EDBT 2026 Demo / reviewers in the wild / expert
Ivan Homoliak
dblp:171/6536
· DBLP profile ↗
17ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0002-0790-0875ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 4 first-author · 10 since 2021Software engineering, systems software and programming languages · 7 · 2 first-author · 7 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Single Secret Leader Election in Ethereum PoS: An Empirical Study of Whisk and Homomorphic Sortition under DoS on the Leader and Censorship
Tereza Burianová, Martin Peresíni, Ivan Homoliak |
ICBC | 3 |
| 2026 | SSLE-DAG: A High-Throughput Proof-of-Stake Consensus Protocol Combining an Adaptive DAG with a Single Secret Leader Election
Tomás Hladký, Martin Peresíni, Juraj Mariani, Ivan Homoliak |
ICBC | 4 |
| 2026 | How Much is Decentralization of Ethereum PoS Adversely Affected by Verifier's Dilemma and Staking Pools under Realistic Operational Costs?
Ivan Homoliak, Martin Hruby, Martin Peresíni, Kristián Kostál, Daria Smuseva |
ICBC | 1 |
| 2026 | Social Capital Consensus for Blockchains: Exploring Design Options for Replacement of Proof-of-Stake by Social Influence
Juraj Mariani, Ivan Homoliak |
ICBC | 2 |
| 2026 | Analysing Multidisciplinary Approaches to Fight Large-Scale Digital Influence Operations
David Arroyo, Rafael Mata Milla, Marc Almeida Ros, Nikolaos Lykousas, Ivan Homoliak, Constantinos Patsakis, Fran Casino |
ICISSP (1) | 5 |
| 2025 | SNARKlet: Efficient Mobile Wallet Synchronization with zk-SNARKsabstractTraditionally, mobile wallets rely on a trusted server that provides them with a current view of the blockchain, and thus, these wallets do not need to validate the header chain or transaction inclusion themselves. If a mobile wallet were to validate a header chain and inclusion of its transactions, it would require significant storage and performance overhead, which is challenging and expensive to ensure on resource-limited devices, such as smartphones. Moreover, such an overhead would be multiplied by the number of cryptocurrencies the user holds.Therefore, we introduce a novel approach, called SNARKlet, to mobile wallet synchronization designed to eliminate trust in a server while providing efficient utilization of resources. Our approach addresses the challenges associated with storage and bandwidth requirements by off-chaining validation of header chains using SNARK-based proofs of chain extension, which are verified by a smart contract. This offers us a means of storing checkpoints in header chains of multiple blockchains.The key feature of our approach is the ability of mobile clients to update their partial local header chains using checkpoints derived from the proof verification results stored in the smart contract. In the evaluation, we created zk-SNARK proofs for the 2, 4, 8, 16, 32, and 64 headers within our trustless off-chain service. For 64-header proofs, the off-chain service producing proofs requires at least 40 GB of RAM, while minimal gas consumption is achieved for 12 proofs bundled in a single transaction. We achieved a 20-fold reduction in storage overhead for a mobile client in contrast to traditional SPV clients. Although we have developed a proof-of-concept for PoW blockchains, the whole approach can be extended in principle to other consensus mechanisms, e.g., PoS. Martin Peresíni, Samuel Oleksák, Samuel Slávka, Ivan Homoliak |
ICBC | 4 |
| 2024 | Resilience of Voice Assistants to Synthetic Speech
Kamil Malinka, Anton Firc, Petr Kaska, Tomás Lapsanský, Oskar Sandor, Ivan Homoliak |
ESORICS (1) | 6 |
| 2024 | SoK: Cryptocurrency Wallets - A Security Review and Classification based on Authentication FactorsabstractIn this work, we review existing cryptocurrency wallet solutions with regard to authentication methods and factors from the user’s point of view. In particular, we distinguish between authentication factors that are verified against the blockchain and the ones verified locally (or against a centralized party). With this in mind, we define notions for k-factor authentication against the blockchain and k-factor authentication against the authentication factors. Based on these notions, we propose a classification of authentication schemes. We extend our classification to accommodate the threshold signatures and signing transactions by centralized parties (such as exchanges or co-signing services). Finally, we apply our classification to existing wallet solutions, which we compare based on various security and key-management features. Ivan Homoliak, Martin Peresíni |
ICBC | 1 |
| 2023 | Detecting and Preventing Credential Misuse in OTP-Based Two and Half Factor Authentication Toward Centralized Services Utilizing Blockchain-Based Identity ManagementabstractThis paper focuses on the problem of detection and prevention of stolen and misused secrets (such as private keys) for authentication toward centralized services. We propose a solution for this problem, based on SmartOTPs, the two-factor authentication scheme against the blockchain, which is intended for smart contract wallets and utilizes one-time passwords (OTPs). We modify SmartOTPs for our purposes and utilize them in the setting of two-and-a-half-factor authentication against a centralized service provider. Out of two and a half factors of our solution, the first factor stands for the private key, and the second and a half factor stands for OTPs and their precursors (a.k.a., pre-images), where OTPs are obtained from the precursors by cryptoaraphically secure hashing. We describe the protocol for bootstrapping our approach as well as the authentication procedure. In the case of stolen creden-tials from the client, we show that our solution enables the user to immediately detect it and proceed to re-initialization with fresh credentials. We utilize blockchain-based identity management and decentralized identities of users to simplify the overhead of the registration process and reinitialization. Jozef Drga, Ivan Homoliak, Juraj Vanco, Athanasios V. Vasilakos, Martin Peresíni, Petr Hanácek |
ICBC | 2 |
| 2022 | Counting in Regexes Considered Harmful: Exposing ReDoS Vulnerability of Nonbacktracking Matchers
Lenka Turonová, Lukás Holík, Ivan Homoliak, Ondrej Lengál, Margus Veanes, Tomás Vojnar |
USENIX Security Symposium | 3 |
| 2022 | HADES-IoT: A Practical and Effective Host-Based Anomaly Detection System for IoT Devices (Extended Version)abstractInternet of Things (IoT) devices have become ubiquitous, with applications in many domains, including industry, transportation, and healthcare; these devices also have many household applications. The proliferation of IoT devices has raised security and privacy concerns, however many manufacturers neglect these aspects, focusing solely on the core functionality of their products due to the short time to market and the need to reduce product costs. Consequently, vulnerable IoT devices are left unpatched, allowing attackers to exploit them for various purposes, which include compromising the device users’ privacy or recruiting the devices to an IoT botnet. We present a practical and effective host-based anomaly detection system for IoT devices (HADES-IoT) as a novel last line of defense. HADES-IoT has proactive detection capabilities that enable the execution of any malicious process to be stopped before it even starts. HADES-IoT provides tamper-proof protection and can be deployed on a wide range of Linux-based IoT devices. HADES-IoT’s main advantage is its low overhead, making it suitable for Linux-based IoT devices where state-of-the-art security solutions are infeasible due to their high-performance demands. We deployed HADES-IoT on seven IoT devices, where it demonstrated 100% effectiveness in the detection of IoT malware, including VPNFilter, IoT Reaper, and Mirai malware, while requiring only 5.5% (on average) of the available memory and consuming just negligible CPU resources. Dominik Breitenbacher, Ivan Homoliak, Yan Lin Aung, Yuval Elovici, Nils Ole Tippenhauer |
IEEE Internet Things J. | 2 |
| 2021 | Intercepting Hail Hydra: Real-time detection of Algorithmically Generated Domains
Fran Casino, Nikolaos Lykousas, Ivan Homoliak, Constantinos Patsakis, Julio César Hernández Castro |
J. Netw. Comput. Appl. | 3 |
| 2020 | SmartOTPs: An Air-Gapped 2-Factor Authentication for Smart-Contract WalletsabstractWith the recent rise of cryptocurrencies' popularity, the security and management of crypto-tokens have become critical. We have witnessed many attacks on users and providers, which have resulted in significant financial losses. To remedy these issues, several wallet solutions have been proposed. However, these solutions often lack either essential security features, usability, or do not allow users to customize their spending rules. In this paper, we propose SmartOTPs, a smart-contract wallet framework that gives a flexible, usable, and secure way of managing crypto-tokens in a self-sovereign fashion. The proposed framework consists of four components (i.e., an authenticator, a client, a hardware wallet, and a smart contract), and it provides 2-factor authentication (2FA) performed in two stages of interaction with the blockchain. To the best of our knowledge, our framework is the first one that utilizes one-time passwords (OTPs) in the setting of the public blockchain. In SmartOTPs, the OTPs are aggregated by a Merkle tree and hash chains whereby for each authentication only a short OTP (e.g., 16B-long) is transferred from the authenticator to the client. Such a novel setting enables us to make a fully air-gapped authenticator by utilizing small QR codes or a few mnemonic words, while additionally offering resilience against quantum cryptanalysis. We have made a proof-of-concept based on the Ethereum platform. Our cost analysis shows that the average cost of a transfer operation is comparable to existing 2FA solutions using smart contracts with multi-signatures. Ivan Homoliak, Dominik Breitenbacher, Ondrej Hujnak, Pieter H. Hartel, Alexander Binder, Pawel Szalachowski |
AFT | 1 |
| 2019 | HADES-IoT: A Practical Host-Based Anomaly Detection System for IoT DevicesabstractInternet of Things (IoT) devices have become ubiquitous and spread across many application domains including the industry, transportation, healthcare, and households. However, the proliferation of the IoT devices has raised the concerns about their security -- many manufacturers focus only on the core functionality of their products due to short time to market and low cost pressures, while neglecting security aspects. Moreover, there is no established or standardized method for measuring and ensuring the security of IoT devices. Consequently, vulnerabilities are left untreated, allowing attackers to exploit IoT devices for various purposes, such as compromising privacy, recruiting devices into a botnet, or misusing devices to perform cryptocurrency mining. In this paper, we present a practical Host-based Anomaly DEtection System for IoT (HADES-IoT) as a novel last line of defense. HADES-IoT has proactive detection capabilities, provides tamper-proof resistance, and can be deployed on a wide range of Linux-based IoT devices. The main advantage of HADES-IoT is its low performance overhead, which makes it suitable for the IoT domain, where state-of-the-art approaches cannot be applied due to their high-performance demands. We deployed HADES-IoT on seven IoT devices and demonstrated 100% effectiveness in the detection of current IoT malware such as VPNFilter and IoTReaper; while on average, requiring only 5.5% of available memory and causing only a low CPU load. Dominik Breitenbacher, Ivan Homoliak, Yan Lin Aung, Nils Ole Tippenhauer, Yuval Elovici |
AsiaCCS | 2 |
| 2019 | Adversarial Attacks on Remote User Authentication Using Behavioural Mouse DynamicsabstractMouse dynamics is a potential means of authenticating users. Typically, the authentication process is based on classical machine learning techniques, but recently, deep learning techniques have been introduced for this purpose. Although prior research has demonstrated how machine learning and deep learning algorithms can be bypassed by carefully crafted adversarial samples, there has been very little research performed on the topic of behavioural biometrics in the adversarial domain. In an attempt to address this gap, we built a set of attacks, which are applications of several generative approaches, to construct adversarial mouse trajectories that bypass authentication models. These generated mouse sequences will serve as the adversarial samples in the context of our experiments. We also present an analysis of the attack approaches we explored, explaining their limitations. In contrast to previous work, we consider the attacks in a more realistic and challenging setting in which an attacker has access to recorded user data but does not have access to the authentication model or its outputs. We explore three different attack strategies: 1) statistics-based, 2) imitation-based, and 3) surrogate-based; we show that they are able to evade the functionality of the authentication models, thereby impacting their robustness adversely. We show that imitation-based attacks often perform better than surrogate-based attacks, unless, however, the attacker can guess the architecture of the authentication model. In such cases, we propose a potential detection mechanism against surrogate-based attacks. Yi Xiang Marcus Tan, Alfonso Iacovazzi, Ivan Homoliak, Yuval Elovici, Alexander Binder |
IJCNN | 3 |
| 2019 | StrongChain: Transparent and Collaborative Proof-of-Work Consensus
Pawel Szalachowski, Daniël Reijsbergen, Ivan Homoliak, Siwei Sun |
USENIX Security Symposium | 3 |
| 2016 | Exploitation of NetEm Utility for Non-payload-based Obfuscation Techniques Improving Network Anomaly Detection
Ivan Homoliak, Martin Teknos, Maros Barabas, Petr Hanácek |
SecureComm | 1 |