| CARVIEW |
Habiba Farrukh
I am an Assistant Professor in the Department of Computer Science at the University of California, Irvine, where I lead the Security and Privacy of Emerging Computing Technology (SPECT) Lab. My research interests broadly lie in the areas of security & privacy and mobile computing. Through system design, machine learning, and human-centered methods, my research investigates security and privacy threats in emerging computing platforms, aiming to design secure systems that are not only technically robust but also aligned with users' needs and preferences.
I received my Ph.D. in Computer Science from Purdue University, where I was advised by Dr. Z. Berkay Celik and was a part of the PurSec Lab. My dissertation focused on leveraging multimodal sensing to improve the security and privacy of mobile and IoT systems.
Prospective Students
If you are a student at UCI, there are research opportunities for undergraduate/graduate students interested in the security and privacy of emerging computing platforms. Please email me for more details.
Updates
- [Aug 2025] Our paper on UI attacks in WebXR received an Honorable Mention Award at USENIX Security 2025!
- [June 2025] Our work on understanding privacy leakages from eye gaze data in extended reality (XR) received the Best Poster Runner-Up Award at MobiSys 2025!
- [May 2025] Our work on understanding users' S&P concerns and attitudes towards conversational AI platforms was presented at IEEE S&P 2025!
- [Aug 2024] Our papers on iOS app tracking transparency and online harassment against refugees appeared in USENIX Security 2024!
- [July 2024] Our paper on physical attacks against intermittent devices was presented at PETS 2024!
- [May 2024] Our paper on cross-device runtime permission models in wearables appeared in IEEE S&P 2024!
- [Feb 2024] Our work on abusive dropshipping appeared in NDSS 2024!
- [Feb 2024] Received the Outstanding Reviewer Award at VehicleSec 2024!
- [Aug 2023] Presented our work on location inference from spatial maps on AR/VR devices at USENIX Security 2023!
- [Nov 2022] Our work on secure group pairing of heterogeneous IoT devices is accepted to IEEE S&P 2023!
- [June 2021] Received Bilsland Dissertation Fellowship Award 2021-2022!
- [Mar 2021] Our paper about side-channel attacks on stylus pencils is accepted to IMWUT-UbiComp 2021!
- [Sep 2020] Our work on secure face liveness detection on commodity smartphones to appear in MobiCom 2020!
Selected Publications
- Virtual Reality, Real Problems: A Longitudinal Security Analysis of VR Firmware
Vamsi Shankar Simhadri, Yichang Xiong, Habiba Farrukh, and Xiaokuan Zhang
ACM Conference on Computer and Communications Security (CCS), 2025
- Scoop: Mitigation of Recapture Attacks on Provenance-Based Media Authentication
Yuxin (Myles) Liu, Habiba Farrukh, Ardalan Amiri Sani, Sharad Agarwal, and Gene Tsudik
USENIX Security Symposium, 2025
- Shadowed Realities: An Investigation of UI Attacks in WebXR
Chandrika Mukherjee, Reham Mohamed, Arjun Arunasalam, Habiba Farrukh, and Z. Berkay Celik
USENIX Security Symposium, 2025 [Paper] (Honorable Mention)
- PeekXR: Understanding Privacy Leakages from Eye Gaze in Extended Reality
Chuyang Peng, Mutahar Ali, and Habiba Farrukh
ACM International Conference on Mobile Systems, Applications, and Services (MobiSys), 2025 (Best Poster Runner-up)
- Understanding Users’ Security and Privacy Concerns and Attitudes Towards Conversational AI Platforms
Mutahar Ali, Arjun Arunasalam, and Habiba Farrukh
IEEE Security and Privacy (S&P), 2025 [Paper]
- Deceptive Sound Therapy on Online Platforms: Do Mental Wellbeing Tracks Conform to User Expectations?
Arjun Arunasalam, Jason Tong, Habiba Farrukh, Muslum Ozgur Ozmen, Koustuv Saha, and Z. Berkay Celik
International AAAI Conference on Web and Social Media (ICWSM), 2025
- Physical Side-Channel Attacks against Intermittent Devices
Muslum Ozgur Ozmen, Habiba Farrukh and Z. Berkay Celik
Privacy Enhancing Technologies (PoPETs), 2024 [Paper]
- Understanding the Security and Privacy Implications of Online Toxic Content on Refugees
Arjun Arunasalam*, Habiba Farrukh*, Eliz Tekcan*, and Z. Berkay Celik
USENIX Security Symposium, 2024 [Paper]
- ATTention Please! An investigation of the App Tracking Transparency Permission
Reham Mohamed, Arjun Arunasalam, Habiba Farrukh, Jason Tong, Antonio Bianchi, and Z. Berkay Celik
USENIX Security Symposium, 2024 [Paper]
- Wear’s my Data? Understanding the Cross-Device Runtime Permission Model in Wearables
Doguhan Yeke, Muhammad Ibrahim, Güliz Seray Tuncay, Habiba Farrukh, Abdullah Imran, Antonio Bianchi, and Z. Berkay Celik
IEEE Security and Privacy (S&P), 2024 [Paper]
- The Dark Side of E-Commerce: Dropshipping Abuse as a Business Model
Arjun Arunasalam, Andrew Chu, Muslum Ozgur Ozmen, Habiba Farrukh, and Z. Berkay Celik
ISOC Network and Distributed System Security Symposium (NDSS), 2024 [Paper]
- LocIn: Inferring Semantic Location from Spatial Maps in Mixed Reality
Habiba Farrukh, Reham Mohamed, Aniket Nare, Antonio Bianchi, and Z. Berkay Celik
USENIX Security Symposium, 2023 [Paper]
- One Key to Rule Them All: Secure Group Pairing for Heterogeneous IoT Devices
Habiba Farrukh*, Muslum Ozgur Ozmen*, Faik Kerem Ors, and Z. Berkay Celik
IEEE Security and Privacy (S&P), 2023 [Paper]
- iStelan: Disclosing Sensitive User Information by Mobile Magnetometer from Finger Touches
Reham Mohamed, Habiba Farrukh, He Wang, Yidong Lu, and Z. Berkay Celik
Privacy Enhancing Technologies (PoPETS), 2023 [Paper]
- Evasion Attacks on Smart Home Physical Event Verification and Defenses
Muslum Ozgur Ozmen, Ruoyu Song, Habiba Farrukh, and Z. Berkay Celik
ISOC Network and Distributed System Security Symposium (NDSS), 2023 [Paper]
- SARA: Secure Android Remote Authorization
Abdullah Imran, Habiba Farrukh, Muhammad Ibrahim, Z. Berkay Celik, and Antonio Bianchi
USENIX Security Symposium, 2022 [Paper]
- S3: Side-Channel Attack on Stylus Pencils through Sensors
Habiba Farrukh, Tinghan Yang, Hanwen Xu, Yuxuan Yin, He Wang, and Z. Berkay Celik
Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies (IMWUT/UbiComp), 2021 [Paper]
- FaceRevelio: A Face Liveness Detection System for Smartphones with a Single Front Camera
Habiba Farrukh, Reham Mohamed Aburas, Siyuan Cao, and He Wang
ACM International Conference on Mobile Computing and Networking (MobiCom), 2020 [Paper], [Video], [Slides]
Teaching
- CS190: Introduction to Security & Privacy (Spring 2025)
- CS204: Usable Security and Privacy (Fall 2024)
- CS295: Security and Privacy of Emerging Computing Platforms (Spring 2024)
Selected Service
-
Organizing Committee
- IEEE/ACM Workshop on the Internet of Safe Things (SafeThings), 2025, General Chair
- Cyber-Physical Systems and Internet-of-Things Week (CPS-IoT Week), 2025, Web Chair
- ACM International Conference on Mobile Systems, Applications, and Services (MobiSys), 2025, Demo Chair
- ISOC Symposium on Vehicle Security and Privacy (VehicleSec), 2024, 2025, Local Arrangement Chair
- IEEE/ACM Internet of Safe Things (SafeThings), 2023, Publicity Chair
-
Program Committee Member
- USENIX Security Symposium, 2023, 2024, 2025
- IEEE Security and Privacy (S&P), 2024, 2025
- Network and Distributed System Security Symposium (NDSS), 2024, 2025
- ACM Conference on Computer and Communications Security (CCS), 2024, 2025
- ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), 2023, 2024
- IEEE INFOCOM, 2024
- ACM CoNEXT, 2024
- ACM Workshop on CPS & IoT Security and Privacy (co-located with CCS), 2023