hh.sePublications
Change search
Link to record
Permanent link

Direct link
Eldefrawy, Mohamed HamdyORCID iD iconorcid.org/0000-0001-6408-5152
Publications (9 of 9) Show all publications
Kurunathan, H., Ali, H., Javanmardi, G., Eldefrawy, M. H., Gaitán, M. G., Robles, R., . . . Tovar, E. (2025). Adaptive Intrusion Mitigation in Software-Defined Vehicles Using Deep Reinforcement Learning. In: Proceedings of the 2025 International Workshop on Real-time and Intelligent Edge Computing (RAGE): Irvine, California, USA | May 6-9, 2025. Paper presented at The 4th International Workshop on Real-time and Intelligent Edge Computing (RAGE), Irvine, California, USA, May 6-9, 2025. New York: ACM Digital Library, Article ID 4.
Open this publication in new window or tab >>Adaptive Intrusion Mitigation in Software-Defined Vehicles Using Deep Reinforcement Learning
Show others...
2025 (English)In: Proceedings of the 2025 International Workshop on Real-time and Intelligent Edge Computing (RAGE): Irvine, California, USA | May 6-9, 2025, New York: ACM Digital Library, 2025, article id 4Conference paper, Published paper (Refereed)
Abstract [en]

Software-defined vehicles (SDVs) leverage vehicle-to-everything (V2X) communication to enable advanced connectivity and autonomous driving capabilities. However, this increased interconnectivity also exposes them to cyber threats such as spoofing, denial-of-service attacks, and data manipulation, making intrusion detection systems (IDS) essential for ensuring SDV security and reliability. In this work, we propose a novel intrusion mitigation approach that integrates Advantage Actor-Critic (A2C) reinforcement learning with a Long Short-Term Memory (LSTM) network to detect anomalies and intrusions in V2X communications. The LSTM component captures temporal dependencies in V2X data, enhancing the model’s ability to identify emerging attack patterns, while the A2C framework dynamically adjusts defensive actions, including flagging, blocking or monitoring traffic, based on evolving threat levels. Experimental results demonstrate the model’s effectiveness, achieving high detection accuracy and sensitivity. Additionally, we analyze how the system adapts over time, becoming more confident in its decision-making and optimizing security enforcement. This work enhances SDV cybersecurity by introducing a learning-based adaptive intrusion response system aiming at mitigating threats in highly dynamic vehicular networks. © 2025 Copyright held by the owner/author(s).

Place, publisher, year, edition, pages
New York: ACM Digital Library, 2025
Keywords
Software-defined vehicles, deep reinforcement learning, intrusion mitigation
National Category
Security, Privacy and Cryptography Computer Sciences Artificial Intelligence
Research subject
Smart Cities and Communities, Future industry
Identifiers
urn:nbn:se:hh:diva-55937 (URN)10.1145/3722567.3727848 (DOI)001498351300004 ()979-8-4007-1611-9 (ISBN)
Conference
The 4th International Workshop on Real-time and Intelligent Edge Computing (RAGE), Irvine, California, USA, May 6-9, 2025
Funder
Halmstad University
Note

Funding: This work was supported by the CISTER Research Unit (UIDP/UIDB/04234/2020), financed by National Funds through FCT/ MCTES(Portuguese Foundation for Science and Technology); by HAL4SDV funding within the Chips Joint Undertaking (Chips JU)the Public-Private Partnership for research, development and innovation under Horizon Europe– and National Authorities under grant agreement n° 101139789. In Addition, it is funded by Halmstad University (Halmstad i Högskolan) research base funding. Also by the Chilean Research Agency ANID through FONDECYT project No. 11241221.

Available from: 2025-04-30 Created: 2025-04-30 Last updated: 2025-10-01Bibliographically approved
Kurunathan, H., Ali, H., Eldefrawy, M. H. & Tovar, E. (2025). Energy Profiling of Lightweight Authentication protocols for Software-Defined Vehicles. In: Proceedings: Energy Profiling of Lightweight Authentication protocols for Software-Defined Vehicles. Paper presented at 12th International Conference on Future Internet of Things and Cloud (FiCloud), Istanbul, Turkey, 11-13 August 2025 (pp. 537-542). IEEE
Open this publication in new window or tab >>Energy Profiling of Lightweight Authentication protocols for Software-Defined Vehicles
2025 (English)In: Proceedings: Energy Profiling of Lightweight Authentication protocols for Software-Defined Vehicles, IEEE, 2025, p. 537-542Conference paper, Published paper (Refereed)
Abstract [en]

Software-Defined Vehicles (SDVs) is a paradigm of the wider internet of autonomous vehicles where its features and functions are enabled and managed through software, allowing for continuous updates and enhancements throughout its lifecycle. Enabling this technology relies on secure and efficient authentication mechanisms to ensure trusted communication in Vehicle-to-Everything (V2X) networks, over-the-air (OTA) updates, and intra-vehicle Electronic Control Unit (ECU) communication. As SDVs progress to support complex applications such as autonomous driving, platooning, and edge-assisted vehicular computing, selecting an optimal authentication scheme becomes critical for maintaining security without compromising real-time performance. In this work, we present a comparative analysis of state-of-the-art cryptographic authentication techniques and evaluate the impact on authentication latency, energy consumption and computational overhead. This work highlights the effectiveness of different authentication strategies and provides insights into the optimal selection of cryptographic primitives for SDV applications, balancing security and power consumption. Index Terms-Authentication Protocols, Energy profiling, Software-defined Vehicles © 2025 by The Institute of Electrical and Electronics Engineers, Inc. All rights reserved.

Place, publisher, year, edition, pages
IEEE, 2025
Series
International Conference on Future Internet of Things and Cloud, ISSN 2996-1009, E-ISSN 2996-1017
Keywords
Authentication Protocols, Energy profiling, Software-defined Vehicles
National Category
Embedded Systems Computer Engineering Security, Privacy and Cryptography
Research subject
Smart Cities and Communities, Future industry
Identifiers
urn:nbn:se:hh:diva-57648 (URN)10.1109/FiCloud66139.2025.00081 (DOI)979-8-3315-5437-8 (ISBN)
Conference
12th International Conference on Future Internet of Things and Cloud (FiCloud), Istanbul, Turkey, 11-13 August 2025
Available from: 2025-10-23 Created: 2025-10-23 Last updated: 2025-11-05Bibliographically approved
Ali, H. I., Kurunathan, H., Eldefrawy, M. H., Gruian, F. & Jonsson, M. (2025). Navigating the Challenges and Opportunities of Securing Internet of Autonomous Vehicles With Lightweight Authentication. IEEE Access, 13, 24207-24222
Open this publication in new window or tab >>Navigating the Challenges and Opportunities of Securing Internet of Autonomous Vehicles With Lightweight Authentication
Show others...
2025 (English)In: IEEE Access, E-ISSN 2169-3536, Vol. 13, p. 24207-24222Article in journal (Refereed) Published
Abstract [en]

The Internet of Things (IoT) can be defined as the network of physical objects, or “things,” embedded with sensors and software for processing and exchanging data with other devices and ecosystems using the Internet as a medium. With its rapid growth over the past decade, it has permeated several application domains, including intelligent vehicular systems. The Internet of Autonomous Vehicles (IoAV) is a subset of IoT that envisions dynamic autonomous driving without human intervention. The dynamic nature of the environment in which autonomous vehicles operate introduces significant challenges, such as real-time communication and security vulnerabilities. These challenges cannot be directly addressed by standard cybersecurity solutions designed primarily for static IoT environments. In this work, we outline the various vulnerabilities of the IoAV systems, and we delve into the critical importance of adopting lightweight security protocols. These protocols are crucial to ensure robust protection while at the same time not jeopardizing the performance of the IoAV system. We also highlight the fast lightweight security protocols implemented on heterogeneous embedded, low-power, high-performance computing platforms as a viable solution to address these challenges. © The authors.

Place, publisher, year, edition, pages
Piscataway: IEEE, 2025
Keywords
Lightweight authentication, Internet of Autonomous Vehicles (IoAV), embedded systems
National Category
Embedded Systems Security, Privacy and Cryptography
Identifiers
urn:nbn:se:hh:diva-55512 (URN)10.1109/access.2025.3537800 (DOI)001420679000008 ()2-s2.0-85217540895 (Scopus ID)
Funder
Halmstad UniversityNordForskEU, Horizon Europe, TRB/2022/00061-C645463824-00000063; 101139789
Note

Funding:

Halmstad University (Högskolan i Halmstad) Research Base Funding

NordForsk 86220 through the Proposal HI2OT: Nordic University Hub on Industrial Internet of Things

Research Centre in Real-Time and Embedded Computing Systems (CISTER) Research Unit financed by National Funds through Fundacao para a Ciencia e a Tecnologia (FCT)/Ministry of Science, Technology and Higher Education (MCTES) (Portuguese Foundation for Science and Technology) (Grant Number: UIDP/UIDB/04234/2020)

Project Route 25 funded by the EU/Next Generation within Call 02/C05-i01/2022 of the Recovery and Resilience Plan (RRP) and Hardware Abstraction Layer for a European Software Defined Vehicle Approach (HAL4SDV) Funding within the Chips Joint Undertaking (Chips JU)—The Public-Private Partnership for Research, Development and Innovation under Horizon Europe—and National Authorities (Grant Number: TRB/2022/00061-C645463824-00000063 and 101139789)

Available from: 2025-02-21 Created: 2025-02-21 Last updated: 2025-10-01Bibliographically approved
Pankaczi, L. & Eldefrawy, M. H. (2023). Enhancing the Security of ISO/IEC 14443-3 and 4 RFID Authentication Protocols through Formal Analysis. In: 2023 IEEE International Conference on Omni-Layer Intelligent Systems, COINS 2023: . Paper presented at 2023 IEEE International Conference on Omni-Layer Intelligent Systems, COINS 2023, Berlin, Germany, 23-25 July, 2023. IEEE
Open this publication in new window or tab >>Enhancing the Security of ISO/IEC 14443-3 and 4 RFID Authentication Protocols through Formal Analysis
2023 (English)In: 2023 IEEE International Conference on Omni-Layer Intelligent Systems, COINS 2023, IEEE, 2023Conference paper, Published paper (Refereed)
Abstract [en]

Due to cyber attacks targeting RFID systems, this paper briefly summarizes parts 3 and 4 of the ISO/IEC 14443 standard, which specify the initialization, selection, and trans-mission protocols in high-frequency RFID smart-card and reader communication. The communication has been modeled, and two experiments have been performed using a security protocol ana-lyzer tool called Scyther. The protocol verification results shows that implementing Random UID can prevent many RFID attacks, such as eavesdropping and replay attacks and successfully protect the cardholder's privacy. © 2023 IEEE.

Place, publisher, year, edition, pages
IEEE, 2023
Keywords
Mutual Authentication, Random UID, RFID, Scyther
National Category
Communication Systems
Identifiers
urn:nbn:se:hh:diva-51581 (URN)10.1109/COINS57856.2023.10189283 (DOI)2-s2.0-85167865478 (Scopus ID)9798350346473 (ISBN)979-8-3503-4648-0 (ISBN)
Conference
2023 IEEE International Conference on Omni-Layer Intelligent Systems, COINS 2023, Berlin, Germany, 23-25 July, 2023
Available from: 2023-09-05 Created: 2023-09-05 Last updated: 2025-10-01Bibliographically approved
Aboelwafa, M. M. N., Seddik, K. G., Eldefrawy, M. H., Gadallah, Y. & Gidlund, M. (2020). A Machine-Learning-Based Technique for False Data Injection Attacks Detection in Industrial IoT. IEEE Internet of Things Journal, 7(9), 8462-8471
Open this publication in new window or tab >>A Machine-Learning-Based Technique for False Data Injection Attacks Detection in Industrial IoT
Show others...
2020 (English)In: IEEE Internet of Things Journal, ISSN 2327-4662, Vol. 7, no 9, p. 8462-8471Article in journal (Refereed) Published
Abstract [en]

The accelerated move toward the adoption of the Industrial Internet-of-Things (IIoT) paradigm has resulted in numerous shortcomings as far as security is concerned. One of the IIoT affecting critical security threats is what is termed as the false data injection (FDI) attack. The FDI attacks aim to mislead the industrial platforms by falsifying their sensor measurements. FDI attacks have successfully overcome the classical threat detection approaches. In this article, we present a novel method of FDI attack detection using autoencoders (AEs). We exploit the sensor data correlation in time and space, which in turn can help identify the falsified data. Moreover, the falsified data are cleaned using the denoising AEs (DAEs). Performance evaluation proves the success of our technique in detecting FDI attacks. It also significantly outperforms a support vector machine (SVM)-based approach used for the same purpose. The DAE data cleaning algorithm is also shown to be very effective in recovering clean data from corrupted (attacked) data. © 2014 IEEE.

Place, publisher, year, edition, pages
Piscataway: Institute of Electrical and Electronics Engineers (IEEE), 2020
Keywords
Correlation, Support vector machines, Security, Training, Noise reduction, Feature extraction, Autoencoders (AEs), false data injection (FDI) attacks, Industrial Internet-of-Things (IIoT) security, machine learning (ML), support vector machine (SVM)
National Category
Computer Systems
Identifiers
urn:nbn:se:hh:diva-43561 (URN)10.1109/JIOT.2020.2991693 (DOI)000571765000052 ()2-s2.0-85090794242 (Scopus ID)
Funder
The Swedish Foundation for International Cooperation in Research and Higher Education (STINT), IB2018-7469
Available from: 2020-11-30 Created: 2020-11-30 Last updated: 2025-10-01Bibliographically approved
Tirumaladass, V., Axelsson, S., Dougherty, M., Rasool, M. A. & Eldefrawy, M. H. (2020). Deep learning-based Electromagnetic Side-Channel Analysis for the Investigation of IoT Devices. In: Proceedings of the 2nd International Conference on Inventive Research in Computing Applications, ICIRCA 2020: . Paper presented at 2nd International Conference on Inventive Research in Computing Applications, ICIRCA 2020, Coimbatore, India, 15-17 July, 2020 (pp. 150-156). Piscataway: IEEE
Open this publication in new window or tab >>Deep learning-based Electromagnetic Side-Channel Analysis for the Investigation of IoT Devices
Show others...
2020 (English)In: Proceedings of the 2nd International Conference on Inventive Research in Computing Applications, ICIRCA 2020, Piscataway: IEEE, 2020, p. 150-156Conference paper, Published paper (Refereed)
Abstract [en]

The boom of Internet of Things (IoT) devices has brought along new security concerns which earlier were not thought of. This has expanded the potential for digital forensic investigators to gather rich evidence from these sources. The data on these IoT devices is not easily accessible due to the lack of proper techniques to investigate such devices. This paper presents a sophisticated non-invasive method to investigate IoT devices. The software activities running on a device can be inspected by observing the electromagnetic radiation emitted from the devices during the process. The objective of this project is to evaluate if it is possible to classify the software activities being run on an IoT device by performing an electromagnetic side-channel analysis (EM-SCA). This paper presents a methodology for analyzing the EM side-channels and classifying encryption algorithms being run on a Raspberry Pi 4. This work demonstrates that the cryptographic encryptions can be classified with over 95% accuracy by using deep neural network-based classifiers. © 2020 IEEE.

Place, publisher, year, edition, pages
Piscataway: IEEE, 2020
Keywords
acoustics classification, ensemble bagged trees, gravel roads, loose gravel, road maintenance, Digital forensics, Internet of Things, Multi-layer perceptron, Neural networks, Side-channel analysis
National Category
Communication Systems
Identifiers
urn:nbn:se:hh:diva-46504 (URN)10.1109/ICIRCA48905.2020.9182814 (DOI)2-s2.0-85092057620 (Scopus ID)9781728153742 (ISBN)
Conference
2nd International Conference on Inventive Research in Computing Applications, ICIRCA 2020, Coimbatore, India, 15-17 July, 2020
Funder
Vinnova
Note

ACKNOWLEDGMENT: The work was supported by Vinnova and the School of Information Technology at Halmstad University which was the backbone for completion of this project.

Available from: 2022-05-09 Created: 2022-05-09 Last updated: 2025-10-01Bibliographically approved
Gidlund, M., Hancke, G. P., Eldefrawy, M. H. & Åkerberg, J. (2020). Guest Editorial: Security, Privacy, and Trust for Industrial Internet of Things. IEEE Transactions on Industrial Informatics, 16(1), 625-628
Open this publication in new window or tab >>Guest Editorial: Security, Privacy, and Trust for Industrial Internet of Things
2020 (English)In: IEEE Transactions on Industrial Informatics, ISSN 1551-3203, E-ISSN 1941-0050, Vol. 16, no 1, p. 625-628Article in journal, Editorial material (Other academic) Published
Abstract [en]

This Special Section on "Security, privacy, and trust for Industrial Internet of Things" of the IEEE Transactions on Industrial Informatics (TII) highlights the main research challenges in the industrial Internet of Things (IoT) security, privacy, and trust. The designated nine high-quality research articles cover a wide range of the special section theme, including innovative solutions and novel technologies. These articles are briefly summarized. © 2019 IEEE.

Place, publisher, year, edition, pages
Piscataway, NJ: IEEE, 2020
Keywords
Special issues and sections, Encryption, Protocols, Internet of Things, Digital twin, Computer architecture, Security, Privacy
National Category
Control Engineering Computer Sciences Robotics and automation
Identifiers
urn:nbn:se:hh:diva-41478 (URN)10.1109/TII.2019.2953241 (DOI)000508428900060 ()2-s2.0-85078292831 (Scopus ID)
Available from: 2020-01-31 Created: 2020-01-31 Last updated: 2025-10-01Bibliographically approved
Gebremichael, T., Ledwaba, L. P. I., Eldefrawy, M. H., Hancke, G. P., Pereira, N., Gidlund, M. & Akerberg, J. (2020). Security and Privacy in the Industrial Internet of Things: Current Standards and Future Challenges. IEEE Access, 8, 152351-152366
Open this publication in new window or tab >>Security and Privacy in the Industrial Internet of Things: Current Standards and Future Challenges
Show others...
2020 (English)In: IEEE Access, E-ISSN 2169-3536, Vol. 8, p. 152351-152366Article in journal (Refereed) Published
Abstract [en]

The Internet of Things (IoT) is rapidly becoming an integral component of the industrial market in areas such as automation and analytics, giving rise to what is termed as the Industrial IoT (IIoT). The IIoT promises innovative business models in various industrial domains by providing ubiquitous connectivity, efficient data analytics tools, and better decision support systems for a better market competitiveness. However, IIoT deployments are vulnerable to a variety of security threats at various levels of the connectivity and communications infrastructure. The complex nature of the IIoT infrastructure means that availability, confidentiality and integrity are difficult to guarantee, leading to a potential distrust in the network operations and concerns of loss of critical infrastructure, compromised safety of network end-users and privacy breaches on sensitive information. This work attempts to look at the requirements currently specified for a secure IIoT ecosystem in industry standards, such as Industrial Internet Consortium (IIC) and OpenFog Consortium, and to what extent current IIoT connectivity protocols and platforms hold up to the standards with regard to security and privacy. The paper also discusses possible future research directions to enhance the security, privacy and safety of the IIoT.

Place, publisher, year, edition, pages
Piscataway, N.J.: IEEE, 2020
Keywords
Protocols, Cryptography, Standards, Privacy, Internet of Things, Peer-to-peer computing, Industrial Internet of Things, IIoT, industrial networks, security and privacy
National Category
Communication Systems
Identifiers
urn:nbn:se:hh:diva-43562 (URN)10.1109/ACCESS.2020.3016937 (DOI)000564158100001 ()2-s2.0-85090760213 (Scopus ID)
Funder
The Swedish Foundation for International Cooperation in Research and Higher Education (STINT), PRP/036/19FX
Available from: 2020-11-30 Created: 2020-11-30 Last updated: 2025-10-01Bibliographically approved
Eldefrawy, M. H., Ferrari, N. & Gidlund, M. (2019). Dynamic User Authentication Protocol for Industrial IoT without Timestamping. In: 2019 15TH IEEE INTERNATIONAL WORKSHOP ON FACTORY COMMUNICATION SYSTEMS (WFCS): . Paper presented at 15th IEEE International Workshop on Factory Communication Systems (WFCS 2019), Sundsvall, Sweden, May 27-29, 2019. Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Dynamic User Authentication Protocol for Industrial IoT without Timestamping
2019 (English)In: 2019 15TH IEEE INTERNATIONAL WORKSHOP ON FACTORY COMMUNICATION SYSTEMS (WFCS), Institute of Electrical and Electronics Engineers (IEEE), 2019Conference paper, Published paper (Refereed)
Abstract [en]

Internet of Things (IoT) technology has drawn the attention of the industry, where it has been able to, and still can, solve many industrial intractable issues. However, the emerging technology suffers from severe security shortcomings. Authentication is a cornerstone of IoT security, as it presents the measures of checking the legitimacy of communication entities. The Industrial IoT (IIoT) technology has special conditions, resulting from a lack of resources and a shortage of security skills. As far as we can tell, from the literature, IIoT user authentication has not been studied extensively. In 2017 Tai et al. presented an authenticated key agreement for IoT networks. Here we prove that Tai et al. scheme is susceptible to sever security weaknesses, such as; i. unknown key share attacks, ii. node capturing attacks, iii node information secrecy. In this research article, we offer an innovative IIoT user authentication protocol that can achieve secure remote user authentication without timestamping requiring precise synchronization, our protocol only needs Hashing and Xor-ing. We examine the efficiency of the presented protocol using Tmote Sky node over an MSP430 microcontroller using a COOJA simulator. we also show its correctness using the Scyther verification tool.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2019
Keywords
Remote User Authentication, IIoT Security, Formal Scyther Analysis
National Category
Communication Systems
Identifiers
urn:nbn:se:hh:diva-41465 (URN)10.1109/WFCS.2019.8757984 (DOI)000490866300013 ()2-s2.0-85070082936 (Scopus ID)978-1-7281-1268-8 (ISBN)978-1-7281-1269-5 (ISBN)
Conference
15th IEEE International Workshop on Factory Communication Systems (WFCS 2019), Sundsvall, Sweden, May 27-29, 2019
Available from: 2020-01-31 Created: 2020-01-31 Last updated: 2025-10-01Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0001-6408-5152

Search in DiVA

Show all publications