VLDB 2026 Research / reviewers in the wild / expert
Tina Rezaei
dblp:296/4662
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2026
0000-0002-2974-0913ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Understanding the state of IoT-specific vulnerabilities via CVE characterization with LLIoTabstractFollowing the expansion of IoT systems, spanning from devices to cloud backends, reported IoT CVE vulnerabilities have increased at an alarming pace. Since most IoT attacks exploit known vulnerabilities, understanding known vulnerabilities is vital for defense and security research. In this work, we systematize the prior research on studying IoT vulnerabilities, revealing the absence of consistent IoT definitions, reliable and scalable classification methodologies, and high-quality IoT CVE datasets. To overcome these limitations, we design LLIoT, a novel and LLM-assisted approach that systematically and automatically distinguishes IoT-specific CVEs at large scale, enabling in-depth under-standing of IoT vulnerabilities. First, leveraging the systematization knowledge from the literature, we derive a four-layer IoT ecosystem taxonomy and define classification criteria for distinguishing IoT CVEs. Then, using an expert-validated ground-truth dataset, we demonstrate that LLMs can reliably distinguish IoT from non-IoT CVEs with a high accuracy of 95%, outperforming humans by avoiding cognitive errors and gaps in domain knowledge. Applying LLIoT to CVEs from 2013-2024, we build a dataset of 15,116 IoT-specific vulnerabilities, of which 8,368 are newly classified with respect to previous datasets. Using this dataset, which we share with the research community for further research and reproducibility, we characterize how IoT vulnerabilities differ from traditional IT vulnerabilities. Upon our observation, we provide actionable recommendations for responsible stakeholders. Tina Rezaei, Suzan Bayhan, Andrea Continella, Jeroen van der Ham, Roland van Rijswijk-Deij |
EuroS&P | 1 |
| 2024 | ERAFL: Efficient Resource Allocation for Federated Learning Training in Smart HomesabstractWith the growing number of Federated Learning (FL) applications in smart homes, it becomes crucial to manage communication and computation resources within the smart home so that FL applications can complete their training on time. While computation offloading has relieved the challenge of timely completion of applications in case of high competition for local resources, privacy of the smart home data remains a critical concern. This paper introduces ERAFL, a resource allocation and computation offloading algorithm running on a home gateway. Unlike privacy-oblivious prior works, ERAFL considers privacy-sensitivity level of FL training data in offloading decision, prioritizing local processing of more sensitive data, e.g., biological personal data. Moreover, in case of insufficient local resources, ERAFL offloads a part of data and accelerates training by leveraging parallel training on the cloud and the edge device. It also imposes limits on the amount of offloaded data or performs the training either locally or remotely to ensure model accuracy. Our simulation results show that ERAFL can satisfy more FL training tasks and reduce data privacy leakage in comparison to the baselines that do not consider partial offloading, privacy sensitivity of application data or resource allocation. Tina Rezaei, Suzan Bayhan, Andrea Continella, Roland van Rijswijk-Deij |
NOMS | 1 |
| 2021 | A PE header-based method for malware detection using clustering and deep embedding techniques
Tina Rezaei, Farnoush Manavi, Ali Hamzeh |
J. Inf. Secur. Appl. | 1 |