EDBT 2026 Demo / reviewers in the wild / expert
Sajjad Dadkhah
dblp:147/3667
· DBLP profile ↗
24ranked-venue papers
5as first author
20since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 1 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 2 since 2021Computer networks · 4 · 4 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Explainable resource-Aware IoT security model via knowledge distillation and adaptive loss function optimizationabstract• Developed RAID-KL, a teacher-student framework tailored for IoT security. • Validated RAID-KL on multiple data, achieving superior accuracy and efficiency. • RAID-KL achieves 11.3% and 64.33% reduction in CPU and memory usage, respectively. • RAID-KL compressed teacher model by 91.24% with an accuracy of approx. 99.75% • Applied SHAP to interpret feature contributions for IoT attack detection. Knowledge distillation (KD) is a pivotal model compression technique that enables the deployment of lightweight neural networks on resource-constrained Internet of Things (IoT) devices without sacrificing predictive performance. In the literature, KD has been widely applied to intrusion detection designs using the Kullback-Leibler (KL) divergence loss to align the distillation loss. However, KL divergence suffers from asymmetry and numerical instability when student predictions poorly match teacher distributions. The Jensen-Shannon (JS) divergence presents an alternative that allows both distributions to be treated equally relative to their average and ensures more balanced knowledge transfer process. The JS although symmetric and bounded, may converge more slowly due to its conservative nature. This study introduces RAID-KL , a resource-aware security model that leverages KD and a novel adaptive loss function combining hybrid KL and JS divergence. By integrating the benefits of both divergences, our method enhances the generalization and convergence of distilled models while maintaining low computational overhead, balanced knowledge sharing and improved numerical robustness. RAID-KL utilizes 1D Convolutional Neural Networks (1DCNNs) as the learning algorithm with teacher-student paradigm where a complex model serves as the teacher model, transferring its learned representations to a significantly smaller student network. RAID-KL is trained and evaluated in real-world network traffic datasets, including CICIoT2023, CICIoMT2024 and NIMSLABIoT2025, which include several IoT threats. RAID-KL demonstrates high performance in all applied metrics and low resource utilization during training and inference. To elucidate the critical relationships and feature contributions in model decisions, we integrate SHapley Additive exPlanations (SHAP) values for interpretability. Our findings reveal that the choice of loss function significantly impacts both performance and resource efficiency, with the hybrid KL-JS loss achieving superior trade-offs. Empirically, RAID-KL achieves 11.3% reduction in CPU usage and 64.33% reduction in memory usage during inference. Additionally, the RAID-KL model achieves 91.24% model compression over the teacher model while maintaining nearly the same classification accuracy. These insights highlight the robustness of RAID-KL framework, while providing a nuanced explainable index compared to the literature. Ogobuchi Daniel Okey, Sajjad Dadkhah, Demóstenes Zegarra Rodríguez, João H. Kleinschmidt |
Expert Syst. Appl. | 2 |
| 2026 | Evaluating Generative Reasoning Models for Credential Tweaking and Lightweight Client-Side Defense in IoT EcosystemsabstractGenerative reasoning models introduce a new paradigm in cybersecurity, enabling not only novel defenses but also sophisticated attack simulations. This paper investigates the use of open-source reasoning models to simulate credential tweaking behavior and enhance password-based authentication security in IoT environments. We propose Hybrid Similarity Scoring (HSS) and its user-contextualized variant HSSuser, a lightweight, client-side similarity metric combining structural (Damerau-Levenshtein) and character-distribution (cosine similarity) components to detect password reuse and subtle modifications or tweaks in real time. Following NIST guidelines, we analyzed over 4 billion password pairs from breached datasets and used five prompt designs in various reasoning models such as DeepSeek-R1, Qwen-QwQ, Phi4-Reasoning, Qwen3, and Magistral series to generate password variants mimicking attacker strategies. Experimental results show that reasoning models can produce highly similar modifications resembling real-world password reuse patterns, while prompt reframing significantly reduces risky outputs. HSS effectively quantifies these behaviors and is suitable for deployment in constrained IoT devices, offering an intent-aware, proactive layer of client-side defense against AIenhanced credential attacks. Erika Thea Ajes, Mahdi Rabbani, Zeynab Anbiaee, Rongxing Lu, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Sajjad Dadkhah |
IEEE Internet Things J. | 8 |
| 2026 | CIC-YNU-IoTMal: A comprehensive multilayer dataset for static and dynamic analysis of IoT malware behaviorabstractMalware continues to pose a critical security threat to the Internet of Things (IoT) ecosystem, driven by the diversity and dynamics of network environments. These conditions introduce significant vulnerabilities, rendering IoT devices prime targets for sophisticated malware attacks. Honeypots have been employed to emulate IoT devices and generate comprehensive malware datasets, enabling the development of adaptive defense systems. However, existing approaches often rely solely on static or dynamic analysis, which fails to keep pace with the evolving nature of malware. Moreover, rigorous detection requires high-fidelity datasets that reflect real-world threats, yet publicly available, multi-architecture IoT malware datasets with recent signatures remain scarce. To address this gap, we present CIC-YNU-IoTMal, a well-researched dataset integrating static and dynamic malware behaviors. Leveraging IoTPOT data and simulated IoT devices, we captured raw network packets, system calls, and system activity logs. Specifically, 10,000 malware binaries were executed on simulated IoT devices within Docker containers and sandbox environments tailored to each architecture. The pipeline processes ARM, MIPS, MIPSEL, and x86 architectures, collecting network traffic (PCAP), system traces (STRACE), and system statistics (SAR). These files were converted to CSV, analyzed, and used to train machine learning algorithms for malware classification. CIC-YNU-IoTMal comprises 2.4M PCAP, 1.8M SAR, and 105M STRACE samples across architectures, representing families such as Mirai, Bashlite (Gafgyt), DarkNexus, Rudedevil, Agent, Generic, and Tsunami. Experimental validation demonstrates that dynamic malware behaviors can be effectively tracked and detected. CIC-YNU-IoTMal2026 is publicly available, advancing research toward a more secure IoT environment. Sajjad Dadkhah, Ogobuchi Daniel Okey, Sebin Abraham Maret, Yen-Wu Lo, Amir Firouzi, Ryu Kuki, Takayuki Sasaki, Katsunari Yoshioka, Tao Ban, Seiichi Ozawa, Ali A. Ghorbani 0001 |
Inf. Syst. | 1 |
| 2026 | A lightweight defense mechanism against next-generation of phishing emails using distilled attention-augmented BiLSTMabstractThe current generation of large language models produces sophisticated social-engineering content that bypasses standard text screening systems in business communication platforms. Our proposed solution for mail gateway and endpoint deception detection operates in a privacy-protective manner while handling the performance requirements of network and mobile security systems. The MobileBERT teacher receives fine-tuning before its transformation into a BiLSTM model with multi-head attention which maintains semantic discrimination only with 4.5 million parameters. The hybrid dataset contains human-written messages together with LLM-generated paraphrases that use masking techniques and personalization methods to enhance modern attack resistance. The evaluation system uses five testing protocols which include human-only and LLM-only tests and two cross-distribution transfer tests and a production-like mixed traffic test to assess performance in native environments and across different distribution types and combined traffic scenarios. The distilled model maintains a weighted-F1 score difference of 1–2.5 points compared to the mixture split results of strong transformer baselines including ModernBERT, DeBERTaV3-base, T5-base, DeepSeek-R1 Distill Qwen-1.5B and Phi-4 mini while achieving 80–95% faster inference times and 95–99% smaller model sizes. The system demonstrates excellent performance in terms of accuracy and latency while maintaining a compact size which enables real-time filtering without acceleration hardware and supports policy-based management. The paper examines system performance under high traffic conditions and security measures for privacy protection and implementation methods for operational deployment. The research team will release all necessary code and training scripts and corpus splits to support security researchers who want to reproduce experiments and implement practical solutions. Morteza Eskandarian, Mahdi Rabbani, Arun Kaniyamattam, Fatemeh Nejati, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Ali A. Ghorbani 0001, Sajjad Dadkhah |
J. Inf. Secur. Appl. | 9 |
| 2026 | URL2Path: A Robust Graph Learning Approach for Malicious URL DetectionabstractPhishing attacks remain one of the most popular, damaging cyber threats, with malicious Uniform Resource Locators (URLs) acting as a primary vector for credential theft, malware distribution. Traditional detection approaches, based on phishing keyword matching, static rule-based systems, struggle against modern phishing attempts due to syntactic variability, semantic obfuscation, adversarial manipulation. Recent advances in Large Language Models (LLMs) have further enabled attackers to generate visually deceptive, syntactically diverse URLs that evade lexical similarity filters. To address these emerging challenges, this paper introduces a content-independent phishing URL detection framework that combines lexical feature extraction with graph-based reasoning. The proposed technique, URL2Path, tokenizes URL strings into sequential segments, maps them onto a homogeneous directed graph, where structural, semantic patterns are captured using DeepWalk-based node embeddings. This approach addresses three key limitations in existing systems: limited scalability of content-based detection, weak robustness of traditional models against LLM generated adversarial URLs, the absence of graph-structured reasoning to vectorize raw URLs into expressive representations. Experimental evaluations show that URL2Path achieves superior precision, recall, F1-score, particularly under cross-dataset validation, adversarial stress testing, imbalanced training conditions. The model is benchmarked against recent lightweight LLMs (BERT-Tiny, DeBERTa-v3, ModernBERT, DeepSeek), demonstrating improved detection accuracy, faster inference. Additionally, we assess its scalability to million-scale datasets, cross-domain generalization, robustness against adversarial perturbations. Mahdi Rabbani, Morteza Eskandarian, Mansur Mirani, Gunjan Piya, Igor V. Opushnyev, Rongxing Lu, Sajjad Dadkhah |
IEEE Trans. Reliab. | 7 |
| 2025 | FragmentFool: Fragment-based Adversarial Perturbation for Graph Neural Network-based Vulnerability DetectionabstractSoftware vulnerability detection has achieved promising performance using graph neural networks (GNNs) to capture structural information in source code graph representations. However, these methods are vulnerable to various attacks. Exploiting GNN vulnerabilities can significantly compromise the robustness and reliability of these detection systems. In this study, we investigate the susceptibility of the current GNN-based source code vulnerability detection methods to structural perturbations. We propose a novel approach to perturb GNN inputs through fragment or subtree manipulation of the original graph representations, such as abstract syntax trees, targeting structure features as a critical feature when using GNN for vulnerability detection. Our comprehensive experiments demonstrate that the proposed perturbation approach effectively attacks common GNN models, thereby reducing the overall performance. Muhammad Fakhrur Rozi, Tao Ban, Seiichi Ozawa, Hiroaki Inoue, Takeshi Takahashi 0001, Sajjad Dadkhah |
PST | 6 |
| 2024 | Enhancing EV Charging Station Security Using a Multi-dimensional Dataset: CICEVSE2024
Emmanuel Dana Buedi, Ali A. Ghorbani 0001, Sajjad Dadkhah, Raphael Ferreira |
DBSec | 3 |
| 2024 | Resilience Against APTs: A Provenance-Based IIoT Dataset for Cybersecurity Research
Erfan Ghiasvand, Suprio Ray, Shahrear Iqbal, Sajjad Dadkhah, Ali A. Ghorbani 0001 |
MobiQuitous | 4 |
| 2024 | A review of Machine Learning (ML)-based IoT security in healthcare: A dataset perspective
Euclides Carlos Pinto Neto, Sajjad Dadkhah, Somayeh Sadeghi, Heather Molyneaux, Ali A. Ghorbani 0001 |
Comput. Commun. | 2 |
| 2024 | IoT-PRIDS: Leveraging packet representations for intrusion detection in IoT networksabstractThe Internet of Things (IoT) devices have been integrated into almost all everyday applications of human life such as healthcare, transportation and agriculture. This widespread adoption of IoT has opened a large threat landscape to computer networks, leaving security gaps in IoT-enabled networks. These resource-constrained devices lack sufficient security mechanisms and become the weakest link in our in computer networks and jeopardize systems and data. To address this issue, Intrusion Detection Systems (IDS) have been proposed as one of many tools to mitigate IoT related intrusions. While IDS have proven to be a crucial tools for threat detection, their dependence on labeled data and their high computational costs have become obstacles to real life adoption. In this work, we present IoT-PRIDS, a new framework equipped with a host-based anomaly-based intrusion detection system that leverages “packet representations” to understand the typical behavior of devices, focusing on their communications, services, and packet header values. It is a lightweight non-ML model that relies solely on benign network traffic for intrusion detection and offers a practical way for securing IoT environments. Our results show that this model can detect the majority of abnormal flows while keeping false alarms at a minimum and is promising to be used in real-world applications. Alireza Zohourian, Sajjad Dadkhah, Heather Molyneaux, Euclides Carlos Pinto Neto, Ali A. Ghorbani 0001 |
Comput. Secur. | 2 |
| 2024 | Transferability of Machine Learning Algorithm for IoT Device Profiling and IdentificationabstractThe lack of appropriate cyber security measures deployed on Internet of Things (IoT) makes these devices prone to security issues. Consequently, the timely identification and detection of these compromised devices become crucial. Machine learning (ML) models which are used to monitor devices in a network have made tremendous strides. However, most of the research in profiling and identification uses the same data for training and testing. Hence, a slight change in the data renders most learning algorithms to work poorly. In this article, we study a transferability approach based on the concept of transductive transfer learning for IoT device profiling and identification. Notably, this type of transfer learning works by explicitly assigning labels to the test data in the target domain by using the test feature space in the target domain, with training data from the source domain. Specifically, we propose a three-component system comprising: 1) the device type identification; 2) the vulnerability assessment; and 3) the visualization module. The device type identification component uses the underlying concept of transductive transfer learning where the trained model is transferred to a remote lab for testing. A variety of ML models are evaluated with respect to accuracy, precision, recall, and F1-score in order to determine which are the most suitable for the proposed transferability profiling. Furthermore, the vulnerability of the predicted device type is also assessed by using three vulnerability databases: 1) Vulners; 2) National Vulnerability Database (NVD); and 3) IBM X-Force. Finally, the results from the vulnerability assessment are visualized and displayed on a dashboard. Priscilla Kyei Danso, Sajjad Dadkhah, Euclides Carlos Pinto Neto, Alireza Zohourian, Heather Molyneaux, Rongxing Lu, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 2 |
| 2024 | The Largest Social Media Ground-Truth Dataset for Real/Fake Content: TruthSeekerabstractAutomatic detection of fake content in social media such as Twitter is an enduring challenge. Technically, determining fake news on social media platforms is a straightforward binary classification problem. However, manually fact-checking even a small fraction of daily tweets would be nearly impossible due to the sheer volume. To address this challenge, we crawled and crowd-sourced one of the most extensive ground-truth tweet datasets. Utilizing Politifact and expert labeling as a base, it contains more than 180 000 labels from 2009 to 2022, creating five-and three-label classification using Amazon Mechanical Turk. We utilized multiple levels of validation to ensure an accurate ground-truth benchmark dataset. Then, we created and implemented numerous machine learning and deep learning algorithms, including different variations of bidirectional encoder representations from transformers (BERT)-based models and classical machine learning algorithms on the data to test the accuracy of real/fake tweet detection with both categories. Then, determining which versions gave us the highest result metrics. Further analysis is performed on the dataset by explicitly utilizing the DBSCAN text clustering algorithm combined with the YAKE keyword creation algorithm to determine topics’ clustering and relationships. Finally, we analyzed each user in the dataset, determining their bot score, credibility score, and influence score for a better understanding of what type of Twitter user posts, their influence with each of their tweets, and if there were any underlying patterns to be drawn from each score concerning the truthfulness of the tweet. The experiment’s results illustrated profound improvement for models dealing with short-length text in solving a real-life classification problem, such as automatically detecting fake content in social media. Sajjad Dadkhah, Xichen Zhang, Alexander Gerald Weismann, Amir Firouzi, Ali A. Ghorbani 0001 |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2024 | MEFaND: A Multimodel Framework for Early Fake News DetectionabstractAlongside social media platforms’ rise in popularity, fake news circulation has increased, highlighting the need for more practical methods to detect this phenomenon. The constantly evolving format of fake news makes it difficult for approaches that rely on a single modality of news to generalize the different types of false news. Furthermore, earlier approaches require extensive propagation data to determine the veracity of news, which can be challenging to collect in the early stages of news dissemination. Thus, we propose a multimodal early fake news detection approach that leverages latent insights into both news content and propagation knowledge. We design a multimodule architecture using graph neural networks (GNNs) to represent edge-enhanced and node-enhanced propagation graphs and bidirectional encoder representations from transformers (BERTs) to generate contextualized representations of news content. Our approach tackles the challenge of early detection in a more realistic scenario, accessing early propagation data in a single social media post and short-length news content. Moreover, we conduct comprehensive studies on user characteristics using statistical techniques to identify attributes with strong discriminative capability for identifying false news. We also analyse temporal and structural properties of fake news propagation graphs to demonstrate distinguishable patterns of false and real news behavior. Our model outperforms several state-of-the-art methods, achieving an impressive F1-score of 99% and 96% on two public datasets. The individual contribution of various components in our model to the final performance is also measured, which can be insightful for future research on multimodal false news detection. Asma Sormeily, Sajjad Dadkhah, Xichen Zhang, Ali A. Ghorbani 0001 |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2024 | Multimodal Fake News Analysis Based on Image-Text SimilarityabstractWith the fast and extensive development of computer vision techniques, multimodal analyses are utilized more frequently for online fake news detection. To better understand the image–text relationship and its role in fake news detection, in this article, we proposed and evaluated four image–text similarities, namely, textual similarity, semantic similarity, contextual similarity, and post-training similarity. The textual and semantic similarities indicate the original image–text similarities in terms of the text information and image caption information. The contextual similarity reflects the image–text similarity in the format of meaningful named entities. The post-training similarity demonstrates how image–text similarity involves before and after a fake news detection model is trained. By evaluating the proposed similarity measurements on three real-world datasets, we find that fake news image–text similarity is higher than real news image–text similarity in most of the cases. Furthermore, the comparison of models’ performance further validates the significance of visual information in online fake news detection. These findings may be considered as the fundamental logic to explain the original purpose of fake news creation and can be used as influential features for improving models’ performance in the future. Xichen Zhang, Sajjad Dadkhah, Alexander Gerald Weismann, Mohammad Amin Kanaani, Ali A. Ghorbani 0001 |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2023 | UCreDiSSiT: User Credibility Measurement incorporating Domain interest, Semantics in Social interactions, and Temporal factorabstractOnline social media platforms provide a range of benefits, such as conversation and information sharing, as well as marketing and advertising for businesses. However, these platforms are soft targets for bad actors to disseminate misinformation or rumors. Untrustworthy content on social media poses a great threat to truth since any user can produce unverified online content to gain popularity. It has been realized that fake information and accounts create a great deal of confusion. To determine user credibility and promote reliable information, we propose UCreDiSSiT method, which incorporates a user's domain of interest, social relations, and temporal features. The suggested approach draws inspiration from earlier works but differs in weighing factors, formalizing factors, and addressing extreme circumstances in large-scale deployment. The experiments are conducted on real-time users' data on Twitter. Our results demonstrate the effectiveness of the proposed method. Rashid Hussain Khokhar, Sajjad Dadkhah, Xichen Zhang, Ali A. Ghorbani 0001 |
PST | 2 |
| 2022 | Towards the Development of a Realistic Multidimensional IoT Profiling DatasetabstractThe Internet of Things (IoT) is an emerging technology that enables the development of low-cost and energy-efficient IoT devices across various solutions from smart cities to healthcare domains. With such a complex and heterogeneous instance of IoT devices and their applications, numerous challenges arise in both device management and security concerns. Thus, it is essential to develop intelligent IoT identification/profiling and intrusion detection components that are tailored to IoT applications. Such systems require a realistic and multidimensional reference IoT dataset for training and evaluation. Device identification/profiling ensures the authenticity of the devices attached to the IoT network and environment which can be achieved by fingerprinting a device. Since fingerprinting is mostly examined by device network flows and device local attributes, we have proposed this study to intelligently recognize machine-to-machine communication and identify each device properly. In this paper, we analyzed the behaviour of 60 IoT devices during experiments conducted in our lab setup at the Canadian Institute for Cybersecurity (CIC). Our IoT devices include WiFi, ZigBee, and Z-Wave devices. We collected data from each device in four stages: powered on, idle, active, and interactions. Besides these stages, different scenario experiments were conducted using a microcosm of devices to simulate the network activity of a smart home. Additionally, we have generated two attack datasets, namely flood denial-of-service attack and RTSP brute-force attack. Lastly, we implement an extensive case study on the transferability of the RF classifier and train our model with the dataset from our lab, transfer the model to the dataset from a different lab and test the trained model on their dataset. This paper’s dataset materials are available on the CIC dataset page under the CIC IoT dataset 20221. Sajjad Dadkhah, Hassan Mahdikhani, Priscilla Kyei Danso, Alireza Zohourian, Kevin Anh Truong, Ali A. Ghorbani 0001 |
PST | 1 |
| 2022 | Collaborative DDoS Detection in Distributed Multi-Tenant IoT using Federated LearningabstractNowadays, the Internet of Things (IoT) has attracted much attention from the industry, and new initiatives are expected to be developed in the next decade. IoT is establishing a globally connected sensor network in which many devices are connected to the Internet generating large amounts of data. Conversely, many challenges need to be overcome to enable efficient and secure IoT applications (e.g., interoperability, security, standards, and server technologies). Furthermore, edge computing presents a paramount role in the diverse range of IoT applications. In this sense, processing sensitive data for different tenants (e.g., e-health and smart cities applications) requires transactions to be protected and isolated from different flows. Thereupon, different tenants can be targeted by Distributed Denial of Service (DDoS) attacks. However, attacks performed against a tenant remain unknown to others, preventing the improvement of detection and mitigation capabilities for DDoS attacks. The main obstacle in this collaboration relies on maintaining privacy in a multi-tenant environment while sharing the characteristics of attacks faced in the past. In this paper, we propose a collaborative DDoS detection and classification approach for distributed multi-tenant IoT environments using Federated Learning. This approach enables multiples tenants to collaboratively enhance their DDoS detection and classification capabilities across all edge nodes while maintaining their privacy. To accomplish this, tenants train deep learning instances on locally scaled traffic data and share the model parameters with other tenants. This strategy enables safer IoT operations and can be adopted in different applications. The experiments performed on a simulated environment considered the CICD-DoS2019 dataset and showed that the proposed approach can classify different DDoS attacks types with over 84.2% accuracy. The results demonstrate that collaborative DDoS detection enhances tenant protection compared to single detection. Euclides Carlos Pinto Neto, Sajjad Dadkhah, Ali A. Ghorbani 0001 |
PST | 2 |
| 2022 | Data breach: analysis, countermeasures and challenges
Xichen Zhang, Mohammad Mehdi Yadollahi, Sajjad Dadkhah, Haruna Isah, Duc-Phong Le, Ali A. Ghorbani 0001 |
Int. J. Inf. Comput. Secur. | 3 |
| 2022 | A Survey on IoT Profiling, Fingerprinting, and IdentificationabstractThe proliferation of heterogeneous Internet of things (IoT) devices connected to the Internet produces several operational and security challenges, such as monitoring, detecting, and recognizing millions of interconnected IoT devices. Network and system administrators must correctly identify which devices are functional, need security updates, or are vulnerable to specific attacks. IoT profiling is an emerging technique to identify and validate the connected devices’ specific behaviour and isolate the suspected and vulnerable devices within the network for further monitoring. This article provides a comprehensive review of various IoT device profiling methods and provides a clear taxonomy for IoT profiling techniques based on different security perspectives. We first investigate several current IoT device profiling techniques and their applications. Next, we analyzed various IoT device vulnerabilities, outlined multiple features, and provided detailed information to implement profiling algorithms’ risk assessment/mitigation stage. By reviewing approaches for profiling IoT devices, we identify various state-of-the-art methods that organizations of different domains can implement to satisfy profiling needs. Furthermore, this article also discusses several machine learning and deep learning algorithms utilized for IoT device profiling. Finally, we discuss challenges and future research possibilities in this domain. Miraqa Safi, Sajjad Dadkhah, Farzaneh Shoeleh, Hassan Mahdikhani, Heather Molyneaux, Ali A. Ghorbani 0001 |
ACM Trans. Internet Things | 2 |
| 2021 | Verification Based Scheme to Restrict IoT AttacksabstractIn recent years, with the increased usage of the Internet of Things (IoT) devices, cyber-attacks have become a serious threat over the Internet. These devices have low memory capacity and processing power, which makes them easy targets for attackers. The research community has proposed different approaches to deal with emerging variants of attacks on IoT devices using various machine learning techniques. However, these approaches rely heavily on the classifier’s categorization of a given record while ignoring its confidence. This paper proposes a verification-based scheme to reject IoT attacks by utilizing the classifier’s confidence. At the same time, existing studies are evaluated using traditional cross-validation approaches (e.g., k-fold), thus, not tested against unknown attacks. We propose using the leave-one-attack-out (LOAO) cross-validation scheme to evaluate the generalizability of the application to unknown attacks. The experiments are performed on Med BIoT, a publicly available dataset consisting of three IoT attacks. The system’s robustness is evaluated in terms of Receiver Operating Curves (ROC) and Equal Error rates (EERs). The results indicate a lower false-positive rate of 12.6% using the proposed verification-based approach in comparison to k-fold cross-validation. Barjinder Kaur, Sajjad Dadkhah, Pulei Xiong, Shahrear Iqbal, Suprio Ray, Ali A. Ghorbani 0001 |
BDCAT | 2 |
| 2019 | Blockchain Scheme Based on Evolutionary Proof of WorkabstractIn recent years, applications of the Blockchain concept, esp. as ledger for bitcoin transactions, has already resulted in huge amounts of wasted electrical energy for performing the Proof-of-Work tasks (cryptographic puzzles). Here, we consider an alternative concept to have this energy used at least for a useful purpose, the solution of real-world optimization problems. By means of the Traveling Salesperson Problem as model problem, we propose a concept to use optimization algorithms in an iterative manner to provide the Proof-of-Work needed to expand the Blockchain by a new block. The basic idea is to improve the tour cost for the best tour found for block n, extended by adding one more city, as a requirement for the inclusion of a new block in the Blockchain. This allows for the design of limited Blockchains, solving the underlying combinatorial optimization problems at the same time. Independently, it calls in for new efficient optimization algorithms and can serve as a real-world contest. It is discussed that metaheuristic algorithms perform an attractive class of optimization algorithms that can be used for the proposed approach. Numerical experiments also demonstrate the growth in problem complexity being handled by a binary PSO, which is a basic requirement for the full concept to work in practice. Willa Ariela Syafruddin, Sajjad Dadkhah, Mario Köppen |
CEC | 2 |
| 2018 | State of the art in passive digital image forgery detection: copy-move image forgery
Somayeh Sadeghi, Sajjad Dadkhah, Hamid Abdullah Jalab, Giuseppe Mazzola, Diaa M. Uliyan |
Pattern Anal. Appl. | 2 |
| 2017 | Electromagnetismlike Mechanism Descriptor with Fourier Transform for a Passive Copy-move Forgery Detection in Digital Image Forensics
Sajjad Dadkhah, Mario Köppen, Hamid Abdullah Jalab, Somayeh Sadeghi, Azizah Abdul Manaf, Diaa M. Uliyan |
ICPRAM | 1 |
| 2014 | An effective SVD-based image tampering detection and self-recovery using active watermarking
Sajjad Dadkhah, Azizah Abdul Manaf, Yoshiaki Hori, Aboul Ella Hassanien, Somayeh Sadeghi |
Signal Process. Image Commun. | 1 |