Research
My work examines how connected systems establish trustworthy identity, identify abuse, share security knowledge, and preserve privacy.
I combine system design, data-driven security analysis, protocol evaluation, graph modelling, proof-of-concept implementation, and controlled experimentation.
Security of VoIP and Next-Generation Networks
Telecommunication systems often rely on weak or fragmented identity signals. Attackers exploit these weaknesses for caller ID spoofing, robocalls, vishing, fraud, and unsolicited communication.
Caller Identity Assurance
- Spoofing detection and verification
- Identity linking across changing identifiers
- Cross-network authentication
Unwanted Communication
- Robocall and telemarketing detection
- Vishing and fraud analysis
- Spam over Internet Telephony
IoT, Mobile, and Cyber-Physical Security
This work addresses security and privacy risks in heterogeneous environments with different capabilities, trust relationships, and operational constraints.
Detection and Resilience
- Intrusion and malware detection
- Federated and edge-enabled learning
- Explainable security analytics
Access and Assurance
- Zero-trust security for IoT
- Mobile application privacy analysis
- Blockchain-supported audit and access
Trust, Reputation, and Decentralised Identity
I design mechanisms that let distributed participants assess behaviour and collaborate without exposing unnecessary information.
Decentralised Trust
- Secure reputation aggregation
- Machine-to-machine reputation
- Online marketplace and vehicle trust
Accountable Collaboration
- Privacy-aware threat sharing
- Verifiable identity and credentials
- Data minimisation and auditability
Trustworthy and Verifiable AI
This research studies how organisations can verify AI behaviour, detect distributed attacks, and maintain evidence across complex model and agent lifecycles.
AI Provenance and Assurance
- Tamper-evident inference evidence
- Cross-session attack-process provenance
- Independent verification and audit
Agentic AI Security
- Promptware and tool-use controls
- Zero-trust enforcement for agents
- LLM and blockchain assurance
Research Methods
- Threat and assurance modellingDefine adversaries, protected assets, attack paths, assumptions, security properties, and residual risks.
- System and protocol designBuild detection models, trust services, privacy controls, verification mechanisms, and secure gateways.
- Empirical evaluationCompare security, privacy, verifiability, operational cost, and utility against relevant baselines.
- Reproducible evidenceProduce structured traces, scripts, configurations, and analysis that support independent review.
Selected Funded Activity
EPSRC · External collaborator
Spoofing Identification in Heterogeneous Telecommunication Networks
Collaboration with the University of Warwick. Total funding: £1 million.
ONTOCHAIN · Co-Principal Investigator
Decentralised Reputation System for Online Marketplaces
Total funding: €123,000.
Innovate UK · Academic supervisor
Data Integration and Intelligence Developer
Knowledge Transfer Partnership. Total funding: £284,000.
FCT Portugal · Principal Investigator
Towards Detecting Unwanted Calls in VoIP
Total funding: €60,000.