Chuadhry Mujeeb Ahmed

dblp:198/6818 · DBLP profile ↗
← Back
20ranked-venue papers
7as first author
13since 2021 · last 2025
0000-0003-3644-0465ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 7 first-author · 5 since 2021Computer networks · 4 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Privacy Preservation Strategies for Malware-Infected Edge Intelligence Systems: A Bayesian Stochastic Game-Based Approach
abstract
Malware in the Internet of Things (IoT) is prone to contaminating various IoT end-points through network communication and information transfer, leading to surreptitious privacy leakage and data theft. The existing privacy-preserving approaches including data masking, anonymization, and differential privacy always lack the consideration of strategic interactions among rational agents. Inspired by Bayesian games, we model incomplete stochastic games between IoT end-points and edge nodes in edge intelligence (EI)-enabled IoT systems to conduct probability analysis for predicting and defending privacy leakage caused by malware infection. It is notable that the posterior probability is defined based on the Bayes’ rule to reflect the statistical inference of incomplete privacy leakage information. Such a method can intrinsically characterize the actual situations of IoT end-points. Further, we propose a novel privacy preservation optimization approach named Bayesian advantage actor critic (BA2C) for the practical implementation of optimization decision in EI-enabled IoT privacy-preserving systems. Eventually, we conduct experimental simulations to understand the most effective parameters in decision-making among the successful detection rate, successful infection rate, and false alarm rate. We also compare traditional algorithms and validate the efficacy of the proposed approach.
Yizhou Shen, Carlton Shepherd, Chuadhry Mujeeb Ahmed, Shigen Shen, Shui Yu 0001
IEEE Trans. Mob. Comput.3
2025 Integrating Deep Spiking Q-Network Into Hypergame-Theoretic Deceptive Defense for Mitigating Malware Propagation in Edge Intelligence-Enabled IoT Systems
abstract
Internet of Things (IoT) systems are susceptible to compromise due to malware propagation, leading to the data breach and information theft. In this paper, we propose a proactive deception-oriented hypergame-theoretic malware propagation-mitigation (DHMPM) model between IoT nodes and edge devices under asymmetric information in edge intelligence (EI)-enabled IoT systems. We then explore malware-propagated deceptive defense strategies based on deep reinforcement learning. Specifically, IoT nodes and edge devices continually adjust their strategies based on obtained utilities under beliefs perceived by uncertainties from the game environment and system dynamics. Built upon the proposed game DHMPM, we next apply spiking neural networks (SNNs) into deep Q-network to form hypergame-theoretic deep spiking Q-network (HGDSQN), practically converging to the optimal malware-propagated deceptive defense strategy in EI-enabled IoT systems. Such SNNs can simulate biological brains with the pulse communication mechanism and break through the bottleneck of temporal processing in traditional models with deep neural networks, realizing intelligent decision-making and real-time malware defense. We eventually perform experimental simulations that assess the effect of attack arrival probability and learning rate on the optimal learning strategy selection, demonstrating the effectiveness of the proposed HGDSQN algorithm.
Yizhou Shen, Carlton Shepherd, Chuadhry Mujeeb Ahmed, Shigen Shen, Shui Yu 0001
IEEE Trans. Serv. Comput.3
2024 Game-theoretic analytics for privacy preservation in Internet of Things networks: A survey
Yizhou Shen, Carlton Shepherd, Chuadhry Mujeeb Ahmed, Shigen Shen, Wenlong Ke, Shui Yu 0001
Eng. Appl. Artif. Intell.3
2024 Comparative DQN-Improved Algorithms for Stochastic Games-Based Automated Edge Intelligence-Enabled IoT Malware Spread-Suppression Strategies
abstract
Massive volumes of malware spread incidents continue to occur frequently across the Internet of Things (IoT). Owing to its self-learning and adaptive capability, artificial intelligence (AI) can provide assistance for automatically converging to an optimal strategy. By merging AI into edge computing, we consider an edge intelligence-enabled IoT (EIIoT) environment and provide a stochastic learning strategy for suppressing the spread of IoT malware. In particular, we introduce stochastic game theory to symbolise the whole process of the confrontation between IoT malware and edge nodes. Built upon the theoretical framework to demonstrate the specific spread-suppression architecture, we apply the improved Deep Q-Network algorithms including DDQMS, D2QMS and D3QMS that can deduce the optimal EIIoT malware spread-suppression strategy with better performance. Through experiments, we investigate the influence of related parameters on learning strategy selection, recommending the optimal parameters setting of automated EIIoT malware spread-suppression. We also compare the performance of the proposed three DQN-improved algorithms.
Yizhou Shen, Carlton Shepherd, Chuadhry Mujeeb Ahmed, Shui Yu 0001, Tingting Li 0001
IEEE Internet Things J.3
2024 SGD3QN: Joint Stochastic Games and Dueling Double Deep Q-Networks for Defending Malware Propagation in Edge Intelligence-Enabled Internet of Things
abstract
Malware propagation in IoT (Internet of Things) systems can lead to data leakages, financial losses, and other serious consequences. To solve this issue, we propose a new active IoT malware propagation defence work. Specifically, aided by stochastic games, we express the process of cyber conflicts between IoT system nodes and edge devices considering malware propagation in edge intelligence-enabled IoT. Here, IoT system nodes and edge devices choose their own strategies and receive the corresponding rewards determined by the current state and strategy. After that, the game randomly moves to the next stage according to the distribution of probabilities and the participants’ strategies until reaching the fixed Nash equilibrium point. Following a theoretical analysis, we design and implement SGD3QN (Stochastic Games and Dueling Double Deep Q-networks)—a novel algorithm to receive the optimal strategy for mitigating IoT malware propagataion in practice. Here, the Dueling Double Deep Q-networks are acted as an end-to-end decision control system, in which IoT malware propagataion environment is used as the input to obtain the failure or success experience to update the network parameters, followed by making the optimal decision output. Afterwards, we perform experimental simulations that probe the influence of batch size and replay memory size on the optimal IoT malware propagation defense strategy selection and prove the ascendancy of the proposed SGD3QN-aided decision-making algorithm.
Yizhou Shen, Carlton Shepherd, Chuadhry Mujeeb Ahmed, Shigen Shen, Shui Yu 0001
IEEE Trans. Inf. Forensics Secur.3
2022 Energy Level Spoofing Attacks and Countermeasures in Blockchain-enabled IoT
abstract
The Internet of Things (IoT) ecosystem is witnessing widespread deployments for emerging applications in diverse domains such as remote sensing, smart homes, and industry 4.0. There is also a growing need to secure such deployments against malicious IoT devices to sustain normal network operations. Since the IoT deployments encompass geographically distributed nodes, blockchain technology, which inherently offers distributed trust in such scenarios, is gaining popularity in providing a secure and trusted IoT deployment. In this paper, we present a use case in which an IoT deployment is retrofitted with a blockchain. The use of blockchain prevents malicious nodes from falsifying information about their energy levels. We first present attack scenarios where IoT nodes can spoof energy while joining or being a part of the network. We then build a defense strategy and evaluate its performance under various attack scenarios. Our results indicate that the IoT deployment is robust under the proposed defense strategy which can detect if a node is spoofing its energy levels over 75% of the time.
Ali Hussain Khan, Humza Ikram, Chuadhry Mujeeb Ahmed, Naveed Ul Hassan, Zartash Afzal Uzmi
GLOBECOM3
2022 Proof-of-Communication-Capability Based Authentication in Blockchain-enabled Wireless Autonomous Vehicular Networks
abstract
Blockchain technology is finding applications in wireless networks, in particular vehicular networks, for the purposes of establishing trust. A certain set of network resources in terms of communication and computation requirements is also necessary for successful blockchain deployment. Moreover, heterogeneity in wireless networks and changing radio conditions at the physical layer, make it even more challenging to guarantee steady block generation latency. In this work, we study the possible denial of blockchain service attacks where malicious nodes threaten to slow down the block generation latency. We propose a novel Proof-of-Communication-Capability (PoCC) authentication framework that acts as a defense against communication capability spoofing over wireless networks. Our PoCC authentication framework utilizes physical properties such as distance between nodes, channel state information (CSI), and communication puzzle latency to establish the communication capabilities of nodes in the wireless network. Results from a simulated AV network under three different variations of the proposed PoCC framework are encouraging and demonstrate that such attacks can be effectively mitigated.
Ali Hussain Khan, Chuadhry Mujeeb Ahmed, Naveed Ul Hassan, Zartash Afzal Uzmi
VTC Spring2
2022 Can You Still See Me?: Identifying Robot Operations Over End-to-End Encrypted Channels
abstract
Connected robots play a key role in automating industrial workflows. Robots can expose sensitive operational information to remote adversaries. Despite the use of end-to-end encryption, a passive adversary could fingerprint and reconstruct the entire workflows being carried out and developing a detailed understanding of how facilities operate. In this paper, we investigate whether a remote passive attacker can accurately fingerprint robot movements and reconstruct operational workflows. Using a neural network-based traffic analysis approach, we found that attackers can predict TLS-encrypted robot movements with around \textasciitilde60% accuracy, increasing to near perfect accuracy in realistic settings. Ultimately, simply adopting best cybersecurity practices is not enough to stop even weak (passive) adversaries.
Ryan Shah, Chuadhry Mujeeb Ahmed, Shishir Nagaraja
WISEC2
2022 An Advanced Boundary Protection Control for the Smart Water Network Using Semisupervised and Deep Learning Approaches
abstract
Critical infrastructures across many industries, such as smart water treatment and distribution networks (SWTDNs) and power generation and public transport networks, depend on the supervisory control and data acquisition (SCADA) system. However, being the core component of the critical infrastructures, it has made the SCADA-based SWTDN system an attractive target for cyberattacks. A successful attack on the SCADA will have a devastating impact on an SWTDN in terms of proper operations; therefore, safeguarding the SCADA from cyberattacks is of paramount. With the increasing cyberattacks on SWTDN, both in number and sophistication, the need to detect these attacks early has become a subject of great interest among practitioners and researchers. To this end, we propose a novel strategy, based on a semisupervised approach. Two semisupervised approaches, including unsupervised learning and deep learning-based approaches, have been proposed. The proposed approaches can involve learning dynamic cyberattack patterns from unlabeled data in an SWTDN. We validate the proposed semisupervised approach experimentally using an operational water treatment plant testbed. The proposed approach achieved almost 100% accuracy and substantially outperforms the existing baseline approaches used in this article. The outcome of the experiment is encouraging and demonstrates the potential use of the semisupervised approach for security control in smart water distribution.
Shaila Sharmeen, Md. Shamsul Huda, Jemal H. Abawajy, Chuadhry Mujeeb Ahmed, Mohammad Mehedi Hassan, Giancarlo Fortino
IEEE Internet Things J.4
2021 Scanning the Cycle: Timing-based Authentication on PLCs
abstract
Programmable Logic Controllers (PLCs) are a core component of an Industrial Control System (ICS). However, if a PLC is compromised or the commands sent across a network from the PLCs are spoofed, consequences could be catastrophic. In this work, a novel technique to authenticate PLCs is proposed that aims at raising the bar against powerful attackers while being compatible with real-time systems. The proposed technique captures timing information for each controller in a non-invasive manner. It is argued that Scan Cycle is a unique feature of a PLC that can be approximated passively by observing network traffic. An attacker that spoofs commands issued by the PLCs would deviate from such fingerprints. To detect replay attacks a PLC Watermarking technique is proposed. PLC Watermarking models the relation between the scan cycle and the control logic by modeling the input/output as a function of request/response messages of a PLC. The proposed technique is validated on an operational water treatment plant (SWaT) and smart grid (EPIC) testbeds. Results from experiments indicate that PLCs can be distinguished based on their scan cycle timing characteristics.
Chuadhry Mujeeb Ahmed, Martín Ochoa, Jianying Zhou 0001, Aditya P. Mathur
AsiaCCS1
2021 Bank of Models: Sensor Attack Detection and Isolation in Industrial Control Systems
Chuadhry Mujeeb Ahmed, Jianying Zhou 0001
CRITIS1
2021 Machine learning for intrusion detection in industrial control systems: challenges and lessons from experimental evaluation
abstract
Abstract Gradual increase in the number of successful attacks against Industrial Control Systems (ICS) has led to an urgent need to create defense mechanisms for accurate and timely detection of the resulting process anomalies. Towards this end, a class of anomaly detectors, created using data-centric approaches, are gaining attention. Using machine learning algorithms such approaches can automatically learn the process dynamics and control strategies deployed in an ICS. The use of these approaches leads to relatively easier and faster creation of anomaly detectors compared to the use of design-centric approaches that are based on plant physics and design. Despite the advantages, there exist significant challenges and implementation issues in the creation and deployment of detectors generated using machine learning for city-scale plants. In this work, we enumerate and discuss such challenges. Also presented is a series of lessons learned in our attempt to meet these challenges in an operational plant.
M. R. Gauthama Raman, Chuadhry Mujeeb Ahmed, Aditya P. Mathur
Cybersecur.2
2021 Can Replay Attacks Designed to Steal Water from Water Distribution Systems Remain Undetected?
abstract
Industrial Control Systems (ICS) monitor and control physical processes. ICS are found in, among others, critical infrastructures such as water treatment plants, water distribution systems, and the electric power grid. While the existence of cyber-components in an ICS leads to ease of operations and maintenance, it renders the system under control vulnerable to cyber and physical attacks. An experimental study was conducted withreplay attackslaunched on an operational water distribution (WADI) plant to understand under what conditions an attacker/attack can remain undetected while stealing water. A detection method, based on an input-output Linear Time-invariant system model of the physical process, was developed and implemented in WADI to detect such attacks. The experiments reveal the strengths and limitations of the detection method and challenges faced by an attacker while attempting to steal water from a water distribution system.
Venkata Reddy Palleti, Vishrut Kumar Mishra, Chuadhry Mujeeb Ahmed, Aditya P. Mathur
ACM Trans. Cyber Phys. Syst.3
2020 A Tale of Two Testbeds: A Comparative Study of Attack Detection Techniques in CPS
Surabhi Athalye, Chuadhry Mujeeb Ahmed, Jianying Zhou 0001
CRITIS2
2020 Process skew: fingerprinting the process for anomaly detection in industrial control systems
abstract
In an Industrial Control System (ICS), its complex network of sensors, actuators and controllers have raised security concerns. In this paper, we proposed a technique called Process Skew that uses the small deviations in the ICS process (herein called as a process fingerprint) for anomaly detection. The process fingerprint appears as noise in sensor measurements due to the process fluctuations. Such a fingerprint is unique to a process due to the intrinsic operational constraints of the physical process. We validated the proposed scheme using the data from a real-world water treatment testbed. Our results show that we can effectively identify a process based on its fingerprint, and detect process anomaly with a very low false-positive rate.
Chuadhry Mujeeb Ahmed, Jay Prakash, Rizwan Qadeer, Anand Agrawal, Jianying Zhou 0001
WISEC1
2020 NoiSense Print: Detecting Data Integrity Attacks on Sensor Measurements Using Hardware-based Fingerprints
abstract
Fingerprinting of various physical and logical devices has been proposed for uniquely identifying users or devices of mainstream IT systems such as PCs, laptops, and smart phones. However, the application of such techniques in Industrial Control Systems (ICS) is less explored for reasons such as a lack of direct access to such systems and the cost of faithfully reproducing realistic threat scenarios. This work addresses the feasibility of using fingerprinting techniques in the context of realistic ICS related to water treatment and distribution systems. A model-free sensor fingerprinting scheme ( NoiSense ) and a model-based sensor fingerprinting scheme ( NoisePrint ) are proposed. Using extensive experimentation with sensors, it is shown that noise patterns due to microscopic imperfections in hardware manufacturing can uniquely identify sensors with accuracy as high as 97%. The proposed technique can be used to detect physical attacks, such as the replacement of legitimate sensors by faulty or manipulated sensors. For NoisePrint , a combined fingerprint for sensor and process noise is created. The difference (called residual), between expected and observed values, i.e., noise, is used to derive a model of the system. It was found that in steady state the residual vector is a function of process and sensor noise. Data from experiments reveals that a multitude of sensors can be uniquely identified with a minimum accuracy of 90% based on NoisePrint . Also proposed is a novel challenge-response protocol that exposes more powerful cyber-attacks, including replay attacks.
Chuadhry Mujeeb Ahmed, Aditya P. Mathur, Martín Ochoa
ACM Trans. Priv. Secur.1
2018 Noise Matters: Using Sensor and Process Noise Fingerprint to Detect Stealthy Cyber Attacks and Authenticate sensors in CPS
abstract
A novel scheme is proposed to authenticate sensors and detect data integrity attacks in a Cyber Physical System (CPS). The proposed technique uses the hardware characteristics of a sensor and physics of a process to create unique patterns (herein termed as fingerprints) for each sensor. The sensor fingerprint is a function of sensor and process noise embedded in sensor measurements. Uniqueness in the noise appears due to manufacturing imperfections of a sensor and due to unique features of a physical process. To create a sensor's fingerprint a system-model based approach is used. A noise-based fingerprint is created during the normal operation of the system. It is shown that under data injection attacks on sensors, noise pattern deviations from the fingerprinted pattern enable the proposed scheme to detect attacks. Experiments are performed on a dataset from a real-world water treatment (SWaT) facility. A class of stealthy attacks is designed against the proposed scheme and extensive security analysis is carried out. Results show that a range of sensors can be uniquely identified with an accuracy as high as 98%. Extensive sensor identification experiments are carried out on a set of sensors in SWaT testbed. The proposed scheme is tested on a variety of attack scenarios from the reference literature which are detected with high accuracy
Chuadhry Mujeeb Ahmed, Jianying Zhou 0001, Aditya P. Mathur
ACSAC1
2018 Poster: Physics-Based Attack Detection for an Insider Threat Model in a Cyber-Physical System
abstract
To ensure the proper functioning of critical systems, it is important to design secure Cyber Physical Systems (CPS). Since CPS are connected systems, most studies consider external adversaries as a threat model, which might not be able to cater for an insider threat with the physical access to the system. In this article, we proposed an attack detection mechanism for an insider who has physical access to a CPS. The proposed method exploits the dynamics of the system and detects an attack based on the laws of Physics. Based on the mass flow equations, we analyze the rate of change in the plant's process and create a feature vector based on the process dynamics. The model has been trained by passing rate of change in system's state as input to Support Vector Machine (SVM), to detect the abnormal behavior in the system. Based on the proposed framework, experiments are performed on a real water treatment testbed, to validate our model and to measure the efficiency of the plant in normal and under attack scenarios. The detection result shows that proposed scheme can detect attacks with accuracy as high as $96%$.
Anand Agrawal, Chuadhry Mujeeb Ahmed, Ee-Chien Chang
AsiaCCS2
2018 NoisePrint: Attack Detection Using Sensor and Process Noise Fingerprint in Cyber Physical Systems
abstract
An attack detection scheme is proposed to detect data integrity attacks on sensors in Cyber-Physical Systems (CPSs). A combined fingerprint for sensor and process noise is created during the normal operation of the system. Under sensor spoofing attack, noise pattern deviates from the fingerprinted pattern enabling the proposed scheme to detect attacks. To extract the noise (difference between expected and observed value) a representative model of the system is derived. A Kalman filter is used for the purpose of state estimation. By subtracting the state estimates from the real system states, a residual vector is obtained. It is shown that in steady state the residual vector is a function of process and sensor noise. A set of time domain and frequency domain features is extracted from the residual vector. Feature set is provided to a machine learning algorithm to identify the sensor and process. Experiments are performed on two testbeds, a real-world water treatment (SWaT) facility and a water distribution (WADI) testbed. A class of zero-alarm attacks, designed for statistical detectors on SWaT are detected by the proposed scheme. It is shown that a multitude of sensors can be uniquely identified with accuracy higher than 90% based on the noise fingerprint.
Chuadhry Mujeeb Ahmed, Martín Ochoa, Jianying Zhou 0001, Aditya P. Mathur, Rizwan Qadeer, Carlos Murguia, Justin Ruths
AsiaCCS1
2017 Model-based Attack Detection Scheme for Smart Water Distribution Networks
abstract
In this manuscript, we present a detailed case study about model-based attack detection procedures for Cyber-Physical Systems (CPSs). In particular, using EPANET (a simulation tool for water distribution systems), we simulate a Water Distribution Network (WDN). Using this data and sub-space identification techniques, an input-output Linear Time Invariant (LTI) model for the network is obtained. This model is used to derive a Kalman filter to estimate the evolution of the system dynamics. Then, residual variables are constructed by subtracting data coming from EPANET and the estimates of the Kalman filter. We use these residuals and the Bad-Data and the dynamic Cumulative Sum (CUSUM) change detection procedures for attack detection. Simulation results are presented - considering false data injection and zero-alarm attacks on sensor readings, and attacks on control input - to evaluate the performance of our model-based attack detection schemes. Finally, we derive upper bounds on the estimator-state deviation that zero-alarm attacks can induce.
Chuadhry Mujeeb Ahmed, Carlos Murguia, Justin Ruths
AsiaCCS1