| 2026 | SP | Exploiting Leaderboards for Large-Scale Distribution of Malicious Models. | Anshuman Suri, Harsh Chaudhari, Yuefeng Peng, Ali Naseh, Alina Oprea, Amir Houmansadr |
| 2025 | AAAI | Improving Private Random Forest Prediction Using Matrix Representation. | Arisa Tajima, Joie Wu, Amir Houmansadr |
| 2025 | CCS | Riddle Me This! Stealthy Membership Inference for Retrieval-Augmented Generation. | Ali Naseh, Yuefeng Peng, Anshuman Suri, Harsh Chaudhari, Alina Oprea, Amir Houmansadr |
| 2025 | NDSS | RAIFLE: Reconstruction Attacks on Interaction-based Federated Learning with Adversarial Data Manipulation. | Dzung Pham, Shreyas Kulkarni, Amir Houmansadr |
| 2025 | NDSS | Wallbleed: A Memory Disclosure Vulnerability in the Great Firewall of China. | Shencha Fan, Jackson Sippe, Sakamoto San, Jade Sheffey, David Fifield, Amir Houmansadr, Elson Wedwards, Eric Wustrow |
| 2025 | NDSS | Diffence: Fencing Membership Privacy With Diffusion Models. | Yuefeng Peng, Ali Naseh, Amir Houmansadr |
| 2025 | SP | A Wall Behind A Wall: Emerging Regional Censorship in China. | Mingshi Wu, Ali Zohaib, Zakir Durumeric, Amir Houmansadr, Eric Wustrow |
| 2024 | CISS | Optimal Obfuscation to Protect Client Privacy in Federated Learning. | Bo Guan, Shuangqing Wei, Amir Houmansadr, Hossein Pishro-Nik, Dennis Goeckel |
| 2024 | EMNLP | PostMark: A Robust Blackbox Watermark for Large Language Models. | Yapei Chang, Kalpesh Krishna, Amir Houmansadr, John Wieting, Mohit Iyyer |
| 2024 | ESORICS | Fake or Compromised? Making Sense of Malicious Clients in Federated Learning. | Hamid Mozaffari, Sunav Choudhary, Amir Houmansadr |
| 2024 | WWW | The Effect of Alter Ego Accounts on A/B Tests in Social Networks. | Katherine Avery, Amir Houmansadr, David D. Jensen |
| 2023 | AsiaCCS | Investigating Traffic Analysis Attacks on Apple iCloud Private Relay. | Ali Zohaib, Jade Sheffey, Amir Houmansadr |
| 2023 | CCS | Realistic Website Fingerprinting By Augmenting Network Traces. | Alireza Bahramali, Ardavan Bozorgi, Amir Houmansadr |
| 2023 | CCS | Stealing the Decoding Algorithms of Language Models. | Ali Naseh, Kalpesh Krishna, Mohit Iyyer, Amir Houmansadr |
| 2023 | ICCV | The Perils of Learning From Unlabeled Data: Backdoor Attacks on Semi-supervised Learning. | Virat Shejwalkar, Lingjuan Lyu, Amir Houmansadr |
| 2023 | ICML | Effectively Using Public Data in Privacy Preserving Machine Learning. | Milad Nasr, Saeed Mahloujifar, Xinyu Tang, Prateek Mittal, Amir Houmansadr |
| 2023 | SP | On the Pitfalls of Security Evaluation of Robust Federated Learning. | Momin Ahmad Khan, Virat Shejwalkar, Amir Houmansadr, Fatima M. Anwar |
| 2022 | ISIT | Constrained Obfuscation to Thwart Pattern Matching Attacks. | Saeede Enayati, Dennis L. Goeckel, Amir Houmansadr, Hossein Pishro-Nik |
| 2022 | ISNCC | Privacy-Preserving Path-Planning for UAVs. | Saeede Enayati, Dennis L. Goeckel, Amir Houmansadr, Hossein Pishro-Nik |
| 2022 | SP | Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated Learning. | Virat Shejwalkar, Amir Houmansadr, Peter Kairouz, Daniel Ramage |
| 2022 | SENSYS | Security Analysis of SplitFed Learning. | Momin Ahmad Khan, Virat Shejwalkar, Amir Houmansadr, Fatima M. Anwar |
| 2021 | AAAI | Membership Privacy for Machine Learning Models Through Knowledge Transfer. | Virat Shejwalkar, Amir Houmansadr |
| 2021 | ACSAC | FINN: Fingerprinting Network Flows using Neural Networks. | Fatemeh Rezaei, Amir Houmansadr |
| 2021 | CCS | Robust Adversarial Attacks Against DNN-Based Wireless Communication Systems. | Alireza Bahramali, Milad Nasr, Amir Houmansadr, Dennis Goeckel, Don Towsley |
| 2021 | NDSS | Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning. | Virat Shejwalkar, Amir Houmansadr |
| 2020 | IMC | How China Detects and Blocks Shadowsocks. | Alice, Bob, Carol, Jan Beznazwy, Amir Houmansadr |
| 2020 | ISIT | Sequence Obfuscation to Thwart Pattern Matching Attacks. | Bo Guan, Nazanin Takbiri, Dennis L. Goeckel, Amir Houmansadr, Hossein Pishro-Nik |
| 2020 | NDSS | Practical Traffic Analysis Attacks on Secure Messaging Applications. | Alireza Bahramali, Amir Houmansadr, Ramin Soltani, Dennis Goeckel, Don Towsley |
| 2020 | NDSS | Heterogeneous Private Information Retrieval. | Hamid Mozaffari, Amir Houmansadr |
| 2020 | NDSS | MassBrowser: Unblocking the Censored Web for the Masses, by the Masses. | Milad Nasr, Hadi Zolfaghari, Amir Houmansadr, Amirhossein Ghafari |
| 2020 | SecureComm | The Bitcoin Hunter: Detecting Bitcoin Traffic over Encrypted Channels. | Fatemeh Rezaei, Shahrzad Naseri, Ittay Eyal, Amir Houmansadr |
| 2019 | ACSAC | Revisiting utility metrics for location privacy-preserving mechanisms. | Virat Shejwalkar, Amir Houmansadr, Hossein Pishro-Nik, Dennis Goeckel |
| 2019 | CISS | Asymptotic Limits of Privacy in Bayesian Time Series Matching. | Nazanin Takbiri, Dennis L. Goeckel, Amir Houmansadr, Hossein Pishro-Nik |
| 2019 | GLOBECOM | Blocking-Resilient Communications in Information-Centric Networks Using Router Redirection. | Hamid Mozaffari, Amir Houmansadr, Arun Venkataramani |
| 2019 | NDSS | Enemy At the Gateways: Censorship-Resilient Proxy Distribution Using Game Theory. | Milad Nasr, Sadegh Farhang, Amir Houmansadr, Jens Grossklags |
| 2019 | WCNC | Asymptotic Loss in Privacy due to Dependency in Gaussian Traces. | Nazanin Takbiri, Ramin Soltani, Dennis L. Goeckel, Amir Houmansadr, Hossein Pishro-Nik |
| 2019 | SP | Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning. | Milad Nasr, Reza Shokri, Amir Houmansadr |
| 2018 | CCGRID | Main-Memory Requirements of Big Data Applications on Commodity Server Platform. | Hosein Mohammadi Makrani, Setareh Rafatirad, Amir Houmansadr, Houman Homayoun |
| 2018 | CCS | DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep Learning. | Milad Nasr, Alireza Bahramali, Amir Houmansadr |
| 2018 | CCS | Machine Learning with Membership Privacy using Adversarial Regularization. | Milad Nasr, Reza Shokri, Amir Houmansadr |
| 2018 | ISIT | Privacy Against Statistical Matching: Inter-User Correlation. | Nazanin Takbiri, Amir Houmansadr, Dennis L. Goeckel, Hossein Pishro-Nik |
| 2017 | ACSSC | Towards provably invisible network flow fingerprints. | Ramin Soltani, Dennis Goeckel, Don Towsley, Amir Houmansadr |
| 2017 | CCS | Compressive Traffic Analysis: A New Paradigm for Scalable Traffic Analysis. | Milad Nasr, Amir Houmansadr, Arya Mazumdar |
| 2017 | CCS | The Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing Attacks. | Milad Nasr, Hadi Zolfaghari, Amir Houmansadr |
| 2017 | CISS | Fundamental limits of location privacy using anonymization. | Nazanin Takbiri, Amir Houmansadr, Dennis L. Goeckel, Hossein Pishro-Nik |
| 2017 | ESORICS | Graphene: A New Protocol for Block Propagation Using Set Reconciliation. | A. Pinar Ozisik, Gavin Andresen, George Bissias, Amir Houmansadr, Brian Neil Levine |
| 2017 | ISIT | Limits of location privacy under anonymization and obfuscation. | Nazanin Takbiri, Amir Houmansadr, Dennis L. Goeckel, Hossein Pishro-Nik |
| 2016 | CCS | GAME OF DECOYS: Optimal Decoy Routing Through Game Theory. | Milad Nasr, Amir Houmansadr |
| 2016 | CCS | Practical Censorship Evasion Leveraging Content Delivery Networks. | Hadi Zolfaghari, Amir Houmansadr |
| 2016 | CISS | Defining perfect location privacy using anonymization. | Zarrin Montazeri, Amir Houmansadr, Hossein Pishro-Nik |
| 2016 | ISITA | Achieving perfect location privacy in Markov models using anonymization. | Zarrin Montazeri, Amir Houmansadr, Hossein Pishro-Nik |
| 2015 | ACSAC | Know Your Achilles' Heel: Automatic Detection of Network Critical Services. | Ali Zand, Amir Houmansadr, Giovanni Vigna, Richard A. Kemmerer, Christopher Kruegel |
| 2015 | CCS | CacheBrowser: Bypassing Chinese Censorship without Proxies Using Cached Content. | John Holowczak, Amir Houmansadr |
| 2014 | NDSS | No Direction Home: The True Cost of Routing Around Decoys. | Amir Houmansadr, Edmund L. Wong, Vitaly Shmatikov |
| 2013 | NDSS | I want my voice to be heard: IP over Voice-over-IP for unobservable censorship circumvention. | Amir Houmansadr, Thomas J. Riedl, Nikita Borisov, Andrew C. Singer |
| 2013 | SP | The Parrot Is Dead: Observing Unobservable Network Communications. | Amir Houmansadr, Chad Brubaker, Vitaly Shmatikov |
| 2012 | CCS | CensorSpoofer: asymmetric communication using IP spoofing for censorship-resistant web browsing. | Qiyan Wang, Xun Gong, Giang T. K. Nguyen, Amir Houmansadr, Nikita Borisov |
| 2012 | DSN | EliMet: Security metric elicitation in power grid critical infrastructures by observing system administrators' responsive behavior. | Saman A. Zonouz, Amir Houmansadr, Parisa Haghani |
| 2011 | ACSAC | Nexat: a history-based approach to predict attacker actions. | Casey Cipriano, Ali Zand, Amir Houmansadr, Christopher Kruegel, Giovanni Vigna |
| 2011 | CCS | Cirripede: circumvention infrastructure using router redirection with plausible deniability. | Amir Houmansadr, Giang T. K. Nguyen, Matthew Caesar, Nikita Borisov |
| 2011 | DSN | A cloud-based intrusion detection and response system for mobile phones. | Amir Houmansadr, Saman A. Zonouz, Robin Berthier |
| 2011 | ICASSP | Towards improving network flow watermarks using the repeat-accumulate codes. | Amir Houmansadr, Nikita Borisov |
| 2011 | NDSS | SWIRL: A Scalable Watermark to Detect Correlated Network Flows. | Amir Houmansadr, Nikita Borisov |
| 2009 | ICASSP | Multi-flow attack resistant watermarks for network flows. | Amir Houmansadr, Negar Kiyavash, Nikita Borisov |
| 2009 | NDSS | RAINBOW: A Robust And Invisible Non-Blind Watermark for Network Flows. | Amir Houmansadr, Negar Kiyavash, Nikita Borisov |