papers

Publications (47)

cs.CR2024

Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine Conflict

Anh V. Vu, Daniel R. Thomas, Ben Collier +3

There has been substantial commentary on the role of cyberattacks carried out by low-level cybercrime actors in the Russia-Ukraine conflict. We analyse 358k website defacement atta…

cs.CR2023

Automatic Bill of Materials

Nicholas Boucher, Ross Anderson

Ensuring the security of software supply chains requires reliable identification of upstream dependencies. We present the Automatic Bill of Materials, or ABOM, a technique for embe…

cs.CV2023

Human-Producible Adversarial Examples

David Khachaturov, Yue Gao, Ilia Shumailov +3

Visual adversarial examples have so far been restricted to pixel-level image manipulations in the digital world, or have required sophisticated equipment such as 2D or 3D printers…

cs.SI2023

ExtremeBB: A Database for Large-Scale Research into Online Hate, Harassment, the Manosphere and Extremism

Anh V. Vu, Lydia Wilson, Yi Ting Chua +2

We introduce ExtremeBB, a textual database of over 53.5M posts made by 38.5k users on 12 extremist bulletin board forums promoting online hate, harassment, the manosphere and other…

cs.CR2020

Hey Alexa what did I just type? Decoding smartphone sounds with a voice assistant

Almos Zarandy, Ilia Shumailov, Ross Anderson

Voice assistants are now ubiquitous and listen in on our everyday lives. Ever since they became commercially available, privacy advocates worried that the data they collect can be…

cs.CR2023

Boosting Big Brother: Attacking Search Engines with Encodings

Nicholas Boucher, Luca Pajola, Ilia Shumailov +2

Search engines are vulnerable to attacks against indexing and searching via text encoding manipulation. By imperceptibly perturbing text using uncommon encoded representations, adv…

math.OC2026

Convex duality contracts for production-grade mathematical optimization

Juan Pablo Vielma, Ross Anderson, Joey Huchette

Deploying mathematical optimization in autonomous production systems requires precise contracts for objects returned by an optimization solver. Unfortunately, conventions on dual s…

cs.CR2023

Threat Models over Space and Time: A Case Study of E2EE Messaging Applications

Partha Das Chowdhury, Maria Sameen, Jenny Blessing +5

Threat modelling is foundational to secure systems engineering and should be done in consideration of the context within which systems operate. On the other hand, the continuous ev…

cs.CR2022

Talking Trojan: Analyzing an Industry-Wide Disclosure

Nicholas Boucher, Ross Anderson

While vulnerability research often focuses on technical findings and post-public release industrial response, we provide an analysis of the rest of the story: the coordinated discl…

cs.LG2020

Reinforcement Learning with Combinatorial Actions: An Application to Vehicle Routing

Arthur Delarue, Ross Anderson, Christian Tjandraatmadja

Value-function-based methods have long played an important role in reinforcement learning. However, finding the best next action given a value function of arbitrary complexity is n…

cs.LG2019

The Taboo Trap: Behavioural Detection of Adversarial Samples

Ilia Shumailov, Yiren Zhao, Robert Mullins +1

Deep Neural Networks (DNNs) have become a powerful toolfor a wide range of problems. Yet recent work has found an increasing variety of adversarial samplesthat can fool them. Most…

quant-ph2015

Maxwell's fluid model of magnetism

Robert Brady, Ross Anderson

In 1861, Maxwell derived two of his equations of electromagnetism by modelling a magnetic line of force as a `molecular vortex' in a fluid-like medium. Later, in 1980, Berry and co…

cs.CL2021

Bad Characters: Imperceptible NLP Attacks

Nicholas Boucher, Ilia Shumailov, Ross Anderson +1

Several years of research have shown that machine-learning systems are vulnerable to adversarial examples, both in theory and in practice. Until now, such attacks have primarily ta…

cs.LG2020

CAQL: Continuous Action Q-Learning

Moonkyung Ryu, Yinlam Chow, Ross Anderson +2

Value-based reinforcement learning (RL) methods like Q-learning have shown success in a variety of domains. One challenge in applying Q-learning to continuous-action RL problems, h…

cs.LG2024

Machine Learning needs Better Randomness Standards: Randomised Smoothing and PRNG-based attacks

Pranav Dahiya, Ilia Shumailov, Ross Anderson

Randomness supports many critical functions in the field of machine learning (ML) including optimisation, data selection, privacy, and security. ML systems outsource the task of ge…

cs.CY2023

One Protocol to Rule Them All? On Securing Interoperable Messaging

Jenny Blessing, Ross Anderson

European lawmakers have ruled that users on different platforms should be able to exchange messages with each other. Yet messaging interoperability opens up a Pandora's box of secu…

cs.CR2022

Attack of the Clones: Measuring the Maintainability, Originality and Security of Bitcoin 'Forks' in the Wild

Jusop Choi, Wonseok Choi, William Aiken +5

Since Bitcoin appeared in 2009, over 6,000 different cryptocurrency projects have followed. The cryptocurrency world may be the only technology where a massive number of competitor…

math.OC2020

Strong mixed-integer programming formulations for trained neural networks

Ross Anderson, Joey Huchette, Will Ma +2

We present strong mixed-integer programming (MIP) formulations for high-dimensional piecewise linear functions that correspond to trained neural networks. These formulations can be…

cs.CY2019

The gift of the gab: Are rental scammers skilled at the art of persuasion?

Sophie Van Der Zee, Richard Clayton, Ross Anderson

Rental scams are a type of advance fee fraud, in which the scammer tries to get a victim to pay a deposit to rent an apartment of which the scammer pretends to be the landlord. We…

cs.CY2020

Snitches Get Stitches: On The Difficulty of Whistleblowing

Mansoor Ahmed-Rengers, Ross Anderson, Darija Halatova +1

One of the most critical security protocol problems for humans is when you are betraying a trust, perhaps for some higher purpose, and the world can turn against you if you're caug…

quant-ph2014

Why bouncing droplets are a pretty good model of quantum mechanics

Robert Brady, Ross Anderson

In 2005, Couder, Protiere, Fort and Badouad showed that oil droplets bouncing on a vibrating tray of oil can display nonlocal interactions reminiscent of the particle-wave associat…

cs.CR2023

If it's Provably Secure, It Probably Isn't: Why Learning from Proof Failure is Hard

Ross Anderson, Nicholas Boucher

In this paper we're going to explore the ways in which security proofs can fail, and their broader lessons for security engineering. To mention just one example, Larry Paulson prov…

cs.LG2021

Sponge Examples: Energy-Latency Attacks on Neural Networks

Ilia Shumailov, Yiren Zhao, Daniel Bates +3

The high energy costs of neural network training and inference led to the use of acceleration hardware such as GPUs and TPUs. While this enabled us to train large-scale neural netw…

cs.LG2021

Manipulating SGD with Data Ordering Attacks

Ilia Shumailov, Zakhar Shumaylov, Dmitry Kazhdan +4

Machine learning is vulnerable to a wide variety of attacks. It is now well understood that by changing the underlying data distribution, an adversary can poison the model trained…

cs.CY2012

Chip and Skim: cloning EMV cards with the pre-play attack

Mike Bond, Omar Choudary, Steven J. Murdoch +2

EMV, also known as "Chip and PIN", is the leading system for card payments worldwide. It is used throughout Europe and much of Asia, and is starting to be introduced in North Ameri…

cs.LG2024

The Curse of Recursion: Training on Generated Data Makes Models Forget

Ilia Shumailov, Zakhar Shumaylov, Yiren Zhao +3

Stable Diffusion revolutionised image creation from descriptive text. GPT-2, GPT-3(.5) and GPT-4 demonstrated astonishing performance across a variety of language tasks. ChatGPT in…

quant-ph2013

Why quantum computing is hard - and quantum cryptography is not provably secure

Ross Anderson, Robert Brady

Despite high hopes for quantum computation in the 1990s, progress in the past decade has been slow; we still cannot perform computation with more than about three qubits and are no…

cs.CR2019

Hearing your touch: A new acoustic side channel on smartphones

Ilia Shumailov, Laurent Simon, Jeff Yan +1

We present the first acoustic side-channel attack that recovers what users type on the virtual keyboard of their touch-screen smartphone or tablet. When a user taps the screen with…

cs.CR2021

Bugs in our Pockets: The Risks of Client-Side Scanning

Hal Abelson, Ross Anderson, Steven M. Bellovin +11

Our increasing reliance on digital technology for personal, economic, and government affairs has made it essential to secure the communications and devices of private citizens, bus…

cs.LG2020

The Convex Relaxation Barrier, Revisited: Tightened Single-Neuron Relaxations for Neural Network Verification

Christian Tjandraatmadja, Ross Anderson, Joey Huchette +3

We improve the effectiveness of propagation- and linear-optimization-based neural network verification algorithms with a new tightened convex relaxation for ReLU neurons. Unlike pr…

cs.LG2019

Blackbox Attacks on Reinforcement Learning Agents Using Approximated Temporal Information

Yiren Zhao, Ilia Shumailov, Han Cui +3

Recent research on reinforcement learning (RL) has suggested that trained agents are vulnerable to maliciously crafted adversarial samples. In this work, we show how such samples c…

cs.LG2024

ImpNet: Imperceptible and blackbox-undetectable backdoors in compiled neural networks

Eleanor Clifford, Ilia Shumailov, Yiren Zhao +2

Early backdoor attacks against machine learning set off an arms race in attack and defence development. Defences have since appeared demonstrating some ability to detect backdoors…

cs.CR2020

BatNet: Data transmission between smartphones over ultrasound

Almos Zarandy, Ilia Shumailov, Ross Anderson

In this paper, we present BatNet, a data transmission mechanism using ultrasound signals over the built-in speakers and microphones of smartphones. Using phase shift keying with an…

cs.CR2025

Yet Another Diminishing Spark: Low-level Cyberattacks in the Israel-Gaza Conflict

Anh V. Vu, Alice Hutchings, Ross Anderson

We report empirical evidence of web defacement and DDoS attacks carried out by low-level cybercrime actors in the Israel-Gaza conflict. Our quantitative measurements indicate an im…

cs.CR2025

When Vision Fails: Text Attacks Against ViT and OCR

Nicholas Boucher, Jenny Blessing, Ilia Shumailov +2

Text-based machine learning models are vulnerable to an emerging class of Unicode-based adversarial examples capable of tricking a model into misreading text with potentially disas…

cs.LG2019

Sitatapatra: Blocking the Transfer of Adversarial Samples

Ilia Shumailov, Xitong Gao, Yiren Zhao +3

Convolutional Neural Networks (CNNs) are widely used to solve classification tasks in computer vision. However, they can be tricked into misclassifying specially crafted `adversari…

cs.CY2022

Chat Control or Child Protection?

Ross Anderson

Ian Levy and Crispin Robinson's position paper "Thoughts on child safety on commodity platforms" is to be welcomed for extending the scope of the debate about the extent to which c…

math.OC2022

Constrained Discrete Black-Box Optimization using Mixed-Integer Programming

Theodore Papalexopoulos, Christian Tjandraatmadja, Ross Anderson +2

Discrete black-box optimization problems are challenging for model-based optimization (MBO) algorithms, such as Bayesian optimization, due to the size of the search space and the n…

math.OC2019

Strong mixed-integer programming formulations for trained neural networks

Ross Anderson, Joey Huchette, Christian Tjandraatmadja +1

We present an ideal mixed-integer programming (MIP) formulation for a rectified linear unit (ReLU) appearing in a trained neural network. Our formulation requires a single binary v…

physics.gen-ph2013

Violation of Bell's inequality in fluid mechanics

Robert Brady, Ross Anderson

We show that a classical fluid mechanical system can violate Bell's inequality because the fluid motion is correlated over large distances.

cs.CR2023

Trojan Source: Invisible Vulnerabilities

Nicholas Boucher, Ross Anderson

We present a new type of attack in which source code is maliciously encoded so that it appears different to a compiler and to the human eye. This attack exploits subtleties in text…

cs.LG2020

Towards Certifiable Adversarial Sample Detection

Ilia Shumailov, Yiren Zhao, Robert Mullins +1

Convolutional Neural Networks (CNNs) are deployed in more and more classification systems, but adversarial samples can be maliciously crafted to trick them, and are becoming a real…

cs.CR2020

Nudge Attacks on Point-Cloud DNNs

Yiren Zhao, Ilia Shumailov, Robert Mullins +1

The wide adaption of 3D point-cloud data in safety-critical applications such as autonomous driving makes adversarial samples a real threat. Existing adversarial attacks on point c…

cs.CR2024

No Easy Way Out: the Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and Harassment

Anh V. Vu, Alice Hutchings, Ross Anderson

Legislators and policymakers worldwide are debating options for suppressing illegal, harmful and undesirable material online. Drawing on several quantitative data sources, we show…

cs.LG2021

Markpainting: Adversarial Machine Learning meets Inpainting

David Khachaturov, Ilia Shumailov, Yiren Zhao +2

Inpainting is a learned interpolation technique that is based on generative modeling and used to populate masked or missing pieces in an image; it has wide applications in picture…

cs.CY2020

Tendrils of Crime: Visualizing the Diffusion of Stolen Bitcoins

Mansoor Ahmed-Rengers, Ilia Shumailov, Ross Anderson

The first six months of 2018 saw cryptocurrency thefts of $761 million, and the technology is also the latest and greatest tool for money laundering. This increase in crime has cau…

cs.CR2020

To compress or not to compress: Understanding the Interactions between Adversarial Attacks and Neural Network Compression

Yiren Zhao, Ilia Shumailov, Robert Mullins +1

As deep neural networks (DNNs) become widely used, pruned and quantised models are becoming ubiquitous on edge devices; such compressed DNNs are popular for lowering computational…