Research

My work examines how connected systems establish trustworthy identity, identify abuse, share security knowledge, and preserve privacy.

I combine system design, data-driven security analysis, protocol evaluation, graph modelling, proof-of-concept implementation, and controlled experimentation.

Security of VoIP and Next-Generation Networks

Telecommunication systems often rely on weak or fragmented identity signals. Attackers exploit these weaknesses for caller ID spoofing, robocalls, vishing, fraud, and unsolicited communication.

Caller Identity Assurance

  • Spoofing detection and verification
  • Identity linking across changing identifiers
  • Cross-network authentication

Unwanted Communication

  • Robocall and telemarketing detection
  • Vishing and fraud analysis
  • Spam over Internet Telephony

IoT, Mobile, and Cyber-Physical Security

This work addresses security and privacy risks in heterogeneous environments with different capabilities, trust relationships, and operational constraints.

Detection and Resilience

  • Intrusion and malware detection
  • Federated and edge-enabled learning
  • Explainable security analytics

Access and Assurance

  • Zero-trust security for IoT
  • Mobile application privacy analysis
  • Blockchain-supported audit and access

Trust, Reputation, and Decentralised Identity

I design mechanisms that let distributed participants assess behaviour and collaborate without exposing unnecessary information.

Decentralised Trust

  • Secure reputation aggregation
  • Machine-to-machine reputation
  • Online marketplace and vehicle trust

Accountable Collaboration

  • Privacy-aware threat sharing
  • Verifiable identity and credentials
  • Data minimisation and auditability

Trustworthy and Verifiable AI

This research studies how organisations can verify AI behaviour, detect distributed attacks, and maintain evidence across complex model and agent lifecycles.

AI Provenance and Assurance

  • Tamper-evident inference evidence
  • Cross-session attack-process provenance
  • Independent verification and audit

Agentic AI Security

  • Promptware and tool-use controls
  • Zero-trust enforcement for agents
  • LLM and blockchain assurance

Research Methods

  • Threat and assurance modellingDefine adversaries, protected assets, attack paths, assumptions, security properties, and residual risks.
  • System and protocol designBuild detection models, trust services, privacy controls, verification mechanisms, and secure gateways.
  • Empirical evaluationCompare security, privacy, verifiability, operational cost, and utility against relevant baselines.
  • Reproducible evidenceProduce structured traces, scripts, configurations, and analysis that support independent review.

Selected Funded Activity

EPSRC · External collaborator

Spoofing Identification in Heterogeneous Telecommunication Networks

Collaboration with the University of Warwick. Total funding: £1 million.

ONTOCHAIN · Co-Principal Investigator

Decentralised Reputation System for Online Marketplaces

Total funding: €123,000.

Innovate UK · Academic supervisor

Data Integration and Intelligence Developer

Knowledge Transfer Partnership. Total funding: £284,000.

FCT Portugal · Principal Investigator

Towards Detecting Unwanted Calls in VoIP

Total funding: €60,000.