Javad Forough

dblp:285/3540 · DBLP profile ↗
← Back
6ranked-venue papers
6as first author
6since 2021 · last 2026
0000-0003-3399-2440ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Reinforced model selection for resource efficient anomaly detection in edge clouds
abstract
• Adaptive Deep Q-Networks (DQN) Integration: Introduced an innovative model selection strategy that adapts DQN for efficient and effective anomaly detection in edge cloud environments, optimizing resource usage and detection accuracy. • Dynamic Resource Management: Demonstrated how the adapted DQN approach significantly reduces computational resource usage by up to 45%, ensuring efficient operation within resource-constrained edge clouds. • Enhanced Real-Time Detection: Achieved up to 85% reduction in detection time, enabling swift anomaly detection through the adapted DQN strategy, while maintaining acceptable accuracy levels. • Robust Experimental Validation: Implemented a realistic testbed setup and tested the proposed approach, providing a comprehensive evaluation of its feasibility and performance across multiple edge cloud scenarios. • Comprehensive Ablation Analysis: Conducted detailed ablation studies on the reward function and state representation, revealing the critical role of resource-awareness in achieving balanced detection performance. Web application services and networks encounter a broad range of security and performance anomalies, necessitating sophisticated detection strategies. However, performing anomaly detection in edge cloud environments, often constrained by limited resources, presents significant computational challenges and demands minimized detection time for real-time response. In this paper, we propose a model selection approach for resource efficient anomaly detection in edge clouds by leveraging an adapted Deep Q-Network (DQN) reinforcement learning technique. The primary objective is to minimize the computational resources required for accurate anomaly detection while achieving low latency and high detection accuracy. Through extensive experimental evaluation in our testbed setup over different representative scenarios, we demonstrate that our adapted DQN approach can reduce resource usage by up to 45% and detection time by up to 85% while incurring less than an 8% drop in F1 score. These results highlight the potential of the adapted DQN model selection strategy to enable efficient, low-latency anomaly detection in resource-constrained edge cloud environments.
Javad Forough, Monowar Bhuyan, Erik Elmroth
Future Gener. Comput. Syst.1
2026 Dynamic Probabilistic Noise Injection for Membership Inference Defense
abstract
Membership Inference Attacks (MIAs) expose privacy risks by determining whether a specific sample was part of a model’s training set. These threats are especially serious in sensitive domains such as healthcare and finance. Traditional mitigation techniques, such as static differential privacy, rely on injecting a fixed amount of noise during training or inference. However, this often leads to a detrimental trade-off: the noise may be insufficient to counter sophisticated attacks or, when increased, can substantially degrade model accuracy. To address this limitation, we propose DynaNoise, an adaptive inference-time defense that modulates injected noise based on per-query sensitivity. DynaNoise estimates risk using measures such as Shannon entropy and scales the noise variance accordingly, followed by a smoothing step that re-normalizes the perturbed outputs to preserve predictive utility. We further introduce MIDPUT (Membership Inference Defense Privacy-Utility Trade-off), a scalar metric that captures both privacy gains and accuracy retention. Our evaluation on several benchmark datasets demonstrates that DynaNoise substantially lowers attack success rates while maintaining competitive accuracy, achieving strong overall MIDPUT scores compared to state-of-the-art defenses.
Javad Forough, Hamed Haddadi 0001
Proc. Priv. Enhancing Technol.1
2023 Unified Identification of Anomalies on the Edge: A Hybrid Sequential PGM Approach
abstract
Edge cloud resources, just as many other computing resources, are prone to both performance and security anomalies due to their decentralized nature and real-time requirements for processing of data. Their behaviour initially observed as anomalous may, however, in many cases be rather generic and hard to detect. To be able to address such anomalies, it is instrumental to determine whether the anomaly is a "Security" threat or only a "Performance" concern. Therefore, in this paper, we develop an anomaly detection model capable of distinguishing between security and performance anomalies. The model is based on sequential modeling and Probabilistic Graphical Model (PGM), which leverage historical information and dependencies between previous predictions to classify future anomalies accurately. The evaluation of our proposed model shows its superior performance on our testbed and benchmark datasets. Accordingly, the model achieves an average 5%, and 3% higher F1 score compared to state-of-the-art methods in binary and multi-label anomaly detection cases, respectively. Moreover, our testing time analysis demonstrates the ability of the proposed model in early detection of such anomalies on the edge cloud.
Javad Forough, Monowar Bhuyan, Erik Elmroth
TrustCom1
2022 DELA: A Deep Ensemble Learning Approach for Cross-layer VSI-DDoS Detection on the Edge
abstract
Web application services and networks become a major target of low-rate Distributed Denial of Service (DDoS) attacks such as Very Short Intermittent DDoS (VSI-DDoS). These threats exploit the TCP congestion control mechanism to cause transient resource outage and impute delays for legitimate users’ requests, while they bypass the secure systems. Besides that, cross-layer VSI-DDoS attacks, where the performed attacks are towards the different layers of the edge cloud infrastructures, are able to cause violation of customers’ Service-Level Agreements (SLAs) with less visible behavioral patterns. In this work, we propose a novel Deep Ensemble Learning Approach named DELA for detection of cross-layer VSI-DDoS on the edge cloud. This approach is developed based on Long Short-Term Memory (LSTM), ensemble learning, and a new voting mechanism based on Feed-Forward Neural Network (FFNN). In addition, it employs a novel training and detection algorithm to combat such attacks in web services and networks. The model shows improved results due to the utilization of historical information in decision- making and also the usage of neural network as aggregator instead of a static threshold-based aggregation. Moreover, we propose a novel overlapped data chunking algorithm that is able to ameliorate the detection performance. Furthermore, the evaluation of DELA shows its superior performance over our testbed and benchmark datasets. Accordingly, DELA achieves on average 4.88% higher F 1 score compared to state-of-the-art methods.
Javad Forough, Monowar Bhuyan, Erik Elmroth
ICDCS1
2022 Sequential credit card fraud detection: A joint deep neural network and probabilistic graphical model approach
abstract
Abstract With the wide usage of e‐banking in recent years, and by increased opportunities for fraudsters subsequently, we are witnessing a loss of billions of Euros worldwide due to credit card fraud every year. Therefore, credit card fraud detection has become a critical necessity for financial institutions. Several studies have used machine learning techniques for proposing a method to address the problem. However, most of them did not take into account the sequential nature of transactional data. In this paper, we proposed a novel credit card fraud detection model using sequence labelling based on both deep neural networks and probabilistic graphical models (PGM). Then by using two real‐world datasets, we compared our model with the baseline model and examined how considering hidden sequential dependencies among transactions and also among predicted labels can improve the results. Moreover, we introduce a novel undersampling algorithm, which helps to maintain the sequential patterns of data during the random undersampling process. Our experiments demonstrate that this algorithm achieves promising results compared to the state‐of‐the‐art methods in oversampling and undersampling.
Javad Forough, Saeedeh Momtazi
Expert Syst. J. Knowl. Eng.1
2021 Detection of VSI-DDoS Attacks on the Edge: A Sequential Modeling Approach
abstract
The advent of crucial areas such as smart healthcare and autonomous transportation, bring in new requirements on the computing infrastructure, including higher demand for real-time processing capability with minimized latency and maximized availability. The traditional cloud infrastructure has several deficiencies when meeting such requirements due to its centralization. Edge clouds seems to be the solution for the aforementioned requirements, in which the resources are much closer to the edge devices and provides local computing power and high Quality of Service (QoS). However, there are still security issues that endanger the functionality of edge clouds. One of the recent types of such issues is Very Short Intermittent Distributed Denial of Service (VSI-DDoS) which is a new category of low-rate DDoS attacks that targets both small and large-scale web services. This attack generates very short bursts of HTTP request intermittently towards target services to encounter unexpected degradation of QoS at edge clouds. In this paper, we formulate the problem with a sequence modeling approach to address short intermittent intervals of DDoS attacks during the rendering of services on edge clouds using Long Short-Term Memory (LSTM) with local attention. The proposed approach ameliorates the detection performance by learning from the most important discernible patterns of the sequence data rather than considering complete historical information and hence achieves a more sophisticated model approximation. Experimental results confirm the feasibility of the proposed approach for VSI-DDoS detection on edge clouds and it achieves 2% more accuracy when compared with baseline methods.
Javad Forough, Monowar Bhuyan, Erik Elmroth
ARES1