User Tools

Site Tools


literature:bibliography

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
literature:bibliography [2026/09/15 16:39] – Add 11 entries for privacy:age_assurance (age verification, COPPA compliance, children's apps, age ratings). Authored by Claude karel.kubicek.claudeliterature:bibliography [2026/09/27 16:40] (current) – Add 2 Telegram Mini Apps preprints for design:mobile_and_app_measurement:mini_programs (review fix). Authored by Claude karel.kubicek.claude
Line 5679: Line 5679:
 } }
  
-@inproceedings{som2017_content,+@inproceedings{some2017_content,
   author        = {Somé, Dolière Francis and Bielova, Nataliia and Rezk, Tamara},   author        = {Somé, Dolière Francis and Bielova, Nataliia and Rezk, Tamara},
   title         = {On the Content Security Policy Violations due to the Same-Origin Policy},   title         = {On the Content Security Policy Violations due to the Same-Origin Policy},
Line 6091: Line 6091:
 } }
  
-@inproceedings{khrer2015_going,+@inproceedings{kuhrer2015_going,
   author        = {Kührer, Marc and Hupperich, Thomas and Bushart, Jonas and Rossow, Christian and Holz, Thorsten},   author        = {Kührer, Marc and Hupperich, Thomas and Bushart, Jonas and Rossow, Christian and Holz, Thorsten},
   title         = {Going Wild: Large-Scale Classification of Open DNS Resolvers},   title         = {Going Wild: Large-Scale Classification of Open DNS Resolvers},
Line 9696: Line 9696:
  
 @inproceedings{zhao2023_mobile, @inproceedings{zhao2023_mobile,
-  author        = {Zhao, Yanjie and Liu, Tianming and Wang, Haoyu and Liu, Yepang and Grundy, John C. and Li, Li},+  author        = {Zhao, Yanjie and Liu, Tianming and Wang, Haoyu and Liu, Yepang and Grundy, John and Li, Li},
   title         = {Are Mobile Advertisements in Compliance with App's Age Group?},   title         = {Are Mobile Advertisements in Compliance with App's Age Group?},
   booktitle     = {Proceedings of the ACM Web Conference},   booktitle     = {Proceedings of the ACM Web Conference},
Line 9756: Line 9756:
   series        = {PoPETs 2025},   series        = {PoPETs 2025},
   doi           = {10.56553/popets-2025-0094},   doi           = {10.56553/popets-2025-0094},
 +}
 +
 +@inproceedings{xue2016_right,
 +  author        = {Xue, Minhui and Magno, Gabriel and Cunha, Evandro and Almeida, Virgilio and Ross, Keith W.},
 +  title         = {The Right to be Forgotten in the Media: A Data-Driven Study},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2016},
 +  series        = {PoPETs 2016},
 +  doi           = {10.1515/popets-2016-0046},
 +}
 +
 +@inproceedings{zaman2019_detecting,
 +  author        = {Zaman, Anis and Acharyya, Rupam and Kautz, Henry A. and Silenzio, Vincent},
 +  title         = {Detecting Low Self-Esteem in Youths from Web Search Data},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2019},
 +  series        = {TheWebConf 2019},
 +  doi           = {10.1145/3308558.3313557},
 +}
 +
 +@inproceedings{wei2020_twitter,
 +  author        = {Wei, Miranda and Stamos, Madison and Veys, Sophie and Reitinger, Nathan and Goodman, Justin and Herman, Margot and Filipczuk, Dorota and Weinshel, Ben and Mazurek, Michelle L. and Ur, Blase},
 +  title         = {What Twitter Knows: Characterizing Ad Targeting Practices, User Perceptions, and Ad Explanations Through Users' Own Twitter Data},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2020},
 +  series        = {USENIX Security 2020},
 +  url           = {https://www.usenix.org/conference/usenixsecurity20/presentation/wei},
 +}
 +
 +@inproceedings{syrmoudis2021_data,
 +  author        = {Syrmoudis, Emmanuel and Mager, Stefan and Kuebler-Wachendorff, Sophie and Pizzinini, Paul and Grossklags, Jens and Kranz, Johann},
 +  title         = {Data Portability between Online Services: An Empirical Analysis on the Effectiveness of GDPR Art. 20},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2021},
 +  series        = {PoPETs 2021},
 +  doi           = {10.2478/popets-2021-0051},
 +}
 +
 +@inproceedings{onaolapo2021_socialheisting,
 +  author        = {Onaolapo, Jeremiah and Leontiadis, Nektarios and Magka, Despoina and Stringhini, Gianluca},
 +  title         = {SocialHEISTing: Understanding Stolen Facebook Accounts},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/onaolapo},
 +}
 +
 +@inproceedings{santhanam2022_scraping,
 +  author        = {Santhanam, Preethi and Dang, Hoang and Shan, Zhiyong and Neamtiu, Iulian},
 +  title         = {Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2022},
 +  series        = {IEEE S&P 2022},
 +  doi           = {10.1109/sp46214.2022.9833720},
 +}
 +
 +@inproceedings{take2022_feels,
 +  author        = {Take, Kejsi and Gallagher, Kevin and Forte, Andrea and McCoy, Damon and Greenstadt, Rachel},
 +  title         = {“It Feels Like Whack-a-mole”: User Experiences of Data Removal from People Search Websites},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2022},
 +  series        = {PoPETs 2022},
 +  doi           = {10.56553/popets-2022-0067},
 +}
 +
 +@inproceedings{liu2022_your,
 +  author        = {Liu, Yijing and Jia, Yan and Tan, Qingyin and Liu, Zheli and Xing, Luyi},
 +  title         = {How Are Your Zombie Accounts? Understanding Users' Practices and Expectations on Mobile App Account Deletion},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/liu-yijing},
 +}
 +
 +@inproceedings{sharma2022_improving,
 +  author        = {Sharma, Vandit and Mondal, Mainack},
 +  title         = {Understanding and Improving Usability of Data Dashboards for Simplified Privacy Control of Voice Assistant Data},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/sharma-vandit},
 +}
 +
 +@inproceedings{du2024_withdrawing,
 +  author        = {Du, Xiaolin and Yang, Zhemin and Lin, Jiapeng and Cao, Yinzhi and Yang, Min},
 +  title         = {Withdrawing is believing? Detecting Inconsistencies between Withdrawal Choices and Third-party Data Collections in Mobile Apps},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2024},
 +  series        = {IEEE S&P 2024},
 +  doi           = {10.1109/sp54263.2024.00014},
 +}
 +
 +@inproceedings{zimmeck2024_generalizable,
 +  author        = {Zimmeck, Sebastian and Kuller, Eliza and Ma, Chunyue and Tassone, Bella and Champeau, Joe},
 +  title         = {Generalizable Active Privacy Choice: Designing a Graphical User Interface for Global Privacy Control},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2024},
 +  series        = {PoPETs 2024},
 +  doi           = {10.56553/popets-2024-0015},
 +}
 +
 +@inproceedings{caravaca2024_overprofiling,
 +  author        = {Caravaca, Francisco and González-Cabañas, José and Cuevas, Ángel and Cuevas, Rubén},
 +  title         = {Overprofiling Analysis on Major Internet Players},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2024},
 +  series        = {PoPETs 2024},
 +  doi           = {10.56553/popets-2024-0149},
 +}
 +
 +@inproceedings{borem2024_data,
 +  author        = {Borem, Arthur and Pan, Elleen and Obielodan, Olufunmilola and Roubinowitz, Aurelie and Dovichi, Luca and Mazurek, Michelle L. and Ur, Blase},
 +  title         = {Data Subjects' Reactions to Exercising Their Right of Access},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/borem},
 +}
 +
 +@inproceedings{nonnenkamp2025_hidden,
 +  author        = {Nonnenkamp, Julia and Gupta, Naman and Gupta, Abhimanyu Dev and Chatterjee, Rahul},
 +  title         = {Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data Exports},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2025},
 +  series        = {CCS 2025},
 +  doi           = {10.1145/3719027.3765147},
 +}
 +
 +@inproceedings{cheng2025_erasing,
 +  author        = {Cheng, Cheng and Ramokapane, Kopo M.},
 +  title         = {``Erasing the Echo'': The Usability of Data Deletion in Smart Personal Assistants},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2025},
 +  series        = {PoPETs 2025},
 +  doi           = {10.56553/popets-2025-0120},
 +}
 +
 +@inproceedings{he2025_accuracy,
 +  author        = {He, Jiahui and Snyder, Peter and Haddadi, Hamed and Bustamante, Fabián E. and Tyson, Gareth},
 +  title         = {Measuring the Accuracy and Effectiveness of PII Removal Services},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2025},
 +  series        = {PoPETs 2025},
 +  doi           = {10.56553/popets-2025-0125},
 +}
 +
 +@inproceedings{yan2025_sign,
 +  author        = {Yan, Jingwen and Liao, Song and Ma, Jin and Aldeen, Mohammed and Kumar, Salish and Cheng, Long},
 +  title         = {No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion Requirements},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/yan-jingwen},
 +}
 +
 +@inproceedings{karnam2026_bowling,
 +  author        = {Karnam, Sai Keerthana and Dash, Abhisek and Gummadi, Krishna P. and Mukherjee, Animesh and Weber, Ingmar and Zannettou, Savvas},
 +  title         = {Bowling with ChatGPT: On the Evolving User Interactions with Conversational AI Systems},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792978},
 +}
 +
 +@inproceedings{mousavi2026_does,
 +  author        = {Mousavi, Sepehr and Dash, Abhisek and Zannettou, Savvas and Gummadi, Krishna P.},
 +  title         = {Does Ad-Free Mean Less Data Collection? An Empirical Study of Platform Data Practices and User Expectations},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792558},
 +}
 +@inproceedings{abramova2023_anatomy,
 +  author        = {Abramova, Svetlana and Böhme, Rainer},
 +  title         = {Anatomy of a High-Profile Data Breach: Dissecting the Aftermath of a Crypto-Wallet Case},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/abramova},
 +}
 +
 +
 +@inproceedings{zafar2025_assessing,
 +  author        = {Zafar, Ahsan and Das, Anupam},
 +  title         = {Assessing Compliance in Digital Advertising: A Deep Dive into Acceptable Ads Standards},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714725},
 +}
 +
 +@inproceedings{zarras2014_dark,
 +  author        = {Zarras, Apostolis and Kapravelos, Alexandros and Stringhini, Gianluca and Holz, Thorsten and Kruegel, Christopher and Vigna, Giovanni},
 +  title         = {The Dark Alleys of Madison Avenue: Understanding Malicious Advertisements},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2014},
 +  series        = {IMC 2014},
 +  doi           = {10.1145/2663716.2663719},
 +}
 +
 +@inproceedings{barford2014_adscape,
 +  author        = {Barford, Paul and Canadi, Igor and Krushevskaja, Darja and Ma, Qiang and Muthukrishnan, S.},
 +  title         = {Adscape: Harvesting and Analyzing Online Display Ads},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2014},
 +  series        = {TheWebConf 2014},
 +  doi           = {10.1145/2566486.2567992},
 +}
 +
 +@inproceedings{bashir2016_recommended,
 +  author        = {Bashir, Muhammad Ahmad and Arshad, Sajjad and Wilson, Christo},
 +  title         = {Recommended For You: A First Look at Content Recommendation Networks},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2016},
 +  series        = {IMC 2016},
 +  doi           = {10.1145/2987443.2987469},
 +}
 +
 +@inproceedings{plane2017_exploring,
 +  author        = {Plane, Angelisa C. and Redmiles, Elissa M. and Mazurek, Michelle L. and Tschantz, Michael Carl},
 +  title         = {Exploring User Perceptions of Discrimination in Online Targeted Advertising},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2017},
 +  series        = {USENIX Security 2017},
 +  url           = {https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/plane},
 +}
 +
 +@inproceedings{cabanas2018_unveiling,
 +  author        = {González-Cabañas, José and Cuevas, Ángel and Cuevas, Rubén},
 +  title         = {Unveiling and Quantifying Facebook Exploitation of Sensitive Personal Data for Advertising Purposes},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2018},
 +  series        = {USENIX Security 2018},
 +  url           = {https://www.usenix.org/conference/usenixsecurity18/presentation/cabanas},
 +}
 +
 +@inproceedings{andreou2018_investigating,
 +  author        = {Andreou, Athanasios and Venkatadri, Giridhari and Goga, Oana and Gummadi, Krishna P. and Loiseau, Patrick and Mislove, Alan},
 +  title         = {Investigating Ad Transparency Mechanisms in Social Media: A Case Study of Facebook's Explanations},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2018},
 +  series        = {NDSS 2018},
 +  doi           = {10.14722/ndss.2018.23191},
 +}
 +
 +@inproceedings{olejnik2014_selling,
 +  author        = {Olejnik, Lukasz and Tran, Minh-Dung and Castelluccia, Claude},
 +  title         = {Selling Off Privacy at Auction},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2014},
 +  series        = {NDSS 2014},
 +  doi           = {10.14722/ndss.2014.23270},
 +}
 +
 +@inproceedings{vadrevu2019_discovering,
 +  author        = {Vadrevu, Phani and Perdisci, Roberto},
 +  title         = {What You See is NOT What You Get: Discovering and Tracking Social Engineering Attack Campaigns},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2019},
 +  series        = {IMC 2019},
 +  doi           = {10.1145/3355369.3355600},
 +}
 +
 +@inproceedings{andreou2019_facebook,
 +  author        = {Andreou, Athanasios and Silva, Márcio and Benevenuto, Fabrício and Goga, Oana and Loiseau, Patrick and Mislove, Alan},
 +  title         = {Measuring the Facebook Advertising Ecosystem},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2019},
 +  series        = {NDSS 2019},
 +  doi           = {10.14722/ndss.2019.23280},
 +}
 +
 +@inproceedings{chen2019_madlife,
 +  author        = {Chen, Gong and Meng, Wei and Copeland, John A.},
 +  title         = {Revisiting Mobile Advertising Threats with MAdLife},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2019},
 +  series        = {TheWebConf 2019},
 +  doi           = {10.1145/3308558.3313549},
 +}
 +
 +@inproceedings{cabanas2021_unique,
 +  author        = {González-Cabañas, José and Cuevas, Ángel and Cuevas, Rubén and López-Fernández, Juan and García, David},
 +  title         = {Unique on Facebook: Formulation and Evidence of (Nano)targeting Individual Users with non-PII Data},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487861},
 +}
 +
 +@inproceedings{ballard2022_conspiracy,
 +  author        = {Ballard, Cameron and Goldstein, Ian and Mehta, Pulak and Smothers, Genesis and Take, Kejsi and Zhong, Victoria and Greenstadt, Rachel and Lauinger, Tobias and McCoy, Damon},
 +  title         = {Conspiracy Brokers: Understanding the Monetization of YouTube Conspiracy Theories},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2022},
 +  series        = {TheWebConf 2022},
 +  doi           = {10.1145/3485447.3512142},
 +}
 +
 +@inproceedings{yeung2024_accessibility,
 +  author        = {Yeung, Christina and Kohno, Tadayoshi and Roesner, Franziska},
 +  title         = {Analyzing the (In)Accessibility of Online Advertisements},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2024},
 +  series        = {IMC 2024},
 +  doi           = {10.1145/3646547.3688427},
 +}
 +
 +@inproceedings{farke2024_connecting,
 +  author        = {Farke, Florian M. and Balash, David G. and Golla, Maximilian and Aviv, Adam J.},
 +  title         = {How Does Connecting Online Activities to Advertising Inferences Impact Privacy Perceptions?},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2024},
 +  series        = {PoPETs 2024},
 +  doi           = {10.56553/popets-2024-0055},
 +}
 +
 +@inproceedings{sabir2025_alexa,
 +  author        = {Sabir, Aafaq and B., Abhinaya S. and Ahmed, Dilawer and Das, Anupam},
 +  title         = {Analyzing Ad Prevalence, Characteristics, and Compliance in Alexa Skills},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2025},
 +  series        = {IEEE S&P 2025},
 +  doi           = {10.1109/sp61157.2025.00257},
 +}
 +
 +@inproceedings{kaushik2025_perceptions,
 +  author        = {Kaushik, Smirity and Sharma, Tanusree and Yu, Yaman and Ali, Amna and Knijnenburg, Bart Piet and Wang, Yang and Zou, Yixin},
 +  title         = {Privacy Perceptions and Behaviors Towards Targeted Advertising on Social Media: A Cross-Country Study on the Effect of Culture and Religion},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2025},
 +  series        = {PoPETs 2025},
 +  doi           = {10.56553/popets-2025-0057},
 +}
 +
 +@article{boerman2017_oba,
 +  author        = {Boerman, Sophie C. and Kruikemeier, Sanne and Zuiderveen Borgesius, Frederik J.},
 +  title         = {Online Behavioral Advertising: A Literature Review and Research Agenda},
 +  journal       = {Journal of Advertising},
 +  volume        = {46},
 +  number        = {3},
 +  pages         = {363--376},
 +  year          = {2017},
 +  doi           = {10.1080/00913367.2017.1339368},
 +}
 +
 +@article{angus2024_donation,
 +  author        = {Angus, Daniel and Obeid, Abdul Karim and Burgess, Jean and Parker, Christine and Andrejevic, Mark and Carah, Nicholas and Tan, Xue Ying},
 +  title         = {Enabling Online Advertising Transparency through Data Donation Methods},
 +  journal       = {Computational Communication Research},
 +  volume        = {6},
 +  number        = {2},
 +  year          = {2024},
 +  doi           = {10.5117/ccr2024.2.6.angu},
 +}
 +
 +@inproceedings{christin2010_dissecting,
 +  author        = {Christin, Nicolas and Yanagihara, Sally S. and Kamataki, Keisuke},
 +  title         = {Dissecting one click frauds},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2010},
 +  series        = {CCS 2010},
 +  doi           = {10.1145/1866307.1866310},
 +}
 +
 +@inproceedings{mccoy2012_priceless,
 +  author        = {McCoy, Damon and Dharmdasani, Hitesh and Kreibich, Christian and Voelker, Geoffrey M. and Savage, Stefan},
 +  title         = {Priceless: the role of payments in abuse-advertised goods},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2012},
 +  series        = {CCS 2012},
 +  doi           = {10.1145/2382196.2382285},
 +}
 +
 +@inproceedings{wang2014_search,
 +  author        = {Wang, David Y. and Der, Matthew F. and Karami, Mohammad and Saul, Lawrence K. and McCoy, Damon and Savage, Stefan and Voelker, Geoffrey M.},
 +  title         = {Search + Seizure: The Effectiveness of Interventions on SEO Campaigns},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2014},
 +  series        = {IMC 2014},
 +  doi           = {10.1145/2663716.2663738},
 +}
 +
 +@inproceedings{starov2018_betrayed,
 +  author        = {Starov, Oleksii and Zhou, Yuchen and Zhang, Xiao and Miramirkhani, Najmeh and Nikiforakis, Nick},
 +  title         = {Betrayed by Your Dashboard: Discovering Malicious Campaigns via Web Analytics},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2018},
 +  series        = {TheWebConf 2018},
 +  doi           = {10.1145/3178876.3186089},
 +}
 +
 +@inproceedings{srinivasan2018_exposing,
 +  author        = {Srinivasan, Bharat and Kountouras, Athanasios and Miramirkhani, Najmeh and Alam, Monjur and Nikiforakis, Nick and Antonakakis, Manos and Ahamad, Mustaque},
 +  title         = {Exposing Search and Advertisement Abuse Tactics and Infrastructure of Technical Support Scammers},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2018},
 +  series        = {TheWebConf 2018},
 +  doi           = {10.1145/3178876.3186098},
 +}
 +
 +@inproceedings{kharraz2018_surveylance,
 +  author        = {Kharraz, Amin and Robertson, William K. and Kirda, Engin},
 +  title         = {Surveylance: Automatically Detecting Online Survey Scams},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2018},
 +  series        = {IEEE S&P 2018},
 +  doi           = {10.1109/sp.2018.00044},
 +}
 +
 +@inproceedings{na2023_evolving,
 +  author        = {Na, Seung Ho and Cho, Sumin and Shin, Seungwon},
 +  title         = {Evolving Bots: The New Generation of Comment Bots and their Underlying Scam Campaigns in YouTube},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624822},
 +}
 +
 +@inproceedings{li2023_double,
 +  author        = {Li, Xigao and Yepuri, Anurag and Nikiforakis, Nick},
 +  title         = {Double and Nothing: Understanding and Detecting Cryptocurrency Giveaway Scams},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2023},
 +  series        = {NDSS 2023},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/double-and-nothing-understanding-and-detecting-cryptocurrency-giveaway-scams/},
 +}
 +
 +@inproceedings{li2024_like,
 +  author        = {Li, Xigao and Rahmati, Amir and Nikiforakis, Nick},
 +  title         = {Like, Comment, Get Scammed: Characterizing Comment Scams on Media Platforms},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2024},
 +  series        = {NDSS 2024},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/like-comment-get-scammed-characterizing-comment-scams-on-media-platforms/},
 +}
 +
 +@inproceedings{liu2024_give,
 +  author        = {Liu, Enze and Kappos, George and Mugnier, Eric and Invernizzi, Luca and Savage, Stefan and Tao, David and Thomas, Kurt and Voelker, Geoffrey M. and Meiklejohn, Sarah},
 +  title         = {Give and Take: An End-To-End Investigation of Giveaway Scam Conversion Rates},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2024},
 +  series        = {IMC 2024},
 +  doi           = {10.1145/3646547.3689005},
 +}
 +
 +@inproceedings{bitaab2023_beyond,
 +  author        = {Bitaab, Marzieh and Cho, Haehyun and Oest, Adam and Lyu, Zhuoer and Wang, Wei and Abraham, Jorij and Wang, Ruoyu and Bao, Tiffany and Shoshitaishvili, Yan and Doupé, Adam},
 +  title         = {Beyond Phish: Toward Detecting Fraudulent e-Commerce Websites at Scale},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2023},
 +  series        = {IEEE S&P 2023},
 +  doi           = {10.1109/sp46215.2023.10179461},
 +}
 +
 +@inproceedings{kotzias2025_ctrl,
 +  author        = {Kotzias, Platon and Pachilakis, Michalis and Iuit, Javier Aldana and Caballero, Juan and Sanchez-Rola, Iskander and Bilge, Leyla},
 +  title         = {Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/ctrlaltdeceive-quantifying-user-exposure-to-online-scams/},
 +}
 +
 +@inproceedings{muzammil2025_poorest,
 +  author        = {Muzammil, Muhammad and Pitumpe, Abisheka and Li, Xigao and Rahmati, Amir and Nikiforakis, Nick},
 +  title         = {The Poorest Man in Babylon: A Longitudinal Study of Cryptocurrency Investment Scams},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714588},
 +}
 +
 +@inproceedings{paudel2026_loki,
 +  author        = {Paudel, Pujan and Stringhini, Gianluca},
 +  title         = {LOKI: Proactively Discovering Online Scam Websites by Mining Toxic Search Queries},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/loki-proactively-discovering-online-scams-by-mining-toxic-search-queries/},
 +}
 +
 +@inproceedings{liu2025_nokescam,
 +  author        = {Liu, Mingxuan and Zhang, Yunyi and Wu, Lijie and Liu, Baojun and Hong, Geng and Zhang, Yiming and Jiang, Hui and Zhang, Jia and Duan, Haixin and Zhang, Min and Guan, Wei and Shi, Fan and Yang, Min},
 +  title         = {NOKEScam: Understanding and Rectifying Non-Sense Keywords Spear Scam in Search Engines},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/liu-mingxuan},
 +}
 +
 +@inproceedings{gomez2023_cybercrime,
 +  author        = {Gómez, Gibran and Liebergen, Kevin van and Caballero, Juan},
 +  title         = {Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and Coverage},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3623094},
 +}
 +
 +@inproceedings{wang2020_into,
 +  author        = {Wang, Peng and Liao, Xiaojing and Qin, Yue and Wang, XiaoFeng},
 +  title         = {Into the Deep Web: Understanding E-commerce Fraud from Autonomous Chat with Cybercriminals},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2020},
 +  series        = {NDSS 2020},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/into-the-deep-web-understanding-e-commerce-fraud-from-autonomous-chat-with-cybercriminals/},
 +}
 +
 +@inproceedings{he2023_txphishscope,
 +  author        = {He, Bowen and Chen, Yuan and Chen, Zhuo and Hu, Xiaohui and Hu, Yufeng and Wu, Lei and Chang, Rui and Wang, Haoyu and Zhou, Yajin},
 +  title         = {TxPhishScope: Towards Detecting and Understanding Transaction-based Phishing on Ethereum},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3623210},
 +}
 +
 +@inproceedings{leontiadis2011_measuring,
 +  author        = {Leontiadis, Nektarios and Moore, Tyler and Christin, Nicolas},
 +  title         = {Measuring and Analyzing Search-Redirection Attacks in the Illicit Online Prescription Drug Trade},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2011},
 +  series        = {USENIX Security 2011},
 +  url           = {https://www.usenix.org/legacy/event/sec11/tech/},
 +}
 +@inproceedings{adjibi2025_guardians,
 +  author        = {Adjibi, Boladji Vinny and Avgetidis, Athanasios and Antonakakis, Manos and Bailey, Michael and Monrose, Fabian},
 +  title         = {The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/the-guardians-of-name-street-studying-the-defensive-registration-practices-of-the-fortune-500/},
 +}
 +@inproceedings{adjibi2026_udrp,
 +  author        = {Adjibi, Vinny and Avgetidis, Athanasios and Antonakakis, Manos and Dainotti, Alberto and Bailey, Michael and Monrose, Fabian},
 +  title         = {Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century’s Worth of Squabbles},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/repairing-trust-in-domain-name-disputes-practices-insights-from-a-quarter-centurys-worth-of-squabbles/},
 +}
 +@inproceedings{akiwate2020_lame,
 +  author        = {Akiwate, Gautam and Jonker, Mattijs and Sommese, Raffaele and Foster, Ian D. and Voelker, Geoffrey M. and Savage, Stefan and Claffy, K. C.},
 +  title         = {Unresolved Issues: Prevalence, Persistence, and Perils of Lame Delegations},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2020},
 +  series        = {IMC 2020},
 +  doi           = {10.1145/3419394.3423623},
 +}
 +@inproceedings{akiwate2021_risky,
 +  author        = {Akiwate, Gautam and Savage, Stefan and Voelker, Geoffrey M. and Claffy, Kimberly C.},
 +  title         = {Risky BIZness: risks derived from registrar name management},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487816},
 +}
 +@inproceedings{alhamdan2025_deno,
 +  author        = {AlHamdan, Abdullah and Staicu, Cristian-Alexandru},
 +  title         = {Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its Ecosystem},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/welcome-to-jurassic-park-a-comprehensive-study-of-security-risks-in-deno-and-its-ecosystem/},
 +}
 +@inproceedings{alowaisheq2019_cracking,
 +  author        = {Alowaisheq, Eihal and Wang, Peng and Alrwais, Sumayah and Liao, Xiaojing and Wang, XiaoFeng and Alowaisheq, Tasneem and Mi, Xianghang and Tang, Siyuan and Liu, Baojun},
 +  title         = {Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downs},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2019},
 +  series        = {NDSS 2019},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/cracking-the-wall-of-confinement-understanding-and-analyzing-malicious-domain-take-downs/},
 +}
 +@inproceedings{alowaisheq2020_zombie,
 +  author        = {Alowaisheq, Eihal and Tang, Siyuan and Wang, Zhihao and Alharbi, Fatemah and Liao, Xiaojing and Wang, XiaoFeng},
 +  title         = {Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting Referral},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417864},
 +}
 +@inproceedings{alrwais2014_parking,
 +  author        = {Alrwais, Sumayah and Yuan, Kan and Alowaisheq, Eihal and Li, Zhou and Wang, XiaoFeng},
 +  title         = {Understanding the Dark Side of Domain Parking},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2014},
 +  series        = {USENIX Security 2014},
 +  url           = {https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/alrwais},
 +}
 +@inproceedings{chen2016_mitm,
 +  author        = {Chen, Qi Alfred and Osterweil, Eric and Thomas, Matthew and Mao, Zhuoqing Morley},
 +  title         = {MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2016},
 +  series        = {IEEE S&P 2016},
 +  doi           = {10.1109/sp.2016.46},
 +}
 +@inproceedings{halvorson2015_academy,
 +  author        = {Halvorson, Tristan and Der, Matthew F. and Foster, Ian D. and Savage, Stefan and Saul, Lawrence K. and Voelker, Geoffrey M.},
 +  title         = {From .academy to .zone: An Analysis of the New TLD Land Rush},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2015},
 +  series        = {IMC 2015},
 +  doi           = {10.1145/2815675.2815696},
 +}
 +@inproceedings{hortea2026_dead,
 +  author        = {Hortea, Gabriel and Girish, Aniketh and Vallina-Rodriguez, Narseo and Tapiador, Juan},
 +  title         = {Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2026},
 +  series        = {PoPETs 2026},
 +  doi           = {10.56553/popets-2026-0112},
 +}
 +@inproceedings{hu2021_idn,
 +  author        = {Hu, Hang and Jan, Steve T.K. and Wang, Yang and Wang, Gang},
 +  title         = {Assessing Browser-level Defense against IDN-based Phishing},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/hu-hang},
 +}
 +@inproceedings{kalafut2010_orphan,
 +  author        = {Kalafut, Andrew J. and Gupta, Minaxi and Cole, Christopher A. and Chen, Lei and Myers, Nathan E.},
 +  title         = {An empirical study of orphan DNS servers in the internet},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2010},
 +  series        = {IMC 2010},
 +  doi           = {10.1145/1879141.1879182},
 +}
 +@inproceedings{khan2015_every,
 +  author        = {Khan, Mohammad Taha and Huo, Xiang and Li, Zhou and Kanich, Chris},
 +  title         = {Every Second Counts: Quantifying the Negative Externalities of Cybercrime via Typosquatting},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2015},
 +  series        = {IEEE S&P 2015},
 +  doi           = {10.1109/sp.2015.16},
 +}
 +@inproceedings{kintis2017_hiding,
 +  author        = {Kintis, Panagiotis and Miramirkhani, Najmeh and Lever, Charles and Chen, Yizheng and Gómez, Rosa Romero and Pitropakis, Nikolaos and Nikiforakis, Nick and Antonakakis, Manos},
 +  title         = {Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2017},
 +  series        = {CCS 2017},
 +  doi           = {10.1145/3133956.3134002},
 +}
 +@inproceedings{lauinger2016_whois,
 +  author        = {Lauinger, Tobias and Onarlioglu, Kaan and Chaabane, Abdelberi and Robertson, William and Kirda, Engin},
 +  title         = {WHOIS Lost in Translation: (Mis)Understanding Domain Name Expiration and Re-Registration},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2016},
 +  series        = {IMC 2016},
 +  doi           = {10.1145/2987443.2987463},
 +}
 +@inproceedings{lauinger2017_game,
 +  author        = {Lauinger, Tobias and Chaabane, Abdelberi and Buyukkayhan, Ahmet Salih and Onarlioglu, Kaan and Robertson, William},
 +  title         = {Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2017},
 +  series        = {USENIX Security 2017},
 +  url           = {https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/lauinger},
 +}
 +@inproceedings{lauinger2018_deletion,
 +  author        = {Lauinger, Tobias and Buyukkayhan, Ahmet Salih and Chaabane, Abdelberi and Robertson, William K. and Kirda, Engin},
 +  title         = {From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2018},
 +  series        = {IMC 2018},
 +  doi           = {10.1145/3278532.3278560},
 +}
 +@inproceedings{lever2016_domainz,
 +  author        = {Lever, Chaz and Walls, Robert J. and Nadji, Yacin and Dagon, David and McDaniel, Patrick D. and Antonakakis, Manos},
 +  title         = {Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in Domains},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2016},
 +  series        = {IEEE S&P 2016},
 +  doi           = {10.1109/sp.2016.47},
 +}
 +@inproceedings{liu2015_whois,
 +  author        = {Liu, Suqi and Foster, Ian D. and Savage, Stefan and Voelker, Geoffrey M. and Saul, Lawrence K.},
 +  title         = {Who is .com?: Learning to Parse WHOIS Records},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2015},
 +  series        = {IMC 2015},
 +  doi           = {10.1145/2815675.2815693},
 +}
 +@inproceedings{liu2016_dangling,
 +  author        = {Liu, Daiping and Hao, Shuai and Wang, Haining},
 +  title         = {All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS Records},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2016},
 +  series        = {CCS 2016},
 +  doi           = {10.1145/2976749.2978387},
 +}
 +@inproceedings{liu2022_container,
 +  author        = {Liu, Guannan and Gao, Xing and Wang, Haining and Sun, Kun},
 +  title         = {Exploring the Unchartered Space of Container Registry Typosquatting},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/liu-guannan},
 +}
 +@inproceedings{ma2023_stale,
 +  author        = {Ma, Zane and Faulkenberry, Aaron and Papastergiou, Thomas and Durumeric, Zakir and Bailey, Michael D. and Keromytis, Angelos D. and Monrose, Fabian and Antonakakis, Manos},
 +  title         = {Stale TLS Certificates: Investigating Precarious Third-Party Access to Valid TLS Keys},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624802},
 +}
 +@inproceedings{miramirkhani2018_panning,
 +  author        = {Miramirkhani, Najmeh and Barron, Timothy and Ferdman, Michael and Nikiforakis, Nick},
 +  title         = {Panning for gold.com: Understanding the Dynamics of Domain Dropcatching},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2018},
 +  series        = {TheWebConf 2018},
 +  doi           = {10.1145/3178876.3186092},
 +}
 +@inproceedings{muzammil2024_panning,
 +  author        = {Muzammil, Muhammad and Wu, Zhengyu and Balasubramanian, Aruna and Nikiforakis, Nick},
 +  title         = {Panning for gold.eth: Understanding and Analyzing ENS Domain Dropcatching},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2024},
 +  series        = {IMC 2024},
 +  doi           = {10.1145/3646547.3689009},
 +}
 +@inproceedings{neupane2023_confusion,
 +  author        = {Neupane, Shradha and Holmes, Grant and Wyss, Elizabeth and Davidson, Drew and De Carli, Lorenzo},
 +  title         = {Beyond Typosquatting: An In-depth Look at Package Confusion},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/neupane},
 +}
 +@inproceedings{nikiforakis2013_bitsquatting,
 +  author        = {Nikiforakis, Nick and Van Acker, Steven and Meert, Wannes and Desmet, Lieven and Piessens, Frank and Joosen, Wouter},
 +  title         = {Bitsquatting: exploiting bit-flips for fun, or profit?},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2013},
 +  series        = {TheWebConf 2013},
 +  doi           = {10.1145/2488388.2488474},
 +}
 +@inproceedings{pauley2022_ipreuse,
 +  author        = {Pauley, Eric and Sheatsley, Ryan and Hoak, Blaine and Burke, Quinn and Beugin, Yohan and McDaniel, Patrick D.},
 +  title         = {Measuring and Mitigating the Risk of IP Reuse on Public Clouds},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2022},
 +  series        = {IEEE S&P 2022},
 +  doi           = {10.1109/sp46214.2022.9833784},
 +}
 +@inproceedings{saric2024_hyperlink,
 +  author        = {Saric, Kevin and Savins, Felix and Ramachandran, Gowri Sankar and Jurdak, Raja and Nepal, Surya},
 +  title         = {Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645510},
 +}
 +@inproceedings{so2022_spots,
 +  author        = {So, Johnny and Miramirkhani, Najmeh and Ferdman, Michael and Nikiforakis, Nick},
 +  title         = {Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2022},
 +  series        = {IEEE S&P 2022},
 +  doi           = {10.1109/sp46214.2022.9833609},
 +}
 +@inproceedings{so2025_lost,
 +  author        = {So, Johnny and Sanchez-Rola, Iskander and Nikiforakis, Nick},
 +  title         = {Lost in the Mists of Time: Expirations in DNS Footprints of Mobile Apps},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/so},
 +}
 +@inproceedings{sommese2024_darkdns,
 +  author        = {Sommese, Raffaele and Akiwate, Gautam and Affinito, Antonia and Müller, Moritz and Jonker, Mattijs and Claffy, K. C.},
 +  title         = {DarkDNS: Revisiting the Value of Rapid Zone Update},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2024},
 +  series        = {IMC 2024},
 +  doi           = {10.1145/3646547.3689021},
 +}
 +@inproceedings{suzuki2019_shamfinder,
 +  author        = {Suzuki, Hiroaki and Chiba, Daiki and Yoneya, Yoshiro and Mori, Tatsuya and Goto, Shigeki},
 +  title         = {ShamFinder: An Automated Framework for Detecting IDN Homographs},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2019},
 +  series        = {IMC 2019},
 +  doi           = {10.1145/3355369.3355587},
 +}
 +@inproceedings{szurdi2014_taile,
 +  author        = {Szurdi, Janos and Kocso, Balazs and Cseh, Gabor and Spring, Jonathan and Felegyhazi, Mark and Kanich, Chris},
 +  title         = {The Long “Taile” of Typosquatting Domain Names},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2014},
 +  series        = {USENIX Security 2014},
 +  url           = {https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/szurdi},
 +}
 +@inproceedings{vissers2015_parking,
 +  author        = {Vissers, Thomas and Joosen, Wouter and Nikiforakis, Nick},
 +  title         = {Parking Sensors: Analyzing and Detecting Parked Domains},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2015},
 +  series        = {NDSS 2015},
 +  url           = {https://www.ndss-symposium.org/ndss2015/ndss-2015-programme/parking-sensors-analyzing-and-detecting-parked-domains/},
 +}
 +@inproceedings{vissers2017_wolf,
 +  author        = {Vissers, Thomas and Barron, Timothy and Van Goethem, Tom and Joosen, Wouter and Nikiforakis, Nick},
 +  title         = {The Wolf of Name Street: Hijacking Domains Through Their Nameservers},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2017},
 +  series        = {CCS 2017},
 +  doi           = {10.1145/3133956.3133988},
 +}
 +@inproceedings{zhang2023_wolf,
 +  author        = {Zhang, Fenglu and Zhang, Yunyi and Liu, Baojun and Alowaisheq, Eihal and Ying, Lingyun and Li, Xiang and Zhang, Zaifeng and Liu, Ying and Duan, Haixin and Zhang, Min},
 +  title         = {Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624839},
 +}
 +@inproceedings{zhang2024_cross,
 +  author        = {Zhang, Yunyi and Zhang, Mingming and Liu, Baojun and Liu, Zhan and Zhang, Jia and Duan, Haixin and Zhang, Min and Shi, Fan and Xu, Chengxi},
 +  title         = {Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/zhang-yunyi-zone},
 +}
 +@inproceedings{zhang2024_glue,
 +  author        = {Zhang, Yunyi and Liu, Baojun and Duan, Haixin and Zhang, Min and Li, Xiang and Shi, Fan and Xu, Chengxi and Alowaisheq, Eihal},
 +  title         = {Rethinking the Security Threats of Stale DNS Glue Records},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/zhang-yunyi-rethinking},
 +}
 +@inproceedings{zhang2025_misty,
 +  author        = {Zhang, Mingming and Zhang, Yunyi and Liu, Baojun and Duan, Haixin and Zhang, Min and Shi, Fan and Xu, Chengxi},
 +  title         = {Misty Registry: An Empirical Study of Flawed Domain Registry Operation},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/zhang-mingming},
 +}
 +@inproceedings{roberts2019_impersonation,
 +  author        = {Roberts, Richard and Goldschlag, Yaelle and Walter, Rachel and Chung, Taejoong and Mislove, Alan and Levin, Dave},
 +  title         = {You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS Certificates},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2019},
 +  series        = {CCS 2019},
 +  doi           = {10.1145/3319535.3363188},
 +}
 +
 +@inproceedings{marjanov2026_stayin,
 +  author        = {Marjanov, Tina and Tsuchiya, Taro and Ioannidis, Konstantinos and Hughes, Jack and Christin, Nicolas and Hutchings, Alice},
 +  title         = {Stayin' Alive: How Global Stolen Data Markets Thrive on Telegram},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/marjanov},
 +}
 +
 +@inproceedings{gao2026_doxing,
 +  author        = {Gao, Yiran and Xia, Pengcheng and Wang, Liu and Liu, Tianming and Wang, Haoyu},
 +  title         = {Doxing-as-a-Service: Demystifying the Chinese Online Doxing Ecosystem},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792296},
 +}
 +
 +@inproceedings{xu2019_anatomy,
 +  author        = {Xu, Jiahua and Livshits, Benjamin},
 +  title         = {The Anatomy of a Cryptocurrency Pump-and-Dump Scheme},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2019},
 +  series        = {USENIX Security 2019},
 +  url           = {https://www.usenix.org/conference/usenixsecurity19/presentation/xu-jiahua},
 +}
 +
 +@inproceedings{sun2021_having,
 +  author        = {Sun, Zhibo and Oest, Adam and Zhang, Penghui and Rubio-Medrano, Carlos and Bao, Tiffany and Wang, Ruoyu and Zhao, Ziming and Shoshitaishvili, Yan and Doupé, Adam and Ahn, Gail-Joon},
 +  title         = {Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/sun-zhibo},
 +}
 +
 +@inproceedings{he2025_unmasking,
 +  author        = {He, Bowen and Hu, Yufeng and Chen, Zhuo and Chen, Yuan and Yu, Ting and Chang, Rui and Wu, Lei and Zhou, Yajin},
 +  title         = {Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on Ethereum},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3764476},
 +}
 +
 +@inproceedings{weyns2026_mirai,
 +  author        = {Weyns, Maarten and Ferrero, Dario and Beek, Stefan Op de and Wagner, Daniel and Smaragdakis, Georgios and Griffioen, Harm},
 +  title         = {From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/weyns},
 +}
 +
 +@inproceedings{acharya2025_pirates,
 +  author        = {Acharya, Bhupendra and Lazzaro, Dario and Cinà, Antonio Emanuele and Holz, Thorsten},
 +  title         = {Pirates of Charity: Exploring Donation-based Abuses in Social Media Platforms},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714634},
 +}
 +
 +@inproceedings{hoseini2020_demystifying,
 +  author        = {Hoseini, Mohamad and Melo, Philipe and Junior, Manoel and Benevenuto, Fabrício and Chandrasekaran, Balakrishnan and Feldmann, Anja and Zannettou, Savvas},
 +  title         = {Demystifying the Messaging Platforms' Ecosystem Through the Lens of Twitter},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2020},
 +  series        = {IMC 2020},
 +  doi           = {10.1145/3419394.3423651},
 +}
 +
 +@inproceedings{resende2019_information,
 +  author        = {Resende, Gustavo and Melo, Philipe F. and Sousa, Hugo and Messias, Johnnatan and Vasconcelos, Marisa and Almeida, Jussara M. and Benevenuto, Fabrício},
 +  title         = {(Mis)Information Dissemination in WhatsApp: Gathering, Analyzing and Countermeasures},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2019},
 +  series        = {TheWebConf 2019},
 +  doi           = {10.1145/3308558.3313688},
 +}
 +
 +@inproceedings{saha2021_short,
 +  author        = {Saha, Punyajoy and Mathew, Binny and Garimella, Kiran and Mukherjee, Animesh},
 +  title         = {"Short is the Road that Leads from Fear to Hate": Fear Speech in Indian WhatsApp Groups},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450137},
 +}
 +
 +@inproceedings{kireev2025_characterizing,
 +  author        = {Kireev, Klim and Mykhno, Yevhen and Troncoso, Carmela and Overdorf, Rebekah},
 +  title         = {Characterizing and Detecting Propaganda-Spreading Accounts on Telegram},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/kireev},
 +}
 +
 +@inproceedings{vu2024_easy,
 +  author        = {Vu, Anh V. and Hutchings, Alice and Anderson, Ross J.},
 +  title         = {No Easy Way Out: the Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and Harassment},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2024},
 +  series        = {IEEE S&P 2024},
 +  doi           = {10.1109/sp54263.2024.00007},
 +}
 +
 +@inproceedings{vu2024_getting,
 +  author        = {Vu, Anh V. and Thomas, Daniel R. and Collier, Ben and Hutchings, Alice and Clayton, Richard and Anderson, Ross J.},
 +  title         = {Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine Conflict},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645401},
 +}
 +
 +@inproceedings{vafa2025_learning,
 +  author        = {Vafa, Elham Pourabbas and Singhal, Mohit and Thota, Poojitha and Roy, Sayak Saha},
 +  title         = {Learning from Censored Experiences: Social Media Discussions around Censorship Circumvention Technologies},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2025},
 +  series        = {IEEE S&P 2025},
 +  doi           = {10.1109/sp61157.2025.00062},
 +}
 +
 +@inproceedings{recabarren2023_strategies,
 +  author        = {Recabarren, Ruben and Carbunar, Bogdan and Hernandez, Nestor and Shafin, Ashfaq Ali},
 +  title         = {Strategies and Vulnerabilities of Participants in Venezuelan Influence Operations},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/recabarren},
 +}
 +
 +@inproceedings{aliapoulios2021_characterization,
 +  author        = {Aliapoulios, Maxwell and Take, Kejsi and Ramakrishna, Prashanth and Borkan, Daniel and Goldberg, Beth and Sorensen, Jeffrey and Turner, Anna and Greenstadt, Rachel and Lauinger, Tobias and McCoy, Damon},
 +  title         = {A large-scale characterization of online incitements to harassment across platforms},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487852},
 +}
 +
 +@inproceedings{bahramali2020_practical,
 +  author        = {Bahramali, Alireza and Houmansadr, Amir and Soltani, Ramin and Goeckel, Dennis and Towsley, Don},
 +  title         = {Practical Traffic Analysis Attacks on Secure Messaging Applications},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2020},
 +  series        = {NDSS 2020},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/practical-traffic-analysis-attacks-on-secure-messaging-applications/},
 +}
 +
 +@inproceedings{weerasinghe2020_people,
 +  author        = {Weerasinghe, Janith and Flanigan, Bailey and Stein, Aviel J. and McCoy, Damon and Greenstadt, Rachel},
 +  title         = {The Pod People: Understanding Manipulation of Social Media Popularity via Reciprocity Abuse},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2020},
 +  series        = {TheWebConf 2020},
 +  doi           = {10.1145/3366423.3380256},
 +}
 +
 +@inproceedings{shen2024_anything,
 +  author        = {Shen, Xinyue and Chen, Zeyuan and Backes, Michael and Shen, Yun and Zhang, Yang},
 +  title         = {"Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670388},
 +}
 +
 +@inproceedings{yu2024_listen,
 +  author        = {Yu, Zhiyuan and Liu, Xiaogeng and Liang, Shunning and Cameron, Zach and Xiao, Chaowei and Zhang, Ning},
 +  title         = {Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/yu-zhiyuan},
 +}
 +
 +@inproceedings{guo2024_moderating,
 +  author        = {Guo, Keyan and Utkarsh, Ayush and Ding, Wenbo and Ondracek, Isabelle and Zhao, Ziming and Freeman, Guo and Vishwamitra, Nishant and Hu, Hongxin},
 +  title         = {Moderating Illicit Online Image Promotion for Unsafe User Generated Content Games Using Large Vision-Language Models},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/guo-keyan},
 +}
 +
 +@inproceedings{schrittwieser2012_guess,
 +  author        = {Schrittwieser, Sebastian and Frühwirt, Peter and Kieseberg, Peter and Leithner, Manuel and Mulazzani, Martin and Huber, Markus and Weippl, Edgar},
 +  title         = {Guess Who’s Texting You? Evaluating the Security of Smartphone Messaging Applications},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2012},
 +  series        = {NDSS 2012},
 +  url           = {https://www.ndss-symposium.org/ndss2012/ndss-2012-programme/guess-whos-texting-you-evaluating-security-smartphone-messaging-applications/},
 +}
 +
 +@inproceedings{li2025_investigating,
 +  author        = {Li, Jiliang and Lu, Nora Sinong and Hanimann, Isaak and Si, Janice Jianing and Cheng, Dazhao and Zhou, Xiaobo and Wang, Kanye Ye},
 +  title         = {Investigating the Impact of Online Community Involvement on Safety Practices and Perceived Risks Among People Who Use Drugs},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/li-jiliang},
 +}
 +
 +@inproceedings{albrecht2021_collective,
 +  author        = {Albrecht, Martin R. and Blasco, Jorge and Jensen, Rikke Bjerg and Mareková, Lenka},
 +  title         = {Collective Information Security in Large-Scale Urban Protests: the Case of Hong Kong},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/albrecht},
 +}
 +
 +@inproceedings{arunasalam2024_security,
 +  author        = {Arunasalam, Arjun and Farrukh, Habiba and Tekcan, Eliz and Celik, Z. Berkay},
 +  title         = {Understanding the Security and Privacy Implications of Online Toxic Content on Refugees},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/arunasalam},
 +}
 +
 +@inproceedings{chou2025_bots,
 +  author        = {Chou, Kai-Hsiang and Lin, Yi-Min and Wang, Yi-An and Li, Jonathan Weiping and Kim, Tiffany Hyun-Jin and Hsiao, Hsu-Chun},
 +  title         = {Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group Chats},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/chou},
 +}
 +
 +@inproceedings{wang2025_detecting,
 +  author        = {Wang, Hongyu and Li, Ying and Huang, Ronghong and Mi, Xianghang},
 +  title         = {Detecting and Understanding the Promotion of Illicit Goods and Services on Twitter},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714550},
 +}
 +@inproceedings{lu2020_demystifying,
 +  author        = {Lu, Haoran and Xing, Luyi and Xiao, Yue and Zhang, Yifan and Liao, Xiaojing and Wang, XiaoFeng and Wang, Xueqiang},
 +  title         = {Demystifying Resource Management Risks in Emerging Mobile App-in-App Ecosystems},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417255},
 +}
 +
 +@inproceedings{yang2022_cross,
 +  author        = {Yang, Yuqing and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability Detection},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2022},
 +  series        = {CCS 2022},
 +  doi           = {10.1145/3548606.3560597},
 +}
 +
 +@inproceedings{zhang2022_identity,
 +  author        = {Zhang, Lei and Zhang, Zhibo and Liu, Ancong and Cao, Yinzhi and Zhang, Xiaohan and Chen, Yanjun and Zhang, Yuan and Yang, Guangliang and Yang, Min},
 +  title         = {Identity Confusion in WebView-based Mobile App-in-app Ecosystems},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/zhang-lei},
 +}
 +
 +@inproceedings{zhang2023_leak,
 +  author        = {Zhang, Yue and Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-Programs},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616591},
 +}
 +
 +@inproceedings{wang2023_uncovering,
 +  author        = {Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Uncovering and Exploiting Hidden APIs in Mobile Super Apps},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616676},
 +}
 +
 +@inproceedings{wang2023_size,
 +  author        = {Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {One Size Does Not Fit All: Uncovering and Exploiting Cross Platform Discrepant APIs in WeChat},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/wang-chao},
 +}
 +
 +@inproceedings{zhang2024_minicat,
 +  author        = {Zhang, Zidong and Hou, Qinsheng and Ying, Lingyun and Diao, Wenrui and Gu, Yacong and Li, Rui and Guo, Shanqing and Duan, Haixin},
 +  title         = {MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-Programs},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670294},
 +}
 +
 +@inproceedings{shi2026_better,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Liu, Dingyi and Zhong, Kangwei and Dai, Jiarun and Yang, Min},
 +  title         = {Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud Services},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/better-safe-than-sorry-uncovering-the-insecure-resource-management-in-app-in-app-cloud-services/},
 +}
 +
 +@inproceedings{cai2025_tell,
 +  author        = {Cai, Yifeng and Zhang, Ziqi and Yao, Mengyu and Liu, Junlin and Zhao, Xiaoke and Fu, Xinyi and Li, Ruoyu and Liu, Zhe and Chen, Xiangqun and Guo, Yao and Li, Ding},
 +  title         = {I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/cai-yifeng},
 +}
 +
 +@inproceedings{chen2026_minigames,
 +  author        = {Chen, Pei and Hong, Geng and Qin, Yicheng and Wang, Huazhe and Wu, Mengying and Yang, Min and Zhao, Ziru and Zhu, Yuanpeng and Su, Tao},
 +  title         = {When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-games},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/chen-pei},
 +}
 +
 +@inproceedings{yang2025_miniapp,
 +  author        = {Yang, Yuqing and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Understanding Miniapp Malware: Identification, Dissection, and Characterization},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/understanding-miniapp-malware-identification-dissection-and-characterization/},
 +}
 +
 +@inproceedings{shi2025_skeleton,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Zhong, Kangwei and Yang, Guangliang and Yang, Yifan and Zhang, Xiaohan and Yang, Min},
 +  title         = {The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/the-skeleton-keys-a-large-scale-analysis-of-credential-leakage-in-mini-apps/},
 +}
 +
 +@inproceedings{he2024_demystifying,
 +  author        = {He, Yi and Guan, Yunchao and Lun, Ruoyu and Song, Shangru and Guo, Zhihao and Zhuge, Jianwei and Chen, Jianjun and Wei, Qiang and Wu, Zehui and Yu, Miao and Shi, Hetian and Li, Qi},
 +  title         = {Demystifying the Security Implications in IoT Device Rental Services},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/he-yi},
 +}
 +
 +@inproceedings{liu2024_riotfuzzer,
 +  author        = {Liu, Kaizheng and Yang, Ming and Ling, Zhen and Zhang, Yue and Lei, Chongqing and Luo, Junzhou and Fu, Xinwen},
 +  title         = {RIoTFuzzer: Companion App Assisted Remote Fuzzing for Detecting Vulnerabilities in IoT Devices},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670342},
 +}
 +
 +@inproceedings{lee2025_deep,
 +  author        = {Lee, Woonghee and Hur, Junbeom and Kwon, Hyunsoo},
 +  title         = {Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate Validation},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2025},
 +  series        = {CCS 2025},
 +  doi           = {10.1145/3719027.3765215},
 +}
 +
 +@inproceedings{wei2026_raising,
 +  author        = {Wei, Zhiao and Wang, Chao and Faheem, Haseeb-Ur-Rehman and Xing, Luyi and Aafer, Yousra and Lin, Zhiqiang},
 +  title         = {Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/wei-zhiao},
 +}
 +
 +@inproceedings{shi2026_convenience,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Yang, Yifan and Yang, Yunteng and Yang, Min},
 +  title         = {Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App Ecosystem},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2026},
 +  series        = {IEEE S\&P 2026},
 +  doi           = {10.1109/sp63933.2026.00074},
 +}
 +
 +@inproceedings{yang2026_real,
 +  author        = {Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting Interface},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792470},
 +}
 +
 +@inproceedings{wang2025_wechat,
 +  author        = {Wang, Mona and Lin, Pellaeon and Knockel, Jeffrey and Greenberg, Will and Mayer, Jonathan and Mittal, Prateek},
 +  title         = {What WeChat Knows: Pervasive First-Party Tracking in a Billion-User Super-App Ecosystem},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2025},
 +  series        = {PoPETs 2025},
 +  doi           = {10.56553/popets-2025-0163},
 +}
 +
 +@article{zhang2021_measurement,
 +  author        = {Zhang, Yue and Turkistani, Bayan and Yang, Allen Yuqing and Zuo, Chaoshun and Lin, Zhiqiang},
 +  title         = {A Measurement Study of {WeChat} Mini-Apps},
 +  journal       = {Proceedings of the ACM on Measurement and Analysis of Computing Systems},
 +  volume        = {5},
 +  number        = {2},
 +  year          = {2021},
 +  series        = {SIGMETRICS 2021},
 +  doi           = {10.1145/3460081},
 +}
 +
 +@inproceedings{baskaran2023_measuring,
 +  author        = {Baskaran, Supraja and Zhao, Lianying and Mannan, Mohammad and Youssef, Amr},
 +  title         = {Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The {WeChat} Case},
 +  booktitle     = {Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses},
 +  year          = {2023},
 +  series        = {RAID 2023},
 +  doi           = {10.1145/3607199.3607236},
 +}
 +
 +@inproceedings{wang2023_taintmini,
 +  author        = {Wang, Chao and Ko, Ronny and Zhang, Yue and Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {{TaintMini}: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis},
 +  booktitle     = {Proceedings of the 45th IEEE/ACM International Conference on Software Engineering},
 +  year          = {2023},
 +  series        = {ICSE 2023},
 +  doi           = {10.1109/ICSE48619.2023.00086},
 +}
 +
 +@inproceedings{meng2023_wemint,
 +  author        = {Meng, Shi and Wang, Liu and Wang, Shenao and Wang, Kailong and Xiao, Xusheng and Bai, Guangdong and Wang, Haoyu},
 +  title         = {{WeMinT}: Tainting Sensitive Data Leaks in {WeChat} Mini-Programs},
 +  booktitle     = {Proceedings of the 38th IEEE/ACM International Conference on Automated Software Engineering},
 +  year          = {2023},
 +  series        = {ASE 2023},
 +  doi           = {10.1109/ASE56229.2023.00151},
 +}
 +
 +@misc{yang2023_sok,
 +  author        = {Yang, Yuqing and Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {{SoK}: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in {OS}-alike Apps},
 +  year          = {2023},
 +  howpublished  = {arXiv:2306.07495},
 +  url           = {https://arxiv.org/abs/2306.07495},
 +}
 +
 +@misc{zhang2026_oauth,
 +  author        = {Zhang, Zidong and Xie, Zhentao and Ying, Lingyun and Hou, Qinsheng and Gu, Yacong and Diao, Wenrui and Wu, Jianliang},
 +  title         = {Mini-Programs, Mega-Problems: Unveiling {OAuth}-based Authentication Misuses in Mini-Programs via Dynamic Analysis},
 +  year          = {2026},
 +  howpublished  = {arXiv:2607.08232, accepted at ACM CCS 2026},
 +  url           = {https://arxiv.org/abs/2607.08232},
 +}
 +
 +@misc{ciccotelli2026_tenet,
 +  author        = {Ciccotelli, Andrea and Zappone, Federico and Di Pietro, Roberto},
 +  title         = {{TENET}: Telegram Mini App (in)security},
 +  year          = {2026},
 +  howpublished  = {arXiv:2608.17538},
 +  url           = {https://arxiv.org/abs/2608.17538},
 +}
 +
 +@misc{ferrari2026_telegapper,
 +  author        = {Ferrari, Luca and Ceccato, Mariano and Verderame, Luca},
 +  title         = {{TeleGapper}: On the (un)reliability of Privacy Policies in Telegram Mini apps},
 +  year          = {2026},
 +  howpublished  = {arXiv:2608.13390},
 +  url           = {https://arxiv.org/abs/2608.13390},
 } }
  
literature/bibliography.1789490361.txt.gz · Last modified: by karel.kubicek.claude