VLDB 2026 Research / reviewers in the wild / expert
Patryk Szewczyk
dblp:19/10027
· DBLP profile ↗
11ranked-venue papers
3as first author
7since 2021 · last 2025
0000-0003-3040-9344ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 5 since 2021Security and privacy · 5 · 3 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | BGP anomaly detection as a group dynamics problemabstractUnderstanding group information and collective behaviors is an ongoing area of research, encompassing natural phenomena and human dynamics. Quantifying interactions and interdependencies at the group level can be valuable for understanding complex and dynamical systems. The Border Gateway Protocol (BGP), the default inter-domain routing protocol for the Internet, operates within a large, complex, and dynamic system vulnerable to security threats. Traditional BGP anomaly detection focuses on single observables from individual Autonomous Systems (ASes), which inadequately addresses the multidimensional, multi-viewpoint nature of the Internet and interdomain routing. This paper introduces a novel approach for quantifying group AS-level information and dynamics. We present the first ever application of Multidimensional Recurrence Quantification Analysis (MdRQA) to any computer system, offering a robust BGP anomaly detection technique that identifies anomalies earlier than traditional single-AS observable methods. This research marks a significant advancement in BGP anomaly detection, treating it as a group dynamics problem within the Internet’s complex and distributed system. • Investigation of multiple Autonomous Systems (ASes) in terms of group information and dynamics for the purposes of group-AS level BGP anomaly detection. • The first time Multidimensional Recurrence Quantification Analysis (MdRQA) has been applied to groups of computer-controlled systems. • The first time MdRQA incorporates all extant RQA metrics. • MdRQA provides more information and detects the incident earlier than the standard single observable variant and some deep learning approaches. Ben Scott, Michael N. Johnstone, Patryk Szewczyk, Steven Richardson |
Comput. Networks | 3 |
| 2025 | Detection of on-manifold adversarial attacks via latent space transformationabstractOut-of-distribution (OOD) generalization is critical for reliable intrusion detection systems (IDS), yet current methods often falter against stealthy, on-manifold adversarial attacks that mimic ID data. To solve this challenge, we propose a semi-supervised approach that applies an invertible transformation to the latent space and leverages changes in differential entropy to detect OOD samples. Experiments on the KDD99 and X-IIoTID datasets demonstrate that our approach outperforms state-of-the-art defenses, providing enhanced robustness and generalizability for IDS. Mohammad Al-Fawa'reh, Jumana M. Abu-Khalaf, Naeem Janjua, Patryk Szewczyk |
Comput. Secur. | 4 |
| 2025 | On and off the manifold: Generation and Detection of adversarial attacks in IIoT networksabstractNetwork Intrusion Detection Systems (NIDS), which play a crucial role in defending Industrial Internet of Things (IIoT) networks, often utilize Deep Neural Networks (DNN) for their pattern recognition capabilities. However, these systems remain susceptible to sophisticated adversarial attacks, particularly on-manifold and off-manifold attacks, which skillfully evade detection. This paper addresses the limitations in existing research, focusing primarily on: the predominant focus on off-manifold attacks, while often overlooking subtler yet potent on-manifold attacks; a lack of consideration for the functional behavior of these attacks; reliance on detailed knowledge of the target NIDS for creating attacks; and the need for detailed knowledge about the creation process of adversarial attacks for effective detection. This paper introduces the Saliency Adversarial Autoencoder (SAAE), designed for generating on-manifold attacks through latent space perturbations. This dual-space perturbation approach enables SAAE to efficiently create stealthy attacks that blend with normal network behavior, posing significant challenges to state-of-the-art (SOTA) NIDS. To counter these advanced threats, we propose an attack-agnostic defence mechanism utilizing a fusion-based Autoencoder (AE) with disentangled representations. This defence is adept at detecting threats within the manifold, significantly enhancing NIDS robustness. Comparative assessments with SOTA DNN and Deep Reinforcement Learning (DRL) models highlight the effectiveness of our approach. The SAAE model markedly reduces True Positive Rates (TPR) in these systems. For DNNs, TPR dropped from 99.72% to 41.5%, and for DRLs, from 95.6% to 63.94%. Conversely, our defence model shows high TPR in detecting these attacks, registering 94% for DNNs and 92% for DRLs. Additionally, we release our dataset, named OOM-X-IIoTID 1 1 The datasets can be found at the following link: https://github.com/mohdah200/OOM-X-IIoTID . , which includes On/Off manifold adversarial attacks, a first in the field, to facilitate further research and development in cybersecurity. Mohammad Al-Fawa'reh, Jumana M. Abu-Khalaf, Naeem Janjua, Patryk Szewczyk |
J. Netw. Comput. Appl. | 4 |
| 2024 | Matrix Profile data mining for BGP anomaly detectionabstractThe Border Gateway Protocol (BGP), acting as the communication protocol that binds the Internet, remains vulnerable despite Internet security advancements. This is not surprising, as the Internet was not designed to be resilient to cyber-attacks, therefore the detection of anomalous activity was not of prime importance to the Internet creators. Detection of BGP anomalies can potentially provide network operators with an early warning system to focus on protecting networks, systems, and infrastructure from significant impact, improve security posture and resilience, while ultimately contributing to a secure global Internet environment. In this paper, we present a novel technique for the detection of BGP anomalies in different events. This research uses publicly available datasets of BGP messages collected from the repositories, Route Views and Réseaux IP Européens (RIPE). Our contribution is the application of a time series data mining approach, Matrix Profile (MP), to detect BGP anomalies in all categories of BGP events. Advantages of the MP detection technique compared to extant approaches include that it is domain agnostic, is assumption-free, requires few parameters, does not require training data, and is scalable and storage efficient. The single hyper-parameter analyzed in MP shows it is robust to change. Our results indicate the MP detection scheme is competitive against existing detection schemes. A novel BGP anomaly detection scheme is also proposed for further research and validation. Ben Scott, Michael N. Johnstone, Patryk Szewczyk, Steven Richardson |
Comput. Networks | 3 |
| 2024 | MalBoT-DRL: Malware Botnet Detection Using Deep Reinforcement Learning in IoT NetworksabstractIn the dynamic landscape of cyber threats, multi-stage malware botnets have surfaced as significant threats of concern. These sophisticated threats can exploit Internet of Things (IoT) devices to undertake an array of cyberattacks, ranging from basic infections to complex operations such as phishing, cryptojacking, and distributed denial of service (DDoS) attacks. Existing machine learning solutions are often constrained by their limited generalizability across various datasets and their inability to adapt to the mutable patterns of malware attacks in real world environments, a challenge known as model drift. This limitation highlights the pressing need for adaptive Intrusion Detection Systems (IDS), capable of adjusting to evolving threat patterns and new or unseen attacks. This paper introduces MalBoT-DRL, a robust malware botnet detector using deep reinforcement learning. Designed to detect botnets throughout their entire lifecycle, MalBoT-DRL has better generalizability and offers a resilient solution to model drift. This model integrates damped incremental statistics with an attention rewards mechanism, a combination that has not been extensively explored in literature. This integration enables MalBoT-DRL to dynamically adapt to the ever-changing malware patterns within IoT environments. The performance of MalBoT-DRL has been validated via trace-driven experiments using two representative datasets, MedBIoT and N-BaIoT, resulting in exceptional average detection rates of 99.80% and 99.40% in the early and late detection phases, respectively. To the best of our knowledge, this work introduces one of the first studies to investigate the efficacy of reinforcement learning in enhancing the generalizability of IDS. Mohammad Al-Fawa'reh, Jumana M. Abu-Khalaf, Patryk Szewczyk, James Jin Kang |
IEEE Internet Things J. | 3 |
| 2023 | DoS/DDoS-MQTT-IoT: A dataset for evaluating intrusions in IoT networks using the MQTT protocolabstractAdversaries may exploit a range of vulnerabilities in Internet of Things (IoT) environments. These vulnerabilities are typically exploited to carry out attacks, such as denial-of-service (DoS) attacks, either against the IoT devices themselves, or using the devices to perform the attacks. These attacks are often successful due to the nature of the protocols used in the IoT. One popular protocol used for machine-to-machine IoT communications is the Message Queueing Telemetry Protocol (MQTT). Countermeasures for attacks against MQTT include testing defenses with existing datasets. However, there is a lack of real-world test datasets in this area. For this reason, this paper introduces a DoS/DDoS-MQTT-IoT dataset—that contains various DoS/DDoS attack scenarios using MQTT traffic—to help develop and test countermeasures against such attacks. To this end, a physical IoT testbed was constructed and a large volume of IoT data was generated that included standard MQTT traffic as well as 10 DoS scenarios. The usability of the dataset has been evaluated via machine learning. Alaa Alatram, Leslie F. Sikos, Mike Johnstone, Patryk Szewczyk, James Jin Kang |
Comput. Networks | 4 |
| 2023 | An exploration of Australian attitudes towards privacyabstractPurpose Using technology to meet national security expectations and requirements is not new. Nations attempt to strike a balance between security and the (expressed or otherwise) privacy needs of citizens. Attacks (physical or cyber) on citizens shift the equilibrium point towards security. In contrast, civil liberties organisations act to preserve or increase privacy. The purpose of this paper is to explore Australian attitudes towards privacy and surveillance during the COVID-19 pandemic. In addition, this paper aims to discover what (if any) factors contribute to societal acceptance of privacy encroachment implicated by surveillance programs. Design/methodology/approach Data collection occurred during 2021 using a cross-sectional survey comprising a variety of self-assessment questions. In addition, anchoring vignettes were introduced as a means of contextualising complex concepts, i.e. privacy and security. Finally, latent class analysis (LCA) was used to identify homogenous patterns within the data, referred to as “classes” for the analysis of trust. Findings First, the survey revealed that citizens appear to be unconcerned about surveillance in public and private spaces (although this may be a temporary effect resulting from the pandemic). The potential for identification, however, does raise concerns. Second, LCA surfaced a specific group that were more likely to trust entities and showed less concern about surveillance in society. Finally, even this latter group displayed a “trust deficit” in specific organisations (private businesses and social media firms). Research limitations/practical implications The tension between security and privacy remains, even in a post-pandemic world; therefore, the authors consider that the results, whilst interesting, are preliminary. Notwithstanding this, the findings provide insight into Australian attitudes towards privacy and surveillance and, consequently, provide input into public policy. Originality/value This is the most recent survey of the Australian public concerning this issue. The analysis of the effect of the pandemic on attitudes provides further value. Aleatha Shanley, Mike Johnstone, Patryk Szewczyk, Michael Crowley |
Inf. Comput. Secur. | 3 |
| 2018 | An Australian Longitudinal Study Into Remnant Data Recovered From Second-Hand Memory CardsabstractConsumers demand fast, high capacity, upgradeable memory cards for portable electronic devices, with secure digital (SD) and microSD the most popular. Despite this demand, secure erasure of data is still not a composite part of disposure practices. To investigate the extent of this problem, second-hand memory cards were procured from the Australian eBay site between 2011 and 2015. Digital forensic tools were used to acquire and analyze each memory card to determine the type and quantity of remnant data. This paper presents the results of the 2014 and 2015 studies and compares these findings to the 2011–2013 research studies. The longitudinal comparison indicates resold memory cards are disposed insecurely, with personal, confidential and business data undeleted or easily recoverable. The impact of such discoveries, where information is placed in the public domain, has the potential to cause embarrassment and financial loss to individuals, business, and government organizations. Patryk Szewczyk, Krishnun Sansurooah, Trish Williams |
Int. J. Inf. Secur. Priv. | 1 |
| 2011 | Using Traffic Analysis to Identify the Second Generation Onion RouterabstractAnonymous networks provide security for users by obfuscating messages with encryption and hiding communications amongst cover traffic provided by other network participants. The traditional goal of academic research into these networks has been attacks that aim to uncover the identity of network users. But the success of an anonymous network relies not only on it's technical capabilities, but on adoption by a large enough user base to provide adequate cover traffic. If anonymous network nodes can be identified, the users can be harassed, discouraging participation. Tor is an example of widely used anonymous network which uses a form of Onion Routing to provide low latency anonymous communications. This paper demonstrates that traffic from a simulated Tor network can be distinguished from regular encrypted traffic, suggesting that real world Tor users may be vulnerable to the same analysis. John Barker, Peter Hannay, Patryk Szewczyk |
EUC | 3 |
| 2011 | Usability of Internet Security Software: Have they got it right?abstractSecurity software usability has been an ongoing issue for end-users. Whilst manufactures have focused on making computers and operating systems more usable, the same cannot be said for security software. Whilst the number of threats continues to escalate, end-users are left attempting to implement a security solution on their own. Previous research has shown that users are unaware of Internet threats and do not know where to start with mitigation. This paper demonstrates that in 2011, Internet Security Software is gradually becoming more usable, although there are key elements which still require improvements. This paper shows the strengths and weaknesses of current security software, and proposes a series of solutions that software vendors should consider in future releases. Patryk Szewczyk |
NSS | 1 |
| 2010 | Ignorant Experts: Computer and Network Security Support from Internet Service ProvidersabstractThe paper examines the advice and support provided by seven major Internet Service Providers in Australia through late 2009 and early 2010 in relation to computer and network security. Previous research has indicated that many end-users will attempt to utilise the support provided by Internet Service Providers as a simple and effective method by which to obtain key information in regards to computer security. This paper demonstrates that in many cases the individuals working at the help desk are either reluctant to provide IT security support or have insufficient skill to provide the correct information. Patryk Szewczyk, Craig Valli |
NSS | 1 |