EDBT 2026 Demo / reviewers in the wild / expert
Irfan Ahmed 0001
dblp:76/5790-1
· DBLP profile ↗
26ranked-venue papers
7as first author
7since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 7 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 3Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Sabotaging Material Extrusion-Based 3D Printed Parts through Low-Magnitude Kinetic Manipulation AttacksabstractThe increasing ubiquity of material-extrusion-based additive manufacturing is motivating cybersecurity researchers to explore its offensive and defensive landscape. Being a physical system, 3D printers have non-zero tolerance specifications for precision and trueness parameters. While a single-bit change in a digital data file is sufficient to fail its integrity and is easily detected through methods such as hashing, the printing process (and subsequently the printed object) remains compliant within the tolerance zone. This study systematically analyzes the material extrusion process and identifies four attack opportunities where low-magnitude kinetic cyberattacks exploit the physical process compliance zone to sabotage the printed part’s mechanical properties. The attacks are demonstrated on ASTM-compliant tensile and flexure bars through a man-in-the-middle attack scenario by hijacking the network layer communication between the 3D printer and the printer control machine. The physically stealthy attacks did not produce any evident deformation in the parts’ dimensions and mass, while the destructive tests confirm that they are still effective in modifying the tensile and bending strength by up to 25%. The effectiveness of the attacks in bypassing the defenses is assessed by implementing one of the leading detection schemes described in the current literature. The attacks were either not detected at all or detected with a significantly high false negative rate at various attack magnitudes. Muhammad Haris Rais, Irfan Ahmed 0001 |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2024 | BioSaFe: Bioprinting Security Framework for Detecting Sabotage Attacks on Printability and Cell ViabilityabstractAdditive manufacturing (aka, 3D printing) is increasingly used in bioprinting to create objects layer by layer from ground zero. As research and development progress in bioprinting technology for medical applications, ensuring the security of 3D bioprinters against adversarial attempts becomes critical. This paper proposes six novel sabotage attacks on two types of bioprint constructs as case studies, i.e., a multilayered square box and a human ear, to show that attackers can deliberately manipulate the bioprinting process to sabotage a bioprinted construct. We use quality assurance metrics, i.e., printability and cell viability, to demonstrate the impact of these attacks on the printed constructs. Furthermore, this paper introduces BioSaFe, a bioprinting security framework for real-time monitoring of critical printing parameters per-layer basis, including nozzle temperature, layer thickness, UV curing, HEPA filter status, print geometry, and print speed. BioSaFe employs spatiotemporal modeling and interpolation functions to compare in-situ sensing data with a reference G-code file (being used for printing) in both space and time domains. This direct comparison does not require a training phase on printed objects and enables BioSaFe to start monitoring from the first printing job, supporting Industry 4.0 for mass customization. Our evaluation results show that BioSaFe can accurately detect our sabotage attacks, demonstrating its potential in safeguarding bioprinting processes. Eunice Pak, Kate Jackson, Muhammad Haris Rais, Barry Najarro-Blancas, Nastassja Lewinski, Irfan Ahmed 0001 |
ACSAC | 7 |
| 2024 | PATCH: Problem-Based Learning Approach for Teaching Cybersecurity and Ethical Hacking in Community CollegesabstractCybersecurity education incorporates a variety of teaching methods such as traditional lectures, lectures combined with hands-on exercises, and concept maps. One of the most well-known instructional methods is the use of lectures supplemented by hands-on activities. However, often these exercises either lack a strong connect with the lecture material or invariably lead students step-by-step in predetermined tasks, thereby hindering critical thinking and problem-solving skills. Hence, the instructional method falls short on providing students with a comprehensive understanding of complex and often associated cybersecurity concepts as encountered in real-world security incidents. The authors propose that a problem-based learning (PBL) approach can effectively address these gaps and improve cybersecurity education learning outcomes. This paper presents an application of PBL approach for teaching cybersecurity and ethical hacking in community colleges that play a crucial role in meeting the demand for cybersecurity professionals, but often face several challenges to effectively introduce cybersecurity concepts in their curriculum. Through this research, an existing course on ethical hacking is redesigned using the PBL pedagogy and offered to community college students. The course involves several PBL modules that are developed to cover all key aspects of ethical hacking and implemented using open-source software's. Each PBL module is based on a real-world cybersecurity incident and mapped to the MITRE ATT&CK framework. An external independent evaluation is conducted to assess the effectiveness of the proposed teaching methodology. Overall, the obtained results positively impact students' critical thinking, problem-solving, and communication skills, along with facilitating their understanding of key cybersecurity concepts. 100% of students reported that they enjoyed the PBL exercises. 75% of the students believed that PBL enhanced their learning of key concepts to a great extent, and remaining 25% believed that their learning of key concepts was somewhat enhanced. Sajal Bhatia, Saaid Elhadad, Irfan Ahmed 0001 |
SIN | 3 |
| 2024 | LAAKA: Lightweight Anonymous Authentication and Key Agreement Scheme for Secure Fog-Driven IoT Systems
Hala S. Ali, Irfan Ahmed 0001 |
Comput. Secur. | 2 |
| 2023 | SOK: Side Channel Monitoring for Additive Manufacturing - Bridging Cybersecurity and Quality Assurance CommunitiesabstractAdditive Manufacturing (AM) is critical for the fourth industrial revolution (i.e., Industry 4.0). It involves printing a 3D object layer-by-layer from scratch. Fused filament fabrication (FFF), one of the most widely used AM technology, has been adopted by commercial and domestic consumers. With the recent addition of metal filaments, FFF caters to a broad spectrum of manufacturing industry requirements. Cybersecurity and Quality Assurance (QA) of the FFF process is an active research area. Like any other cyber-physical system, FFF exhibits many side channels (SCs), including acoustic and thermal emissions, vibrations, etc. Researchers in the QA domain use SCs to predict defects in the printed parts. Cybersecurity researchers, on the other hand, utilize SCs to identify malicious anomalies in the process. While the aims are different, there are definite overlaps in both communities’ acquisition and analysis methodologies. As the two communities bring distinct skill sets and expertise, we find an opportunity to bring them closer through a systematic study of available work and identifying the commonalities and distinctions to motivate the consumption of cross-domain knowledge. Our approach to systematizing the knowledge is based on identifying the available SC, the acquisition and analysis methodologies, performance statistics, associated challenges, and future research directions. This knowledge consolidation and systematization exercise will not only help the new researchers aiming to explore SCs in the FFF process but also highlight collaboration opportunities between QA and cybersecurity communities. Muhammad Haris Rais, Irfan Ahmed 0001 |
EuroS&P | 3 |
| 2023 | SWMAT: Mel-frequency cepstral coefficients-based memory fingerprinting for IoT devicesabstractThe increasing sophistication in computing capability and sensing technologies have continued to drive the design, development, and growth of the smart technologies commonly known as the IoTs. Nonetheless, the rise and spread of malware in this ecosystem is a pressing societal concern that requires immediate attention. In this paper, we propose a novel technique called Sound Wave Memory Analysis Technique (SWMAT), for fingerprinting IoT devices by converting their dynamic memory traces into sound wave signals using a lossless transformation function from which a unique set of determinable features called Mel Frequency Cepstral Coefficients (MFCCs) are extracted. The overarching objective of this research is to explore offline the effectiveness of using features from memory-encoded sound wave signals for fingerprinting and detecting abnormal changes in IoT devices, which potentially can provide an excellent technique for an on-device Host-Based Intrusion Detection System. Our SWMAT scores the similarity between two sequences of MFCCs using a Dynamic Time Warping distance measure . To evaluate our approach, we developed multiple IoT testbeds and generated 125 MFCC sequences from 20 benign and 5 infected IoT applications . Our results showed that the MFCC features, when leveraged as fingerprints for both Intra and Inter-app similarity, can uniquely distinguish an IoT process and can detect when an IoT process has been hijacked and/or is modified by another malicious code . Furthermore, this empirical result shows our technique’s similarity detection accuracy to be ≈ 95%. Ramyapandian Vijayakanthan, Irfan Ahmed 0001, Aisha I. Ali-Gombe |
Comput. Secur. | 2 |
| 2022 | Transforming Memory Image to Sound Wave Signals for an Effective IoT FingerprintingabstractAs the need and adaptation for smart environments continue to rise, owing mainly to the evolution in IoT technology's processing and sensing capabilities, the security community must contend with increasing attack surfaces on our network, critical systems, and infrastructures. Thus, developing an effective fingerprint to deal with some of these threats is of paramount importance. As such, in this paper, we explored the use of memory snapshots for effective dynamic process-level fingerprints. Our technique transforms a memory snapshot into a sound wave signal, from which we then retrieve their distinctive Mel-Frequency Cepstral Coefficients (MFCC) features as unique process-level identifiers. The evaluation of this proposed technique on our dataset demonstrated that MFCC-based fingerprints generated from the same IoT process memory at different times exhibit much stronger similarities than those acquired from different IoT process spaces. Ramyapandian Vijayakanthan, Irfan Ahmed 0001, Aisha I. Ali-Gombe |
CODASPY | 2 |
| 2019 | Overshadow PLC to Detect Remote Control-Logic Injection Attacks
Hyunguk Yoo, Sushma Kalle, Jared Smith, Irfan Ahmed 0001 |
DIMVA | 4 |
| 2019 | Automated Reconstruction of Control Logic for Programmable Logic Controller Forensics
Syed Ali Qasim, Juan Lopez Jr., Irfan Ahmed 0001 |
ISC | 3 |
| 2019 | Control Logic Injection Attacks on Industrial Control Systems
Hyunguk Yoo, Irfan Ahmed 0001 |
SEC | 2 |
| 2019 | Topological Scoring of Concept Maps for Cybersecurity EducationabstractConcept maps are a well-known pedagogical tool for organizing and representing knowledge and developing a deep understanding of concepts. Unfortunately, the grading of concept maps tends to be manual and tedious thereby, posing serious limitation for an instructor to use them in class efficiently. To automate the assessment and grading, the topology and structural features of concept maps are utilized. However, they have never been explored for cybersecurity education. This paper evaluates the effectiveness of topological scoring of the concept maps for two cybersecurity courses: digital forensics, and SCADA system security. We create a dataset of 41 high-quality concept maps developed with expert knowledge. We utilize waterloo rubric to manually validate the quality of the concept maps based-on their contents and further compare the rubric outcome (obtained via manual analysis) with the automated topological scoring of the maps. The evaluation results show that the topological scoring is promising. However, it is not equally effective and warrants for advanced techniques to better utilize the topology of the maps. The dataset is made publicly available for further research on this topic. Pranita Deshpande, Irfan Ahmed 0001 |
SIGCSE | 2 |
| 2019 | Evaluation of Peer Instruction for Cybersecurity EducationabstractPeer instruction pedagogy is a student-centric approach that encourages students to read lecture material before coming to class and engages them in class via group discussion and preplanned conceptual questions. Peer instruction has shown promising results in core computer science courses such as Theory of Computation and Computer Architecture, as well as reducing failure rates and improving student retention in computer science major. This paper presents the results of the first-ever attempt to replicate these results in a cybersecurity course, using an action research methodology to implement and evaluate peer instruction in a semester-long cybersecurity course, Introduction to Computer Security. The evaluation consists of quizzes, subjective exams, peer instruction questions, and attitudinal surveys gathered over two control semesters and one peer instruction condition semester. We find evidence of learning gains during group discussion and improvements in dropout and failure rates compared to traditional lecture classes. In attitudinal surveys, most students report that they would recommend that other instructors use peer instruction. Pranita Deshpande, Cynthia Bailey, Irfan Ahmed 0001 |
SIGCSE | 3 |
| 2018 | Denial of Engineering Operations Attacks in Industrial Control SystemsabstractWe present a new type of attack termed denial of engineering operations in which an attacker can interfere with the normal cycle of an engineering operation leading to a loss of situational awareness. Specifically, the attacker can deceive the engineering software during attempts to retrieve the ladder logic program from a programmable logic controller (PLC) by manipulating the ladder logic on the PLC, such that the software is unable to process it while the PLC continues to execute it successfully. This attack vector can provide sufficient cover for the attacker»s actual scenario to play out while the owner tries to understand the problem and reestablish positive operational control. To enable the forensic analysis and, eventually, eliminate the threat, we have developed the first decompiler for ladder logic programs. Saranyan Senthivel, Shrey Dhungana, Hyunguk Yoo, Irfan Ahmed 0001, Vassil Roussev |
CODASPY | 4 |
| 2018 | Using Virtual Machine Introspection for Operating Systems Security EducationabstractHistorically, hands-on cybersecurity exercises helped reinforce the basic cybersecurity concepts. However, most of them focused on the user level attacks and defenses and did not provide a convenient way of studying the kernel level security. Since OS kernels provide foundations for applications, any compromise to OS kernels will lead to a computer that cannot be trusted. Moreover, there has been a great interest in using virtualization to profile, characterize, and observe kernel events including security incidents. Virtual Machine Introspection (VMI) is a technique that has been deeply investigated in intrusion detection, malware analysis, and memory forensics. Inspired by the great success of VMI, we used it to develop hands-on labs for teaching kernel level security. In this work, we present three VMI-based labs on (1) stack-based buffer over-flow, (2) direct kernel object manipulation (DKOM), and (3) kernel integrity checker which have been made available online. Then, we analyze the differences in approaches taken by VMI-based labs and traditional labs and conclude that VMI-based labs are better as opposed to traditional labs from a teaching standpoint because they provide more visibility than the traditional labs and superior ability to manipulate kernel memory which provides more insight into kernel security concepts. Manish Bhatt, Irfan Ahmed 0001, Zhiqiang Lin 0001 |
SIGCSE | 2 |
| 2016 | AspectDroid: Android App Analysis SystemabstractThe growing threat to user privacy related to Android applications (apps) has tremendously increased the need for more reliable and accessible app analysis systems. This paper presents AspectDroid, an application-level system designed to investigate Android applications for possible unwanted activities. AspectDroid is comprised of app instrumentation, automated testing and containment systems. By using static bytecode instrumentation, The growing threat to user privacy related to Android applications (apps) has tremendously increased the need for more reliable and accessible app analysis systems. This paper presents AspectDroid, an application-level system designed to investigate Android applications for possible unwanted activities. AspectDroid is comprised of app instrumentation, automated testing and containment systems. By using static bytecode instrumentation, AspectDroid weaves monitoring code into an existing application and provides data flow and sensitive API usage as well as dynamic instrumentation capabilities. The newly repackaged app is then executed either manually or via an automated testing module. Finally, the flexible containment provided by AspectDroid adds a layer of protection so that malicious activities can be prevented from affecting other devices. The accuracy score of AspectDroid when tested on 105 DroidBench corpus shows it can detect tagged data with 95.29\%. We further tested our system on 100 real malware families from the Drebin dataset \cite{drebin2014}. The result of our analysis showed AspectDroid incurs approximately 1MB average total memory size overhead and 5.9\% average increase in CPU-usage. Aisha I. Ali-Gombe, Irfan Ahmed 0001, Golden G. Richard III, Vassil Roussev |
CODASPY | 2 |
| 2016 | SPICE: A Software Tool for Bridging the Gap Between End-user's Insecure Cyber Behavior and Personality TraitsabstractEnd users are prone to insecure cyber behavior that may lead them to compromise the integrity, availability or confidentiality of their computer systems. For instance, replying to a phishing email may compromise an end user's login credentials. Identifying tendency toward insecure cyber behavior is critically important to improve cyber security posture and thesis of this paper is that the susceptibility of end-users to be a victim of a cyber-attack may be predicted using personality traits such as trait anxiety and callousness. Anjila Tamrakar, Justin D. Russell, Irfan Ahmed 0001, Golden G. Richard III, Carl F. Weems |
CODASPY | 3 |
| 2016 | API-Based Forensic Acquisition of Cloud Drives
Vassil Roussev, Andres Barreto, Irfan Ahmed 0001 |
IFIP Int. Conf. Digital Forensics | 3 |
| 2016 | Don't Touch that Column: Portable, Fine-Grained Access Control for Android's Native Content ProvidersabstractAndroid applications access native SQLite databases through their Universal Resource Identifiers (URIs), exposed by the Content provider library. By design, the SQLite engine used in the Android system does not enforce access restrictions on database content nor does it log database accesses. Instead, Android enforces read and write permissions on the native providers through which databases are accessed via the mandatory applications permissions system. This system is very coarse grained, however, and can allow applications far greater access to sensitive data than a user might intend. Aisha I. Ali-Gombe, Golden G. Richard III, Irfan Ahmed 0001, Vassil Roussev |
WISEC | 3 |
| 2015 | Robust Fingerprinting for Relocatable CodeabstractRobust fingerprinting of executable code contained in a memory image is a prerequisite for a large number of security and forensic applications, especially in a cloud environment. Prior state of the art has focused specifically on identifying kernel versions by means of complex differential analysis of several aspects of the kernel code implementation. Irfan Ahmed 0001, Vassil Roussev, Aisha I. Ali-Gombe |
CODASPY | 1 |
| 2013 | Rule-Based Integrity Checking of Interrupt Descriptor Tables in Cloud Environments
Irfan Ahmed 0001, Aleksandar Zoranic, Salman Javaid, Golden G. Richard III, Vassil Roussev |
IFIP Int. Conf. Digital Forensics | 1 |
| 2013 | Integrity Checking of Function Pointers in Kernel Pools via Virtual Machine Introspection
Irfan Ahmed 0001, Golden G. Richard III, Aleksandar Zoranic, Vassil Roussev |
ISC | 1 |
| 2011 | Fast Content-Based File Type Identification
Irfan Ahmed 0001, Kyung-suk Lhee, Hyunjung Shin |
IFIP Int. Conf. Digital Forensics | 1 |
| 2011 | User-representative feature selection for keystroke dynamicsabstractContinuous user authentication with keystroke dynamics uses characters sequences as features. Since users can type characters in any order, it is imperative to find character sequences (n-graphs) that are representative of user typing behavior. The contemporary feature selection approaches do not guarantee selecting frequently-typed features which may cause less accurate statistical user-representation. Furthermore, the selected features do not inherently reflect user typing behavior. We propose four statistical-based feature selection techniques that mitigate limitations of existing approaches. The first technique selects the most frequently occurring features. The other three consider different user typing behaviors by selecting: n-graphs that are typed quickly; n-graphs that are typed with consistent time; and n-graphs that have large time variance among users. We use Gunetti's keystroke dataset and k-means clustering algorithm for our experiments. The results show that among the proposed techniques, the most-frequent feature selection technique can effectively find user-representative features. We further substantiate our results by comparing the most-frequent feature selection technique with three existing approaches (popular Italian words, common n-graphs, and least frequent n-graphs). We find that it performs better than the existing approaches after selecting a certain number of most-frequent n-graphs. Eesa Alsolami, Colin Boyd, Andrew J. Clark, Irfan Ahmed 0001 |
NSS | 4 |
| 2009 | On Improving the Accuracy and Performance of Content-Based File Type Identification
Irfan Ahmed 0001, Kyung-suk Lhee, Hyunjung Shin |
ACISP | 1 |
| 2008 | Detection of Malcodes by Packet ClassificationabstractIn this paper, we propose an anomaly detection approach that classifies packets into code-type and data-type. Our objective is to detect a packet containing codes flowing into a network port, which normally expects data packets only. The proposed approach can detect potentially malicious packets such as worms, viruses, and shellcodes. We propose a time-efficient algorithm and show the results of our initial experiments. Irfan Ahmed 0001, Kyung-suk Lhee |
ARES | 1 |
| 2007 | Binding Update Authentication Scheme for Mobile IPv6abstractMobile IPv6 provides route optimization mechanism for fast communication by lessening the overhead of indirection. Although it ameliorates the communication latency but it also needs good authentication mechanism to make route optimization more effective and reliable. In this paper, we improve one of the route optimization security mechanisms called bombing resistant protocol, and propose a new binding update authentication scheme. Both mechanisms perform the care of address validation of the mobile node and maintain the integrity of the binding update message during binding update process, while the latter performs better in terms of latency and computation. They also resolve reflection and amplification, intensive computation problem. Irfan Ahmed 0001, Usman Tariq, Shoaib Mukhtar, Kyung-suk Lhee, S. W. Yoo, Piao Yanji |
IAS | 1 |