EDBT 2026 Demo / reviewers in the wild / expert
Harsha K. Kalutarage
dblp:138/7300 · also Harsha Kalutarage, Harsha Kumara Kalutarage
· DBLP profile ↗
22ranked-venue papers
2as first author
19since 2021 · last 2025
0000-0001-6430-9558ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 2 first-author · 14 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MADONNA: Browser-based malicious domain detection using Optimized Neural Network by leveraging AI and feature analysisabstractDetecting malicious domains is a critical aspect of cybersecurity, with recent advancements leveraging Artificial Intelligence (AI) to enhance accuracy and speed. However, existing browser-based solutions often struggle to achieve both high accuracy and efficient throughput. In this paper, we present MADONNA, a novel browser-based malicious domain detector that exceeds the current state-of-the-art in both accuracy and throughput. MADONNA utilizes feature selection through correlation analysis and model optimization techniques, including pruning and quantization, to significantly enhance detection speed without compromising accuracy. Our approach employs a Shallow Neural Network (SNN) architecture, outperforming Large Language Models (LLMs) and state-of-the-art methods by improving accuracy by 6% (reaching 0.94) and F1-score by 4% (reaching 0.92). We further integrated MADONNA into a Google Chrome extension, demonstrating its practical application with a real-time domain detection accuracy of 94% and an average inference time of 0.87 s. These results highlight MADONNA’s effectiveness in balancing speed and accuracy, providing a scalable, real-world solution for malicious domain detection. Janaka Senanayake, Sampath Rajapaksha, Naoto Yanai, Harsha K. Kalutarage, Chika Komiya |
Comput. Secur. | 4 |
| 2025 | A systematic literature review of log-correlation tools for cyberattack detection and prediction in large networks
Edward Chuah, Harsha K. Kalutarage, Kasim Tasdemir, Atnafu Abrham, Carsten Maple |
J. Inf. Secur. Appl. | 2 |
| 2024 | Cross-Validation for Detecting Label Poisoning Attacks: A Study on Random Forest Algorithm
Tharindu Lakshan Yasarathna, Lankeshwara Munasinghe, Harsha K. Kalutarage, Nhien-An Le-Khac |
SEC | 3 |
| 2024 | Defendroid: Real-time Android code vulnerability detection via blockchain federated neural network with XAIabstractEnsuring strict adherence to security during the phases of Android app development is essential, primarily due to the prevalent issue of apps being released without adequate security measures in place. While a few automated tools are employed to reduce potential vulnerabilities during development, their effectiveness in detecting vulnerabilities may fall short. To address this, “Defendroid”, a blockchain-based federated neural network enhanced with Explainable Artificial Intelligence (XAI) is introduced in this work. Trained on the LVDAndro dataset, the vanilla neural network model achieves a 96% accuracy and 0.96 F1-Score in binary classification for vulnerability detection. Additionally, in multi-class classification, the model accurately identifies Common Weakness Enumeration (CWE) categories with a 93% accuracy and 0.91 F1-Score. In a move to foster collaboration and model improvement, the model has been deployed within a blockchain-based federated environment. This environment enables community-driven collaborative training and enhancements in partnership with other clients. The extended model demonstrates improved accuracy of 96% and F1-Score of 0.96 in both binary and multi-class classifications. The use of XAI plays a pivotal role in presenting vulnerability detection results to developers, offering prediction probabilities for each word within the code. This model has been integrated into an Application Programming Interface (API) as the backend and further incorporated into Android Studio as a plugin, facilitating real-time vulnerability detection. Notably, Defendroid exhibits high efficiency, delivering prediction probabilities for a single code line in an average processing time of a mere 300 ms. The weight-sharing transparency in the blockchain-driven federated model enhances trust and traceability, fostering community engagement while preserving source code privacy and contributing to accuracy improvement. Janaka Senanayake, Harsha K. Kalutarage, Andrei Petrovski 0001, Luca Piras 0003, M. Omar Al-Kadri |
J. Inf. Secur. Appl. | 2 |
| 2023 | RRP: A Reliable Reinforcement Learning Based Routing Protocol for Wireless Medical Sensor NetworksabstractWireless medical sensor networks (WMSNs) offer innovative healthcare applications that improve patients' quality of life, provide timely monitoring tools for physicians, and support national healthcare systems. However, despite these benefits, widespread adoption of WMSN advancements is still hampered by security concerns and limitations of routing protocols. Routing in WMSNs is a challenging task due to the fact that some WMSN requirements are overlooked by existing routing proposals. To overcome these challenges, this paper proposes a reliable multi-agent reinforcement learning based routing protocol (RRP). RRP is a lightweight attacks-resistant routing protocol designed to meet the unique requirements of WMSN. It uses a novel Q-learning model to reduce resource consumption combined with an effective trust management system to defend against various packet-dropping attacks. Experimental results prove the lightweightness of RRP and its robustness against blackhole, selective forwarding, sinkhole and complicated on-off attacks. Muhammad Shadi Hajar, Harsha K. Kalutarage, M. Omar Al-Kadri |
CCNC | 2 |
| 2023 | Android Code Vulnerabilities Early Detection Using AI-Powered ACVED Plugin
Janaka Senanayake, Harsha K. Kalutarage, M. Omar Al-Kadri, Andrei Petrovski 0001, Luca Piras 0003 |
DBSec | 2 |
| 2023 | MADONNA: Browser-Based MAlicious Domain Detection Through Optimized Neural Network with Feature Analysis
Janaka Senanayake, Sampath Rajapaksha, Naoto Yanai, Chika Komiya, Harsha K. Kalutarage |
SEC | 5 |
| 2023 | Labelled Vulnerability Dataset on Android Source Code (LVDAndro) to Develop AI-Based Code Vulnerability Detection ModelsabstractEnsuring the security of Android applications is a vital and intricate aspect requiring careful consideration during development. Unfortunately, many apps are published without sufficient security measures, possibly due to a lack of early vulnerability identification. One possible solution is to employ machine learning models trained on a labelled dataset, but currently, available datasets are suboptimal. This study creates a sequence of datasets of Android source code vulnerabilities, named LVDAndro, labelled based on Common Weakness Enumeration (CWE). Three datasets were generated through app scanning by altering the number of apps and their sources. The LVDAndro, includes over 2,000,000 unique code samples, obtained by scanning over 15,000 apps. The AutoML technique was then applied to each dataset, as a proof of concept to evaluate the applicability of LVDAndro, in detecting vulnerable source code using machine learning. The AutoML model, trained on the dataset, achieved accuracy of 94% and F1-Score of 0.94 in binary classification, and accuracy of 94% and F1-Score of 0.93 in CWE-based multi-class classification. The LVDAndro dataset is publicly available, and continues to expand as more apps are scanned and added to the dataset regularly. The LVDAndro GitHub Repository also includes the source code for dataset generation, and model training. Janaka Senanayake, Harsha K. Kalutarage, M. Omar Al-Kadri, Luca Piras 0003, Andrei Petrovski 0001 |
SECRYPT | 2 |
| 2023 | 3R: A reliable multi agent reinforcement learning based routing protocol for wireless medical sensor networksabstractInterest in the Wireless Medical Sensor Network (WMSN) is rapidly gaining attention thanks to recent advances in semiconductors and wireless communication. However, by virtue of the sensitive medical applications and the stringent resource constraints, there is a need to develop a routing protocol to fulfill WMSN requirements in terms of delivery reliability, attack resiliency, computational overhead, and energy efficiency. This paper proposes 3R, a reliable multi agent reinforcement learning routing protocol for WMSN. 3R uses a novel resource-conservative Reinforcement Learning (RL) model to reduce the computational overhead, along with two updating methods to speed up the algorithm convergence. The reward function is re-defined as a punishment, combining the proposed trust management system to defend against well-known dropping attacks. Furthermore, an energy model is integrated with the reward function to enhance the network lifetime and balance energy consumption across the network. The proposed energy model only uses local information to avoid the resource burdens and the security concerns of exchanging energy information. Experimental results prove the lightweightness, attacks resiliency and energy efficiency of 3R, making it a potential routing candidate for WMSN. Muhammad Shadi Hajar, Harsha K. Kalutarage, M. Omar Al-Kadri |
Comput. Networks | 2 |
| 2023 | Towards a robust, effective and resource efficient machine learning technique for IoT security monitoringabstractThe application of Deep Neural Networks (DNNs) for monitoring cyberattacks in Internet of Things (IoT) systems has gained significant attention in recent years. However, achieving optimal detection performance through DNN training has posed challenges due to computational intensity and vulnerability to adversarial samples. To address these issues, this paper introduces an optimization method that combines regularization and simulated micro-batching. This approach enables the training of DNNs in a robust, efficient, and resource-friendly manner for IoT security monitoring. Experimental results demonstrate that the proposed DNN model, including its performance in Federated Learning (FL) settings, exhibits improved attack detection and resistance to adversarial perturbations compared to benchmark baseline models and conventional Machine Learning (ML) methods typically employed in IoT security monitoring. Notably, the proposed method achieves significant reductions of 79.54% and 21.91% in memory and time usage, respectively, when compared to the benchmark baseline in simulated virtual worker environments. Moreover, in realistic testbed scenarios, the proposed method reduces memory footprint by 6.05% and execution time by 15.84%, while maintaining accuracy levels that are superior or comparable to state-of-the-art methods. These findings validate the feasibility and effectiveness of the proposed optimization method for enhancing the efficiency and robustness of DNN-based IoT security monitoring. Idris Zakariyya, Harsha K. Kalutarage, M. Omar Al-Kadri |
Comput. Secur. | 2 |
| 2023 | Beyond vanilla: Improved autoencoder-based ensemble in-vehicle intrusion detection systemabstractModern automobiles are equipped with a large number of electronic control units (ECUs) to provide safe, driver assistance and comfortable services. The controller area network (CAN) provides near real-time data transmission between ECUs with adequate reliability for in-vehicle communication. However, the lack of security measures such as authentication and encryption makes the CAN bus vulnerable to cyberattacks, which affect the safety of passengers and the surrounding environment. Detecting attacks on the CAN bus, particularly masquerade attacks, presents significant challenges. It necessitates an intrusion detection system (IDS) that effectively utilizes both CAN ID and payload data to ensure thorough detection and protection against a wide range of attacks, all while operating within the constraints of limited computing resources. This paper introduces an ensemble IDS that combines a gated recurrent unit (GRU) network and a novel autoencoder (AE) model to identify cyberattacks on the CAN bus. AEs are expected to produce higher reconstruction errors for anomalous inputs, making them suitable for anomaly detection. However, vanilla AE models often suffer from overgeneralization, reconstructing anomalies without significant errors, resulting in many false negatives. To address this issue, this paper proposes a novel AE called Latent AE, which incorporates a shallow AE into the latent space. The Latent AE model utilizes Cramér’s statistic-based feature selection technique and a transformed CAN payload data structure to enhance its efficiency. The proposed ensemble IDS enhances attack detection capabilities by leveraging the best capabilities of independent GRU and Latent AE models, while mitigating the weaknesses associated with each individual model. The evaluation of the IDS on two public datasets, encompassing 13 different attacks, including sophisticated masquerade attacks, demonstrates its superiority over baseline models with near real-time detection latency of 25ms. Sampath Rajapaksha, Harsha K. Kalutarage, M. Omar Al-Kadri, Andrei Petrovski 0001, Garikayi Madzudzo |
J. Inf. Secur. Appl. | 2 |
| 2022 | Developing Secured Android Applications by Mitigating Code Vulnerabilities with Machine LearningabstractMobile application developers sometimes might not be serious about source code security and publish apps to the marketplaces. Therefore, it is essential to have a fully automated security solutions generator to integrate security-by-design into the development practices, especially for the Android platform. This research proposes a Machine Learning (ML) based highly accurate method to detect Android source code vulnerabilities. A new labelled dataset containing Android source code vulnerability samples was generated initially. The dataset was used to train binary and multi-class classification based ML models, to identify code issues by following a static analysis approach. The proposed model can detect code vulnerabilities with a 0.90 F1-Score and vulnerability categories (CWE) with a 0.96 F1-Score. By integrating this with the Android development environment, app developers can analyse source code and identify security vulnerabilities in real-time. The proposed framework can be extended to suggest suitable patches to overcome the source code issues by providing real-time fixes in future. Janaka Senanayake, Harsha K. Kalutarage, M. Omar Al-Kadri, Andrei Petrovski 0001, Luca Piras 0003 |
AsiaCCS | 2 |
| 2022 | DQR: A Double Q Learning Multi Agent Routing Protocol for Wireless Medical Sensor Network
Muhammad Shadi Hajar, Harsha K. Kalutarage, M. Omar Al-Kadri |
SecureComm | 2 |
| 2022 | FedSim: Similarity guided model aggregation for Federated Learning
Chamath Palihawadana, Nirmalie Wiratunga, Anjana Wijekoon, Harsha K. Kalutarage |
Neurocomputing | 4 |
| 2021 | Resource Efficient Boosting Method for IoT Security MonitoringabstractMachine learning (ML) methods are widely proposed for security monitoring of Internet of Things (IoT). However, these methods can be computationally expensive for resource constraint IoT devices. This paper proposes an optimized resource efficient ML method that can detect various attacks on IoT devices. It utilizes Light Gradient Boosting Machine (LGBM). The performance of this approach was evaluated against four realistic IoT benchmark datasets. Experimental results show that the proposed method can effectively detect attacks on IoT devices with limited resources, and outperforms the state of the art techniques. Idris Zakariyya, M. Omar Al-Kadri, Harsha K. Kalutarage |
CCNC | 3 |
| 2021 | Improving Intrusion Detection Through Training Data AugmentationabstractImbalanced classes in datasets are common problems often found in security data. Therefore, several strategies like class resampling and cost-sensitive training have been proposed to address it. In this paper, we propose a data augmentation strategy to oversample the minority classes in the dataset. Using our Sort-Augment-Combine (SAC) technique, we split the dataset into subsets of the class labels and then generate synthetic data from each of the subsets. The synthetic data were then used to oversample the minority classes. Upon the completion of the oversampling, the independent classes were combined to form an augmented training data for model fitting. Using performance metrics such as accuracy, recall (sensitivity) and true positives (specificity), the models trained using the augmented datasets show an improvement in performance metrics over the original dataset. Similarly, in a binary class dataset, SAC performed optimally and the combination of SAC and ROSE model shows an improvement in overall accuracy, sensitivity and specificity when compared with the performance of the Random Forest model on the original dataset, ROSE and SMOTE augmented datasets. Uneneibotejit Otokwala, Andrei Petrovski 0001, Harsha K. Kalutarage |
SIN | 3 |
| 2021 | TrustMod: A Trust Management Module For NS-3 SimulatorabstractTrust management offers a further level of defense against internal attacks in ad hoc networks. Deploying an effective trust management scheme can reinforce the overall network security. Regardless of limitations, however, security researchers often use numerical simulations to prove the merits of novel methods. This is due to the lack of an adequate testbed to evaluate the proposed trust schemes. Therefore, there is a demanding need to develop a generic testbed that can be used to evaluate the trust relationship for different networks and protocols. This paper proposes TrustMod, an NS-3 module consisting of three main components to evaluate the different trust relationships: direct trust, uncertainty, and indirect trust. It is designed to meet usability, generalisability, flexibility, scalability and high-performance requirements. A series of experiments involving 1680 simulations were performed to prove the design and implementation accuracy of TrustMod. The performance results show that TrustMod's resource footprint is minimal, even for very large networks. Muhammad Shadi Hajar, Harsha K. Kalutarage, M. Omar Al-Kadri |
TrustCom | 2 |
| 2021 | A survey on wireless body area networks: architecture, security challenges and research opportunities
Muhammad Shadi Hajar, M. Omar Al-Kadri, Harsha K. Kalutarage |
Comput. Secur. | 3 |
| 2021 | Naive Bayes: applications, variations and vulnerabilities: a review of literature with code snippets for implementation
Indika P. Wickramasinghe, Harsha K. Kalutarage |
Soft Comput. | 2 |
| 2020 | LTMS: A Lightweight Trust Management System for Wireless Medical Sensor NetworksabstractWireless Medical Sensor Networks (WMSNs) offer ubiquitous health applications that enhance patients' quality of life and support national health systems. Detecting internal attacks on WMSNs is still challenging since cryptographic measures can not protect from compromised or selfish sensor nodes. Establishing a trust relationship between sensor nodes is recognized as a promising measure to reinforce the overall security of Wireless Sensor Networks (WSNs). However, the existing trust schemes for WSNs are not necessarily fit for WMSNs due to their different operation, topology, resources limitations, and critical applications. In this paper, the aforementioned factors are regarded, and accordingly, two different methods to evaluate the trust value have been proposed to fit in-body, on-body, and off-body sensor nodes. Our Lightweight Trust Management System (LTMS) provides a further line of defense to detect packet drop attacks launched by compromised or selfish sensor nodes. Moreover, simulation results show that LTMS is more robust against complicated on-off attacks and can significantly reduce the processing overhead. Muhammad Shadi Hajar, M. Omar Al-Kadri, Harsha K. Kalutarage |
TrustCom | 3 |
| 2015 | Towards an Early Warning System for Network Attacks Using Bayesian InferenceabstractThe Internet has become the most vulnerable part of critical civil infrastructures. Proactive measures such as early warnings are required to reduce the risk of disasters that can be created using it. With the continuous growth in scale, complexity and variety of networked systems the quality of data is continuously decreasing. This paper investigates the ability to employ Bayesian inference for network scenario analysis with low quality data to produce early warnings. Theoretical account of the approach and experimental results using a real world attack scenario and a real network traffic capture is presented. Harsha K. Kalutarage, Chonho Lee, Siraj Ahmed Shaikh, Bu-Sung Lee |
CSCloud | 1 |
| 2013 | Tracing Sources of Anonymous Slow Suspicious Activities
Harsha K. Kalutarage, Siraj Ahmed Shaikh, Qin Zhou 0004, Anne E. James |
NSS | 1 |