VLDB 2026 Research / reviewers in the wild / expert
Fatih Turkmen
dblp:22/2474
· DBLP profile ↗
22ranked-venue papers
6as first author
8since 2021 · last 2026
0000-0002-6262-4869ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | EL-MIA: Quantifying Membership Inference Risks of Sensitive Entities in LLMsabstractMembership inference attacks (MIA) aim to infer whether a particular data point is part of the training dataset of a model. In this paper, we propose a new task in the context of LLM privacy: entity-level discovery of membership risk focused on sensitive information (PII, credit card numbers, etc). Existing methods for MIA can detect the presence of entire prompts or documents in the LLM training data, but they fail to capture risks at a finer granularity. We propose the ``EL-MIA'' framework for auditing entity-level membership risks in LLMs. We construct a benchmark dataset for the evaluation of MIA methods on this task. Using this benchmark, we conduct a systematic comparison of existing MIA techniques as well as two newly proposed methods. We provide a comprehensive analysis of the results, trying to explain the relation of the entity level MIA susceptability with the model scale, training epochs, and other surface level factors. Our findings reveal that existing MIA methods are limited when it comes to entity-level membership inference of the sensitive attributes, while this susceptibility can be outlined with relatively straightforward methods, highlighting the need for stronger adversaries to stress test the provided threat model. Ali Satvaty, Suzan Verberne, Fatih Turkmen |
LREC | 3 |
| 2026 | Beyond Reinforcement Learning for network security: A comprehensive survey and tutorial
Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Fatih Turkmen, Chafika Benzaid |
J. Inf. Secur. Appl. | 4 |
| 2025 | Efficient Verifiable Differential Privacy with Input Authenticity in the Local and Shuffle ModelabstractLocal differential privacy (LDP) enables the efficient release of aggregate statistics without having to trust the central server (aggregator), as in the central model of differential privacy, and simultaneously protects a client's sensitive data. The shuffle model with LDP provides an additional layer of privacy, by disconnecting the link between clients and the aggregator. However, LDP has been shown to be vulnerable to malicious clients who can perform both input and output manipulation attacks, i.e., before and after applying the LDP mechanism, to skew the aggregator's results. In this work, we show how to prevent malicious clients from compromising LDP schemes. Our only realistic assumption is that the initial raw input is authenticated; the rest of the processing pipeline, e.g., formatting the input and applying the LDP mechanism, may be under adversarial control. We give several real-world examples where this assumption is justified. Our proposed schemes for verifiable LDP (VLDP), prevent both input and output manipulation attacks against generic LDP mechanisms, requiring only one-time interaction between client and server, unlike existing alternatives [37, 43]. Most importantly, we are the first to provide an efficient scheme for VLDP in the shuffle model. We describe, and prove security of, two schemes for VLDP in the local model, and one in the shuffle model. We show that all schemes are highly practical, with client run times of less than 2 seconds, and server run times of 5-7 milliseconds per client. Tariq Bontekoe, Hassan Jameel Asghar, Fatih Turkmen |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | PPDL: Efficient Dropout-Resilient Aggregation for Privacy-Preserving Decentralized Learning
Ali Reza Ghavamipour, Benjamin Zi Hao Zhao, Fatih Turkmen |
NSS | 3 |
| 2023 | Federated Synthetic Data Generation with Stronger Security GuaranteesabstractSynthetic data generation plays a crucial role in many areas where data is scarce and privacy/confidentiality is a significant concern. Generative Adversarial Networks (GANs), arguably one of the most widely used data synthesis techniques, allow for the training of a model (i.e., generator) that can generate real-looking data by playing a min-max game with a discriminator model. When multiple organizations are reluctant to share their sensitive data, GANs models can be trained in a federated manner, commonly with the use of differential privacy (DP). In order to achieve a reasonable level of model utility, DP trades privacy exhibiting vulnerability to various attacks (e.g., membership inference attack). In this paper, we propose a hybrid solution, PP-FedGAN, to the asynchronous federated, privacy-preserving training of GANs models by combining the CKKS homomorphic encryption (HE) scheme with differential privacy. The addition of HE results in around 10 seconds of overhead on the client side per round and 115 seconds on the entire training procedure. We also analyze the security of PP-FedGAN under the honest-but-curious security model. Where stronger security guarantees are required, our proposal presents a better alternative to solutions that only employ DP. Ali Reza Ghavamipour, Fatih Turkmen, Rui Wang 0070, Kaitai Liang |
SACMAT | 2 |
| 2023 | Security and privacy concerns in cloud-based scientific and business workflows: A systematic reviewabstractToday, the number of data-intensive and compute-intensive applications like business and scientific workflows has dramatically increased, which made cloud computing more popular because of its ability to deliver a large number of computing resources on-demand. Security is a critical issue affecting the wide adoption of cloud technologies, especially for workflows that are mostly dealing with sensitive data and tasks. In this paper, we carry out a review of the state-of-the-art on how security and privacy concerns in scientific and business workflows in cloud environments are being addressed and identify the limitations and gaps in the current body of knowledge in this area. In this extensive literature review, we first present the state-of-the-art security solutions organized according to the phases of the workflow life cycle they target for both business and scientific workflows. The analysis shows that most of the existing literature focuses on the modeling and execution phases, while the monitoring and adaptation phases are not covered adequately by a scarce amount of publications thus leaving a huge gap in the body of knowledge relevant to detection, prevention of and reaction to security violations in cloud-based workflows. Nafiseh Soveizi, Fatih Turkmen, Dimka Karastoyanova |
Future Gener. Comput. Syst. | 2 |
| 2022 | Poster: Privacy-preserving Genome Analysis using Verifiable Off-Chain ComputationabstractGenome-wide association studies (GWAS) focus on finding associations between genotypes and phenotypes such as susceptibility to diseases. Since genetic data is extremely sensitive and long-lived, individuals and organizations are reluctant to share their data for analysis. This paper proposes two solutions for a fully decentralized and privacy-preserving system for performing minor allele frequency analysis on multiple data sets. Homomorphic encryption and zero-knowledge proofs are used in combination with a blockchain system to achieve data privacy and enable verifiability. Preliminary evaluation of the solutions reveals several important challenges such as handling large cipher texts in smart contracts and reuse of the encrypted data for specific researcher queries that need to be tackled in order to make the solutions more practical. Leon Visscher, Mohammed Alghazwi, Dimka Karastoyanova, Fatih Turkmen |
CCS | 4 |
| 2022 | Blockchain for Genomics: A Systematic Literature ReviewabstractHuman genomic data carry unique information about an individual and offer unprecedented opportunities for healthcare. The clinical interpretations derived from large genomic datasets can greatly improve healthcare and pave the way for personalized medicine. Sharing genomic datasets, however, poses major challenges, as genomic data is different from traditional medical data, indirectly revealing information about descendants and relatives of the data owner and carrying valid information even after the owner passes away. Therefore, stringent data ownership and control measures are required when dealing with genomic data. In order to provide a secure and accountable infrastructure, blockchain technologies offer a promising alternative to traditional distributed systems. Indeed, the research on blockchain-based infrastructures tailored to genomics is on the rise. However, there is a lack of a comprehensive literature review that summarizes the current state-of-the-art methods in the applications of blockchain in genomics. In this article, we systematically look at the existing work both commercial and academic, and discuss the major opportunities and challenges. Our study is driven by five research questions that we aim to answer in our review. We also present our projections of future research directions which we hope the researchers interested in the area can benefit from. Mohammed Alghazwi, Fatih Turkmen, K. Joeri van der Velde, Dimka Karastoyanova |
Distributed Ledger Technol. Res. Pract. | 2 |
| 2020 | Continuous Security Testing: A Case Study on Integrating Dynamic Security Testing Tools in CI/CD PipelinesabstractContinuous Integration (CI) and Continuous Delivery (CD) have become a well-known practice in DevOps to ensure fast delivery of new features. This is achieved by automatically testing and releasing new software versions, e.g. multiple times per day. However, classical security management techniques cannot keep up with this quick Software Development Life Cycle (SDLC). Nonetheless, guaranteeing high security quality of software systems has become increasingly important. The new trend of DevSecOps aims to integrate security techniques into existing DevOps practices. Especially, the automation of security testing is an important area of research in this trend. Although plenty of literature discusses security testing and CI/CD practices, only a few deal with both topics together. Additionally, most of the existing works cover only static code analysis and neglect dynamic testing methods. In this paper, we present an approach to integrate three automated dynamic testing techniques into a CI/CD pipeline and provide an empirical analysis of the introduced overhead. We then go on to identify unique research/technology challenges the DevSecOps communities will face and propose preliminary solutions to these challenges. Our findings will enable informed decisions when employing DevSecOps practices in agile enterprise applications engineering processes and enterprise security. Thorsten Rangnau, Remco v. Buijtenen, Frank Fransen, Fatih Turkmen |
EDOC | 4 |
| 2020 | Benchmarking UAQ SolversabstractThe User Authorization Query (UAQ) Problem is key for RBAC systems that aim to offer permission level user-system interaction, where the system automatically determines the roles to activate in order to enable the requested permissions. Finding a solution to a UAQ problem amounts to determining an optimum set of roles to activate in a given session so to obtain some permissions while satisfying a collection of authorization constraints, most notably Dynamic Mutually-Exclusive Roles (DMER) constraints. Although the UAQ Problem is NP-hard, a number of techniques to solve the UAQ problem have been put forward along with encouraging, albeit inconclusive, experimental results. We propose a methodology for designing parametric benchmarks for the UAQ problem and make a novel suite of parametric benchmarks publicly available that allows for the systematic assessment of UAQ solvers over a number of relevant dimensions. By running three prominent UAQ solvers against our benchmarks, we provide a very comprehensive analysis showing (i) the shortcomings of currently available benchmarks, (ii) the adequacy of the proposed methodology and (iii) that the reduction to PMaxSAT is currently the most effective approach to tackling the UAQ problem. Alessandro Armando, Giorgia Gazzarata, Fatih Turkmen |
SACMAT | 3 |
| 2020 | AQUA: An Efficient Solver for the User Authorization Query ProblemabstractWe present AQUA, a solver for the User Authorization Query (UAQ) problem in Role-Based Access Control (RBAC). The UAQ problem amounts to determining a set of roles granting a given set of permissions, satisfying a collection of authorisation constraints (most notably Dynamic Mutually-Exclusive Roles, DMER) and achieving some optimization objective, i.e. seeking min/max/any number of roles to activate and/or permissions to grant. AQUA supports the enforcement of a wide class of DMER constraints as well as several types of optimization objectives (namely, min/max/any number of roles to activate, min/max/any number of permissions to grant, and a combinations thereof). In this paper, we demonstrate the use of AQUA~over a running example while providing certain implementation details including the architecture. Alessandro Armando, Giorgia Gazzarata, Fatih Turkmen |
SACMAT | 3 |
| 2017 | Defining Intercloud Security Framework and Architecture Components for Multi-Cloud Data Intensive ApplicationsabstractThis paper presents results of the ongoing development of the Intercloud Security Framework (ICSF), that is a part of the Intercloud Architecture Framework (ICAF), and provides an architectural basis for building security infrastructure services for multi-cloud applications. The paper refers to general use case of the data intensive applications that indicate need for multi-cloud applications platforms that will require corresponding multi-cloud security services. The paper presents analysis of the general multi-cloud use case that helps eliciting the general requirement to ICSF and identifying the security infrastructure functional components that would allow using distributed cloud based resources and data sets. The paper defines the main ICSF services and functional components, and explains importance of consistent implementation of the Security Services Lifecycle Management in cloud based applications. The paper provides overview of the cloud compliance standards and their role in cloud security. The paper refers to the security infrastructure development in the CYCLONE project that implements federated identify management, secure logging service, and multi-domain Attribute Based Access Control, security services lifecycle management. The paper discusses implementation of the Trust Bootstrapping Protocol as an important mechanism to ensure consistent security in the virtualised inter-cloud environment. Yuri Demchenko, Fatih Turkmen, Cees T. A. M. de Laat, Mathias Slawik |
CCGrid | 2 |
| 2017 | CYCLONE: The Multi-cloud Middleware Stack for Application Deployment and ManagementabstractDevOps teams have to consider many technology and platform aspects when developing, deploying and operating cloud based applications: application deployments need to work everywhere on different cloud platforms, identities need to come from anywhere, and networks need to connect to anyone. The CYCLONE middleware is a holistic middleware stack that allows deploying and managing cloud based applications on multiple clouds and multiple cloud platforms. It includes a deployment manager, a practical identity federation, as well as a network manager that connects VMs independent of any specific infrastructure. This article explains the CYCLONE middleware stack, and what it can offer for application developers and operators. The paper describes in details the main bioinformatics use cases that evolve from a single VM installation for simple microbial research to multicloud infrastructure for advanced genomic resource. The paper also describes the CYCLONE federated identity management and access control infrastructure that significantly simplifies access for institutional users. Mathias Slawik, Christophe Blanchet, Yuri Demchenko, Fatih Turkmen, Alexy Ilyushkin, Cees T. A. M. de Laat, Charles Loomis |
CloudCom | 4 |
| 2017 | Formal analysis of XACML policies using SMT
Fatih Turkmen, Jerry den Hartog, Silvio Ranise, Nicola Zannone |
Comput. Secur. | 1 |
| 2016 | On the Use of SMT Solving for XACML Policy EvaluationabstracteXtensible Access Control Markup Language (XACML) allows for flexible management of authorisations and is particularly useful in settings where permissions change dynamically. However, it has been shown that policy evaluation in XACML may have scalability problems when policies become large and sophisticated in content. Among several proposals for designing efficient policy decision points for XACML policies, decision diagram (DD) based procedures still represent the state-of-the-art. In this paper, we present an alternative approach to policy evaluation that employs Satisfiability Modulo Theories (SMT) solving instead of DDs. The approach does not only represent a feasible policy evaluation procedure in terms of performance but also easily lends itself to different application areas such as verification at run-time during authorization query answering. We discuss various scenarios in which SMT-based policy evaluation would be more practical compared to DD-based procedures. A preliminary experimental evaluation of our policy evaluation procedure against real-world policies is also provided in the paper. Fatih Turkmen, Yuri Demchenko |
CloudCom | 1 |
| 2016 | iGenoPri: Privacy-preserving genomic data processing with integrity and correctness proofsabstractNowadays, governmental and non-governmental health organisations and insurance companies invest in integrating an individual's genetic information to their daily practices. In this paper, we focus on an emerging area of genome analysis, called Disease Susceptibility (DS), from which an individual's susceptibility to a disease is calculated by using her genetic information. Recent work by Danezis et al. [1] presents an approach for calculating DS in a privacy-preserving manner. However, the proposed solution has two drawbacks. First, it does not provide a mechanism to check the integrity of genomic data that is used to calculate the susceptibility and more importantly the computed result. Second, it lacks a mechanism to check the correctness of the performed DS test. In this paper, we present iGenoPri that aims at addressing both problems by employing the Message Authentication Code (MAC) and verifiable computing. Fatih Turkmen, Muhammad Rizwan Asghar, Yuri Demchenko |
PST | 1 |
| 2014 | POSTER: Analyzing Access Control Policies with SMTabstractThe flexibility and expressiveness of eXtensible Access Control Markup Language (XACML) allows the specification of a wide range of policies in different access control models. However, XACML policies are often verbose and, thus, prone to errors. Several tools have been developed to assist policy authors for the verification and analysis of policies, but most of them are limited in the types of analysis they can perform. In particular, they are not able to reason about predicates of non-boolean variables and, even if they do, they do it inefficiently. In this paper, we present the X2S framework, a formal framework for the analysis of XACML policies that employs Satisfiability Modulo Theories (SMT) as the underlying reasoning mechanism. The use of SMT not only allows more fine-grained analysis of policies, but it also improves the performance of policy analysis significantly. Fatih Turkmen, Jerry den Hartog, Nicola Zannone |
CCS | 1 |
| 2013 | Explanations and Relaxations for Policy Conflicts in Physical Access ControlabstractPhysical access control policies define sets of rulesthat govern people's access to physical resources such asrooms and buildings. While simple decision-precedence can be used to reconcile different rules that result in conflicting access decisions, the presence of rule conflicts and other rule anomalies can make it difficult for a policy-administrator to comprehend and effectively manage complex policies. In this paper we are concerned with discovering conflicts and computing relaxations of access policies in order to eliminate conflicting rule instances. We propose several SAT based encodings in which these rule conflicts and anomalies areexpressed as explanation style problems. Relaxation techniques are in turn used to eliminate these anomalies by recommending what rules have to be revoked or what permissions have to beremoved from which rules. Moreover, we discuss a relaxation strategy that preserves most of the access constraints of theoriginal policy. Finally we provide a preliminary performancestudy of our techniques. Our approach is applicable to access control policies in general. Fatih Turkmen, Simon N. Foley, Barry O'Sullivan, William M. Fitzgerald, Tarik Hadzic, Stylianos Basagiannis, Menouer Boubekeur |
ICTAI | 1 |
| 2012 | Efficient run-time solving of RBAC user authorization queries: pushing the envelopeabstractThe User Authorization Query (UAQ) Problem for Role- Based Access Control (RBAC) amounts to determining a set of roles to be activated in a given session in order to achieve some permissions while satisfying a collection of authorization constraints governing the activation of roles. Techniques ranging from greedy algorithms to reduction to (variants of) the propositional satisfiability (SAT) problem have been used to tackle the UAQ problem. Unfortunately, available techniques su er two major limitations that seem to question their practical usability. On the one hand, authorization constraints over multiple sessions or histories are not considered. On the other hand, the experimental evaluations of the various techniques are not satisfactory since they do not seem to scale to larger RBAC policies. Alessandro Armando, Silvio Ranise, Fatih Turkmen, Bruno Crispo |
CODASPY | 3 |
| 2012 | Anomaly analysis for Physical Access Control security configurationabstractPhysical Access Controls, such as supervised doors, surveillance cameras and alarms, act as important points of demarcation between physical zones (areas/rooms) of different levels of trust. They do so by controlling personnel flow to and from areas in accordance with the enterprise security policy. A significant challenge in providing physical access control for (restricted) areas is attaining a degree of confidence that a Physical Access Control security configuration adequately addresses the threats. A misconfiguration may result in a threat of unapproved personnel access or the denial of approved personnel access to a restricted zone. In practice, Physical Access Control security configurations typically span multiple zones, involve many users and run to many thousands of access-control rules, and such complexity may increase the likelihood of misconfiguration. In this paper, a formal model for Physical Access Control security configurations is presented. This model, implemented in SAT, captures a number of unique anomalies specific to Physical Access Control domain. A preliminary set of experiments that evaluate our approach is presented. William M. Fitzgerald, Fatih Turkmen, Simon N. Foley, Barry O'Sullivan |
CRiSIS | 2 |
| 2010 | Reasoning about Relation Based Access ControlabstractRelation Based Access Control (RelBAC) is an access control model that places permissions as first class concepts. Under this model, we discuss in this paper how to formalize typical access control policies with Description Logics. Important security properties, i.e., Separation of Duties (SoD) and Chinese Wall are studied and formally represented in RelBAC. To meet the needs of automated tools for administrators, we show that RelBAC can formalize and answer queries about access control requests and administrative checks resorting to the reasoning services of the underlying Description Logic. Alessandro Artale, Bruno Crispo, Fausto Giunchiglia, Fatih Turkmen, Rui Zhang 0006 |
NSS | 4 |
| 2008 | P-CDN: Extending access control capabilities of P2P systems to provide CDN servicesabstractNew important emerging business paradigms, such as ldquoservice virtualizationrdquo can be made easy and convenient by the use of P2P systems. In these paradigms, often the owners of the services are different (and independent) from the owners of the resources used to offer such services. In comparison to centralized servers, P2P systems can conveniently offer higher availability and more bandwidth as they harness the computing and network resources of thousands of hosts in a decentralized fashion. Despite these useful features and their success in the research community, P2P systems are still not very popular in the business world. The main reason for such a skepticism is their lack of proper security. In this paper, we address this issue by motivating and explaining the benefits of adding access control in P2P systems to make them more suitable and flexible as a technical platform for providing third party services. We propose an architecture augmented with access control mechanisms to enable content delivery on a P2P system. The proposed architecture is shaped according to CDN requirements. We have also tested the feasibility of our approach with a prototype implementation and the preliminary results show that our system can scale well also in the presence of very large number of policies. Fatih Turkmen, Pietro Mazzoleni, Bruno Crispo, Elisa Bertino |
ISCC | 1 |