Makhduma F. Saiyed

dblp:383/6337 · DBLP profile ↗
← Back
7ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0002-9964-9007ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 5 first-author · 6 since 2021
YearPublicationVenuePosition
2026 A Hybrid Explainable AI for DDoS Attacks Detection in Industrial IoT Networks
abstract
The Industrial Internet of Things (IIoT) has transformed industrial processes by allowing real-time data monitoring and automation. While IIoT offers many operational advantages, it is still at risk of cyberattacks like Distributed Denial of Service (DDoS) attacks. This paper introduces a novel Hybrid Explainable AI for DDoS Attack Detection (HEAD) system. The HEAD system combines deep learning, feature attribution, and model optimization within IIoT networks. Unlike earlier systems that rely on tree-based or black-box models without post-training optimization, the HEAD system introduces three main innovations. Firstly, it applies a combined explanation-based feature selection approach using SHAP and LIME to identify both global and local feature importance. The geometric mean of the normalized SHAP and LIME values is used to rank and select the most informative features. Secondly, the HEAD system uses a feedforward deep neural network trained on the selected features to learn important traffic patterns. It maintains high detection accuracy while keeping the model simple and efficient. This replaces traditional ML models with a more compact and flexible architecture. Thirdly, the system applies SHAP GradientExplainer to the trained model to identify neurons in the first hidden layer that are influenced by the input features. These neurons are pruned to create a lightweight version of the model that reduces computation without compromising accuracy. Evaluation on the HL-IoT, ToNIoT, and Edge-IIoTSet datasets shows that the HEAD system attains over 94% accuracy and enhances model efficiency through SHAP-guided pruning. To support real-world deployment the HEAD system provides an interactive interface that shows SHAP visualizations and training results. This helps network administrators monitor predictions and improve detection policies. This design ensures that HEAD is not only accurate but also transparent and suitable for deployment in real IIoT networks.
Makhduma F. Saiyed, Irfan Al-Anbagi
IEEE Internet Things J.1
2026 An Intelligent Intent-Aware System for DDoS Attacks Detection and Mitigation in IoT Networks
abstract
As Internet of Things (IoT) networks continue to grow in complexity and scale, ensuring reliable service delivery while defending against cyber attacks such as Distributed Denial of Service (DDoS) has become increasingly critical. IoT networks, with their resource-constrained devices, diverse traffic patterns, and real-time requirements, amplify the limitations of existing DDoS detection and mitigation solutions. These solutions often prioritize classification accuracy, but rely on static policies that do not adapt to evolving traffic behaviour or prioritize critical services. To address these challenges, Intent-Based Networking (IBN) offers a promising approach by enabling networks to dynamically align with high-level service goals, such as prioritizing control traffic or ensuring low-latency communication. However, current security solutions lack integration with IBN, resulting in a gap in context-driven, intent-aware DDoS mitigation. To address this, the paper proposes an intelligent intent-aware system for DDoS attack detection and mitigation (INACT) in IoT networks. The INACT system introduces a dual-output deep learning model that classifies both the type of traffic (benign or malicious) and its operational intent (e.g., control, security, or bandwidth priority), using a multitask learning approach. The INACT system uses a gradient-based method to select the most relevant features, allowing it to run smoothly on lightweight edge devices. To take immediate and meaningful action, the system includes a controller that applies different mitigation strategies depending on the intent of traffic. This ensures that critical services are protected first and that nonessential traffic is managed with minimal disruption during the attack response. The INACT system is evaluated using benchmark datasets such as HL-IoT and CICIoT-2023 and is deployed on a real testbed. The INACT system achieves high detection and intent classification accuracy while maintaining low latency, resource usage, and mitigation effectiveness.
Makhduma F. Saiyed, Irfan Al-Anbagi, M. Shamim Hossain
IEEE Internet Things J.1
2026 A Domain-Informed Hierarchical Federated Learning Framework for DDoS Detection in WSN for Critical Infrastructure
abstract
The deployment of Wireless Sensor Networks (WSN) in critical infrastructure, such as Small Modular Reactors (SMRs), faces cybersecurity threats like Distributed Denial of Service (DDoS) attacks that can overload these networks and disrupt monitoring and control functions. Current DDoS detection systems often suffer from high false positive rates, neglect domain-specific operational constraints, and rely on centralized architectures that pose privacy risks, making them less suitable for distributed Internet of Things (IoT) environments. To address these issues, we propose a novel Domain-informed Hierarchical Federated Learning (DHFL) framework for WSN used in SMR monitoring and control applications. Our framework features a dual-branch bidirectional Long Short-Term Memory (LSTM) architecture comprising of two parallel processing branches with network-specific constraints, facilitating precise detection of DDoS attacks. It includes differentiable penalty functions to enforce domain-aligned behaviour and employs adaptive trust scoring to evaluate the reliability of individual nodes. These elements operate within a hierarchical Federated Learning (FL) structure organized into three tiers: sensor nodes, local aggregators, and a global coordinator, allowing collaborative training that preserves privacy. Unlike earlier approaches, our method not only maintains privacy by ensuring that raw sensor data never leaves the local nodes and only model updates are shared but also considers the operational importance and trustworthiness of each node through tier-weighted aggregation. Tested on the CICIoT2023 dataset, our system achieved 93.4% accuracy, 94.5% precision, 97.5% recall, 95.5% F1-score, and 98.9% AUC, surpassing state-of-the-art FL methods in both performance and efficiency. Furthermore, it converged in fewer communication rounds (30–50) with reduced communication costs (from 45 MB to 30 MB per round). Our framework can differentiate between normal reactor transients and actual attacks, making it suitable for mission-critical SMR cybersecurity.
Md Facklasur Rahaman, Makhduma F. Saiyed, Irfan Al-Anbagi, Ramakrishna Gokaraju
IEEE Trans. Netw. Serv. Manag.2
2025 A Genetic Algorithm and Game-Theoretic Model for DDoS Defense in IoT Networks
abstract
The rapid expansion of the Internet of Things (IoT) has introduced significant advancements in real-time monitoring and management, but it has also brought new security challenges, particularly from Distributed Denial of Service (DDoS) attacks. These attacks pose a persistent threat to IoT networks, especially impacting resource-constrained edge nodes. This paper presents a novel Genetic Algorithm and Game-based Defense (G2D) model, designed to identify and adaptively apply optimal strategies to defend against DDoS attacks. The G2D model integrates genetic algorithms and game theory to dynamically determine equilibrium strategies, where defense mechanisms such as high- and lowinteraction honeypots and rate limiting are adjusted based on the intensity of incoming attacks to optimize resource allocation. By modeling attacker-defender interactions with bounded rationality, the system continuously refines its strategies over multiple iterations, adapting to evolving attack patterns. Simulation results indicate that the G2D model offers stable and adaptive defenses, achieving higher average payoffs, and a reduced outcome variance. Additionally, the model shows robust adaptability across different attack volumes, making it a reliable solution for enhancing IoT network security.
Makhduma F. Saiyed, Irfan Al-Anbagi
ICC1
2025 A Game Theoretic Model for Strategic Defence Selection Against DDoS Attacks in IoT Networks
abstract
The rapid integration of the Internet of Things (IoT) into various systems, driven by advanced sensor networks, has dramatically improved real-time data monitoring and overall management across multiple industries. However, this integration also exposes IoT networks to various security vulnerabilities, mainly Distributed Denial of Service (DDoS) attacks, which can severely disrupt many services. Therefore, it is necessary to develop robust defence strategies for IoT networks. Traditional security measures often need to consider the strategic aspects of cybersecurity, where quick and precise decision-making is crucial. Given the adversarial nature of the interactions between attackers and defenders, selecting the most effective defence strategy to maximize benefits remains a challenge. To address this issue, this paper introduces the DDoS Defence Strategy Model (DDSM), which strategically uses game theory to select optimal defence mechanisms in IoT networks. The model dynamically adapts defence strategies based on the intensity and characteristics of the attack, optimizing the deployment of high-interaction and low-interaction honeypots and rate-limiting mechanisms. The DDSM model uses a gradient-based approach to achieve Nash equilibrium, adapting to evolving attack patterns to ensure efficient resource utilization and reduce operational overhead. The simulation results confirm the effectiveness of the model in selecting optimal defence strategies and maximizing defensive payoffs. The DDSM game model is designed to find the best combination of defences for IoT networks against high- and low-volume DDoS attacks, ensuring the continued availability of critical services.
Makhduma F. Saiyed, Irfan Al-Anbagi
IEEE Trans. Netw. Serv. Manag.1
2024 A Lightweight and Optimal Defense System for DDoS Attacks in IoMT Networks
abstract
Integrating the Internet of Things (IoT) into the healthcare sector through the Internet of Medical Things (IoMT) has significantly enhanced patient care and the functionality of medical devices. However, this integration has introduced new challenges in cybersecurity, especially in detecting Distributed Denial of Service (DDoS) attacks. While various Machine Learning (ML)-based methods have been proposed to detect DDoS attacks, they face difficulty detecting both high-and low-volume DDoS attacks simultaneously. Additionally, there is a need to identify the optimal defense strategy to safeguard IoMT networks. This paper introduces a Lightweight And Optimal Defense System (LAMDA) for IoMT networks using a novel and efficient feature selection method called Threshold Feature Selection (TFS) with tree-based ML models. The system incorporates a game theory approach to identify the most effective defense strategies, enabling rapid and accurate decision-making during cyberattacks. The performance of the LAMDA system is evaluated using various datasets containing both high-and low-volume DDoS attacks. Results indicate that the LAMDA system, mainly when using the Random Forest model, achieves an accuracy rate of over 93% in detecting such attacks.
Makhduma F. Saiyed, Irfan Al-Anbagi
GLOBECOM1
2023 Entropy and Divergence-based DDoS Attack Detection System in IoT Networks
abstract
High and low-volume Distributed Denial of Service (DDoS) attacks are critical threats to many Internet of Things (IoT) networks. Low-volume attacks gradually overwhelm the device’s resources, whereas high-volume attacks suddenly flood the device’s resources, causing a decline in Quality of Service (QoS). Researchers have proposed various methods to detect DDoS attacks based on statistical and Machine Learning (ML) approaches. Research has also shown that statistical approaches are more efficient for IoT networks as they are simpler to develop and have better real-time performance. However, most existing ML and statistical-based detection methods are effective for either high-volume or low-volume attacks but not for both. This paper proposes a novel Entropy and Divergence-based DDoS Attack Detection (EDDAD) system that uses a statistical approach to simultaneously detect high and low-volume DDoS attacks with high accuracy. The EDDAD system computes entropy and Kullback-Leibler (KL) divergence of flow features in a time window to detect malicious traffic in IoT networks with adaptive thresholds that utilize statistical information. Our analysis of experimental results from a real testbed demonstrated that the EDDAD system is effective and can achieve detection accuracy of greater than 90% for both high and low-volume DDoS attacks.
Makhduma F. Saiyed, Irfan Al-Anbagi
WiMob1