EDBT 2026 Demo / reviewers in the wild / expert
Naghmeh Moradpoor Sheykhkanloo
dblp:155/4213 · also Naghmeh Moradpoor
· DBLP profile ↗
19ranked-venue papers
4as first author
11since 2021 · last 2025
0000-0002-8709-2678ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 7 since 2021Computer networks · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Post-Quantum ZKP for Privacy-Preserving Authentication and Model Verification in Decentralized CAVabstractDecentralized and Connected Autonomous Vehicle (CAV) networks offer promising advances in safety, efficiency, and real-time decision-making. However, they face significant challenges in authentication, privacy, and scalability—especially in the face of quantum adversaries. This paper proposes a novel post-quantum secure framework that integrates lattice-based Zero-Knowledge Proofs (ZKPs), optimized Binius proofs, and Multi-Layer Compressed Counting Bloom Filters (ML-CCBF) to enable privacy-preserving authentication and model verification in decentralized CAV environments. Our lattice-based ZKP scheme achieves cryptographic commitments in under 5μs, while Binius proofs verify model integrity in less than 0.17 seconds per update. ML-CCBF ensures scalable membership filtering with 0% false positives across 1000 nodes. Experimental results confirm 100% ZKP soundness, strong resilience against simulated quantum and adaptive attacks, and stable latency under increasing network load. These findings demonstrate that our framework delivers quantum-resilient security, real-time efficiency, and robust scalability, offering a viable solution for trustworthy decentralized intelligence in next-generation vehicular systems. Ny Hasina Andriambelo, Naghmeh Moradpoor Sheykhkanloo, Leandros Maglaras |
WoWMoM | 2 |
| 2025 | APOLLO: a proximity-oriented, low-layer orchestration algorithm for resources optimization in mist computing
Messaoud Babaghayou, Noureddine Chaib, Leandros Maglaras, Yagmur Yigit, Mohamed Amine Ferrag, Carol Marsh, Naghmeh Moradpoor Sheykhkanloo |
Wirel. Networks | 7 |
| 2024 | Assessing the Performance of Ethereum and Hyperledger Fabric Under DDoS Attacks for Cyber-Physical SystemsabstractBlockchain technology offers a decentralized and secure platform for addressing various challenges in smart cities and cyber-physical systems, including identity management, trust and transparency, and supply chain management. However, blockchains are susceptible to a variety of threats, akin to any other technological system. To assess the resilience and robustness of diverse blockchain technologies, this study evaluates their performance indicators under various attack scenarios. Therefore, this study conducts a thorough examination of multiple well-known blockchain technologies, such as Ethereum and Hyperledger Fabric, under Distributed Denial of Service attack scenarios. Ethereum, introduced as a revolutionary blockchain technology, has entirely transformed the way smart contracts and decentralized applications operate. Additionally, the innovative open source blockchain framework, Hyperledger Fabric, is intended for businesses and alliances seeking a secure and adaptable platform to develop distributed ledger applications. Hyperledger Besu, an Ethereum client with an extractable Ethereum Virtual Machine implementation designed to be enterprise-friendly for both public and private permissioned network use cases. Therefore, Ethereum and Hyperledger Fabric are utilized in this study for performance comparison. This study provides a summary of Ethereum's salient characteristics, architecture, and noteworthy influence on the blockchain and cryptocurrency ecosystem. Furthermore, it offers an overview of the main characteristics, architecture, and potential uses of Hyperledger Fabric. The blockchain's resilience against DDoS attacks is assessed by examining performance measures such as latency and throughput, which are fundamental metrics crucial for evaluating and enhancing the effectiveness of various systems, including communication protocols, databases, blockchains, and computer networks. The outcomes of these experiments show that Hyperledger Fabric has greater throughput and reduced latency, demonstrating its resistance to DDoS attacks in comparison with Ethereum. Ethereum, being a permissionless blockchain, can introduce challenges such as the potential for network congestion and scalability issues. Vijay Jayadev, Naghmeh Moradpoor Sheykhkanloo, Andrei Petrovski 0001 |
ARES | 2 |
| 2024 | EV-IRP Manager: An Electric Vehicle Incident Response Playbook Manager and Visualizer ToolkitabstractIn the rapidly evolving realm of electric vehicle technology, safeguarding the cybersecurity of both electric vehicles and their charging infrastructure has become fundamental. The integration of electric vehicles and their charging stations into the broader grid introduces complex cybersecurity challenges, necessitating robust incident response strategies. Traditional cybersecurity playbooks often fall short in addressing the unique vulnerabilities associated with electric vehicles and their charging systems. The lack of publicly available community playbooks tailored to these needs leaves the electric vehicle ecosystem vulnerable to cyber threats that could compromise user privacy, vehicle functionality, and grid stability. In response to this, the project undertakes the creation of a foundational playbook for electric vehicle and electric vehicle charging station incident response, addressing a significant void in current cybersecurity practices. This paper introduces a Playbook Manager and Visualizer application, called EV-IRP, designed to enable users to upload, manage, and visualize electric vehicle and electric vehicle charging station incident response playbooks efficiently. Utilizing Python, Tkinter for GUI development, SQLite for database management, and Graphviz for visualization, the application facilitates a dynamic and responsive approach to maintaining up- to-date incident response strategies. The application is expected to streamline the management of incident response playbooks through procedure visualization, enhancing the cybersecurity posture of electric vehicle infrastructure. By converting textual playbook procedures into easily understandable diagrams, it facilitates a clearer understanding of response steps among users, thereby enhancing the overall efficiency and efficacy of incident response practices. Additionally, the research and development process, informed by a comprehensive literature review, contributes to the academic and practical understanding of cybersecurity best practices for electric vehicle technologies. Kerem Alpdag, Naghmeh Moradpoor Sheykhkanloo, Ny Hasina Andriambelo, Paul Wooderson, Leandros Maglaras |
SIN | 2 |
| 2024 | Enhancing Security and Privacy in Federated Learning for Connected Autonomous Vehicles With Lightweight Blockchain and Binius ZeroKnowledge ProofsabstractThe rise of Autonomous Vehicles (AVs) brings with it the need for secure and privacy-preserving machine learning models. Federated Learning (FL) allows AVs to collaboratively train models while keeping raw data localized. However, traditional FL systems are vulnerable to security threats, including adversarial attacks, data breaches, and dependency on a central aggregator, which can be a single point of failure. To address these concerns, this paper introduces a peer-to-peer decentralized federated learning system that integrates lightweight blockchain technology and Binius Zero- Knowledge Proofs (ZKPs) to enhance security and privacy. In this system, Binius ZKPs ensure that model updates are cryptographically verified without exposing sensitive information, guaranteeing data confidentiality and integrity during the learning process. The lightweight blockchain framework secures the network by creating an immutable, decentralized record of all model updates, thus preventing tampering, fraud, or unauthorized modifications. This decentralized approach eliminates the need for a central aggregator, significantly enhancing system resilience to attacks and making it suitable for dynamic environments like AV networks. Additionally, the system's design includes Byzantine resilience, providing protection against adversarial nodes and ensuring that the global model aggregation process remains robust even in the presence of malicious actors. Extensive performance evaluations demonstrate that the system achieves low-latency, scalability, and efficient resource usage while maintaining strong security and privacy guarantees, making it an ideal solution for real-time federated learning in autonomous vehicle networks. The proposed framework not only ensures privacy but also fosters trust among participants in a fully decentralized environment. Ny Hasina Andriambelo, Naghmeh Moradpoor Sheykhkanloo |
SIN | 2 |
| 2024 | Lightweight Blockchain Prototype for Food Supply Chain ManagementabstractThe modern food supply chain often involves multiple layers of participants spread across different countries and continents. This complex system offers significant benefits to businesses worldwide; however, it also presents several challenges. One major problem is the inability to trace the product flow back to its origin, a critical issue in many industries. Another issue is the lack of trust among supply chain participants. Blockchain technology can help address these and other challenges faced by the supply chain industry. However, it is surprising that, globally, there are still not many examples of the technology's adoption, with most projects remaining in the pilot stage. This paper explores the field of custom blockchain design tailored to specific applications, with a focus on supply chain operations in the food industry. It includes the development of a lightweight yet fully featured Python prototype for a decentralized blockchain system. In addition to common features like block validation and state updates, the prototype includes a newly designed type of transaction tailored specifically for supply chain operations. These transactions eliminate the need for smart contracts, making the system more lightweight compared to general-purpose blockchain platforms such as Ethereum and less prone to security vulnerabilities. The prototype is designed as a public blockchain network, with Proof of Work selected as the consensus algorithm. The novelty of this research work lies in advancing the concept of a custom blockchain solution for the food industry. The key elements of the prototype have been unit tested. The overall evaluation was completed using a Python script that simulates product flow through an example supply chain, allowing product provenance to be determined by tracing the product flow back to its origin. Alexey Rusakov, Naghmeh Moradpoor Sheykhkanloo, Aida Akbarzadeh |
SIN | 2 |
| 2024 | Enhancing AI-Generated Image Detection with a Novel Approach and Comparative AnalysisabstractThis study explores advancements in AI-generated image detection, emphasizing the increasing realism of images, including deepfakes, and the need for effective detection meth-ods. Traditional Convolutional Neural Networks (CNNs) have shown success but face limitations in generalization and accu-racy, particularly with newer technologies like Diffusion Models. With the evolution of AI image generation models, from CNNs to Generative Adversarial Networks (GANs) and Diffusion Models, detecting synthetic images has become more challenging. Issues include dataset diversity, adversarial attacks, and inconsistencies in pre-processing methods. While state-of-the-art models like CNNs, Vision Transformers (ViTs), and hybrid approaches exist, their accuracy in detecting increasingly sophisticated fake images remains suboptimal. This research proposes a novel hybrid detection model combining CNNs and ViTs with an additional attention mechanism layer. This structure aims to improve the interaction between local and global features, enhancing detection accuracy. The model was trained using the CIFAKE dataset, which contains 120,000 real and AI -generated images. The added attention mechanism enhances feature extraction, addressing limitations in existing models when faced with next-generation synthetic images. The hybrid CNNNiT +Attention model demonstrated improved detection accuracy, achieving 99.77%, surpassing previous methods. This research lays a foundation for stronger AI -generated image detection, helping to mitigate the risks of synthetic image fraud. Stuart Weir, Muhammad Shahbaz Khan, Naghmeh Moradpoor Sheykhkanloo, Jawad Ahmad 0001 |
SIN | 3 |
| 2023 | Fake PLC in the Cloud, We Thought the Attackers Believed that: How ICS Honeypot Deception Gets Impacted by Cloud Deployments?abstractThe Industrial Control System (ICS) industry faces an ever-growing number of cyber threats - defence against which can be strengthened using honeypots. As the systems they mimic, ICS honeypots shall be deployed in a similar context to field ICS systems. This ICS context demands a novel honeypot deployment process, that is more consistent with real ICS systems. State-of-the-art ICS honeypots mainly focus on deployments in cloud environments which could divulge the true intent to cautious adversaries. This experimental research project addresses this limitation by evaluating the deception capability of a public cloud and an on-premise deployment. Results from a 65-day, HoneyPLC experiment show that the on-premise deployment attracts more Denial of Service and Reconnaissance ICS attacks. The results guide future researchers that an on-premise deployment might be more convincing and attract more ICS-relevant interactions. Stanislava Ivanova, Naghmeh Moradpoor Sheykhkanloo |
WFCS | 2 |
| 2021 | Using IOTA as an Inter-Vehicular Trust Mechanism in Autonomous VehiclesabstractIn a perfect world, coordination and cooperation across distributed autonomous systems would be a trivial task. However, incomplete information, malicious actors and real-world conditions can provide challenges which bring the trust-worthiness of participants into question. In this work-in-progress paper, we propose the novel use of Distributed Ledger Technologies with a particular focus on IOTA to provide a trust overlay governing information interchange across autonomous vehicles. This paper outlines a number of scenarios where information interchange could provide useful data for decision making, defines how trust can be useful in this context, and provides use cases which call for evaluating the trustworthiness of the message. The paper also outlines the architecture of an IOTA-based private tangle integrated with vehicle simulation software which facilitates the evaluation of various scenarios. Owen Cutajar, Naghmeh Moradpoor Sheykhkanloo, Zakwan Jaroucheh |
SIN | 2 |
| 2021 | VNWTS: A Virtual Water Chlorination Process for Cybersecurity Analysis of Industrial Control SystemsabstractThe rapid development of technology during the last decades has led to the integration of the network capabilities in the devices that are essential in the operation of Industrial Control Systems (ICS). Consequently, the attack surface of these assets has increased, putting at risk the nations that depend heavily on them for their continuity and functions. ICS physical and virtual testbeds are ideal platforms that can be used for cybersecurity research. Compared to physical testbeds, virtual testbeds are less expensive, safer to maintain, and more accessible, especially when access to research labs is restricted due to unforeseen circumstances such as COVID 19. Therefore, in this article, we propose VNWTS, a virtual water chlorination process for ICS cybersecurity analysis. VNWTS is composed of virtual components commonly found in physical ICS implementations. In addition, we implemented a set of attacks targeting the memory of the S7-1500 PLC and other VNWTS components such as level sensors, temperature sensors, and pumps. The results obtained from the experimentation phase show that the structure, configuration, and implementation of the VNWTS testbed can be used in ICS cybersecurity research. Andres Robles-Durazno, Naghmeh Moradpoor Sheykhkanloo, James McWhinnie, Jorge Porcel-Bustamante |
SIN | 2 |
| 2021 | Newly engineered energy-based features for supervised anomaly detection in a physical model of a water supply system
Andres Robles-Durazno, Naghmeh Moradpoor Sheykhkanloo, James McWhinnie, Gordon Russell 0001, Zhiyuan Tan 0001 |
Ad Hoc Networks | 2 |
| 2020 | Real-time anomaly intrusion detection for a clean water supply system, utilising machine learning with novel energy-based featuresabstractIndustrial Control Systems have become a priority domain for cybersecurity practitioners due to the number of cyber-attacks against those systems has increased over the past few years. This paper proposes a real-time anomaly intrusion detector for a model of a clean water supply system. A testbed of such system is implemented using the Festo MPA Control Process Rig. A set of attacks to the testbed is conducted during the control process operation. During the attacks, the energy of the components is monitored and recorded to build a novel dataset for training and testing a total of five traditional supervised machine learning algorithms: K-Nearest Neighbour, Support Vector Machine, Decision Tree, Naïve Bayes and Multilayer Perceptron. The trained machine learning algorithms were built and deployed online, during the control system operation, for further testing. The performance obtained from offline and online training and testing steps are compared. The captures results show that KNN and SVM outperformed the rest of the algorithms by achieving high accuracy scores and low false-positive, false-negative alerts. Andres Robles-Durazno, Naghmeh Moradpoor Sheykhkanloo, James McWhinnie, Gordon Russell 0001 |
IJCNN | 2 |
| 2020 | Employing a Machine Learning Approach to Detect Combined Internet of Things Attacks against Two Objective Functions Using a Novel DatasetabstractOne of the important features of routing protocol for low-power and lossy networks (RPLs) is objective function (OF). OF influences an IoT network in terms of routing strategies and network topology. On the contrary, detecting a combination of attacks against OFs is a cutting-edge technology that will become a necessity as next generation low-power wireless networks continue to be exploited as they grow rapidly. However, current literature lacks study on vulnerability analysis of OFs particularly in terms of combined attacks. Furthermore, machine learning is a promising solution for the global networks of IoT devices in terms of analysing their ever-growing generated data and predicting cyberattacks against such devices. Therefore, in this paper, we study the vulnerability analysis of two popular OFs of RPL to detect combined attacks against them using machine learning algorithms through different simulated scenarios. For this, we created a novel IoT dataset based on power and network metrics, which is deployed as part of an RPL IDS/IPS solution to enhance information security. Addressing the captured results, our machine learning approach is successful in detecting combined attacks against two popular OFs of RPL based on the power and network metrics in which MLP and RF algorithms are the most successful classifier deployment for single and ensemble models. John Foley, Naghmeh Moradpoor Sheykhkanloo, Henry Ochenyi |
Secur. Commun. Networks | 2 |
| 2018 | Predicting Malicious Insider Threat Scenarios Using Organizational Data and a Heterogeneous Stack-ClassifierabstractInsider threats continue to present a major challenge for the information security community. Despite constant research taking place in this area; a substantial gap still exists between the requirements of this community and the solutions that are currently available. This paper uses the CERT dataset r4.2 along with a series of machine learning classifiers to predict the occurrence of a particular malicious insider threat scenario - the uploading sensitive information to wiki leaks before leaving the organization. These algorithms are aggregated into a meta-classifier which has a stronger predictive performance than its constituent models. It also defines a methodology for performing pre-processing on organizational log data into daily user summaries for classification, and is used to train multiple classifiers. Boosting is also applied to optimise classifier accuracy. Overall the models are evaluated through analysis of their associated confusion matrix and Receiver Operating Characteristic (ROC) curve, and the best performing classifiers are aggregated into an ensemble classifier. This meta-classifier has an accuracy of 96.2% with an area under the ROC curve of 0.988. Adam J. Hall, Nikolaos Pitropakis, William J. Buchanan, Naghmeh Moradpoor Sheykhkanloo |
IEEE BigData | 4 |
| 2018 | Vulnerability Assessment of Objective Function of RPL Protocol for Internet of ThingsabstractThe Internet of Things (IoT) can be described as the ever-growing global network of objects with built-in sensing and communication interfaces such as sensors, Global Positioning devices (GPS) and Local Area Network (LAN) interfaces. Security is by far one of the biggest challenges in IoT networks. This includes secure routing which involves the secure creation of traffic routes and secure transmission of routed packets from a source to a destination. The Routing Protocol for Low-power and Lossy network (RPL) is one of the popular IoT's routing protocol that supports IPv6 communication. However, it suffers from having a basic system for supporting secure routing procedure which makes the RPL vulnerable to many attacks. This includes rank attack manipulation. Objective Function (OF) is one of the extreme importance features of RPL which influences an IoT network in terms of routing strategies as well as network topology. However, current literature lacks study of vulnerability analysis of OFs. Therefore, this paper aims to investigate the vulnerability assessment of OF of RPL protocol. For this, we focus on the rank attack manipulation and two popular OFs: Objective Function Zero (OF0) and the Minimum Rank with Hysteresis Objective Function (MRHOF). Felisberto Semedo, Naghmeh Moradpoor Sheykhkanloo, Majid Rafiq |
SIN | 2 |
| 2017 | Insider threat detection using principal component analysis and self-organising mapabstractAn insider threat can take on many aspects. Some employees abuse their positions of trust by disrupting normal operations, while others export valuable or confidential data which can damage the employer's marketing position and reputation. In addition, some just lose their credentials which are then abused in their name. In this paper, we use Principal Component Analysis (PCA) in conjunction with Self-Organising Map (SOM) for insider threat detection within an organisation. The results show that using PCA before SOM increases the clustering accuracy. Naghmeh Moradpoor Sheykhkanloo, Martyn Brown, Gordon Russell 0001 |
SIN | 1 |
| 2015 | SQL-IDS: evaluation of SQLi attack detection and classification based on machine learning techniquesabstractStructured Query Language injection (SQLi) attack is a code injection technique where malicious SQL statements are inserted into a given SQL database by simply using a web browser. Injected SQL commands can alter the database and thus compromise the security of a web application. In our previous work, we proposed an effective pattern recognition Neural Network (NN) model for detection and classification of the SQLi attacks. Our proposed model was built from: a Uniform Resource Locator (URL) generator, a URL classifier, and a NN model. The URL generator was implemented in order to generate thousands of malicious and benign URLs. The URL classifier was employed in order to identify each URL, which was generated by the URL generator, as either a benign URL or a malicious URL. The URL classifier also pigeonholed the malicious URLs into seven popular SQLi attack categories. The NN model includes n hidden layers with x input and y output nodes where the benign and malicious URLs were employed for training, validating, and testing phases. Addressing our previous captured results, our proposed pattern recognition NN model for the detection and classification of the SQLi attacks demonstrated a good performance in terms of accuracy, true-positive rate, and false-positive rate. In this paper, we stress test our previous proposal in order to prove the effectiveness of our proposed approach. Naghmeh Moradpoor Sheykhkanloo |
SIN | 1 |
| 2014 | Employing Neural Networks for the Detection of SQL Injection AttackabstractStructured Query Language Injection (SQLI) attack is a code injection technique in which malicious SQL statements are inserted into the SQL database by simply using web browsers. SQLI attack can cause severe damages on a given SQL database such as losing data, disclosing confidential information or even changing the values of data. It has also been rated as the number-one attack on the Open Web Application Security Project (OWASP) top ten. In this paper, we propose an effective model to deal with this problem based on Neural Networks (NNs). The proposed model is built from three main elements of: a Uniform Resource Locator (URL) generator in order to generate thousands of malicious and benign URLs, a URL classifier in order to classify the generated URLs to either benign or malicious URLs, and an NN model in order to detect either a given URL is a malicious URL or a benign URL. The model is first trained and then evaluated by employing both benign and malicious URLs. The results of the experiments are presented in order to demonstrate the effectiveness of the proposed approach. Naghmeh Moradpoor Sheykhkanloo |
SIN | 1 |
| 2011 | Hybrid optical and wireless technology integrations for next generation broadband access networksabstractHybrid optical and wireless technology integrations have been considered as one of the most promising candidates for the next generation broadband access networks for quite some time. The integration scheme provides the bandwidth advantages of the optical networks and mobility features of the wireless networks for Subscriber Stations (SSs). It also brings economic efficiency to the network providers particularly in rural area where the existing wired telecommunication infrastructures such as Digital Subscriber Line (DSL), Cable Modem (CM), T-1/E-1 networks or fibre deployments are either costly or unreachable. For successful integration of the optical and wireless technologies there are some technical issues which need to be addressed efficiently in order to provide End-to-End (ETE) and diverse Quality of Service (QoS) for various service classes. This paper investigates the possible challenging issues for the integrated structure of the Time Division Multiplexing and Wavelength Division Multiplexing Ethernet Passive Optical Networks (TDM EPON and WDM EPON ) with the Worldwide Interoperability for Microwave Access and Wireless Fidelity (WiMAX and Wi-Fi) networks. To reduce the ETE delay and provide the QoS for diverse service classes, we have compared six existing upstream scheduling mechanisms in two levels which are distributed on Access Points (APs) from Wi-Fi domain and Base Stations (BSs) from WiMAX domain. Performance evaluations of the existing scheduling techniques for three popular service classes (Quad-play) have been studied which show the strong impact of using the efficient up-link scheduler in converged scenario. We have also proposed a dynamic scheduling algorithm for optical and wireless integration scheme, which is under the implementation and evaluation process. Naghmeh Moradpoor Sheykhkanloo, Gerard P. Parr, Sally I. McClean, Bryan W. Scotney, Gilbert Owusu |
Integrated Network Management | 1 |