VLDB 2026 Research / reviewers in the wild / expert
M. Ejaz Ahmed
dblp:87/9285 · also Muhammad Ejaz Ahmed
· DBLP profile ↗
23ranked-venue papers
11as first author
9since 2021 · last 2026
0000-0001-8033-0998ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 7 first-author · 1 since 2021Security and privacy · 10 · 4 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
Sajal Halder, M. Ejaz Ahmed, Muhammad Ikram 0001, Seyit Ahmet Çamtepe, Hyoungshick Kim |
AsiaCCS | 3 |
| 2025 | FuncVul: An Effective Function Level Vulnerability Detection Model Using LLM and Code Chunk
Sajal Halder, M. Ejaz Ahmed, Seyit Ahmet Çamtepe |
ESORICS (1) | 2 |
| 2025 | ST-DPGAN: A Privacy-Preserving Framework for Spatiotemporal Data GenerationabstractRecent advancements have sparked a growing interest in integrating spatiotemporal analysis with large-scale language models. However, spatiotemporal data often contains sensitive information, making it unsuitable for open third-party access. To address this challenge, we propose a Graph-GAN-based model for generating privacy-protected spatiotemporal data. Our approach incorporates spatial and temporal attention blocks in the discriminator and a spatiotemporal deconvolution structure in the generator. These enhancements enable efficient training under Gaussian noise to achieve differential privacy. Extensive experiments conducted on three real-world spatiotemporal datasets validate the efficacy of our model. Our method provides a privacy guarantee while maintaining the data utility. The prediction model trained on our generated data maintains a competitive performance compared to the model trained on the original data. Wei Shao 0006, Rongyi Zhu, Chandra Thapa, M. Ejaz Ahmed, Seyit Ahmet Çamtepe, Rui Zhang 0003, Du Yong Kim, Hamid Menouar, Flora D. Salim |
IEEE Internet Things J. | 5 |
| 2024 | Malicious Package Detection using Metadata InformationabstractProtecting software supply chains from malicious packages is paramount in the evolving landscape of software development. Attacks on the software supply chain involve attackers injecting harmful software into commonly used packages or libraries in a software repository. For instance, JavaScript uses Node Package Manager (NPM), and Python uses Python Package Index (PyPi) as their respective package repositories. In the past, NPM has had vulnerabilities such as the event-stream incident, where a malicious package was introduced into a popular NPM package, potentially impacting a wide range of projects. As the integration of third-party packages becomes increasingly ubiquitous in modern software development, accelerating the creation and deployment of applications, the need for a robust detection mechanism has become critical. On the other hand, due to the sheer volume of new packages being released daily, the task of identifying malicious packages presents a significant challenge. To address this issue, in this paper, we introduce a metadata-based malicious package detection model, MeMPtec. This model extracts a set of features from package metadata information. These extracted features are classified as either easy-to-manipulate (ETM) or difficult-to-manipulate (DTM) features based on monotonicity and restricted control properties. By utilising these metadata features, not only do we improve the effectiveness of detecting malicious packages, but also we demonstrate its resistance to adversarial attacks in comparison with existing state-of-the-art. Our experiments indicate a significant reduction in both false positives (up to 97.56%) and false negatives (up to 91.86%). Sajal Halder, Michael Bewong, Arash Mahboubi, Yinhao Jiang, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Ryan H. L. Ip, M. Ejaz Ahmed, Gowri Sankar Ramachandran, Muhammad Ali Babar 0001 |
WWW | 8 |
| 2022 | Transformer-Based Language Models for Software Vulnerability DetectionabstractThe large transformer-based language models demonstrate excellent performance in natural language processing. By considering the transferability of the knowledge gained by these models in one domain to other related domains, and the closeness of natural languages to high-level programming languages, such as C/C++, this work studies how to leverage (large) transformer-based language models in detecting software vulnerabilities and how good are these models for vulnerability detection tasks. In this regard, firstly, we present a systematic (cohesive) framework that details source code translation, model preparation, and inference. Then, we perform an empirical analysis of software vulnerability datasets of C/C++ source codes having multiple vulnerabilities corresponding to the library function call, pointer usage, array usage, and arithmetic expression. Our empirical results demonstrate the good performance of the language models in vulnerability detection. Moreover, these language models have better performance metrics, such as F1-score, than the contemporary models, namely bidirectional long short term memory and bidirectional gated recurrent unit. Experimenting with the language models is always challenging due to the requirement of computing resources, platforms, libraries, and dependencies. Thus, this paper also analyses the popular platforms to efficiently fine-tune these models and present recommendations while choosing the platforms for our framework. Chandra Thapa, Seung Ick Jang, M. Ejaz Ahmed, Seyit Ahmet Çamtepe, Josef Pieprzyk, Surya Nepal |
ACSAC | 3 |
| 2022 | Cross-language Android permission specificationabstractThe Android system manages access to sensitive APIs by permission enforcement. An application (app) must declare proper permissions before invoking specific Android APIs. However, there is no official documentation providing the complete list of permission-protected APIs and the corresponding permissions to date. Researchers have spent significant efforts extracting such API protection mapping from the Android API framework, which leverages static code analysis to determine if specific permissions are required before accessing an API. Nevertheless, none of them has attempted to analyze the protection mapping in the native library (i.e., code written in C and C++), an essential component of the Android framework that handles communication with the lower-level hardware, such as cameras and sensors. While the protection mapping can be utilized to detect various security vulnerabilities in Android apps, such as permission over-privilege, imprecise mapping will lead to false results in detecting such security vulnerabilities. To fill this gap, we thereby propose to construct the protection mapping involved in the native libraries of the Android framework to present a complete and accurate specification of Android API protection. We develop a prototype system, named NatiDroid, to facilitate the cross-language static analysis and compare its performance with two state-of-the-practice tools, termed Axplorer and Arcade. We evaluate NatiDroid on more than 11,000 Android apps, including system apps from custom Android ROMs and third-party apps from the Google Play. Our NatiDroid can identify up to 464 new API-permission mappings, in contrast to the worst-case results derived from both Axplorer and Arcade, where approximately 71% apps have at least one false positive in permission over-privilege. We have disclosed all the potential vulnerabilities detected to the stakeholders. Xiao Chen 0002, Ruoxi Sun 0001, Minhui Xue 0001, Sheng Wen, M. Ejaz Ahmed, Seyit Ahmet Çamtepe, Yang Xiang 0001 |
ESEC/SIGSOFT FSE | 6 |
| 2022 | Backdoor Attack on Machine Learning Based Android Malware DetectorsabstractMachine learning (ML) has been widely used for malware detection on different operating systems, including Android. To keep up with malware's evolution, the detection models usually need to be retrained periodically (e.g., every month) based on the data collected in the wild. However, this leads to poisoning attacks, specifically backdoor attacks, which subvert the learning process and create evasion ‘tunnels’ for manipulated malware samples. To date, we have not found any prior research that explored this critical problem in Android malware detectors. Although there are already some similar works in the image classification field, most of those similar ideas cannot be borrowed to solve this problem, because the assumption that the attacker has full control of the training data collection or labelling process is not realistic in real-world malware detection scenarios. In this article, we are motivated to study the backdoor attack against Android malware detectors. The backdoor is created and injected into the model stealthily without access to the training data and activated when an app with the trigger is presented. We demonstrate the proposed attack on four typical malware detectors that have been widely discussed in academia. Our evaluation shows that the proposed backdoor attack achieves up to 99 percent evasion rate over 750 malware samples. Moreover, the above successful attack is realised by a small size of triggers (only four features) and a very low data poisoning rate (0.3 percent). Xiao Chen 0002, Derui Wang, Sheng Wen, M. Ejaz Ahmed, Seyit Ahmet Çamtepe, Yang Xiang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Decamouflage: A Framework to Detect Image-Scaling Attacks on CNNabstractImage-scaling is a typical operation that processes the input image before feeding it into convolutional neural network models. However, it is vulnerable to the newly revealed image-scaling attack. This work presents an image-scaling attack detection framework, Decamouflage, consisting of three independent detection methods: scaling, filtering, and steganalysis, to detect the attack through examining distinct image characteristics. Decamouflage has a pre-determined detection threshold that is generic. More precisely, as we have validated, the threshold determined from one dataset is also applicable to other different datasets. Extensive experiments show that Decamouflage achieves detection accuracy of 99.9% and 98.5% in the white-box and the black-box settings, respectively. We also measured its running time overhead on a PC with an Intel i5 CPU and 8GB RAM. The experimental results show that image-scaling attacks can be detected in milliseconds. Moreover, Decamouflage is highly robust against adaptive image-scaling attacks (e.g., attack image size variances). Bedeuro Kim, Alsharif Abuadbba, Yansong Gao 0001, Yifeng Zheng 0001, M. Ejaz Ahmed, Surya Nepal, Hyoungshick Kim |
DSN | 5 |
| 2021 | Peeler: Profiling Kernel-Level Events to Detect Ransomware
M. Ejaz Ahmed, Hyoungshick Kim, Seyit Ahmet Çamtepe, Surya Nepal |
ESORICS (1) | 1 |
| 2020 | Void: A fast and light voice liveness detection system
M. Ejaz Ahmed, Il-Youp Kwak, Jun-Ho Huh, Iljoo Kim, Taekkyung Oh, Hyoungshick Kim |
USENIX Security Symposium | 1 |
| 2019 | NOn-parametric Bayesian channEls cLustering (NOBEL) Scheme for Wireless Multimedia Cognitive Radio NetworksabstractIn wireless multimedia cognitive radio networks (WMCRNs), to optimize multimedia transmissions and scarce wireless spectrum utilization, a multimedia secondary user (MSU) needs to estimate and/or identify the achievable quality of service (QoS)-levels over the available licensed channels. However, due to the lack of signaling information among MSUs and the primary users (PUs) in uncoordinated environments, identification of the achievable QoS-levels on the available licensed channels is a challenging problem and has not yet been fully explored. To address this challenge, we propose a novel NOn-parametric Bayesian channEls cLustering (NOBEL) scheme. In NOBEL, an infinite Gaussian mixture model-based collapsed Gibbs sampler is adopted to identify the achievable QoS-levels over the feature space, i.e., bitrate, packet delay variation, and packet delivery ratio on the PUs' licensed channels. Real trace-driven evaluation results demonstrate that NOBEL outperforms other baseline clustering techniques and guarantee high accuracy from 98% to 99.5%. Amjad Ali 0002, M. Ejaz Ahmed, Farman Ali 0001, Nguyen Hoang Tran, Dusit Niyato, Sangheon Pack |
IEEE J. Sel. Areas Commun. | 2 |
| 2019 | Statistical Application Fingerprinting for DDoS Attack MitigationabstractBecause of the dynamic nature of network traffic patterns, such as new traffic application arrivals or flash events, it is becoming increasingly difficult for conventional anomaly detection systems to separate various applications based on their traffic patterns. In this paper, by leveraging transport layer packet-level and flow-level features, new structures called application fingerprints are generated, which express such features in a compact and efficient manner. Based on the generated fingerprints, we propose a novel traffic classification framework. The proposed system generates profiles of normal applications using a multi-modal probability distribution. The proposed classification framework is then extended to detect distributed denial of service attacks from the collected statistical information at flow level. To demonstrate the feasibility of the proposed system, we evaluate its performance using five real-world traffic datasets. The experiment results show that the proposed method is capable of achieving an accuracy of over 97%, whereas the misclassification rate is only 2.5%. M. Ejaz Ahmed, Hyoungshick Kim |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2018 | Traffic-Aware Optimal Spectral Access in Wireless Powered Cognitive Radio NetworksabstractTraffic patterns associated with different primary users (PUs) might provide different spectral access and energy harvesting opportunities to secondary users (SUs) in wireless powered cognitive radio networks (WP-CRNs). Since the traffic applications have their own distinctive patterns, spectral access and energy harvesting opportunities are also expected to be distinctive. In this paper, we propose a novel approach to identify the PU traffic patterns and estimate the energy harvested from each traffic pattern so that SU can maximize its capacity accordingly. More specifically, we propose a theoretical framework based on a variational inference algorithm to cluster various traffic patterns and design a threshold-based SU transmission strategy by taking into account the spectral access and energy harvesting opportunities for each traffic pattern, so as to optimize SU transmission. Through simulations, we demonstrate the effectiveness of the proposed scheme in terms of throughput gains and show the transmission thresholds under various traffic applications (patterns). Further, we illustrate the effects of different collision costs on throughput for different traffic applications using real wireless traces. M. Ejaz Ahmed, Dong In Kim 0001, Kae Won Choi |
IEEE Trans. Mob. Comput. | 1 |
| 2017 | Optimal spectrum sensing policy in RF-powered cognitive radio networks
Hae Sol Lee, M. Ejaz Ahmed, Dong In Kim 0001 |
APCC | 2 |
| 2017 | Poster: Adversarial Examples for Classifiers in High-Dimensional Network DataabstractMany machine learning methods make assumptions about the data, such as, data stationarity and data independence, for an efficient learning process that requires less data. However, these assumptions may give rise to vulnerabilities if violated by smart adversaries. In this paper, we propose a novel algorithm to craft the input samples by modifying a certain fraction of input features as small as in order to bypass the decision boundary of widely used binary classifiers using Support Vector Machine (SVM). We show that our algorithm can reliably produce adversarial samples which are misclassified with 98% success rate while modifying 22% of the input features on average. Our goal is to evaluate the robustness of classification algorithms for high demensional network data by intentionally performing evasion attacks with carefully designed adversarial examples. The proposed algorithm is evaluated using real network traffic datasets (CAIDA 2007 and CAIDA 2016). M. Ejaz Ahmed, Hyoungshick Kim |
CCS | 1 |
| 2017 | Preventing DNS Amplification Attacks Using the History of DNS Queries with SDN
Sora Lee, Geumhwan Cho, M. Ejaz Ahmed, Jaehoon Jeong 0001, Hyoungshick Kim |
ESORICS (2) | 4 |
| 2017 | Traffic-pattern aware opportunistic wireless energy harvesting in cognitive radio networksabstractEach traffic application follows a unique packet transmission pattern, which can be used to identify traffic applications. Current literature on cognitive radio networks (CRNs) assume that primary user (PU) channel idle and busy time probabilities are predefined and known. However, in practice, those probabilities are application-specific. In this paper, from application-dependent traffic features, we propose a Bayesian nonparametric method to detect and classify primary transmitter's (PT's) applications to estimate the secondary user (SU) spectral access and energy harvesting opportunities related to each application. To this end, the Dirichlet process mixture model (DPMM) is employed and a mean-field variational method is proposed. We demonstrate the effectiveness of the proposed method by both simulations and experiment data obtained from the WiMax networks. M. Ejaz Ahmed, Dong In Kim 0001 |
ICC | 1 |
| 2016 | Traffic and energy-aware access in wireless powered cognitive radio networksabstractIn wireless powered cognitive radio networks (WP-CRNs) where secondary users (SUs) access spectral white spaces left by primary users (PUs), there exists a trade-off between SU transmission and energy harvesting. However, the white spaces and the harvested energy depends on the PUs traffic applications, and this fact can be utilized to optimize SU transmissions based on the energy harvested from that traffic application. In this paper, we propose a threshold-based SU transmission strategy under the constraints that take into account the spectral access opportunities and the total energy harvested associated with each traffic application. Furthermore, we propose an algorithm which obtains an optimal threshold with respect to the available harvested energy. In the simulation results, we demonstrate the effectiveness of the proposed scheme in terms of throughput gains and show the transmission thresholds under various traffic applications (patterns). Moreover, we illustrate the effects of different collision costs on throughput for different traffic applications using real wireless traces. M. Ejaz Ahmed, Dong In Kim 0001 |
WCNC | 1 |
| 2014 | Mitigating malicious attacks using Bayesian nonparametric clustering in collaborative cognitive radio networksabstractReliable detection of primary users is an important task in cognitive radio. It becomes challenging in the presence of malicious users' sharing false sensing data in a collaborative spectrum sensing. In this paper, we propose a Bayesian nonparametric clustering approach to estimate the primary user's channel behavior and identify malicious users' collaborative spectrum sensing. The proposed scheme clusters malicious attacks in a Bayesian nonparametric way and identifies malicious users. From the simulation results, we demonstrate the effectiveness of the proposed approach by using real wireless traces and comparing with the nonparametric mean-shift clustering approach. M. Ejaz Ahmed, Ju Bin Song, Zhu Han 0001 |
GLOBECOM | 1 |
| 2014 | Sensing-Transmission Edifice Using Bayesian Nonparametric Traffic Clustering in Cognitive Radio NetworksabstractIn cognitive radio networks, the main objective of spectrum sensing is to exploit spectrum holes left by the primary users (PUs). Different PUs' traffic patterns might provide different opportunities for second user (SU) spectrum access. In this paper, we identify the PUs' traffic patterns and then maximize SU transmission accordingly. First a theoretical framework is developed to cluster PU traffic patterns based on a Bayesian nonparametric inference model, in which the number of traffic types is unknown. Second, in order to exploit the spectrum holes, we study a sensing-transmission structure to optimize the SU transmission strategy. Specifically, we exploit the short and long transmission opportunities based on the PU traffic pattern and channel idle time distribution. Finally, we propose a threshold-based sensing-transmission method that optimizes the SU utility, while protecting PU transmissions. Both sensing and transmission errors are considered for perfect sensing with/without acknowledgement-based transmission and imperfect sensing, respectively. From the simulation results, we show that the proposed technique outperforms the nonparametric mean shift clustering algorithm. Furthermore, we utilize these clustering results to optimize the SU's transmission strategy with perfect and imperfect sensing. We compare our proposed technique with the probabilistic sensing-transmission structure and show the performance gain in terms of throughput. M. Ejaz Ahmed, Ju Bin Song, Zhu Han 0001, Doug Young Suh |
IEEE Trans. Mob. Comput. | 1 |
| 2013 | Traffic pattern-based reward maximization for secondary user in dynamic spectrum accessabstractIn cognitive radio networks where secondary users (SUs) access spectral white spaces left by primary users (PUs), there exists a trade-off between sensing and transmission. However, the white spaces depend on the PUs' traffic patterns, and this fact can be utilized to optimize SU transmissions after traffic identification. This paper studies the effective approaches to adapt SU transmissions to the inherit dynamics associated to each PU traffic application. We define a threshold for sensing-transmission trade-off that is optimal under the technical constraints, and exploit short time and long time opportunities left by PUs. In the simulation results, we demonstrate the effectiveness of the proposed scheme by comparing with the threshold-based sensing transmission structure for throughput gains and show the sensing-transmission threshold under various traffic applications (patterns). Moreover, we illustrate the effects of different sensing times on throughput for different traffic applications using some real traces. M. Ejaz Ahmed, Ju Bin Song, Zhu Han 0001 |
WCNC | 1 |
| 2012 | Nonparametric Bayesian identification of primary users' payloads in cognitive radio networksabstractIn cognitive radio networks, a secondary user needs to estimate the primary users' traffic patterns so as to optimize its transmission strategy. In this paper, we propose a nonparametric Bayesian method for identifying traffic applications, since the traffic applications have their own distinctive patterns. In the proposed algorithm, the collapsed Gibbs sampler is applied to cluster the traffic applications using the infinite Gaussian mixture model over the feature space of the packet length, the packet inter-arrival time, and the variance of packet lengths. We analyze the effectiveness of our proposed technique by extensive simulation using the measured data obtained from the WiMax networks. M. Ejaz Ahmed, Ju Bin Song, Nam Tuan Nguyen, Zhu Han 0001 |
ICC | 1 |
| 2012 | Channel allocation under uncertain primary users for delay sensitive secondary usersabstractFor reducing the channel switching frequency due to uncertain and frequent primary users' interruptions, we design a nonparametric channel allocation algorithm which can effectively manage the spectrum resources in distributed cognitive radio networks and serve for delay-sensitive data traffics. In the proposed algorithm, an infinite Gaussian mixture model is used to get the posterior decision from the feature spaces of the channel idle duration and the primary user's frequency channel, while the collapsed Gibbs sampling is applied for fast convergence. Experimental and simulation results demonstrate that the proposed channel allocation algorithm outperforms the random channel allocation method and the idle probability based channel allocation algorithm in terms of throughput and packet drops. Guanzhe Zhao, M. Ejaz Ahmed, Rukun Mao, Ju Bin Song, Husheng Li |
WCNC | 2 |