Muna Al-Hawawreh

dblp:225/0813 · also Muna Sulieman Al-Hawawreh · DBLP profile ↗
← Back
16ranked-venue papers
12as first author
14since 2021 · last 2026
0000-0003-4690-2256ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 8 first-author · 9 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021
YearPublicationVenuePosition
2026 SAM: A privacy-preserving framework for selective attribute masking in voice recordings
abstract
Human voice is a rich source of information that can reveal a range of sensitive personal attributes, such as age, gender, and country of origin. With advances in Artificial Intelligence (AI), especially in speech processing, these personal attributes can now be inferred on a scale with high accuracy, raising serious privacy concerns. In fact, the ability to extract demographic or identification information from voice data poses risks related to surveillance, profiling, and misuse of personal data, highlighting the urgent need for privacy-preserving solutions in voice-based AI systems. Therefore, this paper proposes Selective Attribute Masking (SAM) , a new model-agnostic framework that uses gradient-based adversarial perturbations to suppress the inference of specific speaker attributes from voice recordings, while preserving the accuracy of non-target attributes and maintaining the utility of Automatic Speech Recognition (ASR). Experimental results using CommonVoice dataset demonstrate that SAM achieves selective masking success rates of up to 74.5 % for age, 59.4 % for gender, and 54.6 % for accent–substantially outperforming baseline methods. At the same time, voice utility (that is, ASR) remains largely unaffected, with the word error rate increasing by less than 3 % absolute under moderate perturbations. These findings demonstrate the effectiveness of our proposed framework (SAM) in balancing privacy and utility in voice-based systems.
Anil Pudasaini, Muna Al-Hawawreh, Mohamed Reda Bouadjenek, Hakim Hacid, Sunil Aryal
Expert Syst. Appl.2
2025 Hierarchical classification for intrusion detection system: Effective design and empirical analysis
abstract
The growing adoption of network technologies, particularly the Internet of Things (IoT), has led to the emergence of new and increasingly complex cyberattacks. To protect critical infrastructure from these evolving threats, it is essential to implement Intrusion Detection Systems (IDS) capable of accurately detecting a wide range of attacks while minimizing false alarms. While machine learning has been widely applied in IDS, most approaches rely on flat multi-class classification to distinguish between normal traffic and various attack types. However, cyberattacks often exhibit a hierarchical structure, where granular attack subtypes can be grouped under broader high-level categories—an aspect largely underexplored in IDS research. In this paper, we investigate the effectiveness of hierarchical classification in the context of IDS. We propose a three-level hierarchical classification model: the first level distinguishes between benign and attack traffic; the second level categorizes coarse-grained attack types; and the third level identifies specific, fine-grained attack subtypes. Our experimental evaluation, conducted using 10 different machine learning classifiers across 10 contemporary IDS datasets, reveals that hierarchical and flat classification approaches achieve comparable performance in terms of overall accuracy, precision, recall, and F1-score. However, flat classifiers are more likely to misclassify attack traffic as normal, whereas the hierarchical approach tends to misclassify one attack type as another. This distinction is critical, as failing to identify an attack altogether poses a greater risk to cybersecurity than incorrectly labeling its type. Thus, our findings highlight the value of hierarchical classification in enhancing the robustness of IDS, especially in environments where minimizing false negatives is paramount.
Ashraf Uddin 0004, Sunil Aryal, Mohamed Reda Bouadjenek, Muna Al-Hawawreh, Md. Alamin Talukder
Ad Hoc Networks4
2025 A dual-tier adaptive one-class classification IDS for emerging cyberthreats
abstract
In today’s digital age, our dependence on IoT (Internet of Things) and IIoT (Industrial IoT) systems has grown immensely, which facilitates sensitive activities such as banking transactions and personal, enterprise data, and legal document exchanges. Cyberattackers consistently exploit weak security measures and tools. The Network Intrusion Detection System (IDS) acts as a primary tool against such cyber threats. However, machine learning-based IDSs, when trained on specific attack patterns, often misclassify new emerging cyberattacks. Further, the limited availability of attack instances for training a supervised learner and the ever-evolving nature of cyber threats further complicate the matter. This emphasizes the need for an adaptable IDS framework capable of recognizing and learning from unfamiliar/unseen attacks over time. In this research, we propose a one-class classification-driven IDS system structured on two tiers. The first tier distinguishes between normal activities and attacks/threats, while the second tier determines if the detected attack is known or unknown. Within this second tier, we also embed a multi-classification mechanism coupled with a clustering algorithm. This model not only identifies unseen attacks but also uses them for retraining them by clustering unseen attacks. This enables our model to be future-proofed, capable of evolving with emerging threat patterns. Leveraging one-class classifiers (OCC) at the first level, our approach bypasses the need for attack samples, addressing data imbalance and zero-day attack concerns and OCC at the second level can effectively separate unknown attacks from the known attacks. Our methodology and evaluations indicate that the presented framework exhibits promising potential for real-world deployments.
Ashraf Uddin 0004, Sunil Aryal, Mohamed Reda Bouadjenek, Muna Al-Hawawreh, Md. Alamin Talukder
Comput. Commun.4
2025 A comprehensive study of audio profiling: Methods, applications, challenges, and future directions
abstract
Audio profiling is at the forefront of a technological breakthrough, offering rich insights into human behavior, emotions, physical attributes, and environmental contexts through detailed analysis of voice data. As we embrace an era where the integration of smart technologies equipped with the ability to capture sound is becoming ubiquitous, the capacity to accurately infer personal traits such as age, gender, height, weight, emotional state , personality, and even environmental contexts through voice analysis opens up vast opportunities across law enforcement, healthcare, social and commercial services, and entertainment. This emerging field promises to enhance our interaction with technology by not only understanding who we are but also by interpreting the world around us. However, the remarkable landscape is fraught with challenges, including data imbalances, the complexity of predictive models , and significant privacy concerns regarding the handling of sensitive paralinguistic information. This survey explores deep into the current landscape of audio profiling, examining the techniques and datasets in use, and showcasing its diverse applications while highlighting the need for advanced methodologies, enriched dataset development, and robust privacy preservation techniques.
Anil Pudasaini, Muna Al-Hawawreh, Mohamed Reda Bouadjenek, Hakim Hacid, Sunil Aryal
Neurocomputing2
2025 A Human-Centered Quantum Machine Learning Framework for Attack Detection in IoT-Based Healthcare Industry 5.0
abstract
Industry 5.0 aims to transform the healthcare sector by integrating emerging technologies like Artificial Intelligence (AI) and the Internet of Things (IoT) with a human-centered focus on patient wellness and preventive care. Although this approach promises personalized care and improved sustainability in healthcare systems, it also introduces cyber risks that could lead to economic and physical losses. This emphasizes the urgent need for enhanced cybersecurity measures in healthcare Industry 5.0 systems. Therefore, this paper presents a new framework for detecting cyberattacks while protecting patient data. The framework employs a human-centric approach and Quantum Random Forest (QRF) with local differential privacy for effective attack detection. It also integrates active learning with threat intelligence feeds and generative AI tools like ChatGPT to further support human roles and improve detection capabilities. We evaluated the efficiency of our proposed framework in terms of performance metrics such as accuracy, detection rate, time, and memory complexity. The experimental results show that our proposed framework excelled in attack detection using the ICU and WUST-EHMS-2020 datasets.
Muna Al-Hawawreh, M. Shamim Hossain
IEEE Internet Things J.1
2025 Quantum-Powered Extended Visibility for Zero-Trust-Based Ransomware Detection in Smart Grids
abstract
Technological evolution in the Industrial Internet of Things (IIoT) domain has fostered smart grid systems’ operation, performance, connectivity, and delivery with higher efficiency. However, it has also exposed the platform to a broader surface for attackers. Current information technology (IT)-centric solutions for detecting, preventing, and mitigating attacks have limitations, especially in comprehensively monitoring industrial control operational technology (OT) and communication systems. The rise of sophisticated cyberattacks, such as targeted ransomware, demand more robust security measures, leading to the emergence of zero trust (ZT) deployment as a response to these threats. This article proposes a new framework for implementing ZT comprising both IT and OT in smart grid infrastructures, with multiple security mechanisms and robust system coverage. We present an EigenGame algorithm for integrating diverse data sources into a rich-context format and an enhanced approach to quantum reinforcement learning for reliable malicious behavior detection in IIoT-enabled smart grids. The framework was evaluated using five sets of data from the X-IIoTID dataset, demonstrating its good performance in verifying any behavior inside the system and identifying any malicious behavior related ransomware attacks.
Muna Al-Hawawreh, Omar Shindi, Zubair A. Baig, Mamoun Alazab, Adnan Anwar, Robin Doss
IEEE Internet Things J.1
2024 Explainable deep learning for attack intelligence and combating cyber-physical attacks
abstract
Cyber-physical control loops comprising sensors, actuators and controllers pose the most valued and critical part of the industrial Internet of Things (IIoT) as it regulates the state of the physical process, such as water treatment or gas flow. Thus, any malicious activities could lead to physical damage, affecting human safety. Cyber-physical attacks against the physical process are difficult to detect using existing threats and attack intelligence due to the (1) lack of such intelligence for the physical process and operational technology systems and (2) such attacks affect the process parameters and states. Artificial Intelligence (AI)-based attack intelligence is required. This study proposes an attack intelligence framework for identifying cyber–physical attacks and extracting attack intelligence. We propose an attribution module for attack identification using various machine and deep learning algorithms. We also utilize Explainable AI (XAI) to improve the explainability of the attack attribution module and extract attack intelligence. Our proposed framework is evaluated and tested using a gas pipeline dataset as a use case. We demonstrate that the proposed framework improves the understanding of attacks and provides attack rules, assisting security analysts in securing critical physical processes.
Muna Al-Hawawreh, Nour Moustafa
Ad Hoc Networks1
2024 Securing the Industrial Internet of Things against ransomware attacks: A comprehensive analysis of the emerging threat landscape and detection mechanisms
Muna Al-Hawawreh, Mamoun Alazab, Mohamed Amine Ferrag, M. Shamim Hossain
J. Netw. Comput. Appl.1
2024 Digital twin-driven secured edge-private cloud Industrial Internet of Things (IIoT) framework
Muna Al-Hawawreh, M. Shamim Hossain
J. Netw. Comput. Appl.1
2024 A threat intelligence framework for protecting smart satellite-based healthcare networks
Muna Al-Hawawreh, Nour Moustafa, Jill Slay
Neural Comput. Appl.1
2023 Enhancing Security in Industrial IoT: A Taxonomy-driven Approach to Risk Assessment
abstract
The Industrial Internet of Things (IIoT) embodies the emerging fourth revolution, which strongly focuses on Machine-to-Machine (M2M) communications, big data, and predictive analytics. One of the major challenges associated with this deployment is physical and cyber security, as new emerging devices and technology have paved the way for new threat vectors, and current security measures have a limited endpoint focus and are inadequate to accommodate the broad scale of these emerged complex and distributed IIoT systems. To create secure and safe IoT systems, a comprehensive risk assessment that can span the entire physical and cyber stack of IIoT systems is needed. In this article, we investigate the current risk assessment frameworks, discuss their strengths and challenges, and show that current frameworks do not sufficiently work for IIoT deployments. We subsequently present a novel security taxonomy to supplement and address existing assessment frameworks' challenges. We validate this proposed taxonomy with extensive recent research literature.
Muna Al-Hawawreh, Robin Doss
TrustCom1
2022 Ultra Light-weight Encryption for Securing D2D Communication of ESP8266 IoT devices in Wireless Mesh Networks
abstract
System-on-chip (SoC) design is extensively used in the Internet of Things (IoT) devices, cyber-physical systems, and embedded systems. However, due to the increasing complexity of on-chip components and the long supply chain, SoC devices, such as ESP8266 IoT devices, are vulnerable to numerous cyberattacks. Consequently, developing and implementing security solutions for protecting these devices and their Device-to-Device (D2D) communications is increasingly becoming crucial. For the first time, this paper presents and investigates securing D2D communication of limited resources ESP8266 IoT devices in Wireless Mesh Network(WMN) using ultra light-weight encryption algorithms, including Speck Small and Diffie-Hellman key exchange using Curve 25519. This is important for protecting these limited-resources devices’ data confidentiality and integrity in critical applications. The experiment results prove that Speck Small and Curve25519 are more efficient than other core algorithms in computation time, demonstrating their suitability for ESP8266 IoT devices in WMN.
Muna Al-Hawawreh, Ibrahim Elgendi, Kumudu S. Munasinghe
ISNCC1
2022 X-IIoTID: A Connectivity-Agnostic and Device-Agnostic Intrusion Data Set for Industrial Internet of Things
abstract
Industrial Internet of Things (IIoT) is a high-value cyber target due to the nature of the devices and connectivity protocols they deploy. They are easy to compromise and, as they are connected on a large scale with high-value data content, the compromise of any single device can extend to the whole system and disrupt critical functions. There are various security solutions that detect and mitigate intrusions. However, as they lack the capability to deal with an IIoT’s co-existing heterogeneity and interoperability, developing new universal security solutions to fit its requirements is critical. This is challenging due to the scarcity of accurate data about IIoT systems’ activities, connectivities, and attack behaviors. In addition, owing to their multiplatform connectivity protocols and multivendor devices, collecting and creating such data are also challenging. To tackle these issues, we propose a holistic approach for generating an appropriate intrusion data set for an IIoT called X-IIoTID, a connectivity-agnostic and device-agnostic intrusion data set for fitting the heterogeneity and interoperability of IIoT systems. It includes the behaviors of new IIoT connectivity protocols, activities of recent devices, diverse attack types and scenarios, and various attack protocols. It defines an attack taxonomy and consists of multiview features, such as network traffic, host resources, logs and alerts. X-IIoTID is evaluated using popular machine and deep learning algorithms and compared with 18 intrusion data sets to verify its novelty.
Muna Al-Hawawreh, Elena Sitnikova, Neda Aboutorab
IEEE Internet Things J.1
2021 Developing a Security Testbed for Industrial Internet of Things
abstract
While achieving security for Industrial Internet of Things (IIoT) is a critical and nontrivial task, more attention is required for brownfield IIoT systems. This is a consequence of long life cycles of their legacy devices which were initially designed without considering security and IoT connectivity, but they are now becoming more connected and integrated with emerging IoT technologies and messaging communication protocols. Deploying today's methodologies and solutions in brownfield IIoT systems is not viable, as security solutions must co-exist and fit these systems' requirements. This necessitates a realistic standardized IIoT testbed that can be used as an optimal format to measure the credibility of security solutions of IIoT networks, analyze IIoT attack landscapes and extract threat intelligence. Developing a testbed for brownfield IIoT systems is considered a significant challenge as these systems are comprised of legacy, heterogeneous devices, communication layers and applications that need to be implemented holistically to achieve high fidelity. In this article, we propose a new generic end-to-end IIoT security testbed, with a particular focus on the brownfield system and provide details of the testbed's architectural design and the implementation process. The proposed testbed can be easily reproduced and reconfigured to support the testing activities of new processes and various security scenarios. The proposed testbed operation is demonstrated on different connected devices, communication protocols and applications. The experiments demonstrate that this testbed is effective in terms of its operation and security testing. A comparison with existing testbeds, including a table of features is provided.
Muna Al-Hawawreh, Elena Sitnikova
IEEE Internet Things J.1
2019 Targeted Ransomware: A New Cyber Threat to Edge System of Brownfield Industrial Internet of Things
abstract
Much value in a brownfield Industrial Internet of Things (IIoT) implementation resides at its edge tier, where new types of devices and technologies are deployed to interoperate the legacy industrial control systems with servers and systems in the cloud, and leverage the benefits of the Internet of Things technologies. One of these novel devices is the IIoT edge gateway, which is used to connect critical physical systems with the cyber world, and to provide consistent storage, processing, and analytical and controlling capabilities. However, these devices also come with new and advanced threats such as targeted ransomware. In this paper, we investigate this threat in detail. We studied the threat actors' motivations, the anatomy of ransomware for edge gateways, and the likelihood of such ransomware attack to happen in the future. We found that threat actors find IIoT edge gateways attractive ransomware targets due to their vital roles and functionalities in working with critical infrastructure and that the likelihood of such attack to occur is high. We built the first version of a ransomware security testbed for IIoT, and for test purposes, we developed a first version of ransomware target at IIoT edge gateway in a brownfield system. From our measurements we conclude that kernel-related activity parameters are significant indicators of the abnormal behavior caused by crypto-ransomware attacks in IIoT edge gateways, much more so even than for similar attacks in information technology server workstation. Thereby, some potential countermeasures for addressing targeted ransomware in IIoT systems are recommended as proactive strategies for dealing with attackers' new techniques and tactics.
Muna Al-Hawawreh, Frank T. H. den Hartog, Elena Sitnikova
IEEE Internet Things J.1
2018 Identification of malicious activities in industrial internet of things based on deep learning models
Muna Al-Hawawreh, Nour Moustafa, Elena Sitnikova
J. Inf. Secur. Appl.1