IMDEA Networks Institute Digital Repository
Not a member yet
1915 research outputs found
Sort by
Wireless coded caching can overcome the worst-user bottleneck by exploiting finite file sizes
We address the worst-user bottleneck of wireless coded caching, which is known to severely diminish cache-aided multicasting gains due to the fundamental worst-channel limitation of multicasting transmission. We consider the quasi-static Rayleigh fading Broadcast Channel, for which we first show that the effective coded caching gain of the XOR-based standard coded-caching scheme completely vanishes in the low-SNR regime. Then, we reveal that this collapse is not intrinsic to coded caching. We do so by presenting a novel scheme that can fully recover the coded caching gains by capitalizing on one aspect that has to date remained unexploited: the shared side information brought about by the effectively unavoidable file-size constraint. As a consequence, the worst-user effect is dramatically ameliorated, as it is substituted by a much more subtle worst-group-of-users effect, where the suggested grouping is fixed, and it is decided before the channel or the demands are known. In some cases, the theoretical gains are completely recovered, and this is done without any user selection technique. We analyze the achievable rate performance of the proposed scheme and derive insightful performance approximations which prove to be very precise.TRUEpu
A PIMS Development Kit for New Personal Data Platforms
The web ecosystem is based on a market where stakeholders collect and sell personal data, but nowadays users expect stronger guarantees of transparency and privacy. With the PIMCity PDK, we provide an open-source development kit for building personal information management systems to foster the development of open and user-centric data markets.European ComissionTRUEpu
Closed form approximation of the actual spectral power emission of commercial color LEDs for VLC
Multi-color Light-Emitting Diode (LED) technology enables a simple approach to increase the throughput of a Visible Light Communications (VLC) system, by using Wavelength-Division Multiplexing (WDM) to transmit independent data streams on different colors. However, to compute the data rate that is achievable in such WDM VLC link, the optical power that leaks between the different colors needs to be estimated accurately, especially when low-cost optical filters are used in reception. So far, the approximations that have been reported in the literature to model the spectral power emission of different color LEDs are not good enough to perform these calculations. Starting from the theoretical spectral emission of a color LED, a closed form expression is derived based on an asymmetric Pearson type VII function, which is shown to approximate accurately the measured spectra of the color LEDs at different working regimes. In addition, the effect that the DC-bias current has on the key parameters of the approximated spectral power emissions, namely the peak and half-maximum wavelengths, as well as the peak spectral emission, are studied. Finally, a new approach is proposed to assess the level of fitness of the derived closed form approximations, using for this purpose the step-size of the MacAdam ellipses that corresponds to the different color LED spectral emissions in the CIE 1931 chromaticity diagram.Juan de la Cierva Formación grant (FJC2019-039541-I / AEI / 10.13039/501100011033)TRUEpu
"Do Android Dream of Electric Sheep?" On Privacy in the Android Supply Chain
The Android Open Source Project (AOSP) was first released by Google in 2008 and has since become the most used operating system. Thanks to the openness of its source code, any smartphone vendor or original equipment manufacturer (OEM) can modify and adapt Android to their specific needs, or add proprietary features before installing it on their devices in order to add custom features to differentiate themselves from competitors. This has created a complex and diverse supply chain, completely opaque to end-users, formed by manufacturers, resellers, chipset manufacturers, network operators, and prominent actors of the online industry that partnered with OEMs. Each of these stakeholders can pre-install extra apps, or implement proprietary features at the framework level.
However, such customizations can create privacy and security threats to end-users. Pre-installed apps are privileged by the operating system, and can therefore access system APIs or personal data more easily than apps installed by the user. Unfortunately, despite these potential threats, there is currently no end-to-end control over what apps come pre-installed on a device and why, and no traceability of the different software and hardware components used in a given Android device. In fact, the landscape of pre-installed software in Android and its security and privacy implications has largely remained unexplored by researchers.
In this thesis, I investigate the customization of Android devices and their impact on the privacy and security of end-users. Specifically, I perform the first large-scale and systematic analysis of pre-installed Android apps and the supply chain. To do so, I first develop an app, Firmware Scanner, to crowdsource close to 34,000 Android firmware versions from 1,000 different OEMs from all over the world. This dataset allows us to map the stakeholders involved in the supply chain and their relationships, from device manufacturers and mobile network operators to third-party organizations like advertising and tracking services, and social network platforms. I could identify multiple cases of privacy-invasive and potentially harmful behaviors. My results show a disturbing lack of transparency and control over the Android supply chain, thus showing that it can be damageable privacy- and security-wise to end-users.
Next, I study the evolution of the Android permission system, an essential security feature of the Android framework. Coupled with other protection mechanisms such as process sandboxing, the permission system empowers users to control what sensitive resources (e.g., user contacts, the camera, location sensors) are accessible to which apps. The research community has extensively studied the permission system, but most previous studies focus on its limitations or specific attacks. In this thesis, I present an up-to-date view and longitudinal analysisof the evolution of the permissions system. I study how some lesser-known features of the permission system, specifically permission flags, can impact the permission granting process, making it either more restrictive or less. I then highlight how pre-installed apps developers use said flags in the wild and focus on the privacy and security implications. Specifically, I show the presence of third-party apps, installed as privileged system apps, potentially using said features to share resources with other third-party apps.
Another salient feature of the permission system is its extensibility: apps can define their own custom permissions to expose features and data to other apps. However, little is known about how widespread the usage of custom permissions is, and what impact these permissions may have on users’ privacy and security. In the last part of this thesis, I investigate the exposure and request of custom permissions in the Android ecosystem and their potential for opening privacy and security risks. I gather a 2.2-million-app-large dataset of both pre-installed and publicly available apps using both Firmware Scanner and purpose-built app store crawlers. I find the usage of custom permissions to be pervasive, regardless of the origin of the apps, and seemingly growing over time. Despite this prevalence, I find that custom permissions are virtually invisible to end-users, and their purpose is mostly undocumented. While Google recommends that developers use their reverse domain name as the prefix of their custom permissions, I find widespread violations of this recommendation, making sound attribution at scale virtually impossible. Through static analysis methods, I demonstrate that custom permissions can facilitate access to permission-protected system resources to apps that lack those permissions, without user awareness. Due to the lack of tools for studying such risks, I design and implement two tools, PermissionTracer and PermissionTainter to study custom permissions. I highlight multiple cases of concerning use of custom permissions by Android apps in the wild.
In this thesis, I systematically studied, at scale, the vast and overlooked ecosystem of pre-installed Android apps. My results show a complete lack of control of the supply chain which is worrying, given the huge potential impact of pre-installed apps on the privacy and security of end-users. I conclude with a number of open research questions and future avenues for further research in the ecosystem of the supply chain of Android devices.Telematics EngineeringUniversidad Carlos III de Madrid, Spai
A Practical way to Handle Service Migration of ML-based Applications in Industrial Analytics
Nowadays, Machine learning (ML) plays a significant role in Industrial Analytics. It enables predictive analytics, and helps uncovering essential insights to transform industries. As a result, real-time data analytics has become an essential requirement for industrial engineering jobs. Edge computing enables local intelligence and real-time analytics that are key for industry processes to take autonomous decisions locally at the edge of the network. However, outages in edge datacenters can jeopardize the whole plant security. In this paper, we proposed a practical approach to effectively handling service and data migration of ML-based applications in Industrial Analytics scenarios in the presence of a lack of computing resources at the edge. We argue that in this context the value of data is inversely proportional to their age and is very important to work with fresher data. In this paper, we describe our architectural approach for service and data handoff and show a predictive diagnostics case study deployed in an edge-enabled IIoT infrastructure. We evaluate our proposed approach in terms of drop of accuracy in a well-known edge computing emulator, i.e., openLEON. The experimental results show the benefit of our solution with respect to standard techniques.AEITRUEpu
A Survey of Data Marketplaces and Their Business Models
Data is becoming an indispensable production factor for the modern economy, matching or exceeding in importance traditional factors such as land, infrastructure, labor and capital. As part of this, a wide range of applications in different sectors require huge amounts of information to feed machine learning models and algorithms responsible for critical roles in production chains and business processes. A variety of data trading entities including, but not limited to data marketplaces, have thus appeared in order to satisfy and match the offer with the demand for data. In this paper, we present the results and conclusions from a comprehensive survey covering 190 commercial data trading entities, the types of data that their trade, as well as their business models and the technologies that they rely upon. We also point to promising open research questions in the areas of data marketplace federation, pricing, and data ownership protection that could benefit the growing ecosystem of data trading entities that we have surveyed.EUTRUEpu
ObfSec: Measuring the Security of Obfuscations from a Testing Perspective
Code obfuscation protects the intellectual property of software.
However, systematically altering the control- and data-flow of a program can deteriorate the security of the resulting program.
There is a wide-range of obfuscation methods available that alter the layout of the program in different ways.
These modifications can introduce bugs in the program or modify the nature and the severity of existing ones.
We propose a novel strategy, called ObfSec (Obfuscation Security), to understand the implications behind obfuscating software.
ObfSec starts by detecting errors in software and exposes how the obfuscation can change the nature of those errors, looking in particular at transformations that turn software bugs into exploitable vulnerable programs.
Our results, on a corpus of around 70,000 programs and obfuscations, show that obfuscation can deteriorate the security of a program."Ramon y Cajal" Fellowship RYC-2020-029401-ITRUEpu
Paying Attention to the Algorithm Behind the Curtain. Bringing Transparency to YouTube’s Demonetization Algorithms
YouTube has long been a top-choice destination for independent video content creators to share their work. A large part of YouTube’s appeal is owed to its practice of sharing advertising revenue with qualifying content creators through the YouTube Partner Program (YPP). In recent years, changes to the monetization policies and the introduction of algorithmic systems for making monetization decisions have been a source of controversy and tension between content creators and the platform. There have been numerous accusations suggesting that the underlying monetization algorithms engage in preferential treatment of larger channels and effectively censor minority voices by demonetizing their content.
In this paper, we conduct a measurement of the YouTube monetization algorithms. We begin by measuring
the incidence rates of different monetization decisions and the time taken to reach them. Next, we analyze
the relationships between video content, channel popularity and these decisions. Finally, we explore the
relationship between demonetization and a channel’s view growth rate. Taken all together, our work suggests that demonetization after a video is publicly listed is not a common occurrence, the characteristics of the process are associated with channel size and (in unexplainable ways) video topic, and demonetization appears to have a harsh influence on the growth rate of smaller channels. We also highlight the challenges associated with conducting large-scale algorithm audits such as ours and make an argument for more transparency in algorithmic decision-making.TRUEpu
AppShot: A Conditional Deep Generative Model for Synthesizing Service-Level Mobile Traffic Snapshots at City Scale
Service-level mobile traffic data enables research studies and innovative applications with a potential to shape future service-oriented communication systems and beyond. However, real-world datasets reporting measurements at the individual service level are hard to access as such data is deemed commercially sensitive by operators. APPSHOT is a model for generating synthetic high-fidelity city-scale snapshots of service level mobile traffic. It can operate in any geographical region and relies solely on easily available spatial context information such as population density, thus allowing the generation of new and open traffic datasets for the research community. The design of APPSHOT is informed by an original characterization of service-level mobile traffic data. APPSHOT is a novel conditional GAN design instantiated by a convolutional neural network generator and two discriminators. The model features several other innovative mechanisms including multi-channel and overlapping patch based generation to address the unique challenges involved in generating mobile service traffic snapshots. Experiments with ground-truth data collected by a major European operator in multiple metropolitan areas show that APPSHOT can produce realistic network loads at the service level for areas where it has no prior traffic knowledge, and that such data can reliably support service-oriented networking studies.TRUEpu