Simon Parkinson

dblp:03/6831 · DBLP profile ↗
← Back
30ranked-venue papers
10as first author
14since 2021 · last 2026
0000-0002-1747-9914ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 11 · 4 first-author · 5 since 2021Security and privacy · 8 · 4 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1
YearPublicationVenuePosition
2026 STSRS: A New Dataset for Simulating Security Threats in Smart Railway Systems
Mays Abukeshek, Mohammed Al-Mhiqani, Simon Parkinson
ICISSP (1)3
2026 Assessing the Impact of Cyber Attacks on Traffic Flow with Mixed Autonomous and Human-Driven Vehicles
abstract
With the advancement of vehicular technology, autonomous vehicles (AVs) are going to share roads with human-driven vehicles (HDVs), introducing increased connectivity and new substantial attack surfaces, making the transport system vulnerable to exploitation. Through extensive simulations using the Berlin scenario in Eclipse MOSAIC, in this paper, we investigate the effects a range of cyber attacks, such as communication attacks like sybil and spoofing on vehicle to infrastructure (V2I) and vehicle to vehicle (V2V), and other attacks such as vehicle sabotage and road side unit (RSU) attacks, to effect the traffic flow using mean values from multiple simulations for analysis. Our investigation demonstrates that certain cyber attacks have a paramount effect on the flow of traffic, with the potential to result in complete road blockages during peak hours traffic.
Christian Wellens-Miles, Simon Parkinson, Mauro Vallati
IV2
2026 Graph-based detection of multi-step attacks using graph convolutional networks
abstract
Multi-step attacks, including advanced persistent threats (APT), distributed denial of service (DDoS) and botnets, are still among the most sophisticated threats that modern organisations are experiencing today. Most traditional methods of detecting these threats have difficulties identifying unknown types of events from unknown sources. In this study, we introduce a reproducible GCN-based event-log correlation framework for Multi-step attack detection. In this work, we replicated GC-PTransE for APT reasoning (Phase-1), then extended GC-PTransE into practical lightweight variants for DDoS and Botnet detection (Phase-3) using a common PyG graph interface. Our models demonstrated significant improvements over all categories of attacks. Using the CICIDS2017 (DDoS) dataset, our model achieved 98% accuracy, 100% precision, and 94% recall. With the CTU-13 (Botnet) dataset, GETrans++ achieved 98% accuracy, 100% precision, and 47% recall. The 72% APT-relevance hit rate from our Phase 1 replication demonstrates that GCN can be deployed, providing good efficiency. Finally, by using neighbourhood batching, we avoided the need to store entire graphs in memory, thereby allowing for deployments on commodity CPU/GPU architectures. Limitations of this study included the class imbalance in enterprise logs (Phase 2) and the lack of heterogeneous operational datasets, both of which were identified as areas for future study.
Syed Usman Shaukat, Saad Khan 0001, Simon Parkinson
J. Inf. Secur. Appl.3
2025 Computational Measures of Gaze Behavior Using the Concept of Situational Awareness
abstract
Eye gaze is fundamental to common sensorimotor activities. It directly indicates attention and its allocation, making it a critical human factor that reflects cognitive behavior. Data-driven measurements of gaze behavior quantitatively evaluate the allocation of visual attention, indicating the mental and physical activity status of individuals. Situational awareness provides a solid and semantically rich basis for gaze behavior during sensorimotor activities. However, few attempts have been made so far to measure eye gaze data from the perspective of situational awareness. In this paper, we propose four new computational measures of gaze behavior that align with the fundamental concept of situational awareness, effectively measuring the efficiency of visual scanning and sensorimotor activity. Our results have clearly shown that the proposed measures are effective and perform satisfactorily compared to the closely related methods. This work offers a new data-driven approach for biomarker discovery and behavioral biometrics using eye gaze data.
Yunxiang Jiang, Qing Xu 0002, Aoxing Xu, Simon Parkinson, Klaus Schöffmann, Chuntie Chen
ICME4
2025 Characterizing High-order Interactions between Eye Movement and Head Motion Variables in Augmented Reality-based Navigation Experience
abstract
The coordination of eye and head in visual scanning is a fundamental behavior of humans in everyday sensorimotor activities such as walking and navigation. Deep understanding of the spatiotemporal dynamics of this coordination behavior undoubtedly plays an important role for many fields. However, relatively little is known about the computational and high-order interactions between eye and head in visual scanning during sensorimotor tasks. In this paper, based on the utilization of a recent tool from information theory, Partial Information Decomposition (PID), we quantify high-order components, namely uniqueness, redundancy, and synergy, in spatiotemporal interactions between eye movement and head motion time-series data during augmented reality-based navigation experience. To our knowledge, this is the first data-driven approach that leverages an information-theoretic tool to characterize high-order interactions involved in eye-head coordination during sensorimotor activities.
Qing Xu 0002, Shunbo Wang, Yunxiang Jiang, Simon Parkinson, Klaus Schöffmann, Chuntie Chen
ICME4
2025 A survey of deep learning for face presentation attack detection
abstract
Face anti-spoofing detection (FASD) has become a crucial technology due to the alarming advancements in presentation attacks (PAs). As more novel PAs with realistic generative capabilities emerge, improved biometric security solutions are needed to address these evolving threats. In early and foundational work, FASD techniques focused mainly on handcrafted features that were unreliable due to their limited representation capacity. In the recent decade, with the advancements in deep learning and its capabilities for image processing tasks and the emergence of large datasets, improvements in the performance of detecting PAs have been achieved. However, as research progresses rapidly, there is an absence of a comprehensive analysis of detection methods to understand the strengths and weaknesses of different types of approaches. Although various approaches utilise sensors in addition to RGB cameras, in this paper, we focus specifically on RGB camera-based methods and provide a comprehensive review of deep learning-based FASDs, including generalised models developed to date. In addition, the datasets are presented, along with the evaluation protocols and metrics. • This article provides an extensive analysis of deep learning-based approaches in the spatial domain, along with a focused review of frequency domain generalisation methods. • This paper covers the application of GANs for FASD, together with semi-supervised and self-supervised learning methods. Therefore, it provides the reader with state-of-the-art methods for different application scenarios (e.g., unseen domain generalisation and unknown attack detection). • The taxonomy of deep learning-based FASD methods using RGB cameras provides readers with an overview of modern approaches. • The strengths and weaknesses of existing models have also been explored and summarised, providing an overview of their capabilities and limitations.
Mohammadreza Sheikh Fathollahi, Simon Parkinson, Richard Hill, Saad Khan 0001
Neurocomputing2
2025 A Systematic Literature Review of Simulated Cyber Attacks on Vehicles and Urban Traffic Control
abstract
This article presents a comprehensive study on the simulation of cyber-attacks and potential countermeasures within Urban Traffic Control (UTC) systems. The growing complexity of UTC systems, aimed at improving traffic efficiency, safety, and exploiting connectivity and autonomous capabilities, is leading to increased attack surfaces and vulnerabilities. The potential to exploit these vulnerabilities to adversely affect the system and its users makes them a desirable target, hence the need to increase understanding of the impact coming from security incidents. There is a large volume of research investigating focused attacks and their mitigation in UTC systems; however, there is an absence of understanding of this body of knowledge, identifying challenges and unaddressed areas. To address this gap, this study analyses simulations of attacks against UTC components and connected vehicles, incorporating current mitigation strategies published in recent literature. It discusses the implications of these vulnerabilities for public safety and traffic management, proposing future research directions to address the identified challenges. Six prevalent challenges are identified in the field, emphasising the importance of up-to-date simulations for reliable integration into real-time systems. The findings aim to strengthen UTC systems against cyber threats, contributing to the overarching goal of safeguarding lives and optimising urban traffic flow.
Christian Wellens-Miles, Rongge Guo, Simon Parkinson, Mauro Vallati
IEEE Trans. Intell. Transp. Syst.4
2024 Exploring perceptions of decision-makers and specialists in defensive machine learning cybersecurity applications: The need for a standardised approach
abstract
Machine learning (ML) utilisation has achieved a vast global impact. This is evident in the cybersecurity sector, where ML has wide-ranging applications, such as identifying and blocking threats, uncovering unusual software and user behaviour, and many others. However, the increase in successful cyberattacks demonstrates that the effectiveness of ML in cybersecurity applications can be questioned. Although the attacks may be new, ML is often adopted due to its ability to handle diverse and often unforeseen situations – a capability that is not possible using traditional rule-based security mechanisms. As both the rate of attacks and adoption of ML solutions are increasing, there is a need to determine whether ML-based security solutions are meeting the expectations of businesses and whether businesses are genuinely aware of the ML capabilities and limitations. Moreover, current literature shows a significant variation in how ML solutions are evaluated in cybersecurity applications, which might result in a poor understanding of ML capabilities. This paper explores the common perceptions and observations of decision-makers and specialists using ML for cybersecurity regarding its capabilities, implementation, evaluation, and communication. A semi-structured interview is conducted with individuals in various managerial positions to perform this investigation. The finding of this study reveals a pressing need for a standard to manifest ML capabilities. As significant variation in the understanding of Machine Learning Cyber Security (MLCS) capabilities is observed, a standard could help better communicate MLCS capabilities. It is observed that external influences heavily impact ML adoption decisions, potentially leading to misinterpretation of ML capabilities.
Omar Alshaikh, Simon Parkinson, Saad Khan 0001
Comput. Secur.2
2023 Context-based irregular activity detection in event logs for forensic investigations: An itemset mining approach
abstract
Event logs are a powerful source of digital evidence as they contain detailed information about activities performed on a computer. Forensic investigation of the event logs is a challenging and time-consuming task due to their large volume and continuous generation. A significant amount of time, effort, and knowledge is required to interpret their contents, discovering irregular events that are potentially pertinent to the investigation. As the number of digital investigations increases, so too must resources available to investigators. This requires new techniques to make the process easier and faster, reducing the burden on human investigators as well as being resource efficient. In this paper, a novel solution is presented to examine event logs and automatically identify irregular activities during forensic analysis. The proposed solution utilises a rare itemset mining approach to establish relationships among event entries, based on their contents. Following on, identified event relationships are ordered based on their temporal order to represent the timeline or sequence of activity. The solution is also capable of prioritising identified activities by calculating their degree of irregularity. The empirical analysis is performed on 15 live machines, and the results are discussed in terms of accuracy and performance metrics.
Saad Khan 0001, Simon Parkinson, Craig Murphy
Expert Syst. Appl.2
2022 Identifying high-risk over-entitlement in access control policies using fuzzy logic
abstract
Abstract Analysing access control policies is an essential process for ensuring over-prescribed permissions are identified and removed. This is a time-consuming and knowledge-intensive process, largely because there is a wealth of policy information that needs to be manually examined. Furthermore, there is no standard definition of what constitutes an over-entitled permission within an organisation’s access control policy, making it not possible to develop automated rule-based approaches. It is often the case that over-entitled permissions are subjective to an organisation’s role-based structure, where access is be divided and managed based on different employee needs. In this context, an irregular permission could be one where an employee has frequently changed roles, thus accumulating a wide-ranging set of permissions. There is no one size fits all approach to identifying permissions where an employee is receiving more permission than is necessary, and it is necessary to examine them in the context of the organisation to establish their individual risk. Risk is not a binary measure and, in this work, an approach is built using Fuzzy Logic to determine an overall risk rating, which can then be used to make a more informed decision as to whether a user is over-entitled and presenting risk to the organisation. This requires the exploratory use of establishing resource sensitivity and user trust as measures to determine a risk rating. The paper presents a generic solution, which has been implemented to perform experimental analysis on Microsoft’s New Technology File System to show how this works in practice. A simulation using expert knowledge for comparison is then performed to demonstrate how effective it is at helping the user identify potential irregular permissions.
Simon Parkinson, Saad Khan 0001
Cybersecur.1
2022 Robust data expansion for optimised modelling using adaptive neuro-fuzzy inference systems
abstract
This work focuses on the problem of constructing accurate prediction models using an adaptive neuro-fuzzy inference system (ANFIS) from data that are scarce and poorly scaled. Many real-world problems have limited data to work with and yet require models with high prediction accuracy. Due to the fuzzy nature of many data sets, it is appropriate to construct prediction models using fuzzy inference systems (FIS), rather than traditional artificial neural network (ANN) models. However, the scarcity of the data raises serious concerns when attempting to construct models of this type. In this paper, we address the problem of constructing accurate prediction models using ANFIS in circumstances where capturing large amounts of data is difficult. We propose a new approach, using robust data expansion methods to enhance the data carefully. This approach provides the learning algorithm with enough representative data to allow all of the parameters (premise and consequent) to be optimised. We compare and contrast the effectiveness in reducing prediction error for three specific expansion models using radial basis function (RBF) kernels. When expanding data, for which the underlying smoothness properties are not known, there is often a danger of over-smoothing. This is usually noticeable at turning points and can occur when fitting the data using polynomials or cubic splines for example. To avoid over-smoothing, we introduce a modified multiquadric approach that allows smooth, near-interpolation while maintaining the desirable shape-preserving properties of the data. The proposed method is explained through two case studies — the first to predict gasoline consumption for the oil/fuel industry in Iraq and the second for predicting natural gas consumption in Iran. This is the first study that uses adjustable, shape-preserving re-sampling methods for optimising ANFIS models in low data environments.
Samer Mohammed Jaber Mubarak, Andrew Crampton, Jennifer Carter, Simon Parkinson
Expert Syst. Appl.4
2021 A Jensen-Shannon Divergence Driven Metric of Visual Scanning Efficiency Indicates Performance of Virtual Driving
abstract
Visual scanning plays an important role in sampling visual information from the surrounding environments for a lot of everyday sensorimotor tasks, such as driving. In this paper, we consider the problem of visual scanning mechanism underpinning sensorimotor tasks in 3D dynamic environments. We exploit the use of eye tracking data as a behaviometric, for indicating the visuo-motor behavioral measure in the context of virtual driving. A new metric of visual scanning efficiency (VSE), which is defined as a mathematical divergence between a fixation distribution and a distribution of optical flows induced by fixations, is proposed by making use of a widely-known information theoretic tool, namely the square root of Jensen-Shannon divergence. Psychophysical eye tracking studies, in virtual reality based driving, are conducted to reveal that the new metric of visual scanning efficiency can be employed very well as a proxy evaluation for driving performance. These results suggest that the exploitation of eye tracking data provides an effective behaviometric for sensorimotor activities.
Zezhong Lv, Qing Xu 0002, Klaus Schöffmann, Simon Parkinson
ICME4
2021 OCEAN: A Non-Conventional Parameter Free Clustering Algorithm Using Relative Densities of Categories
abstract
In this paper, we propose a fully autonomous density-based clustering algorithm named ‘Ocean’, which is inspired by the oceanic landscape and phenomena that occur in it. Ocean is an improvement over conventional algorithms regarding both distance metric and the clustering mechanism. Ocean defines the distance between two categories as the difference in the relative densities of categories. Unlike existing approaches, Ocean neither assigns the same distance to all pairs of categories, nor assigns arbitrary weights to matches and mismatches between categories that can lead to clustering errors. Ocean uses density ratios of adjacent regions in multidimensional space to detect the edges of the clusters. Ocean is robust against clusters of identical patterns. Unlike conventional approaches, Ocean neither makes any assumption regarding the data distribution within clusters, nor requires tuning of free parameters. Empirical evaluations demonstrate improved performance of Ocean over existing approaches.
Iffat Gheyas, Simon Parkinson, Saad Khan 0001
Int. J. Pattern Recognit. Artif. Intell.2
2021 Analysis of security and privacy challenges for DNA-genomics applications and databases
Saadia Arshad, Junaid Arshad, Muhammad Mubashir Khan, Simon Parkinson
J. Biomed. Informatics4
2019 Classifying Ransomware Using Machine Learning Algorithms
Samuel Egunjobi, Simon Parkinson, Andrew Crampton
IDEAL (2)2
2019 Creeper: a tool for detecting permission creep in file system access controls
abstract
Access control mechanisms are widely used in multi-user IT systems where it is necessary to restrict access to computing resources. This is certainly true of file systems whereby information needs to be protected against unintended access. User permissions often evolve over time, and changes are often made in an ad hoc manner and do not follow any rigorous process. This is largely due to the fact that the structure of the implemented permissions are often determined by experts during initial system configuration and documentation is rarely created. Furthermore, permissions are often not audited due to the volume of information, the requirement of expert knowledge, and the time required to perform manual analysis. This paper presents a novel, unsupervised technique whereby a statistical analysis technique is developed and applied to detect instances of permission creep. The system (herein refereed to as Creeper) has initially been developed for Microsoft systems; however, it is easily extensible and can be applied to other access control systems. Experimental analysis has demonstrated good performance and applicability on synthetic file system permissions with an average accuracy of 96%. Empirical analysis is subsequently performed on five real-world systems where an average accuracy of 98% is established.
Simon Parkinson, Saad Khan 0001, James Bray, Daiyaan Shreef
Cybersecur.1
2019 TrustVote: Privacy-Preserving Node Ranking in Vehicular Networks
abstract
The Internet of Vehicles is the network of connected vehicles and transport infrastructure units [roadside units (RSUs)], which utilizes emerging wireless systems (4G, 5G, LTE) for the communication and sharing of information. The network of connected vehicles enables users to disseminate critical information about events happening on the road (for example, accidents, traffic congestions, and hazards). The exchange of information between vehicles and RSUs could improve the driving experience and road safety, as well as help drivers to identify the hazardous and safe routes in a timely manner. The sharing of critical information between vehicles is advantageous to the driver; however, at the same time, malicious actors could mislead drivers by spreading fraudulent and fake messages. Fraudulent messages can have a negative impact on the infrastructure, and more significantly, have potential to cause threats to life. It is, therefore, essential that vehicles can evaluate the credibility of those who send messages (vehicles or RSUs) before taking any action. In this paper, we present TrustVote, a collaborative crowdsourcing-based vehicle reputation system that enables vehicles to evaluate the credibility of other vehicles in a connected vehicular network. The TrustVote system allows participating vehicles to hide their rating/feedback scores and the list of interacted vehicles under a homomorphic cryptographic layer, which can only be unfolded as an aggregate. The proposed approach also considers the trust weight of a vehicle providing the rating scores while computing the aggregate reputation of the vehicles. A prototype of TrustVote is developed and its performance is evaluated in terms of the computational and communication overheads.
Muhammad Ajmal Azad, Samiran Bag, Simon Parkinson, Feng Hao 0001
IEEE Internet Things J.3
2019 Discovering and utilising expert knowledge from security event logs
Saad Khan 0001, Simon Parkinson
J. Inf. Secur. Appl.2
2018 GraphBAD: A general technique for anomaly detection in security information and event management
abstract
Summary The reliance on expert knowledge—required for analysing security logs and performing security audits—has created an unhealthy balance, where many computer users are not able to correctly audit their security configurations and react to potential security threats. The decreasing cost of IT and the increasing use of technology in domestic life are exacerbating this problem, where small companies and home IT users are not able to afford the price of experts for auditing their system configuration. In this paper, we present GraphBAD, a graph‐based analysis tool that is able to analyse security configurations in order to identify anomalies that could lead to potential security risks. GraphBAD, which does not require any prior domain knowledge, generates graph‐based models from security configuration data and, by analysing such models, is able to propose mitigation plans that can help computer users in increasing the security of their systems. A large experimental analysis, conducted on both publicly available (the well‐known KDD dataset) and synthetically generated testing sets (file system permissions), demonstrates the ability of GraphBAD in correctly identifying security configuration anomalies and suggesting appropriate mitigation plans.
Simon Parkinson, Mauro Vallati, Andrew Crampton, Shirin Sohrabi
Concurr. Comput. Pract. Exp.1
2018 Eliciting and utilising knowledge for security event log analysis: An association rule mining and automated planning approach
Saad Khan 0001, Simon Parkinson
Expert Syst. Appl.2
2018 Identifying irregularities in security event logs through an object-based Chi-squared test of independence
Simon Parkinson, Saad Khan 0001
J. Inf. Secur. Appl.1
2017 Edge Influence Computation in Dynamic Graphs
Yongrui Qin, Quan Z. Sheng, Simon Parkinson, Nick Falkner
DASFAA (2)3
2017 Causal Connections Mining Within Security Event Logs
abstract
Performing both security vulnerability assessment and configuration processes are heavily reliant on expert knowledge. This requirement often results in many systems being left insecure due to a lack of analysis expertise and access to specialist resources. It has long been known that a system's event log provides historical information depicting potential security threats, as well as recording configuration activities. In this paper, a novel technique is developed that can process security event logs on a computer that has been assessed and configured by a security professional, and autonomously establish causality amongst event log entries to learn performed configuration tasks. This extracted knowledge can then be exploited by non-professionals to plan steps that can improve the security of a previously unseen system.
Saad Khan 0001, Simon Parkinson
K-CAP2
2017 Cyber Threats Facing Autonomous and Connected Vehicles: Future Challenges
abstract
Vehicles are currently being developed and sold with increasing levels of connectivity and automation. As with all networked computing devices, increased connectivity often results in a heightened risk of a cyber security attack. Furthermore, increased automation exacerbates any risk by increasing the opportunities for the adversary to implement a successful attack. In this paper, a large volume of publicly accessible literature is reviewed and compartmentalized based on the vulnerabilities identified and mitigation techniques developed. This review highlighted that the majority of studies are reactive and vulnerabilities are often discovered by friendly adversaries (white-hat hackers). Many gaps in the knowledge base were identified. Priority should be given to address these knowledge gaps to minimize future cyber security risks in the connected and autonomous vehicle sector.
Simon Parkinson, Paul Ward, Kyle M. Wilson, Jonathan Miller 0006
IEEE Trans. Intell. Transp. Syst.1
2017 Efficient computation of distance labeling for decremental updates in large dynamic graphs
Yongrui Qin, Quan Z. Sheng, Nick Falkner, Lina Yao 0001, Simon Parkinson
World Wide Web5
2016 Auditing file system permissions using association rule mining
Simon Parkinson, Vassiliki Somaraki, R. Ward
Expert Syst. Appl.1
2016 Identification of irregularities and allocation suggestion of relative file system permissions
Simon Parkinson, Andrew Crampton
J. Inf. Secur. Appl.1
2015 Multi-objective optimisation of machine tool error mapping using automated planning
abstract
Error mapping of machine tools is a multi-measurement task that is planned based on expert knowledge. There are no intelligent tools aiding the production of optimal measurement plans. In previous work, a method of intelligently constructing measurement plans demonstrated that it is feasible to optimise the plans either to reduce machine tool downtime or the estimated uncertainty of measurement due to the plan schedule. However, production scheduling and a continuously changing environment can impose conflicting constraints on downtime and the uncertainty of measurement. In this paper, the use of the produced measurement model to minimise machine tool downtime, the uncertainty of measurement and the arithmetic mean of both is investigated and discussed through the use of twelve different error mapping instances. The multi-objective search plans on average have a 3% reduction in the time metric when compared to the downtime of the uncertainty optimised plan and a 23% improvement in estimated uncertainty of measurement metric when compared to the uncertainty of the temporally optimised plan. Further experiments on a High Performance Computing (HPC) architecture demonstrated that there is on average a 3% improvement in optimality when compared with the experiments performed on the PC architecture. This demonstrates that even though a 4% improvement is beneficial, in most applications a standard PC architecture will result in valid error mapping plan.
Simon Parkinson, Andrew Longstaff
Expert Syst. Appl.1
2014 Automated planning to minimise uncertainty of machine tool calibration
Simon Parkinson, Andrew Longstaff, Simon Fletcher
Eng. Appl. Artif. Intell.1
2012 Automatic planning for machine tool calibration: A case study
Simon Parkinson, Andrew Longstaff, Simon Fletcher, Andrew Crampton, Peter Gregory
Expert Syst. Appl.1