VLDB 2026 Research / reviewers in the wild / expert
Lalith Medury
dblp:307/2346
· DBLP profile ↗
5ranked-venue papers
4as first author
5since 2021 · last 2025
0009-0003-5077-3853ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 4 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unmasking IoT Devices: A Dynamic and Adaptive Classification ApproachabstractThe widespread adoption of IoT devices has transformed automation and connectivity across multiple sectors. These devices depend heavily on wireless communication, providing flexibility and enabling real-time data exchange. The unique traffic patterns they generate, shaped by protocol usage, communication frequency, and data exchange behaviors facilitate precise device identification. These patterns can be leveraged to classify devices based solely on their network activity. Current approaches to IoT device identification rely on single machine-learning classifiers trained on historical traffic data. However, these systems face critical limitations, including an inability to detect new devices, failure to adapt to shifting traffic patterns, and challenges with imbalanced data representation, thus requiring frequent re-training of the classifier. To address these challenges, we propose UMIoT, a dynamic and adaptive Multi-Classifier based framework for device identification. Unlike traditional approaches, UMIoT employs a unique classifier for each device, enhancing identification accuracy and adaptability. Our study evaluates UMIoT's performance and compares with existing device identification approaches using metrics such as accuracy, precision, recall, and F1-score. Our experiments demonstrate that UMIoT achieves 100% accuracy for most devices, with an overall average device identification accuracy of 95.58% across the network. Despite employing multiple classifiers to determine the origin of traffic, UMIoT maintains a low prediction time of 0.2 seconds for 1000 packets, comparable to state-of-theart single-classifier approaches. Additionally, with UMIoT's 60% classifier accuracy threshold, devices entering the network are accurately detected as new devices without misclassifying their traffic as originating from existing devices. Lalith Medury, Luke Robinson, Farah I. Kandah |
ICC | 1 |
| 2025 | A Dynamic GAN-Based Obfuscation Approach Against Profiling AttacksabstractThe rapid growth in the number of wireless IoT devices has introduced new privacy challenges. Adversaries can exploit captured wireless traffic to profile and identify specific devices within the network. While several device identification frameworks have been developed to classify and identify devices, researchers have proposed methods such as traffic padding, shaping, and cover traffic injection to counteract identification attempts. However, these approaches often prove ineffective when adversaries gain access to the network. In this study, we propose a GAN-based traffic generation and injection framework designed to enhance device privacy against traffic analysis attacks, even in the presence of local adversaries. Our approach generates highly realistic network traffic and achieves a 98.5% success rate in seamlessly injecting packets into the network without any observable issues. By reducing the prediction confidence of multiple device identification approaches in predicting the origin of network traffic, our framework effectively enhances the privacy of IoT devices. Furthermore, the proposed solution incurs minimal performance overhead, making it a practical and efficient approach to addressing the growing privacy challenges in wireless networks. Lalith Medury, Luke Robinson, Farah I. Kandah |
LCN | 1 |
| 2025 | Unmasking IoT Devices: A Dynamic and Adaptive Classification ApproachabstractThe proliferation of IoT devices has revolutionized automation and connectivity across various industries. These devices rely extensively on wireless communication, enabling flexibility and real-time data exchange. The unique traffic patterns they produce, shaped by protocol usage, communication frequency, and data exchange behaviors allow for accurate device identification based solely on network activity. Previous research on IoT device identification has shown promise but faces key limitations including scalability, requiring frequent retraining for new devices, and are computationally intensive and unsuitable for real-time use. Reliance on spoofable attributes like IP and MAC addresses, or documentation-based profiling, further reduces reliability. To overcome these limitations, this study introduces UMIoT, an adaptive and dynamic Multi-Classifier framework for IoT device identification. UMIoT is trained on packet-streams, assigns a dedicated classifier to each device, improving accuracy, scalability, and adaptability. Furthermore, UMIoT can efficiently detect the presence of new devices without misclassifying their traffic as belonging to existing devices based on a parameterized confidencethreshold metric. Our experimental results demonstrate that UMIoT achieves high identification accuracy, maintains a low prediction time, enables rapid training for new emerging devices in the network, and operates with minimal storage overhead. Additionally, the results highlight the superiority of the proposed framework against existing device identification approaches both in terms of device identification accuracy and performance metrics including prediction time, storage overhead, and new device training time. The framework is also shown to be resilient against adversarial threats including traffic padding, shaping, and MAC address alteration. Lalith Medury, Luke Robinson, Farah I. Kandah |
IEEE Internet Things J. | 1 |
| 2025 | Clustering-Based Intrusion Detection System Meets Multicritics Generative Adversarial NetworksabstractNetwork security has continuously been a major focus of research and concern on a global scale. The intrusion detection system (IDS), as a crucial defensive measure against network attacks, has undergone multiple iterations and evolutions since its inception to adapt to the ever-changing network environment. Due to the widespread issue of data imbalance in network security datasets, a single machine learning or deep learning model often struggles to effectively handle different types of attacks. In this work, we propose a multicritics generative adversarial networks (GAN) clustering-based IDS (MCGC-IDS) model to address the issue of data imbalance. The quality of the generated data is analyzed using correlation heatmaps and PCA plots, which later is used to update the dataset that is utilized for feature extraction with autoencoders (AEs). Subsequently, CNN-LSTM models are employed to analyze clusters formed by the weighted fuzzy c-means (WFCM) clustering algorithm to achieve enhanced performance for the IDS system. This model is then compared with two existing models. The results indicate that while the GAN-generated data retains the original dataset distribution, it also addresses the issue of imbalance. Moreover, the subsequent multilayered processing enables the overall model to more effectively handle various types of attacks. Finally, when this model is tested on a similar dataset, the UNSW-NB15, it continues to demonstrate superior performance, indicating its strong generalizability. Farah I. Kandah, Thilina Mendis, Lalith Medury |
IEEE Internet Things J. | 4 |
| 2024 | GoNP: Graph of Network Patterns for Device Identification using UDP Application Layer ProtocolsabstractAnalyzing network traffic and identifying unique IoT devices is important to secure and safeguard the IoT network. Machine Learning models have been leveraged to train classifiers to identify network devices based on the network packets. However, past approaches have often involved either MAC address, IP address, or both when identifying IoT devices in a network. These approaches do not consider the challenge of IP and MAC spoofing when developing their classifier models. This research introduces GoNP, a graph-based approach for extracting network traffic patterns and matching them to a corresponding IoT device. In contrast to previous approaches, our approach does not consider IP and MAC addresses during device identification as these can be easily spoofed. We have designed and developed a graph-based device identification model that achieves IoT device identification accuracy of upto 100%. We have evaluated our approach against past approaches that leveraged machine learning classifiers for device identification, and our model performed consistently better when the IP and MAC addresses of network devices are spoofed. Lalith Medury, Farah I. Kandah |
LCN | 1 |