VLDB 2026 Research / reviewers in the wild / expert
Junaid Akram
dblp:224/9523
· DBLP profile ↗
15ranked-venue papers
13as first author
7since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 8 first-author · 4 since 2021Security and privacy · 3 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorSystems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Blockchain-Enhanced Framework for Privacy and Data Integrity in Crowdsourced Drone Services
Junaid Akram, Ali Anaissi |
ICSOC (2) | 1 |
| 2024 | Decentralized PKI Framework for Data Integrity in Spatial Crowdsourcing Drone ServicesabstractIn the domain of spatial crowdsourcing drone services, which includes tasks like delivery, surveillance, and data collection, secure communication is paramount. The Public Key Infrastructure (PKI) ensures this by providing a system for digital certificates that authenticate the identities of entities involved, securing data and command transmissions between drones and their operators. However, the centralized trust model of traditional PKI, dependent on Certificate Authorities (CAs), presents a vulnerability due to its single point of failure, risking security breaches. To counteract this, the paper presents D2XChain, a blockchain-based PKI framework designed for the Internet of Drone Things (IoDT). By decentralizing the CA infrastructure, D2XChain eliminates this single point of failure, thereby enhancing the security and reliability of drone communications. Fully compatible with the X.509 standard, it integrates seamlessly with existing PKI systems, supporting all key operations such as certificate registration, validation, verification, and revocation in a distributed manner. This innovative approach not only strengthens the defense of drone services against various security threats but also showcases its practical application through deployment on a private Ethereum testbed, representing a significant advancement in addressing the unique security challenges of drone-based services and ensuring their trustworthy operation in critical tasks. Junaid Akram, Ali Anaissi |
ICWS | 1 |
| 2024 | DDRM: Distributed Drone Reputation Management for Trust and Reliability in Crowdsourced Drone ServicesabstractThis study introduces the Distributed Drone Reputation Management (DDRM) framework, designed to fortify trust and authenticity within the Internet of Drone Things (IoDT) ecosystem. As drones increasingly play a pivotal role across diverse sectors, integrating crowdsourced drone services within the IoDT has emerged as a vital avenue for democratizing access to these services. A critical challenge, however, lies in ensuring the authenticity and reliability of drone service reviews. Leveraging the Ethereum blockchain, DDRM addresses this challenge by instituting a verifiable and transparent review mechanism. The framework innovates with a dual-token system, comprising the Service Review Authorization Token (SRAT) for facilitating review authorization and the Drone Reputation Enhancement Token (DRET) for rewarding and recognizing drones demonstrating consistent reliability. Comprehensive analysis within this paper showcases DDRM’s resilience against various reputation frauds and underscores its operational effectiveness, particularly in enhancing the efficiency and reliability of drone services. Junaid Akram, Ali Anaissi |
ICWS | 1 |
| 2024 | Leveraging Blockchain-as-a-Certificate Authority for Authentication in 6G-Enabled Spatial Crowdsourcing Drone ServicesabstractThe integration of the Internet of Drone Things (IoDT) with spatial crowdsourcing, enhanced by 6G technology, has revolutionized environmental monitoring, particularly in managing Australian bushfires. This approach leverages drones’ mobility, multidimensional motion, and ease of deployment to gather real-time data from hazardous or inaccessible areas. However, the unsecured wireless communication channels and limited computational resources of drones in typical IoDT scenarios make them susceptible to cyber-attacks, including spoofing, GPS manipulation, impersonation, man-in-the-middle, and hijacking. To counter these threats, we propose a robust security protocol that utilizes blockchain technology augmented by Hyperelliptic Curve Cryptography (HECC). By employing blockchain as a Certificate Authority (CA) and treating transactions as certifications, our framework, DronCert, eliminates the need for traditional CAs or Trusted Third Parties (TTP). This decentralized approach, combined with the high-speed, low-latency capabilities of 6G, significantly enhances data transmission security within the IoDT network. A comprehensive security analysis demonstrates DronCert’s resilience against various attacks, such as Denial-of-Service (DoS), man-in-the-middle, replay, and unauthorized device representation. Junaid Akram, Ali Anaissi, Sagar Sidana, Rutvij H. Jhaveri |
VTC Fall | 1 |
| 2022 | Obfuscated code is identifiable by a token-based code clone detection technique
Junaid Akram, Danish Vasan, Ping Luo 0004 |
Int. J. Inf. Comput. Secur. | 1 |
| 2021 | DroidMD: an efficient and scalable Android malware detection approach at source code levelabstractSecurity researchers and anti-virus industries have speckled stress on an Android malware, which can actually damage your phones and threatens the Android markets. In this paper, we propose and develop DroidMD, a scalable self-improvement based tool, based on auto optimisation of signature set, which detect malicious apps in the market at source code level. A prototype has been developed tested and implemented to detect malware in applications. We implement and evaluate our approach on almost 30,000 applications including 27,000 benign and 3,670 malware applications. DroidMD detects malware in different applications at partial level and full level. It analyses only the applications code, which increase its reliability. Our evaluation of DroidMD demonstrates that our approach is very efficient in detecting malware at large scale with high accuracy of 95.5%. Junaid Akram, Majid Mumtaz, Gul Jabeen, Ping Luo 0004 |
Int. J. Inf. Comput. Secur. | 1 |
| 2021 | SQVDT: A scalable quantitative vulnerability detection technique for source code security assessmentabstractSummary Vulnerability detection and exploit is becoming a very important part of security, especially in malware code delivery, hacking a system, efforts to create patches, improving the source code, or updating a software. Vulnerabilities in applications, including browsers, media players, online services, document readers, and so forth. are often exploited and cause a serious damage. In this article, we propose a vulnerability detection technique to detect vulnerabilities in software, as well as shared libraries at source code level. We crawl the vulnerable source code by tracing and locating the patch files from different web sources according to their CVE‐numbers and built a fingerprint index of 2931 vulnerable files. Then we developed a vulnerability detection approach based on code clone detection technique and detect hundreds of vulnerabilities in thousands of GitHub open source projects, which are not noticed before as vulnerable. We detected vulnerabilities in some very famous recently available software, including latest version of Linux, HTC‐kernel, FindX‐8.1‐kernel, and in 7‐TB of C/C++ source code (152,823 open source projects). In this study, we discuss some of the very high severity level (CVSS) vulnerabilities that are detected by our approach. Furthermore, we performed an empirical evaluation and verification on these vulnerabilities, including intraproject clone vulnerabilities, copied‐kernel clone vulnerabilities, and library‐used clone vulnerabilities. Our technique is very fast, efficient, reliable, practical, scalable, and can be implemented at industrial level. The comparison with the state‐of‐the‐art tools shows the effectiveness of our approach. Junaid Akram, Ping Luo 0004 |
Softw. Pract. Exp. | 1 |
| 2020 | Intelligent Target Coverage in Wireless Sensor Networks with Adaptive SensorsabstractDay by day innovation in wireless communications and micro-technology has evolved in the development of wireless sensor networks. This technology has applications such as healthcare supervision, home security, battlefield surveillance and many more. However, due to the use of small batteries with low power this technology faces the issue of power and target monitoring. There is much research done to overcome these issues with the development of different architecture and algorithms. In this paper, a scheduling machine learning algorithm called adaptive learning automata algorithm(ALAA) is used. It provides an efficient scheduling technique. Such that each sensor node in the network has been equipped with learning automata, and with this, they can select their proper state at any given time. The state of the sensor is either active or sleep. For the experiment, different parameters are used to check the consistency of the algorithm to schedule the sensor node such that it can cover all the targets with the use of less power. The results obtained from the experiments show that the proposed algorithm is an efficient way to schedule the sensor nodes to monitor all the targets with use of less power. On the whole, this paper manages to achieve its goal by contributing to the related research on wireless sensor networks with a new design of a learning automata scheduling algorithm. The ability of this proposed algorithm to use the minimum number of sensors to be in active state verified to reduce the use of power in the network. Thus, achieving the goal by enhancing the lifetime of wireless sensor networks. Junaid Akram, Malik Muhammad Saad 0001, Shuja Ansari, Haider Rizvi, Dongkyun Kim, Raza Hasnain |
VTC Fall | 1 |
| 2020 | How to build a vulnerability benchmark to overcome cyber security attacksabstractCybercrimes are on a dramatic rise worldwide. The crime rate is growing day by day in every field or department which is directly or indirectly connected to the internet including Government, business or any individual. The main objective of this study is to evaluate the vulnerabilities in different software systems at the source code level by tracing their patch files. The authors have collected the source code of different types of vulnerabilities at a different level of granularities. They have proposed different ways to collect or trace the vulnerability code, which can be very helpful for security experts, organisations and software developers to maintain security measures. By following their proposed method, you can build your own vulnerability data‐set and can detect vulnerabilities in any system by using suitable code clone detection technique. The study also includes a discussion of reasons for the rise in cybercrimes including zero‐day exploits. A case study has been discussed with results and research questions to show the effectiveness of this study. This study concludes with the effective key findings of published and non‐published vulnerabilities and the ways to prevent from different security attacks to overcome cybercrimes. Junaid Akram, Ping Luo 0004 |
IET Inf. Secur. | 1 |
| 2020 | IBFET: Index-based features extraction technique for scalable code clone detection at file level granularityabstractSummary Many techniques have been developed over the years to detect code clones in different software systems to maintain security measures. These techniques often require the source code to compare the subject system against a very large data set of big code. This paper presents index‐based features extraction technique (IBFET) to detect code clones at a very large‐scale level to billions of LOC at file level granularity. We performed preprocessing, indexing, and clone detection for more than 324 billion of LOC using a Hadoop distributed environment, which is quite faster and more efficient as compared to existing distributed indexing and clone detection techniques; meanwhile, it detects all three types of clones efficiently. The MapReduce rule of divide and conquer is used for a count and retrieve the similar features between different systems. We evaluated the execution time, scalability, precision, and recall of IBFET by using a well‐known clone detection data set IJaDataset and BigCloneBench; furthermore, we compared the results with other state‐of‐the‐art tools. Our approach is faster, flexible, scalable, and provides accurate results with high authenticity and can be implemented at a large‐scale level. Junaid Akram, Majid Mumtaz, Ping Luo 0004 |
Softw. Pract. Exp. | 1 |
| 2020 | MTHAEL: Cross-Architecture IoT Malware Detection Based on Neural Network Advanced Ensemble LearningabstractThe complexity, sophistication, and impact of malware evolve with industrial revolution and technology advancements. This article discusses and proposes a robust cross-architecture IoT malware threat hunting model based on advanced ensemble learning (MTHAEL). Our unique MTHAEL model using stacked ensemble of heterogeneous feature selection algorithms and state-of-the-art neural networks to learn different levels of semantic features demonstrates enhanced IoT malware detection than existing approaches. MTHAEL is the first of its kind that effectively optimizes recurrent neural network (RNN) and convolutional neural network (CNN) with high classification accuracy and consistently low computational overheads on different IoT architectures. Cross-architecture benchmarking is performed during the training with different architectures such as ARM, Intel80386, MIPS, and MIPS+Intel80386 individually. Two different hardware architectures were employed to analyze the architecture overhead, namely Raspberry Pi 4 (ARM-based architecture) and Core-i5 (Intel-based architecture). Our proposed MTHAEL is evaluated comprehensively with a large IoT cross-architecture dataset of 21,137 samples and has achieved 99.98 percent classification accuracy for ARM architecture samples, surpassing prior related works. Overall, MTHAEL has demonstrated practical suitability for cross-architecture IoT malware detection with low computational overheads requiring only 0.32 seconds to detect Any IoT malware. Danish Vasan, Mamoun Alazab, Sitalakshmi Venkatraman, Junaid Akram, Zheng Qin 0003 |
IEEE Trans. Computers | 4 |
| 2019 | VCIPR: Vulnerable Code is Identifiable When a Patch is Released (Hacker's Perspective)abstractVulnerable source code fragments remain unfixed for many years and they always propagate to other systems. Unfortunately, this happens often, when patch files are not propagated to all vulnerable code clones. An unpatched bug is a critical security problem, which should be detected and repaired as early as possible. In this paper, we present VCIPR, a scalable system for vulnerability detection in unpatched source code. We present a unique way, that uses a fast, token-based approach to detect vulnerabilities at function level granularity. This approach is language independent, which supports multiple programming languages including Java, C/C++, JavaScript. VCIPR detects most common repair patterns in patch files for the vulnerability code evaluation. We build fingerprint index of top critical CVE's source code, which were retrieved from a reliable source. Then we detect unpatched (vulnerable/non-vulnerable) code fragments in common open source software with high accuracy. A comparison with the state-of-the-art tools proves the effectiveness, efficiency and scalability of our approach. Furthermore, this paper shows that how the hackers can easily identify the vulnerable software whenever a patch file is released. Junaid Akram, Ping Luo 0004 |
ICST | 1 |
| 2019 | An Integrated Software Vulnerability Discovery Model based on Artificial Neural NetworkabstractQuantitative approaches for software security are needed for effective testing, maintenance and risk assessment of software systems.Vulnerabilities that are present in a software system after its release represent a great risk.Vulnerability discovery models (VDMs) have been proposed to model vulnerability discovery and have has been fined to vulnerability data against calendar time.Though, these models have various shortcomings include changes and development of VDMs for different dataset due to diverse approaches and assumptions in their analytical formulation.There is a clear need for an intensive investigation on these models to enhance predictive accuracy of existing VDMs and adopt the actual behavior of software vulnerabilities which were not modeled previously.This study proposed an integrated model to predict a number of software vulnerabilities by hybridizing the Multi-Layer Perceptron (MLP) artifical neural network and Vulnerability Discovery Models.The proposed model is also widely applicable across various vulnerability datasets and models due to its input diversity by providing improved fitting and predictive accuracy.Further, the experimental results show that this model not only retained the properties of traditional parametric VDM models as well as MLP's good nonlinear mapping ability and useful generalization. Gul Jabeen, Ping Luo 0004, Junaid Akram, Akber Aman Shah |
SEKE | 3 |
| 2018 | DroidCC: A Scalable Clone Detection Approach for Android Applications to Detect Similarity at Source Code LevelabstractAndroid became more popular and widely used operating system. It has been noticed that the code clones in Android apps make it difficult to maintain the security flaws in source code. To avoid these problems, it is essential to find, identify, evaluate and recover those code clones as early as possible. In this paper, we propose and design DroidCC, a novel clone detection approach in Android applications, that helps to detect different types of clones from APK's source code. A prototype has been developed and implemented on the dataset of almost 30,000 top rated Android apps. DroidCC detects type-1, type-2 and type-3 clones in Android apps at the source code level. It also detects the similar code fragments, that were injected into many applications, which might be an indication of spreading malware. Meanwhile it can detect full and partial level similarity between applications. We evaluate DroidCC clone detection approach on real time data-set and count the Recall and Precision, which is quite significant. Furthermore, our results show that our approach is very efficient and effective in detecting different types of clones to check the similarity level in Android applications. Junaid Akram, Zhendong Shi, Majid Mumtaz, Ping Luo 0004 |
COMPSAC (1) | 1 |
| 2018 | DCCD: An Efficient and Scalable Distributed Code Clone Detection Technique for Big CodeabstractCode clone detection is a very hot topic in the field of software maintenance, reuseability and security.There is still a lack of techniques to detect near-miss clones at different level of granularities, especially in big code.This paper presents Distributed Code Clone Detection (DCCD) technique, which detects clones from big code bases based on feature extraction.We performed preprocessing, indexing and clone detection for almost 27 TB of source code (324 billion LOC), DCCD is quite faster and efficient as compared to existing distributed indexing and clone detection techniques, i.e. 36 times faster than Benjamin technique, which is 86 times faster than CCFinder.These two techniques are also distributed and just detect Type-1 and Type-2 clones, but our technique DCCD even detects Type-3 clones, efficiently.Our approach is faster, flexible, scalable and provides 87% accurate results with authenticity, ease of accessibility, upgradeability and maintainability. Junaid Akram, Zhendong Shi, Majid Mumtaz, Ping Luo 0004 |
SEKE | 1 |