EDBT 2026 Demo / reviewers in the wild / expert
Shahrear Iqbal
dblp:51/8816 · also Md. Shahrear Iqbal
· DBLP profile ↗
21ranked-venue papers
5as first author
16since 2021 · last 2025
0000-0001-7819-5715ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 8 since 2021Computer networks · 4 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | CSA-SACS: A Framework for Comparative Security Assessment in Smart Aging Care SystemsabstractSmart Aging Care Systems (SACS) for independent living relies on various IoT service products to support the well-being of older adults. While research in this domain emphasizes the necessity of robust security protocols to protect this vulnerable population from cyber threats, there is a critical gap in methodologies for selecting the most suitable alternatives that meet the security requirements of SACS. This research introduces a framework, called Comparative Security Assessment in SACS (CSA-SACS). CSA-SACS evaluates the security standards of service products within SACS, integrating perspectives from multiple decision-makers, such as usability engineers and security experts. To address these evaluations’ inherent uncertainty and subjectivity, fuzzy triangular numbers are used for comparative assessments. The evaluation criteria are derived from the very recent ISO/IEC 25010:2023 standard, which encompasses conflicting elements, making the Analytic Hierarchy Process (AHP) a suitable approach for prioritization and ensuring consistency in decision-making. CSA-SACS enables evaluators to prioritize security selection criteria based on SACS-specific requirements and an automated error-handling mechanism to improve the reliability of judgment aggregation. Nilesh Chakraborty, Shahrear Iqbal, Mohammad Zulkernine |
COMPSAC | 2 |
| 2025 | CAGAID: Context-Aware Gait Anomaly-Based Intrusion Detection
Youssef Yamout, Shahrear Iqbal, Mohammad Zulkernine |
CRiSIS | 2 |
| 2025 | LIDIT: Low-Latency Intrusion Detection in IoMT Devices using TinyMLabstractThe Internet of Medical Things (IoMT) is reshaping healthcare by facilitating real-time monitoring, diagnosis, and treatment through interconnected devices and systems. However, the proliferation of resource-constrained IoMT devices introduces substantial cybersecurity challenges. Due to limited computational and energy resources, conventional security mechanisms such as complex encryption algorithms and robust firewalls are often infeasible. This poses serious risks in critical healthcare applications where delayed threat detection can lead to life-threatening outcomes. To address these pressing challenges, this research presents LIDIT, a novel anomaly-based intrusion detection framework with specialized feature segmentation designed for resource-constrained environments using TinyML. Our approach employs a multi-branch LSTM-autoencoder model trained exclusively on benign traffic, utilizing an input segmentation strategy based on session-level, TCP flags, and time-window features to capture fine-grained temporal as well as contextual patterns in network behavior. We evaluated the model on the CICIoMT2024 and IoMT-TrafficData dataset and demonstrated that our proposed segmentation framework improves anomaly detection performance over unified models. The best-performing model achieved an accuracy of 0.9990 and an F1-score of 0.9988 with a recall of 0.9995 for the CICIoMT2024 dataset. Post-training quantization using FLOAT16 and INT8 further significantly reduced the model sizes, making it suitable for real-time deployment. The system was successfully deployed on a Raspberry Pi Zero 2 W and tested under a live SYN flood attack, detecting anomalies in real time with an average inference time of 10.25 milliseconds. These results confirm the effectiveness, efficiency, and deployability of LIDIT as a lightweight, low-latency intrusion detection solution for modern healthcare IoT systems. Shaila Tajmim Anuva, Shahrear Iqbal, Mohammad Zulkernine |
GLOBECOM | 2 |
| 2025 | CloudAPT: A Provenance-Based Dataset for Evaluating APT Countermeasures in Cloud EnvironmentsabstractThe dynamic nature of cloud environments has amplified the challenges of defending against Advanced Persistent Threats (APTs), which exploit the complexity and interconnectedness of modern infrastructures. Existing datasets fail to adequately address the unique requirements of cloud-native systems, particularly those leveraging system provenance graphs for comprehensive analysis. In this work, we present CloudAPT, the first dataset to utilize system provenance graphs for capturing APT behaviors in Kubernetes-based cloud environments. The dataset spans eight days, encompassing the complete APT lifecycle: reconnaissance, initial compromise, privilege escalation, lateral movement, data exfiltration, and covering tracks, while integrating realistic, human-driven user interactions. By centralizing activities on a single worker VM, the dataset ensures granular and transparent data collection, avoiding fragmentation and providing a holistic view of attacker strategies and system responses. CloudAPT includes provenance graph data, cluster logs, and application-level data, offering deep insights into interactions within cloud-native systems. This dataset serves as a foundational resource for developing and benchmarking advanced detection mechanisms and security solutions tailored specifically to the complexities of cloud environments. Md Ariful Haque, Euclides Carlos Pinto Neto, Thomas Pasquier, Shahrear Iqbal |
ISNCC | 4 |
| 2025 | Integrating Auxiliary Knowledge into Machine Learning to Improve the Detection of CyberattacksabstractMalicious activities are becoming more complex and difficult to detect, leading to a need for advanced solutions. Machine Learning (ML) presents several success cases across multiple industries and in cybersecurity, ML has demonstrated promising performance in the detection and classification of malicious activities. However, there are still critical limitations that prevent their wide adoption in cybersecurity operations (e.g., lack of interpretability and too many false positives). KnowledgeInfused Learning (KIL) has the potential to address current limitations through different techniques. One possible approach relies on the adoption of Auxiliary Knowledge (AK), which uses domain knowledge to extract and engineer new features present in the raw data and provides additional context that helps the model better understand and differentiate between legitimate and malicious data. The main goal of this research is to propose a method that uses Auxiliary Knowledge (AK) to improve ML performance in detecting cyberattacks. We leveraged relevant domain knowledge to generate features from the raw data that are difficult for an ML model to discover. This approach also reduces the dependence on large amount of training data (big data) that is necessary for better ML predictions. The experiments used the CICIoT2023 dataset and demonstrated that auxiliary knowledge improves the detection performance, paving the way for future integration of automated knowledge management approaches. Shahrear Iqbal, Sourena Khanzadeh, Euclides Carlos Pinto Neto, Scott Buffett, Madeena Sultana, Adrian Taylor |
ISNCC | 1 |
| 2025 | Cyber Threat Mitigation with Knowledge-Infused Reinforcement Learning and LLM-Guided PoliciesabstractAs cyber threats continue to evolve, there is a need for autonomous cyber defense (ACD) strategies capable of fast and context-aware responses. Reinforcement learning (RL) has shown promise for automating cyber defense by exploring and learning effective countermeasures, yet it often struggles with sparse reward signals and insufficient context to handle diverse attack scenarios. Furthermore, the convergence time taken by an RL agent is often high, which makes it difficult to train the RL agent in online settings. To address these challenges, we propose a large language model (LLM)-enhanced RL method that builds and queries a knowledge graph (KG) derived from agent-environment interactions. We leverage the pre-trained knowledge of an LLM on different cybersecurity frameworks and use the LLM to analyze a part of the KG to generate appropriate actions for the RL agent. We infuse the knowledge extracted from the LLM into the RL agent’s training loop in two ways. First, the state vector of the RL agent is augmented with the most effective action and its corresponding reward, as determined from the KG. Second, the suggested action from the LLM is used as a reference policy. In addition, we introduce a regularization term in the loss function to make the RL policy close to the reference policy. To validate our approach, we develop a custom RL environment guided by the MITRE ATT&CK framework, enabling the agent to generate tailored mitigation strategies for detected cyber attacks. Experimental results show that our proposed approach significantly outperforms the baseline RL by over $75 \%$ in terms of taking better mitigation actions. Md. Shamim Towhid, Shahrear Iqbal, Euclides Carlos Pinto Neto, Nashid Shahriar, Scott Buffett, Madeena Sultana, Adrian Taylor |
PST | 2 |
| 2025 | ORTHRUS: Achieving High Quality of Attribution in Provenance-based Intrusion Detection Systems
Baoxiang Jiang, Tristan Bilot, Nour El Madhoun, Khaldoun Al Agha, Anis Zouaoui, Shahrear Iqbal, Xueyuan Han, Thomas Pasquier |
USENIX Security Symposium | 6 |
| 2024 | Resilience Against APTs: A Provenance-Based IIoT Dataset for Cybersecurity Research
Erfan Ghiasvand, Suprio Ray, Shahrear Iqbal, Sajjad Dadkhah, Ali A. Ghorbani 0001 |
MobiQuitous | 3 |
| 2024 | Building Secure Software for Smart Aging Care Systems: An Agile ApproachabstractThere exists a persistent challenge in sufficiently addressing software security issues and effectively integrating security procedures into the software development life cycle. Software products vulnerable to security threats can result in severe consequences, especially in sensitive domains like those providing age-related support for older adults. This work offers guidelines to address software vulnerabilities in one of such evolving and sensitive domains, namely, Smart Aging Care Systems (SACS). The existing guidelines for securing the software cannot effectively address the observed vulnerabilities in SACS because of the unique demographics of its users and special design requirements. Therefore, the primary objective of this paper is to enhance the comprehension of secure software development methods, considering best security practices or controls in general and tailoring their selection based on the unique requirements of SACS. The chosen controls are then reshaped to align with the specific needs of SACS, with implementation carried out using the agile framework, specifically Scrum. We believe that this work will aid software development organizations in significantly enhancing the security of their software products for SACS dynamically and effectively, leveraging the Scrum framework, and also inspire its implementation in other emerging domains. Nilesh Chakraborty, Shahrear Iqbal, Mohammad Zulkernine |
QRS | 2 |
| 2024 | Gait4Auth: Enhancing Identification and Security in Gait-Based Authentication
Youssef Yamout, Shahrear Iqbal, Nilesh Chakraborty, Mohammad Zulkernine |
SecureComm (4) | 2 |
| 2024 | Pulse-to-Pair: Heartbeat-Based Authentication of IoT Devices for Elderly Care
Tashaffi Samin Yeasar, Shahrear Iqbal, Mohammad Zulkernine |
SecureComm (4) | 2 |
| 2024 | MEGR-APT: A Memory-Efficient APT Hunting System Based on Attack Representation LearningabstractThe stealthy and persistent nature of Advanced Persistent Threats (APTs) makes them one of the most challenging cyber threats to uncover. Several systems adopted the development of provenance-graph-based security solutions to capture this persistent nature. Provenance graphs (PGs) represent system audit logs by connecting system entities using causal relations and information flows. Hunting APTs demands the processing of ever-growing large-scale PGs of audit logs for a wide range of activities over months or years, i.e., multi-terabyte graphs. Existing APT hunting systems are typically memory-based, which suffers colossal memory consumption, or disk-based, which suffers from performance hits. Therefore, these systems are hard to scale in terms of graph size or time performance. In this paper, we propose MEGR-APT, a scalable APT hunting system to discover suspicious subgraphs matching an attack scenario (query graph) published in Cyber Threat Intelligence (CTI) reports. MEGR-APT hunts APTs in a twofold process: (i) memory-efficient extraction of suspicious subgraphs as search queries over a graph database, and (ii) fast subgraph matching based on graph neural network (GNN) and our effective attack representation learning. We compared MEGR-APT with state-of-the-art (SOTA) APT systems using popular APT benchmarks, such as DARPA TC3 and OpTC. We also tested it using a real enterprise dataset. MEGR-APT achieves an order of magnitude reduction in memory consumption while achieving comparable performance to SOTA in terms of time and accuracy. Ahmed Aly, Shahrear Iqbal, Amr M. Youssef, Essam Mansour 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | IoT malware: An attribute-based taxonomy, detection mechanisms and challenges
Princy Victor, Arash Habibi Lashkari, Rongxing Lu, Tinshu Sasi, Pulei Xiong, Shahrear Iqbal |
Peer Peer Netw. Appl. | 6 |
| 2022 | Towards a robust and trustworthy machine learning system development: An engineering perspective
Pulei Xiong, Scott Buffett, Shahrear Iqbal, Philippe Lamontagne 0001, Mohammad Saiful Islam Mamun, Heather Molyneaux |
J. Inf. Secur. Appl. | 3 |
| 2021 | Verification Based Scheme to Restrict IoT AttacksabstractIn recent years, with the increased usage of the Internet of Things (IoT) devices, cyber-attacks have become a serious threat over the Internet. These devices have low memory capacity and processing power, which makes them easy targets for attackers. The research community has proposed different approaches to deal with emerging variants of attacks on IoT devices using various machine learning techniques. However, these approaches rely heavily on the classifier’s categorization of a given record while ignoring its confidence. This paper proposes a verification-based scheme to reject IoT attacks by utilizing the classifier’s confidence. At the same time, existing studies are evaluated using traditional cross-validation approaches (e.g., k-fold), thus, not tested against unknown attacks. We propose using the leave-one-attack-out (LOAO) cross-validation scheme to evaluate the generalizability of the application to unknown attacks. The experiments are performed on Med BIoT, a publicly available dataset consisting of three IoT attacks. The system’s robustness is evaluated in terms of Receiver Operating Curves (ROC) and Equal Error rates (EERs). The results indicate a lower false-positive rate of 12.6% using the proposed verification-based approach in comparison to k-fold cross-validation. Barjinder Kaur, Sajjad Dadkhah, Pulei Xiong, Shahrear Iqbal, Suprio Ray, Ali A. Ghorbani 0001 |
BDCAT | 4 |
| 2021 | Analyzing the Usefulness of the DARPA OpTC Dataset in Cyber Threat Detection ResearchabstractMaintaining security and privacy in real-world enterprise networks is becoming more and more challenging. Cyber actors are increasingly employing previously unreported and state-of-the-art techniques to break into corporate networks. To develop novel and effective methods to thwart these sophisticated cyber attacks, we need datasets that reflect real-world enterprise scenarios to a high degree of accuracy. However, precious few such datasets are publicly available. Researchers still predominantly use the decade-old KDD datasets, however, studies showed that these datasets do not adequately reflect modern attacks like Advanced Persistent Threats (APT). In this work, we analyze the usefulness of the recently introduced DARPA Operationally Transparent Cyber (OpTC) dataset in this regard. We describe the content of the dataset in detail and present a qualitative analysis. We show that the OpTC dataset is an excellent candidate for advanced cyber threat detection research while also highlighting its limitations. Additionally, we propose several research directions where this dataset can be useful. Md. Monowar Anjum, Shahrear Iqbal, Benoit Hamelin |
SACMAT | 2 |
| 2019 | Securing Vehicle ECU Communications and Stored DataabstractNowadays, the automobile industry is integrating many new features into vehicles. To provide these features, various electronic systems are being added. These systems are coordinated by different ECUs (Electronic Control Unit). Vehicle ECUs are internally connected through multiple communication buses. Any ECU connected to the bus can read or send data to other ECUs. As a result, if an adversary can compromise one of the ECUs, then the adversary will be able to access and exploit the data of other important ECUs. Moreover, an adversary can modify the stored data of an important ECU, if it is compromised. To solve these problems, we propose the use of symmetric key cryptography and elliptic curve-based Public Key Encryption (PKE) for ensuring confidentiality and the use of digital signature for ensuring integrity and authenticity. In addition, we propose the adoption of an identity-based access control to control the communication permissions. We also introduce a Blockchain-inspired mechanism to secure data stored in ECUs. Finally, we integrate a watcher to monitor the stored data and report if it is modified. We implement our concept using the ARM architecture-based Raspberry Pi Board and show that our approach can improve security in ECU communications and the watcher reports when an ECU data is modified. Md Swawibe Ul Alam, Shahrear Iqbal, Mohammad Zulkernine, Clifford Liem |
ICC | 2 |
| 2019 | Towards a Security Architecture for Protecting Connected Vehicles from MalwareabstractVehicles are becoming increasingly connected to the outside world. We can connect our devices to the vehicle's infotainment system and internet is being added as a functionality. Therefore, security is a major concern as the attack surface has become much larger than before. Consequently, attackers are creating malware that can infect vehicles and perform life-threatening activities. For example, a malware can compromise vehicle ECUs and cause unexpected consequences. Hence, ensuring the security of connected vehicle software and networks is extremely important to gain consumer confidence and foster the growth of this emerging market. In this paper, we propose a characterization of vehicle malware and a security architecture to protect vehicle from these malware. The architecture uses multiple computational platforms and makes use of the virtualization technique to limit the attack surface. There is a real-time operating system to control critical vehicle functionalities and multiple other operating systems for non-critical functionalities (infotainment, telematics, etc.). The security architecture also describes groups of components for the operating systems to prevent malicious activities and perform policing (monitor, detect, and control). We believe this work will help automakers guard their systems against malware and provide a clear guideline for future research. Shahrear Iqbal, Anwar Haque, Mohammad Zulkernine |
VTC Spring | 1 |
| 2018 | Protecting Internet users from becoming victimized attackers of click-fraudabstractAbstract Internet users are often victimized by malicious attackers. Some attackers infect and use innocent users' machines to launch large‐scale attacks without the users' knowledge. One of such attacks is the click‐fraud attack. Click‐fraud happens in pay‐per‐click ad networks where the ad network charges advertisers for every click on their ads. Click‐fraud has been proved to be a serious problem for the online advertisement industry. In a click‐fraud attack, a user or an automated software clicks on an ad with a malicious intent and advertisers need to pay for those valueless clicks. Among many forms of click‐fraud, botnets with the automated clickers are the most severe ones. In this study, we present a method for detecting automated clickers from the user side. The proposed method to fight click‐fraud, FCFraud, can be integrated into the desktop and smart device operating systems. Since most modern operating systems already provide some kind of antimalware service, our proposed method can be implemented as a part of the service. We believe that an effective protection at the operating system level can save billions of dollars of the advertisers. Experiments show that FCFraud is 99.6% (98.2% in mobile ad library–generated traffic) accurate in classifying ad requests from all user processes and it is 100% successful in detecting clickbots in both desktop and mobile devices. We implement a cloud backend for the FCFraud service to save battery power in mobile devices. The overhead of executing FCFraud is also analyzed and we show that it is reasonable for both the platforms. Shahrear Iqbal, Mohammad Zulkernine, Fehmi Jaafar, Yuan Gu |
J. Softw. Evol. Process. | 1 |
| 2017 | Droid Mood Swing (DMS): Automatic Security Modes Based on Contexts
Shahrear Iqbal, Mohammad Zulkernine |
ISC | 1 |
| 2016 | SAM: A secure anti-malware framework for the smartphone operating systemsabstractSmartphones have become an integral part of our daily life. Businesses now offer services through smartphones. Users also store sensitive personal information on their smartphones and perform financial transactions. Consequently, security attacks on smartphone platforms have also increased significantly. Traditional desktop anti-virus software are not very effective in smartphones due to the restrictive security model and they are heavily dependent on their definition updates. In this paper, we propose a Secure Anti-Malware framework (SAM) for smartphone operating systems to prevent malicious activities. The core idea of the framework resembles a smart city. The framework acts as the government of the city and treats the applications as citizens. It has components to enforce laws (prevent) and perform policing (monitor and control). It also provides APIs to aid anti-virus software and third-party applications to leverage the functionalities of the framework. Our goal is to design an operating system framework that hinders malicious activities and thus protects user resources. Shahrear Iqbal, Mohammad Zulkernine |
WCNC | 1 |