Zahra Jadidi

dblp:31/9352 · DBLP profile ↗
← Back
20ranked-venue papers
3as first author
16since 2021 · last 2026
0000-0002-6694-7753ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 1 first-author · 9 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A structure-aware and explainable approach to website fingerprinting using graph neural networks
abstract
Website fingerprinting (WF) poses a significant threat to anonymity networks such as Tor, allowing adversaries to infer visited sites from encrypted traffic. Packet direction has emerged as a dominant feature in WF, outperforming timing and size-based features, even against Tor defences, particularly when leveraged by deep learning (DL) models, yet its resilience remains poorly understood. To investigate this behaviour, we propose a structure-aware WF method that represents each traffic trace as a graph in which nodes correspond to burst-level temporal bins and edges encode both temporal adjacency and data driven dependencies estimated through mutual information. This graph formulation organises burst-level directional information into a topology that exposes temporal continuity and dependency structure across the trace, enabling a GNN to learn request response sequencing, inter-burst interactions, chronology, and non-local dependencies. Directional features show stronger transferability because they are represented at a coarse-grained burst level. This preserves stable web interaction patterns while suppressing packet-level details that are susceptible to distortion by Tor defences, such as obfuscation, including packet-length obfuscation. In closed-world experiments, the proposed method achieves the highest average defended accuracy of 62.99%, while in open-world settings it yields superior precision–recall performance. The graph representation supports a structured examination of traffic traces, providing insights into the robustness of packet direction across defence scenarios and illustrating how graph-based modelling can strengthen systems for encrypted-traffic analysis.
Zulu Okonkwo, Ernest Foo, Qinyi Li, Zahra Jadidi
Inf. Sci.5
2026 Vulnerabilities in Machine Learning for cybersecurity: Current trends and future research directions
abstract
Machine learning (ML) has become integral to cybersecurity applications, e.g., phishing detection, intrusion detection systems, malware analysis, and botnet identification. However, the integration of ML also exposes novel attack surfaces that can be exploited through adversarial machine learning (AML). While prior surveys have examined individual threats or defenses, they often focus narrowly on specific stages, e.g., training or testing. In contrast, in this paper, we provide the first comprehensive survey of adversarial attacks and defenses across the entire ML development life cycle within the cybersecurity domain. Using a structured methodology, we categorize vulnerabilities and countermeasures at each stage, data gathering, model training, testing, deployment, and maintenance, highlighting cross-stage interactions and emerging distributed threat models. Our study addresses key gaps in current defenses, including their limited generalizability and lack of standardized evaluation practices, and identifies promising directions, e.g., lifecycle-aware robustness, distributed resilience, and the integration of statistical with generative methods. Consolidating fragmented research into an end-to-end perspective, this study advances the understanding of AML in cybersecurity and outlines a roadmap for building more trustworthy, and resilient ML-driven security systems.
Shantanu Pal, Geeta Yadav, Zahra Jadidi, Ahsan Habib 0003, Md Palash Uddin, Chandan K. Karmakar, Sandeep K. Shukla
J. Inf. Secur. Appl.3
2025 A graph representation framework for encrypted network traffic classification
abstract
Network Traffic Classification (NTC) is crucial for ensuring internet security, but encryption presents significant challenges to this task. While Machine Learning (ML) and Deep Learning (DL) methods have shown promise, issues such as limited representativeness leading to sub-optimal generalizations and performance remain prevalent. These problems become more pronounced with advanced obfuscation, network security, and privacy technologies, indicating a need for improved model robustness. To address these issues, we focus on feature extraction and representation in NTC by leveraging the expressive power of graphs to represent network traffic at various granularity levels. By modeling network traffic as interconnected graphs, we can analyze both flow-level and packet-level data. Our graph representation method for encrypted NTC effectively preserves crucial information despite encryption and obfuscation. We enhance the robustness of our approach by using cosine similarity to exploit correlations between encrypted network flows and packets, defining relationships between abstract entities. This graph structure enables the creation of structural embeddings that accurately define network traffic across different encryption levels. Our end-to-end process demonstrates significant improvements where traditional NTC methods struggle, such as in Tor classification, which employs anonymization to further obfuscate traffic. Our packet-level classification approach consistently outperforms existing methods, achieving accuracies exceeding 96%.
Zulu Okonkwo, Ernest Foo, Qinyi Li, Zahra Jadidi
Comput. Secur.5
2025 Robust Cyber Threat Intelligence Sharing Using Federated Learning for Smart Grids
abstract
Given the escalating diversity, sophistication, and frequency of cyber attacks, it is imperative for critical infrastructure entities, e.g. smart grids, to recognize the inherent risks of operating in isolation. Sharing cyber threat intelligence (CTI) helps them stand together and build a collective cyber defense by knowledge, skills, and experience encompassing information related to identifying and evaluating cyber and physical threats. The present studies lack on robust CTI sharing strategies in smart grid systems. To address the critical need for secure and effective CTI sharing in smart grid systems, this article proposes a novel approach. Our solution leverages encrypted federated learning (FL) with integrated malicious client detection mechanisms. This approach facilitates collaborative learning of a threat detection model while preserving the privacy of raw CTI data. Employing real-world, heterogeneous smart grid datasets, we rigorously evaluated our approach under two distinct attack scenarios. The results demonstrate resilience against both man-in-the-middle attacks and malicious clients, exceeding the performance typically observed in traditional FL models.
Saifur Rahman 0002, Shantanu Pal, Zahra Jadidi, Chandan K. Karmakar
IEEE Trans. Comput. Soc. Syst.3
2024 Contextual Transformer-based Node Embedding for Vulnerability Detection using Graph Learning
abstract
Automated source code vulnerability detection using code graphs has seen major improvements in recent years, however one critical, but oft-overlooked, element of this problem is producing embeddings for graph nodes. Before graph-based classifiers can be used for vulnerability detection, the nodes in the graph must first be given vector representations. Graphlearning models propagate information from these embeddings through the graph before classification, and so the initial states of these embeddings are vital for all subsequent learning. While a variety of solutions to this problem have been proposed in existing literature, this is typically not the focus of these works. We propose a novel node embedding strategy for graph-based vulnerability discovery, which takes advantage of richly-learned information about the code contained in each node. We also implement and test several existing node embedding strategies, comparing them to each other and our new strategy under a standard graph-learning architecture. We find that our strategy outperforms existing methods by 10.47-50.70%.
Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson
TrustCom5
2024 Improved Packet-Level Synthetic Network Traffic Generation
abstract
While using generative models to create synthetic network traffic is faster and cheaper than traditional testbeds, synthetic traffic suffers from problems with realism and structural completeness. State of the art traffic generation frameworks usually omit payloads because of the difficulties in representing their high-dimensional data, which makes the synthetic traffic unrealistic and limits its usefulness. This work proposes a two-stage process that takes advantage of the high repetition of some protocols, particularly those used by Industrial Control Systems, to selectively simplify payloads, greatly reducing the number of classes and reducing model loss and consequently the ability of the model to handle sequences of payloads. Model training loss was reduced by 47.796%, and payload class selection was improved up to 69% over state of the art approaches, allowing for more realistic synthetic network traffic with reduced memory and computation overheads.
Jacob Soper, Yue Xu 0001, Ernest Foo, Zahra Jadidi, Kien Nguyen Thanh
TrustCom4
2024 Priv-Share: A privacy-preserving framework for differential and trustless delegation of cyber threat intelligence using blockchain
abstract
The emergence of the Internet of Things (IoT), Industry 5.0 applications and associated services have caused a powerful transition in the cyber threat landscape. As a result, organisations require new ways to proactively manage the risks associated with their infrastructure. In response, a significant amount of research has focused on developing efficient Cyber Threat Intelligence (CTI) sharing. However, in many cases, CTI contains sensitive information that has the potential to leak valuable information or cause reputational damage to the sharing organisation. While a number of existing CTI sharing approaches have utilised blockchain to facilitate privacy, it can be highlighted that a comprehensive approach that enables dynamic trust-based decision-making, facilitates decentralised trust evaluation and provides CTI producers with highly granular sharing of CTI is lacking. Subsequently, in this paper, we propose a blockchain-based CTI sharing framework, called Priv-Share, as a promising solution towards this challenge. In particular, we highlight that the integration of differential sharing, trustless delegation, democratic group managers and incentives as part of Priv-Share ensures that it can satisfy these criteria. The results of an analytical evaluation of the proposed framework using both queuing and game theory demonstrate its ability to provide scalable CTI sharing in a trustless manner. Moreover, a quantitative evaluation of an Ethereum proof-of-concept prototype demonstrates that applying the proposed framework within real-world contexts is feasible.
Kealan Dunnett, Shantanu Pal, Zahra Jadidi, Volkan Dedeoglu, Raja Jurdak
Comput. Networks3
2024 Current approaches and future directions for Cyber Threat Intelligence sharing: A survey
abstract
Cyber Threat Intelligence (CTI) is essential knowledge concerning cyber and physical threats aimed at mitigating potential cyber attacks. The rapid evolution of Information and Communications Technology (ICT), the Internet of Things (IoT), and Industry 5.0 has spawned a multitude of sources regarding current or potential cyber threats against organizations. Consequently, CTI sharing among organizations holds considerable promise for facilitating swift responses to attacks and enabling mutual benefits through active participation. However, exchanging CTI among different organizations poses significant challenges, including legal and regulatory obligations, interoperability standards, and data reliability. The current CTI sharing landscape remains inadequately explored, hindering a comprehensive examination of organizations’ critical needs and the challenges they encounter during CTI sharing. This paper presents a comprehensive survey on CTI sharing, beginning with an exploration of CTI fundamentals and its advancements in assessing cyber and physical threats and threat actors from various perspectives. For instance, we discuss the benefits of CTI, its applications, and diverse CTI sharing architectures. Additionally, we extensively discuss a list of CTI sharing challenges and evaluate how available CTI sharing proposals address these challenges. Finally, we provide an inventory of unique future research directions to offer insightful guidelines for CTI sharing.
Poopak Alaeifar, Shantanu Pal, Zahra Jadidi, Mukhtar Hussain, Ernest Foo
J. Inf. Secur. Appl.3
2023 Encrypted Network Traffic Classification with Higher Order Graph Neural Network
Zulu Okonkwo, Ernest Foo, Qinyi Li, Zahra Jadidi
ACISP5
2023 A Blockchain-Based Framework for Scalable and Trustless Delegation of Cyber Threat Intelligence
abstract
CTI sharing is increasingly used by organisations to strengthen security. The sensitivity of CTI has led to research on trust-based sharing, yet most existing CTI sharing approaches only support static trust-based decisions or centralised trust evaluation, limiting their scalability and lead to centralised risk. This paper proposes a blockchain-based CTI sharing framework that relies on trustless delegates for dynamic trust-based decision-making and decentralised trust evaluation. To facilitate trustless delegation, our proposal allows CTI producers to intentionally inject false data on a periodic basis into the system to audit the behaviour of delegates. Moreover, unlike existing approaches, delegates within our framework facilitate sharing of CTI directly with consumers such that scalable CTI sharing occurs. The results of a qualitative evaluation of the proposed framework's security show that it is resilient to common privacy and trust concerns. Moreover, a quantitative evaluation of a proof-of-concept prototype using Ethereum show that the proposed framework is scalable and cost-effective.
Kealan Dunnett, Shantanu Pal, Zahra Jadidi, Raja Jurdak
ICBC3
2023 Discovering a data interpreted petri net model of industrial control systems for anomaly detection
Mukhtar Hussain, Colin J. Fidge, Ernest Foo, Zahra Jadidi
Expert Syst. Appl.4
2022 A Democratically Anonymous and Trusted Architecture for CTI Sharing using Blockchain
abstract
Cyber Threat Intelligence (CTI) sharing has become a significant issue with the increasing number of cyberattacks. In CTI sharing, one entity (e.g., an organisation or a user) intends to share specific threat information to another entity that might otherwise be unavailable to another entity. However, this process needs to address many challenges, including privacy, trust, and accountability. In this paper, we propose a novel blockchain-based architecture that facilitates the secure dissemination of CTI data. The motivation for this study is to provide a solution that can efficiently address privacy, trust, and accountability when sharing CTI among organisations as well as maintaining an intelligence-based informed decisions. We discuss the current problems within the domain of CTI sharing using blockchain, and our proposal leverages the salient properties of the blockchain, e.g., decentralised, cryptographic keys, immutability, etc., to address those issues. We discuss the detailed design of the proposed architecture. We demonstrate that our approach offers a more effective and efficient way of CTI sharing that has the potential to overcome the trust barriers, data privacy, and accountability issues inherent in this domain.
Kealan Dunnett, Shantanu Pal, Zahra Jadidi, Guntur D. Putra, Raja Jurdak
ICCCN3
2022 Security of Machine Learning-Based Anomaly Detection in Cyber Physical Systems
abstract
With the emergence of the Internet of Things (IoT) and Artificial Intelligence (AI) services and applications in the Cyber Physical Systems (CPS), the methods of protecting CPS against cyber threats is becoming more and more challenging. Various security solutions are implemented to protect CPS networks from cyber attacks. For instance, Machine Learning (ML) methods have been deployed to automate the process of anomaly detection in CPS environments. The core of ML is deep learning. However, it has been found that deep learning is vulnerable to adversarial attacks. Attackers can launch the attack by applying perturbations to input samples to mislead the model, which results in incorrect predictions and low accuracy. For example, the Fast Gradient Sign Method (FGSM) is a white-box attack that calculates gradient descent oppositely to maximize the loss and generates perturbations by adding the gradient to unpolluted data. In this study, we focus on the impact of adversarial attacks on deep learning-based anomaly detection in CPS networks and implement a mitigation approach against the attack by retraining models using adversarial samples. We use the Bot-IoT and Modbus IoT datasets to represent the two CPS networks. We train deep learning models and generate adversarial samples using these datasets. These datasets are captured from IoT and Industrial IoT (IIoT) networks. They both provide samples of normal and attack activities. The deep learning model trained with these datasets showed high accuracy in detecting attacks. An Artificial Neural Network (ANN) is adopted with one input layer, four intermediate layers, and one output layer. The output layer has two nodes representing the binary classification results. To generate adversarial samples for the experiment, we used a function called the 'fast_gradient_method’ from the Cleverhans library. The experimental result demonstrates the influence of FGSM adversarial samples on the accuracy of the predictions and proves the effectiveness of using the retrained model to defend against adversarial attacks.
Zahra Jadidi, Shantanu Pal, Nithesh Nayak K, Arawinkumaar Selvakkumar, Chih-Chia Chang, Maedeh Beheshti, Alireza Jolfaei
ICCCN1
2022 A Trusted, Verifiable and Differential Cyber Threat Intelligence Sharing Framework using Blockchain
abstract
Cyber Threat Intelligence (CTI) is the knowledge of cyber and physical threats that help mitigate potential cyber attacks. The rapid evolution of the current threat landscape has seen many organisations share CTI to strengthen their security posture for mutual benefit. However, in many cases, CTI data contains attributes (e.g., software versions) that have the potential to leak sensitive information or cause reputational damage to the sharing organisation. While current approaches allow restricting CTI sharing to trusted organisations, they lack solutions where the shared data can be verified and disseminated ‘differentially’ (i.e., selective information sharing) with policies and metrics flexibly defined by an organisation. In this paper, we propose a blockchain-based CTI sharing framework that allows organisations to share sensitive CTI data in a trusted, verifiable and differential manner. We discuss the limitations associated with existing approaches and highlight the advantages of the proposed CTI sharing framework. We further present a detailed proof of concept using the Ethereum blockchain network. Our experimental results show that the proposed framework can facilitate the exchange of CTI without creating significant additional overheads.
Kealan Dunnett, Shantanu Pal, Guntur D. Putra, Zahra Jadidi, Raja Jurdak
TrustCom4
2022 SCEVD: Semantic-enhanced Code Embedding for Vulnerability Discovery
abstract
Source code vulnerability detection is a major goal in security research. In recent years, deep learning methods have been applied to this end, however the task of embedding code into vector representations as input for deep learning models has yet to be definitively solved. The use of graphs, specifically Abstract Syntax Trees and Code Property Graphs, is a promising research direction for this task, however learning from graphs grows prohibitively computationally expensive for large graphs. No close examination of intelligent ways to prune this input to only vulnerability-relevant information has yet been performed. Additionally, most existing works focus largely on structural information from graphs, often neglecting information contained within the nodes themselves. We address these gaps in the prior research by proposing SCEVD: a deep learning model for vulnerability discovery which utilises semantic information to intelligently select features in source code graphs for learning. It uses information contained within code graph nodes, as well as information about their relationships with one another to select the code graph features which are most relevant to code vulnerability. We implement SCEVD and conduct experiments using the SARD Juliet test suite, finding that we are able to improve vulnerability discovery results using this process of semantic-enhanced code graph feature selection.
Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson
TrustCom5
2022 Discovering Data-Aware Mode-Switching Constraints to Monitor Mode-Switching Decisions in Supervisory Control
abstract
In a multimode industrial control system, mode switching decisions have to follow standard operating procedures which are set for the safety of the system based on the operating limitations of equipment. A rich literature can be found on monitoring multimode systems. However, that work is mainly focused on mode identification and monitoring anomalies in the process running under each mode. Instead, we present a data-driven method for monitoring the modes’ switching constraints. This article is based on state-transition matrix and decision-tree methods to discover data-driven mode switching conditions. Moreover, our approach is not limited to only threshold based condition learning. To capture data trajectory-based conditions, we adopt a functional data descriptors method. In practical experiments, we showed that our approach can discover anomalous mode-switching decisions which cannot be discovered by previous multimode process-monitoring methods.
Mukhtar Hussain, Colin J. Fidge, Ernest Foo, Zahra Jadidi
IEEE Trans. Ind. Informatics4
2020 Securing Manufacturing Using Blockchain
abstract
Due to the rise of Industrial Control Systems (ICSs) cyber-attacks in the recent decade, various security frameworks have been designed for anomaly detection. While advanced ICS attacks use sequential phases to launch their final attacks, existing anomaly detection methods can only monitor a single source of data. However, analysis of multiple security data could provide more comprehensive and system-wide anomaly detection in industrial networks. In this paper, we present an anomaly detection framework for ICSs that consists of two stages: i) blockchain-based log management where the logs of ICS devices are collected in a secure and distributed manner, and ii) multi-source anomaly detection where the blockchain logs are analysed using multi-source deep learning which in turn provides a system wide anomaly detection method. We validated our framework using two ICS datasets: a factory automation dataset and a Secure Water Treatment (SWaT) dataset. These datasets contain physical and network level normal and abnormal traffic. The performance of our new framework is compared with single-source machine learning methods. The precision of our framework is 95% which is comparable with single-source anomaly detectors. However, multi-source analysis is more robust because it can detect anomalies from multiple sources simultaneously, while achieving comparable precision for each of the sources.
Zahra Jadidi, Ali Dorri, Raja Jurdak, Colin J. Fidge
TrustCom1
2014 Flow-based anomaly detection in high-speed links using modified GSA-optimized neural network
Mansour Sheikhan, Zahra Jadidi
Neural Comput. Appl.2
2013 Metaheuristic algorithms based Flow Anomaly Detector
abstract
Increasing throughput of modern high-speed networks needs accurate real-time Intrusion Detection System (IDS). A traditional packet-based Network IDS (NIDS) is time-intensive as it inspects all packets. A flow-based anomaly detector addresses scalability issues by monitoring only packet headers. This method is capable of detecting unknown attacks in high speed networks. An Artificial Neural Network (ANN) is employed in this research to detect anomalies in flow-based traffic. Metaheuristic optimization algorithms have the potential to achieve global optimal solution. In this paper, two metaheuristic algorithms, Cuckoo and PSOGSA, are examined to optimize the interconnection weights of a Multi-Layer Perceptron (MLP) neural network. This optimized MLP is evaluated with two different flow-based data sets. We then compare the performance of these algorithms. The results show that Cuckoo and PSOGSA algorithms enable high accuracy in classifying benign and malicious flows. However, the Cuckoo has lower training time.
Zahra Jadidi, Vallipuram Muthukkumarasamy, Elankayer Sithirasenan
APCC1
2012 Intrusion detection using reduced-size RNN based on feature grouping
Mansour Sheikhan, Zahra Jadidi, Ali Farrokhi
Neural Comput. Appl.2