EDBT 2026 Demo / reviewers in the wild / expert
Abdulrahman Alhaidari
dblp:292/3790
· DBLP profile ↗
5ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0001-6406-9603ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | On-Chain Decentralized Learning and Cost-Effective Inference for DeFi Attack MitigationabstractBillions of dollars are lost every year in DeFi platforms by transactions exploiting business logic or accounting vulnerabilities. Existing defenses focus on static code analysis, public mempool screening, attacker contract detection, or trusted off-chain monitors, none of which prevents exploits submitted through private relays or malicious contracts that execute within the same block. We present the first decentralized, fully on-chain learning framework that: (i) performs gas-prohibitive computation on Layer-2 to reduce cost, (ii) propagates verified model updates to Layer-1, and (iii) enables gas-bounded, low-latency inference inside smart contracts. A novel Proof-of-Improvement (PoIm) protocol governs the training process and verifies each decentralized micro update as a self-verifying training transaction. Updates are accepted by PoIm only if they demonstrably improve at least one core metric (e.g., accuracy, F1-score, precision, or recall) on a public benchmark without degrading any of the other core metrics, while adversarial proposals get financially penalized through an adaptable test set for evolving threats. We develop quantization and loop-unrolling techniques that enable inference for logistic regression, SVM, MLPs, CNNs, and gated RNNs (with support for formally verified decision tree inference) within the Ethereum block gas limit, while remaining bit-exact to their off-chain counterparts, formally proven in Z3. We curate 298 unique real-world exploits (2020 - 2025) with 402 exploit transactions across eight EVM chains, collectively responsible for $3.74 B in losses. We demonstrate that on-chain ML governed by PoIm detects previously unseen attacks with over 97% attack detection accuracy and 82.0% F1. A single inference, such as one made via an external call, typically incurs zero cost. Fully on-chain inference consumes 57,603 gas (≈ $0.18) for linear models, 143,647 gas (≈ $0.49) for CNN(F2, K1), and 506,397 gas (≈ $1.77) for CNN(F8, K4) on L1 (e.g., Ethereum). Our results show that practical and continually evolving DeFi defenses can be embedded directly in protocol logic without trusted guardians, and our solution achieves highly cost-effective protection while filling a critical gap between vulnerability scanners and real-time transaction screening. Abdulrahman Alhaidari, Balaji Palanisamy, Prashant Krishnamurthy |
AFT | 1 |
| 2025 | SolRPDS: A Dataset for Analyzing Rug Pulls in Solana Decentralized FinanceabstractRug pulls in Solana have caused significant damage to users interacting with Decentralized Finance (DeFi). A rug pull occurs when developers exploit users' trust and drain liquidity from token pools on Decentralized Exchanges (DEXs), leaving users with worthless tokens. Although rug pulls in Ethereum and Binance Smart Chain (BSC) have gained attention recently, analysis of rug pulls in Solana remains largely under-explored. In this paper, we introduce SolRPDS (Solana Rug Pull Dataset), the first public rug pull dataset derived from Solana's transactions. We examine approximately four years of DeFi data (2021-2024) that covers suspected and confirmed tokens exhibiting rug pull patterns. The dataset, derived from 3.69 billion transactions, consists of 62,895 suspicious liquidity pools. The data is annotated for inactivity states, which is a key indicator, and includes several detailed liquidity activities such as additions, removals, and last interaction as well as other attributes such as inactivity periods and withdrawn token amounts, to help identify suspicious behavior. Our preliminary analysis reveals clear distinctions between legitimate and fraudulent liquidity pools and we found that 22,195 tokens in the dataset exhibit rug pull patterns during the examined period. SolRPDS can support a wide range of future research on rug pulls including the development of data-driven and heuristic-based solutions for real-time rug pull detection and mitigation. Abdulrahman Alhaidari, Bhavani Kalal, Balaji Palanisamy, Shamik Sural |
CODASPY | 1 |
| 2025 | Protecting DeFi Platforms against Non-Price Flash Loan AttacksabstractSmart contracts in Decentralized Finance (DeFi) platforms are attractive targets for attacks as their vulnerabilities can lead to massive amounts of financial losses. Flash loan attacks, in particular, pose a major threat to DeFi protocols that hold a Total Value Locked (TVL) exceeding 106 billion. These attacks use the atomicity property of blockchains to drain funds from smart contracts in a single transaction. While existing research primarily focuses on price manipulation attacks, such as oracle manipulation, mitigating non-price flash loan attacks that often exploit smart contracts' zero-day vulnerabilities remains largely unaddressed. These attacks are challenging to detect because of their unique patterns, time sensitivity, and complexity. In this paper, we present FlashGuard, a runtime detection and mitigation method for non-price flash loan attacks. Our approach targets smart contract function signatures to identify attacks in real-time and counterattack by disrupting the attack transaction atomicity by leveraging the short window when transactions are visible in the mempool but not yet confirmed. When FlashGuard detects an attack, it dispatches a stealthy dusting counterattack transaction to miners to change the victim contract's state which disrupts the attack's atomicity and forces the attack transaction to revert. We evaluate our approach using 20 historical attacks and several unseen attacks. FlashGuard achieves an average real-time detection latency of 150.31ms, a detection accuracy of over 99.93%, and an average disruption time of 410.92ms. FlashGuard could have potentially rescued over \405.71 million in losses if it were deployed prior to these attack instances. FlashGuard demonstrates significant potential as a DeFi security solution to mitigate and handle rising threats of non-price flash loan attacks. Abdulrahman Alhaidari, Balaji Palanisamy, Prashant Krishnamurthy |
CODASPY | 1 |
| 2025 | The Economics of Deception: Structural Patterns of Rug Pull Across DeFi Blockchains
Bhavani Kalal, Abdulrahman Alhaidari, Balaji Palanisamy, Shamik Sural |
ESORICS (4) | 2 |
| 2024 | Poster: FlashGuard: Real-time Disruption of Non-Price Flash Loan Attacks in DeFiabstractFlash loan attacks threaten decentralized finance (DeFi) protocols, which constitute a Total Value Locked (TVL) of more than 106 billion. These attacks exploit the atomicity property in blockchains to drain funds within a single block. Existing research overlooks the mitigation of non-price flash loan attacks, which mostly exploit zero-day vulnerabilities. These attacks are challenging to detect as they are highly time-sensitive and each instance of the attack is complex and has a unique pattern. To address this challenge, we present FlashGuard, a runtime detection and mitigation framework for non-price flash loan attacks. FlashGuard communicates directly with the miners and bypasses the public mempool, where attack transactions usually reside. We utilize the temporary time window where transactions are visible in the mempool but not yet confirmed. Once the attack is detected, FlashGuard dispatches a dusting counter-transaction for the victim contract to the miners directly within the same block to disrupt the attack's atomicity and change the smart contract state. This forces the malicious transaction to revert. FlashGuard ensures that the series of operations that are required for a non-price flash loan attack cannot be completed atomically, leading to a failure of the attack. Our evaluation using 20 historical attacks that exploited protocol vulnerabilities shows an outstanding detection rate for FlashGuard with minimal false positives, and effective attack disruption and indicates that FlashGuard could have rescued about $405.71 million in losses. Abdulrahman Alhaidari, Balaji Palanisamy, Prashant Krishnamurthy |
CCS | 1 |