Mohammad Shojafar

dblp:06/8812 · DBLP profile ↗
← Back
131ranked-venue papers
11as first author
90since 2021 · last 2026
0000-0003-3284-5086ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 49 · 3 first-author · 37 since 2021Systems, architecture and hardware · 27 · 4 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 26 · 2 first-author · 22 since 2021Security and privacy · 12 · 12 since 2021Artificial intelligence and machine learning · 10 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Digital Twin and AI Driven Multi-Operator Vehicular Networks for Metaverse Applications
Abrar Almazi Bipon, Berna Bulut Cebecioglu, Nasim Dashtifard, Raouf Abozariba, Adel Aneiba, Hamed Ahmadi, Syed Ali Raza Zaidi, Mohammad Shojafar, De Mi
ICC8
2026 GAN-Augmented and LLM-Enhanced Intrusion Detection for Intelligent Vehicles
Elizaveta Andrushkevich, Zahra Pooranian, Chuan Heng Foh, Rocío Pérez de Prado, Fabio Martinelli, Mohammad Shojafar
WCNC6
2026 AI Explainability for Adaptive Mmwave Beam Configuration in Dynamic Vehicular Environments
Ugur Yigit, Ayhan Akbas, Abdulkadir Kose, Chuan Heng Foh, Mohammad Shojafar
WCNC5
2026 PACOB: Priority-aware computation offloading in vehicular edge computing based on multi-armed bandit learning
Sadoon Azizi, Ayub Fatahi, Arash Bozorgchenani, Mohammad Shojafar
Comput. Commun.4
2026 Dynamic and Resource-aware Task Scheduling in Fog-Cloud Environments via an Improved Priority-aware Genetic Algorithm
Rezvan Salimi, Sadoon Azizi, Mohammad Shojafar
J. Grid Comput.3
2026 Service-Oriented Attention HAPPO for xApps Coordination in Digital Twin-Enabled AI-RAN
Zhizhou He, Mohammad Shojafar, Rahim Tafazolli
IEEE Trans. Netw. Serv. Manag.2
2025 A Provably Secure Post-Quantum Based EDHOC Protocol
abstract
Transport Layer Security (TLS) is considered to be the most used standard security protocol for the Internet of Things (IoT). However, as TLS was originally designed for computer networks, it is not optimal with respect to efficiency. Therefore, a new protocol called Object Security for Constrained RESTful Environments (OSCORE) has been standardized for securing constrained devices. Currently, the Ephemeral-Diffie-Hellman-Over-COSE (EDHOC) protocol, which is a key exchange protocol to define a session key used in OSCORE, is also in the process of being standardized. EDHOC consists of four authentication modes, each offering different security strengths and performance. However, these modes are not yet secure against quantum attacks. Since we are in a transition period and do not yet possess deeply analyzed post-quantum algorithms, we propose a generic hybrid protocol. As such, the protocol can easily update from one post-quantum algorithm to the other and becomes secure against either a post-quantum attack or a potential attack against a newly defined post-quantum algorithm. The proposed mode does not require any changes to the original EDHOC protocol and offers perfect backward compatibility. The security is ensured using Real-Or-Random (ROR) logic, and additional performance costs are analyzed using different variants of post-quantum algorithms.
Awaneesh Kumar Yadav, Mohammad Shojafar, An Braeken
CCNC2
2025 Hybrid Telecom Fraud Detection with Machine Learning, Large Language Models, and Blockchain
abstract
This paper presents a first-of-its-kind modular AI framework for telecom fraud detection, integrating machine learning (ML), large language models (LLMs), and blockchain smart contracts to unify statistical classification, semantic reasoning, and decentralized enforcement. A synthetic dataset of 100 users across 300 sessions in Birmingham, UK, simulated telecom usage with$\mathbf{1 \% - 5 \%}$injected fraud, including GPS spoofing, excessive transmission power, and prolonged usage. Seven ML models were trained, with Random Forest optimized using a precision-recall threshold of$\mathbf{0. 7 2 1 7}$. Six configurations varied the decision logic between ML and GPT-4o-based LLMs, with LLMs performing context-aware reasoning via behavioral prompts. Solidity smart contracts on a local Ethereum network enforced decisions, mapping users to blockchain identities with a Proof-of-Stake-style validation mechanism. The ML-only configuration achieved 92.25 % accuracy with perfect user-level precision and recall, while LLM variants enhanced behavioral and temporal reasoning. This framework advances robust and explainable fraud detection for future telecom infrastructures.
Saviz Changizi, Nasibeh Mohammadzadeh, Mohammad Shojafar
HPCC3
2025 Towards Building Robust, Reliable and Private AI/ML Security Solutions in Open Radio Access Networks
abstract
AI/ML utilization in Open RAN plays a crucial role in enhancing the overall network performance, particularly for tasks such as resource and mobility management, quality of service, and security. Integrating AI and ML into the Open RAN framework offers significant improvements in network operations and functionality. However, this integration introduces several security threats, including data poisoning, data reconstruction, and adversarial attacks, which can compromise the integrity and reliability of ML models. To address these challenges and ensure that the final systems use robust, reliable, and private ML models, several techniques can be implemented. These include adversarial training, which helps models become more resilient to malicious inputs, and collaborative learning methodologies like federated learning and split learning, which enhance data privacy by decentralising the training process. By adopting these approaches, it is possible to mitigate ML security vulnerabilities, fostering a more resilient, secure, and trustworthy Open RAN ecosystem.
Sotiris Chatzimiltis, Mohammad Shojafar, Mahdi Boloursaz Mashhadi, Rahim Tafazolli
HPCC2
2025 Towards Transformer-Based Flow Volume Prediction in Network Traffic
abstract
Accurately predicting network flow volume using early packet-level features is critical for real-time applications such as resource allocation, bottleneck prediction, anomaly detection and more. In this paper, we investigate the suitability of Transformer-based architectures for the flow volume regression task. Specifically, we fine-tune two foundation models, NetFound and YaTC, originally pre-trained to learn traffic representations for classification tasks, and adapt them for flow volume regression. Additionally, we train a lightweight Transformer model, and compare the predictive performance and complexity of all Transformer-based models to a simple Multi-Layer Perceptron (MLP) model. Fine-tuning and training are conducted on two public datasets: MAWI and CIC-IDS-2017. Results demonstrate that Transformer-based models significantly outperform the MLP model. The lightweight Transformer achieves the best$\mathrm{R}^{\mathrm{2}}$score of 0.963 on CIC-IDS-2017, while NetFound achieves the best performance on the real-world traffic dataset MAWI with an$\mathrm{R}^{\mathrm{2}}$of 0.812. These findings highlight the effectiveness of Transformers in capturing complex relationships in early packet-level features of network traffic for flow volume regression task.
Samara Mayhoub, Mirko Schiavone, Chuan Heng Foh, Mohammad Shojafar
HPCC4
2025 MF-ESD: A Novel Mean Field Reinforcement Learning Approach for Scalable Edge Server Deployment
abstract
Emerging applications like smart cities necessitate rapid and localized data processing. To meet this critical requirement, the strategic deployment of edge servers within Mobile Edge Computing (MEC) architectures is essential to improve system performance and user experience. However, despite existing methods attempting to address the edge server deployment problem, challenges remain in large-scale deployment scenarios, including low deployment efficiency and reduced service quality. To address these issues, we propose MF-ESD, a novel edge server deployment strategy that leverages Mean Field Reinforcement Learning (MFRL) to optimize the deployment process. Specifically, we first employ an improved Whale Optimization Algorithm (IWOA) with adaptive weights and differential mutation for preprocessing to find a high-quality initial deployment scheme, thereby alleviating the cold-start problem in MFRL. Subsequently, MFRL utilizes the deployment results from IWOA and employs mean field approximation to determine the optimal edge server deployment strategy, which enhances the search efficiency. We validate the proposed method using real-world datasets provided by Shanghai Telecom and compare it against four baseline algorithms: Random, Top-K, Particle Swarm Optimization (PSO), and ESL. The experimental results show that MF-ESD reduces average latency and energy consumption while significantly improving load balancing performance, outperforming the baseline algorithms.
Xia Ou, Zhou Zhou 0001, Taotao Yu, Hongbing Cheng, Mohammad Shojafar
HPCC5
2025 LightChain-RAN-RF: A Lightweight Blockchain-Enabled RFID Framework for O-RAN Edge Environments
abstract
This paper presents the LightChain-RAN-RF, a lightweight blockchain-based architecture designed to enhance the security, privacy, and efficiency of Radio Frequency Identification (RFID) systems operating in Dense Reader Environments (DRE). By combining CSMA-based anti-collision protocols with mutual authentication, encrypted communication, and InterPlanetary File System (IPFS)-backed blockchain storage, the proposed method addresses key challenges such as reader collisions, energy consumption, and vulnerability to attacks like Man-In-The-Middle (MITM) and Sybil. RFID readers act as light blockchain nodes, ensuring secure, scalable interaction across distributed networks. The architecture is fully compatible with Open Radio Access Network (O-RAN) frameworks, allowing RFID readers to function as trusted edge devices in virtualized, Artificial intelligence (AI)-driven mobile infrastructures. Simulation results confirm significant improvements in throughput (almost 60%) and decreases in energy efficiency (almost$\mathbf{1. 4 ~ J}$), demonstrating the system's suitability for modern industrial IoT and mobile network applications.
Hadiseh Rezaei, Mehdi Golsorkhtabaramiri, Rahim Taheri, Chuan Heng Foh, Mohammad Shojafar
HPCC5
2025 Digital Twin-Based Deep Q-Learning Strategy for Smart Handover Optimization in 5G/6G Networks
abstract
Handover management in 5G/6G networks presents significant challenges mainly due to ultradense deployments, high mobility and diversity of scenarios. This work presents a digital twin-based Deep Q-Learning (DQL) strategy to optimize handover processes and resource management in these networks. It is proposed to consider digital twins to support the implementation of real-time network conditions where DQL agents are trained to improve quality of service (QoS) parameters related to throughput. The suggested approach, deployed with the ns-3 mmWave module and ns3-ai framework, shows relevant benefits, including reduced handovers. Moreover, the consideration of digital twins allows adaptive learning and scalability, allowing networks to respond more effectively to dynamic user behavior and environmental modifications. These results underline the potential of combining DQL and digital twins as an efficient solution for smart handover management, and thus, for sustainable and efficient communication in 5G/6G networks.
Carlos Hidalgo-Luque, Rocío Pérez de Prado, Mohammad Shojafar, J. Enrique Muñoz Expósito, Chuan Heng Foh, Ángel Cifuentes
IJCNN3
2025 Mutable Blockchains in IoT-Driven Sustainable Urban Planning: Challenges, and Analytical Modeling
abstract
Sustainable urban planning manages cities to protect the environment and uses resources wisely for the needs of urban daily life. The Internet of Things (IoT) optimizes the usage of resources and the consideration of urban utilities, such as congestion and pollution. Furthermore, Blockchain supports transparent data collection and securely storing data. Immutability is a fundamental feature of Blockchain, which keeps the data unchanged; however, researchers have proposed mutable Blockchains for data modifications by putting away security. This paper studies mutable Blockchains for sustainable IoT urban planning. It aims to discuss the productivity of mutable Blockchain in IoT-driven Sustainable Urban Planning. To this end, it discusses the challenges of mutable blockchains, presents the analytical modeling in practical applications, and examines the security of mutable Blockchains in public and centralized private Blockchains. Our main goal is to discuss their potential and limitations in IoT-based urban planning environments. The analysis shows that mutable Blockchains reduce computational costs but increase security risks. Our study explains the need for carefully governed mutability to support privacy and adaptability in IoT-based urban planning.
Saeed Javanmardi, Marco Scarpa, Mohammad Shojafar, Salvatore Distefano, Giovanni Merlino
SMARTCOMP3
2025 TwinGuard: A Proactive RL-Driven Defence Framework for Digital Twin-Enabled O-RAN Security
abstract
Open and disaggregated O-RAN architectures foster flexibility and vendor diversity in 5G/6G networks but simultaneously expose novel attack surfaces exploitable by sophisticated adversaries. Traditional rule-based or signature-driven detection mechanisms struggle against multi-stage, polymorphic threats in such dynamic environments. This paper proposes TwinGuard, a proactive defence framework that integrates a real-time Digital Twin of a live 5G O-RAN deployment with reinforcement learning (RL) for intelligent threat anticipation and mitigation. Our system mirrors critical KPIs, including throughput, PRB utilisation, SINR, and latency, into the Digital Twin, where an RL agent trained via Proximal Policy Optimisation (PPO) learns optimal mitigation strategies. In our prototype, the RL agent identifies and blocks malicious handover attacks within 100 ms, maintaining service continuity and outperforming a DQN-based baseline. In a second prototype deployed on a containerised OpenAirInterface (OAI) 5G Core and FlexRIC-controlled RAN testbed, our xApp swiftly mitigates an E2 subscription flooding attack in under 100 ms, reducing abnormal PRB utilisation from 95% to nominal levels. TwinGuard demonstrates the feasibility and effectiveness of closed-loop, AI-driven cybersecurity in O-RAN systems, offering a blueprint for future trustworthy and resilient 6G networks.
Liam O'Driscoll, Taneya Sharma, Mohammad Shojafar, Chuan Heng Foh, Ioana Boureanu, Helen Treharne, Sotiris Moschoyiannis
TrustCom4
2025 Secure Communication Protocols and Video Streaming Demonstrations in Open RAN through DTLS and LKH
abstract
Security in 5G high-density networks is vital, especially where large-scale unicast and multicast communication is involved. The ONE4HDD project explores practical and scalable methods for implementing secure communications using TLS, DTLS, and the Logical Key Hierarchy (LKH) for key distribution. This paper consolidates findings and implementations from a sequence of technical deliverables, each tackling specific aspects of secure communication. Simulation-based experiments were conducted using OMNET++ to model multicast security scenarios involving cyber threats such as Man-in-the-Middle (MitM) attacks, replay attacks, sniffing, and spoofed certificates. In parallel, real-world emulation on the Surrey 5GIC testbed validated the effectiveness of TLS/DTLS in secure unicast streaming. The testbed also demonstrated detection of invalid certificates and replay prevention using DTLS sequence numbers. Numerical results highlight that LKH drastically reduces rekeying overhead for multicast communication. For instance, in groups of 1024 and 8192 users, the number of rekey messages was reduced from 1023 and 8191 (flat key) to 19 and 25, respectively, achieving 98.1% and 99.7% overhead reduction. These achievements confirm the scalability and performance of the proposed architecture.
Sudarson Karmaker, Haitham S. Cruickshank, Mohammad Shojafar
TrustCom3
2025 Contrastive Learning for Distortion Tolerable Network Slice Prediction in Open RAN
abstract
Open Radio Access Network (Open RAN) has revolutionized future communications by introducing open interfaces and intelligent network management. Network slicing enables the creation of multiple virtual networks on a single physical infrastructure, providing tailored services for performance, security, and latency. Efficient RAN slice resource allocation requires accurate prediction of the slice loads from the collected reports. However, open interfaces brought by Open RAN have also caused new security challenges. Malicious attackers could modify the data between E2 nodes with Near Real-Time RIC, hence mislead the model for a poor performance. To prevent this attack, we hereby proposed a novel contrastive learning design, which uses data augmentation to grant the model the vulnerability of feature distortion. The contrastive learning model could learn the correlation of original data with distorted data. Meanwhile, the proposed contrastive learning has a greater generalization ability compared to conventional supervised learning, which is suitable for dynamic environments and could adapt to various noise levels. The proposed contrastive learning includes supervised and unsupervised contrastive learning (SCL and UCL). The proposed SCL could achieve 87.1 % out-of-distribution network slice classification accuracy, the proposed UCL could achieve 86.6 %, while the conventional MLP is 82.6 %. Meanwhile, the proposed method only requires 8.4 % of computation during training compared to that of conventional MLP.
Zhizhou He, Hamed Alimohammadi, Sotiris Chatzimiltis, Samara Mayhoub, Mona Akbari, Mohammad Shojafar
WCNC6
2025 FedLLMGuard: A federated large language model for anomaly detection in 5G networks
Hadiseh Rezaei, Rahim Taheri, Mohammad Shojafar
Comput. Networks3
2025 Federated learning-based robust android malware detection: label-flipping attacks and defenses
Mohsen Eslamnejad, Rahim Taheri, Mohammad Shojafar, Mohamed Bahy Bader-El-Den
Neural Comput. Appl.3
2025 GRAF-IDS: graph-based clustering as aggregation for federated intrusion detection system in IoT network
Hadiseh Rezaei, Rahim Taheri, Mohammad Shojafar, Chuan Heng Foh
Neural Comput. Appl.3
2025 Small Fault Sample Adversarial Generation and Diagnosis Method for Vehicular Energy Network
abstract
This paper addresses the challenge of fault analysis in the Vehicular Energy Network (VEN) caused by small fault samples due to transient faults and complex disturbances. The proposed generation and diagnosis networks (GDNs) are developed without necessitating prior knowledge or manual intervention. The approach starts with an encoding and diagnosis network that converts multi-dimensional signals into images through supervised learning. A sample enhancement network, improved with module transfer and a relaxation objective function, is then proposed to increase the reliability of convergence and diversity of features for small fault samples. Additionally, a joint iterative training strategy between these two networks improves diagnostic accuracy and generalization through feature feedback. Performance validation on a semi-physical simulation platform demonstrates that the proposed GDNs achieve a 20% improvement in diagnostic accuracy with small datasets (200 samples) and maintain superior performance as sample volume grows. Thus, the proposed approach offers a potent solution for fault diagnosis in VENs with scarce samples, enhancing the analysis of complex systems. Note to Practitioners—This paper delves into fault diagnosis in the vehicular energy network (VEN) using small samples, employing a data-driven and deep learning model. The proposed method is versatile, suitable for analyzing complex systems with multiple and heterogeneous signals. An end-to-end model, named generation and diagnosis networks (GDNs), is introduced for generating small samples and conducting fault diagnosis without requiring prior knowledge or manual input. This method encodes multiple signals into signal images, which are then processed by a specially designed sample enhancement model, improved through the relaxation objective function and module transfer method. The enhanced samples are utilized for accurate analysis within the encoding and diagnosis networks’ diagnostic unit. The paper also provides a comparison of diagnosis results for reference. This approach enables researchers and engineers to efficiently augment and analyze small samples in practical applications, offering a practical framework for junior and inexperienced analysts. Preliminary experiments conducted using the RT-Lab semi-physical simulation platform suggest the method’s feasibility and effectiveness. Future research will explore the optimization of the model’s topology and parameters for lightweight design.
Yongheng Pang, Dongsheng Yang 0001, Mohammad Shojafar, Shuowei Jin, Mamoun Alazab, Shaohua Wan 0001, Liang Zhao 0004
IEEE Trans Autom. Sci. Eng.3
2025 Guest Editorial: On Advancing Healthcare Informatics With Large Language Models
Saru Kumari, Chien-Ming Chen 0001, Mohammad Shojafar, Muhammad Naveed Aman
IEEE J. Biomed. Health Informatics3
2025 EEGAP: ECC-Based Efficient Group Authentication Protocol for Dynamic Vehicular Platoon
abstract
Vehicular platooning has emerged as a promising paradigm in intelligent transportation, offering significant benefits such as reduced energy consumption, improved road throughput and mitigated traffic congestion. However, the open nature of vehicular communication channels exposes platoons to a wide range of security and privacy threats. Although existing group key-based protocols provide foundational security services, they often incur substantial computation overhead and insufficiently address vehicle privacy, making them unsuitable for dynamic vehicular platoon. Therefore, this paper introduces an efficient group authentication protocol (EEGAP) for dynamic vehicular platoons, which ensures privacy-preserving and secure communication during platoon restructuring operations, such as merging and splitting, by integrating anonymous authentication, fog computing, and group key agreement mechanisms. Leveraging Elliptic Curve Cryptography (ECC) and secret sharing mechanisms, EEGAP enables lightweight yet robust group key negotiation, reducing computation overhead by 7.08% and communication overhead by 6.85% compared to existing schemes. Both formal security proofs and informal analysis confirm that EEGAP satisfies the stringent security requirements of vehicular platoon communication systems.
Hongyuan Cheng, Jingcheng Song, Zahra Pooranian, Fabio Martinelli, Mohammad Shojafar
IEEE Trans. Intell. Transp. Syst.7
2024 An Edge Server Deployment Strategy for Multi-Objective Optimization in the Internet of Vehicles
abstract
This paper proposes an edge server deployment strategy based on multi-agent reinforcement learning (CKM-MAPPO) to address the multi-objective optimization problem in a vehicle networking environment. CKM-MAPPO focuses on optimizing the load balancing among edge servers and minimizing edge servers’ delay and energy consumption. Firstly, the Canopy and K-means algorithms determine the edge server deployment’s number and initial location. Then, we utilize the multi-agent reinforcement learning algorithm to decide the optimal deployment location of the edge server. We performed a series of tests, and the experimental results show that CKM-MAPPO improves load balancing by 26.5% and reduces delay and energy consumption by 12.4% and 17.9%, respectively.
Zhou Zhou 0001, Zahra Pooranian, Mohammad Shojafar, Fabio Martinelli
ISCC3
2024 An Efficient Intrusion Detection Solution for Near-Real-Time Open-RAN
abstract
The rapid adoption of Open Radio Access Network (Open-RAN) architectures has brought unprecedented innovation opportunities in modern telecommunications networks. However, this evolution also introduces novel security challenges, particularly in demanding scenarios where swift decision-making is critical. In this paper, we conduct an in-depth investigation into model poisoning attacks in ensemble learning, highlighting their implications for network security, and provide a detailed demonstration of our proposed Open-RAN Intrusion Detection System (IDS), which is seamlessly incorporated into the security module of the near Real-Time RAN Intelligent Controller (nearRT-RIC). The strategic placement of the IDS within the nearRT-RIC ensures its operation within the demanding 10 ms to 1 second control loop range, enabling nearRT intrusion detection capabilities. Through rigorous evaluation and experimentation, our solution showcases promising results in enhancing network security without compromising performance.
Emmanuel N. Amachaghi, Sulyman Age Abdulkareem, Sotiris Chatzimiltis, Mohammad Shojafar, Chuan Heng Foh
ISCC4
2024 A Reliable Edge Server Deployment Algorithm Based on Spectral Clustering and a Deep Q-network Strategy using Multi-objective Optimization
abstract
Mobile edge computing (MEC) enables real-time processing and reduces core network congestion by bringing computing resources closer to data sources. However, optimizing edge server deployments to minimize latency, energy consumption, and load imbalance remains challenging. We propose the SC-DQN strategy, combining spectral clustering and deep Q-network (DQN) techniques. Spectral clustering analyzes the spatial distribution of base stations, grouping them and identifying cluster centers as initial deployment sites. A deep reinforcement learning environment then enables each edge server (agent) to iteratively optimize deployment, minimizing latency, energy consumption, and load imbalance. Experiments with Shanghai Telecom data demonstrate that SC-DQN improves load balancing by 23.05%, reduces latency by 45.32%, and lowers energy consumption by 9.64%, outperforming traditional methods.
Zhou Zhou 0001, Taotao Yu, Mohammad Shojafar, Xia Ou, Hongbing Cheng
TrustCom3
2024 DCSP: A delay and cost-aware service placement and load distribution algorithm for IoT-based fog networks
Sadoon Azizi, Mohammad Shojafar, Pedram Farzin, Javad Dogani
Comput. Commun.2
2024 A comprehensive survey on cyber deception techniques to improve honeypot performance
abstract
Honeypot technologies are becoming increasingly popular in cybersecurity as they offer valuable insights into adversary behavior with a low rate of false detections. By diverting the attention of potential attackers and siphoning off their resources, honeypots are a powerful tool for protecting critical assets within a network. However, the cybersecurity landscape constantly evolves, and professional attackers are always working to uncover and bypass honeypots. Once an adversary successfully identifies a deception mechanism in place, they may change their tactics, potentially causing significant harm to the network. Maintaining a high level of deception is crucial for honeypots to remain undetectable. This paper explores various deception techniques designed specifically for honeypots to enhance their performance while making them impervious to detection. Previous research has not provided a detailed comparison of these techniques, particularly those tailored to honeynets. Therefore, we categorize the presented techniques into relevant classes, subject them to a comparative analysis, and evaluate their effectiveness in simulation scenarios. We also present a mathematical model that comprehensively represents and compares various honeynet research endeavors. In addition, we provide insightful suggestions that highlight the existing research gaps in this field and offer a roadmap for future expansion. This includes extending deception techniques to emulate vulnerabilities inherent in 5G and software-defined networks, which address the evolving challenges of the cybersecurity landscape. The findings and insights presented in this paper are valuable to honeypot developers and cybersecurity researchers alike, providing a vital resource for advancing the field and fortifying network defenses against ever-evolving threats.
Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Mohammad Shojafar, Chafika Benzaid
Comput. Secur.4
2024 M-RL: A mobility and impersonation-aware IDS for DDoS UDP flooding attacks in IoT-Fog networks
abstract
The Internet of Things (IoT) has recently received a lot of attention from the information and communication technology community. It has turned out to be a crucial development for harnessing the incredible power of wireless media in the real world. The nature of IoT-Fog networks requires the use of defense techniques who are light and mobile-aware. The edge resources in such a distributed environment are open to various safety hazards. DDoS UDP flooding attacks are the most frequent threats to edge resources in IoT-Fog networks. It is crucial for sabotaging fog gateways and can overcome traditional data filtering techniques. This paper introduces M-RL, a lightweight intrusion detection system with mobility awareness that can detect DDoS UDP flooding attacks while taking into account adversarial IoT devices that engage in IP spoofing. To this end, this paper analyzes the malicious behaviors that result in anonymity against Rate Limiting and Received Signal Strength (RSS)-based approaches, combines their advantages, and addresses their vulnerabilities. We test our method in different contexts to achieve that goal, and we find that it may decrease the accuracy of the RL, RSS, and RSS-RL methods to 70%, 48.9%, and 64.3%, respectively. The outcomes demonstrate the proposed approach's resistance to software-based source address forgery, impersonation, and signal modification. It offers more than 99% accuracy and supports node mobility. In this case, the best possible accuracy of the previous methods is 77%.
Saeed Javanmardi, Meysam Ghahramani, Mohammad Shojafar, Mamoun Alazab, Antonio Caruso 0001
Comput. Secur.3
2024 Unveiling vulnerabilities in deep learning-based malware detection: Differential privacy driven adversarial attacks
Rahim Taheri, Mohammad Shojafar, Farzad Arabikhan, Alexander E. Gegov
Comput. Secur.2
2024 Multi-Agent Context Learning Strategy for Interference-Aware Beam Allocation in mmWave Vehicular Communications
abstract
Millimeter wave (mmWave) has been recognized as one of key technologies for 5G and beyond networks due to its potential to enhance channel bandwidth and network capacity. The use of mmWave for various applications including vehicular communications has been extensively discussed. However, applying mmWave to vehicular communications faces challenges of high mobility nodes and narrow coverage along the mmWave beams. Due to high mobility in dense networks, overlapping beams can cause strong interference which leads to performance degradation. As a remedy, beam switching capability in mmWave can be utilized. Then, frequent beam switching and cell change become inevitable to manage interference, which increase computational and signalling complexity. In order to deal with the complexity in interference control, we develop a new strategy called Multi-Agent Context Learning (MACOL), which utilizes Contextual Bandit to manage interference while allocating mmWave beams to serve vehicles in the network. Our approach demonstrates that by leveraging knowledge of neighbouring beam status, the machine learning agent can identify and avoid potential interfering transmissions to other ongoing transmissions. Furthermore, we show that even under heavy traffic loads, our proposed MACOL strategy is able to maintain low interference levels at around 10%.
Abdulkadir Kose, Haeyoung Lee, Chuan Heng Foh, Mohammad Shojafar
IEEE Trans. Intell. Transp. Syst.4
2024 A scalable and flexible platform for service placement in multi-fog and multi-cloud environments
Sadoon Azizi, Pedram Farzin, Mohammad Shojafar, Omer F. Rana
J. Supercomput.3
2024 Deep Reinforcement Learning for Robust VNF Reconfigurations in O-RAN
abstract
Open Radio Access Networks (O-RANs) have revolutionized the telecom ecosystem by bringing intelligence into disaggregated RAN and implementing functionalities as Virtual Network Functions (VNF) through open interfaces. However, dynamic traffic conditions in real-life O-RAN environments may require necessary VNF reconfigurations during run-time, which introduce additional overhead costs and traffic instability. To address this challenge, we propose a multi-objective optimization problem that minimizes VNF computational costs and overhead of periodical reconfigurations simultaneously. Our solution uses constrained combinatorial optimization with deep reinforcement learning, where an agent minimizes a penalized cost function calculated by the proposed optimization problem. The evaluation of our proposed solution demonstrates significant enhancements, achieving up to 76% reduction in VNF reconfiguration overhead, with only a slight increase of up to 23% in computational costs. In addition, when compared to the most robust O-RAN system that doesn’t require VNF reconfigurations, which is Centralized RAN (C-RAN), our solution offers up to 76% savings in bandwidth while showing up to 27% overprovisioning of CPU.
Esmaeil Amiri, Ning Wang 0001, Mohammad Shojafar, Mutasem Q. Hamdan, Chuan Heng Foh, Rahim Tafazolli
IEEE Trans. Netw. Serv. Manag.3
2024 ALIVE: A Latency- and Cost-Aware Hybrid P2P-CDN Framework for Live Video Streaming
abstract
Recent years have witnessed video streaming demands evolve into one of the most popular Internet applications. With the ever-increasing personalized demands for highdefinition and low-latency video streaming services, networkassisted video streaming schemes employing modern networking paradigms have become a promising complementary solution in the HTTP Adaptive Streaming (HAS) context. The emergence of such techniques addresses long-standing challenges of enhancing users’ Quality of Experience (QoE), end-to-end (E2E) latency, as well as network utilization. However, designing a cost-effective, scalable, and flexible network-assisted video streaming architecture that supports the aforementioned requirements for live streaming services is still an open challenge. This article leverages novel networking paradigms, i.e., edge computing and Network Function Virtualization (NFV), and promising video solutions, i.e., HAS, Video Super-Resolution (SR), and Distributed Video Transcoding (TR), to introduce A Latency-and cost-aware hybrId P2P-CDN framework for liVe video strEaming (ALIVE). We first introduce the ALIVE multi-layer architecture and design an action tree that considers all feasible resources (i.e., storage, computation, and bandwidth) provided by peers, edge, and CDN servers for serving peer requests with acceptable latency and quality. We then formulate the problem as a Mixed Integer Linear Programming (MILP) optimization model executed at the edge of the network. To alleviate the optimization model’s high time complexity, we propose a lightweight heuristic, namely, Greedy-Based Algorithm (GBA). Finally, we (i) design and instantiate a large-scale cloud-based testbed including 350 HAS players, (ii) deploy ALIVE on it, and (iii) conduct a series of experiments to evaluate the performance of ALIVE in various scenarios. Experimental results indicate that ALIVE (i) improves the users’ QoE by at least 22%, (ii) decreases incurred cost of the streaming service provider by at least 34%, (iii) shortens clients’ serving latency by at least 40%, (iv) enhances edge server energy consumption by at least 31%, and (v) reduces backhaul bandwidth usage by at least 24% compared to baseline approaches.
Reza Farahani, Ekrem Çetinkaya, Christian Timmerer, Mohammad Shojafar, Mohammed Ghanbari 0001, Hermann Hellwagner
IEEE Trans. Netw. Serv. Manag.4
2024 RESP: A Recursive Clustering Approach for Edge Server Placement in Mobile Edge Computing
abstract
With the rapid advancement of the Internet of Things and 5G networks in smart cities, the inevitable generation of massive amounts of data, commonly known as big data, has introduced increased latency within the traditional cloud computing paradigm. In response to this challenge, Mobile Edge Computing (MEC) has emerged as a viable solution, offloading a portion of mobile device workloads to nearby edge servers equipped with ample computational resources. Despite significant research in MEC systems, optimizing the placement of edge servers in smart cities to enhance network performance has received little attention. In this article, we propose RESP , a novel Recursive clustering technique for Edge Server Placement in MEC environments. RESP operates based on the median of each cluster determined by the number of base transceiver stations, strategically placing edge servers to achieve workload balance and minimize network traffic between them. Our proposed clustering approach substantially improves load balancing compared to existing methods and demonstrates superior performance in handling traffic dynamics. Through experimental evaluation with real-world data from Shanghai Telecom’s base station dataset, our approach outperforms several representative techniques in terms of workload balancing and network traffic optimization. By addressing the ESP problem and introducing an advanced recursive clustering technique, this work makes a substantial contribution to optimizing mobile edge computing networks in smart cities. The proposed algorithm outperforms alternative methodologies, demonstrating a 10% average improvement in optimizing network traffic. Moreover, it achieves a 53% more suitable result in terms of computational load.
Ali Akbar Vali, Sadoon Azizi, Mohammad Shojafar
ACM Trans. Internet Techn.3
2023 A Flexible Service Function Chain Optimisation Scheme Based on Network Topology Clustering
abstract
Service Function Chaining (SFC) is an emerging network technology based on network function virtualisation (NFV), which facilitates in-network data processing during traffic steering. SFC optimisations can be broadly categorised into centralised and distributed solutions, each with advantages and disadvantages. In this paper, we propose a flexible SFC optimisation scheme based on network cluster partitioning, where cluster-based information sharing and decision-making are applied for building optimised SFCs in real-time. Such a scheme can be flexibly adapted based on cluster numbers and sizes. The key challenge is how necessary intra-cluster information is shared across clusters for performance optimisation while retaining privacy and low signalling complexity. According to our simulation experiments based on real network topologies, our proposed solution outperforms the state-of-the-art benchmark by about 20%.
Zili Ning, Ning Wang 0001, Mohammad Shojafar, Rahim Tafazolli
GLOBECOM3
2023 A Heterogenous IoT Attack Detection Through Deep Reinforcement Learning: A Dynamic ML Approach
abstract
This paper presents an innovative Intrusion Detection System (IDS) architecture using Deep Reinforcement Learning (DRL). To accomplish this, we started by analysing the DRL issue for IoT devices, followed by designing intruder attacks using Label Flipping Attack (LFA). We propose an artificial intelligence DRL model to imitate IoT attack detection, along with two defence strategies: Label-based Semi-supervised Defence (LSD) and Clustering-based Semi-supervised Defence (CSD). Finally, we provide the evaluation results of the adaptive attack and defence models on multiple IoT scenarios with the NSL-KDD, IoT-23, and NBaIoT datasets. The research proves that DRL functions effectively with dynamically produced traffic in contrast to existing conventional techniques.
Roshan Baby, Zahra Pooranian, Mohammad Shojafar, Rahim Tafazolli
ICC3
2023 A Distributed Intrusion Detection System for Future Smart Grid Metering Network
abstract
Integrating information and communication technologies into the power generation, transmission and distribution system provides a new concept called Smart Grid (SG). The wide variety of devices connected to the SG communication infrastructure generates heterogeneous data with different Quality of Service (QoS) requirements and communication technologies. An intrusion Detection System (IDS) is a surveillance system monitoring the traffic flow over the network, seeking any abnormal behaviour to detect possible intrusions or attacks against the SG system. Distributed fashion of power and data in SG leads to an increase in the complexity of analysing the QoS and user requirements. Thus, we require a Big Data-aware distributed IDS dealing with the malicious behaviour of the network. Motivated by this, we design a distributed IDS dealing with anomaly big data and impose the proper defence algorithm to alert the SG. This paper proposes a new smart meter (SM) architecture, including a distributed IDS model (SM-IDS). Secondly, we implement SM-IDS using supervised ML algorithms. Finally, a distributed IDS model is introduced using federated learning. Numerical results approve that Neighbourhood Area Network IDS (NAN-IDS) can help decrease smart meters' energy and resource consumption. Thus, SM-IDS achieves an accuracy of 84.31% with a detection rate of 74.69%. Also, NAN-IDS provides an accuracy of 87.40% and a detection rate of 86.73%.
Sotiris Chatzimiltis, Mohammad Shojafar, Rahim Tafazolli
ICC2
2023 SARENA: SFC-Enabled Architecture for Adaptive Video Streaming Applications
abstract
5G and 6G networks are expected to support various novel emerging adaptive video streaming services (e.g., live, VoD, immersive media, and online gaming) with versatile Quality of Experience (QoE) requirements such as high bitrate, low latency, and sufficient reliability. It is widely agreed that these requirements can be satisfied by adopting emerging networking paradigms like Software-Defined Networking (SDN), Network Function Virtualization (NFV), and edge computing. Previous studies have leveraged these paradigms to present network-assisted video streaming frameworks, but mostly in isolation without devising chains of Virtualized Network Functions (VNFs) that consider the QoE requirements of various types of Multime-dia Services (MS). To bridge the aforementioned gaps, we first introduce a set of multimedia VNFs at the edge of an SDN-enabled network, form diverse Service Function Chains (SFCs) based on the QoE requirements of different MS services. We then propose SARENA, an _S_FC-enabled ArchitectuRe for adaptive VidEo StreamiNg Applications. Next, we formulate the problem as a central scheduling optimization model executed at the SDN controller. We also present a lightweight heuristic solution consisting of two phases that run on the SDN controller and edge servers to alleviate the time complexity of the optimization model in large-scale scenarios. Finally, we design a large-scale cloud-based testbed including 250 HTTP Adaptive Streaming (HAS) players requesting two popular MS applications (i.e., live and VoD), conduct various experiments, and compare its effectiveness with baseline systems. Experimental results illustrate that SARENA outperforms baseline schemes in terms of users' QoE by at least 39.6%, latency by 29.3%, and network utilization by 30% in both MS services.
Reza Farahani, Abdelhak Bentaleb, Christian Timmerer, Mohammad Shojafar, Radu Prodan, Hermann Hellwagner
ICC4
2023 A reliable edge server placement strategy based on DDPG in the Internet of Vehicles
abstract
In the Internet of Vehicles, low service delay and fast response are two essential factors to ensure the safety and smooth operation of vehicle networking. As core technologies, the 5G and edge computing networks play a fundamental role in reducing the pressure on the backbone network of vehicle networking and decreasing the service exchange delay. The previous edge server placement strategy can not be directly applied to deploying vehicle networking services, resulting in the degradation of system performance and user quality of experience. To solve the above problem, we propose a reliable edge server deployment algorithm called CFD based on Deep Deterministic Policy Gradient (DDPG). Firstly, the Canopy algorithm is used to cluster the location information of roadside units, and the initial cluster number is obtained. Then, the fuzzy C clustering algorithm (FCM) is leveraged to remove the "noise" and acquire the roadside units’ initial division and priority matrix. Finally, based on the DDPG algorithm, the optimal division of roadside units is obtained, and the cluster center is utilized as the deployment location of the edge server. Many experiments have been conducted, and the results show that, compared with the benchmark algorithm, the CFD algorithm improves the load balancing degree by 25%.
Zhou Zhou 0001, Yonggui Han, Mohammad Shojafar, Zhongsheng Wang, Jemal H. Abawajy
TrustCom3
2023 Impact of Aggregation Function Randomization against Model Poisoning in Federated Learning
abstract
Federated learning has gained significant attention as a privacy-preserving approach for training machine learning models across decentralized devices. However, this distributed learning paradigm is susceptible to adversarial attacks, particularly model poisoning attacks, where adversaries inject malicious model updates to compromise the integrity of the global model. In this paper, we investigate the impact of randomness on model poisoning attacks in federated networks, where the server employs two aggregation rules, Krum and Trimmed Mean, randomly in each federated round. We present three distinct adversaries: one targeting Krum throughout the entire learning process, another targeting Trimmed Mean entirely, and a third adversary employing a randomized strategy between Krum and Trimmed Mean for each round. Our objective is to evaluate their performance in reducing the overall accuracy of the federated network. We propose novel techniques to craft poisoned models and explore the efficacy of these attacks by exploiting the aggregation rules. We evaluated our proposed methods on Fashion-MNIST dataset. The experiments reveal the robustness of the federated network against the proposed adversarial scenarios, contributing to a better understanding of the vulnerabilities and defenses in federated learning systems.
Seyedsina Nabavirazavi, Rahim Taheri, Mohammad Shojafar, S. Sitharama Iyengar
TrustCom3
2023 RCA-IDS: A Novel Real-time Cloud-based Adversarial IDS for Connected Vehicles
abstract
This paper focuses on the requirement for creating novel frameworks to monitor and identify cyberattacks in Connected Vehicles (CVs). The health of the sensors in CVs becomes crucial when performance predictions and communication-related errors can compromise the resilience of the sensory network. To meet the evolving demands of connected vehicle (CV) systems, Intrusion Detection Systems (IDS) must be regularly updated and tailored as powerful monitoring entities. To equip cloud-tied operators with the ability to comprehend unusual sensor data originating from vehicles at the cloud level, we designed an innovative Real-time Cloud-based Adversarial IDS called RCA-IDS. This system exclusively focuses on detecting and explaining instances of sensor data manipulation caused by poisoning attacks. Two attack mechanisms were created utilizing random-based and silhouette-based clustering methods. Subsequently, two defence mechanisms based on multi-layer neural network-type deep learning were proposed to counter these attacks. The newly introduced RCA-IDS demonstrates a minimum accuracy of 90% in detecting cyberattacks.
Zahra Pooranian, Mohammad Shojafar, Pedram Asef, Harry Lees, Mark Longden
TrustCom2
2023 IRATS: A DRL-based intelligent priority and deadline-aware online resource allocation and task scheduling algorithm in a vehicular fog network
abstract
Cloud computing platforms support the Internet of Vehicles, but the main bottlenecks are high latency and massive data transmission in cloud-based processing. Vehicular fog computing has emerged as a promising paradigm to accommodate the increasing computational needs of vehicles. It provides low latency network services that are most important for latency-sensitive tasks. The dynamic nature of VFC, having vehicles with heterogeneous computing resources, vehicle mobility, and diverse tasks with different priorities are the main challenges in vehicular fog networks. In VFC, vehicles can share their idle compute resources with other task-generating vehicles. So, scheduling the tasks on the idle resources of resource-limited vehicles is very important. Existing solutions use a heuristic approach to solve this issue but lack generalizability and adaptability. In this paper, we describe a PPO-based intelligent, priority and deadline-aware online and distributed resource allocation and task scheduling algorithm, called IRATS, in vehicular fog networks. IRATS formulates the resource allocation problem as a Markov decision process to minimize the waiting time and delay of tasks. For vehicles sharing their idle resources, we design a task scheduler for the orderly execution of received tasks according to their priorities using multi-level queues. We conducted extensive simulations using SUMO, OMNeT++, Veins, and veins-gym to validate the effectiveness of the presented algorithm. The simulation results confirm that the proposed algorithm improves the percentage of in-time completed tasks and decreases the packet loss, waiting time, and end-to-end delay as compared to random, A2C, and DQN algorithms considering the task priority and link duration of vehicles.
Bushra Jamil, Humaira Ijaz, Mohammad Shojafar, Kashif Munir
Ad Hoc Networks3
2023 An SDN perspective IoT-Fog security: A survey
Saeed Javanmardi, Mohammad Shojafar, Reza Mohammadi 0003, Mamoun Alazab, Antonio Caruso 0001
Comput. Networks2
2023 S-FoS: A secure workflow scheduling approach for performance optimization in SDN-based IoT-Fog networks
Saeed Javanmardi, Mohammad Shojafar, Reza Mohammadi 0003, Valerio Persico, Antonio Pescapè
J. Inf. Secur. Appl.2
2023 Utility Maximization for IRS Assisted Wireless Powered Mobile Edge Computing and Caching (WP-MECC) Networks
abstract
This paper exploits an intelligent reflecting surface (IRS) assisted wireless powered mobile edge computing and caching (WP-MECC) network. In particular, an IRS is utilized to reflect energy signals from a power station (PS) to various IoT devices for energy harvesting during uplink wireless energy transfer (WET). These devices collect energy to support their own partially local computing for computational tasks and their offloading capabilities to an access point (AP), with the help of IRS via time or frequency division multiple access (TDMA or FDMA). The AP is equipped with a local cache connected with a MEC server via a backhaul link, which prefetches the data to facilitate edge computing capabilities. The maximization of a utility function is formulated to evaluate the overall network performance, which is defined as the difference between the sum of computational bits (offloading bits and local computing bits) and total backhaul cost. Due to multiple coupled variables, we first design the optimal caching strategy. Then, an auxiliary vector is introduced to coordinate the energy consumption of local computing and offloading, where its optimal solution can be achieved by an exhaustive search. Moreover, we utilize the Lagrange dual method and the Karush-Kuhn-Tucker (KKT) conditions to derive the optimal time scheduling for the TDMA scheme or the optimal bandwidth allocation for the FDMA counterpart in closed form. The IRS phase shifts are iteratively designed by employing the quadratic transformation (QT) and the Riemannian Manifold Optimization (RMO). Finally, simulation results are demonstrated to validate the network utility performance and confirm the advantage of the employment of IRS, the optimal IRS phase shift design and caching strategy, in comparison to the benchmark schemes.
Zheng Chu 0001, Pei Xiao 0001, Mohammad Shojafar, De Mi, Wanming Hao, Jia Shi 0001, Fuhui Zhou
IEEE Trans. Commun.3
2023 IdenMultiSig: Identity-Based Decentralized Multi-Signature in Internet of Things
abstract
Most devices in the Internet of Things (IoT) work on unsafe networks and are constrained by limited computing, power, and storage resources. Since the existing centralized signature schemes cannot address the challenges to security and efficiency in IoT identification, this article proposes IdenMultiSig, a decentralized multi-signature protocol that combines identity-based signature (IBS) with Schnorr scheme under discrete logarithms on elliptic curves. First, to solve the problem of offline or faulty devices under unstable networks, we introduce a novel improvement of the existing Schnorr scheme by introducing a threshold Merkle tree for the verification with only$m$valid signatures among$n$participants ($m$–$n$tree), while hiding the real identity to protect the data security and privacy of IoT nodes. Furthermore, to prevent dishonest or malicious behavior of the private key generator (PKG), a consortium blockchain is innovatively applied to replace the traditional PKG as a decentralized and trusted private key issuer. Finally, the proposed scheme is proven to be unforgeable against forgery signature attacks in the random oracle model (ROM) under the elliptic curve discrete logarithm (ECDL) assumption. Theoretical analysis and experimental results show that our scheme matches or outperforms existing research studies in privacy protection, offline device support, decentralized PKG, and provable security.
Han Liu 0009, Dezhi Han, Mingming Cui, Kuanching Li, Alireza Souri, Mohammad Shojafar
IEEE Trans. Comput. Soc. Syst.6
2023 SCEMA: An SDN-Oriented Cost-Effective Edge-Based MTD Approach
abstract
Protecting large-scale networks, especially Software-Defined Networks (SDNs), against distributed attacks in a cost-effective manner plays a prominent role in cybersecurity. One of the pervasive approaches to plug security holes and prevent vulnerabilities from being exploited is Moving Target Defense (MTD), which can be efficiently implemented in SDN as it needs comprehensive and proactive network monitoring. The critical key in MTD is to shuffle the least number of hosts with an acceptable security impact and keep the shuffling frequency low. In this paper, we have proposed an SDN-oriented Cost-effective Edge-based MTD Approach (SCEMA) to mitigate Distributed Denial of Service (DDoS) attacks at a lower cost by shuffling an optimized set of hosts that have the highest number of connections to the critical servers. These connections are named edges from a graph-theoretical point of view. We have proposed a three-layer mathematical model for the network that can easily calculate the attack cost. We have also designed a system based on SCEMA and simulated it in Mininet. The results show that SCEMA has lower complexity than the previous related MTD field with acceptable performance.
Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Mohammad Shojafar, Bin Yang 0010
IEEE Trans. Inf. Forensics Secur.4
2023 SIEMS: A Secure Intelligent Energy Management System for Industrial IoT Applications
abstract
Microgrids are industrial technologies that can provide energy resources for the Internet of Things (IoT) demands in smart grids. Hybrid microgrids supply quality power to the IoT devices and ensure high resiliency in supply and demand for PV-based grid-tied microgrids. In this system, the usage of predictive energy management systems (EMS) is essential to dispatch power from different resources, while the battery energy storage system (BESS) is feeding the loads. In this article, we deploy a one-day-ahead prediction algorithm using a deep neural network for a fast-response BESS in an intelligent energy management system (I-EMS) that is calledSIEMS. The main role of theSIEMSis to maintain the SOC at high rates based on the one-day-ahead information about solar power, which depends on meteorological conditions. The remaining power is supplied by the main grid for sustained power streaming between BESS and end-users. Considering the usage of information and communication technology components in the microgrids, the main objective of this article is focused on the hybrid microgrid performance under cyber-physical security adversarial attacks. Fast gradient sign, basic iterative, and DeepFool methods, which are investigated for the first time in power systems e.g., smart grid and microgrids, in order to produce perturbation for training data. To secure the microgrid’sSIEMS, we proposetwoDefence algorithms based on defensive distillation and adversarial training strategies for the first time in EMSs. We apply and evaluate these benchmark adversarial attack and Defence methods against the proposed machine learning models to increase the robustness of the models in the system against adversarial attacks.
Pedram Asef, Rahim Taheri, Mohammad Shojafar, Iosif Mporas, Rahim Tafazolli
IEEE Trans. Ind. Informatics3
2023 OPERA: Optional Dimensional Privacy-Preserving Data Aggregation for Smart Healthcare Systems
abstract
Massive multidimensional health data collected from Internet of Things (IoT) devices are driving a new era of smart health, and with it come privacy concerns. Privacy-preserving data aggregation (PDA) is a proven solution providing statistics while hiding raw data. However, existing PDA schemes ignore the willingness of data owners to share, so data owners may refuse to share data. To increase their willingness to contribute data, we propose an OPtional dimEnsional pRivacy-preserving data Aggregation scheme(OPERA)to provide data contributors with options on sharing dimensions while keeping their choices and data private. OPERA uses selection vectors to represent the decisions of users and count participants dimensionally and achieves data privacy and utility based on a multisecret sharing method and symmetric homomorphic cryptography. Analyses show that in OPERA, the probability of adversaries breaching privacy is less than 4.68e-97. Performance evaluations demonstrate that OPERA is outstanding in computation and practical in communication.
Huadong Liu, Tianlong Gu, Mohammad Shojafar, Mamoun Alazab, Yi-Ning Liu 0002
IEEE Trans. Ind. Informatics3
2023 DisBezant: Secure and Robust Federated Learning Against Byzantine Attack in IoT-Enabled MTS
abstract
With the intelligentization of Maritime Transportation System (MTS), Internet of Thing (IoT) and machine learning technologies have been widely used to achieve the intelligent control and routing planning for ships. As an important branch of machine learning, federated learning is the first choice to train an accurate joint model without sharing ships' data directly. However, there are still many unsolved challenges while using federated learning in IoT-enabled MTS, such as the privacy preservation and Byzantine attacks. To surmount the above challenges, a novel mechanism, namely DisBezant, is designed to achieve the secure and Byzantine-robust federated learning in IoT-enabled MTS. Specifically, a credibility-based mechanism is proposed to resist the Byzantine attack in non-iid (not independent and identically distributed) dataset which is usually gathered from heterogeneous ships. The credibility is introduced to measure the trustworthiness of uploaded knowledge from ships and is updated based on their shared information in each epoch. Then, we design an efficient privacy-preserving gradient aggregation protocol based on a secure two-party calculation protocol. With the help of a central server, we can accurately recognise the Byzantine attackers and update the global model parameters privately. Furthermore, we theoretically discussed the privacy preservation and efficiency of DisBezant. To verify the effectiveness of our DisBezant, we evaluate it over three real datasets and the results demonstrate that DisBezant can efficiently and effectively achieve the Byzantine-robust federated learning. Although there are 40% nodes are Byzantine attackers in participants, our DisBezant can still recognise them and ensure the accurate model training.
XinDi Ma, Qi Jiang 0001, Mohammad Shojafar, Mamoun Alazab, Sachin Kumar 0002, Saru Kumari
IEEE Trans. Intell. Transp. Syst.3
2023 Privacy-Aware Multiagent Deep Reinforcement Learning for Task Offloading in VANET
abstract
Offloading task to roadside units (RSUs) provides a promising solution for enhancing the real-time data processing capacity and reducing energy consumption of vehicles in the vehicular ad-hoc network (VANET). Recently, multi-agent deep reinforcement learning (MADRL)-based offloading approaches have been widely used for task offloading in VANET. However, existing MADRL-based approaches suffer from offloading preference inference (OPI) attack, which utilizes the vulnerability in the policy learning process of MADRL to mislead vehicles to offload tasks to malicious RSUs. In this paper, we first formulate a joint optimization of offloading action and transmitting power with the objective of minimizing the system cost, including local and edge costs, under the privacy requirement of protecting offloading preference during offloading policy learning process in VANET. Despite the non-convexity and centralized of this joint optimization problem, we propose a privacy-aware MADRL (PA-MADRL) approach to solve it, which can allow the offload decision of each vehicle to reach the Nash Equilibrium (NE) without leaking offloading preference. The key to resisting the OPI attack is to protect the offloading preference by 1)elaborately constructing the noise based on ($\beta,\Phi $)-differential privacy mechanism and 2) adding it to the action selection and policy updating process of vanilla MADRL. We conduct a detailed theoretical analysis of the convergence and privacy guarantee of the proposed PA-MADRL, and extensive simulations are conducted to demonstrate the effectiveness, privacy-protecting capacity, and cost-efficiency of PA-MADRL approach.
Dawei Wei, Mohammad Shojafar, Saru Kumari, Ning Xi 0002, Jianfeng Ma 0001
IEEE Trans. Intell. Transp. Syst.3
2023 ARARAT: A Collaborative Edge-Assisted Framework for HTTP Adaptive Video Streaming
abstract
With the ever-increasing demands for high-definition and low-latency video streaming applications, network-assisted video streaming schemes have become a promising complementary solution in the HTTP Adaptive Streaming (HAS) context to improve users’ Quality of Experience (QoE) as well as network utilization. Edge computing is considered one of the leading networking paradigms for designing such systems by providing video processing and caching close to the end-users. Despite the wide usage of this technology, designing network-assisted HAS architectures that support low-latency and high-quality video streaming, including edge collaboration is still a challenge. To address these issues, this article leverages the Software-Defined Networking (SDN), Network Function Virtualization (NFV), and edge computing paradigms to proposeAcollaboRative edge-Assisted framewoRk for HTTPAdaptive video sTreaming (ARARAT). Aiming at minimizing HAS clients’ serving time and network cost, besides considering available resources and all possible serving actions, we design a multi-layer architecture and formulate the problem as a centralized optimization model executed by the SDN controller. However, to cope with the high time complexity of the centralized model, we introduce three heuristic approaches that produce near-optimal solutions through efficient collaboration between the SDN controller and edge servers. Finally, we implement theARARATframework, conduct our experiments on a large-scale cloud-based testbed including 250 HAS players, and compare its effectiveness with state-of-the-art systems within comprehensive scenarios. The experimental results illustrate that the proposedARARATmethods (${i}$) improve users’ QoE by at least 47%, (ii) decrease the streaming cost, including bandwidth and computational costs, by at least 47%, and (iii) enhance network utilization, by at least 48% compared to state-of-the-art approaches.
Reza Farahani, Mohammad Shojafar, Christian Timmerer, Farzad Tashtarian, Mohammed Ghanbari 0001, Hermann Hellwagner
IEEE Trans. Netw. Serv. Manag.2
2023 Real-Time Link Verification in Software-Defined Networks
abstract
Software-defined networking (SDN) has been widely adopted in different networks, such as datacenter and service providers. The SDN controller has the entire network view and is responsible for managing it. To obtain such a view of the network, the controller employs link discovery protocols, which are vulnerable to attacks such as link fabrication attacks (LFAs). TopoGuard and TopoGuard + are two major systems detecting LFAs. This paper introduces a link latency attack (LLA) that can bypass the defence mechanism of both systems. LLA can poison the view of the SDN controller from the network topology and causes outages, resulting in poor quality of service (QoS) or quality of experience (QoE). To mitigate this, we develop two machine learning-based defence systems, namely machine learning-based link guard (MLLG) and real-time link verification (RLV), to preserve the required defence for LLA. The MLLG works when the network topology rarely updates, while RLV can support frequent updates. Furthermore, RLV trains itself over a link latency dataset (LLD)– including latency data of fabricated and normal links– that is captured from the ongoing packets in the network. It also implements outlier detection techniques to identify a dynamic threshold for link latency. We test both systems on different scenarios using Mininet and show that they achieve reasonable results compared with current defence algorithms. Specifically, RLV presents the highest detection performance (F1-score) to 70% at less than 0.2% false-positive rate. The system also supports the robustness features when the attack rates vary from 3% to 7% in our simulated network.
Sanaz Soltani, Mohammad Shojafar, Habib Mostafaei, Rahim Tafazolli
IEEE Trans. Netw. Serv. Manag.2
2023 Introduction to the Special Section on Internet of Behavior for Emerging Technologies
abstract
introduction Share on Introduction to the Special Section on Internet of Behavior for Emerging Technologies Authors: Mu-Yen Chen National Cheng Kung University, Taiwan National Cheng Kung University, Taiwan 0000-0002-3945-4363View Profile , Vincenzo Piuri University of Milan, Italy University of Milan, Italy 0000-0003-3178-8198View Profile , Alireza Souri Haliç University, Turkey Haliç University, Turkey 0000-0001-8314-9051View Profile , Mohammad Shojafar University of Surrey, UK University of Surrey, UK 0000-0003-3284-5086View Profile Authors Info & Claims ACM Transactions on Sensor NetworksVolume 19Issue 2Article No.: 23pp 1–3https://doi.org/10.1145/3589021Published:16 May 2023Publication History 0citation21DownloadsMetricsTotal Citations0Total Downloads21Last 12 Months21Last 6 weeks21 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
Mu-Yen Chen, Vincenzo Piuri, Alireza Souri, Mohammad Shojafar
ACM Trans. Sens. Networks4
2022 A Cost-Effective MTD Approach for DDoS Attacks in Software-Defined Networks
abstract
Protecting large-scale networks, especially Software-Defined Networks (SDNs), against distributed attacks in a costeffective manner plays a prominent role in cybersecurity. One of the pervasive approaches to plug security holes and prevent vulnerabilities from being exploited is Moving Target Defense (MTD), which can be efficiently implemented in SDN as it needs comprehensive and proactive network monitoring. The critical key in MTD is to shuffle the least number of hosts with an acceptable security impact and keep the shuffling frequency low. In this paper, we have proposed an SDN-oriented Cost-effective Edge-based MTD Approach (SCEMA) to mitigate Distributed Denial of Service (DDoS) attacks with a lower cost by shuffling an optimized set of hosts have the highest number of connections to the critical servers. These connections are named edges from a graph-theoretical point of view. We have designed a system based on SCEMA and simulated it in Mininet. The results show that SCEMA has lower (52.58%) complexity than the previous related MTD methods with improving the security level by 14.32%.
Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Mohammad Shojafar
GLOBECOM4
2022 CHFL: A Collaborative Hierarchical Federated Intrusion Detection System for Vehicular Networks
abstract
Wireless interfaces, remote control schemes, and increased autonomy have raised the attacks surface of vehicular networks. As powerful monitoring entities, intrusion detection systems (IDS) must be updated and customised to respond to emerging networks' requirements. As server-based monitoring schemes were prone to significant privacy concerns, new privacy constrained learning methods such as federated learning (FL) have received considerable attention in designing IDS. However, to alleviate the efficiency and enhance the scalability of the original FL, this paper proposes a novel collaborative hierarchical federated IDS, named CHFL for the vehicular network. In the CHFL model, a group of vehicles assisted by vehicle-to-everything (V2X) communication technologies can exchange intrusion detection information collaboratively in a private format. Each group nominates a leader, and the leading vehicle serves as the intermediate in the second level detection system of the hierarchical federated model. The leader communicates directly with the server to transmit and receive model updates of its nearby end vehicles. By reducing the number of direct communications to the server, our proposed system reduces network uplink traffic and queuing-processing latency. In addition, CHFL improved the prediction loss and the accuracy of the whole system. We are achieving an accuracy of 99.10% compared with 97.01 % accuracy of the original FL.
Parya Haji Mirzaee, Mohammad Shojafar, Haitham S. Cruickshank, Rahim Tafazolli
ISCC2
2022 Optimizing Virtual Network Function Splitting in Open-RAN Environments
abstract
Open radio access network (Open-RAN) is becoming a key component of cellular networks, and therefore optimizing its architecture is vital. The Open-RAN is a distributed architecture that lets the virtualized networking functions be split between Distributed Units (DU) and Centralized Units (CUs); as a result, there is a wide range of design options. We propose an optimization problem to choose the split points. The objective is to balance the load across CUs as well as midhaul links by considering delay requirements. The resulting formulation is an NP-hard problem that is solved with a novel heuristic algorithm. Performance evaluation shows that the gap between optimal and heuristic solutions does not exceed 2%. An in-depth analysis of different centralization levels shows that using multi-CUs could reduce the total bandwidth usage by up to 20%. Moreover, multipath routing can improve the result of load balancing between midhaul links while increasing bandwidth usage.
Esmaeil Amiri, Ning Wang 0001, Mohammad Shojafar, Rahim Tafazolli
LCN3
2022 A multi-queue priority-based task scheduling algorithm in fog computing environment
abstract
Abstract Fog computing is a novel, decentralized and heterogeneous computing environment that extends the traditional cloud computing systems by facilitating task processing near end‐users on computing resources called fog nodes. These diverse and resource‐constrained fog devices process a large volume of tasks generated by various fog applications. These tasks are generated by various applications, some of which may be latency‐sensitive, while others may tolerate some degree of delay in their normal functions. Task scheduling determines when a task should be allocated to a computing resource and how long that task can occupy the assigned resource. The majority of task scheduling algorithms focus on prioritizing the latency‐sensitive tasks only, which results in the long waiting time for the other type of tasks. Hence, these priority‐based schedulers cause task starvation for less important tasks while achieving delay‐optimal results for latency‐sensitive tasks. As a result, in this paper, we propose MQP, a multi‐queue priority‐based preemptive task scheduling approach that achieves a balanced task allocation for those applications that can tolerate a certain amount of processing delay and the latency‐sensitive fog applications. At run‐time, the MQP algorithm categorizes tasks as short and long based on their burst time. MQP algorithm maintains a separate task queue for each task category and dynamically updates the time slot value for preemption. The proposed technique's major purpose is to reduce response time for those data‐intensive applications in the fog computing environment, which include both latency‐sensitive tasks and tasks which are less latency‐sensitive, thereby addressing the starvation problem for less latency‐sensitive tasks. A smart traffic management case study is created to model a scenario with both latency‐sensitive short and less latency‐sensitive long tasks. We implement the MQP algorithm using iFogSim and confirm that it reduces the service latencies for long tasks. Simulation results show that the MQP algorithm allocates tasks to a fog device more efficiently and reduces the service latencies for long tasks. The average value of percentage reduction in the latency across all experimental configurations achieved is 22.68% and 38.45% in comparison to First Come‐First Serve and shortest job first algorithms.
Muhammad Fahad 0012, Mohammad Shojafar, Mubashir Abbas, Israr Ahmed, Humaira Ijaz
Concurr. Comput. Pract. Exp.2
2022 Cryptanalysis of a Honeyword System in the IoT Platform
abstract
Password is one of the most well-known authentication methods in accessing many Internet of Things (IoT) devices. The usage of passwords, however, inherits several drawbacks and emerging vulnerabilities in the IoT platform. However, many solutions have been proposed to tackle these limitations. Most of these defense strategies suffer from a lack of computational power and memory capacity and do not have immediate cover in the IoT platform. Motivated by this consideration, the goal of this article is fivefold. First, we analyze the feasibility of implementing a honeyword-based defense strategy to prevent the latest developed server-side threat on the IoT domain’s password. Second, we perform thorough cryptanalysis of a recently developed honeyword-based method to evaluate its advancement in preventing the threat and explore the best possible way to incorporate it in the IoT platform. Third, we verify that we can add a honeyword-based solution to the IoT infrastructure by ensuring specific guidelines. Fourth, we propose a generic attack model, namely,matching attackutilizing the compromised password file to perform the security check of any legacy-UI approach for meeting the all essential flatness security criterion. Last, we compare the matching attack’s performance with the corresponding one of a benchmark technological methods over the legacy-UI model and confirm that our attack has 5%–22% more vulnerable than others.
Nilesh Chakraborty, Mithun Mukherjee 0001, Jianqiang Li 0001, Mohammad Shojafar, Yi Pan 0001
IEEE Internet Things J.4
2022 Intelligent-Reflecting-Surface-Empowered Wireless-Powered Caching Networks
abstract
In this article, we propose an intelligent reflecting surface (IRS)-enabled wireless-powered caching system. In the proposed IRS model, a power station (PS) provides wireless energy to multiple Internet of Things (IoT) devices, delivering their information to an access point (AP) by utilizing the harvested power. The AP, equipped with a local cache, stores the IoT data to avoid waking up the IoT devices frequently. Meanwhile, we deploy the IRS involving in the wireless energy and information transfer process for performance enhancements. In this practical system, the PS and AP could belong to different service providers. Also, the AP requires to incentivize the PS to offer a provisional energy service. We model the interaction between the PS and AP as a Stackelberg game that jointly optimizes the transmit power of the PS, the energy price, the phase shifts of the wireless energy transfer (WET) and wireless information transfer (WIT) phases, as well as wireless caching strategies of the AP. In this way, we first derive the optimal solutions of the phase shifts and the transmit power of the PS in a closed form. We propose an alternating optimization (AO) algorithm to optimize the wireless caching strategies and the energy price iteratively. Finally, we present various numerical evaluations to validate the beneficial role of the IRS and the wireless caching strategies and the performance of the proposed scheme compared with the existing benchmark schemes.
Zheng Chu 0001, Pei Xiao 0001, Mohammad Shojafar, De Mi, Wanming Hao, Jia Shi 0001, Jie Zhong 0001
IEEE Internet Things J.3
2022 Deadline-aware and energy-efficient IoT task scheduling in fog computing systems: A semi-greedy approach
Sadoon Azizi, Mohammad Shojafar, Jemal H. Abawajy, Rajkumar Buyya
J. Netw. Comput. Appl.2
2022 An authentication and key agreement scheme for smart grid
Masoumeh Safkhani, Saru Kumari, Mohammad Shojafar, Sachin Kumar 0002
Peer-to-Peer Netw. Appl.3
2022 SAKE*: A Symmetric Authenticated Key Exchange Protocol With Perfect Forward Secrecy for Industrial Internet of Things
abstract
Security in the Industrial Internet of Things (IIoT) is vital as there are some cases where IIoT devices collect sensory information for crucial social production and life. Thus, designing secure and efficient communication channels is always a research hotspot. However, end devices have memory, computation, and power-supplying capacities limitations. Moreover, perfect forward secrecy (PFS), which means that long-term key exposure still discloses previous session keys, is a critical security property for authentication and key exchange (AKE). This article proposes an AKE protocol named SAKE* for the IIoT environment, where two types of keys (i.e., a master key and an evolution key) guarantee PFS. In addition, the SAKE* protocol merely uses concatenation, XOR, and hash-function operations to achieve lightweight authentication, key exchange, and message integrity. We also compare the SAKE* protocol with seven current and IoT-related authentication protocols regarding security properties and performance. Comparison results indicate that the SAKE* protocol consumes the least computation resource and third-least communication cost among eight AKE protocols while equipping 12 security properties.
Jianhua Chen 0002, Mohammad Shojafar, Saru Kumari, Debiao He
IEEE Trans. Ind. Informatics3
2022 Guest Editorial: Security and Privacy of Federated Learning Solutions for Industrial IoT Applications
abstract
The Industrial Internet of Things (IoT) typically consists of several thousands of heterogeneous devices, such as sensors, actuators, access points, machinery, end-users' handheld equipment, and supply chain. In such an industrial environment, a multitude of data is generated from massive IoT devices, e.g., sensors for monitoring the environment, reading temperature, and gauging pressure. Most of the data are from delay-sensitive and computation-intensive applications, such as real-time manufacturing and automated diagnostics, which require big data analytics with low latency. Machine learning (ML) has been witnessed as an efficient solution for big data analytics. The majority of such ML algorithms are centralized methods, meaning that they first gather data from different users for use as a training dataset, which is placed on the ML server, and then build a model to classify the new data samples by applying the ML algorithms to this training dataset. However, the access to these datasets in the centralized ML methods raises concerns about data privacy for users. Federated learning (FL) was designed to protect data privacy to address a part of these issues. In FL, each participant uses a global training model without uploading their private data to a third-party server. Compared with the conventional ML, FL can preserve data security, especially in terms of participant data during the learning process. In particular, FL can also help in updating server-side data for the global model, and the participant is not required to provide their data. However, in FL, individual computing units may show abnormal actions, such as faulty software, hardware invasions, unreliable communication channels, and malicious samples deliberately crafting the model. To mitigate these challenges, we require robust policies to control the learning phases in FL. Motivated by the abovementioned issues, this special section solicits original research and practical contributions that advance the security and privacy of the FL solutions for industrial IoT applications as follows.
Mohammad Shojafar, Mithun Mukherjee 0001, Vincenzo Piuri, Jemal H. Abawajy
IEEE Trans. Ind. Informatics1
2022 Forward Privacy Preservation in IoT-Enabled Healthcare Systems
abstract
In recent years, Internet of Things (IoT)-enabled health monitoring wearable devices have become a trend in healthcare systems, regularly collecting vital sign data from patients and uploading them to the cloud. Through on-demand search queries, data are shared with third-party healthcare service providers to monitor patients' health status and provide timely diagnoses. To ensure privacy and security, patient health data should be encrypted before being uploaded to the cloud. The cloud can give search encryption services. However, current searchable encryption (SE) technologies still have problems with forward privacy security and verifiability. This article proposes an IoT-cloud-enabled healthcare data system incorporating a SE method with forward privacy and verifiability. By designing a trapdoor permutation function, we render the resulting output indistinguishable from meaningless random data to the adversary. Thus, the adversary cannot judge the relationship between a newly inserted record and a past search token, and therefore, the system realizes forward privacy or forward secrecy. We propose a multikeyword search verification mechanism based on a pseudo-random function. Our approach solves verifying the correctness of search results in the top-k search scenario with partial search results.Aformal security analysis proves that our scheme achieves forward privacy preservation, which can help guarantee healthcare data privacy. Additionally, a performance evaluation shows that our method is efficient and effective, providing an information security system to preserve patient privacy in IoT-enabled healthcare systems.
Ke Wang 0068, Chien-Ming Chen 0001, Zhuoyu Tie, Mohammad Shojafar, Sachin Kumar 0002, Saru Kumari
IEEE Trans. Ind. Informatics4
2022 Personalized Privacy-Aware Task Offloading for Edge-Cloud-Assisted Industrial Internet of Things in Automated Manufacturing
abstract
Industrial Internet of Things (IIoT) devices are widely used for monitoring and controlling the process of automated manufacturing. Owing to the limited computing capacity of the IIoT sensors in the production line, the scheduling task in the production line needs to be offloaded to the edge computing server (ECS). To obtain the desired quality of service (QoS) during offloading scheduling tasks, the precise interaction information between the production line and ECSs has to be uploaded to the cloud platform, which poses privacy issues. The existing works mostly assume that all the interaction information, i.e., the offloading decision for the subtask in a scheduling task, has same privacy level, which cannot meet the various privacy requirements of the offloading decision for the subtask. Hence, we propose a local-differential-privacy-based deep reinforcement learning (LDP-DRL) approach in the edge-cloud-assisted IIoT to provide personalized privacy guarantee. The LDP mechanism can generate different levels of noise to satisfy the various privacy requirements of the offloading decision for the subtask. The prioritized experience replay is integrated in DRL to reduce the impact of noise on the QoS performance of task offloading. The formal analysis of LDP-DRL is provided in terms of privacy level and convergence. Finally, extensive experiments are conducted to evaluate the effectiveness, the capacity of privacy protection, the impact of discount factor on the convergence, and the cost efficiency of the LDP-DRL approach.
Dawei Wei, Ning Xi 0002, XinDi Ma, Mohammad Shojafar, Saru Kumari, Jianfeng Ma 0001
IEEE Trans. Ind. Informatics4
2022 DEHM: An Improved Differential Evolution Algorithm Using Hierarchical Multistrategy in a Cybertwin 6G Network
abstract
Differential evolution (DE) algorithm can be used in edge/cloud cyberspace to find an optimal solution due to its effectiveness and robustness. With the rapid increase of the mobile traffic data and resources in a cybertwin-driven 6G network, the DE algorithm faces some problems such as premature convergence and search stagnation. To deal with the problems mentioned above, in this article, an improved DE algorithm based on hierarchical multistrategy in a cybertwin-driven 6G network (denoted by DEHM) is proposed. Based on the fitness value of the population, DEHM classifies the population into three sub-population. Regarding each sub-population, DEHM adopts different mutation strategies to achieve a tradeoff between convergence speed and population diversity. In addition, a new selection strategy is presented to ensure that the potential individual with good genes is not lost. Experimental results suggest that the DEHM algorithm surpasses other benchmark algorithms in the field of convergence speed and accuracy. The proposed DEHM is expected to be leveraged in edge/cloud cyberspace, aiming at reducing energy costs and improving resource utilization.
Zhou Zhou 0001, Jemal H. Abawajy, Mohammad Shojafar, Morshed U. Chowdhury
IEEE Trans. Ind. Informatics3
2022 IECL: An Intelligent Energy Consumption Model for Cloud Manufacturing
abstract
The high computational capability provided by a data center makes it possible to solve complex manufacturing issues and carry out large-scale collaborative cloud manufacturing. Accurately, real-time estimation of the power required by a data center can help resource providers predict the total power consumption and improve resource utilization. To enhance the accuracy of server power models, we propose a real-time energy consumption prediction method called IECL that combines the support vector machine, random forest, and grid search algorithms. The random forest algorithm is used to screen the input parameters of the model, while the grid search method is used to optimize the hyperparameters. The error confidence interval is also leveraged to describe the uncertainty in the energy consumption by the server. Our experimental results suggest that the average absolute error for different workloads is less than 1.4% with benchmark models.
Zhou Zhou 0001, Mohammad Shojafar, Mamoun Alazab, Fangmin Li
IEEE Trans. Ind. Informatics2
2022 PPVF: Privacy-Preserving Protocol for Vehicle Feedback in Cloud-Assisted VANET
abstract
The vehicular ad hoc network (VANET) is a platform for exchanging information between vehicles and everything to enhance driver’s driving experience and improve traffic conditions. The reputation system plays an essential role in judging whether to communicate with the target vehicle based on other vehicles’ feedback. However, existing reputation systems ignore the privacy protection of feedback providers. Additionally, traditional VANET based on wireless sensor networks (WSNs) has limited power, storage, and processing capabilities, which cannot meet the real-world demands in a practical VANET deployment. Thus, we attempt to integrate cloud computing with VANET and proposes a privacy-preserving protocol of vehicle feedback (PPVF) for cloud-assisted VANET. In cloud-assisted VANET, we integrate homomorphic encryption and data aggregation technology to design the scheme PPVF, in which with the assistance of the roadside units (RSU), cloud service provider (CSP) obtains the total number of vehicles with the corresponding parameters in the feedback for reputation calculation without violating individual feedback privacy. Simulation results and security analysis confirm that PPVF achieves effective privacy protection for vehicle feedback with acceptable computational and communication burden. Besides, the RSU is capable of handling 1999 messages for every$300ms$, so as the number of vehicles in the communication domain increases, the PPVF has a lower message loss rate.
Hongyuan Cheng, Mohammad Shojafar, Mamoun Alazab, Rahim Tafazolli, Yi-Ning Liu 0002
IEEE Trans. Intell. Transp. Syst.2
2022 AFFIRM: Provably Forward Privacy for Searchable Encryption in Cooperative Intelligent Transportation System
abstract
With the construction of intelligent transportation, big data with heterogeneous, multi-source and massive characteristics has become an important carrier of cooperative intelligent transportation systems (C-ITS) and plays an important role. Big data in C-ITS can break through the restrictions between regions and entities and then learning cooperatively by sharing data. In addition, the combined efficiency and information integration advantages of big data are conducive to the construction of a comprehensive and three-dimensional traffic information system and can enhance traffic prediction. However, such substantial sensitive data, mainly on the cloud infrastructure, exposes several vulnerabilities like data leakages and privacy breaks, especially when data is shared for cooperative learning purposes. To address this, this paper proposes a forward privacy-preserving scheme, named AFFIRM, for multi-party encrypted sample alignment adopting cooperative learning in C-ITS. By introducing the searchable encryption method, we realize the sample alignment of cooperative learning in the multi-party encrypted data space. AFFIRM ensures encrypted sample alignment under the condition of forward privacy security. We have formally proved that the proposed scheme satisfies both forward security and validity. We have assessed AFFIRM by validating the potential threat of malicious tampering by privacy attackers and malicious personnel search for the aligned sample data and verify it. Finally, we numerically tested and compared AFFIRM against the corresponding ones of some state-of-the-art schemes under various record sizes, servers and processing.
Ke Wang 0068, Chien-Ming Chen 0001, Mohammad Shojafar, Zhuoyu Tie, Mamoun Alazab, Saru Kumari
IEEE Trans. Intell. Transp. Syst.3
2022 Privacy-Preserving Distributed Multi-Task Learning against Inference Attack in Cloud Computing
abstract
Because of the powerful computing and storage capability in cloud computing, machine learning as a service (MLaaS) has recently been valued by the organizations for machine learning training over some related representative datasets. When these datasets are collected from different organizations and have different distributions, multi-task learning (MTL) is usually used to improve the generalization performance by scheduling the related training tasks into the virtual machines in MLaaS and transferring the related knowledge between those tasks. However, because of concerns about privacy breaches (e.g., property inference attack and model inverse attack), organizations cannot directly outsource their training data to MLaaS or share their extracted knowledge in plaintext, especially the organizations in sensitive domains. In this article, we propose a novel privacy-preserving mechanism for distributed MTL, namely NOInfer, to allow several task nodes to train the model locally and transfer their shared knowledge privately. Specifically, we construct a single-server architecture to achieve the private MTL, which protects task nodes’ local data even if n-1 out of n nodes colluded. Then, a new protocol for the Alternating Direction Method of Multipliers (ADMM) is designed to perform the privacy-preserving model training, which resists the inference attack through the intermediate results and ensures that the training efficiency is independent of the number of training samples. When releasing the trained model, we also design a differentially private model releasing mechanism to resist the membership inference attack. Furthermore, we analyze the privacy preservation and efficiency of NOInfer in theory. Finally, we evaluate our NOInfer over two testing datasets and evaluation results demonstrate that NOInfer efficiently and effectively achieves the distributed MTL.
XinDi Ma, Jianfeng Ma 0001, Saru Kumari, Fushan Wei, Mohammad Shojafar, Mamoun Alazab
ACM Trans. Internet Techn.5
2022 SETTI: A Self-supervised AdvErsarial Malware DeTection ArchiTecture in an IoT Environment
abstract
In recent years, malware detection has become an active research topic in the area of Internet of Things (IoT) security. The principle is to exploit knowledge from large quantities of continuously generated malware. Existing algorithms practise available malware features for IoT devices and lack real-time prediction behaviours. More research is thus required on malware detection to cope with real-time misclassification of the input IoT data. Motivated by this, in this article, we propose an adversarial self-supervised architecture for detecting malware in IoT networks, SETTI, considering samples of IoT network traffic that may not be labeled. In the SETTI architecture, we design three self-supervised attack techniques, namely, Self-MDS , GSelf-MDS, and ASelf-MDS . The Self-MDS method considers the IoT input data and the adversarial sample generation in real-time. The GSelf-MDS builds a generative adversarial network model to generate adversarial samples in the self-supervised structure. Finally, ASelf-MDS utilises three well-known perturbation sample techniques to develop adversarial malware and inject it over the self-supervised architecture. Also, we apply a defence method to mitigate these attacks, namely, adversarial self-supervised training, to protect the malware detection architecture against injecting the malicious samples. To validate the attack and defence algorithms, we conduct experiments on two recent IoT datasets: IoT23 and NBIoT. Comparison of the results shows that in the IoT23 dataset, the Self-MDS method has the most damaging consequences from the attacker’s point of view by reducing the accuracy rate from 98% to 74%. In the NBIoT dataset, the ASelf-MDS method is the most devastating algorithm that can plunge the accuracy rate from 98% to 77%.
Marjan Golmaryami, Rahim Taheri, Zahra Pooranian, Mohammad Shojafar, Pei Xiao 0001
ACM Trans. Multim. Comput. Commun. Appl.4
2022 An Adaptive Energy-Aware Stochastic Task Execution Algorithm in Virtualized Networked Datacenters
abstract
Virtualized networked datacenters (VNDCs) are gaining considerable attention for stochastic task execution under real-time constraints. However, the problem of efficiently minimizing the high energy consumption while ensuring high quality of service (QoS) in VNDCs has not been fully addressed. Although many solutions have been proposed to address this challenge, they are not efficient and only consider one or two of the energy consuming resources of VNDCs. To this end, an adaptive energy-aware algorithm,MCEC, that efficiently reduces the energy consumption of VNDCs while ensuring high QoS is proposed. Different from the existing approaches, the MCEC algorithm considers energy consumed by computing resources, virtual machine (VM) reconfiguration, communication resources and storage media resources while meeting user QoS requirements defined in the service level agreement (SLA). To validate the effectiveness of our algorithm, we carried out extensive experiments and compared the performance of our algorithm with existing baseline algorithms. The results of the experiments show that our algorithm substantially outperforms the baseline algorithms with respect to reducing energy consumption while respecting the service level agreement.
Zhou Zhou 0001, Kenli Li 0001, Jemal H. Abawajy, Mohammad Shojafar, Morshed U. Chowdhury, Fangmin Li, Keqin Li 0001
IEEE Trans. Sustain. Comput.4
2021 Link Latency Attack in Software-Defined Networks
abstract
Software-Defined Networking (SDN) has found applications in different domains, including wired- and wireless networks. The SDN controller has a global view of the network topology, which is vulnerable to topology poisoning attacks, e.g., link fabrication and host-location hijacking. The adversaries can leverage these attacks to monitor the flows or drop them. However, current defence systems such as TopoGuard and TopoGuard+ can detect such attacks. In this paper, we introduce the Link Latency Attack (LLA) that can successfully bypass the systems' defence mechanisms above. In LLA, the adversary can add a fake link into the network and corrupt the controller's view from the network topology. This can be accomplished by compromising the end hosts without the need to attack the SDN-enabled switches. We develop a Machine Learning-based Link Guard (MLLG) system to provide the required defence for LLA. We test the performance of our system using an emulated network on Mininet, and the obtained results show an accuracy of 98.22% in detecting the attack. Interestingly, MLLG improves 16% the accuracy of TopoGuard+.
Sanaz Soltani, Mohammad Shojafar, Habib Mostafaei, Zahra Pooranian, Rahim Tafazolli
CNSM2
2021 FIDS: A Federated Intrusion Detection System for 5G Smart Metering Network
abstract
In a critical infrastructure such as Smart Grid (SG), providing security of the system and privacy of consumers are significant challenges to be considered. The SG developers adopt Machine Learning (ML) algorithms within the Intrusion Detection System (IDS) to monitor traffic data and network performance. This visibility safeguards the SG from possible intrusions or attacks that may trigger the system. However, it requires access to residents’ consumption information which is a severe threat to their privacy. In this paper, we present a novel method to detect abnormalities on a large scale SG while preserving the privacy of users. We design a Federated IDS (FIDS) architecture using Federated Learning (FL) in a 5G environment for the SG metering network. In this way, we design Federated Deep Neural Network (FDNN) model that protects customers’ information and provides supervisory management for the whole energy distribution network. Simulation results for a real-time dataset demonstrate the reasonable improvement of the proposed FDNN model compared with the state-of-the-art algorithms. The FDNN achieves approximately 99.5% accuracy, 99.5% precision/recall, and 99.5% f1-score when comparing with classification algorithms.
Parya Haji Mirzaee, Mohammad Shojafar, Zahra Pooranian, Pedram Asef, Haitham S. Cruickshank, Rahim Tafazolli
MSN2
2021 A Two-layer Collaborative Vehicle-Edge Intrusion Detection System for Vehicular Communications
abstract
With increased wireless connectivity and embedded sensors, vehicles are becoming more intelligent, offering Internet access, telematics, and advanced driver assistance systems. Along with all benefits, connectivity to the public network and automotive control systems introduces new threats and security risks to connected and autonomous driving systems. Therefore, it is highly critical to design robust security mechanisms to protect the system from potential attacks and security vulnerabilities. An intrusion detection system (IDS) is a promising solution to detect and identify attacks and malicious behaviour within the network. This paper proposes a two-layer IDS mechanism that exploits machine learning (ML) solutions for collaborative attack detection between an on-vehicle IDS module and a developed IDS platform at a mobile edge computing (MEC) server. The results illustrate that the proposed solution can significantly reduce communication latency and energy consumption up to 80% while maintaining a high level of detection accuracy.
Parya Haji Mirzaee, Mohammad Shojafar, Hamidreza Bagheri, Tsz Hin Chan, Haitham S. Cruickshank, Rahim Tafazolli
VTC Fall2
2021 Foreword: Special Issue on Trends in Artificial Intelligence and Data Analytics for an Ethical and Inclusive Digitalized Society
abstract
Artificial Intelligence (AI) and Data Analytics play a crucial role in building a digitalized society that is ethical and inclusive. AI is a simulation that is trained to learn and mimic human behaviour. These AI algorithms are capable of learning from their mistakes and doing tasks that are comparable to those performed by humans. AI will have a significant impact on our quality of life as it develops. The main aim of any tool and approach is to simplify human effort and aid us in making better decisions. Data Analytics helps in analyzing raw data in order to draw inferences from it. These techniques and processes have been automated in order to deal with raw data, which is intended for human consumption. The combination of both these techniques will help humans to evolve further in field of research and will enhance the decision making process…
Mamoun Alazab, Ameer Al-Nemrat, Mohammad Shojafar, Shahd Al-Janabi
Int. J. Uncertain. Fuzziness Knowl. Based Syst.3
2021 RSS: An Energy-Efficient Approach for Securing IoT Service Protocols Against the DoS Attack
abstract
Authentication protocols are powerful tools to ensure confidentiality as an important feature of Internet of Things (IoT). The Denial-of-Service (DoS) attack is one of the significant threats to availability, as another essential feature of IoT, which deprives users of services by consuming the energy of IoT nodes. On the other hand, computational intelligence algorithms can be applied to solve such issues in the network and cyber domains. Motivated by this, this article links these concepts. To do so, we analyze two lightweight authentication protocols, present a DoS attack inspired by users' misbehavior and suggest a solution called received signal strength, which is easy to compute, applicable for resisting against different kinds of vulnerabilities in Internet protocols, and feasible for practical implementations. We implement it on two scenarios for locating attackers, investigate the effects of IoT devices' internal error on locating, and propose an optimization problem to finding the exact location of attackers, which is efficiently solvable for computational intelligence algorithms, such as TLBO. Besides, we analyze the solutions for unreliable results of accurate devices and provide a solution to detect attackers with less than 12-cm error and the false alarm probability of 0.7%.
Meysam Ghahramani, Reza Javidan, Mohammad Shojafar, Rahim Taheri, Mamoun Alazab, Rahim Tafazolli
IEEE Internet Things J.3
2021 Neural Architecture Search for Robust Networks in 6G-Enabled Massive IoT Domain
abstract
6G technology enables artificial intelligence (AI)-based massive IoT to manage network resources and data with ultra high speed, responsive network, and wide coverage. However, many AI-enabled Internet-of-Things (AIoT) systems are vulnerable to adversarial example attacks. Therefore, designing robust deep learning models that can be deployed on resource-constrained devices has become an important research topic in the field of 6G-enabled AIoT. In this article, we propose a method for automatically searching for robust and efficient neural network structures for AIoT systems. By introducing a skip connection structure, a feature map with reduced front-end influence can be used for calculations during the classification process. Additionally, a novel type of densely connected search space is proposed. By relaxing this space, it is possible to search for network structures efficiently. In addition, combined with adversarial training and model delay constraints, we propose a multiobjective gradient optimization method to realize the automatic searching of network structures. Experimental results demonstrate that our method is effective for AIoT systems and superior to state-of-the-art neural architecture search algorithms.
Ke Wang 0068, Peng Xu 0052, Chien-Ming Chen 0001, Saru Kumari, Mohammad Shojafar, Mamoun Alazab
IEEE Internet Things J.5
2021 Closed-loop and open-loop authentication protocols for blockchain-based IoT systems
Seyed Farhad Aghili, Hamid Mala, Christian Schindelhauer, Mohammad Shojafar, Rahim Tafazolli
Inf. Process. Manag.4
2021 FUPE: A security driven task scheduling approach for SDN-based IoT-Fog networks
Saeed Javanmardi, Mohammad Shojafar, Reza Mohammadi 0003, Amin Nazari, Valerio Persico, Antonio Pescapè
J. Inf. Secur. Appl.2
2021 A priority, power and traffic-aware virtual machine placement of IoT applications in cloud data centers
Shvan Omer, Sadoon Azizi, Mohammad Shojafar, Rahim Tafazolli
J. Syst. Archit.3
2021 FPFTS: A joint fuzzy particle swarm optimization mobility-aware approach to fog task scheduling algorithm for Internet of Things devices
abstract
Summary In the Internet of Things (IoT) scenario, the integration with cloud‐based solutions is of the utmost importance to address the shortcomings resulting from resource‐constrained things that may fall short in terms of processing, storing, and networking capabilities. Fog computing represents a more recent paradigm that leverages the wide‐spread geographical distribution of the computing resources and extends the cloud computing paradigm to the edge of the network, thus mitigating the issues affecting latency‐sensitive applications and enabling a new breed of applications and services. In this context, efficient and effective resource management is critical, also considering the resource limitations of local fog nodes with respect to centralized clouds. In this article, we present FPFTS, fog task scheduler that takes advantage of particle swarm optimization and fuzzy theory, which leverages observations related to application loop delay and network utilization. We evaluate FPFTS using an IoT‐based scenario simulated within iFogSim, by varying number of moving users, fog‐device link bandwidth, and latency. Experimental results report that FPFTS compared with first‐come first‐served (respectively, delay‐priority) allows to decrease delay‐tolerant application loop delay by 85.79% (respectively, 86.36%), delay sensitive application loop delay by 87.11% (respectively, 86.61%), and network utilization by 80.37% (respectively, 82.09%), on average.
Saeed Javanmardi, Mohammad Shojafar, Valerio Persico, Antonio Pescapè
Softw. Pract. Exp.2
2021 LEVER: Secure Deduplicated Cloud Storage With Encrypted Two-Party Interactions in Cyber-Physical Systems
abstract
Cloud envisioned cyber--physical systems (CCPS) is a practical technology that relies on the interaction among cyber elements like mobile users to transfer data in cloud computing. In CCPS, cloud storage applies data deduplication techniques aiming to save data storage and bandwidth for real-time services. In this infrastructure, data deduplication eliminates duplicate data to increase the performance of the CCPS application. However, it incurs security threats and privacy risks. For example, the encryption from independent users with different keys is not compatible with data deduplication. In this area, several types of research have been done. Nevertheless, they are suffering from a lack of security, high performance, and applicability. Motivated by this, in this article, we propose a message lock encryption with neVer-decrypt homomorphic encRyption (LEVER) protocol between the uploading CCPS user and cloud storage to reconcile the encryption and data deduplication. Interestingly, LEVER is the first brute-force resilient encrypted deduplication with only cryptographic two-party interactions. We perform several numerical analysis of LEVER and confirm that it provides high performance and practicality compared to the literature.
Zahra Pooranian, Mohammad Shojafar, Sahil Garg, Rahim Taheri, Rahim Tafazolli
IEEE Trans. Ind. Informatics2
2021 Fed-IIoT: A Robust Federated Malware Detection Architecture in Industrial IoT
abstract
The sheer volume of industrial Internet of Things (IIoT) malware is one of the most serious security threats in today's interconnected world, with new types of advanced persistent threats and advanced forms of obfuscations. This article presents a robust federated learning based architecture called Fed-IIoT for detecting Android malware applications in IIoT. Fed-IIoT consists of two parts: first, participant side, where the data are triggered by two dynamic poisoning attacks based on a generative adversarial network (GAN) and federated GAN; and second, server side, which aims to monitor the global model and shape a robust collaboration training model, by avoiding anomaly in aggregation by a GAN network (A3GAN) and adjust two GAN-based countermeasure algorithms. One of the main advantages of Fed-IIoT is that devices can safely participate in the IIoT and efficiently communicate with each other, with no privacy issues. We evaluate our solutions through experiments on various features using three IoT datasets. The results confirm the high accuracy rates of our attack and defense algorithms and show that the A3GAN defensive approach preserves the robustness of data privacy for Android mobile users and is about 8% higher accuracy with existing state-of-the-art solutions.
Rahim Taheri, Mohammad Shojafar, Mamoun Alazab, Rahim Tafazolli
IEEE Trans. Ind. Informatics2
2021 Voice-Transfer Attacking on Industrial Voice Control Systems in 5G-Aided IIoT Domain
abstract
At present, specific voice control has gradually become an important means for 5G-Internet-of-Things-aided industrial control systems, such as controlling the operation and adjustment of industrial Internet of Things equipment through telephone voice of the controller. However, the security of specific voice control system needs to be improved, because the voice cloning technology based on transfer learning can easily simulate the voice of the controller, which may lead to industrial accidents and other potential security risks. Therefore, this article mainly aims to study and understand the principle of voice cloning attack technology, putting forward a voice clone attack method, in order to prepare for the construction of a specific voice recognition system in the future. At present, the key technology of voice cloning attack is how to solve the problem that the target speaker's personalized speech with high quality cannot be synthesized under small samples. In fact, voice cloning is a very challenging problem because speech is more difficult to be represented in the hidden space of the model. We propose a transductive voice transfer learning method to learn the predictive function from the source domain and fine-tune in the target domain adaptively. The target learning task and the source learning task are both synthesizing speech signals from the given audio, while the datasets of both domains are different. By adding different penalty values to each instances and minimizing the expected risk, an optimal precise model can be learned. In addition, an evaluation method to verify the audio similarity of the target speaker was given to show the similarity between the synthesized audio and the original audio. Many details of the experimental results show that our method can effectively synthesize the speech of the target speaker with small samples.
Ke Wang 0068, Chien-Ming Chen 0001, Saru Kumari, Mohammad Shojafar, M. Shamim Hossain
IEEE Trans. Ind. Informatics5
2021 HDMA: Hybrid D2D Message Authentication Scheme for 5G-Enabled VANETs
abstract
The fifth-generation (5G) mobile communication technology with higher capacity and data rate, ultra-low device to device (D2D) latency, and massive device connectivity will greatly promote the development of vehicular ad hoc networks (VANETs). Meantime, new challenges such as security, privacy and efficiency are raised. In this article, a hybrid D2D message authentication (HDMA) scheme is proposed for 5G-enabled VANETs, in which a novel group signature-based algorithm is used for mutual authentication between vehicle to vehicle (V2V) communication. In addition, a pre-computed lookup table is adopted to reduce the computation overhead of modular exponentiation operation. Security analysis shows that HDMA is robust to resist various security attacks, and performance analysis also points out that, the authentication overhead of HDMA is more efficient than some traditional schemes with the help of the pre-computed lookup table in V2V and vehicle to infrastructure (V2I) communication.
Chien-Ming Chen 0001, Saru Kumari, Mohammad Shojafar, Rahim Tafazolli, Yi-Ning Liu 0002
IEEE Trans. Intell. Transp. Syst.4
2021 TEL: Low-Latency Failover Traffic Engineering in Data Plane
abstract
Modern network applications demand low-latency traffic engineering in the presence of network failure, while preserving the quality of service constraints like delay and capacity. Fast Re-Route (FRR) mechanisms are widely used for traffic re-routing purposes in failure scenarios. Control plane FRR typically computes the backup forwarding rules to detour the traffic in the data plane when the failure occurs. This mechanism could be computed in the data plane with the emergence of programmable data planes. In this paper, we propose a system (calledTEL) that containstwoFRR mechanisms, namely, TEL-C and TEL-D. The first one computes backup forwarding rules in the control plane, satisfying max-min fair allocation. The second mechanism provides FRR in the data plane. Both algorithms require minimal memory on programmable data planes and are well-suited with modern line rate match-action forwarding architectures (e.g., PISA). We implement both mechanisms on P4 programmable software switches (e.g., BMv2 and Tofino) and measure their performance on various topologies. The obtained results from a datacenter topology show that our FRR mechanism can improve the flow completion time up to 4.6$\times$–7.3$\times$(i.e., small flows) and 3.1$\times$–12$\times$(i.e., large flows) compared to recirculation-based mechanisms, such as F10, respectively.
Habib Mostafaei, Mohammad Shojafar, Mauro Conti
IEEE Trans. Netw. Serv. Manag.2
2021 Joint QoS-aware and Cost-efficient Task Scheduling for Fog-cloud Resources in a Volunteer Computing System
abstract
Volunteer computing is an Internet-based distributed computing in which volunteers share their extra available resources to manage large-scale tasks. However, computing devices in a Volunteer Computing System (VCS) are highly dynamic and heterogeneous in terms of their processing power, monetary cost, and data transferring latency. To ensure both of the high Quality of Service (QoS) and low cost for different requests, all of the available computing resources must be used efficiently. Task scheduling is an NP-hard problem that is considered as one of the main critical challenges in a heterogeneous VCS. Due to this, in this article, we design two task scheduling algorithms for VCSs, named Min-CCV and Min-V . The main goal of the proposed algorithms is jointly minimizing the computation, communication, and delay violation cost for the Internet of Things (IoT) requests. Our extensive simulation results show that proposed algorithms are able to allocate tasks to volunteer fog/cloud resources more efficiently than the state-of-the-art. Specifically, our algorithms improve the deadline satisfaction task rates around 99.5% and decrease the total cost between 15 to 53% in comparison with the genetic-based algorithm.
Farooq Hoseiny, Sadoon Azizi, Mohammad Shojafar, Rahim Tafazolli
ACM Trans. Internet Techn.3
2020 Computation Offloading Strategy in Heterogeneous Fog Computing with Energy and Delay Constraints
abstract
In fog computing, end-users can offload the computation-intensive tasks to the fog node in the proximity. Additionally, the fog nodes also offload these tasks to the cloud and neighboring fog node to seek additional computational resources. In this paper, we propose an offloading strategy in fog computing to minimize the cost that is a weighted sum of energy consumption and total delay for the task processing per end-user. We take the heterogeneous nature of the fog computing nodes that have different CPU frequency to process the tasks. We aim to find an optimal amount of task data to be either locally processed or offloaded to the preferable fog node and the remote cloud under the energy and delay constraints. We then formulate the optimization problem into a non-convex quadratically constrained quadratic program. We further provide an efficient solution to this problem by semidefinite relaxation. Finally, our proposed offloading scheme is evaluated by the simulation to demonstrate the offloading profile and optimal cost of the offloading with a wide range of parameter settings.
Mithun Mukherjee 0001, Vikas Kumar 0001, Suman Kumar 0005, Rakesh Matam, Constandinos X. Mavromoustakis, Qi Zhang 0013, Mohammad Shojafar, George Mastorakis
ICC7
2020 A job scheduling algorithm for delay and performance optimization in fog computing
abstract
Summary Due to an ever‐increasing number of Internet of Everything (IoE) devices, massive amounts of data are produced daily. Cloud computing offers storage, processing, and analysis services for handling of such large quantities of data. The increased latency and bandwidth consumption is not acceptable to real‐time applications like online gaming, smart health, video surveillance, etc. Fog computing has emerged to overcome the increase in latency and bandwidth consumption in Cloud computing. Fog Computing provides storage, processing, networking, and analytical services at the edge of a network. As Fog Computing is still in its infancy, its significant challenges include resource‐allocation and job‐scheduling. The Fog devices at the edge of the network are resource‐constrained. Therefore, it is important to decide the assignment and scheduling of a job on a Fog node. An efficient job scheduling algorithm can reduce energy consumption and response time of an application request. In this paper, we propose a novel Fog computing scheduler that supports service‐provisioning for Internet of Everything, which optimizes delay and network usage. We present a case study to optimally schedule the requests of Internet of Everything devices on Fog devices and efficiently address their demands on available resources on every Fog device. We consider delay and energy consumption as performance metrics and evaluate the proposed scheduling algorithm using iFogSim in comparison with existing approaches. The results show that the delay and network usage of the proposed scheduler improve by 32% and 16%, respectively, in comparison with FCFS approach.
Bushra Jamil, Mohammad Shojafar, Israr Ahmed, Kashif Munir, Humaira Ijaz
Concurr. Comput. Pract. Exp.2
2020 Similarity-based Android malware detection using Hamming distance of static binary features
Rahim Taheri, Meysam Ghahramani, Reza Javidan, Mohammad Shojafar, Zahra Pooranian, Mauro Conti
Future Gener. Comput. Syst.4
2020 Priority, network and energy-aware placement of IoT-based application services in fog-cloud environments
abstract
Fog computing is a decentralised model which can help cloud computing for providing high quality‐of‐service (QoS) for the Internet of Things (IoT) application services. Service placement problem (SPP) is the mapping of services among fog and cloud resources. It plays a vital role in response time and energy consumption in fog–cloud environments. However, providing an efficient solution to this problem is a challenging task due to difficulties such as different requirements of services, limited computing resources, different delay, and power consumption profile of devices in fog domain. Motivated by this, in this study, we propose an efficient policy, called MinRE, for SPP in fog–cloud systems. To provide both QoS for IoT services and energy efficiency for fog service providers, we classify services into two categories: critical services and normal ones. For critical services, we propose MinRes, which aims to minimise response time, and for normal ones, we propose MinEng, whose goal is reducing the energy consumption of fog environment. Our extensive simulation experiments show that our policy improves the energy consumption up to 18%, the percentage of deadline satisfied services up to 14% and the average response time up to 10% in comparison with the second‐best results.
Hiwa Omer Hassan, Sadoon Azizi, Mohammad Shojafar
IET Commun.3
2020 On defending against label flipping attacks on malware detection systems
abstract
Abstract Label manipulation attacks are a subclass of data poisoning attacks in adversarial machine learning used against different applications, such as malware detection. These types of attacks represent a serious threat to detection systems in environments having high noise rate or uncertainty, such as complex networks and Internet of Thing (IoT). Recent work in the literature has suggested using the K -nearest neighboring algorithm to defend against such attacks. However, such an approach can suffer from low to miss-classification rate accuracy. In this paper, we design an architecture to tackle the Android malware detection problem in IoT systems. We develop an attack mechanism based on silhouette clustering method, modified for mobile Android platforms. We proposed two convolutional neural network-type deep learning algorithms against this Silhouette Clustering-based Label Flipping Attack . We show the effectiveness of these two defense algorithms— label-based semi-supervised defense and clustering-based semi-supervised defense —in correcting labels being attacked. We evaluate the performance of the proposed algorithms by varying the various machine learning parameters on three Android datasets: Drebin, Contagio, and Genome and three types of features: API, intent, and permission. Our evaluation shows that using random forest feature selection and varying ratios of features can result in an improvement of up to 19% accuracy when compared with the state-of-the-art method in the literature.
Rahim Taheri, Reza Javidan, Mohammad Shojafar, Zahra Pooranian, Ali Miri, Mauro Conti
Neural Comput. Appl.3
2020 Adaptive Computing-Plus-Communication Optimization Framework for Multimedia Processing in Cloud Systems
abstract
A clear trend in the evolution of network-based services is the ever-increasing amount of multimedia data involved. This trend towards big-data multimedia processing finds its natural placement together with the adoption of the cloud computing paradigm, that seems the best solution to cope with the demands of a highly fluctuating workload that characterizes this type of services. However, as cloud data centers become more and more powerful, energy consumption becomes a major challenge both for environmental concerns and for economic reasons. An effective approach to improve energy efficiency in cloud data centers is to rely on traffic engineering techniques to dynamically adapt the number of active servers to the current workload. Towards this aim, we propose a joint computing-plus-communication optimization framework exploiting virtualization technologies, called MMGreen. Our proposal specifically addresses the typical scenario of multimedia data processing with computationally intensive tasks and exchange of a big volume of data. The proposed framework not only ensures users the Quality of Service (through Service Level Agreements), but also achieves maximum energy saving and attains green cloud computing goals in a fully distributed fashion by utilizing the DVFS-based CPU frequencies. To evaluate the actual effectiveness of the proposed framework, we conduct experiments with MMGreen under real-world and synthetic workload traces. The results of the experiments show that MMGreen may significantly reduce the energy cost for computing, communication and reconfiguration with respect to the previous resource provisioning strategies, respecting the SLA constraints.
Mohammad Shojafar, Claudia Canali, Riccardo Lancellotti, Jemal H. Abawajy
IEEE Trans. Cloud Comput.1
2020 A secure biometric-based authentication protocol for global mobility networks in smart cities
Meysam Ghahramani, Reza Javidan, Mohammad Shojafar
J. Supercomput.3
2019 Automatic Clustering of Attacks in Intrusion Detection Systems
abstract
Intrusion Detection Systems (IDSs) can identify the malicious activities and anomalies in networks and present robust protection for these systems. Clustering of attacks plays an important role in defining IDS defense policies. A key challenge in clustering has been finding the optimal value for the number of clusters. In this paper, we propose an automatic clustering algorithm as part of an IDS architecture. This algorithm is based on concepts of coherence and separation. Our automatic clustering algorithms find clusters with the most similarity between the proposed cluster elements and the least similarity with other clusters. The proposed clustering is further optimized by considering two types of objective index functions, and Artificial Bee Colony (ABC), Particle Swarm Optimization (PSO), and Differential Evolution (DE) methods. Comparison of the results obtained with other work in the literature shows improvements in terms of the low average number of evaluations functions, high accuracy, and low computation cost.
Mohammad Shojafar, Rahim Taheri, Zahra Pooranian, Reza Javidan, Ali Miri, Yaser Jararweh
AICCSA1
2019 A New Secure Data Dissemination Model in Internet of Drones
abstract
Data Dissemination is the distribution of data/statistics to the end users. With the adoption of Internet of Drones (IoD) environment for data dissemination, an efficient scheme is proposed which provides data integrity, identity anonymity, authentication, authorization, accountability (AAA) to the system model. We propose a system model having Ethereum based public blockchain distributed network in order to secure drone communication for the data collection and transmission. The proposed model provides secure communication between the drones and the users in a decentralized way. In this paper, blockchain technology is used for the storage of collected data from the drones and update the information into the distributed ledgers to reduce the burden of drones. It also provides integrity, authentication, and authorization to the collected data by the drones in the system model. Motivated by this consideration, the goal of this paper is threefold. First, we select a forger node from the number of drones. Second, we create blocks and validate their processes. Third, we provide secure data dissemination by applying Proof-of-Stake consensus mechanism. Afterward, we evaluate the security of the presented system model compared against the corresponding ones of some state-of-the-art in terms of communication time/cost. The results confirm that our system model is reliable and scalable for data dissemination in the IoD environment.
Shubhani Aggarwal, Mohammad Shojafar, Neeraj Kumar 0001, Mauro Conti
ICC2
2019 Joint Task Offloading and Resource Allocation for Delay-Sensitive Fog Networks
abstract
Computational offloading becomes an important and essential research issue for the delay-sensitive task completion at resource-constraint end-users. Fog computing that extends the computing and storage resources of the cloud computing to the network edge emerges as a potential solution towards low-latency task provisioning via computational offloading. In our offloading scenario, each end-user will first offload the task to its primary fog node. When the primary fog node cannot meet the tolerable latency, it has the possibility to offload to the cloud and/or assisting fog node to obtain extra computing resource to shorten the computing latency at the expense of additional transmission latency. Therefore, a trade-off needs to be carefully made in the offloading decision. At the same time, in addition to the task data from the end-users under its primary coverage, the primary fog node receives the tasks from other end-users via its neighbor fog nodes. Thus, to jointly optimize the computing and communication resources in the fog node, we formulate a delay-sensitive data offloading problem that mainly considers the local task execution delay and transmission delay. An approximate solution is obtained via Quadratically Constraint Quadratic Programming (QCQP). Finally, the extensive simulation results demonstrate the effectiveness of the proposed solution, while guaranteeing minimum end-to-end latency for various task processing densities and traffic intensity levels.
Mithun Mukherjee 0001, Suman Kumar 0005, Mohammad Shojafar, Qi Zhang 0013, Constandinos X. Mavromoustakis
ICC3
2019 Joint failure recovery, fault prevention, and energy-efficient resource management for real-time SFC in fog-supported SDN
Mohammad Mahdi Tajiki, Mohammad Shojafar, Behzad Akbari, Stefano Salsano, Mauro Conti, Mukesh Singhal
Comput. Networks2
2019 Identification of Android malware using refined system calls
abstract
Summary The ever increasing number of Android malware has always been a concern for cybersecurity professionals. Even though plenty of anti‐malware solutions exist, we hypothesize that the performance of existing approaches can be improved by deriving relevant attributes through effective feature selection methods. In this paper, we propose a novel two‐step feature selection approach based on Rough Set and Statistical Test named as RSST to extract refined system calls, which can effectively discriminate malware from benign apps. By refined set of system call, we mean the existence of highly relevant calls that are uniformly distributed thought target classes. Moreover, an optimal attribute set is created, which is devoid of redundant system calls. To address the problem of higher dimensional attribute set, we derived suboptimal system call space by applying the proposed feature selection method to maximize the separability between malware and benign samples. Comprehensive experiments conducted on three datasets resulted in an accuracy of 99.9%, Area Under Curve (AUC) of 1.0, with 1% False Positive Rate (FPR). However, other feature selectors (Information Gain, CFsSubsetEval, ChiSquare, FreqSel, and Symmetric Uncertainty) used in the domain of malware analysis resulted in the accuracy of 95.5% with 8.5% FPR. Moreover, the empirical analysis of RSST derived system calls outperformed other attributes such as permissions, opcodes, API, methods, call graphs, Droidbox attributes, and network traces.
Deepa Kundur, Radhamani G, P. Vinod 0001, Mohammad Shojafar, Neeraj Kumar 0001, Mauro Conti
Concurr. Comput. Pract. Exp.4
2019 Recent advances in cloud data centers toward fog data centers
abstract
In recent years, we have witnessed tremendous advances in cloud data centres (CDCs) from the point of view of the communication layer.A recent report from Cisco Systems Inc. demonstrates that CDCs, which are distributed across many geographical locations, will dominate the global data centre traffic flow for the foreseeable future.Their importance is highlighted by a top-line projection from this forecast that by 2019, more than four-fifths of total data centre traffic will be Cloud traffic.The geographical diversity of the computing resources in CDCs provides several benefits, such as high availability, effective disaster recovery, uniform access to users in different regions, and access to different energy sources.Although Cloud technology is currently predominant, it is essential to leverage new agile software technologies, agile processes and agile applications near to both the edge and the users; hence, the concept of Fog has been developed.Fog computing (FC) has emerged as an alternative to traditional Cloud computing to support geographically distributed, latency-sensitive and QoS-aware IoT applications while reducing the burden on data centres used in traditional Cloud computing.In particular, FC with features that can support heterogeneity and real-time applications (e.g.low latency, location awareness, and the capacity to process a large number of nodes with wireless access) is an attractive solution for delay-and resource-constrained large-scale applications.The distinguishing feature of the FC paradigm is that a set of Fog nodes (FNs) spreads communication and computing resources over the wireless access network to provide resource augmentation to resource-and energy-limited wireless (possibly mobile) devices.The joint management of Fog and Internet of Technology (IoT) paradigms can reduce the energy consumption and operating costs of state-of-the-art Fog-based data centres (FDCs).An FDC is dedicated to supervising the transmission, distribution and communication of FC.As a vital component of the Internet of Everything (IoE) environment, an FDC is capable of filtering and processing a considerable amount of incoming data on edge devices, by making the data processing architecture distributed and thereby scalable.An FDC therefore provides a platform for filtering and analysing the data generated by sensors utilising the resources of FNs.Increasing interest is emerging in FDCs and CDCs that allow the delivery of various kinds of agile services and applications over telecommunication networks and the Internet, including resource provisioning, data streaming/transcoding, analysis of high-definition videos across the edge of the network, IoE application analysis etc. Motivated by these issues, this special section solicits original research and practical contributions that advance the use of CDCs/FDCs in new technologies such as IoT, edge networks and industries.Results obtained from simulations are validated in terms of their boundaries by experiments or analytical results.The main objectives of this special issue are to provide a discussion forum for people interested in Cloud and Fog networking, and to present new models, adaptive tools and applications specifically designed for distributed and parallel on-demand requests received from (mobile) users and Cloud applications.The papers presented in this special issue provide insights in fields related to Cloud and Fog/edge architecture, including parallel processing of Cloudlets/Foglets, the presentation of new emerging models, performance evaluation and improvements, and developments in Cloud/Fog applications.We hope that readers can benefit from the insights in these papers, and contribute to these rapidly growing areas.
Mohammad Shojafar, Zahra Pooranian, Mehdi Sookhak, Rajkumar Buyya
Concurr. Comput. Pract. Exp.1
2019 Software defined service function chaining with failure consideration for fog computing
abstract
Summary Middleboxes have become a vital part of modern networks by providing services such as load balancing, optimization of network traffic, and content filtering. A sequence of middleboxes comprising a logical service is called a Service Function Chain (SFC). In this context, the main issues are to maintain an acceptable level of network path survivability and a fair allocation of the resource between different demands in the event of faults or failures. In this paper, we focus on the problems of traffic engineering, failure recovery, fault prevention, and SFC with reliability and energy consumption constraints in Software Defined Networks (SDN). These types of deployments use Fog computing as an emerging paradigm to manage the distributed small‐size traffic flows passing through the SDN‐enabled switches (possibly Fog Nodes). The main aim of this integration is to support service delivery in real‐time failure recovery in an SFC context. First, we present an architecture for Failure Recovery called FRFP; this is a multi‐tier structure in which the real‐time traffic flows pass through SDN‐enabled switches to jointly decrease the network side‐effects of flow rerouting and energy consumption of the Fog Nodes. We then mathematically formulate an optimization problem called the Optimal Fast Failure Recovery algorithm (OFFR) and propose a near‐optimal heuristic called Heuristic HFFR to solve the corresponding problem in polynomial time. In this way, the reliability of the selected paths are optimized, while the network congestion is minimized.
Mohammad Mahdi Tajiki, Mohammad Shojafar, Behzad Akbari, Stefano Salsano, Mauro Conti
Concurr. Comput. Pract. Exp.2
2019 LACO: Lightweight Three-Factor Authentication, Access Control and Ownership Transfer Scheme for E-Health Systems in IoT
Seyed Farhad Aghili, Hamid Mala, Mohammad Shojafar, Pedro Peris-Lopez
Future Gener. Comput. Syst.3
2019 FOCAN: A Fog-supported smart city network architecture for management of applications in the Internet of Everything environments
Paola Gabriela Vinueza Naranjo, Zahra Pooranian, Mohammad Shojafar, Mauro Conti, Rajkumar Buyya
J. Parallel Distributed Comput.3
2019 Energy-Efficient Adaptive Resource Management for Real-Time Vehicular Cloud Services
abstract
Providing real-time cloud services to Vehicular Clients (VCs) must cope with delay and delay-jitter issues. Fog computing is an emerging paradigm that aims at distributing small-size self-powered data centers (e.g., Fog nodes) between remote Clouds and VCs, in order to deliver data-dissemination real-time services to the connected VCs. Motivated by these considerations, in this paper, we propose and test an energy-efficient adaptive resource scheduler for Networked Fog Centers (NetFCs). They operate at the edge of the vehicular network and are connected to the served VCs through Infrastructure-to-Vehicular (I2V) TCP/IP-based single-hop mobile links. The goal is to exploit the locally measured states of the TCP/IP connections, in order to maximize the overall communication-plus-computing energy efficiency, while meeting the application-induced hard QoS requirements on the minimum transmission rates, maximum delays and delay-jitters. The resulting energy-efficient scheduler jointly performs: (i) admission control of the input traffic to be processed by the NetFCs; (ii) minimum-energy dispatching of the admitted traffic; (iii) adaptive reconfiguration and consolidation of the Virtual Machines (VMs) hosted by the NetFCs; and, (iv) adaptive control of the traffic injected into the TCP/IP mobile connections. The salient features of the proposed scheduler are that: (i) it is adaptive and admits distributed and scalable implementation; and, (ii) it is capable to provide hard QoS guarantees, in terms of minimum/maximum instantaneous rates of the traffic delivered to the vehicular clients, instantaneous rate-jitters and total processing delays. Actual performance of the proposed scheduler in the presence of: (i) client mobility; (ii) wireless fading; and, (iii) reconfiguration and consolidation costs of the underlying NetFCs, is numerically tested and compared against the corresponding ones of some state-of-the-art schedulers, under both synthetically generated and measured real-world workload traces.
Mohammad Shojafar, Nicola Cordeschi, Enzo Baccarelli
IEEE Trans. Cloud Comput.1
2019 Joint Energy Efficient and QoS-Aware Path Allocation and VNF Placement for Service Function Chaining
abstract
Service function chaining (SFC) allows the forwarding of traffic flows along a chain of virtual network functions (VNFs). Software defined networking (SDN) solutions can be used to support SFC to reduce both the management complexity and the operational costs. One of the most critical issues for the service and network providers is the reduction of energy consumption, which should be achieved without impacting the Quality of Service. In this paper, we propose a novel resource allocation architecture which enables energy-aware SFC for SDN-based networks, considering also constraints on delay, link utilization, server utilization. To this end, we formulate the problems of VNF placement, allocation of VNFs to flows, and flow routing as integer linear programming (ILP) optimization problems. Since the formulated problems cannot be solved (using ILP solvers) in acceptable timescales for realistic problem dimensions, we design a set of heuristic to find near-optimal solutions in timescales suitable for practical applications. We numerically evaluate the performance of the proposed algorithms over a real-world topology under various network traffic patterns. Our results confirm that the proposed heuristic algorithms provide near-optimal solutions (at most 14% optimality-gap) while their execution time makes them usable for real-life networks.
Mohammad Mahdi Tajiki, Stefano Salsano, Luca Chiaraviglio, Mohammad Shojafar, Behzad Akbari
IEEE Trans. Netw. Serv. Manag.4
2018 An Approach to Balance Maintenance Costs and Electricity Consumption in Cloud Data Centers
abstract
We target the problem of managing the power states of the servers in a Cloud Data Center (CDC) to jointly minimize the electricity consumption and the maintenance costs derived from the variation of power (and consequently of temperature) on the servers' CPU. More in detail, we consider a set of virtual machines (VMs) and their requirements in terms of CPU and memory across a set of Time Slot (TSs). We then model the consumed electricity by taking into account the VMs processing costs on the servers, the costs for transferring data between the VMs, and the costs for migrating the VMs across the servers. In addition, we employ a material-based fatigue model to compute the maintenance costs needed to repair the CPU, as a consequence of the variation over time of the server power states. After detailing the problem formulation, we design an original algorithm, called Maintenance and Electricity Costs Data Center (MECDC), to solve it. Our results, obtained over several scenarios from a real CDC, show that MECDC largely outperforms two reference algorithms, which instead either target the load balancing or the energy consumption of the servers.
Luca Chiaraviglio, Fabio D'Andreagiovanni, Riccardo Lancellotti, Mohammad Shojafar, Nicola Blefari-Melazzi, Claudia Canali
IEEE Trans. Sustain. Comput.4
2017 A Computation- and Network-Aware Energy Optimization Model for Virtual Machines Allocation
Claudia Canali, Riccardo Lancellotti, Mohammad Shojafar
CLOSER3
2017 Mobile Cloud Computing: Challenges and Future Research Directions
abstract
In society today, mobile communication and mobile computing have a significant role in every aspect of our lives, both personal and public communication. However, the growth in mobile computing usage can be enhanced by integrating mobile computing into cloud computing. This will result in emerging a new model called Mobile Cloud Computing (MCC) that has recently attracted much attention in the academic sector. In this work, the main challenges and issues related to MCC are outlined. We also present the recent work and countermeasure solutions that are proposed by researchers to counter the challenges and lastly, crucial open research and issues that direct future research is highlighted.
Samaher Al-Janabi, Ibrahim AlShourbaji, Mohammad Shojafar, Mohammed Eltahir Abdelhag
DeSE3
2017 P5G: A Bio-Inspired Algorithm for the Superfluid Management of 5G Networks
abstract
5G is expected to become the dominant technology in the forthcoming years. In this work, we consider a 5G Superfluid network, as an outcome of the H2020 project SUPERFLUIDITY. The project exploits the concept of Reusable Functional Block (RFB), a virtual resource that can be deployed on top of 5G physical nodes. Specifically, we focus on the management of the RFBs in a Superfluid network to deliver a high definition video to the users. We design an efficient algorithm, called P5G, which is based on Particle Swarm Optimization (PSO). Our solution targets different Key Performance Indicators (KPIs), including the maximization of user throughput, or the minimization of the number of used 5G nodes. Results, obtained over a representative scenario, show that P5G is able to wisely manage the RFBs, while always guaranteeing a large throughput to the users.
Mohammad Shojafar, Luca Chiaraviglio, Nicola Blefari-Melazzi, Stefano Salsano
GLOBECOM1
2017 A Novel Distributed Fog-Based Networked Architecture to Preserve Energy in Fog Data Centers
abstract
The distinguishing feature of the Fog Computing (FC) paradigm is that FC spreads communication and computing resources over the wireless access network, so as to provide resource augmentation to resource and energy-limited wireless (possibly mobile) devices. Since FC would lead to substantial reductions in energy consumption and access latency, it will play a key role in the realization of the Fog of Everything (FoE) paradigm. The core challenge of the resulting FoE paradigm is tomaterialize the seamless convergence of three distinct disciplines, namely, broadband mobile communication, cloud computing, and Internet of Everything (IoE). In this paper, we present a new IoE architecture for FC in order to implement the resulting FoE technological platform. Then, we elaborate the related Quality of Service (QoS) requirements to be satisfied by the underlying FoE technological platform. Furthermore, in order to corroborate the conclusion that advancements in the envisioned architecture description, we present: (i) the proposed energy-aware algorithm adopt Fog data center; and, (ii) the obtained numerical performance, for a real-world case study that shows that our approach saves energy consumption impressively in theFog data Center compared with the existing methods and could be of practical interest in the incoming Fog of Everything (FoE) realm.
Zahra Pooranian, Mohammad Shojafar, Paola Gabriela Vinueza Naranjo, Luca Chiaraviglio, Mauro Conti
MASS2
2017 Optimal superfluid management of 5G networks
abstract
We consider the problem of evaluating the performance of a 5G network based on reusable components, called Reusable Functional Blocks (RFBs), proposed by the Horizon 2020 SUPERFLUIDITY project. RFBs allow a high level of flexibility, agility, portability and high performance. After formally modelling the RFB entities and the network physical nodes, we optimally formulate the problem of maximizing different Key Performance Indicators (KPIs) on an RFB-based network architecture, in which the RFBs are shared among the nodes, and deployed only where and when they are really needed. Our results, obtained by solving the proposed optimization problem over a simple yet representative scenario, show that the network can be managed in a very efficient way. More in depth, the RFBs are placed into the nodes in accordance with the amount of requested traffic from users and the specific pursued KPI, e.g., maximization of user throughput or minimization of the number of used nodes. Moreover, we evaluate the relationship between the capacity of each node and the number of RFBs deployed on it.
Luca Chiaraviglio, Lavinia Amorosi, Stefania Cartolano, Nicola Blefari-Melazzi, Paolo Dell'Olmo, Mohammad Shojafar, Stefano Salsano
NetSoft6
2017 Q*: Energy and delay-efficient dynamic queue management in TCP/IP virtualized data centers
Enzo Baccarelli, Paola Gabriela Vinueza Naranjo, Mohammad Shojafar, Michele Scarpiniti
Comput. Commun.3
2017 Barrier coverage of WSNs with the imperialist competitive algorithm
Habib Mostafaei, Mohammad Shojafar, Bahman Zaher, Mukesh Singhal
J. Supercomput.2
2017 P-SEP: a prolong stable election routing algorithm for energy-limited heterogeneous fog-supported wireless sensor networks
Paola Gabriela Vinueza Naranjo, Mohammad Shojafar, Habib Mostafaei, Zahra Pooranian, Enzo Baccarelli
J. Supercomput.2
2017 FLAPS: bandwidth and delay-efficient distributed data searching in Fog-supported P2P content delivery networks
Mohammad Shojafar, Zahra Pooranian, Paola Gabriela Vinueza Naranjo, Enzo Baccarelli
J. Supercomput.1
2016 An Energy-aware Scheduling Algorithm in DVFS-enabled Networked Data Centers
abstract
In this paper, we propose an adaptive online energy-aware scheduling algorithm by exploiting the reconfiguration capability of a Virtualized Networked Data Centers (VNetDCs) processing large amount of data in parallel. To achieve energy efficiency in such intensive computing scenarios, a joint balanced provisioning and scaling of the networking-plus-computing resources is required. We propose a scheduler that manages both the incoming workload and the VNetDC infrastructure to minimize the communication-plus-computing energy dissipated by processing incoming traffic under hard real-time constraints on the per-job computing-plus-communication delays. Specifically, our scheduler can distribute the workload among multiple virtual machines (VMs) and can tune the processor frequencies and the network bandwidth. The energy model used in our scheduler is rather sophisticated and takes into account also the internal/external frequency switching energy costs. Our experiments demonstrate that the...
Mohammad Shojafar, Claudia Canali, Riccardo Lancellotti, Saeid Abolfazli
CLOSER (2)1
2016 Minimizing computing-plus-communication energy consumptions in virtualized networked data centers
abstract
In this paper, we propose a dynamic resource provisioning scheduler to maximize the application throughput and minimize the computing-plus-communication energy consumption in virtualized networked data centers. The goal is to maximize the energy-efficiency, while meeting hard QoS requirements on processing delay. The resulting optimal resource scheduler is adaptive, and jointly performs: i) admission control of the input traffic offered by the cloud provider; ii) adaptive balanced control and dispatching of the admitted traffic; iii) dynamic reconfiguration and consolidation of the Dynamic Voltage and Frequency Scaling (DVFS)-enabled virtual machines instantiated onto the virtualized data center. The proposed scheduler can manage changes of the workload without requiring server estimation and prediction of its future trend. Furthermore, it takes into account the most advanced mechanisms for power reduction in servers, such as DVFS and reduced power states. Performance of the proposed scheduler is numerically tested and compared against the corresponding ones of some state-of-the-art schedulers, under both synthetically generated and measured real-world workload traces. The results confirm the delay-vs.-energy good performance of the proposed scheduler.
Mohammad Shojafar, Claudia Canali, Riccardo Lancellotti, Enzo Baccarelli
ISCC1
2016 A new Stable Election-based routing algorithm to preserve aliveness and energy in fog-supported wireless sensor networks
abstract
One of the current key challenges in wireless sensor networks is the development of routing protocols that provide stable cluster-head election, while prolonging network lifetime by saving energy. In this contribution, a new Stable Election Protocol (SEP), named New-SEP (N-SEP), is presented to prolong the stable period of Fog-supported sensor networks by maintaining balanced energy consumption. N-SEP takes into account some features of sensor nodes (e.g., distance from base station, network heterogeneity ratio, residual/consumed energy, distance between cluster heads (CHs)) in order to elect the best CHs. For this purpose, it exploits heterogeneous energy thresholds, in order to select CHs and prolong the time interval of the system. Simulation results support the capability of the proposed algorithm to maximize the network lifetime and preserve more energy as compared to the results obtained by using current heuristics, such as, Low Energy Adaptive Clustering Hierarchy (LEACH) and SEP protocols. Additionally, we found that N-SEP outperforms LEACH and SEP in prolonging the stability period of the network by 50% and 25%, respectively.
Paola Gabriela Vinueza Naranjo, Mohammad Shojafar, Ajith Abraham, Enzo Baccarelli
SMC2
2015 TETS: A Genetic-Based Scheduler in Cloud Computing to Decrease Energy and Makespan
Mohammad Shojafar, Maryam Kardgar, Ali A. R. Hosseinabadi, Shahab B. Band, Ajith Abraham
HIS1
2015 An efficient and distributed file search in unstructured peer-to-peer networks
Mohammad Shojafar, Jemal H. Abawajy, Zia Delkhah, Zahra Pooranian, Ajith Abraham
Peer-to-Peer Netw. Appl.1
2015 Energy-efficient adaptive networked datacenters for the QoS support of real-time applications
Nicola Cordeschi, Mohammad Shojafar, Danilo Amendola, Enzo Baccarelli
J. Supercomput.2
2014 Mathematical modeling of blood flow through an eccentric catheterized artery: A practical approach for a complex system
abstract
In this research a two dimensional, single phase, and isothermal model is developed to investigate the effects of eccentric catheterization on blood flow characteristics in a tapered and stenosis artery which is complex system. The model conducted by assuming that the blood is as Newtonian and incompressible fluid and the temperature effects are also neglected. The results clearly show that the axial velocity and the magnitude of the wall shear stress distribution are higher for eccentric catheter than that for concentric one. Also, the resistance impedance gives the reverse trend of the wall shear stress with respect to the taper angle where blood can flow freely through diverging vessel but in the case of eccentric catheter is less than that of the concentric one when the radius of catheter is considered. In addition, the trapping appears near the wall of catheter and the trapped bolus increases in size as the radius of catheter increases.
Sima S. Ahrabi, Mohammad Shojafar, Hamid Kazemi Esfeh, Ajith Abraham
HIS2
2014 A solution for multi-objective commodity vehicle routing problem by NSGA-II
abstract
Vehicle routing is considered the basic issue in distribution management. In real-world problems, customer demand for some commodities increases on special situations. On the one hand, one of the factors that are very important for customers is the timely delivery of the demanded commodities. In this research, customers had several different kinds of demands. Therefore, a new routing model was introduced in the form of integer linear programming by combining the concepts of time windows and multiple demands and by considering the two contradictory goals of minimizing travel cost and maximizing demand coverage. Moreover, two approaches were designed for the problem-solving model based on the NSGA-II algorithm with diversification of the mutation operator structure. The two criteria of spread and coverage of non-dominated solutions were used to compare algorithms. Study of some typical created problems indicated the validity of the model and the computational efficiency of the proposed algorithm. The proposed algorithm could increase the criterion of solution spread by about 10%, and increased the number of obtained solutions on the Pareto border compared to other algorithms, which indicated its high efficiency.
Shahab B. Band, Mohammad Shojafar, Ali A. R. Hosseinabadi, Ajith Abraham
HIS2
2014 GELS-GA: Hybrid metaheuristic algorithm for solving Multiple Travelling Salesman Problem
abstract
The Multiple Traveling Salesmen Problem (mTSP) is of the famous and classical problems of research in operations and is accounted as one of the most famous and widely used problems of combinational optimization. Most of the complex problems can be modeled as the mTSP and then be solved. The mTSP is a NP-Complete one; therefore, it is not possible to use the exact algorithms for solving it instead the heuristics methods are often applied for solving such problems. In this paper, a new hybrid algorithm, called GELS-GA, has been presented for solving the mTSP. The utility of GELS-GA is compared with some related works such as GA and ACO and achieves optimality even in highly complex scenarios. Although, the proposed algorithm is simple, it includes an appropriate time of completion and the least traversed distance among existing algorithms.
Ali A. R. Hosseinabadi, Maryam Kardgar, Mohammad Shojafar, Shahab B. Band, Ajith Abraham
ISDA3
2014 Performance evaluation of primary-secondary reliable resource-management in vehicular networks
abstract
We design and test a distributed and adaptive resource management controller in Vehicular Access Networks, allowing energy and computing-limited car smart phones to opportunistically accede to a spectral-limited wireless backbone. We cast the resource management problem into a suitable constrained stochastic Network Utility Maximization problem and derive the optimal cognitive resource management controller, which dynamically allocates the access time-windows at the serving Roadside Units (i.e., the primary users) and the access rates and traffic flows at the served Vehicular Clients (i.e., the secondary users), allowing hard reliability guarantees to Roadside Units. We validated the controller performances in real-word application scenarios.
Nicola Cordeschi, Danilo Amendola, Mohammad Shojafar, Enzo Baccarelli
PIMRC3
2014 An efficient routing algorithm to preserve k-coverage in wireless sensor networks
Mohammad Shojafar, Seyede Fatemeh Hajeforosh, Mehdi Dehghan 0001, Mukesh Singhal
J. Supercomput.2
2014 PGSW-OS: a novel approach for resource management in a semantic web operating system based on a P2P grid architecture
Saeed Javanmardi, Mohammad Shojafar, Shahdad Shariatmadari, Jemal H. Abawajy, Mukesh Singhal
J. Supercomput.2
2013 Energy-saving self-configuring networked data centers
Nicola Cordeschi, Mohammad Shojafar, Enzo Baccarelli
Comput. Networks2