EDBT 2026 Demo / reviewers in the wild / expert
Mustafa Abdallah
dblp:184/3248
· DBLP profile ↗
11ranked-venue papers
4as first author
11since 2021 · last 2026
0000-0002-9554-9260ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 7 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Auto-Sec: Meta-Learning for Automated Efficient Security Resource Allocation on Attack GraphsabstractCybersecurity threats rapidly affect interdependent systems, making effective defense strategies critical. While several resource allocation frameworks have been proposed, selecting the optimal allocation strategy remains challenging due to the time-consuming nature of naïve and optimization-based methods. This research introduces a meta-learning framework to automatically select the most suitable resource allocation strategy based on system's characteristics. The approach models system vulnerabilities using attack graphs and benchmarks multiple graph-theoretic allocation strategies based on asset ranking. Node features are extracted using Random Walks (RWs) with negative sampling and Stochastic Gradient Descent (SGD). A tabular dataset is constructed using these features and labeled with the optimal allocation strategy. Ten classifiers are trained to predict the best strategy for unseen data. The framework is validated on both real-world and synthetic graphs, outperforming five baselines (including ARGOSMART, ISAC, and Global Best) in security improvement. Using RWs embeddings, our framework outperforms four graph neural network baselines, achieving the highest mean rank. Our model improves security by 42.10% under uniform investments and 43.79% under random investment. We also show that reducing embedding size from 256 to 64 increases security gains. The full implementation is publicly available for further research. Mohammad Ryiad Al-Eiadeh, Mustafa Abdallah |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | A comparative analysis of DNN-based white-box explainable AI methods in network securityabstractAbstract New research focuses on creating artificial intelligence (AI) solutions for network intrusion detection systems (NIDS), drawing its inspiration from the ever-growing number of intrusions on networked systems, increasing its complexity and intelligibility. Hence, the use of explainable AI (XAI) techniques in real-world intrusion detection systems comes from the requirement to comprehend and elucidate black-box AI models to security analysts. In an effort to meet such requirements, this paper focuses on applying and evaluating white-box XAI techniques (particularly LRP, IG, and DeepLift) for NIDS via an end-to-end framework for neural network models, using three widely used network intrusion datasets (NSL-KDD, CICIDS-2017, and RoEduNet-SIMARGL2021), assessing its global and local scopes, and examining six distinct assessment measures (descriptive accuracy, sparsity, stability, robustness, efficiency, and completeness). We also compare the performance of white-box XAI methods with black-box XAI methods. The results show that using white-box XAI techniques scores high in robustness and completeness, which are crucial metrics for IDS. Moreover, the source codes for the programs developed for our XAI evaluation framework are available to be improved and used by the research community. Osvaldo Arreche, Mustafa Abdallah |
EURASIP J. Inf. Secur. | 2 |
| 2025 | CBDRA-IS: Centrality-Based Defense Resource Allocation for Securing Interdependent SystemsabstractInterdependent systems, with multiple interconnected assets, face escalating cybersecurity threats from external attackers. This article explores security decision-making, operating on complex interdependent systems and proposes a security resource allocation methodology to enhance their proactive security. Using attack graphs, we model vulnerabilities and propose different defense mechanisms integrating different network analysis algorithms, including degree, betweenness, and harmonic centralities, TrustRank, and Katz centrality. We introduce Average Based Node Ranking (ABNR) to average ranks from these methods. The resource allocation methods leverage four different graph-theoretic methods. Each ranking algorithm is combined with these four allocation techniques. Our methods show low sensitivity to simultaneous attacks on interdependent systems. We validate our framework using 11 attack graphs representing real-world systems, measuring security improvements against four well-known allocation algorithms: behavioral decision-making, defense-in-depth, risk-based defense, and min-cut. Our framework outperformed the baselines in most cases, with superior outcomes confirmed by the Friedman statistical test. We show that the main components in our framework have low-time overhead. We also evaluate our framework against multi-stage attacks and cascading failures Our framework enhances security decision-making across different scenarios, including top-1 and all attack paths for different attacks. We release the implementation of our resource allocation methodology to the research community Mohammad Ryiad Al-Eiadeh, Mustafa Abdallah |
ACM Trans. Priv. Secur. | 2 |
| 2025 | Evaluation-free Time-series Forecasting Model Selection via Meta-learningabstractTime-series forecasting models are invariably used in a variety of domains for crucial decision-making. Traditionally these models are constructed by experts with considerable manual effort. Unfortunately, this approach has poor scalability while generating accurate forecasts for new datasets belonging to diverse applications. Without access to skilled domain-knowledge, one approach is to train all the models on the new time-series data and then select the best one. However, this approach is nonviable in practice. In this work, we develop techniques for fast automatic selection of the best forecasting model for a new unseen time-series dataset, without having to first train (or evaluate) all the models on the new time-series data to select the best one. In particular, we develop a forecasting meta-learning approach called AutoForecast that allows for the quick inference of the best time-series forecasting model for an unseen dataset. Our approach learns both forecasting models’ performances over time horizon of the same dataset and task similarity across different datasets. The experiments demonstrate the effectiveness of the approach over state-of-the-art (SOTA) single and ensemble methods and several SOTA meta-learners (adapted to our problem) in terms of selecting better forecasting models (i.e., 2 \(\times\) gain) for unseen tasks for univariate and multivariate testbeds. AutoForecast has also significant reduction in inference time compared to the naïve approach (doing inference using all possible models and then selecting the best one), with median of 42 \(\times\) across the two testbeds. We release our meta-learning database corpus (348 datasets), performances of the 322 forecasting models on the database corpus, meta-features, and source codes for the community to access them for forecasting model selection and to build on them with new datasets and models which can help advance automating time-series forecasting problem. In our released database corpus, we unveil new traces of Adobe computing cluster usage for production workloads. Mustafa Abdallah, Ryan Rossi, Kanak Mahadik, Sungchul Kim, Handong Zhao, Saurabh Bagchi |
ACM Trans. Knowl. Discov. Data | 1 |
| 2024 | A Quantal Response Analysis of Simultaneous Multi-Target Attacker-Defender Security GamesabstractModern systems, under the management of human decision-makers, confront rapidly increasing cybersecurity threats. This paper considers security decision-making within these complex modern systems managed by human defender. The defender has responsibility for safeguarding a specific set of assets with heterogeneous loss valuations against an external attacker. These assets are associated with probabilities that represent the likelihood of a successful attack, which can be reduced through security investments by the defender and can be increased via attacker’s investments. Our approach involves modeling these systems using simultaneous game-theoretic framework, accounting for the impact of bounded rationality and imperfect best-response behavior—as frequently observed in human decision-making within the domains of behavioral economics and psychology. We first establish the existence of a quantal response equilibrium in our security games. Subsequently, we analyze the effects of this type of bounded rationality in terms of the expected cost of the defender. To assess our models, we employ a representative system and compare the game-theoretic optimal investment strategies under those derived from a quantal response equilibrium standpoint. We also investigate the influence of various system parameters on the overall security level (expected security cost) of this system. Md. Reya Shad Azim, Mustafa Abdallah |
NOMS | 2 |
| 2024 | GeniGraph: A genetic-based novel security defense resource allocation method for interdependent systems modeled by attack graphs
Mohammad Ryiad Al-Eiadeh, Mustafa Abdallah |
Comput. Secur. | 2 |
| 2022 | AutoForecast: Automatic Time-Series Forecasting Model SelectionabstractIn this work, we develop techniques for fast automatic selection of the best forecasting model for a new unseen time-series dataset, without having to first train (or evaluate) all the models on the new time-series data to select the best one. In particular, we develop a forecasting meta-learning approach called AutoForecast that allows for the quick inference of the best time-series forecasting model for an unseen dataset. Our approach learns both forecasting models performances over time horizon of same dataset and task similarity across different datasets. The experiments demonstrate the effectiveness of the approach over state-of-the-art (SOTA) single and ensemble methods and several SOTA meta-learners (adapted to our problem) in terms of selecting better forecasting models (i.e., 2X gain) for unseen tasks for univariate and multivariate testbeds. Mustafa Abdallah, Ryan Rossi, Kanak Mahadik, Sungchul Kim, Handong Zhao, Saurabh Bagchi |
CIKM | 1 |
| 2022 | TASHAROK: Using Mechanism Design for Enhancing Security Resource Allocation in Interdependent SystemsabstractWe consider interdependent systems managed by multiple defenders that are under the threat of stepping-stone attacks. We model such systems via game-theoretic models and incorporate the effect of behavioral probability weighting that is used to model biases in human decision-making, as descended from the field of behavioral economics. We then incorporate into our framework called TASHAROK, two types of tax-based mechanisms for such interdependent security games where the central regulator incentivizes defenders to invest well in securing their assets so as to achieve the socially optimal outcome. We first show that due to the nature of our interdependent security game, no reliable tax-based mechanism can incentivize the socially optimal investment profile while maintaining a weakly balanced budget. We then show the effect of behavioral probability weighting bias on the amount of taxes paid by defenders, and prove that higher biases make defenders pay more taxes under the two mechanisms. We then explore voluntary participation in tax-based mechanisms. To evaluate our mechanisms, we use four representative real-world interdependent systems where we compare the game-theoretic optimal investments to the socially optimal investments under the two mechanisms. We show that the mechanisms yield higher decrease in the social cost for behavioral decision-makers compared to rational decision-makers. Mustafa Abdallah, Daniel Woods, Parinaz Naghizadeh Ardabili, Issa M. Khalil, Timothy N. Cason, Shreyas Sundaram, Saurabh Bagchi |
SP | 1 |
| 2022 | DAG-based Task Orchestration for Edge ComputingabstractEdge computing promises to exploit underlying computation resources closer to users to help run latency-sensitive applications such as augmented reality and video analytics. However, one key missing piece has been how to incorporate personally owned, unmanaged devices into a usable edge computing system. The primary challenges arise due to the heterogeneity, lack of interference management, and unpredictable availability of such devices. In this paper we propose an orchestration framework IBDASH, which orchestrates application tasks on an edge system that comprises a mix of commercial and personal edge devices. IBDASH targets reducing both end-to-end latency of execution and probability of failure for applications that have dependency among tasks, captured by directed acyclic graphs (DAGs). IBDASH takes memory constraints of each edge device and network bandwidth into consideration. To assess the effectiveness of IBDASH, we run real application tasks on real edge devices with widely varying capabilities. We feed these measurements into a simulator that runs IBDASH at scale. Compared to three state-of-the-art edge orchestration schemes and two intuitive baselines, IBDASH reduces the end-to-end latency and probability of failure, by 14% and 41% on average respectively. The main takeaway from our work is that it is feasible to combine personal and commercial devices into a usable edge computing platform, one that delivers low and predictable latency and high availability. Xiang Li 0226, Mustafa Abdallah, Shikhar Suryavansh, Mung Chiang, Kwang Taik Kim, Saurabh Bagchi |
SRDS | 2 |
| 2021 | Morshed: Guiding Behavioral Decision-Makers towards Better Security Investment in Interdependent SystemsabstractWe model the behavioral biases of human decision-making in securing interdependent systems and show that such behavioral decision-making leads to a suboptimal pattern of resource allocation compared to non-behavioral (rational) decision-making. We provide empirical evidence for the existence of such behavioral bias model through a controlled subject study with 145 participants. We then propose three learning techniques for enhancing decision-making in multi-round setups. We illustrate the benefits of our decision-making model through multiple interdependent real-world systems and quantify the level of gain compared to the case in which the defenders are behavioral. We also show the benefit of our learning techniques against different attack models. We identify the effects of different system parameters (e.g., the defenders' security budget availability and distribution, the degree of interdependency among defenders, and collaborative defense strategies) on the degree of suboptimality of security outcomes due to behavioral decision-making. Mustafa Abdallah, Daniel Woods, Parinaz Naghizadeh Ardabili, Issa M. Khalil, Timothy N. Cason, Shreyas Sundaram, Saurabh Bagchi |
AsiaCCS | 1 |
| 2021 | Context-Aware Collaborative Intelligence With Spatio-Temporal In-Sensor-Analytics for Efficient Communication in a Large-Area IoT TestbedabstractDecades of continuous scaling has reduced the energy of unit computing to virtually zero, while energy-efficient communication has remained the primary bottleneck in achieving fully energy-autonomous Internet-of-Things (IoT) nodes. This article presents and analyzes the tradeoffs between the energies required for communication and computation in a wireless sensor network, deployed in a mesh architecture over a 2400-acre university campus, and is targeted toward multisensor measurement of temperature, humidity and water nitrate concentration for smart agriculture. Several scenarios involving in-sensor analytics (ISA), collaborative intelligence (CI), and context-aware switching (CAS) of the cluster head during CI has been considered. A real-time co-optimization algorithm has been developed for minimizing the energy consumption in the network, hence maximizing the overall battery lifetime. Measurement results show that the proposed ISA consumes ≈ 467× lower energy as compared to traditional Bluetooth low energy (BLE) communication, and ≈ 69500× lower energy as compared with long-range (LoRa) communication. When the ISA is implemented in conjunction with LoRa, the lifetime of the node increases from a mere 4.3 h to 66.6 days with a 230-mAh coin cell battery, while preserving >99% of the total information. The CI and CAS algorithms help in extending the worst case node lifetime by an additional 50%, thereby exhibiting an overall network lifetime of ≈ 104 days, which is >90% of the theoretical limits as posed by the leakage current present in the system, while effectively transferring information sampled every second. A Web-based monitoring system was developed to continuously archive the measured data, and for reporting real-time anomalies. Baibhab Chatterjee, Dong-Hyun Seo, Shramana Chakraborty, Shitij Avlani, Xiaofan Jiang 0002, Heng Zhang 0016, Mustafa Abdallah, Nithin Raghunathan, Charilaos Mousoulis, Ali Shakouri, Saurabh Bagchi, Dimitrios Peroulis, Shreyas Sen |
IEEE Internet Things J. | 7 |