I am a Web Standards Technologist at Samsung Research UK and an Associate in the W3C Technical Architecture Group (TAG). My career is dedicated to bridging academic research, standardisation, and real-world deployment.
Career Timeline
- 2025–Present: Web Platform Architect · Samsung Research UK & W3C TAG
- 2019–2024: Academic Tenure · Trustworthy ML, privacy, fairness, and socio-technical security. (University of Surrey / Durham University / Newcastle University)
- 2018–2025: Invited Expert · W3C Device & Sensors Working Group.
- 2016–2019: Applied Researcher · Mobile/browser security and sensor privacy, influencing browser engine and W3C security changes.
- 2011–2017: Early Security Research · Authentication, cryptography, physical security, and side-channels.
Selected Projects & Implementations
Selected Projects & Implementations
Beyond theoretical research and standardisation, I develop the systems and proofs-of-concept required to validate threat models and test cryptographic primitives.
- DOMtegrity: Proposed and developed a robust cryptographic architecture to protect the Document Object Model (DOM) against manipulation by malicious or overly permissive browser extensions.
- PINlogger.js (Sensor Side-Channel Exploit): Demonstrated how mobile browser orientation and motion APIs leak user input, driving the W3C to fundamentally alter sensor permission gating.
- Acoustic Enigma / Side-Channels: Proved the practicality of acoustic side-channel attacks on physical keyboards using deep learning and standard smartphone microphones, highlighting new vectors for data leakage.
- Cryptographic Physical Authentication (Texture to the Rescue): Developed a physical-object authentication mechanism that extracts unforgeable cryptographic keys directly from the microscopic fiber structure of standard paper.
- Verifiable E-Voting: Engineered self-enforcing electronic voting systems utilizing homomorphic encryption and zero-knowledge proofs to guarantee both voter anonymity and publicly verifiable tallying.
Research Leadership & Grants
During my academic tenure, I supervised and co-supervised research teams across security, privacy, and trustworthy AI domains, successfully securing and managing research grants to fund these initiatives.
| Year | Name | Description |
|---|---|---|
| 2024–2025 | Knowledge Transfer Partnership (KTP) | Co-Investigator in KTP project on trustworthy machine learning in investment sector |
| 2024-2025 | Apple Security Research Device Program | Collaboration with Royal Holloway University of London, our team won a special Apple iPhone for the purpose of security studies |
| 2022–2025 | AGENCY: Assuring Citizen Agency in a World with Complex Online Harms | Co-Investigator in EPSRC-funded project on privacy-enhancing technologies for citizens |
| 2022–2025 | AP4L: Adaptive PETs to Protect & Promote Participation Online | Co-Investigator in EPSRC-funded project on adaptive PETs in marginalised online communities |
| 2021–2023 | Cyfer: Cybersecurity and Privacy in Fertility Technologies | Co-I in PETRAS-funded (project) and Virtual Cyfer Art Exhibition |
| 2022–2023 | Knowledge Transfer Partnership (KTP) | Co-Investigator in KTP project on trustworthy machine learning in weight management recommender systems |
| 2019 | StandICT Grant | Grant to collaborate with W3C on sensor API privacy leakages |
Public Engagement & Media
The societal impact of web privacy extends beyond engineering. My research and perspectives on digital rights, surveillance, and secure systems have been covered by major global outlets.
- Physical Security (Anti-counterfeiting Technologies): ACM Communications, E&T, The Economist, and Wall Street Journal
- Deep Learning Acoustic Side Channel Attack: CNBC, CBS, IEEE Spectrum, New Scientist
- Sensor Security (ML-based side-channel attacks): BBC, The Guardian
- Verifiable e-voting system (Cryptographically verifiable and self-enforcing voting): BBC, CoinDesk
Public Engagements (Selected)
- Invited Talk, Security Awareness Special Interest Group(SaSig) Event, Ethics in cybersecurity: Shaping a secure digital future
- Invited Talk, Surrey Security Cluster, Authenticating Physical Objects
- Interview, Zero Degrees Podcast, The role of large language models in shifting the threats in cyber security
- Panel Member, MozFest’23, on Security and Privacy of fertility-related smart devices
- Invited Talk, Sutton Trust Summer School , A Discussion on Trust, and Security
- Panel Member, Dynamo 20, FinTrust: A discussion of tech, social & ethical approaches to establish trust in FinTech
Awards & Recognition
- Nominated by Department of Computer Science at Durham University for Blavatnik award for young scientists in the UK
- Shortlisted in EPSRC Connected Nation Pioneers Competition
- Winner of The Kaspersky Lab Cyber Security Case Study Competition Hosted by The Economist on blockchain for e-voting
Patents
- US Patent (US20190342102A1): describes a method for preventing counterfeiting by capturing an image of an object's (like paper's) transparent internal structure, generating a binary code from its unique texture using filters like a Gabor filter, and using that code to authenticate the physical object against a reference code.
- US Patent II: this patent protects the specific system and apparatus used to authenticate a physical object by converting an image of its internal structural texture into a verifiable cryptographic code to prevent counterfeiting.
Exhibitions
- Co-organiser of the Cyfer art exhibition: artworks and designs that respond to scientific research on the privacy, security, and ethics of female-oriented technology. Some artefacts were presented in Victoria and Albert Museum afterwards for two weeks.
Academic Services
- Co-organiser and co-chair: CyberMi2 annual event on on Cybersecurity and Privacy for Minority and Minoritized People, 2023 (held in Royal Holloway University of London), 2024 (held in Birmingham University), will be at Edinburgh University in August 2025
- Associate Editor in Security: IET The Journal of Engineering
- Invited Reviewer/PC member (selected) NSS-SocialSec('23,'25), SSR Conference(18,19,20), STAST Conference('23,'24), PriST-AI’23. IEEE Transactions on Information Forensics Security (TIFS), IEEE Transactions on Dependable and Secure Computing (TDSC), etc.
- Guest Editor: Sensors journal (Special issue on AI Systems Design for IoT Applications)
- Member and Speaker: CryptoForma EPSRC Network of Excellence.