

de Recherche et d’Innovation
en Cybersécurité et Société
Moradi, A.; Zhu, Y.; Falk, T. H.
Towards Lightweight On-Device Audio Deepfake Detection Using Squeezeformers Article d'actes
Dans: K., Adi; O., Nguena Timo; N., Boulahia-Cuppens; D., Espes; N., Stakhanova; M., Omar (Ed.): Lect. Notes Comput. Sci., p. 376–389, Springer Science and Business Media Deutschland GmbH, 2026, ISBN: 03029743 (ISSN); 978-303220731-9 (ISBN), (Journal Abbreviation: Lect. Notes Comput. Sci.).
Résumé | Liens | BibTeX | Étiquettes: Audio DeepFake Detection, Detection mechanism, Edge Computing, Edge detection, Foundation models, High-accuracy, Large scale systems, Large-scale systems, Lightweight, Memory footprint, Performance, Real- time
@inproceedings{moradiLightweightOnDeviceAudio2026,
title = {Towards Lightweight On-Device Audio Deepfake Detection Using Squeezeformers},
author = {A. Moradi and Y. Zhu and T. H. Falk},
editor = {Adi K. and Nguena Timo O. and Boulahia-Cuppens N. and Espes D. and Stakhanova N. and Omar M.},
url = {https://www.scopus.com/pages/publications/105046137533?origin=resultslist},
doi = {10.1007/978-3-032-20732-6_24},
isbn = {03029743 (ISSN); 978-303220731-9 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Lect. Notes Comput. Sci.},
volume = {16295 LNCS},
pages = {376–389},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {The increasing threat of audio deepfakes necessitates detection mechanisms that can operate in real-time on resource-constrained edge devices. While large-scale systems, such as detectors based on speech foundation models, have demonstrated high accuracy, their computational and memory footprints make them ill-suited for on-device applications. This paper addresses this critical gap by investigating the key factors that influence the performance of lightweight deepfake detection models. We conduct a systematic comparison of model architectures, input feature choices, and data augmentation techniques, evaluating both deepfake detection accuracy and computational complexity across three datasets. Our findings show that with proper modeling choices, a lightweight model can achieve performance comparable to that of a much larger model while being approximately 100× smaller in size. This work provides actionable insights for developing efficient and effective audio deepfake detectors tailored for the constraints of edge computing. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.},
note = {Journal Abbreviation: Lect. Notes Comput. Sci.},
keywords = {Audio DeepFake Detection, Detection mechanism, Edge Computing, Edge detection, Foundation models, High-accuracy, Large scale systems, Large-scale systems, Lightweight, Memory footprint, Performance, Real- time},
pubstate = {published},
tppubtype = {inproceedings}
}
Boudra, N.; Elhajjout, A.; Moudoud, H.; Oujaoura, M.; Jarir, Z.; Houda, Z. A. El
Toward Lightweight IoC Extraction in IoT: The Role of Small Language Models Article d'actes
Dans: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833157801-5 (ISBN), (Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY).
Résumé | Liens | BibTeX | Étiquettes: Artificial intelligence, Cyber threats, Data-source, Edge Computing, extraction, Indicator of compromize, Indicators of Compromise, Information retrieval, Information Security, IoT Security, Language model, Malware, Natural languages, Network security, Program processors, Resource Constraint, Resource Constraints, Semantics, Small language model, Small Language Models, Threat Intelligence
@inproceedings{boudraLightweightIoCExtraction2025,
title = {Toward Lightweight IoC Extraction in IoT: The Role of Small Language Models},
author = {N. Boudra and A. Elhajjout and H. Moudoud and M. Oujaoura and Z. Jarir and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105037622873?origin=resultslist},
doi = {10.1109/SmartAgriSuSY68475.2025.11466843},
isbn = {979-833157801-5 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The proliferation of cyber threats necessitates rapid and accurate extraction of Indicators of Compromise (IoCs) from diverse security data sources. While Large Language Models (LLMs) have demonstrated exceptional capabilities in natural language processing and information extraction tasks, their deployment on resource-constrained IoT devices remains challenging due to computational and memory requirements. This paper investigates whether Small Language Models (SLMs) can serve as effective alternatives to LLMs for IoC extraction in IoT environments with limited resources. We present a novel direct LLM-based IoC extraction system leveraging context memory mechanisms for document-wide semantic understanding, specifically designed for deployment on edge computing infrastructure with consumer-grade hardware. Our experimental setup utilizes an RTX 4080 GPU and Ryzen 7 7700X processor running the Ollama framework with GPT-OSS:20B model to evaluate the feasibility of using smaller models instead of resource-intensive LLMs for security tasks. Evaluated on 9 diverse threat intelligence reports spanning different malware families and attack campaigns, the system achieved an average F1 score of 0.62, precision of 0.54, recall of 0.79, and accuracy of 0.85, demonstrating that SLMs can achieve acceptable accuracy levels for IoC extraction while operating within the computational constraints typical of IoT edge deployments. The results suggest that smaller models may provide viable alternatives to large language models for distributed threat intelligence processing in resource-limited environments. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
keywords = {Artificial intelligence, Cyber threats, Data-source, Edge Computing, extraction, Indicator of compromize, Indicators of Compromise, Information retrieval, Information Security, IoT Security, Language model, Malware, Natural languages, Network security, Program processors, Resource Constraint, Resource Constraints, Semantics, Small language model, Small Language Models, Threat Intelligence},
pubstate = {published},
tppubtype = {inproceedings}
}
Moudoud, H.; Houda, Z. A. El; Brik, B.
A Blockchain-Based Cross-Domain DDoS Mitigation in Consumer Networks Article de journal
Dans: IEEE Transactions on Consumer Electronics, vol. 71, no 2, p. 7095–7104, 2025, ISSN: 00983063 (ISSN).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Consumer network, Denial-of-service attack, digital twins, Distributed denial of service, Edge Computing, Fuzzy logic, Fuzzy-Logic, Inter-domain, Internet service providers, Network function virtualization, Network functions, NFV, Platform as a Service (PaaS), Resources sharing, SDN, Software-defined networkings, Virtualizations
@article{moudoudBlockchainBasedCrossDomainDDoS2025,
title = {A Blockchain-Based Cross-Domain DDoS Mitigation in Consumer Networks},
author = {H. Moudoud and Z. A. El Houda and B. Brik},
url = {https://www.scopus.com/pages/publications/105002613162?origin=resultslist},
doi = {10.1109/TCE.2025.3559451},
issn = {00983063 (ISSN)},
year = {2025},
date = {2025-01-01},
journal = {IEEE Transactions on Consumer Electronics},
volume = {71},
number = {2},
pages = {7095–7104},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Distributed Denial of Service (DDoS) attacks pose significant threats to the availability and security of consumer networks and Internet service providers (ISPs). This is a significant concern due to the potential vulnerabilities and security risks associated with the rapid increase in the number of insecure Internet of Things (IoT) devices. Adopting an inter-domain DDoS collaboration strategy is a promising solution to address this issue. However, manual configuration and management of resources across multiple domains can be time-consuming, error-prone, and inefficient. Moreover, the existing inter-domain DDoS mitigation mechanisms (i.e., Cooperative Defense mechanisms) are facing obstacles due to the lack of incentives for cooperation, low flexibility, and high cost. Most importantly, many of them are centralized, which risks single points of failure, hampering collaboration and resource sharing among Autonomous Systems (ASs). The new emerging techniques, such as Digital-Twin (DT) empowered by Network Function Virtualization (NFV), Software-Defined Networking (SDN), and Blockchain introduce new opportunities for efficient and flexible inter-domain DDoS collaboration i.e., resources sharing among multiple SDN-based domains. In this context, we propose SecureShare, a novel digital twin-enabled inter-domain DDoS mitigation framework that allows for an efficient, fair, and secure dynamic resource-sharing among SDN-based domains to deal with large-scale DDoS attacks through resource sharing. The deployment of SecureShare is executed within Ethereum’s test network, Sepolia. Furthermore, we performed extensive experiments employing Microsoft Azure Digital Twins (ADT), a platform-as-a-service tool for generating twin graphs of physical objects. The experimental results show that SecureShare achieves promising results in terms of efficiency, security, and flexibility. © 1975-2011 IEEE.},
keywords = {Block-chain, Blockchain, Consumer network, Denial-of-service attack, digital twins, Distributed denial of service, Edge Computing, Fuzzy logic, Fuzzy-Logic, Inter-domain, Internet service providers, Network function virtualization, Network functions, NFV, Platform as a Service (PaaS), Resources sharing, SDN, Software-defined networkings, Virtualizations},
pubstate = {published},
tppubtype = {article}
}



