Imane Fouad

dblp:232/2226 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
4since 2021 · last 2025
0009-0006-7613-0428ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2025 FakeZero: Real-Time, Privacy-Preserving Misinformation Detection for Facebook and X
abstract
Social platforms distribute information at unprecedented speed, which in turn accelerates the spread of misinformation and threatens public discourse. We present FakeZero, a fully client-side, cross-platform browser extension that flags unreliable posts on Facebook and X (formerly Twitter) while the user scrolls. All computation, DOM scraping, tokenisation, Transformer inference, and UI rendering run locally through the Chromium messaging API, so no personal data leaves the device.FakeZero employs a three-stage training curriculum: baseline fine-tuning and domain-adaptive training enhanced with focal loss, adversarial augmentation, and post-training quantisation. Evaluated on a dataset of 239 000 posts, the DistilBERT-Quant model (67.6 MB) reaches 97.1 % macro-F1, 97.4 % accuracy, and an AUROC of 0.996, with a median latency of approximately 103 ms on a commodity laptop. A memory-efficient TinyBERT-Quant variant retains 95.7 % macro-F1and 96.1 % accuracy while shrinking the model to 14.7 MB and lowering latency to approximately 40 ms, showing that high-quality fake-news detection is feasible under tight resource budgets with only modest performance loss.By providing inline credibility cues, the extension can serve as a valuable tool for policymakers seeking to curb the spread of misinformation across social networks. With user consent, FakeZero also opens the door for researchers to collect large-scale datasets of fake news in the wild, enabling deeper analysis and the development of more robust detection techniques.
Soufiane Essahli, Oussama Sarsar, Imane Fouad, Ahmed Bentajer, Anas Motii
TrustCom3
2025 Crumbled Cookies: Exploring E-commerce Websites' Cookie Policies with Data Protection Regulations
abstract
Despite stringent data protection regulations, such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other country-specific laws, numerous websites continue to use cookies to track user activities, raising significant privacy concerns. This study aims to investigate the compliance of e-commerce websites with these regulations from a cookie perspective and explore potential variations in cookie policies across different countries. We conducted a comprehensive analysis of 360 popular e-commerce websites (44,323 cookies) across multiple countries, examining cookie attributes and their potential links to privacy and security breaches. Our findings revealed that 73% of third-party cookies function as tracker cookies, with around 40% breaching lifecycle regulations. Additionally, 85% are vulnerable to potential cross-site scripting (XSS) attacks, while only 349 out of 44,323 adhere to robust measures aimed at combating cross-site request forgery (CSRF) attacks. We also discovered instances of masquerading cookies, where third-party cookies disguise themselves as first-party cookies, enabling unauthorized user tracking without consent. To the best of our knowledge, this study is the first to comprehensively analyze the compliance of e-commerce websites with the GDPR, CCPA, and country-specific regulations concerning cookie policies across different jurisdictions. Our findings highlight the urgent need for uniform and consistent cookie policies across websites and jurisdictions, as well as robust enforcement mechanisms and increased transparency to ensure compliance with data protection regulations. This research contributes to the ongoing discourse on privacy protection and underscores the importance of addressing the challenges posed by insecure cookie practices in the e-commerce sector.
Nivedita Singh, Yejin Do, Yongsang Yu, Imane Fouad, Jungrae Kim, Hyoungshick Kim
ACM Trans. Web4
2024 The Devil is in the Details: Detection, Measurement and Lawfulness of Server-Side Tracking on the Web
abstract
As online privacy is cementing itself as one of the core pillars of the Internet, major changes are happening across many industries. On the technological side, users are pushing for more privacy-preserving technologies and rely on browsers and extensions that limit online tracking as much as possible. On the legal front, regulations like GDPR and the ePrivacy Directive in Europe have forced companies to change their practices and be more transparent about how they handle user data. For the ad industry, the end of third-party cookies planned for 2025 is having severe ramifications as the main source of data on which this industry is built on will be gone. In this tumultuous context, companies have come up with innovative ways to overcome current and future restrictions. A novel technique which has not received much attention called Server-side tracking (SST) moves its tracking logic away from the user's device onto an external server. In this work, our aim is to detect SST on the web and understand its lawfulness with respect to current legislation. We developed a methodology that relies on crawls spaced 2 years apart performed before and after the introduction of SST to identify trackers that moved behind SST domains and that are now hidden from view. Our results show that 389, out of 7,367 visited websites, track users behind a cloaked domain and that 28 websites perform Server-side tracking in a first-party capacity. We demonstrate that such a tracking technique can overcome the Same-Origin Policy and introduce security vulnerabilities. Together with a legal scholar, we also show that SST entails non-compliant practices and infringes the GDPR and the ePrivacy Directive.
Imane Fouad, Cristiana Teixeira Santos, Pierre Laperdrix
Proc. Priv. Enhancing Technol.1
2022 My Cookie is a phoenix: detection, measurement, and lawfulness of cookie respawning with browser fingerprinting
abstract
Stateful and stateless web tracking gathered much attention in the last decade, however they were always measured separately. To the best of our knowledge, our study is the first to detect and measure cookie respawning with browser and machine fingerprinting. We develop a detection methodology that allows us to detect cookies dependency on browser and machine features. Our results show that 1, 150 out of the top 30, 000 Alexa websites deploy this tracking mechanism. We find out that this technique can be used to track users across websites even when third-party cookies are deprecated. Together with a legal scholar, we conclude that cookie respawning with browser fingerprinting lacks legal interpretation under the GDPR and the ePrivacy directive, but its use in practice may breach them, thus subjecting it to fines up to 20 million e.
Imane Fouad, Cristiana Teixeira Santos, Arnaud Legout, Nataliia Bielova
Proc. Priv. Enhancing Technol.1
2020 Missed by Filter Lists: Detecting Unknown Third-Party Trackers with Invisible Pixels
abstract
Abstract Web tracking has been extensively studied over the last decade. To detect tracking, previous studies and user tools rely on filter lists. However, it has been shown that filter lists miss trackers. In this paper, we propose an alternative method to detect trackers inspired by analyzing behavior of invisible pixels. By crawling 84,658 webpages from 8,744 domains, we detect that third-party invisible pixels are widely deployed: they are present on more than 94.51% of domains and constitute 35.66% of all third-party images. We propose a fine-grained behavioral classification of tracking based on the analysis of invisible pixels. We use this classification to detect new categories of tracking and uncover new collaborations between domains on the full dataset of 4, 216, 454 third-party requests. We demonstrate that two popular methods to detect tracking, based on EasyList&EasyPrivacy and on Disconnect lists respectively miss 25.22% and 30.34% of the trackers that we detect. Moreover, we find that if we combine all three lists, 379, 245 requests originated from 8,744 domains still track users on 68.70% of websites.
Imane Fouad, Nataliia Bielova, Arnaud Legout, Natasa Sarafijanovic-Djukic
Proc. Priv. Enhancing Technol.1