User Tools

Site Tools


literature:bibliography

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
literature:bibliography [2026/08/28 18:32] – Add izhikevich2021_identifying, huang2025_trust, sethuraman2022_ipv4 for design:existing_datasets. Authored by Claude karel.kubicek.claudeliterature:bibliography [2026/08/31 19:47] (current) – Add 15 BibTeX entries for privacy:browser_storage (browser storage beyond cookies). Keys checked against all 703 existing entries for collisions, DOIs/URLs checked for the same paper under another key, titles similarity-scanned; all DOIs resolved via Cros karel.kubicek.claude
Line 6352: Line 6352:
   series        = {IMC 2022},   series        = {IMC 2022},
   doi           = {10.1145/3517745.3563018},   doi           = {10.1145/3517745.3563018},
 +}
 +
 +@inproceedings{leontiadis2014_nearly,
 +  author        = {Leontiadis, Nektarios and Moore, Tyler and Christin, Nicolas},
 +  title         = {A Nearly Four-Year Longitudinal Study of Search-Engine Poisoning},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2014},
 +  series        = {CCS 2014},
 +  doi           = {10.1145/2660267.2660332},
 +}
 +
 +@inproceedings{wang2016_anatomy,
 +  author        = {Wang, Bolun and Zhang, Xinyi and Wang, Gang and Zheng, Haitao and Zhao, Ben Y.},
 +  title         = {Anatomy of a Personalized Livestreaming System},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2016},
 +  series        = {IMC 2016},
 +  doi           = {10.1145/2987443.2987453},
 +}
 +
 +@inproceedings{chatterjee2018_spyware,
 +  author        = {Chatterjee, Rahul and Doerfler, Periwinkle and Orgad, Hadas and Havron, Sam and Palmer, Jackeline and Freed, Diana and Levy, Karen and Dell, Nicola and McCoy, Damon and Ristenpart, Thomas},
 +  title         = {The Spyware Used in Intimate Partner Violence},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2018},
 +  series        = {IEEE S&P 2018},
 +  doi           = {10.1109/sp.2018.00061},
 +}
 +
 +@inproceedings{lee2021_practice,
 +  author        = {Lee, Hyunwoo and Kim, Doowon and Kwon, Yonghwi},
 +  title         = {TLS 1.3 in Practice: How TLS 1.3 Contributes to the Internet},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450057},
 +}
 +
 +@inproceedings{maggi2013_years,
 +  author        = {Maggi, Federico and Frossi, Alessandro and Zanero, Stefano and Stringhini, Gianluca and Stone-Gross, Brett and Kruegel, Christopher and Vigna, Giovanni},
 +  title         = {Two years of short URLs internet measurement: security threats and countermeasures},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2013},
 +  series        = {TheWebConf 2013},
 +  doi           = {10.1145/2488388.2488463},
 +}
 +
 +@inproceedings{rueth2018_digging,
 +  author        = {R{\"u}th, Jan and Zimmermann, Torsten and Wolsing, Konrad and Hohlfeld, Oliver},
 +  title         = {Digging into Browser-based Crypto Mining},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2018},
 +  series        = {IMC 2018},
 +  doi           = {10.1145/3278532.3278539},
 +}
 +
 +@inproceedings{sabottke2015_vulnerability,
 +  author        = {Sabottke, Carl and Suciu, Octavian and Dumitra\c{s}, Tudor},
 +  title         = {Vulnerability Disclosure in the Age of Social Media: Exploiting Twitter for Predicting Real-World Exploits},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2015},
 +  series        = {USENIX Security 2015},
 +  url           = {https://www.usenix.org/conference/usenixsecurity15/technical-sessions/presentation/sabottke},
 +}
 +
 +@inproceedings{agten2015_seven,
 +  author        = {Agten, Pieter and Joosen, Wouter and Piessens, Frank and Nikiforakis, Nick},
 +  title         = {Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2015},
 +  series        = {NDSS 2015},
 +  url           = {https://www.ndss-symposium.org/ndss2015/ndss-2015-programme/seven-months-worth-mistakes-longitudinal-study-typosquatting-abuse/},
 +}
 +
 +@inproceedings{murley2021_websocket,
 +  author        = {Murley, Paul and Ma, Zane and Mason, Joshua and Bailey, Michael D. and Kharraz, Amin},
 +  title         = {WebSocket Adoption and the Landscape of the Real-Time Web},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450063},
 +}
 +
 +@inproceedings{kuchhal2021_knock,
 +  author        = {Kuchhal, Dhruv and Li, Frank},
 +  title         = {Knock and talk: investigating local network communications on websites},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487857},
 +}
 +
 +@inproceedings{bijmans2019_inadvertently,
 +  author        = {Bijmans, Hugo L.J. and Booij, Tim M. and Doerr, Christian},
 +  title         = {Inadvertently Making Cyber Criminals Rich: A Comprehensive Study of Cryptojacking Campaigns at Internet Scale},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2019},
 +  series        = {USENIX Security 2019},
 +  url           = {https://www.usenix.org/conference/usenixsecurity19/presentation/bijmans},
 +}
 +
 +@inproceedings{thomas2011_design,
 +  author        = {Thomas, Kurt and Grier, Chris and Ma, Justin and Paxson, Vern and Song, Dawn},
 +  title         = {Design and Evaluation of a Real-Time URL Spam Filtering Service},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2011},
 +  series        = {IEEE S&P 2011},
 +  doi           = {10.1109/sp.2011.25},
 +}
 +
 +@inproceedings{wondracek2010_practical,
 +  author        = {Wondracek, Gilbert and Holz, Thorsten and Kirda, Engin and Kruegel, Christopher},
 +  title         = {A Practical Attack to De-anonymize Social Network Users},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2010},
 +  series        = {IEEE S&P 2010},
 +  doi           = {10.1109/sp.2010.21},
 +}
 +
 +@inproceedings{koop2020_redirect,
 +  author        = {Koop, Martin and Tews, Erik and Katzenbeisser, Stefan},
 +  title         = {In-Depth Evaluation of Redirect Tracking and Link Usage},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2020},
 +  series        = {PoPETs 2020},
 +  doi           = {10.2478/popets-2020-0079},
 +}
 +
 +@inproceedings{konoth2018_minesweeper,
 +  author        = {Konoth, Radhesh Krishnan and Vineti, Emanuele and Moonsamy, Veelasha and Lindorfer, Martina and Kruegel, Christopher and Bos, Herbert and Vigna, Giovanni},
 +  title         = {MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its Defense},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2018},
 +  series        = {CCS 2018},
 +  doi           = {10.1145/3243734.3243858},
 +}
 +
 +@inproceedings{miramirkhani2017_dial,
 +  author        = {Miramirkhani, Najmeh and Starov, Oleksii and Nikiforakis, Nick},
 +  title         = {Dial One for Scam: A Large-Scale Analysis of Technical Support Scams},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2017},
 +  series        = {NDSS 2017},
 +  url           = {https://www.ndss-symposium.org/ndss2017/ndss-2017-programme/dial-one-scam-large-scale-analysis-technical-support-scams/},
 +}
 +
 +@inproceedings{zhang2023_under,
 +  author        = {Zhang, Zhenrui and Hong, Geng and Li, Xiang and Fu, Zhuoqun and Zhang, Jia and Liu, Mingxuan and Wang, Chuhan and Chen, Jianjun and Liu, Baojun and Duan, Haixin and Zhang, Chao and Yang, Min},
 +  title         = {Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616677},
 +}
 +
 +@inproceedings{dahlberg2023_timeless,
 +  author        = {Dahlberg, Rasmus and Pulls, Tobias},
 +  title         = {Timeless Timing Attacks and Preload Defenses in Tor's DNS Cache},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/dahlberg},
 +}
 +
 +@inproceedings{genkin2022_lend,
 +  author        = {Genkin, Daniel and Nissan, Noam and Schuster, Roei and Tromer, Eran},
 +  title         = {Lend Me Your Ear: Passive Remote Physical Side Channels on PCs},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/genkin},
 +}
 +
 +@inproceedings{qiu2023_calpric,
 +  author        = {Qiu, Wenjun and Lie, David and Austin, Lisa},
 +  title         = {Calpric: Inclusive and Fine-grain Labeling of Privacy Policies with Crowdsourcing and Active Learning},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/qiu},
 +}
 +
 +@inproceedings{pu2023_deepfake,
 +  author        = {Pu, Jiameng and Sarwar, Zain and Abdullah, Sifat Muhammad and Rehman, Abdullah and Kim, Yoonjin and Bhattacharya, Parantapa and Javed, Mobin and Viswanath, Bimal},
 +  title         = {Deepfake Text Detection: Limitations and Opportunities},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2023},
 +  series        = {IEEE S&P 2023},
 +  doi           = {10.1109/sp46215.2023.10179387},
 +}
 +
 +@inproceedings{li2021_good,
 +  author        = {Li, Xigao and Azad, Babak Amin and Rahmati, Amir and Nikiforakis, Nick},
 +  title         = {Good Bot, Bad Bot: Characterizing Automated Browsing Activity},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2021},
 +  series        = {IEEE S&P 2021},
 +  doi           = {10.1109/sp40001.2021.00079},
 +}
 +
 +
 +@inproceedings{herley2022_automated,
 +  author        = {Herley, Cormac},
 +  title         = {Automated Detection of Automated Traffic},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/herley},
 +}
 +
 +
 +@inproceedings{venugopalan2025_inconsistent,
 +  author        = {Venugopalan, Hari and Munir, Shaoor and Ahmed, Shuaib and Wang, Tangbaihe and King, Samuel T. and Shafiq, Zubair},
 +  title         = {FP-Inconsistent: Measurement and Analysis of Fingerprint Inconsistencies in Evasive Bot Traffic},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3732919},
 +}
 +
 +
 +@inproceedings{jan2020_throwing,
 +  author        = {Jan, Steve T. K. and Hao, Qingying and Hu, Tianrui and Pu, Jiameng and Oswal, Sonal and Wang, Gang and Viswanath, Bimal},
 +  title         = {Throwing Darts in the Dark? Detecting Bots with Limited Data using Neural Data Augmentation},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2020},
 +  series        = {IEEE S&P 2020},
 +  doi           = {10.1109/sp40000.2020.00079},
 +}
 +
 +
 +@inproceedings{liu2025_somesite,
 +  author        = {Liu, Enze and Luo, Elisa and Shan, Shawn and Voelker, Geoffrey M. and Zhao, Ben Y. and Savage, Stefan},
 +  title         = {Somesite I Used To Crawl: Awareness, Agency and Efficacy in Protecting Content Creators From AI Crawlers},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3732913},
 +}
 +
 +
 +@inproceedings{cui2025_odyssey,
 +  author        = {Cui, Jian and Zha, Mingming and Wang, XiaoFeng and Liao, Xiaojing},
 +  title         = {The Odyssey of robots.txt Governance: Measuring Convention Implications of Web Bots in Large Language Model Services},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2025},
 +  series        = {CCS 2025},
 +  doi           = {10.1145/3719027.3765063},
 +}
 +
 +
 +@inproceedings{kim2025_scrapers,
 +  author        = {Kim, Taein and Bock, Karstan and Luo, Claire and Liswood, Amanda and Poroslay, Chloe and Wenger, Emily},
 +  title         = {Scrapers Selectively Respect robots.txt Directives: Evidence From a Large-Scale Empirical Study},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3764471},
 +}
 +
 +
 +@inproceedings{qi2026_viper,
 +  author        = {Qi, Minfeng and He, Dongyang and Wang, Qin and Zhang, Lefeng},
 +  title         = {VIPER Strike: Defeating Visual Reasoning CAPTCHAs via Structured Vision–Language Inference},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/qi-minfeng},
 +}
 +
 +
 +@inproceedings{nguyen2024_frame,
 +  author        = {Nguyen, Hoang Dai and Subramani, Karthika and Acharya, Bhupendra and Perdisci, Roberto and Vadrevu, Phani},
 +  title         = {C-Frame: Characterizing and measuring in-the-wild CAPTCHA attacks},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2024},
 +  series        = {IEEE S&P 2024},
 +  doi           = {10.1109/sp54263.2024.00200},
 +}
 +
 +
 +@inproceedings{ardi2023_prevalence,
 +  author        = {Ardi, Calvin and Calder, Matt},
 +  title         = {The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624841},
 +}
 +
 +
 +@inproceedings{wang2011_cloak,
 +  author        = {Wang, David Y. and Savage, Stefan and Voelker, Geoffrey M.},
 +  title         = {Cloak and dagger: dynamics of web search cloaking},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2011},
 +  series        = {CCS 2011},
 +  doi           = {10.1145/2046707.2046763},
 +}
 +
 +
 +@inproceedings{maroofi2020_human,
 +  author        = {Maroofi, Sourena and Korczynski, Maciej and Duda, Andrzej},
 +  title         = {Are You Human?: Resilience of Phishing Detection to Evasion Techniques Based on Human Verification},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2020},
 +  series        = {IMC 2020},
 +  doi           = {10.1145/3419394.3423632},
 +}
 +
 +
 +@inproceedings{szurdi2021_where,
 +  author        = {Szurdi, Janos and Luo, Meng and Kondracki, Brian and Nikiforakis, Nick and Christin, Nicolas},
 +  title         = {Where are you taking me?Understanding Abusive Traffic Distribution Systems},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450071},
 +}
 +
 +
 +@inproceedings{shi2020_text,
 +  author        = {Shi, Chenghui and Ji, Shouling and Liu, Qianjun and Liu, Changchang and Chen, Yuefeng and He, Yuan and Liu, Zhe and Beyah, Raheem and Wang, Ting},
 +  title         = {Text Captcha Is Dead? A Large Scale Deployment and Empirical Study},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417258},
 +}
 +
 +
 +@inproceedings{oh2017_fingerprinting,
 +  author        = {Oh, Se Eun and Li, Shuai and Hopper, Nicholas},
 +  title         = {Fingerprinting Keywords in Search Queries over Tor},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2017},
 +  series        = {PETS 2017},
 +  doi           = {10.1515/popets-2017-0048},
 +}
 +
 +@inproceedings{campobasso2020_impersonation,
 +  author        = {Campobasso, Michele and Allodi, Luca},
 +  title         = {Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at Scale},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417892},
 +}
 +
 +@inproceedings{steiner2026_nlweb,
 +  author        = {Steiner, Aaron and Peeters, Ralph and Bizer, Christian},
 +  title         = {MCP vs RAG vs NLWeb vs HTML: A Comparison of the Effectiveness and Efficiency of Different Agent Interfaces to the Web},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792893},
 +}
 +
 +@inproceedings{jeong2026_network,
 +  author        = {Jeong, Hyejun and Teymoorianfard, Mohammadreza and Kumar, Abhinav and Houmansadr, Amir and Bagdasarian, Eugene},
 +  title         = {Network-Level Prompt and Trait Leakage in Local Research Agents},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/jeong},
 +}
 +
 +@inproceedings{zhao2026_parasites,
 +  author        = {Zhao, Shuli and Hou, Qinsheng and Zhan, Zihan and Wang, Yanhao and Xie, Yuchong and Guo, Yu and Chen, Libo and Li, Shenghong and Xue, Zhi},
 +  title         = {Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the {MCP} Ecosystem},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2026},
 +  series        = {IEEE S&P 2026},
 +  doi           = {10.1109/sp63933.2026.00154},
 +}
 +
 +@article{ramesh2026_webspeval,
 +  author        = {Ramesh, Guruprasad Viswanathan and Nayak, Asmit and Siddique, Basieem and Fawaz, Kassem},
 +  title         = {WebSP-Eval: Evaluating Web Agents on Website Security and Privacy Tasks},
 +  journal       = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2026},
 +  volume        = {2026},
 +  number        = {4},
 +  pages         = {666--702},
 +  doi           = {10.56553/popets-2026-0140},
 +}
 +
 +@inproceedings{chang2026_overcoming,
 +  author        = {Chang, Hongyan and Bao, Ergute and Luo, Xinjian and Yu, Ting},
 +  title         = {Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for {LLM} Systems},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/chang-hongyan},
 +}
 +
 +@inproceedings{shuba2018_nomoads,
 +  author        = {Shuba, Anastasia and Markopoulou, Athina and Shafiq, Zubair},
 +  title         = {NoMoAds: Effective and Efficient Cross-App Mobile Ad-Blocking},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2018},
 +  series        = {PoPETs 2018},
 +  doi           = {10.1515/popets-2018-0035},
 +}
 +
 +@inproceedings{shuba2020_nomoats,
 +  author        = {Shuba, Anastasia and Markopoulou, Athina},
 +  title         = {NoMoATS: Towards Automatic Detection of Mobile Tracking},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2020},
 +  series        = {PoPETs 2020},
 +  doi           = {10.2478/popets-2020-0017},
 +}
 +
 +@inproceedings{varmarken2020_smart,
 +  author        = {Varmarken, Janus and Le, Hieu and Shuba, Anastasia and Markopoulou, Athina and Shafiq, Zubair},
 +  title         = {The TV is Smart and Full of Trackers: Measuring Smart TV Advertising and Tracking},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2020},
 +  series        = {PoPETs 2020},
 +  doi           = {10.2478/popets-2020-0021},
 +}
 +
 +@inproceedings{watanabe2020_melting,
 +  author        = {Watanabe, Takuya and Shioji, Eitaro and Akiyama, Mitsuaki and Mori, Tatsuya},
 +  title         = {Melting Pot of Origins: Compromising the Intermediary Web Services that Rehost Websites},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2020},
 +  series        = {NDSS 2020},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/melting-pot-of-origins-compromising-the-intermediary-web-services-that-rehost-websites/},
 +}
 +
 +@inproceedings{ali2023_navigating,
 +  author        = {Ali, Mir Masood and Chitale, Binoy and Ghasemisharif, Mohammad and Kanich, Chris and Nikiforakis, Nick and Polakis, Jason},
 +  title         = {Navigating Murky Waters: Automated Browser Feature Testing for Uncovering Tracking Vectors},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2023},
 +  series        = {NDSS 2023},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/navigating-murky-waters-automated-browser-feature-testing-for-uncovering-tracking-vectors/},
 +}
 +
 +@inproceedings{singh2010_incoherencies,
 +  author        = {Singh, Kapil and Moshchuk, Alexander and Wang, Helen J. and Lee, Wenke},
 +  title         = {On the Incoherencies in Web Browser Access Control Policies},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2010},
 +  series        = {IEEE S&P 2010},
 +  doi           = {10.1109/sp.2010.35},
 +}
 +
 +@inproceedings{liu2024_promises,
 +  author        = {Liu, Xiaoyin and Li, Wenzhi and Hou, Qinsheng and Yang, Shishuai and Ying, Lingyun and Diao, Wenrui and Li, Yanan and Guo, Shanqing and Duan, Haixin},
 +  title         = {From Promises to Practice: Evaluating the Private Browsing Modes of Android Browser Apps},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645320},
 +}
 +
 +@inproceedings{zhou2015_monitoring,
 +  author        = {Zhou, Yuchen and Evans, David},
 +  title         = {Understanding and Monitoring Embedded Web Scripts},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2015},
 +  series        = {IEEE S&P 2015},
 +  doi           = {10.1109/sp.2015.57},
 +}
 +
 +@inproceedings{kancherla2025_least,
 +  author        = {Kancherla, Gayatri Priyadarsini and Goel, Dishank and Bichhawat, Abhishek},
 +  title         = {Least Privilege Access for Persistent Storage Mechanisms in Web Browsers},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714887},
 +}
 +
 +@inproceedings{karami2021_awakening,
 +  author        = {Karami, Soroush and Ilia, Panagiotis and Polakis, Jason},
 +  title         = {Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy Leakage},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2021},
 +  series        = {NDSS 2021},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/awakening-the-webs-sleeper-agents-misusing-service-workers-for-privacy-leakage/},
 +}
 +
 +@inproceedings{lee2018_pride,
 +  author        = {Lee, Jiyeon and Kim, Hayeon and Park, Junghwan and Shin, Insik and Son, Sooel},
 +  title         = {Pride and Prejudice in Progressive Web Apps: Abusing Native App-like Features in Web Applications},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2018},
 +  series        = {CCS 2018},
 +  doi           = {10.1145/3243734.3243867},
 +}
 +
 +@inproceedings{mishra2021_dejavu,
 +  author        = {Mishra, Vikas and Laperdrix, Pierre and Rudametkin, Walter and Rouvoy, Romain},
 +  title         = {D\'ej\`a vu: Abusing Browser Cache Headers to Identify and Track Online Users},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2021},
 +  series        = {PETS 2021},
 +  doi           = {10.2478/popets-2021-0033},
 +}
 +
 +@inproceedings{snyder2023_poolparty,
 +  author        = {Snyder, Peter and Karami, Soroush and Edelstein, Arthur and Livshits, Benjamin and Haddadi, Hamed},
 +  title         = {Pool-Party: Exploiting Browser Resource Pools for Web Tracking},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/snyder},
 +}
 +
 +@inproceedings{aggarwal2010_analysis,
 +  author        = {Aggarwal, Gaurav and Bursztein, Elie and Jackson, Collin and Boneh, Dan},
 +  title         = {An Analysis of Private Browsing Modes in Modern Browsers},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2010},
 +  series        = {USENIX Security 2010},
 +  url           = {https://www.usenix.org/legacy/event/sec10/tech/full_papers/Aggarwal.pdf},
 +}
 +
 +@inproceedings{franken2018_cookiejar,
 +  author        = {Franken, Gertjan and Van Goethem, Tom and Joosen, Wouter},
 +  title         = {Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie Policies},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2018},
 +  series        = {USENIX Security 2018},
 +  url           = {https://www.usenix.org/conference/usenixsecurity18/presentation/franken},
 +}
 +
 +@inproceedings{patat2023_drm,
 +  author        = {Patat, Gwendal and Sabt, Mohamed and Fouque, Pierre-Alain},
 +  title         = {Your DRM Can Watch You Too: Exploring the Privacy Implications of Browsers (mis)Implementations of Widevine EME},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2023},
 +  series        = {PETS 2023},
 +  doi           = {10.56553/popets-2023-0112},
 +}
 +
 +@inproceedings{vekaria2025_bighelp,
 +  author        = {Vekaria, Yash and Canino, Aurelio Loris and Levitsky, Jonathan and Ciechonski, Alex and Callejo, Patricia and Mandalari, Anna Maria and Shafiq, Zubair},
 +  title         = {Big Help or Big Brother? Auditing Tracking, Profiling, and Personalization in Generative AI Assistants},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/vekaria},
 +}
 +
 +@inproceedings{wang2026_masks,
 +  author        = {Wang, Weihong and Dimova, Yana and Vansteenkiste, Victor and Van Goethem, Tom and Van Cutsem, Tom},
 +  title         = {The Masks We (Think We) Wear: Privacy Threats of Browser-Extension Wallets in the Web3 Ecosystem},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2026},
 +  series        = {PETS 2026},
 +  doi           = {10.56553/popets-2026-0094},
 } }
  
 </bibtex> </bibtex>
  
literature/bibliography.1787941979.txt.gz · Last modified: by karel.kubicek.claude

Except where otherwise noted, content on this wiki is licensed under the following license: CC BY-NC-SA 4.0
CC BY-NC-SA 4.0 Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki