Hello,

Karthik

I am Karthik Ramakrishnan, a PhD student at Georgia Institute of Technology currently being advised by Prof. Frank Li.

My research focuses on Web security, privacy, and Internet measurement, with current work on the security and privacy implications of LLM agents, including web and computer-use agents, and detecting automated agent interactions.

I am always up for collaborations, so if you want to discuss projects that I have worked on or a potential collaboration, the best way to get in touch with me is by e-mail:

I am looking for research internships for the Summer 2027. If your team is hiring, please reach out to me!

@rkarthik_14
in/Karthik
L3thal14
Karthik R

Bot traffic, internet-wide

29.2% of the world's verified bot traffic now comes from AI crawlers and AI search.

  • AI crawlers 21.2%
  • AI search 7.9%
  • Other bots 70.8%

OperatorsGoogle 27.6% · Meta 15.7% · Anthropic 7.3% · Microsoft 5.7%

Pages crawled per referralPerplexity 2,947 : 1 · Anthropic 560 : 1 · OpenAI 267 : 1

7-day average of Cloudflare's global network, via Cloudflare Radar, 27 September 2026.

Experience

News

Selected Publications

  • Understanding Website Passkey Policies and User Communication. ACM Conference on Computer and Communications Security (CCS) 2026
    Karthik Ramakrishnan, Frank Li

    Passkey, a modern method for passwordless authentication, has transitioned from nascent development to real-world deployment, with support already by various websites. However, passkey deployment is not simply a binary action (deployed versus not deployed). Instead, websites must determine and implement policies on passkey use, including which accounts support passkeys, what forms of passkeys are allowed, how users can manage passkeys, and how passkeys interface with traditional authentication methods. Furthermore, as passkeys are a new and drastically different way of authenticating, websites must also consider how they communicate about passkeys to users, to facilitate their transition to the newly deployed method.
    To date, there has been limited investigation of website passkey deployments in practice, with prior work focused on measuring adoption or testing certain security-specific configurations (e.g., authenticator attestation). In this work, we develop an LLM-driven pipeline that collects and analyzes passkey-related website documentation to 1) measure adoption with a novel method, 2) evaluate broader passkey deployment policies, and 3) characterize website communication about passkeys. We apply this pipeline to the Tranco Top 100K sites, allowing us to identify and assess the real-world passkey deployments of thousands of sites. We find passkey policies that impact its practical security and usability, such as with the fallback authentication methods allowed and how users can manage account passkeys. We also uncover what websites communicate about passkey security, usability, and privacy, including purported metrics quantifying benefits. Altogether, our findings shed light on passkey security and usability in practice, and serve as a case study on the adoption of new security technology.

  • Crawling in the Deep: Evaluating Web Crawling Configurations for Web Privacy Measurements. ACM Internet Measurement Conference (IMC) 2026
    Karthik Ramakrishnan, Qinge Xie, Uma Anand, Frank Li
    paper

    Web privacy measurements fundamentally depend on web crawling techniques. Unlike many other web measurements that can be performed only using the landing page (e.g., TLS assessments, web server security configurations), web privacy evaluations often must explore deep into a website to more comprehensively identify and characterize its privacy behaviors. However, prior studies adopt various crawling configurations and strategies, and to date, we lack a systematic understanding of the impact of different crawling configurations on the privacy behaviors observed.
    In this paper, we address this gap by conducting controlled web crawling experiments across the top 10k CrUX websites, while monitoring privacy-related metrics including HTTP request domains, JavaScript Web APIs accessed, and cookies set. We evaluate 12 different crawling strategies, varying the page search strategy (depth-first, breadth-first, and a hybrid approach), whether browser state is preserved across page visits, and whether user interaction is simulated. We further assess the impact of varying the number of pages crawled per site, as well as the amount of time the crawler waits per page. Our analysis shows how different crawling parameters influence different privacy metrics, ultimately informing recommendations for designing web crawling methods for web privacy measurements.

  • Head(er)s Up! Detecting Security Header Inconsistencies in Browsers. ACM Conference on Computer and Communications Security (CCS) 2025
    Jannis Rautenstrauch, Trung Tin Nguyen, Karthik Ramakrishnan, Ben Stock
    paper

    In the modern Web, security headers are of the utmost importance for websites to provide protection against various attacks, such as Cross-Site Scripting, Clickjacking, and Cross-Site Leaks. As each security header uses a different syntax and has unique processing rules, correctly implementing them is a complex task for both browser and website developers. Inconsistency in browser behavior related to security headers harms websites as their security depends on their users’ browsers. At the same time, compatibility issues may deter developers from deploying such headers in the first place.
    In this work, we performed a differential evaluation of the security header parsing and enforcement behavior in desktop and mobile browsers to uncover problematic browser differences. We systematically ran 177,146 tests covering 16 security-relevant headers multiple times in 16 browser configurations covering over 97% of the browser engine market share. We identified 5,606 (3.16%) tests that behave inconsistently across browsers. Our subsequent analysis revealed 42 root causes, highlighting the prevalence of implementation issues. 31 of these root causes were yet unknown and resulted in 36 bug reports against the affected browsers and specifications. Many of our reports have already resulted in fixes improving web consistency and users’ security. To foster open science and enable browser vendors to continuously test their security header implementations, we open-source our test framework.

  • Evaluating Privacy Policies under Modern Privacy Laws At Scale: An LLM-Based Automated Approach USENIX Security Symposium 2025
    Qinge Xie, Karthik Ramakrishnan, Frank Li
    paper

    Website privacy policies detail an online service’s information practices, including how they handle user data and rights. For many sites, these disclosures are now necessitated by a growing set of privacy regulations, such as GDPR and multiple US state laws, offering visibility into privacy practices that are often not publicly observable. Motivated by this visibility, prior work has explored techniques for automated analysis of privacy policies and characterized specific aspects of realworld policies on a larger scale. However, existing approaches are constrained in the privacy practices they evaluate, as they rely upon rule-based methods or supervised classifiers, and many predate the prominent privacy laws now enacted that drastically shape privacy disclosures. Thus, we lack a comprehensive understanding of modern website privacy practices disclosed through privacy policies.
    In this work, we seek to close this gap by providing a systematic and comprehensive evaluation of website privacy policies at scale. We first systematize the privacy practices discussed by 10 notable privacy regulations currently in effect in the European Union and the US, identifying 34 distinct clauses on privacy practices across 4 overarching themes. We then develop and evaluate an LLM-based approach for assessing these clauses in privacy policies, providing a more accurate, comprehensive, and flexible analysis compared to prior techniques. Finally, we collect privacy policies from over 100K websites, and apply our LLM method to a subset of sites to investigate in-depth the privacy practices of websites today. Ultimately, our work supports broader investigations into web privacy practices moving forward.

  • Whatcha Lookin' At: Investigating Third-Party Web Content in Popular Android Apps. ACM Internet Measurement Conference (IMC) 2024
    Dhruv Kuchhal, Karthik Ramakrishnan, Frank Li
    paper

    Over 65% of web traffic originates from mobile devices. However, much of this traffic is not from mobile web browsers but rather from mobile apps displaying web content. Android’s WebView has been a common way for apps to display web content, but it entails security and privacy concerns, especially for third-party content. Custom Tabs (CTs) are a more recent and recommended alternative. In this paper, we conduct a large-scale empirical study to examine if the top ∼146.5K Android apps use WebViews and CTs in a manner that aligns with user security and privacy considerations. Our measurements reveal that most apps still use WebViews, particularly to display ads, with only ∼20% using CTs. We also find that while some popular SDKs have migrated to CTs, others (e.g., financial services) benefiting from CT’s properties have not yet done so. Through semi-manual analysis of the top 1K apps, we uncover a handful of apps that use WebViews to show arbitrary web content within their app while modifying the web content behavior. Ultimately, our work seeks to improve our understanding of how mobile apps interact with third-party web content and shed light on real-world security and privacy implications.

More on my scholar profile.

Contact

You can also schedule a 1-on-1 meeting with me using the following link.

Last Updated: September 2026 ;   Thanks to Marco Squarcina for the website template.