Document Type: Research Article

Location Privacy Preservation for Secondary Users in a Database-Driven Cognitive Radio Network

Volume 14, Issue 2, July 2022, Pages 215-227

https://doi.org/10.22042/isecure.2022.243102.568

Zeinab Salami, Mahmoud Ahmadian Attari, Mohammad Reza Aref, Hoda Jannati

Abstract Since their introduction, cognitive radio networks, as a new solution to the problem of spectrum scarcity, have received great attention from the research society. An important field in database driven cognitive radio network studies is pivoted on their security issues. A critical issue in this context is user's location privacy, which is potentially under serious threat. The query process by secondary users from the database is one of the points where the problem rises. In this paper, we propose a Privacy Preserving Query Process (PPQP), accordingly. PPQP is a cryptography-based protocol, which takes advantage of properties of some well-known cryptosystems. This method lets secondary users deal in the process of spectrum query without sacrificing their location information. Analytical assessment of PPQP's privacy preservation capability shows that it preserves location privacy for secondary users against different adversaries, with very high probability. Relatively low communicational cost is a significant property of our novel protocol.

Oblivious Transfer Using Generalized Jacobian of Elliptic Curves

Volume 15, Issue 2, July 2023, Pages 260-273

https://doi.org/10.22042/isecure.2023.336301.779

Maryam Rezaei Kashi, Mojtaba Bahramian

Abstract ‎Oblivious transfer is one of the important tools in cryptography‎, ‎in which a sender sends a message to a receiver with a probability between 0 and 1‎, ‎while the sender remains oblivious that the receiver has received the message‎.
‎A flavor of $OT$ schemes is chosen $t$-out-of-$k$ oblivious transfer ($OT^t_k$)‎. ‎In an $OT^t_k$ scheme‎, ‎a sender transfers $k$ messages to a receiver‎, ‎the receiver can learn only $t$ of them‎, ‎and the sender remains oblivious to which secrets are extracted by the receiver‎.
‎In this paper‎, ‎we first propose a type of Diffie-Hellman key exchange protocol using the generalized Jacobian of elliptic curves‎. ‎Next‎, ‎we introduce simple‎, ‎secure two-round algorithms for $OT$‎, ‎$OT^1_2$‎, ‎$OT^t_k$‎.
‎The security of proposed protocols is based on the intractability assumption of solving discrete logarithm problem; furthermore‎, ‎in our $OT$ schemes‎, ‎it is not necessary to map the messages to the points on the elliptic curve‎.

Dual-Layered Quantum-Secure Concealing: Steganography over Quantum Key Distribution

Articles in Press, Accepted Manuscript, Available Online from 01 January 2026

https://doi.org/10.22042/isecure.2026.240529

Donya Sadat Rezaeishad, Hossein Bahramgiri

Abstract In the quantum computing era, classical encryption faces unprecedented vulnerabilities, while Quantum Key Distribution (QKD) alone remains insufficient for top-secret data transmission due to practical hardware flaws. In this paper, a novel dual-layered framework that integrates steganography with QKD is proposed to enhance security and concealment. The proposed protocol embeds encrypted messages within QKD keys during post-processing, leveraging existing infrastructure without requiring hardware modifications. The message is first compressed, encoded, and encrypted using a pre-shared QKD key via one-time-pad encryption. A block-based search mechanism then hides message bits within the sifted key while preserving statistical randomness. Crucially, this approach provides two-layer security: information-theoretic encryption via QKD and undetectable message existence. Evaluations confirm ultra-low failure probabilities of embedding (below 10−12 for 1000-bit messages) and minimal deviations in sifted key length (under 1% for typical blocks). The solution enables eavesdropper detection, maintaining full compatibility with standard QKD post-processing. By unifying steganographic stealth with QKD’s theoretical security, this work establishes a practical solution for transmitting top-secret data against evolving quantum threats.

Considering Uncertainty in Modeling Historical Knowledge

Volume 11, Issue 3, August 2019, Pages 59-65

https://doi.org/10.22042/isecure.2019.11.0.8

Fairouz Zendaoui, Walid Khaled Hidouci

Abstract Simplifying and structuring qualitatively complex knowledge, quantifying it in a certain way to make it reusable and easily accessible are all aspects that are not new to historians. Computer science is currently approaching a solution to some of these problems, or at least making it easier to work with historical data. In this paper, we propose a historical knowledge representation model taking into consideration the quality of imperfection of historical data in terms of uncertainty. To do this, our model design is based on a multilayer approach in which we distinguish three informational levels: information, source, and belief whose combination allows modeling and modulating historical knowledge. The basic principle of this model is to allow multiple historical sources to represent several versions of the history of a historical event with associated degrees of belief. In our model, we differentiated three levels of granularity (attribute, object, relation) to express belief and defined 11 degrees of uncertainty in belief. The proposed model can be the object of various exploitations that fall within the historian’s decision-making support for the plausibility of the history of historical events.

A Fine-Grained Hybrid Inversion-Based Membership Inference Attack Against GANs

Volume 17, Issue 2, July 2025, Pages 189-198

https://doi.org/10.22042/isecure.2025.216445

Maryam Azadmanesh

Abstract Generative Adversarial Networks (GANs) are commonly used in various applications. Different membership inference attacks have been carried out against GANs. However, the accuracy of these attacks decreases with a large number of training samples, and there have been no attacks conducted against privacy-preserving GAN models with dependent or independent datasets. Therefore, this paper proposes a fine-grained inversion-based attack. In this proposed attack, fine-grained reconstruction error is utilized to infer the membership or non-membership of given samples. To calculate the
reconstruction error, an inversion-based encoder is trained, and the latent code obtained from the encoder is refined using a Genetic Algorithm. The membership status of the candidate target sample is determined using the reconstruction error of the segmentations of the target sample. The proposed attack can be executed by accessing the generator network in both black and white-box settings. The accuracy of the proposed attack is compared with other relevant studies, demonstrating its superior performance. Furthermore, the results indicate that privacy-preserving mechanisms do not ensure that dependent data does not disclose information about individual samples.

5G Attacks: Realistic Scenarios and Simulations Using Open5GS

Articles in Press, Accepted Manuscript, Available Online from 12 February 2026

https://doi.org/10.22042/isecure.2026.240534

Mahdi Jeyhoon, Maryam Rajabzadeh Assar

Abstract The evolution of fifth-generation cellular networks (5G) brings unprecedented improvements in speed, latency, and scalability, but also introduces significant new security challenges. While earlier studies have primarily focused on performance benchmarking or examined isolated vulnerabilities, there remains a lack of comprehensive, reproducible security evaluations of 5G core networks. This paper presents a scenario-based simulation study of three distinct denial-of-service (DoS) attacks targeting critical components of the 5G control plane. Using open-source tools such as Open5GS and UERANSIM, we demonstrate: (1) large-scale registration flooding that overloads both the next-generation NodeB (gNB) and the Access and Mobility Management Function (AMF); (2) AMF resource exhaustion through massive NGSetupRequest messages; and (3) tampering with a security-related parameter in the User Equipment (UE) registration process to disrupt authentication. The evaluation quantifies the impacts of Central Processing Unit (CPU) and Random Access Memory (RAM) under these attacks, showing that even commodity hardware testbeds can reveal critical vulnerabilities. Moreover, analysis of the logs collected during the attacks confirms the successful execution of each attack scenario. The findings highlight how scenario-based simulations effectively explore various 5G attack surfaces and underscore the necessity for targeted defense mechanisms to enhance the resilience of next-generation mobile networks.

Proposed ST-Slotted-CS-ALOHA Protocol for Time Saving and Collision Avoidance

Volume 11, Issue 3, August 2019, Pages 67-72

https://doi.org/10.22042/isecure.2019.11.0.9

Ehab Khatter, Dina Ibrahim

Abstract Time Saving and energy consumption has become a vital issue that attracts the attention of researchers in Underwater Wireless Sensor Networks (UWSNs) fields. According to that, there is a strong need to improve MAC protocols performance in UWSNs, particularly enhancing the effectiveness of ALOHA Protocol. In this paper, a time-saving Aloha protocol with slotted carrier sense proposed which we called, ST-Slotted-CS-ALOHA protocol. The results of the
simulation demonstrate that our proposed protocol can save time and decrease the average delay when it compared with the other protocols. Moreover, it decreased energy consumption and raised the ratio of throughput. However, the number of dropped nodes does not give better results compared to other protocols.

Division Property-Based Integral Attack on Reduced-Round SAND-128

Volume 17, Issue 2, July 2025, Pages 199-207

https://doi.org/10.22042/isecure.2025.216458

Atiyeh Mirzaie, Siavash Ahmadi, Mohammad Reza Aref

Abstract Given the rapid evolution of emerging technologies, such as the Internet of Things (IoT), there is a growing interest in lightweight block ciphers. This paper focuses on the security assessment of SAND-128, a newly proposed lightweight block cipher based on SIMON, recognized for its reliance on S-box-based security evaluation approaches. By employing Xiang’s MILP-aided method for integral distinguisher search, this study utilizes a MILP optimizer to identify a 16-round integral characteristic for SAND-128 with nine balanced bits. Furthermore, by extending the distinguisher to 17 rounds utilizing a novel idea without an increase in data complexity, we propose a comprehensive 20-round integral attack on SAND-128, including the key recovery step. This attack leverages the partial sums technique, resulting in a time complexity of 2119, memory complexity of 276 bytes, and data complexity of 2127. This cryptanalysis is, to the best of our knowledge, the best integral attack on reduced-round SAND-128 presented thus far.

Cognitive Strategic Model applied to a Port System

Volume 11, Issue 3, August 2019, Pages 73-78

https://doi.org/10.22042/isecure.2019.11.0.10

Felisa Córdova, Claudia Durán, Fredi Palominos

Abstract Port organizations have focused their efforts on physical or tangible assets, generating profitability and value. However, it is recognized that the greatest sustainable competitive advantage is the creation of knowledge using the intangible assets of the organization. The Balanced ScoreCard, as a performance tool, has incorporated intangible assets such as intellectual, structural and social capital into management. In this way, the port community can count on new forms of managing innovation, strengthening organizational practices, and increasing collaborative work teams. In this study, the concepts from analysis of the cognitive SWOT are applied to diagnose the port activity and its community. In workshops with experts and from the vision, mission, cognitive SWOT and strategies, a cognitive strategic map considering strategic objectives and indicators is designed in the customer, processes, and learning and growth axis for the port and port community. Causal relationships between objectives, associated indicators and incidence factors are established in a forward way from learning and growth axis to customer axis. Then, the incidence matrix is developed and the direct and indirect effects between factors are analyzed, which allows recommending the future course of the port and its community.

Spotting and Mitigating DDoS Attacks Using Deep Learning for Online Traffic Analysis

Volume 17, Issue 2, July 2025, Pages 209-221

https://doi.org/10.22042/isecure.2025.217461

Mojtaba Shirinjani, Mojtaba Amiri, Amirhosein Salehi, Pouria Arefi Jamal, Rasoul Khazaei Laki, Seyed Hatef Sadegh Esfahani, Siavash Ahmadi, Masoumeh Koochak Shooshtari, Mohammad Reza Aref

Abstract Distributed Denial of Service (DDoS) attacks threaten server and network availability with minimal resources. These attacks mimic legitimate traffic, evading Intrusion Detection Systems (IDS) and Intrusion Prevention Systems(IPS). The primary challenge in countering DDoS attacks is achieving early detection as close to their origin. In addition, the persistence of malicious traffic hidden within legitimate traffic remains a common challenge for various mitigation techniques. This paper introduces a modular approach for identifying and mitigating DDoS attacks in both online and offline settings, using deep learning and rule-based techniques. We train the IDS with VGG16, GoogLeNet, Support Vector Machines (SVM), and Random Forest (RF) and evaluate them using the CICDDoS2019 dataset. Our experiments show a detection accuracy of 99.87% offline and 99.67% online. Our methodology outperforms state-of-the-art approaches in offline detection, particularly with VGG16 and GoogLeNet. In our online setup, the mitigation module successfully addresses all attacks detected by our anti-DDoS solution.

Enhancing Kleptographic Backdoors in Hash-Based Deterministic Random Bit Generators

Articles in Press, Accepted Manuscript, Available Online from 22 February 2026

https://doi.org/10.22042/isecure.2026.241269

Sepehr Jafari, Raziyeh Salarifard

Abstract Deterministic Random Bit Generators (DRBGs) are essential for cryptographic security but remain vulnerable to covert kleptographic attacks that implant backdoors to leak sensitive information. Despite being known for two decades, as demonstrated by incidents such as the Snowden revelations and Dual-EC, these attacks persist in modern protocols, including TLS and post-quantum systems. This paper introduces a novel kleptographic backdoor for hash-based DRBGs, utilising a dual-phase design: secret information is split across two complementary phases, each requiring the other for recovery. This design significantly increases the overall complexity compared with conventional methods. To enhance indistinguishability, we integrate randomness derived from the discrete logarithm problem, ensuring statistical conformity. By leveraging ElGamal encryption to ensure compatibility with our approach, we develop a highly covert backdoor. Rigorous validation via the NIST Statistical Test Suite (STS) and neural network-based anomaly detection confirms the backdoor passes all NIST tests while evading machine learning detection, maintaining statistical integrity and structural consistency. 

Enhancing Learning from Imbalanced Classes via Data Preprocessing: A Data-Driven Application in Metabolomics Data Mining

Volume 11, Issue 3, August 2019, Pages 79-89

https://doi.org/10.22042/isecure.2019.11.0.11

Ahmed BaniMustafa

Abstract This paper presents a data mining application in metabolomics. It aims at building an enhanced machine learning classifier that can be used for diagnosing cachexia syndrome and identifying its involved biomarkers. To achieve this goal, a data-driven analysis is carried out using a public dataset consisting of 1H-NMR metabolite profile. This dataset suffers from the problem of imbalanced classes which is known to deteriorate the performance of classifiers. It also influences its validity and generalizablity. The classification models in this study were built using five machine learning algorithms known as PLS-DA, MLP, SVM, C4.5 and ID3. This model is built after carrying out a number of intensive data preprocessing procedures to tackle the problem of imbalanced classes and improve the performance of the constructed classifiers.
These procedures involves applying data transformation, normalization, standardization, re-sampling and data reduction procedures using a number of variables importance scorers. The best performance was achieved by building an MLP model that was trained and tested using five-fold cross-validation using datasets that were re-sampled using SMOTE method and then reduced using SVM variable importance scorer. This model was successful in classifying samples with excellent accuracy and also in identifying the potential disease biomarkers. The results confirm the validity of metabolomics data mining for diagnosis of cachexia. It also emphasizes the importance of data preprocessing procedures such as sampling and data reduction for improving data mining results, particularly when data suffers from the problem of imbalanced classes.

Differential Fault Analysis of the BipBip Block Cipher

Volume 17, Issue 2, July 2025, Pages 223-232

https://doi.org/10.22042/isecure.2025.217885

Narges Mokhtari, Navid Vafaei, Sadegh Sadeghi, Nasour Bagheri

Abstract Differential Fault Analysis (DFA) represents one of the most effective physical attacks against cryptographic algorithms. It exploits the implementation weaknesses by injecting faults. DFA is a cryptographic technique in which an attacker intentionally injects errors into a cryptographic system and leverages the differences caused by these deliberate faults while executing cryptographic algorithms. The attacker can gain insights into the cryptographic operations by comparing the correct and faulty ciphertexts. This research applies DFA to BipBip, an ultra-low-latency tweakable block cipher characterized by a 24-bit tweakable block and a 256-bit master key. Our primary assumption is that the tweak remains fixed within BipBip. This study’s findings reveal that the structural design of the BipBip block cipher is susceptible to differential fault analysis. We demonstrate a significant vulnerability by injecting a precise number of 30 random faults into different states of BipBip. Through an exhaustive search process, we successfully retrieved the master key. Furthermore, this research marks the first application of differential fault analysis in identifying implementation weaknesses within BipBip, highlighting a critical security concern.

Static Malware Detection in Windows Executables Using Deep Neural Networks and Custom Binary Features

Articles in Press, Accepted Manuscript, Available Online from 22 February 2026

https://doi.org/10.22042/isecure.2026.241272

Sajjad Rezaei, Ali Fanian

Abstract The extensive use of malware targeting Windows systems, particularly through Portable Executable (PE) files, has prompted significant research into malware detection. Although many approaches have been proposed, the increasing complexity and evasiveness of modern malware continue to present substantial challenges, underscoring the need for further advancements in detection strategies. This paper introduces a static malware detection framework based on deep learning and a set of carefully engineered binary features extracted directly from raw PE files. In contrast to conventional methods that rely on metadata or dynamic analysis, our approach performs detailed parsing of file headers, section layouts, entropy levels, import/export tables, and embedded resources to form a comprehensive feature set. A deep neural network is trained on these features, with its architecture and hyperparameters fine-tuned using Bayesian optimisation. The model is evaluated on a balanced dataset of benign and malicious PE files, achieving high accuracy (98.83%) and an F1-score of 98.95%. Fully automated and independent of dynamic execution or commercial tools, the proposed solution is well-suited for deployment in real-world applications such as antivirus systems and intrusion detection platforms. 

Hand Gestures Classification with Multi-Core DTW

Volume 11, Issue 3, August 2019, Pages 91-96

https://doi.org/10.22042/isecure.2019.11.0.12

Ayman Atia, Nada Shorim

Abstract Classifications of several gesture types are very helpful in several applications. This paper tries to address fast classifications of hand gestures using DTW over multi-core simple processors. We presented a methodology to distribute templates over multi-cores and then allow parallel execution of the classification. The results were presented to voting algorithm in which the majority vote was used for the classification purpose. The speed of processing has increased dramatically due to using multi-core processors and DTW.

A Lightweight Online Intrusion Detection and Localization Framework for Industrial Control Systems

Volume 17, Issue 2, July 2025, Pages 233-241

https://doi.org/10.22042/isecure.2025.219359

Amirhosein Salehi, Siavash Ahmadi, Mohammad Reza Aref

Abstract As the Industrial Internet of Things (IIoT) faces increasing cyber threats, the need for effective and practical intrusion detection systems (IDS) becomes paramount. One of the key challenges in designing IDS is ensuring the online detection and identification (localization) of potential attacks in real-time. Our research addresses this challenge by developing a lightweight online intrusion detection framework tailored explicitly for water distribution systems. Our proposed framework aims to balance real-time detection/identification and maintaining accuracy criteria. Immediate alarm triggering for every anomaly detected can lead to a high false positive rate while waiting for attack confirmation can cause harmful delays. To overcome these limitations, we present a novel approach that achieves real-time detection while maintaining a low false positive rate (below 5%), making it highly applicable in real-world scenarios. We train and test our system using BATADAL datasets, demonstrating its superior performance compared to other mechanisms. Additionally, we introduce a PCA-based Concealment Detection Statistical Outlier (PCACD-SO) identification approach that enables the real-time identification of compromised sensors, actuators, or connections during an attack. The results validate the effectiveness of our lightweight online intrusion detection framework, showcasing its ability to detect cyber attacks in real-time while maintaining a low false positive rate. Furthermore, our proposed PCACD-SO identification approach enhances the system’s capability to identify and isolate compromised components swiftly, enabling prompt response and mitigation.

An LSTM-DBSCAN Approach for Interpretable Insider Threat Detection via Behavioural Anomaly Analysis

Articles in Press, Accepted Manuscript, Available Online from 22 February 2026

https://doi.org/10.22042/isecure.2026.241277

Mohammad Mohammadi, Moein Bannaye Zahmati, Morteza Noferesti

Abstract Insider threats pose a significant cybersecurity risk, as authorised users can exploit legitimate access to compromise sensitive systems and data. This paper proposes an integrated behavioural anomaly detection approach to address three critical challenges in AI-driven insider threat detection: lack of interpretability, misleading evaluation metrics, and misalignment with operational taxonomies. Our approach employs a three-stage pipeline: (1) an LSTM autoencoder to detect temporal anomalies in login patterns, (2) DBSCAN clustering to identify suspicious file access and device usage during anomalous sessions, and (3) DBSCAN-based URL analysis to uncover exfiltration patterns. By analysing behaviour across time, location, and web activity, this framework builds actionable threat chains mapped to MITRE ATT&CK techniques including T1078, T1005, T1204.002, T1567.002. It bridges the gap between theoretical models and the daily work of a Security Operations Center (SOC). In the data exfiltration scenario on the CERT R6.2 insider threat dataset, the proposed approach achieved a recall of 83.3% and an accuracy of 91.7% in classifying malicious days. The framework also provides interpretable alerts and maintains operational efficiency. 

Aspect Oriented UML to ECORE Model Transformation

Volume 11, Issue 3, August 2019, Pages 97-103

https://doi.org/10.22042/isecure.2019.11.0.13

Muhammad Ali Memon, Zaira Hassan, Kamran Dahri, Asadullah Shaikh, Muhammad Ali Nizamani

Abstract With the emerging concept of model transformation, information can be extracted from one or more source models to produce the target models. The conversion of these models can be done automatically with specific transformation languages. This conversion requires mapping between both models with the help of dynamic hash tables. Hash tables store reference links between the elements of the source and target model. Whenever there is a need to access the target element, we query the hash table. In contrast, this paper presents an approach by directly creating aspects in the source meta-model with traces. These traces hold references to target elements during the execution. Illustrating the idea of model driven engineering (MDE), This paper proposes a method that transforms UML class models to EMF ECORE model.

A Lightweight General Modular Multiplier for Kyber PQC

Volume 17, Issue 2, July 2025, Pages 243-249

https://doi.org/10.22042/isecure.2025.217886

Hossein Naderi Varandi, Raziye Salarifard

Abstract Kyber, a key encapsulation mechanism (KEM), plays a pivotal role in post-quantum cryptography. As a finalist in the NIST project, Kyber is gaining traction in industry libraries and systems. The heart of the Kyber algorithm lies in the Number Theoretic Transform (NTT), where modular multiplication is the most intricate operation. In this paper, we propose a novel general modular multiplier that reduces both time and area requirements compared to prior methods. Our key innovation lies in the novel reduction algorithm, which avoids fixed values for coefficients A or B (i.e., C = A × B mod q) used in NTT, Inverse NTT (INTT), and PWM (Point-Wise Multiplication). Additionally we introduce two pipeline architectures for modular multiplication within Kyber, emphasizing low area usage and high frequency. These architectures demonstrate 8% and 31% better frequency, while our work achieves the lowest slice usage and AT (Area × Time) among all previous work.

Secure Pairing-Free IBE and CP-ABE from Inner-Product Functional Encryption

Articles in Press, Accepted Manuscript, Available Online from 07 March 2026

https://doi.org/10.22042/isecure.2026.241980

Ahmad Khoureich Ka

Abstract The potential of Attribute-Based Encryption (ABE) in the context of IoT has driven researchers to propose pairing-free ABE schemes that are suitable for resource-constrained devices. Unfortunately, many of these schemes turned out to be insecure. This fact reinforces the view of some researchers according to which instantiating an Identity-Based Encryption (IBE) in plain Decisional Diffie-Hellman (DDH) groups is impossible. In this paper, we provide a generic Ciphertext-Policy ABE (CP-ABE) scheme supporting secret AND-gate policy using Inner-Product Functional Encryption (IPFE). We also propose an instantiation of our generic CP-ABE scheme based on the DDH assumption. From our generic CP-ABE scheme, we derive an IBE scheme by introducing the concept of Clustered Identity-Based Encryption (CIBE). Our schemes show that it is possible to construct secure IBE and ABE schemes based on the classical DDH assumption. An implementation of our CIBE in Python using the Charm framework is available on GitHub. 

Access and Mobility Policy Control at the Network Edge

Volume 11, Issue 3, August 2019, Pages 105-111

https://doi.org/10.22042/isecure.2019.11.0.14

Evelina Pencheva, Ivaylo Atanasov, Ivaylo Asenov

Abstract The fifth generation (5G) system architecture is defined as service-based and the core network functions are described as sets of services accessible through application programming interfaces (API). One of the components of 5G is Multi-access Edge Computing (MEC) which provides the open access to radio network functions through API. Using the mobile edge API third party analytics applications may provide intelligence in the vicinity of end users which improves network performance and enhances user experience. In this paper, we propose new mobile edge API to access and control the mobility at the network edge. The application logic for provisioning access and mobility policies may be based on considerations like load level information per radio network slice instance, user location, accumulated usage, local policy, etc. We describe the basic API functionality by typical use cases and provide the respective data model, which represents the resource structure and data types. Some implementation aspects, related to modeling the resource states as seen by a mobile edge application and by the network, are discussed.

Shapley Value for Federated Learning: A Distributed and Fair Framework

Volume 17, Issue 2, July 2025, Pages 251-259

https://doi.org/10.22042/isecure.2025.219572

Mohammad Amin Sarzaeem, Seyed Reza Hoseini Najarkolaei, Mohammad Reza Aref

Abstract In a federated learning system, the objective is to train a global model over distributed datasets without centralizing all data on a single unit. This is accomplished by training a local model on the dataset of each data owner and then aggregating these local models to preserve the datasets’ privacy. To incentivize clients to actively engage in the learning process, fairness-aware federated learning techniques can be employed. One such approach involves quantifying the contribution of locally trained models in training the global model by Shapley value (SV) using an additional dataset and rewarding them according to their contributions. However, the calculation of the Shapley value presents a significant challenge due to its high computational complexity. To tackle this issue, our research presents a contribution-based federated learning method that efficiently computes the contribution of each locally trained model by distributing the additional dataset among processing nodes in a private manner and calculating the Shapley value over them.

A Multi-Objective Reinforcement Learning Framework for Security Enhancement in Autonomous Vehicle

Articles in Press, Accepted Manuscript, Available Online from 12 March 2026

https://doi.org/10.22042/isecure.2026.242014

Arman Moradi, Mehran Alidoost Nia, Reza Ebrahimi Atani

Abstract Autonomous vehicles must balance road-safety objectives with growing cybersecurity threats. In this paper, we present a reinforcement-learning framework that jointly optimizes driving performance and resilience to Denial-of-Service (DoS) attacks.The problem is formulated as a multi-objective Markov Decision Process that integrates a safety reward with a security reward, while the partial observability of attacks is captured via a Bayesian belief. A Proximal Policy Optimization (PPO) agent controls steering, throttle, and dedicated mitigation actions. The system is implemented in the CARLA simulator with camera and LiDAR inputs and evaluated on urban driving scenarios. Experimental results demonstrate that the agent sustains stable lane-keeping and target-speed performance, while substantially reducing collision-prone incidents and retaining more than 90 % of the nominal travel distance under attack scenarios. The framework outperforms the safety-only PPO baseline and a rule-based security countermeasure.

Evaluating Multipath TCP Resilience against Link Failures

Volume 11, Issue 3, August 2019, Pages 113-122

https://doi.org/10.22042/isecure.2019.11.0.15

Mohammed J.F. Alenazi

Abstract Standard TCP is the de facto reliable transfer protocol for the Internet. It is designed to establish a reliable connection using only a single network interface. However, standard TCP with single interfacing performs poorly due to intermittent node connectivity. This requires the re-establishment of connections as the IP addresses change. Multi-path TCP (MPTCP) has emerged to utilize multiple network interfaces in order to deliver higher throughput. Resilience to link failures can be better supported in MPTCP as the segments’ communication are maintained via alternative interfaces. In this paper, the resilience of MPTCP to link failures against several challenges is evaluated. Several link failure scenarios are applied to examine all aspects of MPTCP including congestion algorithms, path management, and subflow scheduling. In each scenario, the behavior of MPTCP is studied by observing and analyzing the throughput and delay. The evaluation of the results indicates MPTCP resilience to a low number of failed links. However, as the number of failed links increases, MPTCP can only recover full throughput if the link failure occurs on the server side. In addition, in the presence of link failures, the lowestRTT MPTCP scheduler yields the shortest delivery time while providing the minimum application jitter.

A New Scheme Based on (t,n)-Secret Image Sharing With Steganography Based on Joseph’s Problem and HLR

Volume 17, Issue 2, July 2025, Pages 261-265

https://doi.org/10.22042/isecure.2025.219355

Zahra Saeidi, Samaneh Mashhadi

Abstract The paper presents a novel approach to Secret Image Sharing (SIS) that combines (t, n)-threshold schemes with steganography, utilizing Joseph’s problem and Homogeneous Linear Recursion (HLR) to enhance security. The methodology involves dividing a secret image into shadow images, embedding these shadows into cover images using a Least Significant Bit (LSB) method guided by Joseph’s problem. The study aims to increase the security of SIS while maintaining high visual quality in the stego images. The authors validate their approach through various experiments, demonstrating that the proposed method improves Peak Signal-to-Noise Ratio (PSNR) and Structural Similarity Index (SSIM) compared to existing methods.