VLDB 2026 Research / reviewers in the wild / expert
Meisam Mohammady
dblp:149/2441
· DBLP profile ↗
18ranked-venue papers
3as first author
15since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 3 first-author · 11 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Usability of Data with Privacy: A Unified Framework for Privacy-Preserving Data Sharing with High Utility
Mahawaga Arachchige Pathum Chamikara, Seung Ick Jang, Ian J. Oppermann, Dongxi Liu, Musotto Roberto, Sushmita Ruj, Arindam Pal 0001, Meisam Mohammady, Seyit Ahmet Çamtepe, Sylvia Young, Chris Dorrian, Nasir David |
AsiaCCS | 8 |
| 2025 | PLRV-O: Advancing Differentially Private Deep Learning via Privacy Loss Random Variable OptimizationabstractDifferentially Private Stochastic Gradient Descent (DP-SGD) is a standard method for enforcing privacy in deep learning, typically using the Gaussian mechanism to perturb gradient updates. However, conventional mechanisms such as Gaussian and Laplacian noise are parameterized only by variance or scale. This single degree of freedom ties the magnitude of noise directly to both privacy loss and utility degradation, preventing independent control of these two factors. The problem becomes more pronounced when the number of composition rounds T and batch size B vary across tasks, as these variations induce task-dependent shifts in the privacy–utility trade-off, where small changes in noise parameters can disproportionately affect model accuracy. To address this limitation, we introduce PLRV-O, a framework that defines a broad search space of parameterized DP-SGD noise distributions, where privacy loss moments are tightly characterized yet can be optimized more independently with respect to utility loss. This formulation enables systematic adaptation of noise to task-specific requirements, including (i) model size, (ii) training duration, (iii) batch sampling strategies, and (iv) clipping thresholds under both training and fine-tuning settings. Empirical results demonstrate that PLRV-O substantially improves utility under strict privacy constraints. On CIFAR-10, a fine-tuned ViT achieves 94.03% accuracy at ∈ ≈ 0.5, compared to 83.93% with Gaussian noise. On SST-2, RoBERTa-large reaches 92.20% accuracy at ∈ ≈ 0.2, versus 50.25% with Gaussian. Source code is available at https://github.com/datasec-lab/plrvo. Qin Yang 0009, Nicholas Stout, Meisam Mohammady, Han Wang 0021, Ayesha Samreen, Christopher J. Quinn, Yan Yan 0002, Ashish Kundu, Yuan Hong 0001 |
CCS | 3 |
| 2025 | Harmonizing Differential Privacy Mechanisms for Federated Learning: Boosting Accuracy and ConvergenceabstractDifferentially private federated learning (DP-FL) offers a compelling approach to collaborative model training by ensuring robust privacy for clients. Despite its potential, current methods face challenges in effectively balancing privacy, utility, and performance across diverse federated learning scenarios. Addressing these challenges, we introduce UDP-FL, to our knowledge the first DP-FL framework that universally harmonizes any randomization mechanism, including those considered optimal, by employing the Gaussian Moments Accountant (viz. DP-SGD). Central to UDP-FL is the 'Harmonizer,' a dynamic module engineered to intelligently select and apply the most suitable DP mechanism tailored to each client's specific privacy requirements, data sensitivities, and computational capacities. This selection process is driven by the principle of Rényi Differential Privacy, which serves as a crucial mediator for aligning privacy budgets effectively. Our comprehensive evaluation of UDP-FL, benchmarked against established baseline methods, demonstrates superior performance in upholding privacy guarantees and enhancing model functionality. The framework's robustness has been rigorously tested against a broad spectrum of privacy attacks, making it one of the most thorough validations of a DP-FL framework to date. Shuya Feng, Meisam Mohammady, Hanbin Hong, Shenao Yan, Ashish Kundu, Binghui Wang, Yuan Hong 0001 |
CODASPY | 2 |
| 2025 | FedSIG: Privacy-Preserving Federated Recommendation via Synthetic Interaction GenerationabstractRecommendation Systems (RS) play an important role in our everyday life in this data-driven digital era by providing users with the convenience of navigating the plethora of available choices. An RS collects user behavioural data to provide them with valuable suggestions. The growing privacy concerns regarding private data collection have led to the use of Federated Learning (FL) to implement RS. However, many research works have exposed the privacy leakages in FL gradient sharing. The embedding gradients shared by FL users during the RS model training can be used to infer the items that users have interacted with. Existing defences, such as random noise injection or pseudo-interaction sampling to obfuscate the privacysensitive information reflected by the shared gradients. However, these techniques provide limited protection and often result in substantial degradation of recommendation performance, leading to an unfavourable privacy–utility trade-off. In this paper, we propose FedSIG (Federated Synthetic Interaction Generation), a defence mechanism that mitigates useritem interaction inference in federated recommendation systems by generating synthetic interaction data using generative models. The generated items are selectively used to replace or augment real user interactions, thereby obfuscating sensitive data while preserving user preference signals. To further enhance utility, we design an item selection module based on an attention mechanism to identify less contributive interactions for replacement. Extensive experiments conducted on five real-world datasets and two state-of-the-art recommendation models demonstrate that FedSIG achieves a significantly improved privacy–utility balance compared to existing approaches, effectively reducing inference success rates while maintaining competitive recommendation accuracy. Thirasara Ariyarathna, Salil S. Kanhere, Meisam Mohammady, Hye-Young Paik |
RAID | 3 |
| 2025 | UD-LDP: A Technique for optimally catalyzing user driven Local Differential PrivacyabstractLocal Differential Privacy (LDP) has emerged as a popular mechanism for crowd-sourced data collection, but enforcing a uniform level of perturbation may hinder the participation of individuals with higher privacy needs, while high privacy levels that satisfy more users can reduce utility. To address this, we propose a cohort-based mechanism that allows participants to choose the privacy level from a predefined set. We investigate optimal cohort configurations and uncover insights about utility convexity, enabling the identification of privacy-utility balanced settings. Our proposed mechanism, called UD-LDP, empowers users, promotes transparency, and facilitates suitable privacy budget selection. We demonstrate the effectiveness of cohortisation through experiments on synthetic and real-world datasets. Gnana Thedchanamoorthy, Michael Bewong, Meisam Mohammady, Tanveer A. Zia, Md Zahidul Islam 0001 |
Future Gener. Comput. Syst. | 3 |
| 2024 | VLIA: Navigating Shadows with Proximity for Highly Accurate Visited Location Inference Attack against Federated Recommendation ModelsabstractPersonalized location recommendation allows users to enjoy a seamless travel experience by suggesting the optimal travel locations/routes based on user preferences. Most service providers collect users' location data centrally to develop accurate route recommendation applications. Federated learning (FL) can be used as an inherent privacy-preserving mechanism in these applications to prevent users from sharing private data. However, recent research shows that FL is still vulnerable to privacy leakages. Therefore, many FL-based recommendation systems use Local Differential Privacy (LDP) to defend against such attacks. In this paper, we propose the Visited Location Inference Attack (VLIA), a novel attack for federated location recommendation systems through the lens of Membership Inference Attack (MIA). Specifically, we focus on inferring user behaviour data (visited locations) even when the federated recommendation system is protected with LDP. We design and implement VLIA leveraging both embedding and proximity information of locations, making the inference more accurate. Our extensive experiments with two state-of-the-art personalized route recommendation (PRR) systems implemented in the FL setting and two real-world trajectory datasets showcase the effectiveness of the VLIA attack. Our results show that LDP cannot defend VLIA unless the recommendation performance is significantly compromised. Thirasara Ariyarathna, Meisam Mohammady, Hye-Young Paik, Salil S. Kanhere |
AsiaCCS | 2 |
| 2024 | Mitigating Distributed Backdoor Attack in Federated Learning Through Mode ConnectivityabstractFederated Learning (FL) is a privacy-preserving, collaborative machine learning technique where multiple clients train a shared model on their private datasets without sharing the data. While offering advantages, FL is susceptible to backdoor attacks, where attackers insert malicious model updates into the model aggregation process. Compromised models predict attacker-chosen targets when presented with specific attacker-defined inputs. Backdoor defences generally rely on anomaly detection techniques based on Differential Privacy (DP) or require legitimate clean test examples at the server. Anomaly detection-based defences can be defeated by stealth techniques and generally require inspection of client-submitted model updates. DP-based approaches tend to degrade the performance of the trained model due to excessive noise addition during training. Methods that require legitimate clean data on the server require strong assumptions about the task and may not be applicable in real-world settings. In this work, we view the question of backdoor attack robustness through the lens of loss function optimal points to build a defence that overcomes these limitations. We propose Mode Connectivity Based Federated Learning (MCFL), which leverages the recently discovered property of neural network loss surfaces, mode connectivity. We simulate backdoor attack scenarios using computer vision benchmark datasets, including CIFAR10, Fashion MNIST, MNIST, and Federated EMNIST. Our findings show that MCFL converges to high-quality models and effectively mitigates backdoor attacks relative to baseline defences from the literature without requiring inspection of client model updates or assuming clean data at the server. Kane Walter, Meisam Mohammady, Surya Nepal, Salil S. Kanhere |
AsiaCCS | 2 |
| 2024 | DPI: Ensuring Strict Differential Privacy for Infinite Data StreamingabstractStreaming data, crucial for applications like crowd-sourcing analytics, behavior studies, and real-time monitoring, faces significant privacy risks due to the large and diverse data linked to individuals. In particular, recent efforts to release data streams, using the rigorous privacy notion of differential privacy (DP), have encountered issues with unbounded privacy leakage. This challenge limits their applicability to only a finite number of time slots ("finite data stream") or relaxation to protecting the events ("event or w-event DP") rather than all the records of users. A persistent challenge is managing the sensitivity of outputs to inputs in situations where users contribute many activities and data distributions evolve over time. In this paper, we present a novel technique for Differentially Private data streaming over Infinite disclosure (DPI) that effectively bounds the total privacy leakage of each user in infinite data streams while enabling accurate data collection and analysis. Furthermore, we also maximize the accuracy of DPI via a novel boosting mechanism. Finally, extensive experiments across various streaming applications and real datasets (e.g., COVID-19, Network Traffic, and USDA Production), show that DPI maintains high utility for infinite data streams in diverse settings. Code for DPI is available at https://github.com/ShuyaFeng/DPI. Shuya Feng, Meisam Mohammady, Han Wang 0021, Zhan Qin, Yuan Hong 0001 |
SP | 2 |
| 2024 | FUD-LDP: Fully User Driven Local Differential Privacy
Gnana Thedchanamoorthy, Michael Bewong, Meisam Mohammady, Tanveer A. Zia, Md Zahidul Islam 0001 |
WISE (5) | 3 |
| 2024 | Optimally Mitigating Backdoor Attacks in Federated LearningabstractFederated learning (FL) is a distributed, privacy-preserving learning paradigm where a joint model is trained on private data stored on client devices. Data owners (clients) train models locally and then submit them to an aggregation server for incorporation into the joint model. Malicious clients can apply training time attacks, e.g., backdoor attacks, by submitting maliciously trained models. Prior work has shown that Differential Privacy (DP) can provide certified robustness to backdoor attacks; however, there are limited studies regarding DP parameter selection as a function of the model architecture. In this work, we show empirically that larger models (i.e., with more parameters) require stronger DP parameter settings to mitigate backdoor attacks. Furthermore, we present a framework that alters the FL training algorithm to preserve certified accuracy round-by-round and show empirically that it is superior to a model trainer selecting DP parameters ahead of time before training begins and with incomplete information about the attacker. Although tools from DP are used in our proposed framework, it is focused on backdoor attack mitigation and does not provide privacy guarantees. Kane Walter, Meisam Mohammady, Surya Nepal, Salil S. Kanhere |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | A Generalized Framework for Preserving Both Privacy and Utility in Data OutsourcingabstractProperty preserving encryption techniques have significantly advanced the utility of encrypted data in data outsourcing. However, while preserving certain properties (e.g., the prefixes or order of the data) in the encrypted data, such encryption schemes are typically limited to specific data types (e.g., IP addresses) or applications (e.g., range queries over order-preserved data), and highly vulnerable to the emerging inference attacks which may greatly limit their applications in practice. In this paper, to the best of our knowledge, we make the first attempt to generalize the prefix-preserving encryption to make it applicable to more general data types (e.g., geo-locations, market basket data, DNA sequences, numerical data and timestamps) and secure against the inference attacks. Furthermore, we present a generalized multi-view outsourcing framework that generates multiple indistinguishable data views in which one view fully preserves the utility for data analysis, and its accurate analysis result can be obliviously retrieved. We empirically evaluate the performance of our outsourcing framework against two common inference attacks on two different real datasets: the check-in location dataset and network traffic dataset. The experimental results demonstrate that our proposed framework preserves both privacy (with bounded leakage and indistinguishable data views) and utility (with 100% analysis accuracy). Shangyu Xie, Meisam Mohammady, Han Wang 0021, Lingyu Wang 0001, Jaideep Vaidya, Yuan Hong 0001 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2022 | A Generalized Framework for Preserving Both Privacy and Utility in Data Outsourcing (Extended Abstract)abstractIn this paper, we propose a prefix-preserving encryption based data outsourcing framework which is applicable to multiple different types of data, such as geo-locations, market basket data, DNA sequences, numerical data and timestamps. It enables accurate data analyses on the encrypted data while ensuring strong privacy against inference attacks. The basic idea is to generates multiple indistinguishable data views in which one view fully preserves the utility for data analysis, and its accurate analysis result can be obliviously retrieved. We empirically evaluate the performance of our outsourcing framework against two common inference attacks on two different real datasets: the check-in location dataset and network traffic dataset, respectively. The experimental results demonstrate that our proposed framework preserves both privacy (with bounded leakage and indistinguishability of data views) and utility. Shangyu Xie, Meisam Mohammady, Han Wang 0021, Lingyu Wang 0001, Jaideep Vaidya, Yuan Hong 0001 |
ICDE | 2 |
| 2021 | VTDP: Privately Sanitizing Fine-Grained Vehicle Trajectory Data With Boosted UtilityabstractWith the rapidly growing deployment of intelligent transportation systems (ITS) and smart traffic applications, vehicle trajectory data are ubiquitously generated, e.g., from GPS navigation systems, mobile applications, and urban traffic cameras. Analyzing such fine-grained data would greatly benefit the development of ITS and smart cities, yet pose severe privacy risks due to the recorded drivers’ visited locations, routes, and driving habits. Recently, some privacy enhancing techniques were proposed to sanitize such data. However, such schemes have some major limitations–they either lack formal privacy notions to quantify and bound the privacy risks, or result in very limited utility, e.g., only a sequence of locations or aggregated information can be released (without retaining the speeds, accelerations and the timestamps of vehicles). In this article, we propose a novel framework to sanitize the fine-grainedvehicle trajectories with differential privacy(VTDP), which provides rigorous privacy protection against adversaries who possess arbitrary background knowledge. Our VTDP technique involves three phases of differentially private sampling, which sequentially generate all the three categories of data (besides a pseudo identity for each vehicle)–position, moving,andtimestamps. It also includes avehicle trajectory interpolationprocedure to further improve the output utility with the properties of fine-grained vehicle trajectory data. We conducted experiments on real vehicle trajectory datasets to validate the performance of our approach. Shangyu Xie, Han Wang 0021, Yuan Hong 0001, Xuegang Ban, Meisam Mohammady |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | SegGuard: Segmentation-Based Anonymization of Network Data in Clouds for Privacy-Preserving Security AuditingabstractSecurity auditing allows cloud tenants to verify the compliance of cloud infrastructure with respect to desirable security properties, e.g., whether a tenant’s virtual network is properly isolated from other tenants’ networks. However, the input to the auditing task, such as the detailed topology of the underlying cloud infrastructure, typically contains sensitive information which a cloud provider may be reluctant to hand over to a third party auditor. Additionally, auditing results intended for one tenant may inadvertently reveal private information about other tenants, e.g., another tenant’s VM is reachable due to a misconfiguration. How to anonymize both the input data and the auditing results in order to prevent such information leakage is a novel challenge that has received little attention. Directly applying most of the existing anonymization techniques to such a context would either lead to insufficient protection or render the data unsuitable for auditing. In this article, we proposeSegGuard, a novel anonymization approach that prevents cross-tenant information leakage through per-tenant encryption, and prevents information leakage to auditors through hiding real input segments among fake ones; in addition, applying property-preserving encryption in an innovative way enablesSegGuardto preserve the data utility for auditing while mitigating semantic attacks. We implementSegGuardbased on OpenStack, and evaluate its effectiveness and overhead using both synthetic and real data. Our experimental results demonstrate thatSegGuardcan reduce the information leakage to a negligible level (e.g., less than 1 percent for an adversary with 50 percent pre-knowledge) with a practical response time (e.g., 62 seconds to anonymize a cloud infrastructure with 25,000 virtual machines). Momen Oqaily, Yosr Jarraya, Meisam Mohammady, Suryadipta Majumdar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | A Multi-view Approach to Preserve Privacy and Utility in Network Trace AnonymizationabstractAs network security monitoring grows more sophisticated, there is an increasing need for outsourcing such tasks to third-party analysts. However, organizations are usually reluctant to share their network traces due to privacy concerns over sensitive information, e.g., network and system configuration, which may potentially be exploited for attacks. In cases where data owners are convinced to share their network traces, the data are typically subjected to certain anonymization techniques, e.g., CryptoPAn, which replaces real IP addresses with prefix-preserving pseudonyms. However, most such techniques either are vulnerable to adversaries with prior knowledge about some network flows in the traces or require heavy data sanitization or perturbation, which may result in a significant loss of data utility. In this article, we aim to preserve both privacy and utility through shifting the trade-off from between privacy and utility to between privacy and computational cost. The key idea is for the analysts to generate and analyze multiple anonymized views of the original network traces: Those views are designed to be sufficiently indistinguishable even to adversaries armed with prior knowledge, which preserves the privacy, whereas one of the views will yield true analysis results privately retrieved by the data owner, which preserves the utility. We formally analyze the privacy of our solution and experimentally evaluate it using real network traces provided by a major ISP. The experimental results show that our approach can significantly reduce the level of information leakage (e.g., less than 1% of the information leaked by CryptoPAn) with comparable utility. Meisam Mohammady, Momen Oqaily, Lingyu Wang 0001, Yuan Hong 0001, Habib Louafi, Makan Pourzandi, Mourad Debbabi |
ACM Trans. Priv. Secur. | 1 |
| 2020 | R2DP: A Universal and Automated Approach to Optimizing the Randomization Mechanisms of Differential Privacy for Utility Metrics with No Known Optimal DistributionsabstractDifferential privacy (DP) has emerged as a de facto standard privacy notion for a wide range of applications. Since the meaning of data utility in different applications may vastly differ, a key challenge is to find the optimal randomization mechanism, i.e., the distribution and its parameters, for a given utility metric. Existing works have identified the optimal distributions in some special cases, while leaving all other utility metrics (e.g., usefulness and graph distance) as open problems. Since existing works mostly rely on manual analysis to examine the search space of all distributions, it would be an expensive process to repeat such efforts for each utility metric. To address such deficiency, we propose a novel approach that can automatically optimize different utility metrics found in diverse applications under a common framework. Our key idea that, by regarding the variance of the injected noise itself as a random variable, a two-fold distribution may approximately cover the search space of all distributions. Therefore, we can automatically find distributions in this search space to optimize different utility metrics in a similar manner, simply by optimizing the parameters of the two-fold distribution. Specifically, we define a universal framework, namely, randomizing the randomization mechanism of differential privacy (R2DP), and we formally analyze its privacy and utility. Our experiments show that R2DP can provide better results than the baseline distribution (Laplace) for several utility metrics with no known optimal distributions, whereas our results asymptotically approach to the optimality for utility metrics having known optimal distributions. As a side benefit, the added degree of freedom introduced by the two-fold distribution allows R2DP to accommodate the preferences of both data owners and recipients. Meisam Mohammady, Shangyu Xie, Yuan Hong 0001, Mengyuan Zhang 0001, Lingyu Wang 0001, Makan Pourzandi, Mourad Debbabi |
CCS | 1 |
| 2019 | Proactivizer: Transforming Existing Verification Tools into Efficient Solutions for Runtime Security Enforcement
Suryadipta Majumdar, Azadeh Tabiban, Meisam Mohammady, Alaa Oqaily, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (2) | 3 |
| 2018 | Preserving Both Privacy and Utility in Network Trace AnonymizationabstractAs network security monitoring grows more sophisticated, there is an increasing need for outsourcing such tasks to third-party analysts. However, organizations are usually reluctant to share their network traces due to privacy concerns over sensitive information, e.g., network and system configuration, which may potentially be exploited for attacks. In cases where data owners are convinced to share their network traces, the data are typically subjected to certain anonymization techniques, e.g., CryptoPAn, which replaces real IP addresses with prefix-preserving pseudonyms. However, most such techniques either are vulnerable to adversaries with prior knowledge about some network flows in the traces, or require heavy data sanitization or perturbation, both of which may result in a significant loss of data utility. In this paper, we aim to preserve both privacy and utility through shifting the trade-off from between privacy and utility to between privacy and computational cost. The key idea is for the analysts to generate and analyze multiple anonymized views of the original network traces; those views are designed to be sufficiently indistinguishable even to adversaries armed with prior knowledge, which preserves the privacy, whereas one of the views will yield true analysis results privately retrieved by the data owner, which preserves the utility. We formally analyze the privacy of our solution and experimentally evaluate it using real network traces provided by a major ISP. The results show that our approach can significantly reduce the level of information leakage (e.g., less than 1% of the information leaked by CryptoPAn) with comparable utility. Meisam Mohammady, Lingyu Wang 0001, Yuan Hong 0001, Habib Louafi, Makan Pourzandi, Mourad Debbabi |
CCS | 1 |