EDBT 2026 Demo / reviewers in the wild / expert
Poojitha Thota
dblp:296/1793
· DBLP profile ↗
5ranked-venue papers
0as first author
5since 2021 · last 2026
0000-0003-3744-4847ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unequal Privacy: Auditing Demographic Bias Vulnerabilities in Visual Protection SystemsabstractVisual Privacy Protection (VPP) systems, such as blurring, pixelation, adversarial perturbations, and face replacement, are increasingly used to prevent identity disclosure in surveillance footage and publicly shared datasets. However, little is known about whether these protections apply equally across demographic groups, and uneven protection may create exploitable vulnerabilities. In this paper, we introduce FairDeFace, the first comprehensive framework for auditing the fairness, robustness, and visual quality of VPP systems under realistic adversarial threat models. Our framework evaluates how well different VPP techniques resist recognition attacks while preserving facial attributes and visual consistency across groups defined by gender and skin tone. It integrates benchmark datasets, face recognition models, attack pipelines, fairness measures, and novel visualization and statistical tools to trace where and why protections fail—for example, by identifying facial regions that are inconsistently altered. Across 500+ experiments involving seven state-of-the-art VPP methods, we uncover substantial disparities in protection strength and image quality. Certain groups, particularly Black males and females, receive consistently lower protection, framing fairness not only as an ethical concern but as a critical security and privacy risk. We release FairDeFace as an open and extensible framework to support the development and evaluation of equitable visual privacy systems. Seyyed Mohammad Sadegh Moosavi Khorzooghi, Poojitha Thota, Mohit Singhal, Abolfazl Asudeh, Gautam Das 0001, Shirin Nilizadeh |
AsiaCCS | 2 |
| 2026 | The Insider's Advantage: Exploiting Automated Privacy Policy Analyzer Tools Through Subtle Text ManipulationsabstractPrivacy policies are essential for communicating data practices to users, despite their dense, complex language, which often obstructs comprehension. Automated Policy Analyzer Tools (APATs) and recent advancements in Large Language Models (LLMs) have made strides in simplifying these documents through features such as question-answering and summarization. However, the robustness of these tools against adversarial manipulations remains less explored. This study examines how subtle, organization-side modifications to policy text can mislead APATs. We present APATRA, a multi-level framework for assessing the robustness of APATs against a range of policy-specific attacks designed to manipulate them into generating misleading outputs. We uncover vulnerabilities that can lead to substantial errors in outputs by applying character-, word-, phrase-, and sentence-level perturbations to policy contexts while preserving the original information. Our evaluation spans policy-specialized models (PolicyQA, PrivBERT), state-of-the-art LLMs (LLama-4-Maverick, GPT-3.5, GPT-4, GPT-5-mini, Claude-3.5, Claude-4.6-Sonnet), and third-party policy analyzer tools (AesirX). To validate the subtlety of our attacks, we conducted an IRB-approved user study with 100 general participants and 10 legal experts specializing in privacy law, who assessed adversarial excerpts for grammaticality, contradictions, and logical flow. Their evaluations demonstrate that our modifications maintain readability and raise no concerns. Overall, our results reveal critical security gaps in APATs and underscore the urgent need to enhance their robustness. Tanusree Das Tithy, Poojitha Thota, Shirin Nilizadeh, Faysal Hossain Shezan |
AsiaCCS | 2 |
| 2025 | Learning from Censored Experiences: Social Media Discussions around Censorship Circumvention TechnologiesabstractDuring periods of strict internet censorship, maintaining access to online information and communication becomes paramount. However, users must often navigate complicated pathways to find effective censorship circumvention technologies (CCTs). Utilizing real-time data from over 50M posts collected from Twitter and Telegram from September 18th, 2022, to January 31st, 2023, during a peak period of censorship, we examined the impact of CCTs, such as VPNs, proxies, and alternative connectivity solutions, on digital rights, privacy, and internet governance. Through a mixed-method analysis, our findings reveal user resilience and adaptability when the community collaboratively shares and discusses knowledge and resources. First, we developed a codebook for discussions considering English and, for the first time, Persian posts, highlighting the main problems users encounter when attempting to bypass the internet restrictions. Several concerns were common across these discourses, such as traceability, identifiability, and accidental use of malicious configurations. Our temporal study, conducted over 20 weeks, showed shifts in VPN preferences due to changing censorship strategies, with the inclusion of more privacy-focused and accessibility features leading to higher adoption. We also found several dedicated popular VPN channels that shared malicious files masked as free VPN services. Elham Pourabbas Vafa, Mohit Singhal, Poojitha Thota, Sayak Saha Roy |
SP | 3 |
| 2024 | From Chatbots to Phishbots?: Phishing Scam Generation in Commercial Large Language ModelsabstractThe advanced capabilities of Large Language Models (LLMs) have made them invaluable across various applications, from conversational agents and content creation to data analysis, research, and innovation. However, their effectiveness and accessibility also render them susceptible to abuse for generating malicious content, including phishing attacks. This study explores the potential of using four popular commercially available LLMs, i.e., ChatGPT (GPT 3.5 Turbo), GPT 4, Claude, and Bard, to generate functional phishing attacks using a series of malicious prompts. We discover that these LLMs can generate both phishing websites and emails that can convincingly imitate well-known brands and also deploy a range of evasive tactics that are used to elude detection mechanisms employed by anti-phishing systems. These attacks can be generated using unmodified or "vanilla" versions of these LLMs without requiring any prior adversarial exploits such as jailbreaking. We evaluate the performance of the LLMs towards generating these attacks and find that they can also be utilized to create malicious prompts that, in turn, can be fed back to the model to generate phishing scams - thus massively reducing the prompt-engineering effort required by attackers to scale these threats. As a countermeasure, we build a BERT-based automated detection tool that can be used for the early detection of malicious prompts to prevent LLMs from generating phishing content. Our model is transferable across all four commercial LLMs, attaining an average accuracy of 96% for phishing website prompts and 94% for phishing email prompts. We also disclose the vulnerabilities to the concerned LLMs, with Google acknowledging it as a severe issue. Our detection model is available for use at Hugging Face, as well as a ChatGPT Actions plugin. Sayak Saha Roy, Poojitha Thota, Krishna Vamsi Naragam, Shirin Nilizadeh |
SP | 2 |
| 2023 | SoK: Content Moderation in Social Media, from Guidelines to Enforcement, and Research to PracticeabstractSocial media platforms have been establishing content moderation guidelines and employing various moderation policies to counter hate speech and misinformation. The goal of this paper is to study these community guidelines and moderation practices, as well as the relevant research publications, to identify the research gaps, differences in moderation techniques, and challenges that should be tackled by the social media platforms and the research community. To this end, we study and analyze fourteen most popular social media content moderation guidelines and practices, and consolidate them. We then introduce three taxonomies drawn from this analysis as well as covering over two hundred interdisciplinary research papers about moderation strategies. We identify the differences between the content moderation employed in mainstream and fringe social media platforms. Finally, we have in-depth applied discussions on both research and practical challenges and solutions. Mohit Singhal, Chen Ling 0004, Pujan Paudel, Poojitha Thota, Nihal Kumarswamy, Gianluca Stringhini, Shirin Nilizadeh |
EuroS&P | 4 |