EDBT 2026 Demo / reviewers in the wild / expert
Ferhat Demirkiran
dblp:307/5447
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2026
0000-0001-7335-9370ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Active Learning of Negative Relationship-Based AuthorizationsabstractRelationship-based access control (ReBAC) policies naturally express authorization decisions over complex relationships, but their expressiveness makes them difficult to audit, validate, migrate, and maintain. Learning ReBAC policy using observed authorization decisions can help in these tasks, yet it remains challenging in real deployments where complete authorization logs are hard to obtain and expressive features such as \deny rules are common. Existing ReBAC mining approaches either rely on complete logs to infer \permit and \deny rules or avoid logs via an active learning framework but learn only \permit rules, leaving explicit denials indistinguishable from deny-by-default behavior. This paper extends the earlier active learning framework by introducing ARDEN (Active ReBAC Discovery with Explicit Negatives), a multi-phase active learning and optimization workflow with the goal of minimally exploring the authorization space of a target system and composing an optimal set of \permit and \deny rules that capture its authorization decisions. In contrast to the recent work on offline mining of negative ReBAC policies, ARDEN uses a unified strategy for optimizing the selection of \permit and \deny rules. We also propose enhancements to the earlier active learning architecture such as cache-assisted authorization queries and a state-prefix random walk oracle that significantly impact the performance of the framework. We evaluate ARDEN on 18 configuration-induced policies derived from a controlled deployment of the HotCRP conference management system. We report on the performance of our framework in terms of learning accuracy and cost, as well as a comparative evaluation against three baseline approaches. Ferhat Demirkiran, Amirreza Masoumzadeh 0001 |
CODASPY | 1 |
| 2025 | Enhancing Relationship-Based Access Control Policies with Negative Rule MiningabstractRelationship-based access control (ReBAC) policies often rely solely on positive authorization rules, implicitly denying all other requests by default. However, many scenarios require explicitly stating negative authorization rules to capture exceptions or special restrictions that are not naturally enforced by deny-by-default semantics. This work presents a systematic method to mine ReBAC policies that integrate both positive and negative authorization rules from observed authorizations. We formalize the mining problem, show its NP-hardness, and develop an approach that identifies minimal policies while accurately reflecting observed access decisions. We demonstrate the feasibility and effectiveness of our proposed approach through a set of experiments. Our experimental evaluations on representative datasets demonstrate that including negative rules leads to more concise and semantically complete policies, confirming the necessity of explicit negative authorizations in complex access control settings. Ferhat Demirkiran, Amirreza Masoumzadeh 0001 |
CODASPY | 1 |
| 2022 | An ensemble of pre-trained transformer models for imbalanced multiclass malware classification
Ferhat Demirkiran, Aykut Çayir, Ugur Ünal, Hasan Dag |
Comput. Secur. | 1 |