EDBT 2026 Demo / reviewers in the wild / expert
Nur Imtiazul Haque
dblp:238/8547
· DBLP profile ↗
11ranked-venue papers
6as first author
9since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RAPTOR: Adversarially Robust Path Planning for LiDAR-Based Autonomous Robotic Vehicles
Alejandro Almeida, Daniel Aviles Rueda, Nur Imtiazul Haque, Sheikh Iqbal Ahamed, Mohammad Ashiqur Rahman |
COMPSAC | 3 |
| 2026 | MISGUIDE: Security-Aware Attack Analytics for Smart Grid Load Frequency ControlabstractIncorporating advanced information and communication technologies enhances smart grid (SG) operation, while increasing vulnerability to false data injection (FDI) attacks. Identifying and characterizing FDI attack vectors is crucial, as they can jeopardize SG system stability and protection. State-of-the-art (SOTA) attack analytics predominantly employ machine learning (ML) to extract attack vectors that can evade rules-based bad-data detectors. While scalable, these approaches offer no guarantees of identification or stealth and often yield simplistic attack vectors detectable by ML-based anomaly detection models (ADMs). Formal methods, in contrast, can synthesize verifiable attack vectors while ignoring ML-based ADM. Several tools in other domains attempt to identify attack vectors against ML-based ADMs; however, they apply to systems with straightforward control dynamics and cannot be directly transferred to complex, interdependent SG control systems. To address these gaps, we introduce MISGUIDE, a defense-aware attack analytics that jointly models LFC dynamics and an ML-based ADM to extract verifiable, multi-timeslot FDI attack vectors that can trip under/over-frequency relays while remaining stealthy. The ADM used in MISGUIDE can detect 100% of the attack vectors found by SOTA attack analytics. Using real-world load data, we validate the attack vectors generated by MISGUIDE through hardware-in-the-loop OPAL-RT simulations on the IEEE 39-bus system. Nur Imtiazul Haque, Prabin Mali, Mohammad Zakaria Haider, Mohammad Ashiqur Rahman, Sumit Paudyal |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Formal threat analysis of machine learning-based control systems: A study on smart healthcare systems
Nur Imtiazul Haque, Mohammad Ashiqur Rahman, A. Selcuk Uluagac |
Comput. Secur. | 1 |
| 2023 | SHATTER: Control and Defense-Aware Attack Analytics for Activity-Driven Smart Home SystemsabstractModern smart home control systems utilize realtime occupancy and activity monitoring to ensure control efficiency, occupants' comfort, and optimal energy consumption. Moreover, adopting machine learning-based anomaly detection models (ADMs) enhances security and reliability. However, sufficient system knowledge allows adversaries/attackers to alter sensor measurements through stealthy false data injection (FDI) attacks. Although ADMs limit attack scopes, the availability of information like occupants' location, conducted activities, and alteration capability of smart appliances increase the attack surface. Therefore, performing an attack space analysis of modern home control systems is crucial to design robust defense solutions. However, state-of-the-art analyzers do not consider contemporary control and defense solutions and generate trivial attack vectors. To address this, we propose a control and defense-aware novel attack analysis framework for a modern smart home control system, efficiently extracting ADM rules. We verify and validate our framework using a state-of-the-art dataset and a prototype testbed. Nur Imtiazul Haque, Maurice Ngouen, Mohammad Ashiqur Rahman, A. Selcuk Uluagac, Laurent Njilla |
DSN | 1 |
| 2022 | Poster: A Novel Formal Threat Analyzer for Activity Monitoring-based Smart Home Heating, Ventilation, and Cooling Control SystemabstractContemporary home control systems determine real-time heating/cooling demands utilizing smart sensor devices, giving rise to demand control heating, ventilation, and cooling (DCHVAC) systems, thus improving the home's energy efficiency. The adoption of activity monitoring in the smart home control system further augments the controller efficiency and improves occupants' comfort and productivity, elderly monitoring, and so forth. Additionally, the learned occupants' activity patterns help embed machine learning (ML)-based abnormality detection capability to track inconsistencies among the zone sensor measurements. Hence, the incorporation of an activity monitoring system assists anomaly detection models (ADMs) in detecting false data injection (FDI) attacks that are being glowingly researched due to their massive damage capability. However, in this work, we propose a novel attack strategy that identified that the knowledge of occupants' activities along with indoor air quality (IAQ) and occupancy sensor measurements allows the attackers to launch even more hazardous attack (i.e., significant increment in energy cost/ worsening health conditions for the occupants). Hence, it is crucial to analyze the security of the activity monitoring-based smart home DCHVAC system. Accordingly, we propose a novel formal threat analyzer that analyzes the threat space of the smart home DCHVAC control system, which is modeled by rule-based control policies and ML-based ADMs. The rules from the ADM are extracted through an efficient algorithm. The constraints associated with the rules are solved through a satisfiability module theorem (SMT)-based solver. %We performed our initial evaluation of the proposed threat analyzer's effectiveness on the Center of Advanced Studies in Adaptive Systems (CASAS) dataset using some metrics. We will further experiment with other metrics along experimenting with our collaborator's dataset (KTH live-in lab) and open-source Örebro datasets for assessing the framework with realistic occupants' activity. Moreover, we also created our prototype testbed for evaluating the feasibility of the proposed attack and threat analyzer. Nur Imtiazul Haque, Maurice Ngouen, Yazen Al-Wahadneh, Mohammad Ashiqur Rahman |
CCS | 1 |
| 2021 | Ensemble-based Efficient Anomaly Detection for Smart Building Control SystemsabstractModern building control systems integrate the internet of things (IoT) for real-time monitoring of the building’s demand and manage the heating, ventilation, and air conditioning (HVAC) cost-efficiently and reliably. However, adversarial alterations of the sensor data can disrupt the occupants’ comfort or increase energy consumption. Several intrusion detection systems (IDSs) are proposed to detect the tempering of the sensor measurements. However, these approaches either demonstrate a high false alarm rate or fail to detect anomalies, putting the HVAC control or the building occupants in a vulnerable condition. This paper proposes a novel intrusion detection technique amalgamating two unsupervised machine learning techniques, namely autoencoder(AE) and one-class support vector machine (OCSVM), for identifying abnormality in smart building sensor measurements. Our experimental analysis shows that the AE model-based anomaly detector demonstrates satisfactory performance for lowering false alarms but fails to detect a number of anomalous samples. In contrast, the OCSVM-based anomaly detection model performs significantly well for anomaly detection while raises a lot of false alarms. Our proposed ensembled AE-OCSVM model combines both models’ benefits, resulting in significant reductions of false positive and false negative rates compared to the existing smart building IDSs. We evaluate the proposed intrusion detection system on the commercial occupancy dataset (COD) and find that the proposed IDS model can achieve a 99.6% F1-score. Nur Imtiazul Haque, Mohammad Ashiqur Rahman, Hossain Shahriar |
COMPSAC | 1 |
| 2021 | DDAF: Deceptive Data Acquisition Framework against Stealthy Attacks in Cyber-Physical SystemsabstractCyber-physical systems (CPSs) and the Internet of Things (IoT) are converging towards a hybrid platform that is becoming ubiquitous in all modern infrastructures. The massive deployment of CPS requires comprehensive, secure, and reliable communication. The integration of complex and heterogeneous systems makes enormous space for the adversaries to get into the network and inject malicious data. To obfuscate and mislead the attackers, we propose DDAF, a deception defense-based data acquisition framework for a hierarchical communication network of CPSs. Each switch in the hierarchical network generates a random pattern of addresses/IDs by shuffling the original sensor IDs reported through it. Later, while sending the measurement data from remotely located sensors to the central controller, the switches craft the network packets by replacing the sensors’ original IDs with pre-generated deceptive IDs. Due to the deception, any stealthy attack turns into a random data injection and ends up as an outlier during the bad data detection process. By analyzing the outlier data, DDAF detects and localizes the attack points and the targeted sensors. DDAF is generic and highly scalable to be implemented in any size of networked control systems. Experimental results on the standard IEEE 14, 57, and 300 bus power systems show that DDAF can detect, mitigate, and localize almost 100% of the stealthy cyber-attacks. To the best of our knowledge, this is the first framework that implements complete randomization in the data acquisition of a networked control system. Md Hasan Shahriar, Mohammad Ashiqur Rahman, Nur Imtiazul Haque, Badrul H. Chowdhury |
COMPSAC | 3 |
| 2021 | BIoTA: Control-Aware Attack Analytics for Building Internet of ThingsabstractModern building control systems adopt demand control heating, ventilation, and cooling (HVAC) for increased energy efficiency. The integration of the Internet of Things (IoT) in the building control system can determine real-time demand, which has made the buildings smarter, reliable, and efficient. As occupants in a building are the main source of continuous heat and CO2 generation, estimating the accurate number of people in real-time using building IoT (BIoT) system facilities is essential for optimal energy consumption and occupants' comfort. However, the incorporation of less secured IoT sensor nodes and open communication network in the building control system eventually increases the number of vulnerable points to be compromised. Exploiting these vulnerabilities, attackers can manipulate the controller with false sensor measurements and disrupt the system's consistency. The attackers with the knowledge of overall system topology and control logics can launch attacks without alarming the system. This paper proposes a building internet of things analyzer (BIoTA) framework1that assesses the smart building HVAC control system's security using formal attack modeling. We evaluate the proposed attack analyzer's effectiveness on the commercial occupancy dataset (COD) and the KTH live-in lab dataset. To the best of our knowledge, this is the first research attempt to formally model a BIoT-based HVAC control system and perform an attack analysis. Nur Imtiazul Haque, Mohammad Ashiqur Rahman, Dong Chen 0010, Hisham A. Kholidy |
SECON | 1 |
| 2021 | iDDAF: An Intelligent Deceptive Data Acquisition Framework for Secure Cyber-Physical Systems
Md Hasan Shahriar, Mohammad Ashiqur Rahman, Nur Imtiazul Haque, Badrul H. Chowdhury, Steven G. Whisenant |
SecureComm (2) | 3 |
| 2020 | G-IDS: Generative Adversarial Networks Assisted Intrusion Detection SystemabstractThe boundaries of cyber-physical systems (CPS) and the Internet of Things (IoT) are converging together day by day to introduce a common platform on hybrid systems. Moreover, the combination of artificial intelligence (AI) with CPS creates a new dimension of technological advancement. All these connectivity and dependability are creating massive space for the attackers to launch cyber attacks. To defend against these attacks, intrusion detection system (IDS) has been widely used. However, emerging CPS fields suffer from imbalanced and missing sample data, which makes the training of IDS difficult. In this paper, we propose a generative adversarial network (GAN) based intrusion detection system (G-IDS), where GAN generates synthetic samples, and IDS gets trained on them along with the original ones. G-IDS also fixes the difficulties of imbalanced or missing data problems. We model a network security dataset for an emerging CPS using NSL KDD-99 dataset and evaluate our proposed model's performance using different metrics. We find that our proposed G-IDS model performs much better in attack detection and model stabilization during the training process than a standalone IDS. Md Hasan Shahriar, Nur Imtiazul Haque, Mohammad Ashiqur Rahman, Miguel Alonso Jr. |
COMPSAC | 2 |
| 2020 | Adversarial Attacks to Machine Learning-Based Smart Healthcare SystemsabstractThe increasing availability of healthcare data requires accurate analysis of disease diagnosis, progression, and real-time monitoring to provide improved treatments to the patients. In this context, Machine Learning (ML) models are used to extract valuable features and insights from high-dimensional and heterogeneous healthcare data to detect different diseases and patient activities in a Smart Healthcare System (SHS). However, recent researches show that ML models used in different application domains are vulnerable to adversarial attacks. In this paper, we introduce a new type of adversarial attacks to exploit the ML classifiers used in a SHS. We consider an adversary who has partial knowledge of data distribution, SHS model, and ML algorithm to perform both targeted and untargeted attacks. Employing these adversarial capabilities, we manipulate medical device readings to alter patient status (disease-affected, normal condition, activities, etc.) in the outcome of the SHS. Our attack utilizes five different adversarial ML algorithms (HopSkipJump, Fast Gradient Method, Crafting Decision Tree, Carlini & Wagner, Zeroth Order optimization) to perform different malicious activities (e.g., data poisoning, misclassify outputs, etc.) on a SHS. Moreover, based on the training and testing phase capabilities of an adversary, we perform white box and black box attacks on a SHS. We evaluate the performance of our work in different SHS settings and medical devices. Our extensive evaluation shows that our proposed adversarial attack can significantly degrade the performance of a ML-based SHS in detecting diseases and normal activities of the patients correctly, which eventually leads to erroneous treatment. A. K. M. Iqtidar Newaz, Nur Imtiazul Haque, Amit Kumar Sikder, Mohammad Ashiqur Rahman, A. Selcuk Uluagac |
GLOBECOM | 2 |