EDBT 2026 Demo / reviewers in the wild / expert
Aafaq Sabir
dblp:292/9805
· DBLP profile ↗
10ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0003-2856-8362ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PriVA-C: Defending Voice Assistants from Fingerprinting AttacksabstractVoice assistants have become ubiquitous, yet they remain vulnerable to network traffic fingerprinting attacks that can expose sensitive user information. Existing defenses either impose high overheads or fail against advanced attacks. This paper addresses these issues by introducing and evaluating PriVA-C, a fingerprinting defense mechanism tailored specifically for voice assistants. Unlike prior approaches that treat voice assistant traffic as generic web traffic, we analyze its unique characteristics to design a more effective defense. Our approach prioritizes limiting information leakage rather than targeting specific attack vectors, achieving a significant reduction in attacker accuracy from 89% to 13%. We also propose a more practically deployable version of our defense, which protects only traffic directed to the primary voice assistant domain, reducing attacker accuracy to 19%. We implement a functional prototype using the Alexa SDK, conduct user testing, and assess its performance using real network traffic. Our results demonstrate that our proposed defense effectively mitigates fingerprinting attacks while maintaining low overhead and preserving the user experience. Dilawer Ahmed, Aafaq Sabir, Ahsan Zafar, Anupam Das 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2026 | Privacy by Voice: Designing Usable Privacy Notices for the Voice InterfaceabstractWith the increasing prevalence of voice interfaces, such as smart home assistants, conversational AI, and AR/VR systems, the need for effective privacy and consent mechanisms is more critical than ever. We conducted a mixed-methods study to address the challenges of ensuring effective consent for voice-based data sharing. Through interviews with voice assistant users (n=21), we identify five key design and contextual factors for effective privacy notices: context, control flow, modality, timing, and the voice used for notice delivery. We then prototyped these notices and performed a within-subject user study (n=160) to identify preferred notice designs. We found that the voice used for delivery and timing of the notice are the most critical factors influencing user preferences, with participants favoring notices delivered in the default app voice before data is requested. To our knowledge, this is the first study to design privacy notices specifically for voice-based data sharing in voice interfaces. Our findings contribute valuable insights to the privacy design literature and provide actionable guidance for developers working on emerging voice-driven platforms. Aafaq Sabir, Abhinaya S. B., Dilawer Ahmed, Anupam Das 0001 |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | Analyzing Ad Prevalence, Characteristics, and Compliance in Alexa SkillsabstractWith the rapid adoption of smart voice assistants like Amazon Alexa and the potential for more growth with large language model-powered assistants, as well as the introduction of “advertising ID” within Alexa, it is inevitable that advertisements (ads) will become prevalent on such platforms if not already. Although Alexa permits third-party developers to include ads within voice apps (known as “skills”) and enables targeted advertisement through ad identifiers, Alexa also lists an ad policy that restricts ads within skill responses, notifications, or reminders except in defined cases. However, it remains unclear whether all developers comply with these policies or attempt to bypass vetting processes to publish noncompliant ads. This paper presents the first large-scale analysis of advertising on the Alexa platform, examining ad prevalence, characteristics, and adherence to platform policies. We introduce an automated ad detection method using a fine-tuned large language model (LLM) with 88.92% accuracy and, using chain-of-thought (CoT) prompting, achieve 94.52% accuracy in identifying potential policy-violating ads. Analyzing 45,477 Alexa skills, we find that 13.58% include ads or promotional content, with themes such as travel and entertainment. Notably, some ads come from skills by Amazon-promoted agencies like “Vixen Labs” while others are generated by agencies solely focused on voice assistant platforms, such as “Skilled Creative.” Our model identifies approximately 29.18% of ads as possible policy violations. We reported our findings to Amazon, resulting in a bug bounty reward. The proposed system aims to enhance Alexa's vetting by automatically flagging potential ad violations and demonstrates how fine-tuned LLMs can support policy enforcement on voice platforms. Aafaq Sabir, Abhinaya S. B., Dilawer Ahmed, Anupam Das 0001 |
SP | 1 |
| 2024 | Enabling Developers, Protecting Users: Investigating Harassment and Safety in VR
Abhinaya S. B., Aafaq Sabir, Anupam Das 0001 |
USENIX Security Symposium | 2 |
| 2023 | Speaker Orientation-Aware Privacy Control to Thwart Misactivation of Voice AssistantsabstractSmart home voice assistants (VAs) such as Amazon Echo and Google Home have become popular because of the convenience they provide through voice commands. VAs continuously listen to detect the wake command and send the subsequent audio data to the manufacturer-owned cloud service for processing to identify actionable commands. However, research has shown that VAs are prone to replay attack and accidental activations when the wake words are spoken in the background (either by a human or played through a mechanical speaker). Existing privacy controls are not effective in preventing such misactivations. This raises privacy and security concerns for the users as their conversations can be recorded and relayed to the cloud without their knowledge. Recent studies have shown that the visual gaze plays an important role when interacting with conservation agents such as VAs, and users tend to turn their heads or body toward the VA when invoking it. In this paper, we propose a device-free, non-obtrusive acoustic sensing system called HeadTalk to thwart the misactivation of VAs. The proposed system leverages the user's head direction information and verifies that a human generates the sound to minimize accidental activations. Our extensive evaluation shows that HeadTalk can accurately infer a speaker's head orientation with an average accuracy of 96.14% and distinguish human voice from a mechanical speaker with an equal error rate of 2.58%. We also conduct a user interaction study to assess how users perceive our proposed approach compared to existing privacy controls. Our results suggest that HeadTalk can not only enhance the security and privacy controls for VAs but do so in a usable way without requiring any additional hardware. Shaohu Zhang, Aafaq Sabir, Anupam Das 0001 |
DSN | 2 |
| 2023 | INSPIRE: Instance-Level Privacy-Pre Serving Transformation for Vehicular Camera VideosabstractThe wide spread of vehicular cameras has raised broad privacy concerns. Ubiquitous vehicular cameras capture bystanders like people or cars nearby without their awareness. To address privacy concerns, most existing works either blur out direct identifiers such as vehicle license plates and human faces, or obfuscate whole video frames. However, the former solution is vulnerable to re-identification attacks based on general features, and the latter severely impacts utility of the transformed videos. In this paper, we propose an INStance-level PrIvacy-pREserving (INSPIRE) video transformation framework for vehicular camera videos. INSPIRE leverages deep neural network models to detect and replace sensitive object instances in vehicular videos with their non-existent counterparts. We design INSPIRE as a modular framework to enable flexible customization of protected instance categories and their protection modules. An implementation of INSPIRE focused on protecting people and cars is described, which we tested on six re-identification datasets and three real-world vehicular video datasets to evaluate its privacy protection and utility preservation capability. Results show that INSPIRE can thwart 97% of re-identification attacks for people and cars while maintaining a 0.75 object detection mean average precision on transformed instances. We also demonstrate experimentally that INSPIRE is robust against model inversion attacks. Compared to solutions that provide comparable privacy protection, INSPIRE achieves relatively 1.76 times higher counting accuracy and 31.61% higher object detection mean average precision. Zhouyu Li, Ruozhou Yu, Anupam Das 0001, Shaohu Zhang, Huayue Gu, Fangtong Zhou, Aafaq Sabir, Dilawer Ahmed, Ahsan Zafar |
ICCCN | 8 |
| 2023 | Spying through Your Voice Assistants: Realistic Voice Command Fingerprinting
Dilawer Ahmed, Aafaq Sabir, Anupam Das 0001 |
USENIX Security Symposium | 2 |
| 2022 | Hey Alexa, Who Am I Talking to?: Analyzing Users' Perception and Awareness Regarding Third-party Alexa SkillsabstractThe Amazon Alexa voice assistant provides convenience through automation and control of smart home appliances using voice commands. Amazon allows third-party applications known as skills to run on top of Alexa to further extend Alexa’s capability. However, as multiple skills can share the same invocation phrase and request access to sensitive user data, growing security and privacy concerns surround third-party skills. In this paper, we study the availability and effectiveness of existing security indicators or a lack thereof to help users properly comprehend the risk of interacting with different types of skills. We conduct an interactive user study (inviting active users of Amazon Alexa) where participants listen to and interact with real-world skills using the official Alexa app. We find that most participants fail to identify the skill developer correctly (i.e., they assume Amazon also develops the third-party skills) and cannot correctly determine which skills will be automatically activated through the voice interface. We also propose and evaluate a few voice-based skill type indicators, showcasing how users would benefit from such voice-based indicators. Aafaq Sabir, Evan Lafontaine, Anupam Das 0001 |
CHI | 1 |
| 2022 | Analyzing the Impact and Accuracy of Facebook Activity on Facebook's Ad-Interest Inference ProcessabstractSocial media platforms like Facebook have become increasingly popular for serving targeted ads to their users. This has led to increased privacy concerns due to the lack of transparency regarding how ads are matched against each user profile. Facebook infers user interests through their activities and targets ads based on those interests. Although Facebook provides explanations for why a particular interest is inferred about a user, there is still a gap in understanding what activities lead to interest inferences and the extent to which the sentiment or context of activities is considered in inferring interests. To obtain insights into how Facebook generates interests from a user's Facebook activities, we performed controlled experiments by creating new accounts and systematically executing numerous planned activities. This enabled us to make causal inferences about activities that lead to generating specific interests, many of which were not representative of actual user preferences. We also evaluated which activities resulted in interests and found that very naive activities, such as only viewing/scrolling through a page, lead to an interest inference. We found 33.22% of the inferred interests were inaccurate or irrelevant. We further evaluated the interest inference explanations provided by Facebook and found that these explanations were too generalized and, at times, misleading. To understand if our findings hold for a large and diverse sample, we conducted a user study where we recruited 146 participants (through Amazon Mechanical Turk) from different regions of the world to evaluate the accuracy of interests inferred by Facebook. We developed a browser extension to extract data from their own Facebook accounts and ask questions based on such data. Our participants reported a similar range (29%) of inaccuracy as observed in our controlled experiments. We also found that most of our participants were unaware of the availability of Facebook's ad preference manager, interest inference process, and even interest explanations. Aafaq Sabir, Evan Lafontaine, Anupam Das 0001 |
Proc. ACM Hum. Comput. Interact. | 1 |
| 2021 | Understanding the Privacy Implications of Adblock Plus's Acceptable AdsabstractTargeted advertisement is prevalent on the Web. Many privacy-enhancing tools have been developed to thwart targeted advertisement. Adblock Plus is one such popular tool, used by millions of users on a daily basis, to block unwanted ads and trackers. Adblock Plus uses EasyList and EasyPrivacy, the most prominent and widely used open-source filters, to block unwanted web contents. However, Adblock Plus, by default, also enables an exception list to unblock web requests that comply with specific guidelines defined by the Acceptable Ads Committee. Any publisher can enroll into the Acceptable Ads initiative to request the unblocking of web contents. Adblock Plus in return charges a licensing fee from large entities, who gain a significant amount of ad impressions per month due to participation in the Acceptable Ads initiative. However, the privacy implications of the default inclusion of the exception list has not been well studied, especially as it can unblock not only ads, but also trackers (e.g., unblocking contents otherwise blocked by EasyPrivacy). Ahsan Zafar, Aafaq Sabir, Dilawer Ahmed, Anupam Das 0001 |
AsiaCCS | 2 |