VLDB 2026 Research / reviewers in the wild / expert
Mustafa Al Lail
dblp:132/3613 · also Mustafa Al-Lail
· DBLP profile ↗
8ranked-venue papers
5as first author
7since 2021 · last 2025
0009-0000-0326-6363ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Optimizing IoT Botnet Detection: A Comparative Study of Machine Learning and Feature Engineering StrategiesabstractThe Internet of Things (IoT) has transformed many sectors, including healthcare and manufacturing. Nonetheless, the swift increase of IoT devices has heightened security risks, rendering these systems attractive targets for cyberattacks like botnet threats. This pressing cybersecurity challenge requires immediate focus. This study systematically evaluates machine learning (ML) algorithms for identifying IoT botnets using the UNSW-NB15 dataset. We assess four ML models-Support Vector Machine (SVM), Random Forest (RF), Artificial Neural Network (ANN), and XGBoost (XGB)-utilizing various feature engineering methods, such as Correlation-Based Selection (CBS) and Principal Component Analysis (PCA). Our results indicate that ensemble techniques, especially RF and XGBoost, consistently attain a flawless F1-score of $\mathbf{1. 0 0}$. We illustrate that the CBS approach maintains this elevated level of performance while significantly decreasing the number of features, thus providing a computationally efficient and practical solution for IoT environments with limited resources. Unexpectedly, the PCA-based technique proved ineffective, underscoring a notable limitation for this application. Mustafa Al Lail |
AICCSA | 1 |
| 2025 | Impact of Network Data Complexity on Machine Learning Performance for Real-Time Iot SystemsabstractThis paper explores the relationship between network data complexity and machine learning (ML) performance, focusing on distributed and real-time IoT systems. Using intrinsic dimensionality (ID) to measure structural complexity, we analyze 20 datasets ($\mathbf{1 0}$for network and IoT systems and$\mathbf{1 0}$for non-network systems) and show that network datasets have lower ID values, indicating simpler structures that correlate with improved ML performance. We identify optimal algorithms for different ID ranges, offering practical guidance for selecting ML models tailored to network data. Additionally, we find that Euclidean distance outperforms Hamming distance for complexity measurement across both categories of data, though its higher computational cost should be considered for real-time IoT applications. These findings provide valuable insights for selecting efficient ML algorithms and metrics, supporting scalable and time-sensitive IoT systems. Mustafa Al Lail, Alexis Huante, Mariem Belhor |
ISORC | 1 |
| 2025 | A Secure, Context-Aware Software Architecture for Real-Time IoT ApplicationsabstractThis paper introduces a novel, context-aware software architecture to enhance the security of real-time IoT applications. By integrating a robust Role-Based Access Control (RBAC) model that incorporates user location and time, we significantly strengthen protection against unauthorized access and potential attacks. This approach addresses the increasing demand for secure and reliable IoT systems, especially in critical infrastructure and sensitive applications. To validate the feasibility and performance of our architecture, we developed a functional prototype and conducted rigorous evaluations. The results demonstrate that the proposed architecture can effectively handle real-time constraints while ensuring high security. Marshal Moncivais, Mustafa Al Lail |
ISORC | 2 |
| 2024 | Beyond Traditional Methods: Deep Learning with Data Augmentation for Robust Access ControlabstractAccess control systems in large organizations often struggle with managing complex policies and workloads. However, there is potential for deep learning models to address these challenges. This study delves into the suitability of various deep learning architectures for making real-time access control decisions. Six prominent Convolutional Neural Network (CNN) models (ResNet, DenseNet, Xception, Inception, AlexNet, VGG-16) are evaluated, and the impact of data augmentation using SMOTE on their performance is analyzed. The findings demonstrate that most deep learning models consistently deliver results in access control. ResNet outperforms other models, showing high accuracy across original and SMOTE-augmented datasets. Moreover, SMOTE generally enhances performance for most models, highlighting its potential for addressing data imbalance. These results indicate that deep learning shows promise for improving access control tasks. Mustafa Al Lail, Daniela Pinto, Luis Alvarez Almanza, Francisco Salazar, Carolina Rizzi |
ICCCN | 1 |
| 2024 | Streamlining CPS Validation: Using Interoperable UML Tools for Seamless Model ExchangeabstractUML is the standard in software modeling and enjoys widespread use across various domains. However, domains like cyber-physical systems necessitate developers to model across diverse domains. The diverse use of UML underscores the need for tools to be interoperable. Unfortunately, a significant limitation in many UML tools is their lack of robust interoperability, impeding their integration into industrial projects, including cyber-physical systems. This paper proposes an approach to address the interoperability challenges between UML tools. We implemented this approach within an existing tool, USE, improving its ability to interact seamlessly with five widely used UML tools. Antonio Rosales Viesca, Mustafa Al Lail, Omar Alam |
ISORC | 2 |
| 2023 | Poster: Integrating Spatio-temporal Authorization with Generic Cloud-based Software Architecture for Internet of Things DevicesabstractThe significant rise in the usage of IoT devices and their security issues has created a demand for improved security for these systems. Unfortunately, no standard IoT architecture exists, making the development of security solutions for IoT systems difficult. Towards this end, we leverage an IoT framework to create a generic IoT software architecture and integrate it with an extension of the RBAC model incorporating the time and location of users to determine access to different IoT resources. We provide a prototype implementation of the integrated architecture to show its feasibility. Marshal Moncivais, Mustafa Al Lail |
SACMAT | 2 |
| 2021 | Poster: Towards Cloud-Based Software for Incorporating Time and Location into Access Control DecisionsabstractThe increasing dependency on cloud computing has drawn attention to the security weaknesses of cloud providers. Not only how information is accessed, but also where and when have become important considerations in cloud security. Certain situations exist where it is necessary to restrict access to cloud resources based on time and location. An example is a policy for a medical institution where doctors can only access patient records at hospitals during their shifts. The Generalized Spatio-Temporal Role-Based Access Control model (GSTRBAC) determines users' access to resources based on such information. This poster proposes a cloud-based software architecture and outlines it possible implementation of the GSTRBAC model. Mustafa Al Lail |
SACMAT | 1 |
| 2013 | Rigorous Analysis of Temporal Access Control Properties in Mobile SystemsabstractAccess control models must be analyzed to uncover flaws that can be exploited to gain unauthorized access. The UML has been used to describe access control models and there are a number of proposed approaches for analyzing UML access control models. Practical support for checking UML access control models against temporal properties is still lacking. In this paper, we describe a lightweight approach to analyzing a UML model of security policies against linear temporal properties. The access control policies are based on a generalized spatio-temporal role-based access control (GSTRBAC) model. We use a demonstration case study to show how the approach can be used to uncover access control problems. Mustafa Al Lail, Ramadan Abdunabi, Robert B. France, Indrakshi Ray |
ICECCS | 1 |