dey, Arijit Mukherjee, Pubali Datta, Himadri Sekhar Paul, Anupam Basu |
MobiQuitous | 3 |
| 2014 | Facilitating continued run of sensor data analytics services using user driven proactive memory reclamation schemeabstractSmartphones are currently being used to develop diverse range of applications (apps) involving sensors. These apps generally acquire and analyze sensor data and are usually implemented as background services. The importance values of Android processes are in a hierarchy of foreground, visible, background etc. in decreasing order of importance. Whenever a new process arrives, it may necessitate removal of old and less important processes for reclaiming memory. Current smartphones do not provide any options through which user's idea of priority can override that of the system defaults. In this work we present an implementation that enables the user to obtain alerts on system load and recommendations to proactively kill a set of processes to reclaim system memory. This enables user selected background process to be spared from the standard android policy of process termination, in lieu of foreground apps, relatively unimportant from user perspective, during that period. We show that manual reclaiming of memory based on recommendations from our app, reduces the automatic killing and measurement lag experienced by a sensor analytics app under test. This work is redundant if processing power and main memory of a smartphone is always surplus than required for its normal usage. Swarnava Dey, Pubali Datta, Arijit Mukherjee, Himadri Sekhar Paul, Anupam Basu |
SenSys | 2 |