VLDB 2026 Research / reviewers in the wild / expert
Dima Alhadidi
dblp:96/6295
· DBLP profile ↗
28ranked-venue papers
5as first author
9since 2021 · last 2025
0000-0002-2858-5712ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | BTDT: Membership Inference Attacks Against Large Language Models
Shadi Farokhghate, Ali Abbasi Tadi, Dima Alhadidi |
ARES (1) | 3 |
| 2025 | FedMod: Vertical Federated Learning Using Multi-server Secret Sharing
Kasra Mojallal, Ali Abbasi Tadi, Dima Alhadidi |
IDEAS | 3 |
| 2025 | Prompt Attacks and Safeguards in Large Language Models: A Survey
Kasra Mojallal, Pouria Sadr, Sepideh Ahmadian, Dima Alhadidi |
PRICAI | 4 |
| 2025 | PACT: A Passive Accuracy-Based Trust Metric for Malicious Client Detection in Federated LearningabstractDetecting malicious clients in federated learning is particularly challenging when adversaries form the majority. Existing defenses often rely on auxiliary validation data, trusted reference clients, or restrictive attacker assumptions that rarely hold in practice. We introduce Passive Accuracy-Based Client Trust (PACT), a fully passive detector that operates without any probe or validation dataset. PACT estimates client trustworthiness by measuring the class-specific accuracy degradation each client update induces in the global model and by combining the mean and standard deviation of these degradations into a single trust score. Clients whose scores fall below a data-driven threshold, determined using Youden’s J statistic, are flagged as malicious. Experiments on MNIST, Fashion-Mnist, and CIFAR-10 demonstrate that PACT surpasses state-of-the-art baselines including Multi-Krum, FoolsGold, LFighter, and FedDMC under adversary ratios up to 80% in targeted label-flipping attacks. Runtime analysis shows that PACT introduces only modest computational overhead. Overall, PACT provides a practical and robust solution for adversary detection in federated learning deployments lacking auxiliary data or trusted participants. Sayedali Sheykholeslamzadeh, Dima Alhadidi |
TrustCom | 2 |
| 2025 | Key-and-Signature Compact Multi-Signatures for Blockchain: A Compiler With RealizationsabstractMulti-signature is a protocol where a set of signatures jointly sign a message so that the final signature is significantly shorter than concatenating individual signatures together. Recently, it finds applications in blockchain, where several users want to jointly authorize a payment through a multi-signature. However, in this setting, there is no centralized authority and it could suffer from a rogue key attack where the attacker can generate his own public keys. Further, to minimize the storage on blockchain, it is desired that the aggregated public-key and the aggregated signature are both as short as possible. In this article, we find a compiler that converts a kind of identification (ID) scheme (which we call a linear ID) to a multi-signature so that both the aggregated public-key and the aggregated signature have a size independent of the number of signers. Our compiler is provably secure. The advantage of our result is that we reduce a multi-party problem to a weakly secure two-party problem. We realize our compiler with two ID schemes. The first is Schnorr ID. The second is a new lattice-based ID scheme, which via our compiler gives the first regular lattice-based multi-signature scheme with a key-and-signature size independent of the number of signers without a restart during the signing process. Shaoquan Jiang, Dima Alhadidi, Hamid Fazli Khojir |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Comparative Analysis of Membership Inference Attacks in Federated LearningabstractGiven a federated learning model and a record, a membership inference attack can determine whether this record is part of the model’s training dataset. Federated learning is a machine learning technique that enables different parties to train a model without the need to centralize or share that data. Membership inference attack risks the private datasets if those datasets are used to train the federated learning model and access to the generated model is available. There is a need for further study in a federated learning environment to develop effective countermeasures against the membership inference attack without compromising the utility of the target model. In this study, we empirically investigated and compared various membership inference attack approaches in a federated learning environment. We also evaluated these attacks on several optimizers and analyzed them with and without countermeasures. Saroj Dayal, Dima Alhadidi, Ali Abbasi Tadi, Noman Mohammed |
IDEAS | 2 |
| 2023 | FedShare: Secure Aggregation based on Additive Secret Sharing in Federated LearningabstractFederated learning is a machine learning technique where multiple clients with local data collaborate in training a machine learning model. In FedAvg, the main federated learning algorithm, clients train machine learning models locally and share the trained model with the server. While the sensitive data will never be sent to the server, a malicious server can construct the original training data by having access to the clients’ models in each training round. Secure aggregation techniques such as cryptography, trusted execution environment, or differential privacy are used to solve this problem. However, these techniques incur computation and communication overhead or affect the model’s accuracy. In this paper, we consider a secure multi-party computation setup where clients use additive secret sharing to send their models to multiple servers. Our solution provides secure aggregation as long as there are at least two non-colluding servers. Moreover, we provide mathematical proof to show that the securely aggregated model at the end of each training round is exactly equal to the one provided by FedAvg without affecting accuracy and with efficient communication and computation. In comparison with SCOTCH, the state-of-the-art secure aggregation solution, experimental results show that our approach is 557% faster compared to SCOTCH and at the same time it reduces the communication cost of clients by 25%. Additionally, the accuracy of the trained model is exactly as FedAvg under balanced, unbalanced, IID, and Non-IID data distributions while it is only 8% slower. Hamid Fazli Khojir, Dima Alhadidi, Sara Rouhani, Noman Mohammed |
IDEAS | 2 |
| 2023 | Reducing Model Memorization to Mitigate Membership Inference AttacksabstractGiven a machine learning model and a record, membership inference attacks determine whether this record was used as part of the model’s training dataset. This can raise privacy issues. There is a desideratum to provide robust mitigation techniques against this attack that will not affect utility. One of the state-of-the-art frameworks in this area is SELENA, which has two phases: Split-AI and Self-Distillation to train a protected model. In this paper, we introduce a novel approach to the Split-AI phase, which tries to weaken the membership inference by using the Jacobian matrix norm and entropy. We experimentally demonstrate that our approach can decrease the memorization of the machine-learning model for three datasets: Purchase100, CIFAR-10, and SVHN, more than SELENA in the same range of utility in a setting in which we do not know any member of the training data. Mehrdad Sheikhjaberi, Dima Alhadidi |
TrustCom | 2 |
| 2022 | Private Federated Framework for Health DataabstractFederated Learning (FL) is an efficient way to train Machine Learning (ML) algorithms on distributed datasets where data owners are restricted by policies to share their raw data. Through local training and model aggregation to a central server, this method reduces the need to communicate raw data with parties outside of the premises. However, FL raises serious privacy concerns. Therefore, additional privacy measures are required. The differential privacy (DP) approach is a cutting-edge privacy method used to perturb the local models prior to transmission and add an additional layer of privacy. However, this technique can affect the utility of the framework. To balance the privacy-utility trade-off, we implement a hybrid private technique to sanitize raw data using a combination of a top-down taxonomy tree and DP noise. The generalized data using DP noise is used to train local models to be shared in the FL architecture. The proposed framework achieves improved utility with a moderate privacy budget. Tanzir Ul Islam, Noman Mohammed, Dima Alhadidi |
BIBM | 3 |
| 2020 | Membership Inference Attacks: Analysis and MitigationabstractGiven a machine learning model and a record, membership attacks determine whether this record was used as part of the model's training dataset. Membership inference can present a risk to private datasets if these datasets are used to train machine learning models and access to the resulting models is open to the public. To construct attack models, multiple shadow models are created that imitate the behaviour of the target model, but for which we know the training datasets and thus the ground truth about membership in these datasets. Attack models are then trained on the labeled inputs and outputs of the shadow models. There is a desideratum to conduct more analysis about this attack and accordingly to provide robust mitigation techniques that will not affect the target model's utility. In this paper, we empirically analyzed this attack from different perspectives related to the number of models and the type of training algorithms. We also proposed and evaluated different mitigation techniques against this type of attack considering different training algorithms of the target model. Our experiments show that the defence strategies mitigate the membership inference attack considerably while preserving the utility of the target model. Finally, we summarized and compared the existing mitigation techniques with our results. Md Shamimur Rahman Shuvo, Dima Alhadidi |
TrustCom | 2 |
| 2020 | Nearest neighbour search over encrypted data using intel SGX
Kazi Wasif Ahmed, Md Momin Al Aziz, Md. Nazmus Sadat, Dima Alhadidi, Noman Mohammed |
J. Inf. Secur. Appl. | 4 |
| 2019 | Privacy-preserving techniques of genomic data - a surveyabstractGenomic data hold salient information about the characteristics of a living organism. Throughout the past decade, pinnacle developments have given us more accurate and inexpensive methods to retrieve genome sequences of humans. However, with the advancement of genomic research, there is a growing privacy concern regarding the collection, storage and analysis of such sensitive human data. Recent results show that given some background information, it is possible for an adversary to reidentify an individual from a specific genomic data set. This can reveal the current association or future susceptibility of some diseases for that individual (and sometimes the kinship between individuals) resulting in a privacy violation. Regardless of these risks, our genomic data hold much importance in analyzing the well-being of us and the future generation. Thus, in this article, we discuss the different privacy and security-related problems revolving around human genomic data. In addition, we will explore some of the cardinal cryptographic concepts, which can bring efficacy in secure and private genomic data computation. This article will relate the gaps between these two research areas-Cryptography and Genomics. Md Momin Al Aziz, Md. Nazmus Sadat, Dima Alhadidi, Shuang Wang 0002, Xiaoqian Jiang, Cheryl L. Brown, Noman Mohammed |
Briefings Bioinform. | 3 |
| 2019 | Secure Similar Patients Query on Encrypted Genomic DataabstractBoth individuals and enterprises produce genomic data rapidly and continuously. There is a need to outsource such data to the cloud for better flexibility. Outsourcing also helps data owners by eliminating the local storage management problem. To protect data privacy and security, data owners must encrypt the sensitive data before outsourcing. Since genomic data are enormous in volume, executing researchers queries securely, and efficiently is a challenging task. In this paper, we introduce an indexing algorithm based on the prefix-tree to support similar patient queries. The proposed method guarantees the following: data privacy, query privacy, and output privacy. The privacy is guaranteed through encryption and garbled circuits considering the semi-honest adversary model. The overall computation is scalable and fast enough for real-life biomedical applications. Moreover, experimental results show that our method performs better than existing state-of-art techniques in this domain. Md Safiur Rahman Mahdi, Md Momin Al Aziz, Dima Alhadidi, Noman Mohammed |
IEEE J. Biomed. Health Informatics | 3 |
| 2018 | Parallel Linear Regression on Encrypted DataabstractIn recent years, the advent of machine learning models on private data has been remarkable. However, in-corporating machine learning techniques to healthcare data is pretty challenging due to the privacy issues of sensitive data which restricts data sharing in plaintext. Ensuring the privacy of individuals in healthcare datasets while constructing a machine learning model is a challenging research problem today. This paper proposes an approximate mathematical model utilizing linear regression on homomorphically encrypted data to predict the disease association of an individual. Furthermore, as these encryption schemes are not efficient considering computation time, we incorporate the multi-core parallelism to make the framework realistic. We experimentally evaluate the performance of the proposed methods and report on the experimental results. Toufique Morshed, Dima Alhadidi, Noman Mohammed |
PST | 2 |
| 2016 | Secure and Efficient Multiparty Computation on Genomic DataabstractLarge scale biomedical research projects involve analysis of huge amount of genomic data which is owned by different data owners. The collection and storing of genomic data is sometimes beyond the capability of a sole organization. Genomic data sharing is a feasible solution to overcome this problem. These scenarios can be generalized into the problem of aggregating data distributed among multiple databases and owned by different data owners. However, we should guarantee that an adversary cannot learn anything about the data or the individual contribution of each party towards the final output of the computation. In this paper, we propose a practical solution for secure sharing and computation of genomic data. We adopt the Paillier cryptosystem and the order preserving encryption to securely execute the count query and the ranked query. Experimental results demonstrate that the computation time is realistic enough to make our system adoptable in the real world. Md Momin Al Aziz, Mohammad Zahidul Hasan, Noman Mohammed, Dima Alhadidi |
IDEAS | 4 |
| 2015 | Secure and Private Management of Healthcare Databases for Data MiningabstractThere has been a tremendous growth in health data collection since the development of Electronic Medical Record (EMR) systems. Such collected data is further shared and analyzed for diverse purposes. Despite many benefits, data collection and sharing have become a big concern as it threatens individual privacy. In this paper, we propose a secure and private data management framework that addresses both the security and privacy issues in the management of medical data in outsourced databases. The proposed framework ensures the security of data by using semantically-secure encryption schemes to keep data encrypted in outsourced databases. The framework also provides a differentially-private query interface that can support a number of SQL queries and complex data mining tasks. We experimentally evaluate the performance of the proposed framework, and the results show that the proposed framework is practical and has low overhead. Noman Mohammed, Samira Barouti, Dima Alhadidi, Rui Chen 0012 |
CBMS | 3 |
| 2015 | Transportation risk analysis using probabilistic model checking
Andrei Soeanu, Mourad Debbabi, Dima Alhadidi, Makram Makkawi, Mohamad Khaled Allouche, Micheline Bélanger, Nicolas Léchevin |
Expert Syst. Appl. | 3 |
| 2014 | Secure and Privacy-Preserving Querying of Personal Health Records in the Cloud
Samira Barouti, Feras Aljumah, Dima Alhadidi, Mourad Debbabi |
DBSec | 3 |
| 2014 | Secure Two-Party Differentially Private Data Release for Vertically Partitioned DataabstractPrivacy-preserving data publishing addresses the problem of disclosing sensitive data when mining for useful information. Among the existing privacy models, ϵ-differential privacy provides one of the strongest privacy guarantees. In this paper, we address the problem of private data publishing, where different attributes for the same set of individuals are held by two parties. In particular, we present an algorithm for differentially private data release for vertically partitioned data between two parties in the semihonest adversary model. To achieve this, we first present a two-party protocol for the exponential mechanism. This protocol can be used as a subprotocol by any other algorithm that requires the exponential mechanism in a distributed setting. Furthermore, we propose a two-party algorithm that releases differentially private data in a secure way according to the definition of secure multiparty computation. Experimental results on real-life data suggest that the proposed algorithm can effectively preserve information for a data mining task. Noman Mohammed, Dima Alhadidi, Benjamin C. M. Fung, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2013 | Symmetrically-Private Database Search in Cloud ComputingabstractDatabase outsourcing has gained importance in the past few years due to the emergence of the cloud computing. In Database-as-a-Service (DaaS), which is a category of cloud computing services, the database owner outsources both databases and querying services to a cloud server and clients issue queries over the database to the cloud server. In this context, privacy is a primary challenge and it is necessary to fulfill main privacy requirements of database owners and clients. This paper presents protocols for executing keyword search and aggregate SQL queries that preserve the privacy of both the client and the database owner. Client privacy is preserved such that the database owner and the cloud server cannot infer the constants contained in the query predicates. Database owner privacy is preserved such that the client cannot obtain any additional information beyond the query result. The primitives that are utilized in designing these protocols include symmetric private information retrieval and private integer comparison. We experimentally evaluate the performance of the proposed protocols and report on the experimental results. Samira Barouti, Dima Alhadidi, Mourad Debbabi |
CloudCom (1) | 2 |
| 2013 | Common weaving approach in mainstream languages for software security hardening
Dima Alhadidi, Azzam Mourad, Hakim Idrissi Kaitouni, Mourad Debbabi |
J. Syst. Softw. | 1 |
| 2012 | Secure Distributed Framework for Achieving ε-Differential Privacy
Dima Alhadidi, Noman Mohammed, Benjamin C. M. Fung, Mourad Debbabi |
Privacy Enhancing Technologies | 1 |
| 2009 | A Practical Framework for the Dataflow Pointcut in AspectJabstractIn this paper, we present the design and the implementation of the dataflow pointcut in AspectJ compiler ajc 1.5.0. Some security concerns are sensitive to flow of information in a program execution. The dataflow pointcut has been proposed by Masuhara and Kawauchi in order to easily implement such security concerns in aspect-oriented programming languages. The pointcut identifies join points based on the origins of values. The dataflow pointcut can detect and fix a lot of vulnerabilities that result from not validating input effectively, e.g., Web application vulnerabilities, process injection, log forging, and path injection. AspectJ extends the Java programming language to implement crosscutting concerns modularly in general. The implementation methodology of the dataflow pointcut which depends in define-use analysis is described in detail together with case studies that demonstrate how the implemented dataflow pointcut can detect a considerable number of vulnerabilities. Amine Boukhtouta, Dima Alhadidi, Mourad Debbabi |
ARES | 2 |
| 2009 | lambda_SAOP: A Security AOP CalculusabstractThis paper presents an aspect-oriented calculus for security called λ_SAOP. It is based on the λ_calculus and contains pointcuts that are relevant to security hardening of applications. The main contribution of the paper is a semantics for λ_SAOP advice weaving in the presence of these pointcuts. We instrument the effect-based type inference system to inject advices into expressions during static typing. The proposed semantics for advice weaving is in the spirit of AspectJ, a prominent aspect-oriented programming language, where advices are injected before, after or around the join points that match their respective pointcuts. For this purpose, we accommodate the effect-based inference algorithm to take matching and weaving processes into consideration. In addition, we establish the required soundness and preservation proofs. Dima Alhadidi, Nadia Belblidia, Mourad Debbabi, Prabir Bhattacharya |
Comput. J. | 1 |
| 2008 | Cross-Language Weaving Approach Targeting Software Security HardeningabstractIn this paper, we propose an approach for systematic security hardening of software based on aspect-oriented programming and Gimple language. We also present the first steps towards a formal specification for Gimple weaving together with the implementation methodology of the proposed weaving semantics. The primary contribution of this approach is providing the software architects with the capabilities to perform systematic security hardening by applying well-defined solutions and without the need to have expertise in the security solution domain. We explore the viability of our propositions by realizing the weaving semantics for Gimple by implementing it into the GCC compiler and applying our methodologies for systematic security hardening to develop a case study for securing the connections of client applications together with experimental results. Azzam Mourad, Dima Alhadidi, Mourad Debbabi |
PST | 2 |
| 2008 | Towards Language-Independent Approach for Security Concerns Weaving
Azzam Mourad, Dima Alhadidi, Mourad Debbabi |
SECRYPT | 2 |
| 2007 | An AOP Extended Lambda-CalculusabstractThis paper presents an implicitly-typed functional, aspect-oriented programming language: lambda_AOP. The main contribution of the paper is a semantics for lambda_AOP advice weaving. The weaving is type-based and implemented statically. We extend the Hindley-Milner type inference system to inject applicable advices into lambda expressions during typing. The proposed semantics for advice weaving is close to the spirit of Aspect J, the most popular AOP language, where advices are injected before, after, or around points that match their respective pointcuts. For this purpose, the sequence construct of the extended lambda-calculus is used. Dima Alhadidi, Nadia Belblidia, Mourad Debbabi, Prabir Bhattacharya |
SEFM | 1 |
| 2006 | Security crosscutting concerns and AspectJabstractNo abstract available. Dima Alhadidi, Nadia Belblidia, Mourad Debbabi |
PST | 1 |