Mobin Javed

dblp:48/7429 · DBLP profile ↗
← Back
21ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-1321-1988ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 2 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 5 · 5 since 2021Computer networks · 4 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Mapping the Cloud: A Mixed-Methods Study of Cloud Security and Privacy Configuration Challenges
Sumair Ijaz Hashmi, Shafay Kashif, Lea Gröber, Katharina Krombholz, Mobin Javed
NDSS5
2025 Understanding the Security Advice Mechanisms of Low Socioeconomic Pakistanis
abstract
Figure 1: The helper (on the right) sets up a password for the user's new Android phone.
Sumair Ijaz Hashmi, Rimsha Sarfaraz, Lea Gröber, Mobin Javed, Katharina Krombholz
CHI4
2025 Bystander Privacy in Smart Homes: A Systematic Review of Concerns and Solutions
abstract
Smart home devices, such as security cameras and voice assistants, have seen widespread adoption due to the utility and convenience they offer to users. The deployment of these devices in homes, however, raises privacy concerns for bystanders—people who may not necessarily have a say in the deployment and configuration of these devices, and yet are exposed to or affected by their data collection. Examples of bystanders include guests, short-term tenants, and domestic workers. Prior work has studied the privacy concerns of different bystander groups and proposed design solutions for addressing these concerns. In this article, we present a systematic review of previous studies, describing how smart home bystanders are defined and classified, and illuminating the range of concerns and solutions proposed in the existing academic literature. We also discuss limitations in prior work, barriers to the uptake of research-based solutions by industry, and identify avenues for future research.
Eimaan Saqib, Shijing He, Junghyun Choy, Ruba Abu-Salma, Jose M. Such, Julia Bernd, Mobin Javed
ACM Trans. Comput. Hum. Interact.7
2023 "Stalking is immoral but not illegal": Understanding Security, Cyber Crimes and Threats in Pakistan
Afaq Ashraf, Afaq Taha, Nida ul Habib Bajwa, Cornelius J. König, Mobin Javed, Maryam Mustafa
SOUPS5
2023 Deepfake Text Detection: Limitations and Opportunities
abstract
Recent advances in generative models for language have enabled the creation of convincing synthetic text or deepfake text. Prior work has demonstrated the potential for misuse of deepfake text to mislead content consumers. Therefore, deepfake text detection, the task of discriminating between human and machine-generated text, is becoming increasingly critical. Several defenses have been proposed for deepfake text detection. However, we lack a thorough understanding of their real-world applicability. In this paper, we collect deepfake text from 4 online services powered by Transformer-based tools to evaluate the generalization ability of the defenses on content in the wild. We develop several low-cost adversarial attacks, and investigate the robustness of existing defenses against an adaptive attacker. We find that many defenses show significant degradation in performance under our evaluation scenarios compared to their original claimed performance. Our evaluation shows that tapping into the semantic information in the text content is a promising approach for improving the robustness and generalization performance of deepfake text detection schemes.
Jiameng Pu, Zain Sarwar, Sifat Muhammad Abdullah, Abdullah Rehman, Yoonjin Kim, Parantapa Bhattacharya, Mobin Javed, Bimal Viswanath
SP7
2022 Lures for Money: A First Look into YouTube Videos Promoting Money-Making Apps
abstract
YouTube hosts a wide variety of user-generated videos accessible to a global population of users. The potential of videos to persuade users by engaging them with the experience of the content creator makes them an attractive medium for promoting various kinds of products and services, including apps and websites. The Youtubers promoting these products online may not necessarily be aware of the harms to which they might expose potential users. In fact, they may neither have the incentive nor the technical expertise to look into potential harms.
Noshaba Nasir, Faqia Iqbal, Mahnoor Zaheer, Mariam Shahjahan, Mobin Javed
AsiaCCS5
2022 "Ask this from the person who has private stuff": Privacy Perceptions, Behaviours and Beliefs Beyond W.E.I.R.D
abstract
We explore privacy perceptions, beliefs and practices of low-literate, low-income users in Pakistan, a patriarchal and religious context with a literacy rate of approx. 68% and where 59% of mobile users have less than 6 years of formal education. Through a qualitative study with 40 participants (17 male and 23 female) we examine the cultural, religious, and familial structures that impact users perceptions, management, and control of their personal privacy. We reveal significant gendered differences in privacy understandings, privacy preserving practices and the access to privacy related knowledge. Our work also highlights the seminal impact religious beliefs have on men and women’s understandings and management of privacy and the prolific use of after-market modified apps to support users specific privacy needs. The privacy concerns raised by our participants provide HCI researchers with valuable insights into designing privacy affordances for vulnerable and diverse populations beyond Western, educated, industrialized, rich and democratic contexts.
Sheza Naveed, Hamza Naveed, Mobin Javed, Maryam Mustafa
CHI3
2021 Designing Parental Monitoring and Control Technology: A Systematic Review
Zainab Iftikhar, Qutaiba Rohan ul Haq, Osama Younus, Taha Sardar, Hammad Arif, Mobin Javed, Suleman Shahid
INTERACT (4)6
2021 T-Miner: A Generative Approach to Defend Against Trojan Attacks on DNN-based Text Classification
Ahmadreza Azizi, Ibrahim Asadullah Tahmid, Asim Waheed, Neal Mangaokar, Jiameng Pu, Mobin Javed, Chandan K. Reddy, Bimal Viswanath
USENIX Security Symposium6
2021 Deepfake Videos in the Wild: Analysis and Detection
abstract
AI-manipulated videos, commonly known as deepfakes, are an emerging problem. Recently, researchers in academia and industry have contributed several (self-created) benchmark deepfake datasets, and deepfake detection algorithms. However, little effort has gone towards understanding deepfake videos in the wild, leading to a limited understanding of the real-world applicability of research contributions in this space. Even if detection schemes are shown to perform well on existing datasets, it is unclear how well the methods generalize to real-world deepfakes. To bridge this gap in knowledge, we make the following contributions: First, we collect and present the largest dataset of deepfake videos in the wild, containing 1,869 videos from YouTube and Bilibili, and extract over 4.8M frames of content. Second, we present a comprehensive analysis of the growth patterns, popularity, creators, manipulation strategies, and production methods of deepfake content in the real-world. Third, we systematically evaluate existing defenses using our new dataset, and observe that they are not ready for deployment in the real-world. Fourth, we explore the potential for transfer learning schemes and competition-winning techniques to improve defenses.
Jiameng Pu, Neal Mangaokar, Lauren Kelly, Parantapa Bhattacharya, Kavya Sundaram, Mobin Javed, Bolun Wang, Bimal Viswanath
WWW6
2017 Detecting Credential Spearphishing in Enterprise Settings
Grant Ho, Aashish Sharma, Mobin Javed, Vern Paxson, David A. Wagner 0001
USENIX Security Symposium3
2016 Do You See What I See? Differential Treatment of Anonymous Users
Sheharbano Khattak, David Fifield, Sadia Afroz 0001, Mobin Javed, Srikanth Sundaresan, Damon McCoy, Vern Paxson, Steven J. Murdoch
NDSS4
2016 Towards Mining Latent Client Identifiers from Network Traffic
abstract
Abstract Websites extensively track users via identifiers that uniquely map to client machines or user accounts. Although such tracking has desirable properties like enabling personalization and website analytics, it also raises serious concerns about online user privacy, and can potentially enable illicit surveillance by adversaries who broadly monitor network traffic. In this work we seek to understand the possibilities of latent identifiers appearing in user traffic in forms beyond those already well-known and studied, such as browser and Flash cookies. We develop a methodology for processing large network traces to semi-automatically discover identifiers sent by clients that distinguish users/devices/browsers, such as usernames, cookies, custom user agents, and IMEI numbers. We address the challenges of scaling such discovery up to enterprise-sized data by devising multistage filtering and streaming algorithms. The resulting methodology reflects trade-offs between reducing the ultimate analysis burden and the risk of missing potential identifier strings. We analyze 15 days of data from a site with several hundred users and capture dozens of latent identifiers, primarily in HTTP request components, but also in non-HTTP protocols.
Sakshi Jain, Mobin Javed, Vern Paxson
Proc. Priv. Enhancing Technol.2
2015 Measurement and Analysis of Traffic Exchange Services
abstract
Traffic exchange services enable members to bring traffic to their websites from a diverse pool of IP addresses, in return for visiting sites of other members. We examine the world of traffic exchanges to characterize their makeup, usage, and monetization. We find that the ecosystem includes a range of services, from manual exchanges where participants must solve CAPTCHAs between successive page views, to exchanges that provide tools that automatically surf without requiring any user action. By "milking" a sample of these exchanges, we analyze month-long datasets to examine the nature of URLs that members submit to them. We find a wide prevalence of URLs for services that pay users in return for views to their content, and at least 30% of the requested impressions are for pages that clearly participate in a class of impression fraud called referrer spoofing. We also analyze the size and composition of a sample of these exchange networks by making purchases, finding that the exchanges delivered visits from roughly 200K unique IP~addresses, and that in some exchange networks, the majority of visits came from cloud hosting services.
Mobin Javed, Cormac Herley, Marcus Peinado, Vern Paxson
Internet Measurement Conference1
2014 A Look at the Consequences of Internet Censorship Through an ISP Lens
abstract
Internet censorship artificially changes the dynamics of resource production and consumption, affecting a range of stakeholders that include end users, service providers, and content providers. We analyze two large-scale censorship events in Pakistan: blocking of pornographic content in 2011 and of YouTube in 2012. Using traffic datasets collected at home and SOHO networks before and after the censorship events, we: a) quantify the demand for blocked content, b) illuminate challenges encountered by service providers in implementing the censorship policies, c) investigate changes in user behavior (e.g., with respect to circumvention) after censorship, and d) assess benefits extracted by competing content providers of blocked content.
Sheharbano Khattak, Mobin Javed, Syed Ali Khayam, Zartash Afzal Uzmi, Vern Paxson
Internet Measurement Conference2
2014 Information theoretic feature space slicing for statistical anomaly detection
Ayesha Binte Ashfaq, Sajjad Rizvi, Mobin Javed, Syed Ali Khayam, Muhammad Qasim Ali, Ehab Al-Shaer
J. Netw. Comput. Appl.3
2013 Detecting stealthy, distributed SSH brute-forcing
abstract
In this work we propose a general approach for detecting distributed malicious activity in which individual attack sources each operate in a stealthy, low-profile manner. We base our approach on observing statistically significant changes in a parameter that summarizes aggregate activity, bracketing a distributed attack in time, and then determining which sources present during that interval appear to have coordinated their activity. We apply this approach to the problem of detecting stealthy distributed SSH bruteforcing activity, showing that we can model the process of legitimate users failing to authenticate using a beta-binomial distribution, which enables us to tune a detector that trades off an expected level of false positives versus time-to-detection. Using the detector we study the prevalence of distributed bruteforcing, finding dozens of instances in an extensive 8-year dataset collected from a site with several thousand SSH users. Many of the attacks---some of which last months---would be quite difficult to detect individually. While a number of the attacks reflect indiscriminant global probing, we also find attacks that targeted only the local site, as well as occasional attacks that succeeded.
Mobin Javed, Vern Paxson
CCS1
2013 Practical Comprehensive Bounds on Surreptitious Communication over DNS
Vern Paxson, Mihai Christodorescu, Mobin Javed, Josyula R. Rao, Reiner Sailer, Douglas Lee Schales, Marc Ph. Stoecklin, Kurt Thomas, Wietse Z. Venema, Nicholas Weaver
USENIX Security Symposium3
2011 Designing a cluster-based covert channel to evade disk investigation and forensics
Mobin Javed, Syed Ali Khayam, Fauzan Mirza
Comput. Secur.2
2010 An Information-Theoretic Combining Method for Multi-Classifier Anomaly Detection Systems
abstract
Recent studies have shown that standalone anomaly classifiers used by network anomaly detectors are unable to provide acceptable accuracies in real-world deployments. To achieve higher accuracies, Network Anomaly Detection Systems (NADSs) now use multiple classifiers whose outputs are combined to formulate an aggregate anomaly score. Judicious methods of combining these classifiers' outputs are largely unexplored. In this paper, we propose a novel information-theoretic combining method which caters for the individual classifiers' accuracies in a multi-classifier NADS. We first show that existing combining schemes designed for or adapted to the problem of multi-classifier NADS combining do not provide good accuracies because they do not use individual classifiers' detection and false alarm rates in the combining process. Furthermore, we reveal that an accurate multi-classifier NADS, in addition to catering for the mean accuracy rates, must also consider the classifiers' variances during combining. Therefore, we propose a Standard Deviation normalized Entropy of Accuracy (SDnEA) method for classifier combining. Using 9 prominent classifiers operating on two publicly-available traffic datasets, we show that around 3%-10% increase in detection rate and a 40% decrease in false alarm rate over existing combining techniques can be provided by the proposed information-theoretic NADS combining technique.
Ayesha Binte Ashfaq, Mobin Javed, Syed Ali Khayam, Hayder Radha
ICC2
2009 On the Inefficient Use of Entropy for Anomaly Detection
Mobin Javed, Ayesha Binte Ashfaq, Zubair Shafiq, Syed Ali Khayam
RAID1