VLDB 2026 Research / reviewers in the wild / expert
George Loukas
dblp:40/2991 · also Georgios Loukas
· DBLP profile ↗
25ranked-venue papers
3as first author
10since 2021 · last 2025
0000-0003-3559-5182ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 7 since 2021Computer networks · 5 · 2 first-authorSoftware engineering, systems software and programming languages · 3Human-computer interaction and ubiquitous computing · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Mixed-Methods Investigation of XR Security Warnings - Lessons LearnedabstractAs immersive XR environments become more prevalent, timely and effective security warnings are essential to protect users from cyberattacks that compromise performance and well-being. This paper investigates how users perceive and respond to in-headset alerts triggered during Denial-of-Service (DoS) attacks. We developed a real-time warning system and evaluated its effectiveness across three pilot studies ($n$= 46) in healthcare and industrial training scenarios. Using self-report measures (IDSQ, SAM) and behavioural categorization, we assessed alert comprehension, urgency perception, and user action. We distil three design lessons emphasizing the importance of visual salience, modality coordination, and urgency calibration. These findings offer practical guidance for designing effective XR security notifications that support user awareness and action during immersive threats. Junyi Zou, Riccardo Bovo, George Loukas |
CBMI | 4 |
| 2025 | Doing cybersecurity at home: A human-centred approach for mitigating attacks in AI-enabled home devicesabstract• To identify cyber-attacks on the AI, users must have some prior understanding of the AI parameters and their normativity. • Multimodal indicators embedded across the ecosystem of AI-enabled devices are an effective way in raising users’ attention to cyber-attacks. • Engaging users to actively diagnose and resolve cyber-attacks on AI-enabled devices in the home context must take into consideration the home routines, and be designed to avoid cognitive overload. • One way to minimise overload is to make use of users’ propensity to generalise their cybersecurity knowledge and skills where possible. AI-enabled devices are increasingly introduced in the home context and cyber-attacks targeting their AI component are becoming more frequent. Moving away from seeing the user as the problem to recognising the user as part of the solution, our research reports on a novel cybersecurity intervention (comprising Explainable AI features, assisted remediation) designed to support users to identify, diagnose and mitigate cyber-attacks on the AI component of their smart devices. We carried out a case study of a bespoke smart heating device inclusive of this intervention and conducted fieldwork with ten households who experienced simulated integrity cyber-attacks over a month. Our research contributes an understanding of how to design AI-enabled devices and their ecosystems to support users to perceive integrity cyber-attacks, offering new considerations for intervention design that exploits multimodal indicators and supports users to troubleshoot themselves the causes as well as actions of cyber-attacks. Contributing to the growing area of human-centred cybersecurity, we evidence the distinctive challenges users face when evaluating integrity attacks on the AI component in the home context. Asimina Vasalou, Laura Benton, Ana Luisa Serta, Andrea Gauthier, Ceylan Besevli, Sarah Turner, Rea Gill, Rachael Payler, Etienne B. Roesch, Kevin McAreavey, Kim Bauters, Weiru Liu, Hsueh-Ju Chen, Dennis Ivory, Emmanouil A. Panaousis, George Loukas |
Comput. Secur. | 16 |
| 2024 | In pursuit of thermal comfort: An exploration of smart heating in everyday lifeabstractSmart Home Heating Technologies (SHHT) have been designed to improve demand flexibility and energy conservation. SHHT rely on rational theories of energy use postulating that people will use less energy when the energy cost is higher. The inclusion of AI within SHHT is poised to optimise energy use in the future as the introduction of lower carbon energy sources place new demands on the grid. When SHHT is introduced in the home, however, they become situated in temporal heating practices that are shaped by an interplay of materiality, meanings, and competencies. We report findings from a mixed methods field study involving eleven households utilising an AI-enabled SHHT probe ‘Squid’. Taking a temporal focus throughout, our study contributes a new lens as to why households may not fully engage with SHHT's rational design, given that energy conversation is already embedded in their ongoing socio-material practices with heating. Focusing on the AI-human relation, we articulate the necessity for human agency where heating is involved, whilst also advancing an understanding of the new forms of hidden labour that households incur before they can engage with the AI. Crucially, our research informs the ongoing HCI concern over how humans understand AI, raising the question of who is responsible to assess the appropriateness of AI when the effects of human-AI performance remain opaque. Our findings contribute a new theoretical perspective into the intricate relationship between individuals and AI in the home and raise several new design implications for SHHT. Asimina Vasalou, Andrea Gauthier, Ana Luisa Serta, Ceylan Besevli, Sarah Turner, Rachael Payler, Rea Gill, Kevin McAreavey, George Loukas, Weiru Liu, Roser Beneito-Montagut |
Int. J. Hum. Comput. Stud. | 9 |
| 2023 | Privacy Impact Assessment of Cyber Attacks on Connected and Autonomous VehiclesabstractConnected and autonomous vehicles (CAVs) are vulnerable to security gaps that can result in serious consequences, including cyber-physical and privacy risks. For example, an attacker can reconstruct a vehicle’s location trajectory by knowing the speed and steering wheel position of the vehicle. Such inferences not only lead to safety issues but also significantly threaten privacy. This paper assesses the privacy impacts of cyber threats on vehicular networks. We augment the Privacy Risk Assessment Methodology (PRAM), proposed by the National Institute of Standards and Technology, with cyber threats, with cyber threats, which are, in practice, mapped to PRAM impact metrics. We demonstrate the practical application of the enhanced PRAM methodology through a use case that highlights attacks leading to privacy risks in CAVs. The consideration of cyber attacks for privacy risk assessment addresses a major gap in current practices, which is to integrate privacy risk into cyber risk management. Sakshyam Panda, Emmanouil A. Panaousis, George Loukas, Konstantinos Kentrotis |
ARES | 3 |
| 2023 | Virtually secure: A taxonomic assessment of cybersecurity challenges in virtual reality environments
Blessing Odeleye, George Loukas, Ryan Heartfield, Georgia Sakellari, Emmanouil A. Panaousis, Fotis Spyridonis |
Comput. Secur. | 2 |
| 2023 | CROSS: A framework for cyber risk optimisation in smart homesabstractThis work introduces a decision support framework, called Cyber Risk Optimiser for Smart homeS (CROSS), which advises both smart home users and smart home service providers on how to select an optimal portfolio of cyber security controls to counteract cyber attacks in a smart home including traditional cyber attacks and adversarial machine learning attacks. CROSS is based on a multi-objective bi-level two-stage optimisation. In stage-one optimisation, the problem is modelled as a multi-leader-follower game that considers both security and economic objectives, where the provider selects a security portfolio to protect both itself and its users, while rational attackers target the weakest path. Stage-two optimisation is a Stackelberg security game that focuses on additional user security controls under the remit of smart home users. While CROSS can potentially be applied to other similar use cases, in this paper, our aim is to address threats against artificial intelligence (AI) applications as the use of AI in smart Internet of Things (IoT) devices introduces new cyber threats to home environments. Specifically, we have implemented and assessed CROSS in a smart heating use case in a prototypical AI-enabled IoT environment that combines characteristics and vulnerabilities currently present on existing commercial off-the-shelf (COTS) devices, demonstrating the selection of optimal decisions. Yunxiao Zhang 0001, Pasquale Malacaria, George Loukas, Emmanouil A. Panaousis |
Comput. Secur. | 3 |
| 2023 | User experiences with simulated cyber-physical attacks on smart home IoTabstractAbstract With the Internet of Things (IoT) becoming increasingly prevalent in people’s homes, new threats to residents are emerging such as the cyber-physical attack, i.e. a cyber-attack with physical consequences. In this study, we aimed to gain insights into how people experience and respond to cyber-physical attacks to their IoT devices. We conducted a naturalistic field experiment and provided 9 Dutch and 7 UK households, totalling 18 and 13 participants respectively, with a number of smart devices for use in their home. After a period of adaptation, simulated attacks were conducted, leading to events of varying noticeability (e.g., the light going on or off once or several times). After informing people simulated attacks had occurred, the attacks were repeated one more time. User experiences were collected through interviews and analysed with thematic analyses. Four relevant themes were identified, namely (1) the awareness of and concern about privacy and security risks was rather low, (2) the simulated attacks made little impression on the participants, (3) the participants had difficulties with correctly recognizing simulated attacks, and (4) when informed about simulated attacks taking place; participants noticed more simulated attacks and presented decision rules for them (but still were not able to identify and distinguish them well—see Theme 3). The findings emphasise the need for training interventions and an intrusion detection system to increase detection of cyber-physical attacks. Nicole M. A. Huijts, Antal Haans, Sanja Budimir, Johnny R. J. Fontaine, George Loukas, Anatolij Bezemskij, A. Oostveen, Avgoustinos Filippoupolitis, I. Ras, Wijnand A. IJsselsteijn, Etienne B. Roesch |
Pers. Ubiquitous Comput. | 5 |
| 2022 | On-the-Fly Privacy for Location HistogramsabstractAn important motivation for research in location privacy has been to protect against user profiling, i.e., inferring a user’s political affiliation, wealth level, sexual preferences, religious beliefs, and other sensitive attributes. Existing approaches focus on distorting or suppressing individual locations, but we argue that, for directly protecting against profiling, it is more appropriate to focus on the frequency with which various locations are visited – in other words, the histogram of a user’s locations. We introduce and explore a new privacy notion, namely, on-the-fly privacy for location histograms, in which a mobile user repeatedly submits obfuscated locations to a Location-Based Service aiming for the resulting histogram to resemble a target profile or differ from it. For example, she may want to avoid looking wealthy or to resemble a health-conscious person. We describe how to design concrete privacy mechanisms that operate under different assumptions on, e.g., the user’s mobility, including provably optimal mechanisms. We use a mobility dataset with 1083 users to illustrate how these mechanisms achieve privacy while minimizing the quality loss caused by the location obfuscation, in the context of two types of Location-Based Services: nearest-PoI, and geofence. George Theodorakopoulos 0001, Emmanouil A. Panaousis, Kaitai Liang, George Loukas |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Self-Configurable Cyber-Physical Intrusion Detection for Smart Homes Using Reinforcement LearningabstractThe modern Internet of Things (IoT)-based smart home is a challenging environment to secure: devices change, new vulnerabilities are discovered and often remain unpatched, and different users interact with their devices differently and have different cyber risk attitudes. A security breach's impact is not limited to cyberspace, as it can also affect or be facilitated in physical space, for example, via voice. In this environment, intrusion detection cannot rely solely on static models that remain the same over time and are the same for all users. We present MAGPIE, the first smart home intrusion detection system that is able to autonomously adjust the decision function of its underlying anomaly classification models to a smart home's changing conditions (e.g., new devices, new automation rules and user interaction with them). The method achieves this goal by applying a novel probabilistic cluster-based reward mechanism to non-stationary multi-armed bandit reinforcement learning. MAGPIE rewards the sets of hyperparameters of its underlying isolation forest unsupervised anomaly classifiers based on the cluster silhouette scores of their output. Experimental evaluation in a real household shows that MAGPIE exhibits high accuracy because of two further innovations: it takes into account both cyber and physical sources of data; and it detects human presence to utilise models that exhibit the highest accuracy in each case. MAGPIE is available in open-source format, together with its evaluation datasets, so it can benefit from future advances in unsupervised and reinforcement learning and be able to be enriched with further sources of data as smart home environments and attacks evolve. Ryan Heartfield, George Loukas, Anatolij Bezemskij, Emmanouil A. Panaousis |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Data-Driven Decision Support for Optimizing Cyber Forensic InvestigationsabstractCyber attacks consisting of several attack actions can present considerable challenge to forensic investigations. Consider the case where a cybersecurity breach is suspected following the discovery of one attack action, for example by observing the modification of sensitive registry keys, suspicious network traffic patterns, or the abuse of legitimate credentials. At this point, the investigator can have multiple options as to what to check next to discover the rest, and will likely pick one based on experience and training. This will be the case at each new step. We argue that the efficiency of this aspect of the job, which is the selection of what next step to take, can have significant impact on its overall cost (e.g., the duration) of the investigation and can be improved through the application of constrained optimization techniques. Here, we present DISCLOSE, the first data-driven decision support framework for optimizing forensic investigations of cybersecurity breaches. DISCLOSE benefits from a repository of known adversarial tactics, techniques, and procedures (TTPs), for each of which it harvests threat intelligence information to calculate its probabilistic relations with the rest. These relations, as well as a proximity parameter derived from the projection of quantitative data regarding the adversarial TTPs on an attack life cycle model, are both used as input to our optimization framework. We show the feasibility of this approach in a case study that consists of 31 adversarial TTPs, data collected from 6 interviews with experienced cybersecurity professionals and data extracted from the MITRE ATT&CK STIX repository and the Common Vulnerability Scoring System (CVSS). Antonia Nisioti, George Loukas, Aron Laszka, Emmanouil A. Panaousis |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | NeuralPot: An Industrial Honeypot Implementation Based On Deep Neural NetworksabstractHoneypots are powerful security tools, developed to shield commercial and industrial networks from malicious activity. Honeypots act as passive and interactive decoys in a network attracting malicious activity and securing the rest of the network entities. Since an increase in intrusions has been observed lately, more advanced security systems are necessary. In this paper a new method of adapting a honeypot system in a modern industrial network, employing the Modbus protocol, is introduced. In the presented NeuralPot honeypot, two distinct deep neural network implementations are utilized to adapt to network Modbus entities and clone them, actively confusing the intruders. The proposed deep neural networks and their generated data are then compared. Ilias Siniosoglou, George Efstathopoulos, Dimitrios Pliatsios, Ioannis D. Moscholios, Antonios Sarigiannidis, Georgia Sakellari, George Loukas, Panagiotis G. Sarigiannidis |
ISCC | 7 |
| 2019 | Blockchain and IoT-based Secure Multimedia Retrieval System for a Massive Crowd: Sharing Economy PerspectiveabstractBlockchain's properties in addressing trust in highly decentralized environments can make it an enabler for novel sharing economy services. In this paper, we demonstrate the practicality of blockchain-based Secure IoT as a Service (SIoTaaS), where an IoT device can be rented from a service provider, securely and in a privacy-preserving fashion. Our framework allows the simultaneous operations of distinct providers of IoT-based sharing economy services at a large scale. Multiple parties can securely share text and multimedia in the context of location and point-of-interest sharing, perform financial transactions by hiding true identity of parties involved in various online transactions, perform user and IoT registration, transfer value transactions via Ethereum tokens between providers and consumers, as well as raw IoT data payload. This can turn smart room IoT devices, such as smart locks, light bulbs, air conditioning and fans into rentable business entities within a secure sharing economy platform. We will demonstrate such a proof of concept IoT sharing economy framework, which is specifically designed to support the temporary IoT needs of very large numbers of users, such as Hajj pilgrims concentrating for a short period of time at a single area in Saudi Arabia. Mohamed Abdur Rahman 0001, George Loukas, Syed Maruf Abdullah, Areej Abdu, Syed Sadiqur Rahman, Elham Hassanain, Yasmine Arafa |
ICMR | 2 |
| 2019 | Participatory location fingerprinting through stationary crowd in a public or commercial indoor environmentabstractThe training phase of indoor location fingerprinting has been traditionally performed by dedicated surveyors in a manner that is time and labour intensive. Crowdsourcing process is more efficient, but is impractical in public or commercial buildings because it requires occasional location fix provided explicitly by the participant, the availability of an indoor map for correlating the traces, and the existence of landmarks throughout the area. Here, we address these issues for the first time in this context by leveraging the existence of stationary crowd that have timetabled roles, such as desk-bound employees, lecturers and students. We propose a scalable and effortless positioning system in the context of a public/commercial building by using Wi-Fi sensor readings from its stationary occupants' smartphones combined with their timetabling information. Most significantly, the entropy concept of information theory is utilised to differentiate between good and spurious measurements in a manner that does not rely on the existence of known trusted users. Our analysis and experimental results show that, regardless of such participants' unpredictable behaviour, including not following their timetabling information, hiding their location or purposefully generating wrong data, our entropy-based filtering approach ensures the creation of a radio-map incrementally from their measurements. Its effectiveness is validated experimentally with two well-known machine learning algorithms. A. K. M. Mahtab Hossain, George Loukas |
MobiQuitous | 2 |
| 2019 | A taxonomy and survey of cyber-physical intrusion detection approaches for vehicles
George Loukas, Eirini D. Karapistoli, Emmanouil A. Panaousis, Panagiotis G. Sarigiannidis, Anatolij Bezemskij, Tuan Vuong |
Ad Hoc Networks | 1 |
| 2018 | Detecting semantic social engineering attacks with the weakest link: Implementation and empirical evaluation of a human-as-a-security-sensor framework
Ryan Heartfield, George Loukas |
Comput. Secur. | 2 |
| 2018 | A taxonomy of cyber-physical threats and impact in the smart home
Ryan Heartfield, George Loukas, Sanja Budimir, Anatolij Bezemskij, Johnny R. J. Fontaine, Avgoustinos Filippoupolitis, Etienne B. Roesch |
Comput. Secur. | 2 |
| 2017 | An eye for deception: A case study in utilizing the human-as-a-security-sensor paradigm to detect zero-day semantic social engineering attacksabstractIn a number of information security scenarios, human beings can be better than technical security measures at detecting threats. This is particularly the case when a threat is based on deception of the user rather than exploitation of a specific technical flaw, as is the case of spear-phishing, application spoofing, multimedia masquerading and other semantic social engineering attacks. Here, we put the concept of the human-as-a-security-sensor to the test with a first case study on a small number of participants subjected to different attacks in a controlled laboratory environment and provided with a mechanism to report these attacks if they spot them. A key challenge is to estimate the reliability of each report, which we address with a machine learning approach. For comparison, we evaluate the ability of known technical security countermeasures in detecting the same threats. This initial proof of concept study shows that the concept is viable. Ryan Heartfield, George Loukas, Diane Gan |
SERA | 2 |
| 2017 | Evaluating the impact of malicious spoofing attacks on Bluetooth low energy based occupancy detection systemsabstractOccupancy detection of a building has a wide range of applications. Areas such as emergency management, home automation and building energy management can benefit from the knowledge of occupants' locations to provide better results and improve their efficiency. Bluetooth Low Energy (BLE) beacons installed inside a building are able to provide information on an occupant's location. Since, however, their operation is based on broadcasting advertisements, they are vulnerable to network security breaches. In this work, we evaluate the effect of two types of spoofing attacks on a BLE based occupancy detection system. The system is composed of BLE beacons installed inside the building, a mobile application installed on occupants mobile phones and a remote control server. Occupancy detection is performed by a classifier installed on the remote server. We use our real-world experimental results to evaluate the impact of these attacks on the system's operation, particularly in terms of the accuracy with which it can provide location information. William Oliff, Avgoustinos Filippoupolitis, George Loukas |
SERA | 3 |
| 2017 | Assessing the cyber-trustworthiness of human-as-a-sensor reports from mobile devicesabstractThe Human-as-a-Sensor (HaaS) paradigm, where it is human users rather than automated sensor systems that detect and report events or incidents has gained considerable traction over the last decades, especially as Internet-connected smartphones have helped develop an information sharing culture in society. In the law enforcement and civil protection space, HaaS is typically used to harvest information that enhances situational awareness regarding physical hazards, crimes and evolving emergencies. The trustworthiness of this information is typically studied in relation to the trustworthiness of the human sensors. However, malicious modification, prevention or delay of reports can also be the result of cyber or cyber-physical security breaches affecting the mobile devices and network infrastructure used to deliver HaaS reports. Examples of these can be denial of service attacks, where the timely delivery of reports is important, and location spoofing attacks, where the accuracy of the location of an incident is important. The aim of this paper is to introduce this cyber-trustworthiness aspect in HaaS and propose a mechanism for scoring reports in terms of their cyber-trustworthiness based on features of the mobile device that are monitored in real-time. Our initial results show that this is a promising line of work that can enhance the reliability of HaaS. Syed Sadiqur Rahman, Ryan Heartfield, William Oliff, George Loukas, Avgoustinos Filippoupolitis |
SERA | 4 |
| 2010 | Protection Against Denial of Service Attacks: A SurveyabstractDenial of service (DoS) is a prevalent threat in today's networks because DoS attacks are easy to launch, while defending a network resource against them is disproportionately difficult. Despite the extensive research in recent years, DoS attacks continue to harm, as the attackers adapt to the newer protection mechanisms. For this reason, we start our survey with a historical timeline of DoS incidents, where we illustrate the variety of types, targets and motives for such attacks and how they evolved during the last two decades. We then provide an extensive literature review on the existing research on DoS protection with an emphasis on the research of the last years and the most demanding aspects of defence. These include traceback, detection, classification of incoming traffic, response in the presence of an attack and mathematical modelling of attack and defence mechanisms. Our discussion aims to identify the trends in DoS attacks, the weaknesses of protection approaches and the qualities that modern ones should exhibit, so as to suggest new directions that DoS research can follow. George Loukas, Gülay Öke Günel |
Comput. J. | 1 |
| 2007 | Detecting Denial of Service Attacks with Bayesian Classifiers and the Random Neural NetworkabstractDenial of service (DoS) is a prevalent threat in today's networks. While such an attack is not difficult to launch, defending a network resource against it is disproportionately difficult, and despite the extensive research in recent years, DoS attacks continue to harm. The first goal of any protection scheme against DoS is the detection of its existence, ideally long before the destructive traffic build-up. In this paper we propose a generic approach which uses multiple Bayesian classifiers, and we present and compare four different implementations of it, combining likelihood estimation and the random neural network (RNN). The RNNs are biologically inspired structures which represent the true functioning of a biophysical neural network, where the signals travel as spikes rather than analog signals. We use such an RNN structure to fuse real-time networking statistical data and distinguish between normal and attack traffic during a DoS attack. We present experimental results obtained for different traffic data in a large networking testbed. Gülay Öke Günel, George Loukas, Erol Gelenbe |
FUZZ-IEEE | 2 |
| 2007 | A Biologically Inspired Denial of Service Detector Using the Random Neural NetworkabstractSeveral of today's computing challenges have been met by resorting to and adapting optimal solutions that have evolved in nature. For example, autonomic communication networks have started applying biologically-inspired methods to achieve some of their self-* properties. We build upon such methods to solve the recent problem of detection of denial of service networking attacks, by proposing a combination of Bayesian decision making and the random neural networks (RNN) which are inspired by the random spiking behaviour of the biological neurons. Our approach is based on measuring various instantaneous and statistical variables describing the incoming network traffic, acquiring a likelihood estimation and fusing the information gathered from the individual input features using different architectures of the RNN. The experiments are conducted using the CPN networking protocol which is also based on the RNN. George Loukas, Gülay Öke Günel |
MASS | 1 |
| 2007 | A Denial of Service Detector based on Maximum Likelihood Detection and the Random Neural NetworkabstractDue to the simplicity of the concept and the availability of attack tools, launching a DoS attack is relatively easy, while defending a network resource against it is disproportionately difficult. The first step of a protection scheme against DoS must be the detection of its existence, ideally before the destructive traffic build-up. In this paper we propose a DoS detection approach which uses the maximum likelihood criterion with the random neural network (RNN). Our method is based on measuring various instantaneous and statistical variables describing the incoming network traffic, acquiring a likelihood estimation and fusing the information gathered from the individual input features using likelihood averaging and different architectures of RNNs. We present and compare seven variations of it and evaluate our experimental results obtained in a large networking testbed. Gülay Öke Günel, George Loukas |
Comput. J. | 2 |
| 2007 | A self-aware approach to denial of service defence
Erol Gelenbe, George Loukas |
Comput. Networks | 2 |
| 2005 | An Autonomic Approach to Denial of Service DefenceabstractDenial of service attacks, viruses and worms are common tools for malicious adversarial behaviour in networks. We propose the use of our autonomic routing protocol, the cognitive packet network (CPN), as a means to defend nodes from distributed denial of service (DDoS) attacks, where one or more attackers generate flooding traffic from multiple sources towards selected nodes or IP addresses. We use both analytical and simulation modelling, and experiments on our CPN testbed, to evaluate the advantages and disadvantages of our approach in the presence of imperfect detection of DDoS attacks, and of false alarms. Erol Gelenbe, Michael Gellman, George Loukas |
WOWMOM | 3 |