EDBT 2026 Demo / reviewers in the wild / expert
Mohamed Alsharkawy
dblp:415/5404
· DBLP profile ↗
5ranked-venue papers
4as first author
5since 2021 · last 2026
0009-0006-5858-2957ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 4 first-author · 5 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient Federated Learning with Low-Rank Updates under Homomorphic EncryptionabstractFederated Learning has been widely adopted for its ability to collaboratively train models without exposing raw data. However, the server-side aggregation process may still leak sensitive information about client data. Homomorphic Encryption enables privacy-preserving aggregation, but it introduces substantial communication overhead for clients and high computational costs for the server. To address these challenges, we propose HEAL-FL, a federated learning framework that is based on low-rank shared basis vectors across clients. Instead of transmitting full encrypted model updates, clients send only encrypted low-rank coefficients, thereby reducing both communication costs and server-side aggregation overhead. Furthermore, HEAL-FL incorporates a communication-efficient basis update scheme that relies exclusively on homomorphic addition at the server. Our evaluation across various homomorphic encryption schemes shows that HEAL-FL reduces client communication and server aggregation costs, leading to improved efficiency of Federated Learning systems. Notably, these savings translate into up to a significant reduction of 38.6% in total training time compared to conventional homomorphic FedAvg with full model parameter transmission, demonstrating the practical benefits of our approach. Mohamed Aboelenien Ahmed, Mohamed Alsharkawy, Hassan Nassar, Heba Khdr, Jeferson González-Gómez, Jörg Henkel |
DATE | 2 |
| 2026 | TrustSeed: Lightweight Attestation Protocol for Ensuring LLM IntegrityabstractOver the last couple of years, large language models have increasingly been integrated into many computing applications. For privacy preservation, they are now deployed on edge devices. However, these deployments are vulnerable to bit flip attacks and backdoor attacks that compromise the integrity of the model. Traditional remote attestation techniques fail to detect such manipulations due to the large model size and the stealthiness of the attacks.In this paper, we present TrustSeed, a lightweight functional attestation protocol that uses a single inference to ensure large language models’ integrity. TrustSeed verifies integrity by applying deterministic, seed-based modifications to model weights within a Trusted Execution Environment and comparing the last intermediate activations and output distribution against a golden reference on the verifier. This approach prevents precomputed or forged responses, ensuring freshness and unpredictability in each attestation round. Our analysis shows that output distribution and last intermediate activations are effective indicators of integrity. We test TrustSeed against bit-flip, data poisoning, and weight poisoning attacks, reliably detecting even single-bit alterations. Extensive evaluations on edge platforms and an HPC system demonstrate minimal overhead and up to 127× faster attestation compared to state-of-the-art full-model hashing. Mohamed Alsharkawy, Mohamed Aboelenien Ahmed, Hassan Nassar, Jeferson González-Gómez, Heba Khdr, Osama Abboud, Xun Xiao, Jörg Henkel |
DATE | 1 |
| 2025 | Late Breaking Results: Decentralized Voting-Based Attestation for IoT DevicesabstractRemote Attestation (RA) has become a valuable security service for Internet of Things (IoT) devices, as the security of these devices is often not prioritized during the manufacturing process. However, traditional RA schemes suffer from a single point of failure because they rely on a trusted verifier. To address this issue, we propose a voting-based blockchain attestation protocol that provides a reliable solution by eliminating the single point of failure through distributed verification across all nodes. In addition, it offers a traceable and immutable public history of the attestation results, which can be verified by external auditors at any time. Finally, we verify our proposed protocol on three NVIDIA Jetson embedded devices hosting up to 15 attestation nodes. Mohamed Alsharkawy, Eren Sönmez, Jeferson González-Gómez, Hassan Nassar, Jörg Henkel |
DAC | 1 |
| 2025 | Late Breaking Results: The Hidden Risks of Activation Duration in PLPUFsabstractThe security of Internet of Things (IoT) devices is crucial to protect the vast amounts of data exposed due to their widespread adoption. Authentication is one of the key aspects of IoT security, but it becomes increasingly challenging, especially for resource-constrained devices that require lightweight and efficient solutions. Physical Unclonable Functions (PUFs) have emerged as a promising lightweight solution by using the unique physical properties of Integrated Circuits (ICs). Pseudo Liner Feedback Shift Register PUF (PLPUF) is one of the state-of-the-art implementations known for its flexibility in altering the challenge-response space by changing the activation duration. In this work, we demonstrate that selecting an appropriate activation duration for PLPUF is critical, as improper choices can compromise security. By analyzing the linear dependency between the responses of different PLPUF pairs, our results reveal that predictability can reach up to $96 \%$ when an unsuitable activation duration is chosen. Mohamed Alsharkawy, Jan Zwerschke, Hassan Nassar, Jeferson González-Gómez, Jörg Henkel |
DAC | 1 |
| 2025 | DPReF: Decentralized Key Generation Using Physical-Related FunctionsabstractPhysical Unclonable Functions (PUFs) serve as a lightweight source to generate cryptographic keys utilizing the inherent physical device properties, making them particularly suitable for resource-constrained environments such as Internet of Things (IoT) devices. Recently, Physical-Related Functions (PReFs) extended PUFs to enable multiple devices to generate similar keys without the need to exchange or store them, improving security. However, state-of-the-art PReF implementations rely on a Trusted Third Party (TTP) to identify relative challenges, introducing a potential vulnerability if the TTP is compromised. In this work, we propose the first decentralized PReF protocol, removing reliance on the TTP and mitigating associated security risks. The proposed protocol allows relative challenges to be identified directly between devices in a decentralized manner. Additionally, we formalize a mathematical model to estimate the minimum number of devices required to build a network, based on the sizes of the PUF and the shared Challenge-Response Pair (CRP).. We demonstrate the generality of our model by verifying it across different types of state-of-the-art PUFs (Arbiter-based Non-Volatile Memory PUF (ANV-PUF) and Pseudo Linear Feedback Shift Register PUF (PLPUF).). We establish a 128 bit cryptographic key using the proposed protocol that matches the state-of-the-art but in a decentralized manner. Moreover, we prove that our protocol can be used to construct hardware-assisted attestation networks using ANV-PUF and PLPUF implementations with a shared secret of 16 bit that allows for both integrity and identity verification. Mohamed Alsharkawy, Hassan Nassar, Jeferson González-Gómez, Xun Xiao, Osama Abboud, Jörg Henkel |
ACM Trans. Embed. Comput. Syst. | 1 |