Thomas Cory

dblp:285/3298 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
3since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2026 SoK: After Decades of Web Tracker Detection, What's Next?
Wolf Rieder, Philip Raschke, Thomas Cory, Christian René Sechting, Axel Küpper
SP3
2026 Word-level Annotation of GDPR Transparency Compliance in Privacy Policies using Large Language Models
abstract
Ensuring transparency of data practices related to personal information is a core requirement of the General Data Protection Regulation (GDPR). However, large-scale compliance assessment remains challenging due to the complexity and diversity of privacy policy language. Manual audits are labour-intensive and inconsistent, while current automated methods often lack the granularity required to capture nuanced transparency disclosures. In this paper, we present a modular large language model (LLM)-based pipeline for fine-grained word-level annotation of privacy policies with respect to GDPR transparency requirements. Our approach integrates LLM-driven annotation with passage-level classification, retrieval-augmented generation, and a self-correction mechanism to deliver scalable, context-aware annotations across 21 GDPR-derived transparency requirements. To support empirical evaluation, we compile a corpus of 703,791 English-language privacy policies and generate a ground-truth sample of 200 manually annotated policies based on a comprehensive, GDPR-aligned annotation scheme. We propose a two-tiered evaluation methodology capturing both passage-level classification and span-level annotation quality and conduct a comparative analysis of seven state-of-the-art LLMs on two annotation schemes, including the widely used OPP-115 dataset. The results of our evaluation show that decomposing the annotation task and integrating targeted retrieval and classification components significantly improve annotation accuracy, particularly for well-structured requirements. Our work provides new empirical resources and methodological foundations for advancing automated transparency compliance assessment at scale.
Thomas Cory, Wolf Rieder, Julia Krämer, Philip Raschke, Patrick Herbke, Axel Küpper
Proc. Priv. Enhancing Technol.1
2025 Beyond the Request: Harnessing HTTP Response Headers for Cross-Browser Web Tracker Detection in an Imbalanced Setting
abstract
The World Wide Web's connectivity is greatly attributed to the HTTP protocol, with HTTP messages offering informative header fields that appeal to disciplines like web security and privacy, especially concerning web tracking. Despite existing research employing HTTP request messages to identify web trackers, HTTP response headers are often overlooked. This study endeavors to design effective machine learning classifiers for web tracker detection using binarized HTTP response headers. Data from the Chrome, Firefox, and Brave browsers, obtained through the traffic monitoring browser extension T.EX, serves as our dataset. Ten supervised models were trained on Chrome data and tested across all browsers, including a Chrome dataset from a year later. The results demonstrated high accuracy, F1-score, precision, recall, and minimal log-loss error for Chrome and Firefox, but subpar performance on Brave, potentially due to its distinct data distribution and feature set. The research suggests that these classifiers are viable for web tracker detection. However, real-world application testing remains pending, and the distinction between tracker types and broader label sources could be explored in future studies.
Wolf Rieder, Philip Raschke, Thomas Cory
Proc. Priv. Enhancing Technol.3
2020 Heimdall: Illuminating the Hidden Depths of Third-party Tracking in Android Applications
abstract
Although the problems surrounding the ubiquity of Web tracking and its risk to the privacy of online users have attracted public attention in recent years, efforts to counter their adverse effects and protect the privacy and personal data of users, either through counter-tracking solutions or legislation, have done little to stem the tide. This problem is especially pronounced in the mobile world, where the generally opaque nature of mobile platforms prevents effective research to ascertain the nature and extent of third-party tracking and protect user privacy. For this reason, we present Heimdall, an Android Web traffic measurement tool designed to allow users and researchers to shed light on the inner workings of mobile applications and identify connections to third-party trackers that have the potential to abuse users' personal data present on their mobile devices. We demonstrate the feasibility of the concept underlying Heim-dall by using it to monitor the network traffic of 450 Android applications, mapping out their connections to 3,453 unique hosts. Analysing this dataset reveals that 70.9% of monitored apps communicate with known tracking and advertising hosts, highlighting the prevalence of third-party tracking in mobile applications.
Thomas Cory, Philip Raschke, Axel Küpper
TrustCom1