EDBT 2026 Demo / reviewers in the wild / expert
Daniel Hedin
dblp:37/1881
· DBLP profile ↗
17ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0002-6621-8390ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 4 since 2021Software engineering, systems software and programming languages · 3Theory of computation · 2Artificial intelligence and machine learning · 1Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | CodeX: Contextual Flow Tracking for Browser ExtensionsabstractBrowser extensions put millions of users at risk when misusing their elevated privileges. Despite the current practices of semi-automated code vetting, privacy-violating extensions still thrive in the official stores. We propose an approach for tracking contextual flows from browser-specific sensitive sources like cookies, browsing history, bookmarks, and search terms to suspicious network sinks through network requests. We demonstrate the effectiveness of the approach by a prototype called CodeX that leverages the power of CodeQL while breaking away from the conservativeness of bug-finding flavors of the traditional CodeQL taint analysis. Applying CodeX to the extensions published on the Chrome Web Store between March 2021 and March 2024 identified 1,588 extensions with risky flows. Manual verification of 339 of those extensions resulted in flagging 212 as privacy-violating, impacting up to 3.6M users. Mohammad M. Ahmadpanah, Matías F. Gobbi, Daniel Hedin, Johannes Kinder, Andrei Sabelfeld |
CODASPY | 3 |
| 2024 | Merging Places: A Real-Time Distributed Live Reverberation ChamberabstractWe present Auxtrument, a prototype instrument that allows audiences to experience the acoustic qualities of remote locations. Using the metaphor of a reverberation chamber, artists send signals from the mixers, bus, or aux via the Auxtrument’s network connections from a concert hall to a few different locations. At each location the signal is played through loudspeakers and captured, colored by the acoustics and noises of the place, via a stereo or ambisonics microphone. The signal is sent back and played for the audience in a surround sound system conveying the spatial qualities of the places. The Auxtrument allows us to merge and layer the different locations in the concert hall. However, this arrangement places great demands on the network. The audio signals need to be high-resolution to preserve the inherent quality of the sounds, which creates large streams. The system must be equipped to work over different types of networks, and to enable any location, the system must work with mobile devices. After ruling out several commercial and opensource solutions, we built the Auxtrument with web technologies: mainly node.js, WebSockets, WebRTC, and WebAudio. Austin Franklin, Daniel Hedin, Rikard Lindell, Henrik Frisk |
QoMEX | 2 |
| 2023 | Poster: Data Minimization by Construction for Trigger-Action ApplicationsabstractTrigger-Action Platforms (TAPs) enable applications to integrate various devices and services otherwise unconnected. Recent features of TAPs introduce additional sources of data such as queries in IFTTT. The current TAPs, like IFTTT, demand that trigger and query services transmit excessive amounts of user data to the TAP. To limit the data to what is actually necessary for the execution to comply with the principle of data minimization, input services should send no more than the necessary data. LazyTAP proposes a new paradigm of data minimization by construction in TAPs, introducing a novel perspective for data collection from input services. While the existing push-all approach of TAPs entails coarse-grained data over-approximation, LazyTAP pulls input data on-demand at the level of attributes, once accessed by the app execution. Thanks to the fine granularity provided by LazyTAP, multiple trigger and query services can be naturally minimized while the behavior of app executions is preserved. In addition, a great benefit of LazyTAP is being seamless for third-party app developers. By leveraging laziness, LazyTAP defers computation and proxies objects to load necessary remote data behind the scenes. Our evaluation study on app benchmarks shows that on average LazyTAP improves minimization by 95% over IFTTT and by 38% over minTAP, with a tolerable performance overhead. This poster goes into further details about LazyTAP and elaborates on its prototype implementation. Mohammad M. Ahmadpanah, Daniel Hedin, Andrei Sabelfeld |
CCS | 2 |
| 2023 | LazyTAP: On-Demand Data Minimization for Trigger-Action ApplicationsabstractTrigger-Action Platforms (TAPs) empower applications (apps) for connecting otherwise unconnected devices and services. The current TAPs like IFTTT require trigger services to push excessive amounts of sensitive data to the TAP regardless of whether the data will be used in the app, at odds with the principle of data minimization. Furthermore, the rich features of modern TAPs, including IFTTT queries to support multiple trigger services and nondeterminism of apps, have been out of the reach of previous data minimization approaches like minTAP. This paper proposes LazyTAP, a new paradigm for fine-grained on-demand data minimization. LazyTAP breaks away from the traditional push-all approach of coarse-grained data over-approximation. Instead, LazyTAP pulls input data on-demand, once it is accessed by the app execution. Thanks to the fine granularity, LazyTAP enables tight minimization that naturally generalizes to support multiple trigger services via queries and is robust with respect to nondeterministic behavior of the apps. We achieve seamlessness for third-party app developers by leveraging laziness to defer computation and proxy objects to load necessary remote data behind the scenes as it becomes needed. We formally establish the correctness of LazyTAP and its minimization properties with respect to both IFTTT and minTAP. We implement and evaluate LazyTAP on app benchmarks showing that on average LazyTAP improves minimization by 95% over IFTTT and by 38% over minTAP, while incurring a tolerable performance overhead. Mohammad M. Ahmadpanah, Daniel Hedin, Andrei Sabelfeld |
SP | 2 |
| 2021 | SandTrap: Securing JavaScript-driven Trigger-Action Platforms
Mohammad M. Ahmadpanah, Daniel Hedin, Musard Balliu, Eric Olsson 0001, Andrei Sabelfeld |
USENIX Security Symposium | 2 |
| 2018 | Information Flow Tracking for Side-Effectful Libraries
Alexander Sjösten, Daniel Hedin, Andrei Sabelfeld |
FORTE | 2 |
| 2016 | Information-flow security for JavaScript and its APIsabstractJavaScript drives the evolution of the web into a powerful application platform. Increasingly, web applications combine services from different providers. The script inclusion mechanism routinely turns barebone web pages into full-fledged services built up from third-party code. Script inclusion poses a challenge of ensuring that the integrated third-party code respects security and privacy. This paper presents a dynamic mechanism for securing script executions by tracking information flow in JavaScript and its APIs. On the formal side, the paper identifies language constructs that constitute a core of JavaScript: dynamic objects, higher-order functions, exceptions, and dynamic code evaluation. It develops a dynamic type system that guarantees information-flow security for this language. Based on this formal model, the paper presents JSFlow, a practical security-enhanced interpreter for fine-grained tracking of information flow in full JavaScript and its APIs. Our experiments with JSFlow deployed as a browser extension provide in-depth understanding of information manipulation by third-party scripts. We find that different sites intended to provide similar services effectuate rather different security policies for the user’s sensitive information: some ensure it does not leave the browser, others share it with the originating server, while yet others freely propagate it to third parties. Daniel Hedin, Luciano Bello, Andrei Sabelfeld |
J. Comput. Secur. | 1 |
| 2015 | Value-Sensitive Hybrid Information Flow Control for a JavaScript-Like LanguageabstractSecure integration of third-party code is one of the prime challenges for securing today's web. Recent empirical studies give evidence of pervasive reliance on and excessive trust in third-party JavaScript, with no adequate security mechanism to limit the trust or the extent of its abuse. Information flow control is a promising approach for controlling the behavior of third-party code and enforcing confidentiality and integrity policies. While much progress has been made on static and dynamic approaches to information flow control, only recently their combinations have received attention. Purely static analysis falls short of addressing dynamic language features such as dynamic objects and dynamic code evaluation, while purely dynamic analysis suffers from inability to predict side effects in non-performed executions. This paper develops a value-sensitive hybrid mechanism for tracking information flow in a JavaScript-like language. The mechanism consists of a dynamic monitor empowered to invoke a static component on the fly. This enables us to achieve a sound yet permissive enforcement. We establish formal soundness results with respect to the security policy of non-interference. In addition, we demonstrate permissiveness by proving that we subsume the precision of purely static analysis and by presenting a collection of common programming patterns that indicate that our mechanism has potential to provide more permissiveness than dynamic mechanisms in practice. Daniel Hedin, Luciano Bello, Andrei Sabelfeld |
CSF | 1 |
| 2015 | Value Sensitivity and Observable Abstract Values for Information Flow Control
Luciano Bello, Daniel Hedin, Andrei Sabelfeld |
LPAR | 2 |
| 2014 | SeLINQ: tracking information across application-database boundariesabstractThe root cause for confidentiality and integrity attacks against computing systems is insecure information flow. The complexity of modern systems poses a major challenge to secure end-to-end information flow, ensuring that the insecurity of a single component does not render the entire system insecure. While information flow in a variety of languages and settings has been thoroughly studied in isolation, the problem of tracking information across component boundaries has been largely out of reach of the work so far. This is unsatisfactory because tracking information across component boundaries is necessary for end-to-end security. Daniel Schoepe, Daniel Hedin, Andrei Sabelfeld |
ICFP | 2 |
| 2012 | Information-Flow Security for a Core of JavaScriptabstractTracking information flow in dynamic languages remains an important and intricate problem. This paper makes substantial headway toward understanding the main challenges and resolving them. We identify language constructs that constitute a core of Java Script: objects, higher-order functions, exceptions, and dynamic code evaluation. The core is powerful enough to naturally encode native constructs as arrays, as well as functionalities of Java Script's API from the document object model (DOM) related to document tree manipulation and event processing. As the main contribution, we develop a dynamic type system that guarantees information-flow security for this language. Daniel Hedin, Andrei Sabelfeld |
CSF | 1 |
| 2012 | Securing Interactive ProgramsabstractThis paper studies the foundations of information-flow security for interactive programs. Previous research assumes that the environment is total, that is, it must always be ready to feed new inputs into programs. However, programs secure under this assumption can leak the presence of input. Such leaks can be magnified to whole-secret leaks in the concurrent setting. We propose a framework that generalizes previous research along two dimensions: first, the framework breaks away from the totality of the environment and, second, the framework features fine-grained security types for communication channels, where we distinguish between the security level of message presence and message content. We show that the generalized framework features appealing compositionality properties: parallel composition of secure program results in a secure thread pool. We also show that modeling environments as strategies leads to strong compositionality: various types of composition (with and without scoping) follow from our general compositionality result. Further, we propose a type system that supports enforcement of security via fine-grained security types. Willard Rafnsson, Daniel Hedin, Andrei Sabelfeld |
CSF | 2 |
| 2012 | Boosting the Permissiveness of Dynamic Information-Flow Tracking by Testing
Arnar Birgisson, Daniel Hedin, Andrei Sabelfeld |
ESORICS | 2 |
| 2010 | A Machine-Checked Formalization of Sigma-ProtocolsabstractZero-knowledge proofs have a vast applicability in the domain of cryptography, stemming from the fact that they can be used to force potentially malicious parties to abide by the rules of a protocol, without forcing them to reveal their secrets. Σ-protocols are a class of zero-knowledge proofs that can be implemented efficiently and that suffice for a great variety of practical applications. This paper presents a first machine-checked formalization of a comprehensive theory of Σ-protocols. The development includes basic definitions, relations between different security properties that appear in the literature, and general composability theorems. We show its usefulness by formalizing—and proving the security—of concrete instances of several well-known protocols. The formalization builds on CertiCrypt, a framework that provides support to reason about cryptographic systems in the Coq proof assistant, and that has been previously used to formalize security proofs of encryption and signature schemes. Gilles Barthe, Daniel Hedin, Santiago Zanella-Béguelin, Benjamin Grégoire, Sylvain Heraud |
CSF | 2 |
| 2008 | Cryptographically-masked flows
Aslan Askarov, Daniel Hedin, Andrei Sabelfeld |
Theor. Comput. Sci. | 2 |
| 2006 | Noninterference in the Presence of Non-Opaque PointersabstractA common theoretical assumption in the study of information flow security in Java-like languages is that pointers are opaque - i.e., that the only properties that can be observed of pointers are the objects to which they point, and (at most) their equality. These assumptions often fail in practice. For example, various important operations in Java's standard API, such as hashcodes or serialization, might break pointer opacity. As a result, information-flow static analyses which assume pointer opacity risk being unsound in practice, since the pointer representation provides an unchecked implicit leak. We investigate information flow in the presence of non-opaque pointers for an imperative language with records, pointer instructions and exceptions, and develop an information flow aware type system which guarantees noninterference Daniel Hedin, David Sands 0001 |
CSFW | 1 |
| 2006 | Cryptographically-Masked Flows
Aslan Askarov, Daniel Hedin, Andrei Sabelfeld |
SAS | 2 |