Åvald Åslaugson Sommervoll

dblp:283/4733 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2024
0000-0001-5232-5630ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Optimizing Deployment of Homomorphic Encryption and SQL using Reinforcement Learning
abstract
This research explores optimization strategies for the deployment of SQL and homomorphic encryption using reinforcement learning. Marginal gains are established and suggests greater inquiry into optimization techniques as a means of introducing more secure compute to production environments.
Ryan Marinelli, Åvald Åslaugson Sommervoll, Laszlo Erdodi
IEEE Big Data2
2021 Dreaming of Keys: Introducing the Phantom Gradient Attack
Åvald Åslaugson Sommervoll
ICISSP1
2021 The Phantom Gradient Attack: A Study of Replacement Functions for the XOR Function
Åvald Åslaugson Sommervoll
QSHINE1
2021 Simulating SQL injection vulnerability exploitation using Q-learning reinforcement learning agents
abstract
In this paper, we propose a formalization of the process of exploitation of SQL injection vulnerabilities. We consider a simplification of the dynamics of SQL injection attacks by casting this problem as a security capture-the-flag challenge. We model it as a Markov decision process, and we implement it as a reinforcement learning problem. We then deploy reinforcement learning agents tasked with learning an effective policy to perform SQL injection; we design our training in such a way that the agent learns not just a specific strategy to solve an individual challenge but a more generic policy that may be applied to perform SQL injection attacks against any system instantiated randomly by our problem generator. We analyze the results in terms of the quality of the learned policy and in terms of convergence time as a function of the complexity of the challenge and the learning agent’s complexity. Our work fits in the wider research on the development of intelligent agents for autonomous penetration testing and white-hat hacking, and our results aim to contribute to understanding the potential and the limits of reinforcement learning in a security environment.
Laszlo Erdodi, Åvald Åslaugson Sommervoll, Fabio Massimo Zennaro
J. Inf. Secur. Appl.2