EDBT 2026 Demo / reviewers in the wild / expert
Marthie Grobler
dblp:00/10437
· DBLP profile ↗
39ranked-venue papers
1as first author
26since 2021 · last 2026
0000-0001-6933-0145ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 8 since 2021Artificial intelligence and machine learning · 6 · 4 since 2021Human-computer interaction and ubiquitous computing · 6 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 5 · 5 since 2021Databases, data management, data science and information retrieval · 4 · 2 since 2021Computer networks · 3 · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Oversight to Insight: Transforming Cybersecurity Governance in BoardroomsabstractCybersecurity governance is increasingly critical in a digital economy, with board directors playing a central role in shaping organisational resilience. Directors are pivotal in setting cybersecurity strategies and carrying fiduciary obligations that extend to digital risk oversight. This study examines the cybersecurity literacy and governance practices of Australian board directors through a qualitative interview study with 13 participants. Findings reveal a substantial gap in directors’ knowledge and confidence, undermining effective oversight and informed decision-making. This deficit limits their ability to interrogate risk reports, challenge assumptions, and steer investment in line with organisational resilience goals. In response, we propose a Board Cyber Governance Model that integrates targeted education, strategic interventions, and structured board–CISO engagement to improve governance capability. By situating cyber governance at the intersection of executive decision-making, risk perception, and digital security, this work contributes to human-computer interaction by highlighting socio-organisational challenges and offering actionable insights for stronger board-level engagement. Tooba Aamir, Georgia Psaroulis, Marthie Grobler, Helge Janicke |
CHI | 3 |
| 2025 | Systemization of Knowledge (SoK): Goals, Coverage, and Evaluation in Cybersecurity and Privacy GamesabstractThis paper systematized existing knowledge on cybersecurity and privacy game-based approaches, exploring their goals, scope, and evaluation methods. Our review of 93 academic papers revealed that these approaches serve multiple purposes and target diverse player types. We identified 11 key aspects of cybersecurity and privacy that these approaches addressed, such as threats, defensive strategies, and data privacy. Additionally, we analyzed the effectiveness evaluation methods of these approaches, emphasizing the connections between evaluation techniques, types of data used, and their alignment with the approaches' goals. We also summarized the aspects of user experience evaluated in the literature and the types of questions used to capture these experiences. Reflecting on these methods, we provide guidance for future research and practice in designing and evaluating game-based approaches. Finally, we identify key gaps and propose opportunities to enhance user understanding, foster adaptability, and address emerging cybersecurity and privacy challenges. Marthie Grobler, Lauren S. Ferro, Georgia Psaroulis, Sanchari Das 0001, Jing Wei 0002, Helge Janicke |
CHI | 2 |
| 2025 | AI2TALE: An Innovative Information Theory-based Approach for Learning to Localize Phishing AttacksabstractPhishing attacks remain a significant challenge for detection, explanation, and defense, despite over a decade of research on both technical and non-technical solutions. AI-based phishing detection methods are among the most effective approaches for defeating phishing attacks, providing predictions on the vulnerability label (i.e., phishing or benign) of data. However, they often lack intrinsic explainability, failing to identify the specific information that triggers the classification. To this end, we propose AI2TALE, an innovative deep learning-based approach for email (the most common phishing medium) phishing attack localization. Our method aims to not only predict the vulnerability label of the email data but also provide the capability to automatically learn and identify the most important and phishing-relevant information (i.e., sentences) in the phishing email data, offering useful and concise explanations for the identified vulnerability.
Extensive experiments on seven diverse real-world email datasets demonstrate the capability and effectiveness of our method in selecting crucial information, enabling accurate detection and offering useful and concise explanations (via the most important and phishing-relevant information triggering the classification) for the vulnerability of phishing emails. Notably, our approach outperforms state-of-the-art baselines by 1.5% to 3.5% on average in Label-Accuracy and Cognitive-True-Positive metrics under a weakly supervised setting, where only vulnerability labels are used without requiring ground truth phishing information. Van Nguyen 0002, Tingmin Wu, Xingliang Yuan, Marthie Grobler, Surya Nepal, Carsten Rudolph |
ICLR | 4 |
| 2024 | The prince of insiders: a multiple pathway approach to understanding IP theft insider attacksabstractPurpose Intellectual property (IP) theft is an increasing threat that can lead to large financial losses and reputational harm. These attacks are typically noticed only after the IP is stolen, which is usually too late. This paper aims to investigate the psychological profile and the socio-technical events that statistically predict the likelihood of an IP threat. Design/methodology/approach This paper analyses 86 IP theft cases found in court documents. Two novel analyses are conducted. The research uses LLMs to analyse the personality of these insiders, which is followed by an investigation of the pathways to the attack using behaviour sequence analysis (BSA). Findings These IP theft insiders scored significantly higher on measures of Machiavellianism compared to the normal population. Socio-technical variables, including IP theft via photographs, travelling overseas, approaching multiple organisations and delivering presentations, were identified. Contrary to previous assumptions that there is a single pathway to an attack, the authors found that multiple, complex pathways lead to an attack (sometimes multiple attacks). This work, therefore, provides a new framework for considering critical pathways to insider attacks. Practical implications These findings reveal that IP theft insiders may come across as charming, star employees rather than the stereotype of disgruntled employees. Moreover, organisations’ policies may need to consider that IP theft occurs via non-linear and multiple pathways. This means that sequences of events need to be considered in detecting these attacks instead of anomalies outright. The authors also argue that there may be a case for “continuous evaluation” to detect insider activity. Originality/value This paper offers a new framework for understanding and studying insider threats. Instead of a single critical pathway, this work demonstrates the need to consider multiple interconnected pathways. It elucidates the importance of a multidisciplinary approach and provides opportunities to reconsider current practices in detection and prevention. Monica T. Whitty, Christopher Ruddy, David A. Keatley, Marcus A. Butavicius, Marthie Grobler |
Inf. Comput. Secur. | 5 |
| 2024 | Improving National Digital Identity Systems Usage: Human-Centric Cybersecurity SurveyabstractNational digital identity systems (NDIDs) are increasingly important for users’ authentication and secure access to e-government services. However, there is insufficient research on human-centric cybersecurity (HCCS) that impacts the use of NDIDs. Drawing on the theory of planned behavior and technical formal informal model, this paper proposes and validates a research model that depicts how HCCS affect the use of NDIDs. Data were collected from 203 Australian residents and analyzed using structural equation modeling and multiple linear regression analysis. The findings revealed that security, privacy, perceived risk, usability, flexibility, and cultural and social interference significantly impact the use of NDIDs. Considering HCCS in NDIDs usage, especially in risk-conscious cultures, is crucial. Low cybersecurity awareness and trust impede NDIDs adoption, emphasizing the need for cybersecurity education and awareness. The insights benefit policymakers, governments, and cybersecurity practitioners, providing a valuable understanding of human-centric cybersecurity influence on the use of NDIDs. Malyun Muhudin Hilowle, William Yeoh 0002, Marthie Grobler, Graeme Pye, Frank Jiang 0001 |
J. Comput. Inf. Syst. | 3 |
| 2024 | Demystifying the Evolution of Android Malware VariantsabstractIt is important to understand the evolution of Android malware as this facilitates the development of defence techniques by proactively capturing malware features. So far, researchers mainly rely on dendrogram or family-tree analysis for malware's evolutionary development. However, our research finds that these techniques cannot support comprehensive malware evolution modelling, which provides a detailed explanation for why Android malware samples evolve in specific ways. This shortcoming is mainly caused by the coarse-grained clustering and analysis of malware samples. For example, because these works do not divide malware samples of a family into variant sets and explore the evolution principles among those sets, they usually fail to capture new variants that have been empowered by the feature ‘drifting’ in evolution. To address this problem, we propose a fine-grained and in-depth analysis of Android malware. Our experimental work systematically reveals the phylogenetic relationships among the variant sets for a deeper malware evolution analysis. We introduce five metrics: silhouette coefficient, creation date, variant labels, the presentativeness of the variant set formula, and the correctness of the linked edges to evaluate the correctness of our analysis. The results show that our variant clustering achieved a high silhouette value at a small sample distance (0.3), a small standard deviation (three months and 16 days) date based on when the malware samples are lastly modified, a high label consistency (91.4%), a high representativeness (93.1%) of the variant set formula. All the linked variant sets are connected based on our PhyloNet construction rules. We further analyse the coding details of Android malware for each variant set and summarise models of their evolutionary development. In this work, we successfully expose two major models of malware evolution:active evolutionandpassive evolution. We also disclose four technical explanations on the incentives of the two evolution models (two for each model respectively). These findings are valuable for proactive defence against newly emerged malware samples. Lihong Tang, Xiao Chen 0002, Sheng Wen, Li Li 0029, Marthie Grobler, Yang Xiang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Generating Semantic Adversarial Examples via Feature Manipulation in Latent SpaceabstractThe susceptibility of deep neural networks (DNNs) to adversarial intrusions, exemplified by adversarial examples, is well-documented. Conventional attacks implement unstructured, pixel-wise perturbations to mislead classifiers, which often results in a noticeable departure from natural samples and lacks human-perceptible interpretability. In this work, we present an adversarial attack strategy that implements fine-granularity, semantic-meaning-oriented structural perturbations. Our proposed methodology manipulates the semantic attributes of images through the use of disentangled latent codes. We engineer adversarial perturbations by manipulating either a single latent code or a combination thereof. To this end, we propose two unsupervised semantic manipulation strategies: one based on vector-disentangled representation and the other on feature map-disentangled representation, taking into consideration the complexity of the latent codes and the smoothness of the reconstructed images. Our empirical evaluations, conducted extensively on real-world image data, showcase the potency of our attacks, particularly against black-box classifiers. Furthermore, we establish the existence of a universal semantic adversarial example that is agnostic to specific images. Shuo Wang 0012, Shangyu Chen, Surya Nepal, Carsten Rudolph, Marthie Grobler |
IEEE Trans. Neural Networks Learn. Syst. | 6 |
| 2023 | Government Mobile Apps: Analysing Citizen Feedback via App ReviewsabstractGovernments worldwide are increasingly embracing digital transformation initiatives to enhance service delivery, engage citizens, and achieve better outcomes. However, obtaining continuous feedback on these initiatives poses a substantial challenge. This paper investigates the feasibility of leveraging mobile app reviews as a valuable source of citizen feedback on government digital services. We analyse 100,146 app reviews from 129 government mobile apps in Australia and identify several functional and usability issues. These include issues such as app instability, complexity, integration problems, navigation difficulties, inaccuracies, and challenges with ID verification and authentication processes. Furthermore, we uncover several factors that influence user satisfaction, including accuracy and reliability, convenience, dependability, user-centric design, and overall user-friendliness. These findings demonstrate a strong correlation between user feedback and the government's digital transformation strategy, underscoring the viability of mobile app reviews as a cost-effective avenue for collecting citizen feedback. Tooba Aamir, Mohan Baruwal Chhetri, Mahawaga Arachchige Pathum Chamikara, Marthie Grobler |
ASE | 4 |
| 2023 | DACP: Enforcing a dynamic access control policy in cross-domain environmentsabstractEnabling hybrid authorisations to enforce dynamic access control policy from single-domain to cross-domain environments (CDEs) is important for distributed services. However, traditional Attribute-Based Access Control (ABAC) models are incompatible with CDEs. To fill this gap, approaches that apply cryptographic primitives, e.g., attribute-based encryption (ABE), have been proposed. The computation and storage overhead in most ABE constructions is non-negligible and increases with the complexity of the associated policies. In addition, most access control policy systems enforce authorisation policies in a centralized way, raising serious security and privacy issues. In this paper, we introduce DACP – a practical Dynamic Access Control Policy system supporting dynamic cross-domain authorisation. DACP combines traditional ABAC approach and a novel cryptographic primitive Attribute-based group signature (ABGS). ABAC is used for the access control decision and policy enforcement according to the user’s attributes whereas ABGS is used for managing the user’s attributes between users and authorities. Thus, the user’s attributes are securely distributed along with the access structure in CDEs while preserving the user’s privacy. We present the concrete design and implementation of DACP, and evaluate it in real-world settings. The evaluation shows that DACP is practical and efficient in CDEs. Ahmad Salehi S., Runchao Han, Carsten Rudolph, Marthie Grobler |
Comput. Networks | 4 |
| 2023 | Users' Adoption of National Digital Identity Systems: Human-Centric Cybersecurity ReviewabstractThis paper establishes the current state of human-centric cybersecurity factors that influence users’ adoption of national digital identity systems (NDIDs). NDIDs are national-level security systems that provide digital identity management services for secure authentication and access to online government services. Advances in NDIDs have raised concerns about human-centric cybersecurity factors. These concerns motivated researchers to explore the human aspects of cybersecurity. This paper critically synthesizes the literature on human-centric cybersecurity factors to enrich our knowledge of why users adopt or reject NDIDs. This paper identifies a combination of trust, privacy, perceived risk, usability, flexibility, cultural and social interference, and security factors that influence the adoption of NDIDs. This study builds a multi-level conceptual framework to contextualize human-centric cybersecurity factors influencing NDIDs adoption. This paper contributes to current literature and recommends that future research should consider non-technical aspects of cybersecurity that affect NDIDs adoption. Malyun Muhudin Hilowle, William Yeoh 0002, Marthie Grobler, Graeme Pye, Frank Jiang 0001 |
J. Comput. Inf. Syst. | 3 |
| 2023 | UCoin: An Efficient Privacy Preserving Scheme for CryptocurrenciesabstractIn cryptocurrencies, privacy of users is preserved using pseudonymity . However, it has been shown that pseudonymity does not result in anonymity if a user's transactions are linkable. This makes cryptocurrencies vulnerable to deanonymization attacks. The current solutions proposed in the literature suffer from at least one of the following issues: (1) requiring a trusted third–party entity, (2) poor performance, and (3) incompatible with the standard structure of cryptocurrencies. In this article, we propose Unlinkable Coin (UCoin), a secure mix–based approach to address these issues. In UCoin, the link between the input (payer) and output (payee) addresses in a transaction is broken. This is done by mixing the transactions of multiple users into a single aggregated transaction in which the output addresses have been secretly shuffled. In our protocol design, we first develop HDC–net, a secure shuffling protocol that enables a group of users to anonymously publish their data. Then, we deploy the proposed HDC–net protocol in the UCoin architecture (as a mixing unit) to generate the aggregate transactions. We show that UCoin (1) does not rely on a trusted third–party, (2) can mix 50 transactions in 6.3 seconds that is 18% faster than the current solutions, and (3) is fully compatible with the architecture of cryptocurrencies. Mohammad Reza Nosouhi, Shui Yu 0001, Keshav Sood, Marthie Grobler, Raja Jurdak, Ali Dorri, Shigen Shen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | How Does Visualisation Help App Practitioners Analyse Android Apps?abstractBehaviour analysis is essential for the security verification of suspicious Android applications, but analysts are usually faced with a huge obstacle when conducting the app behaviour analysis. They are expected to have comprehensive knowledge of different IT fields and a strong awareness of cyber threats. However, training a new security analyst typically requires a significant amount of time and can be extremely costly. Although there are tools available to assist analysts in studying Android behaviour and security, the completion of this task still heavily relies on the experience of the analysts. To address this problem, we recognise visualisation as a promising method and conduct a series of controlled experiments to demonstrate its effectiveness in the context of Android app behaviour and security analysis. We accordingly develop a visualisation tool based on apps’ call graphs (CG) (namedVisualDroid) and conduct an experiment and a follow-up interview. Compared to existing solutions, the results suggest that the CG-based visualisation solution (VisualDroid) can lower the barriers to Android behaviour and security analysis. The user study reveals that the platform includes CG-based visualisation components leads to a statistically significant improvement in Android behaviour analysis and security awareness. More specifically, it improvesAPK Analyzer,JD-GUI,JD-GUI+FlowDroidby 71.4%, 35.7%, and 39.2% in terms of the effectiveness of behaviour analysis. Participants who useVisualDroidalso show improvements in the aspect of security awareness with an increase of 155% againstAPK Analyzer, 96% againstJD-GUI, and 59.3%JD-GUI+FlowDroid. Lihong Tang, Tingmin Wu, Xiao Chen 0002, Sheng Wen, Li Li 0029, Xin Xia 0001, Marthie Grobler, Yang Xiang 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2023 | Preserving Privacy for Distributed Genome-Wide Analysis Against Identity Tracing AttacksabstractGenome-wide analysis has demonstrated both health and social benefits. However, large scale sharing of such data may reveal sensitive information about individuals. One of the emerging challenges is identity tracing attack that exploits correlations among genomic data to reveal the identity of DNA samples. In this paper, we first demonstrate that the adversary can narrow down the sample's identity by detecting his/her genetic relatives and quantify such privacy threat by employing a Shannon entropy-based measurement. For example, we exemplify that when the dataset size reaches 30% of the population, for any target from that population, the uncertainty of the target's identity is reduced to merely 2.3 bits of entropy (i.e., the identity is pinned down within 5 people). Direct application of existing approaches such as differential privacy (DP), secure multiparty computation (MPC) and homomorphic encryption (HE) may not be applicable to this challenge in genome-wide analysis because of the compromise on utility (i.e., accuracy or efficiency). Towards addressing this challenge, this paper proposes a framework named$\upsilon$Fragto facilitate privacy-preserving data sharing and computation in genome-wide analysis.$\upsilon$Fragmitigates privacy risks by using a vertical fragmentation to disrupt the genetic architecture on which the adversary relies for identity tracing without sacrificing the capability of genome-wide analysis. We theoretically prove that it preserves the correctness of the primitive functionalities and algorithms ranging from basic summary statistics to advanced neural networks. Our experiments demonstrate that$\upsilon$Fragoutperforms secure multiparty computation (MPC) and homomorphic encryption (HE) protocols, with a speedup of more than 221x for training neural networks, and also traditional non-private algorithms and a state-of-the-art noise-based differential privacy (DP) solution in most settings. Yanjun Zhang 0002, Guangdong Bai, Xue Li 0001, Surya Nepal, Marthie Grobler, Chen Chen 0056, Ryan Kok Leong Ko |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | Local Differential Privacy for Federated Learning
Mahawaga Arachchige Pathum Chamikara, Dongxi Liu, Seyit Ahmet Çamtepe, Surya Nepal, Marthie Grobler, Peter Bertók, Ibrahim Khalil 0001 |
ESORICS (1) | 5 |
| 2022 | R-Net: Robustness Enhanced Financial Time-Series Prediction with Differential PrivacyabstractArtificial intelligence has been investigated to conduct automatic predictions on financial time series such as stock. However, they faced two challenges. Firstly, the stock movement is affected by both technical fundamentals and external textual information. Secondly, resource data are often highly-noisy and heterogeneous, and prediction based on noisy data usually leads to significant errors. We propose a robust and accurate model (R-Net) that incorporates both technical information and qualitative sentiment derived from news reports for daily stock movement prediction in response to these challenges. A variety of enhancement strategies are adopted to improve the prediction model's robustness and accuracy. Specifically, a multimodal CNN and LSTM neural networks are applied to extract semantics from text and model complex temporal characteristics for stock market prediction. Further, based on the connection between the robustness of deep neural networks and differential privacy, we utilize provable noise injection and heterogeneous Gaussian mechanisms to enhance model robustness and accuracy. Experimental results on S&P 500 stocks demonstrate that our proposed R-Net, which integrates four enhancements, achieves 12.7% and 0.67% improvement in prediction accuracy for trends and price value prediction, respectively. Shuo Wang 0012, Jinyuan Qin, Carsten Rudolph, Surya Nepal, Marthie Grobler |
IJCNN | 5 |
| 2022 | Towards Improving the Adoption and Usage of National Digital Identity SystemsabstractUser perceptions of national digital identity systems (NDIDs) significantly impact their use and acceptance. Previous study on the use of NDIDs has provided limited frameworks for future research, with a strong emphasis on government services as well as how the system may be improved. This study evaluates how human-centric cybersecurity factors influence the use of NDIDs and acceptance among users. For instance, MyHealth record, which is used in Australia to record medical services provided to users, was overwhelmingly rejected by users due to concerns about digital identification information being used without authorisation and other privacy concerns. We hypothesise that human-centric cybersecurity factors influence the use of NDID and acceptance among users. The study also has a practical implication since it provides a framework to determine human-centric cybersecurity factors that influence adoption and improve NDIDs usage. Malyun Muhudin Hilowle, William Yeoh 0002, Marthie Grobler, Graeme Pye, Frank Jiang 0001 |
ASE | 3 |
| 2022 | Simulating cyber security management: A gamified approach to executive decision makingabstractExecutive managers are not all equipped with the cyber security expertise necessary to enable them to make business decisions that accurately represent the status and needs of the cyber security side of the business. Unfortunately, the lack of understanding between the business and cyber security domains contribute to structurally endorsed vulnerabilities within a business context, where either the business needs were considered without understanding the impact on cyber security, or alternatively, the cyber security needs were considered without fully understanding the impact this would have on the business strategy and financial stability. To combat this dilemma, a gamified approach to cyber security training for executives is proposed as a solution to not only minimise the realisation of cyber vulnerabilities within a business context, but also to improve business outcomes that are supported by cyber security measures. We developed a serious game software platform, Aurelius, to simulate an executive decision maker’s role in managing the everyday cyber security investment decisions, and linking that to business metrics to incorporate the business and cyber security understanding. Our game includes simulated cyber security attacks that would require the executive decision maker (the player) to respond appropriately. The algorithms underpinning our simulated cyber security game are a product of a complex systems approach, as this most accurately models an executive’s experience. In our design, we set up Aurelius to fulfil eight of the nine criteria specified for a state of the art serious game in the cyber security domain. Adam Tonkin, William Kosasih, Marthie Grobler, Mehwish Nasim |
ASE | 3 |
| 2022 | Towards Spoofing Resistant Next Generation IoT NetworksabstractThe potential vulnerability to wireless spoofing attacks is still a critical concern for Next Generation Internet of Things (NGIoT) networks which may result in catastrophic consequences in mission–critical applications. Conventional solutions may impose additional signal processing, protocol, and latency overheads which are inappropriate for NGIoT networks designed to provide high–speed and low–latency connections for a large number of resource–constrained IoT devices. In this paper, we utilize the uniqueness of beam pattern features in mmWave–enabled devices and propose a scalable security mechanism for the detection of wireless spoofing attacks in NGIoT networks. This uniqueness is proven to exist due to the non–ideal manufacturing of antenna arrays used in mmWave–enabled devices. In our approach, when legitimate mmWave–enabled IoT devices enrol into the network, their unique beam features are learned by a learning model developed at the network server. Then, during data transmission, network base stations (gNBs)/Access Points (APs) measure the beam features from the received RF signals and send them to the network server for the detection of anomalies. We develop our learning model based on Deep Autoencoders (DAEs) that are an effective tool for anomaly detection. Fortunately, the beam feature extraction can be performed using the beam searching mechanism that is already provided in mmWave standards (5G–NR and IEEE 802.11ad). Thus, feature extraction does not introduce any signal processing overheads to the system. Moreover, the proposed mechanism imposes zero computation/communication overhead to the resource—constrained IoT nodes. In our experiments, we reached 98.6% accuracy in the detection of illegitimate devices which confirms the effectiveness of the proposed approach. Mohammad Reza Nosouhi, Keshav Sood, Marthie Grobler, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Adversarial Detection by Latent Style TransformationsabstractDetection-based defense approaches are effective against adversarial attacks without compromising the structure of the protected model. However, they could be bypassed by stronger adversarial attacks and are limited in their ability to handle high-fidelity images. In this paper, we explore an effective detection-based defense against adversarial attacks on images (including high-resolution images) by extending the investigation beyond a single-instance perspective to incorporate its transformations as well. Our intuition is that the essential characteristics of a valid image are generally not affected by non-essential style transformations, for example, a slight variation in the facial expression of a portrait would not alter its identification. In contrast, adversarial examples are designed to affect only a single instance at a time, with unpredictable effects on a set of transformations of the instance. Consequently, we leverage a controllable generative mechanism to conduct the non-essential style transformations for a given image via modification along the style axis in the latent space. Next, the consistency of prediction between the given input and its style transformations is used to distinguish adversarial instances. Based on experiments on three image datasets, including high-resolution images, we demonstrated that our defense could detect 90–100 percent of adversarial examples produced by various state-of-the-art adversarial attacks, with a low false-positive rate. Shuo Wang 0012, Surya Nepal, Alsharif Abuadbba, Carsten Rudolph, Marthie Grobler |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | OCTOPUS: Overcoming Performance and Privatization Bottlenecks in Distributed LearningabstractThe diversity and quantity of data warehouses, gathering data from distributed devices such as mobile devices, can enhance the success and robustness of machine learning algorithms. Federated learning enables distributed participants to collaboratively learn a commonly shared model while holding data locally. However, it is also faced with expensive communication and limitations due to the heterogeneity of distributed data sources and lack of access to global data. In this paper, we investigate a practical distributed learning scenario where multiple downstream tasks (e.g., classifiers) could be efficiently learned from dynamically updated and non-iid distributed data sources while providing local data privatization. We introduce a new distributed/collaborative learning scheme to address communication overhead via latent compression, leveraging global data while providing privatization of local data without additional cost due to encryption or perturbation. This scheme divides learning into (1) informative feature encoding, and transmitting the latent representation of local data to address communication overhead; (2) downstream tasks centralized at the server using the encoded codes gathered from each node to address computing overhead. Besides, a disentanglement strategy is applied to address the privatization of sensitive components of local data. Extensive experiments are conducted on image and speech datasets. The results demonstrate that downstream tasks with the compact latent representations with the privatization of local data can achieve comparable accuracy to centralized learning. Shuo Wang 0012, Surya Nepal, Kristen Moore, Marthie Grobler, Carsten Rudolph, Alsharif Abuadbba |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2022 | Backdoor Attacks Against Transfer Learning With Pre-Trained Deep Learning ModelsabstractTransfer learning provides an effective solution for feasibly and fast customize accurateStudentmodels, by transferring the learned knowledge of pre-trainedTeachermodels over large datasets via fine-tuning. Many pre-trained Teacher models used in transfer learning are publicly available and maintained by public platforms, increasing their vulnerability to backdoor attacks. In this article, we demonstrate a backdoor threat to transfer learning tasks on both image and time-series data leveraging the knowledge of publicly accessible Teacher models, aimed at defeating three commonly adopted defenses:pruning-based,retraining-basedandinput pre-processing-based defenses. Specifically, ($\mathcal {A}$A) ranking-based selection mechanism to speed up the backdoor trigger generation and perturbation process while defeatingpruning-basedand/orretraining-based defenses. ($\mathcal {B}$B) autoencoder-powered trigger generation is proposed to produce a robust trigger that can defeat theinput pre-processing-based defense, while guaranteeing that selected neuron(s) can be significantly activated. ($\mathcal {C}$C) defense-aware retraining to generate the manipulated model using reverse-engineered model inputs. We launch effective misclassification attacks on Student models over real-world images, brain Magnetic Resonance Imaging (MRI) data and Electrocardiography (ECG) learning systems. The experiments reveal that our enhanced attack can maintain the 98.4 and 97.2 percent classification accuracy as the genuine model on clean image and time series inputs while improving$27.9\%-100\%$27.9%-100%and$27.1\%-56.1\%$27.1%-56.1%attack success rate on trojaned image and time series inputs respectively in the presence of pruning-based and/or retraining-based defenses. Shuo Wang 0012, Surya Nepal, Carsten Rudolph, Marthie Grobler, Shangyu Chen |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | Defending Adversarial Attacks via Semantic Feature ManipulationabstractMachine learning models have demonstrated vulnerability to adversarial attacks, more specifically misclassification of adversarial examples. In this article, we propose a one-off and attack-agnostic Feature Manipulation (FM)-Defense to detect and purify adversarial examples in an interpretable and efficient manner. The intuition is that the classification result of a normal image is generally resistant to non-significant intrinsic feature changes, e.g., varying the thickness of handwritten digits. In contrast, adversarial examples are sensitive to such changes since the perturbation lacks transferability. To enable manipulation of features, a Combo-variational autoencoder is applied to learn disentangled latent codes that reveal semantic features. The resistance to classification change over the morphs, derived by varying and reconstructing latent codes, is used to detect suspicious inputs. Furthermore, Combo-VAE is enhanced to purify the adversarial examples with good quality by considering class-shared and class-unique features. We empirically demonstrate the effectiveness of detection and quality of purified instances. Our experiments on three datasets show that FM-Defense can detect nearly 100 percent of adversarial examples produced by different state-of-the-art adversarial attacks. It achieves more than 99 percent overall purification accuracy on the suspicious instances that close the manifold of clean examples. Shuo Wang 0012, Surya Nepal, Carsten Rudolph, Marthie Grobler, Shangyu Chen, Zike An |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | Microwave Link Failures Prediction via LSTM-based Feature Fusion NetworkabstractMicrowave links are widely employed in cellular data networks due to high-speed Internet access and easy installation, thus reducing network implementation costs. However, these links are prone to failure and may lead to performance degradation, unavailability and service disruption. Early detection of any link failures is critical to maintain network quality, but the complex environment and the dynamic nature of link information makes this a complicated process. In this work, we propose a Long Short-Term Memory (LSTM)-based feature fusion network (LSTM-FFN) to fuse and encode both homophy and structural equivalence relationships in the LSTM temporal feature learning network. This will simultaneously model the spatial and temporal features exhibited in Long-Term Evolution (LTE) networks to detect any link failures. Our proposed method effectively avoids the gradient exploding problem that RNN-based STGNN faced. This multi-scale topological feature fusion allows the LSTM-FFN to further explore the spatial dependencies among nodel/ink and include additional structural equivalence in modeling compared with previous network failure detection work. The evaluation results show that LSTM- FFN outperforms other statistical-based methods with and without network topology encoded, and reaches 94.1 % precision, 90.2 % recall and 92.1 % fl-score. Zichan Ruan, Shuiqiao Yang, Lei Pan 0002, Xingjun Ma, Wei Luo 0001, Marthie Grobler |
IJCNN | 6 |
| 2021 | Software developers need help too! Developing a methodology to analyse cognitive dimension-based feedback on usabilityabstractSoftware developers use various methods to evaluate usability and identify usability issues that exist in systems they develop. Cognitive dimensions framework (CDF) based usability evaluation is one of the popular usability evaluation methods. It uses an open-ended questionnaire to collect qualitative feedback from users after using a system. To identify usability issues, evaluators should analyse this qualitative feedback. However, the approach to follow when performing this analysis is not explored in detail. We conducted a systematic literature review and reviewed 70 studies that used various CDF questionnaires for usability evaluations and investigated how those studies have analysed CDF questionnaire responses to identify usability issues. This revealed five methods that previous research has used for data analysis and four methods for identifying usability issues from CDF questionnaire responses. We applied the results of the literature review to develop a methodology and a set of guidelines to analyse qualitative feedback collected via a CDF questionnaire that targets evaluating security application programming interfaces. We tested the developed guidelines by conducting an empirical investigation. The results of the experiment revealed that using the proposed guidelines helps to identify significantly more usability issues with a higher validity. Chamila Wijayarathna, Marthie Grobler, Nalin Arachchilage |
Behav. Inf. Technol. | 2 |
| 2021 | "Who Wants to Know all this Stuff?!": Understanding Older Adults' Privacy Concerns in Aged Care Monitoring DevicesabstractAbstract Aged care monitoring devices (ACMDs) enable older adults to live independently at home. But to do so, ACMDs collect and share older adults’ personal information with others, potentially raising privacy concerns. This paper presents a detailed account of the different privacy problems in ACMDs that concern older adults. We report findings from interviews and a focus group conducted with older adults who are ageing in place. Using Daniel Solove’s privacy taxonomy to categorize privacy concerns, our analysis suggests that older adults are concerned about the potential for ACMDs to give rise to six problems: surveillance, secondary use of data, breach of confidentiality, disclosure, decisional interference and disturbing others. Other findings indicate that participants are worried about their ability to impose control over collection and management of their personal details and are willing to only accept privacy trade-offs during emergencies. We provide recommendations for ACMD developers and future directions to address findings from this research. Sami Alkhatib, Ryan Kelly 0001, Jenny Waycott, George Buchanan 0001, Marthie Grobler, Shuo Wang 0012 |
Interact. Comput. | 5 |
| 2021 | The importance of social identity on password formulations
Marthie Grobler, Mahawaga Arachchige Pathum Chamikara, Jacob Abbott, Jongkil Jeong, Surya Nepal, Cécile Paris |
Pers. Ubiquitous Comput. | 1 |
| 2020 | Towards a Trusted Collaborative Medical Decision-Making Platform
Hamza Sellak, Mohan Baruwal Chhetri, Marthie Grobler |
CollaborateCom (2) | 3 |
| 2020 | PART-GAN: Privacy-Preserving Time-Series Sharing
Shuo Wang 0012, Carsten Rudolph, Surya Nepal, Marthie Grobler, Shangyu Chen |
ICANN (1) | 4 |
| 2020 | OIAD: One-for-all Image Anomaly Detection with Disentanglement LearningabstractAnomaly detection aims to recognize samples with anomalous and unusual patterns with respect to a set of normal data. This is significant for numerous domain applications, such as industrial inspection, medical imaging, and security enforcement. There are two key research challenges associated with existing anomaly detection approaches: (1) many approaches perform well on low-dimensional problems however the performance on high-dimensional instances, such as images, is limited; (2) many approaches often rely on traditional supervised approaches and manual engineering of features, while the topic has not been fully explored yet using modern deep learning approaches, even when the well-label samples are limited. In this paper, we propose a One-for-all Image Anomaly Detection system (OIAD) based on disentangled learning using only clean samples. Our key insight is that the impact of small perturbation on the latent representation can be bounded for normal samples while anomaly images are usually outside such bounded intervals, referred to as structure consistency. We implement this idea and evaluate its performance for anomaly detection. Our experiments with three datasets show that OIAD can detect over 90% of anomalies while maintaining a low false alarm rate. It can also detect suspicious samples from samples labeled as clean, coincided with what humans would deem unusual. Shuo Wang 0012, Shangyu Chen, Surya Nepal, Carsten Rudolph, Marthie Grobler |
IJCNN | 6 |
| 2020 | Attribute-Based Data Access Control for Multi-Authority SystemabstractAccess control and authorization in universal basic services is one of the main security issues in distributed systems. In particular, access control in distributed systems, such as in healthcare systems, are crucial to improve facility safety and security. This can lead to the provision of better quality of life and contribute to a healthier future. In order to provide better services, it is necessary to develop a suitable and acceptable authorization system to prevent unauthorized access to data shared in these highly dynamic distributed environments. In practice, several types of service providers, institutes, and authorities generate a variety of data in a shared environment via central authority for their entities. Generally, the use of a central authority introduces several security and privacy issues due to the increased risk if the central authority is compromised. To address this issue, several traditional access control models have been developed and introduced. These models, however, have raised several critical security issues, and there is often a need to combine it with a cryptographic approach to offer and create better access control service to users in multi-domains. To achieve this, we provide an appropriate solution to this issue. In this paper, we introduce an access control policy model for the multi-authority system, which enables attribute authorities to control the security setting. We present a new access control framework for a dynamic authorization model that uses Attribute-Based Access Control (ABAC) and digital signature. We first define and present our system and then formalize the construction of the proposed system. Our system provides flexible access control and enhanced privacy in applied and distributed environments. Ahmad Salehi S., Carsten Rudolph, Marthie Grobler |
TrustCom | 3 |
| 2020 | Privacy-Preserving Data Generation and Sharing Using Identification Sanitizer
Shuo Wang 0012, Lingjuan Lyu, Shangyu Chen, Surya Nepal, Carsten Rudolph, Marthie Grobler |
WISE (2) | 7 |
| 2020 | Blockchain for secure location verification
Mohammad Reza Nosouhi, Shui Yu 0001, Wanlei Zhou 0001, Marthie Grobler, Habiba Keshtiar |
J. Parallel Distributed Comput. | 4 |
| 2020 | PASPORT: A Secure and Private Location Proof Generation and Verification FrameworkabstractRecently, there has been a rapid growth in location-based systems and applications in which users submit their location information to service providers in order to gain access to a service, resource, or reward. We have seen that in these applications, dishonest users have an incentive to cheat on their location. Unfortunately, no effective protection mechanism has been adopted by service providers against these fake location submissions. This is a critical issue that causes severe consequences for these applications. Motivated by this, we propose the Privacy-Aware and Secure Proof Of pRoximiTy (PASPORT) scheme in this article to address the problem. Using PASPORT, users submit a location proof (LP) to service providers to prove that their submitted location is true. PASPORT has a decentralized architecture designed for ad hoc scenarios in which mobile users can act as witnesses and generate LPs for each other. It provides user privacy protection as well as security properties, such as unforgeability and nontransferability of LPs. Furthermore, the PASPORT scheme is resilient to prover-prover collusions and significantly reduces the success probability of Prover-Witness collusion attacks. To further make the proximity checking process private, we propose P-TREAD, a privacy-aware distance bounding protocol and integrate it into PASPORT. To validate our model, we implement a prototype of the proposed scheme on the Android platform. Extensive experiments indicate that the proposed method can efficiently protect location-based applications against fake submissions. Mohammad Reza Nosouhi, Keshav Sood, Shui Yu 0001, Marthie Grobler |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2019 | A Dynamic Cross-Domain Access Control Model for Collaborative Healthcare Application
Ahmad Salehi S., Carsten Rudolph, Marthie Grobler |
IM | 3 |
| 2019 | Catering to Your Concerns: Automatic Generation of Personalised Security-Centric Descriptions for Android AppsabstractAndroid users are increasingly concerned with the privacy of their data and security of their devices. To improve the security awareness of users, recent automatic techniques produce security-centric descriptions by performing program analysis. However, the generated text does not always address users’ concerns as they are generally too technical to be understood by ordinary users. Moreover, different users have varied linguistic preferences that do not match the text. Motivated by this challenge, we develop an innovative scheme to help users avoid malware and privacy-breaching apps by generating security descriptions that explain the privacy and security related aspects of an Android app in clear and understandable terms. We implement a prototype system, PERSCRIPTION, to generate personalised security-centric descriptions that automatically learn users’ security concerns and linguistic preferences to produce user-oriented descriptions. We evaluate our scheme through experiments and user studies. The results clearly demonstrate the improvement on readability and users’ security awareness of PERSCRIPTION’s descriptions compared to existing description generators. Tingmin Wu, Lihong Tang, Rongjunchen Zhang, Sheng Wen, Cécile Paris, Surya Nepal, Marthie Grobler, Yang Xiang 0001 |
ACM Trans. Cyber Phys. Syst. | 7 |
| 2019 | Will They Use It or Not? Investigating Software Developers' Intention to Follow Privacy Engineering MethodologiesabstractWith the increasing concerns over privacy in software systems, there is a growing enthusiasm to develop methods to support the development of privacy aware software systems. Inadequate privacy in software system designs could result in users losing their sensitive data, such as health information and financial information, which may cause financial and reputation loss. Privacy Engineering Methodologies (PEMs) are introduced into the software development processes with the goal of guiding software developers to embed privacy into the systems they design. However, for PEMs to be successful it is imperative that software developers have a positive intention to use PEMs. Otherwise, developers may attempt to bypass the privacy methodologies or use them partially and hence develop software systems that may not protect user privacy appropriately. To investigate the factors that affect software developers’ behavioural intention to follow PEMs, in this article, we conducted a study with 149 software developers. Findings of the study show that the usefulness of the PEM to the developers’ existing work to be the strongest determinant that affects software developers’ intention to follow PEMs. Moreover, the compatibility of the PEM with their way of work and how the PEM demonstrates its results when used were also found to be significant. These findings provide important insights in understanding the behaviour of software developers and how they perceive PEMs. The findings could be used to assist organisations and researchers to deploy PEMs and design PEMs that are positively accepted by software developers. Awanthika Senarath, Marthie Grobler, Nalin Arachchilage |
ACM Trans. Priv. Secur. | 2 |
| 2018 | SPARSE: Privacy-Aware and Collusion Resistant Location Proof Generation and VerificationabstractRecently, there has been an increase in the number of location-based services and applications. It is common for these applications to provide facilities or rewards for users who visit specific venues frequently. This creates the incentive for dishonest users to lie about their location and submit fake check-ins by changing their GPS data. To solve this issue, different distributed location proof schemes have been proposed to generate location proofs for mobile users. However, these schemes have some drawbacks: (1) they are vulnerable to either Prover-Prover or Prover-Witness collusions, (2) the location proof generation process is slow when users adopt a long private key, and (3) their implementation requires some hardware changes on mobile devices. To address these issues, we propose the Secure, Privacy-Aware and collusion Resistant poSition vErification (SPARSE) scheme to generate private location proofs for mobile users. SPARSE has a distributed architecture designed for ad-hoc scenarios in which mobile users generate location proofs for each other. Since we do not integrate any distance bounding protocol into SPARSE, it becomes an easy-to-implement scheme in which the location proof generation process is independent of the length of the users' private key. We provide a comprehensive security analysis and simulation which show that SPARSE provides privacy protection as well as security properties for users including integrity, unforgeability and non-transferability of the location proofs. Moreover, it achieves a highly reliable performance against collusions. Mohammad Reza Nosouhi, Shui Yu 0001, Marthie Grobler, Yong Xiang 0001, Zuqing Zhu |
GLOBECOM | 3 |
| 2017 | My Face is Mine: Fighting Unpermitted Tagging on Personal/Group Photos in Social Media
Lihong Tang, Wanlun Ma, Sheng Wen, Marthie Grobler, Yang Xiang 0001, Wanlei Zhou 0001 |
WISE (2) | 4 |
| 2017 | A general morphological analysis: delineating a cyber-security cultureabstractPurpose The purpose of this paper is to define and delineate cyber security culture. Cyber security has been a concern for many years. In an effort to mitigate the cyber security risks, technology-centred measures were deemed to be the ultimate solution. Nowadays, however, it is accepted that the process of cyber security requires much more than mere technical controls. On the contrary, it now demands a human-centred approach, including a cyber security culture. Although the role of cultivating a culture in pursuing cyber security is well appreciated, research focusing intensely on cyber security culture is still in its infancy. Additionally, knowledge on the subject is not clearly bounded and defined. Design/methodology/approach General morphological analysis (GMA) is used to define, structure and analyse the cyber security environment culture. Findings This paper identifies the most important variables in cultivating a cyber security culture. Research implications The delineation of the national cyber security domain will contribute to the relatively new domain of cyber security culture. They contribute to the research community by means of promoting a shared and common understanding of terms. It is a step in the right direction towards eliminating the ambiguity of domain assumptions. Practical implications Practically, the study can assist developing nations in constructing strategies that addresses the key factors that need to be apparent in lieu to cultivating its envisaged national culture of cyber security. Additionally, the GMA will contribute to the development of solutions or means that do not overlook interrelations of such factors. Originality/value Delineating and defining the cyber security culture domain more precisely could greatly contribute to realizing the elements that collectively play a role in cultivating such a culture for a national perspective. Noluxolo Gcaza, Rossouw von Solms, Marthie Grobler, Joey Jansen van Vuuren |
Inf. Comput. Secur. | 3 |