EDBT 2026 Demo / reviewers in the wild / expert
John Hale
dblp:76/2017
· DBLP profile ↗
37ranked-venue papers
13as first author
6since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 10 first-author · 4 since 2021Artificial intelligence and machine learning · 7 · 3 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Tandem Approach to CPS Threat Modeling
Dallas Elleman, John Hale |
ICISSP (1) | 2 |
| 2026 | Words Matter: Integrating Adaptive Cybersecurity Phraseology in K-12 Education Subjects to Improve Cyber HygieneabstractThe increasing scope, scale, and stakes of cyber attacks motivates a heightened focus on cybersecurity. However, a knowledge gap in the workforce exists in both the technical and non-technical aspects of cybersecurity, creating a major hazard for critical infrastructures, the economy, and society. Closing this gap requires a multi-faceted approach, but of extreme importance is improving the cyber hygiene of the next generation of working professionals. This hard work begins with K-12 education and must span traditional disciplinary boundaries to address the pervasive role computers and networks now play in virtually every job function, role and vertical. We use the NICE Workforce Framework to derive a model of the most foundational cybersecurity concepts key to cyber hygiene. We apply this model within a novel methodology that helps educators strategically integrate adaptive cybersecurity phraseology within any K-12 subject to promote understanding of concepts central to cyber hygiene. Results from early experience in exercising the model and methodology suggest they may be practical and effective tools for enhancing cyber hygiene of K-12 students. Timothy Crisp, John Hale |
SIGCSE (1) | 2 |
| 2026 | Bending the curve: Operational cyber epidemiology for ransomwareabstractRansomware is often treated as a detection problem, but the most disruptive incidents behave more like outbreaks. A single foothold can spread through identities, administrative tools, and shared services while responders make time-critical decisions with incomplete visibility. This paper presents an operational cyber epidemiology framework that adapts the Susceptible-Exposed-Infectious-Removed (SEIR) model to ransomware incident management. In this ontology, Exposed denotes latent compromise and staging, including the dwell period before confirmed secondary compromise, while Infectious denotes active lateral propagation. Drawing on ISO 5477:2023 guidance for public health emergency preparedness and response information management and the 2025 UNDRR-ISC Hazard Information Profiles, the framework defines interoperable ransomware case definitions and Essential Elements of Information for cross-incident comparison. Basic and effective reproduction numbers, R0 and Re, are used as directional, near-real-time decision aids for security operations centers. Propagation state is separated from observation status to avoid confusing spread dynamics with detection capability. Publicly reported incidents, including WannaCry, NotPetya, SolarWinds, and MGM and Caesars, illustrate how outbreak-style measures can support earlier isolation, credential containment, and restoration sequencing. The paper also derives practical protection-threshold heuristics aimed at reducing Re below 1 and provides a tool-agnostic playbook card linking operational information to explicit action triggers. The primary contribution is a shared language that connects technical telemetry to containment decisions under resource constraints. Stephen Flowerday, Nikolay Lipskiy, Steven Furnell, Callum E. Flowerday, John Hale |
Comput. Secur. | 5 |
| 2025 | Blueprint for K-12 Cybersecurity Education: Integrating Cybersecurity Throughout All K-12 Subjects
Timothy Crisp, John Hale |
CRITIS | 2 |
| 2025 | CPSTRIDE: A Threat Modeling Framework for Cyber-Physical Systems
Dallas Elleman, John Hale |
CRITIS | 2 |
| 2024 | An Evaluation of Croatian ASR Models for Čakavian TranscriptionabstractTo assist in the documentation of Čakavian, an endangered language variety closely related to Croatian, we test four currently available ASR models that are trained with Croatian data and assess their performance in the transcription of Čakavian audio data. We compare the models’ word error rates, analyze the word-level error types, and showcase the most frequent Deletion and Substitution errors. The evaluation results indicate that the best-performing system for transcribing Čakavian was a CTC-based variant of the Conformer model. Shulin Zhang, John Hale, Margaret E. L. Renwick, Zvjezdana Vrzic, Keith Langston |
LREC/COLING | 2 |
| 2018 | LSTMs Can Learn Syntax-Sensitive Dependencies Well, But Modeling Structure Makes Them BetterabstractAdhiguna Kuncoro, Chris Dyer, John Hale, Dani Yogatama, Stephen Clark, Phil Blunsom. Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2018. Adhiguna Kuncoro, Chris Dyer, John Hale, Dani Yogatama, Stephen Clark, Phil Blunsom |
ACL (1) | 3 |
| 2017 | POSTER: Evaluating Reflective Deception as a Malware Mitigation StrategyabstractReflective Deception is a class of deception techniques designed to disrupt cyber attacks by confusing and frustrating the adversary. The technique is effective even in the absence of any detective capability. This poster will describe Reflective Deception and propose a testing platform for evaluating its efficacy and performance in the mitigation malware. Thomas Shaw, James Arrowood, Michael Kvasnicka, Shay Taylor, Kyle Cook, John Hale |
CCS | 6 |
| 2015 | Measuring the Potential for Victimization in Malicious ContentabstractSending malicious content to users for obtaining personnel, financial, or intellectual property has become a multi-billion dollar criminal enterprise. This content is primarily presented in the form of emails, social media posts, and phishing websites. User training initiatives seek to minimize the impact of malicious content through improved vigilance. Training works best when tailored to specific user deficiencies. However, tailoring training requires understanding how malicious content victimizes users. In this paper, we link a set of malicious content design factors, in the form of degradations and sophistications, to their potential to form a victimization prediction metric. The design factors examined are developed from an analysis of over 100 pieces of content from email, social media and websites. We conducted an experiment using a sample of the content and a game-based simulation platform to evaluate the efficacy of our victimization prediction metric. The experimental results and their analysis are presented as part of the evaluation. Matthew L. Hale, Rose F. Gamble, John Hale, Charles Haney, Charles Walter |
ICWS | 3 |
| 2015 | Robust wireless signal indoor localizationabstractSummary Localization is a key enabler of context awareness in computing environments. This paper presents a technique for indoor localization using wireless signal strength from mobile devices. The method described treats locations as fuzzy sets and fuzzifies signal strength‐related features to define membership. Membership values are then fused from multiple sources using a rule engine to deduce objective location values. The principal benefits of this technique are that it requires little or no calibration and that it can be used with widely available commercial devices. Simulation shows that this technique is robust to errors and provides reasonable accuracy. Applications to collaborative workflow and human computer interaction are discussed. Copyright © 2015 John Wiley & Sons, Ltd. Liang Kong 0002, Gavin Bauer, John Hale |
Concurr. Comput. Pract. Exp. | 3 |
| 2011 | Preserving Privacy in Structural Neuroimages
Nakeisha Schimke, Mary Kuehler, John Hale |
DBSec | 3 |
| 2007 | Redacting Digital Information from Electronic DevicesabstractRedaction is the process of removing privileged information from a document before it is presented to other parties. This paper discusses the major issues associated with the redaction of digital information from electronic devices. A novel technique involving a tokenized representation is presented as a solution to digital redaction in legal proceedings. Alex Barclay, L. Watson, David Greer, John Hale, Gavin Wylie Manes |
IFIP Int. Conf. Digital Forensics | 4 |
| 2006 | PCFGs with Syntactic and Prosodic Indicators of Speech RepairsabstractA grammatical method of combining two kinds of speech repair cues is presented. One cue, prosodic disjuncture, is detected by a decision tree-based ensemble classifier that uses acoustic cues to identify where normal prosody seems to be interrupted (Lickley, 1996). The other cue, syntactic parallelism, codifies the expectation that repairs continue a syntactic category that was left unfinished in the reparandum (Levelt, 1983). The two cues are combined in a Treebank PCFG whose states are split using a few simple tree transformations. Parsing performance on the Switchboard and Fisher corpora suggests that these two cues help to locate speech repairs in a synergistic way. John Hale, Izhak Shafran, Lisa Yung, Bonnie J. Dorr, Mary P. Harper, Anna Krasnyanskaya, Matthew Lease, Yang Liu 0004, Brian Roark, Matthew G. Snover, Robin Stewart |
ACL | 1 |
| 2006 | Reranking for Sentence Boundary Detection in Conversational SpeechabstractWe present a reranking approach to sentence-like unit (SU) boundary detection, one of the EARS metadata extraction tasks. Techniques for generating relatively small n-best lists with high oracle accuracy are presented. For each candidate, features are derived from a range of information sources, including the output of a number of parsers. Our approach yields significant improvements over the best performing system from the NIST RT-04F community evaluation Brian Roark, Yang Liu 0004, Mary P. Harper, Robin Stewart, Matthew Lease, Matthew G. Snover, Izhak Shafran, Bonnie J. Dorr, John Hale, Anna Krasnyanskaya, Lisa Yung |
ICASSP (1) | 9 |
| 2006 | SParseval: Evaluation Metrics for Parsing Speech
Brian Roark, Mary P. Harper, Eugene Charniak, Bonnie J. Dorr, Mark Johnson 0001, Jeremy G. Kahn, Yang Liu 0004, Mari Ostendorf, John Hale, Anna Krasnyanskaya, Matthew Lease, Izhak Shafran, Matthew G. Snover, Robin Stewart, Lisa Yung |
LREC | 9 |
| 2003 | Integrating Logics and Process Calculi for Cryptographic Protocol Analysis
Mauricio Papa, Oliver Bremer, John Hale, Sujeet Shenoi |
SEC | 3 |
| 2003 | Programmable Access ControlabstractSoftware developers rely on sophisticated programming language protection models and APIs to manifest security policies for Internet applications. These tools do not provide suitable expressiveness for fine-grained, configurable policies. Nor do they ensure the consistency of a given policy impleme ntation across objects in a heterogeneous environment. Programmable access control provides syntactic and semantic constructs in programming languages for systematically embedding security functionality within applications. Secure interoperability is of utmost importance in a distributed heterogeneous environment. This paper introduces a methodology for programmable security by language extension, as well as a prototype model and implementation of JPAC, a programmable access control extension to Java. A coordination language is also presented to support secure interoperability within the framework. John Hale, Mauricio Papa, Sujeet Shenoi |
J. Comput. Secur. | 1 |
| 2002 | On Modeling Computer Networks for Vulnerability Analysis
Clinton Campbell, Jerald Dawkins, Brandon Pollet, Kenneth Fitch, John Hale, Mauricio Papa |
DBSec | 5 |
| 2002 | Implementation and Verification of Programmable Security
Stephen Magill, Bradley Skaggs, Mauricio Papa, John Hale |
DBSec | 4 |
| 2001 | Public Telephone Network Vulnerabilities
G. Lorenz, Gavin Wylie Manes, John Hale, Sujeet Shenoi |
DBSec | 4 |
| 2001 | Formal Analysis of E-Commerce ProtocolsabstractThe paper presents a formalism for the analysis of e-commerce protocols. The approach integrates logics and process calculi, providing an expressive message passing semantics and sophisticated constructs for modeling principals. A common set of inference rules for communication, reduction and information analysis supports proofs about message passing, the knowledge and behavior of principals, and protocol properties. The power of the formalism is illustrated with an analysis of the NetBill Protocol. Mauricio Papa, Oliver Bremer, John Hale, Sujeet Shenoi |
ISADS | 3 |
| 2001 | A Probabilistic Earley Parser as a Psycholinguistic Model
John Hale |
NAACL | 1 |
| 2000 | Policy Mediation for Multi-Enterprise EnvironmentsabstractExisting software infrastructures and middleware provide uniform security services across heterogeneous information networks. However few, if any, tools exist that support access control policy management for and between large enterprise information networks. Insiders often exploit gaps in policies to mount devastating attacks. This paper presents a Policy Machine and Policy Mediation Architecture for coordinating diverse policies in large information networks. The language-based approach adopted by each of these technologies permits local and global access control policy validation with static analysis and other formal techniques. Together the Policy Machine and Policy Mediation Architecture comprise an effective system for closing policy gaps in multi-enterprise environments. Pablo Galiasso, Oliver Bremer, John Hale, Sujeet Shenoi, David F. Ferraiolo, Vincent C. Hu |
ACSAC | 3 |
| 2000 | Extending Java for Package based Access ControlabstractThis paper describes an extension of the Java language that provides programmable security. The approach augments the Java syntax with constructs for specifying various access control policies for Java packages, including DAC, MAC, RBAC and TBAC. A primitive ticket based mechanism serves as the foundation for programmable security. The implementation incorporates a preprocessor for language translation and a security service library that implements the ticket management infrastructure. The preprocessor translates the extended Java source code to native Java for eventual bytecode interpretation simultaneously binding security services to the native code. The design is simple and flexible and provides developers with an effective tool for programming security within Java packages. John Hale, Mauricio Papa, Oliver Bremer, Rodrigo Chandia, Sujeet Shenoi |
ACSAC | 1 |
| 2000 | Language Extensions for Programmable Security
John Hale, Rodrigo Chandia, Clinton Campbell, Sujeet Shenoi |
DBSec | 1 |
| 2000 | Simulation and Analysis of Cryptographic Protocols
Mauricio Papa, Oliver Bremer, Stephen Magill, John Hale, Sujeet Shenoi |
DBSec | 4 |
| 2000 | A Ticket-Based Access Control Architecture for Object SystemsabstractThe design and implementation of authorization services for distributed object systems are hindered by the semantic diversity of object models, the brittleness of access control mechanisms, and the lack of design and analysis tools. This paper presents a primitive ticket-based access control archit ecture that can model a variety of authorization policies. The access control architecture is integrated within a primitive distributed object model that can capture most distributed object languages and systems. The integration provides a common foundation for access control in heterogeneous distributed object systems, instrumental to achieving high assurance secure interoperability. John Hale, Jody Threet, Sujeet Shenoi |
J. Comput. Secur. | 1 |
| 1999 | Security Policy Coordination for Heterogeneous Information SystemsabstractCoordinating security policies in information enclaves is challenging due to their heterogeneity and autonomy. Administrators must reconcile the semantic diversity of data and security models before negotiating secure interoperation. This paper proposes an architecture that uses mediators and a primitive ticket-based authorization model to manage disparate policies in information enclaves. The formal foundation of the architecture facilitates static and dynamic analysis of global consistency and policy enforcement. John Hale, Pablo Galiasso, Mauricio Papa, Sujeet Shenoi |
ACSAC | 1 |
| 1998 | Programmable Security for Object-Oriented Systems
John Hale, Mauricio Papa, Sujeet Shenoi |
DBSec | 1 |
| 1997 | An Environment for Developing Securely Interoperable Heterogeneous Distributed Objects
M. Berryman, C. Rummel, Mauricio Papa, John Hale, Jody Threet, Sujeet Shenoi |
DBSec | 4 |
| 1997 | Capability-Based Primitives for Access Control in Object-Oriented Systems
John Hale, Jody Threet, Sujeet Shenoi |
DBSec | 1 |
| 1997 | Catalytic Inference Analysis: Detecting Inference Threats due to Knowledge DiscoveryabstractKnowledge discovery in databases can be enhanced by introducing "catalytic relations" conveying external knowledge. The new information catalyzes database inference, manifesting latent channels. Catalytic inference is imprecise in nature, but the granularity of inference may be fine enough to create security compromises. Catalytic inference is computationally intensive. However, it can be automated by advanced search engines that gather and assemble knowledge from information repositories. The relentless information gathering potential of such search engines makes them formidable security threats. This paper presents a formalism for modeling and analyzing catalytic inference in "mixed" databases containing various precise, imprecise and fuzzy relations. The inference formalism is flexible and robust, and well-suited to implementation. John Hale, Sujeet Shenoi |
S&P | 1 |
| 1996 | A Framework for High Assurance Security of Distributed Objects
John Hale, Jody Threet, Sujeet Shenoi |
DBSec | 1 |
| 1996 | Analyzing FD Inference in Relational Databases
John Hale, Sujeet Shenoi |
Data Knowl. Eng. | 1 |
| 1995 | A Tool for Inference Detection and Knowledge Discovery in Databases
Surath Rath, Dominic Jones, John Hale, Sujeet Shenoi |
DBSec | 3 |
| 1994 | Learning to Coordinate without Sharing Information
Sandip Sen, Mahendra Sekaran, John Hale |
AAAI | 3 |
| 1994 | A Practical Formalism for Imprecise Inference Control
John Hale, Jody Threet, Sujeet Shenoi |
DBSec | 1 |