EDBT 2026 Demo / reviewers in the wild / expert
Nour Alhussien
dblp:332/5969
· DBLP profile ↗
6ranked-venue papers
6as first author
6since 2021 · last 2026
0009-0001-4803-2744ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adaptive Randomized Smoothing with Certified Robustness for Mitigating Tabular Adversarial Attacks
Nour Alhussien, Bradley Boswell, Gagan Agrawal, Ahmed Aleroud, Gokila Dorai |
ACNS (3) | 1 |
| 2025 | Augmented Tabular Adversarial Evasion Attacks with Constraint Satisfaction Guarantees
Nour Alhussien, Gagan Agrawal, Ahmed Aleroud |
ARES (2) | 1 |
| 2024 | AdvPurRec: Strengthening Network Intrusion Detection with Diffusion Model Reconstruction Against Adversarial AttacksabstractThe ongoing race between attackers and defenders in cybersecurity hinges on who makes the first move. Defenders have a significant advantage if they can anticipate and counteract attacks preemptively. However, if attackers are aware of the defenders’ strategies, meaningful defense becomes exceedingly challenging. In this paper, we propose a reactive defense technique that adapts to the presence of attacks and mitigates their effects. We introduce an adversarial purification defense technique that leverages the capabilities of a diffusion denoising probabilistic model to eliminate adversarial noise. Through training the purifier and classifier independently on clean examples, our defense remains robust against unseen attacks, making it an agnostic defense method. We rigorously evaluate our defense technique using network intrusion datasets, demonstrating its superiority over other state-of-the-art defense techniques in terms of both effectiveness and efficiency. Our results demonstrate the potential of this method to significantly enhance the resilience of network intrusion detection systems against adversarial threats. To ensure the reproducibility of our results, we have made our implementation publicly available.1 Nour Alhussien, Ahmed Aleroud |
TrustCom | 1 |
| 2024 | Constraining Adversarial Attacks on Network Intrusion Detection Systems: Transferability and Defense AnalysisabstractAdversarial attacks have been extensively studied in the domain of deep image classification, but their impacts on other domains such as Machine and Deep Learning-based Network Intrusion Detection Systems (NIDSs) have received limited attention. While adversarial attacks on images are generally more straightforward due to fewer constraints in the input domain, generating adversarial examples in the network domain poses greater challenges due to the diverse types of network traffic and the need to maintain its validity. Prior research has introduced constraints to generate adversarial examples against NIDSs, but their effectiveness across different attack settings, including transferability, targetability, defenses, and the overall attack success have not been thoroughly examined. In this paper, we proposed a novel set of domain constraints for network traffic that preserve the statistical and semantic relationships between traffic features while ensuring the validity of the perturbed adversarial traffic. Our constraints are categorized into four types: feature mutability constraints, feature value constraints, feature dependency constraints and distribution preserving constraints. We evaluated the impacts of these constraints on white box and black box attacks using two intrusion detection datasets. Our results demonstrated that the introduced constraints have a significant impact on the success of white box attacks. Our research revealed that transferability of adversarial examples depends on the similarity between the targeted models and the models to which the examples are transferred, regardless of the attack type or the presence of constraints. We also observed that adversarial training enhanced the robustness of the majority of machine learning and deep learning-based NIDSs against unconstrained attacks, while providing some resilience against constrained attacks. In practice, this suggests the potential use of pre-existing signatures of constrained attacks to combat new variations or zero-day adversarial attacks in real-world NIDSs. Nour Alhussien, Ahmed Aleroud, Abdullah Melhem, Samer Khamaiseh |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | A Novel Poisoning Attack on Few-Shot based Network Intrusion DetectionabstractWith the advancement of Machine Learning (ML) algorithms, more organizations started using Machine Learning based Intrusion Detection Systems (ML-IDSs) to mitigate cyberattacks. However, the lack of training datasets is a major challenge when creating those systems. Therefore, using pre-trained models and small amount of labeled network data or few-shots from internal sources are possible solutions to overcome this challenge. However, using pretrained models or external datasets introduces the risk of poisoned machine learning models. This work investigates a novel poisoning attack that creates a diverse mini cluster of attacks and normal instances around an attack instance, then use the instances in that cluster to poison that instance. The poisoned instances are then injected into training data. A trained model is then created by projecting a labeled data from a poisoned source and the few labeled shots from the target organization. An anomaly-based intrusion detection model is utilized to examine the effectiveness of the introduced approach under the proposed poisoning attack. The results have shown that the attack is effective in the context of few-shot IDS learning. Nour Alhussien, Ahmed Aleroud |
NOMS | 1 |
| 2022 | Triggerability of Backdoor Attacks in Multi-Source Transfer Learning-based Intrusion DetectionabstractNetwork-based Intrusion Detection Systems (NIDSs) automate monitoring of events in networks and analyze them for signatures of cyberattacks. With the advancement of machine learning algorithms, more organizations started using machine learning based IDSs (ML-IDSs) to identify and mitigate cyberattacks. However, the lack of training datasets is a major challenge when implementing ML-IDSs. Therefore, using training data from external sources or transfer learning models are some solutions to overcome this challenge. However, using training data from external sources introduces the risk of backdoored datasets, specifically, when the adversaries also have background knowledge on data sources inside the target organization. This work investigates the role of backdoor attacks on intrusion detection techniques trained using multi-source data. The backdoor examples are injected into one or more training data sources. Transfer learning models are then created by projecting data from different sources into a new subspace containing all source data. The backdoor is then triggered in the target data. An anomaly-based intrusion detection classifier is applied to examine the effectiveness of the introduced backdoors. The results have shown that backdoor attacks on multis-source transfer learning models are feasible, although having less impact compared to backdoors on traditional machine learning models. Nour Alhussien, Ahmed Aleroud, Reza Rahaeimehr, Alexander A. Schwarzmann |
BDCAT | 1 |