VLDB 2026 Research / reviewers in the wild / expert
Thien Duc Nguyen
dblp:153/5738
· DBLP profile ↗
15ranked-venue papers
3as first author
6since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 3 since 2021Computer networks · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Fed-FeRe: An Enhancing Approach for Efficient Anomaly Detection in IoT SecurityabstractThe proliferation of the Internet of Things (IoT) significantly enhances the complexity of device interactions within these networks, elevating susceptibility to cyber threats. Anomaly detection is crucial in defending IoT systems against these threats while preserving user privacy. In this study, we introduce a novel federated learning-based approach, named Fed−FeRe, which integrates federated learning with a Chi-Square-based feature reduction technique and a Gated Recurrent Unit (GRU) model to address anomaly detection in IoT networks. This integration improves the accuracy of anomaly detection and reduces the computational burden and communication overhead in scenarios with non-independent and identically distributed (non-IID) data, typical in IoT environments. Our comprehensive evaluations demonstrate that our approach significantly enhances detection accuracy while reducing communication and computational demands, affirming the potential for real-world applications. This paper contributes to advancing machine learning techniques in enhancing IoT security, offering a robust, decentralised anomaly detection method that ensures data privacy across diverse IoT environments. Thien Duc Nguyen |
GLOBECOM | 1 |
| 2024 | SoK: A Comprehensive Analysis and Evaluation of Docker Container Attack and Defense MechanismsabstractContainer-based applications are increasingly favored for their efficiency in software development, deployment, and operation across various platforms. However, the growing number of security and privacy attacks poses significant concerns. Exploiting vulnerabilities within containers may compromise the entire host system, as both share the same operating system. Unfortunately, container defense mechanisms are inadequate due to the ever-evolving and dynamic attack landscape.In this paper, we systematize container attacks and defense mechanisms. We systematically analyze the effectiveness of (i) static container scanning tools proposed for vulnerability detection and reveal their shortcomings, as well as (ii) existing run-time anomaly-based detection approaches. We then establish an evaluation framework and comprehensively re-evaluate cutting-edge anomaly detection techniques tailored for containers using an extensive dataset of 51 real-world vulnerabilities. We emphasize that existing defenses are ineffective in protecting containers against state-of-the-art attacks. While anomaly detection-based approaches show potential in addressing dynamic attack landscapes, their high false positive rates and limited training data hinder practicality. Therefore, our work highlights the urgent need for further research to enhance the security of container-based applications. Md. Sadun Haq, Thien Duc Nguyen, Ali Saman Tosun, Franziska Vollmer, Turgay Korkmaz, Ahmad-Reza Sadeghi |
SP | 2 |
| 2023 | Design of a Robust MAC Protocol for LoRaabstractLow-power wide-area networks enable large-scale deployments of low-power wireless devices. LoRaWAN is a long-range wireless technology that has emerged as a low-power and low data rate solution to support Internet of Things applications. Although LoRaWAN provides a low-power and cost-efficient networking solution, recent literature shows that it performs poorly in terms of reliability and security in dense deployments due to the uncoordinated (ALOHA-based) nature of the MAC (medium access control) protocol. Furthermore, LoRaWAN is not robust against selective jamming attacks. This article proposes CRAM: a time-synchronized cryptographic frequency hopping MAC protocol designed for the LoRa physical layer. CRAM reduces the contention by fairly exploiting the available frequency space and maximizes the entropy of the channel hopping algorithm. We develop a large physical testbed and a simulator to thoroughly evaluate the proposed protocol. Our evaluations show that CRAM significantly improves reliability and scalability and increases channel utilization while making selective jamming difficult to perform compared to the standard LoRaWAN protocol. Absar-Ul-Haque Ahmar, Emekcan Aras, Thien Duc Nguyen, Sam Michiels, Wouter Joosen, Danny Hughes 0001 |
ACM Trans. Internet Things | 3 |
| 2022 | DeepSight: Mitigating Backdoor Attacks in Federated Learning Through Deep Model Inspection
Phillip Rieger, Thien Duc Nguyen, Markus Miettinen, Ahmad-Reza Sadeghi |
NDSS | 2 |
| 2022 | FLAME: Taming Backdoors in Federated Learning
Thien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame, Helen Möllering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, Azalia Mirhoseini, Shaza Zeitouni, Farinaz Koushanfar, Ahmad-Reza Sadeghi, Thomas Schneider 0003 |
USENIX Security Symposium | 1 |
| 2021 | EH-CRAM: A Sustainable Energy Harvesting Algorithm for LPWANsabstractLow Power Wide Area Network (LPWAN) technologies offer the advantage of wide coverage areas and low power consumption for low data-rate Internet-of-Things (IoT) applications. LoRaWAN, the Long Range Wide Area Network is a key technology in this space, with a growing worldwide presence. LoRa devices are expected to operate autonomously for extended periods in order to support diverse IoT applications. Despite being energy efficient, frequent battery replacements are typically required over the lifetime of a LoRa device. This increases maintenance costs and furthermore, disposing of large numbers of dead batteries is damaging to the environment. Energy harvesting offers a potential solution, but it is difficult to ensure sustainability. In this paper, we propose EH-CRAM, a centralised Kalman filter-based optimisation algorithm where the gateway is responsible for controlling End-Device configurations (i.e: data transmission rates, spreading factors and energy harvesting period) based upon incoming traffic and solar energy, thus balancing energy supply and demand. In addition, by using a time-synchronised cryptographic frequency hopping scheme, EH-CRAM also tackles the issues of energy efficiency and performance. Our evaluation shows that EH-CRAM significantly reduces contention, while maximising reliability and energy efficiency to support sustainable energy-harvesting for LoRa EndDevices (ED's). Absar-Ul-Haque Ahmar, Thien Duc Nguyen, Wouter Joosen, Danny Hughes 0001 |
WCNC | 2 |
| 2020 | CRAM: Robust Medium Access Control for LPWAN using Cryptographic Frequency HoppingabstractLow power wide area networks (LPWANs) are being applied in many Internet of Things applications around the globe. These technologies offer economic coverage of wide areas, while retaining low power operation. LoRaWAN is a key technology in this space, with a world-wide presence and millions of devices deployed in the field. Despite this early success, recent research has shown that LoRa performs poorly in dense deployments with a high degree of contention. Furthermore, LoRa is not robust against selective jamming attacks. In this paper, we propose CRAM: a cryptographic frequency hopping MAC protocol designed for the LoRa physical layer that reduces contention by fairly exploiting all available frequency space, while making it significantly more difficult to perform selective jamming. Our evaluation shows that CRAM significantly reduces contention, thereby dramatically increasing scalability and reliability in comparison to the standard LoRa protocol. Absar-Ul-Haque Ahmar, Emekcan Aras, Thien Duc Nguyen, Sam Michiels, Wouter Joosen, Danny Hughes 0001 |
DCOSS | 3 |
| 2020 | Mind the GAP: Security & Privacy Risks of Contact Tracing AppsabstractGoogle and Apple have jointly provided an API for exposure notification in order to implement decentralized contract tracing apps using Bluetooth Low Energy, the so-called “Google/Apple Proposal”, which we abbreviate by “GAP”. We demonstrate that in real-world scenarios the current GAP design is vulnerable to (i) profiling and possibly de-anonymizing infected persons, and (ii) relay-based wormhole attacks that basically can generate fake contacts with the potential of affecting the accuracy of an app-based contact tracing system. For both types of attack, we have built tools that can easily be used on mobile phones or Raspberry Pis (e.g., Bluetooth sniffers). The goal of our work is to perform a reality check towards possibly providing empirical real-world evidence for these two privacy and security risks. We hope that our findings provide valuable input for developing secure and privacy-preserving digital contact tracing systems. Lars Baumgärtner, Alexandra Dmitrienko, Bernd Freisleben, Alexander Gruler, Jonas Höchst, Joshua Kühlberg, Mira Mezini, Richard Mitev, Markus Miettinen, Anel Muhamedagic, Thien Duc Nguyen, Alvar Penning, Dermot Frederik Pustelnik, Filipp Roos, Ahmad-Reza Sadeghi, Michael Schwarz 0009, Christian Uhl |
TrustCom | 11 |
| 2019 | DÏoT: A Federated Self-learning Anomaly Detection System for IoTabstractIoT devices are increasingly deployed in daily life. Many of these devices are, however, vulnerable due to insecure design, implementation, and configuration. As a result, many networks already have vulnerable IoT devices that are easy to compromise. This has led to a new category of malware specifically targeting IoT devices. However, existing intrusion detection techniques are not effective in detecting compromised IoT devices given the massive scale of the problem in terms of the number of different types of devices and manufacturers involved. In this paper, we present DÏoT, an autonomous self-learning distributed system for detecting compromised IoT devices. DÏoT builds effectively on device-type-specific communication profiles without human intervention nor labeled data that are subsequently used to detect anomalous deviations in devices' communication behavior, potentially caused by malicious adversaries. DÏoT utilizes a federated learning approach for aggregating behavior profiles efficiently. To the best of our knowledge, it is the first system to employ a federated learning approach to anomaly-detection-based intrusion detection. Consequently, DÏoT can cope with emerging new and unknown attacks. We systematically and extensively evaluated more than 30 off-the-shelf IoT devices over a long term and show that DÏoT is highly effective (95.6% detection rate) and fast (257 ms) at detecting devices compromised by, for instance, the infamous Mirai malware. DÏoT reported no false alarms when evaluated in a real-world smart home deployment setting. Thien Duc Nguyen, Samuel Marchal, Markus Miettinen, Hossein Fereidooni, N. Asokan, Ahmad-Reza Sadeghi |
ICDCS | 1 |
| 2019 | DoubleEcho: Mitigating Context-Manipulation Attacks in Copresence VerificationabstractCopresence verification based on context can improve usability and strengthen security of many authentication and access control systems. By sensing and comparing their surroundings, two or more devices can tell whether they are copresent and use this information to make access control decisions. To the best of our knowledge, all context-based copresence verification mechanisms to date are susceptible to context-manipulation attacks. In such attacks, a distributed adversary replicates the same context at the (different) locations of the victim devices, and induces them to believe that they are copresent. In this paper we propose DoubleEcho, a context-based copresence verification technique that leverages acoustic Room Impulse Response (RIR) to mitigate context-manipulation attacks. In DoubleEcho, one device emits a wide-band audible chirp and all participating devices record reflections of the chirp from the surrounding environment. Since RIR is, by its very nature, dependent on the physical surroundings, it constitutes a unique location signature that is hard for an adversary to replicate. We evaluate DoubleEcho by collecting RIR data with various mobile devices and in a range of different locations. We show that DoubleEcho mitigates context-manipulation attacks whereas all other approaches to date are entirely vulnerable to such attacks. DoubleEcho detects copresence (or lack thereof) in roughly 2 seconds and works on commodity devices. Hien Thi Thu Truong, Juhani Toivonen, Thien Duc Nguyen, Claudio Soriente, Sasu Tarkoma, N. Asokan |
PerCom | 3 |
| 2019 | AuDI: Toward Autonomous IoT Device-Type Identification Using Periodic CommunicationabstractIoT devices are being widely deployed. But the huge variance among them in the level of security and requirements for network resources makes it unfeasible to manage IoT networks using a common generic policy. One solution to this challenge is to define policies for classes of devices based on device type. In this paper, we present AuDI, a system for quickly and effectively identifying the type of a device in an IoT network by analyzing their network communications. AuDI models the periodic communication traffic of IoT devices using an unsupervised learning method to perform identification. In contrast to prior work, AuDI operates autonomously after initial setup, learning, without human intervention nor labeled data, to identify previously unseen device types. AuDI can identify the type of a device in any mode of operation or stage of lifecycle of the device. Via systematic experiments using 33 off-the-shelf IoT devices, we show that AuDI is effective (98.2% accuracy). Samuel Marchal, Markus Miettinen, Thien Duc Nguyen, Ahmad-Reza Sadeghi, N. Asokan |
IEEE J. Sel. Areas Commun. | 3 |
| 2018 | Revisiting context-based authentication in IoTabstractThe emergence of IoT poses new challenges towards solutions for authenticating numerous very heterogeneous IoT devices to their respective trust domains. Using passwords or pre-defined keys have drawbacks that limit their use in IoT scenarios. Recent works propose to use contextual information about ambient physical properties of devices' surroundings as a shared secret to mutually authenticate devices that are co-located, e.g., the same room. In this paper, we analyze these context-based authentication solutions with regard to their security and requirements on context quality. We quantify their achievable security based on empirical real-world data from context measurements in typical IoT environments. Markus Miettinen, Thien Duc Nguyen, Ahmad-Reza Sadeghi, N. Asokan |
DAC | 2 |
| 2016 | POSTER: Friend or Foe? Context Authentication for Trust Domain Separation in IoT EnvironmentsabstractNo abstract available. Markus Miettinen, Jialin Huang, Thien Duc Nguyen, N. Asokan, Ahmad-Reza Sadeghi |
WISEC | 3 |
| 2015 | I Know Where You are: Proofs of Presence Resilient to Malicious ProversabstractIn the recent years, new services and businesses leveraging location-based services (LBS) are rapidly emerging. On the other hand this has raised the incentive of users to cheat about their locations to the service providers for personal benefits. Context-based proofs-of-presence (PoPs) have been proposed as a means to enable verification of users' location claims. However, as we show in this paper, they are vulnerable to context guessing attacks. To make PoPs resilient to malicious provers we propose two complementary approaches for making context-based PoPs: one approach focuses on surprisal filtering based on estimating the entropy of particular PoPs in order to detect context measurements vulnerable to such attacks. The other approach is based on utilizing longitudinal observations of ambient modalities like noise level and ambient luminosity. It is capable of extracting more entropy from the context to construct PoPs that are hard to guess by an attacker even in situations in which other context sensor modalities fail to provide reliable PoPs. Markus Miettinen, N. Asokan, Farinaz Koushanfar, Thien Duc Nguyen, Jon Rios, Ahmad-Reza Sadeghi, Majid Sobhani, Sudha Yellapantula |
AsiaCCS | 4 |
| 2014 | Context-Based Zero-Interaction Pairing and Key Evolution for Advanced Personal DevicesabstractSolutions for pairing devices without prior security associations typically require users to actively take part in the pairing process of the devices. Scenarios involving new types of devices like Internet-of-Things (IoT) appliances and wearable devices make it, however, desirable to be able to pair users' personal devices without user involvement. In this paper, we present a new approach for secure zero-interaction pairing suitable for IoT and wearable devices. Markus Miettinen, N. Asokan, Thien Duc Nguyen, Ahmad-Reza Sadeghi, Majid Sobhani |
CCS | 3 |