Dilawer Ahmed

dblp:294/3240 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 6 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PriVA-C: Defending Voice Assistants from Fingerprinting Attacks
abstract
Voice assistants have become ubiquitous, yet they remain vulnerable to network traffic fingerprinting attacks that can expose sensitive user information. Existing defenses either impose high overheads or fail against advanced attacks. This paper addresses these issues by introducing and evaluating PriVA-C, a fingerprinting defense mechanism tailored specifically for voice assistants. Unlike prior approaches that treat voice assistant traffic as generic web traffic, we analyze its unique characteristics to design a more effective defense. Our approach prioritizes limiting information leakage rather than targeting specific attack vectors, achieving a significant reduction in attacker accuracy from 89% to 13%. We also propose a more practically deployable version of our defense, which protects only traffic directed to the primary voice assistant domain, reducing attacker accuracy to 19%. We implement a functional prototype using the Alexa SDK, conduct user testing, and assess its performance using real network traffic. Our results demonstrate that our proposed defense effectively mitigates fingerprinting attacks while maintaining low overhead and preserving the user experience.
Dilawer Ahmed, Aafaq Sabir, Ahsan Zafar, Anupam Das 0001
Proc. Priv. Enhancing Technol.1
2026 Privacy by Voice: Designing Usable Privacy Notices for the Voice Interface
abstract
With the increasing prevalence of voice interfaces, such as smart home assistants, conversational AI, and AR/VR systems, the need for effective privacy and consent mechanisms is more critical than ever. We conducted a mixed-methods study to address the challenges of ensuring effective consent for voice-based data sharing. Through interviews with voice assistant users (n=21), we identify five key design and contextual factors for effective privacy notices: context, control flow, modality, timing, and the voice used for notice delivery. We then prototyped these notices and performed a within-subject user study (n=160) to identify preferred notice designs. We found that the voice used for delivery and timing of the notice are the most critical factors influencing user preferences, with participants favoring notices delivered in the default app voice before data is requested. To our knowledge, this is the first study to design privacy notices specifically for voice-based data sharing in voice interfaces. Our findings contribute valuable insights to the privacy design literature and provide actionable guidance for developers working on emerging voice-driven platforms.
Aafaq Sabir, Abhinaya S. B., Dilawer Ahmed, Anupam Das 0001
Proc. Priv. Enhancing Technol.3
2025 Analyzing Ad Prevalence, Characteristics, and Compliance in Alexa Skills
abstract
With the rapid adoption of smart voice assistants like Amazon Alexa and the potential for more growth with large language model-powered assistants, as well as the introduction of “advertising ID” within Alexa, it is inevitable that advertisements (ads) will become prevalent on such platforms if not already. Although Alexa permits third-party developers to include ads within voice apps (known as “skills”) and enables targeted advertisement through ad identifiers, Alexa also lists an ad policy that restricts ads within skill responses, notifications, or reminders except in defined cases. However, it remains unclear whether all developers comply with these policies or attempt to bypass vetting processes to publish noncompliant ads. This paper presents the first large-scale analysis of advertising on the Alexa platform, examining ad prevalence, characteristics, and adherence to platform policies. We introduce an automated ad detection method using a fine-tuned large language model (LLM) with 88.92% accuracy and, using chain-of-thought (CoT) prompting, achieve 94.52% accuracy in identifying potential policy-violating ads. Analyzing 45,477 Alexa skills, we find that 13.58% include ads or promotional content, with themes such as travel and entertainment. Notably, some ads come from skills by Amazon-promoted agencies like “Vixen Labs” while others are generated by agencies solely focused on voice assistant platforms, such as “Skilled Creative.” Our model identifies approximately 29.18% of ads as possible policy violations. We reported our findings to Amazon, resulting in a bug bounty reward. The proposed system aims to enhance Alexa's vetting by automatically flagging potential ad violations and demonstrates how fine-tuned LLMs can support policy enforcement on voice platforms.
Aafaq Sabir, Abhinaya S. B., Dilawer Ahmed, Anupam Das 0001
SP3
2023 INSPIRE: Instance-Level Privacy-Pre Serving Transformation for Vehicular Camera Videos
abstract
The wide spread of vehicular cameras has raised broad privacy concerns. Ubiquitous vehicular cameras capture bystanders like people or cars nearby without their awareness. To address privacy concerns, most existing works either blur out direct identifiers such as vehicle license plates and human faces, or obfuscate whole video frames. However, the former solution is vulnerable to re-identification attacks based on general features, and the latter severely impacts utility of the transformed videos. In this paper, we propose an INStance-level PrIvacy-pREserving (INSPIRE) video transformation framework for vehicular camera videos. INSPIRE leverages deep neural network models to detect and replace sensitive object instances in vehicular videos with their non-existent counterparts. We design INSPIRE as a modular framework to enable flexible customization of protected instance categories and their protection modules. An implementation of INSPIRE focused on protecting people and cars is described, which we tested on six re-identification datasets and three real-world vehicular video datasets to evaluate its privacy protection and utility preservation capability. Results show that INSPIRE can thwart 97% of re-identification attacks for people and cars while maintaining a 0.75 object detection mean average precision on transformed instances. We also demonstrate experimentally that INSPIRE is robust against model inversion attacks. Compared to solutions that provide comparable privacy protection, INSPIRE achieves relatively 1.76 times higher counting accuracy and 31.61% higher object detection mean average precision.
Zhouyu Li, Ruozhou Yu, Anupam Das 0001, Shaohu Zhang, Huayue Gu, Fangtong Zhou, Aafaq Sabir, Dilawer Ahmed, Ahsan Zafar
ICCCN9
2023 Spying through Your Voice Assistants: Realistic Voice Command Fingerprinting
Dilawer Ahmed, Aafaq Sabir, Anupam Das 0001
USENIX Security Symposium1
2022 Analyzing the Feasibility and Generalizability of Fingerprinting Internet of Things Devices
abstract
Abstract In recent years, we have seen rapid growth in the use and adoption of Internet of Things (IoT) devices. However, some loT devices are sensitive in nature, and simply knowing what devices a user owns can have security and privacy implications. Researchers have, therefore, looked at fingerprinting loT devices and their activities from encrypted network traffic. In this paper, we analyze the feasibility of fingerprinting IoT devices and evaluate the robustness of such fingerprinting approach across multiple independent datasets — collected under different settings. We show that not only is it possible to effectively fingerprint 188 loT devices (with over 97% accuracy), but also to do so even with multiple instances of the same make-and-model device. We also analyze the extent to which temporal, spatial and data-collection-methodology differences impact fingerprinting accuracy. Our analysis sheds light on features that are more robust against varying conditions. Lastly, we comprehensively analyze the performance of our approach under an open-world setting and propose ways in which an adversary can enhance their odds of inferring additional information about unseen devices (e.g., similar devices manufactured by the same company).
Dilawer Ahmed, Anupam Das 0001, Fareed Zaffar
Proc. Priv. Enhancing Technol.1
2021 Understanding the Privacy Implications of Adblock Plus's Acceptable Ads
abstract
Targeted advertisement is prevalent on the Web. Many privacy-enhancing tools have been developed to thwart targeted advertisement. Adblock Plus is one such popular tool, used by millions of users on a daily basis, to block unwanted ads and trackers. Adblock Plus uses EasyList and EasyPrivacy, the most prominent and widely used open-source filters, to block unwanted web contents. However, Adblock Plus, by default, also enables an exception list to unblock web requests that comply with specific guidelines defined by the Acceptable Ads Committee. Any publisher can enroll into the Acceptable Ads initiative to request the unblocking of web contents. Adblock Plus in return charges a licensing fee from large entities, who gain a significant amount of ad impressions per month due to participation in the Acceptable Ads initiative. However, the privacy implications of the default inclusion of the exception list has not been well studied, especially as it can unblock not only ads, but also trackers (e.g., unblocking contents otherwise blocked by EasyPrivacy).
Ahsan Zafar, Aafaq Sabir, Dilawer Ahmed, Anupam Das 0001
AsiaCCS3