Muhammad Mudassar Yamin

dblp:233/3100 · DBLP profile ↗
← Back
12ranked-venue papers
7as first author
10since 2021 · last 2026
0000-0001-5264-7613ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 6 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Securing large language models: A quantitative assurance framework approach
abstract
Large Language Models (LLMs) are increasingly integrated into sensitive domains such as healthcare and autonomous systems, yet adoption is constrained by security risks that conventional assurance methods do not capture. Traditional software assurance techniques are inadequate for LLM-specific vulnerabilities, including prompt injection, insecure output handling, and training data poisoning. We introduce a quantitative security assurance framework for LLM applications that translates security requirements and vulnerabilities into measurable scores. The framework computes an Assurance Metric (AM) as A M = R M − V M , where VM is weighted using CVSS v4.0, and maps results to five security assurance levels, making security posture comparable, auditable, and actionable. Requirements span input/output validation, training data, development and deployment, access control, third-party services, and security procedures; vulnerability tests align with the OWASP Top 10 for LLMs (prompt injection, insecure output handling, training data poisoning, denial of service, sensitive information disclosure, overreliance, and model theft). Case study results show uncensored models (e.g., Llama2-uncensored) exhibit significantly higher exposure, especially to prompt injection and output-handling attacks–while censored and fine-tuned models attain higher assurance levels. Significance and impact: the framework provides transparent, quantitative scoring to compare systems, prioritize mitigations, and support evidence-based deployment and governance in high-takes environments, with continuous human oversight emphasized.
Sander Stamnes Karlsen, Muhammad Mudassar Yamin, Ehtesham Hashmi, Basel Katt, Mohib Ullah
J. Inf. Secur. Appl.2
2025 Self-supervised hate speech detection in Norwegian texts with lexical and semantic augmentations
abstract
The proliferation of social media platforms has significantly contributed to the spread of hate speech, targeting individuals based on race, gender, impaired functioning, religion, or sexual orientation. Online hate speech not only provokes prejudice and violence in cyber-space, but it also has profound impacts in real-world communities, eroding social harmony and increasing the risk of physical harm. This necessitates the urgency for effective hate speech detection systems, especially in low-resource languages such as Norwegian, where limited data availability presents additional challenges. This study utilizes the Barlow Twins methodology, applying a self-supervised learning framework to initially develop robust language representations for Norwegian, a language that is typically underrepresented in NLP research. These learned representations are then utilized in a semi-supervised classification task to detect hate speech. Leveraging a combination of text augmentation techniques at both the word and sentence level, along with self-training strategies, our approach demonstrates the potential to efficiently learn meaningful representations with a minimal amount of annotated data. Experimental results show that the Nor-BERT model is well-suited for detecting hate speech within the limited Norwegian data available, consistently outperforming other models. Additionally, Nor-BERT surpassed all deep learning-based models in terms of F1-score. • Collecting and Annotating Norwegian hate speech data. • Enhanced self-learning with Barlow Twins. • Advancing NLP with Lexical and Semantic Augmentation. • LM-based supervised classification.
Ehtesham Hashmi, Sule Yildirim Yayilgan, Muhammad Mudassar Yamin, Mohamed Abomhara, Mohib Ullah
Expert Syst. Appl.3
2025 Severity-based triage of cybersecurity incidents using kill chain attack graphs
Lukás Sadlek, Muhammad Mudassar Yamin, Pavel Celeda, Basel Katt
J. Inf. Secur. Appl.2
2024 A Self-Supervised Diffusion Framework For Facial Emotion Recognition
abstract
In this paper, we introduced a novel Facial Emotion Recognition (FER) framework that utilizes a diffusion-based approach and an attention mechanism. The model is efficiently trained through self-supervised learning, leveraging labeled and unlabelled data. The proposed framework has been rigorously tested on the FER2013 and AffectNet datasets, achieving promising accuracies of $67.2 \%$ and $68.1 \%$, respectively. The quantitative results not only surpass the performance of existing state-of-the-art FER models but also demonstrate the synergistic effect of combining diffusion-based modeling with self-supervised learning and attention mechanisms within a solid architectural framework. Our approach sets a new benchmark in the field, offering a significant step forward in the accurate and efficient recognition of facial expressions.
Saif Hassan, Mohib Ullah, Ali Shariq Imran, Ghulam Mujtaba 0001, Muhammad Mudassar Yamin, Ehtesham Hashmi, Faouzi Alaya Cheikh, Azeddine Beghdadi
ICIP5
2024 Combining Uncensored and Censored LLMs for Ransomware Generation
Muhammad Mudassar Yamin, Ehtesham Hashmi, Basel Katt
WISE (4)1
2024 All flags are not created equal: A deep look into CTF Scoring Algorithms
abstract
Capture the Flag (CTF) competitions are popular in the cybersecurity field to train and evaluate the skills of students and professionals alike. Each CTF competition has a scoring system that is fundamental in evaluating a participant’s skills by awarding scores for correct behavior and penalizing for incorrect behavior. Even though this topic gets discussed in the CTF community, it has mostly been ignored in previously published research material. The purpose of this research is: (1) to evaluate and understand how scoring algorithms affect the outcome of the two most commonly used CTF formats, i.e., Jeopardy and Attack-Defense. (2) To identify the desired requirements and properties of a CTF scoring algorithm by following a three-step process consisting of conducting a survey targeting experts from the European Cybersecurity Challenge (ECSC), identifying the currently available CTF algorithms using a literature review, and then simulating the identified scoring algorithms using data obtained from real CTFs. Finally, (3) scoring algorithms for both CTF formats are proposed based on the findings of the literature review, survey, and simulation results that fulfill the identified requirements.
Abdullah Zafar, Muhammad Mudassar Yamin, Basel Katt, Espen Torseth
Expert Syst. Appl.2
2022 Modeling and executing cyber security exercise scenarios in cyber ranges
Muhammad Mudassar Yamin, Basel Katt
Comput. Secur.1
2022 Use of cyber attack and defense agents in cyber ranges: A case study
Muhammad Mudassar Yamin, Basel Katt
Comput. Secur.1
2021 Serious games as a tool to model attack and defense scenarios for cyber-security exercises
Muhammad Mudassar Yamin, Basel Katt, Mariusz Nowostawski
Comput. Secur.1
2021 Weaponized AI for cyber attacks
Muhammad Mudassar Yamin, Mohib Ullah, Basel Katt
J. Inf. Secur. Appl.1
2020 Cyber ranges and security testbeds: Scenarios, functions, tools and architecture
Muhammad Mudassar Yamin, Basel Katt, Vasileios Gkioulos
Comput. Secur.1
2019 Cyber Security Skill Set Analysis for Common Curricula Development
abstract
The field of cyber security is getting diversified day by day, with new specialist responsibilities and roles at different levels of competence being required by the industry. The competencies can be mapped with required skills set in multiple cyber security certification programs. However, different certification programs use different curricula and terminology, which makes the offerings overlap in some aspect and be distinct in others. This makes it hard for new institutes and cyber ranges to decide upon their training offerings. The aim of this study is to identify commonalities in skill set requirements for multiple cyber security roles like penetration tester, security operation center analysts, digital forensic and incident responders and information security managers. The identified commonalities will be used for the development of a standard common curricula to set skill set requirements for the achievement of specific competence levels in a specific cyber security field.
Muhammad Mudassar Yamin, Basel Katt
ARES1