Pooria Madani

dblp:161/8806 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
4since 2021 · last 2026
0000-0002-4474-8817ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 SecRL-Prune: Structured Reinforcement Learning-Based Pruning of CodeLLMs for Preserving Adversarial Code Mutation
abstract
Large code language models (CodeLLMs) can generate and rewrite programs, enabling functionality-preserving code mutation that may be used to create diverse malware variants and evade signature-based detection. A key security question is whether this mutation capability survives model compression, which would make deployment feasible under limited hardware budgets. We propose SecRL-Prune, a structured pruning framework for CodeLLMs that operates on feed-forward (MLP/FFN) channels. Starting from a pretrained teacher, it learns a layer-wise pruning policy with reinforcement learning using a teacher-student KL-divergence reward. To improve efficiency, we cache the teacher's top-P predictions once and compare the pruned student against this compact target, avoiding simultaneous teacher-student residency in GPU memory. We evaluate SecRL-Prune on HumanEval using pass@k for execution correctness and var@k for code diversity across three 7B CodeLLMs at 10-30% compression. SecRL-Prune consistently preserves higher pass@k and var@k than recent structured pruning baselines under aggressive pruning. In a case study on real malware samples, semantics-preserving mutations from 20%-pruned models substantially reduced detections. These results show that code mutation capability can survive significant structured pruning, highlighting the security relevance of compressed CodeLLMs.
Parsa Memarzadehsaghezi, Pooria Madani, Khalil El-Khatib
CODASPY2
2025 A Per-Bag Suspicion-Based Bagging Strategy for Fighting Poisoning Attacks in Classification
abstract
The wide adoption of machine learning-powered systems in sensitive applications, such as banking for fraud detection, has attracted malicious actors who seek to break and subvert these systems. In this work, we focus on Data Poisoning attacks, which is a well-known type of adversarial attack carried out by an adversary whose goal is to reduce the effectiveness of the learning system. Bagging, a well-known ensemble learning technique that aims to improve performance and reduce the overall system variance, has demonstrated robustness against data poisoning attacks. Bagging has been further extended to include weighted schemes designed to detect outliers and assign lower resampling probabilities to anomalous instances, thereby enhancing the robustness of the standard bagging mechanism. Weighted bagging significantly improves system performance when the dataset is poisoned; however, it often suffers from instability due to the mechanism used to estimate the resampling probabilities. To address this challenge, we propose a novel weight estimation approach that leverages the reconstruction capabilities of autoencoders to identify and down-weight anomalous training samples. In particular, we investigate a specific type of data poisoning attack known as a label-flipping attack, using the widely studied MNIST dataset of handwritten images and conduct experiments using a Convolutional Neural Network (CNN). Our results show that the proposed weighted bagging mechanism consistently outperforms standard bagging under data poisoning levels of up to $50 \%$. To our knowledge, this is the first study to introduce a per-bag anomaly-based weighting mechanism, paving the way for future adaptive ensemble defenses in adversarial machine learning.
Aghoghomena Akasukpe, Tomi Adeyemi, Pooria Madani, Li Yang 0010, Miguel Vargas Martin
PST3
2025 Evaluating Efficient Patch-Based Backdoor Attacks in Satellite Image Classification Systems
abstract
Backdoor attacks pose a serious and underexplored threat to high-altitude reconnaissance operations that use pre-trained machine learning models for satellite imagery classification and target discovery. As international relations grow increasingly tense, hostile nations around the globe are working hard to protect their sensitive infrastructures from satellite surveillance. In this context, backdoor poisoning of publicly available image classification models (i.e., open-source pre-trained image classifiers) emerges as a promising method to safeguard critical military infrastructure (e.g., armament plant) from discovery. While prior research has examined poisoning attacks in conventional vision tasks, their effectiveness under the unique constraints of satellite image surveillance systems remains largely unaddressed. In this work, we introduce a novel patch-based poisoning strategy that can effectively inject plausible triggers (e.g., patterns to be painted on the roof of a sensitive military complex) into image classification models, inducing misclassifications of scenes captured by surveillance space assets. Moreover, we study and report the effect of plausible triggers with different patterns, colors, and orientations, in order to best emulate different observation conditions encountered by high-altitude surveillance assets. Our results show that even with minimal access to the training set, a threat actor can successfully implant a robust and stealthy backdoor. This manipulation causes misclassifications of scenes containing strategic infrastructure when the trigger is present while preserving high overall classification accuracy on clean inputs. We further demonstrate that triggering patches used in poisoning are resilient to random orientation and position changes, making them effective in scenarios where reconnaissance satellites approach their targets from different orbital planes. These findings reveal a critical vulnerability in satellite classification pipelines relying on pretrained image classification models and demonstrate the need for defenses that go beyond conventional accuracy-based validation of these model-driven systems.
Ghazal Rahmanian, Pooria Madani
PST2
2021 Unsupervised ML Based Detection of Malicious Web Sessions with Automated Feature Selection: Design and Real-World Validation
abstract
As Web bot technologies continue to evolve, the task of separating human Web sessions from those generated by malicious bots becomes increasingly more challenging. To date, many research studies have proposed the use of advanced ML-based methods as automated means of differentiating between Web bot and genuine human sessions. Unfortunately, most of these studies overlook the importance of adequate feature selection during the dataset preprocessing stage. Namely, instead of making the process of feature selection automated and optimized to each particular dataset, these studies generally resort to the use of the same fixed set of hand-picked Web-session attributes. It is well known, however, that suboptimal approach to feature selection is likely to result in suboptimal performance of the respective ML algorithm and, consequently, of the entire system. The main contributions of our work are as follows: First, we propose the use of Gradient Boosting Technique to automatically identify the most significant Web-session features (out of an extensive list of 119 possible attributes) for any given dataset. Second, we integrate this automated features selection technique into a system for Web-session classification based on the unsupervised Self-Organizing Map (SOM) algorithm. Third, we validate the performance of the integrated system on a recent real-world dataset which has been collected during a confirmed large-scale attack on our home institution. The obtained experimental results not only verify that our proposed system is highly effective in identifying malicious Web-sessions, but they also help us better understand the nature and scale of the conducted attack itself.
Shadi Sadeghpour, Natalija Vlajic, Pooria Madani, Dusan Stevanovic
CCNC3
2019 Near-optimal Evasion of Randomized Convex-inducing Classifiers in Adversarial Environments
abstract
Classifiers are often used to detect malicious activities in adversarial environments. Sophisticated adversaries would attempt to find information about deployed classifiers in order to strategise different evasion techniques. It is a widely held belief that randomization of decision boundaries/rules of detection systems would introduce further complexities in attempts made by the adversaries for finding minimal adversarial cost (MAC) evading instances. We have extended the results obtained by Nelson et al. [14] and further presented a novel algorithm that can find optimal evading instances in randomized convex-inducing classifiers using polynomial-many queries. Our results have demonstrated that the complexity introduced through randomization only increases the complexity of finding an optimal evading instance by a constant factor and thus the risk of optimal evasion is still present.
Pooria Madani, Natalija Vlajic
ARES1
2017 Resource Hints in HTML5: A New Pandora's Box of Security Nightmares
abstract
1 To date, much of the development in Web-related technologies has been driven by the users' quest for ever faster and more intuitive WWW. One of the most recent trends in this development is built around the idea that a user's WWW experience can further be improved by predicting and/or preloading Web resources most likely sought by this user, ahead of time. Resource hints is a set of features introduced in HTML5 and intended to support the idea of predictive preloading in the WWW. Unfortunately, as the very actualization and the present use of the resource hints have been almost exclusively driven by the speed and end-user experience in mind, the opportunities for their misuse in terms of other user-related metrics (user privacy and reputation, as well as business analytics) appear to be considerable.
Natalija Vlajic, Xue Ying Shi, Hamzeh Roumani, Pooria Madani
ARES4