My research has consistently focused on establishing trust in systems where users, computation, and adversaries interact across boundaries.
Research Themes
1. Web Security & Privacy
Investigating vulnerabilities in browser extensions, hardware sensor APIs, tracking mechanisms, and web integrity. This includes benchmarking the privacy impact of real-world extensions (AXECC), ensuring DOM integrity against malicious injections (DOMtegrity), and conducting forensic analyses of private browsing modes.
2. Privacy-Preserving & Verifiable Systems
Researching the practical deployment of cryptographic protocols, verifiable computation, decentralized auditing, and e-voting. This encompasses engineering self-enforcing electronic voting systems utilizing homomorphic encryption and zero-knowledge proofs.
3. Trustworthy Machine Learning
Developing privacy-preserving auditing frameworks, fairness metrics, and socio-technical security models for machine learning systems. This includes architecting verifiable fairness frameworks without exposing underlying training data, and defining the relationship between user trust and AI accountability.
4. Security of Physical Systems
Investigating physical authentication, paper fingerprinting, acoustic emanations, and mobile sensor side-channels. This foundational research includes extracting cryptographic keys from paper texture and proving the practicality of deep learning-based acoustic side-channel attacks.
Research Impact
Academic research is only half the equation; I focus on real-world deployment and platform mitigation. Outcomes of my research include:
- Browser Security Changes: Influenced sensor privacy and security implementations in Apple Safari and Mozilla Firefox.
- Web Standards: Directly informed W3C specifications, particularly regarding pressure-sensor standardization and Motion/Orientation API privacy (2016).
- Intellectual Property: Inventor on two US Patents (I and II) relating to secure authentication and privacy-preserving systems.
Publications
Most updated list is in my Scholar Profile, but more detail for each paper is here
Research Team (all alumni now)
- James Clarke (PhD candidate), funded by Surrey University.
- Scott Harper (Research Associate), part of AGENCY project.
- Kevin Kuriakose (KTP Associate), co-supervised with Prof. Bonnie Buchanan.
- Adriano Bermudez Villalva (Research Associate), part of Cyfer project, co-supervised with Dr. Maryam Mehrnezhad.
- Vinod Khandkar (Research Associate), part of AP4L project, co-supervised with Prof. Nishanth Sastry.
- Kieron Ivy Turk(Research Associate), part of AP4L project, co-supervised with Prof. Nishanth Sastry.
- Alexander Boyd (PhD candidate), co-supervised with Prof. Nishanth Sastry. and Dr. Suparna De
- Saeed Fadaei (PhD candidate), co-supervised with Prof. Nishanth Sastry.
- Stella Kazamia (PhD candidate), co-supervised with Prof. Helen Trehan.
- Stephen Cook (PhD candidate), co-supervised with Dr. Maryam Mehrnezhad.
- Patrick Wake (PhD candidate, Global Head of Information Security, FDM Group), co-supervised with Prof. Sue Black.
- Amira Saleem (PhD candidate), co-supervised with Dr. Gaganjeet Aujla.
- Josh Harrison (Research Project, 2022) --> Software Development Engineer @ Amazon uk
- Jack Reeves (Research Project, 2022) --> Digital Consultant @ Newton Europe
- Jia Xiu Sai (Research Project, 2022) --> Graduate Software Engineer @ THG
- Max Dormon (Research Project, 2022) --> Software Engineer @ JPMorgn Chase