VLDB 2026 Research / reviewers in the wild / expert
Fadi Mohsen
dblp:139/2275
· DBLP profile ↗
8ranked-venue papers
5as first author
4since 2021 · last 2025
0000-0003-3876-5781ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Poster: BLE-Shield: A Hybrid Framework for Threat Identification in Bluetooth Low Energy (BLE) NetworksabstractBluetooth Low Energy (BLE) is increasingly prevalent in IoT networks, particularly in high-risk environments such as medical IoT. However, existing security research in BLE often focuses on isolated device types or controlled environments, overlooking the complexities of real-world BLE interactions, including environmental noise and the heterogeneous nature of devices. This paper proposes a multilayered framework for BLE data extraction designed to capture, process, and correlate data from diverse sources to construct comprehensive behavioral signatures. Our approach explores traffic analysis and introduces the potential of spectrum analysis to identify malicious activity beyond conventional packet-level monitoring. By identifying key behavioral markers and deviations from expected norms, this approach enhances BLE anomaly detection and strengthens the security of IoT networks. Adalynn Martinez, Usman Rauf, Fadi Mohsen |
WISEC | 3 |
| 2022 | Security-centric ranking algorithm and two privacy scores to mitigate intrusive appsabstractSummary Smartphone users are constantly facing the risks of losing their private information to third‐party mobile applications. Studies have revealed that the vast majority of users either do not pay attention to privacy or unable to comprehend privacy messages. Developers though have exploited this fact by asking users to grant their apps an enormous number of permissions. In this article, we propose and evaluate a new security‐centric ranking algorithm built on top of the Elasticsearch engine to help users evade such apps. The algorithm calculates an intrusiveness score for an app based on its requested permissions, received system actions, and users' privacy preferences. As such, we further propose a new approach to capture these preferences. We evaluate the ranking algorithm using a million Android applications, contextual data and APK files, that we collect from the Google Play store. The results show that the scoring and reranking steps add minor overhead. Moreover, participants of the user studies gave positive feedback for the ranking algorithm and the privacy preferences solicitation approach. These results suggest that our proposed system would definitely protect the privacy of mobile users and pushes developers into requesting least amount of privileges. Still, there are many risks that endanger the users' privacy. Fadi Mohsen, Hamed Abdelhaq, Halil Bisgin |
Concurr. Comput. Pract. Exp. | 1 |
| 2021 | Extending the Exposure Score of Web Browsers by Incorporating CVSS
Fadi Mohsen, Adel Shtayyeh, Riham Naser, Lena Mohammad, Marten Struijk |
CRiSIS | 1 |
| 2021 | ArabiaNer: A System to Extract Named Entities from Arabic ContentabstractThe extraction of named entities from unstructured text is a crucial component in numerous Natural Language Processing (NLP) applications such as information retrieval, question answering, machine translation, to name but a few. Named-entity Recognition (NER) aims at locating proper nouns from unstructured text and classifying them into a predefined set of types, such as persons, locations, and organizations. There has been extensive research on improving the accuracy of NER in English text. For other languages such as Arabic, extracting Named-entities is quite challenging due to its morphological structure. In this paper, we introduce ArabiaNer, a system employing Conditional Random Field (CRF) learning algorithm with extensive feature engineering steps to effectively extract Arabic named Entities. ArabiaNer produced state-of-the-art results with f1-score of 91.31% when applied on the ANERcrop dataset. Mohammad Hudhud, Hamed Abdelhaq, Fadi Mohsen |
ICAART (1) | 3 |
| 2019 | Raising the Bar Really High: An MTD Approach to Protect Data in Embedded BrowsersabstractThe safety of web browsers is essential to the privacy of Internet users and the security of their computing systems. In the last few years, there have been several cyber attacks geared towards compromising surfers' data and systems via exploiting browser-based vulnerabilities. Android and a number of mobile operating systems have been supporting a UI component called WebView, which can be embedded in any mobile application to render the web contents. Yet, this mini-browser component has been found to be vulnerable to various kinds of attacks. For instance, an attacker in her WebView-Embedded app can inject malicious JavaScripts into the WebView to modify the web contents or to steal user's input values. This kind of attack is particularly challenging due to the full control of attackers over the content of the loaded pages. In this paper, we are proposing and testing a server-side moving target defense technique to counter the risk of JavaScript injection attacks on mobile WebViews. The solution entails creating redundant HTML forms, randomizing their attributes and values, and asserting stealthy prompts for the user data. The solution does not dictate any changes to the browser or applications codes, neither it requires key sharing with benign clients. The results of our performance and security analysis suggest that our proposed approach protects the confidentiality and integrity of user input values with minimum overhead. Fadi Mohsen, Haadi Jafaarian |
COMPSAC (1) | 1 |
| 2014 | POSTER: Android System Broadcast Actions Broadcasts Your PrivacyabstractAndroid provides finer-grained security features through a "permission" mechanism that puts limitations on the resources that each application can access. Upon installing a new Android application, a user is prompted to grant it a set of permissions. There are two typical assumptions made regarding permissions and mobile application security and privacy. The first one is that malicious applications need to retain many permissions. Secondly, mobile devices users assume that installed applications do not access data if they are not in the foreground. In this project, we show that malicious Android applications can still fulfill their objectives with minimum permissions and that they can access user data while in the background. This could happen with the help of another Android component, called broadcast receiver. We study the evaluation of Android broadcast actions. We demonstrate an attack scenario made possible by the broadcast receivers. Moreover, we propose solutions to protect from such attacks. Fadi Mohsen, Mohamed Shehab, Emmanuel Bello-Ogunu, Abeer Al Jarrah |
CCS | 1 |
| 2014 | Securing OAuth implementations in smart phonesabstractWith the roaring growth and wide adoption of smart mobile devices, users are continuously integrating with culture of the mobile applications (apps). These apps are not only gaining access to information on the smartphone but they are also able gain users' authorization to access remote servers on their behalf. The Open standard for Authorization (OAuth) is widely used in mobile apps for gaining access to user's resources on remote service providers. In this work, we analyze the different OAuth implementations adopted by some SDKs of the popular resource providers on smartphones and identify possible attacks on most OAuth implementations. We give some statistics on the trends followed by the service providers and by mobile applications developers. In addition, we propose an application-based OAuth Manager framework, that provides a secure OAuth flow in smartphones that is based on the concept of privilege separation and does not require high overhead. Mohamed Shehab, Fadi Mohsen |
CODASPY | 2 |
| 2013 | Android keylogging threatabstractThe openness of Android platform has attracted users, developers and attackers. Android offers bunch of capabilities and flexibilities, for instance, developers can write their own keyboard service-similar to Android soft keyboards-using the KeyboardView class. This class is available since api leve Fadi Mohsen, Mohamed Shehab |
CollaborateCom | 1 |