Samer Khamaiseh

dblp:217/8631 · also Samer Y. Khamaiseh · DBLP profile ↗
← Back
10ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0001-9339-1685ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 3 first-author · 3 since 2021Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 CodeLLM-Auth: Multimodal Authorship Attribution and Verification via Supervised Contrastive Code Embeddings
Anas M. R. Alsobeh, Samer Khamaiseh, Dylan Middendorf, Jack Dziubinski
COMPSAC2
2025 MuAE: A Mutation Testing Framework for Evaluating Autoencoders
abstract
While autoencoders are pivotal in critical applications such as anomaly detection and medical imaging, their reliability remains understudied compared to supervised models. Although mutation testing has advanced for neural networks, no framework exists for assessing autoencoder robustness against real-world faults, leaving a gap in safety-critical validation. Furthermore, autoencoders lack explicit labels, rendering traditional mutation metrics ineffective. We propose MuAE, the first mutation testing tool tailored for autoencoders, addressing this gap through: (1) a fault taxonomy derived from real-world debugging cases; (2) mutation operators that inject faults while preserving model validity; and (3) reconstruction error (Erec) as an evaluation metric to quantify fault impacts on output fidelity. We validate MuAE on CIFAR-10 using two convolutional autoencoders and four mutation operators (M1, M2, M3), generating 3 mutants per operator. Mutations significantly degraded performance: layer reinitialization increased Erecby up to 210%, while weight noise caused milder degradation. This condensed evaluation demonstrates the feasibility of mutation-based robustness assessment for unsupervised models and highlights potential links to adversarial vulnerability.
Samer Khamaiseh, Steven Chiacchira, Anas M. R. Alsobeh, Aibak Aljadayah
COMPSAC1
2025 ADT++: Advanced Adversarial Distributional Training with Class-Wise Robustness
abstract
Adversarial training (AT) is widely regarded as a leading defense strategy for improving the robustness of deep learning models against adversarial attacks. However, existing AT methods often rely on a single attack strategy during training, which limits the exploration of the perturbation space and leads to poor generalization robustness against stronger, unseen, or adaptive adversarial attacks. Moreover, most AT approaches overlook class-wise robustness–the observed variation in robustness across different image classes–by focusing solely on average performance over the entire dataset. In this paper, we present Advanced Distributional Training with Class-wise Robustness (ADT++), a novel adversarial training framework that significantly improves generalization robustness against unseen and sophisticated adversarial attacks. Following the standard adversarial training framework, ADT++ is formulated as a minmax optimization problem, where the inner maximization aims to learn the worst-case adversarial distribution around adversarial examples to further explore the perturbation space. The outer minimization seeks to find model parameters that minimize the expected loss of the maximum inner loss. To further improve the generalization robustness, ADT++ leverages the class-wise robustness phenomenon by targeting the most vulnerable image classes with high-loss adversarial attacks to generate more impactful adversarial examples. Extensive evaluations on benchmark datasets and against various AT defense methods and adversarial attacks confirm the effectiveness of ADT++ in improving model robustness against stronger and adaptive attacks. The source code of ADT++ can be found.11https://github.com/LAiSR-SK/ADT2Plus
Samer Khamaiseh, Deirdre Jost, Anas M. R. Alsobeh, Abdullah S. Al-Alaj, Honglu Jiang
DSAA1
2025 Powerful & Generalizable, Why not both? VA: Various Attacks Framework for Robust Adversarial Training
Samer Khamaiseh, Deirdre Jost, Abdullah S. Al-Alaj, Ahmed Aleroud
ICAART (2)1
2024 Fool 'Em All - Fool-X: A Powerful & Fast Method for Generating Effective Adversarial Images
abstract
The well-trained image classification neural networks are vulnerable to adversarial examples. An adversarial example is a malicious input carefully crafted by adding small perturbations to the original input, leading to misclassification. Despite advancements in generating adversarial examples, to the best of our knowledge, none of the well-known adversarial attacks can generate effective adversarial examples that work efficiently on large-scale datasets and very deep neural network architectures. In contrast to ordinary adversarial examples, effective adversarial examples have all the following four characteristics: (1) the ability to maximize the loss of DNNs, (2) the ability to cause a high misclassification rate for both undefended and defended DNN models using various defense methods, (3) minimal perturbations with low computational overhead on large-scale datasets, (4) the ability to be transferable across different DNN architectures.To fill this void, we propose Fool-X, an algorithm to generate effective adversarial examples with the least perturbations that can fool state-of-the-art image classification neural networks. To evaluate the performance of Fool-X, we have conducted extensive experiments using 12 baseline adversarial training defense methods and six state-of-the-art adversarial attacks. The results reported on ImageNet-ILSVRC, CIFAR-100, and CIFAR-10 demonstrate that the proposed Fool-X algorithm can generate effective adversarial examples on large-scale datasets that can successfully fool the well-trained, defended image classification neural networks and significantly outperform the state-of-the-art adversarial attacks. The code is available: https://github.com/LAiSR-SK/fool-X-Attack
Samer Khamaiseh, Mathew Mancino, Deirdre Jost, Abdullah S. Al-Alaj, Derek Bagagem, Edoardo Serra
IEEE Big Data1
2024 Constraining Adversarial Attacks on Network Intrusion Detection Systems: Transferability and Defense Analysis
abstract
Adversarial attacks have been extensively studied in the domain of deep image classification, but their impacts on other domains such as Machine and Deep Learning-based Network Intrusion Detection Systems (NIDSs) have received limited attention. While adversarial attacks on images are generally more straightforward due to fewer constraints in the input domain, generating adversarial examples in the network domain poses greater challenges due to the diverse types of network traffic and the need to maintain its validity. Prior research has introduced constraints to generate adversarial examples against NIDSs, but their effectiveness across different attack settings, including transferability, targetability, defenses, and the overall attack success have not been thoroughly examined. In this paper, we proposed a novel set of domain constraints for network traffic that preserve the statistical and semantic relationships between traffic features while ensuring the validity of the perturbed adversarial traffic. Our constraints are categorized into four types: feature mutability constraints, feature value constraints, feature dependency constraints and distribution preserving constraints. We evaluated the impacts of these constraints on white box and black box attacks using two intrusion detection datasets. Our results demonstrated that the introduced constraints have a significant impact on the success of white box attacks. Our research revealed that transferability of adversarial examples depends on the similarity between the targeted models and the models to which the examples are transferred, regardless of the attack type or the presence of constraints. We also observed that adversarial training enhanced the robustness of the majority of machine learning and deep learning-based NIDSs against unconstrained attacks, while providing some resilience against constrained attacks. In practice, this suggests the potential use of pre-existing signatures of constrained attacks to combat new variations or zero-day adversarial attacks in real-world NIDSs.
Nour Alhussien, Ahmed Aleroud, Abdullah Melhem, Samer Khamaiseh
IEEE Trans. Netw. Serv. Manag.4
2023 Target-X: An Efficient Algorithm for Generating Targeted Adversarial Images to Fool Neural Networks
Samer Khamaiseh, Derek Bagagem, Abdullah S. Al-Alaj, Mathew Mancino, Hakem Alomari, Ahmed Aleroud
COMPSAC1
2020 vSwitchGuard: Defending OpenFlow Switches Against Saturation Attacks
abstract
While the decoupling of control and data planes in software-defined networking (SDN) facilitates orchestrating network traffic, it suffers from security threats. For example, saturation attacks can make SDN out of service by exhausting the controller' and switch's computational resources. The existing research has focused on defense against limited types of saturation attacks. In this paper, we propose vSwitchGuard, a framework for detection and countermeasure of known and unknown saturation attacks in SDN. vSwitchGuard aims to identify the victim switches targeted by known or unknown types of saturation attacks with machine learning classifiers and restore the victim switches to their safe state through deep packet inspection. We have evaluated three supervised classifiers and four semi-supervised classifiers for five types of saturation attacks (TCP-SYN, UDP, ICMP, IP-Spoofing, and TCP-SARFU) and their combinations. The results suggest that supervised and semi-supervised classifiers can be combined to deal with known and unknown attacks for better performance. We have also implemented the countermeasure and evaluated it with all combinations of the five types of attacks. The results demonstrate that vSwitchGuard can effectively defend against the attacks without significant performance overhead.
Samer Khamaiseh, Edoardo Serra, Dianxiang Xu
COMPSAC1
2020 Detecting Saturation Attacks Based on Self-Similarity of OpenFlow Traffic
abstract
As a new networking paradigm, Software-Defined Networking (SDN) separates data and control planes to facilitate programmable functions and improve the efficiency of packet delivery. Recent studies have shown that there exist various security threats in SDN. For example, a saturation attack may disturb the normal delivery of packets and even make the SDN system out of service by flooding the data plane, the control plane, or both. The existing research has focused on saturation attacks caused by SYN flooding. This paper presents an anomaly detection method, called SA-Detector, for dealing with a family of saturation attacks through IP spoofing, ICMP flooding, UDP flooding, and other types of TCP flooding, in addition to SYN flooding. SA-Detector builds upon the study of self-similarity characteristics of OpenFlow traffic between the control and data planes. Our work has shown that the normal and abnormal traffic flows through the OpenFlow communication channel have different statistical properties. Specifically, normal OpenFlow traffic has a low self-similarity degree whereas the occurrences of saturation attacks typically imply a higher degree of self-similarity. Therefore, SA-Detector exploits statistical results and self-similarity degrees of OpenFlow traffic, measured by Hurst exponents, for anomaly detection. We have evaluated our approach in both physical and simulation SDN environments with various time intervals, network topologies and applications, Internet protocols, and traffic generation tools. For the physical SDN environment, the average accuracy of detection is 97.68% and the average precision is 94.67%. For the simulation environment, the average accuracy is 96.54% and the average precision is 92.06%. In addition, we have compared SA-Detector with the existing saturation attack detection methods in terms of the aforementioned performance metrics and controller's CPU utilization. The experiment results indicate that SA-Detector is effective for the detection of saturation attacks in SDN.
Zhiyuan Li 0002, Weijia Xing, Samer Khamaiseh, Dianxiang Xu
IEEE Trans. Netw. Serv. Manag.3
2018 Model-Based Testing of Obligatory ABAC Systems
abstract
Attribute-based access control (ABAC) with obligations is a new technique for achieving fine-grained access control and accountability. An obligatory ABAC system can be implemented incorrectly for various reasons, such as programming errors and incorrect access control and obligation specification. To reveal these implementation defects, this paper presents an approach to model-based testing of obligatory ABAC systems. In this approach, we first build a test model by specifying a functional model and an obligatory ABAC policy. The policy represents access control and obligation constraints on the functional model. Then we weave the policy with the functional model into an integrated model that represents both functions under test and access control and obligation constraints on them. Test cases can then be generated from the integrated model. Our approach is built upon MISTA, an open source test code generator that supports a variety of programming languages and test frameworks. To validate our approach, this paper presents a first case study on the development and testing of an open-source obligatory ABAC system. We evaluated the effectiveness of the approach by mutation analysis of the ABAC and obligation rules and the policy enforcement code in the implementation. The result shows that our approach is capable of finding the majority of injected faults.
Samer Khamaiseh, Patrick Chapman, Dianxiang Xu
QRS1