VLDB 2026 Research / reviewers in the wild / expert
Tariqul Islam 0001
dblp:72/10428-1 · also Md Tariqul Islam 0001
· DBLP profile ↗
22ranked-venue papers
3as first author
20since 2021 · last 2026
0000-0002-5572-8504ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 2 first-author · 7 since 2021Security and privacy · 7 · 7 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DECPA-FL: Dynamic Ensemble Clustering for Poison-Aware Federated Learning under Adversarial ConditionsabstractDetecting and mitigating poisoning attacks in Federated Learning (FL) poses a significant challenge, as malicious clients can severely impair model performance through adversarial updates. In this work, we present Dynamic Ensemble Clustering for Poison-Aware Federated Learning (DECPA-FL), a novel defense framework that operates at both the client and sample levels. Our approach leverages three dynamic model clusters—normal, poison, and hybrid—each designed to address varying data properties. Unlike conventional FL methods that treat all client input identically, DECPA-FL utilizes an adaptive Isolation Forest mechanism that progresses via federated rounds to identify poisoned samples with enhanced accuracy. The system’s Poisoning-Aware Loss Function provides reduced weights to potentially contaminated data, while its adaptive learning rate mechanism adjusts training parameters based on identified poison ratios. We evaluate DECPA-FL on the CICIDS 2017 network intrusion dataset and achieve an F1-score of 96.06%, outperforming centralized baselines by 8.25% and traditional FL by 18.83%. Our method maintains robust performance even under 15% poisoning rates, where existing approaches suffer substantial degradation. Through DECPA-FL, we offer an effective and resilient defense for secure federated learning in adversarial and privacy-critical domains. Ahad Bin Islam Shoeb, Kamrul Hasan 0008, Tariqul Islam 0001, Imtiaz Ahmed 0001, Zoheb Hasan, Sumit Chakravarty |
CCNC | 4 |
| 2026 | SoK: The Next Frontier in AV Security: Systematizing Perception Attacks and the Emerging Threat of Multi-Sensor Fusion
Shahriar Rahman Khan, Tariqul Islam 0001, Raiful Hasan |
EuroS&P | 2 |
| 2026 | SWORD: A Secure LoW-Latency Offline-First Authentication and Data Sharing Scheme for Resource Constrained Distributed Networks
Faisal Haque Bappy, Tahrim Hossain, Raiful Hasan, Kamrul Hasan 0008, Tariqul Islam 0001 |
ICC | 6 |
| 2026 | From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness
Faisal Haque Bappy, Tahrim Hossain, Sidratul Muntaher Meheraj, Annoor Sharara Akhand, Tasfia Tabassum, Tarannum S. Zaman, Raiful Hasan, Tariqul Islam 0001 |
SOUPS | 8 |
| 2025 | ChainGuard: A Blockchain-Based Authentication and Access Control Scheme for Distributed NetworksabstractAs blockchain technology gains traction for enhancing data security and operational efficiency, traditional centralized authentication systems remain a significant bottleneck. This paper addresses the challenge of integrating decentralized authentication and access control within distributed networks. We propose a novel solution named ChainGuard, a fully decentralized authentication and access control mechanism based on smart contracts. ChainGuard eliminates the need for a central server by leveraging blockchain technology to manage user roles and permissions dynamically. Our scheme supports user interactions across multiple organizations simultaneously, enhancing security, efficiency, and transparency. By addressing key challenges such as scalability, security, and transparency, ChainGuard not only bridges the gap between traditional centralized systems and blockchain's decentralized ethos but also enhances data protection and operational efficiency. Faisal Haque Bappy, Joon S. Park, Kamrul Hasan 0008, Tariqul Islam 0001 |
CCNC | 4 |
| 2025 | SEAM: A Secure Automated and Maintainable Smart Contract Upgrade FrameworkabstractThis work addresses the critical challenges of upgrading smart contracts, which are vital for trust in automated transactions but difficult to modify once deployed. To address this issue, we propose SEAM, a novel framework that automates the conversion of standard Solidity contracts into upgradable versions using the diamond pattern. SEAM simplifies the upgrade process and addresses two key vulnerabilities: function selector clashes and storage slot collisions. Additionally, the framework provides tools for efficiently deploying, modifying, and managing smart contract lifecycles. By enhancing contract security and reducing the learning curve for developers, SEAM lays a robust foundation for more flexible and maintainable blockchain applications. Tahrim Hossain, Faisal Haque Bappy, Tarannum S. Zaman, Tariqul Islam 0001 |
CCNC | 4 |
| 2025 | CrossLink: A Decentralized Framework for Secure Cross-Chain Smart Contract ExecutionabstractThis paper introduces CrossLink, a decentralized framework for secure cross-chain smart contract execution that effectively addresses the inherent limitations of contemporary solutions, which primarily focus on asset transfers and rely on potentially vulnerable centralized intermediaries. Recognizing the escalating demand for seamless interoperability among decentralized applications, CrossLink provides a trustless mechanism for smart contracts across disparate blockchain networks to communicate and interact. At its core, CrossLink utilizes a compact chain for selectively storing authorized contract states and employs a secure inter-chain messaging mechanism to ensure atomic execution and data consistency. By implementing a deposit/collateral fee system and efficient state synchronization, CrossLink enhances security and mitigates vulnerabilities, offering a novel approach to seamless, secure, and decentralized cross-chain interoperability. A formal security analysis further validates CrossLink’s robustness against unauthorized modifications and denial-of-service attacks. Tahrim Hossain, Faisal Haque Bappy, Tarannum S. Zaman, Tariqul Islam 0001 |
ICBC | 4 |
| 2025 | Bridging Immutability with Flexibility: A Scheme for Secure and Efficient Smart Contract UpgradesabstractThe emergence of blockchain technology has revolutionized contract execution through the introduction of smart contracts. Ethereum, the leading blockchain platform, leverages smart contracts to power decentralized applications (DApps), enabling transparent and self-executing systems across various domains. While the immutability of smart contracts enhances security and trust, it also poses significant challenges for updates, defect resolution, and adaptation to changing requirements. Existing upgrade mechanisms are complex, resource-intensive, and costly in terms of gas consumption, often compromising security and limiting practical adoption. To address these challenges, we propose FlexiContracts+, a novel scheme for secure, in-place smart contract upgrades on Ethereum that preserves historical data without relying on multiple contracts or extensive pre-deployment planning. FlexiContracts+ enhances security, simplifies development, reduces engineering overhead, and supports adaptable, expandable smart contracts. Comprehensive testing demonstrates that FlexiContracts+ achieves a practical balance between immutability and flexibility, advancing the capabilities of smart contract systems. Tahrim Hossain, Sakib Hassan, Faisal Haque Bappy, Muhammad Nur Yanhaona, Tarannum S. Zaman, Tariqul Islam 0001 |
ICBC | 6 |
| 2025 | Spoofing Camera Source Attribution via PRNU Transfer Attacks on Physical and AI Generated Images
Shahriar Rahman Khan, Tariqul Islam 0001, Raiful Hasan |
ISC | 2 |
| 2025 | Characterizing Event-themed Malicious Web Campaigns: A Case Study on War-themed WebsitesabstractCybercrimes such as online scams and fraud have become prevalent. Cybercriminals often abuse various global or regional events as themes of their fraudulent activities to breach user trust and attain a higher attack success rate. These attacks attempt to manipulate and deceive innocent people into interacting with meticulously crafted websites with malicious payloads, phishing, or fraudulent transactions. To deepen our understanding of the problem, this paper investigates how to characterize event-themed malicious website-based campaigns, with a case study on war-themed websites. We find that attackers tailor their attacks by exploiting the unique aspects of events, as evidenced by activities such as fundraising, providing aid, collecting essential supplies, or seeking updated news. We use explainable unsupervised clustering methods to draw further insights, which could guide the design of effective early defenses against various event-themed malicious web campaigns. Maraz Mia, Mir Mehedi Ahsan Pritom, Tariqul Islam 0001, Shouhuai Xu |
PST | 3 |
| 2024 | FASTEN: Towards a FAult-Tolerant and STorage EfficieNt Cloud: Balancing Between Replication and DeduplicationabstractWith the surge in cloud storage adoption, enterprises face challenges managing data duplication and exponential data growth. Deduplication mitigates redundancy, yet maintaining redundancy ensures high availability, incurring storage costs. Balancing these aspects is a significant research concern. We propose FASTEN, a distributed cloud storage scheme ensuring efficiency, security, and high availability. FASTEN achieves fault tolerance by dispersing data subsets optimally across servers and maintains redundancy for high availability. Experimental results show FASTEN's effectiveness in fault tolerance, cost reduction, batch auditing, and file and block-level deduplication. It outperforms existing systems with low time complexity, strong fault tolerance, and commendable deduplication performance. Md. Nahiduzzaman, Tariqul Islam 0001, Faisal Haque Bappy, Tarannum S. Zaman, Raiful Hasan |
CCNC | 3 |
| 2024 | ConChain: A Scheme for Contention-Free and Attack Resilient BlockChainabstractAlthough blockchains have become widely popular for their use in cryptocurrencies, they are now becoming pervasive as more traditional applications adopt blockchain to ensure data security. Despite being a secured network, blockchains have some tradeoffs such as high latency, low throughput, and transaction failures. One of the core problems behind these is improper management of “conflicting transactions”, which is also known as “contention”. When there is a large pool of pending transactions in a blockchain and some of them are conflicting, a situation of contention occurs, and as a result, the latency of the network increases, and a substantial amount of resources are wasted which results in low throughput and transaction failures. In this paper, we proposed ConChain, a novel blockchain scheme that combines transaction parallelism and an intelligent dependency manager to minimize conflicting transactions in blockchain networks as well as improve performance. ConChain is also capable of ensuring proper defense against major attacks due to contention. Faisal Haque Bappy, Tariqul Islam 0001, Tarannum S. Zaman, Md Sajidul Islam Sajid, Mir Mehedi Ahsan Pritom |
CCNC | 2 |
| 2024 | Towards an Interpretable AI Framework for Advanced Classification of Unmanned Aerial Vehicles (UAVs)abstractWith UAVs on the rise, accurate detection and identification are crucial. Traditional unmanned aerial vehicle (UAV) identification systems involve opaque decision-making, restricting their usability. This research introduces an RF-based Deep Learning (DL) framework for drone recognition and identification. We use cutting-edge eXplainable Artificial Intelligence (XAI) tools, SHapley Additive Explanations (SHAP), and Local Interpretable Model-agnostic Explanations(LIME). Our deep learning model uses these methods for accurate, transparent, and interpretable airspace security. With 84.59% accuracy, our deep-learning algorithms detect drone signals from RF noise. Most crucially, SHAP and LIME improve UAV detection. Detailed explanations show the model's identification decision-making process. This transparency and interpretability set our system apart. The accurate, transparent, and user-trustworthy model improves airspace security. Ekramul Haque, Kamrul Hasan 0008, Imtiaz Ahmed 0001, Md. Sahabul Alam, Tariqul Islam 0001 |
CCNC | 5 |
| 2024 | Advancing Healthcare: Innovative ML Approaches for Improved Medical Imaging in Data-Constrained EnvironmentsabstractHealthcare industries face challenges when experiencing rare diseases due to limited samples. Artificial Intelligence (AI) communities overcome this situation to create synthetic data which is an ethical and privacy issue in the medical domain. This research introduces the CAT-U-Net framework as a new approach to overcome these limitations, which enhances feature extraction from medical images without the need for large datasets. The proposed framework adds an extra concatenation layer with downsampling parts, thereby improving its ability to learn from limited data while maintaining patient privacy. To validate, the proposed framework’s robustness, different medical conditioning datasets were utilized including COVID-19, brain tumors, and wrist fractures. The framework achieved nearly 98% reconstruction accuracy, with a Dice coefficient close to 0.946. The proposed CAT-U-Net has the potential to make a big difference in medical image diagnostics in settings with limited data. Al Amin, Kamrul Hasan 0008, Saleh Zein-Sabatto, Sachin Shetty, Imtiaz Ahmed 0001, Tariqul Islam 0001 |
GLOBECOM | 7 |
| 2024 | Impact of Conflicting Transactions in Blockchain: Detecting and Mitigating Potential AttacksabstractConflicting transactions within blockchain networks not only pose performance challenges but also introduce security vulnerabilities, potentially facilitating malicious attacks. In this paper, we explore the impact of conflicting transactions on blockchain attack vectors. Through modeling and simulation, we delve into the dynamics of four pivotal attacks - block withholding, double spending, balance, and distributed denial of service (DDoS), all orchestrated using conflicting transactions. Our analysis not only focuses on the mechanisms through which these attacks exploit transaction conflicts but also underscores their potential impact on the integrity and reliability of blockchain networks. Additionally, we propose a set of countermeasures for mitigating these attacks. Through implementation and evaluation, we show their effectiveness in lowering attack rates and enhancing overall network performance seamlessly, without introducing additional overhead. Our findings emphasize the critical importance of actively managing conflicting transactions to reinforce blockchain security and performance. Faisal Haque Bappy, Tariqul Islam 0001, Kamrul Hasan 0008, Joon S. Park, Carlos E. Caicedo Bastidas |
GLOBECOM | 2 |
| 2024 | Securing Proof of Stake Blockchains: Leveraging Multi-Agent Reinforcement Learning for Detecting and Mitigating alicious NodesabstractProof of Stake (PoS) blockchains offer promising alternatives to traditional Proof of Work (PoW) systems, providing scalability and energy efficiency. However, blockchains operate in a decentralized manner and the network is composed of diverse users. This openness creates the potential for malicious nodes to disrupt the network in various ways. Therefore, it is crucial to embed a mechanism within the blockchain network to constantly monitor, identify, and eliminate these malicious nodes without involving any central authority. In this paper, we propose MRL-PoS+, a novel consensus algorithm to enhance the security of PoS blockchains by leveraging Multi-agent Reinforcement Learning (MRL) techniques. Our proposed consensus algorithm introduces a penalty-reward scheme for detecting and eliminating malicious nodes. This approach involves the detection of behaviors that can lead to potential attacks in a blockchain network and hence penalizes the malicious nodes, restricting them from performing certain actions. Our developed Proof of Concept demonstrates effectiveness in eliminating malicious nodes for six types of major attacks. Experimental results demonstrate that MRL-PoS+ significantly improves the attack resilience of PoS blockchains compared to the traditional schemes without incurring additional computation overhead. Faisal Haque Bappy, Tariqul Islam 0001, Kamrul Hasan 0008, Md Sajidul Islam Sajid, Mir Mehedi Ahsan Pritom |
GLOBECOM | 2 |
| 2024 | An Efficient and Scalable Auditing Scheme for Cloud Data Storage Using an Enhanced B-TreeabstractAn efficient, scalable, and provably secure dynamic auditing scheme is highly desirable in the cloud storage environment for verifying the integrity of the outsourced data. Most of the existing work on remote integrity checking focuses on static archival data and therefore cannot be applied to cases where dynamic data updates are more common. Additionally, existing auditing schemes suffer from performance bottlenecks and scalability issues. To address these issues, in this paper, we present a novel dynamic auditing scheme for centralized cloud environments leveraging an enhanced version of the B-tree. Our proposed scheme achieves the immutable characteristic of a decentralized system (i.e., blockchain technology) while effectively addressing the synchronization and performance challenges of such systems. Unlike other static auditing schemes, our scheme supports dynamic insert, update, and delete operations. Also, by leveraging an enhanced B-tree, our scheme maintains a balanced tree after any alteration to a certain file, improving performance significantly. Experimental results show that our scheme outperforms both traditional Merkle Hash Tree-based centralized auditing and decentralized blockchain-based auditing schemes in terms of block modifications (e.g., insert, delete, update), block retrieval, and data verification time. Tariqul Islam 0001, Faisal Haque Bappy, Md Nafis Ul Haque Shifat, Kamrul Hasan 0008, Tarannum S. Zaman |
ICC | 1 |
| 2024 | FlexiContracts: A Novel and Efficient Scheme for Upgrading Smart Contracts in Ethereum BlockchainabstractBlockchain technology has revolutionized contractual processes, enhancing efficiency and trust through smart contracts. Ethereum, as a pioneer in this domain, offers a platform for decentralized applications but is challenged by the immutability of smart contracts, which makes upgrades cumbersome. Existing design patterns, while addressing upgrad-ability, introduce complexity, increased development effort, and higher gas costs, thus limiting their effectiveness. In response, we introduce FlexiContracts, an innovative scheme that reimagines the evolution of smart contracts on Ethereum. By enabling secure, in-place upgrades without losing historical data, Flexi-Contracts surpasses existing approaches, introducing a previously unexplored path in smart contract evolution. Its streamlined design transcends the limitations of current design patterns by simplifying smart contract development, eliminating the need for extensive upfront planning, and significantly reducing the complexity of the design process. This advancement fosters an environment for continuous improvement and adaptation to new requirements, redefining the possibilities for dynamic, upgradable smart contracts. Tahrim Hossain, Sakib Hassan, Faisal Haque Bappy, Muhammad Nur Yanhaona, Sarker T. A. Rumee, Moinul Islam Zaber, Tariqul Islam 0001 |
TrustCom | 7 |
| 2023 | Towards Immutability: A Secure and Efficient Auditing Framework for Cloud Supporting Data Integrity and File Version ControlabstractAlthough wide-scale integration of cloud services with myriad applications increases quality of services (QoS) for enterprise users, verifying the existence and manipulation of stored cloud information remains an open research problem. Decentralized blockchain-based solutions are becoming more appealing for cloud auditing environments because of the immutable nature of blockchain. However, the decentralized structure of blockchain results in considerable synchronization and communication overhead, which increases maintenance costs for cloud service providers (CSP). This paper proposes a Merkle Hash Tree based architecture named Entangled Merkle Forest to support version control and dynamic auditing of information in centralized cloud environments. We utilized a semi-trusted third-party auditor to conduct the auditing tasks with minimal privacy-preserving file-metadata. To the best of our knowledge, we are the first to design a node sharing Merkle Forest to offer a cost-effective auditing framework for centralized cloud infrastructures while achieving the immutable feature of blockchain, mitigating the synchronization and performance challenges of the decentralized architectures. Our proposed scheme outperforms it's equivalent Blockchain-based schemes by ensuring time and storage efficiency with minimum overhead as evidenced by performance analysis. Faisal Haque Bappy, Saklain Zaman, Tariqul Islam 0001, Redwan Ahmed Rizvee, Joon S. Park, Kamrul Hasan 0008 |
GLOBECOM | 3 |
| 2022 | Predictive Cyber Defense Remediation against Advanced Persistent Threat in Cyber-Physical SystemsabstractAdvanced Persistent Threat (APT) has dramatically changed the landscape of cybersecurity. APT is carried out by stealthy, continuous, sophisticated, and well-funded attack processes for long-term malicious gain thwarting most current defense mechanisms. There is a need for a defense strategy that continuously combats APT over a long time-span in imper-fect/incomplete information on attacker's actions. We propose the stochastic evolutionary game model to simulate the dynamic adversary to address this need in this work. We add the player's rationality parameter c to the Logit Quantal Response Dynamics (LQ RD) model to quantify the cognitive differences of real-world players. We propose an optimal decision-making plan by calculating the stable evolutionary equilibrium that balances a trade-off between defense cost and benefit. Cases studies conducted on Energy Delivery Systems (EDS) indicate that the proposed method can help the defender predict possible attack action, select the related optimal cyber defense remediation over time, and gain the maximum defense payoff. Kamrul Hasan 0008, Sachin Shetty, Tariqul Islam 0001, Imtiaz Ahmed 0001 |
ICCCN | 3 |
| 2020 | Blending Convergent Encryption and Access Control Scheme for Achieving A Secure and Storage Efficient CloudabstractConventional encryption schemes are being used over the years for securing outsourced data to cloud. However, this impedes deduplication- the ability to identify and remove duplicate data from storage server. The idea of Convergent Encryption was introduced to overcome this problem which ensures that identical plaintext files will always produce identical ciphertexts and thus enabling deduplication. Nonetheless, this scheme is vulnerable to a side-channel attack called “confirmation-of-a-file” and its variant “learn-the-remaining-information” attack which breach user privacy by observing the deduplication operation. To resolve the above two seemingly contrasting issues, we propose a scheme which blends convergent encryption with a traditional access control scheme for simultaneously achieving confidentiality and deduplication. Both theoretical security analysis and experimental results show that our scheme is semantically secure and resilient against attacks. It incurs minor storage and latency overhead while performing file and block level deduplication. Furthermore, it ensures secure and fine-grained access control of outsourced data by efficiently handling key-management process. Tariqul Islam 0001, Kiho Lim, D. Manivannan 0001 |
CCNC | 1 |
| 2019 | SecReS: A Secure and Reliable Storage Scheme for Cloud with Client-Side Data DeduplicationabstractIn this paper, we propose a cloud storage scheme which simultaneously achieves security, reliability, and deduplication. Our scheme blends convergent encryption and perfect secret sharing method to achieve confidentiality of data and encryption keys. It also achieves fault tolerance by dispersing data to multiple storage servers using Reed-Solomon erasure code. We use Merkle hash tree to authenticate users by verifying Proof of Ownership (PoW) of data for carrying out secure deduplication. Both theoretical security analysis and experimental evaluation demonstrate that our scheme is provably secure and incurs only a small overhead compared to the existing systems. Tariqul Islam 0001, Hassan Mistareehi, D. Manivannan 0001 |
GLOBECOM | 1 |