EDBT 2026 Demo / reviewers in the wild / expert
Mah-Rukh Fida
dblp:78/9943
· DBLP profile ↗
14ranked-venue papers
8as first author
8since 2021 · last 2026
0000-0001-7660-1150ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 6 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Leveraging programmable data plane for network intrusion detection: A surveyabstractThe rapid proliferation of digital devices, particularly resource-constrained IoT nodes, has expanded the network attack surface, posing new challenges for timely and effective intrusion detection. Traditional centralized Intrusion Detection Systems (IDSs) struggle to cope with the growing scale and sophistication of modern threats. Recent research leverages the programmability of the data plane in switches, edge gateways, and smart network interface cards to enable intrusion detection closer to the traffic source. Programmable Data Planes (PDPs) allow custom packet parsing, real-time header manipulation, and extraction of packet- and flow-level features, facilitating early attack detection without full reliance on centralized systems. This survey reviews PDP-based intrusion detection approaches, from thresholding and rule-based methods to entropy- and AI-driven techniques, while addressing hardware constraints such as limited memory and fixed pipelines. Unlike prior surveys, our work uniquely classifies IDSs as feature- or packet-based, analyzes inference approaches and their deployment points, examines datasets used for evaluation, identifies detectable threat types, and reports code availability to promote reproducibility. The paper concludes with key challenges and research directions for advancing PDP-based intrusion detection in dynamic network environments. Mah-Rukh Fida, Azza H. Ahmed |
Comput. Networks | 1 |
| 2024 | Bottleneck Identification in Cloudified Mobile Networks Based on Distributed TelemetryabstractCloudified mobile networks are expected to deliver a multitude of services with reduced capital and operating expenses. A characteristic example is 5G networks serving several slices in parallel. Such mobile networks, therefore, need to ensure that the SLAs of customised end-to-end sliced services are met. This requires monitoring the resource usage and characteristics of data flows at the virtualised network core, as well as tracking the performance of the radio interfaces and UEs. A centralised monitoring architecture can not scale to support millions of UEs though. This paper, proposes a 2-stage distributed telemetry framework in which UEs act as early warning sensors. After UEs flag an anomaly, a ML model is activated, at network controller, to attribute the cause of the anomaly. The framework achieves 85% F1-score in detecting anomalies caused by different bottlenecks, and an overall 89% F1-score in attributing these bottlenecks. This accuracy of our distributed framework is similar to that of a centralised monitoring system, but with no overhead of transmitting UE-based telemetry data to the centralised controller. The study also finds that passive in-band network telemetry has the potential to replace active monitoring and can further reduce the overhead of a network monitoring system. Mah-Rukh Fida, Azza H. Ahmed, Thomas Dreibholz, Andrés F. Ocampo, Ahmed Elmokashfi, Foivos Michelinakis |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Modeling Variation in Mobile Download Speed in Presence of Missing SamplesabstractA stably fast mobile broadband connectivity is key to customer retention. Mobile networks, however, suffer unpredictability in performance. Analyzing variability in network speed is, therefore, challenging since it tends to exhibit patterns at several time scales. Additionally, frequently monitoring it over time, is costly. In this paper, we analyze speed measurements from 78 stationary probes, spread across Norway. Monitoring was performed thrice per day across the year, to assess performance of the two largest network operators. Despite being unique, the dataset involves a non-trivial extent of missing data. This study investigates the effect of missing data on the extracted performance patterns. We capture patterns with tensor factorizations, that show that missing data at random has a minimal effect on the identified patterns, and that depending upon the determinism of an operator's performance, the acceptable size and structure of missing data varies. Our analysis shows that, for a probe, the difference in speed variation between real and imputed speed values can be around 7% for up to 40% missing data. We also identify that congestion, routine maintenance and sub-optimal network configuration cause high speed variability. These findings can help operators improving their offerings and deciding on optimal performance monitoring frequency. Mah-Rukh Fida, Marie Roald, Evrim Acar, Ahmed Elmokashfi |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | PRINCIPIA: Opportunistic CPU and CPU-shares Allocation for Containerized Virtualization in Mobile Edge ComputingabstractLeveraging virtualization technology, Mobile Edge Computing (MEC) deploys multiple services with different execution time requirements running as isolated processes. For instance, both real-time (RT) and non-RT applications may be (are) running on the same infrastructure using containerized virtualization. Nevertheless, sharing resources (e.g., CPU) with collocated workloads could impact the RT performance of RT applications. This paper presents PRINCIPIA, a dynamic CPU and CPU-shares allocation mechanism that opportunistically enables non-RT applications to run on underutilized CPUs while providing RT guarantees to RT applications. By monitoring MEC’s system metrics like processor’s CPU utilization and container’s CPU usage, PRINCIPIA dynamically allocates both CPU and CPU-shares to containers running non-RT applications aiming at opportunistically exploiting underutilized CPUs by containers running RT applications. We evaluate PRINCIPIA on a small-scale MEC server which uses containerized virtualization along with Linux RT Kernel to deploy both RT and non-RT applications. Our findings show that PRINCIPIA mitigates the impact on the RT performance of RT applications providing bounded processing latency in comparison with the default host Kernel scheduler. Andrés F. Ocampo, Mah-Rukh Fida, Juan Felipe Botero, Ahmed Elmokashfi, Haakon Bryhni |
NOMS | 2 |
| 2023 | Opportunistic CPU Sharing in Mobile Edge Computing Deploying the Cloud-RANabstractLeveraging virtualization technology, Cloud-RAN deploys multiple virtual Base Band Units (vBBUs) along with collocated applications on the same Mobile Edge Computing (MEC) server. However, the performance of real-time (RT) applications such as the vBBU could potentially be impacted by sharing computing resources with collocated workloads. To address this challenge, this paper presents a dynamic CPU sharing mechanism, specifically designed for containerized virtualization in MEC servers, that hosts both RT and non-RT general-purpose applications. Initially, the CPU sharing problem in MEC servers is formulated as a Mixed-Integer Programming (MIP). Then, we present an algorithmic solution that breaks down the MIP into simpler subproblems that are then solved using efficient, constant factor heuristics. We assessed the performance of this mechanism against instances of a commercial solver. Further, via a small-scale testbed, we assessed various CPU sharing mechanisms and their effectiveness in reducing the impact of CPU sharing on RT application processing performance. Our findings indicate that our CPU sharing mechanism reduces the worst-case execution time by more than 150% compared to the default host RT-Kernel approach. This evidence is strengthened when evaluating this mechanism within Cloud-RAN, in which vBBUs share resources with collocated applications on a MEC server. Using our CPU sharing approach, the vBBU’s scheduling latency decreases by up to 21% in comparison with the host RT-Kernel. Andrés F. Ocampo, Mah-Rukh Fida, Juan Felipe Botero, Ahmed Elmokashfi, Haakon Bryhni |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | A Live Demonstration of In-Band Telemetry in OSM-Orchestrated Core NetworksabstractNetwork Function Virtualization is a key enabler to building future mobile networks in a flexible and cost-efficient way. Such a network is expected to manage and maintain itself with minimum human intervention. With early deployments of the fifth generation of mobile technologies – 5G – around the world, setting up 4G/5G experimental infrastructure is necessary to optimally design Self-Organising Networks (SON). In this demo, we present a custom small-scale 4G/5G testbed. As a step towards self-healing, the testbed integrates Programming Protocol-independent Packet Processors (P4) virtual switches, that are placed along interfaces between different components of transport and core network. This demo not only shows the administration and monitoring of the Evolved Packet Core VNF components, using Open Source MANO, but also serves as a proof of concept for the potential of P4-based telemetry in detecting anomalous behaviour of the mobile network, such as a congestion in the transport part. Thomas Dreibholz, Mah-Rukh Fida, Azza H. Ahmed, Andrés F. Ocampo, Foivos Michelinakis |
LCN | 2 |
| 2022 | Measuring and Localising Congestion in Mobile Broadband NetworksabstractMobile broadband networks, although increasingly popular, suffer large fluctuations in performance. Download speeds can drop by 50% or more during peak hours. Hence, understanding and dissecting the causes of these fluctuations is central to improving current and future networks. In this paper, we propose a congestion detection and localisation method, Q-TSLP, that combines and extends the two state-of-the-art congestion detection tools: Q-Probe and TSLP. Q-Probe monitors patterns in packet arrivals, while TSLP tracks shifts in RTT to detect bottleneck at different segments of an end-to-end path. QProbe can attribute congestion, at a very coarse level, to either radio or non-radio related. TSLP on the other hand cannot pinpoint radio related congestion. Q-TSLP provides a per-hop congestion attribution thus addressing these limitations. To this end, we build two small scale LTE testbeds and experiment with a series of congestion scenarios. These controlled experiments show that apart from correct congestion localisation to finer granularity, the detection accuracy improves significantly with Q-TSLP, up to 100% in some cases. We then run a three-month long measurement campaign of congestion over two commercial operators in Norway. Overall, we run 17 million tests from a large number of geographically distributed probes. We find that both operators suffer congestion at different parts of the network. Our findings indicate that apart from mobile radio access, a non-trivial fraction of cases is related to congested mobile operator and Internet paths beyond the mobile network core. These findings hint that operators may need significant infrastructure upgrades to cope with potential 5G traffic volumes. Mah-Rukh Fida, Andrés F. Ocampo, Ahmed Elmokashfi |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | Quality of information with minimum requirements for emergency communications
Ameer Shakayb Arsalaan, Hung X. Nguyen, Andrew Coyle, Mah-Rukh Fida |
Ad Hoc Networks | 4 |
| 2020 | Evaluating the Cloud-RAN architecture: functional splitting and switched Ethernet XhaulabstractThe Cloud-RAN architecture is a key enabler to building future mobile networks in a flexible and cost-efficient way. For instance, switched Ethernet is a prime candidate for mobile transport networks (Xhaul), due to its flexibility, ubiquity, and cost-effectiveness. Understanding its performance under different network configurations would allow concluding about its appeal for Cloud-RAN. On the other hand, evaluating resource sharing mechanisms is relevant to put in place best solutions to host multiple virtual Base Band Units (vBBUs) into the same compute infrastructure. This paper assesses the feasibility of using a switched Ethernet Xhaul, by instantiating two vBBUs using different functional splits. Moreover, this paper evaluates two mechanisms for sharing network interface cards (NIC) in a general purpose server (GPS) hosting vBBUs. Our results point to a marginal performance degradation caused by the switched Ethernet Xhaul and the NIC sharing mechanisms. Such deviations could be seen from the increase in average and maximum Jitter and RTT results. Andrés F. Ocampo, Mah-Rukh Fida, Ahmed Elmokashfi, Haakon Bryhni |
CNSM | 2 |
| 2019 | Uncovering mobile infrastructure in developing countries with crowdsourced measurementsabstractKnowledge of cell tower locations enables multiple applications including identifying unserved or poorly served regions. We consider the problem of estimating the locations of cell towers using crowdsourced measurements, which is challenging due to the uncontrolled nature of the sample collection process. Using large-scale crowdsourced datasets from OpenCelliD with ground-truth cell tower locations, we find that none of the several commonly used localization algorithms (e.g., Weighted Centroid) nor the state of the art Filtered Weighted Centroid (FWC) approach that filters out less predictive measurements manage to deliver robust localization performance. We propose a novel supervised machine learning based approach termed as Adaptive Algorithm Selection (AAS) that adaptively selects the localization algorithm likely to provide the most accurate localization performance for a given cell and its crowdsourced samples. We show that AAS not only significantly outperforms the state-of-the-art FWC approach, with median error improvement over 65%, but also achieves localization performance within 20% of an idealized Oracle solution. We validate the applicability of AAS in new and different settings (including WLAN AP localization) before presenting case studies in three different African countries that demonstrate the use of AAS based cell tower localization to reliably infer mobile infrastructure in developing countries. Mah-Rukh Fida, Mahesh K. Marina |
ICTD | 1 |
| 2019 | Multiway Reliability Analysis of Mobile Broadband NetworksabstractUnderstanding and characterizing the reliability of a mobile broadband network is a challenging task due to the presence of a multitude of root causes that operate at different temporal and spatial scales. This, in turn, limits the use of classical statistical methods for characterizing the mobile network's reliability. We propose leveraging tensor factorizations, a well-established data mining method, to address this challenge. We represent a year-long time series of outages, from two mobile operators as multi-way arrays, and demonstrate how tensor factorizations help in extracting the outage patterns at various time-scales, making it easy to locate possible root causes. Unlike traditional methods of time series analysis, tensor factorizations provide a compact and interpretable picture of outages. Mah-Rukh Fida, Evrim Acar, Ahmed Elmokashfi |
Internet Measurement Conference | 1 |
| 2019 | Web Experience in Mobile Networks: Lessons from Two Million Page VisitsabstractMeasuring and characterizing web page performance is a challenging task. When it comes to the mobile world, the highly varying technology characteristics coupled with the opaque network configuration make it even more difficult. Aiming at reproducibility, we present a large scale empirical study of web page performance collected in eleven commercial mobile networks spanning four countries. By digging into measurement from nearly two million web browsing sessions, we shed light on the impact of different web protocols, browsers, and mobile technologies on the web performance. We find that the impact of mobile broadband access is sizeable. For example, the median page load time using mobile broadband increases by a third compared to wired access. Mobility clearly stresses the system, with handover causing the most evident performance penalties. Contrariwise, our measurements show that the adoption of HTTP/2 and QUIC has practically negligible impact. To understand the intertwining of all parameters, we adopt state-of-the-art statistical methods to identify the significance of different factors on the web performance. Our analysis confirms the importance of access technology and mobility context as well as webpage composition and browser. Our work highlights the importance of large-scale measurements. Even with our controlled setup, the complexity of the mobile web ecosystem is challenging to untangle. For this, we are releasing the dataset as open data for validation and further research. Mohammad Rajiullah, Andra Lutu, Ali Safari Khatouni, Mah-Rukh Fida, Marco Mellia, Anna Brunström, Özgü Alay, Stefan Alfredsson, Vincenzo Mancuso |
WWW | 4 |
| 2018 | Impact of Device Diversity on Crowdsourced Mobile Coverage Maps
Mah-Rukh Fida, Mahesh K. Marina |
CNSM | 1 |
| 2017 | ZipWeave: Towards efficient and reliable measurement based mobile coverage mapsabstractThe accuracy of measurement-driven mobile coverage maps depends on the quality, density and pattern of the signal strength observations. Thus, identifying an efficient measurement data collection methodology is essential, especially when considering the cost associated with the measurement collection approaches (e.g., drive tests, crowd approaches). We propose ZipWeave, a novel measurement data collection and fusion framework for building efficient and reliable measurement-based mobile coverage maps. ZipWeave incorporates a novel nonuniform sampling strategy to achieve reliable coverage maps with reduced sample size. Assuming prior knowledge of the propagation characteristics of the region of interest, we first examine the potential gains of this non-uniform sampling strategy in different cases via a measurement-based statistical analysis methodology; this involves irregular spatial tessellation of the region of interest into sub-regions with internally similar radio propagation characteristics and sampling based on these sub-regions. We then present a practical form of ZipWeave nonuniform sampling strategy that can be used even without any prior information. In all our evaluations, we show that the ZipWeave non-uniform sampling approach reduces the samples by half compared to the common systematic-random sampling, while maintaining similar accuracy. Moreover, we show that the other key feature of ZipWeave to combine high-quality controlled measurements (that present limited geographic footprint similar to drive tests) with crowdsourced measurements (that cover a wider footprint) leads to more reliable mobile coverage maps overall. Mah-Rukh Fida, Andra Lutu, Mahesh K. Marina, Özgü Alay |
INFOCOM | 1 |