EDBT 2026 Demo / reviewers in the wild / expert
Ahmad Salehi S.
dblp:241/2715 · also Ahmad Salehi Shahraki
· DBLP profile ↗
19ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0003-2115-6269ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 3 first-author · 7 since 2021Security and privacy · 5 · 1 first-author · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ZAD-ML: Dual-layer Learning for zero-Day attack detection in multivariate time series
Edward Kwadwo Boahen, Ahmad Salehi S. |
Future Gener. Comput. Syst. | 2 |
| 2026 | A Fault-Tolerant Sharding Mechanism for Resilience and Scalability in Blockchain Using Backup PoolabstractWith the development of blockchain technology, an increasing number of devices are joining the network and generating numerous transactions, which pose significant performance and scalability challenges to blockchain networks. Sharding technology is one solution that improves throughput by parallelising transaction validation and block generation, thereby alleviating this challenge. However, during the process of dividing shard groups in large-scale networks, the uneven distribution of malicious nodes or dynamic changes in joined nodes may lead to failures in the availability and liveness of shard groups. This paper proposes an enhanced sharding blockchain system that improves fault tolerance and reliability to ensure high shard group performance, scalability, and reliability. We also propose the concept of a backup pool and achieve the detection and recovery of faulty shards through pre-deployed backup pool nodes and redesigned consensus algorithms. After a thorough security analysis, we conclude that the proposed sharding blockchain system can increase the Resilience of shard groups from 33.3% to 66.6%. Additionally, we evaluate the proposed system, and the results show that it ensures the security, reliability, and high performance of sharding while increasing the scalability of the system’s network nodes from 10 4 to 10 6 compared to existing sharding blockchains. Ahmad Salehi S., Naveen K. Chilamkurti |
Future Gener. Comput. Syst. | 2 |
| 2025 | PRIV-HFL: Privacy-Preserving and Robust Federated Learning for Heterogeneous Clients Against Data Reconstruction AttacksabstractFederated Learning (FL) is a machine learning paradigm that allows multiple local clients to collaboratively train a global model by sharing their model parameters instead of private data, thereby mitigating privacy leakage. However, recent studies have shown that gradient-based Data Reconstruction Attack (DRA) can still expose private information by exploiting model parameters from local clients. Existing privacy-preserving FL strategies provide some defense against these attacks, but at the cost of significantly reduced model accuracy. Moreover, the issue of client heterogeneity, particularly in Non-Identical and Independent Distributions (Non-IID) clients, further exacerbates these FL methods, resulting in drifted global models, slower convergence, and decreased performance. This study aims to address the two main challenges of FL: Non-IID data and client privacy through DRA. To this end, it leverages the lagrangian duality approach and incorporates a generator model to enable Knowledge Distillation (KD) among clients. By facilitating improved local model performance through inter-client knowledge transfer, the proposed method aims to simultaneously address the practical challenges commonly encountered by FL systems. Our study demonstrates a remarkable improvement in model accuracy, with KD boosting it by up to $15 \%$ on CIFAR-10 and MNIST classification tasks in Non-IID client settings. Furthermore, we propose an aggregation algorithm that inherently preserves client data privacy during the training phase, offering resilience against DRA. Mohammadreza Najafi, Hooman Alavizadeh, Ahmad Salehi S., A. S. M. Kayes, Wenny Rahayu |
RAID | 3 |
| 2025 | Securing cross-domain data access with decentralized attribute-based access controlabstractIn attribute-based access control (ABAC), access to resources depends on the specific attributes of the entity requesting access. Existing ABAC models primarily depend on local attribute authorities to define and confirm attributes, which makes it challenging to support access decisions cross-domains without introducing centralization. Centralized solutions often conflict with individual domains’ security, privacy, and control requirements and, if compromised for any reason, can impact access to large datasets across participating domains. This paper introduces a novel access control model for cross-domain environments that significantly reduces central control. Our decentralized ABAC (D-ABAC) model uses group signature techniques to exchange attribute information securely and privately within cross-domains. Each domain maintains its own policies and attribute authorities, reducing the need for global trust or centralization to mutual trust between attribute authorities. We further design and implement a proof-of-concept system to demonstrate the practical feasibility of our proposed system for the collaborative and secure sharing of healthcare data in cross-domain environments. The proposed system model enhances security, scalability, and privacy in cross-domain settings, making it suitable for sensitive environments such as healthcare. Ahmad Salehi S., Carsten Rudolph, Hooman Alavizadeh, A. S. M. Kayes, Wenny Rahayu, Zahir Tari |
Ad Hoc Networks | 1 |
| 2025 | Social network botnet attack mitigation model for cloudabstractOnline Social Network (OSN) botnet attacks pose a growing threat to the cloud environment and reduce the services’ availability and reliability for users by launching distributed denial of service (DDoS) attacks on crucial servers in the cloud. These attacks involve the deployment of sophisticated botnets that exploit the interconnected nature of social networks to identify targets, exploit vulnerabilities, and launch attacks. The prevalence and impact of these botnet-driven attacks have recently been studied. Although the detection of these botnet attacks is still a challenging process, it remains crucial to gain a comprehensive understanding of and evaluate the best defense strategies against botnet attacks. This evaluation can be further utilized to formulate effective defense plans to mitigate the impact of such botnet attacks. In this paper, we first investigate the properties of OSN botnet attack stages that eventually lead to launching DDoS attacks toward a cloud system. Then, we formalize a defensive model using a sequential game model to analyze both the attacker’s and defenders’ best equilibrium strategies for the proposed botnet attack scenario. Moreover, we formulate optimal strategies for the defender against various attack strategies. Our experiments reveal the best defense strategies against various attack rates to maintain cloud functionality. Finally, we discuss possible countermeasures for these OSN botnet threats. Hooman Alavizadeh, Ahmad Salehi S., A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon |
Comput. Networks | 2 |
| 2025 | Physical layer security techniques for grant-free massive Machine-Type Communications in 5G and beyond: A survey, challenges, and future directionsabstractThe future of smart cities, industrial automation, and connected vehicles is heavily reliant on advanced communication technologies. These technologies, particularly massive Machine-Type Communication (mMTC), are the backbone of the many connected devices required for these applications. Grant -free access in 5G and beyond, while enhancing transmission efficiency by eliminating the need for permission requests, also introduces significant security risks. These risks, such as unauthorised access, data interception, and interference due to the absence of centralised control, are of paramount importance. Physical layer security (PLS) techniques, with their ability to exploit the unique properties of wireless channels to bolster communication security, offer a promising solution. This paper provides a comprehensive review of PLS techniques for securing grant-free mMTC, comparing different approaches and exploring the challenges of their integration. Our findings lay the groundwork for future research and the practical implementation of advanced security solutions in grant-free mMTC, a development that will also enhance the security of advanced 5G and 6G networks. Uchenna P. Enwereonye, Ahmad Salehi S., Hooman Alavizadeh, A. S. M. Kayes |
Comput. Networks | 2 |
| 2025 | Robust Multiuser Physical Layer Security for Grant-Free mMTC in Beyond 5G/6G NetworksabstractIndustry 5.0 introduces human-machine collaboration and resilient automation, demanding secure, low-latency connectivity for ultra-dense Industrial IoT (IIoT). Grant-free massive machine-type communications (mMTC) supports such connectivity but faces challenges including dense multiuser access, passive eavesdropping, and imperfect channel state information (CSI), which undermine physical layer security (PLS). This paper proposes a robust and low-complexity multiuser PLS scheme tailored for grant-free mMTC under CSI uncertainty. The scheme leverages dynamic user clustering based on spatial correlation and real-time interference to enable scalable, interference-aware beamforming. Furthermore, a joint optimisation of receive beamforming and adaptive artificial noise injection is performed, and enhanced by a regularised minimum mean square error (MMSE) framework to mitigate bounded CSI errors. Simulation results show that the scheme consistently outperforms existing benchmarks across secrecy capacity, bit error rate, and secrecy outage probability under different channel models, together with analyses of SOP sensitivity to CSI error and scalability to dense users/eavesdroppers, confirms its robustness, efficiency, and applicability to large-scale, secure IIoT communications in beyond 5G/6G networks aligned with Industry 5.0 requirements. Uchenna P. Enwereonye, Ahmad Salehi S., Hooman Alavizadeh, A. S. M. Kayes |
IEEE Internet Things J. | 2 |
| 2025 | Safeguarding Individuals and Organizations From Privacy Breaches: A Comprehensive Review of Problem Domains, Solution Strategies, and Prospective Research DirectionsabstractPrivacy breaches have become increasingly prevalent, exposing individuals to significant risks. These breaches can have far-reaching consequences, including identity theft and life-threatening situations. Several studies have analyzed data and privacy breaches and presented detection or prevention techniques to combat these breaches. However, because the number and type of breaches have significantly increased, these studies have become less relevant or outdated. Previous research on data and privacy breaches compared the techniques and results of various studies. However, none comprehensively analyzed the type of information and the level and severity of compromise that occurred after such breaches. In this survey, we examine the fundamental concepts of privacy and security and define the security incidents and data/privacy breaches. We propose a set of criteria to evaluate the published studies on privacy breaches. We thoroughly investigate the problem domains and security-related concerns considering six recent breach cases in Australia, elucidating the critical challenges and issues associated with privacy breaches. We comprehensively review and outline the trends and severity of security incidents and data/privacy breaches from 2020 to 2024. Additionally, we review the current state-of-the-art countermeasures to safeguard against these breaches. Finally, we identify an open research direction to develop an artificial intelligence (AI)-powered security framework. This framework aims to analyze cyber threats, characterize attackers’ behaviors, distinguish between legitimate and illegitimate privacy policies, and restrict access to individuals’ information. Overall, this survey will help organizations to reassess and update their security and privacy measures. A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon, Ahmad Salehi S., Hooman Alavizadeh |
IEEE Internet Things J. | 4 |
| 2025 | RACEMAN: Cross-Platform Intrusion Detection in Online Social NetworksabstractOnline Social Networks (OSNs) face various security threats, including account compromisation, where attackers seize control over legitimate user accounts and create fake profiles for nefarious purposes. The dynamic and open nature of OSNs presents unique challenges for cybersecurity, particularly in detecting unauthorized access and malicious activities such as phishing attacks, spamming, and spreading misinformation associated with account compromisation. Traditional intrusion detection systems (IDS) in OSNs often miss attacks or generate false positives due to static thresholds, delayed responses, and poor real-time data handling. These limitations often result in missed detections or false positives during sudden shifts in user activity patterns or emerging attack vectors. We introduce$RACEMAN$, an adaptive IDS designed explicitly for the OSN environment to address this. To enhance adaptability,$RACEMAN$incorporates emergency strategies such as dynamic threshold adjustments based on real-time network traffic analysis and early stopping mechanisms triggered by anomalous behavior spikes, enabling rapid adaptation to changing threat landscapes.$RACEMAN$leverages real-time OSN interactions to continuously update its metamorphic relations, ensuring an up-to-date understanding of normal user behaviour versus potential intrusions. This system utilises advanced semantic analysis to accurately represent user interactions. It generates diverse test cases using genetic algorithms and reinforcement learning to simulate user scenarios and potential intrusion methods. These test cases undergo input transformations to realistically mimic intrusion attempts while maintaining semantic integrity. The system's responses to these test cases are evaluated against expected behaviours defined by the updated metamorphic relations.$RACEMAN$utilizes statistical analysis, Multi-view Convolutional Neural Networks (MVCNN), and rule-based systems for intrusion classification. Our collaborative and distributed IDS approach enhances detection capabilities by promoting knowledge sharing across multiple systems and ensuring scalability without central points of failure. We evaluated$RACEMAN$using six publicly available datasets from Facebook, Google+, Twitter, linkedIn, Youtube and Reddit where it demonstrated a high accuracy rate of 98.85%, outperforming other models such as Convolutional Neural Network (CNN-85.67%), Artificial Neural Network (ANN-86.63%), and Random Forest (RF-78.26%). Edward Kwadwo Boahen, Ahmad Salehi S., Carsten Rudolph, Zahir Tari, Joseph K. Liu |
IEEE Trans. Serv. Comput. | 2 |
| 2024 | A Novel Endorsement Protocol to Secure BFT-Based Consensus in Permissionless BlockchainabstractPermissionless blockchain technology offers numerous potential benefits for decentralised applications, such as security, transparency, and openness. BFT-based consensus mechanisms are widely adopted in the permissioned blockchain to meet the high scalability requirements of the network. Sybil attacks are one of the most potential threats when applying BFT-based consensus mechanisms in permissionless blockchain due to the lack of effective verification mechanisms for participants' identities. This paper presents a novel endorsement-based bootstrapping protocol with a signature algorithm that offers a streamlined, scalable identity endorsement and verification process. This approach effectively safeguards the BFT-based consensus mechanism against Sybil attacks. Using our proposed method, we have conducted thorough security analyses and simulation experiments to assess security, robustness, and scalability advantages in large-scale networks. Our results demonstrate that the scheme can effectively address the identity verification challenges when applying BFT-based consensus in a permissionless blockchain. Ahmad Salehi S., Naveen K. Chilamkurti |
WCNC | 2 |
| 2024 | IoTPredictor: A security framework for predicting IoT device behaviours and detecting malicious devices against cyber attacks
Rudri Kalaria, A. S. M. Kayes, Wenny Rahayu, Eric Pardede, Ahmad Salehi S. |
Comput. Secur. | 5 |
| 2023 | DACP: Enforcing a dynamic access control policy in cross-domain environmentsabstractEnabling hybrid authorisations to enforce dynamic access control policy from single-domain to cross-domain environments (CDEs) is important for distributed services. However, traditional Attribute-Based Access Control (ABAC) models are incompatible with CDEs. To fill this gap, approaches that apply cryptographic primitives, e.g., attribute-based encryption (ABE), have been proposed. The computation and storage overhead in most ABE constructions is non-negligible and increases with the complexity of the associated policies. In addition, most access control policy systems enforce authorisation policies in a centralized way, raising serious security and privacy issues. In this paper, we introduce DACP – a practical Dynamic Access Control Policy system supporting dynamic cross-domain authorisation. DACP combines traditional ABAC approach and a novel cryptographic primitive Attribute-based group signature (ABGS). ABAC is used for the access control decision and policy enforcement according to the user’s attributes whereas ABGS is used for managing the user’s attributes between users and authorities. Thus, the user’s attributes are securely distributed along with the access structure in CDEs while preserving the user’s privacy. We present the concrete design and implementation of DACP, and evaluate it in real-world settings. The evaluation shows that DACP is practical and efficient in CDEs. Ahmad Salehi S., Runchao Han, Carsten Rudolph, Marthie Grobler |
Comput. Networks | 1 |
| 2021 | Authentication and Access Control in 5G Device-to-Device CommunicationabstractDevice-to-device (D2D) communication is one of the most recent advancements in wireless communication technology. It was introduced in cellular communication technology by the 3rdGeneration Partnership Project (3GPP) to lay a foundation for the evolving 5G architecture. It has now emerged as a promising technology for proximate devices. It enables proximate devices to communicate directly without the involvement of a third party network infrastructure. Researchers are analysing various methods to facilitate the smooth integration of D2D communication technology into the existing network system architecture. This paper lists all the different possible modes of operation in D2D communication based on the varying use-case scenarios and highlights the security and privacy requirements for D2D communication. Some of the recent authentication proposals for D2D communication technology are further reviewed, and their security and privacy capabilities are analysed. Apart from authentication, we also reviewed some recent proposals of access control in D2D and highlighted the security issues addressed. We then identified the open issues that prevail in implementing D2D technology in a real-world scenario for future researchers, emphasising the existing authentication and access control techniques in D2D communication. Jithu Geevargheese Panicker, Ahmad Salehi S., Carsten Rudolph |
TrustCom | 2 |
| 2021 | Decentralized Policy Information Points for Multi-Domain EnvironmentsabstractAccess control models have been developed to control authorized access to sensitive resources. This control of access is important as there is now a need for collaborative resource sharing between multiple organizations over open environments like the internet. Although there are multiple access control models that are being widely used, these models are providing access control within a closed environment i.e. within the organization using it. These models have restricted capabilities in providing access control in open environments. Attribute-Based Access Control (ABAC) has emerged as a powerful access control model to bring fine-grained authorization to organizations which possess sensitive data and resources and want to collaborate over open environments. In an ABAC system, access to resources that an organization possess can be controlled by applying policies on attributes of the users. These policies are conditions that need to be satisfied by the requester in order to gain access to the resource. In this paper, we provide an introduction to ABAC and by carrying forward the architecture of ABAC, we propose a Decentralized Policy Information Point (PIP) model. Our model proposes the decentralization of PIP, which is an entity of the ABAC model that allows the storage and query of user-attributes and enforces fine-grained access control for controlling the access of sensitive resources over multiple-domains. Our model makes use of the concept of a cryptographic primitive called Attribute Based Signature (ABS) to keep the identities of the users involved, private. Our model can be used for collaborative resource sharing over the internet. The evaluation of our model is also discussed to reflect the application of the proposed decentralized PIP model. M. Ridwanur Rahman, Ahmad Salehi S., Carsten Rudolph |
TrustCom | 2 |
| 2020 | Attribute-Based Data Access Control for Multi-Authority SystemabstractAccess control and authorization in universal basic services is one of the main security issues in distributed systems. In particular, access control in distributed systems, such as in healthcare systems, are crucial to improve facility safety and security. This can lead to the provision of better quality of life and contribute to a healthier future. In order to provide better services, it is necessary to develop a suitable and acceptable authorization system to prevent unauthorized access to data shared in these highly dynamic distributed environments. In practice, several types of service providers, institutes, and authorities generate a variety of data in a shared environment via central authority for their entities. Generally, the use of a central authority introduces several security and privacy issues due to the increased risk if the central authority is compromised. To address this issue, several traditional access control models have been developed and introduced. These models, however, have raised several critical security issues, and there is often a need to combine it with a cryptographic approach to offer and create better access control service to users in multi-domains. To achieve this, we provide an appropriate solution to this issue. In this paper, we introduce an access control policy model for the multi-authority system, which enables attribute authorities to control the security setting. We present a new access control framework for a dynamic authorization model that uses Attribute-Based Access Control (ABAC) and digital signature. We first define and present our system and then formalize the construction of the proposed system. Our system provides flexible access control and enhanced privacy in applied and distributed environments. Ahmad Salehi S., Carsten Rudolph, Marthie Grobler |
TrustCom | 1 |
| 2019 | A Dynamic Cross-Domain Access Control Model for Collaborative Healthcare Application
Ahmad Salehi S., Carsten Rudolph, Marthie Grobler |
IM | 1 |
| 2016 | IEEE 802.15.6 standard in wireless body area networks from a healthcare point of viewabstractThe first standard supporting communication in wireless body area networks (WBANs) is IEEE 802.15 Task Groups 6 (TG6). IEEE 802.15.6 is a standard for short-range, low power, and highly reliable wireless communication in, on and around the human body. It supports a wide range of applications in body area networks (BANs) such as healthcare services. In WBANs, nodes are partitioned into a physical (PHY) layer and a medium access control (MAC) layer. In this paper, the MAC and PHY layers are investigated. The different types of communication supported by this standard, such as narrowband (NB), ultra-wideband (UWB), and human body communication (HBC), are further defined here. The security aspect of the standard is also discussed and investigated. Finally, using the standard and existing literature in WBAN, open issues and challenges are identified as a source of future study. Ahmad Salehi S., Mohammad Abdur Razzaque, Inmaculada Tomeo-Reyes, Nasir Hussain |
APCC | 1 |
| 2016 | Efficient high-rate key management technique for wireless body area networksabstractWireless body area network (WBAN) is an emerging technology that focuses on healthcare monitoring in indoor and outdoor areas. WBAN technology allows medical sensors to collect vital physiological data and transfer it from a source to a destination via low-energy communication. To be able to encrypt and decrypt healthcare data, it is important for medical sensing and health-related devices to generate and extract the same secret keys at both end points. Recent studies show that two medical sensing devices can generate and share secret keys using their wireless channel properties, such as the received signal strength indicator (RSSI). However, existing approaches have low bit rate values and the key entropy is insufficient. These limitations pose a major threat to WBANs and must be addressed. In this paper, we first provide an overview of existing studies related to key extraction between two devices. We then describe the basic principles of wireless channel properties and the key parameters needed to generate secret keys. Finally, we propose a practical scheme to generate secret keys while avoiding information reconciliation and privacy amplification. The proposed scheme can generate 128 symmetric secret keys in a short time frame, and allows to secure the communication between sensor devices and improve the quality of services in WBANs. Ahmad Salehi S., Mohammad Abdur Razzaque, Inmaculada Tomeo-Reyes, Nasir Hussain, Vahid Kaviani |
APCC | 1 |
| 2015 | Understanding data flow and security requirements in wireless Body Area Networks for healthcareabstractThe Body Area Network (BAN) is an emerging technology that focuses on monitoring physiological data in, on and around the human body. BAN technology permits wearable and implanted sensors to collect vital data about the human body and transmit it to other nodes via low-energy communication. In this paper, we investigate interactions in terms of data flows between parties involved in BANs under four different scenarios targeting outdoor and indoor medical environments: hospital, home, emergency and open areas. Based on these scenarios, we identify data flow requirements between BAN elements such as sensors and control units (CUs) and parties involved in BANs such as the patient, doctors, nurses and relatives. Identified requirements are used to generate BAN data flow models. Petri Nets (PNs) are used as the formal modelling language. We check the validity of the models and compare them with the existing related work. Finally, using the models, we identify communication and security requirements based on the most common active and passive attack scenarios. Ahmad Salehi S., Seyit Ahmet Çamtepe, Dhammika Jayalath |
HealthCom | 1 |