VLDB 2026 Research / reviewers in the wild / expert
Leonie Ruth Simpson
dblp:18/382 · also Leonie Simpson
· DBLP profile ↗
30ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0001-8434-9741ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 3 first-author · 6 since 2021Theory of computation · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 2 since 2021Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The Impact of Gender and Level of Control over Agents' Aesthetics on User Experiences in VR TrainingabstractThis study explores how user gender, agent gender, and control over agent aesthetics affect experiences in a VR phishing awareness training application. As digital agents become more common in immersive training, understanding their design impact is critical. Participants were assigned to one of three conditions: (1) full customization of the agent’s appearance, (2) selection from pre-made agents, or (3) no choice. We measured outcomes including phishing awareness (immediate and retained), mental effort, enjoyment, presence, and relatedness. Results showed no significant effects of user gender or choice condition on awareness, mental effort, or presence. However, female participants reported greater relatedness with their agent at a three-month follow-up, suggesting potential long-term engagement benefits. Aesthetic control did not significantly influence learning or awareness retention, underscoring the importance of content quality over personalization. These findings contribute to research on gender dynamics and customization in immersive learning environments. Sonam Adinolf, David Conroy, Peta Wyeth, Leonie Ruth Simpson |
Int. J. Hum. Comput. Interact. | 4 |
| 2024 | Contextual Transformer-based Node Embedding for Vulnerability Detection using Graph LearningabstractAutomated source code vulnerability detection using code graphs has seen major improvements in recent years, however one critical, but oft-overlooked, element of this problem is producing embeddings for graph nodes. Before graph-based classifiers can be used for vulnerability detection, the nodes in the graph must first be given vector representations. Graphlearning models propagate information from these embeddings through the graph before classification, and so the initial states of these embeddings are vital for all subsequent learning. While a variety of solutions to this problem have been proposed in existing literature, this is typically not the focus of these works. We propose a novel node embedding strategy for graph-based vulnerability discovery, which takes advantage of richly-learned information about the code contained in each node. We also implement and test several existing node embedding strategies, comparing them to each other and our new strategy under a standard graph-learning architecture. We find that our strategy outperforms existing methods by 10.47-50.70%. Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson |
TrustCom | 6 |
| 2024 | A Provably Secure and Efficient Cryptographic-Key Update Protocol for Connected VehiclesabstractWireless broadcast transmission technology enables vehicles to communicate with other nearby vehicles and with nearby fixed equipment. Vehicles and equipment within transmission range establish a self-organizing network called Vehicular Ad-hoc Network (VANET). The communication in VANETs is vulnerable to message manipulation attacks. Thus, mechanisms should be applied to ensure both the authenticity and integrity of the data broadcast. Any cryptographic technique employed for authentication requires the use of a cryptographic key, and mechanisms to restore the system quickly when either long-term and short-term cryptographic keying material are leaked or expired. Such mechanisms must be carefully designed to satisfy both perfect-forward-secrecy and security against known-key attacks. To achieve this, there should be no direct dependencies among keying material. Unfortunately, many existing proposals for authentication are not fully effective in VANETs, since many of them do not take a key-management mechanism into consideration or they fail to satisfy the requirements for secure key-update. In this paper, we first present a case study demonstrating that dependency among keying material is an exploitable vulnerability that violates perfect-forward-secrecy, and results in known-key attacks and message forgery attacks. Secondly, we propose a new cryptographic-key update protocol that consists of two sub-protocols: a long-term-key update protocol (for updating the long-term cryptographic keying material) and a short-term-key update protocol (for session-key establishment). Our scheme is accompanied by both security and efficiency analysis: we provide a formal security proof and demonstrate efficiency by conducting extensive performance analysis. This is compared with the security and efficiency of existing schemes in public literature. Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Key Recovery Attacks on Grain-Like Keystream Generators with Key Injection
Matthew Beighton, Harry Bartlett, Leonie Ruth Simpson, Kenneth Koon-Ho Wong |
ACISP | 3 |
| 2023 | ALI: Anonymous Lightweight Inter-Vehicle Broadcast Authentication With EncryptionabstractWireless broadcast transmission enables Inter-vehicle or Vehicle-to-Vehicle (V2V) communication among nearby vehicles. This communication supports latency-critical applications for improved safety and maybe optimized traffic. However, V2V communication is vulnerable to cyber attacks involving message manipulation. Mechanisms are required to ensure both authenticity and integrity of broadcast data, while maintaining drivers privacy against surveillance. Considering the limited computational resources of vehicles and the possibility of high traffic density scenarios, authentication processes should have low computational overhead. Prior research has produced multiple authentication protocol proposals based on digital signatures, hash functions, or Message Authentication Codes (MACs). To date, there is no computationally efficient secure broadcast authentication scheme tolerable by the vehicles resource-constrained On-Board Units (OBUs) for latency-critical applications in heavy traffic conditions. This paper provides a new secure, efficient, and privacy-preserving scheme proposing Anonymous Lightweight Inter-vehicle (ALI) broadcast authentication with encryption. ALI provides a high level of anonymity by combining a message authentication scheme with beacon encryption. The cryptographic overhead for V2V communication in the ALI scheme is only 149 bytes, and can handle authentication of approximately 700 broadcast messages every 100 milliseconds. This demonstrates the suitability of the ALI scheme in heavy traffic scenarios. We show the security and efficiency of our proposal by conducting security proof and performance analysis. Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | SCEVD: Semantic-enhanced Code Embedding for Vulnerability DiscoveryabstractSource code vulnerability detection is a major goal in security research. In recent years, deep learning methods have been applied to this end, however the task of embedding code into vector representations as input for deep learning models has yet to be definitively solved. The use of graphs, specifically Abstract Syntax Trees and Code Property Graphs, is a promising research direction for this task, however learning from graphs grows prohibitively computationally expensive for large graphs. No close examination of intelligent ways to prune this input to only vulnerability-relevant information has yet been performed. Additionally, most existing works focus largely on structural information from graphs, often neglecting information contained within the nodes themselves. We address these gaps in the prior research by proposing SCEVD: a deep learning model for vulnerability discovery which utilises semantic information to intelligently select features in source code graphs for learning. It uses information contained within code graph nodes, as well as information about their relationships with one another to select the code graph features which are most relevant to code vulnerability. We implement SCEVD and conduct experiments using the SARD Juliet test suite, finding that we are able to improve vulnerability discovery results using this process of semantic-enhanced code graph feature selection. Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson |
TrustCom | 6 |
| 2021 | Towards a Secured and Safe Online Social Media Design Framework for People with Intellectual DisabilityabstractThis paper aims to create a tangible design framework for practitioners to follow when designing an online social media platform for individuals with intellectual disability. Currently, legislation and best practice consider cyber security and safety for the general public, giving particular attention to the protection of children. However, despite the support in health care, financial assistance, and education, individuals with intellectual disability are rarely considered when it comes to cybersafety. To achieve inclusivity, an integrative review was conducted to make connections between disciplines of education and information technology and law. The process was split into three phases: (i) understanding the challenges those with intellectual disability face, both when using a social media interface and when evaluating safety risks; (ii) identifying gaps and understanding the implications for persons with intellectual disability from legislative and design and design principles; and (iii) visualisation of data flow to model interactions. In conclusion, an inclusive framework is proposed for practitioners when designing online social media platforms for people with intellectual disability. Ya-Wen Chang, Laurianne Sitbon, Leonie Ruth Simpson |
ASSETS | 3 |
| 2021 | On the Efficiency of Pairing-Based Authentication for Connected Vehicles: Time is Not on Our Side!abstractIn the near future, intelligent vehicles will be connected via wireless communication links, forming Vehicular Ad-hoc Networks (VANETs). This has potential to improve road safety and to optimize traffic. However, if the communications are not secure, VANETs are vulnerable to cyber attacks involving message manipulation. Research on this problem has produced multiple authentication protocols based on bilinear pairings (a variant of elliptic curve cryptography). The efficiency of such authentication schemes must be addressed before they can be used in real-world deployments. Standards bodies have begun standardizing various pairing-based schemes. The IEEE 1609.2 security standard has not yet selected any pairing-based scheme, leaving the settings related to pairing-based cryptography in the vehicular environments unspecified. In this work, we investigate the efficiency of pairing-based cryptographic primitives over the Barreto-Lynn-Scott and Barreto-Naehrig pairing friendly elliptic curves recommended in the IETF and ISO standards, to determine their suitability for practical application. We implement the algorithms and evaluate the effect of cryptographic pairings using theoretical and experimental analysis of four well-known pairing-based short signature schemes, including: Boneh-Lynn-Shacham, Boneh-Boyen, Zhang-Safavi-Susilo, and Boneh-Gentry-Lynn-Shacham. We use metrics including CPU clock cycles per operation, average computation time in milliseconds, and signature/public key size in bits to estimate the cost of implementing cryptographic pairings on modern processors. We demonstrate the effect of pairing-based cryptography on authentication in vehicular networks. We investigate a high-density highway scenario and show that a crash is possible, as a result of the evaluated authentication delay. We share our findings ahead of the IEEE 1609.2 recommendations for the use of cryptographic pairings. Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | Fault analysis of AEZabstractSummary AEZ is a block cipher mode based on AES which uses three 128‐bit keys. The algorithm has been updated several times during the three rounds of the CAESAR cryptographic competition. Cryptanalytic results presented on AEZ to date do not breach its security. This paper describes a fault injection analysis on AEZ. We focus on analysing AEZ v4.2 but also investigate the applicability of these analyses to the recent version AEZ v5. This paper shows that all three 128‐bit keys in AEZ v4.2 can be uniquely retrieved using only three random‐valued single byte fault injections. A similar approach using four fault injections can uniquely recover all three keys of AEZ v5. The feasibility of this fault injection methodology has been proven against AES in previous works. Hassan Qahur Al Mahri, Leonie Ruth Simpson, Harry Bartlett, Ed Dawson, Kenneth Koon-Ho Wong |
Concurr. Comput. Pract. Exp. | 2 |
| 2019 | Random Fault Attacks on a Class of Stream CiphersabstractIn this paper, we show that stream ciphers with a particular form of ciphertext output function are vulnerable to differential fault attacks using random faults. The CAESAR competition candidates Tiaoxin-346 and AEGIS-128L both fall into this category, and we show that our attack can be used to recover the secret key of Tiaoxin-346 and the entire state of AEGIS-128L with practical complexity. In the case of AEGIS-128L, the attack can be applied in a ciphertext-only scenario. Our attacks are more practical than previous fault attacks on these ciphers, which assumed bit-flipping faults. Although we also consider other ways of mitigating our attacks, we recommend that cipher designers avoid the form of ciphertext output function that we have identified. Harry Bartlett, Ed Dawson, Hassan Qahur Al Mahri, Md. Iftekhar Salam, Leonie Ruth Simpson, Kenneth Koon-Ho Wong |
Secur. Commun. Networks | 5 |
| 2017 | Fault Attacks on XEX Mode with Application to Certain Authenticated Encryption Modes
Hassan Qahur Al Mahri, Leonie Ruth Simpson, Harry Bartlett, Ed Dawson, Kenneth Koon-Ho Wong |
ACISP (1) | 2 |
| 2014 | Weaknesses in the Initialisation Process of the Common Scrambling Algorithm Stream Cipher
Harry Bartlett, Ali Al-Hamdan, Leonie Ruth Simpson, Ed Dawson, Kenneth Koon-Ho Wong |
SETA | 3 |
| 2013 | Security and Privacy in eHealth: Is it possible?abstractAdvances in Information and Communication Technologies have the potential to improve many facets of modern healthcare service delivery. The implementation of electronic health records systems is a critical part of an eHealth system. Despite the potential gains, there are several obstacles that limit the wider development of electronic health record systems. Among these are the perceived threats to the security and privacy of patients' health data, and a widely held belief that these cannot be adequately addressed. We hypothesize that the major concerns regarding eHealth security and privacy cannot be overcome through the implementation of technology alone. Human dimensions must be considered when analyzing the provision of the three fundamental information security goals: confidentiality, integrity and availability. A sociotechnical analysis to establish the information security and privacy requirements when designing and developing a given eHealth system is important and timely. A framework that accommodates consideration of the legislative requirements and human perspectives in addition to the technological measures is useful in developing a measurable and accountable eHealth system. Successful implementation of this approach would enable the possibilities, practicalities and sustainabilities of proposed eHealth systems to be realised. Tony Sahama, Leonie Ruth Simpson, Bill Lane |
Healthcom | 2 |
| 2013 | Key Derivation Function: The SCKDF Scheme
Chuah Chai Wen, Ed Dawson, Leonie Ruth Simpson |
SEC | 3 |
| 2012 | Analysis of Indirect Message Injection for MAC Generation Using Stream Ciphers
Mufeed Juma AlMashrafi, Harry Bartlett, Leonie Ruth Simpson, Ed Dawson, Kenneth Koon-Ho Wong |
ACISP | 3 |
| 2012 | A General Model for MAC Generation Using Direct Injection
Harry Bartlett, Mufeed Juma AlMashrafi, Leonie Ruth Simpson, Ed Dawson, Kenneth Koon-Ho Wong |
Inscrypt | 3 |
| 2012 | A Framework for Security Analysis of Key Derivation Functions
Chuah Chai Wen, Ed Dawson, Juan Manuel González Nieto, Leonie Ruth Simpson |
ISPEC | 4 |
| 2011 | State convergence and the effectiveness of time-memory-data tradeoffsabstractVarious time-memory tradeoffs attacks for stream ciphers have been proposed over the years. However, the claimed success of these attacks assumes the initialisation process of the stream cipher is one-to-one. Some stream cipher proposals do not have a one-to-one initialisation process. In this paper, we examine the impact of this on the success of time-memory-data tradeoff attacks. Under the circumstances, some attacks are more successful than previously claimed while others are less. The conditions for both cases are established. Sui-Guan Teo, Kenneth Koon-Ho Wong, Ed Dawson, Leonie Ruth Simpson |
IAS | 4 |
| 2011 | State Convergence in the Initialisation of Stream Ciphers
Sui-Guan Teo, Ali Al-Hamdan, Harry Bartlett, Leonie Ruth Simpson, Kenneth Koon-Ho Wong, Ed Dawson |
ACISP | 4 |
| 2011 | Algebraic analysis of the SSS stream cipherabstractBoth the SSS and SOBER-t32 stream cipher designs use a single word-based shift register and a nonlinear filter function to produce keystream. In this paper we show that the algebraic attack method previously applied to SOBER-t32 is prevented from succeeding on SSS by the use of the keydependent substitution box (SBox) in the nonlinear filter of SSS. Additional assumptions and modifications to the SSS cipher in an attempt to enable algebraic analysis result in other difficulties that also render the algebraic attack infeasible. Based on these results, we conclude that a well-chosen key-dependent substitution box used in the nonlinear filter of the stream cipher provides resistance against such algebraic attacks. Mufeed Juma AlMashrafi, Kenneth Koon-Ho Wong, Leonie Ruth Simpson, Harry Bartlett, Ed Dawson |
SIN | 3 |
| 2009 | Improved Cryptanalysis of the Common Scrambling Algorithm Stream Cipher
Leonie Ruth Simpson, Matt Henricksen, Wun-She Yap |
ACISP | 1 |
| 2009 | Linearity within the SMS4 Block Cipher
Muhammad Reza Z'aba, Leonie Ruth Simpson, Ed Dawson, Kenneth Koon-Ho Wong |
Inscrypt | 2 |
| 2007 | On the Security of the LILI Family of Stream Ciphers Against Algebraic Attacks
Sultan Al-Hinai, Ed Dawson, Matt Henricksen, Leonie Ruth Simpson |
ACISP | 4 |
| 2006 | Improved Cryptanalysis of MAG
Leonie Ruth Simpson, Matt Henricksen |
ACISP | 1 |
| 2002 | The LILI-II Keystream Generator
Andrew J. Clark, Ed Dawson, Joanne Fuller, Jovan Dj. Golic, Hoonjae Lee 0001, William Millan, Sang-Jae Moon, Leonie Ruth Simpson |
ACISP | 8 |
| 1999 | A Fast Correlation Attack on Multiplexer Generators
Leonie Ruth Simpson, Jovan Dj. Golic, Mahmoud Salmasizadeh, Ed Dawson |
Inf. Process. Lett. | 1 |
| 1998 | A Probabilistic Correlation Attack on the Shrinking Generator
Leonie Ruth Simpson, Jovan Dj. Golic, Ed Dawson |
ACISP | 1 |
| 1998 | Cryptanalysis of ORYX
David A. Wagner 0001, Leonie Ruth Simpson, Ed Dawson, John Kelsey, William Millan, Bruce Schneier |
Selected Areas in Cryptography | 2 |
| 1997 | Fast Correlation Attacks and Multiple Linear Approximations
M. Salmasidazeh, Leonie Ruth Simpson, Jovan Dj. Golic, Ed Dawson |
ACISP | 2 |
| 1997 | Fast Correlation Attacks on Nonlinear Filter Generators
Jovan Dj. Golic, Mahmoud Salmasizadeh, Leonie Ruth Simpson, Ed Dawson |
Inf. Process. Lett. | 3 |