

de Recherche et d’Innovation
en Cybersécurité et Société
Moudoud, H.; Houda, Z. Abou El; Brik, B.
Advancing Privacy and Fairness in Healthcare Using Federated Edge Learning and Blockchain Article de journal
Dans: IEEE Internet of Things Journal, vol. 12, no 22, p. 46129–46137, 2025, ISSN: 23274662 (ISSN).
Résumé | Liens | BibTeX | Étiquettes: Artificial intelligence algorithms, Artificial intelligence techniques, Block-chain, Blockchain, cancer diagnosis, Diagnosis, Distributed computer systems, Federated edge learning, Health care, Healthcare, Healthcare systems, Internet of medical thing, Internet of Medical Things (IoMT), Learning systems, Medical computing, Medical data, Network security, Privacy, Sensitive data
@article{moudoudAdvancingPrivacyFairness2025,
title = {Advancing Privacy and Fairness in Healthcare Using Federated Edge Learning and Blockchain},
author = {H. Moudoud and Z. Abou El Houda and B. Brik},
url = {https://www.scopus.com/pages/publications/105012264671?origin=resultslist},
doi = {10.1109/JIOT.2025.3589179},
issn = {23274662 (ISSN)},
year = {2025},
date = {2025-01-01},
journal = {IEEE Internet of Things Journal},
volume = {12},
number = {22},
pages = {46129–46137},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {artificial intelligence (AI) has revolutionized many fields, including healthcare. The adoption of AI techniques in critical healthcare tasks, such as cancer diagnosis, holds great promise for revolutionizing the healthcare system. AI algorithms can be trained on vast datasets to recognize patterns, detect anomalies, and provide accurate assessments. However, the lack of realistic and up-to-date medical data poses a significant challenge to the widespread adoption of AI techniques. Additionally, privacy concerns surrounding sensitive medical data, particularly patient health records (PHRs), hinder data sharing among healthcare practitioners. This article aims to address these challenges by proposing a novel framework, entitled SecureMed, that uses federated learning (FL) and Blockchain to preserve privacy in the healthcare system. In particular, SecureMed consists of: 1) a novel distributed architecture that enables secure collaboration among multiple mobile edge computing (MEC)-based Internet of Medical Things (IoMT) devices, while ensuring the privacy of healthcare systems; 2) a fairness-aware FL solution to ensure that model performance is balanced across all participating healthcare institutions, addressing the issue of imbalanced data contributions; 3) a secure multiparty computation (SMPC) protocol to ensure secure aggregation of local model updates; and 4) a blockchain-based reputation model for collaborative FL training. The proposed framework leverages smart contracts to ensure trustworthiness, decentralization, and transparency in the FL process. The experimental results using the CIC IoMT dataset 2024 highlight the promising potential of SecureMed in revolutionizing healthcare systems. © 2014 IEEE.},
keywords = {Artificial intelligence algorithms, Artificial intelligence techniques, Block-chain, Blockchain, cancer diagnosis, Diagnosis, Distributed computer systems, Federated edge learning, Health care, Healthcare, Healthcare systems, Internet of medical thing, Internet of Medical Things (IoMT), Learning systems, Medical computing, Medical data, Network security, Privacy, Sensitive data},
pubstate = {published},
tppubtype = {article}
}
Mehrban, A.; Houda, Z. A. El; Moudoud, H.; Brik, B.; Khoukhi, L.
Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification Article d'actes
Dans: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC, p. 1570–1575, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833150887-6 (ISBN), (Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC).
Résumé | Liens | BibTeX | Étiquettes: Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks
@inproceedings{mehrbanSecuringORANEquipment2025,
title = {Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification},
author = {A. Mehrban and Z. A. El Houda and H. Moudoud and B. Brik and L. Khoukhi},
url = {https://www.scopus.com/pages/publications/105011364438?origin=resultslist},
doi = {10.1109/IWCMC65282.2025.11059692},
isbn = {979-833150887-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
pages = {1570–1575},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The Open Radio Access Network (O-RAN) architecture has enabled the integration of multi-vendor equipment, yielding a significant enhancement in the flexibility and interoperability of telecommunications networks. However, this openness has also introduced new security vulnerabilities, particularly in supply chain integrity. Malicious actors may exploit weaknesses at various stages of production, distribution, or integration, leading to critical threats such as data tampering, unauthorized access, and denial-of-service (DOS) attacks. To address these challenges, this paper proposes a novel blockchain-based framework designed to secure the O-RAN supply chain. The proposed solution leverages a private permissioned blockchain ledger and cryptographic firmware authentication to ensure the integrity and authenticity of network equipment throughout its lifecycle. Specifically, the framework consists of: (1) a decentralized architecture integrating blockchain network components, equipment node validators, and secure firmware authentication mechanisms; and (2) a consensus-based verification model to enhance trust and transparency within the supply chain. To the best of our knowledge, this is one of the first approaches to use blockchain for O-RAN supply chain security, and also addressing emerging security threats in a scalable and tamper-resistant manner. Experimental validation and security assessments demonstrate the effectiveness of the proposed framework in mitigating supply chain risks, making it a promising solution for ensuring trust and robustness in next-generation O-RAN ecosystems. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
keywords = {Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks},
pubstate = {published},
tppubtype = {inproceedings}
}
Amari, H.; Houda, Z. A. El; Moudoud, H.; Khoukhi, L.; Belguith, L. H.
Blockchain-Based Federated Learning for Enhanced Cyber-Threats Detection in Connected Vehicles Article d'actes
Dans: M., Valenti; D., Reed; M., Torres (Ed.): IEEE Int Conf Commun, p. 4257–4262, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 15503607 (ISSN); 979-833150521-9 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Central layers, Computer crime, Connected vehicle, Connected Vehicles, Cyber threats, Cyberthreat detection, Cyberthreats, Cyberthreats Detection, Data privacy, Federated learning, Intelligent transport, Intelligent vehicle highway systems, Internet of things, Intrusion Detection, Intrusion Detection Systems, Learning systems, Network security, SDN, Threat detection, Traffic control, Vehicles
@inproceedings{amariBlockchainBasedFederatedLearning2025,
title = {Blockchain-Based Federated Learning for Enhanced Cyber-Threats Detection in Connected Vehicles},
author = {H. Amari and Z. A. El Houda and H. Moudoud and L. Khoukhi and L. H. Belguith},
editor = {Valenti M. and Reed D. and Torres M.},
url = {https://www.scopus.com/pages/publications/105018456633?origin=resultslist},
doi = {10.1109/ICC52391.2025.11161266},
isbn = {15503607 (ISSN); 979-833150521-9 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {IEEE Int Conf Commun},
pages = {4257–4262},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Over the past few years, there have been made significant strides in advancing the Internet of Vehicles (IoV), recognizing its strategic importance in Intelligent Transport Systems. The proliferation of connected and autonomous vehicles on the roads has propelled the IoV into the spotlight. However, addressing the specific demands of vehicular networks, such as low latency, high mobility, extensive connectivity of 5G/6G networks, and robust security, remains a substantial challenge. Therefore, there is a critical need for substantial progress in implementing a resilient Intrusion Detection System within the IoV ecosystem. This paper introduces VFed-IDS, a decentralized, secure, flexible, scalable, and robust Blockchain and Federated Learning-based intrusion detection system. VFed-IDS is designed to identify cyber threats in the IoV while preserving privacy in connected vehicles. The proposed architecture consists of three main layers: the central layer, the local layer, and the Blockchain layer. The central layer includes the SDN Controller, responsible for training and aggregating the global model. The local layer comprises vehicles training individual models based on their private local datasets. The Blockchain layer introduces the Smart Contract VFed-SC, which manages the list of authenticated and collaborating vehicles in the Federated Learning process. It also hashes trained local model updates before transmitting them as transactions between the central and local layers. Simulation results demonstrate that VFed-IDS achieves a high accuracy rate of 99%, effectively enhancing the autonomous behavior of connected vehicles against cyber threats. © 2025 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Block-chain, Blockchain, Central layers, Computer crime, Connected vehicle, Connected Vehicles, Cyber threats, Cyberthreat detection, Cyberthreats, Cyberthreats Detection, Data privacy, Federated learning, Intelligent transport, Intelligent vehicle highway systems, Internet of things, Intrusion Detection, Intrusion Detection Systems, Learning systems, Network security, SDN, Threat detection, Traffic control, Vehicles},
pubstate = {published},
tppubtype = {inproceedings}
}
Moudoud, H.; Houda, Z. A. El; Brik, B.
Securing O-RAN with Zero Trust Architecture and Large Language Models Article d'actes
Dans: C., Iwendi; Z., Boulouard; N., Kryvinska (Ed.): Lect. Notes Networks Syst., p. 357–368, Springer Science and Business Media Deutschland GmbH, 2025, ISBN: 23673370 (ISSN); 978-303194619-6 (ISBN), (Journal Abbreviation: Lect. Notes Networks Syst.).
Résumé | Liens | BibTeX | Étiquettes: Access management, Access Management system, Architecture, Authentication, Block-chain, Blockchain, Computer architecture, Computer crime, Cryptography, Distributed computer systems, Intrusion Detection, Language model, Large language model, Management systems, Mobile security, Mobile telecommunication systems, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security systems, Security vulnerabilities, Trusted computing, Zero Trust
@inproceedings{moudoudSecuringORANZero2025,
title = {Securing O-RAN with Zero Trust Architecture and Large Language Models},
author = {H. Moudoud and Z. A. El Houda and B. Brik},
editor = {Iwendi C. and Boulouard Z. and Kryvinska N.},
url = {https://www.scopus.com/pages/publications/105011259647?origin=resultslist},
doi = {10.1007/978-3-031-94620-2_31},
isbn = {23673370 (ISSN); 978-303194619-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Lect. Notes Networks Syst.},
volume = {1312 LNNS},
pages = {357–368},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {The Open Radio Access Network (O-RAN) architecture is critical for the development of 6G networks, offering flexibility and interoperability through disaggregated components. However, this openness exposes O-RAN to new security vulnerabilities, including unauthorized access, data breaches, and malicious xApp deployments. To address these challenges, we propose DistillORAN, a novel Zero-Trust architecture designed specifically for O-RAN. DistillORAN features two core components: (1) a blockchain-based decentralized trust management system for secure verification, authentication, and dynamic access control of xApps, and (2) a lightweight intrusion detection module powered by DistilBERT, a transformer-based model optimized for resource-constrained environments. DistilBERT’s ability to analyze network activities and detect anomalies in real-time allows it to identify complex security threats and multi-step attack scenarios within the O-RAN ecosystem. Its lightweight nature makes it ideal for O-RAN’s distributed infrastructure, where computational resources may be limited. By combining blockchain technology for trust management with DistilBERT’s powerful pattern recognition for intrusion detection, DistillORAN enforces a Zero-Trust security model, ensuring continuous monitoring and verification of all network components. This comprehensive solution enhances the security and resilience of O-RAN networks, aligning with the dynamic needs of next-generation mobile infrastructures. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.},
note = {Journal Abbreviation: Lect. Notes Networks Syst.},
keywords = {Access management, Access Management system, Architecture, Authentication, Block-chain, Blockchain, Computer architecture, Computer crime, Cryptography, Distributed computer systems, Intrusion Detection, Language model, Large language model, Management systems, Mobile security, Mobile telecommunication systems, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security systems, Security vulnerabilities, Trusted computing, Zero Trust},
pubstate = {published},
tppubtype = {inproceedings}
}
Moudoud, H.; Houda, Z. A. El; Brik, B.
A Blockchain-Based Cross-Domain DDoS Mitigation in Consumer Networks Article de journal
Dans: IEEE Transactions on Consumer Electronics, vol. 71, no 2, p. 7095–7104, 2025, ISSN: 00983063 (ISSN).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Consumer network, Denial-of-service attack, digital twins, Distributed denial of service, Edge Computing, Fuzzy logic, Fuzzy-Logic, Inter-domain, Internet service providers, Network function virtualization, Network functions, NFV, Platform as a Service (PaaS), Resources sharing, SDN, Software-defined networkings, Virtualizations
@article{moudoudBlockchainBasedCrossDomainDDoS2025,
title = {A Blockchain-Based Cross-Domain DDoS Mitigation in Consumer Networks},
author = {H. Moudoud and Z. A. El Houda and B. Brik},
url = {https://www.scopus.com/pages/publications/105002613162?origin=resultslist},
doi = {10.1109/TCE.2025.3559451},
issn = {00983063 (ISSN)},
year = {2025},
date = {2025-01-01},
journal = {IEEE Transactions on Consumer Electronics},
volume = {71},
number = {2},
pages = {7095–7104},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Distributed Denial of Service (DDoS) attacks pose significant threats to the availability and security of consumer networks and Internet service providers (ISPs). This is a significant concern due to the potential vulnerabilities and security risks associated with the rapid increase in the number of insecure Internet of Things (IoT) devices. Adopting an inter-domain DDoS collaboration strategy is a promising solution to address this issue. However, manual configuration and management of resources across multiple domains can be time-consuming, error-prone, and inefficient. Moreover, the existing inter-domain DDoS mitigation mechanisms (i.e., Cooperative Defense mechanisms) are facing obstacles due to the lack of incentives for cooperation, low flexibility, and high cost. Most importantly, many of them are centralized, which risks single points of failure, hampering collaboration and resource sharing among Autonomous Systems (ASs). The new emerging techniques, such as Digital-Twin (DT) empowered by Network Function Virtualization (NFV), Software-Defined Networking (SDN), and Blockchain introduce new opportunities for efficient and flexible inter-domain DDoS collaboration i.e., resources sharing among multiple SDN-based domains. In this context, we propose SecureShare, a novel digital twin-enabled inter-domain DDoS mitigation framework that allows for an efficient, fair, and secure dynamic resource-sharing among SDN-based domains to deal with large-scale DDoS attacks through resource sharing. The deployment of SecureShare is executed within Ethereum’s test network, Sepolia. Furthermore, we performed extensive experiments employing Microsoft Azure Digital Twins (ADT), a platform-as-a-service tool for generating twin graphs of physical objects. The experimental results show that SecureShare achieves promising results in terms of efficiency, security, and flexibility. © 1975-2011 IEEE.},
keywords = {Block-chain, Blockchain, Consumer network, Denial-of-service attack, digital twins, Distributed denial of service, Edge Computing, Fuzzy logic, Fuzzy-Logic, Inter-domain, Internet service providers, Network function virtualization, Network functions, NFV, Platform as a Service (PaaS), Resources sharing, SDN, Software-defined networkings, Virtualizations},
pubstate = {published},
tppubtype = {article}
}
Mehrban, A.; Houda, Z. A. El; Moudoud, H.; Brik, B.; Khoukhi, L.
A Blockchain-Enabled Multi-Layered Zero-Trust Security Framework for O-RAN Article d'actes
Dans: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC, p. 1564–1569, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833150887-6 (ISBN), (Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC).
Résumé | Liens | BibTeX | Étiquettes: Access control, Block-chain, Blockchain, Data privacy, Federated learning, federated learning (FL), Internet of thing, Internet of things, Internet of Things (IoT), Interoperability, Learning systems, Mobile telecommunication systems, Multi-layered, Network architecture, Network security, Open access, Open radio access network, open radio access network (O-RAN), Radio, Radio access networks, Radio access technologies, Radio communication, Secure communication, Security, Security frameworks, Security risks, Transfer learning, Trusted computing
@inproceedings{mehrbanBlockchainEnabledMultiLayeredZeroTrust2025,
title = {A Blockchain-Enabled Multi-Layered Zero-Trust Security Framework for O-RAN},
author = {A. Mehrban and Z. A. El Houda and H. Moudoud and B. Brik and L. Khoukhi},
url = {https://www.scopus.com/pages/publications/105011345211?origin=resultslist},
doi = {10.1109/IWCMC65282.2025.11059720},
isbn = {979-833150887-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
pages = {1564–1569},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {O-RAN (Open Radio Access Network) is a set of open and interoperable radio access technologies, guided by the O-RAN Alliance, that, despite an open ecosystem, introduces significant security risks, expanding the threat surface in 6G networks. Traditional perimeter-based security approaches are inadequate for O-RAN's highly distributed, multi-vendor environments, where Zero Trust Architecture (ZTA) becomes essential for robust security. To address these challenges, we propose a novel blockchain-based, decentralized Zero-Trust Framework specifically designed for O-RAN security. Our proposed framework comprises two key layers: the first layer utilizes Federated Learning (FL) and Transfer Learning (TL) for advanced attack detection, enabling distributed, privacy-preserving threat analysis across O-RAN nodes. The second layer enforces Zero Trust access control through a blockchain-based identity management system, ensuring tamper-resistant, real-time policy updates. This multi-layered framework provides adaptive threat detection and resilient access control, validated through simulations demonstrating high detection accuracy and robust access management with minimal impact on network performance, offering a scalable security solution for next-generation O-RAN deployments. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
keywords = {Access control, Block-chain, Blockchain, Data privacy, Federated learning, federated learning (FL), Internet of thing, Internet of things, Internet of Things (IoT), Interoperability, Learning systems, Mobile telecommunication systems, Multi-layered, Network architecture, Network security, Open access, Open radio access network, open radio access network (O-RAN), Radio, Radio access networks, Radio access technologies, Radio communication, Secure communication, Security, Security frameworks, Security risks, Transfer learning, Trusted computing},
pubstate = {published},
tppubtype = {inproceedings}
}
Mehrban, A.; Moudoud, H.; Houda, Z. A. El
Zta-Driven Hierarchical Byzantine Consensus for Scalable O-Ran Supply Chain Security Article d'actes
Dans: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833157801-5 (ISBN), (Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Byzantine consensus, Firmware, Hierarchical Byzantine consensus, Multi-vendor, Network architecture, Network security, Open RAN, Open RAN (O-RAN), Permissioned blockchain, Supply chain security, Supply chains, Supply-chain attestation, Vendor interoperability, Zero-trust architecture, Zero-Trust Architecture (ZTA)
@inproceedings{mehrbanZtaDrivenHierarchicalByzantine2025,
title = {Zta-Driven Hierarchical Byzantine Consensus for Scalable O-Ran Supply Chain Security},
author = {A. Mehrban and H. Moudoud and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105037585759?origin=resultslist},
doi = {10.1109/SmartAgriSuSY68475.2025.11466868},
isbn = {979-833157801-5 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open RAN (O-RAN) multi-vendor interoperability continues to grow at a rapid pace, bringing flexibility and innovation but also increasing the attack surface. This makes O-RAN deployments vulnerable to supply chain infiltration and firmware tampering. Blockchain has emerged as a promising solution to provide an immutable and verifiable audit trail of equipment firmware hashes from manufacturing through deployment. However, conventional blockchain designs rely on all-to-all validator communication, which introduces scalability challenges and increases verification latency. To alleviate this issue, in this paper, we propose a scalable, efficient, and lightweight blockchain-enabled consensus framework, called H-BFT, to ensure supply chain security and attestation in O-RAN environments. H-BFT consists of three modules. The first module is a hierarchical consensus and attestation module that maps ZeroTrust Architecture (ZTA) microsegments (i.e., RU/DU/CU zones, near-real-time RIC clusters, and SMO domains) to validator committees. These committees verify local attestation events and produce concise summaries. The second module is a lightweight leader checkpointing module that periodically aggregates crosssegment digests, so that only compact validations become global, reducing communication and latency overhead. The third module is a blockchain-based audit and integrity enforcement module, where segment-level contracts enforce onboarding and integrity guarantees, and a checkpoint manager maintains consistency across the entire network. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
keywords = {Block-chain, Blockchain, Byzantine consensus, Firmware, Hierarchical Byzantine consensus, Multi-vendor, Network architecture, Network security, Open RAN, Open RAN (O-RAN), Permissioned blockchain, Supply chain security, Supply chains, Supply-chain attestation, Vendor interoperability, Zero-trust architecture, Zero-Trust Architecture (ZTA)},
pubstate = {published},
tppubtype = {inproceedings}
}



