Mohan Baruwal Chhetri

dblp:48/6411 · DBLP profile ↗
← Back
50ranked-venue papers
15as first author
27since 2021 · last 2026
0000-0002-6138-7742ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 15 · 4 first-author · 12 since 2021Systems, architecture and hardware · 12 · 5 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 3 first-author · 2 since 2021Security and privacy · 6 · 6 since 2021Databases, data management, data science and information retrieval · 5 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 3Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 SoK: Navigating the Privacy-UX Trade-offs in Extended Reality (XR) - A Socio-Technical Taxonomy and Research Roadmap
Shunyao Wang, Mahawaga Arachchige Pathum Chamikara, Mohan Baruwal Chhetri, Zhenchang Xing, Ryan Kok Leong Ko
AsiaCCS3
2026 Fractured Awareness: Why Platform Privacy Systems Are Accepted More than They Are Understood
Omar Haggag, John C. Grundy, Mohan Baruwal Chhetri
ENASE (1)3
2026 LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations Centres
Ronal Singh, Shahroz Tariq, Fatemeh Jalalvand, Mohan Baruwal Chhetri, Surya Nepal, Cécile Paris, Martin Lochner
SP4
2025 Coordinated Self-Exploration for Self-Adaptive Systems in Contested Environments
Saad Sajid Hashmi, Khanh Hoa Dam, Alan W. Colman, Anton V. Uzunov, Quoc Bao Vo, Mohan Baruwal Chhetri, James Dorevski
ICAART (1)6
2025 Enhancing Physical Security in Smart Environments with Ambient Intelligence
abstract
Smart environments are increasingly equipped with interconnected digital systems to manage access and physical security. However, traditional authentication methods, typically restricted to static checkpoints, fail to provide persistent assurance once entry is granted, leaving facilities vulnerable to credential misuse, tailgating, and unauthorised movement. This paper presents the Continuous Authentication Platform (CAP), a modular, multi-modal framework developed within the RAAISE project to enable continuous and context-aware verification across dynamic facility zones. CAP integrates heterogeneous off-the-shelf sensors, including NFC, RFID, biometric, motion, and WiFi positioning units, which collectively support persistent user tracking and real-time access enforcement. The platform’s architecture couples distributed sensing and edge processing with a centralised intelligence layer for event correlation and policy-driven decision-making. A live testbed deployment at Deakin University was used to evaluate CAP’s performance under realistic operational conditions. Results from functional trials demonstrate CAP’s ability to detect credential misuse, prevent tailgating, and maintain authentication continuity with sub-second responsiveness. These findings underscore CAP’s potential as a scalable, privacy-aligned foundation for next-generation smart facility security systems.
Ashish Nanda, Robin Doss, Fokke Heikamp, Abhi Kumar, Haftu Tasew Reda, Adnan Anwar, Zubair A. Baig, Praveen Gauravaram, Debi Prasad Pati, Salil S. Kanhere, Mohan Baruwal Chhetri
TrustCom11
2025 Semantics-Aware Cookie Purpose Compliance
abstract
Websites commonly display cookie banners to inform users about the use and purposes of cookies. However, they may still, whether intentionally or unintentionally (e.g., due to third-party libraries imported), mis-declare cookies that may be abused for tracking. In this work, we introduce COOVER (cookie value examiner) to assess the non-compliance between the website-declared purpose and the semantic-intended purpose of cookies (denoted as potential cookie purpose violation ). We advocate that the value of the cookie is a more reliable indicator of its semantic-intended purpose compared to other features such as expiration time. COOVER decomposes the cookie value into primitive segments representing minimal semantic units, and fine-tunes a GPT-3.5 model to automatically interpret their value-inferred semantics. Based on the interpretation, it classifies cookies into four GDPR-defined purposes. COOVER achieves an F1 score of 95%, significantly outperforming other methods. We employ COOVER to analyze Alexa Top 1k websites to understand the status quo of potential cookie purpose violation on the web. Remarkably, out of 15,339 cookies across these websites, only 3.1% quality as truly necessary cookies, while 44.1% of websites suffer from issues of potential purpose violation.
Baiqi Chen, Jiawei Lyu, Tingmin Wu, Mohan Baruwal Chhetri, Guangdong Bai
WWW4
2025 Proactive self-exploration: Leveraging information sharing and predictive modelling for anticipating and countering adversaries
Saad Sajid Hashmi, Khanh Hoa Dam, Mohan Baruwal Chhetri, Anton V. Uzunov, Alan W. Colman, Quoc Bao Vo
Expert Syst. Appl.3
2025 A2C: A modular multi-stage collaborative decision framework for human-AI teams
abstract
The increasing complexity of decision-making in dynamic environments, particularly in high-stakes domains like cybersecurity, demands more than automated solutions—it requires effective integration of human expertise with advanced AI capabilities. While approaches like ensemble learning and Mixture of Experts (MoE) enhance automated decision-making, they struggle with handling uncertainty and novel scenarios. Techniques such as learning to defer and learning to complement mitigate this by incorporating human input, but assume that a definitive expert is always available—an assumption that often fails in real-world settings. To bridge this gap, we introduce A 2 C , a modular, multi-stage collaborative decision-making framework that enhances adaptability and decision robustness under uncertainty by seamlessly transitioning between three decision-making modes: Automated, Augmented Deferral, and Collaborative Exploration (CoEx). A key innovation of CoEX is its ability to handle cases where both AI and human experts face uncertainty, overcoming a critical limitation of traditional deferral systems. We validate A 2 C through experiments on benchmark datasets, Large Language Model (LLM) simulations of human–AI collaboration, and real-world human–AI interaction studies with cybersecurity researchers. Results show that A 2 C consistently outperforms conventional approaches that rely solely on full automation or selective human intervention, demonstrating its potential as a practical and scalable solution for expert decision-making in complex domains. For image detection on CIFAR-10, detection rates improved from 37.8% with automation alone to 64.75% with augmented deferral, and further to 92.95% with collaborative exploration. Similarly, for intrusion detection on KDDCup, rates rose from 33.43% with automation to 35.18% with augmented deferral, and finally reached 87.04% with CoEx, highlighting its effectiveness in handling uncertainty.
Shahroz Tariq, Mohan Baruwal Chhetri, Surya Nepal, Cécile Paris
Expert Syst. Appl.2
2024 Unveiling Intellectual Property Vulnerabilities of GAN-Based Distributed Machine Learning through Model Extraction Attacks
abstract
Generative Adversarial Networks (GANs), as a cornerstone of artificial intelligence (AI), are widely recognized as the intellectual property (IP) of their owners, given the sensitivity of the training data and the commercial value tied to the models. Model extraction attacks, which aim to steal well-trained proprietary models, pose a significant threat to model IP. Nevertheless, current research predominately focuses on the context of machine learning as a service (MLaaS), where the emphasis lies in understanding the attack knowledge acquired through black-box API queries. This restricted perspective exposes a critical gap in investigating model extraction attacks within realistic distributed settings for generative tasks. In this work, we present the first investigation into model extraction attacks against GANs in distributed settings. We provide a comprehensive attack taxonomy, considering three different levels of knowledge the adversary can obtain in practice. Based on it, we introduce a novel model extraction attack named MoEx, which focuses on the GAN-based distributed learning scenario, i.e., Multi-Discriminator GANs, a typical asymmetric distributed setting. MoEx uses the objective function simulation, leveraging data exchanged during the learning process, to approximate the GAN generator owned by the server. We define two attack goals for MoEx, fidelity extraction and accuracy extraction . Then we comprehensively evaluate the effectiveness of MoEx's two goals with real-world datasets. Our results demonstrate its robust capabilities in extracting generators with high fidelity and accuracy compared with existing methods.
Mengyao Ma, Shuofeng Liu, Mahawaga Arachchige Pathum Chamikara, Mohan Baruwal Chhetri, Guangdong Bai
CIKM4
2024 Microcompositions for Goal-Driven Self-Adaptation
abstract
To adapt to volatile edge environments this paper envisages distributed systems built from small units of coordi-nation called microcompositions. Microcompositions decompose a single goal into subgoals and declaratively express compo-sition and coordination constraints. These microcompositions are managed by agents that self-organise themselves into a distributed management overlay structure - a Goal Realisation Tree (GRT) - based on goal realisation (means-ends) links. Both microcompositions and GRTs serve as runtime models, allowing agents to dynamically restructure them in response to changes in goals, service provision and context. Results from our evaluation demonstrate the effectiveness and scalability of our approach.
Alan W. Colman, Quoc Bao Vo, Anton V. Uzunov, Saad Sajid Hashmi, Khanh Hoa Dam, Mohan Baruwal Chhetri
COMPSAC6
2024 Load balancing for heterogeneous serverless edge computing: A performance-driven and empirical approach
abstract
Serverless edge systems simplify the deployment of real-time AI-based Internet of Things (IoT) applications at the edge. However, the heterogeneity of edge computing nodes – in terms of both hardware and software – makes load balancing challenging in these systems. In this paper, we propose a performance-driven, empirical weight-tuning approach to achieve effective load balancing based on the characteristics and capabilities of the nodes. By extensively profiling the nodes, we gather knowledge on performance metrics such as throughput, energy efficiency, response time, AI accuracy, and cost. Using this acquired knowledge, we introduce a weighted round-robin strategy to optimize the performance metrics according to their observed significance. To address multiple objectives, we introduce a multi-objective method that aims to strike a balance between any arbitrary set of performance objectives simultaneously. Additionally, we explore a coordinated distributed approach to overcome the limitations of centralized load balancing. Next, we introduce Hedgi, a heterogeneous serverless edge architecture designed to efficiently configure and utilize the derived load balancing policies, validated empirically. To demonstrate the practicality of Hedgi, we containerize and serverlessize a real-time object detection application. Extensive empirical studies are conducted using Hedgi to evaluate the performance of the proposed load balancing approach. The results provide valuable insights into the design trade-offs of various load balancing policies and system designs in the heterogeneous serverless edge.
Mohammad Sadegh Aslanpour, Adel Nadjaran Toosi, Muhammad Aamir Cheema, Mohan Baruwal Chhetri, Mohsen Amini Salehi
Future Gener. Comput. Syst.4
2024 Towards Human-AI Teaming to Mitigate Alert Fatigue in Security Operations Centres
abstract
Security Operations Centres (SOCs) play a pivotal role in defending organisations against evolving cyber threats. They function as central hubs for detecting, analysing, and responding promptly to cyber incidents with the primary objective of ensuring the confidentiality, integrity, and availability of digital assets. However, they struggle against the growing problem of alert fatigue, where the sheer volume of alerts overwhelms SOC analysts and raises the risk of overlooking critical threats. In recent times, there has been a growing call for human-AI teaming, wherein humans and AI collaborate with each other, leveraging their complementary strengths and compensating for their weaknesses. The rapid advances in AI and the growing integration of AI-enabled tools and technologies within SOCs give rise to a compelling argument for the implementation of human-AI teaming within the SOC environment. Therefore, in this article, we present our vision for human-AI teaming to address the problem of alert fatigue in the SOC. We propose the 𝒜 2 𝒞 Framework, which enables flexible and dynamic decision making by allowing seamless transitions between automated, augmented, and collaborative modes of operation. Our framework allows AI-powered automation for routine alerts, AI-driven augmentation for expedited expert decision making, and collaborative exploration for tackling complex, novel threats. By implementing and operationalising 𝒜 2 𝒞, SOCs can significantly reduce alert fatigue while empowering analysts to efficiently and effectively respond to security incidents.
Mohan Baruwal Chhetri, Shahroz Tariq, Ronal Singh, Fatemeh Jalalvand, Cécile Paris, Surya Nepal
ACM Trans. Internet Techn.1
2024 Faashouse: Sustainable Serverless Edge Computing Through Energy-Aware Resource Scheduling
abstract
Serverless edge computing is a specialized system design tailored for Internet of Things (IoT) applications. It leverages serverless computing to minimize operational management and enhance resource efficiency, and utilizes the concept of edge computing to allow code execution near the data sources. However, edge devices powered by renewable energy face challenges due to energy input variability, resulting in imbalances in their operational availability. As a result, high-powered nodes may waste excess energy, while lowpowered nodes may frequently experience unavailability, impacting system sustainability. Addressing this issue requires energy-aware resource schedulers, but existing cloud-native serverless frameworks are energy-agnostic. To overcome this, we propose an energyaware scheduler for sustainable serverless edge systems. We introduce a reference architecture for such systems and formally model energy-aware resource scheduling, treating the function-to-node assignment as an imbalanced energy-minimizing assignment problem. We then design an optimal offline algorithm and propose faasHouse, an online energy-aware scheduling algorithm that utilizes resource sharing through computation offloading. Lastly, we evaluate faasHouse against benchmark algorithms using real-world renewable energy traces and a practical cluster of single-board computers managed by Kubernetes. Our experimental results demonstrate significant improvements in balanced operational availability (by 46%) and throughput (by 44%) compared to the Kubernetes scheduler.
Mohammad Sadegh Aslanpour, Adel Nadjaran Toosi, Muhammad Aamir Cheema, Mohan Baruwal Chhetri
IEEE Trans. Serv. Comput.4
2023 Agent Controlled Service Meshes for Resilient, Self-Adaptive Microservice Systems
abstract
This paper envisages an agent-based approach for creating resilient, self-managing microservice systems. The approach is based on a categorisation of the adaptation space for microservices across two dimensions – application/infrastructure and service-type/composition. The monitoring and adaptation actions in the quadrants defined by these dimensions are distinct, requiring controllers/agents with different management capabilities. Based on this division of responsibility, an agent-oriented architectural approach is proposed – the Agent Mesh. A service mesh provides the observability and control of a network overlay that connects agents and services, while agents with the different capabilities defined above close the control loops at the application and infrastructure levels. A core feature of the approach is that both domain (managed) services and managing agents are integrated as microservices within the same mesh, and communicate with each other via sidecar proxies, thereby allowing adaptation of both the domain services and self-adaptation of the agents.
Alan W. Colman, Anton V. Uzunov, Quoc Bao Vo, Mohan Baruwal Chhetri
SSE4
2023 Goal-Driven Adversarial Search for Distributed Self-Adaptive Systems
abstract
Resilience and antifragility are highly desirable properties for systems operating in dynamic, contested environments. Recent work has proposed an approach for achieving antifragility through three new self-* properties, one of which is adversarial self-exploration. In that approach, a single agent is responsible for defending a (distributed) managed system against an adversary. However, a major limitation is that the agent requires full observability of the managed system and its environment, which is not practical in many scenarios - including when a system operates in contested environments. We address this limitation by extending the approach to multi-agent self-exploration, where agents with partial observability and control of the managed system coordinate with other agents to compute the most resilient responses in the presence of adversaries. We demonstrate the feasibility and scalability of the proposed approach through extensive experimentation.
Saad Sajid Hashmi, Khanh Hoa Dam, Anton V. Uzunov, Mohan Baruwal Chhetri, Aditya Ghose, Alan W. Colman
SSE4
2023 Investigating Users' Understanding of Privacy Policies of Virtual Personal Assistant Applications
abstract
The increasingly popular virtual personal assistant (VPA) services, e.g., Amazon Alexa and Google Assistant, enable third-party developers to create and release VPA apps for end users to access through smart speakers. Given that VPA apps handle sensitive personal data, VPA service providers require developers to release a privacy policy document to declare their data handling practice. The privacy policies are regarded as legal or semi-legal documents, which are usually lengthy and complex for users to understand. In this work, we conducted a subjective study to investigate the level of users’ understanding of the privacy policies, targeting the VPA apps (i.e., skills) of Amazon Alexa, the most popular VPA service. Our study focused on technical terms, one of the greatest hurdles to users’ understanding. We found that 84.2% of our participants faced difficulty in understanding technical terms appeared in the skills’ privacy policies, even for participants with IT background. Additionally, 64.3% of them reported that explanations for the technical terms are generally lacking. To address this issue, we proposed two principles, i.e., domain-specificity principle and implication-oriented principle, to guide skill developers in creating easy-to-understand privacy policies. We evaluated their effectiveness by creating explanation sentences for 23 representative terms and examining users’ understanding through a second user study. Our results show that using explanation sentences based on these principles can significantly improve users’ understanding.
Baiqi Chen, Tingmin Wu, Yanjun Zhang 0002, Mohan Baruwal Chhetri, Guangdong Bai
AsiaCCS4
2023 LoDen: Making Every Client in Federated Learning a Defender Against the Poisoning Membership Inference Attacks
abstract
Federated learning (FL) is a widely used distributed machine learning framework. However, recent studies have shown its susceptibility to poisoning membership inference attacks (MIA). In MIA, adversaries maliciously manipulate the local updates on selected samples and share the gradients with the server (i.e., poisoning). Since honest clients perform gradient descent on samples locally, an adversary can distinguish whether the attacked sample is a training sample based on observation of the change of the sample’s prediction. This type of attack exacerbates traditional passive MIA, yet the defense mechanisms remain largely unexplored.
Mengyao Ma, Yanjun Zhang 0002, Mahawaga Arachchige Pathum Chamikara, Leo Yu Zhang, Mohan Baruwal Chhetri, Guangdong Bai
AsiaCCS5
2023 SoK: Systematizing Attack Studies in Federated Learning - From Sparseness to Completeness
abstract
Federated Learning (FL) is a machine learning technique that enables multiple parties to collaboratively train a model using their private datasets. Given its decentralized nature, FL has inherent vulnerabilities that make it susceptible to adversarial attacks. The success of an attack on FL depends upon several (latent) factors, including the adversary’s strength, the chosen attack strategy, and the effectiveness of the defense measures in place. There is a growing body of literature on empirical attack studies on FL, but no systematic way to compare and evaluate the completeness of these studies, which raises questions about their validity. To address this problem, we introduce a causal model that captures the relationship between the different (latent) factors, and their reflexive indicators, that can impact the success of an attack on FL. The proposed model, inspired by structural equation modeling, helps systematize the existing literature on FL attack studies and provides a way to compare and contrast their completeness. We validate the model and demonstrate its utility through experimental evaluation of select attack studies. Our aim is to help researchers in the FL domain design more complete attack studies and improve the understanding of FL vulnerabilities.
Geetanjli Sharma, Mahawaga Arachchige Pathum Chamikara, Mohan Baruwal Chhetri, Yi-Ping Phoebe Chen
AsiaCCS3
2023 Government Mobile Apps: Analysing Citizen Feedback via App Reviews
abstract
Governments worldwide are increasingly embracing digital transformation initiatives to enhance service delivery, engage citizens, and achieve better outcomes. However, obtaining continuous feedback on these initiatives poses a substantial challenge. This paper investigates the feasibility of leveraging mobile app reviews as a valuable source of citizen feedback on government digital services. We analyse 100,146 app reviews from 129 government mobile apps in Australia and identify several functional and usability issues. These include issues such as app instability, complexity, integration problems, navigation difficulties, inaccuracies, and challenges with ID verification and authentication processes. Furthermore, we uncover several factors that influence user satisfaction, including accuracy and reliability, convenience, dependability, user-centric design, and overall user-friendliness. These findings demonstrate a strong correlation between user feedback and the government's digital transformation strategy, underscoring the viability of mobile app reviews as a cost-effective avenue for collecting citizen feedback.
Tooba Aamir, Mohan Baruwal Chhetri, Mahawaga Arachchige Pathum Chamikara, Marthie Grobler
ASE2
2023 Privacy for IoT: Informed consent management in Smart Buildings
abstract
Smart Buildings (SBs) employ the latest IoT technologies to automate building operations and services with the objective of increasing operational efficiency, maximising occupant comfort, and minimising environmental impact. However, these smart devices – mostly cloud-based – can capture and share a variety of sensitive and private data about the occupants, exposing them to various privacy threats. Given the non-intrusive nature of these devices, individuals typically have little or no awareness of the data being collected about them. Even if they do and claim to care about their privacy, they fail to take the necessary steps to safeguard it due to the convenience offered by the IoT devices. This discrepancy between user attitude and actual behaviour is known as the ‘privacy paradox’. To address this tension between data privacy, consent and convenience, this paper proposes a novel solution for informed consent management in shared smart spaces. Our proposed Informed Consent Management Engine (ICME) (a) increases user awareness about the data being collected by the IoT devices in the SB environment, (b) provides fine-grained visibility into privacy conformance and compliance by these devices, and (c) enables informed and confident privacy decision-making, through digital nudging. This study provides a reference architecture for ICME that can be used to implement diverse end-user consent management solutions for smart buildings. A proof-of-concept prototype is also implemented to demonstrate how ICME works in a shared smart workplace. Our proposed solution is validated by conducting expert interviews with 15 highly experienced industry professionals and academic researchers to understand the strengths, limitations, and potential improvements of the proposed system.
Chehara Pathmabandu, John C. Grundy, Mohan Baruwal Chhetri, Zubair A. Baig
Future Gener. Comput. Syst.3
2023 Human-centric software engineering - Approaches, technologies, and applications
Xiao Liu 0004, Kelly Blincoe, Mohan Baruwal Chhetri, John C. Grundy
J. Syst. Softw.3
2023 Towards Proactive Risk-Aware Cloud Cost Optimization Leveraging Transient Resources
abstract
Low-cost transient resources such as Amazon's Elastic Compute Cloud (EC2) Spot instances can be opportunistically leveraged to reduce the ongoing costs of cloud applications. However, they are susceptible to unilateral revocations by the vendor making them a risky proposition for long-running applications with strict performance requirements. It is challenging to effectively balance the cost savings that transient resources provide with the associated revocation risk which, if realised, can impact application performance. To address this challenge, we propose an approach for risk-aware cloud cost optimization that is inspired by the concept ofportfolio diversification.Contract diversificationmitigates the revocation risk by procuring the required compute capacity as a mixed portfolio of transient and non-transient resources.Resource diversificationfurther diversifies the risk by using multiple transient resource types. Using our approach, consumers can leverage contract and resource diversification to proactively (re-)configure their application's resource portfolio to handle workload and resource price fluctuations while minimizing ongoing cost and keeping ongoing revocation risk within tolerable limits. Simulative evaluation using three real-world workload traces and Amazon's EC2 offerings demonstrate that our proposed approach can achieve meaningful cost savings compared to the baseline costs, while significantly reducing the portfolio's exposure to revocation risk.
Mohan Baruwal Chhetri, Abdur Forkan, Quoc Bao Vo, Surya Nepal, Ryszard Kowalczyk
IEEE Trans. Serv. Comput.1
2023 FOCloud: Feature Model Guided Performance Prediction and Explanation for Deployment Configurable Cloud Applications
abstract
The increasing heterogeneity of the VM offerings on public IaaS clouds gives rise to a very large number ofdeployment optionsfor constructing distributed, multi-component cloud applications. However, selecting an appropriatedeployment variant, i.e., a valid combination of deployment options, to meet required performance levels is non-trivial. The combinatorial explosion of thedeployment spacemakes it infeasible to measure the performance of all deployment variants to build a comprehensive empirical performance model. To address this problem, we proposeFeature-Oriented Cloud(FOCloud), a performance engineering approach for deployment configurable cloud applications. FOCloud (i) uses feature modeling to structure and constrain the valid deployment space by modeling the commonalities and variations in the different deployment options and their inter-dependencies, (ii) uses sampling and machine learning to incrementally and cost-effectively build a performance prediction model whose input variables are the deployment options, and the output variable is the performance of the resulting deployment variant, and (iii) uses Explainable AI techniques to provide explanations for the prediction outcomes of valid deployment variants in terms of the deployment options. We demonstrate the practicality and feasibility of FOCloud by applying it to an extension of the RuBiS benchmark application deployed on Google Cloud.
Indika Kumara, Mohamed Hameez Ariz, Mohan Baruwal Chhetri, Majid Mohammadi 0001, Willem-Jan van den Heuvel, Damian A. Tamburri
IEEE Trans. Serv. Comput.3
2022 FOCloud: Feature Model Guided Performance Prediction and Explanation for Deployment Configurable Cloud Applications
abstract
J1C2 Presentation Abstract at IEEE SERVICES 2022 for IEEE Transactions on Services Computing DOI 10.1109/TSC.2022.3142853
Indika Kumara, Mohamed Hameez Ariz, Mohan Baruwal Chhetri, Majid Mohammadi 0001, Willem-Jan van den Heuvel, Damian A. Tamburri
SERVICES3
2021 AWaRE2-MM: A Meta-Model for Goal-Driven, Contract-Mediated, Team-Centric Autonomous Middleware Frameworks for Antifragility
abstract
In this paper, we introduce a new meta-model that captures core concepts for constructing software architectures for general-purpose, autonomous middleware frameworks that realize internalized and externalized self-adaptivity at both a system- and meta-level in order to achieve antifragility. The proposed meta-model builds on, specializes, and complements existing multi-agent meta-models in line with a previously published reference model for antifragile systems in the cyber domain.
Anton V. Uzunov, Matthew Brennan, Mohan Baruwal Chhetri, Quoc Bao Vo, Ryszard Kowalczyk, John Wondoh
APSEC3
2021 ICME: an informed consent management engine for conformance in smart building environments
abstract
Smart buildings can reveal highly sensitive insights about their inhabitants and expose them to new privacy threats and vulnerabilities. Yet, convenience overrides privacy concerns and most people remain ignorant about this issue. We propose a novel Informed Consent Management Engine (ICME) that aims to: (a) increase users’ awareness about privacy issues and data collection practices in their smart building environments, (b) provide fine-grained visibility into privacy conformance and infringement by these devices, (c) recommend and visualise corrective user actions through ”digital nudging”, and (d) support the monitoring and management of personal data disclosure in a shared space. We present a reference architecture for ICME that can be used by software engineers to implement diverse end-user consent management solutions for smart buildings. We also provide a proof-of-concept prototype to demonstrate how the ICME approach works in a shared smart workplace. Demo: https://youtu.be/5y6CdyWAdgY
Chehara Pathmabandu, John C. Grundy, Mohan Baruwal Chhetri, Zubair A. Baig
ESEC/SIGSOFT FSE3
2021 Exploiting Heterogeneity for Opportunistic Resource Scaling in Cloud-Hosted Applications
abstract
Cloud consumers have access to an increasingly diverse range of resource and contract options, but lack appropriate resource scaling solutions that can exploit this to minimize the cost of their cloud-hosted applications. Traditional approaches tend to use homogeneous resources and horizontal scaling to handle workload fluctuations and do not leverage resource and contract heterogeneity to optimize cloud costs. In this paper, we propose a novel opportunistic resource scaling approach that exploits both resource and contract heterogeneity to achieve cost-effective resource allocations. We model resource allocation as anunbounded knapsack problem, and resource scaling as anone-step ahead resource allocation problem. Based on these models, we propose two scaling strategies: (a)delta capacity optimization, which focuses on optimizing costs for the difference between existing resource allocation and the required capacity based on the forecast workload, and (b)full capacity optimization, which focuses on optimizing costs for resource capacity corresponding to the forecast workload. We evaluate both strategies using two real world workload datasets, and compare them against three different scaling strategies. The results show that our proposed approach, particularly full capacity optimization, outperforms all of them and offers in excess of 70 percent cost savings compared to the traditional scaling approach.
Mohan Baruwal Chhetri, Abdur Forkan, Quoc Bao Vo, Surya Nepal, Ryszard Kowalczyk
IEEE Trans. Serv. Comput.1
2020 Towards a Trusted Collaborative Medical Decision-Making Platform
Hamza Sellak, Mohan Baruwal Chhetri, Marthie Grobler
CollaborateCom (2)2
2019 A Note on Quality of Service Issues in Smart Cities
Surya Nepal, Mohan Baruwal Chhetri, Rajiv Ranjan 0003, Ryszard Kowalczyk
J. Parallel Distributed Comput.2
2018 Towards Resource and Contract Heterogeneity Aware Rescaling for Cloud-Hosted Applications
abstract
Cloud infrastructure providers are offering consumers a wide range of resource and contract options to choose from, yet most elasticity management solutions are incapable of leveraging this to optimize the cost and performance of cloudhosted applications. To address this problem, in this paper, we propose a novel resource scaling approach that exploits both resource and contract heterogeneity to achieve optimal resource allocations and better cost control. We model resource allocation as an Unbounded Knapsack Problem, and resource scaling as an one-step ahead resource allocation problem. Based on this, we present two scaling strategies, namely delta scale optimization and full scale optimization. Delta scale optimization supports the traditional notion of scaling resources horizontally, i.e., it computes an optimal allocation (or deallocation) of resources to increase (or decrease) the total compute capacity based on the current allocation and the forecast application workload. Full scale optimization, on the other hand, supports the notion of cost-optimal resource rescaling, i.e., the simultaneous allocation and deallocation of resources to meet the forecast workload irrespective of the decision to increase, decrease or maintain capacity. Both strategies provide users greater flexibility in managing trade offs between cost and performance. We motivate our research work by using a realistic and non-trivial scenario of resource scaling for a cloud-hosted IoT platform and use simple use cases to illustrate the benefit of our proposed approach.
Mohan Baruwal Chhetri, Quoc Bao Vo, Ryszard Kowalczyk, Surya Nepal
CCGrid1
2018 AWaRE - Towards Distributed Self-Management for Resilient Cyber Systems
abstract
Resilience is an important property of distributed cyber defence systems operating in complex, adversarial environments. While resilience can be realized through self-management, implementing distributed self-management poses several significant challenges. In this paper, we identify some of these challenges and present our initial work on an approach for cyber resilience called AWaRE. The novelty of AWaRE lies in the use of a conceptual, state-space-based design and reconstitution framework, combined with run-time models and distributed constraint satisfaction/optimization techniques for decision-making and coordination of system re-configurations. The run-time models are generated via an expressive domain-specific language enabling component, constraint and agent modeling as well as constraint problem decomposition and architectural self-organization. We realize AWaRE via a concrete software framework, focusing specifically on autonomic self-* properties pertaining to distributed system configuration, deployment and reliable operation. We demonstrate the value of AWaRE in the context of a simple, cloud-based enterprise scenario.
Mohan Baruwal Chhetri, Anton V. Uzunov, Quoc Bao Vo, Ryszard Kowalczyk, Michael Docking, Hien P. Luong, Isuru Rajapakse, Surya Nepal
ICECCS1
2017 On Estimating Minimum Bids for Amazon EC2 Spot Instances
abstract
Consumers can realize significant cost savings by procuring resources from computational spot markets such as Amazon Elastic Compute Cloud (EC2) Spot Instances. They can take advantage of the price differentials across time slots, regions, and instance types to minimize the total cost of running their applications on the cloud. However, Spot markets are inherently volatile and dynamic, as a consequence of which Spot prices change continuously. As such, prospective bidders can benefit from intelligent insights into the Spot market dynamics that can help them make more informed bidding decisions. To enable this, we propose a descriptive statistics approach for the analysis of Amazon EC2 Spot markets to detect typical pricing patterns including the presence of seasonal components, extremes and trends. We use three statistical measures - the Gini coefficient, the Theil index, and the exponential weighted moving average. We also devise a model for estimating minimum bids such that the Spot instances will run for specified durations with a probability greater than a set value based on different look back periods. Experimental results show that our estimation yields on average a bidding strategy that can reliably secure an instance at least 80% of the time at minimum target guarantee between 50% and 95%.
Markus Lumpe, Mohan Baruwal Chhetri, Quoc Bao Vo, Ryszard Kowalczyk
CCGrid2
2015 AutoSLAM - A policy-based framework for automated SLA establishment in cloud environments
abstract
Summary Cloud computing offers a realization of SOA in which IT resources are dynamically provisioned as services to consumers using flexible provisioning and pricing models. When provisioning such services, providers and consumers must first agree over the service usage terms and conditions, which are captured in Service Level Agreements (SLAs). In this paper, we propose a policy‐based framework with corresponding models, mechanisms and tools for the automated establishment of SLAs in open, diverse and dynamic cloud environments. The Automated SLA Management framework allows entities to specify their requirements and capabilities, and preferences over them in a flexible and expressive manner. It also supports multiple interaction models for SLA establishment, giving consumers and providers the flexibility to select the one that is most appropriate in a given context, while simultaneously participating in multiple concurrent SLA interactions using different interaction models. As part of the framework, we define a formal model for the underlying policies, a corresponding physical model WS‐SLAM that extends WS‐Policy and a reference architecture that can be easily implemented. We validate the practicability of our framework through the Smart CloudPurchaser prototype that can automatically purchase computing resources from Amazon EC2 under different scenarios and contexts. Copyright © 2013 John Wiley & Sons, Ltd.
Mohan Baruwal Chhetri, Quoc Bao Vo, Ryszard Kowalczyk
Concurr. Comput. Pract. Exp.1
2014 Smart CloudMonitor - Providing Visibility into Performance of Black-Box Clouds
abstract
Migration to the cloud offers several benefits including reduced operational costs, flexibility, scalability, and a greater focus on business goals, but it also has a flip side reduced visibility. Organizations only have a blackbox view of cloud servers and while pricing and specification information is publicly available, there is limited information about cloud performance. This necessitates the need for tools that can provide greater visibility into cloud insfrastructure performance so that consumers can objectively compare and contrast the offerings from different providers. Smart CloudBench [1][2][3] is a system that allows users to run automated, ondemand, real-time and customized benchmark tests on cloud infrastructure. In this paper, we present Smart CloudMonitor - a performance monitoring tool that provides multi-layer performance monitoring capabilities to Smart CloudBench. It provides greater visibility and insight into cloud performance by monitoring both application performance as well as the corresponding resource consumption. Experiments conducted on cloud infrastructure using Smart CloudBench show the add value that Smart CloudMonitor provides to the process of cloud performance evaluation.
Mohan Baruwal Chhetri, Sergei Chichin, Quoc Bao Vo, Ryszard Kowalczyk
IEEE CLOUD1
2013 Smart CloudBench - Automated Performance Benchmarking of the Cloud
abstract
As the rate of cloud computing adoption grows, so does the need for consumption assistance. Enterprises that are looking to migrate their IT systems to the cloud, would like to quickly identify providers that offer resources with the most appropriate pricing and performance levels to match their specific business needs. However, no two vendors offer the same resource configurations, pricing and provisioning models, making the task of selecting appropriate computing resources complex, time-consuming and expensive. In this paper, we present Smart CloudBench - a platform that automates the performance benchmarking of cloud infrastructure, helping potential consumers quickly identify the cloud providers that can deliver the most appropriate price/performance levels to meet their specific requirements. Users can estimate the actual performance of the different cloud platforms by testing representative benchmark applications under representative load conditions. Experimentation using the prototype implementation shows that higher price does not necessarily translate to better or more consistent performance, and benchmarking results can provide more information to help enterprises make better informed decisions.
Mohan Baruwal Chhetri, Sergei Chichin, Quoc Bao Vo, Ryszard Kowalczyk
IEEE CLOUD1
2013 Smart Cloud Broker: Finding your home in the clouds
abstract
As the rate of cloud computing adoption grows, so does the need for consumption assistance. Enterprises looking to migrate their IT systems to the cloud require assistance in identifying providers that offer resources with the most appropriate pricing and performance levels to match their specific business needs. In this paper, we present Smart Cloud Broker - a suite of software tools that allows cloud infrastructure consumers to evaluate and compare the performance of different Infrastructure as a Service (IaaS) offerings from competing cloud service providers, and consequently supports selection of the cloud configuration and provider with the specifications that best meet the user's requirements. Using Smart Cloud Broker, prospective cloud users can estimate the performance of the different cloud platforms by running live tests against representative benchmark applications under representative load conditions.
Mohan Baruwal Chhetri, Sergei Chichin, Quoc Bao Vo, Ryszard Kowalczyk
ASE1
2012 Policy-Based Automation of SLA Establishment for Cloud Computing Services
abstract
We propose a policy-based framework for the automated establishment of SLAs for cloud computing services. The proposed framework supports multiple interaction models for SLA establishment giving consumers and providers the flexibility to choose one that is most appropriate in a given context, while simultaneously supporting multiple concurrent SLA interactions using different interaction models. We describe the underlying policies, focussing on the key features and contributions of the framework. We also validate our framework through a real-world use-case scenario using the Amazon EC2 service.
Mohan Baruwal Chhetri, Quoc Bao Vo, Ryszard Kowalczyk
CCGRID1
2012 On Effective Quality of Service Negotiation
abstract
This paper addresses the problem of flexible procuring of multiple services with multiple non-functional characteristics, i.e., quality of service attributes. We investigate the one-to-many negotiation approach as a flexible method for procuring multiple services by a buyer agent. We address the problem of coordinating multiple concurrent negotiations and propose a novel dynamic negotiation strategy that considers the behaviors of the opponents in managing the local reservation values for the common negotiation issues. Most previous works consider the problem of negotiation over a single issue. We investigate a more complex scenario where a buyer agent negotiates with multiple seller agents over multiple services characterized by multiple issues. The initial experimental results show the effectiveness of our dynamic negotiation strategy when compared to a static strategy.
Khalid Mansour, Ryszard Kowalczyk, Mohan Baruwal Chhetri
CCGRID3
2012 Establishing composite SLAs through concurrent QoS negotiation with surplus redistribution
abstract
SUMMARY The end‐to‐end QoS negotiation for service level agreement establishment for composite services involves compound multi‐party negotiations in which the composite service provider concurrently negotiates with multiple candidates for each atomic service, selecting the one that best satisfies the atomic service QoS preferences while ensuring that the end‐to‐end QoS requirements are also fulfilled. In order to be able to negotiate with potential candidates, it is necessary to derive the atomic utility boundaries from the global utility boundary. Additionally, there has to be a mechanism for updating these boundaries in subsequent negotiation rounds based on the individual negotiation outcomes. In this paper, we propose an algorithm for the decomposition of global utility boundary into atomic service utility boundaries, and the surplus redistribution from successful negotiation outcomes among the remaining negotiations. The proposed mechanism is a practical approach to efficiently coordinate concurrent service negotiations within complex workflows, enabling the iterative and interactive adjustment of the negotiation boundaries for each atomic service in a composition based on the performance of other atomic negotiations. We demonstrate the feasibility of our approach by evaluating it with some popular negotiation strategies using the Specialized Property Search Scenario. Copyright © 2011 John Wiley & Sons, Ltd.
Jan Richter, Mohan Baruwal Chhetri, Ryszard Kowalczyk, Quoc Bao Vo
Concurr. Comput. Pract. Exp.2
2011 A Flexible Policy Framework for the QoS Differentiated Provisioning of Services
abstract
We propose a policy-based framework for the QoS differentiated provisioning of services. The proposed frame-work improves the state-of-the-art in policy-based preference specification by combining cardinal and ordinal preferences. We describe the underlying models, focussing on the key features and contributions of the proposed framework. We also show how, using our framework, the QoS evaluation problem can be translated to a Constraint Satisfaction Problem while preserving the semantics of the preference policies.
Mohan Baruwal Chhetri, Quoc Bao Vo, Ryszard Kowalczyk
CCGRID1
2011 Cloud Broker: Helping You Buy Better
Mohan Baruwal Chhetri, Quoc Bao Vo, Ryszard Kowalczyk, Cam Lan Do
WISE1
2010 Policy-Based Management of QoS in Service Aggregations
abstract
We present a policy-centered QoS meta-model which can be used by service providers and consumers alike to express capabilities, requirements, constraints, and general management characteristics relevant for SLA establishment in service aggregations. We also provide a QoS assertion model which is generic, domain-independent and conforming to the WS-Policy syntax and semantics. Using these two models, assertions over acceptable and required values for QoS properties can be expressed across the different service layers and service roles.
Mohan Baruwal Chhetri, Quoc Bao Vo, Ryszard Kowalczyk
CCGRID1
2009 Agent Enabled Adaptive Management of QoS Assured Provision of Composite Services
abstract
The assurance of quality-of-service (QoS) is critical for the successful deployment of service-oriented applications, especially in open, dynamic, and distributed cross-organizational environments. Adaptive management of the QoS assured provision of composite services is required for more reliable, fault-tolerant, and flexible service delivery in such environments. It can be realized with software agents offering a unified framework and necessary capabilities for carrying out different adaptive management tasks across the whole lifecycle of composite service provision.
Ryszard Kowalczyk, Mohan Baruwal Chhetri
Cybern. Syst.2
2007 Autonomous service level agreement negotiation for service composition provision
Jun Yan 0005, Ryszard Kowalczyk, Mohan Baruwal Chhetri, SukKeong Goh, Jian Ying Zhang
Future Gener. Comput. Syst.4
2006 Towards Autonomous Service Level Agreement Negotiation for Adaptive Service Composition
abstract
This paper reports innovative research aiming at supporting autonomous establishment and maintenance of service level agreements in order to guarantee end-to-end quality of service requirements for service composition provision. In this research, a set of interrelated service level agreements is established and maintained for a service composition, through autonomous agent negotiation. To enable this, an innovative framework is proposed in which agents on behalf of the service requestor and the service providers can negotiate service level agreements in a coordinated way. This framework also enables adaptive service level agreement re-negotiation in the dynamic and ever-changing service environment
Jun Yan 0005, Jian Ying Zhang, Mohan Baruwal Chhetri, SukKeong Goh, Ryszard Kowalczyk
CSCWD4
2006 Adaptive Service Agreement and Process Management
abstract
The ASAPM project aims at developing new techniques, mechanisms and software solutions for enablement of flexible, dynamic and robust management of serviceoriented application provision processes to ensure collective functionality, end-to-end QoS and stateful coordination of complex services.
Boris Wu, Jian Ying Zhang, Mohan Baruwal Chhetri, SukKeong Goh, Xuan Thang Nguyen, Ingo Mueller 0001, E. Gomes, Jun Han 0004, Ryszard Kowalczyk
ICWS3
2004 Mobile Agents as Smart Virtual Counterparts
abstract
Smart spaces should not be bound by physical constraints but should transcend them in order to provide enhanced services. One way of overcoming this is by having smart virtual counterparts represent the real world entities in smart spaces. We propose that mobile agent technology is aptly suited for providing smart virtual counterparts of real-world entities in the virtual world and can be used to enhance the performance of smart spaces. We also present a prototype implementation using the Grasshopper mobile agent toolkit as proof of concept.
Mohan Baruwal Chhetri, Seng W. Loke, Shonali Krishnaswamy
AINA (2)1
2004 PIAVEE - A Pedagogy-Independent Education Environment
abstract
A platform independent agent-based virtual educational environment (PIAVEE) is described. PIAVEE is conceptualized as a lightweight, flexible environment that links educational resources through a virtual data base and that is supported by an intelligent delivery system. PIAVEE is implemented through an evolutionary process, whose initial focus is the development of and access to, the virtual data base. The paper describes the initial implementations, which focus on proof of concept and basic level functionality.
Shonali Krishnaswamy, Selby Markham, Mohan Baruwal Chhetri, A. John Hurst, Des Casey
ICALT3
2004 An Agent Supported Virtual Educational Environment
Mohan Baruwal Chhetri, Shonali Krishnaswamy, Selby Markham, A. John Hurst, Des Casey
iiWAS1
2003 From m-GAIA to Grasshopper: Engineering Mobile Agent Applications
Weanna Sutandiyo, Mohan Baruwal Chhetri, Shonali Krishnaswamy, Seng W. Loke
iiWAS2