Gregory Epiphaniou

dblp:66/7949 · DBLP profile ↗
← Back
28ranked-venue papers
3as first author
21since 2021 · last 2026
0000-0003-1054-6368ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 2 first-author · 9 since 2021Computer networks · 9 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021
YearPublicationVenuePosition
2026 AURA-XR: A risk-based methodology for the optimal selection of user authentication mechanisms in extended reality
abstract
The increasing adoption of Extended Reality (XR) technologies brings immersive interfaces into critical domains like healthcare and manufacturing. However, deciding how to protect users in these environments remains an open challenge. Although prior research explores individual authentication mechanisms, existing selection methods ignore context-specific constraints, environmental factors, and user perceptions central to XR. To address this, we conducted a qualitative study with usable-security experts to uncover key design considerations that current approaches overlook. Next, we mapped well-known selection methodologies against these considerations and identified important mismatches. In response, we developed AURA-XR, a risk-based framework integrating stakeholder perceptions, environmental and scenario-specific constraints, and risk assessment into a decision model. We demonstrate that AURA-XR supports context-sensitive, multi-objective authentication decisions tailored to this emerging domain. By filling a methodological gap, AURA-XR advances adaptive, privacy-aware, human-centred security in immersive systems, opening new routes for robust, situationally informed authentication in XR.
Christina P. Katsini, Gregory Epiphaniou, Carsten Maple
Comput. Secur.2
2026 Adaptive Trust-Aware SOC Human-AI Teaming for resilient operations
abstract
Security Operations Centres (SOCs) face sustained pressure from alert fatigue, fragmented tooling, analyst cognitive overload, and increasingly complex multi-stage attack campaigns. Although Artificial Intelligence (AI) and Machine Learning (ML) can support detection, triage, and response, their operational value is constrained when trust, transparency, accountability, and human oversight are not systematically addressed. This paper presents the Adaptive Trust-Aware SOC Human–AI Teaming (ATA-SOC-HAT) framework, a design-oriented conceptual framework for trust-calibrated collaboration between SOC analysts and AI services. The framework was derived from a structured literature review and maps recurrent barriers in SOC human–AI collaboration to explicit functional modules, including explainable interaction, dynamic task allocation, trust calibration, arbitration, and continuous learning. We describe the framework architecture and workflow and illustrate its intended operation through an advanced threat scenario. Rather than claiming empirical validation, the paper provides a prioritised evaluation roadmap that identifies a practical core set of metrics for future practitioner-in-the-loop studies, simulations, and prototype implementations. We also summarise how the framework aligns with relevant cybersecurity and trustworthy-AI guidance to support accountable deployment. The contribution of this work is therefore a traceable, literature-derived conceptual framework and a realistic basis for future empirical evaluation of human–AI teaming in SOC environments.
Mahender Kumar, Ruby Rani, Gregory Epiphaniou, Carsten Maple
Comput. Secur.3
2026 Intelligent asset parameterisation for risk-based moving target defence
abstract
In an era characterised by evolving cyber threats and sophisticated adversar-ial behaviour, the field of cyber-security faces a continuous and formidablechallenge. The development of dynamic and adaptive security control mea-sures is imperative in order to safeguard critical assets and information.This article delves into the realm of Moving Target Defence (MTD), astrategic approach that seeks to outmanoeuvre adversaries by constantlyshifting the security landscape. Our research specifically focuses on the ap-plication of Reinforcement Learning (RL) in MTD, with a focus on threatexposure and the efficacy of control strategies with respect to risk reduction.A defensive RL agent is proposed that incorporates attack graphs as ablueprint to assess possible paths that an adversary may take. By consideringreceived events about an adversary’s actions, the defensive agent continuouslyupdates its knowledge about the adversary’s position on the attack graph.The proposed research establishes and evaluates a risk-based, RL-drivenagent capable of MTD operations in order to address adversarial behaviours.The proposed approach provides valuable insights into optimally deployingsecurity controls under dynamic threat scenarios and restricted budget resources.
Konstantinos G. Kyriakopoulos, Lincoln Kamau Kiarie, Marios Aristodemou, Susan Babirye, Amit Patel 0002, Isaiah Nassiuma, Mercedeh Rezaei, Iain Phillips 0002, Anhtuan Le, Carsten Maple, Gregory Epiphaniou
Comput. Secur.11
2026 ICSThreatQA: A knowledge-graph enhanced question answering model for industrial control system threat intelligence
Ruby Rani, Mahender Kumar, Gregory Epiphaniou, Carsten Maple
Expert Syst. Appl.3
2026 FREA-XR: An Evaluation Framework for Extended Reality User Authentication Mechanisms
Christina P. Katsini, Gregory Epiphaniou, Carsten Maple
Int. J. Hum. Comput. Interact.2
2026 Quantum-Resilient Blockchain Framework for Intelligent Transportation Systems
abstract
Intelligent transportation systems integrate Internet of Things, blockchain, and quantum-resistant cryptography to enhance autonomous vehicle operations, urban mobility, and road safety. However, their reliance on heterogeneous communication networks exposes them to cyber threats, including identity spoofing, data tampering, and quantum-enabled attacks that compromise security and privacy. To address these challenges, this paper proposes a blind quantum computation-enhanced identity-based quantum-secure framework, which combines decentralized authentication, blockchain-based identity verification, and post-quantum cryptographic techniques to reduce long-term trust in third parties by eliminating persistent key escrow, while mitigating security risks. The framework leverages quantum spin-state mapping and blind quantum encryption to protect against quantum-enabled collision (birthday-type) and key impersonation attacks under the defined adversary model, ensuring tamper-proof and unlinkable transactions in vehicular networks. Additionally, a lightweight consensus mechanism optimizes computational efficiency while maintaining high security and scalability. Through private-chain simulations and micro-benchmarks, Identity-Based Quantum Signature achieves ~94.5 s confirmation time for a batch of 600 transactions (≈ 6.3 TPS) in off-path audit and enrollment functions, while maintaining lightweight cryptographic operations suitable for real-time V2V safety messages (signing ≈ 2.994 ms, verification ≈ 1.493 ms). These results position IBQS as a practical and quantum-resilient security solution for next-generation decentralized transportation systems.
Hafiz Muhammad Waseem, Noor Munir, Saif Ul Islam, Gregory Epiphaniou, Muhammad Asfand Hafeez, Carsten Maple
IEEE Internet Things J.4
2025 SoK: Security of EMV Contactless Payment Systems
abstract
The widespread adoption of EMV (Europay, Mastercard, and Visa) contactless payment systems has greatly improved convenience for both users and merchants. However, this growth has also exposed significant security challenges. This SoK provides a comprehensive analysis of security vulnerabilities in EMV contactless payments, particularly within the open-loop systems used by Visa and Mastercard. We categorize attacks into seven attack vectors across three key areas: application selection, cardholder authentication, and transaction authorization. We replicate the attacks on Visa and Mastercard protocols using our experimental platform to determine their practical feasibility and offer insights into the current security landscape of contactless payments. Our study also includes a detailed evaluation of the underlying protocols, along with a comparative analysis of Visa and Mastercard, highlighting vulnerabilities and recommending countermeasures.
Mahshid Mehr Nezhad, Feng Hao 0001, Gregory Epiphaniou, Carsten Maple, Timur Yunusov
EuroS&P3
2025 Not Just Who You Are, but Where and How: Modeling XR Authentication Scenarios
abstract
Authentication in extended reality (XR) presents unique challenges due to embodied interaction, spatial immersion, and variable environmental conditions. As XR systems become more prevalent, secure and usable authentication mechanisms are critical. However, current research often overlooks the scenarios in which these mechanisms operate, limiting comparability, reproducibility, and real-world applicability. This paper addresses this gap by presenting a structured model of XR authentication scenarios. We conducted semi-structured interviews with experts in the Usable Security and Privacy domain to identify key scenario dimensions influencing the design and evaluation of XR authentication mechanisms. Through thematic analysis, we identified dimensions related to contextual parameters, environmental conditions, and XR-specific properties. The resulting scenario model was validated through literature mapping and demonstrated via a realistic use case. Our work provides a foundation for context-aware design and more rigorous evaluation of authentication mechanisms across diverse XR environments.
Christina P. Katsini, Gregory Epiphaniou, Carsten Maple
VRST2
2025 Security of cyber-physical Additive Manufacturing supply chain: Survey, attack taxonomy and solutions
abstract
Additive Manufacturing (AM) is transforming industries by enabling rapid prototyping and customised production. However, as AM processes become increasingly digitised and interconnected, they introduce significant cybersecurity vulnerabilities, including intellectual property theft, design manipulation, and counterfeit production. This paper offers a comprehensive analysis of cyber and cyber–physical threats within the AM supply chain, addressing a critical research gap that has largely focused on isolated security aspects. Building upon existing taxonomies, we expand cybersecurity frameworks to incorporate emerging AM-specific threats. We propose a structured attack taxonomy that categorises threats by attacker goals, targets, and methods, supported by real-world case studies. The paper emphasizes the need for robust cybersecurity measures to protect intellectual property, ensure production integrity, and strengthen supply chain security. Finally, we present mitigation strategies to counter these threats, laying the foundation for future research and best practices to secure AM ecosystems.
Mahender Kumar, Gregory Epiphaniou, Carsten Maple
Comput. Secur.2
2024 Beyond Face Matching: A Facial Traits based Privacy Score for Synthetic Face Datasets
Robero Leyva, Praveen Selvaraj, Andrew Elliott, Gregory Epiphaniou, Carsten Maple
BMVC4
2024 AutonomousCyber '24 - Workshop on Autonomous Cybersecurity
abstract
Autonomous cybersecurity represents a significant evolution in information security, where systems independently detect, respond to, and neutralize cyber threats without the need for human intervention. This level of autonomy is a more advanced stage in cybersecurity, enabling systems not only to execute tasks but also to interpret contexts, make decisions, and adapt strategies in realtime. The shift towards autonomy promises enhanced adaptability, faster response times, and a reduction in human error. This domain stands out for its unique blend of advanced Machine Learning (ML) systems such as Reinforcement Learning (RL)-driven and Quantum Machine Learning (QML)-based agents with cybersecurity automation techniques such as automated patch management systems, automated incident response systems to forge self-reliant cybersecurity systems. The AutonomousCyber workshop provides a venue for presenting and discussing new developments in this field.
Ali Dehghantanha, Reza M. Parizi, Gregory Epiphaniou
CCS3
2024 Data-agnostic Face Image Synthesis Detection using Bayesian CNNs
abstract
Face image synthesis detection is considerably gaining attention because of the potential negative impact on society that this type of synthetic data brings. In this paper, we propose a data-agnostic solution to detect the face image synthesis process. Specifically, our solution is based on an anomaly detection framework that requires only real data to learn the inference process. It is therefore data-agnostic in the sense that it requires no synthetic face images. The solution uses the posterior probability with respect to the reference data to determine if new samples are synthetic or not. Our evaluation results using different synthesizers show that our solution is very competitive against the state-of-the-art, which requires synthetic data for training.
Roberto Leyva, Victor Sanchez, Gregory Epiphaniou, Carsten Maple
Pattern Recognit. Lett.3
2023 An optimized fuzzy deep learning model for data classification based on NSGA-II
Abbas Yazdinejad, Ali Dehghantanha, Reza M. Parizi, Gregory Epiphaniou
Neurocomputing4
2023 A Deep-Learning-Based Solution for Securing the Power Grid Against Load Altering Threats by IoT-Enabled Devices
abstract
The growing integration of high-wattage Internet of Things (IoT)-enabled electrical appliances at the consumer end has created a new attack surface that an adversary can exploit to disrupt power grid operations. Specifically, dynamic load-altering attacks (D-LAAs), accomplished by an abrupt or strategic manipulation of a large number of consumer appliances in a botnet-type attack, have been recognized as major threats that can potentially destabilize power grid control loops. This article introduces a novel approach-based a multioutput network (2-D convolutional neural networks classifier and reconstruction decoder)—called “2DR-CNN”—to detect and localize D-LAAs with high resolution. To achieve this, we leverage the frequency and phase angle data of the generator buses monitored by phasor measurement units (PMUs) installed in the power grid. To verify the effectiveness of the proposed method, simulations are conducted on IEEE 14- and 39-bus systems. The performance of the 2DR-CNN method is compared against several benchmark machine-learning-based approaches. The results confirm that the proposed method outperforms other techniques in detection and localizing D-LAAs with high resolution in a number of practical scenarios, including PMU measurement noises and missing measurements.
Hamidreza Jahangir, Subhash Lakshminarayana, Carsten Maple, Gregory Epiphaniou
IEEE Internet Things J.4
2022 Super Learner Ensemble for Anomaly Detection and Cyber-Risk Quantification in Industrial Control Systems
abstract
Industrial control systems (ICSs) are integral parts of smart cities and critical to modern societies. Despite indisputable opportunities introduced by disruptor technologies, they proliferate the cybersecurity threat landscape, which is increasingly more hostile. The quantum of sensors utilized by ICS aided by artificial intelligence (AI) enables data collection capabilities to facilitate automation, process streamlining, and cost reduction. However, apart from the operational use, the sensors generated data combined with AI can be innovatively utilized to model anomalous behavior as part of layered security to increase resilience to cyberattacks. We introduce a framework to profile anomalous behavior in ICS and derive a cyber-risk score. A novel super learner ensemble for one-class classification is developed, using overlapping rolling windows with stratified,$k$-fold,$n$-repeat cross-validation applied to each base learner followed by majority voting to derive the best learner. Our approach is demonstrated on a liquid distribution sensor data set. The experimental results reveal that the proposed technique achieves an overall$F1$-score of 99.13%, an anomalous recall score of 99% detecting anomalies lasting only 17 s. The key strength of the framework is the low computational complexity and error rate. The framework is modular, generic, applicable to other ICS, and transferable to other smart city sectors.
Gabriela Ahmadi-Assalemi, Haider M. Al-Khateeb, Gregory Epiphaniou, Amar Aggoun
IEEE Internet Things J.3
2022 Reinforcement Learning for Security-Aware Computation Offloading in Satellite Networks
abstract
The rise ofNewSpaceprovides a platform for small and medium businesses to commercially launch and operate satellites in space. In contrast to traditional satellites,NewSpaceprovides the opportunity for delivering computing platforms in space. However, computational resources within space are usually expensive and satellites may not be able to compute all computational tasks locally. Computation offloading (CO), a popular practice in Edge/Fog computing, could prove effective in saving energy and time in this resource-limited space ecosystem. However, CO alters the threat and risk profile of the system. In this article, we analyze security issues in space systems and propose a security-aware algorithm for CO. Our method is based on the reinforcement learning technique, deep deterministic policy gradient (DDPG). We show, using Monte-Carlo simulations, that our algorithm is effective under a variety of environment and network conditions and provide novel insights into the challenge of optimized location of computation.
Saurav Sthapit, Subhash Lakshminarayana, Ligang He, Gregory Epiphaniou, Carsten Maple
IEEE Internet Things J.4
2022 APIVADS: A Novel Privacy-Preserving Pivot Attack Detection Scheme Based on Statistical Pattern Recognition
abstract
Advanced cyber attackers often “pivot” through several devices in such complex infrastructure to obfuscate their footprints and overcome connectivity restrictions. However, prior pivot attack detection strategies present concerning limitations. This paper addresses an improvement of cyber defence with APIVADS, a novel adaptive pivoting detection scheme based on traffic flows to determine cyber adversaries’ presence based on their pivoting behaviour in simple and complex interconnected networks. Additionally, APIVADS is agnostic regarding transport and application protocols. The scheme is optimized and tested to cover remotely connected locations beyond a corporate campus’s perimeters. The scheme considers a hybrid approach between decentralized host-based detection of pivot attacks and a centralized approach to aggregate the results to achieve scalability. Empirical results from our experiments show the proposed scheme is efficient and feasible. For example, a 98.54% detection accuracy near real-time is achievable by APIVADS differentiating ongoing pivot attacks from regular enterprise traffic as TLS, HTTPS, DNS and P2P over the internet.
Rafael Salema Marques, Haider M. Al-Khateeb, Gregory Epiphaniou, Carsten Maple
IEEE Trans. Inf. Forensics Secur.3
2021 A privacy-preserving route planning scheme for the Internet of Vehicles
Ugur-Ilker Atmaca, Carsten Maple, Gregory Epiphaniou, Mehrdad Dianati
Ad Hoc Networks3
2021 Cyber security in the age of COVID-19: A timeline and analysis of cyber-crime and cyber-attacks during the pandemic
Harjinder Singh Lallie 0001, Lynsay A. Shepherd, Jason R. C. Nurse, Arnau Erola, Gregory Epiphaniou, Carsten Maple, Xavier J. A. Bellekens
Comput. Secur.5
2021 Integration of federated machine learning and blockchain for the provision of secure big data analytics for Internet of Things
Devrim Unal, Mohammad Hammoudeh, Muhammad Asif Khan 0001, Abdelrahman Abuarqoub, Gregory Epiphaniou, Ridha Hamila
Comput. Secur.5
2021 A Flow-based Multi-agent Data Exfiltration Detection Architecture for Ultra-low Latency Networks
abstract
Modern network infrastructures host converged applications that demand rapid elasticity of services, increased security, and ultra-fast reaction times. The Tactile Internet promises to facilitate the delivery of these services while enabling new economies of scale for high fidelity of machine-to-machine and human-to-machine interactions. Unavoidably, critical mission systems served by the Tactile Internet manifest high demands not only for high speed and reliable communications but equally, the ability to rapidly identify and mitigate threats and vulnerabilities. This article proposes a novel Multi-Agent Data Exfiltration Detector Architecture (MADEX), inspired by the mechanisms and features present in the human immune system. MADEX seeks to identify data exfiltration activities performed by evasive and stealthy malware that hides malicious traffic from an infected host in low-latency networks. Our approach uses cross-network traffic information collected by agents to effectively identify unknown illicit connections by an operating system subverted. MADEX does not require prior knowledge of the characteristics or behavior of the malicious code or a dedicated access to a knowledge repository. We tested the performance of MADEX in terms of its capacity to handle real-time data and the sensitivity of our algorithm’s classification when exposed to malicious traffic. Experimental evaluation results show that MADEX achieved 99.97% sensitivity, 98.78% accuracy, and an error rate of 1.21% when compared to its best rivals. We created a second version of MADEX, called MADEX level 2, that further improves its overall performance with a slight increase in computational complexity. We argue for the suitability of MADEX level 1 in non-critical environments, while MADEX level 2 can be used to avoid data exfiltration in critical mission systems. To the best of our knowledge, this is the first article in the literature that addresses the detection of rootkits real-time in an agnostic way using an artificial immune system approach while it satisfies strict latency requirements.
Rafael Salema Marques, Gregory Epiphaniou, Haider M. Al-Khateeb, Carsten Maple, Mohammad Hammoudeh, Paulo André Lima de Castro, Ali Dehghantanha, Kim-Kwang Raymond Choo
ACM Trans. Internet Techn.2
2020 Millimeter-Wave Communication for Internet of Vehicles: Status, Challenges, and Perspectives
abstract
The Internet of Vehicles has attracted a lot of attention in the automotive industry and academia recently. We are witnessing rapid advances in vehicular technologies that comprise many components, such as onboard units (OBUs) and sensors. These sensors generate a large amount of data, which can be used to inform and facilitate decision making (e.g., navigating through traffic and obstacles). One particular focus is for automotive manufacturers to enhance the communication capability of vehicles to extend their sensing range. However, the existing short-range wireless access, such as dedicated short-range communication (DSRC), and cellular communication, such as 4G, is not capable of supporting the high volume data generated by different fully connected vehicular settings. Millimeter-wave (mmWave) technology can potentially provide terabit data transfer rates among vehicles. Therefore, we present an in-depth survey of the existing research, published in the last decade, and we describe the applications of mmWave communications in vehicular communications. In particular, we focus on MAC and physical layers and discuss related issues, such as sensing-aware MAC protocol, handover algorithms, link blockage, and beamwidth size adaptation. Finally, we highlight various aspects related to smart transportation applications, and we discuss future research directions and limitations.
Kayhan Zrar Ghafoor, Linghe Kong, Sherali Zeadally, Ali Safa Sadiq, Gregory Epiphaniou, Mohammad Hammoudeh, Ali Kashif Bashir, Shahid Mumtaz
IEEE Internet Things J.5
2019 Non-interactive zero knowledge proofs for the authentication of IoT devices in reduced connectivity environments
Marcus Walshe, Gregory Epiphaniou, Haider M. Al-Khateeb, Mohammad Hammoudeh, Vasilios Katos, Ali Dehghantanha
Ad Hoc Networks2
2018 Physical characteristics of wireless communication channels for secret key establishment: A survey of the research
Mirko Bottarelli, Gregory Epiphaniou, Dhouha Kbaier Ben Ismail, Petros Karadimas, Haider M. Al-Khateeb
Comput. Secur.2
2018 Nonreciprocity Compensation Combined With Turbo Codes for Secret Key Generation in Vehicular Ad Hoc Social IoT Networks
abstract
The physical attributes of the dynamic vehicle-to-vehicle propagation channel can be utilized for the generation of highly random and symmetric cryptographic keys. However, in a physical-layer key agreement scheme, nonreciprocity due to inherent channel noise and hardware impairments can propagate bit disagreements. This has to be addressed prior to the symmetric key generation which is inherently important in Social Internet of Things networks, including in adversarial settings (e.g., battlefields). In this paper, we parametrically incorporate temporal variability attributes, such as 3-D scattering and scatterers' mobility. Accordingly, this is the first work to incorporate such features into the key generation process by combining nonreciprocity compensation with turbo codes (TCs). Preliminary results indicate a significant improvement when using TCs in bit mismatch rate and key generation rate in comparison to sample indexing techniques.
Gregory Epiphaniou, Petros Karadimas, Dhouha Kbaier Ben Ismail, Haider M. Al-Khateeb, Ali Dehghantanha, Kim-Kwang Raymond Choo
IEEE Internet Things J.1
2013 Internet of Things Forensics: Challenges and approaches
abstract
The scope of this paper is two-fold: firstly it proposes the application of a 1-2-3 Zones approach to Internet of Things (IoT)-related Digital Forensics (DF) investigations. Secondly, it introduces a Next-Best-Thing Triage (NBT) Model for use in conjunction with the 1-2-3 Zones approach where necess
Edewede Oriwoh, David Jazani, Gregory Epiphaniou, Paul Sant
CollaborateCom3
2012 Effects of iterative block ciphers on quality of experience for Internet Protocol Security enabled voice over IP calls
abstract
Voice over IP (VoIP) is the technology used to transport real-time voice over a packet-switched network. This study analyses the effects of encrypted VoIP streams on perceived Quality of Experience (QoE) from a user's perspective. An in-depth analysis on how the transparent nature of encryption can influence the way users perceive the quality of a VoIP call have been investigated by using the E model. A series of experiments have been conducted using a representative sample of modern codecs currently employed for digitising voice, as well as three of the most commonly used iterative block ciphers for encryption (DES, 3DES, AES). It has been found that the Internet Protocol Security encryption of VoIP strongly relates to the payload sizes and choice of codecs and this relationship has different effects on the overall QoE as measured by the E model, in terms of the way that users perceive the quality of a VoIP call. The main result of this paper is that the default payload shipped with the codecs is not the optimal selection for an increased number of VoIP calls, when encryption is applied and a minimum level of QoE has to be maintained, per call.
Gregory Epiphaniou, Carsten Maple, Paul Sant, Ghazanfar Ali Safdar
IET Inf. Secur.1
2010 Affects of Queuing Mechanisms on RTP Traffic: Comparative Analysis of Jitter, End-to-End Delay and Packet Loss
abstract
The idea of converging voice and data into a best-effort service network, such as the Internet, has rapidly developed the need to effectively define the mechanisms for achieving preferential handling of traffic. This sense of QoS assurance has increased due to the enormous growth of users accessing networks, different types of traffic competing for available bandwidth and multiple services running on the core network, defined by different protocols and vendors. VoIP traffic behaviour has become a crucial element of the intrinsic QoS mainly affected by jitter, latency and packet loss rates. This paper focuses on three different mechanisms, DropTail (FIFO), RED and DiffServ, and their effects on real-time voice traffic. Measurements of jitter, end-to-end delay and packet loss, based on simulation scenarios using the NS-2 network simulator are also presented and analyzed.
Gregory Epiphaniou, Carsten Maple, Paul Sant, Matthew Reeve
ARES1