Email: Mainack Mondal
Google Scholar
CV
(Last updated: September 2022)

Department of Computer Science and Engineering, IIT Kharagpur,
Room : 316
IIT Kharagpur, West Bengal,
PIN: 721302, India

I am an Assistant Professor at Department of Computer Science and Engineering, IIT Kharagpur, India. Previously, I was a postdoctoral researcher at Cornell Tech and a member of the Digital Life Initiative where I worked with Prof. Helen Nissenbaum. Prior to joining Cornell Tech I spent a fantastic year as a postdoc at the University of Chicago, Department of Computer Science. There I was a member of SUPERgroup and worked with Prof. Blase Ur. I completed my Ph.D. in Computer Science on November 2017 at the Max Planck Institute for Software systems where I was advised by Prof. Krishna P. Gummadi.

I am broadly interested about incorporating human factors in security and privacy, and consequently designing usable online services. My recent research focus is on developing systems to provide usable privacy and security mechanisms to online users while minimizing system abuse.

I am always looking for students who are interested in human aspects of privacy/security and like to tinker with systems. If you are already a student at IIT Kgp && if you feel strongly about making the digital world private and secure for the users just drop me a mail. Also it will be beneficial for both of us if you have taken the Usable Security and Privacy course.

Latest updates

Research Interests

I design, implement and analyze usable private and secure online systems. My work integrates security and privacy, human-computer interaction and systems research.
Specifically, I often start from prominent privacy, security or anti-abuse norms (via examining laws or performing user studies grounded in contextual integrity of other privacy theories), audit online systems via automation if they are following those norms and finally aim to build end-to-end systems which aligns well with the identified norms. Some of my prominent ongoing research projects are below:

Assisting Users to Afford Protection of Data Privacy and Security Regulations

Today, data privacy regulations are being deployed in multiple different jurisdictions. GDPR is enforced in EU and CCPA is already in effect in the US. Other countries have also enforced regulations like LGPD (Brazil) and PIPEDA (Canada). However, it is not clear, if existing systems are helping end users to afford the protections offered by these laws. Our body of (ongoing) work aims to design and build automated smart assistive mechanisms for privacy and security management of user data as identified by legal regulations. The regulations we focus on span from temporal privacy to third-party tracking protection. Some specific focus of our work is:

  • Improving usability of retrospective access management in online data archives (enabling "Right to be forgotten") [SEC'22][ICWSM'21][NDSS'21][CCS'19][PoPETS'19][SOUPS'18]
    We are investigating the effectiveness of tools (e.g., data privacy dashboard, privacy settings) which enable users to retrospectively modify (delete/edit old content or retrospectively change the audience) their past content in online archives (like social media or cloud storage). Our final goal is to design new mechanisms and systems which will let online users better manage the security and privacy of their old content.
  • Bringing transparency and control to third-party behavior tracking (enabling "informed consent" in cookie-based tracking) [EuroUSEC'22][WebSci'21][CCS'19]
    Laws like GDPR in the EU mandated all websites operating in their jurisdiction to obtain users’ informed consent before tracking those users and collecting their data. Today, this is achieved by showing users cookie consent notices and sometimes showing users the names of the cookies used by a website. However, the cookie consent notices have multiple designs, the cookie names are often intelligible to the users and overall the end-users might not know what data is aggregated about them by correlating data from multiple websites. In this line of research we aim to give control back to users by identifying principles of designing good cookie consent management interfaces as well as informing users about the purpose of the cookies and the data they enable companies to gather about themselves.
  • Improving Indian Unified Payment Interface (UPI) apps to enabling users fight against financial fraud [SOUPS'22 Poster]
    Online payment methods have gained enormous traction in India due to the launch of Unified Payment Interface (UPI), an API developed by the government-based identity National Payments Corporation of India (NPCI), to facilitate free and instant money transfers between users’ bank accounts. Multiple financial apps use this API and often enable money transfer directly from Indian bank accounts via just a click. However, this functionality also gives rise to a flurry of fraudulent transactions, often via social engineering attacks. We are investigating if the UPI app interfaces help to deter or even facilitate financial frauds.

Limiting abuse in online platforms [ICWSM'23] [ICWSM'22] [THAM'18] [HT'17] [ICWSM'16] [ICWSM'15]

HATESPEECH DATASET 89 MILLION ANONYMOUS WHISPER POSTS DATASET HIGH-ACCURACY AD-HOMINEM FALLACY DETECTOR COVID-19 ANTI-PRO VAX STANCE DATASET

We investigate user behavior in online platforms using large-scale data and via user-studies. We identified that privacy and anonymity is a blessing to most of the user since they enable users to upheld free speech. However, a few users abuse the system (sometimes) under the veil of anonymity and take advantage of the platform in the form of posting abusive content like hatespeech, vaccine-related misinformation or using ad-hominem fallacies to silence opinions. To that end, we work on developing techniques to detect and investigate hate speech in online platforms.

Managing online data privacy and security in Online Social Media Platforms [IJAESAM'17] [IC'17] [SOUPS'16] [USEC'14] [SOUPS'14] [CoNEXT'12] [EuroSys'12]

We developed the model of exposure control (controlling who actually views a piece of online content), an extension of existing access control (controlling who has access to the online content) for building more secure/private systems. We apply this theory of exposure control in multiple real-world scenarios and built systems for end users. These exposure control based systems enabled us to better capture user intention and design more private and usable systems compare to the state of the art.

Publications

Refereed publications

  • MASCARA: Systematically Generating Memorable And Secure Passphrases
    Avirup Mukherjee, Kousshik Murali, Shivam Kumar Jha, Niloy Ganguly, Rahul Chatterjee, Mainack Mondal.
    In Proceedings of the 18th ACM ASIA Conference on Computer and Communications Security (ACM ASIACCS 2023).
    ABSTRACT PDF BIBTEX  

  • Understanding the Impact of Awards on Award Winners and the Community on Reddit
    Avinash Tulasi, Mainack Mondal, Arun Balaji Buduru and Ponnurangam Kumaraguru.
    In Proceedings of The IEEE/ACM International Conference on Social Networks Analysis and Mining (ASONAM).
    ABSTRACT PDF  BIBTEX  SHORT PAPER

  • What Cookie Consent Notices Do Users Prefer: A Study In The Wild
    Ashutosh Kumar Singh, Nisarg Upadhyaya , Arka Seth, Xuehui Hu, Nishanth Sastry, Mainack Mondal.
    In Proceedings of The European Symposium on Usable Security (EuroUSEC).
    ABSTRACT PDF BIBTEX

  • "Dummy Grandpa, do you know anything?": Identifying and Characterizing Ad hominem Fallacy Usage in the Wild
    Utkarsh Patel, Animesh Mukherjee, Mainack Mondal.
    In Proceedings of The 17th International AAAI Conference on Weblogs and Social Media (ICWSM'23).
    ABSTRACT PDF BIBTEX MODEL

  • A Privacy Paradox? Impact of Privacy Concerns on Willingness to Disclose COVID-19 Health Status in the United States
    Kirsten Chapman, Melanie Klimes, Braden Wellman, Garrett Smith, Mainack Mondal, Staci Smith, Yunan Chen, Haijing Hao, Xinru Page.
    In Proceedings of the 25th ACM Conference on Computer Supported Cooperative Work and Social Computing (CSCW'22), Virtual Venue, November 2022.
    ABSTRACT PDF [FORTHCOMING] BIBTEX [FORTHCOMING] POSTER

  • A Platform for Uncovering Indian Users' Decision-Making Process in United Payment Interface (UPI) Apps
    Kshitiz Sharma, Nandini Bajaj, Xinru Page, Mainack Mondal.
    In Proceedings of the 18th Symposium on Usable Privacy and Security (SOUPS'22),Boston, US, August 2022.
    ABSTRACT  PDF BIBTEX POSTER

  • "Others Have the Right to Know": Determinants of Willingness to Share COVID-19-Related Health Symptoms
    Kirsten Chapman, Melanie Klimes, Braden Wellman, Garrett Smith, Madeline Bonham, Yunan Chen, Staci Smith, Mainack Mondal, Xinru Page.
    In Proceedings of the 18th Symposium on Usable Privacy and Security (SOUPS'22), Boston, US, August 2022.
    ABSTRACT  PDF BIBTEX POSTER

  • Designing to Fight Pandemics: A Review of Literature and Identifying Design Patterns for COVID-19 Tracing Apps
    Isaac Criddle, Amanda Hardy, Garrett Smith, Thomas Ranck, Mainack Mondal, Xinru Page.
    In Proceedings of The 24th 24th International Conference on Human-Computer Interaction, HCI International 2022 (HCII'22).
    ABSTRACT PDF BIBTEX

  • Winds of Change: Impact of COVID-19 on Vaccine-related Opinions of Twitter users
    Soham Poddar, Mainack Mondal, Janardan Misra, Niloy Ganguly, Saptarshi Ghosh.
    In Proceedings of The 16th International AAAI Conference on Weblogs and Social Media (ICWSM'22).
    ABSTRACT PDF BIBTEX DATA+CODE PDF [PREPRINT]

  • Understanding and Improving Usability of Data Dashboards for Simplified Privacy Control of Voice Assistant Data
    Vandit Sharma, Mainack Mondal.
    In Proceedings of the 31st USENIX Security Symposium (USENIX Security'22), Boston, MA, US, August 2022.
    ABSTRACT PDF PDF [EXTENDED VERSION] BIBTEX

  • Empirical Understanding of Deletion Privacy: Experiences, Expectations, and Measures
    Mohsen Minaei, Mainack Mondal, Aniket Kate.
    In Proceedings of the 31st USENIX Security Symposium (USENIX Security'22), Boston, MA, US, August 2022.
    ABSTRACT PDF PDF [EXTENDED VERSION] BIBTEX

  • Prioritizing Minimalistic Design: The Negative Impact on Users’ Control over Privacy in Facebook’s Ad Preferences
    Rhea Vengurlekar, Sarah Benson, Garrett Smith, Brian Smith, Mainack Mondal, Norman Makoto Su, Xinru Page.
    In Proceedings of the 17th Symposium on Usable Privacy and Security (SOUPS'21), Virtual venue, August 2021.
    ABSTRACT  PDF BIBTEX POSTER

  • CCCC: Corralling Cookies into Categories with CookieMonster
    Xuehui Hu, Nishanth Sastry, Mainack Mondal.
    In Proceedings of The 13th ACM Web Science Conference (WebSci'21).
    ABSTRACT PDF [PREPRINT] PDF BIBTEX

  • Perceptions of Retrospective Edits, Changes, and Deletion on Social Media
    Günce Su Yılmaz, Fiona Gasaway, Blase Ur, Mainack Mondal.
    In Proceedings of The 15th International AAAI Conference on Weblogs and Social Media (ICWSM'21).
    ABSTRACT PDF BIBTEX

  • Cloaking Large-Scale Damaging Deletions on Social Platforms
    Mohsen Minaei, S Chandra Mouli, Mainack Mondal, Bruno Ribeiro, Aniket Kate.
    In Proceedings of Network and Distributed System Security Symposium (NDSS'21).
    ABSTRACT PDF PDF [PREPRINT] BIBTEX VIDEO

  • Cultural Norms and Interpersonal Relationships: Comparing Disclosure Behaviors on Twitter
    Anju Punuru, Tyng-Wen Scott Cheng, Isha Ghosh, Xinru Page, Mainack Mondal.
    In Proceedings of the 23rd ACM Conference on Computer Supported Cooperative Work and Social Computing (CSCW'20), Virtual Venue, October 2020.
    ABSTRACT PDF BIBTEX POSTER

  • Anonymity Effects: A Large-Scale Dataset from an Anonymous Social Media Platform
    Mainack Mondal, Denzil Correa, Fabrício Benevenuto.
    In Proceedings of the 28th ACM Conference on Hypertext and Social Media (HT'20), Virtual Event, USA, July 2020.
    ABSTRACT PDF BIBTEX 

  • Oh, the Places You've Been! User Reactions to Longitudinal Transparency About Third-Party Web Tracking and Inferencing
    Ben Weinshel, Miranda Wei, Mainack Mondal, Euirim Choi, Shawn Shan, Claire Dolin, Michelle L. Mazurek, Blase Ur.
    In the Proceedings of the 26th ACM Conference on Computer and Communications Security (CCS) , London, UK, November 2019.
    ABSTRACT PDF BIBTEX

  • Moving Beyond Set-It-And-Forget-It Privacy Settings on Social Media
    Mainack Mondal, Günce Su Yılmaz, Noah Hirsch, Mohammad Taha Khan, Michael Tang, Christopher Tran, Chris Kanich, Blase Ur, Elena Zheleva.
    In the Proceedings of the 26th ACM Conference on Computer and Communications Security (CCS) , London, UK, November 2019.
    ABSTRACT PDF BIBTEX

  • Lethe: Conceal Content Deletion from Persistent Observers
    Mohsen Minaei, Mainack Mondal, Patrick Loiseau, Krishna Gummadi, and Aniket Kate.
    In the Proceedings of Privacy Enhancing Technologies Symposium (PoPETS), Stockholm, Sweden, July 2019.
    ABSTRACT PDF BIBTEX ArXiv (PRELIMINARY) JOURNAL

  • Enforcing Contextual Integrity With Exposure Control
    Mainack Mondal and Blase Ur.
    In the Symposium on Applications of Contextual Integrity, Princeton, NJ, USA, September 2018.
    ABSTRACT PDF BIBTEX

  • Making Retrospective Data Management Usable
    Noah Hirsch, Chris Kanich, Mohammad Taha Khan, Xuefeng Liu, Mainack Mondal, Michael Tang, Christopher Tran, Blase Ur, William Wang, Günce Su Yılmaz, Elena Zheleva.
    In Proceedings of the 14th Symposium on Usable Privacy and Security (SOUPS'18), Baltimore, MD, USA, August 2018.
    ABSTRACT PDF BIBTEX POSTER

  • Characterizing Usage of Explicit Hate Expressions in Social Media
    Mainack Mondal, Leandro Arau ́jo Silva, Denzil Correa and Fabr ́ıcio Benevenuto.
    In New Review of Hypermedia and Multimedia (THAM), vol. 24, no. 2, pp. 110-130, June 2018.
    ABSTRACT  PDF [PREPRINT] BIBTEX JOURNAL 

  • Draining the Data Swamp: A Similarity-based Approach
    Will Brackenbury, Rui Liu, Mainack Mondal, Aaron Elmore, Blase Ur, Kyle Chard, Michael J. Franklin.
    In Proceedings of the Workshop on Human-In-the-Loop Data Analytics (HILDA), Houston, TX, June 2018.
    ABSTRACT  PDF BIBTEX

  • Managing Longitudinal Exposure of Socially Shared Data on the Twitter Social Media
    Mainack Mondal, Johnnatan Messias, Saptarshi Ghosh, Krishna P Gummadi, Aniket Kate.
    In International Journal of Advances in Engineering Sciences and Applied Mathematics (IJAESAM), vol. 9, no. 4, pp. 238-257, December 2017.
    ABSTRACT PDF (PREPRINT) BIBTEX JOURNAL

  • A Measurement Study of Hate Speech in Social Media
    Mainack Mondal, Leandro Araújo Silva, Fabrício Benevenuto.
    In Proceedings of the 25th ACM Conference on Hypertext and Social Media (HT'17), Prague, Czech Republic, July 2017.
    ABSTRACT PDF BIBTEX TED NELSON AWARD NOMINEE 

  • Longitudinal Privacy Management in Social Media: The Need for Better Controls
    Mainack Mondal, Johnnatan Messias, Saptarshi Ghosh, Krishna P. Gummadi and Aniket Kate.
    In IEEE Internet Computing, vol. 21, no. 3, pp. 48-55, May-June 2017.
    ABSTRACT PDF (PREPRINT) BIBTEX JOURNAL

  • Forgetting in Social Media: Understanding and Controlling Longitudinal Exposure of Socially Shared Data
    Mainack Mondal, Johnnatan Messias, Saptarshi Ghosh, Krishna P. Gummadi and Aniket Kate.
    In Proceedings of the 12th Symposium on Usable Privacy and Security (SOUPS'16), Denver, CO, USA, June 2016.
    ABSTRACT PDF BIBTEX

  • Analyzing the Targets of Hate in Online Social Media
    Leandro Araújo Silva, Mainack Mondal, Denzil Correa, Fabrício Benevenuto and Ingmer Weber.
    In Poster session, 10th International AAAI Conference on Weblogs and Social Media (ICWSM'16), Cologne, Germany, May 2016.
    ABSTRACT PDF POSTER 

  • The Many Shades of Anonymity: Characterizing Anonymous Social Media Content
    Denzil Correa, Leandro Araújo Silva, Mainack Mondal, Fabrício Benevenuto and Krishna P. Gummadi.
    In Proceedings of The 9th International AAAI Conference on Weblogs and Social Media (ICWSM'15), Oxford, UK, May 2015.
    ABSTRACT PDF BIBTEX

  • Understanding and Specifying Social Access Control Lists
    Mainack Mondal, Yabing Liu, Bimal Viswanath, Krishna P. Gummadi and Alan Mislove.
    In Proceedings of the 10th Symposium on Usable Privacy and Security (SOUPS'14), Menlo Park, CA, USA, July 2014.
    ABSTRACT PDF BIBTEX DISTINGUISHED PAPER AWARD

  • Beyond Access Control: Managing Online Privacy via Exposure
    Mainack Mondal, Peter Druschel, Krishna P. Gummadi. and Alan Mislove.
    In Proceedings of the Workshop on Usable Security (USEC'14), San Diego, CA, USA, February 2014.
    ABSTRACT PDF BIBTEX

  • Deep Twitter Diving: Exploring Topical Groups in Microblogs at Scale
    Parantapa Bhattacharya, Saptarshi Ghosh, Juhi Kulshrestha, Mainack Mondal, Muhammad Bilal Zafar, Niloy Ganguly, and Krishna P. Gummadi.
    In Proceedings of the 17th ACM Conference on Computer Supported Cooperative Work and Social Computing (CSCW'14), Baltimore, MD, USA, February 2014.
    ABSTRACT PDF BIBTEX

  • Defending against large-scale crawls in online social networks
    Mainack Mondal, Bimal Viswanath, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove and Ansley Post.
    In Proceedings of the 8th International Conference on emerging Networking EXperiments and Technologies (CoNEXT'12), Nice, France, December 2012.
    ABSTRACT PDF BIBTEX Slides/

  • Simplifying Friendlist Management (Demo Paper)
    Yabing Liu, Bimal Viswanath, Mainack Mondal, Krishna P. Gummadi, and Alan Mislove.
    In Proceedings of the 21st International World Wide Web Conference (WWW'12), Lyon, France, April 2012.
    ABSTRACT PDF BIBTEX

  • Canal: Scaling social network-based Sybil tolerance schemes
    Bimal Viswanath, Mainack Mondal, Krishna P. Gummadi, Alan Mislove and Ansley Post.
    In Proceedings of the 7th European Conference on Computer Systems (EuroSys’12), Bern, Switzerland, April 2012.
    ABSTRACT PDF BIBTEX

  • Limiting Large-scale Crawls of Social Networking Sites
    Mainack Mondal, Bimal Viswanath, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove and Ansley Post.
    In Poster session, Annual Conference of the ACM Special Interest Group on Data Communication (SIGCOMM'11),Toronto, Canada, August 2011.
    ABSTRACT PDF POSTER SIGCOMM'11 STUDENT RESEARCH COMPETITION FINALIST

  • TweLEX: A tweaked version of the LEX stream cipher
    Mainack Mondal, Avik Chakraborty, Nilanjan Dutta, Debdeep Mukhopadhyay.
    In 5th Benelux Workshop on Information and System Security, (WISSec’10), Nijmegen, the Netherlands, November 2010.
    ABSTRACT PDF Slides

  • Pinpointing Cache Timing Attacks on AES
    Chester Rebeiro, Mainack Mondal, Debdeep Mukhopadhyay.
    In 23rd International Conference on VLSI design and 9th International Conference on Embedded Systems (VLSID'10),Bangalore, India, January 2010.
    ABSTRACT PDF

Non-refereed publications

  • Double-edged Swords: The Good and the Bad of Privacy and Anonymity in Social Media (Invited talk abstract)
    Mainack Mondal
    In Proceedings of the 3rd International Workshop on Social Media World Sensors (SIDEWAYS'17), Prague, Czech Republic, July 2017.
    PDF BIBTEX

  • Exploring the design space of social network-based Sybil defenses (Invited paper)
    Bimal Viswanath, Mainack Mondal, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove and Ansley Post.
    In Proceedings of the 4th International Conference on Communication Systems and Networks (COMSNETS'12), Bangalore, India, January 2012.
    ABSTRACT PDF BIBTEX

  • Defending against large-scale crawls in online social networks
    Mainack Mondal, Bimal Viswanath, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove and Ansley Post.
    MPI-SWS Technical Report 2011-006, MPI-SWS, November 2011.
    ABSTRACT PDF BIBTEX

Our Systems/Datasets

A common theme of our work is to collect real world data from deployed systems and analyze this data to identify and address privacy, security or accountability issues in those systems. Consequently, we created some online systems as part of our research to help social network users better understand and manage their data privacy. Please find below a list of such system and datasets from our work:

Systems developed

  • Check Your Secondary Digital Footprint on Twitter: In Twitter, people may converse with you by mentioning your name in their tweets. These conversations constitute your secondary digital footprint. Secondary digital footprints are not created or controlled by you. However, they can still leak your personal information. Our Twitter application aims to help you check what information others leak about you on Twitter (You will need a Twitter account to use it ).

  • Friendlist Manager: Friendlists in Facebook are a great way to share your content with the people you intend to. But they are a huge pain to create and update. Our Facebook application was designed to facilitate and simplify management of your friendlists. Unfortunately, the new version of Facebook API does not allow developers to fetch the data the app needed to use, consequently the app is not live any more. You can check the functions of this (now discontinued) app here.

  • Privacy IQ: Privacy IQ is a quiz that measures both your understanding of how privacy works on Facebook and your knowledge of your own privacy settings. However due to the change in Facebook API this app too is not live any more.

Datasets from our work

Professional Services

Organizing Committee:: CSCW’22, SPACE'22, SPACE’21, SPACE’20, COMSNETS’22, COMSNETS’21, COMSNETS’20 PC Member: WWW'23, USENIX SECURITY'23, USENIX SECURITY'22, ACM CCS'22, SOUPS'22, SOUPS’21, CHI'21, COMSNETS'21, SPACE'20, ICWSM'20, COMSNETS'20, CoDS-COMAD (YRS)'20, ALW'19, CI'19, CHI'19 Workshop, DIS PWiP'19, COMSNETS SNW'2019, CoDS-COMAD (YRS)'19, TRAC'18.
Reviewer (Journal): ACM ToN, IEEE IC, ACM TOIT, ACM TWEB, IEEE TPDS, IEEE TDSC, Elsevier JPDC.
Reviewer (Conference): ACM CSCW, ACM CHI, ACM AsiaCCS, ICWSM, WWW, WebSci.