EDBT 2026 Demo / reviewers in the wild / expert
Yuvraj Agarwal
dblp:84/1053
· DBLP profile ↗
46ranked-venue papers
7as first author
19since 2021 · last 2026
0000-0001-9304-6080ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 4 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 13 · 8 since 2021Security and privacy · 8 · 5 since 2021Systems, architecture and hardware · 6 · 3 first-authorSoftware engineering, systems software and programming languages · 5 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SpiderGen: Towards Procedure Generation for Carbon Life Cycle Assessments with Generative AIabstractInvestigating the effects of climate change and global warming caused by GHG emissions have been a key concern worldwide. These emissions are largely contributed to by the production, use and disposal of consumer products. Thus, it is important to build tools to estimate the environmental impact of consumer goods, an essential part of which is conducting Life Cycle Assessments (LCAs). LCAs specify and account for the appropriate processes involved with the production, use, and disposal of the products. We present SpiderGen, an LLM-based workflow which integrates the taxonomy and methodology of traditional LCA with the reasoning capabilities and world knowledge of LLMs to generate graphical representations of the key procedural information used for LCA, known as Product Category Rules Process Flow Graphs (PCR PFGs). We additionally evaluate the output of SpiderGen by comparing it with 65 real-world LCA documents. We find that SpiderGen provides accurate LCA process information that is either fully correct or has minor errors, achieving an F1-Score of 65% across 10 sample data points, as compared to 53% using a one-shot prompting method. We observe that the remaining errors occur primarily due to differences in detail between LCA documents, as well as differences in the ``scope" of which auxiliary processes must also be included. We also demonstrate that SpiderGen performs better than several baselines techniques, such as chain-of-thought prompting and one-shot prompting. Finally, we highlight SpiderGen's potential to reduce the human effort and costs for estimating carbon impact, as it is able to produce LCA process information for less than $1 USD in under 10 minutes as compared to the status quo LCA, which can cost over $25000 USD and take up to 21-person days. Anupama Sitaraman, Bharathan Balaji, Yuvraj Agarwal |
AAAI | 3 |
| 2026 | On the Freshness of Pinned Dependencies in Maven
Vasudev Vikram, Yuvraj Agarwal, Rohan Padhye |
ICST | 2 |
| 2025 | IMUCoCo: Enabling Flexible On-Body IMU Placement for Human Pose Estimation and Activity RecognitionabstractWe introduce IMU over Continuous Coordinates (IMUCoCo), a novel framework that maps signals from a variable number of IMUs placed on the body surface into a unified feature space based on their spatial coordinates.These features can be plugged into downstream models for pose estimation and activity recognition.Our evaluations demonstrate that IMUCoCo supports accurate pose estimation in a wide range of typical and atypical sensor placements.Overall, IMUCoCo supports significantly more flexible use of IMUs for motion sensing than the state-of-the-art, allowing users to place their sensors-laden devices according to their needs and preferences.The framework also supports the ability to change device locations depending on the context and suggests placement depending on the use case. Haozhe Zhou, Riku Arakawa, Yuvraj Agarwal, Mayank Goel |
UIST | 3 |
| 2024 | Is a Trustmark and QR Code Enough? The Effect of IoT Security and Privacy Label Information Complexity on Consumer Comprehension and BehaviorabstractThe U.S. Government is developing a package label to help consumers access reliable security and privacy information about Internet of Things (IoT) devices when making purchase decisions. The label will include the U.S. Cyber Trust Mark, a QR code to scan for more details, and potentially additional information. To examine how label information complexity and educational interventions affect comprehension of security and privacy attributes and label QR code use, we conducted an online survey with 518 IoT purchasers. We examined participants’ comprehension and preferences for three labels of varying complexities, with and without an educational intervention. Participants favored and correctly utilized the two higher-complexity labels, showing a special interest in the privacy-relevant content. Furthermore, while the educational intervention improved understanding of the QR code’s purpose, it had a modest effect on QR scanning behavior. We highlight clear design and policy directions for creating and deploying IoT security and privacy labels. Claire C. Chen, Dillon Shu, Hamsini Ravishankar, Yuvraj Agarwal, Lorrie Faith Cranor |
CHI | 5 |
| 2024 | Bring Privacy To The Table: Interactive Negotiation for Privacy Settings of Shared Sensing DevicesabstractTo address privacy concerns with the Internet of Things (IoT) devices, researchers have proposed enhancements in data collection transparency and user control. However, managing privacy preferences for shared devices with multiple stakeholders remains challenging. We introduced ThingPoll, a system that helps users negotiate privacy configurations for IoT devices in shared settings. We designed ThingPoll by observing twelve participants verbally negotiating privacy preferences, from which we identified potentially successful and inefficient negotiation patterns. ThingPoll bootstraps a preference model from a custom crowdsourced privacy preferences dataset. During negotiations, ThingPoll strategically scaffolds the process by eliciting users’ privacy preferences, providing helpful contexts, and suggesting feasible configuration options. We evaluated ThingPoll with 30 participants negotiating the privacy settings of 4 devices. Using ThingPoll, participants reached an agreement in 97.5% of scenarios within an average of 3.27 minutes. Participants reported high overall satisfaction of 83.3% with ThingPoll as compared to baseline approaches. Haozhe Zhou, Mayank Goel, Yuvraj Agarwal |
CHI | 3 |
| 2024 | On-Device Speech Filtering for Privacy-Preserving Acoustic Activity RecognitionabstractAcoustic sensing has become increasingly prevalent for mobile and ambient devices for applications such as human activity recognition, health monitoring, and environmental sensing. These approaches develop audio featurization techniques to enable machine learning-based inferences while offering privacy by preventing speech reconstruction. However, recent work [2] has shown that such methods are still vulnerable to speech content recovery when fine-tuned automatic speech recognition (ASR) models are applied. Here, we demonstrate the broad applicability of on-device speech filtering using a detect-and-remove method for acoustic sensing tasks, significantly reducing privacy risks in revealing speech content. Additionally, we introduce an interactive tool to experiment with audio featurization methods, aiding the development of privacy-preserving applications. Haozhe Zhou, Sudershan Boovaraghavan, Mayank Goel, Yuvraj Agarwal |
MobiCom | 4 |
| 2023 | "An Instructor is [already] able to keep track of 30 students": Students' Perceptions of Smart Classrooms for Improving Teaching & Their Emergent Understandings of Teaching and LearningabstractMulti-modal classroom sensing systems can collect complex behaviors in the classroom at a scale and precision far greater than human observers to capture learning insights and provide personalized teaching feedback. As students are critical stakeholders in the adoption of smart classrooms for the improvement of teaching, open questions remain in understanding student perspectives on the use of their data to provide insights to instructors. We conducted a Speed Dating with storyboards study to explore student values and boundaries regarding the acceptance of classroom sensing systems in STEM college courses. We found that students have several emergent beliefs about teaching and learning that influence their views towards smart classroom technologies. Students also held contextual views on the boundaries of data use depending on the outcome. Our findings have implications for the design and communication of classroom sensing systems that reconcile student and instructor beliefs around teaching and learning. Tricia Ngoon, David Kovalev, Prasoon Patidar, Chris Harrison 0001, Yuvraj Agarwal, John Zimmerman, Amy Ogan |
Conference on Designing Interactive Systems | 5 |
| 2023 | A First Look at Third-Party Service Dependencies of Web Services in Africa
Aqsa Kashaf, Jiachen Dou, Margarita Belova, Maria Apostolaki, Yuvraj Agarwal, Vyas Sekar |
PAM | 5 |
| 2023 | Are Consumers Willing to Pay for Security and Privacy of IoT Devices?
Pardis Emami Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, Lorrie Faith Cranor |
USENIX Security Symposium | 3 |
| 2022 | Exploring the Needs of Users for Supporting Privacy-Protective Behaviors in Smart HomesabstractIn this paper, we studied people’s smart home privacy-protective behaviors (SH-PPBs), to gain a better understanding of their privacy management do’s and don’ts in this context. We first surveyed 159 participants and elicited 33 unique SH-PPB practices, revealing that users heavily rely on ad hoc approaches at the physical layer (e.g., physical blocking, manual powering off). We also characterized the types of privacy concerns users wanted to address through SH-PPBs, the reasons preventing users from doing SH-PPBs, and privacy features they wished they had to support SH-PPBs. We then storyboarded 11 privacy protection concepts to explore opportunities to better support users’ needs, and asked another 227 participants to criticize and rank these design concepts. Among the 11 concepts, Privacy Diagnostics, which is similar to security diagnostics in anti-virus software, was far preferred over the rest. We also witnessed rich evidence of four important factors in designing SH-PPB tools, as users prefer (1) simple, (2) proactive, (3) preventative solutions that can (4) offer more control. Haojian Jin, Boyuan Guo, Rituparna Roychoudhury, Yaxing Yao, Swarun Kumar, Yuvraj Agarwal, Jason I. Hong |
CHI | 6 |
| 2022 | Understanding Challenges for Developers to Create Accurate Privacy Nutrition LabelsabstractApple announced the introduction of app privacy details to their App Store in December 2020, marking the first ever real-world, large-scale deployment of the privacy nutrition label concept, which had been introduced by researchers over a decade earlier. The Apple labels are created by app developers, who self-report their app’s data practices. In this paper, we present the first study examining the usability and understandability of Apple’s privacy nutrition label creation process from the developer’s perspective. By observing and interviewing 12 iOS app developers about how they created the privacy label for a real-world app that they developed, we identified common challenges for correctly and efficiently creating privacy labels. We discuss design implications both for improving Apple’s privacy label design and for future deployment of other standardized privacy notices. Tianshi Li 0001, Kayla Reiman, Yuvraj Agarwal, Lorrie Faith Cranor, Jason I. Hong |
CHI | 3 |
| 2022 | TEO: ephemeral ownership for IoT devices to provide granular data controlabstractAs Internet-of-Things (IoT) devices rapidly gain popularity, they raise significant privacy concerns given the breadth of sensitive data they can capture. These concerns are amplified by the fact that in many situations, IoT devices collect data about people other than their owner or administrator, and these stakeholders have no say in how that data is managed, used, or shared. To address this, we propose a new model of ownership, IoT Ephemeral Ownership (TEO). TEO allows stakeholders to quickly register with an IoT device for a limited period, and thus claim co-ownership over the sensitive data that the device generates. Device admins retain the ability to decide who may become an ephemeral owner, but no longer have access or control to the private data generated by the device. The encrypted data in TEO is accessible only by entities after seeking explicit permission from the different co-owners of that data. We verify the key security properties of our protocol underpinning TEO in the symbolic model using ProVerif. We also implement a cross-platform prototype of TEO for mobile phones and embedded devices, and integrate it into three real-world application case studies. Our evaluation shows that the latency and battery impact of TEO is typically small, adding ≤ 187 ms onto one-time operations, and introducing limited (<25%) overhead on recurring operations like private data storage. Han Zhang 0037, Yuvraj Agarwal, Matt Fredrikson |
MobiSys | 2 |
| 2022 | Protecting user data through ephemeral ownership of IoT devicesabstractThis demonstration presents a working prototype of TEO, a new model of device ownership that divides traditional owners into "admin" and "ephemeral owners". TEO addresses the challenge that users have no say in how their data are managed when the device is controlled by third parties, such as in rental and shared spaces. We design a complete protocol suite to address several practical issues, including preserving data ownership after users stop using the device, minimizing trusts with untrusted storage providers, enabling access control and revocation, and supporting groups of owners. Our cross-platform prototype implementation enables us to demonstrate the operational flow for managing ephemeral ownership of TEO-enabled devices in a representative setup with mobile phones, embedded devices, and Linux servers. Han Zhang 0037, Yuvraj Agarwal, Matt Fredrikson |
MobiSys | 2 |
| 2022 | Peekaboo: A Hub-Based Approach to Enable Transparency in Data Processing within Smart HomesabstractWe present Peekaboo, a new privacy-sensitive architecture for smart homes that leverages an in-home hub to pre-process and minimize outgoing data in a structured and enforceable manner before sending it to external cloud servers. Peekaboo's key innovations are (1) abstracting common data preprocessing functionality into a small and fixed set of chainable operators, and (2) requiring that developers explicitly declare desired data collection behaviors (e.g., data granularity, destinations, conditions) in an application manifest, which also specifies how the operators are chained together. Given a manifest, Peekaboo assembles and executes a pre-processing pipeline using operators pre-loaded on the hub. In doing so, developers can collect smart home data on a need-to-know basis; third-party auditors can verify data collection behaviors; and the hub itself can offer a number of centralized privacy features to users across apps and devices, without additional effort from app developers. We present the design and implementation of Peekaboo, along with an evaluation of its coverage of smart home scenarios, system performance, data minimization, and example built-in privacy features. Haojian Jin, Gram Liu, Swarun Kumar, Yuvraj Agarwal, Jason I. Hong |
SP | 5 |
| 2021 | Classroom Digital Twins with Instrumentation-Free Gaze TrackingabstractClassroom sensing is an important and active area of research with great potential to improve instruction. Complementing professional observers – the current best practice – automated pedagogical professional development systems can attend every class and capture fine-grained details of all occupants. One particularly valuable facet to capture is class gaze behavior. For students, certain gaze patterns have been shown to correlate with interest in the material, while for instructors, student-centered gaze patterns have been shown to increase approachability and immediacy. Unfortunately, prior classroom gaze-sensing systems have limited accuracy and often require specialized external or worn sensors. In this work, we developed a new computer-vision-driven system that powers a 3D “digital twin” of the classroom and enables whole-class, 6DOF head gaze vector estimation without instrumenting any of the occupants. We describe our open source implementation, and results from both controlled studies and real-world classroom deployments. Karan Ahuja, Deval Shah, Sujeath Pareddy, Franceska Xhakaj, Amy Ogan, Yuvraj Agarwal, Chris Harrison 0001 |
CHI | 6 |
| 2021 | Which Privacy and Security Attributes Most Impact Consumers' Risk Perception and Willingness to Purchase IoT Devices?abstractIn prior work, researchers proposed an Internet of Things (IoT) security and privacy label akin to a food nutrition label, based on input from experts. We conducted a survey with 1,371 Mechanical Turk (MTurk) participants to test the effectiveness of each of the privacy and security attribute-value pairs proposed in that prior work along two key dimensions: ability to convey risk to consumers and impact on their willingness to purchase an IoT device. We found that the values intended to communicate increased risk were generally perceived that way by participants. For example, we found that consumers perceived more risk when a label conveyed that data would be sold to third parties than when it would not be sold at all, and that consumers were more willing to purchase devices when they knew that their data would not be retained or shared with others. However, participants’ risk perception did not always align with their willingness to purchase, sometimes due to usability concerns. Based on our findings, we propose actionable recommendations on how to more effectively present privacy and security attributes on an IoT label to better communicate risk to consumers. Pardis Emami Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, Lorrie Faith Cranor |
SP | 3 |
| 2021 | Capture: Centralized Library Management for Heterogeneous IoT Devices
Han Zhang 0037, Abhijith Anilkumar, Matt Fredrikson, Yuvraj Agarwal |
USENIX Security Symposium | 4 |
| 2021 | Netter: Probabilistic, Stateful Network Models
Han Zhang 0037, Arthur Azevedo de Amorim, Yuvraj Agarwal, Matt Fredrikson, Limin Jia 0001 |
VMCAI | 4 |
| 2021 | What makes people install a COVID-19 contact-tracing app? Understanding the influence of app design and individual difference on contact-tracing app adoption intentionabstractSmartphone-based contact-tracing apps are a promising solution to help scale up the conventional contact-tracing process. However, low adoption rates have become a major issue that prevents these apps from achieving their full potential. In this paper, we present a national-scale survey experiment (N=1963) in the U.S. to investigate the effects of app design choices and individual differences on COVID-19 contact-tracing app adoption intentions. We found that individual differences such as prosocialness, COVID-19 risk perceptions, general privacy concerns, technology readiness, and demographic factors played a more important role than app design choices such as decentralized design vs. centralized design, location use, app providers, and the presentation of security risks. Certain app designs could exacerbate the different preferences in different sub-populations which may lead to an inequality of acceptance to certain app design choices (e.g., developed by state health authorities vs. a large tech company) among different groups of people (e.g., people living in rural areas vs. people living in urban areas). Our mediation analysis showed that one’s perception of the public health benefits offered by the app and the adoption willingness of other people had a larger effect in explaining the observed effects of app design choices and individual differences than one’s perception of the app’s security and privacy risks. With these findings, we discuss practical implications on the design, marketing, and deployment of COVID-19 contact-tracing apps in the U.S. Tianshi Li 0001, Camille Cobb, Jackie Yang, Sagar Baviskar, Yuvraj Agarwal, Beibei Li 0003, Lujo Bauer, Jason I. Hong |
Pervasive Mob. Comput. | 5 |
| 2020 | Analyzing Third Party Service Dependencies in Modern Web Services: Have We Learned from the Mirai-Dyn Incident?abstractMany websites rely on third parties for services (e.g., DNS, CDN, etc.). However, it also exposes them to shared risks from attacks (e.g., Mirai DDoS attack [24]) or cascading failures (e.g., GlobalSign revocation error [21]). Motivated by such incidents, we analyze the prevalence and impact of third-party dependencies, focusing on three critical infrastructure services: DNS, CDN, and certificate revocation checking by CA. We analyze both direct (e.g., Twitter uses Dyn) and indirect (e.g., Netflix uses Symantec as CA which uses Verisign for DNS) dependencies. We also take two snapshots in 2016 and 2020 to understand how the dependencies evolved. Our key findings are: (1) 89% of the Alexa top-100K websites critically depend on third-party DNS, CDN, or CA providers i.e., if these providers go down, these websites could suffer service disruption; (2) the use of third-party services is concentrated, and the top-3 providers of CDN, DNS, or CA services can affect 50%-70% of the top-100K websites; (3) indirect dependencies amplify the impact of popular CDN and DNS providers by up to 25X; and (4) some third-party dependencies and concentration increased marginally between 2016 to 2020. Based on our findings, we derive key implications for different stakeholders in the web ecosystem. Aqsa Kashaf, Vyas Sekar, Yuvraj Agarwal |
Internet Measurement Conference | 3 |
| 2020 | Ask the Experts: What Should Be on an IoT Privacy and Security Label?abstractInformation about the privacy and security of Internet of Things (IoT) devices is not readily available to consumers who want to consider it before making purchase decisions. While legislators have proposed adding succinct, consumer accessible, labels, they do not provide guidance on the content of these labels. In this paper, we report on the results of a series of interviews and surveys with privacy and security experts, as well as consumers, where we explore and test the design space of the content to include on an IoT privacy and security label. We conduct an expert elicitation study by following a three-round Delphi process with 22 privacy and security experts to identify the factors that experts believed are important for consumers when comparing the privacy and security of IoT devices to inform their purchase decisions. Based on how critical experts believed each factor is in conveying risk to consumers, we distributed these factors across two layers-a primary layer to display on the product package itself or prominently on a website, and a secondary layer available online through a web link or a QR code. We report on the experts' rationale and arguments used to support their choice of factors. Moreover, to study how consumers would perceive the privacy and security information specified by experts, we conducted a series of semi-structured interviews with 15 participants, who had purchased at least one IoT device (smart home device or wearable). Based on the results of our expert elicitation and consumer studies, we propose a prototype privacy and security label to help consumers make more informed IoT-related purchase decisions. Pardis Emami Naeini, Yuvraj Agarwal, Lorrie Faith Cranor, Hanan Hibshi |
SP | 2 |
| 2020 | ACES: Automatic Configuration of Energy Harvesting Sensors with Reinforcement LearningabstractMany modern smart building applications are supported by wireless sensors to sense physical parameters, given the flexibility they offer and the reduced cost of deployment. However, most wireless sensors are powered by batteries today, and large deployments are inhibited by the requirement of periodic battery replacement. Energy harvesting sensors provide an attractive alternative, but they need to provide adequate quality of service to applications given the uncertainty of energy availability. We propose ACES, which uses reinforcement learning to maximize sensing quality of energy harvesting sensors for periodic and event-driven indoor sensing with available energy. Our custom-built sensor platform uses a supercapacitor to store energy and Bluetooth Low Energy to relay sensors data. Using simulations and real deployments, we use the data collected to continually adapt the sensing of each node to changing environmental patterns and transfer learning to reduce the training time in real deployments. In our 60-node deployment lasting 2 weeks, nodes stop operations only 0.1% of the time, and collection of data is comparable with current battery-powered nodes. We show that ACES reduces the node duty-cycle period by an average of 33% compared to three prior reinforcement learning techniques while continuously learning environmental changes over time. Francesco Fraternali, Bharathan Balaji, Yuvraj Agarwal, Rajesh K. Gupta 0001 |
ACM Trans. Sens. Networks | 3 |
| 2019 | Exploring How Privacy and Security Factor into IoT Device Purchase BehaviorabstractDespite growing concerns about security and privacy of Internet of Things (IoT) devices, consumers generally do not have access to security and privacy information when purchasing these devices. We interviewed 24 participants about IoT devices they purchased. While most had not considered privacy and security prior to purchase, they reported becoming concerned later due to media reports, opinions shared by friends, or observing unexpected device behavior. Those who sought privacy and security information before purchase, reported that it was difficult or impossible to find. We asked interviewees to rank factors they would consider when purchasing IoT devices; after features and price, privacy and security were ranked among the most important. Finally, we showed interviewees our prototype privacy and security label. Almost all found it to be accessible and useful, encouraging them to incorporate privacy and security in their IoT purchase decisions. Pardis Emami Naeini, Henry Dixon, Yuvraj Agarwal, Lorrie Faith Cranor |
CHI | 3 |
| 2018 | Automated Extraction of Personal Knowledge from Smartphone Push NotificationsabstractPersonalized services are in need of a rich and powerful personal knowledge base, i.e. a knowledge base containing information about the user. This paper proposes an approach to extracting personal knowledge from smartphone push notifications, which are used by mobile systems and apps to inform users of a rich range of information. Our solution is based on the insight that most notifications are formatted using templates, while knowledge entities can be usually found within the parameters to the templates. As defining all the notification templates and their semantic rules are impractical due to the huge number of notification templates used by potentially millions of apps, we propose an automated approach for personal knowledge extraction from push notifications. We first discover notification templates through pattern mining, then use machine learning to understand the template semantics. Based on the templates and their semantics, we are able to translate notification text into knowledge facts automatically. Users' privacy is preserved as we only need to upload the templates to the server for model training, which do not contain any personal information. According to experiments with about 120 million push notifications from 100,000 smartphone users, our system is able to extract personal knowledge accurately and efficiently. Yuanchun Li 0003, Yao Guo 0001, Xiangqun Chen, Yuvraj Agarwal, Jason I. Hong |
IEEE BigData | 5 |
| 2018 | BuildingRules: A Trigger-Action-Based System to Manage Complex Commercial BuildingsabstractModern Building Management Systems (BMSs) have been designed to automate the behavior of complex buildings, but unfortunately they do not allow occupants to customize it according to their preferences, and only the facility manager is in charge of setting the building policies. To overcome this limitation, we present BuildingRules, a trigger-action programming-based system that aims to provide occupants of commercial buildings with the possibility of specifying the characteristics of their office environment through an intuitive interface. Trigger-action programming is intuitive to use and has been shown to be effective in meeting user requirements in home environments. To extend this intuitive interface to commercial buildings, an essential step is to manage the system scalability as large number of users will express their policies. BuildingRules has been designed to scale well for large commercial buildings as it automatically detects conflicts that occur among user specified policies and it supports intelligent grouping of rules to simplify the policies across large numbers of rooms. We ensure the conflict resolution is fast for a fluid user experience by using the Z3 SMT solver. BuildingRules backend is based on RESTful web services so it can connect to various BMSs and scale well with large number of buildings. We have tested our system with 23 users across 17 days in a virtual office building, and the results we have collected prove the effectiveness and the scalability of BuildingRules. A. A. Nacci, Vincenzo Rana, Bharathan Balaji, Paola Spoletini, Rajesh K. Gupta 0001, Donatella Sciuto, Yuvraj Agarwal |
ACM Trans. Cyber Phys. Syst. | 7 |
| 2017 | Transfer learning for performance modeling of configurable systems: an exploratory analysisabstractModern software systems provide many configuration options which significantly influence their non-functional properties. To understand and predict the effect of configuration options, several sampling and learning strategies have been proposed, albeit often with significant cost to cover the highly dimensional configuration space. Recently, transfer learning has been applied to reduce the effort of constructing performance models by transferring knowledge about performance behavior across environments. While this line of research is promising to learn more accurate models at a lower cost, it is unclear why and when transfer learning works for performance modeling. To shed light on when it is beneficial to apply transfer learning, we conducted an empirical study on four popular software systems, varying software configurations and environmental conditions, such as hardware, workload, and software versions, to identify the key knowledge pieces that can be exploited for transfer learning. Our results show that in small environmental changes (e.g., homogeneous workload change), by applying a linear transformation to the performance model, we can understand the performance behavior of the target environment, while for severe environmental changes (e.g., drastic workload change) we can transfer only knowledge that makes sampling more efficient, e.g., by reducing the dimensionality of the configuration space. Pooyan Jamshidi, Norbert Siegmund, Miguel Velez, Christian Kästner, Akshay Patel, Yuvraj Agarwal |
ASE | 6 |
| 2017 | Understanding the Purpose of Permission Use in Mobile AppsabstractMobile apps frequently request access to sensitive data, such as location and contacts. Understanding the purpose of why sensitive data is accessed could help improve privacy as well as enable new kinds of access control. In this article, we propose a text mining based method to infer the purpose of sensitive data access by Android apps. The key idea we propose is to extract multiple features from app code and then use those features to train a machine learning classifier for purpose inference. We present the design, implementation, and evaluation of two complementary approaches to infer the purpose of permission use, first using purely static analysis, and then using primarily dynamic analysis. We also discuss the pros and cons of both approaches and the trade-offs involved. Haoyu Wang 0001, Yuanchun Li 0003, Yao Guo 0001, Yuvraj Agarwal, Jason I. Hong |
ACM Trans. Inf. Syst. | 4 |
| 2016 | Genie: a longitudinal study comparing physical and software thermostats in office buildingsabstractThermostats are the primary interface for occupants of office buildings to express their thermal comfort preferences. However, traditional thermostats are often ineffective due to physical inaccessibility, lack of information or limited responsiveness, which lead to occupant discomfort. Modern thermostat designs do overcome some of these limitations, but retrofitting them to existing buildings is prohibitively expensive. Software thermostats based on web or smartphone apps provide an alternate interaction mechanism with minimal deployment cost. However, their usage and effectiveness have not been studied extensively in real settings. We present Genie, a novel software thermostat that we designed and deployed in our university for over 21 months. We compare the use of Genie to traditional thermostats. Our data and user study show that due to the clarity of information and wider thermal control provided by Genie, users feel more comfortable in their offices. Furthermore, the improved comfort did not affect the overall energy consumption or lead to misuse of HVAC controls. Bharathan Balaji, Jason Koh, Nadir Weibel, Yuvraj Agarwal |
UbiComp | 4 |
| 2016 | Follow My Recommendations: A Personalized Privacy Assistant for Mobile App Permissions
Bin Liu 0017, Mads Schaarup Andersen, Florian Schaub, Hazim Almuhimedi, Shikun Zhang, Norman M. Sadeh, Yuvraj Agarwal, Alessandro Acquisti |
SOUPS | 7 |
| 2016 | How Short Is Too Short? Implications of Length and Framing on the Effectiveness of Privacy Notices
Joshua Gluck, Florian Schaub, Amy Friedman, Hana Habib, Norman M. Sadeh, Lorrie Faith Cranor, Yuvraj Agarwal |
SOUPS | 7 |
| 2015 | Your Location has been Shared 5, 398 Times!: A Field Study on Mobile App Privacy NudgingabstractSmartphone users are often unaware of the data collected by apps running on their devices. We report on a study that evaluates the benefits of giving users an app permission manager and sending them nudges intended to raise their awareness of the data collected by their apps. Our study provides both qualitative and quantitative evidence that these approaches are complementary and can each play a significant role in empowering users to more effectively control their privacy. For instance, even after a week with access to the permission manager, participants benefited from nudges showing them how often some of their sensitive data was being accessed by apps, with 95% of participants reassessing their permissions, and 58% of them further restricting some of their permissions. We discuss how participants interacted both with the permission manager and the privacy nudges, analyze the effectiveness of both solutions, and derive some recommendations. Hazim Almuhimedi, Florian Schaub, Norman M. Sadeh, Idris Adjerid, Alessandro Acquisti, Joshua Gluck, Lorrie Faith Cranor, Yuvraj Agarwal |
CHI | 8 |
| 2015 | Models, abstractions, and architectures: the missing links in cyber-physical systemsabstractBridging disparate realms of physical and cyber system components requires models and methods that enable rapid evaluation of design alternatives in cyber-physical systems (CPS). The diverse intellectual traditions of physical and mathematical sciences makes this task exceptionally hard. This paper seeks to explore potential solutions by examining specific examples of CPS applications in automobiles and smart buildings. Both smart buildings and automobiles are complex systems with embedded knowledge across several domains. We present our experiences with development of CPS applications to illustrate the challenges that arise when expertise across domains is integrated into the system, and show that creation of models, abstractions, and architectures that address these challenges are key to next generation CPS applications. Bharathan Balaji, Mohammad Abdullah Al Faruque, Nikil Dutt, Rajesh K. Gupta 0001, Yuvraj Agarwal |
DAC | 5 |
| 2015 | Handling a trillion (unfixable) flaws on a billion devices: Rethinking network security for the Internet-of-ThingsabstractThe Internet-of-Things (IoT) has quickly moved from the realm of hype to reality with estimates of over 25 billion devices deployed by 2020. While IoT has huge potential for societal impact, it comes with a number of key security challenges---IoT devices can become the entry points into critical infrastructures and can be exploited to leak sensitive information. Traditional host-centric security solutions in today's IT ecosystems (e.g., antivirus, software patches) are fundamentally at odds with the realities of IoT (e.g., poor vendor security practices and constrained hardware). We argue that the network will have to play a critical role in securing IoT deployments. However, the scale, diversity, cyberphysical coupling, and cross-device use cases inherent to IoT require us to rethink network security along three key dimensions: (1) abstractions for security policies; (2) mechanisms to learn attack and normal profiles; and (3) dynamic and context-aware enforcement capabilities. Our goal in this paper is to highlight these challenges and sketch a roadmap to avoid this impending security disaster. Tianlong Yu, Vyas Sekar, Srinivasan Seshan, Yuvraj Agarwal, Chenren Xu |
HotNets | 4 |
| 2013 | ProtectMyPrivacy: detecting and mitigating privacy leaks on iOS devices using crowdsourcingabstractIn this paper we present the design and implementation of ProtectMyPrivacy (PMP), a system for iOS devices to detect access to private data and protect users by substituting anonymized data in its place if users decide. We developed a novel crowdsourced recommendation engine driven by users who contribute their protection decisions, which provides app specific privacy recommendations. PMP has been in use for over nine months by 90,621 real users, and we present a detailed evaluation based on the data we collected for 225,685 unique apps. We show that access to the device identifer (48.4% of apps), location (13.2% of apps), address book (6.2% of apps) and music library (1.6% of apps) is indeed widespread in iOS. We show that based on the protection decisions contributed by our users we can recommend protection settings for over 97.1% of the 10,000 most popular apps. We show the effectiveness of our recommendation engine with users accepting 67.1% of all recommendations provide to them, thereby helping them make informed privacy choices. Finally, we show that as few as 1% of our users, classified as experts, make enough decisions to drive our crowdsourced privacy recommendation engine. Yuvraj Agarwal, Malcolm Hall |
MobiSys | 1 |
| 2013 | Sentinel: occupancy based HVAC actuation using existing WiFi infrastructure within commercial buildingsabstractCommercial buildings contribute to 19% of the primary energy consumption in the US, with HVAC systems accounting for 39.6% of this usage. To reduce HVAC energy use, prior studies have proposed using wireless occupancy sensors or even cameras for occupancy based actuation showing energy savings of up to 42%. However, most of these solutions require these sensors and the associated network to be designed, deployed, tested and maintained within existing buildings which is significantly costly. Bharathan Balaji, Anthony Nwokafor, Rajesh K. Gupta 0001, Yuvraj Agarwal |
SenSys | 5 |
| 2013 | Underdesigned and Opportunistic Computing in Presence of Hardware VariabilityabstractMicroelectronic circuits exhibit increasing variations in performance, power consumption, and reliability parameters across the manufactured parts and across use of these parts over time in the field. These variations have led to increasing use of overdesign and guardbands in design and test to ensure yield and reliability with respect to a rigid set of datasheet specifications. This paper explores the possibility of constructing computing machines that purposely expose hardware variations to various layers of the system stack including software. This leads to the vision of underdesigned hardware that utilizes a software stack that opportunistically adapts to a sensed or modeled hardware. The envisioned underdesigned and opportunistic computing (UnO) machines face a number of challenges related to the sensing infrastructure and software interfaces that can effectively utilize the sensory data. In this paper, we outline specific sensing mechanisms that we have developed and their potential use in building UnO machines. Puneet Gupta 0001, Yuvraj Agarwal, Lara Dolecek, Nikil Dutt, Rajesh K. Gupta 0001, Rakesh Kumar 0002, Subhasish Mitra, Alexandru Nicolau, Tajana Rosing, Mani Srivastava 0001, Steven Swanson, Dennis Sylvester |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2012 | Verifying GPU kernels by test amplificationabstractWe present a novel technique for verifying properties of data parallel GPU programs via test amplification. The key insight behind our work is that we can use the technique of static information flow to amplify the result of a single test execution over the set of all inputs and interleavings that affect the property being verified. We empirically demonstrate the effectiveness of test amplification for verifying race-freedom and determinism over a large number of standard GPU kernels, by showing that the result of verifying a single dynamic execution can be amplified over the massive space of possible data inputs and thread interleavings. Alan Leung, Manish Gupta 0010, Yuvraj Agarwal, Rajesh K. Gupta 0001, Ranjit Jhala, Sorin Lerner |
PLDI | 3 |
| 2011 | Understanding the role of buildings in a smart microgridabstractA `smart microgrid' refers to a distribution network for electrical energy, starting from electricity generation to its transmission and storage with the ability to respond to dynamic changes in energy supply through co-generation and demand adjustments. At the scale of a small town, a microgrid is connected to the wide-area electrical grid that may be used for `baseline' energy supply; or in the extreme case only as a storage system in a completely self-sufficient microgrid. Distributed generation, storage and intelligence are key components of a smart microgrid. In this paper, we examine the significant role that buildings play in energy use and its management in a smart microgrid. In particular, we discuss the relationship that IT equipment has on energy usage by buildings, and show that control of various building subsystems (such as IT and HVAC) can lead to significant energy savings. Using the UCSD as a prototypical smart microgrid, we discuss how buildings can be enhanced and interfaced with the smart microgrid, and demonstrate the benefits that this relationship can bring as well as the challenges in implementing this vision. Yuvraj Agarwal, Thomas Weng, Rajesh K. Gupta 0001 |
DATE | 1 |
| 2011 | Duty-cycling buildings aggressively: The next frontier in HVAC control
Yuvraj Agarwal, Bharathan Balaji, Seemanta Dutta, Rajesh K. Gupta 0001, Thomas Weng |
IPSN | 1 |
| 2010 | Cyber-physical energy systems: focus on smart buildingsabstractOperating at the intersection of multiple sensing and control systems designed for occupant comfort, performability and operational efficiency, modern buildings represent a prototypical cyber-physical system with deeply coupled embedded sensing and networked information processing that has increasingly become part of our daily lives. In this paper, we look at modern buildings entirely as a cyber-physical energy system and examine the opportunities presented by the joint optimization of energy use by its occupants and information processing equipment. This paper makes two contributions: one, a careful examination of different types of buildings and their energy use; two, opportunities available to improve energy efficient operation through various strategies from lighting to computing. Using a modern 150,000 sq feet office building as a closed system, we detail different strategies to reduce energy use from LEED certification to zero net energy use. Jan Kleissl, Yuvraj Agarwal |
DAC | 2 |
| 2010 | SleepServer: A Software-Only Approach for Reducing the Energy Consumption of PCs within Enterprise Environments
Yuvraj Agarwal, Stefan Savage, Rajesh K. Gupta 0001 |
USENIX ATC | 1 |
| 2009 | Somniloquy: Augmenting Network Interfaces to Reduce PC Energy Usage
Yuvraj Agarwal, Steve Hodges 0001, Ranveer Chandra, James Scott, Paramvir Bahl, Rajesh K. Gupta 0001 |
NSDI | 1 |
| 2009 | Softspeak: Making VoIP Play Well in Existing 802.11 Deployments
Patrick Verkaik, Yuvraj Agarwal, Rajesh K. Gupta 0001, Alex C. Snoeren |
NSDI | 2 |
| 2007 | Wireless wakeups revisited: energy management for voip over wi-fi smartphonesabstractIP based telephony is rapidly gaining acceptance over traditional means of voice communication. Wireless LANs are also becoming ubiquitous due to their inherent ease of deployment and decreasing costs. In enterpriseWi-Fi environments, VoIP is a compelling application for devices such as smart phones with multiple wireless interfaces. However, the high energy consumption of Wi-Fi interfaces, especially when a device is idle,presents a significant barrier to the widespread adoption of VoIP over Wi-Fi.To address this issue, we present Cell2Notify, a practical and deployable energy management architecture that leverages the cellular radio on a smart phone to implement wakeup for the high-energy consumption Wi-Fi radio. We present detailed measurements of energy consumption on smart phone devices, and we show that Cell2Notify, can extend the battery lifetime of VoIPover Wi-Fi enabled smart phones by a factor of 1.7 to 6.4. Yuvraj Agarwal, Ranveer Chandra, Alec Wolman, Paramvir Bahl, Kevin Chin, Rajesh K. Gupta 0001 |
MobiSys | 1 |
| 2006 | CoolSpots: reducing the power consumption of wireless mobile devices with multiple radio interfacesabstractCoolSpots enable a wireless mobile device to automatically switch between multiple radio interfaces, such as WiFi and Bluetooth, in order to increase battery lifetime. The main contribution of this work is an exploration of the policies that enable a system to switch among these interfaces, each with diverse radio characteristics and different ranges, in order to save power - supported by detailed quantitative measurements. The system and policies do not require any changes to the mobile applications themselves, and changes required to existing infrastructure are minimal. Results are reported for a suite of commonly used applications, such as file transfer, web browsing, and streaming media, across a range of operating conditions. Experimental validation of the CoolSpot system on a mobile research platform shows substantial energy savings: more than a 50% reduction in energy consumption of the wireless subsystem is possible, with an associated increase in the effective battery lifetime. Trevor Pering, Yuvraj Agarwal, Rajesh K. Gupta 0001, Roy Want |
MobiSys | 2 |
| 2005 | Dynamic power management using on demand paging for networked embedded systemsabstractThe power consumption of the network interface plays a major role in determining the total operating lifetime of wireless networked embedded systems. In case of on-demand paging, a low power secondary radio is used to wake up the higher power radio, allowing the latter to sleep for longer periods of time. In this paper we present use of Bluetooth radios to serve as a paging channel for the 802.11b wireless LAN. We have implemented an on-demand paging scheme on an infrastructure based WLAN consisting of iPAQ PDAs equipped with Bluetooth radios and Cisco Aironet wireless networking cards. Our results show power saving ranging from 23% to 48% over the present 802.11b standard operating modes with negligible impact on performance. Yuvraj Agarwal, Curt Schurgers, Rajesh K. Gupta 0001 |
ASP-DAC | 1 |