Dipti K. Sarmah is a Docent in the group Semantics, Cyber Security and Services (SCS) in the Department of EEMCS at the University of Twente, The Netherlands.

She works at the intersection of human behavior and cybersecurity, a space where sophisticated algorithms meet wonderfully unpredictable humans. Her research explores how information can be hidden, protected, authenticated, and sometimes unintentionally revealed. From steganography and cryptography to behavioral cybersecurity, her work aims to strengthen security not only at the system level, but at the human level, where most real-world vulnerabilities begin.

Her doctoral research developed a high-capacity, robust image steganography method using nature-inspired optimization technique. In essence, she studied how nature hides patterns and translated those principles into secure digital communication. The major outcomes of her work have been published in the Journal of Information Security and Applications and Information Sciences, contributing to advancements in secure data embedding and resilience.

Beyond technical security mechanisms, she is deeply interested in understanding why people click, trust, reuse passwords, or fall for spear-phishing attempts, and how systems can be designed to anticipate human behavior rather than merely react to breaches. Her work reflects a belief that cybersecurity is not just a technical discipline, but a socio-technical one.

Equally passionate about teaching, she holds a University Teaching Qualification Diploma from the University of Twente. She is committed to mentoring students who wish to move beyond theory and build solutions that address real-world security challenges. She particularly enjoys supervising projects that combine creativity, technical depth, and societal relevance.Selected supervised projects include:

  1. Network Authentication of Images to Stop E-Skimmers.
  2. Hide Your Pattern Password From Shoulder Surfers
  3. Studying Human Behavior to Prevent Successful Spear-phishing Attempts
  4. A Serious Game on Image Steganography Training For Students in Higher Education

Curious about cybersecurity, human behavior, or hiding messages in plain sight? Let’s talk.

Expertise

  • Computer Science

    • Steganography
    • Cryptography
    • Data Hiding
    • Steganalysis
    • stego image
    • Attack
    • Attackers
    • Mathematical Optimization

Organisations

Publications

2026

A Repository for Testing Compliance to the Internet of Things (IoT) Security Standards (2026)[Contribution to conference › Abstract] NWO ICT.OPEN 2026. Greuter, K., Sarmah, D. K., Daneva, M. & Bukhsh, F. A.Integrating user awareness and AI steganalysis for malware detection in digital image forensics (2026)[Contribution to conference › Poster] NWO ICT.OPEN 2026. Yosef, J., Shreshta, P. & Sarmah, D. K.QuishDec: Structural Anomaly-Based Detection of QR Code Phishing Attacks (2026)[Contribution to conference › Poster] NWO ICT.OPEN 2026. Gorlas, M., Bessling, T. & Sarmah, D. K.

2025

Gamifying cybersecurity: A narrative-driven approach to teaching steganography (2025)Computers & Education Open, 9. Article 100288. Weijsenfeld, F. G. J. & Sarmah, D. K.https://doi.org/10.1016/j.caeo.2025.100288A story-driven gamified education on USB-based attack (2025)Journal of computing in higher education, 37, 248-272. Rikkers, V. & Sarmah, D. K.https://doi.org/10.1007/s12528-023-09392-zHow Can Cryptography Secure Online Assessments Against Academic Dishonesty? (2025)Security and Privacy, 8(4). Article e70065. Mehrishi, A. A., Sarmah, D. K. & Daneva, M.https://doi.org/10.1002/spy2.70065An Ontological Model of the Phishing Attack Process (2025)In Enterprise, Business-Process and Information Systems Modeling: 26th International Conference, BPMDS 2025, and 30th International Conference, EMMSAD 2025, Vienna, Austria, June 16-17, 2025, Proceedings (pp. 274-289). Article 17 (Lecture Notes in Business Information Processing; Vol. 558). Springer Spektrum. Oliveira, Í., Wagner, G., Amaral, G., Sales, T. P., Bullée, J.-W., Junger, M., Sarmah, D. K., Daneva, M. & Guizzardi, G.https://doi.org/10.1007/978-3-031-95397-2_17

Research profiles

Affiliated study programs

Courses academic year 2026/2027

Courses in the current academic year are added at the moment they are finalised in the Osiris system. Therefore it is possible that the list is not yet complete for the whole academic year.

Courses academic year 2025/2026

Courses academic year 2024/2025

  1. Featured in UToday for my work on AI-resilient assessment design: https://www.utoday.nl/news/76480/how-ut-teachers-are-making-their-assessments-ai-proof
  2. Best research paper nomination at 42nd Twente Student Conference IT (2025): https://sites.google.com/view/42ntwentestudentconference
  3. Best research paper nomination at  41st Twente Student Conference IT (2024): https://sites.google.com/view/41thtwentestudentconference/programme-and-proceedings
  4. A small contribution of our research was published in an interview conducted by Eveline Meijer from AG Connect at the following link: https://www.agconnect.nl/artikel/social-engineering-groter-risico-door-coronacrisis

News on utwente.nl

https://www.utwente.nl/en/organisation/about/shaping2030/stories/078/

Address

University of Twente

Zilverling (building no. 11), room 2062
Hallenweg 19
7522 NH Enschede
Netherlands

Navigate to location

Organisations

Scan the QR code or
Download vCard