Md. Shamim Towhid

dblp:325/8939 · DBLP profile ↗
← Back
8ranked-venue papers
6as first author
8since 2021 · last 2026
0009-0007-2051-3427ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Leveraging LLM for Enhanced Incident Management in Wireless Networks
abstract
Incident management in telecommunications networks generates large volumes of incident management tickets (IMTs), each containing heterogeneous and often unstructured text describing service outages, performance degradations, or security issues. Accurately categorizing these IMTs into multiple impact and cause labels is essential for rapid diagnosis and resolution. However, existing rule-based and standard language-model-based approaches struggle with noisy data, overlapping categories, and limited contextual understanding. To address these challenges, we propose two complementary solutions for automated multi-label classification of IMTs. To mitigate the effects of noisy data and overlapping categories, the first solution employs an encoder-based language model (i.e., Bidirectional Encoder Representations from Transformers (BERT)) with a relevance-guided feature selection strategy that focuses on semantically meaningful attributes. To improve contextual understanding and label consistency, the second solution leverages a decoder-based large language model (i.e., Phi-3.5) enhanced with retrieval-augmented generation (RAG) and a novel probabilistic re-ranking mechanism to refine label predictions. Experimental results show that our encoder-only model achieves an F1 score of 79.20%, while our RAG-enhanced decoder model achieves 94.98%, outperforming traditional machine learning models and BERT baselines by 23.59% and 29% on average, respectively. These findings demonstrate that combining fine-tuned language models with intelligent retrieval and re-ranking significantly improves classification accuracy in incident management systems.
Md. Shamim Towhid, Nasik Sami Khan, Nashid Shahriar, Massimo Tornatore, Raouf Boutaba, Aladdin Saleh
IEEE J. Sel. Areas Commun.1
2025 Cyber Threat Mitigation with Knowledge-Infused Reinforcement Learning and LLM-Guided Policies
abstract
As cyber threats continue to evolve, there is a need for autonomous cyber defense (ACD) strategies capable of fast and context-aware responses. Reinforcement learning (RL) has shown promise for automating cyber defense by exploring and learning effective countermeasures, yet it often struggles with sparse reward signals and insufficient context to handle diverse attack scenarios. Furthermore, the convergence time taken by an RL agent is often high, which makes it difficult to train the RL agent in online settings. To address these challenges, we propose a large language model (LLM)-enhanced RL method that builds and queries a knowledge graph (KG) derived from agent-environment interactions. We leverage the pre-trained knowledge of an LLM on different cybersecurity frameworks and use the LLM to analyze a part of the KG to generate appropriate actions for the RL agent. We infuse the knowledge extracted from the LLM into the RL agent’s training loop in two ways. First, the state vector of the RL agent is augmented with the most effective action and its corresponding reward, as determined from the KG. Second, the suggested action from the LLM is used as a reference policy. In addition, we introduce a regularization term in the loss function to make the RL policy close to the reference policy. To validate our approach, we develop a custom RL environment guided by the MITRE ATT&CK framework, enabling the agent to generate tailored mitigation strategies for detected cyber attacks. Experimental results show that our proposed approach significantly outperforms the baseline RL by over $75 \%$ in terms of taking better mitigation actions.
Md. Shamim Towhid, Shahrear Iqbal, Euclides Carlos Pinto Neto, Nashid Shahriar, Scott Buffett, Madeena Sultana, Adrian Taylor
PST1
2024 DTL-5G: Deep transfer learning-based DDoS attack detection in 5G and beyond networks
Behnam Farzaneh, Nashid Shahriar, Abu Hena Al Muktadir, Md. Shamim Towhid, Mohammad Sadegh Khosravani
Comput. Commun.4
2023 DTL-IDS: Deep Transfer Learning-Based Intrusion Detection System in 5G Networks
abstract
In the complex landscape of modern networks, the necessity of Intrusion Detection System (IDS) has become paramount. An IDS is a crucial cybersecurity tool that plays a pivotal role in safeguarding networks against a wide array of threats and attacks. The application of deep learning models for intrusion detection is becoming popular among research communities due to its success in many other domains. However, deep learning models require a significant amount of labeled data to achieve effective training. Obtaining labeled data for intrusion detection can be challenging and costly. To address it, Deep Transfer Learning (DTL) can be employed. This research introduces an innovative traffic classification method tailored for 5G networks. The approach leverages deep transfer learning by utilizing pre-trained models and fine-tuning them. We evaluate several deep-learning models in a transfer learning setting. The Inception model being identified as the top-performing model shows an improvement of approximately 10% in terms of F1-score between IDS-based DTL and the same scheme without DTL.
Behnam Farzaneh, Nashid Shahriar, Abu Hena Al Muktadir, Md. Shamim Towhid
CNSM4
2023 A Token-Prioritization Strategy for Handling Data Imbalance in Network-Change Ticket Classification
abstract
Changes are an integral part of the day-to-day operation of large telecommunications networks as they allow to keep pace with technological advancements, meet growing network demands, ensure scalability, enhance security, improve service quality, and meet customer expectations. Changing configurations, installing devices, and migrating traffic are some examples of these changes. These changes are documented by opening tickets through a ticket management system. Automation in the ticket management system is now becoming highly desirable to manage the large number of submitted tickets. An automated ticket management system supports the management of a ticket by automating several parts of a ticket's lifecycle. In this context, ticket classification problem consists in assigning an appropriate label to a ticket to be utilized in the later stages of the ticket management cycle. In this paper, we use a collection of network-change tickets from a real network operator to solve a ticket classification problem. We observe that the network-change ticket dataset is highly skewed in the number of tickets for different possible classes. We address this challenge of classification in a highly imbalanced dataset by proposing two token-prioritization strategies along with other components. We compare three variations of our proposed approach with three methods from the literature and show that the variations of the proposed approach outperform existing methods by up to 7% in terms of F1 score.
Md. Shamim Towhid, Nasik Sami Khan, Nashid Shahriar, Massimo Tornatore, Raouf Boutaba, Aladdin Saleh
CNSM1
2023 Early Detection of Intrusion in SDN
abstract
An intrusion detection system (IDS) is an essential component of any modern network. The purpose of an IDS is to detect intrusion and generate appropriate alarms so that the intrusion can be mitigated. Implementing an IDS in a Software Defined Network (SDN) is easier since an SDN controller has a centralized view of the whole network. Researchers have made many efforts to use machine learning (ML) for developing network-based IDS in SDN. The network-based IDS analyzes different characteristics of incoming network traffic to detect intrusion. Early detection of intrusion is crucial for an IDS because if the intrusion is not detected quickly enough, it can cause severe damage, such as data breaches and service shutdowns. This paper focuses on detecting intrusion in SDN as early as possible using real-time flow-based features. Our aim is to detect intrusion with less amount of packets per flow, which not only facilitates early intrusion detection but also is useful when an intrusion flow has less number of packets. We show that although ML models perform well in offline training on a dataset, their performance decreases ~25% when fewer packets are used to generate features for the ML model. In all our experiments, a simple Random Forest (RF) algorithm outperforms a complex deep learning model on a publicly available dataset for intrusion detection in SDN.
Md. Shamim Towhid, Nashid Shahriar
NOMS1
2022 Encrypted Network Traffic Classification in SDN using Self-supervised Learning
abstract
Network traffic classification has a huge application in software-defined networking (SDN) where we talk about more control over the network traffic. With the increase of encrypted protocols in the network, the problem of traffic classification has become extremely challenging. Many researchers have proposed different techniques to do traffic classification. This demo paper presents an application of our proposed method for traffic classification in an SDN environment. The proposed method leverages one of the self-supervised learning approaches, an emerging field of deep learning, to classify network traffic. This paper shows that the proposed method can outperform the corresponding supervised approach by $\sim 2$% in terms of accuracy using data collected from an SDN testbed. Furthermore, an SDN application is developed to show that the trained model is able to classify real-time traffic.
Md. Shamim Towhid, Nashid Shahriar
NetSoft1
2022 Encrypted Network Traffic Classification using Self-supervised Learning
abstract
Network traffic classification is used in many applications including network provisioning, malware detection, resource management, and so on. In modern networks, use of encrypted protocols is a norm rather than an exception. Existing network traffic classification techniques fall short in working with encrypted traffic. Although deep learning based techniques have been shown to perform well in the case of encrypted traffic classification, they require an abundance of labeled data to achieve high accuracy. However, labeled data is rarely available in sufficient volumes in real network settings as they require domain experts to annotate data with labels. Therefore, in this paper, we propose a self-supervised approach that can achieve high accuracy on encrypted network traffic classification with a few labeled data. The proposed method is evaluated on three publicly available datasets. The empirical result shows that our method not only achieves high accuracy on encrypted traffic but also has the ability to apply the acquired knowledge on a different dataset. In our experiments, our method outperforms the state-of-the-art baseline methods by ~3% in terms of accuracy even with a much lower volume of labeled data.
Md. Shamim Towhid, Nashid Shahriar
NetSoft1