EDBT 2026 Demo / reviewers in the wild / expert
Alice Hutchings
dblp:181/3695
· DBLP profile ↗
19ranked-venue papers
1as first author
12since 2021 · last 2026
0000-0003-3037-2684ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 1 first-author · 9 since 2021Computer networks · 4Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | iOSModZoo: A Large-Scale Study of Third-Party iOS App Markets
Luis Adan Saavedra, Hridoy Sankar Dutta, Alastair R. Beresford, Alice Hutchings |
WISEC | 4 |
| 2025 | App-solutely Modded: Surveying Modded App Market Operators and Original App DevelopersabstractApp-solutely Modded: Surveying Modded App Market Operators and Original App Developers Luis Adan Saavedra, Hridoy Sankar Dutta, Alastair R. Beresford, Alice Hutchings |
AsiaCCS | 4 |
| 2025 | Spy-oT: Understanding How Users Learn to Use Internet of Things Devices For Abusive Purposes
Kieron Ivy Turk, Alice Hutchings |
SOUPS | 2 |
| 2025 | SoK: Digging into the Digital Underworld of Stolen Data MarketsabstractOver the past few decades, the issue of stolen data has expanded from a nuisance caused by few opportunistic individuals to a thriving, highly organised, and profitable economy. As such, it spawned a thread of research trying to document and understand the underground economy. We look back at the past 15 years of research on stolen data markets to uncover the underlying patterns and trends, documented by researchers. We examine the economy and find a changing landscape, both in terms of popular stolen data types as well as the platforms housing the marketplaces. Additionally, we record a consistent decrease in market lifespans and as well as observation periods. We highlight a number of research patterns and potential shortcomings, in particular the low coverage of markets included in research and the low diversity of languages featured in the marketplaces. Finally, we propose a number of directions for future research to better understand the true cost of the economy and the mismatch between data breaches and data appearing on markets. Future research will also need to stay on top of the changing landscape and focus on timely identification of new trends and community movements across platforms. Tina Marjanov, Alice Hutchings |
SP | 2 |
| 2025 | Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services
Anh V. Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton 0001, Alice Hutchings |
USENIX Security Symposium | 6 |
| 2024 | Investigating Wrench Attacks: Physical Attacks Targeting Cryptocurrency Users
Marilyne Ordekian, Gilberto Atondo Siu, Alice Hutchings, Marie Vasek |
AFT | 3 |
| 2024 | No Easy Way Out: the Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and HarassmentabstractLegislators and policymakers worldwide are debating options for suppressing illegal, harmful and undesirable material online. Drawing on several quantitative data sources, we show that deplatforming an active community to suppress online hate and harassment, even with a substantial concerted effort involving several tech firms, can be hard. Our case study is the disruption of the largest and longest-running harassment forum Kiwi Farms in late 2022, which is probably the most extensive industry effort to date. Despite the active participation of a number of tech companies over several consecutive months, this campaign failed to shut down the forum and remove its objectionable content. While briefly raising public awareness, it led to rapid platform displacement and traffic fragmentation. Part of the activity decamped to Telegram, while traffic shifted from the primary domain to previously abandoned alternatives. The forum experienced intermittent outages for several weeks, after which the community leading the campaign lost interest, traffic was directed back to the main domain, users quickly returned, and the forum was back online and became even more connected. The forum members themselves stopped discussing the incident shortly thereafter, and the net effect was that forum activity, active users, threads, posts and traffic were all cut by about half. The disruption largely affected casual users (of whom roughly 87% left), while half the core members remained engaged. It also drew many newcomers, who exhibited increasing levels of toxicity during the first few weeks of participation. Deplatforming a community without a court order raises philosophical issues about censorship versus free speech; ethical and legal issues about the role of industry in online content moderation; and practical issues on the efficacy of private-sector versus government action. Deplatforming a dispersed community using a series of court orders against individual service providers appears unlikely to be very effective if the censor cannot incapacitate the key maintainers, whether by arresting them, enjoining them or otherwise deterring them. Anh V. Vu, Alice Hutchings, Ross J. Anderson |
SP | 2 |
| 2024 | Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine ConflictabstractThere has been substantial commentary on the role of cyberattacks carried out by low-level cybercrime actors in the Russia-Ukraine conflict. We analyse 358k website defacement attacks, 1.7M UDP amplification DDoS attacks, 1764 posts made by 372 users on Hack Forums mentioning the two countries, and 441 Telegram announcements (with 58k replies) of a volunteer hacking group for two months before and four months after the invasion. We find the conflict briefly but notably caught the attention of low-level cybercrime actors, with significant increases in online discussion and both types of attacks targeting Russia and Ukraine. However, there was little evidence of high-profile actions; the role of these players in the ongoing hybrid warfare is minor, and they should be separated from persistent and motivated 'hacktivists' in state-sponsored operations. Their involvement in the conflict appears to have been short-lived and fleeting, with a clear loss of interest in discussing the situation and carrying out both website defacement and DDoS attacks against either Russia or Ukraine after just a few weeks. Anh V. Vu, Daniel R. Thomas, Ben Collier, Alice Hutchings, Richard Clayton 0001, Ross J. Anderson |
WWW | 4 |
| 2023 | Click Here to Exit: An Evaluation of Quick Exit ButtonsabstractAccessing online support services can be dangerous for some users, such as domestic abuse survivors. Many support service websites contain “quick exit” buttons that provide an easy way for users to escape the site. We investigate where exit buttons and other escape mechanisms are currently in use (country and type of site) and how they are implemented. We analyse both the security and usability of exit mechanisms on 323 mobile and 404 desktop sites. We find exit buttons typically replace the current page with another site, occasionally opening additional tabs. Some exit buttons also remove the page from the browser history. When analysing the design choices and shortcomings of exit button implementations, common problems include cookie notices covering the buttons, and buttons not remaining on the screen when scrolling. We provide recommendations for designers of support websites who want to add or improve this feature on their website. Kieron Ivy Turk, Alice Hutchings |
CHI | 2 |
| 2023 | Short Paper: DeFi Deception - Uncovering the Prevalence of Rugpulls in Cryptocurrency Projects
Sharad Agarwal, Gilberto Atondo Siu, Marilyne Ordekian, Alice Hutchings, Enrico Mariconti, Marie Vasek |
FC (1) | 4 |
| 2023 | Automated hate speech detection and span extraction in underground hacking and extremist forumsabstractAbstract Hate speech is any kind of communication that attacks a person or a group based on their characteristics, such as gender, religion and race. Due to the availability of online platforms where people can express their (hateful) opinions, the amount of hate speech is steadily increasing that often leads to offline hate crimes. This paper focuses on understanding and detecting hate speech in underground hacking and extremist forums where cybercriminals and extremists, respectively, communicate with each other, and some of them are associated with criminal activity. Moreover, due to the lengthy posts, it would be beneficial to identify the specific span of text containing hateful content in order to assist site moderators with the removal of hate speech. This paper describes a hate speech dataset composed of posts extracted from HackForums, an online hacking forum, and Stormfront and Incels.co, two extremist forums. We combined our dataset with a Twitter hate speech dataset to train a multi-platform classifier. Our evaluation shows that a classifier trained on multiple sources of data does not always improve the performance compared to a mono-platform classifier. Finally, this is the first work on extracting hate speech spans from longer texts. The paper fine-tunes BERT (Bidirectional Encoder Representations from Transformers) and adopts two approaches – span prediction and sequence labelling. Both approaches successfully extract hateful spans and achieve an F1-score of at least 69%. Linda Zhou, Andrew Caines, Ildiko Pete, Alice Hutchings |
Nat. Lang. Eng. | 4 |
| 2023 | A Graph-Based Stratified Sampling Methodology for the Analysis of (Underground) ForumsabstractResearchers analyze underground forums to study abuse and cybercrime activities. Due to the size of the forums and the domain expertise required to identify criminal discussions, most approaches employ supervised machine learning techniques to automatically classify the posts of interest. Human annotation is costly. How to select samples to annotate that account for the structure of the forum? We present a methodology to generate stratified samples based on information about the centrality properties of the population and evaluate classifier performance. We observe that by employing a sample obtained from a uniform distribution of the post degree centrality metric, we maintain the same level of precision but significantly increase the recall (+30%) compared to a sample whose distribution is respecting the population stratification. We find that classifiers trained with similar samples disagree on the classification of criminal activities up to 33% of the time when deployed on the entire forum. Giorgio Di Tizio, Gilberto Atondo Siu, Alice Hutchings, Fabio Massacci |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Turning Up the Dial: the Evolution of a Cybercrime Market Through Set-up, Stable, and Covid-19 ErasabstractTrust and reputation play a core role in underground cybercrime markets, where participants are anonymous and there is little legal recourse for dispute arbitration. These underground markets exist in tension between two opposing forces: the drive to hide incriminating information, and the trust and stability benefits that greater openness yields. Revealing information about transactions to mitigate scams also provides valuable data about the market. We analyse the first dataset, of which we are aware, about the transactions created and completed on a well-known and high-traffic underground marketplace, Hack Forums, along with the associated threads and posts made by its users over two recent years, from June 2018 to June 2020. We use statistical modelling approaches to analyse the economic and social characteristics of the market over three eras, especially its performance as an infrastructure for trust. In the Set-up era, we observe the growth of users making only one transaction, as well as 'power-users' who make many transactions. In the Stable era, we observe a wide range of activities (including large-scale transfers of intermediate currencies such as Amazon Giftcards) which declines slowly from an initial peak. Finally, we analyse the effects of the Covid-19 pandemic, concluding that while we see a significant increase in transactins across all categories, this reflects a stimulus of the market, rather than a transformation. New users overcome the 'cold start' problem by engaging in low-level currency exchanges to prove their trustworthiness. We observe currency exchange accounts for most contracts, and Bitcoin and PayPal are the preferred payment methods by trading values and number of contracts involved. The market is becoming more centralised over time around influential users and threads, with significant changes observed during the Set-up and Covid-19 eras. Anh V. Vu, Jack Hughes 0001, Ildiko Pete, Ben Collier, Yi Ting Chua 0001, Ilia Shumailov, Alice Hutchings |
Internet Measurement Conference | 7 |
| 2019 | Understanding eWhoringabstractIn this paper, we describe a new type of online fraud, referred to as 'eWhoring' by offenders. This crime script analysis provides an overview of the 'eWhoring' business model, drawing on more than 6,500 posts crawled from an online underground forum. This is an unusual fraud type, in that offenders readily share information about how it is committed in a way that is almost prescriptive. There are economic factors at play here, as providing information about how to make money from 'eWhoring' can increase the demand for the types of images that enable it to happen. We find that sexualised images are typically stolen and shared online. While some images are shared for free, these can quickly become 'saturated', leading to the demand for (and trade in) more exclusive 'packs'. These images are then sold to unwitting customers who believe they have paid for a virtual sexual encounter. A variety of online services are used for carrying out this fraud type, including email, video, dating sites, social media, classified advertisements, and payment platforms. This analysis reveals potential interventions that could be applied to each stage of the crime commission process to prevent and disrupt this crime type. Alice Hutchings, Sergio Pastrana |
EuroS&P | 1 |
| 2019 | Booting the Booters: Evaluating the Effects of Police Interventions in the Market for Denial-of-Service AttacksabstractIllegal booter services offer denial of service (DoS) attacks for a fee of a few tens of dollars a month. Internationally, police have implemented a range of different types of intervention aimed at those using and offering booter services, including arrests and website takedown. In order to measure the impact of these interventions we look at the usage reports that booters themselves provide and at measurements of reflected UDP DoS attacks, leveraging a five year measurement dataset that has been statistically demonstrated to have very high coverage. We analysed time series data (using a negative binomial regression model) to show that several interventions have had a statistically significant impact on the number of attacks. We show that, while there is no consistent effect of highly-publicised court cases, takedowns of individual booters precede significant, but short-lived, reductions in recorded attack numbers. However, more wide-ranging disruptions have much longer effects. The closure of HackForums' booter market reduced attacks for 13 weeks globally (and for longer in particular countries) and the FBI's coordinated operation in December 2018, which involved both takedowns and arrests, reduced attacks by a third for at least 10 weeks and resulted in lasting change to the structure of the booter market. Ben Collier, Daniel R. Thomas, Richard Clayton 0001, Alice Hutchings |
Internet Measurement Conference | 4 |
| 2019 | Measuring eWhoringabstracteWhoring is the term used by offenders to refer to a type of online fraud in which cybersexual encounters are simulated for financial gain. Perpetrators use social engineering techniques to impersonate young women in online communities, e.g., chat or social networking sites. They engage potential customers in conversation with the aim of selling misleading sexual material -- mostly photographs and interactive video shows -- illicitly compiled from third-party sites. eWhoring is a popular topic in underground communities, with forums acting as a gateway into offending. Users not only share knowledge and tutorials, but also trade in goods and services, such as packs of images and videos. In this paper, we present a processing pipeline to quantitatively analyse various aspects of eWhoring. Our pipeline integrates multiple tools to crawl, annotate, and classify material in a semi-automatic way. It builds in precautions to safeguard against significant ethical issues, such as avoiding the researchers' exposure to pornographic material, and legal concerns, which were justified as some of the images were classified as child exploitation material. We use it to perform a longitudinal measurement of eWhoring activities in 10 specialised underground forums from 2008 to 2019. Our study focuses on three of the main eWhoring components: (i) the acquisition and provenance of images; (ii) the financial profits and monetisation techniques; and (iii) a social network analysis of the offenders, including their relationships, interests, and pathways before and after engaging in this fraudulent activity. We provide recommendations, including potential intervention approaches. Sergio Pastrana, Alice Hutchings, Daniel R. Thomas, Juan Tapiador |
Internet Measurement Conference | 2 |
| 2018 | Characterizing Eve: Analysing Cybercrime Actors in a Large Underground Forum
Sergio Pastrana, Alice Hutchings, Andrew Caines, Paula Buttery |
RAID | 2 |
| 2018 | CrimeBB: Enabling Cybercrime Research on Underground Forums at ScaleabstractUnderground forums allow criminals to interact, exchange knowledge, and trade in products and services. They also provide a pathway into cybercrime, tempting the curious to join those already motivated to obtain easy money. Analysing these forums enables us to better understand the behaviours of offenders and pathways into crime. Prior research has been valuable, but limited by a reliance on datasets that are incomplete or outdated. More complete data, going back many years, allows for comprehensive research into the evolution of forums and their users. We describe CrimeBot, a crawler designed around the particular challenges of capturing data from underground forums. CrimeBot is used to update and maintain CrimeBB, a dataset of more than 48m posts made from 1m accounts in 4 different operational forums over a decade. This dataset presents a new opportunity for large-scale and longitudinal analysis using up-to-date information. We illustrate the potential by presenting a case study using CrimeBB, which analyses which activities lead new actors into engagement with cybercrime. CrimeBB is available to other academic researchers under a legal agreement, designed to prevent misuse and provide safeguards for ethical research. Sergio Pastrana, Daniel R. Thomas, Alice Hutchings, Richard Clayton 0001 |
WWW | 3 |
| 2017 | Ethical issues in research using datasets of illicit originabstractWe evaluate the use of data obtained by illicit means against a broad set of ethical and legal issues. Our analysis covers both the direct collection, and secondary uses of, data obtained via illicit means such as exploiting a vulnerability, or unauthorized disclosure. We extract ethical principles from existing advice and guidance and analyse how they have been applied within more than 20 recent peer reviewed papers that deal with illicitly obtained datasets. We find that existing advice and guidance does not address all of the problems that researchers have faced and explain how the papers tackle ethical issues inconsistently, and sometimes not at all. Our analysis reveals not only a lack of application of safeguards but also that legitimate ethical justifications for research are being overlooked. In many cases positive benefits, as well as potential harms, remain entirely unidentified. Few papers record explicit Research Ethics Board (REB) approval for the activity that is described and the justifications given for exemption suggest deficiencies in the REB process. Daniel R. Thomas, Sergio Pastrana, Alice Hutchings, Richard Clayton 0001, Alastair R. Beresford |
Internet Measurement Conference | 3 |