

de Recherche et d’Innovation
en Cybersécurité et Société
Mehrban, A.; Moudoud, H.; Brik, B.; Khoukhi, L.; Houda, Z. A. El
Game-Theoretic Security Orchestration for Cross-RIC Policy Conflicts in O-RAN Article d'actes
Dans: IEEE Int Conf Commun, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 15503607 (ISSN); 979-831954209-0 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Computation theory, Computer system firewalls, Cryptography, Game theory, Game-theoretic, Multiple vendors, Network architecture, Network security, Networks security, Open radio access network, Open RAN, Policy conflict, Radio access networks, Security orchestration, Service management, Service orchestration, SMO, Xapp/rapp conflict, xApp/rApp conflicts
@inproceedings{mehrbanGameTheoreticSecurityOrchestration2026,
title = {Game-Theoretic Security Orchestration for Cross-RIC Policy Conflicts in O-RAN},
author = {A. Mehrban and H. Moudoud and B. Brik and L. Khoukhi and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105045343135?origin=resultslist},
doi = {10.1109/ICC59461.2026.11587926},
isbn = {15503607 (ISSN); 979-831954209-0 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Int Conf Commun},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {In Open Radio Access Network (Open RAN), disaggregated network components can interact through specialized xApps or rApps from multiple vendors. Despite the flexibility of operations and the dynamism of functions enabled by the open architecture, this openness can cause conflicts in security policy enforcement (e.g., encryption levels, key rotation, firewall restrictiveness), formally defined as thresholded divergences on shared or interdependent security parameters, where one app wants to set a stricter rule while another wants a more lenient policy simultaneously. The current solutions of "first-come"or "last-write"make the change one-sided for the benefit of a single app, while other apps may be harmed by the result, and at a network level, security and stability can be compromised. In this paper, we propose a novel Game-Theoretic Security Orchestrator (GTSO) that operates at the Service Management and Orchestration (SMO) layer, with cross-RIC scope, and is responsible for resolving parameter conflicts across xApps and rApps. GTSO treats xApps/rApps as strategic players and negotiates convergent solutions using game-theoretic models such as non-cooperative Nash games, cooperative bargaining, and leader-follower (Stackelberg) that guide competing control applications toward stable equilibrium points, while exchanging strategy summaries over secure channels to protect sensitive details and enhance overall network security. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Computation theory, Computer system firewalls, Cryptography, Game theory, Game-theoretic, Multiple vendors, Network architecture, Network security, Networks security, Open radio access network, Open RAN, Policy conflict, Radio access networks, Security orchestration, Service management, Service orchestration, SMO, Xapp/rapp conflict, xApp/rApp conflicts},
pubstate = {published},
tppubtype = {inproceedings}
}
Malasi, J. -J. M.; Moudoud, H.; Missaoui, R.
A Lightweight Multimodal LLM-Based Intrusion Detection System for Open RAN Article d'actes
Dans: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 979-833157731-5 (ISBN), (Journal Abbreviation: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW).
Résumé | Liens | BibTeX | Étiquettes: Benchmarking, Computational linguistics, Computer crime, Cyber security, Cybersecurity, Embedded systems, Embeddings, Intelligent controllers, Internet protocols, Intrusion Detection, intrusion detection system, Intrusion Detection System (IDS), Intrusion Detection Systems, Language model, Large language model, Large Language Models (LLMs), Mobile telecommunication systems, Multi-modal, Multi-modal learning, Multimodal Learning, Network security, Open RAN, Pipelines, RAN intelligent controller, RAN intelligent controller (RIC), Semantics
@inproceedings{malasiLightweightMultimodalLLMBased2026,
title = {A Lightweight Multimodal LLM-Based Intrusion Detection System for Open RAN},
author = {J. -J. M. Malasi and H. Moudoud and R. Missaoui},
url = {https://www.scopus.com/pages/publications/105043415034?origin=resultslist},
doi = {10.1109/WCNCW67598.2026.11555393},
isbn = {979-833157731-5 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open Radio Access Network architectures introduce unprecedented openness and programmability through RAN Intelligent Controllers, expanding the attack surface beyond traditional volumetric threats. Most existing intrusion detection systems for fifth-generation mobile networks and ORAN rely primarily on numerical Key Performance Indicators (KPIs), often overlooking the security-relevant semantics embedded in logs and control messages. This paper proposes LLM4IDS, a semantic-aware and multimodal intrusion detection system that fuses lightweight Large Language Model (LLM) embeddings of textified events with traditional tabular KPIs in a compact Transformer-based classifier. Evaluated on the realworld OpenIreland O-RAN dataset and two classical IP network benchmarks (UNSW-NB15 and CICIDS2017), LLM4IDS consistently matches or surpasses strong tabular baselines while maintaining high efficiency. On OpenIreland, it reaches nearperfect detection (F1-score $textbackslashapprox 1.0$) and yields large gains for application-layer and volumetric attacks compared to KPI-only models. Across datasets, the classifier maintains an approximately 4 MB footprint and sub-millisecond CPU inference latency; the frozen sentence-LLM encoder can be shared across tasks, and its embeddings can be cached or precomputed when required by the deployment pipeline. These results indicate that integrating semantic context through multimodal fusion can significantly enhance intrusion detection in O-RAN while remaining competitive on standard IP-based IDS tasks. To the best of our knowledge, this work is among the first to study a complete multimodal LLM-based IDS pipeline for O-RAN data with cross-domain evaluation on both O-RAN and classical IP benchmarks. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Wirel. Commun. Netw. Conf. Workshops, WCNCW},
keywords = {Benchmarking, Computational linguistics, Computer crime, Cyber security, Cybersecurity, Embedded systems, Embeddings, Intelligent controllers, Internet protocols, Intrusion Detection, intrusion detection system, Intrusion Detection System (IDS), Intrusion Detection Systems, Language model, Large language model, Large Language Models (LLMs), Mobile telecommunication systems, Multi-modal, Multi-modal learning, Multimodal Learning, Network security, Open RAN, Pipelines, RAN intelligent controller, RAN intelligent controller (RIC), Semantics},
pubstate = {published},
tppubtype = {inproceedings}
}
Mehrban, A.; Moudoud, H.; Houda, Z. A. El
Zta-Driven Hierarchical Byzantine Consensus for Scalable O-Ran Supply Chain Security Article d'actes
Dans: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833157801-5 (ISBN), (Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Byzantine consensus, Firmware, Hierarchical Byzantine consensus, Multi-vendor, Network architecture, Network security, Open RAN, Open RAN (O-RAN), Permissioned blockchain, Supply chain security, Supply chains, Supply-chain attestation, Vendor interoperability, Zero-trust architecture, Zero-Trust Architecture (ZTA)
@inproceedings{mehrbanZtaDrivenHierarchicalByzantine2025,
title = {Zta-Driven Hierarchical Byzantine Consensus for Scalable O-Ran Supply Chain Security},
author = {A. Mehrban and H. Moudoud and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105037585759?origin=resultslist},
doi = {10.1109/SmartAgriSuSY68475.2025.11466868},
isbn = {979-833157801-5 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open RAN (O-RAN) multi-vendor interoperability continues to grow at a rapid pace, bringing flexibility and innovation but also increasing the attack surface. This makes O-RAN deployments vulnerable to supply chain infiltration and firmware tampering. Blockchain has emerged as a promising solution to provide an immutable and verifiable audit trail of equipment firmware hashes from manufacturing through deployment. However, conventional blockchain designs rely on all-to-all validator communication, which introduces scalability challenges and increases verification latency. To alleviate this issue, in this paper, we propose a scalable, efficient, and lightweight blockchain-enabled consensus framework, called H-BFT, to ensure supply chain security and attestation in O-RAN environments. H-BFT consists of three modules. The first module is a hierarchical consensus and attestation module that maps ZeroTrust Architecture (ZTA) microsegments (i.e., RU/DU/CU zones, near-real-time RIC clusters, and SMO domains) to validator committees. These committees verify local attestation events and produce concise summaries. The second module is a lightweight leader checkpointing module that periodically aggregates crosssegment digests, so that only compact validations become global, reducing communication and latency overhead. The third module is a blockchain-based audit and integrity enforcement module, where segment-level contracts enforce onboarding and integrity guarantees, and a checkpoint manager maintains consistency across the entire network. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
keywords = {Block-chain, Blockchain, Byzantine consensus, Firmware, Hierarchical Byzantine consensus, Multi-vendor, Network architecture, Network security, Open RAN, Open RAN (O-RAN), Permissioned blockchain, Supply chain security, Supply chains, Supply-chain attestation, Vendor interoperability, Zero-trust architecture, Zero-Trust Architecture (ZTA)},
pubstate = {published},
tppubtype = {inproceedings}
}



