Md Shihabul Islam

dblp:205/9446 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
4since 2021 · last 2024
0000-0001-8929-3003ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorArtificial intelligence and machine learning · 2Databases, data management, data science and information retrieval · 2
YearPublicationVenuePosition
2024 Ensuring End-to-End IoT Data Security and Privacy Through Cloud-Enhanced Confidential Computing
Md Shihabul Islam, Mahmoud Zamani, Kevin W. Hamlen, Latifur Khan, Murat Kantarcioglu
DBSec1
2023 Confidential Execution of Deep Learning Inference at the Untrusted Edge with ARM TrustZone
abstract
This paper proposes a new confidential deep learning (DL) inference system with ARM TrustZone to provide confidentiality and integrity of DL models and data in an untrusted edge device with limited memory. Although ARM TrustZone supplies a strong, hardware-supported trusted execution environment for protecting sensitive code and data in an edge device against adversaries, resource limitations in typical edge devices have raised significant challenges for protecting on-device DL requiring large memory consumption without sacrificing the security and accuracy of the model. The proposed solution addresses this challenge without modifying the protected DL model, thereby preserving the original prediction accuracy. Comprehensive experiments using different DL architectures and datasets demonstrate that inference services for large and complex DL models can be deployed in edge devices with TrustZone with limited trusted memory, ensuring data confidentiality and preserving the original model's prediction exactness.
Md Shihabul Islam, Mahmoud Zamani, Latifur Khan, Kevin W. Hamlen
CODASPY1
2022 GCI: A GPU-Based Transfer Learning Approach for Detecting Cheats of Computer Game
abstract
Cheating in massive multiple online games (MMOGs) adversely affect the game’s popularity and reputation among its users. Therefore, game developers invest large amount of efforts to detect and prevent cheats that provide an unfair advantage to cheaters over other naive users during game play. Particularly, MMOG clients share data with the server during game play. Game developers leverage this data to detect cheating. However, detecting cheats is challenging mainly due to the limited client-side information, along with unknown and complex cheating techniques. In this article, we aim to leverage machine learning-based models to predict cheats over encrypted game traffic during game play. Concretely, network game traffic during game play from each player can be used to determine whether a cheat is employed. A major challenge in developing such a prediction model is the availability of sufficient training data, which is sparingly available in practice. Game traffic obtained from a few known players can be easily labeled. However, if such players are not a good representation of the population (i.e., other players), then a supervised model trained on labeled game traffic from these set of players may not generalize well for the population. Here, we propose a Graphics Processing Unit (GPU) based scalable transfer learning approach to overcome the constraints of limited labeled data. Our empirical evaluation on a popular MMOG demonstrates significant improvement in cheat prediction compared to other competing methods.
Md Shihabul Islam, Swarup Chandra, Latifur Khan, Bhavani Thuraisingham
IEEE Trans. Dependable Secur. Comput.1
2021 BiMorphing: A Bi-Directional Bursting Defense against Website Fingerprinting Attacks
abstract
Network traffic analysis has been increasingly used in various applications to either protect or threaten people, information, and systems. Website fingerprinting is a passive traffic analysis attack which threatens web navigation privacy. It is a set of techniques used to discover patterns from a sequence of network packets generated while a user accesses different websites. Internet users (such as online activists or journalists) may wish to hide their identity and online activity to protect their privacy. Typically, an anonymity network is utilized for this purpose. These anonymity networks such as Tor (The Onion Router) provide layers of data encryption which poses a challenge to the traffic analysis techniques. Although various defenses have been proposed to counteract this passive attack, they have been penetrated by new attacks that proved the ineffectiveness and/or impracticality of such defenses. In this work, we introduce a novel defense algorithm to counteract the website fingerprinting attacks. The proposed defense obfuscates original website traffic patterns through the use of double sampling and mathematical optimization techniques to deform packet sequences and destroy traffic flow dependency characteristics used by attackers to identify websites. We evaluate our defense against state-of-the-art studies and show its effectiveness with minimal overhead and zero-delay transmission to the real traffic.
Khaled Al-Naami, Amir El-Ghamry, Md Shihabul Islam, Latifur Khan, Bhavani Thuraisingham, Kevin W. Hamlen, Mohammed F. Alrahmawy, Magdi Zakria Rashad
IEEE Trans. Dependable Secur. Comput.3
2020 Secure IoT Data Analytics in Cloud via Intel SGX
abstract
The growing adoption of IoT devices in our daily life is engendering a data deluge, mostly private information that needs careful maintenance and secure storage system to ensure data integrity and protection. Also, the prodigious IoT ecosystem has provided users with opportunities to automate systems by interconnecting their devices and other services with rule-based programs. The cloud services that are used to store and process sensitive IoT data turn out to be vulnerable to outside threats. Hence, sensitive IoT data and rule-based programs need to be protected against cyberattacks. To address this important challenge, in this paper, we propose a framework to maintain confidentiality and integrity of IoT data and rule-based program execution. We design the framework to preserve data privacy utilizing Trusted Execution Environment (TEE) such as Intel SGX, and end-to-end data encryption mechanism. We evaluate the framework by executing rule-based programs in the SGX securely with both simulated and real IoT device data.
Md Shihabul Islam, Mustafa Özdayi, Latifur Khan, Murat Kantarcioglu
CLOUD1
2019 Co-Representation Learning Framework For the Open-Set Data Classification
abstract
Deep Neural Network (DNN) has been largely demonstrated to be effective for real-world classification problems. However, such model requires a huge amount of training samples to get more accurate result. When limited samples allowed for the training step, the model may perform weak generalization ability on the test set, especially when the novel/unseen class may occur during the test period (we call it open-set classification). This severely limits its further utility in many real-world large scale applications, such as the open-set image and text classification scenarios. In this paper, we focus on addressing this key challenge by developing a DNN based co-representation learning approach RLCN. It utilizes limited samples for training a model then applies it to classify normal instances and detect the emergence of novel class over time. The key novelty is that we design a weighted pairwise-constraint loss (WPC) function to learn an enhanced generalization and robust feature embedding, where the intra-class (same class) compactness and inter-class (different class) separation are achieved. Moreover, we apply the temperature scaling scheme on the softmax function to replace traditional softmax output in our open-world classifier to achieve the classification and novel class detection simultaneously. Our extensive empirical evaluation on benchmark datasets demonstrate the effectiveness of our framework compared to other competing techniques.
Zhuoyi Wang, Yu Lin 0002, Yigong Wang, Md Shihabul Islam, Latifur Khan
IEEE BigData5
2018 GCI: A Transfer Learning Approach for Detecting Cheats of Computer Game
abstract
Cheating in massive multiple online games (MMOGs) adversely affect the game's popularity and reputation among its users. Therefore, game developers invest large amount of efforts to detect and prevent cheats that provide an unfair advantage to cheaters over other naive users during game play. Particularly, MMOG clients share data with the server during game play. Game developers leverage this data to detect cheating. However, detecting cheats is challenging mainly due to the limited client-side information, along with unknown and complex cheating techniques. In this paper, we aim to leverage machine learning based models to predict cheats over encrypted game traffic during game play. Concretely, network game traffic during game play from each player can be used to determine whether a cheat is employed. A major challenge in developing such a prediction model is the availability of sufficient training data, which is sparingly available in practice. Game traffic obtained from a few known players can be easily labeled. However, if such players are not a good representation of the population (i.e., other players), then a supervised model trained on labeled game traffic from these set of players may not generalize well for the population. Here, we propose a scalable transfer learning approach to overcome the constraints of limited labeled data. Our empirical evaluation on a popular MMOG demonstrates significant improvement in cheat prediction compared to other competing methods.
Md Shihabul Islam, Swarup Chandra, Latifur Khan, Bhavani Thuraisingham
IEEE BigData2