Nisha Vinayaga-Sureshkanth

dblp:207/7797 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2026
0000-0002-5378-4609ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Linguistic Hooks: Investigating The Role of Language Triggers in Phishing Emails Targeting African Refugees and Students
abstract
Phishing and sophisticated email-based social engineering attacks disproportionately affect vulnerable populations, such as refugees and immigrant students. However, these groups remain understudied in cybersecurity research. This gap in understanding, coupled with their exclusion from broader security and privacy policies, increases their susceptibility to phishing and widens the digital security divide between marginalized and non-marginalized populations. To address this gap, we first conducted digital literacy workshops with newly resettled African refugee populations (n = 48) in the US to improve their understanding of how to safeguard sensitive and private information. Following the workshops, we conducted a real-world phishing deception study using carefully designed emails with linguistic cues for three participant groups: a subset of the African US-refugees recruited from the digital literacy workshops (n = 19), African immigrant students in the US (n = 142), and a control group of monolingual US-born students (n = 184). Our findings indicate that while digital literacy training for refugees improves awareness of safe cybersecurity practices, recently resettled African US-refugees still face significant challenges due to low digital literacy skills and limited English proficiency. This often leads them to ignore or fail to recognize phishing emails as phishing. Both African immigrant students and US-born students showed greater caution, though instances of data disclosure remained prevalent across groups. Our findings highlight, irrespective of literacy, the need to be trained to think critically about digital security. We conclude by discussing how the security and privacy community can better include marginalized populations in policy making and offer recommendations for designing equitable, inclusive cybersecurity initiatives.
Mythili Menon, Nisha Vinayaga-Sureshkanth, Alec Schon, Kaitlyn S. Hemberger, Murtuza Jadliwala
Proc. Priv. Enhancing Technol.2
2025 ScooterID: Posture-Based Continuous User Identification From Mobility Scooter Rides
abstract
Mobility scooters serve as a powerful last-mile transportation tool for people with mobility challenges. Given the unique riding behavior and posture of mobility scooter riders, such user-specific mobility scooter ride data has tremendous potential towards the design of continuous user identification and authentication mechanisms. However, there have been no prior research efforts in the literature exploring this unique modality for the design of continuous user identification techniques. To address this gap, this paper proposesScooterID, the first framework which employs rider posture data collected from cameras on mobility scooters to continuously identify (and authenticate) users/riders. As part of this framework, a machine learning based model comprising of a spatio-temporal Graph Convolutional Network and a body-part-informed encoder is designed to effectively capture a user’s subtle upper-body movements during mobility scooter rides into discriminating embedding vectors. These embeddings can then be used to reliably and continuously identify and authenticate users/riders. Experiments with real-world mobility scooter ride data show thatScooterIDachieves high levels of authentication accuracy with few enrollment video samples.ScooterIDalso performs efficiently on resource-constrained devices (e.g., Raspberry Pis) and is robust against adversarial perturbations to authentication inputs.
Devan Shah, Ruoqi Huang, Nisha Vinayaga-Sureshkanth, Tingting Chen 0001, Murtuza Jadliwala
IEEE Trans. Mob. Comput.3
2024 De-anonymizing VR Avatars using Non-VR Motion Side-channels
abstract
Virtual Reality (VR) technology offers an immersive audio-visual experience to users through which they can interact with a digitally represented 3D space (i.e., a virtual world) using a headset device. By (visually) transporting users from their physical world to realistic virtual spaces, VR systems enable interactive and true-to-life versions of traditional applications such as gaming, remote conferencing and virtual tourism. However, VR applications also present significant user-privacy challenges. This paper studies a new type of privacy threat targeting VR users which attempts to connect their activities visible in the virtual world to their physical state sensed in the real world. Specifically, this paper analyzes the feasibility of carrying out a de-anonymization or identification attack on VR users by correlating visually observed movements of users' avatars in the virtual world with some auxiliary data (e.g., motion sensor data from mobile/wearable devices) representing their context/state in the physical world. To enable this attack, the paper proposes a novel framework which first employs a learning-based activity classification approach to translate the disparate visual movement data and motion sensor data into an activity-vector to ease comparison, followed by a filtering and identity ranking phase outputting an ordered list of potential identities corresponding to the target visual movement data. A comprehensive empirical evaluation of the proposed framework is conducted to study the feasibility of such a de-anonymization attack.
Mohd Sabra, Nisha Vinayaga-Sureshkanth, Ari Sharma, Anindya Maiti, Murtuza Jadliwala
WISEC2
2022 An Investigative Study on the Privacy Implications of Mobile E-scooter Rental Apps
abstract
E-scooter rental services have significantly expanded the micromobility paradigm of short-distance urban and suburban transportation since their inception in 2017. Service providers around the world have followed a common rental model wherein customers (i.e., riders or users) download and install a mobile application for locating (finding) and renting e-scooters. Unlike many other app categories, e-scooter rental apps require a set of privacy-sensitive user data as a functional requirement. Unfortunately, privacy-related questions such as how much user data is being collected by these apps, is user data being safely handled once acquired, and with whom the collected user data is being shared are not readily known to customers. Answering such questions can be critical for users in determining which e-scooter rental services are sufficiently trustworthy per their personal privacy preferences. In this paper, we conduct a comprehensive analysis of e-scooter rental apps to answer these and other research questions related to user data collection, third-party involvement, usefulness of privacy policies, and evolution of user data management by different e-scooter apps/services over time. Our findings will create awareness among consumers vis-à-vis the data they share with service providers in return for the received e-scooter rental service, and it can also evoke more accountability and transparency from service providers towards their efforts and processes on protecting consumer privacy.
Nisha Vinayaga-Sureshkanth, Raveen Wijewickrama, Anindya Maiti, Murtuza Jadliwala
WISEC1