VLDB 2026 Research / reviewers in the wild / expert
Talal Halabi
dblp:196/3827
· DBLP profile ↗
24ranked-venue papers
9as first author
15since 2021 · last 2026
0000-0002-1922-5803ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 1 first-author · 6 since 2021Security and privacy · 4 · 3 first-author · 2 since 2021Systems, architecture and hardware · 3 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dynamic network management games for optimal adaptive defense decisions against malware propagation in IoT and ad-Hoc networks
Kamal Ziadi, Talal Halabi |
Comput. Networks | 2 |
| 2026 | A Unified Convergence Analysis of Decentralized Federated Learning at the EdgeabstractFederated Learning (FL) reshapes the AI model training paradigm by enabling privacy-preserving collaborative learning, where models are trained across distributed clients without sharing raw data, but only model parameters or updates. This learning can be centralized or distributed. Centralized FL (CFL) may suffer from latency and lack of robustness due to the reliance on a coordinating server for model convergence. On the other hand, Decentralized Federated Learning (DFL) enables direct collaboration among participating devices without relying on a central server. Each device can independently connect to other devices and share model parameters. In such collaborative training paradigm, model convergence in the presence of various deployment topologies, AI model types, Non-IID data distribution, and training strategies demands systematic analysis to realize their practical deployment in critical applications such as intelligent transportation, smart factories, and real-time surveillance. Some works have attempted to conduct only partial analysis and completely neglected incorporating Non-IID data distribution, a critical factor in practical deployment of DFL in mentioned applications. This work conducts a systematic analysis on the convergence of DFL considering a wide range of AI models (e.g., classical, deep neural networks, and Large Language Models), network topologies (e.g., linear, ring, star, and mesh), training strategies (e.g., continuous and aggregate), and degree of Non-IID data distributions. The analysis includes both mathematical formulations and their implementation and evaluation using real-world data. The results confirm that the convergence rate of the models is inversely proportional to the degree of Non-IID data distribution. Moreover, judicial selection of network topologies and training strategies can aid in this convergence process for the practical edge deployment of DFL. Chengyan Jiang, Jiamin Fan, Talal Halabi, Israat Haque 0001 |
IEEE Internet Things J. | 3 |
| 2026 | Toward Stress-Adaptive Cyber Defense: Cognitive-Physiological Synchronization in IoT EnvironmentsabstractSecurity Operations Center (SOC) analysts experience notable performance degradation under elevated cognitive stress, yet existing systems treat stress detection and decision support as separate problems. This paper presents a Cognitive–Physiological Synchronization (CPS) Framework for IoT-based Security Operations Centers (IoT-SOCs) that integrates multimodal physiological stress inference with cognitive decision-making agents to enable real-time, uncertainty-aware action selection in cybersecurity environments. Our framework employs a calibrated DNN-XGBoost ensemble to estimate stress probability from electrocardiogram (ECG), electrodermal activity (EDA), and respiration signals collected via wearable biosensors. The CPS layer converts these physiological beliefs into actionable cognitive utilities through Bayesian log-odds updates, dynamically aligning decision policies with the analyst’s momentary stress state. We further introduce a Utility-Aware Temporal Reasoner (UATR) that smooths sequential evidence over time and a Stress-Weighted Memory (SWM) mechanism that adapts experience recall within the SpeedyIBL cognitive model. Evaluated using leave-one-subject-out cross-validation on the WESAD dataset, the framework achieves 95.8% accuracy (AUC = 0.967) with sub-second latency. In zero-shot SOC simulations using CICIDS2017 tasks, unsupervised calibration enhances decision stability and reduces false escalations relative to rule-based baselines. Results confirm that synchronizing physiological stress inference with cognitive policy selection improves end-to-end action quality under uncertainty, laying a foundation for Internet of Things (IoT)-connected, human-centered adaptive cybersecurity operations across cyber–physical and edge environments. Abbas Yazdinejad, Hadis Karimipour, Talal Halabi |
IEEE Internet Things J. | 3 |
| 2026 | Autonomous and Adaptive Cyber Incident Detection and Response in Industrial Cyber-Physical Systems Using Hierarchical Reinforcement LearningabstractCyber-Physical Systems (CPSs) are the backbone of many critical infrastructures. However, they have introduced an uncharted territory of security vulnerabilities and attack vectors, mainly due to the deeply integrated physical and cyber spaces. Moreover, in industrial CPS settings, network openness exposes the system to the outside world and renders it vulnerable to cyber threats. The security of industrial CPS significantly relies on the cyber incident detection and response systems which are fundamental to ensure the continuous and proper operation of cyber-physical processes. Among the key configuration parameters of these defense systems is the detection threshold. However, finding the optimal threshold that strikes the right balance between missed detection and false-positive rates remains a challenging problem. In this article, we propose a novel approach that leverages a Hierarchical Reinforcement Learning (HRL) architecture to autonomously detect the dynamic instability in an industrial CPS network and respond by adapting the cyber incident detection and response threshold range to minimize the effects of possible incidents. We developed and tested four HRL algorithmic variants, each offering potential avenues for optimization with its own strengths and limitations. Our agents dynamically select these ranges by assessing the expected risk and potential damage over time. In addition, the agent’s selection process aims to minimize false positives and reduce the cost associated with changing the selected range. All four algorithmic adaptations show the effectiveness of HRL for designing adaptive cyber-physical defense compared to static approaches. Our experimental results indicate that our proposed technique is effective for building autonomous cyber incident detection systems in industrial CPS. Ayesha Babar, Talal Halabi, Mohammad Zulkernine |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2024 | Generative Adversarial Networks for Robust Anomaly Detection in Noisy IoT EnvironmentsabstractThe Internet of Things (IoT) enables us to collect and process vast amounts of data in real time. However, the security of IoT devices and networks is highly susceptible to cyber attacks that threaten data integrity and service availability. Furthermore, due to the diverse nature of data collected from numerous nodes in IoT systems and the disturbances occurring within them, detecting anomalous activities and compromised nodes is considerably more challenging than in conventional computer systems. Therefore, it is crucial to develop robust and dependable anomaly detection methods to identify and remove malicious and/or unwanted data, which ensures their exclusion from IoT-powered applications and data analytics. To achieve this, this paper proposes a Generative Adverserial Networks (GAN)-based anomaly detection for IoT systems. The proposed model enables the autoencoder - using the adversarial training of GAN - to learn a better representation of IoT data, making it robust against noisy and changing environments. Based on experiments with real-world IoT datasets, the proposed framework has shown to improve the accuracy of detecting malicious traffic in IoT and surpass state-of-the-art anomaly detection models. Adel Abusitta 0001, Talal Halabi, Ahmed Saleh Bataineh, Mohammad Zulkernine |
ICC | 2 |
| 2024 | Credit-Based Client Selection for Resilient Model Aggregation in Federated LearningabstractFederated Learning (FL) has emerged as a revo-lutionary paradigm in the field of machine learning, enabling multiple participants to collaboratively train models without com-promising the privacy of their individual training data. However, the distributed and decentralized nature of FL also exposes it to a diverse array of poisoning threats, wherein adversaries can inject malicious updates to compromise the integrity and accuracy of the global model. To increase FL robustness against model poisoning attacks, this paper proposes a credit-based defense mechanism, named Credit-Based Client Selection (CBCS), where credit scores are assigned to participating clients based on the accuracy and consistency of their historical model updates. The mechanism selectively incorporates reliable clients with higher credit scores into the model aggregation process, while subjecting low-credit clients to thorough scrutiny or exclusion. Through an extensive series of experiments conducted on non-iid image classification datasets, we rigorously evaluate the performance of the CBCS defense mechanism in normal and adversarial scenarios. The results show that CBCS effectively identifies and excludes adversarial clients, maintaining model accuracy in FL. The proposed approach fortifies the resilience of FL systems in the face of adversarial threats and contributes significantly to the safe and trustworthy deployment of FL across diverse domains. Mohammadreza Khorramfar, Yaser Al Mtawa, Adel Abusitta 0001, Talal Halabi |
ICC | 4 |
| 2024 | A Game-theoretic Approach for DDoS Attack Mitigation in IIoT Deterministic NetworkingabstractDeterministic networking (DetNet) is a promising technology that will help achieve the objectives of Industrial Internet of Things (IIoT) by meeting the latency constraints of various applications including the control of remote robots and autonomous vehicles. Nonetheless, adversaries may see in this paradigm a new opportunity for denial of service (DoS) attacks. IIoT control systems are often vulnerable to attacks and can be infected to create botnets capable of launching distributed DoS attacks that target the latency of deterministic IIoT networks, namely delay attacks. On the other hand, the allocation of limited intrusion detection resources within DetNet infrastructures remains a challenge. Conventional attack detection and mitigation solutions do not take the attack strategies into consideration, neither the DetNet network requirements. In this paper, we leverage game theory to design a defense strategy that can be used by the IIoT infrastructure to optimally allocate its security resources. We define the game utility based on system latency, which is crucial for a DetNet network. The proposed approach will enable the DetNet network to mitigate the impact of attacks and increase its resilience. Our results show that the attack impact is reduced by 54% compared to conventional strategies that do not account for the DetNet latency requirements. Thierry M. Ndimis Ndimis Toko, Martine Bellaïche, Talal Halabi |
NOMS | 3 |
| 2023 | The Ultimate Battle Against Zero-Day Exploits: Toward Fully Autonomous Cyber-Physical DefenseabstractThe last decade has shown that networked cyber-physical systems (NCPS) are the future of critical infrastructure such as transportation systems and energy production. However, they have introduced an uncharted territory of security vulnerabilities and a wider attack surface, mainly due to network openness and the deeply integrated physical and cyber spaces. On the other hand, relying on manual analysis of intrusion detection alarms might be effective in stopping run-of-the-mill automated probes but remain useless against the growing number of targeted, persistent, and often AI-enabled attacks on large-scale NCPS. Hence, there is a pressing need for new research directions to provide advanced protection. This paper introduces a novel security paradigm for emerging NCPS, namely Autonomous Cyber-Physical Defense (ACPD). We lay out the theoretical foundations and describe the methods for building autonomous and stealthy cyber-physical defense agents that are able to dynamically hunt, detect, and respond to intelligent and sophisticated adversaries in real time without human intervention. By leveraging the power of game theory and multi-agent reinforcement learning, these self-learning agents will be able to deploy complex cyber-physical deception scenarios on the fly, generate optimal and adaptive security policies without prior knowledge of potential threats, and defend themselves against adversarial learning. Nonetheless, serious challenges including trustworthiness, scalability, and transfer learning are yet to be addressed for these autonomous agents to become the next-generation tools of cyber-physical defense. Talal Halabi, Mohammad Zulkernine |
SSE | 1 |
| 2023 | Stealthy Rootkits vs Low-Power IoT Devices: A Process-level Colonel Blotto GameabstractKernel-level rootkits are considered stealthy malware versions that can target Internet of Things (IoT) devices as part of large-scale Advanced Persistent Threats. These can gain root privileges and easily hide their attack traces within the system. Several rootkit detection approaches have been proposed, but they lack the consideration of power resource limitation on battery-based edge devices. To address these limitations, this paper models the interaction between stealthy malware and the device’s anomaly detection algorithm as a Colonel Blotto game in order to produce the set of mixed strategies that optimize the allocation of security resources dedicated to monitoring kernel-level processes and detecting abnormal system calls while preserving device power. We present the models for both versions of the game, static and dynamic, to reflect a realistic deployment scenario. The preliminary numerical results show that the strategic resource allocation enabled by the proposed game model achieves better security compared to non-strategic scenarios that do not consider the attacker’s resource budget. Talal Halabi |
TrustCom | 1 |
| 2023 | Resilience-by-design in Adaptive Multi-agent Traffic Control SystemsabstractConnected and Autonomous Vehicles (CAVs) with their evolving data gathering capabilities will play a significant role in road safety and efficiency applications supported by Intelligent Transport Systems (ITSs), such as Traffic Signal Control (TSC) for urban traffic congestion management. However, their involvement will expand the space of security vulnerabilities and create larger threat vectors. In this article, we perform the first detailed security analysis and implementation of a new cyber-physical attack category carried out by the network of CAVs against Adaptive Multi-Agent Traffic Signal Control (AMATSC), namely, coordinated Sybil attacks, where vehicles with forged or fake identities try to alter the data collected by the AMATSC algorithms to sabotage their decisions. Consequently, a novel, game-theoretic mitigation approach at the application layer is proposed to minimize the impact of such sophisticated data corruption attacks. The devised minimax game model enables the AMATSC algorithm to generate optimal decisions under a suspected attack, improving its resilience. Extensive experimentation is performed on a traffic dataset provided by the city of Montréal under real-world intersection settings to evaluate the attack impact. Our results improved time loss on attacked intersections by approximately 48.9%. Substantial benefits can be gained from the mitigation, yielding more robust adaptive control of traffic across networked intersections. Ranwa Al Mallah, Talal Halabi, Bilal Farooq |
ACM Trans. Priv. Secur. | 2 |
| 2022 | Optimized Moving Target Defense Against DDoS Attacks in IoT Networks: When to Adapt?abstractMoving Target Defense (MTD) has proven to be a powerful security concept for threat prevention in critical systems, and has been recently applied to protect IoT networks by attempting to dynamically shift the attack surface over time. IoT devices usually have low computational capabilities making it difficult to implement advanced security features to combat cyber attacks, especially Distributed Denial of Service (DDoS), which has shown to be a serious threat to edge/cloud networks. Hence, the idea of a network-based MTD consisting of strategic movement of IoT network parameters such as IP addresses and port numbers to avoid a static configuration is very appealing as a way to make it difficult for an attacker to infiltrate the network and compromise devices following prolonged reconnaissance. However, designing effective MTD strategies is challenging, especially when maintaining IoT service performance is key. This paper addresses the following question: When is the right time to trigger MTD adaptations in a resource-constrained IoT network vulnerable to DoS attacks? To answer this question, the paper formulates an optimization problem in an MTD-driven IoT system using a game-theoretic model. The problem is then solved to produce the optimal defense strategies against DDoS attacks, allowing the system to make dynamic MTD decisions over time following the analysis of Nash equilibrium points in terms of various network configurations. Arnold Brendan Osei, Swati Rudra Yeginati, Yaser Al Mtawa, Talal Halabi |
GLOBECOM | 4 |
| 2022 | Weaponizing Actions in Multi-Agent Reinforcement Learning: Theoretical and Empirical Study on Security and Robustness
Tongtong Liu 0001, Joe McCalmon, Md Asifur Rahman, Cameron Lischke, Talal Halabi, Sarra Alqahtani |
PRIMA | 5 |
| 2021 | Adaptive Security Risk Mitigation in Edge Computing: Randomized Defense Meets Prospect Theory
Talal Halabi |
SEC | 1 |
| 2021 | Toward Efficient and Robust Deep Learning-based Malware Detection in Fog ComputingabstractMachine learning and deep learning have proven to be very useful for malware detection. Due to their ability of data generalization and the usage of past malware data to detect new malware versions, machine and deep learning techniques have been widely used to secure cloud computing. Nonetheless, malware files might be too large to handle by a simple device with a small RAM, especially when the malware detection system is located on fog computing nodes or at the edge of the network where computational resources are limited compared to the cloud. Therefore, new methods for feature reduction should be used. In this paper, we propose an efficient and robust malware detection system that can be deployed in fog computing. We make use of a technique that takes a snapshot of a file and converts it into an image, and propose a new method for feature reduction by reading only a specific number of bytes for each 1 KB of data and splitting an image into chunks, which separates a large file into fixed-size output images. Such methods reduce the usage of RAM drastically, as only a fixed amount of memory is used at a specific time. Additionally, we propose the addition of Poisson noise to the dataset to improve the accuracy of our model when it needs to detect new variations of malware. Our best model achieves an accuracy of 97.2%. Danila Morozovskii, Krunal Thummar, Talal Halabi, Sheela Ramanna |
ISNCC | 3 |
| 2021 | Protecting the Internet of Vehicles Against Advanced Persistent Threats: A Bayesian Stackelberg GameabstractConnected vehicles are essential for the deployment of intelligent transportation services. However, the high level of connectivity in today's Internet of vehicles (IoV) and the extreme reliance on the data collected from the smart transportation infrastructure widen the space of security vulnerabilities, making the IoV a potential target for cyberattacks. This article investigates novel sophisticated ways to exploit the IoV and launch intelligent attacks on road traffic services by creating persistent impact and reducing detection chances. This article models the processes of attack and defense as a cybersecurity Stackelberg game leading to optimal mixed strategies for both the attackers and the IoV defense system, where the latter optimally deploys the available security resources within the transportation infrastructure to minimize the impact of attacks and improve their detection. The game is of Bayesian type and considers several types of data corruption attacks that occur according to a probability distribution that we determine based on a rigorous risk assessment approach. The results show that our game model and solution allow us to reduce the impact of advanced persistent threats compared to a uniform defense design that is indifferent to attackers' strategies and types. The solution could be integrated into the design of IoV intrusion detection systems to increase their robustness. Talal Halabi, Omar Abdel Wahab 0001, Ranwa Al Mallah, Mohammad Zulkernine |
IEEE Trans. Reliab. | 1 |
| 2020 | Reliability-based Formation of Cloud Federations Using Game TheoryabstractCloud federation is one form of the cloud computing model that supports numerous types of applications through collaboration between different service providers. Cloud federation enables providers to offer more efficient services to customers by sharing their computing and storage resources. However, the reliability of cloud can be degraded if the federation is formed and executed in an unreliable fashion. In this paper, we propose a reliability-based cloud federation model. We evaluate the reliability of different service providers using our evaluation approach and then model the federation process as a hedonic coalition formation game based on a reliability-driven utility function. Our proposed federation formation algorithm enables service providers to cooperate while considering the reliability of the infrastructure and refrain from cooperating with unreliable systems. Our evaluation shows that the providers will be able to form acceptable federations through our algorithm while preserving or enhancing the reliability of their services in a reasonable amount of time. A. B. M. Bodrul Alam, Talal Halabi, Anwar Haque, Mohammad Zulkernine |
GLOBECOM | 2 |
| 2020 | Multi-Objective Interdependent VM Placement Model based on Cloud Reliability EvaluationabstractVirtual Machine (VM) placement is considered as one of the crucial problems in Cloud Computing environments. From the perspective of Cloud Service Providers (CSPs), finding the optimal VM placement strategy is often related to optimal resource utilization, revenue maximization, and energy efficiency. However, to ensure the continuity of customer services, CSPs should also consider the reliability of deployed applications when placing VMs on their infrastructures. Existing research in this area either do not focus on the Cloud reliability evaluation aspect or do not account for the trade-off between reliability and performance in the VM placement process. In this paper, we propose a multi-objective placement model for interdependent VMs in the Cloud that considers both reliability and workload. Reliability in our model is quantitatively evaluated through a set of metrics that we propose. The model involves an Integer Linear Programming problem that aims at maximizing the reliability of the Cloud while minimizing network delay. A multi-objective genetic algorithm is then used to solve the problem heuristically. The proposed model introduces a level of flexibility and its parameters could be adjusted depending on the requirements of the infrastructure and services. The results show that our model achieves high Cloud reliability and allows to effectively control the trade-off between reliability and Quality of Service. A. B. M. Bodrul Alam, Talal Halabi, Anwar Haque, Mohammad Zulkernine |
ICC | 2 |
| 2020 | Optimizing Virtual Machine Migration in Multi-CloudsabstractCloud computing is susceptible to failures. Allocating Virtual machine (VM) in a reliable fashion is considered as one of the crucial problems in Cloud computing environment. Most researchers choose the optimal VM allocation based on resource utilization and cost minimization. However, to protect the reputation of cloud providers, service reliability should be addressed appropriately. In this paper, we propose a Markov-based failure prediction model to anticipate the failure of Cloud servers. Our model anticipates a deteriorating server state based on historical data. Server reliability prediction is then integrated into a VM re-allocation approach in a Multi-Cloud setting to optimize fault tolerance by maximizing Cloud reliability while reducing communication delay. The optimization problem is solved optimally and heuristically using the Artificial Bee Colony (ABC) algorithm. The results show that our model enhances reliability and minimizes communication delay between the VMs following service migration. A. B. M. Bodrul Alam, Talal Halabi, Anwar Haque, Mohammad Zulkernine |
ISNCC | 2 |
| 2020 | A Game-Theoretic Approach for Distributed Attack Mitigation in Intelligent Transportation SystemsabstractIntelligent Transportation Systems (ITS) play a vital role in the development of smart cities. They enable various road safety and efficiency applications such as optimized traffic management, collision avoidance, and pollution control through the collection and evaluation of traffic data from Road Side Units (RSUs) and connected vehicles in real time. However, these systems are highly vulnerable to data corruption attacks which can seriously influence their decision-making abilities. Traditional attack detection schemes do not account for attackers’ sophisticated and evolving strategies and ignore the ITS’s constraints on security resources. In this paper, we devise a security game model that allows the defense mechanism deployed in the ITS to optimize the distribution of available resources for attack detection while considering mixed attack strategies, according to which the attacker targets multiple RSUs in a distributed fashion. In our security game, the utility of the ITS is quantified in terms of detection rate, attack damage, and the relevance of the information transmitted by the RSUs. The proposed approach will enable the ITS to mitigate the impact of attacks and increase its resiliency. The results show that our approach reduces the attack impact by at least 20% compared to the one that fairly allocates security resources to RSUs indifferently to attackers’ strategies. Talal Halabi, Omar Abdel Wahab 0001, Mohammad Zulkernine |
NOMS | 1 |
| 2020 | Towards Security-Based Formation of Cloud Federations: A Game Theoretical ApproachabstractCloud federations allow Cloud Service Providers (CSPs) to deliver more efficient service performance by interconnecting their Cloud environments and sharing their resources. However, the security of the federated service could be compromised if the resources are shared with relatively insecure CSPs, and violations of the Security Service Level Agreement (Security-SLA) might occur. In this paper, we propose a Cloud federation formation model that considers the security level of CSPs. We start by applying the Goal-Question-Metric (GQM) method to develop a set of parameters that quantitatively describes the Security-SLA in the Cloud, and use it to evaluate the security levels of the CSPs and formed federations with respect to a defined Security-SLA baseline, while taking into account CSPs' customers' security satisfaction. Then, we model the Cloud federation formation process as a hedonic coalitional game with a preference relation that is based on the security level and reputation of CSPs. We propose a federation formation algorithm that enables CSPs to join a federation while minimizing their loss in security, and refrain from forming relatively insecure federations. Experimental results show that our model helps maintaining higher levels of security in the formed federations and reducing the rate and severity of Security-SLA violations. Talal Halabi, Martine Bellaïche |
IEEE Trans. Cloud Comput. | 1 |
| 2019 | Trust-Based Cooperative Game Model for Secure Collaboration in the Internet of VehiclesabstractThe Internet of Vehicles (IoV) is an emerging computing paradigm that delivers intelligent transportation services. In an IoV system, the legitimacy, reliability, and accuracy of circulating data have a direct impact on decisions and operations, and eventually, public safety and economy. In this paper, we design a decentralized secure collaboration scheme that protects the vehicles in the IoV environment against the attacks on data integrity. First, the trustworthiness of the vehicles is computed based on their experience acquired from direct interactions using a Bayesian inference model. Then, based on the established trust relationships between the vehicles, we present a vehicular coalition formation approach that incorporates a hedonic cooperative game model, which aims at preventing malicious or faulty vehicles from joining benign vehicular collaborative communities. Simulation results show that the proposed scheme is highly resilient to data alteration and corruption attacks. The scheme also demonstrates to be scalable, and will ultimately allow the IoV entities and platform to derive optimal operative decisions on the fly. Talal Halabi, Mohammad Zulkernine |
ICC | 1 |
| 2019 | A deep learning approach for proactive multi-cloud cooperative intrusion detection system
Adel Abusitta 0001, Martine Bellaïche, Michel R. Dagenais, Talal Halabi |
Future Gener. Comput. Syst. | 4 |
| 2018 | A broker-based framework for standardization and management of Cloud Security-SLAs
Talal Halabi, Martine Bellaïche |
Comput. Secur. | 1 |
| 2017 | Towards quantification and evaluation of security of Cloud Service Providers
Talal Halabi, Martine Bellaïche |
J. Inf. Secur. Appl. | 1 |