VLDB 2026 Research / reviewers in the wild / expert
Marwa Elsayed
dblp:165/9480 · also Marwa A. Elsayed
· DBLP profile ↗
12ranked-venue papers
4as first author
9since 2021 · last 2025
0000-0001-9906-5020ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 1 since 2021Security and privacy · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SQL-GENIE: SQL Protection using GENerative Modeling for Anomaly Detection against Injection and Evolved Adversarial AttacksabstractIn an age where data drives innovation and online interactions are integral to daily life, ensuring the security of web applications and databases has never been more critical. The growing surge and sophistication of large-scale SQL injection (SQLi) attacks highlight the urgent need for advanced detection mechanisms to protect sensitive information, especially in cloud-based environments. This paper presents SQL-GENIE, a novel approach that leverages generative modeling to strengthen modern application security, improve anomaly detection, and address emerging challenges in data protection. SQL-GENIE leverages two feature embedding techniques across two different datasets and contrasts their performance against Generative Adversarial Networks (GAN)— under various contamination rates to analyze and detect SQLi attacks, including typical and sophisticated adversarial forms. Our proposed GAN model performs the best with FastText when applied to our benchmark dataset of typical SQLI, achieving F1-score of 92.7% on attack data with a 10% contamination rate. Additionally, it demonstrates an F1-score of 98.6% on the adversarial dataset, highlighting its robustness against evolved SQLi threats. Marwa Elsayed, Nur Zincir-Heywood |
COMPSAC | 2 |
| 2025 | Empirical Insights into Microservice Language Heterogeneity in PracticeabstractBackground: Microservice architecture has become a mainstream approach for cloud-native systems, transforming industries across diverse business domains over the past decade. While scalability has driven much of its adoption, system heterogeneity is frequently highlighted as a critical advantage. The research community frequently underscores heterogeneity as a priority in proposed solutions and innovations. Aims: This study investigates the real-world significance of heterogeneity in industrial microservice-based systems, seeking to answer: How prevalent is heterogeneity in practice? Are there governance practices to manage it? Is heterogeneity truly the main enabler for independent team operations? Method: We combined industrial expertise with a controlled experiment, incorporating insights directly from practitioners to assess the role and prevalence of heterogeneity in microservice-based systems. Results: Our findings reveal common themes and influential factors guiding heterogeneity-related decisions. We also identify varying governance approaches and highlight where industry practices align-or diverge-from common academic assumptions. Conclusions: This work bridges the gap between academic research and industry realities, providing a grounded understanding of heterogeneity in microservice systems. The results offer a foundation for future research to better address the practical needs of the microservice industry. Amr S. Abdelfattah, Tomás Cerný, Marwa Elsayed |
ESEM | 3 |
| 2023 | Depicting Instant Messaging Encrypted Traffic Characteristics through an Empirical StudyabstractInstant Messaging Applications (IMAs), such as Discord and WhatsApp, have become one of the main communication tools for mobile device users. Network traffic analysis is a method of monitoring network activity to identify operational and security issues. There is limited research on network traffic analysis of IMAs on mobile devices due to the challenges of end-to-end encryption, user privacy, and dynamic port usage. In this paper, we design, develop and evaluate a framework to generate end-to-end IMA traffic on mobile devices, employ feature selection and conduct traffic analysis that can cope with encrypted traffic while identifying different IMAs. Results show a performance evaluation workbench as well as highlight the key characterictis of six popular IMAs. Zolboo Erdenebaatar, Riyad Alshammari, Biswajit Nandy, Nabil Seddigh, Marwa Elsayed, Nur Zincir-Heywood |
ICCCN | 5 |
| 2023 | Analyzing Traffic Characteristics of Instant Messaging Applications on Android SmartphonesabstractInstant Messaging Applications (IMAs), such as WhatsApp and Messenger, have become one of the main communication tools for smartphone users. However, there is limited research analyzing the nature of encrypted network traffic produced by IMAs. In this paper, we employ a data driven approach using machine learning classification models to analyze and identify encrypted traffic from six different IMAs. Our results show that it is possible to distinguish the behaviour of different IMAs with high F1 scores. Zolboo Erdenebaatar, Riyad Alshammari, Nur Zincir-Heywood, Marwa Elsayed, Biswajit Nandy, Nabil Seddigh |
NOMS | 4 |
| 2023 | Instant Messaging Application Encrypted Traffic Generation SystemabstractInstant Messaging Applications (IMAs) have become the leading communication tool for smartphone users. While it is insightful for network operators and security researchers to monitor and analyze the network traffic of their organization, there is a lack of research on IMA encrypted traffic analysis. In a companion work [1], we introduced a flow-based encrypted IMA traffic analysis using a data driven approach. Given the lack of publicly available data in this area, a new encrypted IMA traffic generation system is designed and implemented to automatically generate and label encrypted IMA traffic including Discord, Facebook Messenger, Signal, Microsoft Teams, Telegram, and WhatsApp. The new system utilizes a combination of open-source tools to emulate user behavior, to capture, filter and label the resulting traffic directly on an Android device. This demonstration shows the functionality of the proposed system via data generation, capture, and analysis of the six IMAs. Zolboo Erdenebaatar, Biswajit Nandy, Nabil Seddigh, Riyad Alshammari, Marwa Elsayed, Nur Zincir-Heywood |
NOMS | 5 |
| 2023 | On the Fence: Anomaly Detection in IoT NetworksabstractThe Internet of Things (IoT) is increasingly impacting every aspect of life, with deployment in various societal applications. This paper explores anomaly detection via novelty and outlier detection approaches for IoT networks. To this end, three unsupervised learning algorithms, namely Isolation Forest (IF), Local Outlier Factor (LOF), and One-Class Support Vector Machine (OSVM), are evaluated on three publicly available IoT datasets. The results demonstrate that when the proposed solution leverages LOF to embrace the novelty approach by considering only pure benign data for training, it achieves high performance with Fl-scores within the range of 84% to 94%. Patrick Russell, Marwa Elsayed, Biswajit Nandy, Nabil Seddigh, Nur Zincir-Heywood |
NOMS | 2 |
| 2022 | BoostGuard: Interpretable Misbehavior Detection in Vehicular Communication NetworksabstractWireless Communication and Artificial Intelligence are at the heart of driving the evolution in the transportation industry. Cooperative Intelligent Transportation Systems adopt vehicle-to-vehicle (V2V) technology to allow vehicles to exchange real-time information about speed, heading, and location wirelessly with their surrounding vehicles. Such technology has remarkable benefits for improving vehicles’ safety and awareness, albeit imposing many security risks. Despite the evolving efforts to employ authentication mechanisms, there is no guarantee that the exchanged data is trustworthy. Security breaches causing falsified data can aggressively lead to severe safety damages within vehicular networks. This paper proposes, BoostGuard, a novel interpretable framework for detecting falsified data exchanged as part of five different types of position forging attacks against vehicular networks. BoostGuard mainly adopts data science principles and leverages advanced machine learning techniques (i.e., boosting decision tree ensemble) to boost its generalization capabilities for precisely detecting and classifying attack types. Extensive experiments are conducted over an open-source dataset, reflecting dynamic real-world vehicular environments. The evaluation results demonstrate that our solution outperforms existing solutions with high detection effectiveness and computational time efficiency. Marwa Elsayed, Nur Zincir-Heywood |
NOMS | 1 |
| 2022 | OD1NF1ST: True Skip Intrusion Detection and Avionics Network Cyber-attack SimulationabstractMIL-STD-1553 is a communication bus that has been used by many military avionics platforms, such as the F-15 and F-35 fighter jets, for almost 50 years. Recently, it has become clear that the lack of security on MIL-STD-1553 and the requirement for internet communication between planes has revealed numerous potential attack vectors for malicious parties. Prevention of these attacks by modernizing the MIL-STD-1553 is not practical due to the military applications and existing far-reaching installations of the bus. We present a software system that can simulate bus transmissions to create easy, replicable, and large datasets of MIL-STD-1553 communications. We also propose an intrusion detection system (IDS) that can identify anomalies and the precise type of attack using recurrent neural networks with a reinforcement learning true-skip data selection algorithm. Our IDS outperforms existing algorithms designed for MIL-STD-1553 in binary anomaly detection tasks while also performing attack classification and minimizing computational resource cost. Our simulator can generate more data with higher fidelity than existing methods and integrate attack scenarios with greater detail. Furthermore, the simulator and IDS can be combined to form a web-based attack-defense game. Michael Wrana, Marwa Elsayed, Karim Lounis, Ziad Mansour, Steven H. H. Ding, Mohammad Zulkernine |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2022 | AdaptIDS: Adaptive Intrusion Detection for Mission-Critical Aerospace VehiclesabstractAerospace and defense industries are particularly vulnerable to cyber threats given their sensitive nature, significantly extending the consequences of security breaches to the national level. Aerospace vehicles are augmented by cooperative control, intelligent, connected, and autonomous systems. The risk against such systems is further amplified due to commonly relying on the MIL-STD-1553 communication bus developed with a high focus on reliability and fault tolerance, albeit with security as a second priority. MIL-STD-1553 (a.k.a., STANAG 3838 by NATO) is a standard that describes a serial data communication bus primarily used in aerospace vehicles for military and civilian applications, including avionics, aircraft, and spacecraft data handling. In the absence of core security measures such as authentication, authorization, and encryption, the bus connecting sensitive functions, including autopilot, GPS, fuel valve switches, and other avionics equipment, is easily vulnerable to a wide range of attacks. This paper proposes, AdaptIDS, a novel adaptive intrusion detection system as a security analytics framework for the MIL-STD-1553 communication bus. AdaptIDS mainly adopts data science principles and leverages advanced deep learning techniques (i.e., the stacking ensemble) to boost its generalization capabilities for detecting unseen patterns of attacks in the dynamic changing environment of aerospace vehicles. Extensive experiments are conducted using two datasets generated from an open-source simulation system, reflecting dynamic real-life scenarios. The evaluation results demonstrate that our solution outperforms existing solutions with high detection effectiveness of 0.99 F1-measure and computational time efficiency. Marwa Elsayed, Michael Wrana, Ziad Mansour, Karim Lounis, Steven H. H. Ding, Mohammad Zulkernine |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2020 | Vehicle Software Engineering (VSE): Research and PracticeabstractThe Internet of Things (IoT) is shaping the future of the automotive industry. Grounded on the advances in everything from sensors, electronic controllers, artificial intelligence, data analytics, to network connectivity, intelligent connected autonomous vehicles (CAVs) have become the essence in IoT applications. The software in CAVs lies at the core of this digital transformation. Faulty software remains the main reason behind the vast number of safety recalls and reputation damage witnessed recently in the automotive industry. The uniqueness of CAVs originates challenges for vehicle software engineering (VSE) that render traditional models and practical solutions for software development ineffective and inapplicable. Despite the raised necessity to adopt a software engineering model that can handle these challenges, there is a lack of studies recognizing the importance of VSE. This article presents an in-depth and comprehensive analysis to perceive the existing software engineering processes detailing their strengths and limitations in the context of CAVs. It also reviews current practical software solutions, including standards, tools, languages, and research efforts to understand the evolution, trends, and current practice in this article area. This article will enable automakers and software providers to better assess and differentiate among the existing software engineering processes and current practical solutions for vehicle software system development. Hence, they would be able to adopt a VSE model and follow best practices that can better meet their challenging needs. Lama Moukahal, Marwa Elsayed, Mohammad Zulkernine |
IEEE Internet Things J. | 2 |
| 2019 | Offering security diagnosis as a service for cloud SaaS applications
Marwa Elsayed, Mohammad Zulkernine |
J. Inf. Secur. Appl. | 1 |
| 2016 | IFCaaS: Information Flow Control as a Service for Cloud SecurityabstractWith the maturity of service-oriented architecture (SOA) and Web technologies, web services have become critical components of Software as a Service (SaaS) applications in cloud ecosystem environments. Most SaaS applications leverage multi-tenant data stores as a back end to keep and process data with high agility. Although these technologies promise impressive benefits, they put SaaS applications at risk against novel as well as prevalent attack vectors. This security risk is further magnified by the loss of control and lack of security enforcement over sensitive data manipulated by SaaS applications. An effective solution is needed to fulfill several requirements originating in the dynamic and complex nature of such applications. Inspired by the rise of Security as a Service (SecaaS) model, this paper introduces "Information Flow Control as a Service (IFCaaS)". IFCaaS lays the foundation of cloud-delivered IFC-based security analysis and monitoring services. As an example of the adoption of the IFCaaS, this paper presents a novel framework that addresses the detection of information flow vulnerabilities in SaaS applications. Our initial experiments show that the framework is a viable solution to protect against data integrity and confidentiality violations leading to information leakage. Marwa Elsayed, Mohammad Zulkernine |
ARES | 1 |