VLDB 2026 Research / reviewers in the wild / expert
Mahawaga Arachchige Pathum Chamikara
dblp:173/5818 · also M. A. P. Chamikara
· DBLP profile ↗
21ranked-venue papers
10as first author
15since 2021 · last 2026
0000-0002-4286-3774ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 6 since 2021Computer networks · 4 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Navigating the Privacy-UX Trade-offs in Extended Reality (XR) - A Socio-Technical Taxonomy and Research Roadmap
Shunyao Wang, Mahawaga Arachchige Pathum Chamikara, Mohan Baruwal Chhetri, Zhenchang Xing, Ryan Kok Leong Ko |
AsiaCCS | 2 |
| 2025 | Towards Usability of Data with Privacy: A Unified Framework for Privacy-Preserving Data Sharing with High Utility
Mahawaga Arachchige Pathum Chamikara, Seung Ick Jang, Ian J. Oppermann, Dongxi Liu, Musotto Roberto, Sushmita Ruj, Arindam Pal 0001, Meisam Mohammady, Seyit Ahmet Çamtepe, Sylvia Young, Chris Dorrian, Nasir David |
AsiaCCS | 1 |
| 2025 | SoK: The Privacy Paradox of Large Language Models: Advancements, Privacy Risks, and MitigationabstractLarge language models (LLMs) are sophisticated artificial intelligence systems that enable machines to generate human-like text with remarkable precision. While LLMs offer significant technological progress, their development using vast amounts of user data scraped from the web and collected from extensive user interactions poses risks of sensitive information leakage. Most existing surveys focus on the privacy implications of the training data but tend to overlook privacy risks from user interactions and advanced LLM capabilities. This paper aims to fill that gap by providing a comprehensive analysis of privacy in LLMs, categorizing the challenges into four main areas: (i) privacy issues in LLM training data, (ii) privacy challenges associated with user prompts, (iii) privacy vulnerabilities in LLM-generated outputs, and (iv) privacy challenges involving LLM agents. We evaluate the effectiveness and limitations of existing mitigation mechanisms targeting these proposed privacy challenges and identify areas for further research. Yashothara Shanmugarasa, Ming Ding 0001, Mahawaga Arachchige Pathum Chamikara, Thierry Rakotoarivelo |
AsiaCCS | 3 |
| 2024 | Unveiling Intellectual Property Vulnerabilities of GAN-Based Distributed Machine Learning through Model Extraction AttacksabstractGenerative Adversarial Networks (GANs), as a cornerstone of artificial intelligence (AI), are widely recognized as the intellectual property (IP) of their owners, given the sensitivity of the training data and the commercial value tied to the models. Model extraction attacks, which aim to steal well-trained proprietary models, pose a significant threat to model IP. Nevertheless, current research predominately focuses on the context of machine learning as a service (MLaaS), where the emphasis lies in understanding the attack knowledge acquired through black-box API queries. This restricted perspective exposes a critical gap in investigating model extraction attacks within realistic distributed settings for generative tasks. In this work, we present the first investigation into model extraction attacks against GANs in distributed settings. We provide a comprehensive attack taxonomy, considering three different levels of knowledge the adversary can obtain in practice. Based on it, we introduce a novel model extraction attack named MoEx, which focuses on the GAN-based distributed learning scenario, i.e., Multi-Discriminator GANs, a typical asymmetric distributed setting. MoEx uses the objective function simulation, leveraging data exchanged during the learning process, to approximate the GAN generator owned by the server. We define two attack goals for MoEx, fidelity extraction and accuracy extraction . Then we comprehensively evaluate the effectiveness of MoEx's two goals with real-world datasets. Our results demonstrate its robust capabilities in extracting generators with high fidelity and accuracy compared with existing methods. Mengyao Ma, Shuofeng Liu, Mahawaga Arachchige Pathum Chamikara, Mohan Baruwal Chhetri, Guangdong Bai |
CIKM | 3 |
| 2024 | An Adversarial Machine Learning Based Approach for Privacy Preserving Face Recognition in Distributed Smart City SurveillanceabstractSmart cities rely heavily on surveillance cameras for urban management and security. However, the extensive use of these cameras also raises significant concerns regarding data privacy. Unauthorized access to facial data captured by these cameras and the potential for misuse of this data poses serious threats to individuals’ privacy. Current privacy preservation solutions often compromise data usability with noise application-based approaches and vulnerable centralized data handling settings. To address these privacy challenges, we propose a novel approach that combines Adversarial Machine Learning (AML) with Federated Learning (FL). Our approach involves the use of a noise generator that perturbs surveillance data right from the source before they leave the surveillance cameras. By exclusively training the Federated Learning model on these perturbed samples, we ensure that sensitive biometric features are not shared with centralized servers. Instead, such data remains on local devices (e.g., cameras), thereby ensuring that data privacy is maintained. We performed a thorough real-world evaluation of the proposed method and achieved an accuracy of around 99.95% in standard machine learning settings. In distributed settings, we achieved an accuracy of around 96.24% using federated learning, demonstrating the practicality and effectiveness of the proposed solution. 1 1 The code is available at: https://github.com/farah-wahida/Privacy-Preserving-Face-Recognition-in-Distributed-Smart-City-Surveillance . Farah Wahida, Mahawaga Arachchige Pathum Chamikara, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Comput. Networks | 2 |
| 2023 | LoDen: Making Every Client in Federated Learning a Defender Against the Poisoning Membership Inference AttacksabstractFederated learning (FL) is a widely used distributed machine learning framework. However, recent studies have shown its susceptibility to poisoning membership inference attacks (MIA). In MIA, adversaries maliciously manipulate the local updates on selected samples and share the gradients with the server (i.e., poisoning). Since honest clients perform gradient descent on samples locally, an adversary can distinguish whether the attacked sample is a training sample based on observation of the change of the sample’s prediction. This type of attack exacerbates traditional passive MIA, yet the defense mechanisms remain largely unexplored. Mengyao Ma, Yanjun Zhang 0002, Mahawaga Arachchige Pathum Chamikara, Leo Yu Zhang, Mohan Baruwal Chhetri, Guangdong Bai |
AsiaCCS | 3 |
| 2023 | SoK: Systematizing Attack Studies in Federated Learning - From Sparseness to CompletenessabstractFederated Learning (FL) is a machine learning technique that enables multiple parties to collaboratively train a model using their private datasets. Given its decentralized nature, FL has inherent vulnerabilities that make it susceptible to adversarial attacks. The success of an attack on FL depends upon several (latent) factors, including the adversary’s strength, the chosen attack strategy, and the effectiveness of the defense measures in place. There is a growing body of literature on empirical attack studies on FL, but no systematic way to compare and evaluate the completeness of these studies, which raises questions about their validity. To address this problem, we introduce a causal model that captures the relationship between the different (latent) factors, and their reflexive indicators, that can impact the success of an attack on FL. The proposed model, inspired by structural equation modeling, helps systematize the existing literature on FL attack studies and provides a way to compare and contrast their completeness. We validate the model and demonstrate its utility through experimental evaluation of select attack studies. Our aim is to help researchers in the FL domain design more complete attack studies and improve the understanding of FL vulnerabilities. Geetanjli Sharma, Mahawaga Arachchige Pathum Chamikara, Mohan Baruwal Chhetri, Yi-Ping Phoebe Chen |
AsiaCCS | 2 |
| 2023 | Government Mobile Apps: Analysing Citizen Feedback via App ReviewsabstractGovernments worldwide are increasingly embracing digital transformation initiatives to enhance service delivery, engage citizens, and achieve better outcomes. However, obtaining continuous feedback on these initiatives poses a substantial challenge. This paper investigates the feasibility of leveraging mobile app reviews as a valuable source of citizen feedback on government digital services. We analyse 100,146 app reviews from 129 government mobile apps in Australia and identify several functional and usability issues. These include issues such as app instability, complexity, integration problems, navigation difficulties, inaccuracies, and challenges with ID verification and authentication processes. Furthermore, we uncover several factors that influence user satisfaction, including accuracy and reliability, convenience, dependability, user-centric design, and overall user-friendliness. These findings demonstrate a strong correlation between user feedback and the government's digital transformation strategy, underscoring the viability of mobile app reviews as a cost-effective avenue for collecting citizen feedback. Tooba Aamir, Mohan Baruwal Chhetri, Mahawaga Arachchige Pathum Chamikara, Marthie Grobler |
ASE | 3 |
| 2023 | AgrEvader: Poisoning Membership Inference against Byzantine-robust Federated LearningabstractThe Poisoning Membership Inference Attack (PMIA) is a newly emerging privacy attack that poses a significant threat to federated learning (FL). An adversary conducts data poisoning (i.e., performing adversarial manipulations on training examples) to extract membership information by exploiting the changes in loss resulting from data poisoning. The PMIA significantly exacerbates the traditional poisoning attack that is primarily focused on model corruption. However, there has been a lack of a comprehensive systematic study that thoroughly investigates this topic. In this work, we conduct a benchmark evaluation to assess the performance of PMIA against the Byzantine-robust FL setting that is specifically designed to mitigate poisoning attacks. We find that all existing coordinate-wise averaging mechanisms fail to defend against the PMIA, while the detect-then-drop strategy was proven to be effective in most cases, implying that the poison injection is memorized and the poisonous effect rarely dissipates. Inspired by this observation, we propose AgrEvader, a PMIA that maximizes the adversarial impact on the victim samples while circumventing the detection by Byzantine-robust mechanisms. AgrEvader significantly outperforms existing PMIAs. For instance, AgrEvader achieved a high attack accuracy of between 72.78% (on CIFAR-10) to 97.80% (on Texas100), which is an average accuracy increase of 13.89% compared to the strongest PMIA reported in the literature. We evaluated AgrEvader on five datasets across different domains, against a comprehensive list of threat models, which included black-box, gray-box and white-box models for targeted and non-targeted scenarios. AgrEvader demonstrated consistent high accuracy across all settings tested. The code is available at: https://github.com/PrivSecML/AgrEvader. Yanjun Zhang 0002, Guangdong Bai, Mahawaga Arachchige Pathum Chamikara, Mengyao Ma, Liyue Shen, Jingwei Wang 0003, Surya Nepal, Minhui Xue 0001, Joseph K. Liu |
WWW | 3 |
| 2022 | SplitFed: When Federated Learning Meets Split LearningabstractFederated learning (FL) and split learning (SL) are two popular distributed machine learning approaches. Both follow a model-to-data scenario; clients train and test machine learning models without sharing raw data. SL provides better model privacy than FL due to the machine learning model architecture split between clients and the server. Moreover, the split model makes SL a better option for resource-constrained environments. However, SL performs slower than FL due to the relay-based training across multiple clients. In this regard, this paper presents a novel approach, named splitfed learning (SFL), that amalgamates the two approaches eliminating their inherent drawbacks, along with a refined architectural configuration incorporating differential privacy and PixelDP to enhance data privacy and model robustness. Our analysis and empirical results demonstrate that (pure) SFL provides similar test accuracy and communication efficiency as SL while significantly decreasing its computation time per global epoch than in SL for multiple clients. Furthermore, as in SL, its communication efficiency over FL improves with the number of clients. Besides, the performance of SFL with privacy and robustness measures is further evaluated under extended experimental settings. Chandra Thapa, Mahawaga Arachchige Pathum Chamikara, Seyit Ahmet Çamtepe, Lichao Sun 0001 |
AAAI | 2 |
| 2022 | Local Differential Privacy for Federated Learning
Mahawaga Arachchige Pathum Chamikara, Dongxi Liu, Seyit Ahmet Çamtepe, Surya Nepal, Marthie Grobler, Peter Bertók, Ibrahim Khalil 0001 |
ESORICS (1) | 1 |
| 2022 | Privacy-preserving location data stream clustering on mobile edge computing and cloud
Veronika Stephanie, Mahawaga Arachchige Pathum Chamikara, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Inf. Syst. | 2 |
| 2021 | Privacy preserving distributed machine learning with federated learning
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe |
Comput. Commun. | 1 |
| 2021 | PPaaS: Privacy Preservation as a Service
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe |
Comput. Commun. | 1 |
| 2021 | The importance of social identity on password formulations
Marthie Grobler, Mahawaga Arachchige Pathum Chamikara, Jacob Abbott, Jongkil Jeong, Surya Nepal, Cécile Paris |
Pers. Ubiquitous Comput. | 2 |
| 2020 | Privacy Preserving Face Recognition Utilizing Differential Privacy
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe |
Comput. Secur. | 1 |
| 2020 | Local Differential Privacy for Deep LearningabstractThe Internet of Things (IoT) is transforming major industries, including but not limited to healthcare, agriculture, finance, energy, and transportation. IoT platforms are continually improving with innovations, such as the amalgamation of software-defined networks (SDNs) and network function virtualization (NFV) in the edge-cloud interplay. Deep learning (DL) is becoming popular due to its remarkable accuracy when trained with a massive amount of data such as generated by IoT. However, DL algorithms tend to leak privacy when trained on highly sensitive crowd-sourced data such as medical data. The existing privacy-preserving DL algorithms rely on the traditional server-centric approaches requiring high processing powers. We propose a new local differentially private (LDP) algorithm named LATENT that redesigns the training process. LATENT enables a data owner to add a randomization layer before data leave the data owners' devices and reach a potentially untrusted machine learning service. This feature is achieved by splitting the architecture of a convolutional neural network (CNN) into three layers: 1) convolutional module (CNM); 2) randomization module; and 3) fully connected module. Hence, the randomization module can operate as an NFV privacy preservation service in an SDN-controlled NFV, making LATENT more practical for IoT-driven cloud-based environments compared to existing approaches. The randomization module employs a newly proposed LDP protocol named utility enhancing randomization, which allows LATENT to maintain high utility compared to existing LDP protocols. Our experimental evaluation of LATENT on convolutional deep neural networks demonstrates excellent accuracy (e.g., 91%-96%) with high model quality even under low privacy budgets (e.g., ε = 0.5). Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe, Mohammed Atiquzzaman |
IEEE Internet Things J. | 1 |
| 2020 | Efficient privacy preservation of big data for accurate data mining
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Dongxi Liu, Seyit Ahmet Çamtepe, Ibrahim Khalil 0001 |
Inf. Sci. | 1 |
| 2020 | A Trustworthy Privacy Preserving Framework for Machine Learning in Industrial IoT SystemsabstractIndustrial Internet of Things (IIoT) is revolutionizing many leading industries such as energy, agriculture, mining, transportation, and healthcare. IIoT is a major driving force for Industry 4.0, which heavily utilizes machine learning (ML) to capitalize on the massive interconnection and large volumes of IIoT data. However, ML models that are trained on sensitive data tend to leak privacy to adversarial attacks, limiting its full potential in Industry 4.0. This article introduces a framework named PriModChain that enforces privacy and trustworthiness on IIoT data by amalgamating differential privacy, federated ML, Ethereum blockchain, and smart contracts. The feasibility of PriModChain in terms of privacy, security, reliability, safety, and resilience is evaluated using simulations developed in Python with socket programming on a general-purpose computer. We used Ganache_v2.0.1 local test network for the local experiments and Kovan test network for the public blockchain testing. We verify the proposed security protocol using Scyther_v1.1.3 protocol verifier. Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe, Mohammed Atiquzzaman |
IEEE Trans. Ind. Informatics | 1 |
| 2019 | An efficient and scalable privacy preserving algorithm for big data and data streams
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Dongxi Liu, Seyit Ahmet Çamtepe, Ibrahim Khalil 0001 |
Comput. Secur. | 1 |
| 2018 | Efficient data perturbation for privacy preserving and accurate data stream mining
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Dongxi Liu, Seyit Ahmet Çamtepe, Ibrahim Khalil 0001 |
Pervasive Mob. Comput. | 1 |