VLDB 2026 Research / reviewers in the wild / expert
Audun Jøsang
dblp:j/AudunJosang
· DBLP profile ↗
68ranked-venue papers
38as first author
7since 2021 · last 2026
0000-0001-6337-2264ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 25 · 15 first-author · 4 since 2021Artificial intelligence and machine learning · 21 · 10 first-author · 4 since 2021Security and privacy · 19 · 14 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 2Theory of computation · 2Systems, architecture and hardware · 1Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | X-MAP: eXplainable Misclassification Analysis and Profiling for Spam and Phishing Detection
Qi Zhang 0104, Dian Chen 0007, Lance M. Kaplan, Audun Jøsang, Dong Hyun Jeong, Feng Chen 0001, Jin-Hee Cho |
PAKDD (3) | 4 |
| 2025 | fair-LDP: Uncertainty-Guided Fairness and Privacy for Federated Healthcare LearningabstractFederated Learning (FL) offers a promising approach for collaborative model training in healthcare while preserving data privacy. However, existing FL methods often fall short in addressing two critical challenges: client-level fairness and compounded uncertainty from data heterogeneity and privacy-preserving mechanisms. We propose fair-LDP, a fairness-aware Local Differential Privacy framework that promotes fairness and privacy via uncertainty-guided aggregation in federated healthcare AI. fair-LDP leverages evidential neural networks (ENNs) to quantify predictive uncertainty and introduces a novel strategy that uses uncertainty-driven local differential privacy to guide fairness-aware updates while preserving data privacy. This ensures equitable performance across clients with varying data quality while mitigating the influence of unreliable or outlier updates. fair-LDP incorporates an adaptive mechanism that adjusts each client's privacy budget based on model performance, balancing fairness, privacy, and accuracy. We evaluate fair-LDP on real-world healthcare datasets under both IID and non-IID settings. Our experimental results show that it consistently outperforms state-of-the-art fairness-aware and privacy-preserving FL baselines, with no added computational overhead, while maintaining privacy guarantees comparable to homomorphic encryption and secure multiparty computation. By integrating uncertainty modeling, fairness-aware aggregation, and adaptive local differential privacy, fair-LDP provides a practical and principled solution for responsible, equitable, and privacy-preserving federated learning in healthcare. Dian Chen 0007, Qi Zhang 0104, Lance M. Kaplan, Audun Jøsang, Dong Hyun Jeong, Feng Chen 0001, Jin-Hee Cho |
ICDM | 4 |
| 2024 | Dynamic Intelligence Assessment: Benchmarking LLMs on the Road to AGI with a Focus on Model ConfidenceabstractAs machine intelligence evolves, the need to test and compare the problem-solving abilities of different AI models grows. However, current benchmarks are often simplistic, allowing models to perform uniformly well and making it difficult to distinguish their capabilities. Additionally, benchmarks typically rely on static question-answer pairs that the models might memorize or guess. To address these limitations, we introduce Dynamic Intelligence Assessment (DIA), a novel methodology for testing AI models using dynamic question templates and improved metrics across multiple disciplines such as mathematics, cryptography, cybersecurity, and computer science. The accompanying dataset, DIA-Bench, contains a diverse collection of challenge templates with mutable parameters presented in various formats, including text, PDFs, compiled binaries, visual puzzles, and CTF-style cybersecurity challenges. Our framework introduces four new metrics to assess a model’s reliability and confidence across multiple attempts. These metrics revealed that even simple questions are frequently answered incorrectly when posed in varying forms, highlighting significant gaps in models’ reliability. Notably, API models like GPT-4o often overestimated their mathematical capabilities, while ChatGPT-4o demonstrated better performance due to effective tool usage. In self-assessment OpenAI’s o1-mini proved to have the best judgement on what tasks it should attempt to solve. We evaluated 25 state-of-the-art LLMs using DIA-Bench, showing that current models struggle with complex tasks and often display unexpectedly low confidence, even with simpler questions. The DIA framework sets a new standard for assessing not only problem-solving, but also a model’s adaptive intelligence and ability to assess its limitations. The dataset is publicly available on the project’s page: https://github.com/DIA-Bench. Norbert Tihanyi, Tamás Bisztray, Richard A. Dubniczky, Rebeka Tóth, Bertalan Borsos, Bilel Cherif, Ridhi Jain, Lajos Muzsai, Mohamed Amine Ferrag, Ryan Marinelli, Lucas C. Cordeiro, Mérouane Debbah, Vasileios Mavroeidis, Audun Jøsang |
IEEE Big Data | 14 |
| 2024 | Uncertainty-Aware Influence Maximization: Enhancing Propagation in Competitive Social Networks with Subjective LogicabstractThe Competitive Influence Maximization (CIM) problem involves entities competing to maximize influence in online social networks (OSNs). While Deep Reinforcement Learning (DRL) methods have shown promise, most assume binary user opinions and overlook behavioral factors. We introduce DRIM, a novel DRL-based CIM framework using Subjective Logic (SL) to incorporate user preferences and uncertainty, optimizing seed selection to spread true information while countering false information. DRIM’s Uncertainty-based Opinion Model (UOM) provides a realistic representation of user opinions. Results demonstrate that UOM maintains over 80% true influence against advanced misinformation, and DRIM outperforms state-of-the-art methods by up to 45% in influence and 77% in speed. DRIM also excels in limited-resource scenarios, networks with 10% invisibility, and when users are inclined to doubt true information. Qi Zhang 0104, Lance M. Kaplan, Audun Jøsang, Dong Hyun Jeong, Feng Chen 0001, Jin-Hee Cho |
IEEE Big Data | 3 |
| 2024 | Hyper Evidential Deep Learning to Quantify Composite Classification UncertaintyabstractDeep neural networks (DNNs) have been shown to perform well on exclusive, multi-class classification tasks. However, when different classes have similar visual features, it becomes challenging for human annotators to differentiate them. When an image is ambiguous, such as a blurry one where an annotator can't distinguish between a husky and a wolf, it may be labeled with both classes: {husky, wolf}. This scenario necessitates the use of composite set labels.
In this paper, we propose a novel framework called Hyper-Evidential Neural Network (HENN) that explicitly models predictive uncertainty caused by composite set labels in training data in the context of the belief theory called Subjective Logic (SL).
By placing a Grouped Dirichlet distribution on the class probabilities, we treat predictions of a neural network as parameters of hyper-subjective opinions and learn the network that collects both single and composite evidence leading to these hyper-opinions by a deterministic DNN from data.
We introduce a new uncertainty type called vagueness originally designed for hyper-opinions in SL to quantify composite classification uncertainty for DNNs.
Our experiments prove that HENN outperforms its state-of-the-art counterparts based on four image datasets.
The code and datasets are available at: https://shorturl.at/dhoqx. Changbin Li, Kangshuo Li, Yuzhe Ou, Lance M. Kaplan, Audun Jøsang, Jin-Hee Cho, Dong Hyun Jeong, Feng Chen 0001 |
ICLR | 5 |
| 2023 | Multi-Label Temporal Evidential Neural Networks for Early Event DetectionabstractEarly event detection aims to detect events even before the event is complete. However, most of the existing methods focus on an event with a single label but fail to be applied to cases with multiple labels. Another non-negligible issue for early event detection is a prediction with overconfidence due to the high vacuity uncertainty that exists in the early time series. It results in an over-confidence estimation and hence unreliable predictions. To this end, technically, we propose a novel framework, Multi-Label Temporal Evidential Neural Network (MTENN), for multi-label uncertainty estimation in temporal data. MTENN is able to quality predictive uncertainty due to the lack of evidence for multi-label classifications at each time stamp based on belief/evidence theory. In addition, we introduce a novel uncertainty estimation head (weighted binomial comultiplication (WBC)) to quantify the fused uncertainty of a sub-sequence for early event detection. We validate the performance of our approach with state-of-the-art techniques on real-world audio datasets. Xujiang Zhao, Xuchao Zhang, Chen Zhao 0010, Jin-Hee Cho, Lance M. Kaplan, Dong Hyun Jeong, Audun Jøsang, Feng Chen 0001 |
ICASSP | 7 |
| 2023 | Detecting Intents of Fake News Using Uncertainty-Aware Deep Reinforcement LearningabstractIntent mining is critical for controlling the spread of false information across online social networks (OSNs). To this end, we develop deep reinforcement learning (DRL) agents guided by a delayed reward based on intent prediction using a classifier of long short-term memory (LSTM). Additionally, we incorporate an uncertainty-aware function that leverages subjective opinions derived from Subjective Logic (SL). Through evaluation using an annotated fake news tweet dataset, our results demonstrate that our intent classification framework surpasses competing methods in terms of intent accuracy. Our intent mining solutions using DRL algorithms can support effective and efficient intervention strategies for fake news spreading on OSNs. Zhen Guo 0002, Qi Zhang 0104, Qisheng Zhang, Lance M. Kaplan, Audun Jøsang, Feng Chen 0001, Dong Hyun Jeong, Jin-Hee Cho |
ICWS | 5 |
| 2020 | Threat Poker: Gamification of Secure Agile
Audun Jøsang, Viktoria Stray, Hanne Rygge |
WISE | 1 |
| 2019 | Belief Mosaics of Subjective Opinions
Audun Jøsang |
FUSION | 1 |
| 2019 | An empirical evaluation of the approximation of subjective logic operators using Monte Carlo simulations
Fabio Massimo Zennaro, Magdalena Ivanovska, Audun Jøsang |
Int. J. Approx. Reason. | 3 |
| 2018 | A Framework for Data-Driven Physical Security and Insider Threat DetectionabstractThis paper presents PSO, an ontological framework and a methodology for improving physical security and insider threat detection. PSO can facilitate forensic data analysis and proactively mitigate insider threats by leveraging rule-based anomaly detection. In all too many cases, rule-based anomaly detection can detect employee deviations from organizational security policies. In addition, PSO can be considered a security provenance solution because of its ability to fully reconstruct attack patterns. Provenance graphs can be further analyzed to identify deceptive actions and overcome analytical mistakes that can result in bad decision-making, such as false attribution. Moreover, the information can be used to enrich the available intelligence (about intrusion attempts) that can form use cases to detect and remediate limitations in the system, such as loosely-coupled provenance graphs that in many cases indicate weaknesses in the physical security architecture. Ultimately, validation of the framework through use cases demonstrates and proves that PS0 can improve an organization's security posture in terms of physical security and insider threat detection. Vasileios Mavroeidis, Kamer Vishi, Audun Jøsang |
ASONAM | 3 |
| 2018 | Are My Arguments Trustworthy? Abstract Argumentation with Subjective LogicabstractAn Abstract Argumentation Framework (AAF) is an abstract structure consisting of a set arguments, whose origin, nature, and possible internal organisation is not specified, and by a binary relation of attack on the set of arguments, whose meaning is not specified either. Subjective logic provides a standard set of logical operators, intended for use in domains containing uncertainty. In this paper, we define an extension of AAFs in which each argument and attacks is evaluated with an opinion, by revisiting the constellations approach developed for probabilistic AAFs. In this way, different agents can merge their opinions on how much arguments and attacks are “trustworthy”, e.g., they do not represent fallacies or enthymemes. Finally, subjective logic operators can be used to fuse the belief of different possible worlds (i.e., a constellation of sub-graphs in the original AAF) containing different arguments and attacks. Francesco Santini 0001, Audun Jøsang, Maria Silvia Pini |
FUSION | 2 |
| 2018 | Uncertainty Characteristics of Subjective OpinionsabstractIn this work, we study different types of uncertainty in subjective opinions based on the internal belief mass distribution and the base rate distribution. Subjective opinions which are used as arguments in subjective logic (SL) expand the traditional belief functions by including base rate distributions. Fundamental uncertainty characteristics of a given opinion depend on its `singularity', `vagueness', `vacuity', `dissonance', `consonance' and `monosonance'. We define those concepts in the formalism of SL and show how these characteristics can be manifested in the three different opinion classes which are binomial, multinomial, and hyper-opinions. We clarify the relationships between the uncertainty characteristics and discuss how they influence decision making in SL. Audun Jøsang, Jin-Hee Cho, Feng Chen 0001 |
FUSION | 1 |
| 2018 | Global perspectives on cybersecurity educationabstractGlobal cybersecurity crises have compelled universities to address the demand for educated cybersecurity professionals. As no shared framework for cybersecurity as an academic discipline exists, growthhas been unfocused and driven by training materials, which make it harder to create a common body of knowledge. An international perspective is still harder, as different nations use different criteria to define local needs. As a result, new programs entering this space are on their own to conceptualize, design, package and market their programs, as there is no globally accepted reference model for cybersecurity to allow employers or students to understand the extent of a given cybersecurity program. Allen S. Parrish, John Impagliazzo, Rajendra K. Raj, Henrique M. Dinis Santos, Muhammad Rizwan Asghar, Audun Jøsang, Teresa Susana Mendes Pereira, Vítor J. Sá, Eliana Stavrou |
ITiCSE | 6 |
| 2017 | Multi-source fusion in subjective logicabstractBelief fusion consists of taking into account multiple sources of belief about a domain of interest. This paper describes cumulative and averaging multi-source belief fusion in the formalism of subjective logic, which represent generalisations of binary-source belief fusion operators previously described. The advantage of this approach is that we can model and analyse belief fusion situations involving an arbitrary number of sources. Audun Jøsang, Dongxia Wang 0002, Jie Zhang 0002 |
FUSION | 1 |
| 2017 | Multi-source trust revisionabstractDifferent belief sources often provide conflicting evidence, due to e.g. varying source reliability or deliberate deception. Source trust expresses the source reliability as seen by the analyst. In case of conflicting sources the analyst needs a strategy for managing and revising source trust. Intuitively, trust should be reduced for sources that produce advice which is in conflict with the ground truth, or in conflict with the advice from other highly trusted sources. The present paper uses the formalism of subjective logic to describe strategies for source trust revision according to this principle. Audun Jøsang, Jie Zhang 0002, Dongxia Wang 0002 |
FUSION | 1 |
| 2017 | Joint Subjective Opinions
Magdalena Ivanovska, Audun Jøsang, Jie Zhang 0002, Shuo Chen 0006 |
MDAI | 2 |
| 2016 | DEMO: OffPAD - Offline Personal Authenticating Device with Applications in Hospitals and e-BankingabstractIdentity and authentication solutions often lack usability and scalability, or do not provide high enough authentication assurance. The concept of Lucidman (Local User-Centric Identity Management) is an approach to providing scalable, secure and user friendly identity and authentication functionalities. In this context we demonstrate the use of an OffPAD (Offline Personal Authentication Device) as a trusted device to support different forms of authentication. The Lucidman/OffPAD approach consists of locating the identity management and authentication functionalities on the user side instead of on the server side or in the cloud. This demo aims to show how OffPAD strengthens authentication assurance, improves usability, minimizes trust requirements, and has the advantage that trusted online interaction can be achieved even on malware infected client platforms. The trusted device OffPAD has been designed as a phone cover, therefore not requiring the user to carry an extra gadget. We focus on six demonstrators, three useful in e-banking and three in the hospital domain where nurses, doctors, or patients are authenticated and access is granted in various situations base on the OffPAD. A video with the same title is available online at www.offpad.org. Denis Migdal, Christian Johansen, Audun Jøsang |
CCS | 3 |
| 2016 | Decision making under vagueness and uncertainty
Audun Jøsang |
FUSION | 1 |
| 2016 | Principles of subjective networks
Audun Jøsang, Lance M. Kaplan |
FUSION | 1 |
| 2016 | Bayesian Deduction with Subjective Opinions
Magdalena Ivanovska, Audun Jøsang, Francesco Sambo |
KR | 2 |
| 2015 | An accurate rating aggregation method for generating item reputationabstractMany websites presently provide the facility for users to rate items quality based on user opinion. These ratings are used later to produce item reputation scores. The majority of websites apply the mean method to aggregate user ratings. This method is very simple and is not considered as an accurate aggregator. Many methods have been proposed to make aggregators produce more accurate reputation scores. In the majority of proposed methods the authors use extra information about the rating providers or about the context (e.g. time) in which the rating was given. However, this information is not available all the time. In such cases these methods produce reputation scores using the mean method or other alternative simple methods. In this paper, we propose a novel reputation model that generates more accurate item reputation scores based on collected ratings only. Our proposed model embeds statistical data, previously disregarded, of a given rating dataset in order to enhance the accuracy of the generated reputation scores. In more detail, we use the Beta distribution to produce weights for ratings and aggregate ratings using the weighted mean method. Experiments show that the proposed model exhibits performance superior to that of current state-of-the-art models. Ahmad Abdel-Hafez, Yue Xu 0001, Audun Jøsang |
DSAA | 3 |
| 2015 | Trust revision for conflicting sources
Audun Jøsang, Magdalena Ivanovska, Tim Muller |
FUSION | 1 |
| 2015 | Towards subjective networks: Extending conditional reasoning in subjective logic
Lance M. Kaplan, Magdalena Ivanovska, Audun Jøsang, Francesco Sambo |
FUSION | 3 |
| 2015 | Information Theory for Subjective Logic
Tim Muller, Dongxia Wang 0002, Audun Jøsang |
MDAI | 3 |
| 2015 | A normal-distribution based rating aggregation method for generating product reputationsabstractWith the extensive use of rating systems in the web, and their significance in decision making process by users, the need for more accurate aggregation methods has emerged. The Naïve aggregation method, using the simple mean, is not adequate anymore in providing accurate reputation scores for items [6], hence, several researches where conducted in order to provide more accurate alternative aggregation methods. Most of the current reputation models do not consider the distribution of ratings across the different possible ratings values. In this paper, we propose a novel reputation model, which generates more accurate reputation scores for items by deploying the normal distribution over ratings. Experiments show promising results for our proposed model over state-of-the-art ones on sparse and dense datasets. Ahmad Abdel-Hafez, Yue Xu 0001, Audun Jøsang |
Web Intell. | 3 |
| 2014 | URREF self-confidence in information fusion trust
Erik Blasch, Audun Jøsang, Jean Dezert, Paulo C. G. Costa, Anne-Laure Jousselme |
FUSION | 2 |
| 2014 | Biometric data fusion based on subjective logic
Audun Jøsang, Thorvald H. Munch-Moller |
FUSION | 1 |
| 2014 | A Normal-Distribution Based Reputation Model
Ahmad Abdel-Hafez, Yue Xu 0001, Audun Jøsang |
TrustBus | 3 |
| 2014 | Product Feature Taxonomy Learning based on User ReviewsabstractIn recent years, the Web 2.0 has provided considerable facilities for people to create, share and exchange information and ideas. Upon this, the user generated content, such as reviews, has exploded. Such data provide a rich source to exploit in order to identify the information associated with specific reviewed items. Opinion mining has been widely used to identify the significant features of items (e.g., cameras) based upon user reviews. Feature extraction is the most critical step to identify useful information from texts. Most existing approaches only find individual features about a product without revealing the structural relationships between the features which usually exist. In this paper, we propose an approach to extract features and feature relationships, represented as a tree structure called feature taxonomy, based on frequent patterns and associations between patterns derived from user reviews. The generated feature taxonomy profiles the product at multiple levels and provides more detailed information about the product. Our experiment results based on some popularly used review datasets show that our proposed approach is able to capture the product features and relations effectively. Nan Tian, Yue Xu 0001, Yuefeng Li 0001, Ahmad Abdel-Hafez, Audun Jøsang |
WEBIST (2) | 5 |
| 2014 | Identity management and trusted interaction in internet and mobile computingabstractThe convergence of the Internet and mobile computing enables personalised access to online services anywhere and anytime. This potent access capability creates opportunities for new business models which stimulates vigorous investment and rapid innovation. Unfortunately, this innovation also produces new vulnerabilities and threats, and the new business models also create incentives for attacks, because criminals will always follow the money. Unless the new threats are balanced with appropriate countermeasures, growth in the Internet and mobile services will encounter painful setbacks. Security and trust are two fundamental factors for sustainable development of identity management in online markets and communities. The aim of this study is to present an overview of the central aspects of identity management in the Internet and mobile computing with respect to security and trust. Audun Jøsang |
IET Inf. Secur. | 1 |
| 2013 | Determining model correctness for situations of belief fusion
Audun Jøsang, Paulo C. G. Costa, Erik Blasch |
FUSION | 1 |
| 2013 | Combining Recommender and Reputation Systems to Produce Better Online Advice
Audun Jøsang, Guibing Guo, Maria Silvia Pini, Francesco Santini 0001, Yue Xu 0001 |
MDAI | 1 |
| 2013 | The OffPAD: Requirements and Usage
Kent A. Varmedal, Henning Klevjer, Joakim Hovlandsvåg, Audun Jøsang, Johann Vincent, Laurent Miralabé |
NSS | 4 |
| 2012 | Interpretation and fusion of hyper opinions in subjective logic
Audun Jøsang, Robin Hankin |
FUSION | 1 |
| 2012 | Service provider authentication assuranceabstractThe concept of authentication assurance traditionally refers to the robustness of methods and mechanisms for user authentication, including the robustness of initial registration and provisioning of user credentials, as well as the robustness of mechanisms that enforce user authentication during operation. However, the user is not the only party that needs to be authenticated to ensure security of online transactions. In fact, online service provision always involves two parties, typically the user on the client side and the service provider on the server side, so that mutual authentication between the two sides is required. In contrast to the unilateral focus on user authentication by industry and academia, it is in fact equally important for the user to correctly authenticate the service provider. Unfortunately, little attention is paid to the problem of correctly authentication the service provider. This paper proposes a framework for server and service provider authentication assurance, similarly to frameworks for user authentication assurance that have already been specified, or are currently under development by many national governments. Audun Jøsang, Kent A. Varmedal, Christophe Rosenberger |
PST | 1 |
| 2012 | Dempster's Rule as Seen by Little Colored BallsabstractDempster’s rule is traditionally interpreted as an operator for fusing belief functions. While there are different types of belief fusion, there has been considerable confusion regarding the exact type of operation that Dempster’s rule performs. Many alternative operators for belief fusion have been proposed, where some are based on the same fundamental principle as Dempster’s rule, and others have a totally different basis, such as the cumulative and averaging fusion operators. In this article, we analyze Dempster’s rule from a statistical and frequentist perspective and compare it with cumulative and averaging belief fusion. We prove, and illustrate by examples on colored balls, that Dempster’s rule in fact represents a method for serial combination of stochastic constraints. Consequently, Dempster’s rule is not a method for cumulative fusion of belief functions under the assumption that subjective beliefs are an extension of frequentist beliefs. Having identified the true nature of Dempster’s rule, appropriate applications of Dempster’s rule of combination are described such as the multiplication of orthogonal belief functions, and the combination of preferences dictated by different parties. Audun Jøsang, Simon Pope |
Comput. Intell. | 1 |
| 2011 | Redefining material implication with subjective logic
Audun Jøsang, Zied Elouedi |
FUSION | 1 |
| 2010 | SimTrust: A New Method of Trust Network GenerationabstractTrust can be used for neighbor formation to generate automated recommendations. User assigned explicit rating data can be used for this purpose. However, the explicit rating data is not always available. In this paper we present a new method of generating trust network based on user’s interest similarity. To identify the interest similarity, we use user’s personalized tag information. This trust network can be used to find the neighbors to make automated recommendation. Our experiment result shows that the precision of the proposed method outperforms the traditional collaborative filtering approach. Touhid Bhuiyan, Yue Xu 0001, Audun Jøsang |
EUC | 3 |
| 2010 | The base rate fallacy in belief reasoning
Audun Jøsang, Stephen O'Hara |
FUSION | 1 |
| 2010 | Multiplication of Multinomial Subjective Opinions
Audun Jøsang, Stephen O'Hara |
IPMU (1) | 1 |
| 2010 | The Mobile Phone as a Multi OTP Device Using Trusted ComputingabstractThe rapid growth in the number of online services leads to an increasing number of different digital identities each user needs to manage. As a result, many people feel overloaded with credentials, which in turn negatively impacts their ability to manage them securely. Passwords are perhaps the most common type of credential used today. To avoid the tedious task of remembering difficult passwords, users often behave less securely by using low entropy and weak passwords. Weak passwords and bad password habits represent security threats to online services. Some solutions have been developed to eliminate the need for users to create and manage passwords. A typical solution is based on giving the user a hardware token that generates one-time-passwords, i.e. passwords for single session or transaction usage. Unfortunately, most of these solutions do not satisfy scalability and/or usability requirements, or they are simply insecure. In this paper, we propose a scalable OTP solution using mobile phones and based on trusted computing technology that combines enhanced usability with strong security. Mohammed Al Zomai, Audun Jøsang |
NSS | 2 |
| 2010 | Privacy Policy Referencing
Audun Jøsang, Lothar Fritsch, Tobias Mahler |
TrustBus | 1 |
| 2010 | Developing Trust Networks Based on User Tagging Information for Recommendation Making
Touhid Bhuiyan, Yue Xu 0001, Audun Jøsang, Huizhi Liang 0001, Clive Cox |
WISE | 3 |
| 2009 | Fission of opinions in subjective logic
Audun Jøsang |
FUSION | 1 |
| 2009 | Spam filter optimality based on signal detection theoryabstractUnsolicited bulk email, commonly known as spam, represents a significant problem on the Internet. The seriousness of the situation is reflected by the fact that approximately 97% of the total e-mail traffic currently (2009) is spam. To fight this problem, various anti-spam methods have been proposed and are implemented to filter out spam before it gets delivered to recipients, but none of these methods are entirely satisfactory. In this paper we analyze the properties of spam filters from the viewpoint of Signal Detection Theory (SDT). The Bayesian approach of Signal Detection Theory provides a basis for determining the optimality of spam filters, i.e. whether they provide positive utility to users. In the process of decision making by a spam filter various tradeoff's are considered as a function of the costs of incorrect decisions and the benefits of correct decisions. Audun Jøsang, Md Sadek Ferdous, Ravishankar Borgaonkar |
SIN | 2 |
| 2009 | Advanced Features in Bayesian Reputation Systems
Audun Jøsang, Walter Quattrociocchi |
TrustBus | 1 |
| 2009 | A user-centric federated single sign-on system
Suriadi Suriadi, Ernest Foo, Audun Jøsang |
J. Netw. Comput. Appl. | 3 |
| 2008 | Strengthening SMS-Based Authentication through UsabilityabstractCurrent state-of-the art solutions for online banking authentication and identity management include methods for re-authenticating users via out-of-band channels for each transaction. SMS-based schemes belong to this category, and can provide strong authentication to protect against security attacks. Poor usability of these schemes is still a problem, which makes them vulnerable to other obvious attacks. This paper describes a method for improving the usability of typical SMS-based authentication schemes which thereby will improve their overall security. Mohammed Al Zomai, Audun Jøsang, Adrian McCullagh, Ernest Foo |
ISPA | 2 |
| 2008 | Combining Trust and Reputation Management for Web-Based Services
Audun Jøsang, Touhid Bhuiyan, Yue Xu 0001, Clive Cox |
TrustBus | 1 |
| 2007 | Dirichlet Reputation SystemsabstractReputation systems can be used in online markets and communities in order to stimulate quality and good behaviour as well as to sanction poor quality and bad behaviour. The basic idea is to have a mechanism for rating services on various aspects, and a way of computing reputation scores based on the ratings from many different parties. By making the reputation scores public, such systems can assist parties in deciding whether or not to use a particular service. Reputation systems represent soft security mechanisms for social control. This article presents a type of reputation system based on the Dirichlet probability distribution which is a multinomial Bayesian probability distribution. Dirichlet reputation systems represent a generalisation of the binomial Beta reputation system. The multinomial aspect of Dirichlet reputation systems means that any set of discrete rating levels can be defined. This provides great flexibility and usability, as well as a sound basis for designing reputation systems Audun Jøsang, Jochen Haller |
ARES | 1 |
| 2007 | Security Usability Principles for Vulnerability Analysis and Risk AssessmentabstractUsability is the weakest link in the security chain of many prominent applications. A set of security usability prin- ciples should therefore be considered when designing and engineering IT security solutions. When improving the us- ability of existing security applications, it is necessary to examine the underlying security technologies used to build them, and consider whether they need to be replaced by to- tally new security technologies that provide a better basis for good usability. This paper examines a set of security usability principles, proposes how they can be incorporated into the risk management process, and discusses the bene- fits of applying these principles and process to existing and future security solutions. Audun Jøsang, Bander AlFayyadh, Tyrone Grandison, Mohammed Al Zomai, Judith McNamara |
ACSAC | 1 |
| 2007 | Interpreting Belief Functions as Dirichlet Distributions
Audun Jøsang, Zied Elouedi |
ECSQARU | 1 |
| 2007 | A survey of trust and reputation systems for online service provision
Audun Jøsang, Roslan Ismail, Colin Boyd |
Decis. Support Syst. | 1 |
| 2006 | Simplification and analysis of transitive trust networks
Audun Jøsang, Elizabeth Gray, Michael Kinateder |
Web Intell. Agent Syst. | 1 |
| 2005 | Conditional Deduction Under Uncertainty
Audun Jøsang, Simon Pope, Milan Daniel |
ECSQARU | 1 |
| 2005 | Multiplication and comultiplication of beliefs
Audun Jøsang, David McAnally |
Int. J. Approx. Reason. | 1 |
| 2003 | Contract Performance Assessment for Secure and Dynamic Virtual CollaborationsabstractIn this paper we sketch a framework supporting contract enactment within the context of virtual organisation units that are dynamically created in order to achieve a common objective by securely sharing resources, services and information. The framework is built on top of a joint extension of the policy deployment architecture for peer-to-peer communities (Dimitrakos et al., 2002) and the contract enactment capability (Milosevic et al., 2002) that enables monitoring, mediation, arbitration and enforcement of electronic contracts in multiple, simultaneous closed collaborations. A longer-term goal is to deliver a scalable method of setting up contract enforcement and contract performance management infrastructures for interorganisational information systems that allow the on-demand creation and dynamic evolution of secure virtual organizations based on the ad-hoc integration of systems across enterprise boundaries. Theodosis Dimitrakos, Ivan Djordjevic, Zoran Milosevic, Audun Jøsang, Chris Phillips 0001 |
EDOC | 4 |
| 2002 | Discretionary Enforcement of Electronic ContractsabstractAs in traditional commerce, parties to a contract in e-business environments are expected to operate in good faith and comply with mutually agreed terms of the contract. It may be the case however that deviation from the agreed contract obligations occur either intentionally or due to force majeure. We argue that there is value in providing various levels of automated support to deal with contract non-compliance in e-marketplaces in order to reach the best overall outcome for all parties. This includes monitoring contract significant events, simple notifications to the parties about non-compliance events and a range of enforcement mechanisms. These mechanisms can be either nondiscretionary (as in preventive security mechanisms) or discretionary, which rely on a number of control mechanisms that are applied when contract rules are violated. We describe a number of such control mechanisms and how they can be used to extend capabilities of a contract management architecture previously developed. Zoran Milosevic, Audun Jøsang, Theodosis Dimitrakos, Mary Anne Patton |
EDOC | 2 |
| 2002 | The consensus operator for combining beliefs
Audun Jøsang |
Artif. Intell. | 1 |
| 2001 | A Logic for Uncertain ProbabilitiesabstractWe first describe a metric for uncertain probabilities called opinion, and subsequently a set of logical operators that can be used for logical reasoning with uncertain propositions. This framework which is called subjective logic uses elements from the Dempster-Shafer belief theory and we show that it is compatible with binary logic and probability calculus. Audun Jøsang |
Int. J. Uncertain. Fuzziness Knowl. Based Syst. | 1 |
| 2000 | PKI Seeks a Trusting Relationship
Audun Jøsang, Ingar Glenn Pedersen, Dean Povey |
ACISP | 1 |
| 1999 | An Algebra for Assessing Trust in Certification Chains
Audun Jøsang |
NDSS | 1 |
| 1998 | A Subjective Metric of Authentication
Audun Jøsang |
ESORICS | 1 |
| 1997 | Prospectives for Modelling Trust in Information Security
Audun Jøsang |
ACISP | 1 |
| 1997 | A Trust policy framework
Audun Jøsang |
ICICS | 1 |
| 1997 | How to trust systems
Audun Jøsang, F. Van Laenen, Svein J. Knapskog, Joos Vandewalle |
SEC | 1 |
| 1996 | The right type of trust for distributed systemsabstractResearch in information security has traditionally focused on where to place or how to propagate trust.In that sense, a cyptographic algorithm or protocol is simply a mechanism to transfer trust from where it exists to where it is needed.This paper puts the focus on trust itself and shows that it is a very complex concept with many interesting and important implications.We do not attempt to define a formal trust model, but rather examine the types of trust and trust relationships which are relevant for information security.It is shown that the existence of trust as a phenomenon depends on the existence of malicious behaviour.This observation leads to the distinction between passionate entities with human-like capabilities, and rational entities which basically are systems.Dust can then be defined as the belief that a rational entity will resist malicious manipulation or that a passionate entity will behave without malicious intent.It is also shown that trust relationships exhibit a great diversity, that they are based on knowledge and that they contain aspects in common with stmtegy games. Audun Jøsang |
NSPW | 1 |