Ferhat Karakoç

dblp:25/10367 · DBLP profile ↗
← Back
16ranked-venue papers
9as first author
8since 2021 · last 2026
0000-0001-6139-6668ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 6 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-authorTheory of computation · 2 · 2 first-authorComputer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Updatable Private Set Intersection and Beyond: Efficient Constructions via Circuit PSI
Ferran Alborch Escobar, Tom Chauvier, Antonio Faonio, Alexandre Fontaine, Ferhat Karakoç, Alptekin Küpçü, Camille Malek, Melek Önen
ACNS (1)5
2025 Privacy Protection Framework for Data Analytics in Management and Orchestration
abstract
Preserving the privacy of data used for analytics in Management and Orchestration (M&O) entails using a variety of methodologies and tactics to protect sensitive data while allowing for effective analysis and decision-making. In 5G network, the Management Data Analytic Function (MDAF) in M&O layer is responsible for performing data analytics by leveraging current and historical network data, including data from the RAN (radio access network), CN (core network), TN (transport network), and other Network Functions (NFs), to provide insights for managing network performance, resource allocation, and policy enforcement. Similar to 5G network, in 6G network, there will be AI-driven management and orchestration mechanism. We call the network analytic function in this mechanism as AI-driven Data Analytic Function (AI-DAF) for performing data analytics. Thus, ensuring that the data used by AI-DAF is managed securely and in accordance with privacy standards is critical to preserving trust, compliance, and security. In this paper, we propose a privacy protection framework for AI-DAF in management and orchestration in 6G network.
Leyli Karaçay, Ferhat Karakoç, Ramin Fouladi
ISNCC2
2025 Enabling Two-Party Secure Computation on Set Intersection
abstract
We propose the first linear secure-computation private set intersection (PSI) protocol computing the following functionality.$P_{X}$inputs a set$X = \lbrace x_{j} \mid 1 \le j \le n_{X}\rbrace$, whereas$P_{Y}$inputs a set$Y = \lbrace y_{i} \mid 1\le i \le n_{Y} \rbrace$and a data set$D_{Y} = \lbrace (d_{i}^{0},d_{i}^{1}) \mid 1 \le i \le n_{Y}\rbrace$. While$P_{Y}$outputs nothing,$P_{X}$outputs$D_{X} = \lbrace d_{i}^{b_{i}} \mid b_{i} = 1 \rm{ if } y_{i} \in X, b_{i} = 0 \rm{ otherwise}\rbrace$. This functionality is generally required when the PSI protocol is used as a part of a larger secure two-party computation protocol. Existing protocols for similar functionalities have a cuckoo table mapping in the functionality, and therefore the output is not directly indexed on the intersection but on the cuckoo table mapping of the intersection, which complicates the application of different secure computation techniques on top of the output. We introduce a conversion technique based on additively homomorphic encryption used in the construction of our PSI protocol as a separate protocol and show that it can be utilized to convert the existing circuit and secure-computation PSI protocols into the protocols realizing the functionality not having the mapping.
Ferhat Karakoç, Alptekin Küpçü
IEEE Trans. Dependable Secur. Comput.1
2024 Fault Tolerant and Malicious Secure Federated Learning
Ferhat Karakoç, Alptekin Küpçü, Melek Önen
CANS (2)1
2024 Threat Modeling of AI-as-a-Service Framework
abstract
Artificial intelligence will be one of the key enablers of 6G technology. Compared to today's networks where we mostly benefit from ubiquitous communication capabilities, 6G is expected to transform the network into a powerfully distributed AI platform and exposes its AI capabilities to consumers. This is expected to be enabled by the AI-as-a-Service (AIaaS) framework. The latter unlocks new possibilities for network management and orchestration in the context of 6G by enabling network service providers to leverage AI capabilities as a service effectively. Thus, it is extremely important for the AIaaS framework to be intelligently protected against potential threats and malicious attacks. In this paper, we performed a comprehensive threat analysis of the AIaaS framework, identifying potential security threats and discussing mitigation strategies.
Utku Gülen, Ömer Faruk Tuna, Boubakr Nour, Zakaria Laaroussi, Leyli Karaçay, Ferhat Karakoç
WiMob6
2023 A security-friendly privacy-preserving solution for federated learning
Ferhat Karakoç, Leyli Karaçay, Pinar Çomak, Utku Gülen, Ramin Fouladi, Elif Ustundag Soykan
Comput. Commun.1
2022 Context-Aware Authentication with Dynamic Credentials using Electricity Consumption Data
abstract
Abstract Industrial IoT (IIoT) era is evolving rapidly in parallel to the progress in Industry 4.0, which leads factories to increase the engagement with external parties through different communication infrastructures. This brings a larger attack surface and requires the development of new security solutions suitable for IIoT systems. Authentication is a key enabler to prevent the attacks that come from the interactions with the outside world components. Though there are proposed authentication schemes for IoT or machine-to-machine (M2M) applications, they cannot be readily applied for IIoT since manufacturing machines have different features and requirements than generic IT and IoT devices. In this paper, context information is proposed to be used for enhancing the authentication process in the IIoT, where instantaneous electricity consumption measured by smart meters is the main context information used as a dynamic authentication credential. Besides, in our method, existing smart meter infrastructure is utilized for both exchanging credentials over an industrial network and verification of the credentials by trusted components like Supervisory Control and Data Acquisition (SCADA) or Energy Management System (EMS). The proposed method also allows the use of other context information as authentication credentials such as temperature and humidity collected by sensors in the manufacturing environment.
Elif Ustundag Soykan, Leyli Karaçay, Zeki Bilgin, Emrah Tomur, Mehmet Akif Ersoy, Ferhat Karakoç, Pinar Çomak
Comput. J.6
2021 Secure Aggregation Against Malicious Users
abstract
Secure aggregation protocols allow anaggregator to compute the sum of multiple users' data in a privacy-preserving manner. Existing protocols assume that users from whom the data is collected, are fully trusted on the correctness of their individual inputs. We believe that this assumption is too strong, for example when such protocols are used for federated learning whereby the aggregator receives all users' contributions and aggregate them to train and obtain the joint model. A malicious user contributing with incorrect inputs can generate model poisoning or backdoor injection attacks without being detected. In this paper, we propose the first secure aggregation protocol that considers users as potentially malicious. This new protocol enables the correct computation of the aggregate result, in a privacy preserving manner, only if individual inputs belong to a legitimate interval. To this aim, the solution uses a newly designed oblivious programmable pseudo-random function. We validate our solution as a proof of concept under a federated learning scenario whereby potential backdoor injection attacks exist.
Ferhat Karakoç, Melek Önen, Zeki Bilgin
SACMAT1
2020 Linear Complexity Private Set Intersection for Secure Two-Party Protocols
Ferhat Karakoç, Alptekin Küpçü
CANS1
2019 SET-OT: A Secure Equality Testing Protocol Based on Oblivious Transfer
abstract
We propose a new secure equality testing (SET) protocol, namely SET-OT, for two-party setting by using a recently introduced Private Set Membership Protocol (PSM) based on Oblivious Transfer (OT) as a building block. We designed our equality test in such a way that the test result will not be revealed in clear text, which is desired in several cryptographic protocols. The advantage of using OT is that with the help of OT Extension (OTE) protocols, the cost of asymmetric operations per OT operations reduces when the number of OT executions increases. This makes our protocol competitive especially for the cases where the number of equality tests to be invoked is high. When the number of equality test increases, the time complexity of SET-OT converges to one asymmetric key decryption operation, this operation is the dominant part in terms of computational cost. SET-OT has a better performance in terms of the communication rounds and data transmission cost than state-of-the-art solutions: three communication rounds and 2.9 KB of data transmission are the communication costs of performing equality testing protocol for 20-bit string pairs. In addition to our complexity analysis, we also present test results to validate our claim on performance.
Ferhat Karakoç, Majid Nateghizad, Zekeriya Erkin
ARES1
2016 Universal Forgery and Key Recovery Attacks on ELmD Authenticated Encryption Algorithm
Aslí Bay, Oguzhan Ersoy, Ferhat Karakoç
ASIACRYPT (1)3
2015 AKF: A key alternating Feistel scheme for lightweight cipher designs
Ferhat Karakoç, Hüseyin Demirci, A. Emre Harmanci
Inf. Process. Lett.1
2013 Biclique cryptanalysis of LBlock and TWINE
Ferhat Karakoç, Hüseyin Demirci, A. Emre Harmanci
Inf. Process. Lett.1
2012 Biclique Cryptanalysis of TWINE
Mustafa Çoban, Ferhat Karakoç, Özkan Boztas
CANS2
2012 Fixed Points of Special Type and Cryptanalysis of Full GOST
Orhun Kara, Ferhat Karakoç
CANS2
2012 Impossible Differential Cryptanalysis of Reduced-Round LBlock
Ferhat Karakoç, Hüseyin Demirci, A. Emre Harmanci
WISTP1