EDBT 2026 Demo / reviewers in the wild / expert
Ali Shoker
dblp:119/1714
· DBLP profile ↗
20ranked-venue papers
7as first author
10since 2021 · last 2026
0000-0002-4898-9394ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 1 first-author · 1 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SETPA: Structural evasion techniques for PDF malware detection systems
Nasir Iqbal, Hassan Jalil Hadi, Naveed Ahmad 0003, Ali Shoker |
Comput. Secur. | 5 |
| 2026 | A Gateway-Assisted Fine-Grained Data Sharing Scheme for Cross-Domain IIoTabstractCross-domain data sharing is essential for industrial 4.0, envisioning for intelligent manufacturing, equipment collaboration and industrial automation. Inherently, gearing by the interconnection of devices and systems across heterogeneous domains, how to ensure efficient and secure multi-party data sharing remains a critical challenge in the Industrial Internet of Things (IIoT). Many broadcast encryption and signature encryption schemes have been proposed to ensure the privacy and rapid sharing of cross-domain data in recent years . However, existing schemes still have shortcomings in supporting fine-grained access control and adapting to resource-constrained edge node deployments. To address this issue, this paper proposes a ciphertext policy attribute-based broadcast matching encryption scheme (CP-ABBME). This scheme integrates a ciphertext policy attribute-based encryption (CP-ABE) mechanism to achieve one-to-many secure ciphertext transmission in a fine-grained manner. Furthermore, considering the limited computation and storage resources of terminal devices, the proposed scheme builds an encapsulation–decapsulation chain architecture. It introduces bidirectional access control for mutual authentication between the sender and receiver, while offloading deployment and partial decryption to the receiving gateway. This design effectively reduces terminal-side computation and storage overhead during decryption and authentication. Formal security analysis shows that the proposed scheme meets stringent security requirements. Experimental results show that CP-ABBME improves the decryption performance by 39.3% to 99.6%, and reduces the terminal storage resource consumption by up to 9.35 KB. Chuanda Cai, Yue Cao 0002, Changbing Bi, Changgen Peng, Ali Shoker |
IEEE Internet Things J. | 5 |
| 2025 | EVSOAR: Security Orchestration, Automation and Response via EV Charging StationsabstractVehicle cybersecurity has emerged as a critical concern, driven by innovation in the automotive industry, e.g., autonomous, electric, or connected vehicles. Current efforts to address these challenges are constrained by the limited computational resources of vehicles and the reliance on connected infrastructures. This motivated the foundation of Vehicle Security Operations Centers (VSOCs) that extend IT-based Security Operations Centers (SOCs) to cover the entire automotive ecosystem, both the in-vehicle and off-vehicle scopes. Security Orchestration, Automation, and Response (SOAR) tools are considered key for implementing an effective cybersecurity solution. However, existing state-of-the-art solutions depend on infrastructure networks such as 4G, 5G, and WiFi, which often face scalability and congestion issues. To address these limitations, we propose a novel SOAR architecture EVSOAR that leverages the EV charging stations for connectivity and computing to enhance vehicle cybersecurity. Our EV-specific SOAR architecture enables real-time analysis and automated responses to cybersecurity threats closer to the EV, reducing cellular latency, bandwidth, and interference limitations. Our experimental results demonstrate a significant improvement in latency, stability, and scalability through the infrastructure and the capacity to deploy computationally intensive applications that are otherwise infeasible within the resource constraints of individual vehicles. Tadeu Freitas, Erick Silva, Rehana Yasmin, Ali Shoker, Manuel Eduardo Correia, Rolando Martins, Paulo Veríssimo |
VTC2025-Spring | 4 |
| 2025 | EVolve: A Value-Added Services Platform for Electric Vehicle Charging StationsabstractA notable challenge in Electric Vehicle (EV) charging is the time required to fully charge the battery, which can range from 15 minutes to 2-3 hours. However, this idle period for the EV presents an opportunity to offer time-consuming or data-intensive services such as vehicular software updates. ISO 15118 referred to the concept of Value-Added Services (VASs) in the charging scenario, but it remained underexplored in the literature. Our paper addresses this gap by proposing EVolve, the first EV charger compute architecture that supports secure on-charger universal applications with upstream and downstream communication. The architecture covers the end-to-end hardware/software stack, including standard API for vehicles and IT infrastructure. We demonstrate the feasibility and advantages of EVolve by employing and evaluating three suggested valueadded services: vehicular software updates, security information and event management (SIEM), and secure payments. The results demonstrate significant reductions in bandwidth utilization and latency, as well as high throughput, which supports this novel concept and suggests a promising business model for Electric Vehicle charging station operation. Erick Silva, Tadeu Freitas, Rehana Yasmin, Ali Shoker, Paulo Veríssimo |
VTC2025-Spring | 4 |
| 2025 | ResiLogic: Leveraging Composability and Diversity to Design Fault and Intrusion Resilient ChipsabstractA long-standing challenge is the design of chips resilient to faults and glitches. Both fine-grained gate diversity and coarse-grained modular redundancy have been used in the past. However, these approaches have not been well-studied under other threat models where some stakeholders in the supply chain are untrusted. Increasing digital sovereignty tensions raise concerns regarding the use of foreign off-the-shelf tools and intellectual property (IP), or off-sourcing fabrication, driving research into the design of resilient chips under this threat model. This article addresses a threat model considering three pertinent attacks to resilience: distribution, zonal, and compound attacks. To mitigate these attacks, we introduce theResiLogicframework that exploitsDiversity by Composability: constructing diverse circuits composed of smaller diverse ones by design. This approach enables designers to develop circuits in the early stages of design without the need for additional redundancy in terms of space or cost. To generate diverse circuits, we propose a technique using E-Graphs with new rewrite definitions for diversity. Using this approach at different levels of granularity is shown to improve the resilience of circuit design inResiLogicup to$\times 5$against the three considered attacks. Ahmad T. Sheikh, Ali Shoker, Suhaib A. Fahmy, Paulo Veríssimo |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2024 | Resilient and Secure Programmable System-on-Chip Accelerator OffloadabstractComputational offload to hardware accelerators is gaining traction due to increasing computational demands and efficiency challenges. Programmable hardware, like FPGAs, offers a promising platform in rapidly evolving application areas, with the benefits of hardware acceleration and software programmability. Unfortunately, such systems composed of multiple hardware components must consider integrity in the case of malicious components. In this work, we propose Samsara, the first secure and resilient platform that derives, from Byzantine Fault Tolerance (BFT), protocols to enhance the computing resilience of programmable hardware. Samsara uses a novel lightweight hardware-based BFT protocol for Systems-on-Chip, called H-Quorum, that implements the theoretical-minimum latency between applications and replicated compute nodes. To withstand malicious behaviors, Samsara supports hardware rejuvenation, which is used to replace, relocate, or diversify faulty compute nodes. Samsara's architecture ensures the security of the entire workflow while keeping the latency overhead, of both computation and rejuvenation, close to the non-replicated counterpart. Inês Pinto Gouveia, Ahmad T. Sheikh, Ali Shoker, Suhaib A. Fahmy, Paulo Veríssimo |
SRDS | 3 |
| 2023 | ScaIOTA: Scalable Secure Over-the-Air Software Updates for VehiclesabstractOver-the-Air (OTA) software updates are becoming essential for electric/electronic vehicle architectures in order to reduce recalls amid the increasing software bugs and vulnera-bilities. Current OTA update architectures rely heavily on direct cellular repository-to-vehicle links, which makes the repository a communication bottleneck, and increases the cellular bandwidth utilization cost as well as the software download latency. In this paper, we introduce ScalOTA, an end-to-end scalable OTA software update architecture and secure protocol for modern vehicles. For the first time, we propose using a network of update stations, as part of Electric Vehicle charging stations, to boost the download speed through these stations, and reduce the cellular bandwidth overhead significantly. Our formalized OTA update protocol ensures proven end-to-end chain-of-trust including all stakeholders: manufacturer, suppliers, update stations, and all layers of in-vehicle Electric Control Units (ECUs). The empirical evaluation shows that ScalOTA reduces the bandwidth utilization and download latency up to an order of magnitude compared with current OTA update systems. Ali Shoker, Fernando Alves, Paulo Veríssimo |
SRDS | 1 |
| 2023 | Intrusion Resilience Systems for Modern VehiclesabstractCurrent vehicular Intrusion Detection and Prevention Systems either incur high false-positive rates or do not capture zero-day vulnerabilities, leading to safety-critical risks. In addition, prevention is limited to few primitive options like dropping network packets or extreme options, e.g., ECU Bus-off state. To fill this gap, we introduce the concept of vehicular Intrusion Resilience Systems (IRS) that ensures the resilience of critical applications despite assumed faults or zero-day attacks, as long as threat assumptions are met. IRS enables running a vehicular application in a replicated way, i.e., as a Replicated State Machine, over several ECUs, and then requiring the replicated processes to reach a form of Byzantine agreement before changing their local state. Our study rides the mutation of modern vehicular environments, which are closing the gap between simple and resource-constrained "real-time and embedded systems", and complex and powerful "information technology" ones. It shows that current vehicle (e.g., Zonal) architectures and networks are becoming plausible for such modular fault and intrusion tolerance solutions—deemed too heavy in the past. Our evaluation on a simulated Automotive Ethernet network running two state-of-the-art agreement protocols (Damysus and Hotstuff) shows that the achieved latency and throughout are feasible for many Automotive applications. Ali Shoker, Vincent Rahli, Jeremie Decouchant, Paulo Veríssimo |
VTC2023-Spring | 1 |
| 2022 | Exon: An Oblivious Exactly-Once Messaging ProtocolabstractTCP is typically the default transport protocol of choice for its supposed reliability, even for message-oriented middleware (e.g., ZeroMQ) or inter-actor communication (e.g., distributed Erlang). However, under network issues, TCP con-nections can fail, which requires ensuring both at-least-once and at-most-once delivery at the upper middleware layer. Moreover, the use of TCP at scale, in highly concurrent systems, can lead to drastic performance loss due to the need for TCP connection multiplexing and the resulting head-of-line blocking. This paper introduces Exon, an oblivious exactly-once messaging protocol, and a corresponding lightweight library implementation. Exon uses a novel strategy of a per-message four-way protocol to ensure oblivious exactly-once messaging, with on-demand protocol-level “soft half-connections” that are established when needed and safely discarded. This achieves correctness, obliviousness, and performance, through merging and pipelining basic protocol mes-sages. The empirical evaluation of Exon demonstrates significant improvements in throughput and latency under packet loss, while maintaining a negligible overhead over TCP in healthy networks. Ziad Kassam, Paulo Sérgio Almeida, Ali Shoker |
ICCCN | 3 |
| 2021 | ASPAS: As Secure as Possible Available Systems
Houssam Yactine, Ali Shoker, Georges Younes 0002 |
DAIS | 2 |
| 2018 | Brief Announcement: Sustainable Blockchains through Proof of eXercise
Ali Shoker |
PODC | 1 |
| 2018 | Delta state replicated data types
Paulo Sérgio Almeida, Ali Shoker, Carlos Baquero |
J. Parallel Distributed Comput. | 2 |
| 2017 | Aggregation protocols in light of reliable communicationabstractAggregation protocols allow for distributed lightweight computations deployed on ad-hoc networks in a peer-to-peer fashion. Due to reliance on wireless technology, the communication medium is often hostile which makes such protocols susceptible to correctness and performance issues. In this paper, we study the behavior of aggregation protocols when subject to communication failures: message loss, duplication, and network partitions. We show that resolving communication failures at the communication layer, through a simple reliable communication layer, reduces the overhead of using alternative fault tolerance techniques at upper layers, and also preserves the original accuracy and simplicity of protocols. The empirical study we drive shows that tradeoffs exist across various aggregation protocols, and there is no one-size-fits-all protocol. Ziad Kassam, Ali Shoker, Paulo Sérgio Almeida, Carlos Baquero |
NCA | 2 |
| 2017 | Sustainable blockchain through proof of exerciseabstractCryptocurrency and blockchain technologies are recently gaining wide adoption since the introduction of Bitcoin, being distributed, authority-free, and secure. Proof of Work (PoW) is at the heart of blockchain's security, asset generation, and maintenance. Although simple and secure, a hash-based PoW like Bitcoin's puzzle is often referred to as “useless”, and the used intensive computations are considered “waste” of energy. A myriad of Proof of “something” alternatives have been proposed to mitigate energy consumption; however, they either introduced new security threats and limitations, or the “work” remained far from being really “useful”. In this work, we introduce Proof of eXercise (PoX): a sustainable alternative to PoW where an eXercise is a real world matrix-based scientific computation problem. We provide a novel study of the properties of Bitcoin's PoW, the challenges of a more “rational” solution as PoX, and we suggest a comprehensive approach for PoX. Ali Shoker |
NCA | 1 |
| 2016 | Exploiting universal redundancyabstractFault tolerance is essential for building reliable services; however, it comes at the price of redundancy, mainly the “replication factor” and “diversity”. With the increasing reliance on Internet-based services, more machines (mainly servers) are needed to scale out, multiplied with the extra expense of replication. This paper revisits the very fundamentals of fault tolerance and presents “artificial redundancy”: a formal generalization of “exact copy” redundancy in which new sources of redundancy are exploited to build fault tolerant systems. On this concept, we show how to build “artificial replication” and design “artificial fault tolerance” (AFT). We discuss the properties of these new techniques showing that AFT extends current fault tolerant approaches to use other forms of redundancy aiming at reduced cost and high diversity. Ali Shoker |
NCA | 1 |
| 2015 | Making BFT Protocols Really AdaptiveabstractMany state-machine Byzantine Fault Tolerant (BFT) protocols have been introduced so far. Each protocol addressed a different subset of conditions and use-cases. However, if the underlying conditions of a service span different subsets, choosing a single protocol will likely not be a best fit. This yields robustness and performance issues which may be even worse in services that exhibit fluctuating conditions and workloads. In this paper, we reconcile existing state-machine BFT protocols in a single adaptive BFT system, called ADAPT, aiming at covering a larger set of conditions and use-cases, probably the union of individual subsets of these protocols. At anytime, a launched protocol in ADAPT can be aborted and replaced by another protocol according to a potential change (an event) in the underlying system conditions. The launched protocol is chosen according to an "evaluation process" that takes into consideration both: protocol characteristics and its performance. This is achieved by applying some mathematical formulas that match the profiles of protocols to given user (e.g., service owner) preferences. ADAPT can assess the profiles of protocols (e.g., throughput) at run-time using Machine Learning prediction mechanisms to get accurate evaluations. We compare ADAPT with well known BFT protocols showing that it outperforms others as system conditions change and under dynamic workloads. Jean Paul Bahsoun, Rachid Guerraoui, Ali Shoker |
IPDPS | 3 |
| 2014 | Making Operation-Based CRDTs Operation-Based
Carlos Baquero, Paulo Sérgio Almeida, Ali Shoker |
DAIS | 3 |
| 2013 | RAC: A Freerider-Resilient, Scalable, Anonymous Communication ProtocolabstractEnabling anonymous communication over the Internet is crucial. The first protocols that have been devised for anonymous communication are subject to freeriding. Recent protocols have thus been proposed to deal with this issue. However, these protocols do not scale to large systems, and some of them further assume the existence of trusted servers. In this paper, we present RAC, the first anonymous communication protocol that tolerates freeriders and that scales to large systems. Scalability comes from the fact that the complexity of RAC in terms of the number of message exchanges is independent from the number of nodes in the system. Another important aspect of RAC is that it does not rely on any trusted third party. We theoretically prove, using game theory, that our protocol is a Nash equilibrium, i.e, that freeriders have no interest in deviating from the protocol. Further, we experimentally evaluate RAC using simulations. Our evaluation shows that, whatever the size of the system (up to 100.000 nodes), the nodes participating in the system observe the same throughput. Sonia Ben Mokhtar, Gautier Berthou 0002, Amadou Diarra, Vivien Quéma, Ali Shoker |
ICDCS | 5 |
| 2013 | Improving Independence of Failures in BFTabstractIndependence of failures is a basic assumption for the correctness of BFT protocols. In literature, this subject was addressed by providing N-version like abstractions. Though this can provide a good level of obfuscation against semantic-based attacks, if the replicas know each others identities then non-semantic attacks like DoS can still compromise all replicas together. In this paper, we address the obfuscation problem in a different way by keeping replicas unaware of each other. This makes it harder for attackers to sneak from one replica to another and reduces the impact of simultaneous attacks on all replicas. For this sake, we present a new obfuscated BFT protocol, called OBFT, where the replicas remain unaware of each other by exchanging their messages through the clients. Thus, OBFT assumes honest, but possibly crash-prone clients. We show that obfuscation in our context could not be achieved without this assumption, and we give possible applications where this assumption can be accepted. We evaluated our protocol on an Emulab cluster with a wide area topology. Our experiments show that the scalability and throughput of OBFT remain comparable to existing BFT protocols despite the obfuscation overhead. Ali Shoker, Jean Paul Bahsoun, Maysam Yabandeh |
NCA | 1 |
| 2012 | Towards Byzantine Resilient DirectoriesabstractNotable Byzantine Fault Tolerant protocols have been designed so far. These protocols are often evaluated on simple benchmarks, and few times on NFS systems. On the contrary, studies that addressed the behavior of BFT on large back-ends, like Directories, are few. We believe that studying such systems is crucial for practice community due to their popularity. In this paper, we integrate BFT with OpenLDAP Directory. We introduce the design of the integrated system, that we call BFT-LDAP. Then, we study its behavior accompanied with some useful observations. In addition, we discuss the cost overhead of this integration. Our approach ensures that OpenLDAP legacy code remains completely intact, and that the integration with BFT is straightforward using APIs. Moreover, we convey that the additional performance cost of BFT-LDAP is negligible as compared to that of stand-alone OpenLDAP. We conducted our experiments on Emulab. The experiments indicate that the performance discrepancy of BFT-LDAP is negligible whenever different state-of-the-art BFT protocols are used. Other experiments demonstrate that a little sacrifice in throughput (less than 10%) is needed in order to leverage the resiliency of OpenLDAP against Byzantine faults (i.e., through applying BFT). Ali Shoker, Jean Paul Bahsoun |
NCA | 1 |