VLDB 2026 Research / reviewers in the wild / expert
Ahmed Aleroud
dblp:85/9730 · also Ahmed AlEroud, Ahmed F. Al-Eroud
· DBLP profile ↗
27ranked-venue papers
8as first author
17since 2021 · last 2026
0000-0003-4337-1488ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 6 since 2021Computer networks · 5 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adaptive Randomized Smoothing with Certified Robustness for Mitigating Tabular Adversarial Attacks
Nour Alhussien, Bradley Boswell, Gagan Agrawal, Ahmed Aleroud, Gokila Dorai |
ACNS (3) | 4 |
| 2026 | Clustered Federated Learning for Healthcare Analytics: A Dual Blockchain-Functional Encryption Method for Fortified AggregationabstractThe use of healthcare data for collaborative machine learning training amplifies the demand for strong privacy and security protection. Federated learning (FL) addresses this by sharing model gradients instead of raw patient data. However, FL faces critical challenges, including vulnerability to adversarial attacks (e.g., membership inference, model poisoning), reliance on centralized aggregation (introducing single points of failure), and privacy leakage risks from gradient exchanges. To overcome these limitations, we propose C2SecFL, a cross-clustered secure FL framework that combines adaptive, model-aware clustering with an inner-product functional-encryption (IPFE) scheme enabling encrypted aggregation without a key distribution center (KDC). A lightweight permissioned blockchain provides tamper-evident coordination and auditability across clusters without introducing a centralized trust anchor. Experiments on diverse models show substantially lower cryptographic overhead compared to homomorphic-encryption baselines. Encryption is approximately 3.6× faster, and aggregation is up to 2.2× faster, while predictive utility is preserved. Under adversarial settings with compromised participants, C2SecFL reduces the average attack success rate by about 80% relative to a FedAvg baseline. It mitigates membership-inference risk by encrypting updates end-to-end and revealing only aggregate inner products. Our extensive experiments on a heart attack dataset demonstrate that C2SecFL provides a practical, auditable, and resilient approach to secure healthcare FL. Abdullah Melhem, Ahmed Aleroud, Abdullah Al-Mamun 0001, Mohamed I. Ibrahem |
IEEE Internet Things J. | 2 |
| 2025 | Augmented Tabular Adversarial Evasion Attacks with Constraint Satisfaction Guarantees
Nour Alhussien, Gagan Agrawal, Ahmed Aleroud |
ARES (2) | 3 |
| 2025 | GraphRAG-Based NLP at Risk: Graphemic Dot-Level Adversarial Attack on Arabic Sentiment and LLM Retrieval-Augmented Models
Abdullah Melhem, Ahmed Aleroud, Craig Albert |
ASONAM (1) | 2 |
| 2025 | Reinventing CI/CD for Collaborative Sciences: A Blockchain-Integrated Decentralized Middleware for Scalable and Fault-Tolerant WorkflowsabstractThe expansion in the scale of collaborative scientific efforts has brought about numerous challenges in continuous integration/deployment (CI/CD). Current CI/CD tools solely depend on centralized data management, resulting in reliability and scalability concerns. To address the issue, this paper advocates for and demonstrates a decentralized approach that leverages lightweight data management techniques and distributed computing principles. Our middleware solution, DeQL, transforms the current CI/CD workflows, and uses decentralized logic for automated code analysis before GitHub commits. The involvement of distributed participants (i.e., GitHub contributors), together as a part of the decentralized network, ensures code integrity, security and reliable integration processes. For ensuring low overheads and scalability, this paper introduces lightweight consensus protocols designed for efficient smart contract execution, significantly reducing overhead compared to traditional decentralized data management solutions. We incorporate a fine-grained CI/CD commit dependency graph that effectively manages CI/CD commit complexity, facilitating faster (and more reliable) processing. Experimental results show that the proposed decentralized protocol outperforms the traditional centralized CI/CD system and state-of-the-art blockchain protocols, achieving up to 80% faster response times and handling 7× more commits in a given amount of time. Amena Begum Farha, Abdullah Al-Mamun 0001, Gagan Agrawal, Ahmed Aleroud |
eScience | 4 |
| 2025 | Powerful & Generalizable, Why not both? VA: Various Attacks Framework for Robust Adversarial Training
Samer Khamaiseh, Deirdre Jost, Abdullah S. Al-Alaj, Ahmed Aleroud |
ICAART (2) | 4 |
| 2025 | ZTP: A Scalable and Lightweight Privacy-Preserving Blockchain via Scale-Free Quorums and Geometric FragmentationabstractEnsuring data privacy in blockchain systems remains challenging due to the heavy computational and communication costs of traditional cryptographic mechanisms. Existing solutions often suffer from limited scalability, high resource consumption, and inefficient tamper-proof key management. To address these challenges, we propose Zero Trust Privacy (ZTP), a lightweight framework for scalable on-chain privacy and secure distributed key management. ZTP introduces a hybrid quorum protocol using dynamic scale-free graph adjustments and a parallel data and key management mechanism based on the Geometric Fragmentation Technique (GFT), achieving efficient, tamper-resistant shard handling. To further enhance scalability, we incorporate a lightweight consensus protocol with parallel transaction processing, isolating transactions and key access from untrusted blockchain nodes. We implement and evaluate ZTP on a distributed blockchain prototype, demonstrating outstanding performance, achieving up to 49% fault tolerance, and delivering speedups of at least 55 × compared to state-of-the-art blockchain protocols. Our results highlight ZTP’s potential for resource-constrained and large-scale blockchain deployments. Abdullah Al-Mamun 0001, Dongfang Zhao 0001, Gagan Agrawal, Ahmed Aleroud, Mohamed I. Ibrahem |
ICPP | 4 |
| 2025 | Adversary-Resilient Clustered Federated Learning for Secure AI-Driven Healthcare Data AnalyticsabstractThe healthcare sector consistently handles vast amounts of sensitive data, which must always be kept secure and private. Unlike classical machine learning (ML) models that require centralizing all data, federated learning (FL) addresses privacy concerns by enabling collaborative learning without sharing raw data. However, FL models are subject to limitations when managing diverse datasets from pervasive sources and encounter challenges such as adversarial threats; in addition, the generalizability of the resulting global models may limit the effectiveness of the analysis. This paper presents a novel decentralized and cluster-based FL framework designed to enhance healthcare data privacy and strengthen the security of FL processes. This framework addresses vulnerabilities by decentralizing the FL models. It includes a weighted voting mechanism that aims to improve analytics accuracy by aggregating decisions from multiple clusters. Additionally, the proposed approach reduces the risk of adversarial attacks by employing both cluster-based strategies and feature-squeezing (FS). Experimental results show that our approach surpasses classical FL methods in accuracy and security at various stages of the FL process. Abdullah Melhem, Ahmed Aleroud, Abdullah Al-Mamun 0001, George Karabatis, Mohamed I. Ibrahem |
IWCMC | 2 |
| 2024 | Privacy-preserving, Lightweight, and Decentralized Load Forecasting in Smart Grid AMI NetworksabstractLoad forecasting (LF) in smart grids is beneficial not only in mitigating equipment failures and power outages but also in facilitating effective power dispatching and infrastructure planning. To predict future loads accurately, the consumers' fine-grained energy consumption readings are fed into machine-learning (ML) models. However, revealing these readings enables adversaries to deduce confidential information about consumers, including details about their lifestyle, and hence their privacy is violated. To address this privacy issue, the existing works only focus on using federated learning (FL)-based approaches to train and obtain an accurate global LF model. Nevertheless, addressing the privacy violation problem during the LF process (in the deployment phase) after obtaining the global model for AMI networks has not been well investigated yet. Therefore, this paper proposes a novel, efficient, and decentralized approach that enhances the precision of LF while safeguarding the privacy of consumers. The proposed scheme incorporates inner product functional encryption (IPFE) to allow smart meters (SMs) to encrypt their readings with no need for a trusted key distribution center (KDC) while allowing LF without divulging or acquiring knowledge of the consumers' readings to protect their privacy. In addition, a hybrid deep learning approach is developed to construct an LF model that can yield precise forecasts. To show the feasibility of the proposed scheme, the performance of our scheme was assessed on a real energy consumption readings dataset, and the results demonstrate proficiency in LF while providing robustness and privacy preservation with reasonable communication efficiency. Mohamed I. Ibrahem, Hussien AbdelRaouf, Ahmad Alsharif, Mostafa Fouda, Zubair Md Fadlullah, Ahmed Aleroud |
ICC | 6 |
| 2024 | AdvPurRec: Strengthening Network Intrusion Detection with Diffusion Model Reconstruction Against Adversarial AttacksabstractThe ongoing race between attackers and defenders in cybersecurity hinges on who makes the first move. Defenders have a significant advantage if they can anticipate and counteract attacks preemptively. However, if attackers are aware of the defenders’ strategies, meaningful defense becomes exceedingly challenging. In this paper, we propose a reactive defense technique that adapts to the presence of attacks and mitigates their effects. We introduce an adversarial purification defense technique that leverages the capabilities of a diffusion denoising probabilistic model to eliminate adversarial noise. Through training the purifier and classifier independently on clean examples, our defense remains robust against unseen attacks, making it an agnostic defense method. We rigorously evaluate our defense technique using network intrusion datasets, demonstrating its superiority over other state-of-the-art defense techniques in terms of both effectiveness and efficiency. Our results demonstrate the potential of this method to significantly enhance the resilience of network intrusion detection systems against adversarial threats. To ensure the reproducibility of our results, we have made our implementation publicly available.1 Nour Alhussien, Ahmed Aleroud |
TrustCom | 2 |
| 2024 | Constraining Adversarial Attacks on Network Intrusion Detection Systems: Transferability and Defense AnalysisabstractAdversarial attacks have been extensively studied in the domain of deep image classification, but their impacts on other domains such as Machine and Deep Learning-based Network Intrusion Detection Systems (NIDSs) have received limited attention. While adversarial attacks on images are generally more straightforward due to fewer constraints in the input domain, generating adversarial examples in the network domain poses greater challenges due to the diverse types of network traffic and the need to maintain its validity. Prior research has introduced constraints to generate adversarial examples against NIDSs, but their effectiveness across different attack settings, including transferability, targetability, defenses, and the overall attack success have not been thoroughly examined. In this paper, we proposed a novel set of domain constraints for network traffic that preserve the statistical and semantic relationships between traffic features while ensuring the validity of the perturbed adversarial traffic. Our constraints are categorized into four types: feature mutability constraints, feature value constraints, feature dependency constraints and distribution preserving constraints. We evaluated the impacts of these constraints on white box and black box attacks using two intrusion detection datasets. Our results demonstrated that the introduced constraints have a significant impact on the success of white box attacks. Our research revealed that transferability of adversarial examples depends on the similarity between the targeted models and the models to which the examples are transferred, regardless of the attack type or the presence of constraints. We also observed that adversarial training enhanced the robustness of the majority of machine learning and deep learning-based NIDSs against unconstrained attacks, while providing some resilience against constrained attacks. In practice, this suggests the potential use of pre-existing signatures of constrained attacks to combat new variations or zero-day adversarial attacks in real-world NIDSs. Nour Alhussien, Ahmed Aleroud, Abdullah Melhem, Samer Khamaiseh |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | Target-X: An Efficient Algorithm for Generating Targeted Adversarial Images to Fool Neural Networks
Samer Khamaiseh, Derek Bagagem, Abdullah S. Al-Alaj, Mathew Mancino, Hakem Alomari, Ahmed Aleroud |
COMPSAC | 6 |
| 2023 | AI-based MultiModal to Identify State-linked Social Media Accounts in the Middle East: A Study on TwitterabstractState-linked propaganda on Social Media poses a new challenge at the geopolitical level for the United States and other countries. The widespread of social media platforms makes it easier for adversaries to spread disinformation, conspiracy theories and social-cyber attacks at a scale that was not possible without such networks. Not only English content on social media represents such a challenge since some of those cyber-mediated attacks are initiated by agents who target other languages. In this paper, we proposed a Multimodal AI approach to detect statelinked accounts on twitter. As opposed to previous efforts, we focus our research on the Middle East and the Anti-USA content on Twitter. We trained AI Multimodal approaches on data with categorical, textual and numerical features. The study utilized experimental Twitter data connected to numerous suspected state-linked accounts on the platform. Additionally, we collected data to represent the negative samples. The findings indicate that the significance of textual modalities and AI language models in identifying state-linked accounts was limited. Our study demonstrated the crucial significance of account metadata and other modalities to detect state-linked propaganda and the associated accounts effectively. Abdullah Bani Melhem, Ahmed Aleroud, Zain A. Halloush |
ISI | 2 |
| 2023 | A Novel Poisoning Attack on Few-Shot based Network Intrusion DetectionabstractWith the advancement of Machine Learning (ML) algorithms, more organizations started using Machine Learning based Intrusion Detection Systems (ML-IDSs) to mitigate cyberattacks. However, the lack of training datasets is a major challenge when creating those systems. Therefore, using pre-trained models and small amount of labeled network data or few-shots from internal sources are possible solutions to overcome this challenge. However, using pretrained models or external datasets introduces the risk of poisoned machine learning models. This work investigates a novel poisoning attack that creates a diverse mini cluster of attacks and normal instances around an attack instance, then use the instances in that cluster to poison that instance. The poisoned instances are then injected into training data. A trained model is then created by projecting a labeled data from a poisoned source and the few labeled shots from the target organization. An anomaly-based intrusion detection model is utilized to examine the effectiveness of the introduced approach under the proposed poisoning attack. The results have shown that the attack is effective in the context of few-shot IDS learning. Nour Alhussien, Ahmed Aleroud |
NOMS | 2 |
| 2022 | Triggerability of Backdoor Attacks in Multi-Source Transfer Learning-based Intrusion DetectionabstractNetwork-based Intrusion Detection Systems (NIDSs) automate monitoring of events in networks and analyze them for signatures of cyberattacks. With the advancement of machine learning algorithms, more organizations started using machine learning based IDSs (ML-IDSs) to identify and mitigate cyberattacks. However, the lack of training datasets is a major challenge when implementing ML-IDSs. Therefore, using training data from external sources or transfer learning models are some solutions to overcome this challenge. However, using training data from external sources introduces the risk of backdoored datasets, specifically, when the adversaries also have background knowledge on data sources inside the target organization. This work investigates the role of backdoor attacks on intrusion detection techniques trained using multi-source data. The backdoor examples are injected into one or more training data sources. Transfer learning models are then created by projecting data from different sources into a new subspace containing all source data. The backdoor is then triggered in the target data. An anomaly-based intrusion detection classifier is applied to examine the effectiveness of the introduced backdoors. The results have shown that backdoor attacks on multis-source transfer learning models are feasible, although having less impact compared to backdoors on traditional machine learning models. Nour Alhussien, Ahmed Aleroud, Reza Rahaeimehr, Alexander A. Schwarzmann |
BDCAT | 2 |
| 2021 | Generating Optimal Attack Paths in Generative Adversarial PhishingabstractPhishing attacks have witnessed a rapid increase thanks to the matured social engineering techniques, COVID-19 pandemic, and recently adversarial deep learning techniques. Even though adversarial phishing attacks are recent, attackers are crafting such attacks by considering context, testing different attack paths, then selecting paths that can evade machine learning phishing detectors. This research proposes an approach that generates adversarial phishing attacks by finding optimal subsets of features that lead to higher evasion rate. We used feature engineering techniques such as Recursive Feature Elimination, Lasso, and Cancel Out to generate then test attack vectors that have higher potential to evade phishing detectors. We tested the evasion performance of each technique then classified different evasion tests as passed or failed depending on their evasion rate. Our findings showed that our threat model has better evasion capability compared to the original Generative Adversarial Deep Neural Network (GAN) which perturbs features in a random manner. Rayah Al-Qurashi, Ahmed Aleroud, Ahmad A. Saifan, Mohammad Alsmadi, Izzat Alsmadi |
ISI | 2 |
| 2021 | Fault-based testing for discovering SQL injection vulnerabilities in web applicationsabstractIn this paper we proposed a model to investigate the behaviour of websites when dealing with invalid inputs. Many vulnerabilities rise from invalid inputs. An invalid input is considered as a form of a successful attack if it is processed by the website code or back-end database. Based on this assumption, we proposed a list of indicators that tested and processed invalid inputs. A tool is developed to implement this model. We tested the model through evaluating several websites selected randomly. Our tool has no special credentials or access to any of the tested websites. We found many SQL injection vulnerabilities based on our proposed model. Upon the manual investigation of the web pages that showed such vulnerabilities, we found few instances of false positives. We believe that this can provide a systematic and automated approach to test websites for vulnerabilities related to improper input validation. Izzat Alsmadi, Ahmed Aleroud, Ahmad A. Saifan |
Int. J. Inf. Comput. Secur. | 2 |
| 2020 | A graph proximity feature augmentation approach for identifying accounts of terrorists on twitter
Ahmed Aleroud, Nisreen Abu-Alsheeh, Emad Al-Shawakfa |
Comput. Secur. | 1 |
| 2020 | An examination of susceptibility to spear phishing cyber attacks in non-English speaking communities
Ahmed Aleroud, Emad Abu-Shanab, Ahmad Alaiad 0001, Yazan Alshboul |
J. Inf. Secur. Appl. | 1 |
| 2020 | Automatic Bug Triage in Software Systems Using Graph Neighborhood Relations for Feature AugmentationabstractBug triaging is the process of prioritizing bugs based on their severity, frequency, and risk in order to be assigned to appropriate developers for validation and resolution. This article introduces a graph-based feature augmentation approach for enhancing bug triaging systems using machine learning. A new feature augmentation approach that utilizes graph partitioning based on neighborhood overlap is proposed. Neighborhood overlap is a quite effective approach for discovering relationships in social graphs. Terms of bug summaries are represented as nodes in a graph, which is then partitioned into clusters of terms. Terms in strong clusters are augmented to the original feature vectors of bug summaries based on the similarity between the terms in each cluster and a bug summary. We employed other techniques such as term frequency, term correlation, and topic modeling to identify latent terms and augment them to the original feature vectors of bug summaries. Consequently, we utilized frequency, correlation, and neighborhood overlap techniques to create another feature augmentation approach that enriches the feature vectors of bug summaries to use them for bug triaging. The new modified vectors are used to classify bug reports into different priorities. Bug Triage in this context is to correctly recognize the priority of new bugs. Several classification algorithms are tested using the proposed methods. Experimental results on a data set with Eclipse bug reports extracted from the Bugzilla tracking system have shown that our approach outperformed the existing bug triaging systems including modern techniques that utilize deep learning. Iyad Alazzam, Ahmed Aleroud, Zainab Al Latifah, George Karabatis |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2018 | Queryable Semantics to Detect Cyber-Attacks: A Flow-Based Detection ApproachabstractCyber-attacks continue to increase worldwide, leading to significant loss or misuse of information assets. Most of the existing intrusion detection systems rely on per-packet inspection, a resource consuming task in today's high speed networks. A recent trend is to analyze netflows (or simply flows) instead of packets, a technique performed at a relative low level leading to high false alarm rates. Since analyzing raw data extracted from flows lacks the semantic information needed to discover attacks, a novel approach is introduced, which uses contextual information to automatically identify and query possible semantic links between different types of suspicious activities extracted from flows. Time, location, and other contextual information mined from flows is applied to generate semantic links among alerts raised in response to suspicious flows. These semantic links are identified through an inference process on probabilistic semantic link networks (SLNs), which receive an initial prediction from a classifier that analyzes incoming flows. The SLNs are then queried at run-time to retrieve other relevant predictions. We show that our approach can be extended to detect unknown attacks in flows as variations of known attacks. An extensive validation of our approach has been performed with a prototype system on several benchmark datasets yielding very promising results in detecting both known and unknown attacks. Ahmed Aleroud, George Karabatis |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2017 | Methods and techniques to identify security incidents using domain knowledge and contextual informationabstracta recent trend in intrusion detection is toward utilizing knowledge-based IDSs. Knowledge-based IDSs store knowledge about cyber-attacks and possible vulnerabilities and use this knowledge to guide the process of attack prediction. One significant limitation of knowledge-based IDSs is the lack of contextual information and domain knowledge used to detect attacks. Contextual information is not only the configuration on the targeted systems and their vulnerabilities. It also covers semantic relationships between malicious activities. In addition, domain knowledge extracted from taxonomies about those activities is a significant contextual factor in attack identification. To overcome these limitations, this work introduces a novel contextual framework which consists of several attack prediction models that are utilized in conjunction with IDSs to detect cyber-attacks. Ahmed Aleroud, George Karabatis |
IM | 1 |
| 2017 | Phishing environments, techniques, and countermeasures: A survey
Ahmed Aleroud, Lina Zhou |
Comput. Secur. | 1 |
| 2017 | Identifying cyber-attacks on software defined networks: An inference-based intrusion detection approach
Ahmed Aleroud, Izzat Alsmadi |
J. Netw. Comput. Appl. | 1 |
| 2017 | Contextual information fusion for intrusion detection: a survey and taxonomy
Ahmed Aleroud, George Karabatis |
Knowl. Inf. Syst. | 1 |
| 2015 | Multi-granular aggregation of network flows for security analysisabstractInvestigating network flows is an approach of detecting attacks by identifying known patterns. Flow statistics are used to discover anomalies by aggregating network traces and then using machine-learning classifiers to discover suspicious activities. However, the efficiency and effectiveness of the flow classification models depends on the granularity of aggregation. This paper describes a novel approach that aggregates packets into network flows and correlates them with security events generated by payload-based IDSs for detection of cyber-attacks. Ahmed Aleroud, George Karabatis |
ISI | 2 |
| 2014 | Context and semantics for detection of cyber attacksabstractThis paper presents a novel layered cyber-attack detection approach utilising: 1) semantic relationships between attacks to infer possible related suspicious network activities from connections between hosts; 2) contextual information expressed as attack context profiles on top of semantic relationships. The combined use of context and semantics in intrusion detection results in predicting attacks with higher accuracy while decreasing the number of false positives at the same time. A prototype system has been implemented and experiments have been conducted on it. The results exhibit higher or competitive detection rates compared with other existing approaches. Ahmed Aleroud, George Karabatis, Prayank Sharma |
Int. J. Inf. Comput. Secur. | 1 |