VLDB 2026 Research / reviewers in the wild / expert
Christos Dalamagkas
dblp:227/7383
· DBLP profile ↗
9ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0002-0210-5290ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AI-driven digital twin-based security orchestration, automation and response for critical infrastructuresabstractAbstract The more critical infrastructures (CIs) being digitized, the more vulnerable they are regarding cyber security attacks. Digitisation-leveraging technologies in the Internet of Things (IoT) and Cyber-Physical Systems (CPS) have been largely adopted for CIs, along with the Digital Twin (DT) paradigm. However, the distributed and heterogeneous nature of IoT or CPS poses significant challenges in safeguarding against diverse attack surfaces, including physical devices, network infrastructures, and third-party integration. To tackle these challenges, we propose an AI-driven DT-based security orchestration automation and response framework (SOAR4BC). Gathering system contexts from the DT in combination with security intelligence from the security tools gives us a holistic context for SOAR, which has not been seen in the existing approaches. We leverage this holistic context into the decision-making core, which utilizes advanced algorithms, like deep reinforcement learning, to generate adaptation recommendations based on incident alerts, risk assessments, and system state observations. By rigorously evaluating tampered data and distributed denial of service (DDoS) scenarios, we validate the SOAR4BC framework’s efficacy in handling security incidents leveraging digital twin environments. We further demonstrate real-world applicability through false-data injection and DoS attacks on an operational electric-vehicle charging testbed, confirming the practical effectiveness of SOAR4BC in securing critical infrastructures. Together, these results establish SOAR4BC as a robust and explainable AI-driven SOAR framework that advances the use of digital twins for cybersecurity in IoT and CPS ecosystems, offering actionable contributions for both research and industrial deployment. Phu Nguyen, Ashish Rauniyar, Jone Bartel, Jan Laufer 0001, Christos Dalamagkas, Klaus Pohl |
Autom. Softw. Eng. | 5 |
| 2026 | Reinforcement Learning in action: Powering intelligent intrusion responses to advanced cyber threats in realistic scenariosabstractGiven the increasing incidence of sophisticated cyber-attacks, particularly Advanced Persistent Threats (APTs), there is a growing need for intelligent and adaptive intrusion response solutions. In this paper, we propose a Reinforcement Learning (RL)-based model for APT intrusion response that can manage dynamic, multi-stage attacks and large observation spaces. The model supports both policy-based and value-based learning approaches, enabling comparative evaluation between different strategies. We introduce a realistic RL training environment based on emulation infrastructure, which accurately reproduces APT scenarios using real systems and executes a wide range of authentic Intrusion Response System (IRS) actions. This setup includes time and variability constraints commonly encountered in operational environments, offering a more practical alternative to traditional simulations. The RL agents, implemented using Proximal Policy Optimization (PPO) and Deep Q-Network (DQN) algorithms, were both trained and evaluated within this industrial-style emulated environment. Empirical results demonstrate that both DRL algorithms successfully learned effective and well-timed defensive actions under realistic constraints, confirming their capability to operate in dynamic, real-world APT scenarios. Eider Iturbe, Angel Rego, Oscar Llorente-Vazquez, Erkuden Rios, Christos Dalamagkas, Dimitris Merkouris, Nerea Toledo |
Expert Syst. Appl. | 5 |
| 2026 | A pattern-aware LSTM-based approach for APT detection leveraging a realistic dataset for critical infrastructure securityabstractAdvanced Persistent Threats (APTs) represent some of the most sophisticated and coordinated cyberattacks, often targeting critical infrastructure with stealthy, multi-stage techniques. Despite the availability of numerous intrusion detection datasets, most fail to capture the sequential and strategic nature of APT campaigns as outlined in frameworks like MITRE ATT&CK. This paper introduces a novel dataset based on a realistic emulation of the Sandworm APT group targeting the Supervisory Control and Data Acquisition (SCADA) system of a Wide Area Measurement System (WAMS). The dataset captures the full lifecycle of an APT attack, from initial access to impact, in a structured and time-ordered manner, enabling the study of both atomic and multi-step intrusion behaviours. We train and evaluate supervised multiclass sequence-aware models, specifically Long Short-Term Memory (LSTM) and Bidirectional LSTM (BiLSTM) architectures, to detect these behaviours using network flow data, assessing their performance and analysing their strengths and limitations. Our results show that BiLSTM models offer greater stability and generalization, while LSTM models achieve competitive performance with optimal configurations. These findings highlight the importance of realistic, sequence-aware datasets for developing robust intrusion detection systems tailored to modern APT threats. Eider Iturbe, Christos Dalamagkas, Panagiotis I. Radoglou-Grammatikis, Erkuden Rios, Nerea Toledo |
Future Gener. Comput. Syst. | 2 |
| 2025 | The Open V2X Management Platform: An intelligent charging station management system
Christos Dalamagkas, V. D. Melissianos, George Papadakis 0001, Angelos Georgakis, Vasileios-Martin Nikiforidis, Kostas Hrissagis-Chrysagis |
Inf. Syst. | 1 |
| 2024 | The Open V2X Management Platform
Christos Dalamagkas, Angelos Georgakis, Kostas Hrissagis-Chrysagis, George Papadakis 0001 |
ICWE | 1 |
| 2023 | ELECTRON: An Architectural Framework for Securing the Smart Electrical Grid with Federated Detection, Dynamic Risk Assessment and Self-HealingabstractThe electrical grid has significantly evolved over the years, thus creating a smart paradigm, which is well known as the smart electrical grid. However, this evolution creates critical cybersecurity risks due to the vulnerable nature of the industrial systems and the involvement of new technologies. Therefore, in this paper, the ELECTRON architecture is presented as an integrated platform to detect, mitigate and prevent potential cyberthreats timely. ELECTRON combines both cybersecurity and energy defence mechanisms in a collaborative way. The key aspects of ELECTRON are (a) dynamic risk assessment, (b) asset certification, (c) federated intrusion detection and correlation, (d) Software Defined Networking (SDN) mitigation, (e) proactive islanding and (f) cybersecurity training and certification. Panagiotis I. Radoglou-Grammatikis, Thanasis Liatifis, Christos Dalamagkas, Alexios Lekidis, Konstantinos Voulgaridis, Thomas Lagkas, Nikolaos Fotos, Sofia-Anna Menesidou, Thomas Krousarlis, Pedro Ruzafa Alcazar, Juan Francisco Martinez, Antonio F. Skarmeta, Alberto Molinuevo Martín, Iñaki Angulo, Jesus Villalobos Nieto, Hristo Koshutanski, Rodrigo Diaz Rodriguez, Ilias Siniosoglou, Orestis Mavropoulos, Konstantinos Kyranou, Theocharis Saoulidis, Allon Adir, Ramy Masalha, Emanuele Bellini 0001, Nicholas Kolokotronis, Stavros Shiaeles, Jose Garcia Franquelo, George Lalas, Andreas Zalonis, Antonis Voulgaridis, Angelina D. Bintoudi, Konstantinos Votis, David Pampliega, Panagiotis G. Sarigiannidis |
ARES | 3 |
| 2022 | Fault-Tolerant SDN Solution for Cybersecurity ApplicationsabstractThe rapid growth of computer networks in various sectors has led to new services previously hard or impossible to implement. Internet of Things has also assisted in this evolution offering easy access to data but at the same time imposing constraints on both security and quality of service. In this paper, an SDN fault tolerant and resilient SDN controller design approach is presented. The proposed solution is suitable for a wide range of environments. Benefits stemming from actual scenarios are presented and discussed among other solutions. Thanasis Liatifis, Christos Dalamagkas, Panagiotis I. Radoglou-Grammatikis, Thomas Lagkas, Evangelos Markakis 0002, Valeri M. Mladenov, Panagiotis G. Sarigiannidis |
ARES | 2 |
| 2022 | False Data Injection Attacks against Low Voltage Distribution SystemsabstractThe transformation of the conventional electrical grid into a digital ecosystem brings significant benefits, such as two-way communication between energy consumers and utilities, self-monitoring and pervasive controls. However, the advent of the smart electrical grid raises severe cybersecurity and privacy concerns, given the presence of legacy systems and communications protocols. This paper focuses on False Data Injection (FDI) cyberattacks against a low-voltage distribution system, taking full advantage of Man In The Middle (MITM) actions. The first cyberattack targets the communication between a smart meter and an Active Distribution Management System (ADMS), while the second FDI cyberattack targets the communication between a smart inverter and ADMS. In both cases, the cyberattacks affect the operation of the distribution transformer, thus resulting in devastating consequences. Moreover, this paper provides an Artificial Intelligence (AI)-based Intrusion Detection System (IDS), detecting and mitigating the above cyberattacks in a timely manner. The evaluation results demonstrate the efficiency of the proposed IDS. Panagiotis I. Radoglou-Grammatikis, Christos Dalamagkas, Thomas Lagkas, Magda Zafeiropoulou, Maria Atanasova, Pencho Zlatev, Alexandros-Apostolos A. Boulogeorgos, Vasileios Argyriou, Evangelos Markakis 0002, Ioannis D. Moscholios, Panagiotis G. Sarigiannidis |
GLOBECOM | 2 |
| 2019 | A Survey On Honeypots, Honeynets And Their Applications On Smart GridabstractPower grid is a major part of modern Critical Infrastructure (CIN). The rapid evolution of Information and Communication Technologies (ICT) enables traditional power grids to encompass advanced technologies that allow them to monitor their state, increase their reliability, save costs and provide ICT services to end customers, thus converting them into smart grids. However, smart grid is exposed to several security threats, as hackers might try to exploit vulnerabilities of the industrial infrastructure and cause disruption to national electricity system with severe consequences to citizens and commerce. This paper investigates and compares honey-x technologies that could be applied to smart grid in order to distract intruders, obtain attack strategies, protect the real infrastructure and form forensic evidence to be used in court. Christos Dalamagkas, Panagiotis G. Sarigiannidis, Dimosthenis Ioannidis, Eider Iturbe, Odysseas Nikolis, Francisco Ramos 0003, Erkuden Rios, Antonios Sarigiannidis, Dimitrios Tzovaras |
NetSoft | 1 |