Paul A. Watters

dblp:85/10911 · also Paul Andrew Watters · DBLP profile ↗
← Back
48ranked-venue papers
7as first author
16since 2021 · last 2026
0000-0002-1399-7175ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 20 · 4 first-author · 4 since 2021Security and privacy · 11 · 2 first-author · 4 since 2021Systems, architecture and hardware · 7 · 4 since 2021Databases, data management, data science and information retrieval · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3Human-computer interaction and ubiquitous computing · 2 · 1 first-authorComputer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Over the Edge of Chaos? Excess Complexity as a Roadblock to Artificial General Intelligence
abstract
This study explores the progression of artificial intelligence (AI) systems through the lens of complexity theory, challenging conventional linear projections of advancement toward artificial general intelligence (AGI). We posit the existence of critical points, akin to phase transitions, where increasing system complexity may not lead to greater capability, but rather to performance plateaus or instability. To investigate this hypothesis, we used agent-based modelling (ABM) to simulate the evolution of AI systems, using evaluation benchmark performances as a proxy for complexity. Our simulations modeled the possible characteristics that systems could exhibit when crossing a critical threshold, transitioning from predictable improvement to a regime of erratic, volatile behavior. Practically, we introduced and validated a methodology for detecting these simulated critical transitions algorithmically. We proposed a heuristic Stochastic Gradient Descent-based approach and compared it with established CUmulative SUM (CUSUM) and Lyapunov exponent techniques, to show that different signatures of instability-from abrupt shifts to gradual volatility ramps-can be identified. We contextualized these findings with real-world phenomena, arguing that the empirically observed -"Jagged Capability Frontier" in large language models (LLMs) illustrates the kind of nonlinear performance boundaries that could be sharply accentuated by the onset of criticality. This research contributes not only a novel theoretical framework for understanding potential limits to AI scaling but also a practical, validated methodology for monitoring the systemic stability of AI systems, offering a new dimension to AGI evaluation and safety.
Teo Susnjak, Timothy R. McIntosh, Andre L. C. Barczak, Napoleon H. Reyes, Tong Liu 0016, Paul A. Watters, Malka N. Halgamuge
IEEE Trans. Cybern.6
2025 Modeling the Chaotic Semantic States of Generative Artificial Intelligence (AI): A Quantum Mechanics Analogy Approach
abstract
Generative AI models have revolutionized intelligent systems by enabling machines to produce human-like content across diverse domains. However, their outputs often exhibit unpredictability due to complex and opaque internal semantic states, posing challenges for reliability in real-world applications. In this article, we introduce the AI Uncertainty Principle , a novel theoretical framework inspired by quantum mechanics, to model and quantify the inherent unpredictability in generative AI outputs. By drawing parallels with the uncertainty principle and superposition, we formalize the tradeoff between the precision of internal semantic states and output variability. Through comprehensive experiments involving state-of-the-art models and a variety of prompt designs, we analyze how factors such as specificity, complexity, tone, and style influence model behavior. Our results demonstrate that carefully engineered prompts can significantly enhance output predictability and consistency, while excessive complexity or irrelevant information can increase uncertainty. We also show that ensemble techniques, such as Sigma-weighted aggregation across models and prompt variations, effectively improve reliability. Our findings have profound implications for the development of intelligent systems, emphasizing the critical role of prompt engineering and theoretical modeling in creating AI technologies that perceive, reason, and act predictably in the real world.
Tong Liu 0016, Timothy R. McIntosh, Teo Susnjak, Paul A. Watters, Malka N. Halgamuge
ACM Trans. Intell. Syst. Technol.4
2024 From COBIT to ISO 42001: Evaluating cybersecurity frameworks for opportunities, risks, and regulatory compliance in commercializing large language models
abstract
This study investigated the integration readiness of four predominant cybersecurity Governance, Risk and Compliance (GRC) frameworks - NIST CSF 2.0, COBIT 2019, ISO 27001:2022, and the latest ISO 42001:2023 - for the opportunities, risks, and regulatory compliance when adopting Large Language Models (LLMs), using qualitative content analysis and expert validation. Our analysis, with both LLMs and human experts in the loop, uncovered potential for LLM integration together with inadequacies in LLM risk oversight of those frameworks. Comparative gap analysis has highlighted that the new ISO 42001:2023, specifically designed for Artificial Intelligence (AI) management systems, provided most comprehensive facilitation for LLM opportunities, whereas COBIT 2019 aligned most closely with the European Union AI Act. Nonetheless, our findings suggested that all evaluated frameworks would benefit from enhancements to more effectively and more comprehensively address the multifaceted risks associated with LLMs, indicating a critical and time-sensitive need for their continuous evolution. We propose integrating human-expert-in-the-loop validation processes as crucial for enhancing cybersecurity frameworks to support secure and compliant LLM integration, and discuss implications for the continuous evolution of cybersecurity GRC frameworks to support the secure integration of LLMs.
Timothy R. McIntosh, Teo Susnjak, Tong Liu 0016, Paul A. Watters, Dan Xu 0021, Raza Nowrozy, Malka N. Halgamuge
Comput. Secur.4
2024 A Reasoning and Value Alignment Test to Assess Advanced GPT Reasoning
abstract
In response to diverse perspectives on artificial general intelligence (AGI), ranging from potential safety and ethical concerns to more extreme views about the threats it poses to humanity, this research presents a generic method to gauge the reasoning capabilities of artificial intelligence (AI) models as a foundational step in evaluating safety measures. Recognizing that AI reasoning measures cannot be wholly automated, due to factors such as cultural complexity, we conducted an extensive examination of five commercial generative pre-trained transformers (GPTs), focusing on their comprehension and interpretation of culturally intricate contexts. Utilizing our novel “Reasoning and Value Alignment Test,” we assessed the GPT models’ ability to reason in complex situations and grasp local cultural subtleties. Our findings have indicated that, although the models have exhibited high levels of human-like reasoning, significant limitations remained, especially concerning the interpretation of cultural contexts. This article also explored potential applications and use-cases of our Test, underlining its significance in AI training, ethics compliance, sensitivity auditing, and AI-driven cultural consultation. We concluded by emphasizing its broader implications in the AGI domain, highlighting the necessity for interdisciplinary approaches, wider accessibility to various GPT models, and a profound understanding of the interplay between GPT reasoning and cultural sensitivity.
Timothy R. McIntosh, Tong Liu 0016, Teo Susnjak, Paul A. Watters, Malka N. Halgamuge
ACM Trans. Interact. Intell. Syst.4
2023 Applying staged event-driven access control to combat ransomware
abstract
The advancement of modern Operating Systems (OSs), and the popularity of personal computing devices with Internet connectivity, have facilitated the proliferation of ransomware attacks. Ransomware has evolved from executable programs encrypting user files, to novel attack vectors including fileless command scripts, information exfiltration and human-operated ransomware. Many anti-ransomware studies have been published, but many of them assumed newer ransomware variants only performed file encryption, were similar to existing variants, and often did not consider those novel attack vectors. We have defined an updated ransomware threat model to include those novel attack vectors, and redefined false positives and false negatives in the context of ransomware mitigation. We proposed to apply both program-centric and user-centric access control to combat ransomware, but only delegate access control decisions that users are capable of making to users, while enforcing non-negotiable access control decisions by OS and software developers. We have designed a Staged Event-Driven Access Control (SEDAC) approach to incorporate both program-centric and user-centric access control measures, and demonstrated a prototype on Windows OS. Our prototype was able to intercept more types of ransomware attack vectors than existing proposals. We hope to convince OS and software architects to incorporate our design to better combat ransomware.
Timothy R. McIntosh, A. S. M. Kayes, Yi-Ping Phoebe Chen, Alex Ng, Paul A. Watters
Comput. Secur.5
2023 Harnessing GPT-4 for generation of cybersecurity GRC policies: A focus on ransomware attack mitigation
abstract
This study investigated the potential of Generative Pre-trained Transformers (GPTs), a state-of-the-art large language model, in generating cybersecurity policies to deter and mitigate ransomware attacks that perform data exfiltration. We compared the effectiveness, efficiency, completeness, and ethical compliance of GPT-generated Governance, Risk and Compliance (GRC) policies, with those from established security vendors and government cybersecurity agencies, using game theory, cost-benefit analysis, coverage ratio, and multi-objective optimization. Our findings demonstrated that GPT-generated policies could outperform human-generated policies in certain contexts, particularly when provided with tailored input prompts. To address the limitations of our study, we conducted our analysis with thorough human moderation, tailored input prompts, and the inclusion of legal and ethical experts. Based on these results, we made recommendations for corporates considering the incorporation of GPT in their GRC policy making.
Timothy R. McIntosh, Tong Liu 0016, Teo Susnjak, Hooman Alavizadeh, Alex Ng, Raza Nowrozy, Paul A. Watters
Comput. Secur.7
2022 Spam Email Categorization with NLP and Using Federated Deep Learning
Ikram Ul Haq, Paul Black, Iqbal Gondal, Joarder Kamruzzaman, Paul A. Watters, A. S. M. Kayes
ADMA (2)5
2022 A deep learning model for mining and detecting causally related events in tweets
abstract
Abstract Nowadays, public gatherings and social events are an integral part of a modern city life. To run such events seamlessly, it requires real time mining and monitoring of causally related events so that the management can make informed decisions and take appropriate actions. The automatic detection of event causality from short text such as tweets could be useful for event management in this context. However, detecting event causality from tweets is a challenging task. Tweets are short, unstructured, and often written in highly informal language which lacks enough contextual information to detect causality. The existing approaches apply different techniques including hand‐crafted linguistic rules and machine learning models. However, none of the approaches tackle the issue related to the lack of contextual information. In this paper, we detect event causality in tweets by applying a context word extension technique and a deep causal event detection model. The context word extension technique is driven by background knowledge extracted from one million news articles. Our model achieves 79.35% recall and 67.28% f1‐score, which are 17.39% and 2.33% improvements to the state‐of‐the‐art approach.
Humayun Kayesh, Md. Saiful Islam 0003, Junhu Wang, A. S. M. Kayes, Paul A. Watters
Concurr. Comput. Pract. Exp.5
2022 Privacy-preserving cooperative localization in vehicular edge computing infrastructure
abstract
Summary Advancement of computing and communication techniques transforms the traditional transport system into the intelligent transportation system (ITS). The development of distributed computing in a vehicular network platform also called Vehicular Edge Computing (VEC) promise to address most of the challenges faced by the ITS. Localization is important in these vehicular networks because of its key contribution in autonomous driving, smart traffic monitoring, and collision avoidance services. For localization, current GPS and hybrid methods are in‐efficient because of GPS outage in urban infrastructure and dynamic nature of the vehicular networks. The cooperative localization approaches, on the other hand, use dedicated short range communication to broadcast messages and estimate location. However, these messages are un‐encrypted and periodic which gives a privacy risk for vehicles. This article presents a privacy‐preserving cooperative localization in vehicular network based upon dynamic pseudonym changing strategy. First, the localization delay is addressed with the implementation of dynamic vehicular edge assignment for computational task management. In the next step, the localization is estimated from the neighbor and road side unit ranging measurement followed by a real‐time prediction of the vehicle. The performance of the proposed algorithms is analyzed in terms of localization accuracy and privacy preservation strength. Furthermore, the proposed method is simulated in a real city scenario followed by localization accuracy and privacy analysis. Finally, the localization accuracy and privacy strength of the proposed approach are compared with the state‐of‐the‐art methods.
Rathin Chandra Shit, Suraj Sharma, Paul A. Watters, Kumar Yelamarthi, Biswajeet Pradhan, Richard Davison 0001, Graham Morgan, Deepak Puthal
Concurr. Comput. Pract. Exp.3
2021 Dynamic user-centric access control for detection of ransomware attacks
Timothy R. McIntosh, A. S. M. Kayes, Yi-Ping Phoebe Chen, Alex Ng, Paul A. Watters
Comput. Secur.5
2021 Enforcing situation-aware access control to build malware-resilient file systems
Timothy R. McIntosh, Paul A. Watters, A. S. M. Kayes, Alex Ng, Yi-Ping Phoebe Chen
Future Gener. Comput. Syst.2
2021 Intelligent Dynamic Malware Detection using Machine Learning in IP Reputation for Forensics Data Analytics
Nighat Usman, Saeeda Usman, Fazlullah Khan, Mian Ahmad Jan, Ahthasham Sajid, Mamoun Alazab, Paul A. Watters
Future Gener. Comput. Syst.7
2021 Security and blockchain convergence with Internet of Multimedia Things: Current trends, research challenges and future directions
Mian Ahmad Jan, Jinjin Cai, Xiang-chuan Gao, Fazlullah Khan, Spyridon Mastorakis, Muhammad Usman 0015, Mamoun Alazab, Paul A. Watters
J. Netw. Comput. Appl.8
2021 Improving speech emotion recognition based on acoustic words emotion dictionary
abstract
Abstract To improve speech emotion recognition, a U-acoustic words emotion dictionary (AWED) features model is proposed based on an AWED. The method models emotional information from acoustic words level in different emotion classes. The top-list words in each emotion are selected to generate the AWED vector. Then, the U-AWED model is constructed by combining utterance-level acoustic features with the AWED features. Support vector machine and convolutional neural network are employed as the classifiers in our experiment. The results show that our proposed method in four tasks of emotion classification all provides significant improvement in unweighted average recall.
Wei Wang 0085, Xinyi Cao, Lingjie Shen, Yaqin Feng, Paul A. Watters
Nat. Lang. Eng.6
2021 Lightweight Mutual Authentication and Privacy-Preservation Scheme for Intelligent Wearable Devices in Industrial-CPS
abstract
Industry 5.0 is the digitalization, automation and data exchange of industrial processes that involve artificial intelligence, Industrial Internet of Things (IIoT), and Industrial Cyber-Physical Systems (I-CPS). In healthcare, I-CPS enables the intelligent wearable devices to gather data from the real-world and transmit to the virtual world for decision-making. I-CPS makes our lives comfortable with the emergence of innovative healthcare applications. Similar to any other IIoT paradigm, I-CPS capable healthcare applications face numerous challenging issues. The resource-constrained nature of wearable devices and their inability to support complex security mechanisms provide an ideal platform to malevolent entities for launching attacks. To preserve the privacy of wearable devices and their data in an I-CPS environment, we propose a lightweight mutual authentication scheme. Our scheme is based on client-server interaction model that uses symmetric encryption for establishing secured sessions among the communicating entities. After mutual authentication, the privacy risk associated with a patient data is predicted using an AI-enabled Hidden Markov Model (HMM). We analyzed the robustness and security of our scheme using BurrowsAbadiNeedham (BAN) logic. This analysis shows that the use of lightweight security primitives for the exchange of session keys makes the proposed scheme highly resilient in terms of security, efficiency, and robustness. Finally, the proposed scheme incurs nominal overhead in terms of processing, communication and storage and is capable to combat a wide range of adversarial threats.
Mian Ahmad Jan, Fazlullah Khan, Rahim Khan, Spyridon Mastorakis, Varun G. Menon, Mamoun Alazab, Paul A. Watters
IEEE Trans. Ind. Informatics7
2021 A Secured and Intelligent Communication Scheme for IIoT-enabled Pervasive Edge Computing
abstract
Industrial Internet of Things (IIoT) ensures reliable and efficient data exchanges among the industrial processes using Artificial Intelligence (AI) within the cyber-physical systems. In the IIoT ecosystem, devices of industrial applications communicate with each other with little human intervention. They need to act intelligently to safeguard the data confidentiality and devices' authenticity. The ability to gather, process, and store real-time data depends on the quality of data, network connectivity, and processing capabilities of these devices. Pervasive Edge Computing (PEC) is gaining popularity nowadays due to the resource limitations imposed on the sensor-embedded IIoT devices. PEC processes the gathered data at the network edge to reduce the response time for these devices. However, PEC faces numerous research challenges in terms of secured communication, network connectivity, and resource utilization of the edge servers. To address these challenges, we propose a secured and intelligent communication scheme for PEC in an IIoT-enabled infrastructure. In the proposed scheme, forged identities of adversaries, i.e., Sybil devices, are detected by IIoT devices and shared with edge servers to prevent upstream transmission of their malicious data. Upon Sybil attack detection, each edge server executes a parallel Artificial Bee Colony (pABC) algorithm to perform optimal network configuration of IIoT devices. Each edge server performs the job migration to their neighboring servers for load balancing and better network performance, based on their processing and storage capabilities. The experimental results justify the efficiency of our proposed scheme in terms of Sybil attack detection, the convergence curves of our pABC algorithm, delay, throughput, and control overhead of data communication using PEC for IIoT.
Fazlullah Khan, Mian Ahmad Jan, Ateeq Ur Rehman 0001, Spyridon Mastorakis, Mamoun Alazab, Paul A. Watters
IEEE Trans. Ind. Informatics6
2020 API Based Discrimination of Ransomware and Benign Cryptographic Programs
Paul Black, Ammar Sohail, Iqbal Gondal, Joarder Kamruzzaman, Peter Vamplew 0001, Paul A. Watters
ICONIP (2)6
2020 Answering Binary Causal Questions: A Transfer Learning Based Approach
abstract
Causal question answering is a task of answering causality related questions. The questions are referred to as binary causal questions when the questions e.g., "Could X cause Y?" can be answered by yes/no answers. Answer to the previous question is yes if X is a cause of Y, and otherwise no. The binary causal question answering systems can be used to validate causal relationships, which can be particularly useful for decision making. For example, it could be useful for the tourism authorities to know the answer to the question "Could growing social tension cause reduction in tourism?". We aim to automatically answer such binary causal questions by developing a machine learning model. However, training a machine learning model to detect causal relationships is challenging due to the lack of large and high quality labeled datasets. In this paper, we propose a transfer learning-based approach which fine-tunes pretrained transformer based language models on a small dataset of cause-effect pairs to detect causality and answer binary causal questions. The proposed approach achieves performance comparable to a number of benchmark approaches on five benchmark test datasets extracted by human experts conditioned on the same small training dataset.
Humayun Kayesh, Md. Saiful Islam 0003, Junhu Wang, Shikha Anirban, A. S. M. Kayes, Paul A. Watters
IJCNN6
2020 CalBehav: A Machine Learning-Based Personalized Calendar Behavioral Model Using Time-Series Smartphone Data
abstract
Abstract The electronic calendar is a valuable resource nowadays for managing our daily life appointments or schedules, also known as events, ranging from professional to highly personal. Researchers have studied various types of calendar events to predict smartphone user behavior for incoming mobile communications. However, these studies typically do not take into account behavioral variations between individuals. In the real world, smartphone users can differ widely from each other in how they respond to incoming communications during their scheduled events. Moreover, an individual user may respond the incoming communications differently in different contexts subject to what type of event is scheduled in her personal calendar. Thus, a static calendar-based behavioral model for individual smartphone users does not necessarily reflect their behavior to the incoming communications. In this paper, we present a machine learning based context-aware model that is personalized and dynamically identifies individual’s dominant behavior for their scheduled events using logged time-series smartphone data, and shortly name as ‘CalBehav’. The experimental results based on real datasets from calendar and phone logs, show that this data-driven personalized model is more effective for intelligently managing the incoming mobile communications compared to existing calendar-based approaches.
Iqbal H. Sarker, Alan W. Colman, Jun Han 0004, A. S. M. Kayes, Paul A. Watters
Comput. J.5
2020 Achieving security scalability and flexibility using Fog-Based Context-Aware Access Control
A. S. M. Kayes, Wenny Rahayu, Paul A. Watters, Mamoun Alazab, Tharam S. Dillon, Elizabeth Chang 0001
Future Gener. Comput. Syst.3
2019 Trust Modeling for Blockchain-Based Wearable Data Market
abstract
Wearable devices continuously produce physiological data that can provide individuals critical information about their daily routine or fitness level in combination with their smartphones without requiring manual calculations or maintaining log-books. Real-time participant-generated data can enable large scale observational studies of health conditions, provide better insights into medical conditions of individuals and streamline clinical trial processes in medical research. However, privacy is a major concern for health data and there can be a lack of trust among different parties in the health data collection process. In addition, individuals often do not have sufficient control over the sharing of their data from the wearable devices. The lack of control, trust and privacy are key barriers to research participants being prepared to share their personal data from wearable devices. In this work, we propose a trust model to overcome the trust deficit among different parties. Then, we present a reference system architecture, rooted on the developed trust model, that provides incentive for individuals to securely share their health data through a data marketplace. By encouraging individuals to share their real-time health data, researchers will have access to large data sets at low cost.
Mohammad Jabed Morshed Chowdhury, Md Sadek Ferdous, Kamanashis Biswas, Niaz Chowdhury, A. S. M. Kayes, Paul A. Watters, Alex Ng
CloudCom6
2019 The Inadequacy of Entropy-Based Ransomware Detection
Timothy R. McIntosh, Julian Jang, Paul A. Watters, Teo Susnjak
ICONIP (5)3
2018 Large Scale Behavioral Analysis of Ransomware Attacks
Timothy R. McIntosh, Julian Jang, Paul A. Watters
ICONIP (6)3
2017 Evaluating Accuracy in Prudence Analysis for Cyber Security
Omaru Maruatona, Peter Vamplew 0001, Richard Dazeley, Paul A. Watters
ICONIP (5)4
2016 Peeking behind the great firewall: Privacy on Chinese file sharing networks
abstract
As citizens debate the morality of using global surveillance to enforce cyber security, software technologies that can proliferate illegal distribution of copyright material are evolving rapidly. One such technology is Peer-to-Peer networking which, through well-known implementations such as Napster, Bittorrent and eMule, has enabled users to share files at optimal speeds and at near infinite scale. This technology is contentious in that it can distribute highly desired files globally in minutes if not seconds and determining illegal vs legal applications is a challenge. Recently, a new player Xunlei has arrived on the Peer-to-Peer scene with an impressive network and unprecedented global reach. Xunlei, a proprietary Peer-to-Peer network, is unique in that it aggregates multiple file sources together seamlessly enabling content to be consumed via a single client. The aggregated approach raises some ethical dilemmas. Is it a good thing that centralised management of Peer-to-Peer networks exists? Is it a form of populous control? Where will it lead as Peer-to-Peer usage becomes more mainstream? Finally, does it threaten an individual's privacy? This paper investigates the Xunlei network as it stands today and takes valuable steps towards addressing these questions, and to defining future fields of research.
Matthew Comb, Paul A. Watters
PST2
2016 Controlling information behaviour: the case for access control
abstract
Intentional dissemination of information is a key role of information systems. Yet methods for controlling access to information – as opposed to data – are still in their infancy, especially in relation to the key ‘decision points' that need to be made regarding what information users can access when, and under what conditions. This paper presents the case for access control to be explicitly integrated into models of information behaviour, especially as they relate to information access on the relatively unregulated internet. An observational case study relating to information access in Indonesia – which is a highly regulated society – is presented, through advertising on rogue websites – in this case, behaviour which is strictly regulated in the physical world (such as the promotion of gambling) is relatively unchecked online; the absence of effective controls, as suggested by situational crime prevention theory [Clarke, R. V. G., ed. 1997. Situational Crime Prevention. Criminal Justice Press] is reflected in the high levels of offending seen online. The extent to which information systems can manage information-seeking behaviour in a way that is consistent with regulatory or policy requirements in the online environment is discussed, with a view to establishing a foundation and terminology to modify information behaviour theory for the online environment.
Paul A. Watters, Jacqueline Ziegler
Behav. Inf. Technol.1
2016 Editorial for FGCS special issue: Big Data in the cloud
Victor Chang 0001, Muthu Ramachandran, Gary B. Wills, Robert John Walters, Chung-Sheng Li, Paul A. Watters
Future Gener. Comput. Syst.6
2015 Authorship analysis of aliases: Does topic influence accuracy?
abstract
Abstract Aliasesplay an important role in online environments by facilitating anonymity, but also can be used to hide the identity of cybercriminals. Previous studies have investigated this alias matching problem in an attempt to identify whether two aliases are shared by an author, which can assist with identifying users. Those studies create their training data by randomly splitting the documents associated with an alias into two sub-aliases. Models have been built that can regularly achieve over 90% accuracy for recovering the linkage between these ‘random sub-aliases’. In this paper, random sub-alias generation is shown to enable these high accuracies, and thus does not adequately model the real-world problem. In contrast, creating sub-aliases using topic-based splitting drastically reduces the accuracy of all authorship methods tested. We then present a methodology that can be performed on non-topic controlled datasets, to produce topic-based sub-aliases that are more difficult to match. Finally, we present an experimental comparison between many authorship methods to see which methods better match aliases under these conditions, finding that localn-gram methods perform better than others.
Robert Layton, Paul A. Watters, Richard Dazeley
Nat. Lang. Eng.2
2014 A methodology for estimating the tangible cost of data breaches
Robert Layton, Paul A. Watters
J. Inf. Secur. Appl.2
2013 REPLOT: REtrieving profile links on Twitter for suspicious networks detection
abstract
In the last few decades social networking sites have encountered their first large-scale security issues. The high number of users associated with the presence of sensitive data (personal or professional) is certainly an unprecedented opportunity for malicious activities. As a result, one observes that malicious users are progressively turning their attention from traditional e-mail to online social networks to carry out their attacks. Moreover, it is now observed that attacks are not only performed by individual profiles, but that on a larger scale, a set of profiles can act in coordination in making such attacks. The latter are referred to as malicious social campaigns. In this paper, we present a novel approach that combines authorship attribution techniques with a behavioural analysis for detecting and characterizing social campaigns. The proposed approach is performed in three steps: first, suspicious profiles are identified from a behavioural analysis; second, connections between suspicious profiles are retrieved using a combination of authorship attribution and temporal similarity; third, a clustering algorithm is performed to identify and characterise the suspicious campaigns obtained. We provide a real-life application of the methodology on a sample of 1,000 suspicious Twitter profiles tracked over a period of forty days. Our results show that a large set of suspicious profiles behaves in coordination (70%) and propagates mainly, but not only, trustworthy URLs on the online social network. Among the three largest detected campaigns, we have highlighted that one represents an important security issue for the platform by promoting a significant set of malicious URLs.
Charles Perez, Babiga Birregah, Robert Layton, Marc Lemercier, Paul A. Watters
ASONAM5
2013 Young people, child pornography, and subcultural norms on the Internet
abstract
Literature to date has treated as distinct two issues (a) the influence of pornography on young people and (b) the growth of Internet child pornography, also called child exploitation material (CEM). This article discusses how young people might interact with, and be affected by, CEM. The article first considers the effect of CEM on young victims abused to generate the material. It then explains the paucity of data regarding the prevalence with which young people view CEM online, inadvertently or deliberately. New analyses are presented from a 2010 study of search terms entered on an internationally popular peer‐to‐peer website, isoHunt. Over 91 days, 162 persistent search terms were recorded. Most of these related to file sharing of popular movies, music, and so forth. Thirty‐six search terms were categorized as specific to a youth market and perhaps a child market. Additionally, 4 deviant, and persistent search terms were found, 3 relating to CEM and the fourth to bestiality. The article discusses whether the existence of CEM on a mainstream website, combined with online subcultural influences, may normalize the material for some youth and increase the risk of onset (first deliberate viewing). Among other things, the article proposes that future research examines the relationship between onset and sex offending by youth.
Jeremy Prichard, Caroline Spiranovic, Paul A. Watters, Christopher Peter Lueg
J. Assoc. Inf. Sci. Technol.3
2013 Automated unsupervised authorship analysis using evidence accumulation clustering
abstract
Abstract Authorship Analysis aims to extract information about the authorship of documents from features within those documents. Typically, this is performed as a classification task with the aim of identifying the author of a document, given a set of documents of known authorship. Alternatively, unsupervised methods have been developed primarily as visualisation tools to assist the manual discovery of clusters of authorship within a corpus by analysts. However, there is a need in many fields for more sophisticated unsupervised methods to automate the discovery, profiling and organisation of related information through clustering of documents by authorship. An automated and unsupervised methodology for clustering documents by authorship is proposed in this paper. The methodology is named NUANCE, forn-gram Unsupervised Automated Natural Cluster Ensemble. Testing indicates that the derived clusters have a strong correlation to the true authorship of unseen documents.
Robert Layton, Paul A. Watters, Richard Dazeley
Nat. Lang. Eng.2
2013 Evaluating authorship distance methods using the positive Silhouette coefficient
abstract
Abstract Unsupervised Authorship Analysis (UAA) aims to cluster documents by authorship without knowing the authorship of any documents. An important factor in UAA is the method for calculating the distance between documents. This choice of the authorship distance method is considered more critical to the end result than the choice of cluster analysis algorithm. One method for measuring the correlation between a distance metric and a labelling (such as class values or clusters) is the Silhouette Coefficient (SC). The SC can be leveraged by measuring the correlation between the authorship distance method and the true authorship, evaluating the quality of the distance method. However, we show that the SC can be severely affected by outliers. To address this issue, we introduce the Positive Silhouette Coefficient, given as the proportion of instances with a positive SC value. This metric is not easily altered by outliers and produces a more robust metric. A large number of authorship distance methods are then compared using the PSC, and the findings are presented. This research provides an insight into the efficacy of methods for UAA and presents a framework for testing authorship distance methods.
Robert Layton, Paul A. Watters, Richard Dazeley
Nat. Lang. Eng.2
2012 Recentred local profiles for authorship attribution
abstract
Abstract Authorship attribution methods aim to determine the author of a document, by using information gathered from a set of documents with known authors. One method of performing this task is to create profiles containing distinctive features known to be used by each author. In this paper, a new method of creating an author or document profile is presented that detects features considered distinctive, compared to normal language usage. Thisrecentreingapproach creates more accurate profiles than previous methods, as demonstrated empirically using a known corpus of authorship problems. This method, named recentred local profiles, determines authorship accurately using a simple ‘best matching author’ approach to classification, compared to other methods in the literature. The proposed method is shown to be more stable than related methods as parameter values change. Using a weighted voting scheme, recentred local profiles is shown to outperform other methods in authorship attribution, with an overall accuracy of 69.9% on thead-hocauthorship attribution competition corpus, representing a significant improvement over related methods.
Robert Layton, Paul A. Watters, Richard Dazeley
Nat. Lang. Eng.2
2011 A Survey on Latest Botnet Attack and Defense
abstract
A botnet is a group of compromised computers, which are remotely controlled by hackers to launch various network attacks, such as DDoS attack and information phishing. Botnet has become a popular and productive tool behind many cyber attacks. Recently, the owners of some botnets, such as storm worm, torpig and conflicker, are employing fluxing techniques to evade detection. Therefore, the understanding of their fluxing tricks is critical to the success of defending from botnet attacks. Motivated by this, we survey the latest botnet attacks and defenses in this paper. We begin with introducing the principles of fast fluxing (FF) and domain fluxing (DF), and explain how these techniques were employed by botnet owners to fly under the radar. Furthermore, we investigate the state-of-art research on fluxing detection. We also compare and evaluate those fluxing detection methods by multiple criteria. Finally, we discuss future directions on fighting against botnet based attacks.
Shui Yu 0001, Di Wu 0050, Paul A. Watters
TrustCom4
2011 Internet subcultures and pathways to the use of child pornography
Jeremy Prichard, Paul A. Watters, Caroline Spiranovic
Comput. Law Secur. Rev.2
2011 Real-time detection of children's skin on social networking sites using Markov random field modelling
Mofakharul Islam, Paul A. Watters, John Yearwood
Inf. Secur. Tech. Rep.2
2011 Social networking threats
Paul A. Watters
Inf. Secur. Tech. Rep.1
2011 How much material on BitTorrent is infringing content? A case study
Paul A. Watters, Robert Layton, Richard Dazeley
Inf. Secur. Tech. Rep.1
2008 New Traceability Codes and Identification Algorithm for Tracing Pirates
abstract
With the increasing popularity of digital products, there is a strong desire to protect the rights of owners against illegal redistribution. Traditional encryption schemes alone do not provide a comprehensive solution to digital rights management, since they do not prevent users who are authorized to use a digital product for their own use from transferring the cleartext content to unauthorized users. However, traceability schemes can be used to trace the illegitimate redistributors effectively. Two types of traceability schemes have been proposed in the literature - traceability codes (TA codes), and codes with the identifiable parent properties (IPP codes). TA codes are special IPP codes, and many TA codes implement an efficient identification algorithm which can determine at least one redistributor. However, many IPP codes are not TA codes, in which case, no efficient identification algorithms are available. In this paper, we generalize the definition of TA codes to derive a new family of traceability codes that is much larger than the family of traditional TA codes. By using existing decoding algorithms with respect to the Lee distance, an efficient identification algorithm is proposed for generalized TA codes. Furthermore, we show that the identification algorithm of generalized TA codes can find more redistributors than those of traditional TA codes.
Xinwen Wu, Paul A. Watters, John Yearwood
ISPA2
2008 Forensic Characteristics of Phishing - Petty Theft or Organized Crime?
Stephen McCombie, Paul A. Watters, Alex Ng, Brett Watson
WEBIST (1)2
2008 Visual detection of LSB-encoded natural image steganography
abstract
Many steganographic systems embed hidden messages inside the least significant bit layers of colour natural images. The presence of these messages can be difficult to detect by using statistical steganalysis. However, visual steganalysis by humans may be more successful in natural image discrimination. This study examined whether humans could detect least-significant bit steganography in 15 color natural images from the VisTex database using a controlled same/different task ( N = 58) and a yes/no task ( N = 61). While d ′ > 1 was observed for color layers 4--8, layers 1--3 had d ′ < 1 in both experiments. Thus, layers 1--3 appear to be highly resistant to visual steganalysis.
Paul A. Watters, Frances H. Martin, H. Steffen Stripf
ACM Trans. Appl. Percept.1
2007 Are Younger People More Difficult to Identify or Just a Peer-to-Peer Effect
Wai Han Ho, Paul A. Watters, Dominic R. Verity
CAIP2
2007 A New Performance Evaluation Method for Face Identification - Regression Analysis of Misidentification Risk
abstract
The performance of a face identification system varies with its enrollment size. However, most experiments evaluated the performance of algorithms at only one enrollment size with the rank-1 identification rate. The current practice does not demonstrate the usability of algorithms thoroughly. But the problem is, in order to measure identification performance at different sizes, experimenters have to repeat the evaluation with samples of those sizes, which is almost impossible when they are large. Approaches using the Binomial theorem with match and non-match scores have been proposed to estimate performance at different sizes, but as a separate process from the evaluation itself. This paper presents a new way of evaluating identification algorithms that allows the estimating and comparing of performance at different sizes, using the regression analysis of Misidentification Risk.
Wai Han Ho, Paul A. Watters
CVPR2
2007 Robustness of the New Owner-Tester Approach for Face Identification Experiments
abstract
With the broad application of face identification, it is important that the performance estimated for an algorithm using a sample can be generalized to the population performance. We proposed using an Owner-Tester setup to replace the current approach for experiments on face identification (or other biometrics and pattern recognition systems). This paper looks into the robustness of the Owner-Tester setup in terms of goodness of fit and performance estimation using misidentification risk -the newly suggested performance evaluation metric. Testing results have indicated that the approach is robust in term of goodness of fit and performance estimation.
Wai Han Ho, Paul A. Watters, Dominic R. Verity
CVPR2
2004 Coding distributed representations of natural scenes: a comparison of orthogonal and non-orthogonal models
Paul A. Watters
Neurocomputing1
2003 Distributed Variance In Localized Principal Components Of Whitened Natural Scenes
abstract
Naïve models of V1 simple cells, based on principal components analysis (PCA), have poor performance and do not form a distributed population code, limiting their scientific value and practical application in pattern recognition of natural scenes. This paper evaluates two strategies for enhancing the validity of PCA models that have been applied to comparable nonorthogonal models: pre-cortical "whitening", and local decomposition of visual features. The goal is to form a distributed population code. Four sets (landscapes, trees and plants, people and animals, and books and buildings) of sixteen natural images (256 × 256 pixels) were whitened and decomposed into 160 randomly selected local segments of either 8 × 8 or 16 × 16 pixels. The variance distribution of each representation was evaluated using a "distributed coding efficiency index" (DCE). Highly significant increases in DCE were observed for the principal components of local, whitened image segments compared to whole, nonwhitened images. This suggests that whitening and local decomposition may improve PCA performance for natural image processing, potentially providing more accurate simple cell models. In addition, the comparatively good performance of more complex, nonorthogonal models may be partially explained by their use of whitening and local decomposition.
Paul A. Watters
Int. J. Pattern Recognit. Artif. Intell.1
1999 A Neural Network Model of Semantic Processing Errors in Parkinson's Disease
Paul A. Watters, Malti Patel
Neural Process. Lett.1