Taha Belkhouja

dblp:211/8999 · DBLP profile ↗
← Back
19ranked-venue papers
12as first author
12since 2021 · last 2025
0000-0001-8749-6632ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 8 · 4 first-author · 8 since 2021Systems, architecture and hardware · 5 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 4 since 2021Computer networks · 3 · 3 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Sensor-Aware Data Imputation for Time-Series Machine Learning on Low-Power Wearable Devices
abstract
Wearable devices that have low-power sensors, processors, and communication capabilities are gaining wide adoption in several health applications. The machine learning algorithms on these devices assume that data from all sensors are available during runtime. However, data from one or more sensors may be unavailable due to energy or communication challenges. This loss of sensor data can result in accuracy degradation of the application. Prior approaches to handle missing data, such as generative models or training multiple classifiers for each combination of missing sensors are not suitable for low-energy wearable devices due to their high overhead at runtime. In contrast to prior approaches, we present an energy-efficient approach, referred to as Sensor-Aware iMputation (SAM), to accurately impute missing data at runtime and recover application accuracy. SAM first uses unsupervised clustering to obtain clusters of similar sensor data patterns. Next, it learns inter-relationship between clusters to obtain imputation patterns for each combination of clusters using a principled sensor-aware search algorithm. Using sensor data for clustering before choosing imputation patterns ensures that the imputation is aware of sensor data observations. Experiments on seven diverse wearable sensor-based time-series datasets demonstrate that SAM is able to maintain accuracy within 5% of the baseline with no missing data when one sensor is missing. We also compare SAM against generative adversarial imputation networks (GAIN), transformers, and k-nearest neighbor methods. Results show that SAM outperforms all three approaches on average by more than 25% when two sensors are missing with negligible overhead compared to the baseline.
Dina Hussein, Taha Belkhouja, Ganapati Bhat, Janardhan Rao Doppa
ACM Trans. Design Autom. Electr. Syst.2
2024 Energy-Efficient Missing Data Imputation in Wearable Health Applications: A Classifier-aware Statistical Approach
Dina Hussein, Taha Belkhouja, Ganapati Bhat, Janardhan Rao Doppa
IJCAI2
2024 Conformal Prediction for Class-wise Coverage via Augmented Label Rank Calibration
abstract
Conformal prediction (CP) is an emerging uncertainty quantification framework that allows us to construct a prediction set to cover the true label with a pre-specified marginal or conditional probability. Although the valid coverage guarantee has been extensively studied for classification problems, CP often produces large prediction sets which may not be practically useful. This issue is exacerbated for the setting of class-conditional coverage on imbalanced classification tasks with many and/or imbalanced classes. This paper proposes the Rank Calibrated Class-conditional CP (RC3P) algorithm to reduce the prediction set sizes to achieve class-conditional coverage, where the valid coverage holds for each class. In contrast to the standard class-conditional CP (CCP) method that uniformly thresholds the class-wise conformity score for each class, the augmented label rank calibration step allows RC3P to selectively iterate this class-wise thresholding subroutine only for a subset of classes whose class-wise top-$k$ error is small. We prove that agnostic to the classifier and data distribution, RC3P achieves class-wise coverage. We also show that RC3P reduces the size of prediction sets compared to the CCP method. Comprehensive experiments on multiple real-world datasets demonstrate that RC3P achieves class-wise coverage and $26.25\\%$ $\downarrow$ reduction in prediction set sizes on average.
Yuanjie Shi, Subhankar Ghosh, Taha Belkhouja, Janardhan Rao Doppa, Yan Yan 0006
NeurIPS3
2024 Out-of-distribution Detection in Time-series Domain: A Novel Seasonal Ratio Scoring Approach
abstract
Safe deployment of time-series classifiers for real-world applications relies on the ability to detect the data that is not generated from the same distribution as training data. This task is referred to as out-of-distribution (OOD) detection. We consider the novel problem of OOD detection for the time-series domain. We discuss the unique challenges posed by time-series data and explain why prior methods from the image domain will perform poorly. Motivated by these challenges, this article proposes a novel Seasonal Ratio Scoring (SRS) approach. SRS consists of three key algorithmic steps. First, each input is decomposed into class-wise semantic component and remainder. Second, this decomposition is employed to estimate the class-wise conditional likelihoods of the input and remainder using deep generative models. The seasonal ratio score is computed from these estimates. Third, a threshold interval is identified from the in-distribution data to detect OOD examples. Experiments on diverse real-world benchmarks demonstrate that the SRS method is well-suited for time-series OOD detection when compared to baseline methods.
Taha Belkhouja, Yan Yan 0006, Janardhan Rao Doppa
ACM Trans. Intell. Syst. Technol.1
2023 Improving Uncertainty Quantification of Deep Classifiers via Neighborhood Conformal Prediction: Novel Algorithm and Theoretical Analysis
abstract
Safe deployment of deep neural networks in high-stake real-world applications require theoretically sound uncertainty quantification. Conformal prediction (CP) is a principled framework for uncertainty quantification of deep models in the form of prediction set for classification tasks with a user-specified coverage (i.e., true class label is contained with high probability). This paper proposes a novel algorithm referred to as Neighborhood Conformal Prediction (NCP) to improve the efficiency of uncertainty quantification from CP for deep classifiers (i.e., reduce prediction set size). The key idea behind NCP is to use the learned representation of the neural network to identify k nearest-neighbor calibration examples for a given testing input and assign them importance weights proportional to their distance to create adaptive prediction sets. We theoretically show that if the learned data representation of the neural network satisfies some mild conditions, NCP will produce smaller prediction sets than traditional CP algorithms. Our comprehensive experiments on CIFAR-10, CIFAR-100, and ImageNet datasets using diverse deep neural networks strongly demonstrate that NCP leads to significant reduction in prediction set size over prior CP methods.
Subhankar Ghosh, Taha Belkhouja, Yan Yan 0006, Janardhan Rao Doppa
AAAI2
2023 Adversarial Framework with Certified Robustness for Time-Series Domain via Statistical Features (Extended Abstract)
abstract
Time-series data arises in many real-world applications (e.g., mobile health) and deep neural networks (DNNs) have shown great success in solving them. Despite their success, little is known about their robustness to adversarial attacks. In this paper, we propose a novel adversarial framework referred to as Time-Series Attacks via STATistical Features (TSA-STAT). To address the unique challenges of time-series domain, TSA-STAT employs constraints on statistical features of the time-series data to construct adversarial examples. Optimized polynomial transformations are used to create attacks that are more effective (in terms of successfully fooling DNNs) than those based on additive perturbations. We also provide certified bounds on the norm of the statistical features for constructing adversarial examples. Our experiments on diverse real-world benchmark datasets show the effectiveness of TSA-STAT in fooling DNNs for time-series domain and in improving their robustness.
Taha Belkhouja, Janardhan Rao Doppa
IJCAI1
2023 Energy-Efficient Missing Data Recovery in Wearable Devices: A Novel Search-Based Approach
abstract
Wearable and internet of things (IoT) devices are transforming a number of high-impact applications. Machine learning (ML) algorithms on wearable devices assume that data from all sensors is available at runtime. However, one or more sensors may be unavailable at runtime due to malfunction, energy constraints or communication challenges. Loss of sensor data can potentially lead to severe degradation in application accuracy and quality of service. Commonly employed generative ML methods to recover missing data are not suitable for resource-constrained wearables because they incur significant memory, execution time, and energy overhead at runtime. In contrast to prior methods, this paper presents a novel search-based accuracy-preserving imputation (AIM) algorithm that obtains most likely imputation patterns of sensor data for each missing data scenario via offline analytics. Specifically, for each missing data condition, we store the most likely recovery patterns which preserve ML classifier-based application accuracy in a look up table and use it appropriately at runtime. The key insight behind AIM is that we do not need exact recovery of the missing data as long as the ML classifier-based application accuracy (e.g., health assessment) is preserved. To further improve the overall effectiveness of AIM, we train the ML classifiers to be robust to small errors in data recovery. Experiments on four diverse wearable sensor based time-series benchmarks demonstrate that AIM is able to maintain accuracy within 5% of the baseline with no missing data when one sensor is missing, and improves the overall accuracy by 15% compared to a state-of-the-art baseline. AIM achieves this improvement with negligible energy consumption overhead.
Dina Hussein, Taha Belkhouja, Ganapati Bhat, Janardhan Rao Doppa
ISLPED2
2023 Probabilistically robust conformal prediction
abstract
Conformal prediction (CP) is a framework to quantify uncertainty of machine learning classifiers including deep neural networks. Given a testing example and a trained classifier, CP produces a prediction set of candidate labels with a user-specified coverage (i.e., true class label is contained with high probability). Almost all the existing work on CP assumes clean testing data and there is not much known about the robustness of CP algorithms w.r.t natural/adversarial perturbations to testing examples. This paper studies the problem of probabilistically robust conformal prediction (PRCP) which ensures robustness to most perturbations around clean input examples. PRCP generalizes the standard CP (cannot handle perturbations) and adversarially robust CP (ensures robustness w.r.t worst-case perturbations) to achieve better trade-offs between nominal performance and robustness. We propose a novel adaptive PRCP (aPRCP) algorithm to achieve probabilistically robust coverage. The key idea behind aPRCP is to determine two parallel thresholds, one for data samples and another one for the perturbations on data (aka "quantile-of-quantile” design). We provide theoretical analysis to show that aPRCP algorithm achieves robust coverage. Our experiments on CIFAR-10, CIFAR-100, and ImageNet datasets using deep neural networks demonstrate that aPRCP achieves better trade-offs than state-of-the-art CP and adversarially robust CP algorithms.
Subhankar Ghosh, Yuanjie Shi, Taha Belkhouja, Yan Yan 0006, Janardhan Rao Doppa
UAI3
2023 Dynamic Time Warping Based Adversarial Framework for Time-Series Domain
abstract
Despite the rapid progress on research in adversarial robustness of deep neural networks (DNNs), there is little principled work for the time-series domain. Since time-series data arises in diverse applications including mobile health, finance, and smart grid, it is important to verify and improve the robustness of DNNs for the time-series domain. In this paper, we propose a novel framework for the time-series domain referred as Dynamic Time Warping for Adversarial Robustness (DTW-AR) using the dynamic time warping measure. Theoretical and empirical evidence is provided to demonstrate the effectiveness of DTW over the standard euclidean distance metric employed in prior methods for the image domain. We develop a principled algorithm justified by theoretical analysis to efficiently create diverse adversarial examples using random alignment paths. Experiments on diverse real-world benchmarks show the effectiveness of DTW-AR to fool DNNs for time-series data and to improve their robustness using adversarial training.
Taha Belkhouja, Yan Yan 0006, Janardhan Rao Doppa
IEEE Trans. Pattern Anal. Mach. Intell.1
2022 Training Robust Deep Models for Time-Series Domain: Novel Algorithms and Theoretical Analysis
abstract
Despite the success of deep neural networks (DNNs) for real-world applications over time-series data such as mobile health, little is known about how to train robust DNNs for time-series domain due to its unique characteristics compared to images and text data. In this paper, we fill this gap by proposing a novel algorithmic framework referred as RObust Training for Time-Series (RO-TS) to create robust deep models for time-series classification tasks. Specifically, we formulate a min-max optimization problem over the model parameters by explicitly reasoning about the robustness criteria in terms of additive perturbations to time-series inputs measured by the global alignment kernel (GAK) based distance. We also show the generality and advantages of our formulation using the summation structure over time-series alignments by relating both GAK and dynamic time warping (DTW). This problem is an instance of a family of compositional min-max optimization problems, which are challenging and open with unclear theoretical guarantee. We propose a principled stochastic compositional alternating gradient descent ascent (SCAGDA) algorithm for this family of optimization problems. Unlike traditional methods for time-series that require approximate computation of distance measures, SCAGDA approximates the GAK based distance on-the-fly using a moving average approach. We theoretically analyze the convergence rate of SCAGDA and provide strong theoretical support for the estimation of GAK based distance. Our experiments on real-world benchmarks demonstrate that RO-TS creates more robust deep models when compared to adversarial training using prior methods that rely on data augmentation or new definitions of loss functions. We also demonstrate the importance of GAK for time-series data over the Euclidean distance.
Taha Belkhouja, Yan Yan 0006, Janardhan Rao Doppa
AAAI1
2022 Reliable Machine Learning for Wearable Activity Monitoring: Novel Algorithms and Theoretical Guarantees
abstract
Wearable devices are becoming popular for health and activity monitoring. The machine learning (ML) models for these applications are trained by collecting data in a laboratory with precise control of experimental settings. However, during real-world deployment/usage, the experimental settings (e.g., sensor position or sampling rate) may deviate from those used during training. This discrepancy can degrade the accuracy and effectiveness of the health monitoring applications. Therefore, there is a great need to develop reliable ML approaches that provide high accuracy for real-world deployment. In this paper, we propose a novel statistical optimization approach referred as StatOpt that automatically accounts for the real-world disturbances in sensing data to improve the reliability of ML models for wearable devices. We theoretically derive the upper bounds on sensor data disturbance for StatOpt to produce a ML model with reliability certificates. We validate StatOpt on two publicly available datasets for human activity recognition. Our results show that compared to standard ML algorithms, the reliable ML classifiers enabled by the StatOpt approach improve the accuracy up to 50% in real-world settings with zero overhead, while baseline approaches incur significant overhead and fail to achieve comparable accuracy.
Dina Hussein, Taha Belkhouja, Ganapati Bhat, Janardhan Rao Doppa
ICCAD2
2022 Adversarial Framework with Certified Robustness for Time-Series Domain via Statistical Features
abstract
Time-series data arises in many real-world applications (e.g., mobile health) and deep neural networks (DNNs) have shown great success in solving them. Despite their success, little is known about their robustness to adversarial attacks. In this paper, we propose a novel adversarial framework referred to as Time-Series Attacks via STATistical Features (TSA-STAT). To address the unique challenges of time-series domain, TSA-STAT employs constraints on statistical features of the time-series data to construct adversarial examples. Optimized polynomial transformations are used to create attacks that are more effective (in terms of successfully fooling DNNs) than those based on additive perturbations. We also provide certified bounds on the norm of the statistical features for constructing adversarial examples. Our experiments on diverse real-world benchmark datasets show the effectiveness of TSA-STAT in fooling DNNs for time-series domain and in improving their robustness.
Taha Belkhouja, Janardhan Rao Doppa
J. Artif. Intell. Res.1
2020 Analyzing Deep Learning for Time-Series Data Through Adversarial Lens in Mobile and IoT Applications
abstract
Predictive analytics using the time-series data collected from various types of sensors is a fundamental task that enables diverse mobile and Internet of Things applications including smart health. Deep-learning-based solutions are increasingly employed to solve such tasks because of their ability to directly process raw sensor data to achieve high accuracy as opposed to using human-engineered features. However, there are no principled studies on analyzing deep models for multivariate time-series data in adversarial settings. In this article, we propose a novel framework referred as a multivariate time-series adversarial lens (MTS-AdLens) to analyze deep models for wearable and mobile sensing systems through the adversarial lens in a realistic setting. We make three main contributions toward this goal. First, we introduce highly effective black-box attacks that expose significant vulnerabilities of deep models for multivariate time-series input space. Specifically, we show that deep models are vulnerable to attacks on limited channels. Second, inspired by our vulnerability analysis, we propose a novel technique to improve the robustness of the model. Third, we perform comprehensive experiments on data collected from real tasks to validate all our claims. Our results show the effectiveness of MTS-AdLens in identifying the vulnerabilities of deep models and in improving their robustness to realistic attacks.
Taha Belkhouja, Janardhan Rao Doppa
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2019 Role-Based Hierarchical Medical Data Encryption for Implantable Medical Devices
abstract
Wireless communication became an essential tool for information exchange between modern Implantable Medical Devices (IMDs) and hospital servers. In spite of the many advantages of wireless technology, it puts the patients' health and data privacy in serious danger if no proper security mechanism is imployed. We aim to secure these devices while taking into consideration the limitations of these small devices. The IMDs have resources that are relatively simple and sometimes, once implemented in the body, require surgery to be altered. Consequently, common security mechanisms cannot be simply implemented in fear of consuming all the resources dedicated to healthcare needs. A certain balance between security and efficiency must thus be sought in each IMD architecture. In this work, we propose an encryption scheme for IMDs that stores its monitored data for future use. For privacy issues, not all the stored data should be accessed by any device that has access to the IMD. Certain privileges need to be allocated to different people to protect the privacy of the patient. Hence, we propose a new role-based encryption scheme, that both guarantees hierarchical access to personal data based on their role and still satisfies the computational limitations of IMDs. This scheme employs the Chinese Remainder properties to achieve the desired encryption hierarchy. The IMD uses keys form the same key pool for any encryption, and depending on the access rights of the users, the latter will only be able to decrypt the data he is allowed to. This work resulted in a secure scheme that we have proven it can formally protect the stored data. This scheme performs well under statistical analysis and is characterized by a relatively low complexity. Also, this work led to encrypted data with a lossless compression rate that saves on the communication cost.
Taha Belkhouja, Sameh Sorour, Mohamed Hefeida
GLOBECOM1
2019 Biometric-based authentication scheme for Implantable Medical Devices during emergency situations
abstract
Biometric recognition and analysis are among the most trusted features to be used by Implantable Medical Devices (IMDs). We aim to secure these devices by using these features in emergency scenarios. As patients can witness unpredictable lethal accidents, any implantable medical device should allow access to urgent medical interventions from legitimate parties. Any delay in providing immediate medical support can endanger the patient’s life. Hence, we propose in this work an authentication scheme that allows access to the implanted devices in emergency situations for only legitimate users. We have designed in the first place a scheme for authentication using Electrocardiogram instantaneous readings. Then, we joined the latter to a fixed biometric reading, which is fingerprint reading, to enable access to emergency medical teams. We have designed a scheme in a way to prevent attackers from accessing/hijacking the device even during emergency situations . This scheme has been assisted with elliptic curve cryptography to protect the wireless exchange of requested keys. The scheme relies on the instantaneous reading of the patient’s heartbeat and his/her fingerprint reading to create a secure key. This key will validate the authentication request of the new medical team. We have analyzed this scheme deeply to verify that they offer the necessary security for the patient’s life. We have tested if the wireless exchange of the key will expose the device’s privacy. We have also tested the accuracy of the authentication process to ensure a safe and a valid performance of the authentication process . The scheme has been designed with consideration to any hardware/software limitation that characterize any implantable medical device.
Taha Belkhouja, Xiaojiang Du, Amr Mohamed 0001, Abdulla K. Al-Ali, Mohsen Guizani
Future Gener. Comput. Syst.1
2018 Light-Weight Solution to Defend Implantable Medical Devices against Man-In-The-Middle Attack
abstract
Nowadays, Implantable Medical Devices (IMDs) rely mainly on wireless technology for information exchange. In spite of the many advantages wireless technology offers to patients in terms of efficiency, speed and ease; it puts the patients' health in serious danger if no proper security mechanism is deployed. The IMDs rely generally on resources that are relatively simple and sometimes require surgery to be altered. Therefore, common security mechanisms cannot be simply implemented in fear of consuming all the resources held for healthcare purposes. A certain balance between security and efficiency must be found in each IMD architecture. In this work, we try to avoid encryption algorithms to protect IMDs from Man-In-The-Middle (MITM) attacks. Encryption is generally used to protect communication confidentiality. However, this method is still a subject for replay and MITM attacks. In this work, we propose to create a signature protocol that protects IMDs from MITM attempts using less resources than common encryption/decryption algorithms. This signature algorithm is dynamic, which means that the signature output depends on a key and the same message can have different signatures if this key is different. This dynamic part will be introduced using chaotic generators.
Taha Belkhouja, Amr Mohamed 0001, Abdulla K. Al-Ali, Xiaojiang Du, Mohsen Guizani
GLOBECOM1
2018 Salt Generation for Hashing Schemes based on ECG readings for Emergency Access to Implantable Medical Devices
abstract
Secure communication in medical devices is a pillar in ensuring patient's safety. However, in emergency cases, this can hinder the recovery of the patient. If an emergency team cannot give themselves access to the IMD without the user's assistance, they may be unable to offer any help. This paper introduces a security scheme for similar cases. By creating a backdoor to the IMDs, legal authentication may be performed with the IMD and gain access to it. This work presents a procedure for an emergency team to validate their actions to the IMD without the need of the patient's conscious. This is ensured using hashing function and elliptic curves for the security key generation. The seed that will be used will be the heart rhythm of the patient. The authentication process introduced will only allow access to the identified parties. An eavesdropper will be unable to interfere during emergency cases and can threaten patients' lives.
Taha Belkhouja, Amr Mohamed 0001, Abdulla K. Al-Ali, Xiaojiang Du, Mohsen Guizani
ISNCC1
2017 New Plain-Text Authentication Secure Scheme for Implantable Medical Devices with Remote Control
abstract
Implantable medical devices are being increasingly used to treat or monitor different medical conditions. For such purposes, wireless is the most desired communication scheme to be implemented in these devices. On the other hand, the wireless scheme increases security threats on these electronic devices, and any possibility of attack on the medical device may have lethal consequences. The patients usually have their implantable medical devices configured and monitored by their doctors. But for practical purposes, most of the time they possess a remote control for daily non-critical operations. This remote control can be considered as an open gate for attackers to target those medical devices and cause major harm. Motivated by this, we analyze in this paper the communication scheme implemented in the wireless devices, having as a starting point an Implantable Insulin Pump to develop a new protocol that can be used in the remote control-implantable device communication, and that will rely on plain text messages to avoid encryption implementation. Finally, we will analyze how the novelties introduced with this protocol can secure such a wireless link.
Taha Belkhouja, Xiaojiang Du, Amr Mohamed 0001, Abdulla K. Al-Ali, Mohsen Guizani
GLOBECOM1
2017 Light-weight encryption of wireless communication for implantable medical devices using henon chaotic system (invited paper)
abstract
Implantable Medical Devices (IMDs) are a growing industry regarding personal health care and monitoring. In addition, they provide patients with efficient treatments. In general, these devices use wireless communication technologies that may require synchronization with the medical team. Even though wireless technology offers satisfaction to the patient's daily life, it is still prone to security threats. Many malicious attacks on these devices can directly affect the patient's health in a lethal way. Using insecure wireless channels for these devices offers adversaries easy ways to steal the patient's private data and hijack these systems. This can cause damage to patients and render their devices unusable. In the aim of protecting these devices, we explore in this paper a new way to create symmetric encryption keys to encrypt the wireless communication held by the IMDs. This key generation will rely on chaotic systems to obtain synchronized Pseudo-Random keys that will be generated separately in the system. This generation is in a way that the communication channel will avoid a wireless key exchange, protecting the patient from key theft. Moreover, we will explore the performance of this generator from a cryptographic point of view, ensuring that these keys are safe to use for communication encryption.
Taha Belkhouja, Amr Mohamed 0001, Abdulla K. Al-Ali, Xiaojiang Du, Mohsen Guizani
WINCOM1