EDBT 2026 Demo / reviewers in the wild / expert
Reza Tourani
dblp:144/4933
· DBLP profile ↗
15ranked-venue papers
1as first author
9since 2021 · last 2025
0000-0002-4561-4546ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 6 since 2021Computer networks · 4 · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Privacy Analysis of Oblivious DNS over HTTPS: a Website Fingerprinting StudyabstractAs our digital presence expands, safeguarding private data and preserving online privacy becomes paramount. Thus, motivating the development of secure DNS systems, such as DNS over TLS or HTTPS. The vulnerability of these protocols against privacy attacks has led to the development of the Oblivious DNS-over-HTTPS (ODoH) protocol. Nevertheless, the extent of ODoH’s effectiveness in protecting clients’ privacy is still unknown. This study investigates ODoH resiliency against website fingerprinting attacks in the open-world setting. We deploy an ODoH testbed on GENI for data collection and employ deep learning techniques such as ensemble learning for data analysis. Our findings reveal that a passive adversary can identify targeted websites using ODoH traces with an accuracy of 94%. Additionally, we analyze the impact of various factors, including clients’ locations, available resolvers, and time stability, on the attack’s success. Finally, we prototype a mitigation strategy and demonstrate its effectiveness in safeguarding clients privacy. Mohammad Amir Salari, Abhinav Kumar 0007, Federico Rinaudi, Reza Tourani, Alessio Sacco, Flavio Esposito |
DSN | 4 |
| 2025 | Mitigating De-Authentication DoS Attacks in 802.11 via eBPF and XDPabstractDe-authentication Denial of Service (DoS) attacks in wireless networks allow adversaries to maliciously disassociate devices, interrupting communication and effectively denying service. The 802.11w protocol was designed to counter this issue using Protected Management Frames (PMF). However, our analysis reveals that during de-authentication DoS attacks, throughput drops significantly, and client disconnections may occur, exposing the limitations of the 802.11w protocol. Extended Berkeley Packet Filter (eBPF) and eXpress Data Path (XDP) technologies, recently adopted in wired networks to enhance packet processing efficiency, remain largely unexplored in wireless networks and their unique challenges, such as those posed by the 802.11 protocol. In this paper, we introduce a novel approach that integrates eBPF/XDP into the mac80211 Linux kernel module to mitigate de-authentication attacks in near real-time with minimal overhead. Our solution partially overcomes the shortcomings of the 802.11w protocol, offering a more robust defense. Alessandro Sangiorgi, Andrea Pinto, Reza Tourani, Flavio Esposito |
NetSoft | 3 |
| 2025 | Persistent Backdoor Attacks in Continual Learning
Abhinav Kumar 0007, Reza Tourani |
USENIX Security Symposium | 3 |
| 2024 | A Generative Framework for Low-Cost Result Validation of Machine Learning-as-a-Service InferenceabstractThe growing popularity of Machine Learning (ML) has led to its deployment in various sensitive domains, which has resulted in significant research focused on ML security and privacy. However, in some applications, such as Augmented/Virtual Reality, integrity verification of the outsourced ML tasks is more critical-a facet that has not received much attention. Existing solutions, such as multi-party computation and proof-based systems, impose significant computation overhead, which makes them unfit for real-time applications. We propose Fides, a novel framework for real-time integrity validation of ML-as-a-Service (MLaaS) inference. Fides features a novel and efficient distillation technique-Greedy Distillation Transfer Learning-that dynamically distills and fine-tunes a space and compute-efficient verification model for verifying the corresponding service model while running inside a trusted execution environment. Fides features a client-side attack detection model that uses statistical analysis and divergence measurements to identify, with a high likelihood, if the service model is under attack. Fides also offers a re-classification functionality that predicts the original class whenever an attack is identified. We devised a generative adversarial network framework for training the attack detection and re-classification models. The evaluation shows that Fides achieves an accuracy of up to 98% for attack detection and 94% for re-classification. Abhinav Kumar 0007, Miguel A. Guirao Aguilera, Reza Tourani, Satyajayant Misra |
AsiaCCS | 3 |
| 2024 | PEPPER: Privacy-prEserving, auditable, and fair Payment based resource discovery at the PERvasive edgeabstractPervasive Edge Computing (PEC), a recent addition to the edge computing paradigm, leverages the computing resources of end-user devices to execute computation tasks in close proximity to users. One of the primary challenges in the PEC environment is determining the appropriate servers for offloading computation tasks based on factors, such as computation latency, response quality, device reliability, and cost of service. Computation outsourcing in the PEC ecosystem requires additional security and privacy considerations. Finally, mechanisms need to be in place to guarantee fair payment for the executed service(s). Emrah Sariboz, Reza Tourani, Roopa Vishwanathan, Satyajayant Misra |
AsiaCCS | 2 |
| 2023 | IoT Sentinel: Correlation-based Attack Detection, Localization, and Authentication in IoT NetworksabstractSecurity issues have become one of the major challenges for Internet-of-Things (IoT) networks. To overcome this challenge, the recent commonly-used approaches mainly focus on conducting encryption on IoT communication or performing continuous authentication for IoT devices by using pre-shared credentials (e.g., passcode and wireless channel signatures). However, these mechanisms are deemed insufficient, in part, due to the increasing number of data breaches and the recent proliferation of sensitive IoT devices and applications. We present IoT Sentinel - a novel security system that explores the correlation between IoT devices to effectively and efficiently secure IoT networks. Specifically, our system (i) detects potential attacks, (ii) localizes the attacker, and (iii) conducts dynamic implicit authentication at the same time. Moreover, instead of requiring full physical-layer access to IoT devices for finegrained measurement of the wireless signal, IoT Sentinel uses only coarse packet-level device correlation information to secure IoT networks with negligible overhead to the network. Thus, making our approach compatible with existing constrained IoT devices. We extensively evaluate the efficacy of IoT Sentinel in different scenarios and settings. The experiment results show that our approach achieves around 96% attack detection accuracy, more than 70% attacker localization accuracy, and around 100% device authentication accuracy. Dianshi Yang, Abhinav Kumar 0007, Stuart Ray, Wei Wang 0190, Reza Tourani |
ICCCN | 5 |
| 2022 | Harpocrates: Anonymous Data Publication in Named Data NetworkingabstractNamed-Data Networking (NDN), a realization of the Information-Centric Networking (ICN) vision, offers a request-response communication model where data is identified based on application-defined names at the network layer. This amplifies the ability of censoring authorities to restrict access to certain data/websites/applications and monitor user requests. The majority of existing NDN-based frameworks have focused on enabling users in a censoring network to access data available outside of this network, without considering how data producers in a censoring network can make their data available to users outside of this network. This problem becomes especially challenging, since the NDN communication paths are symmetric, while producers are mandated to sign the data they generate and identify their certificates. In this paper, we propose Harpocrates, an NDN-based framework for anonymous data publication under censorship conditions. Harpocrates enables producers in censoring networks to produce and make their data available to users outside of these networks while remaining anonymous to censoring authorities. Our evaluation demonstrates that Harpocrates achieves anonymous data publication under different settings, being able to identify and adapt to censoring actions. Md Washik Al Azad, Reza Tourani, Abderrahmen Mtibaa, Spyridon Mastorakis |
SACMAT | 2 |
| 2021 | DLWIoT: Deep Learning-based Watermarking for Authorized IoT OnboardingabstractThe onboarding of IoT devices by authorized users constitutes both a challenge and a necessity in a world, where the number of IoT devices and the tampering attacks against them continuously increase. Commonly used onboarding techniques today include the use of QR codes, pin codes, or serial numbers. These techniques typically do not protect against unauthorized device access-a QR code is physically printed on the device, while a pin code may be included in the device packaging. As a result, any entity that has physical access to a device can onboard it onto their network and, potentially, tamper it (e.g., install malware on the device). To address this problem, in this paper, we present a framework, called Deep Learning-based Watermarking for authorized IoT onboarding (DLWIoT), featuring a robust and fully automated image watermarking scheme based on deep neural networks. DLWIoT embeds user credentials into carrier images (e.g., QR codes printed on IoT devices), thus enables IoT onboarding only by authorized users. Our experimental results demonstrate the feasibility of DLWIoT, indicating that authorized users can onboard IoT devices with DLWIoT within 2.5-3sec. Spyridon Mastorakis, Xin Zhong 0001, Pei-Chi Huang, Reza Tourani |
CCNC | 4 |
| 2021 | APECS: A Distributed Access Control Framework for Pervasive Edge Computing ServicesabstractEdge Computing is a new computing paradigm where applications operate at the network edge, providing low-latency services with augmented user and data privacy. A desirable goal for edge computing is pervasiveness, that is, enabling any capable and authorized entity at the edge to provide desired edge services--pervasive edge computing (PEC). However, efficient access control of users receiving services and edge servers handling user data, without sacrificing performance is a challenge. Current solutions, based on "always-on" authentication servers in the cloud, negate the latency benefits of services at the edge and also do not preserve user and data privacy. In this paper, we present APECS, an advanced access control framework for PEC, which allows legitimate users to utilize any available edge services without need for communication beyond the network edge. The APECS framework leverages multi-authority attribute-based encryption to create a federated authority, which delegates the authentication and authorization tasks to semi-trusted edge servers, thus eliminating the need for an "always-on" authentication server in the cloud. Additionally, APECS prevents access to encrypted content by unauthorized edge servers. We analyze and prove the security of APECS in the Universal Composability framework and provide experimental results on the GENI testbed to demonstrate the scalability and effectiveness of APECS. Sean Dougherty, Reza Tourani, Gaurav Panwar, Roopa Vishwanathan, Satyajayant Misra, Srikathyayani Srikanteswara |
CCS | 2 |
| 2019 | AccConF: An Access Control Framework for Leveraging In-Network Cached Data in the ICN-Enabled Wireless EdgeabstractThe fast-growing Internet traffic is increasingly becoming content-based and driven by mobile users, with users more interested in data rather than its source. This has precipitated the need for an information-centric Internet architecture. Research in information-centric networks (ICNs) have resulted in novel architectures, e.g., CCN/NDN, DONA, and PSIRP/PURSUIT; all agree on named data based addressing and pervasive caching as integral design components. With network-wide content caching, enforcement of content access control policies become non-trivial. Each caching node in the network needs to enforce access control policies with the help of the content provider. This becomes inefficient and prone to unbounded latencies especially during provider outages. In this paper, we propose an efficient access control framework for ICN, which allows legitimate users to access and use the cached content directly, and does not require verification/authentication by an online provider authentication server or the content serving router. This framework would help reduce the impact of system down-time from server outages and reduce delivery latency by leveraging caching while guaranteeing access only to legitimate users. Experimental/simulation results demonstrate the suitability of this scheme for all users, but particularly for mobile users, especially in terms of the security and latency overheads. Satyajayant Misra, Reza Tourani, Frank Natividad, Travis Mick, Nahid Ebrahimi Majd, Hong Huang 0003 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | TACTIC: Tag-Based Access ConTrol Framework for the Information-Centric Wireless Edge NetworksabstractPervasive content caching is one of the information-centric networking (ICN) fundamentals. Although advantageous, pervasive caching introduces new challenges. In particular, the high possibility of content providers losing control over their published contents, which clients can access without authenticating themselves. The approaches that constitute the state-of-the-art in access control either have high computation overhead or require an always-online authentication server, thus suffering in terms of scalability for large number of end devices. In this paper, we propose TACTIC, a lightweight access control mechanism for the ICN wireless edge, which allows legitimate clients to utilize the cached content without per-request authentication at the providers. TACTIC delegates the authentication and authorization tasks to the (semi-trusted) routers in an ISP's network to eliminate the need for an always-online authentication server. It prevents delivery of the encrypted content to unauthorized users; a bandwidth-wasteful practice, which may lead to Distributed Denial of Service (DDoS) attack. Experimental results demonstrate the scalability and effectiveness of TACTIC in providing low-overhead access to legitimate clients while preventing malicious users' access. Reza Tourani, Ray Stubbs, Satyajayant Misra |
ICDCS | 1 |
| 2018 | LASeR: Lightweight Authentication and Secured Routing for NDN IoT in Smart CitiesabstractRecent literature suggests that the Internet of Things (IoT) scales much better in an information-centric networking (ICN) model instead of the current host-centric Internet protocol (IP) model. In particular, the named data networking (NDN) project (one of the ICN architecture flavors) offers features exploitable by IoT applications, such as stateful forwarding, in-network caching, and built-in assurance of data provenance. Though NDN-based IoT frameworks have been proposed, none have adequately and holistically addressed concerns related to secure onboarding and routing. Additionally, emerging IoT applications such as smart cities require high scalability and thus pose new challenges to NDN routing. Therefore, in this paper, we propose and evaluate a novel, scalable framework for lightweight authentication and hierarchical routing in the NDN IoT. Our ns-3 based simulation analyses demonstrate that our framework is scalable and efficient. It supports deployment densities as high as 40000 nodes/km2with an average onboarding convergence time of around 250 s and overhead of less than 20 kibibytes per node. This demonstrates its efficacy for emerging large-scale IoT applications such as smart cities. Travis Mick, Reza Tourani, Satyajayant Misra |
IEEE Internet Things J. | 2 |
| 2017 | Pseudo-Tree Construction Heuristics for DCOPs and Evaluations on the ns-2 Network SimulatorabstractDistributed Constraint Optimization Problems (DCOPs) are commonly used to model multi-agent coordination problems. However, empirical evaluations of DCOP algorithms are typically done in simulation under the assumption that the communication times between all pairs of agents are identical, which is unrealistic in many real-world applications. In this paper, we investigate the impact of empirically evaluating a DCOP algorithm under the assumption that communication times between pairs of agents can vary and propose the use of ns-2, a de-facto simulator used by the computer networking community, to simulate the communication times. Additionally, we introduce heuristics that exploit the non- uniform communication times to speed up DCOP algorithms that operate on pseudo-trees. Atena M. Tabakhi, Reza Tourani, Francisco Natividad, William Yeoh 0001, Satyajayant Misra |
ICTAI | 2 |
| 2014 | Split-Cache: A holistic caching framework for improved network performance in wireless ad hoc networksabstractWireless ad hoc networks (WAHNs) consist of autonomous nodes cooperating with each other to transmit/receive data over multiple-hops in the network. Caching is a useful mechanism to leverage this cooperation. Nodes with cached content can satisfy requests from other nodes, thus helping reduce network traffic and energy consumption, and improve latency. With the proliferation of wireless devices on the Internet and the proposal of a future Internet with emphasis on in-network caching, improvements in caching can significantly improve network response while reducing network load. In this paper, we present a holistic caching framework, Split-Cache, which enables a network node to account for the frequency of requests of data items and their presence in the network, and to leverage a split-cache (one part caches popular items and the other caches less popular items) to make caching and cache-eviction decisions. We performed exhaustive simulations to compare Split-Cache with the state-of-the-art: Split-Cache improved the cache request resolution time on an average by 30% (and as high as 72%), and required 15% less average traffic for resolving requests-large savings when considering large number of requests. Nahid Ebrahimi Majd, Satyajayant Misra, Reza Tourani |
GLOBECOM | 3 |
| 2014 | Towards Achieving Linear Capacity Scaling in Wireless Networks through Directed Energy LinksabstractLarge-scale multi-hop wireless networks have many important applications. However, Gupta and Kumar showed that the capacity of multi-hop wireless networks decreases as the number of nodes in the network increases. Subsequent research efforts to achieve linear capacity scaling have significant limitations such as long latency, high technical complexity, restricted traffic pattern, or infrastructure requirement. We propose to achieve close-to-linear (CTL) capacity scaling through the use of directed energy (DE) links such as laser communications links or highly directional pencil beam links in the EHF band in a hybrid network that also contains traditional omni-directional (OD) antenna links. Our approach has none of limitations mentioned earlier. We show that when the probability distribution of DE links follows the inverse-square law, a distributed scheme with local routing information suffice to achieve CTL capacity scaling. Hong Huang 0003, Yousef Jaradat, Satyajayant Misra, Reza Tourani |
IEEE Trans. Wirel. Commun. | 4 |