EDBT 2026 Demo / reviewers in the wild / expert
Ansam Khraisat
dblp:137/1591
· DBLP profile ↗
7ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0002-8623-0987ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Feature reduction in federated learning for intrusion detection in IoT networksabstractAbstract The rapid growth of the Internet of Things (IoT) has significantly increased the complexity of device interactions, making IoT networks more vulnerable to sophisticated cyber threats. Effective intrusion detection is therefore crucial to ensuring the security and resilience of these systems. This paper presents federated learning with feature reduction (Fed-FeRe), a novel approach that enhances decentralized intrusion detection by integrating $$\chi ^{2}$$ χ 2 -based feature selection with a gated recurrent unit model. Fed-FeRe introduces an adaptive initialization of the performance threshold $$\alpha $$ α and a data-driven estimation of key hyperparameters ( $$\theta _{0}$$ θ 0 , $$\eta $$ η ), enabling robust performance across diverse IoT conditions. By dynamically optimizing feature selection, the framework reduces computational overhead and communication costs, achieving approximately 2% lower transmission costs than FedAvg and 17.6% lower GPU utilization than MOON (Model-Contrastive Federated Learning), while improving detection precision by 3.06%. Fed-FeRe further demonstrates scalability to varying client sizes and adaptability to distinct IoT application domains such as smart cities, healthcare, and industrial networks. These results highlight Fed-FeRe as a scalable, efficient, and privacy-preserving solution for real-world IoT security, advancing the state of federated learning-based intrusion detection. Thien D. Nguyen, Ammar Alazab, Ansam Khraisat, Tony Jan |
Cybersecur. | 3 |
| 2026 | Advancing Loan Approval Prediction With SHAP-Guided Feature Selection and LIME-Based Model Interpretability in a Multiclassifier Context Through a Web-Based Application Development ApproachabstractIn today’s dynamic financial environment, bank loan approval systems are crucial for determining credit accessibility and maintaining economic stability. Efficient and accurate mechanisms help financial institutions minimize risks, enhance customer satisfaction, and make informed lending decisions. Traditional evaluation methods, however, often struggle with complex applicant data, underscoring the need for advanced, data‐driven approaches. This study proposes an enhanced loan approval prediction framework that integrates SHAP‐guided feature selection and LIME‐based interpretability within a robust multiclassifier architecture. The methodology includes extensive data preprocessing, handling missing values, and encoding categorical variables, followed by SHAP to identify the most influential features. Using two Kaggle datasets, logistic regression achieved the highest performance, with 86.17% accuracy and 81% AUC on Dataset 1 and 99.06% accuracy on Dataset 2. LIME provided intuitive, visual explanations of model predictions, fostering transparency and trust. In addition, a user‐friendly, real‐time web application was developed for practical deployment. Overall, the study advances intelligent, interpretable, and efficient loan approval systems for modern banking. Raisa Akter, Rajib Kumar Halder, Mohammed Nasir Uddin, Ashraf Uddin 0004, Ansam Khraisat, Mijanur Rahman, Md. Kabir Hossain |
Int. J. Intell. Syst. | 5 |
| 2025 | Adaptive memory replay for network intrusion detection: Tackling data drift and catastrophic forgettingabstractNetwork intrusion detection aims to identify anomalous activities in network traffic, while continual learning (CL) methods strive to preserve past knowledge and adapt to evolving threats. Memory replay-based CL approaches have been widely used and proven effective at mitigating catastrophic forgetting. However, previous research has primarily focused on addressing class imbalance and has largely relied on augmented and random memory replay strategies, which introduce significant computational overhead and limit practicality in real-time applications. To overcome these challenges, we propose Task-Aware Memory Replay (TAMR), a novel framework that prioritizes past experiences based on their relevance to the current task. By dynamically adjusting the importance of replayed samples, TAMR balances the integration of new attack patterns with the retention of critical historical knowledge, ensuring resilience against evolving threats and variations in normal traffic. Unlike traditional methods that employ random selection or augmented replays, TAMR selectively replays high-impact experiences, thereby optimizing memory usage and improving adaptability. Our experiments demonstrate that TAMR achieves real-time adaptability across five distinct NIDS datasets, ultimately delivering superior performance and computational efficiency in detecting even unknown attacks in dynamic network environments. In general, we highlight the potential of memory-based replay strategies for continual learning in detecting unknown attacks using a task-aware approach. Nasreen Fathima, Ansam Khraisat, S. P. Syed Ibrahim |
Comput. Networks | 2 |
| 2021 | A critical review of intrusion detection systems in the internet of things: techniques, deployment strategy, validation strategy, attacks, public datasets and challengesabstractAbstract The Internet of Things (IoT) has been rapidly evolving towards making a greater impact on everyday life to large industrial systems. Unfortunately, this has attracted the attention of cybercriminals who made IoT a target of malicious activities, opening the door to a possible attack on the end nodes. To this end, Numerous IoT intrusion detection Systems (IDS) have been proposed in the literature to tackle attacks on the IoT ecosystem, which can be broadly classified based on detection technique, validation strategy, and deployment strategy. This survey paper presents a comprehensive review of contemporary IoT IDS and an overview of techniques, deployment Strategy, validation strategy and datasets that are commonly applied for building IDS. We also review how existing IoT IDS detect intrusive attacks and secure communications on the IoT. It also presents the classification of IoT attacks and discusses future research challenges to counter such IoT attacks to make IoT more secure. These purposes help IoT security researchers by uniting, contrasting, and compiling scattered research efforts. Consequently, we provide a unique IoT IDS taxonomy, which sheds light on IoT IDS techniques, their advantages and disadvantages, IoT attacks that exploit IoT communication systems, corresponding advanced IDS and detection capabilities to detect IoT attacks. Ansam Khraisat, Ammar Alazab |
Cybersecur. | 1 |
| 2019 | Survey of intrusion detection systems: techniques, datasets and challengesabstractCyber-attacks are becoming more sophisticated and thereby presenting increasing challenges in accurately detecting intrusions. Failure to prevent the intrusions could degrade the credibility of security services, e.g. data confidentiality, integrity, and availability. Numerous intrusion detection methods have been proposed in the literature to tackle computer security threats, which can be broadly classified into Signature-based Intrusion Detection Systems (SIDS) and Anomaly-based Intrusion Detection Systems (AIDS). This survey paper presents a taxonomy of contemporary IDS, a comprehensive review of notable recent works, and an overview of the datasets commonly used for evaluation purposes. It also presents evasion techniques used by attackers to avoid detection and discusses future research challenges to counter such techniques so as to make computer systems more secure. Ansam Khraisat, Iqbal Gondal, Peter Vamplew 0001, Joarder Kamruzzaman |
Cybersecur. | 1 |
| 2014 | Using response action with intelligent intrusion detection and prevention system against web application malwareabstractPurpose – The purpose of this paper is to mitigate vulnerabilities in web applications, security detection and prevention are the most important mechanisms for security. However, most existing research focuses on how to prevent an attack at the web application layer, with less work dedicated to setting up a response action if a possible attack happened. Design/methodology/approach – A combination of a Signature-based Intrusion Detection System (SIDS) and an Anomaly-based Intrusion Detection System (AIDS), namely, the Intelligent Intrusion Detection and Prevention System (IIDPS). Findings – After evaluating the new system, a better result was generated in line with detection efficiency and the false alarm rate. This demonstrates the value of direct response action in an intrusion detection system. Research limitations/implications – Data limitation. Originality/value – The contributions of this paper are to first address the problem of web application vulnerabilities. Second, to propose a combination of an SIDS and an AIDS, namely, the IIDPS. Third, this paper presents a novel approach by connecting the IIDPS with a response action using fuzzy logic. Fourth, use the risk assessment to determine an appropriate response action against each attack event. Combining the system provides a better performance for the Intrusion Detection System, and makes the detection and prevention more effective. Ammar Alazab, Michael Hobbs, Jemal H. Abawajy, Ansam Khraisat, Mamoun Alazab |
Inf. Manag. Comput. Secur. | 4 |
| 2013 | Malware Detection and Prevention System Based on Multi-Stage RulesabstractThe continuously rising Internet attacks pose severe challenges to develop an effective Intrusion Detection System (IDS) to detect known and unknown malicious attack. In order to address the problem of detecting known, unknown attacks and identify an attack grouped, the authors provide a new multi stage rules for detecting anomalies in multi-stage rules. The authors used the RIPPER for rule generation, which is capable to create rule sets more quickly and can determine the attack types with smaller numbers of rules. These rules would be efficient to apply for Signature Intrusion Detection System (SIDS) and Anomaly Intrusion Detection System (AIDS). Ammar Alazab, Michael Hobbs, Jemal H. Abawajy, Ansam Khraisat |
Int. J. Inf. Secur. Priv. | 4 |