Abdullah Aydeger

dblp:158/1432 · DBLP profile ↗
← Back
20ranked-venue papers
13as first author
14since 2021 · last 2026
0000-0003-3333-1941ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 5 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2026 Edge-Local Verification for Post-Quantum Cryptographic Agility in Autonomous UAV Swarms
abstract
Autonomous UAV swarms must employ a diverse set of post-quantum cryptographic algorithms to adapt to evolving mission requirements, energy budgets, and computational limits. However, this cryptographic flexibility introduces a serious security risk: adversaries may exploit algorithm selection mechanisms to steer the system toward insecure or resource-draining configurations. In contrast to centrally supervised networks, autonomous UAVs cannot depend on human oversight to identify or correct malicious cryptographic transitions during flight. This paper introduces a lightweight, edge-local verification framework that enforces formal safety contracts before any cryptographic algorithm change is enacted. Designed to operate within tight real-time constraints, the framework ensures fail-closed decisions compatible with onboard control loops and scales efficiently with swarm size. Simulation results across six attack strategies confirm that this local verification approach significantly reduces successful attack rates across multiple threat vectors, blocks quantum downgrade attempts, and maintains negligible resource overhead. The analysis also highlights timing-based manipulation as the most persistent residual threat, underscoring the need for continued research in adaptive security defenses for autonomous edge systems.
Abdullah Aydeger
CCNC1
2026 Real-Time Cryptographic Agility for Autonomous UAV Swarms: A Performance-Driven Approach to Post-Quantum Migration
abstract
Autonomous UAV swarms are increasingly deployed for time-sensitive missions where secure communication and strict real-time control must coexist. The transition to post-quantum cryptography (PQC) introduces substantial computational overhead that can push cryptographic operations beyond coordination deadlines if algorithms are fixed a priori. This challenge is compounded by dynamic operational requirements: reconnaissance missions prioritize efficiency while tactical operations demand higher security, which static cryptographic configurations cannot accommodate. We evaluate cryptographic agility, defined as adapting algorithms to operational context, using a simulator grounded in empirical cycle counts for ARM Cortex-M4 processors. Through extensive simulation, agile configurations maintain high deadline compliance rates while static policies experience significant degradation under operational stress. Because no single NIST-approved PQC scheme jointly optimizes security, latency, and energy across varying mission requirements, these results provide evidence that adaptive selection is necessary to address performance bottlenecks in post-quantum UAV swarms. We also discuss design implications and outline how agility can be integrated with real-time coordination and provisioning workflows.
Abdullah Aydeger
CCNC1
2026 Post-Quantum Public Key Infrastructures: Hybrid Certificates, Cryptographic Combiners, and Migration Strategies
abstract
The impending threat posed by quantum-capable adversaries necessitates a secure and practical transition of Public Key Infrastructures (PKIs) to support post-quantum cryptography (PQC). This paper addresses the multifaceted challenges of integrating PQC into existing PKI ecosystems by examining novel cryptographic combiners and hybrid certificate designs that can provide quantum-resistant security. We assess the performance, compatibility, and security of these hybrid certificates across standard communication protocols such as TLS, considering variations in root and intermediate certification paths. In addition, we introduce key management procedures that cover signature generation, validation, and lifecycle considerations under both software and hardware constraints. Beyond X.509, alternative trust models and certificate mechanisms are also analyzed for specialized domains, including IoT, firmware signing, and smart cards.
Abdullah Aydeger, Engin Zeydan, Awaneesh Kumar Yadav, Madhusanka Liyanage
CCNC1
2026 Bias-Free and Auto-Evolving Generative AI: Design Principles, Architectures, and Reinforcement Integration
abstract
The increasing deployment of generative Artificial Intelligence (AI) systems, particularly large language and multimodal foundation models, presents unprecedented challenges in software engineering. Current development pipelines face issues such as bias propagation, evolving model integration, security vulnerabilities, and lack of explainability, especially in compliance with AI regulations. This paper presents a comprehensive framework for engineering bias-free and auto-evolving generative AI systems, addressing key technical and regulatory challenges through modular software design, hardware-aware optimisation, and human-in-the-loop reinforcement learning. We propose a reference architecture that integrates fairness-aware orchestration, explainability mechanisms, and resilience against prompt and dataset poisoning.
Engin Zeydan, Abdullah Aydeger
CCNC2
2026 Security Evaluations of Post-Quantum Cryptographic Primitives Against Quantum and AI-Based Attacks
Engin Zeydan, Abdullah Aydeger, Awaneesh Kumar Yadav, Madhusanka Liyanage
ICC2
2025 MTDNS: Moving Target Defense for Resilient DNS Infrastructure
abstract
One of the most critical components of the Internet that an attacker could exploit is the DNS (Domain Name System) protocol and infrastructure. Researchers have been constantly developing methods to detect and defend against the attacks against DNS, specifically DNS flooding attacks. However, most solutions discard packets for defensive approaches, which can cause legitimate packets to be dropped, making them highly dependable on detection strategies. In this paper, we propose MTDNS, a resilient MTD-based approach that employs Moving Target Defense techniques through Software Defined Networking (SDN) switches to redirect traffic to alternate DNS servers that are dynamically created and run under the Network Function Virtualization (NFV) framework. The proposed approach is implemented in a testbed environment by running our DNS servers as separate Virtual Network Functions, NFV Manager, SDN switches, and an SDN Controller. The experimental result shows that the MTDNS approach achieves a much higher success rate in resolving DNS queries and significantly reduces average latency even if there is a DNS flooding attack.
Abdullah Aydeger, Sanzida Hoque, Engin Zeydan
CCNC1
2025 Post-Quantum Cryptography Integration to O-RAN
abstract
With its disaggregated and open interfaces, the Open Radio Access Network (O-RAN) architecture promises flexibility, innovation, and cost-effectiveness for future wireless networks. However, the increased reliance on software and open interfaces also introduces new security challenges. As the threat of quantum computing looms, the traditional cryptographic algorithms used in O-RAN will become vulnerable to potential attacks. This paper proposes the integration of Post-Quantum Cryptography (PQC) into O-RAN to enhance its security against post-quantum adversaries. We discuss the specific vulnerabilities of current O-RAN security mechanisms to quantum attacks and identify key areas where PQC can be applied, such as key exchange, authentication, and data protection. We present a framework for evaluating the suitability of different PQC algorithms for O-RAN and outline potential challenges and implementation considerations. By proactively integrating PQC into O-RAN, we aim to ensure the long-term security and resilience of this emerging network architecture in the era of quantum computing.
Abdullah Aydeger, Engin Zeydan, Josep Mangues-Bafalluy
CCNC1
2025 F-KANs: Federated Kolmogorov-Arnold Networks
abstract
In this paper, we present an innovative federated learning (FL) approach that utilizes Kolmogorov-Arnold Networks (KANs) for classification tasks. By utilizing the adaptive activation capabilities of KANs in a federated framework, we aim to improve classification capabilities while preserving privacy. The study evaluates the performance of federated KANs (F-KANs) compared to traditional federated Multi-Layer Perceptrons (F-MLPs) on classification task. The results show that the F-KANs model significantly outperforms the F-MLP model in terms of accuracy, precision, recall, F1 score and stability, and achieves better performance, paving the way for more efficient and privacy-preserving predictive analytics.
Engin Zeydan, Cristian J. Vaca-Rubio, Luis Blanco 0001, Roberto M. Pinheiro Pereira, Màrius Caus, Abdullah Aydeger
CCNC6
2025 Towards a Converged Telco Edge Cloud: Architecting the 3C Network for Sustainable Digital Infrastructure
abstract
The convergence of connectivity, cloud and compute, the so-called “3 C network”, is a turning point that can promote industrial innovation, digital sovereignty and sustainability. In this paper, we present a comprehensive framework for implementing large-scale telco-edge cloud use cases that can integrate heterogeneous computing and communication resources across device, edge and cloud layers. We explore an architecture that incorporates AI-driven orchestration, lightweight virtualisation and privacy protection, tailored to meet stringent latency, energy and mobility requirements. The proposed approach supports open, multi-supplier and interoperable implementations. By considering governance models, security by design and industrial use cases, this paper provides a foundational blueprint for the transition to a federated, scalable digital infrastructure that can support next-generation applications in key vertical sectors.
Engin Zeydan, Abdullah Aydeger
CNSM2
2025 Analysis of Robust and Secure DNS Protocols for IoT Devices
abstract
The DNS (Domain Name System) protocol has been in use since the early days of the Internet. Although DNS as a de facto networking protocol had no security considerations in its early years, there have been many security enhancements, such as DNSSec (Domain Name System Security Extensions), DoT (DNS over Transport Layer Security), DoH (DNS over HTTPS) and DoQ (DNS over QUIC). With all these security improvements, it is not yet clear what resource-constrained Internet-of-Things (IoT) devices should be used for robustness. In this paper, we investigate different DNS security approaches using an edge DNS resolver implemented as a Virtual Network Function (VNF) to replicate the impact of the protocol from an IoT perspective and compare their performances under different conditions. We present our results for cache-based and non-cached responses and evaluate the corresponding security benefits. Our results and framework can greatly help consumers, manufacturers, and the research community decide and implement their DNS protocols depending on the given dynamic network conditions and enable robust Internet access via DNS for different devices.
Abdullah Aydeger, Sanzida Hoque, Engin Zeydan, Kapal Dev
ICC1
2025 Analysis of Post-Quantum Cryptography in User Equipment in 5G and Beyond
abstract
The advent of quantum computing threatens the security of classical public-key cryptographic systems, prompting the transition to post-quantum cryptography (PQC). While PQC has been analyzed in theory, its performance in practical wireless communication environments remains underexplored. This paper presents a detailed implementation and performance evaluation of NIST-selected PQC algorithms in user equipment (UE) to UE communications over 5G networks. Using a full 5G emulation stack (Open5GS and UERANSIM) and PQC-enabled TLS 1.3 via BoringSSL and liboqs, we examine key encapsulation mechanisms and digital signature schemes across realistic network conditions. We evaluate performance based on handshake latency, CPU and memory usage, bandwidth, and retransmission rates, under varying cryptographic configurations and client loads. Our findings show that ML-KEM with ML-DSA offers the best efficiency for latency-sensitive applications, while SPHINCS+ and HQC combinations incur higher computational and transmission overheads, making them unsuitable for security-critical but time-sensitive 5G scenarios.
Sanzida Hoque, Abdullah Aydeger, Engin Zeydan, Madhusanka Liyanage
LCN2
2024 Blockchain-Based Self-Sovereign Identity in 6G Non-Public Networks: Enhanced Security in Industrial Cyber-Physical Systems
abstract
The industrial sector’s digital transformation under Industry 4.0 necessitates robust, scalable, and secure communication frameworks. 6G technology, particularly its nonpublic network (NPN) configurations, offers promising solutions for industrial cyber-physical systems (ICPS). However, security and privacy remain significant challenges, especially concerning identity management in these networks. This paper proposes the integration of blockchain-based Self-Sovereign Identity (SSI) within 6G NPNs as a novel approach to enhance security and data privacy. We explore how this combination can provide decentralized identity management, reduce reliance on centralized authorities, and increase trustworthiness within industrial networks. The paper also examines real-world scenarios and provides a detailed analysis of deployment models, highlighting the potential benefits and challenges of integrating blockchain-based SSI into 6G networks.
Abdullah Aydeger, Engin Zeydan
CNSM1
2024 Integrating Quantum-Secured Blockchain Identity Management in Open RAN for 6G Networks
abstract
In this paper, we propose an innovative integration of Quantum Key Distribution (QKD) and Blockchain-based Self-Sovereign Identity (SSI) within the Open RAN (O-RAN) framework for 6G networks to address the critical need for enhanced security and robust identity management. We first present a general architecture that takes a multi-layered approach and is carefully designed to leverage the different capabilities of quantum security and blockchain technology. The architecture ensures seamless and secure operation across different layers of the O-RAN, focusing on the Distributed Identity Management (DIM) and Management & Orchestration layers, and explains the interactions between these layers to improve the security and operational efficiency of the network. We also investigate detailed case studies and applications that demonstrate the practicality and transformative potential of integrating QKD-secured blockchain identity management systems in real-world 6G scenarios. We also address the inherent challenges and limitations of such integration and propose viable solutions to overcome them. Finally, we provide insights into future research and implementation directions and highlight the critical role of quantum-secured blockchain systems in the evolution of telecommunication networks toward a more secure, decentralized, and user-centric paradigm.
Engin Zeydan, Luis Blanco 0001, Josep Mangues-Bafalluy, Abdullah Aydeger, Suayb S. Arslan, Yekta Turk
LCN4
2021 A General and Practical Framework for Realization of SDN-based Vehicular Networks
abstract
With the recent developments of communication technologies surrounding vehicles, we will be witnessing the simultaneous availability of multiple on-board communication interfaces on vehicles. While most of the current interfaces already include Bluetooth, WiFi, and LTE, they will be augmented further by IEEE 802.11p and the 5G interfaces, which will serve for safety, maintenance, and infotainment applications. However, dynamic management of interfaces depending on application needs will become a significant issue that can be best addressed by Software Defined Networking (SDN) technology. While SDN-based vehicular networks have been promoted previously, none of these works dealt with their practical challenges. In this paper, we propose and develop a practical framework that will realize SDN-based vehicular networks for a wide range of applications. Through this framework, we demonstrate a platoon example which demonstrates the use of SDN for quick and efficient multi-hop messaging. The route from source vehicle to destination is computed with the help of the SDN Controller to transmit the Beacon Safety Messages through Road Side Units (RSUs) at the MAC layer without relying on IP for proper platooning operations. The results show the efficiency of the SDN-based approach compared to the traditional routing approaches.
Juan V. Leon, Oscar G. Bautista, Abdullah Aydeger, Suat Mercan, Kemal Akkaya
IPCCC3
2020 Cloud-based Deception against Network Reconnaissance Attacks using SDN and NFV
abstract
An attacker's success crucially depends on the reconnaissance phase of Distributed Denial of Service (DDoS) attacks, which is the first step to gather intelligence. Although several solutions have been proposed against network reconnaissance attacks, they fail to address the needs of legitimate users' requests. Thus, we propose a cloud-based deception framework which aims to confuse the attacker with reconnaissance replies while allowing legitimate uses. The deception is based on for-warding the reconnaissance packets to a cloud infrastructure through tunneling and SDN so that the returned IP addresses to the attacker will not be genuine. For handling legitimate requests, we create a reflected virtual topology in the cloud to match any changes in the original physical network to the cloud topology using SDN. Through experimentations on GENI platform, we show that our framework can provide reconnaissance responses with negligible delays to the network clients while also reducing the management costs significantly.
Abdullah Aydeger, Nico Saputro, Kemal Akkaya
LCN1
2019 A moving target defense and network forensics framework for ISP networks using SDN and NFV
Abdullah Aydeger, Nico Saputro, Kemal Akkaya
Future Gener. Comput. Syst.1
2019 SDN-enabled recovery for Smart Grid teleprotection applications in post-disaster scenarios
Abdullah Aydeger, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac
J. Netw. Comput. Appl.1
2018 Assessing the overhead of authentication during SDN-enabled restoration of smart grid inter-substation communications
abstract
Since real-time and resilient recovery of link failures is crucial for power grid infrastructure to continue its services, emerging technologies such as Software Defined Networking (SDN) has started to be employed for such purposes. SDN switches can be remotely controlled to change their configurations by exploiting the wireless communication options. However, when wireless is to be used in Smart Grid communications, security and reliability become important issues due to the specific characteristics of wireless communications. This paper investigates the overhead of providing such services on wireless links when SDN is utilized. Specifically, we consider the establishment of authentication services when wireless back-up links (i.e., WiFi or LTE) are employed as a result of a reactive link failure detection mechanism. To the best of our knowledge, this work is the first to consider authentication of such an SDN-enabled Smart Grid inter-substation communication with WiFi and LTE. To be able to effectively evaluate the performance of this proposed SDN-enabled framework, we developed it in Mininet emulator. Since Mininet does not support the authentication services for WiFi or LTE, we proposed several novel extensions to Mininet by integrating it with ns-3 simulator that supports the LTE/WiFi protocol stacks. We conducted extensive experiments by considering a general application using Smart Grid Manufacturing Message Specification (MMS) standard to assess the recovery performance of the proposed secure SDN-enabled recovery system. The results show that when authentication and reliable protocols such as TCP are to be employed, the proposed framework can still meet the deadlines of 100 ms with WiFi while LTE misses only a few packets.
Abdullah Aydeger, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac
CCNC1
2016 Software defined networking for resilient communications in Smart Grid active distribution networks
abstract
Emerging Software Defined Networking (SDN) technology provides excellent flexibility to large-scale networks in terms of control, management, security, and maintenance. In this paper, we propose an SDN-based communication infrastructure for Smart Grid distribution networks among substations. A Smart Grid communication infrastructure consists of a large number of heterogenous devices that exchange real-time information for monitoring the status of the grid. We then investigate how SDN-enabled Smart Grid infrastructure can provide resilience to active distribution substations with self-recovery. Specifically, by introducing redundant and wireless communication links that can be used during the emergencies, we show that SDN controllers can be effective for restoring the communication while providing a lot of flexibility. Furthermore, to be able to effectively evaluate the performance of the proposed work in terms of various fine-grained network metrics, we developed a Mininet-based testing framework and integrated it with ns-3 network simulator. Finally, we conducted experiments by using actual Smart Grid communication data to assess the recovery performance of the proposed SDN-based system. The results show that SDN is a viable technology for the Smart Grid communications with almost negligible delays in switching to backup wireless links during the times of link failures in reliable fashion.
Abdullah Aydeger, Kemal Akkaya, Mehmet Hazar Cintuglu, A. Selcuk Uluagac, Osama Mohammed 0001
ICC1
2016 Mitigating Crossfire Attacks Using SDN-Based Moving Target Defense
abstract
Recent research demonstrated that software defined networking (SDN) can be leveraged to enable moving target defense (MTD) to mitigate distributed denial of service (DDoS) attacks. The network states are continuously changed in MTD by effectively collecting information from the network and enforcing certain security measures on the fly in order to deceive the attackers. Being motivated from the success of SDN-based maneuvering, this work targets an emerging type of DDoS attacks, called Crossfire, and proposes an SDN-based MTD mechanism to defend against such attacks. We analyze Crossfire attack planning and utilize the analyzed results to develop the defense mechanism which in turn reorganize the routes in such a way that the congested links are avoided during packet forwarding. The detection and mitigation techniques are implemented using Mininet emulator and Floodlight SDN controller. The evaluation results show that the route mutation can effectively reduce the congestion in the targeted links without making any major disruption on network services.
Abdullah Aydeger, Nico Saputro, Kemal Akkaya, Mohammad Ashiqur Rahman
LCN1