Prasad Calyam

dblp:06/1313 · DBLP profile ↗
← Back
116ranked-venue papers
15as first author
55since 2021 · last 2025
0000-0002-7666-5389ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 29 · 5 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 18 · 2 first-author · 9 since 2021Systems, architecture and hardware · 17 · 3 first-author · 9 since 2021Artificial intelligence and machine learning · 9 · 7 since 2021Databases, data management, data science and information retrieval · 9 · 7 since 2021Security and privacy · 8 · 4 since 2021Software engineering, systems software and programming languages · 8 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 7 · 1 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 1 first-author · 2 since 2021Theory of computation · 3 · 3 since 2021
YearPublicationVenuePosition
2025 Adaptive Virtual Reality Learning Environment with a Reinforcement Learning-Driven Pedagogical Agent
abstract
With the fast evolving advances in technology to create immersive learner experiences in Virtual Reality (VR), there are significant opportunities for developing immersive and engaging VR Learning Environments (VRLEs) to train neurodiverse individuals. Integrating Pedagogical Agents (PAs) in these VRLEs has the potential for supporting neurodiverse learners by providing personalized, adaptive guidance tailored to their unique needs. However, a key challenge lies in ensuring the PAs can adapt effectively to the diverse circumstances of the learners. In this paper, we present a novel VRLE viz., uSucceed that leverages a Reinforcement Learning (RL)-driven PA to provide adaptive, personalized support to enhance the training experiences by tailoring the VRLE to the needs of neurodiverse learners. By designing the RL-driven PA algorithm to use Deep Q-Network, we study its capability in guiding the actions of the student in an ongoing learning basis. Simulation experiment results of the speed, accuracy and efficiency of the RL-driven PA in a VRLE demonstrate the benefits of our approach. These results build a strong base for future dynamic VRLE research that can be programmed to adapt based on the learners' experience.
Sai Shreya Nuguri, Anirudh Kambhampati, Noah Glaser, Prasad Calyam, Shangman Li, Cassidy Bates, Alia Stevens, Sanjana Nuguri
CCNC4
2025 Disentangling Complex Questions in LLMs via Multi-Hop Dependency Graphs
abstract
While Large language models (LLMs) have shown to exhibit remarkable performance in a wide range of NLP tasks, they often struggle to interpret and reason over multi-hop questions in open-domain question answering (ODQA) settings. While popular prompt approaches such as Chain-of-Thought and Plan-and-Solve facilitate more manageable questions for OQDA via task decomposition, these approaches are prone to generating erroneous and redundant intermediate steps in multi-hop queries due to limited capacity for modeling complex entity relationships. In this paper, we introduce a novel prompt approach for multi-hop QA viz., MoDeGraph (Multi-Hop Dependency Graphs), that is designed to steer LLMs to extract and model entity relationships in complex questions. MoDeGraph constructs a dependency graph from LLM-generated entity-relation triples to enable more coherent and human-like multi-step reasoning. Experimental results in knowledge-intensive tasks for multi-hop QA demonstrate our approach produces more coherent and faithful reasoning chains as well as consistent increase in QA performance across several benchmark datasets.
Roland Oruche, Alphaeus Dmonte, Vani Seth, Zian Zeng, Yuanxun Zhang, Marcos Zampieri, Prasad Calyam
CIKM7
2025 NetPrompt: LLM-driven Programmable Network Policy Management and Optimization
abstract
Software-Defined Networking (SDN) requires adaptive policy generation to ensure satisfactory Quality of Service (QoS) and Quality of Experience (QoE) expectations under dynamic network conditions. While generative AI can potentially automate the optimization of network configuration, there is a lack of methods for AI-driven policy automation and enforcement, particularly in translating high-level network intent into suitable service function chains using P4 switch configurations without misconfigurations. In this paper, we present a novel framework, viz., NetPrompt, that uses Large Language Models (LLMs) for automated and intent-driven policy generation in SDN in the context of a video streaming application. By integrating prompt engineering and structured model refinement, pre-trained NetPrompt adaptively selects the appropriate LLM configuration to generate suitable P4 scripts that align with user requirements, such as dynamic QoS adaptation. We validate NetPrompt in network emulators and advanced compute/network testbed environments, including Mininet, Chameleon Cloud, and FABRIC, to construct practical network topologies for evaluation against key performance metrics such as latency reduction, throughput improvement, and error rate minimization. Our experimental results demonstrate that NetPrompt reduces misconfigurations significantly, showcasing its potential in dynamic policy management of programmable networks.
Kiran Neupane, Kevin Kostage, Sean Peppers, Prasad Calyam, Chengyi Qu
ICCCN5
2025 Edge-Enabled Scalable Routing via Graph Neural Network Pruning and Metaheuristic Optimization
abstract
Edge intelligence enables distributed decision-making by executing complex optimization tasks directly on resource-constrained edge nodes, minimizing reliance on centralized cloud infrastructure. This work introduces a hybrid edge-intelligent routing framework that combines Graph Neural Network (GNN)-based graph pruning with metaheuristic optimization to achieve scalable and low-latency routing at the network edge. The GNN functions as a lightweight inference module that identifies and removes low-utility edges from a sensing network, substantially reducing communication and computational overhead. On the resulting sparse subgraph, a Guided Local Search (GLS) algorithm performs localized route refinement to produce near-optimal paths without central coordination. This integrated GNN-GLS design allows simultaneous graph learning and optimization on edge hardware while retaining solution quality comparable to centralized solvers. Experimental results on synthetic datasets demonstrate a 13.2% runtime improvement on 1000-node graphs with only a 0.7% increase in route length, confirming the feasibility of learning-driven pruning and decentralized metaheuristic search for scalable edge deployment.
Subrahmanya Chandra Bhamidipati, William Echols, Jesus Lopez Olivares, Kenzie Markley, Sharan Srinivas, Prasad Calyam
SEC6
2025 Securing Inverter-Based Resources via Knowledge-Driven Threat Modeling, Analysis, and Mitigation
abstract
Inverter-based Resources (IBRs) present unique cybersecurity challenges due to their digital control systems and connection to the electric grid. They rely on digital communications and control systems, making them vulnerable to cyberattacks. These attacks can disrupt grid operations and stability, compromise data, or cause physical damage to equipment. To address these challenges, it is essential to establish robust cybersecurity measures that meet and exceed existing industry standards. In this paper, we describe a comprehensive strategy to bolster the cybersecurity of IBRs through cutting-edge applications and technologies via a cybersecurity framework called “CIBR-Fort”, a knowledge-driven, interoperable, scalable, and manageable framework for modeling, analysis, and mitigation of cyber threats disrupting different components of IBR systems. Our knowledge-driven analysis consists of a fusion of knowledge graphs (KGs) in cybersecurity and the electric grid, achieved through link prediction leveraging Large Language Models (LLMs) and cosine similarity, attributed towards informed decision-making for threat mitigation. The evaluation results show how we can automate LLM-driven link prediction based on the fusion of two distantly separated ontologies, generating a dataset that can be used for scaling via graph learning that can be utilized for further security analyses of IBR systems. In addition, we show our knowledge-driven threat analysis can predict different attacks with 91.88% maximum accuracy. Lastly, we show how we can achieve real-time end-to-end threat mitigation with an average of 40 ms per traffic flow.
Roshan Neupane, Vamsi Pusapati, Lakshmi Srinivas Edara, Xiyao Cheng, Kiran Neupane, Harshavardhan Chintapatla, Reshmi Mitra, Mert Korkali, Hyeong Suk Na, Sharan Srinivas, Prasad Calyam
NOMS11
2025 Entangled collaborations: tensions in cross-disciplinary user experience studies in cyberinfrastructure projects
abstract
Cyberinfrastructure research develops and deploys solutions that benefit cyberinfrastructure and the broader scientific community. Designing novel cyberinfrastructure solutions is inherently complex and requires collaborative relations between heterogeneous scientific stakeholders, governing bodies, and organisations. This study investigated the problems and pitfalls experienced in the cross-disciplinary collaboration of three groups: computer scientists (Group 1), User Experience (UX) researchers (Group 2), and domain scientists (Group 3 – bioinformatics, and health informatics researchers) who worked together to build cyberinfrastructure applications. Using participatory action research (PAR), we studied the dynamics of conducting UX research. The main results indicate four tensions that impacted the collaborative practices of cross-disciplinary groups using UX studies in cyberinfrastructure projects: (1) contradictory views on the quality of prototype development, (2) mental models of the work processes (know how) varied among the different groups (3) clarity of feedback was lacking, and (4) the usability problem was perceived to be with the users. Our results highlight the significance of aligning UX and computer science research goals and actively engaging involved cyberinfrastructure research members to meet user expectations. Findings reveal the nuanced ways in which computer science and UX work processes become entangled during the research process and shape cyberinfrastructure development.
Kanu Priya Singh, Isa Jahnke, Prasad Calyam
Behav. Inf. Technol.3
2025 ScholarFinder: Knowledge Embedding Based Recommendations Using a Deep Embedded Clustering Model
abstract
Bold scientific research tasks need multi-disciplinary knowledge and collaborations that require finding scholars from particular domains with relevant knowledge. Given the variety of scholars and diversity, finding the appropriate scholar is an important and challenging problem for scientific communities. In this paper, we propose a “ScholarFinder” framework that uses contextual information (abstracts or publications) for embedding a scholar's knowledge in an unsupervised learning manner. Specifically, we implement an unsupervised embedding technique viz.,Variational AutoEncoder (VAE). For better feature representation learning, we also implement aVariational Deep Embedded Clustering (VDEC)method that further enhances downstream tasks (e.g., clustering, classification) accuracy, scalability, and performance. In addition, we incorporate a multi-task learning scheme into our VDEC model for improving the effectiveness of simultaneously learning both embedding and clustering. Subsequently, the downstream tasks can be built based on pre-trained scholars' knowledge embeddings to predict suitability of a scholar for a research task. Using a dataset involving a 20-year collection of federal grant awards, we have demonstrated how our pre-trained model improved the performance for downstream tasks. We have also investigated how our pre-trained model can be integrated into a knowledge graph to achieve better performance. Lastly, we show that our ScholarFinder model variants outperform state-of-the-art baseline models (i.e., XGBoost, GBDT, AdaBoost, DNN, GraphSAGE, DEC, VaDE) and recent LLM based models (i.e., Bert4Rec, OpenP5) by atleast 18%.
Yuanxun Zhang, Xiyao Cheng, Roland Oruche, Sai Swathi Sivarathri, Prasad Calyam
IEEE Trans. Big Data5
2025 Securing Virtual Reality Experiences: Unveiling and Tackling Cybersickness Attacks With Explainable AI
abstract
The synergy between virtual reality (VR) and artificial intelligence (AI), specifically deep learning (DL)-based cybersickness detection models, has ushered in unprecedented advancements in immersive experiences by automatically detecting cybersickness severity and adaptively various mitigation techniques, offering a smooth and comfortable VR experience. While this DL-enabled cybersickness detection method provides promising solutions for enhancing user experiences, it also introduces new risks since these models are vulnerable to adversarial attacks; a small perturbation of the input data that is visually undetectable to human observers can fool the cybersickness detection model and trigger unexpected mitigation, thus disrupting user immersive experiences (UIX) and even posing safety risks. In this paper, we present a new type of VR attack, specifically a cybersickness attack, which successfully prevents the triggering of cybersickness mitigation by deceiving DL-based cybersickness detection models and significantly hinders the UIX. Next, we propose a novel explainable artificial intelligence (XAI)-guided cybersickness attack detection framework to detect such attacks in VR, ensuring UIX and a comfortable VR experience. We evaluate the proposed attack and detection framework using two state-of-the-art open-source VR cybersickness datasets: the Simulation 2021 dataset and the Gameplay dataset. Finally, to verify the effectiveness of our proposed method, we implement the attack and the XAI-based detection using a custom-built testbed with a VR roller coaster simulation, utilizing an HTC Vive Pro Eye headset, and conduct a user study. Our study shows that such an attack can dramatically hinder the UIX. However, our proposed XAI-guided cybersickness attack detection can successfully detect cybersickness attacks and trigger the proper mitigation, effectively reducing VR cybersickness.
Ripan Kumar Kundu, Matthew Denton, Genova Mongalo, Prasad Calyam, Khaza Anuarul Hoque
IEEE Trans. Dependable Secur. Comput.4
2025 Chatbot Dialog Design for Improved Human Performance in Domain Knowledge Discovery
abstract
The advent of machine learning (ML) has led to the widespread adoption of developing task-oriented dialog systems for scientific applications (e.g., science gateways) where voluminous information sources are retrieved and curated for domain users. Yet, there still exists a challenge in designing chatbot dialog systems that achieve widespread diffusion among scientific communities. In this article, we propose a novel Vidura advisor design framework (VADF) to develop dialog system designs for information retrieval (IR) and question-answering (QA) tasks, while enabling the quantification of system utility based on human performance in diverse application environments. We adopt a socio-technical approach in our framework for designing dialog systems by utilizing domain expert feedback, which features a sparse retriever for enabling accurate responses in QA settings using linear interpolation smoothing. We apply our VADF for an exemplar science gateway, viz. KnowCOVID-19, to conduct experiments that demonstrate the utility of dialog systems based on IR and QA performance, application utility, and perceived adoption. Experimental results show our VADF approach significantly improves IR performance against retriever baselines (up to 5% increase) and QA performance against large language models (LLMs) such as ChatGPT (up to 43% increase) on scientific literature datasets. In addition, through a usability survey, we observe that measuring application utility and human performance when applying VADF to KnowCOVID-19 translates to an increase in perceived community adoption.
Roland Oruche, Xiyao Cheng, Zian Zeng, Audrey Vazzana, MD Ashraful Goni, Bruce Wang Shibo, Sai Keerthana Goruganthu, Kerk F. Kee, Prasad Calyam
IEEE Trans. Hum. Mach. Syst.9
2024 Influence Role Recognition and LLM-Based Scholar Recommendation in Academic Social Networks
abstract
Identifying scholars and their relevant publications in interdisciplinary collaborations within an academic social network (ASN) can help drive new scientific knowledge discovery. This involves a challenging and time-consuming process, which requires scholar's influence role recognition in a scholar team for a given research task. In this paper, we propose a novel “ScholarInfluencer” recommendation system that: (a) uses a classification model combined with network analysis on a heterogeneous knowledge graph to recognize the scholar influencers within interdisciplinary teams of collaborators, and (b) features a large language model (LLM) to use influence role recognition results to support user queries to produce pertinent scholar and their publication recommendations. Our novel approach involves building a heterogeneous knowledge graph using diverse ASN datasets involving entities such as scholars, publications, research grants, and the relationship among these entities. We perform an evaluation of ScholarInfluencer using four widely-used ASN datasets (i.e., NSF, DBLP, Cora and CA-HepTh). Our experiment results show that our influence role recognition model outperforms the state-of-the-art models across the different datasets; especially in the case of the NSF dataset, our model outperforms by up to 13.6%. Further, we show how our recommendation model with role recognition outperforms the model without role recognition across the different datasets; especially in the case of the NSF dataset, our model outperforms by 7%.
Xiyao Cheng, Lakshmi Srinivas Edara, Yuanxun Zhang, Mayank Kejriwal, Prasad Calyam
DSAA5
2024 Deep Contrastive Active Learning for Out-of-domain Filtering in Dialog Systems
abstract
Task-oriented dialog systems have shown to foster effective human-chatbot collaborations for accomplishing goal-specific tasks through intent classification. In a real-world setting, collecting and training over user intents incurs a labeling-cost challenge for human annotators. While existing human-AI collaborative approaches such as active learning (AL) can properly resolve such labeling-cost challenges, most existing AL algorithms assume the unlabeled pool has similar distributions as the in domain (IND) training set. To address the conflict between AL and out-of-domain (OOD) data samples, we present Deep Contrastive Active Learning (DeCAL), a deep novel AL framework that uses contrastive learning techniques for query intent classification in task-oriented dialogs. DeCAL features an acquisition function that filters OOD samples by computing a distance-based confidence score over unlabeled samples using their neighboring features. To validate DeCAL, we compare against deep AL baselines via the performance of acquired IND/OOD samples and using the classification accuracy metric. Experimental results on benchmark datasets demonstrate De-CAL outperforms deep AL baseline algorithms on acquired OOD by 14%, while simultaneously showing competitive performance on IND accuracy.
Roland Oruche, Marcos Zampieri, Prasad Calyam
DSAA3
2024 Enhancing Autonomous Intrusion Detection System with Generative Adversarial Networks
abstract
Effective training in Machine Learning and Deep Learning models necessitates datasets that provide sufficient patterns and contextual information, particularly crucial in IoT networks. Imbalanced datasets, however, significantly challenge the performance of Autonomous Intrusion Detection Systems (IDS), leading to suboptimal detection rates for minority classes. In this paper, we address this issue by utilizing various Generative Adversarial Network (GAN) models, including WGANGP, CGAN, CTGAN, and CWGANGP, to generate synthetic data that balance these imbalanced datasets. We evaluate the performance of IDS models trained on GAN-augmented datasets against those trained on unbalanced datasets, considering metrics such as fitting duration, generation duration, accuracy, precision, recall, and F1 score. Our findings reveal substantial improvements in IDS performance with the application of GANs across binary, general, and specific attack classifications. Additionally, we compare the effectiveness of GANs with classical sampling algorithms, such as SMOTE and Random Oversampling. This comprehensive evaluation underscores the potential of GANs as a sophisticated solution for improving IDS accuracy and reliability in handling complex and highly imbalanced datasets.
Kevin Kostage, Timothy Meinert, Chengyi Qu, Prasad Calyam, Luca Mazzola
e-Science5
2024 VECA: Reliable and Confidential Resource Clustering for Volunteer Edge-Cloud Computing
abstract
Volunteer Edge-Cloud (VEC) computing has a significant potential to support scientific workflows in user communities contributing volunteer edge nodes. However, managing heterogeneous and intermittent resources to support machine/deep learning (ML/DL) based workflows poses challenges in resource governance for reliability, and confidentiality for model/data privacy protection. There is a need for approaches to handle the volatility of volunteer edge node availability, and also to scale the confidential data-intensive workflow execution across a large number of VEC nodes. In this paper, we present VECA, a reliable and confidential VEC resource clustering solution featuring three-fold methods tailored for executing ML/DL-based scientific workflows on VEC resources. Firstly, a capacity-based clustering approach enhances system reliability and minimizes VEC node search latency. Secondly, a novel two-phase, globally distributed scheduling scheme optimizes job allocation based on node attributes and using time-series-based Recurrent Neural Networks. Lastly, the integration of confidential computing ensures privacy preservation of the scientific workflows, where model and data information are not shared with VEC resources providers. We evaluate VECA in a Function-as-a-Service (FaaS) cloud testbed that features OpenFaaS and MicroK8S to support two ML/DL-based scientific workflows viz., G2P-Deep (bioinformatics) and PAS-ML (health informatics). Results from tested experiments demonstrate that our proposed VECA approach outperforms state-of-the-art methods; especially VECA exhibits a two-fold reduction in VEC node search latency and over $20 \%$ improvement in productivity rates following execution failures compared to the next best method.
Hemanth Sai Yeddulapalli, Mauro Lemus, Upasana Roy, Roshan Neupane, Durbek Gafurov, Motahare Mounesan, Saptarshi Debroy, Prasad Calyam
IC2E8
2024 Reinforcement Learning-driven Data-intensive Workflow Scheduling for Volunteer Edge-Cloud
abstract
In recent times, Volunteer Edge-Cloud (VEC) has gained traction as a cost-effective, community computing paradigm to support data-intensive scientific workflows. However, due to the highly distributed and heterogeneous nature of VEC resources, centralized workflow task scheduling remains a challenge. In this paper, we propose a Reinforcement Learning (RL)-driven data-intensive scientific workflow scheduling approach that takes into consideration: i) workflow requirements, ii) VEC resources' preference on workflows, and iii) diverse VEC resource policies, to ensure robust resource allocation. We formulate the long-term average performance optimization problem as a Markov Decision Process, which is solved using an event-based Asynchronous Advantage Actor-Critic based RL approach. Our extensive simulations and testbed implementations demonstrate our approach's benefits over popular baseline strategies in terms of workflow requirement satisfaction, VEC preference satisfaction, and available VEC resource utilization.
Motahare Mounesan, Mauro Lemus, Hemanth Sai Yeddulapalli, Prasad Calyam, Saptarshi Debroy
ICFEC4
2024 Preliminary Analysis of Empathy-Driven Design and Inclusive Cybersecurity Education: The Initial Phase of the uSucceed Project's Virtual Reality Curriculum for Neurodiverse Adults in STEM
Noah Glaser, Prasad Calyam, Yupei Duan, Shangman Li, Sai Shreya Nuguri, Cannon Ousley, Anirudh Kambhampati, Zeinab Parishani, Amogh Chetankumar Joshi, Mohan Yang
iLRN (1)2
2024 Formal Verification for Blockchain-based Insurance Claims Processing
abstract
Insurance claims processing involves multi-domain entities and multi-source data, along with a number of human-agent interactions. Use of Blockchain technology-based platform can significantly improve scalability and response time for processing of claims which are otherwise manually-intensive and time-consuming. However, the chaincodes involved within the processes that issue claims, approve or deny them as required, need to be formally verified to ensure secure and reliable processing of transactions in Blockchain. In this paper, we use a formal modeling approach to verify various processes and their underlying chaincodes relating to different stages in insurance claims processing viz., issuance, approval, denial, and flagging for fraud investigation by using linear temporal logic (LTL). We simulate the formalism on the chaincodes and analyze the breach of chaincodes via model checking.
Roshan Neupane, Ernest Bonnah, Bishnu Bhusal, Kiran Neupane, Khaza Anuarul Hoque, Prasad Calyam
NOMS6
2024 Adaptive Open-Set Active Learning with Distance-Based Out-of-Distribution Detection for Robust Task-Oriented Dialog System
abstract
The advancements in time-efficient data collection techniques such as active learning (AL) have become salient for user intent classification performance in task-oriented dialog systems (TODS).In realistic settings, however, traditional AL techniques often fail to efficiently select targeted in-distribution (IND) data when encountering newly acquired out-ofdistribution (OOD) user intents in the unlabeled pool.In this paper, we introduce a novel adaptive open-set AL framework viz., "AOSAL" for TODS that combines a distance-based OOD detector using an adaptive false positive rate threshold along with an informativeness measure (e.g., entropy) to strategically select informative IND data points in the unlabeled pool.Specifically, we utilize the adaptive OOD detector to classify and filter out OOD samples from the unlabeled pool, then prioritize the acquisition of classified IND instances based on their informativeness scores.To validate our approach, we conduct experiments that display our framework's flexibility and performance over multiple distance-based approaches and informativeness measures against deep AL baselines on benchmark text datasets.The results show that our AOSAL consistently outperforms the baselines on IND classification and percentage of acquired IND samples, demonstrating its ability to improve robustness of task-oriented dialog systems.
Sai Keerthana Goruganthu, Roland Oruche, Prasad Calyam
SIGDIAL3
2024 Improving big data governance in healthcare institutions: user experience research for honest broker based application to access healthcare big data
abstract
Data users (researchers, scientists) in healthcare institutions need access to integrated healthcare data to conduct timely analysis of diseases to serve the right population at the right time. However, preserving patient privacy and timely access to quality healthcare data is a critical challenge. Current healthcare data governance systems are largely manual. Besides, processing process data requests is extremely slow, often taking months. To address this gap, we designed an honest-broker-based healthcare application to support data users in accessing healthcare data securely and to design a comprehendible process of data governance for data users. This study applied two iterations of a user experience (UX) evaluation of an honest broker prototype. Results show that participants found the new system promising for their research prospects. Implications suggest that technological knowledge should not be a requirement for using healthcare applications to promote broader adoption in the community. This study highlights the necessity of a process to balance the control of access to sensitive data between data providers and users as well as to educate data users on data privacy. Iterative UX studies can be a fruitful approach in gradually uncovering problems and improving the design of complex systems.
Kanu Priya Singh, Shangman Li, Isa Jahnke, Mauro Lemus, Abu Saleh Mohammad Mosa, Prasad Calyam
Behav. Inf. Technol.6
2024 ChatGPT or Bard: Who is a better Certified Ethical Hacker?
abstract
In this study, we compare two leading Generative AI (GAI) tools, ChatGPT and Bard, specifically in Cybersecurity, using a robust set of standardized questions from a validated Certified Ethical Hacking (CEH) dataset. In the rapidly evolving domain of Generative AI (GAI) and large language models (LLM), a comparative analysis of tools becomes essential to measure their performance. We determine the Comprehensiveness, Clarity, and Conciseness of the AI-generated responses through a detailed questioning-based framework. The study revealed an overall accuracy rate of 80.8% for ChatGPT and 82.6% for Bard, indicating comparable capabilities and specific differences. Bard slightly outperformed ChatGPT in accuracy, while ChatGPT exhibited superiority in Comprehensiveness, Clarity, and Conciseness of responses. Introducing a confirmation query like "Are you sure?" increased accuracy for both generative AI tools, illustrating the potential of iterative query processing in enhancing GAI tools' effectiveness. The readability evaluation placed both tools at a college reading level, with Bard marginally more accessible. While evaluating certain questions, a distinct pattern emerged where Bard provided generic denials of assistance while ChatGPT referenced "ethics." This discrepancy illustrates the contrasting philosophies of the developers of these tools, with Bard possibly following stricter guidelines, especially in sensitive topics like Cybersecurity. We explore the implications and identify key areas for future research that become increasingly relevant as GAI tools see broader adoption.
Raghu Raman, Prasad Calyam, Krishnashree Achuthan
Comput. Secur.2
2024 Learning-Based Multi-Drone Network Edge Orchestration for Video Analytics
abstract
Unmanned aerial vehicles (also known as drones) equipped with high-resolution video cameras have become increasingly popular for applications such as public safety and smart farming. However, inefficient configurations in drone video analytics due to misconfigured edge networks can lead to degraded video quality and inefficient resource utilization. In this paper, we propose a novel scheme for network edge orchestration that utilizes both offline and online learning-based approaches to achieve pertinent selections of network protocols and video properties in multi-drone-based video analytics. Our approach utilizes both supervised and unsupervised machine learning algorithms to make decisions regarding network protocols and video properties during the pre-takeoff stage of the drones (i.e., offline stage). Additionally, our approach incorporates a reinforcement learning-based multi-agent deep Q-network algorithm for drone trajectory optimization during flights (i.e., online stage) and a memory-to-memory multi-hop data forwarding strategy for drone swarm video transmission. Our evaluation results demonstrate that our offline orchestration approach can suitably choose network protocols (i.e., among TCP/HTTP, UDP/RTP, QUIC), while our unsupervised learning approach outperforms existing methods and achieves efficient offloading while improving network performance (i.e., throughput and round-trip time) by at least 25%, with satisfactory video quality. Furthermore, we demonstrate through trace-based and real-field experiment testbeds how our online orchestration in terms of decision-making and data forwarding strategies achieves 91% of the oracle baseline network throughput performance with comparable video quality. Overall, our approach offers a promising solution for optimizing drone video analytics and enhancing the overall performance of drone-swarm-based applications.
Chengyi Qu, Rounak Singh, Alicia Esquivel Morel, Prasad Calyam
IEEE Trans. Netw. Serv. Manag.4
2023 Knowledge Graph-based Embedding for Connecting Scholars in Academic Social Networks
abstract
In recent years, research tasks have increasingly involved using multi-disciplinary knowledge through collaborations of scholars from multiple fields. However, identifying a team of suitable collaborators from diverse fields for a given research task is a challenging and time-consuming process. In this paper, we propose a novel “ScholarTeamFinder” model that uses knowledge graph based link prediction to identify collaborators within an academic social network (ASN) to form a research team to address a multi-disciplinary research problem. Our approach involves building a heterogeneous knowledge graph within an ASN using entities such as scholars, publications, research grants, and the relationship among these entities. Following this, we use graph-based deep learning to learn the node embedding from the knowledge graph that can be used for scholar team recommendation. More specifically, we used the classical meth-path2vec as our base graph learning algorithm and improved its performance by considering semantic meaning of entities and encoding edge embeddings in the graph. Finally, we propose a beam-search algorithm for scholar team prediction based on our model embeddings. Our evaluation of ScholarTeamFinder is performed using large ASN datasets including a unique dataset (i.e., NSF award dataset) of federal grant awards collected over the last ten years and the scholars’ publication data, as well as three other widely used datasets (i.e., APS, SCHOLAT and Gowalla). Experiment results show that our model outperforms the state-of-the-art models across the different datasets.
Xiyao Cheng, Yuanxun Zhang, Harsh Joshi, Mayank Kejriwal, Prasad Calyam
DSAA5
2023 FlyPaw: Optimized Route Planning for Scientific UAVMissions
abstract
Many Internet of Things (IoT) applications require compute resources that cannot be provided by the devices themselves. On the other hand, processing of the data generated by IoT devices and sensors often has to be performed in real- or near real-time, i.e., with stringent latency requirements in constrained environments (e.g., intermittent network connectivity and limited power envelopes). Examples of such scenarios are autonomous vehicles in the form of cars and drones where the processing and analysis of observational data (e.g., video feeds) need to be performed expeditiously to allow for safe operation of the vehicles and to deliver the results in a timely fashion to the stakeholders of the mission. To support the compute and timeliness requirements of such applications, it is essential to include suitable edge resources to process these workflows, and to develop an end-to-end system that can route the vehicles dynamically and process and deliver mission-critical data and analyzed results. In this paper, we develop and evaluate a dynamic scheduling approach that considers complex tradeoffs between real-time constraints, network availability, and latency sensitivity of the mission. We devise an optimized route planning and data transmission schedule for drone flights. The scheduling algorithm is encapsulated in a novel end-to-end architecture (FlyPaw) and an associated adaptive drone mission control system, which enables deployment and management of an integrated cyberphysical system (CPS) – from real drone testbed to base stations to edge-to-cloud resources. The planning algorithm takes into account measured network communication characteristics, estimated uncertainties of future data link connectivity, and data timeliness requirements of the mission to prioritize candidate decision tree solutions based on a risk metric derived from Sharpe's ratio. Our results show that for given task sets, Net Time to Retrieve, our metric describing the time required to perform end-to-end collection and downstream processing of data, can be significantly reduced compared to other naive approaches. The theoretical improvement provided by our algorithm over other naive approaches is dependent on several factors — task locations, network connectivity, processing times and available resources, and is bounded by the duration of the drone flight.
Andrew Grote, Eric Lyons 0001, Komal Thareja, George Papadimitriou 0002, Ewa Deelman, Anirban Mandal, Prasad Calyam, Michael Zink
e-Science7
2023 Environmentally-Aware Robotic Vehicle Networks Routing Computation for Last-mile Deliveries
abstract
For next-generation logistics management, robotic vehicles such as autonomous ground robots and aerial drones can alleviate the strain on last-mile distribution. They can help avoid on-road congestion, navigate hard-to-reach locations, and parallelize delivery operations. However, as the robotic vehicles move in a given delivery area, environmental barriers e.g., trees or buildings, affect air-to-air (A2A), air-to-ground (A2G), ground-to-ground (G2G) network communications on a hybrid truck-drone-robot system. In this paper, we present an environmentally-aware cooperative network routing computation scheme to avoid obstacle blockage in A2A/A2G/G2G network communications for addressing large-scale coordinated operations of the hybrid truck-drone-robot system. Specifically, we propose an offline policy-based routing algorithm and two online extensions (i.e., heuristics and learning-based) to solve the hybrid last-mile delivery vehicles communication problem in order to trade-off between end-to-end communication (i.e., increase network throughput) and delivery efficiencies (i.e., lower parcel delivery time consumption). We evaluate our scheme using state-of-the-art network routing algorithms in a trace-based simulator that integrates both the vehicles and networking sides. Performance evaluation results from our simulations show that: (i) our offline approach is Pareto-optimal among non-learning supported algorithms in a pre-delivery scenario, and (ii) our RL-based online algorithm achieves between 85–96 % of the Oracle strategy performance during delivery procedures.
Chengyi Qu, Rounak Singh, Sharan Srinivas, Prasad Calyam
ICCCN4
2023 Risk-Based Zero Trust Scale for Tactical Edge Network Environments
abstract
In dynamic and resource-constrained Tactical Edge Network (TEN) environments, where Denied, Disrupted, Intermittent, and Limited Impact (DDIL) conditions prevail, a tailored security approach is vital for real-time decision-making. In this paper, we propose adapting the Zero Trust (ZT) security paradigm to suit TEN settings, focusing on strict access controls, continuous entity verification, and unauthorized access mitigation. Our solution introduces a risk-based ZT scale approach, aligning security measures with scenario-associated risk levels while minimizing resource usage. We employ a Bayesian Network (BN) model to evaluate communication request risk, considering potential attacks. Our experiments confirm the effectiveness and adaptability of our approach in ensuring secure and efficient operations in these challenging environments.
Saketh Poduvu, Sayed M. Saghaian N. E., Ekincan Ufuktepe, Alicia Esquivel Morel, Prasad Calyam
SEC5
2023 VR-LENS: Super Learning-based Cybersickness Detection and Explainable AI-Guided Deployment in Virtual Reality
abstract
Virtual reality (VR) systems are known for their susceptibility to cybersickness, which can seriously hinder users’ experience. Therefore, a plethora of recent research has proposed several automated methods based on machine learning (ML) and deep learning (DL) to detect cybersickness. However, these detection methods are perceived as computationally intensive and black-box methods. Thus, those techniques are neither trustworthy nor practical for deploying on standalone VR head-mounted displays (HMDs). This work presents an explainable artificial intelligence (XAI)-based framework VR-LENS for developing cybersickness detection ML models, explaining them, reducing their size, and deploying them in a Qualcomm Snapdragon 750G processor-based Samsung A52 device. Specifically, we first develop a novel super learning-based ensemble ML model for cybersickness detection. Next, we employ a post-hoc explanation method, such as SHapley Additive exPlanations (SHAP), Morris Sensitivity Analysis (MSA), Local Interpretable Model-Agnostic Explanations (LIME), and Partial Dependence Plot (PDP) to explain the expected results and identify the most dominant features. The super learner cybersickness model is then retrained using the identified dominant features. Our proposed method identified eye tracking, player position, and galvanic skin/heart rate response as the most dominant features for the integrated sensor, gameplay, and bio-physiological datasets. We also show that the proposed XAI-guided feature reduction significantly reduces the model training and inference time by 1.91X and 2.15X while maintaining baseline accuracy. For instance, using the integrated sensor dataset, our reduced super learner model outperforms the state-of-the-art works by classifying cybersickness into 4 classes (none, low, medium, and high) with an accuracy of and regressing (FMS 1–10) with a Root Mean Square Error (RMSE) of 0.03. Our proposed method can help researchers analyze, detect, and mitigate cybersickness in real time and deploy the super learner-based cybersickness detection model in standalone VR headsets.
Ripan Kumar Kundu, Osama Yahia Elsaid, Prasad Calyam, Khaza Anuarul Hoque
IUI3
2023 Transmitting Information with Global-designation of Emergency Routes for Edge Video Processing
abstract
Large volumes of video feeds are generated by systems of Unmanned Aerial Vehicles (UAV) or city intersections with cameras in edge applications such as border security, crime mitigation, precision agriculture and smart city traffic management. Due to compute/network resource demands in video processing in a reliable and scalable manner to enable situational awareness for application consumers of video feeds, these systems need to rely on network services, edge computing devices and cloud infrastructure resources. Consequently, there is a need for effective integration of point-solutions that can transmit information from the system edge to the cloud platforms. In this paper, we present a novel framework viz., TIGER (Transmitting Information with Global-designation of Emergency Routes) that leverages the merits of Software-Defined Networking (SDN) and Programming Protocol-Independent Packet Processors (P4) to provide intelligent network services. Specifically, TIGER framework comprises two network services ‘priority routing’ and ‘congestion control’ that distinguish emergency traffic transmission based on source-based routing, and select congestion-free links based on multi-hop routing inspection as network cross-traffic increases, respectively. Our experiment results show that TIGER framework achieves priority routing by reducing packet jitter by 52%, corresponding to robust real-time data transmission. In addition, it achieves congestion control through traffic reduction by 45% across multiple pathways.
Anvitha Ramachandran, Alicia Esquivel Morel, Durbek Gafurov, Prasad Calyam
NOMS5
2023 Trust Quantification in a Collaborative Drone System with Intelligence-driven Edge Routing
abstract
Collaborative Drone systems (CDS) have the potential to benefit a variety of application areas such as agriculture, military operations, surveillance, and disaster response. At the same time, CDS can pose challenges due to their limited flight time impacted by battery capacities, and constrained edge computation capabilities on-board the drones. Furthermore, an understudied subject relates to when drones in a CDS trust each other to accomplish a task, resulting in new vulnerabilities that can be exploited via cyber attacks. In this paper, we propose a novel trust quantification methodology in a CDS with intelligence-driven edge routing, which can help detect malicious nodes in a CDS that compromise communication and disrupt the functionality of packet forwarding. Our approach for trust quantification is guided by a CDS vulnerability analysis that characterizes impact due to the presence of two malicious threat agents viz., flooder node and faker node. Detection of these threat agents in a CDS is aided by trust quantification in the form of trust scores obtained by using a Bayesian Network model that allows for decision-making on CDS nodes’ trust levels. We validate our trust quantification methodology in ns-3 based simulation experiments and show how we can categorize nodes based on different thresholds of trust scores with varying sensitivities, which helps in the detection of CDS threat agents.
Alicia Esquivel Morel, Ekincan Ufuktepe, Cameron Grant, Samuel Elfrink, Chengyi Qu, Prasad Calyam, Kannappan Palaniappan
NOMS6
2023 Science gateway adoption using plug-in middleware for evidence-based healthcare data management
abstract
Summary There is a growing need for next‐generation science gateways to increase the accessibility of emerging large‐scale datasets for data consumers (e.g., clinicians, researchers) who aim to combat COVID‐19‐related challenges. Such science gateways that enable access to distributed computing resources for large‐scale data management need to be made more programmable, extensible, and scalable. In this article, we propose a novel socio‐technical approach for developing a next‐generation healthcare science gateway, namely, OnTimeEvidence that addresses data consumer challenges surrounding the COVID‐19 pandemic related data analytics. OnTimeEvidence implements an intelligent agent, namely, Vidura Advisor that integrates an evidence‐based filtering method to transform manual practices and improve scalability of data analytics. It also features a plug‐in management middleware that improves the programmability and extensibility of the science gateway capabilities using microservices. Lastly, we present a usability study that shows the important factors from data consumers' perspective to adopt OnTimeEvidence with chatbot‐assisted middleware support to increase their productivity and collaborations to access vast publication archives for rapid knowledge discovery tasks.
Roland Oruche, Eric D. Milman, Mauro Lemus, Xiyao Cheng, Songjie Wang, Prasad Calyam, Kerk F. Kee
Concurr. Comput. Pract. Exp.7
2023 Cyber Threat Intelligence Sharing for Co-Operative Defense in Multi-Domain Entities
abstract
Cloud-hosted applications are prone to targeted attacks such as DDoS, advanced persistent threats, Cryptojacking which threaten service availability. Recently, methods for threat information sharing and defense require cooperation and trust between multiple domains/entities. There is a need for mechanisms that establish distributed trust to allow for such a collective defense. In this paper, we present a novel threat intelligence sharing and defense system, namely “DefenseChain,” to allow organizations to have incentive-based and trustworthy cooperation to mitigate the impact of cyber attacks. Our solution approach features a consortium Blockchain platform and an economic model to obtain threat data and select suitable peers to help with attack detection and mitigation. We apply DefenseChain in the financial technology industry for an insurance claim processing use case to demonstrate the effectiveness of DefenseChain in a real-world application setting. Our evaluation experiments with DefenseChain implementation are performed on an Open Cloud testbed with Hyperledger Composer and in a simulation environment. Our results show that the DefenseChain system overall performs better than state-of-the-art decision making schemes in choosing the most appropriate detector and mitigator peers. Lastly, we validate how DefenseChain helps mitigate the threat risk of incidents relating to potential fraudulent insurance claims or cyber attacks.
Soumya Purohit, Roshan Neupane, Naga Ramya Bhamidipati, Varsha Vakkavanthula, Songjie Wang, Matthew Rockey, Prasad Calyam
IEEE Trans. Dependable Secur. Comput.7
2023 Domain-Specific Topic Model for Knowledge Discovery in Computational and Data-Intensive Scientific Communities
abstract
Shortened time to knowledge discovery and adapting prior domain knowledge is a challenge for computational and data-intensive communities such as e.g., bioinformatics and neuroscience. The challenge for a domain scientist lies in the actions to obtain guidance through query of massive information from diverse text corpus comprising of a wide-ranging set of topics when: investigating new methods, developing new tools, or integrating datasets. In this paper, we propose a novel "domain-specific topic model" (DSTM) to discover latent knowledge patterns about relationships among research topics, tools and datasets from exemplary scientific domains. Our DSTM is a generative model that extends the Latent Dirichlet Allocation (LDA) model and uses the Markov chain Monte Carlo (MCMC) algorithm to infer latent patterns within a specific domain in an unsupervised manner. We apply our DSTM to large collections of data from bioinformatics and neuroscience domains that include more than 25,000 of papers over the last ten years, featuring hundreds of tools and datasets that are commonly used in relevant studies. Evaluation experiments based on generalization and information retrieval metrics show that our model has better performance than the state-of-the-art baseline models for discovering highly-specific latent topics within a domain. Lastly, we demonstrate applications that benefit from our DSTM to discover intra-domain, cross-domain and trend knowledge patterns.
Yuanxun Zhang, Prasad Calyam, Trupti Joshi, Satish S. Nair, Dong Xu 0002
IEEE Trans. Knowl. Data Eng.2
2023 Knowledge-Engineered Multi-Cloud Resource Brokering for Application Workflow Optimization
abstract
Data-intensive application workflows benefit by leveraging cloud services to decrease execution times and increase data sharing. Cloud service providers (CSPs) have distinct capabilities and policies, and performance/cost of the cloud services are amongst the prime factors for CSP selection. However, workflow users who need brokering of cloud resources often lack expert guidance to handle the problem of overwhelming choice in CSP selection, and optimization to compensate for service dynamics. In this paper, we address the optimal resource selection problem using a multi-cloud resource broker viz., OnTimeURB that uses knowledge-engineering of user requirements and service capabilities across multiple CSPs. OnTimeURB is powered by integer linear programming and a Naive Bayes classifier to recommend optimal cloud template solutions by weighting performance, agility, cost, and security (PACS) factors. We evaluate the OnTimeURB recommendations with a catalog of bioinformatics application workflows using four CSP resources featuring more than 300 different instance configurations. Our evaluation results show the efficacy of OnTimeURB in creating consistently cost-effective and agile solutions compared to a state-of-the-art k-nearest neighbors (k-NN) approach. We also show that OnTimeURB has 91% success rate improvement in workflow execution times via cloud template recommendations over approaches that do not use knowledge-engineered multi-CSP resource brokering.
Prasad Calyam, Zhen Lyu, Songjie Wang, D. Yu. Chemodanov, Trupti Joshi
IEEE Trans. Netw. Serv. Manag.2
2023 Environmentally-Aware and Energy-Efficient Multi-Drone Coordination and Networking for Disaster Response
abstract
In a disaster response management (DRM) scenario, communication and coordination are limited, and absence of related infrastructure hinders situational awareness. Unmanned aerial vehicles (UAVs) or drones provide new capabilities for DRM to address these barriers. However, there is a dearth of works that address multiple heterogeneous drones collaboratively working together to form a flying ad-hoc network (FANET) with air-to-air and air-to-ground links that are impacted by: (i) environmental obstacles, (ii) wind, and (iii) limited battery capacities. In this paper, we present a novel environmentally-aware and energy-efficient multi-drone coordination and networking scheme that features a Reinforcement Learning (RL) based location prediction algorithm coupled with a packet forwarding algorithm for drone-to-ground network establishment. We specifically present two novel drone location-based solutions (i.e., heuristic greedy, and learning-based) in our packet forwarding approach to support application requirements. These requirements involve improving connectivity (i.e., optimize packet delivery ratio and end-to-end delay) despite environmental obstacles, and improving efficiency (i.e., by lower energy use and time consumption) despite energy constraints. We evaluate our scheme with state-of-the-art networking algorithms in a trace-based DRM FANET simulation testbed featuring rural and metropolitan areas. Results show that our strategy overcomes obstacles and can achieve 81-to-90% of network connectivity performance observed under no obstacle conditions. In the presence of obstacles, our scheme improves the network connectivity performance by 14-to-38% while also providing 23-to-54% of energy savings in rural areas; the same in metropolitan areas achieved an average of 25% gain when compared with baseline obstacle awareness approaches with 15-to-76% of energy savings.
Chengyi Qu, Francesco Betti Sorbelli, Rounak Singh, Prasad Calyam, Sajal K. Das 0001
IEEE Trans. Netw. Serv. Manag.4
2023 Detection of Security and Privacy Attacks Disrupting User Immersive Experience in Virtual Reality Learning Environments
abstract
Virtual Reality Learning Environments (VRLEs) are a new form of immersive environments which are integrated with wearable devices for delivering distance learning content in a collaborative manner in e.g.,special education,surgical training. Gaining unauthorized access to these connected devices can cause security, privacy attacks (SP) that adversely impacts the user immersive experience (UIX). In this article, we identify potential SP attack surfaces that impact the application usability and immersion experience, and propose a novel anomaly detection method to detect attacks before the UIX can be disrupted. Specifically, we apply: (i) machine learning techniques such as amulti-label KNN classificationalgorithm to detect anomaly events of network-based attacks that include potential threat scenarios ofDoS (packet tampering, packet drop, packet duplication), and (ii) statistical analysis techniques that use a combination of boolean and threshold functions (Z-scores) to detect an anomaly related to application-based attacks (Unauthorized access). We demonstrate the effectiveness of our proposed anomaly detection method using a VRLE application case study viz., vSocial, specifically designed for teaching youth with learning impediments about social cues and interactions. Based on our detection results, we validate the impact of network and application based SP attacks on the VRLE UIX.
Samaikya Valluripally, Benjamin Frailey, Brady Kruse, Boonakij Palipatana, Roland Oruche, Aniket Gulhane, Khaza Anuarul Hoque, Prasad Calyam
IEEE Trans. Serv. Comput.8
2022 Networked and Multimodal 3D Modeling of Cities for Collaborative Virtual Environments
abstract
3D city-scale models are useful in a number of applications, including education, city planning, navigation systems, artificial intelligence training, and simulations. However, final models need to be immersive and interactive, which requires a mixed reality (XR) environment design that combines e.g., a Cave Automatic Virtual Environment (CAVE) VR system with the Microsoft Hololens2 in a networked and multimodal setting. In this paper, we propose a pipeline to convert a city-scale point cloud into a finalized city-scale textured mesh in which, a number of XR devices can share the same environment and co-exist in a shared space for model interactions. Specifically, we use input point clouds obtained from wide area motion imagery systems or off-the-shelf drones pertaining to Albuquerque, New Mexico, but the pipeline is generalized so that other input can be used. Using four different traditional algorithms and an additional deep learning method, we create meshes for the model interactions. For each mesh produced, we map high-resolution textures onto them, producing a more accurate city, which is then passed into the shared/networked Unity environment. Ten participants provided their assessment of mesh quality and interactivity of the networked environment during exploration of different city reconstructions with the CAVE and laptop device modalities. Results on the perceptual immersive quality of the Point2Mesh deep learning meshes highlights the need for improvements to handle large city scale point clouds.
Benjamin Hall, Joseph Kessler, Osayamen Edo-Ohanba, Jaired Collins, Nick Allegreti, Ye Duan, Songjie Wang, Kannappan Palaniappan, Prasad Calyam
BDCAT10
2022 Automating Edge-to-cloud Workflows for Science: Traversing the Edge-to-cloud Continuum with Pegasus
abstract
In this paper, we describe how we extended the Pegasus Workflow Management System to support edge-to-cloud workflows in an automated fashion. We discuss how Pegasus and HTCondor (its job scheduler) work together to enable this automation. We use HTCondor to form heterogeneous pools of compute resources and Pegasus to plan the workflow onto these resources and manage containers and data movement for executing workflows in hybrid edge-cloud environments. We then show how Pegasus can be used to evaluate the execution of workflows running on edge only, cloud only, and edge-cloud hybrid environments. Using the Chameleon Cloud testbed to set up and configure an edge-cloud environment, we use Pegasus to benchmark the executions of one synthetic workflow and two production workflows: CASA-Wind and the Ocean Observatories Initiative Orcasound workflow, all of which derive their data from edge devices. We present the performance impact on workflow runs of job and data placement strategies employed by Pegasus when configured to run in the above three execution environments. Results show that the synthetic workflow performs best in an edge only environment, while the CASA - Wind and Orcasound workflows see significant improvements in overall makespan when run in a cloud only environment. The results demonstrate that Pegasus can be used to automate edge-to-cloud science workflows and the workflow provenance data collection capabilities of the Pegasus monitoring daemon enable computer scientists to conduct edge-to-cloud research.
Ryan Tanaka, George Papadimitriou 0002, Sai Charan Viswanath, Cong Wang 0014, Eric Lyons 0001, Komal Thareja, Chengyi Qu, Alicia Esquivel Morel, Ewa Deelman, Anirban Mandal, Prasad Calyam, Michael Zink
CCGRID11
2022 CAVE-VR and Unity Game Engine for Visualizing City Scale 3D Meshes
abstract
Modeling and simulation of large urban regions is beneficial for a range of applications including intelligent transportation, smart cities, infrastructure planning, and training artificial intelligence for autonomous navigation systems including ground vehicles and aerial drones. Immersive environments including virtual reality (VR), augmented reality (AR), mixed reality (MR or XR) can be used to explore city scale regions for planning, design, training and operations. Virtual environments are in the midst of rapid change as innovations in display tech-nologies, graphics processors and game engine software present new opportunities for incorporating modeling and simulation into engineering workflows. Game engine software like Unity with photorealistic rendering and realistic physics have plug-in support for a variety of virtual environments. In this paper, we explore the visualization of urban scale real world accurate meshes in virtual environments, including the Microsoft HoloLens head mounted display or the CAVE VR for multi-user interaction.
Calvin Davis, Jaired Collins, Joshua Fraser, Shizeng Yao, Emily Lattanzio, Bimal Balakrishnan, Ye Duan, Prasad Calyam, Kannappan Palaniappan
CCNC9
2022 Securing Remote User Authentication in Industrial Internet of Things
abstract
The Industrial Internet of Things (IIoT) enhances the benefit of the Internet of Things (IoT) to a higher level, especially in industries where human error can lead to catastrophic effects. However, security is a major concern in IIoT as hackers can gain access to connected systems, thus potentially subjecting operations to a shutdown. Besides, the outbreak of the COVID-19 pandemic changed the operations style of organizations into a remote work model. Consequently, there has been a significant increase in cyber-attacks leveraging vulnerabilities of IoT devices connected to the Internet. Considering the above factors, we propose a method of remote user authentication combining Photo Response Non-Uniformity (PRNU) with fingerprint bio-metric, which can prevent attacks. PRNU uniquely identifies the scanner, thereby authenticates the device of the user. To prove the effectiveness of PRNU, we collect fingerprint images from various scanners prototyped using Raspberry Pi and evaluate the performance. Our performance evaluation with a set of 10 fingerprint scanners shows promising results. Moreover, our analysis shows that the proposed scheme achieves a classification accuracy of 99%.
K. Nimmy, Sriram Sankaran, Krishnashree Achuthan, Prasad Calyam
CCNC4
2022 Remote Instrumentation Science Environment for Intelligent Image Analytics
abstract
Current scientific experiments frequently involve control of specialized instruments (e.g., scanning electron microscopes), image data collection from those instruments, and transfer of the data for processing at simulation centers. This process requires a “human-in-the-loop” to perform those tasks manually, which besides requiring a lot of effort and time, could lead to inconsistencies or errors. Thus, it is essential to have an automated system capable of performing remote instrumentation to intelligently control and collect data from the scientific instruments. In this paper, we propose a Remote Instrumentation Science Environment (RISE) for intelligent image analytics that provides the infrastructure to securely capture images, determine process parameters via machine learning, and provide experimental control actions via automation, under the premise of “human-on-the-loop”. The machine learning in RISE aids an iterative discovery process to assist researchers to tune instrument settings to improve the outcomes of experiments. Driven by two scientific use cases of image analytics pipelines, one in material science, and another in biomedical science, we show how RISE automation leverages a cutting-edge integration of cloud computing, on-premise HPC cluster, and a Python programming interface available on a microscope. Using web services, we implement RISE to perform automated image data collection/analysis guided by an intelligent agent to provide real-time feedback control of the microscope using the image analytics outputs. Our evaluation results show the benefits of RISE for researchers to obtain higher image analytics accuracy, save precious time in manually controlling the microscopes, while reducing errors in operating the instruments.
Mauro Lemus, Songjie Wang, Nguyen P. Nguyen, Filiz Bunyak, Matthew R. Maschmann, Kannappan Palaniappan, Prasad Calyam
e-Science8
2022 UAV Swarms in Smart Agriculture: Experiences and Opportunities
abstract
Smart agriculture benefits from unmanned aerial vehicles (UAV), and in-field sensors to collect data used to make responsible crop management decisions which sustainably increase yields. In addition, smart agriculture relies on machine learning algorithms, creative networking solutions, and edge and cloud computing resources to collect, transfer, and process agricultural data. UAV can carry a wide array of sensors, maneuver rapidly throughout the field, apply treatments for some crop health problems, and can be flown by software. UAV, however, have small batteries and limited carrying capacities which keep missions short. In this paper, we provide an overview of state-of-the-art UAV swarm technology for smart agriculture, and present experiences from real-world agricultural UAV swarm case studies. We describe how quick mapping of large areas such as crop fields necessitates multiple UAV missions, potentially using multiple UAV simultaneously as a swarm. We detail how swarms of UAV have added advantages over a single UAV deployment. They can coordinate to map areas in parallel, leverage multiple sensor types, target areas for close inspection, and diagnose and treat problems rapidly. UAV swarms come with additional implementation difficulties beyond single UAV. We list challenges to implementers in terms of Resource allocation, compute orchestration, multi-agent mission planning and swarm goal definition. We also describe recent advances in edge computing, machine learning, and autonomy in orchestration and resource management techniques for swarm deployments. Finally, we conclude with research opportunities that future work can address to improve swarm performance, scale, and adoption for smart agriculture.
Chengyi Qu, Jayson G. Boubin, Durbek Gafurov, Noel Aloysius, Henry Nguyen, Prasad Calyam
e-Science7
2022 Learning-based Multi-Drone Network Edge Orchestration for Video Analytics
abstract
Unmanned aerial vehicles (a.k.a. drones) with high-resolution video cameras are useful for applications in e.g., public safety and smart farming. Inefficient configurations in drone video analytics applications due to edge network miscon-figurations can result in degraded video quality and inefficient resource utilization. In this paper, we present a novel scheme for offline/online learning-based network edge orchestration to achieve pertinent selection of both network protocols and video properties in multi-drone based video analytics. Our approach features both supervised and unsupervised machine learning algorithms to enable decision making for selection of both network protocols and video properties in the drones’ pre-takeoff stage i.e., offline stage. In addition, our approach facilitates drone trajectory optimization during drone flights through an online reinforcement learning-based multi-agent deep Q-network algorithm. Evaluation results show how our offline orchestration can suitably choose network protocols (i.e., amongst TCP/HTTP, UDP/RTP, QUIC). We also demonstrate how our unsupervised learning approach outperforms existing learning approaches, and achieves efficient offloading while also improving the network performance (i.e., throughput and round-trip time) by least 25% with satisfactory video quality. Lastly, we show via trace-based simulations, how our online orchestration achieves 91% of oracle baseline network throughput performance with comparable video quality.
Chengyi Qu, Rounak Singh, Alicia Esquivel Morel, Prasad Calyam
INFOCOM4
2022 TruVR: Trustworthy Cybersickness Detection using Explainable Machine Learning
abstract
Cybersickness can be characterized by nausea, vertigo, headache, eye strain, and other discomforts when using virtual reality (VR) systems. The previously reported machine learning (ML) and deep learning (DL) algorithms for detecting (classification) and predicting (regression) VR cybersickness use black-box models; thus, they lack explainability. Moreover, VR sensors generate a massive amount of data, resulting in complex and large models. Therefore, having inherent explainability in cybersickness detection models can significantly improve the model’s trustworthiness and provide insight into why and how the ML/DL model amved at a specific decision. To address this issue, we present three explainable machine learning (xML) models to detect and predict cybersickness: 1) explainable boosting machine (EBM), 2) decision tree (DT), and 3) logistic regression (LR). We evaluate xML-based models with publicly available physiological and gameplay datasets for cybersickness. The results show that the EBM can detect cybersickness with an accuracy of 99.75% and 94.10% for the physiological and gameplay datasets, respectively. On the other hand, while predicting the cybersickness, EBM resulted in a Root Mean Square Error (RMSE) of 0.071 for the physiological dataset and 0.27 for the gameplay dataset. Furthermore, the EBM-based global explanation reveals exposure length, rotation, and acceleration as key features causing cybersickness in the gameplay dataset. In contrast, galvanic skin responses and heart rate are most significant in the physiological dataset. Our results also suggest that EBM-based local explanation can identify cybersickness-causing factors for individual samples. We believe the proposed xML-based cybersickness detection method can help future researchers understand, analyze, and design simpler cybersickness detection and reduction models.
Ripan Kumar Kundu, Rifatul Islam, Prasad Calyam, Khaza Anuarul Hoque
ISMAR3
2022 Modeling and Defense of Social Virtual Reality Attacks Inducing Cybersickness
abstract
Social Virtual Reality Learning Environments (VRLE) offer a new medium for flexible and immersive learning environments with geo-distributed users. Ensuring user safety in VRLE application domains such as education, flight simulations, military training is of utmost importance. Specifically, there is a need to study the impact of “immersion attacks” (e.g., chaperone attack, occlusion) and other types of attacks/faults (e.g., unauthorized access, network congestion) that may cause user safety issues (i.e., inducing ofcybersickness). In this article, we present a novel framework to quantify the security, privacy issues triggered via immersion attacks and other types of attacks/faults. By using a real-world social VRLE viz., vSocial and creating a novel attack-fault tree model, we show that such attacks can induce undesirable levels of cybersickness. Next, we convert these attack-fault trees into stochastic timed automata (STA) representations to perform statistical model checking for a given attacker profile. Using this model checking approach, we determine the most vulnerable threat scenarios that can trigger high occurrence cases of cybersickness for VRLE users. Lastly, we show the effectiveness of our attack-fault tree modeling by incorporating suitable design principles such ashardening,diversity,redundancyandprinciple of least privilegeto ensure user safety in a VRLE session.
Samaikya Valluripally, Aniket Gulhane, Khaza Anuarul Hoque, Prasad Calyam
IEEE Trans. Dependable Secur. Comput.4
2021 3D Modeling of Cities for Virtual Environments
abstract
Modeling and simulation of large urban regions is beneficial for a range of applications including intelligent transportation, smart cities, infrastructure planning, and training artificial intelligence for autonomous navigation systems including ground vehicles and aerial drones. Immersive environments including virtual reality (VR), augmented reality (AR), mixed reality (MR or XR) can be used to explore city scale regions for planning, design, training and operations. Virtual environments are in the midst of rapid change as innovations in display technologies, graphics processors and game engine software present new opportunities for incorporating modeling and simulation into engineering workflows. Game engine software like Unity with photorealistic rendering and realistic physics have plug-in support for a variety of virtual environments and typically model the scene as meshes. In this paper, we develop an end-to-end workflow for creating urban scale real world accurate synthetic environments that can be visualized in virtual environments including the Microsoft HoloLens head mounted display or the CAVE VR for multi-user interaction. Four meshing algorithms are evaluated for representation accuracy and city-scale meshes imported into Unity for assessing the quality of the immersive experience.
Calvin Davis, Jaired Collins, Joshua Fraser, Shizeng Yao, Emily Lattanzio, Bimal Balakrishnan, Ye Duan, Prasad Calyam, Kannappan Palaniappan
IEEE BigData9
2021 Fuzzy-Engineered Multi-Cloud Resource Brokering for Data-intensive Applications
abstract
Multi-cloud resource brokering is becoming a critical requirement for applications that require high scale, diversity, and resilience. Applications demand timely selection of distributed data storage and computation platforms that span local private cloud resources as well as resources from multiple cloud service providers (CSPs). The distinct capabilities and policies, as well as performance/cost of the cloud services, are amongst the prime factors for CSP selection. However, application owners who need suitable cyber resources in community/public clouds, often have preliminary knowledge and preferences of certain CSPs. They also lack expert guidance to handle the problem of overwhelming resource choice from CSPs, and optimization to compensate for service dynamics. In this paper, we address this challenge of optimal resource selection while also leveraging limited user's expertise and preferences towards CSPs through multi-level fuzzy logic modeling based on convoluted factors of performance, agility, cost, and security. We evaluate the efficiency of our fuzzy-engineered resource brokering in improving allocation of resources as well as user satisfiability by using case studies and independent validations of CSPs evaluation.
Prasad Calyam, Zhen Lyu, Trupti Joshi
CCGRID2
2021 Obstacle-Aware and Energy-Efficient Multi-Drone Coordination and Networking for Disaster Response
abstract
Unmanned aerial vehicles or drones provide new capabilities for disaster response management (DRM). In a DRM scenario, multiple heterogeneous drones collaboratively work together forming a flying ad-hoc network (FANET) instantiated by a ground control station. However, FANET air-to-air and air-to-ground links that serve critical application expectations can be impacted by: (i) environmental obstacles, and (ii) limited battery capacities. In this paper, we present a novel obstacle-aware and energy-efficient multi-drone coordination and networking scheme that features a Reinforcement Learning (RL) based location prediction algorithm coupled with a packet forwarding algorithm for drone-to-ground network establishment. We specifically present two novel drone location-based solutions (i.e., heuristic greedy, and learning-based) in our packet forwarding approach to support heterogeneous drone operation as per application requirements. These requirements involve improving connectivity (i.e., optimize packet delivery ratio and end-to-end delay) despite environmental obstacles, and improving efficiency (i.e., by lower energy use and time consumption) despite energy constraints. We evaluate our scheme by comparing it with state-of-the-art networking algorithms in a trace-based DRM FANET simulation testbed. Results show that our strategy overcomes obstacles and can achieve between 81-90% of network connectivity performance observed under no obstacle conditions. With obstacles, our scheme improves network connectivity performance by 14-38 % while also providing 23-54% of energy savings.
Chengyi Qu, Rounak Singh, Alicia Esquivel Morel, Francesco Betti Sorbelli, Prasad Calyam, Sajal K. Das 0001
CNSM5
2021 Proactive Detection for Countermeasures on Port Scanning based Attacks
abstract
Defending a cyber asset from a targeted attack based on port scanning is a challenging task because attackers exploit protocol behavior essential for productive use of applications. For instance, TCP or UDP ports opened for applications such as file transfer or video can be exploited to launch denial of service attacks. There is a need for proactive methods that can detect port scanning based attacks at their initial stage so that countermeasures can be initiated before the attack impact is disruptive on a cyber asset. This paper presents methods to counteract the initial stages of network attacks involving TCP and UDP port scanning. Our methods analyze outgoing traffic to identify ICMP 3.3 and TCP RST response packets that indicate the beginning of an attack launch. We specifically describe two countermeasures based on software-defined networking controller (at the network level) and Linux utility (at the host level) modules we developed. To validate the effectiveness of our proactive detection based methodology, we set up a testbed with a scheme of a polygon and conducted experiments related to distortion of the port status of attacks. Our results demonstrate that our approach is effective and the accuracy of determining open TCP ports did not exceed 15%, and it did not reach 2% for the remaining ports (closed TCP, UDP of any type).
Evgeny S. Sagatov, Samara Mayhoub, Andrei M. Sukhov, Flavio Esposito, Prasad Calyam
CNSM5
2021 Network-based Active Defense for Securing Cloud-based Healthcare Data Processing Pipelines
abstract
Active defense schemes are becoming critical to secure cloud-based applications in the fields such as healthcare, entertainment, and manufacturing. Active defense mechanisms in cloud platforms need to be robust against targeted attacks (such as Distributed Denial-of-Service (DDoS), malware, and SQL injection) that make servers unresponsive and/or cause data breaches/loss, which in turn can cause high impact especially for healthcare applications. In this paper, we present a novel network-based active defense mechanism viz., “defense by pretense” that uses real-time attack detection and creates cyber deception e.g., by redirecting attacker’s traffic to quarantine machines and sending spoofed responses to attacker for cloud-based healthcare data processing applications. We implement our active defense mechanism by creating a realistic testbed on AWS cloud platform featuring the Observational Health Data Sciences and Informatics (OHDSI) framework for protected health data analytics with electronic health record data (SynPUF) and COVID-19 publications (CORD-19). Our evaluation experiments show the need and effectiveness of our active defense mechanism against targeted resource and data exfiltration attacks. We compare our active defense system against state-of-the-art active defense works, and our results show that our system is cost-effective, scalable and easy to deploy for active defense.
Vaibhav Akashe, Roshan Neupane, Mauro Lemus, Songjie Wang, Prasad Calyam
ICCCN5
2021 A Networked Social Virtual Reality Learning Environment Platform for Special Education
abstract
Delivering curriculum using desktop-based virtual learning environment (VLE) technologies in a collaborative group setting has been shown to reduce the social skill limitations of students with learning disabilities. However, the lack of the immersiveness and effective generalization of acquiring knowledge and skills among students remains a critical challenge in the interactive tools used in current VLEs. In this paper, we present a networked social virtual reality learning environment (VRLE) system viz., vSocial that has been redesigned based on iterative user feedback and developed in order to leverage the latest advances in integration of smart devices such as VR headsets for virtual content delivery. We describe a comparative study to evaluate technology trade-offs in the development process of transitioning from a VLE to a VRLE, from both technological and user (e.g., student/instructor) perspectives. Lastly, we outline open issues in using VRLEs which include: system complexity, emotion recognition, cybersickness and system sustainability.
Roland Oruche, Vaibhav Akashe, Samaikya Valluripally, Aniket Gulhane, Prasad Calyam, Janine Stichter, Zhihai He
LCN5
2021 Measuring success for a future vision: Defining impact in science gateways/virtual research environments
abstract
Summary Scholars worldwide leverage science gateways/virtual research environments (VREs) for a wide variety of research and education endeavors spanning diverse scientific fields. Evaluating the value of a given science gateway/VRE to its constituent community is critical in obtaining the financial and human resources necessary to sustain operations and increase adoption in the user community. In this article, we feature a variety of exemplar science gateways/VREs and detail how they define impact in terms of, for example, their purpose, operation principles, and size of user base. Further, the exemplars recognize that their science gateways/VREs will continuously evolve with technological advancements and standards in cloud computing platforms, web service architectures, data management tools and cybersecurity. Correspondingly, we present a number of technology advances that could be incorporated in next‐generation science gateways/VREs to enhance their scope and scale of their operations for greater success/impact. The exemplars are selected from owners of science gateways in the Science Gateways Community Institute (SGCI) clientele in the United States, and from the owners of VREs in the International Virtual Research Environment Interest Group (VRE‐IG) of the Research Data Alliance. Thus, community‐driven best practices and technology advances are compiled from diverse expert groups with an international perspective to envisage futuristic science gateway/VRE innovations.
Prasad Calyam, Nancy Wilkins-Diehr, Mark A. Miller, Emre H. Brookes, Ritu Arora, Amit Chourasia, Douglas M. Jennewein, Viswanath Nandigam, Michael Drew Lamar, Sean B. Cleveland, Greg Newman, Shaowen Wang 0001, Ilya Zaslavsky, Michael A. Cianfrocco, Kevin M. Ellett, David G. Tarboton, Keith G. Jeffery, Zhiming Zhao, Juan González-Aranda, Mark J. Perri, Gregory E. Tucker, Leonardo Candela, Tamás Kiss, Sandra Gesing
Concurr. Comput. Pract. Exp.1
2021 Recommender-as-a-service with chatbot guided domain-science knowledge discovery in a science gateway
abstract
Scientists in disciplines such as neuroscience and bioinformatics are increasingly relying on science gateways for experimentation on voluminous data, as well as analysis and visualization in multiple perspectives. Though current science gateways provide easy access to computing resources, datasets and tools specific to the disciplines, scientists often use slow and tedious manual efforts to perform knowledge discovery to accomplish their research/education tasks. Recommender systems can provide expert guidance and can help them to navigate and discover relevant publications, tools, data sets, or even automate cloud resource configurations suitable for a given scientific task. To realize the potential of integration of recommenders in science gateways in order to spur research productivity, we present a novel "OnTimeRecommend" recommender system. The OnTimeRecommend comprises of several integrated recommender modules implemented as microservices that can be augmented to a science gateway in the form of a recommender-as-a-service. The guidance for use of the recommender modules in a science gateway is aided by a chatbot plug-in viz., Vidura Advisor. To validate our OnTimeRecommend, we integrate and show benefits for both novice and expert users in domain-specific knowledge discovery within two exemplar science gateways, one in neuroscience (CyNeuro) and the other in bioinformatics (KBCommons).
Komal Bhupendra Vekaria, Prasad Calyam, Sai Swathi Sivarathri, Songjie Wang, Yuanxun Zhang, Dong Xu 0002, Trupti Joshi, Satish S. Nair
Concurr. Comput. Pract. Exp.2
2021 DroneCOCoNet: Learning-based edge computation offloading and control networking for drone video analytics
Chengyi Qu, Prasad Calyam, Jeromy Yu, Aditya Vandanapu, Osunkoya Opeoluwa, Ke Gao 0003, Songjie Wang, Raymond L. Chastain, Kannappan Palaniappan
Future Gener. Comput. Syst.2
2021 vSocial: a cloud-based system for social virtual reality learning environment applications in special education
Sai Shreya Nuguri, Prasad Calyam, Roland Oruche, Aniket Gulhane, Samaikya Valluripally, Janine Stichter, Zhihai He
Multim. Tools Appl.2
2021 HonestChain: Consortium blockchain for protected data sharing in health information systems
Soumya Purohit, Prasad Calyam, Mauro Lemus, Naga Ramya Bhamidipati, Abu Saleh Mohammad Mosa, Khaled Salah 0001
Peer-to-Peer Netw. Appl.2
2021 Multi-Cloud Performance and Security Driven Federated Workflow Management
abstract
Federated multi-cloud resource allocation for data-intensive application workflows is generally performed based on performance or quality of service (i.e., QSpecs) considerations. At the same time, end-to-end security requirements of these workflows across multiple domains are considered as an afterthought due to lack of standardized formalization methods. Consequently, diverse/heterogenous domain resource and security policies cause inter-conflicts between application's security and performance requirements that lead to sub-optimal resource allocations. In this paper, we present a joint performance and security-driven federated resource allocation scheme for data-intensive scientific applications. In order to aid joint resource brokering among multi-cloud domains with diverse/heterogenous security postures, we first define and characterize a data-intensive application's security specifications (i.e., SSpecs). Then we describe an alignment technique inspired by Portunes Algebra to homogenize the various domain resource policies (i.e., RSpecs) along an application's workflow lifecycle stages. Using such formalization and alignment, we propose a near optimal cost-aware joint QSpecs-SSpecs-driven, RSpecs-compliant resource allocation algorithm for multi-cloud computing resource domain/location selection as well as network path selection. We implement our security formalization, alignment, and allocation scheme as a framework, viz., “OnTimeURB” and validate it in a multi-cloud environment with exemplar data-intensive application workflows involving distributed computing and remote instrumentation use cases with different performance and security requirements.
Matthew Dickinson, Saptarshi Debroy, Prasad Calyam, Samaikya Valluripally, Yuanxun Zhang, Ronny Bazan Antequera, Trupti Joshi, Tommi A. White, Dong Xu 0002
IEEE Trans. Cloud Comput.3
2021 On QoE-Oriented Cloud Service Orchestration for Application Providers
abstract
New virtualization technologies allow Infrastructure Providers (InPs) to lease their resources to Application Service Providers (ASPs) for highly scalable delivery of cloud services to end-users. However, existing literature lacks knowledge on Quality of Experience (QoE)-oriented cloud service orchestration algorithms that can guide ASPs on how to plan their budget to enhance satisfactory QoE delivery to end-users. In contrast to the InP's cloud service orchestration, the ASP's orchestration should not rely on expensive infrastructure control mechanisms such as Software-Defined Networking (SDN), or require aprioriknowledge on the number of services to be instantiated and their anticipated placement location within InP's infrastructure. In this paper, we address this issue of delivering satisfactory user QoE by synergistically optimizing both ASP's management and data planes. The optimization within the ASP management planefirst maximizes Service Level Objective (SLO) coverage of users when application services are being deployed, and are not yet operational. The optimization of the ASP data plane then enhances satisfactory user QoE delivery when applications services are operational with real user access. Our evaluation of QoE-oriented algorithms using realistic numerical simulations, real-world cloud testbed experiments with actual users and ASP case studies show notably improved performance over existing cloud service orchestration solutions.
D. Yu. Chemodanov, Prasad Calyam, Samaikya Valluripally, Huy Trinh, Jon Patman, Kannappan Palaniappan
IEEE Trans. Serv. Comput.2
2020 A Formative Usability Study to Improve Prescriptive Systems for Bioinformatics Big Data
abstract
Big data computation tools are vital for researchers and educators from various domains such as plant science, animal science, biomedical science and others. With the growing computational complexity of biology big data, advanced analytic systems, known as prescriptive systems, are being built using machine learning models to intelligently predict optimum computation solutions for users for better data analysis. However, lack of user-friendly prescriptive systems poses a critical roadblock to facilitating informed decision-making by users. In this paper, we detail a formative usability study to address the complexities faced by users while using prescriptive systems. Our usability research approach considers bioinformatics workflows and community cloud resources in the KBCommons framework's science gateway. The results show that recommendations from usability studies performed in iterations during the development of prescriptive systems can improve user experience, user satisfaction and help novice as well as expert users to make decisions in a well-informed manner.
Kanu Priya Singh, Shangman Li, Isa Jahnke, Zhen Lyu, Trupti Joshi, Prasad Calyam
BIBM7
2020 Attack Trees for Security and Privacy in Social Virtual Reality Learning Environments
abstract
Social Virtual Reality Learning Environment (VRLE) is a novel edge computing platform for collaboration amongst distributed users. Given that VRLEs are used for critical applications (e.g., special education, public safety training), it is important to ensure security and privacy issues. In this paper, we present a novel framework to obtain quantitative assessments of threats and vulnerabilities for VRLEs. Based on the use cases from an actual social VRLE viz., vSocial, we first model the security and privacy using the attack trees. Subsequently, these attack trees are converted into stochastic timed automata representations that allow for rigorous statistical model checking. Such an analysis helps us adopt pertinent design principles such as hardening, diversity and principle of least privilege to enhance the resilience of social VRLEs. Through experiments in a vSocial case study, we demonstrate the effectiveness of our attack tree modeling with a reduction of 26% in probability of loss of integrity (security) and 80% in privacy leakage (privacy) in before and after scenarios pertaining to the adoption of the design principles.
Samaikya Valluripally, Aniket Gulhane, Reshmi Mitra, Khaza Anuarul Hoque, Prasad Calyam
CCNC5
2020 Impact of False Data Injection Attacks on Deep Learning Enabled Predictive Analytics
abstract
Industry 4.0 is the latest industrial revolution primarily merging automation with advanced manufacturing to reduce direct human effort and resources. Predictive maintenance (PdM) is an industry 4.0 solution, which facilitates predicting faults in a component or a system powered by state-of-the- art machine learning (ML) algorithms (especially deep learning algorithms) and the Internet-of-Things (IoT) sensors. However, IoT sensors and deep learning (DL) algorithms, both are known for their vulnerabilities to cyber-attacks. In the context of PdM systems, such attacks can have catastrophic consequences as they are hard to detect due to the nature of the attack. To date, the majority of the published literature focuses on the accuracy of DL enabled PdM systems and often ignores the effect of such attacks. In this paper, we demonstrate the effect of IoT sensor attacks (in the form of false data injection attack) on a PdM system. At first, we use three state-of-the-art DL algorithms, specifically, Long Short-Term Memory (LSTM), Gated Recurrent Unit (GRU), and Convolutional Neural Network (CNN) for predicting the Remaining Useful Life (RUL) of a turbofan engine using NASA's C-MAPSS dataset. The obtained results show that the GRU-based PdM model outperforms some of the recent literature on RUL prediction using the C-MAPSS dataset. Afterward, we model and apply two different types of false data injection attacks (FDIA), specifically, continuous and interim FDIAs on turbofan engine sensor data and evaluate their impact on CNN, LSTM, and GRU-based PdM systems. The obtained results demonstrate that FDI attacks on even a few IoT sensors can strongly defect the RUL prediction in all cases. However, the GRU-based PdM model performs better in terms of accuracy and resiliency to FDIA. Lastly, we perform a study on the GRU-based PdM model using four different GRU networks with different sequence lengths. Our experiments reveal an interesting relationship between the accuracy, resiliency and sequence length for the GRU-based PdM models.
Gautam Raj Mode, Prasad Calyam, Khaza Anuarul Hoque
NOMS2
2020 REBATE: A REpulsive-BAsed Traffic Engineering protocol for dynamic scale-free networks
D. Yu. Chemodanov, Flavio Esposito, Prasad Calyam, Andrei M. Sukhov
Future Gener. Comput. Syst.3
2020 Frequency-Minimal Utility-Maximal Moving Target Defense Against DDoS in SDN-Based Systems
abstract
With the increase of DDoS attacks, resource adaptation schemes need to be effective to protect critical cloud-hosted applications. Specifically, they need to be adaptable to attack behavior, and be dynamic in terms of resource utilization. In this paper, we propose an intelligent strategy for proactive and reactive application migration by leveraging the concept of `moving target defense' (MTD). The novelty of our approach lies in: (a) stochastic proactive migration frequency minimization across heterogeneous cloud resources to optimize migration management overheads, (b) market-driven migration location selection during proactive migration to optimize resource utilization, cloud service providers (CSPs) cost and user quality of experience, and (c) fast converging cost-minimizing reactive migration coupled with a `false reality' pretense to reduce the future attack success probability. We evaluate the effectiveness of our proposed MTD-based defense strategy using a Software-defined Networking (SDN) enabled GENI Cloud testbed for a “Just-in-time news articles and video feeds” application. Our frequency minimization results show more than 40% reduction in DDoS attack success rate in the best cases when compared to the traditional periodic migration schemes on homogeneous cloud resources. The results also show that our market-driven migration location selection strategy decreases CSP cost and increases resource utilization by 30%.
Saptarshi Debroy, Prasad Calyam, Roshan Neupane, Bidyut Mukherjee, Ajay Kumar Eeralla, Khaled Salah 0001
IEEE Trans. Netw. Serv. Manag.2
2020 Predictive Cyber Foraging for Visual Cloud Computing in Large-Scale IoT Systems
abstract
Cyber foraging has been shown to be especially effective for augmenting low-power Internet-of-Thing (IoT) devices by offloading video processing tasks to nearby edge/cloud computing servers. Factors such as dynamic network conditions, concurrent user access, and limited resource availability, cause offloading decisions that negatively impact overall processing throughput and end-user delays. Moreover, edge/cloud platforms currently offer both Virtual Machine (VM) and serverless computing pricing models, but many existing edge offloading approaches only investigate single VM-based offloading performance. In this paper, we propose a predictive (NP-complete) scheduling-based offloading framework and a heuristic-based counterpart that use machine learning to dynamically decide what combinations of functions or single VM needs to be deployed so that tasks can be efficiently scheduled. We collected over 10,000 network and device traces in a series of realistic experiments relating to a protest crowds incident management application. We then evaluated the practicality of our predictive cyber foraging approach using trace-driven simulations for up to 1000 devices. Our results indicate that predicting single VM offloading costs: (a) leads to near-optimal scheduling in 70% of the cases for service function chaining, and (b) offers a 40% gain in performance over traditional baseline estimation techniques that rely on simple statistics for estimations in the case of single VM-offloading. Considering a series of visual computing offloading scenarios, we also validate our approach benefits of using online versus offline machine learning models for predicting offloading delays.
Jon Patman, D. Yu. Chemodanov, Prasad Calyam, Kannappan Palaniappan, Claudio Sterle, Maurizio Boccia
IEEE Trans. Netw. Serv. Manag.3
2019 OnTimeURB: Multi-Cloud Resource Brokering for Bioinformatics Workflows
abstract
Scientific workflows due to their data and memory intensive requirements are among the prime applications which benefit by leveraging cloud computing. However, Cloud service providers (CSPs) have distinct policies and service dynamics that present a problem of excess choice for users. Performance and cost of the cloud services are among the principal factors in CSP selection for scientific bioinformatics workflows. The workflows typically are based on private data, and require diverse cloud resources, thus often requiring synergistic services from multiple CSPs. In this paper, we address this challenge of multi-cloud resource selection using cloud template solutions based on user specifications. We propose an optimizer that incorporates a combinatorial optimization model built on performance, cost and CSPs interoperability factors. The optimizer is integrated within a novel resource broker (i.e., OnTimeURB) for prescriptive recommendations of template solutions with intuitive choices for users. We implement and evaluate the OnTimeURB recommendations framework with a catalog of bioinformatics workflow applications integrated within a KBCommons science gateway. The evaluation considered four CSP resources featuring more than 300 different machine configuration instances. Our evaluation results show that our OnTimeURB creates consistently more economical, performance optimized and practical cloud solutions compared to a k-nearest neighbors (k-NN) approach.
Zhen Lyu, Trupti Joshi, Prasad Calyam
BIBM4
2019 Security, Privacy and Safety Risk Assessment for Virtual Reality Learning Environment Applications
abstract
Social Virtual Reality based Learning Environments (VRLEs) such as vSocial render instructional content in a three-dimensional immersive computer experience for training youth with learning impediments. There are limited prior works that explored attack vulnerability in VR technology, and hence there is a need for systematic frameworks to quantify risks corresponding to security, privacy, and safety (SPS) threats. The SPS threats can adversely impact the educational user experience and hinder delivery of VRLE content. In this paper, we propose a novel risk assessment framework that utilizes attack trees to calculate a risk score for varied VRLE threats with rate and duration of threats as inputs. We compare the impact of a well-constructed attack tree with an adhoc attack tree to study the trade-offs between overheads in managing attack trees, and the cost of risk mitigation when vulnerabilities are identified. We use a vSocial VRLE testbed in a case study to showcase the effectiveness of our framework and demonstrate how a suitable attack tree formalism can result in a more safer, privacy-preserving and secure VRLE system.
Aniket Gulhane, Akhil Vyas, Reshmi Mitra, Roland Oruche, Gabriela Hoefer, Samaikya Valluripally, Prasad Calyam, Khaza Anuarul Hoque
CCNC7
2019 Multi-Cloud Performance and Security-driven Brokering for Bioinformatics Workflows
abstract
Data-intensive bioinformatics applications often use federated multi-cloud infrastructures to support compute-intensive processing needs. In this paper, we propose a Multi-Cloud Performance and Security (MCPS) Brokering framework within such federated multi-cloud infrastructures to allocate cloud resources to applications by satisfying their performance and security requirements.
Saptarshi Debroy, Prasad Calyam, Zhen Lyu, Trupti Joshi
ICNP3
2019 Data-intensive Workflow Execution using Distributed Compute Resources
abstract
Cloud computing has become a necessary utility for scientific and technical applications. Many diverse web services are published and subscribed using cloud data centers. It has become fairly easy to use services from Cloud Service Providers (CSPs) for computation and data processing. However, even with all their benefits, commercial cloud resources are not economical when large data processing is required. Hence, educators and researchers need guidance to use commercial cloud resources to run large data processing workflow applications within a budget. In this paper, we propose a framework to help users to leverage distributed compute resources to execute data-intensive application workflows, under budget constraints. We demonstrate how our framework can be used by users who may have access to small-scale compute resources in-house, to seamlessly interoperate with public cloud resources.
Songjie Wang, Prasad Calyam
ICNP3
2019 DyCOCo: A Dynamic Computation Offloading and Control Framework for Drone Video Analytics
abstract
Unmanned aerial vehicles (UAV) or drone systems equipped with cameras are extensively used in different surveillance scenarios and often require real-time control and high-quality video transmission. However, unstable network situations and various transport protocols may result in impairments during video streaming, which in turn negatively impacts user's quality of experience (QoE). In this paper, we propose a dynamic computation offloading and control framework, named DyCOCo, based on image impairment detection under various available network bandwith conditions. Our DyCOCo framework demo features IoT devices in a testbed setup on the GENI infrastructure. Our demo results show that our DyCOCo approach can efficiently choose the suitable networking protocols and orchestrate both the camera control on the drone, and the computation offloading of the video analytics over limited edge computing/networking resources.
Chengyi Qu, Songjie Wang, Prasad Calyam
ICNP3
2019 A Near Optimal Reliable Composition Approach for Geo-Distributed Latency-Sensitive Service Chains
abstract
Traditionally, Network Function Virtualization uses Service Function Chaining (SFC) to place service functions and chain them with corresponding flows allocation. With the advent of Edge computing and IoT, a retiable composition of latency-sensitive SFCs is needed to support applications in geo-distributed cloud infrastructures. However, the optimal SFC composition in this case becomes the NP-hard integer multi-commodity-chain flow (MCCF) problem that has no known approximation guarantees. In this paper, we present a novel practical and near optimal SFC composition approach for geo-distributed cloud infrastructures that also admits end-to-end network QoS constraints such as latency, packet loss, etc. Specifically, we propose a novel metapath composite variable approach that reaches 99% optimality on average and takes seconds for practically sized integer MCCF problems of US Tier-1 (~300 nodes) and regional (~600 nodes) infrastructure providers' topologies. To ensure reliability, we compose SFCs with capacity chance-constraints and backup policies. Using trace-driven simulations comprising of challenging disaster-incident conditions, we show that our solution composes twice as many SFCs than the state-of-the-art network virtualization methods.
D. Yu. Chemodanov, Prasad Calyam, Flavio Esposito
INFOCOM2
2019 Policy-Based Function-Centric Computation Offloading for Real-Time Drone Video Analytics
abstract
Computer vision applications are increasingly used on mobile Internet-of-Things (IoT) devices such as drones. They provide real-time support in disaster/incident response or crowd protest management scenarios by e.g., counting human/vehicles, or recognizing faces/objects. However, deployment of such applications for real-time video analytics at geo-distributed areas presents new challenges in processing intensive media-rich data to meet users' Quality of Experience (QoE) expectations, due to limited computing power on the devices. In this paper, we present a novel policy-based decision computation offloading scheme that not only facilitates trade-offs in performance vs. cost, but also aids in offloading decision to either an Edge, Cloud or Function-Centric Computing resource architecture for real-time video analytics. To evaluate our offloading scheme, we decompose an existing computer vision pipeline for object/motion detection and object classification into a chain of container-based micro-service functions that communicate via a RESTful API. We evaluate the performance of our scheme on a realistic geo-distributed edge/core cloud testbed using different policies and computing architectures. Results show how our scheme utilizes state-of-the-art computation offloading techniques to Pareto-optimally trade-off performance (i.e., frames-per-second) vs. cost factors (using Amazon Web Services Lambda pricing) during real-time drone video analytics, and thus fosters effective environmental situational awareness.
D. Yu. Chemodanov, Chengyi Qu, Osunkoya Opeoluwa, Songjie Wang, Prasad Calyam
LANMAN5
2019 Recommending heterogeneous resources for science gateway applications based on custom templates composition
Ronny Bazan Antequera, Prasad Calyam, Arjun Ankathatti Chandrashekara, Reshmi Mitra
Future Gener. Comput. Syst.2
2019 AGRA: AI-augmented geographic routing approach for IoT-based incident-supporting applications
D. Yu. Chemodanov, Flavio Esposito, Andrei M. Sukhov, Prasad Calyam, Huy Trinh, Zakariya A. Oraibi
Future Gener. Comput. Syst.4
2019 Intelligent defense using pretense against targeted attacks in cloud platforms
Roshan Neupane, Travis Neely, Prasad Calyam, Nishant Chettri, Mark Vassell, Ramakrishnan Durairajan
Future Gener. Comput. Syst.3
2019 A Constrained Shortest Path Scheme for Virtual Network Service Management
abstract
Virtual network services that span multiple data centers are important to support emerging data-intensive applications in fields such as bioinformatics and retail analytics. Successful virtual network service composition and maintenance requires flexible and scalable “constrained shortest path management” both in the management plane for virtual network embedding (VNE) or network function virtualization service chaining (NFV-SC), as well as in the data plane for traffic engineering (TE). In this paper, we show analytically and empirically that leveraging constrained shortest paths within recent VNE, NFV-SC and TE algorithms can lead to network utilization gains (of up to 50%) and higher energy efficiency. The management of complex VNE, NFV-SC and TE algorithms can be, however, intractable for large scale substrate networks due to the NP-hardness of the constrained shortest path problem. To address such scalability challenges, we propose a novel, exact constrained shortest path algorithm viz., neighborhoods method (NM). Our NM uses novel search space reduction techniques and has a theoretical quadratic speed-up making it practically faster (by an order of magnitude) than recent branch-and-bound exhaustive search solutions. Finally, we detail our NM-based SDN controller implementation in a real-world testbed to further validate practical NM benefits for virtual network services.
D. Yu. Chemodanov, Flavio Esposito, Prasad Calyam, Andrei M. Sukhov
IEEE Trans. Netw. Serv. Manag.3
2019 Security Middleground for Resource Protection in Measurement Infrastructure-as-a-Service
abstract
Securing multi-domain network performance monitoring (NPM) systems that are being widely deployed as `Measurement Infrastructure-as-a-Service' (MIaaS) in high-performance computing is becoming increasingly critical. It presents an emerging set of research challenges in cloud security given that security mechanisms such as policy-driven access to federated NPM services across multiple domains need to be designed carefully to protect MIaaS resources and data. In this paper, we advocate the design of a security middleground between default open/closed access settings and present policy-driven access controls of measurement functions for a multi-domain federation using a MIaaS. Our approach involves an analytical investigation based on a set of custom metrics to compare and contrast the legacy, role-based and more fine-grained, attribute-based access control schemes to design a security middleground. We implement the chosen middleground with a secured middleware, viz., “OnTimeSecure”. Our middleware enables `user-to-service' and `service-to-service' authentication, and enforces federated authorization entitlement policies for timely orchestration of MIaaS services. Lastly, we evaluate OnTimeSecure in a real multi-domain MIaaS testbed by performing threat modeling and security risk assessments to validate the analysis outcomes and demonstrate its effectiveness for easy integration and sustainable adoption.
Ravi Akella, Saptarshi Debroy, Prasad Calyam, Alex Berryman, Kunpeng Zhu, Mukundan Sridharan
IEEE Trans. Serv. Comput.3
2018 Fuzzy-Based Conversational Recommender for Data-intensive Science Gateway Applications
abstract
Neuro-scientists are increasingly relying on parallel and distributed computing resources for analysis and visualization of their neuron simulations. Although science gateways have democratized relevant high performance/throughput resources, users require expert knowledge about programming and infrastructure configuration that is beyond the repertoire of most neuroscience programs. These factors become deterrents for the successful adoption and the ultimate diffusion (i.e., systemic spread) of science gateways in the neuroscience community. In this paper, we present a novel intuitionistic fuzzy logic based conversational recommender that can provide guidance to users when using science gateways for research and education workflows. The users interact with a context-aware chatbot that is embedded within custom web-portals to obtain simulation tools/resources to accomplish their goals. In order to ensure user goals are met, the chatbot profiles a user's cyberinfrastructure and neuroscience domain proficiency level using a `usability quadrant' approach. Simulation of user queries for an exemplary neuroscience use case demonstrates that our chatbot can provide step-by-step navigational support and generate distinct responses based on user proficiency.
Arjun Ankathatti Chandrashekara, Radha Krishna Murthy Talluri, Sai Swathi Sivarathri, Reshmi Mitra, Prasad Calyam, Kerk F. Kee, Satish S. Nair
IEEE BigData5
2018 Domain-specific Topic Model for Knowledge Discovery through Conversational Agents in Data Intensive Scientific Communities
abstract
Machine learning techniques underlying Big Data analytics have the potential to benefit data intensive communities in e.g., bioinformatics and neuroscience domain sciences. Today's innovative advances in these domain communities are increasingly built upon multi-disciplinary knowledge discovery and cross-domain collaborations. Consequently, shortened time to knowledge discovery is a challenge when investigating new methods, developing new tools, or integrating datasets. The challenge for a domain scientist particularly lies in the actions to obtain guidance through query of massive information from diverse text corpus comprising of a wide-ranging set of topics. In this paper, we propose a novel "domain-specific topic model" (DSTM) that can drive conversational agents for users to discover latent knowledge patterns about relationships among research topics, tools and datasets from exemplar scientific domains. The goal of DSTM is to perform data mining to obtain meaningful guidance via a chatbot for domain scientists to choose the relevant tools or datasets pertinent to solving a computational and data intensive research problem at hand. Our DSTM is a Bayesian hierarchical model that extends the Latent Dirichlet Allocation (LDA) model and uses a Markov chain Monte Carlo algorithm to infer latent patterns within a specific domain in an unsupervised manner. We apply our DSTM to large collections of data from bioinformatics and neuroscience domains that include hundreds of papers from reputed journal archives, hundreds of tools and datasets. Through evaluation experiments with a perplexity metric, we show that our model has better generalization performance within a domain for discovering highly specific latent topics.
Yuanxun Zhang, Prasad Calyam, Trupti Joshi, Satish S. Nair, Dong Xu 0002
IEEE BigData2
2018 Towards a social virtual reality learning environment in high fidelity
abstract
Virtual Learning Environments (VLEs) are spaces designed to educate students remotely via online platforms. Although traditional VLEs such as iSocial have shown promise in educating students, they offer limited immersion that diminishes learning effectiveness. This paper outlines a virtual reality learning environment (VRLE) over a high-speed network, which promotes educational effectiveness and efficiency via our creation of flexible content and infrastructure which meet established VLE standards with improved immersion. This paper further describes our implementation of multiple learning modules developed in High Fidelity, a “social VR” platform. Our experiment results show that the VR mode of content delivery better stimulates the generalization of lessons to the real world than non-VR lessons and provides improved immersion when compared to an equivalent desktop version.
Chiara Zizza, Adam Starr, Devin Hudson, Sai Shreya Nuguri, Prasad Calyam, Zhihai He
CCNC5
2018 Data-Driven Edge Computing Resource Scheduling for Protest Crowds Incident Management
abstract
Computation offloading has been shown to be a viable solution for addressing the challenges of processing compute-intensive workloads between low-power devices and nearby servers known as cloudlets. However, factors such as dynamic network conditions, concurrent user access, and limited resource availability often result in offloading decisions negatively impacting end users in terms of delay and energy consumption. To address these shortcomings, we investigate the benefits of using Machine Learning for predicting offloading costs for a facial recognition service in a series of realistic wireless experiments. We also perform a set of trace-driven simulations to emulate a multi-edge protest crowd incident case study and formulate an optimization model that minimizes the time taken for all service tasks to be completed. Because optimizing offloading schedules for such a system is a well-known NP-complete problem, we use mixed integer programming and show that our scheduling solution scales efficiently for a moderate number of user devices (10-100) with a correspondingly small number of cloudlets (1-10), a scale commonly sufficient for public safety officials in crowd incident management. Moreover, our results indicate that using Machine Learning for predicting offloading costs leads to near-optimal scheduling in 70 % of the cases we investigated and offers a 40 % gain in performance over baseline estimation techniques.
Jon Patman, Peter Lovett, Andrew Banning, Annie Barnert, D. Yu. Chemodanov, Prasad Calyam
NCA6
2018 Flexible IoT security middleware for end-to-end cloud-fog communication
Bidyut Mukherjee, Songjie Wang, Wenyi Lu, Roshan Neupane, Daniel Dunn, Yijie Ren, Prasad Calyam
Future Gener. Comput. Syst.8
2018 ADON: Application-Driven Overlay Network-as-a-Service for Data-Intensive Science
abstract
Campuses are increasingly adopting hybrid cloud architectures for supporting data-intensive science applications that require “on-demand” resources, which are not always available locally on-site. Policies at the campus edge for handling multiple such applications competing for remote resources can cause bottlenecks across applications. These bottlenecks can be proactively avoided with pertinent profiling, monitoring and control of application flows using software-defined networking and pertinent selection of local or remote compute resources. In this paper, we present an “application-driven overlay network-as-a-service” (ADON) that manages the hybrid cloud requirements of multiple applications in a scalable and extensible manner by allowing users to specify requirements of the application that are translated into the underlying network and compute provisioning requirements. Our solution involves scheduling transit selection, a cost optimized selection of site(s) for computation and traffic engineering at the campus-edge based upon real-time policy control that ensures prioritized application performance delivery for multi-tenant traffic profiles. We validate our ADON approach through an emulation study and through a wide-area overlay network testbed implementation across two campuses. Our workflow orchestration results show the ADON effectiveness in handling temporal behavior of multi-tenant traffic burst arrivals using profiles from a diverse set of actual data-intensive applications.
Ronny Bazan Antequera, Prasad Calyam, Saptarshi Debroy, Longhai Cui, Sripriya Seetharam, Matthew Dickinson, Trupti Joshi, Dong Xu 0002, Tsegereda Beyene
IEEE Trans. Cloud Comput.2
2018 Energy-Aware Mobile Edge Computing and Routing for Low-Latency Visual Data Processing
abstract
New paradigms such as Mobile Edge Computing (MEC) are becoming feasible for use in, e.g., real-time decision-making during disaster incident response to handle the data deluge occurring in the network edge. However, MEC deployments today lack flexible IoT device data handling such as handling user preferences for real-time versus energy-efficient processing. Moreover, MEC can also benefit from a policy-based edge routing to handle sustained performance levels with efficient energy consumption. In this paper, we study the potential of MEC to address application issues related to energy management on constrained IoT devices with limited power sources, while also providing low-latency processing of visual data being generated at high resolutions. Using a facial recognition application that is important in disaster incident response scenarios, we propose a novel “offload decision-making” algorithm that analyzes the tradeoffs in computing policies to offload visual data processing (i.e., to an edge cloud or a core cloud) at low-to-high workloads. This algorithm also analyzes the impact on energy consumption in the decision-making under different visual data consumption requirements (i.e., users with thick clients or thin clients). To address the processing-throughput versus energy-efficiency tradeoffs, we propose a “Sustainable Policy-based Intelligence-Driven Edge Routing” algorithm that uses machine learning within Mobile Ad hoc Networks. This algorithm is energy aware and improves the geographic routing baseline performance (i.e., minimizes impact of local minima) for throughput performance sustainability, while also enabling flexible policy specification. We evaluate our proposed algorithms by conducting experiments on a realistic edge and core cloud testbed in the GENI Cloud infrastructure, and recreate disaster scenes of tornado damages within simulations. Our empirical results show how MEC can provide flexibility to users who desire energy conservation over low latency or vice versa in the visual data processing with a facial recognition application. In addition, our simulation results show that our routing approach outperforms existing solutions under diverse user preferences, node mobility, and severe node failure conditions.
Huy Trinh, Prasad Calyam, D. Yu. Chemodanov, Shizeng Yao, Kannappan Palaniappan
IEEE Trans. Multim.2
2018 Social Plane for Recommenders in Network Performance Expectation Management
abstract
Multi-domain end-to-end network performance monitoring federations such as perfSONAR are increasingly being used in Big Data application management. They rely on trustworthy collaborative measurement intelligence to identify and diagnose network anomaly events that impact application performance. Large volumes of end-to-end measurement traces are generated on a daily basis, and new Big Data analysis techniques are needed to isolate network-wide anomaly event(s) and to diagnose the root-cause(s). In addition, not all network operators and application users have enough knowledge and experience to understand the anomaly events. The lack of a platform for sharing knowledge and working collaboratively makes it difficult to isolate and diagnose network-wide anomaly events quickly and accurately. In this paper, we define a “social plane” that relies on recommended measurements based on “content-based filtering” and “collaborative filtering” approaches to enable network performance expectation management. Based on similarity analysis, the content-based filtering facilitates users to subscribe to useful measurements, and the collaborative filtering promotes users to share knowledge on anomaly symptoms. Using real perfSONAR measurements and synthetic events, we show the effectiveness of our social plane approach within a SoyKB Big Data application case study using social network creation and mingling of experts. Our experimental results show that our measurements recommendation scheme has high precision, recall, and accuracy, as well as efficiency in terms of the time taken for large volume measurement trace analysis.
Yuanxun Zhang, Prasad Calyam, Saptarshi Debroy, Sai Shreya Nuguri
IEEE Trans. Netw. Serv. Manag.2
2017 End-to-End IoT Security Middleware for Cloud-Fog Communication
abstract
IoT (Internet of Things) devices such as sensors have been actively used in 'fogs' to provide critical data during e.g., disaster response scenarios or in-home healthcare. Since IoT devices typically operate in resource-constrained computing environments at the network-edge, data transfer performance to the cloud as well as end-to-end security have to be robust and customizable. In this paper, we present the design and implementation of a middleware featuring "intermittent" and "flexible" end-to-end security for cloud-fog communications. Intermittent security copes with unreliable network connections, and flexibility is achieved through security configurations that are tailored to application needs. Our experiment results show how our middleware that leverages static pre-shared keys forms a promising solution for delivering light-weight, fast and resource-aware security for a variety of IoT-based applications.
Bidyut Mukherjee, Roshan Neupane, Prasad Calyam
CSCloud3
2017 Socio-technical approach to engineer gigabit app performance for physicaltherapy-as-a-service
abstract
The deployment of Gigabit Apps owing to their high-bandwidth and low-latency nature pushes the limits of today's end-to-end networking, and reveals new bottlenecks at multiple layers of networking, virtualization, application and user experience. In this paper, we use an exemplar smart health related Gigabit App use case viz., PhysicalTherapy-as-a-Service to show how a multi-layer instrumentation approach of measurement points was critical to successfully deploy our lab-tested App out to residential homes with Google Fiber connections. The salient instrumentation strategies involved an organized co-design method between the App Developer and Network Engineer roles, and a multi-domain network performance monitoring featuring perfSONAR extensions, both of which were realized through our Narada Metrics framework. Our instrumentation strategies engendered a “socio-technical tool” for co-ordination between multi-layer stakeholders in identifying and overcoming the intertwined bottlenecks, and in tuning the App performance. Our results highlight the new instrumentation and measurement challenges to foster multi-layer stakeholder collaboration, and provide rare insights to the budding Gigabit App developer community for performance engineering their Apps to serve residential users.
Ronny Bazan Antequera, Prasad Calyam, D. Yu. Chemodanov, Walter de Donato, Anup K. Mishra, Antonio Pescapè, Marjorie Skubic
Healthcom2
2017 Hyperprofile-Based Computation Offloading for Mobile Edge Networks
abstract
In recent studies, researchers have developed various computation offloading frameworks for bringing cloud services closer to the user via edge networks. Specifically, an edge device needs to offload computationally intensive tasks because of energy and processing constraints. These constraints present the challenge of identifying which edge nodes should receive tasks to reduce overall resource consumption. We propose a unique solution to this problem which incorporates elements from Knowledge-Defined Networking (KDN) to make intelligent predictions about offloading costs based on historical data. Each server instance can be represented in a multidimensional feature space where each dimension corresponds to a predicted metric. We compute features for a "hyperprofile" and position nodes based on the predicted costs of offloading a particular task. We then perform a k-Nearest Neighbor (kNN) query within the hyperprofile to select nodes for offloading computation. This paper formalizes our hyperprofile-based solution and explores the viability of using machine learning (ML) techniques to predict metrics useful for computation offloading. We also investigate the effects of using different distance metrics for the queries. Our results show various network metrics can be modeled accurately with regression, and there are circumstances where kNN queries using Euclidean distance as opposed to rectilinear distance is more favorable.
Andrew Crutcher, Caleb Koch 0001, Kyle Coleman, Jon Patman, Flavio Esposito, Prasad Calyam
MASS6
2017 Incident-Supporting Visual Cloud Computing Utilizing Software-Defined Networking
abstract
In the event of natural or man-made disasters, providing rapid situational awareness through video/image data collected at salient incident scenes is often critical to the first responders. However, computer vision techniques that can process the media-rich and data-intensive content obtained from civilian smartphones or surveillance cameras require large amounts of computational resources or ancillary data sources that may not be available at the geographical location of the incident. In this paper, we propose an incident-supporting visual cloud computing solution by defining a collection, computation, and consumption (3C) architecture supporting fog computing at the network edge close to the collection/consumption sites, which is coupled with cloud offloading to a core computation, utilizing software-defined networking (SDN). We evaluate our 3C architecture and algorithms using realistic virtual environment test beds. We also describe our insights in preparing the cloud provisioning and thin-client desktop fogs to handle the elasticity and user mobility demands in a theater-scale application. In addition, we demonstrate the use of SDN for on-demand compute offload with congestion-avoiding traffic steering to enhance remote user quality of experience in a regional-scale application. The optimization between fogs computing at the network edge with core cloud computing for managing visual analytics reduces latency, congestion, and increases throughput.
Rasha S. Gargees, Brittany Morago, Rengarajan Pelapur, D. Yu. Chemodanov, Prasad Calyam, Zakariya A. Oraibi, Ye Duan, Guna Seetharaman, Kannappan Palaniappan
IEEE Trans. Circuits Syst. Video Technol.5
2017 Analytical Model for Elastic Scaling of Cloud-Based Firewalls
abstract
This paper shows how to properly achieve elasticity for network firewalls deployed in a cloud environment. Elasticity is the ability to adapt to workload changes by provisioning and de-provisioning resources in an autonomic manner, such that at each point in time the available resources match the current demand as closely as possible. Elasticity for cloud-based firewalls aims to satisfy an agreed-upon performance measure using only the minimal number of cloud firewall instances. Our contribution lies in determining the number of firewall instances that should be dynamically adjusted in accordance with the incoming traffic load and the targeted rules within the firewall rulebase. To do so, we develop an analytical model based on the principles of Markov chains and queueing theory. The model captures the behavior of a cloud-based firewall service comprising a load balancer and a variable number of virtual firewalls. From the analytical model, we then derive closed-form formulas to determine the minimal number of virtual firewalls required to meet the response time specified in the service level agreement. The model takes as input key system parameters including workload, processing capacity of load balancer and virtual machines, as well as the depth of the targeted firewall rules. We validate our model using discrete-event simulation, and real-world experiments conducted on Amazon Web Services cloud. We also provide numerical examples to show how our model can be used in practice by cloud performance/security engineers to achieve proper elasticity under fluctuating traffic load and variable depth of targeted firewall rules.
Khaled Salah 0001, Prasad Calyam, Raouf Boutaba
IEEE Trans. Netw. Serv. Manag.2
2016 End-to-End Security Formalization and Alignment for Federated Workflow Management
abstract
Traditionally, the allocation and dynamic adaptation of federated cyberinfrastructure resources residing across multiple domains for data-intensive application workflows have been performance or quality of service-centric (i.e., QSpecs), often compromising the end-to-end security requirements of scientific workflows. Lack of standardized formalization methods of the workflows' end-to-end security requirements, and diverse/heterogenous domain resource and security policies make inter-conflict characterization between application's security and performance requirements non-trivial, and leads to sub-optimal resource allocation. In this paper, we present a joint security and performance-driven federated resource allocation and adaptation scheme to define and characterize a data-intensive scientific application's security specifications (i.e., SSpecs). In order to aid security-driven resource brokering among domains with diverse security postures, we describe an alignment technique inspired by Portunes Algebra to combine domain-specific resource policies (i.e., RSpecs) along the application workflow life cycle. We use standardized guidelines that help in compute/storage resource domain/location selection as well as network path selection based on both application QSpecs and SSpecs. We implement our security formalization and alignment methods as a framework, viz., "OnTimeURB" and apply it on an exemplar Distributed Computing workflow to show the benefits of joint QSpecs-SSpecs-driven, RSpecs-compliant federated workflow management.
Matthew Dickinson, Saptarshi Debroy, Prasad Calyam, Samaikya Valluripally, Yuanxun Zhang, Trupti Joshi, Dong Xu 0002
CLOUD3
2016 Panacea's Cloud: Augmented reality for mass casualty disaster incident triage and co-ordination
abstract
Communication in a mass casualty disaster scene is limited and difficult for medical personnel in the absence of necessary communication infrastructure and collaboration technologies. It leads to misdirected and delayed triage of scene-wide critically injured patients, especially when there is a large volume of patients needing diverse care levels. Our demonstration of Panacea's Cloud shows a solution that utilizes a Responder Theater Dashboard that incorporates Internet of Things (IoT) within a standardized Incident Command System (ICS) in order to improve communication and co-ordination across multiple concurrent disaster incident scenes. The Internet of Things (IoT) in our Panacea Cloud include heads-up displays, virtual beacons, QR-code cards, and wireless mesh network.
John Gillis, Prasad Calyam, Olivia Apperson
CCNC2
2016 Intelligent Dashboard for augmented reality based incident command response co-ordination
abstract
Communication in a mass casualty disaster scene is limited and difficult for medical personnel in the absence of necessary communication infrastructure and collaboration technologies. It leads to misdirected and delayed triage of scene-wide critically injured patients, especially when there is a large volume of patients needing diverse care levels. In this paper, we describe a novel Intelligent Dashboard that provides augmented reality benefits with minimal human communication through integration of a standardized Incident Command System (ICS) with Internet of Things (IoT) such as heads-up displays, virtual beacons, QR-code cards, and wireless mesh network elements. We conduct a usability evaluation with a two-incident `Task Force 1 Rescue' simulation to show the ease-of-use and effectiveness of our Intelligent Dashboard. Our work lays the foundation for next-generation ICS for an Incident Commander to deploy resources at the right locations more efficiently, and reduce triage time, mitigate over/under triage, and thus increase triage care levels.
Mark Vassell, Olivia Apperson, Prasad Calyam, John Gillis
CCNC3
2016 A general constrained shortest path approach for virtual path embedding
abstract
Network virtualization has become a fundamental technology to deliver services for emerging data-intensive applications in fields such as bioinformatics and retail analytics hosted at multi-data center scale. To create and maintain a successful virtual network service, the problem of generating a constrained path manifests both in the management plane with a physical path creation -chains of virtual network functions or virtual link embedding - and in the data plane with on-demand path adaptation - traffic steering with Service Level Objective (SLO) guarantees. In this paper, we define the virtual path embedding problem to subsume the virtual link embedding and the constrained traffic steering problems, and propose a new scheme to solve it optimally. Specifically, we introduce a novel algorithm viz., `Neighborhood Method' (NM) which provides an on-demand path with SLO guarantees while reducing expensive over provisioning. We show that by solving the Virtual Path Embedding problem in a set of diverse topology scenarios we gain up to 20% in network utilization, and up to 150% in energy efficiency, compared to the existing path embedding solutions.
D. Yu. Chemodanov, Prasad Calyam, Flavio Esposito, Andrei M. Sukhov
LANMAN2
2016 Network measurement recommendations for performance bottleneck correlation analysis
abstract
Multi-domain network performance monitoring (NPM) federations, such as perfSONAR rely on collaborative measurement intelligence to identify network anomaly events and diagnose performance bottlenecks affecting data-intensive science applications. In this paper, we present a novel measurement recommendation scheme to assist network operators and application users by recommending pertinent samples from a pool of measurement data involving multiple domains to detect and troubleshoot correlated network anomaly events. The recommendations are based on the principles of content-based filtering. Such recommendations are complimented with Bayesian Inference based domain reputation meta-information to strengthen the veracity information of the recommended traces. Using actual long-term and short-term perfSONAR traces, we analyze recommendation results and show: a) how the content-based filter recommends the most pertinent traces based on their attributes, and b) the time-variant characteristics of domain reputation. Finally, using synthetic traces, we show the effectiveness of our proposed measurements recommendation scheme in accurately identifying anomaly events for an exemplar use case, and also show how our content filter based recommendation scheme performs better in terms of false alarms in comparison to: a) recommendations that consider partial trace features for filtering, and b) greedy recommendation approaches based on random trace selection.
Yuanxun Zhang, Saptarshi Debroy, Prasad Calyam
LANMAN3
2016 Contextual geotracking service of incident markers in disaster search-and-rescue operations
abstract
Real-time geovisualization of disaster scenes provides visual situational awareness, which could decrease medical triage time, and also allows first responders to better allocate relief resources. In this paper, we describe a novel contextual geotracking service that provides spatiotemporal visualization of response history through the use of mobile devices and a wireless mesh network. During crisis response, with limited resources in a high-stress disaster relief environment, contextual data visualization of disaster incident scene status markers, and their presentation in a usable dashboard is crucial. We present novel visualization tools that we have developed to integrate custom map markers, tracking information collected through a wireless network, geovisualization over time through gradients, and spatiotemporal event filters. We evaluate our geotracking service in a field trial with a search-and-rescue task force comprising of professional first responders.We show effectiveness of our service in terms of data entry time, usability survey, and qualitative feedback within a disaster response simulation experiment.
Ev Cheng, Kourtney Meiss, Kendall Park, John Gillis, Dave Weber, Prasad Calyam
NCA7
2016 PGen: large-scale genomic variations analysis workflow and browser in SoyKB
abstract
BACKGROUND: With the advances in next-generation sequencing (NGS) technology and significant reductions in sequencing costs, it is now possible to sequence large collections of germplasm in crops for detecting genome-scale genetic variations and to apply the knowledge towards improvements in traits. To efficiently facilitate large-scale NGS resequencing data analysis of genomic variations, we have developed "PGen", an integrated and optimized workflow using the Extreme Science and Engineering Discovery Environment (XSEDE) high-performance computing (HPC) virtual system, iPlant cloud data storage resources and Pegasus workflow management system (Pegasus-WMS). The workflow allows users to identify single nucleotide polymorphisms (SNPs) and insertion-deletions (indels), perform SNP annotations and conduct copy number variation analyses on multiple resequencing datasets in a user-friendly and seamless way. RESULTS: We have developed both a Linux version in GitHub ( https://github.com/pegasus-isi/PGen-GenomicVariations-Workflow ) and a web-based implementation of the PGen workflow integrated within the Soybean Knowledge Base (SoyKB), ( http://soykb.org/Pegasus/index.php ). Using PGen, we identified 10,218,140 single-nucleotide polymorphisms (SNPs) and 1,398,982 indels from analysis of 106 soybean lines sequenced at 15X coverage. 297,245 non-synonymous SNPs and 3330 copy number variation (CNV) regions were identified from this analysis. SNPs identified using PGen from additional soybean resequencing projects adding to 500+ soybean germplasm lines in total have been integrated. These SNPs are being utilized for trait improvement using genotype to phenotype prediction approaches developed in-house. In order to browse and access NGS data easily, we have also developed an NGS resequencing data browser ( http://soykb.org/NGS_Resequence/NGS_index.php ) within SoyKB to provide easy access to SNP and downstream analysis results for soybean researchers. CONCLUSION: PGen workflow has been optimized for the most efficient analysis of soybean data using thorough testing and validation. This research serves as an example of best practices for development of genomics data analysis workflows by integrating remote HPC resources and efficient data management with ease of use for biological users. PGen workflow can also be easily customized for analysis of data in other species.
Saad M. Khan, Juexin Wang, Mats Rynge, Yuanxun Zhang, Shiyuan Chen, João V. Maldonado dos Santos, Babu Valliyodan, Prasad Calyam, Nirav C. Merchant, Henry T. Nguyen, Dong Xu 0002, Trupti Joshi
BMC Bioinform.10
2016 Synchronous Big Data analytics for personalized and remote physical therapy
Prasad Calyam, Anup K. Mishra, Ronny Bazan Antequera, D. Yu. Chemodanov, Alex Berryman, Kunpeng Zhu, Carmen Abbott, Marjorie Skubic
Pervasive Mob. Comput.1
2016 Network-Wide Anomaly Event Detection and Diagnosis With perfSONAR
abstract
High-performance computing (HPC) environments supporting data-intensive applications need multidomain network performance measurements from open frameworks such as perfSONAR. Detected network-wide correlated anomaly events that impact data throughput performance need to be quickly and accurately notified along with a root-cause analysis for remediation. In this paper, we present a novel network anomaly events detection and diagnosis scheme for network-wide visibility that improves accuracy of root-cause analysis. We address analysis limitations in cases where there is absence of complete network topology information, and when measurement probes are mis-calibrated leading to erroneous diagnosis. Our proposed scheme fuses perfSONAR time-series path measurements data from multiple domains using principal component analysis (PCA) to transform data for accurate correlated and uncorrelated anomaly events detection. We quantify the certainty of such detection using a measurement data sanity checking that involves: 1) measurement data reputation analysis to qualify the measurement samples and 2) filter framework to prune potentially misleading samples. Lastly, using actual perfSONAR one-way delay measurement traces, we show our proposed scheme's effectiveness in diagnosing the root-cause of critical network performance anomaly events.
Yuanxun Zhang, Saptarshi Debroy, Prasad Calyam
IEEE Trans. Netw. Serv. Manag.3
2015 Resource Defragmentation Using Market-Driven Allocation in Virtual Desktop Clouds
abstract
Similar to memory or disk fragmentation in personal computers, emerging "virtual desktop cloud" (VDC) services experience the problem of data center resource fragmentation which occurs due to on-the-fly provisioning of virtual desktop (VD) resources. Irregular resource holes due to fragmentation lead to sub-optimal VD resource allocations, and cause: (a)decreased user quality of experience (QoE), and (b) increased operational costs for VDC service providers. In this paper, we address this problem by developing a novel, optimal "Market-Driven Provisioning and Placement" (MDPP) scheme that is based upon distributed optimization principles. The MDPP scheme channelizes inherent distributed nature of the resource allocation problem by capturing VD resource bids via a virtual market to explore soft spots in the problem space, and consequently defragments a VDC through cost-aware utility-maximal VD re-allocations or migrations. Through extensive simulations of VD request allocations to multiple data centers for diverse VD application and user QoE profiles, we demonstrate that our MDPP scheme outperforms existing schemes that are largely based on centralized optimization principles. Moreover, MDPP scheme can achieve high VDC performance and scalability, measurable in terms of a 'Net Utility' metric, even when VD resource location constraints are imposed to meet orthogonal security objectives.
Prasad Calyam, Sripriya Seetharam, Baisravan HomChaudhuri, Manish Kumar 0006
IC2E1
2015 LIDAR-based virtual environment study for disaster response scenarios
abstract
In the event of natural or man-made disasters, many videos may be collected by civilians and surveillance cameras that can be extremely useful for first responders trying to ascertain the extent of the damage. However, watching and analyzing numerous videos on separate screens can be a cumbersome task. Registering a set of 2D videos with a 3D model can provide an intuitive venue for viewing multiple videos simultaneously. In such a setup, it is likely that the user will want to work with the dynamic 3D environment from a remote location, requiring that videos be transferred over a network to be registered with a 3D model. In this paper, we propose combining the fields of computer vision, cloud computing, and high-speed networking to create a system that takes in HD videos, streams the data to a server where a dynamic 3D model is constructed, and provides a virtual scene navigation program for viewing the videos in a 3D scene from a mobile device. We test transferring the data of interest over different types of networks and processing the videos on various server configurations to determine the capabilities of such a system and the necessary requirements for it to provide a high-quality user experience.
Giang Bui, Prasad Calyam, Brittany Morago, Ronny Bazan Antequera, Ye Duan
IM2
2015 Benchmarking in virtual desktops for end-to-end performance traceability
abstract
There are proven benefits in terms of cost and convenience in delivering thin-client based virtual desktops, versus the use of traditional physical computers for end-user computing purposes. In this paper, we present novel extensions in terms of user interface and methodology to our previously developed VDBench benchmarking toolkit for virtual desktop environments that uses principles of slow-motion benchmarking. We focus on automation aspects of benchmarking, and describe how we extend the end-to-end performance traceability for different desktop applications such as Internet Explorer, Media Player and Excel Spreadsheets. Our approach prevents invasive modification of thin-client systems, and allows emulation of user behavior with realistic workloads. Our user interface design issues are aimed at managing workflows between the benchmarking client and server, for easy instrumentation and generation of comprehensive performance reports for complex environment setups. In a validation study, we deploy the enhanced VDBench toolkit in a real-world virtual desktop testbed that hosts applications that render 3D visualizations of disaster scenarios for scene understanding and situational awareness. Through the benchmarking results, we show how the toolkit provides user QoE assessments involving reliable video events display under different network health conditions and computation resource configurations.
Prasad Calyam, Ronny Bazan Antequera
IM2
2015 Ontology integration for advanced manufacturing collaboration in cloud platforms
abstract
Advances in the field of cloud computing and networking have led to rapid development and market growth in areas such as online retail, gaming and healthcare. In the field of advanced manufacturing however, the impact has been significantly lesser than expected due to limitations in cloud platforms for fostering community engagement. To address this problem, we study a new cloud-based architecture that provides Platform-asa-Service (PaaS) management capabilities to the manufacturing community for delivering Software-as-a-Service (SaaS) “Apps” to their customers. Our architecture aims at supporting an “App Marketplace” that thrives on agile development, organic collaboration and scalable sales of next generation manufacturing Apps requiring high-performance simulation and modeling. Towards realizing the vision of the above architecture, our paper involves investigation and implementation of an Ontology Service that interoperates with other common web services related to resource brokering and accounting. Our Ontology Service uses principles of mapping and merging to translate a manufacturing App's collaboration requirements to suitable resource specifications on public cloud platforms. Integrated resultant ontology can be queried to provision the required resource parameters such as amount of memory/storage, number of processing units, and network protocol configurations needed for deployment of an App. We validate the effectiveness of our Ontology Service using the Protégé framework in a pilot testbed of a real-world “WheelSim” App in the NSF GENI Cloud platform. Our ontology integration results show benefits to an App developer in terms of: optimal user experience, lower design time and lower cost/simulation.
Shravya Ramisetty, Prasad Calyam, Joe Cecil 0001, Amit Rama Akula, Ronny Bazan Antequera, Raymond E. Leto
IM2
2014 VDC-Analyst: Design and verification of virtual desktop cloud resource allocations
Prasad Calyam, Sudharsan Rajagopalan, Sripriya Seetharam, Arunprasath Selvadhurai, Khaled Salah 0001, Rajiv Ramnath
Comput. Networks1
2013 OnTimeSecure: Secure middleware for federated Network Performance Monitoring
abstract
Multi-domain network monitoring systems based on active measurements are being widely deployed in high-performance computing and other communities that support large-scale data transfers. Security mechanisms such as policy-driven access to related federated Network Performance Monitoring (NPM) services are important to protect measurement resources and data. In this paper, we present a novel, secure middleware framework viz., “OnTimeSecure” that enables `user-to-service' and `service-to-service' authentication, and enforces federated authorization entitlement policies for timely orchestration of NPM services. OnTimeSecure is built using RESTful APIs and features a hierarchical policy-engine that interfaces with a meta-scheduler for prioritization of measurement requests when there is contention of users concurrently attempting to utilize measurement resources. We validate OnTimeSecure in a federated multi-domain NPM infrastructure by performing threat modeling and security risk assessments based on overall attack likelihood and impact factors.
Prasad Calyam, Shweta Kulkarni, Alex Berryman, Kunpeng Zhu, Mukundan Sridharan, Rajiv Ramnath, Gordon Springer
CNSM1
2013 Leveraging OpenFlow for resource placement of virtual desktop cloud applications
Prasad Calyam, Sudharsan Rajagopalan, Arunprasath Selvadhurai, Mohan Saravanan, Aishwarya Venkataraman, Alex Berryman, Rajiv Ramnath
IM1
2011 Utility-directed resource allocation in virtual desktop clouds
Prasad Calyam, Rohit Patali, Alex Berryman, Albert M. Lai, Rajiv Ramnath
Comput. Networks1
2011 Modeling and Detection of Camouflaging Worm
abstract
Active worms pose major security threats to the Internet. This is due to the ability of active worms to propagate in an automated fashion as they continuously compromise computers on the Internet. Active worms evolve during their propagation, and thus, pose great challenges to defend against them. In this paper, we investigate a new class of active worms, referred to as Camouflaging Worm (C-Worm in short). The C-Worm is different from traditional worms because of its ability to intelligently manipulate its scan traffic volume over time. Thereby, the C-Worm camouflages its propagation from existing worm detection systems based on analyzing the propagation traffic generated by worms. We analyze characteristics of the C-Worm and conduct a comprehensive comparison between its traffic and nonworm traffic (background traffic). We observe that these two types of traffic are barely distinguishable in the time domain. However, their distinction is clear in the frequency domain, due to the recurring manipulative nature of the C-Worm. Motivated by our observations, we design a novel spectrum-based scheme to detect the C-Worm. Our scheme uses the Power Spectral Density (PSD) distribution of the scan traffic volume and its corresponding Spectral Flatness Measure (SFM) to distinguish the C-Worm traffic from background traffic. Using a comprehensive set of detection metrics and real-world traces as background traffic, we conduct extensive performance evaluations on our proposed spectrum-based detection scheme. The performance data clearly demonstrates that our scheme can effectively detect the C-Worm propagation. Furthermore, we show the generality of our spectrum-based scheme in effectively detecting not only the C-Worm, but traditional worms as well.
Wei Yu 0002, Xun Wang 0009, Prasad Calyam, Dong Xuan, Wei Zhao 0001
IEEE Trans. Dependable Secur. Comput.3
2010 VDBench: A Benchmarking Toolkit for Thin-Client Based Virtual Desktop Environments
abstract
The recent advances in thin client devices and the push to transition users' desktop delivery to cloud environments will eventually transform how desktop computers are used today. The ability to measure and adapt the performance of virtual desktop environments is a major challenge for ''virtual desktop cloud'' service providers. In this paper, we present the ''VD Bench'' toolkit that uses a novel methodology and related metrics to benchmark thin-client based virtual desktop environments in terms of scalability and reliability. We also describe how we used a VD Bench instance to benchmark the performance of: (a) popular user applications (Spreadsheet Calculator, Internet Browser, Media Player, Interactive Visualization), (b) TCP/UDP based thin client protocols (RDP, RGS, PCoIP), and (c) remote user experience (interactive response times, perceived video quality), under a variety of system load and network health conditions. Our results can help service providers to mitigate over-provisioning in sizing virtual desktop resources, and guesswork in thin client protocol configurations, and thus obtain significant cost savings while simultaneously fostering satisfied customers.
Alex Berryman, Prasad Calyam, Matthew Honigford, Albert M. Lai
CloudCom2
2010 Semantic scheduling of active measurements for meeting network monitoring objectives
abstract
Network control and management techniques (e.g., dynamic path switching, on-demand bandwidth provisioning) rely on active measurements of end-to-end network status. These measurements are needed to meet network monitoring objectives such as: (a) intra-domain/inter-domain paths statuschecking, (b) network weather forecasting, (c) anomaly event detection and (d) fault-diagnosis. In this paper, we present a novel semantic scheduling algorithm based on deterministic and heuristic scheduling principles to handle measurement request loads for meeting network monitoring objectives that aid in resource adaptation decisions. The semantic priorities specified to our scheduling algorithm that are based on user-level and resource-level policies allow preferential treatment of measurement requests that supercede typical scheduling priorities based on periodicity and execution time. We evaluate our semantic scheduling algorithm using metrics such as cycle time and satisfaction ratio for increasing measurement request loads. Our semantic scheduling algorithm and evaluation study findings are vital to deploy and manage large-scale measurement infrastructures used for meeting monitoring objectives in support of nextgeneration applications and networks.
Prasad Calyam, Lakshmi Kumarasamy, Füsun Özgüner
CNSM1
2010 OnTimeDetect: Dynamic Network Anomaly Notification in perfSONAR Deployments
abstract
To monitor and diagnose bottlenecks on network paths used for large-scale data transfers, there is an increasing trend to deploy measurement frameworks such as perfSONAR. These deployments use Web-services to expose vast data archives of current and historic measurements, which can be queried across end-to-end multi-domain network paths. Consequently, there has arisen a need to develop automated techniques and intuitive tools that help analyze these measurements for detecting and notifying prominent network anomalies such as plateaus in both real-time and offline manner. In this paper, we present a dynamically adaptive plateau-detection (APD) scheme and its implementation in our “OnTimeDetect” tool to enable consumers of perfSONAR measurements within the data-intensive scientific communities in overcoming their existing limitations of network anomaly detection and notification. We empirically evaluate our APD scheme in terms of accuracy, agility and scalability by using measurement traces collected by OnTimeDetect tool from worldwide perfSONAR deployments in HPC communities.
Prasad Calyam, Jialu Pu, Weiping Mandrawa, Ashok K. Krishnamurthy 0001
MASCOTS1
2009 A human-and-network aware encoding adaptation scheme for Remote Desktop Access
abstract
Remote desktop access (RDA) applications have become vital for users involved in tasks such as tele-commuting, distance learning, and remote instrumentation. To deliver optimum user quality of experience (QoE), existing RDA applications are "network-aware" i.e., they employ online encoding adaptation that is based on network quality of service (QoS) measurement between the client and server ends. In this paper, we propose and evaluate an online RDA encoding adaptation scheme that is "human-and-network aware" i.e., our novel adaptation considers quality of application (QoA) performance perceived by the user in addition to the network QoS measured by the application. Owing to our offline QoA performance modeling strategy that uses polynomial regression and bootstrap sampling, our scheme does not require input from actual users for the online encoding adaptation. Our performance validation results show that our proposed human-network-aware adaptation outperforms the network-aware adaptation in terms of user QoE for a wide-variety of degraded network QoS conditions.
Prasad Calyam, Abdul Kalash, Ashok K. Krishnamurthy 0001, Gordon Renkes
MMSP1
2009 Resiliency of open-source firewalls against remote discovery of last-matching rules
abstract
In today's networks, firewalls act as the first line of defense against unwanted and malicious traffics. Firewalls themselves can become targets of DoS attacks, thus jeopardizing their primary operation to filter traffic. Typically, packets are checked against a firewall policy consisting (in many cases) of thousands of rules. Last-matching rules are located at the bottom of the ruleset and consume the most CPU processing power of firewalls. If these rules get discovered by an attacker, the attacker can effectively launch a low-rate DoS attack that can bring the firewall to its knees. In prior work [1], we proposed and evaluated a technique to remotely discover the last matching rules of the Linux Netfilter firewall. In this paper, we examine the effectiveness of such technique on the discovery of last-matching rules in two other popular open-source network firewalls, namely Linux IPSets and FreeBSD ipfw.
Khaled Salah 0001, Karim Sattar, Zubair A. Baig, Mohammed H. Sqalli, Prasad Calyam
SIN5
2008 Experiences from Cyberinfrastructure Development for Multi-user Remote Instrumentation
abstract
Computer-controlled scientific instruments such as electron microscopes, spectrometers, and telescopes are expensive to purchase and maintain. Also, they generate large amounts of raw and processed data that has to be annotated and archived. Cyber-enabling these instruments and their data sets using remote instrumentation cyberinfrastructures can improve user convenience and significantly reduce costs. In this paper, we discuss our experiences in gathering technical and policy requirements of remote instrumentation for research and training purposes. Next, we describe the cyberinfrastructure solutions we are developing for supporting related multi-user workflows. Finally, we present our solution-deployment experiences in the form of case studies. The case studies cover both technical issues (bandwidth provisioning, collaboration tools, data management, system security) and policy issues (service level agreements, use policy, usage billing). Our experiences suggest that developing cyberinfrastructures for remote instrumentation requires: (a) understanding and overcoming multi-disciplinary challenges, (b) developing reconfigurable-and-integrated solutions, and (c) close collaborations between instrument labs, infrastructure providers, and application developers.
Prasad Calyam, Abdul Kalash, Neil Ludban, Sowmya Gopalan, Siddharth Samsi, Karen A. Tomko, David E. Hudak, Ashok K. Krishnamurthy 0001
eScience1
2008 Modeling of multi-resolution active network measurement time-series
abstract
Active measurements on network paths provide end-to-end network health status in terms of metrics such as bandwidth, delay, jitter and loss. Hence, they are increasingly being used for various network control and management functions on the Internet. For purposes of network health anomaly detection and forecasting involved in these functions, it is important to accurately model the time-series process of active measurements. In this paper, we describe our time-series analysis of two typical active measurement data sets collected over several months: (i) routine, and (ii) event-laden. Our analysis suggests that active network measurements follow the moving average process. Specifically, they possess ARIMA(0,1,q) model characteristics with low q values, across multi-resolution timescales. We validate our model selection accuracy by comparing how well our predicted values using our model match the actual measurements.
Prasad Calyam, Ananth Devulapalli
LCN1
2008 Assessing readiness of IP networks to support desktop videoconferencing using OPNET
Khaled Salah 0001, Prasad Calyam, Seyed M. Buhari
J. Netw. Comput. Appl.2
2007 Orchestration of Network-Wide Active Measurements for Supporting Distributed Computing Applications
abstract
Recent computing applications such as videoconferencing and grid computing run their tasks on distributed computing resources connected through networks. For such applications, knowledge of the network status such as delay, jitter, and available bandwidth can help them select proper network resources to meet the Quality-of-Service (QoS) requirements. Also, the applications can dynamically change the resource selection if the current selection is found to experience poor performance. For such purposes, Internet Service Providers (ISPs) have started to instrument their networks with Network Measurement Infrastructures (NMIs) that run active measurement tasks periodically and/or on demand. However, one problem that most network engineers have overlooked is the measurement conflict problem, which happens when multiple active measurement tasks inject probing packets into the same network segment at the same time, resulting in misleading reports of network performance due to their combined effects. This paper proposes enhanced Earliest Deadline First (EDF) algorithms that allow "Concurrent Executions" to orchestrate offline/online measurement jobs in a conflict-free manner. The simulation study shows that our measurement scheduling mechanism can improve the schedulable utilization of offline measurement tasks up to 300 percent and the response time of on-demand jobs up to 50 percent. Further, we implement and deploy our scheduling mechanism in a real working NMI for monitoring the Internet2 Abilene network. As a case study, we show the utility of our algorithms in the widely used Network Weather Service (NWS).
Prasad Calyam, Chang-Gun Lee, Eylem Ekici, Mark Haffner, Nathan Howes
IEEE Trans. Computers1
2006 On Detecting Camouflaging Worm
abstract
Active worms pose major security threats to the Internet. In this paper, we investigate a new class of active worms, i.e., camouflaging worm (C-Worm in short). The C-Worm has the capability to intelligently manipulate its scan traffic volume over time, thereby camouflaging its propagation from existing worm detection systems. We analyze characteristics of the C-Worm and conduct a comprehensive comparison between its traffic and non-worm traffic. We observe that these two types of traffic are barely distinguishable in the time domain, however, their distinction is clear in the frequency domain, due to the recurring manipulative nature of the C-Worm. Motivated by our observations, we design a novel spectrum-based scheme to detect the C-Worm. Our scheme uses the power spectral density (PSD) distribution of the scan traffic volume and its corresponding spectral flatness measure (SFM) to distinguish the C-Worm traffic from non-worm traffic. We conduct extensive performance evaluations on our proposed detection scheme against the C-Worm. The performance data clearly demonstrates that our proposed scheme can effectively detect the C-Worm propagation
Wei Yu 0002, Xun Wang 0009, Prasad Calyam, Dong Xuan, Wei Zhao 0001
ACSAC3
2005 Active and passive measurements on campus, regional and national network backbone paths
abstract
It has become a common practice for Internet service providers (ISPs) to instrument their networks with network measurement infrastructures (NMIs). These NMIs support network-wide "active" and "passive" measurement data collection and analysis to: 1) identify end-to-end performance bottlenecks in network paths and 2) broadly understand Internet traffic characteristics, on an ongoing basis. In this paper, we present our analysis of the active and passive measurement data collected along network backbone paths within typical campus, regional and national networks which carry traffic of cutting-edge Internet applications such as high-quality voice and video conferencing, multimedia streaming and distributed file sharing. The active measurement data has been obtained by using "ActiveMon" software, which we have developed and deployed along the above network backbone paths. The passive measurement data has been obtained using SNMP, Syslog and NetFlow data available at the intermediate routers located at strategic points along the same network backbone paths. Our analysis of the measurement data includes studying notable trends, network events and relative performance issues of the network backbone paths which are reflected in the active and passive measurement data collected regularly over several months. Our results thus provide valuable insights regarding traffic dynamics in the different academic network backbones and can be used for better design and control of networks and also to develop traffic source models based on empirical data from real-networks.
Prasad Calyam, Dima Krymskiy, Mukundan Sridharan, Paul Schopis
ICCCN1
2005 Enhanced EDF Scheduling Algorithms for Orchestrating Network-Wide Active Measurements
abstract
Monitoring network status such as end-to-end delay, jitter, and available bandwidth is important to support QoS-sensitive applications and timely detection of network anomalies like denial of service attacks. For this purpose, Internet service providers (ISPs) have started to instrument their networks with network measurement infrastructures (NMIs) that periodically run active measurement tasks using measurement servers located at strategic points in their networks. However, one problem that most network engineers have overlooked is the measurement conflict problem. Since active measurement tasks actively inject test packets to collect measurements along network paths, running multiple active measurements at the same time over the same path could result in misleading reports of network performance. We call this phenomenon a measurement conflict. Our recent observation of such measurement conflict motivates us to form a measurement task scheduling problem of meeting periodicity requirements, where real-time scheduling algorithms can play a role. The scheduling problem, however, is not exactly same as any of the existing scheduling problems in the realtime literature, because the problem involves multiple measurement servers running multiple measurement tasks whose conflict dependency propagates along the chains of paths. For this problem, we propose to use an EDF (earliest deadline first) heuristic but allowing "concurrent executions" if possible, to construct an offline schedule for a given measurement task set. Also, we propose a novel mechanism to flexibly use the offline schedule for minimizing the response time of dynamic on-demand measurement jobs. Further, we implement and deploy our scheduling algorithms in a real working NMI for monitoring Internet 2 Abilene network.
Prasad Calyam, Chang-Gun Lee, Phani Kumar Arava, Dima Krymskiy
RTSS1