EDBT 2026 Demo / reviewers in the wild / expert
Apu Kapadia
dblp:50/6916
· DBLP profile ↗
78ranked-venue papers
7as first author
17since 2021 · last 2026
0000-0003-4142-8444ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 37 · 14 since 2021Security and privacy · 36 · 6 first-author · 3 since 2021Systems, architecture and hardware · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Computer networks · 3Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | How Well do LLMs Assist Parents in Assessing Child Appropriateness of Videos?abstractChildren’s entertainment has become increasingly digital, with much of it available on video-sharing platforms. Although traditional media such as movies and TV are manually curated for appropriateness, the sheer quantity of videos being uploaded online makes this approach impractical. Current automated techniques fail to capture the diversity in parental supervision caused by varying parental preferences, culture, and other factors, while also lacking the transparency and explainability necessary to build parental trust. This study seeks to evaluate LLM’s ability to assess the appropriateness of videos for children under the age of 7 in an explainable manner and its overall alignment with parental values. Our study shows that while LLMs are less effective at determining appropriateness themselves, they can provide beneficial descriptions of the videos and effectively aid in the parental decision-making process. Sabila Nawshin, Ashley Phoebe Ishoel, Arun Balaji Buduru, Apu Kapadia |
CHI | 4 |
| 2026 | Think Twice: Improving Privacy Awareness with Tailored LLM-Powered Interventions
Sabid Bin Habib Pias, Christopher Nathaniel Page, Christine Chen, Mary Jean Amon, Apu Kapadia |
CHI | 5 |
| 2026 | "They are not my children to post": Examining Non-Parental Sharenting Practices in In-home Childcare
Meghna Gupta, Sophie Stephenson, Apu Kapadia, Julie A. Kientz, Franziska Roesner |
SOUPS | 3 |
| 2024 | Sharenting on TikTok: Exploring Parental Sharing Behaviors and the Discourse Around Children's Online PrivacyabstractSince the inception of social media, parents have been sharing information about their children online. Unfortunately, this “sharenting” can expose children to several online and offline risks. Although researchers have studied sharenting on multiple platforms, sharenting on short-form video platforms like TikTok—where posts can contain detailed information, spread quickly, and spark considerable engagement—is understudied. Thus, we provide a targeted exploration of sharenting on TikTok. We analyzed 328 TikTok videos that demonstrate sharenting and 438 videos where TikTok creators discuss sharenting norms. Our results indicate that sharenting on TikTok indeed creates several risks for children, not only within individual posts but also in broader patterns of sharenting that arise when parents repeatedly use children to generate viral content. At the same time, creators voiced sharenting concerns and boundaries that reflect what has been observed on other platforms, indicating the presence of cross-platform norms. Promisingly, we observed that TikTok users are engaging in thoughtful conversations around sharenting and beginning to shift norms toward safer sharenting. We offer concrete suggestions for designers and platforms based on our findings. Sophie Stephenson, Christopher Nathaniel Page, Miranda Wei, Apu Kapadia, Franziska Roesner |
CHI | 4 |
| 2023 | Bottom-up psychosocial interventions for interdependent privacy: Effectiveness based on individual and content differencesabstractAlthough a great deal of research has examined interventions to help users protect their own information online, less work has examined methods for reducing interdependent privacy (IDP) violations on social media (i.e., sharing of other people's information). This study tested the effectiveness of concept-based (i.e., general information), fact-based (i.e., statistics), and narrative-based (i.e., stories) educational videos in altering IDP-relevant attitudes and multimedia sharing behaviors. Our study revealed concept and fact videos reduced sharing of social media content that portrayed people negatively. The narrative intervention backfired and increased sharing among participants who did not believe IDP violations to be especially serious; however, the narrative intervention decreased sharing for participants who rated IDP violations as more serious. Notably, our study found participants preferred narrative-based interventions with real world examples, despite other strategies more effectively reducing sharing. Implications for narrative transportation theory and advancing bottom-up (i.e., user-centered) psychosocial interventions are discussed. Renita Washburn, Tangila Islam Tanni, Yan Solihin, Apu Kapadia, Mary Jean Amon |
CHI | 4 |
| 2023 | User Preferences for Interdependent Privacy Preservation Strategies in Social MediaabstractInterdependent privacy (IDP) violations occur when users share personal information about others without permission, resulting in potential embarrassment, reputation loss, or harassment. There are several strategies that can be applied to protect IDP, but little is known regarding how social media users perceive IDP threats or how they prefer to respond to them. We utilized a mixed-method approach with a replication study to examine user beliefs about various government-, platform-, and user-level strategies for managing IDP violations. Participants reported that IDP represented a 'serious' online threat, and identified themselves as primarily responsible for responding to violations. IDP strategies that felt more familiar and provided greater perceived control over violations (e.g., flagging, blocking, unfriending) were rated as more effective than platform or government driven interventions. Furthermore, we found users were more willing to share on social media if they perceived their interactions as protected. Findings are discussed in relation to control paradox theory. Aaron Necaise, Tangila Islam Tanni, Aneka Williams, Yan Solihin, Apu Kapadia, Mary Jean Amon |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2023 | Modeling User Characteristics Associated with Interdependent Privacy Perceptions on Social Mediaabstract“Interdependent” privacy violations occur when users share private photos and information about other people in social media without permission. This research investigated user characteristics associated with interdependent privacy perceptions, by asking social media users to rate photo-based memes depicting strangers on the degree to which they were too private to share. Users also completed questionnaires measuring social media usage and personality. Separate groups rated the memes on shareability, valence, and entertainment value. Users were less likely to share memes that were rated as private, except when the meme was entertaining or when users exhibited dark triad characteristics. Users with dark triad characteristics demonstrated a heightened awareness of interdependent privacy and increased sharing of others’ photos. A model is introduced that highlights user types and characteristics that correspond to different privacy preferences: privacy preservers, ignorers, and violators. We discuss how interventions to support interdependent privacy must effectively influence diverse users. Mary Jean Amon, Aaron Necaise, Nika Kartvelishvili, Aneka Williams, Yan Solihin, Apu Kapadia |
ACM Trans. Comput. Hum. Interact. | 6 |
| 2022 | The Impact of Viral Posts on Visibility and Behavior of Professionals: A Longitudinal Study of Scientists on Twitter
Rakibul Hasan 0001, Cristobal Cheyre, Yong-Yeol Ahn, Roberto Hoyle, Apu Kapadia |
ICWSM | 5 |
| 2022 | Preventing sensitive-word recognition using self-supervised learning to preserve user-privacy for automatic speech recognition
Apu Kapadia, Donald S. Williamson |
INTERSPEECH | 2 |
| 2022 | Tangible Privacy for Smart Voice Assistants: Bystanders' Perceptions of Physical Device ControlsabstractSmart voice assistants such as Amazon Alexa and Google Home are becoming increasingly pervasive in our everyday environments. Despite their benefits, their miniaturized and embedded cameras and microphones raise important privacy concerns related to surveillance and eavesdropping. Recent work on the privacy concerns of people in the vicinity of these devices has highlighted the need for 'tangible privacy', where control and feedback mechanisms can provide a more assured sense of whether the camera or microphone is 'on' or 'off'. However, current designs of these devices lack adequate mechanisms to provide such assurances. To address this gap in the design of smart voice assistants, especially in the case of disabling microphones, we evaluate several designs that incorporate (or not) tangible control and feedback mechanisms. By comparing people's perceptions of risk, trust, reliability, usability, and control for these designs in a between-subjects online experiment (N=261), we find that devices with tangible built-in physical controls are perceived as more trustworthy and usable than those with non-tangible mechanisms. Our findings present an approach for tangible, assured privacy especially in the context of embedded microphones. Taslima Akter, Zachary Buher, Rosta Farzan, Apu Kapadia, Adam J. Lee |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2022 | Sharenting and Children's Privacy in the United States: Parenting Style, Practices, and Perspectives on Sharing Young Children's Photos on Social MediaabstractParents posting photos and other information about children on social media is increasingly common and a recent source of controversy. We investigated characteristics that predict parental sharing behavior by collecting information from 493 parents of young children in the United States on self-reported demographics, social media activity, parenting styles, children's social media engagement, and parental sharing attitudes and behaviors. Our findings indicate that most social media active parents share photos of their children online and feel comfortable doing so without their child's permission. The strongest predictor of parental sharing frequency was general social media posting frequency, suggesting that participants do not strongly differentiate between "regular" photo-sharing activities and parental sharing. Predictors of parental sharing frequency include greater social media engagement, larger social networks with norms encouraging parental sharing, more permissive and confident parenting styles, and greater social media engagement by their children. Contrasting previous research that often highlights benefits of parental sharing, our findings point to a number of risky online behaviors associated with parental sharing not previously uncovered. Implications for children's privacy and early social media exposure are discussed, including future directions for influencing parental sharing attitudes and behaviors. Mary Jean Amon, Nika Kartvelishvili, Bennett I. Bertenthal, Kurt Hugenberg, Apu Kapadia |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2022 | "Adulthood is trying each of the same six passwords that you use for everything": The Scarcity and Ambiguity of Security Advice on Social MediaabstractIn order to keep one's computing systems and data secure, it is critical to be aware of how to effectively maintain security and privacy online. Prior experimental work has shown that social media are effective platforms for encouraging security-enhancing behavior. Through an analysis of historical social media logs of 38 participants containing almost 200,000 social media posts, we study the extent to which participants talked about security and privacy on social media platforms, specifically Facebook and Twitter. We found that interactions with posts that feature content relevant to security and privacy made up less than 0.09% of all interactions we observed. A thematic analysis of the security- and privacy-related posts that participants interacted with revealed that such posts very rarely discussed security and privacy constructively, instead often joking about security practices or encouraging undesirable behavior. Based on the overall findings from this thematic analysis, we develop and present a taxonomy of how security and privacy may be typically discussed on social networks, which is useful for constructing helpful security and privacy advice or for identifying advice that may have an undesirable impact. Our findings, though based on a fraction of the population of social media users, suggest that while social networks may be effective in influencing security behavior, there may not be enough substantial or useful discussions of security and privacy to encourage better security behaviors in practice and on a larger scale. Our findings highlight the importance of increasing the prevalence of constructive security and privacy advice on online social media in order to encourage widespread adoption of healthy security practices. Sruti Bhagavatula, Lujo Bauer, Apu Kapadia |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | Decaying Photos for Enhanced Privacy: User Perceptions Towards Temporal Redactions and 'Trusted' PlatformsabstractWith the rising popularity of photo sharing in online social media, interpersonal privacy violations, where one person violates the privacy of another, have become an increasing concern. Although applying image obfuscations can be a useful tool for improving privacy when sharing photos, prior studies have found these obfuscation techniques adversely affect viewers' satisfaction. On the other hand, ephemeral photos, popularized by apps such as Snapchat, allow viewers to see the entire photo, which then disappears shortly thereafter to protect privacy. However, people often use workarounds to save these photos before deletion. In this work, we study people's sharing preferences with two proposed 'temporal redactions', which combines ephemerality with redactions to allow viewers to see the entire image, yet make these images safe for longer storage through a gradual or delayed application of redaction on the sensitive portions of the photo. We conducted an online experiment (N=385) to study people's sharing behaviors in different contexts and under different levels of assurance provided by the viewer's platform (e.g., guaranteeing temporal redactions are applied through the use of 'trusted hardware'). Our findings suggest that the proposed temporal redaction mechanisms are often preferred over existing methods. On the other hand, more efforts are needed to convey the benefits of trusted hardware to users, as no significant differences were observed in attitudes towards 'trusted hardware' on viewers' devices. Sabid Bin Habib Pias, Taslima Akter, Apu Kapadia, Adam J. Lee |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2021 | Your Photo is so Funny that I don't Mind Violating Your Privacy by Sharing it: Effects of Individual Humor Styles on Online Photo-sharing BehaviorsabstractWe investigate how people’s ‘humor style’ relates to their online photo-sharing behaviors and reactions to ‘privacy primes’. In an online experiment, we queried 437 participants about their humor style, likelihood to share photo-memes, and history of sharing others’ photos. In two treatment conditions, participants were either primed to imagine themselves as the photo-subjects or to consider the photo-subjects’ privacy before sharing memes. We found that participants who frequently use aggressive and self-deprecating humor were more likely to violate others’ privacy by sharing photos. We also replicated the interventions’ paradoxical effects – increasing sharing likelihood – as reported in earlier work and identified the subgroups that demonstrated this behavior through interaction analyses. When primed to consider the subjects’ privacy, only humor deniers (participants who use humor infrequently) demonstrated increased sharing. In contrast, when imagining themselves as the photo-subjects, humor deniers, unlike other participants, did not increase the sharing of photos. Rakibul Hasan 0001, Bennett I. Bertenthal, Kurt Hugenberg, Apu Kapadia |
CHI | 4 |
| 2021 | Effect of Mood, Location, Trust, and Presence of Others on Video-Based Social Authentication
Cheng Guo 0003, Brianne Campbell, Apu Kapadia, Michael K. Reiter, Kelly Caine |
USENIX Security Symposium | 3 |
| 2021 | Does This Photo Make Me Look Good?: How Social Media Feedback on Photos Impacts Posters, Outsiders, and FriendsabstractIn recent years, the use and importance of visual communication through photos have grown considerably. However, we have little understanding of the alignment between the intentions of the photo posters and the reactions of viewers. To address this gap, we replicated previous work that studied the alignment of poster and outsider judgments of text posts by extending it to photo posts. In our study of 573 users across four social media platforms, we found that outsiders generally judge photo posts more positively than anticipated by posters. Examining viewer engagement on social media revealed that photos depicting family and friends receive fewer reactions. We apply our insight to propose novel solutions that can help users create a more positive digital presence by aligning their photo posts with the expectations of their audiences. Sanchari Das 0001, Tousif Ahmed, Apu Kapadia, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2021 | Defending Against Microphone-Based Attacks with Personalized NoiseabstractAbstract Voice-activated commands have become a key feature of popular devices such as smartphones, home assistants, and wearables. For convenience, many people configure their devices to be ‘always on’ and listening for voice commands from the user using a trigger phrase such as “Hey Siri,” “Okay Google,” or “Alexa.” However, false positives for these triggers often result in privacy violations with conversations being inadvertently uploaded to the cloud. In addition, malware that can record one’s conversations remains a signifi-cant threat to privacy. Unlike with cameras, which people can physically obscure and be assured of their privacy, people do not have a way of knowing whether their microphone is indeed off and are left with no tangible defenses against voice based attacks. We envision a general-purpose physical defense that uses a speaker to inject specialized obfuscating ‘babble noise’ into the microphones of devices to protect against automated and human based attacks. We present a comprehensive study of how specially crafted, personalized ‘babble’ noise (‘MyBabble’) can be effective at moderate signal-to-noise ratios and can provide a viable defense against microphone based eavesdropping attacks. Eun Ji Seong, Apu Kapadia, Donald S. Williamson |
Proc. Priv. Enhancing Technol. | 4 |
| 2020 | Privacy Considerations of the Visually Impaired with Camera Based Assistive Technologies: Misrepresentation, Impropriety, and FairnessabstractCamera based assistive technologies such as smart glasses can provide people with visual impairments (PVIs) information about people in their vicinity. Although such ‘visually available’ information can enhance one’s social interactions, the privacy implications for bystanders from the perspective of PVIs remains underexplored. Motivated by prior findings of bystanders’ perspectives, we conducted two online surveys with visually impaired (N=128) and sighted (N=136) participants with two ‘field-of-view’ (FoV) experimental conditions related to whether information about bystanders was gathered from the front of the glasses or all directions. We found that PVIs considered it as ‘fair’ and equally useful to receive information from all directions. However, they reported being uncomfortable in receiving some visually apparent information (such as weight and gender) about bystanders as they felt it was ‘impolite’ or ‘improper’. Both PVIs and bystanders shared concerns about the fallibility of AI, where bystanders can be misrepresented by the devices. Our finding suggests that beyond issues of social stigma, both PVIs and bystanders have shared concerns that need to be considered to improve the social acceptability of camera based assistive technologies. Taslima Akter, Tousif Ahmed, Apu Kapadia, S. Manohar 0001 |
ASSETS | 3 |
| 2020 | Visual Attention and Real-World Decision Making: Sharing Photos on Social Media
Shawn Fagan, Lauren Wade, Kurt Hugenberg, Apu Kapadia, Bennett I. Bertenthal |
CogSci | 4 |
| 2020 | Influencing Photo Sharing Decisions on Social Media: A Case of Paradoxical FindingsabstractWe investigate the effects of perspective taking, privacy cues, and portrayal of photo subjects (i.e., photo valence) on decisions to share photos of people via social media. In an online experiment we queried 379 participants about 98 photos (that were previously rated for photo valence) in three conditions: (1) Baseline: participants judged their likelihood of sharing each photo; (2) Perspective-taking: participants judged their likelihood of sharing each photo when cued to imagine they are the person in the photo; and (3) Privacy: participants judged their likelihood to share after being cued to consider the privacy of the person in the photo. While participants across conditions indicated a lower likelihood of sharing photos that portrayed people negatively, they - surprisingly - reported a higher likelihood of sharing photos when primed to consider the privacy of the person in the photo. Frequent photo sharers on real-world social media platforms and people without strong personal privacy preferences were especially likely to want to share photos in the experiment, regardless of how the photo portrayed the subject. A follow-up study with 100 participants explaining their responses revealed that the Privacy condition led to a lack of concern with others' privacy. These findings suggest that developing interventions for reducing photo sharing and protecting the privacy of others is a multivariate problem in which seemingly obvious solutions can sometimes go awry. Mary Jean Amon, Rakibul Hasan 0001, Kurt Hugenberg, Bennett I. Bertenthal, Apu Kapadia |
SP | 5 |
| 2020 | Automatically Detecting Bystanders in Photos to Reduce Privacy RisksabstractPhotographs taken in public places often contain bystanders - people who are not the main subject of a photo. These photos, when shared online, can reach a large number of viewers and potentially undermine the bystanders' privacy. Furthermore, recent developments in computer vision and machine learning can be used by online platforms to identify and track individuals. To combat this problem, researchers have proposed technical solutions that require bystanders to be proactive and use specific devices or applications to broadcast their privacy policy and identifying information to locate them in an image.We explore the prospect of a different approach - identifying bystanders solely based on the visual information present in an image. Through an online user study, we catalog the rationale humans use to classify subjects and bystanders in an image, and systematically validate a set of intuitive concepts (such as intentionally posing for a photo) that can be used to automatically identify bystanders. Using image data, we infer those concepts and then use them to train several classifier models. We extensively evaluate the models and compare them with human raters. On our initial dataset, with a 10-fold cross validation, our best model achieves a mean detection accuracy of 93% for images when human raters have 100% agreement on the class label and 80% when the agreement is only 67%. We validate this model on a completely different dataset and achieve similar results, demonstrating that our model generalizes well. Rakibul Hasan 0001, David Crandall, Mario Fritz, Apu Kapadia |
SP | 4 |
| 2020 | "I am uncomfortable sharing what I can't see": Privacy Concerns of the Visually Impaired with Camera Based Assistive Applications
Taslima Akter, Bryan Dosono, Tousif Ahmed, Apu Kapadia, Bryan C. Semaan |
USENIX Security Symposium | 4 |
| 2020 | Tangible Privacy: Towards User-Centric Sensor Designs for Bystander PrivacyabstractSensor-enabled computers in the form of 'IoT' devices such as home security cameras and voice assistants are increasingly becoming pervasive in our environment. With the embedded cameras and microphones in these devices, this 'invasion' of our everyday spaces can pose significant threats to the privacy of bystanders. Because of their complex functionality, even when people attempt privacy measures (such as asking the owner to "turn the camera off"), these devices may still record information because of the lack of a 'real' off button. With the ambiguities of current designs, a bystander's perceived privacy can diverge from their actual privacy. Indeed, being able to assess one's actual privacy is a key aspect in managing one's privacy according to Altman's theory of boundary regulation, and current designs fall short in assuring people of their privacy. To understand how people as bystanders manage their privacy with IoT devices, we conducted an interview study about people's perceptions of and behaviors around current IoT devices. We find that although participants' behaviors line up with Altman's theory of boundary regulation, in the face of uncertainty about their privacy, they desire or engage in various 'tangible' workarounds. Based on our findings, we identify and introduce the concept of 'tangible privacy' as being essential to boundary regulation with IoT devices. We argue that IoT devices should be designed in a way that clearly and unambiguously conveys sensor states to people around them and make actionable design recommendations to provide strong privacy assurances to bystanders. Rosta Farzan, Apu Kapadia, Adam J. Lee |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2020 | "It's easier than causing confrontation": Sanctioning Strategies to Maintain Social Norms and Privacy on Social MediaabstractSanctions play an essential role in enforcing and sustaining social norms. On social networking sites (SNS), sanctions allow individuals to shape community norms on appropriate privacy respecting behaviors. Existing theories of privacy assume the use of such sanctions but do not examine the extent and effectiveness of sanctioning behaviors. We conducted a qualitative interview study of young adults (N=23), and extend research on collective boundary regulation by studying sanctions in the context of popular SNS. Through a systematization of sanctioning strategies, we find that young adults prefer to use indirect and invisible sanctions to preserve strong-tie relationships. Such sanctions are not always effective in helping the violator understand the nature of their normative violation. We offer suggestions on supporting online sanctioning that make norms more visible and signal violations in ways that avoid direct confrontation to reduce the risk of harming on-going social relationships. Yasmeen Rashidi, Apu Kapadia, Christena Nippert-Eng, Norman Makoto Su |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2020 | Privacy Norms and Preferences for Photos Posted OnlineabstractWe are surrounded by digital images of personal lives posted online. Changes in information and communications technology have enabled widespread sharing of personal photos, increasing access to aspects of private life previously less observable. Most studies of privacy online explore differences in individual privacy preferences. Here we examine privacy perceptions of online photos considering both social norms, collectively—shared expectations of privacy and individual preferences. We conducted an online factorial vignette study on Amazon’s Mechanical Turk ( n = 279). Our findings show that people share common expectations about the privacy of online images, and these privacy norms are socially contingent and multidimensional. Use of digital technologies to share personal photos is influenced by social context as well as individual preferences, while such sharing can affect the social meaning of privacy. Roberto Hoyle, Luke Stark, Qatrunnada Ismail, David Crandall, Apu Kapadia, Denise L. Anthony |
ACM Trans. Comput. Hum. Interact. | 5 |
| 2019 | Can Privacy Be Satisfying?: On Improving Viewer Satisfaction for Privacy-Enhanced Photos Using Aesthetic TransformsabstractPervasive photo sharing in online social media platforms can cause unintended privacy violations when elements of an image reveal sensitive information. Prior studies have identified image obfuscation methods (e.g., blurring) to enhance privacy, but many of these methods adversely affect viewers' satisfaction with the photo, which may cause people to avoid using them. In this paper, we study the novel hypothesis that it may be possible to restore viewers' satisfaction by 'boosting' or enhancing the aesthetics of an obscured image, thereby compensating for the negative effects of a privacy transform. Using a between-subjects online experiment, we studied the effects of three artistic transformations on images that had objects obscured using three popular obfuscation methods validated by prior research. Our findings suggest that using artistic transformations can mitigate some negative effects of obfuscation methods, but more exploration is needed to retain viewer satisfaction. Rakibul Hasan 0001, Yifang Li, Eman T. Hassan, Kelly Caine, David Crandall, Roberto Hoyle, Apu Kapadia |
CHI | 7 |
| 2018 | Viewer Experience of Obscuring Scene Elements in Photos to Enhance PrivacyabstractWith the rise of digital photography and social networking, people are sharing personal photos online at an unprecedented rate. In addition to their main subject matter, photographs often capture various incidental information that could harm people's privacy. While blurring and other image filters may help obscure private content, they also often affect the utility and aesthetics of the photos, which is important since images shared in social media are mainly for human consumption. Existing studies of privacy-enhancing image filters either primarily focus on obscuring faces, or do not systematically study how filters affect image utility. To understand the trade-offs when obscuring various sensitive aspects of images, we study eleven filters applied to obfuscate twenty different objects and attributes, and evaluate how effectively they protect privacy and preserve image quality for human viewers. Rakibul Hasan 0001, Eman T. Hassan, Yifang Li, Kelly Caine, David Crandall, Roberto Hoyle, Apu Kapadia |
CHI | 7 |
| 2017 | Was my message read?: Privacy and Signaling on Facebook MessengerabstractMajor online messaging services such as Facebook Messenger and WhatsApp are starting to provide users with real-time information about when people read their messages, while useful, the feature has the potential to negatively impact privacy as well as cause concern over access to self. We report on two surveys using Mechanical Turk which looked at senders' (N=402} use of and reactions to the `message seen' feature, and recipients' (N=316) privacy and signaling behaviors in the face of such visibility. Our findings indicate that senders experience a range of emotions when their message is not read, or is read but not answered immediately. Recipients also engage in various signaling behaviors in the face of visibility by both replying or not replying immediately. Roberto Hoyle, Srijita Das 0001, Apu Kapadia, Adam J. Lee, Kami Vaniea |
CHI | 3 |
| 2017 | Viewing the Viewers: Publishers' Desires and Viewers' Privacy Concerns in Social NetworksabstractSocial networking sites are starting to provide users with services that expose information about their audiences' composition and behavior, such as LinkedIn's 'Who's viewed my profile' feature. Providing information about content viewers to content publishers, however, raises new privacy concerns for viewers themselves, possibly creating a chilling effect on viewer behavior. We report on a study of 718 respondents using Mechanical Turk across two surveys to study publishers' (N=402) use and expectations of information about their viewers, and viewers' (N=316) privacy behaviors and concerns in the face of such visibility. Our findings indicate that publishers are generally mindful of viewers' privacy; viewers engage in various self-censorship behaviors in the face of visibility; and in some cases (e.g., dating sites) significant gender differences exist about what information respondents felt should be shared with publishers and required of viewers. Roberto Hoyle, Srijita Das 0001, Apu Kapadia, Adam J. Lee, Kami Vaniea |
CSCW | 3 |
| 2017 | Challenges in Transitioning from Civil to Military Culture: Hyper-Selective Disclosure through ICTsabstractA critical element for a successful transition is the ability to disclose, or make known, one's struggles. We explore the transition disclosure practices of Reserve Officers' Training Corps (ROTC) students who are transitioning from an individualistic culture to one that is highly collective. As ROTC students routinely evaluate their peers through a ranking system, the act of disclosure may impact a student's ability to secure limited opportunities within the military upon graduation. Through a qualitative interview study of active ROTC students (N=14) examining how they use information communication technologies (ICTs) to disclose their struggles in a hyper-competitive environment, we find they engage in a process of highly selective disclosure, choosing different groups with which to disclose based on the types of issues they face. We share implications for designing ICTs that better facilitate how ROTC students cope with personal challenges during their formative transition into the military. Bryan Dosono, Yasmeen Rashidi, Taslima Akter, Bryan C. Semaan, Apu Kapadia |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2017 | To Permit or Not to Permit, That is the Usability Question: Crowdsourcing Mobile Apps' Privacy Permission SettingsabstractAbstract Millions of apps available to smartphone owners request various permissions to resources on the devices including sensitive data such as location and contact information. Disabling permissions for sensitive resources could improve privacy but can also impact the usability of apps in ways users may not be able to predict. We study an efficient approach that ascertains the impact of disabling permissions on the usability of apps through large-scale, crowdsourced user testing with the ultimate goal of making recommendations to users about which permissions can be disabled for improved privacy without sacrificing usability. We replicate and significantly extend previous analysis that showed the promise of a crowdsourcing approach where crowd workers test and report back on various configurations of an app. Through a large, between-subjects user experiment, our work provides insight into the impact of removing permissions within and across different apps (our participants tested three apps: Facebook Messenger (N=218), Instagram (N=227), and Twitter (N=110)). We study the impact of removing various permissions within and across apps, and we discover that it is possible to increase user privacy by disabling app permissions while also maintaining app usability. Qatrunnada Ismail, Tousif Ahmed, Kelly Caine, Apu Kapadia, Michael K. Reiter |
Proc. Priv. Enhancing Technol. | 4 |
| 2016 | Enhancing Lifelogging Privacy by Detecting ScreensabstractLow-cost, lightweight wearable cameras let us record (or 'lifelog') our lives from a 'first-person' perspective for purposes ranging from fun to therapy. But they also capture private information that people may not want to be recorded, especially if images are stored in the cloud or visible to other people. For example, recent studies suggest that computer screens may be lifeloggers' single greatest privacy concern, because many people spend a considerable amount of time in front of devices that display private information. In this paper, we investigate using computer vision to automatically detect computer screens in photo lifelogs. We evaluate our approach on an existing in-situ dataset of 36 people who wore cameras for a week, and show that our technique could help manage privacy in the upcoming era of wearable cameras. Mohammed Korayem, Robert Templeman, Dennis Chen, David Crandall, Apu Kapadia |
CHI | 5 |
| 2016 | Twitter's Glass Ceiling: The Effect of Perceived Gender on Online Visibility
Shirin Nilizadeh, Anne Groggel, Peter Lista, Srijita Das 0001, Yong-Yeol Ahn, Apu Kapadia, Fabio Rojas |
ICWSM | 6 |
| 2016 | Addressing Physical Safety, Security, and Privacy for People with Visual Impairments
Tousif Ahmed, Patrick Shaffer, Kay Connelly, David Crandall, Apu Kapadia |
SOUPS | 5 |
| 2016 | Editors' Introduction
Claudia Díaz, Apu Kapadia |
Proc. Priv. Enhancing Technol. | 2 |
| 2016 | Editors' Introduction
Claudia Díaz, Apu Kapadia |
Proc. Priv. Enhancing Technol. | 2 |
| 2016 | Editors' Introduction
Claudia Díaz, Apu Kapadia |
Proc. Priv. Enhancing Technol. | 2 |
| 2016 | Editor's Introduction
Apu Kapadia |
Proc. Priv. Enhancing Technol. | 1 |
| 2015 | Privacy Concerns and Behaviors of People with Visual ImpairmentsabstractVarious technologies have been developed to help make the world more accessible to visually impaired people, and recent advances in low-cost wearable and mobile computing are likely to drive even moreadvances. However, the unique privacy and security needs of visually impaired people remain largely unaddressed. We conducted an exploratory user study with 14 visually impaired participants to understand the techniques they currently use for protecting privacy, their remaining privacy concerns,and how new technologies may be able to help. The interviews explored privacy not only in the physical world (e.g., bystanders overhearing private conversations) and the online world (e.g., determining if a URL is legitimate), but also in the interface between the two (e.g. bystanders `shoulder-surfing' data from screens). The study revealed serious concerns that are not adequately solved by current technology, and suggested new directions for improving the privacy of this significant fraction of the population. Tousif Ahmed, Roberto Hoyle, Kay Connelly, David Crandall, Apu Kapadia |
CHI | 5 |
| 2015 | Sensitive Lifelogs: A Privacy Analysis of Photos from Wearable CamerasabstractWhile media reports about wearable cameras have focused on the privacy concerns of bystanders, the perspectives of the `lifeloggers' themselves have not been adequately studied. We report on additional analysis of our previous in-situ lifelogging study in which 36 participants wore a camera for a week and then reviewed the images to specify privacy and sharing preferences. In this Note, we analyze the photos themselves, seeking to understand what makes a photo private, what participants said about their images, and what we can learn about privacy in this new and very different context where photos are captured automatically by one's wearable camera. We find that these devices record many moments that may not be captured by traditional (deliberate) photography, with camera owners concerned about impression management and protecting private information of both themselves and bystanders. Roberto Hoyle, Robert Templeman, Denise L. Anthony, David Crandall, Apu Kapadia |
CHI | 5 |
| 2015 | Crowdsourced Exploration of Security ConfigurationsabstractSmartphone apps today request permission to access a multitude of sensitive resources, which users must accept completely during installation (e.g., on Android) or selectively configure after installation (e.g., on iOS, but also planned for Android). Everyday users, however, do not have the ability to make informed decisions about which permissions are essential for their usage. For enhanced privacy, we seek to leverage crowdsourcing to find minimal sets of permissions that will preserve the usability of the app for diverse users. We advocate an efficient 'lattice-based' crowd-management strategy to explore the space of permissions sets. We conducted a user study (N = 26) in which participants explored different permission sets for the popular Instagram app. This study validates our efficient crowd management strategy and shows that usability scores for diverse users can be predicted accurately, enabling suitable recommendations. Qatrunnada Ismail, Tousif Ahmed, Apu Kapadia, Michael K. Reiter |
CHI | 3 |
| 2015 | Interrupt Now or Inform Later?: Comparing Immediate and Delayed Privacy FeedbackabstractFeedback about privacy-affecting system operations is important for informed end-user privacy management. While feedback is most relevant if provided immediately, such delivery interrupts the user and risks disrupting ongoing tasks. The timing, volume, and nature of feedback is therefore critical for avoiding inopportune interruption. We varied the timing and actionability of feedback regarding accesses to a user's physical location. We found that the sense of privacy violation was heightened when feedback was immediate, but not actionable. While immediate and actionable feedback may sometimes be necessary, our findings suggest that moderately delayed feedback is often acceptable. A moderate delay may serve as a compromise to minimize interruption and avoid overly alarming reaction to immediate feedback. However, immediate and actionable feedback could still be beneficial when privacy sensitivity is high or ambiguous. Sameer Patil 0001, Roberto Hoyle, Roman Schlegel, Apu Kapadia, Adam J. Lee |
CHI | 4 |
| 2015 | Editors' Introduction
Apu Kapadia, Steven J. Murdoch |
Proc. Priv. Enhancing Technol. | 1 |
| 2015 | Editors' Introduction
Apu Kapadia, Steven J. Murdoch |
Proc. Priv. Enhancing Technol. | 1 |
| 2014 | Community-Enhanced De-anonymization of Online Social NetworksabstractOnline social network providers have become treasure troves of information for marketers and researchers. To profit from their data while honoring the privacy of their customers, social networking services share `anonymized' social network datasets, where, for example, identities of users are removed from the social network graph. However, by using external information such as a reference social graph (from the same network or another network with similar users), researchers have shown how such datasets can be de-anonymized. These approaches use `network alignment' techniques to map nodes from the reference graph into the anonymized graph and are often sensitive to larger network sizes, the number of seeds, and noise --- which may be added to preserve privacy. We propose a divide-and-conquer approach to strengthen the power of such algorithms. Our approach partitions the networks into `communities' and performs a two-stage mapping: first at the community level, and then for the entire network. Through extensive simulation on real-world social network datasets, we show how such community-aware network alignment improves de-anonymization performance under high levels of noise, large network sizes, and a low number of seeds. Even when nodes cannot be explicitly mapped, the community structure can be mapped between both networks, thus reducing the anonymity of users. For example, for our (real-world) Twitter dataset with 90,000 nodes, 20% noise, and 16 seeds, the state-of-the-art technique reduces anonymity by 0 bits, whereas our approach reduces anonymity by 9.71 bits (with 40% of nodes mapped). Shirin Nilizadeh, Apu Kapadia, Yong-Yeol Ahn |
CCS | 2 |
| 2014 | Reflection or action?: how feedback and control affect location sharing decisionsabstractOwing to the ever-expanding size of social and professional networks, it is becoming cumbersome for individuals to configure information disclosure settings. We used location sharing systems to unpack the nature of discrepancies between a person's disclosure settings and contextual choices. We conducted an experience sampling study (N = 35) to examine various factors contributing to such divergence. We found that immediate feedback about disclosures without any ability to control the disclosures evoked feelings of oversharing. Moreover, deviation from specified settings did not always signal privacy violation; it was just as likely that settings prevented information disclosure considered permissible in situ. We suggest making feedback more actionable or delaying it sufficiently to avoid a knee-jerk reaction. Our findings also make the case for proactive techniques for detecting potential mismatches and recommending adjustments to disclosure settings, as well as selective control when sharing location with socially distant recipients and visiting atypical locations. Sameer Patil 0001, Roman Schlegel, Apu Kapadia, Adam J. Lee |
CHI | 3 |
| 2014 | Defending against device theft with human notarizationabstractPeople increasingly rely on mobile phones for storing sensitive information and credentials for access to services. Because these devices are vulnerable to theft, security of this data is put at higher risk - once the attacker is in physical possession of the device, recovering these credentials and Alana Libonati, Kelly Caine, Apu Kapadia, Michael K. Reiter |
CollaborateCom | 3 |
| 2014 | Privacy behaviors of lifeloggers using wearable camerasabstractA number of wearable 'lifelogging' camera devices have been released recently, allowing consumers to capture images and other sensor data continuously from a first-person perspective. Unlike traditional cameras that are used deliberately and sporadically, lifelogging devices are always 'on' and automatically capturing images. Such features may challenge users' (and bystanders') expectations about privacy and control of image gathering and dissemination. While lifelogging cameras are growing in popularity, little is known about privacy perceptions of these devices or what kinds of privacy challenges they are likely to create. Roberto Hoyle, Robert Templeman, Steven Armes, Denise L. Anthony, David Crandall, Apu Kapadia |
UbiComp | 6 |
| 2014 | PlaceAvoider: Steering First-Person Cameras away from Sensitive Spaces
Robert Templeman, Mohammed Korayem, David Crandall, Apu Kapadia |
NDSS | 4 |
| 2014 | Short paper: "here i am, now pay me!": privacy concerns in incentivised location-sharing systemsabstractSocial network sites, location-sharing services and, more recently, applications enabling the quantified self, mean that people are generating and sharing more data than ever before. It is important to understand the potential privacy impacts when such personal data are commercialised, to ensure that expectations of privacy are preserved. This paper presents the first user study of incentivised location sharing, where people are given a direct monetary incentive to share their location with a business or their social network. We use Nissenbaum's framework of contextual integrity in a preliminary user study (n=22) to investigate potential privacy risks with such services. We find that monetisation changes why people share their data, but not the frequency of disclosures. Our results motivate further study and are useful for designers of location-sharing systems and researchers who wish to leverage the diverse range of personal data that are available in a privacy-sensitive manner. Luke Hutton, Tristan Henderson, Apu Kapadia |
WISEC | 3 |
| 2014 | ReDS: A Framework for Reputation-Enhanced DHTsabstractDistributed hash tables (DHTs), such as Chord and Kademlia, offer an efficient means to locate resources in peer-to-peer networks. Unfortunately, malicious nodes on a lookup path can easily subvert such queries. Several systems, including Halo (based on Chord) and Kad (based on Kademlia), mitigate such attacks by using redundant lookup queries. Much greater assurance can be provided; we present Reputation for Directory Services (ReDS), a framework for enhancing lookups in redundant DHTs by tracking how well other nodes service lookup requests. We describe how the ReDS technique can be applied to virtually any redundant DHT including Halo and Kad. We also study the collaborative identification and removal of bad lookup paths in a way that does not rely on the sharing of reputation scores, and we show that such sharing is vulnerable to attacks that make it unsuitable for most applications of ReDS. Through extensive simulations, we demonstrate that ReDS improves lookup success rates for Halo and Kad by 80 percent or more over a wide range of conditions, even against strategic attackers attempting to game their reputation scores and in the presence of node churn. Ruj Akavipat, Mahdi N. Al-Ameen, Apu Kapadia, Zahid Rahman, Roman Schlegel, Matthew Wright 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2013 | Peer-produced privacy protectionabstractPrivacy risks have been addressed through technical solutions such as Privacy-Enhancing Technologies (PETs) as well as regulatory measures including Do Not Track. These approaches are inherently limited as they are grounded in the paradigm of a rational end user who can determine, articulate, and manage consistent privacy preferences. This assumes that self-serving efforts to enact privacy preferences lead to socially optimal outcomes with regard to information sharing. We argue that this assumption typically does not hold true. Consequently, solutions to specific risks are developed - even mandated - without effective reduction in the overall harm of privacy breaches. We present a systematic framework to examine these limitations of current technical and policy solutions. To address the shortcomings of existing privacy solutions, we argue for considering information sharing to be transactions within a community. Outcomes of privacy management can be improved at a lower overall cost if peers, as a community, are empowered by appropriate technical and policy mechanisms. Designing for a community requires encouraging dialogue, enabling transparency, and supporting enforcement of community norms. We describe how peer production of privacy is possible through PETs that are grounded in the notion of information as a common-pool resource subject to community governance. Sameer Patil 0001, Apu Kapadia, L. Jean Camp |
ISTAS | 3 |
| 2013 | PlaceRaider: Virtual Theft in Physical Spaces with Smartphones
Robert Templeman, Zahid Rahman, David Crandall, Apu Kapadia |
NDSS | 4 |
| 2012 | PERM: practical reputation-based blacklisting without TTPSabstractSome users may misbehave under the cover of anonymity by, e.g., defacing webpages on Wikipedia or posting vulgar comments on YouTube. To prevent such abuse, a few anonymous credential schemes have been proposed that revoke access for misbehaving users while maintaining their anonymity such that no trusted third party (TTP) is involved in the revocation process. Recently we proposed BLACR, a TTP-free scheme that supports `reputation-based blacklisting' --- the service provider can score users' anonymous sessions (e.g., good vs. inappropriate comments) and users with insufficient reputation are denied access. Man Ho Au, Apu Kapadia |
CCS | 2 |
| 2012 | Cachet: a decentralized architecture for privacy preserving social networking with cachingabstractOnline social networks (OSNs) such as Facebook and Google+ have transformed the way our society communicates. However, this success has come at the cost of user privacy; in today's OSNs, users are not in control of their own data, and depend on OSN operators to enforce access control policies. A multitude of privacy breaches has spurred research into privacy-preserving alternatives for social networking, exploring a number of techniques for storing, disseminating, and controlling access to data in a decentralized fashion. In this paper, we argue that a combination of techniques is necessary to efficiently support the complex functionality requirements of OSNs. Shirin Nilizadeh, Sonia Jahid, Prateek Mittal, Nikita Borisov, Apu Kapadia |
CoNEXT | 5 |
| 2012 | BLACR: TTP-Free Blacklistable Anonymous Credentials with Reputation
Man Ho Au, Apu Kapadia, Willy Susilo |
NDSS | 2 |
| 2012 | Pools, clubs and security: designing for a party not a personabstractSecurity solutions fail not only because of technological or usability limitations, but also due to economic constraints and lack of coordinated adoption. Existing research conceptualizes security as a public good suffering from underinvestment, or as a private good with externalities, i.e. consequences that are not part of the price. It is also difficult to distinguish high and low quality security products, thus where there is incentive the resulting investments may be misdirected. We argue for a new paradigm of security solutions designed for communities rather than individuals. We leverage canonical economic theory of 'club goods' and 'common-pool resources' to encourage security through collective action and peer production. We operationalize these by providing examples of security solutions redesigned as club or pool goods. Investigating the paradigm of cooperation through community informs novel solutions that impinge on real world security and we advocate further research to enable this shift. L. Jean Camp, Apu Kapadia |
NSPW | 4 |
| 2012 | PlexC: a policy language for exposure controlabstractWith the widespread use of online social networks and mobile devices, it is not uncommon for people to continuously broadcast contextual information such as their current location or activity. These technologies present both new opportunities for social engagement and new risks to privacy, and traditional static "write once" disclosure policies are not well suited for controlling aggregate exposure risks in the current technological landscape. Yann Le Gall, Adam J. Lee, Apu Kapadia |
SACMAT | 3 |
| 2012 | Reasons, rewards, regrets: privacy considerations in location sharing as an interactive practiceabstractRapid growth in the usage of location-aware mobile phones has enabled mainstream adoption of location-sharing services (LSS). Integration with social-networking services (SNS) has further accelerated this trend. To uncover how these developments have shaped the evolution of LSS usage, we conducted an online study (N = 362) aimed at understanding the preferences and practices of LSS users in the US. We found that the main motivations for location sharing were to connect and coordinate with one's social and professional circles, to project an interesting image of oneself, and to receive rewards offered for 'checking in.' Respondents overwhelmingly preferred sharing location only upon explicit action. More than a quarter of the respondents recalled at least one instance of regret over revealing their location. Our findings suggest that privacy considerations in LSS are affected due to integration within SNS platforms and by transformation of location sharing into an interactive practice that is no longer limited only to finding people based on their whereabouts. We offer design suggestions, such as delayed disclosure and conflict detection, to enhance privacy-management capabilities of LSS. Sameer Patil 0001, Gregory Norcie, Apu Kapadia, Adam J. Lee |
SOUPS | 3 |
| 2012 | GANGRENE: Exploring the Mortality of Flash Memory
Robert Templeman, Apu Kapadia |
HotSec | 2 |
| 2011 | Soundcomber: A Stealthy and Context-Aware Sound Trojan for Smartphones
Roman Schlegel, Kehuan Zhang, Xiao-yong Zhou, Mehool Intwala, Apu Kapadia, XiaoFeng Wang 0001 |
NDSS | 5 |
| 2011 | Eyeing your exposure: quantifying and controlling information sharing for improved privacyabstractA large body of research has focused on disclosure policies for controlling information release in social sharing (e.g., location-based) applications. However, less work has considered how exposed these policies actually leave users; i.e., to what extent are disclosures in compliance with these policies actually being made? For instance, consider a disclosure policy granting Alice's coworkers access to her location during work hours. Alice might feel that this policy appropriately controls her exposure, but may feel differently if she learned that her boss was accessing her location every 5 minutes. In addition to specifying who has access to personal information, users need a way to quantify, interpret, and control the extent to which this data is shared. Roman Schlegel, Apu Kapadia, Adam J. Lee |
SOUPS | 2 |
| 2011 | AnonySense: A system for anonymous opportunistic sensing
Minho Shin, Cory Cornelius, Daniel Peebles, Apu Kapadia, David Kotz, Nikos Triandopoulos |
Pervasive Mob. Comput. | 4 |
| 2011 | Nymble: Blocking Misbehaving Users in Anonymizing NetworksabstractAnonymizing networks such as Tor allow users to access Internet services privately by using a series of routers to hide the client's IP address from the server. The success of such networks, however, has been limited by users employing this anonymity for abusive purposes such as defacing popular Web sites. Web site administrators routinely rely on IP-address blocking for disabling access to misbehaving users, but blocking IP addresses is not practical if the abuser routes through an anonymizing network. As a result, administrators block all known exit nodes of anonymizing networks, denying anonymous access to misbehaving and behaving users alike. To address this problem, we present Nymble, a system in which servers can “blacklist” misbehaving users, thereby blocking users without compromising their anonymity. Our system is thus agnostic to different servers' definitions of misbehavior-servers can blacklist users for whatever reason, and the privacy of blacklisted users is maintained. Patrick P. Tsang, Apu Kapadia, Cory Cornelius, Sean W. Smith |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2011 | PEREA: Practical TTP-free revocation of repeatedly misbehaving anonymous usersabstractSeveral anonymous authentication schemes allow servers to revoke a misbehaving user's ability to make future accesses. Traditionally, these schemes have relied on powerful Trusted Third Parties (TTPs) capable of deanonymizing (or linking) users' connections. Such TTPs are undesirable because users' anonymity is not guaranteed, and users must trust them to judge misbehaviors fairly. Recent schemes such as Blacklistable Anonymous Credentials (BLAC) and Enhanced Privacy ID (EPID) support “privacy-enhanced revocation”— servers can revoke misbehaving users without a TTP's involvement, and without learning the revoked users' identities. In BLAC and EPID, however, the computation required for authentication at the server is linear in the size (L) of the revocation list , which is impractical as the size approaches thousands of entries. We propose PEREA, a new anonymous authentication scheme for which this bottleneck computation is independent of the size of the revocation list . Instead, the time complexity of authentication is linear in the size of a revocation window K ≪ L , the number of subsequent authentications before which a user's misbehavior must be recognized if the user is to be revoked. We extend PEREA to support more complex revocation policies that take the severity of misbehaviors into account. Users can authenticate anonymously if their naughtiness , i.e., the sum of the severities of their blacklisted misbehaviors, is below a certain naughtiness threshold. We call our extension PEREA-Naughtiness. We prove the security of our constructions, and validate their efficiency as compared to BLAC analytically and quantitatively. Man Ho Au, Patrick P. Tsang, Apu Kapadia |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2010 | BLAC: Revoking Repeatedly Misbehaving Anonymous Users without Relying on TTPsabstractSeveral credential systems have been proposed in which users can authenticate to service providers anonymously. Since anonymity can give users the license to misbehave, some variants allow the selective deanonymization (or linking) of misbehaving users upon a complaint to a Trusted Third Party (TTP). The ability of the TTP to revoke a user’s privacy at any time, however, is too strong a punishment for misbehavior. To limit the scope of deanonymization, some systems have been proposed in which users can be deanonymized only if they authenticate “too many times,” such as “double spending” with electronic cash. While useful in some applications, such techniques cannot be generalized to more subjective definitions of misbehavior, for example, using such schemes it is not possible to block anonymous users who “deface too many Web pages” on a Web site. We present BLAC, the first anonymous credential system in which service providers can revoke the credentials of misbehaving users without relying on a TTP . Since revoked users remain anonymous, misbehaviors can be judged subjectively without users fearing arbitrary deanonymization by a TTP . Additionally, our construction supports a d-strikes-out revocation policy, whereby users who have been subjectively judged to have repeatedly misbehaved at least d times are revoked from the system. Thus, for the first time, it is indeed possible to block anonymous users who have “defaced too many Web pages” using our scheme. Patrick P. Tsang, Man Ho Au, Apu Kapadia, Sean W. Smith |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2008 | PEREA: towards practical TTP-free revocation in anonymous authenticationabstractSeveral anonymous authentication schemes allow servers to revoke a misbehaving user's ability to make future accesses. Traditionally, these schemes have relied on powerful TTPs capable of deanonymizing (or linking) users' connections. Recent schemes such as Blacklistable Anonymous Credentials (BLAC) and Enhanced Privacy ID (EPID) support privacy-enhanced -- servers can revoke misbehaving users without a TTP's involvement, and without learning the revoked users' identities.In BLAC and EPID, however, the computation required for authentication at the server is linear in the size (L) of the revocation list. We propose PEREA, a new anonymous authentication scheme for which this bottleneck computation is independent of the size of the revocation list. Instead, the time complexity of authentication is linear in the size (K Patrick P. Tsang, Man Ho Au, Apu Kapadia, Sean W. Smith |
CCS | 3 |
| 2008 | Anonysense: privacy-aware people-centric sensingabstractPersonal mobile devices are increasingly equipped with the capability to sense the physical world (through cameras, microphones, and accelerometers, for example) and the, network world (with Wi-Fi and Bluetooth interfaces). Such devices offer many new opportunities for cooperative sensing applications. For example, users' mobile phones may contribute data to community-oriented information services, from city-wide pollution monitoring to enterprise-wide detection of unauthorized Wi-Fi access points. This people-centric mobile-sensing model introduces a new security challenge in the design of mobile systems: protecting the privacy of participants while allowing their devices to reliably contribute high-quality data to these large-scale applications. Cory Cornelius, Apu Kapadia, David Kotz, Daniel Peebles, Minho Shin, Nikos Triandopoulos |
MobiSys | 2 |
| 2008 | Halo: High-Assurance Locate for Distributed Hash Tables
Apu Kapadia, Nikos Triandopoulos |
NDSS | 1 |
| 2007 | Blacklistable anonymous credentials: blocking misbehaving users without ttpsabstractSeveral credential systems have been proposed in which users can authenticate to services anonymously. Since anonymity can give users the license to misbehave, some variants allow the selective deanonymization (or linking) of misbehaving users upon a complaint to a trusted third party (TTP). The ability of the TTP to revoke a user's privacy at any time, however, is too strong a punishment for misbehavior. To limit the scope of deanonymization, systems such as "e-cash" have been proposed in which users are deanonymized under only certain types of well-defined misbehavior such as "double spending." While useful in some applications, it is not possible to generalize such techniques to more subjective definitions of misbehavior. Patrick P. Tsang, Man Ho Au, Apu Kapadia, Sean W. Smith |
CCS | 3 |
| 2007 | Attribute-Based Publishing with Hidden Credentials and Hidden Policies
Apu Kapadia, Patrick P. Tsang, Sean W. Smith |
NDSS | 1 |
| 2007 | Nymble: Anonymous IP-Address Blocking
Peter C. Johnson 0001, Apu Kapadia, Patrick P. Tsang, Sean W. Smith |
Privacy Enhancing Technologies | 2 |
| 2007 | TwoKind authentication: usable authenticators for untrustworthy environmentsabstractThe ease with which a malicious third party can obtain a user's password when he or she logs into Internet sites (such as bank or email accounts) from an insecure computer creates a substantial security risk to private information and transactions. For example, a malicious administrator at a cybercafe, or a malicious user with sufficient access to install key loggers at a kiosk, can obtain users' passwords easily. Even when users do not trust the machines they are using, many of them are faced with the prospect of accessing their accounts with a single level of privilege. To address this problem, we propose a system based on two modes of authentication--default and restricted. Users can signal to the server whether they are in an untrusted environment so that the server can log them in under restricted privileges that allow them to perform basic actions that cause no serious damage if the session or their password is compromised. Katelin Bailey, Linden Vongsathorn, Apu Kapadia, Chris Masone, Sean W. Smith |
SOUPS | 3 |
| 2004 | KNOW Why your access was denied: regulating feedback for usable securityabstractWe examine the problem of providing useful feedback about access control decisions to users while controlling the disclosure of the system's security policies. Relevant feedback enhances system usability, especially in systems where permissions change in unpredictable ways depending on contextual information. However, providing feedback indiscriminately can violate the confidentiality of system policy. To achieve a balance between system usability and the protection of security policies, we present Know, a framework that uses cost functions to provide feedback to users about access control decisions. Know honors the policy protection requirements, which are represented as a meta-policy, and generates permissible and relevant feedback to users on how to obtain access to a resource. To the best of our knowledge, our work is the first to address the need for useful access control feedback while honoring the privacy and confidentiality requirements of a system's security policy. Apu Kapadia, Geetanjali Sampemane, Roy H. Campbell |
CCS | 1 |
| 2002 | GREEN: proactive queue management over a best-effort networkabstractWe present a proactive queue-management (PQM) algorithm called GREEN (generalized random early evasion network) that applies knowledge of the steady-state behavior of TCP connections to drop packets intelligently and proactively, thus preventing congestion from ever occurring and ensuring a higher degree of fairness between flows. This congestion-prevention approach is in contrast to the congestion-avoidance approach of traditional active queue-management (AQM) schemes where congestion is actively detected early and then reacted to. In addition to enhancing fairness, GREEN keeps packet-queue lengths relatively low and reduces bandwidth and latency jitter. These characteristics are particularly beneficial to real-time multimedia applications. Further, GREEN achieves the above while maintaining high link utilization and low packet loss. Wu-chun Feng, Apu Kapadia, Sunil Thulasidasan |
GLOBECOM | 2 |
| 2002 | Routing Through the Mist: Privacy Preserving Communication in Ubiquitous Computing EnvironmentsabstractUbiquitous computing is poised to revolutionize the way we compute and interact with each other. However, unless privacy concerns are taken into account early in the design process, we will end up creating a very effective distributed surveillance system, which would be a dream come true for electronic stalkers and "big brothers". We present a protocol, which preserves the privacy of users and keeps their communication anonymous. In effect, we create a "mist" that conceals users from the system and other users. Yet, users will still be able to enjoy seamless interaction with services and other entities that wander within the ubiquitous computing environment. Jalal Al-Muhtadi, Roy H. Campbell, Apu Kapadia, M. Dennis Mickunas, Seung Yi |
ICDCS | 3 |
| 2002 | Packet Spacing: An Enabling Mechanism for Delivering Multimedia Content in Computational Grids
Annette C. Feng, Apu Kapadia, Wu-chun Feng, Geneva G. Belford |
J. Supercomput. | 2 |
| 2001 | The Effects of Inter-packet Spacing on the Delivery of Multimedia ContentabstractStreaming multimedia content with UDP has become increasingly popular over distributed systems such as the Internet. However, because UDP does not possess any congestion control mechanism and most best-effort traffic is served by the congestion-controlled TCP, UDP flows steal bandwidth from TCP to the point that TCP flows can starve for network resources. Furthermore, such applications may cause the Internet infrastructure to eventually suffer from congestion collapse because UDP traffic does not self-regulate itself. To address this problem, next-generation Internet routers will implement active queue management schemes to punish malicious traffic, e.g. non-adaptive UDP flows, and to the improve the performance of congestion-controlled traffic, e.g. TCP flows. The arrival of such routers will cripple the performance of today's UDP-based multimedia applications. So, in this paper, we introduce the notion of inter-packet spacing with control feedback to enable these UDP-based applications to perform well in the next-generation Internet while being adaptive and self-regulating. When compared with traditional UDP-based multimedia streaming, we illustrate that our counter-intuitive inter-packet spacing scheme with control feedback can reduce packet loss by 90% without adversely affecting the delivered throughput. Apu Kapadia, Annette C. Feng, Wu-chun Feng |
ICDCS | 1 |