EDBT 2026 Demo / reviewers in the wild / expert
Constantinos Patsakis
dblp:70/180 · also Costas Patsakis
· DBLP profile ↗
56ranked-venue papers
14as first author
25since 2021 · last 2026
0000-0002-4460-9331ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 34 · 8 first-author · 17 since 2021Artificial intelligence and machine learning · 10 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 4 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 6 · 3 first-authorComputer networks · 5 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Analysing Multidisciplinary Approaches to Fight Large-Scale Digital Influence Operations
David Arroyo, Rafael Mata Milla, Marc Almeida Ros, Nikolaos Lykousas, Ivan Homoliak, Constantinos Patsakis, Fran Casino |
ICISSP (1) | 6 |
| 2025 | Coding Malware in Fancy Programming Languages for Fun and ProfitabstractThe continuous increase in malware samples, both in sophistication and number, presents many challenges for organizations and analysts, who must cope with thousands of new heterogeneous samples daily.This requires robust methods to quickly determine whether a file is malicious.Due to its speed and efficiency, static analysis is the first line of defense.In this work, we illustrate how the practical state-of-the-art methods used by antivirus solutions may fail to detect evident malware traces.The reason is that they highly depend on very strict signatures where minor deviations prevent them from detecting shellcodes that otherwise would immediately be flagged as malicious.Thus, our findings illustrate that malware authors may drastically decrease the detections by converting the code base to less-used programming languages.To this end, we study the features that such programming languages introduce in executables and the practical issues that arise for practitioners to detect malicious activity. Theodoros Apostolopoulos, Vasilios Koutsokostas, Nikolaos Totosis, Constantinos Patsakis, Georgios Smaragdakis |
CODASPY | 4 |
| 2025 | Multi-Agent Reinforcement Learning for EV energy management and trading using the Lightning NetworkabstractMicropayments, involving low-value transactions (e.g., fractions of a euro/dollar), are critical for unlocking granular digital services. In this paper we present a novel highlevel architecture integrating artificial intelligence (AI) agents with the Bitcoin Lightning Network (LN) to enable efficient micropayments for electric vehicle (EV) charging and peer-to-peer energy trading. The proposed architecture leverages the ultra fast and low-cost nature of the LN to enforce trustless payments upon verified energy delivery. AI agents embedded in EVs and charging stations autonomously negotiate dynamic pricing and energy allocation using reinforcement learning (RL) approaches, optimizing grid load balancing and enhancing profitability compared to on-chain methods. Based on a comprehensive use case involving EV owners, operators and energy providers, we demonstrate the system’s viability, supported by a prototype implementation on the LN Testnet. Results show a $\mathbf{9 8. 2 \%}$ success rate for micropayments during simulated charging sessions, with AI agents reducing latency by prioritizing high-liquidity payment channels. Thomas K. Dasaklis, Panagiotis Giannopoulos, Vangelis Malamas, Georgios Tantis, Constantinos Patsakis |
CoDIT | 5 |
| 2025 | PRIVÉ: Towards Privacy-Preserving Swarm AttestationabstractIn modern large-scale systems comprising multiple heterogeneous devices, the introduction of swarm attestation schemes aims to alleviate the scalability and efficiency issues of traditional single-Prover and single-Verifier attestation. In this paper, we propose PRIVÉ, a privacy-preserving, scalable, and accountable swarm attestation scheme that addresses the limitations of existing solutions. Specifically, we eliminate the assumption of a trusted Verifier, which is not always applicable in real-world scenarios, as the need for the devices to share identifiable information with the Verifier may lead to the expansion of the attack landscape. To this end, we have designed an enhanced variant of the Direct Anonymous Attestation (DAA) protocol, offering traceability and linkability whenever needed. This enables PRIVÉ to achieve anonymous, privacy-preserving attestation while also providing the capability to trace a failed attestation back to the compromised device. To the best of our knowledge, this paper presents the first Universally Composable (UC) security model for swarm attestation accompanied by mathematical UC security proofs, as well as experimental benchmarking results that highlight the efficiency and scalability of the proposed scheme. Nada El Kassem, Wouter Hellemans, Ioannis Siachos, Edlira Dushku, Stefanos Vasileiadis, Dimitrios S. Karas, Liqun Chen 0002, Constantinos Patsakis, Thanassis Giannetsos |
SECRYPT | 8 |
| 2025 | Assessing the impact of packing on static machine learning-based malware detection and classification systemsabstractThe proliferation of malware, particularly through the use of packing, presents a significant challenge to static analysis and signature-based malware detection techniques. Applying packing to the original executable code renders extracting meaningful features and signatures challenging. To deal with the increasing amount of malware in the wild, researchers and anti-malware companies started harnessing machine learning capabilities with very promising results. However, little is known about the effects of packing on static machine learning-based malware detection and classification systems. This work addresses this gap by investigating the impact of packing on the performance of static machine learning-based models used for malware detection and classification, with a particular focus on those using visualization techniques. To this end, we present a comprehensive analysis of various packing techniques and their effects on the performance of machine learning-based detectors and classifiers. Our findings highlight the limitations of current static detection and classification systems and underscore the need to be proactive to effectively counteract the evolving tactics of malware authors. Daniel Gibert, Nikolaos Totosis, Constantinos Patsakis, Quan Le, Giulio Zizzo |
Comput. Secur. | 3 |
| 2025 | Beyond the sandbox: Leveraging symbolic execution for evasive malware classificationabstractThreat actors continuously update their code to incorporate counter-analysis techniques designed to evade detection and hinder the blocking of their malware. The first line of defence for malware authors is often to bypass static analysis, a relatively straightforward task using readily available tools such as packers and cryptors. To address this shortcoming, defenders send potential malware samples for execution in a sandbox environment. While sandboxing can provide valuable insights into the behaviour of software on an information system, advanced techniques like anti-virtualisation and hooking evasion allow malware to escape detection. The primary objective of this work is to complement sandbox execution with symbolic execution frameworks to detect new malware strains efficiently. Symbolic execution offers a distinct advantage over sandboxing by achieving greater coverage of all possible execution traces, as it can explore every potential execution path, regardless of the evasion methods employed by the malware authors. By carefully selecting the samples to be analysed, we can significantly reduce the workload while extracting essential dynamic features in a fraction of the time and with far fewer computational resources compared to sandboxing. To this end, we leverage machine learning in an automated pipeline, enabling the accurate detection of sophisticated malware using a real-world dataset. Our approach yields average F1 scores of 0.93 for the benign class and 0.99 for the malware class in a binary classification setup, surpassing the detection rates reported in the literature. Additionally, our method outperforms a commercial malware sandbox when applied to the same dataset, further highlighting the efficacy of the proposed method. Vasilis Vouvoutsis, Fran Casino, Constantinos Patsakis |
Comput. Secur. | 3 |
| 2024 | Outside the Comfort Zone: Analysing LLM Capabilities in Software Vulnerability Detection
Yuejun Guo 0001, Constantinos Patsakis, Qiang Tang 0001, Fran Casino |
ESORICS (1) | 2 |
| 2024 | Hello me, meet the real me: Voice synthesis attacks on voice assistants
Domna Bilika, Nikoletta Michopoulou, Efthymios Alepis, Constantinos Patsakis |
Comput. Secur. | 4 |
| 2024 | The anatomy of deception: Measuring technical and human factors of a large-scale phishing campaignabstractIn an era dominated by digital interactions, phishing campaigns have evolved to exploit not just technological vulnerabilities but also human traits. This study takes an unprecedented deep dive into large-scale phishing campaigns aimed at Meta's users, offering a dual perspective on the technical mechanics and human elements involved. Analysing data from over 25,000 victims worldwide, we highlight the nuances of these campaigns, from the intricate techniques deployed by the attackers to the sentiments and behaviours of those targeted. Unlike prior research conducted in controlled environments, this investigation capitalises on the vast, diverse, and genuine data extracted directly from active phishing campaigns, allowing for a more holistic understanding of the drivers, facilitators, and human factors. Through applying advanced computational techniques, including natural language processing and machine learning, this work unveils critical insights into the psyche of victims and the evolving tactics of modern phishers. Our analysis illustrates very poor password selection choices from the victims, with 30.27% of them picking low-complexity passwords and 58.23% reusing leaked passwords. Additionally, more than 10% exhibit strong persistence in re-victimisation by posting again to the phishing platforms of the same phishers. Finally, we reveal many correlations regarding demographics and the time periods when victims are more vulnerable during the day, as well as analyse the sentiment, emotion, and tone of text responses that they submitted, illustrating how convinced they were of the scam. Anargyros Chrysanthou, Yorgos Pantis, Constantinos Patsakis |
Comput. Secur. | 3 |
| 2024 | Decoding developer password patterns: A comparative analysis of password extraction and selection practicesabstractPasswords play a crucial role in authentication, ensuring that only authorised entities can access sensitive information. However, user password choices are often weak and predictable, making them susceptible to cyber-attacks. Additionally, hard-coded credentials in source code can expose organisations and infrastructure to significant risks. This paper explores the patterns of passwords used by developers, examining their similarities to those of typical users. We also investigate the efficacy of large language models (LLMs) in identifying hard-coded credentials in source code. Our findings suggest that developers foster more complex and, hence, more secure password selection patterns than regular users. Nevertheless, they can use worse patterns when the context allows them. The latter, combined with the ample commits in public code repositories containing secrets, exemplifies the need for more targeted awareness campaigns and tighter integration of code security tools in the development lifecycle. Finally, we explore the capacity of LLMs to detect hard-coded credentials, highlighting their differences and limitations. Nikolaos Lykousas, Constantinos Patsakis |
Comput. Secur. | 2 |
| 2024 | Assessing LLMs in malicious code deobfuscation of real-world malware campaignsabstractThe integration of large language models (LLMs) into various cybersecurity pipelines has become increasingly prevalent, enabling the automation of numerous manual tasks and often surpassing human performance. Recognising this potential, cybersecurity researchers and practitioners are actively investigating the application of LLMs to process vast volumes of heterogeneous data for anomaly detection, potential bypass identification, attack mitigation, and fraud prevention. Moreover, LLMs’ advanced capabilities in generating functional code, interpreting code context, and code summarisation present significant opportunities for reverse engineering and malware deobfuscation. In this work, we comprehensively examine the deobfuscation capabilities of state-of-the-art LLMs. Specifically, we conducted a detailed evaluation of four prominent LLMs using real-world malicious scripts from the notorious Emotet malware campaign. Our findings reveal that while current LLMs are not yet perfectly accurate, they demonstrate substantial potential in efficiently deobfuscating payloads. This study highlights the importance of fine-tuning LLMs for specialised tasks, suggesting that such optimisation could pave the way for future AI-powered threat intelligence pipelines to combat obfuscated malware. Our contributions include a thorough analysis of LLM performance in malware deobfuscation, identifying strengths and limitations, and discussing the potential for integrating LLMs into cybersecurity frameworks for enhanced threat detection and mitigation. Our experiments illustrate that LLMs can automatically and accurately extract the necessary indicators of compromise from a real-world campaign with an accuracy of 69.56% and 88.78% for the URLs and the corresponding domains of the droppers, respectively. Constantinos Patsakis, Fran Casino, Nikolaos Lykousas |
Expert Syst. Appl. | 1 |
| 2023 | What's Inside a Node? Malicious IPFS Nodes Under the Magnifying Glass
Christos Karapapas, George C. Polyzos, Constantinos Patsakis |
SEC | 3 |
| 2022 | Invoice #31415 attached: Automated analysis of malicious Microsoft Office documentsabstractMicrosoft Office may be by far the most widely used suite for processing documents, spreadsheets, and presentations. Due to its popularity, it is continuously utilised to carry out malicious campaigns. Threat actors, exploiting the platform’s dynamic features, use it to launch their attacks and penetrate millions of hosts in their campaigns. This work explores the modern landscape of malicious Microsoft Office documents, exposing the means that malware authors use. We leverage a taxonomy of the tools used to weaponise Microsoft Office documents and explore the modus operandi of malicious actors. Moreover, we generated and publicly shared a specially crafted dataset, which relies on incorporating benign and malicious documents containing many dynamic features such as VBA macros and DDE. The latter is crucial for a fair and realistic analysis, an open issue in the current state of the art. This allows us to draw safe conclusions on the malicious features and behaviour. More precisely, we extract the necessary features with an automated analysis pipeline to efficiently and accurately classify a document as benign or malicious using machine learning with an F1 score above 0.98, outperforming the current state of the art detection algorithms. Vasilios Koutsokostas, Nikolaos Lykousas, Theodoros Apostolopoulos, Gabriele Orazi, Amrita Ghosal, Fran Casino, Mauro Conti, Constantinos Patsakis |
Comput. Secur. | 8 |
| 2022 | Promoting smart tourism personalised services via a combination of deep learning techniques
Aristea Kontogianni, Efthymios Alepis, Constantinos Patsakis |
Expert Syst. Appl. | 3 |
| 2022 | On the effectiveness of binary emulation in malware classification
Vasilis Vouvoutsis, Fran Casino, Constantinos Patsakis |
J. Inf. Secur. Appl. | 3 |
| 2022 | On the Unbearable Lightness of FIPS 140-2 Randomness TestsabstractRandom number generation is critical to many applications. Gaming, gambling, and particularly cryptography all require random numbers that are uniform and unpredictable. For testing whether supposedly random sources feature particular characteristics commonly found in random sequences, batteries of statistical tests are used. These are fundamental tools in the evaluation of random number generators and form part of the pathway to certification of secure systems implementing them. Although there have been previous studies into this subject (Becker, 2013), RNG manufacturers and vendors continue to use statistical tests known to be of dubious reliability, in their RNG verification processes. Our research shows that FIPS-140-2 cannot identify adversarial biases effectively, even very primitive ones. Concretely, this work illustrates the inability of the FIPS 140 family of tests to detect bias in three obviously flawed PRNGs. Deprecated by official standards, these tests are nevertheless still widely used, for example in hardware-level self-test schemes incorporated into the design of many True RNGs (TRNGs). They are also popular with engineers and cryptographers for quickly assessing the randomness characteristics of security primitives and protocols, and even with manufacturers aiming to market the randomness features of their products to potential customers. In the following, we present threebiased-by-designRNGs to show in explicit detail how simple, glaringly obvious biases are not detected by any of the FIPS 140–2 tests. One of these RNGs is backdoored, leaking key material, while others suffer from significantly reduced unpredictability in their output sequences. To make our point even more straightforward, we show how files containing images can also fool the FIPS 140 family of tests. We end with a discussion on the security issues affecting an interesting and active project to create a randomness beacon. Their authors only tested the quality of their randomness with the FIPS 140 family of tests, and we will show how this has led them to produce predictable output that, albeit passing FIPS fails other randomness tests quite catastrophically. Darren Hurley-Smith, Constantinos Patsakis, Julio César Hernández Castro |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Python and Malware: Developing Stealth and Evasive Malware without Obfuscation
Vasilios Koutsokostas, Constantinos Patsakis |
SECRYPT | 2 |
| 2021 | EtherClue: Digital investigation of attacks on Ethereum smart contractsabstractProgramming errors in Ethereum smart contracts can result in catastrophic financial losses from stolen cryptocurrency. While vulnerability detectors can prevent vulnerable contracts from being deployed, this does not mean that such contracts will not be deployed. Once a vulnerable contract is instantiated on the blockchain and becomes the target of attacks, the identification of exploit transactions becomes indispensable in assessing whether it has been actually exploited and identifying which malicious or subverted accounts were involved. In this work, we study the problem of post-factum investigation of Ethereum attacks using Indicators of Compromise (IoC) specially crafted for use in the blockchain. IoC definitions need to capture the side-effects of successful exploitation in the context of the Ethereum blockchain. Therefore, we define a model for smart contract execution, comprising multiple abstraction levels that mirror the multiple views of code execution on a blockchain. Subsequently, we compare IoCs defined across the different levels in terms of their effectiveness and practicality through EtherClue, a prototype tool for investigating Ethereum security incidents. Our results illustrate that coarse-grained IoCs defined over blocks of transactions can detect exploit transactions with less computation. However, they are contract-specific and suffer from false negatives. On the other hand, fine-grained IoCs defined over virtual machine instructions can avoid these pitfalls at the expense of increased computation, which is nevertheless applicable for practical use. Simon Joseph Aquilina, Fran Casino, Mark Vella, Joshua Ellul, Constantinos Patsakis |
Blockchain Res. Appl. | 5 |
| 2021 | Unearthing malicious campaigns and actors from the blockchain DNS ecosystem
Fran Casino, Nikolaos Lykousas, Vasilios Katos, Constantinos Patsakis |
Comput. Commun. | 4 |
| 2021 | Large-scale analysis of grooming in modern social networks
Nikolaos Lykousas, Constantinos Patsakis |
Expert Syst. Appl. | 2 |
| 2021 | Resurrecting anti-virtualization and anti-debugging: Unhooking your hooks
Theodoros Apostolopoulos, Vasilios Katos, Kim-Kwang Raymond Choo, Constantinos Patsakis |
Future Gener. Comput. Syst. | 4 |
| 2021 | Introduction to the special issue on privacy and security for location-based services and devices
Luca Calderoni, Paolo Palmieri 0001, Constantinos Patsakis |
J. Inf. Secur. Appl. | 3 |
| 2021 | NodeXP: NOde.js server-side JavaScript injection vulnerability DEtection and eXPloitation
Christoforos Ntantogian, Panagiotis Bountakas, Dimitris Antonaropoulos, Constantinos Patsakis, Christos Xenakis |
J. Inf. Secur. Appl. | 4 |
| 2021 | Exploiting statistical and structural features for the detection of Domain Generation Algorithms
Constantinos Patsakis, Fran Casino |
J. Inf. Secur. Appl. | 1 |
| 2021 | Intercepting Hail Hydra: Real-time detection of Algorithmically Generated Domains
Fran Casino, Nikolaos Lykousas, Ivan Homoliak, Constantinos Patsakis, Julio César Hernández Castro |
J. Netw. Comput. Appl. | 4 |
| 2020 | Encrypted and covert DNS queries for botnets: Challenges and countermeasures
Constantinos Patsakis, Fran Casino, Vasilios Katos |
Comput. Secur. | 1 |
| 2020 | Delegated content erasure in IPFS
Eugenia A. Politou, Efthymios Alepis, Constantinos Patsakis, Fran Casino, Mamoun Alazab |
Future Gener. Comput. Syst. | 3 |
| 2019 | Behavioral Biometric Authentication in Android Unlock Patterns through Machine Learning
Sergio de los Santos, Efthymios Alepis, Constantinos Patsakis |
ICISSP | 4 |
| 2019 | Sharing Emotions at Scale: The Vent Dataset
Nikolaos Lykousas, Constantinos Patsakis, Andreas Kaltenbrunner, Vicenç Gómez |
ICWSM | 2 |
| 2019 | Profiling tax and financial behaviour with big data under the GDPR
Eugenia A. Politou, Efthymios Alepis, Constantinos Patsakis |
Comput. Law Secur. Rev. | 3 |
| 2019 | HEDGE: Efficient Traffic Classification of Encrypted and Compressed PacketsabstractAs the size and source of network traffic increase, so does the challenge of monitoring and analyzing network traffic. Therefore, sampling algorithms are often used to alleviate these scalability issues. However, the use of high entropy data streams, through the use of either encryption or compression, further compounds the challenge as current state-of-the-art algorithms cannot accurately and efficiently differentiate between encrypted and compressed packets. In this paper, we propose a novel traffic classification method named High Entropy DistinGuishEr (HEDGE) to distinguish between compressed and encrypted traffic. HEDGE is based on the evaluation of the randomness of the data streams and can be applied to individual packets without the need to have access to the entire stream. The findings from the evaluation show that our approach outperforms current state of the art. We also make available our statistically sound dataset, based on known benchmarks, to the wider research community. Fran Casino, Kim-Kwang Raymond Choo, Constantinos Patsakis |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Adult Content in Social Live Streaming Services: Characterizing Deviant Users and RelationshipsabstractSocial Live Stream Services (SLSS) exploit a new level of social interaction. One of the main challenges in these services is how to detect and prevent deviant behaviors that violate community guidelines. In this work, we focus on adult content production and consumption in two widely used SLSS, namely Live.me and Loops Live, which have millions of users producing massive amounts of video content on a daily basis. We use a pre-trained deep learning model to identify broadcasters of adult content. Our results indicate that moderation systems in place are highly ineffective in suspending the accounts of such users. We create two large datasets by crawling the social graphs of these platforms, which we analyze to identify characterizing traits of adult content producers and consumers, and discover interesting patterns of relationships among them, evident in both networks. Nikolaos Lykousas, Constantinos Patsakis, Vicenç Gómez |
ASONAM | 2 |
| 2018 | Knock-Knock: The Unbearable Lightness of Android NotificationsabstractAndroid Notifications can be considered as essential parts in Human-Smartphone interaction and inextricable modules of modern mobile applications that can facilitate User Interaction and improve User Experience. This paper presents how this well-crafted and thoroughly documented mechanism, provided by the OS can be exploited by an adversary. More precisely, we present attacks that result either in forging smartphone application notifications to lure the user in disclosing sensitive information, or manipulate Android Notifications to launch a Denial of Service attack to the users' device, locally and remotely, rendering them unusable. This paper concludes by proposing generic countermeasures for the discussed security threats. Constantinos Patsakis, Efthymios Alepis |
ICISSP | 1 |
| 2018 | Sensus Vox: Sentiment Mapping Through Smartphone Multi-Sensory CrowdsourcingabstractSentiment analysis is a rather intriguing subject that modern ICT tools enable us to explore and analyze. In this work we perform, to the best of our knowledge, the most wide analysis of sentiment mapping to geographic locations and time through smartphones, in an attempt to both visualize them and also reveal possible correlations and patterns. Our vast dataset consisting of more than 56.000 samples, from 100 individuals, for a time period of nine months, revealed patterns, both in space and time, that are directly linked to geographic locations of users and provide an aggregated real-time insight on how people feel, allowing for a wide range of applications. Angelos Fasoulis, Maria Virvou, George A. Tsihrintzis, Constantinos Patsakis, Efthymios Alepis |
ICTAI | 4 |
| 2018 | Backups and the right to be forgotten in the GDPR: An uneasy relationship
Eugenia A. Politou, Alexandra K. Michota, Efthymios Alepis, Matthias Pocs, Constantinos Patsakis |
Comput. Law Secur. Rev. | 5 |
| 2018 | The market's response toward privacy and mass surveillance: The Snowden aftermath
Constantinos Patsakis, Athanasios Charemis, Achilleas Papageorgiou, Dimitrios Mermigas, Sotirios Pirounias |
Comput. Secur. | 1 |
| 2018 | Session Fingerprinting in Android via Web-to-App IntercommunicationabstractThe extensive adoption of mobile devices in our everyday lives, apart from facilitating us through their various enhanced capabilities, has also raised serious privacy concerns. While mobile devices are equipped with numerous sensors which offer context-awareness to their installed apps, they can also be exploited to reveal sensitive information when correlated with other data or sources. Companies have introduced a plethora of privacy invasive methods to harvest users’ personal data for profiling and monetizing purposes. Nonetheless, up till now, these methods were constrained by the environment they operate, e.g., browser versus mobile app, and since only a handful of businesses have actual access to both of these environments, the conceivable risks could be calculated and the involved enterprises could be somehow monitored and regulated. This work introduces some novel user deanonymization approaches for device and user fingerprinting in Android. Having Android AOSP as our baseline, we prove that web pages, by using several inherent mechanisms, can cooperate with installed mobile apps to identify which sessions operate in specific devices and consequently further expose users’ privacy. Efthymios Alepis, Constantinos Patsakis |
Secur. Commun. Networks | 2 |
| 2017 | There's Wally! Location Tracking in Android without Permissions
Efthymios Alepis, Constantinos Patsakis |
ICISSP | 2 |
| 2017 | Mapping the Wireless Coverage Grid for Carrier and User Recommendations through CrowdsourcingabstractAs mobile devices have become an indefeasible part of people's everyday lives, the need arises to ensure that signal quality is at least fair, in the geographic areas that users tend to use their mobile terminals. In order to offer a valid feedback about signal coverage, we have developed a system that aims to utilize the power of participatory sensing, along with this of the crowd, in order to gather signal strength information in combination with location information. In particular, an android application is developed that gathers data required, which are then stored in a cloud, processed and ultimately displayed on a Google Maps interface. Upon initial review, it may seems that the aforementioned research can only benefit carriers. Within the scope of this article, though, we aim to propose a fair number of applications that can be empowered via our system, which are rewarding for individuals and other companies too. Efthymios Alepis, Aristea Kontogianni, Constantinos Patsakis |
ICTAI | 3 |
| 2017 | Trapped by the UI: The Android Case
Efthymios Alepis, Constantinos Patsakis |
RAID | 2 |
| 2017 | Context Dissemination for Dynamic Urban-Scale Applications
Alistair Morris, Constantinos Patsakis, Mélanie Bouroche, Vinny Cahill |
Mob. Networks Appl. | 2 |
| 2016 | Lightweight private proximity testing for geospatial social networks
Panayiotis Kotzanikolaou, Constantinos Patsakis, Emmanouil Magkos, Michalis Korakakis |
Comput. Commun. | 2 |
| 2015 | Privacy-Aware Genome Mining: Server-Assisted Protocols for Private Set Intersection and Pattern MatchingabstractThe Human Genome Project has generated a great wealth of information. Currently, almost all human genome has been sequenced and now it is time to identify the functionality of each gene. The sequence of base pairs accounts for approximately 3 billion elements. While there are many efficient algorithms and implementations to mine this information, doing it privately is a great challenge. Current state-of-the-art methods have improved their efficiency, but they are not practical yet. In this article, we introduce several protocols to drastically boost the performance of genome mining processes while guaranteeing privacy, thus, enabling practical implementations. We describe how to solve the private set intersection problem and a set of pattern matching queries with privacy. The proposed protocols are server-assisted and we prove that they are secure under the semi-honest model. We report the assessment of our solution using synthetic datasets and prove their efficiency. Constantinos Patsakis, Athanasios Zigomitros, Agusti Solanas |
CBMS | 1 |
| 2015 | Privacy and Security for Multimedia Content shared on OSNs: Issues and CountermeasuresabstractA key aspect of online social networks (OSNs) is the user-generated multimedia content shared online. OSNs like Facebook have to deal with up to 300 million photos uploaded on a daily basis, both video- and audio-related social networks have also started to gain important shares of the market. Although the security and privacy mechanisms deployed by OSNs can cope with several risks and discourage inexperienced users from malicious behaviours, many issues still need to be addressed. Uploaded multimedia content carries information that could be transmitted virally and almost instantaneously within OSNs and beyond. OSNs could be seen as a multimedia heaven for users. However, in many cases they might end up being the user's personal hell with information disclosure or distortion, contrary to his/her will. In this article, we outline the most significant security and privacy issues related to the exposure of multimedia content in OSNs and we discuss possible countermeasures. Constantinos Patsakis, Athanasios Zigomitros, Achilleas Papageorgiou, Agusti Solanas |
Comput. J. | 1 |
| 2015 | A k-anonymous approach to privacy preserving collaborative filtering
Fran Casino, Josep Domingo-Ferrer, Constantinos Patsakis, Domenec Puig, Agusti Solanas |
J. Comput. Syst. Sci. | 3 |
| 2014 | Privacy-Aware Large-Scale Virological and Epidemiological Data MonitoringabstractModern mobile and wearable devices are enabling the realization of so-called ubiquitous computing. This provides citizens the technological means to contribute to urban management by becoming sensors within a smart city. Notwithstanding, the health sector is a very crucial factor for city management, imposing restrictions to the decisions directly or indirectly. The question that arises is given the current technological advances, could we collect health related data from citizens without violating their privacy? In this work we propose a methodology that can be used to allow citizens to send their data without disclosing their identity, while simultaneously enabling almost real-time urban-scale virological and epidemiological data monitoring. Constantinos Patsakis, Michael Clear, Paul Laird, Athanasios Zigomitros, Mélanie Bouroche |
CBMS | 1 |
| 2014 | The Role of Inference in the Anonymization of Medical RecordsabstractThe quality of life has been significantly improved and one of the main reasons is the medical advances of the past decades. Nevertheless, to further advance the research and services in the field, practitioners, researchers and health organizations should share more information. While this need is indisputable, the sensitivity of the information demands that it is preprocessed, so that the published data are anonym zed and individuals cannot be identified. The scope of this work is to highlight the difficulties in providing automated anonymization approaches for medical records without consulting experts in the field. One of the major problems that is going to be highlighted is that Quasi-Identifiers (QI) are not independent. It is well known that combinations of QIs can be used to infer other relevant information. Nevertheless, this work tries to exploit the other way of information flow, we show how sensitive attributes can be exploited to derive information about the QIs, leading to many privacy hazards for the patients whose records are shared. To this extent, we illustrate some relevant examples and discuss probable counter-measures. Athanasios Zigomitros, Agusti Solanas, Constantinos Patsakis |
CBMS | 3 |
| 2014 | Private Aggregation with Custom Collusion Tolerance
Constantinos Patsakis, Michael Clear, Paul Laird |
Inscrypt | 1 |
| 2014 | Playing Hide and Seek with Mobile Dating Applications
Guojun Qin, Constantinos Patsakis, Mélanie Bouroche |
SEC | 2 |
| 2014 | Distributing privacy policies over multimedia content across multiple online social networks
Constantinos Patsakis, Athanasios Zigomitros, Achilleas Papageorgiou, Edgar Galván López |
Comput. Networks | 1 |
| 2014 | Towards a distributed secure in-vehicle communication architecture for modern vehicles
Constantinos Patsakis, Kleanthis Dellios, Mélanie Bouroche |
Comput. Secur. | 1 |
| 2014 | The relation between information security events and firm market value, empirical evidence on recent disclosures: An extension of the GLZ study
Sotirios Pirounias, Dimitrios Mermigas, Constantinos Patsakis |
J. Inf. Secur. Appl. | 3 |
| 2013 | A cryptographic approach for monitoring patients with mild cognitive impairment and dementiaabstractModern technological advances have enabled us to improve the quality of our lives, increasing the life expectancy as well, in almost every developed country. Therefore, a big part of the population, has reached older age. As a result, mild cognitive impairment and several types of dementia, are becoming a serious problem. Apart from medical care solutions, others are proposing modern technology based solutions. Patients are using geolocation devices, allowing tracing in case they have an accident, get lost or simply disoriented. Nevertheless, in the first stages cognitive impairment is not so dangerous, so patients have a high degree of autonomy. Forcing them to carry such devices, surely invades their privacy. This work proposes a novel, more privacy-aware method for sharing patient's information, using cryptographic primitives. Constantinos Patsakis |
CBMS | 1 |
| 2013 | Recovering RSA Private Keys on Implementations with Tampered LSBs
Constantinos Patsakis |
SECRYPT | 1 |
| 2012 | Securing In-vehicle Communication and Redefining the Role of Automotive Immobilizer
Constantinos Patsakis, Kleanthis Dellios |
SECRYPT | 1 |
| 2012 | Social Network Content Management through WatermarkingabstractDue to the rise of social media, several new needs, problems and challenges have emerged in users' privacy and security policies. Two very serious problems that should be addressed are identity theft and unauthorized content sharing. In this work we propose a more secure scheme for privacy in social networks by the use of watermarking that manages to diminish these problems, at least inside current social media architectures, without the need for building them from scratch. Athanasios Zigomitros, Achilleas Papageorgiou, Constantinos Patsakis |
TrustCom | 3 |