VLDB 2026 Research / reviewers in the wild / expert
Rafidha Rehiman K. A.
dblp:331/7746
· DBLP profile ↗
11ranked-venue papers
0as first author
11since 2021 · last 2025
0009-0004-7330-1178ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 since 2021Computer networks · 3 · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SeCTIS: A framework to Secure CTI SharingabstractThe rise of IT-dependent operations in modern organizations has heightened their vulnerability to cyberattacks. Organizations are inadvertently enlarging their vulnerability to cyber threats by integrating more interconnected devices into their operations, which makes these threats both more sophisticated and more common. Consequently, organizations have been compelled to seek innovative approaches to mitigate the menaces inherent in their infrastructure. In response, considerable research efforts have been directed towards creating effective solutions for sharing Cyber Threat Intelligence (CTI). Current information-sharing methods lack privacy safeguards, leaving organizations vulnerable to proprietary and confidential data leaks. To tackle this problem, we designed a novel framework called SeCTIS (Secure Cyber Threat Intelligence Sharing), integrating Swarm Learning and Blockchain technologies to enable businesses to collaborate, preserving the privacy of their CTI data. Moreover, our approach provides a way to assess the data and model quality and the trustworthiness of all the participants leveraging some validators through Zero Knowledge Proofs. Extensive experimentation has confirmed the accuracy and performance of our framework. Furthermore, our detailed attack model analyzes its resistance to attacks that could impact data and model quality. • Definition of a Swarm Learning approach for collaborative CTI. • Definition of a Blockchain-based solution for privacy preservation in CTI sharing. • Secure CTI validation using a consensus mechanism and Zero-Knowledge Proof. Dincy R. Arikkat, Mert Cihangiroglu, Mauro Conti, Rafidha Rehiman K. A., Serena Nicolazzo, Antonino Nocera, P. Vinod 0001 |
Future Gener. Comput. Syst. | 4 |
| 2025 | SecDefender: Detecting low-quality models in multidomain federated learning systems
K. M. Sameera, Arnaldo Sgueglia, P. Vinod 0001, Rafidha Rehiman K. A., Corrado Aaron Visaggio, Andrea Di Sorbo, Mauro Conti |
Future Gener. Comput. Syst. | 4 |
| 2025 | DroidTTP: Mapping android applications with TTP for Cyber Threat IntelligenceabstractThe widespread use of Android devices for sensitive operations has made them prime targets for sophisticated cyber threats, including Advanced Persistent Threats (APT). Traditional malware detection methods focus primarily on malware classification, often failing to reveal the Tactics, Techniques, and Procedures (TTPs) used by attackers. To address this issue, we propose DroidTTP, a novel system for mapping Android malware to attack behaviors. We curated a dataset linking Android applications to Tactics and Techniques and developed an automated mapping approach using the Problem Transformation Approach and Large Language Models (LLMs). Our pipeline includes dataset construction, feature selection, data augmentation, model training, and explainability via SHAP. Furthermore, we explored the use of LLMs for TTP prediction using both Retrieval Augmented Generation and fine-tuning strategies. The Label Powerset XGBoost model achieved the best performance, with Jaccard Similarity scores of 0.9893 for Tactic classification and 0.9753 for Technique classification. The fine-tuned LLaMa model also performed competitively, achieving 0.9583 for Tactics and 0.9348 for Techniques. Although XGBoost slightly outperformed LLMs, the narrow performance gap highlights the potential of LLM-based approaches for Tactic and Technique prediction. Dincy R. Arikkat, P. Vinod 0001, Rafidha Rehiman K. A., Serena Nicolazzo, Marco Arazzi, Antonino Nocera, Mauro Conti |
J. Inf. Secur. Appl. | 3 |
| 2025 | HExNet: Enhancing malware classification through hierarchical CNNs and multi-level feature attributionabstractThe ever-shifting landscape of malware presents a significant threat, as it routinely circumvents traditional defenses. This paper presents HExNet, a Hierarchical Explainable Convolutional Neural Network (CNN) architecture, designed to improve malware analysis and bolster security defenses. Recognizing the growing sophistication of malware, HExNet leverages a dual image representation, converting assembly mnemonics and raw bytecode of malware into visual representations for in-depth pattern recognition. The architecture, optimized for performance and security relevance, integrates multi-level features to enhance detection accuracy. To increase trust and facilitate security audits, HExNet incorporates SHAPley Additive Explanations (SHAP), Class Activation Maps (CAM), and GIST descriptors, providing transparent insights into the model’s classification process. t-SNE visualizations further demonstrate HExNet’s ability to effectively separate malware families, aiding in security intelligence. Evaluated on the Microsoft Malware Classification Challenge (BIG 2015) dataset, HExNet achieves an overall F1-score of 0.9890, with three malware families reaching a perfect F1-score of 1.0 and the remaining six families achieving near-optimal values. To evaluate the generalization capability, we further tested HExNet on a custom dataset consisting 26,401 samples collected from VirusShare, where the proposed model achieved an F1-score of 0.9724, demonstrating generalization performance across diverse malware datasets. Muhammed Shafi K. P., P. Vinod 0001, Rafidha Rehiman K. A., Alejandro Guerra-Manzanares |
J. Inf. Secur. Appl. | 3 |
| 2025 | WeiDetect: Weibull distribution-based defense against poisoning attacks in federated learning for network intrusion detection systems
K. M. Sameera, P. Vinod 0001, Anderson Rocha 0001, Rafidha Rehiman K. A., Mauro Conti |
J. Inf. Secur. Appl. | 4 |
| 2025 | Android malware defense through a hybrid multi-modal approachabstractThe rapid proliferation of Android apps has given rise to a dark side, where increasingly sophisticated malware poses a formidable challenge for detection. To combat this evolving threat, we present an explainable hybrid multi-modal framework. This framework leverages the power of deep learning , with a novel model fusion technique, to illuminate the hidden characteristics of malicious apps . Our approach combines models (leveraging late fusion approach) trained on attributes derived from static and dynamic analysis, hence utilizing the unique strengths of each model. We thoroughly analyze individual feature categories, feature ensembles, and model fusion using traditional machine learning classifiers and deep neural networks across diverse datasets. Our hybrid fused model outperforms others, achieving an F1-score of 99.97% on CICMaldroid2020. We use SHAP (SHapley Additive exPlanations) and t-SNE (t-distributed Stochastic Neighbor Embedding) to further analyze and interpret the best-performing model. We highlight the efficacy of our architectural design through an ablation study, revealing that our approach consistently achieves over 99% detection accuracy across multiple deep learning models . This paves the way groundwork for substantial advancements in security and risk mitigation within interconnected Android OS environments. K. A. Asmitha, P. Vinod 0001, Rafidha Rehiman K. A., Neeraj Raveendran, Mauro Conti |
J. Netw. Comput. Appl. | 3 |
| 2024 | SoK: Visualization-based Malware Detection TechniquesabstractCyber attackers leverage malware to infiltrate systems, steal sensitive data, and extort victims, posing a significant cybersecurity threat. Security experts address this challenge by employing machine learning and deep learning approaches to detect malware precisely, using static, dynamic, or hybrid methodologies. They visualize malware to identify patterns, behaviors, and common features across different malware families. Various methods and tools are used for malware visualization to represent different aspects of malware behavior, characteristics, and relationships. This article evaluates the effectiveness of visualization techniques in detecting and classifying malware. We methodically categorize studies based on their approach to information retrieval, visualization, feature extraction, classification, and evaluation, allowing for an in-depth review of cutting-edge methods. This analysis identifies key challenges in visualization-based techniques and sheds light on the field’s progress and future possibilities. Our thorough analysis can provide valuable insights to researchers, helping them establish optimal practices for selecting suitable visualizations based on the specific characteristics of the analyzed malware. Matteo Brosolo, P. Vinod 0001, Asmitha KA, Rafidha Rehiman K. A., Mauro Conti |
ARES | 4 |
| 2024 | Relation Extraction Techniques in Cyber Threat Intelligence
Dincy R. Arikkat, P. Vinod 0001, Rafidha Rehiman K. A., Serena Nicolazzo, Antonino Nocera, Mauro Conti |
NLDB (1) | 3 |
| 2024 | LFGurad: A Defense against Label Flipping Attack in Federated Learning for Vehicular Network
K. M. Sameera, P. Vinod 0001, Rafidha Rehiman K. A., Mauro Conti |
Comput. Networks | 3 |
| 2024 | Privacy-preserving in Blockchain-based Federated Learning systems
K. M. Sameera, Serena Nicolazzo, Marco Arazzi, Antonino Nocera, Rafidha Rehiman K. A., P. Vinod 0001, Mauro Conti |
Comput. Commun. | 5 |
| 2024 | OSTIS: A novel Organization-Specific Threat Intelligence System
Dincy R. Arikkat, P. Vinod 0001, Rafidha Rehiman K. A., Serena Nicolazzo, Antonino Nocera, Georgiana Timpau, Mauro Conti |
Comput. Secur. | 3 |