EDBT 2026 Demo / reviewers in the wild / expert
Mohammad Saiful Islam Mamun
dblp:117/9459 · also Mohammad Mamun 0001
· DBLP profile ↗
33ranked-venue papers
14as first author
20since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 10 first-author · 12 since 2021Computer networks · 5 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Autonomous Adversary: Red-Teaming in the Age of LLM
Mohammad Saiful Islam Mamun, Mohamed Gaber, Scott Buffett, Sherif Saad |
ACISP (3) | 1 |
| 2026 | Preserving data and model privacy during inference and training
William Briguglio, Issa Traoré, Mohammad Saiful Islam Mamun, Waleed A. Yousef, Sherif Saad |
Expert Syst. Appl. | 3 |
| 2025 | Synthetic Lateral Movement Data Generation for Azure Cloud: A Hopper-Based Approach
Mohammad Saiful Islam Mamun, Hadeer Ahmed, Anas Mabrouk, Sherif Saad |
CANS | 1 |
| 2025 | Drift-RL: A Reinforcement Learning Framework for Simulating Textual Data Drift in Cybersecurity
Hadeer Ahmed, Issa Traoré, Sherif Saad, Mohammad Saiful Islam Mamun |
CRiSIS | 4 |
| 2025 | Privacy-Preserving Logistic Regression Prediction over Vertically Partitioned Data for AiP SystemabstractAging in Place (AiP) programs enable elderly individuals to live independently and comfortably within their homes and communities by utilizing technological innovations such as smart homes and remote healthcare monitoring. In practical AiP scenarios, data necessary for accurate health predictions are typically vertically partitioned across multiple medical institutions, raising significant privacy concerns during data integration and analysis. To address this challenge, we propose an efficient and privacy-preserving logistic regression (LR) prediction scheme tailored explicitly for vertically partitioned AiP data. Our scheme effectively combines the computational efficiency of Trusted Execution Environments (TEE) under the honest-but-curious model with cryptographic security based on the Matrix Diffie-Hellman (MDDH) assumption. Security analysis confirms that our approach provides privacy protections against honest-but-curious adversaries. Extensive experimental evaluations demonstrate that our proposed scheme achieves computational efficiency, privacy protection, and practical scalability for real-world AiP implementations. Zhuliang Jia, Suprio Ray, Rongxing Lu, Mohammad Saiful Islam Mamun |
GLOBECOM | 4 |
| 2025 | Towards Efficient and Privacy-Preserving Data Sharing Scheme for Aging in PlaceabstractWith the global aging population rising rapidly, the Aging in Place (AiP) system has gained significant attention and is seen as a vital strategy for meeting the diverse needs of older adults. In the AiP system, Electronic Health Records (EHRs) play a critical role in managing the healthcare records of older adults. Compared to traditional medical records, EHRs in AiP include not only clinical data but also data from Internet of Things (IoT) devices, social determinants of health, and other sources, resulting in a significant increase in the volume of EHRs. Consequently, preserving the privacy of these EMRs while sharing with access control in AiP scenarios becomes a significant challenge. Many data sharing schemes based on Attribute-Based Encryption (ABE) suffer from limited computational efficiency and inadequate privacy protections. To address these issues, we propose an efficient and privacy-preserving data sharing scheme for AiP systems. Our scheme not only facilitates the sharing of large files with matched users but also conceals the policy from other users. Furthermore, our proposed scheme is secure under the semi-honest model, and experiments demonstrate its high efficiency. Zhuliang Jia, Jinkun Gui, Rongxing Lu, Mohammad Saiful Islam Mamun |
ICC | 4 |
| 2025 | Adaptive Ensemble Defense: Mitigating NLP Adversarial Attacks with Data-Augmented Voting Mechanisms
Amira Abdelbaky, Sherif Saad, Mohammad Saiful Islam Mamun |
ICISSP (2) | 3 |
| 2025 | An Alternative Approach to Federated Learning for Model Security and Data PrivacyabstractFederated learning (FL) enables machine learning on data held across multiple clients without exchanging private data. However, exchanging information for model training can compromise data privacy. Further, participants may be untrustworthy and can attempt to sabotage model performance. Also, data that is not independently and identically distributed (IID) impede the convergence of FL techniques. We present a general framework for federated learning via aggregating multivariate estimated densities (FLAMED). FLAMED aggregates density estimations of clients’ data, from which it simulates training datasets to perform centralized learning, bypassing problems arising from non-IID data and contributing to addressing privacy and security concerns. FLAMED does not require a copy of the global model to be distributed to each participant during training, meaning the aggregating server can retain sole proprietorship of the global model without the use of resource-intensive homomorphic encrypti on. We compared its performance to standard FL approaches using synthetic and real datasets and evaluated its resilience to model poisoning attacks. Our results indicate that FLAMED effectively handles non-IID data in many settings while also being more secure. William Briguglio, Waleed A. Yousef, Issa Traoré, Mohammad Saiful Islam Mamun, Sherif Saad |
ICISSP (1) | 4 |
| 2025 | HybridMTD: Enhancing Robustness Against Adversarial Attacks with Ensemble Neural Networks and Moving Target Defense
Kimia Tahayori, Sherif Saad, Mohammad Saiful Islam Mamun, Saeed Samet |
ICISSP (2) | 3 |
| 2025 | Thoth: A Lightweight Framework for End-to-End Consumer IoT Rapid TestingabstractThe rapid expansion of consumer IoT devices has increased the need for scalable, automated testing solutions. Manual methods are often slow, error-prone, and inadequate for capturing real-world IoT complexities. Existing frameworks typically lack comprehensiveness, quantifiable metrics, and support for cascading failure scenarios. This paper introduces Thoth, a lightweight, end-to-end IoT testing framework that addresses these limitations. Thoth enables holistic evaluation through integrated support for performance, reliability, recovery, security, and load testing. It also incorporates standardized metrics and real-time failure simulations, including cascading faults. We evaluated Thoth using eight test cases in a real-world health-monitoring setup involving a smartwatch, edge gateway, and cloud infrastructure. Key metrics—such as fault detection time, recovery speed, data loss, and energy usage—were logged and analyzed. Results show that Thoth detects faults in as little as 2.5 seconds, recovers in under 1 second, limits data loss to a few points, and maintains sub-1% energy overhead. These findings highlight its effectiveness for low-intrusion testing in resource-constrained environments. By combining scenario-driven design with reproducible, metrics-based evaluation, Thoth fills key gaps in IoT testing. Salma Roshdy Aly, Sherif Saad, Mohammad Saiful Islam Mamun |
ICSOFT | 3 |
| 2025 | An Efficient and Privacy-Preserving AdaBoost Federated Learning Framework for AiP SystemabstractAs the global population continues to age rapidly, Aging in Place (AiP) solutions have become increasingly vital for enabling elderly individuals to maintain their independence and continue living comfortably in their own homes. These solutions leverage advanced technologies such as smart homes and remote health monitoring. However, in real-world AiP applications, the health data needed for accurate predictions is often spread across multiple medical institutions, which raises signficant privacy concerns when integrating and analyzing the data. To address this challenge, we propose an efficient and privacy-preserving AdaBoost learning framework for vertically partitioned AiP data by utilizing Symmetric Homomorphic Encryption (SHE) technique. To ensure compatibility with the integer-based constraints of SHE, we adopt a straightforward weight quantization strategy by representing AdaBoost sample weights as integers. This design simplifies encrypted computation and maintains the boosting mechanism’s effectiveness. Our theoretical and experimental evaluations validate both the accuracy and security of the proposed framework, highlighting its practical viability for deployment in real-world AiP systems. Zhuliang Jia, Suprio Ray, Rongxing Lu, Mohammad Saiful Islam Mamun |
PST | 4 |
| 2024 | An Efficient Multicast Authenticated Encryption Scheme for Smart Elderly Care SystemsabstractUndoubtedly, smart elderly care systems can leverage Internet of Things (IoT) technology to enhance senior living services by integrating connected devices and sensors. Nevertheless, it is still a challenging issue to achieve secure and efficient multicast group communication among these IoT devices in smart elderly care systems, as IoT devices can dynamically become targets during multicast communication. To address this challenge, in this paper, we propose a new efficient multicast authenticated encryption scheme, which is characterized by integrating Merkle Tree, prefix encoding, XOR filters, and ASCON techniques to provide a robust solution for secure and personalized eldercare services in IoT-enabled environments. Security analysis demonstrates that our proposed scheme can satisfy the confidentiality and integrity requirements. In addition, the performance evaluation confirms that our proposed scheme is computationally efficient. Jinkun Gui, Zeming Zhou, Rongxing Lu, Mohammad Saiful Islam Mamun |
ICC | 5 |
| 2024 | Effect of Text Augmentation and Adversarial Training on Fake News DetectionabstractThe action of spreading false information through fake news articles presents a significant danger to society because it has the ability to shape public opinion with inaccurate facts. This can lead to negative effects, such as reduced trust in institutions and the promotion of conflict, division, and even violence. In this article, a text augmentation technique is introduced as a means of generating new data from preexisting fake news datasets. This approach has the potential to enhance classifier performance by a range of 3%–11%. It can also be utilized to launch a successful attack on trained classifiers, with up to a 90% success rate. However, the success rate of these attacks decreased to less than 28% when the model was retrained with the generated adversarial examples. These results demonstrate the effectiveness of text augmentation as a viable method for detecting fake news and increasing classifier accuracy and performance, as well as its ability to be utilized to perform adversarial machine learning (ML) and improve the resilience of ML algorithms. Hadeer Ahmed, Issa Traoré, Sherif Saad, Mohammad Saiful Islam Mamun |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2024 | Federated Supervised Principal Component AnalysisabstractIn federated learning, standard machine learning (ML) techniques are modified so they can be applied to data held by separate participants without the need for exchanging said data and while preserving privacy. Other data modelling techniques, such as singular value decomposition, have been similarly federated, enabling federated principal component analysis (PCA), which is a popular preprocessing step for ML tasks. Supervised PCA improves on standard PCA by using labeled data to retain more relevant information for supervised ML problems. However, a federated version of supervised PCA does not exist in the literature. In this paper, we propose a federated version of supervised PCA and its dual and kernel variations, called FeS-PCA, dual FeS-PCA, and FeSK-PCA, respectively. We used random orthogonal matrix masking to keep FeS-PCA and dual FeS-PCA private, while FeSK-PCA was kept private using an approximation of the standard approach. We tested our proposed approaches by recreating visualization, classification, and regression experiments from the original unfederated supervised PCA paper. We further added a real-world federated dataset to test the scalability and fidelity of our approach. Our analysis and results indicate that FeS-PCA and dual FeS-PCA are faithful, lossless, and private versions of their unfederated counterparts. Furthermore, despite being an approximation, FeSK-PCA achieves nearly identical performance to standard kernel SPCA in many cases. This is in addition to the added benefit of a reduced runtime and smaller memory footprint. William Briguglio, Waleed A. Yousef, Issa Traoré, Mohammad Saiful Islam Mamun |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Detecting BrakTooth AttacksabstractMore than 5.1 billion Bluetooth-enabled devices were shipped in the year 2022 and this trend is expected to exceed 7.1 billion by the year 2026. A large proportion of these devices are used in smart homes designed for older adults, to help them age in place. Monitoring vitals, climate control, illumination control, fall detection, incontinence detection, pill dispensing, and several other functions are successfully addressed by many of these Bluetooth-enabled devices. Therefore it becomes crucial to protect them from malicious attacks and ensure the safety and well-being of their users. Some of these devices have only Bluetooth connectivity which makes patching them challenging for older adults, as a result, most remain unpatched. The family of vulnerabilities recently found in the Bluetooth Classic (BT Classic) stack called BrakTooth, poses a genuine threat to such devices. In this study, we develop an experimental procedure to capture traffic at the Link Manager Protocol (LMP) layer of the BT Classic stack and use machine learning algorithms to detect BrakTooth-based attacks. Achyuth Nandikotkur, Issa Traoré, Mohammad Saiful Islam Mamun |
SECRYPT | 3 |
| 2022 | TapTree: Process-Tree Based Host Behavior Modeling and Threat Detection Framework via Sequential Pattern Mining
Mohammad Saiful Islam Mamun, Scott Buffett |
ICICS | 1 |
| 2022 | Towards a robust and trustworthy machine learning system development: An engineering perspective
Pulei Xiong, Scott Buffett, Shahrear Iqbal, Philippe Lamontagne 0001, Mohammad Saiful Islam Mamun, Heather Molyneaux |
J. Inf. Secur. Appl. | 5 |
| 2021 | DeepTaskAPT: Insider APT detection using Task-tree based Deep LearningabstractAPT, known as Advanced Persistent Threat, is a difficult challenge for cyber defence. These threats make many traditional defences ineffective as the vulnerabilities exploited by these threats are insiders who have access to and are within the network. This paper proposes DeepTaskAPT, a heterogeneous task-tree based deep learning method to construct a baseline model based on sequences of tasks using a Long Short-Term Memory (LSTM) neural network that can be applied across different users to identify anomalous behaviour. Rather than applying the model to sequential log entries directly, as most current approaches do, DeepTaskAPT applies a process tree based task generation method to generate sequential log entries for the deep learning model. To assess the performance of DeepTaskAPT, we use a recently released synthetic dataset, DARPA Operationally Transparent Computing (OpTC) dataset and a real-world dataset, Los Alamos National Laboratory (LANL) dataset. Both of them are composed of host-based data collected from sensors. Our results show that DeepTaskAPT outperforms similar approaches e.g. DeepLog and the DeepTaskAPT baseline model demonstrate its capability to detect malicious traces in various attack scenarios while having high accuracy and low false-positive rates. To the best of knowledge this is the very first attempt of using recently introduced OpTC dataset for cyber threat detection. Mohammad Saiful Islam Mamun, Kevin Shi |
TrustCom | 1 |
| 2021 | A lightweight multi-party authentication in insecure reader-server channel in RFID-based IoT
Mohammad Saiful Islam Mamun, Atsuko Miyaji, Rongxing Lu, Chunhua Su |
Peer-to-Peer Netw. Appl. | 1 |
| 2021 | Machine learning in precision medicine to preserve privacy via encryption
William Briguglio, Parisa Moghaddam, Waleed A. Yousef, Issa Traoré, Mohammad Saiful Islam Mamun |
Pattern Recognit. Lett. | 5 |
| 2020 | Privacy-Preserving Computation Offloading for Time-Series Activities Classification in eHealthcareabstractThe convergence of Internet of Things (IoT) and smart healthcare technologies has opened up various promising applications that can significantly improve the quality of healthcare services. Among those applications, predicting patients’ physical health based on their routine activities data collected from IoT devices is one of the most popular applications, where patients’ data are considered as time-series activities and patients’ physical health can be predicted by a classification model. Though many existing works have been exploited in this application, they either impose the computational costs of the classification on the healthcare center (e.g., hospitals) or delegate the cloud to process the classification without considering the privacy issues. However, since the healthcare center may not be powerful in computing and the cloud is not fully trusted, there is a high demand in offloading the computational cost of the healthcare center to the cloud while preserving the privacy of classification result against the cloud. Aiming at this challenge, in this paper, we present a novel privacy-preserving time-series activities classification algorithm by using hidden markov model (HMM). Specifically, we first design a variant of forward algorithm of HMM and further introduce a privacy-preserving variant of forward (PPVF) protocol for the variant of forward algorithm. Then, based on the PPVF protocol, we propose our classification algorithm, which can offload the computational cost of the healthcare center to the cloud and preserve the privacy of classification result. Finally, security analysis and performance show that our proposal is not only privacy-preserving but also efficient in terms of lower computational cost. Yandong Zheng, Rongxing Lu, Mohammad Saiful Islam Mamun |
ICC | 3 |
| 2019 | Tell Them from Me: An Encrypted Application Profiler
Mohammad Saiful Islam Mamun, Rongxing Lu, Manon Gaudet |
NSS | 1 |
| 2018 | SupAUTH: A new approach to supply chain authentication for the IoTabstractAbstract Recent advances of the Internet of Things (IoT) technologies have enhanced the use of radio‐frequency identification‐based tracking system to be widely deployed in supply chain management covering every step involved in the flow of merchandise from the supplier to the customer to ensure a trustworthy delivery environment. Such authentication system (also known as path authentication) not only guarantees the merchandise to be available in the right destination with no discrepancies and errors but also ensures the route of the merchandise progress to be valid. This paper outlines the current state‐of‐the‐art cryptographic solutions for path authentication, highlights their properties and weakness, and proposes a novel, privacy‐preserving, and efficient solution. Compared with the existing elliptic curve ElGamal re‐encryption–based solution, our homomorphic message authentication code on arithmetic circuit–based solution offers less memory storage (with limited scalability) and no computational requirement on the reader. Moreover, we allow computational ability inside the tag that articulates a new privacy direction to the state‐of‐the‐art path privacy. This privacy notion helps support the confidentiality of the tag movement in the context of IoT‐enabled cross‐organizational tracking environment where the stakeholders can be from different organizations associated together with the merchandise being delivered. As a potential extension to the path authentication protocol, we further propose a polynomial‐based mutual authentication as a security extension and batch initialization as an efficiency extension. Besides our brief security and privacy analysis, our evaluation shows that the proposed solution can significantly reduce memory requirements on tags with marginal computational overhead to ensure transmission path confidentiality. We observe that SupAUTH requires maximum 513‐bit tag memory and 57.3 ms of processing time during evaluation, which is not only practical but also suitable for any suitable low‐cost radio‐frequency identification deployment in IoT. Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001, Atsuko Miyaji, Uyen Trang Nguyen |
Comput. Intell. | 1 |
| 2018 | OTP-IoT: An ownership transfer protocol for the Internet of Things
Mohammad Saiful Islam Mamun, Chunhua Su, Anjia Yang, Atsuko Miyaji, Ali A. Ghorbani 0001 |
J. Inf. Secur. Appl. | 1 |
| 2017 | Characterization of Tor Traffic using Time based Features
Arash Habibi Lashkari, Gerard Draper-Gil, Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001 |
ICISSP | 3 |
| 2016 | Characterization of Encrypted and VPN Traffic using Time-related FeaturesabstractTraffic characterization is one of the major challenges in today’s security industry. The continuous evolution
and generation of new applications and services, together with the expansion of encrypted communications
makes it a difficult task. Virtual Private Networks (VPNs) are an example of encrypted communication service
that is becoming popular, as method for bypassing censorship as well as accessing services that are geographically
locked. In this paper, we study the effectiveness of flow-based time-related features to detect VPN traffic
and to characterize encrypted traffic into different categories, according to the type of traffic e.g., browsing,
streaming, etc. We use two different well-known machine learning techniques (C4.5 and KNN) to test the accuracy
of our features. Our results show high accuracy and performance, confirming that time-related features
are good classifiers for encrypted traffic characterization. Gerard Draper-Gil, Arash Habibi Lashkari, Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001 |
ICISSP | 3 |
| 2016 | Detecting Malicious URLs Using Lexical Analysis
Mohammad Saiful Islam Mamun, Mohammad Ahmad Rathore, Arash Habibi Lashkari, Natalia Stakhanova, Ali A. Ghorbani 0001 |
NSS | 1 |
| 2015 | An Entropy Based Encrypted Traffic Classifier
Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001, Natalia Stakhanova |
ICICS | 1 |
| 2015 | An efficient batch verification system and its effect in a real time VANET environmentabstractABSTRACT Vehicle ad hoc network (VANET) provides communication between vehicles and vehicle‐to‐infrastructure communication. High mobility, high speed of vehicles, fast topology changes, and sheer scale are some characteristics that establish VANET as an intensive research topic different from other types of mobile ad hoc network. In this paper, we improve an existing batch verification system on ID‐based group signature and also compare the performance achieved. Then, we analyze the best possible value of the number of signatures to batch at a time for large‐scale VANET. In addition, we introduce a scheduling algorithm for signature verification where batch verification cannot be implemented efficiently. Copyright © 2014 John Wiley & Sons, Ltd. Jiageng Chen, Mohammad Saiful Islam Mamun, Atsuko Miyaji |
Secur. Commun. Networks | 2 |
| 2014 | RFID Path Authentication, RevisitedabstractIn an RFID-enabled supply chain, where items are outfitted with RFID tags, path authentication based on tag enables the destination checkpoints to validate the route that a tag has already accessed. In this work, we propose a novel, efficient, privacy-preserving path authentication system for RFID-enabled supply chains. Compared to existing Elliptic curve Elgamal Re-encryption (ECElgamal) based solution, our Homomorphic Message authentication Code on arithmetic circuit (HomMAC) based solution offers less memory storage (with limited scalability) and no computational requirement on the reader. However, unlike previous schemes, we allow computational ability inside the tag that consents a new privacy direction to path privacy proposed by Cai et al. in ACNS012. In addition, we customize a polynomial-based authentication scheme (to thwart potential tag impersonation and Denial of Service (DoS) attacks), so that it fits our new path authentication protocol. Mohammad Saiful Islam Mamun, Atsuko Miyaji |
AINA | 1 |
| 2014 | A Scalable and Secure RFID Ownership Transfer ProtocolabstractOwnership transfer in an RFID inventory system experiences many security and privacy oriented problems. We consider scenarios related to ownership transfer of RFID tags in a large inventory system. In this paper, we propose a new mutual authentication protocol from Ring LPN problem that leverages the reader authentication phase to incorporate Semi-Trusted Parties (STP) seamlessly in RFID ownership transfer protocol. Employing STPs could ease the ownership transfer process for the consumers in the remote location. More precisely, we introduce a new variant of Learning Parity from Noise (LPN) based mutual authentication scheme for efficient ownership transfer protocol where ownership of multiple tags can be transferred from one owner to another by taking advantages of an efficient homomorphic aggregated signature (HomSig) and pseudo-inverse matrix properties. To the best of our knowledge, this is the first RFID ownership transfer protocol from LPN problem that is secure, private and scalable under standard model. Mohammad Saiful Islam Mamun, Atsuko Miyaji |
AINA | 1 |
| 2014 | Secure VANET applications with a refined group signatureabstractThis paper proposes an application-friendly group signature (GS) model for wireless ad hoc network like Wireless Sensor Networks (WSN) or Vehicle ad hoc Network (VANET). Our new GS properties can be used to carry out potential solution to some real life problems. We modify Boneh, Boyen and Shacham (BBS) short GS to meet a restricted, but arguably sufficient set of privacy properties. In particular, we aggregate linking, direct opening, message-dependent opening (MDO), revoking, batch-verification in a single short GS scheme. Our link manager can link messages whether they are coming from the same messages or not without colluding to the opener. It helps relaxing strong privacy properties of GS to a lightly lesser one that fit certain application requirement. We introduce a new application to the ad hoc network security, that is, value-added service provider (VSP) with the help of MDO properties and redesign the traditional GS-friendly VANET architecture. Our revocation algorithm adapts both rekeying and verifier-local revocation (VLR) approaches to revoke illegitimate signers in a constant time. Finally, we present an optional batch verification system to expedite signature verification. Note that all these properties have already been shown in the literature scatteredly. The novelty of our proposal stems from accumulating all these properties in a single GS scheme that can best fit to the application demand. Mohammad Saiful Islam Mamun, Atsuko Miyaji |
PST | 1 |
| 2012 | A Secure and Private RFID Authentication Protocol under SLPN Problem
Mohammad Saiful Islam Mamun, Atsuko Miyaji, Mohammad Shahriar Rahman |
NSS | 1 |