Nadia Niknami

dblp:268/2121 · DBLP profile ↗
← Back
11ranked-venue papers
10as first author
10since 2021 · last 2026
0000-0001-5636-5808ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 6 first-author · 7 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 AdaptiveOnline-IDS: Efficient Intrusion Detection via Lifelong Learning and Knowledge Distillation
Nadia Niknami, Jie Wu 0001
ICC1
2025 An Interpretable Multi-Modal Transformer-Based Intrusion Detection System Utilizing Log Messages and PCAP Files
abstract
Intrusion detection systems (IDS) primarily rely on signature-based approaches, which can fail to detect novel or sophisticated attacks. This paper addresses the underutilized potential of leveraging a multi-modal approach that combines packet capture (PCAP) and log data for anomaly detection. To enhance detection capabilities, we propose an interpretable hybrid neural network architecture, TransIDS, that integrates a packet-based transformer with an efficient transformer-based language model for log messages. The proposed framework extracts semantic vectors from raw log messages and concatenates them with packet embeddings. An attention-based classification model then detects anomalies by determining the importance of each log message and packet for the neural network’s decision. By fusing spatial features from PCAP data with temporal features from log data, TransIDS utilizes this multi-modal data fusion to identify anomalies that might be missed by conventional systems. This approach not only leverages the strengths of two distinct transformer-based architectures but also provides a more comprehensive analysis of network traffic, leading to more effective detection of previously undetected attacks and strengthening overall network security. We use a real testbed for our experiments to validate the effectiveness of our proposed approach.
Nadia Niknami, Vahid Mahzoon, Rajorshi Biswas, Slobadan Vucetic, Jie Wu 0001
MASS1
2025 Enhanced Meta-IDS: Adaptive multi-stage IDS with sequential model adjustments
abstract
Traditional single-machine Network Intrusion Detection Systems (NIDS) are increasingly challenged by rapid network traffic growth and the complexities of advanced neural network methodologies. To address these issues, we propose an Enhanced Meta-IDS framework inspired by meta-computing principles, enabling dynamic resource allocation for optimized NIDS performance. Our hierarchical architecture employs a three-stage approach with iterative feedback mechanisms. We leverage these intervals in real-world scenarios with intermittent data batches to enhance our models. Outputs from the third stage provide labeled samples back to the first and second stages, allowing retraining and fine-tuning based on the most recent results without incurring additional latency. By dynamically adjusting model parameters and decision boundaries, our system optimizes responses to real-time data, effectively balancing computational efficiency and detection accuracy. By ensuring that only the most suspicious data points undergo intensive analysis, our multi-stage framework optimizes computational resource usage. Experiments on benchmark datasets demonstrate that our Enhanced Meta-IDS improves detection accuracy and reduces computational load or CPU time, ensuring robust performance in high-traffic environments. This adaptable approach offers an effective solution to modern network security challenges.
Nadia Niknami, Vahid Mahzoon, Slobadan Vucetic, Jie Wu 0001
High Confid. Comput.1
2024 DeepIDPS: An Adaptive DRL-Based Intrusion Detection and Prevention System for SDN
abstract
Most intrusion detection systems (IDS) are vulnerable to novel attacks and struggle to maintain a balance between high accuracy and a low false positive rate. Furthermore, the relevant features of Distributed Denial of Service (DDoS) attacks in conventional networks may not necessarily apply to the Software-defined network (SDN) environment. Additionally, weak feature selection algorithms can omit critical parameters and result in significant data loss. Although earlier works on network flow analysis using Long Short-Term Memory (LSTM) show excellent ability, they fall short in obtaining deep features from network flow, resulting in lower accuracy. The emergence of Attention Mechanism(AM) and deep reinforcement learning (DRL) present a promising solution for intrusion detection and enhancing security in SDN. AM has the capability to assign varying weights to different network traffic features, enabling IDS to extract and emphasize more crucial information. This paper introduces DeepIDPS, a novel DRL-based network intrusion detection system utilizing a CNN-LSTM approach and Attention Mechanism specifically designed for SDN environments. DeepIDPS demonstrates an exceptional ability for continuous auto-learning within the network context, effectively identifying diverse forms of network intrusions while significantly augmenting both prevention and detection capabilities.
Nadia Niknami, Jie Wu 0001
ICC1
2024 PTN-IDS: Prototypical Network Solution for the Few-shot Detection in Intrusion Detection Systems
abstract
Local Area Networks (LANs), as interconnected networks, are susceptible to numerous security threats. Existing intrusion detection systems (IDS) heavily rely on large, fully-labeled datasets to have accurate detection, facing challenges when only a few malicious samples are available. In addition, previous studies have identified the deterioration of IDS’s performance when the test dataset deviates from the training dataset distribution. To mitigate these issues, we propose a Prototypical Network-based IDS within a meta-learning framework. Our method adopts a Few-Shot Learning (FSL) approach, aiming to distinguish and compare network traffic samples to classify them as either normal or malicious. Notably, our model not only identifies benign or malicious traffic but also accurately identifies the specific types of attacks. We evaluate the effectiveness of our approach in different scenarios for few-shot network intrusion detection using real-world network traffic data. Additionally, we conduct a comprehensive sensitivity analysis to assess the impact of key factors such as model hyperparameters, support set size, attack type distribution, and distance metrics within the prototypical network model.
Nadia Niknami, Vahid Mahzoon, Jie Wu 0001
LCN1
2024 Cyber-AnDe: Cybersecurity Framework With Adaptive Distributed Sampling for Anomaly Detection on SDNs
abstract
By decoupling the control plane and data plane in the software-defined network (SDN), the controller gains a comprehensive global view of the network. The SDN controller samples traffic from all switches to effectively manage data plane traffic. The sampling rate of flow traffic significantly impacts the accuracy of the controller’s decisions. While increasing the sampling rate is desirable for improved detection accuracy, it also escalates resource consumption on both switches and the controller. Hence, it is crucial to carefully manage sampling on switches to fine-tune anomaly detection accuracy. Existing flow sampling solutions often struggle to strike a balance between detection accuracy, sampling rate, and overhead. To address this challenge, we propose a robust cybersecurity framework for anomaly detection on SDNs through traffic flow inspection. Our proposed framework, Cyber-AnDe, integrates adaptive distributed sampling (ADS) with a Reinforcement Learning (RL) agent to enhance anomaly detection accuracy while minimizing the increase in controller overhead. In our framework, the controller leverages information gathered from each sampled traffic flow to determine whether the flow’s state is malicious, suspicious, or benign based on underlying anomaly detection algorithms. Once the flow state is determined, the controller takes the appropriate action with the help of the RL agent. Through extensive simulations and SDN test-bed experiments, we confirm a significant improvement of up to 93% in network traffic-based anomaly detection compared to existing solutions.
Nadia Niknami, Avinash Srinivasan, Jie Wu 0001
IEEE Trans. Inf. Forensics Secur.1
2023 SmartPipe: Intelligently Freezing Layers in Pipeline Parallelism for Distributed DNN Training
abstract
Deep Neural Network (DNN) models have been widely utilized in various applications. However, the growing complexity of DNNs has led to increased challenges and prolonged training durations. Despite the availability of high-performance computing systems, certain DNNs still require several days for successful training. This study aims to address this issue by proposing a method for significantly reducing the training time of deep learning models while maintaining test accuracy. Existing approaches primarily concentrate on optimizing training efficiency through computational and communication overlap/scheduling. In contrast, this research takes a step further by inspiring transfer learning. Transfer learning is a useful way to quickly retrain a model on new data without having to retrain the entire network. During transfer learning, the first layers of the network are frozen while leaving the end layers open to modification. By doing so, computation and communication requirements in these frozen layers are eliminated. This intelligent approach involves freezing some of the specific DNN layers and allocating resources to the remaining active layers during the training process, thereby minimizing DNN training time. To achieve this objective, we propose an intelligently freezing DNN using pipeline parallelism. Through trace-based simulation results, our scheme has demonstrated its effectiveness in efficiently reducing the time cost of a training iteration.
Nadia Niknami, Abdalaziz Sawwan, Jie Wu 0001
ICPADS1
2023 Evaluating Performance of Intrusion Detection Systems under Different Configurations in SDN
abstract
Software Defined Networks (SDN) have been proposed as a possible development for next generation networking technology. In a SDN, Virtual Network Functions (VNFs) are used to replace the functions of traditional middleboxes. All of these VNFs can be controlled from a centralized controller, which comes with its own security concerns. However, there are many benefits that come from having a centralized controller as traffic can be easily controlled from a single point. This makes it interesting to further study security when it concerns SDN. This work looks to test intrusion detection system (IDS) performance under different configurations in a SDN in order to make security in SDN more robust. In this work, we take two IDSs, Snort and Suricata, and test their performance under different configurations and traffic loads. We test four different configurations: single, chain, parallel, and cross. Our findings seem to suggest that the cross configuration has the best performance of these IDS configurations.
Dennis Yeom, Nadia Niknami, Jie Wu 0001
MobiHoc2
2022 A Budged Framework to Model a Multi-round Competitive Influence Maximization Problem
abstract
The concept of competitive influence maximization has attracted considerable research interest in recent years. Modeling the behavior of social network members is a key challenge in this regard. This kind of forwarding occurs from newly activated nodes to their not yet activated neighbors, especially when some competitors try to gain maximum influence over the network. For competitors, the main objective is to find which potential members are most valuable to them and how many resources they should allocate to them in order to get as much influence as possible. Previous studies on competitive influence maximization tended to focus on the single-shot game without considering how budget allocation affects the outcome. We are interested in maximizing the total number of activated nodes through multi-round competitive influence maximization, where each competitor has to determine the locations and budget amount to invest simultaneously and repeatedly within a given total budget. In this paper, we propose a tree-approximate game-theoretical framework and introduce the new measurement as a dynamic weight. This measure allows us to isolate the most influential member with a high degree of accuracy. Our simulation study demonstrates the effectiveness of our approach in solving a multi-round, learning-based CIM problem.
Nadia Niknami, Jie Wu 0001
ICC1
2022 A Defense-Attack Game under Multiple Preferences and Budget Constraints with Equilibrium
abstract
Cyber-security research often focuses on attack-defense games where a strategic attacker seeks to destroy the defender's targets or kill him. In such a game there is a defender who just try to protect himself. In the real world, players can choose to protect themselves as well as kill their opponents to maximize their overall gain. In this case, the player allocates their budget for both defending and attacking actions and decides how well to attack and how well to defend against others. Players should allocate their budgets appropriately for each action throughout multiple rounds when playing such a game. The probabilities of surviving and killing in each round are determined by what happened in the previous rounds and the amount of the remaining budget. Players can continue playing until they die or run out of money. It is possible for the player not to be aware of everything his opponent does. Despite knowing that his opponent is playing according to one of the possible types, he cannot see which action exactly he is taking. Likewise, it may be the case that the player only sees the opponent's action, but does not know what its objective is. To meet this challenge, this paper develops a game where players decide how to allocate resources when they have partial information. For a model with complete information, equilibrium can be found and, as an extension, models with incomplete and imperfect information are also discussed. Our simulation examines how utility changes based on prior beliefs, total budgets, costs, and uncertainty.
Nadia Niknami, Abdalaziz Sawwan, Jie Wu 0001
ICCCN1
2020 A fully spatial personalized differentially private mechanism to provide non-uniform privacy guarantees for spatial databases
Nadia Niknami, Mahdi Abadi, Fatemeh Deldar
Inf. Syst.1