EDBT 2026 Demo / reviewers in the wild / expert
Mert Nakip
dblp:275/5790
· DBLP profile ↗
14ranked-venue papers
7as first author
13since 2021 · last 2026
0000-0002-6723-6494ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 6 · 2 first-author · 6 since 2021Computer networks · 4 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A predictive neural network architecture for early detection of low-rate cyberattacksabstractLow-Rate Denial of Service (LDoS) attacks pose a significant challenge to IoT networks due to their subtle and prolonged nature, often evading traditional intrusion detection systems. This paper presents IDQS (Intrusion Detection via QoS Prediction), a lightweight and proactive framework for early LDoS attack detection. IDQS integrates two new key components: (i) RTP-QoS, a Recurrent Trend Predictive Neural Network that learns and forecasts future Quality of Service (QoS) based on historical traffic patterns, and (ii) PDM, a Pairwise Decision Model that evaluates discrepancies between predicted and actual QoS to identify potential attacks. Evaluated on the public SDN-SlowRate-DDoS and CIC-IDS2017 datasets, IDQS respectively achieves over 79% and 91% detection accuracy across most attack scenarios with high recall and low false negatives, while maintaining an end-to-end inference time of just 0.28 s. The results demonstrate the effectiveness and efficiency of IDQS for real-time deployment in resource-constrained IoT environments. Mert Nakip |
Knowl. Based Syst. | 1 |
| 2026 | Self-supervised online learning algorithm for rTPNN to reduce false alarms in fire detectionabstractCommercial fire detectors often suffer from false positive alarms due to benign environmental variations, such as cooking odors, humidity, and smoke. In order to address this issue, we develop a self-adapting fire detection system with Sample & Sensor Selective Self Online Learning Algorithm (4-SOLA). This system is comprised of Recurrent Trend Predictive Neural Network (rTPNN) enhanced with 4-SOLA for a multi-sensor fire detector. The rTPNN model processes sensor data and makes decisions providing a real-time detection while 4-SOLA combines and orchestrates supervised transfer learning based on human feedback and self-learning using unlabeled and precisely selected sensor data. The proposed system is evaluated using two public datasets, namely the NIST indoor fire dataset and the EN 54 test room dataset. Results show that the rTPNN enhanced with 4-SOLA is the best performing model among nine different models, achieving a balanced performance of 0.75 TPR and 0.90 TNR on the NIST dataset, and 0.97 TPR and 0.94 TNR on the EN 54 dataset when human feedback is fully available. The rTPNN enhanced with 4-SOLA system demonstrates great potential for applications beyond fire detection, particularly for time-series systems that require adaptation to constantly updating data. Mert Nakip, Nur Kelesoglu, Taylan Mert, Cüneyt Güzelis |
Knowl. Based Syst. | 1 |
| 2024 | An Associated Random Neural Network Detects Intrusions and Estimates Attack GraphsabstractCyberattacks, especially Botnet Distributed Denial of Service (DDoS), increasingly target networked systems, compromise interconnected nodes by constantly spreading malware. In order to prevent these attacks in their early stages, which includes stopping the spread of malware, it is vital to identify compromised nodes and successfully predict potential attack paths. To this end, this paper proposes a novel system based on an Associated Random Neural Network (ARNN) that simultaneously detects intrusion at the network-level and estimates the network attack graph. In this system, ARNN is trained online to minimize problem-specific multi-task loss so that it identifies compromised network nodes, while the neural network connection weights also estimate the attack path. The performance of the method is calculated using the Kitsune attack dataset, showing that the method achieves a recall rate above 0.95 in estimating the network attack graph, and provides a near-perfect classification of compromised nodes. The ARNN-based system for dynamic and continuous estimation of compromised nodes and network attack graphs, can pave the way for enhancing security measures, and stopping Botnet DDoS attacks from spreading in networked systems. Mert Nakip, Erol Gelenbe |
MASCOTS | 1 |
| 2024 | Deep Learning Intrusion Detection and Mitigation of DoS AttacksabstractInternet of Things (IoT) networks are highly vulnerable to common network DoS and DDoS attacks, which flood limited system resources or IoT devices, overwhelming them with large numbers of attack packets. In order to mitigate such attacks, this paper develops a lightweight yet effective Intrusion Detection and Prevention System (IDPS), that sequentially detects and mitigates the attack via a Deep Random Neural Network (DRNN) and a Drop-Idle-Repeat process. The IDPS is evaluated for UDP Floods, attacks on an experimental test-bed. The results show that UDP Flood attacks can be mitigated with the proposed IDPS, allowing the system to continue routine operations, and resume communications when the attack ends. Mohammed Nasereddin, Mert Nakip, Erol Gelenbe |
MASCOTS | 2 |
| 2024 | Online Self-Supervised Deep Learning for Intrusion Detection SystemsabstractThis paper proposes a novel Self-Supervised Intrusion Detection (SSID) framework, which enables a fully online Deep Learning (DL) based Intrusion Detection System (IDS) that requires no human intervention or prior off-line learning. The proposed framework analyzes and labels incoming traffic packets based only on the decisions of the IDS itself using an Auto-Associative Deep Random Neural Network, and on an online estimate of its statistically measured trustworthiness. The SSID framework enables IDS to adapt rapidly to time-varying characteristics of the network traffic, and eliminates the need for offline data collection. This approach avoids human errors in data labeling, and human labor and computational costs of model training and data collection. The approach is experimentally evaluated on public datasets and compared with well-known machine learning and deep learning models, showing that this SSID framework is very useful and advantageous as an accurate and online learning DL-based IDS for IoT systems. Mert Nakip, Erol Gelenbe |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Real-Time Cyberattack Detection with Offline and Online LearningabstractThis paper presents several novel algorithms for real-time cyberattack detection using the Auto-Associative Deep Random Neural Network. Some of these algorithms require offline learning, while others allow the algorithm to learn during its normal operation while it is also testing the flow of incoming traffic to detect possible attacks. Most of the methods we present are designed to be used at a single node, while one specific method collects data from multiple network ports to detect and monitor the spread of a Botnet. The evaluation of the accuracy of all these methods is carried out with real attack traces. The novel methods presented here are compared with other state-of-the-art approaches, showing that they offer better or equal performance, with lower learning times and shorter detection times, as compared to the existing state-of-the-art approaches. Erol Gelenbe, Mert Nakip |
LANMAN | 2 |
| 2023 | Measurement Based Evaluation and Mitigation of Flood Attacks on a LAN Test-BedabstractThe IoT is vulnerable to network attacks, and Intrusion Detection Systems (IDS) can provide high attack detection accuracy and are easily installed in IoT Servers. However, IDS are seldom evaluated in operational conditions which are seriously impaired by attack overload. Thus a Local Area Network testbed is used to evaluate the impact of UDP Flood Attacks on an IoT Server, whose first line of defence is an accurate IDS. We show that attacks overload the multi-core Server and paralyze its IDS. Thus a mitigation scheme that detects attacks rapidly, and drops packets within milli-seconds after the attack begins, is proposed and experimentally evaluated. Mohammed Nasereddin, Mert Nakip, Erol Gelenbe |
LCN | 2 |
| 2023 | Decentralized Online Federated G-Network Learning for Lightweight Intrusion DetectionabstractCyberattacks are increasingly threatening net-worked systems, often with the emergence of new types of unknown (zero-day) attacks and the rise of vulnerable devices. uch attacks can also target multiple components of a Supply Chain, which can be protected via Machine Learning (ML)-based Intrusion Detection Systems (IDSs). However, the need to learn large amounts of labelled data often limits the applicability of ML-based IDSs to cybersystems that only have access to private local data, while distributed systems such as Supply Chains have multiple components, each of which must preserve its private data while being targeted by the same attack To address this issue, this paper proposes a novel Decentralized and Online Federated Learning Intrusion Detection (DOF-ID) architecture based on the G-Network model with collaborative learning, that allows each IDS used by a specific component to learn from the experience gained in other components, in addition to its own local data, without violating the data privacy of other components. The performance evaluation results using public Kitsune and Bot-loT datasets show that DOF -ID significantly improves the intrusion detection performance in all of the collaborating components, with acceptable computation time for online learning. Mert Nakip, Baran Can Gül, Erol Gelenbe |
MASCOTS | 1 |
| 2022 | G-Networks Can Detect Different Types of CyberattacksabstractMalicious network attacks are a serious source of concern, and machine learning techniques are widely used to build Attack Detectors with off-line training with real attack and non-attack data, and used online to monitor system entry points connected to networks. Many machine learning based Attack Detectors are typically trained to identify specific types attacks, and the training of such algorithms to cover several types of attacks may be excessively time consuming. This paper shows that G-Networks, which are queueing networks with product form solution and special customers such as negative customers and triggers, can be trained just with “non-attack” traffic, can accurately detect several different attack types. This is established with a special case of G-Networks with triggerred customer movement. A DARPA attack and non-attack traffic repository is used to train and test the the G-Network, yielding comparable or clearly better accuracy than most known attack detection techniques. Erol Gelenbe, Mert Nakip |
MASCOTS | 2 |
| 2022 | Dynamic Automatic Forecaster Selection via Artificial Neural Network Based Emulation to Enable Massive Access for the Internet of Things
Mert Nakip, Erdem Çakan, Volkan Rodoplu, Cüneyt Güzelis |
J. Netw. Comput. Appl. | 1 |
| 2022 | Improving Massive Access to IoT GatewaysabstractIoT networks handle incoming packets from large numbers of IoT Devices (IoTDs) to IoT Gateways. This can lead to the IoT Massive Access Problem that causes buffer overflow, large end-to-end delays and missed deadlines. This paper analyzes a novel traffic shaping method named the Quasi-Deterministic Traffic Policy (QDTP) that mitigates this problem by shaping the incoming traffic without increasing the end-to-end delay or dropping packets. Using queueing theoretic techniques and extensive data driven simulations with real IoT datasets, the value of QDTP is shown as a means to considerably reduce congestion at the Gateway, and significantly improve the IoT network’s overall performance. Erol Gelenbe, Mert Nakip, Tadeusz Czachórski |
Perform. Evaluation | 2 |
| 2021 | MIRAI Botnet Attack Detection with Auto-Associative Dense Random Neural NetworkabstractInternet connected IoT devices have often been particularly vulnerable to Botnet attacks of the Mirai family in recent years. Thus we develop an attack detection scheme for Mirai Botnets, using the Auto-Associative Dense Random Neural Network that has recently been successful for other attacks such as the SYN attack. The resulting method is trained with normal traffic and tested with attack traffic, and shown to result in high accuracy detection of attacks with low false alarms. The approach is compared on the same data set with two other common Machine learning methods (Lasso and KNN) and shown to have higher accuracy, and much lower computation times than KNN and slightly higher (but comparable) computation times with respect to Lasso. Mert Nakip, Erol Gelenbe |
GLOBECOM | 1 |
| 2021 | Diffusion Analysis Improves Scalability of IoT Networks to Mitigate the Massive Access ProblemabstractA significant challenge of IoT networks is to offer Quality of Service (QoS) and meet deadline requirements when packets from a massive number of IoT devices are forwarded to an IoT gateway. Many IoT devices tend to report their data to their wired or wireless network gateways at closely correlated instants of time, leading to congestion known as the Massive Access Problem (MAP), which increases the probability that the IoT data will not meet its required deadlines. Since IoT data loses much of its value if it arrives to destination beyond a required deadline, MAP has been extensively studied in the literature. Thus we first take a queueing theoretic view of the problem, and also use a Diffusion Approximation to gain insight into the IoT traffic statistics that affect MAP. Then we introduce the Quasi-Deterministic Transmission Policy (QDTP) which significantly alleviates MAP when the average traffic rate grows beyond a given level and substantially reduces the probability that IoT data deadlines are missed. The results are validated using real IoT data which has been placed in IP packets for transmission. Erol Gelenbe, Mert Nakip, Dariusz Marek, Tadeusz Czachórski |
MASCOTS | 2 |
| 2020 | A Multiscale Algorithm for Joint Forecasting-Scheduling to Solve the Massive Access Problem of IoTabstractThe massive access problem of the Internet of Things (IoT) is the problem of enabling the wireless access of a massive number of IoT devices to the wired infrastructure. In this article, we describe a multiscale algorithm (MSA) for joint forecasting-scheduling at a dedicated IoT gateway to solve the massive access problem at the medium access control (MAC) layer. Our algorithm operates at multiple time scales that are determined by the delay constraints of IoT applications as well as the minimum traffic generation periods of IoT devices. In contrast with the current approaches to the massive access problem that assume random arrivals for IoT data, our algorithm forecasts the upcoming traffic of IoT devices using a multilayer perceptron architecture and preallocates the uplink wireless channel based on these forecasts. The multiscale nature of our algorithm ensures scalable time and space complexity to support up to 6650 IoT devices in our simulations. We compare the throughput and energy consumption of MSA with those of reservation-based access barring (RAB), priority based on average load (PAL), and enhanced predictive version burst-oriented (E-PRV-BO) protocols, and show that MSA significantly outperforms these beyond 3000 devices. Furthermore, we show that the percentage control overhead of MSA remains less than 1.5%. Our results pave the way to building scalable joint forecasting-scheduling engines to handle a massive number of IoT devices at IoT gateways. Volkan Rodoplu, Mert Nakip, Deniz Türsel Eliiyi, Cüneyt Güzelis |
IEEE Internet Things J. | 2 |