EDBT 2026 Demo / reviewers in the wild / expert
Faysal Hossain Shezan
dblp:180/3862
· DBLP profile ↗
11ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-1649-0978ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 6 since 2021Computer networks · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Insider's Advantage: Exploiting Automated Privacy Policy Analyzer Tools Through Subtle Text ManipulationsabstractPrivacy policies are essential for communicating data practices to users, despite their dense, complex language, which often obstructs comprehension. Automated Policy Analyzer Tools (APATs) and recent advancements in Large Language Models (LLMs) have made strides in simplifying these documents through features such as question-answering and summarization. However, the robustness of these tools against adversarial manipulations remains less explored. This study examines how subtle, organization-side modifications to policy text can mislead APATs. We present APATRA, a multi-level framework for assessing the robustness of APATs against a range of policy-specific attacks designed to manipulate them into generating misleading outputs. We uncover vulnerabilities that can lead to substantial errors in outputs by applying character-, word-, phrase-, and sentence-level perturbations to policy contexts while preserving the original information. Our evaluation spans policy-specialized models (PolicyQA, PrivBERT), state-of-the-art LLMs (LLama-4-Maverick, GPT-3.5, GPT-4, GPT-5-mini, Claude-3.5, Claude-4.6-Sonnet), and third-party policy analyzer tools (AesirX). To validate the subtlety of our attacks, we conducted an IRB-approved user study with 100 general participants and 10 legal experts specializing in privacy law, who assessed adversarial excerpts for grammaticality, contradictions, and logical flow. Their evaluations demonstrate that our modifications maintain readability and raise no concerns. Overall, our results reveal critical security gaps in APATs and underscore the urgent need to enhance their robustness. Tanusree Das Tithy, Poojitha Thota, Shirin Nilizadeh, Faysal Hossain Shezan |
AsiaCCS | 4 |
| 2026 | Breaking the Illusion: Automated Reasoning of GDPR Consent Violations
Ying Li 0095, Wenjun Qiu, Faysal Hossain Shezan, Kunlin Cai, Michelangelo van Dam, Lisa M. Austin, David Lie, Yuan Tian 0001 |
SP | 3 |
| 2025 | SoK: Towards Effective Automated Vulnerability Repair
Ying Li 0095, Faysal Hossain Shezan, Bomin Wei, Gang Wang 0011, Yuan Tian 0001 |
USENIX Security Symposium | 2 |
| 2024 | Poster: Do Privacy-Preserving Obfuscation Techniques Degrade the Accuracy of Odometry?abstractOn-device sensors in mobile systems, e.g., autonomous vehicles and AR/VR, use odometry for real-time positioning, but they risk capturing sensitive data of non-consenting bystanders. Prior works have investigated various privacy-preserving techniques to protect those sensitive data. However, it is still unclear about the impact of such approaches on the accuracy of odometry. In this work, we investigate the impact of various privacy-preserving obfuscation techniques on the accuracy of monocular visual odometry. We focus on three widely used obfuscation methods: Gaussian Blur, Gaussian Noise, and Laplacian Noise, applied to protect bystander privacy. Our investigation reveals that some obfuscation techniques can increase the odometry errors by up to 56.9%, while others surprisingly reduce the errors by up to 66.8%, compared to raw data. Our key findings indicate that data obfuscation primarily affects the duration of tracking loss in ORB-SLAM3, which is the main source of the errors, and successful relocalization immediately following tracking loss plays a crucial role in reducing the overall errors. Nikolaos Ntokos, Nahin Kumar Dey, Jiayi Meng, Faysal Hossain Shezan |
MobiCom | 4 |
| 2023 | CHKPLUG: Checking GDPR Compliance of WordPress Plugins via Cross-language Code Property Graph
Faysal Hossain Shezan, Zihao Su, Mingqing Kang, Nicholas Phair, Patrick William Thomas, Michelangelo van Dam, Yinzhi Cao, Yuan Tian 0001 |
NDSS | 1 |
| 2023 | Towards Usable Security Analysis Tools for Trigger-Action Programming
McKenna McCall, Eric Zeng 0001, Faysal Hossain Shezan, Mitchell Yang, Lujo Bauer, Abhishek Bichhawat, Camille Cobb, Limin Jia 0001, Yuan Tian 0001 |
SOUPS | 3 |
| 2023 | SenRev: Measurement of Personal Information Disclosure in Online Health CommunitiesabstractWith life style shifting during the pandemic, online health communities start to attract more users (including healthcare workers and patients) to discuss health-related questions. While such online platforms provide convenience to users, with health-related information shared broadly over text and images (e.g., X-Ray scans, photocopies of documents), they also raise questions regarding privacy. In this paper, we propose SenRev to systematically measure the leakages of sensitive information in those publicly available discussions. We use SenRev to analyze 1,894,900 multi-modal and multi-lingual data elements from four different online health communities. We find that sensitive data leakages are common; overall 1,324,064 (69.88%) pieces of evidence of data leakages are detected, with 23,587 (1.78%) of them involving identifiers and 1,300,477 (98.22%) involving quasi-identifiers. Surprisingly, leakages through medical images occur more frequently in the community of healthcare professionals compared with the other communities. Finally, based on our results, we discuss the potential directions for countermeasures. Faysal Hossain Shezan, Minjun Long, David Hasani, Gang Wang 0011, Yuan Tian 0001 |
Proc. Priv. Enhancing Technol. | 1 |
| 2020 | TKPERM: Cross-platform Permission Knowledge Transfer to Detect Overprivileged Third-party Applications
Faysal Hossain Shezan, Kaiming Cheng, Yinzhi Cao, Yuan Tian 0001 |
NDSS | 1 |
| 2020 | Read Between the Lines: An Empirical Measurement of Sensitive Applications of Voice Personal Assistant SystemsabstractVoice Personal Assistant (VPA) systems such as Amazon Alexa and Google Home have been used by tens of millions of households. Recent work demonstrated proof-of-concept attacks against their voice interface to invoke unintended applications or operations. However, there is still a lack of empirical understanding of what type of third-party applications that VPA systems support, and what consequences these attacks may cause. In this paper, we perform an empirical analysis of the third-party applications of Amazon Alexa and Google Home to systematically assess the attack surfaces. A key methodology is to characterize a given application by classifying the sensitive voice commands it accepts. We develop a natural language processing tool that classifies a given voice command from two dimensions: (1) whether the voice command is designed to insert action or retrieve information; (2) whether the command is sensitive or nonsensitive. The tool combines a deep neural network and a keyword-based model, and uses Active Learning to reduce the manual labeling effort. The sensitivity classification is based on a user study (N=404) where we measure the perceived sensitivity of voice commands. A ground-truth evaluation shows that our tool achieves over 95% of accuracy for both types of classifications. We apply this tool to analyze 77,957 Amazon Alexa applications and 4,813 Google Home applications (198,199 voice commands from Amazon Alexa, 13,644 voice commands from Google Home) over two years (2018-2019). In total, we identify 19,263 sensitive “action injection” commands and 5,352 sensitive “information retrieval” commands. These commands are from 4,596 applications (5.55% out of all applications), most of which belong to the “smart home” category. While the percentage of sensitive applications is small, we show the percentage is increasing over time from 2018 to 2019. Faysal Hossain Shezan, Hang Hu 0002, Gang Wang 0011, Yuan Tian 0001 |
WWW | 1 |
| 2017 | Poster: HeartFit: An Intuitive Smartphone Application for Well-being of Hypertensive PatientsabstractHypertension is the single most significant risk factor for heart disease, stroke and kidney disease. The key causes of hypertension can be directly linked to the lifestyle of the patient, including age, family history, smoking, obesity etc. Our work consists of an interactive mobile application that acquires these lifestyle information and use several recommendation techniques to warn and guide the user towards well-being. So far, this is one of the earliest approaches in this domain for a developing country like Bangladesh. Syeda Farzia Afroze, Faysal Hossain Shezan, Sadia Sharmin |
MobiSys | 2 |
| 2016 | Privacy in Repair: An Analysis of the Privacy Challenges Surrounding Broken Digital Artifacts in BangladeshabstractThis paper presents an analysis of the privacy issues associated with the practice of repairing broken digital objects in Bangladesh. Historically, research in Human-Computer Interaction (HCI), Information and Communication Technologies for Development (ICTD), and related disciplines has focused on the design and development of new interventions or technologies. As a result, the repair of old or broken technologies has been an often neglected topic of research. The goal of our work is to improve the practices surrounding the repair of digital artifacts in developing countries. Specifically, in this paper we examine the privacy challenges associated with the process of repairing digital artifacts, which usually requires that the owner of a broken artifact hand over the technology to a repairer. Findings from our ethnographic work conducted at 10 repair markets in Dhaka, Bangladesh, show a variety of ways in which the privacy of an individual's personal data may be compromised during the repair process. We also examine people's perceptions around privacy in repair and its connections with broader social and cultural values. Finally, we discuss the challenges and opportunities for future research to strengthen the repair ecosystem in developing countries. Taken together, our findings contribute to the growing discourse around post-use cycles of technology in ICTD and HCI. Syed Ishtiaque Ahmed, Shion Guha, Md. Rashidujjaman Rifat, Faysal Hossain Shezan, Nicola Dell |
ICTD | 4 |