VLDB 2026 Research / reviewers in the wild / expert
Scott Buffett
dblp:12/3121
· DBLP profile ↗
22ranked-venue papers
10as first author
6since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 5 first-authorArtificial intelligence and machine learning · 3 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Autonomous Adversary: Red-Teaming in the Age of LLM
Mohammad Saiful Islam Mamun, Mohamed Gaber, Scott Buffett, Sherif Saad |
ACISP (3) | 3 |
| 2025 | Integrating Auxiliary Knowledge into Machine Learning to Improve the Detection of CyberattacksabstractMalicious activities are becoming more complex and difficult to detect, leading to a need for advanced solutions. Machine Learning (ML) presents several success cases across multiple industries and in cybersecurity, ML has demonstrated promising performance in the detection and classification of malicious activities. However, there are still critical limitations that prevent their wide adoption in cybersecurity operations (e.g., lack of interpretability and too many false positives). KnowledgeInfused Learning (KIL) has the potential to address current limitations through different techniques. One possible approach relies on the adoption of Auxiliary Knowledge (AK), which uses domain knowledge to extract and engineer new features present in the raw data and provides additional context that helps the model better understand and differentiate between legitimate and malicious data. The main goal of this research is to propose a method that uses Auxiliary Knowledge (AK) to improve ML performance in detecting cyberattacks. We leveraged relevant domain knowledge to generate features from the raw data that are difficult for an ML model to discover. This approach also reduces the dependence on large amount of training data (big data) that is necessary for better ML predictions. The experiments used the CICIoT2023 dataset and demonstrated that auxiliary knowledge improves the detection performance, paving the way for future integration of automated knowledge management approaches. Shahrear Iqbal, Sourena Khanzadeh, Euclides Carlos Pinto Neto, Scott Buffett, Madeena Sultana, Adrian Taylor |
ISNCC | 4 |
| 2025 | Cyber Threat Mitigation with Knowledge-Infused Reinforcement Learning and LLM-Guided PoliciesabstractAs cyber threats continue to evolve, there is a need for autonomous cyber defense (ACD) strategies capable of fast and context-aware responses. Reinforcement learning (RL) has shown promise for automating cyber defense by exploring and learning effective countermeasures, yet it often struggles with sparse reward signals and insufficient context to handle diverse attack scenarios. Furthermore, the convergence time taken by an RL agent is often high, which makes it difficult to train the RL agent in online settings. To address these challenges, we propose a large language model (LLM)-enhanced RL method that builds and queries a knowledge graph (KG) derived from agent-environment interactions. We leverage the pre-trained knowledge of an LLM on different cybersecurity frameworks and use the LLM to analyze a part of the KG to generate appropriate actions for the RL agent. We infuse the knowledge extracted from the LLM into the RL agent’s training loop in two ways. First, the state vector of the RL agent is augmented with the most effective action and its corresponding reward, as determined from the KG. Second, the suggested action from the LLM is used as a reference policy. In addition, we introduce a regularization term in the loss function to make the RL policy close to the reference policy. To validate our approach, we develop a custom RL environment guided by the MITRE ATT&CK framework, enabling the agent to generate tailored mitigation strategies for detected cyber attacks. Experimental results show that our proposed approach significantly outperforms the baseline RL by over $75 \%$ in terms of taking better mitigation actions. Md. Shamim Towhid, Shahrear Iqbal, Euclides Carlos Pinto Neto, Nashid Shahriar, Scott Buffett, Madeena Sultana, Adrian Taylor |
PST | 5 |
| 2025 | G-STAR: A Threat Modeling Framework for General-Purpose AI SystemsabstractThis research presents the preliminary findings of an ongoing project focused on the security of General-Purpose AI (GPAI) applications. We introduce three key contributions: (i) a taxonomy of GPAI-specific vulnerabilities, offering a structured classification of security risks unique to GPAI models and applications; (ii) a generalized GPAI application architecture, serving as a meta-model for analyzing a wide range of real-world use cases; and (iii) G-STAR, a novel threat modeling reference framework that identifies key entities and their interrelationships in GPAI ecosystems, and provides a structured methodology for assessing and mitigating potential threats. Our study addresses both data and model vulnerabilities inherent in GPAI systems, highlighting critical security challenges. While the research is still in its early stages, the initial results provide a valuable foundation for continued investigation. Future work will focus on enhancing the generalized architecture, exploring mitigation strategies in depth, and applying and refining the G-STAR framework in real-world GPAI scenarios. This work aims to support AI security practitioners in promoting secure development and deployment of GPAI systems across diverse domains. Pulei Xiong, Saeedeh Lohrasbi, Prini Kotian, Scott Buffett |
PST | 4 |
| 2022 | TapTree: Process-Tree Based Host Behavior Modeling and Threat Detection Framework via Sequential Pattern Mining
Mohammad Saiful Islam Mamun, Scott Buffett |
ICICS | 2 |
| 2022 | Towards a robust and trustworthy machine learning system development: An engineering perspective
Pulei Xiong, Scott Buffett, Shahrear Iqbal, Philippe Lamontagne 0001, Mohammad Saiful Islam Mamun, Heather Molyneaux |
J. Inf. Secur. Appl. | 2 |
| 2018 | Candidate List Maintenance in High Utility Sequential Pattern MiningabstractHigh utility sequential pattern mining (HUSPM) lends the aspect of item value or importance to sequential pattern mining by identifying patterns that comprise a significant level of utility in a database. This paper addresses the challenge of establishing upper bounds on future candidate pattern utilities in an effort to reduce the search space required to identify the full set of patterns, and proposes a new approach where a list of possible candidate concatenation items is maintained. This list specifies the only items that ever need to be considered as possible candidates for concatenation with a sequential pattern being considered, or any future sequential pattern appearing as a descendant in the search tree. As a result of the elimination of items that are known to have no possibility of appearing in future high utility sequential patterns, an approach is presented that exploits this knowledge and computes a significantly tighter upper bound on the utilities of the such patterns. Tests on a variety of publicly available datasets show a dramatic reduction in the number of candidates considered, and the time taken to identify the full set of high utility sequential patterns is significantly reduced accordingly. Scott Buffett |
IEEE BigData | 1 |
| 2016 | Analysing and Refining Pilot Training
Bruno Emond, Scott Buffett, Cyril Goutte, Jaff Guo |
EDM | 2 |
| 2015 | Analyzing Student Inquiry Data Using Process Discovery and Sequence Classification
Bruno Emond, Scott Buffett |
EDM | 2 |
| 2012 | Simulating social commerce applied to buyer group pricing, recommendation incentives, and bundlingabstractCurrently social networks are used by buyers to become more aware of sellers and their goods. Increasingly, they are used with three other market mechanisms: Buyers use social networks to form buyer groups that leverage purchasing power. Sellers incentivize buyers to post recommendations on social media. Sellers or buyers compose compatible items into bundles with increased value and reduced price. In this paper we study the potential effects of social networks on these mechanisms. For comprehensive and consistent coverage, we simulate combinations of these mechanisms, using published metrics for authenticity. Our results show seller profitability increases with the use of social networks applied to all possible combinations. Bruce Spencer, Scott Buffett |
ICEC | 2 |
| 2010 | Using classification methods to label tasks in process miningabstractAbstract We investigate a method designed to improve the accuracy of process mining in scenarios where the identification of task labels for log events is uncertain. Such situations are prevalent in business processes where events consist of communications between people, such as email messages. We examine how the accuracy of an independent task identifier, such as a classification or clustering engine, can be improved by examining the currently mined process model. First, a classification scheme based on identifying the keywords in each message is presented to provide an initial labeling. We then demonstrate how these labels can be refined by considering the likelihood that the event represents a particular task as obtained via an analysis of the current representation of the process model. This process is then repeated a number of times until the model is sufficiently refined. Results show that both keyword classification and the current process model analysis can be significantly effective on their own, and when combined have the potential to correct virtually all errors when noise is low (less than 20%), and can reduce the error rate by about 85% when noise is in the 30–40% range. Copyright © 2010 Crown in the right of Canada. Scott Buffett, Liqiang Geng |
J. Softw. Maintenance Res. Pract. | 1 |
| 2009 | Discovering Structured Event Logs from Unstructured Audit Trails for Workflow Mining
Liqiang Geng, Scott Buffett, Bruce Hamilton, Xin Wang 0004, Larry Korba, Yunli Wang |
ISMIS | 2 |
| 2008 | Private Data Discovery for Privacy Compliance in Collaborative Environments
Larry Korba, Yunli Wang, Liqiang Geng, Ronggong Song, George Yee, Andrew S. Patrick, Scott Buffett, Yonghua You |
CDVE | 7 |
| 2007 | Private Data Management in Collaborative Environments
Larry Korba, Ronggong Song, George Yee, Andrew S. Patrick, Scott Buffett, Yunli Wang, Liqiang Geng |
CDVE | 5 |
| 2006 | Detecting opponent concessions in multi-issue automated negotiationabstractAn agent engaged in multi-issue automated negotiation can benefit greatly from learning about its opponent's preferences. Knowledge of the opponent's preferences can help the agent not only to find mutually acceptable agreements more quickly, but also to negotiate deals that are better for the agent in question. In this paper, we describe a new technique for learning about an opponent's preferences by observing its history of offers in a negotiation. Patterns in the similarity between the opponent's offers and our own agent's offers are used to determine the likelihood that the opponent is making a concession at each stage in the negotiation. These probabilities of concession are then used to determine the opponent's most likely preference relation over all offers. Experimental results show that our technique significantly outperforms a previous method that assumes that a negotiation agent will always make concessions during the course of a negotiation. Scott Buffett, Luc Comeau, Bruce Spencer, Michael W. Fleming |
ICEC | 1 |
| 2006 | Towards a model for risk and consent management of personal health informationabstractNo abstract available. Scott Buffett, T. A. Kosa |
PST | 1 |
| 2005 | Learning opponents' preferences in multi-object automated negotiationabstractWe present a classification method for learning an opponent's preferences during a bilateral multi-issue negotiation. Similar candidate preference relations are grouped into classes, and a Bayesian technique is used to determine, for each class, the likelihood that the opponent's true preference relation over the set of offers lies in that class. Evidence used for classification decision-making is obtained by observing the opponents' sequence of offers, and applying the concession assumption, which states that negotiators usually decrease their offer utilities as time passes in order to find a deal. Simple experiments show that the technique can find the correct class after very few offers and can select a preference relation that is likely to match closely with the opponent's true preferences. Scott Buffett, Bruce Spencer |
ICEC | 1 |
| 2005 | MONOLOGUE: A Tool for Negotiating Exchanges of Private Information in E-Commerce
Scott Buffett, Luc Comeau, Michael W. Fleming, Bruce Spencer |
PST | 1 |
| 2004 | Considering expected utility of future bidding options in bundle purchasing with multiple auctionsabstractThis paper presents an algorithm for decision-making in multiple open ascending-price (English) auctions where the buyer needs to procure a complete bundle of complementary products. When making bidding decisions, the utility of each choice is determined by considering the buyer's expected utility of future consequential decisions. The problem is modeled as a Markov decision process (MDP), and the value iteration method of dynamic programming is used to determine the value of bidding/not bidding in each state. To ease the computational burden, three state-reducing techniques are employed. When tested against adaptations of two methods from the literature, results show that the algorithm works significantly better when sufficient information on the progress of other concurrently running auctions will be available when future bidding decisions are made. Scott Buffett |
ICEC | 1 |
| 2004 | Determining Internet Users' Values for Private Information
Scott Buffett, Nathan Scott, Bruce Spencer, Michael W. Fleming |
PST | 1 |
| 2004 | Negotiating Exchanges of P3p-Labeled Information for CompensationabstractWe consider private information a commodity, of value to both the information holder and the information seeker. Hence, a customer can be enticed to trade his/her private information with a business in exchange for compensation. In this article, we propose to apply utility theory to allow each participant to express the value they place on each private datum and, separately, on combinations of data. The PrivacyPact protocol transmits messages that comprise possible exchanges. Each participant is prevented from making offers that necessarily have lower utility for the other partner than previous ones. The protocol is complete in that if an exchange exists that is acceptable to both, it will be found as long as neither partner exits the negotiation early. While the space of possible offers grows exponentially on the number of negotiable items, experimentation with simple strategies indicates that negotiations can converge relatively quickly. Scott Buffett, Keping Jia, Sandy Liu, Bruce Spencer |
Comput. Intell. | 1 |
| 2003 | Efficient Monte Carlo decision tree solution in dynamic purchasing environmentsabstractThis paper considers the problem of making decisions in a dynamic environment where one of possibly many bundles of items must be purchased and quotes for items open and close over time. Probability measures on item prices are used when exact prices are not yet known. We show that expected utility estimation can be improved by considering how future information can affect the purchasing agent's behaviour. An efficient Monte Carlo simulation method is presented that determines the expected utility of an option in our decision tree, referred to as a QR-tree, where the number of simulations needed is linear in the size of the tree. In our experiments simulating a purchase agent in a specific market, the expected utility was estimated more than 50 times more accurately than a greedy method that always pursues the bundle with the current highest expected utility. Scott Buffett, Bruce Spencer |
ICEC | 1 |