EDBT 2026 Demo / reviewers in the wild / expert
Zengrui Liu
dblp:280/8292
· DBLP profile ↗
5ranked-venue papers
4as first author
4since 2021 · last 2025
0000-0002-7936-8435ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The First Early Evidence of the Use of Browser Fingerprinting for Online TrackingabstractWhile advertising has become commonplace in today's online interactions, there is a notable dearth of research investigating the extent to which browser fingerprinting is harnessed for user tracking and targeted advertising. Prior studies only measured whether fingerprinting-related scripts are being run on the websites but that in itself does not necessarily mean that fingerprinting is being used for the privacy-invasive purpose of online tracking because fingerprinting might be deployed for the defensive purposes of bot/fraud detection and user authentication. It is imperative to address the mounting concerns regarding the utilization of browser fingerprinting in the realm of online advertising. Zengrui Liu, Jimmy Dani, Yinzhi Cao, Shujiang Wu, Nitesh Saxena |
WWW | 1 |
| 2024 | Dual Study of Canvas Fingerprinting Based Authentication: A Novel Spoofing Attack and the CountermeasureabstractBrowser fingerprinting is a tracking technique used to distinguish individual users. By leveraging unique fingerprint features or combining multiple ones, websites can not only identify users but also monitor their online activities. A specific aspect of browser fingerprinting, known as canvas fingerprinting, generates distinct values based on the characteristics of users' devices. This unique trait of canvas browser fingerprinting can be employed in challenge-response authentication, enabling user verification without requiring additional actions and potentially replacing the need for two-factor authentication. Furthermore, canvas fingerprinting can serve as an alternative to cookies, facilitating functionalities like the “Remember me” feature. This paper introduces an implementation of man-in-the-middle attack called “CRSlash” that targets prevalent challenge-response authentication methods, with a particular focus on canvas finger-printing based challenge-response authentication. In the case of CRSlash, an attacker only needs to obtain a challenge from the targeted device once. Subsequently, they can successfully navigate the authentication process. Our investigation reveals that existing challenge-response authentication methods relying on canvas fingerprinting are vulnerable to this attack. This vulnerability persists in both one-time authentication scenarios and continuous authentication setups. The outcomes of the attack demonstrate that prior canvas authentication methods are inadequate in countering this new threat. In response to this security concern, we propose a novel approach to canvas fingerprinting-based challenge-response authentication, which we call “CanvasDict.” In the CanvasDict process, the website creates a distinct authentication dictionary using the user's browser fingerprint during the registration phase. Later, during the login phase, the website selects random challenges from this dictionary for the authentication process. Through in-depth analysis, we ascertain the effectiveness of our approach in thwarting the aforementioned attack. Our evaluation encompasses two modes of CanvasDict, and the results underscore the success of CanvasDict in neutralizing the potential risks posed by the attack. This paper highlights the significance of browser fingerprinting, specifically focusing on canvas fingerprinting, as a means of user tracking and authentication. It sheds light on the vulnerabilities of existing challenge-response authentication methods and proposes an innovative solution to bolster security in the realm of canvas fingerprinting-based authentication. Zengrui Liu, Nitesh Saxena |
ICDCS | 1 |
| 2024 | Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?abstractData protection regulations, such as GDPR and CCPA, require websites and embedded third-parties, especially advertisers, to seek user consent before they can collect and process user data. Only when the users opt in, should these entities collect, process, and share user data. Websites typically incorporate Consent Management Platforms (CMPs), such as OneTrust and CookieBot, to solicit and convey user consent to the embedded advertisers, with the expectation that the consent will be respected. However, neither the websites nor the regulators currently have any mechanism to audit advertisers' compliance with the user consent, i.e., to determine if advertisers indeed do not collect, process, and share user data when the user opts out. In this paper, we propose an auditing framework that leverages advertisers' bidding behavior to empirically assess the violations of data protection regulations. Using our framework, we conduct a measurement study to evaluate four of the most widely deployed CMPs, i.e., Didomi, Quantcast, OneTrust, and CookieBot, as well as advertiser-offered opt-out controls, i.e., National Advertising Initiative's opt-out, under GDPR and CCPA. Our results indicate that in many cases user data is unfortunately still being collected, processed, and shared even when users opt-out. We also find that some CMPs are better than the others at conveying user consent and that several ad platforms ignore user consent. Our results also indicate that advertiser-offered opt-out are equally ineffective at protecting user privacy. Zengrui Liu, Umar Iqbal 0002, Nitesh Saxena |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | Gummy Browsers: Targeted Browser Spoofing Against State-of-the-Art Fingerprinting Techniques
Zengrui Liu, Prakash Shrestha, Nitesh Saxena |
ACNS | 1 |
| 2020 | IvoriWatch: Exploring Transparent Integrity Verification of Remote User Input Leveraging WearablesabstractSeveral sensitive operations, such as financial transactions, email construction, configurations of safety-critical devices (e.g., medical devices or smart home systems), are often performed via web interfaces from a host machine, usually a desktop or laptop PC. It is typically easy to secure the communication link between the local host machine and the remote server, for example, via a standard cryptographic protocol (e.g., TLS). However, if the host machine itself is compromised with a trojan or malware, the malicious adversary can manipulate the user-provided input (e.g., money transfer information, email content and configuration data) that can lead to severe consequences, including financial loss, damage of reputation, security breach, and even put human lives in danger. Prakash Shrestha, Zengrui Liu, Nitesh Saxena |
ACSAC | 2 |