Ahmad Salehi S.

dblp:241/2715 · also Ahmad Salehi Shahraki · DBLP profile ↗
← Back
19ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0003-2115-6269ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 3 first-author · 7 since 2021Security and privacy · 5 · 1 first-author · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 ZAD-ML: Dual-layer Learning for zero-Day attack detection in multivariate time series
Edward Kwadwo Boahen, Ahmad Salehi S.
Future Gener. Comput. Syst.2
2026 A Fault-Tolerant Sharding Mechanism for Resilience and Scalability in Blockchain Using Backup Pool
abstract
With the development of blockchain technology, an increasing number of devices are joining the network and generating numerous transactions, which pose significant performance and scalability challenges to blockchain networks. Sharding technology is one solution that improves throughput by parallelising transaction validation and block generation, thereby alleviating this challenge. However, during the process of dividing shard groups in large-scale networks, the uneven distribution of malicious nodes or dynamic changes in joined nodes may lead to failures in the availability and liveness of shard groups. This paper proposes an enhanced sharding blockchain system that improves fault tolerance and reliability to ensure high shard group performance, scalability, and reliability. We also propose the concept of a backup pool and achieve the detection and recovery of faulty shards through pre-deployed backup pool nodes and redesigned consensus algorithms. After a thorough security analysis, we conclude that the proposed sharding blockchain system can increase the Resilience of shard groups from 33.3% to 66.6%. Additionally, we evaluate the proposed system, and the results show that it ensures the security, reliability, and high performance of sharding while increasing the scalability of the system’s network nodes from 10 4 to 10 6 compared to existing sharding blockchains.
Ahmad Salehi S., Naveen K. Chilamkurti
Future Gener. Comput. Syst.2
2025 PRIV-HFL: Privacy-Preserving and Robust Federated Learning for Heterogeneous Clients Against Data Reconstruction Attacks
abstract
Federated Learning (FL) is a machine learning paradigm that allows multiple local clients to collaboratively train a global model by sharing their model parameters instead of private data, thereby mitigating privacy leakage. However, recent studies have shown that gradient-based Data Reconstruction Attack (DRA) can still expose private information by exploiting model parameters from local clients. Existing privacy-preserving FL strategies provide some defense against these attacks, but at the cost of significantly reduced model accuracy. Moreover, the issue of client heterogeneity, particularly in Non-Identical and Independent Distributions (Non-IID) clients, further exacerbates these FL methods, resulting in drifted global models, slower convergence, and decreased performance. This study aims to address the two main challenges of FL: Non-IID data and client privacy through DRA. To this end, it leverages the lagrangian duality approach and incorporates a generator model to enable Knowledge Distillation (KD) among clients. By facilitating improved local model performance through inter-client knowledge transfer, the proposed method aims to simultaneously address the practical challenges commonly encountered by FL systems. Our study demonstrates a remarkable improvement in model accuracy, with KD boosting it by up to $15 \%$ on CIFAR-10 and MNIST classification tasks in Non-IID client settings. Furthermore, we propose an aggregation algorithm that inherently preserves client data privacy during the training phase, offering resilience against DRA.
Mohammadreza Najafi, Hooman Alavizadeh, Ahmad Salehi S., A. S. M. Kayes, Wenny Rahayu
RAID3
2025 Securing cross-domain data access with decentralized attribute-based access control
abstract
In attribute-based access control (ABAC), access to resources depends on the specific attributes of the entity requesting access. Existing ABAC models primarily depend on local attribute authorities to define and confirm attributes, which makes it challenging to support access decisions cross-domains without introducing centralization. Centralized solutions often conflict with individual domains’ security, privacy, and control requirements and, if compromised for any reason, can impact access to large datasets across participating domains. This paper introduces a novel access control model for cross-domain environments that significantly reduces central control. Our decentralized ABAC (D-ABAC) model uses group signature techniques to exchange attribute information securely and privately within cross-domains. Each domain maintains its own policies and attribute authorities, reducing the need for global trust or centralization to mutual trust between attribute authorities. We further design and implement a proof-of-concept system to demonstrate the practical feasibility of our proposed system for the collaborative and secure sharing of healthcare data in cross-domain environments. The proposed system model enhances security, scalability, and privacy in cross-domain settings, making it suitable for sensitive environments such as healthcare.
Ahmad Salehi S., Carsten Rudolph, Hooman Alavizadeh, A. S. M. Kayes, Wenny Rahayu, Zahir Tari
Ad Hoc Networks1
2025 Social network botnet attack mitigation model for cloud
abstract
Online Social Network (OSN) botnet attacks pose a growing threat to the cloud environment and reduce the services’ availability and reliability for users by launching distributed denial of service (DDoS) attacks on crucial servers in the cloud. These attacks involve the deployment of sophisticated botnets that exploit the interconnected nature of social networks to identify targets, exploit vulnerabilities, and launch attacks. The prevalence and impact of these botnet-driven attacks have recently been studied. Although the detection of these botnet attacks is still a challenging process, it remains crucial to gain a comprehensive understanding of and evaluate the best defense strategies against botnet attacks. This evaluation can be further utilized to formulate effective defense plans to mitigate the impact of such botnet attacks. In this paper, we first investigate the properties of OSN botnet attack stages that eventually lead to launching DDoS attacks toward a cloud system. Then, we formalize a defensive model using a sequential game model to analyze both the attacker’s and defenders’ best equilibrium strategies for the proposed botnet attack scenario. Moreover, we formulate optimal strategies for the defender against various attack strategies. Our experiments reveal the best defense strategies against various attack rates to maintain cloud functionality. Finally, we discuss possible countermeasures for these OSN botnet threats.
Hooman Alavizadeh, Ahmad Salehi S., A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon
Comput. Networks2
2025 Physical layer security techniques for grant-free massive Machine-Type Communications in 5G and beyond: A survey, challenges, and future directions
abstract
The future of smart cities, industrial automation, and connected vehicles is heavily reliant on advanced communication technologies. These technologies, particularly massive Machine-Type Communication (mMTC), are the backbone of the many connected devices required for these applications. Grant -free access in 5G and beyond, while enhancing transmission efficiency by eliminating the need for permission requests, also introduces significant security risks. These risks, such as unauthorised access, data interception, and interference due to the absence of centralised control, are of paramount importance. Physical layer security (PLS) techniques, with their ability to exploit the unique properties of wireless channels to bolster communication security, offer a promising solution. This paper provides a comprehensive review of PLS techniques for securing grant-free mMTC, comparing different approaches and exploring the challenges of their integration. Our findings lay the groundwork for future research and the practical implementation of advanced security solutions in grant-free mMTC, a development that will also enhance the security of advanced 5G and 6G networks.
Uchenna P. Enwereonye, Ahmad Salehi S., Hooman Alavizadeh, A. S. M. Kayes
Comput. Networks2
2025 Robust Multiuser Physical Layer Security for Grant-Free mMTC in Beyond 5G/6G Networks
abstract
Industry 5.0 introduces human-machine collaboration and resilient automation, demanding secure, low-latency connectivity for ultra-dense Industrial IoT (IIoT). Grant-free massive machine-type communications (mMTC) supports such connectivity but faces challenges including dense multiuser access, passive eavesdropping, and imperfect channel state information (CSI), which undermine physical layer security (PLS). This paper proposes a robust and low-complexity multiuser PLS scheme tailored for grant-free mMTC under CSI uncertainty. The scheme leverages dynamic user clustering based on spatial correlation and real-time interference to enable scalable, interference-aware beamforming. Furthermore, a joint optimisation of receive beamforming and adaptive artificial noise injection is performed, and enhanced by a regularised minimum mean square error (MMSE) framework to mitigate bounded CSI errors. Simulation results show that the scheme consistently outperforms existing benchmarks across secrecy capacity, bit error rate, and secrecy outage probability under different channel models, together with analyses of SOP sensitivity to CSI error and scalability to dense users/eavesdroppers, confirms its robustness, efficiency, and applicability to large-scale, secure IIoT communications in beyond 5G/6G networks aligned with Industry 5.0 requirements.
Uchenna P. Enwereonye, Ahmad Salehi S., Hooman Alavizadeh, A. S. M. Kayes
IEEE Internet Things J.2
2025 Safeguarding Individuals and Organizations From Privacy Breaches: A Comprehensive Review of Problem Domains, Solution Strategies, and Prospective Research Directions
abstract
Privacy breaches have become increasingly prevalent, exposing individuals to significant risks. These breaches can have far-reaching consequences, including identity theft and life-threatening situations. Several studies have analyzed data and privacy breaches and presented detection or prevention techniques to combat these breaches. However, because the number and type of breaches have significantly increased, these studies have become less relevant or outdated. Previous research on data and privacy breaches compared the techniques and results of various studies. However, none comprehensively analyzed the type of information and the level and severity of compromise that occurred after such breaches. In this survey, we examine the fundamental concepts of privacy and security and define the security incidents and data/privacy breaches. We propose a set of criteria to evaluate the published studies on privacy breaches. We thoroughly investigate the problem domains and security-related concerns considering six recent breach cases in Australia, elucidating the critical challenges and issues associated with privacy breaches. We comprehensively review and outline the trends and severity of security incidents and data/privacy breaches from 2020 to 2024. Additionally, we review the current state-of-the-art countermeasures to safeguard against these breaches. Finally, we identify an open research direction to develop an artificial intelligence (AI)-powered security framework. This framework aims to analyze cyber threats, characterize attackers’ behaviors, distinguish between legitimate and illegitimate privacy policies, and restrict access to individuals’ information. Overall, this survey will help organizations to reassess and update their security and privacy measures.
A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon, Ahmad Salehi S., Hooman Alavizadeh
IEEE Internet Things J.4
2025 RACEMAN: Cross-Platform Intrusion Detection in Online Social Networks
abstract
Online Social Networks (OSNs) face various security threats, including account compromisation, where attackers seize control over legitimate user accounts and create fake profiles for nefarious purposes. The dynamic and open nature of OSNs presents unique challenges for cybersecurity, particularly in detecting unauthorized access and malicious activities such as phishing attacks, spamming, and spreading misinformation associated with account compromisation. Traditional intrusion detection systems (IDS) in OSNs often miss attacks or generate false positives due to static thresholds, delayed responses, and poor real-time data handling. These limitations often result in missed detections or false positives during sudden shifts in user activity patterns or emerging attack vectors. We introduce$RACEMAN$, an adaptive IDS designed explicitly for the OSN environment to address this. To enhance adaptability,$RACEMAN$incorporates emergency strategies such as dynamic threshold adjustments based on real-time network traffic analysis and early stopping mechanisms triggered by anomalous behavior spikes, enabling rapid adaptation to changing threat landscapes.$RACEMAN$leverages real-time OSN interactions to continuously update its metamorphic relations, ensuring an up-to-date understanding of normal user behaviour versus potential intrusions. This system utilises advanced semantic analysis to accurately represent user interactions. It generates diverse test cases using genetic algorithms and reinforcement learning to simulate user scenarios and potential intrusion methods. These test cases undergo input transformations to realistically mimic intrusion attempts while maintaining semantic integrity. The system's responses to these test cases are evaluated against expected behaviours defined by the updated metamorphic relations.$RACEMAN$utilizes statistical analysis, Multi-view Convolutional Neural Networks (MVCNN), and rule-based systems for intrusion classification. Our collaborative and distributed IDS approach enhances detection capabilities by promoting knowledge sharing across multiple systems and ensuring scalability without central points of failure. We evaluated$RACEMAN$using six publicly available datasets from Facebook, Google+, Twitter, linkedIn, Youtube and Reddit where it demonstrated a high accuracy rate of 98.85%, outperforming other models such as Convolutional Neural Network (CNN-85.67%), Artificial Neural Network (ANN-86.63%), and Random Forest (RF-78.26%).
Edward Kwadwo Boahen, Ahmad Salehi S., Carsten Rudolph, Zahir Tari, Joseph K. Liu
IEEE Trans. Serv. Comput.2
2024 A Novel Endorsement Protocol to Secure BFT-Based Consensus in Permissionless Blockchain
abstract
Permissionless blockchain technology offers numerous potential benefits for decentralised applications, such as security, transparency, and openness. BFT-based consensus mechanisms are widely adopted in the permissioned blockchain to meet the high scalability requirements of the network. Sybil attacks are one of the most potential threats when applying BFT-based consensus mechanisms in permissionless blockchain due to the lack of effective verification mechanisms for participants' identities. This paper presents a novel endorsement-based bootstrapping protocol with a signature algorithm that offers a streamlined, scalable identity endorsement and verification process. This approach effectively safeguards the BFT-based consensus mechanism against Sybil attacks. Using our proposed method, we have conducted thorough security analyses and simulation experiments to assess security, robustness, and scalability advantages in large-scale networks. Our results demonstrate that the scheme can effectively address the identity verification challenges when applying BFT-based consensus in a permissionless blockchain.
Ahmad Salehi S., Naveen K. Chilamkurti
WCNC2
2024 IoTPredictor: A security framework for predicting IoT device behaviours and detecting malicious devices against cyber attacks
Rudri Kalaria, A. S. M. Kayes, Wenny Rahayu, Eric Pardede, Ahmad Salehi S.
Comput. Secur.5
2023 DACP: Enforcing a dynamic access control policy in cross-domain environments
abstract
Enabling hybrid authorisations to enforce dynamic access control policy from single-domain to cross-domain environments (CDEs) is important for distributed services. However, traditional Attribute-Based Access Control (ABAC) models are incompatible with CDEs. To fill this gap, approaches that apply cryptographic primitives, e.g., attribute-based encryption (ABE), have been proposed. The computation and storage overhead in most ABE constructions is non-negligible and increases with the complexity of the associated policies. In addition, most access control policy systems enforce authorisation policies in a centralized way, raising serious security and privacy issues. In this paper, we introduce DACP – a practical Dynamic Access Control Policy system supporting dynamic cross-domain authorisation. DACP combines traditional ABAC approach and a novel cryptographic primitive Attribute-based group signature (ABGS). ABAC is used for the access control decision and policy enforcement according to the user’s attributes whereas ABGS is used for managing the user’s attributes between users and authorities. Thus, the user’s attributes are securely distributed along with the access structure in CDEs while preserving the user’s privacy. We present the concrete design and implementation of DACP, and evaluate it in real-world settings. The evaluation shows that DACP is practical and efficient in CDEs.
Ahmad Salehi S., Runchao Han, Carsten Rudolph, Marthie Grobler
Comput. Networks1
2021 Authentication and Access Control in 5G Device-to-Device Communication
abstract
Device-to-device (D2D) communication is one of the most recent advancements in wireless communication technology. It was introduced in cellular communication technology by the 3rdGeneration Partnership Project (3GPP) to lay a foundation for the evolving 5G architecture. It has now emerged as a promising technology for proximate devices. It enables proximate devices to communicate directly without the involvement of a third party network infrastructure. Researchers are analysing various methods to facilitate the smooth integration of D2D communication technology into the existing network system architecture. This paper lists all the different possible modes of operation in D2D communication based on the varying use-case scenarios and highlights the security and privacy requirements for D2D communication. Some of the recent authentication proposals for D2D communication technology are further reviewed, and their security and privacy capabilities are analysed. Apart from authentication, we also reviewed some recent proposals of access control in D2D and highlighted the security issues addressed. We then identified the open issues that prevail in implementing D2D technology in a real-world scenario for future researchers, emphasising the existing authentication and access control techniques in D2D communication.
Jithu Geevargheese Panicker, Ahmad Salehi S., Carsten Rudolph
TrustCom2
2021 Decentralized Policy Information Points for Multi-Domain Environments
abstract
Access control models have been developed to control authorized access to sensitive resources. This control of access is important as there is now a need for collaborative resource sharing between multiple organizations over open environments like the internet. Although there are multiple access control models that are being widely used, these models are providing access control within a closed environment i.e. within the organization using it. These models have restricted capabilities in providing access control in open environments. Attribute-Based Access Control (ABAC) has emerged as a powerful access control model to bring fine-grained authorization to organizations which possess sensitive data and resources and want to collaborate over open environments. In an ABAC system, access to resources that an organization possess can be controlled by applying policies on attributes of the users. These policies are conditions that need to be satisfied by the requester in order to gain access to the resource. In this paper, we provide an introduction to ABAC and by carrying forward the architecture of ABAC, we propose a Decentralized Policy Information Point (PIP) model. Our model proposes the decentralization of PIP, which is an entity of the ABAC model that allows the storage and query of user-attributes and enforces fine-grained access control for controlling the access of sensitive resources over multiple-domains. Our model makes use of the concept of a cryptographic primitive called Attribute Based Signature (ABS) to keep the identities of the users involved, private. Our model can be used for collaborative resource sharing over the internet. The evaluation of our model is also discussed to reflect the application of the proposed decentralized PIP model.
M. Ridwanur Rahman, Ahmad Salehi S., Carsten Rudolph
TrustCom2
2020 Attribute-Based Data Access Control for Multi-Authority System
abstract
Access control and authorization in universal basic services is one of the main security issues in distributed systems. In particular, access control in distributed systems, such as in healthcare systems, are crucial to improve facility safety and security. This can lead to the provision of better quality of life and contribute to a healthier future. In order to provide better services, it is necessary to develop a suitable and acceptable authorization system to prevent unauthorized access to data shared in these highly dynamic distributed environments. In practice, several types of service providers, institutes, and authorities generate a variety of data in a shared environment via central authority for their entities. Generally, the use of a central authority introduces several security and privacy issues due to the increased risk if the central authority is compromised. To address this issue, several traditional access control models have been developed and introduced. These models, however, have raised several critical security issues, and there is often a need to combine it with a cryptographic approach to offer and create better access control service to users in multi-domains. To achieve this, we provide an appropriate solution to this issue. In this paper, we introduce an access control policy model for the multi-authority system, which enables attribute authorities to control the security setting. We present a new access control framework for a dynamic authorization model that uses Attribute-Based Access Control (ABAC) and digital signature. We first define and present our system and then formalize the construction of the proposed system. Our system provides flexible access control and enhanced privacy in applied and distributed environments.
Ahmad Salehi S., Carsten Rudolph, Marthie Grobler
TrustCom1
2019 A Dynamic Cross-Domain Access Control Model for Collaborative Healthcare Application
Ahmad Salehi S., Carsten Rudolph, Marthie Grobler
IM1
2016 IEEE 802.15.6 standard in wireless body area networks from a healthcare point of view
abstract
The first standard supporting communication in wireless body area networks (WBANs) is IEEE 802.15 Task Groups 6 (TG6). IEEE 802.15.6 is a standard for short-range, low power, and highly reliable wireless communication in, on and around the human body. It supports a wide range of applications in body area networks (BANs) such as healthcare services. In WBANs, nodes are partitioned into a physical (PHY) layer and a medium access control (MAC) layer. In this paper, the MAC and PHY layers are investigated. The different types of communication supported by this standard, such as narrowband (NB), ultra-wideband (UWB), and human body communication (HBC), are further defined here. The security aspect of the standard is also discussed and investigated. Finally, using the standard and existing literature in WBAN, open issues and challenges are identified as a source of future study.
Ahmad Salehi S., Mohammad Abdur Razzaque, Inmaculada Tomeo-Reyes, Nasir Hussain
APCC1
2016 Efficient high-rate key management technique for wireless body area networks
abstract
Wireless body area network (WBAN) is an emerging technology that focuses on healthcare monitoring in indoor and outdoor areas. WBAN technology allows medical sensors to collect vital physiological data and transfer it from a source to a destination via low-energy communication. To be able to encrypt and decrypt healthcare data, it is important for medical sensing and health-related devices to generate and extract the same secret keys at both end points. Recent studies show that two medical sensing devices can generate and share secret keys using their wireless channel properties, such as the received signal strength indicator (RSSI). However, existing approaches have low bit rate values and the key entropy is insufficient. These limitations pose a major threat to WBANs and must be addressed. In this paper, we first provide an overview of existing studies related to key extraction between two devices. We then describe the basic principles of wireless channel properties and the key parameters needed to generate secret keys. Finally, we propose a practical scheme to generate secret keys while avoiding information reconciliation and privacy amplification. The proposed scheme can generate 128 symmetric secret keys in a short time frame, and allows to secure the communication between sensor devices and improve the quality of services in WBANs.
Ahmad Salehi S., Mohammad Abdur Razzaque, Inmaculada Tomeo-Reyes, Nasir Hussain, Vahid Kaviani
APCC1
2015 Understanding data flow and security requirements in wireless Body Area Networks for healthcare
abstract
The Body Area Network (BAN) is an emerging technology that focuses on monitoring physiological data in, on and around the human body. BAN technology permits wearable and implanted sensors to collect vital data about the human body and transmit it to other nodes via low-energy communication. In this paper, we investigate interactions in terms of data flows between parties involved in BANs under four different scenarios targeting outdoor and indoor medical environments: hospital, home, emergency and open areas. Based on these scenarios, we identify data flow requirements between BAN elements such as sensors and control units (CUs) and parties involved in BANs such as the patient, doctors, nurses and relatives. Identified requirements are used to generate BAN data flow models. Petri Nets (PNs) are used as the formal modelling language. We check the validity of the models and compare them with the existing related work. Finally, using the models, we identify communication and security requirements based on the most common active and passive attack scenarios.
Ahmad Salehi S., Seyit Ahmet Çamtepe, Dhammika Jayalath
HealthCom1