EDBT 2026 Demo / reviewers in the wild / expert
Mehmet Demirci
dblp:20/2310
· DBLP profile ↗
20ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0002-1088-5215ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 2 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DeepSpect: An RF spectrogram-based deep learning approach for near-real-time attack detection in FANETs
Cengizhan Yapicioglu, Sedef Demirci, Mehmet Demirci |
Ad Hoc Networks | 3 |
| 2025 | HELP4DNS: Leveraging the programmable data plane for effective and robust defense against DDoS attacks on DNS
Mehmet Emin Sahin, Mehmet Demirci |
J. Netw. Comput. Appl. | 2 |
| 2023 | ConPoolUBF: Connection pooling and updatable Bloom filter based SYN flood defense in programmable data planes
Mehmet Emin Sahin, Mehmet Demirci |
Comput. Networks | 2 |
| 2023 | RAIDS: Robust autoencoder-based intrusion detection system model against adversarial attacks
Alper Sarikaya 0002, Banu Gunel, Mehmet Demirci |
Comput. Secur. | 3 |
| 2022 | Design and evaluation of adaptive deep learning models for weather forecasting
Nawaf Abdulla, Mehmet Demirci, Suat Özdemir |
Eng. Appl. Artif. Intell. | 2 |
| 2022 | GRU-GBM: A combined intrusion detection model using LightGBM and gated recurrent unitabstractAbstract Due to the increasing sophistication of cyber‐attacks, intrusion detection systems need to be improved constantly. Each machine learning classifier has different advantages against intrusion detection and combining the advantages of different classifiers increases detection rates. In this study, we combine a machine learning classifier with a deep learning model to propose a new approach called GRU‐GBM. The LightGBM gradient boosting machine framework is used for feature selection, and each feature in the dataset is evaluated by a second LightGBM classifier to determine the optimal feature set using a novel threshold‐based approach. After the selection of the feature set, a gated recurrent unit is used for attack detection by a recurrent neural network model. Besides, different training/testing ratios (60/40–70/30) are chosen for comparison of GRU‐GBM accuracy. The proposed combined model achieved 76.61% and 93.65% overall accuracy in multi‐class experiments conducted with the UNSW‐NB15 and LITNET‐2020 datasets, respectively. Lastly, the GRU‐GBM model is compared to other machine learning models. The overall accuracy result is tested with a non‐parametric Friedman test to determine the significance of the results. The test result shows that there is enough evidence that the accuracy of the GRU‐GBM classifier is statistically significant. Alper Sarikaya 0002, Banu Gunel, Mehmet Demirci |
Expert Syst. J. Knowl. Eng. | 3 |
| 2021 | Adaptive Learning on Fog-Cloud Collaborative Architecture for Stream Data ProcessingabstractRecently, learning from continuously evolving streaming data attracts many researchers, especially when this data is inclined to change trends regularly (i.e. concept drift). Unluckily, conventional mining techniques and algorithms are proved inadequate to solve this problem, in which the model’s performance degrades in stationary data, let alone in the case of data streams. Correspondingly, adjusting the model manually and constantly is ineffective, and with the current growth of the data size, it becomes impractical as well. However, automatic adaptive learning methods and algorithms could be a good solution, but they are seldom exploited in IoT business applications to address this issue. To that end, we aim to tackle the problem of concept drift occurs in time-series streaming data on IoT applications, in general, meteorology prediction, in specific. And taking into account the rapidly growing structure of fog-cloud computing, we attempt to leverage the powerful computation of the cloud layer as well as the closeness to IoT devices of the fog layer to design and implement a cooperative fog-cloud architecture in order to produce a faster and more accurate model. Our main objective is to obtain high performance and low latency, as these are the key requirements for real-time or nearly real-time data processing on IoT applications. The experimental findings have confirmed the study’s hypothesis, where the adaptive model on the suggested cooperative fog-cloud architecture reduces both the error of prediction by 20% and the overall time for training the model by almost 41% compared to the baseline model. Nawaf Abdulla, Mehmet Demirci, Suat Özdemir |
ISNCC | 2 |
| 2021 | Citadel: Cyber threat intelligence assisted defense system for software-defined networks
Özgür Yürekten, Mehmet Demirci |
Comput. Networks | 2 |
| 2021 | Security analysis of SDN controller-based DHCP services and attack mitigation with DHCPguard
Mevlut Serkan Tok, Mehmet Demirci |
Comput. Secur. | 2 |
| 2021 | SDN-based cyber defense: A survey
Özgür Yürekten, Mehmet Demirci |
Future Gener. Comput. Syst. | 2 |
| 2019 | DoS Attack Detection using Packet Statistics in SDNabstractDenial-of-service (DoS) attacks targeting the controller in software-defined networks (SDN) are dangerous due to the importance of the controller. In this paper, we characterize the effects of flooding attacks in SDN and discuss potential countermeasures. We concentrate on the controller-side effects of flooding attacks and present our experimental results on how packet-in message counts change in a simulation scenario. Our results imply that differentiating hosts based on only packet-in counts may be misleading for detecting attackers. Instead, packet-in to transmitted packet count ratio is better for distinguishing attackers from normal users. In addition, we measure fairness values with different attacker counts. Our results show that Jain's index is better than entropy in terms of detecting anomaly in our simulation environment. We leave utilizing fairness values to better handle packet-in requests as a future study. Nail Goksel, Mehmet Demirci |
ISNCC | 2 |
| 2018 | Optimal Placement of Virtual Security Functions to Minimize Energy ConsumptionabstractNFV (Network Functions Virtualization) is one of the latest promising technologies making networks more flexible, controllable, cost-efficient and innovative. NFV is being utilized extensively for providing cutting edge networking solutions, including virtual cyber security functions. Functions virtualized with NFV such as firewall, deep packet inspection, intrusion detection systems etc. can reside as applications in the network architecture. Determining the deployment locations of these functions in the network is an important research challenge due to the necessity of achieving different operational objectives such as minimizing latency, network load, cost or energy consumption etc. while meeting cyber security requirements. Among these objectives, optimizing the energy consumption of a network is of vital importance to reduce operating expenses. In this study, we propose an ILP (Integer Linear Programming) model for placing virtualized cyber security functions in a network with the objective of minimizing server energy consumption. We implement and test our model on two different network topologies. Experimental results show that our model can reduce energy consumption significantly while providing cyber security at the desired level. Sedef Demirci, Mehmet Demirci, Seref Sagiroglu |
ISNCC | 2 |
| 2015 | A Survey of Machine Learning Applications for Energy-Efficient Resource Management in Cloud Computing EnvironmentsabstractEnsuring energy efficiency in data centers is a crucial objective in modern cloud computing because it reduces operating costs and complies with the goals of green computing. Researchers strive to develop optimal policies for resource management in the cloud, which has many components such as virtual machine placement, task scheduling, workload consolidation, and so on. Machine learning has a major role to play in these efforts. In this paper, we provide a detailed survey of recent works in the literature which have employed machine learning (ML) to offer solutions for energy efficiency in cloud computing environments. We also present a comparative classification of the proposed methods. Furthermore, we enrich this survey by studying non-ML proposals to energy conservation in data centers, and also how ML has been applied towards other objectives in the cloud. Mehmet Demirci |
ICMLA | 1 |
| 2015 | A Review of Machine Learning Solutions to Denial-of-Services Attacks in Wireless Sensor NetworksabstractWireless sensor networks (WSNs) are used in various fields where remote data collection is necessary, such as environment and habitat monitoring, military applications, smart homes, traffic control, and health monitoring etc. Since WSNs play a crucial role in various domains and the sensors are constrained by resources, they are vulnerable to different types of attacks. One of the main attack types that threaten WSNs is Denial-of-Service (DoS) attacks. DoS attacks can be carried out at various layers of the network architecture. In this paper, we review the DoS attacks at each layer of TCP/IP protocol stack. Among them we focus on the network layer attacks because they are more diverse than other layer attacks. We review a number of studies proposing machine learning solutions pertaining to network layer DoS attacks in WSNs. We also provide some comparative conclusions to aid researchers studying in this field. Sedef Gunduz, Bilgehan Arslan, Mehmet Demirci |
ICMLA | 3 |
| 2014 | Design and analysis of techniques for mapping virtual networks to software-defined network substrates
Mehmet Demirci, Mostafa H. Ammar |
Comput. Commun. | 1 |
| 2014 | Problem Localization and Quantification Using Formal Evidential Reasoning for Virtual NetworksabstractOverlay (virtual) networks are mainly used to improve Internet reliability and facilitate a rapid deployment of new services. However, in order for overlay services to adapt to dynamic network conditions in a timely manner, efficient diagnosis of performance problems is required. Existing overlay diagnosis approaches assume extensive knowledge about the network and require invasive monitoring sensors or active measurements. In this paper, we propose a novel diagnosis technique to localize performance anomalies and determine the packet loss in each network component. Our approach is purely based on packet loss observations at the end-points to reason about the loss location and severity in the network without any active probing or sensor deployment. We formulate the problem as a constraint-satisfaction problem using network loss properties and end-user observations. Our diagnosis is robust against insufficient observations or malicious end-user participation. We evaluate our approach extensively using simulation and experimentation and demonstrate the accuracy, effectiveness, and scalability of our approach under various network sizes, participation ratio, and malicious observation ratio. Fida Gillani, Mehmet Demirci, Ehab Al-Shaer, Mostafa H. Ammar |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2013 | Overlay network placement for diagnosabilityabstractOverlay networks have become an effective method to help overcome the limitations of the Internet in the last decade. Overlays must be monitored for various kinds of problems so that efficient performance can be sustained. An overlay's topology and placement on the substrate have a considerable effect on the level of difficulty in monitoring it. In this paper, we study the problem of placing overlay networks onto the substrate in a way that makes it easier to detect and localize faults, in other words, improves their diagnosability. Overlay network fault diagnosis is especially challenging because of their construction as virtual networks on top of a network substrate. We give a practical definition of diagnosability, and develop an overlay assignment algorithm that aims to optimize overlay placement for the ease and quickness of fault diagnosis. We evaluate the efficiency of this algorithm using an existing passive fault diagnosis scheme, and show that we are able to improve diagnosability without placing a significant strain on the network. We also analyze diagnosability in situations where traffic is sufficient for passive measurements on a percentage of paths rather than the whole network, and study how to augment passive diagnosis with selective active probing in order to raise diagnosability to a desired level. Mehmet Demirci, Fida Gillani, Mostafa H. Ammar, Ehab Al-Shaer |
GLOBECOM | 1 |
| 2012 | Fine-grain diagnosis of overlay performance anomalies using end-point network experiences
Fida Gillani, Ehab Al-Shaer, Mostafa H. Ammar, Mehmet Demirci |
CNSM | 4 |
| 2010 | Fair Allocation of Substrate Resources among Multiple Overlay NetworksabstractOverlay networks are becoming prevalent in today's networking environment. We consider scenarios where substrate resources are primarily consumed by many overlay networks placed on top of the substrate. We focus on the fair and efficient allocation of substrate link bandwidth among competing overlays. We adapt various existing fairness definitions to this scenario and define a metric to evaluate the fairness of an allocation in a multi-overlay setting. We also examine the effect of routing decisions on resource allocation, and discuss methods to deviate from shortest-path routing in the substrate in order to achieve higher rates and increased fairness for the overlays. We demonstrate that substrate networks can better meet overlay demands when a combination of fair allocation algorithms and intelligent routing decisions is employed. Mehmet Demirci, Mostafa H. Ammar |
MASCOTS | 1 |
| 2009 | Multi-layer Monitoring of Overlay Networks
Mehmet Demirci, Samantha Lo, Srinivasan Seetharaman, Mostafa H. Ammar |
PAM | 1 |