:: 1449 Words

I am a Senior Research Engineer (Web Standards Technologist) at Samsung Research UK and an Associate in the W3C Technical Architecture Group (TAG). My career bridges academic cryptography, applied software engineering, and Web standardisation.

Career Timeline

  • 2025–Present: Senior Research Engineer · Samsung Research UK & W3C TAG
  • 2019–2024: Academic Tenure · Trustworthy ML, privacy, fairness, and socio-technical security. (University of Surrey / Durham University / Newcastle University)
  • 2018–2025: Invited Expert · W3C Device & Sensors Working Group.
  • 2016–2019: Applied Researcher · Mobile/browser security and sensor privacy, influencing browser engine and W3C security changes.
  • 2011–2017: Early Security Research · Authentication, cryptography, physical security, and side-channels.

Research Leadership & Cross-Institutional Collaboration

Bridging theoretical security and real-world deployment requires significant ecosystem collaboration. During my academic tenure, I served as a Principle-Investigator (PI), Co-Investigator (Co-I) and collaborative lead on consortia focusing on privacy-enhancing technologies, trustworthy AI, and platform security.

I have contributed to securing over £4.5 million in total grant funding, directly supervising over £1 million of these budgets.

  • EPSRC AGENCY (£3.5M): Co-Investigator for a major UKRI consortium assuring citizen agency against complex online harms. As Project Local Lead in Durham University, I managed £1M of the total fund and led a cross-disciplinary team of five academics to develop adaptive Privacy-Enhancing Technologies (PETs).
  • Trustworthy AI / KTPs (£780k): Co-Investigator on two Knowledge Transfer Partnerships applying verifiable machine learning frameworks to commercial environments (a £500k healthcare system and a £280k investment management solution).
  • Apple Security Research Device Program: Secured collaborative access (under a 1% acceptance rate) to specialized Apple hardware alongside Royal Holloway University of London to conduct advanced mobile security threat modeling.
  • PETRAS CyFer (£220k): Co-Investigator researching cybersecurity, privacy, and bias vulnerabilities in female-oriented health technologies.
  • W3C Standardisation (StandICT): Secured European Commission funding to collaborate directly with the W3C, accelerating the mitigation of hardware sensor API privacy leakages within browser engines.

Doctoral Supervision & Team Building

As a research leader, I secured three fully funded home-student PhD scholarships (at the University of Surrey and Durham University) to direct active research into:

  1. Trustworthy physical fraud detection with machine learning (2024).
  2. Security and privacy of accessibility technologies (2023).
  3. Privacy-preserving, fair machine learning (2022).

Selected Technical Work

Beyond theoretical research and standardisation, I develop the systems and proofs-of-concept required to validate threat models and test cryptographic primitives.

  • DOMtegrity: Proposed and developed a robust cryptographic architecture to protect the Document Object Model (DOM) against manipulation by malicious or overly permissive browser extensions.
  • PINlogger.js (Sensor Side-Channel Exploit): Demonstrated how mobile browser orientation and motion APIs leak user input, driving the W3C to fundamentally alter sensor permission gating.
  • Acoustic Attacks: Proved the practicality of acoustic side-channel attacks on physical keyboards using deep learning and standard smartphone microphones, highlighting new vectors for data leakage.
  • Cryptographic Physical Authentication (Texture to the Rescue):Developed a physical-object authentication mechanism that extracts unforgeable cryptographic keys directly from the microscopic fiber structure of standard paper.
  • Verifiable E-Voting: Engineered self-enforcing electronic voting systems utilising homomorphic encryption and zero-knowledge proofs to guarantee both voter anonymity and publicly verifiable tallying.

Public Engagements (Selected)

Selected Media Coverage

Awards & Recognition

Patents

  • US Patent (US20190342102A1): describes a method for preventing counterfeiting by capturing an image of an object's (like paper's) transparent internal structure, generating a binary code from its unique texture using filters like a Gabor filter, and using that code to authenticate the physical object against a reference code.
  • US Patent II: this patent protects the specific system and apparatus used to authenticate a physical object by converting an image of its internal structural texture into a verifiable cryptographic code to prevent counterfeiting.

Exhibitions

  • Co-organiser of the Cyfer art exhibition: artworks and designs that respond to scientific research on the privacy, security, and ethics of female-oriented technology. Some artefacts were presented in Victoria and Albert Museum afterwards for two weeks.

Academic Services

Research Team (all alumni now)

  • James Clarke (PhD candidate), funded by Surrey University.
  • Scott Harper (Research Associate), part of AGENCY project.
  • Adriano Bermudez Villalva (Research Associate), part of Cyfer project, co-supervised with Dr. Maryam Mehrnezhad.
  • Kieron Ivy Turk(Research Associate), part of AP4L project, co-supervised with Prof. Nishanth Sastry.
  • Saeed Fadaei (PhD candidate), co-supervised with Prof. Nishanth Sastry.
  • Patrick Wake (PhD candidate, Global Head of Information Security, FDM Group), co-supervised with Prof. Sue Black.
  • Josh Harrison (Research Project, 2022) --> Software Development Engineer @ Amazon uk
  • Max Dormon (Research Project, 2022) --> Software Engineer @ JPMorgn Chase