Skip to main content
Mohamed Moustafa Dawoud

Mohamed Moustafa Dawoud

PhD Student · UC Santa Cruz

I am a PhD student in Computer Science & Engineering at UC Santa Cruz, working with Prof. Ram Sundara Raman. I study the sociotechnical dimensions of AI-enabled privacy risks and abuse, and how they impact people and society. I am particularly interested in how AI facilitates new forms of harm — such as non-consensual deepfakes, synthetic media generation, and the commodification of abuse services — and in how the stakeholders affected by these threats understand, misinterpret, and struggle to keep pace with them: how everyday users form mental models of digital protections, how engineers and practitioners weigh privacy trade-offs under regulatory pressure, and how policymakers interpret ambiguous or conflicting frameworks. I use large-scale internet measurements, qualitative interviews, and controlled experiments to surface these misalignments. I am equally driven by the complementary question: can AI itself be turned into a tool for defense? I explore how the same technology that enables harm can also empower users to recognize and resist threats, help practitioners build safer systems under regulatory uncertainty, and provide policymakers with the empirical grounding they need to act.

News

Aug 2026PrivAudit accepted at ACM CCS 2026: a dual-lens framework for auditing website privacy under the CCPA, pairing LLM analysis of privacy policies with automated measurement of real tracking behavior
Jun 2026Joined the California Privacy Protection Agency as a Research Technologist Intern in the Audits Division
Mar 2026Paper rejected from IMC '26 — back to the drawing board
Mar 2026Completed my Master of Science in Computer Science & Engineering at UC Santa Cruz, en route to the PhD

Work in Progress

The Impact of Age Verification Laws on the Consumption of Pornographic Content in the US

In progress

Alejandro Cuevas, Mohamed Moustafa Dawoud, Zhibin Shen, Ram Sundara Raman, Manoel Horta Ribeiro

We leverage individual-level panel data derived from mobile browsing activity to study the impact of age verification laws on adult content consumption, from both compliant and non-compliant sites, in the US.

Quasi-ExperimentalDifference-in-DifferencesPolicy ImpactAdult Content

Publications

View all
2026

PrivAudit: A Dual-Lens Auditing Framework for Website Privacy Practices under the CCPA

Mohamed Moustafa Dawoud, Riya Aggarwal, Likith Rahul Krishnamurthy, Ram Sundara Raman

ACM CCS 2026To appear

An automated framework that audits website privacy two ways at once: LLM scoring of privacy policies against CCPA provisions, and browser measurement of what cookies actually get written. Across 998 sites, CCPA-subject policies disclose more, but tracking barely moves: 6,392 targeting cookies, 49% of them third-party writes, largely unresponsive to privacy signals.

2026

From Underground to Mainstream Marketplaces: Measuring AI-Enabled NSFW Deepfakes on Fiverr

Mohamed Moustafa Dawoud, Alejandro Cuevas, Ram Sundara Raman

USEC 2026, co-located with NDSS

We investigate whether AI-enabled NSFW services have moved into mainstream gig marketplaces. Through keyword searches, sitemap analysis, and snowball sampling, we identify 593 AI-enabled NSFW gigs on Fiverr: 82.8% expose deepfake-enabling features, 74.9% of sellers joined in 2025, and sellers disproportionately target platforms like OnlyFans and Instagram.

2025

Vendor communication themes in darknet Ransomware-as-a-Service (RaaS) advertisements

Taylor Fisher, Zacharias Pieri, C. Jordan Howell, Roberta O'Malley, Lauren Tremblay, Mohamed Dawoud

Computers in Human Behavior

A thematic analysis of RaaS advertisements on darknet markets. The most common theme was victimization, appearing in 70% of the dataset, revealing the strategic mechanisms vendors employ to attract both novice and experienced cybercriminals through the commodification of ransomware.

2024

DVa: Extracting Victims and Abuse Vectors from Android Accessibility Malware

Haichuan Xu, Mingxuan Yao, Runze Zhang, Mohamed Moustafa Dawoud, Jeman Park, Brendan Saltaformaggio

USENIX Security 2024

We developed DVa, a malware analysis pipeline using dynamic victim-guided execution and symbolic analysis, to uncover accessibility malware's targeted victims and abuse vectors. Deployed on 9,850 a11y malware samples, DVa uncovered 215 unique victims targeted with an average of 13.9 abuse routines.



Let's Collaborate

I welcome research collaborations and enjoy mentoring students finding their path. If something here resonated, I'd love to connect.

Get in touch