EDBT 2026 Demo / reviewers in the wild / expert
Mengmeng Ge 0001
dblp:60/10299-1
· DBLP profile ↗
19ranked-venue papers
6as first author
11since 2021 · last 2026
0000-0003-2869-4203ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 7 since 2021Computer networks · 7 · 3 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 3 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Poisoning-based Link Inference Attacks Against Federated Graph Neural NetworksabstractFederated graph neural networks (FedGNNs) have emerged as a promising solution for handling graph data distributed across multiple owners. They enable collaborative training while preserving data decentralisation and complying with privacy and regulatory constraints. However, the inherent structural dependencies in graph data and the message-passing mechanisms of GNNs introduce both cross-client and intra-client edges in FedGNNs. Cross-client edges, in combination with federated learning (FL) protocol designs, open additional channels for information propagation and heighten the risk of privacy leakage. In FedGNNs, once edge information is compromised, adversaries can infer local neighbourhood structures and reconstruct inter-client relationships, even without direct access to raw data. Existing research on privacy inference in FL has largely overlooked edge privacy threats specific to FedGNNs. To address this gap, we propose a poisoning link inference approach with two strategies: Label Flipping Link Inference Attack (LFLIA) and Gradient Ascent Link Inference Attack (GALIA). LFLIA flips the label of a candidate node so that its perturbation propagates along structural topology during training. GALIA perturbs the candidate node’s gradient to amplify its loss. The perturbations on the candidate node can propagate to its linked neighbours by message-passing mechanism, which induces representation shifts on these linked nodes. By monitoring FedGNN outputs of a target node set before and after poisoning, an adversary can distinguish linked nodes through observable output shifts, whereas unlinked nodes exhibit little to no change. Experimental results on multiple benchmark datasets show that our poisoning-based LIA can effectively infer link existence and structure with high accuracy across diverse federated settings. Guizhen Yang, Yanjun Zhang 0002, Leo Yu Zhang, Mengmeng Ge 0001, Shang Gao 0003 |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Multi-agent Simulation and Reinforcement Learning to Optimize Moving Target Defense
William Valentine, Etienne Borde, Mengmeng Ge 0001 |
ARES (2) | 3 |
| 2025 | Unveiling the evolution of IoT threats: Trends, tactics, and simulation analysisabstractSince the inception of Mirai in 2016, a proliferation of advanced botnets targeting Internet of Things (IoT) devices has occurred, resulting in a notable increase in large-scale cyber attacks against online services. The continual emergence of novel strategies characterises the evolving landscape of IoT botnets. Despite this, a comprehensive understanding of this evolving threat remains elusive, impeding the development of robust defence mechanisms. This paper investigated 55 instances of IoT botnets spanning from 2008 to 2021 to elucidate their evolutionary patterns based on prevalent tactics and techniques. A novel taxonomy of IoT botnets is proposed and formulated with attack tactics, techniques, types, and procedures. We augment our existing simulation framework, IoTSecSim, with enhanced functionalities to simulate novel cyber-attack scenarios incorporating diverse network configurations, evolving attack tactics, and defence strategies. Through comprehensive simulations via the extended IoTSecSim, we assessed the impact of these evolving IoT attack tactics and gauged the efficacy of traditional defence mechanisms using various security metrics. Kok Onn Chee, Mengmeng Ge 0001, Guangdong Bai, Dong Seong Kim 0001 |
Comput. Secur. | 2 |
| 2025 | Graphical security modelling for Autonomous Vehicles: A novel approach to threat analysis and defence evaluationabstractAutonomous Vehicles (AVs) integrate numerous control units , network components, and protocols to operate effectively and interact with their surroundings, such as pedestrians and other vehicles. While these technologies enhance vehicle capabilities and enrich the driving experience, they also introduce new attack surfaces, making AVs vulnerable to cyber-attacks. Such cyber-attacks can lead to severe consequences, including traffic disruption and even threats to human life. Security modelling is crucial to safeguarding AVs as it enables the simulation and analysis of an AV’s security before any potential attacks. However, the existing research on AV security modelling methods for analysing security risks and evaluating the effectiveness of security measures remains limited. In this work, we introduce a novel graphical security model and metrics to assess the security of AV systems. The proposed model utilizes initial network information to build attack graphs and attack trees at different layers of network depth. From this, various metrics are automatically calculated to analyse the security and safety of the AV network. The proposed model is designed to identify potential attack paths, analyse security and safety with precise metrics, and evaluate various defence strategies. We demonstrate the effectiveness of our framework by applying it to two AV networks and distinct AV attack scenarios, showcasing its capability to enhance the security of AVs. Nhung H. Nguyen, Mengmeng Ge 0001, Jin-Hee Cho, Terrence J. Moore, Seunghyun Yoon 0001, Hyuk Lim, Frederica Free-Nelson, Guangdong Bai, Dong Seong Kim 0001 |
Comput. Secur. | 2 |
| 2024 | IoTSecSim: A framework for modelling and simulation of security in Internet of thingsabstractThe proliferation of the Internet of Things (IoT) devices has provided attackers with tremendous opportunities to launch various cyber-attacks. It has been challenging to analyse the impact of cyber-attacks and evaluate the effectiveness of defences in real IoT environments due to the scale and heterogeneity of IoT networks. In this work, we propose a novel simulation framework and a software tool, IoT Security Simulator (IoTSecSim). IoTSecSim is operated based on a framework we propose for modelling and simulating cyber-attacks and various defences in IoT networks. IoTSecSim is not only able to support the creation of an IoT network with flexible settings of IoT devices and topology information but also models the attack behaviours, node-level, and network-level defences. Moreover, a systematic security evaluation can be performed by comparing the results based on the calculation of security metrics. We perform simulations with case studies on Mirai malware and its variants to model cyber-attack behaviours on IoT networks and evaluate the impact of these attacks and the effectiveness of defence techniques via IoTSecSim. Then, we carry out a sensitivity analysis to justify that the simulation results produced by IoTSecSim are accurate and feasible when compared with related works. We also perform a comparative performance analysis with four combinations of cyber-attack behaviours and show that these behaviours can influence IoT malware propagation in different situations. We consider multiple attacker models and deploy conventional defence techniques (including firewall, intrusion detection, and vulnerability patching) to investigate the effectiveness of defence techniques. IoTSecSim provides a generalised and extensible simulation framework that enables users to model emerging cyber-attacks against IoT networks and evaluate the effectiveness of defences against these attacks. This helps users to focus on the design and performance evaluation of new defences before the actual implementation and deployment of the defences are required. Kok Onn Chee, Mengmeng Ge 0001, Guangdong Bai, Dong Seong Kim 0001 |
Comput. Secur. | 2 |
| 2023 | Fog-cloud based intrusion detection system using Recurrent Neural Networks and feature selection for IoT networks
Naeem Firdous Syed, Mengmeng Ge 0001, Zubair A. Baig |
Comput. Networks | 2 |
| 2022 | A Differential Privacy Mechanism for Deceiving Cyber Attacks in IoT Networks
Guizhen Yang, Mengmeng Ge 0001, Shang Gao 0003, Xuequan Lu, Leo Yu Zhang, Robin Doss |
NSS | 2 |
| 2022 | An integrated security hardening optimization for dynamic networks using security and availability modeling with multi-objective algorithm
Simon Yusuf Enoch, Julio Mendonca 0001, Jin B. Hong, Mengmeng Ge 0001, Dong Seong Kim 0001 |
Comput. Networks | 4 |
| 2022 | Proactive Defense for Internet-of-things: Moving Target Defense With CyberdeceptionabstractResource constrained Internet-of-Things (IoT) devices are highly likely to be compromised by attackers, because strong security protections may not be suitable to be deployed. This requires an alternative approach to protect vulnerable components in IoT networks. In this article, we propose an integrated defense technique to achieve intrusion prevention by leveraging cyberdeception (i.e., a decoy system) and moving target defense (i.e., network topology shuffling). We evaluate the effectiveness and efficiency of our proposed technique analytically based on a graphical security model in a software-defined networking (SDN)-based IoT network. We develop four strategies (i.e., fixed/random and adaptive/hybrid) to address “when” to perform network topology shuffling and three strategies (i.e., genetic algorithm/decoy attack path-based optimization/random) to address “how” to perform network topology shuffling on a decoy-populated IoT network, and we analyze which strategy can best achieve a system goal, such as prolonging the system lifetime, maximizing deception effectiveness, maximizing service availability, or minimizing defense cost. We demonstrated that a software-defined IoT network running our intrusion prevention technique at the optimal parameter setting prolongs system lifetime, increases attack complexity of compromising critical nodes, and maintains superior service availability compared with a counterpart IoT network without running our intrusion prevention technique. Further, when given a single goal or a multi-objective goal (e.g., maximizing the system lifetime and service availability while minimizing the defense cost) as input, the best combination of “when” and “how” strategies is identified for executing our proposed technique under which the specified goal can be best achieved. Mengmeng Ge 0001, Jin-Hee Cho, Dong Seong Kim 0001, Ing-Ray Chen |
ACM Trans. Internet Techn. | 1 |
| 2021 | Automated Security Assessment for the Internet of ThingsabstractInternet of Things (IoT) based applications face an increasing number of potential security risks, which need to be systematically assessed and addressed. Expert-based manual assessment of IoT security is a predominant approach, which is usually inefficient. To address this problem, we propose an automated security assessment framework for IoT networks. Our framework first leverages machine learning and natural language processing to analyze vulnerability descriptions for predicting vulnerability metrics. The predicted metrics are then input into a two-layered graphical security model, which consists of an attack graph at the upper layer to present the network connectivity and an attack tree for each node in the network at the bottom layer to depict the vulnerability information. This security model automatically assesses the security of the IoT network by capturing potential attack paths. We evaluate the viability of our approach using a proof-of-concept smart building system model which contains a variety of real-world IoT devices and poten-tial vulnerabilities. Our evaluation of the proposed framework demonstrates its effectiveness in terms of automatically predicting the vulnerability metrics of new vulnerabilities with more than 90% accuracy, on average, and identifying the most vulnerable attack paths within an IoT network. The produced assessment results can serve as a guideline for cybersecurity professionals to take further actions and mitigate risks in a timely manner. Xuanyu Duan, Mengmeng Ge 0001, Triet Huynh Minh Le, Faheem Ullah, Shang Gao 0003, Xuequan Lu, Muhammad Ali Babar 0001 |
PRDC | 2 |
| 2021 | Towards a deep learning-driven intrusion detection approach for Internet of Things
Mengmeng Ge 0001, Naeem Firdous Syed, Xiping Fu, Zubair A. Baig, Antonio Robles-Kelly |
Comput. Networks | 1 |
| 2020 | Integrated Proactive Defense for Software Defined Internet of Things under Multi-Target AttacksabstractDue to the constrained resource and computational limitation of many Internet of Things (IoT) devices, conventional security protections, which require high computational overhead are not suitable to be deployed. Thus, vulnerable IoT devices could be easily exploited by attackers to break into networks. In this paper, we employ cyber deception and moving target defense (MTD) techniques to proactively change the network topology with both real and decoy nodes with the support of software-defined networking (SDN) technology and investigate the impact of single-target and multi-target attacks on the effectiveness of the integrated mechanism via a hierarchical graphical security model with security metrics. We also implement a web-based visualization interface to show topology changes with highlighted attack paths. Finally, the qualitative security analysis is performed for a small-scale and SDN-supported IoT network with different combinations of decoy types and levels of attack intelligence. Simulation results show the integrated defense mechanism can introduce longer mean-time-to-security-failure and larger attack impact under the multi-target attack, compared with the single-target attack model. In addition, adaptive shuffling has better performance than fixed interval shuffling in terms of a higher proportion of decoy paths, longer mean-time-to-security-failure and largely reduced defense cost. Weilun Liu, Mengmeng Ge 0001, Dong Seong Kim 0001 |
CCGRID | 2 |
| 2019 | Multi-Objective Security Hardening Optimisation for Dynamic NetworksabstractHardening the dynamic networks is a very challenging task due to their complexity and dynamicity. Moreover, there may be multi-objectives to satisfy, while containing the solutions within the constraints (e.g., fixed budget, availability of countermeasures, performance degradation, non-patchable vulnerabilities, etc). In this paper, we propose a systematic approach to optimise the selection of the security hardening options for the dynamic networks given multiple constraints and objectives. To do so, we evaluate potential attack scenarios for a given time period, and then use a multi-objective optimisation based on Non-dominated Sorting Genetic Algorithm to find the optimal set of security hardening options. We measure the effectiveness of the options using various security metrics, which is demonstrated through experimental analysis. The results show that our approach can be applied to select the optimal set of security hardening options to be deployed for the dynamic networks given multiple objectives and constraints. Simon Yusuf Enoch, Jin B. Hong, Mengmeng Ge 0001, Khaled M. Khan, Dong Seong Kim 0001 |
ICC | 3 |
| 2019 | Deep Learning-Based Intrusion Detection for IoT NetworksabstractInternet of Things (IoT) has an immense potential for a plethora of applications ranging from healthcare automation to defence networks and the power grid. The security of an IoT network is essentially paramount to the security of the underlying computing and communication infrastructure. However, due to constrained resources and limited computational capabilities, IoT networks are prone to various attacks. Thus, safeguarding the IoT network from adversarial attacks is of vital importance and can be realised through planning and deployment of effective security controls; one such control being an intrusion detection system. In this paper, we present a novel intrusion detection scheme for IoT networks that classifies traffic flow through the application of deep learning concepts. We adopt a newly published IoT dataset and generate generic features from the field information in packet level. We develop a feed-forward neural networks model for binary and multi-class classification including denial of service, distributed denial of service, reconnaissance and information theft attacks against IoT devices. Results obtained through the evaluation of the proposed scheme via the processed dataset illustrate a high classification accuracy. Mengmeng Ge 0001, Xiping Fu, Naeem Firdous Syed, Zubair A. Baig, Gideon Teo, Antonio Robles-Kelly |
PRDC | 1 |
| 2018 | Evaluating the Security of IoT Networks with Mobile DevicesabstractThe Internet of Things (IoT) is a network comprised of heterogeneous devices that can exchange data without requiring human-to-human or human-to-computer interactions. However, there are various vulnerabilities found due to the heterogeneity of the IoT network. Moreover, the mobility of IoT devices causes potential dynamic changes to the attack surfaces of IoT networks. As a result, static network security analysis approaches cannot capture these changes. In order to address this problem, we present an IoT security assessment approach by modelling different movement patterns of mobile IoT devices. Graphical security models are used in conjunction to evaluate the security of the IoT networks taking into account the mobility of the IoT devices. Further, we use various security metrics to analyze the security of the network to show the changing security posture when mobility is taken into account. The feasibility of the proposed approach is demonstrated by analyzing the security of an example mobile IoT network using three existing synthetic mobility models: Random Waypoint, Gauss-Markov and Reference Point Group. The experimental analysis shows the changing attack surface of the IoT networks when mobile devices are considered. Amelia Samandari, Mengmeng Ge 0001, Jin B. Hong, Dong Seong Kim 0001 |
PRDC | 2 |
| 2018 | A systematic evaluation of cybersecurity metrics for dynamic networks
Simon Yusuf Enoch, Mengmeng Ge 0001, Jin B. Hong, Hani Alzaid, Dong Seong Kim 0001 |
Comput. Networks | 2 |
| 2018 | Proactive defense mechanisms for the software-defined Internet of Things with non-patchable vulnerabilities
Mengmeng Ge 0001, Jin B. Hong, Simon Yusuf Enoch, Dong Seong Kim 0001 |
Future Gener. Comput. Syst. | 1 |
| 2017 | A framework for automating security analysis of the internet of things
Mengmeng Ge 0001, Jin B. Hong, Walter Guttmann, Dong Seong Kim 0001 |
J. Netw. Comput. Appl. | 1 |
| 2015 | A Framework for Modeling and Assessing Security of the Internet of ThingsabstractInternet of Things (IoT) is enabling innovative applications in various domains. Due to its heterogeneous and wide scale structure, it introduces many new security issues. To address the security problem, we propose a framework for security modeling and assessment of the IoT. The framework helps to construct graphical security models for the IoT. Generally, the framework involves five steps to find attack scenarios, analyze the security of the IoT through well-defined security metrics, and assess the effectiveness of defense strategies. The benefits of the framework are presented via a study of two example IoT networks. Through the analysis results, we show the capabilities of the proposed framework on mitigating impacts of potential attacks and evaluating the security of large-scale networks. Mengmeng Ge 0001, Dong Seong Kim 0001 |
ICPADS | 1 |