EDBT 2026 Demo / reviewers in the wild / expert
Hisham Alasmary
dblp:226/5296
· DBLP profile ↗
24ranked-venue papers
3as first author
17since 2021 · last 2026
0000-0002-6482-3968ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 2 first-author · 11 since 2021Security and privacy · 6 · 3 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SUAD: A Secure Attribute-Based Data Sharing Framework with User-Controlled Key Management for Cloud-Assisted IoTabstractCloud computing supports the Internet of Things (IoT) in handling diverse and large-scale data. However, outsourcing data control to the cloud raises security concerns, particularly in key management. Although Ciphertext-Policy Attribute-Based Encryption (CP-ABE) preserves data confidentiality, it entrusts key management to a centralized attribute authority, resulting in the key escrow problem. Furthermore, existing CP-ABE schemes lack mechanisms for key verification and identity authentication, leaving IoT systems susceptible to key errors and impersonation attacks. To overcome these limitations, we propose Secure and User-autonomous Attribute-based Data Sharing (SUAD) for cloud-assisted IoT. The SUAD scheme transfers key management from the authority to data users themselves, thereby eliminating key escrow. Built on a data user-centric architecture, the SUAD scheme removes the decryption privilege of the attribute authority. To prevent key forgeries and operational errors, we design a correctness verification mechanism covering five critical keys and the decryption result, along with a two-way interactive authentication protocol based on the Schnorr scheme for reliable identity verification. The SUAD scheme further supports dynamic user management, enabling user logout, replacement, and joining while optimizing maintenance overhead through periodic updates. We formally prove that SUAD achieves selective IND-CCA security in the random oracle model. Both theoretical analysis and experimental evaluations demonstrate that SUAD enhances user autonomy and strengthens security without incurring additional encryption or decryption costs, confirming its practicality for IoT deployments. Bei Gong, Akhtar Badshah, Xin Ai 0009, Hisham Alasmary, Muhammad Waqas 0001, Muhammad Taimoor Khan 0001 |
ACM Trans. Priv. Secur. | 5 |
| 2026 | Efficient Privacy-Preserving Conjunctive Searchable Encryption for Cloud-IoT Healthcare SystemsabstractIn cloud-Internet of Things (IoT) healthcare systems, private medical data leakage is a serious concern as the cloud server is not fully trusted. Dynamic searchable symmetric encryption (DSSE), with necessary forward and backward privacy security properties, enables doctors to retrieve ciphertexts while guaranteeing data privacy. However, existing forward and backward private DSSE schemes are not well-suited for cloud-IoT healthcare systems with attribute-value type databases. To this end, we propose an efficient privacy-preserving conjunctive searchable encryption scheme for cloud-IoT healthcare systems, called PC-SE. It is the first conjunctive DSSE scheme designed for attribute-value type databases. Specifically, we design flexible search capabilities for PC-SE to address users’ various search requirements. It can not only achieve precise conjunctive search based on keywords but also realize broad attribute search. Moreover, our scheme achieves fine-grained search for attribute values while maintaining forward and Type-I - backward privacy. This approach reduces the communication burden and minimizes the risk of privacy exposure. To ensure that users with different authorities can only access the corresponding attribute values, we introduce an attribute access control mechanism in PC-SE. Finally, security analysis and experimental results demonstrate that PC-SE is secure and effective. Jiadi Ma, Tianqi Peng, Bei Gong, Muhammad Waqas 0001, Hisham Alasmary, Sheng Chen 0013 |
ACM Trans. Priv. Secur. | 5 |
| 2026 | TruChord: A Secure Communication Framework for Hybrid SDIoT Architecture Based on Chord Overlay
Bei Gong, Zahid Halim, Hisham Alasmary, Muhammad Waqas 0001, Iftekhar Ahmad |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Multi-User Oriented Data Sharing Scheme for Internet of Medical Things Based on Dual Cryptography MechanismabstractEncrypted sharing of Internet of Medical Things (IoMT) data is essential for facilitating collaboration, safeguarding patient privacy, and advancing clinical research. However, existing encryption schemes face numerous challenges in multi-user environments. Traditional proxy re-encryption requires exclusive ciphertext for each user, which is evidently unsuitable for IoMT's multi-user scenarios. Meanwhile, attribute-based encryption provides flexible data access control, but its complex computations and high resource demands limit its use in large-scale IoMT environments. Additionally, challenges like single-point failure and redundant backups emerge in ciphertext storage. To address these challenges, we propose a dual-cryptography mechanism integrating enhanced proxy re-encryption and attribute-based encryption. Our scheme enables unified ciphertext access for authorized users while applying attribute encryption exclusively to small data keys. To mitigate potential data loss from storage server failures, we propose a decentralized ciphertext storage and recovery mechanism with verifiable secret sharing. Furthermore, we implement decentralized ciphertext storage using verifiable secret sharing, ensuring recoverability from server failures. Formal analysis proves confidentiality under the random oracle model. Experimental results demonstrate high security strength, computational efficiency, and robustness. The solution prevents single-point failures, resists collusion attacks, and maintains traceability through blockchain-integrated audit trails. Guiping Zheng, Bei Gong, Muhammad Waqas 0001, Iftekhar Ahmad, Hisham Alasmary, Sheng Chen 0001 |
IEEE Trans. Sustain. Comput. | 5 |
| 2024 | Futuristic Decentralized Vehicular Network Architecture and Repairing Management System on BlockchainabstractBlockchain technology is used often as a merger with other technologies to achieve a high level of security, privacy, and robustness and to handle issues such as maliciousness of nodes, privacy leakage, the selfishness of nodes, communication delays, and high execution and transaction costs. There is currently a lack of a comprehensive system for automating and cost-effectively managing vehicle repairs, maintenance, and other associated services. To solve such issues we proposed a novel futuristic comprehensive model that integrates a blockchain-based framework to safely record vehicle maintenance, validate repair services, and oversee parts inventory. It employs smart contracts and consensus protocols to secure communications and data storage, thus reducing data breaches and vulnerabilities from single-point failures. A reward system is embedded within the network to encourage positive behavior and deter detrimental actions. We also incorporated advanced privacy-ensuring methods, like zero-knowledge proofs and secure multi-party computation, to safeguard sensitive data while preserving its utility. Our model features automatic detection and response mechanisms for node failure, improving network resilience by 25% thus also providing a 20% reduction in execution, operational costs, and scalability with an enhancement of 15%, underscoring the model’s efficiency in vehicular repair and maintenance activities. Results and simulations clearly depict the overall performance and efficiency in terms of security, privacy, node failure, and the management of vehicle repairs with respect to other closely related models. Usama Arshad, Zahid Halim, Hisham Alasmary, Muhammad Waqas 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Hybrid Edge-Cloud Collaborator Resource Scheduling Approach Based on Deep Reinforcement Learning and Multiobjective OptimizationabstractCollaborative resource scheduling between edge terminals and cloud centers is regarded as a promising means of effectively completing computing tasks and enhancing quality of service. In this paper, to further improve the achievable performance, the edge cloud resource scheduling (ECRS) problem is transformed into a multi-objective Markov decision process based on task dependency and features extraction. A multi-objective ECRS model is proposed by considering the task completion time, cost, energy consumption and system reliability as the four objectives. Furthermore, a hybrid approach based on deep reinforcement learning (DRL) and multi-objective optimization are employed in our work. Specifically, DRL preprocesses the workflow, and a multi-objective optimization method strives to find the Pareto-optimal workflow scheduling decision. Various experiments are performed on three real data sets with different numbers of tasks. The results obtained demonstrate that the proposed hybrid DRL and multi-objective optimization design outperforms existing design approaches. Jiangjiang Zhang, Muhammad Waqas 0001, Hisham Alasmary, Shanshan Tu, Sheng Chen 0001 |
IEEE Trans. Computers | 4 |
| 2024 | EAKE-WC: Efficient and Anonymous Authenticated Key Exchange Scheme for Wearable ComputingabstractWearable computing has shown tremendous potential to revolutionize and uplift the standard of our lives. However, researchers and field experts have often noted several privacy and security vulnerabilities in the field of wearable computing. In order to tackle these problems, various schemes have been proposed in the literature to improve the efficiency of authentication and key establishment procedure. However, the existing schemes have relatively high computation and communication overheads and are not resilient to various potential security attacks, which reduces their significance for applicability in constrained wearable devices. In this work, we propose an efficient and anonymous authenticated key exchange scheme for wearable computing (EAKE-WC), which performs mutual authentication between the user and the wearable device, and between the cloud server and the user. It also establishes secret session keys for each session to secure communication among the communicating entities. Additionally, the proposed EAKE-WC scheme is designed using authenticated encryption with associated data (AEAD) primitives like ASCON, bitwise XOR, and hash functions. Our results from the security analysis depict compliance of the proposed EAKE-WC with wearable computing's security criteria. In addition, we also demonstrate through a comprehensive comparative analysis that the proposed scheme, EAKE-WC, outperforms the existing benchmark schemes in various key performance areas, including lower communication and computational overheads, enhanced security, and added functionality. Shanshan Tu, Akhtar Badshah, Hisham Alasmary, Muhammad Waqas 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Blockchain-Enhanced Time-Variant Mean Field-Optimized Dynamic Computation Sharing in Mobile NetworkabstractAlthough 5G and beyond communication technology empower a large number of edge heterogeneous devices and applications, the stringent security remains a major concern when dealing with the millions of edge computing tasks in the highly dynamic heterogeneous networks (HDHNs). Blockchains contribute significantly to addressing security challenges by guaranteeing the reliability of data and information. Since the node’s mobility, there are risks of exiting the network and leaving the remaining tasks noncomputed. Therefore, we model the cost function of offloaded computing tasks as a dynamic stochastic game. To reduce the computational complexity, the Time-Variant Mean-Field term (TVMF) is adopted to solve the cost-optimized problem. What’s more, we design an Adaptivity-Aware Practical byzantine fault tolerance consensus Protocol (AAPP) to dynamically formulate domains, execute leader node selection with regard to task completion and quickly verify computational results. In addition, a Dynamic Multi-domain Fractional Repetition uncoded repair storage (DMFR) scheme with variant redundancy is proposed to reduce the storage pressure and repair overhead. The simulation is implemented to demonstrate our scheme outperforms the benchmarks in terms of cost and time overhead. Fenhua Bai, Tao Shen 0004, Jian Song 0011, Bei Gong, Muhammad Waqas 0001, Hisham Alasmary |
IEEE Trans. Wirel. Commun. | 7 |
| 2023 | Defense scheme against advanced persistent threats in mobile fog computing security
Muhammad Waqas 0001, Shanshan Tu, Jialin Wan, Talha Mir, Hisham Alasmary, Ghulam Abbas 0002 |
Comput. Networks | 5 |
| 2023 | Network load prediction and anomaly detection using ensemble learning in 5G cellular networks
Usman Haider, Muhammad Waqas 0001, Muhammad Hanif 0001, Hisham Alasmary, Saeed Mian Qaisar |
Comput. Commun. | 4 |
| 2023 | Deep convolutional cross-connected kernel mapping support vector machine based on SelectDropout
Zhaoying Liu, Ting Zhang 0012, Hisham Alasmary, Muhammad Waqas 0001, Zahid Halim |
Inf. Sci. | 4 |
| 2022 | Understanding Internet of Things malware by analyzing endpoints in their static artifacts
Jinchun Choi, Afsah Anwar, Abdulrahman Alabduljabbar, Hisham Alasmary, Jeffrey Spaulding, An Wang 0002, Songqing Chen, DaeHun Nyang, Amro Awad, David Mohaisen |
Comput. Networks | 4 |
| 2022 | RouteChain: Towards Blockchain-based secure and efficient BGP routing
Muhammad Saad 0001, Afsah Anwar, Ashar Ahmad, Hisham Alasmary, Murat Yuksel, David Mohaisen |
Comput. Networks | 4 |
| 2022 | ShellCore: Automating Malicious IoT Software Detection Using Shell Commands RepresentationabstractThe Linux shell is a command-line interpreter that provides users with a command interface to the operating system, allowing them to perform various functions. Although very useful in building capabilities at the edge, the Linux shell can be exploited, giving adversaries a prime opportunity to use them for malicious activities. With access to Internet of Things (IoT) devices, malware authors can abuse the Linux shell of those devices to propagate infections and launch large-scale attacks, e.g., Distributed Denial of Service. In this work, we provide a first look at the tasks managed by shell commands in Linux-based IoT malware toward detection. We analyze malicious shell commands found in IoT malware and build a neural network-based model, ShellCore, to detect malicious shell commands. Namely, we collected a large data set of shell commands, including malicious commands extracted from 2891 IoT malware samples and benign commands collected from real-world network traffic analysis and volunteered data from Linux users. Using conventional machine and deep learning-based approaches trained with a term- and character-level features, ShellCore is shown to achieve an accuracy of more than 99% in detecting malicious shell commands and files (i.e., binaries). Hisham Alasmary, Afsah Anwar, Ahmed Abusnaina, Abdulrahman Alabduljabbar, Mohammed Abuhamad, An Wang 0002, DaeHun Nyang, Amro Awad, David Mohaisen |
IEEE Internet Things J. | 1 |
| 2022 | DL-FHMC: Deep Learning-Based Fine-Grained Hierarchical Learning Approach for Robust Malware ClassificationabstractThe acceptance of the Internet of Things (IoT) for both household and industrial applications is accompanied by the rapid growth of IoT malware. With the increase of their attack surface, analyzing, understanding, and detecting IoT malicious behavior are crucial. Traditionally, machine and deep learning-based approaches are used for malware detection and behavioral understanding. However, recent research has shown the susceptibility of those approaches to adversarial attacks by introducing noise to the feature space. In this work, we introduce DL-FHMC, a fine-grained hierarchical learning approach for robust IoT malware detection. DL-FHMC utilizes Control Flow Graph (CFG)-based behavioral patterns for adversarial IoT malicious software detection. In particular, we extract a comprehensive list of behavioral patterns from a large dataset of malicious IoT binaries, represented by the shared execution flows, and use them as a modality for malicious behavior detection. Leveraging machine learning and subgraph isomorphism matching algorithms, DL-FHMC provides state-of-the-art performance in detecting malware samples and adversarial examples (AEs). We first highlight the caveats of CFG-based IoT malware detection systems, showing the adversarial capabilities in generating practical functionality-preserving AEs with reduced overhead using Graph Embedding and Augmentation (GEA) techniques. We then introduce Suspicious Behavior Detector, a component that extracts comprehensive behavioral patterns from three popular IoT malicious families, Gafgyt, Mirai, and Tsunami, for AEs detection with high accuracy. The proposed detector operates as a model-independent standalone module, with no prior assumptions of the adversarial attacks nor their configurations. Ahmed Abusnaina, Mohammed Abuhamad, Hisham Alasmary, Afsah Anwar, RhongHo Jang, Saeed Salem, DaeHun Nyang, David Mohaisen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Domain name system security and privacy: A contemporary survey
Aminollah Khormali, Jeman Park 0001, Hisham Alasmary, Afsah Anwar, Muhammad Saad 0001, David Mohaisen |
Comput. Networks | 3 |
| 2021 | Corrigendum to "Domain name system security and privacy: A contemporary survey" Computer Networks Volume 185 (2020) 107699
Aminollah Khormali, Jeman Park 0001, Hisham Alasmary, Afsah Anwar, Muhammad Saad 0001, David Mohaisen |
Comput. Networks | 3 |
| 2020 | Soteria: Detecting Adversarial Examples in Control Flow Graph-based Malware ClassifiersabstractDeep learning algorithms have been widely used for security applications, including malware detection and classification. Recent results have shown that those algorithms are vulnerable to adversarial examples, whereby a small perturbation in the input sample may result in misclassification. In this paper, we systematically tackle the problem of adversarial examples detection in the control flow graph (CFG) based classifiers for malware detection using Soteria. Unique to Soteria, we use both density-based and level-based labels for CFG labeling to yield a consistent representation, a random walk-based traversal approach for feature extraction, and n-gram based module for feature representation. End-to-end, Soteria's representation ensures a simple yet powerful randomization property of the used classification features, making it difficult even for a powerful adversary to launch a successful attack. Soteria also employs a deep learning approach, consisting of an auto-encoder for detecting adversarial examples, and a CNN architecture for detecting and classifying malware samples. We evaluate the performance of Soteria, using a large dataset consisting of 16,814 IoT samples, and demonstrate its superiority in comparison with state-of-the-art approaches. In particular, Soteria yields an accuracy rate of 97.79% for detecting AEs, and 99.91% overall accuracy for classification malware families. Hisham Alasmary, Ahmed Abusnaina, RhongHo Jang, Mohammed Abuhamad, Afsah Anwar, DaeHun Nyang, David Mohaisen |
ICDCS | 1 |
| 2020 | Statically Dissecting Internet of Things Malware: Analysis, Characterization, and Detection
Afsah Anwar, Hisham Alasmary, Jeman Park 0001, An Wang 0002, Songqing Chen, David Mohaisen |
ICICS | 2 |
| 2019 | Adversarial Learning Attacks on Graph-based IoT Malware Detection SystemsabstractIoT malware detection using control flow graph (CFG)-based features and deep learning networks are widely explored. The main goal of this study is to investigate the robustness of such models against adversarial learning. We designed two approaches to craft adversarial IoT software: off-the-shelf methods and Graph Embedding and Augmentation (GEA) method. In the off-the-shelf adversarial learning attack methods, we examine eight different adversarial learning methods to force the model to misclassification. The GEA approach aims to preserve the functionality and practicality of the generated adversarial sample through a careful embedding of a benign sample to a malicious one. Intensive experiments are conducted to evaluate the performance of the proposed method, showing that off-the-shelf adversarial attack methods are able to achieve a misclassification rate of 100%. In addition, we observed that the GEA approach is able to misclassify all IoT malware samples as benign. The findings of this work highlight the essential need for more robust detection tools against adversarial learning, including features that are not easy to manipulate, unlike CFG-based features. The implications of the study are quite broad, since the approach challenged in this work is widely used for other applications using graphs. Ahmed Abusnaina, Aminollah Khormali, Hisham Alasmary, Jeman Park 0001, Afsah Anwar, David Mohaisen |
ICDCS | 3 |
| 2019 | Breaking graph-based IoT malware detection systems using adversarial examples: posterabstractThe main goal of this study is to investigate the robustness of graph-based Deep Learning (DL) models used for Internet of Things (IoT) malware classification against Adversarial Learning (AL). We designed two approaches to craft adversarial IoT software, including Off-the-Shelf Adversarial Attack (OSAA) methods, using six different AL attack approaches, and Graph Embedding and Augmentation (GEA). The GEA approach aims to preserve the functionality and practicality of the generated adversarial sample through a careful embedding of a benign sample to a malicious one. Our evaluations demonstrate that OSAAs are able to achieve a misclassification rate (MR) of 100%. Moreover, we observed that the GEA approach is able to misclassify all IoT malware samples as benign. Ahmed Abusnaina, Aminollah Khormali, Hisham Alasmary, Jeman Park 0001, Afsah Anwar, Ulku Meteriz, David Mohaisen |
WiSec | 3 |
| 2019 | Analyzing endpoints in the internet of things malware: posterabstractThe lack of security measures in the Internet of Things (IoT) devices and their persistent online connectivity give adversaries an opportunity to target them or abuse them as intermediary targets for volumetric attacks such as Distributed Denial-of-Service (DDoS) campaigns. In this paper, we analyze IoT malware with a focus on endpoints to understand the affinity between the dropzones and their target IP addresses, and to understand the different patterns among them. Towards this goal, we reverse-engineer 2,423 IoT malware samples to obtain IP addresses. We further augment additional information about the endpoints from Internet-wide scanners, including Shodan and Censys. We then perform a deep data-driven analysis of the dropzones and their target IP addresses and further examine the attack surface of the target device space. Jinchun Choi, Afsah Anwar, Hisham Alasmary, Jeffrey Spaulding, DaeHun Nyang, David Mohaisen |
WiSec | 3 |
| 2019 | Analyzing and Detecting Emerging Internet of Things Malware: A Graph-Based ApproachabstractThe steady growth in the number of deployed Internet of Things (IoT) devices has been paralleled with an equal growth in the number of malicious software (malware) targeting those devices. In this paper, we build a detection mechanism of IoT malware utilizing control flow graphs (CFGs). To motivate for our detection mechanism, we contrast the underlying characteristics of IoT malware to other types of malware—Android malware, which are also Linux-based—across multiple features. The preliminary analyses reveal that the Android malware have high density, strong closeness and betweenness, and a larger number of nodes. We show that IoT malware samples have a large number of edges despite a smaller number of nodes, which demonstrate a richer flow structure and higher complexity. We utilize those various characterizing features as a modality to build a highly effective deep learning-based detection model to detect IoT malware. To test our model, we use CFGs of about 6000 malware and benign IoT disassembled samples, and show a detection accuracy of $\approx 99.66$ %. Hisham Alasmary, Aminollah Khormali, Afsah Anwar, Jeman Park 0001, Jinchun Choi, Ahmed Abusnaina, Amro Awad, DaeHun Nyang, David Mohaisen |
IEEE Internet Things J. | 1 |
| 2018 | QOI: Assessing Participation in Threat Information SharingabstractWe introduce the notion of Quality of Indicator (QoI) to assess the level of contribution by participants in threat intelligence sharing. We exemplify QoI by metrics of the correctness, relevance, utility, and uniqueness of indicators. We build a system that extrapolates the metrics using a machine learning process over a reference set of indicators. We compared these results against a model that only considers the volume of information as a metric for contribution, and unveiled various observations, including the ability to spot low-quality contributions that are synonymous to free-riding. Jeman Park 0001, Hisham Alasmary, Omar Al-Ibrahim, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla, David Mohaisen |
ICASSP | 2 |