I am a Web Standards Technologist at Samsung Research UK and an Associate in the W3C Technical Architecture Group (TAG). My career is dedicated to bridging academic research, standardisation, and real-world deployment.
Career Timeline
- 2025–Present: Web Platform Architect · Samsung Research UK & W3C TAG
- 2019–2024: Academic Tenure · Trustworthy ML, privacy, fairness, and socio-technical security. (University of Surrey / Durham University / Newcastle University)
- 2018–2025: Invited Expert · W3C Device & Sensors Working Group.
- 2016–2019: Applied Researcher · Mobile/browser security and sensor privacy, influencing browser engine and W3C security changes.
- 2011–2017: Early Security Research · Authentication, cryptography, physical security, and side-channels.
z
Selected Projects & Implementations
Beyond theoretical research and standardisation, I develop the systems and proofs-of-concept required to validate threat models and test cryptographic primitives.
- DOMtegrity: Proposed and developed a robust cryptographic architecture to protect the Document Object Model (DOM) against manipulation by malicious or overly permissive browser extensions.
- PINlogger.js (Sensor Side-Channel Exploit): Demonstrated how mobile browser orientation and motion APIs leak user input, driving the W3C to fundamentally alter sensor permission gating.
- Acoustic Attacks: Proved the practicality of acoustic side-channel attacks on physical keyboards using deep learning and standard smartphone microphones, highlighting new vectors for data leakage.
- Cryptographic Physical Authentication (Texture to the Rescue):Developed a physical-object authentication mechanism that extracts unforgeable cryptographic keys directly from the microscopic fiber structure of standard paper.
- Verifiable E-Voting: Engineered self-enforcing electronic voting systems utilising homomorphic encryption and zero-knowledge proofs to guarantee both voter anonymity and publicly verifiable tallying.
Research Leadership & Grants
Bridging theoretical security and real-world deployment requires significant ecosystem collaboration. During my academic tenure, I served as a Co-Investigator (Co-I) and collaborative lead on consortia focusing on privacy-enhancing technologies, trustworthy AI, and platform security.
I have contributed to securing over £4.5 million in total grant funding, directly supervising over £1 million of these budgets.
- EPSRC AGENCY (£3.5M): Co-Investigator for a major UKRI consortium assuring citizen agency against complex online harms. I managed £1M of the total fund and led a cross-disciplinary team of five academics to develop adaptive Privacy-Enhancing Technologies (PETs).
- Trustworthy AI / KTPs (£780k): Co-Investigator on two Knowledge Transfer Partnerships applying verifiable machine learning frameworks to commercial environments (a £500k healthcare system and a £280k investment management solution).
- Apple Security Research Device Program: Secured collaborative access (under a 1% acceptance rate) to specialized Apple hardware alongside Royal Holloway University of London to conduct advanced mobile security threat modeling.
- PETRAS CyFer (£220k): Co-Investigator researching cybersecurity, privacy, and bias vulnerabilities in female-oriented health technologies.
- W3C Standardisation (StandICT): Secured European Commission funding to collaborate directly with the W3C, accelerating the mitigation of hardware sensor API privacy leakages within browser engines.
Doctoral Supervision & Team Building
As a research leader, I secured three fully funded home-student PhD scholarships (at the University of Surrey and Durham University) to direct active research into:
- Trustworthy physical fraud detection with machine learning (2024).
- Security and privacy of accessibility technologies (2023).
- Privacy-preserving, fair machine learning (2022).
Public Engagement & Media
The societal impact of web privacy extends beyond engineering. My research and perspectives on digital rights, surveillance, and secure systems have been covered by major global outlets.
- Physical Security (Anti-counterfeiting Technologies): ACM Communications, E&T, The Economist, and Wall Street Journal
- Deep Learning Acoustic Side Channel Attack: CNBC, CBS, IEEE Spectrum, New Scientist
- Sensor Security (ML-based side-channel attacks): BBC, The Guardian
- Verifiable e-voting system (Cryptographically verifiable and self-enforcing voting): BBC, CoinDesk
Public Engagements (Selected)
- Invited Talk, Security Awareness Special Interest Group(SaSig) Event, Ethics in cybersecurity: Shaping a secure digital future
- Invited Talk, Surrey Security Cluster, Authenticating Physical Objects
- Interview, Zero Degrees Podcast, The role of large language models in shifting the threats in cyber security
- Panel Member, MozFest’23, on Security and Privacy of fertility-related smart devices
- Invited Talk, Sutton Trust Summer School , A Discussion on Trust, and Security
- Panel Member, Dynamo 20, FinTrust: A discussion of tech, social & ethical approaches to establish trust in FinTech
Awards & Recognition
- Nominated by Department of Computer Science at Durham University for Blavatnik award for young scientists in the UK
- Shortlisted in EPSRC Connected Nation Pioneers Competition
- Winner of The Kaspersky Lab Cyber Security Case Study Competition Hosted by The Economist on blockchain for e-voting
Patents
- US Patent (US20190342102A1): describes a method for preventing counterfeiting by capturing an image of an object's (like paper's) transparent internal structure, generating a binary code from its unique texture using filters like a Gabor filter, and using that code to authenticate the physical object against a reference code.
- US Patent II: this patent protects the specific system and apparatus used to authenticate a physical object by converting an image of its internal structural texture into a verifiable cryptographic code to prevent counterfeiting.
Exhibitions
- Co-organiser of the Cyfer art exhibition: artworks and designs that respond to scientific research on the privacy, security, and ethics of female-oriented technology. Some artefacts were presented in Victoria and Albert Museum afterwards for two weeks.
Academic Services
- Co-organiser and co-chair: CyberMi2 annual event on on Cybersecurity and Privacy for Minority and Minoritized People, 2023 (held in Royal Holloway University of London), 2024 (held in Birmingham University), will be at Edinburgh University in August 2025
- Associate Editor in Security: IET The Journal of Engineering
- Invited Reviewer/PC member (selected) NSS-SocialSec('23,'25), SSR Conference(18,19,20), STAST Conference('23,'24), PriST-AI’23. IEEE Transactions on Information Forensics Security (TIFS), IEEE Transactions on Dependable and Secure Computing (TDSC), etc.
- Guest Editor: Sensors journal (Special issue on AI Systems Design for IoT Applications)
- Member and Speaker: CryptoForma EPSRC Network of Excellence.
Research Team (all alumni now)
- James Clarke (PhD candidate), funded by Surrey University.
- Scott Harper (Research Associate), part of AGENCY project.
- Kevin Kuriakose (KTP Associate), co-supervised with Prof. Bonnie Buchanan.
- Adriano Bermudez Villalva (Research Associate), part of Cyfer project, co-supervised with Dr. Maryam Mehrnezhad.
- Vinod Khandkar (Research Associate), part of AP4L project, co-supervised with Prof. Nishanth Sastry.
- Kieron Ivy Turk(Research Associate), part of AP4L project, co-supervised with Prof. Nishanth Sastry.
- Alexander Boyd (PhD candidate), co-supervised with Prof. Nishanth Sastry. and Dr. Suparna De
- Saeed Fadaei (PhD candidate), co-supervised with Prof. Nishanth Sastry.
- Stella Kazamia (PhD candidate), co-supervised with Prof. Helen Trehan.
- Stephen Cook (PhD candidate), co-supervised with Dr. Maryam Mehrnezhad.
- Patrick Wake (PhD candidate, Global Head of Information Security, FDM Group), co-supervised with Prof. Sue Black.
- Amira Saleem (PhD candidate), co-supervised with Dr. Gaganjeet Aujla.
- Josh Harrison (Research Project, 2022) --> Software Development Engineer @ Amazon uk
- Jack Reeves (Research Project, 2022) --> Digital Consultant @ Newton Europe
- Jia Xiu Sai (Research Project, 2022) --> Graduate Software Engineer @ THG
- Max Dormon (Research Project, 2022) --> Software Engineer @ JPMorgn Chase