VLDB 2026 Research / reviewers in the wild / expert
Ali A. Ghorbani 0001
dblp:g/AliAGhorbani · also Ali Akbar Ghorbani
· DBLP profile ↗
164ranked-venue papers
4as first author
56since 2021 · last 2026
0000-0001-9189-6268ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 79 · 24 since 2021Artificial intelligence and machine learning · 38 · 4 first-author · 8 since 2021Computer networks · 21 · 11 since 2021Databases, data management, data science and information retrieval · 20 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 7 since 2021Human-computer interaction and ubiquitous computing · 5 · 1 since 2021Software engineering, systems software and programming languages · 4 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3Theory of computation · 2Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cybersecurity in the quantum era: Assessing the impact of quantum computing on infrastructureabstractThe emergence of quantum computing presents a double-edged sword for cybersecurity. While its immense power holds promise for advancements in various fields, it also threatens to crack the foundation of current encryption methods. This analysis explores the impact of quantum computing on critical infrastructure and cloud services, meticulously evaluating potential vulnerabilities across various layers, including applications, data, runtime, middleware, operating systems, virtualization, hardware, storage, and networks. We advocate for proactive security strategies and collaboration between sectors to develop and implement quantum-resistant cryptography. This crucial shift necessitates a comprehensive approach, and the paper introduces a tailored security blueprint encompassing nine critical infrastructure components. This blueprint strengthens each area's defenses against potential quantum-induced cyber threats. Our strategic vulnerability and risk assessment equips stakeholders with the knowledge to navigate the complex quantum threat landscape. This empowers them to make informed decisions about design, implementation, and policy formulation, ultimately bolstering the resilience of critical infrastructure. In essence, this analysis not only forecasts quantum threats but also offers a sophisticated, actionable framework for fortifying infrastructure and cloud environments against the multifaceted challenges of the quantum era. This proactive approach will ensure continued data security and a thriving digital landscape in the years to come Yaser Baseri, Vikas Chouhan, Ali A. Ghorbani 0001 |
Comput. Secur. | 3 |
| 2026 | Dual explanations via subgraph matching for malware detectionabstractInterpretable malware detection is crucial for understanding harmful behaviors and building trust in automated security systems. Traditional explainable methods for Graph Neural Networks (GNNs) often highlight important regions within a graph but fail to associate them with known benign or malicious behavioral patterns. This limitation reduces their utility in security contexts, where alignment with verified prototypes is essential. In this work, we introduce a novel dual prototype-driven explainable framework that interprets GNN-based malware detection decisions. This dual explainable framework integrates a base explainer (a state-of-the-art explainer) with a novel second-level explainer which is designed by subgraph matching technique, called SubMatch explainer. The proposed explainer assigns interpretable scores to nodes based on their association with matched subgraphs, offering a fine-grained distinction between benign and malicious regions. This prototype-guided scoring mechanism enables more interpretable, behavior-aligned explanations. Experimental results demonstrate that our method preserves high detection performance while significantly improving interpretability in malware analysis. • Dual prototype-driven framework for explainable GNN-based malware detection. • SubMatch explainer uses subgraph matching for structure-aware node interpretation. • Behavior-aligned explanations via verified malicious and benign subgraph prototypes. • Fine-grained localization of malicious and benign regions within a CFG. Hossein Shokouhi-Nejad, Roozbeh Razavi-Far, Griffin Higgins, Ali A. Ghorbani 0001 |
Eng. Appl. Artif. Intell. | 4 |
| 2026 | DNS user profiling and risk assessment: A learning approach
Yaser Baseri, Mahdi Daghmechi Firoozjaei, Somayeh Sadeghi, Ali A. Ghorbani 0001, William Belanger, Roozbeh Razavi-Far |
Future Gener. Comput. Syst. | 4 |
| 2026 | CIC-YNU-IoTMal: A comprehensive multilayer dataset for static and dynamic analysis of IoT malware behaviorabstractMalware continues to pose a critical security threat to the Internet of Things (IoT) ecosystem, driven by the diversity and dynamics of network environments. These conditions introduce significant vulnerabilities, rendering IoT devices prime targets for sophisticated malware attacks. Honeypots have been employed to emulate IoT devices and generate comprehensive malware datasets, enabling the development of adaptive defense systems. However, existing approaches often rely solely on static or dynamic analysis, which fails to keep pace with the evolving nature of malware. Moreover, rigorous detection requires high-fidelity datasets that reflect real-world threats, yet publicly available, multi-architecture IoT malware datasets with recent signatures remain scarce. To address this gap, we present CIC-YNU-IoTMal, a well-researched dataset integrating static and dynamic malware behaviors. Leveraging IoTPOT data and simulated IoT devices, we captured raw network packets, system calls, and system activity logs. Specifically, 10,000 malware binaries were executed on simulated IoT devices within Docker containers and sandbox environments tailored to each architecture. The pipeline processes ARM, MIPS, MIPSEL, and x86 architectures, collecting network traffic (PCAP), system traces (STRACE), and system statistics (SAR). These files were converted to CSV, analyzed, and used to train machine learning algorithms for malware classification. CIC-YNU-IoTMal comprises 2.4M PCAP, 1.8M SAR, and 105M STRACE samples across architectures, representing families such as Mirai, Bashlite (Gafgyt), DarkNexus, Rudedevil, Agent, Generic, and Tsunami. Experimental validation demonstrates that dynamic malware behaviors can be effectively tracked and detected. CIC-YNU-IoTMal2026 is publicly available, advancing research toward a more secure IoT environment. Sajjad Dadkhah, Ogobuchi Daniel Okey, Sebin Abraham Maret, Yen-Wu Lo, Amir Firouzi, Ryu Kuki, Takayuki Sasaki, Katsunari Yoshioka, Tao Ban, Seiichi Ozawa, Ali A. Ghorbani 0001 |
Inf. Syst. | 11 |
| 2026 | A lightweight defense mechanism against next-generation of phishing emails using distilled attention-augmented BiLSTMabstractThe current generation of large language models produces sophisticated social-engineering content that bypasses standard text screening systems in business communication platforms. Our proposed solution for mail gateway and endpoint deception detection operates in a privacy-protective manner while handling the performance requirements of network and mobile security systems. The MobileBERT teacher receives fine-tuning before its transformation into a BiLSTM model with multi-head attention which maintains semantic discrimination only with 4.5 million parameters. The hybrid dataset contains human-written messages together with LLM-generated paraphrases that use masking techniques and personalization methods to enhance modern attack resistance. The evaluation system uses five testing protocols which include human-only and LLM-only tests and two cross-distribution transfer tests and a production-like mixed traffic test to assess performance in native environments and across different distribution types and combined traffic scenarios. The distilled model maintains a weighted-F1 score difference of 1–2.5 points compared to the mixture split results of strong transformer baselines including ModernBERT, DeBERTaV3-base, T5-base, DeepSeek-R1 Distill Qwen-1.5B and Phi-4 mini while achieving 80–95% faster inference times and 95–99% smaller model sizes. The system demonstrates excellent performance in terms of accuracy and latency while maintaining a compact size which enables real-time filtering without acceleration hardware and supports policy-based management. The paper examines system performance under high traffic conditions and security measures for privacy protection and implementation methods for operational deployment. The research team will release all necessary code and training scripts and corpus splits to support security researchers who want to reproduce experiments and implement practical solutions. Morteza Eskandarian, Mahdi Rabbani, Arun Kaniyamattam, Fatemeh Nejati, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Ali A. Ghorbani 0001, Sajjad Dadkhah |
J. Inf. Secur. Appl. | 8 |
| 2026 | Large language model (LLM) for software security: Code analysis, malware analysis, reverse engineering
Hamed Jelodar, Samita Bai, Parisa Hamedi, Hesamodin Mohammadian, Roozbeh Razavi-Far, Ali A. Ghorbani 0001 |
J. Inf. Secur. Appl. | 6 |
| 2026 | DRCF: A Privacy-Enhanced Distributed Publish-Subscribe System for Secure Data Computation in Untrusted EnvironmentsabstractModern publish-subscribe systems are increasingly deployed in applications such as smart grids, industrial IoT, and smart homes, where brokers perform not only message forwarding but also in-broker computation. This shift from receive-forward (RF) to receive-compute-forward (RCF) models introduces new privacy and trust concerns, as centralized brokers gain access to sensitive data. In this article, we present a distributed and privacy-preserving RCF ( \(\textsf{DRCF}\) ) framework that replaces the trust assumption on a single centralized broker with multiple semi-honest brokers. Our system integrates distributed authenticated encryption, threshold signatures, and 2-party secure computation realized using homomorphic encryption and garbled circuits to protect both communication and computation. We formally prove the security of \(\textsf{DRCF}\) in the semi-honest adversarial model. We implement \(\textsf{DRCF}\) on top of the Mosquitto broker and evaluate it on real-world IoT workloads, including anomaly detection, load forecasting, and electricity price prediction. Experimental results demonstrate that \(\textsf{DRCF}\) achieves scalability and efficiency while preserving privacy, confidentiality, and integrity in modern publish-subscribe systems. Shabnam Saderi Oskouei, Kalikinkar Mandal, Ali A. Ghorbani 0001 |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2025 | SBAN: A Framework & Multi-Dimensional Dataset for Large Language Model Pre-Training and Software Code MiningabstractThis paper introduces SBAN (Source code, Binary, Assembly, and Natural Language Description), a large-scale, multi-dimensional dataset designed to advance the pre-training and evaluation of large language models (LLMs) for software code analysis. SBAN comprises more than 3 million samples, including 2.9 million benign and 672,000 malware respectively, each represented across four complementary layers: binary code, assembly instructions, natural language descriptions, and source code. This unique multimodal structure enables research on cross-representation learning, semantic understanding of software, and automated malware detection. Beyond security applications, SBAN supports broader tasks such as code translation, code explanation, and other software mining tasks involving heterogeneous data. It is particularly suited for scalable training of deep models, including transformers and other LLM architectures. By bridging low-level machine representations and high-level human semantics, SBAN provides a robust foundation for building intelligent systems that reason about code. We believe that this dataset opens new opportunities for mining software behavior, improving security analytics, and enhancing LLM capabilities in pre-training and fine-tuning tasks for software code mining. Hamed Jelodar, Mohammad Meymani, Samita Bai, Roozbeh Razavi-Far, Ali A. Ghorbani 0001 |
ICDM | 5 |
| 2025 | NLD-LLM: A systematic framework for evaluating small language transformer models on natural language descriptionabstractNatural Language Description (NLD) is a Natural Language Processing (NLP) task that requires models to generate structured and meaningful outputs from natural language inputs. In this work, we propose NLD-LLM, a systematic NLP framework to evaluate the performance of language models to generate accurate and concise source code descriptions. This framework incorporates a diverse set of transformer models, including Qwen, DeepSeek, Phi, LLaMA, and Mistral, spanning various sizes, architectures, and training approaches. Central to NLD-LLM is a comprehensive prompt design strategy that includes standardized formatting, clear task guidance, and NLD prompting, ensuring fair and consistent evaluation. Additionally, we apply an iterative refinement process to improve output’s quality and assess the model’s adaptability. Using semantic and structural metrics, our analysis demonstrates that prompt engineering significantly impacts the effectiveness of the model such that smaller models often performing competitively when supported by well-crafted prompts. Hamed Jelodar, Mohammad Meymani, Parisa Hamedi, Tochukwu Emmanuel Nwankwo, Samita Bai, Roozbeh Razavi-Far, Ali A. Ghorbani 0001 |
ICMLA | 7 |
| 2025 | Role of cybersecurity for a secure global communication eco-system: A comprehensive cyber risk assessment for satellite communications
Samuel Ansong, Windhya Hansinie Rankothge, Somayeh Sadeghi, Hesamodin Mohammadian, Farrukh Bin Rashid, Ali A. Ghorbani 0001 |
Comput. Secur. | 6 |
| 2025 | Evaluation framework for quantum security risk assessment: A comprehensive strategy for quantum-safe transitionabstractThe rise of large-scale quantum computing poses a significant threat to traditional cryptographic security measures. Quantum attacks, particularly targeting the mathematical foundations of current asymmetric cryptographic algorithms, render them ineffective. Even standard symmetric key cryptography is susceptible, albeit to a lesser extent, with potential security enhancements through longer keys or extended hash function outputs. Consequently, the cryptographic solutions currently employed to safeguard data will be inadequately secure and vulnerable to emerging quantum technology threats. In response to this impending quantum menace, organizations must chart a course towards quantum-safe environments, demanding robust business continuity plans and meticulous risk management throughout the migration process. This study provides an in-depth exploration of the challenges associated with migrating from a non-quantum-safe cryptographic state to one resilient against quantum threats. We introduce a comprehensive security risk assessment framework that scrutinizes vulnerabilities across algorithmic, certificate, and protocol layers, covering the entire migration journey, including pre-migration, through-migration, and post-migration stages. Our methodology links identified vulnerabilities to the well-established STRIDE threat model, establishing precise criteria for evaluating their potential impact and likelihood throughout the migration process. Moving beyond theoretical analysis, we address vulnerabilities practically, especially within critical components like cryptographic algorithms, public key infrastructures, and network protocols. Our study not only identifies potential attacks and vulnerabilities at each layer and migration stage but also suggests possible countermeasures and alternatives to enhance system resilience, empowering organizations to construct a secure infrastructure for the quantum era. Through these efforts, we establish the foundation for enduring security in networked systems amid the challenges of the quantum era. Yaser Baseri, Vikas Chouhan, Ali A. Ghorbani 0001, Aaron Chow |
Comput. Secur. | 3 |
| 2025 | Corrigendum to "Evaluation framework for quantum security risk assessment: A comprehensive strategy for quantum-safe transition" [Computers & Security, 150, 104272]
Yaser Baseri, Vikas Chouhan, Ali A. Ghorbani 0001, Aaron Chow |
Comput. Secur. | 3 |
| 2025 | Securing financial sector applications in the quantum era: a comprehensive evaluation of NIST's recommended algorithms through use-case analysis
Somayeh Sadeghi, Vikas Chouhan, Mohammed Aldarwbi, Ali A. Ghorbani 0001, Aaron Chow, Robby Burko |
Expert Syst. Appl. | 4 |
| 2025 | Device Identification and Anomaly Detection in IoT EnvironmentsabstractAs the Internet of Things (IoT) landscape continues to expand, a diverse range of devices with various functionalities is being integrated into the IoT ecosystem. When traditional systems, which involve human interaction, are replaced by devices, it becomes crucial to upgrade the conventional authorization and authentication mechanisms. Traditional approaches for device identification and anomaly detection often fail to address the dynamic behaviors of IoT devices due to the highly heterogeneous nature of the IoT environment. To address these challenges, this article proposes a novel and lightweight integrated model for simultaneous IoT device identification and anomaly detection. The proposed approach leverages both packet-based and flow-based feature extraction techniques to extract a diverse and significant set of features, which are crucial for robust anomaly detection and device classification. This novel combined feature set incorporates a wide range of attributes from various domains, including HTTPS-related features, handshake information, and user agent strings, specifically extracted for IoT device identification. In addition, the feature set includes specialized attributes for anomaly detection, such as stream, channel, and jitter metrics, which are calculated over different time intervals to enhance the model’s anomaly detection capabilities. Experimental analysis, conducted using real network traffic data from state-of-the-art datasets, demonstrates the model’s efficiency and scalability, which makes the model well-suited for real-time IoT threat detection and device management in resource-constrained environments. Mahdi Rabbani, Jinkun Gui, Fatemeh Nejati, Zeming Zhou, Arun Kaniyamattam, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Rongxing Lu, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 10 |
| 2025 | On the consistency of GNN explanations for malware detectionabstractControl Flow Graphs (CFGs) are critical for analyzing program execution and characterizing malware behavior. With the growing adoption of Graph Neural Networks (GNNs), CFG-based representations have proven highly effective for malware detection. This study proposes a novel framework that dynamically constructs CFGs and embeds node features using a hybrid approach combining rule-based encoding and autoencoder-based embedding. A GNN-based classifier is then constructed to detect malicious behavior from the resulting graph representations. To improve model interpretability, we apply state-of-the-art explainability techniques, including GNNExplainer, PGExplainer, and CaptumExplainer, the latter is utilized three attribution methods: Integrated Gradients, Guided Backpropagation, and Saliency. In addition, we introduce a novel aggregation method, called RankFusion, that integrates the outputs of the top-performing explainers to enhance the explanation quality. We also evaluate explanations using two subgraph extraction strategies, including the proposed Greedy Edge-wise Composition (GEC) method for improved structural coherence. A comprehensive evaluation using accuracy, fidelity, and consistency metrics demonstrates the effectiveness of the proposed framework in terms of accurate identification of malware samples and generating reliable and interpretable explanations. Hossein Shokouhi-Nejad, Griffin Higgins, Roozbeh Razavi-Far, Hesamodin Mohammadian, Ali A. Ghorbani 0001 |
Inf. Sci. | 5 |
| 2025 | A lightweight IoT device identification using enhanced behavioral-based features
Mahdi Rabbani, Jinkun Gui, Zeming Zhou, Fatemeh Nejati, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Rongxing Lu, Ali A. Ghorbani 0001 |
Peer Peer Netw. Appl. | 9 |
| 2024 | Enhancing EV Charging Station Security Using a Multi-dimensional Dataset: CICEVSE2024
Emmanuel Dana Buedi, Ali A. Ghorbani 0001, Sajjad Dadkhah, Raphael Ferreira |
DBSec | 2 |
| 2024 | Resilience Against APTs: A Provenance-Based IIoT Dataset for Cybersecurity Research
Erfan Ghiasvand, Suprio Ray, Shahrear Iqbal, Sajjad Dadkhah, Ali A. Ghorbani 0001 |
MobiQuitous | 5 |
| 2024 | Poisoning and Evasion: Deep Learning-Based NIDS under Adversarial AttacksabstractGiven their crucial role in protecting networks from numerous security threats, intrusion detection systems are crucial to any cybersecurity architecture. Deep neural networks have recently shown astounding effectiveness and performance in various machine learning applications, including intrusion detection. However, it has been observed that deep learning models are highly susceptible to a wide range of attacks during both the training and testing phases. These attacks can compromise the privacy of deep learning models, such as poisoning attacks that can affect the performance of the target model during the training process and evasion attacks that can undermine the security of these models during the testing phase. Numerous studies have been conducted to understand and mitigate these attacks and to propose more efficient techniques with higher success rates and accuracy in various tasks utilizing deep learning models, such as image classification, face recognition, network intrusion detection, and healthcare applications. Despite the considerable efforts in this area, the network domain still lacks sufficient attention to these attacks and vulnerabilities. This paper aims to address this gap by proposing a framework for adversarial attacks against network intrusion detection systems (NIDS). The proposed framework focuses on poisoning and evasion attacks and tries to combine these attacks. We evaluate the proposed framework on three CIC-IDS2017, CIC-IDS2018, and CIC-UNSW-NB15 datasets. Hesamodin Mohammadian, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
PST | 3 |
| 2024 | A review of Machine Learning (ML)-based IoT security in healthcare: A dataset perspective
Euclides Carlos Pinto Neto, Sajjad Dadkhah, Somayeh Sadeghi, Heather Molyneaux, Ali A. Ghorbani 0001 |
Comput. Commun. | 5 |
| 2024 | Detecting Distributed Denial-of-Service (DDoS) attacks that generate false authentications on Electric Vehicle (EV) charging infrastructureabstractIn recent years, smart grid-based Electric Vehicle (EV) charging systems have increasingly faced vulnerabilities to Distributed Denial of Service (DDoS) attacks, especially through malicious authentication failures. These attacks typically involve monopolizing the Grid Server (GS), thereby hindering the authentication process for legitimate EVs. Despite the severity of this issue, no research (to the best of our knowledge) has focused on detecting DDoS attacks exploiting weaknesses in EV authentication. This study introduces a DDoS attack detection model specifically designed for EV authentication. The approach involves developing a machine learning model involving unique feature selection and combination. The proposed approach has been evaluated using a new DDOS attack dataset. The model is engineered to optimize feature combination, aiming for high sampling resolution, minimal information loss, and robust performance under 16 distinct attack scenarios. The feature combination used in this study shows improved accuracy over traditional DDoS detection methods based on access time variation while minimizing information loss. Yoonjib Kim, Saqib Hakak, Ali A. Ghorbani 0001 |
Comput. Secur. | 3 |
| 2024 | IoT-PRIDS: Leveraging packet representations for intrusion detection in IoT networksabstractThe Internet of Things (IoT) devices have been integrated into almost all everyday applications of human life such as healthcare, transportation and agriculture. This widespread adoption of IoT has opened a large threat landscape to computer networks, leaving security gaps in IoT-enabled networks. These resource-constrained devices lack sufficient security mechanisms and become the weakest link in our in computer networks and jeopardize systems and data. To address this issue, Intrusion Detection Systems (IDS) have been proposed as one of many tools to mitigate IoT related intrusions. While IDS have proven to be a crucial tools for threat detection, their dependence on labeled data and their high computational costs have become obstacles to real life adoption. In this work, we present IoT-PRIDS, a new framework equipped with a host-based anomaly-based intrusion detection system that leverages “packet representations” to understand the typical behavior of devices, focusing on their communications, services, and packet header values. It is a lightweight non-ML model that relies solely on benign network traffic for intrusion detection and offers a practical way for securing IoT environments. Our results show that this model can detect the majority of abnormal flows while keeping false alarms at a minimum and is promising to be used in real-world applications. Alireza Zohourian, Sajjad Dadkhah, Heather Molyneaux, Euclides Carlos Pinto Neto, Ali A. Ghorbani 0001 |
Comput. Secur. | 5 |
| 2024 | Transferability of Machine Learning Algorithm for IoT Device Profiling and IdentificationabstractThe lack of appropriate cyber security measures deployed on Internet of Things (IoT) makes these devices prone to security issues. Consequently, the timely identification and detection of these compromised devices become crucial. Machine learning (ML) models which are used to monitor devices in a network have made tremendous strides. However, most of the research in profiling and identification uses the same data for training and testing. Hence, a slight change in the data renders most learning algorithms to work poorly. In this article, we study a transferability approach based on the concept of transductive transfer learning for IoT device profiling and identification. Notably, this type of transfer learning works by explicitly assigning labels to the test data in the target domain by using the test feature space in the target domain, with training data from the source domain. Specifically, we propose a three-component system comprising: 1) the device type identification; 2) the vulnerability assessment; and 3) the visualization module. The device type identification component uses the underlying concept of transductive transfer learning where the trained model is transferred to a remote lab for testing. A variety of ML models are evaluated with respect to accuracy, precision, recall, and F1-score in order to determine which are the most suitable for the proposed transferability profiling. Furthermore, the vulnerability of the predicted device type is also assessed by using three vulnerability databases: 1) Vulners; 2) National Vulnerability Database (NVD); and 3) IBM X-Force. Finally, the results from the vulnerability assessment are visualized and displayed on a dashboard. Priscilla Kyei Danso, Sajjad Dadkhah, Euclides Carlos Pinto Neto, Alireza Zohourian, Heather Molyneaux, Rongxing Lu, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 7 |
| 2024 | Area in circle: A novel evaluation metric for object detection
Xichen Zhang, Roozbeh Razavi-Far, Haruna Isah, Amir David, Griffin Higgins, Rongxing Lu, Ali A. Ghorbani 0001 |
Knowl. Based Syst. | 7 |
| 2024 | The Largest Social Media Ground-Truth Dataset for Real/Fake Content: TruthSeekerabstractAutomatic detection of fake content in social media such as Twitter is an enduring challenge. Technically, determining fake news on social media platforms is a straightforward binary classification problem. However, manually fact-checking even a small fraction of daily tweets would be nearly impossible due to the sheer volume. To address this challenge, we crawled and crowd-sourced one of the most extensive ground-truth tweet datasets. Utilizing Politifact and expert labeling as a base, it contains more than 180 000 labels from 2009 to 2022, creating five-and three-label classification using Amazon Mechanical Turk. We utilized multiple levels of validation to ensure an accurate ground-truth benchmark dataset. Then, we created and implemented numerous machine learning and deep learning algorithms, including different variations of bidirectional encoder representations from transformers (BERT)-based models and classical machine learning algorithms on the data to test the accuracy of real/fake tweet detection with both categories. Then, determining which versions gave us the highest result metrics. Further analysis is performed on the dataset by explicitly utilizing the DBSCAN text clustering algorithm combined with the YAKE keyword creation algorithm to determine topics’ clustering and relationships. Finally, we analyzed each user in the dataset, determining their bot score, credibility score, and influence score for a better understanding of what type of Twitter user posts, their influence with each of their tweets, and if there were any underlying patterns to be drawn from each score concerning the truthfulness of the tweet. The experiment’s results illustrated profound improvement for models dealing with short-length text in solving a real-life classification problem, such as automatically detecting fake content in social media. Sajjad Dadkhah, Xichen Zhang, Alexander Gerald Weismann, Amir Firouzi, Ali A. Ghorbani 0001 |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2024 | Social Alignment Contagion in Online Social NetworksabstractResearchers have already observed social contagion effects in both in-person and online interactions. However, such studies have primarily focused on users’ beliefs, mental states, and interests. In this article, we expand the state of the art by exploring the impact of social contagion on social alignment, i.e., whether the decision to socially align oneself with the general opinion of the users on the social network is contagious to one’s connections on the network or not. The novelty of our work in this article includes: 1) unlike earlier work, this article is among the first to explore the contagiousness of the concept of social alignment on social networks; 2) our work adopts an instrumental variable approach to determine reliable causal relations between observed social contagion effects on the social network; and 3) our work expands beyond the mere presence of contagion in social alignment and also explores the role of population heterogeneity on social alignment contagion. Based on the systematic collection and analysis of data from two large social network platforms, namely, Twitter and Foursquare, we find that a user’s decision to socially align or distance from social topics and sentiments influences the social alignment decisions of their connections on the social network. We further find that such social alignment decisions are significantly impacted by population heterogeneity. Amin Mirlohi, Jalehsadat Mahdavimoghaddam, Jelena Jovanovic 0001, Feras N. Al-Obeidat, Mehdi Khani, Ali A. Ghorbani 0001, Ebrahim Bagheri |
IEEE Trans. Comput. Soc. Syst. | 6 |
| 2024 | MEFaND: A Multimodel Framework for Early Fake News DetectionabstractAlongside social media platforms’ rise in popularity, fake news circulation has increased, highlighting the need for more practical methods to detect this phenomenon. The constantly evolving format of fake news makes it difficult for approaches that rely on a single modality of news to generalize the different types of false news. Furthermore, earlier approaches require extensive propagation data to determine the veracity of news, which can be challenging to collect in the early stages of news dissemination. Thus, we propose a multimodal early fake news detection approach that leverages latent insights into both news content and propagation knowledge. We design a multimodule architecture using graph neural networks (GNNs) to represent edge-enhanced and node-enhanced propagation graphs and bidirectional encoder representations from transformers (BERTs) to generate contextualized representations of news content. Our approach tackles the challenge of early detection in a more realistic scenario, accessing early propagation data in a single social media post and short-length news content. Moreover, we conduct comprehensive studies on user characteristics using statistical techniques to identify attributes with strong discriminative capability for identifying false news. We also analyse temporal and structural properties of fake news propagation graphs to demonstrate distinguishable patterns of false and real news behavior. Our model outperforms several state-of-the-art methods, achieving an impressive F1-score of 99% and 96% on two public datasets. The individual contribution of various components in our model to the final performance is also measured, which can be insightful for future research on multimodal false news detection. Asma Sormeily, Sajjad Dadkhah, Xichen Zhang, Ali A. Ghorbani 0001 |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2024 | Multimodal Fake News Analysis Based on Image-Text SimilarityabstractWith the fast and extensive development of computer vision techniques, multimodal analyses are utilized more frequently for online fake news detection. To better understand the image–text relationship and its role in fake news detection, in this article, we proposed and evaluated four image–text similarities, namely, textual similarity, semantic similarity, contextual similarity, and post-training similarity. The textual and semantic similarities indicate the original image–text similarities in terms of the text information and image caption information. The contextual similarity reflects the image–text similarity in the format of meaningful named entities. The post-training similarity demonstrates how image–text similarity involves before and after a fake news detection model is trained. By evaluating the proposed similarity measurements on three real-world datasets, we find that fake news image–text similarity is higher than real news image–text similarity in most of the cases. Furthermore, the comparison of models’ performance further validates the significance of visual information in online fake news detection. These findings may be considered as the fundamental logic to explain the original purpose of fake news creation and can be used as influential features for improving models’ performance in the future. Xichen Zhang, Sajjad Dadkhah, Alexander Gerald Weismann, Mohammad Amin Kanaani, Ali A. Ghorbani 0001 |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2024 | Evaluation Framework for Electric Vehicle Security Risk AssessmentabstractElectric Vehicles (EVs) seem promising for future transportation to solve environmental concerns and energy management problems. According to Reuters, global car makers plan to invest over half a billion in more efficient and intelligent EVs and batteries. However, there are several challenges in EV mass production, including cybersecurity. Due to the cyber-physical nature of EVs and charging stations, their security and trustworthiness are ongoing challenges. In this study, we identify gaps in the security profiling of EVs and categorize them into five components: 1) charging station security, 2) information privacy, 3) software security, 4) connected vehicle security, and 5) autonomous driving security. Our study provides a comprehensive analysis of identified vulnerabilities, threats, challenges and attacks for different EV security aspects, along with their possible surface/subsurface and countermeasures. We develop a comprehensive security risk assessment framework by first using EV security profiles and mapping identified vulnerabilities to a well-known threat model, STRIDE. Then, we classify the risk levels associated with each vulnerability by setting ground criteria for the impact and likelihood of the threats. Finally, we validate our risk assessment framework by applying the same criteria to eight real-world EV attack scenarios. As a result, researchers can adapt the proposed risk assessment framework to discover threats and assess their risks in EVs and charging station ecosystems. Soheil Shirvani, Yaser Baseri, Ali A. Ghorbani 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2024 | CapsRule: Explainable Deep Learning for Classifying Network AttacksabstractDespite the potential deep learning (DL) algorithms have shown, their lack of transparency hinders their widespread application. Extracting if-then rules from deep neural networks is a powerful explanation method to capture nonlinear local behaviors. However, existing rule extraction methods suffer from inefficiency, incomprehensibility, infidelity, and not scaling well. Concerning security applications, they are not optimized regarding the decision boundary, data types and ranges, classification tasks, and dataset size. In this article, we propose CapsRule, an effective and efficient rule-based DL explanation method dedicated to classifying network attacks. It extracts high-fidelity rules from the feed-forward capsule network that explains how an input sample is classified. Using precomputed coupling coefficients, the training phase overlaps the rule extraction process to increase efficiency. The activation vector of a capsule can represent semantic intelligence about the attributes of the input sample. The rules extracted from CapsRule address the major concerns of network attack detection. The rules: 1) approximate the nonlinear decision boundary of the underlying data; 2) reduce the number of false positives significantly; 3) increase transparency; and 4) help find errors and noise in the data. We evaluate CapsRule on the CICDDoS2019 dataset that contains over a million of the most advanced Distributed Denial-of-Service (DDoS) attacks. The extensive evaluation shows that it generates accurate, high-fidelity, and comprehensible rules. CapsRule achieves an average accuracy of 99.0% and a false positive rate of 0.70% for reflection- and exploitation-based attacks. We verify that the learned features from the rulesets match our domain-specific knowledge. They also help find flaws in the dataset generation process and erroneous patterns caused by attack simulators. Samaneh Mahdavifar, Ali A. Ghorbani 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2024 | A Graph Learning-Based Approach for Lateral Movement DetectionabstractLateral movement, a crucial phase in the Advanced Persistent Threat (APT) life cycle, refers to a strategy employed by adversaries to traverse horizontally within a network. The aim is to gain access to various systems or resources, thereby expanding their control and potential access to valuable targets. Detecting these attacks becomes challenging for conventional detection systems due to various factors, including the complexity of pathways, the mimicking of legitimate user behavior by attackers, and limited network visibility. To address these challenges, advanced detection techniques are required to effectively and dynamically analyze multiple features within the interconnected structure of the network. This paper introduces an innovative approach to detect malicious lateral movement paths by leveraging authentication events and graph learning techniques. The proposed method involves constructing a heterogeneous graph, and employing DeepWalk for node embedding. By combining node embedding features with the temporal information of authentication events, feature vectors are generated for each authentication request. These features are then used to train multiple machine learning-based classifiers to detect malicious lateral movement paths. Furthermore, to assess the model’s performance in a more realistic scenario, a series of additional experiments were conducted. These experiments provided further validation of the model’s robustness and its capability for forward prediction. Mahdi Rabbani, Leila Rashidi, Ali A. Ghorbani 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Securing Substations with Trust, Risk Posture, and Multi-Agent Systems: A Comprehensive ApproachabstractThe Smart Grid is an IT-integrated power grid that generates, transmits, and distributes electricity to households and businesses. The substation is a crucial element of the Smart Grid’s operation, which adjusts voltages during the entire process. The integration of IT has increased in the substation’s attack surfaces. Sophisticated attacks such as the Pipeline APT contain multi-protocol modules for various devices. Performance constraints make substations a unique case; hence it is challenging to implement encryption and intrusion detection systems. We believe trust can tackle this problem. We present an improved trust model that detects protocol-based attacks toward an IED/SCADA HMI. This model is included within a multi-agent-based trust management system that computes the substation’s risk posture. Our proposed design was implemented in a Docker-based testbed environment with a SOC-influenced dashboard to provide real-time updates. The implementation was subjected to three attack scenarios: external attack, internal attack from compromised SCADA HMI, and internal attack from a compromised non-trusted IED. We observed that our model was robust against all attacks except for the baseline replay and delay response attacks. Detecting these attacks will be considered for future work as well as trust transferability. Our institute’s website provides a publicly available dataset containing captures of our MAS testbed. Kwasi Boakye-Boateng, Ali A. Ghorbani 0001, Arash Habibi Lashkari |
PST | 2 |
| 2023 | UCreDiSSiT: User Credibility Measurement incorporating Domain interest, Semantics in Social interactions, and Temporal factorabstractOnline social media platforms provide a range of benefits, such as conversation and information sharing, as well as marketing and advertising for businesses. However, these platforms are soft targets for bad actors to disseminate misinformation or rumors. Untrustworthy content on social media poses a great threat to truth since any user can produce unverified online content to gain popularity. It has been realized that fake information and accounts create a great deal of confusion. To determine user credibility and promote reliable information, we propose UCreDiSSiT method, which incorporates a user's domain of interest, social relations, and temporal features. The suggested approach draws inspiration from earlier works but differs in weighing factors, formalizing factors, and addressing extreme circumstances in large-scale deployment. The experiments are conducted on real-time users' data on Twitter. Our results demonstrate the effectiveness of the proposed method. Rashid Hussain Khokhar, Sajjad Dadkhah, Xichen Zhang, Ali A. Ghorbani 0001 |
PST | 5 |
| 2023 | DDoS Attack Dataset (CICEV2023) against EV Authentication in Charging InfrastructureabstractDenial-of-Service (DoS) or Distributed DoS (DDoS) attacks are on the rise in smart grid-based electric vehicle (EV) charging facilities. To develop effective mitigation solutions against such attacks, a dataset containing different attack scenarios is of vital importance. There is no such comprehensive dataset available as of now. To fill this research gap, in this work, we have created a new dataset, namely CICEV2023, which contains four different attack scenarios on EVs within smart grid infrastructure. To achieve this, we developed a simulator that establishes an authentication protocol on EV charging infrastructure and launches DDoS attacks related to EV authentication. Yoonjib Kim, Saqib Hakak, Ali A. Ghorbani 0001 |
PST | 3 |
| 2023 | Securing Supply Chain: A Comprehensive Blockchain-based Framework and Risk AssessmentabstractCyber attacks on data, networks, and software have become a crucial problem for supply chain management due to the globalization, decentralization, and digitalization. Blockchain provides an ideal platform for business stakeholders to address issues with modern supply chains, such as traceability, interoperability, and transparency. However, adopting blockchain is challenging as it introduces risks to the supply chain.In this paper, we propose a blockchain-based framework to manage the supply chain and enable a trust-based feedback mechanism, fostering trust among supply chain stakeholders. Moreover, we perform a qualitative risk assessment for adopting blockchain in the supply chain management process, based on standards provided by the National Institute of Standards and Technology (NIST). Our assessment shows that if a threat is imminent, the risk associated with the consensus, limited fixed verification capacity, and inter-autonomous system communication is high in a blockchain-based supply chain that uses proof of authority. Leila Rashidi, Windhya Hansinie Rankothge, Hesamodin Mohammadian, Rashid Hussain Khokhar, Brian Frei, Shawn Ellis, Lago Freitas, Ali A. Ghorbani 0001 |
PST | 8 |
| 2023 | Evaluating Label Flipping Attack in Deep Learning-Based NIDS
Hesamodin Mohammadian, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
SECRYPT | 3 |
| 2022 | Privacy-preserving Worker Selection in Mobile Crowdsensing over Spatial-temporal ConstraintsabstractWorker selection is one of the most fundamental problems in Mobile Crowdsensing (MCS) applications. In this paper, we formulate a practical worker selection scenario in MCS services where the selected workers should meet both the spatial and temporal constraints. To protect participants’ (both the task requestor and the workers) personal information from being disclosed, we design a privacy-preserving worker selection scheme based on the Symmetric Homomorphic Encryption (SHE) technique. Besides, we devise a pre-filtering process to further increase the efficiency of the worker assignment process. Security analysis shows that our proposed scheme can achieve the desirable security properties. In addition, extensive experiments are conducted to validate the effectiveness of the proposed scheme. Xichen Zhang, Rongxing Lu, Songnian Zhang, Suprio Ray, Ali A. Ghorbani 0001 |
ICC | 5 |
| 2022 | Evaluating Deep Learning-based NIDS in Adversarial Settings
Hesamodin Mohammadian, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
ICISSP | 3 |
| 2022 | Towards the Development of a Realistic Multidimensional IoT Profiling DatasetabstractThe Internet of Things (IoT) is an emerging technology that enables the development of low-cost and energy-efficient IoT devices across various solutions from smart cities to healthcare domains. With such a complex and heterogeneous instance of IoT devices and their applications, numerous challenges arise in both device management and security concerns. Thus, it is essential to develop intelligent IoT identification/profiling and intrusion detection components that are tailored to IoT applications. Such systems require a realistic and multidimensional reference IoT dataset for training and evaluation. Device identification/profiling ensures the authenticity of the devices attached to the IoT network and environment which can be achieved by fingerprinting a device. Since fingerprinting is mostly examined by device network flows and device local attributes, we have proposed this study to intelligently recognize machine-to-machine communication and identify each device properly. In this paper, we analyzed the behaviour of 60 IoT devices during experiments conducted in our lab setup at the Canadian Institute for Cybersecurity (CIC). Our IoT devices include WiFi, ZigBee, and Z-Wave devices. We collected data from each device in four stages: powered on, idle, active, and interactions. Besides these stages, different scenario experiments were conducted using a microcosm of devices to simulate the network activity of a smart home. Additionally, we have generated two attack datasets, namely flood denial-of-service attack and RTSP brute-force attack. Lastly, we implement an extensive case study on the transferability of the RF classifier and train our model with the dataset from our lab, transfer the model to the dataset from a different lab and test the trained model on their dataset. This paper’s dataset materials are available on the CIC dataset page under the CIC IoT dataset 20221. Sajjad Dadkhah, Hassan Mahdikhani, Priscilla Kyei Danso, Alireza Zohourian, Kevin Anh Truong, Ali A. Ghorbani 0001 |
PST | 6 |
| 2022 | Collaborative DDoS Detection in Distributed Multi-Tenant IoT using Federated LearningabstractNowadays, the Internet of Things (IoT) has attracted much attention from the industry, and new initiatives are expected to be developed in the next decade. IoT is establishing a globally connected sensor network in which many devices are connected to the Internet generating large amounts of data. Conversely, many challenges need to be overcome to enable efficient and secure IoT applications (e.g., interoperability, security, standards, and server technologies). Furthermore, edge computing presents a paramount role in the diverse range of IoT applications. In this sense, processing sensitive data for different tenants (e.g., e-health and smart cities applications) requires transactions to be protected and isolated from different flows. Thereupon, different tenants can be targeted by Distributed Denial of Service (DDoS) attacks. However, attacks performed against a tenant remain unknown to others, preventing the improvement of detection and mitigation capabilities for DDoS attacks. The main obstacle in this collaboration relies on maintaining privacy in a multi-tenant environment while sharing the characteristics of attacks faced in the past. In this paper, we propose a collaborative DDoS detection and classification approach for distributed multi-tenant IoT environments using Federated Learning. This approach enables multiples tenants to collaboratively enhance their DDoS detection and classification capabilities across all edge nodes while maintaining their privacy. To accomplish this, tenants train deep learning instances on locally scaled traffic data and share the model parameters with other tenants. This strategy enables safer IoT operations and can be adopted in different applications. The experiments performed on a simulated environment considered the CICD-DoS2019 dataset and showed that the proposed approach can classify different DDoS attacks types with over 84.2% accuracy. The results demonstrate that collaborative DDoS detection enhances tenant protection compared to single detection. Euclides Carlos Pinto Neto, Sajjad Dadkhah, Ali A. Ghorbani 0001 |
PST | 3 |
| 2022 | Efficient and Privacy-preserving Worker Selection in Mobile Crowdsensing Over Tentative Future TrajectoriesabstractMobile Crowdsourcing (MCS) is a newly-emerged sensing paradigm where a group of workers is selected to collect and share real-time data for a particular task. With the recent advances of Internet of Things (IoTs), cloud computing, and 5G network, MCS has drawn great attention in recent years. Worker selection is one of the most fundamental problems in MCS, as the selected workers’ qualifications play a significant role in the service quality. In this paper, by extending the research scope of previous literature, we formulate a novel worker selection problem in MCS that incorporates spatial-temporal constraints over workers’ tentative future trajectories. Specifically, each worker is required to submit a tentative future trajectory in advance and the MCS platform only selects qualified workers who meet both the spatial and temporal constraints. To increase the efficiency of worker selection, we propose a hybrid indexing approach to efficiently index workers’ spatial-temporal information by combining MX-CIF quadtree and Interval tree. Besides, we design a greedy algorithm, which considers both the reliability of the selected workers and the overall budget at the same time. Furthermore, to protect workers’ sensitive spatial-temporal information from being disclosed to untrusted parties, we design a privacy-preserving technique by transferring workers’ real spatial-temporal information to the approximate data with restricted information. Security analysis shows that the proposed solution is privacy-preserving. Extensive experiments are conducted, and the results demonstrate that our scheme outperforms the baseline methods. Xichen Zhang, Songnian Zhang, Suprio Ray, Ali A. Ghorbani 0001 |
PST | 4 |
| 2022 | Data breach: analysis, countermeasures and challenges
Xichen Zhang, Mohammad Mehdi Yadollahi, Sajjad Dadkhah, Haruna Isah, Duc-Phong Le, Ali A. Ghorbani 0001 |
Int. J. Inf. Comput. Secur. | 6 |
| 2022 | FedSky: An Efficient and Privacy-Preserving Scheme for Federated Mobile CrowdsensingabstractMobile crowdsensing (MCS) is a newly emerged sensing paradigm, where a large group of mobile workers collectively sense and share data for real-time services. However, one major problem that hinders the further development of MCS is the potential leakage of workers’ data privacy. In this article, we integrate federated learning (FL) with MCS and introduce a novel sensing system, called federated MCS (F-MCS). In F-MCS, the workers can optimize the global model while keeping all the sensitive training data locally, thus ensuring their data privacy. Nevertheless, there are still two major issues in F-MCS. The first issue is that in F-MCS services, the workers are heterogeneous in terms of computational capacities and data resources. Hence, qualified workers should be appropriately selected to improve the efficiency of the training process. The second issue is that F-MCS is across-deviceFL system, where the platform will finally get the global model after multiple training rounds. However, most privacy-preserving techniques are designed forcross-siloFL platforms, which cannot be applied to real-world F-MCS scenarios. To tackle the above problems, in this article, we propose a privacy-preserving scheme for F-MCS, namely, FedSky. Mainly, by extending the classic FedAvg algorithm, FedSky selects qualified workers based on the constrained group skyline (CG-skyline) and securely aggregates model updates based on the homomorphic encryption technique. Comprehensive security analysis demonstrates the privacy preservation of FedSky. Extensive experiments are conducted on an image classification task, where the comparison results validate the proposed scheme’s efficiency and effectiveness. Xichen Zhang, Rongxing Lu, Jun Shao 0001, Fengwei Wang, Hui Zhu 0001, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 6 |
| 2022 | Preventing proof-of-work mining attacks
Hamid Azimy, Ali A. Ghorbani 0001, Ebrahim Bagheri |
Inf. Sci. | 2 |
| 2022 | Achieving Efficient Secure Deduplication With User-Defined Access Control in CloudabstractCloud storage as one of the most important services of cloud computing which significantly facilitates cloud users to outsource their data to the cloud for storage and share them with authorized users. In cloud storage, secure deduplication has been widely investigated as it can eliminate the redundancy over the encrypted data to reduce storage space and communication overhead. Regarding the security and privacy, many existing secure deduplication schemes generally focus on achieving the following properties: data confidentiality, tag consistency, access control, and resistance to brute-force attacks. However, as far as we know, none of them can achieve these four requirements at the same time. To overcome this shortcoming, in this article, we propose an efficient secure deduplication scheme that supports user-defined access control. Specifically, by allowing only the cloud service provider to authorize data access on behalf of data owners, our scheme can maximally eliminate duplicates without violating the security and privacy of cloud users. Detailed security analysis shows that our authorized secure deduplication scheme achieves data confidentiality and tag consistency while resisting brute-force attacks. Furthermore, extensive simulations demonstrate that our scheme outperforms the existing competing schemes, in terms of computational, communication and storage overheads as well as the effectiveness of deduplication. Xue Yang 0003, Rongxing Lu, Jun Shao 0001, Xiaohu Tang 0004, Ali A. Ghorbani 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | A Survey on IoT Profiling, Fingerprinting, and IdentificationabstractThe proliferation of heterogeneous Internet of things (IoT) devices connected to the Internet produces several operational and security challenges, such as monitoring, detecting, and recognizing millions of interconnected IoT devices. Network and system administrators must correctly identify which devices are functional, need security updates, or are vulnerable to specific attacks. IoT profiling is an emerging technique to identify and validate the connected devices’ specific behaviour and isolate the suspected and vulnerable devices within the network for further monitoring. This article provides a comprehensive review of various IoT device profiling methods and provides a clear taxonomy for IoT profiling techniques based on different security perspectives. We first investigate several current IoT device profiling techniques and their applications. Next, we analyzed various IoT device vulnerabilities, outlined multiple features, and provided detailed information to implement profiling algorithms’ risk assessment/mitigation stage. By reviewing approaches for profiling IoT devices, we identify various state-of-the-art methods that organizations of different domains can implement to satisfy profiling needs. Furthermore, this article also discusses several machine learning and deep learning algorithms utilized for IoT device profiling. Finally, we discuss challenges and future research possibilities in this domain. Miraqa Safi, Sajjad Dadkhah, Farzaneh Shoeleh, Hassan Mahdikhani, Heather Molyneaux, Ali A. Ghorbani 0001 |
ACM Trans. Internet Things | 6 |
| 2021 | Verification Based Scheme to Restrict IoT AttacksabstractIn recent years, with the increased usage of the Internet of Things (IoT) devices, cyber-attacks have become a serious threat over the Internet. These devices have low memory capacity and processing power, which makes them easy targets for attackers. The research community has proposed different approaches to deal with emerging variants of attacks on IoT devices using various machine learning techniques. However, these approaches rely heavily on the classifier’s categorization of a given record while ignoring its confidence. This paper proposes a verification-based scheme to reject IoT attacks by utilizing the classifier’s confidence. At the same time, existing studies are evaluated using traditional cross-validation approaches (e.g., k-fold), thus, not tested against unknown attacks. We propose using the leave-one-attack-out (LOAO) cross-validation scheme to evaluate the generalizability of the application to unknown attacks. The experiments are performed on Med BIoT, a publicly available dataset consisting of three IoT attacks. The system’s robustness is evaluated in terms of Receiver Operating Curves (ROC) and Equal Error rates (EERs). The results indicate a lower false-positive rate of 12.6% using the proposed verification-based approach in comparison to k-fold cross-validation. Barjinder Kaur, Sajjad Dadkhah, Pulei Xiong, Shahrear Iqbal, Suprio Ray, Ali A. Ghorbani 0001 |
BDCAT | 6 |
| 2021 | Spatio-Temporal Similarity based Privacy-Preserving Worker Selection in Mobile CrowdsensingabstractAs one of the most fundamental problems in mobile crowdsensing (MCS), worker selection has drawn significant attention in recent years. However, very few studies consider the workers' spatio- and temporal-coverage for the sensing task. In this paper, we propose a novel top-k worker selection scheme such that the MCS platform can select qualified workers in terms of spatio-temporal similarity. Besides, we design a novel privacy-preserving approach for protecting participants' spatio-temporal information based on the modified Paillier encryption technique. Detailed security analysis showed that the task re-questor's temporal information and the workers' spatio-temporal information are preserved and will not be revealed to any other parties. Extensive experiments are conducted, and the results demonstrate that our scheme outperforms the baseline methods regarding the selection of reliable workers. Xichen Zhang, Rongxing Lu, Suprio Ray, Jun Shao 0001, Ali A. Ghorbani 0001 |
GLOBECOM | 5 |
| 2021 | A Novel Trust Model In Detecting Final-Phase Attacks in SubstationsabstractA substation’s security is paramount because it is an integral part of the Smart Grid for the transmission and distribution of electricity. Advanced persistent threats (APTs) have become the bane of the substation because they can remain undetected for a period until final attacks are launched. A lot of existing techniques may not be real-time enough to detect these final attacks. Trust, even though less investigated, can be used to tackle these attacks. In this paper, we present a trust model designed specifically for the Modbus communication protocol that can detect final attacks from APTs when a substation is compromised. This model is formed from the perspective of the substation device and was successfully tested on two publicly available Modbus datasets under three testing scenarios. The external test, the internal test, and the internal test with IP-MAC blacklisting. The first test assumes attackers’ IP, and MAC addresses are not part of the substation network, and the other two assume otherwise. Our model detected the attacks within each dataset and also revealed the attack behaviour within the two datasets. Our model can also be extended to other protocols, and this has been marked for future work. Kwasi Boakye-Boateng, Ali A. Ghorbani 0001, Arash Habibi Lashkari |
PST | 2 |
| 2021 | User Profiling on Universal Data Insights tool on IBM Cloud Pak for SecurityabstractUser profiling is one of the most important research topics where organizations endeavour to establish profiles of user activities to detect or predict potential abnormal behaviours. Previous researches have mainly focused on detecting and identifying static activities through social media. A universal analysis based on streaming settings to monitor user activities continuously is missing. This paper proposes a framework for user profiling based on UDI platforms to address this issue. Our framework consists of three main steps: simulating realistic scenarios for user activities, proposing and extracting potential features, and applying machine learning models on simulated datasets. Our experimental results show that selected machine learning algorithms can distinguish most abnormal behaviours correctly. LODA, RRCF, and LSCP algorithms achieve the highest performance among all algorithms. Tree-based algorithms such as Isolation Forest acquire the best results when considering small datasets and speed. Furthermore, machine learning algorithms’ performance demonstrates the high quality of our simulated datasets. Farzaneh Shoeleh, Masoud Erfani, Saeed Shafiee Hasanabadi, Duc-Phong Le, Arash Habibi Lashkari, Adam Frank, Ali A. Ghorbani 0001 |
PST | 7 |
| 2021 | Towards Query-efficient Black-box Adversarial Attack on Text Classification ModelsabstractRecent work has demonstrated that modern text classifiers trained on Deep Neural Networks are vulnerable to adversarial attacks. There is not sufficient study on text data in comparison to the image domain. The lack of investigation originates from the challenges that authors confront in the NLP domain. Despite being extremely prosperous, most adversarial attacks in the text domain ignore the overhead they induced on the victim model. In this paper, we propose a Query-efficient Black-box Adversarial Attack on text data that tries to attack a textual deep neural network by considering the amount of overhead that it may produce. We show that the proposed attack is as powerful as the state-of-the-art adversarial attacks while requiring fewer queries to the victim model. The evaluation of our method proves the promising results. Mohammad Mehdi Yadollahi, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
PST | 3 |
| 2021 | Classifying and clustering malicious advertisement uniform resource locators using deep learningabstractAbstract Malicious online advertisement detection has attracted increasing attention in recent years in both academia and industry. The existing advertising blocking systems are vulnerable to the evolution of new attacks and can cause time latency issues by analyzing web content or querying remote servers. This article proposes a lightweight detection system for advertisement Uniform resource locators (URLs) detection, depending only on lexical‐based features. Deep learning algorithms are used for online advertising classification. After optimizing the deep neural network architecture, our proposed approach can achieve satisfactory results with false negative rate as low as 1.31%. We also design a novel unsupervised method for data clustering. With the implementation of AutoEncoder for feature preprocessing and t‐distributed stochastic neighbor embedding for clustering and visualization, our model outperforms other dimensionality reduction algorithms by generating clear clusterings for different URL families. Xichen Zhang, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
Comput. Intell. | 3 |
| 2021 | Using Reduced Paths to Achieve Efficient Privacy-Preserving Range Query in Fog-Based IoTabstractThe fog computing architectural model has recently seen advances with respect to bandwidth and latency issues. However, since fog devices are deployed at the network edge and are not fully trustable, there are still security and privacy challenges. In this article, aiming at improving both communication efficiency and privacy protection, we propose a new efficient and privacy-preserving range query scheme in fog-based Internet of Things (IoT). We, first, introduce a new decomposition technique to efficiently interpret a given range query [L, U], where 0 ≤ L ≤ U ≤ n - 1, as a form of inverted reduced path strings. Then, the symmetric homomorphic encryption (SHE) scheme is employed to encrypt the reduced paths and hand them over securely through a fog node to the IoT devices. This technique enables a query user to launch a privacy-preserving continuous or noncontinuous range query and receive a homomorphically aggregated encrypted response with an improved O(log2n) communication efficiency. The detailed security analysis shows that our proposed scheme is privacy preserving. In addition, extensive performance evaluations are also conducted, and the results demonstrate that our proposed scheme is by far more efficient than those previously reported schemes in terms of computational overhead and communication complexity. Hassan Mahdikhani, Rongxing Lu, Jun Shao 0001, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 4 |
| 2021 | Continuous Probabilistic Skyline Query for Secure Worker Selection in Mobile CrowdsensingabstractWorker selection is always one of the most fundamental problems in mobile crowdsensing (MCS), since the reliability of workers' sensing data is hugely significant to the service quality. In the worker selection process, it is inevitable for the workers to share some of their sensitive information. Consequently, numerous studies are conducted on the problem of privacy-preserving worker selection in MCS platforms. However, most of the existing methods focus on static and short-term situations. As a result, they are inapplicable to the highly dynamic environments where the MCS tasks are long term and the workers can continuously arrive at/leave the system. To solve these problems, in this article, we propose a privacy-preserving worker selection scheme based on the probabilistic skyline over sliding windows. Specifically, the proposed scheme can select reliable workers for each current sliding window in terms of working experience, expiry time, and trustability. Besides, we design an ElGamal encryption-based scheme for securely outsourcing and comparing workers' personal information without revealing their privacy. Detailed security analysis shows that the workers' sensitive information, e.g., working experience and trustability, are not revealed to any authorized parties during the process of MCS under our security model. Furthermore, extensive experiments on both real-world and simulated data sets demonstrate that our proposed scheme outperforms the baseline method in two application scenarios, i.e., 1) continuous worker arrival and 2) continuous worker departure. Xichen Zhang, Rongxing Lu, Jun Shao 0001, Hui Zhu 0001, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 5 |
| 2021 | On the causal relation between real world activities and emotional expressions of social media usersabstractAbstract Social interactions through online social media have become a daily routine of many, and the number of those whose real world (offline) and online lives have become intertwined is continuously growing. As such, the interplay of individuals' online and offline activities has been the subject of numerous research studies, the majority of which explored the impact of people's online actions on their offline activities. The opposite direction of impact—the effect of real‐world activities on online actions—has also received attention but to a lesser degree. To contribute to the latter form of impact, this paper reports on a quasi‐experimental design study that examined the presence of causal relations between real‐world activities of online social media users and their online emotional expressions. To this end, we have collected a large dataset (over 17K users) from Twitter and Foursquare, and systematically aligned user content on the two social media platforms. Users' Foursquare check‐ins provided information about their offline activities, whereas the users' expressions of emotions and moods were derived from their Twitter posts. Since our study was based on a quasi‐experimental design, to minimize the impact of covariates, we applied an innovative model of computing propensity scores. Our main findings can be summarized as follows: (a) users' offline activities do impact their affective expressions, both of emotions and moods, as evidenced in their online shared textual content; (b) the impact depends on the type of offline activity and if the user embarks on or abandons the activity. Our findings can be used to devise a personalized recommendation mechanism to help people better manage their online emotional expressions. Seyed Amin Mirlohi Falavarjani, Jelena Jovanovic 0001, Hossein Fani 0001, Ali A. Ghorbani 0001, Zeinab Noorian, Ebrahim Bagheri |
J. Assoc. Inf. Sci. Technol. | 4 |
| 2021 | Achieving Efficient and Privacy-Preserving Multi-Domain Big Data Deduplication in CloudabstractSecure data deduplication, as it can eliminate redundancies over encrypted data, has been widely developed in cloud storage to reduce storage space and communication overheads. Among them, the convergent encryption has been extensively adopted. However, it is vulnerable to brute-force attacks that can determine which plaintext in a message space corresponds to a given ciphertext. Many existing schemes have to sacrifice efficiency to resist brute-force attacks, especially for cross-domain deduplication, which is inevitably contrary to practical applications. Moreover, few existing schemes consider protecting the message equality information (i.e., whether two different ciphertexts correspond to an identical plaintext). To address the above challenges, in this paper, we propose an efficient and privacy-preserving big data deduplication scheme for a two-level multi-domain architecture. Specifically, by generating a random tag and a constant number of random ciphertexts for each data, our scheme not only ensures data confidentiality under multi-domain deduplication but also resists brute-force attacks. By allowing only the agent and cloud service provider to perform intra-deduplication and inter-deduplication, respectively, our scheme can protect the message equality information from disclosure as much as possible. Detailed security analysis shows that our scheme achieves privacy-preservation for both data content and the message equality information and data integrity while resisting brute-force attacks. Furthermore, extensive simulations demonstrate that our scheme significantly outperforms the existing competing schemes, especially the computational cost and the time complexity of the duplicate search. Xue Yang 0003, Rongxing Lu, Jun Shao 0001, Xiaohu Tang 0004, Ali A. Ghorbani 0001 |
IEEE Trans. Serv. Comput. | 5 |
| 2020 | Financial Fraud Detection using Deep Support Vector Data DescriptionabstractNowadays, most financial transactions are virtual all over the world. The rapid usage of credit cards and online transnational applications raises fraudulent activities using these services. So, fraud detection is one of the challenging real-world problems. One of the main challenges in fraud detection is imbalanced datasets, where there are very few cases of fraud in an extremely large amount of non-fraud samples. Also, the behavior of fraud changes frequently making the learning process for the state-of-the-art machine learning binary classifiers complicated. As a result, in this paper, we propose an efficient framework for fraud detection. Our framework consists of a novel preprocessing and subsampling step, which is followed by applying deep support vector data description for fraud detection. We provide a trend analysis based on the size of the training, test datasets, and performance of the model using Area Under the Receiver Operating Characteristic Curve(ROC-AUC) and Average Precision(AP) as metrics. Finally, based on results, our approach outperforms SVM and Random Forest as the state-of-the-art binary classifiers in different scenarios. It achieves a remarkable performance in terms of AP and ROC-AUC equal to 90% and 93%(Best results), respectively. Masoud Erfani, Farzaneh Shoeleh, Ali A. Ghorbani 0001 |
IEEE BigData | 3 |
| 2020 | Ensemble of Hierarchical Temporal Memory for Anomaly DetectionabstractHierarchical Temporal Memory (HTM) is a continuously learning algorithm derived from neuroscience that models spatial and temporal streaming data. It was demonstrated that HTM produces a good performance in predicting unusual patterns or anomaly detection in univariate datasets. In this paper, we deploy the HTM algorithm for the anomaly detection problem in multivariate datasets, which are more common in practical scenarios. We first investigate the implementation of HTM using multi-encoders for multiple variables and analyze its performance in different parameter settings. Then, we introduce a new framework for ensemble learning by using single-encoder HTMs as weak learners. We carried out experiments on public datasets in different dimensions. Our experimental results show that our new approach outperforms the multi-encoder implementation of the HTM algorithm. Farzaneh Shoeleh, Masoud Erfani, Duc-Phong Le, Ali A. Ghorbani 0001 |
DSAA | 4 |
| 2020 | Achieving Efficient and Privacy-Preserving Range Query in Fog-enhanced IoT with Bloom FilterabstractFog-enhanced Internet of Things (IoT), which can locally process data at the network edge for better response to the IoT field and pre-computation for further efficient process at the cloud side, has attracted substantial studies in recent years. However, as the fog device is not fully trustable at the network edge, more advancement in efficiency and privacy should be considered to persuade enterprises to migrate to fog and cloud environments. With this in mind, in this paper, we propose a new communication-efficient privacy-preserving range query in the fog-enhanced IoT. The proposed scheme is characterized by employing Paillier homomorphic cryptosystem and ingenious Bloom filter data structure for simultaneously achieving better privacy and higher efficiency in the count aggregation in a privacy-preserving range query scenario. More precisely, $(n+|E|)\log n$-bit communication efficiency can be achieved by our proposed scheme where $n, |E|$ are respectively the range size and the ciphertext size. Detailed security analysis shows that our proposed scheme really achieves the privacy preservation in the range query. Extensive experiments are conducted, and the results demonstrate the efficiency of our proposed scheme. Hassan Mahdikhani, Rongxing Lu, Yandong Zheng, Ali A. Ghorbani 0001 |
ICC | 4 |
| 2020 | Achieving O(log³n) Communication-Efficient Privacy-Preserving Range Query in Fog-Based IoTabstractThe advance of Internet-of-Things (IoT) techniques has promoted an increasing number of organizations to explore more mission-critical solutions. However, the response latency, bandwidth usage, and reliability are still challenging issues in the traditional IoT. To tackle these challenges, the fog-based IoT has become popular and the range query is one of the most frequently used operations in fog-based IoT, where given a range query, a fog node will return the aggregated data from IoT devices to the query user. Because the fog nodes are not fully trusted, there is a desire to design a privacy-preserving range query scheme in the fog-based IoT. However, most of existing privacy-preserving range query schemes are not efficient in terms of communication overhead, especially for a large-size range. Therefore, it is still a challenging issue to design a communication-efficient range query in fog-based IoT. Aiming at this challenge, in this article, we propose a new privacy-preserving range query scheme in the fog-based IoT. Specifically, we first devise an efficient homomorphic encryption scheme for maintaining data privacy and security in a range query. Then, we present a novel range decomposition technique to compile the range query, which can transform a given range query [L, U], where 0 ≤ L ≤ U ≤ n - 1, into a semi-triangular structure, and enable our proposed scheme to achieve O(log3n) communication efficiency. The detailed security analysis shows that our proposed scheme is really privacy preserving, and the extensive performance evaluation demonstrates that our proposed scheme is efficient in terms of low communication overhead and the computational cost. Hassan Mahdikhani, Rongxing Lu, Yandong Zheng, Jun Shao 0001, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 5 |
| 2020 | Secure and Efficient Probabilistic Skyline Computation for Worker Selection in MCSabstractThe rapid advance of the Internet of Things (IoT) has enabled a new paradigm of the sensing network, i.e., mobile crowdsensing (MCS). Primarily, in MCS systems, a crowd of participating mobile users, namely, workers, are allocated by the MCS platforms to outsource their sensory data for specific tasks. Obviously, the reliability of workers and the trustability of their sensing data play significant roles in the service quality, thus the worker selection becomes crucial for the success of MCS applications. However, due to either a large number of candidates or their dynamic natures, selecting reliable workers poses big challenges to the MCS platform. Evidently, workers' reputation-based characteristics, such as trustability and credibility, are also pivotal for the worker selection in MCS, but they were often neglected in previous literature. In this article, aiming at addressing the above challenges, we propose a new privacy-preserving worker selection scheme based on the probabilistic skyline computation technique. Specifically, our proposed scheme is characterized by: 1) assigning a trustability score to each worker based on his/her past performance without revealing his/her sensitive information and 2) efficiently selecting a subset of reliable workers for a particular task. Detailed security analysis shows that our proposed scheme can preserve workers' privacy. In addition, performance evaluations via extensive simulations are conducted, and the results also demonstrate its effectiveness and efficiency for reliable worker selection in MCS applications. Xichen Zhang, Rongxing Lu, Jun Shao 0001, Hui Zhu 0001, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 5 |
| 2020 | An overview of online fake news: Characterization, detection, and discussion
Xichen Zhang, Ali A. Ghorbani 0001 |
Inf. Process. Manag. | 2 |
| 2020 | DeNNeS: deep embedded neural network expert system for detecting cyber attacks
Samaneh Mahdavifar, Ali A. Ghorbani 0001 |
Neural Comput. Appl. | 2 |
| 2019 | On the causal relation between users' real-world activities and their affective processesabstractResearch in social network analytics has already extensively explored how engagement on online social networks can lead to observable effects on users' real-world behavior (e.g., changing exercising patterns or dietary habits), and their psychological states. The objective of our work in this paper is to investigate the flip-side and examine whether engaging in or disengaging from real-world activities would reflect itself in users' affective processes such as anger, anxiety, and sadness, as expressed in users' posts on online social media. We have collected data from Foursquare and Twitter and found that engaging in or disengaging from a real-world activity, such as frequenting at bars or stopping going to a gym, have direct impact on the users' affective processes. In particular, we report that engaging in a routine real-world activity leads to expressing less emotional content online, whereas the reverse is observed when users abandon a regular real-world activity. Seyed Amin Mirlohi Falavarjani, Ebrahim Bagheri, Ssu Yu Zoe Chou, Jelena Jovanovic 0001, Ali A. Ghorbani 0001 |
ASONAM | 5 |
| 2019 | Generating Phishing Emails Using Graph Database
Nasim Maleki, Ali A. Ghorbani 0001 |
ISPEC | 2 |
| 2019 | Competitive Selfish MiningabstractBitcoin mining is the process of generating new blocks in Bitcoin blockchain. This process is vulnerable to different types of attacks. One of the most famous attacks in this category is Selfish Mining, introduced by Eyal and Sirer [1] in 2014. This attack is essentially a strategy that a sufficiently powerful mining pool can follow to obtain more revenue than its fair share. This is a tempting attack to deploy because every pool is trying to increase its revenue and this is an excellent opportunity. However, in most of the works to date, the effect of only one selfish pool has been studied. This is an attempt to analyze selfish mining in a competitive environment, where there are more than one selfish miners in play. To do so, we created a Bitcoin network simulator and used it to simulate different configurations of miners to be able to address this problem. In short, our finding shows that in almost all of the configurations, with the presence of a more powerful selfish miner, selfish mining actually decreases the revenue of the weaker selfish miners and also helps the stronger selfish miner. Hamid Azimy, Ali A. Ghorbani 0001 |
PST | 2 |
| 2019 | EVChain: A Blockchain-based Credit Sharing in Electric Vehicles ChargingabstractThe Digital economy is based on confidence in its trustworthiness. Blockchain distributed consensus provides a reliable and trustful network for financial and non-financial transactions. Blockchain-based electric vehicles (EVs) charging applications benefit blockchain features to provide automated and verifiable services for EV charging market. Requirements for feasible charging operation and privacy concerns are challenging issues with blockchain-based EV charging approaches. To provide a feasible charging ability and preserve EV owner's privacy, we introduce EVChain. The EVChain is a trustful and decentralized platform based on blockchain technology to share charging credits in the EV charging market. To share credits, the main blockchain in EVChain is connected to one or more subnetwork blockchains. We introduce an interconnection position to preserve EV owners' privacy with k-anonymity protection. We simulate and evaluate the privacy protection it provides, based on an example EV charging scenario. Mahdi Daghmechi Firoozjaei, Ali A. Ghorbani 0001, Hyoungshick Kim, Jaeseung Song |
PST | 2 |
| 2019 | A New Multisignature Scheme with Public Key Aggregation for BlockchainabstractA multi signature scheme allows a group of signers to produce a joint signature on a common message, which is more compact than a collection of distinct signatures from all signers. Given this signature and the list of signers' public keys, a verifier is able to check if every signer in the group participated in signing. Recently, a multisignature scheme with public key aggregation has drawn a lot of attention due to their applications into the blockchain technology. Such multisignatures provide not only a compact signature, but also a compact aggregated public key, that is both the signature size and the public key size used to verify the correctness of the signature are independent from the number of signers. This is useful for a blockchain because of its duplication over a distributed network, and thus it is required to be as compact as possible. In this paper, we introduce a new multisignature scheme with such a feature. Our scheme is proven secure under the Decisional Diffie-Hellman assumption. In addition, in the presence of rogue key attacks, the security of our scheme is proven in the plain public key model. Duc-Phong Le, Guomin Yang, Ali A. Ghorbani 0001 |
PST | 3 |
| 2019 | An evaluation framework for network security visualizations
Iman Sharafaldin, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
Comput. Secur. | 3 |
| 2019 | Towards insider threats detection in smart grid communication systemsabstractIn today's communication systems, the most damaging security threats are not originating from the outsiders but from the trusted insiders – both malicious insiders and negligent insiders. Always endowed with high privileges, insiders are significantly prone to conduct acts that can cause catastrophic damages to the whole system either intentionally or unintentionally. Characterised by the full and rapid integration of information and communication technologies, smart grid – arguably the largest national critical engineering infrastructure – is suffering from a multitude of security threats initiated from both outsiders and insiders. Without security guarantee, the promising benefits of achieving an efficient, green, and reliable power grid would not be a success. In this study, the authors investigate the insider threats and summarise the existing threats detection solutions in smart grid communication systems. In addition, a novel hybrid insider threats modelling, analysis, and detection framework, which is based on stochastic Petri net and behaviour rule specifications, is proposed to contain insider threats in smart grid communication systems. Beibei Li 0002, Rongxing Lu, Gaoxi Xiao, Haiyong Bao, Ali A. Ghorbani 0001 |
IET Commun. | 5 |
| 2019 | Application of deep learning to cybersecurity: A survey
Samaneh Mahdavifar, Ali A. Ghorbani 0001 |
Neurocomputing | 2 |
| 2019 | The reflection of offline activities on users' online social behavior: An observational study
Seyed Amin Mirlohi Falavarjani, Fattane Zarrinkalam, Jelena Jovanovic 0001, Ebrahim Bagheri, Ali A. Ghorbani 0001 |
Inf. Process. Manag. | 5 |
| 2019 | Neural embedding-based indices for semantic search
Fatemeh Lashkari, Ebrahim Bagheri, Ali A. Ghorbani 0001 |
Inf. Process. Manag. | 3 |
| 2018 | Authorship Attribution of Android AppsabstractSince the first computer virus hit the Advanced Research Projects Agency Network (ARPANET) in the early 1970s, the security community interest revolved around ways to expose the identities of malware writers. Knowledge of the adversarial identities promised additional leverage to security experts in their ongoing battle against those perpetrators. At the dawn of computing era, when malware writers and malicious software were characterized by the lack of experience and relative simplicity, the task of uncovering the identities of virus writers was more or less straightforward. Manual analysis of source code often revealed personal, identifiable information embedded by authors themselves. But these times have long gone. Modern day's malware writers extensively use numerous malware code generators to mass produce new variants and employ advanced obfuscation techniques to hide their identities. As a result the work of security experts trying to uncover the identities of malware writers became significantly more challenging and time consuming. Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001 |
CODASPY | 3 |
| 2018 | PAMA: A Proactive Approach to Mitigate False Data Injection Attacks in Smart GridsabstractThe pervasiveness of information and communications technologies as well as intelligent electronic devices leads to an expanded attack surface in smart grids, making it increasingly challenging to withstand the high-profile false data injection (FDI) attacks. In this paper, we propose a Proactive Approach to Mitigate FDI Attacks (PAMA) in smart grids. With PAMA scheme, the critical information - power grid connections and configurations as well as the original measurement data - used for constructing FDI attacks is well protected from leakage or theft, so that FDI attacks are effectively mitigated. Specifically, we transform the state estimation and FDI detection application into a distributed one equipped with converted information from the critical information provided by the control center. In addition, the original measurement data is also protected by using a secure hybrid Paillier cryptosystem. Our PAMA scheme is proved to be secure and effective in mitigating FDI attacks on smart grids. The computational complexity and the communication overhead are evaluated on the standard IEEE 14-bus test system. Keywords__Smart grids, false data injection (FDI) attack, Paillier cryptosystem, state estimation. Beibei Li 0002, Rongxing Lu, Gaoxi Xiao, Zhou Su 0001, Ali A. Ghorbani 0001 |
GLOBECOM | 5 |
| 2018 | Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization
Iman Sharafaldin, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
ICISSP | 3 |
| 2018 | EagleEye: A Novel Visual Anomaly Detection MethodabstractWe propose a novel visualization technique (Eagle-Eye) for intrusion detection, which visualizes a host as a commu- nity of system call traces in two-dimensional space. The goal of EagleEye is to visually cluster the system call traces. Although human eyes can easily perceive anomalies using EagleEye view, we propose two different methods called SAM and CPM that use the concept of data depth to help administrators distinguish between normal and abnormal behaviors. Our experimental results conducted on Australian Defence Force Academy Linux Dataset (ADFA-LD), which is a modern system calls dataset that includes new exploits and attacks on various programs, show EagleEye's efficiency in detecting diverse exploits and attacks. Iman Sharafaldin, Ali A. Ghorbani 0001 |
PST | 2 |
| 2018 | SupAUTH: A new approach to supply chain authentication for the IoTabstractAbstract Recent advances of the Internet of Things (IoT) technologies have enhanced the use of radio‐frequency identification‐based tracking system to be widely deployed in supply chain management covering every step involved in the flow of merchandise from the supplier to the customer to ensure a trustworthy delivery environment. Such authentication system (also known as path authentication) not only guarantees the merchandise to be available in the right destination with no discrepancies and errors but also ensures the route of the merchandise progress to be valid. This paper outlines the current state‐of‐the‐art cryptographic solutions for path authentication, highlights their properties and weakness, and proposes a novel, privacy‐preserving, and efficient solution. Compared with the existing elliptic curve ElGamal re‐encryption–based solution, our homomorphic message authentication code on arithmetic circuit–based solution offers less memory storage (with limited scalability) and no computational requirement on the reader. Moreover, we allow computational ability inside the tag that articulates a new privacy direction to the state‐of‐the‐art path privacy. This privacy notion helps support the confidentiality of the tag movement in the context of IoT‐enabled cross‐organizational tracking environment where the stakeholders can be from different organizations associated together with the merchandise being delivered. As a potential extension to the path authentication protocol, we further propose a polynomial‐based mutual authentication as a security extension and batch initialization as an efficiency extension. Besides our brief security and privacy analysis, our evaluation shows that the proposed solution can significantly reduce memory requirements on tags with marginal computational overhead to ensure transmission path confidentiality. We observe that SupAUTH requires maximum 513‐bit tag memory and 57.3 ms of processing time during evaluation, which is not only practical but also suitable for any suitable low‐cost radio‐frequency identification deployment in IoT. Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001, Atsuko Miyaji, Uyen Trang Nguyen |
Comput. Intell. | 2 |
| 2018 | OTP-IoT: An ownership transfer protocol for the Internet of Things
Mohammad Saiful Islam Mamun, Chunhua Su, Anjia Yang, Atsuko Miyaji, Ali A. Ghorbani 0001 |
J. Inf. Secur. Appl. | 5 |
| 2017 | Characterization of Tor Traffic using Time based Features
Arash Habibi Lashkari, Gerard Draper-Gil, Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001 |
ICISSP | 4 |
| 2017 | DNA-Droid: A Real-Time Android Ransomware Detection Framework
Amirhossein Gharib, Ali A. Ghorbani 0001 |
NSS | 2 |
| 2017 | Towards a Network-Based Framework for Android Malware Detection and CharacterizationabstractMobile malware is so pernicious and on the rise, accordingly having a fast and reliable detection system is necessary for the users. In this research, a new detection and characterization system for detecting meaningful deviations in the network behavior of a smart-phone application is proposed. The main goal of the proposed system is to protect mobile device users and cellular infrastructure companies from malicious applications with just 9 traffic feature measurements. The proposed system is not only able to detect the malicious or masquerading apps, but can also identify them as general malware or specific malware (i.e. adware) on a mobile device. The proposed method showed the average accuracy (91.41%), precision (91.24%), and false positive (0.085) for five classifiers namely; Random Forest (RF), K-Nearest Neighbor (KNN), Decision Tree (DT), Random Tree (RT) and Regression (R). We also offer a labeled dataset of mobile malware traffic with 1900 applications includes benign and 12 different families of both adware and general malware. Arash Habibi Lashkari, Andi Fitriah Abdul Kadir, Hugo Gonzalez, Kenneth Fon Mbah, Ali A. Ghorbani 0001 |
PST | 5 |
| 2017 | A Lightweight Online Advertising Classification System using Lexical-based Features
Xichen Zhang, Arash Habibi Lashkari, Ali A. Ghorbani 0001 |
SECRYPT | 3 |
| 2017 | Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling
Hossein Hadian Jazi, Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001 |
Comput. Networks | 4 |
| 2017 | Efficient indexing for semantic search
Fatemeh Lashkari, Faezeh Ensan, Ebrahim Bagheri, Ali A. Ghorbani 0001 |
Expert Syst. Appl. | 4 |
| 2016 | Characterization of Encrypted and VPN Traffic using Time-related FeaturesabstractTraffic characterization is one of the major challenges in today’s security industry. The continuous evolution
and generation of new applications and services, together with the expansion of encrypted communications
makes it a difficult task. Virtual Private Networks (VPNs) are an example of encrypted communication service
that is becoming popular, as method for bypassing censorship as well as accessing services that are geographically
locked. In this paper, we study the effectiveness of flow-based time-related features to detect VPN traffic
and to characterize encrypted traffic into different categories, according to the type of traffic e.g., browsing,
streaming, etc. We use two different well-known machine learning techniques (C4.5 and KNN) to test the accuracy
of our features. Our results show high accuracy and performance, confirming that time-related features
are good classifiers for encrypted traffic characterization. Gerard Draper-Gil, Arash Habibi Lashkari, Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001 |
ICISSP | 4 |
| 2016 | Detecting Malicious URLs Using Lexical Analysis
Mohammad Saiful Islam Mamun, Mohammad Ahmad Rathore, Arash Habibi Lashkari, Natalia Stakhanova, Ali A. Ghorbani 0001 |
NSS | 5 |
| 2016 | Measuring code reuse in Android appsabstractThe appearance of the Android platform and its popularity has resulted in a sharp rise in the number of reported vulnerabilities and consequently in the number of mobile threats. Leveraging openness of Android app markets and the lack of security testing, malware authors commonly plagiarize Android applications through code reuse, boosting the amount of malware on the markets and consequently the infection rate. In the last few years the number of studies focused on detection of mobile app code reuse has drastically increased. Ranging from lightweight detection of suspicious signs to more sophisticated and computationally expensive methods assessing apps' similarity, the studies treated the presence of code reuse as a sign of plagiarized apps and maliciousness. In this work, we revisit this assumption and investigate code reuse in legitimate and malicious mobile apps. The main questions that this study aims to answer are what it is that is being reused, what we can learn from this reuse and consequently how we can use this knowledge. To answer these questions we measure code uniqueness and identify common components originating from third-party sources. We further analyze and correlate reused code extracted from over 60,000 apps from ten markets around the world and commonly used app repositories. As our analysis shows, understanding code reuse can shed some light on app origin and evolution. Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001 |
PST | 3 |
| 2016 | Dynamic graph-based malware classifierabstractDue to the vast majority of obfuscation techniques employed by the malware authors, extraction of a high-level representation of malware structure is an efficient way in this regard. High-level graph representations are able to represent the main functionality of a given sample in more abstract way. The graph-based approaches have mostly revolved around static analysis of the binary and share the common drawbacks of any static based approaches. In addition to the type of analysis, the scalability of these approaches is also affected by the employed graph comparison algorithm. Full graph comparison is by itself a NP-hard problem. Approximated graph comparison algorithms such as Graph Edit Distance have been commonly studied in the field of graph classification. To address the two major weaknesses involved with the current graph-based approaches, we propose a dynamic graph-based malware classifier. At the time of this proposal, this is the first attempt to generate and classify dynamic graphs. In spite of providing more accurate graphs, dynamic analysis leads to the generating larger graphs, and aggravating the problem of comparison measurement. To address this problem we modify an existing algorithm called Simulated Annealing to reduce computational complexity. Our comparative experimental results with two other malware classifiers confirm the effectiveness of our framework. Hossein Hadian Jazi, Ali A. Ghorbani 0001 |
PST | 2 |
| 2016 | Context Free Frequently Asked Questions Detection Using Machine Learning TechniquesabstractFAQs are the lists of common questions and answers on particular topics. Today one can find them in almost all web sites on the internet and they can be a great tool to give information to the users. Questions in FAQs are usually identified by the site administrators on the basis of the questions that are asked by their users. While such questions can respond to required information about a service, topic, or particular subject, they can not easily be distinguished from non-FAQ questions. This paper describes machine learning based parsing and question classification for FAQs. We demonstrate that questions for FAQs can be distinguished from other types of questions. Identification of specific features is the key to obtaining an accurate FAQ classifier. We propose a simple yet effective feature set including bag of words, lexical, syntactical, and semantic features. To evaluate our proposed methods, we gathered a large data set of FAQs in three different contexts, which were labeled by humans from real data. We showed that the SVM and Naive Bayes reach the accuracy of 80.3%, which is an outstanding result for the early stage research on FAQ classification. Experimental results show that the proposed approach can be a practical tool for question answering systems. To evaluate the accuracy of our classifier we have conducted an evaluation process and built the questionnaire. Therefore, we compared our classifier ranked questions with user rates and almost 81% similarity of the question ratings gives some confidence. Fatemeh Razzaghi, Hamed Minaee, Ali A. Ghorbani 0001 |
WI | 3 |
| 2016 | A network based document management model to prevent data extrusion
Kamran Morovati, Sanjay Kadam, Ali A. Ghorbani 0001 |
Comput. Secur. | 3 |
| 2015 | A Performance Evaluation of Hash Functions for IP Reputation Lookup Using Bloom FiltersabstractIP reputation lookup is one of the traditional methods for recognition of blacklisted IPs, i.e., IP addresses known to be sources of spam and malware-related threats. Its use however has been rapidly increasing beyond its traditional domain reaching various IP filtering tasks. One of the solutions able to provide a necessary scalability is a Bloom filter. Efficient in memory consumption, Bloom filters provide a fast membership check, allowing to confirm a presence of set elements in a data structure with a constant false positive probability. With the increased usage of IP reputation check and an increasing adoption of IPv6 protocol, Bloom filters quickly gained popularity. In spite of their wide application, the question of what hash functions to use in practice remains open. In this work, we investigate a 10 cryptographic and non-cryptographic functions for on their suitability for Bloom filter analysis for IP reputation lookup. Experiments are performed with controlled, randomly generated IP addresses as well as a real dataset containing blacklisted IP addresses. Based on our results we recommend two hash functions for their performance and acceptably low false positive rate. Marc Antoine Gosselin-Lavigne, Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001 |
ARES | 4 |
| 2015 | An Entropy Based Encrypted Traffic Classifier
Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001, Natalia Stakhanova |
ICICS | 2 |
| 2015 | Android Botnets: What URLs are Telling Us
Andi Fitriah Abdul Kadir, Natalia Stakhanova, Ali A. Ghorbani 0001 |
NSS | 3 |
| 2015 | Real-time signature-based detection approach for SMS botnetabstractAs an open platform for mobile electronic devices, Android is experiencing a steady growth in the number of published applications (apps). Features of the Android platform have caught the attention of malicious users who have targeted the Short Message Service (SMS) to abuse its permissions. Various types of attack, referred to as botnets, can be executed without the user's knowledge by taking advantage of SMS messages, such as sending text message spam, transferring all command and control (C&C) instructions, launching denial-of-service (DoS) attacks, sending premium-rate SMS messages, or distributing malicious applications via URLs embedded in text messages. In this paper, we propose a real-time signature-based detection mechanism to combat SMS botnets, in which we first apply pattern-matching detection approaches for incoming and outgoing SMS text messages, and then use rule-based techniques to label unknown SMS messages as suspicious or normal. This approach was evaluated using over 12,000 test messages. It was able to detect all 747 malicious SMS messages in the dataset (100% detection rate with no false negatives). It also flagged 351 SMS messages as suspicious. Abdullah J. Alzahrani, Ali A. Ghorbani 0001 |
PST | 2 |
| 2015 | Application-layer denial of service attacks: taxonomy and surveyabstractThe recent escalation of application-layer denial of service (DoS) attacks has attracted a significant interest of the security research community. Since application-layer DoS attacks usually do not manifest themselves at the network level, they avoid traditional network-layer-based detection. Therefore, the security community has focused on specialised application-layer DoS attacks detection and mitigation mechanisms. However, the deployment of reliable and efficient defence mechanisms against these attacks requires the comprehensive understanding of the existing application-layer DoS attacks supported by a unified terminology. Thus, in this paper we address this issue and devise a taxonomy of application-layer DoS attacks. By devising the proposed taxonomy, we intend to give researchers a better understanding of these attacks and provide a foundation for organising research efforts within this specific field. Georgios Mantas, Natalia Stakhanova, Hugo Gonzalez, Hossein Hadian Jazi, Ali A. Ghorbani 0001 |
Int. J. Inf. Comput. Secur. | 5 |
| 2014 | DroidKin: Lightweight Detection of Android Apps Similarity
Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001 |
SecureComm (1) | 3 |
| 2013 | Sentence Subjectivity Analysis in Social DomainsabstractSubjectivity analysis recognizes the contextual polarity of opinions, attitudes, emotions, feelings etc. regarding products, services, topics, or issues. Subjectivity classification categorizes the given text as subjective or objective. While an objective text contains one or more facts about a product or an issue, a subjective text expresses author's opinions. Statistical analysis shows that subjectivity analysis of social issues is different from that of products. This paper focuses on subjectivity analysis of social issues. Subjectivity of a document strongly depends on its sentences. Hence, a lexical-syntactical approach is proposed to recognize and classify subjectivity at the sentence level. This approach considers the role of various opinion terms especially verbs on opinions regarding social issues. Evaluation of the proposed approach on a data-set consisting comments about abortion shows that it slightly outperforms other similar works. It has a good accuracy especially on the strong sentences which express explicit opinions. Its reasonable F-measure demonstrates a good balance between the precision and recall which makes it suitable for applications such as sentiment polarity classification, text sentiment summarization, and opinion question answering. Mostafa Karamibekr, Ali A. Ghorbani 0001 |
Web Intelligence | 2 |
| 2013 | Botnet detection based on traffic behavior analysis and flow intervals
Issa Traoré, Bassam Sayed, Wei Lu 0018, Sherif Saad, Ali A. Ghorbani 0001, Daniel Garant |
Comput. Secur. | 6 |
| 2012 | Group Behavior Metrics for P2P Botnet Detection
John Felix Charles Joseph, Ali A. Ghorbani 0001 |
ICICS | 2 |
| 2012 | Peer to Peer Botnet Detection Based on Flow Intervals
Issa Traoré, Ali A. Ghorbani 0001, Bassam Sayed, Sherif Saad, Wei Lu 0018 |
SEC | 3 |
| 2012 | Verb Oriented Sentiment ClassificationabstractSentiment analysis refers to a broad range of fields of natural language processing, computational linguistics and text mining. Sentiment classification of reviews and comments has emerged as the most useful application in the area of sentiment analysis. Although sentiment classification generally is carried out at the document level, accurate results require analysis at the sentence level. Bag of words and feature based sentiment are the most popular approaches used by researchers to deal with sentiment classification of opinions about products such as movies, electronics, cars etc. Until recently most classification techniques have considered adjectives, adverbs and nouns as features. This paper proposes a new approach based on verb as an important opinion term particularly in social domains. We extract opinion structures which consider verb as the core element. Sentiment orientation is recognized from sentiments inside of opinion structures and their association with the social issue. Experimental results show that considering verbs improves the performance of sentiment classification. Mostafa Karamibekr, Ali A. Ghorbani 0001 |
Web Intelligence | 2 |
| 2012 | Multi-layer episode filtering for the multi-step attack detection
Mahboobeh Soleimani, Ali A. Ghorbani 0001 |
Comput. Commun. | 2 |
| 2012 | Toward developing a systematic approach to generate benchmark datasets for intrusion detection
Ali Shiravi, Hadi Shiravi, Mahbod Tavallaee, Ali A. Ghorbani 0001 |
Comput. Secur. | 4 |
| 2012 | Improved competitive learning neural networks for network intrusion and fraud detection
John Zhong Lei, Ali A. Ghorbani 0001 |
Neurocomputing | 2 |
| 2012 | A Survey of Visualization Systems for Network SecurityabstractSecurity Visualization is a very young term. It expresses the idea that common visualization techniques have been designed for use cases that are not supportive of security-related data, demanding novel techniques fine tuned for the purpose of thorough analysis. Significant amount of work has been published in this area, but little work has been done to study this emerging visualization discipline. We offer a comprehensive review of network security visualization and provide a taxonomy in the form of five use-case classes encompassing nearly all recent works in this area. We outline the incorporated visualization techniques and data sources and provide an informative table to display our findings. From the analysis of these systems, we examine issues and concerns regarding network security visualization and provide guidelines and directions for future researchers and visual system developers. Hadi Shiravi, Ali Shiravi, Ali A. Ghorbani 0001 |
IEEE Trans. Vis. Comput. Graph. | 3 |
| 2011 | A statistical approach to botnet virulence estimationabstractNetwork vulnerability and infection rates are key factors in mathematical models of botnet propagation dynamics, which in turn are increasingly deemed to have potential for playing an important role in various botnet mitigation strategies. In this paper we discuss research that draws on epidemiological models in biology in order to solve the problem of how to estimate network vulnerability and infection rates in relation to a botnet. This research provides botnet propagation models with concrete measures that make those models practical, and hence employable in mitigation of real world botnets in a timely fashion. The proposed estimation approach is based on random sampling and follows a novel application of statistical learning and inference in a botnet-versus-network setting. We have implemented this research in the Matlab programming language, and thus in the paper we also discuss an experimental validation of the effectiveness of this research with respect to realistically simulated botnet propagation dynamics in a GTNetS network simulation platform. Julian L. Rrushi, Ehsan Mokhtari, Ali A. Ghorbani 0001 |
AsiaCCS | 3 |
| 2011 | Situational Assessment of Intrusion Alerts: A Multi Attack Scenario Evaluation
Hadi Shiravi, Ali Shiravi, Ali A. Ghorbani 0001 |
ICICS | 3 |
| 2011 | Detecting P2P botnets through network behavior analysis and machine learningabstractBotnets have become one of the major threats on the Internet for serving as a vector for carrying attacks against organizations and committing cybercrimes. They are used to generate spam, carry out DDOS attacks and click-fraud, and steal sensitive information. In this paper, we propose a new approach for characterizing and detecting botnets using network traffic behaviors. Our approach focuses on detecting the bots before they launch their attack. We focus in this paper on detecting P2P bots, which represent the newest and most challenging types of botnets currently available. We study the ability of five different commonly used machine learning techniques to meet online botnet detection requirements, namely adaptability, novelty detection, and early detection. The results of our experimental evaluation based on existing datasets show that it is possible to detect effectively botnets during the botnet Command-and-Control (C&C) phase and before they launch their attacks using traffic behaviors only. However, none of the studied techniques can address all the above requirements at once. Sherif Saad, Issa Traoré, Ali A. Ghorbani 0001, Bassam Sayed, Wei Lu 0018, John Felix, Payman Hakimian |
PST | 3 |
| 2011 | Clustering botnet communication traffic based on n-gram feature selection
Wei Lu 0018, Goaletsa Rammidi, Ali A. Ghorbani 0001 |
Comput. Commun. | 3 |
| 2011 | Estimating botnet virulence within mathematical models of botnet propagation dynamics
Julian L. Rrushi, Ehsan Mokhtari, Ali A. Ghorbani 0001 |
Comput. Secur. | 3 |
| 2010 | An Online Adaptive Approach to Alert Correlation
Hanli Ren, Natalia Stakhanova, Ali A. Ghorbani 0001 |
DIMVA | 3 |
| 2010 | IDS Alert Visualization and Monitoring through Heuristic Host Selection
Hadi Shiravi, Ali Shiravi, Ali A. Ghorbani 0001 |
ICICS | 3 |
| 2010 | Selective Regular Expression Matching
Natalia Stakhanova, Hanli Ren, Ali A. Ghorbani 0001 |
ISC | 3 |
| 2010 | The analysis and management of non-canonical requirement specifications through a belief integration game
Ebrahim Bagheri, Ali A. Ghorbani 0001 |
Knowl. Inf. Syst. | 2 |
| 2010 | A Model for the Integration of Prioritized Knowledge Bases Through Subjective Belief GamesabstractBelief merging is concerned with the integration of several belief bases such that a coherent belief base is developed. Various belief merging models that use a belief negotiation game have been developed. These models often consist of two key functions, namely, negotiation and weakening. A negotiation function finds and selects the weakest belief bases among the available belief bases, while the weakening function removes the least valuable set of information from the selected belief base. This process is iteratively repeated until a consistent belief base is developed. In this paper, we extend the current game-based belief merging models by introducing the Subjective belief game model. The Subjective belief game model operates over a Subjective belief profile, which consists of belief bases with Subjectively annotated formulas. The Subjective information attached to each formula enables the proposed model to prioritize the formulas in the merging process. One of the advantages of the proposed game is that it provides room for enhancing the content of the weak belief bases, instead of enforcing their further weakening. Trustworthiness of the information sources is also considered. We provide several instantiations of the model. The Subjective belief game model can be useful for formalizing a negotiation process between the human participants of a design process in cases where discrepancies and conflicts arise. We apply this belief game model to an example case study of collaboratively designing some parts of unified modeling language (UML) class diagram for vehicle design. Ebrahim Bagheri, Ali A. Ghorbani 0001 |
IEEE Trans. Syst. Man Cybern. Part A | 2 |
| 2010 | Toward Credible Evaluation of Anomaly-Based Intrusion-Detection MethodsabstractSince the first introduction of anomaly-based intrusion detection to the research community in 1987, the field has grown tremendously. A variety of methods and techniques introducing new capabilities in detecting novel attacks were developed. Most of these techniques report a high detection rate of 98% at the low false alarm rate of 1%. In spite of the anomaly-based approach's appeal, the industry generally favors signature-based detection for mainstream implementation of intrusion-detection systems. While a variety of anomaly-detection techniques have been proposed, adequate comparison of these methods' strengths and limitations that can lead to potential commercial application is difficult. Since the validity of experimental research in academic computer science, in general, is questionable, it is plausible to assume that research in anomaly detection shares the above problem. The concerns about the validity of these methods may partially explain why anomaly-based intrusion-detection methods are not adopted by industry. To investigate this issue, we review the current state of the experimental practice in the area of anomaly-based intrusion detection and survey 276 studies in this area published during the period of 2000-2008. We summarize our observations and identify the common pitfalls among surveyed works. Mahbod Tavallaee, Natalia Stakhanova, Ali A. Ghorbani 0001 |
IEEE Trans. Syst. Man Cybern. Part C | 3 |
| 2009 | Automatic discovery of botnet communities on large-scale communication networksabstractBotnets are networks of compromised computers infected with malicious code that can be controlled remotely under a common command and control (C&C) channel. Recognized as one the most serious security threats on current Internet infrastructure, advanced botnets are hidden not only in existing well known network applications (e.g. IRC, HTTP, or Peer-to-Peer) but also in some unknown or novel (creative) applications, which makes the botnet detection a challenging problem. Most current attempts for detecting botnets are to examine traffic content for bot signatures on selected network links or by setting up honeypots. In this paper, we propose a new hierarchical framework to automatically discover botnets on a large-scale WiFi ISP network, in which we first classify the network traffic into different application communities by using payload signatures and a novel cross-association clustering algorithm, and then on each obtained application community, we analyze the temporal-frequent characteristics of flows that lead to the differentiation of malicious channels created by bots from normal traffic generated by human beings. We evaluate our approach with about 100 million flows collected over three consecutive days on a large-scale WiFi ISP network and results show the proposed approach successfully detects two types of botnet application flows (i.e. Blackenergy HTTP bot and Kaiten IRC bot) from about 100 million flows with a high detection rate and an acceptable low false alarm rate. Wei Lu 0018, Mahbod Tavallaee, Ali A. Ghorbani 0001 |
AsiaCCS | 3 |
| 2009 | A detailed analysis of the KDD CUP 99 data setabstractDuring the last decade, anomaly detection has attracted the attention of many researchers to overcome the weakness of signature-based IDSs in detecting novel attacks, and KDDCUP'99 is the mostly widely used data set for the evaluation of these systems. Having conducted a statistical analysis on this data set, we found two important issues which highly affects the performance of evaluated systems, and results in a very poor evaluation of anomaly detection approaches. To solve these issues, we have proposed a new data set, NSL-KDD, which consists of selected records of the complete KDD data set and does not suffer from any of mentioned shortcomings. Mahbod Tavallaee, Ebrahim Bagheri, Wei Lu 0018, Ali A. Ghorbani 0001 |
CISDA | 4 |
| 2009 | Hybrid Traffic Classification Approach Based on Decision TreeabstractClassifying network traffic is very challenging and is still an issue yet to be solved due to the increase of new applications and traffic encryption. In this paper, we propose a novel hybrid approach for the network flow classification, in which we first apply the payload signature based classifier to identify the flow applications and unknown flows are then identified by a decision tree based classifier in parallel. We evaluate our approach with over 100 million flows collected over three consecutive days on a large-scale WiFi ISP network and results show the proposed approach successfully classifies all the flows with an accuracy approaching 93%. Wei Lu 0018, Mahbod Tavallaee, Ali A. Ghorbani 0001 |
GLOBECOM | 3 |
| 2009 | An incremental frequent structure mining framework for real-time alert correlation
Reza Sadoddin, Ali A. Ghorbani 0001 |
Comput. Secur. | 2 |
| 2009 | A belief-theoretic framework for the collaborative development and integration of para-consistent conceptual models
Ebrahim Bagheri, Ali A. Ghorbani 0001 |
J. Syst. Softw. | 2 |
| 2009 | Astrolabe: A Collaborative Multiperspective Goal-Oriented Risk Analysis MethodologyabstractThe intention of this paper is to introduce a risk analysis methodology called Astrolabe. Astrolabe is based on causal analysis of systems risks. It allows the analysts to both align the current standpoint of the system with its intentions and identify any vulnerabilities or hazards that threaten the systems stability. Astrolabe adopts concepts from organizational theory and software requirement engineering. The aim of Astrolabe is to guide risk analysis through its phases so that a near complete investigation of system risks is performed. The concepts and methods driving the Astrolabe methodology have been clearly explained in this paper. Ebrahim Bagheri, Ali A. Ghorbani 0001 |
IEEE Trans. Syst. Man Cybern. Part A | 2 |
| 2008 | A Behavioral Model of Ideologically-motivated "Snowball" AttacksabstractAs our daily life depends more and more on Internet technology, it also becomes increasingly susceptible to new types of cyber threats. These threats often take a form of innovative malicious behavior and commonly emerge in a pace that exceeds the capability of security experts to develop timely solutions to counter such threats. In this context it becomes particularly important to develop a good understanding of the complete cycle of malicious behavior including its evolution and the factors contributing to its spread so that these types of threats are addressed in proactive manner. In this paper we describe and define the new type of recently emerged threat - the ideologically-motivated "snow ball" attack. We develop a conceptual model for explaining the evolution of ideologically motivated attacks and discuss a set of methods that can be used to detect and respond to this type of threat at all stages of its development. Finally, we use the recent case of ideologically motivated attack - the attack on Estonia's cyber infrastructure to evaluate our conceptual model. Natalia Stakhanova, Oleg Stakhanov, Ali A. Ghorbani 0001 |
ARES | 3 |
| 2008 | Real-time Alert Correlation Using Stream Data Mining Techniques
Reza Sadoddin, Ali A. Ghorbani 0001 |
AAAI | 2 |
| 2008 | Automating Architecture Trade-Off Decision Making through a Complex Multi-attribute Decision Process
Majid Makki, Ebrahim Bagheri, Ali A. Ghorbani 0001 |
ECSA | 3 |
| 2008 | Botnets Detection Based on IRC-CommunityabstractBotnets are networks of compromised computers controlled under a common command and control (C&C) channel. Recognized as one the most serious security threats on current Internet infrastructure, botnets are often hidden in existing applications, e.g. IRC, HTTP, or Peer-to-Peer, which makes the botnet detection a challenging problem. Previous attempts for detecting botnets are to examine traffic content for IRC command on selected network links or by setting up honeypots. In this paper, we propose a new approach for detecting and characterizing botnets on a large-scale WiFi ISP network, in which we first classify the network traffic into different applications by using payload signatures and a novel clustering algorithm and then analyze the specific IRC application community based on the temporal-frequent characteristics of flows that leads the differentiation of malicious IRC channels created by bots from normal IRC traffic generated by human beings. We evaluate our approach with over 160 million flows collected over five consecutive days on a large scale network and results show the proposed approach successfully detects the botnet flows from over 160 million flows with a high detection rate and an acceptable low false alarm rate. Wei Lu 0018, Ali A. Ghorbani 0001 |
GLOBECOM | 2 |
| 2008 | Oracle Clustering: Dynamic Partitioning Based on Random ObservationsabstractIn this paper, a new dynamic clustering algorithm based on random sampling is proposed. The algorithm addresses well known challenges in clustering such as dynamism, stability, and scaling. The core of the proposed method isbased on the definition of a function, named the Oracle,which can predict whether two random data points belongto the same cluster or not. Furthermore, this algorithm isalso equipped with a novel technique for determination ofthe optimal number of clusters in datasets. These properties add the capabilities of high performance and reducing the effect of scale in datasets to this algorithm. Finally, the algorithm is tuned and evaluated by means of various experiments and in-depth analysis. High accuracy and performance results obtained, demonstrate the competitiveness of our algorithm. Reza Zafarani, Ali A. Ghorbani 0001 |
ICTAI (2) | 2 |
| 2008 | An Empirical Analysis on the Stability of Clustering AlgorithmsabstractOne of the aspects of a clustering algorithm that should be considered for choosing an appropriate algorithm in an unsupervised learning task is stability. A clustering algorithm is stable (on a dataset) if it results in the same clustering as it performed on the whole dataset, when actually performs on a (sub)sample of the dataset. In this paper, we report the results of an empirical study on the stability of two clustering algorithms, namely k-Means and normalized spectral clustering, along with some analysis on those results that are useful for practitioners who deal with scalability and researchers who employ stability as a tool for model selection. Reza Zafarani, Majid Makki, Ali A. Ghorbani 0001 |
ICTAI (2) | 3 |
| 2008 | Bots Behaviors vs. Human Behaviors on Large-Scale Communication Networks (Extended Abstract)
Wei Lu 0018, Ali A. Ghorbani 0001 |
RAID | 2 |
| 2008 | An Interactive Search Assistant Architecture Based on Intrinsic Query Stream CharacteristicsabstractSearch engine query log mining has evolved over time to more like data stream mining due to the endless and continuous sequence of queries known as query stream. In this paper, we propose an online frequent sequence discovery (OFSD) algorithm to extract frequent phrases from within query streams, based on a new frequency rate metric, which is suitable for query stream mining. OFSD is an online, single pass, and real‐time frequent sequence miner appropriate for data streams. The frequent phrases extracted by the OFSD algorithm are used to guide novice Web search engine users to complete their search queries more efficiently. YourEye, our online phrase recommender is then introduced. The advantages of YourEye compared with Google Suggest, a service powered by Google for phrase suggestion, is also described. Various characteristics of two specific Web search engine query logs are analyzed and then the query logs are used to evaluate YourEye. The experimental results confirm the significant benefit of monitoring frequent phrases within the queries instead of the whole queries because none‐separable items. The number of the monitored elements substantially decreases, which results in smaller memory consumption as well as better performance. Re‐ranking the retrieved pages based on past users clicks for each frequent phrase extracted by OFSD is also introduced. The preliminary results show the advantages of the proposed method compared to the similar work reported in Smyth et al. M. Barouni-Ebrahimi, Ali A. Ghorbani 0001 |
Comput. Intell. | 2 |
| 2008 | Approximate autoregressive modeling for network attack detectionabstractThis paper presents a technique for creating an ARX model of network signals and using it for detecting network anomalies caused by intrusions. Network signals are non-stationary, highly volatile and hard to model using traditional methods. We presen Harshit Nayyar, Ali A. Ghorbani 0001 |
J. Comput. Secur. | 2 |
| 2008 | Guest Editors' Introduction
George Yee, Ali A. Ghorbani 0001, Patrick C. K. Hung |
J. Comput. Secur. | 2 |
| 2008 | A language for high-level description of adaptive web systems
S. Hossein Sadat-Mohtasham, Ali A. Ghorbani 0001 |
J. Syst. Softw. | 2 |
| 2007 | Features vs. Attacks: A Comprehensive Feature Selection Model for Network Based Intrusion Detection Systems
Iosif-Viorel Onut, Ali A. Ghorbani 0001 |
ISC | 2 |
| 2007 | On Query Completion in Web Search Engines Based on Query Stream MiningabstractIn this paper, youreye, the real-time phrase recommender is introduced that suggests the related frequent phrases to the incomplete user query. The frequent phrases are extracted from within previous queries based on a new frequency rate metric suitable for query stream mining. The advantages of YourEye compared to Google suggest, a service powered by Google for phrase suggestion, is described. The experimental results also confirm the significant benefit of monitoring phrases instead of queries. The number of the monitored elements significantly reduces that results in smaller memory consumption as well as better performance. M. Barouni-Ebrahimi, Ali A. Ghorbani 0001 |
Web Intelligence | 2 |
| 2007 | A Fuzzy Markov Model Approach for Predicting User NavigationabstractUser navigation is an interesting aspect in Web usage mining. Analysis of this issue can be of great benefit in discovering users' behavior. This paper presents a fuzzy approach for predicting users' navigation paths using the Markov chain model. A standard Markov model can be used to predict the ID of the next page. However, our proposed approach can predict not only users' next requests for pages, but also the time-duration to be spent on the requests. The experimental results show that our method is highly accurate (average 77.9%) in session prediction. Even though the standard methods also perform well (average 78.9%), our proposed approach Ali A. Ghorbani 0001 |
Web Intelligence | 1 |
| 2007 | SVision: A novel visual network-anomaly identification technique
Iosif-Viorel Onut, Ali A. Ghorbani 0001 |
Comput. Secur. | 2 |
| 2006 | Behavior analysis through reputation propagation in a multi-context environmentabstractReputation is a distributed, socially ascribed, and collective belief of the society towards the stand point of a single person, group, role or even a non-human identity within the context of that society. Therefore, reputation can be only formalized based on the underlying principals and values of a specific context. In this paper we propose a model that clearly depicts how the reputation of a person in one context can affect his reputation in other contexts. This model provides a reputation propagation scheme that allows us to analyze the overall behavior of a person within the scope of a multi-context environment. It also caters suitable mechanisms to anticipate a proper initial reputation value for a person within the contexts that he has not been present in before. Ebrahim Bagheri, Ali A. Ghorbani 0001 |
PST | 2 |
| 2006 | Towards an MDA-oriented UML profile for critical infrastructure modelingabstractInfrastructures are networks of highly complex systems that can be classified as socio-technical organisms with hidden consciousness. The hidden consciousness of these types of systems lies beyond their definition. Although these systems are structurally independent of any outside component, but collaborate synergistically to provide their services to the end customer. The interdependencies between these complex systems bring about sophisticated and unpredictable outcomes. In this paper we propose a platform independent metamodel for critical infrastructures. The metamodel precisely defines every aspect of an infrastructure through clear syntactical and semantic definition of existing concepts and relationships. The Platform independent model (PIM) has been defined as a UML profile (UML-CI) and serves as one of the first steps towards building an agent based simulation environment. Ebrahim Bagheri, Ali A. Ghorbani 0001 |
PST | 2 |
| 2006 | Trust-based contextual information filteringabstractWe describe a multilayer information filtering approach, implemented as part of the Comprehensive Information Filtering System (CIFS) - a personal filtering system for mobile users. CIFS combines the message content, context, and contact information into a scenario that maintains an amalgamated relevance, privacy and trust rating. Eugenia Kondratova, Stephen Marsh 0001, Ali A. Ghorbani 0001 |
PST | 3 |
| 2006 | Design and implementation of a behavioral difference analyzer for network intrusion detectionabstractThis paper discusses the use of diversity and redundancy techniques for network intrusion detection, and explains the design and implementation of a Behavioral Difference Analyzer to examine behavioral disparity of two heterogeneous network servers under normal and compromised conditions. The challenges of differential intrusion detection are explained, and solutions and algorithms for carrying out differential analysis are proposed. Mehran Nadjarbashi-Noghani, Ali A. Ghorbani 0001 |
PST | 2 |
| 2006 | Approximate autoregressive modeling for network attack detectionabstractThis paper presents a technique for creating an ARX model of network signals and using it for detecting network anomalies caused by intrusions. Network signals are non-stationary, highly volatile and hard to model using traditional methods. We present our own modeling technique using a combination of system identification theory and wavelet approximation. We also present the results of a prototype implementation applied to 1999 DARPA intrusion detection evaluation data set. We verify that the technique is viable for anomaly based intrusion detection and can contribute to defense in depth in a network. The technique proposed is online, generic and can be used with many other network signals like bandwidth consumption, rate of flow arrival or SNMP variables. Moreover, it requires minimal expertise for use on the part of the network administrator and automatically adapts to the underlying network behavior. Harshit Nayyar, Ali A. Ghorbani 0001 |
PST | 2 |
| 2006 | Alert correlation survey: framework and techniquesabstractManaging raw alerts generated by various sensors are becoming of more significance to intrusion detection systems as more sensors with different capabilities are distributed spatially in the network. Alert Correlation addresses this issue by reducing, fusing and correlating raw alerts to provide a condensed, yet more meaningful view of the network from the intrusion standpoint. Techniques from a divers range of disciplines have been used by researchers for different aspects of correlation. This paper provides a survey of the state of the art in alert correlation techniques. Our main contribution is a two-fold classification of literature based on correlation framework and applied techniques. The previous works in each category have been described alongside with their strengths and weaknesses from our viewpoint. Reza Sadoddin, Ali A. Ghorbani 0001 |
PST | 2 |
| 2006 | An improved familiarity measurement for formalization of trust in e-commerce based multiagent systemsabstractFamiliarity between agents is often considered to be an important factor in determining the level of trust. In electronic marketplaces, trust is modeled, for instance, in order to allow buying agents to make effective selection of selling agents. In previous research, familiarity between two agents has been simply assumed to be the similarity between them, which is fixed for the two agents. We propose an improved familiarity measurement based on the exploration of factors that affect a human's feelings of familiarity and the mapping from those factors to the properties of agent societies. We examine the trust model in the context of a multiagent system within an e-commerce framework. We also carry out experiments to compare the stability of the system using the trust model with the improved familiarity measurement and that with the fixed familiarity values. Experimental results show that the stability of the system is increased by 33.47% through the improved familiarity measurement. Jie Zhang 0002, Ali A. Ghorbani 0001, Robin Cohen |
PST | 2 |
| 2006 | A Phrase Recommendation Algorithm Based on Query Stream Mining in Web Search Engines
M. Barouni-Ebrahimi, Ali A. Ghorbani 0001 |
WAW | 2 |
| 2005 | Value-Centric Trust Model with Improved Familiarity Measurement
Jie Zhang 0002, Ali A. Ghorbani 0001 |
IJCAI | 2 |
| 2005 | Agent-oriented Design for Network SurvivabilityabstractIntelligent behavior is the selection of actions based on knowledge. The design of the fuzzy adaptive survivability tool (FAST) agents and their intelligent behavior is explained. A FAST agent uses Belief-Desire-Intention (BDI) logic as the reasoning framework to decide on desirable response plans. These decisions are both context-sensitive to take into account the changes in the network status and cost-sensitive to avoid the risk of collateral damage. A real-world scenario, which shows how the FAST agents choose desirable responses to mitigate scanning worm traffic, is also presented. Mehdi Shajari, Ali A. Ghorbani 0001 |
ISDA | 2 |
| 2005 | SVision: A Network Host-Centered Anomaly Visualization Technique
Iosif-Viorel Onut, Ali A. Ghorbani 0001 |
ISC | 3 |
| 2005 | Information Domain Modeling for Adaptive Web SystemsabstractThis paper presents a domain modeling system, which builds a domain model framework for adaptive Web systems. It records concepts and the relationships among them and represents them as a concept network. To speed up run time searches, the system finds all related concepts offline and in advance by calculating the optimal paths between all pairs of concepts. In addition, a new algorithm, rich maximal frequent sequence algorithm, is introduced in the system for discovering frequent sequence patterns among concepts. For the purpose of evaluation, the system is applied to an adaptive Web system. The experiments demonstrate that the adaptive Web system is improved in the performance of accurate page recommendations and quick responses. Wenpu Xing, Ali A. Ghorbani 0001 |
Web Intelligence | 2 |
| 2005 | Incremental communication for adaptive resonance theory networksabstractWe have proposed earlier the incremental internode communication method to reduce the communication cost as well as the time of the learning process in artificial neural networks (ANNs). In this paper, the limited precision incremental communication method is applied to a class of recurrent neural networks, the adaptive resonance theory 2 (ART2) networks. Simulation studies are carried out to examine the effects of the incremental communication method on the convergence behavior of ART2 networks. We have found that, 7-13-b precision is sufficient to obtain almost the same results as those with full (32-b) precision conventional communication. A theoretical error analysis is also carried out to analyze the effects of the limited precision incremental communication. The simulation and analytical results show that the limited precision errors are bounded and do not seriously degrade the convergence of ART2 networks. Therefore, the incremental communication can be incorporated in parallel and special-purpose very large scale integration (VLSI) implementations of the ART2 networks. Ali A. Ghorbani 0001, Virendrakumar C. Bhavsar |
IEEE Trans. Neural Networks | 2 |
| 2004 | Classifying cognitive states from fMRI data using neural networksabstractSince the discovery of functional magnetic resonance imaging (fMRI) studies have proved that this technique is one of the best for collecting vast quantities of data about activity of the human brain. Our aim is to use this information in order to predict the cognitive status of the subject given its fMRI activity. We present a new approach for creating single-subject classifiers using bagging from a pool of feed-forward backpropagation networks. Our experiments indicate that as the number of selected features (voxels) increases, the accuracy of the system increases too. Nevertheless, when the number of voxels exceeds 120, the accuracy of the system rapidly increases from 45% to 70%. Eventually it reaches a (near) saturation point after which the increase in the accuracy is very slow. Iosif-Viorel Onut, Ali A. Ghorbani 0001 |
IJCNN | 2 |
| 2004 | A novel visualization technique for network anomaly detection
Iosif-Viorel Onut, Ali A. Ghorbani 0001 |
PST | 3 |
| 2004 | Application of Belief-Desire-Intention Agents in Intrusion Detection & Response
Mehdi Shajari, Ali A. Ghorbani 0001 |
PST | 2 |
| 2004 | Familiarity and Trust: Measuring Familiarity with a Web Site
Jie Zhang 0002, Ali A. Ghorbani 0001 |
PST | 2 |
| 2004 | Introduction to Special Issue on Agent Technologies for Electronic Business
Ali A. Ghorbani 0001 |
Comput. Intell. | 1 |
| 2004 | Towards a formalization of value-centric trust in agent societies
Jonathan Carter 0003, Ali A. Ghorbani 0001 |
Web Intell. Agent Syst. | 2 |
| 2003 | Using Fuzzy System to Manage False Alarms in Intrusion Detection
Mehdi Shajari, Ali A. Ghorbani 0001 |
SEC | 2 |
| 2003 | Value Centric Trust in Multiagent SystemsabstractWe focus on the design and implementation of a new model of trust based on the formalizations of reputation, self-esteem, and similarity within an agent. We universalize reputation through the use of values found within all multiagent systems. The following values are manifested within multiagent systems: responsibility, honesty, independence, obedience, ambition, helpfulness, capability, knowledgability, and cost-efficiency. Manifestations of these values lead to a more universalized approach to formalizing reputation. This new model of trust is examined within the context of an e-commerce framework. It is analyzed with respect to stability, scalability, accuracy in attaining e-commerce objectives, and general effectiveness in discouraging untrustworthy behavior. Based on the experiments, the model is scalable and stable dependent upon the agent population of buyers and sellers. It achieves its primary objective of discouraging untrustworthy behavior as measured through the acceleration of Gross Domestic Product growth over time. Jonathan Carter 0003, Ali A. Ghorbani 0001 |
Web Intelligence | 2 |
| 2003 | The ACORN multi-agent system
Stephen Marsh 0001, Ali A. Ghorbani 0001, Virendrakumar C. Bhavsar |
Web Intell. Agent Syst. | 2 |
| 2002 | Reputation Formalization for an Information-Sharing Multi-Agent SystemabstractWe propose that through the formalization of concepts related to trust, a more accurate model of trust can be implemented. This paper presents a new model of trust that is based on the formalization of reputation. A multidisciplinary approach is taken to understanding the nature of trust and its relation to reputation. Through this approach, a practical definition of reputation is adopted from sociological contexts and a model of reputation is designed and presented. Reputation is defined as role fulfillment. To formalize reputation, it is necessary to formalize the expectations placed upon an agent within a particular multi–agent system (MAS). In this case, the agents are part of an information–sharing society. Five roles are defined along with the ways in which these roles are objectively fulfilled. Through the measurement of role fulfillment, a vector representing reputation can be developed. This vector embodies the magnitude of the reputation and describes the patterns of behavior associated with the direction of the vector. Experiments are conducted to verify the sensibility of the proposed models for role fulfillment and overall reputation. The simulation results show that the roles, defined for building reputation in an information–sharing MAS environment, react to different agent and user actions in a manner consistent with the formal definitions. Jonathan Carter 0003, Elijah Bitting, Ali A. Ghorbani 0001 |
Comput. Intell. | 3 |
| 2002 | Architectural Components of Information-Sharing SocietiesabstractTwo similar multi–agent systems have been designed to address the issue of information sharing within a multi–agent system. This paper examines the architectural components that have been added to our information–sharing societies, ACORN and MP3. Through this exploration, we conclude that these components and their underlying concepts can be added to other information–retrieval societies. ACORN consists of a set of information–sharing locations referred to as cafés. Cafés are defined as meeting locations for like–minded agents. Like–minded agents are defined as agents that share a common set of interests. As an example, a café may contain agents that are interested in information relating to cars. A dynamic café clustering method is developed. The performance evaluation of the proposed structure for the café is presented. The concept of a fat/thin agent architecture is introduced. This agent architecture allows for minimizing network traffic as agents traverse the network in search of or distribution of knowledge. The directory server component is presented along with its relation to the fat/thin agent architecture. Finally, an anonymity service provider which allows anonymity for users is introduced. The MP3 society exists with the sole purpose of finding MP3s throughout a given network. Through this society, the core design issues of agent verification and agent validation are addressed and solutions are presented through respective interface components. Jonathan Carter 0003, Ali A. Ghorbani 0001, Stephen Marsh 0001 |
Comput. Intell. | 2 |
| 1998 | Incremental communication for multilayer neural networks: error analysisabstractArtificial neural networks (ANNs) involve a large amount of internode communications. To reduce the communication cost as well as the time of learning process in ANNs, we earlier proposed (1995) an incremental internode communication method. In the incremental communication method, instead of communicating the full magnitude of the output value of a node, only the increment or decrement to its previous value is sent to a communication link. In this paper, the effects of the limited precision incremental communication method on the convergence behavior and performance of multilayer neural networks are investigated. The nonlinear aspects of representing the incremental values with reduced (limited) precision for the commonly used error backpropagation training algorithm are analyzed. It is shown that the nonlinear effect of small perturbations in the input(s)/output of a node does not cause instability. The analysis is supported by simulation studies of two problems. The simulation results demonstrate that the limited precision errors are bounded and do not seriously affect the convergence of multilayer neural networks. Ali A. Ghorbani 0001, Virendrakumar C. Bhavsar |
IEEE Trans. Neural Networks | 1 |
| 1995 | Incremental communication for multilayer neural networksabstractA new method of inter-neuron communication called incremental communication is presented. In the incremental communication method, instead of communicating the whole value of a variable, only the increment or decrement of its previous value is sent on a communication link. The incremental value may be either a fixed-point or a floating-point value. Multilayer feedforward network architecture is used to illustrate the effectiveness of the proposed communication scheme. The method is applied to three different learning problems and the effect of the precision of incremental input-output values of the neurons on the convergence behavior is examined. It is shown through simulation that for some problems even four-bit precision in fixed- and/or floating-point representations is sufficient for the network to converge. With 8-12 bit precisions almost the same results are obtained as that with the conventional communication using 32-bit precision. The proposed method of communication can lead to significant savings in the intercommunication cost for implementations of artificial neural networks on parallel computers as well as the interconnection cost of direct hardware realizations. The method can be incorporated into most of the current learning algorithms in which inter-neuron communications are required. Moreover, it can be used along with the other limited precision strategies for representation of variables suggested in literature. Ali A. Ghorbani 0001, Virendrakumar C. Bhavsar |
IEEE Trans. Neural Networks | 1 |