EDBT 2026 Demo / reviewers in the wild / expert
Sayak Saha Roy
dblp:306/0885
· DBLP profile ↗
7ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0001-6444-2623ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PhishLang: A Real-Time, Fully Client-Side Phishing Detection Framework Using MobileBERT
Sayak Saha Roy, Shirin Nilizadeh |
NDSS | 1 |
| 2025 | Learning from Censored Experiences: Social Media Discussions around Censorship Circumvention TechnologiesabstractDuring periods of strict internet censorship, maintaining access to online information and communication becomes paramount. However, users must often navigate complicated pathways to find effective censorship circumvention technologies (CCTs). Utilizing real-time data from over 50M posts collected from Twitter and Telegram from September 18th, 2022, to January 31st, 2023, during a peak period of censorship, we examined the impact of CCTs, such as VPNs, proxies, and alternative connectivity solutions, on digital rights, privacy, and internet governance. Through a mixed-method analysis, our findings reveal user resilience and adaptability when the community collaboratively shares and discusses knowledge and resources. First, we developed a codebook for discussions considering English and, for the first time, Persian posts, highlighting the main problems users encounter when attempting to bypass the internet restrictions. Several concerns were common across these discourses, such as traceability, identifiability, and accidental use of malicious configurations. Our temporal study, conducted over 20 weeks, showed shifts in VPN preferences due to changing censorship strategies, with the inclusion of more privacy-focused and accessibility features leading to higher adoption. We also found several dedicated popular VPN channels that shared malicious files masked as free VPN services. Elham Pourabbas Vafa, Mohit Singhal, Poojitha Thota, Sayak Saha Roy |
SP | 4 |
| 2025 | DarkGram: A Large-Scale Analysis of Cybercriminal Activity Channels on Telegram
Sayak Saha Roy, Elham Pourabbas Vafa, Kobra Khanmohamaddi, Shirin Nilizadeh |
USENIX Security Symposium | 1 |
| 2024 | Users' Behavioral and Emotional Response to Toxicity in Twitter ConversationsabstractPrior works have shown connections between online toxicity attacks, such as harassment, cyberbullying, and hate speech, and the subsequent increase in offline violence, as well as negative psychological effects on victims. These correlations are primarily identified through user studies conducted via virtual environments, simulations, and questionnaires. However, no work has investigated how, in practice and authentically, people react to online toxicity both emotionally, showing anger, anxiety, and sadness, and behaviorally in terms of engaging with and responding to toxicity instigators, considering conversations as a whole and the relation between emotions and behaviors. This data-driven study investigates the effect of toxicity on Twitter users' behaviors and emotions considering confounding factors, such as account identifiability, activity, and conversation's structure and topic. We collected about 80K Twitter conversations and identified those with and without toxic replies. Performing statistical tests along with propensity score matching, we investigated the causal association of receiving toxicity and users' responses. We found that authors of conversations with toxic replies are more likely to engage in conversations, reply in a toxic way, and unfollow toxicity instigators. In terms of users' emotional responses, we found that sadness and anger after the first toxic reply are more likely to increase as the amount of toxicity increases. These findings not only emphasize the negative emotional and behavioral effects of online toxicity on social media users but also, as demonstrated in this paper, can be utilized to build prediction models for users' reactions, which could then aid the implementation of proactive detection and intervention measures helping users in such situations. Ana Aleksandric, Sayak Saha Roy, Hanani Pankaj, Gabriela Mustata Wilson, Shirin Nilizadeh |
ICWSM | 2 |
| 2024 | Unveiling the Risks of NFT Promotion ScamsabstractThe rapid growth in popularity and hype surrounding digital assets such as art, video, and music in the form of non-fungible tokens (NFTs) has made them a lucrative investment opportunity, with NFT-based sales surpassing $25B in 2021 alone. However, the volatility and general lack of technical understanding of the NFT ecosystem have led to the spread of various scams. The success of an NFT heavily depends on its online virality. As a result, creators use dedicated promotion services to drive engagement to their projects on social media websites, such as Twitter. However, these services are also utilized by scammers to promote fraudulent projects that attempt to steal users' cryptocurrency assets, thus posing a major threat to the ecosystem of NFT sales. In this paper, we conduct a longitudinal study of 439 promotion services (accounts) on Twitter that have collectively promoted 823 unique NFT projects through giveaway competitions over a period of two months. Our findings reveal that more than 36% of these projects were fraudulent, comprising of phishing, rug pull, and pre-mint scams. We also found that a majority of accounts engaging with these promotions (including those for fraudulent NFT projects) are bots that artificially inflate the popularity of the fraudulent NFT collections by increasing their likes, followers, and retweet counts. This manipulation results in significant engagement from real users, who then invest in these scams. We also identify several shortcomings in existing anti-scam measures, such as blocklists, browser protection tools, and domain hosting services, in detecting NFT-based scams. We utilize our findings to develop and open-source a machine learning classifier tool that was able to proactively detect 382 new fraudulent NFT projects on Twitter. Sayak Saha Roy, Dipanjan Das 0002, Priyanka Bose, Christopher Krügel, Giovanni Vigna, Shirin Nilizadeh |
ICWSM | 1 |
| 2024 | From Chatbots to Phishbots?: Phishing Scam Generation in Commercial Large Language ModelsabstractThe advanced capabilities of Large Language Models (LLMs) have made them invaluable across various applications, from conversational agents and content creation to data analysis, research, and innovation. However, their effectiveness and accessibility also render them susceptible to abuse for generating malicious content, including phishing attacks. This study explores the potential of using four popular commercially available LLMs, i.e., ChatGPT (GPT 3.5 Turbo), GPT 4, Claude, and Bard, to generate functional phishing attacks using a series of malicious prompts. We discover that these LLMs can generate both phishing websites and emails that can convincingly imitate well-known brands and also deploy a range of evasive tactics that are used to elude detection mechanisms employed by anti-phishing systems. These attacks can be generated using unmodified or "vanilla" versions of these LLMs without requiring any prior adversarial exploits such as jailbreaking. We evaluate the performance of the LLMs towards generating these attacks and find that they can also be utilized to create malicious prompts that, in turn, can be fed back to the model to generate phishing scams - thus massively reducing the prompt-engineering effort required by attackers to scale these threats. As a countermeasure, we build a BERT-based automated detection tool that can be used for the early detection of malicious prompts to prevent LLMs from generating phishing content. Our model is transferable across all four commercial LLMs, attaining an average accuracy of 96% for phishing website prompts and 94% for phishing email prompts. We also disclose the vulnerabilities to the concerned LLMs, with Google acknowledging it as a severe issue. Our detection model is available for use at Hugging Face, as well as a ChatGPT Actions plugin. Sayak Saha Roy, Poojitha Thota, Krishna Vamsi Naragam, Shirin Nilizadeh |
SP | 1 |
| 2023 | Phishing in the Free Waters: A Study of Phishing Attacks Created using Free Website Building ServicesabstractFree Website Building services (FWBs) provide individuals with a cost-effective and convenient way to create a website without requiring advanced technical knowledge or coding skills. However, malicious actors often abuse these services to host phishing websites. In this work, we propose FreePhish, a scalable framework to continuously identify phishing websites that are created using FWBs. Using FreePhish, we were able to detect and characterize more than 31.4K phishing URLs that were created using 17 unique free website builder services and shared on Twitter and Facebook over a period of six months. We find that FWBs provide attackers with several features that make it easier to create and maintain phishing websites at scale while simultaneously evading anti-phishing countermeasures. Our study indicates that anti-phishing blocklists and browser protection tools have significantly lower coverage and high detection time against FWB phishing attacks when compared to regular (self-hosted) phishing websites. While our prompt disclosure of these attacks helped some FWBs to remove these attacks, we found several others who were slow at removal or did not remove them outright, with the same also being true for Twitter and Facebook. Finally, we also provide FreePhish as a free Chromium web extension that can be utilized to prevent end-users from accessing potential FWB-based phishing attacks. Sayak Saha Roy, Unique Karanjit, Shirin Nilizadeh |
IMC | 1 |