Mina Alishahi

dblp:168/2454 · also Mina Sheikh Alishahi, Mina Sheikhalishahi · DBLP profile ↗
← Back
29ranked-venue papers
9as first author
18since 2021 · last 2026
0000-0002-1159-8832ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 21 · 6 first-author · 16 since 2021Computer networks · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Blurred Points, Clear Clusters: A Non-interactive Framework for Locally Private Clustering
Tjibbe van der Ende, Mina Alishahi, Clara Maathuis
DBSec2
2026 Are Explanations Robust to Federated Poisoning? An Empirical Study in Cyber Threat Detection
Daniel Bakhtiari, Mina Alishahi, Gaurav Choudhary
SECRYPT (1)2
2025 Fair Play for Individuals, Foul Play for Groups? Auditing Anonymization's Impact on ML Fairness
abstract
Machine learning (ML) algorithms are heavily based on the availability of training data, which, depending on the domain, often includes sensitive information about data providers. This raises critical privacy concerns. Anonymization techniques have emerged as a practical solution to address these issues by generalizing features or suppressing data to make it more difficult to accurately identify individuals. Although recent studies have shown that privacy-enhancing technologies can influence ML predictions across different subgroups, thus affecting fair decision-making, the specific effects of anonymization techniques, such as k-anonymity, ℓ-diversity, and t-closeness, on ML fairness remain largely unexplored. In this work, we systematically audit the impact of anonymization techniques on ML fairness, evaluating both individual and group fairness. Our quantitative study reveals that anonymization can degrade group fairness metrics by up to fourfold. Conversely, similarity-based individual fairness metrics tend to improve under stronger anonymization, largely as a result of increased input homogeneity. By analyzing varying levels of anonymization across diverse privacy settings and data distributions, this study provides critical insights into the trade-offs between privacy, fairness, and utility, offering actionable guidelines for responsible AI development. Our code is publicly available at: https://github.com/hharcolezi/anonymity-impact-fairness.
Héber Hwang Arcolezi, Mina Alishahi, Adda-Akram Bendoukha, Nesrine Kaaniche
ECAI2
2025 Learning Without Sharing: A Comparative Study of Federated Learning Models for Healthcare
Anja Campmans, Mina Alishahi, Vahideh Moghtadaiee
SECRYPT2
2025 From Real to Synthetic: GAN and DPGAN for Privacy Preserving Classifications
Mohammad Emadi, Vahideh Moghtadaiee, Mina Alishahi
SECRYPT3
2025 A survey and future outlook on indoor location fingerprinting privacy preservation
Amir Fathalizadeh, Vahideh Moghtadaiee, Mina Alishahi
Comput. Networks3
2025 Fed-GWAS: Privacy-preserving individualized incentive-based cross-device federated GWAS learning
Omid Torki, Maede Ashouri-Talouki, Mina Alishahi
J. Inf. Secur. Appl.3
2024 Autoencoder for Detecting Malicious Updates in Differentially Private Federated Learning
abstract
Differentially Private Federated Learning (DP-FL) is a novel machine learning paradigm that integrates federated learning with the principles of differential privacy. In DP-FL, a global model is trained across decentralized devices or servers, each holding local data samples, without the need to exchange raw data. This approach ensures data privacy by adding noise to the model updates before aggregation, thus preventing any individual contributor’s data from being compromised. However, ensuring the integrity of the model updates from these contributors is paramount. This research explores the application of autoencoders as a means to detect anomalous or fraudulent updates from contributors in DP-FL. By leveraging the reconstruction errors generated by autoencoders, this study assesses their effectiveness in identifying anomalies while also discussing potential limitations of this approach.
Lucía Alonso, Mina Alishahi
SECRYPT2
2024 Local Differential Privacy for Data Clustering
abstract
This study presents an innovative framework that utilizes Local Differential Privacy (LDP) to address the challenge of data privacy in practical applications of data clustering. Our framework is designed to prioritize the protection of individual data privacy by empowering users to proactively safeguard their information before it is shared to any third party. Through a series of experiments, we demonstrate the effectiveness of our approach in preserving data privacy while simultaneously facilitating insightful clustering analysis.
Lisa Bruder, Mina Alishahi
SECRYPT2
2024 Membership Inference Attacks Against Indoor Location Models
abstract
With the widespread adoption of location-based services and the increasing demand for indoor positioning systems, the need to protect indoor location privacy has become crucial. One metric used to assess a dataset’s resistance against leaking individuals’ information is the Membership Inference Attack (MIA). In this paper, we provide a comprehensive examination of MIA on indoor location privacy, evaluating their effectiveness in extracting sensitive information about individuals’ locations. We investigate the vulnerability of indoor location datasets under white-box and black-box attack settings. Additionally, we analyze MIA results after employing Differential Privacy (DP) to privatize the original indoor location training data. Our findings demonstrate that DP can act as a defense mechanism, especially against black-box MIA, reducing the efficiency of MIA on indoor location models. We conduct extensive experimental tests on three real-world indoor localization datasets to assess MIA in terms of the model architecture, the nature of the data, and the specific characteristics of the training datasets.
Vahideh Moghtadaiee, Amir Fathalizadeh, Mina Alishahi
SECRYPT3
2024 Anonify: Decentralized Dual-level Anonymity for Medical Data Donation
abstract
Medical data donation involves voluntarily sharing medical data with research institutions, which is crucial for advancing healthcare research. However, the sensitive nature of medical data poses privacy and security challenges. The primary concern is the risk of de-anonymization, where users can be linked to their donated data through background knowledge or communication metadata. In this paper, we introduce Anonify, a decentralized anonymity protocol offering strong user protection during data donation without reliance on a single entity. It achieves dual-level anonymity protection, covering both communication and data aspects by leveraging Distributed Point Functions, and incorporating k-anonymity and stratified sampling within a secret-sharing-based setting. Anonify ensures that the donated data is in a form that affords flexibility for researchers in their analyses. Our evaluation demonstrates the efficiency of Anonify in preserving privacy and optimizing data utility. Furthermore, the performance of machine learning algorithms on the anonymized datasets generated by the protocol shows high accuracy and precision.
Sarah Abdelwahab Gaballah, Lamya Abdullah, Mina Alishahi, Thanh Hoang Long Nguyen, Ephraim Zimmer, Max Mühlhäuser, Karola Marky
Proc. Priv. Enhancing Technol.3
2023 BC-FL k-means: A Blockchain-based Framework for Federated Clustering
abstract
This work presents a novel framework to train clustering models collaboratively without compromising accuracy while accommodating privacy and security in a decentralized manner. Our decentralized collaborative learning model removes the single point of failure and excludes unreliable input by designing a committee-based consensus method in a blockchain-based federated learning, which is equipped with a reputation system. We present a prototype implementation of our approach and show that its performance is comparable with centralized clustering regardless of the distribution of data among devices.
Mina Alishahi, Wouter Leeuw, Nicola Zannone
TrustCom1
2022 Add noise to remove noise: Local differential privacy for feature selection
abstract
Feature selection has become significantly important for data analysis. It selects the most informative features describing the data to filter out the noise, complexity, and over-fitting caused by less relevant features. Accordingly, feature selection improves the predictors’ accuracy, enables them to be trained faster and more cost-effectively, and provides a better understanding of the underlying data. While plenty of practical solutions have been proposed in the literature to identify the most discriminating features describing a dataset, an understanding of feature selection over privacy-sensitive data in the absence of a trusted party is still missing. The design of such a framework is specifically important in our modern society, where each individual through accessing the Internet can play simultaneously the role of a data provider and a data-analysis beneficiary. In this study, we propose a novel feature selection framework based on Local Differential Privacy (LDP), named LDP-FS, which estimates the importance of features over securely protected data while protects the confidentiality of each individual data before leaving the user’s device. The performance of LDP-FS in terms of scoring and ordering the features is assessed by investigating the impact of datasets properties, privacy mechanism, privacy levels, and feature selection techniques on this framework. The accuracy of classifiers trained on the selected subset of features by LDP-FS is also presented. Our experimental results demonstrate the effectiveness and efficiency of the proposed framework.
Mina Alishahi, Vahideh Moghtadaiee, Hojjat Navidan
Comput. Secur.1
2022 On the privacy protection of indoor location dataset using anonymization
Amir Fathalizadeh, Vahideh Moghtadaiee, Mina Alishahi
Comput. Secur.3
2021 Not a Free Lunch, But a Cheap One: On Classifiers Performance on Anonymized Datasets
Mina Alishahi, Nicola Zannone
DBSec1
2021 Multi-Party Private Set Intersection Protocols for Practical Applications
abstract
Multi-Party Private Set Intersection (MPSI) is an attractive topic in research since a practical MPSI protocol can be deployed in several real-world scenarios, including but not limited to finding the common list of customers among several companies or privacy-preserving analyses of data from different stakeholders. Several solutions have been proposed in the literature however, the existing solutions still suffer from performance related challenges such as long run-time and high bandwidth demand, particularly when the number of involved parties grows. In this paper, we propose a new approach based on threshold additively homomorphic encryption scheme, e.g., Paillier, which enables us to process the bit-set representation of sets under encryption. By doing so, it is feasible to securely compute the intersection of several data sets in an efficient manner. To prove our claims on performance, we compare the communication complexity of our approach with the existing solutions and show performance test results. We also show how the proposed protocol can be extended to securely compute other set operations on multi-party data sets.
Aslí Bay, Zekeriya Erkin, Mina Alishahi, Jelle Vos
SECRYPT3
2021 Comparing Classifiers' Performance under Differential Privacy
abstract
The application of differential privacy in privacy-preserving data analysis has gained momentum in recent years. In particular, it provides an effective solution for the construction of privacy-preserving classifiers, in which one party owns the data and another party is interested in obtaining a classifier model from this data. While several approaches have been proposed in the literature to employ differential privacy for the construction of classifiers, an understanding of the difference in performance of these classifiers is currently missing. This knowledge enables the data owner and the analyst to select the most appropriate classification algorithm and training parameters in order to guarantee high privacy requirements while minimizing the loss of accuracy. In this study, we investigate the impact of the use of differential privacy on three well-known classifiers, i.e., Naïve Bayes, SVM, and Decision Tree classifiers. To this end, we show how these classifiers can be trained in a differential privacy setting and perform extensive experiments to evaluate the effect of this privacy enforcement on their performance.
Milan Lopuhaä-Zwakenberg, Mina Alishahi, Jeroen Kivits, Jordi Klarenbeek, Gert-Jan van der Velde, Nicola Zannone
SECRYPT2
2021 Privacy-preserving policy evaluation in multi-party access control
abstract
Recent years have seen an increasing popularity of online collaborative systems like social networks and web-based collaboration platforms. Collaborative systems typically offer their users a digital environment in which they can work together and share resources and information. These resources and information might be sensitive and, thus, they should be protected from unauthorized accesses. Multi-party access control is emerging as a new paradigm for the protection of co-owned and co-managed resources, where the policies of all users involved in the management of a resource should be accounted for collaborative decision making. Existing approaches, however, only focus on the jointly protection of resources and do not address the protection of the individual user policies themselves, whose disclosure might leak sensitive information. In this work, we propose a privacy-preserving mechanism for the evaluation of multi-party access control policies, which preserves the confidentiality of user policies while remaining capable of making collaborative decisions. To this end, we design secure computation protocols for the evaluation of policies in protected form against an access query and realize such protocols using two privacy-preserving techniques, namely Homomorphic Encryption and Secure Functional Evaluation. We show the practical feasibility of our mechanism in terms of computation and communication costs through an experimental evaluation.
Mina Alishahi, Ischa Stork, Nicola Zannone
J. Comput. Secur.1
2020 On the Comparison of Classifiers' Construction over Private Inputs
abstract
Classifiers are often trained over data collected from different sources. Sharing their data with other entities, however, can raise privacy concerns for data owners. To protect data confidentiality while being able to train a classifier, effective solutions have been proposed in the literature to construct various types of classifiers over private data. However, to date an analysis and comparison of the computation and communication costs for the construction of classifiers over private data is missing, making it difficult to determine which classifier can be used in a given application domain. In this work, we show how two well-known classifiers (Naive Bayes and SVM classifiers) can be securely build over private inputs, and evaluate their construction costs. We assess the computation and communication costs for training the classifiers both theoretically and empirically for different benchmark datasets.
Mina Alishahi, Nicola Zannone
TrustCom1
2020 Privacy Preserving Statistical Detection of Adversarial Instances
abstract
Adversarial instances are malicious input designed by attackers to cause a classification model to make a false prediction, e.g. in Spam detection. Effective solutions have been proposed to detect and block adversarial instances in real time. Still, the proposed approaches fail to detect adversarial instances over private input (required by many on-line platforms analyzing sensitive personal data). In this work, we propose a novel framework that applies a statistical test to detect adversarial instances when data under analysis are in private format. The practical feasibility of our approach in terms of computation cost is shown through an experimental evaluation.
Mina Alishahi, Nicola Zannone
WETICE1
2018 Secure Two-party Agglomerative Hierarchical Clustering Construction
Mona Hamidi, Mina Alishahi, Fabio Martinelli
ICISSP2
2018 A Secure Distributed Framework for Agglomerative Hierarchical Clustering Construction
abstract
This paper presents a general framework for constructing any agglomerative hierarchical clustering algorithm over partitioned data. It is assumed that data is distributed between two (or more) parties horizontally, such that for mutual benefits the participated parties are willing to identify the clusters' structure on their data as a whole, but for privacy restrictions, they avoid to share the original datasets. To this end, in this study, we propose general algorithms based on secure scalar product and secure hamming distance computation to securely compute the desired criteria for shaping the clusters' scheme. The proposed approach covers all possible secure agglomerative hierarchical clustering construction when data is distributed between two (or more) parties, including both numerical and categorical data.
Mona Hamidi, Mina Alishahi, Fabio Martinelli
PDP2
2018 Walking Through the Deep: Gait Analysis for User Authentication Through Deep Learning
Giacomo Giorgi, Fabio Martinelli, Andrea Saracino, Mina Alishahi
SEC4
2017 Privacy-preserving text mining as a service
abstract
Text mining is the process to automatically infer relevant information from semantically related text documents. This technique, which has applications from business intelligence to homeland security, terrorism and crime fight, might bring noticeable privacy issues when analyzed documents contain privacy sensitive information. In this paper, we propose a framework for privacy-preserving text analysis, which exploits Homomorphic Encryption, to analyze text documents in a privacy preserving manner. The proposed framework is designed to ensure that there is no disclosure of privacy sensitive information contained in the document to any party, including the analysis engine itself. Furthermore, we present two use cases of analysis based on bag-of-words classification, where the proposed framework manages to obtain good classification results without information disclosure. In particular the two different settings that are considered are: tweet analysis for detection of terrorist Twitter accounts, and out-box email analysis for detection of bot infected devices. Accuracy results with different classifiers, performances and a security analysis of our approach are presented and discussed.
Gianpiero Costantino, Antonio La Marra, Fabio Martinelli, Andrea Saracino, Mina Alishahi
ISCC5
2017 Privacy preserving clustering over horizontal and vertical partitioned data
abstract
This paper presents a framework for constructing a hierarchical categorical clustering algorithm on horizontal and vertical partitioned dataset. It is assumed that data is distributed between two parties, such that for general benefits both are willing to detect the clusters on whole dataset, but for privacy concerns, they refuse to share the original datasets. To this end, we propose algorithms based on secure weighted average protocol and secure number comparison protocol, to securely compute the desired criteria in constructing clusters' scheme.
Mina Alishahi, Fabio Martinelli
ISCC1
2017 A Distributed Framework for Collaborative and Dynamic Analysis of Android Malware
abstract
Combination of dynamic and static analysis is very effective in detecting malicious Android apps. However, dynamic analysis is hardly practiced on large scale, due to the necessary active interaction with the malicious app, which is reliable only if performed by a user on a real device. In this paper we present a framework for distributed and collaborative analysis of Android suspicious apps, which leverages real users to test the functionality of apps and detect eventual malicious behaviors by exploiting an on-host app for intrusion detection. The paper introduces the architecture, workflow and protocols to handle the report received by participating users, detecting and filtering the malicious ones. Simulative results to assess the performance of the proposed framework are reported and discussed.
Mario Faiella, Antonio La Marra, Fabio Martinelli, Francesco Mercaldo, Andrea Saracino, Mina Alishahi
PDP6
2017 Privacy-Utility Feature Selection as a Privacy Mechanism in Collaborative Data Classification
abstract
This paper presents a novel framework for privacy aware collaborative information sharing for data classification. Data holders participating in this information sharing system, for global benefits are interested to model a classifier on whole dataset, but are ready to share their own table of data if a certain amount of privacy is guaranteed. To address this issue, we propose a privacy mechanism based on privacy-utility feature selection, which by eliminating the most irrelevant set of features in terms of accuracy and privacy, guarantees the privacy requirements of data providers, whilst the data remain practically useful for classification. Due to the fact that the proposed trade-off metric is required to be exploited on whole dataset, a distributed secure sum protocol is utilized to protect information leakage in each site. The proposed approach is evaluated and validated through standard Tumor dataset.
Mina Alishahi, Fabio Martinelli
WETICE1
2016 Collaborative Attribute Retrieval in Environment with Faulty Attribute Managers
abstract
Attributes describing the features of subjects, objects and of the environment are used in access and usage control models to determine the right of a subject to use an object in a given environment. Hence, it is crucial for the effective enforcement of access and usage policies that authorization systems are able to promptly retrieve the values of the required attributes from the Attribute Providers. However, sometimes attribute providers could not respond when queried by Authorization systems, because they could be temporary down or unreachable. This could affect the decision processes, causing some requests to be unduly denied or some ongoing accesses to be unduly interrupted. This paper proposes a strategy that can be adopted by an Authorization system to estimate the value of the attributes it requires when the corresponding attribute providers are not responding. This strategy leverages on the collaboration of the other Authorization systems which exploit the same attribute providers, and which could have cached a value for the required attributes. We validate the presented approach through a set of simulative experiments which consider the presence of malicious authorization systems in the cooperative environment.
Mario Faiella, Fabio Martinelli, Paolo Mori, Andrea Saracino, Mina Alishahi
ARES5
2015 Clustering Spam Emails into Campaigns
abstract
Spam emails constitute a fast growing and costly problems associated with the Internet today. To fight effectively against spammers, it is not enough to block spam messages. Instead, it is necessary to analyze the behavior of spammer. This analysis is extremely difficult if the huge amount of spam messages is considered as a whole. Clustering spam emails into smaller groups according to their inherent similarity, facilitates discovering spam campaigns sent by a spammer, in order to analyze the spammer behavior. This paper proposes a methodology to group large sets of spam emails into spam campaigns, on the base of categorical attributes of spam messages. A new informative clustering algorithm, named Categorical Clustering Tree (CCTree), is introduced to cluster and characterize spam campaigns. The complexity of the algorithm is also analyzed and its efficiency has been proven.
Mina Alishahi, Nadia Tawbi
ICISSP1