Publications
My academic research on privacy, secure systems, and trustworthy machine learning has been published in top-tier security venues.
Selected Publications
These papers represent the core of my architectural and systemic research:
- AXECC: Benchmarking the Privacy and Accessibility Impact of Browser Extensions: Evaluated the privacy risks of over 21,000 real-world browser extensions, establishing a novel framework to measure third-party tracking and DOM manipulation at scale.
- DOMtegrity: Ensuring Web Page Integrity against Malicious Browser Extensions: Proposed a robust cryptographic architecture to protect the Document Object Model (DOM) against manipulation by malicious or overly permissive browser extensions.
- TouchSignatures: Identification of User Touch Actions via Mobile Sensors: Demonstrated how mobile browser orientation and motion APIs leak user input, driving the W3C to fundamentally alter sensor permission gating.
- On the Privacy of Private Browsing: A Forensic Approach: Conducted a foundational forensic analysis of private browsing modes across major browser engines, exposing systemic local and remote data leakage vectors.
- Verifiable Fairness: Privacy-Preserving Computation of Fairness: Established a privacy-preserving auditing framework that enables verifiable computation of algorithmic fairness without exposing underlying training data.
- Privacy-Preserving Yet Verifiable Remote Electronic Voting: Engineered self-enforcing electronic voting systems utilizing homomorphic encryption and zero-knowledge proofs to guarantee both voter anonymity and publicly verifiable tallying.
- Texture to the Rescue: Practical Paper Fingerprinting: Developed a physical-object authentication mechanism that extracts unforgeable cryptographic keys directly from the microscopic fiber structure of standard paper.
- How Can and Would People Protect From Online Tracking?: Analyzed the critical gaps between web privacy regulations (GDPR), platform-level privacy-enhancing technologies (PETs), and actual user mental models regarding tracking protection.
- A Practical Deep Learning-Based Acoustic Side Channel Attack on Keyboards: Proved the practicality of acoustic side-channel attacks on laptop keyboards using deep learning and standard smartphone microphones, highlighting new vectors for data leakage.
- Stealing PINs via Mobile Sensors: Actual Risk vs. User Perception: Investigated the disconnect between the severity of sensor-based side-channel attacks and user threat models, reinforcing the need for "secure by default" platform architectures.
- The Relationship Between Trust in AI and Trustworthy ML: Formulated the socio-technical relationship between user trust and trustworthy machine learning technologies, defining the architectural requirements for AI accountability.
Full publications
2026
-
ACM TOPS
"AXECC: Benchmarking the Privacy and Accessibility Impact of Browser Extensions".
James Clarke, Maryam Mehrnezhad, Ehsan Toreini. IEEE Transactions on Technology and Society,
2025
ePrint
2025
-
IEEE Transactions
"Measuring Online Hate on 4chan Using Pre-Trained Deep Learning Models".
Adrian Bermudez-Villalva, Maryam Mehrnezhad, Ehsan Toreini. IEEE Transactions on Technology and Society,
2025
ePrint
2024
-
IJIS
"Fairness as a Service (FaaS): verifiable and privacy-preserving fairness auditing of machine learning systems".
Ehsan Toreini, Maryam Mehrnezhad, Aad van Moorsel. International Journal of Information Security,
2024
ePrint -
ACM Transactions
"Invisible, Unreadable, and Inaudible Cookie Notices: An Evaluation of Cookie Notices for
Users with Visual Impairments.".
James Clarke, Maryam Mehrnezhad, and Ehsan Toreini. ACM Transactions on Accessible Computing.
ePrint -
IJIS
"Bluetooth security analysis of general and intimate health IoT devices and apps: the case of FemTech".
Stephen Cook, Maryam Mehrnezhad, Ehsan Toreini. International Journal of Information Security,
ePrint
2023
-
ESORICS Workshop
"Verifiable Fairness: Privacy-preserving Computation of Fairness for Machine Learning
Systems".
Ehsan Toreini, Maryam Mehrnezhad, Aad van Moorsel. Workshop on Private,Secure, and Trustworthy AI,
2023
ePrint -
EuroS&P Workshop
"A Practical Deep Learning-Based Acoustic Side Channel Attack on Keyboards.".
Joshua Harrison, Ehsan Toreini, Maryam Mehrnezhad. IEEE European Symposium on Security and Privacy
Workshops (EuroS&PW) 2023
ePrint | Source Code | (Listed as top 5% of all research outputs scored by Altmetric) | more info inc. abstract, media coverage, and BibTeX
2022
-
USENIX Security
"I feel invaded, annoyed, anxious and I may protect myself": Individuals' Feelings
about Online Tracking and their Protective Behaviour across Gender and
Country".
Kovila Coopamootoo, Maryam Mehrnezhad, Ehsan Toreini. 31st USENIX Security Symposium 2022
ePrint -
PoPETS
"How Can and Would People Protect From Online Tracking?.".
Maryam Mehrnezhad, Kovila Coopamootoo, Ehsan Toreini. Proceedings on Privacy Enhancing
Technologies (PETS) 2022
ePrint -
NordiCHI
"Bodies Like Yours: Enquiring Data Privacy in FemTech".
Teresa Almeida, Laura Shipp, Maryam Mehrnezhad, Ehsan Toreini. Nordic Human-Computer Interaction
Conference 2022
ePrint -
EuroUSEC
"Vision: Too Little too Late? Do the Risks of FemTech already Outweigh the
Benefits?".
Maryam Mehrnezhad, Laura Shipp, Teresa Almeida, Ehsan Toreini. European Symposium on Usable Security
2022
ePrint -
"In Private, Secure, Conversational FinBots We Trust".
Magdalene Ng, Kovila PL Coopamootoo, Tasos Spiliotopoulos, Dave Horsfall, Mhairi Aitken, Ehsan
Toreini,
Karen Elliott, Aad van Moorsel. Arxiv
ePrint
2021
-
TIFS
"Anti-Counterfeiting for Polymer Banknotes Based on Polymer Substrate
Fingerprinting".
Shen Wang, Ehsan Toreini, Feng Hao. IEEE Transactions on Information Forensics and Security
(TIFS)
ePrint - "On Secure E-Voting over Blockchain".
Patrick Mccorry, Maryam Mehrnezhad, Ehsan Toreini, Siamak F Shahandashti, Feng Hao.
ACM journal of Digital Threats: Research and Practice (DTRAP)
ePrint
2020
-
ESORICS "Keeping it Human: A Focus Group Study of Public Attitudes Towards AI in Banking". Mhairi Aitken, Magdalene Ng, Ehsan Toreini, Aad van Moorsel, Kovila Coopamootoo, Karen Elliott. European Symposium on Research in Computer Security
ePrint -
"Technologies for Trustworthy Machine Learning: A Survey in a Socio-Technical Context" . Ehsan Toreini, Mhairi Aitken, Kovila PL Coopamootoo, Karen Elliott, Vladimiro Gonzalez Zelaya, Paolo Missier, Magdalene Ng, Aad van Moorsel.
ePrint -
EuroUSEC "Simulating the Effects of Social Presence on Trust, Privacy Concerns & Usage Intentions in Automated Bots for Finance" . Magdalene Ng, Kovila PL Coopamootoo, Ehsan Toreini, Mhairi Aitken, Karen Elliot, Aad van Moorsel. EuroUSEC 2020, The 5th European Workshop on Usable Security.
ePrint -
IEEE S&P "End-to-End Verifiable E-Voting Trial for Polling Station Voting at Gateshead" .Feng Hao, Shen Wang, Samiran Bag, Rob Procter, Siamak F Shahandashti, Maryam Mehrnezhad, Ehsan Toreini, Roberto Metere, Lana Liu. IEEE Security & Privacy Journal, 2020
ePrint
2019
-
ACM FacCT "The relationship between trust in AI and trustworthy machine learning technologies" .Ehsan Toreini, Mhari Aitken, Aad van Moorsel, Karen Elliot, Kovila Koopamootoo. ACM conference on Fairness, Accountability and Transparency in Machine Learning (ACM FAT*), Spain, 2020.
ePrint | Presentation | Video -
IJIS "DOMtegrity: Ensuring Web Page Integrity against Malicious Browser Extensions" . Ehsan Toreini, Siamak F. Shahandashti, Maryam Mehrnezhad, Feng Hao. International Journal of Information Security.
ePrint | Source Code | More -
"What Is This Sensor and Does This App Need Access to It?" . Maryam Mehrnezhad, Ehsan Toreini. Informatics Journal.
2018
-
STAST "Making sense of sensors: mobile sensor security awareness and education" . Maryam Mehrnezhad, Ehsan Toreini, Sami Alajrami. 7th Workshop on Socio-Technical Aspects in Security and Trust (STAST)
ePrint -
IJIS "Stealing PINs via Mobile Sensors: Actual Risk versus User Perception" . Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao. International Journal of Information Security.
ePrint | Source Code | (Listed as top 5% of all research outputs scored by Altmetric)
2017
-
ACM TOPS "Texture to the Rescue: Practical Paper Fingerprinting based on Texture Patterns" . Ehsan Toreini, Siamak F. Shahandashti, Feng Hao. ACM Transactions on Privacy and Security (TOPS), ACM, 2017.
ePrint | more info inc. abstract, media coverage, and BibTeX
2016
-
JISA "Touchsignatures: identification of user touch actions and pins based on mobile sensor data via javascript" . Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti, Feng Hao. Journal of Information Security and Applications 26, 23-38.
Publication | Source Code | -
IJIS "PiSHi: click the images and I tell if you are a human" . Maryam Mehrnezhad, Abbas Ghaemi Bafghi, Ahad Harati, Ehsan Toreini. International Journal of Information Security, 1-17.
Publication | -
"Removing Trusted Tallying Authorities" . Patrick McCorry, Ehsan Toreini, Maryam Mehrnezhad. Newcastle University.
Technical Report
2015
-
"Determining User Passwords From Partial Information" . Dylan Clarke, Ehsan Toreini, Feng Hao. Newcastle University.
Technical Report -
"An acoustic side channel attack on enigma" . Ehsan Toreini, Brian Randell, Feng Hao. Newcastle University.
Technical Report
2014
-
"Analysis Of The Usage Of Chaotic Theory In Data Clustering Using Particle Swarm Optimization" . Saman Poursiah Navi, Ehsan Toreini, Maryam Mehrnejad, Seyyed Kazem Shekofteh. Indian Journal of Scientific Research 4 (3), 335-353.
Publication -
"On the privacy of private browsing–a forensic approach" . Kiavash Satvat, Matthew Forshaw, Feng Hao, Ehsan Toreini. Data Privacy Management and Autonomous Spontaneous Security, 380-389.
ePrint
2012
-
Maryam Mehrnejad, Abbas Ghaemi Bafghi, Ahad Harati, Ehsan Toreini. "SEIMCHA: a new semantic image CAPTCHA using geometric transformations" . The ISC International Journal of Information Security 4 (1), 63-76.
ePrint
2011
-
"Multiple seimcha: multiple semantic image captcha" . Maryam Mehrnejad, Abbas Ghaemi Bafghi, Ahad Harati, Ehsan Toreini International Conference for Internet Technology and Secured Transactions (ICITST), 2011.
ePrint -
"A novel method in fuzzy data clustering based on chaotic PSO" . Ehsan Toreini, Maryam Mehrnejad. International Conference for Internet Technology and Secured Transactions (ICITST), 2011.
ePrint -
"Security analyzing and designing GUI with the resources model" . Maryam Mehrnejad, Ehsan Toreini, Abbas Ghaemi Bafghi. International Conference for Internet Technology and Secured Transactions (ICITST), 2011.
ePrint -
"Clustering Data with Particle Swarm Optimization using a new fitness" . Ehsan Toreini, Maryam Mehrnejad. Data Mining and Optimization (DMO), 2011 3rd Conference on, 266-270.
ePrint -
"A novel fuzzy metric to evaluate clusters for prolonging lifetime in wireless sensor networks" . Peyman Neamatollahi, Hoda Taheri, Ehsan Toreini, Mahmoud Naghibzadeh, Mohhamad Hossein Yaghmaee. Artificial Intelligence and Signal Processing (AISP), 2011 International.
ePrint -
"A new image based CAPTCHA based on geometric transformations" . Maryam Mehrnejad, Abbas Ghaemi Bafghi, Ahad Harati, Ehsan Toreini. 8th International ISC Conference on Information Security and Cryptology, FUM.
ePrint