User Tools

Site Tools


literature:bibliography

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
literature:bibliography [2026/08/27 13:53] – security:phishing: add 13 cited measurement keys. Authored by Claude karel.kubicek.claudeliterature:bibliography [2026/08/31 19:47] (current) – Add 15 BibTeX entries for privacy:browser_storage (browser storage beyond cookies). Keys checked against all 703 existing entries for collisions, DOIs/URLs checked for the same paper under another key, titles similarity-scanned; all DOIs resolved via Cros karel.kubicek.claude
Line 5708: Line 5708:
   series        = {USENIX Security 2021},   series        = {USENIX Security 2021},
   url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/acharya},   url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/acharya},
 +}
 +
 +
 +@inproceedings{kranch2015_upgrading,
 +  author        = {Kranch, Michael and Bonneau, Joseph},
 +  title         = {Upgrading HTTPS in Mid-Air: An Empirical Study of Strict Transport Security and Key Pinning},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2015},
 +  series        = {NDSS 2015},
 +  url           = {https://www.ndss-symposium.org/ndss2015/ndss-2015-programme/upgrading-https-mid-air-empirical-study-strict-transport-security-and-key-pinning/},
 +}
 +
 +@inproceedings{som2017_content,
 +  author        = {Somé, Dolière Francis and Bielova, Nataliia and Rezk, Tamara},
 +  title         = {On the Content Security Policy Violations due to the Same-Origin Policy},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2017},
 +  series        = {TheWebConf 2017},
 +  doi           = {10.1145/3038912.3052634},
 +}
 +
 +@inproceedings{kumar2017_security,
 +  author        = {Kumar, Deepak and Ma, Zane and Durumeric, Zakir and Mirian, Ariana and Mason, Joshua and Halderman, J. Alex and Bailey, Michael D.},
 +  title         = {Security Challenges in an Increasingly Tangled Web},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2017},
 +  series        = {TheWebConf 2017},
 +  doi           = {10.1145/3038912.3052686},
 +}
 +
 +@inproceedings{chang2017_security,
 +  author        = {Chang, Li and Hsiao, Hsu-Chun and Jeng, Wei and Kim, Tiffany Hyun-Jin and Lin, Wei-Hsi},
 +  title         = {Security Implications of Redirection Trail in Popular Websites Worldwide},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2017},
 +  series        = {TheWebConf 2017},
 +  doi           = {10.1145/3038912.3052698},
 +}
 +
 +@inproceedings{chapuis2020_integrity,
 +  author        = {Chapuis, Bertil and Omolola, Olamide and Cherubini, Mauro and Humbert, Mathias and Huguenin, Kévin},
 +  title         = {An Empirical Study of the Use of Integrity Verification Mechanisms for Web Subresources},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2020},
 +  series        = {TheWebConf 2020},
 +  doi           = {10.1145/3366423.3380092},
 +}
 +
 +@inproceedings{calzavara2021_reining,
 +  author        = {Calzavara, Stefano and Urban, Tobias and Tatang, Dennis and Steffens, Marius and Stock, Ben},
 +  title         = {Reining in the Web’s Inconsistencies with Site Policy},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2021},
 +  series        = {NDSS 2021},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/reining-in-the-webs-inconsistencies-with-site-policy/},
 +}
 +
 +@inproceedings{lim2025_phishers,
 +  author        = {Lim, Kyungchan and Lee, Kiho and Ji, Fujiao and Kwon, Yonghwi and Kim, Hyoungshick and Kim, Doowon},
 +  title         = {What's in Phishers: A Longitudinal Study of Security Configurations in Phishing Websites and Kits},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714710},
 +}
 +
 +@inproceedings{agarwal2022_helping,
 +  author        = {Agarwal, Shubham},
 +  title         = {Helping or Hindering?: How Browser Extensions Undermine Security},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2022},
 +  series        = {CCS 2022},
 +  doi           = {10.1145/3548606.3560685},
 +}
 +
 +@inproceedings{luo2019_time,
 +  author        = {Luo, Meng and Laperdrix, Pierre and Honarmand, Nima and Nikiforakis, Nick},
 +  title         = {Time Does Not Heal All Wounds: A Longitudinal Analysis of Security Mechanism Support in Mobile Browsers},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2019},
 +  series        = {NDSS 2019},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/time-does-not-heal-all-wounds-a-longitudinal-analysis-of-security-mechanism-support-in-mobile-browsers/},
 +}
 +
 +@inproceedings{zheng2015_cookies,
 +  author        = {Zheng, Xiaofeng and Jiang, Jian and Liang, Jinjin and Duan, Haixin and Chen, Shuo and Wan, Tao and Weaver, Nicholas},
 +  title         = {Cookies Lack Integrity: Real-World Implications},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2015},
 +  series        = {USENIX Security 2015},
 +  url           = {https://www.usenix.org/conference/usenixsecurity15/technical-sessions/presentation/zheng},
 +}
 +
 +@inproceedings{calzavara2020_tale,
 +  author        = {Calzavara, Stefano and Roth, Sebastian and Rabitti, Alvise and Backes, Michael and Stock, Ben},
 +  title         = {A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the Web},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2020},
 +  series        = {USENIX Security 2020},
 +  url           = {https://www.usenix.org/conference/usenixsecurity20/presentation/calzavara},
 +}
 +
 +@inproceedings{durumeric2013_zmap,
 +  author        = {Durumeric, Zakir and Wustrow, Eric and Halderman, J. Alex},
 +  title         = {{ZMap}: Fast Internet-wide Scanning and Its Security Applications},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2013},
 +  series        = {USENIX Security 2013},
 +  url           = {https://www.usenix.org/conference/usenixsecurity13/technical-sessions/paper/durumeric},
 +}
 +
 +@inproceedings{durumeric2014_view,
 +  author        = {Durumeric, Zakir and Bailey, Michael and Halderman, J. Alex},
 +  title         = {An Internet-Wide View of Internet-Wide Scanning},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2014},
 +  series        = {USENIX Security 2014},
 +  url           = {https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/durumeric},
 +}
 +
 +@inproceedings{kelley2012_guess,
 +  author        = {Kelley, Patrick Gage and Komanduri, Saranga and Mazurek, Michelle L. and Shay, Richard and Vidas, Timothy and Bauer, Lujo and Christin, Nicolas and Cranor, Lorrie Faith and L\'{o}pez, Julio C.},
 +  title         = {Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2012},
 +  series        = {IEEE S&P 2012},
 +  doi           = {10.1109/sp.2012.38},
 +}
 +
 +@inproceedings{pei2020_attention,
 +  author        = {Pei, Weiping and Mayer, Arthur and Tu, Kaylynn and Yue, Chuan},
 +  title         = {Attention Please: Your Attention Check Questions in Survey Studies Can Be Automatically Answered},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2020},
 +  series        = {TheWebConf 2020},
 +  doi           = {10.1145/3366423.3380195},
 +}
 +
 +@inproceedings{redmiles2020_comprehensive,
 +  author        = {Redmiles, Elissa M. and Warford, Noel and Jayanti, Amritha and Koneru, Aravind and Kross, Sean and Morales, Miraida and Stevens, Rock and Mazurek, Michelle L.},
 +  title         = {A Comprehensive Quality Evaluation of Security and Privacy Advice on the Web},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2020},
 +  series        = {USENIX Security 2020},
 +  url           = {https://www.usenix.org/conference/usenixsecurity20/presentation/redmiles},
 +}
 +
 +@inproceedings{herbert2025_digital,
 +  author        = {Herbert, Franziska and Munyendo, Collins W. and Hielscher, Jonas and Becker, Steffen and Zou, Yixin},
 +  title         = {Digital Security Perceptions and Practices Around the World: A {WEIRD} versus Non-{WEIRD} Comparison},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/herbert},
 +}
 +
 +@inproceedings{park2021_experimental,
 +  author        = {Park, Sungkyu and Park, Jamie Yejean and Chin, Hyojin and Kang, Jeong-han and Cha, Meeyoung},
 +  title         = {An Experimental Study to Understand User Experience and Perception Bias Occurred by Fact-checking Messages},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450121},
 +}
 +
 +@inproceedings{bhuiyan2025_visitors,
 +  author        = {Bhuiyan, Masudul Hasan Masud and Varvello, Matteo and Zaki, Yasir and Staicu, Cristian-Alexandru},
 +  title         = {Not All Visitors are Bilingual: A Measurement Study of the Multilingual Web from an Accessibility Perspective},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3764505},
 +}
 +
 +@article{tang2024_automatic,
 +  author        = {Tang, Jenny and Alvarez, L{\'e}o and Brar, Arjun and Hoang, Nguyen Phong and Christin, Nicolas},
 +  title         = {Automatic Generation of Web Censorship Probe Lists},
 +  journal       = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2024},
 +  volume        = {2024},
 +  number        = {4},
 +  pages         = {44--60},
 +  doi           = {10.56553/popets-2024-0106},
 +}
 +
 +@inproceedings{xie2025_evaluating,
 +  author        = {Xie, Qinge and Ramakrishnan, Karthik and Li, Frank},
 +  title         = {Evaluating Privacy Policies under Modern Privacy Laws At Scale: An {LLM}-Based Automated Approach},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  pages         = {5797--5816},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/xie},
 +}
 +
 +@inproceedings{nguyen2025_please,
 +  author        = {Nguyen, Hoang Dai and Dhungana, Sumit and Itha, Madhulika and Vadrevu, Phani},
 +  title         = {"Please don't send that bot anything": A Mixed-methods Study of Personal Impersonation Attacks Targeting Digital Payments on Social Media},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/nguyen},
 +}
 +
 +@inproceedings{vombatkere2024_tiktok,
 +  author        = {Vombatkere, Karan and Mousavi, Sepehr and Zannettou, Savvas and Roesner, Franziska and Gummadi, Krishna P.},
 +  title         = {TikTok and the Art of Personalization: Investigating Exploration and Exploitation on Social Media Feeds},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645600},
 +}
 +
 +@inproceedings{west2024_picture,
 +  author        = {West, Jack and Thiemt, Lea and Ahmed, Shimaa and Bartig, Maggie and Fawaz, Kassem and Banerjee, Suman},
 +  title         = {A Picture is Worth 500 Labels: A Case Study of Demographic Disparities in Local Machine Learning Models for Instagram and TikTok},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2024},
 +  series        = {IEEE S&P 2024},
 +  doi           = {10.1109/sp54263.2024.00203},
 +}
 +
 +@inproceedings{capozzi2023_thin,
 +  author        = {Capozzi, Arthur and Morales, Gianmarco De Francisci and Mejova, Yelena and Monti, Corrado and Panisson, André},
 +  title         = {The Thin Ideology of Populist Advertising on Facebook during the 2019 EU Elections},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2023},
 +  series        = {TheWebConf 2023},
 +  doi           = {10.1145/3543507.3583267},
 +}
 +
 +@inproceedings{bouchaud2024_beyond,
 +  author        = {Bouchaud, Paul and Liénard, Jean F.},
 +  title         = {Beyond the Guidelines: Assessing Meta's Political Ad Moderation in the EU},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2024},
 +  series        = {IMC 2024},
 +  doi           = {10.1145/3646547.3689020},
 +}
 +
 +@inproceedings{venkatadri2019_auditing,
 +  author        = {Venkatadri, Giridhari and Sapiezynski, Piotr and Redmiles, Elissa M. and Mislove, Alan and Goga, Oana and Mazurek, Michelle L. and Gummadi, Krishna P.},
 +  title         = {Auditing Offline Data Brokers via Facebook's Advertising Platform},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2019},
 +  series        = {TheWebConf 2019},
 +  doi           = {10.1145/3308558.3313666},
 +}
 +
 +@inproceedings{he2023_flocking,
 +  author        = {He, Jiahui and Zia, Haris Bin and Castro, Ignacio and Raman, Aravindh and Sastry, Nishanth and Tyson, Gareth},
 +  title         = {Flocking to Mastodon: Tracking the Great Twitter Migration},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624819},
 +}
 +
 +@inproceedings{xue2021_throttling,
 +  author        = {Xue, Diwen and Ramesh, Reethika and S, Valdik S. and Evdokimov, Leonid and Viktorov, Andrey and Jain, Arham and Wustrow, Eric and Basso, Simone and Ensafi, Roya},
 +  title         = {Throttling Twitter: an emerging censorship technique in Russia},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487858},
 +}
 +
 +@inproceedings{hagen2021_numbers,
 +  author        = {Hagen, Christoph and Weinert, Christian and Sendner, Christoph and Dmitrienko, Alexandra and Schneider, Thomas},
 +  title         = {All the Numbers are US: Large-scale Abuse of Contact Discovery in Mobile Messengers},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2021},
 +  series        = {NDSS 2021},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/all-the-numbers-are-us-large-scale-abuse-of-contact-discovery-in-mobile-messengers/},
 +}
 +
 +@inproceedings{gegenhuber2026_there,
 +  author        = {Gegenhuber, Gabriel K. and Frenzel, Philipp E. and Günther, Maximilian and Ullrich, Johanna and Judmayer, Aljosha},
 +  title         = {Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and Privacy},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/hey-there-you-are-using-whatsapp-enumerating-three-billion-accounts-for-security-and-privacy/},
 +}
 +
 +@inproceedings{cohn2020_delf,
 +  author        = {Cohn-Gordon, Katriel and Damaskinos, Georgios and Neto, Divino and Cordova, Joshi and Reitz, Benoît and Strahs, Benjamin and Obenshain, Daniel and Pearce, Paul and Papagiannis, Ioannis},
 +  title         = {DELF: Safeguarding deletion correctness in Online Social Networks},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2020},
 +  series        = {USENIX Security 2020},
 +  url           = {https://www.usenix.org/conference/usenixsecurity20/presentation/cohn-gordon},
 +}
 +
 +@inproceedings{schlinker2019_internet,
 +  author        = {Schlinker, Brandon and Cunha, Ítalo S. and Chiu, Yi-Ching and Sundaresan, Srikanth and Katz-Bassett, Ethan},
 +  title         = {Internet Performance from Facebook's Edge},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2019},
 +  series        = {IMC 2019},
 +  doi           = {10.1145/3355369.3355567},
 +}
 +
 +@inproceedings{zannettou2018_origins,
 +  author        = {Zannettou, Savvas and Caulfield, Tristan and Blackburn, Jeremy and Cristofaro, Emiliano De and Sirivianos, Michael and Stringhini, Gianluca and Suarez-Tangil, Guillermo},
 +  title         = {On the Origins of Memes by Means of Fringe Web Communities},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2018},
 +  series        = {IMC 2018},
 +  doi           = {10.1145/3278532.3278550},
 +}
 +
 +@inproceedings{acharya2024_imitation,
 +  author        = {Acharya, Bhupendra and Lazzaro, Dario and López-Morales, Efrén and Oest, Adam and Saad, Muhammad and Cinà, Antonio Emanuele and Schönherr, Lea and Holz, Thorsten},
 +  title         = {The Imitation Game: Exploring Brand Impersonation Attacks on Social Media Platforms},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/acharya},
 +}
 +
 +@inproceedings{beluri2025_exploration,
 +  author        = {Beluri, Mario and Acharya, Bhupendra and Khodayari, Soheil and Stivala, Giada and Pellegrino, Giancarlo and Holz, Thorsten},
 +  title         = {Exploration of the Dynamics of Buy and Sale of Social Media Accounts},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3732927},
 +}
 +
 +@inproceedings{galeazzi2026_revealing,
 +  author        = {Galeazzi, Alessandro and Paudel, Pujan and Conti, Mauro and Cristofaro, Emiliano De and Stringhini, Gianluca},
 +  title         = {Revealing The Secret Power: How Algorithms Can Influence Content Visibility on Twitter/X},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/revealing-the-secret-power-how-algorithms-can-influence-content-visibility-on-twitter-x/},
 +}
 +
 +@inproceedings{simko2024_modern,
 +  author        = {Simko, Lucy and Hutchinson, Adryana and Isaac, Alvin and Fries, Evan and Sherr, Micah and Aviv, Adam J.},
 +  title         = {"Modern problems require modern solutions": Community-Developed Techniques for Online Exam Proctoring Evasion},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3691638},
 +}
 +
 +@inproceedings{liao2024_gdpr,
 +  author        = {Liao, Song and Aldeen, Mohammed and Yan, Jingwen and Cheng, Long and Luo, Xiapu and Cai, Haipeng and Hu, Hongxin},
 +  title         = {Understanding GDPR Non-Compliance in Privacy Policies of Alexa Skills in European Marketplaces},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645409},
 +}
 +
 +@inproceedings{cinus2025_exposing,
 +  author        = {Cinus, Federico and Minici, Marco and Luceri, Luca and Ferrara, Emilio},
 +  title         = {Exposing Cross-Platform Coordinated Inauthentic Activity in the Run-Up to the 2024 U.S. Election},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714698},
 +}
 +
 +@inproceedings{biswas2026_longitudinal,
 +  author        = {Biswas, Md. Rafiul and Bessghaier, Mabrouka and Ibrahim, Shimaa and Mikros, George K. and Zaghouani, Wajdi},
 +  title         = {Longitudinal Trends in Global Climate Change Discourse on Facebook},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3793026},
 +}
 +
 +@inproceedings{mccrosky2026_does,
 +  author        = {McCrosky, Jesse and Malla, Ranadheer and Tanskanen, Aapo and Camargo, Chico Q.},
 +  title         = {Does This Button Work? Investigating YouTube's Ineffective User Controls},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792183},
 +}
 +
 +@article{benzaamia2026_year,
 +  author        = {Benzaamia, Abir and {El Fraihi}, Asmaa and Abdelaziz, Ines and Goga, Oana},
 +  title         = {A Year Under the DSA: Ad Transparency's Uneven Landscape},
 +  journal       = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2026},
 +  volume        = {2026},
 +  number        = {2},
 +  pages         = {517--532},
 +  doi           = {10.56553/popets-2026-0059},
 +}
 +
 +@article{knockel2026_banned,
 +  author        = {Knockel, Jeffrey and Dałek, Jakub and Aljizawi, Noura and Ahmed, Mohamed and Meletti, Levi and Lau, Justin},
 +  title         = {Banned Books: Analysis of Censorship on Amazon.com},
 +  journal       = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2026},
 +  volume        = {2026},
 +  number        = {3},
 +  pages         = {200--214},
 +  doi           = {10.56553/popets-2026-0078},
 +}
 +
 +@inproceedings{roy2025_darkgram,
 +  author        = {{Saha Roy}, Sayak and {Pourabbas Vafa}, Elham and Khanmohamaddi, Kobra and Nilizadeh, Shirin},
 +  title         = {DarkGram: A Large-Scale Analysis of Cybercriminal Activity Channels on Telegram},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/roy},
 +}
 +
 +@inproceedings{kaleli2021_human,
 +  author        = {Kaleli, Beliz and Kondracki, Brian and Egele, Manuel and Nikiforakis, Nick and Stringhini, Gianluca},
 +  title         = {To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2021},
 +  series        = {NDSS 2021},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/to-err-is-human-characterizing-the-threat-of-unintended-urls-in-social-media/},
 +}
 +
 +@inproceedings{khrer2015_going,
 +  author        = {Kührer, Marc and Hupperich, Thomas and Bushart, Jonas and Rossow, Christian and Holz, Thorsten},
 +  title         = {Going Wild: Large-Scale Classification of Open DNS Resolvers},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2015},
 +  series        = {IMC 2015},
 +  doi           = {10.1145/2815675.2815683},
 +}
 +@inproceedings{ager2010_comparing,
 +  author        = {Ager, Bernhard and Mühlbauer, Wolfgang and Smaragdakis, Georgios and Uhlig, Steve},
 +  title         = {Comparing DNS resolvers in the wild},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2010},
 +  series        = {IMC 2010},
 +  doi           = {10.1145/1879141.1879144},
 +}
 +@inproceedings{lu2019_over,
 +  author        = {Lu, Chaoyi and Liu, Baojun and Li, Zhou and Hao, Shuang and Duan, Hai-Xin and Zhang, Mingming and Leng, Chunying and Liu, Ying and Zhang, Zaifeng and Wu, Jianping},
 +  title         = {An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come?},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2019},
 +  series        = {IMC 2019},
 +  doi           = {10.1145/3355369.3355580},
 +}
 +@inproceedings{chhabra2021_over,
 +  author        = {Chhabra, Rishabh and Murley, Paul and Kumar, Deepak and Bailey, Michael D. and Wang, Gang},
 +  title         = {Measuring DNS-over-HTTPS performance around the world},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487849},
 +}
 +@inproceedings{randall2021_home,
 +  author        = {Randall, Audrey and Liu, Enze and Padmanabhan, Ramakrishna and Akiwate, Gautam and Voelker, Geoffrey M. and Savage, Stefan and Schulman, Aaron},
 +  title         = {Home is where the hijacking is: understanding DNS interception by residential routers},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487817},
 +}
 +@inproceedings{izhikevich2022_zdns,
 +  author        = {Izhikevich, Liz and Akiwate, Gautam and Berger, Briana and Drakontaidis, Spencer and Ascheman, Anna and Pearce, Paul and Adrian, David and Durumeric, Zakir},
 +  title         = {ZDNS: a fast DNS toolkit for internet measurement},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2022},
 +  series        = {IMC 2022},
 +  doi           = {10.1145/3517745.3561434},
 +}
 +@inproceedings{liu2023_dial,
 +  author        = {Liu, Guannan and Jin, Lin and Hao, Shuai and Zhang, Yubao and Liu, Daiping and Stavrou, Angelos and Wang, Haining},
 +  title         = {Dial "N" for NXDomain: The Scale, Origin, and Security Implications of DNS Queries to Non-Existent Domains},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624805},
 +}
 +@inproceedings{aldalky2019_look,
 +  author        = {Al-Dalky, Rami and Rabinovich, Michael and Schomp, Kyle},
 +  title         = {A Look at the ECS Behavior of DNS Resolvers},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2019},
 +  series        = {IMC 2019},
 +  doi           = {10.1145/3355369.3355586},
 +}
 +@inproceedings{ashiq2025_decoding,
 +  author        = {Ashiq, Md. Ishtiaq and Hureau, Olivier and Deccio, Casey T. and Chung, Tijay},
 +  title         = {Decoding DNSSEC Errors at Scale: An Automated DNSSEC Error Resolution Framework using Insights from DNSViz Logs},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3764428},
 +}
 +@inproceedings{li2024_worldwide,
 +  author        = {Li, Ruixuan and Liu, Baojun and Lu, Chaoyi and Duan, Haixin and Shao, Jun},
 +  title         = {A Worldwide View on the Reachability of Encrypted DNS Services},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645539},
 +}
 +@inproceedings{xia2026_starlink,
 +  author        = {Xia, Ruoxuan and Li, Bingyu and Chen, Zhenyu and Yuan, Pengyu and Wang, Yunjia and Zheng, Xiaofeng and Lin, Jingqiang},
 +  title         = {Starlink in the Wild: Multi-Perspective Measurements via DNS},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792366},
 +}
 +@inproceedings{klein2019_cache,
 +  author        = {Klein, Amit and Pinkas, Benny},
 +  title         = {dns-cache-based-user-tracking},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2019},
 +  series        = {NDSS 2019},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/dns-cache-based-user-tracking/},
 +}
 +@inproceedings{randall2020_trufflehunter,
 +  author        = {Randall, Audrey and Liu, Enze and Akiwate, Gautam and Padmanabhan, Ramakrishna and Voelker, Geoffrey M. and Savage, Stefan and Schulman, Aaron},
 +  title         = {Trufflehunter: Cache Snooping Rare Domains at Large Public DNS Resolvers},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2020},
 +  series        = {IMC 2020},
 +  doi           = {10.1145/3419394.3423640},
 +}
 +@inproceedings{moura2019_cache,
 +  author        = {Moura, Giovane C. M. and Heidemann, John S. and Schmidt, Ricardo de Oliveira and Hardaker, Wes},
 +  title         = {Cache Me If You Can: Effects of DNS Time-to-Live},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2019},
 +  series        = {IMC 2019},
 +  doi           = {10.1145/3355369.3355568},
 +}
 +@inproceedings{nosyk2023_extended,
 +  author        = {Nosyk, Yevheniya and Korczynski, Maciej and Duda, Andrzej},
 +  title         = {Extended DNS Errors: Unlocking the Full Potential of DNS Troubleshooting},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624835},
 +}
 +
 +@inproceedings{pearce2017_global,
 +  author        = {Pearce, Paul and Jones, Ben and Li, Frank and Ensafi, Roya and Feamster, Nick and Weaver, Nick and Paxson, Vern},
 +  title         = {Global Measurement of {DNS} Manipulation},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2017},
 +  series        = {USENIX Security 2017},
 +  url           = {https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/pearce},
 +}
 +
 +@inproceedings{liu2018_answering,
 +  author        = {Liu, Baojun and Lu, Chaoyi and Duan, Haixin and Liu, Ying and Li, Zhou and Hao, Shuang and Yang, Min},
 +  title         = {Who Is Answering My Queries: Understanding and Characterizing Interception of the {DNS} Resolution Path},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2018},
 +  series        = {USENIX Security 2018},
 +  url           = {https://www.usenix.org/conference/usenixsecurity18/presentation/liu-baojun},
 +}
 +
 +@inproceedings{bhaskar2022_many,
 +  author        = {Bhaskar, Abhishek and Pearce, Paul},
 +  title         = {Many Roads Lead To Rome: How Packet Headers Influence {DNS} Censorship Measurement},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/bhaskar},
 +}
 +
 +@inproceedings{nisenoff2023_awareness,
 +  author        = {Nisenoff, Alexandra and Sharma, Ranya and Feamster, Nick},
 +  title         = {User Awareness and Behaviors Concerning Encrypted {DNS} Settings in Web Browsers},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/nisenoff-awareness},
 +}
 +
 +@article{tsai2023_certainty,
 +  author        = {Tsai, Elisa and Kumar, Deepak and Sundara Raman, Ram and Li, Gavin and Eiger, Yael and Ensafi, Roya},
 +  title         = {{CERTainty}: Detecting {DNS} Manipulation at Scale using {TLS} Certificates},
 +  journal       = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2023},
 +  volume        = {2023},
 +  number        = {3},
 +  pages         = {122--137},
 +  doi           = {10.56553/popets-2023-0073},
 +}
 +
 +@article{ververis2025_path,
 +  author        = {Ververis, Vasilis and Sassala, Steffen and Roth, Felix and Bajpai, Vaibhav},
 +  title         = {Path to Encrypted {DNS} with {DDR}: Adoption, Configuration Patterns, and Privacy Implications},
 +  journal       = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2025},
 +  volume        = {2025},
 +  number        = {4},
 +  pages         = {465--484},
 +  doi           = {10.56553/popets-2025-0140},
 +}
 +@inproceedings{dong2024_exploring,
 +  author        = {Dong, Hongying and Zhang, Yizhe and Lee, Hyeonmin and Huque, Shumon and Sun, Yixin},
 +  title         = {Exploring the Ecosystem of DNS HTTPS Resource Records: An End-to-End Perspective},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2024},
 +  series        = {IMC 2024},
 +  doi           = {10.1145/3646547.3688410},
 +}
 +@inproceedings{weissteiner2026_continuous,
 +  author        = {Weissteiner, Hannes and Czerny, Roland and Franza, Simone and Gast, Stefan and Ullrich, Johanna and Gruss, Daniel},
 +  title         = {Continuous User Behavior Monitoring using DNS Cache Timing Attacks},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/continuous-user-behavior-monitoring-using-dns-cache-timing-attacks/},
 +}
 +
 +@inproceedings{izhikevich2021_identifying,
 +  author        = {Izhikevich, Liz and Teixeira, Renata and Durumeric, Zakir},
 +  title         = {LZR: Identifying Unexpected Internet Services},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/izhikevich},
 +}
 +
 +@inproceedings{huang2025_trust,
 +  author        = {Huang, Szu-Chun and Griffioen, Harm and van der Horst, Max and Smaragdakis, Georgios and van Eeten, Michel and Zhauniarovich, Yury},
 +  title         = {Trust but Verify: An Assessment of Vulnerability Tagging Services},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/huang-szu-chun},
 +}
 +
 +@inproceedings{sethuraman2022_ipv4,
 +  author        = {Sethuraman, Manasvini and Bischof, Zachary S. and Dainotti, Alberto},
 +  title         = {Analysis of IPv4 Address Space Utilization with ANT ISI Dataset and Censys},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2022},
 +  series        = {IMC 2022},
 +  doi           = {10.1145/3517745.3563018},
 +}
 +
 +@inproceedings{leontiadis2014_nearly,
 +  author        = {Leontiadis, Nektarios and Moore, Tyler and Christin, Nicolas},
 +  title         = {A Nearly Four-Year Longitudinal Study of Search-Engine Poisoning},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2014},
 +  series        = {CCS 2014},
 +  doi           = {10.1145/2660267.2660332},
 +}
 +
 +@inproceedings{wang2016_anatomy,
 +  author        = {Wang, Bolun and Zhang, Xinyi and Wang, Gang and Zheng, Haitao and Zhao, Ben Y.},
 +  title         = {Anatomy of a Personalized Livestreaming System},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2016},
 +  series        = {IMC 2016},
 +  doi           = {10.1145/2987443.2987453},
 +}
 +
 +@inproceedings{chatterjee2018_spyware,
 +  author        = {Chatterjee, Rahul and Doerfler, Periwinkle and Orgad, Hadas and Havron, Sam and Palmer, Jackeline and Freed, Diana and Levy, Karen and Dell, Nicola and McCoy, Damon and Ristenpart, Thomas},
 +  title         = {The Spyware Used in Intimate Partner Violence},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2018},
 +  series        = {IEEE S&P 2018},
 +  doi           = {10.1109/sp.2018.00061},
 +}
 +
 +@inproceedings{lee2021_practice,
 +  author        = {Lee, Hyunwoo and Kim, Doowon and Kwon, Yonghwi},
 +  title         = {TLS 1.3 in Practice: How TLS 1.3 Contributes to the Internet},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450057},
 +}
 +
 +@inproceedings{maggi2013_years,
 +  author        = {Maggi, Federico and Frossi, Alessandro and Zanero, Stefano and Stringhini, Gianluca and Stone-Gross, Brett and Kruegel, Christopher and Vigna, Giovanni},
 +  title         = {Two years of short URLs internet measurement: security threats and countermeasures},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2013},
 +  series        = {TheWebConf 2013},
 +  doi           = {10.1145/2488388.2488463},
 +}
 +
 +@inproceedings{rueth2018_digging,
 +  author        = {R{\"u}th, Jan and Zimmermann, Torsten and Wolsing, Konrad and Hohlfeld, Oliver},
 +  title         = {Digging into Browser-based Crypto Mining},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2018},
 +  series        = {IMC 2018},
 +  doi           = {10.1145/3278532.3278539},
 +}
 +
 +@inproceedings{sabottke2015_vulnerability,
 +  author        = {Sabottke, Carl and Suciu, Octavian and Dumitra\c{s}, Tudor},
 +  title         = {Vulnerability Disclosure in the Age of Social Media: Exploiting Twitter for Predicting Real-World Exploits},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2015},
 +  series        = {USENIX Security 2015},
 +  url           = {https://www.usenix.org/conference/usenixsecurity15/technical-sessions/presentation/sabottke},
 +}
 +
 +@inproceedings{agten2015_seven,
 +  author        = {Agten, Pieter and Joosen, Wouter and Piessens, Frank and Nikiforakis, Nick},
 +  title         = {Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2015},
 +  series        = {NDSS 2015},
 +  url           = {https://www.ndss-symposium.org/ndss2015/ndss-2015-programme/seven-months-worth-mistakes-longitudinal-study-typosquatting-abuse/},
 +}
 +
 +@inproceedings{murley2021_websocket,
 +  author        = {Murley, Paul and Ma, Zane and Mason, Joshua and Bailey, Michael D. and Kharraz, Amin},
 +  title         = {WebSocket Adoption and the Landscape of the Real-Time Web},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450063},
 +}
 +
 +@inproceedings{kuchhal2021_knock,
 +  author        = {Kuchhal, Dhruv and Li, Frank},
 +  title         = {Knock and talk: investigating local network communications on websites},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487857},
 +}
 +
 +@inproceedings{bijmans2019_inadvertently,
 +  author        = {Bijmans, Hugo L.J. and Booij, Tim M. and Doerr, Christian},
 +  title         = {Inadvertently Making Cyber Criminals Rich: A Comprehensive Study of Cryptojacking Campaigns at Internet Scale},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2019},
 +  series        = {USENIX Security 2019},
 +  url           = {https://www.usenix.org/conference/usenixsecurity19/presentation/bijmans},
 +}
 +
 +@inproceedings{thomas2011_design,
 +  author        = {Thomas, Kurt and Grier, Chris and Ma, Justin and Paxson, Vern and Song, Dawn},
 +  title         = {Design and Evaluation of a Real-Time URL Spam Filtering Service},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2011},
 +  series        = {IEEE S&P 2011},
 +  doi           = {10.1109/sp.2011.25},
 +}
 +
 +@inproceedings{wondracek2010_practical,
 +  author        = {Wondracek, Gilbert and Holz, Thorsten and Kirda, Engin and Kruegel, Christopher},
 +  title         = {A Practical Attack to De-anonymize Social Network Users},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2010},
 +  series        = {IEEE S&P 2010},
 +  doi           = {10.1109/sp.2010.21},
 +}
 +
 +@inproceedings{koop2020_redirect,
 +  author        = {Koop, Martin and Tews, Erik and Katzenbeisser, Stefan},
 +  title         = {In-Depth Evaluation of Redirect Tracking and Link Usage},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2020},
 +  series        = {PoPETs 2020},
 +  doi           = {10.2478/popets-2020-0079},
 +}
 +
 +@inproceedings{konoth2018_minesweeper,
 +  author        = {Konoth, Radhesh Krishnan and Vineti, Emanuele and Moonsamy, Veelasha and Lindorfer, Martina and Kruegel, Christopher and Bos, Herbert and Vigna, Giovanni},
 +  title         = {MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its Defense},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2018},
 +  series        = {CCS 2018},
 +  doi           = {10.1145/3243734.3243858},
 +}
 +
 +@inproceedings{miramirkhani2017_dial,
 +  author        = {Miramirkhani, Najmeh and Starov, Oleksii and Nikiforakis, Nick},
 +  title         = {Dial One for Scam: A Large-Scale Analysis of Technical Support Scams},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2017},
 +  series        = {NDSS 2017},
 +  url           = {https://www.ndss-symposium.org/ndss2017/ndss-2017-programme/dial-one-scam-large-scale-analysis-technical-support-scams/},
 +}
 +
 +@inproceedings{zhang2023_under,
 +  author        = {Zhang, Zhenrui and Hong, Geng and Li, Xiang and Fu, Zhuoqun and Zhang, Jia and Liu, Mingxuan and Wang, Chuhan and Chen, Jianjun and Liu, Baojun and Duan, Haixin and Zhang, Chao and Yang, Min},
 +  title         = {Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616677},
 +}
 +
 +@inproceedings{dahlberg2023_timeless,
 +  author        = {Dahlberg, Rasmus and Pulls, Tobias},
 +  title         = {Timeless Timing Attacks and Preload Defenses in Tor's DNS Cache},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/dahlberg},
 +}
 +
 +@inproceedings{genkin2022_lend,
 +  author        = {Genkin, Daniel and Nissan, Noam and Schuster, Roei and Tromer, Eran},
 +  title         = {Lend Me Your Ear: Passive Remote Physical Side Channels on PCs},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/genkin},
 +}
 +
 +@inproceedings{qiu2023_calpric,
 +  author        = {Qiu, Wenjun and Lie, David and Austin, Lisa},
 +  title         = {Calpric: Inclusive and Fine-grain Labeling of Privacy Policies with Crowdsourcing and Active Learning},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/qiu},
 +}
 +
 +@inproceedings{pu2023_deepfake,
 +  author        = {Pu, Jiameng and Sarwar, Zain and Abdullah, Sifat Muhammad and Rehman, Abdullah and Kim, Yoonjin and Bhattacharya, Parantapa and Javed, Mobin and Viswanath, Bimal},
 +  title         = {Deepfake Text Detection: Limitations and Opportunities},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2023},
 +  series        = {IEEE S&P 2023},
 +  doi           = {10.1109/sp46215.2023.10179387},
 +}
 +
 +@inproceedings{li2021_good,
 +  author        = {Li, Xigao and Azad, Babak Amin and Rahmati, Amir and Nikiforakis, Nick},
 +  title         = {Good Bot, Bad Bot: Characterizing Automated Browsing Activity},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2021},
 +  series        = {IEEE S&P 2021},
 +  doi           = {10.1109/sp40001.2021.00079},
 +}
 +
 +
 +@inproceedings{herley2022_automated,
 +  author        = {Herley, Cormac},
 +  title         = {Automated Detection of Automated Traffic},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/herley},
 +}
 +
 +
 +@inproceedings{venugopalan2025_inconsistent,
 +  author        = {Venugopalan, Hari and Munir, Shaoor and Ahmed, Shuaib and Wang, Tangbaihe and King, Samuel T. and Shafiq, Zubair},
 +  title         = {FP-Inconsistent: Measurement and Analysis of Fingerprint Inconsistencies in Evasive Bot Traffic},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3732919},
 +}
 +
 +
 +@inproceedings{jan2020_throwing,
 +  author        = {Jan, Steve T. K. and Hao, Qingying and Hu, Tianrui and Pu, Jiameng and Oswal, Sonal and Wang, Gang and Viswanath, Bimal},
 +  title         = {Throwing Darts in the Dark? Detecting Bots with Limited Data using Neural Data Augmentation},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2020},
 +  series        = {IEEE S&P 2020},
 +  doi           = {10.1109/sp40000.2020.00079},
 +}
 +
 +
 +@inproceedings{liu2025_somesite,
 +  author        = {Liu, Enze and Luo, Elisa and Shan, Shawn and Voelker, Geoffrey M. and Zhao, Ben Y. and Savage, Stefan},
 +  title         = {Somesite I Used To Crawl: Awareness, Agency and Efficacy in Protecting Content Creators From AI Crawlers},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3732913},
 +}
 +
 +
 +@inproceedings{cui2025_odyssey,
 +  author        = {Cui, Jian and Zha, Mingming and Wang, XiaoFeng and Liao, Xiaojing},
 +  title         = {The Odyssey of robots.txt Governance: Measuring Convention Implications of Web Bots in Large Language Model Services},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2025},
 +  series        = {CCS 2025},
 +  doi           = {10.1145/3719027.3765063},
 +}
 +
 +
 +@inproceedings{kim2025_scrapers,
 +  author        = {Kim, Taein and Bock, Karstan and Luo, Claire and Liswood, Amanda and Poroslay, Chloe and Wenger, Emily},
 +  title         = {Scrapers Selectively Respect robots.txt Directives: Evidence From a Large-Scale Empirical Study},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3764471},
 +}
 +
 +
 +@inproceedings{qi2026_viper,
 +  author        = {Qi, Minfeng and He, Dongyang and Wang, Qin and Zhang, Lefeng},
 +  title         = {VIPER Strike: Defeating Visual Reasoning CAPTCHAs via Structured Vision–Language Inference},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/qi-minfeng},
 +}
 +
 +
 +@inproceedings{nguyen2024_frame,
 +  author        = {Nguyen, Hoang Dai and Subramani, Karthika and Acharya, Bhupendra and Perdisci, Roberto and Vadrevu, Phani},
 +  title         = {C-Frame: Characterizing and measuring in-the-wild CAPTCHA attacks},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2024},
 +  series        = {IEEE S&P 2024},
 +  doi           = {10.1109/sp54263.2024.00200},
 +}
 +
 +
 +@inproceedings{ardi2023_prevalence,
 +  author        = {Ardi, Calvin and Calder, Matt},
 +  title         = {The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624841},
 +}
 +
 +
 +@inproceedings{wang2011_cloak,
 +  author        = {Wang, David Y. and Savage, Stefan and Voelker, Geoffrey M.},
 +  title         = {Cloak and dagger: dynamics of web search cloaking},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2011},
 +  series        = {CCS 2011},
 +  doi           = {10.1145/2046707.2046763},
 +}
 +
 +
 +@inproceedings{maroofi2020_human,
 +  author        = {Maroofi, Sourena and Korczynski, Maciej and Duda, Andrzej},
 +  title         = {Are You Human?: Resilience of Phishing Detection to Evasion Techniques Based on Human Verification},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2020},
 +  series        = {IMC 2020},
 +  doi           = {10.1145/3419394.3423632},
 +}
 +
 +
 +@inproceedings{szurdi2021_where,
 +  author        = {Szurdi, Janos and Luo, Meng and Kondracki, Brian and Nikiforakis, Nick and Christin, Nicolas},
 +  title         = {Where are you taking me?Understanding Abusive Traffic Distribution Systems},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450071},
 +}
 +
 +
 +@inproceedings{shi2020_text,
 +  author        = {Shi, Chenghui and Ji, Shouling and Liu, Qianjun and Liu, Changchang and Chen, Yuefeng and He, Yuan and Liu, Zhe and Beyah, Raheem and Wang, Ting},
 +  title         = {Text Captcha Is Dead? A Large Scale Deployment and Empirical Study},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417258},
 +}
 +
 +
 +@inproceedings{oh2017_fingerprinting,
 +  author        = {Oh, Se Eun and Li, Shuai and Hopper, Nicholas},
 +  title         = {Fingerprinting Keywords in Search Queries over Tor},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2017},
 +  series        = {PETS 2017},
 +  doi           = {10.1515/popets-2017-0048},
 +}
 +
 +@inproceedings{campobasso2020_impersonation,
 +  author        = {Campobasso, Michele and Allodi, Luca},
 +  title         = {Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at Scale},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417892},
 +}
 +
 +@inproceedings{steiner2026_nlweb,
 +  author        = {Steiner, Aaron and Peeters, Ralph and Bizer, Christian},
 +  title         = {MCP vs RAG vs NLWeb vs HTML: A Comparison of the Effectiveness and Efficiency of Different Agent Interfaces to the Web},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792893},
 +}
 +
 +@inproceedings{jeong2026_network,
 +  author        = {Jeong, Hyejun and Teymoorianfard, Mohammadreza and Kumar, Abhinav and Houmansadr, Amir and Bagdasarian, Eugene},
 +  title         = {Network-Level Prompt and Trait Leakage in Local Research Agents},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/jeong},
 +}
 +
 +@inproceedings{zhao2026_parasites,
 +  author        = {Zhao, Shuli and Hou, Qinsheng and Zhan, Zihan and Wang, Yanhao and Xie, Yuchong and Guo, Yu and Chen, Libo and Li, Shenghong and Xue, Zhi},
 +  title         = {Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the {MCP} Ecosystem},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2026},
 +  series        = {IEEE S&P 2026},
 +  doi           = {10.1109/sp63933.2026.00154},
 +}
 +
 +@article{ramesh2026_webspeval,
 +  author        = {Ramesh, Guruprasad Viswanathan and Nayak, Asmit and Siddique, Basieem and Fawaz, Kassem},
 +  title         = {WebSP-Eval: Evaluating Web Agents on Website Security and Privacy Tasks},
 +  journal       = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2026},
 +  volume        = {2026},
 +  number        = {4},
 +  pages         = {666--702},
 +  doi           = {10.56553/popets-2026-0140},
 +}
 +
 +@inproceedings{chang2026_overcoming,
 +  author        = {Chang, Hongyan and Bao, Ergute and Luo, Xinjian and Yu, Ting},
 +  title         = {Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for {LLM} Systems},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/chang-hongyan},
 +}
 +
 +@inproceedings{shuba2018_nomoads,
 +  author        = {Shuba, Anastasia and Markopoulou, Athina and Shafiq, Zubair},
 +  title         = {NoMoAds: Effective and Efficient Cross-App Mobile Ad-Blocking},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2018},
 +  series        = {PoPETs 2018},
 +  doi           = {10.1515/popets-2018-0035},
 +}
 +
 +@inproceedings{shuba2020_nomoats,
 +  author        = {Shuba, Anastasia and Markopoulou, Athina},
 +  title         = {NoMoATS: Towards Automatic Detection of Mobile Tracking},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2020},
 +  series        = {PoPETs 2020},
 +  doi           = {10.2478/popets-2020-0017},
 +}
 +
 +@inproceedings{varmarken2020_smart,
 +  author        = {Varmarken, Janus and Le, Hieu and Shuba, Anastasia and Markopoulou, Athina and Shafiq, Zubair},
 +  title         = {The TV is Smart and Full of Trackers: Measuring Smart TV Advertising and Tracking},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2020},
 +  series        = {PoPETs 2020},
 +  doi           = {10.2478/popets-2020-0021},
 +}
 +
 +@inproceedings{watanabe2020_melting,
 +  author        = {Watanabe, Takuya and Shioji, Eitaro and Akiyama, Mitsuaki and Mori, Tatsuya},
 +  title         = {Melting Pot of Origins: Compromising the Intermediary Web Services that Rehost Websites},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2020},
 +  series        = {NDSS 2020},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/melting-pot-of-origins-compromising-the-intermediary-web-services-that-rehost-websites/},
 +}
 +
 +@inproceedings{ali2023_navigating,
 +  author        = {Ali, Mir Masood and Chitale, Binoy and Ghasemisharif, Mohammad and Kanich, Chris and Nikiforakis, Nick and Polakis, Jason},
 +  title         = {Navigating Murky Waters: Automated Browser Feature Testing for Uncovering Tracking Vectors},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2023},
 +  series        = {NDSS 2023},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/navigating-murky-waters-automated-browser-feature-testing-for-uncovering-tracking-vectors/},
 +}
 +
 +@inproceedings{singh2010_incoherencies,
 +  author        = {Singh, Kapil and Moshchuk, Alexander and Wang, Helen J. and Lee, Wenke},
 +  title         = {On the Incoherencies in Web Browser Access Control Policies},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2010},
 +  series        = {IEEE S&P 2010},
 +  doi           = {10.1109/sp.2010.35},
 +}
 +
 +@inproceedings{liu2024_promises,
 +  author        = {Liu, Xiaoyin and Li, Wenzhi and Hou, Qinsheng and Yang, Shishuai and Ying, Lingyun and Diao, Wenrui and Li, Yanan and Guo, Shanqing and Duan, Haixin},
 +  title         = {From Promises to Practice: Evaluating the Private Browsing Modes of Android Browser Apps},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645320},
 +}
 +
 +@inproceedings{zhou2015_monitoring,
 +  author        = {Zhou, Yuchen and Evans, David},
 +  title         = {Understanding and Monitoring Embedded Web Scripts},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2015},
 +  series        = {IEEE S&P 2015},
 +  doi           = {10.1109/sp.2015.57},
 +}
 +
 +@inproceedings{kancherla2025_least,
 +  author        = {Kancherla, Gayatri Priyadarsini and Goel, Dishank and Bichhawat, Abhishek},
 +  title         = {Least Privilege Access for Persistent Storage Mechanisms in Web Browsers},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714887},
 +}
 +
 +@inproceedings{karami2021_awakening,
 +  author        = {Karami, Soroush and Ilia, Panagiotis and Polakis, Jason},
 +  title         = {Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy Leakage},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2021},
 +  series        = {NDSS 2021},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/awakening-the-webs-sleeper-agents-misusing-service-workers-for-privacy-leakage/},
 +}
 +
 +@inproceedings{lee2018_pride,
 +  author        = {Lee, Jiyeon and Kim, Hayeon and Park, Junghwan and Shin, Insik and Son, Sooel},
 +  title         = {Pride and Prejudice in Progressive Web Apps: Abusing Native App-like Features in Web Applications},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2018},
 +  series        = {CCS 2018},
 +  doi           = {10.1145/3243734.3243867},
 +}
 +
 +@inproceedings{mishra2021_dejavu,
 +  author        = {Mishra, Vikas and Laperdrix, Pierre and Rudametkin, Walter and Rouvoy, Romain},
 +  title         = {D\'ej\`a vu: Abusing Browser Cache Headers to Identify and Track Online Users},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2021},
 +  series        = {PETS 2021},
 +  doi           = {10.2478/popets-2021-0033},
 +}
 +
 +@inproceedings{snyder2023_poolparty,
 +  author        = {Snyder, Peter and Karami, Soroush and Edelstein, Arthur and Livshits, Benjamin and Haddadi, Hamed},
 +  title         = {Pool-Party: Exploiting Browser Resource Pools for Web Tracking},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/snyder},
 +}
 +
 +@inproceedings{aggarwal2010_analysis,
 +  author        = {Aggarwal, Gaurav and Bursztein, Elie and Jackson, Collin and Boneh, Dan},
 +  title         = {An Analysis of Private Browsing Modes in Modern Browsers},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2010},
 +  series        = {USENIX Security 2010},
 +  url           = {https://www.usenix.org/legacy/event/sec10/tech/full_papers/Aggarwal.pdf},
 +}
 +
 +@inproceedings{franken2018_cookiejar,
 +  author        = {Franken, Gertjan and Van Goethem, Tom and Joosen, Wouter},
 +  title         = {Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie Policies},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2018},
 +  series        = {USENIX Security 2018},
 +  url           = {https://www.usenix.org/conference/usenixsecurity18/presentation/franken},
 +}
 +
 +@inproceedings{patat2023_drm,
 +  author        = {Patat, Gwendal and Sabt, Mohamed and Fouque, Pierre-Alain},
 +  title         = {Your DRM Can Watch You Too: Exploring the Privacy Implications of Browsers (mis)Implementations of Widevine EME},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2023},
 +  series        = {PETS 2023},
 +  doi           = {10.56553/popets-2023-0112},
 +}
 +
 +@inproceedings{vekaria2025_bighelp,
 +  author        = {Vekaria, Yash and Canino, Aurelio Loris and Levitsky, Jonathan and Ciechonski, Alex and Callejo, Patricia and Mandalari, Anna Maria and Shafiq, Zubair},
 +  title         = {Big Help or Big Brother? Auditing Tracking, Profiling, and Personalization in Generative AI Assistants},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/vekaria},
 +}
 +
 +@inproceedings{wang2026_masks,
 +  author        = {Wang, Weihong and Dimova, Yana and Vansteenkiste, Victor and Van Goethem, Tom and Van Cutsem, Tom},
 +  title         = {The Masks We (Think We) Wear: Privacy Threats of Browser-Extension Wallets in the Web3 Ecosystem},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2026},
 +  series        = {PETS 2026},
 +  doi           = {10.56553/popets-2026-0094},
 } }
  
 </bibtex> </bibtex>
  
literature/bibliography.1787838828.txt.gz · Last modified: by karel.kubicek.claude

Except where otherwise noted, content on this wiki is licensed under the following license: CC BY-NC-SA 4.0
CC BY-NC-SA 4.0 Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki