

de Recherche et d’Innovation
en Cybersécurité et Société
Elhajjout, A.; Jarir, Z.; Moudoud, H.; Davoust, A.; Houda, Z. A. El
Leveraging Large Language Models for Contextual Threat Hypothesis Generation in IoT Networks Article d'actes
Dans: Dig Tech Pap IEEE Int Conf Consum Electron, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 0747668X (ISSN); 979-833155343-2 (ISBN), (Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron).
Résumé | Liens | BibTeX | Étiquettes: Alert Triage, Cybersecurity, Hypotheses generation, Internet of thing security, Internet of things, IoT Security, Language model, Large datasets, Large language model, large language models, Network security, Prompt Engineering, Security alerts, Security operation center, Security Operations, Security systems, Threat Hypothesis Generation
@inproceedings{elhajjoutLeveragingLargeLanguage2026,
title = {Leveraging Large Language Models for Contextual Threat Hypothesis Generation in IoT Networks},
author = {A. Elhajjout and Z. Jarir and H. Moudoud and A. Davoust and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105037351870?origin=resultslist},
doi = {10.1109/ICCE67443.2026.11449914},
isbn = {0747668X (ISSN); 979-833155343-2 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Dig Tech Pap IEEE Int Conf Consum Electron},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Modern Security Operations Centers face numerous challenges in managing the volume and complexity of security alerts from Internet of Things (IoT) networks. While traditional rule-based systems excel at detection, they provide limited contextual reasoning to help analysts understand ambiguous alerts. Large Language Models (LLMs) have shown promise across various cybersecurity domains. However, their potential to generate rich, explanatory threat hypotheses for ambiguous IoT alerts remains largely unexplored. To address these issues, in this paper, we present a systematic investigation of Large Language Model-based threat hypothesis generation with three key contributions. First, we introduce a context-aware structured prompting framework capable of synthesizing heterogeneous device telemetry into coherent threat narratives. Second, we formalize the assessment of explainability in security through a rigorous multidimensional quality metric system. Third, we provide the first comparative analysis of five state-of-the-art models on real-world IoT incidents, revealing critical performance tradeoffs. Results show that GPT-4o-mini achieves 88.2% accuracy on diverse attack types, while Qwen 3-235B achieves 95.2% accuracy on network-focused attacks. Statistical analysis reveals significant model-dataset interactions. These findings show that properly guided Large Language Models can augment analyst capabilities by providing detailed, contextual explanations that facilitate efficient alert triage. © 2026 IEEE.},
note = {Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron},
keywords = {Alert Triage, Cybersecurity, Hypotheses generation, Internet of thing security, Internet of things, IoT Security, Language model, Large datasets, Large language model, large language models, Network security, Prompt Engineering, Security alerts, Security operation center, Security Operations, Security systems, Threat Hypothesis Generation},
pubstate = {published},
tppubtype = {inproceedings}
}
Zoungrana, A. F.; Moudoud, H.; Tajeuna, E. G.; Adi, K.
Adversarial Ensemble Framework: Leveraging GANs for Robust Intrusion Detection in IoT Networks Article d'actes
Dans: K., Adi; O., Nguena Timo; N., Boulahia-Cuppens; D., Espes; N., Stakhanova; M., Omar (Ed.): Lect. Notes Comput. Sci., p. 85–99, Springer Science and Business Media Deutschland GmbH, 2026, ISBN: 03029743 (ISSN); 978-303220731-9 (ISBN), (Journal Abbreviation: Lect. Notes Comput. Sci.).
Résumé | Liens | BibTeX | Étiquettes: Adversarial networks, Class imbalance, Computer crime, Concept drifts, Gallium nitride, Generative adversarial networks, Internet of thing network, Internet of things, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, IoT Networks, Key Issues, Network intrusion, Network security, Rapid expansion, Security, Security challenges
@inproceedings{zoungranaAdversarialEnsembleFramework2026,
title = {Adversarial Ensemble Framework: Leveraging GANs for Robust Intrusion Detection in IoT Networks},
author = {A. F. Zoungrana and H. Moudoud and E. G. Tajeuna and K. Adi},
editor = {Adi K. and Nguena Timo O. and Boulahia-Cuppens N. and Espes D. and Stakhanova N. and Omar M.},
url = {https://www.scopus.com/pages/publications/105046136116?origin=resultslist},
doi = {10.1007/978-3-032-20732-6_6},
isbn = {03029743 (ISSN); 978-303220731-9 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Lect. Notes Comput. Sci.},
volume = {16295 LNCS},
pages = {85–99},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {The rapid expansion of Internet of Things (IoT) devices introduces complex security challenges that traditional intrusion detection systems struggle to address. This paper proposes an Adversarial Ensemble Framework using Generative Adversarial Networks (GANs) to improve the accuracy and resilience of intrusion detection in IoT environments. The framework tackles key issues such as class imbalance, concept drift, and adversarial attacks by employing multiple GAN variants such as Vanilla GAN, Conditional GAN (CGAN), and Wasserstein GAN (WGAN) to generate high-quality synthetic attack data. A dynamic ensemble learning mechanism selects the most effective model for each attack type based on performance metrics. Experiments on NSL-KDD and CIC-IDS2017 show that WGAN yields the most effective synthetic data, contributing to a detection rate of up to 96%. The approach proves particularly effective in identifying rare attacks, making it a scalable and adaptive solution for IoT security. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.},
note = {Journal Abbreviation: Lect. Notes Comput. Sci.},
keywords = {Adversarial networks, Class imbalance, Computer crime, Concept drifts, Gallium nitride, Generative adversarial networks, Internet of thing network, Internet of things, Intrusion Detection, Intrusion Detection Systems, Intrusion-Detection, IoT Networks, Key Issues, Network intrusion, Network security, Rapid expansion, Security, Security challenges},
pubstate = {published},
tppubtype = {inproceedings}
}
Amari, H.; Houda, Z. A. El; Moudoud, H.; Khoukhi, L.; Belguith, L. H.
Blockchain-Based Federated Learning for Enhanced Cyber-Threats Detection in Connected Vehicles Article d'actes
Dans: M., Valenti; D., Reed; M., Torres (Ed.): IEEE Int Conf Commun, p. 4257–4262, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 15503607 (ISSN); 979-833150521-9 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Central layers, Computer crime, Connected vehicle, Connected Vehicles, Cyber threats, Cyberthreat detection, Cyberthreats, Cyberthreats Detection, Data privacy, Federated learning, Intelligent transport, Intelligent vehicle highway systems, Internet of things, Intrusion Detection, Intrusion Detection Systems, Learning systems, Network security, SDN, Threat detection, Traffic control, Vehicles
@inproceedings{amariBlockchainBasedFederatedLearning2025,
title = {Blockchain-Based Federated Learning for Enhanced Cyber-Threats Detection in Connected Vehicles},
author = {H. Amari and Z. A. El Houda and H. Moudoud and L. Khoukhi and L. H. Belguith},
editor = {Valenti M. and Reed D. and Torres M.},
url = {https://www.scopus.com/pages/publications/105018456633?origin=resultslist},
doi = {10.1109/ICC52391.2025.11161266},
isbn = {15503607 (ISSN); 979-833150521-9 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {IEEE Int Conf Commun},
pages = {4257–4262},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Over the past few years, there have been made significant strides in advancing the Internet of Vehicles (IoV), recognizing its strategic importance in Intelligent Transport Systems. The proliferation of connected and autonomous vehicles on the roads has propelled the IoV into the spotlight. However, addressing the specific demands of vehicular networks, such as low latency, high mobility, extensive connectivity of 5G/6G networks, and robust security, remains a substantial challenge. Therefore, there is a critical need for substantial progress in implementing a resilient Intrusion Detection System within the IoV ecosystem. This paper introduces VFed-IDS, a decentralized, secure, flexible, scalable, and robust Blockchain and Federated Learning-based intrusion detection system. VFed-IDS is designed to identify cyber threats in the IoV while preserving privacy in connected vehicles. The proposed architecture consists of three main layers: the central layer, the local layer, and the Blockchain layer. The central layer includes the SDN Controller, responsible for training and aggregating the global model. The local layer comprises vehicles training individual models based on their private local datasets. The Blockchain layer introduces the Smart Contract VFed-SC, which manages the list of authenticated and collaborating vehicles in the Federated Learning process. It also hashes trained local model updates before transmitting them as transactions between the central and local layers. Simulation results demonstrate that VFed-IDS achieves a high accuracy rate of 99%, effectively enhancing the autonomous behavior of connected vehicles against cyber threats. © 2025 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Block-chain, Blockchain, Central layers, Computer crime, Connected vehicle, Connected Vehicles, Cyber threats, Cyberthreat detection, Cyberthreats, Cyberthreats Detection, Data privacy, Federated learning, Intelligent transport, Intelligent vehicle highway systems, Internet of things, Intrusion Detection, Intrusion Detection Systems, Learning systems, Network security, SDN, Threat detection, Traffic control, Vehicles},
pubstate = {published},
tppubtype = {inproceedings}
}
Soultana, O. A.; Moudoud, H.
Adaptive Heterogeneous Ensemble Learning for Attack Detection in IoT Networks Article d'actes
Dans: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern., p. 27–32, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 1062922X (ISSN); 979-833153358-8 (ISBN), (Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.).
Résumé | Liens | BibTeX | Étiquettes: Attack detection, Classification (of information), Computational efficiency, Detection accuracy, Ensemble learning, Ensemble techniques, Heterogeneous ensembles, Internet of thing security, Internet of things, Intrusion Detection, Intrusion-Detection, IoT Security, Learning systems, Nearest neighbor search, Security vulnerabilities, Stackings, Support vector machines, Zero-day attack, Zero-day detection
@inproceedings{soultanaAdaptiveHeterogeneousEnsemble2025,
title = {Adaptive Heterogeneous Ensemble Learning for Attack Detection in IoT Networks},
author = {O. A. Soultana and H. Moudoud},
url = {https://www.scopus.com/pages/publications/105033149093?origin=resultslist},
doi = {10.1109/SMC58881.2025.11343130},
isbn = {1062922X (ISSN); 979-833153358-8 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
pages = {27–32},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The proliferation of Internet of Things (IoT) devices has introduced significant security vulnerabilities, particularly in detecting zero-day attacks within highly dynamic and heterogeneous environments. Traditional machine learning models often fall short due to their static nature and computational demands. In this paper, we propose an adaptive ensemble learning framework that dynamically selects optimal detection models on a per-attack-class basis to improve detection accuracy while maintaining computational efficiency. Our approach combines multiple base classifiers (Random Forest, K-Nearest Neighbors, and Support Vector Machine) using ensemble techniques including bagging, boosting, and stacking. Ensemble techniques such as Bagging, Boosting, Voting, and Stacking. The key innovation lies in a class-aware model selection mechanism that identifies the most effective classifier-ensemble combination for each specific attack category, rather than applying a single model across all threat types. This targeted approach recognizes that different attack patterns exhibit distinct characteristics that may be better captured by different algorithmic approaches. Finally, we propose a decision-rule mechanism that selects the best-performing model for each attack class to improve detection accuracy. The proposed framework is evaluated through extensive experiments. The results show that our approach significantly enhances classification performance, especially for complex and rare attack types. © 2025 IEEE.},
note = {Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
keywords = {Attack detection, Classification (of information), Computational efficiency, Detection accuracy, Ensemble learning, Ensemble techniques, Heterogeneous ensembles, Internet of thing security, Internet of things, Intrusion Detection, Intrusion-Detection, IoT Security, Learning systems, Nearest neighbor search, Security vulnerabilities, Stackings, Support vector machines, Zero-day attack, Zero-day detection},
pubstate = {published},
tppubtype = {inproceedings}
}
Mehrban, A.; Houda, Z. A. El; Moudoud, H.; Brik, B.; Khoukhi, L.
A Blockchain-Enabled Multi-Layered Zero-Trust Security Framework for O-RAN Article d'actes
Dans: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC, p. 1564–1569, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833150887-6 (ISBN), (Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC).
Résumé | Liens | BibTeX | Étiquettes: Access control, Block-chain, Blockchain, Data privacy, Federated learning, federated learning (FL), Internet of thing, Internet of things, Internet of Things (IoT), Interoperability, Learning systems, Mobile telecommunication systems, Multi-layered, Network architecture, Network security, Open access, Open radio access network, open radio access network (O-RAN), Radio, Radio access networks, Radio access technologies, Radio communication, Secure communication, Security, Security frameworks, Security risks, Transfer learning, Trusted computing
@inproceedings{mehrbanBlockchainEnabledMultiLayeredZeroTrust2025,
title = {A Blockchain-Enabled Multi-Layered Zero-Trust Security Framework for O-RAN},
author = {A. Mehrban and Z. A. El Houda and H. Moudoud and B. Brik and L. Khoukhi},
url = {https://www.scopus.com/pages/publications/105011345211?origin=resultslist},
doi = {10.1109/IWCMC65282.2025.11059720},
isbn = {979-833150887-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
pages = {1564–1569},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {O-RAN (Open Radio Access Network) is a set of open and interoperable radio access technologies, guided by the O-RAN Alliance, that, despite an open ecosystem, introduces significant security risks, expanding the threat surface in 6G networks. Traditional perimeter-based security approaches are inadequate for O-RAN's highly distributed, multi-vendor environments, where Zero Trust Architecture (ZTA) becomes essential for robust security. To address these challenges, we propose a novel blockchain-based, decentralized Zero-Trust Framework specifically designed for O-RAN security. Our proposed framework comprises two key layers: the first layer utilizes Federated Learning (FL) and Transfer Learning (TL) for advanced attack detection, enabling distributed, privacy-preserving threat analysis across O-RAN nodes. The second layer enforces Zero Trust access control through a blockchain-based identity management system, ensuring tamper-resistant, real-time policy updates. This multi-layered framework provides adaptive threat detection and resilient access control, validated through simulations demonstrating high detection accuracy and robust access management with minimal impact on network performance, offering a scalable security solution for next-generation O-RAN deployments. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
keywords = {Access control, Block-chain, Blockchain, Data privacy, Federated learning, federated learning (FL), Internet of thing, Internet of things, Internet of Things (IoT), Interoperability, Learning systems, Mobile telecommunication systems, Multi-layered, Network architecture, Network security, Open access, Open radio access network, open radio access network (O-RAN), Radio, Radio access networks, Radio access technologies, Radio communication, Secure communication, Security, Security frameworks, Security risks, Transfer learning, Trusted computing},
pubstate = {published},
tppubtype = {inproceedings}
}
Saini, H. K.; Rani, S.; Ouaissa, M.; Ouaissa, M.; Houda, Z. A. El; Moudoud, H.
CRC Press, 2025, ISBN: 978-100364032-5 (ISBN); 978-104107046-7 (ISBN), (Journal Abbreviation: Digit. Forensics in Next-Gener. Internet of Med. Things: Balanc. Secur. and Sustain. Pages: 283 Publication Title: Digit. Forensics in Next-Gener. Internet of Med. Things: Balanc. Secur. and Sustain.).
Résumé | Liens | BibTeX | Étiquettes: Case-studies, Computer forensics, Forensic Techniques, Internet of things, Machine data, Medical computing, Medical data, Medical practitioner, Network security, Next generation Internet, Patient data, Real-world, Security challenges, Security solutions, sustainable development
@book{sainiDigitalForensicsNextGeneration2025,
title = {Digital Forensics in Next-Generation Internet of Medical Things: Balancing Security and Sustainability},
author = {H. K. Saini and S. Rani and M. Ouaissa and M. Ouaissa and Z. A. El Houda and H. Moudoud},
url = {https://www.scopus.com/pages/publications/105024400792?origin=resultslist},
doi = {10.1201/9781003640325},
isbn = {978-100364032-5 (ISBN); 978-104107046-7 (ISBN)},
year = {2025},
date = {2025-01-01},
publisher = {CRC Press},
series = {Digital Forensics in Next-Generation Internet of Medical Things: Balancing Security and Sustainability},
abstract = {This book provides a comprehensive exploration of the security challenges and solutions with digital sustainability in the rapidly evolving digital landscape of digital forensics. It explores the details of protecting Internet of Medical Things (IoMT) environments, where the medical data, patient data, and machine data are at high risk with the digital experiences. The book seeks to provide researchers, medical practitioners, and IT specialists with important information. It aims to set the stage for a future in which security and efficiency in IoMT smoothly blend through real-world case studies. Key themes cover IoMT-specific forensic techniques, the difficulties of striking a balance between environmental responsibility and security, and creative solutions that combine the two viewpoints. © 2026 selection and editorial matter, Hemant Kumar Saini, Sita Rani, Mariya Ouaissa, Mariyam Ouaissa, Zakaria Abou El Houda, and Hajar Moudoud. All rights reserved.},
note = {Journal Abbreviation: Digit. Forensics in Next-Gener. Internet of Med. Things: Balanc. Secur. and Sustain.
Pages: 283
Publication Title: Digit. Forensics in Next-Gener. Internet of Med. Things: Balanc. Secur. and Sustain.},
keywords = {Case-studies, Computer forensics, Forensic Techniques, Internet of things, Machine data, Medical computing, Medical data, Medical practitioner, Network security, Next generation Internet, Patient data, Real-world, Security challenges, Security solutions, sustainable development},
pubstate = {published},
tppubtype = {book}
}



