VLDB 2026 Research / reviewers in the wild / expert
Mahdi Rabbani
dblp:179/8448
· DBLP profile ↗
15ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0002-6613-0954ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 5 · 2 since 2021Systems, architecture and hardware · 1Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Design and evaluation of a robust and explainable intrusion detection framework for 5G/B5G networksabstractAs Fifth-generation (5G) networks advance towards future 6G technology, they provide enhanced capabilities in terms of data rates, latency, and connectivity. The expanding and heterogeneous landscape further extends the attack surface with increasing vulnerability to a wide range of dynamic cyber threats. Traditional Intrusion Detection Systems, relying on static signature-based methods, face significant challenges in detecting novel attacks in such complex environments. This paper proposes an explainable hybrid AE-XGBoost framework to address these gaps. In this proposed framework, the deep autoencoder serves as the backbone for two primary tasks: learning robust features from high-dimensional traffic data and synthesizing high-quality samples for minority, underrepresented attack classes. It effectively forms a class-balanced dataset. This is further extended to integrate Shapley Additive Explanations (SHAP), which provide needed interpretability. The framework robustness is determined by an extensive evaluation strategy. Extensive experiments are conducted using a 5-fold cross-validation and cross-dataset validation using three different datasets. The experimental results demonstrate the model effectiveness and promising generalization across the different datasets. Across these settings, the proposed IDS achieves F1-scores between approximately 0.96 and 0.999 and AUC values above 0.97, with only minor performance differences between original and synthetic test samples. SHAP-based analysis further reveals that a small subset of 5G- and TCP-level features consistently dominates the predictions, offering actionable explanations for security analysts. This provides a successful, scalable, and reliable security measure that proves effective and appropriate for 6G mobile network implementations in the near future. Nasim Nezhadsistani, Mohsen Tajgardan, Mahdi Rabbani, Weijie Niu, Burkhard Stiller |
Comput. Networks | 3 |
| 2026 | Evaluating Generative Reasoning Models for Credential Tweaking and Lightweight Client-Side Defense in IoT EcosystemsabstractGenerative reasoning models introduce a new paradigm in cybersecurity, enabling not only novel defenses but also sophisticated attack simulations. This paper investigates the use of open-source reasoning models to simulate credential tweaking behavior and enhance password-based authentication security in IoT environments. We propose Hybrid Similarity Scoring (HSS) and its user-contextualized variant HSSuser, a lightweight, client-side similarity metric combining structural (Damerau-Levenshtein) and character-distribution (cosine similarity) components to detect password reuse and subtle modifications or tweaks in real time. Following NIST guidelines, we analyzed over 4 billion password pairs from breached datasets and used five prompt designs in various reasoning models such as DeepSeek-R1, Qwen-QwQ, Phi4-Reasoning, Qwen3, and Magistral series to generate password variants mimicking attacker strategies. Experimental results show that reasoning models can produce highly similar modifications resembling real-world password reuse patterns, while prompt reframing significantly reduces risky outputs. HSS effectively quantifies these behaviors and is suitable for deployment in constrained IoT devices, offering an intent-aware, proactive layer of client-side defense against AIenhanced credential attacks. Erika Thea Ajes, Mahdi Rabbani, Zeynab Anbiaee, Rongxing Lu, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Sajjad Dadkhah |
IEEE Internet Things J. | 2 |
| 2026 | A lightweight defense mechanism against next-generation of phishing emails using distilled attention-augmented BiLSTMabstractThe current generation of large language models produces sophisticated social-engineering content that bypasses standard text screening systems in business communication platforms. Our proposed solution for mail gateway and endpoint deception detection operates in a privacy-protective manner while handling the performance requirements of network and mobile security systems. The MobileBERT teacher receives fine-tuning before its transformation into a BiLSTM model with multi-head attention which maintains semantic discrimination only with 4.5 million parameters. The hybrid dataset contains human-written messages together with LLM-generated paraphrases that use masking techniques and personalization methods to enhance modern attack resistance. The evaluation system uses five testing protocols which include human-only and LLM-only tests and two cross-distribution transfer tests and a production-like mixed traffic test to assess performance in native environments and across different distribution types and combined traffic scenarios. The distilled model maintains a weighted-F1 score difference of 1–2.5 points compared to the mixture split results of strong transformer baselines including ModernBERT, DeBERTaV3-base, T5-base, DeepSeek-R1 Distill Qwen-1.5B and Phi-4 mini while achieving 80–95% faster inference times and 95–99% smaller model sizes. The system demonstrates excellent performance in terms of accuracy and latency while maintaining a compact size which enables real-time filtering without acceleration hardware and supports policy-based management. The paper examines system performance under high traffic conditions and security measures for privacy protection and implementation methods for operational deployment. The research team will release all necessary code and training scripts and corpus splits to support security researchers who want to reproduce experiments and implement practical solutions. Morteza Eskandarian, Mahdi Rabbani, Arun Kaniyamattam, Fatemeh Nejati, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Ali A. Ghorbani 0001, Sajjad Dadkhah |
J. Inf. Secur. Appl. | 2 |
| 2026 | URL2Path: A Robust Graph Learning Approach for Malicious URL DetectionabstractPhishing attacks remain one of the most popular, damaging cyber threats, with malicious Uniform Resource Locators (URLs) acting as a primary vector for credential theft, malware distribution. Traditional detection approaches, based on phishing keyword matching, static rule-based systems, struggle against modern phishing attempts due to syntactic variability, semantic obfuscation, adversarial manipulation. Recent advances in Large Language Models (LLMs) have further enabled attackers to generate visually deceptive, syntactically diverse URLs that evade lexical similarity filters. To address these emerging challenges, this paper introduces a content-independent phishing URL detection framework that combines lexical feature extraction with graph-based reasoning. The proposed technique, URL2Path, tokenizes URL strings into sequential segments, maps them onto a homogeneous directed graph, where structural, semantic patterns are captured using DeepWalk-based node embeddings. This approach addresses three key limitations in existing systems: limited scalability of content-based detection, weak robustness of traditional models against LLM generated adversarial URLs, the absence of graph-structured reasoning to vectorize raw URLs into expressive representations. Experimental evaluations show that URL2Path achieves superior precision, recall, F1-score, particularly under cross-dataset validation, adversarial stress testing, imbalanced training conditions. The model is benchmarked against recent lightweight LLMs (BERT-Tiny, DeBERTa-v3, ModernBERT, DeepSeek), demonstrating improved detection accuracy, faster inference. Additionally, we assess its scalability to million-scale datasets, cross-domain generalization, robustness against adversarial perturbations. Mahdi Rabbani, Morteza Eskandarian, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Rongxing Lu, Sajjad Dadkhah |
IEEE Trans. Reliab. | 1 |
| 2025 | Device Identification and Anomaly Detection in IoT EnvironmentsabstractAs the Internet of Things (IoT) landscape continues to expand, a diverse range of devices with various functionalities is being integrated into the IoT ecosystem. When traditional systems, which involve human interaction, are replaced by devices, it becomes crucial to upgrade the conventional authorization and authentication mechanisms. Traditional approaches for device identification and anomaly detection often fail to address the dynamic behaviors of IoT devices due to the highly heterogeneous nature of the IoT environment. To address these challenges, this article proposes a novel and lightweight integrated model for simultaneous IoT device identification and anomaly detection. The proposed approach leverages both packet-based and flow-based feature extraction techniques to extract a diverse and significant set of features, which are crucial for robust anomaly detection and device classification. This novel combined feature set incorporates a wide range of attributes from various domains, including HTTPS-related features, handshake information, and user agent strings, specifically extracted for IoT device identification. In addition, the feature set includes specialized attributes for anomaly detection, such as stream, channel, and jitter metrics, which are calculated over different time intervals to enhance the model’s anomaly detection capabilities. Experimental analysis, conducted using real network traffic data from state-of-the-art datasets, demonstrates the model’s efficiency and scalability, which makes the model well-suited for real-time IoT threat detection and device management in resource-constrained environments. Mahdi Rabbani, Jinkun Gui, Fatemeh Nejati, Zeming Zhou, Arun Kaniyamattam, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Rongxing Lu, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 1 |
| 2025 | A lightweight IoT device identification using enhanced behavioral-based features
Mahdi Rabbani, Jinkun Gui, Zeming Zhou, Fatemeh Nejati, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Rongxing Lu, Ali A. Ghorbani 0001 |
Peer Peer Netw. Appl. | 1 |
| 2024 | A Graph Learning-Based Approach for Lateral Movement DetectionabstractLateral movement, a crucial phase in the Advanced Persistent Threat (APT) life cycle, refers to a strategy employed by adversaries to traverse horizontally within a network. The aim is to gain access to various systems or resources, thereby expanding their control and potential access to valuable targets. Detecting these attacks becomes challenging for conventional detection systems due to various factors, including the complexity of pathways, the mimicking of legitimate user behavior by attackers, and limited network visibility. To address these challenges, advanced detection techniques are required to effectively and dynamically analyze multiple features within the interconnected structure of the network. This paper introduces an innovative approach to detect malicious lateral movement paths by leveraging authentication events and graph learning techniques. The proposed method involves constructing a heterogeneous graph, and employing DeepWalk for node embedding. By combining node embedding features with the temporal information of authentication events, feature vectors are generated for each authentication request. These features are then used to train multiple machine learning-based classifiers to detect malicious lateral movement paths. Furthermore, to assess the model’s performance in a more realistic scenario, a series of additional experiments were conducted. These experiments provided further validation of the model’s robustness and its capability for forward prediction. Mahdi Rabbani, Leila Rashidi, Ali A. Ghorbani 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | An intelligent and blind dual color image watermarking for authentication and copyright protection
Sajjad Bagheri Baba Ahmadi, Gongxuan Zhang, Mahdi Rabbani, Lynda Boukela, Hamed Jelodar |
Appl. Intell. | 3 |
| 2021 | A NLP framework based on meaningful latent-topic detection and sentiment analysis via fuzzy lattice reasoning on youtube comments
Hamed Jelodar, Mahdi Rabbani, Sajjad Bagheri Baba Ahmadi, Lynda Boukela, Ruxin Zhao, Raja Sohail Ahmed Larik |
Multim. Tools Appl. | 3 |
| 2021 | Recommendation system based on semantic scholar mining and topic modeling on conference publications
Hamed Jelodar, Yongli Wang 0002, Gang Xiao 0003, Mahdi Rabbani, Ruxin Zhao, Seyedvalyallah Ayobi, Isma Masood |
Soft Comput. | 4 |
| 2020 | Discrete selfish herd optimizer for solving graph coloring problem
Ruxin Zhao, Yongli Wang 0002, Hamed Jelodar, Mahdi Rabbani, Hao Li 0050 |
Appl. Intell. | 6 |
| 2020 | A hybrid machine learning approach for malicious behaviour detection and recognition in cloud computing
Mahdi Rabbani, Reza Khoshkangini, Hamed Jelodar, Ruxin Zhao |
J. Netw. Comput. Appl. | 1 |
| 2020 | Selfish herd optimization algorithm based on chaotic strategy for adaptive IIR system identification problem
Ruxin Zhao, Yongli Wang 0002, Hamed Jelodar, Chi Yuan, Yanchao Li 0001, Isma Masood, Mahdi Rabbani, Hao Li 0050 |
Soft Comput. | 9 |
| 2019 | Selfish herds optimization algorithm with orthogonal design and information update for training multi-layer perceptron neural network
Ruxin Zhao, Yongli Wang 0002, Hamed Jelodar, Chi Yuan, Yanchao Li 0001, Isma Masood, Mahdi Rabbani |
Appl. Intell. | 8 |
| 2018 | A survey of real-time approximate nearest neighbor query over streaming data for fog computing
Xiaohui Jiang, Yanchao Li 0001, Chi Yuan, Isma Masood, Hamed Jelodar, Mahdi Rabbani, Yongli Wang 0002 |
J. Parallel Distributed Comput. | 7 |