VLDB 2026 Research / reviewers in the wild / expert
Sevil Sen
dblp:84/6540
· DBLP profile ↗
25ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0001-5814-9973ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 8 · 1 first-author · 1 since 2021Computer networks · 6 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A comprehensive analysis of adversarial attacks against spam filters
Esra Hotoglu, Sevil Sen, Burcu Can |
Comput. Secur. | 2 |
| 2026 | Explainable android malware detection and malicious code localization using graph attention
Merve Çigdem Ipek, Sevil Sen |
J. Inf. Secur. Appl. | 2 |
| 2025 | Exploring and Enhancing Placement of IDS in RPL: A Federated Learning-Based ApproachabstractIn routing protocol for low power and lossy networks (RPL) security, intrusion detection (ID) plays a vital role, especially given its susceptibility to attacks, particularly those carried out by insider threats. While numerous studies in the literature have proposed ID systems (IDSs) utilizing diverse techniques, the placement of such systems within RPL topology remains largely unexplored. This study aims to address this gap by rigorously evaluating three ID architectures, considering central and distributed placement, across multiple criteria, including effectiveness, cost, privacy, and security. The findings underscore the significant impact of attacker position and the proximity of IDS to attackers on detection outcomes. Hence, alongside the evaluation of traditional ID architectures, this study explores the use of federated learning (FL) for improving ID within RPL networks. FL’s decentralized model training approach effectively addresses the impact of attacker position on IDS performance by ensuring the collection of relevant information from nodes regardless of their proximity to potential attackers. Moreover, this approach not only mitigates security concerns but also minimizes communication overhead among ID nodes. Consequently, FL reduces the need for extensive data transfer, thus mitigating the impact of packet loss and latency inherent in lossy networks. Additionally, the study investigates the effect of local data sharing on FL performance, clarifying the balance between effectiveness and security. Selim Yilmaz, Sevil Sen, Emre Aydogan |
IEEE Internet Things J. | 2 |
| 2024 | Distributed Intrusion Detection in Dynamic Networks of UAVs Using Few-Shot Federated Learning
Ozlem Ceviz, Sevil Sen, Pinar Sadioglu |
SecureComm (2) | 2 |
| 2023 | Evolving Lightweight Intrusion Detection Systems for RPL-Based Internet of Things
Ali Deveci, Selim Yilmaz, Sevil Sen |
EvoApplications@EvoStar | 3 |
| 2022 | Deep reinforcement learning based flexible preamble allocation for RAN slicing in 5G networks
Ahmet Melih Gedikli, Mehmet Köseoglu 0001, Sevil Sen |
Comput. Networks | 3 |
| 2021 | Load balancing for RPL-based Internet of Things: A review
Doruk Pancaroglu, Sevil Sen |
Ad Hoc Networks | 2 |
| 2021 | A Transfer Learning Approach for Securing Resource-Constrained IoT DevicesabstractIn recent years, Internet of Things (IoT) security has attracted significant interest by researchers due to new characteristics of IoT such as heterogeneity of devices, resource constraints, and new types of attacks targeting IoT. Intrusion detection, which is an indispensable part of a security system, is also included in these studies. In order to explore the complex characteristics of IoT, machine learning methods, which rely on long training time to generate intrusion detection models, are proposed in the literature. Furthermore, these systems need to learn a new/fresh model from scratch when the environment changes. This study explores the use of transfer learning in order to generate intrusion detection algorithms for such dynamically changing IoT. Transfer learning is an approach that stores knowledge learned from a problem domain/task and applies that knowledge to another problem domain/task. Here, it is employed in the following two settings: transferring knowledge for generating suitable intrusion algorithms for new devices, transferring knowledge for detecting new types of attacks. In this study, Routing Protocol for Low-Power and Lossy Network (RPL), a routing protocol for resource-constrained wireless networks, is used as an exemplar protocol and specific attacks against RPL are targeted. The experimental results show that the transfer learning approach gives better performance than the traditional approach. Moreover, the proposed approach significantly reduces learning time, which is an important factor for putting devices/networks in operation in a timely manner. Even though transfer learning has been considered a potential candidate for improving IoT security, to the best of our knowledge, this is the first application of transfer learning under these two settings in RPL-based IoT networks. Selim Yilmaz, Emre Aydogan, Sevil Sen |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Electric fish optimization: a new heuristic algorithm inspired by electrolocation
Selim Yilmaz, Sevil Sen |
Neural Comput. Appl. | 2 |
| 2019 | Evolving Trust Formula to Evaluate Data Trustworthiness in VANETs Using Genetic Programming
Mehmet Aslan, Sevil Sen |
EvoApplications | 2 |
| 2019 | Early Detection of Botnet Activities Using Grammatical Evolution
Selim Yilmaz, Sevil Sen |
EvoApplications | 2 |
| 2019 | Efficient Evolutionary Fuzzing for Android Application Installation ProcessabstractSource code analysis techniques used for automated software testing are insufficient to find security flaws in programs. Therefore, security researchers have been employing also fuzzing techniques for finding bugs and vulnerabilities in target programs. With the proliferation of mobile devices, researchers have started to explore the use of fuzz tests on mobile platforms. While most of these studies are GUI-based and implemented at the application level, the detection of vulnerabilities in lower levels is very critical due to affecting a broader range of Android users. Therefore, in this study, a new approach is proposed to fuzz testing for Android application installation process. The use of a search heuristic namely genetic algorithms is investigated for efficient fuzz testing on DEX (Dalvik EXecutable) files. The proposed black box fuzzing tool called GFuzz is shown to be able to produce more unique crashes in Android in a shorter time than recently proposed similar approaches and to detect new and existing bugs. Veysel Hatas, Sevil Sen, John A. Clark |
QRS | 2 |
| 2019 | A novel multi-featured metric for adaptive routing in mobile ad hoc networks
Songul Hasdemir, Selim Yilmaz, Sevil Sen |
Appl. Intell. | 3 |
| 2019 | Analysis of dynamic code updating in Android with security perspectiveabstractAttackers have been searching for security vulnerabilities to exploit in Android applications. Such security vulnerabilities include Android applications that could load code at runtime which helps attackers avoid detection by static analysis tools. In this study, an extensive analysis is conducted in order to see how attackers employ updating techniques to exploit such vulnerabilities and to assess the security risks of applications in the marketplace using these techniques. A comprehensive analysis was carried out on nearly 30,000 applications collected from three different Android markets and two malware datasets. Static, dynamic and permission‐based analyses were employed in order to monitor malicious activities in such applications, and new malicious applications using updating techniques were discovered in Google Play. The results show that applications employing code updating techniques are on the rise. It is believed that this is the first study of its kind to monitor updating behaviours of applications during their execution. This analysis allows us to deeply analyse suspicious applications and thereby develop better security solutions. Ahmet Ilhan Aysan, Fatih Sakiz, Sevil Sen |
IET Inf. Secur. | 3 |
| 2018 | Coevolution of Mobile Malware and Anti-MalwareabstractMobile malware is one of today's greatest threats in computer security. Furthermore, new mobile malware is emerging daily that introduces new security risks. However, while existing security solutions generally protect mobile devices against known risks, they are vulnerable to as yet unknown risks. How anti-malware software reacts to new, unknown malicious software is generally difficult to predict. Therefore, anti-malware software is in continuous development in order to be able to detect new malware or new variants of existing malware. Similarly, as long as anti-malware software develops, malware writers also develop their malicious code by using various evasion strategies, such as obfuscation and encryption. This is the lifecycle of malicious and anti-malware software. In this paper, the use of evolutionary computation techniques are investigated, both for developing new variants of mobile malware which successfully evades anti-malware systems based on static analysis and for developing better security solutions against them automatically. A coevolutionary arms race mechanism has always been considered a potential candidate for developing a more robust system against new attacks and for system testing. To the best of the authors' knowledge, this paper is the first application of coevolutionary computation to address this problem. Sevil Sen, Emre Aydogan, Ahmet Ilhan Aysan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2017 | A survey of attacks and detection mechanisms on intelligent transportation systems: VANETs and IoV
Fatih Sakiz, Sevil Sen |
Ad Hoc Networks | 2 |
| 2015 | "Do You Want to Install an Update of This Application?" A Rigorous Analysis of Updated Android ApplicationsabstractAttackers have been searching for security vulnerabilities in Android applications to exploit. One of these security vulnerabilities is that Android applications could load codes at runtime. This helps attackers to avoid being detected by static analysis tools. In this study, we have done a rigorous analysis to see how attackers employ updating techniques in order to exploit this vulnerability, and to assess the security risks of applications using these techniques in the markets. A comprehensive analysis is carried out on nearly 30,000 applications collected from three different Android markets and two malware datasets. Both static and dynamic analysis techniques are employed to monitor malicious activities in such applications. As a result, we found 70 new malicious applications from Google Play. Our work is the first study which monitors updating behaviours of applications during their execution. This analysis allows us to analyse suspicious applications deeply and to develop better security solutions. Ahmet Ilhan Aysan, Sevil Sen |
CSCloud | 2 |
| 2015 | Automatic Generation of Mobile Malwares Using Genetic Programming
Emre Aydogan, Sevil Sen |
EvoApplications | 2 |
| 2015 | Internet of Things security and privacy: Design methods and optimization
Yacine Challal, Enrico Natalizio, Sevil Sen, Anna Maria Vegni |
Ad Hoc Networks | 3 |
| 2015 | Sequence-based masquerade detection for different user groupsabstractABSTRACT Insider threats are one of the biggest threats that organizations are confronted with today. A masquerader who impersonates another user for his malicious activities has been studied extensively in the literature. The approaches proposed on masquerade detection mainly assume that masquerader behavior will deviate from the typical behavior of the victim. This research presents a rigorous evaluation of sequence‐based approaches based on this assumption. The main idea underlying sequence‐based approaches is that users type similar commands, in a similar order, every time to do a specific job and, these similarities could distinguish users from others. Sequence‐based approaches in the literature only consider commands typed in a specific order, at all times. In this research, we also take into account typing similar commands in a command sequence, but in an unordered way, in the newly proposed method, Matching of Unordered Command Sequences. We compare this new technique with another sequence‐based approach called Matching of Ordered Command Sequences, and a command‐based approach called Matching of Commands. These techniques are evaluated with varying parameters in order to explore how the order of commands, the variations in a command sequence, and the variety of commands affect masquerade detection. Furthermore, the performance of these methods on different types of users and masqueraders is analyzed. We explore what kind of users are easily distinguishable from others, and what kind of masqueraders are difficult to detect. Copyright © 2014 John Wiley & Sons, Ltd. Sevil Sen |
Secur. Commun. Networks | 1 |
| 2014 | Evolving a Trust Model for Peer-to-Peer Networks Using Genetic Programming
Ugur Eray Tahta, Ahmet Burak Can, Sevil Sen |
EvoApplications | 3 |
| 2014 | Exposure: A Passive DNS Analysis Service to Detect and Report Malicious DomainsabstractA wide range of malicious activities rely on the domain name service (DNS) to manage their large, distributed networks of infected machines. As a consequence, the monitoring and analysis of DNS queries has recently been proposed as one of the most promising techniques to detect and blacklist domains involved in malicious activities (e.g., phishing, spam, botnets command-and-control, etc.). EXPOSURE is a system we designed to detect such domains in real time, by applying 15 unique features grouped in four categories. We conducted a controlled experiment with a large, real-world dataset consisting of billions of DNS requests. The extremely positive results obtained in the tests convinced us to implement our techniques and deploy it as a free, online service. In this article, we present the Exposure system and describe the results and lessons learned from 17 months of its operation. Over this amount of time, the service detected over 100K malicious domains. The statistics about the time of usage, number of queries, and target IP addresses of each domain are also published on a daily basis on the service Web page. Leyla Bilge, Sevil Sen, Davide Balzarotti, Engin Kirda, Christopher Krügel |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2011 | Evolutionary computation techniques for intrusion detection in mobile ad hoc networks
Sevil Sen, John A. Clark |
Comput. Networks | 1 |
| 2009 | A grammatical evolution approach to intrusion detection on mobile ad hoc networksabstractIn recent years mobile ad hoc networks (MANETs) have become a very popular research topic. By providing communication in the absence of a fixed infrastructure they are very attractive for many applications such as tactical and disaster recovery operations and virtual conferences. On the other hand, this flexibility introduces new security risks. Moreover, different characteristics of MANETs make conventional security systems ineffective and inefficient for this new environment. Intrusion detection, which is an indispensable part of a security system, presents also a particular challenge due to the dynamic nature of MANETs, the lack of central points, and their highly constrained nodes. In this paper, we propose to investigate the use of an artificial intelligence based learning technique to explore this difficult design space. The grammatical evolution technique inspired by natural evolution is explored to detect known attacks on MANETs such as DoS attacks and route disruption attacks. Intrusion detection programs are evolved for each attack and distributed to each node on the network. The performance of these programs is evaluated on different types of networks with different mobility and traffic patterns to show their effects on intrusion detection ability. Sevil Sen, John A. Clark |
WISEC | 1 |
| 2008 | Evolving Intrusion Detection Rules on Mobile Ad Hoc Networks
Sevil Sen, John A. Clark |
PRICAI | 1 |