

de Recherche et d’Innovation
en Cybersécurité et Société
Malasi, J. -J. M.; Moudoud, H.; Missaoui, R.
CausalGraph: When Causal Reasoning Meets Large Language Models for Intrusion Detection Systems Article d'actes
Dans: Dig Tech Pap IEEE Int Conf Consum Electron, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 0747668X (ISSN); 979-833155343-2 (ISBN), (Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron).
Résumé | Liens | BibTeX | Étiquettes: Alarm systems, Budget control, causal reasoning, Chains, Computer crime, Concept Drift, Concept drifts, Conformal Risk Control, Counterfactuals, Generative AI, Human computer interaction, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, Knowledge based systems, Language model, LLM, LLMs, Network intrusion, Network security, Risks controls, Sampling
@inproceedings{malasiCausalGraphWhenCausal2026,
title = {CausalGraph: When Causal Reasoning Meets Large Language Models for Intrusion Detection Systems},
author = {J. -J. M. Malasi and H. Moudoud and R. Missaoui},
url = {https://www.scopus.com/pages/publications/105037367854?origin=resultslist},
doi = {10.1109/ICCE67443.2026.11449614},
isbn = {0747668X (ISSN); 979-833155343-2 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Dig Tech Pap IEEE Int Conf Consum Electron},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Modern intrusion detection systems often achieve impressive benchmark accuracy yet fail in real-world deployment, where network behavior and attacker tactics continuously evolve. Under concept drift, decision boundaries learned offline can diverge from operational reality, triggering false-alarm cascades and creating detection blind spots that erode analyst trust. In this paper, we propose CausalGraph-IDS, a causal and language-model-assisted intrusion detection framework that moves beyond purely correlational scoring by explicitly verifying multi-stage attack chains. Additionally, we propose CHAIN-CRC, a unified algorithm that (i) learns a constrained attack-chain causal graph guided by knowledge-based priors derived from widely used adversary behavior taxonomies, (ii) computes robustness scores by testing whether alarms persist under feasible counterfactual security interventions, and (iii) applies conformal risk control to enforce operator-defined false-positive budgets with finite-sample guarantees.Generative models are integrated in strictly assistive roles through three modules: prior induction to distill causal constraints from unstructured threat reports, counterfactual generation to propose realistic and operationally feasible interventions, and causal logic justification to produce human-readable explanations grounded in the learned attack chain. Experiments on two widely used network intrusion detection benchmarks show that CausalGraph-IDS provides robust, explainable, and risk-governed detection, maintaining strong recall at low false-positive rates while delivering actionable causal insights for mitigation. © 2026 IEEE.},
note = {Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron},
keywords = {Alarm systems, Budget control, causal reasoning, Chains, Computer crime, Concept Drift, Concept drifts, Conformal Risk Control, Counterfactuals, Generative AI, Human computer interaction, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, Knowledge based systems, Language model, LLM, LLMs, Network intrusion, Network security, Risks controls, Sampling},
pubstate = {published},
tppubtype = {inproceedings}
}
Laamari, A.; Moudoud, H.; Houda, Z. A. El
Lightweight LLM Adaptation for Intrusion Detection via Token-Efficient Flow Representation Article d'actes
Dans: IEEE Conf. Artif. Intell., CAI, p. 2122–2127, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833156039-3 (ISBN), (Journal Abbreviation: IEEE Conf. Artif. Intell., CAI).
Résumé | Liens | BibTeX | Étiquettes: Classification (of information), Data flow analysis, Decoder-only large language model, Decoder-only LLMs, decoding, Flow classification, Intrusion Detection, Intrusion-Detection, Language model, Large language model, LLMs, LoRA, Low-rank adaptation, Network Flow Classification, Network intrusion, Network security, Networks flows, Qwen2.5, Signal encoding, T5-Small, Token-oriented object notation, Tokenization, TOON
@inproceedings{laamariLightweightLLMAdaptation2026,
title = {Lightweight LLM Adaptation for Intrusion Detection via Token-Efficient Flow Representation},
author = {A. Laamari and H. Moudoud and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105042133342?origin=resultslist},
doi = {10.1109/CAI68641.2026.11536533},
isbn = {979-833156039-3 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Conf. Artif. Intell., CAI},
pages = {2122–2127},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Large language models (LLMs) are emerging as a promising approach for intrusion detection using structured network flow data. However, their practical deployment is constrained by context window limitations and the excessive token overhead introduced by conventional tabular serialization formats such as JSON. Verbose data representations inflate sequence lengths, often exceeding model input limits and causing feature truncation. Additionally, it remains unclear which LLM architecture is more suitable for structured intrusion detection tasks under limited training resources. To tackle this issue, we propose a novel representation-aware intrusion detection framework based on Token-Oriented Object Notation (TOON), a compact serialization format that maximizes token efficiency while preserving schema structure. Also, we integrate a Low-Rank Adaptation (LoRA) scheme to enable parameter-efficient fine-tuning. Finally, we evaluate the proposed framework as an encoder-decoder model (T5-Small) with a decoder-only model (Qwen2.5) on three benchmark datasets, including NSL-KDD, UNSW-NB15, and CIC-IDS2018 for binary and multi-class classification scenarios. The results show that our tokenizer-aligned, representation-aware preprocessing combined with lightweight encoder-decoder adaptation provides a practical and resource-efficient foundation for LLM-based intrusion detection. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Conf. Artif. Intell., CAI},
keywords = {Classification (of information), Data flow analysis, Decoder-only large language model, Decoder-only LLMs, decoding, Flow classification, Intrusion Detection, Intrusion-Detection, Language model, Large language model, LLMs, LoRA, Low-rank adaptation, Network Flow Classification, Network intrusion, Network security, Networks flows, Qwen2.5, Signal encoding, T5-Small, Token-oriented object notation, Tokenization, TOON},
pubstate = {published},
tppubtype = {inproceedings}
}



