Skip to main content

About

PhD student in Computer Science at UC Santa Cruz, studying how people experience security, privacy, and AI — through internet measurements, experiments, and interviews.

Mohamed Moustafa Dawoud

I am a PhD student in Computer Science & Engineering at the University of California, Santa Cruz, where I am fortunate to be advised by Prof. Ramakrishnan (Ram) Sundara Raman. At my core, I am an empiricist with a mission: the Internet threat landscape is evolving faster than ever in the age of AI, and protecting users now requires treating security and privacy as deeply socio-technical problems.

Engineering 2 (E2), Room E2-311
1156 High Street, Santa Cruz, CA 95064

Research

I believe that the future of technology cannot be designed in isolation — it must be grounded in evidence of how it is used, misused, and experienced by real people. Technical defenses alone are insufficient. We must understand how AI is deployed, interpreted, and misused across the systems and institutions that shape everyday digital life. My research focuses on human-centered security and privacy, examining how technology, policy, and lived human experience intersect to shape — and too often undermine — trust, freedom, and dignity. I am especially interested in how different stakeholders form their mental models of security and privacy: how everyday users understand digital protections, how engineers and practitioners weigh trade-offs under pressure, and how policymakers interpret ambiguous or conflicting regulations. By studying these perspectives through large-scale internet measurements, experiments, surveys, and interviews, I aim to uncover where misunderstandings, misalignments, and compliance failures emerge — and to design interventions that close these gaps.

My work aims to illuminate these dynamics through empirical, human-centered investigation. In collaboration with Stanford, I study how AI privacy and governance frameworks function in practice — how engineers interpret ambiguous regulations, how organizations deploy generative models under pressure, and where governance intentions diverge from implementation realities. With Princeton CITP, I measure how deepfake production, synthetic identities, and other AI-enabled abuse offerings propagate on freelance marketplaces, providing some of the first empirical insight into how AI-enabled harm is packaged and sold at Internet scale. A third line of work uses a dual-lens audit combining LLM-based privacy-policy evaluation with automated cookie-tracking measurements to examine how the CCPA reshapes transparency and tracking behavior across websites.

At the same time, I am equally interested in how AI can be harnessed for good. Beyond analyzing threats like deepfakes and disinformation, I explore how large language models (LLMs) can be leveraged to support stakeholders across the ecosystem — helping users make sense of risks, assisting experts with decision-making, and giving policymakers clearer evidence for action. My long-term goal is not incremental fixes but evidence-based redesigns that bridge the gap between users, practitioners, and policymakers — reimagining technology and policy as forces that empower people and strengthen democratic values.

The published work is on the publications page.

Where I Come From

I proudly come from Zefta, Egypt, a city that once declared itself the Zefta Republic during the 1919 revolution, a bold act of defiance that continues to inspire me with its legacy of resilience and independence. That spirit shaped my own journey: as a high school student I ranked 18th out of more than 600,000 students nationwide in Egypt’s Thanawya Amma mathematics exam, which earned me a full merit scholarship to study Computer Science (Information Security) at the German International University in Cairo.

While still in Egypt, I worked remotely with Prof. C. Jordan Howell on cybercrime and underground economies, resulting in a publication in Computers in Human Behavior. My path then brought me to the United States as a research intern at Georgia Tech, where I worked under Prof. Brendan D. Saltaformaggio on systems security and contributed to research at USENIX Security. I continued to MBZUAI in Abu Dhabi researching deepfakes and responsible AI, then to Dartmouth College as a Graduate Teaching Assistant, where I helped redesign a Security & Privacy course to embrace AI tools while encouraging deeper reflection. I also represented Dartmouth at the AAAS CASE Workshop in Washington, D.C., engaging with policymakers on science and technology policy.

Community

My commitment to community-building is central to my identity as a researcher. I co-founded Egyptians in CS Research, a directory of 262 Egyptian computer science researchers across 16 tracks worldwide. I also run an annual mentorship program supporting prospective PhD applicants, particularly from underrepresented regions — providing guidance on research statements, program selection, and application strategy.

More on this on the service & outreach page.

Beyond Research

When I’m not buried in research, you’ll probably catch me at the gym, walking along the California coast, wandering through redwood forests, or chasing down the next great coffee shop.

I tell myself these moments are breaks from research, but truthfully, even while sipping coffee or hiking a trail, my mind drifts back to the same question: how can I leave the world better than I found it?

Sometimes that means pushing my research forward, sometimes it means dreaming about building impactful startups, and sometimes it simply means working hard to be kind and present with the people around me.

Best way to reach me is mdawoud@ucsc.edu.