EDBT 2026 Demo / reviewers in the wild / expert
Komminist Weldemariam
dblp:61/5240 · also Kommy Weldemariam
· DBLP profile ↗
42ranked-venue papers
7as first author
8since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 5 first-authorArtificial intelligence and machine learning · 11 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 since 2021Software engineering, systems software and programming languages · 4 · 2 first-authorDatabases, data management, data science and information retrieval · 3 · 1 since 2021Systems, architecture and hardware · 2Human-computer interaction and ubiquitous computing · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
4 papers |
Graph learning · 47% Efficient and distributed learning · 31% Reinforcement learning · 16% | |
| Interdisciplinary, comprehensive, and emerging computing
3 papers |
Environmental and earth informatics · 50% Medical and health informatics · 50% | |
| Databases, data mining, and information retrieval
1 paper |
Data mining · 100% | |
| Network and information security
2 papers |
Security and privacy of machine learning · 82% Cryptographic protocols and secure computation · 18% |
Topics — the 14 heaviest of 17, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Efficient and distributed learning
active learning |
0.8 | 1 | 2024 | Neural Active Learning Beyond Bandits · ICLR 2024 |
Machine learning › Reinforcement learning
bandit |
0.8 | 1 | 2024 | Neural Active Learning Beyond Bandits · ICLR 2024 |
Machine learning › Efficient and distributed learning › active learning
deep active learning |
0.8 | 1 | 2024 | Neural Active Learning Beyond Bandits · ICLR 2024 |
Machine learning › Graph learning › efficient graph learning › data-efficient graph learning
imbalanced graph learning |
0.8 | 1 | 2024 | Class-Imbalanced Graph Learning without Class Rebalancing · ICML 2024 |
Machine learning › Graph learning › graph neural network
node classification |
0.8 | 1 | 2024 | Class-Imbalanced Graph Learning without Class Rebalancing · ICML 2024 |
Data mining
pattern mining |
0.4 | 1 | 2020 | Decision Platform for Pattern Discovery and Causal Effect Estimation in Contraceptive Discontinuation · IJCAI 2020 |
Data mining › pattern mining
subgroup discovery |
0.4 | 1 | 2020 | Decision Platform for Pattern Discovery and Causal Effect Estimation in Contraceptive Discontinuation · IJCAI 2020 |
Security and privacy of machine learning › adversarial defense
adversarial example detection |
0.4 | 1 | 2020 | Detecting Adversarial Attacks via Subset Scanning of Autoencoder Activations and Reconstruction Error · IJCAI 2020 |
Computer vision › Segmentation and scene understanding › semantic segmentation
remote sensing image segmentation |
0.2 | 1 | 2022 | Deploying an Artificial Intelligence Application to Detect Flood from Sentinel 1 Data · AAAI 2022 |
Machine learning › Trustworthy machine learning
interpretability |
0.1 | 1 | 2020 | Inspection of Blackbox Models for Evaluating Vulnerability in Maternal, Newborn, and Child Health · IJCAI 2020 |
Medical and health informatics
public health |
0.1 | 1 | 2020 | Decision Platform for Pattern Discovery and Causal Effect Estimation in Contraceptive Discontinuation · IJCAI 2020 |
Cryptographic protocols and secure computation
electronic voting |
0.1 | 1 | 2009 | Development, formal verification, and evaluation of an E-voting system with VVPAT · IEEE Trans. Inf. Forensics Secur. 2009 |
Program verification
model checking |
0.1 | 1 | 2009 | Development, formal verification, and evaluation of an E-voting system with VVPAT · IEEE Trans. Inf. Forensics Secur. 2009 |
Requirements engineering and software design › user-centered design
participatory design |
0.0 | 1 | 2009 | Development, formal verification, and evaluation of an E-voting system with VVPAT · IEEE Trans. Inf. Forensics Secur. 2009 |
Methods — techniques the papers use, named apart from their topics
convolutional neural network · 1.1causal inference · 0.9black-box model inspection · 0.9topological augmentation · 0.8neural network · 0.8exploration-exploitation · 0.8class rebalancing · 0.8subset scanning · 0.4autoencoder · 0.4participatory design · 0.2model checking · 0.2formal methods · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ClimateBench-M: A Multi-Modal Climate Data Benchmark with a Simple Generative MethodabstractClimate science studies the structure and dynamics of Earth's climate system and seeks to understand how climate changes over time, where the data is usually stored in the format of time series, recording the climate features, geolocation, time attributes, etc. Recently, much research attention has been paid to the climate benchmarks. In addition to the most common task of weather forecasting, several pioneering benchmark works are proposed for extending the modality, such as domain-specific applications like tropical cyclone intensity prediction and flash flood damage estimation, or climate statement and confidence level in the format of natural language. To further motivate the artificial intelligence development for climate science, in this paper, we first contribute a multi-modal climate benchmark, i.e., ClimateBench-M, which aligns (1) the time series climate data from ERA5, (2) extreme weather events data from NOAA, and (3) satellite image data from NASA HLS based on a unified spatial-temporal granularity. Second, under each data modality, we also propose a simple but strong generative method that could produce competitive performance in weather forecasting, thunderstorm alerts, and crop segmentation tasks in the proposed ClimateBench-M. The data and code of ClimateBench-M are publicly available at https://github.com/iDEA-iSAIL-Lab-UIUC/ClimateBench-M. Dongqi Fu, Yada Zhu, Zhining Liu 0002, Lecheng Zheng, Xiao Lin 0016, Zihao Li 0006, Liri Fang, Katherine Tieu, Onkar Bhardwaj, Komminist Weldemariam, Hanghang Tong, Hendrik F. Hamann, Jingrui He |
CIKM | 10 |
| 2024 | Encoding Seasonal Climate Predictions with Modular Neural NetworkabstractWe propose a novel modeling framework that efficiently encodes seasonal climate predictions to provide robust and reliable time-series forecasting for supply chain functions. The encoding framework enables effective learning of latent representations—be it uncertain seasonal climate prediction or other time-series data (e.g., buyer patterns)—via a modular neural network architecture. Our extensive experiments indicate that learning such representations to model seasonal climate forecasts results in an error reduction of approximately 13% to 17% across multiple real-world data sets compared to existing demand forecasting methods. Smit Marvaniya, Nicolas Galichet, Fred Otieno, Geeth de Mel, Komminist Weldemariam |
ICASSP | 6 |
| 2024 | Neural Active Learning Beyond BanditsabstractWe study both stream-based and pool-based active learning with neural network approximations. A recent line of works proposed bandit-based approaches that transformed active learning into a bandit problem, achieving both theoretical and empirical success. However, the performance and computational costs of these methods may be susceptible to the number of classes, denoted as $K$, due to this transformation. Therefore, this paper seeks to answer the question: "How can we mitigate the adverse impacts of $K$ while retaining the advantages of principled exploration and provable performance guarantees in active learning?" To tackle this challenge, we propose two algorithms based on the newly designed exploitation and exploration neural networks for stream-based and pool-based active learning. Subsequently, we provide theoretical performance guarantees for both algorithms in a non-parametric setting, demonstrating a slower error-growth rate concerning $K$ for the proposed approaches. We use extensive experiments to evaluate the proposed algorithms, which consistently outperform state-of-the-art baselines. Yikun Ban, Ishika Agarwal, Yada Zhu, Komminist Weldemariam, Hanghang Tong, Jingrui He |
ICLR | 5 |
| 2024 | Class-Imbalanced Graph Learning without Class RebalancingabstractClass imbalance is prevalent in real-world node classification tasks and poses great challenges for graph learning models. Most existing studies are rooted in a class-rebalancing (CR) perspective and address class imbalance with class-wise reweighting or resampling. In this work, we approach the root cause of class-imbalance bias from an topological paradigm. Specifically, we theoretically reveal two **fundamental phenomena in the graph topology** that greatly exacerbate the predictive bias stemming from class imbalance. On this basis, we devise a lightweight topological augmentation framework BAT to mitigate the class-imbalance bias without class rebalancing. Being orthogonal to CR, BAT can function as an **efficient plug-and-play module** that can be seamlessly combined with and significantly boost existing CR techniques. Systematic experiments on real-world imbalanced graph learning tasks show that BAT can deliver up to 46.27% performance gain and up to 72.74% bias reduction over existing techniques. Code, examples, and documentations are available at https://github.com/ZhiningLiu1998/BAT. Zhining Liu 0002, Ruizhong Qiu, Zhichen Zeng 0001, Hyunsik Yoo, David Zhou, Zhe Xu 0007, Yada Zhu, Komminist Weldemariam, Jingrui He, Hanghang Tong |
ICML | 8 |
| 2022 | Deploying an Artificial Intelligence Application to Detect Flood from Sentinel 1 DataabstractAs climate change is increasing the frequency and intensity of climate and weather hazards, improving detection and monitoring of flood events is a priority. Being weather independent and high resolution, Sentinel 1 (S1) radar satellite imagery data has become the go to data source to detect flood events accurately. However, current methods are either based on fixed thresholds to differentiate water from land or train Artificial Intelligence (AI) models based on only S1 data, despite the availability of many other relevant data sources publicly. These models also lack comprehensive validations on out-of-sample data and deployment at scale. In this study, we investigated whether adding extra input layers could increase the performance of AI models in detecting floods from S1 data. We also provide performance across a range of 11 historical events, with results ranging between 0.93 and 0.97 accuracy, 0.53 and 0.81 IoU, and 0.68 and 0.89 F1 scores. Finally, we show the infrastructure we developed to deploy our AI models at scale to satisfy a range of use cases and user requests. Paolo Fraccaro, Nikola Stoyanov, Zaheed Gaffoor, Laura Elena Cue La Rosa, Tatsuya Ishikawa, Blair Edwards, Anne Jones, Komminist Weldemariam |
AAAI | 9 |
| 2022 | Pattern detection in the activation space for identifying synthesized content
Celia Cintas, Skyler Speakman, Girmaw Abebe, Victor Akinwande, Edward McFowland, Komminist Weldemariam |
Pattern Recognit. Lett. | 6 |
| 2021 | Data-Driven Sequential Uptake Pattern Discovery for Family Planning Studies
Celia Cintas, Victor Akinwande, Ramya Raghavendra, Girmaw Abebe, Aisha Walcott-Bryant, Charity Wayua, Fredrick Makumbi, Rhoda Wanyenze, Komminist Weldemariam |
AMIA | 9 |
| 2021 | DeepMI: Deep multi-lead ECG fusion for identifying myocardial infarction and its occurrence-time
Girmaw Abebe, Hamza A. Javed, Komminist Weldemariam, Jiyan Chen, Tingting Zhu 0001 |
Artif. Intell. Medicine | 3 |
| 2020 | Identifying Factors Associated with Neonatal Mortality in Sub-Saharan Africa using Machine Learning
William Ogallo, Skyler Speakman, Victor Akinwande, Kush R. Varshney, Aisha Walcott-Bryant, Charity Wayua, Komminist Weldemariam, Claire-Helene Mershon, Nosa Orobaton |
AMIA | 7 |
| 2020 | Preservation of Anomalous Subgroups On Variational Autoencoder Transformed DataabstractWe investigate the effect of variational autoencoder (VAE) based data anonymization and its ability to preserve anomalous subgroup properties. We present a Utility Guaranteed Deep Privacy (UGDP) system which casts existing anomalous pattern detection methods as a new utility measure for data synthesis. UGDP's approach shows that properties of an anomalous subset of records, identified in the original data set, are preserved through the anonymization of a VAE. This is despite the newly generated records being completely synthetic. More specifically, the Bias-Scan algorithm identifies a subgroup of records that are consistently over- (or under-) risked by a black-box classifier as an area of 'poor fit'. This scanning process is applied on both pre- and post- VAE synthesized data. The areas of poor fit (i.e. anomalous records) persist in both settings. We evaluate our approach using publicly available datasets from the financial industry. Our evaluation confirmed that the approach is able to produce synthetic datasets that preserved a high level of subgroup differentiation as identified initially in the original dataset. Such a distinction was maintained while having distinctly different records between the synthetic and original dataset. Samuel C. Maina, Reginald E. Bryant, William Ogallo, Kush R. Varshney, Skyler Speakman, Celia Cintas, Aisha Walcott-Bryant, Robert-Florian Samoilescu, Komminist Weldemariam |
ICASSP | 9 |
| 2020 | Decision Platform for Pattern Discovery and Causal Effect Estimation in Contraceptive DiscontinuationabstractContraceptive use improves the health of women and children in several ways, yet data shows high rates of discontinuation which is not well understood. We introduce an AI-based decision platform capable of analyzing event data to identify patterns of contraceptive uptake that are unique to a subpopulation of interest. These discriminatory patterns provide valuable, interpretable insights to policy-makers. The sequences then serve as a hypothesis for downstream causal analysis to estimate the effect of specific variables on discontinuation outcomes. Our platform presents a way to visualize, stratify, compare, and perform a causal analysis on covariates that determine contraceptive uptake behavior, and yet is general enough to be extended to a variety of applications. Celia Cintas, Ramya Raghavendra, Victor Akinwande, Aisha Walcott-Bryant, Charity Wayua, Komminist Weldemariam |
IJCAI | 6 |
| 2020 | Detecting Adversarial Attacks via Subset Scanning of Autoencoder Activations and Reconstruction ErrorabstractReliably detecting attacks in a given set of inputs is of high practical relevance because of the vulnerability of neural networks to adversarial examples. These altered inputs create a security risk in applications with real-world consequences, such as self-driving cars, robotics and financial services. We propose an unsupervised method for detecting adversarial attacks in inner layers of autoencoder (AE) networks by maximizing a non-parametric measure of anomalous node activations. Previous work in this space has shown AE networks can detect anomalous images by thresholding the reconstruction error produced by the final layer. Furthermore, other detection methods rely on data augmentation or specialized training techniques which must be asserted before training time. In contrast, we use subset scanning methods from the anomalous pattern detection domain to enhance detection power without labeled examples of the noise, retraining or data augmentation methods. In addition to an anomalous “score” our proposed method also returns the subset of nodes within the AE network that contributed to that score. This will allow future work to pivot from detection to visualisation and explainability. Our scanning approach shows consistently higher detection power than existing detection methods across several adversarial noise models and a wide range of perturbation strengths. Celia Cintas, Skyler Speakman, Victor Akinwande, William Ogallo, Komminist Weldemariam, Srihari Sridharan, Edward McFowland |
IJCAI | 5 |
| 2020 | Inspection of Blackbox Models for Evaluating Vulnerability in Maternal, Newborn, and Child HealthabstractImproving maternal, newborn, and child health (MNCH) outcomes is a critical target for global sustainable development. Our research is centered on building predictive models, evaluating their interpretability, and generating actionable insights about the markers (features) and triggers (events) associated with vulnerability in MNCH. In this work, we demonstrate how a tool for inspecting "black box" machine learning models can be used to generate actionable insights from models trained on demographic health survey data to predict neonatal mortality. William Ogallo, Skyler Speakman, Victor Akinwande, Kush R. Varshney, Aisha Walcott-Bryant, Charity Wayua, Komminist Weldemariam |
IJCAI | 7 |
| 2020 | Discriminant Knowledge Extraction from Electrocardiograms for Automated Diagnosis of Myocardial Infarction
Girmaw Abebe, Komminist Weldemariam, Hamza A. Javed, Jiyan Chen, Tingting Zhu 0001 |
PKAW | 2 |
| 2017 | Towards Blockchain-enabled School Information HubabstractSeveral initiatives have been proposed to collect, report, and analyze data about school systems for supporting decision-making. These initiatives rely mostly on self-reported and summarized data collected irregularly and rarely. They also lack a single independent and systematic process to validate the collected data during its entire lifecycle. Furthermore, schools in developing countries still do not maintain complete and up-to-date school records. Due to these and other factors addressing the education challenges in those countries remains a high priority for local and international governments, donor and non-governmental agencies across the world. In this paper, we discuss our initial design, implementation, and evaluation of a blockchain-enabled School Information Hub (SIH) using Kenya's school system as a case study. Nelson Bore, Samuel Karumba, Juliet Mutahi, Shelby Solomon Darnell, Charity Wayua, Komminist Weldemariam |
ICTD | 6 |
| 2017 | Studying engagement and performance with learning technology in an African classroomabstractIn this paper, we study the engagement and performance of students in a classroom using a system the Cognitive Learning Companion (CLC). CLC is designed to keep track of the relationship between the student, content interaction and learning progression. It also provides evidence-based engagement-oriented actionable insights to teachers by assessing information from a sensor-rich instrumented learning environment in order to infer a learner's cognitive and affective states. Data captured from the instrumented environment is aggregated and analyzed to create interlinked insights helping teachers identify how students engage with learning content and view their performance records on selected assignments. We conducted a 1 month pilot with 27 learners in a primary school in Nairobi, Kenya during their maths and science instructional periods. We present our primary analysis of content-level interactions and engagement at the individual student and classroom level. Juliet Mutahi, Andrew Kinai, Nelson Bore, Abdigani Diriye, Komminist Weldemariam |
LAK | 5 |
| 2017 | Modeling user behavior data in systems of engagement
Oliver Bent, Komminist Weldemariam, Mukesh K. Mohania |
Future Gener. Comput. Syst. | 3 |
| 2015 | FPGuard: Detection and Prevention of Browser Fingerprinting
Amin FaizKhademi, Mohammad Zulkernine, Komminist Weldemariam |
DBSec | 3 |
| 2015 | Towards Capturing Learners Sentiment and ContextabstractWe report on the motivation and qualitative studies that examine the design of a sentiment and context collection tool in a mobile-enabled blended learning technology. The tool concept emerged from field studies with teachers and students from two primary schools in Kenya. In this paper, we discuss the background and motivation of learners sentiment and context. Next, we present the overall design of the proposed module and its prototype implementation in a blended learning environment. Detailed discussions on the algorithms underlying the tool are beyond the scope of this paper. Jaye Clarkes-Nias, Juliet Mutahi, Andrew Kinai, Oliver Bent, Komminist Weldemariam |
L@S | 5 |
| 2014 | TabsGuard: A Hybrid Approach to Detect and Prevent Tabnabbing Attacks
Hana Fahim-Hashemi, Mohammad Zulkernine, Komminist Weldemariam |
CRiSIS | 3 |
| 2014 | From Needs to Services: Delivering Personalized Water Assurance Services in Urban Africa
Kala Fleming, Komminist Weldemariam |
ER | 2 |
| 2014 | Some Issues in Modeling User Behavior Data in Systems of Engagement
Mukesh K. Mohania, Komminist Weldemariam |
MEDI | 3 |
| 2014 | Dynamic Analysis of Web ObjectsabstractVarious reports show that web browsers are known for being insecure, with growing amount of flaws that make them vulnerable to various attacks. Such attacks can be used to execute arbitrary procedures on the victims' computer and silently install malicious software, turning them into bots. In addition, browsers are complex and typically incorporate third-party libraries installed on-demand. This makes it very difficult for security experts to analyze the causes of such flaws or devise countermeasures. In this paper, we present an approach to detect and prevent attacks against a browser by intercepting the interactions between its core libraries and the underlying operating system. We then build mathematical models that capture the behavior of the browser during the rendering of web objects. Finally, we show that such models can be leveraged to automatically classify web objects as malicious or benign using real-world malicious websites. Komminist Weldemariam, Hossain Shahriar, Vamshee Krishna Devendran |
SIN | 1 |
| 2014 | Effective detection of vulnerable and malicious browser extensions
Hossain Shahriar, Komminist Weldemariam, Mohammad Zulkernine, Thibaud Lutellier |
Comput. Secur. | 2 |
| 2013 | EINSPECT: Evolution-Guided Analysis and Detection of Malicious Web PagesabstractMost existing work to thwart malicious web pages capture maliciousness via discriminative artifacts, learn a model, and detect by leveraging static and/or dynamic analysis. Unfortunately, there is a two-sided evolution of the artifacts of web pages. On one hand, cybercriminals constantly revamp attack payloads in malicious web pages. On the other hand, benign web pages evolve to improve content rendering and interaction with users. Consequently, the onceprecise detection techniques suffer from limitations to cope with the evolution, resulting in malicious web pages that escape detection. In this paper, we present EINSPECT, an evolution-aware and learning-based approach to address evolution of web page artifacts to more precisely analyze and detect malicious web pages. EINSPECT continuously tunes its detection models to automatically decide the best interplay of features and learning algorithms to embrace the evolution of web page artifacts into the analysis and detection. We have implemented and evaluated our approach and the results show that EINSPECT is able to improve the effectiveness of analysis and detection ofmalicious web pages while aligning the detection models with the continuous evolution of web page artifacts. Birhanu Eshete, Adolfo Villafiorita, Komminist Weldemariam, Mohammad Zulkernine |
COMPSAC | 3 |
| 2013 | Protecting Web Browser Extensions from JavaScript Injection AttacksabstractVulnerable web browser extensions can be used by an attacker to steal users' credentials and lure users into leaking sensitive information to unauthorized parties. Current browser security models and existing JavaScript security solutions are inadequate for preventing JavaScript injection attacks that can exploit such vulnerable extensions. In this paper, we present a runtime protection mechanism based on a code randomization technique coupled with a static analysis technique to protect browser extensions from JavaScript injection attacks. The protection is enforced at runtime by distinguishing malicious code from the randomized extension code. We implemented our protection mechanism for the Mozilla Firefox browser and evaluated it on a set of vulnerable and non-vulnerable Firefox extensions. The evaluation results indicate that our approach can be a viable solution for preventing attacks on JavaScript-based browser extensions. In designing and implementing our approach, we were also able to reduce false positives and achieve maximum backward compatibility with existing extensions. Anton Barua, Mohammad Zulkernine, Komminist Weldemariam |
ICECCS | 3 |
| 2012 | Understanding the Development Trends of Electronic Voting SystemsabstractDuring the past few years a huge interests in e-voting has occurred, which resulted in a significant funding for e-voting research and development (R&D) projects with the aim of developing trustworthy e-voting systems. Although it is good that major e-voting development trends are capitalizing on previous R&D efforts in other domains, it is difficult to say that the necessary R&D efforts has been utilized to realize the vision and principles of e-voting. Today, we now have a much better understanding of the issues that pose the development of a trustworthy e-voting system. In this paper, we categorize and analyze the most important research and development trends in e-voting systems. We identify the lessons learned from these projects and analyze whether the existing R&D projects meet the identified flaws in past. Finally, based on these results the way to the future of e-voting R&D is postulated. Ali Fawzi Najm Al-Shammari, Adolfo Villafiorita, Komminist Weldemariam |
ARES | 3 |
| 2012 | Towards an Open Standard Vote Verification Framework in Electronic Voting SystemsabstractVote verification allows voters or other election participating entities to verify that votes are correctly captured, stored and counted. To facilitate the vote verification process, a number of verification techniques (either physical or digital) have been developed to provide an evidence to voters and other participating entities for the assurance of the integrity of election result. However, we observed that these techniques have a number of limitations among which, the fact that the existing techniques do not fully comply with verification requirements (e.g., public verifiability). They implement limited prevention mechanisms from known attacks and they are not based on interoperable components and processes (typically, vendor lock-in). In order to address these issues, we propose a new method for vote verification based on open standards which allows interested parties or organizations to participate in vote verification process so as to enhance transparency and capture vote threats and challenges during and after elections. Ali Fawzi Najm Al-Shammari, Adolfo Villafiorita, Komminist Weldemariam |
ARES | 3 |
| 2012 | On the use of goal-oriented methodology for designing agriculture services in developing countriesabstractAccess to agricultural information services is vital to improve the livelihood of farmers in many directions specifically in the developing countries. There are several requirements for these services most of which stem from the nature and livelihood of involved stakeholders. Though various systems have been put to use so far, most failed to integrate these stakeholders in their requirement elicitation and design strategies. This paper uses a goal-oriented approach to provide an exhaustive view on the domain from specific design ideas to abstract requirements. The approach allows us to consider alternatives when developing novel services and to balance the impact that each design space can have on functional requirements of the system to-be. The analysis and design process took a bottom-up approach that starts from field study to the use of goal-oriented approach for the analysis and designing of requirements for the system to-be. Amanuel Zewge, Komminist Weldemariam, Sebsibe Hailemariam, Adolfo Villafiorita, Angelo Susi, Mesfin Belachew |
MEDES | 2 |
| 2012 | BINSPECT: Holistic Analysis and Detection of Malicious Web Pages
Birhanu Eshete, Adolfo Villafiorita, Komminist Weldemariam |
SecureComm | 3 |
| 2011 | Early Detection of Security Misconfiguration Vulnerabilities in Web ApplicationsabstractThis paper presents a web-based tool to supplement defense against security misconfiguration vulnerabilities in web applications. The tool automatically audits security configuration settings of server environments in web application development and deployment. It also offers features to automatically adjust security configuration settings and quantitatively rates level of safety for server environments before deploying web applications. Using the tool, we were able to evaluate eleven server packages for Apache, PHP and MySQL across three operating system platforms. Our evaluation revealed that the tool is able to audit current security configuration settings and alert users to fix the server environment to achieve the level of safety of security configuration with respect to recommended configurations for real-life web application deployment. Birhanu Eshete, Adolfo Villafiorita, Komminist Weldemariam |
ARES | 3 |
| 2011 | Formal analysis of an electronic voting system: An experience report
Komminist Weldemariam, Richard A. Kemmerer, Adolfo Villafiorita |
J. Syst. Softw. | 1 |
| 2011 | Procedural security analysis: A methodological approach
Komminist Weldemariam, Adolfo Villafiorita |
J. Syst. Softw. | 1 |
| 2010 | Formal Specification and Analysis of an E-voting SystemabstractElectronic voting systems are a perfect example of security-critical computing. One of the critical and complex parts of such systems is the voting process, which is responsible for correctly and securely storing intentions and actions of the voters. Unfortunately, recent studies revealed that various e-voting systems show serious specification, design, and implementation flaws. The application of formal specification and verification can greatly help to better understand the system requirements of e-voting systems by thoroughly specifying and analyzing the underlying assumptions and the security specific properties.This paper presents the specification and verification of the electronic voting process for the Election Systems & Software (ES&S) system. We used the ASTRAL language to specify the voting process of ES&S machines and the critical security requirements for the system. Proof obligations that verify that the specified system meets the critical requirements were automatically generated by the ASTRAL Software Development Environment (SDE). The PVS interactive theorem prover was then used to apply the appropriate proof strategies and discharge the proof obligations. Komminist Weldemariam, Richard A. Kemmerer, Adolfo Villafiorita |
ARES | 1 |
| 2010 | Host-based anomaly detection for pervasive medical systemsabstractIntrusion detection systems are deployed on hosts in a computing infrastructure to tackle undesired events in the course of usage of the systems. One of the promising domains of applying intrusion detection is the healthcare domain. A typical healthcare scenario is characterized by high degree of mobility, frequent interruptions and above all demands access to sensitive medical records by concerned stakeholders. Migrating this set of concerns in pervasive healthcare environments where the traditional characteristics are more intensified in terms of uncertainty, one ends up with more challenges on security due to nature of pervasive devices and wireless communication media along with classic security problems for desktop based systems. Despite evolution of automated healthcare services and sophistication of attacks against such services, there is a reasonable lack of techniques, tools and experimental setups for protecting hosts against intrusive actions. This paper presents a contribution to provide a host-based, anomaly modeling and detection approach based on data mining techniques for pervasive healthcare systems. The technique maintains normal usage profile of pervasive healthcare applications and inspects current workflow against normal usage profile so as to classify it as anomalous or normal. The technique is implemented as a prototype with sample data set and the results obtained revealed that the technique is able to perform classification of anomalous activities. Biniyam Asfaw, Dawit Bekele, Birhanu Eshete, Adolfo Villafiorita, Komminist Weldemariam |
CRiSIS | 5 |
| 2010 | Context Information Refinement for Pervasive Medical SystemsabstractEmerging technologies like mobile and wireless communication are offering promising opportunities to enable mobile healthcare delivery to citizens. But, enhancing the quality of service of such systems demands systematic improvement of existing service infrastructure. In this paper, we describe a context information refinement architecture proposed to address the shortcomings of existing works in relation to context information refinement in pervasive medical systems. The shortcomings are lack of adequate consideration for: quality parameters of context information, relevance of context information and particular requirements of the pervasive healthcare domain. The proposed architecture facilitates and coordinates the refinement of context information starting from acquisition of context information up until the refined context information is delivered to the target application in a pervasive medical system. We developed a prototype that implements the core components of the proposed architecture and evaluated it with real-life pervasive healthcare scenario and proved the validity of the architecture using a real-life scenario. Dawit Bekele, Birhanu Eshete, Adolfo Villafiorita, Komminist Weldemariam |
ICDS | 4 |
| 2010 | ICT for Good: Opportunities, Challenges and the Way ForwardabstractICT seems well understood as a tool and an infrastructure for delivering information and services for the society and for allowing communications through interactions among the service users -mostly, the digital society. Using ICT for ensuring better life requires far more than good infrastructure, ICT know-how and the various techniques and tools in place. If ICT has to address the real problems of the society, it should be at a rescue being environment-friendly, with real and tangible impact, sustainable, seamless, down to the grass-roots and above all with reproducible experiences. In this paper, we introduce a different perspective of looking into and using ICT, which we call ICT for Good (ICT4G). It is about using ICT for addressing problems of societies with low ICT penetration and changing a society's life for the better. More specifically, based on our observation of current promises ICT gives to society, we discuss ICT4G's distinguishing aspects, opportunities it offers, challenges it imposes along with preliminary roadmap for its realization. A high-level correlation of what we pointed out with a relevant case study (i.e., the eGIF4M1) is presented. Birhanu Eshete, Andrea Mattioli 0001, Adolfo Villafiorita, Komminist Weldemariam |
ICDS | 4 |
| 2010 | Modeling and Analysis of Laws Using BPR and Goal-Oriented FrameworkabstractRecently, two complementary approaches are proposed to represent, model, and analyze laws: the Nomos and VLPM approaches. Nomos is a goal-oriented approach to effectively capture high-level principles in terms of goal realization for requirements guided by satisfiability of normative propositions obtained from rules embedded in a law. The latter offers a tool supported (re-)engineering methodology to extract laws represented in XML and build models using a subset of UML diagrams. Both allow traceability between laws and their respective models. This paper proposes an integration of these two approaches. We believe that this provides a framework that allows to trace and reason either top-down, from principles to their implementation or, viceversa, bottom-up, from a change in the procedure to the principles. It is exactly this connection that adds value to the solution we propose and makes our approach more significant than a simple juxtaposition of the two techniques. Adolfo Villafiorita, Komminist Weldemariam, Angelo Susi, Alberto Siena |
ICDS | 2 |
| 2009 | Formal analysis of attacks for e-voting systemabstractRecently, the use of formal methods to specify and verify properties of electronic voting (e-voting) systems, with particular interest in security, verifiability, and anonymity, is getting much attention. Formal specification and verification of such systems can greatly help to better understand the system requirements by thoroughly specifying and analyzing the underlying assumptions and security specific properties. Unfortunately, even though these systems have been formally verified to satisfy the desired system security requirements, they are still vulnerable to attack. In this paper we extend a formal specification of the ES&S voting system by specifying attacks that have been shown to successfully compromise the system. We believe that performing such analysis is important for two reasons: first, it allows us to discover some missing critical requirements for the specification and/or assumptions that were not met Second, it allows us to derive mitigation or counter-measure strategies when the system behaves differently than it should. We used the ASTRAL language for the specification, and the verification is performed using the PVS tool. Komminist Weldemariam, Richard A. Kemmerer, Adolfo Villafiorita |
CRiSIS | 1 |
| 2009 | Experiments and data analysis of electronic voting systemabstractExperimental data sets related to e-voting systems are very demanding in order to improve currently deployed e-voting machines. Unfortunately, the studies of such data about the machines' security, performance and their evolution with respect to the social and technical aspects are still unsatisfactory. During the last four years we have been involved in the development, experimentation, and evaluation of an e-voting system. The system tried out in several regular elections, and also used in two small elections with legal value. Each experiment provided various sociological (e.g. citizens' opinions on the system) and technical data that are related to system's performance and behavior. In this paper, we present various technical insights and the lessons learned during the e-voting experiment. The methodology for the various experiments we have carried-out and the data sets collection process are also discussed. This helps to confirm existing data on the subject (e.g., data related to security, procedures and logistics) and, in some cases, provide novel information or, at least, shed a new perspective on some security-critical factors concerning e-voting systems. Komminist Weldemariam, Adolfo Villafiorita, Andrea Mattioli 0001 |
CRiSIS | 1 |
| 2009 | Development, formal verification, and evaluation of an E-voting system with VVPATabstractThe use of new technologies to support voting has been and is the subject of great debate. Several people advocate the benefits it can bring-such as improved speed and accuracy in counting, accessibility, voting from home-and as many are concerned with the risks it poses, such as unequal access (digital divide), violation to secrecy and anonymity, alteration of the results of an election (because of malicious attacks, bad design/coding, or procedural weaknesses). The attitude of different governments towards electronic voting (e-voting) varies accordingly. In this paper, we present the activities related to the development and formal verification of an e-voting system, called ProVotE. ProVotE is an end-to-end e-voting system with a voter verified paper audit trial, developed within the framework of a larger initiative whose goal is assessing the feasibility of introducing e-voting in the Autonomous Province of Trento. ProVotE has been used in trials and elections with legal value in Italy. What we believe to be of interest is the approach we took for its development, which has been based on a participatory design for the definition of the voter interface, on the usage of formal methods and model checking for the validation of the core logic of the machine, on open source components, and on the formal analysis of some critical procedures related to the usage of the machine during the election. Adolfo Villafiorita, Komminist Weldemariam, Roberto Tiella |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2008 | Formal procedural security modeling and analysisabstractWe are involved in a project related to the evaluation and possible introduction of e-voting for elections held in the Autonomous Province of Trento. One of the goals of the project is defining the laws and the procedures that will regulate e-voting and guarantee the same or an higher level of security than the traditional, paper-based, elections. To do so, we are tackling the problem (also) at the procedural level, namely, we are trying to understand weaknesses and strengths of the procedures regulating elections in Italy, in order to analyze possible attacks and their effects. The analyzes are based on formal specifications of the procedures and on model checkers to help us derive possible attacks. We believe the approach to be useful to help us systematically identifying the limits of the current procedures (i.e. under what hypotheses attacks are undetectable) and, consequently, to state more precisely under what hypotheses and conditions we can guarantee reasonably secure elections. Komminist Weldemariam, Adolfo Villafiorita |
CRiSIS | 1 |