EDBT 2026 Demo / reviewers in the wild / expert
Michael A. Specter
dblp:169/8186
· DBLP profile ↗
10ranked-venue papers
4as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 7 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Uncovering Relationships Between Android Developers, User Privacy, and Developer Willingness to Reduce Fingerprinting RisksabstractThe major mobile platforms, Android and iOS, have introduced changes that restrict user tracking to improve user privacy, yet apps continue to covertly track users via device fingerprinting. We study the opportunity to improve this dynamic with a case study on mobile fingerprinting that evaluates developers’ perceptions of how well platforms protect user privacy and how developers perceive platform privacy interventions. Specifically, we study developers’ willingness to make changes to protect users from fingerprinting and how developers consider trade-offs between user privacy and developer effort. We do this via a survey of 246 Android developers, presented with a hypothetical Android change that protects users from fingerprinting at the cost of additional developer effort. Alex Berke, Güliz Seray Tuncay, Michael A. Specter, Mihai Christodorescu |
CHI | 3 |
| 2026 | A Real-World Law-Enforcement Hack: The Case of Encrochat
Martin R. Albrecht, Sunoo Park, Michael A. Specter, Douglas Stebila |
CRYPTO (10) | 3 |
| 2026 | Papers, Please: A First Look at Age Verification on the Web
Shreyas Minocha, Isaac Sheridan, Harry Oppenheimer, Paul Pearce, Michael A. Specter |
SP | 5 |
| 2026 | SoK: Offline Finding Protocols for Lightweight Location TrackingabstractOffline finding (OF) protocols---such as Apple's Find My, Google's Find Hub, Samsung’s SmartThingsFind, and Tile---enable hundreds of millions of users to track their belongings via Bluetooth-based tracker tags. However, their scale and tracking capabilities give rise to privacy risks for tag owners and bystanders, as well as safety risks for victims of tag-facilitated stalking. In response, academics and practitioners have suggested cryptographic and non-cryptographic mitigations to improve privacy and anti-stalking protections, working to navigate complex and subtle tensions between these goals. The result is a large landscape of privacy goals, threat models, protocol designs, implementations, and analyses. In this work, we systematize the OF protocol landscape. We gather and analyze a corpus of 49 research papers and OF protocol technical specifications, and use it to develop a taxonomy capturing the functionality, security, and privacy goals of OF protocols. We use the taxonomy to guide a focused assessment of the four major OF deployments along with six academic constructions, comparing design choices, consolidating known attacks, and analyzing the designs' trade-offs between privacy, security, abusability, and efficiency. We provide a simple OF protocol that achieves most security goals, and which clarifies the essential cryptographic components underlying OF protocols. We also provide a survey of physical layer attacks and usability issues that undermine protections in practice. Finally, we discuss open problems and potential research directions towards secure, interoperable, and abuse-resistant OF systems. Akshaya Kumar, Carolina Ortega Pérez, Joseph Jaeger, Thomas Ristenpart, Michael A. Specter |
Proc. Priv. Enhancing Technol. | 5 |
| 2025 | Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device FingerprintingabstractThis paper presents a large-scale analysis of fingerprinting-like behavior in the mobile application ecosystem. We take a market-based approach, focusing on third-party tracking as enabled by applications' common use of third-party SDKs. Our dataset consists of over 228,000 SDKs from popular Maven repositories, 178,000 Android applications collected from the Google Play store, and our static analysis pipeline detects exfiltration of over 500 individual signals. To the best of our knowledge, this represents the largest-scale analysis of SDK behavior undertaken to date. Michael A. Specter, Mihai Christodorescu, Abbie Farr, Bo Ma 0013, Robin Lassonde |
CCS | 1 |
| 2024 | Cryptography in the Wild: An Empirical Analysis of Vulnerabilities in Cryptographic LibrariesabstractThe security of the Internet and numerous other applications rests on a small number of open-source cryptographic libraries: A vulnerability in any one of them threatens to compromise a significant percentage of web traffic. Despite this potential for security impact, the characteristics and causes of vulnerabilities in cryptographic software are not well understood. In this work, we conduct the first systematic, longitudinal analysis of cryptographic libraries and the vulnerabilities they produce. We collect data from the National Vulnerability Database, individual project repositories and mailing lists, and other relevant sources for all widely used cryptographic libraries. Jenny Blessing, Michael A. Specter, Daniel J. Weitzner |
AsiaCCS | 2 |
| 2021 | Security Analysis of the Democracy Live Online Voting System
Michael A. Specter, J. Alex Halderman |
USENIX Security Symposium | 1 |
| 2021 | KeyForge: Non-Attributable Email from Forward-Forgeable Signatures
Michael A. Specter, Sunoo Park, Matthew Green 0001 |
USENIX Security Symposium | 1 |
| 2020 | The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, the First Internet Voting Application Used in U.S. Federal Elections
Michael A. Specter, James Koppel, Daniel J. Weitzner |
USENIX Security Symposium | 1 |
| 2018 | Explaining Explanations: An Overview of Interpretability of Machine LearningabstractThere has recently been a surge of work in explanatory artificial intelligence (XAI). This research area tackles the important problem that complex machines and algorithms often cannot provide insights into their behavior and thought processes. XAI allows users and parts of the internal system to be more transparent, providing explanations of their decisions in some level of detail. These explanations are important to ensure algorithmic fairness, identify potential bias/problems in the training data, and to ensure that the algorithms perform as expected. However, explanations produced by these systems is neither standardized nor systematically assessed. In an effort to create best practices and identify open challenges, we describe foundational concepts of explainability and show how they can be used to classify existing literature. We discuss why current approaches to explanatory methods especially for deep neural networks are insufficient. Finally, based on our survey, we conclude with suggested future research directions for explanatory artificial intelligence. Leilani H. Gilpin, David Bau, Ben Z. Yuan, Ayesha Bajwa, Michael A. Specter, Lalana Kagal |
DSAA | 5 |