EDBT 2026 Demo / reviewers in the wild / expert
Sandra Deepthy Siby
dblp:156/5453
· DBLP profile ↗
11ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-9481-0826ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 5 since 2021Computer networks · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Catching Hackers by Watching Watts: A Measurement Study of Power-Only Attack Detection on Consumer IoT DevicesabstractSecurity analysis of consumer Internet of Things (IoT) devices is increasingly constrained by limited visibility into encrypted traffic and closed firmware, which motivates the exploration of observable and privacy preserving external signals. Prior work has shown that adversarial activity can induce measurable changes in device power usage, indicating that power based intrusion detection is feasible, yet its stability and reliability under realistic operating conditions remain unclear. We address this gap through a systematic measurement study of 33 commercial IoT devices, collecting per second power traces and complete background traffic logs during idle operation and realistic active use under Denial of Service (DoS) and Reconnaissance attacks. Our analysis shows that power usage provides clear separation between benign and adversarial behavior in stable idle states, while legitimate activity introduces masking that varies across devices. We identify 4 behavioral regimes that describe how activity suppresses or alters attack related increments and analyze power stability and background traffic characteristics to explain the observed differences in detection strength. Our findings provide the first systematic large-scale characterization of when power-based detection remains reliable and when it degrades, highlighting the physical and network conditions that govern its robustness in realistic deployments. Hashim Zia, Jiahui Qin, Sandra Deepthy Siby, Anna Maria Mandalari |
IEEE Internet Things J. | 4 |
| 2024 | SINBAD: Saliency-informed detection of breakage caused by ad blockingabstractPrivacy-enhancing blocking tools based on filter-list rules tend to break legitimate functionality. Filter-list maintainers could benefit from automated breakage detection tools that allow them to proactively fix problematic rules before deploying them to millions of users. We introduce SINBAD, an automated breakage detector that improves the accuracy over the state of the art by 20%, and is the first to detect dynamic breakage and breakage caused by style-oriented filter rules. The success of SINBAD is rooted in three innovations: (1) the use of user-reported breakage issues in forums that enable the creation of a high-quality dataset for training in which only breakage that users perceive as an issue is included; (2) the use of ‘web saliency’ to automatically identify user-relevant regions of a website on which to prioritize automated interactions aimed at triggering breakage; and (3) the analysis of webpages via subtrees which enables fine-grained identification of problematic filter rules. Saiid El Hajj Chehade, Sandra Deepthy Siby, Carmela Troncoso |
SP | 2 |
| 2024 | PURL: Safe and Effective Sanitization of Link Decoration
Shaoor Munir, Patrick Lee, Umar Iqbal 0002, Sandra Deepthy Siby, Zubair Shafiq |
USENIX Security Symposium | 4 |
| 2023 | CookieGraph: Understanding and Detecting First-Party Tracking CookiesabstractAs third-party cookie blocking is becoming the norm in mainstream web browsers, advertisers and trackers have started to use first-party cookies for tracking. To understand this phenomenon, we conduct a differential measurement study with versus without third-party cookies. We find that first-party cookies are used to store and exfiltrate identifiers to known trackers even when third-party cookies are blocked. Shaoor Munir, Sandra Deepthy Siby, Umar Iqbal 0002, Steven Englehardt, Zubair Shafiq, Carmela Troncoso |
CCS | 2 |
| 2023 | Evaluating practical QUIC website fingerprinting defenses for the massesabstractWebsite fingerprinting (WF) is a well-known threat to users' web privacy. New Internet standards, such as QUIC, include padding to support defenses against WF. Previous work on QUIC WF only analyzes the effectiveness of defenses when users are behind a VPN. Yet, this is not how most users browse the Internet. In this paper, we provide a comprehensive evaluation of QUIC-padding-based defenses against WF when users directly browse the web, i.e., without VPNs, HTTPS proxies, or other tunneling protocols. We confirm previous claims that network-layer padding cannot provide effective protection against powerful adversaries capable of observing all traffic traces. We show that the claims hold even against adversaries with constraints on traffic visibility and processing power. We then show that the current approach to web development, in which the use of third-party resources is the norm, impedes the effective use of padding-based defenses as it requires first and third parties to coordinate in order to thwart traffic analysis. We show that even when coordination is possible, in most cases, protection comes at a high cost. Sandra Deepthy Siby, Ludovic Barman, Christopher A. Wood, Marwan Fayed, Nick Sullivan, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | WebGraph: Capturing Advertising and Tracking Information Flows for Robust Blocking
Sandra Deepthy Siby, Umar Iqbal 0002, Steven Englehardt, Zubair Shafiq, Carmela Troncoso |
USENIX Security Symposium | 1 |
| 2020 | Encrypted DNS -> Privacy? A Traffic Analysis Perspective
Sandra Deepthy Siby, Marc Juarez, Claudia Díaz, Narseo Vallina-Rodriguez, Carmela Troncoso |
NDSS | 1 |
| 2017 | Practical Evaluation of Passive COTS Eavesdropping in 802.11b/n/ac WLAN
Daniele Antonioli, Sandra Deepthy Siby, Nils Ole Tippenhauer |
CANS | 2 |
| 2017 | Link-Layer Device Type Classification on Encrypted Wireless Traffic with COTS Radios
Rajib Ranjan Maiti, Sandra Deepthy Siby, Ragav Sridharan, Nils Ole Tippenhauer |
ESORICS (2) | 2 |
| 2015 | METhoD: A Framework for the Emulation of a Delay Tolerant Network Scenario for Media-Content Distribution in Under-Served RegionsabstractWireless communication remains to be the most efficient way of providing access to information to users in developing economies. We are interested in Delay-Tolerant Networks (DTNs) for distributing multimedia content to micro-entrepreneurs in under-served rural areas of South Africa. In our project, public commuter buses carrying WLAN-enabled devices (mobile infostations) that provide DTN connectivity are used to ferry data between urban and rural areas. Before the actual deployment in the field, rigorous lab experiments have been performed to study the performance of the proposed network design. Such an activity is time consuming and requires arduous preparation. Simulators, while convenient, do not provide the most realistic results. Given the complexity of DTN testing, we try to find a middle ground approach by building a mobility emulator testbed, which we use to emulate the network scenario. In this paper, we outline the design and implementation details of the network emulator. We then describe the experiments that were performed to study the impact of different network dynamics on content delivery, and their results. The results from the experiments are used to improve our current network design. Sandra Deepthy Siby, Adriano Galati, Theodoros Bourchas, Maria Olivares, Thomas R. Gross, Stefan Mangold |
ICCCN | 1 |
| 2011 | ISSTA: An Integrated Sensing System for Transportation ApplicationsabstractTraffic congestion has become an increasingly important issue worldwide. One way to mitigate this problem is to provide real time traffic information to drivers and help them make better decisions. Hence, a system with the function of traffic sensing, data aggregation and information delivery is desired. In this paper, we illustrate how we design and build such a system, which is called ISSTA (An Integrated Sensing System for Transportation Applications).This system consists of two parts: the front end is a mobile device attached to a vehicle; it can perform real time traffic and environment sensing, wireless information transmission, and interaction with drivers. The back end is a server, which stores the information collected and implements smart decision-making. In addition to this, the system supports "plug-and-play" for a list of sensing components. At the same time, the information collected and decision made can be easily monitored in real time through web service. Applications like real time environment monitoring and lane sensing have already been implemented and tested on this system. We have shown that it is a reliable system by itself and can provide valuable help to drivers and researchers. Ken Yeo-Moriuchi, Sandra Deepthy Siby, Zhengqing Hu, Mehul Motani |
VTC Fall | 2 |