

de Recherche et d’Innovation
en Cybersécurité et Société
Elhajjout, A.; Jarir, Z.; Moudoud, H.; Davoust, A.; Houda, Z. A. El
Leveraging Large Language Models for Contextual Threat Hypothesis Generation in IoT Networks Article d'actes
Dans: Dig Tech Pap IEEE Int Conf Consum Electron, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 0747668X (ISSN); 979-833155343-2 (ISBN), (Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron).
Résumé | Liens | BibTeX | Étiquettes: Alert Triage, Cybersecurity, Hypotheses generation, Internet of thing security, Internet of things, IoT Security, Language model, Large datasets, Large language model, large language models, Network security, Prompt Engineering, Security alerts, Security operation center, Security Operations, Security systems, Threat Hypothesis Generation
@inproceedings{elhajjoutLeveragingLargeLanguage2026,
title = {Leveraging Large Language Models for Contextual Threat Hypothesis Generation in IoT Networks},
author = {A. Elhajjout and Z. Jarir and H. Moudoud and A. Davoust and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105037351870?origin=resultslist},
doi = {10.1109/ICCE67443.2026.11449914},
isbn = {0747668X (ISSN); 979-833155343-2 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Dig Tech Pap IEEE Int Conf Consum Electron},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Modern Security Operations Centers face numerous challenges in managing the volume and complexity of security alerts from Internet of Things (IoT) networks. While traditional rule-based systems excel at detection, they provide limited contextual reasoning to help analysts understand ambiguous alerts. Large Language Models (LLMs) have shown promise across various cybersecurity domains. However, their potential to generate rich, explanatory threat hypotheses for ambiguous IoT alerts remains largely unexplored. To address these issues, in this paper, we present a systematic investigation of Large Language Model-based threat hypothesis generation with three key contributions. First, we introduce a context-aware structured prompting framework capable of synthesizing heterogeneous device telemetry into coherent threat narratives. Second, we formalize the assessment of explainability in security through a rigorous multidimensional quality metric system. Third, we provide the first comparative analysis of five state-of-the-art models on real-world IoT incidents, revealing critical performance tradeoffs. Results show that GPT-4o-mini achieves 88.2% accuracy on diverse attack types, while Qwen 3-235B achieves 95.2% accuracy on network-focused attacks. Statistical analysis reveals significant model-dataset interactions. These findings show that properly guided Large Language Models can augment analyst capabilities by providing detailed, contextual explanations that facilitate efficient alert triage. © 2026 IEEE.},
note = {Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron},
keywords = {Alert Triage, Cybersecurity, Hypotheses generation, Internet of thing security, Internet of things, IoT Security, Language model, Large datasets, Large language model, large language models, Network security, Prompt Engineering, Security alerts, Security operation center, Security Operations, Security systems, Threat Hypothesis Generation},
pubstate = {published},
tppubtype = {inproceedings}
}
Temmar, D. E.; Hamadene, A.; Nallaguntla, V.; Fursule, A.; Allili, M. S.; Kshirsagar, S.; Avila, A. R.
Phonetic Analysis of Real and Synthetic Speech Using HuBERT Embeddings: Perspectives for Deepfake Detection Article d'actes
Dans: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern., p. 86–91, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 1062922X (ISSN); 979-833153358-8 (ISBN), (Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.).
Résumé | Liens | BibTeX | Étiquettes: Artificial intelligence, Audio acoustics, Audio DeepFake Detection, Audio signal processing, Embeddings, Hu-BERT, KL-divergence, Linguistics, Phoneme and word Embedding, Phonetic analysis, Security systems, Self-Supervised Speech Representation, Speech analysis, Speech communication, Speech processing, Speech synthesis, Synthetic speech, Text to speech, Voice conversion
@inproceedings{temmarPhoneticAnalysisReal2025,
title = {Phonetic Analysis of Real and Synthetic Speech Using HuBERT Embeddings: Perspectives for Deepfake Detection},
author = {D. E. Temmar and A. Hamadene and V. Nallaguntla and A. Fursule and M. S. Allili and S. Kshirsagar and A. R. Avila},
url = {https://www.scopus.com/pages/publications/105033145913?origin=resultslist},
doi = {10.1109/SMC58881.2025.11343334},
isbn = {1062922X (ISSN); 979-833153358-8 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
pages = {86–91},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The growing sophistication of speech generated by Artificial Intelligence (AI) has introduced new challenges in audio deepfake detection. Text-to-speech (TTS) and voice conversion (VC) technologies can now produce convincing synthetic speech with high quality and intelligibility. This poses a serious threat to voice biometric security systems, such as automatic speaker recognition. It also increases the risks associated to the spread of spoken disinformation, where synthetic voices can be used to disseminate malicious content. In this study, we conduct an analysis of real and synthetic speech at phonetic and word levels. For that, a parallel dataset comprising real and synthetic speech signals were developed based on a subset of the LibriSpeech ASR corpus. Synthetic speech samples were generated using two TTS and one VC systems: Coqui TTS, VITS TTS, and StarGANv2 VC. We adopted HuBERT, a self-supervised speech model, to extract speech embeddings. The motivation for using this model stems from its ability to recognize sound units corresponding to the so-called pseudo phonemes. Our analysis is based on the KL divergence (KLD) between the distributions of synthetic and real phonemes, which allowed us to rank synthetic phonemes based on their alignment with their real counterpart. We also trained several classifiers per phoneme to distinguish between real and synthetic samples. We then compute the correlations between KLD and accuracies per phoneme. Besides showing a list of phonemes that are more discriminative, our findings suggest that vowels correlate better with the classifiers' performance, suggesting that the KLD can be an indicator of the most distinguishable phonemes for deepfake detection. © 2025 IEEE.},
note = {Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
keywords = {Artificial intelligence, Audio acoustics, Audio DeepFake Detection, Audio signal processing, Embeddings, Hu-BERT, KL-divergence, Linguistics, Phoneme and word Embedding, Phonetic analysis, Security systems, Self-Supervised Speech Representation, Speech analysis, Speech communication, Speech processing, Speech synthesis, Synthetic speech, Text to speech, Voice conversion},
pubstate = {published},
tppubtype = {inproceedings}
}
Mehrban, A.; Houda, Z. A. El; Moudoud, H.; Brik, B.; Khoukhi, L.
Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification Article d'actes
Dans: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC, p. 1570–1575, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833150887-6 (ISBN), (Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC).
Résumé | Liens | BibTeX | Étiquettes: Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks
@inproceedings{mehrbanSecuringORANEquipment2025,
title = {Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification},
author = {A. Mehrban and Z. A. El Houda and H. Moudoud and B. Brik and L. Khoukhi},
url = {https://www.scopus.com/pages/publications/105011364438?origin=resultslist},
doi = {10.1109/IWCMC65282.2025.11059692},
isbn = {979-833150887-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
pages = {1570–1575},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The Open Radio Access Network (O-RAN) architecture has enabled the integration of multi-vendor equipment, yielding a significant enhancement in the flexibility and interoperability of telecommunications networks. However, this openness has also introduced new security vulnerabilities, particularly in supply chain integrity. Malicious actors may exploit weaknesses at various stages of production, distribution, or integration, leading to critical threats such as data tampering, unauthorized access, and denial-of-service (DOS) attacks. To address these challenges, this paper proposes a novel blockchain-based framework designed to secure the O-RAN supply chain. The proposed solution leverages a private permissioned blockchain ledger and cryptographic firmware authentication to ensure the integrity and authenticity of network equipment throughout its lifecycle. Specifically, the framework consists of: (1) a decentralized architecture integrating blockchain network components, equipment node validators, and secure firmware authentication mechanisms; and (2) a consensus-based verification model to enhance trust and transparency within the supply chain. To the best of our knowledge, this is one of the first approaches to use blockchain for O-RAN supply chain security, and also addressing emerging security threats in a scalable and tamper-resistant manner. Experimental validation and security assessments demonstrate the effectiveness of the proposed framework in mitigating supply chain risks, making it a promising solution for ensuring trust and robustness in next-generation O-RAN ecosystems. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
keywords = {Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks},
pubstate = {published},
tppubtype = {inproceedings}
}
Moudoud, H.; Houda, Z. A. El; Khoukhi, L.; Mouftah, H. T.
An SDN-based Adaptive Ensemble Learning Framework for Intrusion Mitigation in Wireless Networks Article d'actes
Dans: M., Valenti; D., Reed; M., Torres (Ed.): IEEE Int Conf Commun, p. 554–559, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 15503607 (ISSN); 979-833150521-9 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Aerial vehicle, Antennas, Artificial intelligence, Computer crime, Ensemble learning, Intrusion Detection, Intrusion Detection Systems, Jamming, Jamming Attacks, Learning algorithms, Learning frameworks, Network intrusion, Network operations, Radio communication, Security systems, Security threats, Sensors network, Unmanned aerial vehicle, Unmanned Aerial Vehicles, Unmanned aerial vehicles (UAV), Wireless networks, Wireless sensor, Wireless Sensor Networks, Zero-day attack
@inproceedings{moudoudSDNbasedAdaptiveEnsemble2025,
title = {An SDN-based Adaptive Ensemble Learning Framework for Intrusion Mitigation in Wireless Networks},
author = {H. Moudoud and Z. A. El Houda and L. Khoukhi and H. T. Mouftah},
editor = {Valenti M. and Reed D. and Torres M.},
url = {https://www.scopus.com/pages/publications/105018460686?origin=resultslist},
doi = {10.1109/ICC52391.2025.11161745},
isbn = {15503607 (ISSN); 979-833150521-9 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {IEEE Int Conf Commun},
pages = {554–559},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Jamming attacks are among the most critical security threats to Wireless Sensor Networks (WSNs), as they can severely disrupt normal network operations, leading to data loss, network downtime, and reduced system performance. Intrusion Detection Systems (IDSs) have therefore become essential to protect WSNs. However, conventional IDSs often struggle to detect zero-day attacks, creating a significant security gap. To address this, Artificial Intelligence (AI)-based IDSs have been introduced, offering improved detection capabilities but frequently encountering high bias or variance issues, which reduce their reliability. Recently, ensemble learning (EL) has emerged as a promising approach to build more adaptable and data-resilient models by combining multiple learning algorithms. In this context, we propose AdaptiveBoost, an SDN-based Adaptive Ensemble Learning Framework, specifically designed for effective jamming attack detection in WSNs. The SDN integration allows AdaptiveBoost to optimize network traffic flow, identify anomalies in real-time, and adaptively fine-tune detection mechanisms based on current network conditions. We conduct several experiments to evaluate AdaptiveBoost using real-world WSN attacks; using the well-known public network security dataset, WSN-DS, show that AdaptiveBoost outperforms AI-based algorithms in terms of accuracy, precision, recall, and F1 score, while achieving a remarkable reduction in training time by a factor of 235, making it an efficient, scalable solution for securing WSNs against jamming attacks. © 2025 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Aerial vehicle, Antennas, Artificial intelligence, Computer crime, Ensemble learning, Intrusion Detection, Intrusion Detection Systems, Jamming, Jamming Attacks, Learning algorithms, Learning frameworks, Network intrusion, Network operations, Radio communication, Security systems, Security threats, Sensors network, Unmanned aerial vehicle, Unmanned Aerial Vehicles, Unmanned aerial vehicles (UAV), Wireless networks, Wireless sensor, Wireless Sensor Networks, Zero-day attack},
pubstate = {published},
tppubtype = {inproceedings}
}
Moudoud, H.; Houda, Z. A. El; Brik, B.
Securing O-RAN with Zero Trust Architecture and Large Language Models Article d'actes
Dans: C., Iwendi; Z., Boulouard; N., Kryvinska (Ed.): Lect. Notes Networks Syst., p. 357–368, Springer Science and Business Media Deutschland GmbH, 2025, ISBN: 23673370 (ISSN); 978-303194619-6 (ISBN), (Journal Abbreviation: Lect. Notes Networks Syst.).
Résumé | Liens | BibTeX | Étiquettes: Access management, Access Management system, Architecture, Authentication, Block-chain, Blockchain, Computer architecture, Computer crime, Cryptography, Distributed computer systems, Intrusion Detection, Language model, Large language model, Management systems, Mobile security, Mobile telecommunication systems, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security systems, Security vulnerabilities, Trusted computing, Zero Trust
@inproceedings{moudoudSecuringORANZero2025,
title = {Securing O-RAN with Zero Trust Architecture and Large Language Models},
author = {H. Moudoud and Z. A. El Houda and B. Brik},
editor = {Iwendi C. and Boulouard Z. and Kryvinska N.},
url = {https://www.scopus.com/pages/publications/105011259647?origin=resultslist},
doi = {10.1007/978-3-031-94620-2_31},
isbn = {23673370 (ISSN); 978-303194619-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Lect. Notes Networks Syst.},
volume = {1312 LNNS},
pages = {357–368},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {The Open Radio Access Network (O-RAN) architecture is critical for the development of 6G networks, offering flexibility and interoperability through disaggregated components. However, this openness exposes O-RAN to new security vulnerabilities, including unauthorized access, data breaches, and malicious xApp deployments. To address these challenges, we propose DistillORAN, a novel Zero-Trust architecture designed specifically for O-RAN. DistillORAN features two core components: (1) a blockchain-based decentralized trust management system for secure verification, authentication, and dynamic access control of xApps, and (2) a lightweight intrusion detection module powered by DistilBERT, a transformer-based model optimized for resource-constrained environments. DistilBERT’s ability to analyze network activities and detect anomalies in real-time allows it to identify complex security threats and multi-step attack scenarios within the O-RAN ecosystem. Its lightweight nature makes it ideal for O-RAN’s distributed infrastructure, where computational resources may be limited. By combining blockchain technology for trust management with DistilBERT’s powerful pattern recognition for intrusion detection, DistillORAN enforces a Zero-Trust security model, ensuring continuous monitoring and verification of all network components. This comprehensive solution enhances the security and resilience of O-RAN networks, aligning with the dynamic needs of next-generation mobile infrastructures. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.},
note = {Journal Abbreviation: Lect. Notes Networks Syst.},
keywords = {Access management, Access Management system, Architecture, Authentication, Block-chain, Blockchain, Computer architecture, Computer crime, Cryptography, Distributed computer systems, Intrusion Detection, Language model, Large language model, Management systems, Mobile security, Mobile telecommunication systems, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security systems, Security vulnerabilities, Trusted computing, Zero Trust},
pubstate = {published},
tppubtype = {inproceedings}
}



