EDBT 2026 Demo / reviewers in the wild / expert
Nour Moustafa
dblp:172/9981
· DBLP profile ↗
84ranked-venue papers
10as first author
66since 2021 · last 2026
0000-0001-6127-9349ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 22 · 2 first-author · 20 since 2021Security and privacy · 19 · 4 first-author · 10 since 2021Computer networks · 18 · 2 first-author · 14 since 2021Systems, architecture and hardware · 13 · 2 first-author · 11 since 2021Artificial intelligence and machine learning · 7 · 6 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ST-Attention-XAI: Intrinsic Spatio-Temporal Explainability for IoT Intrusion Detection via Attention Analysis
Nimesha Dilini, Nan Sun 0002, Yuantian Miao, Nour Moustafa |
ACISP (2) | 4 |
| 2026 | LGP: Layerwise Gradient Purify for Robust Federated Learning Against Poisoning AttacksabstractFederated learning (FL) has become a promising framework for collaborative model training on devices while preserving privacy. However, despite its significant potential, it faces notable cyber threats, such as poisoning attacks and codenamed Byzantine clients. These threats have the potential to significantly degrade the global model by jeopardizing the integrity of the collaborative model training process. Whilst previous research has addressed the detection and elimination of malicious gradients from Byzantine clients, it has also shown that model poisoning attacks can evade most statistical defence approaches relying on metrics such as median and distance. To address the challenge posed by poisoning attacks, we introduce a novel approach called Layerwise Gradient Purify (LGP), which aims to remove any harmful gradients before the global aggregation process. It is comprised of two closely-related stages. The first stage focuses on pruning gradients at the layer level using the Median Absolute Deviation (MAD) pruning criterion. In the second stage, statistical features are extracted from the pruned gradients layer-by-layer and then clustered into honest and malicious categories. The proposed methodology treats each layer of the model across all clients as a probability distribution, employing hierarchical clustering to differentiate between malicious and honest clusters. Moreover, we introduce a new innocent criterion for selecting honest clusters, relying on reputation scores and gradient deviations from the global model. Extensive experiments were conducted employing diverse deep learning models, including CNN, RNN, and MLP, across a spectrum of datasets, including Cifar-10, AG-News, MNIST and ToN-IoT. The experiments evaluated the resilience of state-of-the-art approaches against recently introduced attacks. The numerical results demonstrate that theLGPapproach is effective and superior. Wael Issa, Nour Moustafa, Benjamin P. Turnbull, Zahir Tari |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | TFVDFuzzer: Transformer-based Fuzzing Framework for Vulnerability Detection in Modbus ProtocolabstractThe development of industrial control systems (ICS) has led to security vulnerabilities in ICS protocols, which have caused significant threats to these systems. Fuzzing is a highly effective technique for detecting vulnerabilities by exposing the target program to a large volume of malformed and unexpected input. Traditional fuzzing methods are time-consuming and have low acceptance rates and coverage due to the manual extraction of specifications, lack of guidance, and blind mutations, limiting their efficiency in discovering vulnerabilities. Currently, the Generative Adversarial Network (GAN)-based fuzzing methods are used to learn the syntax and format of the input data and generate valid test cases. However, they still suffer from low diversity in the generated test cases, which can affect the potential of triggering vulnerabilities. We have proposed a transformerbased fuzzing framework called TFVDFuzzer to solve these issues. In this framework, we leverage the Transformer model to automate the learning of ICS protocol specifications, especially Modbus, significantly speeding up the fuzzing process and enhancing the test case acceptance rate. Furthermore, we used a deep learning model that employs an attention mechanism to determine the appropriate bytes for mutations to enhance the diversity of the test cases. The TFVDFuzzer is assessed using a benchmark Modbus dataset. It outperforms Peach, Fuzzowski, and NCMFuzzer with significant improvements, achieving a Test Case Reception Rate (TCRR) of $\mathbf{9 8. 1 5 \%}$ compared to their highest values of $\mathbf{5 1. 4 2 \%, ~} \mathbf{6 9. 0 2 \%}$, and $\mathbf{9 4. 2 5 \%}$, respectively, and a Test System Anomaly Rate (TSAR) of $3.1 \%$ relative to their highest values of $0.445 \%, 0.475 \%$, and $0.96 \%$, respectively. Ahmed Reda Aldysty, Nour Moustafa, Erandi Lakshika |
PST | 2 |
| 2025 | DT-BFL: Digital Twins for Blockchain-enabled Federated Learning in Internet of Things networksabstractSixth-generation (6G) wireless networks are set to transform the Internet of Things (IoT) by enabling faster, smarter, and more connected systems. These networks will bring together a wide range of devices, including cars, robots, industrial machines, and smartphones, to support edge intelligence and real-time decision-making. Federated learning (FL) supports this shift by allowing devices to collaboratively train models without sharing raw data, which helps to protect user privacy. Despite its advantages, FL faces significant security challenges, including poisoning attacks and Byzantine clients, both of which can compromise the training process and degrade the accuracy and reliability of the global model. Although existing methods can detect malicious updates, many advanced attacks still bypass statistical defenses relying on metrics such as median and distance. Thus, developing an FL system that ensures both reliable decision-making and privacy and security guarantees in IoT networks remains a significant challenge. This study introduces a Digital Twin-driven Blockchain-enabled Federated Learning (DT-BFL) framework designed for IoT networks. The framework creates a digital representation of the IoT environment to support secure and decentralized edge intelligence using blockchain and federated learning technologies. DT-BFL is built to detect and filter out potentially poisoned model updates from malicious participants. This is achieved through a new smart contract-enabled decentralized aggregation method called Local Updates Purify (LUP). LUP uses a two-stage filtering process: First, it applies Median Absolute Deviation (MAD) to initially remove outliers, then uses statistical features and clustering to separate honest from malicious updates before aggregating the global model. It also assigns a Trust Score (TS) to each participant based on how much their updates differ from the global model and then uses a genuine criterion to select honest clients by evaluating trust scores, update similarity, and deviation from the global model. Experimental results show that DT-BFL effectively defends against various poisoning attacks on datasets like MNIST, ToN-IoT, and CIFAR-10 using models such as CNN, MLP, ResNet, and DenseNet, and maintains high accuracy even when 50% of the clients are malicious. Using a permissioned blockchain further secures the system by enabling aggregation of the decentralized model and authentication of clients through smart contracts. The source code is available on https://github.com/UNSW-Canberra-2023/LUP . Wael Issa, Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
Ad Hoc Networks | 2 |
| 2025 | IoT-CAD: A comprehensive Digital Forensics dataset for AI-based Cyberattack Attribution Detection methods in IoT environmentsabstractTracing and identifying attack characteristics, known as Cyberattack Attribution Detection (CAD), is in its early stages. It requires utilizing Deep Learning (DL) techniques to scan multiple devices to identify cyberattacks and detect their attributes effectively in IoT environments. Training and validation of these techniques require comprehensive datasets generated from heterogeneous data sources. However, there is a lack of high-quality and diverse IoT-based datasets involving cyberattack attributes. In this paper, a testbed and novel Internet of Things (IoT) forensics dataset suitable for CAD, called IoT-CAD, are introduced. The proposed dataset focuses on obtaining traces from Windows and Linux operating systems to encompass a plethora of sources, such as memory information, hard drives, processes, system calls, and network traffic. It incorporates traces from many IoT devices and realistic attack scenarios to ensure its relevance and applicability to real-world situations. After collecting, processing and analyzing the dataset, it is evaluated using Machine Learning (ML), Digital Forensics (DF), and Explainable AI (X-AI) techniques. The learning evaluation involves two approaches: Centralized learning for cyberattack detection; and Federated Learning (FL) for CAD. Also, network forensics is employed to investigate the network traffic to ensure that the dataset is realistic and accurately represents attack scenarios. Furthermore, X-AI techniques are used to assess the impact and contribution of each feature on the performances of the ML models, thus justifying the data features presented . This work can be considered a baseline for CAD methods in IoT environments. The dataset can be downloaded from https://shorturl.at/eTlLm . Hania Mohamed, Nickolaos Koroniotis, Francesco Schiliro, Nour Moustafa |
Ad Hoc Networks | 4 |
| 2025 | BFL-SC: A blockchain-enabled federated learning framework, with smart contracts, for securing social media-integrated internet of things systems
Sara Salim, Nour Moustafa, Benjamin P. Turnbull |
Ad Hoc Networks | 2 |
| 2025 | Vulnerability defence using hybrid moving target defence in Internet of Things systemsabstractCyber threat actors are increasingly targeting networked assets and critical infrastructure, with the potential for major socioeconomic impacts. Moving target defence (MTD) is a cyber defence paradigm that creates constantly shifting attack surfaces (i.e., vulnerabilities). It intends to make it more difficult for cyber adversaries to exploit systems, thereby increasing costs and chances of detection. There is a lack of research into the efficiency of combined MTD techniques, especially regarding several types of security considerations like time, cost, and effort. This gap is particularly significant in the Internet of Things (IoT) context, where security problems arise from its heterogeneous architecture . Moreover, MTD may result in the overutilization of network and system resources to enhance cybersecurity. We present a Vulnerability Defence method to address this issue using the three-layer Temporal Hierarchical Attack Representation Model (3-layer-THARM). This approach overcomes this difficulty by evaluating the safety of aggregated network states, considering security metrics in each state and the accessibility of network nodes and edges. Using this model, we can recognize probable attack scenarios in the context of Internet of Things (IoT) systems, conduct a thorough security analysis of the IoT system using well-defined security metrics, and assess the effectiveness of various defence tactics. This feature inherently introduces an additional level of security for the system. Furthermore, this model showcases the ability to identify potential attack pathways and effectively mitigate the consequences of such attacks. Our analysis reveals a noteworthy trend: combining MTD techniques from different categories, such as shuffle and diversity, generally produces more favorable outcomes, including a lower probability of attack success, lower attack risk and higher attack cost. Mohammed Tanvir Masud, Marwa Keshk, Nour Moustafa, Benjamin P. Turnbull, Willy Susilo |
Comput. Secur. | 3 |
| 2025 | Responsible Deep-Federated-Learning-Based Threat Detection for Satellite CommunicationsabstractSatellite communications (Satcoms) have become an indispensable part of modern society, enabling various applications ranging from global connectivity to critical disaster management. However, reliance on Satcoms also raises concerns about cyber threats, highlighting the need for robust detection mechanisms. This article presents a novel model for threat detection (TD) in Satcoms, leveraging deep-federated learning (DFL). Our DFL-based TD model utilizes variational autoencoders (VAEs) as local models, strategically deployed across satellite ground stations and communication nodes. This architecture is meticulously tailored to the distributed nature of Satcom systems, ensuring robust data privacy at local nodes while enhancing collective TD capabilities. To protect sensitive information during model updates, we integrate differential privacy and secure aggregation techniques, reinforcing the model’s commitment to data confidentiality. Furthermore, we prioritize trustworthiness and accountability in TD processes by emphasizing responsible AI practices, explainability, and ethical compliance. By incorporating SHAP values and local explanation methods, we significantly enhance transparency in decision making, empowering stakeholders to effectively understand and interpret model outputs. In addition, our model addresses bias mitigation and fairness concerns, striving for equitable treatment across diverse data subsets and promoting inclusivity. Real-world case studies demonstrate the model’s effectiveness in detecting anomalies in Satcoms, supporting predictive maintenance, and enhancing network security. Sara Salim, Nour Moustafa, Abdulrazaq Almorjan |
IEEE Internet Things J. | 2 |
| 2025 | ERT: Data placement based on estimated response time for P2P storage systems
Fitrio Pakana, Nasrin Sohrabi, Hai Dong 0001, Zahir Tari, Nour Moustafa |
J. Parallel Distributed Comput. | 5 |
| 2025 | FedCAD: Federated Cyberattack Attribution Detection for Internet of Things ForensicsabstractAttributing cyberattacks in Internet of Things (IoT) environments is challenging due to their distributed, heterogeneous natures and the limitations of traditional Digital Forensics (DF) tools for preserving privacy and scalability. This paper presents FedCAD, a novel Federated Learning (FL)-based forensic method for multi-attribute cyberattack attribution that operates directly on IoT devices. It leverages a lightweight 1D Convolutional Neural Network (CNN) architecture with a shared feature extractor and three parallel sub-networks, each of which targets a distinct attribute, i.e., attack types, tactics/tools, and motives. Its architecture consists of three layers: an IoT device one collecting traces and local training; an FL one for privacy-preserving model aggregation via FedAvg; and a DF analysis one for multi-attribute inference and reporting. Also, FedCAD integrates the MITRE ATT&CK framework to enrich training data with real-world adversarial knowledge. Evaluations on the three public datasets TON-IoT, Bot-IoT, and UNSW-NB15 show that FedCAD outperforms centralized models, with gains of 2.1% accuracy, 1.0% precision, 1.5% recall, and 1.3% f1-score on TON-IoT. Experimental results demonstrate FedCAD's effectiveness as a scalable, privacy-preserving solution for cyberattack attribution in dynamic IoT ecosystems. Hania Mohamed, Nour Moustafa, Nickolaos Koroniotis, Zahir Tari, Albert Y. Zomaya, Francesco Schiliro |
IEEE Trans. Sustain. Comput. | 2 |
| 2025 | Cybersecurity Solutions and Techniques for Internet of Things Integration in Combat SystemsabstractThe Internet of Things (IoT) has enabled pervasive networking and multi-modal sensing, offering various services such as remote operations and augmenting existing processes. The military setting has increasingly and notably adopted IoT technologies, such as sensor-rich drones or autonomous vehicles, which provide military personnel with enhanced situational awareness, faster decision-making capabilities, and improved operational precision. However, integrating IoT into military systems introduces new security challenges due to increased connectivity and susceptibility to vulnerabilities. Cyberattacks on military IoT systems can have severe consequences, including operational disruptions and compromises of sensitive information. This article proposes a new perspective on examining threat models in IoT-enhanced combat systems, emphasising approaches for identifying threats, conducting vulnerability assessments, and suggesting countermeasures. It delves into the characteristics and structures of IoT-enhanced combat systems, exploring technical implementations and technologies. Additionally, it outlines five significant areas of focus, including blockchain, machine learning, game theory, protocols, and algorithms, to enhance understanding of IoT-enhanced combat systems. The insights gained from this analysis can inform the development of secure and resilient military IoT systems, ultimately enhancing the safety and effectiveness of military operations. Amirmohammad Pasdar, Nickolaos Koroniotis, Marwa Keshk, Nour Moustafa, Zahir Tari |
IEEE Trans. Sustain. Comput. | 4 |
| 2024 | A Predictive Profiling and Performance Modeling Approach for Distributed Stream Processing in EdgeabstractThe advent of edge computing has allowed the continuously generated data to be processed closer to their sources instead of being sent to the cloud for processing. Given the heterogeneous and limited computational resources and dynamic nature of edge computing, stream processing systems need an accurate and easily accessible performance modeling/measurement to perform efficiently in edge environments. This paper proposes a predictive profiling model to enable measuring the performance of a system by predicting the operators' processing time on heterogeneous devices without having to carry out the testing on individual devices. This profiling model comprises a quadratic function to generate CPU clock speed/processing time curves for each operator. By using these curves, the model predicts the processing times of operators without requiring any extra profiling runs. Moreover, a performance model is proposed to deal with (performance) degradation of stream processing applications by modeling their topologies as systems comprising M/M/1 queues. The model uses the performance expectations of queueing models to define the data transfer rates inside topologies and uses Integer Linear Programming to specify the maximum input rate and an operator placement plan that can process that input rate. Experimental results showed that the profiling approach predicts the processing times of 17 operators with an average error rate of 5%. The performance model finds the maximum input rate accurately, while the operator placement plan achieves up to 84% higher throughput and 70% less latency in AWS EC2 instances and 257% higher throughput and 66% less latency in real hardware compared to the default resource-aware scheduler of Apache Storm. Hasan Geren, Nasrin Sohrabi, Zahir Tari, Nour Moustafa |
ICDE | 4 |
| 2024 | PEL: Privacy Embedded Learning in Smart Healthcare SystemsabstractThe widespread use of healthcare data for online medical diagnosis has been made possible by deep learning advancements. However, entrusting computation and storage to unreliable external medical servers introduces security and privacy concerns. As a result, developing trustworthy deep learning algorithms has attracted growing interest in defending against privacy concerns in patient data. Federated learning was developed to protect sensitive data privacy by allowing computation on the client side. Privacy leakage in the communication channel of healthcare systems, through inference, free-riding, Man-in-the-Middle, model poisoning, and gradient attacks, is still a crucial issue. To address this, we introduce an efficient Privacy Embedded Learning (PEL) method that trains machine learning models without compromising privacy. This PEL method addresses how machine learning models handle privacy issues by securing privacy at the patient end, at a medical server and in communication media. To balance privacy protection and model performance, PEL uses edge intelligence-enabled federated learning to defend Smart Healthcare Systems from privacy attacks by applying artificial noise functions and an iteration-based Conventional Neural Network (CNN) model. PEL also offers gradient encryption in federated learning to protect the derived model parameters as gradients on communication media to protect users' privacy without revealing user-sensitive information. We also integrated Federated Edge Aggregator (FEA) into the proposed PEL method to offer a lower overhead than peer mechanisms. We compare the proposed method with existing work and evaluate performance with well-known datasets: COVID-19 chest X-rays and MNIST. The performance is demonstrated by testing accuracy of about 92% and good privacy protection when safeguarding patient and healthcare provider data. Mahmuda Akter, Nour Moustafa, Benjamin P. Turnbull |
PST | 2 |
| 2024 | Explainable deep learning for attack intelligence and combating cyber-physical attacksabstractCyber-physical control loops comprising sensors, actuators and controllers pose the most valued and critical part of the industrial Internet of Things (IIoT) as it regulates the state of the physical process, such as water treatment or gas flow. Thus, any malicious activities could lead to physical damage, affecting human safety. Cyber-physical attacks against the physical process are difficult to detect using existing threats and attack intelligence due to the (1) lack of such intelligence for the physical process and operational technology systems and (2) such attacks affect the process parameters and states. Artificial Intelligence (AI)-based attack intelligence is required. This study proposes an attack intelligence framework for identifying cyber–physical attacks and extracting attack intelligence. We propose an attribution module for attack identification using various machine and deep learning algorithms. We also utilize Explainable AI (XAI) to improve the explainability of the attack attribution module and extract attack intelligence. Our proposed framework is evaluated and tested using a gas pipeline dataset as a use case. We demonstrate that the proposed framework improves the understanding of attacks and provides attack rules, assisting security analysts in securing critical physical processes. Muna Al-Hawawreh, Nour Moustafa |
Ad Hoc Networks | 2 |
| 2024 | A survey of intelligent multimedia forensics for internet of things communications: Approaches, strategies, perspectives, and challenges for a sustainable future
Weiping Ding 0001, Mohamed Abdel-Basset, Ahmed M. Ali 0005, Nour Moustafa |
Eng. Appl. Artif. Intell. | 4 |
| 2024 | Deep-Federated-Learning-Based Threat Detection Model for Extreme Satellite CommunicationsabstractSatellite communications (Satcoms), whether ground-to-space or intersatellite, have, to date, primarily combined the two cutting-edge fields of communication and space, in which cybersecurity and space activities are intricately connected. The susceptibility of Satcoms and other space assets to cyberattacks, as a means of targeting critical infrastructure, is sometimes overlooked. Neither space nor cybersecurity policies, particularly for Satcoms systems, are equipped for the challenges posed by the convergence of space and cyberspace. With the rising number of cyberattacks, including reconnaissance, Denial-of-Service (DoS), and zero-day attacks, on Satcoms systems by extreme nation-state attackers, further defenses must be established. These defenses should enable the discovery of zero-day attacks whilst reducing false positives associated with the detection of advanced persistent threats. In this article, to address these cyber concerns, a comprehensive deep federated learning (DFL)-based threat detection model for proactively recognizing intrusions in Satcoms networks using decentralized on-device data while preserving the privacy of this data is proposed. Our approach leverages a decentralized data-level preprocessing (DLP) mechanism, ensuring that original data remains concealed while providing well-processed, statistically transformed thought-out data for robust threat detection. The proposed model executes federated learning rounds on a novel deep auto-encoder (DAE) architecture, maintaining local data on secure warehouses, and sharing only the learned weights with the central FL server. Also, its ensemble mechanism aggregates the updates from multiple sources to optimize the accuracy of the global learning model. The experimental results demonstrate that the proposed model outperforms the classic/centralised learning (non-FL) versions in terms of protecting the privacy of local data and providing an optimal accuracy rate for attack detection. Furthermore, using differential privacy (DP)-based DLP as a privacy preservation mechanism, the proposed model exhibits high levels of accuracy and better levels of privacy over the training data. Sara Salim, Nour Moustafa, Mohamed Hassanian, David G. A. Ormrod, Jill Slay |
IEEE Internet Things J. | 2 |
| 2024 | A threat intelligence framework for protecting smart satellite-based healthcare networks
Muna Al-Hawawreh, Nour Moustafa, Jill Slay |
Neural Comput. Appl. | 2 |
| 2024 | CNA-TCC: Campaign Network Attribute Based Thematic Campaign ClassificationabstractWith the emergence of social media and computing, many users have utilized social media platforms (SMPs) in communicating and sharing their interests and preferences. One critical challenge is that social media have been employed for propaganda and influence campaigns for various purposes, such as spreading fake news. SMPs generate vast amounts of data that demand machine learning (ML) capabilities to efficiently learn and infer influence campaigns. This study proposes an ML framework for the thematic campaign classification (TCC), assisting decision-makers in understanding the impacts of social media toward end-users and aiding the mitigation of their side effects. The proposed framework relies on a newly developed characterization that we have termed the campaign network attribute (CNA), which adopts representative network features for the effective TCC by neural networks. The proposed CNA-TCC framework was validated using Twitter and Instagram data sources. The proposed framework can achieve a classification precision in the range of 68%–90% for two campaigns. Also, it can identify a known campaign in generic social media data with a 60% precision. The empirical results indicated high-performance levels of the proposed CNA-TCC framework that can substantially reduce the search spaces for social influence campaigns on specific themes. The proposed CNA-TCC framework has the potential to be applied in real-world SMPs and to process their large-scale data, so as to effectively classify influence campaigns. Nathan Johnson, Benjamin P. Turnbull, Martin Reisslein, Nour Moustafa |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2024 | A Blockchain-Enabled Explainable Federated Learning for Securing Internet-of-Things-Based Social Media 3.0 NetworksabstractSocial media (SM) 3.0 integrates SM platforms, such as Facebook and Twitter, with the Internet of Things (IoT), and has a great potential to change how we interact with mobile devices, online platforms, and the world around us. This integration with end users produces large-scale and heterogeneous data sources that demand machine learning (ML)-based data analytics for decision-making and to provide security against ML and data privacy attacks. The development of privacy-aware ML models within a federated learning (FL) ecosystem can empower an entire network to learn from data in a decentralized manner. In this article, we propose a differentially privacy blockchain-based explainable FL (DP-BFL) framework by harnessing the ever-evolving power of SM 3.0 networks. This framework permits any Internet empowered device to partake and contribute data to a global privacy preserved model. In this framework, participants will upload the differentially private local updates to the miners of blockchain, where the local updates will be evaluated and rewarded. The experimental results obtained from real-world datasets, namely, SM 3.0 and MNIST, demonstrated that the proposed framework could achieve high utility, enhanced privacy, and elevated efficiency. More Specifically, the experimental analysis of our proposed framework reveals the following two key properties. First, our proposed DP-BFL yields noticeable performance improvements in the applied learning models with high privacy and comparable utility levels, in terms of accuracy and f-measure metrics, to a standard FL and centralized learning approaches under the restriction of privacy preservation. Second, given a certain number of the malicious entities, DP-BFL allowed an enhanced recognition of users' preferences in the SM 3.0 dataset and precise prediction of images' class in the MNIST dataset while mitigating the impact of the malicious entities' poisoned updates. Moreover, as the proposed DP-BFL attains DP on the local model's update, it is considered the same as the standard FL-based setting, along with some kinds of privacy preservation on the uploaded model's updates. Sara Salim, Benjamin P. Turnbull, Nour Moustafa |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2024 | RVE-PFL: Robust Variational Encoder-Based Personalized Federated Learning Against Model Inversion AttacksabstractFederated learning (FL) enables distributed joint training of machine learning (ML) models without the need to share local data. FL is, however, not immune to privacy threats such as model inversion (MI) attacks. The conventional FL paradigm often uses privacy-preserving techniques, and this could lead to a considerable loss in the model’s utility and consequently compromised by MI attackers. Seeking to address this limitation, this paper proposes a robust variational encoder-based personalised FL (RVE-PFL) approach that mitigates MI attacks, preserves model utility, and ensures data privacy. RVE-PFL comprises an innovative personalised variational encoder architecture and a trustworthy threat model-integrated FL method to autonomously preserve data privacy, and mitigate MI attacks. The proposed architecture seamlessly trains heterogeneous data at every client, while the proposed approach aggregates data at the server side and effectively discriminates against adversarial settings (i.e., MI); thus, achieving robustness and trustworthiness in real-time. RVE-PFL is evaluated on three benchmark datasets, namely: MNIST, Fashion-MNIST, and Cifar-10. The experimental results revealed that RVE-PFL achieves high accuracy level while preserving data and tuning adversarial settings. It outperforms Noising before Model Aggregation FL (NbAFL) with significant accuracy improvements of 8%, 20%, and 59% on MNIST, Fashion-MNIST, and Cifar-10, respectively. These findings reinforce the effectiveness of RVE-PFL in protecting against MI attacks while maintaining the model’s utility. The source code for RVE-PFL can be found on GitHub 1. Wael Issa, Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Privacy-Preserving Microservices in Industrial Internet-of-Things-Driven Smart ApplicationsabstractMachine learning (ML) algorithms can effectively perform analytics and inferences for building smart applications, such as early detection of diseases in the Industrial Internet of Things (IIoT) and smart healthcare systems. The main components of ML, including training and testing phases, can be decomposed into microservices to improve service quality, along with fast implementation and integration with the edge and cloud services. However, the execution of ML in an edge-cloud environment introduces privacy risks to data owners (e.g., patients). In this article, we present a privacy-preserving ML framework by leveraging microservice technology for safeguarding healthcare IIoT systems. More specifically, we develop a microservice-based distributed privacy-preserving technique using differential privacy (DP) and a radial basis function network (RBFN) to balance between privacy protection and model performance in edge networks. We conduct extensive experiments to evaluate the performance of the proposed technique. The results revealed that DP has a significant influence on the model’s performance and achieves more than 90% accuracy with an epsilon value over 0.4, enhancing data protection and analytics through the implementation of microservices. Neda Bugshan, Ibrahim Khalil 0001, Nour Moustafa, Mohammad Saidur Rahman 0001 |
IEEE Internet Things J. | 3 |
| 2023 | An explainable deep learning-enabled intrusion detection framework in IoT networksabstractAlthough the field of eXplainable Artificial Intelligence (XAI) has a significant interest these days, its implementation within cyber security applications still needs further investigation to understand its effectiveness in discovering attack surfaces and vectors. In cyber defence, especially anomaly-based Intrusion Detection Systems (IDS), the emerging applications of machine/deep learning models require the interpretation of the models' architecture and the explanation of models' prediction to examine how cyberattacks would occur. This paper proposes a novel explainable intrusion detection framework in the Internet of Things (IoT) networks. We have developed an IDS using a Short-Term Long Memory (LSTM) model to identify cyberattacks and explain the model's decisions. This uses a novel set of input features extracted by a novel SPIP (S: Shapley Additive exPlanations, P: Permutation Feature Importance, I: Individual Conditional Expectation, P: Partial Dependence Plot) framework to train and evaluate the LSTM model. The framework was validated using the NSL-KDD, UNSW-NB15 and TON_IoT datasets. The SPIP framework achieved high detection accuracy, processing time, and high interpretability of data features and model outputs compared with other peer techniques. The proposed framework has the potential to assist administrators and decision-makers in understanding complex attack behaviour. Marwa Keshk, Nickolaos Koroniotis, Nam Pham, Nour Moustafa, Benjamin P. Turnbull, Albert Y. Zomaya |
Inf. Sci. | 4 |
| 2023 | An improved Henry gas optimization algorithm for joint mining decision and resource allocation in a MEC-enabled blockchain networksabstractAbstract This paper investigates a wireless blockchain network with mobile edge computing in which Internet of Things (IoT) devices can behave as blockchain users (BUs). This blockchain network’s ultimate goal is to increase the overall profits of all BUs. Because not all BUs join in the mining process, using traditional swarm and evolution algorithms to solve this problem results in a high level of redundancy in the search space. To solve this problem, a modified chaotic Henry single gas solubility optimization algorithm, called CHSGSO, has been proposed. In CHSGSO, the allocation of resources to BUs who decide to engage in mining as an individual is encoded. This results in a different size for each individual in the entire population, which leads to the elimination of unnecessary search space regions. Because the individual size equals the number of participating BUs, we devise an adaptive strategy to fine-tune each individual size. In addition, a chaotic map was incorporated into the original Henry gas solubility optimization to improve resource allocation and accelerate the convergence rate. Extensive experiments on a set of instances were carried out to validate the superiority of the proposed CHSGSO. Its efficiency is demonstrated by comparing it to four well-known meta-heuristic algorithms. Reda M. Hussien, Amr A. Abohany, Nour Moustafa, Karam M. Sallam |
Neural Comput. Appl. | 3 |
| 2023 | USMD: UnSupervised Misbehaviour Detection for Multi-Sensor DataabstractCyber-Physical Systems (CPSs) enable Information Technology to be integrated with Operation Technology to efficiently monitor and manage the physical processes of various critical infrastructures. Recent incidents in cyber ecosystems have shown that CPSs are becoming increasingly vulnerable to complex attacks. These incidents often lead to sensing and actuation misbehaviour by illegal manipulations of data, which can severely impact the underlying physical processes of critical infrastructures. Current research acknowledges that IT-based security measures cannot entirely protect CPSs from such threats. Moreover, they are not designed to monitor the measurement level activities of physical processes, and they fail to mitigate blended cyberattacks, especially multi-stage and zero-day ones. This article addresses these limitations by proposing a framework, named UnSupervised Misbehaviour Detection (USMD), comprising a deep neural network that learns about a system's expected behaviour from data-driven representations. USMD can identify in real-time the attacks on CPSs by using the long-short term memory and Attention method for multi-sensor data. The USMD's performance is evaluated on various known data sets (i.e., ToN_IoT, SWaT, WADI and Gas pipeline datasets). The experimental results indicate that the superior performance of USMD compared with six state-of-the-art methods, which we implemented and extensively tested. USMD achieves F-scores of 0.9699 and 0.9702 on SWaT and WADI datasets, respectively. Abdullah Alsaedi, Zahir Tari, Md. Redowan Mahmud, Nour Moustafa, Abdun Naser Mahmood, Adnan Anwar |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Privacy-Preserved Generative Network for Trustworthy Anomaly Detection in Smart Grids: A Federated Semisupervised ApproachabstractThe deep integration of industrial internet of things technologies in the industrial smart grid (ISG) brings many privacy and security attacks, threatening the trustworthiness of underlying system infrastructures and associated services. That, in turn, raises the necessity for anomaly detection staged by appropriate authorities. Deep learning can provide a promising solution for anomaly detection, but it remains untrustworthy as it fails to do well with small-size labeled data and class-imbalanced data. To solve these issues, this article introduces a novel privacy-preserving federated semisupervised class-rebalanced (Fed-SCR) framework for the detection of anomalous power data in fog-assisted smart grids. Fed-SCR introduces a semisupervised generative network to enhance the quality of generated minority samples and model the relationships between labeled and unlabeled data. Moreover, the generator and discriminator are block-structured leveraging temporal convolutions to improve the representation power during the training. A novel aggregation scheme [termed federated geometric median aggregation (Fed-GMA)] is also introduced based on selective and periodic geometric-median-based aggregation with the main aim to increase the robustness of the federated semi supervised class-rebalanced (Fed-SRC) against noisy gradients while maintaining communication efficiency. The evaluations of Fed-SCR on public power grid datasets reveal its efficiency in improving the trustworthiness of the ISG platform, outperforming the competing methods in terms of binary classification (accuracy: 97.28) and multiclass classification (accuracy: 96.36–95.04). Mohamed Abdel-Basset, Nour Moustafa, Hossam Hawash |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | DFF-SC4N: A Deep Federated Defence Framework for Protecting Supply Chain 4.0 NetworksabstractThe management of contemporary communication networks of supply chain (SC) 4.0 is becoming more complex due to the heterogeneity requirements of new devices concerning the integration of the Internet of Things in the legacy industry networks. Hence, it becomes a challenging task to secure networks of SC 4.0 from cyber-attacks and provide a robust and efficient defence framework that can resist sophisticated attacks. Machine learning-based intelligent detection algorithms are often trained at either a centralized or single server, which makes it difficult to train an effective model and also it violates privacy concerns if gathering data from other servers at the edge. Classical machine learning approaches function on the legacy group of data placed on a central or single server, which brands it the least favored choice for supply chain networks, with data privacy issues. To address these problems, this article proposes a federated learning-based efficient detection model named, DFF-SC4N, to proactively identify intrusions from SC 4.0 networks using distributed local data training. DFF-SC4N uses communication rounds in a federated learning manner having gated recurrent units by only sharing the learned parameters and keeps the data intact on local servers. The accuracy of the global model is optimized by an aggregating model, which updates from multiple servers and multiple SC 4.0 networks. Extensive experiments on real industrial network data demonstrate that the DFF-SC4N outperforms both centralized training models and state-of-the-art peer methods in protecting SC 4.0 networks. Izhar Ahmed Khan, Nour Moustafa, Dechang Pi, Yasir Hussain, Nauman Ali Khan |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | Trustworthy Deep Neural Network for Inferring Anticancer Synergistic CombinationsabstractThe lack of a gold standard synergy quantification method for chemotherapeutic drug combinations warrants the consideration of different synergy metrics to develop efficient predictive models. Furthermore, neglecting combination sensitivity may lead to biased synergistic combinations, which are ineffective in cancer treatment. In this paper, we propose a deep learning-based model, SynPredict, which effectively predicts synergy in five synergy metrics together with the combination sensitivity score. SynPredict assesses the impact of multimodal fusion architectures of the input data, including the gene expression data of cancer cells, along with the representative chemical features of drugs in pairwise combinations. Both ONEIL and ALMANAC anticancer combination datasets are employed comparatively. The impact of the training datasets was more significant and consistent across most synergy models than input data fusion architectures. Synpredict outperforms the state-of-the-art predictive models, including DeepSynergy, AuDNN synergy, TranSynergy and DrugComb, with up to 74% decline in the mean square error. We highlight the pivotal need to consider a multiplex of synergy metrics and the combined sensitivity in the predictive models. Muhammad Alsherbiny, Ibrahim Radwan, Nour Moustafa, Deep Jyoti Bhuyan, Muath El-Waisi, Dennis Chang |
IEEE J. Biomed. Health Informatics | 3 |
| 2023 | The SAir-IIoT Cyber Testbed as a Service: A Novel Cybertwins Architecture in IIoT-Based Smart AirportsabstractRapid technological advancements have resulted in increasingly more efficient and lightweight devices that, coupled with low-power and wide-range wireless connectivity, have given rise to Industrial Internet of Things (IIoT) systems. As a result, the concept of intelligent environments was developed, such as smart airports, where ubiquitous sensors seamlessly cooperate through several types of communication technologies, such as WiFi, BLE, ZigBEE and 5G, enable the collection of data and the dynamic adaption of the system to changing circumstances. However, along with certain benefits, such as augmented communication, enhanced business processes and improved efficiency, IIoT introduces new vulnerabilities, enabling cyber-attackers to compromise not only the digital infrastructure of IIoT architecture-enabled smart airports, but also affecting their physical assets. In this paper, we present a novel smart airport cybertwins security-oriented IIoT testbed, named SAir-IIoT, which comprises multiple heterogeneous IIoT devices and communication protocols, organised into distinct zones, automatically interconnected with each other, that can be remotely accessed as-a-service. To the best of our knowledge, this is the first cybertwins security-oriented testbed that enables researchers and practitioners to remotely practice attack and defence scenarios in smart airport IIoT environments. Additionally, we introduce a new data management technique for dynamically collecting, analysing and tagging heterogeneous data from diverse data sources including IIoT devices and network flows. Finally, we compare SAir-IIoT with other IIoT-based testbeds, revealing its complexity and effectiveness to evaluate new cyber security methods. Nickolaos Koroniotis, Nour Moustafa, Francesco Schiliro, Praveen Gauravaram, Helge Janicke |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | An Explainable Deep Learning Framework for Resilient Intrusion Detection in IoT-Enabled Transportation NetworksabstractThe security of safety-critical IoT systems, such as the Internet of Vehicles (IoV), has a great interest, focusing on using Intrusion Detection Systems (IDS) to recognise cyber-attacks in IoT networks. Deep learning methods are commonly used for the anomaly detection engines of many IDSs because of their ability to learn from heterogeneous data. However, while this type of machine learning model produces high false-positive rates and the reasons behind its predictions are not easily understood, even by experts. The ability to understand or comprehend the reasoning behind the decision of an IDS to block a particular packet helps cybersecurity experts validate the system’s effectiveness and develop more cyber-resilient systems. This paper proposes an explainable deep learning-based intrusion detection framework that helps improve the transparency and resiliency of DL-based IDS in IoT networks. The framework employs a SHapley Additive exPlanations (SHAP) mechanism to interpret decisions made by deep learning-based IDS to experts who rely on the decisions to ensure IoT networks’ security and design more cyber-resilient systems. The proposed framework was validated using the ToN_IoT dataset and compared with other compelling techniques. The experimental results have revealed the high performance of the proposed framework with a 99.15% accuracy and a 98.83% F1 score, illustrating its capability to protect IoV networks against sophisticated cyber-attacks. Ayodeji Oseni, Nour Moustafa, Gideon Creech, Nasrin Sohrabi, Andrew Strelzoff, Zahir Tari, Igor Linkov |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | DeepCog: A Trustworthy Deep Learning-Based Human Cognitive Privacy Framework in Industrial PolicingabstractThe proliferation of the Internet of Things (IoT) has led to the design and incorporation of innovative user control mechanisms, one category based on brain-derived biometric data and known as Brain Control Interface (BCI). BCI devices measure brain signals in EEG and allow users to interact with computerised systems, such as the Industrial Internet of Things (IIoT), intuitively. However, the utilisation of EEG data in the IIoT for actuator control and the collection of such biometric data as evidence for policing the IIoT introduces considerable implications for the users’ cognitive privacy. Thus, considering the importance of cognitive privacy in an evolving era of smart environments, it becomes imperative to develop methods that can ensure the cognitive privacy of users. Cognitive privacy also protects the anonymity of corporations and law enforcement. Furthermore, it maintains the inherent information found in EEG measurements, used by various machine and deep learning models. This paper proposes a novel deep learning-based human cognitive privacy framework, named DeepCog, that ensures users’ privacy through the application of feature transforming normalisation. A deep MLP model then processes the encoded data to classify samples according to an integer-based subject ID, enabling the framework to select the correct secondary deep MLP model (one for each subject) to identify eye activity. Our experiments indicate high accuracy of 93.4%, with precision 93.2% and recall 93.8%, outperforming compelling techniques. Francesco Schiliro, Nour Moustafa, Muhammad Imran Razzak, Amin Beheshti |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | OQFL: An Optimized Quantum-Based Federated Learning Framework for Defending Against Adversarial Attacks in Intelligent Transportation SystemsabstractIntelligent transportation systems, especially Autonomous Vehicles (AVs), are emerging as a paradigm with the potential to change modern society. However, with this, there is a strong need to ensure the security and privacy of such systems. AV ecosystems depend on machine learning algorithms to autonomously control their operations. Given the amount of personal information AVs collect, coupled with the distributed nature of such ecosystems, there is a movement to employ federated learning algorithms to develop secure decision-making models. Although federated learning is a viable candidate for data privacy, it is vulnerable to adversarial attacks, particularly data poisoning attacks, where malicious vectors would be injected in the training phase. Additionally, hyperparameters play an important role in establishing an efficient federated learning model that can be resilient against adversarial attacks. In this paper, to address these challenges, we propose a novel Optimized Quantum-based Federated Learning (OQFL) framework to automatically adjust the hyperparameters of federated learning using various adversarial attacks in AV settings. This work is innovative in two ways: first, a quantum-behaved particle swarm optimization technique is used to update the hyperparameters of the learning rate, local and global epochs. Second, the proposed technique is utilized within a cyber defense framework to defend against adversarial attacks. The performance of the proposed framework was evaluated using two benchmark datasets: MINST and Fashion-MINST, where they include images that would be extracted from smart cameras of AVs. This framework is shown to be more resilient against various adversarial attacks compared with peer techniques. Waleed Yamany, Nour Moustafa, Benjamin P. Turnbull |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | AI-Enabled Secure Microservices in Edge Computing: Opportunities and ChallengesabstractThe paradigm of edge computing has formed an innovative scope within the domain of the Internet of Things (IoT) through expanding the services of the cloud to the network edge to design distributed architectures and securely enhance decision-making applications. Due to the heterogeneous, distributed and resource-constrained essence of edge Computing, edge applications are required to be developed as a set of lightweight and interdependent modules. As this concept aligns with the objectives of microservice architecture, effective implementation of microservices-based edge applications within IoT networks has the prospective of fully leveraging edge nodes capabilities. Deploying microservices at IoT edge faces plenty of challenges associated with security and privacy. Advances in Artificial Intelligence (AI) (especially Machine Learning), and the easy access to resources with powerful computing providing opportunities for deriving precise models and developing different intelligent applications at the edge of network. In this study, an extensive survey is presented for securing edge computing-based AI Microservices to elucidate the challenges of IoT management and enable secure decision-making systems at the edge. We present recent research studies on edge AI and microservices orchestration and highlight key requirements as well as challenges of securing Microservices at IoT edge. We also propose a Microservices-based edge computing framework that provides secure edge AI algorithms as Microservices utilizing the containerization technology to offer automated and secure AI-based applications at the network edge. Firas Al-Doghman, Nour Moustafa, Ibrahim Khalil 0001, Nasrin Sohrabi, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | CDTier: A Chinese Dataset of Threat Intelligence Entity RelationshipsabstractCyber Threat Intelligence (CTI), which is knowledge of cyberspace threats gathered from security data, is critical in defending against cyberattacks.However, there is no open-source CTI dataset for security researchers to effectively apply enormous CTI information for security analysis in the field of threat intelligence, particularly in the field of Chinese threat intelligence. As a result, for network security research and development, this article constructed a Chinese CTI entity relationship dataset–CDTier, which includes: 1) A threat entity extraction dataset composed of 100 CTI reports, 3744 threat sentences and 4259 threat knowledge objects; 2) A dataset for entity relation extraction including 100 CTI reports, 2598 threat sentences and 2562 knowledge object relations. CDTier is, as far as we know, the first CTI dataset. On the CDTier, we trained 4 models for threat entity extraction and relation extraction using well-established and widely used deep learning methods in the NLP. The results showed that the model trained on CDTier extracts knowledge objects and their relationships described in threat intelligence more accurately. This significantly minimizes threat intelligence analysts’ work while assessing threat intelligence. Yinghai Zhou, Yitong Ren, Yanjun Xiao 0001, Zhiyuan Tan 0001, Nour Moustafa, Zhihong Tian 0001 |
IEEE Trans. Sustain. Comput. | 6 |
| 2022 | Data analytics of social media 3.0: Privacy protection perspectives for integrating social media and Internet of Things (SM-IoT) systems
Sara Salim, Benjamin P. Turnbull, Nour Moustafa |
Ad Hoc Networks | 3 |
| 2022 | Rethinking maximum-margin softmax for adversarial robustness
Mohammed Hassanin, Nour Moustafa, Murat Tahtali, Kim-Kwang Raymond Choo |
Comput. Secur. | 2 |
| 2022 | Radial Basis Function Network with Differential Privacy
Neda Bugshan, Ibrahim Khalil 0001, Nour Moustafa, Mahathir Almashor, Alsharif Abuadbba |
Future Gener. Comput. Syst. | 3 |
| 2022 | XSRU-IoMT: Explainable simple recurrent units for threat detection in Internet of Medical Things networks
Izhar Ahmed Khan, Nour Moustafa, Muhammad Imran Razzak, Muhammad Tanveer 0001, Dechang Pi, Yue Pan 0007, Bakht Sher Ali |
Future Gener. Comput. Syst. | 2 |
| 2022 | One-class tensor machine with randomized projection for large-scale anomaly detection in high-dimensional and noisy dataabstractThe modern industrial sector generates enormous amounts of high-dimensional heterogeneous data daily. However, mostly the vectored data (rank-one tensor) have been considered for anomaly detection, whereas the data in real-life is high dimensional. The expressive power of methods based on vector data is restrictive as they may destroy the structural information embedded in data and lead to the curse-of-dimensionality and overfitting. In this paper, we present a novel anomaly detection approach for large-scale tensor data. We first present novel one-class support tensor machines (OCSTM) with bounded loss function. We further extend it by leveraging the randomness to design a scalable approach that can also be used for large-scale anomaly detection. To solve the corresponding optimization of the objective function, we utilize half-quadratic optimization followed by solving it like a traditional OCSTM optimization at each iteration. We demonstrate the proposed randomized OCSTM with bounded hinge loss through experiments on 14 benchmark data sets. Experimental results demonstrate the effectiveness of the proposed approach against anomalies and a significant reduction in the computational complexity. Muhammad Imran Razzak, Nour Moustafa, Shahid Mumtaz, Guandong Xu |
Int. J. Intell. Syst. | 2 |
| 2022 | H2HI-Net: A Dual-Branch Network for Recognizing Human-to-Human Interactions From Channel-State InformationabstractRecognizing human activities is considered a vital research challenge because of its essential significance for improving human–machine collaboration in the Internet of Things environments. The present deep learning (DL) literature focused on studying human activities (HAs) from one subject, with several schemes differing in the recognition method and sensing strategy. However, few research interests have been dedicated to situations where numerous individuals interact to perform common activities. This challenge is termed human-to-human interaction (H2HI) recognition. This study addresses the H2HI problem by a novel device-free DL model, named H2HI-NET, for modeling the HA representation of the Channel State Information of Wireless Fidelity devices. In H2HI-NET, a bi-directional temporal learning module is introduced to capture temporal representation from historical and future information. Simultaneously, the residual spatial learning module is designed to combine residual learning and transformer network capabilities for the efficient extraction of complex spatial features of HAs. The experimental evaluations reveal the efficiency of the H2HI-NET with 96.39% accuracy overcoming cutting-edge studies. Mohamed Abdel-Basset, Hossam Hawash, Nour Moustafa, Mohammad Nazeeruddin |
IEEE Internet Things J. | 3 |
| 2022 | ToN_IoT: The Role of Heterogeneity and the Need for Standardization of Features and Attack Types in IoT Network Intrusion Data SetsabstractThe Internet of Things (IoT) is reshaping our connected world as the number of lightweight devices connected to the Internet is rapidly growing. Therefore, high-quality research on intrusion detection in the IoT domain is essential. To this end, network intrusion data sets are fundamental, as many attack detection strategies have to be trained and evaluated using such data sets. In this article, we introduce the description, statistical analysis, and machine learning evaluation of the novel ToN_IoT data set. A comparison to other recent IoT data sets shows the importance of heterogeneity within these data sets, and how differences between data sets may have a huge impact on detection performance. In a cross-training experiment, we show that the inclusion of different data collection methods and a large diversity of the monitored features are of crucial importance for IoT network intrusion data sets to be useful for the industry. We also explain that the practical application of IoT data sets in operational environments requires the standardization of feature descriptions and cyberattack classes. This can only be achieved with a joint effort from the research community. Tim M. Booij, Irina Chiscop, Erik Meeuwissen, Nour Moustafa, Frank T. H. den Hartog |
IEEE Internet Things J. | 4 |
| 2022 | A New Explainable Deep Learning Framework for Cyber Threat Discovery in Industrial IoT NetworksabstractIndustrial Internet of Things (IIoT) and Industry 4.0 empower interrelation among manufacturing processes, industrial machines, and utility services. The time-critical data collected from heterogeneous sensing devices are usually communicated to processing points for analysis and aggregation as the basis of IIoT. The IIoTs’ service quality typically depends on data integrity and accuracy, which could be exploited by injecting malicious events, such as false data injection and data poisoning attacks. Thus, effective anomaly recognition and explanation are critical for ensuring quality services and empowering security administrators to interpret the causal reasoning of prediction decisions and underlying data evidence. This study proposes an autoencoder-based detection framework using convolutional and recurrent networks to discover cyber threats in IIoT networks and explain the model. A two-step sliding window (SW) is applied to learn the latent representations of data features better. Malicious points from the raw time series are transformed into fixed-length series through the first-step SW. Every series is converted into continuous-time-reliant subseries via another smaller SW to learn latent representations of malicious events. Fully connected networks use the extracted temporal and spatial features for the classification and explanation of attack events. The empirical results revealed that this framework effectively extracts features that include contexts of malicious patterns. This demonstrated that the proposed framework is robust in detecting malicious events using multiple evaluation metrics and outperforming the contemporary state-of-the-art methods, indicating its suitability as an operative application method in real-world IIoT-based networks. Izhar Ahmed Khan, Nour Moustafa, Dechang Pi, Karam M. Sallam, Albert Y. Zomaya, Bentian Li |
IEEE Internet Things J. | 2 |
| 2022 | Interval type-2 fuzzy temporal convolutional autoencoder for gait-based human identification and authentication
Weiping Ding 0001, Mohamed Abdel-Basset, Hossam Hawash, Nour Moustafa |
Inf. Sci. | 4 |
| 2022 | Progressive ShallowNet for large scale dynamic and spontaneous facial behaviour analysis in children
Abdul Qayyum 0002, Muhammad Imran Razzak, Nour Moustafa, Moona Mazher |
Image Vis. Comput. | 3 |
| 2022 | An Automated Task Scheduling Model Using Non-Dominated Sorting Genetic Algorithm II for Fog-Cloud SystemsabstractProcessing data from Internet of Things (IoT) applications at the cloud centers has known limitations relating to latency, task scheduling, and load balancing. Hence, there have been a shift towards adopting fog computing as a complementary paradigm to cloud systems. In this article, we first propose a multi-objective task-scheduling optimization problem that minimizes both the makespans and total costs in a fog-cloud environment. Then, we suggest an optimization model based on a Discrete Non-dominated Sorting Genetic Algorithm II (DNSGA-II) to deal with the discrete multi-objective task-scheduling problem and to automatically allocate tasks that should be executed either on fog or cloud nodes. The NSGA-II algorithm is adapted to discretize crossover and mutation evolutionary operators, rather than using continuous operators that require high computational resources and not able to allocate proper computing nodes. In our model, the communications between the fog and cloud tiers are formulated as a multi-objective function to optimize the execution of tasks. The proposed model allocates computing resources that would effectively run on either the fog or cloud nodes. Moreover, it efficiently organizes the distribution of workloads through various computing resources at the fog. Several experiments are conducted to determine the performance of the proposed model compared with a continuous NSGA-II (CNSGA-II) algorithm and four peer mechanisms. The outcomes demonstrate that the model is capable of achieving dynamic task scheduling with minimizing the total execution times (i.e., makespans) and costs in fog-cloud environments. Ismail M. Ali, Karam M. Sallam, Nour Moustafa, Ripon K. Chakrabortty, Michael J. Ryan, Kim-Kwang Raymond Choo |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | Session Invariant EEG Signatures using Elicitation Protocol Fusion and Convolutional Neural NetworkabstractBrain signals are potential biometric markers in user authentication, complementing existing biometric authentication techniques (such as those based on fingerprint, iris and facial recognition). This article proposes a novel EEG fusion method to examine the reliability and durability of EEG biometric markers across recording sessions. Our hypothesis is that models trained using EEG signals collected during various elicitation protocols can capture generalised brain patterns that pertain personalised information which can improve the durability of biometric systems. Different protocols are likely to produce different responses across brain regions, which can result in more identifiable responses from EEG. In our approach, an end-to-end convolutional neural network (CNN) model is adopted for feature extraction and classification of raw EEG data. The proposed method is evaluated on two EEG datasets which were collected over two separate sessions on different days using multiple different EEG elicitation protocols. Within-session and across-session experiments were conducted. Results for within session experiments showed that CNN models with protocol fusion can achieve similar if not better results than models trained with single protocol. In across-session scenarios, models trained with the proposed protocol fusion approach significantly outperformed single protocol based models. The obtained results illustrate the durability and reliability capabilities of the proposed fusion approach. Essam Soliman Debie, Nour Moustafa, Athanasios V. Vasilakos |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Privacy-Preserved Cyberattack Detection in Industrial Edge of Things (IEoT): A Blockchain-Orchestrated Federated Learning ApproachabstractThe Industrial Internet ofThings (IIoT) plays an essential role in the digital renovation of conventional industries to Industry 4.0. With the connectivity of sensors, actuators, appliances, and other industrial objects, IIoT enables data availability, improved analytics, and automatic control. Thanks to the complex distributed nature, a wide range of stealthy and evolving cyberattacks become a major threat to the trustworthiness and security of IIoT systems. This makes the standard security procedures unable to assure the trustworthiness of IIoT that protect against cyberattacks. As a remedy, this article presents a blockchain-orchestrated edge intelligence (BoEI) framework that integrates an innovative decentralized federated learning (called Fed-Trust) for cyberattack detection in IIoT. In the Fed-Trust, a temporal convolutional generative network is introduced to enable semi-supervised learning from semi-labeled data. BoEI includes reputation-based blockchain to enable decentralized recording and verification of the transactions for guaranteeing the security and privacy of data and gradients. Fog computing is exploited to offload the block mining operation from the edge side thereby improving the overall computation and communication performance of Fed-Trust. Proof of concept simulations using two public datasets validate the robustness and efficiency of the Fed-Trust over the cutting-edge cyberattack detection approaches. Mohamed Abdel-Basset, Nour Moustafa, Hossam Hawash |
IEEE Trans. Ind. Informatics | 2 |
| 2022 | Guest Editorial: AI-Enabled Threat Intelligence and Hunting Microservices for Distributed Industrial IoT SystemabstractIndustrial Internet of Things (IIoT) systems are increasingly found in settings such as factories, smart cities/nations, and healthcare institutions. These systems facilitate the interconnection of automation and data analytics across different industrial technologies, such as cyber-physical systems, Internet of Things (IoT), and cloud and edge computing devices and systems. However, IIoT systems also generate significant volume of data, which can incur significant overheads in processing such data at cloud centers [A1]. Existing IIoT systems may be developed as monolithic architecture, where such a system is deployed as a single solution. In this architectural design, few programming languages can be used to create a single application or process composed of several classes, methods, and packages, in which the entire application is executed in one server irrespective of the application requirements. Nour Moustafa, Kim-Kwang Raymond Choo, Adnan M. Abu-Mahfouz |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | A Blockchain-Enabled Privacy-Preserving Verifiable Query Framework for Securing Cloud-Assisted Industrial Internet of Things SystemsabstractAdvanced Industrial Internet-of-Things (IIoT), such as smart grids, 5G-enabled unmanned aerial vehicles (UAV), and supply chain 4.o, can be used to facilitate smart management. Nevertheless, IIoT systems generate huge amounts of data that need to be outsourced to the cloud for storing and providing real-time search facilities to end-users. Outsourcing IIoT data to a third-party cloud service provider (CSP) introduces several data privacy and integrity issues related to verifying the reliability of users’ queries and aggregated outcomes. In this article, we propose a blockchain-based framework for provisioning a privacy-preserving and verifiable query facility to end-users in IIoT systems. The framework uses blockchain to store IoT data as on-chain data and the cloud to store extensive data (e.g., image) as off-chain data and provisioning search services to users by executing a query in both on-chain and off-chain data and generating an aggregated result. Besides, it introduces a new privacy-preserving query mechanism for ensuring sensitive data privacy during query execution. A data owner encrypts both on-chain and off-chain data in the privacy-preserving query mechanism before sending it to the blockchain and cloud. A CSP can perform search operations on the encrypted on-chain and off-chain data to ensure sensitive data privacy. A multisignature-powered query verification model is also built for the blockchain. The query verification model allows each blockchain node to endorse the query result individually and a user to verify the endorsement of the query result before use. The experiments revealed the high efficiency and scalability of the proposed framework. Mohammad Saidur Rahman 0001, Ibrahim Khalil 0001, Nour Moustafa, Aditya Pribadi Kalapaaking, Abdelaziz Bouras |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | Edge Intelligence: Federated Learning-Based Privacy Protection Framework for Smart Healthcare SystemsabstractFederated learning methods offer secured monitor services and privacy-preserving paradigms to end-users and organisations in the Internet of Things networks such as smart healthcare systems. Federated learning has been coined to safeguard sensitive data, and its global aggregation is often based on a centralised server. This design is vulnerable to malicious attacks and could be breached by privacy attacks such as inference and free-riding, leading to inefficient training models. Besides, uploaded analysing parameters by patients can reveal private information and the threat of direct manipulation by the central server. To address these issues, we present a three-fold Federated Edge Aggregator, the so-called Edge Intelligence, a federated learning-based privacy protection framework for safeguarding Smart Healthcare Systems at the edge against such privacy attacks. We employ an iteration-based Conventional Neural Network (CNN) model and artificial noise functions to balance privacy protection and model performance. A theoretical convergence bound of Edge Intelligence on the trained federated learning model's loss function is also introduced here. We evaluate and compare the proposed framework with the recently established methods using model performance and privacy budget on popular and recent datasets: MNIST, CIFAR10, STL10, and COVID19 chest x-ray. Finally, the proposed framework achieves 90% accuracy and a high privacy rate demonstrating better performance than the baseline technique. Mahmuda Akter, Nour Moustafa, Timothy Lynar, Muhammad Imran Razzak |
IEEE J. Biomed. Health Informatics | 2 |
| 2022 | AI-Driven Synthetic Biology for Non-Small Cell Lung Cancer Drug Effectiveness-Cost Analysis in Intelligent Assisted Medical SystemsabstractAccording to statistics, in the 185 countries' 36 types of cancer, the morbidity and mortality of lung cancer take the first place, and non-small cell lung cancer (NSCLC) accounts for 85% of lung cancer (International Agency for Research on Cancer, 2018), (Bray et al., 2018). Significantly in many developing countries, limited medical resources and excess population seriously affect the diagnosis and treatment of alung cancer patients. The 21st century is an era of life medicine, big data, and information technology. Synthetic biology is known as the driving force of natural product innovation and research in this era. Based on the research of NSCLC targeted drugs, through the cross-fusion of synthetic biology and artificial intelligence, using the idea of bioengineering, we construct an artificial intelligence assisted medical system and propose a drug selection framework for the personalized selection of NSCLC patients. Under the premise of ensuring the efficacy, considering the economic cost of targeted drugs as an auxiliary decision-making factor, the system predicts the drug effectiveness-cost then. The experiment shows that our method can rely on the provided clinical data to screen drug treatment programs suitable for the patient's conditions and assist doctors in making an efficient diagnosis. Liu Chang, Jia Wu 0002, Nour Moustafa, Ali Kashif Bashir, Keping Yu |
IEEE J. Biomed. Health Informatics | 3 |
| 2022 | Federated Intrusion Detection in Blockchain-Based Smart Transportation SystemsabstractWith the integration of the Internet of Things (IoT) in the field of transportation, the Internet of Vehicles (IoV) turned to be a vital method for designing Smart Transportation Systems (STS). STS consist of various interconnected vehicles and transportation infrastructure exposed to cyber intrusion due to the broad usage of software and the initiation of wireless interfaces. This study proposes a federated deep learning-based intrusion detection framework (FED-IDS) to efficiently detect attacks by offloading the learning process from servers to distributed vehicular edge nodes. FED-IDS introduces a context-aware transformer network to learn spatial-temporal representations of vehicular traffic flows necessary for classifying different categories of attacks. Blockchain-managed federated training is presented to enable multiple edge nodes to offer secure, distributed, and reliable training without the need for centralized authority. In the blockchain, miners confirm the distributed local updates from participating vehicles to stop unreliable updates from being deposited on the blockchain. The experiments on two public datasets (i.e., Car-Hacking, TON_IoT) demonstrated the efficiency of FED-IDS against state-of-the-art approaches. It reveals the credibility of securing networks of intelligent transportation systems against cyber-attacks. Mohamed Abdel-Basset, Nour Moustafa, Hossam Hawash, Muhammad Imran Razzak, Karam M. Sallam, Osama M. Elkomy |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | A Blockchain-Based Emergency Message Transmission Protocol for Cooperative VANETabstractThe Industrial Internet of Things (IIoT) is creating a massive impact in a wide range of applications. In addition, with the forthcoming 5G and 6G technologies, vehicular ad-hoc networks will have pioneer advancements. However, security concerns are not well addressed, as vehicular networks should be deployed at a large scale. To address the security concerns, especially to ensure secure emergency message transmission, a blockchain-based protocol is proposed in this paper, where one of the blockchains is to store the authentication information of the vehicle, and another one to store and distribute blockchain services. Experimental analysis revealed that the proposed blockchain-based protocols are superior than the existing ones in terms of several metrics. Nour Moustafa, A. F. M. Suaib Akhter, Muhammad Imran Razzak, Ehsanuzzaman Surid, Adnan Anwar, A. F. M. Shahen Shah, Ahmet Zengin |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | An Enhanced Multi-Stage Deep Learning Framework for Detecting Malicious Activities From Autonomous VehiclesabstractIntelligent Transportation Systems (ITS), particularly Autonomous Vehicles (AVs), are susceptible to safety and security concerns that impend people’s lives. Nothing like manually controlled vehicles, the safekeeping of communications and computing constituents of AVs can be threatened using sophisticated hacking techniques, consequently disrupting AVs from the operative usage in our daily life routines. Once manually controlled vehicles are linked to the Internet, so-called the Internet of Vehicles (IoVs), they would be misused by cyberattacks. In this paper, we present a multi-stage intrusion detection framework to identify intrusions from ITSs and produce low rate of false alarms. The proposed framework can automatically distinguish intrusions in real-time. The proposed framework is based on normal state-based and a deep learning-centered bidirectional Long Short Term Memory (LSTM) architecture to efficiently discover intrusions from the fundamental network gateways and communication networks of AVs. The designed framework is evaluated through two benchmark datasources, that is, the UNSWNB-15 datasource for exterior network communications and the car hacking datasource for in-vehicle communications. The outcomes indicated that the proposed framework achieves high performance that outperforms various current state-of-the-art systems with an accuracy rate of 98.88% for the UNSWNB-15 dataset and 99.11% for the car hacking dataset. Besides, the proposed framework is furthermore capable to detect zero-day (concealed) outbreaks from IoVs networks. Izhar Ahmed Khan, Nour Moustafa, Dechang Pi, Waqas Haider, Bentian Li, Alireza Jolfaei |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | Renewable Energy Re-Distribution via Multiscale IoT for 6G-Oriented Green Highway ManagementabstractWhile recent works on investigating renewable energy sources for powering the highway offer promising solutions for sustainable environments, they are often impeded by unequal distribution of sources across the region due to variations in solar exposure and road intensity that electromagnetically and mechanically generate the energy. By exploiting viable gathering of massive renewable energy data using the Internet of Things (IoT), this paper proposes a framework for improved highway-energy management based on the unmanned aerial vehicle-assisted wireless energy re-distribution of the harvested renewable energy. Combining both massive low-rate sensing with high-speed 6G-envisioned transmission for data aggregation, the IoT architecture is of multi-scale, consisting of: i) global data exchange and analytics for energy mapping, re-distribution planning and forecasting, and ii) local data sensing and processing at individual highway lampposts for micro-energy management. The feasibility of the networked energy system is analyzed via analytical cost-reliability analyses. The cost analysis demonstrates the cost-effectiveness through the lowest Requirement of Energy and Cost of Energy for the setup and maintenance. The reliability analysis reveals the energy plus (E+) feature of the system in certain conditions with enhanced reliability in adverse weathers that impact energy generation. With multi-scale data connectivity to intelligently manage standalone renewable energy, this work puts forward a viable idea of 6G use cases with massively networked energy sensors with a vision of achieving super-connected and intelligence-equipped highways. Md. Arafatur Rahman, Marufa Yeasmin Mukta, A. Taufiq Asyhari, Nour Moustafa, Mohammad N. Patwary, Abu Yousuf, Muhammad Imran Razzak, Brij B. Gupta |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | A Secure and Intelligent Framework for Vehicle Health Monitoring Exploiting Big-Data AnalyticsabstractThe dependency on vehicles is increasing tremendously due to its excellent transport capacity, fast, efficient, flexible, pleasant journey, minimal physical effort, and substantial economic impact. As a result, the demand for smart and intelligent feature enhancement is growing and becoming a prime concern for maximum productivity based on the current perspective. In this case, the Internet of Everything (IoE) is an emerging concept that can play an essential role in the automotive industry by integrating the stakeholders, process, data, and things via networked connections. But the unavailability of intelligent features leads to negligence about proper maintenance of vehicle vulnerable parts, reckless driving and severe accident, lack of instructive driving, and improper decision, which incurred extra expenses for maintenance besides hindering national economic growth. For this, we proposed a conceptual framework for a central VHMS exploiting IoE-driven Multi-Layer Heterogeneous Networks (HetNet) and a machine learning technique to oversee individual vehicle health conditions, notify the respective owner-driver real-timely and store the information for further necessary action. This article transparently portrayed an overview of central VHMS and proposed the taxonomy to achieve such an objective. Subsequently, we unveiled the framework for central VHMS, IoE-driven Multi-tire HetNet, with a secure and trustworthy data collection and analytics system. Finally, anticipating this proposition’s outcome is immense in the automotive sector. It may motivate the researcher to develop a central intelligent and secure vehicular condition diagnostic system to move this sector towards Industry 4.0. Md. Arafatur Rahman, Md. Abdur Rahim, Nour Moustafa, Muhammad Imran Razzak, Mohammad N. Patwary |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Perturbation-enabled Deep Federated Learning for Preserving Internet of Things-based Social NetworksabstractFederated Learning (FL), as an emerging form of distributed machine learning (ML), can protect participants’ private data from being substantially disclosed to cyber adversaries. It has potential uses in many large-scale, data-rich environments, such as the Internet of Things (IoT), Industrial IoT, Social Media (SM), and the emerging SM 3.0. However, federated learning is susceptible to some forms of data leakage through model inversion attacks. Such attacks occur through the analysis of participants’ uploaded model updates. Model inversion attacks can reveal private data and potentially undermine some critical reasons for employing federated learning paradigms. This article proposes novel differential privacy (DP)-based deep federated learning framework. We theoretically prove that our framework can fulfill DP’s requirements under distinct privacy levels by appropriately adjusting scaled variances of Gaussian noise. We then develop a Differentially Private Data-Level Perturbation (DP-DLP) mechanism to conceal any single data point’s impact on the training phase. Experiments on real-world datasets, specifically the social media 3.0, Iris, and Human Activity Recognition (HAR) datasets, demonstrate that the proposed mechanism can offer high privacy, enhanced utility, and elevated efficiency. Consequently, it simplifies the development of various DP-based FL models with different tradeoff preferences on data utility and privacy levels. Sara Salim, Nour Moustafa, Benjamin P. Turnbull, Muhammad Imran Razzak |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2022 | Privacy-preserving big data analytics for cyber-physical systems
Marwa Keshk, Nour Moustafa, Elena Sitnikova, Benjamin P. Turnbull |
Wirel. Networks | 2 |
| 2021 | Hunter in the Dark: Discover Anomalous Network Activity Using Deep Ensemble NetworkabstractMachine learning (ML)-based intrusion detection systems (IDSs) play a critical role in discovering unknown threats in a large-scale cyberspace. They have been adopted as a mainstream hunting method in many organizations, such as financial institutes, manufacturing companies and govern-ment agencies. However, existing designs achieve a high threat detection performance at the cost of a large number of false alarms, leading to alert fatigue. To tackle this issue, in this paper, we propose a neural-network-based defense mechanism named DarkHunter. DarkHunter incorporates both supervised learning and unsupervised learning in the design. It uses a deep ensemble network (trained through supervised learning) to detect anomalous network activities and exploits an unsupervised learning-based scheme to trim off mis-detection results. For each detected threat, DarkHunter can trace to its source and present the threat in its original traffic format. Our evaluations, based on the UNSW-NB15 dataset, show that DarkHunter outperforms the existing ML- based IDSs and is able to achieve a high detection accuracy while keeping a low false positive rate. Shiyi Yang 0001, Nour Moustafa |
QRS | 3 |
| 2021 | A Deep Learning-based Penetration Testing Framework for Vulnerability Identification in Internet of Things EnvironmentsabstractThe Internet of Things (IoT) paradigm has displayed tremendous growth in recent years, resulting in innovations like Industry 4.0 and smart environments that provide improvements to efficiency, management of assets and facilitate intelligent decision making. However, these benefits are offset by considerable cybersecurity concerns that arise due to inherent vulnerabilities, which hinder IoT-based systems' Confidentiality, Integrity, and Availability. Security vulnerabilities can be detected through the application of penetration testing, and specifically, a subset of the information-gathering stage, known as vulnerability identification. Yet, existing penetration testing solutions can not discover zero-day vulnerabilities from IoT environments, due to the diversity of generated data, hardware constraints, and environmental complexity. Thus, it is imperative to develop effective penetration testing solutions for the detection of vulnerabilities in smart IoT environments. In this paper, we propose a deep learning-based penetration testing framework, namely Long Short-Term Memory Recurrent Neural Network-Enabled Vulnerability Identification (LSTM-EVI). We utilize this framework through a novel cybersecurity-oriented testbed, which is a smart airport-based testbed comprised of both physical and virtual elements. The framework was evaluated using this testbed and on real-time data sources. Our results revealed that the proposed framework achieves about 99% detection accuracy for scanning attacks, outperforming other four peer techniques. Nickolaos Koroniotis, Nour Moustafa, Benjamin P. Turnbull, Francesco Schiliro, Praveen Gauravaram, Helge Janicke |
TrustCom | 2 |
| 2021 | DAD: A Distributed Anomaly Detection system using ensemble one-class statistical learning in edge networks
Nour Moustafa, Marwa Keshk, Kim-Kwang Raymond Choo, Timothy Lynar, Seyit Ahmet Çamtepe, Monica T. Whitty |
Future Gener. Comput. Syst. | 1 |
| 2021 | A Deep Blockchain Framework-Enabled Collaborative Intrusion Detection for Protecting IoT and Cloud NetworksabstractThere has been significant research in incorporating both blockchain and intrusion detection to improve data privacy and detect existing and emerging cyberattacks, respectively. In these approaches, learning-based ensemble models can facilitate the identification of complex malicious events and concurrently ensure data privacy. Such models can also be used to provide additional security and privacy assurances during the live migration of virtual machines (VMs) in the cloud and to protect Internet-of-Things (IoT) networks. This would allow the secure transfer of VMs between data centers or cloud providers in real time. This article proposes a deep blockchain framework (DBF) designed to offer security-based distributed intrusion detection and privacy-based blockchain with smart contracts in IoT networks. The intrusion detection method is employed by a bidirectional long short-term memory (BiLSTM) deep learning algorithm to deal with sequential network data and is assessed using the data sets of UNSW-NB15 and BoT-IoT. The privacy-based blockchain and smart contract methods are developed using the Ethereum library to provide privacy to the distributed intrusion detection engines. The DBF framework is compared with peer privacy-preserving intrusion detection techniques, and the experimental outcomes reveal that DBF outperforms the other competing models. The framework has the potential to be used as a decision support system that can assist users and cloud providers in securely migrating their data in a timely and reliable manner. Osama Al-Kadi, Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 2 |
| 2021 | Fair and size-scalable participant selection framework for large-scale mobile crowdsensing
Wei Shen 0005, Muhammad Bilal 0003, Xiaolong Xu 0001, Wan-Chun Dou, Nour Moustafa |
J. Syst. Archit. | 6 |
| 2021 | Two-Stage Deep Learning Framework for Discrimination between COVID-19 and Community-Acquired Pneumonia from Chest CT scans
Mohamed Abdel-Basset, Hossam Hawash, Nour Moustafa, Osama M. Elkomy |
Pattern Recognit. Lett. | 3 |
| 2021 | Novel Deep Learning-Enabled LSTM Autoencoder Architecture for Discovering Anomalous Events From Intelligent Transportation SystemsabstractIntelligent Transportation Systems (ITS), especially Autonomous Vehicles (AVs), are vulnerable to security and safety issues that threaten the lives of the people. Unlike manual vehicles, the security of communications and computing components of AVs can be compromised using advanced hacking techniques, thus barring AVs from the effective use in our routine lives. Once manual vehicles are connected to the Internet, called the Internet of Vehicles (IoVs), it would be exploited by cyber-attacks, like denial of service, sniffing, distributed denial of service, spoofing and replay attacks. In this article, we present a deep learning-based Intrusion Detection System (IDS) for ITS, in particular, to discover suspicious network activity of In-Vehicles Networks (IVN), vehicles to vehicles (V2V) communications and vehicles to infrastructure (V2I) networks. A Deep Learning architecture-based Long-Short Term Memory (LSTM) autoencoder algorithm is designed to recognize intrusive events from the central network gateways of AVs. The proposed IDS is evaluated using two benchmark datasets, i.e., the car hacking dataset for in-vehicle communications and the UNSW-NB15 dataset for external network communications. The experimental results demonstrated that our proposed system achieved over a 99% accuracy for detecting all types of attacks on the car hacking dataset and a 98% accuracy on the UNSW-NB15 dataset, outperforming other eight intrusion detection techniques. Javed Ashraf, Asim D. Bakhshi, Nour Moustafa, Muhammad Hasnat Khurshid, Abdullah Javed, Amin Beheshti |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2021 | An Integrated Framework for Privacy-Preserving Based Anomaly Detection for Cyber-Physical SystemsabstractProtecting Cyber-physical Systems (CPSs) is highly important for preserving sensitive information and detecting cyber threats. Developing a robust privacy-preserving anomaly detection method requires physical and network data about the systems, such as Supervisory Control and Data Acquisition (SCADA), for protecting original data and recognising cyber-attacks. In this paper, a new privacy-preserving anomaly detection framework, so-called PPAD-CPS, is proposed for protecting confidential information and discovering malicious observations in power systems and their network traffic. The framework involves two main modules. First, a data pre-processing module is suggested for filtering and transforming original data into a new format that achieves the target of privacy preservation. Second, an anomaly detection module is suggested using a Gaussian Mixture Model (GMM) and Kalman Filter (KF) for precisely estimating the posterior probabilities of legitimate and anomalous events. The performance of the PPAD-CPS framework is assessed using two public datasets, namely the Power System and UNSW-NB15 dataset. The experimental results show that the framework is more effective than four recent techniques for obtaining high privacy levels. Moreover, the framework outperforms seven peer anomaly detection techniques in terms of detection rate, false positive rate, and computational time. Marwa Keshk, Elena Sitnikova, Nour Moustafa, Jiankun Hu, Ibrahim Khalil 0001 |
IEEE Trans. Sustain. Comput. | 3 |
| 2021 | Generalized Outlier Gaussian Mixture Technique Based on Automated Association Features for Simulating and Detecting Web Application AttacksabstractWeb application attacks constitute considerable security threats to computer networks and end users. Existing threat detection methods are mostly designed on signature-based approaches which cannot recognize zero-day vulnerabilities. Moreover, with the minimal availability of real-world web attack data, the effectiveness of such approaches is limited further. In this paper, we propose an architectural scheme for designing a threat intelligence technique for web attacks to address these challenges through a four-step methodology: 1) collecting web attack data by crawling websites and accumulating network traffic for representing this data as feature vectors; 2) dynamically extracting important features using the Association Rule Mining (ARM) algorithm; 3 ) using these extracted features to simulate web attack data; and 4) proposing a new Outlier Gaussian Mixture (OGM) technique for detecting known as well as zero-day attacks based on the anomaly detection methodology. The performance of the scheme is appraised using two well-known datasets, namely, the Web Attack and UNSW-NB15 datasets. The empirical evaluations demonstrate that the proposed scheme outperforms four other competing machine learning mechanisms in terms of detection rate and false alarm rates on both the original as well as simulated web data. Nour Moustafa, Gaurav Misra, Jill Slay |
IEEE Trans. Sustain. Comput. | 1 |
| 2020 | A Privacy-Preserving Generative Adversarial Network Method for Securing EEG Brain SignalsabstractGenerative adversarial networks (GANs) have recently shown high success in applications such as image and time- series classification. However, those applications are vulnerable to complex hacking scenarios, for example, inference and data poisoning attacks, which would alter or infer sensitive information about systems and users. Protecting Electroencephalographic (EEG) brain signals against illegal disclosure has a great interest these days. In this paper, we propose a privacy-preserving GAN method to generate and classify EEG data effectively. Generating EEG data offers a range of capabilities, including sharing experimental data without infringing user privacy, improving machine learning models for brain-computer interface tasks and restore corrupted data. The proposed GAN model is trained under a differential privacy model to enhance the data privacy level by limiting queries of data from artificial trials that could identify the real participants from their EEG signals. The performance of the proposed method was evaluated using a motor imagery classification task, where real EEG data are augmented with artificially generated samples for training machine learning classifiers. The evaluation was performed on a benchmark EEG data set for nine subjects. The experimental outcomes revealed that the non-private version of the proposed approach could produce high-quality data that significantly improve the motor imagery classification performance. The private version showed lower but comparable performance to the standard models trained on real data only. Essam Soliman Debie, Nour Moustafa, Monica T. Whitty |
IJCNN | 2 |
| 2020 | Privacy-Preserving Techniques for Protecting Large-Scale Data of Cyber-Physical SystemsabstractAs Cyber-Physical Systems (CPSs), such as power and gas networks, generate heterogeneous and large-scale data sources from devices and networks, they need efficient privacy-preserving techniques to protect data and systems from cyber attacks. To safeguard CPSs from potential cyber threats, it is vital to identify vulnerabilities of CPSs' components to prevent Advanced Persistent Threats (APTs) and protect their generated data using privacy-preserving techniques. This paper aims to review the current state of privacy-preserving techniques for protecting CPSs and their networks against cyber attacks. Concepts of Privacy preservation and CPSs are discussed, illustrating CPSs' components and how they could be hacked using cyber and physical hacking scenarios. Then, types of privacy preservation, including perturbation, authentication, machine learning (ML), cryptography and blockchain, are discussed to demonstrate how they would be applied to protect the original data in CPSs and their networks. Finally, we explain existing challenges, solutions and future research directions of privacy preservation in CPSs. Marwa Keshk, Nour Moustafa, Elena Sitnikova, Benjamin P. Turnbull, Dinusha Vatsalan |
MSN | 2 |
| 2020 | Enhancing IoT Anomaly Detection Performance for Federated LearningabstractWhile federated learning (FL) has gained great attention for mobile and Internet of Things (IoT) computing with the benefits of scalable cooperative learning and privacy protection capabilities, there still exist a great deal of technical challenges to make it practically deployable. For instance, the distribution of the training process to a myriad of devices limits the classification performance of machine learning (ML) algorithms, often showing a significantly degraded accuracy compared to centralized learning. In this paper, we investigate the problem of performance limitation under FL and present the benefit of data augmentation with an application of anomaly detection using an IoT dataset. Our initial study reveals that one of the critical reasons for the performance degradation is that each device sees only a small fraction of data (that it generates), which limits the efficacy of the local ML model (constructed by the device). This becomes more critical if the data holds the class imbalance problem, observed not infrequently in practice (e.g., a small fraction of anomalies). Moreover, device heterogeneity with respect to data quantity is an open challenge in FL. Based on these observations, we examine the impact of data augmentation on detection performance in FL settings (both homogeneous and heterogeneous). Our experimental results show that even a simple random oversampling can improve detection performance with manageable learning complexity. Brett Weinger, Jinoh Kim, Alex Sim, Makiya Nakashima, Nour Moustafa, Kesheng Wu |
MSN | 5 |
| 2020 | Data Analytics-enabled Intrusion Detection: Evaluations of ToN IoT Linux DatasetsabstractWith the widespread of Artificial Intelligence (AI)-enabled security applications, there is a need for collecting heterogeneous and scalable data sources for effectively evaluating the performances of security applications. This paper presents the description of new datasets, named ToN_IoT datasets that include distributed data sources collected from Telemetry datasets of Internet of Things (IoT) services, Operating systems datasets of Windows and Linux, and datasets of Network traffic. The paper aims to describe the new testbed architecture used to collect Linux datasets from audit traces of hard disk, memory and process. The architecture was designed in three distributed layers of edge, fog, and cloud. The edge layer comprises IoT and network systems, the fog layer includes virtual machines and gateways, and the cloud layer includes data analytics and visualization tools connected with the other two layers. The layers were programmatically controlled using Software-Defined Network (SDN) and Network-Function Virtualization (NFV) using the VMware NSX and vCloud NFV platform. The Linux ToN_IoT datasets would be used to train and validate various new federated and distributed AI-enabled security solutions such as intrusion detection, threat intelligence, privacy preservation and digital forensics. Various Data analytical and machine learning methods are employed to determine the fidelity of the datasets in terms of examining feature engineering, statistics of legitimate and security events, and reliability of security events. The datasets can be publicly accessed from [1]. Nour Moustafa, Sherif Ahmed |
TrustCom | 1 |
| 2020 | Federated TON_IoT Windows Datasets for Evaluating AI-based Security ApplicationsabstractExisting cyber security solutions have been basically developed using knowledge-based models that often cannot trigger new cyber-attack families. With the boom of Artificial Intelligence (AI), especially Deep Learning (DL) algorithms, those security solutions have been plugged-in with AI models to discover, trace, mitigate or respond to incidents of new security events. The algorithms demand a large number of heterogeneous data sources to train and validate new security systems. This paper presents the description of new datasets, the so-called ToN_IoT, which involve federated data sources collected from Telemetry datasets of IoT services, Operating system datasets of Windows and Linux, and datasets of Network traffic. The paper introduces the testbed and description of TON_IoT datasets for Windows operating systems. The testbed was implemented in three layers: edge, fog and cloud. The edge layer involves IoT and network devices, the fog layer contains virtual machines and gateways, and the cloud layer involves cloud services, such as data analytics, linked to the other two layers. These layers were dynamically managed using the platforms of software-Defined Network (SDN) and Network-Function Virtualization (NFV) using the VMware NSX and vCloud NFV platform. The Windows datasets were collected from audit traces of memories, processors, networks, processes and hard disks. The datasets would be used to evaluate various AI-based cyber security solutions, including intrusion detection, threat intelligence and hunting, privacy preservation and digital forensics. This is because the datasets have a wide range of recent normal and attack features and observations, as well as authentic ground truth events. The datasets can be publicly accessed from this link [1]. Nour Moustafa, Marwa Keshk, Essam Soliman Debie, Helge Janicke |
TrustCom | 1 |
| 2020 | Privacy-Encoding Models for Preserving Utility of Machine Learning Algorithms in Social MediaabstractSocial media has become a vital platform in our daily life, where users can interact with their friends and other people throughout the world. The vast data generated by these platforms is unique in its variety and sensitivity, and although it potentially has significant utility, but also the potential for misuse. Although social media providers apply some existing privacy techniques, such as encryption and anonymization, the techniques cannot achieve a solid level of data privacy while maintaining the highest level of data utility. This paper proposes new Privacy-Encoding (PE) models that contain two-levels of data privacy: 1) data perturbation-based encoding techniques, and 2) data normalization-based scaling techniques. The data perturbation-based encoding techniques involve label encoder and one-hot encoder ones, while data normalization-based scaling techniques include min-max and z-score normalization ones. The aim of the two-levels is to transform original data into perturbed data, along with balancing the high level of data utility using machine learning algorithms. To evaluate the data utility, the proposed models are applied on the adult dataset as well as a simulated social media dataset and the accuracy of the results is compared with several machine learning algorithms. The experiment results reveal that the models could achieve high privacy and utility levels in terms of variance, accuracy and f-measure metrics. Sara Salim, Nour Moustafa, Benjamin P. Turnbull |
TrustCom | 2 |
| 2020 | Densely Connected Residual Network for Attack RecognitionabstractHigh false alarm rate and low detection rate are the major sticking points for unknown threat perception. To address the problems, in the paper, we present a densely connected residual network (Densely-ResNet) for attack recognition. Densely-ResNet is built with several basic residual units, where each of them consists of a series of Conv-GRU subnets by wide connections. Our evaluation shows that Densely-ResNet can accurately discover various unknown threats that appear in edge, fog and cloud layers and simultaneously maintain a much lower false alarm rate than existing algorithms. Peilun Wu, Nour Moustafa, Shiyi Yang 0001 |
TrustCom | 2 |
| 2020 | FGMC-HADS: Fuzzy Gaussian mixture-based correntropy models for detecting zero-day attacks from linux systems
Waqas Haider, Nour Moustafa, Marwa Keshk, Amanda S. Fernandez, Kim-Kwang Raymond Choo |
Comput. Secur. | 2 |
| 2020 | A new network forensic framework based on deep learning for Internet of Things networks: A particle deep framework
Nickolaos Koroniotis, Nour Moustafa, Elena Sitnikova |
Future Gener. Comput. Syst. | 2 |
| 2020 | An Ontological Graph Identification Method for Improving Localization of IP Prefix Hijacking in Network SystemsabstractIP prefix hijacking continues to be a pervasive cyber security threat to the core internet routing infrastructure. The data security of multiple cloud-based services is also susceptible to these threats, due to the high dependency on traditional routing protocols. Although a number of hijacking detection techniques have been recently proposed, no existing system has effectively addressed the problem of detecting malicious transit Autonomous System (AS) services in any detected hijacking occurrences. The ability to locate and isolate malicious services is critical for conducting a necessary mitigation strategy at an early stage, to minimise the impact of the attack, to restore cloud services quickly. In this paper, we propose an effective real-time processing method, so-called Ontological Graph Identification (OGI), for detecting IP prefix hijacking of nodes and suspicious transit nodes caused by the hijacked nodes through ASs. The proposed method is evaluated using the two public datasets of RIPE RIS and RouteView. Experimental results revealed improved performance for the detection of malicious transit nodes compared with peer techniques. It is, therefore, shown that the proposed method has utility in automating the process of investigating nodes with suspicious activities in real network systems. Osama Al-Kadi, Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | A Privacy-Preserving-Framework-Based Blockchain and Deep Learning for Protecting Smart Power NetworksabstractModern power systems depend on cyber-physical systems to link physical devices and control technologies. A major concern in the implementation of smart power networks is to minimize the risk of data privacy violation (e.g., by adversaries using data poisoning and inference attacks). In this article, we propose a privacy-preserving framework to achieve both privacy and security in smart power networks. The framework includes two main modules: a two-level privacy module and an anomaly detection module. In the two-level privacy module, an enhanced-proof-of-work-technique-based blockchain is designed to verify data integrity and mitigate data poisoning attacks, and a variational autoencoder is simultaneously applied for transforming data into an encoded format for preventing inference attacks. In the anomaly detection module, a long short-term memory deep learning technique is used for training and validating the outputs of the two-level privacy module using two public datasets. The results highlight that the proposed framework can efficiently protect data of smart power networks and discover abnormal behaviors, in comparison to several state-of-the-art techniques. Marwa Keshk, Benjamin P. Turnbull, Nour Moustafa, Dinusha Vatsalan, Kim-Kwang Raymond Choo |
IEEE Trans. Ind. Informatics | 3 |
| 2019 | Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset
Nickolaos Koroniotis, Nour Moustafa, Elena Sitnikova, Benjamin P. Turnbull |
Future Gener. Comput. Syst. | 2 |
| 2019 | An Ensemble Intrusion Detection Technique Based on Proposed Statistical Flow Features for Protecting Network Traffic of Internet of ThingsabstractInternet of Things (IoT) plays an increasingly significant role in our daily activities, connecting physical objects around us into digital services. In other words, IoT is the driving force behind home automation, smart cities, modern health systems, and advanced manufacturing. This also increases the likelihood of cyber threats against IoT devices and services. Attackers may attempt to exploit vulnerabilities in application protocols, including Domain Name System (DNS), Hyper Text Transfer Protocol (HTTP) and Message Queue Telemetry Transport (MQTT) that interact directly with backend database systems and client-server applications to store data of IoT services. Successful exploitation of one or more of these protocols can result in data leakage and security breaches. In this paper, an ensemble intrusion detection technique is proposed to mitigate malicious events, in particular botnet attacks against DNS, HTTP, and MQTT protocols utilized in IoT networks. New statistical flow features are generated from the protocols based on an analysis of their potential properties. Then, an AdaBoost ensemble learning method is developed using three machine learning techniques, namely decision tree, Naive Bayes (NB), and artificial neural network, to evaluate the effect of these features and detect malicious events effectively. The UNSW-NB15 and NIMS botnet datasets with simulated IoT sensors' data are used to extract the proposed features and evaluate the ensemble technique. The experimental results show that the proposed features have the potential characteristics of normal and malicious activity using the correntropy and correlation coefficient measures. Moreover, the proposed ensemble technique provides a higher detection rate and a lower false positive rate compared with each classification technique included in the framework and three other state-of-the-art techniques. Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 1 |
| 2019 | A holistic review of Network Anomaly Detection Systems: A comprehensive survey
Nour Moustafa, Jiankun Hu, Jill Slay |
J. Netw. Comput. Appl. | 1 |
| 2019 | Novel Geometric Area Analysis Technique for Anomaly Detection Using Trapezoidal Area Estimation on Large-Scale NetworksabstractThe prevalence of interconnected appliances and ubiquitous computing face serious threats from the hostile activities of network attackers. Conventional Intrusion Detection Systems (IDSs) are incapable of detecting these intrusive events as their outcomes reflect high false positive rates (FPRs). In this paper, we present a novel Geometric Area Analysis (GAA) technique based on Trapezoidal Area Estimation (TAE) for each observation computed from the parameters of the Beta Mixture Model (BMM) for features and the distances between observations. As this GAA-based detection depends on the methodology of anomaly-based detection (ADS), it constructs the areas of normal observations in a normal profile with those of the testing set estimated from the same parameters to recognise abnormal patterns. We also design a scalable framework for handling large-scale networks, and our GAA technique considers a decision engine module in this framework. The performance of our GAA technique is evaluated using the NSL-KDD and UNSW-NB15 datasets. To reduce the high-dimensional data of network connections, we apply the Principal Component Analysis (PCA) and evaluate its influence on the GAA technique. The empirical results show that our technique achieves a higher detection rate and lower FPR with a lower processing time than other competing methods. Nour Moustafa, Jill Slay, Gideon Creech |
IEEE Trans. Big Data | 1 |
| 2019 | Outlier Dirichlet Mixture Mechanism: Adversarial Statistical Learning for Anomaly Detection in the FogabstractCurrent anomaly detection systems (ADSs) apply statistical and machine learning algorithms to discover zero-day attacks, but such algorithms are vulnerable to advanced persistent threat actors. In this paper, we propose an adversarial statistical learning mechanism for anomaly detection, outlier Dirichlet mixture-based ADS (ODM-ADS), which has three new capabilities. First, it can self-adapt against data poisoning attacks that inject malicious instances in the training phase for disrupting the learning process. Second, it establishes a statistical legitimate profile and considers variations from the baseline of the profile as anomalies using a proposed outlier function. Third, to deal with dynamic and large-scale networks such as Internet of Things and cloud and fog computing, we suggest a framework for deploying the mechanism as Software as a Service in the fog nodes. The fog enables the proposed mechanism to concurrently process streaming data at the edge of the network. The ODM-ADS mechanism is evaluated using both NSL-KDD and UNSW-NB15 datasets, whose findings indicate that ODM-ADS outperforms seven other peer algorithms in terms of accuracy, detection rates, false positive rates, and computational time. Nour Moustafa, Kim-Kwang Raymond Choo, Ibrahim Radwan, Seyit Ahmet Çamtepe |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2018 | A Network Forensic Scheme Using Correntropy-Variation for Attack Detection
Nour Moustafa, Jill Slay |
IFIP Int. Conf. Digital Forensics | 1 |
| 2018 | Identification of malicious activities in industrial internet of things based on deep learning models
Muna Al-Hawawreh, Nour Moustafa, Elena Sitnikova |
J. Inf. Secur. Appl. | 2 |