VLDB 2026 Research / reviewers in the wild / expert
Farah I. Kandah
dblp:196/3866
· DBLP profile ↗
24ranked-venue papers
8as first author
14since 2021 · last 2026
0000-0002-5729-8536ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 6 first-author · 7 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BAFLE-DCT: Bypassing Adversarial Filters via Frequency-Selective Embedding in the DCT DomainabstractDeep learning-based vision systems are increasingly deployed in high-stakes applications, yet remain vulnerable to imperceptible manipulations that exploit detection limitations in current steganalysis models. We present BAFLE-DCT, a frequency-domain steganography framework that achieves high-capacity, imperceptible data embedding while evading state-of-the-art deep steganalysis detection methods. Unlike traditional spatial-domain methods that alter pixel values and trigger visual or statistical artifacts, BAFLE-DCT operates in the Discrete Cosine Transform (DCT) domain, selectively modifying mid-frequency coefficients in perceptually insignificant regions identified via saliency analysis. A lightweight feedforward network further refines block selection using entropy and DCT variance features to balance embedding capacity and visual fidelity. Stego images generated by BAFLE-DCT consistently bypass advanced steganalysis models including YeNet, SRNet, and Hybrid Deep-Learning Framework, yielding near-random detection rates (~50%) across payload sizes. Importantly, embedded images maintain classification consistency under CLIP, demonstrating semantic preservation. We also release a large-scale, full-color steganographic dataset for frequency-domain research, addressing limitations of grayscale, spatial-domain benchmarks. Our results expose critical vulnerabilities and limitations in visual content authentication pipelines and motivate the development of frequency-aware detection strategies. Thilina Mendis, Farah I. Kandah, Sathyanarayanan N. Aakur |
WACV | 2 |
| 2026 | Knowledge distillation-based Multi-Optimization intrusion detection system
Farah I. Kandah |
Future Gener. Comput. Syst. | 2 |
| 2025 | Unmasking IoT Devices: A Dynamic and Adaptive Classification ApproachabstractThe widespread adoption of IoT devices has transformed automation and connectivity across multiple sectors. These devices depend heavily on wireless communication, providing flexibility and enabling real-time data exchange. The unique traffic patterns they generate, shaped by protocol usage, communication frequency, and data exchange behaviors facilitate precise device identification. These patterns can be leveraged to classify devices based solely on their network activity. Current approaches to IoT device identification rely on single machine-learning classifiers trained on historical traffic data. However, these systems face critical limitations, including an inability to detect new devices, failure to adapt to shifting traffic patterns, and challenges with imbalanced data representation, thus requiring frequent re-training of the classifier. To address these challenges, we propose UMIoT, a dynamic and adaptive Multi-Classifier based framework for device identification. Unlike traditional approaches, UMIoT employs a unique classifier for each device, enhancing identification accuracy and adaptability. Our study evaluates UMIoT's performance and compares with existing device identification approaches using metrics such as accuracy, precision, recall, and F1-score. Our experiments demonstrate that UMIoT achieves 100% accuracy for most devices, with an overall average device identification accuracy of 95.58% across the network. Despite employing multiple classifiers to determine the origin of traffic, UMIoT maintains a low prediction time of 0.2 seconds for 1000 packets, comparable to state-of-theart single-classifier approaches. Additionally, with UMIoT's 60% classifier accuracy threshold, devices entering the network are accurately detected as new devices without misclassifying their traffic as originating from existing devices. Lalith Medury, Luke Robinson, Farah I. Kandah |
ICC | 3 |
| 2025 | Case-Based Reasoning with Diffusion Model for Ransomware Detection
Jarrod Hardy, Farah I. Kandah |
ICCBR | 3 |
| 2025 | A Dynamic GAN-Based Obfuscation Approach Against Profiling AttacksabstractThe rapid growth in the number of wireless IoT devices has introduced new privacy challenges. Adversaries can exploit captured wireless traffic to profile and identify specific devices within the network. While several device identification frameworks have been developed to classify and identify devices, researchers have proposed methods such as traffic padding, shaping, and cover traffic injection to counteract identification attempts. However, these approaches often prove ineffective when adversaries gain access to the network. In this study, we propose a GAN-based traffic generation and injection framework designed to enhance device privacy against traffic analysis attacks, even in the presence of local adversaries. Our approach generates highly realistic network traffic and achieves a 98.5% success rate in seamlessly injecting packets into the network without any observable issues. By reducing the prediction confidence of multiple device identification approaches in predicting the origin of network traffic, our framework effectively enhances the privacy of IoT devices. Furthermore, the proposed solution incurs minimal performance overhead, making it a practical and efficient approach to addressing the growing privacy challenges in wireless networks. Lalith Medury, Luke Robinson, Farah I. Kandah |
LCN | 3 |
| 2025 | Unmasking IoT Devices: A Dynamic and Adaptive Classification ApproachabstractThe proliferation of IoT devices has revolutionized automation and connectivity across various industries. These devices rely extensively on wireless communication, enabling flexibility and real-time data exchange. The unique traffic patterns they produce, shaped by protocol usage, communication frequency, and data exchange behaviors allow for accurate device identification based solely on network activity. Previous research on IoT device identification has shown promise but faces key limitations including scalability, requiring frequent retraining for new devices, and are computationally intensive and unsuitable for real-time use. Reliance on spoofable attributes like IP and MAC addresses, or documentation-based profiling, further reduces reliability. To overcome these limitations, this study introduces UMIoT, an adaptive and dynamic Multi-Classifier framework for IoT device identification. UMIoT is trained on packet-streams, assigns a dedicated classifier to each device, improving accuracy, scalability, and adaptability. Furthermore, UMIoT can efficiently detect the presence of new devices without misclassifying their traffic as belonging to existing devices based on a parameterized confidencethreshold metric. Our experimental results demonstrate that UMIoT achieves high identification accuracy, maintains a low prediction time, enables rapid training for new emerging devices in the network, and operates with minimal storage overhead. Additionally, the results highlight the superiority of the proposed framework against existing device identification approaches both in terms of device identification accuracy and performance metrics including prediction time, storage overhead, and new device training time. The framework is also shown to be resilient against adversarial threats including traffic padding, shaping, and MAC address alteration. Lalith Medury, Luke Robinson, Farah I. Kandah |
IEEE Internet Things J. | 3 |
| 2025 | Clustering-Based Intrusion Detection System Meets Multicritics Generative Adversarial NetworksabstractNetwork security has continuously been a major focus of research and concern on a global scale. The intrusion detection system (IDS), as a crucial defensive measure against network attacks, has undergone multiple iterations and evolutions since its inception to adapt to the ever-changing network environment. Due to the widespread issue of data imbalance in network security datasets, a single machine learning or deep learning model often struggles to effectively handle different types of attacks. In this work, we propose a multicritics generative adversarial networks (GAN) clustering-based IDS (MCGC-IDS) model to address the issue of data imbalance. The quality of the generated data is analyzed using correlation heatmaps and PCA plots, which later is used to update the dataset that is utilized for feature extraction with autoencoders (AEs). Subsequently, CNN-LSTM models are employed to analyze clusters formed by the weighted fuzzy c-means (WFCM) clustering algorithm to achieve enhanced performance for the IDS system. This model is then compared with two existing models. The results indicate that while the GAN-generated data retains the original dataset distribution, it also addresses the issue of imbalance. Moreover, the subsequent multilayered processing enables the overall model to more effectively handle various types of attacks. Finally, when this model is tested on a similar dataset, the UNSW-NB15, it continues to demonstrate superior performance, indicating its strong generalizability. Farah I. Kandah, Thilina Mendis, Lalith Medury |
IEEE Internet Things J. | 2 |
| 2024 | Design and Development of XiveNet: A Hybrid CAN Research TestbedabstractWe have developed an affordable distributed Internet of Things (IoT) testbed, named XiveNet, to conduct in-vehicle security research. This testbed merges the adaptability of simulators with the real-time ECU characteristics of actual vehicles. The testbed is made up of ECU chips found in vehicles, Raspberry Pis, and is combined with a bus master simulator. Our experiments with CAN (controller area network) traffic from actual vehicles (Oak Ridge National Laboratories Road Data Set) demonstrate that our testbed closely replicates the attributes of a real vehicle. We have further authenticated our testbed by deploying SecCAN, a secure CAN algorithm, and evaluating its security by injecting invalid frames. Furthermore, we examined ORNL’s timing-based intrusion detection on our testbed and successfully produced alerts. Additionally, we incorporated Named Data Networking (NDN) capable nodes, providing researchers with an additional resource to develop future in-vehicle security solutions. Finally, we have proposed a bitrate hopping technique focused on preventing the denial of service attack and conducted a preliminary investigation using the testbed. Our evaluation and validation indicate that the testbed provides the real-world vehicle environment with the flexibility of a simulation environment that supports a wide range of hardware and software configurations. William Luke Lambert, Sheikh K. Ghafoor, Haley Burnell, Brennan Huber, Farah I. Kandah, Anthony Skjellum |
ISPDC | 5 |
| 2024 | GoNP: Graph of Network Patterns for Device Identification using UDP Application Layer ProtocolsabstractAnalyzing network traffic and identifying unique IoT devices is important to secure and safeguard the IoT network. Machine Learning models have been leveraged to train classifiers to identify network devices based on the network packets. However, past approaches have often involved either MAC address, IP address, or both when identifying IoT devices in a network. These approaches do not consider the challenge of IP and MAC spoofing when developing their classifier models. This research introduces GoNP, a graph-based approach for extracting network traffic patterns and matching them to a corresponding IoT device. In contrast to previous approaches, our approach does not consider IP and MAC addresses during device identification as these can be easily spoofed. We have designed and developed a graph-based device identification model that achieves IoT device identification accuracy of upto 100%. We have evaluated our approach against past approaches that leveraged machine learning classifiers for device identification, and our model performed consistently better when the IP and MAC addresses of network devices are spoofed. Lalith Medury, Farah I. Kandah |
LCN | 2 |
| 2023 | BEAST: Behavior as a Service for Trust management in IoT devices
Brennan Huber, Farah I. Kandah, Anthony Skjellum |
Future Gener. Comput. Syst. | 2 |
| 2022 | Mitigating Location-based Attacks Using Predication Models in Vehicular Ad-Hoc NetworksabstractThe modern world is constantly in a state of technological revolution. Everyday new technological ideas, inventions, and threats emerge. With modern computer software and hardware advancements, we have the emergence of the Internet of Things (IoT). In conjunction, modern car companies have a push from public demand for a fully-autonomous car. To accomplish autonomy, small, and secure Vehicular Ad-Hoc Networks (VANETs) it is necessary to ensure that the systems that rely on connected vehicle data is reliable and accurate. In the event there is a malicious actor manipulating the data through replica and injection attacks or there is a hardware failure yielding inaccurate location information, it is necessary to explore efficient methods for predicting connected vehicles locations such that these systems, which rely on accurate information are not impacted. This study analyzes multiple clustering and prediction models to discover how effectively a multi-layered machine learning approach is able to meet the real-time requirement of future generation smart cities. Adam Dean, Brennan Huber, Farah I. Kandah |
CCNC | 3 |
| 2022 | Towards feasibility of Deep-Learning based Intrusion Detection System for IoT Embedded DevicesabstractIn this work we seek to determine the feasibility of implementing deep learning-based intrusion detection on higher-capacity embedded devices, by evaluating the performance metrics of pre-trained models on devices of varying resource capacity. Four deep learning models, trained on separate well-known intrusion detection dataset, will be deployed on each device. With an initial evaluation of neural network architecture, activation functions, and accuracy and later comparisons will include precision, f1 score, recall, and prediction rate, or time to predict per sample. Additionally, separate datasets will be used to observe model responses to new attack patterns. Jonathan Hunter, Brennan Huber, Farah I. Kandah |
CCNC | 3 |
| 2022 | An Analysis of Signal Energy Impacts and Threats to Deep Learning Based SEIabstractSpecific Emitter Identification (SEI) was conceived to detect, characterize, and identify radars using their transmitted signals. SEI’s success is linked to the imperfections of an emitter’s Radio Frequency (RF) front-end, which imparts unique "coloration" to the signal during its formation and transmission without impeding normal transceiver operations. Recent works propose Deep Learning (DL) based SEI due to its demonstrated successes in image and facial recognition, as well as its ability to learn radio-specific features directly from the sampled signals. This removes the needless, handcrafted feature engineering of traditional SEI. However, signal energy, its impacts, and its susceptibility to adversary mimicry has received little attention by DL-based SEI works. This work is the first to investigate the impacts and threats posed to DL-based SEI by the presence, lack, or manipulation of signal energy. Our work shows that Long Short-Term Memory (LSTM)-based SEI provides the highest average percent correct classification performance of 89.9% and the lowest rate, 0.68%, at which an adversary can circumvent the SEI process by manipulating the energy of its signals. Joshua H. Tyler, Mohamed K. M. Fadul, Donald R. Reising, Farah I. Kandah |
ICC | 4 |
| 2021 | Radio Identity Verification-Based IoT Security Using RF-DNA Fingerprints and SVMabstractIt is estimated that the number of Internet-of-Things (IoT) devices will reach 75 billion in the next five years. Most of those currently and soon-to-be deployed devices lack sufficient security to protect themselves and their networks from attacks by malicious IoT devices masquerading as authorized devices in order to circumvent digital authentication approaches. This work presents a physical (PHY) layer IoT authentication approach capable of addressing this critical security need through the use of feature-reduced, radio frequency-distinct native attributes (RF-DNA) fingerprints and support vector machines (SVM). This work successfully demonstrates: 1) authorized identity (ID) verification across three trials of six randomly chosen radios at signal-to-noise ratios greater than or equal to 6 dB and 2) rejection of all rogue radio ID spoofing attacks at signal-to-noise ratios greater than or equal to 3 dB using RF-DNA fingerprints whose features are selected using the Relief-F algorithm. Donald R. Reising, Joseph Cancelleri, T. Daniel Loveless, Farah I. Kandah, Anthony Skjellum |
IEEE Internet Things J. | 4 |
| 2020 | Towards trusted and energy-efficient data collection in unattended wireless sensor networks
Farah I. Kandah, Jesse Whitehead, Peyton Ball |
Wirel. Networks | 1 |
| 2015 | Energy-aware Multipath Provisioning in wireless mesh networksabstractMultipath routing has been extensively employed in wireless mesh networks (WMNs) to provide network reliability and survivability, thereby, improving energy consumptions. To support the network survivability, we need to protect users' requests against network failure such as link or node failure. For each request, a primary path is set up for normal transmission, and an alternate path (protection path) should also be provided to protect the request in case of network failure. In this paper, we study the network survivability through the use of multipath scheme to handle dynamic network traffic, where users' requests have random arrival times. Compared to previous work, our scheme considers each link's bandwidth, reusability, and the energy consumption factors when providing multiple paths for each request, to support the network survivability under multiple failure. By applying our scheme, the numerical results show that we can improve the network survivability in handling multiple failures. Farah I. Kandah, Jesse Whitehead |
CCNC | 1 |
| 2013 | Mitigating Misleading Routing Attack using path signature in Mobile Ad-Hoc NetworksabstractThe growth of laptops, personal digital assistant (PDA) and 802.11/Wi-Fi wireless networking made mobile ad-hoc network (MANET) a popular research topic recently. However, the flexible deployment nature and the lack of fixed infrastructure make MANETs suffer from a variety of security attacks. We, in this paper, discuss the Misleading Routing Attack (MIRA) in Mobile Ad-hoc Networks and propose a mitigation scheme using a dynamic one-way hash chain to form a path signature to sign the path, thus allowing the nodes on the path to detect any unexpected changes occur in the path. Our simulation results show that by applying our path signature mitigation scheme, we can improve the network performance under MIRA attack in terms of packets transmission/retransmission in the network. Farah I. Kandah, Yashaswi Singh, Weiyi Zhang 0001, Yulu Ma |
GLOBECOM | 1 |
| 2013 | Mitigating colluding injected attack using monitoring verification in mobile ad-hoc networksabstractABSTRACT Mobile ad‐hoc networks (MANETs) have attracted significant research attention recently because of the fast growth of laptops, personal digital assistant, and 802.11/Wi‐Fi wireless networking. However, the flexible deployment nature and the lack of fixed infrastructure make MANETs suffer from a variety of security attacks. In this paper, we show how an adversary can utilize a colluding injected attack (CIA) in MANET by injecting malicious nodes in the network, while hiding their identities from other legitimate nodes. These injected nodeswill work together(colluding) to create a collision at an arbitrary node, thus preventing it from receiving or relaying any packet. Because of this collision, a legitimate node could be reported as malicious nodes by monitoring nodes in the neighborhood. In this work, we propose a monitoring verification scheme to mitigate the effect of the CIA attack. Our proposed scheme is able to accurately detect malicious nodes in the network compared with previous detection schemes. Through simulations, we show that our proposed scheme outperforms previous detection schemes in terms of true/false detection of any malicious behavior in the network caused by the CIA attack. Copyright © 2013 John Wiley & Sons, Ltd. Farah I. Kandah, Yashaswi Singh, Weiyi Zhang 0001, Chonggang Wang |
Secur. Commun. Networks | 1 |
| 2012 | Diverse Path Routing with Interference and Reusability Consideration in Wireless Mesh Networks
Farah I. Kandah, Weiyi Zhang 0001, Chonggang Wang, Juan Li 0004 |
Mob. Networks Appl. | 1 |
| 2012 | Self-protecting networking using dynamic p-cycle construction within link capacity constraintabstractABSTRACT The p‐cycle design problem has been extensively studied because it can provide both ring‐like fast self‐protection speed and spare capacity efficiency of path protection scheme. However, p‐cycle provisioning for dynamic traffic has not been fully addressed. Most related works have not considered link capacity in the construction of p‐cycles, which may cause problems in practice because the protection paths may not have enough backup bandwidth. In this paper, with the consideration of link capacity, we present a sufficient and necessary condition that guarantees p‐cycles for providing enough protection bandwidth. Based on this condition, we propose an effective solution to provide connections for dynamic requests with the property that each link used for a connection is protected by a p‐cycle. Simulation results show that our dynamic p‐cycle provisioning solution outperforms the traditional path protection scheme. Copyright © 2011 John Wiley & Sons, Ltd. Weiyi Zhang 0001, Farah I. Kandah, Xiaojiang Du, Chonggang Wang |
Secur. Commun. Networks | 2 |
| 2011 | MIRA: Misleading Routing Attack in Mobile Ad-Hoc NetworksabstractThe growth of laptops, personal digital assistant (PDA) and 802.11/Wi-Fi wireless networking have made mobile ad-hoc network (MANET) a popular research topic recently. Due to the flexible deployment nature and the lack of fixed infrastructure, MANETs suffer from varieties of security attacks. In this paper, we propose the misleading routing attack (MIRA), which is different from the well known gray/black hole attacks, in which a node is relaying the coming packets and not dropping them. MIRA attack aims to delay the packet as much as possible so as to let the source node time out before it receives the acknowledgment. Also it aims to overload the network by increasing the number of unexpected routing packets generated in the network. Our simulation results show that the existence of an adversary in the network launching a misleading routing attack will degrade packet transmissions in the network and increasing the number of lost packets as well as the retransmissions at the sender. Farah I. Kandah, Yashaswi Singh, Weiyi Zhang 0001 |
GLOBECOM | 1 |
| 2011 | A Secure Key Management Scheme in Wireless Mesh NetworksabstractWireless mesh network (WMN) is a rapid deployed, self organized and multi-hop wireless network. The wireless and distributed natures of WMNs make them subject to various kinds of attacks, which raise a great challenge in securing these networks. Most existing security mechanisms are based on cryptographic keys where a high degree key management services are in demand. In this paper, we present an effective key management scheme which seeks an encryption key assignment such that the induced network is connected and well protected against potential eavesdropping attacks. Compared with previous work, our scheme assigns the available encryption keys among all the nodes in the network. The simulation results show that our scheme out performs previous schemes through providing a network that is resistant against malicious eavesdropping attack. Farah I. Kandah, Weiyi Zhang 0001, Xiaojiang Du, Yashaswi Singh |
ICC | 1 |
| 2010 | Interference-Aware Robust Topology Design in Multi-Channel Wireless Mesh NetworksabstractThe performance of wireless networks can be significantly improved by multi-channel communications compared with single-channel communications since the use of multiple channels can reduce interference influence. In this paper, we study interference-aware topology control in IEEE 802.11-based multichannel wireless mesh networks with dynamic traffic. Channel assignment is one of the most basic and important issues in such networks. Different channel assignments can lead to different network topologies. Based on a novel definition of co-channel interference, we formally define and present an effective heuristic for the minimum interference robust topology design problem which seeks a channel assignment for the given network such that the induced network topology is 2-connected and has minimum network interference. Weiyi Zhang 0001, Farah I. Kandah, Jian Tang 0008, Kendall E. Nygard |
CCNC | 2 |
| 2010 | Interference-Aware Robust Wireless Mesh Network DesignabstractInterference has been proven to have an effect on the performance in wireless mesh networks (WMN). Using multichannels can improve the performance of WMNs by reducing interference influence. In this paper, we study how to design a robust WMN for a set of mesh nodes, each with Q Networking Interface Cards (NICs) and pre-defined connection requests. Our scheme aims to construct an interference-aware network topology for the nodes, then set up a pair of link-disjoint paths for each request with fault- tolerant capability. We propose two novel schemes to improve the network design. First, we embrace the network interference for providing resource- efficient protections. Second, protection links are shared and reused by multiple connections for protection, which further improves the efficiency of network resource usage. Our simulation results show that our scheme outperformed previous schemes. Farah I. Kandah, Weiyi Zhang 0001, Yashaswi Singh, Juan Li 0004 |
GLOBECOM | 1 |