VLDB 2026 Research / reviewers in the wild / expert
Mamoona Humayun
dblp:117/5623
· DBLP profile ↗
15ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0001-6339-2257ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 5 · 3 first-author · 2 since 2021Computer networks · 4 · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The double-edged sword: LLM operations (LLMOps) security in the cloud- a comprehensive review
Sijjad Ali, Dhani Bux Talpur, Mamoona Humayun, Maram Fahaad Almufareh, Ghadah Alwakid, Jahanzaib Yaqoob |
Neurocomputing | 3 |
| 2026 | NLP in cybersecurity: Advances, applications, and future directions for threat analysis and dark web intelligenceabstractThe rapid evolution of cyber threats requires advanced techniques for analyzing large amounts of textual data from threat reports, security bulletins, and dark web forums. Natural Language Processing (NLP) has emerged as a powerful tool for automating the extraction of actionable intelligence from unstructured cybersecurity data. This review paper explores the role of NLP in cybersecurity, focusing on its applications in processing threat reports and dark web data to identify, predict, and mitigate cyber risks. We begin by discussing the challenges in cybersecurity text analysis, including noisy data, multilingual content, and adversarial language obfuscation. Next, we review key NLP techniques-such as named entity recognition (NER), sentiment analysis, topic modeling, and deep learning-based approaches-that enhance threat intelligence by classifying malware, detecting phishing attempts, and uncovering threat actor communications. We also examine how large language models (LLMs) such as BERT and GPT are being adapted for cybersecurity tasks. Furthermore, the paper highlights the ethical and privacy concerns associated with dark web data scraping and the risks of AI-powered cyberattacks. We compare existing NLP-based cybersecurity frameworks and identify gaps in real-time threat detection and cross-domain adaptability. Finally, we outline future research directions, including multimodal threat analysis, adversarial NLP defenses, and explainable AI for security analysts. This review serves as a comprehensive resource for researchers and practitioners, bridge the gap between NLP advancements and cybersecurity applications while addressing emerging challenges in the field. Amjad Alsirhani, Sijjad Ali, Mamoona Humayun, Shafique U. Rehman, Mona Saleh Alzahrani |
Neurocomputing | 3 |
| 2026 | Intent-Based Secure Fault Tolerance Model With Integrated AI for Edge-IoT NetworksabstractThe development of real-time applications integrated with Intent-Based Networking (IBN) integrates an Internet of Things (IoT), providing interconnection between heterogeneous devices and physical objects for the formulation of smart cities. These systems provide seamless communication and maintain the adaptive network policies and infrastructure. Many existing schemes have proposed solutions for efficient routing with support from intelligent architectures; however, although most of them overlook the bounded and limited resources of IoT networks, they impose additional overhead while addressing unpredictable communications in IBN-IoT. Furthermore, security and trustworthiness are significant research challenges that must be addressed to prevent data breaches and allow only the use of authentic devices. This research presents a scalable model for an IBN-IoT environment that utilizes edge computing to enable trustworthy and fault-tolerant communication with energy efficiency. Firstly, Software-Defined Networking (SDN) is explored for load balancing and effective resource allocation in 6G Internet of Things (IoT) systems. Secondly, the proposed model explores artificial intelligence techniques to analyze the network environment and predict anomalies in the fault tolerance approach. Lastly, data is kept private and maintained in integrity using a private blockchain, providing a more reliable, distributed, autonomous system with minimal overhead. Using synthetic data, the proposed model is validated against QGA-ACO and MER-ODLADT solutions for energy consumption, anomaly detection, and time-to-failure metrics across dynamic scenarios. Menwa Alshammeri, Mamoona Humayun, Khalid Haseeb, Malak Alamri, Abdellah Chehri, Gwanggil Jeon |
IEEE Internet Things J. | 2 |
| 2025 | Hybrid Semantic-Structural Learning for URL Multi-Classification Using DistilBERT and Feature EngineeringabstractThis research presents a robust framework for the multi-classification of URLs into benign and malicious categories, specifically addressing defacement, malware, phishing, and spam. We aggregated multiple publicly available datasets into a unified, balanced dataset, followed by rigorous preprocessing to enhance data quality. Structural URL features-including length, subdomain count, HTTPS presence, digit and special character ratios-were systematically extracted. The model uses DistilBERT transformer embeddings to turn the URLs into semantic representations. Experiments are done using XGBoost, LSTM, and fine-tuned DistilBERT. Results show that the DistilBERT model has an accuracy of $97.4 \%$, which is better than traditional ensemble methods and recurrent neural networks. Merging the structure of data with its meaning gave better results, proving that transformer-based approaches are valuable for cybersecurity. Noshina Tariq, Khulud Salem S. Alshudukhi, Muhammad Haroon Wajid, Mamoona Humayun, Hamid Jahankhani |
AICCSA | 4 |
| 2025 | Security and privacy in multi-cloud and hybrid cloud environments: Challenges, strategies, and future directions
Sijjad Ali, Dhani Bux Talpur, Adeel Abro, Khulud Salem S. Alshudukhi, Ghadah Alwakid, Mamoona Humayun, Farhan Bashir, Shuaib Ahmed Wadho, Asadullah Shah |
Comput. Secur. | 6 |
| 2025 | CID-RPL: Clone ID Attack Detection Using Deep Neural Network for RPL-Based IoT NetworksabstractABSTRACT The proliferation of the Internet of Things (IoT) has reshaped industries based on seamless connectivity. However, it has also brought about immense security challenges, especially in the communication protocol of routing protocol for low‐power and lossy networks (RPL). One of these security threats vital to the RPL‐based IoT networks includes the Clone ID attack on malicious nodes when they clone the identity of legitimate nodes to access their sensitive data without authorization. Detecting Clone ID attacks in RPL‐based IoT networks is complex because network traffic data has high dimensions and substantial data imbalances while facing limited resources in these environments. The unmanaged control message system and insufficient identity authentication methods within the RPL protocol directly expose networks to state‐of‐the‐art cyber security threats. This paper proposes a new edge layer‐based deep neural network (DNN) approach to detect Clone ID attacks from IoT sensor networks by network traffic pattern analysis. The proposed method is based on deep data features to distinguish legitimate nodes from cloned nodes and improve the overall security, resilience, and operational efficiency of RPL‐based IoT networks. To check the efficiency of our proposed method, we designed a synthetic dataset called CID‐RPL. The CID‐RPL dataset consists of 25 attributes and 2,131,328 samples. The experimental results are best to describe that our proposed approach outperformed the previously designed methods by offering an accuracy improvement of 5.06%, precision improvement of 7.60%, recall increment of 7.0%, and F1 score enhancement of 11.0%. Similarly, residual energy at the network level increased by 32.84%, which infers that the lifetime of the network will be extended and its energy efficiency increased under attack situations. Thus, the results testify to the effectiveness of the DL‐based solution proposed herein to detect Clone ID attacks in dynamic and evolving network environments. Fatima Al-Quayed, Sana Rauf Awan, Noshina Tariq, Mamoona Humayun, Thanaa S. Alnusairi, Tayyab Rehman |
IET Commun. | 4 |
| 2025 | GANSCCS: Synergizing Generative Adversarial Networks and Spectral Clustering for Enhanced MRI Resolution in the Diagnosis of Cervical SpondylosisabstractThe expeditious improvement in medical imaging technology has been crucial in diagnosing various conditions like cervical spondylosis. However, there is a need for improvement in terms of accuracy and efficiency in the existing models to obtain optimal diagnostic results. This limitation of existing models particularly hampers the resolution and clarity of MRI where there is a need for finer details for the accurate diagnoses of the problem. To limit this gap, our research represents a pioneering approach that merges GAN and spectral clustering. Our research shows the innovative amalgamation of two technologies. The GAN model is enhanced by the sturdy segmentation abilities of spectral clustering, resulting in the significant betterment in diagnosis of problems. This GAN is specifically designed for medical imaging; it consists of a deep convolutional network based on U‐Net architecture. GAN consists of a generator that generates the MRI image through a series of convolutional and deconvolutional layers, and a discriminator checks whether the MRI image is real or generated. This approach not only improves the quality of the image but also leads to a more brisk and accurate diagnosis of cervical spine deformities. The methodology was meticulously tested on diverse datasets, including Medscape, RSNA 2022, and CTSpine1k. The results were remarkable, showing an 8.3% increase in accuracy, 5.5% improvement in precision, 8.5% higher recall, 3.5% greater AUC, 4.9% increased specificity, and a 1.9% reduction in delay compared to the existing classification methods. The influence of this work is profound, providing a consideration spike in the capability of diagnosing problems of cervical spondylosis. By providing improved image resolution and highly precise diagnostic tools, this advancement helps clinicians to make more accurate decisions as well as provides various innovations that help in medical imaging in the future. Robin Kumar, Dalwinder Singh, Rahul Malik, Isha Batra, Mamoona Humayun, Javed Ali Khan |
Int. J. Intell. Syst. | 5 |
| 2025 | Complex outsourcing relationships management modelabstractAbstract Global software development (GSD) refers to developing software with a distributed team spanning multiple locations and time zones. Based on relationships, there are four types of outsourcing: dyadic (one client–one vendor), multi‐vendor (one client–many vendors), co‐sourcing (many clients–one vendor), and complex outsourcing (many clients–many vendors). Compared to the other types of outsourcing contracts, complex outsourcing contracts are the hardest to work on and have the highest risk of project failure. This paper presents a model, the complex outsourcing relationships management model (CORMM), to assist the complex outsourcing stakeholders (both the clients and vendors) in managing their relationships in the context of GSD. This paper aims to develop a CORMM to assist the complex outsourcing relationships management stakeholders in GSD. Also, we are interested in identifying the applicability and effectiveness of the CORMM in the real‐world industry. The research approach follows a structured methodology comprising multiple phases. Initially, it leverages a systematic literature review (SLR) as its primary research method. The second phase involves the validation of the SLR findings via an empirical study. Subsequently, in the third phase, a model is developed. Finally, the proposed research approach is validated by incorporating two industrial case studies to assess the organization's relationship management utilizing the Motorola tool. The case study results show that CORMM can successfully point out relationship management issues in a complex outsourcing context. The feedback received from the participants of both companies indicates several positive and valuable insights about the CORMM and its application in the context of complex outsourcing relationships. The results highlight that CORMM serves as an assessment tool for evaluating an organization's relationship management capability and a means for organizations to enhance their position. Through CORMM, complex outsourcing organizations (many clients–many vendors) can identify strengths and weaknesses in their relationship management practices, enabling targeted improvement efforts. Ghulam Murtaza Khan, Siffat Ullah Khan, Mahmood Niazi, Muhammad Ilyas 0002, Mamoona Humayun, Akash Ahmad, Javed Ali Khan, Sajjad Mahmood |
J. Softw. Evol. Process. | 5 |
| 2024 | A Machine Learning-Based Framework for Accurate and Early Diagnosis of Liver Diseases: A Comprehensive Study on Feature Selection, Data Imbalance, and Algorithmic PerformanceabstractThe liver is the largest organ of the human body with more than 500 vital functions. In recent decades, a large number of liver patients have been reported with diseases such as cirrhosis, fibrosis, or other liver disorders. There is a need for effective, early, and accurate identification of individuals suffering from such disease so that the person may recover before the disease spreads and becomes fatal. For this, applications of machine learning are playing a significant role. Despite the advancements, existing systems remain inconsistent in performance due to limited feature selection and data imbalance. In this article, we reviewed 58 articles extracted from 5 different electronic repositories published from January 2015 to 2023. After a systematic and protocol‐based review, we answered 6 research questions about machine learning algorithms. The identification of effective feature selection techniques, data imbalance management techniques, accurate machine learning algorithms, a list of available data sets with their URLs and characteristics, and feature importance based on usage has been identified for diagnosing liver disease. The reason to select this research question is, in any machine learning framework, the role of dimensionality reduction, data imbalance management, machine learning algorithm with its accuracy, and data itself is very significant. Based on the conducted review, a framework, machine learning‐based liver disease diagnosis (MaLLiDD), has been proposed and validated using three datasets. The proposed framework classified liver disorders with 99.56%, 76.56%, and 76.11% accuracy. In conclusion, this article addressed six research questions by identifying effective feature selection techniques, data imbalance management techniques, algorithms, datasets, and feature importance based on usage. It also demonstrated a high accuracy with the framework for early diagnosis, marking a significant advancement. Attique Ur Rehman, Wasi Haider Butt, Tahir Muhammad Ali, Sabeen Javaid, Maram Fahaad Almufareh, Mamoona Humayun, Hameedur Rahman, Azka Mir, Momina Shaheen |
Int. J. Intell. Syst. | 6 |
| 2024 | Advancing database security: a comprehensive systematic mapping study of potential challengesabstractAbstract The value of data to a company means that it must be protected. When it comes to safeguarding their local and worldwide databases, businesses face a number of challenges. To systematically review the literature to highlight the difficulties in establishing, implementing, and maintaining secure databases. In order to better understand database system problems, we did a systematic mapping study (SMS). We’ve analyzed 100 research publications from different digital libraries and found 20 issues after adopting inclusion and exclusion criteria. This SMS study aimed to identify the most up-to-date research in database security and the different challenges faced by users/clients using various databases from a software engineering perspective. In total, 20 challenges were identified related to database security. Our results show that “weak authorization system”, “weak access control”, “privacy issues/data leakage”, “lack of NOP security”, and “database attacks” as the most frequently cited critical challenges. Further analyses were performed to show different challenges with respect to different phases of the software development lifecycle, venue of publications, types of database attacks, and active research institutes/universities researching database security. The organizations should implement adequate mitigation strategies to address the identified database challenges. This research will also provide a direction for new research in this area. Siffat Ullah Khan, Mahmood Khan Niazi, Mamoona Humayun, Najm Us Sama, Arif Ali Khan, Aakash Ahmad |
Wirel. Networks | 4 |
| 2023 | Toward a readiness model for secure software codingabstractAbstract The heart of the application's secure operation is its software code. If the code contains flaws, the entire program might be hacked. The issue with software vulnerabilities is that they reveal coding flaws that hackers could exploit. The prevention of cybersecurity issues begins with the program code itself. When writing software code, a software developer must consider expressing the application's architecture and design requirements, keeping the code streamlined and efficient, and ensuring the code is safe. Secure code helps save the system from various cyber‐attacks by eliminating the weaknesses that many hacks rely on. To assist the software organization in Secure Software Coding (SSC), this article proposes a readiness model for SSC, namely SSCRM. The proposed model has five levels; SSC challenges and best practices (BP) are mapped at each level. The proposed model will help the organizations better understand SSC challenges and BPs and provide a roadmap for developing secure software code. The proposed model was evaluated using three case studies. The findings demonstrate that the proposed approach helps determine an organization's SSC level. Mamoona Humayun, Mahmood Niazi, N. Z. Jhanjhi, Sajjad Mahmood, Mohammad R. Alshayeb |
Softw. Pract. Exp. | 1 |
| 2022 | Secure Critical Data Reclamation Scheme for Isolated Clusters in IoT-Enabled WSNabstractInternet of Things (IoT) comprises of a huge number of connected devices that can communicate within the same network and across the networks. IoT-enabled wireless sensor networks (WSNs) are getting growing interest due to its wide applicability in healthcare, patient monitoring, transportation, and surveillance. The main issue is that the network is mostly deployed in hostile environments where an attacker may physically destroy the CHs or other technical fault may occur. It isolates the cluster and causes loss of sensitive data from that region. This article presents a critical data reclamation (CDR) protocol that provides secure data transmission for isolated clusters. We present the data transfer and data aggregation algorithms for sensing nodes and data receiving and extraction at CH and sink. We performed extensive simulations using NS-2.35. The results prove the dominance of CDR in contrast to counterparts in terms of communication cost, energy consumption, and resilience. Ata Ullah, Muhammad Azeem 0003, Humaira Ashraf, N. Z. Jhanjhi, Lewis Nkenyereye, Mamoona Humayun |
IEEE Internet Things J. | 6 |
| 2015 | Web application security vulnerabilities detection approaches: A systematic mapping studyabstractNumber of security vulnerabilities in web application has grown with the tremendous growth of web application in last two decades. As the domain of Web Applications is maturing, large number of empirical studies has been reported in web applications to address the solution of vulnerable web application. However, before advancing towards finding new approaches of web applications security vulnerability detection, there is a need to analyze and synthesize existing evidence based studies in web applications area. To do this, we have planned to conduct a systematic mapping study to view and report the state-of-the-art of empirical work in existing research of web applications. In this paper, we aimed at providing a description of mapping study for synthesizing the reported empirical research in the area of web applications security vulnerabilities detection approaches. The proposed solutions are mapped against: (1) the software development stages for which the solution has been proposed and (2) the web application vulnerabilities mapping according to OWASP Top 10 security vulnerabilities. To do this, existing literature has been surveyed using a systematic mapping study by phrasing two research questions. In the mapping study, a total of 41 studies dating from 1994 to 2014 were evaluated and mapped against the aforementioned categories. Sajjad Rafique, Mamoona Humayun, Bushra Hamid, Ansar Abbas, Muhammad Akhtar, Kamil Iqbal |
SNPD | 2 |
| 2013 | An empirical study on investigating the role of KMS in promoting trust within GSD teamsabstractThe purpose of this paper is to examine the extent to which KMS usage helps in developing and maintaining trust within GSD project's team members- an area that is very important but has, to date, not been addressed adequately. Design/methodology/approach -- A survey instrument comprising of 7 factors and 35 elements was developed based on tested questions and literature review. Through a web-based survey, data were collected from GSD employees working in different countries that are using KMS for knowledge management. Findings -- The results of the survey revealed that KMS usage is positively related with employee's propensity to trust and cooperative behavior. There exist an indirect positive relationship between KMS and perceived trustworthiness. Further, Leadership support help in promoting the use of KMS for knowledge seeking and contribution within GSD organizations employees. However, the KMS usage is negatively related with monitoring behavior exist within GSD teams. Research limitations/implications -- The number of responses received was rather small since GSD and KMS are both new and emerging disciplines, and not many organizations are formally using KMS for this purpose. Practical implications -- The results of the study suggest that KMS if implemented and used properly helps the GSD organizations in getting the desired benefits of GSD. Further, leaders play an important role in the success of KMS by motivating the employees towards KMS usage. The findings of this study, we hope, will help and facilitate the organizations in making their GSD projects successful. Academics can use the results to build models that further enhance the KMS domain and propose the strategies for improving KMS usage in order to get maximum benefits through KMS. Mamoona Humayun, Gang Cui, Isma Masood |
EASE | 1 |
| 2012 | An Empirical Study on Improving Trust among GSD Teams Using KMR
Mamoona Humayun, Gang Cui |
SEKE | 1 |