Supervision

Research group and supervision

Three PhDs and one MPhil completed, four PhD researchers in progress, and more than 40 BSc and MSc projects supervised at Cardiff since 2019, most of them applying machine learning to real attacks.

PhD researchersBSc & MSc projectsProspective students

PhD researchers

Current

Obrina Briliyant

Continuous, AI-assisted compliance auditing for IoT security

Closing the gap between point-in-time audits and live IoT networks. The work combines human-centred continuous audit, knowledge graphs and retrieval-augmented LLMs for packet and log analysis, and ML intrusion detection for smart buildings and vehicle networks.

Key papers: Computers & Security 2026 · Journal of Cybersecurity 2026 · JCP 2026

Arunima Chaudhary

Generative AI in cyber security education

Exploring how generative AI can be brought safely into security teaching, addressing transparency, accuracy and security, and using LLMs to help students analyse code vulnerabilities.

Key papers: Springer LNNS 2025 · CISSE 2026

Nima Valizadeh

Forecasting vehicle emissions trajectories using data-driven approaches

Developing data-driven methods and surrogate models to forecast how vehicle emissions will evolve, drawing on machine learning, digital twins and edge computing for sustainable, smart transport. Nima is also a Research Software Engineer at Cardiff, working on the security of EV charging infrastructure.

Related papers: ACM Computing Surveys 2025 · IET ITS 2026 · Profile

Jenny Highfield

Operational technology security incident response

Researching how organisations detect, respond to and recover from cyber incidents in operational technology: the industrial control systems behind critical national infrastructure, studied through testbeds, cyber ranges and digital twins. Jenny also works on how to teach cyber-physical security, teaches at the National Software Academy and is a member of the NCSC ICS Community of Interest.

Key papers: ICERI 2025 · Profile

Completed

Dr Muzun Althunayyan

Intrusion detection for in-vehicle networks

Built intrusion detection for the CAN bus in modern cars. The thesis combined hierarchical federated learning, so vehicles learn from each other without sharing raw data, with a multi-stage detector for known and unknown attacks and a lightweight feature-selection method for CAN data.

Key papers: Vehicular Communications 2024 · Future Internet 2024 · Computer Networks 2026

Dr Fatimah Aloraini

Adversarial attacks on intrusion detection in connected and autonomous vehicles

Showed how attackers can fool machine-learning intrusion detection systems, including crafting traffic that triggers floods of false alarms, and what that means for defending connected and autonomous vehicles and IoT from insiders.

Key papers: Sensors 2024 · IEEE CSR 2024 · JISA 2022

Dr Turki Al Lelah

Abuse of legitimate cloud services for command-and-control

Investigated how malware hides its command-and-control traffic inside trusted cloud and public services, and developed ways to detect it with dynamic malware analysis and machine learning.

Key papers: JCP 2023 (review) · JCP 2023 · IEEE ISNCC 2024

Loic Lorente Lemoine MPhil

Exploring adaptive machine learning applications in edge IDS for vehicular systems

Investigated adaptive machine-learning models for intrusion detection that run at the edge, on or near the vehicle, so connected vehicles can detect attacks in real time as threats change.

BSc and MSc projects supervised

Final-year BSc and MSc dissertation projects I have supervised since 2019, grouped by theme.

Phishing and social engineering

  • A multi-layered framework for detecting AI-generated phishing attacks 2026
  • PhishEye: a hybrid system for detecting phishing campaigns 2026
  • Lightweight explainable SMS phishing detection using pre-trained language models 2026
  • Deepfake or social engineering detection 2026
  • Understanding human emotional vulnerability to phishing email using eye tracking 2025
  • OSINT phishing tracker 2025
  • Hacking human vulnerability to phishing 2024–25
  • Phishing trends 2024–25
  • Quantifying a person's risk score from their susceptibility to phishing 2024
  • Classifier for phishing email 2021
  • A machine-learning scanner to detect phishing and malware-bearing emails 2021
  • Educational animation tool for phishing and vishing awareness 2021

Malicious content and cybercrime online

  • Detection and security analysis of malicious websites 2026
  • A machine-learning crawler detecting malicious websites via multi-dimensional feature analysis 2024
  • Detecting drive-by downloads on Twitter and uncovering cybercriminal tactics 2023
  • Fingerprinting the networks of users disseminating malware on Twitter 2023
  • Relevant features and models for detecting malicious COVID-19 tweets 2021
  • Predicting the information flow and survival of malicious posts around COVID-19 2021
  • Using machine learning to detect cryptocurrency scams 2021

Intrusion and malware detection

  • AI-driven automation for intrusion detection: efficient analysis of PCAP files 2024
  • An adaptive defence architecture using an adaptive honeypot algorithm and network traffic classifier 2023
  • Detecting DDoS attacks on a network 2022
  • A network-activity model to detect attacks from malicious web servers 2021
  • Penetration testing based on machine learning 2021
  • Identifying the best machine-learning model for web-based attacks 2020

IoT, vehicles and cyber-physical systems

  • A time-based intrusion detection system for cyber-physical vehicle networks 2025
  • A CAN bus AI model to detect cyber-attacks 2024
  • Secure cloud platform for MiFi devices and mobile apps (industry project with the Cyber Innovation Hub) 2024
  • Risk quantification and analysis of malicious IoT network traffic 2023
  • A machine-learning model to identify attacks on IoT devices 2021–22
  • Malware detection from IoT devices using machine-learning algorithms 2020

Cyber risk, governance and operations

  • Implementing a Security Operations Centre in public sector organisations 2025
  • The impact of risk perception on cyber security training effectiveness in SMEs 2023
  • Giving corporate leadership visibility of residual risk across monolithic and microservice development 2022

Security education and AI

  • VulnForge: generative AI to create and deploy replayable hands-on security challenges 2026
  • How human–AI collaboration modes shape the perceived quality of portfolio websites 2026
  • Is AI leading to more cheating in education? 2025
  • Cyber escape rooms for IT and OT 2024
  • Capture the Flag learning resource 2024
  • Findbridge: connecting non-native speakers with local services 2023

Prospective PhD students

I welcome proposals in cybercrime and phishing, intrusion detection, adversarial and explainable machine learning, LLMs for security, and IoT or vehicle security. Please send a short proposal covering the scope, the state of the art and its limitations, your proposed methods, and the contribution you expect to make, to [email protected].