VLDB 2026 Research / reviewers in the wild / expert
Max Smith-Creasey
dblp:198/9582
· DBLP profile ↗
8ranked-venue papers
2as first author
3since 2021 · last 2024
0000-0001-6576-6603ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 2 since 2021Computer networks · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A privacy-aware authentication and usage-controlled access protocol for IIoT decentralized data marketplaceabstractData is ubiquitous, powerful and valuable today. With vast instalments of Industrial Internet-of-Things (IIoT) infrastructure, data is in abundance albeit sitting in organizational silos. Data Marketplaces have emerged to allow monetization of data by trading it with interested buyers. While centralized marketplaces are common, they are controlled by few and are non-transparent. Decentralized data marketplaces allow the democratization of rates, trading terms and fine control to participants. However, in such a marketplace, ensuring privacy and security is crucial. Existing data exchange schemes depend on a trusted third party for key management during authentication and rely on a ‘one-time-off’ approach to authorization. This paper proposes a user-empowered, privacy-aware, authentication and usage-controlled access protocol for IIoT data marketplace. The proposed protocol leverages the concept of Self-Sovereign Identity (SSI) and is based on the standards of Decentralized Identifier (DID) and Verifiable Credential (VC). DIDs empower buyers and give them complete control over their identities. The buyers authenticate and prove claims to access data securely using VC. The proposed protocol also implements a dynamic user-revocation policy. Usage-controlled based access provides secure ongoing authorization during data exchange. A detailed performance and security analysis is provided to show its feasibility. Akanksha Dixit 0001, Bruno Bogaz Zarpelão, Max Smith-Creasey, Muttukrishnan Rajarajan |
Comput. Secur. | 3 |
| 2022 | A Decentralized IIoT Identity Framework based on Self-Sovereign Identity using BlockchainabstractThe fundamental requirement for interaction between digital entities is a secure and privacy-preserving digital identity infrastructure. Traditional approaches rely heavily on centralized architectural components such as Certificate Authorities (CAs) and credential storage databases that have drawbacks like a single point of failure, attack prone honeypot databases and poor scalability. Self-Sovereign Identity (SSI) is a novel decentralized digital identity model that uses Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs). In this work, we propose a novel decentralized identity framework for Industrial Internet-of-Things (IIoT) based on SSI model. The proposed framework is implemented on two blockchain platforms namely Ethereum and Hyperledger Indy to study the underlying overheads. Akanksha Dixit 0001, Max Smith-Creasey, Muttukrishnan Rajarajan |
LCN | 2 |
| 2021 | Generative adversarial attacks on motion-based continuous authentication schemesabstractTraditional authentication mechanisms use passwords, Personal Identification Numbers (PINs) and biometrics, but these only authenticate at the point of entry. Continuous authentication schemes instead allow systems to verify identity and mitigate unauthorised access continuously. However, recent developments in generative modelling can significantly threaten continuous authentication systems, allowing attackers to craft adversarial examples to gain unauthorised access and may even limit a legitimate user from accessing protected data in the network. The research available on the use of generative models for attacking continuous authentication is relatively scarce. This paper explores the feasibility of bypassing continuous authentication using generative models, measuring the impact of the damage, and advising the usage of metrics to compare the various advertised attacks in such a system. Our empirical results demonstrate that generative models cause a higher Equal Error Rate and misclassification error in attack scenarios. At the same time, training and detection time during attack scenarios is increased compared to perturbation models. The results prove that data samples crafted by generative models can be a severe threat to continuous authentication schemes using motion sensor data. Narges Pourshahrokhi, Max Smith-Creasey, Mona Ghassemian, Samaneh Kouchaki |
SIN | 2 |
| 2020 | Discerning User Activity in Extended Reality Through Side-Channel Accelerometer ObservationsabstractExtended reality technologies such as virtual reality are becoming increasingly common for enterprise applications. They have the potential to create secure multi-user environment in previously less-secure spaces, without the need for privacy filters or secure rooms. In this pilot paper we explore how malicious actors may be able to eavesdrop on a virtual reality session, by tracking the physical movements of a user. This is carried out using a third-party accelerometer, attached to the user. Through initial experimentation, we observe that specific actions and session types can be identified through visual analysis of the accelerometer. We posit there is substantial potential for sophisticated and automatic classification of user activity in VR. We discuss how this may enable eavesdropping by malicious actors, or could serve as a mechanism for improved security. Tiago Martins Andrade, Max Smith-Creasey, Jonathan Francis Roscoe |
ISI | 2 |
| 2020 | Unconventional Mechanisms for Biometric Data Acquisition via Side-ChannelsabstractIn this paper, we discuss the proliferation of household smart devices and review the literature to explore whether the implementation characteristics of such systems may provide avenues of attack to obtain private biometric data. Examples include the use of mechanical hard drives as audio microphones and interception of soft-keyboard input through audio analysis of haptic feedback. As the use of biometric data increases in casual environments, the opportunity for it to be stolen in unexpected ways is also increasing. There are many examples of the technology being utilised by hackers to enable unexpected use such as spoofing. We examine the importance and sanctity of biometric data in the modern world and posit that manufacturers must avoid complacency and advocate secure design, to ensure security and privacy of users. Jonathan Francis Roscoe, Max Smith-Creasey |
SIN | 2 |
| 2019 | A novel word-independent gesture-typing continuous authentication scheme for mobile devices
Max Smith-Creasey, Muttukrishnan Rajarajan |
Comput. Secur. | 1 |
| 2019 | HoneyDOC: An Efficient Honeypot Architecture Enabling All-Round DesignabstractHoneypots are designed to trap the attacker with the purpose of investigating its malicious behavior. Owing to the increasing variety and sophistication of cyber attacks, how to capture high-quality attack data has become a challenge in the context of honeypot area. All-round honeypots, which mean a significant improvement in sensibility, countermeasure, and stealth, are necessary to tackle the problem. In this paper, we propose a novel honeypot architecture termed HoneyDOC to support all-round honeypot design and implementation. Our HoneyDOC architecture clearly identifies three essential independent and collaborative modules, Decoy, Captor, and Orchestrator. Based on the efficient architecture, a software-defined networking-enabled honeypot system is designed, which supplies a high programmability for technically sustaining the features for capturing high-quality data. A proof-of-concept system is implemented to validate its feasibility and effectiveness. The experimental results show the benefits by using the proposed architecture compared with the previous honeypot solutions. Wenjun Fan, Zhihui Du, Max Smith-Creasey, David Fernández 0002 |
IEEE J. Sel. Areas Commun. | 3 |
| 2016 | A continuous user authentication scheme for mobile devicesabstractFace and touch modalities have independently been shown to yield promising results for continuous user authentication. In this study, we present a novel framework that combines these modalities. We show a stacked classifier approach can be used to improve the continuous authentication on mobile devices and address some prevalent issues with the current state-of-the-art. We use a state-of-the-art public dataset containing face and touch-gesture modalities for 50 users. Features are extracted from each modality for each user. We train a set of classifiers for user modalities to provide probability scores on a sample. The scores capture the nuances of each sample and are concatenated into a vector. This vector is used in a meta-level classifier. The scores we obtain from the meta-level classifiers show our approach performs better than previous continuous authentication approaches. We achieve an equal error rate of 3.77% for a single sample. We also show the added robustness a multi-modal approach provides if one modality is compromised. Max Smith-Creasey, Muttukrishnan Rajarajan |
PST | 1 |