EDBT 2026 Demo / reviewers in the wild / expert
Mati Ur Rehman
dblp:339/9563
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2026
0009-0000-3345-2482ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Network security · 95% Malware analysis · 5% | |
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 50% Operating systems · 50% | |
| Computer networks
1 paper |
Network measurement and analytics · 100% |
Topics — the 5 heaviest of 7, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › intrusion detection and prevention › intrusion detection › attack detection
advanced persistent threat detection |
2.6 | 3 | 2026 | Accurate and Scalable Detection and Investigation of Cyber Persistence Threats · IEEE Trans. Dependable Secur. Comput. 2026 A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics · INFOCOM 2025 Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning · SP 2024 |
Network security › intrusion detection and prevention
intrusion detection |
2.6 | 3 | 2026 | Accurate and Scalable Detection and Investigation of Cyber Persistence Threats · IEEE Trans. Dependable Secur. Comput. 2026 A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics · INFOCOM 2025 Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning · SP 2024 |
Operating systems
provenance |
1.0 | 1 | 2026 | Accurate and Scalable Detection and Investigation of Cyber Persistence Threats · IEEE Trans. Dependable Secur. Comput. 2026 |
Program analysis
provenance analysis |
1.0 | 1 | 2026 | Accurate and Scalable Detection and Investigation of Cyber Persistence Threats · IEEE Trans. Dependable Secur. Comput. 2026 |
Network security › intrusion detection and prevention › intrusion detection › intrusion detection system › host-based intrusion detection
provenance-based intrusion detection |
0.8 | 1 | 2024 | Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning · SP 2024 |
Methods — techniques the papers use, named apart from their topics
pseudo-dependency edges · 2.0expert-guided edges · 2.0alert triage · 2.0multi-stage causal analytics · 1.7word2vec · 0.8graph representation learning · 0.8graph neural network · 0.8
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RAPID: Restorative Amortized Protection for Image Diffusion
Muhammad Saad Umer, Sharjeel Sajid, Mati Ur Rehman, Maham Jahangir, Faisal Shafait |
ICPR (15) | 3 |
| 2026 | Accurate and Scalable Detection and Investigation of Cyber Persistence ThreatsabstractIn Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to maintain prolonged access, often evading detection mechanisms. Recognizing its pivotal role in the APT lifecycle, this paper introduces Cyber Persistence Detector (CPD), a novel system dedicated to detecting cyber persistence through provenance analytics. CPD is founded on the insight that persistent operations typically manifest in two phases: the “persistence setup” and the subsequent “persistence execution”. By causally relating these phases, we enhance our ability to detect persistent threats. First, CPD discerns setups signaling an impending persistent threat and then traces processes linked to remote connections to identify persistence execution activities. A key feature of our system is the introduction ofpseudo-dependency edges(pseudoedges), which effectively connect these disjoint phases using data provenance analysis, andexpert-guided edges, which enable faster tracing and reduced log size. These edges empower us to detect persistence threats accurately and efficiently. Moreover, we propose a novel alert triage algorithm that further reduces false positives associated with persistence threats. Evaluations conducted on well-known datasets demonstrate that our system reduces the average false positive rate by 93% compared to stateof- the-art methods. Qi Liu 0023, Mati Ur Rehman, Kaibin Bao, Veit Hagenmeyer, Wajih Ul Hassan |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics
Jiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou, Mati Ur Rehman, Wajih Ul Hassan |
INFOCOM | 5 |
| 2024 | Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation LearningabstractRecently, provenance-based Intrusion Detection Systems (IDSes) have gained popularity for their potential in detecting sophisticated Advanced Persistent Threat (APT) attacks. These IDSes employ provenance graphs created from system logs to identify potentially malicious activities. Despite their potential, they face challenges in accuracy, practicality, and scalability, particularly when dealing with large provenance graphs. We present Flash, a scalable IDS that leverages graph representation learning through Graph Neural Networks (GNNs) on data provenance graphs to overcome these limitations. Flash employs a Word2Vec-based semantic encoder to capture essential semantic attributes (e.g., process names and file paths) and the temporal ordering of events within the provenance graph. Furthermore, Flash incorporates a novel adaptation of a GNN-based contextual encoder to efficiently encode both local and global graph structures into expressive node embeddings. To learn benign node behaviors, we utilize a lightweight classifier that combines the GNN and Word2Vec embeddings. Recognizing the computational demands and slow processing times of GNN, particularly for large provenance graphs, we have developed an embedding recycling database to store the node embeddings generated during the training phase. During runtime, our lightweight classifier leverages the stored embeddings, obviating the need to regenerate GNN embeddings, thus facilitating real-time APT detection. Extensive evaluation of Flash on real-world datasets demonstrates superior detection accuracy compared to existing provenance-based IDSes. The results also illustrate Flash’s scalability, robustness against mimicry attacks, and potential for accelerating the alert verification process. Mati Ur Rehman, Hadi Ahmadi, Wajih Ul Hassan |
SP | 1 |