Panagiotis Bountakas

dblp:291/6921 · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0001-8155-1784ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 7 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Advanced situational awareness and resilience for hyper-connected industrial scenarios
Cristina Alcaraz, Fabio Martinelli, Panagiotis Bountakas
Future Gener. Comput. Syst.3
2026 Enhanced-LLM extraction of CTI from unstructured threat reports. A tough nut to crack or a walk in the park?
Konstantina Psarrou, Panagiotis Bountakas, Dimitris Eleutheriou, Rafail A. Ellinitakis, Konstantinos Fysarakis, Alexios Lekidis, George Spanoudakis
Future Gener. Comput. Syst.2
2026 Adaptive DeSeTra: Adaptive deformable-span self-attention transformer for LLM security
abstract
Large Language Models (LLMs) remain vulnerable to prompt-based attacks such as jailbreaks and prompt injection, highlighting the need for security mechanisms that not only detect malicious intent but also determine whether an attack actually succeeds. In this paper, we introduce Adaptive DeSeTra, a novel security-centric Transformer model designed for deployment that mirrors the real-world attack pipeline through two layers: intent detection via multi-class prompt classification into Benign , Jailbreak and Prompt Injection ; and impact assessment via response-level classification into Compliant or Refusal . Prompt-level intent identification enables low-latency routing to appropriate guardrails, policies, and monitoring controls before a malicious prompt reaches the target Large Language Model (LLM). Conversely, response-level evaluation quantifies whether the adversarial attempt resulted in compliance or refusal, providing an outcome-based measure of attack effectiveness that supports risk assessment and enables more informative security benchmarking than intent detection alone. Experiments demonstrate strong performance across both layers: 99.35% Accuracy/F1/Precision/Recall with 99.85% AUC for prompt classification, and 99.80% for the same metrics with 99.98% AUC for impact assessment, positioning Adaptive DeSeTra as a strong candidate for deployment-oriented LLM security monitoring and evaluation.
Konstantinos Giapantzis, Panagiotis Bountakas, Apostolis Zarras, Aristeidis Farao, Vaios Bolgouras, Christos Xenakis
Inf. Sci.2
2024 AIAS: AI-ASsisted cybersecurity platform to defend against adversarial AI attacks
abstract
The increasing integration of Artificial Intelligence (AI) in critical sectors such as healthcare, finance, and cybersecurity has simultaneously exposed these systems to unique vulnerabilities and cyber threats. This paper discusses the escalating risks associated with adversarial AI and outlines the development of AIAS. AIAS is a comprehensive, AI-driven security platform designed to enhance the resilience of AI systems against such threats. In addition, AIAS features advanced modules for threat simulation, detection, mitigation, and deception, using adversarial defense techniques, attack detection mechanisms, and sophisticated honeypots. The platform leverages explainable AI (XAI) to improve the transparency and effectiveness of threat countermeasures. Through meticulous analysis and innovative methodologies, AIAS aims to revolutionize cybersecurity defenses, enhancing the robustness of AI systems against adversarial attacks while fostering a safer deployment of AI technologies in critical applications. The paper details the components of the AIAS platform, explores its operational framework, and discusses future research directions for advancing AI security measures.
George Petihakis 0002, Aristeidis Farao, Panagiotis Bountakas, Athanasia Sabazioti, John Polley, Christos Xenakis
ARES3
2024 SYNAPSE - An Integrated Cyber Security Risk & Resilience Management Platform, With Holistic Situational Awareness, Incident Response & Preparedness Capabilities: SYNAPSE
abstract
In an era of escalating cyber threats, the imperative for robust and comprehensive cybersecurity measures has never been more pressing. To address this challenge, SYNAPSE presents a pioneering approach by conceptualising, designing, and delivering an Integrated cybersecurity Risk & Resilience Management Platform. The innovation of this platform lies in the integration of key elements, such as situational awareness, incident response, and preparedness (i.e., cyber range), augmented by advanced AI capabilities. Through its holistic approach, SYNAPSE aims to elevate cyber resilience by not only mitigating threats but also fostering a culture of proactive defence, informed decision-making, and collaborative response within organisations and across industries.
Panagiotis Bountakas, Konstantinos Fysarakis, Thomas Kyriakakis, Panagiotis Karafotis, Aristeidis Sotiropoulos, Maria Tasouli, Cristina Alcaraz, George Alexandris, Vassiliki Andronikou, Tzortzia Koutsouri, Romarick Yatagha, George Spanoudakis, Sotiris Ioannidis, Fabio Martinelli, Oleg Illiashenko
ARES1
2023 Adversarial Machine Learning Attacks on Multiclass Classification of IoT Network Traffic
abstract
Machine Learning-based Intrusion Detection Systems have been proven to be very effective in the protection of IoT Networks. However, the expansion of Adversarial Machine Learning attacks threatens their efficacy affecting also the security of IoT networks. Thus, this paper proposes a Machine Learning-driven methodology for multiclass classification of cyber-attacks in IoT networks and investigates the robustness of the Machine and Deep Learning classifiers against several well-known Adversarial Machine Learning attacks (JSMA, FGSM, DeepFool). Moreover, the effectiveness of the Adversarial Training defense method has been studied in tackling Adversarial Machine Learning attacks. The proposed methodology was evaluated using a new and large IoT dataset (IoTID20) and the experimental results concluded that the Random Forest classifier can classify the cyber-attacks with high classification accuracy (99.9%) as well as the JSMA, FGSM, and DeepFool attacks can significantly reduce the performance of all the classifiers. Finally, based on the evaluation adversarial training can overall enhance the classifiers’ robustness against all the utilized Adversarial Machine Learning attacks without affecting the performance when only normal samples are present.
Vasileios Pantelakis, Panagiotis Bountakas, Aristeidis Farao, Christos Xenakis
ARES2
2023 A Bring Your Own Device security awareness survey among professionals
abstract
The increasing prevalence of Bring Your Own Device (BYOD) practices in the workplace has posed significant challenges to organizations in terms of security and management. This paper presents a survey-based study aimed at exploring the adoption, implications, and security considerations associated with BYOD policies. The study utilized a questionnaire developed based on guidelines provided by the National Institute of Standards and Technology (NIST). The primary objectives of this research are to investigate the cautiousness and awareness of BYOD users, as well as the effectiveness of security measures implemented by organizations, in order to gain insights into the key aspects of BYOD practices in the workplace. The findings of this paper highlight the need for increased caution among BYOD users regarding device security, a lack of knowledge among users about organizational security measures, and the potential for enhancing security policies and implementing additional measures despite organizations having achieved a satisfactory level of security for BYOD.
George Petihakis 0002, Dimitrios Kiritsis, Aristeidis Farao, Panagiotis Bountakas, Aggeliki Panou, Christos Xenakis
ARES4
2023 HELPHED: Hybrid Ensemble Learning PHishing Email Detection
abstract
Phishing email attack is a dominant cyber-criminal strategy for decades. Despite its longevity, it has evolved during the COVID-19 pandemic, indicating that adversaries exploit critical situations to lure victims. Plenty of detectors have been proposed over the years, which mainly focus on the contents or the textual information of emails; however, to cope with the evolution of phishing emails more sophisticated approaches should be introduced that will exploit all the emails' traits to enhance the detection capability of Machine Learning/Deep Learning classifiers. To tackle the limitations of existing works, this paper proposes a phishing email detection methodology, named HELPHED that focuses on the detection of phishing emails by combining Ensemble Learning methods with hybrid features. The hybrid features provide an accurate representation of emails by fusing their content and textual traits. We propose two methods of HELPHED, the first one employs the Stacking Ensemble Learning method, while the second method utilizes the Soft Voting Ensemble Learning. Both methods deploy two different Machine Learning algorithms to handle the hybrid features separately, yet in parallel, minimizing the features' complexity and improving the model's performance. A thorough evaluation analysis is carried out considering innovative guidelines that aim to prevent partial and misleading results. Experimental tests verified that the combination of hybrid features with Ensemble Learning, overall, accomplishes better detection performance than when employing only content-based or text-based features. Numerical results on a rich imbalanced dataset (i.e., 32,051 benign and 3,460 phishing email samples) that considers the evolution of phishing emails show that Soft Voting Ensemble Learning outperforms other prominent Machine Learning/Deep Learning algorithms and existing works yielding F1-score equal to 0.9942.
Panagiotis Bountakas, Christos Xenakis
J. Netw. Comput. Appl.1
2022 GTM: Game Theoretic Methodology for optimal cybersecurity defending strategies and investments
abstract
Investments on cybersecurity are essential for organizations to protect operational activities, develop trust relationships with clients, and maintain financial stability. A cybersecurity breach can lead to financial losses as well as to damage the reputation of an organization. Protecting an organization from cyber attacks demands considerable investments; however, it is known that organisations unequally divide their budget between cybersecurity and other technological needs. Organizations must consider cybersecurity measures, including but not limited to security controls, in their cybersecurity investment plans. Nevertheless, designing an effective cybersecurity investment plan to optimally distribute the cybersecurity budget is a primary concern. This paper presents GTM, a methodology depicted as a tool dedicated to providing optimal cybersecurity defense strategies and investment plans. GTM utilizes attack graphs to predict all possible cyber attacks, game theory to simulate the cyber attacks and 0-1 Knapsack to optimally allocate the budget. The output of GTM is an optimal cybersecurity strategy that includes security controls to protect the organisation against potential cyber attacks and enhance its cyber defenses. Furthermore, GTM’s effectiveness is evaluated against three use cases and compared against different attacker types under various scenarios.
Ioannis Kalderemidis, Aristeidis Farao, Panagiotis Bountakas, Sakshyam Panda, Christos Xenakis
ARES3
2022 EKnad: Exploit Kits' network activity detection
Panagiotis Bountakas, Christoforos Ntantogian, Christos Xenakis
Future Gener. Comput. Syst.1
2021 A Comparison of Natural Language Processing and Machine Learning Methods for Phishing Email Detection
abstract
Phishing is the most-used malicious attempt in which attackers, commonly via emails, impersonate trusted persons or entities to obtain private information from a victim. Even though phishing email attacks are a known cybercriminal strategy for decades, their usage has been expanded over last couple of years due to the COVID-19 pandemic, where attackers exploit people’s consternation to lure victims. Therefore, further research is needed in the phishing email detection field. Recent phishing email detection solutions that extract representational text-based features from the email’s body have proved to be an appropriate strategy to tackle these threats. This paper proposes a comparison approach for the combined usage of Natural Language Processing (TF-IDF, Word2Vec, and BERT) and Machine Learning (Random Forest, Decision Tree, Logistic Regression, Gradient Boosting Trees, and Naive Bayes) methods for phishing email detection. The evaluation was performed on two datasets, one balanced and one imbalanced, both of which were comprised of emails from the well-known Enron corpus and the most recent emails from the Nazario phishing corpus. The best combination in the balanced dataset proved to be the Word2Vec with the Random Forest algorithm, while in the imbalanced dataset the Word2Vec with the Logistic Regression algorithm.
Panagiotis Bountakas, Konstantinos Koutroumpouchos, Christos Xenakis
ARES1
2021 NodeXP: NOde.js server-side JavaScript injection vulnerability DEtection and eXPloitation
Christoforos Ntantogian, Panagiotis Bountakas, Dimitris Antonaropoulos, Constantinos Patsakis, Christos Xenakis
J. Inf. Secur. Appl.2