EDBT 2026 Demo / reviewers in the wild / expert
Hooman Alavizadeh
dblp:139/2506
· DBLP profile ↗
14ranked-venue papers
5as first author
9since 2021 · last 2025
0000-0002-0033-6706ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 4 since 2021Computer networks · 5 · 1 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | PRIV-HFL: Privacy-Preserving and Robust Federated Learning for Heterogeneous Clients Against Data Reconstruction AttacksabstractFederated Learning (FL) is a machine learning paradigm that allows multiple local clients to collaboratively train a global model by sharing their model parameters instead of private data, thereby mitigating privacy leakage. However, recent studies have shown that gradient-based Data Reconstruction Attack (DRA) can still expose private information by exploiting model parameters from local clients. Existing privacy-preserving FL strategies provide some defense against these attacks, but at the cost of significantly reduced model accuracy. Moreover, the issue of client heterogeneity, particularly in Non-Identical and Independent Distributions (Non-IID) clients, further exacerbates these FL methods, resulting in drifted global models, slower convergence, and decreased performance. This study aims to address the two main challenges of FL: Non-IID data and client privacy through DRA. To this end, it leverages the lagrangian duality approach and incorporates a generator model to enable Knowledge Distillation (KD) among clients. By facilitating improved local model performance through inter-client knowledge transfer, the proposed method aims to simultaneously address the practical challenges commonly encountered by FL systems. Our study demonstrates a remarkable improvement in model accuracy, with KD boosting it by up to $15 \%$ on CIFAR-10 and MNIST classification tasks in Non-IID client settings. Furthermore, we propose an aggregation algorithm that inherently preserves client data privacy during the training phase, offering resilience against DRA. Mohammadreza Najafi, Hooman Alavizadeh, Ahmad Salehi S., A. S. M. Kayes, Wenny Rahayu |
RAID | 2 |
| 2025 | Securing cross-domain data access with decentralized attribute-based access controlabstractIn attribute-based access control (ABAC), access to resources depends on the specific attributes of the entity requesting access. Existing ABAC models primarily depend on local attribute authorities to define and confirm attributes, which makes it challenging to support access decisions cross-domains without introducing centralization. Centralized solutions often conflict with individual domains’ security, privacy, and control requirements and, if compromised for any reason, can impact access to large datasets across participating domains. This paper introduces a novel access control model for cross-domain environments that significantly reduces central control. Our decentralized ABAC (D-ABAC) model uses group signature techniques to exchange attribute information securely and privately within cross-domains. Each domain maintains its own policies and attribute authorities, reducing the need for global trust or centralization to mutual trust between attribute authorities. We further design and implement a proof-of-concept system to demonstrate the practical feasibility of our proposed system for the collaborative and secure sharing of healthcare data in cross-domain environments. The proposed system model enhances security, scalability, and privacy in cross-domain settings, making it suitable for sensitive environments such as healthcare. Ahmad Salehi S., Carsten Rudolph, Hooman Alavizadeh, A. S. M. Kayes, Wenny Rahayu, Zahir Tari |
Ad Hoc Networks | 3 |
| 2025 | Social network botnet attack mitigation model for cloudabstractOnline Social Network (OSN) botnet attacks pose a growing threat to the cloud environment and reduce the services’ availability and reliability for users by launching distributed denial of service (DDoS) attacks on crucial servers in the cloud. These attacks involve the deployment of sophisticated botnets that exploit the interconnected nature of social networks to identify targets, exploit vulnerabilities, and launch attacks. The prevalence and impact of these botnet-driven attacks have recently been studied. Although the detection of these botnet attacks is still a challenging process, it remains crucial to gain a comprehensive understanding of and evaluate the best defense strategies against botnet attacks. This evaluation can be further utilized to formulate effective defense plans to mitigate the impact of such botnet attacks. In this paper, we first investigate the properties of OSN botnet attack stages that eventually lead to launching DDoS attacks toward a cloud system. Then, we formalize a defensive model using a sequential game model to analyze both the attacker’s and defenders’ best equilibrium strategies for the proposed botnet attack scenario. Moreover, we formulate optimal strategies for the defender against various attack strategies. Our experiments reveal the best defense strategies against various attack rates to maintain cloud functionality. Finally, we discuss possible countermeasures for these OSN botnet threats. Hooman Alavizadeh, Ahmad Salehi S., A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon |
Comput. Networks | 1 |
| 2025 | Physical layer security techniques for grant-free massive Machine-Type Communications in 5G and beyond: A survey, challenges, and future directionsabstractThe future of smart cities, industrial automation, and connected vehicles is heavily reliant on advanced communication technologies. These technologies, particularly massive Machine-Type Communication (mMTC), are the backbone of the many connected devices required for these applications. Grant -free access in 5G and beyond, while enhancing transmission efficiency by eliminating the need for permission requests, also introduces significant security risks. These risks, such as unauthorised access, data interception, and interference due to the absence of centralised control, are of paramount importance. Physical layer security (PLS) techniques, with their ability to exploit the unique properties of wireless channels to bolster communication security, offer a promising solution. This paper provides a comprehensive review of PLS techniques for securing grant-free mMTC, comparing different approaches and exploring the challenges of their integration. Our findings lay the groundwork for future research and the practical implementation of advanced security solutions in grant-free mMTC, a development that will also enhance the security of advanced 5G and 6G networks. Uchenna P. Enwereonye, Ahmad Salehi S., Hooman Alavizadeh, A. S. M. Kayes |
Comput. Networks | 3 |
| 2025 | Robust Multiuser Physical Layer Security for Grant-Free mMTC in Beyond 5G/6G NetworksabstractIndustry 5.0 introduces human-machine collaboration and resilient automation, demanding secure, low-latency connectivity for ultra-dense Industrial IoT (IIoT). Grant-free massive machine-type communications (mMTC) supports such connectivity but faces challenges including dense multiuser access, passive eavesdropping, and imperfect channel state information (CSI), which undermine physical layer security (PLS). This paper proposes a robust and low-complexity multiuser PLS scheme tailored for grant-free mMTC under CSI uncertainty. The scheme leverages dynamic user clustering based on spatial correlation and real-time interference to enable scalable, interference-aware beamforming. Furthermore, a joint optimisation of receive beamforming and adaptive artificial noise injection is performed, and enhanced by a regularised minimum mean square error (MMSE) framework to mitigate bounded CSI errors. Simulation results show that the scheme consistently outperforms existing benchmarks across secrecy capacity, bit error rate, and secrecy outage probability under different channel models, together with analyses of SOP sensitivity to CSI error and scalability to dense users/eavesdroppers, confirms its robustness, efficiency, and applicability to large-scale, secure IIoT communications in beyond 5G/6G networks aligned with Industry 5.0 requirements. Uchenna P. Enwereonye, Ahmad Salehi S., Hooman Alavizadeh, A. S. M. Kayes |
IEEE Internet Things J. | 3 |
| 2025 | Safeguarding Individuals and Organizations From Privacy Breaches: A Comprehensive Review of Problem Domains, Solution Strategies, and Prospective Research DirectionsabstractPrivacy breaches have become increasingly prevalent, exposing individuals to significant risks. These breaches can have far-reaching consequences, including identity theft and life-threatening situations. Several studies have analyzed data and privacy breaches and presented detection or prevention techniques to combat these breaches. However, because the number and type of breaches have significantly increased, these studies have become less relevant or outdated. Previous research on data and privacy breaches compared the techniques and results of various studies. However, none comprehensively analyzed the type of information and the level and severity of compromise that occurred after such breaches. In this survey, we examine the fundamental concepts of privacy and security and define the security incidents and data/privacy breaches. We propose a set of criteria to evaluate the published studies on privacy breaches. We thoroughly investigate the problem domains and security-related concerns considering six recent breach cases in Australia, elucidating the critical challenges and issues associated with privacy breaches. We comprehensively review and outline the trends and severity of security incidents and data/privacy breaches from 2020 to 2024. Additionally, we review the current state-of-the-art countermeasures to safeguard against these breaches. Finally, we identify an open research direction to develop an artificial intelligence (AI)-powered security framework. This framework aims to analyze cyber threats, characterize attackers’ behaviors, distinguish between legitimate and illegitimate privacy policies, and restrict access to individuals’ information. Overall, this survey will help organizations to reassess and update their security and privacy measures. A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon, Ahmad Salehi S., Hooman Alavizadeh |
IEEE Internet Things J. | 5 |
| 2023 | Harnessing GPT-4 for generation of cybersecurity GRC policies: A focus on ransomware attack mitigationabstractThis study investigated the potential of Generative Pre-trained Transformers (GPTs), a state-of-the-art large language model, in generating cybersecurity policies to deter and mitigate ransomware attacks that perform data exfiltration. We compared the effectiveness, efficiency, completeness, and ethical compliance of GPT-generated Governance, Risk and Compliance (GRC) policies, with those from established security vendors and government cybersecurity agencies, using game theory, cost-benefit analysis, coverage ratio, and multi-objective optimization. Our findings demonstrated that GPT-generated policies could outperform human-generated policies in certain contexts, particularly when provided with tailored input prompts. To address the limitations of our study, we conducted our analysis with thorough human moderation, tailored input prompts, and the inclusion of legal and ethical experts. Based on these results, we made recommendations for corporates considering the incorporation of GPT in their GRC policy making. Timothy R. McIntosh, Tong Liu 0016, Teo Susnjak, Hooman Alavizadeh, Alex Ng, Raza Nowrozy, Paul A. Watters |
Comput. Secur. | 4 |
| 2022 | A Novel Hybrid Approach for Multi-Dimensional Data Anonymization for Apache SparkabstractMulti-dimensional data anonymization approaches (e.g., Mondrian) ensure more fine-grained data privacy by providing a different anonymization strategy applied for each attribute. Many variations of multi-dimensional anonymization have been implemented on different distributed processing platforms (e.g., MapReduce, Spark) to take advantage of their scalability and parallelism supports. According to our critical analysis on overheads, either existing iteration-based or recursion-based approaches do not provide effective mechanisms for creating the optimal number of and relative size of resilient distributed datasets (RDDs), thus heavily suffer from performance overheads. To solve this issue, we propose a novel hybrid approach for effectively implementing a multi-dimensional data anonymization strategy (e.g., Mondrian) that is scalable and provides high-performance. Our hybrid approach provides a mechanism to create far fewer RDDs and smaller size partitions attached to each RDD than existing approaches. This optimal RDD creation and operations approach is critical for many multi-dimensional data anonymization applications that create tremendous execution complexity. The new mechanism in our proposed hybrid approach can dramatically reduce the critical overheads involved in re-computation cost, shuffle operations, message exchange, and cache management. Sibghat Ullah Bazai, Julian Jang, Hooman Alavizadeh |
ACM Trans. Priv. Secur. | 3 |
| 2021 | Evaluating the effectiveness of shuffle and redundancy MTD techniques in the cloud
Hooman Alavizadeh, Jin B. Hong, Dong Seong Kim 0001, Julian Jang |
Comput. Secur. | 1 |
| 2020 | Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the CloudabstractThe cloud model allows many enterprises able to outsource computing resources at an affordable price without having to commit the expense upfront. Although the cloud providers are responsible for the security of the cloud, there are still many security concerns due to inherently complex model the cloud providers operate on (e.g.,multi-tenancy). In addition, the enterprises whose services have migrated into the cloud have a preference for their own cybersecurity situation awareness capability on top of the security mechanisms provided by the cloud providers. In this way, the enterprises can monitor the performance of the security offerings of the cloud and have a choice to decide and select potential response strategies more appropriate to the enterprise in the presence of the attack where the defense provided by the cloud doesn't work for them. However, some response strategies, such as Moving Target Defense (MTD) techniques shown to be effective to secure cloud, cannot be deployed by the enterprise themselves. In this paper, we propose a framework that enables better collaboration between enterprises and cloud providers. Our proposed framework, which offers more in-depth security analysis based on the set of most advanced security metrics, allows the security experts of the enterprise to obtain better situational awareness in the cloud. With better and more effective situation awareness of cloud security, our framework can support better decision-making and further allows to deploy more appropriate threat responses to protect the outsourced resources. We also propose a secure protocol which can facilitate more secure communication between the enterprises and cloud provider. Using our proposed secure protocol, which is based on authentication and key exchange mechanism, the enterprises can send a secure request to the cloud provider to perform a selected defensive strategy. Hootan Alavizadeh, Hooman Alavizadeh, Julian Jang |
TrustCom | 2 |
| 2020 | Model-based evaluation of combinations of Shuffle and Diversity MTD techniques on the cloud
Hooman Alavizadeh, Dong Seong Kim 0001, Julian Jang |
Future Gener. Comput. Syst. | 1 |
| 2017 | A Secure Server-Based Pseudorandom Number Generator Protocol for Mobile Devices
Hooman Alavizadeh, Hootan Alavizadeh, Kudakwashe Dube, Dong Seong Kim 0001, Julian Jang, Hans W. Guesgen |
ISPEC | 1 |
| 2017 | Effective Security Analysis for Combinations of MTD Techniques on Cloud Computing (Short Paper)
Hooman Alavizadeh, Dong Seong Kim 0001, Jin B. Hong, Julian Jang |
ISPEC | 1 |
| 2013 | Secure true random number generator in WLAN/LANabstractWireless networks need more security in comparison to the other networks due to their intrinsic vulnerabilities to possible attacks. It is expected that by using a distributed method for true random number generators (TRNG) in wireless sensor networks (WSN) and wireless LAN (WLAN) randomness quality of generated numbers can be enhanced. We analyze a protocol for a distributed TRNG named ScatterLight (L. R. Giuseppe, M. Fabrizio and O. Marco, 2011) for a WSN. After making some changes on ScatterLight structure and physical data sources, the Enhanced ScatterLight protocol is introduced; it provides secure and high qualified true random numbers. Thus, the quality of randomness of obtained random numbers using National Institute of Standards and Technology tests is evaluated. Finally, by analyzing the results, it can be conducted that Enhanced ScatterLight protocol in comparisons with ScatterLight protocol in WLAN and LAN provides 60% and 53% better randomness quality respectively, while the performance is equal in both protocols. Alexander G. Chefranov, SeyedMasoud Alavi Abhari, Hooman Alavizadeh, Maryam Farajzadeh-Zanjani |
SIN | 3 |