EDBT 2026 Demo / reviewers in the wild / expert
Ibrahim Khalil 0001
dblp:41/749
· DBLP profile ↗
169ranked-venue papers
4as first author
70since 2021 · last 2026
0000-0001-5512-114XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 62 · 3 first-author · 28 since 2021Systems, architecture and hardware · 32 · 9 since 2021Security and privacy · 18 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 15 · 12 since 2021Databases, data management, data science and information retrieval · 13 · 6 since 2021Human-computer interaction and ubiquitous computing · 7Artificial intelligence and machine learning · 5 · 1 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Theory of computation · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hardening Output Privacy for Secure Inference: A Lightweight Realization via Distributed Trust
Xinqian Wang, Xiaoning Liu 0002, Shangqi Lai, Xun Yi, Ibrahim Khalil 0001, Kwok-Yan Lam |
ICDCS | 5 |
| 2026 | Explainable Machine Unlearning for Secure and Trustworthy Wireless Internet-of-Things Network
Amani Aldahiri, Ibrahim Khalil 0001, Mohammad Saidur Rahman 0001, Jer Shyuan Ng |
IWCMC | 2 |
| 2026 | WinFLoRA: Incentivizing Client-Adaptive Aggregation in Federated LoRA under Privacy HeterogeneityabstractLarge Language Models (LLMs) increasingly underpin intelligent web applications, from chatbots to search and recommendation, where efficient specialization is essential. Low-Rank Adaptation (LoRA) enables such adaptation with minimal overhead, while federated LoRA allows web service providers to fine-tune shared models without data sharing. However, in privacy-sensitive deployments, clients inject varying levels of differential privacy (DP) noise, creating privacy heterogeneity that misaligns individual incentives and global performance. In this paper, we propose WinFLoRA, a privacy-heterogeneous federated LoRA that utilizes aggregation weights as incentives with noise awareness. Specifically, the noises from clients are estimated based on the uploaded LoRA adapters. A larger weight indicates greater influence on the global model and better downstream task performance, rewarding lower-noise contributions. By up-weighting low-noise updates, WinFLoRA improves global accuracy while accommodating clients' heterogeneous privacy requirements. Consequently, WinFLoRA aligns heterogeneous client utility in terms of privacy and downstream performance with global model objectives without third-party involvement. Extensive evaluations demonstrate that across multiple LLMs and datasets, WinFLoRA achieves up to 52.58% higher global accuracy and up to 2.56× client utility than state-of-the-art benchmarks. Source code is publicly available at https://github.com/koums24/WinFLoRA.git. Mengsha Kou, Xiaoyu Xia 0001, Ziqi Wang 0008, Ibrahim Khalil 0001, Ruikun Luo, Minhui Xue 0001 |
WWW | 4 |
| 2026 | A privacy-preserving class imbalance mitigation framework for face recognitionabstractAI-powered face recognition has become essential to various IoT applications, including home automation, security systems, and personalized services. While these systems offer significant advancements, they still face critical challenges related to accuracy and privacy. One major issue is class imbalance, which is common in face recognition systems where certain demographic groups are underrepresented. This imbalance results in biased models, compromising the accuracy and fairness of these systems. Furthermore, traditional centralized training methods can expose sensitive facial data, raising serious privacy concerns. Federated Learning (FL) has emerged as a solution to improve model training by enabling collaboration across devices without sharing sensitive data. However, it also worsens the issue of data heterogeneity. This paper proposes a Hierarchical Federated Learning (HFL) framework to address class imbalance while preserving privacy. By aggregating local models at different hierarchical levels, the framework mitigates data imbalance and enhances fairness in face recognition systems. Additionally, a privacy-preserving mechanism based on Secure Multi-Party Computation (SMPC) is implemented to ensure data security during the training process. Amani Aldahiri, Ibrahim Khalil 0001, Mohammad Saidur Rahman 0001, Mohammed Atiquzzaman |
High Confid. Comput. | 2 |
| 2026 | SSFU: Selective Semantic Feature Unlearning for Federated Learning in 6G Internet of Things SystemsabstractIn next-generation 6G Internet-of-Things (IoT) networks, semantic communication has emerged as a key paradigm that transforms raw data into high-level feature representations, thereby reducing communication overhead while enhancing interpretability. When combined with federated learning (FL), these semantic embeddings enable decentralized model training without centralizing raw data, preserving user privacy, and supporting large-scale collaboration. However, semantic features may inadvertently encode sensitive information or act as adversarial triggers, introducing new privacy risks that current unlearning techniques fail to address. To overcome this challenge, we propose Selective Semantic Feature Unlearning (SSFU), a novel framework that performs unlearning at the feature level rather than at the client level. SSFU employs an ensemble-based risk scoring mechanism to identify high-risk latent components, followed by gradient ascent and semantic masking to remove their influence. Unlike existing methods that depend on costly retraining or full client exclusion, SSFU preserves benign semantic knowledge and allows training to continue with minimal disruption. The framework guarantees bounded convergence, and empirical results on benchmark datasets show that SSFU effectively eliminates sensitive features while maintaining predictive accuracy. SSFU thus represents a robust, privacy-preserving FL framework tailored for semantic communication in 6G IoT systems. Wathsara Daluwatta, Ibrahim Khalil 0001, Shehan Edirimannage, Charith Elvitigala, Jer Shyuan Ng, Dusit Niyato |
IEEE Internet Things J. | 2 |
| 2026 | Intent-Driven Dual-Layer Model Pruning for Energy-Efficient Hierarchical Federated Learning in IoT With Non-IID DataabstractThe proliferation of Internet of Things (IoT) devices has intensified the need for scalable and energy-efficient federated learning (FL). While Hierarchical Federated Learning (HFL) improves scalability by adding an edge aggregation tier, it still suffers from high communication costs, slow convergence, and degraded accuracy under non-IID data. Existing methods such as quantization, sparsification, and static pruning alleviate specific bottlenecks but fail to jointly optimize efficiency, robustness, and accuracy. This paper proposes an intent-driven dual-layer model pruning framework for HFL, where an Energy Management System (EMS) and an Intent-driven Pruning Orchestrator (IDPO) dynamically translate system-level intents (e.g., energy minimization or accuracy preservation) into pruning actions at both edge and cloud layers. Experiments on MNIST, CIFAR-10, and FEMNIST show up to 41% smaller models, 12× faster training, 28–35% lower energy use, and +12.9% accuracy gain under non-IID data, establishing the framework as a robust and sustainable solution for IoT learning. Charith Elvitigala, Ibrahim Khalil 0001, Shehan Edirimannage, Mohammed Atiquzzaman, Wathsara Daluwatta |
IEEE Internet Things J. | 2 |
| 2026 | Toward Personalized Federated Meta-Learning With Constrained Hypernetwork on Non-IID DataabstractPersonalized Federated Learning (pFL) tailors models to each client’s local data distribution in heterogeneous federated learning settings. Federated Meta-Learning (FML) is a branch of pFL that uses meta-learning to achieve fast adaptation, where clients start with a meta-model and personalize it by fine-tuning it with local data. Since a single global meta-model has limitations when the data distribution of clients varies significantly, meta-model personalization should be considered in FML. However, most benchmark pFL methods lack meta-model personalization, and usually lack meta-learning or relying on a single global meta-model. Besides, these methods can neither provide meta-model personalization nor guarantee generalization and convergence, due to the challenges in measuring the distance between the meta-model and the client model in FML. To address these issues, we combine FML with hypernetwork and propose a constrained hypernetwork-based FML framework called FMLH, which innovatively utilizes hypernetwork to capture the differences in fine-tuned models, thereby providing personalized meta-models for each client. We provide rigorous mathematical proofs illustrating how the hypernetwork affects the convergence and generalization bounds of FMLH. Experimental results demonstrate that FMLH significantly improves the generalization of the model in cross-client shifts, with the lowest decile accuracy improved by up to 18.71%. FMLH also outperforms representative pFL algorithms by up to 5.6% in terms of maximum accuracy improvement. Lizhao Wu, Xiaoding Wang 0001, Hui Lin 0007, Xu Yang 0002, Jiwu Shu, Xun Yi, Ibrahim Khalil 0001, Albert Y. Zomaya |
IEEE Trans. Computers | 7 |
| 2026 | KGEES: An Energy Saving System With Location Privacy Preservation in Multi-Access Edge ComputingabstractThe burgeoning 5G network brings edge servers closer to users to host online applications. These edge servers are typically kept running 24/7 to meet users' computational demands. However, the user coverage, privacy assurance, and service delay have consistently undermined users' confidence, compounded by the significant environmental damage caused by excessive energy consumption. Recently, various approaches have been proposed to tackle the energy-saving demand response issue in the multi-access edge computing (MEC) system. Unfortunately, existing attempts often compromise service quality and energy efficiency for privacy enhancement, and incur significant computational overheads and delays unsuitable for real-time services. Therefore, maintaining satisfying user coverage with energy consumption while adhering to users' privacy demands with low computational overhead is critical to achieving sustainable edge services. To address those challenges, we systematically formulate the location-privacy-preserving edge demand response (LEDR) problem and introduce a novel system named KGEES. KGEES incorporates$k$-anonymity geo-obfuscation to enhance user privacy while leveraging a heuristic approach to finalize resource allocation strategies under geo-distortion greedily to jointly improve system utility, energy, and time efficiency. Comprehensive experiments on a real-world dataset demonstrate that KGEES surpasses the representative approaches by an average of$1.187 \times$in system utility and$1.192 \times$in energy efficiency while being$ 203.5 \times$faster. Ziqi Wang 0008, Xiaoyu Xia 0001, Ibrahim Khalil 0001, Minghui LiWang, Xiaolong Xu 0001, Xun Yi, Yan Li 0002, Minhui Xue 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Data Flipping Attack and Defense in Web Edge Caching SystemsabstractCaching web data on edge servers has become a common practice in latency-sensitive services to minimize data retrieval delays for web users. However, the geographic distribution of edge servers and frequent data transmissions make these systems vulnerable to security threats, particularly cache pollution attacks (CPAs). In such attacks, malicious users send excessive requests for unpopular data at abnormal frequencies, causing irrelevant content to be cached and degrading the system’s performance. Traditional CPAs, though impactful in conventional caching systems, are less effective in edge environments where user requests are more diverse and edge servers collaborate in caching strategies. In this paper, we identify a novel attack named data flipping attack (DFA) that targets the data transmission process among edge servers. This attack manipulates request distribution by swapping the frequencies of popular and unpopular data requests, all while maintaining other characteristics like request timing and user identity. This tactic disrupts caching strategies without raising suspicion. Experimental results indicate DFA is independent of user request patterns and demonstrates substantial effectiveness and robustness, successfully forcing edge web users to retrieve data from the cloud across various scales and configurations of edge networks. Furthermore, it evades detection by state-of-the-art methods that rely on specific distribution patterns, such as the Zipf distribution. To counter this attack, we propose an effective defense method that alters the request distribution by frequency distillation, mitigating its impact. Mengsha Kou, Xiaoyu Xia 0001, Ibrahim Khalil 0001, Ziqi Wang 0008, Xiuzhen Zhang 0001, Lin Yao 0001, Minhui Xue 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | MERA: A Green Edge Resource Control System With Privacy-Preservation via Mean-Field Reinforcement Learning
Ziqi Wang 0008, Xiaoyu Xia 0001, Ibrahim Khalil 0001, Tianxu Lan, Feng Liu 0003, Xiaolong Xu 0001, Xun Yi, Minhui Xue 0001, Elisa Bertino |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2026 | MoSEEC: Sustainable and Trajectory Privacy-Preserving Edge Resource ManagementabstractAs the 5G network rapidly expands, more edge servers are being deployed to provide more efficient and low-latency mobile services. However, limited edge resources constrain users' demand response, while continuous server operation leads to significant energy consumption, undermining the sustainability of the multi-access edge computing (MEC) system. Existing resource allocation methods rely on accurate user locations, which can lead to privacy exposure, while protection techniques often result in significant service degradation due to spatial distortion. Moreover, user mobility in MEC systems poses new challenges for edge resource management, which requires dynamic server collaboration and user data migration, incurring additional costs and delays. To address these challenges, we propose MoSEEC, which employs user-adaptive differential geo-obfuscation to secure trajectory privacy while dynamically enhancing service performance with energy awareness. Our results demonstrate its superior performance in migration delays and system utility by$1.54 \times$faster and$1.15 \times$higher compared to existing techniques with privacy guarantees, respectively. In addition, our system outperforms state-of-the-art approaches by$5 \times$faster on average in terms of computation overhead. Ziqi Wang 0008, Xiaoyu Xia 0001, Ibrahim Khalil 0001, Minghui LiWang, Minhui Xue 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | Differentially Private Model Recombination as a Service for Trustable and Federated Learning in Next-Generation Networks With Non-IID Data
Charith Elvitigala, Ibrahim Khalil 0001, Shehan Edirimannage, Mohammed Atiquzzaman, Wathsara Daluwatta |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2026 | $\mathsf {SENTRY}$: A Compliance-Check Service for Dynamic Searchable Encryption With Sanitized Authorization QueryabstractSearchable encryption enables privacy-preserving queries over data outsourced to cloud services. Classical symmetric schemes deliver efficient search but largely assume a single client setting; multi-client variants permit delegation yet typically treat authorization as an owner-local decision, overlooking regulations enforced by higher-level authorities (e.g., sector-specific compliance). In practice, limited familiarity with regulatory detail or operational lapses can lead owners to delegate search permissions that violate authority regulations, rendering existing systems unsuited to regulated, multi-client cloud environments. To address this gap, we propose two systems. First, we propose SENTRY, a multi-client dynamic searchable encryption framework with a built-in compliance-check service via sanitized authorization. Its core is a tag-based sanitization protocol: the authority encodes prohibited keywords as hidden tags, and the sanitizer uses these tags to remove non-compliant per-keyword search permissions before they reach readers, without learning the underlying keywords. As a result, readers receive only compliant search capabilities. We then proposeF-SENTRY, a forward private variant of SENTRY for settings where regulations evolve over time.F-SENTRY preserves the same sanitized-authorization mechanism and further adds forward privacy through a tailored constrained shiftable encryption, which binds search permissions and newly added encrypted updates to regulatory epochs. Consequently, permissions issued before a policy change cannot be used to retrieve data added afterward unless they are refreshed for the new epoch. We formalize the security of both SENTRY andF-SENTRY and prove them secure under standard assumptions. Experiments under cloud-like workloads show that SENTRY achieves regulation-compliant authorization with modest over head, whileF-SENTRY provides stronger protection under changing regulations at practical additional cost. Lei Xu 0019, Xiaoning Liu 0002, Xun Yi, Ibrahim Khalil 0001 |
IEEE Trans. Serv. Comput. | 5 |
| 2025 | TurboCache: Empowering Switch-Accelerated Key-Value Caches with Accurate and Fast Cache UpdatesabstractRecent key-value (KV) caches are offloaded to programmable switches to offer high query processing performance. However, they suffer from both low accuracy in hot key detection and high latency in cache updates due to the strict limitations on switch registers. We propose TurboCache, a switch-accelerated KV cache with accurate hot key detection and fast cache updates. Our key idea is to leverage the switch recirculation capability to build a novel data structure that caches hot KV pairs. With this hardware-compatible cache data structure, TurboCache designs efficient data plane algorithms that accurately detects new hot keys and quickly updates its cache entirely within switch ASIC pipelines. We have implemented TurboCache on a${64}\times {100}$Gbps Tofino switch. Testbed results indicate that TurboCache improves the hot key detection accuracy and decreases the cache update latency of existing KV caches by several orders of magnitude. Xiang Chen 0017, Longlong Zhu, Linying Zheng, Lingfei Cheng, Jianshan Zhang, Xu Yang 0002, Dong Zhang 0010, Xuan Liu 0006, Xiaoming Lu, Xun Yi, Ibrahim Khalil 0001, Albert Y. Zomaya, Haifeng Zhou, Chunming Wu 0001 |
INFOCOM | 11 |
| 2025 | Optimizing Energy Efficiency with QoE-Awareness in Multi-Access Edge ComputingabstractMulti-access edge computing (MEC) brings computational resources closer to end-users by widely distributing the physical edge services, reducing end-to-end service latency at the network edge. Continuous operation of edge servers results in high energy usage and significant carbon footprints. Efficient resource management is essential for MEC sustainability. Recent solutions focus on demand response to reduce energy consumption. However, the reduction in available resources due to server shutdowns forces a degradation in the quality of service (QoS) provided to users, significantly impacting their quality of experience (QoE). Moreover, the non-linear relationship between QoS and QoE further complicates the issue. Therefore, maintaining user's QoE with energy consumption is critical to achieving sustainable edge services. To tackle these challenges, we formulate the QoE-aware energy saving (QoEES) problem and propose QESGame, a game-theoretical algorithm to solve this problem effectively and efficiently with a guaranteed convergence to Nash equilibrium. Through extensive evaluations, we demonstrate that QESGame surpasses the representative approaches by up to 20.21%, 41.62%, and 23.54% in terms of the overall system benefit, energy saving, and QoE. Zongchao Xie, Xiaoyu Xia 0001, Boyun Hu, Ibrahim Khalil 0001, Ziqi Wang 0008, Guangming Cui, Gang Xie 0001, Minhui Xue 0001 |
IWQoS | 4 |
| 2025 | Edge Unlearning is Not "on Edge"! an Adaptive Exact Unlearning System on Resource-Constrained DevicesabstractThe right to be forgotten mandates that machine learning models enable the erasure of a data owner's data and information from a trained model. Removing data from the dataset alone is inadequate, as machine learning models can memorize information from the training data, increasing the potential privacy risk to users. To address this, multiple machine unlearning techniques have been developed and deployed. Among them, approximate unlearning is a popular solution, but recent studies report that its unlearning effectiveness is not fully guaranteed. Another approach, exact unlearning, tackles this issue by discarding the data and retraining the model from scratch, but at the cost of considerable computational and memory resources. However, not all devices have the capability to perform such retraining. In numerous machine learning applications, such as edge devices, Internet-of-Things (IoT), mobile devices, and satellites, resources are constrained, posing challenges for deploying existing exact unlearning methods. In this study, we propose a Constraint-aware Adaptive Exact Unlearning System at the network Edge (CAUSE), an approach to enabling exact unlearning on resource-constrained devices. Aiming to minimize the retrain overhead by storing sub-models on the resource-constrained device, CAUSE inno-vatively applies a Fibonacci-based replacement strategy and updates the number of shards adaptively in the user-based data partition process. To further improve the effectiveness of memory usage, CAUSE leverages the advantage of model pruning to save memory via compression with minimal accuracy sacrifice. The experimental results demonstrate that CAUSE significantly outperforms other representative systems in realizing exact unlearning on the resource-constrained device by 9.23%-80.86%, 66.21%-83.46%, and 5.26%-194.13% in terms of unlearning speed, energy consumption, and accuracy. Xiaoyu Xia 0001, Ziqi Wang 0008, Ruoxi Sun 0001, Bowen Liu 0002, Ibrahim Khalil 0001, Minhui Xue 0001 |
SP | 5 |
| 2025 | Remote sensing revolutionizing agriculture: Toward a new frontier
Xiaoding Wang 0001, Haitao Zeng, Xu Yang 0002, Jiwu Shu, Qibin Wu, Youxiong Que, Xuechao Yang, Xun Yi, Ibrahim Khalil 0001, Albert Y. Zomaya |
Future Gener. Comput. Syst. | 9 |
| 2025 | A lightweight practical consensus mechanism for supply chain blockchainabstractWe present a consensus mechanism in this paper that is designed specifically for supply chain blockchains, with a core focus on establishing trust among participating stakeholders through a novel reputation-based approach. The prevailing consensus mechanisms, initially crafted for cryptocurrency applications, prove unsuitable for the unique dynamics of supply chain systems. Unlike the broad inclusivity of cryptocurrency networks, our proposed mechanism insists on stakeholder participation rooted in process-specific quality criteria. The delineation of roles for supply chain participants within the consensus process becomes paramount. While reputation serves as a well-established quality parameter in various domains, its nuanced impact on non-cryptocurrency consensus mechanisms remains uncharted territory. Moreover, recognizing the primary role of efficient block verification in blockchain-enabled supply chains, our work introduces a comprehensive reputation model. This model strategically selects a leader node to orchestrate the entire block mining process within the consensus. Additionally, we innovate with a Schnorr Multisignature-based block verification mechanism seamlessly integrated into our proposed consensus model. Rigorous experiments are conducted to evaluate the performance and feasibility of our pioneering consensus mechanism, contributing valuable insights to the evolving landscape of blockchain technology in supply chain applications. Mohammad Saidur Rahman 0001, Ibrahim Khalil 0001, Mohammed Atiquzzaman, Abdelaziz Bouras |
High Confid. Comput. | 2 |
| 2025 | Edge Association Strategies for Synthetic Data Empowered Hierarchical Federated Learning With Non-IID DataabstractIn recent years, Federated Learning (FL) has emerged as a widely adopted privacy-preserving distributed training approach, attracting significant interest from both academia and industry. Research efforts have been dedicated to improving different aspects of FL, such as algorithm improvement, resource allocation, and client selection, to enable its deployment in distributed edge networks for practical applications. One of the reasons for the poor FL model performance is due to the worker dropout during training as the FL server may be located far away from the FL workers. To address this issue, an Hierarchical Federated Learning (HFL) framework has been introduced, incorporating an additional layer of edge servers to relay communication between the FL server and workers. While the HFL framework improves the communication between the FL server and workers, large number of communication rounds may still be required for model convergence, particularly when FL workers have non-independent and identically distributed (non-IID) data. Moreover, the FL workers are assumed to fully cooperate in the FL training process, which may not always be true in practical situations. To overcome these challenges, we propose a synthetic-data-empowered HFL framework that mitigates the statistical issues arising from non-IID local datasets while also incentivizing FL worker participation. In our proposed framework, the edge servers reward the FL workers in their clusters for facilitating the FL training process. To improve the performance of the FL model given the non-IID local datasets of the FL workers, the edge servers generate and distribute synthetic datasets to FL workers within their clusters. FL workers determine which edge server to associate with, considering the computational resources required to train on both their local datasets and the synthetic datasets. The simulation results show that an evolutionary equilibrium is reached where the FL workers do not have incentive to change their edge association strategies. Given this equilibrium, the FL workers facilitate the FL training of the edge servers that they associate with and be rewarded for their contributions. The proposed framework achieves higher FL model accuracy with an addition of 5% of synthetic data. Jer Shyuan Ng, Aditya Pribadi Kalapaaking, Xiaoyu Xia 0001, Dusit Niyato, Ibrahim Khalil 0001, Iqbal Gondal |
IEEE Internet Things J. | 5 |
| 2025 | ZeTFRi - A Zero Trust-Based Free Rider Detection Framework for Next Generation Federated Learning NetworksabstractWith the rapid expansion of next-generation networking, Internet of Things (IoT) devices have become central components of federated learning (FL) networks. FL offers a paradigm for distributed training machine learning models while preserving user data privacy. However, existing network security measures often struggle to identify legitimate contributors from opportunistic free riders within these networks. The Free Rider (FR) problem arises when participants seek to benefit from the FL processes without contributing. In particular, free riders are known to exist within or outside of the network, whereas outside free riders can hardly be identified. The Zero Trust model proposes an environment where no entity, including the network itself, is inherently trusted, providing a foundation to counter external threats seeking to exploit the network. This study proposes a novel framework strengthened by the Zero Trust model to identify external free riders in FL networks. Leveraging a Deep Autoencoding Gaussian Mixture Model (DAGMM)-based technique for internal free rider detection, our framework demonstrates superior performance in identifying free riders across various FR scenarios compared to current state-of-the-art solutions. Through our proposed framework and the principles of Zero Trust, we establish a robust security guarantee for FL networks, ensuring the integrity of the learning process. Shehan Edirimannage, Ibrahim Khalil 0001, Charith Elvitigala, Wathsara Daluwatta, Primal Wijesekera, Albert Y. Zomaya |
IEEE J. Sel. Areas Commun. | 2 |
| 2025 | Lightweight Privacy-Friendly Aggregation Scheme Against Internal Attacks for Smart GridsabstractWhile real-time electricity consumption data of users in smart grids can enable value-added services, such as Big Data analytics, each individual user's privacy needs to be protected. How to balance data utility and privacy protection is a significant issue, of which privacy-preserving data aggregation (PPDA) is a viable solution. Prior to this, researchers have proposed a number of PPDA schemes to address the above challenge. Unluckily, most of them suffer from security and privacy drawbacks, while others are inappropriate for resource-limited smart meters due to high cost of cryptographic operations. To tackle this issue, in this article, we propose a pairing-free and exponentiation-free certificateless PPDA scheme named CL-PPDA for smart grids. We prove the security of our design and analyze its performance. Comparative analyses with state-of-the-art work in theory and experiment show that our design not only has better security properties, but also has competitive computation overhead, especially on the resource-constrained smart meter side. Besides, we present an extension of our CL-PPDA scheme to support multidimensional data aggregation, which further enriches the functionality of our design. Wei Wu 0001, Alsharif Abuadbba, Saru Kumari, Xu Yang 0002, Ibrahim Khalil 0001, Xun Yi |
IEEE Trans. Ind. Informatics | 6 |
| 2025 | Auditable and Verifiable Federated Learning Based on Blockchain-Enabled DecentralizationabstractAuditability and verifiability are critical elements in establishing trustworthiness in federated learning (FL). These principles promote transparency, accountability, and independent validation of FL processes. Incorporating auditability and verifiability is imperative for building trust and ensuring the robustness of FL methodologies. Typical FL architectures rely on a trustworthy central authority to manage the FL process. However, reliance on a central authority could become a single point of failure, making it an attractive target for cyber-attacks and insider frauds. Moreover, the central entity lacks auditability and verifiability, which undermines the privacy and security that FL aims to ensure. This article proposes an auditable and verifiable decentralized FL (DFL) framework. We first develop a smart-contract-based monitoring system for DFL participants. This monitoring system is then deployed to each DFL participant and executed when the local model training is initiated. The monitoring system records necessary information during the local training process for auditing purposes. Afterward, each DFL participant sends the local model and monitoring system to the respective blockchain node. The blockchain nodes representing each DFL participant exchange the local models and use the monitoring system to validate each local model. To ensure an auditable and verifiable decentralized aggregation procedure, we record the aggregation steps taken by each blockchain node in the aggregation contract. Following the aggregation phase, each blockchain node applies a multisignature scheme to the aggregated model, producing a globally verifiable model. Based on the signed global model and the aggregation contract, each blockchain node implements a consensus protocol to store the validated global model in tamper-proof storage. To evaluate the performance of our proposed model, we conducted a series of experiments with different machine learning architectures and datasets, including CIFAR-10, F-MNIST, and MedMNIST. The experimental results indicate a slight increase in time consumption compared with the state-of-the-art, serving as a tradeoff to ensure auditability and verifiability. The proposed blockchain-enabled DFL also saves up to 95% communication costs for the participant side. Aditya Pribadi Kalapaaking, Ibrahim Khalil 0001, Xun Yi, Kwok-Yan Lam, Guang-Bin Huang |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2025 | UaaS-SFL: Unlearning as a Service for Safeguarding Federated LearningabstractThe rapid expansion of the Internet of Things (IoT) and network services has revolutionized technology, enabling numerous intelligent applications. However, this interconnected environment also introduces significant security challenges, particularly the susceptibility of federated learning (FL) systems to poisoning attacks. Such attacks compromise the integrity of the global model by injecting malicious data, leading to inaccurate predictions and potentially endangering system reliability and user safety. While traditional approaches, such as early detection and secure aggregation methods, aim to prevent the aggregation of malicious updates, they are ineffective in addressing threats within systems that have already been compromised and did not initially implement these safeguards. This gap highlights the urgent need for robust post-compromise mitigation strategies in FL security. To address this challenge, we introduce “Unlearning as a Service for Safeguarding Federated Learning” (UaaS-SFL), a novel service designed to seamlessly integrate with any FL management system to remove the impact of poisoning clients and restore the integrity of the global model. UaaS-SFL effectively unlearns the contributions of malicious clients, ensuring both model security and system reliability. Our empirical evaluations, conducted in a simulated IoT environment, demonstrate that our service maintains model accuracy with less than a 10% deviation from the baseline achieved through retraining from scratch, underscoring the efficacy of our methodology in safeguarding FL systems. These results highlight UaaS-SFL as a critical service for securing FL management systems, providing a robust foundation for the continued growth of secure and intelligent IoT applications. Wathsara Daluwatta, Ibrahim Khalil 0001, Shehan Edirimannage, Mohammed Atiquzzaman |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | Q-SupCon: Quantum-Enhanced Supervised Contrastive Learning Architecture within the Representation Learning FrameworkabstractIn the evolving landscape of data privacy regulations, the challenge of providing extensive data for robust deep classification models arises. The accuracy of these models relies on the amount of training data, due to the multitude of parameters that require tuning. Unfortunately, obtaining such ample data proves challenging, particularly in domains like medical applications, where there is a pressing need for robust models for early disease detection but a shortage of labeled data. Nevertheless, the classical supervised contrastive learning models, have shown the potential to address this challenge up to a certain limit, by utilizing deep encoder models. However, recent advancements in quantum machine learning enable the extraction of meaningful representations from extremely limited and simple data. Thus, replacing classical counterparts in classical or hybrid quantum-classical supervised contrastive models enhances feature learning capability with minimal data. Therefore, this work proposes the Q-SupCon model, a fully quantum-powered supervised contrastive learning model comprising a quantum data augmentation circuit, quantum encoder, quantum projection head, and quantum variational classifier, enabling efficient image classification with minimal labeled data. Furthermore, the novel model attains 80%, 60%, and 80% test accuracy on MNIST, KMNIST, and FMNIST datasets, marking a significant advancement in addressing the data scarcity challenge. Asitha Kottahachchi Kankanamge Don, Ibrahim Khalil 0001 |
ACM Trans. Quantum Comput. | 2 |
| 2024 | GEES: Enabling Location Privacy-Preserving Energy Saving in Multi-Access Edge ComputingabstractThe global deployment of the 5G network has led to a substantial increase in the deployment of edge servers to host web applications, catering to the growing demand for low service latency by edge web users. Yet, running edge servers 24/7 leads to enormous energy consumption and excessive carbon emissions. Energy-efficient edge resource provision is desired to achieve sustainable development goals in the new multi-access edge computing (MEC) architecture. Recently, several approaches have been proposed to solve the demand response problem for energy saving in cloud computing and MEC. However, accurate location information of edge web users should always be provided, which sacrifices users' privacy. To protect edge web users' location privacy while saving energy in MEC, we systematically formulate this location privacy-preserving edge demand response (LEDR) problem. To solve the LEDR problem effectively and efficiently, we propose a system named GEES by incorporating differential geo-obfuscation to secure user privacy while maximizing system utility and energy efficiency through inferences with theoretical analysis. Extensive and comprehensive experiments are conducted based on a synthetic real-world dataset, and the results demonstrate that GEES outperforms representative approaches by 23.02%, 31.47%, and 17.29% on average in terms of energy efficiency, user privacy and system utility. Ziqi Wang 0008, Xiaoyu Xia 0001, Minhui Xue 0001, Ibrahim Khalil 0001, Minghui LiWang, Xun Yi |
WWW | 4 |
| 2024 | An Adversarial Machine Learning Based Approach for Privacy Preserving Face Recognition in Distributed Smart City SurveillanceabstractSmart cities rely heavily on surveillance cameras for urban management and security. However, the extensive use of these cameras also raises significant concerns regarding data privacy. Unauthorized access to facial data captured by these cameras and the potential for misuse of this data poses serious threats to individuals’ privacy. Current privacy preservation solutions often compromise data usability with noise application-based approaches and vulnerable centralized data handling settings. To address these privacy challenges, we propose a novel approach that combines Adversarial Machine Learning (AML) with Federated Learning (FL). Our approach involves the use of a noise generator that perturbs surveillance data right from the source before they leave the surveillance cameras. By exclusively training the Federated Learning model on these perturbed samples, we ensure that sensitive biometric features are not shared with centralized servers. Instead, such data remains on local devices (e.g., cameras), thereby ensuring that data privacy is maintained. We performed a thorough real-world evaluation of the proposed method and achieved an accuracy of around 99.95% in standard machine learning settings. In distributed settings, we achieved an accuracy of around 96.24% using federated learning, demonstrating the practicality and effectiveness of the proposed solution. 1 1 The code is available at: https://github.com/farah-wahida/Privacy-Preserving-Face-Recognition-in-Distributed-Smart-City-Surveillance . Farah Wahida, Mahawaga Arachchige Pathum Chamikara, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Comput. Networks | 3 |
| 2024 | QARMA-FL: Quality-Aware Robust Model Aggregation for Mobile CrowdsourcingabstractOver the past few years, the improved detection and processing features of Internet-of-Things (IoT) devices have opened the doors to several mobile crowdsourcing applications. Federated Learning (FL) is being seen as an attractive framework to address the data privacy concerns of mobile users in the context of crowdsourcing. In FL on a crowdsourcing platform, constructing an effective deep neural network (DNN) is challenging. This is primarily because the quality of the global model depends on the local model quality, which can vary greatly due to differences in the computational resources, data quantity, and data quality provided by each worker. To address these challenges, we propose QARMA-FL: Quality-aware robust model aggregation for federated learning in crowdsourcing applications, where we select the local model for aggregation based on its quality and performance. We also propose a model-quality-aware incentive mechanism to reward workers, based on their contribution to model training. Our model selection and incentive mechanism is capable of detecting Free Rider attacks, identifying workers who benefit from others contributions without contributing themselves. Most existing evaluations of FL in mobile crowdsourcing studies are not based on the real-world FL scenarios. Therefore, we evaluate QARMA-FL alongside a baseline FL model in a quantity-skew, non-IID data setup where different workers contribute varying amounts of data for model training. Our diverse experiments validated QARMA-FLs performance, demonstrating its ability to efficiently aggregate models in mobile crowdsourcing scenarios, reaching baseline results with a reduced worker participation by 40% to 60%. Shehan Edirimannage, Charith Elvitigala, Ibrahim Khalil 0001, Primal Wijesekera, Xun Yi |
IEEE Internet Things J. | 3 |
| 2024 | Automated Disaster Monitoring From Social Media Posts Using AI-Based Location Intelligence and Sentiment AnalysisabstractWorldwide disasters like bushfires, earthquakes, floods, cyclones, and heatwaves have affected the lives of social media users in an unprecedented manner. They are constantly posting their level of negativity over the disaster situations at their location of interest. Understanding location-oriented sentiments about disaster situation is of prime importance for political leaders, and strategic decision-makers. To this end, we present a new fully automated algorithm based on artificial intelligence (AI) and natural language processing (NLP), for extraction of location-oriented public sentiments on global disaster situation. We designed the proposed system to obtain exhaustive knowledge and insights on social media feeds related to disaster in 110 languages through AI- and NLP-based sentiment analysis, named entity recognition (NER), anomaly detection, regression, and Getis Ord Gi* algorithms. We deployed and tested this algorithm on live Twitter feeds from 28 September to 6 October 2021. Tweets with 67 515 entities in 39 different languages were processed during this period. Our novel algorithm extracted 9727 location entities with greater than 70% confidence from live Twitter feed and displayed the locations of possible disasters with disaster intelligence. The rates of average precision, recall, and F₁-Score were measured to be 0.93, 0.88, and 0.90, respectively. Overall, the fully automated disaster monitoring solution demonstrated 97% accuracy. To the best of our knowledge, this study is the first to report location intelligence with NER, sentiment analysis, regression and anomaly detection on social media messages related to disasters and has covered the largest set of languages. Fahim K. Sufi, Ibrahim Khalil 0001 |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2024 | Weight-Based Privacy-Preserving Asynchronous SplitFed for Multimedia Healthcare DataabstractMultimedia significantly enhances modern healthcare by facilitating the analysis and sharing of diverse data, including medical images, videos, and sensor data. Integrating AI for multimedia data classification shows promise in improving healthcare services, data analysis, and decision-making. However, ensuring privacy in AI-integrated healthcare systems remains a challenge, especially with data continuously transmitted over networks. Synchronous Federated Learning (FL) is designed to address these privacy concerns by allowing end devices to collaboratively train a machine learning model without sharing data. Nonetheless, FL alone does not fully resolve privacy issues and faces efficiency challenges, particularly with devices of varying computational capabilities. In this article, we introduce an Asynchronous Partial Privacy-preserving Split-Federated Learning (APP-SplitFed) approach for smart healthcare systems. This method reduces computational demands on resource-limited devices and uses a weight-based aggregation method to allow devices of differing computational power to contribute effectively, ensuring optimal model performance and rapid convergence. Additionally, we incorporate a secure aggregation method to prevent adversaries from identifying individual models owned by healthcare institutions. Veronika Stephanie, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2024 | Towards Sustainable Trust: A Practical SGX Aided Anonymous Reputation SystemabstractReputation systems are widely used to provide a trustworthy environment and improve the sustainability of online discussions. They help users understand and evaluate the quality of information by collecting and counting feedback from different users. However, a common issue in most reputation systems is how to maintain users’ reputation and protect their anonymity simultaneously. In this paper, we introduce a new practical anonymous reputation system based on SGX. The establishment of an anonymous reputation system has a positive effect on sustainable trust in reputation-based online applications. Our system achieves the combination of reputation and anonymity by utilizing Intel SGX and the Bloom filter. The Path ORAM algorithm is also implemented to resist side-channel attacks. The experiments demonstrate that our system achieves high performance in terms of computation and storage costs. When compared to two state-of-the-art anonymous reputation systems, our system has better computation performance with at least three orders of magnitude. Xu Yang 0002, Xuechao Yang, Xun Yi, Ibrahim Khalil 0001, Shangqi Lai, Wei Wu 0001, Albert Y. Zomaya |
IEEE Trans. Sustain. Comput. | 5 |
| 2023 | ECG compression technique using fast fractals in the Internet of medical thingsabstractAbstract ECG signal is widely used in most cardiology e‐health systems. Patients may be monitored continuously for at least 12 h a day. Therefore, the ECG signal size transmitted to a hospital server during continuous monitoring is significant. Furthermore, transmission of the large size ECG signal is a power consuming process. ECG compression is one of the proposed solutions to overcome this problem. In this paper, a new fractal‐based ECG lossy compression technique is proposed. It is clear that fractal can use ECG signal self similarity characteristics efficiently to achieve high compression ratios. The proposed technique is based on developing the fractal model in conjunction with Iterated Function System. Fractal is well known as a time consuming technique, and therefore, new mathematical development is proposed to potentially reduce fractal computations. Experiments have proven the significant performance of fast fractal in comparison with the traditional version. Furthermore, the resultant compression ratios are close to the traditional fractal results and higher than other existing techniques. Ayman Ibaida, Alsharif Abuadbba, Dhiah Al-Shammary, Ibrahim Khalil 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2023 | Privacy-Preserving Microservices in Industrial Internet-of-Things-Driven Smart ApplicationsabstractMachine learning (ML) algorithms can effectively perform analytics and inferences for building smart applications, such as early detection of diseases in the Industrial Internet of Things (IIoT) and smart healthcare systems. The main components of ML, including training and testing phases, can be decomposed into microservices to improve service quality, along with fast implementation and integration with the edge and cloud services. However, the execution of ML in an edge-cloud environment introduces privacy risks to data owners (e.g., patients). In this article, we present a privacy-preserving ML framework by leveraging microservice technology for safeguarding healthcare IIoT systems. More specifically, we develop a microservice-based distributed privacy-preserving technique using differential privacy (DP) and a radial basis function network (RBFN) to balance between privacy protection and model performance in edge networks. We conduct extensive experiments to evaluate the performance of the proposed technique. The results revealed that DP has a significant influence on the model’s performance and achieves more than 90% accuracy with an epsilon value over 0.4, enhancing data protection and analytics through the implementation of microservices. Neda Bugshan, Ibrahim Khalil 0001, Nour Moustafa, Mohammad Saidur Rahman 0001 |
IEEE Internet Things J. | 2 |
| 2023 | A Triggerless Backdoor Attack and Defense Mechanism for Intelligent Task Offloading in Multi-UAV SystemsabstractIn recent years, multiunmanned aerial vehicular systems (MUAVs) have become prevalent in divergent applications: agriculture, spectrum utilization, transportation, forest fire monitoring, and among others, due to their flexible, robust, and autonomous operational maneuver. Battery-powered multiunmanned aerial vehicles (MUAVs) systems possess limited computation and communication resources, significantly reducing their functional dimension by limiting mission time and range. To address this issue, we propose a federated deep reinforcement learning (FDRL)-based intelligent and decentralized task offloading scheme for resource-constrained UAVs that can enhance the operational capability of the MUAV systems. Moreover, the proposed FDRL scheme can improve offloading policy quality while preserving data privacy in MUAV. However, such intelligent systems may fall prey to backdoor attacks that can intervene in the system’s regular operation causing rapid degradation of its performance. We introduce a novel triggerless backdoor attack scheme on intelligent task offloading UAVs and analyze its impact to gauge the resiliency of the offloading policy in the presence of an adversary. Then, we propose lightweight agnostic defense mechanisms to combat such backdoors in multi-UAV settings. The extensive simulation results show that the proposed attack and defense strategies are practical and efficient. Shafkat Islam, Shahriar Badsha, Ibrahim Khalil 0001, Mohammed Atiquzzaman, Charalambos Konstantinou |
IEEE Internet Things J. | 3 |
| 2023 | Blockchain-Enabled and Multisignature-Powered Verifiable Model for Securing Federated Learning SystemsabstractThe Internet of Things (IoT) is revolutionizing numerous industrial applications by employing smart devices in manufacturing and industrial processes. Industries based on IoT generate extensive data, typically analyzed using various machine learning (ML) models. Federated learning (FL) is an emerging, privacy-preserving ML method where clients train models locally and develop a global model based on the aggregation of local models, without sharing the local data set with a third party. However, FL methods struggle to achieve trustworthiness and incorporate accountable ML principles. Blockchain technologies are being developed across different industries to enhance trust and security. This article proposes a blockchain-enabled, verifiable model for securing FL within IoT systems. Our proposed framework combines a trusted execution platform (TEE) to secure each client’s local model training process, and multisignature-powered global model verification to ensure ML model verifiability. We conducted several experiments with different data sets to assess our proposed framework. The experiments demonstrated the high efficiency and scalability of the proposed framework. Aditya Pribadi Kalapaaking, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
IEEE Internet Things J. | 2 |
| 2023 | Blockchain-Based AI-Enabled Industry 4.0 CPS Protection Against Advanced Persistent ThreatabstractIndustry 4.0 is all about doing things in a concurrent, secure, and fine-grained manner. Internet of Things edge sensors and their associated data play a predominant role in today’s industry ecosystem. Breaching data or forging source devices after injecting advanced persistent threats (APTs) damages the industry owners’ money and loss of operators’ lives. The existing challenges include APT injection attacks targeting vulnerable edge devices, insecure data transportation, trust inconsistencies among stakeholders, incompliant data storing mechanisms, etc. Edge servers often suffer because of their lightweight computation capacity to stamp out unauthorized data or instructions, which, in essence, makes them exposed to attackers. When attackers target edge servers while transporting data using traditional public-key infrastructure-rendered trusts, consortium blockchain (CBC) offers proven techniques to transfer and maintain those sensitive data securely. With the recent improvement of edge machine learning, edge devices can filter malicious data at their end, which largely motivates us to institute a blockchain and artificial intelligence-aligned APT detection system. The unique contributions of this article include efficient APT detection at the edge and transparent recording of the detection history in an immutable blockchain ledger. In line with that, the certificateless data transfer mechanism boosts trust among collaborators and ensures an economical and sustainable mechanism after eliminating existing certificate authority. Finally, the edge-compliant storage technique facilitates efficient predictive maintenance. The respective experimental outcomes reveal that the proposed technique outperforms the other competing systems and models. Ziaur Rahman 0003, Xun Yi, Ibrahim Khalil 0001 |
IEEE Internet Things J. | 3 |
| 2023 | Privacy-Preserving Ensemble Infused Enhanced Deep Neural Network Framework for Edge Cloud ConvergenceabstractWe propose a privacy-preserving ensemble infused enhanced deep neural network (DNN)-based learning framework in this article for Internet of Things (IoT), edge, and cloud convergence in the context of healthcare. In the convergence, the edge server is used for both storing IoT produced bioimage and hosting DNN algorithm for local model training. The cloud is used for ensembling local models. The DNN-based training process of a model with a local data set suffers from low accuracy, which can be improved by the aforementioned convergence and ensemble learning. The ensemble learning allows multiple participants to outsource their local model for producing a generalized final model with high accuracy. Nevertheless, ensemble learning elevates the risk of leaking sensitive private data from the final model. The proposed framework presents a differential privacy-based privacy-preserving DNN with transfer learning for a local model generation to ensure minimal loss and higher efficiency at the edge server. We conduct several experiments to evaluate the performance of our proposed framework. Veronika Stephanie, Ibrahim Khalil 0001, Mohammad Saidur Rahman 0001, Mohammed Atiquzzaman |
IEEE Internet Things J. | 2 |
| 2023 | Digital Twin Enabled Asynchronous SplitFed Learning in E-Healthcare SystemsabstractThe advancement of Industrial Internet of Things (IIoT) technology has resulted in the fourth industrial revolution, or Industry 4.0, enabling industries to enhance productivity. However, despite the benefits, there remain significant challenges, such as resource heterogeneity, communication efficiency, and data privacy, that limit the applications of IIoT in privacy-sensitive domains like healthcare. In order to protect data privacy, Federated Learning (FL) has been suggested as a solution, involving the sharing of model parameters rather than data itself. Current FL applications, however, still struggle with cost efficiency, especially when IIoT devices with heterogenous resources are involved. To address this, this paper proposes Digital Twin (DT) enabled Asynchronous SplitFed Learning (DT-ASFL) for classification tasks in the e-healthcare system over mobile networks. We first develop SplitFed Learning to introduce communication efficiency in the e-healthcare system, sending only extracted features during the learning process instead of the entire learning model. This enables resource-constrained devices to participate in the learning process by allowing the participants to train a partial learning model. DT is then employed to provide real-time statuses of IIoT devices deployed in the system, enabling asynchronous model updates in SplitFed Learning. The experimental results demonstrate the efficacy of DT-ASFL compared to the existing methods. Veronika Stephanie, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
IEEE J. Sel. Areas Commun. | 2 |
| 2023 | Toward Trustworthy and Privacy-Preserving Federated Deep Learning Service Framework for Industrial Internet of ThingsabstractIn this article, we propose a trustworthy privacy-preserving federated learning (FL)-based deep learning (DL) service framework for Industrial Internet of Things-enabled systems. FL mitigates the privacy issues of the traditional collaborative learning model by aggregating multiple locally trained models without sharing any datasets among the participants. Nevertheless, the FL-based DL (FDL) model cannot be trusted as it is susceptible to intermediate results and data structure leakage during the model aggregation process. The proposed framework introduces an edge and cloud-powered service-oriented architecture identifying the key components and a service model for residual networks-based FDL with differential privacy for generating trustworthy locally trained models. The service model decomposes the functionality of the overall FDL process as services to ensure trustworthy execution through privacy preservation. Finally, we develop a privacy-preserving local model aggregation mechanism for FDL. We perform several experiments to assess the performance of the proposed framework. Neda Bugshan, Ibrahim Khalil 0001, Mohammad Saidur Rahman 0001, Mohammed Atiquzzaman, Xun Yi, Shahriar Badsha |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | An Intelligent Privacy Preservation Scheme for EV Charging InfrastructureabstractThe electric vehicle (EV) charging ecosystem, being a distinguishable paradigm of IIoT infrastructure, consists of distributed and complex hybrid systems that demand adaptive data-driven cyber-defense mechanisms to tackle the ever-growing attack vectors of cyber-physical systems. We propose an adaptive differential privacy-based federated learning framework for building a collaborative network intrusion detection system model for EV charging stations (EVCS). We use utility optimized local differential privacy to provide data privacy to the local network traffic data of each EVCS. Moreover, we propose a reinforcement learning-based intelligent privacy allocation mechanism at the EVCS level. The main significance of the proposed mechanism is that it can make privacy provisioning adaptive to the extent of privacy breaching rate, and dynamically optimize the privacy budget and the utility to avoid human intervention such as domain knowledge experts. The experimental results confirm the efficacy of our proposed mechanism and achieves appropriate privacy provisioning accuracy to approximately 95%. Shafkat Islam, Shahriar Badsha, Shamik Sengupta, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
IEEE Trans. Ind. Informatics | 4 |
| 2023 | Blockchain-Based Federated Learning With Secure Aggregation in Trusted Execution Environment for Internet-of-ThingsabstractThis article proposes a blockchain-based federated learning (FL) framework with Intel Software Guard Extension (SGX)-based trusted execution environment (TEE) to securely aggregate local models in Industrial Internet-of-Things (IIoTs). In FL, local models can be tampered with by attackers. Hence, a global model generated from the tampered local models can be erroneous. Therefore, the proposed framework leverages a blockchain network for secure model aggregation. Each blockchain node hosts an SGX-enabled processor that securely performs the FL-based aggregation tasks to generate a global model. Blockchain nodes can verify the authenticity of the aggregated model, run a blockchain consensus mechanism to ensure the integrity of the model, and add it to the distributed ledger for tamper-proof storage. Each cluster can obtain the aggregated model from the blockchain and verify its integrity before using it. We conducted several experiments with different CNN models and datasets to evaluate the performance of the proposed framework. Aditya Pribadi Kalapaaking, Ibrahim Khalil 0001, Mohammad Saidur Rahman 0001, Mohammed Atiquzzaman, Xun Yi, Mahathir Almashor |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | Trustworthy Privacy-Preserving Hierarchical Ensemble and Federated Learning in Healthcare 4.0 With BlockchainabstractThe advancement of internet and communication technologies has led to the era of Industry 4.0. This shift is followed by healthcare industries creating the term Healthcare 4.0. In Healthcare 4.0, the use of Internet of Things-enabled medical imaging devices for early disease detection has enabled medical practitioners to increase healthcare institutions' quality of service. However, Healthcare 4.0 is still lagging in artificial intelligence and big data compared to other Industry 4.0 due to data privacy concerns. In addition, institutions' diverse storage and computing capabilities restrict institutions from incorporating the same training model structure. This article presents a secure multiparty computation-based ensemble federated learning with blockchain that enables heterogeneous models to collaboratively learn from healthcare institutions' data without violating users' privacy. Blockchain properties also allow the party to enjoy data integrity without trust in a centralized server while also providing each healthcare institution with auditability and version control capability. Veronika Stephanie, Ibrahim Khalil 0001, Mohammed Atiquzzaman, Xun Yi |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | A Security-Enhanced Certificateless Conditional Privacy-Preserving Authentication Scheme for Vehicular Ad Hoc NetworksabstractBy adopting advanced Internet of Things (IoT) technology to sense and collect traffic-related information to improve traffic safety and efficiency, the vehicular ad hoc network (VANET) is becoming a prominent application that changes human driving experiences in the current era. Because frequent data exchange occurs in open environments, VANETs are inherently vulnerable to security and privacy attacks. In history, many certificateless aggregate signature (CLAS) schemes with conditional privacy-preserving (CPP) have been proposed to ensure the authenticity and integrity of the exchanged data and protect users’ privacy. However, we reveal that the state-of-the-art schemes cannot be deployed in practical VANET applications by proposing concrete signature forgery attacks. To this end, we propose a new CLAS-based authentication scheme with CPP for VANETs. The rigorous security proofs based on the standard cryptographic assumption show that the scheme has enhanced security. Moreover, theoretical analysis and experimental evaluation illustrate the practicality of our design. Xun Yi, Alsharif Abuadbba, Ibrahim Khalil 0001, Xinyi Huang 0001, Feihong Xu |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2023 | Smart Policy Control for Securing Federated Learning Management SystemabstractThe widespread adoption of Internet of Things (IoT) devices in smart cities, intelligent healthcare systems, and various real-world applications have resulted in the generation of vast amounts of data, often analyzed using different Machine Learning (ML) models. Federated learning (FL) has been acknowledged as a privacy-preserving machine learning technology, where multiple parties cooperatively train ML models without exchanging raw data. However, the current FL architecture does not allow for an audit of the training process due to the various data-protection policies implemented by each FL participant. Furthermore, there is no global model verifiability available in the current architecture. This paper proposes a smart contract-based policy control for securing the Federated Learning (FL) management system. First, we develop and deploy a smart contract-based local training policy control on the FL participants’ side. This policy control is used to verify the training process, ensuring that the evaluation process follows the same rules for all FL participants. We then enforce a smart contract-based aggregation policy to manage the global model aggregation process. Upon completion, the aggregated model and policy are stored on blockchain-based storage. Subsequently, we distribute the aggregated global model and the smart contract to all FL participants. Our proposed method uses smart policy control to manage access and verify the integrity of machine learning models. We conducted multiple experiments with various machine learning architectures and datasets to evaluate our proposed framework, such as MNIST and CIFAR-10. Aditya Pribadi Kalapaaking, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | AI-Enabled Secure Microservices in Edge Computing: Opportunities and ChallengesabstractThe paradigm of edge computing has formed an innovative scope within the domain of the Internet of Things (IoT) through expanding the services of the cloud to the network edge to design distributed architectures and securely enhance decision-making applications. Due to the heterogeneous, distributed and resource-constrained essence of edge Computing, edge applications are required to be developed as a set of lightweight and interdependent modules. As this concept aligns with the objectives of microservice architecture, effective implementation of microservices-based edge applications within IoT networks has the prospective of fully leveraging edge nodes capabilities. Deploying microservices at IoT edge faces plenty of challenges associated with security and privacy. Advances in Artificial Intelligence (AI) (especially Machine Learning), and the easy access to resources with powerful computing providing opportunities for deriving precise models and developing different intelligent applications at the edge of network. In this study, an extensive survey is presented for securing edge computing-based AI Microservices to elucidate the challenges of IoT management and enable secure decision-making systems at the edge. We present recent research studies on edge AI and microservices orchestration and highlight key requirements as well as challenges of securing Microservices at IoT edge. We also propose a Microservices-based edge computing framework that provides secure edge AI algorithms as Microservices utilizing the containerization technology to offer automated and secure AI-based applications at the network edge. Firas Al-Doghman, Nour Moustafa, Ibrahim Khalil 0001, Nasrin Sohrabi, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | Authenticated Data Sharing With Privacy Protection and Batch Verification for Healthcare IoTabstractThe healthcare Internet of Things (IoT) is rapidly becoming an invaluable tool in the healthcare industry. However, sharing data in healthcare IoT raises many security and privacy concerns, such as how to ensure data integrity, source authentication, and data privacy. Redactable signature schemes (${{\sf RSS}}$s) could be a feasible solution to address this question because it allows a signature holder to independently delete the privacy-sensitive part of the authenticated data without invalidating the respective signature. This flexible data sharing mechanism not only protects data privacy but also saves bandwidth. However, the state-of-the-art${{\sf RSS}}$s suffer from either the costly public key management problem or the secret key escrow problem. Another drawback of these schemes lies in their computation and communication overheads and hence are quite expensive for constrained devices. To address these challenging issues, in this work, we first propose the notion of certificateless${{\sf RSS}}$. We then provide an efficient instantiation of our scheme and prove its security under cryptographic assumptions. Our construction supports batch verification and redaction control, which further saves bandwidth and enhances the security of shared data by preventing the dishonest holder from arbitrarily editing data. Moreover, the comparison analysis of theory and experiment with more recent works shows the practicability of our design. Xun Yi, Alsharif Abuadbba, Ibrahim Khalil 0001, Surya Nepal, Xinyi Huang 0001 |
IEEE Trans. Sustain. Comput. | 4 |
| 2022 | Local Differential Privacy for Federated Learning
Mahawaga Arachchige Pathum Chamikara, Dongxi Liu, Seyit Ahmet Çamtepe, Surya Nepal, Marthie Grobler, Peter Bertók, Ibrahim Khalil 0001 |
ESORICS (1) | 7 |
| 2022 | Blockchain-Based Access Control for Secure Smart Industry Management Systems
Aditya Pribadi Kalapaaking, Ibrahim Khalil 0001, Mohammad Saidur Rahman 0001, Abdelaziz Bouras |
NSS | 2 |
| 2022 | Forward-Secure Edge Authentication for GraphsabstractAbstract The edge authentication of graphs has been studied in the literature because graphs are one of the most widely used data organization structures. The majority of such schemes cannot be used to authenticate general directed graphs (GDGs); other schemes cannot be used for addressing either the issue of dynamic update or the issue of information leakage (such as the existence of nodes/edges and structural relationship of the graph). Also, all the existing schemes do not consider the forward security: if the signer’s secret key has been compromised, all previously generated signatures remain valid. This property provides high-level security protection for authentication schemes. To address these issues, in this work, we propose a forward-secure edge authentication scheme for GDGs. Observe that existing such schemes can only give a proof such that ‘there is an edge between nodes $u$ and $v$’. Our scheme, however, can directly give a proof such that ‘there is no edge between nodes $u$ and $v$’, which makes the function of edge authentication schemes more diverse. Moreover, our proposed scheme is proven to be secure against an adaptive chosen-message adversary in the random oracle model. To show its desirable performance, we analyze the computational costs of our scheme and compare it with other related schemes in terms of features. Xun Yi, Alsharif Abuadbba, Ibrahim Khalil 0001, Surya Nepal, Xinyi Huang 0001 |
Comput. J. | 4 |
| 2022 | Privacy Aware Internet of Medical Things Data Certification Framework on Healthcare Blockchain of 5G Edge
Mohammad Saidur Rahman 0001, Abdulatif Alabdulatif, Ibrahim Khalil 0001 |
Comput. Commun. | 3 |
| 2022 | Radial Basis Function Network with Differential Privacy
Neda Bugshan, Ibrahim Khalil 0001, Nour Moustafa, Mahathir Almashor, Alsharif Abuadbba |
Future Gener. Comput. Syst. | 2 |
| 2022 | Secure and Lightweight Authentication for Mobile-Edge Computing-Enabled WBANsabstractWireless body area networks (WBANs) technology nowadays has become a promising networking paradigm in the Internet of Things (IoT) as it can provide people with high quality of life and high level of medical service. In order to ensure the security and privacy of patients’ sensitive biomedical data and the efficiency of message processing across different devices, it is critical to provide a secure and lightweight authentication scheme for WBANs. In this article, we propose an extra lightweight authentication scheme for mobile-edge computing-enabled WBANs. Two different authentication phases based on the modular square roots technique are designed: one is the intra-BAN authentication between the sensor node and edge node (EN), and the other is the inter-BAN authentication between EN and application provider. The proposed scheme offers robust security by providing comprehensive security analysis. Performance is also evaluated in terms of computation, communication, and storage costs. The evaluation results demonstrate that the proposed scheme achieves a reduction of at least 90% in computation cost and at least 30% in communication cost when compared to four other related schemes. Xu Yang 0002, Xun Yi, Ibrahim Khalil 0001, Elisa Bertino, Surya Nepal, Xinyi Huang 0001 |
IEEE Internet Things J. | 3 |
| 2022 | Blockchain-Based Secure and Lightweight Authentication for Internet of ThingsabstractOver the past decade, the Internet of Things (IoT) is widely adopted in various domains, including education, commerce, government, and healthcare. There are also many IoT-based applications drawn significant attentions in recent years. With the increasing numbers of the connected devices in the IoT system, one of the challenging tasks is to ensure devices’ authenticity, which allows users to have a high confidence in the decision. In addition, due to the heterogeneity of the IoT system and the resource-constrained devices, how to efficiently manage such system and guarantee the security and privacy for devices is concerned. In this article, we proposed a new blockchain-based authentication scheme to meet the challenges. Our proposed framework combines the blockchain technique and the modular square root algorithm to achieve an effective authentication process. Besides, we demonstrate the security and utility of the proposed scheme by providing the security analysis and the detailed experiment. Xu Yang 0002, Xuechao Yang, Xun Yi, Ibrahim Khalil 0001, Xiaotong Zhou, Debiao He, Xinyi Huang 0001, Surya Nepal |
IEEE Internet Things J. | 4 |
| 2022 | Certificate-Based Anonymous Authentication With Efficient Aggregation for Wireless Medical Sensor NetworksabstractWireless medical sensor networks (WMSNs) have aroused widespread attention in recent years with the development of Internet of Things (IoT) technology. WMSNs offer many new opportunities for healthcare professionals to monitor patients and patient self-monitoring. To overcome the resource (such as memory and power) limitations of sensors and attain data security of patients’ private medical information, researchers have designed plenty of work for securing WMSNs. For years, certificate-based aggregate signature (CBAS) schemes have been put forward for WMSNs to prevent patients’ sensitive medical data from being tampered with and damaged. In this work, we analyze the security flaws of a very recent CBAS scheme proposed by Vermaet al.(2021) by presenting two types of security attacks. We later propose a CBAS scheme with user anonymity protection for WMSNs and prove its security based on the standard cryptographic assumption. The performance comparison results from theory and experiment illustrate the practicality of our design. Xun Yi, Alsharif Abuadbba, Ibrahim Khalil 0001, Surya Nepal, Xinyi Huang 0001, Xingfu Yan |
IEEE Internet Things J. | 4 |
| 2022 | Privacy-preserving location data stream clustering on mobile edge computing and cloud
Veronika Stephanie, Mahawaga Arachchige Pathum Chamikara, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Inf. Syst. | 3 |
| 2022 | A Blockchain-Enabled Privacy-Preserving Verifiable Query Framework for Securing Cloud-Assisted Industrial Internet of Things SystemsabstractAdvanced Industrial Internet-of-Things (IIoT), such as smart grids, 5G-enabled unmanned aerial vehicles (UAV), and supply chain 4.o, can be used to facilitate smart management. Nevertheless, IIoT systems generate huge amounts of data that need to be outsourced to the cloud for storing and providing real-time search facilities to end-users. Outsourcing IIoT data to a third-party cloud service provider (CSP) introduces several data privacy and integrity issues related to verifying the reliability of users’ queries and aggregated outcomes. In this article, we propose a blockchain-based framework for provisioning a privacy-preserving and verifiable query facility to end-users in IIoT systems. The framework uses blockchain to store IoT data as on-chain data and the cloud to store extensive data (e.g., image) as off-chain data and provisioning search services to users by executing a query in both on-chain and off-chain data and generating an aggregated result. Besides, it introduces a new privacy-preserving query mechanism for ensuring sensitive data privacy during query execution. A data owner encrypts both on-chain and off-chain data in the privacy-preserving query mechanism before sending it to the blockchain and cloud. A CSP can perform search operations on the encrypted on-chain and off-chain data to ensure sensitive data privacy. A multisignature-powered query verification model is also built for the blockchain. The query verification model allows each blockchain node to endorse the query result individually and a user to verify the endorsement of the query result before use. The experiments revealed the high efficiency and scalability of the proposed framework. Mohammad Saidur Rahman 0001, Ibrahim Khalil 0001, Nour Moustafa, Aditya Pribadi Kalapaaking, Abdelaziz Bouras |
IEEE Trans. Ind. Informatics | 2 |
| 2022 | A Lossless Data-Hiding based IoT Data Authenticity Model in Edge-AI for Connected LivingabstractEdge computing is an emerging technology for the acquisition of Internet-of-Things (IoT) data and provisioning different services in connected living. Artificial Intelligence (AI) powered edge devices (edge-AI) facilitate intelligent IoT data acquisition and services through data analytics. However, data in edge networks are prone to several security threats such as external and internal attacks and transmission errors. Attackers can inject false data during data acquisition or modify stored data in the edge data storage to hamper data analytics. Therefore, an edge-AI device must verify the authenticity of IoT data before using them in data analytics. This article presents an IoT data authenticity model in edge-AI for a connected living using data hiding techniques. Our proposed data authenticity model securely hides the data source’s identification number within IoT data before sending it to edge devices. Edge-AI devices extract hidden information for verifying data authenticity. Existing data hiding approaches for biosignal cannot reconstruct original IoT data after extracting the hidden message from it (i.e., lossy) and are not usable for IoT data authenticity. We propose the first lossless IoT data hiding technique in this article based on error-correcting codes (ECCs). We conduct several experiments to demonstrate the performance of our proposed method. Experimental results establish the lossless property of the proposed approach while maintaining other data hiding properties. Mohammad Saidur Rahman 0001, Ibrahim Khalil 0001, Xun Yi, Mohammed Atiquzzaman, Elisa Bertino |
ACM Trans. Internet Techn. | 2 |
| 2022 | Efficient and Anonymous Authentication for Healthcare Service With Cloud Based WBANsabstractAs a promising technology in the development of human healthcare services, the wireless body area networks (WBANs) technology has attracted widespread attention in recent years from both industry and academia. However, due to the sensitiveness of the medical system and the capability limitation of the wearable devices, security, privacy, and efficiency of the healthcare services in WBANs are remained as major challenges. Although different authentication mechanisms have been designed to meet the challenges in recent years, most of them suffer from some functional defects or security problems. In this article, we firstly provide a review and cryptanalysis on the state-of-the-art authentication scheme. In order to meet the challenges and address the drawbacks in previous works, we then propose a new efficient and anonymous authentication scheme for cloud based WBANs. Through the security analysis, we show that our scheme could overcome the weaknesses in previous schemes and meet all the security requirements. Besides, we show the advantages of the proposed scheme through performance evaluation in terms of functionality features, computation overhead, communication overhead and storage overhead, which shows our scheme is more appropriate for practical applications on healthcare services. Xu Yang 0002, Xun Yi, Surya Nepal, Ibrahim Khalil 0001, Xinyi Huang 0001, Jian Shen 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | Blockchain for IoT: A Critical Analysis Concerning Performance and Scalability
Ziaur Rahman 0003, Xun Yi, Ibrahim Khalil 0001, Andrei V. Kelarev |
QSHINE | 3 |
| 2021 | Chaos and Logistic Map Based Key Generation Technique for AES-Driven IoT Security
Ziaur Rahman 0003, Xun Yi, Ibrahim Khalil 0001, Mousumi Akter Sumi |
QSHINE | 3 |
| 2021 | Efficient and Anonymous Authentication for Healthcare Service With Cloud Based WBANsabstractWireless body area networks (WBANs) technology nowadays has become a promising networking paradigm in the Internet of Things (IoT) as it can provide people with high quality of life and a high level of medical service. Specifically, to make sure those people with a high incidence of chronic diseases, including hypertension, diabetes, and cardiovascular diseases, are taking care of which further reduces social costs. Thus, both industry and academia in recent years pay widely attention to WBANs technology. After years of research, security, privacy, and efficiency of the healthcare services in WBANs have remained as major challenges. Although different authentication mechanisms have been designed to meet the challenges in recent years, most of them suffer from some functional defects or security problems. To ensure the security and privacy of patients’ sensitive biomedical data and the efficiency of message processing across different devices, it is critical to provide a secure and lightweight authentication scheme for WBANs. Xu Yang 0002, Xun Yi, Surya Nepal, Ibrahim Khalil 0001, Xinyi Huang 0001, Jian Shen 0001 |
SERVICES | 4 |
| 2021 | EdgeSOM: Distributed Hierarchical Edge-driven IoT Data Analytics Framework
Kassem Bagher, Ibrahim Khalil 0001, Abdulatif Alabdulatif, Mohammed Atiquzzaman |
Comput. Commun. | 2 |
| 2021 | Privacy preserving distributed machine learning with federated learning
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe |
Comput. Commun. | 3 |
| 2021 | PPaaS: Privacy Preservation as a Service
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe |
Comput. Commun. | 3 |
| 2021 | Cost-Effective Authenticated Data Redaction With Privacy Protection in IoTabstractIn a typical e-healthcare system, it is common for users' physiological data collected by Internet-of-Things (IoT) devices to be processed and shared in a third-party environment. To improve service quality, healthcare data sharing in third-party environments needs to ensure the integrity, source authentication, and privacy of the data. Redactable signature schemes (RSSs) are designed to address this concern over the past decades. More concretely, an RSS allows a signature holder to delete privacy-sensitive parts of the signed data and derive a valid signature for the retained data without any help from the original signer. This also provides a flexible data sharing mechanism in a bandwidth-saving manner. However, almost all of the existing RSSs are built on top of public-key infrastructure (PKI) systems, which involve heavyweight public-key management problems and are not suitable for resource-limited IoT applications. Besides, we argue that the only known PKI independent RSS for IoT has some security flaws and requires a large storage space. In this work, we eliminate some of the costs associated with PKI and certificates (such as key managements and certificate verifications) in traditional RSS and propose the first identity-based RSS satisfying the requirements of protecting the integrity and source authentication with selective disclosure control for healthcare data sharing in IoT. We prove the security of the scheme in the random oracle model under the k-SDH assumption. Theoretical comparison and experimental analysis show that our construction has a practical performance. As an extension, we also discuss how to extend our design to achieve fine-grained redaction control, which provides a feasible strategy for a signer to prevent additional redaction or arbitrary redaction from dishonest signature holders. Xun Yi, Alsharif Abuadbba, Ibrahim Khalil 0001, Surya Nepal, Xinyi Huang 0001 |
IEEE Internet Things J. | 4 |
| 2021 | ALICIA: Applied Intelligence in blockchain based VANET: Accident Validation as a Case Study
Shirshak Raja Maskey, Shahriar Badsha, Shamik Sengupta, Ibrahim Khalil 0001 |
Inf. Process. Manag. | 4 |
| 2021 | Towards secure and practical consensus for blockchain based VANET
Sowmya Kudva, Shahriar Badsha, Shamik Sengupta, Ibrahim Khalil 0001, Albert Y. Zomaya |
Inf. Sci. | 4 |
| 2021 | A scalable blockchain based trust management in VANET routing protocol
Sowmya Kudva, Shahriar Badsha, Shamik Sengupta, Hung Manh La, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
J. Parallel Distributed Comput. | 5 |
| 2021 | Reversible Biosignal Steganography Approach for Authenticating Biosignals Using Extended Binary Golay CodeabstractWe present a reversible biosignal steganography method to authenticate the source of biosignal in this paper. Cloud is being a popular platform for storing a large volume of biosignals such as an electrocardiogram (ECG), electroencephalogram (EEG), and photoplethysmogram (PPG). However, outsourcing biosignals to the cloud may introduce authenticity issues. For instance, patient data can be altered, or fake patient data can be inserted by the dishonest cloud service provider or attacker for giving benefits to business organizations such as insurance service providers. Steganography approaches can be used to hide data source's identification data before outsourcing to the cloud for maintaining authenticity. Existing biosignal steganography approaches fail to reconstruct original biosignal after applying a reverse data hiding technique. In other words, current biosignal steganography approaches are irreversible. Reversible biosignal steganography method is required for protecting biosignal data from deterioration and efficient use by its stakeholders. In this work, we develop a reversible biosignal steganography approach using the Extended Binary Golay Code based error correction method. Our proposed method embeds secret authentication message as an error within different types of biosignals such as ECG, PPG, and EEG. Extended Binary Golay Code based error correction method is used to extract the secret message, and reconstruct original biosignal. We conduct a set of experiments for evaluating the performance of our proposed method. Mohammad Saidur Rahman 0001, Ibrahim Khalil 0001, Xun Yi |
IEEE J. Biomed. Health Informatics | 2 |
| 2021 | Privacy Preserving Location-Aware Personalized Web Service RecommendationsabstractThe personalized Web service recommendation based on Quality of Service (QoS) is gaining increasing popularity due to its promising ability to help users find high quality services. Studies suggest that it is beneficial to use Collaborative Filtering (CF)-based techniques to facilitate Web service recommendations which can achieve high accuracy in predicting the QoS for unobserved Web services. With the QoS, location of users and Web services has been another significant factor in predicting the QoS values. The more factors that are available to the service providers, the more accurate predictions can be generated. However these factors are privacy sensitive and therefore it is risky to disclose them to any third party service provider. To address this challenge, in this paper we develop a privacy preserving protocol to predict missing QoS values and thereby providing Web service recommendations based on past QoS experiences and locations of users. Our protocol is able to achieve user privacy by means of encrypting the QoS and location as well as to select suitable Web services for users without disclosing any private information. We conduct extensive experimental analysis on publicly available data sets and prove that our method is both secure and practical. Shahriar Badsha, Xun Yi, Ibrahim Khalil 0001, Dongxi Liu, Surya Nepal, Elisa Bertino, Kwok-Yan Lam |
IEEE Trans. Serv. Comput. | 3 |
| 2021 | An Integrated Framework for Privacy-Preserving Based Anomaly Detection for Cyber-Physical SystemsabstractProtecting Cyber-physical Systems (CPSs) is highly important for preserving sensitive information and detecting cyber threats. Developing a robust privacy-preserving anomaly detection method requires physical and network data about the systems, such as Supervisory Control and Data Acquisition (SCADA), for protecting original data and recognising cyber-attacks. In this paper, a new privacy-preserving anomaly detection framework, so-called PPAD-CPS, is proposed for protecting confidential information and discovering malicious observations in power systems and their network traffic. The framework involves two main modules. First, a data pre-processing module is suggested for filtering and transforming original data into a new format that achieves the target of privacy preservation. Second, an anomaly detection module is suggested using a Gaussian Mixture Model (GMM) and Kalman Filter (KF) for precisely estimating the posterior probabilities of legitimate and anomalous events. The performance of the PPAD-CPS framework is assessed using two public datasets, namely the Power System and UNSW-NB15 dataset. The experimental results show that the framework is more effective than four recent techniques for obtaining high privacy levels. Moreover, the framework outperforms seven peer anomaly detection techniques in terms of detection rate, false positive rate, and computational time. Marwa Keshk, Elena Sitnikova, Nour Moustafa, Jiankun Hu, Ibrahim Khalil 0001 |
IEEE Trans. Sustain. Comput. | 5 |
| 2020 | Privacy-Preserving Authentication for Tree-Structured Data with Designated Verification in Outsourced Environments
Xun Yi, Alsharif Abuadbba, Ibrahim Khalil 0001, Xu Yang 0002, Surya Nepal, Xinyi Huang 0001 |
ProvSec | 4 |
| 2020 | Formalizing Dynamic Behaviors of Smart Contract Workflow in Smart Healthcare Supply Chain
Mohammad Saidur Rahman 0001, Ibrahim Khalil 0001, Abdelaziz Bouras |
SecureComm (2) | 2 |
| 2020 | Privacy Preserving Face Recognition Utilizing Differential Privacy
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe |
Comput. Secur. | 3 |
| 2020 | Towards privacy preserving AI based composition framework in edge networks using fully homomorphic encryption
Mohammad Saidur Rahman 0001, Ibrahim Khalil 0001, Mohammed Atiquzzaman, Xun Yi |
Eng. Appl. Artif. Intell. | 2 |
| 2020 | Local Differential Privacy for Deep LearningabstractThe Internet of Things (IoT) is transforming major industries, including but not limited to healthcare, agriculture, finance, energy, and transportation. IoT platforms are continually improving with innovations, such as the amalgamation of software-defined networks (SDNs) and network function virtualization (NFV) in the edge-cloud interplay. Deep learning (DL) is becoming popular due to its remarkable accuracy when trained with a massive amount of data such as generated by IoT. However, DL algorithms tend to leak privacy when trained on highly sensitive crowd-sourced data such as medical data. The existing privacy-preserving DL algorithms rely on the traditional server-centric approaches requiring high processing powers. We propose a new local differentially private (LDP) algorithm named LATENT that redesigns the training process. LATENT enables a data owner to add a randomization layer before data leave the data owners' devices and reach a potentially untrusted machine learning service. This feature is achieved by splitting the architecture of a convolutional neural network (CNN) into three layers: 1) convolutional module (CNM); 2) randomization module; and 3) fully connected module. Hence, the randomization module can operate as an NFV privacy preservation service in an SDN-controlled NFV, making LATENT more practical for IoT-driven cloud-based environments compared to existing approaches. The randomization module employs a newly proposed LDP protocol named utility enhancing randomization, which allows LATENT to maintain high utility compared to existing LDP protocols. Our experimental evaluation of LATENT on convolutional deep neural networks demonstrates excellent accuracy (e.g., 91%-96%) with high model quality even under low privacy budgets (e.g., ε = 0.5). Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe, Mohammed Atiquzzaman |
IEEE Internet Things J. | 3 |
| 2020 | Efficient privacy preservation of big data for accurate data mining
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Dongxi Liu, Seyit Ahmet Çamtepe, Ibrahim Khalil 0001 |
Inf. Sci. | 5 |
| 2020 | Lightweight privacy preservation for secondary users in cognitive radio networks
Yali Zeng, Li Xu 0002, Xu Yang 0002, Xun Yi, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 5 |
| 2020 | Towards secure big data analytic for cloud-enabled applications with fully homomorphic encryption
Abdulatif Alabdulatif, Ibrahim Khalil 0001, Xun Yi |
J. Parallel Distributed Comput. | 2 |
| 2020 | A Trustworthy Privacy Preserving Framework for Machine Learning in Industrial IoT SystemsabstractIndustrial Internet of Things (IIoT) is revolutionizing many leading industries such as energy, agriculture, mining, transportation, and healthcare. IIoT is a major driving force for Industry 4.0, which heavily utilizes machine learning (ML) to capitalize on the massive interconnection and large volumes of IIoT data. However, ML models that are trained on sensitive data tend to leak privacy to adversarial attacks, limiting its full potential in Industry 4.0. This article introduces a framework named PriModChain that enforces privacy and trustworthiness on IIoT data by amalgamating differential privacy, federated ML, Ethereum blockchain, and smart contracts. The feasibility of PriModChain in terms of privacy, security, reliability, safety, and resilience is evaluated using simulations developed in Python with socket programming on a general-purpose computer. We used Ganache_v2.0.1 local test network for the local experiments and Kovan test network for the public blockchain testing. We verify the proposed security protocol using Scyther_v1.1.3 protocol verifier. Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Ibrahim Khalil 0001, Dongxi Liu, Seyit Ahmet Çamtepe, Mohammed Atiquzzaman |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | Fully Homomorphic based Privacy-Preserving Distributed Expectation Maximization on CloudabstractExpectation maximization (EM) is a clustering-based machine learning algorithm that is widely used in many areas of science (e.g., bioinformatics and computer vision) to find maximum likelihood and maximum a posteriori estimates for models with latent variables. To deploy such an algorithm in cloud environments, security and privacy issues need be considered to avoid data breaches or abuses by external malicious parties or even by cloud service providers. However, the processing performance of the EM algorithm poses a challenge in terms of building a secure environment. This article describes an innovative and practical privacy-preserving EM algorithm for cloud systems that addresses this challenge, and estimates the EM parameters in an accurate and secure manner. Fully homomorphic encryption (FHE) is used to ensure the privacy of both the EM algorithm computations and the users' sensitive data in the cloud. A distributed-based approach is also proposed to overcome the overheads of FHE computations and ensure a fast convergence of the EM algorithm. The conducted experiments demonstrate a significant improvement in the convergence time of the distributed EM algorithm, while achieving a high level of accuracy and reducing the associated computational FHE overheads. Abdulatif Alabdulatif, Ibrahim Khalil 0001, Albert Y. Zomaya, Zahir Tari, Xun Yi |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2019 | Collaborative extreme learning machine with a confidence interval for P2P learning in healthcare
Rongjun Xie, Ibrahim Khalil 0001, Shahriar Badsha, Mohammed Atiquzzaman |
Comput. Networks | 2 |
| 2019 | An efficient and scalable privacy preserving algorithm for big data and data streams
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Dongxi Liu, Seyit Ahmet Çamtepe, Ibrahim Khalil 0001 |
Comput. Secur. | 5 |
| 2019 | A new privacy-preserving authentication protocol for anonymous web browsingabstractSummary Anonymous authentication technique receives wide attention in recent years since it can protect users' privacy. Anonymous web browsing refers to utilization of the World Wide Web that hides a user's personally identifiable information from the websites visited. Even if a user can hide the IP address and other physical information with anonymity programs such as Tor, the web server can always monitor the user on the basis of the identity. In this paper, we firstly give an overview and cryptanalysis on the protocol of Yang et al and point out the security weaknesses of their protocol. Then, we propose a new authentication protocol for anonymous web browsing. In the proposed protocol, we take the advantages of a pseudo identity mechanism and an identity‐based elliptic curve cryptography algorithm to achieve user anonymity, robust security, and high efficiency. The result of security analysis and performance evaluation indicate the feasibility and practicality of our proposed anonymous authentication protocol. Xu Yang 0002, Xun Yi, Ibrahim Khalil 0001, Hui Cui 0001, Xuechao Yang, Surya Nepal, Xinyi Huang 0001, Yali Zeng |
Concurr. Comput. Pract. Exp. | 3 |
| 2019 | Privacy-preserving aggregation for cooperative spectrum sensing
Yali Zeng, Li Xu 0002, Xu Yang 0002, Xun Yi, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 5 |
| 2019 | Privacy-preserving anomaly detection in the cloud for quality assured decision-making in smart cities
Abdulatif Alabdulatif, Ibrahim Khalil 0001, Heshan Kumarage, Albert Y. Zomaya, Xun Yi |
J. Parallel Distributed Comput. | 2 |
| 2019 | Efficient threshold password-authenticated secret sharing protocols for cloud computing
Xun Yi, Zahir Tari, Feng Hao 0001, Liqun Chen 0002, Joseph K. Liu, Xuechao Yang, Kwok-Yan Lam, Ibrahim Khalil 0001, Albert Y. Zomaya |
J. Parallel Distributed Comput. | 8 |
| 2019 | Privacy preserving service selection using fully homomorphic encryption scheme on untrusted cloud service platform
Mohammad Saidur Rahman 0001, Ibrahim Khalil 0001, Abdulatif Alabdulatif, Xun Yi |
Knowl. Based Syst. | 2 |
| 2018 | GazeRevealer: Inferring Password Using Smartphone Front CameraabstractThe widespread use of smartphones has brought great convenience to our daily lives, while at the same time we have been increasingly exposed to security threats. Keystroke security is an essential element in user privacy protection. In this paper, we present GazeRevealer, a novel side-channel based keystroke inference framework to infer sensitive inputs on smartphone from video recordings of victim's eye patterns captured from smartphone front camera. We observe that eye movements typically follow the keystrokes typing on the number-only soft keyboard during password input. By exploiting eye patterns, we are able to infer the passwords being entered. We propose a novel algorithm to extract sensitive eye pattern images from video streams, and classify different eye patterns with Support Vector Classification. We also propose a novel enhanced method to boost the inference accuracy. Compared with prior keystroke detection approaches, GazeRevealer does not require any external auxiliary devices, and it relies only on smartphone front camera. We evaluate the performance of GazeRevealer with three different types of smartphones, and the result shows that GazeRevealer achieves 77.43% detection accuracy for a single key number and 83.33% inference rate for the 6-digit password in the ideal case. Yao Wang 0005, Wandong Cai, Tao Gu 0001, Wei Shao 0006, Ibrahim Khalil 0001, Xianghua Xu |
MobiQuitous | 5 |
| 2018 | An Improved Lightweight RFID Authentication Protocol for Internet of Things
Xu Yang 0002, Xun Yi, Yali Zeng, Ibrahim Khalil 0001, Xinyi Huang 0001, Surya Nepal |
WISE (1) | 4 |
| 2018 | Fast and peer-to-peer vital signal learning system for cloud-based healthcare
Rongjun Xie, Ibrahim Khalil 0001, Shahriar Badsha, Mohammed Atiquzzaman |
Future Gener. Comput. Syst. | 2 |
| 2018 | Efficient data perturbation for privacy preserving and accurate data stream mining
Mahawaga Arachchige Pathum Chamikara, Peter Bertók, Dongxi Liu, Seyit Ahmet Çamtepe, Ibrahim Khalil 0001 |
Pervasive Mob. Comput. | 5 |
| 2017 | Privacy Preserving User-Based Recommender SystemabstractWith the rapid development of the social networks, Collaborative Filtering (CF)-based recommender systems have been increasingly prevalent and become widely accepted by users. The CF-based techniques generate recommendations by collecting privacy sensitive data from users. Usually, the users are sensitive to disclosure of personal information and, consequently, there are unavoidable security concerns since private information can be easily misused by malicious third parties. In order to protect against breaches of personal information, it is necessary to obfuscate user information by means of an efficient encryption technique while simultaneously generating the recommendation by making true information inaccessible to service providers. Therefore, we propose a privacy preserving user-based CF technique based on homomorphic encryption, which is capable of determining similarities among users followed by generating recommendations without revealing any private information. We introduce different semi-honest parties to preserve privacy and to carry out intermediate computations for generating recommendations. We implement our method on publicly available datasets and show that our method is practical as well as achieves high level of security for users without compromising the recommendation accuracy. Shahriar Badsha, Xun Yi, Ibrahim Khalil 0001, Elisa Bertino |
ICDCS | 3 |
| 2017 | Privacy Preserving Location Recommendations
Shahriar Badsha, Xun Yi, Ibrahim Khalil 0001, Dongxi Liu, Surya Nepal, Elisa Bertino |
WISE (2) | 3 |
| 2017 | Reliable delay-sensitive spectrum handoff management for re-entrant secondary users
Uthpala Subodhani Premarathne, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Ad Hoc Networks | 2 |
| 2017 | ViSiBiD: A learning model for early discovery and real-time prediction of severe clinical events using vital signs as big data
Abdur Forkan, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Comput. Networks | 2 |
| 2017 | Design and implementation of a secure cloud-based billing model for smart meters as an Internet of things using homomorphic cryptography
Vu Mai, Ibrahim Khalil 0001 |
Future Gener. Comput. Syst. | 2 |
| 2017 | Privacy-preserving anomaly detection in cloud with lightweight homomorphic encryption
Abdulatif Alabdulatif, Heshan Kumarage, Ibrahim Khalil 0001, Xun Yi |
J. Comput. Syst. Sci. | 3 |
| 2017 | PEACE-Home: Probabilistic estimation of abnormal clinical events using vital sign correlations for reliable home-based monitoring
Abdur Forkan, Ibrahim Khalil 0001 |
Pervasive Mob. Comput. | 2 |
| 2017 | BDCaM: Big Data for Context-Aware Monitoring - A Personalized Knowledge Discovery Framework for Assisted HealthcareabstractContext-aware monitoring is an emerging technology that provides real-time personalised health-care services and a rich area of big data application. In this paper, we propose a knowledge discovery-based approach that allows the context-aware system to adapt its behaviour in runtime by analysing large amounts of data generated in ambient assisted living (AAL) systems and stored in cloud repositories. The proposed BDCaM model facilitates analysis of big data inside a cloud environment. It first mines the trends and patterns in the data of an individual patient with associated probabilities and utilizes that knowledge to learn proper abnormal conditions. The outcomes of this learning method are then applied in context-aware decision-making processes for the patient. A use case is implemented to illustrate the applicability of the framework that discovers the knowledge of classification to identify the true abnormal conditions of patients having variations in blood pressure (BP) and heart rate (HR). The evaluation shows a much better estimate of detecting proper anomalous situations for different types of patients. The accuracy and efficiency obtained for the implemented case study demonstrate the effectiveness of the proposed model. Abdur Forkan, Ibrahim Khalil 0001, Ayman Ibaida, Zahir Tari |
IEEE Trans. Cloud Comput. | 2 |
| 2017 | Cloud-Based Utility Service Framework for Trust Negotiations Using Federated Identity ManagementabstractUtility based cloud services can efficiently provide various supportive services to different service providers. Trust negotiations with federated identity management are vital for preserving privacy in open systems such as distributed collaborative systems. However, due to the large amounts of server based communications involved in trust negotiations scalability issues prove to be less cumbersome when offloaded on to the cloud as a utility service. In this view, we propose trust based federated identity management as a cloud based utility service. The main component of this model is the trust establishment between the cloud service provider and the identity providers. We propose novel trust metrics based on the potential vulnerability to be attacked, the available security enforcements and a novel cost metric based on policy dependencies to rank the cooperativeness of identity providers. Practical use of these trust metrics is demonstrated by analyses using simulated data sets, attack history data: published by MIT Lincoln laboratory, real-life attacks and vulnerabilities extracted from Common Vulnerabilities and Exposures (CVE) repository and fuzzy rule based evaluations. The results of the evaluations imply the significance of the proposed trust model to support cloud based utility services to ensure reliable trust negotiations using federated identity management. Uthpala Subodhani Premarathne, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Cloud Comput. | 2 |
| 2016 | kNNVWC: An efficient k-nearest neighbours approach based on Various-Widths ClusteringabstractIn this paper, a novel k-NN approach based on Various-Widths Clustering, named kNNVWC, is proposed to efficiently find k-NNs for a query object from a given data set. kNNVWC does clustering using various widths, where a data set is clustered with a global width first and each produced cluster that meets the predefined criteria is recursively clustered with its own local width that suits its distribution. Experimental results demonstrate that kNNVWC performs well compared to state-ofart of k-NN search algorithms. Abdulmohsen Almalawi, Adil Fahad, Zahir Tari, Muhammad Aamir Cheema, Ibrahim Khalil 0001 |
ICDE | 5 |
| 2016 | Securing Body Sensor Network with ECG
Xuechao Yang, Xun Yi, Ibrahim Khalil 0001, Fengling Han, Zahir Tari |
MoMM | 3 |
| 2016 | A probabilistic model for early prediction of abnormal clinical events using vital sign correlations in home-based monitoringabstractChronic diseases are major causes of deaths in Australia and throughout the world. This necessitates the need for a self-care, preventive, predictive and protective assisted living system where a patient can be monitored continuously using wearable and wireless sensors. In real-time home monitoring system, various biological signals of a patient are obtained continuously using a mobile device (smart phone or tablet) and sent to the cloud to discover patient-specific abnormalities. The objective of this work is to develop a probabilistic model that identifies the future clinical abnormalities of a patient using recent and past values of multiple vital signs (e.g. heart rate, blood pressure, respiratory rate). Chronic patients living alone in home die of various diseases for the lack of an efficient automated system having prior prediction ability in the irregularities of vital signs. In this paper, Hidden Markov Model (HMM) is adopted to predict different clinical onsets using the temporal behaviours of six biosignals. The HMM models are trained and evaluated using continuous monitoring data of more than 1000 patients collected from the MIMIC-II database of MIT physiobank archive. The best models are selected using expectation maximisation (EM) algorithm and used in personalized remote monitoring system to forecast the most probable forthcoming clinical states of a continuously monitored patient. The scalable power of cloud computing is utilized for fast learning of various clinical events from large samples. The results obtained from the innovative home-based monitoring application show a new approach of detecting clinical anomalies using multi-parameter trends. Abdur Forkan, Ibrahim Khalil 0001 |
PerCom | 2 |
| 2016 | Resilient to shared spectrum noise scheme for protecting cognitive radio smart grid readings - BCH based steganographic approach
Alsharif Abuadbba, Ibrahim Khalil 0001, Ayman Ibaida, Mohammed Atiquzzaman |
Ad Hoc Networks | 2 |
| 2016 | Trust based reliable transmissions strategies for smart home energy consumption management in cognitive radio based smart grid
Uthpala Subodhani Premarathne, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Ad Hoc Networks | 2 |
| 2016 | A Practical Privacy-Preserving Recommender SystemabstractThe main goal of a personalized recommender system is to provide useful recommendations on various items to the users. In order to generate recommendations, the service needs to access various types of user data such as previous product purchasing history, demographic and biographical information. However, users are sensitive to disclosure of personal information as it can be easily misused by malicious third parties. Consequently, there are unavoidable security concerns which will become known through attempted unauthorized access while providing the recommendation services. In order to protect against breaches of personal information, it is necessary to obfuscate the user information by means of an efficient encryption technique while simultaneously generating the recommendation by making true information inaccessible to the system. To address these challenges, we propose a privacy-preserving recommender system using homomorphic encryption, by which the system can provide recommendations without knowing the actual ratings. Our approach is based on the ElGamal cryptosystem by which both addition and multiplication of plaintexts can be performed. The performance of the proposed scheme shows significantly high accuracy in-terms of computation and communication costs as well as outperforming other existing solutions. Shahriar Badsha, Xun Yi, Ibrahim Khalil 0001 |
Data Sci. Eng. | 3 |
| 2016 | ID2S Password-Authenticated Key Exchange ProtocolsabstractIn a two-server password-authenticated key exchange (PAKE) protocol, a client splits its password and stores two shares of its password in the two servers, respectively, and the two servers then cooperate to authenticate the client without knowing the password of the client. In case one server is compromised by an adversary, the password of the client is required to remain secure. In this paper, we present two compilers that transform any two-party PAKE protocol to a two-server PAKE protocol on the basis of the identity-based cryptography, called ID2S PAKE protocol. By the compilers, we can construct ID2S PAKE protocols which achieve implicit authentication. As long as the underlying two-party PAKE protocol and identity-based encryption or signature scheme have provable security without random oracles, the ID2S PAKE protocols constructed by the compilers can be proven to be secure without random oracles. Compared with the Katz et al.'s two-server PAKE protocol with provable security without random oracles, our ID2S PAKE protocol can save from 22 to 66 percent of computation in each server. Xun Yi, Fang-Yu Rao, Zahir Tari, Feng Hao 0001, Elisa Bertino, Ibrahim Khalil 0001, Albert Y. Zomaya |
IEEE Trans. Computers | 6 |
| 2016 | A Novel Congestion Avoidance Technique for Simultaneous Real-Time Medical Data TransmissionabstractThe use of wireless body sensor networks (WBSN) in medical services aims at providing continuous monitoring of patients' physiological data. However, the scarce resources in WBSN nodes limit their capabilities to cope with massive traffic during multiple, simultaneous data transmissions. This will create a high tendency for congestion, causing severe performance degradation. Congestion may lead to high number of packet loss and unbounded delay which are critical and may lead to wrong diagnosis. This paper, therefore, aims at improving this limitation using a novel congestion avoidance technique to avoid losing real-time and life-critical medical data (e.g., electrocardiogram and electroencephalography) which are vital for diagnosis. The main idea is to integrate the existing rate control scheme of relaxation theory (RT) with a method known as max-min fairness (MMF) to achieve better performance. The MMF can be accomplished using a progressive filling algorithm, which cuts-down excessive sending rates that may overwhelme the limited buffer in WBSN. This paper builds upon our prior study, which provides a preliminary analysis of RT technique in single node. Our current technique integrates the MMF phase to enhance RT performance when the transmission rates exceed certain threshold. Performance evaluation on RT-MMF technique shows remarkable performance improvements, while maintaining the desired quality of service. Naimah Yaakob, Ibrahim Khalil 0001 |
IEEE J. Biomed. Health Informatics | 2 |
| 2016 | kNNVWC: An Efficient k-Nearest Neighbors Approach Based on Various-Widths ClusteringabstractThe k-nearest neighbor approach (k-NN) has been extensively used as a powerful non-parametric technique in many scientific and engineering applications. However, this approach incurs a large computational cost. Hence, this issue has become an active research field. In this work, a novel k-NN approach based on various-widths clustering, named kNNVWC, to efficiently find k-NNs for a query object from a given data set, is presented. kNNVWC does clustering using various widths, where a data set is clustered with a global width first and each produced cluster that meets the predefined criteria is recursively clustered with its own local width that suits its distribution. This reduces the clustering time, in addition to balancing the number of produced clusters and their respective sizes. Maximum efficiency is achieved by using triangle inequality to prune unlikely clusters. Experimental results demonstrate that kNNVWC performs well in finding k-NNs for query objects compared to a number of k-NN search algorithms, especially for a data set with high dimensions, various distributions and large size. Abdulmohsen Almalawi, Adil Fahad, Zahir Tari, Muhammad Aamir Cheema, Ibrahim Khalil 0001 |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2016 | Distributed collision control with the integration of packet size for congestion control in wireless sensor networksabstractAbstract Several great features offered by wireless sensor networks (WSN) result in its wide deployment in various remote and continuous monitoring applications. As such, managing huge collected readings in this domain posted many challenges due to its design limitations. In order to provide seamless data transmission, which is of utmost importance in those delay‐sensitive applications, minimum delay and packet loss occurrence should be considered. Specifically, this paper addresses the common issue of congested networks in WSN with the combination technique of variance‐based distributed contention control (DCC‐V) and packet size optimization. The proposed integration technique, which operates on medium access control layer, takes into consideration the packet size advantages as it plays a key role in determining successful data delivery, given the error‐prone nature of WSN. While ensuring fewer corrupted packets, the proposed contention window (CW) in DCC‐V minimizes the chances of packet collisions and so alleviates congestion. In this technique, CW is determined based on slot utilization and average collision values, which also involve standard deviation measurements. Simulation analysis using network simulator‐2 shows outstanding performance of the proposed solution compared with the existing IEEE 802.15.4 protocol. Copyright © 2014 John Wiley & Sons, Ltd. Naimah Yaakob, Ibrahim Khalil 0001, Mohammed Atiquzzaman, Ibrahim Habib, Jiankun Hu |
Wirel. Commun. Mob. Comput. | 2 |
| 2015 | Multi-Binomial mixes: A proposal for secure and efficient anonymous communication
Shaahin Madani, Ibrahim Khalil 0001 |
Comput. Networks | 2 |
| 2015 | Location-dependent disclosure risk based decision support framework for persistent authentication in pervasive computing applications
Uthpala Subodhani Premarathne, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Comput. Networks | 2 |
| 2015 | Wavelet based steganographic technique to protect household confidential information and seal the transmitted smart grid readings
Alsharif Abuadbba, Ibrahim Khalil 0001 |
Inf. Syst. | 2 |
| 2015 | Robust privacy preservation and authenticity of the collected data in cognitive radio network - Walsh-Hadamard based steganographic approach
Alsharif Abuadbba, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Pervasive Mob. Comput. | 2 |
| 2015 | Secure and reliable surveillance over cognitive radio sensor networks in smart grid
Uthpala Subodhani Premarathne, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
Pervasive Mob. Comput. | 2 |
| 2015 | A context-aware approach for long-term behavioural change detection and abnormality prediction in ambient assisted living
Abdur Forkan, Ibrahim Khalil 0001, Zahir Tari, Sebti Foufou, Abdelaziz Bouras |
Pattern Recognit. | 2 |
| 2015 | Granular Evaluation of Anomalies in Wireless Sensor Networks Using Dynamic Data Partitioning with an Entropy CriteriaabstractThis paper presents an anomaly detection model that is granular and distributed to accurately and efficiently identify sensed data anomalies within wireless sensor networks. A more decentralised mechanism is introduced with wider use of in-network processing on a hierarchical sensor node topology resulting in a robust framework for dynamic data domains. This efficiently addresses the big data issue that is encountered in large scale industrial sensor network applications. Data vectors on each node's observation domain is first partitioned using an unsupervised approach that is adaptive regarding dynamic data streams using cumulative point-wise entropy and average relative density. Second order statistical analysis applied on average relative densities and mean entropy values is then used to differentiate anomalies through robust and adaptive thresholds that are responsive to a dynamic environment. Anomaly detection is then performed in a non-parametric and non-probabilistic manner over the different network tiers in the hierarchical topology in offering increased granularity for evaluation. Experiments were performed extensively using both real and artificial data distributions representative of different dynamic and multi-density observation domains. Results demonstrate higher accuracies in detection as more than 94 percent accompanied by a desirable reduction of more than 85 percent in communication costs when compared to existing centralized methods. Heshan Kumarage, Ibrahim Khalil 0001, Zahir Tari |
IEEE Trans. Computers | 2 |
| 2015 | By-Passing Infected Areas in Wireless Sensor Networks Using BPRabstractAbnormalities in sensed data streams indicate the spread of malicious attacks, hardware failure and software corruption among the different nodes in a wireless sensor network. These factors of node infection can affect generated and incoming data streams resulting in high chances of inaccurate data, misleading packet translation, wrong decision making and severe communication disruption. This problem is detrimental to real-time applications having stringent quality-of-service (QoS) requirements. The sensed data from other uninfected regions might also get stuck in an infected region should no prior alternative arrangements are made. Although several existing methods (BOUNDHOLE and GAR) can be used to mitigate these issues, their performance is bounded by some limitations, mainly the high risk of falling into routing loops and involvement in unnecessary transmissions. This paper provides a solution to by-pass the infected nodes dynamically using a twin rolling balls technique and also divert the packets that are trapped inside the identified area. The identification of infected nodes is done by adapting a Fuzzy data clustering approach which classifies the nodes based on the fraction of anomalous data that is detected in individual data streams. This information is then used in the proposed by-passed routing (BPR) which rotates two balls in two directions simultaneously: clockwise and counter-clockwise. The first node that hits any ball in any direction and is uninfected, is selected as the next hop. We are also concerned with the incoming packets or the packets-on-the-fly that may be affected when this problem occurs. Besides solving both of the problems in the existing methods, the proposed BPR technique has greatly improved the studied QoS parameters as shown by almost 40 percent increase in the overall performance. Naimah Yaakob, Ibrahim Khalil 0001, Heshan Kumarage, Mohammed Atiquzzaman, Zahir Tari |
IEEE Trans. Computers | 2 |
| 2015 | Cooperative Web Caching Using Dynamic Interest-Tagged Filtered Bloom FiltersabstractAlthough cooperative Web caching has been widely researched, comparatively little has been done to reduce inter-proxy network overhead whilst allowing for a high percentage of requested documents to be retrieved from the cache. Alleviating these issues can substantially reduce Web traffic, increase scalability and enhance a user's browsing experience. This paper introduces a novel cache sharing system employing data structures called Dynamic Interest-Tagged Filtered Bloom Filters (DITFBFs). DITFBFs are capable of representing the cache content of a proxy in a compact form, which is then shared with other proxies in the cooperative Web caching system. What distinguishes the proposed system from others is that DITFBFs only represent the portion of a proxy's cache content that will be of interest to another proxy. This then results in a reduction of inter-proxy overhead. Experimental simulations indicate that, when compared with existing protocols, the proposed system is capable of multiple improvements. Namely, lowering the number of remote cache search messages by at least 60 percent, decreasing user-perceived latency by at least 65 percent and appreciably reducing the overall inter-proxy network overhead. The proposed system accomplishes this whilst maintaining a cache hit ratio as high as the other protocols. Holly Alexander, Ibrahim Khalil 0001, Conor Cameron, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2015 | Enhancing Availability in Content Delivery Networks for Mobile PlatformsabstractEnsuring high data availability is a vital prerogative for Content Delivery Networks (CDN), and as we look to deploy CDN mechanisms onto mobile platforms, this imperative becomes ever more challenging. In traditional CDNs, replication ensures high availability of data, with server-loads and content-popularity often used as parameters to tightly control the process. However, the highly transient properties of such wireless and mobile devices constitute a major hurdle for any replication algorithm, rendering most simplified methods inadequate. Our contribution begins with a unique message-pulsing mechanism operating within a wireless cluster, that detects devices and ascertains their reliability. Results show the viability of our pulsing algorithm in determining a base replication level. Next, a Markovian queueing model is introduced, allowing us to induce replication based on the required speed of service. This affords finer control over the replication process, creating a more effective replication strategy suited for mobile-based CDNs. Extensive analysis of the model were performed, with parameters derived from real-world conditions. Results indicate that the model is able to compute logical values for the expected waiting times in service and thus, control the speed of replication within the CDN. Mahathir Almashor, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya, Sartaj Sahni |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2014 | CluClas: Hybrid clustering-classification approach for accurate and efficient network classificationabstractThe traffic classification is the foundation for many network activities, such as Quality of Service (QoS), security monitoring, Lawful Interception and Intrusion Detection Systems (IDS). A recent statistics-based approach to address the unsatisfactory results of traditional port-based and payload-based approaches has attracted attention. However, the presence of non-informative attributes and noise instances degrade the performance of this approach. Thus, to address this problem, in this paper, we propose a hybrid clustering-classification approach (called CluClas) to improve the accuracy and efficiency of network traffic classification by selecting informative attributes and representative instances. An extensive empirical study on four traffic data sets shows the effectiveness of our proposed approach. Adil Fahad, Kurayman Alharthi, Zahir Tari, Abdulmohsen Almalawi, Ibrahim Khalil 0001 |
LCN | 5 |
| 2014 | Multiplicative Attributes Graph Approach for Persistent Authentication in Single-Sign-On Mobile SystemsabstractSingle-sign-on (SSO) has been proposed as a more efficient and convenient authentication method. Classic SSO systems re-authenticate a user to different applications based on a fixed set of attributes (e.g. Username-password combinations). However, the use of a fixed set of attributes fail to account for mobility and contextual variations of user activities. Thus, in a SSO based system, robust persistent authentications and secure session termination management are vital for ensuring secure operations. In this paper we propose a novel persistent authentication technique using multiplicative attribute graph model. We use multiple attribute based persistent authentication model using facial biometrics, location and activity specific information. We propose a novel membership (or group affiliations) based session management technique for user initiated SSO global logout management. Significance and viability of these methods are demonstrated by security, complexity and numerical analyses. In conclusion, our model provides meaningful insights and more pragmatic approaches for persistent authentication and session termination management in implementing SSO based mobile collaborative applications. Uthpala Subodhani Premarathne, Ibrahim Khalil 0001 |
TrustCom | 2 |
| 2014 | An unsupervised anomaly-based detection approach for integrity attacks on SCADA systems
Abdulmohsen Almalawi, Xinghuo Yu 0001, Zahir Tari, Adil Fahad, Ibrahim Khalil 0001 |
Comput. Secur. | 5 |
| 2014 | PPFSCADA: Privacy preserving framework for SCADA data publishing
Adil Fahad, Zahir Tari, Abdulmohsen Almalawi, Andrzej M. Goscinski, Ibrahim Khalil 0001, Abdun Naser Mahmood |
Future Gener. Comput. Syst. | 5 |
| 2014 | An optimal and stable feature selection approach for traffic classification based on multi-criterion fusion
Adil Fahad, Zahir Tari, Ibrahim Khalil 0001, Abdulmohsen Almalawi, Albert Y. Zomaya |
Future Gener. Comput. Syst. | 3 |
| 2014 | CoCaMAAL: A cloud-oriented context-aware middleware in ambient assisted living
Abdur Forkan, Ibrahim Khalil 0001, Zahir Tari |
Future Gener. Comput. Syst. | 2 |
| 2014 | Cloud enabled fractal based ECG compression in wireless body sensor networks
Ayman Ibaida, Dhiah Al-Shammary, Ibrahim Khalil 0001 |
Future Gener. Comput. Syst. | 3 |
| 2014 | A distributed aggregation and fast fractal clustering approach for SOAP traffic
Dhiah Al-Shammary, Ibrahim Khalil 0001, Zahir Tari |
J. Netw. Comput. Appl. | 2 |
| 2014 | Accurate positioning using long range active RFID technology to assist visually impaired people
Saleh Ahmed Alghamdi, Ron G. van Schyndel, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 3 |
| 2014 | An ID-based approach to the caching and distribution of peer-to-peer, proxy-based video content
Conor Cameron, Ibrahim Khalil 0001, Zahir Tari |
J. Netw. Comput. Appl. | 2 |
| 2014 | PileCast: Multiple bit rate live video streaming over BitTorrent
Aukrit Chadagorn, Ibrahim Khalil 0001, Conor Cameron, Zahir Tari |
J. Netw. Comput. Appl. | 2 |
| 2014 | Data summarization for network traffic monitoring
Demetris Hoplaros, Zahir Tari, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 3 |
| 2014 | Garbled Routing (GR): A generic framework towards unification of anonymous communication systems
Shaahin Madani, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 2 |
| 2014 | Data mining in mobile ECG based biometric identification
Khairul Azami Sidek, Vu Mai, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 3 |
| 2014 | ECG Biometric with Abnormal Cardiac Conditions in Remote Monitoring SystemabstractThis paper presents a person identification mechanism using electrocardiogram (ECG) signals with abnormal cardiac conditions in network environments. A total of 164 subjects were used in this paper using three different databases containing various irregular heart states from MIT-BIH arrhythmia database (MITDB), MIT-BIH supraventricular arrhythmia database (SVDB), and Charles Sturt diabetes complication screening initiative (DiSciRi) database. We proposed a simple yet effective biometric sample extraction technique for ECG samples with abnormal cardiac conditions to improve the person identification process. These sample points were then applied to four classifiers to verify the robustness of identification. Varying numbers of enrollment and recognition QRS complexes were used to validate the stability of the proposed method. Our experimentation results show that the biometric technique outperforms existing methods lacking the ability to efficiently extract features for biometric matching. This is evident by obtaining high accuracy results of 96.7% for MITDB, 96.4% for SVDB, and 99.3% for DiSciRi. Moreover, high sensitivity, specificity, positive predictive value, and Youden Index's values further verifies the reliability of the proposed method. This technique also suggests the possibility of improving the classification performance using ECG recordings with low sampling frequency and increased number of ECG samples. Khairul Azami Sidek, Ibrahim Khalil 0001, Herbert F. Jelinek |
IEEE Trans. Syst. Man Cybern. Syst. | 2 |
| 2013 | SCADAVT-A framework for SCADA security testbed based on virtualization technologyabstractSupervisory Control and Data Acquisition (SCADA) systems monitor and control infrastructures and industrial processes such as smart grid power and water distribution systems. Recently, such systems have been attacked, and traditional security solutions have failed to provide an appropriate level of protection. Therefore, it is important to develop security solutions tailored to SCADA systems. However, it is impractical to evaluate such solutions on actual live systems. This paper proposes a SCADA security testbed based on virtualization technology, and introduces a server which is used as a surrogate for water distribution systems. In addition, this paper presents a case study of two malicious attacks to demonstrate how the testbed can easily monitor and control any automatised processes, and also to show how malicious attacks can disrupt supervised processes. Abdulmohsen Almalawi, Zahir Tari, Ibrahim Khalil 0001, Adil Fahad |
LCN | 3 |
| 2013 | Toward an efficient and scalable feature selection approach for internet traffic classification
Adil Fahad, Zahir Tari, Ibrahim Khalil 0001, Ibrahim Habib, Hussein M. Alnuweiri |
Comput. Networks | 3 |
| 2013 | Fractal self-similarity measurements based clustering technique for SOAP Web messages
Dhiah Al-Shammary, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya |
J. Parallel Distributed Comput. | 2 |
| 2013 | Distributed anomaly detection for industrial wireless sensor networks based on fuzzy data modelling
Heshan Kumarage, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya |
J. Parallel Distributed Comput. | 2 |
| 2013 | Automatic and Autonomous Load Management in Peer-to-Peer Virtual EnvironmentsabstractThe very notion of a fully Peer-to-Peer (P2P) Virtual Environment (VE) places exacting demands on its underlying network. Subset applications such as online games are notorious for their sensitivity to latency and high bandwidth demands. By omitting the centralised mechanisms that underpin current commercial implementations, the task of managing a disparate and dynamic peer population is made ever more daunting. For any VE, arbitrating the interactions between players is an inescapable need. Online games are equal parts collaboration and competition, requiring robust conflict resolution mechanisms to govern game-play. With centralised systems, arbitration duties are simply assigned to a provisioned server infrastructure. In a P2P system however, the issue looms large. As such, managing arbitration loads across the peer population is the focus here. Being a game-play arbitrator entails added bandwidth and processing demands. Thus, great care is needed to avoid overloading peers whilst providing a responsive and uninterrupted experience. The work here exploits 3D Voronoi Diagrams (3D-VD) as a scalable, flexible and fault-tolerant P2P overlay that is able to automatically balance arbitration loads amongst peers. Simulation results indicate how 3D-VD, with the right arbitrator-selection policy, can appropriately distribute loads and reduce load fluctuations by up to 90%. This is then augmented with algorithms based on classical Newtonian gravity laws. Doing so provides an autonomous method to detect and respond to high-demand areas within the VE. Further experimentation demonstrates an ability to reduce the instances of failed arbitration attempts by 50%. Mahathir Almashor, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya |
IEEE J. Sel. Areas Commun. | 2 |
| 2012 | Redundancy-aware SOAP messages compression and aggregation for enhanced performance
Dhiah Al-Shammary, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 2 |
| 2011 | Clustering SOAP Web Services on Internet Computing Using Fast FractalsabstractThe interoperability of Web services has resulted in its adoption for recently-emerging cloud platforms. SOAP (Simple Object Access Protocol) is considered as the main platform independent communication tool for the Cloud Web service. Generally, Cloud Web services suffer performance bottlenecks and congestions that are mainly caused by the encoding of XML messages as they are bigger than the real payloads. In this paper, Fractal clustering model is proposed to compute the Fractal clustering similarity of SOAP messages in order to cluster them and enable the aggregation of SOAP messages to significantly reduce the size of the aggregated SOAP messages. Furthermore, as Fractal is a well-known as a time-consuming technique especially for large dataset, two fast Fractal clustering models have been proposed that are aiming to reduce the required clustering time. The proposed fast Fractal models have tremendously outperformed the classical Fractal model in terms of the processing time and have outperformed both K-means and PCA combined with K-means models in terms of both the processing time and SOAP messages size reduction. Dhiah Al-Shammary, Ibrahim Khalil 0001, Loay Edwar George |
NCA | 2 |
| 2011 | Timely Arbitrator Selection in P2P Virtual Environments with 3D Voronoi DiagramsabstractDynamically selecting game-play arbitrators remains a key concern in fully Peer-to-Peer Virtual Environments (P2P-VE). The lack of hierarchical structures and dedicated servers mean suitable candidates must be chosen from amongst the peer population. These selected peers are elevated to the role of momentary referees, deciding on the outcomes of interactions (e.g., combat) between adversarial peers. Accordingly, a timely selection process will aid game-play responsiveness in such time-sensitive applications. There is a need to promptly affirm the arbitrator as delays will hinder peers from initiating combat, impeding game-play. The aim is to address this singular issue, investigating a myriad of selection policies contrived within the context of 3D Voronoi Diagrams (3D-VD). Prior art utilized basic 2D varieties to spatially cluster peers and limit network traffic growth. The work presented here augments this approach with a non-spatial Z-axis and the use of unique selection algorithms. Each mechanism is discussed and extensively tested, with detailed simulation results presented herein. We thus demonstrate 3D-VD's unique ability to deterministically appoint such on-the-fly adjudicators from localised candidate pools in a timely manner. Mahathir Almashor, Ibrahim Khalil 0001 |
NCA | 2 |
| 2011 | A clustering based system for instant detection of cardiac abnormalities from compressed ECG
Fahim K. Sufi, Ibrahim Khalil 0001, Abdun Naser Mahmood |
Expert Syst. Appl. | 2 |
| 2011 | Seamless integration of dependability and security concepts in SOA: A feedback control system based framework and taxonomy
Jiankun Hu, Ibrahim Khalil 0001, Song Han 0004, Abdun Naser Mahmood |
J. Netw. Comput. Appl. | 2 |
| 2011 | Faster person identification using compressed ECG in time critical wireless telecardiology applications
Fahim K. Sufi, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 2 |
| 2011 | An embedded DSP hardware encryption module for secure e-commerce transactionsabstractAbstract Cryptography is one of the key elements in providing security for modern e‐commerce systems. It is well known that software‐based encryption has built‐in security weaknesses due to storing and managing digital certificates/keys in a high‐risk environment such as a local hard disk or software. This makes embedded hardware encryption a superior solution. However, most existing embedded hardware encryption modules need additional dedicated software in order to implement a secure e‐commerce application, which increases cost as well as adds complexity. In this paper, a new embedded hardware DSP (digital signal processor) encryption module, using the RSA (Rivest, Shamir, and Adleman) algorithm, is developed for secure e‐commerce transactions from the client side. The goal is to seamlessly integrate the embedded DSP hardware encryption module, which combines computational power and flexibility in programming, with a widely available web browser that provides the required e‐commerce functions. The integrated system can store and process security sensitive data inside the plug‐in hardware. The proposed scheme tries to maximize security strength while limiting overheads by utilizing a widely available web browser to perform e‐commerce functions such as product searching, etc. A fully functional web e‐commerce system has been developed as a proof of concept. Our major contribution is a design of a functional RSA plug‐in encryptor which can store and encrypt sensitive information originated from the e‐commerce process using standard web browsers. Implementation details addressing challenging issues such as big integer, large message, and communication components have been provided which have never been reported in the public literature. This can be very useful for real‐life industry security applications. Copyright © 2010 John Wiley & Sons, Ltd. Jiankun Hu, Xuan Dau Hoang, Ibrahim Khalil 0001 |
Secur. Commun. Networks | 3 |
| 2011 | A chaos-based encryption technique to protect ECG packets for time critical telecardiology applicationsabstractAbstract Electrocardiography (ECG) signal is popularly used for diagnosing cardiovascular diseases (CVDs). However, in recent times ECG is being used for identifying person. As ECG signals contain sensitive private health information along with details for person identification, it needs to be encrypted before transmission through public media. Moreover, this encryption must be applied with minimal delay for authenticating CVD patients, as time is critical for saving CVD affected patient's life. Within this paper, we propose the usage of multi‐scroll chaos to encrypt ECG packets. ECG packets are being encrypted by the mobile phones using the chaos key by patients' subscribed in tele‐cardiology applications. On the other hand, doctors and hospital attendants receive the encrypted ECG packets, which can be decrypted using the same chaos key. Using the techniques described in this paper, end‐to‐end security can be applied to wireless tele‐cardiology application, with minimal processing. Our experimentation with 12 ECG segments shows that with multi‐scroll chaos implementation, CVD patients remain completely unidentified, upholding patients' privacy and preventing spoof attacks. Most importantly, the proposed method is 18 times faster than permutation‐based ECG encoding, 25 times faster than wavelet‐based ECG annonymization techniques and 31 times faster than noise‐based ECG obfuscation techniques, establishing the proposed technique as the fastest ECG encryption system according to the literature. Copyright © 2010 John Wiley & Sons, Ltd. Fahim K. Sufi, Fengling Han, Ibrahim Khalil 0001, Jiankun Hu |
Secur. Commun. Networks | 3 |
| 2011 | Cardioids-based faster authentication and diagnosis of remote cardiovascular patientsabstractABSTRACT In recent times, dealing with deaths associated with cardiovascular diseases (CVD) has been one of the most challenging issues. The usage of mobile phones and portable Electrocardiogram (ECG) acquisition devices can mitigate the risks associated with CVD by providing faster patient diagnosis and patient care. The existing technologies entail delay in patient authentication and diagnosis. However, for the cardiologists minimizing the delay between a possible CVD symptom and patient care is crucial, as this has a proven impact in the longevity of the patient. Therefore, every seconds counts in terms of patient authentication and diagnosis. In this paper, we introduce the concept of Cardioid based patient authentication and diagnosis. According to our experimentations, the authentication time can be reduced from 30.64 s (manual authentication in novice mobile user) to 0.4398 s (automated authentication). Our ECG based patient authentication mechanism is up to 4878 times faster than conventional biometrics like, face recognition. The diagnosis time could be improved from several minutes to less than 0.5 s (cardioid display on a single screen). Therefore, with our presented mission critical alerting mechanism on wireless devices, minute's worth of tasks can be reduced to second's, without compromising the accuracy of authentication and quality of diagnosis. Copyright © 2011 John Wiley & Sons, Ltd. Fahim K. Sufi, Ibrahim Khalil 0001, Ibrahim Habib |
Secur. Commun. Networks | 2 |
| 2011 | Diagnosis of Cardiovascular Abnormalities From Compressed ECG: A Data Mining-Based ApproachabstractUsage of compressed ECG for fast and efficient telecardiology application is crucial, as ECG signals are enormously large in size. However, conventional ECG diagnosis algorithms require the compressed ECG packets to be decompressed before diagnosis can be performed. This added step of decompression before performing diagnosis for every ECG packet introduces unnecessary delay, which is undesirable for cardiovascular diseased (CVD) patients. In this paper, we are demonstrating an innovative technique that performs real-time classification of CVD. With the help of this real-time classification of CVD, the emergency personnel or the hospital can automatically be notified via SMS/MMS/e-mail when a life-threatening cardiac abnormality of the CVD affected patient is detected. Our proposed system initially uses data mining techniques, such as attribute selection (i.e., selects only a few features from the compressed ECG) and expectation maximization (EM)-based clustering. These data mining techniques running on a hospital server generate a set of constraints for representing each of the abnormalities. Then, the patient's mobile phone receives these set of constraints and employs a rule-based system that can identify each of abnormal beats in real time. Our experimentation results on 50 MIT-BIH ECG entries reveal that the proposed approach can successfully detect cardiac abnormalities (e.g., ventricular flutter/fibrillation, premature ventricular contraction, atrial fibrillation, etc.) with 97% accuracy on average. This innovative data mining technique on compressed ECG packets enables faster identification of cardiac abnormality directly from the compressed ECG, helping to build an efficient telecardiology diagnosis system. Fahim K. Sufi, Ibrahim Khalil 0001 |
IEEE Trans. Inf. Technol. Biomed. | 2 |
| 2010 | Reducing network load in large-scale, Peer-to-Peer Virtual Environments with 3D Voronoi DiagramsabstractWhen moving towards fully Peer-to-Peer Virtual Environments (P2P-VE), the amount of network traffic generated at each peer remains a significant concern. Multiplayer Online Games (MOG) are the largest application subset of VEs and have been shown to require high frequency of update messages and minimal network latencies. Yet, this demanding criteria must be balanced with the need to also limit the otherwise quadratic growth of network traffic amongst peers. Two-dimensional Voronoi Diagrams (2D-VD) have been proposed as a way to address the inherent traffic scalability issues by naturally clustering players (and thus their update traffic) within the game-world. However, other important issues related to game-play and overall VE performance remained and were only addressed by our recent introduction of a third dimension to the VD computations (3D-VD). As our experimentation indicates, this unique approach has significant impact on the network characteristics of a P2P-VE. Due to its 3D nature, more connections are necessary per peer but a mechanism is successfully introduced to cope with the increased bandwidth requirement. More importantly, the results obtained show considerable reduction in traffic load under varying peer topologies while still maintaining the desirable features of 3D-VD. Mahathir Almashor, Ibrahim Khalil 0001 |
HiPC | 2 |
| 2010 | Load-Balancing Properties of 3D Voronoi Diagrams in Peer-to-Peer Virtual EnvironmentsabstractBalancing communication workloads is a perennial performance issue in the area of Distributed Virtual Environments (DVE). The stringent time constraints of Multiplayer Online Games (MOG) complicate efforts to effectively distribute the networking load amongst servers. This issue becomes ever more exacting, when we move towards a fully Peer-to-peer virtual world (P2P-VE). We are consequently forced to factor in the limited capabilities of ordinary peers in the network. Traditional MOGs have been built on the client-server (CS) paradigm and the industry brute-force approach of over-provisioning resources is both inelegant and non-resilient in the face of failures. Moving such systems onto P2P architectures mitigates these drawbacks significantly. Our recent application of three-dimensional Voronoi Diagrams (3D-VD) onto P2P-VEs has further introduced desirable load-balancing properties in such systems. This is due to the novel use network capacity as the metric for the 3rd dimension and the subsequent use of the 3D-VD to intelligently appoint dynamic game-play arbitrators from amongst the peer population. This short paper is a preliminary report on the load-balancing properties seen in our extensive simulations. It is shown how this approach is able to appropriately distribute load in a variety of network configurations and peer populations. Thus, the performance of the collaborating peers is enhanced, ultimately leading to better game-play experience. Mahathir Almashor, Ibrahim Khalil 0001 |
ICPADS | 2 |
| 2010 | SOAP Web Services Compression Using Variable and Fixed Length CodingabstractSOAP Web services create high network traffic because of its generated large XML messages resulting in poor network performance. Therefore, enhancing the performance of Web services by compressing SOAP messages is considered to be an important issue. Compression ratios achieved by most of the existing techniques and tools are not high enough, and even a tiny improvement could save tremendous amount of network bandwidth in emerging cloud and mobile scenarios. In this paper, we try to achieve this objective by proposing two innovative techniques capable of reducing small as well as very large messages. Instead of encoding the characters of XML message individually, Fixed-length encoding and Huffman encoding as a variable-length technique are developed to deal with XML tags as individual input items. XML tree and binary tree are constructed that support the encoding algorithm by removing the closing tags. A high Compression Ratio has been achieved that is up to 7.8 and around 13.5 for large and very large messages respectively. Dhiah Al-Shammary, Ibrahim Khalil 0001 |
NCA | 2 |
| 2010 | Dynamic Game-Play Arbitrators with 3D Voronoi DiagramsabstractVoronoi Diagrams (VD) have recently been proposed as a way to enable Massively Multi-player On-line Games (MMOG) and Virtual Environments (VE) on fully Peer-to-Peer (P2P) network architectures. Using typical two-dimensional varieties, the peers maintain direct single-hop connections to others in the game-world in a scalable manner. However, direct connections do not guarantee the timely delivery of update messages amongst peers. There is also the issue of fair game-play resolution between opposing players. Thus, as is standard industry practice, game-play arbitrators are needed. Arbitrators also incorporate lag-compensation techniques which improve the responsiveness felt by individual players, thereby enhancing their experience. The approach outlined in this short paper aims to bridge the gap between industry and academia, by introducing the use of an additional 3rd dimension when deriving the VDs. Initial experimentation indicates that 3D-VD is computationally feasible within the time constraints of a typical game. A discussion into several metrics that can act as the differentiating 3rd dimension is also included. Mahathir Almashor, Ibrahim Khalil 0001, Geoff Leach |
NCA | 2 |
| 2010 | Performance Analysis of Optimal Packet Size for Congestion Control in Wireless Sensor NetworksabstractWhile witnessing a remarkable and rapid emergence of Wireless Sensor Network (WSN) that seems to facilitate promising features, congestion problem still remains the key issue that attract very high attention in research community. Congestion not only severely degrades network performance, but also gives adverse quality to various related applications such as real-time monitoring systems that demands strict and stringent requirements. A robust solution is therefore required to mitigate this critical issue, yet to cope with challenging dynamic WSN's nature. Concerning this issue, in this paper, we have investigated a potential solution to alleviate congestion by determining an appropriate packet size in various error conditions. This prospective factor have high potential in improving network efficiency by maximizing the link utilization and minimizing the number of retransmissions, thus ensuring reliability. In addition, the error-prone characteristic and noisy channel in sensor network increase the needs for determining appropriate packet size during data transmission in order to massively reduce congestion and helps providing consistent WSN's performance. This paper investigates the impact of varying packet size in various Bit Error Rate (BER) conditions and highlights other key factors that may help alleviate congestion in WSN. Simulation study demonstrates an overall network efficiency improvement and favourable performance. Naimah Yaakob, Ibrahim Khalil 0001, Jiankun Hu |
NCA | 2 |
| 2010 | Polynomial distance measurement for ECG based biometric authenticationabstractAbstract Existing electrocardiography (ECG) based biometric systems are constantly being challenged by higher misclassification error, longer acquisition time, larger template size, slower processing time and pertinence of abnormal beats within the biometric template. These challenges are the prime hindrance for ECG based biometric being commercialized as a pervasive authentication mechanism. At least, ECG based biometric can provide a secured mechanism for cardiac patients being monitored over telephony network. In this paper, we present a polynomial distance measurement (PDM) method for ECG based biometric authentication for the very first time, according to the literature and to the best of our knowledge. The proposed PDM method is up to 12 times faster than existing algorithms, requires up to 6.5 times less template storage, needs only 2.49 (average) acquisition time with the highest accuracy rate (up to 100 per cent) when experimented on a population size of 15. Moreover, this proposed ECG based biometric system was deployed on a mobile phone based telemonitoring scenario with multilayer authentication mechanism upholding its applicability. Copyright © 2008 John Wiley & Sons, Ltd. Fahim K. Sufi, Ibrahim Khalil 0001, Ibrahim Habib |
Secur. Commun. Networks | 2 |
| 2009 | Novel methods of faster cardiovascular diagnosis in wireless telecardiologyabstractWith the rapid development wireless technologies, mobile phones are gaining acceptance to become an effective tool for cardiovascular monitoring. However, existing technologies have limitations in terms of efficient transmission of compressed ECG over text messaging communications like SMS and MMS. In this paper, we first propose an ECG compression algorithm which allows lossless transmission of compressed ECG over bandwidth constrained wireless link. Then, we propose several algorithms for cardiovascular abnormality detection directly from the compressed ECG maintaining end to end security, patient privacy while offering the benefits of faster diagnosis. Next, we show that our mobile phone based cardiovascular monitoring solution is capable of harnessing up to 6.72 times faster diagnosis compared to existing technologies. As the decompression time on a doctor's mobile phone could be significant, our method will be highly advantageous in patient wellness monitoring system where a doctor has to read and diagnose from compressed ECGs of several patients assigned to him. Finally, we successfully implemented the prototype system by establishing mobile phone based cardiovascular patient monitoring. Fahim K. Sufi, Qiang Fang 0004, Ibrahim Khalil 0001, Seedahmed S. Mahmoud |
IEEE J. Sel. Areas Commun. | 3 |
| 2008 | QoS-aware Application Layer MulticastabstractThe crux of large scale Application Layer Multicast or Peer-to-Peer streaming systems is how to cope with the inherent dynamics, the reason is that the participating users may join and leave at will. It is even worse for single-tree-based multicast systems, which are preferred due to their efficiency. In these single multicast tree based schemes, userpsilas departure may cause serious service disruption for all the downstream users. The solution stems from the characteristics of the problem itself, and it exploits the property that the participating userspsila lifetime follow a Pareto distribution, which has the used better than new (UBTN) feature. The participating nodes are dynamically organized into a hierarchy in such a way that it reflects the relative stabilities among the nodes. The proposed algorithm is distributed in the sense that no a prior knowledge about userspsila lifetime is needed. A maximum of 50% improvement can be achieved in terms of peerspsila perceived QoS. Detailed mathematical analysis and simulation results are presented to validate the proposed algorithm. Simulation results show that the algorithm is valid for other lifetime distributions as well. Bin Rong, Ibrahim Khalil 0001, Zahir Tari |
ISCC | 2 |
| 2008 | Enforcing secured ECG transmission for realtime telemonitoring: A joint encoding, compression, encryption mechanismabstractAbstract Realtime telemonitoring of critical, acute and chronic patients has become increasingly popular with the emergence of portable acquisition devices and IP enabled mobile phones. During telemonitoring, enormous physiological signals are transmitted through the public communication network in realtime. However, these physiological signals can be intercepted with minimal effort, since existing telemonitoring practise ignores the privacy and security requirements. In this paper, to achieve end‐to‐end security, we first proposed an encoding method capable of securing Electrocardiogram (ECG) data transmission from an acquisition device to a mobile phone, and then from a mobile phone to a centralised medical server by concealing cardiovascular details as well as features in ECG data required to identify an individual. The encoding method not only conceals cardiovascular condition, but also reduces the enormous file size of the ECG with a compression ratio of up to 3.84, thus making it suitable in energy constrained small acquisition devices. As ECG data transfer faces even greater security vulnerabilities while traversing through the public Internet, we further designed and implemented 3 phase encoding—compression—encryption mechanism on mobile phones using the proposed encoding method and existing compression and encryption tools. This new mechanism elevates the security strength of the system even further. Apart from higher security, we also achieved higher compression ratio of up to 20.06, which will enable faster transmission and make the system suitable for realtime telemonitoring. Copyright © 2008 John Wiley & Sons, Ltd. Fahim K. Sufi, Ibrahim Khalil 0001 |
Secur. Commun. Networks | 2 |
| 2006 | Probabilistic QoS Routing inWiFi P2P NetworksabstractQoS routing in WiFi P2P networks is the process of selecting a path to be used by peers based on their QoS requirements, such as bandwidth or delay. Existing QoS routing solutions provide an effective way of dealing with path selection; however, even though there exist paths with more available capacity or better reliability, these paths are not taken into consideration. In this paper we propose algorithms to compute paths with maximal path-capacity-to-hop count ratio from a super-peer to all other super-peers in a WiFi P2P network. The complexities of these algorithms are O(MH), where M is the number of edges and H is the diameter of the P2P network. Simulations conducted on different topologies demonstrate that our proposed algorithms perform up to 15% better (in terms of information loss) when compared to existing techniques Sathish Rajasekhar, Ibrahim Khalil 0001, Zahir Tari |
AINA (1) | 2 |
| 2006 | Load Sharing in Peer-to-Peer Networks using Dynamic ReplicationabstractThe peer-to-peer (P2P) architecture provides support for the next generation of information sharing applications. A difficult challenge faced by these systems in the presence of non-uniform data distribution and dynamic network conditions is load sharing. This paper addresses the problem of load sharing in P2P networks across heterogeneous super-peers. We propose two load sharing techniques that use data replication to improve access performance. In the first technique, called periodic push-based replication (PPR), super-peers periodically send replicas of the most frequently accessed files to remote super-peers. This effectively reduces the hop count to fetch these files. The second technique, called on-demand replication (ODR), performs replication based on access frequency. By performing replication on-demand, ODR provides adaptability to changes in access behavior. Extensive testing have been conducted to study the performance of the proposed techniques. The results obtained demonstrate significant performance improvements through replication Sathish Rajasekhar, Bin Rong, Kwong Yuen Lai, Ibrahim Khalil 0001, Zahir Tari |
AINA (1) | 4 |
| 2006 | Reliability Enhanced Large-Scale Application Layer MulticastabstractReliability has become the major concern in application layer multicast because the participating users may join and leave at will. The overlay network, built on-the-fly, is highly dynamic. It is getting worse in reality because single-tree based multicast structures are preferred, due to their efficient usage of network resources. In these single multicast tree based schemes, users' departure may cause serious service disruption for all the downstream users. A new tree construction algorithm is proposed to enhance reliability for application layer multicast. It exploits the property that the participating users' lifetime follow a Pareto distribution, which has the used better than new (UBTN) feature, and dynamically adjusts the multicast tree. The participating nodes are mapped into a hierarchy which is organized in such a way that it reflects the relative stability among the participating nodes. The proposed approach is light-weight and no a prior knowledge about users' lifetime is needed. A minimum of 50% reduction can be achieved in terms of service disruption frequency. Detailed mathematical analysis and simulation results are presented to validate the proposed algorithm. Bin Rong, Ibrahim Khalil 0001, Zahir Tari |
GLOBECOM | 2 |
| 2006 | Making Application Layer Multicast Reliableis FeasibleabstractApplication layer multicast (ALM henceforth) was proposed as a substitute for network layer multicast (IP multicast). However, the end users, who take the responsibility to replicate and forward data in ALM, are not as stable as routers in IP multicast. Therefore, reliability has become the major concern in ALM. This paper presents a new tree construction algorithm and demonstrates that making ALM reliable is achievable, even when a single-tree based multicast structure is used. It exploits the property that participating users' lifetime follow a Pareto distribution which has the used better than new (UBTN) feature, and dynamically adjusts the multicast tree. Participating nodes are organized into a hierarchy and the hierarchy is organized in such a way that it reflects the relative stability among participating nodes. The proposed approach achieves reliability enhancement for ALM by using a very low overhead and no a priori knowledge about users' lifetime is required. A minimum reduction of 50% can be achieved in terms of service disruption frequency. Detailed mathematical analysis and simulation results reveal that making ALM reliable is feasible Bin Rong, Ibrahim Khalil 0001, Zahir Tari |
LCN | 2 |
| 2005 | A Gossip-based Membership Management Algorithm for Large-Scale Peer-to-Peer Media StreamingabstractA new adaptive gossip-based membership management algorithm is proposed. Its adaptive nature enables it to confine the control overhead to local ranges, and adapt to the ever-changing network traffic conditions and group membership. The random nature of the algorithm ensures that it can cope with random failures and offer proactive measures to maintain service at a certain level. Mathematical analysis and simulation results indicate that more than 90% of the nodes can work properly even under very high network dynamics (with a short half-life time of 50 seconds), and all these are achieved by using a relatively low overhead. Bin Rong, Ibrahim Khalil 0001, Zahir Tari |
LCN | 2 |
| 2002 | Automated service provisioning in heterogeneous large-scale environmentabstractWith the increasing complexity of network management activities due to naturally limited human involvement, carriers and service providers are looking to migrate from manual, static provisioning models to the more dynamic service-oriented automated provisioning models to meet customer demands for rapid service turn-up and obtain more customers and maximize revenue opportunities. We propose a novel distributed architecture where highly mobile and intelligent agents can take the responsibilities of not only provisioning, but also configuration audit management in a timely fashion. Although previous research has focused on using mobile agents for network monitoring or simple push-based device configuration in a distributed architecture, their ability have not been exploited in dynamic IP service provisioning. Using a simple push-based model to configure network services while ignoring dependencies among configuration elements may easily lead to configuration inconsistencies resulting in failure or inefficiencies. In this paper, we have taken a new approach to configuration modeling that is device neutral and based on which any existing or emerging IP services can be presented by encapsulating service semantics, including service-specific data. We have developed new mobile intelligent provisioning and audit agent architectures that use the knowledge built upon configuration dependency modeling. Examples of intelligent agents are presented to complement the proposed management architecture. Ibrahim Khalil 0001, Torsten Braun |
NOMS | 1 |
| 2001 | A Range-Based SLA and Edge Driven Virtual Core Provisioning in DiffServ-VPNsabstractWe previously proposed a range-based service level agreement (SLA) approach and edge provisioning in DiffServ capable virtual private networks (VPNs) to customers that are unable or unwilling to predict the load between VPN endpoints exactly. With range-based SLAs customers specify their requirements as a range of quantitative values rather than a single one. Various suitable policies and algorithms dynamically provision and allocate resources at the edges for VPN connections. However, we also need to provision the interior nodes of a transit network to meet the assurances offered at the boundaries of the network. Although a deterministic guaranteed service (single quantitative value approach) provides the highest level of QoS guarantees, it leaves a significant portion of network resources on the average unused. We show that with range-based SLAs providers have the flexibility to allocate bandwidth that falls between a lower and upper bound of the range only, and therefore, take advantage of this to make multiplexing gain in the core that is usually not possible with a deterministic approach. But dynamic and frequent configurations of an interior device is not desired as this will lead to scalability problems and also defeats the purpose of the DiffServ architecture which suggests to drive all the complexities towards edges. We, therefore, propose virtual core provisioning that only requires a capacity inventory of interior devices to be updated based on VPN connection acceptance, termination or modification at the edges. Ibrahim Khalil 0001, Torsten Braun |
LCN | 1 |
| 2000 | Edge provisioning and fairness in VPN-Diffserv networksabstractCustomers of virtual private networks (VPN) over differentiated services (Diffserv) infrastructure are most likely to demand not only security but also guaranteed quality of service (QoS) as there is a desire to have leased line like services. However, it is expected that they will be unable or unwilling to predict load between VPN endpoints. In this paper, we propose that customers specify their requirements as a range of quantitative services in the service level agreements (SLAs). To support such services ISPs would need to have an automated provisioning system that can logically partition the capacity at the edges to various classes (or groups) of VPNs and manage them efficiently to allow resource sharing among the groups in a dynamic and fair manner. While with edge provisioning, a certain amount of resources based on SLAs (traffic contract at edge) are allocated to VPN connections, we also need to provision the interior nodes of a transit network to meet the assurances offered at the boundaries of the network. We therefore propose a two-layered model to provision such VPN-Diffserv networks where the top layer is responsible for edge provisioning and drives the lower layer in charge of interior resource provisioning with the help of a bandwidth broker (BB). Various algorithms, with examples and analysis, are presented to provision and allocate resources dynamically at the edges for VPN connections. We have developed a prototype BB performing the required provisioning and connection admission. Ibrahim Khalil 0001, Torsten Braun |
ICCCN | 1 |
| 2000 | Implementation of a Bandwidth Broker for Dynamic End-to-End Resource Reservation in Outsourced Virtual Private NetworksabstractAs today's network infrastructure continues to grow and Differentiated Services IP backbones are now available to provide various levels of quality of service (QoS) to VPN traffic, the ability to manage increasing network complexity is considered as a crucial factor for QoS enabled VPN solutions. There is growing trend by corporate customers to outsource such complicated management services to Internet service providers (ISP) not only to avoid the for economic reasons. We present methods to provide end-to-end capacity allocation to VPN connections in a single ISP domain and show the implementation of a bandwidth broker managing the outsourced VPNs for corporate customers that have service level agreements (SLAs) with their ISPs. We also present practical configuration examples of commercial routers for enabling QoS enabled VPN tunnels and show how the bandwidth broker can dynamically establish tunnels when users send connection requests from the WWW interface. Ibrahim Khalil 0001, Torsten Braun |
LCN | 1 |
| 1999 | An Architecture for Managing QoS-Enabled VPNs over the InternetabstractThis paper describes an architecture for the management of QoS-enabled virtual private networks (VPNs) over the Internet. The architecture focuses on two important issues of VPNs: security and quality-of-service (QoS). The security achieved in VPNs is based on IPSec tunnels, while QoS can be supported by mechanisms as proposed by the differentiated services currently being defined by the IETF. We describe an architecture that is based on the concept of service brokers. These service brokers are used for communication between different domains (such as ISP and customer networks) as well as within domains. The architecture described in the paper is currently being implemented as part of the CATI project funded by the Swiss National Science Foundation (SNF). Manuel Günter, Torsten Braun, Ibrahim Khalil 0001 |
LCN | 3 |