Associate Professor Nalin Arachchilage

Associate Professor Nalin Arachchilage

Associate Professor in Cyber Security

Details

Open to

  • Masters Research or PhD student supervision
  • Media enquiries
  • Collaborative projects
  • Industry Projects
  • Join a web conference as a panellist or speaker
  • Membership of an advisory committee
  • Mentoring (long-term)

About

Dr Nalin Arachchilage is an Associate Professor in Cyber Security in the School of Computing Technologies at RMIT University, a Regenerative Futures Fellow, and the Group Leader of the Human-Centred Cyber Security (HCCS) research group within the RMIT Centre for Cyber Security Research and Innovation (CCSRI). He currently leads the redevelopment of RMIT’s Master of Cyber Security program, integrating regenerative futures principles to create a cutting-edge, industry-informed, and culturally inclusive curriculum that fosters sustainable, ethical, and resilient cyber capabilities for the evolving digital landscape.

Nalin’s career reflects a global journey of academic leadership and innovation across Australia, New Zealand, the United Kingdom, Canada, Vietnam, and Sri Lanka. He has held senior research and teaching roles that bridge academia, industry, and government, shaping the next generation of cybersecurity education and practice.

At the University of Auckland, he served as Senior Lecturer and Assistant Head of School (Research), where he led the Master of Professional Studies in Digital Security program and strengthened research capacity in emerging areas of cyber resilience. He was previously a Senior Research Fellow at La Trobe University, contributing to the Optus–La Trobe Cyber Security Research Hub, advancing applied cybersecurity research and industry collaboration.

Nalin led the Usable Security Engineering Group, where he pioneered Australia’s first human-centred cybersecurity courses for defence personnel, integrating behavioural science with secure systems design. His international research journey began at the University of Oxford, where he worked as a Postdoctoral Research Assistant on systems security engineering and trust frameworks, followed by a Postdoctoral Fellowship at the University of British Columbia (UBC), Canada, exploring human behaviour and decision-making in digital security and privacy.

He has also held an Honorary Associate Professorship in Cyber Security at the University of Warwick (UK) and currently serves as a Technical Advisor to DEFSAFE Cyber Security Inc. (New Zealand), providing strategic direction on cyber risk, training, and product innovation.

Together, these experiences position Nalin as a thought leader at the intersection of research, education, and policy, dedicated to strengthening cyber resilience across communities, industry, and national security sectors.

 

Research Focus:

Nalin’s research advances human-centred cybersecurity and privacy by integrating the human, technical, and policy dimensions of digital trust. Positioned at the intersection of computer security, human–computer interaction (HCI), software engineering, machine learning (ML), and natural language processing (NLP), his work focuses on building secure, ethical, and resilient technologies that place people at the centre of digital design.

 

With a strong emphasis on AI safety and responsible technology development, Nalin’s research tackles some of the most pressing national and global cyber challenges, including:

🧠 Human-Centred Cybersecurity & Privacy: Designing secure systems that account for user behaviour, cognition, and decision-making.

🔐 Applied & Post-Quantum Cryptography: Supporting developers to integrate quantum-resilient algorithms into contemporary applications.

🤖 AI, ML, NLP & Responsible AI Security: Safeguarding systems and societies against AI-driven deception, misinformation, and adversarial attacks.

🛰️ Critical Infrastructure, Space, Satellite & IoT Security: Enhancing resilience and trust in cyber-physical and Positioning, Navigation and Timing (PNT) systems.

⚙️ Cybersecurity Capability, Policy & Regulation: Informing policy frameworks that strengthen national digital security and workforce capability.

 

Nalin’s interdisciplinary research has led to high-impact outcomes — including improving the OWASP Enterprise Security API (ESAPI 2.2.1.0), enabling developers worldwide to build more secure applications. He has presented his research at Facebook Headquarters (Menlo Park, USA), collaborated with HP Labs (Bristol, UK), and his work has featured widely across national and international media (ABC TV, ABC News Radio, Sky News Australia, TVNZ 1 News, Guardian Labs, and 10 News TV Australia).

 

Leadership & Engagement:

A recognised thought leader in human-centred cybersecurity, Nalin has served on program committees for the world’s premier security and privacy venues, including:

ACM CCS (2022–2024), ACM AsiaCCS (2023–2024), USEC (2025-2026), USENIX SOUPS (2018–2024), ACM CSCW(Associate Chair 2019–2024), ACM FAccT 2022, and EASE 2019.
He has also contributed as Karat Award Chair (SOUPS 2021), SOUPS Mentor (2020), and ACM CSCW Awards Committee Member (2023) — reflecting his sustained global leadership in usable security and privacy research.

 

Academic Pathway & Mentorship:

Nalin holds a PhD in Cyber Security from Brunel University London, where he developed a game-based learning framework to teach users how to defend against phishing attacks. He also earned an MSc in Information Management and Security (University of Bedfordshire, UK) and a BSc (Hons) in Management Information Systems from University College Dublin, Ireland.

He is a Sun Certified Java Programmer (SCJP) and has extensive international teaching experience across leading universities in the UK, Canada, and Australia.

 

Dr Arachchilage actively supervises PhD, Master’s, and Honours students at RMIT University.
Prospective students or collaborators interested in cybersecurity, privacy, AI security, or human-centred cyber research are warmly encouraged to contact him at nalin.arachchilage@rmit.edu.au.

Media

Research fields

  • 4604 Cybersecurity and privacy
  • 460806 Human-computer interaction
  • 4612 Software engineering
  • 4611 Machine learning
  • 460208 Natural language processing
  • 460706 Serious games
  • 460904 Information security management

Academic positions

  • RMIT Regenerative Futures Fellow
  • RMIT University
  • Melbourne, Australia
  • 10 Mar 2025 – Present
  • Associate Professor in Cyber Security
  • RMIT University, Australia
  • School of Computing Technologies
  • Melbourne, Australia
  • 2024 – Present
  • Director of MProfStuds in Digital Security
  • The University of Auckland
  • The School of Computer Science
  • Auckland, New Zealand
  • 2022 – 2024
  • Assistant Head of School (Research)
  • The University of Auckland
  • The School of Computer Science
  • Auckland, New Zealand
  • 2022 – 2023
  • Lecturer/Senior Lecturer in Cyber Security
  • The University of Auckland
  • The School of Computer Science
  • Auckland, New Zealand
  • 2021 – 2024
  • Senior Research Fellow in Cyber Security
  • La Trobe University
  • Optus La Trobe Cyber Security Research Hub, La Trobe University
  • Melbourne, Australia
  • 2019 – 2021
  • PhD Research Supervisor (External)
  • King’s College London (KCL)
  • Department of Informatics
  • London, United Kingdom
  • 2019 – Present
  • Lecturer (Assistant Professor) in Cyber Security
  • University of New South Wales, Australian Defence Force Academy (ADFA)
  • Canberra, Australia
  • 2015 – 2019
  • Postdoctoral Research Fellow in Usable Security
  • The University of British Columbia
  • Electrical and Computer Engineering
  • Vancouver, Canada
  • 2014 – 2015
  • Postdoctoral Research Assistant in Systems Security Engineering
  • Oxford University
  • Department of Computer Science
  • Oxford, United Kingdom
  • 2013 – 2014

Non-academic positions

  • Advisor (Board of Advisors)
  • DEFSAFE Cyber Security Inc
  • Auckland, New Zealand
  • 2023 – Present
  • Chair of the Academic Board (in Cyber Security)
  • Canberra Business and Technology College (CBIT) - Australia
  • Canberra, Australia
  • 2020 – 2021

Supervisor projects

  • Advancing Cybersecurity Education: Leveraging Gamification Platforms and AI for Enhanced Cybersecurity Learning
  • 17 Oct 2025
  • Designing Inclusive and Intelligent Cybersecurity Literacy Tools: A Gender and Culturally Aware Approach
  • 1 Oct 2025
  • Thesis: Developing a threat model for organisations through a gamified approach to thwart phishing attacks
  • 6 Aug 2025
  • Data-Driven Machine Learning Framework for Blockchain Security
  • 13 Jun 2025
  • Digital Phenotype implications: Decoding the digital footprint of behaviors that indicate problematic gaming behaviors
  • 1 Jun 2025
  • Development of AI/ML technique on network traffic data for cyber threat intelligence generation
  • 29 May 2025
  • Advanced Automotive Intrusion Detection and Prevention Systems: Leveraging Machine Learning and Real-Time Monitoring for Cyber Attack Mitigation
  • 28 Feb 2025
  • Digital Forensic Framework: A study to develop a standard operational procedure and framework for Cyber Crime Investigations in South Asia.
  • 5 Feb 2025
  • Digital Phenotyping
  • 18 Dec 2024
  • Security training and its effects on team trust and intention to violate security protocols.
  • 10 Nov 2024
  • An Empirical Study of Computational Thinking Education in Remote Primary Schools
  • 2 Sep 2024

Teaching interests

  • Lecturer — Course coordinator - INTE2625 - Introduction to Cyber Security [2024]
  • Lecturer - COSC2738 - Human-centric Cyber Security {2025}
  • Lecturer - COSC2737 - IT Infrastructure and Security {2024]
  • Project Supervisor - COSC2410 - Software Engineering Project (2024)

Research interests

His current research addresses national and global cyber challenges, including:

🧠 Human-Centred Cybersecurity & Privacy: Designing secure systems that account for user behaviour, cognition, and decision-making.

🔐 Applied & Post-Quantum Cryptography: Supporting developers to integrate quantum-resilient algorithms into contemporary applications.

🤖 AI, ML, NLP & Responsible AI Security: Safeguarding systems and societies against AI-driven deception, misinformation, and adversarial attacks.

🛰️ Critical Infrastructure, Space, Satellite & IoT Security: Enhancing resilience and trust in cyber-physical and Positioning, Navigation and Timing (PNT) systems.

⚙️ Cybersecurity Capability, Policy & Regulation: Informing policy frameworks that strengthen national digital security and workforce capability.

Initiatives and links

aboriginal flag float-start torres strait flag float-start

Acknowledgement of Country

RMIT University acknowledges the people of the Woi wurrung and Boon wurrung language groups of the eastern Kulin Nation on whose unceded lands we conduct the business of the University. RMIT University respectfully acknowledges their Ancestors and Elders, past and present. RMIT also acknowledges the Traditional Custodians and their Ancestors of the lands and waters across Australia where we conduct our business - Artwork 'Sentient' by Hollie Johnson, Gunaikurnai and Monero Ngarigo.

More information