EDBT 2026 Demo / reviewers in the wild / expert
Nikolaos Lykousas
dblp:222/2787
· DBLP profile ↗
10ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0001-8874-1230ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 2 first-author · 2 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Analysing Multidisciplinary Approaches to Fight Large-Scale Digital Influence Operations
David Arroyo, Rafael Mata Milla, Marc Almeida Ros, Nikolaos Lykousas, Ivan Homoliak, Constantinos Patsakis, Fran Casino |
ICISSP (1) | 4 |
| 2024 | Decoding developer password patterns: A comparative analysis of password extraction and selection practicesabstractPasswords play a crucial role in authentication, ensuring that only authorised entities can access sensitive information. However, user password choices are often weak and predictable, making them susceptible to cyber-attacks. Additionally, hard-coded credentials in source code can expose organisations and infrastructure to significant risks. This paper explores the patterns of passwords used by developers, examining their similarities to those of typical users. We also investigate the efficacy of large language models (LLMs) in identifying hard-coded credentials in source code. Our findings suggest that developers foster more complex and, hence, more secure password selection patterns than regular users. Nevertheless, they can use worse patterns when the context allows them. The latter, combined with the ample commits in public code repositories containing secrets, exemplifies the need for more targeted awareness campaigns and tighter integration of code security tools in the development lifecycle. Finally, we explore the capacity of LLMs to detect hard-coded credentials, highlighting their differences and limitations. Nikolaos Lykousas, Constantinos Patsakis |
Comput. Secur. | 1 |
| 2024 | Assessing LLMs in malicious code deobfuscation of real-world malware campaignsabstractThe integration of large language models (LLMs) into various cybersecurity pipelines has become increasingly prevalent, enabling the automation of numerous manual tasks and often surpassing human performance. Recognising this potential, cybersecurity researchers and practitioners are actively investigating the application of LLMs to process vast volumes of heterogeneous data for anomaly detection, potential bypass identification, attack mitigation, and fraud prevention. Moreover, LLMs’ advanced capabilities in generating functional code, interpreting code context, and code summarisation present significant opportunities for reverse engineering and malware deobfuscation. In this work, we comprehensively examine the deobfuscation capabilities of state-of-the-art LLMs. Specifically, we conducted a detailed evaluation of four prominent LLMs using real-world malicious scripts from the notorious Emotet malware campaign. Our findings reveal that while current LLMs are not yet perfectly accurate, they demonstrate substantial potential in efficiently deobfuscating payloads. This study highlights the importance of fine-tuning LLMs for specialised tasks, suggesting that such optimisation could pave the way for future AI-powered threat intelligence pipelines to combat obfuscated malware. Our contributions include a thorough analysis of LLM performance in malware deobfuscation, identifying strengths and limitations, and discussing the potential for integrating LLMs into cybersecurity frameworks for enhanced threat detection and mitigation. Our experiments illustrate that LLMs can automatically and accurately extract the necessary indicators of compromise from a real-world campaign with an accuracy of 69.56% and 88.78% for the URLs and the corresponding domains of the droppers, respectively. Constantinos Patsakis, Fran Casino, Nikolaos Lykousas |
Expert Syst. Appl. | 3 |
| 2022 | Invoice #31415 attached: Automated analysis of malicious Microsoft Office documentsabstractMicrosoft Office may be by far the most widely used suite for processing documents, spreadsheets, and presentations. Due to its popularity, it is continuously utilised to carry out malicious campaigns. Threat actors, exploiting the platform’s dynamic features, use it to launch their attacks and penetrate millions of hosts in their campaigns. This work explores the modern landscape of malicious Microsoft Office documents, exposing the means that malware authors use. We leverage a taxonomy of the tools used to weaponise Microsoft Office documents and explore the modus operandi of malicious actors. Moreover, we generated and publicly shared a specially crafted dataset, which relies on incorporating benign and malicious documents containing many dynamic features such as VBA macros and DDE. The latter is crucial for a fair and realistic analysis, an open issue in the current state of the art. This allows us to draw safe conclusions on the malicious features and behaviour. More precisely, we extract the necessary features with an automated analysis pipeline to efficiently and accurately classify a document as benign or malicious using machine learning with an F1 score above 0.98, outperforming the current state of the art detection algorithms. Vasilios Koutsokostas, Nikolaos Lykousas, Theodoros Apostolopoulos, Gabriele Orazi, Amrita Ghosal, Fran Casino, Mauro Conti, Constantinos Patsakis |
Comput. Secur. | 2 |
| 2021 | Unearthing malicious campaigns and actors from the blockchain DNS ecosystem
Fran Casino, Nikolaos Lykousas, Vasilios Katos, Constantinos Patsakis |
Comput. Commun. | 2 |
| 2021 | Large-scale analysis of grooming in modern social networks
Nikolaos Lykousas, Constantinos Patsakis |
Expert Syst. Appl. | 1 |
| 2021 | Intercepting Hail Hydra: Real-time detection of Algorithmically Generated Domains
Fran Casino, Nikolaos Lykousas, Ivan Homoliak, Constantinos Patsakis, Julio César Hernández Castro |
J. Netw. Comput. Appl. | 2 |
| 2019 | Unveiling Trends and Predictions in Digital FactoriesabstractThe emergence of the Industrial Internet of Things paves the way for enhancing the real-time monitoring capabilities of contemporary manufacturing enterprises through the extensive utilization of physical and virtual sensors. This paradigm enables the detection of early warning signals concerning systems' degradation and facilitates the prompt decision making and actions performed ahead of time. Currently, even large manufacturing companies have not yet developed a complete Predictive Maintenance strategy and appropriate sensor-driven, real-time systems in order to utilize these benefits. In this paper, we propose a failure prediction system for complex IT systems in the steel industry. The novelty of our work lies in the exploitation of Deep Learning techniques from streaming operational sensor data, enabling earlier failure predictions through a Neural Networks approach. To evaluate the proposed framework, real-life data are collected and analyzed based on daily operational and maintenance activities within the production line. We further demonstrate the framework's potential by presenting some early results in modeling and predicting the complex and dynamic behavior in the manufacturing settings. Sophia Karagiorgou, Georgios Vafeiadis, Dimitrios Ntalaperas, Nikolaos Lykousas, Danai Vergeti, Dimitrios Alexandrou |
DCOSS | 4 |
| 2019 | Sharing Emotions at Scale: The Vent Dataset
Nikolaos Lykousas, Constantinos Patsakis, Andreas Kaltenbrunner, Vicenç Gómez |
ICWSM | 1 |
| 2018 | Adult Content in Social Live Streaming Services: Characterizing Deviant Users and RelationshipsabstractSocial Live Stream Services (SLSS) exploit a new level of social interaction. One of the main challenges in these services is how to detect and prevent deviant behaviors that violate community guidelines. In this work, we focus on adult content production and consumption in two widely used SLSS, namely Live.me and Loops Live, which have millions of users producing massive amounts of video content on a daily basis. We use a pre-trained deep learning model to identify broadcasters of adult content. Our results indicate that moderation systems in place are highly ineffective in suspending the accounts of such users. We create two large datasets by crawling the social graphs of these platforms, which we analyze to identify characterizing traits of adult content producers and consumers, and discover interesting patterns of relationships among them, evident in both networks. Nikolaos Lykousas, Constantinos Patsakis, Vicenç Gómez |
ASONAM | 1 |