EDBT 2026 Demo / reviewers in the wild / expert
Erisa Karafili
dblp:66/8658
· DBLP profile ↗
15ranked-venue papers
5as first author
5since 2021 · last 2026
0000-0002-8250-4389ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Evolutionary Black-Box Framework for Adversarial Prompt Generation in Large Language ModelsabstractLarge language models (LLMs) remain susceptible to adversarial prompts that can bypass alignment mechanisms. Existing approaches to adversarial prompt generation typically rely on manual prompt engineering, helper LLMs, or white-box adversarial machine learning methods, which either lack scalability or require access to model internals. In this paper, we propose a novel black-box framework for automated adversarial prompt generation based on evolutionary algorithms. The framework is instantiated using a genetic algorithm and an evolution strategy and operates without access to internal model parameters, making it applicable to both open-source and proprietary LLMs. To improve search effectiveness under realistic query constraints, we introduce a novel population initialisation strategy based on templates, pre-prompts, and post-prompts. Evolutionary search is guided by heuristic, model-agnostic fitness signals derived from prompt goal semantic similarity, refusal based response assessment, and a small heuristic lexical bonus based on lightweight instruction-following indicators. We evaluate our framework across multiple LLMs using a refusal based attack success rate metric, demonstrating consistent improvements over direct dataset prompting and competitive performance against a state-of-the-art white-box baseline under comparable query budgets. Additional analyses examine fitness stabilisation and cross-model transferability for unseen models. Erisa Karafili |
CODASPY | 2 |
| 2024 | A Web Browser Plugin for Users' Security AwarenessabstractBrowsing online continues to pose a risk to the users’ privacy and security. There is a plethora of existing tools and solutions that aim at ensuring safe and private browsing but they are not used by the majority of the users due to the lack of ease of use or because they are too restrictive. In this work, we present a plugin for Google Chrome that aims to increase the users’ security awareness regarding the visited websites. We aim to provide the user with simple and understandable information about the security of the visited website. We evaluated our tool through a usability analysis and compared it with existing well-known solutions. Our study showed that our plugin ranking was high in the ease of use, and in the middle range for clarity, information provided, and overall satisfaction. Overall, our study showed that the users would like to use a tool that has ease of use but that also provides some simple security information about the visited website. Thomas Hoad, Erisa Karafili |
ARES | 2 |
| 2024 | AttackER: Towards Enhancing Cyber-Attack Attribution with a Named Entity Recognition Dataset
Pritam Deka, Sampath Rajapaksha, Ruby Rani, Amirah Almutairi, Erisa Karafili |
WISE (5) | 5 |
| 2023 | A Hybrid Threat Model for Smart SystemsabstractCyber-physical systems and their smart components have a pervasive presence in all our daily activities. Unfortunately, identifying the potential threats and issues in these systems and selecting enough protection is challenging given that such environments combine human, physical and cyber aspects to the system design and implementation. Current threat models and analysis do not take into consideration all three aspects of the analyzed system, how they can introduce new vulnerabilities or protection measures to each other. In this work, we introduce a novel threat model for cyber-physical systems that combines the cyber, physical, and human aspects. Our model represents the system's components relations and security properties by taking into consideration these three aspects. Together with the threat model we also propose a threat analysis method that allows understanding the security state of the system's components. The threat model and the threat analysis have been implemented into an automatic tool, called TAMELESS, that automatically analyzes threats to the system, verifies its security properties, and generates a graphical representation, useful for security architects to identify the proper prevention/mitigation solutions. We show and prove the use of our threat model and analysis with three cases studies from different sectors. Fulvio Valenza, Erisa Karafili, Rodrigo Vieira Steiner, Emil C. Lupu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Forensic analysis of Tor in Windows environment: A case studyabstractThe Tor browser is a popular tool that is used by many users around the world. The browser is common among cyber criminals who use the tool to hide their activities. Until now, little research has been conducted by forensics researchers on the Tor browser, its application, and the data that can be obtained from the artefacts generated from its execution. In this work, we present a forensics analysis of the footprint left by the Tor application in the Windows environment. Our analysis focuses on three critical areas that are examined: network, memory, and hard disk. We provide a methodology that allows a structured forensic investigation. In this work, we examine multiple tools’ abilities in obtaining artefacts. The artefacts were identified not only when the Tor browser was running, but also when it was closed and uninstalled. We provide a methodology to analyse Tor applications with a focused case study of the Tor browser, allowing investigators to analyse Tor browsers and reproduce our results. Vaia-Maria Angeli, Ahmad Atamli-Reineh, Erisa Karafili |
ARES | 3 |
| 2020 | Towards a Framework for Automatic Firewalls Configuration via Argumentation ReasoningabstractFirewalls have been widely used to protect not only small and local networks but also large enterprise networks. The configuration of firewalls is mainly done by network administrators, thus, it suffers from human errors. This paper aims to solve the network administrators’ problem by introducing a formal approach that helps to configure centralized and distributed firewalls and automatically generate conflict-free firewall rules. We propose a novel framework, called ArgoFiCo, which is based on argumentation reasoning. Our framework automatically populates the firewalls of a network, given the network topology and the high-level requirements that represent how the network should behave. ArgoFiCo provides two strategies for firewall rules distribution. Erisa Karafili, Fulvio Valenza, Emil C. Lupu |
NOMS | 1 |
| 2018 | A Formal Approach to Analyzing Cyber-Forensics Evidence
Erisa Karafili, Matteo Cristani, Luca Viganò 0001 |
ESORICS (1) | 1 |
| 2018 | Helping Forensic Analysts to Attribute Cyber-Attacks: An Argumentation-Based Reasoner
Erisa Karafili, Linna Wang, Antonis C. Kakas, Emil C. Lupu |
PRIMA | 1 |
| 2017 | Improving data sharing in data rich environmentsabstractThe increasing use of big data comes along with the problem of ensuring correct and secure data access. There is a need to maximise the data dissemination whilst controlling their access. Depending on the type of users different qualities and parts of data are shared. We introduce an alteration mechanism, more precisely a restriction one, based on a policy analysis language. The alteration reflects the level of trust and relations the users have, and are represented as policies inside the data sharing agreements. These agreements are attached to the data and are enforced every time the data are accessed, used or shared. We show the use of our alteration mechanism with a military use case, where different parties are involved during the missions, and they have different relations of trust and partnership. Erisa Karafili, Emil C. Lupu, Alan Cullen, Bill Williams, Saritha Arunkumar, Seraphin B. Calo |
IEEE BigData | 1 |
| 2017 | Enabling Data Sharing in Contextual Environments: Policy Representation and AnalysisabstractInternet of Things environments enable us to capture more and more data about the physical environment we live in and about ourselves. The data enable us to optimise resources, personalise services and offer unprecedented insights into our lives. However, to achieve these insights data need to be shared (and sometimes sold) between organisations imposing rights and obligations upon the sharing parties and in accordance with multiple layers of sometimes conflicting legislation at international, national and organisational levels. In this work, we show how such rules can be captured in a formal representation called "Data Sharing Agreements". We introduce the use of abductive reasoning and argumentation based techniques to work with context dependent rules, detect inconsistencies between them, and resolve the inconsistencies by assigning priorities to the rules. We show how through the use of argumentation based techniques use-cases taken from real life application are handled flexibly addressing trade-offs between confidentiality, privacy, availability and safety. Erisa Karafili, Emil C. Lupu |
SACMAT | 1 |
| 2016 | Defeasible Reasoning about Electric ConsumptionsabstractConflicting rules and rules with exceptions are very common in natural language specification to describe the behaviour of devices operating in a real-world context. This is common exactly because those specifications are processed by humans, and humans apply common sense and strategic reasoning about those rules. In this paper, we deal with the challenge of providing, step by step, a model of energy saving rule specification and processing methods that are used to reduce the consumptions of a system of devices. We argue that a very promising non-monotonic approach to such a problem can lie upon Defeasible Logic. Starting with rules specified at an abstract level, but compatibly with the natural aspects of such a specification (including temporal and power absorption constraints), we provide a formalism that generates the extension of a basic defeasible logic, which corresponds to turned on or off devices. Matteo Cristani, Claudio Tomazzoli, Erisa Karafili, Francesco Olivieri |
AINA | 3 |
| 2016 | Formalizing Threat Models for Virtualized Systems
Daniele Sgandurra, Erisa Karafili, Emil C. Lupu |
DBSec | 2 |
| 2015 | Improving Energy Saving Techniques by Ambient Intelligence SchedulingabstractEnergy saving is one of the most challenging aspects of modern ambient intelligence technologies, for both domestic and business usages. In this paper we show how to combine Ambient Intelligence and Artificial Intelligence techniques to solve the problem of scheduling a set of devices under a given set of constraints, like limits to the maximal energy usage (Energy Span) and maximal energy absorption (Energy Peak). We provide a method that can be used to schedule the usage of devices in a given environment in a way that respects the input constraints. We adapt an existent approach to scheduling for Ambient Intelligence to a specific framework and exhibit a sample usage for a real life system, Elettra, that is in use in an industrial context. Matteo Cristani, Erisa Karafili, Claudio Tomazzoli |
AINA | 2 |
| 2013 | A complete tableau procedure for risk analysisabstractIn many real-life situations making a decision entails evaluating the risks associated with the decision, which in turn requires reasoning about events and their relations. In addition to the simpler and better-understood notions of causation and precondition, in this paper we focus on block (or prevention), which is the relation established between an event φ1and another event φ2such that the number of occurrences of φ2decreases whenever φ1occurs, and mitigation, where the occurrence of φ1reduces the “negative” (for the particular decision we are considering) consequences of the occurrence of φ2. By introducing two further counting operators and the notion of interval of observation, we give here a sound and complete tableau system along with a systematic tableau construction procedure. Matteo Cristani, Erisa Karafili, Luca Viganò 0001 |
CRiSIS | 2 |
| 2011 | Blocking Underhand Attacks by Hidden Coalitions
Matteo Cristani, Erisa Karafili, Luca Viganò 0001 |
ICAART (2) | 2 |