EDBT 2026 Demo / reviewers in the wild / expert
Alexios Mylonas
dblp:12/8421
· DBLP profile ↗
25ranked-venue papers
7as first author
6since 2021 · last 2026
0000-0001-8819-5831ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 7 first-author · 5 since 2021Computer networks · 3 · 1 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Causality aware explainable deep reinforcement learning with adaptive attention mechanisms for scalable resource orchestration in 6G wireless networks
Salman Khan 0007, Woong-Kee Loh, Hamid Ullah, Javed Ali Khan, Alexios Mylonas |
Comput. Networks | 5 |
| 2025 | MIDAS: Multi-layered attack detection architecture with decision optimisationabstractThe proliferation of cyber attacks has led to the use of data-driven detection countermeasures, in an effort to mitigate this threat. Machine learning techniques, such as the use of neural networks, have become mainstream and proven effective in attack detection. However, these data-driven solutions are limited by: a) high computational overhead associated with data pre-processing and inference cost, b) inability to scale beyond a centralised deployment to cope with environmental variances, and c) requirement to use multiple bespoke detection models for effective attack detection coverage across the cyber kill chain. In this context, this paper introduces MIDAS, a cost-effective framework for attack detection, which introduces a dynamic decision boundary that is used in a multi-layered detection architecture. This is achieved by modelling the decision confidence of the participating detection models and judging its benefits using a novel reward policy. Specifically, a reward is assigned to a set of available actions, corresponding to a decision boundary, based on its cost-to-performance, where an overall cost-saving is prioritised. We evaluate our approach on two widely used datasets representing two of the most common threats today, i.e., phishing and malware. MIDAS shows that it effectively reduces the expenditure on detection inference and processing costs by controlling the frequency of expensive detection operations. This is achieved without significant sacrifice of attack detection performance. Kieran Rendall, Alexios Mylonas, Stilianos Vidalis, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2024 | Malicious Insider Threat Detection Using Sentiment Analysis of Social Media Topics
Matt Kenny, Nikolaos Pitropakis, Sarwar Sayeed, Christos Chrysoulas, Alexios Mylonas |
SEC | 5 |
| 2024 | Smart homes under siege: Assessing the robustness of physical security against wireless network attacksabstractNowadays domestic smart security devices, such as smart locks, smart doorbells, and security cameras, are becoming increasingly popular with users, due to their ease of use, convenience, and declining prices. Unlike conventional non-smart security devices, such as alarms and locks, performance standards for smart security devices, such as the British TS 621, are not easily understandable by end users due to the technical language employed. Users also have very few sources of unbiased information regarding product performance in real world conditions and protection against attacks from cyber attacker-burglars and, as a result, tend to take manufacturer claims at face value. This means that, as this work proves, users may be exposed to threats, such as theft, impersonation (should an attacker steal their credentials), and even physical injury, if the device fails and is used to prevent access to hazardous environments. As such, this paper deploys several attacks using popular wireless attack vectors (i.e., 433MHz radio, Bluetooth, and RFID) against domestic smart security devices to assess the protection offered against a cyber attacker-burglar. Our results suggest that users are open to considerable cyber physical attacks, irrespective if they use lesser known (i.e., no name) or branded smart security devices, due to the poor security offered by these devices. Ashley Allen, Alexios Mylonas, Stilianos Vidalis, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2022 | Investigating machine learning attacks on financial time series modelsabstractMachine learning and Artificial Intelligence (AI) already support human decision-making and complement professional roles, and are expected in the future to be sufficiently trusted to make autonomous decisions. To trust AI systems with such tasks, a high degree of confidence in their behaviour is needed. However, such systems can make drastically different decisions if the input data is modified, in a way that would be imperceptible to humans. The field of Adversarial Machine Learning studies how this feature could be exploited by an attacker and the countermeasures to defend against them. This work examines the Fast Gradient Signed Method (FGSM) attack, a novel Single Value attack and the Label Flip attack on a trending architecture, namely a 1-Dimensional Convolutional Neural Network model used for time series classification. The results show that the architecture was susceptible to these attacks and that, in their face, the classifier accuracy was significantly impacted. Michael Gallagher, Nikolaos Pitropakis, Christos Chrysoulas, Pavlos Papadopoulos, Alexios Mylonas, Sokratis K. Katsikas |
Comput. Secur. | 5 |
| 2021 | Use-Case Informed Task Analysis for Secure and Usable Design Solutions in Rail
Amna Altaf, Shamal Faily, Huseyin Dogan, Alexios Mylonas, Eylem Thron |
CRITIS | 4 |
| 2020 | Known unknowns: Indeterminacy in authentication in IoT
Alexios Mylonas, Vahid Heydari Fami Tafreshi, Elhadj Benkhelifa, Surjit Singh |
Future Gener. Comput. Syst. | 2 |
| 2020 | R2BN: An Adaptive Model for Keystroke-Dynamics-Based Educational Level ClassificationabstractOver the past decade, keystroke-based pattern recognition techniques, as a forensic tool for behavioral biometrics, have gained increasing attention. Although a number of machine learning-based approaches have been proposed, they are limited in terms of their capability to recognize and profile a set of an individual's characteristics. In addition, up to today, their focus was primarily gender and age, which seem to be more appropriate for commercial applications (such as developing commercial software), leaving out from research other characteristics, such as the educational level. Educational level is an acquired user characteristic, which can improve targeted advertising, as well as provide valuable information in a digital forensic investigation, when it is known. In this context, this paper proposes a novel machine learning model, the randomized radial basis function network, which recognizes and profiles the educational level of an individual who stands behind the keyboard. The performance of the proposed model is evaluated by using the empirical data obtained by recording volunteers' keystrokes during their daily usage of a computer. Its performance is also compared with other well-referenced machine learning models using our keystroke dynamic datasets. Although the proposed model achieves high accuracy in educational level prediction of an unknown user, it suffers from high computational cost. For this reason, we examine ways to reduce the time that is needed to build our model, including the use of a novel data condensation method, and discuss the tradeoff between an accurate and a fast prediction. To the best of our knowledge, this is the first model in the literature that predicts the educational level of an individual based on the keystroke dynamics information only. Ioannis Tsimperidis, Paul D. Yoo, Kamal Taha, Alexios Mylonas, Vasilios Katos |
IEEE Trans. Cybern. | 4 |
| 2017 | You can run but you cannot hide from memory: Extracting IM evidence of Android appsabstractSmartphones have become a vital part of our business and everyday life, as they constitute the primary communication vector. Android dominates the smartphone market (86.2%) and has become pervasive, running in `smart' devices such as tablets, TV, watches, etc. Nowadays, instant messaging applications have become popular amongst smartphone users and since 2016 are the main way of messaging communication. Consequently, their inclusion in any forensics analysis is necessary as they constitute a source of valuable data, which might be used as (admissible) evidence. Often, their examination involves the extraction and analysis of the applications' databases that reside in the device's internal or external memory. The downfall of this method is the fact that databases can be tampered or erased, therefore the evidence might be accidentally or maliciously modified. In this paper, a methodology for retrieving instant messaging data from the volatile memory of Android smartphones is proposed, instead of the traditional database retrieval. The methodology is demonstrated with the use of a case study of four experiments, which provide insights regarding the behavior of such data in memory. Our experimental results show that a large amount of data can be retrieved from the memory, even if the device's battery is removed for a short time. In addition, the retrieved data are not only recent messages, but also messages sent a few months before data acquisition. Antonia Nisioti, Alexios Mylonas, Vasilios Katos, Paul D. Yoo, Anargyros Chryssanthou |
ISCC | 2 |
| 2017 | TRAWL: Protection against rogue sites for the massesabstractThe number of smartphones reached 3.4 billion in the third quarter of 2016 [1]. These devices facilitate our daily lives and have become the primary way of accessing the web. Although all desktop browsers filter rogue websites, their mobile counterparts often do not filter them at all, exposing their users to websites serving malware or hosting phishing attacks. In this paper we revisit the anti-phishing filtering mechanism which is offered in the most popular web browsers of Android, iOS and Windows Phone. Our results show that mobile users are still unprotected against phishing attacks, as most of the browsers are unable to filter phishing URLs. Thus, we implement and evaluate TRAWL (TRAnsparent Web protection for alL), as a cost effective security control that provides DNS and URL filtering using several blacklists. Antonia Nisioti, Alexios Mylonas, Vasilios Katos, Vahid Heydari Fami Tafreshi |
RCIS | 3 |
| 2017 | Exploring the protection of private browsing in desktop browsers
Nikolaos Tsalis, Alexios Mylonas, Antonia Nisioti, Dimitris Gritzalis, Vasilios Katos |
Comput. Secur. | 2 |
| 2016 | A study on usability and security features of the Android pattern lock screenabstractPurpose – The Android pattern lock screen (or graphical password) is a popular user authentication method that relies on the advantages provided by the visual representation of a password, which enhance its memorability. Graphical passwords are vulnerable to attacks (e.g. shoulder surfing); thus, the need for more complex passwords becomes apparent. This paper aims to focus on the features that constitute a usable and secure pattern and investigate the existence of heuristic and physical rules that possibly dictate the formation of a pattern. Design/methodology/approach – The authors conducted a survey to study the users’ understanding of the security and usability of the pattern lock screen. The authors developed an Android application that collects graphical passwords, by simulating user authentication in a mobile device. This avoids any potential bias that is introduced when the survey participants are not interacting with a mobile device while forming graphical passwords (e.g. in Web or hard-copy surveys). Findings – The findings verify and enrich previous knowledge for graphical passwords, namely, that users mostly prefer usability than security. Using the survey results, the authors demonstrate how biased input impairs security by shrinking the available password space. Research limitations/implications – The sample’s demographics may affect our findings. Therefore, future work can focus on the replication of our work in a sample with different demographics. Originality/value – The authors define metrics that measure the usability of a pattern (handedness, directionality and symmetry) and investigate their impact to its formation. The authors propose a security assessment scheme using features in a pattern (e.g. the existence of knight moves or overlapping nodes) to evaluate its security strengths. Panagiotis Andriotis, George C. Oikonomou, Alexios Mylonas, Theodore Tryfonas |
Inf. Comput. Secur. | 3 |
| 2015 | An Intensive Analysis of Security and Privacy Browser Add-Ons
Nikolaos Tsalis, Alexios Mylonas, Dimitris Gritzalis |
CRiSIS | 2 |
| 2015 | Security Busters: Web browser security vs. rogue sites
Nikos Virvilis, Alexios Mylonas, Nikolaos Tsalis, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2014 | Mobile Devices - A Phisher's ParadiseabstractMobile devices — especially smartphones — have gained widespread adoption in recent years, due to the plethora of features they offer. The use of such devices for web browsing and accessing email services is also getting continuously more popular. The same holds true with other more sensitive online activities, such as online shopping, contactless payments, and web banking. However, the security mechanisms that are available on smartphones and protect their users from threats on the web are not yet mature, as well as their effectiveness is still questionable. As a result, smartphone users face increased risks when performing sensitive online activities with their devices, compared to desktop/laptop users. In this paper, we present an evaluation of the phishing protection mechanisms that are available with the popular web browsers of Android and iOS. Then, we compare the protection they offer against their desktop counterparts, revealing and analyzing the significant gap between the two. Nikos Virvilis, Nikolaos Tsalis, Alexios Mylonas, Dimitris Gritzalis |
SECRYPT | 3 |
| 2013 | A Qualitative Metrics Vector for the Awareness of Smartphone Security Users
Alexios Mylonas, Dimitris Gritzalis, Bill Tsoumas, Theodore K. Apostolopoulos |
TrustBus | 1 |
| 2013 | Delegate the smartphone user? Security awareness in smartphone platforms
Alexios Mylonas, Anastasia Kastania, Dimitris Gritzalis |
Comput. Secur. | 1 |
| 2013 | Smartphone sensor data as digital evidence
Alexios Mylonas, Vasilis Meletiadis, Lilian Mitrou, Dimitris Gritzalis |
Comput. Secur. | 1 |
| 2012 | Smartphone Forensics: A Proactive Investigation Scheme for Evidence Acquisition
Alexios Mylonas, Vasilis Meletiadis, Bill Tsoumas, Lilian Mitrou, Dimitris Gritzalis |
SEC | 1 |
| 2012 | A Risk Assessment Method for Smartphones
Marianthi Theoharidou, Alexios Mylonas, Dimitris Gritzalis |
SEC | 2 |
| 2012 | Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software
Alexios Mylonas, Dimitris Gritzalis |
Comput. Secur. | 1 |
| 2011 | Exploitation of auctions for outsourcing security-critical projectsabstractICT outsourcing may introduce several risks. This paper attempts to mitigate this problem by applying an auctioning scheme. By adopting the scheme, the involved organization selects one or more potential outsourced service providers via an auction similar to the FCC spectrum ones. The project is divided in sub-projects, bidders are pre-evaluated, in terms of security and each bid is assessed in terms of cost and appropriate security metrics. The bidding process continues according to the auction rules allocating all the sub-projects to the best bidders. The ultimate goal is to achieve upgraded security, while keeping the cost at a reasonable level and meeting adequate security requirements. In this direction our model provokes competition and motivates providers to place superior bids, in terms of security, while providing flexibility to the organization. The auction process is demonstrated through a case study, where the outsourcer is a critical infrastructure organization. Miltiadis Kandias, Alexios Mylonas, Marianthi Theoharidou, Dimitris Gritzalis |
ISCC | 2 |
| 2011 | Smartphone Security Evaluation - The Malware Attack Case
Alexios Mylonas, Stelios Dritsas, Bill Tsoumas, Dimitris Gritzalis |
SECRYPT | 1 |
| 2011 | A Secure Smartphone Applications Roll-out Scheme
Alexios Mylonas, Bill Tsoumas, Stelios Dritsas, Dimitris Gritzalis |
TrustBus | 1 |
| 2010 | An Insider Threat Prediction Model
Miltiadis Kandias, Alexios Mylonas, Nikos Virvilis, Marianthi Theoharidou, Dimitris Gritzalis |
TrustBus | 2 |