Joel Brynielsson

dblp:26/2403 · DBLP profile ↗
← Back
19ranked-venue papers
7as first author
7since 2021 · last 2025
0000-0002-2677-9759ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 14 · 4 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 9 · 4 first-author · 3 since 2021Databases, data management, data science and information retrieval · 8 · 3 first-author · 3 since 2021Security and privacy · 4 · 2 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Strategic Steering of Large Language Models via Game-Theoretic Action Space Optimization
abstract
Abstract This paper investigates how large language models can be steered to act more strategically in text-based negotiation settings. Two prompt-based action space designs are compared, namely emotional tone prompts and explicit offer prompts, within a negotiation environment, and outcomes are compared in simulated dialogues. The results show that both approaches improve strategic outcomes compared to a baseline, with tone-based actions yielding higher agreement rates and offer-based actions providing more stable tradeoffs. These findings demonstrate how action space design influences agent behavior, providing insights for deployment of large language models in strategic negotiation scenarios to gain an advantage in, for example, online influence operations.
Samuel Lavebrink, Joel Brynielsson, Mika Cohen, Farzad Kamrani, Christoffer Limér, Madeleine Lindström, Marius Vangeli
ASONAM (3)2
2025 Outsmarting Willful-Thinking Opponents: Bayesian Belief Revision for Adversarial Reasoning in Large Language Models
abstract
Abstract In adversarial contexts, success often hinges on understanding not just what the opponent knows, but what they believe and how they revise those beliefs. This study investigates how large language models can be made more resilient and strategically capable by modeling the opponent’s reasoning using Bayesian belief revision. By formalizing negotiations as Bayesian games of incomplete information, it is shown that models equipped with belief revision are better able to counter deceptive or willful-thinking adversaries. The findings underscore the role of second-order reasoning in adversarial settings, with implications for social manipulation in the context of, for example, online communication and intelligence gathering.
Madeleine Lindström, Joel Brynielsson, Mika Cohen, Farzad Kamrani, Samuel Lavebrink, Christoffer Limér, Marius Vangeli
ASONAM (3)2
2025 Anti-Submarine Warfare Planning Using Public Belief States and Self-Play
abstract
We consider the problem of how to move active sonars unpredictably in pursuit of a stealthy underwater vehicle. The search problem is formalized as an imperfect-information game played on a discretized nautical chart with fine-grained hydroacoustics. The game is solved approximately using public belief states and self-play following a game-theoretically sound approach. The solution method is shown empirically to approximate the Nash equilibrium in a restricted scenario small enough to be solvable with tabular methods from algorithmic game theory.
Christoffer Limér, Joel Brynielsson, Mika Cohen, Felix Rydell
ICMLA2
2025 Jailbreaking Large Language Models: Safety Alignment, Response Quality, Computational Cost
abstract
Large language models are often equipped with safety alignment mechanisms designed to prevent generation of harmful or other unwanted content. However, an increasing number of jailbreaking techniques attempt to circumvent these safeguards, raising significant safety concerns. This paper introduces an open-source evaluation framework that analyzes jailbreaking effectiveness in several dimensions: refusal bypass rate, harmful response quality, impact on general model capabilities, and computational cost. In the study, prompt injection, sampling exploits, and model manipulation techniques are examined across four open-weight instruction-tuned large language models. The results demonstrate that high refusal bypass does not necessarily equate to practical safety compromise. Specifically, model manipulation methods like single refusal direction ablation achieve a high attack success rate, but often degrade general capabilities and require significant computational resources. Meanwhile, sampling-based exploits show a minimal practical threat when assessed with a robust model classifier. The findings emphasize the importance of comprehensive, multi-dimensional evaluation to accurately characterize jailbreaking effectiveness and safety risks in large language models.
Jonas Rosengren, Joel Brynielsson, Patrik Jonell
ICMLA2
2023 Comparison of Strategies for Honeypot Deployment
abstract
Recent experimental studies have explored how well adaptive honeypot allocation strategies defend against human adversaries. As the experimental subjects were drawn from an unknown, nondescript pool of subjects using Amazon Mechanical Turk, the relevance to defense against real-world adversaries is unclear. The present study reproduces the experiments with more relevant experimental subjects. The results suggest that the strategies considered are less effective against attackers from the current population. In particular, their ability to predict the next attack decreased steadily over time, that is, the human subjects from this population learned to attack less and less predictably.
Joel Brynielsson, Mika Cohen, Patrik Hansen, Samuel Lavebrink, Madeleine Lindström, Edward Tjörnhammar
ASONAM1
2023 Active Learning for Improvement of Classification of Cyberthreat Actors in Text Fragments
abstract
In the domain of cybersecurity, machine learning can offer advanced threat detection. However, the volume of unlabeled data poses challenges for efficient data management. This study investigates the potential for active learning to reduce the effort required for manual data labeling. Through different query strategies, the most informative unlabeled data points were selected for labeling. The performance of different query strategies was assessed by testing a transformer model's ability to accurately distinguish tweets mentioning names of advanced persistent threats. The findings suggest that the K-means diversity-based query strategy outperformed both the uncertainty-based approach and the random data point selection, when the amount of labeled training data was limited. This study also evaluated the cost-effective active learning approach, which incorporates high-confidence data points into the training dataset. However, this was shown to be the least effective strategy.
Amanda Carp, Joel Brynielsson, Agnes Tegen
ICMLA2
2021 Cyber-threat perception and risk management in the Swedish financial sector
abstract
The financial sector relies heavily on information systems for business. This study sets out to investigate cyber situation awareness in the financial sector in Sweden, by examining what information elements that are needed for a common operational picture, and exploring how key actors perceive cyber-threats. Data was collected through a survey and a series of interviews with key actors in the sector in conjunction with a national level crisis management exercise. The data was then analyzed and contrasted to theory. Conclusions were drawn and results discussed. Finally, possible mitigation actions were suggested. It was found that actors in the Swedish financial sector have a well developed crisis management working concept. However, information about rational adversaries that cause prolonged disturbances is possibly not collected, analyzed and utilized systematically. Much effort is put into ensuring that timely and relevant information from organizations is shared in an efficient manner. The sector perceives cyber-threats against the underlying financial infrastructure, as well as against IT service availability and data confidentiality, besides financial theft. The sector has particular concerns for the potential of reputational loss due to cyberattacks. There are also special concerns about the insider threat. Respondents agree that risk management has to account for cyber risk. A possible route to enhance risk management practices is to ensure that cyber personnel is integrated in crisis management teams.
Stefan Varga, Joel Brynielsson, Ulrik Franke
Comput. Secur.2
2020 A Census of Swedish Government Administrative Authority Employee Communications on Cybersecurity during the COVID-19 Pandemic
abstract
Cybersecurity is the backbone of a successful digitalization of society, and cyber situation awareness is an essential aspect of managing it. The COVID-19 pandemic has sped up an already ongoing digitalization of Swedish government agencies, but the cybersecurity maturity level varies across agencies. In this study, we conduct a census of Swedish government administrative authority communications on cybersecurity to employees at the beginning of the COVID-19 pandemic. The census shows that the employee communications in the beginning of the pandemic to a greater extent have focused on first-order risks, such as video meetings and telecommuting, rather than on second-order risks, such as invoice fraud or social engineering. We also find that almost two thirds of the administrative authorities have not yet implemented, but only initiated or documented, their cybersecurity policies.
Annika Andreasson, Henrik Artman, Joel Brynielsson, Ulrik Franke
ASONAM3
2020 Veracity assessment of online data
abstract
Fake news, malicious rumors, fabricated reviews, generated images and videos, are today spread at an unprecedented rate, making the task of manually assessing data veracity for decision-making purposes a daunting task. Hence, it is urgent to explore possibilities to perform automatic veracity assessment. In this work we review the literature in search for methods and techniques representing state of the art with regard to computerized veracity assessment. We study what others have done within the area of veracity assessment, especially targeted towards social media and open source data, to understand research trends and determine needs for future research. The most common veracity assessment method among the studied set of papers is to perform text analysis using supervised learning. Regarding methods for machine learning much has happened in the last couple of years related to the advancements made in deep learning. However, very few papers make use of these advancements. Also, the papers in general tend to have a narrow scope, as they focus on solving a small task with only one type of data from one main source. The overall veracity assessment problem is complex, requiring a combination of data sources, data types, indicators, and methods. Only a few papers take on such a broad scope, thus, demonstrating the relative immaturity of the veracity assessment domain.
Marianela García Lozano, Joel Brynielsson, Ulrik Franke, Magnus Rosell, Edward Tjörnhammar, Stefan Varga, Vladimir Vlassov
Decis. Support Syst.2
2018 Information Requirements for National Level Cyber Situational Awareness
abstract
As modern societies become more dependent on IT services, the potential impact both of adversarial cyberattacks and non-adversarial service management mistakes grows. This calls for better cyber situational awareness-decision-makers need to know what is going on. The main focus of this paper is to examine the information elements that need to be collected and included in a common operational picture in order for stakeholders to acquire cyber situational awareness. This problem is addressed through a survey conducted among the participants of a national information assurance exercise conducted in Sweden. Most participants were government officials and employees of commercial companies that operate critical infrastructure. The results give insight into information elements that are perceived as useful, that can be contributed to and required from other organizations, which roles and stakeholders would benefit from certain information, and how the organizations work with creating cyber common operational pictures today. Among findings, it is noteworthy that adversarial behavior is not perceived as interesting, and that the respondents in general focus solely on their own organization.
Stefan Varga, Joel Brynielsson, Ulrik Franke
ASONAM2
2017 Tracking geographical locations using a geo-aware topic model for analyzing social media data
abstract
Tracking how discussion topics evolve in social media and where these topics are discussed geographically over time has the potential to provide useful information for many different purposes. In crisis management, knowing a specific topic's current geographical location could provide vital information to where, or even which, resources should be allocated. This paper describes an attempt to track online discussions geographically over time. A distributed geo-aware streaming latent Dirichlet allocation model was developed for the purpose of recognizing topics' locations in unstructured text. To evaluate the model it has been implemented and used for automatic discovery and geographical tracking of election topics during parts of the 2016 American presidential primary elections. It was shown that the locations correlated with the actual election locations, and that the model provides a better geolocation classification compared to using a keyword-based approach.
Marianela García Lozano, Jonah Schreiber, Joel Brynielsson
Decis. Support Syst.3
2016 Using cyber defense exercises to obtain additional data for attacker profiling
abstract
In order to be able to successfully defend an IT system it is useful to have an accurate appreciation of the cyber threat that goes beyond stereotypes. To effectively counter potentially decisive and skilled attackers it is necessary to understand, or at least model, their behavior. Although the real motives for untraceable anonymous attackers will remain a mystery, a thorough understanding of their observable actions can still help to create well-founded attacker profiles that can be used to design effective countermeasures and in other ways enhance cyber defense efforts. In recent work empirically founded attacker profiles, so-called attacker personas, have been used to assess the overall threat situation for an organization. In this paper we elaborate on 1) the use of attacker personas as a technique for attacker profiling, 2) the design of tailor-made cyber defense exercises for the purpose of obtaining the necessary empirical data for the construction of such attacker personas, and 3) how attacker personas can be used for enhancing the situational awareness within the cyber domain. The paper concludes by discussing the possibilities and limitations of using cyber defense exercises for data gathering, and what can and cannot be studied in such exercises.
Joel Brynielsson, Ulrik Franke, Muhammad Adnan Tariq, Stefan Varga
ISI1
2015 Detectability of Low-Rate HTTP Server DoS Attacks using Spectral Analysis
abstract
Denial-of-Service (DoS) attacks pose a threat to any service provider on the internet. While traditional DoS flooding attacks require the attacker to control at least as much resources as the service provider in order to be effective, so-called low-rate DoS attacks can exploit weaknesses in careless design to effectively deny a service using minimal amounts of network traffic.
Joel Brynielsson, Rishie Sharma
ASONAM1
2014 The security awareness paradox: A case study
abstract
Knowledge-intensive organizations are characterized by their dependency on highly skilled personnel who perform their daily work in a decentralized manner. In these organizations it is the users who make the important decisions, and therefore the organization's information security awareness is upheld by and depends on its users' combined security awareness. To assess the overall organizational security awareness it therefore becomes interesting to assess both the users' individual level of security awareness, as well as their level of consistency and conformity with regard to other users' awareness. In the present case study, 15 semi-structured interviews have been undertaken within a large telecommunication company in order to understand how significant IT security aspects are understood within the organization. The study highlights a number of perception differences where the technical IT staff and the ordinary users do not share the same understanding. It is suggested that these perception differences result from a paradoxical situation where the users' possibility to uphold security awareness is hindered because of security concerns.
Muhammad Adnan Tariq, Joel Brynielsson, Henrik Artman
ASONAM2
2014 Cyber situational awareness - A systematic review of the literature
Ulrik Franke, Joel Brynielsson
Comput. Secur.2
2013 Learning to classify emotional content in crisis-related tweets
abstract
Social media is increasingly being used during crises. This makes it possible for crisis responders to collect and process crisis-related user generated content to allow for improved situational awareness. We describe a methodology for collecting a large number of relevant tweets and annotating them with emotional labels. This methodology has been used for creating a training data set consisting of manually annotated tweets from the Sandy hurricane. Those tweets have been utilized for building machine learning classifiers able to automatically classify new tweets. Results show that a support vector machine achieves the best results (60% accuracy on the multi-classification problem).
Joel Brynielsson, Anders Westling
ISI1
2010 Detecting Social Positions Using Simulation
abstract
Describing social positions and roles is an important topic within social network analysis. One approach is to compute a suitable equivalence relation on the nodes of the target network. One relation that is often used for this purpose is regular equivalence, or bisimulation, as it is known within the field of computer science. In this paper we consider a relation from computer science called simulation relation. Simulation creates a partial order on the set of actors in a network and we can use this order to identify actors that have characteristic properties. The simulation relation can also be used to compute simulation equivalence which is a less restrictive equivalence relation than regular equivalence but is still computable in polynomial time. This paper primarily considers weighted directed networks and we present definitions of both weighted simulation equivalence and weighted regular equivalence. Weighted networks can be used to model a number of network domains, including information flow, trust propagation, and communication channels. Many of these domains have applications within homeland security and in the military, where one wants to survey and elicit key roles within an organization. Identifying social positions can be difficult when the target organization lacks a formal structure or is partially hidden.
Joel Brynielsson, Johanna Björklund, Lisa Kaati, Christian Mårtenson, Pontus Svenson
ASONAM1
2009 An information assurance curriculum for commanding officers using hands-on experiments
abstract
To authorize and initiate necessary investments and enforce appropriate policies and procedures, decision-makers need to have at least a fair understanding of computer security fundamentals. This paper presents the course design and the laboratory settings that have been developed for, and used within, the high rank officer curriculum at the Swedish National Defence College. The developed course looks at computer security from an attack versus defend viewpoint, meaning that computer attacks are studied to learn about prevention and self-defense. The paper discusses the pedagogical challenges related to education of high rank officers and similar personnel in light of recently-held courses and contrasts the course relative to similar undertakings. A standpoint taken is that computer security is best taught using hands-on laboratory experiments focusing on problem solving assignments. This is not undisputed since, e.g., high rank officers are busy people who are not fond of getting stuck learning about the peripherals.
Joel Brynielsson
SIGCSE1
2007 Using AI and games for decision support in command and control
Joel Brynielsson
Decis. Support Syst.1