EDBT 2026 Demo / reviewers in the wild / expert
M. Ali Aydin
dblp:10/569 · also Muhammed Ali Aydin
· DBLP profile ↗
15ranked-venue papers
0as first author
12since 2021 · last 2026
0000-0002-1846-6090ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy-preserving VPN handshakes with Schnorr-based zero-knowledge proofs
Mehmet Fatih Yuce, Mehmet Ali Ertürk, M. Ali Aydin |
Comput. Secur. | 3 |
| 2025 | State of the Art and First Synthetic Dataset for Misbehavior Detection with Collective Perception in [C-]V2X Networks*abstractAs vehicular networks evolve into fully connected intelligent transportation systems, Collective Perception (CP) enables vehicles and infrastructure to share sensor data for enhanced situational awareness. However, this cooperation introduces new attack surfaces, making misbehavior detection essential for securing [C-]V2X communications. Despite advances in machine learning, no public dataset exists for misbehavior detection in CP scenarios. This work introduces the first synthetic dataset tailored for this purpose and applies a spatio-temporal graph neural network (ST-GNN) model to it. The paper also surveys state-of-the-art approaches to misbehavior detection in CP-enabled V2X and discusses integration into open-source cooperative perception frameworks. By addressing both data and model gaps, this study supports practical and secure deployment of CP in future V2X systems. To the best of our knowledge, this is the first publicly available dataset and evaluation pipeline supporting misbehavior detection over standardized CPMs in [C-]V2X scenarios. Mehmet Fatih Yuce, Mehmet Ali Ertürk, M. Ali Aydin, Gulsum Zeynep Gurkas Aydin |
PIMRC | 3 |
| 2025 | Design of an autonomous multi-agent-based defense system against DDoS attacks in the Industrial Internet of Things (IIoT) environmentabstractAbstract With widespread adoption across industries, Industrial Internet of Things (IIoT) environments have become prime targets for cyberattacks. Moreover, the complexity and scale of these attacks can involve highly sophisticated, artificial intelligence (AI)–enabled, and even autonomous capabilities, occurring at machine speeds and making conventional defensive mechanisms insufficient. Therefore, defensive systems must possess considerable autonomy to detect and mitigate such attacks effectively and promptly. This work presents an IIoT cyber defense system (NS-IoT) that integrates the sensitivity of Deep Reinforcement Learning (DRL) with the agility of multi-agent systems, providing an autonomous defense solution for distributed denial of service (DDoS) attacks. The NS-IoT system consists of two modules: detection and defense. For the detection module, a Deep Q-Network (DQN)-based agent (DQN-IoT) was developed to detect DDoS attacks. This agent employs DRL techniques to treat attack classification like a guessing game, leverages feedback to improve decision-making within the Markov Decision Process (MDP), and combines rewards for enhanced performance. In this study, DDoS attacks were detected using the proposed DQN-IoT model, achieving 98.43% and 98.05% accuracy on the CIC-IoT-2022 and CIC-IoT-2023 datasets, respectively. While these results highlight the model’s effectiveness, real-time response speed is crucial in real-time events. Therefore, the proposed NS-IoT system addresses this need with its autonomous multi-agent structure, which minimizes human intervention. Hakan Aydin, Gulsum Zeynep Gurkas Aydin, Ahmet Sertbas, M. Ali Aydin |
Comput. J. | 4 |
| 2025 | An Effective Federated Learning Approach for Secure and Private Scalable Intrusion Detection on the Internet of VehiclesabstractABSTRACT The rapid proliferation of connected vehicles in the Internet of Vehicles (IoV) has introduced significant data security and privacy challenges, emphasizing the need for advanced intrusion detection systems (IDS). This article proposes a federated learning‐based intrusion detection system (FL‐IDS), explicitly designed to identify both external network‐level threats and internal vehicular cyberattacks. Federated learning enables collaborative training across distributed vehicles without sharing raw data, significantly reducing communication overhead and preserving data privacy. To further enhance privacy, differential privacy (DP) mechanisms are applied, ensuring sensitive information remains protected even during model updates. Additionally, secure communication channels are established using Secure Sockets Layer/Transport Layer Security (SSL/TLS) protocols, effectively safeguarding the integrity and authenticity of data exchanges between vehicles, roadside units, and cloud servers. Robust preprocessing methods, including data balancing, normalization, and feature selection, are combined with an adaptive federated learning strategy (FedXgbBagging) specifically designed to address the challenges posed by heterogeneous and non‐independent and identically distributed (non‐IID) data. Extensive evaluations on two real‐world datasets, CSE‐CIC‐IDS2018 for network attacks and CICIoV2024 for in‐vehicle Controller Area Network (CAN) bus attacks—show remarkable performance, achieving accuracy rates of 99.64% and 99.99%, respectively. The proposed FL‐IDS significantly outperforms existing methods, demonstrating its robustness, adaptability, and scalability in securing IoV environments against diverse cyber threats. Wisam Makki Alwash, Mustafa Kara, M. Ali Aydin, Hasan Hüseyin Balik |
Concurr. Comput. Pract. Exp. | 3 |
| 2023 | Android Malware Detection in Bytecode Level Using TF-IDF and XGBoostabstractAbstract Android is the dominant operating system in the smartphone market and there exists millions of applications in various application stores. The increase in the number of applications has necessitated the detection of malicious applications in a short time. As opposed to dynamic analysis, it is possible to obtain results in a shorter time in static analysis as there is no need to run the applications. However, obtaining various information from application packages using reverse engineering techniques still requires a substantial amount of processing power. Although some attempts have been made to solve this problem by analyzing binary files without decoding the source code, there is still more work to be done in this area. In this study, we analyzed the applications in bytecode level without decoding the binary source files. We proposed a model using Term Frequency - Inverse Document Frequency (TF-IDF) word representation for feature extraction and Extreme Gradient Boosting (XGBoost) method for classification. The experimental results show that our model classifies a given application package as a malware or benign in 2.75 s with 99.05% F1-score on a balanced dataset, and in 3.30 s with 99.35% F1-score on an imbalanced dataset containing obfuscated malwares. Gokhan Ozogur, Mehmet Ali Ertürk, Gulsum Zeynep Gurkas Aydin, M. Ali Aydin |
Comput. J. | 4 |
| 2023 | VoIPChain: A decentralized identity authentication in Voice over IP using Blockchain
Mustafa Kara, Hisham R. J. Merzeh, M. Ali Aydin, Hasan Hüseyin Balik |
Comput. Commun. | 3 |
| 2023 | A Framework for Personalized Human Activity RecognitionabstractIn today’s world, Human Activity Recognition (HAR) through video streams is actively used in every aspect of our life, such as automated surveillance systems and sports statistics are computed according to the videos with the help of HAR. Activity detection is not a new subject, and several methods are available. However, the most recent and most promising techniques rely on Convolutional Neural Networks (CNNs). CNNs primary usage is based on a single image frame to perform logical or categorical identification of an object, scene, or activity. We exploit this feature to adapt CNN on video streams to achieve HAR. In this study, we present a Personalized HAR (PHAR) framework that increases activity recognition accuracy with Object Detection (OD). First, we demonstrate the state-of-the-art HAR and OD methods in the literature. Then we illustrate our framework with two new Single Person Human Activity Recognition models. Finally, the performance of the new framework is evaluated with the well-known activity detection methods. Results show that our new PHAR model with 95% accuracy ratio outperforms the CNN-LSTM-based reference model (90%). Moreover, a new metric Average Accuracy Score (AAS) is described in this study, PHAR models approximately have 94% AAS, which is better than the reference model with 89% AAS. Hasan Ali Eris, Mehmet Ali Ertürk, M. Ali Aydin |
Int. J. Pattern Recognit. Artif. Intell. | 3 |
| 2022 | Machine Learning-Based Security Test Model and Evaluation for SIP-Based DoS AttacksabstractIn recent years, with the development of IP-based systems, circuit-switched systems have rapidly started to be replaced by packet-switched systems in communication infrastructures and operators have started to prefer VoIP systems more due to their advantages such as cost and resource efficiency. However, since VoIP (Voice over Internet Protocol) systems are equally open to all threats to which IP-based systems are open, researchers have proposed different methods for obtaining strong security solutions. Recently, rule-based systems have been replaced by machine learning-based systems in many areas and different machine learning-based solutions have been suggested for VoIP security.In this study, a machine learning-based solution was proposed for detecting SIP flooding attacks within the scope of DoS (Denial of Service) attacks which is one of the current threats to VoIP infrastructure. For this purpose, a test environment was created on a previously developed simulation infrastructure, primarily normal traffic and attack traffic were generated, and then the effectiveness of certain machine learning methods in the classification of traffic was tested with the labeled data obtained.When the results are evaluated with the parameters based on the working conditions, it is observed that the related methods can produce meaningful results. Sabit Çakir, Ahmet Sertbas, M. Ali Aydin |
INISTA | 3 |
| 2022 | MGA-IDS: Optimal feature subset selection for anomaly detection framework on in-vehicle networks-CAN bus based on genetic algorithm and intrusion detection approach
Dogukan Aksu, M. Ali Aydin |
Comput. Secur. | 2 |
| 2022 | A long short-term memory (LSTM)-based distributed denial of service (DDoS) detection and defense system design in public cloud network environment
Hakan Aydin, Zeynep Orman, M. Ali Aydin |
Comput. Secur. | 3 |
| 2022 | A Novel Password Policy Focusing on Altering User Password Selection Habits: A Statistical Analysis on Breached Data
Ebu Yusuf Güven, Ali Boyaci, M. Ali Aydin |
Comput. Secur. | 3 |
| 2021 | A New Geometric Data Perturbation Method for Data Anonymization Based on Random Number GeneratorsabstractWith the technology’s rapid development and its involvement in all areas of our lives, the volume and value of data have become a significant field of study. Valuation of the data to this extent has produced some consequences in terms of people’s knowledge. Data anonymization is the most important of these issues in terms of the security of personal data. Much work has been done in this area and continues to being done. In this study, we proposed a method called RSUGP for the anonymization of sensitive attributes. A new noise model based on random number generators has been proposed instead of the Gaussian noise or random noise methods, which are being used conventionally in geometric data perturbation. We tested our proposed RSUGP method with six different databases and four different classification methods for classification accuracy and attack resistance; then, we presented the results section. Experiments show that the proposed method was more successful than the other two classification accuracy, attack resistance, and runtime. Merve Kanmaz, M. Ali Aydin, Ahmet Sertbas |
J. Web Eng. | 2 |
| 2017 | LoRaWAN as an e-Health Communication TechnologyabstractLoRaWAN is a Low Power Wide Area Network (LPWAN) technology which enables low cost and low power IoT device communication even in dense urban areas. LoRa modulation is capable of extracting data from a weak signal in noisy environments. This modulation technique can be useful for the delivery of critical data in the noisy environment. In this study, we investigate LoRaWAN technology in the context of data transmission for health care systems (or critical health data in disaster environments). In the study, we explore the standard and evaluate data frame transmission in LoRaWAN with a custom test-bed system. M. Talha Buyukakkaslar, Mehmet Ali Ertürk, M. Ali Aydin, Luca Vollero |
COMPSAC (2) | 3 |
| 2012 | Half cycling dynamic bandwidth allocation with prediction on EPONabstractThis study is about a prediction approach for our previous dynamic bandwidth allocation algorithm for Ethernet Passive Optical Networks (EPON). Our previous work (hcDBA) is based on half cycle timing for bandwidth allocation. That can be handled as a middle way between online and offline bandwidth allocation schemes. In PONs, prediction is used for bandwidth allocation to grant loaded nodes with early responses. However, due to the versatile nature of data traffic, prediction algorithms have a handicap to provide a better solution in classical approaches. In this study, a novel prediction approach integrated with hcDBA algorithm described. Performance comparison of hcDBA with & without prediction and IPACT algorithm is given. According to the simulation results, prediction on hcDBA seems to give some performance improvements in terms of access-delay. Özgür Can Turna 0001, M. Ali Aydin, Tülin Atmaca |
ISCC | 2 |
| 2011 | Traffic characterization study on EPON upstream channelabstractMetropolitan ring networks are usually used to connect the high speed backbone networks with access networks. Until now, the metropolitan network and the access network are gained much attention of researchers. However they have been investigated in separate ways. There is no work in which the end-to-end performance from end-users of the access network to metropolitan network is evaluated. How to simulate a complete end-to-end network while keeping basic characteristics of access and metro traffic is an emergence problem to evaluate the end-to-end performance. In reality, a complete end-to-end network in which hundreds of Ethernet Passive Optical Network (EPON) are connected to metro ring networks cannot be simulated because of the huge amount of traffic generated from the access network side. In this paper, we aim to obtain trace files of incoming traffic at the entrance of Optical Line Terminal (OLT) by running simulations of an EPON network which implements Interleaved Polling with Adaptive Cycle Time (IPACT). Then, the generated traffic pattern will be characterized in order to find corresponding traffic model among well known traffic models and this model will be used as output traffic of OLTs. After, we can use this traffic model without simulating a complete EPON network. Through various simulations, we observe that the generated traffic that comes to OLT is similar to the traffic obtained with Poisson sources. Özgür Can Turna 0001, M. Ali Aydin, Tülin Atmaca, Tuan-Dung Nguyen |
IWCMC | 2 |