EDBT 2026 Demo / reviewers in the wild / expert
Rafal Kozik
dblp:80/2851
· DBLP profile ↗
72ranked-venue papers
15as first author
43since 2021 · last 2026
0000-0001-7122-3306ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 29 · 8 first-author · 23 since 2021Security and privacy · 21 · 4 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 9 · 3 first-author · 9 since 2021Software engineering, systems software and programming languages · 3Theory of computation · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Computer networks · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Survey on Explainability-Weaponising Adversarial Attack Vectors against Deep Neural Networks and Artificial Intelligence
Marek Pawlicki, Ryszard S. Choras, Rafal Kozik, Michal Choras |
ICAART (2) | 3 |
| 2026 | GRA-FIN: New method of large graphs reduction for financial transactions and financial crime analysis
Rafal Kozik, Piotr Gocal, Michal Choras |
Knowl. Based Syst. | 1 |
| 2025 | Application of Selected Machine Learning Models in Leaf-Based Plant Health Assessment
Jakub Filipek, Marek Pawlicki, Ryszard S. Choras, Rafal Kozik, Aleksandra Pawlicka, Michal Choras |
AINA (6) | 4 |
| 2025 | Evaluation of Selected Few-Shot Learning Methods in Network Intrusion Detection
Eryk Winiecki, Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras |
AINA (6) | 4 |
| 2025 | From Relevance to Discovery: Trends in Overcoming Information Bubbles
Michal Lesniak, Rafal Kozik |
ICCCI (2) | 2 |
| 2025 | Evaluating the Strategy to Deploy Large Language Models to Label Training Data in the Process of Fake News Detection
Martyna Tarczewska, Rafal Kozik, Michal Choras |
ICCCI (1) | 2 |
| 2025 | In depth analysis for securing the truth: Addressing the fake news challenge with graph neural networksabstractThe fake news phenomenon has a significant impact on societies, homeland security, democracy and the functioning of the public space. The spread of false information is becoming an increasing challenge in the context of the dynamic growth of the volume of content shared by news outlets and social media. The overwhelming amount of this information makes manual verification of every news item or press release practically impossible. The current development of technology in the field of natural language processing (NLP) opens up new possibilities for the development of automatic content verification systems. The automation of this process not only improves but also significantly speeds up the detection of unreliable information, which is a key tool in the fight against fake news. In this article, we propose an innovative approach that involves a multi-factor assessment of the content of documents, as opposed to the frequently used approach of binary classification into fake and non-fake. Our classification system is based on analysis using graph neural networks, which allows for a more complex and contextual understanding of the data. The obtained results indicate a significant improvement in effectiveness compared to the baseline approaches, which suggests a potential for enhanced mitigation of misinformation dissemination. Gracjan Katek, Rafal Kozik, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras |
Neurocomputing | 2 |
| 2025 | A meta-survey of adversarial attacks against artificial intelligence algorithms, including diffusion modelsabstractDeep neural networks have revolutionized artificial intelligence, solving complex issues in areas like healthcare or law enforcement and security. However, they are susceptible to adversarial attacks where small data manipulations can compromise system reliability and security. This paper conducts an umbrella review of the literature on these attacks, synthesizing results from various systematic reviews to assess attack strategies, defense effectiveness, and research gaps. Guided by the PICO framework, this review categorizes and examines adversarial attacks, identifying key challenges in the field. The review finds that even though adversarial vulnerabilities were first explored in computer vision, analogous threats have expanded to domains like graph neural networks, natural language processing, federated learning, and text-to-image models. Despite varied attack surfaces, commonalities can be found. • First umbrella review synthesising systematic reviews and meta-analyses of adversarial attacks on deep neural networks, including the emerging threat to diffusion-based generative models. • PICO-driven framework addressing three research questions: (1) mapping survey themes and methods, (2) comparing domain-specific attack strategies, (3) identifying universal adversarial characteristics. • Comprehensive taxonomy covering gradient-based, transfer-based, score-based, decision-based, black-box, poisoning, privacy, and universal adversarial attacks. • Domain-specific analysis across computer vision, natural language processing, graph neural networks, intrusion detection systems, federated learning, GANs/VAEs, and text-to-image models like Stable Diffusion. Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras |
Neurocomputing | 3 |
| 2024 | Enhancing Network Security Through Granular Computing: A Clustering-by-Time Approach to NetFlow Traffic AnalysisabstractThis paper presents a study of the effect of the size of the time window from which network features are derived on the predictive ability of a Random Forest classifier implemented as a network intrusion detection component. The network data is processed using granular computing principles, gradually increasing the time windows to allow the detection algorithm to find patterns in the data at different levels of granularity. Experiments were conducted iteratively with time windows ranging in size from 2 to 1024 seconds. Each iteration involved time-based clustering of the data, followed by splitting into training and test sets at a ratio of 67% - 33%. The Random Forest algorithm was applied as part of a 10-fold cross-validation. Assessments included standard detection metrics: accuracy, precision, F1 score, BCC, MCC and recall. The results show a statistically significant improvement in the detection of cyber attacks in network traffic with a larger time window size (p-value 0.001953125). These results highlight the effectiveness of using longer time intervals in network data analysis, resulting in increased anomaly detection. Mikolaj Komisarek, Marek Pawlicki, Salvatore D'Antonio, Rafal Kozik, Aleksandra Pawlicka, Michal Choras |
ARES | 4 |
| 2024 | Introducing a Multi-Perspective xAI Tool for Better Model ExplainabilityabstractThis paper introduces an innovative tool equipped with a multi-perspective, user-friendly dashboard designed to enhance the explainability of AI models, particularly in cybersecurity. By enabling users to select data samples and apply various xAI methods, the tool provides insightful views into the decision-making processes of AI systems. These methods offer diverse perspectives and deepen the understanding of how models derive their conclusions, thus demystifying the "black box" of AI. The tool’s architecture facilitates easy integration with existing ML models, making it accessible to users regardless of their technical expertise. This approach promotes transparency and fosters trust in AI applications by aligning decision-making with domain knowledge and mitigating potential biases. Marek Pawlicki, Damian Puchalski, Sebastian Szelest, Aleksandra Pawlicka, Rafal Kozik, Michal Choras |
ARES | 5 |
| 2024 | Trustworthy AI-based Cyber-Attack Detector for Network Cyber Crime ForensicsabstractIn recent years, the increasing sophistication and proliferation of cyberthreats have underscored the necessity for robust network security measures, as well as a comprehensive approach to cyberprotection at large. As cyberthreats are continuously more and more complex, and their detection, response and mitigation often involve dealing with big data, the need for novel solutions is present also in cyber-criminal law enforcement (LEA) and network forensics contexts. Traditional, anomaly-based or signature-based intrusion detection systems (IDS) often face challenges in adapting to the evolving cyberattack landscape. On the other hand, Machine Learning (ML) has emerged as a promising approach, proving its ability to detect complex patterns in big data, including applications such as intrusion detection and classification of threats in the network environment, with high accuracy and precision (reduced rate of false positives). In this paper we present the Trustworthy Cyberattack Detector tool (TCAD), benefiting from the machine learning algorithms for the detection and classification of cyberattacks. TCAD can be used for monitoring the network in real-time and for offline analysis of collected network data. We believe that the TCAD can be successfully applied for the task of detecting and classifying evidence during criminal investigations related to network cyber attacks, but also can be helpful for the correlation of discovered network-based events over time with other collected non-network evidence. Damian Puchalski, Marek Pawlicki, Rafal Kozik, Rafal Renk, Michal Choras |
ARES | 3 |
| 2024 | Involving Society to Protect Society from Fake News and Disinformation: Crowdsourced Datasets and Text Reliability Assessment
Gracjan Katek, Marta Gackowska, Joanna Komorniczak, Pawel Ksieniewicz, Rafal Kozik, Marek Pawlicki, Michal Choras |
ACIIDS (2) | 5 |
| 2024 | ULTIMATE Project Toolkit for Robotic AI-Based Data Analysis and Visualization
Rafal Kozik, Damian Puchalski, Aleksandra Pawlicka, Szymon Bus, Jakub Glówka, Krishna Chandramouli, Marco Tiemann, Marek Pawlicki, Rafal Renk, Michal Choras |
ACIIDS (2) | 1 |
| 2024 | A Novel Approach to the Use of Explainability to Mine Network Intrusion Detection Rules
Federica Uccello, Marek Pawlicki, Salvatore D'Antonio, Rafal Kozik, Michal Choras |
ACIIDS (1) | 4 |
| 2024 | When an Old Telecommunication Law Meets Generative AI: the Manifesto to Unbundle AIabstractThe emergence and consecutive entrance of Generative AI (particularly ChatGPT) into the mainstream has provoked all kinds of reactions, from excitement to apprehension, but it has not been definitely decided whether it is a boon or a bane yet. We wish to voice the still unmentioned relation between AI accessibility and social injustice. So far, the initial access to tools such as ChatGPT has been free or low-cost. This is predicated on the availability of open-source or inexpensively sourced data. As the value of models hinges upon high quality, diverse data, the demand for it will increase, resulting in the rising costs of its procuration. We worry that the free models will then turn into expensive commodities, limiting their use only to the privileged entities. This potential shift causes major concerns about ethics and social equity, with the concept of unbundling being one of the potential solutions. Aleksandra Pawlicka, Marek Pawlicki, Dagmara Jaroszewska-Choras, Damian Puchalski, Rafal Kozik, Michal Choras |
IEEE Big Data | 5 |
| 2024 | When explainability turns into a threat - using xAI to fool a fake news detection methodabstractThe inclusion of Explainability of Artificial Intelligence (xAI) has become a mandatory requirement for designing and implementing reliable, interpretable and ethical AI solutions in numerous domains. xAI is now the subject of extensive research, from both the technical and social science perspectives. It is being received enthusiastically by legislative bodies and regular users of machine-learning-boosted applications alike. However, opening the black box of AI comes at a cost. This paper presents the results of the first study proving that xAI can enable successful adversarial attacks in the domain of fake news detection and lead to a decrease in AI security. We postulate the novel concept that xAI and security should strike a balance, especially in critical applications, such as fake news detection. An attack scheme against fake news detection methods is presented that employs an explainable solution. The described experiment demonstrates that the well-established SHAP explainer can be used to reshape the structure of the original message in such a way that the value of the model's prediction could be arbitrarily forced, whilst the meaning of the message stays the same. The paper presents various examples for which the SHAP values are used to point the adversary to the words and phrases that have to be changed to flip the label on the model prediction. To the best of the authors' knowledge, it has been the first research work to experimentally demonstrate the sinister side of xAI. As the generation and spreading of fake news has become a tool of modern warfare and a grave threat to democracy, the potential impact of explainable AI should be addressed as soon as possible. Rafal Kozik, Massimo Ficco, Aleksandra Pawlicka, Marek Pawlicki, Francesco Palmieri 0002, Michal Choras |
Comput. Secur. | 1 |
| 2024 | Towards explainable fake news detection and automated content credibility assessment: Polish internet and digital media use-case
Rafal Kozik, Gracjan Katek, Marta Gackowska, Sebastian Kula, Joanna Komorniczak, Pawel Ksieniewicz, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras |
Neurocomputing | 1 |
| 2024 | Advanced insights through systematic analysis: Mapping future research directions and opportunities for xAI in deep learning and artificial intelligence used in cybersecurityabstractThis paper engages in a comprehensive investigation concerning the application of Explainable Artificial Intelligence (xAI) within the context of deep learning and Artificial Intelligence, with a specific focus on its implications for cybersecurity. Firstly, the paper gives an overview of xAI techniques and their significance and benefits when applied in cybersecurity. Subsequently, the authors methodically delineate their systematic mapping study, which serves as an investigative tool for discerning the potential trajectory of the field. This strategic methodological framework lets one identify the future research directions and opportunities that underlie the integration of xAI within the realm of Deep Learning, Artificial Intelligence, and cybersecurity, which are described in-depth. Then, the paper brings together all the gathered insights from this extensive investigation and closes with final conclusions. Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras |
Neurocomputing | 3 |
| 2024 | Evaluating the necessity of the multiple metrics for assessing explainable AI: A critical examinationabstractThis paper investigates the specific properties of Explainable Artificial Intelligence (xAI), particularly when implemented in AI/ML models across high-stakes sectors, in this case cybersecurity. The authors execute a comprehensive systematic review of xAI properties, various evaluation metrics, and existing frameworks to assess their utility and relevance. Subsequently, the experimental sections evaluate selected xAI techniques against these metrics, delivering key insights into their practical utility and effectiveness. The findings highlight that the proliferation of metrics enhances the understanding of xAI systems but simultaneously exposes challenges such as metric duplication, inefficacy, and confusion. These issues underscore the pressing need for standardized evaluation frameworks to streamline their application and strengthen their effectiveness, thereby improving the overall utility of xAI in critical domains. Marek Pawlicki, Aleksandra Pawlicka, Federica Uccello, Sebastian Szelest, Salvatore D'Antonio, Rafal Kozik, Michal Choras |
Neurocomputing | 6 |
| 2024 | AI vs linguistic-based human judgement: Bridging the gap in pursuit of truth for fake news detection
Aleksandra Pawlicka, Marek Pawlicki, Rafal Kozik, Agnieszka Andrychowicz-Trojanowska, Michal Choras |
Inf. Sci. | 3 |
| 2024 | A Meta-Analysis of State-of-the-Art Automated Fake News Detection MethodsabstractRecently, various artificial intelligence (AI)-based methods have been proposed to support humans in detecting disinformation and fake news. The goal of this article is to provide a meta-analysis, and formally evaluate, compare, and benchmark various classes of fake news detection approaches. To this end, the following paper performs a comprehensive analysis of the performance-related results of different models using a range of benchmark datasets. The performed and disclosed meta-analysis compares the statistical significance of differences in a range of performance metrics, including precision,$F1$-score, recall, and balanced accuracy (BACC). The utilized approach features the$5$$\times$$2$cross-validation methodology. The models undergoing the formal evaluation constitute state-of-the-art (SOTA) solutions meeting acceptance criteria. The evaluated approaches draw from the most recent advancements in natural language processing (NLP). The outcome of this work is the formal benchmarking and meta-analysis of fake news detection methods that can be further utilized by the research community, but more importantly by the practitioners and decision-makers that counter fake news on a daily basis, e.g., in press agencies, homeland security agencies, fact-checkers, and so on. This work is the natural extension of the authors’ previous systematic analysis of fake news detection methods and authors’ own fake news detection methods based on machine learning (ML)/artificial intelligence (AI) techniques. Rafal Kozik, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras, Wojciech Mazurczyk, Krzysztof Cabaj |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2023 | Modern NetFlow network dataset with labeled attacks and detection methodsabstractNetwork Intrusion Detection Systems are an important part of cyber-defensive inventory. Currently, Machine-Learning-Based Network Intrusion Detection Systems are being researched as an effective security measure. This paper introduces a novel NetFlow-based dataset geared for the training of machine-learning-based detection systems. The dataset incorporates common cyberattacks such as Denial-of-Service, Port Scanning, and brute-force attacks, which represent significant threats to network security. The efficacy of the dataset is evaluated with the use of four machine learning algorithms, with the detection metrics reported. The dataset is an attempt to fill the vacuum for current, realistic datasets in cybersecurity research. The traffic was collected in a real network in the BTC complex in Ljubljana. The dataset can significantly contribute to enhancing the effectiveness of machine learning-based Network Intrusion Detection Systems. Mikolaj Komisarek, Marek Pawlicki, Tomi Simic, David Kavcnik, Rafal Kozik, Michal Choras |
ARES | 5 |
| 2023 | Security Architecture in the SILVANUS projectabstractSILVANUS is a new EU-funded project whose main objectives are to address the causes of wildfires in Europe. To achieve this aim, a dedicated platform for environmentally sustainable and climate-resilient forest management has been developed with the help of many state-of-the-art, modern technologies. One of the major challenges to solve when building such a heterogeneous, multi-component, multipurpose platform is to provide the necessary security architecture. It should ensure that only trusted users and devices (e.g., sensors, drones, UGVs, etc.) would be allowed to use it, and attackers or other third parties would not jeopardize its communication and assets. In this paper, we outline the main design principles, solutions, and mechanisms we have considered when building the security architecture for the SILVANUS platform. Moreover, we present the current state of development of this platform and the main challenges we have been facing. Natan Orzechowski, Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk, Helen-Catherine Leligou, Marcin Przybyszewski, Rafal Kozik, Michal Choras |
ARES | 8 |
| 2023 | Combating Disinformation with Holistic Architecture, Neuro-symbolic AI and NLU ModelsabstractIt is important to realize that false news is more than just a deception. Sadly, it is impossible to confirm every bit of information we come across. A normal human impulse is to accept any information that looks sufficiently convincing, relevant, or exciting. In doing so, we often do not realize that we have just contributed to the misinformation of the community to which we belong. As a result, fake news happens to be our collective error. In this paper, we propose an architecture for combating the disinformation problem using a hybrid-based approach. We demonstrate our preliminary results on the health-related fake news dataset. Rafal Kozik, Wojciech Mazurczyk, Krzysztof Cabaj, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras |
DSAA | 1 |
| 2023 | Model Stitching Algorithm for Fake News Detection ProblemabstractNowadays, we can see how social media networks are developing. We must accept the fact that the opinion of an expert is frequently just as valuable and crucial as that of a non-expert. It is feasible to see how traditional media is undergoing changes and processes that diminish the importance of the traditional ”editing office” and place a growing focus on journalists’ remote labour.As a result, social media has evolved into a component of national security since fake news and disinformation spread by nefarious individuals can influence readers and spark pointless debates on social issues that are inherently unimportant. This has a domino effect, instils dread in the populace, and eventually puts the security of the state in jeopardy.Recently, deep machine learning techniques have proven to be one of the technologies thought to be an effective way to combat the false news problem. However, due to shortages of labelled data, these methods often have poor model generalization capabilities when applied in real-world cases.In this paper, we address this problem by utilizing lightweight model stitching, which serves as a foundation for a hybrid method for fake news detection. Six distinct benchmark datasets have been used in our varied experiments. The outcomes are promising and pave the way for additional studies. Rafal Kozik, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras |
DSAA | 1 |
| 2023 | Explainable Artificial Intelligence 101: Techniques, Applications and Challenges
Wiktor Kurek, Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras |
ICIC (4) | 4 |
| 2023 | Improving Siamese Neural Networks with Border Extraction Sampling for the use in Real-Time Network Intrusion DetectionabstractSociety reaps the benefits of networking technologies, with the number of connected citizens and devices constantly on the rise. The convenience and efficiency brought by connected technologies are adopted in normal households and industrial plants alike. As the proliferation of the technology expands, the incentives for malicious users to cause mischief are also getting stronger. This causes an influx in cyber incidents. To deal with the rising cyberthreats, a suite of defensive methods has been proposed. One prominent example is network intrusion detection systems. The Machine-Learning-based network intrusion detection systems utilised in critical infrastructure or soft target protection offer many benefits, but still, need improvements in numerous areas. This paper contains a proposition of an improved network intrusion detection system featuring a Siamese network as a few-shot learner. The used NetFlow features allow the system to perform real-time intrusion detection, the Siamese network allows spotting attacks from classes that were not used during the training of the network, and the used sampling method allows circumventing the over-counting problem when formulating sample pairs to train the Siamese networks. The results of the research are presented and show promise. Marek Pawlicki, Rafal Kozik, Michal Choras |
IJCNN | 2 |
| 2023 | Alphabet Flatting as a variant of n-gram feature extraction method in ensemble classification of fake news
Pawel Ksieniewicz, Pawel Zyblewski, Weronika Borek-Marciniec, Rafal Kozik, Michal Choras, Michal Wozniak 0001 |
Eng. Appl. Artif. Intell. | 4 |
| 2023 | The survey and meta-analysis of the attacks, transgressions, countermeasures and security aspects common to the Cloud, Edge and IoT
Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras |
Neurocomputing | 3 |
| 2023 | First broad and systematic horizon scanning campaign and study to detect societal and ethical dilemmas and emerging issues spanning over cybersecurity solutions
Aleksandra Pawlicka, Michal Choras, Rafal Kozik, Marek Pawlicki |
Pers. Ubiquitous Comput. | 3 |
| 2022 | A novel, refined dataset for real-time Network Intrusion DetectionabstractIn this day and age of widespread Internet access, more and more aspects of the economy are becoming dependent on various aspects of network technologies. Cybercrimes are on the rise and massive numbers of network security breaches occur every year. This paper presents network data collected in the Netflow format and its application to detect network attacks. The paper proposes a refined, real-world dataset collected from an academic network. The dataset is a direct result from the experience gained by working on and with the SIMARGL2021 dataset. The applicability of the new dataset is demonstrated on several machine learning algorithms. This novel dataset is open-sourced for researchers to download and use in scientific work. Mikolaj Komisarek, Marek Pawlicki, Maria-Elena Mihailescu, Darius Mihai, Mihai Carabas, Rafal Kozik, Michal Choras |
ARES | 6 |
| 2022 | The cybersecurity-related ethical issues of cloud technology and how to avoid themabstractNowadays, cloud technology is assuming immense significance, being treated as a critical infrastructure, and is also a buzzword. Nevertheless, the technology has also brought about a number of new adverse phenomena and threats; it has attracted criminals, as well. Whenever the questions of “good” and “bad” arise, the ethical issues arise alongside them; the cybersecurity of cloud technology is no exception. This paper deals with the ethical dilemmas of cloud technology. It discusses a collection of the ethical issues of the cloud technology presented from the perspective of cybersecurity, based on the state-of-the-art literature. The main contribution of this work is that it gathers, synthesizes and organises the cybersecurity-related ethical dilemmas of cloud technology, thus offering the most extensive collection thereof. In addition, the work presents a comprehensive list of recommendations and suggestions which may help solve or prevent these ethical issues, and are a good starting point for anyone designing an ethical cybersecurity strategy. Aleksandra Pawlicka, Marek Pawlicki, Rafal Renk, Rafal Kozik, Michal Choras |
ARES | 4 |
| 2022 | Towards Deployment Shift Inhibition Through Transfer Learning in Network Intrusion DetectionabstractCurrently, machine learning sees growing adoption in numerous domains, including critical applications, like cybersecurity. However, to fully enjoy the benefits of artificial intelligence the end-user has some high barriers to entry to circumnavigate. The deployment of machine-learning-based Network Intrusion Detection Systems requires the collection of labelled data to train the intelligent components. This is an expensive and laborious process, which necessitates expert knowledge in cyberattacks and computer networks. Even when using data collected and labelled on premises, phenomena like concept drift can cause the model to underperform - a concept known as deployment shift. This paper evaluates the use of transfer learning techniques to curb the effects of deployment shift in machine-learning-based network intrusion detection. Marek Pawlicki, Rafal Kozik, Michal Choras |
ARES | 2 |
| 2022 | Fast Hybrid Oracle-Explainer Approach to Explainability Using Optimized Search of Comprehensible Decision TreesabstractExplainability, Transparency, and Fairness are now recognized foundations that have altered the landscape of the artificial intelligence domain. Excellent performance is no longer enough if the decisions of a system can upset the life of a regular citizen. The stakeholders of a utilised system must know whether they can trust the results the system provides, for both ethical and legal reasons. This can be made possible with Explainable Artificial Intelligence (xAI). It helps detect errors that could compromise the effectiveness of an intelligent system. It can discover biases present in the data that could lead to unfair treatment. It also provides novel insights regarding the data and the investigated domain. The applicability and benefits of Explainable Artificial Intelligence are explicit; however, scalable and simple-to-use solutions are scarce. Therefore, this paper proposes a new approach to explainability called "Fast Hybrid Oracle-Explainer". This method is a significant extension and improvement over previous approaches utilizing Comprehensible Decision Trees, expanded with the Nearest Neighbors Search algorithm. Compared to its predecessors, the proposed method maintains a similar level of agreement while drastically reducing the time necessary to provide an explanation. Furthermore, it still offers concise and intuitive decision-tree-based explanations. This paper presents details of this new approach in the context of an Intrusion Detection System. The soundness, clarity, and performance of the proposed method are proven experimentally. Mateusz Szczepanski, Marek Pawlicki, Rafal Kozik, Michal Choras |
DSAA | 3 |
| 2022 | Efficient Post Event Analysis and Cyber Incident Response in IoT and E-commerce Through Innovative Graphs and Cyberthreat Intelligence Employment
Rafal Kozik, Marek Pawlicki, Mateusz Szczepanski, Rafal Renk, Michal Choras |
ICIC (3) | 1 |
| 2022 | A survey on neural networks for (cyber-) security and (cyber-) security of neural networksabstractThe goal of this systematic and broad survey is to present and discuss the main challenges that are posed by the implementation of Artificial Intelligence and Machine Learning in the form of Artificial Neural Networks in Cybersecurity, specifically in Intrusion Detection Systems. Based on the results of the state-of-the-art analysis with a number of bibliographic methods, as well as their own implementations, the authors provide a survey of the answers to the posed problems as well as effective, experimentally-found solutions to those key issues. The issues include hyperparameter tuning, dataset balancing, increasing the effectiveness of an ANN, securing the networks from adversarial attacks, and a range of non-technical challenges of applying ANNs for IDS, such as societal, ethical and legal dilemmas, and the question of explainability. Thus, it is a systematic review and a summary of the body of knowledge amassed around implementations of Artificial Neural Networks in Network Intrusion Detection, guided by an actual, real-world implementation. Marek Pawlicki, Rafal Kozik, Michal Choras |
Neurocomputing | 2 |
| 2022 | Implementation of the BERT-derived architectures to tackle disinformation challengesabstractRecent progress in the area of modern technologies confirms that information is not only a commodity but can also become a tool for competition and rivalry among governments and corporations, or can be applied by ill-willed people to use it in their hate speech practices. The impact of information is overpowering and can lead to many socially undesirable phenomena, such as panic or political instability. To eliminate the threats of fake news publishing, modern computer security systems need flexible and intelligent tools. The design of models meeting the above-mentioned criteria is enabled by artificial intelligence and, above all, by the state-of-the-art neural network architectures, applied in NLP tasks. The BERT neural network belongs to this type of architectures. This paper presents Transformer-based hybrid architectures applied to create models for detecting fake news. Sebastian Kula, Rafal Kozik, Michal Choras |
Neural Comput. Appl. | 2 |
| 2021 | Network Intrusion Detection in the Wild - the Orange use case in the SIMARGL projectabstractThere is a profuse abundance of network security incidents around the world every day. Increasingly, services and data stored on servers fall victim to sophisticated techniques that cause all sorts of damage. Hackers invent new ways to bypass security measures and modify the existing viruses in order to deceive defense systems. Therefore, in response to these illegal procedures, new ways to defend against them are being developed. In this paper, a method for anomaly detection based on machine learning technique is presented and a near real-time processing system architecture is proposed. The main contribution is a test-run of ML algorithms on real-world data coming from a world-class telecom operator. This work investigates the effectiveness of detecting malicious behaviour in network packets using several machine learning techniques. The results achieved are expressed with a set of metrics. For better clarity on the classifier performance, 10-fold cross-validation was used. Mikolaj Komisarek, Marek Pawlicki, Mikolaj Kowalski, Adrian Marzecki, Rafal Kozik, Michal Choras |
ARES | 5 |
| 2021 | Missing and Incomplete Data Handling in Cybersecurity Applications
Marek Pawlicki, Michal Choras, Rafal Kozik, Witold Holubowicz |
ACIIDS | 3 |
| 2021 | Towards AI-Based Reaction and Mitigation for e-Commerce - the ENSURESEC Engine
Marek Pawlicki, Rafal Kozik, Damian Puchalski, Michal Choras |
ICIC (3) | 2 |
| 2021 | Intelligent operator: Machine learning based decision support and explainer for human operators and service providers in the fog, cloud and edge networks
Sebastian Laskawiec, Michal Choras, Rafal Kozik, Varadarajan Vijayakumar 0001 |
J. Inf. Secur. Appl. | 3 |
| 2021 | Multimedia analysis platform for crime prevention and investigationabstractAbstract Nowadays,the use of digital technologies is promoting three main characteristics of information, i.e. the volume, the modality and the frequency. Due to the amount of information generated by tools and individuals, it has been identified a critical need for the Law Enforcement Agencies to exploit this information and carry out criminal investigations in an effective way. To respond to the increasing challenges of managing huge amounts of heterogeneous data generated at high frequency, the paper outlines a modular approach adopted for the processing of information gathered from different information sources, and the extraction of knowledge to assist criminal investigation. The proposed platform provides novel technologies and efficient components for processing multimedia information in a scalable and distributed way, allowing Law Enforcement Agencies to make the analysis and a multidimensional visualization of criminal information in a single and secure point. Francisco J. Pérez, Victor Garrido, Alberto García, Oscar Marcelo Zambrano Vizuete, Rafal Kozik, Michal Choras, Dirk Mühlenberg, Dirk Pallmer, Wilmuth Müller |
Multim. Tools Appl. | 5 |
| 2021 | A new method of hybrid time window embedding with transformer-based traffic data classification in IoT-networked environmentabstractAbstract The Internet of Things (IoT) appliances often expose sensitive data, either directly or indirectly. They may, for instance, tell whether you are at home right now or what your long or short-term habits are. Therefore, it is crucial to protect such devices against adversaries and has in place an early warning system which indicates compromised devices in a quick and efficient manner. In this paper, we propose time window embedding solutions that efficiently process a massive amount of data and have a low-memory-footprint at the same time. On top of the proposed embedding vectors, we use the core anomaly detection unit. It is a classifier that is based on the transformer’s encoder component followed by a feed-forward neural network. We have compared the proposed method with other classical machine-learning algorithms. Therefore, in the paper, we formally evaluate various machine-learning schemes and discuss their effectiveness in the IoT-related context. Our proposal is supported by detailed experiments that have been conducted on the recently published Aposemat IoT-23 dataset. Rafal Kozik, Marek Pawlicki, Michal Choras |
Pattern Anal. Appl. | 1 |
| 2020 | Real-time stream processing tool for detecting suspicious network patterns using machine learningabstractIn this paper, the performance of stream processing and accuracy in the prediction of suspicious flows in simulated network traffic is investigated. In addition, concepts of an engine that integrates with novel solutions like the Elastic-search database and Apache Kafka that allows easy definition of streams and implementation of any machine learning algorithm are presented. Mikolaj Komisarek, Michal Choras, Rafal Kozik, Marek Pawlicki |
ARES | 3 |
| 2020 | Stegomalware detection through structural analysis of media filesabstractThe growing diffusion of malware is causing non-negligible economic and social costs. Unfortunately, modern attacks evolve and adapt to defensive mechanisms, and many threats are designed for the optimal exploitation of the traits of the victims. Thus, phenomena such as mobile malware, fileless malware or stegomalware are becoming widespread and represent the next variations of malicious attacks that have to be faced. In particular, the massive amount of digital content shared on the Internet is increasingly more often being used by attackers for the injection of malicious code to bypass security tools or prevent detection. Damian Puchalski, Luca Caviglione, Rafal Kozik, Adrian Marzecki, Slawomir Krawczyk, Michal Choras |
ARES | 3 |
| 2020 | Actionable Software Metrics: An Industrial PerspectiveabstractBackground: Practitioners would like to take action based on software metrics, as long as they find them reliable. Existing literature explores how metrics can be made reliable, but remains unclear if there are other conditions necessary for a metric to be actionable. Context & Method: In the context of a European H2020 Project, we conducted a multiple case study to study metrics' use in four companies, and identified instances where these metrics influenced actions. We used an online questionnaire to enquire about the project participants' views on actionable metrics. Next, we invited one participant from each company to elaborate on the identified metrics' use for taking actions and the questionnaire responses (N=17). Result: We learned that a metric that is practical, contextual, and exhibits high data quality characteristics is actionable. Even a non-actionable metric can be useful, but an actionable metric mostly requires interpretation. However, the more these metrics are simple and reflect the software development context accurately, the less interpretation required to infer actionable information from the metric. Company size and project characteristics can also influence the type of metric that can be actionable. Conclusion: This exploration of industry's views on actionable metrics help characterize actionable metrics in practical terms. This awareness of what characteristics constitute an actionable metric can facilitate their definition and development right from the start of a software metrics program. Prabhat Ram, Pilar Rodríguez 0002, Markku Oivo, Silverio Martínez-Fernández, Alessandra Bagnato, Michal Choras, Rafal Kozik, Sanja Aaramaa, Milla Ahola |
EASE | 7 |
| 2020 | Fake News Detection from Data StreamsabstractUsing fake news as a political or economic tool is not new, but the scale of their use is currently alarming, especially on social media. The authors of misinformation try to influence the users' decisions, both in the economic and political sphere. The facts of using disinformation during elections are well known. Currently, two fake news detection approaches dominate. The first approach, so-called fact or news checker, is based on the knowledge and work of volunteers, the second approach employs artificial intelligence algorithms for news analysis and manipulation detection. In this work, we will focus on using machine learning methods to detect fake news. However, unlike most approaches, we will treat incoming messages as stream data, taking into account the possibility of concept drift occurring, i.e., appearing changes in the probabilistic characteristics of the classification model during the exploitation of the classifier. The developed methods have been evaluated based on computer experiments on benchmark data, and the obtained results prove their usefulness for the problem under consideration. The proposed solutions are part of the distributed platform developed by the H2020 SocialTruth project consortium. Pawel Ksieniewicz, Pawel Zyblewski, Michal Choras, Rafal Kozik, Agata Gielczyk, Michal Wozniak 0001 |
IJCNN | 4 |
| 2020 | Achieving Explainability of Intrusion Detection System by Hybrid Oracle-Explainer ApproachabstractWith the progressing development and ubiquitousness of Artificial Intelligence (AI) observed in last decade, the need for creating methods which are explainable and/or interpretable for humans has become a pressing matter. The ability to understand how a system makes a decision is necessary to help develop trust, settle issues of fairness and perform the debugging of a model. Although there are many different techniques allowing to get insights into models' inner workings, they often come with a trade off in the form of decreased accuracy. In the context of cybersecurity, where a single false negative can lead to a breach and compromise of the whole system, such a price is unacceptable. Therefore, there is a need for a solution which allows for the maximum possible model performance, and at the same time delivers human understandable interpretations. The hybrid approaches to Explainable Artificial Intelligence (XAI) have the potential to achieve this goal. In this work, we present the fundamental concepts and a prototype of a system using such an architecture. Mateusz Szczepanski, Michal Choras, Marek Pawlicki, Rafal Kozik |
IJCNN | 4 |
| 2020 | An Empirical Investigation into Industrial Use of Software Metrics Programs
Prabhat Ram, Pilar Rodríguez 0002, Markku Oivo, Alessandra Bagnato, Antonin Abherve, Michal Choras, Rafal Kozik |
PROFES | 7 |
| 2020 | Defending network intrusion detection systems against adversarial evasion attacks
Marek Pawlicki, Michal Choras, Rafal Kozik |
Future Gener. Comput. Syst. | 3 |
| 2020 | Data-driven and tool-supported elicitation of quality requirements in agile companies
Marc Oriol, Silverio Martínez-Fernández, Woubshet Behutiye, Carles Farré, Rafal Kozik, Pertti Seppänen, Anna Maria Vollmer, Pilar Rodríguez 0002, Xavier Franch, Sanja Aaramaa, Antonin Abherve, Michal Choras, Jari Partanen |
Softw. Qual. J. | 5 |
| 2019 | SocialTruth Project Approach to Online Disinformation (Fake News) Detection and MitigationabstractThe extreme growth and adoption of Social Media, in combination with their poor governance and the lack of quality control over the digital content being published and shared, has led information veracity to a continuous deterioration. Current approaches entrust content verification to a single centralised authority, lack resilience towards attempts to successfully "game" verification checks, and make content verification difficult to access and use. In response, our ambition is to create an open, democratic, pluralistic and distributed ecosystem that allows easy access to various verification services (both internal and third-party), ensuring scalability and establishing trust in a completely decentralized environment. In fact, this is the ambition of the EU H2020 SocialTruth project. In this paper, we present the innovative project approach and the vision of effective online disinformation detection for various practical use-cases. Michal Choras, Marek Pawlicki, Rafal Kozik, Konstantinos P. Demestichas, Pavlos Kosmides, Manik Gupta |
ARES | 3 |
| 2019 | The Identification and Creation of Ontologies for the Use in Law Enforcement AI Solutions - MAGNETO Platform Use Case
Rafal Kozik, Michal Choras, Marek Pawlicki, Witold Holubowicz, Dirk Pallmer, Wilmuth Müller, Ernst-Josef Behmer, Ioannis V. Loumiotis, Konstantinos P. Demestichas, Roxana Horincar, Claire Laudy, David Faure |
ICCCI (2) | 1 |
| 2019 | Artificial Neural Network Hyperparameter Optimisation for Network Intrusion Detection
Marek Pawlicki, Rafal Kozik, Michal Choras |
ICIC (1) | 2 |
| 2019 | The Feasibility of Deep Learning Use for Adversarial Model Extraction in the Cybersecurity Domain
Michal Choras, Marek Pawlicki, Rafal Kozik |
IDEAL (2) | 3 |
| 2019 | Machine Learning Methods for Fake News Classification
Pawel Ksieniewicz, Michal Choras, Rafal Kozik, Michal Wozniak 0001 |
IDEAL (2) | 3 |
| 2018 | Recent Granular Computing Implementations and its Feasibility in Cybersecurity DomainabstractAs the importance of data stored in daily-use information system grows, so does the damage a malicious user could inflict. Network traffic can be notoriously complicated and prone to fluctuations. With the prevailing risk of cybersecurity breaches, improving the detection algorithms is of utmost importance. Advanced systems using various facets of artificial intelligence and machine learning exist. We look forward to Granular Computing (GrC) as a novel, promising way to improve network traffic classification, intrusion detection and reduction in the computational cost of real time traffic analysis. In this paper, aquick primer on granular computing is offered, its properties of abstracting data into meaningful, compact packages named granules are looked into. The basic principles of granule creation are explained. Consecutively, a survey of the most recent Granular Computing implementations is presented, with analysis of how certain aspects of Granular Computing are utilized to solve particular real-world problems. In multiple cases, the techniques of GrC allow for an increase in efficiency and calculating speed, better data legibility and improvements in the performance of classifier algorithms the granulated data is supplied to. The examined approaches are then taxonomised with regard to the purpose of granulation, and with regard to the utilized aspect of Granular Computing. Marek Pawlicki, Michal Choras, Rafal Kozik |
ARES | 3 |
| 2018 | A scalable distributed machine learning approach for attack detection in edge computing environments
Rafal Kozik, Michal Choras, Massimo Ficco, Francesco Palmieri 0002 |
J. Parallel Distributed Comput. | 1 |
| 2018 | Distributing extreme learning machines with Apache Spark for NetFlow-based malware activity detection
Rafal Kozik |
Pattern Recognit. Lett. | 1 |
| 2018 | Cost-Sensitive Distributed Machine Learning for NetFlow-Based Botnet Activity DetectionabstractThe recent advancements of malevolent techniques have caused a situation where the traditional signature-based approach to cyberattack detection is rendered ineffective. Currently, new, improved, potent solutions incorporating Big Data technologies, effective distributed machine learning, and algorithms countering data imbalance problem are needed. Therefore, the major contribution of this paper is the proposal of the cost-sensitive distributed machine learning approach for cybersecurity. In particular, we proposed to use and implemented cost-sensitive distributed machine learning by means of distributed Extreme Learning Machines (ELM), distributed Random Forest, and Distributed Random Boosted-Trees to detect botnets. The system’s concept and architecture are based on the Big Data processing framework with data mining and machine learning techniques. In practical terms in this paper, as a use case, we consider the problem of botnet detection by means of analysing the data in form of NetFlows. The reported results are promising and show that the proposed system can be considered as a useful tool for the improvement of cybersecurity. Rafal Kozik, Marek Pawlicki, Michal Choras |
Secur. Commun. Networks | 1 |
| 2017 | The Concept of Applying Lifelong Learning Paradigm to Cybersecurity
Michal Choras, Rafal Kozik, Rafal Renk, Witold Holubowicz |
ICIC (3) | 2 |
| 2017 | Pattern Extraction Algorithm for NetFlow-Based Botnet Activities DetectionabstractAs computer and network technologies evolve, the complexity of cybersecurity has dramatically increased. Advanced cyber threats have led to current approaches to cyber-attack detection becoming ineffective. Many currently used computer systems and applications have never been deeply tested from a cybersecurity point of view and are an easy target for cyber criminals. The paradigm of security by design is still more of a wish than a reality, especially in the context of constantly evolving systems. On the other hand, protection technologies have also improved. Recently, Big Data technologies have given network administrators a wide spectrum of tools to combat cyber threats. In this paper, we present an innovative system for network traffic analysis and anomalies detection to utilise these tools. The systems architecture is based on a Big Data processing framework, data mining, and innovative machine learning techniques. So far, the proposed system implements pattern extraction strategies that leverage batch processing methods. As a use case we consider the problem of botnet detection by means of data in the form of NetFlows. Results are promising and show that the proposed system can be a useful tool to improve cybersecurity. Rafal Kozik, Michal Choras |
Secur. Commun. Networks | 1 |
| 2016 | Evolutionary-based packets classification for anomaly detection in web layerabstractAbstract In this paper, we propose a novel method for web layer anomaly detection. In contrast to the majority of other state of the art approaches, we do not adapt manually configured parsers or packet content type detection techniques to partition the request sent from clients to server. In our experiments, we showed that making certain assumptions about the request content types may lead to the degradation of the detection performance. Therefore, we proposed unsupervised algorithm for automated packet structure extraction. We formulate this as the optimisation problem that is solved by means of genetic algorithm. Moreover, on top of the request segmentation schema, we provide the set of algorithms that measure statistics and apply machine learning techniques to solve the classification problems. The effectiveness of our methods is proved by the results achieved on the extended benchmark database. Copyright © 2016 John Wiley & Sons, Ltd. Rafal Kozik, Michal Choras, Witold Holubowicz |
Secur. Commun. Networks | 1 |
| 2016 | DWT-based anomaly detection method for cyber security of wireless sensor networksabstractAbstract Critical infrastructures are exposed to many natural and man‐made hazards and threats. Recently, in the era of moving previously disconnected (tele)‐monitoring, control and supervisory systems (e.g., information and communication technologies or supervisory control and data acquisition) towards full network connection, the risk of cyber attacks on such systems is continuously growing. One of the current trends in information and communication technology systems controlling critical infrastructures (such as energy grids, telecommunication networks, or water systems) is deployment of wireless sensor networks. Therefore, the cyber security of the mentioned networks becomes an important challenge to be solved. In this paper, we propose a discrete wavelet transform‐based method of anomaly detection in wireless sensor networks that could be deployed in critical infrastructures (e.g., in energy grids, to measure some parameters). The major contribution of the paper is the implementation of the innovative SNORT‐based pre‐processor using the effective anomaly detection methods based on discrete wavelet transform. We apply the discrete wavelet transform to 26 network traffic parameters measured in our realistic testbed. We also discuss which parameters of the traffic are most useful for such purpose. Moreover, we implement our method as an algorithm in a dedicated SNORT preprocessor in order to be compliant with this popular state of the art intrusion detection system. Copyright © 2016 John Wiley & Sons, Ltd. Lukasz Saganowski, Tomasz Andrysiak, Rafal Kozik, Michal Choras |
Secur. Commun. Networks | 3 |
| 2015 | Comprehensive Approach to Increase Cyber Security and ResilienceabstractIn this paper the initial results of the European project CAMINO in terms of the realistic roadmap to counter cyber crime and cyber terrorism are presented. The roadmap is built in accordance to so called CAMINO THOR approach, where cyber security is perceived comprehensively in 4 dimensions: Technical, Human, Organisational, and Regulatory. Michal Choras, Rafal Kozik, Maria Pilar Torres Bruna, Artsiom Yautsiukhin, Andrew Churchill, Iwona Maciejewska, Irene Eguinoa, Adel Jomni |
ARES | 2 |
| 2012 | Contactless palmprint and knuckle biometrics for mobile devicesabstractIn this paper, biometric methods for contactless and unrestricted access control for mobile devices are proposed. The major contribution of this paper are palmprint and knuckles feature extraction methods dedicated for the mobile contactless biometrics. We use texture mask-based features for the palmprint. For the knuckles, we use Probabilistic Hough Transform and Speeded Up Robust Features as well as the 3-step classification methodology. We prove the efficiency of the presented methods by reporting promising results. Michal Choras, Rafal Kozik |
Pattern Anal. Appl. | 2 |
| 2010 | Feature Extraction Method for Contactless Palmprint Biometrics
Michal Choras, Rafal Kozik |
ICIC (3) | 2 |
| 2010 | Ontology Applied in Decision Support System for Critical Infrastructures Protection
Michal Choras, Rafal Kozik, Adam Flizikowski, Witold Holubowicz |
IEA/AIE (1) | 2 |
| 2010 | Intersection Approach to Vulnerability Handling
Michal Choras, Salvatore D'Antonio, Rafal Kozik, Witold Holubowicz |
WEBIST (1) | 3 |
| 2009 | Decision Aid Tool and Ontology-Based Reasoning for Critical Infrastructure Vulnerabilities and Threats Analysis
Michal Choras, Adam Flizikowski, Rafal Kozik, Witold Holubowicz |
CRITIS | 3 |
| 2009 | Ontology-Based Decision Support for Security Management in Heterogeneous Networks
Michal Choras, Rafal Kozik, Adam Flizikowski, Rafal Renk, Witold Holubowicz |
ICIC (2) | 2 |
| 2009 | Performance comparison of guard channel admission control schemes for IEEE 802.16 system with various turbo code FEC schemesabstractAlthough by default the Network Simulator 2 (NS2) does not implement the IEEE 802.16 networks, a few patches are available, that provide WiMAX specifications at different fidelity level. The ns2 environment is useful for system-level evaluation, but mainly with respect to wired networks. In order to provide an adequate QoS provisioning to different service flows and to prevent base station (BS) from running out of resources an appropriate connection admission control (CAC) algorithms needs to be considered. Since the introduction of IEEE 802.16e standard a lot of studies have focused on development of CAC. In this paper we present the ns-2 module with integrated Connection Admission Control support. Currently three admission control algorithms based on so called guard channel were implemented. In the final sections authors show the CAC performance as well as influence of various turbo-FEC schemes deployed in physical layer on the system level performance. Especially it is found that the nb-LDPC codes provide link level solution able to improve system level quality metrics. Adam Flizikowski, Rafal Kozik, Mateusz Majewski, Marcin Przybyszewski |
IPCCC | 2 |