VLDB 2026 Research / reviewers in the wild / expert
Mahmoud Ammar
dblp:02/5804
· DBLP profile ↗
21ranked-venue papers
9as first author
8since 2021 · last 2026
0000-0002-4963-5854ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 7 first-author · 6 since 2021Computer networks · 4 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TAGShield: Persistent Tagging for Robust Stack Memory Error Protection
Michele Grisafi, Carlo Ramponi, Mahmoud Ammar, Silviu Vlasceanu, Bruno Crispo |
AsiaCCS | 3 |
| 2025 | SoK: Integrity, Attestation, and Auditing of Program ExecutionabstractThis paper provides a systematic exploration of Control Flow Integrity (CFI) and Control Flow Attestation (CFA) mechanisms, examining their differences and relationships. It addresses crucial questions about the goals, assumptions, features, and design spaces of CFI and CFA, including their potential coexistence on the same platform. Through a comprehensive review of existing defenses, this paper positions CFI and CFA within the broader landscape of runtime defenses, critically evaluating their strengths, limitations, and trade-offs. The findings emphasize the importance of further research to bridge the gaps in CFI and CFA and thus advance the field of runtime defenses. Mahmoud Ammar, Adam Caulfield, Ivan Oliveira Nunes |
SP | 1 |
| 2024 | On Bridging the Gap between Control Flow Integrity and Attestation Schemes
Mahmoud Ammar, Ahmed Abdelraoof, Silviu Vlasceanu |
USENIX Security Symposium | 1 |
| 2024 | FLAShadow: A Flash-based Shadow Stack for Low-end Embedded SystemsabstractRuntime attacks are a rising threat to both low- and high-end systems with the spread of techniques such as Return-Oriented Programming (ROP), which aims at hijacking the control flow of vulnerable applications. Although several control flow integrity schemes have been proposed by both academia and the industry, the vast majority of them are not compatible with low-end embedded devices, especially the ones that lack hardware security features. In this article, we propose \(\sf {\textsc {FLAShadow}}\) , a secure shadow stack design and implementation for low-end embedded systems, relying on zero hardware security features. The key idea is to leverage a software-based memory isolation mechanism to establish an integrity-protected memory area on the Flash of the target device, where \(\sf {\textsc {FLAShadow}}\) can be securely maintained. \(\sf {\textsc {FLAShadow}}\) exclusively reserves a register for maintaining the integrity of the stack pointer and also depends on a minimal trusted runtime component to avoid trusting the compiler toolchain. We evaluate an open-source implementation of \(\sf {\textsc {FLAShadow}}\) for the MSP430 architecture, showing an average performance and memory overhead of 168.58% and 25.91%, respectively. While the average performance overhead is considered high, we show that it is application dependent and incurs less than 5% for some applications. Michele Grisafi, Mahmoud Ammar, Marco Roveri, Bruno Crispo |
ACM Trans. Internet Things | 2 |
| 2022 | PISTIS: Trusted Computing Architecture for Low-end Embedded Systems
Michele Grisafi, Mahmoud Ammar, Marco Roveri, Bruno Crispo |
USENIX Security Symposium | 2 |
| 2022 | MPI: Memory Protection for Intermittent ComputingabstractBatteryless devices harvest energy from sporadic ambient sources, enabling a wide range of long-lived, stand-alone, and environmentally-friendly sustainable applications. Software on these devices operates intermittently due to frequent power failures. Each power failure leads the device to lose its computational state that hinders the forward progress of computation and memory consistency. One solution to remedy this situation is to pair programs with checkpoints to save a snapshot of the intermediate program state to non-volatile memory before a power loss. Due to the lack of protection mechanisms in the state-of-the-art intermittent systems, checkpoints can be altered either by programmer errors or deliberately by an attacker. This situation leads to catastrophic effects since the program execution might be corrupted, and in turn, the device might malfunction. In this paper, we propose MPI, a memory protection mechanism for intermittent computing systems. In particular, MPI is a minimal intermittent-compliant trusted computing base acting as a hypervisor that fully manages and protects the underlying memory of a batteryless device. MPI enables a reliable and secure generation and restoration of checkpoints, maintaining their integrity and access control in the presence of remote software-based attacks without trusting the user program or requiring programmer intervention. Notable is that MPI neither requires hardware modifications nor depends on hardware features that might not exist in all batteryless platforms. Our experiments on a real batteryless platform show that MPI provides stronger security guarantees compared to the state-of-the-art approaches, with a comparable time and energy overhead. Michele Grisafi, Mahmoud Ammar, Kasim Sinan Yildirim, Bruno Crispo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Delegated attestation: scalable remote attestation of commodity CPS by blending proofs of execution with software attestationabstractRemote Attestation (RA) is an interaction between a trusted verifier (Vrf) and one or more remote and potentially compromised devices (provers or Prv-s) that allow the former to measure the software state of the latter. RA is particularly relevant to safety-critical cyber-physical systems (CPS) where a set of low-end micro-controllers (MCUs), operate under the control of a remote and more powerful controller. In such cases, RA is an effective and relatively efficient means to detect software compromise, e.g., malware infections, on these low-end MCUs that cannot support expensive security mechanisms. Mahmoud Ammar, Bruno Crispo, Ivan Oliveira Nunes, Gene Tsudik |
WISEC | 1 |
| 2021 | OSLo: Optical Sensor Localization through Mesh Networked CamerasabstractAccurate indoor positioning remains an open research question. Existing solutions are either expensive, short-range, or inaccurate. A new approach is therefore required to cost-effectively and accurately support localization in large indoor environments. We tackle this problem by introducing a practical optical localization scheme, called OSLo, that cost-effectively scales to support large buildings. OSLo uses a meshed network of low-cost cameras as localization anchors and smart LEDs as tags, which transmit their IDs and context sensor data over the meshed cameras using optical communication. OSLo is capable of localizing dense deployments of tags with an accuracy of under 1 meter at a distance of 35 meters from the localization anchor. Furthermore, smart LED tags can be manufactured for less than $1. We systematically evaluate the performance of OSLo in the context of a real-world car localization use-case at Ford Motor Company in Germany and demonstrate promising results in terms of detection distance, and localization accuracy. Hassaan Janjua, Fan Yang 0051, Mahmoud Ammar, David Newton, Seonhi Ro, Sam Michiels, Danny Hughes 0001 |
WOWMOM | 3 |
| 2020 | Verify&Revive: Secure Detection and Recovery of Compromised Low-end Embedded DevicesabstractTiny and specialized computing platforms, so-called embedded or Internet of Things (IoT) devices, are increasingly used in safety- and privacy-critical application scenarios. A significant number of such devices offer limited or no security features, making them attractive targets for a wide variety of cyber attacks, exemplified by malware infestations. One key component in securing these devices is establishing a root of trust, which is typically attained via remote attestation (RA), a security service that aims to ascertain the current state of a remote device and detect any malicious tampering. Although several (software-based, hardware-based, and hybrid) RA approaches have been proposed to address this problem, two main issues remain, regardless of the type of RA. First, all but one of the existing RA approaches are vulnerable to Time-Of-Check Time-Of-Use (TOCTOU) attack, where a transient malware may infect the corresponding embedded device between two consecutive RA routines without being detected. Second, little attention has been devoted to efficiently and securely rescuing devices that are determined to be compromised, increasing the maintenance cost of IoT deployments, especially in industrial control systems, where (re-)deploying a new device is often a cost-sensitive operation. Mahmoud Ammar, Bruno Crispo |
ACSAC | 1 |
| 2020 | MicroVault: Reliable Storage Unit for IoT DevicesabstractThe Internet of Things (IoT) is being deployed at large scale in a wide range of long-life applications. Examples range from Industry 4.0 to smart lighting systems. These applications have diverse requirements of non-volatile storage. However, the flash memory that is used in today's IoT devices offers limited write endurance and must therefore be carefully managed if applications are to deliver on their promises of multiyear lifetimes. Managing the health of flash memory is difficult for application developers, as it requires in-depth hardware and software knowledge, which often needs to the problem being neglected. While various techniques have been proposed to preserve the health of flash memory, prior work tends to focus on a single hardware platform and data type. Furthermore, prior work does not provide lifetime guarantees. This paper tackles this problem by proposing MicroVault, a simple and unified interface for reliable non-volatile data storage on resource-constrained IoT devices. MicroVault enforces developer-specified lifetime guarantees through a range of lifetime extension techniques, which are adaptively applied based upon the needs of the application. Evaluation shows that MicroVault dramatically extends the lifetime of flash memory while minimising overhead. Emekcan Aras, Mahmoud Ammar, Fan Yang 0051, Wouter Joosen, Danny Hughes 0001 |
DCOSS | 2 |
| 2020 | WISE: A Lightweight Intelligent Swarm Attestation Scheme for the Internet of ThingsabstractThe Internet of Things (IoT) is shaped by increasing number of low-cost Internet-connected embedded devices that are becoming ubiquitous in every aspect of modern life, including safety- and privacy-critical application scenarios. Such devices offer limited or no security features, creating a large new attack surface. One key component in securing these devices is software integrity checking, which is typically attained with Remote Attestation (RA). RA is a security service that helps in detecting malware-infected IoT devices through remotely verifying their internal state by a trusted party. In the vast majority of IoT application domains, IoT devices operate in swarms or groups to achieve common tasks. Existing swarm attestation techniques are still rigid and not smart enough to address heterogeneity and adapt the different requirements of various IoT devices connected to a swarm, thus triggering the need for more efficient swarm attestation schemes. In this article, we present WISE, the first intelligent swarm attestation scheme that takes into account the various characteristics, differences, and requirements of connected devices in a swarm, aiming at minimizing the communication overhead while preserving an adequate level of security. WISE depends on a resource-efficient smart broadcast authentication scheme where devices are organized in fine-grained multi-clusters, and whenever needed, the most likely compromised devices are attested. The candidate devices are selected intelligently taking into account the attestation history and diverse characteristics and constraints of each device in the swarm. We show that WISE is suitable for resource-constrained embedded devices, highly efficient and scalable in static and dynamic heterogeneous IoT networks, and offers an adjustable level of security. Mahmoud Ammar, Bruno Crispo |
ACM Trans. Internet Things | 1 |
| 2019 | SμV - The Security MicroVisor: A Formally-Verified Software-Based Security Architecture for the Internet of ThingsabstractThe Internet of Things (IoT) is shaped by the increasing number of low-cost Internet-connected embedded devices that are becoming ubiquitous in every aspect of modern life. With their cost-sensitive design, integrating hardware-based security mechanisms into such devices is undesirable. Therefore, securing these devices is a particularly difficult challenge, especially, due to their growing popularity as attack targets, via remote malware infestations. The vast majority of such devices are bare-metal, where they execute programs in fully-accessible and unprotected memories without any operating system and even without including any form of security. This is beside the fact that IoToperating systems offer little or no protection. This paper addresses this problem through the concept of a Security MicroVisor (SμV), which provides embedded devices that lack hardware-based memory protection units with memory isolation using software virtualisation and assembly-level code verification. More specifically, our contribution is two-fold. First, we propose SμV as a software-based memory isolation technique. We then formally verify the software architecture, written in C, to prove that it is memory-safe and crash-free. Second, we propose a software-based remote attestation, as an example of a fundamental security service that can be implemented on top of SμV, to detect malware-infected devices. We first describe the design and implementation of SμV. Then, we highlight the formal verification of software architecture, and characterize the remote attestation protocol. We evaluate the SμV implementation using an 8-bit AVR microcontroller that is widely used in IoT devices. Evaluation results show that SμV provides strong security guarantees while maintaining extremely low overhead in terms of memory footprint, performance, and power consumption. Furthermore, we extend the performance evaluation also to the remote attestation scheme, illustrating its limited overhead. Mahmoud Ammar, Bruno Crispo, Bart Jacobs 0002, Danny Hughes 0001, Wilfried Daniels |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2018 | SPEED: Secure Provable Erasure for Class-1 IoT DevicesabstractThe Internet of Things (IoT) consists of embedded devices that sense and manage our environment in a growing range of applications. Large-scale IoT systems such as smart cities require significant investment in both equipment and personnel. To maximize return on investment, IoT platforms should support multiple third-party applications and adaptation of infrastructure over time. Realizing the vision of shared IoT platforms demands strong security guarantees. That is particularly challenging considering the limited capability and resource constraints of many IoT devices. Mahmoud Ammar, Wilfried Daniels, Bruno Crispo, Danny Hughes 0001 |
CODASPY | 1 |
| 2018 | WISE: Lightweight Intelligent Swarm Attestation Scheme for IoT (The Verifier's Perspective)abstractThe growing pervasiveness of Internet of Things (IoT) expands the attack surface by connecting more and more attractive attack targets, i.e. embedded devices, to the Internet. One key component in securing these devices is software integrity checking, which typically attained with Remote Attestation (RA). RA is realized as an interactive protocol, whereby a trusted party, verifier, verifies the software integrity of a potentially compromised remote device, prover. In the vast majority of IoT applications, smart devices operate in swarms, thus triggering the need for efficient swarm attestation schemes.In this paper, we present WISE, the first intelligent swarm attestation protocol that aims to minimize the communication overhead while preserving an adequate level of security. WISE depends on a resource-efficient smart broadcast authentication scheme where devices are organized in fine-grained multi-clusters, and whenever needed, the most likely compromised devices are attested. The candidate devices are selected intelligently taking into account the attestation history and the diverse characteristics (and constraints) of each device in the swarm. We show that WISE is very suitable for resource-constrained embedded devices, highly efficient and scalable in heterogenous IoT networks, and offers an adjustable level of security. Mahmoud Ammar, Mahdi Washha, Bruno Crispo |
WiMob | 1 |
| 2018 | Internet of Things: A survey on the security of IoT frameworks
Mahmoud Ammar, Giovanni Russello, Bruno Crispo |
J. Inf. Secur. Appl. | 1 |
| 2017 | Autonomous and dynamic inter-cell interference coordination techniques for future wireless networksabstractInter-Cell Interference Coordination (ICIC) techniques are proposed as solutions to alleviate the negative impact of interference on system performance, while enhancing the provided Quality of Service (QoS). Typically, the available bandwidth is divided into inner and edge sub-bands. Users are also classified into interior and edge users. The available resources in each zone are exclusively allocated to users belonging to this zone. Mobile users classification is usually based on a threshold that can be either a given mean SINR value or a given distance. However, ICIC approaches based on these static parameters cannot efficiently manage non-homogeneous distribution of users. In this paper, we introduce a dynamic handoff algorithm that aims to adapt static ICIC schemes to uneven distribution of users. Our new solution dynamically computes the classification of active users into interior and edge users, based on a heuristic load balancing algorithm. In our proposal, each cell autonomously reconfigures its bandwidth allocation constraints without modifying bandwidth repartition across the cellular network. This makes the solution well adapted to the non-uniform repartition of users at the multicell scale. Simulation results show that the proposed scheme improves bandwidth usage, reduces packet delay, and increases user satisfaction compared to state-of-the-art ICIC techniques. Mahdi Ezzaouia, Cédric Gueguen, Mohamad Yassin, Mahmoud Ammar, Xavier Lagrange, Ammar Bouallègue |
WiMob | 4 |
| 2017 | Improvement of downlink LTE system performances using nonlinear equalization methods based on SVM and Wiener-Hammerstein
Nasreddine Mallouki, Bechir Nsiri, Mohammad Ghanbarisabagh, Walid Hakimi, Mahmoud Ammar |
Wirel. Networks | 5 |
| 2010 | A new SIC-HARQ receiver for the WCDMA enhanced uplink systemabstractIn this paper, we propose a new interference canceller (SIC-HARQ) for the WCDMA enhanced uplink system which is the combination of the hybrid ARQ technique (HARQ) with an improved successive interference canceller (SIC). The proposed SIC detector is an iterative receiver which consists of a multiple stages. It is capable of eliminating multiple user interferences (MUI) by generating and subtracting the user's contribution from the received signal. At the last stage, when there are users which have transmission errors, the erroneous packets are saved at the receiver buffer and negative acknowledgements (NACK) are sent to the transmitters which in response retransmit the packets. The retransmitted packets are maximum ratio combined (MRC) with the previously saved ones. In this manner, the obtained packet after combining is more reliable than the individually transmitted packet. This increases the probability of correct decoding and increases the performance of the improved SIC detector. We have shown that the proposed SIC-HARQ receiver improves the block error rate (BLER) results of the data physical channels. This enhancement achieves, for the modulation and coding scheme 1 (MCS1), almost 5dB at the BLER equal to 10-2. Messaoud Eljamai, Mohamed Et-tolba, Samir Saoudi, Mahmoud Ammar |
IWCMC | 4 |
| 2008 | A Generalised Wideband Space-Time MIMO Channel Simulator Based on the Geometrical Multi-Radii One-Ring ModelabstractThis paper extends the geometrical one-ring multi- input multi output (MIMO) channel model for a frequency flat fading process in a land mobile radio system with respect to frequency-selectivity. Our approach enables the design of efficient simulation models for space-time MIMO channels under isotropic scattering conditions for any numbers of transmit and receive antennas. A simulation study is performed into the space- time cross correlation to gain understanding of the modification of some relevant parameters. A conventional four transmit four receive 4 x 4 MIMO radio channel is analyzed. Walid Hakimi, Mahmoud Ammar, Ammar Bouallègue, Samir Saoudi |
VTC Spring | 2 |
| 2007 | Iterative Soft Multipath Interference Cancellation Assisted by Hybrid ARQ with Constellation Rearrangement for HSDPA SystemabstractHigh speed downlink packet access (HSDPA) is the major evolution of UMTS downlink. It provides peak data rates up to 10.8 Mbps. This is reached by radio link adaptivity, which includes fast scheduling, adaptive modulation and coding (AMC), and hybrid automatic repeat request (HARQ). The performance of AMC suffers from multipath interference introduced by the channel especially when using 16-QAM modulation. This is because of the variation in bit reliabilities caused by the bit-mapping onto the signal constellation. In this paper, we present a soft iterative multipath interference canceller (MPIC) for suppressing the multipath interference. We also propose to use HARQ Chase combining with the constellation rearrangement technique in joint application with MPIC. This can equalize the variation of bit reliabilities by using different mapping rules over HARQ transmissions. It is proven that the performance of adaptive modulation and coding is significantly improved after only two HARQ transmissions. Mohamed Et-tolba, Samir Saoudi, Mahmoud Ammar, Raphaël Visoz |
VTC Spring | 3 |
| 2004 | Block turbo codes for efficient image transmission over wireless channelsabstractIn this paper we propose an image coding scheme based on Block Turbo Codes (BTC) for protecting SPIHT coded images transmitted over wireless channels. An Unequal Error Protection (UEP) scheme using different product codes is also presented. The optimization of the UEP scheme under a transmission budget constraint is investigated. Performance of the proposed system are first evaluated over Gilbert-Elliott (GE) channels. They are then compared to the well-known system of Sherwood and Zeger, through numerical simulations over a single path Rayleigh fading channel. Then, we present an optimized mobile image transmission framework involving a multiuser asynchronous DS-CDMA transmission system over Rayleigh multipath channels. Simulation results for the 512x512 Lena image, transmitted over the ITU Vehicular A channel, show that a significant gain in PSNR is obtained by using the SIC/RAKE multiuser detector in comparison with a conventional detection by the RAKE receiver. Furthermore, performance are also improved when introducing the UEP scheme. Sonia Zaibi, Mahmoud Ammar, Karine Amis, Ramesh Pyndiah, Samir Saoudi |
VCIP | 2 |