VLDB 2026 Research / reviewers in the wild / expert
Mahmoud Nabil 0001
dblp:123/9731 · also M. Nabil Mahmoud, Mahmoud Nabil Mahmoud
· DBLP profile ↗
28ranked-venue papers
4as first author
20since 2021 · last 2026
0000-0003-3059-7912ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 5 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 2 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ADP-Net: Adaptive point network with multi-scale attention mechanism for small object detection
Abenezer Girma, Abdollah Homaifar, Mahmoud Nabil 0001 |
Neurocomputing | 3 |
| 2026 | Consensus-Based Fully Decentralized and Privacy-Preserving Federated Learning in Dynamic AAV Networks Without Key Distribution Center
Mohammed Mynuddin, Zayed Uddin Chowdhury, Reza Ahmari, Ahmad Alsharif, Abdollah Homaifar, Mahmoud Nabil 0001 |
IEEE Internet Things J. | 6 |
| 2026 | Leveraging Functional Encryption and Deep Learning for Privacy-Preserving Traffic ForecastingabstractIn recent years, traffic congestion have become a common problem in modern transportation systems, causing people to spend more time on the road, increased emissions, and elevated safety risks. Intelligent Transportation Systems (ITS) address these issues by integrating cutting-edge technologies, advanced sensing, innovative deep learning algorithms, and driver participation to enable real-time monitoring and predictive traffic management. However, the collection of sensitive driver spatiotemporal location data required for effective real-time analysis raises privacy concerns. Such detailed reporting can inadvertently expose individual travel patterns, daily routines, and personal habits, making drivers vulnerable to profiling, unauthorized surveillance, and even malicious exploitation. To address these challenges, this paper introduces a secure and privacy-preserving traffic forecasting framework that combines k-anonymity with functional encryption to guarantee protection of individual driver information while enabling accurate aggregation of encrypted reports. The aggregated data are then used to train a deep learning architecture that integrates Convolutional Long Short-Term Memory (Conv-LSTM) for spatial and short-term temporal dependencies with Bidirectional LSTM (Bi-LSTM) for capturing long-term periodic traffic patterns for forecasting. Extensive experiments on real-world datasets demonstrate that the proposed scheme achieves high forecasting accuracy, maintaining mean absolute error below 10% for a 60-minute forecasting horizon, while safeguarding driver privacy. Isaac Adom, Mohammad Iqbal Hossain, Hassan Mahmoud, Ahmad Alsharif, Mahmoud Nabil 0001, Yang Xiao 0001 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2025 | A Data-Driven Framework for Performance Assessment of SIEM Solutions
Jason M. Green, Mahmoud Nabil 0001, Abdolhossein Sarrafzadeh, Ahmad Patooghy |
CRiSIS | 2 |
| 2025 | An Experimental Study of Trojan Vulnerabilities in UAV Autonomous LandingabstractThis study investigates the vulnerabilities of autonomous navigation and landing systems in Urban Air Mobility (UAM) vehicles. Specifically, it focuses on Trojan attacks that target deep learning models, such as Convolutional Neural Networks (CNNs). Trojan attacks work by embedding covert triggers within a model’s training data. These triggers cause specific failures under certain conditions, while the model continues to perform normally in other situations.We assessed the vulnerability of Urban Autonomous Aerial Vehicles (UAAVs) using the DroNet framework. Our experiments showed a significant drop in accuracy, from 96.4% on clean data to 73.3% on data triggered by Trojan attacks. To conduct this study, we collected a custom dataset and trained models to simulate real-world conditions. We also developed an evaluation framework designed to identify Trojan-infected models. This work demonstrates the potential security risks posed by Trojan attacks and lays the groundwork for future research on enhancing the resilience of UAM systems. Reza Ahmari, Ahmad Mohammadi, Vahid Hemmati, Mohammed Mynuddin, Mahmoud Nabil 0001, Parham M. Kebria, Abdollah Homaifar, Mehrdad Saif |
SMC | 5 |
| 2025 | GPS Spoofing Attack Detection in Autonomous Vehicles Using Adaptive DBSCANabstractAs autonomous vehicles become an essential component of modern transportation, they are increasingly vulnerable to threats such as GPS spoofing attacks. This study presents an adaptive detection approach utilizing a dynamically tuned Density Based Spatial Clustering of Applications with Noise (DBSCAN) algorithm, designed to adjust the detection threshold (ε) in real-time. The threshold is updated based on the recursive mean and standard deviation of displacement errors between GPS and in-vehicle sensors data, but only at instances classified as non-anomalous. Furthermore, an initial threshold, determined from 120,000 clean data samples, ensures the capability to identify even subtle and gradual GPS spoofing attempts from the beginning. To assess the performance of the proposed method, five different subsets from the real-world Honda Research Institute Driving Dataset (HDD) are selected to simulate both large and small magnitude GPS spoofing attacks. The modified algorithm effectively identifies turn-by-turn, stop, overshoot, and multiple small biased spoofing attacks, achieving detection accuracies of 98.62±1%, 99.96±0.1%, 99.88±0.1%, and 98.38±0.1%, respectively. This work provides a substantial advancement in enhancing the security and safety of AVs against GPS spoofing threats. Ahmad Mohammadi, Reza Ahmari, Vahid Hemmati, Frederick Owusu-Ambrose, Mahmoud Nabil 0001, Parham M. Kebria, Abdollah Homaifar, Mehrdad Saif |
SMC | 5 |
| 2025 | TrustTrade: A Trustworthy IoT Data Marketplace With Post-Trading Accountability
Hassan Mahmoud, Mahmoud Nabil 0001, Ahmad Alsharif |
IEEE Internet Things J. | 2 |
| 2024 | Poisoning Attack Mitigation for Privacy-Preserving Federated Learning-Based Energy Theft DetectionabstractIn federated learning (FL) based electricity theft detection, detection nodes (DNs) locally train deep learning models on consumers' data and share only the local model parameters with an aggregation server (AS) to generate a global model shared by all nodes for better detection accuracy. However, several privacy concerns should be addressed including membership and inference attacks. To mitigate these attacks, several privacy-preserving aggregation schemes have been introduced. Nevertheless, existing FL detectors often overlook the threat of poisoning attacks, in which certain DNs hold maliciously labeled, i.e., poisoned, data during the training. This manipulated data can subsequently be exploited to introduce backdoors into the global model after its deployment. This paper introduces a novel approach that enhances privacy and resilience against poisoning attacks in FL-based electricity theft detection within smart grids. Our approach enables encrypting local parameters before sending them to the AS, thus safeguarding consumers' privacy. Additionally, it utilizes a cosine similarity test over encrypted data to detect and mitigate poisoning attacks by filtering out malicious local gradients from being considered in the global model computation. Through extensive evaluations, we demonstrate the effectiveness of our FL-based detector in substantially reducing the poisoning attack success rate even when 50% of DNs train their local models with malicious targeted power consumption data, all while preserving consumers' privacy. Mahmoud Srewa, Michaela F. Winfree, Mohamed I. Ibrahem, Mahmoud Nabil 0001, Rongxing Lu, Ahmad Alsharif |
ICC | 4 |
| 2024 | Decentralized Federated Learning Using the Metropolis-Hastings for Highly Dynamic UAVsabstractUnmanned Aerial Vehicles (UAVs) are increasingly employed in cooperative surveillance missions where data collection across disparate areas is crucial. In such systems, data from all UAVs is collected and processed in a central server, making it vulnerable to breaches and unauthorized access. Federated Learning (FL) addresses these concerns by enabling collaborative model training without centralized data collection. In FL, each UAV trains a local model on its own data and only shares the model updates with a central server. The central server then aggregates these parameters to update a global model, which is redistributed to all participating UAVs. However, FL’s reliance on a central server introduces challenges, especially in geographically highly dynamic and dispersed scenarios. The central server can become a single point of failure and may struggle with the communication overhead and latency issues inherent in such dynamic environments. To overcome these limitations, this paper proposes a decentralized federated learning framework for multi-agent UAV systems. This approach facilitates direct sharing of local deep learning (DL) model parameters among UAVs, eliminating the need for a central server. Our approach employs the Metropolis-Hastings algorithm to ensure UAVs achieve consensus on shared model parameters, ensuring balanced weight distribution and stable training processes. We validate our fully distributed DL model aggregation using the ResNet-18 model. Our results confirm DFL’s effectiveness in achieving low RMSE values and rapid convergence, comparable to centralized FL, across dynamic UAV networks. Mohammed Mynuddin, Zayed Uddin Chowdhury, Reza Ahmari, Mahmoud Nabil 0001, Ahmad Alsharif, Abdollah Homaifar |
VTC Fall | 4 |
| 2024 | Securing Smart Grid False Data Detectors Against White-Box Evasion Attacks Without Sacrificing AccuracyabstractIn the realm of smart grids, smart meters can be hacked to report false data to lower the consumers’ electricity bills. While machine learning (ML) techniques have shown promise in detecting false data, they are also prone to adversarial attacks, such as evasion attacks. This article investigates the impact of gradient-ensemble-based evasion attacks on the smart grid ML-based false data detectors, focusing on the white-box threat model where attackers possess detailed knowledge of the defense mechanism. First, we examines the vulnerability of three detectors (consumer-based, cluster-based, and global) to gradient-based evasion attacks. The evaluation results show an inverse relationship between robustness of the detectors and regularization (i.e., generalization), where higher data set variability usually causes higher regularization. Notably, minimal regularization level is observed when electricity consumption patterns are close. Our findings also indicate that the consumer-based detector exhibits higher accuracy and robustness but remains susceptible to zero day attacks and demands substantial computational resources for training an ML model for each consumer. In contrast, the cluster-based detector improves accuracy and exhibits satisfactory robustness compared to the global detector. Subsequently, we proposes two parallel-ensemble approaches (stacking and voting) for the cluster-based false data detectors trained on the adversarial samples. The evaluation results demonstrate that integrating clustering, adversarial training, and ensemble methods, the proposed detector enhances robustness against gradient-ensemble-based evasion attacks while significantly boosting accuracy. This stands in contrast to benchmark defenses, which often face a tradeoff between accuracy and robustness, sacrificing accuracy to bolster resilience against evasion attacks. Islam Elgarhy, Mahmoud M. Badr, Mohamed Mahmoud 0001, Mahmoud Nabil 0001, Maazen Alsabaan, Mohamed I. Ibrahem |
IEEE Internet Things J. | 4 |
| 2023 | Enabling Content-Centric Device-to-Device Communication in the Millimeter-Wave BandabstractThe growth in wireless traffic and mobility of devices have congested the core network significantly. This bottleneck, along with spectrum scarcity, made the conventional cellular networks insufficient for the dissemination of large contents. The ability of content-centric networking (CCN) and device-to-device (D2D) communication in offloading the network and huge unlicensed spectrum at millimeter-wave (mmWave) band, make the integration of CCN with D2D communication in the mmWave band a viable solution to improve the network's throughput. In this paper, we propose a novel scheme that enables efficient initialization of CCN-based D2D networks in the mmWave band through addressing decentralized D2D peer association and antenna beamwidth selection. The proposed scheme considers mmWave characteristics such as directional communication and blockage susceptibility. We propose a heuristic peer association algorithm to associate D2D users using context information, including link stability time and content availability. We model the beamwidth selection problem as a potential game and propose a synchronous log-linear learning algorithm to obtain the game's optimal Nash equilibrium. The performance of the proposed scheme in terms of data throughput and transmission efficiency is evaluated through extensive simulations. Simulation results show that the proposed scheme improves network performance significantly and outperforms other methods in the literature. Niloofar Bahadori, Mahmoud Nabil 0001, Brian Kelley, Abdollah Homaifar |
IEEE Trans. Mob. Comput. | 2 |
| 2022 | Identifying Anomalous Flight Trajectories by leveraging ensembled outlier detection frameworkabstractIncreased traffic density with a greater degree of increased automation in aviation is expected within the next decade. Therefore, airspace capacity will become more congested and result in increasing challenges for detecting conflicts between aerial vehicles. Furthermore, because these vehicles rely on surrounding vehicles following a planned path, it is essential to identify flights not following a planned direction. In this paper, we utilize an ensemble of the existing outlier detection approaches for identifying the anomalous flight trajectories. In the initial step, flight trajectories are preprocessed to extract and process vital features, with the next step of having twenty different outlier detection algorithms assembled to classify trajectories. Throughout our extensive experiments and comparison studies, promising results are shown including the effectiveness of different anomaly detection algorithms and how utilizing feature engineering can improve the results of these outlier detection methods. Mikol Forney, Xuyang Yan, Kishor Datta Gupta, Mahmoud Nabil 0001, Abdollah Homaifar |
IJCNN | 4 |
| 2022 | Detecting Sybil Attacks Using Proofs of Work and Location in VANETsabstractVehicular Ad Hoc Networks (VANETs) have the potential to enable the next-generation Intelligent Transportation Systems (ITS). In ITS, data contributed by vehicles can build a spatio-temporal view of traffic statistics, which can improve road safety and reduce slow traffic and jams. To preserve drivers’ privacy, vehicles should use multiple pseudonyms instead of only one identity. However, vehicles may exploit this abundance of pseudonyms and launch Sybil attacks by pretending to be multiple vehicles. Then, these Sybil (or fake) vehicles report false data, e.g., to create fake congestion or pollute traffic management data. In this article, we propose a Sybil attack detection scheme using proofs of work and location. The idea is that each road side unit (RSU) issues a signed time-stamped tag as a proof for the vehicle’s anonymous location. Proofs sent from multiple consecutive RSUs are used to create a trajectory which is used as vehicle anonymous identity. Also, contributions from one RSU are not enough to create trajectories, rather the contributions of several RSUs are needed. By this way, attackers need to compromise an infeasible number of RSUs to create fake trajectories. Moreover, upon receiving the proof of location from an RSU, the vehicle should solve a computational puzzle by running proof of work (PoW) algorithm. Then, it should provide a valid solution (proof of work) to the next RSU before it can obtain a proof of location. Using the PoW can prevent the vehicles from creating multiple trajectories in case of low-dense RSUs. To report an event, the vehicle has to send the latest trajectory to an event manager. Then, the event manager uses a matching technique to identify the trajectories sent from Sybil vehicles. The scheme depends on the fact that the Sybil trajectories are bounded physically to one vehicle, and therefore, their trajectories should overlap. Extensive experiments and simulations demonstrate that our scheme achieves high detection rate of Sybil attacks with low false negative and acceptable communication and computation overhead. Mohamed Baza, Mahmoud Nabil 0001, Mohamed Mahmoud 0001, Niclas Bewermeier, Kemal Fidan, Waleed Alasmary, Mohamed M. Abdallah 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Privacy-Preserving and Collusion-Resistant Charging Coordination Schemes for Smart GridsabstractCharging coordination is necessary for the successful integration of the Energy Storage Units (ESUs), including electric vehicles and home batteries, into the smart grid. To coordinate charging, the ESUs should send charging requests including time-to-complete-charging (TCC) and battery state-of-charge (SoC) to the charging controller (CC) for scheduling charging, but these data can reveal sensitive information on the ESUs’ owners such as their locations, when they return home and whether they are on travel. In this article, we propose centralized and decentralized privacy-preserving and collusion-resistant charging coordination schemes for ESUs. In the centralized scheme, ESUs authenticate their requests using anonymous tokens. To thwart linkability attacks where the CC uses TCC and SoC to link requests sent from the same ESU at consecutive time slots, an ESU needs to send multiple charging requests with different TCC and SoC values instead of only one request. In the decentralized scheme, charging is coordinated in a distributed way using a privacy-preserving data aggregation technique. The idea is that each ESU selects some ESUs to act as proxies, and shares a secret mask with each proxy. Then, each ESU adds a mask to its charging request and encrypts it so that by aggregating all requests, all masks are nullified and the total charging demand is known, and then it is used to compute the charging schedules. Due to using masking technique, the scheme is secure against collusion attacks. The results of extensive experiments and simulations confirm that our schemes are efficient and secure, and can preserve ESU owners’ privacy and thwart linkability attacks. Mohamed Baza, Marbin Pazos-Revilla, Ahmed B. T. Sherif, Mahmoud Nabil 0001, Abdulah Jeza Aljohani, Mohamed Mahmoud 0001, Waleed Alasmary |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | A Review on Human-Machine Trust Evaluation: Human-Centric and Machine-Centric PerspectivesabstractAs complex autonomous systems become increasingly ubiquitous, their deployment and integration into our daily lives will become a significant endeavor. Human–machine trust relationship is now acknowledged as one of the primary aspects that characterize a successful integration. In the context of human–machine interaction (HMI), proper use of machines and autonomous systems depends both on the human and machine counterparts. On one hand, it depends on how well the human relies on the machine regarding the situation or task at hand based on willingness and experience. On the other hand, it depends on how well the machine carries out the task and how well it conveys important information on how the job is done. Furthermore, proper calibration of trust for effective HMI requires the factors affecting trust to be properly accounted for and their relative importance to be rightly quantified. In this article, the functional understanding of human–machine trust is viewed from two perspectives—human-centric and machine- centric. The human aspect of the discussion outlines factors, scales, and approaches, which are available to measure and calibrate human trust. The discussion on the machine aspect spans trustworthy artificial intelligence, built-in machine assurances, and ethical frameworks of trustworthy machines. Biniam Gebru, Lydia Zeleke, Daniel Blankson, Mahmoud Nabil 0001, Shamila Nateghi, Abdollah Homaifar, Edward W. Tunstel |
IEEE Trans. Hum. Mach. Syst. | 4 |
| 2021 | Detection of Denial of Charge (DoC) Attacks in Smart Grid Using Convolutional Neural NetworksabstractSpatial-temporal charging coordination mechanisms are developed to avoid electrical overload at the charging stations and extravagant waiting time for electric vehicle drivers. Though, attackers could attack these mechanisms by launching distributed attacks against charging stations to prevent legitimate drivers from charging their vehicles. To attack a charging station, an attacker can compromise a set of vehicles, e.g., by disseminating a malware, and instruct them to send fake charging requests simultaneously to reserve the available energy capacity that is provided to a charging station without having the intention for charging, and thus benign vehicles do not find charging slots. This paper introduces an anomaly-based detection technique to identify the charging stations under this denial of charge (DoC) attacks using convolutional neural networks. The main idea is that each charging station has a normal energy demand pattern and launching DoC attacks changes this pattern. To capture such anomalous pattern, we use convolutional neural model to capture the temporal features within the demand of the charging station. To train our anomaly detector, we first create a benign dataset that could be utilized in other research areas such as load forecast and energy management. Then, we introduce a group of attacks that are used to create the malicious dataset. Finally, we used the benign and malicious datasets to train and test the deep neural model to detect DoC attacks. Our experiments show that our detector has high detection and low false alarm rates. Ahmad Shafee, Mahmoud Nabil 0001, Mohamed Mahmoud 0001, Waleed Alasmary, Fathi H. Amsaad 0001 |
ISNCC | 2 |
| 2021 | DA2-Net : Diverse & Adaptive Attention Convolutional Neural NetworkabstractStandard Convolutional Neural Network (CNN) designs rarely focus on the importance of explicitly capturing diverse features to enhance the network’s performance. Instead, most existing methods follow an indirect approach of increasing or tuning the networks’ depth and width, which in many cases significantly increase the computational cost. Inspired by biological visual system, we proposes a Diverse and Adaptive Attention Convolutional Network (DA2-Net), which enables any feed-forward CNNs to explicitly capture diverse features and adaptively select and emphasize the most informative features to efficiently boost the network’s performance. DA2-Net incurs negligible computational overhead and it is designed to be easily integrated with any CNN architecture. We extensively evaluated DA2-Net on benchmark datasets, including CIFAR100, SVHN, and ImageNet, with various CNN architectures. The experimental results show DA2-Net provides a significant performance improvement with very minimal computational overhead. Abenezer Girma, Abdollah Homaifar, Mahmoud Nabil 0001, Xuyang Yan, Mrinmoy Sarkar |
SMC | 3 |
| 2021 | A Robust Completed Local Binary Pattern (RCLBP) for Surface Defect DetectionabstractIn this paper, we present a Robust Completed Local Binary Pattern (RCLBP) framework for a surface defect detection task. Our approach uses a combination of Non-Local (NL) means filter with wavelet thresholding and Completed Local Binary Pattern (CLBP) to extract robust features which are fed into classifiers for surface defects detection. This paper combines three components: A denoising technique based on Non-Local (NL) means filter with wavelet thresholding is established to denoise the noisy image while preserving the textures and edges. Second, discriminative features are extracted using the CLBP technique. Finally, the discriminative features are fed into the classifiers to build the detection model and evaluate the performance of the proposed framework. The performance of the defect detection models are evaluated using a real-world steel surface defect database from Northeastern University (NEU). Experimental results demonstrate that the proposed approach RCLBP is noise robust and can be applied for surface defect detection under varying conditions of intraclass and inter-class changes and with illumination changes. Nana Kankam Gyimah, Abenezer Girma, Mahmoud Nabil 0001, Shamila Nateghi, Abdollah Homaifar, Daniel Opoku |
SMC | 3 |
| 2021 | Efficient Privacy-Preserving Electricity Theft Detection With Dynamic Billing and Load Monitoring for AMI NetworksabstractIn advanced metering infrastructure (AMI), smart meters (SMs) are installed at the consumer side to send fine-grained power consumption readings periodically to the system operator (SO) for load monitoring, energy management, and billing. However, fraudulent consumers launch electricity theft cyber attacks by reporting false readings to reduce their bills illegally. These attacks do not only cause financial losses but may also degrade the grid performance because the readings are used for grid management. To identify these attackers, the existing schemes employ machine-learning models using the consumers' fine-grained readings, which violates the consumers' privacy by revealing their lifestyle. In this article, we propose an efficient scheme that enables the SO to detect electricity theft, compute bills, and monitor load while preserving the consumers' privacy. The idea is that SMs encrypt their readings using functional encryption (FE), and the SO uses the ciphertexts to: 1) compute the bills following the dynamic pricing approach; 2) monitor the grid load; and 3) evaluate a machine-learning model to detect fraudulent consumers, without being able to learn the individual readings to preserve consumers' privacy. We adapted an FE scheme so that the encrypted readings are aggregated for billing and load monitoring and only the aggregated value is revealed to the SO. Also, we exploited the inner-product operations on encrypted readings to evaluate a machine-learning model to detect fraudulent consumers. The real data set is used to evaluate our scheme, and our evaluations indicate that our scheme is secure and can detect fraudulent consumers accurately with low communication and computation overhead. Mohamed I. Ibrahem, Mahmoud Nabil 0001, Mostafa Fouda, Mohamed Mahmoud 0001, Waleed Alasmary, Fawaz Alsolami 0001 |
IEEE Internet Things J. | 2 |
| 2021 | Efficient and Privacy-Preserving Ridesharing Organization for Transferable and Non-Transferable ServicesabstractRidesharing allows multiple persons to share one vehicle for their trips instead of using multiple vehicles. Ridesharing can reduce the number of vehicles in the street, which consequently can reduce air pollution, traffic congestion, and transportation cost. However, ridesharing organization requires passengers to report sensitive location information about their trips to a trip organizing server (TOS) which creates a serious privacy issue. The existing ridesharing organization schemes are neither flexible nor scalable in the sense that they require a driver and a rider to have exactly the same trip to share a ride, and they are inefficient if applied to large geographic areas. In this paper, we propose two efficient privacy-preserving ridesharing organization schemes for Non-transferable Ridesharing Service (NRS) and Transferable Ridesharing Service (TRS). In NRS, a rider shares a ride from his/her trip's start to the destination with only one driver, whereas, in TRS, a rider can transfer between multiple drivers while en route until he reaches his destination. In the proposed schemes, the ridesharing area is divided into a number of small geographic areas, called cells, and each cell has a unique identifier. Each driver/rider should encrypt his/her trip's data with modified kNN encryption scheme, and send an encrypted ridesharing offer/request to the TOS. In NRS scheme, Bloom filters are used to represent the trip information compactly before encryption. Then, the TOS can measure the similarity of the encrypted trips to organize shared rides without revealing either the users' identities or the locations. In TRS scheme, drivers report their encrypted routes, and then the TOS builds a directed graph that is passed to a modified version of Dijkstra's shortest path algorithm to search for an optimal path for rides that can achieve a set of preferences prescribed by the riders. Although TRS can be used to organize non-transferable trips, performance evaluation shows that NRS requires less communication overhead than TRS. Our formal privacy proof and analysis demonstrate that the proposed schemes can preserve users privacy and our experimental results using routes extracted from real maps show that the proposed schemes can be used efficiently for large cities. Mahmoud Nabil 0001, Ahmed B. T. Sherif, Mohamed Mahmoud 0001, Ahmad Alsharif, Mohamed M. Abdallah 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Mimic Learning to Generate a Shareable Network Intrusion Detection ModelabstractPurveyors of malicious network attacks continue to increase the complexity and the sophistication of their techniques, and their ability to evade detection continues to improve as well. Hence, intrusion detection systems must also evolve to meet these increasingly challenging threats. Machine learning is often used to support this needed improvement. However, training a good prediction model can require a large set of labeled training data. Such datasets are difficult to obtain because privacy concerns prevent the majority of intrusion detection agencies from sharing their sensitive data. In this paper, we propose the use of mimic learning to enable the transfer of intrusion detection knowledge through a teacher model trained on private data to a student model. This student model provides a mean of publicly sharing knowledge extracted from private data without sharing the data itself. Our results confirm that the proposed scheme can produce a student intrusion detection model that mimics the teacher model without requiring access to the original dataset. Ahmad Shafee, Mohamed Baza, Douglas A. Talbert, Mostafa Fouda, Mahmoud Nabil 0001, Mohamed Mahmoud 0001 |
CCNC | 5 |
| 2020 | A Blockchain-based Medical Data Marketplace with Trustless Fair Exchange and Access ControlabstractThe unprecedented growth of decentralized technologies and the abundance of healthcare data creates numerous opportunities for the digital healthcare industry and poses major challenges for data security. In this paper, we propose a novel decentralized blockchain-based medical data marketplace in which medical record sellers can sell their data to interested buyers, e.g., pharmaceutical corporations. Sellers use a smart contract to exchange their records with buyers for a digital currency. In our model, sellers can enforce flexible access control policy on the encrypted records while allowing the buyers to verify the correctness of the encrypted records without revealing any information about the records using the developed zk-SNARK protocol. In addition, sellers acquire a proof-of-delivery to redeem buyers' contingent payments by exchanging a record access key for a buyer signature using the developed trustless zero-knowledge contingent payment protocol. Our security analysis proves that our model is secure against malicious behaviors of both dishonest sellers/buyers. Performance evaluation indicates that the GAS cost on Etherume blockchain and the computational cost of the cryptographic operations are low. Ahmad Alsharif, Mahmoud Nabil 0001 |
GLOBECOM | 2 |
| 2019 | Blockchain-based Firmware Update Scheme Tailored for Autonomous VehiclesabstractRecently, Autonomous Vehicles (AVs) have gained extensive attention from both academia and industry. AVs are a complex system composed of many subsystems, making them a typical target for attackers. Therefore, the firmware of the different subsystems needs to be updated to the latest version by the manufacturer to fix bugs and introduce new features, e.g., using security patches. In this paper, we propose a distributed firmware update scheme for the AVs' subsystems, leveraging blockchain and smart contract technology. A consortium blockchain made of different AVs manufacturers is used to ensure the authenticity and integrity of firmware updates. Instead of depending on centralized third parties to distribute the new updates, we enable AVs, namely distributors, to participate in the distribution process and we take advantage of their mobility to guarantee high availability and fast delivery of the updates. To incentivize AVs to distribute the updates, a reward system is established that maintains a credit reputation for each distributor account in the blockchain. A zero-knowledge proof protocol is used to exchange the update in return for a proof of distribution in a trustless environment. Moreover, we use attribute-based encryption (ABE) scheme to ensure that only authorized AVs will be able to download and use a new update. Our analysis indicates that the additional cryptography primitives and exchanged transactions do not affect the operation of the AVs network. Also, our security analysis demonstrates that our scheme is efficient and secure against different attacks. Mohamed Baza, Mahmoud Nabil 0001, Noureddine Lasla, Kemal Fidan, Mohamed Mahmoud 0001, Mohamed M. Abdallah 0001 |
WCNC | 2 |
| 2019 | MDMS: Efficient and Privacy-Preserving Multidimension and Multisubset Data Collection for AMI NetworksabstractAdvanced metering infrastructure (AMI) networks allow utility companies to collect fine-grained power consumption data of electricity consumers for load monitoring and energy management. This brings serious privacy concerns since the fine-grained power consumption data can expose consumers' activities. Privacy-preserving data aggregation techniques have been used to preserve consumers' privacy while allowing the utility to obtain only the consumers total consumption. However, most of the existing schemes do not consider the multidimensional nature of power consumption in which electricity consumption can be categorized based on the consumption type. They also do not consider multisubset data collection in which the utility should be able to obtain the number of consumers whose consumption lies within a specific consumption range, and the overall consumption of each set of consumers. In this article, we propose an efficient and privacy-preserving multidimensional and multisubset data collection scheme, named “MDMS. ” In MDMS, the utility can obtain the total power consumption as well as the number of consumers of each subset in each dimension. In addition, for better scalability, MDMS allows the utility to delegate bill computation to the AMI networks' gateways using the encrypted readings and following the dynamic prices in which electricity prices are different based on both the time and the consumption type. Moreover, MDMS uses lightweight operations in encryption, aggregation, and decryption resulting in low computation and communication overheads as given in our experimental results. Our security analysis demonstrates that MDMS is secure and can resist collusion attacks that aim to reveal the consumers' readings. Ahmad Alsharif, Mahmoud Nabil 0001, Ahmed B. T. Sherif, Mohamed Mahmoud 0001, Min Song 0002 |
IEEE Internet Things J. | 2 |
| 2019 | EPIC: Efficient Privacy-Preserving Scheme With EtoE Data Integrity and Authenticity for AMI NetworksabstractIn this paper, we propose EPIC, an efficient and privacy-preserving data collection scheme with EtoE data integrity verification for advanced metering infrastructure networks. Using efficient cryptographic operations, each meter should send a masked reading to the utility such that all the masks are canceled after aggregating all meters' masked readings, and thus the utility can only obtain an aggregated reading to preserve consumers' privacy. The utility can verify the aggregated reading integrity without accessing the individual readings to preserve privacy. It can also identify the attackers and compute electricity bills efficiently by using the fine-grained readings without violating privacy. Furthermore, EPIC can resist collusion attacks in which the utility colludes with a relay node to extract the meters' readings. A formal proof and probabilistic analysis are used to evaluate the security of EPIC, and ns-3 is used to implement EPIC and evaluate the network performance. In addition, we compare EPIC to existing data collection schemes in terms of overhead and security/privacy features. Ahmad Alsharif, Mahmoud Nabil 0001, Samet Tonyali, Hawzhin Mohammed, Mohamed Mahmoud 0001, Kemal Akkaya |
IEEE Internet Things J. | 2 |
| 2018 | Efficient Multi-Keyword Ranked Search over Encrypted Data for Multi-Data-Owner SettingsabstractThe availability of high-performance computing platforms, large storage devices, and high- speed communications have boosted the popularity of cloud computing. Users exploit these capabilities by using the cloud as a repository for their data and sharing these data with others. However, since the cloud is usually owned and operated by private companies, storing sensitive data in the cloud servers raises privacy concerns. To address these concerns, privacy-preserving keyword search schemes have been developed. Nevertheless, most of the existing schemes are either inefficient for multi-data- owner settings or designed for single-data-owner settings, and becomes insecure and inefficient when used for multi-data-owner. This paper proposes an efficient multi-keyword ranked search scheme over encrypted data for multi-data-owner settings. The proposed scheme allows each data owner and each user to have a distinct key, and allows the server to efficiently search the files of different data owners using one encrypted query sent by the user. Our privacy analysis demonstrates that the proposed scheme can preserve the privacy of the data owners and users. In addition, our extensive performance evaluations demonstrate that our scheme is much more efficient than existing approaches in the literature. Mahmoud Nabil 0001, Ahmad Alsharif, Ahmed B. T. Sherif, Mohamed Mahmoud 0001, Mohamed F. Younis |
ICC | 1 |
| 2018 | Deep Recurrent Electricity Theft Detection in AMI Networks with Random Tuning of Hyper-parametersabstractModern smart grids rely on advanced metering infrastructure (AMI) networks for monitoring and billing purposes. However, such an approach suffers from electricity theft cyberattacks. Different from the existing research that utilizes shallow, static, and customer-specific-based electricity theft detectors, this paper proposes a generalized deep recurrent neural network (RNN)-based electricity theft detector that can effectively thwart these cyberattacks. The proposed model exploits the time series nature of the customers' electricity consumption to implement a gated recurrent unit (GRU)-RNN, hence, improving the detection performance. In addition, the proposed RNN-based detector adopts a random search analysis in its learning stage to appropriately fine-tune its hyper-parameters. Extensive test studies are carried out to investigate the detector's performance using publicly available real data of 107,200 energy consumption days from 200 customers. Simulation results demonstrate the superior performance of the proposed detector compared with state-of-the-art electricity theft detectors. Mahmoud Nabil 0001, Muhammad Ismail 0001, Mohamed Mahmoud 0001, Mostafa Shahin, Khalid A. Qaraqe, Erchin Serpedin |
ICPR | 1 |
| 2015 | ASTD: Arabic Sentiment Tweets DatasetabstractThis paper introduces ASTD, an Arabic social sentiment analysis dataset gathered from Twitter.It consists of about 10,000 tweets which are classified as objective, subjective positive, subjective negative, and subjective mixed.We present the properties and the statistics of the dataset, and run experiments using standard partitioning of the dataset.Our experiments provide benchmark results for 4 way sentiment classification on the dataset. Mahmoud Nabil 0001, Mohamed A. Aly, Amir F. Atiya |
EMNLP | 1 |