Aurore Fass's Avatar

Aurore Fass

@aurore-fass

Tenured Researcher @Inria USENIX Security Artifact Evaluation Co-Chair 2025 & 2026 Web Security & Privacy: JavaScript (in)security, browser extensions https://aurore54f.github.io

90
Followers
233
Following
11
Posts
12.09.2025
Joined
Posts Following

Latest posts by Aurore Fass @aurore-fass

Post image

Are you interested in a ๐—ง๐—ฒ๐—ป๐˜‚๐—ฟ๐—ฒ๐—ฑ ๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ฃ๐—ผ๐˜€๐—ถ๐˜๐—ถ๐—ผ๐—ป ๐˜„๐—ถ๐˜๐—ต ๐—ฎ ๐—ฏ๐—ฎ๐—ฐ๐—ธ๐—ด๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ ๐—ถ๐—ป ๐—˜๐—จ ๐——๐—ฎ๐˜๐—ฎ ๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป, ๐——๐—ฆ๐—”, ๐——๐— ๐—” ๐—Ÿ๐—ฎ๐˜„ at Inria? With Nataliia Bielova, we are seeking candidates interested in applying to join our future team!
๐Ÿ“… Express interest by Feb 6, 2026
๐Ÿ‘‰ More info here: www-sop.inria.fr/members/Nata...

27.01.2026 13:30 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
(Self-)Nomination for the USENIX Security '26 Artifact Evaluation Committee (AEC) For the seventh year, USENIX Security allows the evaluation of artifacts that support a paper: software, hardware, evaluation data and documentation, raw measurement data, raw survey results, mechaniz...

Last chance to (self-) nominate for USENIX Security'26 Artifact Evaluation Committee!
You should expect a low load of ~1 artifact for functionality/reproducibility assessments per cycle (max 3 for the whole year).

Please support Open Science and fill the form by Oct 17: forms.gle/WoYRX4govNY1... ๐Ÿš€

16.10.2025 05:48 ๐Ÿ‘ 8 ๐Ÿ” 7 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Post image

You are an Early Career Researcher in #cybersec? Here is an opportunity: The AEC chairs of @USENIXSecurity '26 are looking for (self)nominations for the Artifact Evaluation Committee. Deadline: October 17th, 2025, so sign up soon!
@chwress.bsky.social, @kumarde.bsky.social, @aurore-fass.bsky.social

10.10.2025 10:16 ๐Ÿ‘ 5 ๐Ÿ” 9 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - its-not-easy/tweb25: Repository for the paper "It's not Easy: Applying Supervised Machine Learning to Detect Malicious Extensions in the Chrome Web Store" Repository for the paper "It's not Easy: Applying Supervised Machine Learning to Detect Malicious Extensions in the Chrome Web Store" - its-not-easy/tweb25

Repository: github.com/its-not-easy...
Paper: arxiv.org/pdf/2509.21590

Joint work with Ben Rosenzweig, @rossoalfiere.bsky.social, and Giovanni Apruzzese

07.10.2025 18:59 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

We also provide ground truth (benign or malicious), category, manifest version, date of last update, and ID of each extension. Put simply, you can just (i) grab the dataset, (ii) load it into a pandas dataframe, and (iii) train & test any type of ML-based classifier on it. Enjoy!

07.10.2025 18:58 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Each extension in our dataset is provided as a *feature vector that is ready for ML-based experiments*. For instance, we provide 2.5k features extracted from extensionsโ€™ source code and over 2k features extracted from extensionsโ€™ metadata.

07.10.2025 18:58 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

For the results, look at the paper (spoiler: the browser- extension ecosystem is strongly impacted by concept drift). For those who want to get their hands dirty, we release all our codebase in our GitHub repository.

07.10.2025 18:57 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

In our new TWEB paper, we collected ~100k browser extensions that appeared on the Chrome Web Store in 2012โ€“2023 and used them to develop and test a set of classifiers based on supervised machine learning (ML).

07.10.2025 18:57 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Ever wanted to get into malicious browser-extension research, but couldn't find any dataset to experiment on? We got you covered!

07.10.2025 18:57 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
(Self-)Nomination for the USENIX Security '26 Artifact Evaluation Committee (AEC) For the seventh year, USENIX Security allows the evaluation of artifacts that support a paper: software, hardware, evaluation data and documentation, raw measurement data, raw survey results, mechaniz...

We are still looking for (self) nominations for USENIX Security '26 Artifact Evaluation Committee!
Please help us spread the word ๐Ÿš€

You can *Promote and Support Open Science* by filling out the nomination form by Friday, October 17: forms.gle/sMCJHww2qcUK...

07.10.2025 06:36 ๐Ÿ‘ 3 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

No award in 2025? Here is another chance: @chwress.bsky.social, @kumarde.bsky.social, and I are looking for (self) nominations for @USENIXSecurity '26 Artifact Evaluation Committee!

Remember to fill the nomination form by Friday, Oct 17: forms.gle/sMCJHww2qcUK...

And help us spread the word! ๐Ÿš€

22.09.2025 14:54 ๐Ÿ‘ 1 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image Post image Post image

Congratulations to USENIX Security 2025 AE:
๐Ÿ† Distinguished Artifact Awards
๐Ÿ† Distinguished Reviewer Awards
โญ Noteworthy Reviewer Recognition
๐Ÿฅท Ninja Reviewer Recognition
secartifacts.github.io/usenixsec202...

And thank you all for your help!

CC @pvadrevu.bsky.social Tiago Heinrich

12.09.2025 13:12 ๐Ÿ‘ 7 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1