VLDB 2026 Research / reviewers in the wild / expert
George Theodorakopoulos 0001
dblp:47/3584 · also Georgios Efthymios Theodorakopoulos
· DBLP profile ↗
27ranked-venue papers
5as first author
5since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 1 first-author · 3 since 2021Computer networks · 7 · 4 first-authorDatabases, data management, data science and information retrieval · 3Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | POSTER: Automating ICS Malware Analysis with MITRE ATT&CKabstractThe increasing interconnections and rapid changes in the nature of cyber threats targeting the Industrial Control Systems (ICS), it is crucial to understand how the malware patterns and behavior have evolved over the years. Gaining this understanding allows us to assess the effectiveness of current detection and defense mechanisms. Insights from this work will help in building effective defenses to counter such sophisticated behavior. Traditional threat analysis methods rely on text heavy representations, making it difficult to identify attack trends efficiently. This work improves the usability of the MITRE ATT&CK framework by automating the extraction, comparison, and visualization of malware attack techniques. By analyzing five ICS targeting malware families BlackEnergy, Industroyer, Industroyer2, Pipedream, and Triton, our developed tool identifies recurring adversary tactics and provides structured heatmaps and network graphs for improved threat intelligence. This approach enables analysts to compare malware behaviors more effectively, prioritize security strategies, and strengthen ICS cybersecurity resilience. Fatih Kurt, Neetesh Saxena, George Theodorakopoulos 0001 |
AsiaCCS | 4 |
| 2024 | Detecting the Abuse of Cloud Services for C&C Infrastructure Through Dynamic Analysis and Machine LearningabstractCybercriminals increasingly abuse cloud and legitimate services (CLS) as covert command and control (C&C) infrastructure to orchestrate malicious operations and evade detection. This paper addresses the critical challenge of detecting such abuse of cloud platforms. We introduce a detection system that integrates dynamic analysis with Machine Learning (ML) to accurately distinguish between benign and malicious interactions with cloud services. By utilising a comprehensive data set from VirusTotal, the system uses advanced feature extraction techniques from both host behaviour and network traffic, using Cuckoo and Triage sandboxes to extract behaviors, to develop a detection model. The results demonstrate that the model achieves nearly 98% accuracy in identifying cloud service abuse, substantially outperforming previous efforts. Furthermore, we evaluate the model's robustness against adversarial attacks that aim to decrease accuracy by manipulating the feature values. Comparative evaluations show that our method maintains a higher detection accuracy under attack compared to related systems. Turki Al Lelah, George Theodorakopoulos 0001, Amir Javed, Eirini Anthi |
ISNCC | 2 |
| 2022 | On-the-Fly Privacy for Location HistogramsabstractAn important motivation for research in location privacy has been to protect against user profiling, i.e., inferring a user’s political affiliation, wealth level, sexual preferences, religious beliefs, and other sensitive attributes. Existing approaches focus on distorting or suppressing individual locations, but we argue that, for directly protecting against profiling, it is more appropriate to focus on the frequency with which various locations are visited – in other words, the histogram of a user’s locations. We introduce and explore a new privacy notion, namely, on-the-fly privacy for location histograms, in which a mobile user repeatedly submits obfuscated locations to a Location-Based Service aiming for the resulting histogram to resemble a target profile or differ from it. For example, she may want to avoid looking wealthy or to resemble a health-conscious person. We describe how to design concrete privacy mechanisms that operate under different assumptions on, e.g., the user’s mobility, including provably optimal mechanisms. We use a mobility dataset with 1083 users to illustrate how these mechanisms achieve privacy while minimizing the quality loss caused by the location obfuscation, in the context of two types of Location-Based Services: nearest-PoI, and geofence. George Theodorakopoulos 0001, Emmanouil A. Panaousis, Kaitai Liang, George Loukas |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Quantifying the Privacy Risks of Learning High-Dimensional Graphical ModelsabstractModels leak information about their training data. This enables attackers to infer sensitive information about their training sets, notably determine if a data sample was part of the model’s training set. The existing works empirically show the possibility of these membership inference (tracing) attacks against complex deep learning models. However, the attack results are dependent on the specific training data, can be obtained only after the tedious process of training the model and performing the attack, and are missing any measure of the confidence and unused potential power of the attack. In this paper, we theoretically analyze the maximum power of tracing attacks against high-dimensional graphical models, with the focus on Bayesian networks. We provide a tight upper bound on the power (true positive rate) of these attacks, with respect to their error (false positive rate), for a given model structure even before learning its parameters. As it should be, the bound is independent of the knowledge and algorithm of any specific attack. It can help in identifying which model structures leak more information, how adding new parameters to the model increases its privacy risk, and what can be gained by adding new data points to decrease the overall information leakage. It provides a measure of the potential leakage of a model given its structure, as a function of the model complexity and the size of the training set. Sasi Kumar Murakonda, Reza Shokri, George Theodorakopoulos 0001 |
AISTATS | 3 |
| 2021 | Joint obfuscation of location and its semantic information for privacy protection
Behnaz Bostanipour, George Theodorakopoulos 0001 |
Comput. Secur. | 2 |
| 2020 | Towards using differentially private synthetic data for machine learning in collaborative data science projectsabstractAs organisations increasingly embrace data science to extract additional value from the data they hold, understanding how ethical and secure data sharing practices effect the utility of models is necessary. For organisations taking first steps towards data science applications, collaborations may involve third parties which intend to design and train models for the data owner to use. However, the disclosure of bulk data sets presents risks in terms of privacy and security. Michael Holmes, George Theodorakopoulos 0001 |
ARES | 2 |
| 2020 | Automating GDPR Compliance Verification for Cloud-hosted ServicesabstractCloud-hosted business processes require access to customer data to complete a transaction, to improve a customer's on-line experience or provide useful product recommendations. However, privacy concerns associated with the use of this data have led to legal regulations that impose restrictions on how such data is requested or processed by an on-line service, with large penalties for violating these restrictions, e.g. the European General Data Protection Regulation (GDPR). We propose a framework for helping cloud-hosted services automate GDPR compliance checking. The framework comprises three steps: represent data flow in business processes with an appropriate abstraction (timed transition systems), formalise GDPR rules and obligations and incorporate them into the same abstraction, and implement the abstraction in a model checking tool (Uppaal) in order to automatically verify compliance of business process activities with GDPR. We demonstrate the approach using a cloud-based purchase order system. Masoud Barati, George Theodorakopoulos 0001, Omer F. Rana |
ISNCC | 2 |
| 2020 | A flexible n/2 adversary node resistant and halting recoverable blockchain sharding protocolabstractSummary Blockchain sharding is a promising approach to solving the dilemma between decentralization and high performance (transaction throughput) for blockchain. The main challenge of blockchain sharding systems is how to reach a decision on a statement among a subgroup (shard) of people while ensuring the whole population recognizes this statement. Namely, the challenge is to prevent an adversary who does not have the majority of nodes globally but have the majority of nodes inside a shard. Most blockchain sharding approaches can only reach a correct consensus inside a shard with at most n/3 evil nodes in a n node system. There is a blockchain sharding approach which can prevent an incorrect decision to be reached when the adversary does not have n/2 nodes globally. However, the system can be stopped from reaching consensus (become deadlocked) if the adversary controls a smaller number of nodes. In this article, we present an improved Blockchain sharding approach that can withstand n/2 adversarial nodes and recover from deadlocks. The recovery is made by dynamically adjusting the number of shards and the shard size. A performance analysis suggests our approach has a high performance (transaction throughput) while requiring little bandwidth for synchronization. Yibin Xu, Yangyu Huang, Jianhua Shao 0001, George Theodorakopoulos 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2020 | Modelling perceived risks to personal privacy from location disclosure on online social networksabstractAs users increasingly rely on online social networks for their communication activities, personal location data processing through such networks poses significant risks to users’ privacy. Location tracks can be mined with other shared information to extract rich personal profiles. To protect users’ privacy, online social networks face the challenge of ensuring transparent communication to users of how their data are processed, and explicitly obtaining users’ informed consent for the use of this data. In this paper, we explore the complex nature of the location disclosure problem and its risks to personal privacy. We evaluate, with an experiment involving 715 participants, the contributing factors to the perception of such risks with scenarios that mimic (a) realistic modes of interaction, where users are not fully aware of the extent of their location-related data being processed, and (b) with devised scenarios that deliberately inform users of the data they are sharing and its visibility to others. The results are used to represent the users’ perception of privacy risks when sharing their location information online and to derive a possible model of privacy risks associated with this sharing behaviour. Such a model can inform the design of privacy-aware online social networks to improve users’ trust and to ensure compliance with legal frameworks for personal privacy. Fatma S. Alrayes, Alia I. Abdelmoty, Waleed El-Geresy, George Theodorakopoulos 0001 |
Int. J. Geogr. Inf. Sci. | 4 |
| 2020 | Location histogram privacy by Sensitive Location Hiding and Target Histogram Avoidance/ResemblanceabstractAbstract A location histogram is comprised of the number of times a user has visited locations as they move in an area of interest, and it is often obtained from the user in the context of applications such as recommendation and advertising. However, a location histogram that leaves a user’s computer or device may threaten privacy when it contains visits to locations that the user does not want to disclose (sensitive locations), or when it can be used to profile the user in a way that leads to price discrimination and unsolicited advertising (e.g., as “wealthy” or “minority member”). Our work introduces two privacy notions to protect a location histogram from these threats: Sensitive Location Hiding, which aims at concealing all visits to sensitive locations, and Target Avoidance/Resemblance, which aims at concealing the similarity/dissimilarity of the user’s histogram to a target histogram that corresponds to an undesired/desired profile. We formulate an optimization problem around each notion: Sensitive Location Hiding ( $${ SLH}$$ SLH ), which seeks to construct a histogram that is as similar as possible to the user’s histogram but associates all visits with nonsensitive locations, and Target Avoidance/Resemblance ( $${ TA}$$ TA / $${ TR}$$ TR ), which seeks to construct a histogram that is as dissimilar/similar as possible to a given target histogram but remains useful for getting a good response from the application that analyzes the histogram. We develop an optimal algorithm for each notion, which operates on a notion-specific search space graph and finds a shortest or longest path in the graph that corresponds to a solution histogram. In addition, we develop a greedy heuristic for the $${ TA}$$ TA / $${ TR}$$ TR problem, which operates directly on a user’s histogram. Our experiments demonstrate that all algorithms are effective at preserving the distribution of locations in a histogram and the quality of location recommendation. They also demonstrate that the heuristic produces near-optimal solutions while being orders of magnitude faster than the optimal algorithm for $${ TA}$$ TA / $${ TR}$$ TR . Grigorios Loukides, George Theodorakopoulos 0001 |
Knowl. Inf. Syst. | 2 |
| 2020 | BLATTA: Early Exploit Detection on Network Traffic with Recurrent Neural NetworksabstractDetecting exploits is crucial since the effect of undetected ones can be devastating. Identifying their presence on the network allows us to respond and block their malicious payload before they cause damage to the system. Inspecting the payload of network traffic may offer better performance in detecting exploits as they tend to hide their presence and behave similarly to legitimate traffic. Previous works on deep packet inspection for detecting malicious traffic regularly read the full length of application layer messages. As the length varies, longer messages will take more time to analyse, during which time the attack creates a disruptive impact on the system. Hence, we propose a novel early exploit detection mechanism that scans network traffic, reading only 35.21% of application layer messages to predict malicious traffic while retaining a 97.57% detection rate and a 1.93% false positive rate. Our recurrent neural network- (RNN-) based model is the first work to our knowledge that provides early prediction of malicious application layer messages, thus detecting a potential attack earlier than other state-of-the-art approaches and enabling a form of early warning system. Baskoro Adi Pratomo, Pete Burnap, George Theodorakopoulos 0001 |
Secur. Commun. Networks | 3 |
| 2019 | A Supervised Intrusion Detection System for Smart Home IoT DevicesabstractThe proliferation in Internet of Things (IoT) devices, which routinely collect sensitive information, is demonstrated by their prominence in our daily lives. Although such devices simplify and automate every day tasks, they also introduce tremendous security flaws. Current insufficient security measures employed to defend smart devices make IoT the “weakest” link to breaking into a secure infrastructure, and therefore an attractive target to attackers. This paper proposes a three layer intrusion detection system (IDS) that uses a supervised approach to detect a range of popular network based cyber-attacks on IoT networks. The system consists of three main functions: 1) classify the type and profile the normal behavior of each IoT device connected to the network; 2) identifies malicious packets on the network when an attack is occurring; and 3) classifies the type of the attack that has been deployed. The system is evaluated within a smart home testbed consisting of eight popular commercially available devices. The effectiveness of the proposed IDS architecture is evaluated by deploying 12 attacks from 4 main network based attack categories, such as denial of service (DoS), man-in-the-middle (MITM)/spoofing, reconnaissance, and replay. Additionally, the system is also evaluated against four scenarios of multistage attacks with complex chains of events. The performance of the system's three core functions result in an F-measure of: 1) 96.2%; 2) 90.0%; and 3) 98.0%. This demonstrates that the proposed architecture can automatically distinguish between IoT devices on the network, whether network activity is malicious or benign, and detect which attack was deployed on which device connected to the network successfully. Eirini Anthi, Lowri Williams, Malgorzata Slowinska, George Theodorakopoulos 0001, Pete Burnap |
IEEE Internet Things J. | 4 |
| 2018 | EclipseIoT: A secure and adaptive hub for the Internet of Things
Eirini Anthi, Shazaib Ahmad, Omer F. Rana, George Theodorakopoulos 0001, Pete Burnap |
Comput. Secur. | 4 |
| 2017 | Privacy Games Along Location Traces: A Game-Theoretic Framework for Optimizing Location PrivacyabstractThe mainstream approach to protecting the privacy of mobile users in location-based services (LBSs) is to alter (e.g., perturb, hide, and so on) the users’ actual locations in order to reduce exposed sensitive information. In order to be effective, a location-privacy preserving mechanism must consider both the privacy and utility requirements of each user, as well as the user’s overall exposed locations (which contribute to the adversary’s background knowledge). In this article, we propose a methodology that enables the design of optimal user-centric location obfuscation mechanisms respecting each individual user’s service quality requirements, while maximizing the expected error that the optimal adversary incurs in reconstructing the user’s actual trace. A key advantage of a user-centric mechanism is that it does not depend on third-party proxies or anonymizers; thus, it can be directly integrated in the mobile devices that users employ to access LBSs. Our methodology is based on the mutual optimization of user/adversary objectives (maximizing location privacy versus minimizing localization error) formalized as a Stackelberg Bayesian game. This formalization makes our solution robust against any location inference attack, that is, the adversary cannot decrease the user’s privacy by designing a better inference algorithm as long as the obfuscation mechanism is designed according to our privacy games. We develop two linear programs that solve the location privacy game and output the optimal obfuscation strategy and its corresponding optimal inference attack. These linear programs are used to design location privacy--preserving mechanisms that consider the correlation between past, current, and future locations of the user, thus can be tuned to protect different privacy objectives along the user’s location trace. We illustrate the efficacy of the optimal location privacy--preserving mechanisms obtained with our approach against real location traces, showing their performance in protecting users’ different location privacy objectives. Reza Shokri, George Theodorakopoulos 0001, Carmela Troncoso |
ACM Trans. Priv. Secur. | 2 |
| 2016 | On the Inference of User Paths from Anonymized Mobility DataabstractUsing the plethora of apps on smartphones andtablets entails giving them access to different types of privacysensitive information, including the device's location. This canpotentially compromise user privacy when app providers shareuser data with third parties (e.g., advertisers) for monetizationpurposes. In this paper, we focus on the interface for datasharing between app providers and third parties, and devisean attack that can break the strongest form of the commonlyused anonymization method for protecting the privacy of users. More specifically, we develop a mechanism called Comberthat given completely anonymized mobility data (without anypseudonyms) as input is able to identify different users andtheir respective paths in the data. Comber exploits the observationthat the distribution of speeds is typically similar amongdifferent users and incorporates a generic, empirically derivedhistogram of user speeds to identify the users and disentangletheir paths. Comber also benefits from two optimizations thatallow it to reduce the path inference time for large datasets. Weuse two real datasets with mobile user location traces (MobileData Challenge and GeoLife) for evaluating the effectivenessof Comber and show that it can infer paths with greater than 90% accuracy with both these datasets. Galini Tsoukaneri, George Theodorakopoulos 0001, Hugh Leather, Mahesh K. Marina |
EuroS&P | 2 |
| 2014 | Hiding in the Mobile Crowd: LocationPrivacy through CollaborationabstractLocation-aware smartphones support various location-based services (LBSs): users query the LBS server and learn on the fly about their surroundings. However, such queries give away private information, enabling the LBS to track users. We address this problem by proposing a user-collaborative privacy-preserving approach for LBSs. Our solution does not require changing the LBS server architecture and does not assume third party servers; yet, it significantly improves users’ location privacy. The gain stems from the collaboration of mobile devices: they keep their context information in a buffer and pass it to others seeking such information. Thus, a user remains hidden from the server, unless all the collaborative peers in the vicinity lack the sought information. We evaluate our scheme against the Bayesian localization attacks that allow for strong adversaries who can incorporate prior knowledge in their attacks. We develop a novel epidemic model to capture the, possibly time-dependent, dynamics of information propagation among users. Used in the Bayesian inference framework, this model helps analyze the effects of various parameters, such as users’ querying rates and the lifetime of context information, on users’ location privacy. The results show that our scheme hides a high fraction of location-based queries, thus significantly enhancing users’ location privacy. Our simulations with real mobility traces corroborate our model-based findings. Finally, our implementation on mobile platforms indicates that it is lightweight and the cost of collaboration is negligible. Reza Shokri, George Theodorakopoulos 0001, Panagiotis Papadimitratos, Ehsan Kazemi 0001, Jean-Pierre Hubaux |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2013 | Broker Emergence in Social CloudsabstractCloud computing generally involves the use of data storage and computational resources from external providers. Although a number of commercial providers are currently on the market, it is often beneficial for a user to consider capability from a number of different ones. This would prevent vendor lock-in and more economic choice for a user. Based on this observation, work on "Social Clouds" has involved using social relationships formed between individuals and institutions to establish Peer-2-Peer resource sharing networks, enabling market forces to determine how demand for resources can be met by a number of different (often individually owned) providers. In this paper we identify how trading within such a network could be enhanced by the dynamic emergence (or identification) of brokers -- based on their social position in the network (based on connectivity metrics within a social network). We investigate how offering financial incentives to such brokers, once discovered, could help improve the number of trades that could take place with a network. A social score algorithm is described and simulated with PeerSim to validate our approach. We also compare the approach to a distributed dominating set algorithm - the closest approximation to our approach. Ioan Petri, Magdalena Punceva, Omer F. Rana, George Theodorakopoulos 0001 |
IEEE CLOUD | 4 |
| 2012 | Protecting location privacy: optimal strategy against localization attacksabstractThe mainstream approach to protecting the location-privacy of mobile users in location-based services (LBSs) is to alter the users' actual locations in order to reduce the location information exposed to the service provider. The location obfuscation algorithm behind an effective location-privacy preserving mechanism (LPPM) must consider three fundamental elements: the privacy requirements of the users, the adversary's knowledge and capabilities, and the maximal tolerated service quality degradation stemming from the obfuscation of true locations. We propose the first methodology, to the best of our knowledge, that enables a designer to find the optimal LPPM for a LBS given each user's service quality constraints against an adversary implementing the optimal inference algorithm. Such LPPM is the one that maximizes the expected distortion (error) that the optimal adversary incurs in reconstructing the actual location of a user, while fulfilling the user's service-quality requirement. We formalize the mutual optimization of user-adversary objectives (location privacy vs. correctness of localization) by using the framework of Stackelberg Bayesian games. In such setting, we develop two linear programs that output the best LPPM strategy and its corresponding optimal inference attack. Our optimal user-centric LPPM can be easily integrated in the users' mobile devices they use to access LBSs. We validate the efficacy of our game theoretic method against real location traces. Our evaluation confirms that the optimal LPPM strategy is superior to a straightforward obfuscation method, and that the optimal localization attack performs better compared to a Bayesian inference attack. Reza Shokri, George Theodorakopoulos 0001, Carmela Troncoso, Jean-Pierre Hubaux, Jean-Yves Le Boudec |
CCS | 2 |
| 2012 | Traps and pitfalls of using contact traces in performance studies of opportunistic networksabstractContact-based simulations are a very popular tool for the analysis of opportunistic networks. They are used for evaluation of networking metrics, for quantifying the effects of infrastructure and for the design of forwarding strategies. However, little evidence exists that the results of such simulations accurately describe the performance of opportunistic networks, as they commonly ignore some important factors (like limited transmission bandwidth) or they rely on assumptions such as infinite user cache sizes. In order to evaluate this issue, we design a testbed with a real application and real users; we collect application data in addition to the contact traces and compare measured performance to the results of the contact-based simulations. We find that contact-based simulations significantly overestimate delivery ratio, while the captured delay tends to be 2-3 times lower than the experimentally obtained delay. We show that assuming infinite cache sizes leads to misinterpretation of the effects of backbone on an opportunistic network. Finally, we show that contact traces can be used to analytically estimate the delivery ratios and the impact of backbone, through the dependency between a user centrality measure and her delivery ratio. Nikodin Ristanovic, George Theodorakopoulos 0001, Jean-Yves Le Boudec |
INFOCOM | 2 |
| 2011 | Collaborative Location PrivacyabstractLocation-aware smart phones support various location-based services (LBSs): users query the LBS server and learn on the fly about their surroundings. However, such queries give away private information, enabling the LBS to identify and track users. We address this problem by proposing the first, to the best of our knowledge, user-collaborative privacy preserving approach for LBSs. Our solution, MobiCrowd, is simple to implement, it does not require changing the LBS server architecture, and it does not assume third party privacy-protection servers; still, MobiCrowd significantly improves user location-privacy. The gain stems from the collaboration of MobiCrowd-ready mobile devices: they keep their context information in a buffer, until it expires, and they pass it to other users seeking such information. Essentially, the LBS does not need to be contacted unless all the collaborative peers in the vicinity lack the sought information. Hence, the user can remain hidden from the server, unless it absolutely needs to expose herself through a query. Our results show that MobiCrowd hides a high fraction of location-based queries, thus significantly enhancing user location-privacy. To study the effects of various parameters, such as the collaboration level and contact rate between mobile users, we develop an epidemic model. Our simulations with real mobility datasets corroborate our model-based findings. Finally, our implementation of MobiCrowd on Nokia platforms indicates that it is lightweight and the collaboration cost is negligible. Reza Shokri, Panagiotis Papadimitratos, George Theodorakopoulos 0001, Jean-Pierre Hubaux |
MASS | 3 |
| 2011 | Quantifying Location Privacy: The Case of Sporadic Location Exposure
Reza Shokri, George Theodorakopoulos 0001, George Danezis, Jean-Pierre Hubaux, Jean-Yves Le Boudec |
PETS | 2 |
| 2011 | Quantifying Location PrivacyabstractIt is a well-known fact that the progress of personal communication devices leads to serious concerns about privacy in general, and location privacy in particular. As a response to these issues, a number of Location-Privacy Protection Mechanisms (LPPMs) have been proposed during the last decade. However, their assessment and comparison remains problematic because of the absence of a systematic method to quantify them. In particular, the assumptions about the attacker's model tend to be incomplete, with the risk of a possibly wrong estimation of the users' location privacy. In this paper, we address these issues by providing a formal framework for the analysis of LPPMs, it captures, in particular, the prior information that might be available to the attacker, and various attacks that he can perform. The privacy of users and the success of the adversary in his location-inference attacks are two sides of the same coin. We revise location privacy by giving a simple, yet comprehensive, model to formulate all types of location-information disclosure attacks. Thus, by formalizing the adversary's performance, we propose and justify the right metric to quantify location privacy. We clarify the difference between three aspects of the adversary's inference attacks, namely their accuracy, certainty, and correctness. We show that correctness determines the privacy of users. In other words, the expected estimation error of the adversary is the metric of users' location privacy. We rely on well-established statistical methods to formalize and implement the attacks in a tool: the Location-Privacy Meter that measures the location privacy of mobile users, given various LPPMs. In addition to evaluating some example LPPMs, by using our tool, we assess the appropriateness of some popular metrics for location privacy: entropy and k-anonymity. The results show a lack of satisfactory correlation between these two metrics and the success of the adversary in inferring the users' actual locations. Reza Shokri, George Theodorakopoulos 0001, Jean-Yves Le Boudec, Jean-Pierre Hubaux |
IEEE Symposium on Security and Privacy | 2 |
| 2009 | Preserving privacy in collaborative filtering through distributed aggregation of offline profilesabstractIn recommender systems, usually, a central server needs to have access to users' profiles in order to generate useful recommendations. Having this access, however, undermines the users' privacy. Reza Shokri, Pedram Pedarsani, George Theodorakopoulos 0001, Jean-Pierre Hubaux |
RecSys | 3 |
| 2008 | Game Theoretic Modeling of Malicious Users in Collaborative NetworksabstractIf a network is to operate successfully, its users need to collaborate. Collaboration takes the form of following a network protocol and involves some resource expenditure on the part of the user. Therefore, users cannot automatically be expected to follow the protocol if they are not forced to. The situation is exacerbated by the presence of malicious users whose objective is to damage the network and increase the cost incurred by the legitimate users. The legitimate users are, at least initially, unaware of the type (legitimate or malicious) of the other users. Our contribution is a model for the strategic interaction of legitimate and malicious users as described above. The model is based on repeated graphical games with incomplete information. We describe and analyze two specific instantiations, aiming to demonstrate the modeliquests expressive power and tractability. The main benefit we see from using game theory for this essentially security problem is the ability to bound the damage caused by the malicious users. George Theodorakopoulos 0001, John S. Baras |
IEEE J. Sel. Areas Commun. | 1 |
| 2007 | Malicious Users in Unstructured NetworksabstractUnstructured networks (like ad-hoc or peer-to-peer networks) are networks without centralized control of their operation. Users make local decisions regarding whether to follow the network protocol or not. While providing scalability benefits, this degrades the performance, which is compounded by the potential presence of Malicious Users. In general, these users are trying to disrupt the operation of the network, and prevent the legitimate users from achieving their objectives. More specifically, they could try to break the connectivity of the network, or waste the resources of the legitimate users. In this work we use game theory to examine the effect of malicious users. All users are modeled as payoff-maximizing strategic agents. A simple model, fictitious play, is used for the legitimate user behavior, but no limits are imposed on the Malicious Users strategies. We look for the worst case equilibrium: the one that gives Malicious Users the highest payoff. We identify the importance of the network topology. George Theodorakopoulos 0001, John S. Baras |
INFOCOM | 1 |
| 2006 | A Game for Ad Hoc Network Connectivity in the Presence of Malicious UsersabstractAd hoc network users are resource constrained: Before transmitting data, they have to take into account the energy expenditure involved. Even if a user is, in principle, willing to spend energy to improve network connectivity, his actual decision will be heavily influenced by the decisions of his neighboring users, since they act as relay nodes for him. Moreover, some of the neighbors may not be as benign as he is; in fact, they could be outright malicious. We are abstracting the tradeoff between spending energy and increasing connectivity by modeling the interaction of a user with his one-hop neighbors in a game theoretic fashion. Two types of users exist: Good users willingly trade energy for connectivity, but only if they expect their neighbors to do the same; Bad users try to destroy connectivity, but also lure the Good users to waste energy. Within our model for user behavior and sophistication, we explore outcomes that can arise in this graphical game. George Theodorakopoulos 0001, John S. Baras |
GLOBECOM | 1 |
| 2006 | On trust models and trust evaluation metrics for ad hoc networksabstractWithin the realm of network security, we interpret the concept of trust as a relation among entities that participate in various protocols. Trust relations are based on evidence created by the previous interactions of entities within a protocol. In this work, we are focusing on the evaluation of trust evidence in ad hoc networks. Because of the dynamic nature of ad hoc networks, trust evidence may be uncertain and incomplete. Also, no preestablished infrastructure can be assumed. The evaluation process is modeled as a path problem on a directed graph, where nodes represent entities, and edges represent trust relations. We give intuitive requirements and discuss design issues for any trust evaluation algorithm. Using the theory of semirings, we show how two nodes can establish an indirect trust relation without previous direct interaction. We show that our semiring framework is flexible enough to express other trust models, most notably PGP's Web of Trust. Our scheme is shown to be robust in the presence of attackers. George Theodorakopoulos 0001, John S. Baras |
IEEE J. Sel. Areas Commun. | 1 |