Milan Stojkov

Milan Stojkov is an Assistant Professor and a researcher in secure software and cyber-physical systems, with expertise spanning information and systems security, critical infrastructures, distributed systems, and standards-driven secure software engineering. He is interested in what it takes to make a security guarantee provable rather than merely plausible — stating precisely what is protected, against which adversary, under which assumptions, and then building systems that survive the argument. In practice this means applied cryptography, privacy-enhancing technologies, access control in distributed and decentralised settings, and formal methods used as engineering tooling rather than as an end in itself.

He received his B.Sc. (2014), M.Sc. (2015), and Ph.D. (2022) degrees in Computing and Control Engineering from the Faculty of Technical Sciences, University of Novi Sad, Serbia. He began his academic career in 2016 as a Teaching Assistant in the Department of Computing and Control Engineering, where he has been continuously engaged in teaching and research, and currently holds the position of Assistant Professor.

From August 2023 to July 2024, he held the position of Postdoctoral Research Scholar at the School of Computing and Augmented Intelligence, Ira A. Fulton Schools of Engineering, Arizona State University, USA, within the STAM (Secure, Trusted, and Assured Microelectronics) Center. During this appointment, he served as Lead Researcher of the Secure & Resilient Cyber-Physical Systems (SECPS) Laboratory. His research addressed the design of security models and protocols for distributed systems, aiming to enable collective and aggregated security capabilities, coordinated services, and resilience in highly heterogeneous cyber-physical environments. In parallel, he led the development of a comprehensive software stack for an open, capability-based secure compartmentalization architecture, including a microkernel, compiler support, binary instrumentation tools, and a benchmarking framework for systematic evaluation of memory-related vulnerabilities. He was a co-instructor for the graduate-level course CSE/CEN 598 Hardware Security & Trust.

His doctoral research focused on secure software engineering methodologies and practices, covering both formally standardized processes and industry-proven approaches. A particular emphasis of his work lies in security requirements engineering, especially the analysis and formal interpretation of requirements defined by international standardization bodies such as ISO/IEC and NIST, and their consistent translation into software design, implementation, and verification artifacts.

He participated in the European Network for Cybersecurity (NECS) PhD Winter Schools in 2017 and 2018, organized within European Union–funded initiatives aimed at training and developing early-stage researchers, in alignment with the European Cybersecurity Strategy and the European Commission’s Digital Agenda. He was a scholarship holder of the Young Talent Fund of the Republic of Serbia, Ministry of Youth and Sports.

Milan Stojkov is a member of the Association for Computing Machinery (ACM) and actively contributes to the international research community as a reviewer for numerous peer-reviewed international journals indexed on the SCI list. He has also been involved in several international and domestic research and education projects, including:

  1. Information Security Services Education in Serbia (ISSES). Erasmus+ Key Action 2 (Capacity Building in Higher Education), focused on strengthening higher education capacities in information security in the Republic of Serbia
  2. Trustworthy and Resilient Decentralized Intelligence for Edge Systems (TaRDIS). Horizon Europe project
  3. Edge Privacy-Preserving Computation as a Service for Trusted Collaboration. An innovative project

He is the author or co-author of more than 20 scientific papers presented at international conferences and five journal articles published in leading international SCI-indexed journals.

Alongside his academic work he builds and maintains production software, which keeps the teaching honest: the courses he runs are grounded in systems that have to survive real load and real attackers.

Research

  • Applied cryptography. Secure computation, zero-knowledge proofs, and homomorphic encryption applied to problems where the data cannot be pooled in the clear.
  • Privacy-enhancing technologies. Oblivious data structures, metadata-private communication, and anonymous credentials.
  • Provable and verified systems. Provable deletion, verified cryptographic software, and formal security models for distributed architectures.
  • Access control and data spaces. Authorization models for IoT, edge, and resilient data-space architectures.

Courses

Undergraduate studies

  • Internet Software Architectures
  • Secure Software Engineering

Professional studies

  • Algorithms and Data Structures
  • Information Security
  • Software Development Methodologies

Doctoral studies

  • Selected Topics in Information Security

Working with students

He supervises bachelor’s, master’s and doctoral’s theses and is open to proposals from students who want to work on something harder than a CRUD application. Recent supervised work includes privacy-preserving statistical analysis of medical data using homomorphic encryption, decentralised smart-grid architectures built on zero-knowledge proofs and secure multi-party computation, ORAM-based private graph analytics, and Sybil- and eclipse-resistant gossip overlays.

Themes he is happy to supervise:

  1. Applied cryptography in real systems (MPC, ZKP, FHE)
  2. Privacy-preserving data analysis and sharing
  3. Oblivious and metadata-private storage and communication
  4. Digital identity, anonymous credentials, and verifiable claims
  5. Threat modelling and security architecture of distributed systems

Students interested in any of these are welcome to get in touch by e-mail before writing a proposal.

Selected publications

A complete and current list is available on Google Scholar and ResearchGate.