Apostolis Zarras

dblp:121/4930 · also Apostolos Zarras · DBLP profile ↗
← Back
31ranked-venue papers
7as first author
10since 2021 · last 2026
0000-0002-8480-6989ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 6 first-author · 3 since 2021Artificial intelligence and machine learning · 5 · 4 since 2021Computer networks · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Adaptive DeSeTra: Adaptive deformable-span self-attention transformer for LLM security
abstract
Large Language Models (LLMs) remain vulnerable to prompt-based attacks such as jailbreaks and prompt injection, highlighting the need for security mechanisms that not only detect malicious intent but also determine whether an attack actually succeeds. In this paper, we introduce Adaptive DeSeTra, a novel security-centric Transformer model designed for deployment that mirrors the real-world attack pipeline through two layers: intent detection via multi-class prompt classification into Benign , Jailbreak and Prompt Injection ; and impact assessment via response-level classification into Compliant or Refusal . Prompt-level intent identification enables low-latency routing to appropriate guardrails, policies, and monitoring controls before a malicious prompt reaches the target Large Language Model (LLM). Conversely, response-level evaluation quantifies whether the adversarial attempt resulted in compliance or refusal, providing an outcome-based measure of attack effectiveness that supports risk assessment and enables more informative security benchmarking than intent detection alone. Experiments demonstrate strong performance across both layers: 99.35% Accuracy/F1/Precision/Recall with 99.85% AUC for prompt classification, and 99.80% for the same metrics with 99.98% AUC for impact assessment, positioning Adaptive DeSeTra as a strong candidate for deployment-oriented LLM security monitoring and evaluation.
Konstantinos Giapantzis, Panagiotis Bountakas, Apostolis Zarras, Aristeidis Farao, Vaios Bolgouras, Christos Xenakis
Inf. Sci.3
2025 Game on: a performance comparison of interpolation techniques applied to Shamir's secret sharing
abstract
Abstract Public-key encryption is typically managed through a public key infrastructure. However, it relies on a central control point, the certification authority, which acts as a single point of failure. Recent technological advancements have led to the need for decentralized cryptographic protocols. This paper presents a comprehensive study on enhancing public-key encryption via threshold cryptography and multiparty computation to ensure robust security in decentralized systems. The focus lies in exploring various polynomial interpolation techniques within Shamir’s secret sharing scheme, particularly addressing the efficiency and practicality of Newton interpolation, fast Fourier transformation (FFT), and advanced versions of Lagrange’s method. Utilizing SageMath for a dedicated testing environment, the research investigates the swiftest interpolation methods for secret recovery, introducing new shares into the system, and evaluating the impact of optimizations on performance. The findings highlight FFT as the most effective interpolation method in speed and efficiency, albeit with limitations on the number of shares that can be processed. This paper critically evaluates these interpolation techniques against practical constraints and aims to answer pivotal research questions regarding the optimal approach for large-scale scenarios, challenging existing notions on the efficiency of Newton’s method and providing experimental evidence to support the superiority of FFT in specific contexts.
Anastassis Voudouris, Aristomenis Tressos, Apostolis Zarras, Christos Xenakis
Comput. J.3
2025 CRASHED: Cyber risk assessment for smart home electronic devices
abstract
The rapid proliferation of Internet of Things (IoT) technology has enriched modern households with smart home devices , enhancing convenience, but simultaneously increasing vulnerability to cyber threats. This paper introduces CRASHED , an innovative cyber risk assessment methodology specifically designed for smart home ecosystems. Compared to existing approaches, CRASHED integrates the MITRE ATT&CK and CAPEC frameworks to systematically identify and analyze threats, vulnerabilities, and potential impacts. By employing device-specific profiling, quantitative metrics, and sophisticated weighting mechanisms, it delivers a multilayered assessment of cyber risks that accounts for asset criticality and threat severity, distinguishing it from conventional methods lacking such granularity . The novelty of CRASHED lies in its comprehensive evaluation of systemic vulnerabilities and domestic repercussions. Case studies on various smart home configurations demonstrate its effectiveness in modeling, analyzing, and mitigating risks compared to existing frameworks. This work represents a significant advancement in safeguarding smart home environments, underscoring the urgent need for specialized cyber risk assessment models in our interconnected era. The proposed methodology not only enhances threat detection and response, but also addresses critical gaps in vulnerability databases and risk calculation processes, offering a transformative solution to the evolving challenges of smart home cybersecurity.
Georgios Paparis, Apostolis Zarras, Aristeidis Farao, Christos Xenakis
J. Inf. Secur. Appl.2
2023 Label-Efficient and Robust Learning from Multiple Experts
abstract
Learning from multiple sources of labeled data presents unique challenges, including the cost of using many annotators in the training, test, and production time and their limited reliability. In this paper, we analyze the problem of label-efficient learning and propose a method for training a classification system from data labeled by multiple annotators, where only a small subset of them is chosen adaptively to reduce later communication effort and the effect of malicious annotators, especially in the validation and test phase. We define an iterative optimization procedure where the annotation weight vector’s sparsity is enforced while reducing the overall classification error. Using real-world data, we show that our approach can pertain to the classification performance on the complete set of annotators while reducing the need for annotator labels by over 50% on several different tasks. Furthermore, we demonstrate that label sparsity reduces label flip attacks’ effect on performance.
Bojan Kolosnjaji, Apostolis Zarras
ICASSP2
2023 Vacant holes for unsupervised detection of the outliers in compact latent representation
abstract
Detection of the outliers is pivotal for any machine learning model deployed and operated in real-world. It is essential for the Deep Neural Networks that were shown to be overconfident with such inputs. Moreover, even deep generative models that allow estimation of the probability density of the input fail in achieving this task. In this work, we concentrate on the specific type of these models: Variational Autoencoders (VAEs). First, we unveil a significant theoretical flaw in the assumption of the classical VAE model. Second, we enforce an accommodating topological property to the image of the deep neural mapping to the latent space: compactness to alleviate the flaw and obtain the means to provably bound the image within the determined limits by squeezing both inliers and outliers together. We enforce compactness using two approaches: $(i)$ Alexandroff extension and $(ii)$ fixed Lipschitz continuity constant on the mapping of the encoder of the VAEs. Finally and most importantly, we discover that the anomalous inputs predominantly tend to land on the vacant latent holes within the compact space, enabling their successful identification. For that reason, we introduce a specifically devised score for hole detection and evaluate the solution against several baseline benchmarks achieving promising results.
Misha Glazunov, Apostolis Zarras
UAI2
2022 Upside Down: Exploring the Ecosystem of Dark Web Data Markets
Bogdan Covrig, Enrique Barrueco Mikelarena, Constanta Rosca, Catalina Goanta, Gerasimos Spanakis, Apostolis Zarras
SEC6
2022 Do Bayesian variational autoencoders know what they don't know?
abstract
The problem of detecting the Out-of-Distribution (OoD) inputs is of paramount importance for Deep Neural Networks. It has been previously shown that even Deep Generative Models that allow estimating the density of the inputs may not be reliable and often tend to make over-confident predictions for OoDs, assigning to them a higher density than to the in-distribution data. This over-confidence in a single model can be potentially mitigated with Bayesian inference over the model parameters that take into account epistemic uncertainty. This paper investigates three approaches to Bayesian inference: stochastic gradient Markov chain Monte Carlo, Bayes by Backpropagation, and Stochastic Weight Averaging-Gaussian. The inference is implemented over the weights of the deep neural networks that parameterize the likelihood of the Variational Autoencoder. We empirically evaluate the approaches against several benchmarks that are often used for OoD detection: estimation of the marginal likelihood utilizing sampled model ensemble, typicality test, disagreement score, and Watanabe-Akaike Information Criterion. Finally, we introduce two simple scores that demonstrate the state-of-the-art performance.
Misha Glazunov, Apostolis Zarras
UAI2
2021 Falcon: Malware Detection and Categorization with Network Traffic Images
Peng Xu 0057, Claudia Eckert 0001, Apostolis Zarras
ICANN (1)3
2021 HawkEye: Cross-Platform Malware Detection with Representation Learning on Graphs
Peng Xu 0057, Youyi Zhang, Claudia Eckert 0001, Apostolis Zarras
ICANN (3)4
2021 Hybroid: Toward Android Malware Detection and Categorization with Program Code and Network Traffic
Mohammad Reza Norouzian, Peng Xu 0057, Claudia Eckert 0001, Apostolis Zarras
ISC4
2019 Can Today's Machine Learning Pass Image-Based Turing Tests?
Apostolis Zarras, Ilias Gerostathopoulos, Daniel Méndez 0001
ISC1
2018 Hiding in the Shadows: Empowering ARM for Stealthy Virtual Machine Introspection
abstract
ARM has become the leading processor architecture for mobile and IoT devices, while it has recently started claiming a bigger slice of the server market pie as well. As such, it will not be long before malware more regularly target the ARM architecture. Therefore, the stealthy operation of Virtual Machine Introspection (VMI) is an obligation to successfully analyze and proactively mitigate this growing threat. Stealthy VMI has proven itself perfectly suitable for malware analysis on Intel's architecture, yet, it often lacks the foundation required to be equally effective on ARM.
Sergej Proskurin, Tamas K. Lengyel, Marius Momeu, Claudia Eckert 0001, Apostolis Zarras
ACSAC5
2018 Learning on a Budget for User Authentication on Mobile Devices
abstract
Since the amount of sensitive information stored on smart-phones expands with the growth of their popularity, the need for reliable and usable authentication on these devices increases. Constant reauthentication requests of standard methods, such as PINs, passwords, and swipe patterns, annoy many users who prefer to sacrifice the security of their mobile devices for the quest for maximum usability. An alternative to this approach is sensor-based authentication, where we fingerprint the user interaction by processing signals from sensors such as touchscreen or accelerometer. In this paper, we construct a budgeted online version of One-Class Support Vector Machine (OC-SVM) to maintain authentication performance while limiting the model size and evaluate the performance compared to an unconstrained model. The results of our experiments reveal that it is possible to correctly detect invalid smartphone users in a constrained environment using our budgeted learning methodology.
Bojan Kolosnjaji, Antonia Hufner, Claudia Eckert 0001, Apostolis Zarras
ICASSP4
2018 Smashing the Stack Protector for Fun and Profit
Bruno Bierbaumer, Julian Kirsch, Thomas Kittel 0001, Aurélien Francillon, Apostolis Zarras
SEC5
2018 Follow the WhiteRabbit: Towards Consolidation of On-the-Fly Virtualization and Virtual Machine Introspection
Sergej Proskurin, Julian Kirsch, Apostolis Zarras
SEC3
2017 Finding the Needle: A Study of the PE32 Rich Header and Respective Malware Triage
George D. Webster, Bojan Kolosnjaji, Christian von Pentz, Julian Kirsch, Zachary D. Hanif, Apostolis Zarras, Claudia Eckert 0001
DIMVA6
2017 Empowering convolutional networks for malware classification and analysis
abstract
Performing large-scale malware classification is increasingly becoming a critical step in malware analytics as the number and variety of malware samples is rapidly growing. Statistical machine learning constitutes an appealing method to cope with this increase as it can use mathematical tools to extract information out of large-scale datasets and produce interpretable models. This has motivated a surge of scientific work in developing machine learning methods for detection and classification of malicious executables. However, an optimal method for extracting the most informative features for different malware families, with the final goal of malware classification, is yet to be found. Fortunately, neural networks have evolved to the state that they can surpass the limitations of other methods in terms of hierarchical feature extraction. Consequently, neural networks can now offer superior classification accuracy in many domains such as computer vision and natural language processing. In this paper, we transfer the performance improvements achieved in the area of neural networks to model the execution sequences of disassembled malicious binaries. We implement a neural network that consists of convolutional and feedforward neural constructs. This architecture embodies a hierarchical feature extraction approach that combines convolution of n-grams of instructions with plain vectorization of features derived from the headers of the Portable Executable (PE) files. Our evaluation results demonstrate that our approach outperforms baseline methods, such as simple Feedforward Neural Networks and Support Vector Machines, as we achieve 93% on precision and recall, even in case of obfuscations in the data.
Bojan Kolosnjaji, Ghadir Eraisha, George D. Webster, Apostolis Zarras, Claudia Eckert 0001
IJCNN4
2017 Hiding Behind the Shoulders of Giants: Abusing Crawlers for Indirect Web Attacks
abstract
It could be argued that without search engines, the web would have never grown to the size that it has today. To achieve maximum coverage and provide relevant results, search engines employ large armies of autonomous crawlers that continuously scour the web, following links, indexing content, and collecting features that are then used to calculate the ranking of each page. In this paper, we describe how autonomous crawlers can be abused by attackers to exploit vulnerabilities on thirdparty websites while hiding the true origin of the attacks. Moreover, we show how certain vulnerabilities on websites that are currently deemed unimportant, can be abused in a way that would allow an attacker to arbitrarily boost the rankings of malicious websites in the search results of popular search engines. Motivated by the potentials of these vulnerabilities, we propose a series of preventive and defensive countermeasures that website owners and search engines can adopt to minimize, or altogether eliminate, the effects of crawler-abusing attacks.
Apostolis Zarras, Federico Maggi 0001
PST1
2017 Towards Automated Classification of Firmware Images and Identification of Embedded Devices
Andrei Costin, Apostolis Zarras, Aurélien Francillon
SEC2
2017 Combating Control Flow Linearization
Julian Kirsch, Clemens Jonischkeit, Thomas Kittel 0001, Apostolis Zarras, Claudia Eckert 0001
SEC4
2016 Automated Dynamic Firmware Analysis at Scale: A Case Study on Embedded Web Interfaces
abstract
Embedded devices are becoming more widespread, interconnected, and web-enabled than ever. However, recent studies showed that embedded devices are far from being secure. Moreover, many embedded systems rely on web interfaces for user interaction or administration. Web security is still difficult and therefore the web interfaces of embedded systems represent a considerable attack surface.
Andrei Costin, Apostolis Zarras, Aurélien Francillon
AsiaCCS2
2016 Neuralyzer: Flexible Expiration Times for the Revocation of Online Data
abstract
Once data is released to the Internet, there is little hope to successfully delete it, as it may have been duplicated, reposted, and archived in multiple places. This poses a significant threat to users' privacy and their right to permanently erase their very own data. One approach to control the implications on privacy is to assign a lifetime value to the published data and ensure that the data is no longer accessible after this point in time. However, such an approach suffers from the inability to successfully predict the right time when the data should vanish. Consequently, the author of the data can only estimate the correct time, which unfortunately can cause the premature or belated deletion of data.
Apostolis Zarras, Katharina Kohls, Markus Dürmuth, Christina Pöpper
CODASPY1
2016 Adaptive Semantics-Aware Malware Classification
Bojan Kolosnjaji, Apostolis Zarras, Tamas K. Lengyel, George D. Webster, Claudia Eckert 0001
DIMVA2
2016 SKALD: A Scalable Architecture for Feature Extraction, Multi-user Analysis, and Real-Time Information Sharing
George D. Webster, Zachary D. Hanif, Andre L. P. Ludwig, Tamas K. Lengyel, Apostolis Zarras, Claudia Eckert 0001
ISC5
2016 Leveraging Internet Services to Evade Censorship
Apostolis Zarras
ISC1
2015 Revealing the relationship network behind link spam
abstract
Accessing the large volume of information that is available on the Web is more important than ever before. Search engines are the primary means to help users find the content they need. To suggest the most closely related and the most popular Web pages for a user's query, search engines assign a ranking to each Web page, which typically increases with the number and ranking of other Web sites that link to this page. However, link spammers have developed several techniques to exploit this algorithm and improve the ranking of their Web pages. These techniques are commonly based on underground forums for collaborative link exchange; building a relationship network among spammers to favor their Web pages in search engine results. In this study, we provide a systematic analysis of the spam link exchange performed through 15 Search Engine Optimization (SEO) forums. We design a system, which is able to capture the activity of link spammers in SEO forums, identify spam link exchange, and visualize the link spam ecosystem. The outcomes of this study shed light on a different aspect of link spamming that is the collaboration among spammers.
Apostolis Zarras, Antonis Papadogiannakis, Sotiris Ioannidis, Thorsten Holz
PST1
2014 The Dark Alleys of Madison Avenue: Understanding Malicious Advertisements
abstract
Online advertising drives the economy of the World Wide Web. Modern websites of any size and popularity include advertisements to monetize visits from their users. To this end, they assign an area of their web page to an advertising company (so called ad exchange) that will use it to display promotional content. By doing this, the website owner implicitly trusts that the advertising company will offer legitimate content and it will not put the site's visitors at risk of falling victims of malware campaigns and other scams.
Apostolis Zarras, Alexandros Kapravelos, Gianluca Stringhini, Thorsten Holz, Christopher Krügel, Giovanni Vigna
Internet Measurement Conference1
2014 Automated generation of models for fast and precise detection of HTTP-based malware
abstract
Malicious software and especially botnets are among the most important security threats in the Internet. Thus, the accurate and timely detection of such threats is of great importance. Detecting machines infected with malware by identifying their malicious activities at the network level is an appealing approach, due to the ease of deployment. Nowadays, the most common communication channels used by attackers to control the infected machines are based on the HTTP protocol. To evade detection, HTTP-based malware adapt their behavior to the communication patterns of the benign HTTP clients, such as web browsers. This poses significant challenges to existing detection approaches like signature-based and behavioral-based detection systems. In this paper, we propose BO THO U N D: a novel approach to precisely detect HTTP-based malware at the network level. The key idea is that implementations of the HTTP protocol by different entities have small but perceivable differences. Building on this observation, BO THO U N D automatically generates models for malicious and benign requests and classifies at real time the HTTP traffic of a monitored network. Our evaluation results demonstrate that BO THO U N D outperforms prior work on identifying HTTP-based botnets, being able to detect a large variety of real-world HTTP-based malware, including advanced persistent threats used in targeted attacks, with a very low percentage of classification errors.
Apostolis Zarras, Antonis Papadogiannakis, Robert Gawlik, Thorsten Holz
PST1
2013 k-subscription: privacy-preserving microblogging browsing through obfuscation
abstract
Over the past few years, microblogging social networking services have become a popular means for information sharing and communication. Besides sharing information among friends, such services are currently being used by artists, politicians, news channels, and information providers to easily communicate with their constituency. Even though following specific channels on a microblogging service enables users to receive interesting information in a timely manner, it may raise significant privacy concerns as well. For example, the microblogging service is able to observe all the channels that a particular user follows. This way, it can infer all the subjects a user might be interested in and generate a detailed profile of this user. This knowledge can be used for a variety of purposes that are usually beyond the control of the users.
Panagiotis Papadopoulos, Antonis Papadogiannakis, Michalis Polychronakis, Apostolis Zarras, Thorsten Holz, Evangelos P. Markatos
ACSAC4
2012 B@bel: Leveraging Email Delivery for Spam Mitigation
Gianluca Stringhini, Manuel Egele, Apostolis Zarras, Thorsten Holz, Christopher Krügel, Giovanni Vigna
USENIX Security Symposium3
2011 Understanding fraudulent activities in online ad exchanges
abstract
Online advertisements (ads) provide a powerful mechanism for advertisers to effectively target Web users. Ads can be customized based on a user's browsing behavior, geographic location, and personal interests. There is currently a multi-billion dollar market for online advertising, which generates the primary revenue for some of the most popular websites on the Internet. In order to meet the immense market demand, and to manage the complex relationships between advertisers and publishers (i.e., the websites hosting the ads), marketplaces known as "ad exchanges" are employed. These exchanges allow publishers (sellers of ad space) and advertisers(buyers of this ad space) to dynamically broker traffic through ad networks to efficiently maximize profits for all parties. Unfortunately, the complexities of these systems invite a considerable amount of abuse from cybercriminals, who profit at the expense of the advertisers.
Brett Stone-Gross, Ryan Stevens, Apostolis Zarras, Richard A. Kemmerer, Christopher Krügel, Giovanni Vigna
Internet Measurement Conference3