VLDB 2026 Research / reviewers in the wild / expert
Mohamed Abdur Rahman 0003
dblp:129/2393-3 · also Md. Abdur Rahman 0003
· DBLP profile ↗
9ranked-venue papers
4as first author
9since 2021 · last 2025
0000-0002-4512-5830ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 4 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 4 first-author · 9 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Embedding with Large Language Models for Classification of HIPAA Safeguard Compliance RulesabstractAlthough software developers of mHealth apps are responsible for protecting patient data and adhering to strict privacy and security requirements, many of them lack awareness of HIPAA regulations and struggle to distinguish between HIPAA rules categories. Therefore, providing guidance of HIPAA rules patterns classification is essential for developing secured applications for Google Play Store. In this work, we identified the limitations of traditional Word2Vec embeddings in processing code patterns. To address this, we adopt multilingual BERT (Bidirectional Encoder Representations from Transformers) which offers contextualized embeddings to the attributes of dataset to overcome the issues. Therefore, we applied this BERT to our dataset for embedding code patterns and then uses these embedded code to various machine learning approaches. Our results demonstrate that the models significantly enhances classification performance, with Logistic Regression achieving a remarkable accuracy of 99.95%. Additionally, we obtained high accuracy from Support Vector Machine (99.79%), Random Forest (99.73%), and Naive Bayes (95.93%), outperforming existing approaches. This work underscores the effectiveness and showcases its potential for secure application development. Mohamed Abdur Rahman 0003, Md Abdul Barek, ABM Kamrul Islam Riad, Md Bajlur Rashid, Md Raihan Mia, Hossain Shahriar, Guillermo A. Francia III, Fan Wu 0013, Alfredo Cuzzocrea, Sheikh Iqbal Ahamed |
COMPSAC | 1 |
| 2025 | White-box Fuzzing in the Wild: A Chaos Engineering Module for DevOps Security EducationabstractIn today’s fast-paced software development environments, DevOps has revolutionized the way teams build, test, and deploy applications by emphasizing automation, collaboration, and continuous integration/continuous delivery (CI/CD). However, with these advancements comes an increased need to address security proactively, giving rise to the DevSecOps movement, which integrates security practices into every phase of the software development lifecycle. DevOps security remains underrepresented in academic curricula despite its growing importance in the industry. To address this gap, this paper presents a hands-on learning module that combines Chaos Engineering and White- box Fuzzing to teach core principles of secure DevOps practices in an authentic, scenario-driven environment. Chaos Engineering allows students to intentionally disrupt systems to observe and understand their resilience, while White-box Fuzzing enables systematic exploration of internal code paths to discover corner- case vulnerabilities that typical tests might miss. The module was deployed across three academic institutions, and both pre- and post-surveys were conducted to evaluate its impact. Pre-survey data revealed that while most students had prior experience in software engineering and cybersecurity, the majority lacked exposure to DevOps security concepts. Post-survey responses gathered through ten structured questions showed highly positive feedback 66.7% of students strongly agreed, and 22.2% agreed that the hands-on labs improved their understanding of secure DevOps practices. Participants also reported increased confidence in secure coding, vulnerability detection, and resilient infrastructure design. These findings support the integration of experiential learning techniques like chaos simulations and white-box fuzzing into security education. By aligning academic training with real- world industry needs, this module effectively prepares students for the complex challenges of modern software development and operations. Md Bajlur Rashid, Md Abdul Barek, ABM Kamrul Islam Riad, Mohamed Abdur Rahman 0003, Hossain Shahriar, Akond Ashfaque Ur Rahman, Fan Wu 0013, Guillermo A. Francia III, Md. Jobair Hossain Faruk, Sharaban Tahora |
COMPSAC | 5 |
| 2025 | Fine-tuned Large Language Models (LLMs): Improved Prompt Injection Attacks DetectionabstractLarge language models (LLMs) are becoming a popular tool as they have significantly advanced in their capability to tackle a wide range of language-based tasks. However, LLMs applications are highly vulnerable to prompt injection attacks, which poses a critical problem. These attacks target LLMs applications through using carefully designed input prompts to divert the model from adhering to original instruction, thereby it could execute unintended actions. These manipulations pose serious security threats which potentially results in data leaks, biased outputs, or harmful responses. This project explores the security vulnerabilities in relation to prompt injection attacks. To detect whether a prompt is vulnerable or not, we follows two approaches: 1) a pre-trained LLM, and 2) a fine-tuned LLM. Then, we conduct a thorough analysis and comparison of the classification performance. Firstly, we use pre-trained XLM-RoBERTa model to detect prompt injections using test dataset without any fine-tuning and evaluate it by zero-shot classification. Then, this proposed work will apply supervised fine-tuning to this pre-trained LLM using a task-specific labeled dataset from deepset in huggingface, and this fine-tuned model achieves impressive results with 99.13% accuracy, 100% precision, 98.33% recall and 99.15% F1-score thorough rigorous experimentation and evaluation. We observe that our approach is highly efficient in detecting prompt injection attacks. Mohamed Abdur Rahman 0003, Hossain Shahriar, Guillermo A. Francia III, Fan Wu 0013, Alfredo Cuzzocrea, Muhammad Rahman 0006, Md. Jobair Hossain Faruk, Sheikh Iqbal Ahamed |
COMPSAC | 1 |
| 2024 | Authentic Learning Approach for Data Poisoning Vulnerability in LLMsabstractThe primary goal of authentic learning is to provide students with an engaging learning environment that offers hands-on experiences in solving real-world security challenges. Each educational theme consists of prelab activities, lab activities, and hands-on lab activities. By implementing authentic learning, we design and build portable lab for data poisoning vulnerability in LLM models on Google Colab. These hands-on labs can be accessed and practiced in real-time without the need for complex installations and configurations. This allows students to focus on learning concepts and increase their hands-on problem-solving skills. Mst. Shapna Akter, Mohamed Abdur Rahman 0003, Juanjose Rodriguez-Cardenas, Hossain Shahriar, Fan Wu 0013, Muhammad Rahman 0006 |
COMPSAC | 2 |
| 2024 | Mitigating Insecure Outputs in Large Language Models(LLMs): A Practical Educational ModuleabstractLarge Language Models (LLMs) have extensive ability to produce promising output. Nowadays, people are increasingly relying on them due to easy accessibility, rapid and outstanding outcomes. However, the use of these results without appropriate scrutiny poses serious security risks, particularly when they are integrated with other software, APIs, or plugins. This is because the LLM outputs are highly dependent on the prompts they receive. Therefore, it is essential to carefully clean these outputs before using them in additional software environments. This paper is designed to teach students about the potential dangers of contaminated LLM output within the context of web development through prelab, hands-on, and postlab experiences. Hands-on lab provides practical guidance on how to handle LLM vulnerabilities to make applications safe with some real-world examples in Python. This approach aims to provide students with a deeper understanding of the precautions necessary to ensure software against the vulnerabilities introduced by LLM output. Md Abdul Barek, Mst. Shapna Akter, ABM Kamrul Islam Riad, Mohamed Abdur Rahman 0003, Hossain Shahriar, Akond Ashfaque Ur Rahman, Fan Wu 0013 |
COMPSAC | 5 |
| 2024 | Fine-Tuned Variational Quantum Classifiers for Cyber Attacks Detection Based on Parameterized Quantum Circuits and OptimizersabstractRecent investigations into Quantum Machine Learning (QML) techniques have unveiled methodologies that accelerate training in established machine learning models to provide an alternative for capturing complex patterns. This study focuses on implementing a practical QML Algorithm, Variational Quantum Classification (VQC) for cybersecurity dataset so that detecting anomalies can be improved and faster by reducing number of attributes$\log_{2} M$while training the model using Qiskit. Also, we study quantum algorithms to understand how it impacts on cyber datasets to detect anomalies in a improved way as it follows logarithms in the dimensionality reduction of quantum states which opens new horizons to quantum big data applications. Most importantly, we aim to also investigate the impact of various parameterized quantum circuits on VQC using quantum data as quantum states encoded by the cyber security dataset, NSL-KDD. In this research, we train VQC with various structures and parameters of quantum circuits as well as optimizers to adjust parameters of quantum circuits (ansatz) to minimize the objective function values so as to improve accuracy of the model in which quantum circuit, EfficientSU2, along with optimizer, COBYLA, outperforms the accuracy than other circuits and optimizers which shows great potential for improving cybersecurity systems. The research could effectively bridge in the gap between theory and implementation based quantum machine learning on cybersecurity systems. Mohamed Abdur Rahman 0003, Mst. Shapna Akter, Emily Miller, Bogdan Timofti, Hossain Shahriar, Mohammad Masum, Fan Wu 0013 |
COMPSAC | 1 |
| 2024 | Authentic Learning on DevOps Security with Labware: Git Hooks To Facilitate Automated Security Static AnalysisabstractThis paper presents an innovative approach to DevOps security education, addressing the dynamic landscape of cybersecurity threats. We propose a student-centered learning methodology by developing comprehensive hands-on learning modules. Specifically, we introduce labware modules designed to automate static security analysis, empowering learners to identify known vulnerabilities efficiently. These modules offer a structured learning experience with pre-lab, hands-on, and post-lab sections, guiding students through DevOps concepts and security challenges. In this paper, we introduce hands-on learning modules that familiarize students with recognizing known security flaws through the application of Git Hooks. Through prac-tical exercises with real-world code examples containing security flaws, students gain proficiency in detecting vulnerabilities using relevant tools. Initial evaluations conducted across educational institutions indicate that these hands-on modules foster student interest in software security and cybersecurity and equip them with practical skills to address DevOps security vulnerabilities. Md Abdul Barek, Mst. Shapna Akter, ABM Kamrul Islam Riad, Mohamed Abdur Rahman 0003, Hossain Shahriar, Akond Ashfaque Ur Rahman, Fan Wu 0013 |
COMPSAC | 5 |
| 2024 | Enhancing HIPAA Compliance in AI-driven mHealth Devices Security and Privacyabstract-The integration of Artificial Intelligence (AI) in mobile health (mHealth) devices offers significant advancements in patient care but also raises complex security and privacy concerns for sensitive health data. This paper explores the evolving landscape of Health Insurance Portability and Accountability Act (HIP AA) compliance within the context of AI-based mHealth devices, focusing on anticipated challenges in 2024. It examines the current state of HIP AA compliance in AI-driven mHealth, identifying potential vulnerabilities and gaps among mHealth devices in considering privacy and security. The study outlines key security and privacy considerations specific to AI-powered mHealth technologies, emphasizing risks such as data breaches, ransomware attack and unauthorized access. The paper concludes by highlighting the importance of continual adaptation to the dynamic nature of AI technologies and offers insights for stakeholders to navigate the regulatory landscape and ensure the responsible deployment of AI in healthcare. ABM Kamrul Islam Riad, Md Abdul Barek, Mst. Shapna Akter, Tahia Islam, Mohamed Abdur Rahman 0003, Md Raihan Mia, Hossain Shahriar, Fan Wu 0013, Sheikh Iqbal Ahamed |
COMPSAC | 6 |
| 2023 | A Quantum Generative Adversarial Network-based Intrusion Detection System
Mohamed Abdur Rahman 0003, Hossain Shahriar, Victor Clincy, Md Faruque Hossain, Muhammad Asadur Rahman |
COMPSAC | 1 |