VLDB 2026 Research / reviewers in the wild / expert
Kemal Bicakci
dblp:45/4438
· DBLP profile ↗
31ranked-venue papers
15as first author
3since 2021 · last 2026
0000-0002-2378-8027ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 6 first-author · 3 since 2021Computer networks · 11 · 5 first-authorHuman-computer interaction and ubiquitous computing · 3 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 first-authorSystems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Formal Verification of Peer-Assisted FIDO2 Passkey Recovery Protocol with Tamarin
Murat Sekmen, Kemal Bicakci |
CODASPY | 2 |
| 2024 | KAIME: Central Bank Digital Currency with Realistic and Modular Privacyabstracthttps://doi.org/10.5220/0012308600003648 Ali Dogan, Kemal Bicakci |
ICISSP | 2 |
| 2024 | ROSTAM: A passwordless web single sign-on solution mitigating server breaches and integrating credential manager and federated identity systems
Amin Mahnamfar, Kemal Bicakci, Yusuf Uzunay |
Comput. Secur. | 2 |
| 2018 | Automated Generation of Attack Graphs Using NVDabstractToday's computer networks are prone to sophisticated multi-step, multi-host attacks. Common approaches of identifying vulnerabilities and analyzing the security of such networks with naive methods such as counting the number of vulnerabilities, or examining the vulnerabilities independently produces incomprehensive and limited security assessment results. On the other hand, attack graphs generated from the identified vulnerabilities at a network illustrate security risks via attack paths that are not apparent with the results of the primitive approaches. One common technique of generating attack graphs requires well established definitions and data of prerequisites and postconditions relating to the known vulnerabilities. A number of works suggest prerequisite and postcondition categorization schemes for software vulnerabilities. However, generating them in an automated way is an open issue. In this paper, we first define a model that evolves over the previous works to depict the requirements of exploiting vulnerabilities for generating attack graphs. Then we describe and compare the results of two different novel approaches (rule-based and machine learning-employed) that we propose for generating attacker privilege fields as prerequisites and postconditions from the National Vulnerability Database (NVD) in an automated way. We observe that prerequisite and postcondition privileges can be generated with overall accuracy rates of 88,8 % and 95,7 % with rule-based and machine learning-employed (Multilayer Perceptron) models respectively. M. Ugur Aksu, Kemal Bicakci, M. Hadi Dilek, A. Murat Ozbayoglu, Emin Islam Tatli |
CODASPY | 2 |
| 2018 | How Safe Is Safety Number? A User Study on SIGNAL's Fingerprint and Safety Number Methods for Public Key Verification
Kemal Bicakci, Enes Altuncu, Muhammet Sakir Sahkulubey, Hakan Ezgi Kiziloz, Yusuf Uzunay |
ISC | 1 |
| 2017 | A Closer Look at Pure-Text Human-Interaction ProofsabstractHuman-interaction proofs (HIPs) are used to mitigate automated attacks. Security and usability have always been a critical problem for HIPs, especially when “accessibility” is a system requirement. Pure-text HIPs are more favorable from the usability perspective, but they are not secure. Audio HIPs usually cannot reliably distinguish attacks from legitimate use; they are either easy, and can be automatically solved, or hard, even for humans. In this study, we first compare the usability of a currently used pure-text HIP service, textCAPTCHA, against Google's reCAPTCHA. After analyzing the results, we propose a new HIP system (SMARTCHA). In this system, by using human computation we generate around 21 000 HIP tests. We conduct a user study among 31 visually impaired users to compare SMARTCHA against the latest version of audio reCAPTCHA HIPs. The study results show that SMARTCHA takes less time and is more enjoyable to solve, which suggests that pure-text HIPs could be a promising solution for secure, usable, and accessible HIPs. Hakan Ezgi Kiziloz, Kemal Bicakci |
IEEE Trans. Hum. Mach. Syst. | 2 |
| 2016 | Maximizing Wireless Sensor Network lifetime by communication/computation energy optimization of non-repudiation security service: Node level versus network level strategies
Huseyin Ugur Yildiz, Kemal Bicakci, Bülent Tavli, Hakan Gultekin, Davut Incebacak |
Ad Hoc Networks | 2 |
| 2016 | Leveraging human computation for pure-text Human Interaction Proofs
Kemal Bicakci, Hakan Ezgi Kiziloz |
Int. J. Hum. Comput. Stud. | 1 |
| 2015 | Towards making accessible human-interaction proofs more secure and usableabstractHuman-Interaction Proof (HIP) systems are widely used to prevent malicious acts of abusers. Legitimate users, however, are not satisfied with their ease of use. The response of Google to the complaints of difficulty in solving audio reCAPTCHAs was to introduce a much simpler version. But now we are back at the position where we have an accessible and usable but insecure solution. In this work, we propose a pure-text HIP system as an attempt to satisfy accessibility, security, usability requirements altogether. We conduct a user study involving 31 blind or partially sighted users which compares the usability of our pure-text HIP system (SMARTCHA) against Google's new audio reCAPTCHA. The results of the user study show that visually impaired users enjoy solving SMARTCHA more and prefer it against audio reCAPTCHA. Hakan Ezgi Kiziloz, Kemal Bicakci |
ISCC | 2 |
| 2014 | The impact of bandwidth constraints on the energy consumption of Wireless Sensor NetworksabstractOptimization of flows to maximize Wireless Sensor Network (WSN) lifetime is a problem already investigated in various aspects. However, most studies ignored the effects of finite bandwidth. As source data rate of sensor nodes increases, flow patterns that balance energy dissipation optimally might need more bandwidth than available. As a result, ignoring bandwidth limitations may lead to infeasible solutions. In this study, we make a comprehensive evaluation of the impacts of finite bandwidth by building a linear programming framework. The objective is the minimization of the energy expenditure in the maximum energy-dissipating node to achieve the maximum lifetime under bandwidth constraints. Our analysis reveals that energy consumption values may stay constant until a threshold data rate is reached. But, after the threshold the energy values increase because suboptimal paths are used due to bandwidth constraints. The bandwidth for optimal energy dissipation is limited approximately by twice the minimum bandwidth requirement. Huseyin Cotuk, Bülent Tavli, Kemal Bicakci |
WCNC | 3 |
| 2014 | The impact of scalable routing on lifetime of smart grid communication networks
Erkam Uzun, Bülent Tavli, Kemal Bicakci, Davut Incebacak |
Ad Hoc Networks | 3 |
| 2014 | The Impact of Transmission Power Control Strategies on Lifetime of Wireless Sensor NetworksabstractTransmission power control has paramount importance in the design of energy-efficient wireless sensor networks (WSNs). In this paper, we systematically explore the effects of various transmission power control strategies on WSN lifetime with an emphasis on discretization of power levels and strategies for transmission power assignment. We investigate the effects of the granularity of power levels on energy dissipation characteristics through a linear programming framework by modifying a well known and heavily utilized continuous transmission power model (HCB model). We also investigate various transmission power assignment strategies by using two sets of experimental data on Mica motes. A novel family of mathematical programming models are developed to analyze the performance of these strategies. Bandwidth requirements of the proposed transmission power assignment strategies are also investigated. Numerical analysis of our models are performed to characterize the effects of various design parameters and to comparethe relative performance of transmission power assignment strategies. Our results show that the granularity of discrete energy consumption has a profound impact on WSN lifetime, furthermore, more fine-grained control of transmission power (i.e., link level control) can extend network lifetime up to 20% in comparison to optimally-assigned network-level single transmission power. Huseyin Cotuk, Kemal Bicakci, Bülent Tavli, Erkam Uzun |
IEEE Trans. Computers | 2 |
| 2013 | Revisiting graphical passwords for augmenting, not replacing, text passwordsabstractUsers generally choose weak passwords which can be easily guessed. On the other hand, adoption of alternatives to text passwords has been slow due to cost and usability factors. We acknowledge that incumbent passwords remain difficult to beat and introduce in this study Type&Click (T&C), a hybrid scheme supporting text passwords with the graphical passwords. In T&C, users first type a text as usual and then make a single click on an image to complete the password entry. While largely preserving the login experience with the text passwords, the new scheme utilizes accumulated scientific knowledge in graphical password research (implicit feedback, persuasion during password creation, leveraging cued recall memory). The results of our user study suggest that T&C is promising for augmenting text passwords for improved security without degrading usability. Murat Akpulat, Kemal Bicakci, Ugur Cil |
ACSAC | 2 |
| 2013 | Uncovering the Impact of Minimum-Energy Routing on Lifetime of Wireless Sensor NetworksabstractIt is well-known that in wireless sensor networks using minimum-energy paths to transfer data from sensor nodes to base station is not an energy-balancing option and not the optimal solution if lifetime, defined as the duration till the first node in the network exhausts all its energy, is of concern. However, the net effect of minimum-energy routing on network lifetime has not been studied in detail before. In this study, we present comparative analysis using both simulations and linear programming models to investigate this issue with respect to various system parameters such as energy model, network area and number of nodes. Our results show that network lifetime achieved with minimum-energy routing could be as low as 19.3% of the maximum achievable lifetime depending on the values of other system parameters. Arda Söylev, Kemal Bicakci, Bülent Tavli |
DCOSS | 2 |
| 2013 | The impact of link unidirectionality and reverse path length on wireless sensor network lifetimeabstractThe occurrence of unidirectional links in wireless sensor networks (WSNs) is an inherent feature of wireless communication. Transceiver characteristics, asymmetric interference, and many other properties of the electromagnetic propagation environment result in link unidirectionality, however, transmission power heterogeneity is the dominant factor that creates unidirectional links. Most of the data transfer mechanisms designed for wireless networks work only on bidirectional links, yet, there are some mechanisms capable of utilizing unidirectional links. Employment of a multi-hop reverse path for acknowledgement delivery is the key concept and hop length of the reverse path is an important design criterion in such mechanisms. If the maximum reverse path length is allowed to take large values then the number of usable unidirectional links increases. Increasing the number of available links leads to better energy balancing and longer network lifetime. But is it necessary to keep the reverse path length large to achieve the maximum network lifetime possible? In this study, we investigate the effects of reverse path length in WSNs with unidirectional links induced by transmission power heterogeneity on network lifetime through a novel mixed integer programming framework. Our results show that reverse path length has significant impact on WSN lifetime. Anil Ufuk Batmaz, Bülent Tavli, Davut Incebacak, Kemal Bicakci |
ICC | 4 |
| 2013 | LAKE: A Server-Side Authenticated Key-Establishment with Low Computational WorkloadabstractServer-side authenticated key-establishment protocols are characterized by placing a heavy workload on the server. We propose LAKE: a new protocol that enables amortizing servers’ workload peaks by moving most of the computational burden to the clients. We provide a formal analysis of the LAKE protocol under the Canetti-Krawczyk model and prove it to be secure. To the best of our knowledge, this is the most computationally efficient authenticated key-establishment ever proposed in the literature. Kemal Bicakci, Bruno Crispo, Gabriele Oligeri |
ACM Trans. Internet Techn. | 1 |
| 2012 | A second look at the performance of neural networks for keystroke dynamics using a publicly available dataset
Yasin Uzun, Kemal Bicakci |
Comput. Secur. | 2 |
| 2012 | Communication/computation tradeoffs for prolonging network lifetime in wireless sensor networks: The case of digital signatures
Kemal Bicakci, Ibrahim Ethem Bagci, Bülent Tavli |
Inf. Sci. | 1 |
| 2012 | A survey of visual sensor network platforms
Bülent Tavli, Kemal Bicakci, Ruken Zilan, José M. Barceló-Ordinas |
Multim. Tools Appl. | 2 |
| 2011 | A multi-word password proposal (gridWord) and exploring questions about science in security research and usable security evaluationabstractOur agenda is two-fold. First, we introduce and give a technical description of gridWord, a novel knowledge-based authentication mechanism involving elements of both text and graphical passwords. It is intended to address a new research challenge arising from the evolution of Internet access devices, and which may arguably be viewed as motivating a new paradigm: remote access password schemes which accommodate users who alternately login from devices with, and without, full physical keyboards (e.g., users alternating between desktops with easy text input, and mobile devices with tiny or touch-screen virtual keyboards). While the core ideas behind gridWord are well-formed, and may be viewed as a new variation of old (text-based) ideas of building passwords from multiple words, many aspects including recommended parameterization and configuration details, preferred platforms, and primary targets of application remain to be explored in detail. We nonetheless solicit early feedback from the community for several reasons, related to our second agenda item: we use gridWord as a concrete target to focus exploration of a number of questions involving (a) the evaluation of usable security proposals, (b) the often conflicting objectives of various parties involved in the publication of academic research, and (c) the relationship between the design and publication of new security mechanisms and the pursuit of scientific knowledge through experimentation. We believe the second agenda item is important to pursue, given our observation that experts in usability and security have widely varying expectations, and lack consensus on what is important for the evaluation, comparison, and publication of usable security proposals. Kemal Bicakci, Paul C. van Oorschot |
NSPW | 1 |
| 2010 | Prolonging network lifetime with multi-domain cooperation strategies in wireless sensor networks
Kemal Bicakci, Bülent Tavli |
Ad Hoc Networks | 1 |
| 2009 | Towards Usable Solutions to Graphical Password Hotspot ProblemabstractClick based graphical passwords that use background images suffer from hot-spot problem. Previous graphical password schemes based on recognition of images do not have a sufficiently large password space suited for most Internet applications. In this paper, we propose two novel graphical password methods based on recognition of icons to solve the hotspot problem without decreasing the password space. The experiment we have conducted that compares the security and usability of proposed methods with earlier work (i.e. Passpoints) shows that hotspot problem can be eliminated if a small increase in password entrance and confirmation times is tolerable. Kemal Bicakci, Nart Bedin Atalay, Mustafa Yuceel, Hakan Gurbaslar, Burak Erdeniz |
COMPSAC (2) | 1 |
| 2009 | Pushing the limits of one-time signaturesabstractComputational and security advantages of one-time signatures come together with their length restrictions. In most applications, one-time signature should be accompanied with one-time public key(s) to enable multiple signing with a single certified public key. This is why most of the time decreasing the size of one-time signature at a cost of larger public key is not what we desire. In this paper, we show the most efficient one-time signature construction proposed so far in the sense that the total length of a signature and a public key is minimized. Kemal Bicakci |
SIN | 1 |
| 2009 | Graphical passwords as browser extension: implementation and usability studyabstractNo abstract available. Kemal Bicakci, Mustafa Yuceel, Burak Erdeniz, Hakan Gurbaslar, Nart Bedin Atalay |
SOUPS | 1 |
| 2006 | Security for the Mythical Air-Dropped Sensor NetworkabstractThe research area of very large scale wireless sensor networks made of low-cost sensors is gaining a lot of interest as witnessed by the large number of published papers. The security aspects of such networks are addressed as well, and in particular many security papers investigating the security aspects of such networks make important assumptions about the capabilities of low-cost sensors. Consequently, the techniques proposed in the current literature to provide security properties for this low-cost wireless sensor networks are heavily shaped by such assumptions. In this position paper, we challenge such assumptions by presenting the results of an experiment we conducted using sensors representative of low cost units. And we show that the same security properties can be better provided using techniques based on application-specific knowledge, heuristics and statistical tests. Finally, we show that one of the most highly cited application scenarios to motivate such techniques, the air-dropped sensor network, is likely to be more a myth than a realistic scenario for low-cost sensors. Chandana Gamage, Kemal Bicakci, Bruno Crispo, Andrew S. Tanenbaum |
ISCC | 2 |
| 2005 | Counting Abuses Using Flexible Off-line Credentials
Kemal Bicakci, Bruno Crispo, Andrew S. Tanenbaum |
ACISP | 1 |
| 2005 | Improved server assisted signatures
Kemal Bicakci, Nazife Baykal |
Comput. Networks | 1 |
| 2004 | Server Assisted Signatures Revisited
Kemal Bicakci, Nazife Baykal |
CT-RSA | 1 |
| 2003 | Survivable Authentication for Health Information Systems
Kemal Bicakci, Nazife Baykal |
AMIA | 1 |
| 2003 | Design and Performance Evaluation of a Flexible and Efficient Server Assisted Signature ProtocolabstractOne method to reduce the computational costs of generating public key signatures on constrained devices is to get help from a verifiable server. In this paper, we propose a (verifiable) server assisted signature protocol, which is the first one that totally eliminates public key operations for the ordinary user. Our protocol is also more efficient and flexible in terms of storage since unlike previous ones the user does not need to save the server's signature to prove it's cheating. Kemal Bicakci, Nazife Baykal |
ISCC | 1 |
| 2003 | How to construct optimal one-time signatures
Kemal Bicakci, Gene Tsudik, Brian Tung |
Comput. Networks | 1 |