EDBT 2026 Demo / reviewers in the wild / expert
F. Betül Durak
dblp:187/0789
· DBLP profile ↗
13ranked-venue papers
8as first author
6since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 8 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ACM CCS Young Scholars Development ProgramabstractIn this short document, we introduce The ACM CCS Young Scholars Development Program (YSDP); a new initiative aiming at supporting early-career researchers within the computer security community. YSDP is created and organized by dedicated chairs. The program promotes collaboration, communication, and professional growth through structured events such as talks, panels, and breakout technical discussions sessions. It emphasizes skill-building and networking, with a focus on integrating young scholars into the broader academic ecosystem. In this report, we detail the planning, selection, and execution of the program, and highlight its role in shaping a stronger research environment. F. Betül Durak, Fengjun Li, Sophie Stephenson |
CCS | 1 |
| 2025 | Sandi: A System for AccountabilityabstractWe present a system, Sandi, for creating trust through accountability. Concretely, we focus on online communication scenarios, where the communicating parties do not know each other, yet would benefit from a degree of initial trust. Sandi can be seen as a reputation system that measures bad behavior, with strong integrity protections and resistance to manipulation. Unlike most reputation systems, Sandi is entirely based on "downvotes" and therefore requires strong privacy guarantees to prevent retaliation. It utilizes a ticket-based reporting mechanism to limit who can report. We also prove that Sandi incentivizes good behavior in a well-defined sense.Sandi is by design unidirectional, so that message senders have Sandi scores and receivers can report them for inappropriate communication, but it is designed to benefit both senders and receivers. Senders benefit, as receivers are more likely to react to communication with the added trust signal. Receivers benefit from seeing senders’ scores, allowing them to make more informed decisions about which senders to trust.Receivers do not need registered accounts and neither senders nor receivers need long-term keys. Sandi guarantees score integrity, communication privacy, reporter privacy to protect reporting receivers, and sender unlinkability. Sandi can be implemented on top of any communication system that allows for small binary data transfer. F. Betül Durak, Kim Laine, Simon Langowski, Radames Cruz Moreno |
EuroS&P | 1 |
| 2024 | Precio: Private Aggregate Measurement via Oblivious ShufflingabstractWe introduce Precio, a new secure aggregation method for computing layered histograms and sums over secret shared data in a client-server setting. Precio is motivated by ad conversion measurement scenarios, where online advertisers and ad networks want to measure the performance of ad campaigns without requiring privacy-invasive techniques, such as third-party cookies. Erik Anderson, Melissa Chase, F. Betül Durak, Kim Laine, Chenkai Weng |
CCS | 3 |
| 2024 | Non-Transferable Anonymous Tokens by Secret BindingabstractNon-transferability (NT) is a security notion which ensures that credentials are only used by their intended owners. Despite its importance, it has not been formally treated in the context of anonymous tokens (AT) which are lightweight anonymous credentials. In this work, we consider a client who "buys" access tokens which are forbidden to be transferred although anonymously redeemed. We extensively study the trade-offs between privacy (obtained through anonymity) and security in AT through the notion of non-transferability. We formalise new security notions, design a suite of protocols with various flavors of NT, prove their security, and implement the protocols to assess their efficiency. Finally, we study the existing anonymous credentials which offer NT, and show that they cannot automatically be used as AT without security and complexity implications. F. Betül Durak, Laurane Marco, Abdullah Talayhan, Serge Vaudenay |
CCS | 1 |
| 2023 | Anonymous Tokens with Stronger Metadata Bit Hiding from Algebraic MACs
Melissa Chase, F. Betül Durak, Serge Vaudenay |
CRYPTO (2) | 2 |
| 2021 | FAST: Secure and High Performance Format-Preserving Encryption and Tokenization
F. Betül Durak, Henning Horst, Michael Horst, Serge Vaudenay |
ASIACRYPT (3) | 1 |
| 2020 | \(\mathsf {BioLocker}\): A Practical Biometric Authentication Mechanism Based on 3D Fingervein
F. Betül Durak, Loïs Huguenin-Dumittan, Serge Vaudenay |
ACNS (2) | 1 |
| 2019 | Misuse Attacks on Post-quantum Cryptosystems
Ciprian Baetu, F. Betül Durak, Loïs Huguenin-Dumittan, Abdullah Talayhan, Serge Vaudenay |
EUROCRYPT (2) | 2 |
| 2019 | A multi-server oblivious dynamic searchable encryption frameworkabstractData privacy is one of the main concerns for data outsourcing on the cloud. Although standard encryption can provide confidentiality, it prevents the client from searching/retrieving meaningful information on the outsourced data thereby, degrading the benefits of using cloud services. To address this data utilization versus privacy dilemma, Dynamic Searchable Symmetric Encryption (DSSE) has been proposed. DSSE enables encrypted search and update functionality over the encrypted data via a secure index. However, the state-of-the-art DSSE constructions leak information from the access pattern, making them vulnerable against various attacks. While generic Oblivious Random Access Machine (ORAM) can hide the access pattern, it incurs a heavy communication overhead, which was shown costly to be directly used in the DSSE setting. In this article, by exploiting the multi-cloud infrastructure, we develop a comprehensive Oblivious Distributed DSSE (ODSE) framework that allows oblivious search and updates on the encrypted index with high security and improved efficiency over the use of generic ORAM. Our framework contains a series of [Formula: see text] schemes each featuring different levels of performance and security required by various types of real-life applications. ODSE offers desirable security guarantees such as information-theoretic security and robustness in the presence of a malicious adversary. We fully implemented [Formula: see text] framework and evaluated its performance in a real cloud environment (Amazon EC2). Our experiments showed that ODSE schemes are [Formula: see text]-[Formula: see text] faster than using generic ORAMs on a DSSE encrypted index under real network settings. Thang Hoang, Attila A. Yavuz, F. Betül Durak, Jorge Guajardo |
J. Comput. Secur. | 3 |
| 2018 | Generic Round-Function-Recovery Attacks for Feistel Networks over Small Domains
F. Betül Durak, Serge Vaudenay |
ACNS | 1 |
| 2018 | Oblivious Dynamic Searchable Encryption on Distributed Cloud Systems
Thang Hoang, Attila A. Yavuz, F. Betül Durak, Jorge Guajardo |
DBSec | 3 |
| 2017 | Breaking the FF3 Format-Preserving Encryption Standard over Small Domains
F. Betül Durak, Serge Vaudenay |
CRYPTO (2) | 1 |
| 2016 | What Else is Revealed by Order-Revealing Encryption?abstractThe security of order-revealing encryption (ORE) has been unclear since its invention. Dataset characteristics for which ORE is especially insecure have been identified, such as small message spaces and low-entropy distributions. On the other hand, properties like one-wayness on uniformly-distributed datasets have been proved for ORE constructions. F. Betül Durak, Thomas DuBuisson, David Cash |
CCS | 1 |