

de Recherche et d’Innovation
en Cybersécurité et Société
Pimentel, A.; Zhu, Y.; Falk, T. H.
Partial Audio Deepfake Detection: Are We Really Detecting Synthetic Media or Just Dataset Content Biases? Article d'actes
Dans: IEEE Conf. Artif. Intell., CAI, p. 1846–1851, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833156039-3 (ISBN), (Journal Abbreviation: IEEE Conf. Artif. Intell., CAI).
Résumé | Liens | BibTeX | Étiquettes: Audio signal processing, Computational linguistics, Condition, Detection models, Information integrity, Language model, Large datasets, Learning models, Optimistics, Performance, Self-supervised learning, Speech communication, Speech models, Speech recognition, Speech signals, Synthetic media, Transcription
@inproceedings{pimentelPartialAudioDeepfake2026,
title = {Partial Audio Deepfake Detection: Are We Really Detecting Synthetic Media or Just Dataset Content Biases?},
author = {A. Pimentel and Y. Zhu and T. H. Falk},
url = {https://www.scopus.com/pages/publications/105042045476?origin=resultslist},
doi = {10.1109/CAI68641.2026.11536622},
isbn = {979-833156039-3 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Conf. Artif. Intell., CAI},
pages = {1846–1851},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {In recent years, the generation of highly realistic audio deepfakes has raised significant concerns regarding privacy and information integrity. While most research has focused on fully bonafide or spoofed speech, partial deep-fakes, where only segments of an utterance are manipulated, remain less explored. Given the nature of the task, existing datasets are relying on large language models to manipulate bonafide speech signals into partial deepfakes by altering, deleting, or replacing segments with synthetic content. These manipulations may alter the semantics and sentiment of the generated content, creating biases that can be captured by deepfake detection models, leading to overly optimistic performance and poor generalizability. In this work, we investigate the presence of such biases in two popular partial deepfake datasets, namely AV-Deepfake1M and PartialEdit. We explore four self-supervised learning models, two relying only on text transcriptions (RoBERTa and RoBERTa-sentiment) and two relying on universal speech representations (WavLM Large and Wav2vec2-XLSR). Our experiments show that, while speech models achieve higher in-domain performance, they do not generalize to out-of-domain conditions. In turn, models trained on only transcribed speech can effectively distinguish manipulated content, achieving up to 97.8% AUC in-domain and nearly 70% AUC out-of-domain. These results suggest that linguistic patterns and dataset confounds may indeed be biasing partial deepfake detection models, leading to poor generalizability. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Conf. Artif. Intell., CAI},
keywords = {Audio signal processing, Computational linguistics, Condition, Detection models, Information integrity, Language model, Large datasets, Learning models, Optimistics, Performance, Self-supervised learning, Speech communication, Speech models, Speech recognition, Speech signals, Synthetic media, Transcription},
pubstate = {published},
tppubtype = {inproceedings}
}
Malasi, J. -J. M.; Moudoud, H.; Missaoui, R.
A Lightweight Multimodal LLM-Based Intrusion Detection System for Open RAN Article d'actes
Dans: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833157731-5 (ISBN), (Journal Abbreviation: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW).
Résumé | Liens | BibTeX | Étiquettes: Benchmarking, Computational linguistics, Computer crime, Cyber security, Cybersecurity, Embedded systems, Embeddings, Intelligent controllers, Internet protocols, Intrusion Detection, intrusion detection system, Intrusion Detection System (IDS), Intrusion Detection Systems, Language model, Large language model, Large Language Models (LLMs), Mobile telecommunication systems, Multi-modal, Multi-modal learning, Multimodal Learning, Network security, Open RAN, Pipelines, RAN intelligent controller, RAN intelligent controller (RIC), Semantics
@inproceedings{malasiLightweightMultimodalLLMBased2026,
title = {A Lightweight Multimodal LLM-Based Intrusion Detection System for Open RAN},
author = {J. -J. M. Malasi and H. Moudoud and R. Missaoui},
url = {https://www.scopus.com/pages/publications/105043415034?origin=resultslist},
doi = {10.1109/WCNCW67598.2026.11555393},
isbn = {979-833157731-5 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open Radio Access Network architectures introduce unprecedented openness and programmability through RAN Intelligent Controllers, expanding the attack surface beyond traditional volumetric threats. Most existing intrusion detection systems for fifth-generation mobile networks and ORAN rely primarily on numerical Key Performance Indicators (KPIs), often overlooking the security-relevant semantics embedded in logs and control messages. This paper proposes LLM4IDS, a semantic-aware and multimodal intrusion detection system that fuses lightweight Large Language Model (LLM) embeddings of textified events with traditional tabular KPIs in a compact Transformer-based classifier. Evaluated on the realworld OpenIreland O-RAN dataset and two classical IP network benchmarks (UNSW-NB15 and CICIDS2017), LLM4IDS consistently matches or surpasses strong tabular baselines while maintaining high efficiency. On OpenIreland, it reaches nearperfect detection (F1-score $textbackslashapprox 1.0$) and yields large gains for application-layer and volumetric attacks compared to KPI-only models. Across datasets, the classifier maintains an approximately 4 MB footprint and sub-millisecond CPU inference latency; the frozen sentence-LLM encoder can be shared across tasks, and its embeddings can be cached or precomputed when required by the deployment pipeline. These results indicate that integrating semantic context through multimodal fusion can significantly enhance intrusion detection in O-RAN while remaining competitive on standard IP-based IDS tasks. To the best of our knowledge, this work is among the first to study a complete multimodal LLM-based IDS pipeline for O-RAN data with cross-domain evaluation on both O-RAN and classical IP benchmarks. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW},
keywords = {Benchmarking, Computational linguistics, Computer crime, Cyber security, Cybersecurity, Embedded systems, Embeddings, Intelligent controllers, Internet protocols, Intrusion Detection, intrusion detection system, Intrusion Detection System (IDS), Intrusion Detection Systems, Language model, Large language model, Large Language Models (LLMs), Mobile telecommunication systems, Multi-modal, Multi-modal learning, Multimodal Learning, Network security, Open RAN, Pipelines, RAN intelligent controller, RAN intelligent controller (RIC), Semantics},
pubstate = {published},
tppubtype = {inproceedings}
}



