EDBT 2026 Demo / reviewers in the wild / expert
Eirini Anthi
dblp:218/8785
· DBLP profile ↗
11ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0002-5274-0727ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 4 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Federated Detection at the Edge: Collaborative Anomaly Detection for Resource-Limited IoTabstractThe rapid expansion of Internet of Things (IoT) devices has heightened the need for effective intrusion detection systems (IDS) that operate under strict resource constraints. Conventional IDS implementations require substantial computational resources, making them unsuitable for low-power microcontroller-based devices. This paper proposes a novel collaborative IDS architecture that separates centralised model training from distributed edge inference. The system employs an autoencoder-based labelling mechanism trained on regular traffic to identify anomalies. Each ESP32 device performs local inference and exchanges predictions via UDP multicast, whilst MD5 hashing ensures model consistency across the network. Collaborative verification enables devices to identify and isolate compromised nodes without central coordination. Experimental evaluation demonstrates 98.5% F-score with 3ms average inference latency and 12.7KB memory footprint, consuming only 2.4% of available SRAM. Our approach achieves superior detection accuracy compared to existing cloud-edge systems whilst operating on severely resource-constrained hardware, making it a practical solution for large-scale IoT security deployments. Vasilis Ieropoulos, Eirini Anthi, Theodoros Spyridopoulos, Pete Burnap, Pietro Edoardo Carnelli, Aftab Khan 0001 |
IEEE Internet Things J. | 2 |
| 2025 | Collaborative intrusion detection in resource-constrained IoT environments: Challenges, methods, and future directions a reviewabstractThe rapid growth of technology has increased interconnected large-scale systems, broadening the attack surface for malicious actors . Traditional security solutions often employ centralised management of components like firewalls and intrusion detection systems for consistent configuration. This centralisation introduces a ”single point of failure,” risking severe consequences if compromised. While redundancy can mitigate concerns in IT systems, it does not scale well for larger systems. Edge computing , which pushes computation closer to endpoint devices , has been explored to improve scalability. The research community has also explored distributing and decentralising cybersecurity operations, especially intrusion detection , using new machine learning methods that mix centralised and distributed approaches to scale effectively while preserving data privacy. However, challenges remain in implementing these methods in large-scale IoT systems due to resource constraints . This paper evaluates intrusion detection methods in large-scale, resource-limited IoT systems, exploring the benefits of low-powered devices for network security and discussing solutions to current implementation challenges. Vasilis Ieropoulos, Eirini Anthi, Theodoros Spyridopoulos, Pete Burnap, Ioannis Mavromatis, Aftab Khan 0001, Pietro Edoardo Carnelli |
J. Inf. Secur. Appl. | 2 |
| 2025 | The Role of Artificial Intelligence in Shaping Intelligent Motorways: Opportunities, Challenges, and Real-World ImplementationsabstractThe incorporation of Artificial Intelligence (AI) into transportation infrastructure has drastically reshaped the conception and functioning of motorways worldwide. This paper conducts an in-depth examination of the role and impact of AI-based technologies in intelligent motorways, detailing their mechanisms, data utilisation, and the advantages and disadvantages stemming from their implementation. This review highlights prevalent AI technologies, including Automated Incident Detection Systems (AIDs), Automated Number Plate Recognition (ANPR), and Traffic Prediction and Management Systems, elucidating the unique AI algorithms that drive these systems and the distinct data types they harness. The paper also underscores real-world examples of these technologies in operation, offering practical insights into their application. It also explores the potential issues surrounding AI integration, focusing on adversarial machine learning attacks and concept drift that pose significant challenges to the robustness and security of AI systems in transportation. Subsequently, the overarching aim of this paper is to facilitate a comprehensive understanding of the current state of AI implementation in motorways and to stimulate further research and dialogue on the rapidly evolving intersection of AI and transportation. As such, this comprehensive review serves as a valuable resource for policymakers, industry practitioners, and researchers, fostering a well-rounded understanding of AI’s transformative role in modern motorways while highlighting areas that demand further exploration. The integration of AI into transportation infrastructure has significantly reshaped the operation of motorways worldwide. This paper provides a comprehensive review of AI applications in intelligent motorways, focusing on technologies such as Automated Incident Detection Systems (AIDs), Traffic Prediction Models, and Digital Twins. It examines real-world implementations and highlights challenges, including adversarial attacks, concept drift, and data privacy concerns. To address these challenges, we propose a structured evaluation framework emphasising explainability, robustness, and fairness. By identifying key research and policy gaps—spanning ethics, transparency, and public trust—the paper outlines actionable insights and future research priorities. Case studies offer practical examples, making this work a valuable resource for policymakers, industry practitioners, and researchers aiming to advance the safe and effective deployment of AI in transportation systems. Eirini Anthi, Lowri Williams, Hamza Ahmad Afzal, Bilal Ahmad Brar, Joydip Bhowmick, Kabir Gujral, Emyr Thomas |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | Detecting the Abuse of Cloud Services for C&C Infrastructure Through Dynamic Analysis and Machine LearningabstractCybercriminals increasingly abuse cloud and legitimate services (CLS) as covert command and control (C&C) infrastructure to orchestrate malicious operations and evade detection. This paper addresses the critical challenge of detecting such abuse of cloud platforms. We introduce a detection system that integrates dynamic analysis with Machine Learning (ML) to accurately distinguish between benign and malicious interactions with cloud services. By utilising a comprehensive data set from VirusTotal, the system uses advanced feature extraction techniques from both host behaviour and network traffic, using Cuckoo and Triage sandboxes to extract behaviors, to develop a detection model. The results demonstrate that the model achieves nearly 98% accuracy in identifying cloud service abuse, substantially outperforming previous efforts. Furthermore, we evaluate the model's robustness against adversarial attacks that aim to decrease accuracy by manipulating the feature values. Comparative evaluations show that our method maintains a higher detection accuracy under attack compared to related systems. Turki Al Lelah, George Theodorakopoulos 0001, Amir Javed, Eirini Anthi |
ISNCC | 4 |
| 2023 | Federated Deep Learning for Intrusion Detection in IoT NetworksabstractThe vast increase of Internet of Things (IoT) technologies and the ever-evolving attack vectors have increased cyber-security risks dramatically. A common approach to implementing AI-based Intrusion Detection Systems (IDSs) in distributed IoT systems is in a centralised manner. However, this approach may violate data privacy and prohibit IDS scalability. Therefore, intrusion detection solutions in IoT ecosystems need to move towards a decentralised direction. Federated Learning (FL) has attracted significant interest in recent years due to its ability to perform collaborative learning while preserving data confidentiality and locality. Nevertheless, most FL-based IDS for IoT systems are designed under unrealistic data distribution conditions. To that end, we design an experiment representative of the real-world and evaluate the performance of an FL-based IDS. For our experiments, we rely on TON-IoT, a realistic IoT network traffic dataset, associating each IP address with a single FL client. Additionally, we explore pre-training and investigate various aggregation methods to mitigate the impact of data heterogeneity. Lastly, we benchmark our approach against a centralised solution. The comparison shows that the heterogeneous nature of the data has a considerable negative impact on the model's performance when trained in a distributed manner. However, in the case of a pre-trained initial global FL model, we demonstrate a performance improvement of over 20% (F1-score) compared to a randomly initiated global model. Othmane Belarbi, Theodoros Spyridopoulos, Eirini Anthi, Ioannis Mavromatis, Pietro Edoardo Carnelli, Aftab Khan 0001 |
GLOBECOM | 3 |
| 2023 | Detection and mitigation of field flooding attacks on oil and gas critical infrastructure communicationabstractIndustrial Cyber-Physical Systems (ICPS) are highly dependent on Supervisory Control and Data Acquisition (SCADA) for process monitoring and control. Such SCADA systems are known to communicate using various insecure protocols such as Modbus, DNP3, and Open Platform Communication (OPC) Data Access standards (providing access to real-time automation data), which are vulnerable to a range of attacks. This leads to increased cyber risks faced in critical infrastructures, especially in the Oil and Gas sector. One of the most popular and critical attacks deployed against such infrastructure is Denial of Service (DoS), as it can have severe consequences that range from financial loss to loss of life. Such attacks can disrupt the ability of an operator to control hazardous operations leading to potentially unsafe scenarios. A novel Field Flooding attack is described which takes advantage of the packet memory structure of the Modbus protocol to perform a DoS attack. This attack can cause overflowing of the memory bank allocated in the Programmable Logic Controller (PLC) for Modbus operations. The attack is deployed and evaluated on a real industrial testbed and its impact against the Mitre ATT&CK framework is assessed, in order to identify which tactics an adversary could use to compromise the system. A novel mechanism that utilises supervised machine learning to detect this attack in industrial control system networks is also described. Experimental results show that the proposed mechanism, using the XGBoost algorithm, can identify this attack with 99% accuracy. Abubakar Sadiq Mohammed, Eirini Anthi, Omer F. Rana, Neetesh Saxena, Pete Burnap |
Comput. Secur. | 2 |
| 2022 | Cybersecurity Challenges in the Offshore Oil and Gas Industry: An Industrial Cyber-Physical Systems (ICPS) PerspectiveabstractThere has been significant interest within the offshore oil and gas industry to utilise Industrial Internet of Things (IIoT) and Industrial Cyber-Physical Systems (ICPS) . There has also been a corresponding increase in cyberattacks targeted at oil and gas companies. Offshore oil production requires remote access to and control of large and complex hardware resources. This is achieved by integrating ICPS, Supervisory, Control and Data Acquisition (SCADA) systems, and IIoT technologies. A successful cyberattack against an oil and gas (O&G) offshore asset could have a major impact on the environment, marine ecosystem and safety of personnel. Any disruption to the world’s supply of O&G can also have an effect on oil prices and the global economy. We describe the cyberattack surface within the oil and gas industry, discussing emerging trends in the offshore sub-sector and provide a historical perspective of known cyberattacks. We also present a case study of a subsea control system architecture typically used in offshore O&G operations and highlight potential vulnerabilities affecting the components of the system. This study is the first to provide a detailed analysis of attack vectors in a subsea control system. The analysis provided can be used to understand key vulnerabilities in such systems and may be used to implement efficient mitigation methods. Abubakar Sadiq Mohammed, Philipp Reinecke, Pete Burnap, Omer F. Rana, Eirini Anthi |
ACM Trans. Cyber Phys. Syst. | 5 |
| 2021 | Hardening machine learning denial of service (DoS) defences against adversarial attacks in IoT smart home networksabstractMachine learning based Intrusion Detection Systems (IDS) allow flexible and efficient automated detection of cyberattacks in Internet of Things (IoT) networks. However, this has also created an additional attack vector; the machine learning models which support the IDS’s decisions may also be subject to cyberattacks known as Adversarial Machine Learning (AML). In the context of IoT, AML can be used to manipulate data and network traffic that traverse through such devices. These perturbations increase the confusion in the decision boundaries of the machine learning classifier, where malicious network packets are often miss-classified as being benign. Consequently, such errors are bypassed by machine learning based detectors, which increases the potential of significantly delaying attack detection and further consequences such as personal information leakage, damaged hardware, and financial loss. Given the impact that these attacks may have, this paper proposes a rule-based approach towards generating AML attack samples and explores how they can be used to target a range of supervised machine learning classifiers used for detecting Denial of Service attacks in an IoT smart home network. The analysis explores which DoS packet features to perturb and how such adversarial samples can support increasing the robustness of supervised models using adversarial training. The results demonstrated that the performance of all the top performing classifiers were affected, decreasing a maximum of 47.2 percentage points when adversarial samples were present. Their performances improved following adversarial training, demonstrating their robustness towards such attacks. Eirini Anthi, Lowri Williams, Amir Javed, Pete Burnap |
Comput. Secur. | 1 |
| 2021 | Adversarial attacks on machine learning cybersecurity defences in Industrial Control SystemsabstractThe proliferation and application of machine learning-based Intrusion Detection Systems (IDS) have allowed for more flexibility and efficiency in the automated detection of cyber attacks in Industrial Control Systems (ICS). However, the introduction of such IDSs has also created an additional attack vector; the learning models may also be subject to cyber attacks, otherwise referred to as Adversarial Machine Learning (AML). Such attacks may have severe consequences in ICS systems, as adversaries could potentially bypass the IDS. This could lead to delayed attack detection which may result in infrastructure damages, financial loss, and even loss of life. This paper explores how adversarial learning can be used to target supervised models by generating adversarial samples using the Jacobian-based Saliency Map attack and exploring classification behaviours. The analysis also includes the exploration of how such samples can support the robustness of supervised models using adversarial training. An authentic power system dataset was used to support the experiments presented herein. Overall, the classification performance of two widely used classifiers, Random Forest and J48, decreased by 6 and 11 percentage points when adversarial samples were present. Their performances improved following adversarial training, demonstrating their robustness towards such attacks. Eirini Anthi, Lowri Williams, Matilda Rhode, Pete Burnap, Adam Wedgbury |
J. Inf. Secur. Appl. | 1 |
| 2019 | A Supervised Intrusion Detection System for Smart Home IoT DevicesabstractThe proliferation in Internet of Things (IoT) devices, which routinely collect sensitive information, is demonstrated by their prominence in our daily lives. Although such devices simplify and automate every day tasks, they also introduce tremendous security flaws. Current insufficient security measures employed to defend smart devices make IoT the “weakest” link to breaking into a secure infrastructure, and therefore an attractive target to attackers. This paper proposes a three layer intrusion detection system (IDS) that uses a supervised approach to detect a range of popular network based cyber-attacks on IoT networks. The system consists of three main functions: 1) classify the type and profile the normal behavior of each IoT device connected to the network; 2) identifies malicious packets on the network when an attack is occurring; and 3) classifies the type of the attack that has been deployed. The system is evaluated within a smart home testbed consisting of eight popular commercially available devices. The effectiveness of the proposed IDS architecture is evaluated by deploying 12 attacks from 4 main network based attack categories, such as denial of service (DoS), man-in-the-middle (MITM)/spoofing, reconnaissance, and replay. Additionally, the system is also evaluated against four scenarios of multistage attacks with complex chains of events. The performance of the system's three core functions result in an F-measure of: 1) 96.2%; 2) 90.0%; and 3) 98.0%. This demonstrates that the proposed architecture can automatically distinguish between IoT devices on the network, whether network activity is malicious or benign, and detect which attack was deployed on which device connected to the network successfully. Eirini Anthi, Lowri Williams, Malgorzata Slowinska, George Theodorakopoulos 0001, Pete Burnap |
IEEE Internet Things J. | 1 |
| 2018 | EclipseIoT: A secure and adaptive hub for the Internet of Things
Eirini Anthi, Shazaib Ahmad, Omer F. Rana, George Theodorakopoulos 0001, Pete Burnap |
Comput. Secur. | 1 |