Safa Otoum

dblp:164/3650 · DBLP profile ↗
← Back
40ranked-venue papers
12as first author
31since 2021 · last 2026
0000-0002-0814-7328ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 32 · 10 first-author · 25 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Privacy-preserving federated feature selection with differential privacy
abstract
There is an urgent need to perform effective feature selection in distributed environments while preserving data privacy. In this paper, a new federated feature selection framework is developed to protect the privacy of input features held by multiple distributed clients, with applications in engineering systems where secure and efficient feature selection is critical in distributed environments. The proposed framework is based on federated learning and differential privacy techniques for distributed environments. The distributed clients send the noisy features’ values to the server preserving the privacy. The server then aggregates these noisy features’ values for further computations and feature selection. The performance of the proposed framework is evaluated against a centralized scenario where feature selection occurs centrally. Comparative analysis involves inputting the selected features into various machine learning models employing various evaluation metrics. The simulation results indicate comparable performance between the proposed federated approach and the centralized method. To further compare performance, a new method, ’Rank of Features’ is developed in this paper that evaluates similarity between features selected by the proposed framework and centralized method. The results of this analysis also demonstrate strong similarity between the two approaches. Further, privacy analyses are conducted in detail that include protection against reconstruction and membership inference attacks demonstrating robust preservation against data leakage and unauthorized inference of sensitive information.
Amir Anees, Ouns Bouachir, Safa Otoum
Eng. Appl. Artif. Intell.3
2025 FL-SATS: Federated Learning for Sybil Attack Detection in Transportation System
Muhammad Asad 0002, Safa Otoum
ICC2
2025 STO: A Dynamic AIoT-Based Approach for Energy-Efficient Urban Traffic Management
abstract
Urban congestion and environmental pollution are pressing issues in urban sustainability. This study introduces the Streamlined Traffic Optimizer (STO), an AIoT-based system designed to improve urban traffic flow and reduce energy consumption. The STO algorithm dynamically adapts traffic signals using real-time data from the Uber Movement dataset. Initial results from simulations show a significant reduction in average travel time from 35 minutes to 28 minutes and an increase in average speed from 30 km/h to 36 km/h. Additionally, congestion levels dropped from 40% to 25%, while fuel consumption decreased by 18%, from 10,000 liters to 8,200 liters. These improvements are accompanied by a reduction in CO2 emissions from 1,200 to 950 tons per year. The STO system offers a scalable and flexible solution for cities aiming to reduce their environmental impact while optimizing traffic efficiency.
Muhammad Asad 0002, Safa Otoum, Bassem Ouni
ICC2
2025 On the Security of Connected Vehicles: Intrusion Detection Using Federated Learning in the IoV
abstract
The expansion of Internet of Vehicles (IoV) technology brings significant cybersecurity and privacy concerns. This research study addresses cybersecurity challenges within the IoV and Intelligent Transportation System (ITS). It explores machine learning applications for detecting and preventing cyberattacks on the IoV network and autonomous vehicles, with the goal of developing and evaluating algorithms tailored to enhance IoV security, intrusion detection, and privacy. In this paper, we adopted a clustered machine learning model using Federated Learning and Convolutional Neural Networks (CNN) for IoV intrusion detection. Different scenarios involving centralized and decentralized clustering schemes are introduced. The proposed federated learning intrusion detection model has achieved a testing accuracy of 97.54 %, precision of 97.01 %, recall of 98.12 %, and an F1-score of 0.976.
Fadwa Darwaish, Safa Otoum, Hussein T. Mouftah
ICC2
2025 Zero-Trust Federated Learning via 6G URLLC for Vehicular Communications
Muhammad Asad 0002, Safa Otoum, Bassem Ouni
IEEE J. Sel. Areas Commun.2
2024 A Federated MRI and ML Approach for Precision Healthcare Detection
abstract
In the context of neurodegenerative illnesses, including Alzheimer's disease (neuroAD), this study employs simulated Federated Learning (FL) techniques to explore decentralized model training and the application of Machine Learning (ML) algorithms, specifically Random Forest and XGBoost, for neu-roAD detection. The research demonstrates promising results, with Random Forest achieving an average recall and accuracy of 94.19%, and XGBoost outperforming with an average recall and accuracy of 95.53% within a FL framework. These findings highlight the potential of ML in early AD diagnosis. Additionally, this study contributes to the broader field of research on the application of ML in healthcare and provides valuable insights into AD and the identification of other diseases. A limitation faced in this research is the use of a desktop computer with high capacity resources since laptop resources are not enough. The study utilizes a public dataset from Kaggle's “Best Alzheimer's MRI Dataset” to support its findings.
Noof Almarar, Safa Otoum
ICC2
2024 Clients Eligibility-Based Lightweight Protocol in Federated Learning: An IDS Use Case
abstract
Federated learning (FL) enables clients to train models locally, enhancing privacy by avoiding data centralization. Traditional FL assumes all clients have adequate resources, an often unrealistic expectation in heterogeneous networks with resource constraints like limited battery, memory, and bandwidth. These limitations can hinder performance, prolong convergence times, and lead to inaccurate models. To address these challenges, we introduce the Client Eligibility-based Lightweight Protocol (CELP), optimized for resource-constrained environments. CELP employs a sample-based pruning mechanism and a re-parameterized FedAvg algorithm, enhancing its management of resource variability. It also integrates an intrusion detection system to safeguard against malicious activities. Our results show that CELP significantly reduces communication overhead by up to 81.01% compared to FedAvg and up to 72.54% compared to FedProx and enhances system stability, achieving 93% accuracy on the MNIST dataset and 83% accuracy on CIFAR-10. These improvements demonstrate CELP’s ability to deliver robust performance and efficiency in diverse FL scenarios.
Muhammad Asad 0002, Safa Otoum, Saima Shaukat
IEEE Trans. Netw. Serv. Manag.2
2023 Modeling and Evaluation of the Internet of Things Communication Protocols in Security Constrained Systems
abstract
As the term implies, the main focus when designing security constrained systems is ensuring that the defined constraints are strictly adhered to. Developers of such systems must identify a balance between providing user and data security while also ensuring that the service's functionality is good. Extra security constraints can have a direct impact on other system aspects such as the communication between different devices especially in the emerging networking systems such as the Internet of Things and edge networking. In this work, we model and evaluate the main Internet of Things communication protocols including AMQP, CoAP, MQTT and XMPP in a security constrained system. We consider different evaluation metrics such the network utilization and success rate. Different protocols will react differently to the constrained security system but the increase in the communication latency is the common factor for all protocols.
Colton Helbig, Safa Otoum, Yaser Jararweh
CCNC2
2023 Overcoming Resource Bottlenecks in Vehicular Federated Learning: A Cluster-Based and QoS-Aware Approach
abstract
Federated learning (FL) is a promising approach for processing on-board data in vehicular networks due to its distributed nature and its ability to accurately and efficiently handle the large amount of sensed data. However, training and transmitting the model parameters during FL process can consume a significant amount of energy and time, which is not suitable for applications with strict real-time requirements. Moreover, the dynamicity of the vehicular network, as well as the varying capabilities of each vehicle, can impact the performance of the training process, bringing to the forefront the optimization of the participants selection and their resources. In this paper, we propose VOC-FL, a Vehicular-based Offloading and Clustering framework supported by FL. The proposed scheme bypasses communication bottlenecks by enabling groups of vehicles to train models simultaneously, with only the Cluster Head (CH) sending the aggregated results of each cluster to the roadside units for further processing. To form the clusters, we select a CH for each cluster based on multiple metrics, including stability, computational resources, bandwidth, and network topology. Moreover, the CH runs an offloading strategy that allows struggling nodes with limited computational resources to offload their tasks to other nodes with enough resources within the cluster, enabling efficient and effective use of resources.
Sawsan Abdul Rahman, Ouns Bouachir, Safa Otoum, Azzam Mourad
GLOBECOM3
2023 FLDetect: An API-Based Ransomware Detection Using Federated Learning
abstract
Ransomware, a malicious piece of software responsible for several high-profile attacks in recent years, poses a significant threat to organizations of all sizes. Such attacks can cause significant operational and financial harm, including system interruptions and compromises of system integrity. By developing the ability to detect and prevent ransomware attacks, we can contribute to the creation of a more secure and safe digital ecosystem. In this research, we propose FLDetect, a unique Federated Learning (FL)-based method for identifying ransomware on Windows machines. Windows machines, integral to Internet of Things (loT) networks, can act as brokers to other sensor nodes, rendering them susceptible to such attacks. Our approach utilizes distributed computing to train a Machine Learning (ML) model using data from various devices without relying on centralized data storage. The API-call-pattern-based detection method is the preferred approach for detecting ransomware in this paper. We made use of an open-source dataset, known as ransomwaredataset2016, for a comparable objective. The global model's accuracy was 93.1% after we trained it with twenty different devices. Our results demonstrate that our method is effective in identifying ransomware while maintaining the privacy and security of the training data by utilizing FL.
Tomas Petros, Henos Ghirmay, Safa Otoum, Reem Salem, Mérouane Debbah
GLOBECOM3
2023 Towards Boosting Federated Learning Convergence: A Computation Offloading & Clustering Approach
abstract
With an innovative door opened for a new era of Machine Learning, Federated Learning (FL) is now revolutionizing Artificial Intelligence. It exploits both decentralized data and decentralized computation to preserve user privacy. Albeit its popularity and being the most widely used framework nowadays, FL becomes a sub-optimal solution when the convergence of the global model occurs at a slow pace, which exacerbates the communication bottlenecks. To address this challenge, we propose in this paper CISCO-FL, a Clustered FL with Intelligent Selection and Computation Offloading. First, we partition the clients into different groups, where sub-aggregations of the clients models are performed at each cluster before the global aggregation. Second, we study the computing resources of the clients, and we embed in the proposed approach an intelligent offloading model, where the clients with high computational resources can assist and optimize the model of those struggling with limited resources. As such, both communication cost and computation resources are reduced and optimized. Finally, thorough experimental results are presented to support our findings and validate our model.
Sawsan Abdul Rahman, Ouns Bouachir, Safa Otoum, Azzam Mourad
ICC3
2023 On the privacy and security for e-health services in the metaverse: An overview
Mehdi Letafati, Safa Otoum
Ad Hoc Networks2
2023 On-Demand-FL: A Dynamic and Efficient Multicriteria Federated Learning Client Deployment Scheme
abstract
In this article, we increase the availability and integration of devices in the learning process to enhance the convergence of federated learning (FL) models. To address the issue of having all the data in one location, FL, which maintains the ability to learn over decentralized data sets, combines privacy and technology. Until the model converges, the server combines the updated weights obtained from each data set over a number of rounds. The majority of the literature suggested client selection techniques to accelerate convergence and boost accuracy. However, none of the existing proposals have focused on the flexibility to deploy and select clients as needed, wherever and whenever that may be. Due to the extremely dynamic surroundings, some devices are actually not available to serve as clients in FL, which affects the availability of data for learning and the applicability of the existing solution for client selection. In this article, we address the aforementioned limitations by introducing an On-Demand-FL, a client deployment approach for FL, offering more volume and heterogeneity of data in the learning process. We make use of the containerization technology, such as Docker, to build efficient environments using Internet of Things and mobile devices serving as volunteers. Furthermore, Kubernetes is used for orchestration. A multiobjective optimization problem representing the client and model deployment is solved using the genetic algorithm (GA) due to its evolutionary strategy. The performed experiments using the mobile data challenge (MDC) data set and the Localfed framework illustrate the relevance of the proposed approach and the efficiency of the on-the-fly deployment of clients whenever and wherever needed with less discarded rounds and more available data.
Mario Chahoud, Hani Sami, Azzam Mourad, Safa Otoum, Hadi Otrok, Jamal Bentahar, Mohsen Guizani
IEEE Internet Things J.4
2023 A Federated Learning and Blockchain-Enabled Sustainable Energy Trade at the Edge: A Framework for Industry 4.0
abstract
Through the digitization of essential functional processes, Industry 4.0 aims to build knowledgeable, networked, and stable value chains. Network trustworthiness is a critical component of network security that is built on positive interactions, guarantees, transparency, and accountability. Blockchain technology has drawn the attention of researchers in various fields of data science as a safe and low-cost platform to track a large number of eventual transactions. Such a technique is adaptable to the renewable energy-trade sector, which suffers from security and trustworthy issues. Having a decentralized energy infrastructure, that is supported by blockchain and artificial intelligence, enables smart and secure microgrid energy trading. The new age of industrial production will be highly versatile in terms of production volume and customization. As such a robust collaboration solution between consumers, businesses, and suppliers must be both secure and sustainable. In this article, we introduce a cooperative and distributed framework that relies on computing, communication, and intelligence capabilities of edge and end devices to enable secure energy trading, remote monitoring, and network trustworthiness. The blockchain and federated learning-enabled solution provide secure energy trading between different critical entities. Such a technique, coupled with 5G and beyond networks, would enable mass surveillance, monitoring, and analysis to occur at the edge. Performance evaluations are conducted to test the effectiveness of the proposed solution in terms of reliability and responsiveness in a vehicular network energy-trade scenario.
Safa Otoum, Ismaeel Al Ridhawi, Hussein T. Mouftah
IEEE Internet Things J.1
2023 FedMint: Intelligent Bilateral Client Selection in Federated Learning With Newcomer IoT Devices
abstract
Federated learning (FL) is a novel distributed privacy-preserving learning paradigm, which enables the collaboration among several participants (e.g., Internet of Things (IoT) devices) for the training of machine learning models. However, selecting the participants that would contribute to this collaborative training is highly challenging. Adopting a random selection strategy would entail substantial problems due to the heterogeneity in terms of data quality, and computational and communication resources across the participants. Although several approaches have been proposed in the literature to overcome the problem of random selection, most of these approaches follow a unilateral selection strategy. In fact, they base their selection strategy on only the federated server’s side, while overlooking the interests of the client devices in the process. To overcome this problem, we present in this articleFedMint, an intelligent client selection approach for FL on IoT devices using game theory and bootstrapping mechanism. Our solution involves the design of: 1) preference functions for the client IoT devices and federated servers to allow them to rank each other according to several factors, such as accuracy and price; 2) intelligent matching algorithms that take into account the preferences of both parties in their design; and 3) bootstrapping technique that capitalizes on the collaboration of multiple federated servers in order to assign initial accuracy value for the newly connected IoT devices. We compare our approach against theVanillaFLselection process as well as other state-of-the-art approach and showcase the superiority of our proposal.
Osama Wehbi, Sarhad Arisdakessian, Omar Abdel Wahab 0001, Hadi Otrok, Safa Otoum, Azzam Mourad, Mohsen Guizani
IEEE Internet Things J.5
2023 On the feasibility of Federated Learning towards on-demand client deployment at the edge
Mario Chahoud, Safa Otoum, Azzam Mourad
Inf. Process. Manag.2
2023 Management of Digital Twin-Driven IoT Using Federated Learning
abstract
Internet of Things (IoT), Digital Twin (DT), and Federated Learning (FL) are redefining the future vision of globalization. While IoT is about sensing data from physical devices, DTs reflect their digital representation and enable optimized decision-making by tightly integrating Artificial Intelligence (AI). Although swiftly growing, DTs are raising new challenges in privacy concerns, which are nowadays addressed by FL. However, the limited IoT resources, the communication overhead, and the lack of trust among clients are major obstacles that hinder the effectiveness of learning systems. In this paper, we design a new IoT-based architecture empowered by DT to improve the efficiencies of limited-resources devices. On top of this architecture, we leverage FL to construct the DT models. We further propose CISCO-FL, a Clustered FL with Intelligent Selection and Computation Offloading. Particularly, we study the computing resources of the clients and the quality of their models, and we embed in the proposed approach an intelligent offloading model, where the clients with high computational resources can assist and optimize the model of those struggling with limited resources. As such, both communication cost and computation resources are reduced and optimized. Finally, thorough experimental results are presented to support our findings and validate our model.
Sawsan Abdul Rahman, Safa Otoum, Ouns Bouachir, Azzam Mourad
IEEE J. Sel. Areas Commun.2
2023 On the Feasibility of Split Learning, Transfer Learning and Federated Learning for Preserving Security in ITS Systems
abstract
Due to the absence of distinct boundaries, wireless networks are vulnerable to a variety of intrusions. As the number of intruders has increased, the risks on critical infrastructures monitored by networked systems have also increased. Protecting shared information using effective and robust Intrusion Detection Systems (IDSs) remains a critical issue, especially with the growing implementation of vehicular networks. Building an IDS that detects threats efficiently with maximum accuracy and detection is a challenging undertaking. Machine Learning (ML) mechanisms have been successfully adopted in IDSs to detect a variety of network intruders. Split learning is considered one of the main developments in creating efficient ML approaches. In utilizing the Split Learning approach, an IDS is successful in performing at higher accuracy, and detection rate as well as a higher classification performance (Precision, Recall). In this work, a Split Learning-based IDS ($SplitLearn$) for Intelligent Transportation System (ITS) infrastructures has been proposed to address the potential security concerns. The proposed model has been evaluated and compared against other models (i.e., Federated Learning ($FedLearn$) and Transfer Learning ($TransLearn$)-based solutions). With the highest accuracy and detection rates, the proposed model ($SplitLearn$) outperforms$FedLearn$and$TransLearn$by 2 to 5 % respectively. We also see a decrease in power consumption when utilizing$SplitLearn$versus$FedLearn$.
Safa Otoum, Nadra Guizani, Hussein T. Mouftah
IEEE Trans. Intell. Transp. Syst.1
2022 Resource and Heterogeneity-aware Clients Eligibility Protocol in Federated Learning
abstract
Federated Learning (FL) is a new paradigm of Machine Learning (ML) that enables on-device computation via decentralized data training. However, traditional FL algorithms impose strict requirements on the clients' selection and its ratio. Moreover, the data training becomes inefficient when the client's computational resources are limited. Towards this goal, we aim to extend FL, a decentralized learning framework that efficiently works with heterogeneous clients in practical industrial scenarios. To this end, we propose a Clients' Eligibility Protocol (CEP), a resource-aware FL solution, for a heterogeneous environment. To this end, we use a Trusted Authority (TA) between the clients and the cloud server, which calculates the client's eligibility score based on local computing resources such as bandwidth, memory, and battery life and selects the most resourceful clients for training. If a client gives a slow response or infuses an incorrect model, the TA declares that the client is ineligible for future training. Besides, the proposed CEP leverages the asynchronous FL model, which avoids a long delay in a client's response. The empirical results proves that the proposed CEP gains the benefits of resource-aware clients selection and achieves 88 % and 93 % of accuracy on AlexNet and LeNet, respectively.
Muhammad Asad 0002, Safa Otoum, Saima Shaukat
GLOBECOM2
2022 On the Feasibility of Federated Learning for Neurodevelopmental Disorders: ASD Detection Use-Case
abstract
Autism Spectrum Disorder (ASD) is a neurodevelopmental syndrome resulting from alterations in the embryological brain pre-birth. This disorder distinguishes its patients by special socially restricted and repetitive behavior, in addition to specific behavioral traits, deteriorating their social behavior and interaction within their community. Moreover, medical research has proved that ASD affects the facial features of its patients, making the syndrome recognizable from distinctive signs within an individual's face. Given that as a motivation behind our work, we propose a novel privacy-preserving FL model, in order to predict ASD in a certain individual based on their behavioral traits or facial features, while respecting patient data privacy, as ASD data is medical and hence sensitive to leakage. After training behavioral and facial image data on Federated Machine Learning (FL) models, promising results are achieved, with 70% accuracy for prediction of ASD according to behavioral traits in a federated learning private environment, and a 62% accuracy is reached for prediction of ASD given an image of the patient's face.
Hala Shamseddine, Safa Otoum, Azzam Mourad
GLOBECOM2
2022 AI-Enabled Health 4.0: An IoT-Based COVID-19 Diagnosis Use-Case
abstract
The Internet of Things (IoT) has revamped service-oriented architectures by enabling edge-based devices to collect and share information that is vital for the service provisioning process. IoT devices have evolved from simple data acquirers and have become part of the service provisioning process. These devices are now able to sense, acquire, communicate, and process data in an intelligent manner. With the support of Artificial Intelligence (AI), IoT devices can now support users with minimal reliance on centralized entities, such as the Cloud. IoT devices are now able to share raw and processed information securely, without or with minimal reliance on centralized devices. This paper proposes a general framework for Health 4.0 to provide edge-based health services with the support of AI. IoT devices collect and share patient information in a secure manner to enable user-side disease diagnosis. The solution enables both federated and centralized learning to coexist under one framework. As a proof-of-concept, the solution considers a COVID-19 diagnosis use-case. A Machine Learning (ML) web-based user application is developed to analyze frontal chest X-ray (CXR) images and make predictions on whether patients' lungs are damaged. The solution provides an experimental study on mechanisms and approaches needed to increase learning accuracy with reduced dataset sizes and image quality through Federated Learning (FL).
Ismaeel Al Ridhawi, Safa Otoum
GLOBECOM5
2022 Towards Bilateral Client Selection in Federated Learning Using Matching Game Theory
abstract
Federated Learning (FL) is a novel distributed privacy-preserving learning paradigm, which enables the collaboration among several devices. However, selecting the participants that would contribute to this collaborative training is highly challenging. Adopting a random selection strategy would entail substantial problems due to the heterogeneity in terms of data quality and resources across the participants. To overcome this problem, we propose an intelligent client selection approach for federated learning on IoT devices using matching game theory. Our solution involves the design of: (1) preference functions for the client IoT devices and federated servers to allow them to rank each other according to several criteria such as accuracy and price, and (2) intelligent matching algorithms that take into account the preferences of both parties in their design. Based on our simulation findings, our strategy surpasses the VanillaFL selection approach in terms of maximizing both the revenues of the client devices and accuracy of the global federated learning model.
Osama Wehbi, Sarhad Arisdakessian, Omar Abdel Wahab 0001, Hadi Otrok, Safa Otoum, Azzam Mourad
GLOBECOM5
2022 A Hybrid Edge-assisted Machine Learning Approach for Detecting Heart Disease
abstract
Various resources are provided by cloud computing over the Internet, which enable plenty of applications to be employed to offer different services for industries. However, cloud computing due to the relying on a central server/datacenter has limitations such as high latency and response time, which are so crucial in real time applications like healthcare systems. To solve this, edge computing paradigm paves the way and provides pioneering solutions by moving the computational and storage resources closer to the end users. Edge computing by facilitating the real-time applications becomes more suitable for healthcare systems. This paper uses edge technology for detecting heart disease in patients utilizing a hybrid machine learning method. Although there exist some works in this area, there is still a need for improving the prediction accuracy. To this end, this paper proposes a meta-heuristic-based feature selection method using Black Widow Optimization (BWO) algorithm, and then, applies different classifiers on the selected features. The experimental results show that AdaBoost classifier along with BWO-based feature selection by 90.11 % accuracy outperforms other experimental methods, such as KNN, SVM, DT, and RF.
Vahideh Hayyolalam, Safa Otoum, Öznur Özkasap
ICC2
2022 Realizing Health 4.0 in Beyond 5G Networks
abstract
The advancements of Edge and Internet of Things (IoT) devices in terms of their processing, storage and communication capabilities, in addition to the advancements in wireless communication and networking technologies, have led to the rise in Intelligent Edge-enabled IoT architectures. Federated Learning (FL) is one example in which intelligence is adapted to the edge to offload some of the processing load from centralized entities and maintain secure localized model training. With Health 4.0, it is anticipated that distributed and edge-supported Artificial Intelligence (AI) will enable faster and more accurate early-stage disease discovery that relies significantly on intelligent remote and on-site IoT devices. Given that healthcare systems are highly scrutinized by both governments and patients to maintain high levels of data privacy and security, FL coupled with the support of blockchain will provide an optimal solution to reinforce today's healthcare frameworks. In this paper, we propose a FL-enabled framework for healthcare systems that is supported by edge-computing, blockchain and intelligent IoT devices. The solution considers a pneumonia detection use-case as a proof-of-concept and is applicable to an extended set of health-related use-cases. Different pre-trained models are compared against the proposed FL-supported model, namely, CNN, GG16, VGG19, InceptionV3, ResNet, DenseNet, and Xception. Results show high model accuracy attainment and significant improvements in terms of data privacy.
Safa Otoum, Ismaeel Al Ridhawi, Hussein T. Mouftah
ICC1
2022 Securing Critical IoT Infrastructures With Blockchain-Supported Federated Learning
abstract
Network trustworthiness is considered a very crucial element in network security and is developed through positive experiences, guarantees, clarity, and responsibility. Trustworthiness becomes even more compelling with the ever-expanding set of Internet of Things (IoT) smart city services and applications. Most of today’s network trustworthy solutions are considered inadequate, notably for critical applications where IoT devices may be exposed and easily compromised. In this article, we propose an adaptive framework that integrates both federated learning and blockchain to achieve both network trustworthiness and security. The solution is capable of dealing with individuals’ trust as a probability and estimates the end devices’ trust values belonging to different networks subject to achieving security criteria. We evaluate and verify the proposed model through simulation to showcase the effectiveness of the framework in terms of network lifetime, energy consumption, and trust using multiple factors. Results show that the proposed model maintains high accuracy and detection rates with values of$\approx 0.93$and$\approx 0.96$, respectively.
Safa Otoum, Ismaeel Al Ridhawi, Hussein T. Mouftah
IEEE Internet Things J.1
2022 VeNet: Hybrid Stacked Autoencoder Learning for Cooperative Edge Intelligence in IoV
abstract
Emerging applications of the Internet of Vehicles (IoV) require the wireless transmission of growing amounts of data, e.g., vehicle location and sensor data, over unreliable and increasingly congested wireless links between the mobile vehicles and the Road Side Units (RSUs); also, urban areas are becoming increasingly congested with vehicle road traffic. Road traffic management and data network traffic management to address these challenges require accurate representations of the road and network traffic, which are difficult due to the wide temporal and spatial correlations in the road and network traffic. We address this representation problem by designing, implementing, and evaluating the VeNet deep learning system to exploit the wirelessly transmitted data to predict future vehicle locations and network traffic. We develop the novel VeNet hybrid learning system that employs a stacked autoencoder (AE) consisting of a central AE and multiple local AEs that jointly feed into a Long-Short Term Memory (LSTM). We propose a new training algorithm for the hybrid VeNet learning system. The novel VeNet hybrid learning system conducts spatial learning that accounts for the spatial and temporal correlations in the dataset gathered from the mobile vehicles. Evaluations that involve measurements with custom-made Raspberry Pi vehicles indicate that the VeNet learning model significantly reduces the required signalling network traffic and prediction errors (down to approx. three quarters) compared to existing prediction models. At the same time, VeNet reduces the energy consumption on the vehicles as well as the learning delay.
Venkatraman Balasubramanian 0002, Safa Otoum, Martin Reisslein
IEEE Trans. Intell. Transp. Syst.2
2021 A Novel Deep Reinforcement Learning-based Approach for Task-offloading in Vehicular Networks
abstract
Next-generation vehicular networks will impose unprecedented computation demand due to the wide adoption of compute-intensive services with stringent latency requirements. Computational capacity of vehicular networks can be enhanced by integration of vehicular edge or fog computing; however, the growing popularity and massive adoption of novel services make edge resources insufficient. This challenge can be addressed by utilizing the onboard computation resources of neighboring vehicles that are not resource-constrained along with the edge computing resources. To fill the gaps, in this paper, we propose to solve the problem of task offloading by jointly considering the communication and computation resources in a mobile vehicular network. We formulate a non-linear problem to minimize the energy consumption subject to the network resources. Further-more, we consider a practical vehicular environment by taking into account the dynamics of mobile vehicular networks. The formulated problem is solved via a deep reinforcement learning (DRL) based approach. Finally, numerical evaluations are performed that demonstrates the effectiveness of our proposed scheme.
S. M. Ahsan Kazmi, Safa Otoum, Rasheed Hussain, Hussein T. Mouftah
GLOBECOM2
2021 Federated Reinforcement Learning-Supported IDS for IoT-steered Healthcare Systems
abstract
Wireless Networks lack clear boundaries which leads to security concerns and vulnerabilities to numerous kinds of intrusions. With the growth of cyber intruders, the risks on crucial applications monitored by networked systems have also grown. Effective and vigorous Intrusion Detection Systems (IDSs) for protecting shared information continues to be an essential task to keep private data safe especially in the healthcare sphere. Constructing an IDS that detects and returns information efficiently and with the highest accuracy is a challenging task. Machine Learning (ML) techniques have been effectively adopted in IDSs to detect network intruders. Reinforcement learning is considered as one of the main developments in ML. IDS mainly performs a higher accuracy rate, detection rate as well as a higher performance of a classification (ROC curve). According to these and to tackle the security issues, a Federated Reinforcement Learning-based Intrusion Detection System (FRL-IDS) in the Internet of Things (IoT) networks for healthcare infrastructures has been proposed. The proposed model has been evaluated and compared to a similar model (i.e. SVM system). The proposed model shows superiority over the SVM-steered IDS with accuracy and detection rates of ≈ 0.985 and ≈ 96.5%, respectively. This proposed infrastructure will not only aid in intrusion detection of large health care systems but also other wireless decentralized networks found across multiple real-world applications.
Safa Otoum, Nadra Guizani, Hussein T. Mouftah
ICC1
2021 A Survey on Blockchain for Information Systems Management and Security
David Berdik, Safa Otoum, Nikolas Schmidt, Dylan Porter, Yaser Jararweh
Inf. Process. Manag.2
2021 Intelligent Control and Security of Fog Resources in Healthcare Systems via a Cognitive Fog Model
abstract
There have been significant advances in the field of Internet of Things (IoT) recently, which have not always considered security or data security concerns: A high degree of security is required when considering the sharing of medical data over networks. In most IoT-based systems, especially those within smart-homes and smart-cities, there is a bridging point (fog computing) between a sensor network and the Internet which often just performs basic functions such as translating between the protocols used in the Internet and sensor networks, as well as small amounts of data processing. The fog nodes can have useful knowledge and potential for constructive security and control over both the sensor network and the data transmitted over the Internet. Smart healthcare services utilise such networks of IoT systems. It is therefore vital that medical data emanating from IoT systems is highly secure, to prevent fraudulent use, whilst maintaining quality of service providing assured, verified and complete data. In this article, we examine the development of a Cognitive Fog (CF) model, for secure, smart healthcare services, that is able to make decisions such as opting-in and opting-out from running processes and invoking new processes when required, and providing security for the operational processes within the fog system. Overall, the proposed ensemble security model performed better in terms of Accuracy Rate, Detection Rate, and a lower False Positive Rate (standard intrusion detection measurements) than three base classifiers (K-NN, DBSCAN, and DT) using a standard security dataset (NSL-KDD).
Mohammed Al-Khafajiy, Safa Otoum, Thar Baker, Muhammad Asim 0001, Zakaria Maamar, Moayad Aloqaily, Mark Taylor 0005, Martin Randles
ACM Trans. Internet Techn.2
2021 A Comparative Study of AI-Based Intrusion Detection Techniques in Critical Infrastructures
abstract
Volunteer computing uses Internet-connected devices (laptops, PCs, smart devices, etc.), in which their owners volunteer them as storage and computing power resources, has become an essential mechanism for resource management in numerous applications. The growth of the volume and variety of data traffic on the Internet leads to concerns on the robustness of cyberphysical systems especially for critical infrastructures. Therefore, the implementation of an efficient Intrusion Detection System for gathering such sensory data has gained vital importance. In this article, we present a comparative study of Artificial Intelligence (AI)-driven intrusion detection systems for wirelessly connected sensors that track crucial applications. Specifically, we present an in-depth analysis of the use of machine learning, deep learning and reinforcement learning solutions to recognise intrusive behavior in the collected traffic. We evaluate the proposed mechanisms by using KDD’99 as real attack dataset in our simulations. Results present the performance metrics for three different IDSs, namely the Adaptively Supervised and Clustered Hybrid IDS (ASCH-IDS), Restricted Boltzmann Machine-based Clustered IDS (RBC-IDS), and Q-learning based IDS (Q-IDS), to detect malicious behaviors. We also present the performance of different reinforcement learning techniques such as State-Action-Reward-State-Action Learning (SARSA) and the Temporal Difference learning (TD). Through simulations, we show that Q-IDS performs with detection rate while SARSA-IDS and TD-IDS perform at the order of .
Safa Otoum, Burak Kantarci, Hussein T. Mouftah
ACM Trans. Internet Techn.1
2020 Blockchain-Supported Federated Learning for Trustworthy Vehicular Networks
abstract
The advances in today's IoT devices and machine learning methods have given rise to the concept of Federated Learning. Through such a technique, a plethora of network devices collaboratively train and update a mutual machine learning model while protecting their individual data-sets. Federated learning proves its effectiveness in tackling communication efficiency and privacy-safeguarding issues. Moreover, blockchain was introduced to solve many network issues in regard to data privacy and network single point of failure. In this article, we introduce a solution that integrates both federated learning and blockchain to ensure both data privacy and network security. We present a framework to decentralize the mutual machine learning models on end-devices. A blockchain-based consensus solution as a second line of privacy is used to ensure trustworthy shared training on the fog. The proposed model enables on-end device machine learning without any centralized training of the data nor coordination by utilizing a consensus method in the blockchain. We evaluate and verify our proposed model through simulation to showcase the effectiveness of the adapted scheme in terms of accuracy, energy consumption, and lifetime rate, along with throughput and latency metrics. The proposed model performs with an accuracy rate of ≈ 0.97.
Safa Otoum, Ismaeel Al Ridhawi, Hussein T. Mouftah
GLOBECOM1
2020 A Novel Ensemble Method for Advanced Intrusion Detection in Wireless Sensor Networks
abstract
With the increase of cyber attack risks on critical infrastructures monitored by networked systems, robust Intrusion Detection Systems (IDSs) for protecting the information have become vital. Designing an IDS that performs with maximum accuracy with minimum false alarms is a challenging task. Ensemble method considered as one of the main developments in machine learning in the past decade, it finds an accurate classifier by combining many classifiers. In this paper, an ensemble classification procedure is proposed using Random Forest (RF), DensityBased Spatial Clustering of Applications with Noise (DBSCAN) and Restricted Boltzmann Machine (RBM) as base classifiers. RF, DBSCAN, and RBM techniques have been used for classification purposes. The ensemble model is introduced for achieving better results. Bayesian Combination Classification (BCC) has been adopted as a combination technique. Independent BCC (IBCC) and Dependent BCC (DBCC) have been tested for performance comparison. The model shows a promising result for all classes of attacks. DBCC performs over IBCC in terms of accuracy and detection rates. Through simulations under a wireless sensor network scenario, we have verified that DBCC-based IDS works with ≈ 100% detection and ≈ 1.0 accuracy rate in the existence of intrusive behavior in the tested Wireless Sensor Network (WSN).
Safa Otoum, Burak Kantarci, Hussein T. Mouftah
ICC1
2020 Blockchain Solution for IoT-based Critical Infrastructures: Byzantine Fault Tolerance
abstract
Providing an acceptable level of security for Internet of Things (IoT)-based critical infrastructures, such as the connected vehicles, considers as an open research issue. Nowadays, blockchain overcomes a wide range of network limitations. In the context of IoT and blockchain, Byzantine Fault Tolerance (BFT)-based consensus protocol, that elects a set of authenticated devices/nodes within the network, considers as a solution for achieving the desired energy efficiency over the other consensus protocols. In BFT, the elected devices are responsible for ensuring the data blocks’ integrity and preventing the concurrently appended blocks that might contain some malicious data. In this paper, we evaluate the fault-tolerance with different network settings, i.e., the number of connected vehicles. We verify and validate the proposed model with MATLAB/Simulink package simulations. The results show that our proposed hybrid scenario performed over the non-hybrid scenario taking throughput and latency in the consideration as the evaluated metrics.
Omar Alfandi, Safa Otoum, Yaser Jararweh
NOMS2
2020 Intelligent jamming-aware routing in multi-hop IoT-based opportunistic cognitive radio networks
Haythem Bany Salameh, Safa Otoum, Moayad Aloqaily, Rawan Derbas, Ismaeel Al Ridhawi, Yaser Jararweh
Ad Hoc Networks2
2019 Empowering Reinforcement Learning on Big Sensed Data for Intrusion Detection
abstract
Wireless sensor and actuator networks are widely adopted in various applications such as critical infrastructure monitoring where sensory data in big volumes and velocity are prone to security vulnerabilities for the network and the monitored infrastructure. Despite the vulnerabilities of the big data phenomenon, intelligent data analytics technique can enable the analysis of huge amount of data and identification of intrusive behavior in real time. The main performance targets for any Intrusion Detection System (IDS) involve accuracy, detection, precision, F1 score and Receiver Operating Characteristics. Pursuant to these, this paper proposes a big data-driven IDS approach in Wireless Sensor Networks by harnessing reinforcement learning techniques on a hybrid IDS framework. We study the performance of RL-IDS and compare it to the previously proposed Adaptive Machine Learning-based IDS (AML-IDS) namely the Adaptively Supervised and Clustered Hybrid IDS (ASCH-IDS). The experimental results show that RL-IDS can achieve ≈ 100% success in detection, accuracy and precisionrecall rates whereas its predecessor ASCH-IDS performs with an accuracy level that is slightly above 99%.
Safa Otoum, Burak Kantarci, Hussein T. Mouftah
ICC1
2019 An intrusion detection system for connected vehicles in smart cities
Moayad Aloqaily, Safa Otoum, Ismaeel Al Ridhawi, Yaser Jararweh
Ad Hoc Networks2
2018 Adaptively Supervised and Intrusion-Aware Data Aggregation for Wireless Sensor Clusters in Critical Infrastructures
abstract
Wireless sensor networks have become integral components of the monitoring systems for critical infrastructures such as the power grid or residential microgrids. Therefore, implementation of robust Intrusion Detection Systems (IDS) at the sensory data aggregation stage has become of paramount importance. Key performance targets for IDS in these environments involve accuracy, precision, and the receiver operating characteristics which is a function of the sensitivity and the ratio of false alarms. Furthermore, the interplay between machine learning and networked systems has led to promising opportunities, particularly for the system level security of wireless sensor networks. Pursuant to these, in this paper, we propose Adaptively Supervised and Clustered Hybrid IDS (ASCH-IDS) for wirelessly connected sensor clusters that monitor critical infrastructures. The proposed ASCH-IDS mechanism is built on a hybrid IDS framework, and transforms the previous work by continuously monitoring the behavior of the receiver operating characteristics, and adaptively directing the incoming packets at a sensor cluster towards either misuse detection or anomaly detection module. We evaluate the proposed mechanism by introducing real attack data sets into simulations, and show that our proposal performs at 98.9% detection rate and approximately 99.80% overall accuracy to detect known and unknown malicious behavior in the sensor network.
Safa Otoum, Burak Kantarci, Hussein T. Mouftah
ICC1
2017 Hierarchical trust-based black-hole detection in WSN-based smart grid monitoring
abstract
Wireless Sensor Networks (WSNs) have been widely adopted to monitor various ambient conditions including critical infrastructures. Since power grid is considered as a critical infrastructure, and the smart grid has appeared as a viable technology to introduce more reliability, efficiency, controllability, and safety to the traditional power grid, WSNs have been envisioned as potential tools to monitor the smart grid. The motivation behind smart grid monitoring is to improve its emergency preparedness and resilience. Despite their effectiveness in monitoring critical infrastructures, WSNs also introduce various security vulnerabilities due to their open nature and unreliable wireless links. In this paper, we focus on the, Black-Hole (B-H) attack. To cope with this, we propose a hierarchical trust-based WSN monitoring model for the smart grid equipment in order to detect the B-H attacks. Malicious nodes have been detected by testing the trade-off between trust and dropped packet ratios for each Cluster Head (CH). We select different thresholds for the Packets Dropped Ratio (PDR) in order to test the network behaviour with them. We set four different thresholds (20%, 30%, 40%, and 50%). Threshold of 50% has been shown to reach the system stability in early periods with the least number of re-clustering operations.
Safa Otoum, Burak Kantarci, Hussein T. Mouftah
ICC1
2017 Mitigating False Negative intruder decisions in WSN-based Smart Grid monitoring
abstract
Monitoring the Smart Grid (SG) is highly desired for critical applications such as power quality assessment and transformer monitoring. Due to their low-cost, flexibility and efficiency as well as their widely usage in several critical infrastructure monitoring applications, Wireless Sensor Networks (WSNs) are estimated to be extensively used in SG applications. WSNs-based SG networks are vulnerable to different types of attacks and intruders. In order to operate networks in secured environments, in this paper we analyze our Clustered Hierarchal Hybrid-Intrusion Detection System (CHH-IDS) that is responsible for various attacks injected by known and unknown intruders. As False Positives (FPs) and False Negatives (FNs) are the key performance parameters in IDS, we investigate mitigation of FNs through a two-tier intrusion detection approach, which deals with anomaly and signature detection in parallel. In the presence of such a hybrid mode, utilization proportion between the anomaly detection and signature detection models affect the FN performance. In these two subsystems, Random Forest method is used for signature detection over known attacks and E-DBSCAN (Enhanced Density-Based Spatial Clustering of Applications with Noise) method is used for anomaly detection over unknown attacks. Through simulations that run on real datasets, we validate that the higher the weight of anomaly detection subsystem (i.e. the lower the weight of the signature detection subsystem), the lower the FN rates experienced by the entire H-IDS system. More specifically, we show that FN rates can be significantly reduced by 20.4% when the weight on anomaly detection subsystem is increased from 60% to 70% while the accuracy is expected to be improved through signature detection subsystem by using the Random Forest which has higher detection rate than the E-DBSCAN method.
Safa Otoum, Burak Kantarci, Hussein T. Mouftah
IWCMC1