

de Recherche et d’Innovation
en Cybersécurité et Société
Malasi, J. -J. M.; Moudoud, H.; Missaoui, R.
CausalGraph: When Causal Reasoning Meets Large Language Models for Intrusion Detection Systems Article d'actes
Dans: Dig Tech Pap IEEE Int Conf Consum Electron, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 0747668X (ISSN); 979-833155343-2 (ISBN), (Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron).
Résumé | Liens | BibTeX | Étiquettes: Alarm systems, Budget control, causal reasoning, Chains, Computer crime, Concept Drift, Concept drifts, Conformal Risk Control, Counterfactuals, Generative AI, Human computer interaction, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, Knowledge based systems, Language model, LLM, LLMs, Network intrusion, Network security, Risks controls, Sampling
@inproceedings{malasiCausalGraphWhenCausal2026,
title = {CausalGraph: When Causal Reasoning Meets Large Language Models for Intrusion Detection Systems},
author = {J. -J. M. Malasi and H. Moudoud and R. Missaoui},
url = {https://www.scopus.com/pages/publications/105037367854?origin=resultslist},
doi = {10.1109/ICCE67443.2026.11449614},
isbn = {0747668X (ISSN); 979-833155343-2 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Dig Tech Pap IEEE Int Conf Consum Electron},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Modern intrusion detection systems often achieve impressive benchmark accuracy yet fail in real-world deployment, where network behavior and attacker tactics continuously evolve. Under concept drift, decision boundaries learned offline can diverge from operational reality, triggering false-alarm cascades and creating detection blind spots that erode analyst trust. In this paper, we propose CausalGraph-IDS, a causal and language-model-assisted intrusion detection framework that moves beyond purely correlational scoring by explicitly verifying multi-stage attack chains. Additionally, we propose CHAIN-CRC, a unified algorithm that (i) learns a constrained attack-chain causal graph guided by knowledge-based priors derived from widely used adversary behavior taxonomies, (ii) computes robustness scores by testing whether alarms persist under feasible counterfactual security interventions, and (iii) applies conformal risk control to enforce operator-defined false-positive budgets with finite-sample guarantees.Generative models are integrated in strictly assistive roles through three modules: prior induction to distill causal constraints from unstructured threat reports, counterfactual generation to propose realistic and operationally feasible interventions, and causal logic justification to produce human-readable explanations grounded in the learned attack chain. Experiments on two widely used network intrusion detection benchmarks show that CausalGraph-IDS provides robust, explainable, and risk-governed detection, maintaining strong recall at low false-positive rates while delivering actionable causal insights for mitigation. © 2026 IEEE.},
note = {Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron},
keywords = {Alarm systems, Budget control, causal reasoning, Chains, Computer crime, Concept Drift, Concept drifts, Conformal Risk Control, Counterfactuals, Generative AI, Human computer interaction, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, Knowledge based systems, Language model, LLM, LLMs, Network intrusion, Network security, Risks controls, Sampling},
pubstate = {published},
tppubtype = {inproceedings}
}
Laamari, A.; Moudoud, H.; Houda, Z. A. El
Lightweight LLM Adaptation for Intrusion Detection via Token-Efficient Flow Representation Article d'actes
Dans: IEEE Conf. Artif. Intell., CAI, p. 2122–2127, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833156039-3 (ISBN), (Journal Abbreviation: IEEE Conf. Artif. Intell., CAI).
Résumé | Liens | BibTeX | Étiquettes: Classification (of information), Data flow analysis, Decoder-only large language model, Decoder-only LLMs, decoding, Flow classification, Intrusion Detection, Intrusion-Detection, Language model, Large language model, LLMs, LoRA, Low-rank adaptation, Network Flow Classification, Network intrusion, Network security, Networks flows, Qwen2.5, Signal encoding, T5-Small, Token-oriented object notation, Tokenization, TOON
@inproceedings{laamariLightweightLLMAdaptation2026,
title = {Lightweight LLM Adaptation for Intrusion Detection via Token-Efficient Flow Representation},
author = {A. Laamari and H. Moudoud and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105042133342?origin=resultslist},
doi = {10.1109/CAI68641.2026.11536533},
isbn = {979-833156039-3 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Conf. Artif. Intell., CAI},
pages = {2122–2127},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Large language models (LLMs) are emerging as a promising approach for intrusion detection using structured network flow data. However, their practical deployment is constrained by context window limitations and the excessive token overhead introduced by conventional tabular serialization formats such as JSON. Verbose data representations inflate sequence lengths, often exceeding model input limits and causing feature truncation. Additionally, it remains unclear which LLM architecture is more suitable for structured intrusion detection tasks under limited training resources. To tackle this issue, we propose a novel representation-aware intrusion detection framework based on Token-Oriented Object Notation (TOON), a compact serialization format that maximizes token efficiency while preserving schema structure. Also, we integrate a Low-Rank Adaptation (LoRA) scheme to enable parameter-efficient fine-tuning. Finally, we evaluate the proposed framework as an encoder-decoder model (T5-Small) with a decoder-only model (Qwen2.5) on three benchmark datasets, including NSL-KDD, UNSW-NB15, and CIC-IDS2018 for binary and multi-class classification scenarios. The results show that our tokenizer-aligned, representation-aware preprocessing combined with lightweight encoder-decoder adaptation provides a practical and resource-efficient foundation for LLM-based intrusion detection. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Conf. Artif. Intell., CAI},
keywords = {Classification (of information), Data flow analysis, Decoder-only large language model, Decoder-only LLMs, decoding, Flow classification, Intrusion Detection, Intrusion-Detection, Language model, Large language model, LLMs, LoRA, Low-rank adaptation, Network Flow Classification, Network intrusion, Network security, Networks flows, Qwen2.5, Signal encoding, T5-Small, Token-oriented object notation, Tokenization, TOON},
pubstate = {published},
tppubtype = {inproceedings}
}
Selamnia, A.; Moudoud, H.; Khoukhi, L.; Brik, B.; Houda, Z. A. El
QSFL-ID: Quantum-Split Federated Learning for Intrusion Detection in IIoT Networks Article d'actes
Dans: IEEE Int Conf Commun, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 15503607 (ISSN); 979-831954209-0 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Automation, Complex networks, Cyber threats, Federated learning, IIoT, Industrial automation, Industrial internet of thing, Intrusion Detection, Intrusion-Detection, Learning systems, Machine learning methods, Network intrusion, Network security, Privacy-preserving techniques, Processing power, QML, Quantum circuit, Quantum entanglement, Split Learning, Variational quantum circuit, VQC
@inproceedings{selamniaQSFLIDQuantumSplitFederated2026,
title = {QSFL-ID: Quantum-Split Federated Learning for Intrusion Detection in IIoT Networks},
author = {A. Selamnia and H. Moudoud and L. Khoukhi and B. Brik and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105045419288?origin=resultslist},
doi = {10.1109/ICC59461.2026.11587037},
isbn = {15503607 (ISSN); 979-831954209-0 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Int Conf Commun},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The Industrial Internet of Things (IIoT) is reshaping industrial automation through interconnected, intelligent systems. However, this evolution increases exposure to sophisticated cyber threats, especially given the constraints of IIoT devices such as limited processing power, bandwidth, and heterogeneous protocols. Traditional machine learning methods often fail to meet these security demands due to their computational intensity and centralized data requirements. To address this, we propose a hybrid quantum-classical Split Federated Learning (SFL) framework for intrusion detection in IIoT networks. Our method integrates Variational Quantum Circuits (VQCs) to model complex, non-linear data relationships, enhancing detection accuracy while preserving data privacy through decentralized learning. The architecture assigns lightweight preprocessing to edge devices and complex analysis to a quantum backend, ensuring efficiency and scalability. To evaluate the proposed framework, we conduct extensive experiments on the real-world EDGE-IIoT dataset; the experimental results demonstrate that the model attains 95.5% training accuracy, significantly surpassing classical SFL (85.7%). In addition, the quantum model's enhanced entanglement properties and expressibility strengthen its generalization performance. This approach offers an efficient and privacy-preserving solution for securing IIoT systems. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Automation, Complex networks, Cyber threats, Federated learning, IIoT, Industrial automation, Industrial internet of thing, Intrusion Detection, Intrusion-Detection, Learning systems, Machine learning methods, Network intrusion, Network security, Privacy-preserving techniques, Processing power, QML, Quantum circuit, Quantum entanglement, Split Learning, Variational quantum circuit, VQC},
pubstate = {published},
tppubtype = {inproceedings}
}
Guerziz, I.; Falk, T.; Le, L. B.; Houda, Z. A. E.
Domain Adversarial Neural Networks with Adversarial Robustness Evaluation for Intrusion Detection Systems Article d'actes
Dans: K., Adi; O., Nguena Timo; N., Boulahia-Cuppens; D., Espes; N., Stakhanova; M., Omar (Ed.): Lect. Notes Comput. Sci., p. 153–165, Springer Science and Business Media Deutschland GmbH, 2026, ISBN: 03029743 (ISSN); 978-303220731-9 (ISBN), (Journal Abbreviation: Lect. Notes Comput. Sci.).
Résumé | Liens | BibTeX | Étiquettes: Adversarial Attacks, Adversarial neural network, Adversarial Neural Networks, Attack Resilience, Attack resiliences, Computer crime, Domain adaptation, Fast gradient sign method, FGSM, Gradient-descent, Intrusion Detection, Intrusion Detection Systems, Network intrusion, Network intrusion detection systems, Network security, Neural networks, Neural-networks, PGD, Projected gradient, Projected gradient descent
@inproceedings{guerzizDomainAdversarialNeural2026,
title = {Domain Adversarial Neural Networks with Adversarial Robustness Evaluation for Intrusion Detection Systems},
author = {I. Guerziz and T. Falk and L. B. Le and Z. A. E. Houda},
editor = {Adi K. and Nguena Timo O. and Boulahia-Cuppens N. and Espes D. and Stakhanova N. and Omar M.},
url = {https://www.scopus.com/pages/publications/105046102448?origin=resultslist},
doi = {10.1007/978-3-032-20732-6_10},
isbn = {03029743 (ISSN); 978-303220731-9 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Lect. Notes Comput. Sci.},
volume = {16295 LNCS},
pages = {153–165},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {Modern Network Intrusion Detection Systems (NIDS) face the dual challenge of maintaining performance across diverse network environments while resisting adversarial manipulations. This paper investigates the intersection of domain adaptation and adversarial robustness in NIDS, a topic that has not been extensively studied. We implement a Domain-Adversarial Neural Network (DANN) with dynamic gradient reversal to adapt models from NSL-KDD to UNSW-NB15. To evaluate security, we assess the model under Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) attacks. Additionally, we introduce FGSM-based adversarial training to enhance robustness. Our results show that while domain adaptation improves cross-domain detection, it also increases susceptibility to adversarial attacks. Incorporating adversarial training mitigates this vulnerability, improving resilience without compromising performance on clean data. These findings provide key insights for designing adaptive and secure intrusion detection systems. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.},
note = {Journal Abbreviation: Lect. Notes Comput. Sci.},
keywords = {Adversarial Attacks, Adversarial neural network, Adversarial Neural Networks, Attack Resilience, Attack resiliences, Computer crime, Domain adaptation, Fast gradient sign method, FGSM, Gradient-descent, Intrusion Detection, Intrusion Detection Systems, Network intrusion, Network intrusion detection systems, Network security, Neural networks, Neural-networks, PGD, Projected gradient, Projected gradient descent},
pubstate = {published},
tppubtype = {inproceedings}
}
Kadi, A.; Moudoud, H.; Khoukhi, L.; Houda, Z. A. El
Quantum-Enhanced LSTM for Sequential Network Flow Analysis: A Hybrid Approach to DDoS Detection Article d'actes
Dans: Proc. - Int. Conf. Quantum Commun., Netw., Comput., QCNC, p. 830–834, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833156110-9 (ISBN), (Journal Abbreviation: Proc. - Int. Conf. Quantum Commun., Netw., Comput., QCNC).
Résumé | Liens | BibTeX | Étiquettes: Denialof- service attacks, Distributed computer systems, Distributed denial of service, Distributed denial-of-service, Distributed Denial-of-Service (DDoS), Hybrid approach, Intrusion Detection, Learning systems, Logic gates, Long short-term memory, Machine-learning, Memory architecture, Network architecture, Network flow analysis, Network security, QLSTM, Quantum entanglement, Quantum machine learning, Quantum Machine Learning(QML), Quantum machines, Qubits, short term memory
@inproceedings{kadiQuantumEnhancedLSTMSequential2026,
title = {Quantum-Enhanced LSTM for Sequential Network Flow Analysis: A Hybrid Approach to DDoS Detection},
author = {A. Kadi and H. Moudoud and L. Khoukhi and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105040813271?origin=resultslist},
doi = {10.1109/QCNC69040.2026.00136},
isbn = {979-833156110-9 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Proc. - Int. Conf. Quantum Commun., Netw., Comput., QCNC},
pages = {830–834},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Distributed Denial-of-Service (DDoS) attacks continue to grow at a rapid rate, making timely and reliable detection a challenge for intrusion detection systems (IDSs). Classical deep models such as Long Short-Term Memory (LSTM) can capture temporal dependencies; however, they still struggle with highly nonlinear and noisy flow dynamics, especially when attack patterns shift. To address this, we propose QLSTM-E, an enhanced hybrid quantum-classical architecture for network intrusion detection that uses Variational Quantum Circuits (VQCs) and LSTM modeling to learn complex temporal dependencies in network traffic. QLSTM-E exploits quantum characteristics, including superposition and entanglement, to improve the representation of nonlinear patterns in sequential flow features. To balance expressivity and circuit cost on near-term devices, we adopt an angle-based encoding strategy and a star-topology entangling layout that reduces two-qubit gate overhead while preserving effective quantum correlations. We implement QLSTM-E using PennyLane and Qiskit and evaluate it on the CIC-DDoS2019 dataset under a fully simulated setting, requiring no access to quantum hardware. Experimental results demonstrate strong detection effectiveness, achieving 99.7% accuracy and F1-score, and show strong robustness under depolarizing noise up to p= 0.1. © 2026 IEEE.},
note = {Journal Abbreviation: Proc. - Int. Conf. Quantum Commun., Netw., Comput., QCNC},
keywords = {Denialof- service attacks, Distributed computer systems, Distributed denial of service, Distributed denial-of-service, Distributed Denial-of-Service (DDoS), Hybrid approach, Intrusion Detection, Learning systems, Logic gates, Long short-term memory, Machine-learning, Memory architecture, Network architecture, Network flow analysis, Network security, QLSTM, Quantum entanglement, Quantum machine learning, Quantum Machine Learning(QML), Quantum machines, Qubits, short term memory},
pubstate = {published},
tppubtype = {inproceedings}
}
Zoungrana, A. F.; Moudoud, H.; Tajeuna, E. G.; Adi, K.
Adversarial Ensemble Framework: Leveraging GANs for Robust Intrusion Detection in IoT Networks Article d'actes
Dans: K., Adi; O., Nguena Timo; N., Boulahia-Cuppens; D., Espes; N., Stakhanova; M., Omar (Ed.): Lect. Notes Comput. Sci., p. 85–99, Springer Science and Business Media Deutschland GmbH, 2026, ISBN: 03029743 (ISSN); 978-303220731-9 (ISBN), (Journal Abbreviation: Lect. Notes Comput. Sci.).
Résumé | Liens | BibTeX | Étiquettes: Adversarial networks, Class imbalance, Computer crime, Concept drifts, Gallium nitride, Generative adversarial networks, Internet of thing network, Internet of things, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, IoT Networks, Key Issues, Network intrusion, Network security, Rapid expansion, Security, Security challenges
@inproceedings{zoungranaAdversarialEnsembleFramework2026,
title = {Adversarial Ensemble Framework: Leveraging GANs for Robust Intrusion Detection in IoT Networks},
author = {A. F. Zoungrana and H. Moudoud and E. G. Tajeuna and K. Adi},
editor = {Adi K. and Nguena Timo O. and Boulahia-Cuppens N. and Espes D. and Stakhanova N. and Omar M.},
url = {https://www.scopus.com/pages/publications/105046136116?origin=resultslist},
doi = {10.1007/978-3-032-20732-6_6},
isbn = {03029743 (ISSN); 978-303220731-9 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Lect. Notes Comput. Sci.},
volume = {16295 LNCS},
pages = {85–99},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {The rapid expansion of Internet of Things (IoT) devices introduces complex security challenges that traditional intrusion detection systems struggle to address. This paper proposes an Adversarial Ensemble Framework using Generative Adversarial Networks (GANs) to improve the accuracy and resilience of intrusion detection in IoT environments. The framework tackles key issues such as class imbalance, concept drift, and adversarial attacks by employing multiple GAN variants such as Vanilla GAN, Conditional GAN (CGAN), and Wasserstein GAN (WGAN) to generate high-quality synthetic attack data. A dynamic ensemble learning mechanism selects the most effective model for each attack type based on performance metrics. Experiments on NSL-KDD and CIC-IDS2017 show that WGAN yields the most effective synthetic data, contributing to a detection rate of up to 96%. The approach proves particularly effective in identifying rare attacks, making it a scalable and adaptive solution for IoT security. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.},
note = {Journal Abbreviation: Lect. Notes Comput. Sci.},
keywords = {Adversarial networks, Class imbalance, Computer crime, Concept drifts, Gallium nitride, Generative adversarial networks, Internet of thing network, Internet of things, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, IoT Networks, Key Issues, Network intrusion, Network security, Rapid expansion, Security, Security challenges},
pubstate = {published},
tppubtype = {inproceedings}
}
Malasi, J. -J. M.; Moudoud, H.; Missaoui, R.
A Lightweight Multimodal LLM-Based Intrusion Detection System for Open RAN Article d'actes
Dans: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833157731-5 (ISBN), (Journal Abbreviation: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW).
Résumé | Liens | BibTeX | Étiquettes: Benchmarking, Computational linguistics, Computer crime, Cyber security, Cybersecurity, Embedded systems, Embeddings, Intelligent controllers, Internet protocols, Intrusion Detection, intrusion detection system, Intrusion Detection System (IDS), Intrusion Detection Systems, Language model, Large language model, Large Language Models (LLMs), Mobile telecommunication systems, Multi-modal, Multi-modal learning, Multimodal Learning, Network security, Open RAN, Pipelines, RAN intelligent controller, RAN intelligent controller (RIC), Semantics
@inproceedings{malasiLightweightMultimodalLLMBased2026,
title = {A Lightweight Multimodal LLM-Based Intrusion Detection System for Open RAN},
author = {J. -J. M. Malasi and H. Moudoud and R. Missaoui},
url = {https://www.scopus.com/pages/publications/105043415034?origin=resultslist},
doi = {10.1109/WCNCW67598.2026.11555393},
isbn = {979-833157731-5 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open Radio Access Network architectures introduce unprecedented openness and programmability through RAN Intelligent Controllers, expanding the attack surface beyond traditional volumetric threats. Most existing intrusion detection systems for fifth-generation mobile networks and ORAN rely primarily on numerical Key Performance Indicators (KPIs), often overlooking the security-relevant semantics embedded in logs and control messages. This paper proposes LLM4IDS, a semantic-aware and multimodal intrusion detection system that fuses lightweight Large Language Model (LLM) embeddings of textified events with traditional tabular KPIs in a compact Transformer-based classifier. Evaluated on the realworld OpenIreland O-RAN dataset and two classical IP network benchmarks (UNSW-NB15 and CICIDS2017), LLM4IDS consistently matches or surpasses strong tabular baselines while maintaining high efficiency. On OpenIreland, it reaches nearperfect detection (F1-score $textbackslashapprox 1.0$) and yields large gains for application-layer and volumetric attacks compared to KPI-only models. Across datasets, the classifier maintains an approximately 4 MB footprint and sub-millisecond CPU inference latency; the frozen sentence-LLM encoder can be shared across tasks, and its embeddings can be cached or precomputed when required by the deployment pipeline. These results indicate that integrating semantic context through multimodal fusion can significantly enhance intrusion detection in O-RAN while remaining competitive on standard IP-based IDS tasks. To the best of our knowledge, this work is among the first to study a complete multimodal LLM-based IDS pipeline for O-RAN data with cross-domain evaluation on both O-RAN and classical IP benchmarks. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW},
keywords = {Benchmarking, Computational linguistics, Computer crime, Cyber security, Cybersecurity, Embedded systems, Embeddings, Intelligent controllers, Internet protocols, Intrusion Detection, intrusion detection system, Intrusion Detection System (IDS), Intrusion Detection Systems, Language model, Large language model, Large Language Models (LLMs), Mobile telecommunication systems, Multi-modal, Multi-modal learning, Multimodal Learning, Network security, Open RAN, Pipelines, RAN intelligent controller, RAN intelligent controller (RIC), Semantics},
pubstate = {published},
tppubtype = {inproceedings}
}
Moudoud, H.; Houda, Z. A. El; Khoukhi, L.; Mouftah, H. T.
An SDN-based Adaptive Ensemble Learning Framework for Intrusion Mitigation in Wireless Networks Article d'actes
Dans: M., Valenti; D., Reed; M., Torres (Ed.): IEEE Int Conf Commun, p. 554–559, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 15503607 (ISSN); 979-833150521-9 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Aerial vehicle, Antennas, Artificial intelligence, Computer crime, Ensemble learning, Intrusion Detection, Intrusion Detection Systems, Jamming, Jamming Attacks, Learning algorithms, Learning frameworks, Network intrusion, Network operations, Radio communication, Security systems, Security threats, Sensors network, Unmanned aerial vehicle, Unmanned Aerial Vehicles, Unmanned aerial vehicles (UAV), Wireless networks, Wireless sensor, Wireless Sensor Networks, Zero-day attack
@inproceedings{moudoudSDNbasedAdaptiveEnsemble2025,
title = {An SDN-based Adaptive Ensemble Learning Framework for Intrusion Mitigation in Wireless Networks},
author = {H. Moudoud and Z. A. El Houda and L. Khoukhi and H. T. Mouftah},
editor = {Valenti M. and Reed D. and Torres M.},
url = {https://www.scopus.com/pages/publications/105018460686?origin=resultslist},
doi = {10.1109/ICC52391.2025.11161745},
isbn = {15503607 (ISSN); 979-833150521-9 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {IEEE Int Conf Commun},
pages = {554–559},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Jamming attacks are among the most critical security threats to Wireless Sensor Networks (WSNs), as they can severely disrupt normal network operations, leading to data loss, network downtime, and reduced system performance. Intrusion Detection Systems (IDSs) have therefore become essential to protect WSNs. However, conventional IDSs often struggle to detect zero-day attacks, creating a significant security gap. To address this, Artificial Intelligence (AI)-based IDSs have been introduced, offering improved detection capabilities but frequently encountering high bias or variance issues, which reduce their reliability. Recently, ensemble learning (EL) has emerged as a promising approach to build more adaptable and data-resilient models by combining multiple learning algorithms. In this context, we propose AdaptiveBoost, an SDN-based Adaptive Ensemble Learning Framework, specifically designed for effective jamming attack detection in WSNs. The SDN integration allows AdaptiveBoost to optimize network traffic flow, identify anomalies in real-time, and adaptively fine-tune detection mechanisms based on current network conditions. We conduct several experiments to evaluate AdaptiveBoost using real-world WSN attacks; using the well-known public network security dataset, WSN-DS, show that AdaptiveBoost outperforms AI-based algorithms in terms of accuracy, precision, recall, and F1 score, while achieving a remarkable reduction in training time by a factor of 235, making it an efficient, scalable solution for securing WSNs against jamming attacks. © 2025 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Aerial vehicle, Antennas, Artificial intelligence, Computer crime, Ensemble learning, Intrusion Detection, Intrusion Detection Systems, Jamming, Jamming Attacks, Learning algorithms, Learning frameworks, Network intrusion, Network operations, Radio communication, Security systems, Security threats, Sensors network, Unmanned aerial vehicle, Unmanned Aerial Vehicles, Unmanned aerial vehicles (UAV), Wireless networks, Wireless sensor, Wireless Sensor Networks, Zero-day attack},
pubstate = {published},
tppubtype = {inproceedings}
}
Amari, H.; Houda, Z. A. El; Moudoud, H.; Khoukhi, L.; Belguith, L. H.
Blockchain-Based Federated Learning for Enhanced Cyber-Threats Detection in Connected Vehicles Article d'actes
Dans: M., Valenti; D., Reed; M., Torres (Ed.): IEEE Int Conf Commun, p. 4257–4262, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 15503607 (ISSN); 979-833150521-9 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Central layers, Computer crime, Connected vehicle, Connected Vehicles, Cyber threats, Cyberthreat detection, Cyberthreats, Cyberthreats Detection, Data privacy, Federated learning, Intelligent transport, Intelligent vehicle highway systems, Internet of things, Intrusion Detection, Intrusion Detection Systems, Learning systems, Network security, SDN, Threat detection, Traffic control, Vehicles
@inproceedings{amariBlockchainBasedFederatedLearning2025,
title = {Blockchain-Based Federated Learning for Enhanced Cyber-Threats Detection in Connected Vehicles},
author = {H. Amari and Z. A. El Houda and H. Moudoud and L. Khoukhi and L. H. Belguith},
editor = {Valenti M. and Reed D. and Torres M.},
url = {https://www.scopus.com/pages/publications/105018456633?origin=resultslist},
doi = {10.1109/ICC52391.2025.11161266},
isbn = {15503607 (ISSN); 979-833150521-9 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {IEEE Int Conf Commun},
pages = {4257–4262},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Over the past few years, there have been made significant strides in advancing the Internet of Vehicles (IoV), recognizing its strategic importance in Intelligent Transport Systems. The proliferation of connected and autonomous vehicles on the roads has propelled the IoV into the spotlight. However, addressing the specific demands of vehicular networks, such as low latency, high mobility, extensive connectivity of 5G/6G networks, and robust security, remains a substantial challenge. Therefore, there is a critical need for substantial progress in implementing a resilient Intrusion Detection System within the IoV ecosystem. This paper introduces VFed-IDS, a decentralized, secure, flexible, scalable, and robust Blockchain and Federated Learning-based intrusion detection system. VFed-IDS is designed to identify cyber threats in the IoV while preserving privacy in connected vehicles. The proposed architecture consists of three main layers: the central layer, the local layer, and the Blockchain layer. The central layer includes the SDN Controller, responsible for training and aggregating the global model. The local layer comprises vehicles training individual models based on their private local datasets. The Blockchain layer introduces the Smart Contract VFed-SC, which manages the list of authenticated and collaborating vehicles in the Federated Learning process. It also hashes trained local model updates before transmitting them as transactions between the central and local layers. Simulation results demonstrate that VFed-IDS achieves a high accuracy rate of 99%, effectively enhancing the autonomous behavior of connected vehicles against cyber threats. © 2025 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Block-chain, Blockchain, Central layers, Computer crime, Connected vehicle, Connected Vehicles, Cyber threats, Cyberthreat detection, Cyberthreats, Cyberthreats Detection, Data privacy, Federated learning, Intelligent transport, Intelligent vehicle highway systems, Internet of things, Intrusion Detection, Intrusion Detection Systems, Learning systems, Network security, SDN, Threat detection, Traffic control, Vehicles},
pubstate = {published},
tppubtype = {inproceedings}
}
Moudoud, H.; Houda, Z. A. El; Brik, B.
Securing O-RAN with Zero Trust Architecture and Large Language Models Article d'actes
Dans: C., Iwendi; Z., Boulouard; N., Kryvinska (Ed.): Lect. Notes Networks Syst., p. 357–368, Springer Science and Business Media Deutschland GmbH, 2025, ISBN: 23673370 (ISSN); 978-303194619-6 (ISBN), (Journal Abbreviation: Lect. Notes Networks Syst.).
Résumé | Liens | BibTeX | Étiquettes: Access management, Access Management system, Architecture, Authentication, Block-chain, Blockchain, Computer architecture, Computer crime, Cryptography, Distributed computer systems, Intrusion Detection, Language model, Large language model, Management systems, Mobile security, Mobile telecommunication systems, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security systems, Security vulnerabilities, Trusted computing, Zero Trust
@inproceedings{moudoudSecuringORANZero2025,
title = {Securing O-RAN with Zero Trust Architecture and Large Language Models},
author = {H. Moudoud and Z. A. El Houda and B. Brik},
editor = {Iwendi C. and Boulouard Z. and Kryvinska N.},
url = {https://www.scopus.com/pages/publications/105011259647?origin=resultslist},
doi = {10.1007/978-3-031-94620-2_31},
isbn = {23673370 (ISSN); 978-303194619-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Lect. Notes Networks Syst.},
volume = {1312 LNNS},
pages = {357–368},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {The Open Radio Access Network (O-RAN) architecture is critical for the development of 6G networks, offering flexibility and interoperability through disaggregated components. However, this openness exposes O-RAN to new security vulnerabilities, including unauthorized access, data breaches, and malicious xApp deployments. To address these challenges, we propose DistillORAN, a novel Zero-Trust architecture designed specifically for O-RAN. DistillORAN features two core components: (1) a blockchain-based decentralized trust management system for secure verification, authentication, and dynamic access control of xApps, and (2) a lightweight intrusion detection module powered by DistilBERT, a transformer-based model optimized for resource-constrained environments. DistilBERT’s ability to analyze network activities and detect anomalies in real-time allows it to identify complex security threats and multi-step attack scenarios within the O-RAN ecosystem. Its lightweight nature makes it ideal for O-RAN’s distributed infrastructure, where computational resources may be limited. By combining blockchain technology for trust management with DistilBERT’s powerful pattern recognition for intrusion detection, DistillORAN enforces a Zero-Trust security model, ensuring continuous monitoring and verification of all network components. This comprehensive solution enhances the security and resilience of O-RAN networks, aligning with the dynamic needs of next-generation mobile infrastructures. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.},
note = {Journal Abbreviation: Lect. Notes Networks Syst.},
keywords = {Access management, Access Management system, Architecture, Authentication, Block-chain, Blockchain, Computer architecture, Computer crime, Cryptography, Distributed computer systems, Intrusion Detection, Language model, Large language model, Management systems, Mobile security, Mobile telecommunication systems, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security systems, Security vulnerabilities, Trusted computing, Zero Trust},
pubstate = {published},
tppubtype = {inproceedings}
}



