VLDB 2026 Research / reviewers in the wild / expert
Thusitha Dayaratne
dblp:253/8483 · also T. T. Dayaratne, Thusitha Thilina Dayaratne
· DBLP profile ↗
4ranked-venue papers
4as first author
3since 2021 · last 2026
0000-0003-0624-1967ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhancing Security and Resilience in DER Integration: A Self-Sovereign Identity Approach for Smart Inverters in Virtual Power PlantsabstractUtility companies are expected to leverage privately owned distributed energy resources (DERs) to create virtual power plants (VPPs), which offer promising solutions for maintaining the demand–supply balance efficiently and reducing emissions. Smart inverters play a crucial role in integrating DERs into VPPs, making the security of smart inverters and the reliability of inverter data essential for the successful implementation of secure and effective VPPs. However, traditional public-key infrastructure and X.509 digital certificate-based security approaches (PKIX) are sub-optimal in this integration context due to their inherent limitations. Therefore, in this work, we analyse the self-sovereign identity concept in DER integration context and develop a secure and reliable framework for DER integration via smart inverters. The proposed framework aims to overcome the issues associated with the current PKIX-based design and enhance the overall resiliency of the DER integration process by extending the existing industry standards. Thusitha Dayaratne, Carsten Rudolph, Jiangshan Yu |
Distributed Ledger Technol. Res. Pract. | 1 |
| 2022 | False Data Injection Attack Detection for Secure Distributed Demand Response in Smart GridsabstractDistributed demand response (DR) schemes for smart energy networks rely on data from various sources, many of them outside the network operator’s perimeter. Therefore, compromised inputs from false data injection attacks (FDIAs) can be detrimental to the expectations of stakeholders, pro-vide financial benefits to malicious actors, compromise the commercial viability of the scheme and have the potential to disrupt the energy supply. Due to the heterogeneity of data sources, FDIAs are arduous to prevent with standard security controls. Thus, detecting FDIAs is necessary to facilitate impact mitigations. However, FDIA detection in the residential DR context is arduous, given the inherent challenges such as the noisiness of residential demand, lack of labelled data in real-life settings, and variety and dynamicity of demand forecasts (e.g., weekdays vs weekend, different months/seasons). Addressing mentioned challenges, in this paper, we propose a data-driven unsupervised anomaly detection approach, named Clustering-based Spectral Residual (CSR), to detect false data injection attacks in smart grids’ DR. The CSR model is based on the popular k-means clustering and Spectral Residual method. The combination highlights the attack time slots, which increases the detection accuracy in our model. A supervised model is also proposed based on Convolutional Neural Network (CNN) to increase the detection accuracy in scenarios where label information is available. Using an energy consumption dataset from Austin, Texas, as a case study and through extensive experimental results, we show that our proposed CSR and CNN models outperform 25 widely used anomaly detection benchmarks. Thusitha Dayaratne, Mahsa Salehi, Carsten Rudolph, Ariel Liebman |
DSN | 1 |
| 2021 | We Can Pay Less: Coordinated False Data Injection Attack Against Residential Demand Response in Smart GridsabstractAdvanced metering infrastructure, along with home automation processes, is enabling more efficient and effective demand-side management opportunities for both consumers and utility companies. However, tight cyber-physical integration also enables novel attack vectors for false data injection attacks (FDIA) as home automation/ home energy management systems reside outside the utilities' control perimeter. Authentic users themselves can manipulate these systems without causing significant security breaches compared to traditional FDIAs. This work depicts a novel FDIA that exploits one of the commonly utilised distributed device scheduling architectures. We evaluate the attack impact using a realistic dataset to demonstrate that adversaries gain significant benefits, independently from the actual algorithm used for optimisation, as long as they have control over a sufficient amount of demand. Compared to traditional FDIAs, reliable security mechanisms such as proper authentication, security protocols, security controls or, sealed/controlled devices cannot prevent this new type of FDIA. Thus, we propose a set of possible impact alleviation solutions to thwart this type of attack. Thusitha Dayaratne, Carsten Rudolph, Ariel Liebman, Mahsa Salehi |
CODASPY | 1 |
| 2020 | Inherent Vulnerability of Demand Response Optimisation against False Data Injection Attacks in Smart GridsabstractThe transition of energy networks to so-called smart grids benefits from advancements in Internet of Things technology. Energy management systems enable efficient and effective demand response (DR) schemes optimising load distribution. The increased user involvements through such DR schemes creates a new vector for false data injection attacks (FDIA), where authentic users themselves inject false data. Unlike in most existing FDIAs, no breaches to communication or devices are needed to execute this type of FDIA. In this work, we depict that this new FDIA can impact any optimisation-based DR scheme. Further, we show that adversaries achieve financial benefits independently from the actual algorithm used for optimisation, as long as they are able to inject false demand predictions. Compared to traditional FDIAs, reliable security mechanisms such as proper authentication, security protocols, security controls or sealed/controlled devices cannot prevent this new type of FDIA. Additionally, we show that there is no straightforward solution and we highlight the need for highly reliable FDIA detection mechanisms to thwart this type of attacks. Thusitha Dayaratne, Carsten Rudolph, Ariel Liebman, Mahsa Salehi |
NOMS | 1 |