EDBT 2026 Demo / reviewers in the wild / expert
Tzipora Halevi
dblp:32/7214 · also Tzipora T. Halevi
· DBLP profile ↗
16ranked-venue papers
7as first author
3since 2021 · last 2022
0000-0003-3988-0239ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 5 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Hearing Check Failed: Using Laser Vibrometry to Analyze the Potential for Hard Disk Drives to Eavesdrop Speech VibrationsabstractSound waves from speech can potentially induce vibrations, proportional to the speech signal, on nearby objects. Each of these objects introduces the risk for a malicious attacker to exploit the induced vibrations to eavesdrop on the speech. Such an eavesdropping attack is critical when we consider the potential for induced vibrations in standard magnetic hard disk drives (HDDs). As an instance of this threat, prior research has demonstrated that speech in certain scenarios can induce vibrations on the read/write head of an HDD in order to eavesdrop on the speech (Kwong et al.; Oakland'19). In this paper, we revisit this line of research and aim to provide a closer investigation into whether HDDs can in fact be used as a source for eavesdropping on speech vibrations. As a foundation for our study, we utilize an effective, and robust methodology using laser vibrometry to measure the subtle speech vibrations induced on the read/write head. The prior study tested only a single HDD and only machine-rendered speech in a single setting with very loud speech. Our work broadens the scope of this research in many significant ways. First, we test multiple popular HDDs of different models and sizes to evaluate the generalizability of the overall threat. Second, we evaluate the threat from live human speech spoken near an HDD, expanding the scope of the attack to include most real-world speech settings involving normal human conversations. Third, we define machine-rendered speech scenarios to explore different propagation media and degrees of speech loudness. Our findings are two-fold. First, we observed that live human speech traveling through the air is not generally strong enough to impact HDDs such that intelligible speech information is leaked. Second, most tested HDDs did not seem capable of eavesdropping on machine-rendered speech unless the speech is loud enough, or the HDD shares a surface or is in direct contact with the speaker device. This implies HDDs cannot eavesdrop live human speech. Payton Walker, Shalini Saini, S. Abhishek Anand, Tzipora Halevi, Nitesh Saxena |
AsiaCCS | 4 |
| 2021 | MPC-Friendly Symmetric Cryptography from Alternating Moduli: Candidates, Protocols, and Applications
Itai Dinur, Steven Goldfeder, Tzipora Halevi, Yuval Ishai, Mahimna Kelkar, Gregory M. Zaverucha |
CRYPTO (4) | 3 |
| 2021 | Towards a Framework to Support the Design of Esports Curricula in Higher EducationabstractEsports has generated an industry of increasing economic and cultural importance. In recent years, universities and other higher education institutions have responded to its growth by establishing undergraduate courses to satisfy the needs of innovators operating in the area. However, there is not yet consensus on what an esports curriculum should include. Despite being a technology-driven sector with ethical and professional dimensions that intersect computing, current ACM and IEEE curricula do not mention esports. Furthermore, existing courses tend to provide teaching and training on a wide variety of topics aside from those traditionally in computer science. These include: live events management; psychological research; sports science; marketing; public relations; video (livestream) production; and community management; in addition to coaching. This working group seeks to examine the requirements for developing esports studies at universities with a focus on understanding career prospects in esports and on the challenges presented by its disciplinary complexity. The group will identify key learning outcomes and assess how they align with industry needs, paving the way for a framework to support the design of esports curricula in higher education. Michael 'Adrir' Scott, Rory Summerley, Nicolas Besombes, Cornelia Connolly, Joey Gawrysiak, Tzipora Halevi, Seth Jenny, Michael Miljanovic, Melissa C. Stange, Toni Taipalus, J. Patrick Williams |
ITiCSE (2) | 6 |
| 2019 | Homomorphic Training of 30, 000 Logistic Regression Models
Flávio Bergamaschi, Shai Halevi, Tzipora Halevi, Hamish Hunt |
ACNS | 3 |
| 2018 | Supporting Private Data on Hyperledger Fabric with Secure Multiparty ComputationabstractHyperledger Fabric is a "permissioned" blockchain architecture, providing a consistent distributed ledger, shared by a set of "peers." As with every blockchain architecture, the core principle of Hyperledger Fabric is that all the peers must have the same view of the shared ledger, making it challenging to support private data for the different peers. Extending Hyperledger Fabric to support private data (that can influence transactions) would open the door to many exciting new applications, in areas from healthcare to commerce, insurance, finance, and more. In this work we explored adding private-data support to Hyperledger Fabric using secure multiparty computation (MPC). Specifically, in our solution the peers store on the chain encryption of their private data, and use secure MPC whenever such private data is needed in a transaction. This solution is very general, allowing in principle to base transactions on any combination of public and private data. We created a demo of our solution over Hyperledger Fabric v1.0, implementing a bidding system where sellers can list assets on the ledger with a secret reserve price, and bidders publish their bids on the ledger but keep secret the bidding price itself. We implemented a smart contract (aka "chaincode") that runs the auction on this secret data, using a simple secure-MPC protocol that was built using the EMP-toolkit library. The chaincode itself was written in Go, and we used the SWIG library to make it possible to call our protocol implementation in C++. We identified two basic services that should be added to Hyperledger Fabric to support our solution, and are now working on implementing them. Fabrice Benhamouda, Shai Halevi, Tzipora Halevi |
IC2E | 3 |
| 2017 | Implementing BP-Obfuscation Using Graph-Induced EncodingabstractWe implemented (a simplified version of) the branching-program obfuscator due to Gentry et al. (GGH15), which is itself a variation of the first obfuscation candidate by Garg et al. (GGHRSW13). To keep within the realm of feasibility, we had to give up on some aspects of the construction, specifically the "multiplicative bundling" factors that protect against mixed-input attacks. Hence our implementation can only support read-once branching programs. Shai Halevi, Tzipora Halevi, Victor Shoup, Noah Stephens-Davidowitz |
CCS | 2 |
| 2016 | Cultural and psychological factors in cyber-securityabstractIncreasing cyber-security presents an ongoing challenge to security professionals. Research continuously suggests that online users are a weak link in information security. This research explores the relationship between cyber-security and cultural, personality and demographic variables. Tzipora Halevi, Nasir Memon, Ponnurangam Kumaraguru, Sumit Arora, Nikita Dagar, Fadi A. Aloul, Jay Chen |
iiWAS | 1 |
| 2014 | An HMM-based behavior modeling approach for continuous mobile authenticationabstractThis paper studies continuous authentication for touch interface based mobile devices. A Hidden Markov Model (HMM) based behavioral template training approach is presented, which does not require training data from other subjects other than the owner of the mobile. The stroke patterns of a user are modeled using a continuous left-right HMM. The approach models the horizontal and vertical scrolling patterns of a user since these are the basic and mostly used interactions on a mobile device. The effectiveness of the proposed method is evaluated through extensive experiments using the Toucha-lytics database which comprises of touch data over time. The results show that the performance of the proposed approach is better than the state-of-the-art method. Tzipora Halevi, Nasir Memon |
ICASSP | 2 |
| 2013 | Sensing-enabled channels for hard-to-detect command and control of mobile devicesabstractThe proliferation of mobile computing devices has enabled immense opportunities for everyday users. At the same time, however, this has opened up new, and perhaps more severe, possibilities for attacks. In this paper, we explore a novel generation of mobile malware that exploits the rich variety of sensors available on current mobile devices. Ragib Hasan, Nitesh Saxena, Tzipora Halevi, Shams Zawoad, Dustin Rinehart |
AsiaCCS | 3 |
| 2013 | Acoustic Eavesdropping Attacks on Constrained Wireless Device PairingabstractSecure “pairing” of wireless devices based on auxiliary or out-of-band (OOB)-audio, visual, or tactile-communication is a well-established research direction. Specifically, authenticated as well as secret OOB (AS-OOB) channels have been shown to be quite useful for this purpose. Pairing can be achieved by simply transmitting the key or short password over the AS-OOB channel, avoiding potential serious human errors. This paper analyzes the security of AS-OOB pairing. Specifically, we take a closer look at three notable prior AS-OOB pairing proposals and challenge the assumptions upon which the security of these proposals relies, i.e., the secrecy of underlying audio channels. The first proposal (IMD Pairing) uses a low frequency audio channel to pair an implanted RFID tag with an external reader. The second proposal (PIN-Vibra) uses an automated vibrational channel to pair a mobile phone with a personal RFID tag. The third proposal (BEDA) uses vibration (or blinking) on one device and manually synchronized button pressing on another device or simultaneous button pressing on two devices. We demonstrate the feasibility of eavesdropping over acoustic emanations associated with these methods and conclude that they provide a weaker level of security than was originally assumed or desired for the pairing operation. Tzipora Halevi, Nitesh Saxena |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2012 | A closer look at keyboard acoustic emanations: random passwords, typing styles and decoding techniquesabstractWe take a closer look at keyboard acoustic emanations specifically for the purpose of eavesdropping over random passwords. In this scenario, dictionary and HMM language models are not applicable; the attacker can only utilize the raw acoustic information which has been recorded. We investigate several existing signal processing techniques for our purpose, and introduce a novel technique -- time-frequency decoding -- that improves the detection accuracy compared to previous techniques. We also carefully examine the effect of typing style -- a crucial variable largely ignored by prior research -- on the detection accuracy. Our results show that using the same typing style (hunt and peck) for both training and decoding the data, the best case success rate for detecting correctly the typed key is 64% per character. The results also show that changing the typing style, to touch typing, during the decoding stage reduces the success rate, but using the time-frequency technique, we can still achieve a success rate of around 40% per character. Tzipora Halevi, Nitesh Saxena |
AsiaCCS | 1 |
| 2012 | Secure Proximity Detection for NFC Devices Based on Ambient Sensor Data
Tzipora Halevi, Di Ma 0001, Nitesh Saxena, Tuo Xiang |
ESORICS | 1 |
| 2012 | Sensing-enabled defenses to RFID unauthorized reading and relay attacks without changing the usage modelabstractMany RFID tags store valuable information privy to their users that can easily be subject to unauthorized reading, leading to owner tracking or impersonation. RFID tags are also susceptible to different forms of relay attacks. This paper presents novel sensing-enabled defenses to unauthorized reading and relay attacks against RFID systems without necessitating any changes to the traditional RFID usage model. More specifically, the paper proposes the use of on-board tag sensors to (automatically) acquire useful contextual information about the tag's environment (or its owner, or the tag itself). It suggests how this information can be used to achieve two security functionalities. First, such context recognition can be leveraged for the purpose of selective tag unlocking - the tag will respond selectively to reader interrogations, i.e., only when it is deemed safe to do so. Second, context recognition can be used as a basis for transaction verification in order to provide protection against a severe form of relay attacks involving malicious RFID readers. To demonstrate the feasibility of the overall idea, a novel selective unlocking mechanism based on owner's posture recognition is presented. The evaluation of the proposed mechanism shows its effectiveness in significantly raising the bar against many different RFID attacks. Tzipora Halevi, Sein Lin, Di Ma 0001, Anudath K. Prasad, Nitesh Saxena, Jonathan Voris, Tuo Xiang |
PerCom | 1 |
| 2011 | Accelerometers and randomness: perfect togetherabstractAccelerometers are versatile sensors that are nearly ubiquitous. They are available on a wide variety of devices and are particularly common on those that are mobile or have wireless capabilities. Accelerometers are applicable in a number of settings and circumstances, including important security and privacy domains. In this paper, we investigate the use of accelerometers for the purpose of true random number generation. As our first contribution, we discover that an accelerometer possesses two unique and appealing properties when used as an entropy source. First, contrary to intuition, an accelerometer can derive sufficient entropy even when it is stationary (i.e., not subject to perceivable acceleration). Next, and more importantly, the entropy of a stationary accelerometer can not be reduced in the presence of a variety of environmental variations or even under adversarial manipulations. This means that, unlike other sensors, accelerometers are resistant to changing environments, benign or otherwise. To support this claim, we develop a thorough experimental adversarial model for accelerometers that supply a system with entropy. To the authors' knowledge, this is the first real world model in the context of entropy collection. As our second contribution, we demonstrate the validity of accelerometer based random number generation on an RFID tag, which is a highly resource constrained device. We present the design and implementation of our method on an Intel WISP tag and conduct several novel experiments to evaluate its feasibility. Our results indicate that a high quality 128-bit random number can be extracted using an accelerometer in about 1.5 seconds even when the sensor is in a stationary state. To our knowledge, this is the first random number generation technique that is known to be viable for RFID devices based on general-purpose hardware. Jonathan Voris, Nitesh Saxena, Tzipora Halevi |
WISEC | 3 |
| 2011 | Tree-based HB protocols for privacy-preserving authentication of RFID tagsabstractAn RFID reader must authenticate its designated tags in order to prevent tag forgery and counterfeiting. At the same time, due to privacy requirements of many applications, a tag should remain anonymous and untraceable to an adversary during the authentication process. In this paper, we propose an “HB-like” protocol for privacy-preserving authentication of RFID tags. Previous protocols for privacy-preserving authentication were based on PRF computations. Our protocol can instead be used on low-cost tags that may be incapable of computing traditional PRFs. Moreover, since the underlying computations in HB protocols are very efficient, our protocol also reduces reader-side load compared to PRF-based protocols. We suggest a tree-based approach that replaces the PRF-based authentication from prior work with a procedure such as HB+ or HB#. We optimize the tree-traversal stage through usage of a “light version” of the underlying protocol and shared random challenges across all levels of the tree. This provides significant reduction of the communication resources, resulting in a privacy-preserving protocol almost as efficient as the underlying HB+ or HB#. We also present analytical and simulation results comparing our method with prior proposals in terms of computation, communication and memory overheads. Tzipora Halevi, Nitesh Saxena, Shai Halevi |
J. Comput. Secur. | 1 |
| 2010 | On pairing constrained wireless devices based on secrecy of auxiliary channels: the case of acoustic eavesdroppingabstractSecure "pairing" of wireless devices based on auxiliary or out-of-band (OOB) - audio, visual or tactile - communication is a well-established research direction. Lack of good quality interfaces on or physical access to certain constrained devices (e.g., headsets, access points, medical implants) makes pairing a challenging problem in practice. Prior work shows that pairing of constrained devices based on authenticated OOB (A-OOB) channels can be prone to human errors that eventually translate into man-in-the-middle attacks. An alternative and more usable solution is to use OOB channel(s) that are authenticated as well as secret (AS-OOB). AS-OOB pairing can be achieved by simply transmitting the key or a short password over the AS-OOB channel, avoiding potential serious human errors. Tzipora Halevi, Nitesh Saxena |
CCS | 1 |