

de Recherche et d’Innovation
en Cybersécurité et Société
Malasi, J. -J. M.; Moudoud, H.; Missaoui, R.
A Lightweight Multimodal LLM-Based Intrusion Detection System for Open RAN Article d'actes
Dans: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833157731-5 (ISBN), (Journal Abbreviation: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW).
Résumé | Liens | BibTeX | Étiquettes: Benchmarking, Computational linguistics, Computer crime, Cyber security, Cybersecurity, Embedded systems, Embeddings, Intelligent controllers, Internet protocols, Intrusion Detection, intrusion detection system, Intrusion Detection System (IDS), Intrusion Detection Systems, Language model, Large language model, Large Language Models (LLMs), Mobile telecommunication systems, Multi-modal, Multi-modal learning, Multimodal Learning, Network security, Open RAN, Pipelines, RAN intelligent controller, RAN intelligent controller (RIC), Semantics
@inproceedings{malasiLightweightMultimodalLLMBased2026,
title = {A Lightweight Multimodal LLM-Based Intrusion Detection System for Open RAN},
author = {J. -J. M. Malasi and H. Moudoud and R. Missaoui},
url = {https://www.scopus.com/pages/publications/105043415034?origin=resultslist},
doi = {10.1109/WCNCW67598.2026.11555393},
isbn = {979-833157731-5 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open Radio Access Network architectures introduce unprecedented openness and programmability through RAN Intelligent Controllers, expanding the attack surface beyond traditional volumetric threats. Most existing intrusion detection systems for fifth-generation mobile networks and ORAN rely primarily on numerical Key Performance Indicators (KPIs), often overlooking the security-relevant semantics embedded in logs and control messages. This paper proposes LLM4IDS, a semantic-aware and multimodal intrusion detection system that fuses lightweight Large Language Model (LLM) embeddings of textified events with traditional tabular KPIs in a compact Transformer-based classifier. Evaluated on the realworld OpenIreland O-RAN dataset and two classical IP network benchmarks (UNSW-NB15 and CICIDS2017), LLM4IDS consistently matches or surpasses strong tabular baselines while maintaining high efficiency. On OpenIreland, it reaches nearperfect detection (F1-score $textbackslashapprox 1.0$) and yields large gains for application-layer and volumetric attacks compared to KPI-only models. Across datasets, the classifier maintains an approximately 4 MB footprint and sub-millisecond CPU inference latency; the frozen sentence-LLM encoder can be shared across tasks, and its embeddings can be cached or precomputed when required by the deployment pipeline. These results indicate that integrating semantic context through multimodal fusion can significantly enhance intrusion detection in O-RAN while remaining competitive on standard IP-based IDS tasks. To the best of our knowledge, this work is among the first to study a complete multimodal LLM-based IDS pipeline for O-RAN data with cross-domain evaluation on both O-RAN and classical IP benchmarks. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW},
keywords = {Benchmarking, Computational linguistics, Computer crime, Cyber security, Cybersecurity, Embedded systems, Embeddings, Intelligent controllers, Internet protocols, Intrusion Detection, intrusion detection system, Intrusion Detection System (IDS), Intrusion Detection Systems, Language model, Large language model, Large Language Models (LLMs), Mobile telecommunication systems, Multi-modal, Multi-modal learning, Multimodal Learning, Network security, Open RAN, Pipelines, RAN intelligent controller, RAN intelligent controller (RIC), Semantics},
pubstate = {published},
tppubtype = {inproceedings}
}
Kadi, A.; Selamnia, A.; Houda, Z. A. E.; Moudoud, H.; Brik, B.; Khoukhi, L.
An In-Depth Comparative Study of Quantum-Classical Encoding Methods for Network Intrusion Detection Article de journal
Dans: IEEE Open Journal of the Communications Society, vol. 6, p. 1129–1148, 2025, ISSN: 2644125X (ISSN).
Résumé | Liens | BibTeX | Étiquettes: Adversarial machine learning, Cyber attacks, Embeddings, Encoding methods, Encoding techniques, Encodings, Intrusion Detection, intrusion detection system, Intrusion Detection Systems, Machine-learning, Network embeddings, Network intrusion, Quantum cryptography, Quantum efficiency, Quantum electronics, Quantum machine learning, Quantum machines, Quantum-classical, Quantum-classical encoding, Zero-day attack
@article{kadiInDepthComparativeStudy2025,
title = {An In-Depth Comparative Study of Quantum-Classical Encoding Methods for Network Intrusion Detection},
author = {A. Kadi and A. Selamnia and Z. A. E. Houda and H. Moudoud and B. Brik and L. Khoukhi},
url = {https://www.scopus.com/pages/publications/85217024576?origin=resultslist},
doi = {10.1109/OJCOMS.2025.3537957},
issn = {2644125X (ISSN)},
year = {2025},
date = {2025-01-01},
journal = {IEEE Open Journal of the Communications Society},
volume = {6},
pages = {1129–1148},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {In today's rapidly evolving cyber landscape, the growing sophistication of attacks, including the rise of zero-day exploits, poses critical challenges for network intrusion detection. Traditional Intrusion Detection Systems (IDSs) often struggle with the complexity and high dimensionality of modern cyber threats. Quantum Machine Learning (QML) seamlessly integrates the computational power of quantum computing with the adaptability of machine learning, offering an innovative approach to solving intricate and high-dimensional challenges. A key factor in QML's performance is the method used to encode classical data into quantum states, as it defines how data is represented and processed in quantum circuits. QML offers promising advances for IDS, particularly through hybrid quantum-classical models. This study presents an in-depth comparative analysis of quantum-classical data encoding techniques for QML-based IDS. To the best of our knowledge, this is the first study to comprehensively evaluate the performance impact of different quantum encoding methods and provide a thorough evaluation of their impacts on the overall model performances. To achieve this, we first present a comprehensive evaluation of quantum and classical data encoding techniques, focusing on four key encoding techniques namely, Amplitude Embedding, Angle Embedding, Instantaneous Quantum Polynomial (IQP) Encoding, and Quantum Approximate Optimization Algorithm (QAOA) Embedding. Then, we develop a hybrid quantum-classical QML model to analyze how each encoding affects classification performance for malicious traffic. Finally, we conduct extensive experiments using two well-known, real-world network attack datasets to assess the accuracy and efficiency of each encoding approach. Our obtained results show notable differences in classification accuracy, underscoring the importance of encoding choice in optimizing QML-based IDS. This study aims to advance the application of quantum methodologies in network security by identifying effective encoding strategies for intrusion detection. © 2025 IEEE.},
keywords = {Adversarial machine learning, Cyber attacks, Embeddings, Encoding methods, Encoding techniques, Encodings, Intrusion Detection, intrusion detection system, Intrusion Detection Systems, Machine-learning, Network embeddings, Network intrusion, Quantum cryptography, Quantum efficiency, Quantum electronics, Quantum machine learning, Quantum machines, Quantum-classical, Quantum-classical encoding, Zero-day attack},
pubstate = {published},
tppubtype = {article}
}



