Charith Elvitigala

dblp:205/7762 · also Charitha Elvitigala · DBLP profile ↗
← Back
13ranked-venue papers
2as first author
10since 2021 · last 2026
0000-0002-5923-4341ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 2 first-author · 5 since 2021Security and privacy · 5 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 SSFU: Selective Semantic Feature Unlearning for Federated Learning in 6G Internet of Things Systems
abstract
In next-generation 6G Internet-of-Things (IoT) networks, semantic communication has emerged as a key paradigm that transforms raw data into high-level feature representations, thereby reducing communication overhead while enhancing interpretability. When combined with federated learning (FL), these semantic embeddings enable decentralized model training without centralizing raw data, preserving user privacy, and supporting large-scale collaboration. However, semantic features may inadvertently encode sensitive information or act as adversarial triggers, introducing new privacy risks that current unlearning techniques fail to address. To overcome this challenge, we propose Selective Semantic Feature Unlearning (SSFU), a novel framework that performs unlearning at the feature level rather than at the client level. SSFU employs an ensemble-based risk scoring mechanism to identify high-risk latent components, followed by gradient ascent and semantic masking to remove their influence. Unlike existing methods that depend on costly retraining or full client exclusion, SSFU preserves benign semantic knowledge and allows training to continue with minimal disruption. The framework guarantees bounded convergence, and empirical results on benchmark datasets show that SSFU effectively eliminates sensitive features while maintaining predictive accuracy. SSFU thus represents a robust, privacy-preserving FL framework tailored for semantic communication in 6G IoT systems.
Wathsara Daluwatta, Ibrahim Khalil 0001, Shehan Edirimannage, Charith Elvitigala, Jer Shyuan Ng, Dusit Niyato
IEEE Internet Things J.4
2026 Intent-Driven Dual-Layer Model Pruning for Energy-Efficient Hierarchical Federated Learning in IoT With Non-IID Data
abstract
The proliferation of Internet of Things (IoT) devices has intensified the need for scalable and energy-efficient federated learning (FL). While Hierarchical Federated Learning (HFL) improves scalability by adding an edge aggregation tier, it still suffers from high communication costs, slow convergence, and degraded accuracy under non-IID data. Existing methods such as quantization, sparsification, and static pruning alleviate specific bottlenecks but fail to jointly optimize efficiency, robustness, and accuracy. This paper proposes an intent-driven dual-layer model pruning framework for HFL, where an Energy Management System (EMS) and an Intent-driven Pruning Orchestrator (IDPO) dynamically translate system-level intents (e.g., energy minimization or accuracy preservation) into pruning actions at both edge and cloud layers. Experiments on MNIST, CIFAR-10, and FEMNIST show up to 41% smaller models, 12× faster training, 28–35% lower energy use, and +12.9% accuracy gain under non-IID data, establishing the framework as a robust and sustainable solution for IoT learning.
Charith Elvitigala, Ibrahim Khalil 0001, Shehan Edirimannage, Mohammed Atiquzzaman, Wathsara Daluwatta
IEEE Internet Things J.1
2026 Differentially Private Model Recombination as a Service for Trustable and Federated Learning in Next-Generation Networks With Non-IID Data
Charith Elvitigala, Ibrahim Khalil 0001, Shehan Edirimannage, Mohammed Atiquzzaman, Wathsara Daluwatta
IEEE Trans. Netw. Serv. Manag.1
2025 ZeTFRi - A Zero Trust-Based Free Rider Detection Framework for Next Generation Federated Learning Networks
abstract
With the rapid expansion of next-generation networking, Internet of Things (IoT) devices have become central components of federated learning (FL) networks. FL offers a paradigm for distributed training machine learning models while preserving user data privacy. However, existing network security measures often struggle to identify legitimate contributors from opportunistic free riders within these networks. The Free Rider (FR) problem arises when participants seek to benefit from the FL processes without contributing. In particular, free riders are known to exist within or outside of the network, whereas outside free riders can hardly be identified. The Zero Trust model proposes an environment where no entity, including the network itself, is inherently trusted, providing a foundation to counter external threats seeking to exploit the network. This study proposes a novel framework strengthened by the Zero Trust model to identify external free riders in FL networks. Leveraging a Deep Autoencoding Gaussian Mixture Model (DAGMM)-based technique for internal free rider detection, our framework demonstrates superior performance in identifying free riders across various FR scenarios compared to current state-of-the-art solutions. Through our proposed framework and the principles of Zero Trust, we establish a robust security guarantee for FL networks, ensuring the integrity of the learning process.
Shehan Edirimannage, Ibrahim Khalil 0001, Charith Elvitigala, Wathsara Daluwatta, Primal Wijesekera, Albert Y. Zomaya
IEEE J. Sel. Areas Commun.3
2024 Semantic Ranking for Automated Adversarial Technique Annotation in Security Text
abstract
We introduce a novel approach for mapping attack behaviors described in threat analysis reports to entries in an adversarial techniques knowledge base. Our method leverages a multi-stage ranking architecture to efficiently rank the most related techniques based on their semantic relevance to the input text. Each ranker in our pipeline uses a distinct design for text representation. To enhance relevance modeling, we leverage pretrained language models, which we fine-tune for the technique annotation task. While generic large language models are not yet capable of fully addressing this challenge, we obtain very promising results. We achieve a recall rate improvement of +35% compared to the previous state-of-the-art results. We further create new public benchmark datasets for training and validating methods in this domain, which we release to the research community aiming to promote future research in this important direction.
Udesh Kumarasinghe, Ahmed Lekssays, Husrev T. Sencar, Sabri Boughorbel, Charith Elvitigala, Preslav Nakov
AsiaCCS5
2024 Blocklist-Forecast: Proactive Domain Blocklisting by Identifying Malicious Hosting Infrastructure
abstract
Domain blocklists play an important role in blocking malicious domains reaching users. However, existing blocklists are reactive in nature and slow to react to attacks, by which time the damage is already caused. This is mainly due to the fact that existing blocklists and reputation systems rely on either website content or user interactions with the websites in order to ascertain if a website is malicious. In this work, we explore the possibility of predicting malicious domains proactively, given a seed list of malicious domains from such reactive blocklists. We observe that malicious domains often share the infrastructure utilized for previous attacks, reuse or rotate resources. Leveraging this observation, we selectively crawl passive DNS data to identify domains in the "neighborhood" of seed malicious domains extracted from reactive blocklists. Due to the increased utilization of cloud hosting, not all such domains in the neighborhood are malicious. Further vetting is required to identify unseen malicious domains. Along with the proximity, we identify that hosting and lexical features help distinguish malicious domains from benign ones. We model the infrastructure as a heterogeneous network graph and design a graph neural network to detect malicious domains. Our approach is blocklist-agnostic in that it can work with any blocklist and detect new malicious domains. We demonstrate our approach utilizing 7 month longitudinal data from three popular blocklists, PhishTank, OpenPhish, and VirusTotal. Our experimental results show that, our approach for VirusTotal feed detects 4.7 unseen malicious domains for every seed malicious domain at a very low FPR of 0.059. Further, we observe the concerning trend that 47% of predicted malicious domains that are later flagged in VirusTotal are identified only after more than 3 weeks to months since our model detects them.
Udesh Kumarasinghe, Mohamed Nabeel, Charith Elvitigala
RAID3
2024 QARMA-FL: Quality-Aware Robust Model Aggregation for Mobile Crowdsourcing
abstract
Over the past few years, the improved detection and processing features of Internet-of-Things (IoT) devices have opened the doors to several mobile crowdsourcing applications. Federated Learning (FL) is being seen as an attractive framework to address the data privacy concerns of mobile users in the context of crowdsourcing. In FL on a crowdsourcing platform, constructing an effective deep neural network (DNN) is challenging. This is primarily because the quality of the global model depends on the local model quality, which can vary greatly due to differences in the computational resources, data quantity, and data quality provided by each worker. To address these challenges, we propose QARMA-FL: Quality-aware robust model aggregation for federated learning in crowdsourcing applications, where we select the local model for aggregation based on its quality and performance. We also propose a model-quality-aware incentive mechanism to reward workers, based on their contribution to model training. Our model selection and incentive mechanism is capable of detecting Free Rider attacks, identifying workers who benefit from others contributions without contributing themselves. Most existing evaluations of FL in mobile crowdsourcing studies are not based on the real-world FL scenarios. Therefore, we evaluate QARMA-FL alongside a baseline FL model in a quantity-skew, non-IID data setup where different workers contribute varying amounts of data for model training. Our diverse experiments validated QARMA-FLs performance, demonstrating its ability to efficiently aggregate models in mobile crowdsourcing scenarios, reaching baseline results with a reduced worker participation by 40% to 60%.
Shehan Edirimannage, Charith Elvitigala, Ibrahim Khalil 0001, Primal Wijesekera, Xun Yi
IEEE Internet Things J.2
2022 EmoMent: An Emotion Annotated Mental Health Corpus from Two South Asian Countries
abstract
People often utilise online media (e.g., Facebook, Reddit) as a platform to express their psychological distress and seek support. State-of-the-art NLP techniques demonstrate strong potential to automatically detect mental health issues from text. Research suggests that mental health issues are reflected in emotions (e.g., sadness) indicated in a person’s choice of language. Therefore, we developed a novel emotion-annotated mental health corpus (EmoMent),consisting of 2802 Facebook posts (14845 sentences) extracted from two South Asian countries - Sri Lanka and India. Three clinical psychology postgraduates were involved in annotating these posts into eight categories, including ‘mental illness’ (e.g., depression) and emotions (e.g., ‘sadness’, ‘anger’). EmoMent corpus achieved ‘very good’ inter-annotator agreement of 98.3% (i.e. % with two or more agreement) and Fleiss’ Kappa of 0.82. Our RoBERTa based models achieved an F1 score of 0.76 and a macro-averaged F1 score of 0.77 for the first task (i.e. predicting a mental health condition from a post) and the second task (i.e. extent of association of relevant posts with the categories defined in our taxonomy), respectively.
Thushari Atapattu, Mahen Herath, Charith Elvitigala, Piyanjali de Zoysa, Kasun Gunawardana, Menasha Thilakaratne, Kasun De Zoysa, Katrina Falkner
COLING3
2021 Demo: Large Scale Analysis on Vulnerability Remediation in Open-source JavaScript Projects
abstract
Given the widespread prevalence of vulnerabilities, remediation is a critical phase that every software project has to go through. When comparing the studies on understanding the security vulnerabilities in software, such as vulnerability discovery and patterns, there is a lack of studies on the vulnerability remediation phase. To address this, we have done a timeline analysis for 130 of the most dependent upon open source projects written in JavaScript language, hosted on GitHub to understand the nature and the lifetime of the vulnerabilities in those projects. We used a static code analyzer on 501K commits from the repositories to identify commits that introduced new vulnerabilities to the code and fixed existing vulnerabilities in the code. In 90% of the projects, we identified that a commit that fixed an existing vulnerability had introduced one or more new vulnerabilities into the code. On average, 16% of the commits intended to fix vulnerabilities have introduced one or more new vulnerabilities from the analyzed projects. We also found that 18% of the total vulnerabilities found in those projects have originated from a commit meant to fix an existing vulnerability, and 78% of those vulnerabilities could have been avoided of introduction if the developers were to use proper internal testing. Here, we demonstrate Sequza, a visualization tool to help organizations detect such instances at the earliest possible.
Vinuri Bandara, Thisura Rathnayake, Nipuna Weerasekara, Charith Elvitigala, Kenneth Thilakarathna, Primal Wijesekera, Kasun De Zoysa, Chamath Keppitiyagama
CCS4
2021 Compromised or Attacker-Owned: A Large Scale Classification and Study of Hosting Domains of Malicious URLs
Ravindu De Silva, Mohamed Nabeel, Charith Elvitigala, Issa M. Khalil, Ting Yu 0001, Chamath Keppitiyagama
USENIX Security Symposium3
2020 Investigating MMM Ponzi Scheme on Bitcoin
abstract
Cybercriminals exploit cryptocurrencies to carry out illicit activities. In this paper, we focus on Ponzi schemes that operate on Bitcoin and perform an in-depth analysis of MMM, one of the oldest and most popular Ponzi schemes. Based on 423K transactions involving 16K addresses, we show that: (1) Starting Sep 2014, the scheme goes through three phases over three years. At its peak, MMM circulated more than 150M dollars a day, after which it collapsed by the end of Jun 2016. (2) There is a high income inequality between MMM members, with the daily Gini index reaching more than 0.9. The scheme also exhibits a zero-sum investment model, in which one member's loss is another member's gain. The percentage of victims who never made any profit has grown from 0% to 41% in five months, during which the top-earning scammer has made 765K dollars in profit. (3) The scheme has a global reach with 80 different member countries but a highly-asymmetrical flow of money between them. While India and Indonesia have the largest pairwise flow in MMM, members in Indonesia have received 12x more money than they have sent to their counterparts in India.
Yazan Boshmaf, Charith Elvitigala, Husam Al Jawaheri, Primal Wijesekera, Mashael Al Sabah
AsiaCCS2
2020 Fix that Fix Commit: A real-world remediation analysis of JavaScript projects
abstract
While there is a large body of work on understanding vulnerabilities in the wild, little has been done to understand the dynamics of the remediation phase of the development cycle. To this end, we have done a timeline analysis on 118K commits from 53 of the most used JavaScript projects from GitHub to understand the provenance and prevalence of vulnerabilities in those projects. We used a vulnerability detector (CodeQL) to filter commits that introduced vulnerabilities and the commits that fixed a prior vulnerability. We found that in 82% of the projects, a commit fixing a prior vulnerability, in turn, introduced one or more new vulnerabilities. Among those projects, on average, 18% of the commits intended to fix vulnerabilities, in turn, introduced one or more new vulnerabilities. We also found that 50% of the total vulnerabilities found in those projects originated from a commit meant to fix a prior vulnerability, and 78% of those vulnerabilities could have been avoided if they were to use proper internal testing. We provide critical insights into how proper internal testing can avoid a significant portion of vulnerabilities, increasing organizations' security posture.
Vinuri Bandara, Thisura Rathnayake, Nipuna Weerasekara, Charith Elvitigala, Kenneth Thilakarathna, Primal Wijesekera, Chamath Keppitiyagama
SCAM4
2017 A Machine Learning Approach for Identifying Mosquito Breeding Sites via Drone Images
abstract
Dengue is one of the deadly and fast spreading diseases in Sri Lanka. The female Aedes mosquito is the dengue vector and these mosquitoes breed in clear and non-flowing water. The Public Health Inspectors (PHIs) are tasked with detecting and eliminating such water collection areas.
Akarshani Amarasinghe, Chathura Suduwella, Charith Elvitigala, Lasith Niroshan, Rangana Jayashanka Amaraweera, Kasun Gunawardana, Prabash Kumarasinghe, Kasun De Zoysa, Chamath Keppitiyagama
SenSys3