Alexandros Bakas

dblp:243/0467 · DBLP profile ↗
← Back
17ranked-venue papers
8as first author
13since 2021 · last 2026
0000-0002-0731-1851ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 7 first-author · 12 since 2021Computer networks · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 From See to Shield: ML-Assisted Fine-Grained Access Control for Visual Data: Data/Toolset Paper
Mete Harun Akcay, Buse G. A. Tekgul, Siddharth Prakash Rao, Alexandros Bakas
CODASPY4
2026 When Only Parts Matter: Efficient Privacy-Preserving Analytics with Fully Homomorphic Encryption
Alexandros Bakas, Dimitrios Schoinianakis
ICISSP (2)1
2026 It Runs and It Hides: A Function-Hiding Construction for Private-Key Multi-Input Functional Encryption
Antonis Michalas, Alexandros Bakas
ICISSP (1)2
2024 Need for Speed: Leveraging the Power of Functional Encryption for Resource-Constrained Devices
abstract
Functional Encryption (FE) is a cutting-edge cryptographic technique that enables a user with a specific functional decryption key to determine a certain function of encrypted data without gaining access to the underlying data. Given its potential and the fact that FE is still a relatively new field, we set out to investigate how it could be applied to resource-constrained environments. This work presents what we believe to be the first lightweight FE scheme explicitly designed for resource-constrained devices. We also propose a use case protocol that demonstrates how our scheme can secure an Internet of Things (IoT) architecture where relevant devices collect data and securely deliver them to a storage server, where an analyst can request access to the encrypted data. Finally, we conduct thorough experiments on two commercially available resource-constrained devices to provide compelling evidence of our approach’s practicality and efficiency. Although the results of our evaluations show that there is room for improvement in the proposed scheme, this work represents one of the first attempts to apply FE to the IoT setting that can directly impact people’s daily lives and the everyday operations of organizations.
Eugene Frimpong, Alexandros Bakas, Camille Nuoskala, Antonis Michalas
IoTBDS2
2023 Love or Hate? Share or Split? Privacy-Preserving Training Using Split Learning and Homomorphic Encryption
abstract
Split learning (SL) is a new collaborative learning technique that allows participants, e.g. a client and a server, to train machine learning models without the client sharing raw data. In this setting, the client initially applies its part of the machine learning model on the raw data to generate activation maps and then sends them to the server to continue the training process. Previous works in the field demonstrated that reconstructing activation maps could result in privacy leakage of client data. In addition to that, existing mitigation techniques that overcome the privacy leakage of SL prove to be significantly worse in terms of accuracy. In this paper, we improve upon previous works by constructing a protocol based on U-shaped SL that can operate on homomorphically encrypted data. More precisely, in our approach, the client applies homomorphic encryption on the activation maps before sending them to the server, thus protecting user privacy. This is an important improvement that reduces privacy leakage in comparison to other SL-based works. Finally, our results show that, with the optimum set of parameters, training with HE data in the U-shaped SL setting only reduces accuracy by 2.65% compared to training on plaintext. In addition, raw training data privacy is preserved.
Tanveer Khan, Khoa Nguyen 0005, Antonis Michalas, Alexandros Bakas
PST4
2023 Authenticating Mobile Users to Public Internet Commodity Services Using SIM Technology
abstract
The traditional use of the Subscriber Identity Module (SIM), which resides in a mobile device, is to authenticate a user to cellular mobile networks. However, we believe that the cryptographic capabilities of SIM are not fully utilized for authenticating a user to other types of services. To address this concern, we introduce a novel SIM-based solution to authenticate users to Commodity Services (CS) on the public Internet. We present SIM-Based Authentication (SIMBA), a protocol that comprises registration, key establishment, authentication, and revocation. Our solution consists of a variant of the Remote SIM Provisioning (RSP) protocol that can be run between a commodity service, users, and a Mobile Network Operator (MNO). Furthermore, we introduce the concept of asub-profile for CS that can reside inside an operating SIM profile of an MNO. Unlike the SIM profiles defined in the RSP, our solution can have multiple active sub-profiles that allow users to simultaneously log in to different commodity services without swapping between profiles. We formally define a threat model and present an analysis to prove the protocol's security guarantees. SIMBA offers several benefits to mobile end-users, CS providers, and MNOs. In this realm, we believe that our work contributes to the ongoing research on novel authentication methods.
Siddharth Prakash Rao, Alexandros Bakas
WISEC2
2022 Private Lives Matter: A Differential Private Functional Encryption Scheme
abstract
The use of data combined with tailored statistical analysis has presented a unique opportunity to organizations in diverse fields to observe users' behaviors and needs, and accordingly adapt and fine-tune their services. However, in order to offer utilizable, plausible, and personalized alternatives to users, this process usually also entails a breach of their privacy. The use of statistical databases for releasing data analytics is growing exponentially, and while many cryptographic methods are utilized to protect the confidentiality of the data -- a task that has been ably carried out by many authors over the years -- only a few %rudimentary number of works focus on the problem of privatizing the actual databases. Believing that securing and privatizing databases are two equilateral problems, in this paper, we propose a hybrid approach by combining Functional Encryption with the principles of Differential Privacy. Our main goal is not only to design a scheme for processing statistical data and releasing statistics in a privacy-preserving way but also to provide a richer, more balanced, and comprehensive approach in which data analytics and cryptography go hand in hand with a shift towards increased privacy.
Alexandros Bakas, Antonis Michalas, Tassos Dimitriou
CODASPY1
2022 Feel the Quantum Functioning: Instantiating Generic Multi-Input Functional Encryption from Learning with Errors
Alexandros Bakas, Antonis Michalas, Eugene Frimpong, Reyhaneh Rabaninejad
DBSec1
2022 Symmetrical Disguise: Realizing Homomorphic Encryption Services from Symmetric Primitives
Alexandros Bakas, Eugene Frimpong, Antonis Michalas
SecureComm1
2022 MetaPriv: Acting in Favor of Privacy on Social Media Platforms
Robert Cantaragiu, Antonis Michalas, Eugene Frimpong, Alexandros Bakas
SecureComm4
2021 Attestation Waves: Platform Trust via Remote Power Analysis
Ignacio M. Delgado-Lozano, Macarena C. Martínez-Rodríguez, Alexandros Bakas, Billy Bob Brumley, Antonis Michalas
CANS3
2021 Nowhere to Leak: A Multi-client Forward and Backward Private Symmetric Searchable Encryption Scheme
Alexandros Bakas, Antonis Michalas
DBSec1
2021 Blind Faith: Privacy-Preserving Machine Learning using Function Approximation
abstract
Over the past few years, a tremendous growth of machine learning was brought about by a significant increase in adoption of cloud-based services. As a result, various solutions have been proposed in which the machine learning models run on a remote cloud provider. However, when such a model is deployed on an untrusted cloud, it is of vital importance that the users' privacy is preserved. To this end, we propose Blind Faith - a machine learning model in which the training phase occurs in plaintext data, but the classification of the users' inputs is performed on homomorphically encrypted ciphertexts. To make our construction compatible with homomorphic encryption, we approximate the activation functions using Chebyshev polynomials. This allowed us to build a privacy-preserving machine learning model that can classify encrypted images. Blind Faith preserves users' privacy since it can perform high accuracy predictions by performing computations directly on encrypted data.
Tanveer Khan, Alexandros Bakas, Antonis Michalas
ISCC2
2020 Do Not Tell Me What I Cannot Do! (The Constrained Device Shouted under the Cover of the Fog): Implementing Symmetric Searchable Encryption on Constrained Devices
Eugene Frimpong, Alexandros Bakas, Hai-Van Dang, Antonis Michalas
IoTBDS2
2020 Power Range: Forward Private Multi-Client Symmetric Searchable Encryption with Range Queries Support
abstract
Symmetric Searchable encryption (SSE) is an encryption technique that allows users to search directly over their outsourced encrypted data while preserving the privacy of both the files and the queries. In this paper, we present Power Range - a dynamic SSE scheme (DSSE) that supports range queries in the multi-client model. We prove that our construction captures the very crucial notion of forward privacy in the sense that additions and deletions of files do not reveal any information about the content of past queries. Finally, to deal with the problem of synchronization in the multi-client model, we exploit the functionality offered by Trusted Execution Environments and Intel’s SGX.
Alexandros Bakas, Antonis Michalas
ISCC1
2020 Multi-Input Functional Encryption: Efficient Applications from Symmetric Primitives
abstract
Functional Encryption (FE) allows users who hold a specific secret key (known as the functional key) to learn a specific function of encrypted data whilst learning nothing about the content of the underlying data. Considering this functionality and the fact that the field of FE is still in its infancy, we sought a route to apply this potent tool to design efficient applications. To this end, we first built a symmetric FE scheme for the l1norm of a vector space, which allows us to compute the sum of the components of an encrypted vector. Then, we utilized our construction, to design an Order-Revealing Encryption (ORE) scheme and a privately encrypted database. While there is room for improvement in our schemes, this work is among the first attempts that seek to utilize FE for the solution of practical problems that can have a tangible effect on people's daily lives.
Alexandros Bakas, Antonis Michalas
TrustCom1
2019 Modern Family: A Revocable Hybrid Encryption Scheme Based on Attribute-Based Encryption, Symmetric Searchable Encryption and SGX
Alexandros Bakas, Antonis Michalas
SecureComm (2)1