

de Recherche et d’Innovation
en Cybersécurité et Société
Laamari, A.; Moudoud, H.; Houda, Z. A. El
Lightweight LLM Adaptation for Intrusion Detection via Token-Efficient Flow Representation Article d'actes
Dans: IEEE Conf. Artif. Intell., CAI, p. 2122–2127, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833156039-3 (ISBN), (Journal Abbreviation: IEEE Conf. Artif. Intell., CAI).
Résumé | Liens | BibTeX | Étiquettes: Classification (of information), Data flow analysis, Decoder-only large language model, Decoder-only LLMs, decoding, Flow classification, Intrusion Detection, Intrusion-Detection, Language model, Large language model, LLMs, LoRA, Low-rank adaptation, Network Flow Classification, Network intrusion, Network security, Networks flows, Qwen2.5, Signal encoding, T5-Small, Token-oriented object notation, Tokenization, TOON
@inproceedings{laamariLightweightLLMAdaptation2026,
title = {Lightweight LLM Adaptation for Intrusion Detection via Token-Efficient Flow Representation},
author = {A. Laamari and H. Moudoud and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105042133342?origin=resultslist},
doi = {10.1109/CAI68641.2026.11536533},
isbn = {979-833156039-3 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Conf. Artif. Intell., CAI},
pages = {2122–2127},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Large language models (LLMs) are emerging as a promising approach for intrusion detection using structured network flow data. However, their practical deployment is constrained by context window limitations and the excessive token overhead introduced by conventional tabular serialization formats such as JSON. Verbose data representations inflate sequence lengths, often exceeding model input limits and causing feature truncation. Additionally, it remains unclear which LLM architecture is more suitable for structured intrusion detection tasks under limited training resources. To tackle this issue, we propose a novel representation-aware intrusion detection framework based on Token-Oriented Object Notation (TOON), a compact serialization format that maximizes token efficiency while preserving schema structure. Also, we integrate a Low-Rank Adaptation (LoRA) scheme to enable parameter-efficient fine-tuning. Finally, we evaluate the proposed framework as an encoder-decoder model (T5-Small) with a decoder-only model (Qwen2.5) on three benchmark datasets, including NSL-KDD, UNSW-NB15, and CIC-IDS2018 for binary and multi-class classification scenarios. The results show that our tokenizer-aligned, representation-aware preprocessing combined with lightweight encoder-decoder adaptation provides a practical and resource-efficient foundation for LLM-based intrusion detection. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Conf. Artif. Intell., CAI},
keywords = {Classification (of information), Data flow analysis, Decoder-only large language model, Decoder-only LLMs, decoding, Flow classification, Intrusion Detection, Intrusion-Detection, Language model, Large language model, LLMs, LoRA, Low-rank adaptation, Network Flow Classification, Network intrusion, Network security, Networks flows, Qwen2.5, Signal encoding, T5-Small, Token-oriented object notation, Tokenization, TOON},
pubstate = {published},
tppubtype = {inproceedings}
}
Mehrban, A.; Houda, Z. Abou El; Moudoud, H.; Bao, L. Le
Integrating Zero Trust Architecture in O-RAN: A Comprehensive Survey and Analysis Article de journal
Dans: IEEE Open Journal of the Communications Society, vol. 6, p. 10465–10495, 2025, ISSN: 2644125X (ISSN).
Résumé | Liens | BibTeX | Étiquettes: 6g network, 6G networks, Access control, Data flow analysis, Intelligent controllers, Interoperability, Mobile telecommunication systems, Multi-vendor, Network architecture, Network components, Network security, New approaches, Open radio access network, open radio access network (O-RAN), Radio access networks, RAN intelligent controller, RAN intelligent controller (RIC), Smart contract, Survey and analysis, Trusted computing, Vendor interoperability, Zero trust architecture, Zero trust architecture (ZTA)
@article{mehrbanIntegratingZeroTrust2025,
title = {Integrating Zero Trust Architecture in O-RAN: A Comprehensive Survey and Analysis},
author = {A. Mehrban and Z. Abou El Houda and H. Moudoud and L. Le Bao},
url = {https://www.scopus.com/pages/publications/105025432034?origin=resultslist},
doi = {10.1109/OJCOMS.2025.3644132},
issn = {2644125X (ISSN)},
year = {2025},
date = {2025-01-01},
journal = {IEEE Open Journal of the Communications Society},
volume = {6},
pages = {10465–10495},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open Radio Access Network (O-RAN) is a new approach to mobile networks that disaggregates the network architecture into multi-vendor interoperable physical and software-defined network components connected through standardized open interfaces. This architecture enables deploying solutions on cloud-native platforms and boosting Artificial Intelligence(AI)-driven automation for network optimization. Despite the benefits of O-RAN’s heterogeneous and multi-vendor architecture, this approach inevitably enlarges the attack surface and introduces additional trust boundaries, which imminently threaten the uniformity of network performance. This also justifies the necessity of Zero Trust Architecture (ZTA) principles as a countermeasure, securing all network components, interfaces, and data flows. This survey shows how ZTA tenets can be integrated into O-RAN settings, contributing in three key areas: (1) a novel ZTA-to-O-RAN mapping model that explicitly places Policy Engine (PE), Policy Administrator (PA), and Policy Enforcement Points (PEPs) across RIC layers (Non-RT/Near-RT RIC), standardized interfaces (A1/E2/O1/O2), and disaggregated RAN functions (O-DU/O-CU/O-RU); (2) a Risk-Adaptive Access Control (RAdAC) framework that dynamically modulates verification depth based on contextual risk; and (3) integration of blockchain-based decentralized identity management with smart-contract-driven authorization for xApp/rApp lifecycle security. © 2020 IEEE.},
keywords = {6g network, 6G networks, Access control, Data flow analysis, Intelligent controllers, Interoperability, Mobile telecommunication systems, Multi-vendor, Network architecture, Network components, Network security, New approaches, Open radio access network, open radio access network (O-RAN), Radio access networks, RAN intelligent controller, RAN intelligent controller (RIC), Smart contract, Survey and analysis, Trusted computing, Vendor interoperability, Zero trust architecture, Zero trust architecture (ZTA)},
pubstate = {published},
tppubtype = {article}
}



