VLDB 2026 Research / reviewers in the wild / expert
Matthew Bradbury
dblp:119/3574
· DBLP profile ↗
24ranked-venue papers
8as first author
11since 2021 · last 2026
0000-0003-4661-000XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 2 first-author · 2 since 2021Security and privacy · 6 · 1 first-author · 4 since 2021Computer networks · 5 · 4 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Exploring Communication and Collaboration in Distributed AR Escape Rooms: Design Opportunities to Support Social PlayabstractEscape rooms are traditionally in-person activities that foster collaboration. Augmented reality (AR) enables these experiences to extend into distributed (all participants separated) and hybrid settings (both co-located and remote) while retaining embodied, physically grounded play. This study examines how players communicate and collaborate in an AR escape room across different spatial configurations, and how design choices affect situation awareness, engagement, and social connection. We developed an AR application for distributed escape room play and evaluated it with 19 participants in eight groups. Findings show how participants dynamically appropriated multimodal communication channels and leveraged embodied interactions for coordination. However, they also faced challenges with maintaining situation awareness across spaces, balancing enforced collaboration with individual engagement, and ensuring equitable participation, particularly for remote or information-giving players. With these insights, we discuss design implications for creating more engaging and socially connected distributed and hybrid AR experiences through multimodal communication support, flexible embodied interaction, and equitable collaborative mechanisms. Matthew Bradbury, Matthew Collard, Kieran Gara, Sam Gorman, Ethan Kannampuzha, Ye Yuan 0010 |
CHI | 1 |
| 2024 | Enabling Multi-Layer Threat Analysis in Dynamic Cloud EnvironmentsabstractMost Threat Analysis (TA) techniques analyze threats to targeted assets (e.g., components, services) by considering static interconnections among them. However, in dynamic environments, e.g., the Cloud, resources can instantiate, migrate across physical hosts, or decommission to provide rapid resource elasticity to its users. Existing TA techniques are not capable of addressing such requirements. Moreover, complex multi-layer/multi-asset attacks on Cloud systems are increasing, e.g., the Equifax data breach; thus, TA approaches must be able to analyze them. This paper proposes ThreatPro, which supports dynamic interconnections and analysis of multi-layer attacks in the Cloud. ThreatPro facilitates threat analysis by developing a technology-agnostic information flow model, representing the Cloud's functionality through conditional transitions. The model establishes the basis to capture the multi-layer and dynamic interconnections during the life cycle of a Virtual Machine. ThreatPro contributes to (1) enabling the exploration of a threat's behavior and its propagation across the Cloud, and (2) assessing the security of the Cloud by analyzing the impact of multiple threats across various operational layers/assets. Using public information on threats from the National Vulnerability Database, we validate ThreatPro's capabilities, i.e., identify and trace actual Cloud attacks and speculatively postulate alternate potential attack paths. Salman Manzoor, Antonios Gouglidis, Matthew Bradbury, Neeraj Suri |
IEEE Trans. Cloud Comput. | 3 |
| 2024 | Security-Minded Verification of Cooperative Awareness MessagesabstractAutonomous robotic systems systems are both safety- and security-critical, since a breach in system security may impact safety. In such critical systems, formal verification is used to model the system and verify that it obeys specific functional and safety properties. Independently, threat modelling is used to analyse and manage the cyber security threats that such systems may encounter. Both verification and threat analysis serve the purpose of ensuring that the system will be reliable, albeit from differing perspectives. In prior work, we argued that these analyses should be used to inform one another and, in this paper, we extend our previously defined methodology for security-minded verification by incorporating runtime verification. To illustrate our approach, we analyse an algorithm for sending Cooperative Awareness Messages between autonomous vehicles. Our analysis centres on identifying STRIDE security threats. We show how these can be formalised, and subsequently verified, using a combination of formal tools for static aspects, namely Promela/SPIN and Dafny, and generate runtime monitors for dynamic verification. Our approach allows us to focus our verification effort on those security properties that are particularly important and to consider safety and security in tandem, both statically and at runtime. Marie Farrell, Matthew Bradbury, Rafael C. Cardoso 0001, Michael Fisher 0001, Louise A. Dennis, Clare Dixon, Al Tariq Sheik, Hu Yuan 0001, Carsten Maple |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Into the Heat of the Debate: Simulating a Program Committee Within Computer Science EducationabstractThere are many teaching strategies in higher education; one of these is discussion-based teaching which aims to stimulate conversation and peer learning. Although this teaching strategy has many benefits for students, such as learning how to argue, it has not gained much traction in STEM subjects like Computer Science. However, soft skills have become increasingly important within these fields. A focus when recruiting for roles is not only on hard skills such as programming but also on the ability to communicate well with stakeholders. This paper explores and evaluates an approach to incorporate discussion-based teaching within computer science education, focusing on teaching hard and soft skills. To achieve this, we organised an emulated program committee type of activity for MSc students at our university. We evaluated the activity by asking the students to complete a survey and followed this up by interviewing several students to gather more in-depth reactions from the cohort. The results show that students feel they learnt about the topics tackled within the papers we have chosen, gained more confidence to tackle paper writing, understood the requirements of academic work, and improved their soft skills such as academic writing. The interviews show that students thoroughly enjoyed the activity and are keen to have more interactive discussion sessions like this. Sam Maesschalck, Matthew Bradbury, Vasileios Giotsas |
EDUCON | 2 |
| 2022 | Poster: Effectiveness of Moving Target Defense Techniques to Disrupt Attacks in the CloudabstractMoving Target Defense (MTD) can eliminate the asymmetric advantage that attackers have in terms of time to explore a static system by changing a system's configuration dynamically to reduce the efficacy of reconnaissance and increase uncertainty and complexity for attackers. To this extent, a variety of MTDs have been proposed for specific aspects of a system. However, deploying MTDs at different layers/components of the Cloud and assessing their effects on the overall security gains for the entire system is still challenging since the Cloud is a complex system entailing physical and virtual resources, and there exists a multitude of attack surfaces that an attacker can target. Thus, we explore the combination of MTDs, and their deployment at different components (belonging to various operational layers) to maximize the security gains offered by the MTDs.We also propose a quantification mechanism to evaluate the effectiveness of the MTDs against the attacks in the Cloud. Salman Manzoor, Antonios Gouglidis, Matthew Bradbury, Neeraj Suri |
CCS | 3 |
| 2022 | Poster: Multi-Layer Threat Analysis of the CloudabstractA variety of Threat Analysis (TA) techniques exist that typically target exploring threats to discrete assets (e.g., services, data, etc.) and reveal potential attacks pertinent to these assets. Furthermore, these techniques assume that the interconnection among the assets is static. However, in the Cloud, resources can instantiate or migrate across physical hosts at run-time, thus making the Cloud a dynamic environment. Additionally, the number of attacks targeting multiple assets/layers emphasizes the need for threat analysis approaches developed for Cloud environments. Therefore, this proposal presents a novel threat analysis approach that specifically addresses multi-layer attacks. The proposed approach facilitates threat analysis by developing a technology-agnostic information flow model. It contributes to exploring a threat's propagation across the operational stack of the Cloud and, consequently, holistically assessing the security of the Cloud. Salman Manzoor, Antonios Gouglidis, Matthew Bradbury, Neeraj Suri |
CCS | 3 |
| 2022 | SlowCoach: Mutating Code to Simulate Performance BugsabstractPerformance bugs are unnecessarily inefficient code chunks in software codebases that cause prolonged execution times and degraded computational resource utilization. For performance bug diagnostics, tools that aid in the identification of said bugs, such as benchmarks and profilers, are commonly employed. However, due to factors such as insufficient workloads or ineffective benchmarks, software defects related to code inefficiencies are inherently difficult to diagnose. Hence, the capabilities of performance bug diagnostic tools are limited and performance bug instances may be missed. Traditional mutation testing (MT) is a technique for quantifying a test suite's ability to find functional bugs by mutating the code of the test subject. Similarly, we adopt performance mutation testing (PMT) to evaluate performance bug diagnostic tools and identify where improvements need to be made to a performance testing methodology. We carefully investigate the different performance bug fault models and how synthesized performance bugs based on these models can evaluate benchmarks and workload selection to help improve performance diagnostics. In this paper, we present the design of our PMT framework, SLOWCOACH, and evaluate it with over 1600 mutants from 4 real-world software projects. Oliver Schwahn, Roberto Natella, Matthew Bradbury, Neeraj Suri |
ISSRE | 4 |
| 2022 | Information management for trust computation on resource-constrained IoT devicesabstractResource-constrained Internet of Things (IoT) devices are executing increasingly sophisticated applications that may require computational or memory intensive tasks to be executed. Due to their resource constraints, IoT devices may be unable to compute these tasks and will offload them to more powerful resource-rich edge nodes. However, as edge nodes may not necessarily behave as expected, an IoT device needs to be able to select which edge node should execute its tasks. This selection problem can be addressed by using a measure of behavioural trust of the edge nodes delivering a correct response, based on historical information about past interactions with edge nodes that are stored in memory. However, due to their constrained memory capacity, IoT devices will only be able to store a limited amount of trust information, thereby requiring an eviction strategy when its memory is full of which there has been limited investigation in the literature. To address this, we develop the concept of the memory profile of an agent and that profile’s utility. We formalise the profile eviction problem in a unified profile memory model and show it is NP-complete. To circumvent the inherent complexity, we study the performance of eviction algorithms in a partitioned profile memory model using our utility metric. Our results show that localised eviction strategies which only consider one specific type of information do not perform well. Thus we propose a novel eviction strategy that globally considers all types of trust information stored and we show that it outperforms local eviction strategies for the majority of memory sizes and agent behaviours. In this paper, we develop a concept of information utility to a trust model and formalise the problem of information eviction, which we prove to be NP-complete. We then investigate the usefulness of different eviction strategies to maximise the utility of information stored to enable trust-based task offloading. Matthew Bradbury, Arshad Jhumka, Tim Watson |
Future Gener. Comput. Syst. | 1 |
| 2022 | Quantifying Source Location Privacy Routing Performance via Divergence and Information LossabstractSource location Privacy (SLP) is an important property for security critical applications deployed over a wireless sensor network. This property specifies that the location of the source of messages needs to be kept secret from an eavesdropping adversary that is able to move around the network. Most previous work on SLP has focused on developing protocols to enhance the SLP imparted to the network under various attacker models and other conditions. Other works have focused on analysing the level of SLP being imparted by a specific protocol. In this paper, we introduce the notion of a routing matrix which captures when messages arefirstreceived. We then introduce a novel approach where an optimal SLP routing matrix is derived. In this approach, the attacker’s movement is modelled as a Markov chain where measures of conditional entropy and divergence are used to compare routing matrices and quantify if they provide high levels of SLP. We propose the notion of aproperly competing pathsthat causes an attacker todivertwhen moving towards the source. This concept provides the basis for developing aperturbation model, similar to those used in privacy-preserving data mining. We formally prove that properly competing paths are both necessary and sufficient in ensuring the existence of an SLP-aware routing matrix and show their usage in developing an SLP-aware routing matrix. Further, we show how different SLP-aware routing matrices can be obtained through different instantiations of the framework. Those instantiations are obtained based on a notion of information loss achieved through the use of the perturbation model proposed. Matthew Bradbury, Arshad Jhumka |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Threat-modeling-guided Trust-based Task Offloading for Resource-constrained Internet of ThingsabstractThere is an increasing demand for Internet of Things (IoT) networks consisting of resource-constrained devices executing increasingly complex applications. Due to these resource constraints, IoT devices will not be able to execute expensive tasks. One solution is to offload expensive tasks to resource-rich edge nodes, which requires a framework that facilitates the selection of suitable edge nodes to perform task offloading. Therefore, in this article, we present a novel trust-model-driven system architecture , based on behavioral evidence , that is suitable for resource-constrained IoT devices and supports computation offloading. We demonstrate the viability of the proposed architecture with an example deployment of the Beta Reputation System trust model on real hardware to capture node behaviors. The open environment of edge-based IoT networks means that threats against edge nodes can lead to deviation from expected behavior. Hence, we perform a threat modeling to identify such threats. The proposed system architecture includes threat handling mechanisms that provide security properties such as confidentiality, authentication, and non-repudiation of messages in required scenarios and operate within the resource constraints. We evaluate the efficacy of the threat handling mechanisms and identify future work for the standards used. Matthew Bradbury, Arshad Jhumka, Tim Watson, Denys A. Flores, Jonathan Burton, Matthew Butler 0004 |
ACM Trans. Sens. Networks | 1 |
| 2021 | Trust Trackers for Computation Offloading in Edge-Based IoT NetworksabstractWireless Internet of Things (IoT) devices will be deployed to enable applications such as sensing and actuation. These devices are typically resource-constrained and are unable to perform resource-intensive computations. Therefore, these jobs need to be offloaded to resource-rich nodes at the edge of the IoT network for execution. However, the timeliness and correctness of edge nodes may not be trusted (such as during high network load or attack). In this paper, we look at the applicability of trust for successful offloading. Traditionally, trust is computed at the application level, with suitable mechanisms to adjust for factors such as recency. However, these do not work well in IoT networks due to resource constraints. We propose a novel device called Trust Tracker (denoted by Σ) that provides higher-level applications with up-to-date trust information of the resource-rich nodes. We prove impossibility results regarding computation offloading and show that Σ is necessary and sufficient for correct offloading. We show that, Σ cannot be implemented even in a synchronous network and we compute the probability of offloading to a bad node, which we show to be negligible when a majority of nodes are correct. We perform a small-scale deployment to demonstrate our approach. Matthew Bradbury, Arshad Jhumka, Tim Watson |
INFOCOM | 1 |
| 2020 | A Spatial Source Location Privacy-aware Duty Cycle for Internet of Things Sensor NetworksabstractSource Location Privacy (SLP) is an important property for monitoring assets in privacy-critical sensor network and Internet of Things applications. Many SLP-aware routing techniques exist, with most striking a tradeoff between SLP and other key metrics such as energy (due to battery power). Typically, the number of messages sent has been used as a proxy for the energy consumed. Existing work (for SLP against a local attacker) does not consider the impact of sleeping via duty cycling to reduce the energy cost of an SLP-aware routing protocol. Therefore, two main challenges exist: (i) how to achieve a low duty cycle without loss of control messages that configure the SLP protocol and (ii) how to achieve high SLP without requiring a long time spent awake. In this article, we present a novel formalisation of a duty cycling protocol as a transformation process. Using derived transformation rules, we present the first duty cycling protocol for an SLP-aware routing protocol for a local eavesdropping attacker . Simulation results on grids demonstrate a duty cycle of 10%, while only increasing the capture ratio of the source by 3 percentage points, and testbed experiments on FlockLab demonstrate an 80% reduction in the average current draw. Matthew Bradbury, Arshad Jhumka, Carsten Maple |
ACM Trans. Internet Things | 1 |
| 2019 | Using Threat Analysis Techniques to Guide Formal Verification: A Case Study of Cooperative Awareness Messages
Marie Farrell, Matthew Bradbury, Michael Fisher 0001, Louise A. Dennis, Clare Dixon, Hu Yuan 0001, Carsten Maple |
SEFM | 2 |
| 2019 | Throughput Aware Authentication Prioritisation for Vehicular Communication NetworksabstractConnected vehicles will be a prominent feature of future Intelligent Transport Systems. Which means that there will be a very high volume of wireless traffic that vehicles will receive and process. Due to this large quantity of traffic, there will be Quality of Service (QoS) constraints on the system that means messages will need to be prioritised. As vehicles will have a finite buffer to hold messages, the prioritisation scheme must consider network throughput to ensure QoS requirements are met. In our throughput authentication prioritisation technique, a Markov model is used to detect abnormally large data traffic users who are potential attackers performing a Denial of Service (DoS). Our results show that the algorithm can efficiently enhance network throughput. Hu Yuan 0001, Matthew Bradbury, Carsten Maple, Chen Gu |
VTC Fall | 2 |
| 2019 | Phantom walkabouts: A customisable source location privacy aware routing protocol for wireless sensor networksabstractSummary Source location privacy (SLP) is an important property for a large class of security‐critical wireless sensor network (WSN) applications such as monitoring and tracking. In the seminal work on SLP, phantom routing was proposed as a viable approach to address SLP. However, recent work has shown some limitations of phantom routing such as poor data yield and low SLP. In this paper, we propose phantom walkabouts, a novel and more general version of phantom routing, which performs phantom routes of variable lengths. Through extensive simulations, we show that phantom walkabouts provides high SLP level than phantom routing under specific network configuration. Chen Gu, Matthew Bradbury, Arshad Jhumka |
Concurr. Comput. Pract. Exp. | 2 |
| 2018 | Towards optimal source location privacy-aware TDMA schedules in wireless sensor networks
Jack Kirton, Matthew Bradbury, Arshad Jhumka |
Comput. Networks | 2 |
| 2018 | A decision theoretic framework for selecting source location privacy aware routing protocols in wireless sensor networksabstractSource location privacy (SLP) is becoming an important property for a large class of security-critical wireless sensor network applications such as monitoring and tracking. Many routing protocols have been proposed that provide SLP, all of which provide a trade-off between SLP and energy. Experiments have been conducted to gauge the performance of the proposed protocols under different network parameters such as noise levels . As that there exists a plethora of protocols which contain a set of possibly conflicting performance attributes, it is difficult to select the SLP protocol that will provide the best trade-offs across them for a given application with specific requirements. In this paper, we propose a methodology where SLP protocols are first profiled to capture their performance under various protocol configurations. Then, we present a novel decision theoretic procedure for selecting the most appropriate SLP routing algorithm for the application and network under investigation. We show the viability of our approach through different case studies . Chen Gu, Matthew Bradbury, Jack Kirton, Arshad Jhumka |
Future Gener. Comput. Syst. | 2 |
| 2018 | Hybrid online protocols for source location privacy in wireless sensor networksabstractWireless sensor networks (WSNs) will form the building blocks of many novel applications such as asset monitoring. These applications will have to guarantee that the location of the occurrence of specific events is kept private from attackers, in what is called the source location privacy (SLP) problem. Fake sources have been used in numerous techniques, however, the solution’s efficiency is typically achieved by fine-tuning parameters at compile time. This is undesirable as WSN conditions may change. In this paper, we first present an SLP algorithm – Dynamic – that estimates the relevant parameters at runtime and show that it provides a high level of SLP, albeit at the expense of a high number of messages. To address this, we provide a hybrid online algorithm – DynamicSPR – that uses directed random walks for the fake sources allocation strategy to reduce energy usage. We perform simulations of the various protocols we present and our results show that DynamicSPR provides a similar level of SLP as when parameters are optimised at compile-time, with a lower number of messages sent. Matthew Bradbury, Arshad Jhumka, Matthew Leeke |
J. Parallel Distributed Comput. | 1 |
| 2017 | Source Location Privacy-Aware Data Aggregation Scheduling for Wireless Sensor NetworksabstractSource location privacy (SLP) is an important property for the class of asset monitoring problems in wireless sensor networks (WSNs). SLP aims to prevent an attacker from finding a valuable asset when a WSN node is broadcasting information due to the detection of the asset. Most SLP techniques focus at the routing level, with typically high message overhead. The objective of this paper is to investigate the novel problem of developing a TDMA MAC schedule that can provide SLP. We make a number of important contributions: (i) we develop a novel formalisation of a class of eavesdropping attackers and provide novel formalisations of SLP-aware data aggregation schedules (DAS), (ii) we present a decision procedure to verify whether a DAS schedule is SLP-aware, that returns a counterexample if the schedule is not, similar to model checking, and (iii) we develop a 3-stage distributed algorithm that transforms an initial DAS algorithm into a corresponding SLP-aware schedule against a specific class of eavesdroppers. Our simulation results show that the resulting SLP-aware DAS protocol reduces the capture ratio by 50% at the expense of negligable message overhead. Jack Kirton, Matthew Bradbury, Arshad Jhumka |
ICDCS | 2 |
| 2017 | Understanding source location privacy protocols in sensor networks via perturbation of time seriesabstractSource location privacy (SLP) is becoming an important property for a large class of security-critical wireless sensor network applications such as monitoring and tracking. Much of the previous work on SLP has focused on the development of various protocols to enhance the level of SLP imparted to the network, under various attacker models and other conditions. Other work has focused on analysing the level of SLP being imparted by a specific protocol. In this paper, we adopt a different approach where we model the attacker movement as a time series and use information theoretic concepts to infer the properties of a routing protocol that imparts high levels of SLP. We propose the notion of a properly competing path that causes an attacker to “stall” when moving towards the source. This concept provides the basis for developing a perturbation model, similar to those in privacy-preserving data mining. We then show how to use properly competing paths to develop properties of an SLP-aware routing protocol. Further, we show how different SLP-aware routing protocols can be obtained through different instantiations of the framework. Those instantiations are obtained based on a notion of information loss achieved through the use of the perturbation model proposed. Matthew Bradbury, Arshad Jhumka |
INFOCOM | 1 |
| 2015 | Assessing the Performance of Phantom Routing on Source Location Privacy in Wireless Sensor NetworksabstractAs wireless sensor networks (WSNs) have been applied across a spectrum of application domains, the problem of source location privacy (SLP) has emerged as a significant issue, particularly in safety-critical situations. In seminal work on SLP, phantom routing was proposed as an approach to addressing the issue. However, results presented in support of phantom routing have not included considerations for practical network configurations, omitting simulations and analyses with larger network sizes. This paper addresses this shortcoming by conducting an in-depth investigation of phantom routing under various network configurations. The results presented demonstrate that previous work in phantom routing does not generalise well to different network configurations. Specifically, under certain configurations, it is shown that the afforded SLP is reduced by a factor of up to 75. Chen Gu, Matthew Bradbury, Arshad Jhumka, Matthew Leeke |
PRDC | 2 |
| 2015 | Fake source-based source location privacy in wireless sensor networksabstractSummary The development of novel wireless sensor network (WSN) applications, such as asset monitoring, has led to novel reliability requirements. One such property is source location privacy (SLP). The original SLP problem is to protect the location of a source node in a WSN from a singledistributed eavesdropperattacker. Several techniques have been proposed to address the SLP problem, and most of them use some form of traffic analysis and engineering to provide enhanced SLP. The use of fake sources is considered to be promising for providing SLP, and several works have investigated the effectiveness of the fake sources approach under various attacker models. However, very little work has been done to understand the theoretical underpinnings of the fake source technique. In this paper, we (i) provide a novel formalisation of the fake sources selection problem; (ii) prove the fake sources selection problem to be NP‐complete; (iii) provide parametric heuristics for three different network configurations; and (iv) show that these heuristics provide (near) optimal levels of SLP under appropriate parameterisation. Our results show that fake sources can provide a high level of SLP. Our work is the first to investigate the theoretical underpinnings of the fake source technique. Copyright © 2014 John Wiley & Sons, Ltd. Arshad Jhumka, Matthew Bradbury, Matthew Leeke |
Concurr. Comput. Pract. Exp. | 2 |
| 2014 | Efficient fault-tolerant collision-free data aggregation scheduling for wireless sensor networks
Arshad Jhumka, Matthew Bradbury, Sain Saginbekov |
J. Parallel Distributed Comput. | 2 |
| 2012 | Towards Understanding Source Location Privacy in Wireless Sensor Networks through Fake SourcesabstractSource location privacy is becoming an increasingly important property in wireless sensor network applications, such as asset monitoring. The original source location problem is to protect the location of a source in a wireless sensor network from a single distributed eavesdropper attack. Several techniques have been proposed to address the source location problem, where most of these apply some form of traffic analysis and engineering to provide enhanced privacy. One such technique, namely fake sources, has proved to be promising for providing source location privacy. Recent research has concentrated on investigating the efficiency of fake source approaches under various attacker models. In this paper, we (i) provide a novel formalisation of the source location privacy problem, (ii) prove the source location privacy problem to be NP-complete, and (iii) provide a heuristic that yields an optimal level of privacy under appropriate parameterisation. Crucially, the results presented show that fake sources can provide a high, sometimes optimal, level of privacy. Arshad Jhumka, Matthew Bradbury, Matthew Leeke |
TrustCom | 2 |