

de Recherche et d’Innovation
en Cybersécurité et Société
Elhajjout, A.; Jarir, Z.; Moudoud, H.; Davoust, A.; Houda, Z. A. El
Leveraging Large Language Models for Contextual Threat Hypothesis Generation in IoT Networks Article d'actes
Dans: Dig Tech Pap IEEE Int Conf Consum Electron, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 0747668X (ISSN); 979-833155343-2 (ISBN), (Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron).
Résumé | Liens | BibTeX | Étiquettes: Alert Triage, Cybersecurity, Hypotheses generation, Internet of thing security, Internet of things, IoT Security, Language model, Large datasets, Large language model, large language models, Network security, Prompt Engineering, Security alerts, Security operation center, Security Operations, Security systems, Threat Hypothesis Generation
@inproceedings{elhajjoutLeveragingLargeLanguage2026,
title = {Leveraging Large Language Models for Contextual Threat Hypothesis Generation in IoT Networks},
author = {A. Elhajjout and Z. Jarir and H. Moudoud and A. Davoust and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105037351870?origin=resultslist},
doi = {10.1109/ICCE67443.2026.11449914},
isbn = {0747668X (ISSN); 979-833155343-2 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Dig Tech Pap IEEE Int Conf Consum Electron},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Modern Security Operations Centers face numerous challenges in managing the volume and complexity of security alerts from Internet of Things (IoT) networks. While traditional rule-based systems excel at detection, they provide limited contextual reasoning to help analysts understand ambiguous alerts. Large Language Models (LLMs) have shown promise across various cybersecurity domains. However, their potential to generate rich, explanatory threat hypotheses for ambiguous IoT alerts remains largely unexplored. To address these issues, in this paper, we present a systematic investigation of Large Language Model-based threat hypothesis generation with three key contributions. First, we introduce a context-aware structured prompting framework capable of synthesizing heterogeneous device telemetry into coherent threat narratives. Second, we formalize the assessment of explainability in security through a rigorous multidimensional quality metric system. Third, we provide the first comparative analysis of five state-of-the-art models on real-world IoT incidents, revealing critical performance tradeoffs. Results show that GPT-4o-mini achieves 88.2% accuracy on diverse attack types, while Qwen 3-235B achieves 95.2% accuracy on network-focused attacks. Statistical analysis reveals significant model-dataset interactions. These findings show that properly guided Large Language Models can augment analyst capabilities by providing detailed, contextual explanations that facilitate efficient alert triage. © 2026 IEEE.},
note = {Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron},
keywords = {Alert Triage, Cybersecurity, Hypotheses generation, Internet of thing security, Internet of things, IoT Security, Language model, Large datasets, Large language model, large language models, Network security, Prompt Engineering, Security alerts, Security operation center, Security Operations, Security systems, Threat Hypothesis Generation},
pubstate = {published},
tppubtype = {inproceedings}
}
Boudra, N.; Elhajjout, A.; Moudoud, H.; Oujaoura, M.; Jarir, Z.; Houda, Z. A. El
Toward Lightweight IoC Extraction in IoT: The Role of Small Language Models Article d'actes
Dans: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833157801-5 (ISBN), (Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY).
Résumé | Liens | BibTeX | Étiquettes: Artificial intelligence, Cyber threats, Data-source, Edge Computing, extraction, Indicator of compromize, Indicators of Compromise, Information retrieval, Information Security, IoT Security, Language model, Malware, Natural languages, Network security, Program processors, Resource Constraint, Resource Constraints, Semantics, Small language model, Small Language Models, Threat Intelligence
@inproceedings{boudraLightweightIoCExtraction2025,
title = {Toward Lightweight IoC Extraction in IoT: The Role of Small Language Models},
author = {N. Boudra and A. Elhajjout and H. Moudoud and M. Oujaoura and Z. Jarir and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105037622873?origin=resultslist},
doi = {10.1109/SmartAgriSuSY68475.2025.11466843},
isbn = {979-833157801-5 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The proliferation of cyber threats necessitates rapid and accurate extraction of Indicators of Compromise (IoCs) from diverse security data sources. While Large Language Models (LLMs) have demonstrated exceptional capabilities in natural language processing and information extraction tasks, their deployment on resource-constrained IoT devices remains challenging due to computational and memory requirements. This paper investigates whether Small Language Models (SLMs) can serve as effective alternatives to LLMs for IoC extraction in IoT environments with limited resources. We present a novel direct LLM-based IoC extraction system leveraging context memory mechanisms for document-wide semantic understanding, specifically designed for deployment on edge computing infrastructure with consumer-grade hardware. Our experimental setup utilizes an RTX 4080 GPU and Ryzen 7 7700X processor running the Ollama framework with GPT-OSS:20B model to evaluate the feasibility of using smaller models instead of resource-intensive LLMs for security tasks. Evaluated on 9 diverse threat intelligence reports spanning different malware families and attack campaigns, the system achieved an average F1 score of 0.62, precision of 0.54, recall of 0.79, and accuracy of 0.85, demonstrating that SLMs can achieve acceptable accuracy levels for IoC extraction while operating within the computational constraints typical of IoT edge deployments. The results suggest that smaller models may provide viable alternatives to large language models for distributed threat intelligence processing in resource-limited environments. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
keywords = {Artificial intelligence, Cyber threats, Data-source, Edge Computing, extraction, Indicator of compromize, Indicators of Compromise, Information retrieval, Information Security, IoT Security, Language model, Malware, Natural languages, Network security, Program processors, Resource Constraint, Resource Constraints, Semantics, Small language model, Small Language Models, Threat Intelligence},
pubstate = {published},
tppubtype = {inproceedings}
}
Soultana, O. A.; Moudoud, H.
Adaptive Heterogeneous Ensemble Learning for Attack Detection in IoT Networks Article d'actes
Dans: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern., p. 27–32, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 1062922X (ISSN); 979-833153358-8 (ISBN), (Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.).
Résumé | Liens | BibTeX | Étiquettes: Attack detection, Classification (of information), Computational efficiency, Detection accuracy, Ensemble learning, Ensemble techniques, Heterogeneous ensembles, Internet of thing security, Internet of things, Intrusion Detection, Intrusion-Detection, IoT Security, Learning systems, Nearest neighbor search, Security vulnerabilities, Stackings, Support vector machines, Zero-day attack, Zero-day detection
@inproceedings{soultanaAdaptiveHeterogeneousEnsemble2025,
title = {Adaptive Heterogeneous Ensemble Learning for Attack Detection in IoT Networks},
author = {O. A. Soultana and H. Moudoud},
url = {https://www.scopus.com/pages/publications/105033149093?origin=resultslist},
doi = {10.1109/SMC58881.2025.11343130},
isbn = {1062922X (ISSN); 979-833153358-8 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
pages = {27–32},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The proliferation of Internet of Things (IoT) devices has introduced significant security vulnerabilities, particularly in detecting zero-day attacks within highly dynamic and heterogeneous environments. Traditional machine learning models often fall short due to their static nature and computational demands. In this paper, we propose an adaptive ensemble learning framework that dynamically selects optimal detection models on a per-attack-class basis to improve detection accuracy while maintaining computational efficiency. Our approach combines multiple base classifiers (Random Forest, K-Nearest Neighbors, and Support Vector Machine) using ensemble techniques including bagging, boosting, and stacking. Ensemble techniques such as Bagging, Boosting, Voting, and Stacking. The key innovation lies in a class-aware model selection mechanism that identifies the most effective classifier-ensemble combination for each specific attack category, rather than applying a single model across all threat types. This targeted approach recognizes that different attack patterns exhibit distinct characteristics that may be better captured by different algorithmic approaches. Finally, we propose a decision-rule mechanism that selects the best-performing model for each attack class to improve detection accuracy. The proposed framework is evaluated through extensive experiments. The results show that our approach significantly enhances classification performance, especially for complex and rare attack types. © 2025 IEEE.},
note = {Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
keywords = {Attack detection, Classification (of information), Computational efficiency, Detection accuracy, Ensemble learning, Ensemble techniques, Heterogeneous ensembles, Internet of thing security, Internet of things, Intrusion Detection, Intrusion-Detection, IoT Security, Learning systems, Nearest neighbor search, Security vulnerabilities, Stackings, Support vector machines, Zero-day attack, Zero-day detection},
pubstate = {published},
tppubtype = {inproceedings}
}



