VLDB 2026 Research / reviewers in the wild / expert
Pawani Porambage
dblp:140/8377
· DBLP profile ↗
20ranked-venue papers
4as first author
13since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 3 first-author · 4 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Non-Fungible Token Enabled Resource Trading Marketplace for 6G Network SlicingabstractThe shift from fifth generation (5G) to sixth generation (6G) networks is anticipated to significantly advance network slicing. This progress is driven by the growing demand for next-generation applications and services. However, these advancements must be managed within the constraints of limited resources. This evolution opens up opportunities for resource sharing through emerging marketplaces, yet it introduces various business and technical complexities that need to be addressed. Additionally, finding cost-effective solutions is also essential for the future of networks. In this paper, we propose a blockchain-based architecture that utilizes non-fungible tokens (NFTs) for the trading of network resources within the 6G network slicing. To the best of our knowledge, this is the first study to represent network resources as NFTs within the context of network slicing. The architecture employs NFTs to authenticate and manage various network resources, providing a decentralized platform for their secure creation, management, and exchange. Using resource NFTs, our system ensures more granular and flexible control over network resources than existing state-of-the-art systems, where NFTs are tied to network slices. We implemented a prototype of this system to validate its viability. Our performance evaluation confirms that the proposed approach is efficient and cost-effective compared to baseline models in managing network resources within network slicing. These findings highlight the potential of our system to transform network management practices and effectively meet the demands of future networks. Nisita Weerasinghe, Pawani Porambage, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
CCNC | 2 |
| 2025 | Demo: Blockchain-Based NFT Resource Marketplace for Efficient 6G Network SlicingabstractAs 6G networks introduce increasingly diverse and complex applications, network slicing is a key enabling technology for partitioning network resources to meet these dynamic demands. However, efficiently managing and allocating these finite resources has become vital. This necessity drives the adoption of an open marketplace model. To address the business and technical complexities associated with such open marketplaces, this paper presents the demonstration of a non-fungible token (NFT)-enabled resource trading marketplace tailored for 6G network slicing. The proposed solution is implemented on an Ethereum-based blockchain system to assess its viability. Nisita Weerasinghe, Pawani Porambage, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
CCNC | 2 |
| 2025 | SHIELD - Secure Aggregation Against Poisoning in Hierarchical Federated LearningabstractFederated Learning (FL) is a privacy-preserving distributed Machine Learning (ML) technique. Hierarchical FL is a novel variant of FL applicable to networks with multiple layers. Instead of transmitting client models to the server, hierarchical FL performs aggregations in the layers between the devices and the server. This further reduces the traffic toward the higher layers, which helps efficient link utilization. An adversary can manipulate a set of clients and send malicious model updates toward upper layers to create a trained model with a malicious objective. These attacks, also known as poisoning attacks, disrupt the model training. Like FL, Hierarchical FL is also vulnerable to poisoning attacks since the aggregators do not possess raw data. The existing robust algorithms are designed for FL systems with$n$clients and a server. Therefore, they are not effective against poisoning attacks in hierarchical FL systems. This paper proposes SHIELD, a novel robust aggregation technique that defends hierarchical FL systems from poisoning attacks. We evaluate SHIELD with several datasets in different application areas with different attack strategies and data distributions. The evaluation results demonstrate that SHIELD effectively defends hierarchical FL systems from poisoning attacks with a negligible impact on the benign performance of the models. Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Samuel Marchal, Mika Ylianttila |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Intent-Based Service Provisioning and Closed-Loop Automation for Cobot Service Migration in a Multi-Stakeholder EnvironmentabstractThis paper presents a Proof-of-Concept (PoC) focused on intent-based service provisioning and closed-loop automation for collaborative robot (cobot) use case. The PoC demonstrates the integration of two key IBN enablers: the Intent-Based Network Intent Management Entity (IBN-IME) and CL Automation and Coordination, both aligned with 3GPP and ETSI Zero-Touch Service and Network Management (ZSM) standards. These enablers support the seamless interpretation of user intents, service deployment, and migration. The testbed, designed to emulate certain functionalities present in a 6G end-to-end system, highlights the potential for automation in future networks. The work addresses the need for an ecosystem that allows for the interaction of multiple stakeholders in a secure platform. The PoC presented can adapt to increasingly complex use cases, laying the groundwork for future improvements and broader deployments. Rafael Pires 0002, Jere Malinen, Pawani Porambage, Pol Alemany, Daniel Adanza 0001, Raul Muñoz 0001, Ricard Vilalta, Pietro G. Giardina, Michael De Angelis, Giada Landi |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Robust Aggregation Technique Against Poisoning Attacks in Multi-Stage Federated Learning ApplicationsabstractFederated Learning (FL) is a distributed Machine Learning (ML) technique that allows model training without sharing data. FL is vulnerable to poisoning attacks where an adversary manipulates the learning process by providing false information to the federation. Ensuring security in FL is vital before using FL in real applications, as the consequences can be adverse. Multi-stage FL is a novel variant of FL that performs intermediate model aggregations, thereby reducing the traffic toward the FL central server. The existing robust aggregation techniques are insufficient in multi-stage FL systems. This paper proposes a novel robust aggregation algorithm against poisoning attacks in a three-layer multi-stage FL system that consists of device, edge, and cloud layers. We evaluate the proposed robust algorithm considering an Augmented Reality (AR) application with different poisoner placements and attack strategies. The evaluation results show that the proposed algorithm can effectively defend against poisoning attacks in three-layer multi-stage FL systems. Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Samuel Marchal, Mika Ylianttila |
CCNC | 2 |
| 2023 | Peer-to-Peer Federated Learning Based Anomaly Detection for Open Radio Access NetworksabstractOpen radio access network (O-RAN) has been recognized as a revolutionized architecture to support the multi-class wireless services required in fifth-generation (5G) and beyond 5G networks. The openness and the distributed nature of the O-RAN architecture have created new forms of threat surfaces than the conventional RAN architecture and require complex anomaly detection mechanisms. Moreover, with the introduction of RAN intelligent controllers (RICs), it is possible to utilize advanced Artificial Intelligence (AI)/ Machine Learning (ML) algorithms based on closed control loops to detect anomalies in a data-driven manner. In this paper, we particularly investigate the use of Federated Learning (FL) for anomaly detection in the O-RAN architecture, which can further preserve data privacy. We propose a peer-to-peer (P2P) FL-based anomaly detection mechanism for the O-RAN architecture and provide a comprehensive analysis of four variants of P2P FL techniques. Moreover, we simulate the proposed models using the UNSW-NB15 dataset. Dinaj Attanayaka, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
ICC | 2 |
| 2023 | Comprehensive Analysis Over Centralized and Federated Learning-Based Anomaly Detection in Networks with Explainable AI (XAI)abstractMany forms of machine learning (ML) and artificial intelligence (AI) techniques are adopted in communication networks to perform all optimizations, security management, and decision-making tasks. Instead of using conventional blackbox models, the tendency is to use explainable ML models that provide transparency and accountability. Moreover, Federate Learning (FL) type ML models are becoming more popular than the typical Centralized Learning (CL) models due to the distributed nature of the networks and security privacy concerns. Therefore, it is very timely to research how to find the explainability using Explainable AI (XAI) in different ML models. This paper comprehensively analyzes using XAI in CL and FL-based anomaly detection in networks. We use a deep neural network as the black-box model with two data sets, UNSW-NB15 and NSLKDD, and SHapley Additive exPlanations (SHAP) as the XAI model. We demonstrate that the FL explanation differs from CL with the client anomaly percentage. Yasintha Rumesh, Thulitha Senevirathna, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
ICC | 3 |
| 2023 | Blockchain-Based Network Slice Broker to Facilitate Factory-As-a-ServiceabstractThe novel concept of factory-as-a-service (FaaS) allows the agility of adapting the manufacturing process by identifying the industry’s supply chain and user requirements. To cater to FaaS, flexibility in networking and cloud services is a must. 5G network slice broker (NSB) is a third-party mediator that caters to networking resource demand from clients to the service providers. Thus, this article introduces a secure blockchain-based NSB to facilitate FaaS. The proposed secure NSB (SNSB) provides secure, cognitive, and distributed network services for resource allocation and security service level agreement (SSLA) formation with coordination of slice managers and SSLA managers. In SNSB, we introduce a federated slice selection algorithm with Stackelberg game model and reinforcement learning algorithm to compute the real time and the optimal unit price and demand level. We provide an extensive implementation and performance evaluation of SNSB using the slice manager and a custom SSLA manager. Tharaka Mawanane Hewa, Pawani Porambage, Nisita Weerasinghe, Erkki Harjula, Madhusanka Liyanage, Mika Ylianttila |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | Proof-of-Monitoring (PoM): A Novel Consensus Mechanism for Blockchain-Based Secure Service Level Agreement ManagementabstractIn the current 5th Generation (5G) networking paradigm, the enforcement of Service Level Agreements (SLAs) is a non-trivial measure to ensure the scope and the quality of services and standards between tenants and service providers (SPs). On top of this, Secure Service Level Agreements (SSLA) are introduced to ensure that SPs deliver the most critical and required security-related standards defined in the contract, such as integrity, confidentiality, availability, non-repudiation, and privacy assurance. However, with the tendency for more distributed and multi-stakeholder networking architectures in next-generation networks, the management process of such SSLAs will be challenging due to the diversified security vulnerabilities and complexity of underlying technologies. Although blockchain is emerging as a platform to facilitate such distributed SSLA/SLA management frameworks, its currently available consensus mechanisms are more generic. Still, they need to improve in terms of applying in multi-stakeholder networks. Therefore, this paper presents a novel consensus mechanism called Proof-of-Monitoring (PoM) for a blockchain-based novel SSLA management framework. Moreover, we provide details about the prototype implementation of our proposed consensus algorithm and SSLA management framework. It is proven by comparing our proposal with the other existing solutions that our solution outperforms in many aspects, such as energy consumption, computation cost, and security features. Nisita Weerasinghe, Raaj Anand Mishra, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | A Comprehensive Analysis on Network Slicing for Smart Hospital ApplicationsabstractNetwork slicing (NS) is technology that enables emerging smart applications and use cases in Fifth Generation (5G) and beyond networks. One such application is smart hospitals, which has diverse network requirements for applications ranging from Augmented Reality (AR) and robot assisted surgeries to connecting large numbers of medical wearables and sensors. NS can be performed in smart hospitals under different strategies based on dynamicity, ownership, and application. This paper investigates how these strategies can be utilized in different smart hospital applications. The performance of each slicing strategy in a hospital network is analyzed under three matrices: bandwidth utilization, handover count, and block count. Shalitha Wijethilaka, Pawani Porambage, Chamitha de Alwis, Madhusanka Liyanage |
CCNC | 2 |
| 2022 | Demo: Blockchain-based Secured and Federated Slice Broker (SFSBroker)abstractNetwork slicing is a versatile and distinguishing capability of the 5th and 6th Generation (5G & 6G) mobile networks. Network slicing enables the consumers to deliver individualized and customized telecommunication services on the commonly shared infrastructure. Slice brokering is the dedicated service to facilitate the tenants and resource providers in slice allocation process. We proposed SFSBroker (Secured and Federated Slice Broker) to leverage the slice brokering process with the application of game theory. We formulated the optimal slice selection problem into the Stackelberg game model. The computational logic has been incorporated on smart contracts. Furthermore, the proposed architecture includes Security Service Blockchain (SSB) which has been integrated for Denial of Service (DoS) attack prevention. We implemented the end to end setup including tenant request to slice creation using Hyperledger Fabric blockchain, Katana slice manager, and OpenStack. In this demonstration, the system provisions to obtain hands-on experience on the end to end workflow of slice brokering process. Tharaka Mawanane Hewa, Nisita Weerasinghe, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
NOMS | 3 |
| 2021 | Performance Analysis of Softwarized Local Mobile NetworksabstractThe ever growing and revolutionizing demands in telecommunication industry to facilitate numerous business verticals are pushing towards more softwarized mobile communication technologies. Utilizing the capabilities of network softwarization, a novel telecommunication concept of local mobile network has been developed. The local mobile networks are getting popular due to their capability of providing efficient and reliable local services to a focused use case with higher flexibility. This paper presents the practical implementation aspects of a softwarized local mobile network and compare its performance with a conventional mobile network and a hybrid network. Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
CCNC | 2 |
| 2021 | How DoS attacks can be mounted on Network Slice Broker and can they be mitigated using blockchain?abstractSeveral recent works talk about the potential use of network slice brokering mechanism to facilitate the resource allocation of network slicing in next generation networks. This involves network tenants on the one hand and resource/infrastructure providers on the other hand. However, the potential downside of deploying Network Slice Broker (NSB) is that it can be victimized by DoS (Denial of Service) attack. Thus, the aim of this work is three fold. First, to present the possible ways in which DoS/DDoS attacks can be mounted on NSB and their adverse effects. Second, to propose and implement initial blockchain-based solution named as Security Service Blockchain (SSB) to prevent DoS attacks on NSB. Third, to enumerate the challenges and future research directions to effectively utilize blockchain for mitigating DoS/DDoS attacks on NSB. To evaluate the performance the proposed SSB framework is implemented using Hyperledger Fabric. The results manifest that the latency impact of the legitimate slice creation over scaled up malicious traffic remains minimal with the use of SSB framework. The integration of SSB with NSB results in gaining several fold reduction in latency under DoS attack scenario. Tharaka Mawanane Hewa, Anshuman Kalla, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila |
PIMRC | 3 |
| 2020 | Performance Analysis of Local 5G Operator Architectures for Industrial Internetabstract5G calls for a network architecture that ensures ultraresponsive and ultrareliable communication links, in addition to the high degree of flexibility and customization required by different vertical sectors. The novel concept called local 5G networks enables a versatile set of stakeholders to operate 5G networks within their premises with guaranteed quality and reliability to complement mobile network operators' (MNOs) offerings. This article proposes a descriptive architecture for a local 5G operator which provides user specific and location-specific services in a spatially confined environment, i.e., industrial Internet environment. In addition to that, the article proposes hybrid architecture options where both the local 5G operator and MNO collaboratively contribute to establish the core network to cater to such communications. The architecture is discussed in terms of network functions (NFs) and the operational units which entail the core and radio access networks in a smart factory environment which supports Industry 4.0 standards. Moreover, to realize the conceptual design, the article provides simulation results for the latency measurements of the proposed architecture options with respect to an augmented reality (AR), massive wireless sensor networks, and mobile robots use cases. Thereby the article discusses the benefits of deploying core NFs locally to cater to specialized user requirements, rather than continuing with the conventional approach where only MNOs can deploy cellular networks. Yushan Siriwardhana, Pawani Porambage, Mika Ylianttila, Madhusanka Liyanage |
IEEE Internet Things J. | 2 |
| 2019 | Managing Mobile Relays for Secure E2E Connectivity of Low-Power IoT DevicesabstractThe widespread Internet of Things (IoT) ecosystems empower the deployment of various Bluetooth Low Energy (BLE) sensor nodes in many ambient assisted living (AAL) type applications. Regardless of their limitations, these low-power IoT sensor nodes need pervasive and secure connections to transfer the aggregated data to the central servers located in remote clouds which will perform further processing and storing functions. The common practice is to use one or multiple dedicated gateways to assist the communication between the sensor and the cloud. This paper presents a mobile-based relay assistance solution for establishing secure end-to-end (E2E) connectivity between low-power IoT sensors and cloud servers without using a dedicated gateway. za The prototype implementation and the described security features verify the technical readiness of the proposed solution. Pawani Porambage, Ahsan Manzoor, Madhusanka Liyanage, Andrei V. Gurtov, Mika Ylianttila |
CCNC | 1 |
| 2019 | Micro-Operator driven Local 5G Network Architecture for Industrial InternetabstractIn addition to the high degree of flexibility and customization required by different vertical sectors, 5G calls for a network architecture that ensures ultra-responsive and ultra-reliable communication links. The novel concept called micro-operator (uO) enables a versatile set of stakeholders to operate local 5G networks within their premises with a guaranteed quality and reliability to complement mobile network operators' (MNOs) offerings. In this paper, we propose a descriptive architecture for emerging 5G uOs which provides user specific and location specific services in a spatially confined environment. The architecture is discussed in terms of network functions and the operational units which entail the core and radio access networks in a smart factory environment which supports industry 4.0 standards. Moreover, in order to realize the conceptual design, we provide simulation results for the latency measurements of the proposed uO architecture with respect to an augmented reality use case in industrial internet. Thereby we discuss the benefits of having uO driven local 5G networks for specialized user requirements, rather than continuing with the conventional approach where only MNOs can deploy cellular networks. Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Jaspreet Singh Walia, Marja Matinmikko, Mika Ylianttila |
WCNC | 2 |
| 2018 | DEMO: Mobile Relay Architecture for Low-Power IoT DevicesabstractInternet of Things (IoT) devices need pervasive and secure connections to transfer the aggregated data to the central servers located in remote clouds where the collected data further processed and stored. However, most low-power IoT devices cannot transmit the collected the data directly to such servers due the limited transmission power and range. Thus, third-party devices such as smart mobile phones are used as a relay to establish the communication link between IoT devices and the cloud server. This paper demonstrates a mobile-based relay assistance solution for secure end-to-end connectivity between low-power IoT sensors and cloud servers by using Bluetooth Low Energy (BLE) technology. The prototype implementation verifies the technical readiness of the proposed solution. Ahsan Manzoor, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov |
WOWMOM | 2 |
| 2015 | Efficient Key Establishment for Constrained IoT Devices with Collaborative HIP-Based ApproachabstractThe Internet of Things (IoT) technologies interconnect wide ranges of network devices irrespective of their resource capabilities and local networks. The device constraints and the dynamic link creations make it challenging to use pre-shared keys for every secure end-to-end (E2E) communication scenario in IoT. Variants of Host Identity Protocol (HIP) are adopted for constructing dynamic and secure E2E connections among the heterogenous network devices with imbalanced resource profiles and less or no previous knowledge about each other. We propose a collaborative HIP solution with an efficient key establishment component for the high constrained devices in IoT, which delegates the expensive cryptographic operations to the resource rich devices in the local networks. Finally, we demonstrate the applicability of the key establishment in collaborative HIP solution for the constrained IoT devices rather than the existing HIP variants, by providing performance and security analysis. Pawani Porambage, An Braeken, Pardeep Kumar 0001, Andrei V. Gurtov, Mika Ylianttila |
GLOBECOM | 1 |
| 2015 | Group key establishment for secure multicasting in IoT-enabled Wireless Sensor NetworksabstractWireless Sensor Network (WSN) is a fundamental technology of the Internet of Things (IoT). Group communications in the form of broadcasting and multicasting incur efficient message deliveries among resource-constrained sensors in IoT-enabled WSNs. Secure and efficient key management is significant to protect the authenticity, integrity, and confidentiality of multicast messages. This paper develops two group key establishment protocols for secure multicast communications among resource-constrained devices in IoT. The applicability of the two protocols are analyzed and justified by performance and security analysis. Pawani Porambage, An Braeken, Corinna Schmitt, Andrei V. Gurtov, Mika Ylianttila, Burkhard Stiller |
LCN | 1 |
| 2014 | Two-phase authentication protocol for wireless sensor networks in distributed IoT applicationsabstractIn the centralized Wireless Sensor Network (WSN) architecture there exists a central entity, which acquires, processes and provides information from sensor nodes. Conversely, in the WSN applications in distributed Internet of Things (IoT) architecture, sensor nodes sense data, process, exchange information and perform collaboratively with other sensor nodes and endusers. In order to maintain the trustworthy connectivity and the accessibility of distributed IoT, it is important to establish secure links for end-to-end communication with proper authentication. The authors propose an implicit certificate-based authentication mechanism for WSNs in distributed IoT applications. The developed two-phase authentication protocol allows the sensor nodes and the end-users to authenticate each other and initiate secure connections. The proposed protocol supports the resource scarcity of the sensor nodes, heterogeneity and scalability of the network. The performance and security analysis justify that the proposed scheme is viable to deploy in resource constrained WSNs. Pawani Porambage, Corinna Schmitt, Pardeep Kumar 0001, Andrei V. Gurtov, Mika Ylianttila |
WCNC | 1 |