VLDB 2026 Research / reviewers in the wild / expert
Arash Habibi Lashkari
dblp:00/7661
· DBLP profile ↗
33ranked-venue papers
3as first author
26since 2021 · last 2026
0000-0002-1240-6433ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 2 first-author · 15 since 2021Computer networks · 5 · 5 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unveiling Hierarchical Machine Learning UDP-QUIC Intrusion Detection: Protocol-Aware Flow Analysis and a New Cloud-Generated DDoS Dataset
Sepehr Jafari, MohammadMoein Shafi, Arash Habibi Lashkari |
SECRYPT (1) | 3 |
| 2026 | CAN-BiGRUBERT: Unveiling automotive vehicle intruders by profiling and characterizing anomalies in controller area networkabstractIn-vehicle Controller Area Networks (CAN) are vulnerable to various injection attacks that can compromise the safety of vehicle occupants and result in financial losses. While a substantial body of work on CAN intrusion detection exists, it lacks multiclass attack classification models. Current multiclass models do not encompass all attack types or account for the vehicle’s state, i.e., whether the car is stationary or in motion. This work addresses these limitations by proposing CAN-BiGRUBERT, a multiclass CAN intrusion detection model that jointly predicts the vehicle state and attack class from CAN traffic windows. CAN-BiGRUBERT employs Bidirectional Encoder Representations from Transformers (BERT) to capture spatial dependencies within individual CAN frames, and a Bidirectional Gated Recurrent Unit (BiGRU) network to capture temporal dependencies across multiple frames in a window. For training and evaluating CAN-BiGRUBERT, we comprehensively reviewed current CAN intrusion datasets to select the HCRL Attack & Defense dataset, which contains all injection attacks executed in both vehicle states. We implemented CAN-BiGRUBERT and compared its performance with other variants and state-of-the-art CAN attack classification models, based on individual CAN frames, arbitration identifier (AID) sequences, and windows of complete frames. Compared to the baseline models, the proposed model achieved higher accuracy and F1-score, indicating its superior ability to predict the vehicle state and attack class simultaneously. Specifically excelling in detecting replay attacks and discriminating between driving and stationary states, CAN-BiGRUBERT represents a promising enhanced, informative intrusion detection method for in-vehicle CAN. Shaila Sharmin, Arash Habibi Lashkari, Hafizah Mansor, Andi Fitriah Abdul Kadir |
Comput. Networks | 2 |
| 2026 | Unveiling malicious PDF behavior: Interpretable classification and profiling malicious PDF using TabNet
Arousha Haghighian Roudsari, Arash Habibi Lashkari, Woong-Kee Loh |
J. Inf. Secur. Appl. | 2 |
| 2026 | Unveiling intruders' behaviors: explainable AI-based profiling of malicious bot activities in IoT networks
Sepideh Niktabe, Dilli P. Sharma, Arash Habibi Lashkari |
J. Supercomput. | 3 |
| 2025 | Unveiling smart contract vulnerabilities: Toward profiling smart contract vulnerabilities using enhanced genetic algorithm and generating benchmark datasetabstractWith the advent of blockchain networks, there has been a transition from traditional contracts to Smart Contracts (SCs), which are crucial for maintaining trust within these networks. Previous methods for analyzing SCs vulnerabilities typically suffer from a lack of accuracy and effectiveness. Many of them, such as rule-based methods, machine learning techniques , and neural networks , also struggle to detect complex vulnerabilities due to limited data availability. This study introduces a novel approach to detecting, identifying, and profiling SC vulnerabilities, comprising two key components: an updated analyzer named SCsVulLyzer (V2.0) and an advanced Genetic Algorithm (GA) profiling method. The analyzer extracts 240 features across different categories, while the enhanced GA, explicitly designed for profiling SC vulnerabilities, employs techniques such as penalty fitness function, retention of elites, and adaptive mutation rate to create a detailed profile for each vulnerability. Furthermore, due to the lack of comprehensive validation and evaluation datasets with sufficient samples and diverse vulnerabilities, this work introduces a new dataset named BCCC-SCsVul-2024. This dataset consists of 111,897 Solidity source code samples, ensuring the practical validation of the proposed approach. Additionally, three types of taxonomies are established, covering SC literature review, profiling techniques, and feature extraction. These taxonomies offer a systematic classification and analysis of information, enhancing the efficiency of the proposed profiling technique. Our proposed approach demonstrated superior capabilities with higher precision and accuracy through rigorous testing and experimentation. It not only showed excellent results for evaluation parameters but also proved highly efficient in terms of time and space complexity. Moreover, the concept of the profiling technique makes our model highly transparent and explainable. These promising results highlight the potential of GA-based profiling to improve the detection and identification of SC vulnerabilities, contributing to enhanced security in blockchain networks. Sepideh HajiHossein Khani, Arash Habibi Lashkari, Ali Mizani Oskui |
Blockchain Res. Appl. | 2 |
| 2025 | A survey on encrypted network traffic: A comprehensive survey of identification/classification techniques, challenges, and future directions
Adit Sharma, Arash Habibi Lashkari |
Comput. Networks | 2 |
| 2025 | NTLFlowLyzer: Towards generating an intrusion detection dataset and intruders behavior profiling through network and transport layers traffic analysis and pattern extraction
MohammadMoein Shafi, Arash Habibi Lashkari, Arousha Haghighian Roudsari |
Comput. Secur. | 2 |
| 2025 | VADViT: Vision transformer-driven memory forensics for malicious process detection and explainable threat attribution
Yasin Dehfouli, Arash Habibi Lashkari |
J. Inf. Secur. Appl. | 2 |
| 2025 | A Comprehensive Survey of Smart Contracts Vulnerability Detection Tools: Techniques and Methodologies
Niosha Hejazi, Arash Habibi Lashkari |
J. Netw. Comput. Appl. | 2 |
| 2025 | SCsVulSegLytix: Detecting and extracting vulnerable segments from smart contracts using weakly-supervised learningabstractSmart contracts (SCs), self-executing digital contracts deployed on blockchain networks, are becoming increasingly more prevalent in various sectors, such as finance, thanks to their automation, transparency, and cost efficiency. Given the substantial size of assets managed by them, SCs have become attractive targets for hackers, who exploit vulnerabilities in them to steal funds. Blockchain’s inherent immutability means vulnerabilities cannot be fixed quickly, and the immaturity of the Solidity programming language, which introduces potential security threats to SCs, exacerbates this problem. As such, there is a pressing need to develop security measures to identify vulnerabilities in SCs. Non-learning-based detection methods utilizing heuristics designed by experts often cannot handle the evolving complexity of SC vulnerabilities. In contrast, though typically outperforming non-learning-based solutions, learning-based solutions generally do not pinpoint the locations of vulnerabilities in SCs. Learning-based approaches that identify the locations of vulnerabilities come with several challenges: First, they convert SCs into graphs, incurring computational overhead and making the learning system more complex. Second, most require line- or function-level labels to be trained, which are difficult to gather. Lastly, their coverage of vulnerability types is not extensive, exposing the user to vulnerabilities not covered by them. This work presents SCsVulSegLytix, a learning-based approach for detecting and extracting vulnerable segments in SCs. SCsVulSegLytix uses a source code-based Transformer model trained with contract-level labels to classify entire contracts as vulnerable, followed by a post-hoc interpretability method to extract vulnerable segments in SCs according to relevance scores. Unlike previous extraction models, SCsVulSegLytix requires no line-level annotations and can be trained using contract-wide labels only, which are much easier to collect. Moreover, it operates directly on Solidity source code, substantially improving efficiency compared to expensive graph-based models. Finally, it extends support to several important classes of SC vulnerabilities, meaning developers are protected against various potential attacks. Experiments show that our model outperforms existing models concerning both contract- and line-level vulnerability identification while achieving greater computation efficiency. Borna Ahmadzadeh, Arousha Haghighian Roudsari, Sepideh HajiHossein Khani, Arash Habibi Lashkari |
J. Syst. Softw. | 4 |
| 2025 | Unveiling evasive malware behavior: toward generating a multi-sources benchmark dataset and evasive malware behavior profiling using network traffic and memory analysis
Arash Habibi Lashkari, MohammadMoein Shafi, Yongkun Li 0005, Abhay Pratap Singh, Ashley Barkworth |
J. Supercomput. | 1 |
| 2024 | Poisoning and Evasion: Deep Learning-Based NIDS under Adversarial AttacksabstractGiven their crucial role in protecting networks from numerous security threats, intrusion detection systems are crucial to any cybersecurity architecture. Deep neural networks have recently shown astounding effectiveness and performance in various machine learning applications, including intrusion detection. However, it has been observed that deep learning models are highly susceptible to a wide range of attacks during both the training and testing phases. These attacks can compromise the privacy of deep learning models, such as poisoning attacks that can affect the performance of the target model during the training process and evasion attacks that can undermine the security of these models during the testing phase. Numerous studies have been conducted to understand and mitigate these attacks and to propose more efficient techniques with higher success rates and accuracy in various tasks utilizing deep learning models, such as image classification, face recognition, network intrusion detection, and healthcare applications. Despite the considerable efforts in this area, the network domain still lacks sufficient attention to these attacks and vulnerabilities. This paper aims to address this gap by proposing a framework for adversarial attacks against network intrusion detection systems (NIDS). The proposed framework focuses on poisoning and evasion attacks and tries to combine these attacks. We evaluate the proposed framework on three CIC-IDS2017, CIC-IDS2018, and CIC-UNSW-NB15 datasets. Hesamodin Mohammadian, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
PST | 2 |
| 2024 | Unveiling vulnerable smart contracts: Toward profiling vulnerable smart contracts using genetic algorithm and generating benchmark datasetabstractSmart Contracts (SCs) are crucial in maintaining trust within blockchain networks. However, existing methods for analyzing SC vulnerabilities often lack accuracy and effectiveness, while approaches based on Deep Neural Networks (DNN) struggle with detecting complex vulnerabilities due to limited data availability. This paper proposes a novel approach to analyze Smart Contracts (SCs) vulnerabilities. Our method leverages an advanced form of Genetic Algorithm (GA) and includes the development of a comprehensive benchmark dataset consisting of 36,670 Solidity source code samples. The primary objective of our study is to profile vulnerable SCs effectively. To achieve this goal, we have devised an analyzer called SCsVulLyzer based on Genetic Algorithms, designed explicitly for profiling SCs. Additionally, we have carefully curated a new dataset encompassing a wide range of examples, ensuring the practical validation of our approach. Furthermore, we have established three distinct taxonomies that cover SCs, profiling techniques, and feature extraction. These taxonomies provide a systematic classification and analysis of information, improving the efficiency of our approach. Our methodology underwent rigorous testing through experimentation, and the results demonstrated the superior capabilities of our model in detecting vulnerabilities. Compared to traditional and DNN-based approaches, our approach achieved higher precision, recall, and F1-score, widely used metrics for evaluating model performance. Across all these metrics, our model showcased exceptional results. The customization and adaptations we implemented within the Genetic Algorithm significantly enhanced its effectiveness. Our approach detects smart contract vulnerabilities more efficiently and facilitates robust exploration. These promising results highlight the potential of GA-based profiling to improve the detection of smart contract vulnerabilities, contributing to enhanced security in blockchain networks. Sepideh HajiHossein Khani, Arash Habibi Lashkari, Ali Mizani Oskui |
Blockchain Res. Appl. | 2 |
| 2024 | Unveiling DoH tunnel: Toward generating a balanced DoH encrypted traffic dataset and profiling malicious behavior using inherently interpretable machine learning
Sepideh Niktabe, Arash Habibi Lashkari, Arousha Haghighian Roudsari |
Peer Peer Netw. Appl. | 2 |
| 2023 | An Evolutionary Algorithm for Adversarial SQL Injection Attack GenerationabstractWeb application security poses ongoing challenges for organizations, and researchers have increasingly turned to machine and deep learning techniques to address vulnerabilities such as SQL injection and Cross Site Scripting. While these studies have made notable progress, the vulnerability to adversarial attacks remains a significant challenge. In this work, we aim to explore the impact of adversarial examples on machine and deep learning applications for detecting web vulnerabilities. We propose an evolutionary algorithm to create effective adversarial samples for bypassing various detection systems by iterative exploration of the search space. The effectiveness of our proposed approach is validated through rigorous testing on different diverse SQL injection detection systems. Maryam Issakhani, Mufeng Huang, Mohammad A. Tayebi, Arash Habibi Lashkari |
ISI | 4 |
| 2023 | Securing Substations with Trust, Risk Posture, and Multi-Agent Systems: A Comprehensive ApproachabstractThe Smart Grid is an IT-integrated power grid that generates, transmits, and distributes electricity to households and businesses. The substation is a crucial element of the Smart Grid’s operation, which adjusts voltages during the entire process. The integration of IT has increased in the substation’s attack surfaces. Sophisticated attacks such as the Pipeline APT contain multi-protocol modules for various devices. Performance constraints make substations a unique case; hence it is challenging to implement encryption and intrusion detection systems. We believe trust can tackle this problem. We present an improved trust model that detects protocol-based attacks toward an IED/SCADA HMI. This model is included within a multi-agent-based trust management system that computes the substation’s risk posture. Our proposed design was implemented in a Docker-based testbed environment with a SOC-influenced dashboard to provide real-time updates. The implementation was subjected to three attack scenarios: external attack, internal attack from compromised SCADA HMI, and internal attack from a compromised non-trusted IED. We observed that our model was robust against all attacks except for the baseline replay and delay response attacks. Detecting these attacks will be considered for future work as well as trust transferability. Our institute’s website provides a publicly available dataset containing captures of our MAS testbed. Kwasi Boakye-Boateng, Ali A. Ghorbani 0001, Arash Habibi Lashkari |
PST | 3 |
| 2023 | Evaluating Label Flipping Attack in Deep Learning-Based NIDS
Hesamodin Mohammadian, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
SECRYPT | 2 |
| 2023 | IoT malware: An attribute-based taxonomy, detection mechanisms and challenges
Princy Victor, Arash Habibi Lashkari, Rongxing Lu, Tinshu Sasi, Pulei Xiong, Shahrear Iqbal |
Peer Peer Netw. Appl. | 2 |
| 2022 | Detecting Obfuscated Malware using Memory Feature Engineering
Tristan Carrier, Princy Victor, Ali Tekeoglu, Arash Habibi Lashkari |
ICISSP | 4 |
| 2022 | PDF Malware Detection based on Stacking Learning
Maryam Issakhani, Princy Victor, Ali Tekeoglu, Arash Habibi Lashkari |
ICISSP | 4 |
| 2022 | Evaluating Deep Learning-based NIDS in Adversarial Settings
Hesamodin Mohammadian, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
ICISSP | 2 |
| 2022 | Robust stacking ensemble model for darknet traffic classification under adversarial settings
Hardhik Mohanty, Arousha Haghighian Roudsari, Arash Habibi Lashkari |
Comput. Secur. | 3 |
| 2021 | A Novel Trust Model In Detecting Final-Phase Attacks in SubstationsabstractA substation’s security is paramount because it is an integral part of the Smart Grid for the transmission and distribution of electricity. Advanced persistent threats (APTs) have become the bane of the substation because they can remain undetected for a period until final attacks are launched. A lot of existing techniques may not be real-time enough to detect these final attacks. Trust, even though less investigated, can be used to tackle these attacks. In this paper, we present a trust model designed specifically for the Modbus communication protocol that can detect final attacks from APTs when a substation is compromised. This model is formed from the perspective of the substation device and was successfully tested on two publicly available Modbus datasets under three testing scenarios. The external test, the internal test, and the internal test with IP-MAC blacklisting. The first test assumes attackers’ IP, and MAC addresses are not part of the substation network, and the other two assume otherwise. Our model detected the attacks within each dataset and also revealed the attack behaviour within the two datasets. Our model can also be extended to other protocols, and this has been marked for future work. Kwasi Boakye-Boateng, Ali A. Ghorbani 0001, Arash Habibi Lashkari |
PST | 3 |
| 2021 | User Profiling on Universal Data Insights tool on IBM Cloud Pak for SecurityabstractUser profiling is one of the most important research topics where organizations endeavour to establish profiles of user activities to detect or predict potential abnormal behaviours. Previous researches have mainly focused on detecting and identifying static activities through social media. A universal analysis based on streaming settings to monitor user activities continuously is missing. This paper proposes a framework for user profiling based on UDI platforms to address this issue. Our framework consists of three main steps: simulating realistic scenarios for user activities, proposing and extracting potential features, and applying machine learning models on simulated datasets. Our experimental results show that selected machine learning algorithms can distinguish most abnormal behaviours correctly. LODA, RRCF, and LSCP algorithms achieve the highest performance among all algorithms. Tree-based algorithms such as Isolation Forest acquire the best results when considering small datasets and speed. Furthermore, machine learning algorithms’ performance demonstrates the high quality of our simulated datasets. Farzaneh Shoeleh, Masoud Erfani, Saeed Shafiee Hasanabadi, Duc-Phong Le, Arash Habibi Lashkari, Adam Frank, Ali A. Ghorbani 0001 |
PST | 5 |
| 2021 | Towards Query-efficient Black-box Adversarial Attack on Text Classification ModelsabstractRecent work has demonstrated that modern text classifiers trained on Deep Neural Networks are vulnerable to adversarial attacks. There is not sufficient study on text data in comparison to the image domain. The lack of investigation originates from the challenges that authors confront in the NLP domain. Despite being extremely prosperous, most adversarial attacks in the text domain ignore the overhead they induced on the victim model. In this paper, we propose a Query-efficient Black-box Adversarial Attack on text data that tries to attack a textual deep neural network by considering the amount of overhead that it may produce. We show that the proposed attack is as powerful as the state-of-the-art adversarial attacks while requiring fewer queries to the victim model. The evaluation of our method proves the promising results. Mohammad Mehdi Yadollahi, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
PST | 2 |
| 2021 | Classifying and clustering malicious advertisement uniform resource locators using deep learningabstractAbstract Malicious online advertisement detection has attracted increasing attention in recent years in both academia and industry. The existing advertising blocking systems are vulnerable to the evolution of new attacks and can cause time latency issues by analyzing web content or querying remote servers. This article proposes a lightweight detection system for advertisement Uniform resource locators (URLs) detection, depending only on lexical‐based features. Deep learning algorithms are used for online advertising classification. After optimizing the deep neural network architecture, our proposed approach can achieve satisfactory results with false negative rate as low as 1.31%. We also design a novel unsupervised method for data clustering. With the implementation of AutoEncoder for feature preprocessing and t‐distributed stochastic neighbor embedding for clustering and visualization, our model outperforms other dimensionality reduction algorithms by generating clear clusterings for different URL families. Xichen Zhang, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
Comput. Intell. | 2 |
| 2019 | An evaluation framework for network security visualizations
Iman Sharafaldin, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
Comput. Secur. | 2 |
| 2018 | Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization
Iman Sharafaldin, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
ICISSP | 2 |
| 2017 | Characterization of Tor Traffic using Time based Features
Arash Habibi Lashkari, Gerard Draper-Gil, Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001 |
ICISSP | 1 |
| 2017 | Towards a Network-Based Framework for Android Malware Detection and CharacterizationabstractMobile malware is so pernicious and on the rise, accordingly having a fast and reliable detection system is necessary for the users. In this research, a new detection and characterization system for detecting meaningful deviations in the network behavior of a smart-phone application is proposed. The main goal of the proposed system is to protect mobile device users and cellular infrastructure companies from malicious applications with just 9 traffic feature measurements. The proposed system is not only able to detect the malicious or masquerading apps, but can also identify them as general malware or specific malware (i.e. adware) on a mobile device. The proposed method showed the average accuracy (91.41%), precision (91.24%), and false positive (0.085) for five classifiers namely; Random Forest (RF), K-Nearest Neighbor (KNN), Decision Tree (DT), Random Tree (RT) and Regression (R). We also offer a labeled dataset of mobile malware traffic with 1900 applications includes benign and 12 different families of both adware and general malware. Arash Habibi Lashkari, Andi Fitriah Abdul Kadir, Hugo Gonzalez, Kenneth Fon Mbah, Ali A. Ghorbani 0001 |
PST | 1 |
| 2017 | A Lightweight Online Advertising Classification System using Lexical-based Features
Xichen Zhang, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
SECRYPT | 2 |
| 2016 | Characterization of Encrypted and VPN Traffic using Time-related FeaturesabstractTraffic characterization is one of the major challenges in today’s security industry. The continuous evolution
and generation of new applications and services, together with the expansion of encrypted communications
makes it a difficult task. Virtual Private Networks (VPNs) are an example of encrypted communication service
that is becoming popular, as method for bypassing censorship as well as accessing services that are geographically
locked. In this paper, we study the effectiveness of flow-based time-related features to detect VPN traffic
and to characterize encrypted traffic into different categories, according to the type of traffic e.g., browsing,
streaming, etc. We use two different well-known machine learning techniques (C4.5 and KNN) to test the accuracy
of our features. Our results show high accuracy and performance, confirming that time-related features
are good classifiers for encrypted traffic characterization. Gerard Draper-Gil, Arash Habibi Lashkari, Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001 |
ICISSP | 2 |
| 2016 | Detecting Malicious URLs Using Lexical Analysis
Mohammad Saiful Islam Mamun, Mohammad Ahmad Rathore, Arash Habibi Lashkari, Natalia Stakhanova, Ali A. Ghorbani 0001 |
NSS | 3 |