VLDB 2026 Research / reviewers in the wild / expert
Anna Lito Michala
dblp:223/9328
· DBLP profile ↗
9ranked-venue papers
1as first author
9since 2021 · last 2025
0000-0001-7821-1279ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A practical solution for modelling GDPR-compliance based on defeasible logic reasoningabstractThe General Data Protection Regulation (GDPR), the EU/UK data protection legislation, has necessitated a critical need for compliance modelling to meet its strict and sophisticated requirements. Traditional techniques for modelling security and privacy-related threats fall short of addressing and mitigating the threats of non-compliance. This paper introduces a practical solution to modelling GDPR-compliance based on Defeasible Logic Programming (DeLP), which enhances the robustness and reasoning capabilities of compliance models in real-world scenarios. Furthermore, to overcome the challenges of UNDECIDED query outputs in logical reasoning, we incorporate explicit priorities for conflicting rules and suggest related knowledge for a query in an incomplete knowledge base. To finalize the compliance modelling system, we develop the threat mitigation mechanism that specifies the reasons in case there is a non-compliance threat, along with the suggested actions to mitigate the threats. The application of our approach is demonstrated through a case study on Fitbit , health tracking devices, focusing on non-compliance threats and resolving ”UNDECIDED” query results. Our findings show that the inference engine efficiently identifies non-compliance threats, handles UNDECIDED query results, and suggests appropriate threat mitigation measures. • Developed a knowledge base using Defeasible Logic Programming (DeLP) for GDPR compliance. • Integrated a DeLP-based reasoning mechanism to identify and mitigate non-compliance threats. • Implemented handlers for resolving contradictions in the knowledge base. • Integrated mechanisms to address incompleteness in the knowledge base. • Validated the approach with a Fitbit case study addressing non-compliance threats. Naila Azam, Alex Chak, Anna Lito Michala, Shuja Ansari, Nguyen Binh Truong |
Expert Syst. Appl. | 3 |
| 2024 | Modelling GDPR-compliance based on Defeasible Logic Reasoning: Insights from Time Complexity Perspective*abstractThe General Data Protection Regulation (GDPR), an EU data protection law, requires compliance modeling techniques to help service providers meet its stringent requirements. Traditional privacy modeling techniques often fail to address and mitigate threats of non-compliance. This paper introduces an efficient threat modeling technique based on Defeasible Logic Programming (DeLP) to identify and mitigate non-compliance threats. To achieve this, we construct a DeLP-based knowledge base that integrates facts and rules derived from GDPR requirements. We then implement an inference engine to reason about GDPR non-compliance threats upon this knowledge base. Two novel concepts, namely the horizontal complexity and vertical complexity of a DeLP knowledge base, have been defined to further analyze and evaluate the complexity of the proposed DeLP-based modeling mechanism. An empirical demonstration validates the system’s feasibility and confirms the time complexity of the proposed reasoner. The findings demonstrate that the proposed DeLP-based technique provides an effective approach to GDPR compliance modeling and improves legal reasoning. Naila Azam, Alex Chak, Anna Lito Michala, Shuja Ansari, Nguyen Binh Truong |
TrustCom | 3 |
| 2023 | Modelling Technique for GDPR-Compliance: Toward a Comprehensive SolutionabstractData-driven applications and services have been increasingly deployed in all aspects of life including healthcare and medical services in which a huge amount of personal data is collected, aggregated, and processed in a centralised server from various sources. As a consequence, preserving the data privacy and security of these applications is of paramount importance. Since May 2018, the new data protection legislation in the EU/UK, namely the General Data Protection Regulation (GDPR), has come into force and this has called for a critical need for modelling compliance with the GDPR's sophisticated requirements. Existing threat modelling techniques are not designed to model GDPR compliance, particularly in a complex system where personal data is collected, processed, manipulated, and shared with third parties. In this paper, we present a novel comprehensive solution for developing a threat modelling technique to address threats of non-compliance and mitigate them by taking GDPR requirements as the baseline and combining them with the existing security and privacy modelling techniques (i.e., STRIDE and LINDDUN, respectively). For this purpose, we propose a new data flow diagram integrated with the GDPR principles, develop a knowledge base for the non-compliance threats, and leverage an inference engine for reasoning the GDPR non-compliance threats over the knowledge base. Finally, we demonstrate our solution for threats of non-compliance with legal basis and accountability in a telehealth system to show the feasibility and effectiveness of the proposed solution. Naila Azam, Anna Lito Michala, Shuja Ansari, Nguyen Binh Truong |
GLOBECOM | 2 |
| 2023 | Data Privacy Threat Modelling for Autonomous Systems: A Survey From the GDPR's PerspectiveabstractArtificial Intelligence-based applications have been increasingly deployed in every field of life including smart homes, smart cities, healthcare services, and autonomous systems where personal data is collected across heterogeneous sources and processed using ”black-box” algorithms in opaque centralised servers. As a consequence, preserving the data privacy and security of these applications is of utmost importance. In this respect, a modelling technique for identifying potential data privacy threats and specifying countermeasures to mitigate the related vulnerabilities in such AI-based systems plays a significant role in preserving and securing personal data. Various threat modelling techniques have been proposed such as STRIDE, LINDDUN, and PASTA but none of them is sufficient to model the data privacy threats in autonomous systems. Furthermore, they are not designed to model compliance with data protection legislation like the EU/UK General Data Protection Regulation (GDPR), which is fundamental to protecting data owners’ privacy as well as to preventing personal data from potential privacy-related attacks. In this article, we survey the existing threat modelling techniques for data privacy threats in autonomous systems and then analyse such techniques from the viewpoint of GDPR compliance. Following the analysis, We employ STRIDE and LINDDUN in autonomous cars, a specific use-case of autonomous systems, to scrutinise the challenges and gaps of the existing techniques when modelling data privacy threats. Prospective research directions for refining data privacy threats & GDPR-compliance modelling techniques for autonomous systems are also presented. Naila Azam, Anna Lito Michala, Shuja Ansari, Nguyen Binh Truong |
IEEE Trans. Big Data | 2 |
| 2022 | ELSA: A Keyword-based Searchable Encryption for Cloud-edge assisted Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) plays a powerful role in smart manufacturing by performing real-time analysis for large volumes of data. In addition, IIoT systems can monitor several factors, such as data accuracy, network bandwidth and operations latency. To perform these operations securely and in a privacy-preserving manner, one solution is to use cryptographic primitives. However, most cryptographic solutions add performance overhead causing latency. In this paper, we propose an Edge Lightweight Searchable Attribute-based encryption system (ELSA). ELSA leverages the cloud-edge architecture to improve search time beyond the state-of-the-art. The main contributions of this paper are as follows. First, we present an untrusted cloud/trusted edge architecture, which optimises the efficiency of data processing and decision making in the IIoT context. Second, we enhance search performance over current state-of-the-art (LSABE-MA) by an order of magnitude. We achieve this by improving the organisation of the data to provide better than linear search performance. We leverage the edge server to cluster data indices by keyword and introduce a query optimiser. The query optimiser uses k-means clustering to improve the efficiency of range queries, removing the need for linear search. In addition, we achieve this without sacrificing accuracy over the results. Jawhara Aljabri, Anna Lito Michala, Jeremy Singer |
CCGRID | 2 |
| 2022 | Vibration Edge Computing in Maritime IoTabstractIoT and the Cloud are among the most disruptive changes in the way we use data today. These changes have not significantly influenced practices in condition monitoring for shipping. This is partly due to the cost of continuous data transmission. Several vessels are already equipped with a network of sensors. However, continuous monitoring is often not utilised and onshore visibility is obscured. Edge computing is a promising solution but there is a challenge sustaining the required accuracy for predictive maintenance. We investigate the use of IoT systems and Edge computing, evaluating the impact of the proposed solution on the decision making process. Data from a sensor and the NASA-IMS open repository were used to show the effectiveness of the proposed system and to evaluate it in a realistic maritime application. The results demonstrate our real-time dynamic intelligent reduction of transmitted data volume by without sacrificing specificity or sensitivity in decision making. The output of the Decision Support System fully corresponds to the monitored system's actual operating condition and the output when the raw data are used instead. The results demonstrate that the proposed more efficient approach is just as effective for the decision making process. Anna Lito Michala, Ioannis Vourganas, Andrea Coraddu |
ACM Trans. Internet Things | 1 |
| 2021 | Real-time Recursive Risk Assessment Framework for Autonomous Vehicle OperationsabstractExisting risk assessment (RA) methodology used for autonomous vehicle (AV) development and validation is insufficient for future AV operations. Existing frameworks operate based on processes such as hazard analysis and risk assessment (HARA) where risk is defined based on functional hazardous event severity and the likelihood of occurrence. This is a static process performed during the development stage and relies on prior lessons learnt and know-how. A drawback of this is the omission of potential complex environments that could occur during real-time – especially with more stringent safety requirements for AV operating at higher automation levels. Therefore, there is a need for an additional framework to further enhance the safety levels of the AV, focusing on real-time instead of static risk assessment during development. In this paper, a novel real-time recursive RA framework (ReRAF) addresses the gap by creating a novel risk representation, predictive risk number (PRN), and eventual safety levels (SLs) in the temporal and spatial domain. This approach focuses on risk assessment based on AV collision to the detected hazardous object and controllability of the AV. A dynamic recursive RA continuously captures potentially hazardous events in real-time and compares them with past occurrences to predict future safety actions. ReRAF provides a continuous improvement on the RA and acts as an additional safety layer for AV operations. Wei Ming Dan Chia, Sye Loong Keoh, Anna Lito Michala, Cindy Goh |
VTC Spring | 3 |
| 2021 | Optimizing Task Allocation for Edge Micro-Clusters in Smart CitiesabstractCurrent urban technology trends like Internet-of-Things and 5G require ultra low latency compute resource to be distributed liberally at the network edge. We characterize and advocate the need for heterogeneous edge micro-clusters; these are pragmatic, low-power, low-cost, minimal footprint units that can provide sufficient resource for typical edge compute applications in smart cities. However, to make best use of heterogeneous edge micro-clusters, we require resource management techniques that are both efficient and effective. In this paper, we report on an empirical study to demonstrate that mathematical optimization (in particular, mixed integer programming) for resource management is appropriate in terms of overhead, also highly effective for executing batch-arrival workloads in smart city use cases. Yousef Alhaizaey, Jeremy Singer, Anna Lito Michala |
WOWMOM | 3 |
| 2021 | Searchable Encryption with Access Control in Industrial Internet of Things (IIoT)abstractThe technological advancements in the Internet of Things (IoT) and related technologies lead to revolutionary advancements in many sectors. One of these sectors, is the industrial sector red that leverages IoT technologies forming the Industrial Internet of Things (IIoT). IIoT has the potential to enhance the manufacturing process by improving the quality, trace‐ability, and integrity of the industrial processes. The enhancement of the manufacturing process is achieved by deploying IoT devices (sensors) across the manufacturing facilities; therefore, monitoring systems are required to collect (from multiple locations) and analyse the data, most likely in the cloud. As a result, IIoT monitoring systems should be secure, preserve the privacy, and provide real‐time responses for critical decision‐making. In this review, we identified a gap in the state‐of‐the‐art of secure IIoT and propose a set of criteria for secure and privacy preserving IIoT systems to enhance efficiency and deliver better IIoT applications. Jawhara Bader, Anna Lito Michala |
Wirel. Commun. Mob. Comput. | 2 |