Kuljeet Kaur

dblp:161/6927 · DBLP profile ↗
← Back
62ranked-venue papers
11as first author
37since 2021 · last 2026
0000-0003-4597-1700ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 42 · 7 first-author · 27 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 3 first-author · 8 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Security and privacy · 1Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 MEGA-Fence: Multi-metric Entropy-based GMM Aggregation to Defend Poisoning Attacks in FL
M. A. Moyeen, Kuljeet Kaur, Anjali Agarwal, Ricardo Manzano, Marzia Zaman, Nishith Goel
ICC2
2026 LIME: Lightweight Multi-head Early-exit Transformer for Network Intrusion Detection
Ishfaq Bashir Sofi, Anjali Agarwal, Kuljeet Kaur
ICC3
2026 A Secure Multiradio Resource Scheme Using Cooperative DRL Agents for Heterogeneous Inter-RAN Slicing Under Hardware Impairments
Ohood Sabr, Kuljeet Kaur, Georges Kaddoum
IEEE Internet Things J.2
2026 GAN-Empowered Parasitic Covert Communication: Data Privacy in Next-Generation Networks
abstract
The widespread integration of artificial intelligence (AI) in next-generation communication networks poses a serious threat to data privacy while achieving advanced signal processing. Eavesdroppers can use AI-based analysis to detect and reconstruct transmitted signals, leading to serious leakage of confidential information. In order to protect data privacy at the physical layer, we redefine covert communication as an active data protection mechanism. We propose a new parasitic covert communication framework in which communication signals are embedded into dynamically generated interference by generative adversarial networks (GANs). This method is implemented by our CDGUBSS (complex double generator unsupervised blind source separation) system. The system is explicitly designed to prevent unauthorized AI-based strategies from analyzing and compromising signals. For the intended recipient, the pretrained generator acts as a trusted key and can perfectly recover the original data. Extensive experiments have shown that our framework achieves powerful covert communication, and more importantly, it provides strong defense against data reconstruction attacks, ensuring excellent data privacy in next-generation wireless systems.
Zhi Lin 0001, Haotong Cao, Yifu Sun, Kuljeet Kaur, Sherif Moussa
IEEE Trans. Netw. Serv. Manag.5
2025 AE-Multi-WGAN: A Robust Multi-Attack Detection IDS for Imbalanced Datasets
Ishfaq Bashir Sofi, Anjali Agarwal, Kuljeet Kaur
GLOBECOM3
2025 COPS: Controller Placement in Next-Generation Software Defined Edge-Cloud Networks
abstract
To mitigate various challenges in the edge-cloud ecosystem, such as global monitoring, flow control, and policy modification of legacy networking paradigms, software-defined networks (SDN) have evolved as a major technology. However, the dependency on a single centralized controller is challenging due to the scalability and resilience issues. Thus, deploying multiple controllers becomes inevitable to process the data with maximum throughput and minimum delay. Controller placement problem (CPP) is a major issue that needs to be addressed by designing efficient solutions. To address the CPP, two parameters, i) number of controllers and ii) location of controllers, need to be handled optimally. Thus, an Optimal COntroller Placement Scheme (COPS) using the multi-objective evolutionary approach for SDN is proposed in this paper. The results prove its effectiveness in terms of various evaluation parameters.
Gagangeet Singh Aujla, Anish Jindal, Kuljeet Kaur, Sahil Garg, Rajat Chaudhary, Hongjian Sun 0001, Neeraj Kumar 0001
ICC3
2025 SignDefence: Byzantine-Robust Federated Learning with Sign Direction and Leaky ReLU
abstract
The advancement of big data has paved the way for the development of intelligent and smart applications; however, privacy concerns often hinder fully realizing their benefits. Federated Learning (FL) has emerged as a promising framework for enhancing privacy while training models collaboratively across decentralized data sources. However, it remains susceptible to poisoning attacks, severely undermining its effectiveness. Existing robust aggregation techniques often struggle with the sensitivity of data distributions, and cluster-based strategies often fail to cluster poisoned model updates correctly. The direction obtained from the signs of the gradient mostly solves these problems but remains vulnerable to dying ReLU problems and usually becomes sensitive to outliers. In this paper, we introduce SignDefence, a sign direction and LeakyReLU-based aggregation technique, which considers the direction of the gradients and overcomes the performance issues related to the dying ReLU problem. Moreover, the proposed SignDefence computes Jaccard Similarity over binary encoded model weights and remains robust across sparse data. The experimental results suggest that the proposed technique shows consistently better accuracy and F1 score than the state-of-the-art techniques, without attack and under different attack scenarios.
M. A. Moyeen, Kuljeet Kaur, Anjali Agarwal, Ricardo Manzano, Marzia Zaman, Nishith Goel
ICC2
2025 SOIS-A2C Scheme: Facilitating Management of Multi-Radio Resources in Heterogeneous Inter-RAN Slicing in the Presence of Hardware Impairments
abstract
Recent years have witnessed the emergence of the concept of network slicing (NS) that enables the creation of independent, virtualized logical networks on the same physical infrastructure. Each NS is tailored to meet the needs of a particular service or application. NS is widely considered a key enabling technology for end-to-end (E2E) automation in managing resources within radio access networks (RAN). To achieve E2E automation in RAN slicing, it is essential to automate resource allocation at both the intra- and inter-slice levels to meet the demands of future applications and services. In this context, the present study focuses on the automated management of multiple radio resources at the inter-slice level. More specifically, we propose a self-optimizing inter-slice scheme based on the deep reinforcement learning (DRL) advantage actor-critic (A2C) algorithm, named SOIS-A2C. Our goal is to maximize the spectral efficiency of the system while maintaining high service quality by considering the effects of hardware distortions and intra-slicing interference. The results highlight the effectiveness of the proposed SOIS-A2C scheme, which demonstrates superior performance in maximizing spectral efficiency as compared to benchmark schemes such as the SOIS-based deep Q-network (DQN) and hard slicing in highly fluctuating environments and under ideal and non-ideal hardware conditions.
Ohood Sabr, Kuljeet Kaur, Georges Kaddoum
ICC2
2025 Advanced Home Energy Management Using Proximal Policy Optimization with a Comprehensive Appliance Set
abstract
Home Energy Management Systems (HEMS) are essential for optimizing household energy consumption and reducing costs, particularly in smart grids, where renewable energy sources and demand side management play a critical role. We propose an advanced HEMS framework that utilizes Proximal Policy Optimization (PPO), a reinforcement learning (RL) algorithm to address the challenges of managing energy consumption in realistic and dynamic environments. Our approach provides a comprehensive smart home environment by incorporating a wide range of household appliances, each with distinct patterns of energy consumption and operational constraints. This enhances the realism and practical relevance of the system, allowing cost savings while respecting user preferences and the limitations of the appliance. Simulations reveal that the proposed HEMS framework significantly improves energy savings, reduces costs, and enhances user satisfaction compared to other baseline methods, achieving 38% lower costs and 3% higher satisfaction of the energy level of electric vehicles (EV) than the Soft Actor-Critic based HEMS. These results highlight the effectiveness of RL and realistic environment modeling in the development of adaptive and efficient HEMS solutions, paving the way for more sustainable energy management practices.
Mahmoud Sallam, Kuljeet Kaur, Georges Kaddoum
ICC2
2025 Guest Editorial Special Issue on Distributed-Edge-Intelligence-Empowered Internet of Vehicles
Jia Hu 0001, Tie Qiu 0001, Kuljeet Kaur, Tony Q. S. Quek, Peng Liu 0027
IEEE Internet Things J.3
2025 Uncrewed Aerial Vehicles Empowering Secure Authentication in Cognitive IoMT for Transformative Knowledge Discovery in Data
abstract
The paradigm shift toward digital transformation is increasingly advancing toward cognitive decision discovery, particularly within the healthcare domain, where it has emerged as a critical area of research. Numerous researchers are actively contributing to this field. However, due to the sensitive nature of healthcare data, ensuring robust security within the cognitive decision-making process is paramount for Internet of Medical Things (IoMT). To address this concern, the present study proposes a comprehensive privacy-preserving authentication scheme associating aerial computing and knowledge discovery. This scheme leverages an elliptic curve-based cryptosystem to establish the authentication protocol and incorporates blockchain technology to ensure data storage security. Furthermore, the scheme facilitates secure knowledge discovery in data (KDD) within cognitive decision-making frameworks. The proposed authentication mechanism is evaluated across communication, computational efficiency, and security parameters to validate its functionality and robustness as well as to formally verify the developed scheme Scyther tool verification is done by authors. Additionally, to demonstrate the necessity and effectiveness of the proposed scheme, the authors conducted a KDD experiment using both a securely authenticated dataset and an insecure, compromised dataset. The results of these experiments are presented and thoroughly analyzed in the article.
Abhishek Kumar Pandey, Ashok Kumar Das, Mohammad Wazid, Kuljeet Kaur, Youngho Park 0005, Mohammad Mehedi Hassan
IEEE Internet Things J.4
2025 Optimized Resource Forecasting for Carbon-Intelligent Data Centers With TempoSight: A Hybrid Deep Learning Approach
abstract
Precise resource utilization forecasting is paramount for enabling carbon-intelligent operation in Industrial Internet of Things (IIoT) environments; Cloud data centers (DCs) are no exception. Optimizing their resource allocation not only reduces operational costs but also minimizes energy consumption and associated carbon emissions, contributing to sustainable computing. This paper introducesTempoSight, a novel hybrid Deep Learning (DL) architecture designed for multivariate (MV) time series forecasting, specifically targeting carbon-intelligent resource provisioning in Cloud DCs.TempoSightsynergistically combines the strengths of Patch Time Series Transformers (PatchTST), excelling at capturing global context and long-range dependencies, and Long Short-Term Memory (LSTM) networks, mastering sequential dynamics. To address the critical need for efficient hyperparameter tuning in complex DL models, we propose a Cuckoo Search Algorithm (CSA) based optimization approach. This enables efficient training and optimization ofTempoSightfor MV time series forecasting, leading to improved resource utilization predictions. Rigorous evaluation on the Alibaba and Bitbrains datasets, representing diverse real-world IIoT workload patterns, demonstratesTempoSight’s superior accuracy and robustness compared to state-of-the-art DL models. Notably, under high-load conditions,TempoSightachieves a remarkable 10-15% reduction in Root Mean Square Error (RMSE) and Mean Absolute Percentage Error (MAPE). This research highlights the critical role of hybrid DL models and intelligent optimization in achieving accurate and efficient resource provisioning, paving the way for carbon-aware IIoT applications and contributing to the broader goals of sustainable and green computing. Simulation studies also suggest thatTempoSight’s high-fidelity CPU forecasts significantly improve the Green Energy Utilization Factor (GEUF) when guiding Predictive Carbon-Aware (PCA) scheduling, quantitatively connecting forecasting precision with concrete sustainability advantages in DC operations.
Mahmoud Sallam, Kuljeet Kaur
IEEE Internet Things J.2
2024 A Stochastic Geometry Model and Analysis Scheme for SCMA Aided Mobile Edge Computing
abstract
Sparse code multiple access (SCMA) and mobile edge computing (MEC) can greatly enhance the capabilities of IoT networks by providing massive connectivity and timely computation. The paper presents a model and analysis of the performance for a large-scale grant-free (GF) SCMA aided MEC network. Firstly, stochastic geometry is used to derive closed-form solutions for offloading probability and SCMA ergodic rate. Then, the impact of SCMA on task completion time and energy cost in MEC networks is studied using queueing theory. Simulation results verify the validity of the theoretical expression and demonstrate that SCMA has advantages over orthogonal multiple access (OMA) in improving the offloading probability and ergodic rate, and reducing task latency and energy cost.
Pengtao Liu, Jing Lei 0001, Haotong Cao, Sahil Garg, Kuljeet Kaur, Georges Kaddoum
WCNC5
2024 Energy Efficiency Optimization in RIS-assisted ISATRNs with RSMA: A Federated Deep Reinforcement Learning Approach
abstract
The performance of integrated satellite-aerial-terrestrial relay networks (ISATRNs) faces two main challenges, severe signal strength degradation over long transmission distances and limited spectrum resources. To address these issues, we consider the introduction of high altitude platforms (HAPs) and unmanned aerial vehicles (UAVs) carrying reconfigurable intelligent surface (RIS) as relays during transmission from satellites to the ground. Additionally, we employ rate splitting multiple access (RSMA) at HAPs to improve signal transmission robustness. To optimize system energy efficiency, we formulate a multi-objective problem that considers the active transmit beamforming vector, RIS phase shift, power splitting ratio, and UAV trajectory. To tackle the non-convex problem involving both discrete and continuous variables, we introduce a novel approach called access-free federated deep reinforcement learning (AF-DRL). The optimal transmit beamforming and power splitting ratio are obtained by allowing the UAV to plan its path and locally train, reducing computational overhead caused by high-dimensional UAV movement. Simulation results demonstrate that the proposed RSMA-based enhancement scheme achieves higher energy efficiency compared to the comparison scheme.
Min Wu 0008, Kefeng Guo, Zhi Lin 0001, Sahil Garg, Kuljeet Kaur, Georges Kaddoum
WCNC5
2023 FedChallenger: Challenge-Response-Based Defence for Federated Learning Against Byzantine Attacks
abstract
Federated Learning (FL) is an emerging paradigm that enables multiple clients to train a global model collaboratively without sharing their privacy-sensitive data. However, one of the significant challenges in FL is the aggregation of the model updates from different client devices, as malicious participants acting as Byzantine attackers can craft the model update and poison the global model. The state-of-the-art defence mechanisms mostly rely on aggregation-based security defences to improve the degraded accuracy. However, preventing attacker's participation in the training can have an impact on improving the global model's accuracy. Therefore, in this paper, FedChallenger, a dual-layer defence mechanism, is proposed, which attempts to detect and prevent malicious participation in the FL training process in its first layer. The other layer incorporates a trimmed-mean aggregation strategy, where pairwise cosine similarity identifies malicious updates and removes entire client updates from federated averaging. Extensive experiments using the BloodMNIST dataset validate that the FedChallenger gains nearly 85%, 80%, 15%, and 4% accuracy with more than 1.2 times faster convergence rate over the state-of-the-art Byzantine resilient aggregation strategies called FedAvg, Fang, Krum, and Trimmed-Mean approach, respectively, on 40% compromised devices. Above all, it shows consistently better results than them in both attack and non-attack scenarios.
M. A. Moyeen, Kuljeet Kaur, Anjali Agarwal, Ricardo Manzano, Marzia Zaman, Nishith Goel
GLOBECOM2
2023 Efficient GBS Sleep Strategy of UAV Assisted Wireless Networks for Energy Saving
abstract
In 5G Radio Access Networks (RANs), the energy consumption of the ground base station (GBS) accounts for more than 80%. Therefore, reducing the energy consumption of GBSs has been an important research direction for building green and environment-friendly communication networks. In view of this, we formulate an unmanned aerial vehicle (UAV)-assisted GBS sleep strategy for energy saving, which utilizes the mobility of UAVs to fill the wireless coverage holes caused by the sleeping of GBSs. To further enhance the effect of the formulated strategy, we propose a joint GBS sleeping, UAV trajectory planning, and UAV transmission power allocation problem to minimize the energy consumption of the entire system. To address the intractable problem, we first devise an iterative algorithm to optimize the trajectory and power of the UAV based on the block coordinate descent (BCD), and then nest it into the branch and bound (BaB) to obtain the GBSs operation status. Simulations demonstrate that the formulated strategy efficiently reduces the energy consumption of the network compared with other schemes.
Daosen Zhai, Ruonan Zhang 0001, Kuljeet Kaur
ICC4
2023 PSLP-5G: A Provably Secure and Lightweight Protocol for 5G Communication
abstract
Due to the constant influx of multiple security attacks into the next generation of mobile communication technologies, the Third Generation Partnership Project (3GPP) has established authentication and key agreement protocol, 5-GAKA, to securely access the 5G communication services while maintaining the integrity of the underlying network. However, some recent findings pointed out that 5G-AKA has many drawbacks, including perfect forward secrecy violations, malicious Serving Network (SN) attacks, desynchronization attacks, privacy theft, stolen device, and denial of service (DoS) attacks when the user uses roaming mobile services. Considering the drawbacks of current 5G communication protocols and the necessity to facilitate additional security, a provably secure and lightweight protocol for 5G communication (PSLP-5G) is introduced. The PSLP-5G's security is guaranteed using the Scyther tool and Real-Or-Random (ROR) logic. Furthermore, performance comparisons are made to show how much lighter the PSLP-5G is than its counterparts. Additionally, the PSLP-5G's suitability for use in real-time applications is demonstrated by comparing the network performance of PSLP-5G and its counterparts using the Network Simulator tool NS3.
Awaneesh Kumar Yadav, Pradumn Kumar Pandey, Kuljeet Kaur, Abbas Bradai
ICC3
2023 Privacy-Aware Access Control in IoT-Enabled Healthcare: A Federated Deep Learning Approach
abstract
The traditional healthcare is overwhelmed by the processing and storage of massive medical data. The emergence and gradual maturation of Internet-of-Things (IoT) technologies bring the traditional healthcare an excellent opportunity to evolve into the IoT-enabled healthcare of massive data storage and extraordinary data processing capability. However, in IoT-enabled healthcare, sensitive medical data are subject to both privacy leakage and data tampering caused by unauthorized users. In this article, an attribute-based secure access control mechanism, coined (SACM), is proposed for IoT-Health utilizing the federated deep learning (FDL). Specifically, we manage to discover the relationship between users’ social attributes and their trusts, which is the trustworthiness of users rely on their social influences. By applying graph convolutional networks to the social graph with the susceptible–infected–recovered model-based loss function, users’ influences are obtained and then are transformed to their trusts. For each occupation, users’ trusts allow them to access specific medical data only if their trusts are higher than the corresponding threshold. Then, the FDL is applied to obtain the optimal threshold and relevant access control parameters for the improvement of access control accuracy and the enhancement of privacy preservation. The experimental results show that the proposed SACM achieves accurate access control in IoT-enabled healthcare with high data integrity and low privacy leakage.
Hui Lin 0007, Kuljeet Kaur, Xiaoding Wang 0001, Georges Kaddoum, Jia Hu 0001, Mohammad Mehedi Hassan
IEEE Internet Things J.2
2023 Two-Stage Intrusion Detection System in Intelligent Transportation Systems Using Rule Extraction Methods From Deep Neural Networks
abstract
In recent years, intrusion detection systems (IDSs) are offering effective solutions to protect various types of cyber-attacks in different networks such as Internet of Vehicles (IoVs) network in Intelligent Transportation Systems (ITS). Deep learning models have largely been leveraged by these intrusion detection systems to achieve better effectiveness results. However, deep learning models are black boxes, which limits their acceptability in decision systems. Also, they require powerful processing capabilities such as GPU, which limit their deployments in resource-constrained devices in IoV environment. To deal with these issues, we propose a two-stage IDS in ITS to discover suspicious network activity of In-Vehicles Networks (IVN) and vehicles to everything (V2X) networks. Our proposed IDS system uses rule extraction methods from deep learning models, i.e., deep neural networks in two stages. In the first stage, we analyze network traffic to distinguish between normal and attack traffic. If the traffic is found malicious, the second stage is invoked to identify the type of attack. To this end, we propose three variants of rule extraction. The first and the second variants are homogeneous, and they apply$DeepRed$and$HypInv$rule extraction methods in both stages respectively. The third variant is heterogeneous, and it applies$HypInv$in the first stage to perform binary classification, and$DeepRed$in the second stage to perform attack classification. The key idea is to combine the advantages of rule extraction technique and two-stage IDS architecture to resource consumption and improve classification accuracy. The proposed IDS model was tested using four benchmark datasets, i.e. ISCXIDS2012, CIC-IDS2017, and CSE-CIC-IDS2018 datasets are used for external network communications and the car hacking dataset are used for in-vehicle communications. The evaluation results show that the homogeneous$DeepRed$is the optimal one in all cases of IDS system with an accuracy scores ranging between 92.43%-98.32% under CIC-IDS2017 dataset, between 91.32%-99.46% under CSE-CIC-IDS2018 dataset, and between 96.05%-99.21% under Car-hacking dataset.
Samah Almutlaq, Abdelouahid Derhab, Mohammad Mehedi Hassan, Kuljeet Kaur
IEEE Trans. Intell. Transp. Syst.4
2023 Intelligent Anomaly Detection of Trajectories for IoT Empowered Maritime Transportation Systems
abstract
The convergence of Maritime Transportation Systems (MTS) and Internet of Things (IoT) has led to the promising IoT-empowered MTS (IoT-MTS). However, abnormal trajectories of maritime transportation ships can have highly negative impacts on the management of IoT-MTS. Therefore, anomaly detection of trajectories is important for the successful deployment of IoT-MTS. In this paper, we propose a Transfer Learning based Trajectory Anomaly Detection strategy, named TLTAD, for IoT-MTS. Specifically, a variational autoencoder is used to discover the potential connections between each dimension of the normal trajectory, while a graph variational autoencoder is used to explore the spatial similarity between normal trajectories. Based on internal connection of trajectories, a deep reinforcement learning algorithm, Twin Delayed Deep Deterministic policy gradient (TD3), is employed to train the trajectory anomaly detection model. To reduce the model training time, transfer learning is used to migrate the trained anomaly detection model between different regions of an ocean area or between similar ocean areas. Moreover, an efficient data transformation module is designed to improve the efficiency of model transfer. The experiments were conducted on a real-world automatic identification system (AIS) dataset. The results indicate that the proposed TLTAD can provide accurate anomaly detection on ships’ trajectories in IoT-MTS with reduced model training times.
Jia Hu 0001, Kuljeet Kaur, Hui Lin 0007, Xiaoding Wang 0001, Mohammad Mehedi Hassan, Muhammad Imran Razzak, Mohammad Hammoudeh
IEEE Trans. Intell. Transp. Syst.2
2023 Blockchain-Based Privacy-Preserving Authentication Model Intelligent Transportation Systems
abstract
Intelligent Transportation Systems (ITS) have gained popularity due to smart services and applications to facilitate the users on the roads. The increasing growth of users in these networks created new and complex data processing, storage, security, and privacy concerns. These networks are using centralized edge, fog, or cloud architecture for data management. User privacy is compromised in these networks due to the increasing demands and service provider’s services. To ensure the data privacy, the centralized architectures are used without privacy regulations. In this paper, we present a Blockchain-based Privacy-Preserving Authentication (BPPAU) model for ITS networks to ensures users privacy and security. The proposed model provides data storage, data accessing, and processing management by using a blockchain smartcontract system, access control policy and on demand based functions. The proposed model is tested in a simulation environment to check its performance in terms of transaction cost with data size, transaction per second analysis with block time, and computational time analysis with several transactions.
Kashif Naseer Qureshi, Gwanggil Jeon, Mohammad Mehedi Hassan, Md. Rafiul Hassan, Kuljeet Kaur
IEEE Trans. Intell. Transp. Syst.5
2023 AI-Empowered Trajectory Anomaly Detection for Intelligent Transportation Systems: A Hierarchical Federated Learning Approach
abstract
The vigorous development of positioning technology and ubiquitous computing has spawned trajectory big data. By analyzing and processing the trajectory big data in the form of data streams in a timely and effective manner, anomalies hidden in the trajectory data can be found, thus serving urban planning, traffic management, safety control and other applications. Limited by the inherent uncertainty, infinity, time-varying evolution, sparsity and skewed distribution of trajectory big data, traditional anomaly detection techniques cannot be directly applied to anomaly detection in trajectory big data. To solve this problem, we propose a hierarchical trajectory anomaly detection scheme for Intelligent Transportation Systems (ITS) using both machine learning and blockchain technologies. To be specific, a hierarchical federated learning strategy is proposed to improve the generalization ability of the global trajectory anomaly detection model by secondary fusion of the multi-area trajectory anomaly detection model. Then, by integrating blockchain and federated learning, the iterative exchange and fusion of the global trajectory anomaly detection model can be realized by means of on-chain and off-chain coordinated data access. Experiments show that the proposed scheme can improve the generalization ability of the trajectory anomaly detection model in different areas, while ensuring its reliability.
Xiaoding Wang 0001, Hui Lin 0007, Jia Hu 0001, Kuljeet Kaur, M. Shamim Hossain
IEEE Trans. Intell. Transp. Syst.5
2022 A Secure Data Dissemination Scheme for IoT-Based e-Health Systems using AI and Blockchain
abstract
In Internet of Things (IoT)-based e-Health Systems (IoTEHS), medical devices form a large network that continuously sense and share the healthcare data with the nearby edge devices or cloud servers. The health data is subsequently made available to various IoTEHS stakeholders (such as doctors, nurses and patients) to track and monitor patients under observation. However, the entire IoTEHS stakeholders communicate with each other over a wireless unsecured public communication channel. This is a major security and privacy loophole wherein the attacker can exploit the vulnerability of the system and can launch various attacks on the ongoing communication. Motivated by the aforementioned challenges, a secure data dissemination scheme using AI and blockchain is proposed. In this scheme, the transaction collected through healthcare sensors installed around the patients premises act as data sets that is forwarded to the nearby edge devices. The collected data is first filtered using AI-based intrusion detection system located at the edge of the network. Second, a secure health monitoring network is designed using blockchain. Specifically, the filtered or normal transactions are transmitted to centralized cloud servers where the smart contact-enabled consensus mechanism is used to validate the transactions. Once the transaction gets validated, it is stored on distributed InterPlanetary File System (IPFS) of cloud and returned transaction hash is stored on the blockchain ledger located at edge devices making data exchange faster. The detailed experimental investigation demonstrates that the proposed schemes are efficient (in terms of computing and processing time) as well as its resistance to a variety of security attacks.
Prabhat Kumar 0003, Randhir Kumar, Sahil Garg, Kuljeet Kaur, Yin Zhang 0002, Mohsen Guizani
GLOBECOM4
2022 LASUA: A Lightweight Authentication Scheme with User Anonymity for IoT-Enabled Mobile Cloud
abstract
Mobile Cloud Computing (MCC) also known as on-demand computing uses cloud computing to deliver applications to mobile devices. This new computational paradigm model which plays a big part in the Internet of Things (IoT), has increased its popularity even more during Covid-19 pandemic and became a necessity when schools, businesses and hospitals must work remotely. We can access and process remote data which are stored over the cloud server in real-time by connecting to a wireless network. For accessing any cloud server, a mutual authentication and key agreement between a mobile user and a cloud server provider is required. However, existing authentication schemes for MCC fail to provide user anonymity, server anonymity and user untraceability. Therefore, we propose a Lightweight Authentication Scheme with User Anonymity (LASUA) which artfully employs Elliptic Curve Cryptography (ECC), random number, time stamps, one-way hash functions, concatenation, XOR operations and fuzzy extractor for biometric to enable various security features including anonymity and resistance against various attacks. LASUA utilises the hardness of ECC to provide top-notch security with low computation and communication cost, a perfect solution for resource constrained devices.
Vincent Amande, Kuljeet Kaur, Sahil Garg, Mohsen Guizani
GLOBECOM2
2022 A Provably Secure ECC-based Multi-factor 5G-AKA Authentication Protocol
abstract
Due to the constant penetration of various security attacks, it is highly important to secure the underlying communication networks between the IoT, Fog and Cloud in the next generation of mobile communication system (5G). Thus, secure authentication and key agreement protocol, namely 5G-AKA, has been proposed in the literature to safely and stably access the 5G mobile services. However, some recent findings reveal that 5G-AKA and its numerous versions based on symmetric or asymmetric encryption are either vulnerable to different attacks such as perfect forward secrecy violation, malicious Serving Network (SN), de-synchronization attack, privacy theft, stolen device, or are computationally intensive. Apart from that, these protocols use single-factor authentication. Considering the above demerits of these protocols and the necessity to provide enhanced security, we propose an Elliptic Curve-Cryptography (ECC)-based multi-factor 5G-AKA authentication protocol. It provides additional security and achieves cost-effectiveness in terms of computational, communication, storage costs and energy consumption. The formal security analysis using Real-Or-Random (ROR) logic has been done to confirm its security. Moreover, we evaluate the performance of the proposed protocol in terms of computational, communication, storage costs and energy consumption. The evaluation results show that the proposed protocol requires less cost than its counterparts, reducing computational cost by up to 57%, communication cost by up to 59%, storage cost by up to 52%, and energy consumption by up to 51%.
Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Kuljeet Kaur, Sahil Garg, Xi Chen 0009
GLOBECOM4
2022 LEMAP: A Lightweight EAP based Mutual Authentication Protocol for IEEE 802.11 WLAN
abstract
The growing usage of wireless devices has significantly increased the need for Wireless Local Area Network (WLAN) during the past two decades. However, security (most notably authentication) remains a major roadblock to WLAN adoption. Several authentication protocols exist for verifying a supplicant’s identity who attempts to connect his wireless device to an access point (AP) of an organization’s WLAN. Many of these protocols use the Extensible Authentication Protocol (EAP) framework. These protocols are either vulnerable to attacks such as violation of perfect forward secrecy, replay attack, synchronization attack, privileged insider attack, and identity theft or require high computational and communication costs. In this paper, a lightweight EAP-based authentication protocol for IEEE 802.11 WLAN is proposed that not only addresses the security issues in the existing WLAN authentication protocols but is also cost-effective. The security of the proposed protocol is verified using BAN logic and the Scyther tool. Our analysis shows that the proposed protocol is safe against all the above attacks and attacks defined in RFC-4017. A comparison of the computational and communication costs of the proposed protocol with other existing state-of-the-art protocols shows that the proposed protocol is lightweight than existing solutions.
Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Kuljeet Kaur, Sahil Garg, Madhusanka Liyanage
ICC4
2022 A Binary Gray Wolf Optimization algorithm for deployment of Virtual Network Functions in 5G hybrid cloud
Mohammad Shahjalal, Nusrat Farhana, Palash Roy, Md. Abdur Razzaque, Kuljeet Kaur, Mohammad Mehedi Hassan
Comput. Commun.5
2022 A Multi-Objective Optimization Scheme for Job Scheduling in Sustainable Cloud Data Centers
abstract
For a number of years, due to an exponential increase in the demand for an eco-friendly environment, there has been a rapid increase in the green city revolution across the globe. Subsequently, load shifting of major energy consumers from conventional power grids to renewable energy sources (RES) has become inevitable. Towards this end, cloud data centers (DCs) have emerged as significant consumers of energy that solely rely on power grids to fuel their day-to-day operations. Nevertheless, their energy consumption has increased significantly which in turn has substantially raised the global carbon footprint rate. These challenges can be best addressed by the judicious utilization of RES which have well established advantages like reduced operational costs and carbon emissions. Keeping in view of the above facts, the ultimate goal of the proposed work is to design a comprehensive workload classification; and job scheduling and Vitual machine placement architecture for cloud DCs powered by RES and power grids. For this, a multi-objective optimization scheme is proposed which operates in two phases. In phase I,a random forest-based wrapper schemeknown as Boruta, is used for relevant feature set selection for the incoming workload. This is followed by classification of the workload using a locality sensitive hashing-based support vector machines approach. In phase II, a multi-objective optimization problem for job scheduling and VM placement is formulated with respect to parameters such as service level agreement (SLA), energy cost, carbon footprint rate (CFR), and availability of RES. It is further solved using an enhanced heuristic approach based on a greedy strategy. Our experimental evaluations show an average improvement of approximately 31 percent in energy utilization, 28 percent in energy cost, and 36 percent in CFR, with a slight degradation in SLA assurance (about 2 percent) compared with the existing schemes.
Kuljeet Kaur, Sahil Garg, Gagangeet Singh Aujla, Neeraj Kumar 0001, Albert Y. Zomaya
IEEE Trans. Cloud Comput.1
2022 Heuristic Optimization of Multipulse Rectifier for Reduced Energy Consumption
abstract
Intelligent Manufacturing 5.0 of multipulse rectifier systems requires them to be optimized for a variety of use in transportation and factories producing hearty touch technology. The research presented in this article show advances of using heuristic models to set 12-pulse and 24-pulse rectifiers to work under low- and high-voltage load. As a result of heuristic optimization electric systems increase efficiency and reduce energy consumption by efficiency benefits in adopting artificial intelligence. Applied heuristic models helped in computer simulations to optimize system settings in a short time. Results show that optimized models are more efficient and our proposed approach is reducing voltage pulsation. As a result optimized system improves electromagnetic compatibility for beneficial use in modern industry and sensible human–machine cooperation.
Marcin Wozniak, Andrzej Sikora, Adam Zielonka, Kuljeet Kaur, M. Shamim Hossain, Mohammad Shorfuzzaman
IEEE Trans. Ind. Informatics4
2022 A NOMA-Enabled Framework for Relay Deployment and Network Optimization in Double-Layer Airborne Access VANETs
abstract
A non-orthogonal multiple access (NOMA)-enabled double-layer airborne access vehicular ad hoc networks (DLAA-VANETs) architecture is designed in this paper, which consists of a high-altitude platform (HAP), multiple unmanned aerial vehicles (UAVs) and vehicles. For the designed DLAA-VANETs, we investigate the UAV deployment and network optimization problems. In particular, a UAV deployment scheme based on particle swarm optimization is presented. Then, the NOMA technique is introduced into the designed architecture, which can improve the transmission rate. Afterward, we take the information security into account and formulate a downlink total transmission rate maximization problem by optimizing UAV height and subcarrier allocation. For tackling this non-convex problem, we decouple this downlink total transmission rate maximization problem as two subproblems, where UAV height and subcarrier allocation problems are solved in turn. Moreover, the transmission performance of the designed DLAA-VANETs is analyzed, based on which the security outage probability (SOP) is derived. Finally, simulation results demonstrate that the presented UAV deployment scheme can maximize the relay coverage ratio. In addition, the proposed can achieve a higher downlink total transmission rate in comparison with the current works.
Yixin He 0001, Laisen Nie, Tan Guo, Kuljeet Kaur, Mohammad Mehedi Hassan, Keping Yu
IEEE Trans. Intell. Transp. Syst.4
2022 ML-Based IDPS Enhancement With Complementary Features for Home IoT Networks
abstract
The Internet of Things (IoT) networks are obstructed by security vulnerabilities that hackers can leverage to operate intrusions in many environments, such as smart homes, smart factories, and smart healthcare systems. To overcome this obstruction, researchers have come up with different intrusion detection and prevention systems (IDPSs). Out of all the implemented technologies, Machine Learning (ML) has emerged as the most promising approach. Therefore, to improve the detection accuracy, most ML-based intrusion detection solutions focus only on investigating appropriate ML algorithms. Yet, the limitations in terms of detection accuracy in various attacks are often caused by lack of appropriate detection features. Moreover, the majority of the previous works lack intrusion prevention mechanisms and deployment architectures. Thus, in this research, we study the properties of different smart home security attacks and the quality of the features that can be brought out and employed in ML algorithms to detect each of these attacks efficiently. Furthermore, this research proposes effective intrusion prevention mechanisms and a Software-Defined Networking (SDN) based deployment architecture of the IDPSs within home networks. Experimental evaluations of the proposed solution are provided using different feature sets and various ML models. The contributions and advancements discussed in this paper will upgrade future research and engineering works on IDPSs for IoT.
Poulmanogo Illy, Georges Kaddoum, Kuljeet Kaur, Sahil Garg
IEEE Trans. Netw. Serv. Manag.3
2022 EDCSuS: Sustainable Edge Data Centers as a Service in SDN-Enabled Vehicular Environment
abstract
Cloud computing has emerged as one of the popular technologies which provide on-demand services to the end users. Such services are hosted by massive geo-distributed data centers (DCs). Nowadays, connected vehicles in a smart city can also avail cloud services through Internet using cellular technologies. But, the advent of 5G technology has posed challenges for DCs such as-low latency and higher data rate requirements. To handle these challenges, edge-DCs (EDCs) can be deployed across a smart city to provide low latency services to the connected vehicles. In lieu of this, in this paper, EDCSuS: Sustainable EDC as a service framework in software defined vehicular environment is proposed. In EDCSuS, first, a software defined controller handles the incoming requests and suggest an optimal flow path. Second, a multi-leader multi-follower Stackelberg game is presented for resource allocation. Third, to improve the resource utilization, a cooperative resource sharing scheme is designed, thereby minimizing the energy consumption of servers in the EDCs. Lastly, a caching scheme is presented to avert excessive energy consumption for retracing the lost link due to vehicular mobility. The efficacy of the proposed scheme has been evaluated using extensive simulations with respect to various parameters. The results obtained prove the effectiveness of EDCSuS.
Gagangeet Singh Aujla, Neeraj Kumar 0001, Sahil Garg, Kuljeet Kaur, Rajiv Ranjan 0001
IEEE Trans. Sustain. Comput.4
2021 Newton-interpolation-based zk-SNARK for Artificial Internet of Things
Xinglin Shang, Liang Tan 0001, Keping Yu, Jing Zhang 0057, Kuljeet Kaur, Mohammad Mehedi Hassan
Ad Hoc Networks5
2021 Spam message detection using Danger theory and Krill herd optimization
Aakanksha Sharaff, Chandramani Kamal, Siddhartha Porwal, Surbhi Bhatia, Kuljeet Kaur, Mohammad Mehedi Hassan
Comput. Networks5
2021 Guest Editorial: Special Section on Transfer Learning for 5G-Aided Industrial Internet of Things
abstract
The potential for the wide-scale acceptance of the Industrial IoT is limited by a lack of automation, real-time monitoring, and connectedness. However, the future communication trend towards 5G is expected to bring greater benefits to IIoT infrastructures in terms of high-speed transmission and ultra-low latency. Furthermore, with emerging techniques such as millimeter-wave (mmWave), massive multiple-input multiple-output (MIMO), and machine-to-machine (M2M) communications, the coupling of IIoT and 5G will advance profoundly. Despite these advantages, 5G-envisioned IIoT ecosystems are expected to face other potential concerns such as trust, security, and privacy. Apart from this, the challenges related to data storage and processing and computational complexities will also draw significant attention. To address the above-mentioned challenges, it's important to analyze data in real-time. In this direction, transfer learning (TL) can be a revolutionary breakthrough. TL fosters greater explorations and experimentations, leading to innovations and greater productivity.
Kuljeet Kaur, Song Guo 0001, Min Chen 0003, Danda B. Rawat
IEEE Trans. Ind. Informatics1
2021 Blockchain-Based Cyber-Physical Security for Electrical Vehicle Aided Smart Grid Ecosystem
abstract
The ever-growing trend of making the traditional power grids smarter than before has resulted in their gradual evolution to more sophisticated grids, referred to as Smart Grids (SGs) Cyber-Physical Systems with complex networking technologies. The integration of Information and Communication Technologies with power grids fosters seamless data sharing between different SG entities, which supports effective and smart governance in terms of demand response management, frequency support, and voltage stabilization. Nonetheless, this integration opens up several security and privacy concerns, namely, electricity theft, power loss, battery exhaustion, infrastructure mapping, etc. These issues become even more important with the addition of distributed energy sources, e.g. electric vehicles (EVs), battery energy storage systems, and renewable energy sources, into the SGs. We present a framework based on Software Defined Networking (SDN) and BlockChain (BC) to address two challenging issues of EV-aided SG ecosystems, namely, privacy assurance and power security. We leverage the capabilities of SDN to handle the complex interactions between different subsystems of the SG. Furthermore, we also employ BC and smart contracts' properties to secure energy transactions and data communications. We design a secure and efficient mutual authentication protocol based on Elliptic Curve Cryptography (ECC) and BC for privacy preservation during smart energy trading. We also proposed a BC-based smart contract for effective Demand Response Management (DRM) during bidirectional energy transfer between EVs and SG. Finally, we present experimental evaluations to validate the proposed framework's performance. The results obtained demonstrate the improved performance of the proposed scheme compared with current state-of-the-art approaches. The mutual authentication protocol designed is not only secure against major attack vectors (namely, session key security, message integrity, anonymity, forward secrecy, and so on), but it is also cost-efficient in terms of communication and computational costs. Additionally, the SC designed assures power security and maintains an adequate balance between demand and supply.
Kuljeet Kaur, Georges Kaddoum, Sherali Zeadally
IEEE Trans. Intell. Transp. Syst.1
2021 Energy and SLA-driven MapReduce Job Scheduling Framework for Cloud-based Cyber-Physical Systems
abstract
Energy consumption minimization of cloud data centers (DCs) has attracted much attention from the research community in the recent years; particularly due to the increasing dependence of emerging Cyber-Physical Systems on them. An effective way to improve the energy efficiency of DCs is by using efficient job scheduling strategies. However, the most challenging issue in selection of efficient job scheduling strategy is to ensure service-level agreement (SLA) bindings of the scheduled tasks. Hence, an energy-aware and SLA-driven job scheduling framework based on MapReduce is presented in this article. The primary aim of the proposed framework is to explore task-to-slot/container mapping problem as a special case of energy-aware scheduling in deadline-constrained scenario. Thus, this problem can be viewed as a complex multi-objective problem comprised of different constraints. To address this problem efficiently, it is segregated into three major subproblems (SPs), namely, deadline segregation, map and reduce phase energy-aware scheduling. These SPs are individually formulated using Integer Linear Programming. To solve these SPs effectively, heuristics based on Greedy strategy along with classical Hungarian algorithm for serial and serial-parallel systems are used. Moreover, the proposed scheme also explores the potential of splitting Map/Reduce phase(s) into multiple stages to achieve higher energy reductions. This is achieved by leveraging the concepts of classical Greedy approach and priority queues. The proposed scheme has been validated using real-time data traces acquired from OpenCloud. Moreover, the performance of the proposed scheme is compared with the existing schemes using different evaluation metrics, namely, number of stages, total energy consumption, total makespan, and SLA violated. The results obtained prove the efficacy of the proposed scheme in comparison to the other schemes under different workload scenarios.
Kuljeet Kaur, Sahil Garg, Georges Kaddoum, Neeraj Kumar 0001
ACM Trans. Internet Techn.1
2020 ECC-based Secure and Provable Authentication Mechanism for Smart Healthcare Ecosystem
abstract
In the smart healthcare domain, a number of mutual authentication and key agreement protocols have been suggested by the research fraternity. However, the majority of the existing protocols fail to provide the required level of security and fall for different attack vectors. Thus, in this paper, a robust, secure, and lightweight authentication and key agreement protocol is presented. The designed protocol exploits the enhanced security and reduced key size features of Elliptic Curve Cryptography (ECC) to establish mutual trust between the patients (equipped with mobile devices/sensors) and the central servers; followed by settlement on a common session key for further communication. Furthermore, the designed protocol also exploits one of the crucial features of the blockchain technology, i.e., maintaining the hash of the previous transaction. This feature, in turn, instills greater security and prevents impersonation attacks to a much larger extent. The formal and informal security assessments of the proposed protocol establish the fact that it more secure and resilient against different attack vectors than its existing counterpart. In addition to this, comparative evaluation in terms of communication and computational overhead also indicate the lightweight attribute of the proposed protocol.
Sahil Garg, Kuljeet Kaur, Georges Kaddoum, Min Client
ICC2
2020 ESP-VDCE: Energy, SLA, and Price-driven Virtual Data Center Embedding
abstract
In this work, we present a multi-objective Virtual Data Center Embedding (VDCE) scheme for multi-domain cloud computing setups. The primary focus of the proposed scheme is on -Energy minimization, SLA assurance, and reduced energy Prices; and is named as ESP-driven VDCE. In the preliminary phase of this work, we formulate the proposed scheme as an optimization problem. However, due to the intractability of the formulated problem, its is remodelled and divided into three sub-problems (SP), i.e., data center identification, virtual machine mapping, and virtual link embedding. The output of one SP serves as an input to the next SP, such that the search space can be significantly narrowed. Finally, the proposed approach for VDCE is extensively validated against other algorithms. The obtained results indicate that the proposed ESP-driven VDCE approach achieves almost 7.6% more energy-aware embeddings with 11.5% higher SLA levels and approximately 23% lower energy expenses.
Kuljeet Kaur, Sahil Garg, Georges Kaddoum, Song Guo 0001
ICC1
2020 Secure Authentication and Key Agreement Protocol for Tactile Internet-based Tele-Surgery Ecosystem
abstract
With the recent advancements in wireless communications, Tactile Internet (TI) has witnessed a major blow. TI is considered the next big evolution that will provide real-time control in industrial setups, particularly in the domain of tele-surgery. However, in remote-surgery ecosystems the transmission of data is prone to different attack vectors. Thus, to realize the true potential of secure tele-surgery under the umbrella of TI, it is required to design a secure authentication and key agreement protocol for tele-surgery. In this paper, we present an effective and secure mutual authentication and session establishment protocol for TI-driven remote surgery setups. The designed protocol enables secure communications between the surgeon, robotic arm, and the trusted authority (TA); where the protocol leverages the advantages of Elliptic Curve Cryptography (ECC) and biometrics. The protocol operates along the following three phases: i) setup phase, ii) registration phase, and iii) mutual authentication and key agreement phase. During the third phase, the surgeon and the robotic arm mutually authenticate each other with the help of the TA. Further, the security features of the designed protocol have been established using formal and informal means. The obtained results indicate the resiliency of the protocol against offline password guessing attacks, replay attacks, impersonation attacks, man-in-the-middle attacks, denial of service attacks, etc.
Kuljeet Kaur, Sahil Garg, Georges Kaddoum, Mohsen Guizani
ICC1
2020 A multi-stage anomaly detection scheme for augmenting the security in IoT-enabled applications
Sahil Garg, Kuljeet Kaur, Shalini Batra, Georges Kaddoum, Neeraj Kumar 0001, Azzedine Boukerche
Future Gener. Comput. Syst.2
2020 Toward Secure and Provable Authentication for Internet of Things: Realizing Industry 4.0
abstract
The Internet of Things (IoT) has many applications, including Industry 4.0. There are a number of challenges when deploying IoT devices in the Industry 4.0 setting, partly due to the low-cost IoT devices/nodes with limited capacity to run/support security solutions. Hence, there is a need for a lightweight and efficient security solution to protect the environment. Thus, in this article, we present a robust, lightweight, and provably secure authentication and key agreement protocol specifically for the IoT environment based on a hierarchical approach. The proposed protocol relies on lightweight operations, such as elliptic curve cryptography, physically unclonable functions, hash functions, concatenation, and XOR operations. We then evaluate the security of the designed protocol, including the widely used automated validation of Internet security protocols and applications (AVISPA), and demonstrate that it supports mutual authentication between IoT nodes and server, and is resilient against a number of common security attacks [denial of service (DoS), replay, spoofing, etc.]. The computational and communication overhead analysis shows that the proposed protocol is comparatively less expensive than three other recently published, competing protocols.
Sahil Garg, Kuljeet Kaur, Georges Kaddoum, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2020 KEIDS: Kubernetes-Based Energy and Interference Driven Scheduler for Industrial IoT in Edge-Cloud Ecosystem
abstract
With the rapid explosion of Industrial Internet of Things (IIoT), the need for real-time data processing with enhanced flexibility and scalability has increased manifold. However, the newly evolved containerization technology offers lucrative advantages in comparison to the conventional virtual machines. However, management of these light-weight containers is a tedious task, but Google Kubernetes offers a consolidated container management and scheduling for successful execution of various lightweight containers. Nevertheless, the existing Kubernetes solutions fall short in efficiently handling the “interference” and “energy minimization” challenges in IIoT set-up. Hence, in this article, we present a competent controller, named Kubernetes-based energy and interference driven scheduler (KEIDS), for container management on edge-cloud nodes taking into account the emission of carbon footprints, interference, and energy consumption. The problem of task scheduling has been formulated using integer linear programming based on multiobjective optimization problem. In detail, KEIDS minimizes the energy utilization of edge-cloud nodes in IIoT for optimal green energy utilization. Henceforth, the applications are scheduled on the available nodes in less time with minimum interference from other applications, which in turn guarantees an optimal performance to the end-users. An extensive evaluation of the proposed KEIDS scheduler in comparison to the existing state-of-the-art schemes indicates its superior performance on real-time data acquired from Google compute cluster.
Kuljeet Kaur, Sahil Garg, Georges Kaddoum, Syed Hassan Ahmed, Mohammed Atiquzzaman
IEEE Internet Things J.1
2020 En-ABC: An ensemble artificial bee colony based anomaly detection scheme for cloud environment
Sahil Garg, Kuljeet Kaur, Shalini Batra, Gagangeet Singh Aujla, Graham Morgan, Neeraj Kumar 0001, Albert Y. Zomaya, Rajiv Ranjan 0001
J. Parallel Distributed Comput.2
2020 A Collaborative Security Framework for Software-Defined Wireless Sensor Networks
abstract
With the advent of 5G, technologies such as Software-Defined Networks (SDNs) and Network Function Virtualization (NFV) have been developed to facilitate simple programmable control of Wireless Sensor Networks (WSNs). However, WSNs are typically deployed in potentially untrusted environments. Therefore, it is imperative to address the security challenges before they can be implemented. In this paper, we propose a software-defined security framework that combines intrusion prevention in conjunction with a collaborative anomaly detection systems. Initially, an IPS-based authentication process is designed to provide a lightweight intrusion prevention scheme in the data plane. Subsequently, a collaborative anomaly detection system is leveraged with the aim of supplying a cost-effective intrusion detection solution near the data plane. Moreover, to correlate the true positive alerts raised by the sensor nodes in the network edge, a Smart Monitoring System (SMS) is exploited in the control plane. The performance of the proposed model is evaluated under different security scenarios as well as compared with other methods, where the model's high security and reduction of false alarms are demonstrated.
Christian Miranda, Georges Kaddoum, Elias Bou-Harb, Sahil Garg, Kuljeet Kaur
IEEE Trans. Inf. Forensics Secur.5
2020 Secure and Lightweight Authentication Scheme for Smart Metering Infrastructure in Smart Grid
abstract
In this article, a secure and lightweight authentication scheme, which provides trust, anonymity, and mutual authentication, with reduced energy, communicational, and computational overheads, is proposed for resource-constrained smart meters (SMs). The designed mutual authentication-based key agreement protocol leverages the advantages of fully hashed menezes-qu-vanstone key exchange mechanism along with Elliptic curve cryptography and one-way hash functions. Moreover, it allows to securely establish and verify the trust between the two communicating parties, i.e., SMs and neighbourhood area network gateway. These entities communicate over the insecure channel and form an important component of the smart metering infrastructure. Furthermore, extensive performance evaluation validates the supremacy of the designed protocol over the state-of-the-art in furnishing higher security features with minimal communicational and computational overheads. The obtained results also reflect that the proposed protocol is fit for implementation on resource-constrained SMs as it leads to minimal energy consumption.
Sahil Garg, Kuljeet Kaur, Georges Kaddoum, Joel J. P. C. Rodrigues, Mohsen Guizani
IEEE Trans. Ind. Informatics2
2020 A Big Data-Enabled Consolidated Framework for Energy Efficient Software Defined Data Centers in IoT Setups
abstract
The rapidly evolving industry standards and transformative advances in the field of Internet of Things are expected to create a tsunami of Big Data shortly. This, in turn, will demand real-time data analysis and processing from cloud computing platforms. A substantial part of the computing infrastructure is supported by large-scale and geographically distributed data centers (DCs). Nevertheless, these DCs impose a substantial cost in terms of rapidly growing energy consumption, which in turn adversely affects the environment. In this context, efficient resource utilization is seen as a potential candidate to enhance energy efficiency and minimize the load on the power sector. Nevertheless, in the majority of the public clouds, the resources are idle most of the time (i.e., under-utilized) as the load of the servers is unpredictable; thereby leading to a lofty increase in the energy utilization index and wastage of resources. Thus, it is highly essential to devise a precise and efficient resource management technique. Therefore, in this article, we leverage the advantages of software defined data centers (SDDCs) to minimize energy utilization levels. Precisely, SDDC refers to the process of programmatically abstracting the logical computing, network, and storage resources; and configuring them in real-time based on workload demands. In detail, we demonstrate the possibility of 1) designing a consolidated SDDC-based model to jointly optimize the process of virtual machine (VM) deployment and network bandwidth allocation for reduced energy consumption and guaranteed quality of service (QoS), particularly for heterogeneous computing infrastructures; 2) formulating a multiobjective optimization problem to deduce the optimal allocation of resources for both critical and noncritical applications; and 3) designing an efficient scheme based on heuristics to provide suboptimal results for the formulated multiobjective optimization problem. The proposed article presents a suboptimal approach based on first fit decreasing algorithm. Further, our empirical evaluations suggest that the proposed framework leads to almost 27.9% savings in terms of energy consumptions against the existing schemes with negligible QoS violations (approximately 0.33).
Kuljeet Kaur, Sahil Garg, Georges Kaddoum, Elias Bou-Harb, Kim-Kwang Raymond Choo
IEEE Trans. Ind. Informatics1
2019 LiSA: A Lightweight and Secure Authentication Mechanism for Smart Metering Infrastructure
abstract
Smart metering infrastructure (SMI) is the core component of the smart grid (SG) which enables two-way communication between consumers and utility companies to control, monitor, and manage the energy consumption data. Despite their salient features, SMIs equipped with information and communication technology are associated with new threats due to their dependency on public communication networks. Therefore, the security of SMI communications raises the need for robust authentication and key agreement primitives that can satisfy the security requirements of the SG. Thus, in order to realize the aforementioned issues, this paper introduces a lightweight and secure authentication protocol, "LiSA", primarily to secure SMIs in SG setups. The protocol employs Elliptic Curve Cryptography at its core to provide various security features such as mutual authentication, anonymity, replay protection, session key security, and resistance against various attacks. Precisely, LiSA exploits the hardness of the Elliptic Curve Qu Vanstone (EVQV) certificate mechanism along with Elliptic Curve Diffie Hellman Problem (ECDHP) and Elliptic Curve Discrete Logarithm Problem (ECDLP). Additionally, LiSA is designed to provide the highest level of security relative to the existing schemes with least computational and communicational overheads. For instance, LiSA incurred barely 11.826 ms and 0.992 ms for executing different passes across the smart meter and the service providers. Further, it required a total of 544 bits for message transmission during each session.
Sahil Garg, Kuljeet Kaur, Georges Kaddoum, François Gagnon, Syed Hassan Ahmed, Dushantha N. K. Jayakody
GLOBECOM2
2019 A Lightweight and Privacy-Preserving Authentication Protocol for Mobile Edge Computing
abstract
With the advent of the Internet-of-Things (IoT), vehicular networks and cyber-physical systems, the need for real-time data processing and analysis has emerged as an essential pre-requite for customers' satisfaction. In this direction, Mobile Edge Computing (MEC) provides seamless services with reduced latency, enhanced mobility, and improved location awareness. Since MEC has evolved from Cloud Computing, it inherited numerous security and privacy issues from the latter. Further, decentralized architectures and diversified deployment environments used in MEC platforms also aggravate the problem; causing great concerns for the research fraternity. Thus, in this paper, we propose an efficient and lightweight mutual authentication protocol for MEC environments; based on Elliptic Curve Cryptography (ECC), one-way hash functions and concatenation operations. The designed protocol also leverages the advantages of discrete logarithm problems, computational Diffie- Hellman, random numbers and time-stamps to resist various attacks namely-impersonation attacks, replay attacks, man-in-the-middle attacks, etc. The paper also presents a comparative assessment of the proposed scheme relative to the current state-of-the-art schemes. The obtained results demonstrate that the proposed scheme incurs relatively less communication and computational overheads, and is appropriate to be adopted in resource constraint MEC environments.
Kuljeet Kaur, Sahil Garg, Georges Kaddoum, Mohsen Guizani, Dushantha N. K. Jayakody
GLOBECOM1
2019 Managing Fog Networks using Reinforcement Learning Based Load Balancing Algorithm
abstract
The powerful paradigm of Fog computing is currently receiving major interest, as it provides the possibility to integrate virtualized servers into networks and brings cloud service closer to end devices. To support this distributed intelligent platform, Software-Defined Network (SDN) has emerged as a viable network technology in the Fog computing environment. However, uncertainties related to task demands and the different computing capacities of Fog nodes, inquire an effective load balancing algorithm. In this paper, the load balancing problem has been addressed under the constraint of achieving the minimum latency in Fog networks. To handle this problem, a reinforcement learning based decision-making process has been proposed to find the optimal offloading decision with unknown reward and transition functions. The proposed process allows Fog nodes to offload an optimal number of tasks among incoming tasks by selecting an available neighboring Fog node under their respective resource capabilities with the aim to minimize the processing time and the overall overloading probability. Compared with the traditional approaches, the proposed scheme not only simplifies the algorithmic framework without imposing any specific assumption on the network model but also guarantees convergence in polynomial time. The results show that, during average delays, the proposed reinforcement learning-based offloading method achieves significant performance improvements over the variation of service rate and traffic arrival rate. The proposed algorithm achieves 1.17%, 1.02%, and 3.21% lower overload probability relative to random, least-queue and nearest offloading selection schemes, respectively.
Jung-Yeon Baek 0001, Georges Kaddoum, Sahil Garg, Kuljeet Kaur, Vivianne Gravel
WCNC4
2019 Securing Fog-to-Things Environment Using Intrusion Detection System Based On Ensemble Learning
abstract
The growing interest in the Internet of Things (IoT) applications is associated with an augmented volume of security threats. In this vein, the Intrusion detection systems (IDS) have emerged as a viable solution for the detection and prevention of malicious activities. Unlike the signature-based detection approaches, machine learning-based solutions are a promising means for detecting unknown attacks. However, the machine learning models need to be accurate enough to reduce the number of false alarms. More importantly, they need to be trained and evaluated on realistic datasets such that their efficacy can be validated on real-time deployments. Many solutions proposed in the literature are reported to have high accuracy but are ineffective in real applications due to the non-representativity of the dataset used for training and evaluation of the underlying models. On the other hand, some of the existing solutions overcome these challenges but yield low accuracy which hampers their implementation for commercial tools. These solutions are majorly based on single learners and are therefore directly affected by the intrinsic limitations of each learning algorithm. The novelty of this paper is to use the most realistic dataset available for intrusion detection called NSL-KDD, and combine multiple learners to build ensemble learners that increase the accuracy of the detection. Furthermore, a deployment architecture in a fog-to-things environment that employs two levels of classifications is proposed. In such architecture, the first level performs an anomaly detection which reduces the latency of the classification substantially, while the second level, executes attack classifications, enabling precise prevention measures. Finally, the experimental results demonstrate the effectiveness of the proposed IDS in comparison with the other state-of-the-arts on the NSL-KDD dataset.
Poulmanogo Illy, Georges Kaddoum, Christian Miranda, Kuljeet Kaur, Sahil Garg
WCNC4
2019 SAFE: SDN-Assisted Framework for Edge-Cloud Interplay in Secure Healthcare Ecosystem
abstract
Improved quality of life has lead the healthcare industry to geographically expand and support real-time services. Following this trend, a surge of healthcare monitoring devices has substantially overgrown in the global market. These devices tend to generate data in humongous quantity that need real-time analysis with seamless and secure transmission to the computing nodes. The existing computing and networking infrastructures fall short to cater the services with desirable quality of service. Hence, to overcome these challenges, the proposed work presents a comprehensive platform referred as software defined network (SDN) Assisted Framework for Edge-Cloud Interplay in Secure Healthcare Ecosystem (SAFE). The objectives of SAFE include: first, an offloading scheme to support edge-cloud interplay, second, an SDN-assisted virtualized flow management scheme, and, third, a secure Lattice-based cryptosystem. Finally, the proposed scheme is validated on different performance parameters. Additionally, a security evaluation of the designed cryptosystem is also presented. The results obtained indicate the supremacy of the designed framework.
Gagangeet Singh Aujla, Rajat Chaudhary, Kuljeet Kaur, Sahil Garg, Neeraj Kumar 0001, Rajiv Ranjan 0001
IEEE Trans. Ind. Informatics3
2019 Renewable Energy-Based Multi-Indexed Job Classification and Container Management Scheme for Sustainability of Cloud Data Centers
abstract
Cloud computing has emerged as one of the most popular technologies of the modern era for providing on-demand services to the end users. Most of the computing tasks in cloud data centers are performed by geodistributed data centers which may consume a hefty amount of energy for their operations. However, the usage of renewable energy resources with appropriate server selection and consolidation can mitigate the energy related issues in cloud environment. Hence, in this paper, we propose a renewable energy-aware multi-indexed job classification and scheduling scheme using container as-a-service for data centers sustainability. In the proposed scheme, incoming workloads from different devices are transferred to the data center which has sufficient amount of renewable energy available with it. For this purpose, a renewable energy-based host selection and container consolidation scheme is also designed. The proposed scheme has been evaluated using Google workload traces. The results obtained prove 15%, 28%, and 10.55% higher energy savings in comparison to the existing schemes of its category.
Neeraj Kumar 0001, Gagangeet Singh Aujla, Sahil Garg, Kuljeet Kaur, Rajiv Ranjan 0001, Saurabh Kumar Garg 0001
IEEE Trans. Ind. Informatics4
2019 Fuzzy-Folded Bloom Filter-as-a-Service for Big Data Storage in the Cloud
abstract
With the ongoing trend of smart and Internet-connected objects being deployed across a broad range of applications, there is also a corresponding increase in the amount of data movement across different geographical regions. This, in turn, poses a number of challenges with respect to big data storage across multiple locations, including cloud computing platform. For example, the underlying distributed file system has a large number of directories and files in the form of gigantic trees, which are difficult to parse in polynomial time. Moreover, with the exponential increase of big data streams (i.e., unbounded sets of continuous data flows), challenges associated with indexing and membership queries are compounded. The capability to process such significant amount of data with high accuracy can have significant impact on decision-making and formulation of business and risk-related strategies, particularly in our current Industrial Internet of Things environment (IIoT). However, existing storage solutions are deterministic in nature. In other words, they tend to consume considerable memory and CPU time to yield accurate results. This necessitates the design of efficient quality of service-aware IIoT applications that are able to deal with the challenges of data storage and retrieval in the cloud computing environment. In this paper, we present an effective space-effective strategy for massive data storage using bloom filter (BF). Specifically, in the proposed scheme, the standard BF is extended to incorporate fuzzy-enabled folding approach, hereafter referred to as fuzzy folded BF (FFBF). In FFBF, fuzzy operations are used to accommodate the hashed data of one BF into another to reduce storage requirements. Evaluations on UCI ML AReM and Facebook datasets demonstrate the efficacy of FFBF, in terms of dealing with approximately 1.9 times more data as compared to using the standard BF. This is also achieved without affecting the false positive rate and query time.
Sahil Garg, Kuljeet Kaur, Shalini Batra, Neeraj Kumar 0001, Kim-Kwang Raymond Choo
IEEE Trans. Ind. Informatics3
2019 Hybrid Deep-Learning-Based Anomaly Detection Scheme for Suspicious Flow Detection in SDN: A Social Multimedia Perspective
abstract
The continuous development and usage of multi-media-based applications and services have contributed to the exponential growth of social multimedia traffic. In this context, secure transmission of data plays a critical role in realizing all of the key requirements of social multimedia networks such as reliability, scalability, quality of information, and quality of service (QoS). Thus, a trust-based paradigm for multimedia analytics is highly desired to meet the increasing user requirements and deliver more timely and actionable insights. In this regard, software-defined networks (SDNs) play a vital role; however, several factors such as as-runtime security, and energy-aware networking limit its capabilities to facilitate efficient network control and management. Thus, with the view to enhance the reliability of the SDN, a hybrid deep-learning-based anomaly detection scheme for suspicious flow detection in the context of social multimedia is proposed. It consists of the following two modules: (1) an anomaly detection module that leverages improved restricted Boltzmann machine and gradient descent-based support vector machine to detect the abnormal activities, and (2) an end-to-end data delivery module to satisfy strict QoS requirements of the SDN, that is, high bandwidth and low latency. Finally, the proposed scheme has been experimentally evaluated on both real-time and benchmark datasets to prove its effectiveness and efficiency in terms of anomaly detection and data delivery essential for social multimedia. Further, a large-scale analysis over a Carnegie Mellon University (CMU)-based insider threat dataset has been conducted to identify its performance in terms of detecting malicious events such as-Identity theft, profile cloning, confidential data collection, etc.
Sahil Garg, Kuljeet Kaur, Neeraj Kumar 0001, Joel J. P. C. Rodrigues
IEEE Trans. Multim.2
2019 A Hybrid Deep Learning-Based Model for Anomaly Detection in Cloud Datacenter Networks
abstract
With the emergence of the Internet-of-Things (IoT) and seamless Internet connectivity, the need to process streaming data on real-time basis has become essential. However, the existing data stream management systems are not efficient in analyzing the network log big data for real-time anomaly detection. Further, the existing anomaly detection approaches are not proficient because they cannot be applied to networks, are computationally complex, and suffer from high false positives. Thus, in this paper a hybrid data processing model for network anomaly detection is proposed that leverages grey wolf optimization (GWO) and convolutional neural network (CNN). To enhance the capabilities of the proposed model, GWO and CNN learning approaches were enhanced with: 1) improved exploration, exploitation, and initial population generation abilities and 2) revamped dropout functionality, respectively. These extended variants are referred to as Improved-GWO (ImGWO) and Improved-CNN (ImCNN). The proposed model works in two phases for efficient network anomaly detection. In the first phase, ImGWO is used for feature selection in order to obtain an optimal trade-off between two objectives, i.e., reduced error rate and feature-set minimization. In the second phase, ImCNN is used for network anomaly classification. The efficacy of the proposed model is validated on benchmark (DARPA'98 and KDD'99) and synthetic datasets. The results obtained demonstrate that the proposed cloud-based anomaly detection model is superior in comparison to the other state-of-the-art models (used for network anomaly detection), in terms of accuracy, detection rate, false positive rate, and F-score. In average, the proposed model exhibits an overall improvement of 8.25%, 4.08%, and 3.62% in terms of detection rate, false positives, and accuracy, respectively; relative to standard GWO with CNN.
Sahil Garg, Kuljeet Kaur, Neeraj Kumar 0001, Georges Kaddoum, Albert Y. Zomaya, Rajiv Ranjan 0001
IEEE Trans. Netw. Serv. Manag.2
2018 HyClass: Hybrid Classification Model for Anomaly Detection in Cloud Environment
abstract
Network traffic analysis is one of the most important tasks in the era of on-demand Cloud Computing. However, increased resilience on computing needs, migration flexibility, and decreased costs, have made the security and privacy issues more challenging in the context of cloud computing. Although, there are several anomaly detection techniques available in literature, but due to the unbalanced nature of data, curse of dimensionality, noise in incoming data, and frequently changing anomalies, most of the existing solutions pose critical challenges in detection of aberrant patterns. Thus, in order to overcome these gaps, a new ensemble based anomaly detection scheme called "Hybrid Classification Model for Anomaly Detection (HyClass)" in cloud environment has been proposed. HyClass operates in two phases: feature selection and classification namely- (i) Boruta algorithm supported by scaling and normalization to identify important set of features and improve the accuracy and efficiency of subsequent classification and (ii) Chaotic Optimization and Differential evolution based Support Vector Machine to reduce the computational complexity by tuning the parameters of kernel function and perform classification with high accuracy. In order to evaluate the proposed anomaly detection model, two case-studies were conducted using real-time dataset from our University network and benchmark Knowledge Discovery and Data Mining (KDD'99) dataset. Experimental results in terms of detection rate, false positive rate and accuracy demonstrate the effectiveness and reliability of the proposed HyClass model.
Sahil Garg, Kuljeet Kaur, Neeraj Kumar 0001, Shalini Batra, Mohammad S. Obaidat
ICC2
2018 Edge-Based Content Delivery for Providing QoE in Wireless Networks Using Quotient Filter
abstract
With an exponential increase in the data generation from various Internet-enabled devices, end user's demand satisfaction with respect to Quality of experience (QoE) has become a prime concern over the past few years. However, to assure QoE to the end users, content delivery networks (CDNs) aim to provide the content close to the user's geographical location so as to decrease network congestion, and latency along with an optimal bandwidth consumption. This paper proposes a popular content storage at the edge nodes/gateways instead of a remote server for increasing the data availability. For efficient cache management at the edge nodes, data is stored using Quotient filters (QFs), where number of QFs considered are determined by the number of categories taken for data segregation. To improve the accuracy and reduce the effort in caching process, one extra bit called timer-based metabit has been used with the QF, which helps to implement least frequently used caching efficiently. It has been experimentally proved that the proposed scheme has an approximate gain of 8.9% in object hit ratio with respect to the existing CDN based techniques. Moreover, the search time complexity of the proposed edge-based CDN is independent of the number of incoming requests.
Sahil Garg, Kuljeet Kaur, Shalini Batra, Neeraj Kumar 0001, Mohammad S. Obaidat
ICC3
2018 EnLoc: Data Locality-Aware Energy-Efficient Scheduling Scheme for Cloud Data Centers
abstract
With the rapid proliferation of big data, real-time processing of huge datasets becomes a challenging task; primarily because of their heterogeneous nature. Due to this, one of the most serious concerns of the modern cloud data centers is massive energy consumption during job execution. Hence, energy-aware task scheduling with data placement are considered as two important parameters for enhanced energy efficiency of modern cloud data centers. Moreover, considering the ``pay-per-use" model of cloud computing infrastructure, it is important to maintain desirable service level agreement (SLA) while attaining improved data locality. Poor task scheduling decisions with limited focus of data locality are the prime reasons for escalated data communications and energy utilization levels. In order to deal with the aforementioned issues, data locality- aware energy-efficient (EnLoc) scheme for task scheduling and data placement has been proposed, particularly for MapReduce framework. The proposed EnLoc scheme is a multi-objective optimization problem (MOOP) and is solved using multi-objective evolutionary algorithm with ``Tchebycheff decomposition"; wherein the formulated MOOP is decomposed into theoretically finite number of subproblems to get optimal scheduling and placement decisions. The proposed scheme has been evaluated on real-time data traces acquired from OpenCloud Hadoop Cluster. The results obtained clearly demonstrate that the proposed EnLoc scheme outperforms the existing schemes in terms of energy efficiency, SLA assurance, and data locality.
Kuljeet Kaur, Neeraj Kumar 0001, Sahil Garg, Joel J. P. C. Rodrigues
ICC1
2016 Lightweight Authentication Protocol for RFID-Enabled Systems Based on ECC
abstract
Radio Frequency Identification(RFID) is a leading wireless technology with respect to Automatic Identification and Data Capture(AIDC). With its increasing popularity amongst the researchers and industries, it has been successful in paving its way to various domains including supply chain management, healthcare, agriculture, aviation, etc. Potential applications of RFID range from tracking of assets to real-time human monitoring. However, with its wide-scale deployment, RFID systems have become more vulnerable to different kinds of active and passive attacks leading to various issues such as information leakage, identity revelation, spoofing, tracking, etc. Thus, privacy needs to be embedded in such systems so as to maintain highest levels of privacy and authenticity at all times. In order to address these issues, this paper proposes an efficient and lightweight authentication protocol using Elliptical Curve Cryptography(ECC). It is found to be safe as it establishes mutual authentication between the server and tags; while protecting against replay, tracking, eavesdropping, and cloning risks. In addition to this, AVISPA has been used to formally verify the security features of the protocol. The obtained results indicate that it is more preferable for RFID- enabled devices and provides better security than its previous counterparts.
Kuljeet Kaur, Neeraj Kumar 0001, Mukesh Singh, Mohammad S. Obaidat
GLOBECOM1
2016 An intelligent RFID-enabled authentication scheme for healthcare applications in vehicular mobile cloud
Neeraj Kumar 0001, Kuljeet Kaur, Subhas C. Misra, Rahat Iqbal
Peer-to-Peer Netw. Appl.2
2016 Decision Tree and SVM-Based Data Analytics for Theft Detection in Smart Grid
abstract
Nontechnical losses, particularly due to electrical theft, have been a major concern in power system industries for a long time. Large-scale consumption of electricity in a fraudulent manner may imbalance the demand-supply gap to a great extent. Thus, there arises the need to develop a scheme that can detect these thefts precisely in the complex power networks. So, keeping focus on these points, this paper proposes a comprehensive top-down scheme based on decision tree (DT) and support vector machine (SVM). Unlike existing schemes, the proposed scheme is capable enough to precisely detect and locate real-time electricity theft at every level in power transmission and distribution (T&D). The proposed scheme is based on the combination of DT and SVM classifiers for rigorous analysis of gathered electricity consumption data. In other words, the proposed scheme can be viewed as a two-level data processing and analysis approach, since the data processed by DT are fed as an input to the SVM classifier. Furthermore, the obtained results indicate that the proposed scheme reduces false positives to a great extent and is practical enough to be implemented in real-time scenarios.
Anish Jindal, Amit Dua, Kuljeet Kaur, Mukesh Singh, Neeraj Kumar 0001, Sukumar Mishra
IEEE Trans. Ind. Informatics3