VLDB 2026 Research / reviewers in the wild / expert
Rana Abubakar
dblp:270/7460 · also Rana Abu Bakar
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-4206-4999ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 3 first-author · 6 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PQKE-hCPABE: A Hybrid CP-ABE Scheme with Post‑Quantum Key Exchange for Secure Multicast
Matteo Sandrucci, Rana Abubakar, Abraham Cano Aguilera, Francesco Fumagalli, Francesco Paolucci, Juan Jose Vegas Olmos, Piero Castoldi, Filippo Cugini |
SECRYPT (1) | 2 |
| 2025 | 6GUPF: A DPU-based Programmable User Plane Function for Enhanced Flow-based QoSabstractTraditional 5G user plane function (UPF) architectures are software-based implementations that struggle to maintain performance. To meet the stringent quality of service (QoS) and scalability requirements of 5G under high session and data plane loads, a highly efficient next-generation UPF is required. In this paper, we present a next-generation 6GUPF that fully leverages the hardware acceleration of SmartNICs/DPUs. The 6GUPF is developed using DOCA Flow API, which enables fast, programmable packet processing directly in the data path, specifically for the N3 gNB network and N6 interfaces of datanet. The architecture integrates flow-based acceleration for stateful flow tracking and symmetric Receive Side Scaling (RSS) to utilize cores and manage non-blocking states efficiently. This will help minimize latency and avoid contention in multi-core environments. Our experiments show that hardware-offloaded UPF achieves an aggregate line rate of 400 Gbit/s, supports 1 million concurrent data streams, and scales up to 500,000 active User Equipment (UE) instances while maintaining QoS and session isolation. It also enables 40% lower latency compared to traditional software UPFs. Unlike Tofino-based P4 switch UPF designs, which are limited by SRAM and TCAM constraints when storing large-scale data streams, our DPU-based solution is ideal for high-density Protocol Data Unit (PDU) deployments without sacrificing programmability and performance. It creates a path for cloud-native, 6G UPF deployments that can scale to a wide range of workloads, from ultra-low-latency applications to large-scale IoT backhaul. Rana Abubakar, Ahmed Salah Tawfik Ibrahim, Francesco Paolucci, Andrea Sgambelluri, Piero Castoldi, Filippo Cugini, Juan Jose Vegas Olmos |
GLOBECOM | 1 |
| 2025 | IDS-NGNN: A SmartNIC-based Intrusion Detection System Based on Reduce and Merge Nested Graph Neural NetworksabstractThe growing complexity of network attacks has outpaced the capabilities of traditional intrusion detection systems (IDS), which often rely on flat data structures that fail to capture complex relationships within networks. To address this limitation, we propose IDS-NGNN, a novel IDS that integrates hardware-offload SmartNIC preprocessing with a nested graph neural network (NGNN) architecture. Unlike standard Graph Neural Networks (GNN), IDS-NGNN jointly captures local and global dependencies using a three-layer design: an internal GNN for host-level activity, a nested graph module for hierarchical aggregation, and an external GNN for inter-host communication. SmartNIC acceleration enables efficient real-time processing of large-scale graph-structured network data at the edge. We evaluate IDS-NGNN on six public IDS datasets, including CIC-IDS-2017, CSE-CIC-IDS-2018, and ToN-IoT. Experimental results demonstrate that IDS-NGNN achieves up to 95% accuracy and 92% F1-score, while maintaining efficiency suitable for real-time 100 Gbps deployments. Rana Abubakar, Francesco Paolucci, Filippo Cugini, Juan Jose Vegas Olmos, Lorenzo De Marinis |
GLOBECOM | 1 |
| 2024 | Wire-speed DDoS Attack Mitigation using Hardware Acceleration of Programmable DPUsabstractService providers face significant challenges from Distributed Denial of Service (DDoS) attacks since existing mitigation techniques, including various Machine Learning and flow-based approaches, often lack efficiency due to high latency and inadequate filtering. This paper proposes a novel DDoS mitigation strategy using programmable Data Processing Units (DPUs) to offload detection and mitigation processes, utilizing hardware acceleration. Our approach leverages DPUs to execute flow-based filtering, focusing on mitigating TCP SYN flood attacks. We demonstrate that our DPU-based hardware-accelerated framework successfully eliminates, after a fast learning phase, all the malicious traffic while maintaining high data throughput up to 100 Gbps. Stefano Hinic, Rana Abubakar, Andrea Marotta, Francesco Paolucci |
GLOBECOM | 2 |
| 2024 | 5GDAD: A Deep Learning Approach for DDoS Attack Detection in 5G P4-based UPFabstractThe fast-paced growth of 5G networks, along with the emergence of 6G technology, has emphasized the crucial importance of strong security measures to safeguard communication infrastructures. A key security issue in 5G data networks is Distributed Denial-of-Service (DDoS) at tacks, which specifically target the GTP-based protocol which is a significant threat. However, network telemetry data provides a rich source of information about the nature of network traffic, which can be used to detect and predict DDoS attacks. We propose a novel framework for collecting and processing large amounts of telemetry data in 5G networks leveraging state-of-the-art technologies, including data-plane programmability in P4-based User-Plane Function (UPF) and Data Processing Unit (DPU). Furthermore, we propose an anomaly-detection method for performing live deep learning analysis on network traffic using a Convolutional Neural Network (CNN) to detect DDoS attacks. Our results demonstrate the effectiveness of our framework, achieving an impressive 98.6% accuracy and 98% F1-score. Rana Abubakar, Faris Alhamed, Piero Castoldi, Andrea Sgambelluri, Juan Jose Vegas Olmos, Filippo Cugini, Francesco Paolucci |
HPSR | 1 |
| 2024 | FTG-Net-E: A hierarchical ensemble graph neural network for DDoS attack detectionabstractDistributed Denial-of-Service (DDoS) attacks are a major threat to computer networks. These attacks can be carried out by flooding a network with malicious traffic, overwhelming its resources, and/or making it unavailable to legitimate users. Existing machine learning methods for DDoS attack detection typically use statistical features of network traffic, such as packet sizes and inter-arrival times. However, these methods often fail to capture the complex relationships between different traffic flows. This paper proposes a new DDoS attack detection approach that uses Graph Neural Networks (GNN) ensemble learning. GNN ensemble learning is a type of machine learning that combines multiple GNN models to improve the detection accuracy. We evaluated our approach on the Canadian Institute for Cybersecurity Intrusion Detection Evaluation Dataset (CICIDS2018) and CICIDS2017 datasets, a benchmark dataset for DDoS attack detection. Our work provides two main contributions. First, we extend our DDoS attack detection approach using GNN ensemble learning. Second, we explore the evaluation and fine-tuning of hyperparameter metrics through ensemble learning, significantly enhancing accuracy compared to a single GNN model and achieving an average 3.2% higher F1-score. Additionally, our approach effectively reduces overfitting by incorporating regularization techniques, such as dropout and early stopping. Specifically, we use a hierarchical ensemble of GNN, where each GNN learns the relationships between traffic flows at a different granularity level. We then use bagging and boosting to combine the predictions of the individual GNN, further improving detection accuracy. Results show that our system can achieve 99.67% accuracy, with a F1-score of 99.29%, which is better than state-of-the-art methods, even using single traffic architecture. Rana Abubakar, Lorenzo De Marinis, Filippo Cugini, Francesco Paolucci |
Comput. Networks | 1 |
| 2023 | Cascaded Look Up Table Distillation of P4 Deep Neural Network SwitchesabstractIn-network function offloading represents a key enabler of the SDN-based data plane programmability to enhance network operation and awareness while speeding up applications and reducing the energy footprint. The offload of network functions exploiting machine learning and artificial intelligence has been recently considered with intermediate solutions such as feature extraction acceleration and mixed architectures including AI-specific platforms (e.g., GPU, FPGA). Indeed, the P4 language enables the programmability of deep neural networks inside the pipelines of both software and hardware switches and NICs. However, programmable hardware pipeline chipsets suffer from significant computing capability limitations (e.g., missing arithmetic logic units, limited and slow stateful registers) preventing the plain programmability of a deep neural network (DNN) operating at wirespeed. This paper proposes an innovative knowledge distillation technique that maps a DNN into a cascade of lookup tables (i.e., flow tables) with limited entry size. The proposed mapping avoids stateful elements and maths operators, whose requirement prevented the deployment of DNNs within hardware switches up to now. The evaluation is carried out considering a cyber security use case targeting a DDoS mitigator network function, showing negligible impact due to the lossless mapping reduction and feature quantization. Lorenzo De Marinis, Emilio Paolini, Rana Abubakar, Filippo Cugini, Francesco Paolucci |
GLOBECOM | 3 |
| 2023 | LSNCP: Lightweight and Secure Numeric Comparison Protocol for Wireless Body Area NetworksabstractWireless body area networks (WBANs) have been deployed in numerous applications, where the most common communication technology is Bluetooth. Bluetooth uses the numeric comparison protocol (NCP) to negotiate session keys based on the elliptic curve cryptography (ECC) and Out-of-Band (OoB) channels. However, the scalar multiplication of ECC is a heavy computing operation for devices in WBANs. To address this issue, we propose the lightweight and secure NCP (LSNCP) which requires less scalar multiplication than the NCP in Bluetooth. New logic expressions and rules are proposed to verify the security of LSNCP in GNY logic. The proof shows that LSNCP is secure. We conduct a provable security analysis by integrating the commitment scheme and short hash function. The result shows that LSNCP is secure in the modified Bellare–Rogaway model. Finally, we conduct theoretical analysis and experiments to evaluate the performance of LSNCP. The results confirm that LSNCP has less computation cost than NCP and other benchmark protocols. LSNCP has many potential application scenarios, such as healthcare, Metaverse, and blockchain. Haotian Yin, Xin Huang 0005, Xiaoxin Sun, Jianshuang Li, Sheng Chai, Rana Abubakar, Wei Wang 0042 |
IEEE Internet Things J. | 9 |