Omar Adel Ibrahim

dblp:234/7670 · DBLP profile ↗
← Back
11ranked-venue papers
8as first author
9since 2021 · last 2025
0000-0002-0171-8757ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 5 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 first-author · 2 since 2021Computer networks · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Drone-Mag: UAV Identification and Authentication via Electromagnetic Emissions
abstract
Unmanned Aerial Vehicles (UAVs) are gaining increased popularity in a wide range of domains and applications. As a result, they are also becoming a target of malicious attacks. For example, drone impersonation of military or civilian drones can cause serious security and privacy breaches. There have been some recent contributions that aim to integrate digital certificates as an authentication tool for drones, but such software techniques are often defenseless against physical compromise. In this article, to the best of our knowledge, we are the first to propose a physical layer drone authentication framework to augment existing multifactor authentication schemes leveraging the unintentional Electromagnetic (EM) emissions of the drone’s electronic components. Our solution, Drone-Mag , exploits the inherent non-idealities and imperfections present in drones’ electronic integrated circuits that are introduced during their manufacturing process. Those emissions are hard to mimic or replicate, providing a robust basis for drone authentication. Drone-Mag is a passive, non-interactive, and privacy-preserving authentication solution and does not require software or hardware modifications to available drones. We test the performance of Drone-Mag focusing on the unintentional EM emissions of 23 drones. In particular, we addressed three main tasks: (i) identification of 14 different drones and flight controllers; (ii) authentication of 10 identical (same brand and model) drones; and (iii) rogue drone detection using autoencoders. All the listed tasks achieve a minimum average of 0.97 F1-score, showing the viability and efficiency of the proposed authentication method.
Omar Adel Ibrahim, Roberto Di Pietro
ACM Trans. Cyber Phys. Syst.1
2024 MAG-JAM: Jamming Detection via Magnetic Emissions
Omar Adel Ibrahim, Roberto Di Pietro
ESORICS (1)1
2024 MAG-PUFs: Authenticating IoT devices via electromagnetic physical unclonable functions and deep learning
abstract
The challenge of authenticating Internet of Things (IoT) devices, particularly in low-cost deployments with constrained nodes that struggle with dynamic re-keying solutions, renders these devices susceptible to various attacks. This paper introduces a robust alternative mitigation strategy based on Physical-Layer Authentication (PLA), which leverages the intrinsic physical layer characteristics of IoT devices. These unique imperfections, stemming from the manufacturing process of IoT electronic integrated circuits (ICs), are difficult to replicate or falsify and vary with each function executed by the IoT device. We propose a novel lightweight authentication scheme, MAG-PUFs, that uses the unintentional Electromagnetic (EM) emissions from IoT devices as Physical Unclonable Functions (PUFs). MAG-PUFs operate by collecting these unintentional EM emissions during the execution of pre-defined reference functions by the IoT devices. The authentication is achieved by matching these emissions with profiles recorded at the time of enrollment, using state-of-the-art Deep Learning (DL) approaches such as Neural Networks (NN) and Autoencoders. Notably, MAG-PUFs offer compelling advantages: (i) it preserves privacy, as it does not require direct access to the IoT devices; and, (ii) it provides unique flexibility, permitting the selection of numerous and varied reference functions. We rigorously evaluated MAG-PUFs using 25 Arduino devices and a diverse set of 325 reference function classes. Employing a DL framework, we achieved a minimum authentication F1-Score of 0.99. Furthermore, the scheme’s efficacy in detecting impostor EM emissions was also affirmed, achieving a minimum F1-Score of 0.99. We also compared our solution to other solutions in the literature, showing its remarkable performance. Finally, we discussed code obfuscation techniques and the impact of Radio Frequency (RF) interference on the IoT authentication process.
Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro
Comput. Secur.1
2023 Mag-Auth: Authenticating Wireless Transmitters and Receivers on the Receiver Side via Magnetic Emissions
abstract
Device authentication over the wireless channel is still an open issue. This is especially true for low-end devices like the IoT ones, where the overhead required by traditional asymmetric cryptographic techniques can be overwhelming, or-more in general-when the crypto material might have been compromised. A robust solution for the above scenarios is Physical-Layer Authentication (PLA), which exploits the inherent intrinsic unique features of the wireless devices to achieve low-cost, crypto-less authentication. In this paper, we present Mag-Auth, a novel and lightweight authentication scheme that leverages the Electro-Magnetic (EM) emissions released at the joint connection between the wireless device and its antenna in response to an excitation signal. Specifically, Mag-Auth trains, on the collected EM emissions, an autoencoder and a Neural Network (NN). The autoencoder is employed to reject wireless devices that do not belong to the set the autoencoder and the NN have been trained over, while the NN is applied to uniquely identify the different classes of wireless transmitter-receiver pairs. Mag-Auth enjoys some unique features: it is privacy-preserving as it does not require to have access to the radio board (unlike, for instance, in-phase/quadrature (IQ)-based PLA methods); it caters to both wireless transmitter and receiver authentication scenarios; and, it sports striking performance. Indeed, our extensive experimental campaign involving 600 combinations of various wireless devices and antennas (including SDRs and IoTs) unveiled a minimum average F1-Score of 0.94 when classifying samples collected over a maximum length of 1s, proving the effectiveness and viability of using EM emissions as a lightweight, efficient, and robust authentication mechanism. Finally, we also released the collected EM emissions raw data to foster further investigations and development by Academia, Industry, and practitioners.
Omar Adel Ibrahim, Roberto Di Pietro
WISEC1
2022 MAG-PUF: Magnetic Physical Unclonable Functions for Device Authentication in the IoT
Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro
SecureComm1
2022 MAG-PUF - Authenticating IoT Devices via Magnetic Physical Unclonable Functions
abstract
Authenticating Internet of Things (IoT) devices is still a defiant task, despite the remarkable technological advancement achieved in the last few years. The issue is especially challenging in scenarios involving low-cost constrained nodes, hardly supporting dynamic re-keying algorithms. To provide a viable general-purpose solution, we propose MAG-PUF: a novel and lightweight authentication scheme using unintentional magnetic emissions produced by IoT devices to implement Physical Unclonable Functions (PUFs). Our extensive experimental campaign, involving 25 Arduino boards and four example reference functions, unveiled an outstanding authentication accuracy of over 99%, proving the feasibility of using code-driven magnetic emissions as a lightweight, efficient, and robust PUF for IoT deployments.
Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro
WISEC1
2022 GPS spoofing detection via crowd-sourced information for connected vehicles
abstract
Modern vehicular systems rely on the Global Positioning System (GPS) technology to provide accurate and timely services. However, the GPS has been proved to be characterized by an intrinsic insecure design, thus being subject to several security attacks. Current solutions can reliably detect GPS spoofing attacks leveraging the physical features of the received GPS signals or resorting to multiple antennas. However, these techniques cannot be deployed when the physical properties of the received signals cannot be accessed, which is the most general case for commercial GPS receivers. Alternative solutions in the literature rely on the cross-check of the received signal with information coming from additional sources. However, such proposals are typically limited to a single source, are rarely supported by experimental results, and do not provide insights on the impact of several parameters, such as detection accuracy, time, false-positives, and robustness to malicious information. To overcome the cited limitations, in this paper, we propose an innovative approach, resorting to combined crowd-sourced information from the mobile cellular infrastructure and the WiFi networks to detect GPS spoofing attacks. Our analysis leverages an extensive experimental dataset, available online for the research community, gathered by driving around a car in urban, suburban, and rural scenarios, for around 5 h and covering more than 196 km. Our solution allows for a tunable tradeoff between detection delay and false positive; for instance, we can detect an attack in approximately 6 s, when leveraging the information coming from only the WiFi, while the delay increases to 30 s when using the information from the mobile cellular network, still achieving a false positive probability strictly less than 0.01. We also show the limitations and trade-offs of our approach, in terms of minimum detection accuracy, time, and robustness to malicious information. The data adopted in this work are publicly released to allow results replicability and foster further research in the highlighted directions.
Gabriele Oligeri, Savio Sciancalepore, Omar Adel Ibrahim, Roberto Di Pietro
Comput. Networks3
2022 Noise2Weight: On detecting payload weight from drones acoustic emissions
abstract
The increasing popularity of autonomous and remotely-piloted drones has paved the way for several use-cases and application scenarios, including merchandise delivery, surveillance, and warfare, to cite a few. In many application scenarios, estimating with zero-touch the weight of the payload carried by a drone before it approaches could be of particular interest, e.g., to provide early tampering detection when the weight of the payload is sensitively different from the expected one. To the best of our knowledge, we are the first to investigate the possibility to remotely detect the weight of the payload carried by a commercial drone by analyzing its acoustic fingerprint. Rooted on a sound methodology and validated by an extensive experimental on-field campaign carried out on a reference 3DR Solo drone, we characterize how the differences in the thrust needed by a drone to carry different payloads affect the speed of the motors and the blades and, in turn, introduces significant variations in the resulting acoustic fingerprint. We applied the above findings to different use-cases and scenarios, characterized by different computational capabilities of the detection system. Results are striking: using the Mel-Frequency Cepstral Coefficients (MFCC) components of the audio signal and different Support Vector Machine (SVM) classifiers, we showed that it is possible to achieve a minimum classification accuracy of 98% in the detection of the specific payload class carried by the drone, using an acquisition time of only 0.25 s—performances improve when using longer time acquisitions. All the data used for our analysis have been released as open-source, to enable the community to validate our findings and use such data as a ready-to-use basis for further investigations.
Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro
Future Gener. Comput. Syst.1
2021 MAGNETO: Fingerprinting USB Flash Drives via Unintentional Magnetic Emissions
abstract
Universal Serial Bus (USB) Flash Drives are nowadays one of the most convenient and diffused means to transfer files, especially when no Internet connection is available. However, USB flash drives are also one of the most common attack vectors used to gain unauthorized access to host devices. For instance, it is possible to replace a USB drive so that when the USB key is connected, it would install passwords stealing tools, root-kit software, and other disrupting malware. In such a way, an attacker can steal sensitive information via the USB-connected devices, as well as inject any kind of malicious software into the host. To thwart the above-cited raising threats, we propose MAGNETO, an efficient, non-interactive, and privacy-preserving framework to verify the authenticity of a USB flash drive, rooted in the analysis of its unintentional magnetic emissions. We show that the magnetic emissions radiated during boot operations on a specific host are unique for each device, and sufficient to uniquely fingerprint both the brand and the model of the USB flash drive, or the specific USB device, depending on the used equipment. Our investigation on 59 different USB flash drives—belonging to 17 brands, including the top brands purchased on Amazon in mid-2019—reveals a minimum classification accuracy of 98.2% in the identification of both brand and model, accompanied by a negligible time and computational overhead. MAGNETO can also identify the specific USB Flash drive, with a minimum classification accuracy of 91.2%. Overall, MAGNETO proves that unintentional magnetic emissions can be considered as a viable and reliable means to fingerprint read-only USB flash drives. Finally, future research directions in this domain are also discussed.
Omar Adel Ibrahim, Savio Sciancalepore, Gabriele Oligeri, Roberto Di Pietro
ACM Trans. Embed. Comput. Syst.1
2020 PiNcH: An effective, efficient, and robust solution to drone detection via network traffic analysis
Savio Sciancalepore, Omar Adel Ibrahim, Gabriele Oligeri, Roberto Di Pietro
Comput. Networks2
2019 Drive me not: GPS spoofing detection via cellular network: (architectures, models, and experiments)
abstract
The Global Positioning System (GPS) has been proved to be exposed to several cybersecurity attacks, due to its intrinsic insecure design. GPS spoofing is one of the most easiest, cheap, and dreadful attacks that can be delivered: fake GPS signals can be sent to a target device and make it moving according to a pre-computed path.
Gabriele Oligeri, Savio Sciancalepore, Omar Adel Ibrahim, Roberto Di Pietro
WiSec3