Bhanuka Silva

dblp:278/8325 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
4since 2021 · last 2026
0009-0000-6558-6514ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2026 TrafficLLM: LLMs for improved open-set encrypted traffic analysis
abstract
Encrypted traffic has been known to be vulnerable to traffic analysis attacks that exploit the statistical features of encrypted traffic flows, such as packet sizes, timing, and direction, to infer information about the underlying content, which undermines the privacy guarantees of end-to-end encryption. Existing methods such as CNNs lack generalizability, requiring model changes based on the dataset. Furthermore, while state-of-the-art attacks leverage deep learning models to achieve high accuracy, most attacks work under the less realistic closed-set assumption, failing in the open-set setting. Deploying such attacks in practice requires addressing the open-set scenario, which allows the models to filter out target content from other background traffic. The effectiveness of open-set traffic classification largely relies on the model’s ability to generalize and accurately extract features from traffic traces, which are essentially sequential data. Concurrently, Large Language Models (LLM) are increasingly becoming popular in modeling sequential data beyond their typical applications in natural language processing. Inspired by this, our work introduces TrafficLLM, a novel traffic analysis attack method that leverages pre-trained LLMs, such as GPT-2 and LLaMA-2-7B, to extract features from network traffic traces with minimal fine-tuning. Using seven existing encrypted traffic datasets, we show that LLMs improve the open-set performance of traffic classification; for instance, our method, TrafficLLM outperforms ET-BERT and CNN-based approaches by 12.7 % and 13.7 % with GPT-2 feature extractor and 17.6 % and 21.5 % with LLaMA-2-7B feature extractor, respectively.
Yasod Ginige, Bhanuka Silva, Thilini Dahanayaka, Suranga Seneviratne
Comput. Networks2
2025 Detecting Content Rating Violations in Android Applications: A Vision-Language Approach
abstract
Despite regulatory efforts to establish reliable content-rating guidelines for mobile apps, the process of assigning content ratings in the Google Play Store remains self-regulated by the app developers. There is no straightforward method of verifying developer-assigned content ratings manually due to the overwhelming scale or automatically due to the challenging problem of interpreting textual and visual data and correlating them with content ratings. We propose and evaluate a vision-language approach to predict the content ratings of mobile game applications and detect content rating violations, using a dataset of metadata of popular Android games.Our method achieves ∼6% better relative accuracy compared to the state-of-the-art CLIP-fine-tuned model in a multi-modal setting. Applying our classifier in the wild, we detected more than 70 possible cases of content rating violations, including nine instances with the ‘Teacher Approved’ badge. Additionally, our findings indicate that 34.5% of the apps identified by our classifier as violating content ratings were later removed from the Play Store. In contrast, the removal rate for correctly classified apps was only 27%. This discrepancy highlights the practical effectiveness of our classifier in identifying apps likely to be removed based on user complaints.
Dishanika Denipitiyage, Bhanuka Silva, Suranga Seneviratne, Aruna Seneviratne, Sanjay Chawla
TrustCom2
2025 Quantifying and Exploiting Adversarial Vulnerability: Gradient-Based Input Pre-Filtering for Enhanced Performance in Black-Box Attacks
abstract
We investigate the vulnerability of inputs in an adversarial setting and demonstrate that certain samples are more susceptible to adversarial perturbations compared to others. Specifically, we employ a simple yet effective approach to quantify the adversarial vulnerability of inputs, which relies on the clipped gradients of the loss with respect to the input. Our observations indicate that inputs with a low percentage of zero gradient components tend to be more vulnerable to attacks. These findings are supported by a theoretical explanation on a linear model and empirical evidence on deep neural networks. Across all datasets we tested, we find that inputs with the lowest zero gradient percentage, on average, exhibit 34.5% more susceptibility to adversarial attacks than randomly selected inputs. Additionally, we demonstrate that the zero gradient percentage, as a metric, transfers across different model architectures. Finally, we propose a novel black-box attack pipeline that enhances the efficiency of conventional query-based black-box attacks and show that input pre-filtering based on Zero Gradient Percentage can boost the attack success rates, particularly under low perturbation levels. On average, across all datasets we test, our approach outperforms the conventional shadow model-based and query-based black-box attack pipelines by 44.9% and 30.4%, respectively.
Naveen Karunanayake, Bhanuka Silva, Yasod Ginige, Suranga Seneviratne, Sanjay Chawla
ACM Trans. Priv. Secur.2
2025 Detecting and Characterising Mobile App Metamorphosis in Google Play Store
abstract
App markets have evolved into highly competitive and dynamic environments for developers. While the traditional app life cycle involves incremental updates for feature enhancements and issue resolution, some apps deviate from this norm by undergoing significant transformations in their use cases or market positioning. We define this previously unstudied phenomenon as ‘app metamorphosis'. In this paper, we propose a novel and efficient multi-modal search methodology to identify apps undergoing metamorphosis and apply it to analyse two snapshots of the Google Play Store taken five years apart. Our methodology uncovers various metamorphosis scenarios, including re-births, re-branding, re-purposing, and others, enabling comprehensive characterisation. Although these transformations may register as successful for app developers based on our defined success score metric (e.g., re-branded apps performing approximately 11.3% better than an average top app), we shed light on the concealed security and privacy risks that lurk within, potentially impacting even tech-savvy end-users.
Dishanika Denipitiyage, Bhanuka Silva, Kavishka Gunathilaka, Suranga Seneviratne, Anirban Mahanti, Aruna Seneviratne, Sanjay Chawla
IEEE Trans. Mob. Comput.2