EDBT 2026 Demo / reviewers in the wild / expert
Issa M. Khalil
dblp:115/8715 · also Issa Khalil
· DBLP profile ↗
5ranked-venue papers in the field
0as first author
5since 2021 · last 2025
0000-0002-7660-9512ORCID · verified
Domains — venue-derived; a paper can count in several
Big Data, Cloud & Distributed Data Systems · 3Other / Interdisciplinary · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SGFusion: Stochastic Geographic Gradient Fusion in Federated Learning
Khang Tran, NhatHai Phan, Cristian Borcea, Ruoming Jin, Issa M. Khalil |
IEEE Big Data | 6 |
| 2025 | Adaptive Inter-Modality Attention for Enhanced Cross-Domain Deepfake Detection TransferabilityabstractCross-domain generalization remains a critical challenge in deepfake detection, with existing methods exhibiting severe performance degradation across unseen generative architectures. We propose CAMME (Cross-domain Adaptive Multi-Modal Embeddings), which dynamically integrates visual, textual, and frequency-domain features via embedding-level multi-modal self-attention. Treating each modality as a distinct sequence element enables cross-modal interactions that adaptively weight discriminative features based on input characteristics. Unlike static fusion approaches, CAMME learns input-specific contributions, dynamically emphasizing optimal signals across visual semantics, textual consistency, and spectral artifacts. Evaluation across twelve generative architectures demonstrates superior cross-domain performance: 77.34% average F1-score on natural scenes (7.30% improvement) and 66.46% on facial datasets (13.25% improvement). CAMME exhibits exceptional robustness with 14.7% Attack Success Rate against seven prominent adversarial attacks (4-6 × improvement) and 96.63% accuracy under natural perturbations. Ablation results confirm the importance of each modality and the effectiveness of our inter-modal attention over standard fusion methods. Naseem Khan, Nguyen Vu Tuan, Issa M. Khalil |
MMAsia | 3 |
| 2025 | Dynamic Routing between Multimodal Capsules for Deepfake Image Editing DetectionabstractState-of-the-art methods have demonstrated exceptional performance in detecting deepfakes, particularly when the entire image content is generated by text-to-image generation models. However, significant challenges remain in the cases of instructional image editing, where AI models conditionally generate content based on both a real image and an edit prompt. In such scenarios, the generated content closely resembles the original image, making it more difficult for detection systems to identify deepfakes. In this paper, we propose a novel multimodal capsule network designed to address the detection of deepfake image editing. Specifically, low-level capsules from multiple modalities are integrated to predict capsules in subsequent layers. High-level capsules compete to select relevant low-level capsules, effectively aggregating local features to detect manipulated entities. The proposed approach is evaluated on diverse datasets, including natural images from real-world scenarios. Experimental results demonstrate that our model significantly outperforms state-of-the-art methods, achieving a substantial 10% improvement in Three-turn Edits or 20% improvement in Open Images Edits. Ablation studies further validate the robustness of the network, achieving detection rates exceeding 94% against natural perturbations and over 91% recall against white-box and black-box attacks. Additionally, the model effectively adapts to unseen image editing datasets, highlighting its ability to generalize across diverse and previously unencountered editing scenarios. Naseem Khan, Issa M. Khalil |
MMAsia | 3 |
| 2022 | Heterogeneous Randomized Response for Differential Privacy in Graph Neural NetworksabstractGraph neural networks (GNNs) are susceptible to privacy inference attacks (PIAS) given their ability to learn joint representation from features and edges among nodes in graph data. To prevent privacy leakages in GNNs, we propose a novel heterogeneous randomized response (HeteroRR) mechanism to protect nodes’ features and edges against PIAS under differential privacy (DP) guarantees, without an undue cost of data and model utility in training GNNs. Our idea is to balance the importance and sensitivity of nodes’ features and edges in redistributing the privacy budgets since some features and edges are more sensitive or important to the model utility than others. As a result, we derive significantly better randomization probabilities and tighter error bounds at both levels of nodes’ features and edges departing from existing approaches, thus enabling us to maintain high data utility for training GNNs. An extensive theoretical and empirical analysis using benchmark datasets shows that HeteroRR significantly outperforms various baselines in terms of model utility under rigorous privacy protection for both nodes’ features and edges. That enables us to defend PIAs in DP-preserving GNNs effectively. Khang Tran, Phung Lai, NhatHai Phan, Issa M. Khalil, Yao Ma 0001, Abdallah Khreishah, My T. Thai, Xintao Wu |
IEEE Big Data | 4 |
| 2021 | A Synergetic Attack against Neural Network Classifiers combining Backdoor and Adversarial ExamplesabstractThe pervasiveness of neural networks (NNs) in critical computer vision and image processing applications makes them very attractive for adversarial manipulation. A large body of existing research thoroughly investigates two broad categories of attacks targeting the integrity of NN models. The first category of attacks, commonly called Adversarial Examples, perturbs the model’s inference by carefully adding noise into input examples. In the second category of attacks, adversaries try to manipulate the model during the training process by implanting Trojan backdoors. Researchers show that such attacks pose severe threats to the growing applications of NNs and propose several defenses against each attack type individually. However, such one-sided defense approaches leave potentially unknown risks in real-world scenarios when an adversary can unify different attacks to create new and more lethal ones bypassing existing defenses.In this work, we show how to jointly exploit adversarial perturbation and model poisoning vulnerabilities to practically launch a new stealthy attack, dubbed AdvTrojan. AdvTrojan is stealthy because it can be activated only when: 1) a carefully crafted adversarial perturbation is injected into the input examples during inference, and 2) a Trojan backdoor is implanted during the training process of the model. We leverage adversarial noise in the input space to move Trojan-infected examples across the model decision boundary, making it difficult to detect. The stealthiness behavior of AdvTrojan fools the users into accidentally trusting the infected model as a robust classifier against adversarial examples. AdvTrojan can be implemented by only poisoning the training data similar to conventional Trojan backdoor attacks. Our thorough analysis and extensive experiments on several benchmark datasets show that AdvTrojan can bypass existing defenses with a success rate close to 100% in most of our experimental scenarios and can be extended to attack federated learning as well as high-resolution images. Guanxiong Liu, Issa M. Khalil, Abdallah Khreishah, NhatHai Phan |
IEEE BigData | 2 |