Leonie Ruth Simpson

dblp:18/382 · also Leonie Simpson · DBLP profile ↗
← Back
30ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0001-8434-9741ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 3 first-author · 6 since 2021Theory of computation · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 2 since 2021Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 The Impact of Gender and Level of Control over Agents' Aesthetics on User Experiences in VR Training
abstract
This study explores how user gender, agent gender, and control over agent aesthetics affect experiences in a VR phishing awareness training application. As digital agents become more common in immersive training, understanding their design impact is critical. Participants were assigned to one of three conditions: (1) full customization of the agent’s appearance, (2) selection from pre-made agents, or (3) no choice. We measured outcomes including phishing awareness (immediate and retained), mental effort, enjoyment, presence, and relatedness. Results showed no significant effects of user gender or choice condition on awareness, mental effort, or presence. However, female participants reported greater relatedness with their agent at a three-month follow-up, suggesting potential long-term engagement benefits. Aesthetic control did not significantly influence learning or awareness retention, underscoring the importance of content quality over personalization. These findings contribute to research on gender dynamics and customization in immersive learning environments.
Sonam Adinolf, David Conroy, Peta Wyeth, Leonie Ruth Simpson
Int. J. Hum. Comput. Interact.4
2024 Contextual Transformer-based Node Embedding for Vulnerability Detection using Graph Learning
abstract
Automated source code vulnerability detection using code graphs has seen major improvements in recent years, however one critical, but oft-overlooked, element of this problem is producing embeddings for graph nodes. Before graph-based classifiers can be used for vulnerability detection, the nodes in the graph must first be given vector representations. Graphlearning models propagate information from these embeddings through the graph before classification, and so the initial states of these embeddings are vital for all subsequent learning. While a variety of solutions to this problem have been proposed in existing literature, this is typically not the focus of these works. We propose a novel node embedding strategy for graph-based vulnerability discovery, which takes advantage of richly-learned information about the code contained in each node. We also implement and test several existing node embedding strategies, comparing them to each other and our new strategy under a standard graph-learning architecture. We find that our strategy outperforms existing methods by 10.47-50.70%.
Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson
TrustCom6
2024 A Provably Secure and Efficient Cryptographic-Key Update Protocol for Connected Vehicles
abstract
Wireless broadcast transmission technology enables vehicles to communicate with other nearby vehicles and with nearby fixed equipment. Vehicles and equipment within transmission range establish a self-organizing network called Vehicular Ad-hoc Network (VANET). The communication in VANETs is vulnerable to message manipulation attacks. Thus, mechanisms should be applied to ensure both the authenticity and integrity of the data broadcast. Any cryptographic technique employed for authentication requires the use of a cryptographic key, and mechanisms to restore the system quickly when either long-term and short-term cryptographic keying material are leaked or expired. Such mechanisms must be carefully designed to satisfy both perfect-forward-secrecy and security against known-key attacks. To achieve this, there should be no direct dependencies among keying material. Unfortunately, many existing proposals for authentication are not fully effective in VANETs, since many of them do not take a key-management mechanism into consideration or they fail to satisfy the requirements for secure key-update. In this paper, we first present a case study demonstrating that dependency among keying material is an exploitable vulnerability that violates perfect-forward-secrecy, and results in known-key attacks and message forgery attacks. Secondly, we propose a new cryptographic-key update protocol that consists of two sub-protocols: a long-term-key update protocol (for updating the long-term cryptographic keying material) and a short-term-key update protocol (for session-key establishment). Our scheme is accompanied by both security and efficiency analysis: we provide a formal security proof and demonstrate efficiency by conducting extensive performance analysis. This is compared with the security and efficiency of existing schemes in public literature.
Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk
IEEE Trans. Dependable Secur. Comput.2
2023 Key Recovery Attacks on Grain-Like Keystream Generators with Key Injection
Matthew Beighton, Harry Bartlett, Leonie Ruth Simpson, Kenneth Koon-Ho Wong
ACISP3
2023 ALI: Anonymous Lightweight Inter-Vehicle Broadcast Authentication With Encryption
abstract
Wireless broadcast transmission enables Inter-vehicle or Vehicle-to-Vehicle (V2V) communication among nearby vehicles. This communication supports latency-critical applications for improved safety and maybe optimized traffic. However, V2V communication is vulnerable to cyber attacks involving message manipulation. Mechanisms are required to ensure both authenticity and integrity of broadcast data, while maintaining drivers privacy against surveillance. Considering the limited computational resources of vehicles and the possibility of high traffic density scenarios, authentication processes should have low computational overhead. Prior research has produced multiple authentication protocol proposals based on digital signatures, hash functions, or Message Authentication Codes (MACs). To date, there is no computationally efficient secure broadcast authentication scheme tolerable by the vehicles resource-constrained On-Board Units (OBUs) for latency-critical applications in heavy traffic conditions. This paper provides a new secure, efficient, and privacy-preserving scheme proposing Anonymous Lightweight Inter-vehicle (ALI) broadcast authentication with encryption. ALI provides a high level of anonymity by combining a message authentication scheme with beacon encryption. The cryptographic overhead for V2V communication in the ALI scheme is only 149 bytes, and can handle authentication of approximately 700 broadcast messages every 100 milliseconds. This demonstrates the suitability of the ALI scheme in heavy traffic scenarios. We show the security and efficiency of our proposal by conducting security proof and performance analysis.
Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk
IEEE Trans. Dependable Secur. Comput.2
2022 SCEVD: Semantic-enhanced Code Embedding for Vulnerability Discovery
abstract
Source code vulnerability detection is a major goal in security research. In recent years, deep learning methods have been applied to this end, however the task of embedding code into vector representations as input for deep learning models has yet to be definitively solved. The use of graphs, specifically Abstract Syntax Trees and Code Property Graphs, is a promising research direction for this task, however learning from graphs grows prohibitively computationally expensive for large graphs. No close examination of intelligent ways to prune this input to only vulnerability-relevant information has yet been performed. Additionally, most existing works focus largely on structural information from graphs, often neglecting information contained within the nodes themselves. We address these gaps in the prior research by proposing SCEVD: a deep learning model for vulnerability discovery which utilises semantic information to intelligently select features in source code graphs for learning. It uses information contained within code graph nodes, as well as information about their relationships with one another to select the code graph features which are most relevant to code vulnerability. We implement SCEVD and conduct experiments using the SARD Juliet test suite, finding that we are able to improve vulnerability discovery results using this process of semantic-enhanced code graph feature selection.
Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson
TrustCom6
2021 Towards a Secured and Safe Online Social Media Design Framework for People with Intellectual Disability
abstract
This paper aims to create a tangible design framework for practitioners to follow when designing an online social media platform for individuals with intellectual disability. Currently, legislation and best practice consider cyber security and safety for the general public, giving particular attention to the protection of children. However, despite the support in health care, financial assistance, and education, individuals with intellectual disability are rarely considered when it comes to cybersafety. To achieve inclusivity, an integrative review was conducted to make connections between disciplines of education and information technology and law. The process was split into three phases: (i) understanding the challenges those with intellectual disability face, both when using a social media interface and when evaluating safety risks; (ii) identifying gaps and understanding the implications for persons with intellectual disability from legislative and design and design principles; and (iii) visualisation of data flow to model interactions. In conclusion, an inclusive framework is proposed for practitioners when designing online social media platforms for people with intellectual disability.
Ya-Wen Chang, Laurianne Sitbon, Leonie Ruth Simpson
ASSETS3
2021 On the Efficiency of Pairing-Based Authentication for Connected Vehicles: Time is Not on Our Side!
abstract
In the near future, intelligent vehicles will be connected via wireless communication links, forming Vehicular Ad-hoc Networks (VANETs). This has potential to improve road safety and to optimize traffic. However, if the communications are not secure, VANETs are vulnerable to cyber attacks involving message manipulation. Research on this problem has produced multiple authentication protocols based on bilinear pairings (a variant of elliptic curve cryptography). The efficiency of such authentication schemes must be addressed before they can be used in real-world deployments. Standards bodies have begun standardizing various pairing-based schemes. The IEEE 1609.2 security standard has not yet selected any pairing-based scheme, leaving the settings related to pairing-based cryptography in the vehicular environments unspecified. In this work, we investigate the efficiency of pairing-based cryptographic primitives over the Barreto-Lynn-Scott and Barreto-Naehrig pairing friendly elliptic curves recommended in the IETF and ISO standards, to determine their suitability for practical application. We implement the algorithms and evaluate the effect of cryptographic pairings using theoretical and experimental analysis of four well-known pairing-based short signature schemes, including: Boneh-Lynn-Shacham, Boneh-Boyen, Zhang-Safavi-Susilo, and Boneh-Gentry-Lynn-Shacham. We use metrics including CPU clock cycles per operation, average computation time in milliseconds, and signature/public key size in bits to estimate the cost of implementing cryptographic pairings on modern processors. We demonstrate the effect of pairing-based cryptography on authentication in vehicular networks. We investigate a high-density highway scenario and show that a crash is possible, as a result of the evaluated authentication delay. We share our findings ahead of the IEEE 1609.2 recommendations for the use of cryptographic pairings.
Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk
IEEE Trans. Inf. Forensics Secur.2
2019 Fault analysis of AEZ
abstract
Summary AEZ is a block cipher mode based on AES which uses three 128‐bit keys. The algorithm has been updated several times during the three rounds of the CAESAR cryptographic competition. Cryptanalytic results presented on AEZ to date do not breach its security. This paper describes a fault injection analysis on AEZ. We focus on analysing AEZ v4.2 but also investigate the applicability of these analyses to the recent version AEZ v5. This paper shows that all three 128‐bit keys in AEZ v4.2 can be uniquely retrieved using only three random‐valued single byte fault injections. A similar approach using four fault injections can uniquely recover all three keys of AEZ v5. The feasibility of this fault injection methodology has been proven against AES in previous works.
Hassan Qahur Al Mahri, Leonie Ruth Simpson, Harry Bartlett, Ed Dawson, Kenneth Koon-Ho Wong
Concurr. Comput. Pract. Exp.2
2019 Random Fault Attacks on a Class of Stream Ciphers
abstract
In this paper, we show that stream ciphers with a particular form of ciphertext output function are vulnerable to differential fault attacks using random faults. The CAESAR competition candidates Tiaoxin-346 and AEGIS-128L both fall into this category, and we show that our attack can be used to recover the secret key of Tiaoxin-346 and the entire state of AEGIS-128L with practical complexity. In the case of AEGIS-128L, the attack can be applied in a ciphertext-only scenario. Our attacks are more practical than previous fault attacks on these ciphers, which assumed bit-flipping faults. Although we also consider other ways of mitigating our attacks, we recommend that cipher designers avoid the form of ciphertext output function that we have identified.
Harry Bartlett, Ed Dawson, Hassan Qahur Al Mahri, Md. Iftekhar Salam, Leonie Ruth Simpson, Kenneth Koon-Ho Wong
Secur. Commun. Networks5
2017 Fault Attacks on XEX Mode with Application to Certain Authenticated Encryption Modes
Hassan Qahur Al Mahri, Leonie Ruth Simpson, Harry Bartlett, Ed Dawson, Kenneth Koon-Ho Wong
ACISP (1)2
2014 Weaknesses in the Initialisation Process of the Common Scrambling Algorithm Stream Cipher
Harry Bartlett, Ali Al-Hamdan, Leonie Ruth Simpson, Ed Dawson, Kenneth Koon-Ho Wong
SETA3
2013 Security and Privacy in eHealth: Is it possible?
abstract
Advances in Information and Communication Technologies have the potential to improve many facets of modern healthcare service delivery. The implementation of electronic health records systems is a critical part of an eHealth system. Despite the potential gains, there are several obstacles that limit the wider development of electronic health record systems. Among these are the perceived threats to the security and privacy of patients' health data, and a widely held belief that these cannot be adequately addressed. We hypothesize that the major concerns regarding eHealth security and privacy cannot be overcome through the implementation of technology alone. Human dimensions must be considered when analyzing the provision of the three fundamental information security goals: confidentiality, integrity and availability. A sociotechnical analysis to establish the information security and privacy requirements when designing and developing a given eHealth system is important and timely. A framework that accommodates consideration of the legislative requirements and human perspectives in addition to the technological measures is useful in developing a measurable and accountable eHealth system. Successful implementation of this approach would enable the possibilities, practicalities and sustainabilities of proposed eHealth systems to be realised.
Tony Sahama, Leonie Ruth Simpson, Bill Lane
Healthcom2
2013 Key Derivation Function: The SCKDF Scheme
Chuah Chai Wen, Ed Dawson, Leonie Ruth Simpson
SEC3
2012 Analysis of Indirect Message Injection for MAC Generation Using Stream Ciphers
Mufeed Juma AlMashrafi, Harry Bartlett, Leonie Ruth Simpson, Ed Dawson, Kenneth Koon-Ho Wong
ACISP3
2012 A General Model for MAC Generation Using Direct Injection
Harry Bartlett, Mufeed Juma AlMashrafi, Leonie Ruth Simpson, Ed Dawson, Kenneth Koon-Ho Wong
Inscrypt3
2012 A Framework for Security Analysis of Key Derivation Functions
Chuah Chai Wen, Ed Dawson, Juan Manuel González Nieto, Leonie Ruth Simpson
ISPEC4
2011 State convergence and the effectiveness of time-memory-data tradeoffs
abstract
Various time-memory tradeoffs attacks for stream ciphers have been proposed over the years. However, the claimed success of these attacks assumes the initialisation process of the stream cipher is one-to-one. Some stream cipher proposals do not have a one-to-one initialisation process. In this paper, we examine the impact of this on the success of time-memory-data tradeoff attacks. Under the circumstances, some attacks are more successful than previously claimed while others are less. The conditions for both cases are established.
Sui-Guan Teo, Kenneth Koon-Ho Wong, Ed Dawson, Leonie Ruth Simpson
IAS4
2011 State Convergence in the Initialisation of Stream Ciphers
Sui-Guan Teo, Ali Al-Hamdan, Harry Bartlett, Leonie Ruth Simpson, Kenneth Koon-Ho Wong, Ed Dawson
ACISP4
2011 Algebraic analysis of the SSS stream cipher
abstract
Both the SSS and SOBER-t32 stream cipher designs use a single word-based shift register and a nonlinear filter function to produce keystream. In this paper we show that the algebraic attack method previously applied to SOBER-t32 is prevented from succeeding on SSS by the use of the keydependent substitution box (SBox) in the nonlinear filter of SSS. Additional assumptions and modifications to the SSS cipher in an attempt to enable algebraic analysis result in other difficulties that also render the algebraic attack infeasible. Based on these results, we conclude that a well-chosen key-dependent substitution box used in the nonlinear filter of the stream cipher provides resistance against such algebraic attacks.
Mufeed Juma AlMashrafi, Kenneth Koon-Ho Wong, Leonie Ruth Simpson, Harry Bartlett, Ed Dawson
SIN3
2009 Improved Cryptanalysis of the Common Scrambling Algorithm Stream Cipher
Leonie Ruth Simpson, Matt Henricksen, Wun-She Yap
ACISP1
2009 Linearity within the SMS4 Block Cipher
Muhammad Reza Z'aba, Leonie Ruth Simpson, Ed Dawson, Kenneth Koon-Ho Wong
Inscrypt2
2007 On the Security of the LILI Family of Stream Ciphers Against Algebraic Attacks
Sultan Al-Hinai, Ed Dawson, Matt Henricksen, Leonie Ruth Simpson
ACISP4
2006 Improved Cryptanalysis of MAG
Leonie Ruth Simpson, Matt Henricksen
ACISP1
2002 The LILI-II Keystream Generator
Andrew J. Clark, Ed Dawson, Joanne Fuller, Jovan Dj. Golic, Hoonjae Lee 0001, William Millan, Sang-Jae Moon, Leonie Ruth Simpson
ACISP8
1999 A Fast Correlation Attack on Multiplexer Generators
Leonie Ruth Simpson, Jovan Dj. Golic, Mahmoud Salmasizadeh, Ed Dawson
Inf. Process. Lett.1
1998 A Probabilistic Correlation Attack on the Shrinking Generator
Leonie Ruth Simpson, Jovan Dj. Golic, Ed Dawson
ACISP1
1998 Cryptanalysis of ORYX
David A. Wagner 0001, Leonie Ruth Simpson, Ed Dawson, John Kelsey, William Millan, Bruce Schneier
Selected Areas in Cryptography2
1997 Fast Correlation Attacks and Multiple Linear Approximations
M. Salmasidazeh, Leonie Ruth Simpson, Jovan Dj. Golic, Ed Dawson
ACISP2
1997 Fast Correlation Attacks on Nonlinear Filter Generators
Jovan Dj. Golic, Mahmoud Salmasizadeh, Leonie Ruth Simpson, Ed Dawson
Inf. Process. Lett.3