VLDB 2026 Research / reviewers in the wild / expert
Paul Tavolato
dblp:26/4192
· DBLP profile ↗
17ranked-venue papers
5as first author
9since 2021 · last 2025
0009-0004-4641-8653ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 4 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | PenQuestEnv: A Reinforcement Learning Environment for Cyber Security
Sebastian Eresheim, Simon Gmeiner, Alexander Piglmann, Thomas Petelin, Robert Luh, Paul Tavolato, Sebastian Schrittwieser |
ICISSP (1) | 6 |
| 2025 | A Privacy-Preserving and Explainable Approach for Anomaly Detection in Substation Networks
Paul Tavolato, Oliver Eigner, Philipp Kreimel-Haindl, Patrizia Agnello, Marta Petyx, Antonella Santone, Fabio Martinelli, Francesco Mercaldo |
IJCCI (3) | 1 |
| 2025 | Gamifying information security: Adversarial risk exploration for IT/OT infrastructures
Robert Luh, Sebastian Eresheim, Paul Tavolato, Thomas Petelin, Simon Gmeiner, Andreas Holzinger, Sebastian Schrittwieser |
Comput. Secur. | 3 |
| 2024 | How to Find out What's Going on in Encrypted Smart Meter Networks - without Decrypting AnythingabstractSmart meter networks are part of the critical infrastructure and therefore central to IT security consideration. Besides various forms of access control a permanent monitoring of the network traffic is of utmost importance to the detection of malicious activities taking place. Such monitoring must happen in real time and should possibly be implementable everywhere in the network. These requirements do not allow for the decryption of the network traffic. The paper describes a method by which network packets can be assigned to use cases common in smart meter infrastructures without the need for decryption. It is based solely on metadata and reliably can establish the relationship between a network packet and a use case. The information calculated with this method can be used to detect packets that are not pertaining to any of the allowed use cases and hence are highly suspicious. Moreover, the execution of use cases not initiated by the central server become evident, too, and should raise corresponding alerts. The method was implemented as a proof-of-concept and tested in the real-world environment of a medium-sized city. Oliver Eigner, Hubert Schölnast, Paul Tavolato |
ARES | 3 |
| 2024 | Comparing the Effectivity of Planned Cyber Defense Controls in Order to Support the Selection Process
Paul Tavolato, Robert Luh, Sebastian Eresheim, Simon Gmeiner, Sebastian Schrittwieser |
ICISSP | 1 |
| 2023 | Enhancing Trust in Machine Learning Systems by Formal Methods - With an Application to a Meteorological ProblemabstractWith the deployment of applications based on machine learning techniques the need for understandable explanations of these systems’ results becomes evident. This paper clarifies the concept of an “explanation”: the main goal of an explanation is to build trust in the recipient of the explanation. This can only be achieved by creating an understanding of the results of the AI systems in terms of the users’ domain knowledge. In contrast to most of the approaches found in the literature, which base the explanation of the AI system’s results on the model provided by the machine learning algorithm, this paper tries to find an explanation in the specific expert knowledge of the system’s users. The domain knowledge is defined as a formal model derived from a set of if-then-rules provided by experts. The result from the AI system is represented as a proposition in a temporal logic. Now we attempt to formally prove this proposition within the domain model. We use model checking algorithms and tools for this purpose. If the proof is successful, the result of the AI system is consistent with the model of the domain knowledge. The model contains the rules it is based on and hence the path representing the proof can be translated back to the rules: this explains, why the proposition is consistent with the domain knowledge. The paper describes the application of this approach to a real world example from meteorology, the short-term forecasting of cloud coverage for particular locations. Christina Tavolato-Wötzl, Paul Tavolato |
CD-MAKE | 2 |
| 2023 | A Game Theoretic Analysis of Cyber Threats
Paul Tavolato, Robert Luh, Sebastian Eresheim |
ICISSP | 1 |
| 2022 | PenQuest Reloaded: A Digital Cyber Defense Game for Technical EducationabstractToday’s IT and OT infrastructure is threatened by a plethora of cyber-attacks conducted by actors with different motivations and means. Furthermore, the complexity of these exposed systems as well as the adversaries’ sophisticated technical arsenal makes it increasingly difficult to plan and implement an organization’s defense. Understanding the link between specific attacks and effective mitigating measures is particularly challenging – as is understanding the underlying information security concepts. To support the training of current, and more importantly, nascent security engineers, we propose PenQuest, a digital attack and defense game where an attacker attempts to compromise an abstracted IT infrastructure and the defender works to prevent or mitigate the threat. The game is based on MITRE ATT&CK, D3FEND, and the NIST SP 800-53 security standard and incorporates a multitude of concepts such as cyber kill chains, attack vectors, network segmentation, and more. PenQuest is built to support security education and risk assessment and was evaluated with a class of engineering students as well as independent security experts. Initial results show a significant increase in knowledge retention and attest to the game’s feasibility for educational use. Robert Luh, Sebastian Eresheim, Stefanie Größbacher, Thomas Petelin, Florian Mayr, Paul Tavolato, Sebastian Schrittwieser |
EDUCON | 6 |
| 2022 | Formalizing Real-world Threat Scenarios
Paul Tavolato, Robert Luh, Sebastian Eresheim |
ICISSP | 1 |
| 2020 | Anomaly Detection in Communication Networks of Cyber-physical Systems using Cross-over Data Compression
Hubert Schölnast, Paul Tavolato, Philipp Kreimel |
ICISSP | 2 |
| 2020 | Anomaly detection in substation networks
Philipp Kreimel, Oliver Eigner, Francesco Mercaldo, Antonella Santone, Paul Tavolato |
J. Inf. Secur. Appl. | 5 |
| 2019 | Analytical Modelling of Cyber-physical SystemsabstractIn connection with anomaly detection in cyber-physical systems, we suggest in this paper a new way of modelling large systems consisting of a huge number of sensors, actuators and controllers. We base the approach on analytical methods usually used in kinetic gas theory, where one tries to describe the overall behaviour of a gas without looking at each molecule separately. We model the system as a multi-agent network and derive predictions on the behaviour of the network as a whole. These predictions can then be used to monitor the operation of the system. If the deviation between the predictions and the measured attributes of the operational cyber-physical system is sufficiently large, the monitoring system can raise an alarm. This way of modelling the normal behaviour of a cyber-physical system has the advantage over machine learning methods mainly used for this purpose, that it is not based on the effective operation of the system during a training phase, but rather on the specification of the system and its intended use. It will detect anomalies in the system’s operation independent of its source – may it be an attack, a malfunction or a faulty implementation. Paul Tavolato, Christina Tavolato-Wötzl |
ICISSP | 1 |
| 2018 | Attacks on Industrial Control Systems - Modeling and Anomaly Detection
Oliver Eigner, Philipp Kreimel, Paul Tavolato |
ICISSP | 3 |
| 2017 | Anomaly Detection for Simulated IEC-60870-5-104 TrafiicabstractSubstation security plays an important role in the delivery system of electrical energy. During the past years, there has been an increase in the number of attacks on automation systems. In spite of that, there has not been enough focus dedicated to the protection of such networks. In this paper, we introduce a novel machine learning based intrusion detection system targeted at automation networks of substations based on the IEC 60780-5-104 protocol. The novelty of our approach opposed to the state-of-the-art is the monitoring of several features on multiple protocol layers, which enables the identification of multiple types of attacks. Firstly, we simulate the communication between the substation slave and the server based on data gained from real substations and we simulate the systems behaviour under attack, too. Secondly, we observe the system's normal behavior and its behavior under the attack, in order to extract features needed for building an anomaly detection system. Lastly, based on these features we suggest an anomaly detection system for the asynchronous IEC 60870-5-104 protocol. We designed the anomaly detection model by using machine learning from the IEC 60870-5-104 protocol data acquired. The classifier with the highest performance was chosen by comparing 7 different classification algorithms: the Rule Learner classifier algorithm turned out to be the best. Ersi Hodo, Stepan Grebeniuk, Henri Ruotsalainen, Paul Tavolato |
ARES | 4 |
| 2017 | Anomaly-Based Detection and Classification of Attacks in Cyber-Physical SystemsabstractCyber-physical systems are found in industrial and production systems, as well as critical infrastructures. Due to the increasing integration of IP-based technology and standard computing devices, the threat of cyber-attacks on cyber-physical systems has vastly increased. Furthermore, traditional intrusion defense strategies for IT systems are often not applicable in operational environments. In this paper we present an anomaly-based approach for detection and classification of attacks in cyber-physical systems. To test our approach, we set up a test environment with sensors, actuators and controllers widely used in industry, thus, providing system data as close as possible to reality. First, anomaly detection is used to define a model of normal system behavior by calculating outlier scores from normal system operations. This valid behavior model is then compared with new data in order to detect anomalies. Further, we trained an attack model, based on supervised attacks against the test setup, using the naive Bayes classifier. If an anomaly is detected, the classification process tries to classify the anomaly by applying the attack model and calculating prediction confidences for trained classes. To evaluate the statistical performance of our approach, we tested the model by applying an unlabeled dataset, which contains valid and anomalous data. The results show that this approach was able to detect and classify such attacks with satisfactory accuracy. Philipp Kreimel, Oliver Eigner, Paul Tavolato |
ARES | 3 |
| 2014 | Defining Malicious BehaviorabstractIn this paper we propose the use of formal methods to model malicious code behavior. The paradigm shift in malware detection from conventional, signature-based static methods to evaluating dynamic system behavior is motivated by the rising number and ever-increasing sophistication of malware currently in the wild. Because of advanced polymorphic and metamorphic techniques, a purely signature-based approach is no longer sufficient for accurate malware recognition. Automating the process of behavior analysis necessitates the use of formal methods. The modeling process is built upon two cornerstones: special system call execution traces generated through dynamic analysis of suspicious code and a self-defined taxonomy of (malicious) system activities. The formal model consists of two parts: A definition of malicious behavior in the form of combinations of tasks necessary to achieve a certain malign goal and of rules for translating each task into possible patterns of system calls. Both models are realized through formal grammars. The behavior model uses the tasks as the alphabet and the grammar rules define which patterns of activities can be used to accomplish certain high-level malicious goals. The translation model on the other hand contains an attributed context-free grammar for each task. The alphabet of each grammar consists of Windows system (API) calls, the grammar rules map each task to patterns of these calls. The attributes are used to convey information contained in the parameters of the individual calls. Hermann Dornhackl, Konstantin Kadletz, Robert Luh, Paul Tavolato |
ARES | 4 |
| 2014 | Problem characterization and abstraction for visual analytics in behavior-based malware pattern analysisabstractBehavior-based analysis of emerging malware families involves finding suspicious patterns in large collections of execution traces. This activity cannot be automated for previously unknown malware families and thus malware analysts would benefit greatly from integrating visual analytics methods in their process. However existing approaches are limited to fairly static representations of data and there is no systematic characterization and abstraction of this problem domain. Therefore we performed a systematic literature study, conducted a focus group as well as semi-structured interviews with 10 malware analysts to elicit a problem abstraction along the lines of data, users, and tasks. The requirements emerging from this work can serve as basis for future design proposals to visual analytics-supported malware pattern analysis. Markus Wagner 0008, Wolfgang Aigner, Alexander Rind, Hermann Dornhackl, Konstantin Kadletz, Robert Luh, Paul Tavolato |
VizSEC | 7 |