VLDB 2026 Research / reviewers in the wild / expert
Carsten Rudolph
dblp:45/1443
· DBLP profile ↗
58ranked-venue papers
5as first author
27since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 3 first-author · 12 since 2021Computer networks · 8 · 2 since 2021Artificial intelligence and machine learning · 7 · 5 since 2021Software engineering, systems software and programming languages · 5 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Systems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PQCIP: A Post-Quantum Cryptography Educational Program for Cybersecurity ProfessionalsabstractIn 2023, the National Institute of Standards and Technology (NIST) announced its post-quantum cryptography (PQC) standards; CRYSTALS-Dilithium, Falcon and SPHINCS+ as digital signatures and CRYSTALS-Kyber as the key-encapsulation mechanism (KEM) (or put simply, encryption). These PQC standards are to replace today’s quantum-vulnerable cryptography algorithms, currently securing digital systems, to protect against emerging quantum computing threats. One of the main challenges in transitioning into such standards is to educate the current and future IT/Cybersecurity workforce about PQC, particularly around the practical aspects. In particular, the original proposers of the selected algorithms only provided the reference (and optimized) software implementations of them. The final NIST standard specifications will only be equipped with mathematical explanations and test vectors. Hence, there are not many custom-designed educational content, assessment, and practical tools for PQC. In this experience paper, we introduce and discuss our PQC educational program, PQCIP, targeted at industry and governmental IT/Cybersecurity professionals. PQCIP has significantly contributed to its participants’ learning and engagement by providing tailored high-quality content, hands-on assessments, and strategic planning, making them ready to develop evaluated transition plans for their organizations and/or governments. We have also created custom software interfaces for CRYSTALS-Kyber, the NIST PQC standard for KEM. Using the developed interface along with Open Quantum Safe (OQS) software library for OpenSSL, we bridge a gap in available educational tools for PQC training. This tool has been shown to enhance the participants’ understanding of PQC’s practical applications and improve their engagement with highly technical cryptographic contents. Ron Steinfeld, Muhammed F. Esgin, Nikai Jagganath, Amin Sakzad, Carsten Rudolph, James Boorman |
SIGCSE (1) | 5 |
| 2026 | Enhancing Security and Resilience in DER Integration: A Self-Sovereign Identity Approach for Smart Inverters in Virtual Power PlantsabstractUtility companies are expected to leverage privately owned distributed energy resources (DERs) to create virtual power plants (VPPs), which offer promising solutions for maintaining the demand–supply balance efficiently and reducing emissions. Smart inverters play a crucial role in integrating DERs into VPPs, making the security of smart inverters and the reliability of inverter data essential for the successful implementation of secure and effective VPPs. However, traditional public-key infrastructure and X.509 digital certificate-based security approaches (PKIX) are sub-optimal in this integration context due to their inherent limitations. Therefore, in this work, we analyse the self-sovereign identity concept in DER integration context and develop a secure and reliable framework for DER integration via smart inverters. The proposed framework aims to overcome the issues associated with the current PKIX-based design and enhance the overall resiliency of the DER integration process by extending the existing industry standards. Thusitha Dayaratne, Carsten Rudolph, Jiangshan Yu |
Distributed Ledger Technol. Res. Pract. | 2 |
| 2026 | Unfairness Attack and Unified Provable Defense on AI-Powered Internet of EnergyabstractThe critical energy infrastructure is undergoing two significant transformations: the rapid increase in renewable distributed energy resources (DER) and the digitalization of the energy sector, collectively shaping what is known as the Internet of Energy (IoE). Artificial intelligence (AI) has become a widely adopted tool for effectively allocating energy and managing sector-related resources, where ensuring fairness is essential. While inherent unfairness in AI systems is well acknowledged, little attention has been given to evaluating this unfairness and its real-world implications within the context of the IoE. In this study, we take a first step to elucidate the unfairness in AI-powered IoE systems induced by malicious users. We introduce Unfairness Score (UScore), a novel metric designed to evaluate the unfairness of machine learning models in real-world IoE scenarios. We then extensively evaluate unfairness attacks using three IoE tabular datasets, demonstrating that AI model fairness can be compromised through data poisoning, whether in centralized learning (CL) or federated learning (FL) settings. Notably, such compromises can occur when malicious users tamper with only a small subset of the data they control. Finally, we propose a novel approach that unifies fairness and differential privacy (DP) by leveraging DP as a provable defense mechanism. This approach provides a universally applicable solution to unfairness attacks, regardless of whether the learning tasks are classification or regression, and is effective in both FL and CL settings. Our contributions represent a significant step in addressing unfairness and privacy concerns in AI-powered IoE systems. Ruoxi Sun 0001, Xin Yuan 0004, Minhui Xue 0001, Yansong Gao 0001, Surya Nepal, Xingliang Yuan, Carsten Rudolph, Ling Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2025 | SAFE: A Novel Approach For Software Vulnerability Detection from Enhancing The Capability of Large Language ModelsabstractSoftware vulnerabilities (SVs) have emerged as a prevalent and crucial concern for safety-critical systems. This has spurred significant advancements in utilizing AI-based methods, including machine learning and deep learning, for software vulnerability detection (SVD). While AI-based methods have shown promising performance in SVD, their effectiveness on real-world, complex, and diverse source code datasets remains limited in practice. To tackle this challenge, in this paper, we propose a novel framework that enhances the capability of large language models to learn and utilize semantic and syntactic relationships from source code data for SVD. As a result, our proposed SAFE approach can enable the acquisition of fundamental knowledge from source code data while adeptly utilizing crucial relationships, i.e., semantic and syntactic associations, to improve the effectiveness of solving the SVD problem. The rigorous and extensive experimental results on three real-world challenging datasets (i.e., Devign, ReVeal, and D2A) demonstrate the superiority of our approach over eight effective and state-of-the-art baselines. In summary, on average, our SAFE approach achieves higher performances from 4.79% to 11.57% for F1-measure and from 16.93% to 26.24% for Recall compared to the baseline methods across all the datasets used. Van Nguyen 0002, Surya Nepal, Xingliang Yuan, Tingmin Wu, Carsten Rudolph |
AsiaCCS | 5 |
| 2025 | AI2TALE: An Innovative Information Theory-based Approach for Learning to Localize Phishing AttacksabstractPhishing attacks remain a significant challenge for detection, explanation, and defense, despite over a decade of research on both technical and non-technical solutions. AI-based phishing detection methods are among the most effective approaches for defeating phishing attacks, providing predictions on the vulnerability label (i.e., phishing or benign) of data. However, they often lack intrinsic explainability, failing to identify the specific information that triggers the classification. To this end, we propose AI2TALE, an innovative deep learning-based approach for email (the most common phishing medium) phishing attack localization. Our method aims to not only predict the vulnerability label of the email data but also provide the capability to automatically learn and identify the most important and phishing-relevant information (i.e., sentences) in the phishing email data, offering useful and concise explanations for the identified vulnerability.
Extensive experiments on seven diverse real-world email datasets demonstrate the capability and effectiveness of our method in selecting crucial information, enabling accurate detection and offering useful and concise explanations (via the most important and phishing-relevant information triggering the classification) for the vulnerability of phishing emails. Notably, our approach outperforms state-of-the-art baselines by 1.5% to 3.5% on average in Label-Accuracy and Cognitive-True-Positive metrics under a weakly supervised setting, where only vulnerability labels are used without requiring ground truth phishing information. Van Nguyen 0002, Tingmin Wu, Xingliang Yuan, Marthie Grobler, Surya Nepal, Carsten Rudolph |
ICLR | 6 |
| 2025 | Securing cross-domain data access with decentralized attribute-based access controlabstractIn attribute-based access control (ABAC), access to resources depends on the specific attributes of the entity requesting access. Existing ABAC models primarily depend on local attribute authorities to define and confirm attributes, which makes it challenging to support access decisions cross-domains without introducing centralization. Centralized solutions often conflict with individual domains’ security, privacy, and control requirements and, if compromised for any reason, can impact access to large datasets across participating domains. This paper introduces a novel access control model for cross-domain environments that significantly reduces central control. Our decentralized ABAC (D-ABAC) model uses group signature techniques to exchange attribute information securely and privately within cross-domains. Each domain maintains its own policies and attribute authorities, reducing the need for global trust or centralization to mutual trust between attribute authorities. We further design and implement a proof-of-concept system to demonstrate the practical feasibility of our proposed system for the collaborative and secure sharing of healthcare data in cross-domain environments. The proposed system model enhances security, scalability, and privacy in cross-domain settings, making it suitable for sensitive environments such as healthcare. Ahmad Salehi S., Carsten Rudolph, Hooman Alavizadeh, A. S. M. Kayes, Wenny Rahayu, Zahir Tari |
Ad Hoc Networks | 2 |
| 2025 | RACEMAN: Cross-Platform Intrusion Detection in Online Social NetworksabstractOnline Social Networks (OSNs) face various security threats, including account compromisation, where attackers seize control over legitimate user accounts and create fake profiles for nefarious purposes. The dynamic and open nature of OSNs presents unique challenges for cybersecurity, particularly in detecting unauthorized access and malicious activities such as phishing attacks, spamming, and spreading misinformation associated with account compromisation. Traditional intrusion detection systems (IDS) in OSNs often miss attacks or generate false positives due to static thresholds, delayed responses, and poor real-time data handling. These limitations often result in missed detections or false positives during sudden shifts in user activity patterns or emerging attack vectors. We introduce$RACEMAN$, an adaptive IDS designed explicitly for the OSN environment to address this. To enhance adaptability,$RACEMAN$incorporates emergency strategies such as dynamic threshold adjustments based on real-time network traffic analysis and early stopping mechanisms triggered by anomalous behavior spikes, enabling rapid adaptation to changing threat landscapes.$RACEMAN$leverages real-time OSN interactions to continuously update its metamorphic relations, ensuring an up-to-date understanding of normal user behaviour versus potential intrusions. This system utilises advanced semantic analysis to accurately represent user interactions. It generates diverse test cases using genetic algorithms and reinforcement learning to simulate user scenarios and potential intrusion methods. These test cases undergo input transformations to realistically mimic intrusion attempts while maintaining semantic integrity. The system's responses to these test cases are evaluated against expected behaviours defined by the updated metamorphic relations.$RACEMAN$utilizes statistical analysis, Multi-view Convolutional Neural Networks (MVCNN), and rule-based systems for intrusion classification. Our collaborative and distributed IDS approach enhances detection capabilities by promoting knowledge sharing across multiple systems and ensuring scalability without central points of failure. We evaluated$RACEMAN$using six publicly available datasets from Facebook, Google+, Twitter, linkedIn, Youtube and Reddit where it demonstrated a high accuracy rate of 98.85%, outperforming other models such as Convolutional Neural Network (CNN-85.67%), Artificial Neural Network (ANN-86.63%), and Random Forest (RF-78.26%). Edward Kwadwo Boahen, Ahmad Salehi S., Carsten Rudolph, Zahir Tari, Joseph K. Liu |
IEEE Trans. Serv. Comput. | 3 |
| 2024 | Towards Private Multi-operator Network Slicing
Blake Haydon, Shangqi Lai, Xingliang Yuan, Alsharif Abuadbba, Carsten Rudolph |
ACISP (3) | 5 |
| 2024 | SePEnTra: A Secure and Privacy-Preserving Energy Trading Mechanism in the Transactive Energy Market
Rumpa Dasgupta, Amin Sakzad, Carsten Rudolph, Rafael Dowsley |
ProvSec (2) | 3 |
| 2024 | ALAN: Assessment-as-Learning Authentic Tasks for NetworkingabstractIn this experience paper, we present ALAN, a framework to automate the generation of authentic assessment tasks in networking courses (NC). Using ALAN, all students in a cohort complete a set of assessment tasks generated from the same skeleton, with each student having their own parameters as input. The way we run ALAN assessments fosters students' self-regulation and peer learning and activates students' engagement in learning through assessment. We present three different ALAN assessments. We finally report on student perceptions and satisfaction and reflect on our experience. Sepehr Minagar, Amin Sakzad, Guido Tack, Carsten Rudolph, Judithe Sheard |
SIGCSE (1) | 4 |
| 2024 | Generating Semantic Adversarial Examples via Feature Manipulation in Latent SpaceabstractThe susceptibility of deep neural networks (DNNs) to adversarial intrusions, exemplified by adversarial examples, is well-documented. Conventional attacks implement unstructured, pixel-wise perturbations to mislead classifiers, which often results in a noticeable departure from natural samples and lacks human-perceptible interpretability. In this work, we present an adversarial attack strategy that implements fine-granularity, semantic-meaning-oriented structural perturbations. Our proposed methodology manipulates the semantic attributes of images through the use of disentangled latent codes. We engineer adversarial perturbations by manipulating either a single latent code or a combination thereof. To this end, we propose two unsupervised semantic manipulation strategies: one based on vector-disentangled representation and the other on feature map-disentangled representation, taking into consideration the complexity of the latent codes and the smoothness of the reconstructed images. Our empirical evaluations, conducted extensively on real-world image data, showcase the potency of our attacks, particularly against black-box classifiers. Furthermore, we establish the existence of a universal semantic adversarial example that is agnostic to specific images. Shuo Wang 0012, Shangyu Chen, Surya Nepal, Carsten Rudolph, Marthie Grobler |
IEEE Trans. Neural Networks Learn. Syst. | 5 |
| 2024 | TechnoSapiens: merging humans with technology in augmented realityabstractAbstract We present a marker-less AR/DR system that can replace the arm of the user with a virtual bionic prosthesis in real time including finger tracking. For this, we use a mixed reality HMD that provides the user with a stereo image based on video-see-through (VST). We apply chroma-keying to remove the user’s arm from each captured image and input reconstructed background information into the removed pixels. Before rendering the prosthesis model into the image, we re-target motion capture data of the user’s hand to the kinematic skeleton of the prosthesis to match the current hand pose. This system opens new research possibilities on self- and other-perception of bionic bodies. In a first evaluation study of the system, we propose that users perceive the virtual prosthesis model as a part of their body (i.e., that they experience a sense of ownership). We tested this assumption in a laboratory study with 27 individuals who used the system to perform a series of simple tasks in AR with their prosthesis. We measured body ownership and other measures with self-reports. In support of the hypothesis, users experienced a sense of body ownership. Also, a feeling of self-presence is induced during the task, and participants rated the overall experience as positive. Carsten Rudolph, Guido Brunnett, Maximilian Bretschneider, Bertolt Meyer, Frank Asbrock |
Vis. Comput. | 1 |
| 2023 | TimeClave: Oblivious In-Enclave Time Series Processing System
Kassem Bagher, Shujie Cui, Xingliang Yuan, Carsten Rudolph, Xun Yi |
ICICS | 4 |
| 2023 | DACP: Enforcing a dynamic access control policy in cross-domain environmentsabstractEnabling hybrid authorisations to enforce dynamic access control policy from single-domain to cross-domain environments (CDEs) is important for distributed services. However, traditional Attribute-Based Access Control (ABAC) models are incompatible with CDEs. To fill this gap, approaches that apply cryptographic primitives, e.g., attribute-based encryption (ABE), have been proposed. The computation and storage overhead in most ABE constructions is non-negligible and increases with the complexity of the associated policies. In addition, most access control policy systems enforce authorisation policies in a centralized way, raising serious security and privacy issues. In this paper, we introduce DACP – a practical Dynamic Access Control Policy system supporting dynamic cross-domain authorisation. DACP combines traditional ABAC approach and a novel cryptographic primitive Attribute-based group signature (ABGS). ABAC is used for the access control decision and policy enforcement according to the user’s attributes whereas ABGS is used for managing the user’s attributes between users and authorities. Thus, the user’s attributes are securely distributed along with the access structure in CDEs while preserving the user’s privacy. We present the concrete design and implementation of DACP, and evaluate it in real-world settings. The evaluation shows that DACP is practical and efficient in CDEs. Ahmad Salehi S., Runchao Han, Carsten Rudolph, Marthie Grobler |
Comput. Networks | 3 |
| 2023 | Defeating Misclassification Attacks Against Transfer LearningabstractTransfer learning is prevalent as a technique to efficiently generate new models (Student models) based on the knowledge transferred from a pre-trained model (Teacher model). However, Teacher models are often publicly available for sharing and reuse, which inevitably introduces vulnerability to trigger severe attacks against transfer learning systems. In this article, we take a first step towards mitigating one of the most advanced misclassification attacks in transfer learning. We design a distilleddifferentiatorvia activation-based network pruning to enervate the attack transferability while retaining accuracy. We adopt an ensemble structure from variant differentiators to improve the defence robustness. To avoid the bloated ensemble size during inference, we propose a two-phase defence, in which inference from the Student model is first performed to narrow down the candidate differentiators to be assembled, and later only a small, fixed number of them can be chosen to validate clean or reject adversarial inputs effectively. Our comprehensive evaluations on both large and small image recognition tasks confirm that the Student models with our defence of only 5 differentiators are immune to over 90% of the adversarial inputs with an accuracy loss of less than 10%. Our comparison also demonstrates that our design outperforms prior problematic defences. Bang Wu 0004, Shuo Wang 0012, Xingliang Yuan, Cong Wang 0001, Carsten Rudolph, Xiangwen Yang |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | Email Summarization to Assist Users in Phishing IdentificationabstractCyber-phishing attacks recently became more precise, targeted, and tailored by training data to activate only in the presence of specific information or cues. They are adaptable to a much greater extent than traditional phishing detection. Hence, automated detection systems cannot always be 100% accurate, increasing the uncertainty around expected behavior when faced with a potential phishing email. On the other hand, human-centric defence approaches focus extensively on user training but face the difficulty of keeping users up to date with continuously emerging patterns. Therefore, advances in analyzing the content of an email in novel ways along with summarizing the most pertinent content to the recipients of emails is a prospective gateway to furthering how to combat these threats. Addressing this gap, this work leverages transformer-based machine learning to (i) analyze prospective psychological triggers, to (ii) detect possible malicious intent, and to (iii) create representative summaries of emails. We then amalgamate this information and present it to the user to allow them to (i) easily decide whether the email is "phishy" and (ii) self-learn advanced malicious patterns. Amir Kashapov, Tingmin Wu, Alsharif Abuadbba, Carsten Rudolph |
AsiaCCS | 4 |
| 2022 | NOTE: Unavoidable Service to Unnoticeable Risks: A Study on How Healthcare Record Management Opens the Doors of Unnoticeable Vulnerabilities for Rohingya RefugeesabstractSecure management of healthcare records in dynamic contexts requires an understanding of the overall infrastructure of record flows and poses more challenges for vulnerable environments such as amongst the Rohingya refugees in Bangladesh. Understanding the overall infrastructure of how health clinics are providing medical treatments and how they are collecting and storing patient records is crucial as any changes or mismanagement in these records enables misuse or deliberate misinterpretations of medical data on various levels amongst individuals and Rohingya communities. Through an extensive field study in the Rohingya refugee camps in Bangladesh, we explored the management of healthcare records in different organizations. Over the course of our fieldwork, we interviewed 22 medical service providers from nine healthcare organizations connected to the Rohingya camps. Based on our findings, we design an abstract record management model and analyze it using a data provenance approach to identify the limitations of the existing record management. Our study shows vulnerabilities in ID management and security practices in healthcare record management. We further illustrate potential exploitation of these vulnerabilities through political, financial, and social lenses. To the best of our knowledge, this study is the first to discuss vulnerabilities in Rohingya refugees’ medical record management from political, social and economic views. Fariha Tasmin Jaigirdar, Carsten Rudolph, Rayhan Rashed, Md. Nahiyan Uddin, Chris Bain, A. B. M. Alim Al Islam |
COMPASS | 2 |
| 2022 | False Data Injection Attack Detection for Secure Distributed Demand Response in Smart GridsabstractDistributed demand response (DR) schemes for smart energy networks rely on data from various sources, many of them outside the network operator’s perimeter. Therefore, compromised inputs from false data injection attacks (FDIAs) can be detrimental to the expectations of stakeholders, pro-vide financial benefits to malicious actors, compromise the commercial viability of the scheme and have the potential to disrupt the energy supply. Due to the heterogeneity of data sources, FDIAs are arduous to prevent with standard security controls. Thus, detecting FDIAs is necessary to facilitate impact mitigations. However, FDIA detection in the residential DR context is arduous, given the inherent challenges such as the noisiness of residential demand, lack of labelled data in real-life settings, and variety and dynamicity of demand forecasts (e.g., weekdays vs weekend, different months/seasons). Addressing mentioned challenges, in this paper, we propose a data-driven unsupervised anomaly detection approach, named Clustering-based Spectral Residual (CSR), to detect false data injection attacks in smart grids’ DR. The CSR model is based on the popular k-means clustering and Spectral Residual method. The combination highlights the attack time slots, which increases the detection accuracy in our model. A supervised model is also proposed based on Convolutional Neural Network (CNN) to increase the detection accuracy in scenarios where label information is available. Using an energy consumption dataset from Austin, Texas, as a case study and through extensive experimental results, we show that our proposed CSR and CNN models outperform 25 widely used anomaly detection benchmarks. Thusitha Dayaratne, Mahsa Salehi, Carsten Rudolph, Ariel Liebman |
DSN | 3 |
| 2022 | Latent Space-Based Backdoor Attacks Against Deep Neural NetworksabstractThe outstanding performance of modern deep learning systems resulted in their widespread adoption in various application domains, which include security-critical applications. However, recent works have shown that these systems are vulnerable to backdoor attacks. This paper proposed a novel approach to perform latent backdoor attacks. Instead of designing the exogenetic trigger backdoor on the pixel space, which has been done by existing works, this paper explored the connection between latent space manipulation and endogenic backdoor trigger generation by utilising deep generative models to generate the backdoor trigger in the latent space. The effectiveness of the proposed attack is demonstrated on several neural network architectures trained on three well-known datasets, which are MNIST, CIFAR-10 and GTSRB. This study is undertaken to provide a new viewpoint for better understanding the endogenic vulnerability of the deep neural networks due to the lack of training data and test data, instead of creating new exogenetic misclassification behaviours for existing backdoor attacks. Adrian Kristanto, Shuo Wang 0012, Carsten Rudolph |
IJCNN | 3 |
| 2022 | R-Net: Robustness Enhanced Financial Time-Series Prediction with Differential PrivacyabstractArtificial intelligence has been investigated to conduct automatic predictions on financial time series such as stock. However, they faced two challenges. Firstly, the stock movement is affected by both technical fundamentals and external textual information. Secondly, resource data are often highly-noisy and heterogeneous, and prediction based on noisy data usually leads to significant errors. We propose a robust and accurate model (R-Net) that incorporates both technical information and qualitative sentiment derived from news reports for daily stock movement prediction in response to these challenges. A variety of enhancement strategies are adopted to improve the prediction model's robustness and accuracy. Specifically, a multimodal CNN and LSTM neural networks are applied to extract semantics from text and model complex temporal characteristics for stock market prediction. Further, based on the connection between the robustness of deep neural networks and differential privacy, we utilize provable noise injection and heterogeneous Gaussian mechanisms to enhance model robustness and accuracy. Experimental results on S&P 500 stocks demonstrate that our proposed R-Net, which integrates four enhancements, achieves 12.7% and 0.67% improvement in prediction accuracy for trends and price value prediction, respectively. Shuo Wang 0012, Jinyuan Qin, Carsten Rudolph, Surya Nepal, Marthie Grobler |
IJCNN | 3 |
| 2022 | Adversarial Detection by Latent Style TransformationsabstractDetection-based defense approaches are effective against adversarial attacks without compromising the structure of the protected model. However, they could be bypassed by stronger adversarial attacks and are limited in their ability to handle high-fidelity images. In this paper, we explore an effective detection-based defense against adversarial attacks on images (including high-resolution images) by extending the investigation beyond a single-instance perspective to incorporate its transformations as well. Our intuition is that the essential characteristics of a valid image are generally not affected by non-essential style transformations, for example, a slight variation in the facial expression of a portrait would not alter its identification. In contrast, adversarial examples are designed to affect only a single instance at a time, with unpredictable effects on a set of transformations of the instance. Consequently, we leverage a controllable generative mechanism to conduct the non-essential style transformations for a given image via modification along the style axis in the latent space. Next, the consistency of prediction between the given input and its style transformations is used to distinguish adversarial instances. Based on experiments on three image datasets, including high-resolution images, we demonstrated that our defense could detect 90–100 percent of adversarial examples produced by various state-of-the-art adversarial attacks, with a low false-positive rate. Shuo Wang 0012, Surya Nepal, Alsharif Abuadbba, Carsten Rudolph, Marthie Grobler |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | OCTOPUS: Overcoming Performance and Privatization Bottlenecks in Distributed LearningabstractThe diversity and quantity of data warehouses, gathering data from distributed devices such as mobile devices, can enhance the success and robustness of machine learning algorithms. Federated learning enables distributed participants to collaboratively learn a commonly shared model while holding data locally. However, it is also faced with expensive communication and limitations due to the heterogeneity of distributed data sources and lack of access to global data. In this paper, we investigate a practical distributed learning scenario where multiple downstream tasks (e.g., classifiers) could be efficiently learned from dynamically updated and non-iid distributed data sources while providing local data privatization. We introduce a new distributed/collaborative learning scheme to address communication overhead via latent compression, leveraging global data while providing privatization of local data without additional cost due to encryption or perturbation. This scheme divides learning into (1) informative feature encoding, and transmitting the latent representation of local data to address communication overhead; (2) downstream tasks centralized at the server using the encoded codes gathered from each node to address computing overhead. Besides, a disentanglement strategy is applied to address the privatization of sensitive components of local data. Extensive experiments are conducted on image and speech datasets. The results demonstrate that downstream tasks with the compact latent representations with the privatization of local data can achieve comparable accuracy to centralized learning. Shuo Wang 0012, Surya Nepal, Kristen Moore, Marthie Grobler, Carsten Rudolph, Alsharif Abuadbba |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2022 | Backdoor Attacks Against Transfer Learning With Pre-Trained Deep Learning ModelsabstractTransfer learning provides an effective solution for feasibly and fast customize accurateStudentmodels, by transferring the learned knowledge of pre-trainedTeachermodels over large datasets via fine-tuning. Many pre-trained Teacher models used in transfer learning are publicly available and maintained by public platforms, increasing their vulnerability to backdoor attacks. In this article, we demonstrate a backdoor threat to transfer learning tasks on both image and time-series data leveraging the knowledge of publicly accessible Teacher models, aimed at defeating three commonly adopted defenses:pruning-based,retraining-basedandinput pre-processing-based defenses. Specifically, ($\mathcal {A}$A) ranking-based selection mechanism to speed up the backdoor trigger generation and perturbation process while defeatingpruning-basedand/orretraining-based defenses. ($\mathcal {B}$B) autoencoder-powered trigger generation is proposed to produce a robust trigger that can defeat theinput pre-processing-based defense, while guaranteeing that selected neuron(s) can be significantly activated. ($\mathcal {C}$C) defense-aware retraining to generate the manipulated model using reverse-engineered model inputs. We launch effective misclassification attacks on Student models over real-world images, brain Magnetic Resonance Imaging (MRI) data and Electrocardiography (ECG) learning systems. The experiments reveal that our enhanced attack can maintain the 98.4 and 97.2 percent classification accuracy as the genuine model on clean image and time series inputs while improving$27.9\%-100\%$27.9%-100%and$27.1\%-56.1\%$27.1%-56.1%attack success rate on trojaned image and time series inputs respectively in the presence of pruning-based and/or retraining-based defenses. Shuo Wang 0012, Surya Nepal, Carsten Rudolph, Marthie Grobler, Shangyu Chen |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | Defending Adversarial Attacks via Semantic Feature ManipulationabstractMachine learning models have demonstrated vulnerability to adversarial attacks, more specifically misclassification of adversarial examples. In this article, we propose a one-off and attack-agnostic Feature Manipulation (FM)-Defense to detect and purify adversarial examples in an interpretable and efficient manner. The intuition is that the classification result of a normal image is generally resistant to non-significant intrinsic feature changes, e.g., varying the thickness of handwritten digits. In contrast, adversarial examples are sensitive to such changes since the perturbation lacks transferability. To enable manipulation of features, a Combo-variational autoencoder is applied to learn disentangled latent codes that reveal semantic features. The resistance to classification change over the morphs, derived by varying and reconstructing latent codes, is used to detect suspicious inputs. Furthermore, Combo-VAE is enhanced to purify the adversarial examples with good quality by considering class-shared and class-unique features. We empirically demonstrate the effectiveness of detection and quality of purified instances. Our experiments on three datasets show that FM-Defense can detect nearly 100 percent of adversarial examples produced by different state-of-the-art adversarial attacks. It achieves more than 99 percent overall purification accuracy on the suspicious instances that close the manifold of clean examples. Shuo Wang 0012, Surya Nepal, Carsten Rudolph, Marthie Grobler, Shangyu Chen, Zike An |
IEEE Trans. Serv. Comput. | 3 |
| 2021 | We Can Pay Less: Coordinated False Data Injection Attack Against Residential Demand Response in Smart GridsabstractAdvanced metering infrastructure, along with home automation processes, is enabling more efficient and effective demand-side management opportunities for both consumers and utility companies. However, tight cyber-physical integration also enables novel attack vectors for false data injection attacks (FDIA) as home automation/ home energy management systems reside outside the utilities' control perimeter. Authentic users themselves can manipulate these systems without causing significant security breaches compared to traditional FDIAs. This work depicts a novel FDIA that exploits one of the commonly utilised distributed device scheduling architectures. We evaluate the attack impact using a realistic dataset to demonstrate that adversaries gain significant benefits, independently from the actual algorithm used for optimisation, as long as they have control over a sufficient amount of demand. Compared to traditional FDIAs, reliable security mechanisms such as proper authentication, security protocols, security controls or, sealed/controlled devices cannot prevent this new type of FDIA. Thus, we propose a set of possible impact alleviation solutions to thwart this type of attack. Thusitha Dayaratne, Carsten Rudolph, Ariel Liebman, Mahsa Salehi |
CODASPY | 2 |
| 2021 | Authentication and Access Control in 5G Device-to-Device CommunicationabstractDevice-to-device (D2D) communication is one of the most recent advancements in wireless communication technology. It was introduced in cellular communication technology by the 3rdGeneration Partnership Project (3GPP) to lay a foundation for the evolving 5G architecture. It has now emerged as a promising technology for proximate devices. It enables proximate devices to communicate directly without the involvement of a third party network infrastructure. Researchers are analysing various methods to facilitate the smooth integration of D2D communication technology into the existing network system architecture. This paper lists all the different possible modes of operation in D2D communication based on the varying use-case scenarios and highlights the security and privacy requirements for D2D communication. Some of the recent authentication proposals for D2D communication technology are further reviewed, and their security and privacy capabilities are analysed. Apart from authentication, we also reviewed some recent proposals of access control in D2D and highlighted the security issues addressed. We then identified the open issues that prevail in implementing D2D technology in a real-world scenario for future researchers, emphasising the existing authentication and access control techniques in D2D communication. Jithu Geevargheese Panicker, Ahmad Salehi S., Carsten Rudolph |
TrustCom | 3 |
| 2021 | Decentralized Policy Information Points for Multi-Domain EnvironmentsabstractAccess control models have been developed to control authorized access to sensitive resources. This control of access is important as there is now a need for collaborative resource sharing between multiple organizations over open environments like the internet. Although there are multiple access control models that are being widely used, these models are providing access control within a closed environment i.e. within the organization using it. These models have restricted capabilities in providing access control in open environments. Attribute-Based Access Control (ABAC) has emerged as a powerful access control model to bring fine-grained authorization to organizations which possess sensitive data and resources and want to collaborate over open environments. In an ABAC system, access to resources that an organization possess can be controlled by applying policies on attributes of the users. These policies are conditions that need to be satisfied by the requester in order to gain access to the resource. In this paper, we provide an introduction to ABAC and by carrying forward the architecture of ABAC, we propose a Decentralized Policy Information Point (PIP) model. Our model proposes the decentralization of PIP, which is an entity of the ABAC model that allows the storage and query of user-attributes and enforces fine-grained access control for controlling the access of sensitive resources over multiple-domains. Our model makes use of the concept of a cryptographic primitive called Attribute Based Signature (ABS) to keep the identities of the users involved, private. Our model can be used for collaborative resource sharing over the internet. The evaluation of our model is also discussed to reflect the application of the proposed decentralized PIP model. M. Ridwanur Rahman, Ahmad Salehi S., Carsten Rudolph |
TrustCom | 3 |
| 2020 | PART-GAN: Privacy-Preserving Time-Series Sharing
Shuo Wang 0012, Carsten Rudolph, Surya Nepal, Marthie Grobler, Shangyu Chen |
ICANN (1) | 2 |
| 2020 | OIAD: One-for-all Image Anomaly Detection with Disentanglement LearningabstractAnomaly detection aims to recognize samples with anomalous and unusual patterns with respect to a set of normal data. This is significant for numerous domain applications, such as industrial inspection, medical imaging, and security enforcement. There are two key research challenges associated with existing anomaly detection approaches: (1) many approaches perform well on low-dimensional problems however the performance on high-dimensional instances, such as images, is limited; (2) many approaches often rely on traditional supervised approaches and manual engineering of features, while the topic has not been fully explored yet using modern deep learning approaches, even when the well-label samples are limited. In this paper, we propose a One-for-all Image Anomaly Detection system (OIAD) based on disentangled learning using only clean samples. Our key insight is that the impact of small perturbation on the latent representation can be bounded for normal samples while anomaly images are usually outside such bounded intervals, referred to as structure consistency. We implement this idea and evaluate its performance for anomaly detection. Our experiments with three datasets show that OIAD can detect over 90% of anomalies while maintaining a low false alarm rate. It can also detect suspicious samples from samples labeled as clean, coincided with what humans would deem unusual. Shuo Wang 0012, Shangyu Chen, Surya Nepal, Carsten Rudolph, Marthie Grobler |
IJCNN | 5 |
| 2020 | Inherent Vulnerability of Demand Response Optimisation against False Data Injection Attacks in Smart GridsabstractThe transition of energy networks to so-called smart grids benefits from advancements in Internet of Things technology. Energy management systems enable efficient and effective demand response (DR) schemes optimising load distribution. The increased user involvements through such DR schemes creates a new vector for false data injection attacks (FDIA), where authentic users themselves inject false data. Unlike in most existing FDIAs, no breaches to communication or devices are needed to execute this type of FDIA. In this work, we depict that this new FDIA can impact any optimisation-based DR scheme. Further, we show that adversaries achieve financial benefits independently from the actual algorithm used for optimisation, as long as they are able to inject false demand predictions. Compared to traditional FDIAs, reliable security mechanisms such as proper authentication, security protocols, security controls or sealed/controlled devices cannot prevent this new type of FDIA. Additionally, we show that there is no straightforward solution and we highlight the need for highly reliable FDIA detection mechanisms to thwart this type of attacks. Thusitha Dayaratne, Carsten Rudolph, Ariel Liebman, Mahsa Salehi |
NOMS | 2 |
| 2020 | Prov-IoT: A Security-Aware IoT Provenance ModelabstractA successful application of an Internet of Things (IoT) based network depends on the accurate and successful delivery of a large amount of data collected from numerous sources. However, the highly dynamic nature of IoT network prevents the establishment of clear security perimeters and hampers the understanding of security aspects. Risk assessment in such networks requires good situational awareness with respect to security. Therefore, a comprehensive view of data propagation including information on security controls can improve security analysis and risk assessment in each layer of data propagation in an IoT architecture. Documentation of metadata is already used in data provenance to identify who generates which data, how, and when. However, documentation of security information is not seen as relevant for data provenance graphs. In this paper, we discuss the importance of adding security metadata in a data provenance graph. We propose a novel IoT Provenance model, Prov-IoT, which documents the history of data records considering data processing and aggregation along with security metadata to enable a foundation for trust in data. The model portrays a comprehensive framework and outlines the identification of information to be included in designing a security-aware provenance graph. This can be beneficial for uncovering system fault or intrusion. Also, it can be useful for decision-based systems for security analysis and risk estimation. We design an associated class diagram for the Prov-IoT model. Finally, we use an IoT healthcare example scenario to demonstrate the impact of the proposed model. Fariha Tasmin Jaigirdar, Carsten Rudolph, Chris Bain |
TrustCom | 2 |
| 2020 | Attribute-Based Data Access Control for Multi-Authority SystemabstractAccess control and authorization in universal basic services is one of the main security issues in distributed systems. In particular, access control in distributed systems, such as in healthcare systems, are crucial to improve facility safety and security. This can lead to the provision of better quality of life and contribute to a healthier future. In order to provide better services, it is necessary to develop a suitable and acceptable authorization system to prevent unauthorized access to data shared in these highly dynamic distributed environments. In practice, several types of service providers, institutes, and authorities generate a variety of data in a shared environment via central authority for their entities. Generally, the use of a central authority introduces several security and privacy issues due to the increased risk if the central authority is compromised. To address this issue, several traditional access control models have been developed and introduced. These models, however, have raised several critical security issues, and there is often a need to combine it with a cryptographic approach to offer and create better access control service to users in multi-domains. To achieve this, we provide an appropriate solution to this issue. In this paper, we introduce an access control policy model for the multi-authority system, which enables attribute authorities to control the security setting. We present a new access control framework for a dynamic authorization model that uses Attribute-Based Access Control (ABAC) and digital signature. We first define and present our system and then formalize the construction of the proposed system. Our system provides flexible access control and enhanced privacy in applied and distributed environments. Ahmad Salehi S., Carsten Rudolph, Marthie Grobler |
TrustCom | 2 |
| 2020 | Privacy-Preserving Data Generation and Sharing Using Identification Sanitizer
Shuo Wang 0012, Lingjuan Lyu, Shangyu Chen, Surya Nepal, Carsten Rudolph, Marthie Grobler |
WISE (2) | 6 |
| 2019 | P-STM: Privacy-Protected Social Tie Mining of Individual TrajectoriesabstractWith the prevalence of location-aware devices and applications, enormous volumes of human spatiotemporal trajectories are being produced. It is feasible to estimate the similarity between user movement patterns according to such trajectories, which can be regarded as a potential social tie between users. There are two key research challenges associated with social tie discovery from trajectories: (1) trajectories contain users' accurate locations and releasing such data for social tie discovery raises serious privacy concerns; (2) trajectories are archived as discrete approximations of actual movement patterns using different sampling strategies and rates which are intrinsically heterogeneous. To address these challenges, this paper proposes a Privacy-protected Social Tie Mining (P-STM) approach. It provides a new social tie discovery solution based on the similarity of calibrated trajectories incorporating three key components: (1) a location entropy-based indicative dense region (IDR) mining approach to handle the heterogeneity of trajectories under differential privacy; (2) a private model-based calibration system used to rewrite trajectories using a sanitized IDR set to improve the utility of sanitized trajectories for similarity evaluation; (3) a social tie mining approach to indicate potential social ties between individuals using the similarity trajectories, which aims at finding the acquaintances for users based on solely their local geographical activities. The proposed approach is evaluated using real-world trajectory datasets from location-based social networks. Shuo Wang 0012, Surya Nepal, Richard O. Sinnott, Carsten Rudolph |
ICWS | 4 |
| 2019 | A Dynamic Cross-Domain Access Control Model for Collaborative Healthcare Application
Ahmad Salehi S., Carsten Rudolph, Marthie Grobler |
IM | 2 |
| 2017 | An implementation of access-control protocol for IoT home scenarioabstractThe internet of things comes into our daily life. It connected lots of resource-constrained devices, denoted as smart device, in an Internet-like structure. Considering the computing burden, the CoAP protocol is developed for serving the resource-constrained device and maps to HTTP for integration with existing web. In this paper, an access-control protocol will be introduced. The protocol is designed for IoT(Internet of Things) home scenario. Like the most IoT we can see, the IoT home scenario contains lots smart devices which collect some private information from us. To protect those data, an access-control protocol is needed. The protocol is deployed into Contiki OS and evaluated using the powertrace and some other tools. The results shows the protocol we designed takes a little more memory usage than an OAuth based authorisation protocol but smaller power consumption and more suitable for small scale IoT environment. Xiaoyang Wu 0006, Ron Steinfeld, Joseph K. Liu, Carsten Rudolph |
ICIS | 4 |
| 2017 | Security knowledge representation artifacts for creating secure IT systems
José Fran. Ruiz, Marcos Arjona, Antonio Maña, Carsten Rudolph |
Comput. Secur. | 4 |
| 2016 | Exploring the Space of Digital Evidence - Position Paper
Carsten Rudolph |
ACISP (1) | 1 |
| 2015 | Distributed security management for the IoTabstractThis paper proposes a concept of a distributed, hierarchical management structure for large interconnected, dynamic and heterogeneous infrastructures. This approach supporting has the potential to enable efficient security management as well as meta-data distribution is particularly relevant for applications relying on the so-called Internet of Things (IoT). The management structure is motivated by existing and successful approaches in peer-2-peer (P2P) networks for content distribution and it shares some of the characteristics. In contrast to P2P networks with clearly defined functional goals, the IoT can support various applications. Security management functionalities as well as other management tasks need to conform to the heterogeneity of applications and devices. Further, there is no single entity in control of the complete system and applications will definitely be cross-domain. Thus, a classical middle-ware is not suitable and a distributed approach as proposed in this paper can constitute the basis for a new management core for the IoT. Nico Lincke, Nicolai Kuntze, Carsten Rudolph |
IM | 3 |
| 2015 | On the Secure Distribution of Vendor-Specific Keys in Deployment Scenarios
Nicolai Kuntze, Andreas Fuchs 0002, Carsten Rudolph |
SEC | 3 |
| 2015 | An Integrated Security and Systems Engineering Process and Modelling FrameworkabstractThe modelling, engineering and development of systems with security requirements (which today means all systems) have been the target of different research works that are intended to deal with the increasing complexity of systems and characteristics such as distribution, real-time constraints and heterogeneity and with the need to provide increasing levels of security and privacy for users and businesses. Unfortunately, the situation is that no integral and comprehensive approach has been able to successfully address those challenges and gain acceptance in the industry. In fact, industrial system security engineering is in practice oversimplified, uses inadequate or obsolete solutions and is not treated consistently with the rest of the system engineering to allow an adequate assessment and tracing of the identified security goals, the security decisions made, security mechanisms selected and implemented. As a result, security problems are still too common in most systems. This paper presents a novel engineering process that seamlessly integrates security engineering activities throughout the whole system lifecycle, starting from the very first phases of the engineering process, named integrated security and system engineering process (ISSEP). In order to address the need to use accurate and up-to-date security knowledge by average system engineers, ISSEP follows a separation-of-responsibilities approach. Security knowledge is provided by experts in the form of libraries of engineering artefacts that can then be used by average system engineers in an easy and semi-automatic way. The ISSEP that we present here has been validated in real-world applications by several relevant companies (e.g. RUAG, Technicolor, Mixed Mode, etc.). One of the key points of the ISSEP is that it has been designed to be tool-supported. We have developed different tools to support its application. In particular, the main tool is available as a plugin for MagicDraw that offers support to the different actors in all the steps of the process. An Eclipse-based version is also under development. José Fran. Ruiz, Antonio Maña, Carsten Rudolph |
Comput. J. | 3 |
| 2014 | Integrity based relationships and trustworthy communication between network participantsabstractEstablishing trust relationships between network participants by having them prove their operating system's integrity via a Trusted Platform Module (TPM) provides interesting approaches for securing local networks at a higher level. In the introduced approach on OSI layer 2, attacks carried out by already authenticated and participating nodes (insider threats) can be detected and prevented. Forbidden activities and manipulations in hard- and software, such as executing unknown binaries, loading additional kernel modules or even inserting unauthorized USB devices, are detected and result in an autonomous reaction of each network participant. The provided trust establishment and authentication protocol operates independently from upper protocol layers and is optimized for resource constrained machines. Well known concepts of backbone architectures can maintain the chain of trust between different kinds of network types. Each endpoint, forwarding and processing unit monitors the internal network independently and reports misbehaviours autonomously to a central instance in or outside of the trusted network. Alexander Oberle, Pedro Larbig, Nicolai Kuntze, Carsten Rudolph |
ICC | 4 |
| 2013 | Enhancing Security Testing via Automated Replication of IT-Asset TopologiesabstractSecurity testing of IT-infrastructure in a production environment can have a negative impact on business processes supported by IT-assets. A test bed can be used to provide an alternate testing environment in order to mitigate this impact. Unfortunately, for small and medium enterprises, maintaining a physical test bed and its consistency with the production environment is a cost-intensive task. In this paper, we present the Infrastructure Replication Process (IRP) and a corresponding Topology Editor, to provide a cost-efficient method that makes security testing in small and medium enterprises more feasible. We utilize a virtual environment as a test bed and provide a structured approach that takes into account the differences between a physical and a virtual environment. Open standards, such as SCAP, OVAL or XCCDF, and the utilization the Interconnected-asset Ontology-IO-support the integration of the IRP into existing (automated) processes. We use the implementation of a prototype to present a proof-of-concept that shows how typical challenges regarding security testing can be successfully mitigated via the IRP. Henk Birkholz, Ingo Sieverdingbeck, Nicolai Kuntze, Carsten Rudolph |
ARES | 4 |
| 2013 | Demo: Zero touch configuration
Nicolai Kuntze, Pedro Larbig, Carsten Rudolph |
IM | 3 |
| 2013 | On the automatic establishment of security relations for devices
Nicolai Kuntze, Carsten Rudolph |
IM | 2 |
| 2013 | LMM - A Common Component for Software License Management on Cloud
Shinsaku Kiyomoto, Andre Rein, Yuto Nakano, Carsten Rudolph, Yutaka Miyake |
SECRYPT | 4 |
| 2013 | Integrating trust establishment into routing protocols of today's MANETsabstractConventional network protocols and its security mechanisms fail to cope with arising challenges in trust. Well known concepts from the domain of Trusted Computing can be applied to the example of mobile ad-hoc networks (MANETs) in order to establish extended trust capabilities between devices. The approach of such an anchor of trust in MANETs shows interesting possibilities since no central instances such as Access Points are involved in those networks. The communication between directly connected devices of the network is protected by a cryptographic protocol making use of a Trusted Platform Module (TPM) that serves as root-of-trust on each device. Such a hardware chip allows devices to attest the local system state and assess states of remote systems. Building on this, transmission of routing and payload data can be restricted to devices in trustworthy states. The resulting mobile ad-hoc network, by using this protocol, is protected against many of today's security threats. Single malicious devices are automatically recognised and excluded from participation in the network by all devices. Especially the dissemination of misleading routing information, which affects the availability of the whole network, is effectively prevented by the developed protocol. Thus, it is shown that the device itself is secured by a hardware TPM. Also the communication is secured, by verifying the device's state between the counterparts. Alexander Oberle, Andre Rein, Nicolai Kuntze, Carsten Rudolph, Janne Paatero, Andrew Lunn, Péter Rácz |
WCNC | 4 |
| 2012 | Trusted service access with dynamic security infrastructure configurationabstractThe increasing complexity of IT infrastructures and the integration of mobile end-user devices requires more sophisticated approaches in network perimeter protection. Currently, the state of the art in network safeguarding is represented by firewalls restricting and filtering the traffic entering and leaving the network. In most cases firewalls are static with respect to their configuration. This publication aims to introduce a generic approach that will enable dynamic configuration to these firewalls. Such a dynamic change allows for fine-grained policies supporting elaborate rules concerning the service usage within a network infrastructure. Ronald Marx, Nicolai Kuntze, Carsten Rudolph, Ingo Bente, Jörg Vieweg |
APCC | 3 |
| 2012 | On the Creation of Reliable Digital Evidence
Nicolai Kuntze, Carsten Rudolph, Aaron Alva, Barbara Endicott-Popovsky, John Christiansen, Thomas Kemmerich |
IFIP Int. Conf. Digital Forensics | 2 |
| 2010 | Trust in Peer-to-Peer Content Distribution Protocols
Nicolai Kuntze, Carsten Rudolph, Andreas Fuchs 0002 |
WISTP | 2 |
| 2009 | On the Security Validation of Integrated Security Solutions
Andreas Fuchs 0002, Sigrid Gürgens, Carsten Rudolph |
SEC | 3 |
| 2007 | Security Evaluation of Scenarios Based on the TCG's TPM Specification
Sigrid Gürgens, Carsten Rudolph, Dirk Scheuermann, Marion Atts, Rainer Plaga |
ESORICS | 2 |
| 2007 | Covert Identity Information in Direct Anonymous Attestation (DAA)
Carsten Rudolph |
SEC | 1 |
| 2005 | Abstractions Preserving Parameter Confidentiality
Sigrid Gürgens, Peter Ochsenschläger, Carsten Rudolph |
ESORICS | 3 |
| 2005 | Specification and automated processing of security requirements (SAPS'05)abstractThe first edition of SAPS (in 2004) focused on the development of tools to automate software engineering processes with support for security. Our focus in this edition will be on the tools to automate processing, validation and monitoring of security requirements, both during development and during operation of the system. Security and reliability issues are rarely considered at the initial stages of software development. The erroneous consideration of security technology as supplementary, and the lack of integration of security engineering techniques within software engineering processes have very negative consequences. Approaches integrating security issues in software engineering processes are especially relevant to SAPS. Good security measures can fail due to errors in design or implementation. Therefore, automated tools are essential for the analysis and deployment of secure systems. Comprehensive approaches, encompassing all phases of development are encouraged. Furthermore, in the near future, the increasing dynamism, heterogeneity and complexity of emerging computing paradigms and environments such as grid computing, mixed-mode systems or ambient intelligence, along with the disappearing notion of system boundaries introduced by these paradigms, will make it impossible for security engineers to foresee all possible situations that may arise during system operation, therefore increasing the need for automated support for the processing of security. Carsten Rudolph, Antonio Maña |
ASE | 1 |
| 2005 | Security analysis of efficient (Un-)fair non-repudiation protocolsabstractAbstract An approach to protocol analysis using asynchronous product automata (APA) and the simple homomorphism verification tool (SHVT) is demonstrated on several variants of the well known Zhou–Gollmann fair non-repudiation protocol and on two more recent optimistic fair non-repudiation protocols. Attacks on all these protocols are presented and an improved version of the Zhou–Gollmann protocol is proposed. Sigrid Gürgens, Carsten Rudolph |
Formal Aspects Comput. | 2 |
| 2003 | On the Security of Fair Non-repudiation Protocols
Sigrid Gürgens, Carsten Rudolph, Holger Vogt |
ISC | 2 |
| 1998 | A Formal Model for Systematic Design of Key Establishment Protocols
Carsten Rudolph |
ACISP | 1 |