VLDB 2026 Research / reviewers in the wild / expert
Sena Hounsinou
dblp:228/4900 · also Sena G. Hounsinou
· DBLP profile ↗
20ranked-venue papers
2as first author
20since 2021 · last 2026
0000-0002-4187-6135ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 7 since 2021Security and privacy · 5 · 5 since 2021Computer networks · 4 · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Federated DDoS Detection with Clustered Quantization-Aware Training Models for IoRTabstractIoRT systems, which operate with microcontroller-class processors and limited memory (≤ 2MB), require real-time DDoS detection. However, existing federated learning approaches cannot simultaneously achieve the necessary model compression, DP, and communication efficiency for resource-constrained deployments. This paper presents a novel federated learning framework that resolves these conflicting requirements through an integrated QAT approach with DP-based clustering.Our approach achieves 4.0x model compression (0.52MB to 0.13MB) with only 0.79% accuracy degradation compared to uncompressed federated baselines, while maintaining F1-scores (0.998). Evaluation against methods such as FedProx, DeepShield, and AUWPAE on CICIoT2023 demonstrates the advantage of our approach: 433x faster inference than centralized ensemble methods (0.15ms vs. 65ms) with a 75% reduction in federated communication overhead. The DP_Clustering successfully handles non-IID data heterogeneity while providing formal privacy guarantees unavailable in centralized approaches. Matilda Nkoom, Daniel Commey, Yousef Alsenani, Sena Hounsinou, Garth V. Crosby |
CCNC | 4 |
| 2026 | Schedule-Based Attack Against TSN TAS with Frame PreemptionabstractTime-Sensitive Networking (TSN) achieves deterministic communication using mechanisms like Time-Aware Shaping, which manages the timing of network traffic streams using a Gate Control List (GCL). The GCL operates according to a cyclic schedule by opening and closing gates for priority (egress) queues in out-bound ports. However, the cyclic schedule in the GCL introduces potential security vulnerabilities to schedule-based attacks. This type of attack exploits TSN’s deterministic schedules to manipulate traffic flow and can impact availability and safety. Traditional intrusion detection systems (IDS) are commonly employed in TSN to detect malicious activities by monitoring traffic patterns and bandwidth usage. However, schedule-based attacks can align malicious packets with legitimate traffic, making the attack more stealthy and harder to detect by rate-based IDS. This paper presents a novel schedule-based attack that synchronizes malicious traffic to exploit predictability in TSN’s GCL schedule. This attack causes an adversarial blocking in which low-priority traffic delays higher-priority traffic without being detected using a rate-based IDS. We demonstrate the feasibility and impact of this schedule-based attack on TSN with off-the-shelf hardware. Omolade Ikumapayi, Vijay Banerjee, Sena Hounsinou, Gedare Bloom |
ECRTS | 3 |
| 2026 | Fusing Vessel Behavior and Weather Context for Real-time Attribution of AIS Dropouts
Kamel Abbad, Daniel Commey, Sena Hounsinou, Lyes Khoukhi, Lionnel Mesnil, Garth V. Crosby |
ICC | 3 |
| 2026 | PUFZIN: Secure and scalable blockchain-IoT with PUFs and zero-knowledge proofs
Daniel Commey, Sena Hounsinou, Garth V. Crosby |
J. Inf. Secur. Appl. | 2 |
| 2026 | On Evading Randomization-Based Defense in Hierarchical Real-Time SystemsabstractSecurity for real-time systems is increasingly important with the growth of connected real-time systems in safety-critical domains such as automotive, medical, and avionics. A crucial aspect of securing such systems is to understand the attacks that the current techniques cannot effectively safeguard against. Especially relevant are vulnerabilities of real-time systems arising from their rigid temporal guarantees and attacks that exploit such vulnerabilities. Randomization-based defense techniques can reduce side-channel inference, but such techniques are limited due to the strict timing bounds of real-time systems. In this article, we design and analyze NosyNeighbor , an inter-partition side-channel attack that exploits the timing guarantees of real-time systems to infer the timing parameters of a safety-critical task in a hierarchical system. Using an adaptive technique, NosyNeighbor can improve its inference over time and evade randomization-based defense. Experimental results show that NosyNeighbor can infer victim task execution with a precision of roughly 73% under normal system load, and with a recall of about 35% using multiple malicious tasks across partitions. NosyNeighbor is also effective under the common attack model with two malicious tasks in the system, with a precision of 64%. Vijay Banerjee, Sena Hounsinou, Yanyan Zhuang, Monowar Hasan, Gedare Bloom |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2025 | Work-in-Progress: Vulnerability of TSN TAS with Frame Preemption to Schedule-Based AttackabstractTime-Sensitive Networking enables deterministic communication in cyber-physical systems using time-aware shapers governed by Gate Control Lists (GCL). Although this mechanism improves reliability, it also introduces vulnerabilities exploitable through schedule-based attacks. We show that, by analyzing traffic patterns, adversaries can estimate GCL parameters and reconstruct the schedule to inject precisely timed traffic. These injections can cause priority inversions, where low-priority flows delay high-priority traffic, degrading latency and schedulability. Such schedule-based attacks are particularly stealthy as conventional Intrusion Detection Systems (IDS) may fail to detect them. We implement this attack and conduct randomized experiments to evaluate the impact on synthetic workloads and on off-the-shelf hardware. Omolade Ikumapayi, Vijay Banerjee, Sena Hounsinou, Gedare Bloom |
RTSS | 3 |
| 2025 | Securing the Internet of Robotic Things (IoRT) against DDoS Attacks: A Federated Learning with Differential Privacy Clustering Approach
Matilda Nkoom, Sena Hounsinou, Garth V. Crosby |
Comput. Secur. | 2 |
| 2025 | Blockchain-enabled dynamic honeypot conversion for resource-efficient IoT security
Daniel Commey, Matilda Nkoom, Sena Hounsinou, Garth V. Crosby |
J. Inf. Secur. Appl. | 3 |
| 2024 | MCFICS: Model-based Coverage-guided Fuzzing for Industrial Control System Protocol ImplementationsabstractIndustrial control system (ICS) protocols face the threat of adversaries launching cyber-physical attacks against protocol endpoints. Vulnerability discovery approaches such as fuzzing can be effective at reducing the risk of such threats. In this paper, we present MCFICS, a coverage-guided greybox fuzzing framework that uses (1) active automata learning for stochastic reactive systems to infer the state machine of a stateful ICS protocol server implementation, and (2) guided fuzzing to explore the state space using this learned state machine. During fuzzing, new input sequences that increase code coverage are used to improve the state space exploration of the ICS protocol implementations. We implemented and tested MCFICS with six example server implementations spanning three widely used ICS protocol implementations. Experimental results show that MCFICS achieves higher branch coverage than the AFLNwe, AFLNet and StateAFL fuzzers by an average (mean of means) of 15.82%, 1.99%, and 37.52%, respectively, with an overall average of 18.44% increased branch coverage. Furthermore, using MCFICS we discovered a new bug in a protocol implementation that we have reported to its upstream maintainer. Uchenna Ezeobi, Sena Hounsinou, Habeeb Olufowobi, Yanyan Zhuang, Gedare Bloom |
IECON | 2 |
| 2024 | Securing Blockchain-based IoT Systems with Physical Unclonable Functions and Zero-Knowledge ProofsabstractThis paper presents a framework for securing blockchain-based IoT systems by integrating Physical Unclonable Functions (PUFs) and Zero-Knowledge Proofs (ZKPs) within a Hyperledger Fabric environment. Our approach leverages PUFs for robust device authentication and ZKPs for privacy-preserving transaction processing, addressing key challenges of security, privacy, and scalability in IoT systems. The framework’s architecture utilizes Hyperledger Fabric’s modular design and private channels to enhance scalability. Off-chain experimental results demonstrate the framework’s feasibility, with compact proof sizes (median 805 bytes) and efficient processing times (average 2,800 ms end-to-end). A comprehensive security analysis shows the framework’s resilience against various attacks, including device impersonation and data tampering. This work provides a foundation for secure and scalable blockchain-based IoT systems, with directions for future on-chain implementation and optimization for resource-constrained devices. Daniel Commey, Sena Hounsinou, Garth V. Crosby |
LCN | 2 |
| 2024 | Securing the Internet of Robotic Things: A Federated Learning ApproachabstractThis paper addresses the challenge of Distributed Denial of Service (DDoS) attacks in the Internet of Robotic Things (IoRT) using a federated learning approach. We investigate the performance of Convolutional Neural Networks (CNNs), Long Short-Term Memory (LSTM) networks, and Gated Recurrent Units (GRUs) for DDoS detection in IoRT systems. Our models are evaluated using the CICDDoS2019 dataset. The CNN-based model achieves the highest performance with an accuracy of 0.9810 and an F1-score of 0.9800, outperforming LSTM and GRU-based models. We analyze the models’ convergence properties and discuss their suitability for resource-constrained IoRT devices. Our results demonstrate the potential of federated learning for enhancing IoRT security while highlighting the trade-offs between model performance and efficiency. Matilda Nkoom, Daniel Commey, Sena Hounsinou, Garth V. Crosby |
LCN | 3 |
| 2024 | D-NDNoT: Deterministic Named Data Networking for Time-Sensitive IoT ApplicationsabstractNamed Data Networking (NDN) revolutionized IP-based communication by introducing a content-centric model, based on name-based communication. This paradigm shift offers benefits, including optimized network traffic through in-network caching, improved data security, and resilient communication for Internet of Things (IoT) applications. While these benefits are significant, the deterministic data delivery necessary for time-sensitive IoT applications cannot be guaranteed using the NDN’s best-effort routing mechanism. This paper addresses this challenge by proposing deterministic NDN of things (D-NDNoT), a protocol-level integration of a schedulability algorithm into NDN, making it deadline-aware and addressing the specific requirements of time-sensitive IoT applications. We present a time-sensitive NDN protocol incorporating a critical deadline-first scheduler to prioritize traffic. By integrating deadline awareness, quality of service metrics, and network characteristics, the algorithm ensures the delivery of time-sensitive data takes precedence over non-time-sensitive content. To validate the effectiveness of the proposed protocol, we evaluate using simulation experiments in OMNET++ and consider metrics such as end-to-end latency, delay, and deadline. The results demonstrate that the deadline-aware deterministic NDN protocol effectively meets the communication needs of time-sensitive IoT applications, ensuring the timely delivery of critical data. Afia Anjum, Paul Agbaje, Sena Hounsinou, Nadra Guizani, Habeeb Olufowobi |
IEEE Internet Things J. | 3 |
| 2024 | From Weeping to Wailing: A Transitive Stealthy Bus-Off AttackabstractThe integration of the Internet of Things (IoT) devices and solutions into passenger vehicles has transformed cars into a complex system with intelligence and a platform for extending information technology possibilities. These devices communicate through in-vehicle networks that use the controller area network (CAN) as a de facto standard for the safety-critical functionality of the vehicles. One creative exploit against CAN is the bus-off attack, which uses the fault tolerance capabilities of the CAN bus to coerce a victim electronic control unit (ECU) into the bus-off state from which it is not allowed to access the bus. As a result, the victim ECU is unable to send or receive messages. The WeepingCAN attack is a stealthy variation of the bus-off attack that reduces its observability and therefore the effectiveness of detection-based mitigation. In this paper, we introduce three software-based improvements that greatly increase both the efficiency and effectiveness of the WeepingCAN attack. First, we introduce a novel zero-phase approach for synchronizing the attack. Second, we discover an alternative approach to disable retransmissions, which is a key capability of WeepingCAN, that allows the attack to be conducted from more ECUs than before. Third, we identify a transitive attack strategy that enables an attacker to target many more ECUs than originally possible. We evaluate our improvements experimentally using a CAN benchmark and find that the zero-phase synchronization improves the attack success rate from 75% to over 90% and the transitive attack strategy enables all the ECUs in the benchmark to be attacked. Paul Agbaje, Habeeb Olufowobi, Sena Hounsinou, Gedare Bloom |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2023 | Privacy-Preserving Intrusion Detection System for Internet of Vehicles using Split LearningabstractThe Internet of Vehicles (IoV) is envisioned to improve road safety, reduce traffic congestion, and minimize pollution. However, the connectedness of IoV entities increases the risk of cyber attacks, which can have serious consequences. Traditional intrusion detection systems (IDS) transfer large amounts of raw data to central servers, leading to potential privacy concerns. Also, training IDS on resource-constrained IoV devices generally can result in slower training times and poor service quality. To address these issues, we propose a split learning-based privacy-preserving IDS that deploys IDS on edge devices without sharing sensitive raw data. In addition, we propose a regret minimization-based adaptive offloading technique that reduces the training time on resource-constrained devices. Our approach effectively detects anomalous behavior while preserving data privacy and reducing training time, making it a practical solution for IoV. Experimental results show the effectiveness of our approach and its potential to enhance the security of the IoV network. Paul Agbaje, Afia Anjum, Arkajyoti Mitra, Sena Hounsinou, Ebelechukwu Nwafor, Habeeb Olufowobi |
BDCAT | 4 |
| 2023 | Work-in-Progress: Deadline-Aware Named Data Networking for Time-Sensitive IoT ApplicationsabstractNamed Data Networking (NDN) has evolved as a networking model that can facilitate Internet of Things (IoT) applications by providing a name-based communication model, innetwork caching, and inherent support for data-centric security. However, despite the benefits, the best-effort NDN cannot offer the deterministic data delivery required by safety-critical IoT applications. This paper proposes a novel deadline-aware NDN protocol that utilizes a critical deadline first scheduler to prioritize traffic based on the approaching deadline. Evaluation results show that the proposed deadline-aware NDN can meet the communication needs of time-sensitive IoT applications. Afia Anjum, Sena Hounsinou, Habeeb Olufowobi |
RTAS | 2 |
| 2023 | Sidecar-based Path-aware Security for MicroservicesabstractMicroservice architectures decompose web applications into loosely-coupled, distributed components that interact with each other to provide an overall service. While this popular software architecture paradigm has many advantages in development and deployment, it also introduces a wider attack surface that is vulnerable to both internal and external attackers. Potentially malicious third-party services or software packages, as well as increased communication endpoints, introduce a wide array of security concerns. To improve the resiliency of microservice-based applications, many of which store sensitive data, we propose a novel, path-based anomaly detection and access control infrastructure that requires no modifications to existing software. We propose leveraging trusted proxies deployed alongside each service for request inspection, anomaly detection and signed token propagation for end-user path validation. Our approach reduces the trusted computing base away from the microservices to a smaller set of components that allow for less trust and a smaller attack surface. Catherine Meadows 0002, Sena Hounsinou, Timothy Wood 0001, Gedare Bloom |
SACMAT | 2 |
| 2022 | Poster: Toward Zero-Trust Path-Aware Access ControlabstractIn this poster, we introduce path-aware risk scores for access control (PARSAC), a novel context-sensitive technique to enrich access requests with risk scoring of the path taken by those requests between the authenticated user and the resources they access. These path-aware risk scores enable another layer of security for traditional access control systems that addresses the need for fine-grained monitoring and enforcement within a zero-trust architecture. We define rules for general functions that can be used to determine risk and instantiate a specific approach to calculate path risk scores. We evaluate our approach with realistic network graphs; PARSAC finds more paths with lower risk when compared with traditional routing algorithms that select the shortest path. Joshua H. Seaton, Sena Hounsinou, Timothy Wood 0001, Shouhuai Xu, Philip N. Brown, Gedare Bloom |
SACMAT | 2 |
| 2021 | Strong APA scheduling in a real-time operating system: work-in-progressabstractArbitrary processor affinities are used in multiprocessor systems to specify the processors on which a task can be scheduled. However, affinity constraints can prevent some high priority real-time tasks from being scheduled, while lower priority tasks execute. This paper presents an implementation and evaluation of the Strong Arbitrary Processor Affinity scheduling on a real-time operating system, an approach that not only respects user-defined affinities, but also supports migration of a higher priority task to allow execution of a task limited by affinity constraints. Results show an improvement in response and turnaround times of higher priority tasks. Richi Dubey, Vijay Banerjee, Sena Hounsinou, Gedare Bloom |
EMSOFT | 3 |
| 2021 | Work-in-Progress: Enabling Secure Boot for Real-Time Restart-Based Cyber-Physical SystemsabstractSeveral cyber-physical systems use real-time restart-based embedded systems with the Simplex architecture to provide safety guarantees against system faults. Some approaches have been developed to protect such systems from security violations too, but none of these approaches can prevent an adversary from modifying the operating system or application code to execute an attack that persists even after a reboot. In this work, we present a secure boot mechanism to restore real-time restart-based embedded systems into a secure computing environment after every restart. We analyze the delay introduced by the proposed security feature and present preliminary results to demonstrate the viability of our approach using an open-source bootloader and real-time operating system. Sena Hounsinou, Vijay Banerjee, Chunhao Peng, Monowar Hasan, Gedare Bloom |
RTSS | 1 |
| 2021 | Vulnerability of Controller Area Network to Schedule-Based AttacksabstractThe secure functioning of automotive systems is vital to the safety of their passengers and other roadway users. One of the critical functions for safety is the controller area network (CAN), which interconnects the safety-critical electronic control units (ECUs) in the majority of ground vehicles. Unfortunately CAN is known to be vulnerable to several attacks. One such attack is the bus-off attack, which can be used to cause a victim ECU to disconnect itself from the CAN bus and, subsequently, for an attacker to masquerade as that ECU. A limitation of the bus-off attack is that it requires the attacker to achieve tight synchronization between the transmission of the victim and the attacker’s injected message. In this paper, we introduce a schedule-based attack framework for the CAN bus-off attack that uses the real-time schedule of the CAN bus to predict more attack opportunities than previously known. We describe a ranking method for an attacker to select and optimize its attack injections with respect to criteria such as attack success rate, bus perturbation, or attack latency. The results show that vulnerabilities of the CAN bus can be enhanced by schedulebased attacks. Sena Hounsinou, Mark Stidd, Uchenna Ezeobi, Habeeb Olufowobi, Mitra Nasri, Gedare Bloom |
RTSS | 1 |