VLDB 2026 Research / reviewers in the wild / expert
Antonis Michalas
dblp:28/9590
· DBLP profile ↗
47ranked-venue papers
7as first author
31since 2021 · last 2026
0000-0002-0189-3520ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 30 · 2 first-author · 25 since 2021Computer networks · 7 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorSystems, architecture and hardware · 2Artificial intelligence and machine learning · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hidden Elo: Private Matchmaking through Encrypted Rating SystemsabstractMatchmaking has become a prevalent part in contemporary applications, being used in dating apps, social media, online games, contact tracing and in various other use-cases. However, most implementations of matchmaking require the collection of sensitive/personal data for proper functionality. As such, with this work we aim to reduce the privacy leakage inherent in matchmaking applications. We propose H-Elo, a Fully Homomorphic Encryption (FHE)-based, private rating system, which allows for secure matchmaking through the use of traditional rating systems. In this work, we provide the construction of H-Elo, analyse the security of it against a capable adversary as well as benchmark our construction in a chess-based rating update scenario. Through our experiments we show that H-Elo can achieve similar accuracy to a plaintext implementation, while keeping rating values private and secure. Additionally, we compare our work to other private matchmaking solutions as well as cover some future directions in the field of private matchmaking. To the best of our knowledge we provide one of the first private and secure rating system-based matchmaking protocols. Mindaugas Budzys, Bin Liu 0077, Antonis Michalas |
CODASPY | 3 |
| 2026 | It Runs and It Hides: A Function-Hiding Construction for Private-Key Multi-Input Functional Encryption
Antonis Michalas, Alexandros Bakas |
ICISSP (1) | 1 |
| 2026 | Coercion-Resistant Voting via Anamorphic EncryptionabstractThe paper addresses the challenging and timely issue of vote buying in electronic voting. Electronic voting is a well established process in modern democracies. However, problems such as vote buying continue to pose a significant challenge. This paper aims at addressing this issue by leveraging the novel concept of Anamorphic Encryption to enable voters to cast their original vote together with a hidden ''fake'' one. In this way voters can pursue their true preferences unobstructed while providing a compliance proof to potential vote buyers. The security of our construction is proved through a formal security analysis, that considers powerful adversaries who aim at breaching user privacy and influencing votes. We believe that this innovation e-voting approach can enhance the overall security of e-voting systems and pave the way to avoid electoral manipulation. Antonis Michalas |
SACMAT | 1 |
| 2025 | To Vaccinate or Not to Vaccinate? Analyzing $\mathbb {X}$ Power over the Pandemic
Tanveer Khan, Fahad Sohrab, Antonis Michalas, Moncef Gabbouj |
AINA (7) | 3 |
| 2025 | Blind Brother: Attribute-Based Selective Video EncryptionabstractThe emergence of video streams as a primary medium for communication and the demand for high-quality video sharing over the internet have given rise to several security and privacy issues, such as unauthorized access and data breaches. To address these limitations, various Selective Video Encryption (SVE) schemes have been proposed, which encrypt specific portions of a video while leaving others unencrypted. The SVE approach balances security and usability, granting unauthorized users access to certain parts while encrypting sensitive content. However, existing SVE schemes adopt an all-or-nothing coarse-grain encryption approach, where a user with a decryption key can access all the contents of a given video stream. This paper proposes and designs a fine-grained access control-based selective video encryption scheme, ABSVE, and a use-case protocol called Blind Brother. Our scheme encrypts different identified Regions of Interest (ROI) with a unique symmetric key and applies a Ciphertext Policy Attribute Based Encryption (CP-ABE) scheme to tie these keys to specific access policies. This method provides multiple access levels for a single encrypted video stream. Crucially, we provide a formal syntax and security definitions for ABSVE, allowing for rigorous security analysis of this and similar schemes - which is absent in prior works. Finally, we provide an implementation and evaluation of our protocol in the Kvazaar HEVC encoder. Overall, our constructions enhance security and privacy while allowing controlled access to video content and achieve comparable efficiency to compression without encryption. Eugene Frimpong, Bin Liu 0077, Camille Nuoskala, Antonis Michalas |
CODASPY | 4 |
| 2025 | FaaS and Furious: Accelerating Privacy-Preserving ML with Function as a Service at the EdgeabstractThe demand for Privacy-Preserving Machine Learning (PPML) is growing, facing challenges in privacy balance, computational efficiency, and real-world feasibility, as traditional cloud approaches often suffer from high latency and resource limitations. Our paper introduces an innovative approach leveraging Function as a Service (FaaS) and edge computing to address these issues, significantly accelerating encrypted ML inference with strong privacy guarantees. Using Hybrid Homomorphic Encryption (HHE) and a distributed serverless architecture, we build a scalable solution that limits computational overhead and maximises resource utilisation. Offloading compute-intensive ML inference tasks to stateless functions, allocated on-demand at the edge, enables parallel processing, minimising latency and improving execution time. Evaluations on real-world medical datasets show substantial improvements over conventional methods, demonstrating feasible low-latency, high-efficiency PPML in distributed environments. Our findings highlight the potential of edge-driven FaaS architectures to bridge security and speed, paving the way for practical, real-time, privacy-preserving AI. Francesco Tusa, Antonis Michalas, James Bowden, Tamás Kiss |
ICCCN | 2 |
| 2025 | The Sound of Reduction: Minimal Inputs, Maximal CoverageabstractGuaranteeing the security of cryptographic constructions requires not only theoretically sound designs but also correct and robust implementations. Among the various software testing techniques, fuzz testing is a technique commonly used to automatically verify computer programs that accept user input, by observing its behavior upon receiving diverse inputs. While fuzz testing has proven effective in identifying implementation issues, the structural complexity and input constraints of cryptographic software is one of the big hurdles that existing fuzzers are wrestling with. In this work, we introduce The Sound of Reduction (SoR), a novel fuzzing framework that combines complexity reduction with coverage guidance to improve the effectiveness of fuzzers when applied in cryptographic software. At the core of SoR is an enhanced version of Proptest testing library, that can perform efficient input minimization while leveraging runtime coverage feedback to explore deeper execution paths. We evaluate our approach across a broad range of Post-Quantum Cryptography implementations, including lattice, code, and multivariate-based schemes. Our results demonstrate significant improvements in code coverage and input corpus quality compared to state-of-the-art coverage-guided fuzzers. Iaroslav Gridin, Antonis Michalas, Alejandro Cabrera Aldaya |
TrustCom | 2 |
| 2024 | Trustworthiness of $\mathbb {X}$ Users: A One-Class Classification Approach
Tanveer Khan, Fahad Sohrab, Antonis Michalas, Moncef Gabbouj |
AINA (2) | 3 |
| 2024 | Swarmchestrate: Towards a Fully Decentralised Framework for Orchestrating Applications in the Cloud-to-Edge Continuum
Tamás Kiss, Amjad Ullah, Gábor Terstyánszky, Odej Kao, Sören Becker 0001, Giannis Verginadis, Antonis Michalas, Vlado Stankovski, Attila Kertész, Elisa Ricci 0001, Jörn Altmann, Bernhard Egger 0002, Francesco Tusa, József Kovács, Róbert Lovas |
AINA (5) | 7 |
| 2024 | Rainbow Over Clouds: A Lightweight Pairing-Free Multi-replica Multi-cloud Public Auditing Scheme
Reyhaneh Rabaninejad, Antonis Michalas, Salil S. Kanhere |
CRiSIS | 2 |
| 2024 | A Pervasive, Efficient and Private Future: Realizing Privacy-Preserving Machine Learning Through Hybrid Homomorphic EncryptionabstractMachine Learning (ML) has become one of the most impactful fields of data science in recent years. However, a significant concern with ML is its privacy risks due to rising attacks against ML models. Privacy-Preserving Machine Learning (PPML) methods have been proposed to mitigate the privacy and security risks of ML models. A popular approach to achieving PPML uses Homomorphic Encryption (HE). However, the highly publicized inefficiencies of HE make it unsuitable for highly scalable scenarios with resource-constrained devices. Hence, Hybrid Homomorphic Encryption (HHE) – a modern encryption scheme that combines symmetric cryptography with HE – has recently been introduced to overcome these challenges. HHE potentially provides a foundation to build new efficient and privacy-preserving services that transfer expensive HE operations to the cloud. This work introduces HHE to the ML field by proposing resource-friendly PPML protocols for edge devices. More precisely, we utilize HHE as the primary building block of our PPML protocols. We assess the performance of our protocols by first extensively evaluating each party’s communication and computational cost on a dummy dataset and show the efficiency of our protocols by comparing them with similar protocols implemented using plain BFV. Subsequently, we demonstrate the real-world applicability of our construction by building an actual PPML application that uses HHE as its foundation to classify heart disease based on sensitive ECG data. Khoa Nguyen 0005, Mindaugas Budzys, Eugene Frimpong, Tanveer Khan, Antonis Michalas |
DASC | 5 |
| 2024 | Point Intervention: Improving ACVP Test Vector Generation Through Human Assisted Fuzzing
Iaroslav Gridin, Antonis Michalas |
ICICS (2) | 2 |
| 2024 | Need for Speed: Leveraging the Power of Functional Encryption for Resource-Constrained DevicesabstractFunctional Encryption (FE) is a cutting-edge cryptographic technique that enables a user with a specific functional decryption key to determine a certain function of encrypted data without gaining access to the underlying data. Given its potential and the fact that FE is still a relatively new field, we set out to investigate how it could be applied to resource-constrained environments. This work presents what we believe to be the first lightweight FE scheme explicitly designed for resource-constrained devices. We also propose a use case protocol that demonstrates how our scheme can secure an Internet of Things (IoT) architecture where relevant devices collect data and securely deliver them to a storage server, where an analyst can request access to the encrypted data. Finally, we conduct thorough experiments on two commercially available resource-constrained devices to provide compelling evidence of our approach’s practicality and efficiency. Although the results of our evaluations show that there is room for improvement in the proposed scheme, this work represents one of the first attempts to apply FE to the IoT setting that can directly impact people’s daily lives and the everyday operations of organizations. Eugene Frimpong, Alexandros Bakas, Camille Nuoskala, Antonis Michalas |
IoTBDS | 4 |
| 2024 | Make Split, not Hijack: Preventing Feature-Space Hijacking Attacks in Split LearningabstractThe popularity of Machine Learning (ML) makes the privacy of sensitive data more imperative than ever. Collaborative learning techniques like Split Learning (SL) aim to protect client data while enhancing ML processes. Though promising, SL has been proved to be vulnerable to a plethora of attacks, thus raising concerns about its effectiveness on data privacy. In this work, we introduce a hybrid approach combining SL and Function Secret Sharing (FSS) to ensure client data privacy. The client adds a random mask to the activation map before sending it to the servers. The servers cannot access the original function but instead work with shares generated using FSS. Consequently, during both forward and backward propagation, the servers cannot reconstruct the client's raw data from the activation map. Furthermore, through visual invertibility, we demonstrate that the server is incapable of reconstructing the raw image data from the activation map when using FSS. It enhances privacy by reducing privacy leakage compared to other SL-based approaches where the server can access client input information. Our approach also ensures security against feature space hijacking attack, protecting sensitive information from potential manipulation. Our protocols yield promising results, reducing communication overhead by over 2× and training time by over 7× compared to the same model with FSS, without any SL. Also, we show that our approach achieves > 96% accuracy and remains equivalent to the plaintext models. Tanveer Khan, Mindaugas Budzys, Antonis Michalas |
SACMAT | 3 |
| 2024 | FE[r]Chain: Enforcing Fairness in Blockchain Data Exchanges Through Verifiable Functional EncryptionabstractFunctional Encryption (FE) allows users to extract specific function-related information from encrypted data while preserving the privacy of the underlying plaintext. Though significant research has been devoted to developing secure and efficient Multi-Input Functional Encryption schemes supporting diverse functions, there remains a noticeable research gap in the development of verifiable FE schemes. Functionality and performance have received considerable attention, however, the crucial aspect of verifiability in FE has been relatively understudied. Another important aspect that prior research in FE with outsourced decryption has not adequately addressed is the fairness of the data-for-money exchange between a curator and an analyst. This paper focuses on addressing these gaps by proposing a verifiable FE scheme for inner product computation. The scheme not only supports the multi-client setting but also extends its functionality to accommodate multiple users -- an essential feature in modern privacy-respecting services. Additionally, it demonstrates how this FE scheme can be effectively utilized to ensure fairness and atomicity in a payment protocol, further enhancing the trustworthiness of data exchanges. Camille Nuoskala, Reyhaneh Rabaninejad, Tassos Dimitriou, Antonis Michalas |
SACMAT | 4 |
| 2024 | SPADE: Digging into Selective and PArtial DEcryption Using Functional Encryption
Camille Nuoskala, Hossein Abdinasibfar, Antonis Michalas |
SecureComm (1) | 3 |
| 2024 | SoK: Wildest Dreams: Reproducible Research in Privacy-preserving Neural Network TrainingabstractMachine Learning (ML), addresses a multitude of complex issues in multiple disciplines, including social sciences, finance, and medical research. ML models require substantial computing power and are only as powerful as the data utilized. Due to the high computational cost of ML methods, data scientists frequently use Machine Learning-as-a-Service (MLaaS) to outsource computation to external servers. However, when working with private information, like financial data or health records, outsourcing the computation might result in privacy issues. Recent advances in Privacy-Preserving Techniques (PPTs) have enabled ML training and inference over protected data through the use of Privacy-Preserving Machine Learning (PPML). However, these techniques are still at a preliminary stage and their application in real-world situations is demanding. In order to comprehend the discrepancy between theoretical research suggestions and actual applications, this work examines the past and present of PPML, focusing on Homomorphic Encryption (HE) and Secure Multi-party Computation (SMPC) applied to ML. This work primarily focuses on the ML model's training phase, where maintaining user data privacy is of utmost importance. We provide a solid theoretical background that eases the understanding of current approaches and their limitations. We also provide some preliminaries of SMPC, HE, and ML. In addition, we present a systemization of knowledge of the most recent PPML frameworks for model training and provide a comprehensive comparison in terms of the unique properties and performances on standard benchmarks. Also, we reproduce the results for some of the surveyed papers and examine at what level existing works in the field provide support for open science. We believe our work serves as a valuable contribution by raising awareness about the current gap between theoretical advancements and real-world applications in PPML, specifically regarding open-source availability, reproducibility, and usability. Tanveer Khan, Mindaugas Budzys, Khoa Nguyen 0005, Antonis Michalas |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | stoRNA: Stateless Transparent Proofs of Storage-time
Reyhaneh Rabaninejad, Behzad Abdolmaleki, Giulio Malavolta, Antonis Michalas, Amir Nabizadeh |
ESORICS (3) | 4 |
| 2023 | Love or Hate? Share or Split? Privacy-Preserving Training Using Split Learning and Homomorphic EncryptionabstractSplit learning (SL) is a new collaborative learning technique that allows participants, e.g. a client and a server, to train machine learning models without the client sharing raw data. In this setting, the client initially applies its part of the machine learning model on the raw data to generate activation maps and then sends them to the server to continue the training process. Previous works in the field demonstrated that reconstructing activation maps could result in privacy leakage of client data. In addition to that, existing mitigation techniques that overcome the privacy leakage of SL prove to be significantly worse in terms of accuracy. In this paper, we improve upon previous works by constructing a protocol based on U-shaped SL that can operate on homomorphically encrypted data. More precisely, in our approach, the client applies homomorphic encryption on the activation maps before sending them to the server, thus protecting user privacy. This is an important improvement that reduces privacy leakage in comparison to other SL-based works. Finally, our results show that, with the optimum set of parameters, training with HE data in the U-shaped SL setting only reduces accuracy by 2.65% compared to training on plaintext. In addition, raw training data privacy is preserved. Tanveer Khan, Khoa Nguyen 0005, Antonis Michalas, Alexandros Bakas |
PST | 3 |
| 2023 | Split Without a Leak: Reducing Privacy Leakage in Split Learning
Khoa Nguyen 0005, Tanveer Khan, Antonis Michalas |
SecureComm (2) | 3 |
| 2023 | Learning in the Dark: Privacy-Preserving Machine Learning using Function ApproximationabstractOver the past few years, a tremendous growth of machine learning was brought about by a significant increase in adoption and implementation of cloud-based services. As a result, various solutions have been proposed in which the machine learning models run on a remote cloud provider and not locally on a user’s machine. However, when such a model is deployed on an untrusted cloud provider, it is of vital importance that the users’ privacy is preserved. To this end, we propose Learning in the Dark – a hybrid machine learning model in which the training phase occurs in plaintext data, but the classification of the users’ inputs is performed directly on homomorphically encrypted ciphertexts. To make our construction compatible with homomorphic encryption, we approximate the ReLU and Sigmoid activation functions using low-degree Chebyshev polynomials. This allowed us to build Learning in the Dark – a privacy-preserving machine learning model that can classify encrypted images with high accuracy. Learning in the Dark preserves users’ privacy since it is capable of performing high accuracy predictions by performing computations directly on encrypted data. In addition to that, the output of Learning in the Dark is generated in a blind and therefore privacy-preserving way by utilizing the properties of homomorphic encryption. Tanveer Khan, Antonis Michalas |
TrustCom | 2 |
| 2022 | Private Lives Matter: A Differential Private Functional Encryption SchemeabstractThe use of data combined with tailored statistical analysis has presented a unique opportunity to organizations in diverse fields to observe users' behaviors and needs, and accordingly adapt and fine-tune their services. However, in order to offer utilizable, plausible, and personalized alternatives to users, this process usually also entails a breach of their privacy. The use of statistical databases for releasing data analytics is growing exponentially, and while many cryptographic methods are utilized to protect the confidentiality of the data -- a task that has been ably carried out by many authors over the years -- only a few %rudimentary number of works focus on the problem of privatizing the actual databases. Believing that securing and privatizing databases are two equilateral problems, in this paper, we propose a hybrid approach by combining Functional Encryption with the principles of Differential Privacy. Our main goal is not only to design a scheme for processing statistical data and releasing statistics in a privacy-preserving way but also to provide a richer, more balanced, and comprehensive approach in which data analytics and cryptography go hand in hand with a shift towards increased privacy. Alexandros Bakas, Antonis Michalas, Tassos Dimitriou |
CODASPY | 2 |
| 2022 | Feel the Quantum Functioning: Instantiating Generic Multi-Input Functional Encryption from Learning with Errors
Alexandros Bakas, Antonis Michalas, Eugene Frimpong, Reyhaneh Rabaninejad |
DBSec | 2 |
| 2022 | Cryptographic Role-Based Access Control, Reconsidered
Bin Liu 0077, Antonis Michalas, Bogdan Warinschi |
ProvSec | 2 |
| 2022 | Symmetrical Disguise: Realizing Homomorphic Encryption Services from Symmetric Primitives
Alexandros Bakas, Eugene Frimpong, Antonis Michalas |
SecureComm | 3 |
| 2022 | MetaPriv: Acting in Favor of Privacy on Social Media Platforms
Robert Cantaragiu, Antonis Michalas, Eugene Frimpong, Alexandros Bakas |
SecureComm | 2 |
| 2022 | Footsteps in the fog: Certificateless fog-based access controlabstractThe proliferating adoption of the Internet of Things (IoT) paradigm has fuelled the need for more efficient and resilient access control solutions that aim to prevent unauthorized resource access. The majority of existing works in this field follow either a centralized approach (i.e. cloud-based) or an architecture where the IoT devices are responsible for all decision-making functions. Furthermore, the resource-constrained nature of most IoT devices make securing the communication between these devices and the cloud using standard cryptographic solutions difficult. In this paper, we propose a distributed access control architecture where the core components are distributed between fog nodes and the cloud. To facilitate secure communication, our architecture utilizes a Certificateless Hybrid Signcryption scheme without pairing. We prove the effectiveness of our approach by providing a comparative analysis of its performance in comparison to the commonly used cloud-based centralized architectures. Our implementation uses Azure – an existing commercial platform, and Keycloak – an open-source platform, to demonstrate the real-world applicability. Additionally, we measure the performance of the adopted encryption scheme on two types of resource-constrained devices to further emphasize the applicability of the proposed architecture. Finally, the experimental results are coupled with a theoretical analysis that proves the security of our approach. Eugene Frimpong, Antonis Michalas, Amjad Ullah |
Comput. Secur. | 2 |
| 2021 | Attestation Waves: Platform Trust via Remote Power Analysis
Ignacio M. Delgado-Lozano, Macarena C. Martínez-Rodríguez, Alexandros Bakas, Billy Bob Brumley, Antonis Michalas |
CANS | 5 |
| 2021 | Nowhere to Leak: A Multi-client Forward and Backward Private Symmetric Searchable Encryption Scheme
Alexandros Bakas, Antonis Michalas |
DBSec | 2 |
| 2021 | Blind Faith: Privacy-Preserving Machine Learning using Function ApproximationabstractOver the past few years, a tremendous growth of machine learning was brought about by a significant increase in adoption of cloud-based services. As a result, various solutions have been proposed in which the machine learning models run on a remote cloud provider. However, when such a model is deployed on an untrusted cloud, it is of vital importance that the users' privacy is preserved. To this end, we propose Blind Faith - a machine learning model in which the training phase occurs in plaintext data, but the classification of the users' inputs is performed on homomorphically encrypted ciphertexts. To make our construction compatible with homomorphic encryption, we approximate the activation functions using Chebyshev polynomials. This allowed us to build a privacy-preserving machine learning model that can classify encrypted images. Blind Faith preserves users' privacy since it can perform high accuracy predictions by performing computations directly on encrypted data. Tanveer Khan, Alexandros Bakas, Antonis Michalas |
ISCC | 3 |
| 2021 | Fake news outbreak 2021: Can we stop the viral spread?abstractSocial Networks' omnipresence and ease of use has revolutionized the generation and distribution of information in today's world. However, easy access to information does not equal an increased level of public knowledge. Unlike traditional media channels, social networks also facilitate faster and wider spread of disinformation and misinformation. Viral spread of false information has serious implications on the behaviours, attitudes and beliefs of the public, and ultimately can seriously endanger the democratic processes. Limiting false information's negative impact through early detection and control of extensive spread presents the main challenge facing researchers today. In this survey paper, we extensively analyze a wide range of different solutions for the early detection of fake news in the existing literature. More precisely, we examine Machine Learning (ML) models for the identification and classification of fake news, online fake news detection competitions, statistical outputs as well as the advantages and disadvantages of some of the available data sets. Finally, we evaluate the online web browsing tools available for detecting and mitigating fake news and present some open research challenges. Tanveer Khan, Antonis Michalas, Adnan Akhunzada |
J. Netw. Comput. Appl. | 2 |
| 2020 | Do Not Tell Me What I Cannot Do! (The Constrained Device Shouted under the Cover of the Fog): Implementing Symmetric Searchable Encryption on Constrained Devices
Eugene Frimpong, Alexandros Bakas, Hai-Van Dang, Antonis Michalas |
IoTBDS | 4 |
| 2020 | IoT-CryptoDiet: Implementing a Lightweight Cryptographic Library based on ECDH and ECDSA for the Development of Secure and Privacy-preserving Protocols in Contiki-NGabstractEven though the idea of transforming basic objects to smart objects with the aid sensors is not new, it is only now that we have started seeing the incredible impact of this digital transformation in our societies. There is no doubt that the Internet of Things (IoT) has the power to change our world and drive us to a complete social evolution. This is something that has been well understood by the research and industrial communities that have been investing significant resources in the field of IoT. In business and industry, there are thousands of IoT use cases and real-life IoT deployments across a variety of sectors (e.g. industry 4.0 and smart factories, smart cities, etc.). However, due to the vastly resource-constrained nature of the devices used in IoT, implementing secure and privacy-preserving services, using, for example, standard asymmetric cryptographic algorithms, has been a real challenge. The majority of IoT devices on the market currently employ the use of various forms of symmetric cryptography such as key pre-distribution. The overall efficiency of such implementations correlates directly to the size of the IoT environment and the deployment method. In this paper, we implement a lightweight cryptographic library that can be used to secure communication protocols between multiple communicating nodes without the need for external trusted entities or a server. Our work focuses on extending the functionalities of the User Datagram Protocol (UDP) broadcast application on the Contiki-NG Operating System (OS) platform. Eugene Frimpong, Antonis Michalas |
IoTBDS | 2 |
| 2020 | Power Range: Forward Private Multi-Client Symmetric Searchable Encryption with Range Queries SupportabstractSymmetric Searchable encryption (SSE) is an encryption technique that allows users to search directly over their outsourced encrypted data while preserving the privacy of both the files and the queries. In this paper, we present Power Range - a dynamic SSE scheme (DSSE) that supports range queries in the multi-client model. We prove that our construction captures the very crucial notion of forward privacy in the sense that additions and deletions of files do not reveal any information about the content of past queries. Finally, to deal with the problem of synchronization in the multi-client model, we exploit the functionality offered by Trusted Execution Environments and Intel’s SGX. Alexandros Bakas, Antonis Michalas |
ISCC | 2 |
| 2020 | Multi-Input Functional Encryption: Efficient Applications from Symmetric PrimitivesabstractFunctional Encryption (FE) allows users who hold a specific secret key (known as the functional key) to learn a specific function of encrypted data whilst learning nothing about the content of the underlying data. Considering this functionality and the fact that the field of FE is still in its infancy, we sought a route to apply this potent tool to design efficient applications. To this end, we first built a symmetric FE scheme for the l1norm of a vector space, which allows us to compute the sum of the components of an encrypted vector. Then, we utilized our construction, to design an Order-Revealing Encryption (ORE) scheme and a privately encrypted database. While there is room for improvement in our schemes, this work is among the first attempts that seek to utilize FE for the solution of practical problems that can have a tangible effect on people's daily lives. Alexandros Bakas, Antonis Michalas |
TrustCom | 2 |
| 2020 | Trust and Believe - Should We? Evaluating the Trustworthiness of Twitter UsersabstractSocial networking and micro-blogging services, such as Twitter, play an important role in sharing digital information. Despite the popularity and usefulness of social media, they are regularly abused by corrupt users. One of these nefarious activities is so-called fake news - a virus that has been spreading rapidly thanks to the hospitable environment provided by social media platforms. The extensive spread of fake news is now becoming a major problem with far-reaching negative repercussions on both individuals and society. Hence, the identification of fake news on social media is a problem of utmost importance that has attracted the interest not only of the research community but most of the big players on both sides - such as Facebook, on the industry side, and political parties on the societal one. In this work, we create a model through which we hope to be able to offer a solution that will instill trust in social network communities. Our model analyses the behaviour of 50,000 politicians on Twitter and assigns an influence score for each evaluated user based on several collected and analysed features and attributes. Next, we classify political Twitter users as either trustworthy or untrustworthy using random forest and support vector machine classifiers. An active learning model has been used to classify any unlabeled ambiguous records from our dataset. Finally, to measure the performance of the proposed model, we used accuracy as the main evaluation metric. Tanveer Khan, Antonis Michalas |
TrustCom | 2 |
| 2019 | Red Alert: Break-Glass Protocol to Access Encrypted Medical Records in the CloudabstractAvailability of medical records during an emergency situation is of paramount importance since it allows healthcare professionals to access patient's data on time and properly plan the next steps that need to be taken. Cloud storage has the potential to provide a solution to the problem of data unavailability during an emergency situation. However, sharing medical records raises several concerns about security and privacy. In this paper, we study the problem of how to share encrypted patients' data during an emergency situation. To this end, we propose a protocol through which a team of healthcare professionals can securely decrypt the medical records of a patient who is under an emergency situation (e.g. acute stroke). Furthermore, our protocol ensures that a team of healthcare professionals will only have access to the patient's data for the time needed to complete a specific process related to the patient's situation (e.g. transfer patient to the hospital). In our study, the dynamically granting and revoking data access during an emergency treatment is the main novelty. Marcela Tuler de Oliveira, Antonis Michalas, Adrien E. D. Groot, Henk A. Marquering, Sílvia Delgado Olabarriaga |
HealthCom | 2 |
| 2019 | Modern Family: A Revocable Hybrid Encryption Scheme Based on Attribute-Based Encryption, Symmetric Searchable Encryption and SGX
Alexandros Bakas, Antonis Michalas |
SecureComm (2) | 2 |
| 2017 | HealthShare: Using Attribute-Based Encryption for Secure Data Sharing between Multiple CloudsabstractIn this invited paper, we propose HealthShare - a forward-looking approach for secure ehealth data sharing between multiple organizations that are hosting patients data in different clouds. The proposed protocol is based on a Revocable Key-Policy Attribute-Based Encryption scheme and allows users to share encrypted health records based on a policy that has been defined by the data owner (i.e. patient, a member of the hospital, etc). Furthermore, access to a malicious or compromised user/organization can be easily revoked without the need to generate fresh encryption keys. Antonis Michalas, Noam Weingarten |
CBMS | 1 |
| 2017 | PaaSword: A Holistic Data Privacy and Security by Design Framework for Cloud ServicesabstractEnterprises increasingly recognize the compelling economic and operational benefits from virtualizing and pooling IT resources in the cloud. Nevertheless, the significant and valuable transformation of organizations that adopt cloud computing is accompanied by a number of security threats that should be considered. In this paper, we outline significant security challenges presented when migrating to a cloud environment and propose PaaSword – a novel holistic framework that aspires to alleviate these challenges. Specifically, the proposed framework involves a context-aware security model, the necessary policies enforcement mechanism along with a physical distribution, encryption and query middleware. Giannis Verginadis, Antonis Michalas, Panagiotis Gouvas, Gunther Schiefer, Gerald Hübsch, Iraklis Paraskakis |
J. Grid Comput. | 2 |
| 2017 | Providing User Security Guarantees in Public Infrastructure CloudsabstractThe infrastructure cloud (IaaS) service model offers improved resource flexibility and availability, where tenants - insulated from the minutiae of hardware maintenance - rent computing resources to deploy and operate complex systems. Large-scale services running on IaaS platforms demonstrate the viability of this model; nevertheless, many organizations operating on sensitive data avoid migrating operations to IaaS platforms due to security concerns. In this paper, we describe a framework for data and operation security in IaaS, consisting of protocols for a trusted launch of virtual machines and domain-based storage protection. We continue with an extensive theoretical analysis with proofs about protocol resistance against attacks in the defined threat model. The protocols allow trust to be established by remotely attesting host platform configuration prior to launching guest virtual machines and ensure confidentiality of data in remote storage, with encryption keys maintained outside of the IaaS domain. Presented experimental results demonstrate the validity and efficiency of the proposed protocols. The framework prototype was implemented on a test bed operating a public electronic health record system, showing that the proposed protocols can be integrated into existing cloud environments. Nicolae Paladi, Christian Gehrmann 0001, Antonis Michalas |
IEEE Trans. Cloud Comput. | 3 |
| 2016 | LocLess: Do you Really Care Where Your Cloud Files Are?abstractPhysical location of data in cloud storage is a problem that gains a lot of attention not only from the actual cloud providers but also from the end users' who lately raise many concerns regarding the privacy of their data. It is a common practice that cloud service providers create replicate users' data across multiple physical locations. However, moving data in different countries means that basically the access rights are transferred based on the local laws of the corresponding country. In other words, when a cloud service provider stores users' data in a different country then the transferred data is subject to the data protection laws of the country where the servers are located. In this paper, we propose LocLess, a protocol which is based on a symmetric searchable encryption scheme for protecting users' data from unauthorized access even if the data is transferred to different locations. The idea behind LocLess is that "Once data is placed on the cloud in an unencrypted form or encrypted with a key that is known to the cloud service provider, data privacy becomes an illusion". Hence, the proposed solution is solely based on encrypting data with a key that is only known to the data owner. Antonis Michalas, Kassaye Yitbarek Yigzaw |
CloudCom | 1 |
| 2015 | PaaSword: A Holistic Data Privacy and Security by Design Framework for Cloud ServicesabstractEnterprises increasingly recognize the compelling economic and operational benefits from virtualizing and pooling IT resources in the cloud. Nevertheless, the significant and valuable transformation of organizations that adopt cloud computing is accompanied by a number of security threats that should be considered. In this position paper, we outline significant security challenges presented when migrating to a cloud environment and propose PaaSword - a novel holistic framework that aspires to alleviate these challenges. Specifically, this proposed framework involves a context-aware security model, the necessary policies enforcement mechanism along with a physical distribution, encryption and query middleware. Giannis Verginadis, Antonis Michalas, Panagiotis Gouvas, Gunther Schiefer, Gerald Hübsch, Iraklis Paraskakis |
CLOSER | 2 |
| 2014 | Security aspects of e-Health systems migration to the cloudabstractAs adoption of e-health solutions advances, new computing paradigms - such as cloud computing - bring the potential to improve efficiency in managing medical health records and help reduce costs. However, these opportunities introduce new security risks which can not be ignored. Based on our experience with deploying part of the Swedish electronic health records management system in an infrastructure cloud, we make an overview of major requirements that must be considered when migrating e-health systems to the cloud. Furthermore, we describe in-depth a new attack vector inherent to cloud deployments and present a novel data confidentiality and integrity protection mechanism for infrastructure clouds. This contribution aims to encourage exchange of best practices and lessons learned in migrating public e-health systems to the cloud. Antonis Michalas, Nicolae Paladi, Christian Gehrmann 0001 |
Healthcom | 1 |
| 2014 | The lord of the sense: A privacy preserving reputation system for participatory sensing applicationsabstractElectronic devices we use on a daily basis collect sensitive information without preserving user's privacy. In this paper, we propose the lord of the sense (LotS), a privacy preserving reputation system for participatory sensing applications. Our system maintains the privacy and anonymity of information with the use of cryptographic techniques and combines voting approaches to support users' reputation. Furthermore, LotS maintains accountability by tracing back a misbehaving user while maintaining k-anonymity. A detailed security analysis is presented with the current advantages and disadvantages of our system. Antonis Michalas, Nikos Komninos |
ISCC | 1 |
| 2014 | Multi-party trust computation in decentralized environments in the presence of malicious adversaries
Tassos Dimitriou, Antonis Michalas |
Ad Hoc Networks | 2 |
| 2011 | Privacy-preserving scheme for mobile ad hoc networksabstractIn this paper we propose a decentralized privacy-preserving scheme for mobile ad hoc networks (MANETs), where nodes establish security associations. In order to achieve privacy and security, we use homomorphic encryption and polynomial intersection so as to find the common friends of two nodes. Through our experimental results we verify the correctness of our scheme given the limitations of MANETs. Antonis Michalas, Vladimir A. Oleshchuk, Nikos Komninos, Neeli R. Prasad |
ISCC | 1 |