Joseph Gardiner

dblp:150/6451 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
4since 2021 · last 2026
0000-0003-4748-4228ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Reasoning That Leaks, Fine-Tuning That Amplifies: Exposing the Hidden Threats of Chain-of-Thought Models
abstract
Chain-of-Thought (CoT) guides large language models to reason step-by-step, yielding remarkable performance gains across diverse tasks. However, this structured reasoning process also introduces novel and underexplored security risks. In this paper, we present an in-depth analysis of fine-tuning attacks targeting CoT-enabled LLMs, with particular focus on “aha moments” during reasoning, which are critical intermediate steps the model takes to make a significant decision or change its behavior. Through experiments on six CoT models and three non-CoT baselines, we find that even aligned CoT models can be more harmful than their base models. Moreover, the reasoning process frequently contains more harmful and actionable content than the final answer, even when the final answer refuses a harmful request. By examining the causal relationship between the reasoning process and the final outputs, we identify two distinct failure modes, Unintentional Leakage and Harmful Escalation, that systematically drive the generation of harmful reasoning. To rigorously assess these risks, we propose an evaluation framework grounded in the EU AI Act and construct a policy-aligned benchmark dataset for CoT reasoning. Our findings expose inherent vulnerabilities in CoT and offer insights for supervising and aligning the reasoning process in LLMs.
Joseph Gardiner, Sana Belguith
AsiaCCS2
2024 Threat models over space and time: A case study of end-to-end-encrypted messaging applications
abstract
Abstract Threat modeling is one of the foundations of secure systems engineering and must take heed of the context within which systems operate. In this work, we explore the extent to which real‐world systems engineering reflects a changing threat context. We examine the desktop clients of six widely used end‐to‐end‐encrypted mobile messaging applications to understand the extent to which they adjusted their threat model over space (when enabling clients on new platforms, such as desktop clients) and time (as new threats emerged). We experimented with short‐lived adversarial access against these desktop clients and analyzed the results using two popular threat elicitation frameworks, STRIDE and LINDDUN. The results demonstrate that system designers need to track threats in the evolving context within which systems operate and, more importantly, mitigate them by rescoping trust boundaries so that they remain consistent with administrative boundaries. A nuanced understanding of the relationship between trust and administration is vital for robust security, including the provision of safe defaults.
Partha Das Chowdhury, Maria Sameen, Jenny Blessing, Nicholas Boucher, Joseph Gardiner, Tom Burrows, Ross J. Anderson, Awais Rashid
Softw. Pract. Exp.5
2022 SoK: A Taxonomy for Contrasting Industrial Control Systems Asset Discovery Tools
abstract
Asset scanning and discovery is the first and foremost step for organizations to understand what assets they have and what to protect. There is currently a plethora of free and commercial asset scanning tools specializing in identifying assets in industrial control systems (ICS). However, there is little information available on their comparative capabilities and how their respective features contrast. Nor is it clear to what depth of scanning these tools can reach and whether they are fit-for-purpose in a scaled industrial network architecture. We provide the first systematic feature comparison of free-to-use asset scanning tools on the basis of an ICS scanning taxonomy that we propose. Based on the taxonomy, we investigate scanning depths reached by the tools’ features and validate our investigation through experimentation on Siemens, Schneider Electric, and Allen Bradley devices in a testbed environment.
Emmanouil Samanis, Joseph Gardiner, Awais Rashid
ARES2
2022 Threat-Driven Dynamic Security Policies for Cyber-Physical Infrastructures
Joseph Hallett, Simon N. Foley, David Manda, Joseph Gardiner, Dimitri Jonckers, Wouter Joosen, Awais Rashid
CRITIS4
2019 Everything Is Awesome! or Is It? Cyber Security Risks in Critical Infrastructure
Awais Rashid, Joseph Gardiner, Benjamin Green 0001, Barnaby Craggs
CRITIS2
2016 Discordant patient pain level reporting between questionnaires and physician encounters of the same day
David Juckett, Fred N. Davis, Mark Gostine, Eric P. Kasten, Philip L. Reed, Joseph Gardiner, Rebecca Risko
AMIA6