VLDB 2026 Research / reviewers in the wild / expert
Konstantinos G. Kyriakopoulos
dblp:71/2616
· DBLP profile ↗
14ranked-venue papers
5as first author
4since 2021 · last 2026
0000-0002-7498-4589ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 2 since 2021Computer networks · 4 · 2 first-authorArtificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Intelligent asset parameterisation for risk-based moving target defenceabstractIn an era characterised by evolving cyber threats and sophisticated adversar-ial behaviour, the field of cyber-security faces a continuous and formidablechallenge. The development of dynamic and adaptive security control mea-sures is imperative in order to safeguard critical assets and information.This article delves into the realm of Moving Target Defence (MTD), astrategic approach that seeks to outmanoeuvre adversaries by constantlyshifting the security landscape. Our research specifically focuses on the ap-plication of Reinforcement Learning (RL) in MTD, with a focus on threatexposure and the efficacy of control strategies with respect to risk reduction.A defensive RL agent is proposed that incorporates attack graphs as ablueprint to assess possible paths that an adversary may take. By consideringreceived events about an adversary’s actions, the defensive agent continuouslyupdates its knowledge about the adversary’s position on the attack graph.The proposed research establishes and evaluates a risk-based, RL-drivenagent capable of MTD operations in order to address adversarial behaviours.The proposed approach provides valuable insights into optimally deployingsecurity controls under dynamic threat scenarios and restricted budget resources. Konstantinos G. Kyriakopoulos, Lincoln Kamau Kiarie, Marios Aristodemou, Susan Babirye, Amit Patel 0002, Isaiah Nassiuma, Mercedeh Rezaei, Iain Phillips 0002, Anhtuan Le, Carsten Maple, Gregory Epiphaniou |
Comput. Secur. | 1 |
| 2025 | Maximizing Uncertainty for Federated Learning via Bayesian Optimization-Based Model PoisoningabstractAs we transition from Narrow Artificial Intelligence towards Artificial Super Intelligence, users are increasingly concerned about their privacy and the trustworthiness of machine learning (ML) technology. A common denominator for the metrics of trustworthiness is the quantification of uncertainty inherent in DL algorithms, and specifically in the model parameters, input data, and model predictions. One of the common approaches to address privacy-related issues in DL is to adopt distributed learning such as federated learning (FL), where private raw data is not shared among users. Despite the privacy-preserving mechanisms in FL, it still faces challenges in trustworthiness. Specifically, the malicious users, during training, can systematically create malicious model parameters to compromise the models’ predictive and generative capabilities, resulting in high uncertainty about their reliability. To demonstrate malicious behaviour, we propose a novel model poisoning attack method named Delphi which aims to maximise the uncertainty of the global model output. We achieve this by taking advantage of the relationship between the uncertainty and the model parameters of the first hidden layer of the local model. Delphi employs two types of optimisation, Bayesian Optimisation and Least Squares Trust Region, to search for the optimal poisoned model parameters, named as Delphi-BO and Delphi-LSTR. We quantify the uncertainty using the KL Divergence to minimise the distance of the predictive probability distribution towards an uncertain distribution of model output. Furthermore, we establish a mathematical proof for the attack effectiveness demonstrated in FL. Numerical results demonstrate that Delphi-BO induces a higher amount of uncertainty than Delphi-LSTR highlighting vulnerability of FL systems to model poisoning attacks. Marios Aristodemou, Xiaolan Liu 0001, Yuan Wang 0008, Konstantinos G. Kyriakopoulos, Sangarapillai Lambotharan, Qingsong Wei |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Causally aware reinforcement learning agents for autonomous cyber defenceabstractArtificial Intelligence (AI) is seen as a disruptive solution to the ever increasing security threats on network infrastructures. To automate the process of defending networked environments from such threats, approaches such as Reinforcement Learning (RL) have been used to train agents in cyber adversarial games. One primary challenge is how contextual information could be integrated into RL models to create agents which adapt their behaviour to adversarial posture. Two desirable characteristics identified for such models are that they should be interpretable and causal. To address this challenge, we propose an approach through the integration of a causal rewards model with a modified Proximal Policy Optimisation (PPO) agent in Meta’s MBRL-Lib framework. Our RL agents are trained and evaluated against a range of cyber-relevant scenarios in the Dstl YAWNING-TITAN (YT) environment. We have constructed and experimented with two types of reward functions to facilitate the agent’s learning process. Evaluation metrics include, among others, games won by the defence agent (blue wins), episode length, healthy nodes and isolated nodes. Results show that, over all scenarios, our causally aware agent achieves better performance than causally-blind state-of-the-art benchmarks in these scenarios for the above evaluation metrics. In particular, with our proposed High Value Target (HVT) rewards function, which aims not to disrupt HVT nodes, the number of isolated nodes is improved by 17% and 18% against the model-free and Neural Network (NN) model-based agents across all scenarios. More importantly, the overall performance improvement for the blue wins metric exceeded that of model-free and NN model-based agents by 40% and 17%, respectively, across all scenarios. • Integrated a causal inference approach within a Deep Reinforcement Learning framework. • Compared the proposed algorithm against model-based and model-free DRL algorithms. • Demonstrated our approach on PPO agents, but is applicable for any RL algorithm. • Increased win-rate by up to 40%, and reduced number of environment interactions. Tom Purves, Konstantinos G. Kyriakopoulos, Siân Jenkins, Iain Phillips 0002, Tim Dudman |
Knowl. Based Syst. | 2 |
| 2021 | Evidential classification and feature selection for cyber-threat hunting
Matthew Beechey, Konstantinos G. Kyriakopoulos, Sangarapillai Lambotharan |
Knowl. Based Syst. | 2 |
| 2020 | Analysis of hidden Markov model learning algorithms for the detection and prediction of multi-stage network attacks
Timothy A. Chadza, Konstantinos G. Kyriakopoulos, Sangarapillai Lambotharan |
Future Gener. Comput. Syst. | 2 |
| 2020 | A Fog caching scheme enabled by ICN for IoT environments
Yining Hua, Konstantinos G. Kyriakopoulos |
Future Gener. Comput. Syst. | 3 |
| 2019 | Contemporary Sequential Network Attacks Prediction using Hidden Markov ModelabstractIntrusion prediction is a key task for forecasting network intrusions. Intrusion detection systems have been primarily deployed as a first line of defence in a network, however; they often suffer from practical testing and evaluation due to unavailability of rich datasets. This paper evaluates the detection accuracy of determining all states (AS), the current state (CS), and the prediction of next state (NS) of an observation sequence, using the two conventional Hidden Markov Model (HMM) training algorithms, namely, Baum Welch (BW) and Viterbi Training (VT). Both BW and VT were initialised using uniform, random and count-based parameters and the experiment evaluation was conducted on the CSE-CIC-IDS2018 dataset. Results show that the BW and VT count-based initialisation techniques perform better than uniform and random initialisation when detecting AS and CS. In contrast, for NS prediction, uniform and random initialisation techniques perform better than BW and VT count-based approaches. Timothy A. Chadza, Konstantinos G. Kyriakopoulos, Sangarapillai Lambotharan |
PST | 2 |
| 2017 | Using the pattern-of-life in networks to improve the effectiveness of intrusion detection systemsabstractAs the complexity of cyber-attacks keeps increasing, new and more robust detection mechanisms need to be developed. The next generation of Intrusion Detection Systems (IDSs) should be able to adapt their detection characteristics based not only on the measureable network traffic, but also on the available highlevel information related to the protected network to improve their detection results. We make use of the Pattern-of-Life (PoL) of a network as the main source of high-level information, which is correlated with the time of the day and the usage of the network resources. We propose the use of a Fuzzy Cognitive Map (FCM) to incorporate the PoL into the detection process. The main aim of this work is to evidence the improved the detection performance of an IDS using an FCM to leverage on network related contextual information. The results that we present verify that the proposed method improves the effectiveness of our IDS by reducing the total number of false alarms; providing an improvement of 9.68% when all the considered metrics are combined and a peak improvement of up to 35.64%, depending on particular metric combination. Francisco J. Aparicio-Navarro, Jonathon A. Chambers, Konstantinos G. Kyriakopoulos, Yu Gong 0001, David J. Parish |
ICC | 3 |
| 2017 | A look into the information your smartphone leaksabstractSome smartphone applications (apps) pose a risk to users' personal information. Events of apps leaking information stored in smartphones illustrate the danger that they present. In this paper, we investigate the amount of personal information leaked during the installation and use of apps when accessing the Internet. We have opted for the implementation of a Man-in-the-Middle proxy to intercept the network traffic generated by 20 popular free apps installed on different smartphones of distinctive vendors. This work describes the technical considerations and requirements for the deployment of the monitoring WiFi network employed during the conducted experiments. The presented results show that numerous mobile and personal unique identifiers, along with personal information are leaked by several of the evaluated apps, commonly during the installation process. Timothy A. Chadza, Francisco J. Aparicio-Navarro, Konstantinos G. Kyriakopoulos, Jonathon A. Chambers |
ISNCC | 3 |
| 2014 | Manual and Automatic assigned thresholds in multi-layer data fusion intrusion detection system for 802.11 attacksabstractAbuse attacks on wireless networks are becoming increasingly sophisticated. Most of the recent research on intrusion detection systems for wireless attacks either focuses on just one layer of observation or uses a limited number of metrics without proper data fusion techniques. However, the true status of a network is rarely accurately detectable by examining only one network layer. The goal of this study is to detect injection types of attacks in wireless networks by fusing multi‐metrics using the Dempster–Shafer (D–S) belief theory. When combining beliefs, an important step to consider is the automatic and self‐adaptive process of basic probability assignment (BPA). This study presents a comparison between manual and automatic BPA methods using the D–S technique. Custom tailoring BPAs in an optimum manner under specific network conditions could be extremely time consuming and difficult. In contrast, automatic methods have the advantage of not requiring any prior training or calibration from an administrator. The results show that multi‐layer techniques perform more efficiently when compared with conventional methods. In addition, the automatic assignment of beliefs makes the use of such a system easier to deploy while providing a similar performance to that of a manual system. Konstantinos G. Kyriakopoulos, Francisco J. Aparicio-Navarro, David J. Parish |
IET Inf. Secur. | 1 |
| 2010 | Applying wavelets for the controlled compression of communication network measurementsabstractMonitoring and measuring various metrics of high-speed networks produces a vast amount of information over a long period of time making the storage of the metrics a serious issue. Previous work has suggested stream aware compression algorithms, among others, that is, methodologies that try to organise the network packets in a compact way in order to occupy less storage. However, these methods do not reduce the redundancy in the stream information. Lossy compression becomes an attractive solution, as higher compression ratios can be achieved. However, the important and significant elements of the original data need to be preserved. This study proposes the use of a lossy wavelet compression mechanism that preserves crucial statistical and visual characteristics of the examined computer network measurements and provides significant compression against the original file sizes. To the best of authors' knowledge, this is the first study to suggest and implement a wavelet analysis technique for compressing computer network measurements. Here, wavelet analysis is used and compared against the Gzip and Bzip2 tools for data rate and delay measurements. In addition, this study also provides a comparison of eight different wavelets with respect to the compression ratio, the preservation of the scaling behaviour, of the long-range dependence (LRD), of the mean and standard deviation and of the general reconstruction quality. The results show that the Haar wavelet provides higher peak signal-to-noise ratio (PSNR) values and better overall results, than other wavelets with more vanishing moments. Our proposed methodology has been implemented on an on-line-based measurement platform and compressed data traffic generated from a live network. Konstantinos G. Kyriakopoulos, David J. Parish |
IET Commun. | 1 |
| 2009 | Challenges in the capture and dissemination of measurements from high-speed networksabstractThe production of a large-scale monitoring system for a high-speed network leads to a number of challenges. These challenges are not purely technical but also socio-political and legal. The number of stakeholders in such monitoring activity is large including the network operators, the users, the equipment manufacturers and, of course, the monitoring researchers. The MASTS project (measurement at all scales in time and space) was created to instrument the high-speed JANET Lightpath network and has been extended to incorporate other paths supported by JANET(UK). Challenges the project has faced included: simple access to the network; legal issues involved in the storage and dissemination of the captured information, which may be personal; the volume of data captured and the rate at which these data appear at store. To this end, the MASTS system will have established four monitoring points each capturing packets on a high-speed link. Traffic header data will be continuously collected, anonymised, indexed, stored and made available to the research community. A legal framework for the capture and storage of network measurement data has been developed which allows the anonymised IP traces to be used for research purposes. Richard G. Clegg, Mark S. Withall, Andrew W. Moore 0002, Iain Phillips 0002, David J. Parish, Miguel Rio, Raul Landa, Hamed Haddadi 0001, Konstantinos G. Kyriakopoulos, J. Auge, R. Clayton, D. Salmon |
IET Commun. | 9 |
| 2007 | Automated Detection of Changes in Computer Network Measurements using WaveletsabstractMonitoring and measuring various metrics of high speed and high capacity networks produces a vast amount of information over a long period of time. For the collected monitoring data to be useful to administrators, these measurements need to be analyzed and processed in order to detect interesting characteristics such as sudden changes. In this paper wavelet analysis is used along with the universal threshold proposed by Donoho-Johnstone in order to detect abrupt changes in computer network measurements. Experimental results are obtained to compare the behaviour of the algorithm on delay and data rate signals. Both type of signals are measurements from real networks and not produced from a simulation tool. Results show that detection of anomalies is achievable in a variety of signals. Konstantinos G. Kyriakopoulos, David J. Parish |
ICCCN | 1 |
| 2007 | A Live System for Wavelet Compression of High Speed Computer Network Measurements
Konstantinos G. Kyriakopoulos, David J. Parish |
PAM | 1 |