Rahim Taheri

dblp:239/6055 · DBLP profile ↗
← Back
19ranked-venue papers
5as first author
16since 2021 · last 2025
0000-0002-4078-3105ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 LightChain-RAN-RF: A Lightweight Blockchain-Enabled RFID Framework for O-RAN Edge Environments
abstract
This paper presents the LightChain-RAN-RF, a lightweight blockchain-based architecture designed to enhance the security, privacy, and efficiency of Radio Frequency Identification (RFID) systems operating in Dense Reader Environments (DRE). By combining CSMA-based anti-collision protocols with mutual authentication, encrypted communication, and InterPlanetary File System (IPFS)-backed blockchain storage, the proposed method addresses key challenges such as reader collisions, energy consumption, and vulnerability to attacks like Man-In-The-Middle (MITM) and Sybil. RFID readers act as light blockchain nodes, ensuring secure, scalable interaction across distributed networks. The architecture is fully compatible with Open Radio Access Network (O-RAN) frameworks, allowing RFID readers to function as trusted edge devices in virtualized, Artificial intelligence (AI)-driven mobile infrastructures. Simulation results confirm significant improvements in throughput (almost 60%) and decreases in energy efficiency (almost$\mathbf{1. 4 ~ J}$), demonstrating the system's suitability for modern industrial IoT and mobile network applications.
Hadiseh Rezaei, Mehdi Golsorkhtabaramiri, Rahim Taheri, Chuan Heng Foh, Mohammad Shojafar
HPCC3
2025 FedLLMGuard: A federated large language model for anomaly detection in 5G networks
Hadiseh Rezaei, Rahim Taheri, Mohammad Shojafar
Comput. Networks2
2025 Federated learning-based robust android malware detection: label-flipping attacks and defenses
Mohsen Eslamnejad, Rahim Taheri, Mohammad Shojafar, Mohamed Bahy Bader-El-Den
Neural Comput. Appl.2
2025 GRAF-IDS: graph-based clustering as aggregation for federated intrusion detection system in IoT network
Hadiseh Rezaei, Rahim Taheri, Mohammad Shojafar, Chuan Heng Foh
Neural Comput. Appl.2
2025 LFD-IDS: Bagging-Based Data Poisoning Attacks Against Cyberattack Detection in Connected Vehicle
abstract
This paper explores the need for new systems to detect and monitor cyberattacks in Connected Vehicles (CVs). Sensor health in CVs is vital, as prediction errors and communication issues can weaken the sensor network. Intrusion Detection Systems (IDS) for CVs must be continuously updated to meet changing needs and be robust against adversarial attacks. We developed a new Label Flipping system against Deep learning-based IDS (LFD-IDS) to help cloud operators understand unusual vehicle sensor data. LFD-IDS specifically targets detecting and explaining sensor data manipulation from poisoning attacks. We proposed two label-flipping attacks based on Bootstrapping and Bagging and a defensive strategy using a multi-layer deep neural network. Our LFD-IDS achieves at least 90% accuracy in identifying cyberattacks.
Zahra Pooranian, Rahim Taheri, Fabio Martinelli
IEEE Trans. Intell. Transp. Syst.2
2025 Federated Learning Under Attack: Exposing Vulnerabilities Through Data Poisoning Attacks in Computer Networks
abstract
Federated Learning is an approach that enables multiple devices to collectively train a shared model without sharing raw data, thereby preserving data privacy. However, federated learning systems are vulnerable to data-poisoning attacks during the training and updating stages. Three data-poisoning attacks–label flipping, feature poisoning, and VagueGAN–are tested on FL models across one out of ten clients using the CIC and UNSW datasets. For label flipping, we randomly modify labels of benign data; for feature poisoning, we alter highly influential features identified by the Random Forest technique; and for VagueGAN, we generate adversarial examples using Generative Adversarial Networks. Adversarial samples constitute a small portion of each dataset. In this study, we vary the percentages by which adversaries can modify datasets to observe their impact on the Client and Server sides. Experimental findings indicate that label flipping and VagueGAN attacks do not significantly affect server accuracy, as they are easily detectable by the Server. In contrast, feature poisoning attacks subtly undermine model performance while maintaining high accuracy and attack success rates, highlighting their subtlety and effectiveness. Therefore, feature poisoning attacks manipulate the server without causing a significant decrease in model accuracy, underscoring the vulnerability of federated learning systems to such sophisticated attacks. To mitigate these vulnerabilities, we explore a recent defensive approach known as Random Deep Feature Selection, which randomizes server features with varying sizes (e.g., 50 and 400) during training. This strategy has proven highly effective in minimizing the impact of such attacks, particularly on feature poisoning.
Ehsan Nowroozi, Imran Haider, Rahim Taheri, Mauro Conti
IEEE Trans. Netw. Serv. Manag.3
2025 A Random Deep Feature Selection Approach to Mitigate Transferable Adversarial Attacks
abstract
Machine learning and deep learning are transformative forces reshaping our networks, industries, services, and ways of life. However, the susceptibility of these intelligent systems to adversarial attacks remains a significant issue. On the one hand, recent studies have demonstrated the potential transferability of adversarial attacks across diverse models. On the other hand, existing defense mechanisms are vulnerable to advanced attacks or are often limited to certain attack types. This study proposes a random deep feature selection approach to mitigate such transferability and improve the robustness of models against adversarial manipulations. Our approach is designed to strengthen deep models against poisoning (e.g., label flipping) and exploratory (e.g., DeepFool, BIM, FGSM, I-FGSM, L-BFGS, C&W, JSMA, and PGD) attacks that are applied in both the training and testing stages, and Transfer Learning-Based Adversarial Attacks. We consider scenarios involving perfect and semi-knowledgeable attackers. The performance of our approach is evaluated through extensive experiments on the renowned UNSW-NB15 dataset, including both real-world and synthetic data, covering a wide range of modern attack behaviors and benign activities. The results indicate that our approach boosts the effectiveness of the target network to over 80% against labelflipping poisoning attacks and over 60% against all major types of exploratory attacks.
Ehsan Nowroozi, Mohammadreza Mohammadi, Ahmad Rahdari, Rahim Taheri, Mauro Conti
IEEE Trans. Netw. Serv. Manag.4
2024 Unveiling vulnerabilities in deep learning-based malware detection: Differential privacy driven adversarial attacks
Rahim Taheri, Mohammad Shojafar, Farzad Arabikhan, Alexander E. Gegov
Comput. Secur.1
2024 Enhancing federated learning robustness through randomization and mixture
Seyedsina Nabavirazavi, Rahim Taheri, S. Sitharama Iyengar
Future Gener. Comput. Syst.2
2023 Impact of Aggregation Function Randomization against Model Poisoning in Federated Learning
abstract
Federated learning has gained significant attention as a privacy-preserving approach for training machine learning models across decentralized devices. However, this distributed learning paradigm is susceptible to adversarial attacks, particularly model poisoning attacks, where adversaries inject malicious model updates to compromise the integrity of the global model. In this paper, we investigate the impact of randomness on model poisoning attacks in federated networks, where the server employs two aggregation rules, Krum and Trimmed Mean, randomly in each federated round. We present three distinct adversaries: one targeting Krum throughout the entire learning process, another targeting Trimmed Mean entirely, and a third adversary employing a randomized strategy between Krum and Trimmed Mean for each round. Our objective is to evaluate their performance in reducing the overall accuracy of the federated network. We propose novel techniques to craft poisoned models and explore the efficacy of these attacks by exploiting the aggregation rules. We evaluated our proposed methods on Fashion-MNIST dataset. The experiments reveal the robustness of the federated network against the proposed adversarial scenarios, contributing to a better understanding of the vulnerabilities and defenses in federated learning systems.
Seyedsina Nabavirazavi, Rahim Taheri, Mohammad Shojafar, S. Sitharama Iyengar
TrustCom2
2023 SIEMS: A Secure Intelligent Energy Management System for Industrial IoT Applications
abstract
Microgrids are industrial technologies that can provide energy resources for the Internet of Things (IoT) demands in smart grids. Hybrid microgrids supply quality power to the IoT devices and ensure high resiliency in supply and demand for PV-based grid-tied microgrids. In this system, the usage of predictive energy management systems (EMS) is essential to dispatch power from different resources, while the battery energy storage system (BESS) is feeding the loads. In this article, we deploy a one-day-ahead prediction algorithm using a deep neural network for a fast-response BESS in an intelligent energy management system (I-EMS) that is calledSIEMS. The main role of theSIEMSis to maintain the SOC at high rates based on the one-day-ahead information about solar power, which depends on meteorological conditions. The remaining power is supplied by the main grid for sustained power streaming between BESS and end-users. Considering the usage of information and communication technology components in the microgrids, the main objective of this article is focused on the hybrid microgrid performance under cyber-physical security adversarial attacks. Fast gradient sign, basic iterative, and DeepFool methods, which are investigated for the first time in power systems e.g., smart grid and microgrids, in order to produce perturbation for training data. To secure the microgrid’sSIEMS, we proposetwoDefence algorithms based on defensive distillation and adversarial training strategies for the first time in EMSs. We apply and evaluate these benchmark adversarial attack and Defence methods against the proposed machine learning models to increase the robustness of the models in the system against adversarial attacks.
Pedram Asef, Rahim Taheri, Mohammad Shojafar, Iosif Mporas, Rahim Tafazolli
IEEE Trans. Ind. Informatics2
2022 SETTI: A Self-supervised AdvErsarial Malware DeTection ArchiTecture in an IoT Environment
abstract
In recent years, malware detection has become an active research topic in the area of Internet of Things (IoT) security. The principle is to exploit knowledge from large quantities of continuously generated malware. Existing algorithms practise available malware features for IoT devices and lack real-time prediction behaviours. More research is thus required on malware detection to cope with real-time misclassification of the input IoT data. Motivated by this, in this article, we propose an adversarial self-supervised architecture for detecting malware in IoT networks, SETTI, considering samples of IoT network traffic that may not be labeled. In the SETTI architecture, we design three self-supervised attack techniques, namely, Self-MDS , GSelf-MDS, and ASelf-MDS . The Self-MDS method considers the IoT input data and the adversarial sample generation in real-time. The GSelf-MDS builds a generative adversarial network model to generate adversarial samples in the self-supervised structure. Finally, ASelf-MDS utilises three well-known perturbation sample techniques to develop adversarial malware and inject it over the self-supervised architecture. Also, we apply a defence method to mitigate these attacks, namely, adversarial self-supervised training, to protect the malware detection architecture against injecting the malicious samples. To validate the attack and defence algorithms, we conduct experiments on two recent IoT datasets: IoT23 and NBIoT. Comparison of the results shows that in the IoT23 dataset, the Self-MDS method has the most damaging consequences from the attacker’s point of view by reducing the accuracy rate from 98% to 74%. In the NBIoT dataset, the ASelf-MDS method is the most devastating algorithm that can plunge the accuracy rate from 98% to 77%.
Marjan Golmaryami, Rahim Taheri, Zahra Pooranian, Mohammad Shojafar, Pei Xiao 0001
ACM Trans. Multim. Comput. Commun. Appl.2
2021 RSS: An Energy-Efficient Approach for Securing IoT Service Protocols Against the DoS Attack
abstract
Authentication protocols are powerful tools to ensure confidentiality as an important feature of Internet of Things (IoT). The Denial-of-Service (DoS) attack is one of the significant threats to availability, as another essential feature of IoT, which deprives users of services by consuming the energy of IoT nodes. On the other hand, computational intelligence algorithms can be applied to solve such issues in the network and cyber domains. Motivated by this, this article links these concepts. To do so, we analyze two lightweight authentication protocols, present a DoS attack inspired by users' misbehavior and suggest a solution called received signal strength, which is easy to compute, applicable for resisting against different kinds of vulnerabilities in Internet protocols, and feasible for practical implementations. We implement it on two scenarios for locating attackers, investigate the effects of IoT devices' internal error on locating, and propose an optimization problem to finding the exact location of attackers, which is efficiently solvable for computational intelligence algorithms, such as TLBO. Besides, we analyze the solutions for unreliable results of accurate devices and provide a solution to detect attackers with less than 12-cm error and the false alarm probability of 0.7%.
Meysam Ghahramani, Reza Javidan, Mohammad Shojafar, Rahim Taheri, Mamoun Alazab, Rahim Tafazolli
IEEE Internet Things J.4
2021 Adversarial android malware detection for mobile multimedia applications in IoT environments
Rahim Taheri, Reza Javidan, Zahra Pooranian
Multim. Tools Appl.1
2021 LEVER: Secure Deduplicated Cloud Storage With Encrypted Two-Party Interactions in Cyber-Physical Systems
abstract
Cloud envisioned cyber--physical systems (CCPS) is a practical technology that relies on the interaction among cyber elements like mobile users to transfer data in cloud computing. In CCPS, cloud storage applies data deduplication techniques aiming to save data storage and bandwidth for real-time services. In this infrastructure, data deduplication eliminates duplicate data to increase the performance of the CCPS application. However, it incurs security threats and privacy risks. For example, the encryption from independent users with different keys is not compatible with data deduplication. In this area, several types of research have been done. Nevertheless, they are suffering from a lack of security, high performance, and applicability. Motivated by this, in this article, we propose a message lock encryption with neVer-decrypt homomorphic encRyption (LEVER) protocol between the uploading CCPS user and cloud storage to reconcile the encryption and data deduplication. Interestingly, LEVER is the first brute-force resilient encrypted deduplication with only cryptographic two-party interactions. We perform several numerical analysis of LEVER and confirm that it provides high performance and practicality compared to the literature.
Zahra Pooranian, Mohammad Shojafar, Sahil Garg, Rahim Taheri, Rahim Tafazolli
IEEE Trans. Ind. Informatics4
2021 Fed-IIoT: A Robust Federated Malware Detection Architecture in Industrial IoT
abstract
The sheer volume of industrial Internet of Things (IIoT) malware is one of the most serious security threats in today's interconnected world, with new types of advanced persistent threats and advanced forms of obfuscations. This article presents a robust federated learning based architecture called Fed-IIoT for detecting Android malware applications in IIoT. Fed-IIoT consists of two parts: first, participant side, where the data are triggered by two dynamic poisoning attacks based on a generative adversarial network (GAN) and federated GAN; and second, server side, which aims to monitor the global model and shape a robust collaboration training model, by avoiding anomaly in aggregation by a GAN network (A3GAN) and adjust two GAN-based countermeasure algorithms. One of the main advantages of Fed-IIoT is that devices can safely participate in the IIoT and efficiently communicate with each other, with no privacy issues. We evaluate our solutions through experiments on various features using three IoT datasets. The results confirm the high accuracy rates of our attack and defense algorithms and show that the A3GAN defensive approach preserves the robustness of data privacy for Android mobile users and is about 8% higher accuracy with existing state-of-the-art solutions.
Rahim Taheri, Mohammad Shojafar, Mamoun Alazab, Rahim Tafazolli
IEEE Trans. Ind. Informatics1
2020 Similarity-based Android malware detection using Hamming distance of static binary features
Rahim Taheri, Meysam Ghahramani, Reza Javidan, Mohammad Shojafar, Zahra Pooranian, Mauro Conti
Future Gener. Comput. Syst.1
2020 On defending against label flipping attacks on malware detection systems
abstract
Abstract Label manipulation attacks are a subclass of data poisoning attacks in adversarial machine learning used against different applications, such as malware detection. These types of attacks represent a serious threat to detection systems in environments having high noise rate or uncertainty, such as complex networks and Internet of Thing (IoT). Recent work in the literature has suggested using the K -nearest neighboring algorithm to defend against such attacks. However, such an approach can suffer from low to miss-classification rate accuracy. In this paper, we design an architecture to tackle the Android malware detection problem in IoT systems. We develop an attack mechanism based on silhouette clustering method, modified for mobile Android platforms. We proposed two convolutional neural network-type deep learning algorithms against this Silhouette Clustering-based Label Flipping Attack . We show the effectiveness of these two defense algorithms— label-based semi-supervised defense and clustering-based semi-supervised defense —in correcting labels being attacked. We evaluate the performance of the proposed algorithms by varying the various machine learning parameters on three Android datasets: Drebin, Contagio, and Genome and three types of features: API, intent, and permission. Our evaluation shows that using random forest feature selection and varying ratios of features can result in an improvement of up to 19% accuracy when compared with the state-of-the-art method in the literature.
Rahim Taheri, Reza Javidan, Mohammad Shojafar, Zahra Pooranian, Ali Miri, Mauro Conti
Neural Comput. Appl.1
2019 Automatic Clustering of Attacks in Intrusion Detection Systems
abstract
Intrusion Detection Systems (IDSs) can identify the malicious activities and anomalies in networks and present robust protection for these systems. Clustering of attacks plays an important role in defining IDS defense policies. A key challenge in clustering has been finding the optimal value for the number of clusters. In this paper, we propose an automatic clustering algorithm as part of an IDS architecture. This algorithm is based on concepts of coherence and separation. Our automatic clustering algorithms find clusters with the most similarity between the proposed cluster elements and the least similarity with other clusters. The proposed clustering is further optimized by considering two types of objective index functions, and Artificial Bee Colony (ABC), Particle Swarm Optimization (PSO), and Differential Evolution (DE) methods. Comparison of the results obtained with other work in the literature shows improvements in terms of the low average number of evaluations functions, high accuracy, and low computation cost.
Mohammad Shojafar, Rahim Taheri, Zahra Pooranian, Reza Javidan, Ali Miri, Yaser Jararweh
AICCSA2