:: 414 Words

My research has consistently focused on establishing trust in systems where users, computation, and adversaries interact across boundaries. My work has moved from physical and interactive systems security, through browser and Web security, to trustworthy machine learning and privacy-preserving computation.

Research Themes

1. Web Security & Privacy

Investigating vulnerabilities in browser extensions, hardware sensor APIs, tracking mechanisms, and Web integrity. This includes benchmarking the privacy impact of real-world extensions, protecting the DOM against malicious injections, and conducting forensic analyses of private browsing modes.

2. Privacy-Preserving & Verifiable Systems

Researching the practical deployment of cryptographic protocols, verifiable computation, decentralized auditing, and e-voting. This includes engineering self-enforcing electronic voting systems using homomorphic encryption and zero-knowledge proofs.

3. Trustworthy Machine Learning

Developing privacy-preserving auditing frameworks, fairness metrics, and socio-technical security models for machine learning systems. This includes verifiable fairness frameworks that do not expose underlying training data, and work on the relationship between user trust and AI accountability.

4. Security of Physical Systems

Investigating physical authentication, paper fingerprinting, acoustic emanations, and mobile sensor side-channel. This includes extracting cryptographic keys from paper texture and demonstrating practical deep-learning-based acoustic side-channel attacks.


Research leading to Platform Impact

Academic research is only half the equation; I focus on real-world deployment and platform mitigation.

  • 2014 — Private browsing: Research identified privacy leakage in private-browsing implementations across major browsers.
  • 2016 — W3C Motion/Orientation: Research on browser sensor attacks contributed to privacy and security changes in the Web platform.
  • 2018 — Browser security: Research on mobile sensor side channels and private browsing privacy leakages contributed to security fixes in Mozilla Firefox and Apple iOS Safari.
  • 2023 — W3C pressure sensors: Research was acknowledged in pressure-sensor standardisation work.

Research Leadership

During my academic career, I supervised and co-supervised research teams across security, privacy, and trustworthy AI, and contributed to funded projects including AGENCY, AP4L, Cyfer, and trustworthy-machine-learning Knowledge Transfer Partnerships. My research team alumni have gone on to roles including software engineering at Amazon and JPMorgan Chase, and information-security leadership at FDM Group.

Current Direction

My current work is closer to the architecture of the Web itself. Through Samsung Research UK and W3C, I work on questions around privacy, identity, language, AI, browser capabilities, and how emerging technologies should fit into the Web platform.

Publications

Most updated list is in my Scholar Profile, but more detail for each paper is here