VLDB 2026 Research / reviewers in the wild / expert
Amir Javed
dblp:142/6631
· DBLP profile ↗
11ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0001-9761-0945ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-authorComputer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A survey of learning-based intrusion detection systems for in-vehicle networksabstractConnected and Autonomous Vehicles (CAVs) have advanced modern transportation by improving the efficiency, safety, and convenience of mobility through automation and connectivity, yet they remain vulnerable to cybersecurity threats, particularly through the insecure Controller Area Network (CAN) bus. Cyberattacks can have devastating consequences in connected vehicles, including the loss of control over critical systems, necessitating robust security solutions. In-vehicle Intrusion Detection Systems (IDSs) offer a promising approach by detecting malicious activities in real time. This survey provides a comprehensive review of state-of-the-art research on learning-based in-vehicle IDSs, focusing on Machine Learning (ML), Deep Learning (DL), and Federated Learning (FL) approaches. Based on the reviewed studies, we critically examine existing IDS approaches, categorising them by the types of attacks they detect—known, unknown, and combined known-unknown attacks—while identifying their limitations. We also review the evaluation metrics used in research, emphasising the need to consider multiple criteria to meet the requirements of safety-critical systems. Additionally, we analyse FL-based IDSs and highlight their limitations. By doing so, this survey helps identify effective security measures, address existing limitations, and guide future research toward more resilient and adaptive protection mechanisms, ensuring the safety and reliability of CAVs. Muzun Althunayyan, Amir Javed, Omer F. Rana |
Comput. Networks | 2 |
| 2026 | Beyond the automation gap: A survey of continuous audit for IoT securityabstractDespite decades of research into automated compliance, real-world adoption remains surprisingly low. This implementation gap is particularly significant for auditing Internet of Things (IoT) environments, where the sheer volume of connected devices makes manual security auditing challenging. This adoption gap could cause severe business and governance risks, such as operational disruptions and massive regulatory penalties. By following PRISMA methodology, our review investigates why computer-assisted auditing technologies fail to gain traction in practice. We trace the evolution of compliance automation and reveal a fundamental disconnect: the adoption gap emerges not from technological inadequacy but from interconnected research tensions that neglected the traceability and auditability of the audit itself. Our analysis suggests that closing the adoption gap requires research realignment in a human-centered auditing framework that could be supported by technologies and identifies where each could augment human auditors. Rather than pursuing ever-more sophisticated automation, we argue that effective auditing tools must augment human expertise through responsible human–computer interaction. The review synthesizes diverse approaches across process mining, rule-based matching, machine learning, and language models, consistently finding that technical excellence alone cannot bridge the implementation gap. We conclude by presenting a research roadmap that guides security researchers toward building practically viable solutions that leverage strong technological foundations while addressing the urgent, real-world needs of auditors. Obrina Candra Briliyant, Amir Javed, Yulia Cherdantseva |
Comput. Secur. | 2 |
| 2024 | Detecting the Abuse of Cloud Services for C&C Infrastructure Through Dynamic Analysis and Machine LearningabstractCybercriminals increasingly abuse cloud and legitimate services (CLS) as covert command and control (C&C) infrastructure to orchestrate malicious operations and evade detection. This paper addresses the critical challenge of detecting such abuse of cloud platforms. We introduce a detection system that integrates dynamic analysis with Machine Learning (ML) to accurately distinguish between benign and malicious interactions with cloud services. By utilising a comprehensive data set from VirusTotal, the system uses advanced feature extraction techniques from both host behaviour and network traffic, using Cuckoo and Triage sandboxes to extract behaviors, to develop a detection model. The results demonstrate that the model achieves nearly 98% accuracy in identifying cloud service abuse, substantially outperforming previous efforts. Furthermore, we evaluate the model's robustness against adversarial attacks that aim to decrease accuracy by manipulating the feature values. Comparative evaluations show that our method maintains a higher detection accuracy under attack compared to related systems. Turki Al Lelah, George Theodorakopoulos 0001, Amir Javed, Eirini Anthi |
ISNCC | 3 |
| 2023 | A Fuzzy-Based Approach to Enhance Cyber Defence Security for Next-Generation IoTabstractIn the modern era, the Cognitive Internet of Things (CIoT) in conjunction with IoT evolves which provides the intelligence power of sensing and computation for next-generation IoT (Nx-IoT) networks. The data scientists have discovered a large amount of techniques for knowledge discovery from processed data in CIoT. This task is accomplished successfully and data proceeds for further processing. The major cause for the failure of IoT devices is due to the attacks, in which Web spam is more prominent. There seems a requirement of a technique which can detect the Web spam before it enters into a device. Motivated from these issues, in this article, a cognitive spammer framework (CSF) for Web spam detection is proposed. CSF detects the Web spam by fuzzy rule-based classifiers along with machine learning classifiers. Each classifier produces the quality score of the webpage. These quality scores are then ensembled to generate a single score, which predicts the spamicity of the webpage. For ensembling, the fuzzy voting approach is used in CSF. The experiments were performed using a standard data set WEBSPAM-UK 2007 with respect to accuracy and overhead generated. From the results obtained, it has been demonstrated that CSF improves the accuracy by 97.3%, which is comparatively high in comparison to the other existing approaches in the literature. Aaisha Makkar, Uttam Ghosh, Pradip Kumar Sharma, Amir Javed |
IEEE Internet Things J. | 4 |
| 2022 | Adversarial machine learning in IoT from an insider point of viewabstractWith the rapid progress and significant successes in various applications, machine learning has been considered a crucial component in the Internet of Things ecosystem. However, machine learning models have recently been vulnerable to carefully crafted perturbations, so-called adversarial attacks. A capable insider adversary can subvert the machine learning model at either the training or testing phase, causing them to behave differently. The vulnerability of machine learning to adversarial attacks becomes one of the significant risks. Therefore, there is a need to secure machine learning models enabling the safe adoption in malicious insider cases. This paper reviews and organizes the body of knowledge in adversarial attacks and defense presented in IoT literature from an insider adversary point of view. We proposed a taxonomy of adversarial methods against machine learning models that an insider can exploit. Under the taxonomy, we discuss how these methods can be applied in real-life IoT applications. Finally, we explore defensive methods against adversarial attacks. We believe this can draw a comprehensive overview of the scattered research works to raise awareness of the existing insider threats landscape and encourages others to safeguard machine learning models against insider threats in the IoT ecosystem. Fatimah Aloraini, Amir Javed, Omer F. Rana, Pete Burnap |
J. Inf. Secur. Appl. | 2 |
| 2022 | Security analytics for real-time forecasting of cyberattacksabstractSummary Protection of networked computing infrastructures (such as Internet of Things, Industrial Control Systems, and Edge computing) is dependent on the continuous monitoring of interaction between such devices and network/Cloud‐based hosts (especially in Industry 4.0 environments). This real‐time monitoring enables an analyst to quantify evolving and emerging threats to such network infrastructures. A framework for identifying patterns in observed cyberthreats and the use of these patterns for forecasting the growth of an emerging threat to network infrastructure is proposed. This framework enables predicting the maximum threat intensity and the time period over which this maximum intensity is likely to occur. The proposed framework integrates: (a) continuous monitoring of device/network activity, (b) forecasting behavior using exponentially weighted moving averages, (c) utilizing Fibonacci retracement for estimating the potential intensity of a cyberattack, and (d) linear regression for predicting response time for high risk thresholds and a machine learning strategy to predict potential risk over a pre‐defined time window. Using this approach, we can produce time intervals between the forecast and the actual attacks using real‐world network activity data. Our results show an average lead time of around 1.75 hours, providing a window of opportunity to limit the impact of an attack and counter it. Amir Javed, Mike Lakoju, Pete Burnap, Omer F. Rana |
Softw. Pract. Exp. | 1 |
| 2021 | Hardening machine learning denial of service (DoS) defences against adversarial attacks in IoT smart home networksabstractMachine learning based Intrusion Detection Systems (IDS) allow flexible and efficient automated detection of cyberattacks in Internet of Things (IoT) networks. However, this has also created an additional attack vector; the machine learning models which support the IDS’s decisions may also be subject to cyberattacks known as Adversarial Machine Learning (AML). In the context of IoT, AML can be used to manipulate data and network traffic that traverse through such devices. These perturbations increase the confusion in the decision boundaries of the machine learning classifier, where malicious network packets are often miss-classified as being benign. Consequently, such errors are bypassed by machine learning based detectors, which increases the potential of significantly delaying attack detection and further consequences such as personal information leakage, damaged hardware, and financial loss. Given the impact that these attacks may have, this paper proposes a rule-based approach towards generating AML attack samples and explores how they can be used to target a range of supervised machine learning classifiers used for detecting Denial of Service attacks in an IoT smart home network. The analysis explores which DoS packet features to perturb and how such adversarial samples can support increasing the robustness of supervised models using adversarial training. The results demonstrated that the performance of all the top performing classifiers were affected, decreasing a maximum of 47.2 percentage points when adversarial samples were present. Their performances improved following adversarial training, demonstrating their robustness towards such attacks. Eirini Anthi, Lowri Williams, Amir Javed, Pete Burnap |
Comput. Secur. | 3 |
| 2020 | Emotions Behind Drive-by Download Propagation on TwitterabstractTwitter has emerged as one of the most popular platforms to get updates on entertainment and current events. However, due to its 280-character restriction and automatic shortening of URLs, it is continuously targeted by cybercriminals to carry out drive-by download attacks, where a user’s system is infected by merely visiting a Web page. Popular events that attract a large number of users are used by cybercriminals to infect and propagate malware by using popular hashtags and creating misleading tweets to lure users to malicious Web pages. A drive-by download attack is carried out by obfuscating a malicious URL in an enticing tweet and used as clickbait to lure users to a malicious Web page. In this article, we answer the following two questions: Why are certain malicious tweets retweeted more than others? Do emotions reflecting in a tweet drive virality? We gathered tweets from seven different sporting events over 3 years and identified those tweets that were used to carry to out a drive-by download attack. From the malicious (N= 105, 642) and benign (N= 169, 178) data sample identified, we built models to predict information flow size and survival. We define size as the number of retweets of an original tweet, and survival as the duration of the original tweet’s presence in the study window. We selected the zero-truncated negative binomial (ZTNB) regression method for our analysis based on the distribution exhibited by our dependent size measure and the comparison of results with other predictive models. We used the Cox regression technique to model the survival of information flows as it estimates proportional hazard rates for independent measures. Our results show that both social and content factors are statistically significant for the size and survival of information flows for both malicious and benign tweets. In the benign data sample, positive emotions and positive sentiment reflected in the tweet significantly predict size and survival. In contrast, for the malicious data sample, negative emotions, especially fear, are associated with both size and survival of information flows. Amir Javed, Pete Burnap, Matthew L. Williams, Omer F. Rana |
ACM Trans. Web | 1 |
| 2019 | Prediction of drive-by download attacks on TwitterabstractThe popularity of Twitter for information discovery, coupled with the automatic shortening of URLs to save space, given the 140 character limit, provides cybercriminals with an opportunity to obfuscate the URL of a malicious Web page within a tweet. Once the URL is obfuscated, the cybercriminal can lure a user to click on it with enticing text and images before carrying out a cyber attack using a malicious Web server. This is known as a drive-by download . In a drive-by download a user's computer system is infected while interacting with the malicious endpoint, often without them being made aware the attack has taken place. An attacker can gain control of the system by exploiting unpatched system vulnerabilities and this form of attack currently represents one of the most common methods employed. In this paper we build a machine learning model using machine activity data and tweet metadata to move beyond post-execution classification of such URLs as malicious, to predict a URL will be malicious with 0.99 F -measure (using 10-fold cross-validation) and 0.833 (using an unseen test set) at 1 s into the interaction with the URL. Thus, providing a basis from which to kill the connection to the server before an attack has completed and proactively blocking and preventing an attack, rather than reacting and repairing at a later date. Amir Javed, Pete Burnap, Omer F. Rana |
Inf. Process. Manag. | 1 |
| 2015 | Real-time Classification of Malicious URLs on Twitter using Machine Activity DataabstractMassive online social networks with hundreds of millions of active users are increasingly being used by Cyber criminals to spread malicious software (malware) to exploit vulnerabilities on the machines of users for personal gain. Twitter is particularly susceptible to such activity as, with its 140 character limit, it is common for people to include URLs in their tweets to link to more detailed information, evidence, news reports and so on. URLs are often shortened so the endpoint is not obvious before a person clicks the link. Cyber criminals can exploit this to propagate malicious URLs on Twitter, for which the endpoint is a malicious server that performs unwanted actions on the person's machine. This is known as a drive-by-download. In this paper we develop a machine classification system to distinguish between malicious and benign URLs within seconds of the URL being clicked (i.e. 'real-time'). We train the classifier using machine activity logs created while interacting with URLs extracted from Twitter data collected during a large global event -- the Superbowl -- and test it using data from another large sporting event -- the Cricket World Cup. The results show that machine activity logs produce precision performances of up to 0.975 on training data from the first event and 0.747 on a test data from a second event. Furthermore, we examine the properties of the learned model to explain the relationship between machine activity and malicious software behaviour, and build a learning curve for the classifier to illustrate that very small samples of training data can be used with only a small detriment to performance. Pete Burnap, Amir Javed, Omer F. Rana, Malik Shahzad Kaleem Awan |
ASONAM | 2 |
| 2013 | Comparison of glacier change detection using pixel based and object based classification techniquesabstractGlaciers are important indicators of sustainable life on the globe by various means and hence provide a good motivation for continuous monitoring. Temporal analysis of two valley glaciers (namely Apsara and Singhi lie in Shaksgam valley, China) have been performed using supervised, knowledge and object based classification techniques. Landsat MSS and TM data from 1978 to 2011 have been used. It has been observed that object based and supervised classifications are relatively more effective than knowledge based classification to detect the glaciers change having 95%, 93% and 86% overall accuracy respectively. Variation in glaciers extent is due to their characteristics relating to topography, geographic condition, orientation, altitude as well as local climate conditions. Apsara and Singhi glacier lost 3.32 and 8.98 percent of their area respectively throughout the study period. Chaman Gul, Amir Javed, Javeria Muneer, Mirza Muhammad Waqar |
IGARSS | 3 |