VLDB 2026 Research / reviewers in the wild / expert
Nasrin Sohrabi
dblp:231/1712
· DBLP profile ↗
14ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0002-8340-2261ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Split Learning With Local Epoch Regulation and Time-Aware DetectionabstractFederated learning (FL) has become a popular approach in Edge AI for extracting valuable knowledge within edge computing (EC) systems. To enhance AI application performance, large-scale models have gained increasing attention due to their strong generalization capabilities. However, training and transmitting such models impose substantial computational and communication overhead on resource-constrained clients at the edge, and exchanging complete models may also compromise model privacy. To alleviate these burdens and safeguard privacy, split learning (SL) has been introduced by combining data and model parallelism. Although SL alleviates resource constraints, it still encounters efficiency and security challenges in EC environments, where heterogeneous clients can slow down training without enhancing accuracy, and malicious clients may manipulate model behavior. To address these challenges, we propose a novel SL framework, CoDefend, which integrates local epoch regulation and time-aware detection. Specifically, local epoch regulation dynamically assigns heterogeneous clients with appropriate local epoch numbers to improve training efficiency, while time-aware detection provides an effective detection window to identify clients' malicious manipulation to improve model security. Moreover, CoDefend jointly optimizes these two strategies by leveraging their interdependence to further improve SL performance. Extensive experiments on both simulated and real-world platforms using NVIDIA Jetson edge nodes demonstrate that CoDefend achieves approximately 2× faster training speed than baseline methods, while maintaining comparable model accuracy and effectively identifying malicious manipulations even under collusion. Yao Zhao 0006, Zahir Tari, Nasrin Sohrabi, Qin Wang 0008, Xiaoyu Xia 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | DSPFL: A Deep-Layer Sign Sharing Personalized Federated Learning Scheme for Mitigating Poisoning AttacksabstractWith the rise of the smart industry, machine learning (ML) has become a popular method to improve the security of the Industrial Internet of Things (IIoT) by training anomaly detection models. Federated learning (FL) is a distributed ML scheme that facilitates anomaly detection on IIoT by preserving data privacy and breaking data silos. However, poisoning attacks pose significant threats to FL, where adversaries upload poisoned local models to the aggregation server, thereby degrading model accuracy. The prevalence of non-independent and identically distributed (non-IID) data across IIoT devices further exacerbates this threat, as it naturally leads to diverse local models, making malicious ones harder to distinguish. To address the above challenges, we propose a deep-layer sign-sharing personalized FL (DSPFL) scheme. DSPFL innovatively aggregates only the signs of stochastic gradients (SignSGD) from the deep layers of local models during training. This targeted aggregation enhances the robustness of the shared components against poisoning attacks, while shallow layers are retained locally to preserve personalization. This integrated approach improves the accuracy and resilience of personalized local models on IIoT devices under poisoning attacks. Extensive experimental results show that DSPFL consistently achieves up to 20% higher and more stable overall personalized model accuracy compared to state-of-the-art methods under specific poisoning attacks. Chenhao Xu 0003, Nasrin Sohrabi, Youyang Qu, Hai Dong 0001, Zahir Tari, Xun Yi |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2026 | FedGDD: Defending Federated Learning Against Targeted Model Poisoning Sybil Attacks Based on Gradient Drift DetectionabstractSybil attacks pose a significant threat to federated learning, as malicious nodes can collaborate to form a majority and overwhelm the system. Therefore, developing effective countermeasures is essential to ensure the security of federated learning systems. To address this challenge, we introduce a novel targeted model poisoning defence method for federated learning, named Gradient Drift Detection (FedGDD). Unlike existing approaches, such as clustering, statistical analysis, and re-training, which struggle in scenarios where malicious nodes constitute the majority, FedGDD reframes malicious detection as a gradient drift detection problem. This approach identifies potential attacks by detecting deviations in gradients, operating on the premise that the loss functions for benign and malicious nodes are inherently different. Extensive experimental evaluations demonstrate the efficacy of FedGDD compared to six well-established methods: Flame, FLTrust, FedCPA, Median, Krum, and FL-WBC. Using tasks from both image classification and natural language processing, the experiments confirm that FedGDD is robust and independent of specific application settings. Results show that FedGDD effectively safeguards federated learning systems across a wide range of malicious node ratios. Specifically, FedGDD maintains a low attack success rate for malicious nodes when their ratio ranges from 0.2 to 0.8. Additionally, it preserves high model accuracy when the malicious node ratio is between 0.2 and 0.5. These findings highlight FedGDD's potential to enhance the reliability and performance of Federated Learning systems. Hai Dong 0001, Nasrin Sohrabi, Zahir Tari |
IEEE Trans. Reliab. | 3 |
| 2025 | ERT: Data placement based on estimated response time for P2P storage systems
Fitrio Pakana, Nasrin Sohrabi, Hai Dong 0001, Zahir Tari, Nour Moustafa |
J. Parallel Distributed Comput. | 2 |
| 2025 | Intelligent Edge Data Integrity Verification With Dynamic Unreliable Data Replica SelectionabstractWith the advancement of Mobile Edge Computing (MEC), App vendors are increasingly motivated to cache multiple data replicas on geographically distributed edge servers to ensure rapid responses for latency-sensitive applications. However, the security of data replicas is a critical concern due to the dynamic nature and resource limitations of MEC environments. To this end, data replicas’ integrity must be regularly verified to maintain the accuracy of data-driven decision-making. Existing Edge Data Integrity (EDI) verification solutions suffer from low efficiency due to relying on indiscriminative verification, where all data replicas are checked at each round without considering their inherent reliability characteristics. This paper designs an Intelligent framework called I-EDI, which enables discriminative EDI verification by integrating a novel Long-term Unreliable data Replica Selection (L-URS) mechanism. This framework aims to reduce verification costs without compromising accuracy, while resisting spoofing, forgery, outsourcing, collusion, alteration-before-verification, delayed-response, and adaptive attacks. Specifically, each data replica is associated with a reliability representation by evaluating its long-term performance. Based on that, the L-URS problem is defined as stochastically minimizing the global reliability representation over time, subject to constraints on the number of data replicas to be verified. To make it easy-to-handle, the L-URS problem is decomposed into a series of online minimization problems. An Online Opportunistic-based Replica Selection approach called O2RS is developed. O2RS allows App vendors to significantly decrease verification costs by targetedly inspecting unreliable data replicas. Moreover, this work provides a thorough theoretical analysis of O2RS’s time complexity and approximation bound, as well as I-EDI’s security. Extensive experiments are conducted to validate the effectiveness and efficiency of O2RS and I-EDI. The results demonstrate that, compared to commonly used alternatives, O2RS achieves an approximate 50% improvement in selection efficiency, while I-EDI reduces verification costs by 1.23 times on average. Yao Zhao 0006, Youyang Qu, Nasrin Sohrabi, Md. Redowan Mahmud, Zahir Tari |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | A Predictive Profiling and Performance Modeling Approach for Distributed Stream Processing in EdgeabstractThe advent of edge computing has allowed the continuously generated data to be processed closer to their sources instead of being sent to the cloud for processing. Given the heterogeneous and limited computational resources and dynamic nature of edge computing, stream processing systems need an accurate and easily accessible performance modeling/measurement to perform efficiently in edge environments. This paper proposes a predictive profiling model to enable measuring the performance of a system by predicting the operators' processing time on heterogeneous devices without having to carry out the testing on individual devices. This profiling model comprises a quadratic function to generate CPU clock speed/processing time curves for each operator. By using these curves, the model predicts the processing times of operators without requiring any extra profiling runs. Moreover, a performance model is proposed to deal with (performance) degradation of stream processing applications by modeling their topologies as systems comprising M/M/1 queues. The model uses the performance expectations of queueing models to define the data transfer rates inside topologies and uses Integer Linear Programming to specify the maximum input rate and an operator placement plan that can process that input rate. Experimental results showed that the profiling approach predicts the processing times of 17 operators with an average error rate of 5%. The performance model finds the maximum input rate accurately, while the operator placement plan achieves up to 84% higher throughput and 70% less latency in AWS EC2 instances and 257% higher throughput and 66% less latency in real hardware compared to the default resource-aware scheduler of Apache Storm. Hasan Geren, Nasrin Sohrabi, Zahir Tari, Nour Moustafa |
ICDE | 2 |
| 2024 | A Query Language to Enhance Security and Privacy of Blockchain as a Service (BaaS)
Nasrin Sohrabi, Norrathep Rattanavipanon, Zahir Tari |
ICSOC (2) | 1 |
| 2024 | Request Dispatching Over Distributed SDN Control Plane: A Multiagent ApproachabstractSoftware-defined networking (SDN) allows flexible and centralized control in cloud data centers. An elastic set of distributed SDN controllers is often required to provide sufficient yet cost-effective processing capacity. However, this introduces a new challenge: Request Dispatching among the controllers by SDN switches. It is essential to design a dispatching policy for each switch to guide the request distribution. Existing policies are designed under certain assumptions, including a single centralized agent, global network knowledge, and a fixed number of controllers, which often cannot be satisfied in practice. This article proposes MADRina, Multiagent Deep Reinforcement Learning for request dispatching, to design policies with high dispatching adaptability and performance. First, we design a multiagent system to address the limitation of using a centralized agent with global network knowledge. Second, we propose a Deep Neural Network-based adaptive policy to enable request dispatching over an elastic set of controllers. Third, we develop a new algorithm to train the adaptive policies in a multiagent context. We prototype MADRina and build a simulation tool to evaluate its performance using real-world network data and topology. The results show that MADRina can significantly reduce response time by up to 30% compared to existing approaches. Victoria Huang 0001, Gang Chen 0002, Xingquan Zuo, Albert Y. Zomaya, Nasrin Sohrabi, Zahir Tari, Qiang Fu 0011 |
IEEE Trans. Cybern. | 5 |
| 2023 | RADAR: Reactive Concept Drift Management with Robust Variational Inference for Evolving IoT Data StreamsabstractThe accuracy and performance of Machine Learning (ML) models can gradually or even suddenly degrade when the underlying statistical distribution of data streams changes over time; this is known as concept drift. This phenomenon could adversely affect the IoT data management and analysis landscape that relies intensely on data-driven cognitive technologies. Therefore, concept drift should be detected immediately, which is challenging due to the increasing number of dimensional features and lack of ground truth. Its adaptive countermeasures also become difficult to design when data streams are being generated frequently and require latency-sensitive responses. The uncertainty and time dependencies characteristics of IoT data streams further intensify the complexity of concept drift management. This work proposes a reactive drift management framework named RADAR for streaming IoT applications that can simultaneously detect and react to concept drift using two novel methods: temporal discrepancy measure, and intensity-aware analyser. Collectively, these methods help to determine the adaptation decision to ensure reliable performance, thereby limiting the scope of the frequent ML model update. Experiments conducted using synthetic and real-world setups comprising end-to-end systems demonstrate that RADAR outperforms other benchmarks in achieving better improvement of the performance with the best F-score of 0.86, and obtaining efficient runtime with large data streams. Abdullah Alsaedi, Nasrin Sohrabi, Md. Redowan Mahmud, Zahir Tari |
ICDE | 2 |
| 2023 | An Explainable Deep Learning Framework for Resilient Intrusion Detection in IoT-Enabled Transportation NetworksabstractThe security of safety-critical IoT systems, such as the Internet of Vehicles (IoV), has a great interest, focusing on using Intrusion Detection Systems (IDS) to recognise cyber-attacks in IoT networks. Deep learning methods are commonly used for the anomaly detection engines of many IDSs because of their ability to learn from heterogeneous data. However, while this type of machine learning model produces high false-positive rates and the reasons behind its predictions are not easily understood, even by experts. The ability to understand or comprehend the reasoning behind the decision of an IDS to block a particular packet helps cybersecurity experts validate the system’s effectiveness and develop more cyber-resilient systems. This paper proposes an explainable deep learning-based intrusion detection framework that helps improve the transparency and resiliency of DL-based IDS in IoT networks. The framework employs a SHapley Additive exPlanations (SHAP) mechanism to interpret decisions made by deep learning-based IDS to experts who rely on the decisions to ensure IoT networks’ security and design more cyber-resilient systems. The proposed framework was validated using the ToN_IoT dataset and compared with other compelling techniques. The experimental results have revealed the high performance of the proposed framework with a 99.15% accuracy and a 98.83% F1 score, illustrating its capability to protect IoV networks against sophisticated cyber-attacks. Ayodeji Oseni, Nour Moustafa, Gideon Creech, Nasrin Sohrabi, Andrew Strelzoff, Zahir Tari, Igor Linkov |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2023 | AI-Enabled Secure Microservices in Edge Computing: Opportunities and ChallengesabstractThe paradigm of edge computing has formed an innovative scope within the domain of the Internet of Things (IoT) through expanding the services of the cloud to the network edge to design distributed architectures and securely enhance decision-making applications. Due to the heterogeneous, distributed and resource-constrained essence of edge Computing, edge applications are required to be developed as a set of lightweight and interdependent modules. As this concept aligns with the objectives of microservice architecture, effective implementation of microservices-based edge applications within IoT networks has the prospective of fully leveraging edge nodes capabilities. Deploying microservices at IoT edge faces plenty of challenges associated with security and privacy. Advances in Artificial Intelligence (AI) (especially Machine Learning), and the easy access to resources with powerful computing providing opportunities for deriving precise models and developing different intelligent applications at the edge of network. In this study, an extensive survey is presented for securing edge computing-based AI Microservices to elucidate the challenges of IoT management and enable secure decision-making systems at the edge. We present recent research studies on edge AI and microservices orchestration and highlight key requirements as well as challenges of securing Microservices at IoT edge. We also propose a Microservices-based edge computing framework that provides secure edge AI algorithms as Microservices utilizing the containerization technology to offer automated and secure AI-based applications at the network edge. Firas Al-Doghman, Nour Moustafa, Ibrahim Khalil 0001, Nasrin Sohrabi, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | SAZyzz: Scaling AZyzzyva to Meet Blockchain RequirementsabstractWe present SAZyzz, a leader-based Byzantine Fault Tolerant consensus protocol for partially synchronous networks. SAZyzz exhibits a better performance/scalability compared to the state-of-the-art leader-based BFT consensus protocols. It is built on top of AZyzzyva and has adopted a tree-based communication model which enables it to enhance the scalability of AZyzzyva. Additionally, SAZyzz reduces the communication complexity toO(logN) in two paths of the protocol. However, the tree-based topology has been argued that has a shortcoming when used in designing BFT consensus protocols. This refers to the strong assumption that all the internal nodes of the tree are honest, which leads to a trade-off between tolerating Byzantine faults and better performance and scalability. This paper shows that, with the current technological infrastructures available for industrial systems, such as Trusted Execution Environment (TEE) and Public Key Infrastructure (PKI), this assumption is realistic. SAZyzz comprises of fast-path and backup-path, each of which has two modes:simple modeandscalable mode. To demonstrate the efficiency and feasibility of SAZyzz's adoption for blockchain systems, we designed and implemented the ZyConChain blockchain system based on SAZyzz. The evaluation results show that SAZyzz can significantly improve the performance/scalability of blockchain systems. Nasrin Sohrabi, Zahir Tari, Gauthier Voron, Vincent Gramoli, Qiang Fu 0011 |
IEEE Trans. Serv. Comput. | 1 |
| 2020 | On The Scalability of Blockchain SystemsabstractBlockchain, as a promising solution to develop secure distributed ledgers, has drawn a huge attention over the last decade. By introducing a pseudonymous payment model with no central authority, blockchain marked the new generation of online payment systems, known as Cryptocurrencies. For most of the existing cryptocurrencies, scalability has become a challenging problem. When dealing with an ever increasing number of users, miners, and transactions, the technology is unable to scale and provide the same performance as centralised systems (e.g. centralised payment systems).Without addressing this fundamental scalability problem, such a promising technology may not be able to be adopted in mainstream. This paper provides an attempt to analyse the scalability of existing blockchain protocols and look at the major factors affecting scalability, namely throughput and latency. We also describe the HTNZ protocol, a new approach to improve the scalability of Satoshi Nakamoto's model [1], validated by experimental results. HTNZ introduces two new components, namely, sideBlock and helper. SideBlock has a slightly different structure of block and increases the number of transactions that can be processed per each interval. Nasrin Sohrabi, Zahir Tari |
IC2E | 1 |
| 2018 | DTFA: A Dynamic Threshold-Based Fuzzy Approach for Power-Efficient VM ConsolidationabstractDynamic virtual machine (VM) consolidation is considered an effective approach for improving power consumption and computing resource utilization in cloud-based data centers. However, the ever-changing workload in a data center makes it difficult for VM consolidation to prevent service level agreement (SLA) violations and optimize power consumption. Detection of overutilized and underutilized physical machines (PMs) plays a significant role in effective VM consolidation, immediately improving resource utilization, SLA violations, and power consumption. This paper presents a new proposal for the dynamic adjustment of threshold values that aims to minimize the number of migrations in varying workload environments. The proposed approach, named the `dynamic threshold-based fuzzy approach' (DTFA), is a fuzzy threshold-based approach used for adjusting the threshold values of PMs in a cloud environment. The proposed approach allows the number of migrations caused by overloading to be reduced and SLAs to be met. Three sets of experiments with different workloads were conducted to validate the proposed approach. The results demonstrate that DTFA outperforms existing solutions by an average of 22.52%, 45.63% and 56.68% in power consumption, VM migration count, and SLA violations, respectively. Deafallah Alsadie, Eidah J. Alzahrani, Nasrin Sohrabi, Zahir Tari, Albert Y. Zomaya |
NCA | 3 |