Hidden risks in encrypted traffic  

Image 1 of 3
A close-up of a man on stage during his presentation
Three men on stage. One of them is holding a diploma.
Two men at a stand where the winner is explaining to his colleague
As part of the prize, Atmane Ayoub Mansour Bahar was given the opportunity to give a longer presentation on the research behind ‘Towards Closing the Video-Fingerprinting Loophole’, which he carried out together with Rajalakshmi Anantharayanan and Romaric Duvignau. Photo: Cybercampus Sweden

Could an attacker identify which video you are watching without decrypting your traffic? Research by doctoral student Atmane Ayoub Mansour Bahar into defense against passive network attacks won the Best Poster award at CyberSweden 2026. He is now working on a browser extension designed to protect users against this type of monitoring. 

One minute on stage. That was the time given to participants to present their research during the poster pitches at CyberSweden 2026. Following the audience vote, Atmane Ayoub Mansour Bahar, Computer Science and Engineering, was named the winner. 

A fingerprint hidden in the traffic 

The winning poster, Towards Closing the Video-Fingerprinting Loophole, was produced by Atmane Ayoub Mansour Bahar together with Rajalakshmi Anantharayanan and Romaric Duvignau. It addresses a privacy weakness in adaptive video streaming: encryption may conceal the content itself, but not the tell-tale pattern of data it generates. 

Each video produces a distinctive fingerprint based on the size and timing of its network bursts. By comparing this pattern with a pre-built database, an eavesdropper may be able to determine what someone is watching – even when the viewer is using a VPN. 

Traffic patterns can reveal the video 

“It’s about a very large-scale attack that could tell which video you are watching right now just by the sizes of network bursts,” says Atmane Ayoub Mansour Bahar. 

His work also includes a countermeasure. The researchers have implemented a client-side solution intended for deployment as a browser extension. 

“Someone will have it as a plug-in, just toggle it and you will have the mitigation, and then you will be secure when watching videos, knowing that no one will actually know what you are watching at that moment,” he says. 

A comeback after last year’s competition 

For Bahar, the award was also a personal comeback. He entered the same competition at CyberSweden 2025 and came close to winning. 

“I competed last year for the same best poster award at CyberSweden 2025, and I was close, but unfortunately, not enough to win. It had a bit bitter taste back then, and it’s normal when you believe you had high chances to win. So on that day, I made the conviction that I will work hard enough to win the next edition. And that finally happened today!” 

He describes stepping onto the stage to receive the award as a reminder of the value of persistence. 

“The moment of getting on stage to get The Award makes you forget all the sleepless nights; hard work always pays off. This is for me a lesson about the importance of never quitting.” 

He dedicated the achievement to his family and to his colleagues in the Computer and Network Systems division and the Department of Computer Science and Engineering. 

Chalmers is a Cybercampus Sweden partner 

CyberSweden took place in Stockholm on 15–17 September, bringing together researchers, doctoral students and representatives from industry and the public sector. The conference is Cybercampus Sweden’s annual meeting place for research in cybersecurity and cyber defence. 

Chalmers has been one of Cybercampus Sweden’s affiliated partner organisations since November 2025. Other Chalmers participants included Magnus Almgren, Romaric Duvignau and Anas Ait ben M’bark, a new doctoral student in the Cybercampus-linked BASIS project. His research will focus on lightweight, scalable and post-quantum security solutions for large swarms of connected devices. 

Alejandro Russo also contributed to the programme, presenting research on data sharing and privacy in the age of AI. 

 

Coming up: The poster has also been accepted for presentation at the upcoming ACM Conference on Computer and Communications Security (ACM CCS 2026), taking place on 15–19 November in The Hague, the Netherlands. 

Atmane Ayoub Mansour Bahar
  • Doctoral Student, Computer and Network Systems, Computer Science and Engineering
Romaric Duvignau
  • Head of Unit, Computer and Network Systems, Computer Science and Engineering

Skribent

Carina Schultz