Yousra Javed

dblp:76/7908 · DBLP profile ↗
← Back
11ranked-venue papers
7as first author
3since 2021 · last 2025
0000-0002-0293-9551ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorComputer networks · 1Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2025 Evaluating privacy policies of AI-powered mHealth iOS applications
abstract
OBJECTIVES: This article evaluates the privacy policies of Artificial Intelligence (AI)-powered mHealth apps, focusing on their availability, readability, transparency, and scope. MATERIALS AND METHODS: We replicate the methodology of Sunyaev et al. 2015 for AI-focused mHealth iOS apps and compile a dataset of 2231 apps. RESULTS: Our analysis reveals that only 68.04% of these apps have publicly accessible privacy policies. On average, a privacy policy contains 2784.25 words, with a mean readability score of 13.48. Regarding transparency, aspects such as "information collection" and "sharing of information" are more frequently discussed, whereas "rationale for collection" is less commonly discussed. Additionally, only 15% of the apps mention the types of information collected, and 11.2% mention the use of user health data for training AI systems. In terms of scope, over 60% of app privacy policies cover the single app, and 25% cover no app-related scope (indicating a general or boilerplate privacy policy not tailored to the specific app). DISCUSSION: Our dataset reflects a post-AI and post-General Data Protection Regulation (GDPR) landscape. Therefore, we contrast that with pre-AI 2015, and compared our findings with those of general iOS mHealth apps studied by Sunyaev et al. 2015. Our dataset showed an increase in the presence of privacy policies. In the original study, 38.3% iOS apps were found to have privacy policies, with the mean length being 1755 words and the mean readability being 16. Our results, however, indicate that 68.04% of AI-powered iOS mHealth apps have privacy policies. Additionally, we found the mean length of a privacy policy to be 2784.25 words and the mean readability to be 13.48 (longer but better readability than the original study). Similarly, Sunyaev et al. found that for iOS mHealth apps, 47.8% of privacy policies cover all developer services. Our data, on the other hand, indicates that over 60% of app privacy policies cover the single app, and 25% cover no app-related scope. Our findings have implications for researchers, companies, developers, and end-users. CONCLUSION: Our study highlights the increase in the availability, presence, and length of privacy policies of AI mHealth iOS apps. While progress has been made toward greater transparency in policies, the readability and scope of privacy policies still have significant room for improvement.
Yousra Javed, Saaketh Bhojanam
J. Am. Medical Informatics Assoc.1
2022 "Why would Someone Hack Me out of Thousands of Students": Video Presenter's Impact on Motivating Users to Adopt 2FA
abstract
The voluntary adoption rate of two-factor authentication (2FA) remains low. This paper investigates whether video-based risk communication messages about Duo 2FA impacts voluntary 2FA adoption rate when delivered by a human speaker versus a cartoon speaker. We conducted an online two-phased survey-based study with 435 university students comprised of those who have not enabled Duo 2FA (non-adopters) on their university account as well as those who had previously enabled Duo 2FA (adopters). Participants in the non-adopters group (139) were assigned to one of the three groups: Threat-R (human speaker video), Threat-A (cartoon speaker video), and Control (no video). We found that 31% of participants enabled Duo 2FA through the human speaker video message compared to 7% with the cartoon speaker video message. However, there was no significant difference between the treatment and control groups (17% of participants enabled Duo 2FA in the Control group). Nevertheless, the treatment group participants showed their intention to activate Duo 2FA on their university account in the future. Those who enabled Duo 2FA rated Duo's usability as good. Moreover, enabling Duo 2FA on university accounts led some participants to enable 2FA on other online accounts. Our findings suggest that risk communication through videos that have a human speaker could increase users' willingness to adopt security features.
Elham Al Qahtani, Lipsarani Sahoo, Yousra Javed, Mohamed Shehab
SACMAT3
2022 User Perceptions of Gmail's Confidential Mode
Elham Al Qahtani, Yousra Javed, Mohamed Shehab
Proc. Priv. Enhancing Technol.2
2019 Alexa's Voice Recording Behavior: A Survey of User Understanding and Awareness
abstract
The use of Amazon's virtual assistant Alexa in controlling smart home devices is on the rise. The convenience provided by an Alexaenabled device comes at the cost of Alexa service's voice recording and storage behavior, raising privacy concerns. Amazon claims to record and store voice data in the cloud only when the wake word is spoken. However, Alexa records user's voice even at times when the wake word is not used. Though short, these recordings can potentially contain a sensitive conversation between individuals. Anyone in the possession of the Amazon Alexa mobile application with which the smart device is registered, can access these recordings.
Yousra Javed, Shashank Sethi, Akshay Jadoun
ARES1
2017 Investigating User Comprehension and Risk Perception of Apple's Touch ID Technology
abstract
Apple's Touch ID serves as an alternative to PIN/password for unlocking Apple devices, signing into third party iOS applications, and authorizing purchases on the iTunes Store by simply tapping a registered finger on the home button.
Yousra Javed, Mohamed Shehab, Emmanuel Bello-Ogunu
ARES1
2017 Look before you Authorize: Using Eye-Tracking to Enforce User Attention towards Application Permissions
abstract
Abstract Habituation is a key factor behind the lack of attention towards permission authorization dialogs during third party application installation. Various solutions have been proposed to combat the problem of achieving attention switch towards permissions. However, users continue to ignore these dialogs, and authorize dangerous permissions, which leads to security and privacy breaches. We leverage eye-tracking to approach this problem, and propose a mechanism for enforcing user attention towards application permissions before users are able to authorize them. We deactivate the dialog’s decision buttons initially, and use feedback from the eye-tracker to ensure that the user has looked at the permissions. After determining user attention, the buttons are activated. We implemented a prototype of our approach as a Chrome browser extension, and conducted a user study on Facebook’s application authorization dialogs. Using participants’ permission identification, eye-gaze fixations, and authorization decisions, we evaluate participants’ attention towards permissions. The participants who used our approach on authorization dialogs were able to identify the permissions better, compared to the rest of the participants, even after the habituation period. Their average number of eye-gaze fixations on the permission text was significantly higher than the other group participants. However, examining the rate in which participants denied a dangerous and unnecessary permission, the hypothesized increase from the control group to the treatment group was not statistically significant.
Yousra Javed, Mohamed Shehab
Proc. Priv. Enhancing Technol.1
2016 A Body of Knowledge for Usable Security and Privacy Education (Abstract Only)
abstract
The importance of usability in security and privacy technologies is now widely accepted. A vibrant and growing research community in usable security and privacy has contributed a wide range of results in the past 15 years. Despite this, the vast majority of computing students are being exposed to very little of this discipline. In this presentation, we describe our ongoing efforts to enable broader education in this area. We are leading the construction of a body of knowledge for usable security and privacy education, to serve as an organizing framework for the discipline. We are also creating online learning modules for several key topics, as resources for faculty and students. We seek feedback on these resources as well as faculty participants who are interested in utilizing and evaluating the learning modules.
Yousra Javed, Heather Lipford
SIGCSE1
2012 How do Facebookers Use Friendlists
abstract
Facebook friend lists are used to classify friends into groups and assist users in controlling access to their information. In this paper, we study the effectiveness of Facebook friend lists from two aspects: Friend Management and Policy Patterns by examining how users build friend lists and to what extent they use them in their policy templates. We have collected real Facebook profile information and photo privacy policies of 222 participants, through their consent in our Facebook survey application posted on Mechanical Turk. Our data analysis shows that users' customized friend lists are less frequently created and have fewer overlaps as compared to Facebook created friend lists. Also, users do not place all of their friends into lists. Moreover, friends in more than one friend lists have higher values of node betweenness and outgoing to incoming edge ratio values among all the friends of a particular user. Last but not the least, friend list and user based exceptions are less frequently used in policies as compared to allowing all friends, friends of friends and everyone to view photos.
Yousra Javed, Mohamed Shehab
ASONAM1
2012 Population density estimation using textons
abstract
In this paper we propose an efficient method for population density estimation using textons and k nearest neighbor classifier (k-NN). Leung Malik (LM) filter bank is used for texture extraction (textons) from Google Earth Satellite Images and classification into high, medium, low population density and non-populated areas. We have tested the proposed method for 5 different images of cities of Pakistan at high resolution. Comparison of our results with those obtained using Grey Level Co-occurrence Matrix (GLCM) are also presented, indicating the effectiveness of the proposed method.
Yousra Javed, Muhammad Murtaza Khan, Jocelyn Chanussot
IGARSS1
2011 Breaking undercover: exploiting design flaws and nonuniform human behavior
abstract
This paper reports two attacks on Undercover, a human authentication scheme against passive observers proposed at CHI 2008. The first attack exploits nonuniform human behavior in responding to authentication challenges and the second one is based on information leaked from authentication challenges or responses visible to the attacker. The second attack can be generalized to break two alternative Undercover designs presented at Pervasive 2009. All the attacks exploit design flaws of the Undercover implementations.
Toni Perkovic, Shujun Li 0001, Asma Mumtaz, Syed Ali Khayam, Yousra Javed, Mario Cagalj
SOUPS5
2009 Embedding a Covert Channel in Active Network Connections
abstract
Covert timing channels exploit varying packet rates between synchronized sending and receiving hosts to transmit hidden information. The overhead in synchronizing covert timing channels and their inherent dependence on network conditions are their main drawbacks. In this paper, we propose a covert channel using multiple active connections that does not depend on the timing differences between consecutive packets. Our proposed approach uses multiple network connections between a pair of communicating hosts to transmit covert data. Hence this covert channel is unaffected by underlying unpredictable network conditions. The concealed data is embedded in the order and sequence of connections to/from which regular (cover) packets of data are sent/received. Our experimental results show that, in addition to higher channel capacity, our proposed channel is undetectable using contemporary timing channel detection approaches.
Yousra Javed, Fauzan Mirza, Syed Ali Khayam
GLOBECOM2