Islam Obaidat

dblp:191/3175 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0002-2258-0785ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Few-Shot Retrieval-Augmented LLMs for Anomaly Detection in Network Traffic
Furqan Rustam, Islam Obaidat, Davide Di Monda, Anca Jurcut
CANS2
2025 One Model to Catch Them All: Autoencoder-Based Anomaly Detection in Next-Generation Networks
abstract
Anomaly detection is crucial for ensuring the security and reliability of next-generation heterogeneous networks, which integrate a variety of devices (e.g., IoT and traditional devices). Autoencoder (AE)-based approaches have shown promise in identifying network anomalies by modeling benign traffic and detecting deviations. However, existing AE methods, mostly evaluated in homogeneous environments, struggle to generalize in next-generation multi-environment (M-En) networks (comprising both IoT and traditional devices) due to diverse traffic patterns. This generalization issue is evidenced through an initial ablation study, where AE models trained solely on a single traffic type (e.g., IoT-only) fail to detect anomalies effectively in M-En networks. To address this limitation, a Residual Autoencoder (RD-AE) specifically designed for anomaly detection in next-generation M-En networks is presented. RD-AE is trained on a combined actual benign dataset containing both IoT and traditional traffic, allowing it to accurately identify abnormal (malicious) deviations in M-En networks. An attention-based BiLSTM classifier subsequently categorizes these detected anomalies, differentiating between malicious IoT and traditional traffic to support targeted defensive measures. A human-in-the-loop continuous learning mechanism is integrated into the classifier, ensuring adaptability to emerging threats. A realistic testbed is used to generate M-En traffic and evaluate the proposed framework in real time. Experimental results show that RD-AE achieves up to 97.4% accuracy in detecting previously unseen attack scenarios.
Islam Obaidat, Furqan Rustam, Anca Jurcut
GLOBECOM1
2025 Lightweight Fine-Tuning of LLMS for Explainable Intrusion Detection in SDN
abstract
Cybersecurity concerns are rising with the rapid adoption of technology as cybercriminals grow more active. Protecting complex networks like Software-Defined Networking (SDN) is increasingly challenging because its centralized architecture introduces vulnerabilities that traditional security systems struggle to handle. This paper investigates the application of large language models (LLMs) for intrusion detection in SDN environments. Our proposed approach fine-tunes three LLMs, GPT_NEO, Phi-2, and Llama2-7b, through Quantized Low-Rank Adaptation (QLoRA), enabling efficient 4-bit quantization and reduced memory usage. Structured network features are transformed into natural language prompts for binary classification of benign and malicious traffic. Experimental results show that all models achieve high accuracy, with Llama2-7b and Phi-2 reaching high scores across multiple data scales. CodeCarbon tracking highlights the environmental trade-offs, with Llama27b consuming the most energy and Phi-2 being the most efficient. Our proposed framework for Phi-2 and GPT_NEO achieves a 1.00 accuracy score with the lowest$\text{CO}_{2}$emission of 0.173 when compared with the baselines. Further, we explore explainability challenges for our LLM models, noting the limitations of token-level interpretability tools in handling dense textual embeddings.
Suvajit Lodh, Islam Obaidat, Furqan Rustam, Anca Jurcut
WiMob2
2024 Guided Learning and Interactive Visualization for Teaching & Learning Stack Smashing Attacks & Defenses: Experiences and Evaluation
abstract
This Innovative Practice paper presents the design, deployment, and evaluation of a software security module that teaches stack smashing attacks and defenses using innovative pedagogical practices. Widely ubiquitous buffer overflow vul-nerabilities and stack smashing attacks that exploit them are critical components in advanced software security curricula, since buffer overflows can arise due to simple programmer oversight, and stack smashing can have dangerous consequences in critical systems. However, these topics are known to be difficult to teach and learn due to the vast amount of background needed, the difficulty of learning type-unsafe languages, and laborious memory address space calculations involved. In this work, we aim to bring innovative pedagogical practices to this advanced cybersecurity education topic through a suite of four guided learning activities that follow the Process Oriented Guided Inquiry Learning (POGIL) style, and DISSAV, an interactive visualization tool for modeling stack smashing attacks. This paper presents an evaluation of the module based on deploying it in multiple sections of an introductory undergraduate cybersecurity course in the UNC Charlotte in Fall 2022, Spring 2023, and Fall 2023. Our study finds that students have mostly positive perceptions about activity structure / design, content, and style, but that improvements may be needed to some aspects, including question phrasing, activity length, and teamwork facilitation.
Harini Ramaprasad, Meera Sridhar, Sushma Indrani Dangeti, Soham Pradhan, Islam Obaidat
FIE5
2023 Creating a Large-scale Memory Error IoT Botnet Using NS3DockerEmulator
abstract
DDoSim, a simulation testbed for mimicking real-world, large-scale botnet DDoS attacks, is presented. DDoSim offers various capabilities, including running user-specified software, testing botnet-recruitment exploits, and measuring the severity of resulting DDoS attacks. DDoSim leverages NS3DockerEmulator's Docker and NS-3 integration to load Docker containers with actual binaries and connect them over a simulated NS-3 network. DDoSim is validated through a comparison with results from real hardware experiments. This paper focuses on the results of an experiment series concerning deploying a memory error botnet on IoT devices. Unlike the Mirai attack, which relies on default credentials, these experiments exploit memory error vulnerabilities to access IoT devices. DDoSim also implements realistic IoT churn, reflecting dynamic network conditions in real-world IoT environments. The results reveal that memory error vulnerabilities enable botnet recruitment, while network conditions, attack size, and duration all have a proportional impact on target servers. DDoSim is publicly available for researchers' use.
Islam Obaidat, Bennett Kahn, Fatemeh Tavakoli, Meera Sridhar
DSN1
2022 Jadeite: A novel image-behavior-based approach for Java malware detection using deep learning
Islam Obaidat, Meera Sridhar, Khue M. Pham, Phu H. Phung
Comput. Secur.1
2019 Unstructured Medical Text Classification using Linguistic Analysis: A Supervised Deep Learning Approach
abstract
A vast amount of unstructured text that contains valuable information is available over the web. This text is changing and proliferating, making it hard for people to process, read, and remember. Data mining and information extraction algorithms are used to develop new automation techniques to process the unstructured text. Among this publicly available text, there are a considerable amount of online medical articles, which provides valuable information about diseases, symptoms, operations, treatments, drugs, etc. Automatic unstructured text classification offers practical information management that does not depend on the subjective criteria of classification. It also provides useful information by obtaining and correlating relevant data present in documents. It also classifies, identifies and presents all sources of knowledge and reduces the time for retrieving information by simplifying access to content. Therefore, medical information needs to be classified into their respected categories (such as Diabetes, Cancer, Depression, Pediatrics, etc.). In this paper, we propose to use a deep learning approach for unstructured medical text classification at the document level. In our classification model we used two types of features: (i) content-based features (stylistic and complexity), and (ii) health domain-specific features. Moreover, rather than dealing with binary classification, this work handles multiclasses medical articles classification. This classification is done based on linguistic features that are extracted from the text, it also incorporates medical domain-specific terms/keywords as part of the classification feature set. These domain-specific features are extracted by applying topic modeling technique to spot the most probable terms for each medical class. Our experiments shows a reasonable classification accuracy for such a large number of classes.
Ahmad Al-Doulat, Islam Obaidat, Minwoo Lee 0001
AICCSA2
2019 Exploiting Memory Corruption Vulnerabilities in Connman for IoT Devices
abstract
In the recent past, there has been a rapid increase in attacks on consumer Internet-of-Things (IoT) devices. Several attacks currently focus on easy targets for exploitation, such as weak configurations (weak default passwords). However, with governments, industries, and organizations proposing new laws and regulations to reduce and prevent such easy targets in the IoT space, attackers will move to more subtle exploits in these devices. Memory corruption vulnerabilities are a significant class of vulnerabilities in software security through which attackers can gain control of the entire system. Numerous memory corruption vulnerabilities have been found in IoT firmware already deployed in the consumer market. This paper presents an approach for exploiting stack-based buffer-overflow attacks in IoT firmware, to hijack the device remotely. To show the feasibility of this approach, we demonstrate exploiting a common network software application, Connman, used widely in IoT firmware such as Samsung smart TVs. A series of experiments are reported on, including: crashing and executing arbitrary code in the targeted software application in a controlled environment, adopting the attacks in uncontrolled environments (with standard software defenses such as W⊕X and ASLR enabled), and installing publicly available IoT firmware that uses this software application on a Raspberry Pi. The presented exploits demonstrate the ease in which an adversary can control IoT devices.
K. Virgil English, Islam Obaidat, Meera Sridhar
DSN2
2017 A security framework for cloud-based video surveillance system
Mohammad A. Alsmirat, Islam Obaidat, Yaser Jararweh, Mohammed I. Al-Saleh
Multim. Tools Appl.2
2017 Internet of surveillance: a cloud supported large-scale wireless surveillance system
Mohammad A. Alsmirat, Yaser Jararweh, Islam Obaidat, Brij B. Gupta
J. Supercomput.3