Zahra Pooranian

dblp:127/7438 · DBLP profile ↗
← Back
22ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0003-3767-0377ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 1 first-author · 5 since 2021Systems, architecture and hardware · 6 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 GAN-Augmented and LLM-Enhanced Intrusion Detection for Intelligent Vehicles
Elizaveta Andrushkevich, Zahra Pooranian, Chuan Heng Foh, Rocío Pérez de Prado, Fabio Martinelli, Mohammad Shojafar
WCNC2
2025 Enhancing the Robustness of Federated Learning-Based Intrusion Detection Systems in Transportation Networks
abstract
As transportation systems become more connected and automated, strong cybersecurity is essential. This paper presents a novel Intrusion Detection System (IDS) based on Federated Learning (FL) to improve security in transportation networks without compromising user privacy. FL enables multiple devices, such as vehicles and roadside units, to collaboratively train a shared model using local data. We focus on major challenges such as adversarial and data poisoning attacks that can disrupt system operations and reduce detection accuracy. To address these threats, we propose new techniques using model diversity and progressive training. These methods allow different network nodes to train slightly different models, making the system more resilient to attacks. Our experimental results on realworld datasets show that model diversity can improve accuracy by up to 25% under attack scenarios. Progressive training also helps reduce prediction errors by 40%, leading to better overall system performance. The proposed approach strengthens the robustness and adaptability of FL-based IDS in dynamic and hostile transportation environments.
Ramin Taheri, Zahra Pooranian, Fabio Martinelli
HPCC2
2025 EEGAP: ECC-Based Efficient Group Authentication Protocol for Dynamic Vehicular Platoon
abstract
Vehicular platooning has emerged as a promising paradigm in intelligent transportation, offering significant benefits such as reduced energy consumption, improved road throughput and mitigated traffic congestion. However, the open nature of vehicular communication channels exposes platoons to a wide range of security and privacy threats. Although existing group key-based protocols provide foundational security services, they often incur substantial computation overhead and insufficiently address vehicle privacy, making them unsuitable for dynamic vehicular platoon. Therefore, this paper introduces an efficient group authentication protocol (EEGAP) for dynamic vehicular platoons, which ensures privacy-preserving and secure communication during platoon restructuring operations, such as merging and splitting, by integrating anonymous authentication, fog computing, and group key agreement mechanisms. Leveraging Elliptic Curve Cryptography (ECC) and secret sharing mechanisms, EEGAP enables lightweight yet robust group key negotiation, reducing computation overhead by 7.08% and communication overhead by 6.85% compared to existing schemes. Both formal security proofs and informal analysis confirm that EEGAP satisfies the stringent security requirements of vehicular platoon communication systems.
Hongyuan Cheng, Jingcheng Song, Zahra Pooranian, Fabio Martinelli, Mohammad Shojafar
IEEE Trans. Intell. Transp. Syst.5
2025 LFD-IDS: Bagging-Based Data Poisoning Attacks Against Cyberattack Detection in Connected Vehicle
abstract
This paper explores the need for new systems to detect and monitor cyberattacks in Connected Vehicles (CVs). Sensor health in CVs is vital, as prediction errors and communication issues can weaken the sensor network. Intrusion Detection Systems (IDS) for CVs must be continuously updated to meet changing needs and be robust against adversarial attacks. We developed a new Label Flipping system against Deep learning-based IDS (LFD-IDS) to help cloud operators understand unusual vehicle sensor data. LFD-IDS specifically targets detecting and explaining sensor data manipulation from poisoning attacks. We proposed two label-flipping attacks based on Bootstrapping and Bagging and a defensive strategy using a multi-layer deep neural network. Our LFD-IDS achieves at least 90% accuracy in identifying cyberattacks.
Zahra Pooranian, Rahim Taheri, Fabio Martinelli
IEEE Trans. Intell. Transp. Syst.1
2024 An Edge Server Deployment Strategy for Multi-Objective Optimization in the Internet of Vehicles
abstract
This paper proposes an edge server deployment strategy based on multi-agent reinforcement learning (CKM-MAPPO) to address the multi-objective optimization problem in a vehicle networking environment. CKM-MAPPO focuses on optimizing the load balancing among edge servers and minimizing edge servers’ delay and energy consumption. Firstly, the Canopy and K-means algorithms determine the edge server deployment’s number and initial location. Then, we utilize the multi-agent reinforcement learning algorithm to decide the optimal deployment location of the edge server. We performed a series of tests, and the experimental results show that CKM-MAPPO improves load balancing by 26.5% and reduces delay and energy consumption by 12.4% and 17.9%, respectively.
Zhou Zhou 0001, Zahra Pooranian, Mohammad Shojafar, Fabio Martinelli
ISCC2
2023 A Heterogenous IoT Attack Detection Through Deep Reinforcement Learning: A Dynamic ML Approach
abstract
This paper presents an innovative Intrusion Detection System (IDS) architecture using Deep Reinforcement Learning (DRL). To accomplish this, we started by analysing the DRL issue for IoT devices, followed by designing intruder attacks using Label Flipping Attack (LFA). We propose an artificial intelligence DRL model to imitate IoT attack detection, along with two defence strategies: Label-based Semi-supervised Defence (LSD) and Clustering-based Semi-supervised Defence (CSD). Finally, we provide the evaluation results of the adaptive attack and defence models on multiple IoT scenarios with the NSL-KDD, IoT-23, and NBaIoT datasets. The research proves that DRL functions effectively with dynamically produced traffic in contrast to existing conventional techniques.
Roshan Baby, Zahra Pooranian, Mohammad Shojafar, Rahim Tafazolli
ICC2
2023 RCA-IDS: A Novel Real-time Cloud-based Adversarial IDS for Connected Vehicles
abstract
This paper focuses on the requirement for creating novel frameworks to monitor and identify cyberattacks in Connected Vehicles (CVs). The health of the sensors in CVs becomes crucial when performance predictions and communication-related errors can compromise the resilience of the sensory network. To meet the evolving demands of connected vehicle (CV) systems, Intrusion Detection Systems (IDS) must be regularly updated and tailored as powerful monitoring entities. To equip cloud-tied operators with the ability to comprehend unusual sensor data originating from vehicles at the cloud level, we designed an innovative Real-time Cloud-based Adversarial IDS called RCA-IDS. This system exclusively focuses on detecting and explaining instances of sensor data manipulation caused by poisoning attacks. Two attack mechanisms were created utilizing random-based and silhouette-based clustering methods. Subsequently, two defence mechanisms based on multi-layer neural network-type deep learning were proposed to counter these attacks. The newly introduced RCA-IDS demonstrates a minimum accuracy of 90% in detecting cyberattacks.
Zahra Pooranian, Mohammad Shojafar, Pedram Asef, Harry Lees, Mark Longden
TrustCom1
2022 iFaaSBus: A Security- and Privacy-Based Lightweight Framework for Serverless Computing Using IoT and Machine Learning
abstract
As data of COVID-19 patients is increasing, the new framework is required to secure the data collected from various Internet of Things (IoT) devices and predict the trend of disease to reduce its spreading. This article proposes security- and privacy-based lightweight framework called iFaaSBus, which uses the concept of IoT, machine learning (ML), and function as a service (FaaS) or serverless computing to diagnose the COVID-19 disease and manages resources automatically to enable dynamic scalability. iFaaSBus offers OAuth-2.0 Authorization protocol-based privacy and JSON Web Token & Transport Layer Socket protocol-based security to secure the patient's health data. iFaaSBus outperforms response time compared to nonserverless computing while responding to up to 1100 concurrent requests. Further, the performance of various ML models is evaluated based on accuracy, precision, recall, F-score, and area under the curve (AUC) values, and the K-nearest neighbor model gives the highest accuracy rate of 97.51%.
Muhammed Golec, Ridvan Ozturac, Zahra Pooranian, Sukhpal Singh, Rajkumar Buyya
IEEE Trans. Ind. Informatics3
2022 SETTI: A Self-supervised AdvErsarial Malware DeTection ArchiTecture in an IoT Environment
abstract
In recent years, malware detection has become an active research topic in the area of Internet of Things (IoT) security. The principle is to exploit knowledge from large quantities of continuously generated malware. Existing algorithms practise available malware features for IoT devices and lack real-time prediction behaviours. More research is thus required on malware detection to cope with real-time misclassification of the input IoT data. Motivated by this, in this article, we propose an adversarial self-supervised architecture for detecting malware in IoT networks, SETTI, considering samples of IoT network traffic that may not be labeled. In the SETTI architecture, we design three self-supervised attack techniques, namely, Self-MDS , GSelf-MDS, and ASelf-MDS . The Self-MDS method considers the IoT input data and the adversarial sample generation in real-time. The GSelf-MDS builds a generative adversarial network model to generate adversarial samples in the self-supervised structure. Finally, ASelf-MDS utilises three well-known perturbation sample techniques to develop adversarial malware and inject it over the self-supervised architecture. Also, we apply a defence method to mitigate these attacks, namely, adversarial self-supervised training, to protect the malware detection architecture against injecting the malicious samples. To validate the attack and defence algorithms, we conduct experiments on two recent IoT datasets: IoT23 and NBIoT. Comparison of the results shows that in the IoT23 dataset, the Self-MDS method has the most damaging consequences from the attacker’s point of view by reducing the accuracy rate from 98% to 74%. In the NBIoT dataset, the ASelf-MDS method is the most devastating algorithm that can plunge the accuracy rate from 98% to 77%.
Marjan Golmaryami, Rahim Taheri, Zahra Pooranian, Mohammad Shojafar, Pei Xiao 0001
ACM Trans. Multim. Comput. Commun. Appl.3
2021 Link Latency Attack in Software-Defined Networks
abstract
Software-Defined Networking (SDN) has found applications in different domains, including wired- and wireless networks. The SDN controller has a global view of the network topology, which is vulnerable to topology poisoning attacks, e.g., link fabrication and host-location hijacking. The adversaries can leverage these attacks to monitor the flows or drop them. However, current defence systems such as TopoGuard and TopoGuard+ can detect such attacks. In this paper, we introduce the Link Latency Attack (LLA) that can successfully bypass the systems' defence mechanisms above. In LLA, the adversary can add a fake link into the network and corrupt the controller's view from the network topology. This can be accomplished by compromising the end hosts without the need to attack the SDN-enabled switches. We develop a Machine Learning-based Link Guard (MLLG) system to provide the required defence for LLA. We test the performance of our system using an emulated network on Mininet, and the obtained results show an accuracy of 98.22% in detecting the attack. Interestingly, MLLG improves 16% the accuracy of TopoGuard+.
Sanaz Soltani, Mohammad Shojafar, Habib Mostafaei, Zahra Pooranian, Rahim Tafazolli
CNSM4
2021 FIDS: A Federated Intrusion Detection System for 5G Smart Metering Network
abstract
In a critical infrastructure such as Smart Grid (SG), providing security of the system and privacy of consumers are significant challenges to be considered. The SG developers adopt Machine Learning (ML) algorithms within the Intrusion Detection System (IDS) to monitor traffic data and network performance. This visibility safeguards the SG from possible intrusions or attacks that may trigger the system. However, it requires access to residents’ consumption information which is a severe threat to their privacy. In this paper, we present a novel method to detect abnormalities on a large scale SG while preserving the privacy of users. We design a Federated IDS (FIDS) architecture using Federated Learning (FL) in a 5G environment for the SG metering network. In this way, we design Federated Deep Neural Network (FDNN) model that protects customers’ information and provides supervisory management for the whole energy distribution network. Simulation results for a real-time dataset demonstrate the reasonable improvement of the proposed FDNN model compared with the state-of-the-art algorithms. The FDNN achieves approximately 99.5% accuracy, 99.5% precision/recall, and 99.5% f1-score when comparing with classification algorithms.
Parya Haji Mirzaee, Mohammad Shojafar, Zahra Pooranian, Pedram Asef, Haitham S. Cruickshank, Rahim Tafazolli
MSN3
2021 Adversarial android malware detection for mobile multimedia applications in IoT environments
Rahim Taheri, Reza Javidan, Zahra Pooranian
Multim. Tools Appl.3
2021 LEVER: Secure Deduplicated Cloud Storage With Encrypted Two-Party Interactions in Cyber-Physical Systems
abstract
Cloud envisioned cyber--physical systems (CCPS) is a practical technology that relies on the interaction among cyber elements like mobile users to transfer data in cloud computing. In CCPS, cloud storage applies data deduplication techniques aiming to save data storage and bandwidth for real-time services. In this infrastructure, data deduplication eliminates duplicate data to increase the performance of the CCPS application. However, it incurs security threats and privacy risks. For example, the encryption from independent users with different keys is not compatible with data deduplication. In this area, several types of research have been done. Nevertheless, they are suffering from a lack of security, high performance, and applicability. Motivated by this, in this article, we propose a message lock encryption with neVer-decrypt homomorphic encRyption (LEVER) protocol between the uploading CCPS user and cloud storage to reconcile the encryption and data deduplication. Interestingly, LEVER is the first brute-force resilient encrypted deduplication with only cryptographic two-party interactions. We perform several numerical analysis of LEVER and confirm that it provides high performance and practicality compared to the literature.
Zahra Pooranian, Mohammad Shojafar, Sahil Garg, Rahim Taheri, Rahim Tafazolli
IEEE Trans. Ind. Informatics1
2020 Similarity-based Android malware detection using Hamming distance of static binary features
Rahim Taheri, Meysam Ghahramani, Reza Javidan, Mohammad Shojafar, Zahra Pooranian, Mauro Conti
Future Gener. Comput. Syst.5
2020 On defending against label flipping attacks on malware detection systems
abstract
Abstract Label manipulation attacks are a subclass of data poisoning attacks in adversarial machine learning used against different applications, such as malware detection. These types of attacks represent a serious threat to detection systems in environments having high noise rate or uncertainty, such as complex networks and Internet of Thing (IoT). Recent work in the literature has suggested using the K -nearest neighboring algorithm to defend against such attacks. However, such an approach can suffer from low to miss-classification rate accuracy. In this paper, we design an architecture to tackle the Android malware detection problem in IoT systems. We develop an attack mechanism based on silhouette clustering method, modified for mobile Android platforms. We proposed two convolutional neural network-type deep learning algorithms against this Silhouette Clustering-based Label Flipping Attack . We show the effectiveness of these two defense algorithms— label-based semi-supervised defense and clustering-based semi-supervised defense —in correcting labels being attacked. We evaluate the performance of the proposed algorithms by varying the various machine learning parameters on three Android datasets: Drebin, Contagio, and Genome and three types of features: API, intent, and permission. Our evaluation shows that using random forest feature selection and varying ratios of features can result in an improvement of up to 19% accuracy when compared with the state-of-the-art method in the literature.
Rahim Taheri, Reza Javidan, Mohammad Shojafar, Zahra Pooranian, Ali Miri, Mauro Conti
Neural Comput. Appl.4
2019 Automatic Clustering of Attacks in Intrusion Detection Systems
abstract
Intrusion Detection Systems (IDSs) can identify the malicious activities and anomalies in networks and present robust protection for these systems. Clustering of attacks plays an important role in defining IDS defense policies. A key challenge in clustering has been finding the optimal value for the number of clusters. In this paper, we propose an automatic clustering algorithm as part of an IDS architecture. This algorithm is based on concepts of coherence and separation. Our automatic clustering algorithms find clusters with the most similarity between the proposed cluster elements and the least similarity with other clusters. The proposed clustering is further optimized by considering two types of objective index functions, and Artificial Bee Colony (ABC), Particle Swarm Optimization (PSO), and Differential Evolution (DE) methods. Comparison of the results obtained with other work in the literature shows improvements in terms of the low average number of evaluations functions, high accuracy, and low computation cost.
Mohammad Shojafar, Rahim Taheri, Zahra Pooranian, Reza Javidan, Ali Miri, Yaser Jararweh
AICCSA3
2019 Recent advances in cloud data centers toward fog data centers
abstract
In recent years, we have witnessed tremendous advances in cloud data centres (CDCs) from the point of view of the communication layer.A recent report from Cisco Systems Inc. demonstrates that CDCs, which are distributed across many geographical locations, will dominate the global data centre traffic flow for the foreseeable future.Their importance is highlighted by a top-line projection from this forecast that by 2019, more than four-fifths of total data centre traffic will be Cloud traffic.The geographical diversity of the computing resources in CDCs provides several benefits, such as high availability, effective disaster recovery, uniform access to users in different regions, and access to different energy sources.Although Cloud technology is currently predominant, it is essential to leverage new agile software technologies, agile processes and agile applications near to both the edge and the users; hence, the concept of Fog has been developed.Fog computing (FC) has emerged as an alternative to traditional Cloud computing to support geographically distributed, latency-sensitive and QoS-aware IoT applications while reducing the burden on data centres used in traditional Cloud computing.In particular, FC with features that can support heterogeneity and real-time applications (e.g.low latency, location awareness, and the capacity to process a large number of nodes with wireless access) is an attractive solution for delay-and resource-constrained large-scale applications.The distinguishing feature of the FC paradigm is that a set of Fog nodes (FNs) spreads communication and computing resources over the wireless access network to provide resource augmentation to resource-and energy-limited wireless (possibly mobile) devices.The joint management of Fog and Internet of Technology (IoT) paradigms can reduce the energy consumption and operating costs of state-of-the-art Fog-based data centres (FDCs).An FDC is dedicated to supervising the transmission, distribution and communication of FC.As a vital component of the Internet of Everything (IoE) environment, an FDC is capable of filtering and processing a considerable amount of incoming data on edge devices, by making the data processing architecture distributed and thereby scalable.An FDC therefore provides a platform for filtering and analysing the data generated by sensors utilising the resources of FNs.Increasing interest is emerging in FDCs and CDCs that allow the delivery of various kinds of agile services and applications over telecommunication networks and the Internet, including resource provisioning, data streaming/transcoding, analysis of high-definition videos across the edge of the network, IoE application analysis etc. Motivated by these issues, this special section solicits original research and practical contributions that advance the use of CDCs/FDCs in new technologies such as IoT, edge networks and industries.Results obtained from simulations are validated in terms of their boundaries by experiments or analytical results.The main objectives of this special issue are to provide a discussion forum for people interested in Cloud and Fog networking, and to present new models, adaptive tools and applications specifically designed for distributed and parallel on-demand requests received from (mobile) users and Cloud applications.The papers presented in this special issue provide insights in fields related to Cloud and Fog/edge architecture, including parallel processing of Cloudlets/Foglets, the presentation of new emerging models, performance evaluation and improvements, and developments in Cloud/Fog applications.We hope that readers can benefit from the insights in these papers, and contribute to these rapidly growing areas.
Mohammad Shojafar, Zahra Pooranian, Mehdi Sookhak, Rajkumar Buyya
Concurr. Comput. Pract. Exp.2
2019 FOCAN: A Fog-supported smart city network architecture for management of applications in the Internet of Everything environments
Paola Gabriela Vinueza Naranjo, Zahra Pooranian, Mohammad Shojafar, Mauro Conti, Rajkumar Buyya
J. Parallel Distributed Comput.2
2017 A Novel Distributed Fog-Based Networked Architecture to Preserve Energy in Fog Data Centers
abstract
The distinguishing feature of the Fog Computing (FC) paradigm is that FC spreads communication and computing resources over the wireless access network, so as to provide resource augmentation to resource and energy-limited wireless (possibly mobile) devices. Since FC would lead to substantial reductions in energy consumption and access latency, it will play a key role in the realization of the Fog of Everything (FoE) paradigm. The core challenge of the resulting FoE paradigm is tomaterialize the seamless convergence of three distinct disciplines, namely, broadband mobile communication, cloud computing, and Internet of Everything (IoE). In this paper, we present a new IoE architecture for FC in order to implement the resulting FoE technological platform. Then, we elaborate the related Quality of Service (QoS) requirements to be satisfied by the underlying FoE technological platform. Furthermore, in order to corroborate the conclusion that advancements in the envisioned architecture description, we present: (i) the proposed energy-aware algorithm adopt Fog data center; and, (ii) the obtained numerical performance, for a real-world case study that shows that our approach saves energy consumption impressively in theFog data Center compared with the existing methods and could be of practical interest in the incoming Fog of Everything (FoE) realm.
Zahra Pooranian, Mohammad Shojafar, Paola Gabriela Vinueza Naranjo, Luca Chiaraviglio, Mauro Conti
MASS1
2017 P-SEP: a prolong stable election routing algorithm for energy-limited heterogeneous fog-supported wireless sensor networks
Paola Gabriela Vinueza Naranjo, Mohammad Shojafar, Habib Mostafaei, Zahra Pooranian, Enzo Baccarelli
J. Supercomput.4
2017 FLAPS: bandwidth and delay-efficient distributed data searching in Fog-supported P2P content delivery networks
Mohammad Shojafar, Zahra Pooranian, Paola Gabriela Vinueza Naranjo, Enzo Baccarelli
J. Supercomput.2
2015 An efficient and distributed file search in unstructured peer-to-peer networks
Mohammad Shojafar, Jemal H. Abawajy, Zia Delkhah, Zahra Pooranian, Ajith Abraham
Peer-to-Peer Netw. Appl.5