Publications
publications by categories in reversed chronological order. generated by jekyll-scholar.
2025
-
ReGAIN: Retrieval-Grounded AI Framework for Network Traffic AnalysisShaghayegh Shajarian, Kennedy Marsh, James Benson, and 2 more authorsarXiv preprint arXiv:2512.22223, 2025Modern networks generate vast, heterogeneous traff ic that must be continuously analyzed for security and performance. Traditional network traffic analysis systems, whether rule-based or machine learning–driven, often suffer from high false positives and lack interpretability, limiting analyst trust. In this paper, we present ReGAIN, a multi-stage framework that combines traffic summarization, retrieval-augmented generation (RAG), and Large Language Model (LLM) reasoning for transparent and accurate network traffic analysis. ReGAIN creates natural-language summaries from network traffic, embeds them into a multi-collection vector database, and utilizes a hierarchical retrieval pipeline to ground LLM responses with evidence citations. The pipeline features metadata-based filtering, MMR sampling, a two-stage cross-encoder reranking mechanism, and an abstention mechanism to reduce hallucinations and ensure grounded reasoning. Evaluated on ICMP ping flood and TCP SYN flood traces from the real-world traffic dataset, it demonstrates robust performance, achieving accuracy between 95.95% and 98.82% across different attack types and evaluation benchmarks. These results are validated against two complementary sources: dataset ground truth and human expert assessments. ReGAIN also outperforms rule-based, classical ML, and deep learning baselines while providing unique explainability through trustworthy, verifiable responses.
@article{shajarian2025regain, title = {ReGAIN: Retrieval-Grounded AI Framework for Network Traffic Analysis}, author = {Shajarian, Shaghayegh and Marsh, Kennedy and Benson, James and Khorsandroo, Sajad and Abdelsalam, Mahmoud}, journal = {arXiv preprint arXiv:2512.22223}, year = {2025}, publisher = {arXiv}, primaryclass = {cs.CR}, dimensions = {true}, } -
Towards Autonomous Network Management: AI-Driven Framework for Intelligent Log Analysis, Troubleshooting and DocumentationShaghayegh ShajarianIn Proceedings of the AAAI Conference on Artificial Intelligence, 2025As modern network management grows increasingly complex, administrators are tasked with navigating vast volumes of log data, often resulting in inefficiencies, errors, and operational challenges. My doctoral research addresses these pressing issues by leveraging advanced AI techniques to minimize human intervention and pave the way for fully automated network operations. I propose a novel AI-driven framework that integrates Large Language Models (LLMs) with Retrieval-Augmented Generation (RAG) and a human-in-the-loop process to effectively automate key network management tasks, including log analysis, troubleshooting recommendations, and documentation generation. By enhancing the accuracy and efficiency of these tasks, this study aims to improve network reliability, reduce operational complexity, and contribute to the evolution of self-running networks.
-
Self-Running Networks: A Comprehensive Survey of Foundations, Applications, and ChallengesShaghayegh Shajarian, Sajad Khorsandroo, and Mahmoud AbdelsalamAuthorea Preprints, 2025Self-running networks represent a groundbreaking paradigm for achieving fully autonomous network infrastructures capable of self-configuration, self-optimization, self-healing, and self-protection without human intervention. Although numerous isolated studies have explored aspects of self-running networks, an integrated and holistic overview is still lacking. This survey addresses this gap by providing a comprehensive system-level exposition, formalizing the concept of self-running networks, and detailing the architectural components that enable end-to-end autonomy through a unified seven-layer reference model. We also analyze the key self-* functionalities, including their core mechanisms, operational challenges, and representative application domains. Furthermore, we propose a six-level network autonomy maturity model to evaluate the evolution of network intelligence from manual operations to fully autonomous systems. We further synthesize foundational paradigms and practical implementations, providing a consolidated view of current advancements. In addition, we discuss critical challenges in self-running networks, including security, scalability, interoperability, and ethical considerations. Finally, we highlight research directions and open issues to guide future innovations and accelerate the deployment of self-running networks in real-world environments. This work serves as a conceptual and practical reference for researchers, practitioners, and industry stakeholders aiming to design, deploy, and advance next-generation self-running networks.
@article{shajarian2025survey, title = {Self-Running Networks: A Comprehensive Survey of Foundations, Applications, and Challenges}, author = {Shajarian, Shaghayegh and Khorsandroo, Sajad and Abdelsalam, Mahmoud}, journal = {Authorea Preprints}, year = {2025}, publisher = {techRxiv}, primaryclass = {cs.CR}, dimensions = {true}, } -
Explainable artificial intelligence (xai) for malware analysis: A survey of techniques, applications, and open challengesHarikha Manthena, Shaghayegh Shajarian, Jeffrey Kimmell, and 3 more authorsIEEE Access, 2025Machine learning (ML) has rapidly advanced in recent years, revolutionizing fields such as finance, medicine, and cybersecurity. In malware detection, ML-based approaches have demonstrated high accuracy; however, their lack of transparency poses a significant challenge. Traditional ML models often fail to provide interpretable justifications for their predictions, limiting their adoption in security-critical environments where understanding the reasoning behind a detection is essential for threat mitigation and response. Explainable AI (XAI) addresses this gap by enhancing model interpretability while maintaining strong detection capabilities. This survey presents a comprehensive review of stateof-the-art ML techniques for malware analysis, with a specific focus on explainability methods and research mainly from 2018 to 2024. We examine existing XAI frameworks, their application in malware classification and detection, and the challenges associated with making malware detection models more interpretable. Additionally, we explore recent advancements and highlight open research challenges in the field of explainable malware analysis. By providing a structured overview of XAI-driven malware detection approaches, this survey serves as a valuable resource for researchers and practitioners seeking to bridge the gap between ML performance and explainability in cybersecurity.
@article{manthena2025explainable, title = {Explainable artificial intelligence (xai) for malware analysis: A survey of techniques, applications, and open challenges}, author = {Manthena, Harikha and Shajarian, Shaghayegh and Kimmell, Jeffrey and Abdelsalam, Mahmoud and Khorsandroo, Sajad and Gupta, Maanak}, journal = {IEEE Access}, year = {2025}, publisher = {IEEE}, dimensions = {true}, }
2024
-
Poster: Intelligent Network Management: RAG-Enhanced LLMs for Log Analysis, Troubleshooting, and DocumentationShaghayegh Shajarian, Sajad Khorsandroo, and Mahmoud AbdelsalamIn Proceedings of the 20th International Conference on emerging Networking EXperiments and Technologies, 2024Modern network management is increasingly complex, requiring administrators to handle vast amounts of log data from diverse sources, leading to inefficiencies, errors, and operational challenges. In this work, we propose a novel AI-driven framework that integrates Large Language Models (LLMs) with Retrieval-Augmented Generation (RAG) and human-in-the-loop process to automate network management tasks such as log analysis, troubleshooting recommendations, and documentation generation. This study aims to enhance network reliability, reduce operational complexity, and move forward to autonomous network management.
@inproceedings{shajarian2024poster, title = {Poster: Intelligent Network Management: RAG-Enhanced LLMs for Log Analysis, Troubleshooting, and Documentation}, author = {Shajarian, Shaghayegh and Khorsandroo, Sajad and Abdelsalam, Mahmoud}, booktitle = {Proceedings of the 20th International Conference on emerging Networking EXperiments and Technologies}, pages = {27--28}, year = {2024}, publisher = {ACM}, primaryclass = {cs.CR}, dimensions = {true}, } -
Transfer learning with ResNet50 for malicious domains classification using image visualizationFikirte Ayalke Demmese, Shaghayegh Shajarian, and Sajad KhorsandrooDiscover Artificial Intelligence, 2024The Internet has become a vital part of our daily lives, serving as a hub for global connectivity and a facilitator for seamless communication and information exchange. However, the rise of malicious domains presents a serious challenge, undermining the reliability of the Internet and posing risks to user safety. These malicious activities exploit the Domain Name System (DNS) to deceive users, leading to harmful activities such as spreading drive-by-download malware, operating botnets, creating phishing sites, and sending spam. In response to this growing threat, the application of Machine Learning (ML) techniques has proven to be highly effective. These methods excel in quickly and accurately detecting, classifying, and analyzing such threats. This paper explores the latest developments in using transfer learning for the classification of malicious domains, with a focus on image visualization as a key methodological approach. Our proposed solution has achieved a remarkable testing accuracy rate of 98.67%, demonstrating its effectiveness in detecting and classifying malicious domains.
@article{demmese2024transfer, title = {Transfer learning with ResNet50 for malicious domains classification using image visualization}, author = {Demmese, Fikirte Ayalke and Shajarian, Shaghayegh and Khorsandroo, Sajad}, journal = {Discover Artificial Intelligence}, volume = {4}, number = {1}, pages = {52}, year = {2024}, publisher = {Springer}, dimensions = {true}, }