Ania M. Piotrowska

dblp:178/2737 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
2since 2021 · last 2026
0000-0002-7438-0152ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Website fingerprinting on Nym: Attacks and Defenses
abstract
Website fingerprinting (WF) enables a passive eavesdropper to infer which web page a client is visiting, even when communications are encrypted or anonymized. In this paper, we study the vulnerability to website fingerprinting of Nym, a mix network based on the Loopix design that enables users to browse the Web. We show that although Nym adds delays and cover traffic to change packet patterns compared to Tor, it still leaks features that website fingerprinting attacks can exploit in both closed‑ and open‑world settings. We carry out an in-depth analysis of the effectiveness of Nym's obfuscation mechanisms, originally designed to provide anonymity in messaging, in thwarting website fingerprinting. We show that mix delays, counterintuitively, not only fail to protect against website fingerprinting but actually make the attack more effective as the mix delays make it easier to distinguish incoming from outgoing packets. We also demonstrate that the current cover traffic strategy of Nym is not effective in thwarting website fingerprinting attacks unless it imposes a large overhead. To address these limitations, we design two new WF defenses based on Nym's existing obfuscation mechanisms that significantly reduce WF effectiveness. The first defense introduces cover traffic to match the bursty nature of real-world web traffic, reducing the F1 score to 0.39 (compared to 0.65 obtained by similar defenses applied on Tor) at moderate overhead increase. The second defense plummets the F1 score to 0.06 by channeling web traffic via Nym's constant traffic capabilities, at the cost of bandwidth.
Eric Jollès, Simon Wicky, Ania M. Piotrowska, Harry Halpin, Carmela Troncoso
Proc. Priv. Enhancing Technol.3
2023 Compact and Divisible E-Cash with Threshold Issuance
abstract
Decentralized, offline, and privacy-preserving e-cash could fulfil the need for both scalable and byzantine fault-resistant payment systems. Existing offline anonymous e-cash schemes are unsuitable for distributed environments due to a central bank. We construct a distributed offline anonymous e-cash scheme, in which the role of the bank is performed by a quorum of authorities, and present its two instantiations. Our first scheme is compact, i.e. the cost of the issuance protocol and the size of a wallet are independent of the number of coins issued, but the cost of payment grows linearly with the number of coins spent. Our second scheme is divisible and thus the cost of payments is also independent of the number of coins spent, but the verification of deposits is more costly. We provide formal security proof of both schemes and compare the efficiency of their implementations.
Alfredo Rial, Ania M. Piotrowska
Proc. Priv. Enhancing Technol.2
2019 No Right to Remain Silent: Isolating Malicious Mixes
Hemi Leibowitz, Ania M. Piotrowska, George Danezis, Amir Herzberg
USENIX Security Symposium2
2018 Light-weight and secure aggregation protocols based on Bloom filters✰
Marek Klonowski, Ania M. Piotrowska
Comput. Secur.2
2017 The Loopix Anonymity System
Ania M. Piotrowska, Jamie Hayes, Tariq Elahi, Sebastian Meiser 0001, George Danezis
USENIX Security Symposium1