

de Recherche et d’Innovation
en Cybersécurité et Société
Malasi, J. -J. M.; Moudoud, H.; Missaoui, R.
CausalGraph: When Causal Reasoning Meets Large Language Models for Intrusion Detection Systems Article d'actes
Dans: Dig Tech Pap IEEE Int Conf Consum Electron, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 0747668X (ISSN); 979-833155343-2 (ISBN), (Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron).
Résumé | Liens | BibTeX | Étiquettes: Alarm systems, Budget control, causal reasoning, Chains, Computer crime, Concept Drift, Concept drifts, Conformal Risk Control, Counterfactuals, Generative AI, Human computer interaction, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, Knowledge based systems, Language model, LLM, LLMs, Network intrusion, Network security, Risks controls, Sampling
@inproceedings{malasiCausalGraphWhenCausal2026,
title = {CausalGraph: When Causal Reasoning Meets Large Language Models for Intrusion Detection Systems},
author = {J. -J. M. Malasi and H. Moudoud and R. Missaoui},
url = {https://www.scopus.com/pages/publications/105037367854?origin=resultslist},
doi = {10.1109/ICCE67443.2026.11449614},
isbn = {0747668X (ISSN); 979-833155343-2 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Dig Tech Pap IEEE Int Conf Consum Electron},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Modern intrusion detection systems often achieve impressive benchmark accuracy yet fail in real-world deployment, where network behavior and attacker tactics continuously evolve. Under concept drift, decision boundaries learned offline can diverge from operational reality, triggering false-alarm cascades and creating detection blind spots that erode analyst trust. In this paper, we propose CausalGraph-IDS, a causal and language-model-assisted intrusion detection framework that moves beyond purely correlational scoring by explicitly verifying multi-stage attack chains. Additionally, we propose CHAIN-CRC, a unified algorithm that (i) learns a constrained attack-chain causal graph guided by knowledge-based priors derived from widely used adversary behavior taxonomies, (ii) computes robustness scores by testing whether alarms persist under feasible counterfactual security interventions, and (iii) applies conformal risk control to enforce operator-defined false-positive budgets with finite-sample guarantees.Generative models are integrated in strictly assistive roles through three modules: prior induction to distill causal constraints from unstructured threat reports, counterfactual generation to propose realistic and operationally feasible interventions, and causal logic justification to produce human-readable explanations grounded in the learned attack chain. Experiments on two widely used network intrusion detection benchmarks show that CausalGraph-IDS provides robust, explainable, and risk-governed detection, maintaining strong recall at low false-positive rates while delivering actionable causal insights for mitigation. © 2026 IEEE.},
note = {Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron},
keywords = {Alarm systems, Budget control, causal reasoning, Chains, Computer crime, Concept Drift, Concept drifts, Conformal Risk Control, Counterfactuals, Generative AI, Human computer interaction, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, Knowledge based systems, Language model, LLM, LLMs, Network intrusion, Network security, Risks controls, Sampling},
pubstate = {published},
tppubtype = {inproceedings}
}
Laamari, A.; Moudoud, H.; Houda, Z. A. El
Lightweight LLM Adaptation for Intrusion Detection via Token-Efficient Flow Representation Article d'actes
Dans: IEEE Conf. Artif. Intell., CAI, p. 2122–2127, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833156039-3 (ISBN), (Journal Abbreviation: IEEE Conf. Artif. Intell., CAI).
Résumé | Liens | BibTeX | Étiquettes: Classification (of information), Data flow analysis, Decoder-only large language model, Decoder-only LLMs, decoding, Flow classification, Intrusion Detection, Intrusion-Detection, Language model, Large language model, LLMs, LoRA, Low-rank adaptation, Network Flow Classification, Network intrusion, Network security, Networks flows, Qwen2.5, Signal encoding, T5-Small, Token-oriented object notation, Tokenization, TOON
@inproceedings{laamariLightweightLLMAdaptation2026,
title = {Lightweight LLM Adaptation for Intrusion Detection via Token-Efficient Flow Representation},
author = {A. Laamari and H. Moudoud and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105042133342?origin=resultslist},
doi = {10.1109/CAI68641.2026.11536533},
isbn = {979-833156039-3 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Conf. Artif. Intell., CAI},
pages = {2122–2127},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Large language models (LLMs) are emerging as a promising approach for intrusion detection using structured network flow data. However, their practical deployment is constrained by context window limitations and the excessive token overhead introduced by conventional tabular serialization formats such as JSON. Verbose data representations inflate sequence lengths, often exceeding model input limits and causing feature truncation. Additionally, it remains unclear which LLM architecture is more suitable for structured intrusion detection tasks under limited training resources. To tackle this issue, we propose a novel representation-aware intrusion detection framework based on Token-Oriented Object Notation (TOON), a compact serialization format that maximizes token efficiency while preserving schema structure. Also, we integrate a Low-Rank Adaptation (LoRA) scheme to enable parameter-efficient fine-tuning. Finally, we evaluate the proposed framework as an encoder-decoder model (T5-Small) with a decoder-only model (Qwen2.5) on three benchmark datasets, including NSL-KDD, UNSW-NB15, and CIC-IDS2018 for binary and multi-class classification scenarios. The results show that our tokenizer-aligned, representation-aware preprocessing combined with lightweight encoder-decoder adaptation provides a practical and resource-efficient foundation for LLM-based intrusion detection. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Conf. Artif. Intell., CAI},
keywords = {Classification (of information), Data flow analysis, Decoder-only large language model, Decoder-only LLMs, decoding, Flow classification, Intrusion Detection, Intrusion-Detection, Language model, Large language model, LLMs, LoRA, Low-rank adaptation, Network Flow Classification, Network intrusion, Network security, Networks flows, Qwen2.5, Signal encoding, T5-Small, Token-oriented object notation, Tokenization, TOON},
pubstate = {published},
tppubtype = {inproceedings}
}
Selamnia, A.; Moudoud, H.; Khoukhi, L.; Brik, B.; Houda, Z. A. El
QSFL-ID: Quantum-Split Federated Learning for Intrusion Detection in IIoT Networks Article d'actes
Dans: IEEE Int Conf Commun, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 15503607 (ISSN); 979-831954209-0 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Automation, Complex networks, Cyber threats, Federated learning, IIoT, Industrial automation, Industrial internet of thing, Intrusion Detection, Intrusion-Detection, Learning systems, Machine learning methods, Network intrusion, Network security, Privacy-preserving techniques, Processing power, QML, Quantum circuit, Quantum entanglement, Split Learning, Variational quantum circuit, VQC
@inproceedings{selamniaQSFLIDQuantumSplitFederated2026,
title = {QSFL-ID: Quantum-Split Federated Learning for Intrusion Detection in IIoT Networks},
author = {A. Selamnia and H. Moudoud and L. Khoukhi and B. Brik and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105045419288?origin=resultslist},
doi = {10.1109/ICC59461.2026.11587037},
isbn = {15503607 (ISSN); 979-831954209-0 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Int Conf Commun},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The Industrial Internet of Things (IIoT) is reshaping industrial automation through interconnected, intelligent systems. However, this evolution increases exposure to sophisticated cyber threats, especially given the constraints of IIoT devices such as limited processing power, bandwidth, and heterogeneous protocols. Traditional machine learning methods often fail to meet these security demands due to their computational intensity and centralized data requirements. To address this, we propose a hybrid quantum-classical Split Federated Learning (SFL) framework for intrusion detection in IIoT networks. Our method integrates Variational Quantum Circuits (VQCs) to model complex, non-linear data relationships, enhancing detection accuracy while preserving data privacy through decentralized learning. The architecture assigns lightweight preprocessing to edge devices and complex analysis to a quantum backend, ensuring efficiency and scalability. To evaluate the proposed framework, we conduct extensive experiments on the real-world EDGE-IIoT dataset; the experimental results demonstrate that the model attains 95.5% training accuracy, significantly surpassing classical SFL (85.7%). In addition, the quantum model's enhanced entanglement properties and expressibility strengthen its generalization performance. This approach offers an efficient and privacy-preserving solution for securing IIoT systems. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Automation, Complex networks, Cyber threats, Federated learning, IIoT, Industrial automation, Industrial internet of thing, Intrusion Detection, Intrusion-Detection, Learning systems, Machine learning methods, Network intrusion, Network security, Privacy-preserving techniques, Processing power, QML, Quantum circuit, Quantum entanglement, Split Learning, Variational quantum circuit, VQC},
pubstate = {published},
tppubtype = {inproceedings}
}
Zoungrana, A. F.; Moudoud, H.; Tajeuna, E. G.; Adi, K.
Adversarial Ensemble Framework: Leveraging GANs for Robust Intrusion Detection in IoT Networks Article d'actes
Dans: K., Adi; O., Nguena Timo; N., Boulahia-Cuppens; D., Espes; N., Stakhanova; M., Omar (Ed.): Lect. Notes Comput. Sci., p. 85–99, Springer Science and Business Media Deutschland GmbH, 2026, ISBN: 03029743 (ISSN); 978-303220731-9 (ISBN), (Journal Abbreviation: Lect. Notes Comput. Sci.).
Résumé | Liens | BibTeX | Étiquettes: Adversarial networks, Class imbalance, Computer crime, Concept drifts, Gallium nitride, Generative adversarial networks, Internet of thing network, Internet of things, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, IoT Networks, Key Issues, Network intrusion, Network security, Rapid expansion, Security, Security challenges
@inproceedings{zoungranaAdversarialEnsembleFramework2026,
title = {Adversarial Ensemble Framework: Leveraging GANs for Robust Intrusion Detection in IoT Networks},
author = {A. F. Zoungrana and H. Moudoud and E. G. Tajeuna and K. Adi},
editor = {Adi K. and Nguena Timo O. and Boulahia-Cuppens N. and Espes D. and Stakhanova N. and Omar M.},
url = {https://www.scopus.com/pages/publications/105046136116?origin=resultslist},
doi = {10.1007/978-3-032-20732-6_6},
isbn = {03029743 (ISSN); 978-303220731-9 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Lect. Notes Comput. Sci.},
volume = {16295 LNCS},
pages = {85–99},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {The rapid expansion of Internet of Things (IoT) devices introduces complex security challenges that traditional intrusion detection systems struggle to address. This paper proposes an Adversarial Ensemble Framework using Generative Adversarial Networks (GANs) to improve the accuracy and resilience of intrusion detection in IoT environments. The framework tackles key issues such as class imbalance, concept drift, and adversarial attacks by employing multiple GAN variants such as Vanilla GAN, Conditional GAN (CGAN), and Wasserstein GAN (WGAN) to generate high-quality synthetic attack data. A dynamic ensemble learning mechanism selects the most effective model for each attack type based on performance metrics. Experiments on NSL-KDD and CIC-IDS2017 show that WGAN yields the most effective synthetic data, contributing to a detection rate of up to 96%. The approach proves particularly effective in identifying rare attacks, making it a scalable and adaptive solution for IoT security. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.},
note = {Journal Abbreviation: Lect. Notes Comput. Sci.},
keywords = {Adversarial networks, Class imbalance, Computer crime, Concept drifts, Gallium nitride, Generative adversarial networks, Internet of thing network, Internet of things, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, IoT Networks, Key Issues, Network intrusion, Network security, Rapid expansion, Security, Security challenges},
pubstate = {published},
tppubtype = {inproceedings}
}
Soltani, N.; Nejadshamsi, S.; Houda, Z. A. El; Khoury, R.; Costa, K. A. P.; Falk, T. H.; Avila, A. R.
Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial Attacks Article d'actes
Dans: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern., p. 39–44, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 1062922X (ISSN); 979-833153358-8 (ISBN), (Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.).
Résumé | Liens | BibTeX | Étiquettes: Adversarial machine learning, Adversarial networks, Classification (of information), Computer crime, Fast gradient sign method, Fast Gradient Sign Method (FGSM), Generative adversarial network, Generative Adversarial Network (GAN), Generative adversarial networks, Generative model, Generative Models, Intrusion Detection, Intrusion-Detection, Learning algorithms, Learning systems, Machine-learning, Multi-layers, Network intrusion, Network intrusion detection systems, Network layers, Network security, Second layer, Stackings
@inproceedings{soltaniEnhancingNetworkIntrusion2025,
title = {Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial Attacks},
author = {N. Soltani and S. Nejadshamsi and Z. A. El Houda and R. Khoury and K. A. P. Costa and T. H. Falk and A. R. Avila},
url = {https://www.scopus.com/pages/publications/105033159769?origin=resultslist},
doi = {10.1109/SMC58881.2025.11342479},
isbn = {1062922X (ISSN); 979-833153358-8 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
pages = {39–44},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Adversarial examples can represent a serious threat to machine learning (ML) algorithms. If used to manipulate the behaviour of ML-based Network Intrusion Detection Systems (NIDS), they can jeopardize network security. In this work, we aim to mitigate such risks by increasing the robustness of NIDS towards adversarial attacks. To that end, we explore two adversarial methods for generating malicious network traffic. The first method is based on Generative Adversarial Networks (GAN) and the second one is the Fast Gradient Sign Method (FGSM). The adversarial examples generated by these methods are then used to evaluate a novel multilayer defense mechanism, specifically designed to mitigate the vulnerability of ML-based NIDS. Our solution consists of one layer of stacking classifiers and a second layer based on an autoencoder. If the incoming network data are classified as benign by the first layer, the second layer is activated to ensure that the decision made by the stacking classifier is correct. We also incorporated adversarial training to further improve the robustness of our solution. Experiments on two datasets, namely UNSW-NB15 and NSL-KDD, demonstrate that the proposed approach increases resilience to adversarial attacks. © 2025 IEEE.},
note = {Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
keywords = {Adversarial machine learning, Adversarial networks, Classification (of information), Computer crime, Fast gradient sign method, Fast Gradient Sign Method (FGSM), Generative adversarial network, Generative Adversarial Network (GAN), Generative adversarial networks, Generative model, Generative Models, Intrusion Detection, Intrusion-Detection, Learning algorithms, Learning systems, Machine-learning, Multi-layers, Network intrusion, Network intrusion detection systems, Network layers, Network security, Second layer, Stackings},
pubstate = {published},
tppubtype = {inproceedings}
}
Soultana, O. A.; Moudoud, H.
Adaptive Heterogeneous Ensemble Learning for Attack Detection in IoT Networks Article d'actes
Dans: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern., p. 27–32, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 1062922X (ISSN); 979-833153358-8 (ISBN), (Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.).
Résumé | Liens | BibTeX | Étiquettes: Attack detection, Classification (of information), Computational efficiency, Detection accuracy, Ensemble learning, Ensemble techniques, Heterogeneous ensembles, Internet of thing security, Internet of things, Intrusion Detection, Intrusion-Detection, IoT Security, Learning systems, Nearest neighbor search, Security vulnerabilities, Stackings, Support vector machines, Zero-day attack, Zero-day detection
@inproceedings{soultanaAdaptiveHeterogeneousEnsemble2025,
title = {Adaptive Heterogeneous Ensemble Learning for Attack Detection in IoT Networks},
author = {O. A. Soultana and H. Moudoud},
url = {https://www.scopus.com/pages/publications/105033149093?origin=resultslist},
doi = {10.1109/SMC58881.2025.11343130},
isbn = {1062922X (ISSN); 979-833153358-8 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
pages = {27–32},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The proliferation of Internet of Things (IoT) devices has introduced significant security vulnerabilities, particularly in detecting zero-day attacks within highly dynamic and heterogeneous environments. Traditional machine learning models often fall short due to their static nature and computational demands. In this paper, we propose an adaptive ensemble learning framework that dynamically selects optimal detection models on a per-attack-class basis to improve detection accuracy while maintaining computational efficiency. Our approach combines multiple base classifiers (Random Forest, K-Nearest Neighbors, and Support Vector Machine) using ensemble techniques including bagging, boosting, and stacking. Ensemble techniques such as Bagging, Boosting, Voting, and Stacking. The key innovation lies in a class-aware model selection mechanism that identifies the most effective classifier-ensemble combination for each specific attack category, rather than applying a single model across all threat types. This targeted approach recognizes that different attack patterns exhibit distinct characteristics that may be better captured by different algorithmic approaches. Finally, we propose a decision-rule mechanism that selects the best-performing model for each attack class to improve detection accuracy. The proposed framework is evaluated through extensive experiments. The results show that our approach significantly enhances classification performance, especially for complex and rare attack types. © 2025 IEEE.},
note = {Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
keywords = {Attack detection, Classification (of information), Computational efficiency, Detection accuracy, Ensemble learning, Ensemble techniques, Heterogeneous ensembles, Internet of thing security, Internet of things, Intrusion Detection, Intrusion-Detection, IoT Security, Learning systems, Nearest neighbor search, Security vulnerabilities, Stackings, Support vector machines, Zero-day attack, Zero-day detection},
pubstate = {published},
tppubtype = {inproceedings}
}



