Mid Sweden University

miun.sePublications
Change search
Link to record
Permanent link

Direct link
Shahzad, Raja KhurramORCID iD iconorcid.org/0000-0003-2806-9694
Publications (5 of 5) Show all publications
Ayusinta, R., Jolak, R. & Shahzad, R. K. (2026). Broken Access Control Risks in Open Source Javascript Projects: A Security Analysis. In: Proceedings - 2026 IEEE International Conference on Software Analysis, Evolution and Reengineering - Companion, SANER-C 2026: . Paper presented at 2026 IEEE International Conference on Software Analysis, Evolution and Reengineering - Companion, SANER-C 2026 (pp. 222-229). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Broken Access Control Risks in Open Source Javascript Projects: A Security Analysis
2026 (English)In: Proceedings - 2026 IEEE International Conference on Software Analysis, Evolution and Reengineering - Companion, SANER-C 2026, Institute of Electrical and Electronics Engineers (IEEE), 2026, p. 222-229Conference paper, Published paper (Refereed)
Abstract [en]

Context: Broken Access Control (BAC) is ranked by OWASP as the most critical web security risk. Open-source JavaScript projects, with their openness and diverse contributors, are particularly exposed. Objective: This study investigates the prevalence and patterns of BAC vulnerabilities in open-source JavaScript projects, addressing the lack of empirical evidence beyond enterprise systems. Method: A hybrid approach combined Semgrep static analysis with manual penetration testing. A curated set of 166 GitHub repositories was scanned using custom rules for Insecure Direct Object Reference (IDOR), unprotected routes, forced browsing, and token/session flaws; flagged cases were validated in Docker with Postman. Results: Static analysis flagged 33 repositories as potentially vulnerable, of which 5 were confirmed to contain exploitable BAC vulnerabilities through manual penetration testing. Confirmed issues included unauthenticated endpoints, parameter-based privilege escalation, and insecure token or Cross-Origin Resource Sharing (CORS) handling. Static analysis was useful, but showed high false positives and limited contextual accuracy. Conclusion: BAC vulnerabilities recur in open-source JavaScript projects. Static tools aid in detection but require manual validation for reliable assessment. 

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2026
Keywords
Broken Access Control, JavaScript, Penetration Testing, Security, Semgrep, Static Analysis
National Category
Computer and Information Sciences
Identifiers
urn:nbn:se:miun:diva-57844 (URN)10.1109/SANER-C67878.2026.00036 (DOI)2-s2.0-105040703027 (Scopus ID)9798331585891 (ISBN)
Conference
2026 IEEE International Conference on Software Analysis, Evolution and Reengineering - Companion, SANER-C 2026
Available from: 2026-06-24 Created: 2026-06-24 Last updated: 2026-06-24Bibliographically approved
Shahzad, R. K., Ström, E. & Mozelius, P. (2026). DIFA : AI-Assisted Formative Feedback for Scalable Pedagogy. In: 4th Symposium on AI Opportunities and Challenges  (SAIOC 2026): After the bubble, a more mature appreciation of AI? Booklet of Keynote Speaker Outlines and Presentation Abstracts. Paper presented at 4th Symposium on AI Opportunities and Challenges (SAIOC 2026), Online Symposium, 16th of June, 2026 (pp. 27-27). Academic Conferences and Publishing International Limited, 4
Open this publication in new window or tab >>DIFA : AI-Assisted Formative Feedback for Scalable Pedagogy
2026 (English)In: 4th Symposium on AI Opportunities and Challenges  (SAIOC 2026): After the bubble, a more mature appreciation of AI? Booklet of Keynote Speaker Outlines and Presentation Abstracts, Academic Conferences and Publishing International Limited, 2026, Vol. 4, p. 27-27Conference paper, Oral presentation with published abstract (Refereed)
Abstract [en]

The Draft-Based Iterative Feedback Accelerator (DIFA) is an AI-enhanced extension of the FAMS (Shahzad et al., 2023), which is designed to address challenges in providing scalable, high-quality formative feedback in higher education. Formative feedback is crucial for metacognitive development and self-regulated learning, yet its effective implementation is often limited in large cohorts, particularly for neurodiverse learners who need structured and transparent feedback. Moreover, the rise in students' reliance on generative AI raises concerns about deep learning, highlighting the need for assessment designs that promote meaningful cognitive engagement. DIFA transforms AI from a passive tool into an active pedagogical assistant within the feedback loop. It allows students to submit ongoing, incomplete work for evaluation, shifting focus from outcome-oriented grading to a process centered on reflection and continuous improvement. DIFA features reusable feedback fragments and a repository of common errors.

DIFA offers a modern approach to feedback by processing student drafts to generate context-specific responses that instructors can refine. This makes iterative feedback cycles more manageable within existing workloads. It enhances the Feedback and Assessment Management System (FAMS) by using natural language processing (NLP) to automate the categorization of feedback and create descriptive titles, improving organization and retrieval. When predefined feedback is unavailable, a lightweight language model trained on historical data generates relevant and clear responses, transforming the system into an adaptive feedback generator.

The architecture employs a teacher-in-the-loop approach where AI-generated feedback serves as a draft for instructors to review and refine. This ensures that AI enhances, rather than replaces, educators' professional judgment. By integrating AI into organizing and refining feedback, the DIFA system creates a continuous, data-driven feedback cycle that lightens instructors' workloads while delivering timely, personalized responses. Moreover, incorporating AI within a structured assessment framework helps prevent students' misuse of generative AI, positioning it as a tool for genuine learning.

Preliminary results show that this AI-enhanced architecture improves feedback delivery while maintaining the necessary depth and personalization for effective formative assessment. The DIFA system allows for iterative revisions rather than just final outputs, illustrating how explainable AI can enhance educational expertise. Future developments will include a student-facing interface that focuses on adaptive explanations and interactive feedback for neurodiverse learners

Place, publisher, year, edition, pages
Academic Conferences and Publishing International Limited, 2026
Keywords
AI-enhanced feedback, Formative feedback, Iterative feedback, Natural language processing, DIFA
National Category
Educational Work
Identifiers
urn:nbn:se:miun:diva-57994 (URN)
Conference
4th Symposium on AI Opportunities and Challenges (SAIOC 2026), Online Symposium, 16th of June, 2026
Available from: 2026-06-29 Created: 2026-06-29 Last updated: 2026-07-03Bibliographically approved
Rogell, L., Ho-Quang, T., Shahzad, R. K. & Jolak, R. (2026). Eliminating trust in the cloud: Design, implementation and evaluation of an end-to-end encrypted Git service. Array, 31, 101030-101030, Article ID 101030.
Open this publication in new window or tab >>Eliminating trust in the cloud: Design, implementation and evaluation of an end-to-end encrypted Git service
2026 (English)In: Array, ISSN 2590-0056, Vol. 31, p. 101030-101030, article id 101030Article in journal (Refereed) Published
Abstract [en]

Cloud computing has become a cornerstone of modern technology, offering on-demand and scalable access to shared computational resources. As critical infrastructure increasingly migrates to cloud environments, concerns regarding data privacy and security have intensified. Users often need to trust service providers, despite risks like unauthorized access, insider threats, and data breaches. This study presents Git as a use-case of trust-dependent cloud services and investigates the potential of an end-to-end encrypted Git service on trust assumptions, security guarantees, and application performance. A prototype (E2Git) was designed to enforce end-to-end encryption at the application layer by encrypting repository contents and metadata on the client side, and automating key distribution across users and workstations, under the assumption of a fully covert adversary with complete access to the cloud infrastructure. The prototype’s security features and performance characteristics were evaluated in comparison with existing secure Git solutions. Although the E2Git prototype incurs elevated resource overhead during push operations, due to retransmission of a monolithically encrypted and compressed repository snapshot, it strengthens confidentiality and reduces server trust assumptions for repository contents and Git metadata. Notably, the E2Git prototype outperforms the standard Git client in terms of execution time during clone and fetch operations. These findings highlight the feasibility of trustless version control and the application of end-to-end encryption to secure sensitive data and enhance privacy in cloud environments.

Keywords
Cloud security, Encryption, Trustless services, Data privacy, Version control
National Category
Computer Engineering
Identifiers
urn:nbn:se:miun:diva-58067 (URN)10.1016/j.array.2026.101030 (DOI)001810945400001 ()2-s2.0-105042649357 (Scopus ID)
Available from: 2026-07-02 Created: 2026-07-02 Last updated: 2026-08-13Bibliographically approved
Shahzad, R. K., Ström, E. & Mozelius, P. (2023). FAMS: A Formative Assessment Management System for Generating Individualised Feedback. In: Olga Viberg, Ioana Jivet, Pedro J. Muñoz-Merino, Maria Perifanou, Tina Papathoma (Ed.), Responsive and Sustainable Educational Futures: 18th European Conference on Technology Enhanced Learning, EC-TEL 2023 Aveiro, Portugal, September 4–8, 2023, Proceedings. Paper presented at 18th European Conference on Technology Enhanced Learning, EC-TEL 2023 Aveiro, Portugal, September 4–8, 2023 (pp. 642-647). Springer
Open this publication in new window or tab >>FAMS: A Formative Assessment Management System for Generating Individualised Feedback
2023 (English)In: Responsive and Sustainable Educational Futures: 18th European Conference on Technology Enhanced Learning, EC-TEL 2023 Aveiro, Portugal, September 4–8, 2023, Proceedings / [ed] Olga Viberg, Ioana Jivet, Pedro J. Muñoz-Merino, Maria Perifanou, Tina Papathoma, Springer, 2023, p. 642-647Conference paper, Published paper (Refereed)
Abstract [en]

Virtual learning environments offer new possibilities for technology enhanced teaching and learning, but providing rapid, individualised feedback for complex assignments in large student groups remains challenging. This paper presents a Formative Assessment Management System (FAMS), a computer-based tool for teachers to generate written feedback at scale with minimal overhead. FAMS leverages archived feedback fragments and thematic identifiers to create pertinent feedback while consistently maintaining quality and fairness. The system has been implemented in programming courses and yielded promising results, including reduced feedback delivery time and maintained feedback quality. Future research will evaluate FAMS from student and teacher perspectives, conforming to educational action research, continuous quality improvements, and investigating correlations between aspect-based assessment and learning outcomes.

Place, publisher, year, edition, pages
Springer, 2023
Series
Lecture Notes in Computer Science, ISSN 0302-9743, E-ISSN 1611-3349
Keywords
Formative assessment, Individualised feedback, Archived feedback, Technology enhanced learning, Educational action research
National Category
Educational Sciences Computer and Information Sciences
Identifiers
urn:nbn:se:miun:diva-49265 (URN)10.1007/978-3-031-42682-7_55 (DOI)001351067800053 ()2-s2.0-85171995108 (Scopus ID)978-3-031-42682-7 (ISBN)
Conference
18th European Conference on Technology Enhanced Learning, EC-TEL 2023 Aveiro, Portugal, September 4–8, 2023
Available from: 2023-09-11 Created: 2023-09-11 Last updated: 2025-09-25Bibliographically approved
Shahzad, R. K. (2018). Android malware detection using feature fusion and artificial data. In: Proceedings - IEEE 16th International Conference on Dependable, Autonomic and Secure Computing, IEEE 16th International Conference on Pervasive Intelligence and Computing, IEEE 4th International Conference on Big Data Intelligence and Computing and IEEE 3rd Cyber Science and Technology Congress, DASC-PICom-DataCom-CyberSciTec 2018: . Paper presented at 16th IEEE International Conference on Dependable, Autonomic and Secure Computing, IEEE 16th International Conference on Pervasive Intelligence and Computing, IEEE 4th International Conference on Big Data Intelligence and Computing and IEEE 3rd Cyber Science and Technology Congress, DASC-PICom-DataCom-CyberSciTec 2018; Athens; Greece; 12 August 2018 through 15 August 2018 (pp. 702-709). , Article ID 8511966.
Open this publication in new window or tab >>Android malware detection using feature fusion and artificial data
2018 (English)In: Proceedings - IEEE 16th International Conference on Dependable, Autonomic and Secure Computing, IEEE 16th International Conference on Pervasive Intelligence and Computing, IEEE 4th International Conference on Big Data Intelligence and Computing and IEEE 3rd Cyber Science and Technology Congress, DASC-PICom-DataCom-CyberSciTec 2018, 2018, p. 702-709, article id 8511966Conference paper, Published paper (Refereed)
Abstract [en]

For the Android malware detection / classification anti-malware community has relied on traditional malware detection methods as a countermeasure. However, traditional detection methods are developed for detecting the computer malware, which is different from Android malware in structure and characteristics. Thus, they may not be useful for Android malware detection. Moreover, majority of suggested detection approaches may not be generalized and are incapable of detecting zero-day malware due to different reasons such as available data set with specific set of examples. Thus, their detection accuracy may be questionable. To address this problem, this paper presents a malware classification approach with a reliable detection accuracy and evaluate the approach using artificially generated examples. The suggested approach generates the signature profiles and behavior profiles of each application in the data set, which are further used as input for the classification task. For improving the detection accuracy, feature fusion of features from filter methods and wrapper method and algorithm fusion is investigated. Without affecting the detection accuracy, the optimal balance between real world examples and synthetic examples is also investigated. The experimental results suggest that both AUC and F1 can be obtained up to 0.94 for both known and unknown malware using original examples and synthetic examples.

National Category
Computer and Information Sciences
Identifiers
urn:nbn:se:miun:diva-35144 (URN)10.1109/DASC/PiCom/DataCom/CyberSciTec.2018.00123 (DOI)000450146600108 ()2-s2.0-85056882366 (Scopus ID)
Conference
16th IEEE International Conference on Dependable, Autonomic and Secure Computing, IEEE 16th International Conference on Pervasive Intelligence and Computing, IEEE 4th International Conference on Big Data Intelligence and Computing and IEEE 3rd Cyber Science and Technology Congress, DASC-PICom-DataCom-CyberSciTec 2018; Athens; Greece; 12 August 2018 through 15 August 2018
Available from: 2018-12-10 Created: 2018-12-10 Last updated: 2025-09-25Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0003-2806-9694

Search in DiVA

Show all publications