VLDB 2026 Research / reviewers in the wild / expert
Khaled Sarieddine
dblp:274/8976
· DBLP profile ↗
11ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0002-6099-2502ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Plug and prey: Exploiting design flaws to hijack EV charging stationsabstractElectric Vehicles (EVs) have become a major element in the global push to combat climate change, given their ability to reduce the transportation sector’s emissions. To support the increasing number of EVs on the road, EV Charging Stations (EVCSs) are being deployed and have become a core element of the transportation infrastructure. EVCSs with individual web portals have been widely studied and proven to be vulnerable to network-based attacks. On the other hand, EVCSs that do not host web portals and cannot be accessed remotely are considered more secure. These EVCSs are generally considered to be more secure and have been overlooked in previous studies. Consequently, in this work, we present the first attack framework that exploits design flaws in this type of EVCS to hijack their operation. Our tests were performed on six actual EVCSs that follow the deployment strategy commonly preferred in North America by most operators and a few operators in Europe. We demonstrate how adversaries can successfully exploit the discussed vulnerabilities to gain unauthorized access to the EVCS configuration and acquire administrator privileges. We then proceed to craft multiple attacks to affect the power grid, steal money, or deteriorate EVCS availability. Mohammad Ali Sayed, Khaled Sarieddine, Rinith Reghunath, Chadi Assi, Mourad Debbabi |
Comput. Secur. | 2 |
| 2025 | Electric Vehicle Switching Attacks Against Subsynchronous Stability of Power SystemsabstractThe deployment of electric vehicles (EVs) requires the integration of information and communication technologies, making power grids prone to cyber threats from EV cyber-infrastructure. On this basis, this paper studies the impact of a new family of EV-based load-altering attacks (EV-LAA) against the subsynchronous stability of the power grid. First, the cyber-physical connections between the EV ecosystem and the power grid are discussed to represent a threat model for coordinated electric vehicle switching attacks (EVSAs) that can excite torsional modes of the system. Then, it will be demonstrated that a traditional proportional-integral (PI)-based subsynchronous resonance damping controller (SSRDC) cannot stabilize the power grid. With the help of a customized unknown input observer (UIO), an adaptive control framework is developed based on a model predictive control (MPC). This framework can generate online control signals and add them to the internal control framework of the synchronous generators (SGs). A modified IEEE Second Benchmark (M-IEEE-SBM) is used to demonstrate the EV-LAAs' consequences and evaluate the effectiveness of the developed adaptive technique. The proposed strategy is also studied through real-time simulations under a testbed that integrates a virtual sphere (vSphere) for an EV ecosystem with power grids simulated in a real-time simulator (i.e., OPAL-RT 5650). To demonstrate the feasibility of this switching attack vector in an actual power system and its impact on SSR stability, the Palo Verde Nuclear Generating Station (PVNGS) is also simulated in this real-time simulator, and the effectiveness of the proposed adaptive control framework is validated under the EV-LAAs. Ahmadreza Abazari, Khaled Sarieddine, Mohsen Ghafouri, Danial Jafarigiv, Ribal Atallah, Chadi Assi |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | Uncovering Covert Attacks on EV Charging Infrastructure: How OCPP Backend Vulnerabilities Could Compromise Your SystemabstractThe Electric Vehicle (EV) charging infrastructure has been rapidly expanding to keep up with the increased demands of EV consumers. This government-backed infrastructure expansion resulted in the rushed integration of a significant number of insecure EV Charging Stations (EVCS), which are vulnerable to cyber-attacks. Motivated by the uncovered vulnerabilities in different components of the EV charging infrastructure, in this paper, we study the security of the EVCS Cloud Management System (CMS). Specifically, we focus on the (in)security of the Open Charge Point Protocol (OCPP) backend communication with the EVCS. We verified the prevalence of such security weaknesses by discovering 6 zero-day vulnerabilities in each of the 16 representative live EV charging management systems. Our findings highlight the insecurity of the OCPP backend, which is widely deployed on existing EVCSs in the wild. Indeed, we discuss various attack scenarios that lead to man-in-the-middle, denial of service, firmware theft, and data poisoning, to name a few. We also leverage the developed testbed to demonstrate the feasibility of launching switching attacks against the power grid using compromised EVCSs. Finally, we contribute to the security of the EV charging ecosystem by also recommending countermeasures to mitigate/prevent future cyber-attacks. Khaled Sarieddine, Mohammad Ali Sayed, Sadegh Torabi, Ribal Atallah, Danial Jafarigiv, Chadi Assi, Mourad Debbabi |
AsiaCCS | 1 |
| 2024 | A Real-time Monitoring Architecture for Enhanced Cybersecurity in the EV EcosystemabstractElectric Vehicles (EV) have experienced a tremendous rise in popularity as they offer a sustainable alternative to conventional vehicles. However, the EV ecosystem is a complex system consisting of many interconnected components such as the EV Charging Station (CS) and the EV Charging Station Management System (CSMS). Given its connection to the smart grid and its direct impact on the transportation sector, securing the EV ecosystem is essential and requires the design of novel monitoring solutions. Previous studies proposed single-component detection mechanisms that cannot detect all potential anomalies across the system. Our work addresses this issue through the combination and correlation of monitoring data collected from the different EV ecosystem components. Our objective is to develop a real-time monitoring platform for attack detection in the public EV charging ecosystem that is based on the extension of the IEC 62351-7:2017 Network and System Management (NSM) standard. By adopting an international security standard, we ensure the monitoring platform is compatible with international power systems. To validate the utility of the approach, we integrate the monitoring framework with a real-time EV charging cosimulation testbed and discuss how it can be used to detect EV-based cyberattacks. Rinith Reghunath, M. A. Sayed, Khaled Sarieddine, Ribal Atallah, Danial Jafarigiv, Marthe Kassouf, Chadi Assi, Mohsen Ghafouri |
IECON | 3 |
| 2024 | A Data-Driven Framework for Improving Public EV Charging Infrastructure: Modeling and ForecastingabstractThis work presents an investigation and assessment framework, which, supported by realistic data, aims at provisioning operators with in-depth insights into the consumer-perceived Quality-of-Experience (QoE) at public Electric Vehicle (EV) charging infrastructures. Motivated by the unprecedented EV market growth, it is suspected that the existing charging infrastructure will soon be no longer capable of sustaining the rapidly growing charging demands; let alone that the currently adopted ad hoc infrastructure expansion strategies seem to be far from contributing any quality service sustainability solutions that tangibly reduce (ultimately mitigate) the severity of this problem. Without suitable QoE metrics, operators, today, face remarkable difficulty in assessing the performance of EV Charging Stations (EVCSs) in this regard. This paper aims at filling this gap through the formulation of novel and original critical QoE performance metrics that provide operators with visibility into the per-EVCS operational dynamics and allow for the optimization of these stations’ respective utilization. Such metrics shall then be used as inputs to a Machine Learning model finely tailored and trained using recent real-world data sets for the purpose of forecasting future long-term EVCS loads. This will, in turn, allow for making informed optimal EV charging infrastructure expansions that will be capable of reliably coping with the rising EV charging demands and maintaining acceptable QoE levels. The model’s accuracy has been tested and extensive simulations are conducted to evaluate the achieved performance in terms of the above-listed metrics and show the suitability of the recommended infrastructure expansions. Nassr Al-Dahabreh, Mohammad Ali Sayed, Khaled Sarieddine, Mohamed Kadry Elhattab, Maurice Khabbaz, Ribal Atallah, Chadi Assi |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2024 | EV Charging Infrastructure Discovery to Contextualize Its Deployment SecurityabstractElectric Vehicle Charging Stations (EVCSs) have been shown to be susceptible to remote exploitation due to manufacturer-induced vulnerabilities, demonstrated by recent attacks on this ecosystem. What is more alarming is that compromising these high-wattage IoT systems can be leveraged to perform coordinated oscillatory load attacks against the power grid which could lead to the instability of this critical infrastructure. In this paper, we investigate a previously sidelined aspect of EVCS security. We analyze the deployment security of EVCSs and highlight operator-induced vulnerabilities rendering the ecosystem exposed to remote intrusions. We create an advanced discovery technique that leverages Web interface artifacts to dynamically discover new charging station vendors. As a result, we uncover 33,320 charging station management systems in the wild. Consequently, we study the deployment security of the charging stations and identify that 28,046 EVCSs were found to be vulnerable to eavesdropping, and around 24% of the studied EVCSs are deployed with default configurations exposing the ecosystem to a Mirai-like attack vector. Aligned with this finding, we discover that the EVCS ecosystem has been targeted by nefarious IoT malware such as Mirai and its variants. This demonstrates that further security measures should be implemented by vendors and operators to ensure the security of this vital ecosystem. Consequently, we provide a comprehensive recommendation for securing the deployment of EVCSs. Khaled Sarieddine, Mohammad Ali Sayed, Chadi Assi, Ribal Atallah, Sadegh Torabi, Joseph Khoury, Morteza Safaei Pour, Elias Bou-Harb |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Quality of Service Evaluation and Forecast for EV Charging Based on Real-World DataabstractIn line with the global push towards smart cities, the world is increasingly adopting Electric Vehicles (EVs). This increased EV proliferation is putting the Public Charging Infrastructure (PCI) under a large strain. To this end, this work presents a data-driven analysis of the Quality of Service (QoS) on the current EV PCI. This work presents a comprehensive set of metrics that are developed to evaluate the QoS at the current PCI in Quebec, Canada. The analysis is performed on a real dataset covering 5 full years of over 7,000 EV Charging Stations (EVCSs) in Quebec. This data is then used to create a forecast model for predicting future EV charging requests and assessing their impact on the QOS at the current PCI deployment levels. The developed metrics and forecast model are used to recommend new EVCS deployment sites to guarantee acceptable QoS levels in the future based on the current trends in EV adoption. Ribal Atallah, Nassr Al-Dahabreh, Mohammad Ali Sayed, Khaled Sarieddine, Mohamed Kadry Elhattab, Maurice Khabbaz, Chadi Assi |
WiMob | 4 |
| 2023 | Investigating the Security of EV Charging Mobile Applications as an Attack SurfaceabstractThe adoption rate of EVs has witnessed a significant increase in recent years driven by multiple factors, chief among which is the increased flexibility and ease of access to charging infrastructure. To improve user experience and increase system flexibility, mobile applications have been incorporated into the EV charging ecosystem. EV charging mobile applications allow consumers to remotely trigger actions on charging stations and use functionalities such as start/stop charging sessions, pay for usage, and locate charging stations, to name a few. In this article, we study the security posture of the EV charging ecosystem against a new type of remote that exploits vulnerabilities in the EV charging mobile applications as an attack surface. We leverage a combination of static and dynamic analysis techniques to analyze the security of widely used EV charging mobile applications. Our analysis was performed on 31 of the most widely used mobile applications including their interactions with various components such as cloud management systems. The attack scenarios that exploit these vulnerabilities were verified on a real-time co-simulation test bed. Our discoveries indicate the lack of user/vehicle verification and improper authorization for critical functions, which allow adversaries to remotely hijack charging sessions and launch attacks against the connected critical infrastructure. The attacks were demonstrated using the EVCS mobile applications showing the feasibility and the applicability of our attacks. Indeed, we discuss specific remote attack scenarios and their impact on EV users. More importantly, our analysis results demonstrate the feasibility of leveraging existing vulnerabilities across various EV charging mobile applications to perform wide-scale coordinated remote charging/discharging attacks against the connected critical infrastructure (e.g., power grid), with significant economical and operational implications. Finally, we propose countermeasures to secure the infrastructure and impede adversaries from performing reconnaissance and launching remote attacks using compromised accounts. Khaled Sarieddine, Mohammad Ali Sayed, Sadegh Torabi, Ribal Atallah, Chadi Assi |
ACM Trans. Cyber Phys. Syst. | 1 |
| 2022 | An Opportunistic Vehicle-Based Task Assignment for IoT offloading
Khaled Sarieddine, Hassan Artail, Haïdar Safa |
Comput. Networks | 1 |
| 2022 | On Ransomware Family Attribution Using Pre-Attack Paranoia ActivitiesabstractRansomware attacks are among the most disruptive cyber threats, causing significant financial losses while impacting productivity, accessibility, and reputation. Despite their end goals (encryption/locking), ransomware are often designed to evade detection by executing a series of pre-attack API calls, namely “paranoia” activities, for determining a suitable execution environment. In this work, we present a first-of-a-kind effort to utilize such paranoia activities for characterizing ransomware distinguishable behaviors. To this end, we draw-upon more than 3K samples from recent/prominent ransomware families to fingerprint their uniquely leveraged paranoia activities. Specifically, by leveraging techniques rooted in Natural Language Processing (NLP) such as Occurrence of Words (OoW), we model ransomware-generated evasion API calls while tailoring various machine and deep learning algorithms to perform ransomware classification. The thoroughly conducted evaluations demonstrate the effectiveness of the implemented approach, with the Random Forest (RF) and OoW techniques producing an optimal classification accuracy (94.92%). The insights/findings from this work not only shed light on contemporary ransomware-specific evasion methods, but also (i) indicates that such tactics could be employed effectively as features for ransomware family attribution while (ii) laying the foundation for implementing proactive and portable countermeasures for further ransomware attack detection/mitigation by solely utilizing ransomware-generated paranoia activities. Ricardo Misael Ayala Molina, Sadegh Torabi, Khaled Sarieddine, Elias Bou-Harb, Nizar Bouguila, Chadi Assi |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | A framework for mobile relay node selection for serving outdoor cell edge users
Khaled Sarieddine, Malak Charaf, Mohammad Ayad, Hassan Artail |
Comput. Networks | 1 |