

de Recherche et d’Innovation
en Cybersécurité et Société
Malasi, J. -J. M.; Moudoud, H.; Missaoui, R.
CausalGraph: When Causal Reasoning Meets Large Language Models for Intrusion Detection Systems Article d'actes
Dans: Dig Tech Pap IEEE Int Conf Consum Electron, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 0747668X (ISSN); 979-833155343-2 (ISBN), (Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron).
Résumé | Liens | BibTeX | Étiquettes: Alarm systems, Budget control, causal reasoning, Chains, Computer crime, Concept Drift, Concept drifts, Conformal Risk Control, Counterfactuals, Generative AI, Human computer interaction, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, Knowledge based systems, Language model, LLM, LLMs, Network intrusion, Network security, Risks controls, Sampling
@inproceedings{malasiCausalGraphWhenCausal2026,
title = {CausalGraph: When Causal Reasoning Meets Large Language Models for Intrusion Detection Systems},
author = {J. -J. M. Malasi and H. Moudoud and R. Missaoui},
url = {https://www.scopus.com/pages/publications/105037367854?origin=resultslist},
doi = {10.1109/ICCE67443.2026.11449614},
isbn = {0747668X (ISSN); 979-833155343-2 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Dig Tech Pap IEEE Int Conf Consum Electron},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Modern intrusion detection systems often achieve impressive benchmark accuracy yet fail in real-world deployment, where network behavior and attacker tactics continuously evolve. Under concept drift, decision boundaries learned offline can diverge from operational reality, triggering false-alarm cascades and creating detection blind spots that erode analyst trust. In this paper, we propose CausalGraph-IDS, a causal and language-model-assisted intrusion detection framework that moves beyond purely correlational scoring by explicitly verifying multi-stage attack chains. Additionally, we propose CHAIN-CRC, a unified algorithm that (i) learns a constrained attack-chain causal graph guided by knowledge-based priors derived from widely used adversary behavior taxonomies, (ii) computes robustness scores by testing whether alarms persist under feasible counterfactual security interventions, and (iii) applies conformal risk control to enforce operator-defined false-positive budgets with finite-sample guarantees.Generative models are integrated in strictly assistive roles through three modules: prior induction to distill causal constraints from unstructured threat reports, counterfactual generation to propose realistic and operationally feasible interventions, and causal logic justification to produce human-readable explanations grounded in the learned attack chain. Experiments on two widely used network intrusion detection benchmarks show that CausalGraph-IDS provides robust, explainable, and risk-governed detection, maintaining strong recall at low false-positive rates while delivering actionable causal insights for mitigation. © 2026 IEEE.},
note = {Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron},
keywords = {Alarm systems, Budget control, causal reasoning, Chains, Computer crime, Concept Drift, Concept drifts, Conformal Risk Control, Counterfactuals, Generative AI, Human computer interaction, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, Knowledge based systems, Language model, LLM, LLMs, Network intrusion, Network security, Risks controls, Sampling},
pubstate = {published},
tppubtype = {inproceedings}
}
Zoungrana, A. F.; Moudoud, H.; Tajeuna, E. G.; Adi, K.
Adversarial Ensemble Framework: Leveraging GANs for Robust Intrusion Detection in IoT Networks Article d'actes
Dans: K., Adi; O., Nguena Timo; N., Boulahia-Cuppens; D., Espes; N., Stakhanova; M., Omar (Ed.): Lect. Notes Comput. Sci., p. 85–99, Springer Science and Business Media Deutschland GmbH, 2026, ISBN: 03029743 (ISSN); 978-303220731-9 (ISBN), (Journal Abbreviation: Lect. Notes Comput. Sci.).
Résumé | Liens | BibTeX | Étiquettes: Adversarial networks, Class imbalance, Computer crime, Concept drifts, Gallium nitride, Generative adversarial networks, Internet of thing network, Internet of things, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, IoT Networks, Key Issues, Network intrusion, Network security, Rapid expansion, Security, Security challenges
@inproceedings{zoungranaAdversarialEnsembleFramework2026,
title = {Adversarial Ensemble Framework: Leveraging GANs for Robust Intrusion Detection in IoT Networks},
author = {A. F. Zoungrana and H. Moudoud and E. G. Tajeuna and K. Adi},
editor = {Adi K. and Nguena Timo O. and Boulahia-Cuppens N. and Espes D. and Stakhanova N. and Omar M.},
url = {https://www.scopus.com/pages/publications/105046136116?origin=resultslist},
doi = {10.1007/978-3-032-20732-6_6},
isbn = {03029743 (ISSN); 978-303220731-9 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Lect. Notes Comput. Sci.},
volume = {16295 LNCS},
pages = {85–99},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {The rapid expansion of Internet of Things (IoT) devices introduces complex security challenges that traditional intrusion detection systems struggle to address. This paper proposes an Adversarial Ensemble Framework using Generative Adversarial Networks (GANs) to improve the accuracy and resilience of intrusion detection in IoT environments. The framework tackles key issues such as class imbalance, concept drift, and adversarial attacks by employing multiple GAN variants such as Vanilla GAN, Conditional GAN (CGAN), and Wasserstein GAN (WGAN) to generate high-quality synthetic attack data. A dynamic ensemble learning mechanism selects the most effective model for each attack type based on performance metrics. Experiments on NSL-KDD and CIC-IDS2017 show that WGAN yields the most effective synthetic data, contributing to a detection rate of up to 96%. The approach proves particularly effective in identifying rare attacks, making it a scalable and adaptive solution for IoT security. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.},
note = {Journal Abbreviation: Lect. Notes Comput. Sci.},
keywords = {Adversarial networks, Class imbalance, Computer crime, Concept drifts, Gallium nitride, Generative adversarial networks, Internet of thing network, Internet of things, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, IoT Networks, Key Issues, Network intrusion, Network security, Rapid expansion, Security, Security challenges},
pubstate = {published},
tppubtype = {inproceedings}
}



