Publications (47)
Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine Conflict
Anh V. Vu, Daniel R. Thomas, Ben Collier +3
There has been substantial commentary on the role of cyberattacks carried out by low-level cybercrime actors in the Russia-Ukraine conflict. We analyse 358k website defacement atta…
Automatic Bill of Materials
Nicholas Boucher, Ross Anderson
Ensuring the security of software supply chains requires reliable identification of upstream dependencies. We present the Automatic Bill of Materials, or ABOM, a technique for embe…
Human-Producible Adversarial Examples
David Khachaturov, Yue Gao, Ilia Shumailov +3
Visual adversarial examples have so far been restricted to pixel-level image manipulations in the digital world, or have required sophisticated equipment such as 2D or 3D printers…
ExtremeBB: A Database for Large-Scale Research into Online Hate, Harassment, the Manosphere and Extremism
Anh V. Vu, Lydia Wilson, Yi Ting Chua +2
We introduce ExtremeBB, a textual database of over 53.5M posts made by 38.5k users on 12 extremist bulletin board forums promoting online hate, harassment, the manosphere and other…
Hey Alexa what did I just type? Decoding smartphone sounds with a voice assistant
Almos Zarandy, Ilia Shumailov, Ross Anderson
Voice assistants are now ubiquitous and listen in on our everyday lives. Ever since they became commercially available, privacy advocates worried that the data they collect can be…
Boosting Big Brother: Attacking Search Engines with Encodings
Nicholas Boucher, Luca Pajola, Ilia Shumailov +2
Search engines are vulnerable to attacks against indexing and searching via text encoding manipulation. By imperceptibly perturbing text using uncommon encoded representations, adv…
Convex duality contracts for production-grade mathematical optimization
Juan Pablo Vielma, Ross Anderson, Joey Huchette
Deploying mathematical optimization in autonomous production systems requires precise contracts for objects returned by an optimization solver. Unfortunately, conventions on dual s…
Threat Models over Space and Time: A Case Study of E2EE Messaging Applications
Partha Das Chowdhury, Maria Sameen, Jenny Blessing +5
Threat modelling is foundational to secure systems engineering and should be done in consideration of the context within which systems operate. On the other hand, the continuous ev…
Talking Trojan: Analyzing an Industry-Wide Disclosure
Nicholas Boucher, Ross Anderson
While vulnerability research often focuses on technical findings and post-public release industrial response, we provide an analysis of the rest of the story: the coordinated discl…
Reinforcement Learning with Combinatorial Actions: An Application to Vehicle Routing
Arthur Delarue, Ross Anderson, Christian Tjandraatmadja
Value-function-based methods have long played an important role in reinforcement learning. However, finding the best next action given a value function of arbitrary complexity is n…
The Taboo Trap: Behavioural Detection of Adversarial Samples
Ilia Shumailov, Yiren Zhao, Robert Mullins +1
Deep Neural Networks (DNNs) have become a powerful toolfor a wide range of problems. Yet recent work has found an increasing variety of adversarial samplesthat can fool them. Most…
Maxwell's fluid model of magnetism
Robert Brady, Ross Anderson
In 1861, Maxwell derived two of his equations of electromagnetism by modelling a magnetic line of force as a `molecular vortex' in a fluid-like medium. Later, in 1980, Berry and co…
Bad Characters: Imperceptible NLP Attacks
Nicholas Boucher, Ilia Shumailov, Ross Anderson +1
Several years of research have shown that machine-learning systems are vulnerable to adversarial examples, both in theory and in practice. Until now, such attacks have primarily ta…
CAQL: Continuous Action Q-Learning
Moonkyung Ryu, Yinlam Chow, Ross Anderson +2
Value-based reinforcement learning (RL) methods like Q-learning have shown success in a variety of domains. One challenge in applying Q-learning to continuous-action RL problems, h…
Machine Learning needs Better Randomness Standards: Randomised Smoothing and PRNG-based attacks
Pranav Dahiya, Ilia Shumailov, Ross Anderson
Randomness supports many critical functions in the field of machine learning (ML) including optimisation, data selection, privacy, and security. ML systems outsource the task of ge…
One Protocol to Rule Them All? On Securing Interoperable Messaging
Jenny Blessing, Ross Anderson
European lawmakers have ruled that users on different platforms should be able to exchange messages with each other. Yet messaging interoperability opens up a Pandora's box of secu…
Attack of the Clones: Measuring the Maintainability, Originality and Security of Bitcoin 'Forks' in the Wild
Jusop Choi, Wonseok Choi, William Aiken +5
Since Bitcoin appeared in 2009, over 6,000 different cryptocurrency projects have followed. The cryptocurrency world may be the only technology where a massive number of competitor…
Strong mixed-integer programming formulations for trained neural networks
Ross Anderson, Joey Huchette, Will Ma +2
We present strong mixed-integer programming (MIP) formulations for high-dimensional piecewise linear functions that correspond to trained neural networks. These formulations can be…
The gift of the gab: Are rental scammers skilled at the art of persuasion?
Sophie Van Der Zee, Richard Clayton, Ross Anderson
Rental scams are a type of advance fee fraud, in which the scammer tries to get a victim to pay a deposit to rent an apartment of which the scammer pretends to be the landlord. We…
Snitches Get Stitches: On The Difficulty of Whistleblowing
Mansoor Ahmed-Rengers, Ross Anderson, Darija Halatova +1
One of the most critical security protocol problems for humans is when you are betraying a trust, perhaps for some higher purpose, and the world can turn against you if you're caug…
Why bouncing droplets are a pretty good model of quantum mechanics
Robert Brady, Ross Anderson
In 2005, Couder, Protiere, Fort and Badouad showed that oil droplets bouncing on a vibrating tray of oil can display nonlocal interactions reminiscent of the particle-wave associat…
If it's Provably Secure, It Probably Isn't: Why Learning from Proof Failure is Hard
Ross Anderson, Nicholas Boucher
In this paper we're going to explore the ways in which security proofs can fail, and their broader lessons for security engineering. To mention just one example, Larry Paulson prov…
Sponge Examples: Energy-Latency Attacks on Neural Networks
Ilia Shumailov, Yiren Zhao, Daniel Bates +3
The high energy costs of neural network training and inference led to the use of acceleration hardware such as GPUs and TPUs. While this enabled us to train large-scale neural netw…
Manipulating SGD with Data Ordering Attacks
Ilia Shumailov, Zakhar Shumaylov, Dmitry Kazhdan +4
Machine learning is vulnerable to a wide variety of attacks. It is now well understood that by changing the underlying data distribution, an adversary can poison the model trained…
Chip and Skim: cloning EMV cards with the pre-play attack
Mike Bond, Omar Choudary, Steven J. Murdoch +2
EMV, also known as "Chip and PIN", is the leading system for card payments worldwide. It is used throughout Europe and much of Asia, and is starting to be introduced in North Ameri…
The Curse of Recursion: Training on Generated Data Makes Models Forget
Ilia Shumailov, Zakhar Shumaylov, Yiren Zhao +3
Stable Diffusion revolutionised image creation from descriptive text. GPT-2, GPT-3(.5) and GPT-4 demonstrated astonishing performance across a variety of language tasks. ChatGPT in…
Why quantum computing is hard - and quantum cryptography is not provably secure
Ross Anderson, Robert Brady
Despite high hopes for quantum computation in the 1990s, progress in the past decade has been slow; we still cannot perform computation with more than about three qubits and are no…
Hearing your touch: A new acoustic side channel on smartphones
Ilia Shumailov, Laurent Simon, Jeff Yan +1
We present the first acoustic side-channel attack that recovers what users type on the virtual keyboard of their touch-screen smartphone or tablet. When a user taps the screen with…
Bugs in our Pockets: The Risks of Client-Side Scanning
Hal Abelson, Ross Anderson, Steven M. Bellovin +11
Our increasing reliance on digital technology for personal, economic, and government affairs has made it essential to secure the communications and devices of private citizens, bus…
The Convex Relaxation Barrier, Revisited: Tightened Single-Neuron Relaxations for Neural Network Verification
Christian Tjandraatmadja, Ross Anderson, Joey Huchette +3
We improve the effectiveness of propagation- and linear-optimization-based neural network verification algorithms with a new tightened convex relaxation for ReLU neurons. Unlike pr…
Blackbox Attacks on Reinforcement Learning Agents Using Approximated Temporal Information
Yiren Zhao, Ilia Shumailov, Han Cui +3
Recent research on reinforcement learning (RL) has suggested that trained agents are vulnerable to maliciously crafted adversarial samples. In this work, we show how such samples c…
ImpNet: Imperceptible and blackbox-undetectable backdoors in compiled neural networks
Eleanor Clifford, Ilia Shumailov, Yiren Zhao +2
Early backdoor attacks against machine learning set off an arms race in attack and defence development. Defences have since appeared demonstrating some ability to detect backdoors…
BatNet: Data transmission between smartphones over ultrasound
Almos Zarandy, Ilia Shumailov, Ross Anderson
In this paper, we present BatNet, a data transmission mechanism using ultrasound signals over the built-in speakers and microphones of smartphones. Using phase shift keying with an…
Yet Another Diminishing Spark: Low-level Cyberattacks in the Israel-Gaza Conflict
Anh V. Vu, Alice Hutchings, Ross Anderson
We report empirical evidence of web defacement and DDoS attacks carried out by low-level cybercrime actors in the Israel-Gaza conflict. Our quantitative measurements indicate an im…
When Vision Fails: Text Attacks Against ViT and OCR
Nicholas Boucher, Jenny Blessing, Ilia Shumailov +2
Text-based machine learning models are vulnerable to an emerging class of Unicode-based adversarial examples capable of tricking a model into misreading text with potentially disas…
Sitatapatra: Blocking the Transfer of Adversarial Samples
Ilia Shumailov, Xitong Gao, Yiren Zhao +3
Convolutional Neural Networks (CNNs) are widely used to solve classification tasks in computer vision. However, they can be tricked into misclassifying specially crafted `adversari…
Chat Control or Child Protection?
Ross Anderson
Ian Levy and Crispin Robinson's position paper "Thoughts on child safety on commodity platforms" is to be welcomed for extending the scope of the debate about the extent to which c…
Constrained Discrete Black-Box Optimization using Mixed-Integer Programming
Theodore Papalexopoulos, Christian Tjandraatmadja, Ross Anderson +2
Discrete black-box optimization problems are challenging for model-based optimization (MBO) algorithms, such as Bayesian optimization, due to the size of the search space and the n…
Strong mixed-integer programming formulations for trained neural networks
Ross Anderson, Joey Huchette, Christian Tjandraatmadja +1
We present an ideal mixed-integer programming (MIP) formulation for a rectified linear unit (ReLU) appearing in a trained neural network. Our formulation requires a single binary v…
Violation of Bell's inequality in fluid mechanics
Robert Brady, Ross Anderson
We show that a classical fluid mechanical system can violate Bell's inequality because the fluid motion is correlated over large distances.
Trojan Source: Invisible Vulnerabilities
Nicholas Boucher, Ross Anderson
We present a new type of attack in which source code is maliciously encoded so that it appears different to a compiler and to the human eye. This attack exploits subtleties in text…
Towards Certifiable Adversarial Sample Detection
Ilia Shumailov, Yiren Zhao, Robert Mullins +1
Convolutional Neural Networks (CNNs) are deployed in more and more classification systems, but adversarial samples can be maliciously crafted to trick them, and are becoming a real…
Nudge Attacks on Point-Cloud DNNs
Yiren Zhao, Ilia Shumailov, Robert Mullins +1
The wide adaption of 3D point-cloud data in safety-critical applications such as autonomous driving makes adversarial samples a real threat. Existing adversarial attacks on point c…
No Easy Way Out: the Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and Harassment
Anh V. Vu, Alice Hutchings, Ross Anderson
Legislators and policymakers worldwide are debating options for suppressing illegal, harmful and undesirable material online. Drawing on several quantitative data sources, we show…
Markpainting: Adversarial Machine Learning meets Inpainting
David Khachaturov, Ilia Shumailov, Yiren Zhao +2
Inpainting is a learned interpolation technique that is based on generative modeling and used to populate masked or missing pieces in an image; it has wide applications in picture…
Tendrils of Crime: Visualizing the Diffusion of Stolen Bitcoins
Mansoor Ahmed-Rengers, Ilia Shumailov, Ross Anderson
The first six months of 2018 saw cryptocurrency thefts of $761 million, and the technology is also the latest and greatest tool for money laundering. This increase in crime has cau…
To compress or not to compress: Understanding the Interactions between Adversarial Attacks and Neural Network Compression
Yiren Zhao, Ilia Shumailov, Robert Mullins +1
As deep neural networks (DNNs) become widely used, pruned and quantised models are becoming ubiquitous on edge devices; such compressed DNNs are popular for lowering computational…