EDBT 2026 Demo / reviewers in the wild / expert
Muhammad Taqi Raza
dblp:12/7085 · also Taqi Raza
· DBLP profile ↗
23ranked-venue papers
12as first author
10since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 6 first-author · 6 since 2021Security and privacy · 6 · 4 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ORACLE: Reconciling Next-G Cellular Core Operations for Correctness
Muhammad Shayan Nazeer, Muhammad Taqi Raza |
ICC | 2 |
| 2026 | SynchroNB: Toward Robust Timing for 5G NB-IoT NetworksabstractEmerging resource-constrained cellular Internet of Things (IoT) applications such as drone swarms, autonomous vehicles, and remote surgery via mixed reality demand millisecond-level time synchronization. Narrow-Band IoT (NB-IoT), the leading low-power wide-area technology, struggles to meet these requirements. The root cause lies in the non-deterministic delays inherent in the 5G protocol design. Uplink reliability and scheduling mechanisms introduce asymmetric latencies that disrupt conventional time synchronization algorithms such as the Network Time Protocol (NTP). Time-critical packets are further affected by deep-sleep wake-up latency, base station scheduling delays, uplink/downlink asymmetry, and unpredictable drift from inexpensive oscillators. Together, these factors can accumulate into timing errors on the order of hundreds of milliseconds. In this paper, we first quantify timing errors across five dimensions on a commercial NB-IoT network. We then present SynchroNB, an on-device framework that combines lightweight machine learning with a cross-layer control loop. SynchroNB forecasts 5G network volatility and crystal drift to adaptively wake the cellular modem, reserves uplink resources just in time, switches into resilience mode when the wireless link degrades, and prioritizes time synchronization packets in the MAC-layer queue. We deploy SynchroNB on commercial NB-IoT hardware and evaluate it over a live 5G network. Our experiments show that SynchroNB achieves single-millisecond-level synchronization accuracy under NB-IoT uplink/downlink asymmetry and, diverse wireless conditions, while requiring only \(36\%\) of the radio-on time and \(25\%\) of the bandwidth of the NTP baseline, transforming NB-IoT time synchronization from a reactive protocol into an intelligent, self-tuning control loop. Muhammad Abdullah Soomro, Muhammad Shayan Nazeer, Collin DelSignore, Yasra Chandio, Muhammad Taqi Raza, Fatima M. Anwar 0001 |
SenSys | 5 |
| 2025 | QSec '25: Workshop on Quantum Security and PrivacyabstractThe Quantum Security and Privacy (QSec) Workshop aims to establish a focused venue dedicated to examining both the novel threats introduced by quantum technologies and the security of quantum systems themselves. By bringing together experts from traditional security domains such as post-quantum cryptography and network security, as well as from quantum computing research including quantum key distribution and quantum architectures, QSec provides a forum to expose emerging quantum-era threats by analyzing how adversaries with quantum or quantum-enhanced capabilities can undermine both classical and quantum systems. It further seeks to showcase innovative defenses by presenting hybrid cryptographic schemes, quantum-native protocols such as QKD, and hardware-level protections. In addition, the workshop aims to bridge disparate communities by fostering collaboration among researchers in cryptography, networking, architecture, and quantum information science. Finally, QSec aspires to chart a roadmap for future research by using keynotes, technical sessions, and blue-sky discussions to identify long-term challenges and research directions. Muhammad Taqi Raza, Jakub Szefer |
CCS | 1 |
| 2025 | Cloud Nine Connectivity: Security Analysis of In-Flight Wi-Fi Paywall SystemsabstractIn-flight Wi-Fi provides high-speed Internet connectivity to travelers at 30,000 feet at premium fees. In this paper, we present the first systematic study of the architecture and security policies of in-flight Wi-Fi paywall systems using network tomography analysis. We discover that attackers can exploit the inherent architectural shortcomings of airborne networks to create covert channels and conceal data packets within certain ''always-allowed'' traffic for free Internet access. Moreover, broken device authentication policies in these systems allow unlimited complimentary Internet connectivity. Finally, insecure ARP policies allow attackers to steal paid users' bandwidth to access the free Internet even faster. We validate these issues in practice over two major in-flight Wi-Fi providers using common protocols, e.g., UDP, DNS, etc. We also find that the root causes of these issues stem from different design choices in the architectures of these systems and propose countermeasures to address these flaws and prevent similar attacks. Abdullah Al Ishtiaq, Raja Hasnain Anwar, Yasra Chandio, Fatima M. Anwar 0001, Syed Rafiul Hussain, Muhammad Taqi Raza |
WISEC | 6 |
| 2024 | In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping
Raja Hasnain Anwar, Syed Rafiul Hussain, Muhammad Taqi Raza |
USENIX Security Symposium | 3 |
| 2023 | Redefining the Driver's Attention Gauge in Semi-Autonomous VehiclesabstractDriver distraction caused by over-reliance on automotive technology is one of the leading causes of accidents in semi-autonomous vehicles. Existing driver's attention-gauging approaches are intrusive and as such emphasize constant driver engagement. In case of an urgent traffic event, they fail to measure the event's criticality and subsequently generate timely alerts. In this paper, we re-position the driver's attention-gauging approach as a way to improve the driver's situational awareness during critical situations. We exploit how a vehicle captures its surroundings information to convert an automotive decision into defining the criticality and timeliness of an alert. For this, we identify the relationship between the traffic event, the type of automotive sensing technologies, and its processing resources to capture that event to design the driver's attention gauge. We evaluate the timeliness of alerts for different traffic scenarios over a prototype built using NVIDIA Jetson Xavier AGX and Carla. Our results show that we can improve the timeliness of an alert by up to 75x as compared to existing state-of-the-art approaches, while also providing feedback on its criticality. Raja Hasnain Anwar, Fatima M. Anwar 0001, Muhammad Kumail Haider, Alon Efrat, Muhammad Taqi Raza |
MSWiM | 5 |
| 2022 | Enabling emerging edge applications through a 5G control plane interventionabstract5G networks are considered potential enablers for many emerging edge applications, such as those related to autonomous vehicles, virtual and augmented reality, and online gaming. However, recent works have shown the cellular control plane is a potential bottleneck in enabling such applications --- control plane operations are slow, frequent, and can directly impact the delay experienced by end-user applications. Moreover, failures in the cellular control plane can significantly degrade application performance. In this paper, we consider the problem of enabling latency-sensitive and safety-critical edge applications on 5G networks. We identify fundamental control plane design challenges and posit enabling these applications requires re-thinking the cellular control plane. We propose a new edge-based cellular control plane, CellClone, which provides fast and fault-tolerant control plane processing. CellClone employs multiple active control plane clones at the network edge to mask control plane faults and speedup control processing. Central to its design is a custom quorum-based consistency protocol that provides state consistency with low latency. Testbed evaluations using real cellular traces show a median improvement of more than 3.8× in speeding up control plane operations with outright node failures and stragglers. These improvements translate into better application performance; with CellClone, autonomous cars and VR applications reduce missed application deadlines by more than 90%. Mukhtiar Ahmad, Muhammad Ali Nawazish, Muhammad Taimoor Tariq, Muhammad Basit Iqbal Awan, Muhammad Taqi Raza, Zafar Ayyub Qazi |
CoNEXT | 5 |
| 2022 | LTE NFV Rollback RecoveryabstractNetwork Function Virtualization (NFV) migrates the carrier-grade LTE Evolved Packet Core (EPC) that runs on commodity boxes to the public cloud. In the new virtualized environment, LTE EPC must offer high availability to its mobile users upon failures. Achieving high service availability is challenging because failover procedure must keep the latency-sensitive control-plane procedures intact during failures. Through our empirical study, we show that existing recovery mechanisms on the cloud and standardized LTE solutions are coarse-grained, thus unable to quickly recover from failures. They incur LTE service outage, lost network connectivity, and slow recovery. To address these issues, we describe a new design for fault-tolerant LTE EPC. It provides quick failure detection and timely recovery from failed operations. To reduce failure detection time, it leverages frequent retransmission of LTE control-plane signaling within EPC as an indication of failure. To recover from failure, it adopts a checkpointing based rollback recovery approach in the LTE context and addresses the shortcomings known in the classic checkpointing approach. Our design is LTE standard-compliant and works as a plug-and-play without modifying existing LTE implementations. Our results show that this approach can recover from the failure in 2.6 seconds and only incurs tens of milliseconds of overhead. Muhammad Taqi Raza, Zhowei Tan, Ali Tufail, Fatima M. Anwar 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | On Key Reinstallation Attacks over 4G LTE Control-Plane: Feasibility and Negative ImpactabstractThis paper studies the feasibility of key reinstallation attacks in the 4G LTE network.It is well known that LTE uses session keys for confidentiality and integrity protection of its control-plane signaling packets.However, if the keys are not updated and counters are reset, key reinstallation attacks may arise.In this paper, we show that several design choices in the current LTE security setup are vulnerable to key reinstallation attacks.Specifically, on the control plane, the LTE security association setup procedures, which establish security between the device and the network, are disconnected.The keys are installed through one procedure, whereas their associated parameters (such as uplink and downlink counters) are reset through another different procedure.The adversary can thus exploit the disjoint security setup procedures, and launch the key stream reuse attacks.He consequently breaks message encryption, when he tricks the victim to use the same pair of keys and counter value to encrypt multiple messages.This control-plane attack hijacks the location update procedure, thus rendering the device to be unreachable from the Internet.Moreover, it may also deregister the victim from the LTE network.We have confirmed our findings with two major US operators, and found that such attacks can be launched with software-defined radio devices that cost about $299.We further propose remedies to defend against such threats. Muhammad Taqi Raza, Yunqi Guo, Songwu Lu, Fatima M. Anwar 0001 |
ACSAC | 1 |
| 2021 | Highly Available Service Access Through Proactive Events Execution in LTE NFVabstractThe explosion of mobile applications and phenomenal adoption of mobile connectivity by end users make all-IP based 4G LTE as an ideal choice for providing Internet access on the go. LTE core network which handles device control-plane and data-plane traffic becomes susceptible to network resource constraints. To ease these constraints, Network Function Virtualization (NFV) provides high scalability and flexibility by enabling dynamic allocation of LTE core network resources. NFV achieves this by decomposing LTE Network Functions (NF) into multiple instances. However, LTE core network architecture which is designed considering fewer NF boxes does not fit well where decomposed NF instances add delays in network event execution. Certain control-plane events being time critical hurt data-plane traffic requirements defined by LTE standard. This paper proposes Fat-proxy which acts as a stand-alone execution engine of these critical network events. Through space uncoupling, we execute several signalling messages in parallel while skipping unnecessary messages to reduce event execution time and signalling overhead while ensuring highly available service access. We build our system prototype of open source LTE core network over virtualized platform. Our results show that we can reduce event execution time and signalling overhead upto 50% and 40%, respectively. Muhammad Taqi Raza, Fatima M. Anwar 0001, Kyu-Han Kim |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | Uninterruptible IMS: Maintaining Users Access During Faults in Virtualized IP Multimedia SubsystemabstractNetwork function virtualization (NFV) of IP Multimedia Subsystem (IMS) pose promise to service increasing multimedia traffic demand. In this paper, we show that virtualized IMS (vIMS) is unable to provide session-level resilience under faults and becomes the bottleneck to high service availability. We propose a design to provide fault-tolerance for vIMS operations. In control-plane, our system decomposes single IMS operation into different atomic actions, and partition these actions into critical and non-critical actions. Only the critical actions are then monitored in real time and the system can easily resume IMS operations after failure. In data-plane, we decompose multimedia traffic flows and partition each multimedia service as a separate Virtualized Network Function (VNF). Through data-plane partitioning, our design restricts the damage from faults to only failed VNF. Thereafter, impacted service flow is merged with other ongoing service flows. We build our system prototype of open source IMS over virtualized platform. Our results show that we can achieve session-level resilience by performing fail-over procedure within tens of milliseconds under different combinations of IMS failures in both control-plane and data-plane operations. Muhammad Taqi Raza, Songwu Lu |
IEEE J. Sel. Areas Commun. | 1 |
| 2019 | A Systematic Way to LTE TestingabstractLTE test cases are standardized by 3GPP. They must be executed on every LTE-capable device model before commercial release. In this work, we examine the LTE testing practices in terms of completeness and efficiency. We discover that the standardized tests are incomplete in that a number of test cases related to multiple protocol interactions are missing. Our analysis also shows that, the isolated treatment of test cases, but not from the system perspective, incurs repetitive executions of test operations, thus resulting in testing inefficiencies. We thus make a case for a paradigm shift from ad hoc testing to a methodical approach to LTE testing. We follow a few guidelines from the LTE standards and propose an algorithmic approach to systematic testing. In the process, we address various challenges, provide complete list of test cases, and present the related algorithms. Our evaluation shows that, by eliminating repetitive operations, our new scheme reduces up to 70% of LTE testing steps. We also find 87 new, yet valid test cases that are not defined by the LTE standards. Muhammad Taqi Raza, Songwu Lu |
MobiCom | 1 |
| 2019 | vEPC-sec: Securing LTE Network Functions Virtualization on Public CloudabstractPublic cloud offers economy of scale to adapt workload changes in an autonomic manner, maximizing the use of resources. Through network function virtualization (NFV), network operators can move LTE core to the cloud; hence removing their dependency on carrier-grade LTE network functions. Recent research efforts discuss performance, latency, and fault tolerance of LTE NFV, largely ignoring the security aspects. In this paper, we discover new vulnerabilities that LTE NFV face today with no standard solutions to address them. These vulnerabilities span at both LTE control and user planes. To address them, we propose vEPC-sec that cryptographically secures LTE control-plane signaling messages in the cloud. It provides distributed key management and key derivation schemes to derive shared-symmetric keys for securing the communication between any two network functions. Our approach provides encryption and integrity protection to the messages even during virtual machines scalability and failure recovery scenarios. vEPC-sec also prevents user-plane vulnerabilities by ensuring that LTE routing modules should faithfully forward the LTE subscriber packets. Muhammad Taqi Raza, Songwu Lu, Mario Gerla |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2018 | A Machine Learning Based Approach to Mobile Network AnalysisabstractIn this paper, we present our recent work in progress on 4G mobile network analysis. In order to provide an in-depth study on the closed network operations, we advocate a novel approach via two-level, device-centric machine learning that can open up the system behaviors and facilitate fine-grained analysis . We describe our proposed approach, and use the latency analysis on two popular mobile apps (Web browsing and Instant Messaging) to illustrate how our scheme works. We further preliminary results and discuss the open issues. Zengwen Yuan, Yuanjie Li, Chunyi Peng 0001, Songwu Lu, Haotian Deng 0001, Zhaowei Tan, Muhammad Taqi Raza |
ICCCN | 7 |
| 2018 | Refactoring Network Functions Modules to Reduce Latencies and Improve Fault Tolerance in NFVabstractNetwork functions virtualization (NFV) allows service providers to deliver new services to their customers more quickly by adopting software-centric network functions implementation over commercial, off-the-shelf hardwares. This NFV-based software-centric approach cannot use dedicated mechanisms implemented over custom built boxes to reduce latencies and tolerate faults. We present a case study of IP multimedia subsystem (IMS), which is the most complex NFV instance, requires extremely low end-to-end latency (40 msec), and demands system availability as high as five nines. Through an empirical study, we discover that highly modular IMS network functions implementation over virtualized platform: 1) incurs latencies and 2) does not tolerate faults. NFV-based IMS modules incur high latencies by creating a feedback loop among each other while executing delay sensitive data-plane traffic. These IMS modules are also susceptible to failure, causing the control-plane to terminate the application session while keeping the data-plane to forward data packets. To address these issues, we propose to refactor network function modules. We reduce latencies by pipelining the IMS modules, and recover failed modules by reconfiguring their neighboring modules. We build our system prototype of open source IMS over OpenStack platform. Our results show that our scheme reduces latencies and failure recovery time up to 12× and 10×, respectively, when compared with the state-of-the-art virtualized IMS implementation. Muhammad Taqi Raza, Songwu Lu, Mario Gerla, Xi Li 0003 |
IEEE J. Sel. Areas Commun. | 1 |
| 2017 | Enabling low latency and high reliability for IMS-NFVabstractNetwork Functions Virtualization (NFV) allows service providers to deliver new services to their customers more quickly by adopting software centric network functions implementation over commercial, off-the-shelf hardwares. IP Multimedia Subsystem (IMS) which is one of the most complex NFV instances requires extremely low end-to-end latency (up to 40 msec), and demands system availability as high as five nines. We discover that highly modular 3GPP standardized IMS network functions implementation over virtualized platform (1) incurs latencies, and (2) does not tolerate faults. NFV-based IMS modules incur high latencies by creating a feedback loop among each other while executing delay sensitive data-plane traffic. These IMS modules are also susceptible to failures, causing the control-plane to terminate the application session while keeping the data-plane to forward data packets. To address these issues, we propose to refactor network function modules. We reduce latencies by pipelining the communication between IMS modules, and achieve fault tolerance by reconfiguring their neighboring modules. We build our system prototype of open source 3GPP compliant IMS over OpenStack platform. Our results show that our scheme reduces latencies and failure recovery time upto 12X and 10X, respectively, when compared to the stat-of-the-art 3GPP compliant virtualized IMS implementation. Muhammad Taqi Raza, Songwu Lu |
CNSM | 1 |
| 2017 | Towards Automated Intelligence in 5G SystemsabstractIn this paper, we call for a paradigm shift away from the wireless-access focused research efforts on 5G networked systems. We believe that the architectural limitations should share equal blame on issues of performance, reliability, and security. We thus identify architectural weakness on both sides of the mobile clients and the 4G network infrastructure. Our recent findings show that, contrary to commonly held perceptions, many design and operational issues arise not due to poor wireless link qualities. Instead, they are rooted in such architectural downsides. To address these issues, we further propose a new approach of enabling automated intelligence inside the 4G/5G network systems. We next describe our ongoing efforts along two dimensions: empowering date-driven smart clients and constructing verifiable network infrastructure. We report some early results and discuss possible next steps. Haotian Deng 0001, Qianru Li 0002, Yuanjie Li, Songwu Lu, Chunyi Peng 0001, Muhammad Taqi Raza, Zhaowei Tan, Zengwen Yuan, Zhehui Zhang |
ICCCN | 6 |
| 2017 | Rethinking LTE network functions virtualizationabstractLTE Network Function Virtualization (LTE-NFV) scales user services in a low cost fashion by transforming the centralized legacy LTE Core architecture to a distributed architecture. This distributed architecture makes multiple instances of LTE Network Functions (NFs) and virtualizes them on commodity data-center network. The functionality of LTE-NFV architecture breaks however, since the distributed NF instances connected via unreliable IP links delay the execution of critical events. The failure of time-critical events results in users' quality of service degradation and temporary service unavailability. In this paper, we propose a new way to virtualize LTE core network. We argue that logic-based NFs segregation should be done for NFV, instead of instance-based NFs segregation done in current NFV implementation. Our approach of ‘logic-based NFs segregation’ combines the logic of an event into a single NF, thus localizing the execution of critical events to one virtual machine. This way, only the localized entities exchange signalling messages, and the events do not experience large delays. We further reduce the delays by exploiting the parallelism in LTE network protocols; and partition these protocols such that their signalling messages run in parallel. In addition, we eliminate unnecessary messages to reduce the signalling overhead. We build our system prototype over OpenEPC LTE core network in virtualized platform. Our results show that we can reduce event execution time and signalling overhead up to 50% and 40%, respectively. Muhammad Taqi Raza, Kyu-Han Kim, Songwu Lu, Mario Gerla |
ICNP | 1 |
| 2017 | Exposing LTE Security Weaknesses at Protocol Inter-layer, and Inter-radio Interactions
Muhammad Taqi Raza, Fatima M. Anwar 0001, Songwu Lu |
SecureComm | 1 |
| 2010 | FESP: Fast and Energy Efficient Service Provisioning in 6LoWPANabstractIn this paper we propose a fast and energy efficient service provisioning approach. In our work, we focus towards the management of already discovered services. We assert that if the sensor nodes share the important service information among each other, then the service re-discovery can be reduced at greater extent. Hence a significant amount of Service Discover (SD) time and the network energy cost can be saved. We propose the threshold-based technique by devising the formula that determines the importance of the service, and a mechanism of sharing that service through the proposed scheme. We also discuss the performance of different SD protocols with and without implementation of proposed Fast and Energy Efficient Service Provisioning (FESP). Muhammad Taqi Raza, Fatima M. Anwar 0001, Seung-Wha Yoo, Ki-Hyung Kim |
PIMRC | 1 |
| 2010 | ENUM Based Service Discovery Architecture for 6LoWPANabstractService discovery in Ubiquitous Sensor Networks has been targeted mostly for services available within certain proximity, but the service availability only in close vicinity is no longer feasible in the pervasive and ubiquitous era. In order to address the ubiquity in service discovery, we have proposed a framework that makes use of the Electronic Number Mapping (ENUM) protocol. Our network architecture consists of sensor nodes associated with few relatively powerful nodes called master nodes. Only master nodes within IPv6 enabled Low power Personal Area Networks (6LoWPANs) are assigned unique E.164 numbers so that the services offered by the network could be accessed globally. Services destined for sensor nodes first reach the master node to which they are associated to, using the E.164 number of the master node. The gateway of the network performs the task of converting attribute-value pair based human readable queries to E.164 numbers. Also the gateway facilitates its network by running ENUM protocol for service sharing like multimedia, mail, web and many other services. Moreover, a significant improvement in service discovery cost in terms of latency and traffic overhead is observed. Fatima M. Anwar 0001, Muhammad Taqi Raza, Seung-Wha Yoo, Ki-Hyung Kim |
WCNC | 2 |
| 2009 | Network Assisted Mobility Support for 6LoWPANabstractThis paper presents a network-assisted mobility support scheme for 6LoWPAN nodes, which enables multi-hop communication between the Gateway (GW) and the Mobile 6LoWPAN devices (MNs), with minimum mobility related signaling at the MN's end as compared to conventional mobility related protocols like MIPv6. The scheme provides mobility support to the MNs with the help of low cost static 6LoWPAN devices (SNs) which can be deployed in large numbers. In order to reduce the handover latency, the MN in the proposed scheme is assigned a fixed address which remains unchanged during its course of movement within the network. Moreover the scheme aims to reduce packets loss of the MN by predicting its future location and having a provision of buffering its packet at SNs when needed. The signaling overhead consumption needed to support a MN is determined through analytical modeling. Gargi Bag, S. M. Saif Shams, Ali Hammad Akbar 0001, Muhammad Taqi Raza, Ki-Hyung Kim, Seung-Wha Yoo |
CCNC | 4 |
| 2008 | RSRP: A Robust Secure Routing Protocol for Mobile Ad Hoc NetworksabstractRouting scenario in ad hoc networks is different from infrastructure-based wireless networks; since in ad hoc networks each node acts as a router and is responsible for managing topological information and ensuring correct route learning. Although a number of secure routing protocols have been proposed so far, all of them have certain advantages and disadvantages. Hence, security in ad hoc networks is still a contentious area. In this paper we first explore the security problems and attacks in existing routing protocols and then we present the design and analysis of a new secure on-demand routing protocol, called RSRP which confiscates the problems mentioned in the existing protocols. Moreover, unlike Ariadne, RSRP uses a very efficient broadcast authentication mechanism which does not require any clock synchronization and facilitates instant authentication. Syed Rehan Afzal, Subir Biswas 0004, Jong-bin Koh, Muhammad Taqi Raza, Dong-Kyoo Kim |
WCNC | 4 |