Claudia Díaz

dblp:d/ClaudiaDiaz · DBLP profile ↗
← Back
43ranked-venue papers
12as first author
14since 2021 · last 2026
0000-0003-2336-7123ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 37 · 12 first-author · 13 since 2021Computer networks · 4Artificial intelligence and machine learning · 2 · 1 since 2021
YearPublicationVenuePosition
2026 Decentralized Reliability Estimation for Low-Latency Mixnets
Claudia Díaz, Harry Halpin, Aggelos Kiayias
EuroS&P1
2026 Shift Your Shape: Correlating and Defending Mixnet Flows Based on Their Shapes
abstract
When the packet rate of flows in a mixnet depends on the amount of transferred data, it is possible to identify which flow entering is which flow exiting the mixnet based on their shapes. We present a passive shape-based flow correlation attack against state-of-the-art mixnet Nym and a systematic evaluation of countermeasures. Assuming an adversary controlling both the entry and exit gateway-requesters selected by users to access the public Internet through Nym, our attack's artificial neural network assigns correlation scores to flow pairs based on traffic distribution similarities to accurately distinguish paired from unpaired flow tuples. From data we collected on the live Nym mixnet, we generate$ \mathbf {45}$datasets and$ \mathbf {119}$testing scenarios for different defense configurations. After one minute of attacking flow pairs on default Nym, we achieve a PR-AUC of$ \mathbf {0.9998}$at a base rate of$ \mathbf {1.9 \times 10^{-4}}$paired flow tuples. However, (combinations of) the five evaluated defense strategies indicate that the right choice and scale of countermeasure(s) can offer meaningful protection. Our evaluation also informs on the resources overhead spent on defenses. We discuss steps a mixnet such as Nym can take to make our attack both less likely and less accurate.
Lennart Oldenburg, Marc Juarez, Enrique Argones-Rúa, Claudia Díaz
IEEE Trans. Dependable Secur. Comput.4
2025 LAMP: Lightweight Approaches for Latency Minimization in Mixnets with Practical Deployment Considerations
Mahdi Rahimi 0003, Piyush Kumar Sharma, Claudia Díaz
NDSS3
2024 LARMix: Latency-Aware Routing in Mix Networks
Mahdi Rahimi 0003, Piyush Kumar Sharma, Claudia Díaz
NDSS3
2024 Are continuous stop-and-go mixnets provably secure?
abstract
This work formally analyzes the anonymity guarantees of continuous stop-and-go mixnets and attempts to answer the titular question. Existing mixnet based anonymous communication protocols that aim to provide provable anonymity guarantees rely on round-based communication models, which requires synchronization among all the nodes and clients that is difficult to achieve in practice. Continuous stop-and-go mixnets (e.g., Loopix and Nym) provide a nice alternative by adding a random delay for each message on every hop independent of all other hops and all other messages. The core anonymization technique of continuous mixnets combined with the fact that the messages are sent by the clients to the mixnet at different times makes it a difficult problem to formally prove security for such mixnet protocols; existing end-to-end analyses for such designs provide only experimental evaluations for anonymity and were lacking a comprehensive formal treatment. We are the first to close that gap and provide a formal analysis. We provide two indistinguishability based definitions (of sender anonymity), namely pairwise unlinkability and user unlinkability, tuned specifically for continuous stop-and-go mixnets. We derive the adversarial advantage as a function of the protocol parameters for the two definitions. We show that there is a fundamental lower bound on the adversarial advantage $\delta$ for pairwise unlinkability; however, strong user unlinkability (negligible adversarial advantage) can be achieved if the users message rate ($\lambda_u$) is proportional to message processing rate ($\lambda$) on the nodes.
Debajyoti Das 0001, Claudia Díaz, Aggelos Kiayias, Thomas Zacharias 0001
Proc. Priv. Enhancing Technol.2
2024 Blending Different Latency Traffic With Beta Mixing
abstract
We analyze the anonymity provided by continuous mixnets (e.g., Loopix) when messages with different latency requirements are sent through the same network. The anonymity provided by existing mixnets that offer bounded latency guarantees has only been studied considering that all the traffic in the network follows the same latency distribution. In this work we evaluate whether it is beneficial to aggregate different types of traffic in the same network or to keep them separate, when the latency distributions are exponential and the traffic arrivals are a poisson process --- as is the case in Loopix and related designs. We present a novel evaluation method to analyze the leakage to the adversary when multiple different types of traffic are sent through the same network of continuous mixes. We apply the method to empirically evaluate the end-to-end anonymity (in terms of entropy) for each type of traffic in the presence of a global passive adversary that may additionally compromise a constant fraction of mixes or may have knowledge about the type of traffic of network output messages. Finally we show via empirical evaluation using our analytical framework that it is beneficial for anonymity to blend different types of traffic in the same mixnet.
Iness Ben Guirat, Debajyoti Das 0001, Claudia Díaz
Proc. Priv. Enhancing Technol.3
2024 MixMatch: Flow Matching for Mixnet Traffic
abstract
Mixnets provide communication anonymity against network adversaries by routing packets independently via multiple hops, delaying them artificially at each hop, and introducing cover traffic. We show that these features (particularly the use of cover traffic) significantly diminish the effectiveness of state-of-the-art flow correlation techniques developed to link the two ends of a Tor connection. In this work, we propose novel methods to determine whether a set of endpoints exchanges packets via a mixnet and demonstrate their effectiveness by applying them to the Nym mixnet. We consider Nym in both an idealized lab setup and the official live network, and propose and compare three classifiers to conduct flow matching on it. Our statistical classifier tests whether egress packet timestamps are consistent with ingress timestamps and the (known) routing delay characteristic of the mixnet. In contrast, our two deep learning (DL) classifiers learn to distinguish matched from unmatched flow pairs from collected datasets directly, rather than relying on priors that describe the delay distribution. All three classifiers use our flow merging technique, which enables testing a match for sets of communicating endpoints of any cardinality. Considering a use case where two observed endpoints communicate exclusively to exchange a file through Nym, we find that flow matching is fast and accurate in the idealized lab setup. If flow pairs are aligned using all network observations in a download, we achieve a TPR of circa 0.6 (DL) and 0.47 (statistical) at an FPR of 10^-2 after only processing 100 observations. We evaluate classifier performance under key variations of this setup: the absence of loop cover traffic, an increased or decreased average per-mix delay, larger communicating sets (three endpoints) with faster responders, and the presence of realistic network effects (live network). The classifiers' matching performance diminishes on the live network where packet losses and variable propagation delays exist, reducing DL TPR to circa 0.26 and statistical TPR to circa 0.28 at an FPR of 10^-2. Informed by the insights of our analyses, we outline countermeasures that can be deployed in mixnets such as Nym to mitigate flow matching threats.
Lennart Oldenburg, Marc Juarez, Enrique Argones-Rúa, Claudia Díaz
Proc. Priv. Enhancing Technol.4
2023 Traffic Analysis by Adversaries with Partial Visibility
Iness Ben Guirat, Claudia Díaz, Karim M. El Defrawy, Hadas Zeilberger
ESORICS (2)2
2023 On the Anonymity of Peer-To-Peer Network Anonymity Schemes Used by Cryptocurrencies
Piyush Kumar Sharma, Devashish Gosain, Claudia Díaz
NDSS3
2022 Use of Multi-agent System to Classify Control EEG Signals: A Preliminary Study
Francisco Sierra, Rosario Baltazar, Anabel Pineda, Miguel Angel Casillas, Claudia Díaz, Martha-Alicia Rocha
KES-AMSTA5
2022 VerLoc: Verifiable Localization in Decentralized Systems
Katharina Kohls, Claudia Díaz
USENIX Security Symposium2
2022 Mixnet optimization methods
abstract
We propose a method to optimally select mix network parameters for a given deployment context and adversarial model. Our method considers both worstcase and average-case anonymity and selects configurations that meet worst-case constraints while maximizing average anonymity. We apply our methods to mixnet size optimization to determine the number and width of mixnet layers, and provide results for various deployment and adversarial scenarios. For cases where the deployment context suddenly changes (drop in user traffic) we evaluate countermeasures based on mix-generated dummy traffic and show that inexpensive link dummies can significantly boost protection in some of these cases.
Iness Ben Guirat, Claudia Díaz
Proc. Priv. Enhancing Technol.2
2022 From "Onion Not Found" to Guard Discovery
Lennart Oldenburg, Gunes Acar, Claudia Díaz
Proc. Priv. Enhancing Technol.3
2021 Less is More: A privacy-respecting Android malware classifier using federated learning
abstract
Abstract In this paper we present LiM (‘Less is More’), a malware classification framework that leverages Federated Learning to detect and classify malicious apps in a privacy-respecting manner. Information about newly installed apps is kept locally on users’ devices, so that the provider cannot infer which apps were installed by users. At the same time, input from all users is taken into account in the federated learning process and they all benefit from better classification performance. A key challenge of this setting is that users do not have access to the ground truth (i.e. they cannot correctly identify whether an app is malicious). To tackle this, LiM uses a safe semi-supervised ensemble that maximizes classification accuracy with respect to a baseline classifier trained by the service provider (i.e. the cloud). We implement LiM and show that the cloud server has F1 score of 95%, while clients have perfect recall with only 1 false positive in > 100 apps, using a dataset of 25K clean apps and 25K malicious apps, 200 users and 50 rounds of federation. Furthermore, we conduct a security analysis and demonstrate that LiM is robust against both poisoning attacks by adversaries who control half of the clients, and inference attacks performed by an honest-but-curious cloud server. Further experiments with Ma-MaDroid’s dataset confirm resistance against poisoning attacks and a performance improvement due to the federation.
Rafa Gálvez, Veelasha Moonsamy, Claudia Díaz
Proc. Priv. Enhancing Technol.3
2020 Encrypted DNS -> Privacy? A Traffic Analysis Perspective
Sandra Deepthy Siby, Marc Juarez, Claudia Díaz, Narseo Vallina-Rodriguez, Carmela Troncoso
NDSS3
2018 Inside Job: Applying Traffic Analysis to Measure Tor from Within
Rob Jansen, Marc Juarez, Rafa Gálvez, Tariq Elahi, Claudia Díaz
NDSS5
2017 How Unique is Your .onion?: An Analysis of the Fingerprintability of Tor Onion Services
abstract
Recent studies have shown that Tor onion (hidden) service websites are particularly vulnerable to website fingerprinting attacks due to their limited number and sensitive nature. In this work we present a multi-level feature analysis of onion site fingerprintability, considering three state-of-the-art website fingerprinting methods and 482 Tor onion services, making this the largest analysis of this kind completed on onion services to date.
Rebekah Overdorf, Marc Juarez, Gunes Acar, Rachel Greenstadt, Claudia Díaz
CCS5
2017 Editors' Introduction
Claudia Díaz, Rachel Greenstadt, Damon McCoy
Proc. Priv. Enhancing Technol.1
2017 Editors' Introduction
Claudia Díaz, Rachel Greenstadt, Damon McCoy
Proc. Priv. Enhancing Technol.1
2017 Editors' Introduction
Claudia Díaz, Rachel Greenstadt, Damon McCoy
Proc. Priv. Enhancing Technol.1
2017 Editors' Introduction
Claudia Díaz, Rachel Greenstadt, Damon McCoy
Proc. Priv. Enhancing Technol.1
2017 Towards Inferring Communication Patterns in Online Social Networks
abstract
The separation between the public and private spheres on online social networks is known to be, at best, blurred. On the one hand, previous studies have shown how it is possible to infer private attributes from publicly available data. On the other hand, no distinction exists between public and private data when we consider the ability of the online social network (OSN) provider to access them. Even when OSN users go to great lengths to protect their privacy, such as by using encryption or communication obfuscation, correlations between data may render these solutions useless. In this article, we study the relationship between private communication patterns and publicly available OSN data. Such a relationship informs both privacy-invasive inferences as well as OSN communication modelling, the latter being key toward developing effective obfuscation tools. We propose an inference model based on Bayesian analysis and evaluate, using a real social network dataset, how archetypal social graph features can lead to inferences about private communication. Our results indicate that both friendship graph and public traffic data may not be informative enough to enable these inferences, with time analysis having a non-negligible impact on their precision.
Ero Balsa, Cristina Pérez-Solà, Claudia Díaz
ACM Trans. Internet Techn.3
2016 Toward an Efficient Website Fingerprinting Defense
Marc Juarez, Mohsen Imani, Mike Perry, Claudia Díaz, Matthew Wright 0001
ESORICS (1)4
2016 Editors' Introduction
Claudia Díaz, Apu Kapadia
Proc. Priv. Enhancing Technol.1
2016 Editors' Introduction
Claudia Díaz, Apu Kapadia
Proc. Priv. Enhancing Technol.1
2016 Editors' Introduction
Claudia Díaz, Apu Kapadia
Proc. Priv. Enhancing Technol.1
2014 The Web Never Forgets: Persistent Tracking Mechanisms in the Wild
abstract
We present the first large-scale studies of three advanced web tracking mechanisms - canvas fingerprinting, evercookies and use of "cookie syncing" in conjunction with evercookies. Canvas fingerprinting, a recently developed form of browser fingerprinting, has not previously been reported in the wild; our results show that over 5% of the top 100,000 websites employ it. We then present the first automated study of evercookies and respawning and the discovery of a new evercookie vector, IndexedDB. Turning to cookie syncing, we present novel techniques for detection and analysing ID flows and we quantify the amplification of privacy-intrusive tracking practices due to cookie syncing.
Gunes Acar, Christian Eubank, Steven Englehardt, Marc Juarez, Arvind Narayanan, Claudia Díaz
CCS6
2014 A Critical Evaluation of Website Fingerprinting Attacks
abstract
Recent studies on Website Fingerprinting (WF) claim to have found highly effective attacks on Tor. However, these studies make assumptions about user settings, adversary capabilities, and the nature of the Web that do not necessarily hold in practical scenarios. The following study critically evaluates these assumptions by conducting the attack where the assumptions do not hold. We show that certain variables, for example, user's browsing habits, differences in location and version of Tor Browser Bundle, that are usually omitted from the current WF model have a significant impact on the efficacy of the attack. We also empirically show how prior work succumbs to the base rate fallacy in the open-world scenario. We address this problem by augmenting our classification method with a verification step. We conclude that even though this approach reduces the number of false positives over 63\%, it does not completely solve the problem, which remains an open issue for WF attacks.
Marc Juarez, Sadia Afroz 0001, Gunes Acar, Claudia Díaz, Rachel Greenstadt
CCS4
2014 Censorship-resistant and privacy-preserving distributed web search
abstract
The vast majority of Internet users are relying on centralized search engine providers to conduct their web searches. However, search results can be censored and search queries can be recorded by these providers without the user's knowledge. Distributed web search engines based on peer-to-peer networks have been proposed to mitigate these threats. In this paper we analyze the three most popular real-world distributed web search engines: Faroo, Seeks and Yacy, with respect to their censorship resistance and privacy protection. We show that none of them provides an adequate level of protection against an adversary with modest resources. Recognizing these flaws, we identify security properties a censorship-resistant and privacy-preserving distributed web search engine should provide. We propose two novel defense mechanisms called node density protocol and webpage verification protocol to achieve censorship resistance and show their effectiveness and feasibility with simulations. Finally, we elaborate on how state-of-the-art defense mechanisms achieve privacy protection in distributed web search engines.
Michael Herrmann 0003, Ren Zhang 0003, Kai-Chun Ning, Claudia Díaz, Bart Preneel
P2P4
2014 Practical privacy-preserving location-sharing based services with aggregate statistics
abstract
Location-sharing-based services (LSBSs) allow users to share their location with their friends in a sporadic manner. In currently deployed LSBSs users must disclose their location to the service provider in order to share it with their friends. This default disclosure of location data introduces privacy risks. We define the security properties that a privacy-preserving LSBS should fulfill and propose two constructions. First, a construction based on identity based broadcast encryption (IBBE) in which the service provider does not learn the user's location, but learns which other users are allowed to receive a location update. Second, a construction based on anonymous IBBE in which the service provider does not learn the latter either. As advantages with respect to previous work, in our schemes the LSBS provider does not need to perform any operations to compute the reply to a location data request, but only needs to forward IBBE ciphertexts to the receivers. We implement both constructions and present a performance analysis that shows their practicality. Furthermore, we extend our schemes such that the service provider, performing some verification work, is able to collect privacy-preserving aggregate statistics on the locations users share with each other.
Michael Herrmann 0003, Alfredo Rial, Claudia Díaz, Bart Preneel
WISEC3
2014 Optimizing the design parameters of threshold pool mixes for anonymity and delay
David Rebollo-Monedero, Javier Parra-Arnau, Jordi Forné, Claudia Díaz
Comput. Networks4
2013 FPDetective: dusting the web for fingerprinters
abstract
In the modern web, the browser has emerged as the vehicle of choice, which users are to trust, customize, and use, to access a wealth of information and online services. However, recent studies show that the browser can also be used to invisibly fingerprint the user: a practice that may have serious privacy and security implications.
Gunes Acar, Marc Juarez, Nick Nikiforakis, Claudia Díaz, Seda Gurses, Frank Piessens, Bart Preneel
CCS4
2012 OB-PWS: Obfuscation-Based Private Web Search
abstract
Obfuscation-based private web search (OB-PWS) solutions allow users to search for information in the Internet while concealing their interests. The basic privacy mechanism in OB-PWS is the automatic generation of dummy queries that are sent to the search engine along with users' real requests. These dummy queries prevent the accurate inference of search profiles and provide query deniability. In this paper we propose an abstract model and an associated analysis framework to systematically evaluate the privacy protection offered by OB-PWS systems. We analyze six existing OB-PWS solutions using our framework and uncover vulnerabilities in their designs. Based on these results, we elicit a set of features that must be taken into account when analyzing the security of OB-PWS designs to avoid falling into the same pitfalls as previous proposals.
Ero Balsa, Carmela Troncoso, Claudia Díaz
IEEE Symposium on Security and Privacy3
2012 A Metric to Evaluate Interaction Obfuscation in Online Social Networks
abstract
Online social networks (OSNs) have become one of the main communication channels in today's information society, and their emergence has raised new privacy concerns. The content uploaded to OSNs (such as pictures, status updates, comments) is by default available to the OSN provider, and often to other people to whom the user who uploaded the content did not intend to give access. A different class of concerns relates to sensitive information that can be inferred from the behavior of users. For example, the analysis of user interactions augments social network graphs with potentially privacy-sensitive details on the nature of social relations, such as the strength of user relationships. A solution to prevent such inferences is to automatically generate dummy interactions that obfuscate the real interactions between OSN users. Given an adversary that observes the obfuscated interactions, the goal is to prevent the adversary from recovering parameters of interest (e.g., relationships strength) that accurately describe the real user interactions. The design and evaluation of obfuscation strategies requires metrics that express the level of protection they would offer when deployed in a particular OSN with its underlying user interaction patterns. In this paper we propose mutual information as obfuscation metric. It measures the amount of information leaked by the (observable) obfuscated interactions in the system on the (concealed) real interactions between users. We show that the metric is suitable for comparing different obfuscation strategies, and flexible to accommodate different network topologies and user communication patterns. Obfuscation comes at the cost of network overhead, and the proposed metric contributes to enabling the optimization of strategies to achieve good levels of privacy protection at minimum overhead. We provide a detailed methodology to compute the metric and perform experiments that illustrate its suitability.
Ero Balsa, Carmela Troncoso, Claudia Díaz
Int. J. Uncertain. Fuzziness Knowl. Based Syst.3
2011 On the difficulty of achieving anonymity for Vehicle-2-X communication
Carmela Troncoso, Enrique Costa-Montenegro, Claudia Díaz, Stefan Schiffner
Comput. Networks3
2010 Drac: An Architecture for Anonymous Low-Volume Communications
George Danezis, Claudia Díaz, Carmela Troncoso, Ben Laurie
Privacy Enhancing Technologies2
2010 Impact of Network Topology on Anonymity and Overhead in Low-Latency Anonymity Networks
Claudia Díaz, Steven J. Murdoch, Carmela Troncoso
Privacy Enhancing Technologies1
2009 The Wisdom of Crowds: Attacks and Optimal Constructions
George Danezis, Claudia Díaz, Emilia Käsper, Carmela Troncoso
ESORICS2
2008 A Framework for the Analysis of Mix-Based Steganographic File Systems
Claudia Díaz, Carmela Troncoso, Bart Preneel
ESORICS1
2008 On the Impact of Social Network Profiling on Anonymity
Claudia Díaz, Carmela Troncoso, Andrei Serjantov
Privacy Enhancing Technologies1
2007 Efficient Negative Databases from Cryptographic Hash Functions
George Danezis, Claudia Díaz, Sebastian Faust, Emilia Käsper, Carmela Troncoso, Bart Preneel
ISC2
2007 Two-Sided Statistical Disclosure Attack
George Danezis, Claudia Díaz, Carmela Troncoso
Privacy Enhancing Technologies2
2004 Comparison Between Two Practical Mix Designs
Claudia Díaz, Len Sassaman, Evelyne Dewitte
ESORICS1