VLDB 2026 Research / reviewers in the wild / expert
Ioannis Krontiris
dblp:32/1264
· DBLP profile ↗
20ranked-venue papers
5as first author
5since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 1 first-author · 3 since 2021Computer networks · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Quantifying Calibration Error in Neural Networks Through Evidence-Based TheoryabstractTrustworthiness in neural networks is crucial for their deployment in critical applications, where reliability, confidence, and uncertainty play a pivotal role in decision-making. Traditional performance metrics such as accuracy and precision fail to capture these aspects, particularly in cases where models exhibit overconfidence. To address these limitations, this paper introduces a novel framework for quantifying the trustworthiness of neural networks by incorporating subjective logic into the evaluation of Expected Calibration Error (ECE). This method provides a comprehensive measure of trust, distrust, and uncertainty by clustering predicted probabilities and fusing opinions using appropriate fusion operators. We demonstrate the effectiveness of this approach through experiments on the MNIST and CIFAR-10 datasets, where post-calibration results indicate improved trustworthiness. The proposed framework offers a more interpretable and nuanced assessment of AI models, with potential applications in sensitive domains such as healthcare and autonomous systems. Koffi Ismael Ouattara, Ioannis Krontiris, Theodosis Dimitrakos, Frank Kargl |
FUSION | 2 |
| 2025 | Actions Speak Louder Than Words: Evidence-Based Trust Level Evaluation in Multi-agent Systems
Nikolaos Fotos, Koffi Ismael Ouattara, Dimitrios S. Karas, Ioannis Krontiris, Weizhi Meng 0001, Thanassis Giannetsos |
ICICS (2) | 4 |
| 2025 | An Optimized Framework for DSPG Synthesis and Trust Network Analysis with Subjective Logic
Koffi Ismael Ouattara, Ana Petrovska, Ioannis Krontiris, Theodosis Dimitrakos, Frank Kargl |
RuleML+RR | 3 |
| 2023 | Achieving Higher Level of Assurance in Privacy Preserving Identity WalletsabstractRecent advances in Decentralized Digital Identity solutions, revolving around the use of Verifiable Credentials towards identity sovereignty, are centered around Identity Wallets for ensuring that identity data control remains with the user. However, such schemes still lack the capabilities to provide higher Level of Assurance (LoA) guarantees, for identity verification, which restricts their full potential. In this paper, we design and showcase DOOR; a library that enables Identity Wallets to leverage hardware Roots-of-Trust (RoT) for binding user authentication factors to HW-based keys, thus, allowing for both proof of (User) identity and (Wallet) integrity, bringing them in alignment with emerging regulations and standards that require higher LoA for services (e.g. eIDAS). At the same time, we make sure that privacy-enhancing properties like selective-disclosure are fully supported in order to make the Wallet compliant with privacy regulations (e.g. GDPR). To achieve all the above, we have designed an enhanced variant of Attribute-based Direct Anonymous Attestation (DAA-A) crypto protocol for offering anonymity, unlinkability, and unforgeability, while being the first to offer strong guarantees on the Wallet’s integrity when constructing attribute attestations. We formally prove the security properties of DOOR, offered by the underlying crypto primitives used to enable selective disclosure of attributes, by describing their construction while also benchmarking their computational footprint and comparing them with other widespread cryptographic mechanisms (adopted by the standards) in terms of performance, size of the associated verifiable presentations while safeguarding user anonymous authentication and unlinkability. Benjamin Larsen, Nada El Kassem, Thanassis Giannetsos, Ioannis Krontiris, Stefanos Vasileiadis, Liqun Chen 0002 |
TrustCom | 4 |
| 2021 | Direct anonymous attestation on the road: efficient and privacy-preserving revocation in C-ITSabstractVehicular networks rely on Public Key Infrastructure (PKIs) to generate long-term and short-term pseudonyms that protect vehicle's privacy. Instead of relying on a complex and centralized ecosystem of PKI entities, a more scalable solution is to rely on Direct Anonymous Attestation (DAA) and the use of Trusted Computing elements. In particular, revocation based on DAA is very attractive in terms of efficiency and privacy: it does not require the use of Certificate Revocation Lists (CRLs) and revocation authorities can exclude misbehaving participants from a V2X system without resolving (i.e. learning) their long-term identity. In this paper, we present a novel revocation protocol based on the use of DAA and showcase a detailed design and modeling of the implementation on a real TPM platform in order to demonstrate its significant performance improvements compared to existing solutions. Benjamin Larsen, Thanassis Giannetsos, Ioannis Krontiris, Kenneth A. Goldman |
WISEC | 3 |
| 2019 | Securing V2X Communications for the Future: Can PKI Systems offer the answer?abstractOver recent years, emphasis in secure V2X communications research has converged on the use of Vehicular Public Key Infrastructures (VPKIs) for credential management and privacy-friendly authentication services. However, despite the security and privacy guarantees offered by such solutions, there are still a number of challenges to be conquered. By reflecting on state-of-the-art PKI-based architectures, in this paper, we identify their limitations focusing on scalability, interoperability, pseudonym reusage policies and revocation mechanisms. We argue that in their current form such mechanisms cannot capture the strict security, privacy, and trust requirements of all involved stakeholders. Motivated by these weaknesses, we then proceed on proposing the use of trusted computing technologies as an enabler for more decentralized approaches where trust is shifted from the back-end infrastructure to the edge. We debate on the advantages offered and underline the specifis of such a novel approach based on the use of advanced cryptographic primitives, using Direct Anonymous Attestation (DAA) as a concrete example. Our goal is to enhance run-time security, privacy and trustworthiness of edge devices with a scalable and decentralized solution eliminating the need for federated infrastructure trust. Based on our findings, we posit open issues and challenges, and discuss possible ways to address them. Thanassis Giannetsos, Ioannis Krontiris |
ARES | 2 |
| 2017 | Privacy-respecting auctions and rewarding mechanisms in mobile crowd-sensing applications
Tassos Dimitriou, Ioannis Krontiris |
J. Netw. Comput. Appl. | 2 |
| 2015 | Privacy-Respecting Auctions as Incentive Mechanisms in Mobile Crowd Sensing
Tassos Dimitriou, Ioannis Krontiris |
WISTP | 2 |
| 2015 | A platform for privacy protection of data requesters and data providers in mobile sensing
Ioannis Krontiris, Tassos Dimitriou |
Comput. Commun. | 1 |
| 2014 | Towards a Framework for Benchmarking Privacy-ABC Technologies
Fatbardh Veseli, Tsvetoslava Vateva-Gurova, Ioannis Krontiris, Kai Rannenberg, Neeraj Suri |
SEC | 3 |
| 2014 | Trust Relationships in Privacy-ABCs' Ecosystems
Ahmad Sabouri, Ioannis Krontiris, Kai Rannenberg |
TrustBus | 2 |
| 2013 | Privacy-Respecting Discovery of Data Providers in Crowd-Sensing ApplicationsabstractCrowd-sensing applications are based on the contribution of user-related context information and as such, they are particularly vulnerable to privacy-compromising attacks. In this paper we focus on the problem of information discovery by data consumers who can pose queries to mobile users providing sensed data. The way to protect the privacy of these mobile users is through the use of cloud-based agents, which obfuscate user location and enforce the sharing practices of their owners. The cloud agents organise themselves in a structure, namely a quadtree, that enables queriers to contact directly the mobile users in the area of interest and, based on their own criteria, select the ones to get sensing data from. The tree is kept in a decentralized manner, stored and maintained by the mobile agents themselves, thus avoiding the privacy implications of previous, centralized techniques. Our proposed solution complements and expands upon prior work in the area while it is shown experimentally to be both scalable, efficient and easy to maintain. Ioannis Krontiris, Tassos Dimitriou |
DCOSS | 1 |
| 2012 | Privacy-by-design based on quantitative threat modelingabstractWhile the general concept of “Privacy-by-Design (PbD)” is increasingly a popular one, there is considerable paucity of either rigorous or quantitative underpinnings supporting PbD. Drawing upon privacy-aware modeling techniques, this paper proposes a quantitative threat modeling methodology (QTMM) that can be used to draw objective conclusions about different privacy-related attacks that might compromise a service. The proposed QTMM has been empirically validated in the context of the EU project ABC4Trust, where the end-users actually elicited security and privacy requirements of the so-called privacy-Attribute Based Credentials (privacy-ABCs) in a real-world scenario. Our overall objective, is to provide architects of privacy-respecting systems with a set of quantitative and automated tools to help decide across functional system requirements and the corresponding trade-offs (security, privacy and economic), that should be taken into account before the actual deployment of their services. Jesus Luna, Neeraj Suri, Ioannis Krontiris |
CRiSIS | 3 |
| 2012 | Attribute-Based Credentials for Trust (ABC4Trust)
Ahmad Sabouri, Ioannis Krontiris, Kai Rannenberg |
TrustBus | 2 |
| 2011 | Towards privacy-enhanced mobile communities - Architecture, concepts and user trials
Markus Tschersich, Christian Kahl, Stephan Heim, Stephen Crane, Katja Böttcher, Ioannis Krontiris, Kai Rannenberg |
J. Syst. Softw. | 6 |
| 2010 | Arbitrary Code Injection through Self-propagating Worms in Von Neumann Architecture DevicesabstractMalicious code (or malware) is defined as a software designed to execute attacks on software systems and fulfill the harmful intents of an attacker. As lightweight embedded devices become more ubiquitous and increasingly networked, they present a new and very disturbing target for malware developers. In this paper, we demonstrate how to execute malware on wireless sensor nodes that are based on the Von Neumann architecture. We achieve this by exploiting a buffer overflow vulnerability to smash the call stack and intrude a remote node over the radio channel. By breaking the malware into multiple packets, the attacker can inject arbitrarily long malicious code to the node and completely take control of it. Then we proceed to show how the malware can be crafted to become a self-replicating worm that broadcasts itself and infects the network in a hop-by-hop manner. To our knowledge, this is the first instance of a self-propagating worm that provides a detailed analysis along with instructions in order to execute arbitrary malicious code. We also provide a complete implementation of our attack, measure its effectiveness in terms of time taken for the worm to propagate to the entire sensor network and, finally, suggest possible countermeasures. Thanassis Giannetsos, Tassos Dimitriou, Ioannis Krontiris, Neeli R. Prasad |
Comput. J. | 3 |
| 2009 | Cooperative Intrusion Detection in Wireless Sensor Networks
Ioannis Krontiris, Zinaida Benenson, Thanassis Giannetsos, Felix C. Freiling, Tassos Dimitriou |
EWSN | 1 |
| 2008 | LIDeA: a distributed lightweight intrusion detection architecture for sensor networksabstractWireless sensor networks are vulnerable to adversaries as they are frequently deployed in open and unattended environments. Preventive mechanisms can be applied to protect them from an assortment of attacks. However, more sophisticated methods, like intrusion detection systems, are needed to achieve a more autonomic and complete defense mechanism, even against attacks that have not been anticipated in advance. In this paper, we present a lightweight intrusion detection system, called LIDeA, designed for wireless sensor networks. LIDeA is based on a distributed architecture, in which nodes overhear their neighboring nodes and collaborate with each other in order to successfully detect an intrusion. We show how such a system can be implemented in TinyOS, which components and interfaces are needed, and what is the resulting overhead imposed. Ioannis Krontiris, Thanassis Giannetsos, Tassos Dimitriou |
SecureComm | 1 |
| 2008 | Launching a Sinkhole Attack in Wireless Sensor Networks; The Intruder SideabstractOne of the reasons that the research of intrusion detection in wireless sensor networks has not advanced significantly is that the concept of "intrusion" is not clear in these networks. In this paper we investigate in depth one of the most severe attacks against sensor networks, namely the sinkhole attack, and we emphasize on strategies that an attacker can follow to successfully launch such an attack. Then we propose specific detection rules that can make legitimate nodes become aware of the threat, while the attack is still taking place. Finally, we demonstrate the attack and present some implementation details that emphasize the little effort that an attacker would need to put in order to break into a realistic sensor network. Ioannis Krontiris, Thanassis Giannetsos, Tassos Dimitriou |
WiMob | 1 |
| 2004 | SPEED: Scalable Protocols for Efficient Event Delivery in Sensor Networks
Tassos Dimitriou, Ioannis Krontiris, Fotios Nikakis, Paul G. Spirakis |
NETWORKING | 2 |