VLDB 2026 Research / reviewers in the wild / expert
Nesrine Kaaniche
dblp:137/8933
· DBLP profile ↗
33ranked-venue papers
14as first author
14since 2021 · last 2025
0000-0002-1045-6445ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 5 first-author · 7 since 2021Systems, architecture and hardware · 5 · 2 first-author · 2 since 2021Computer networks · 5 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-authorArtificial intelligence and machine learning · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unveiling the (in)Security of Threshold FHE-Based Federated Learning: The Practical Impact of Recent CPAD AttacksabstractThe security of Fully Homomorphic Encryption (FHE) has received a lot of attention in recent years with new security notions emerging to better understand the practical attacks that may threaten the real-world deployments of passively secure FHE schemes. One such new notions is CPAD a slight extension of CPA security modelling a passive adversary who is granted access to a decryption oracle accepting only well-formed ciphertexts. While successful CPAD attacks have initially been performed on approximate FHE schemes such as CKKS, recent works have also demonstrated practical CPAD attacks on all mainstream non-approximate FHE, such as BFV, BGV or TFHE. Despite their clear computational practicality, these latter attacks however focus on the abstract security game defining CPAD security. In this paper, we show how to concretely build on these to mount successful FHE key recovery attacks in the Federated Learning (FL) setting, an application scenario of choice for FHE techniques. In FL, participating entities or workers encrypt successive model updates based on their local training data, enabling a central server to aggregate them in order to homomorphically update a global model. As this paper demonstrates, this environment provides a playground for an attacker to launch key recovery attacks against the FHE underlying the secure aggregation mechanism. As such, our findings reveal substantial stealthy key-recovery threats from both the server and a single worker, with very limited impact on the FL training progression or final model quality. Adda-Akram Bendoukha, Renaud Sirdey, Aymen Boudguiga, Nesrine Kaaniche |
CSF | 4 |
| 2025 | Fair Play for Individuals, Foul Play for Groups? Auditing Anonymization's Impact on ML FairnessabstractMachine learning (ML) algorithms are heavily based on the availability of training data, which, depending on the domain, often includes sensitive information about data providers. This raises critical privacy concerns. Anonymization techniques have emerged as a practical solution to address these issues by generalizing features or suppressing data to make it more difficult to accurately identify individuals. Although recent studies have shown that privacy-enhancing technologies can influence ML predictions across different subgroups, thus affecting fair decision-making, the specific effects of anonymization techniques, such as k-anonymity, ℓ-diversity, and t-closeness, on ML fairness remain largely unexplored. In this work, we systematically audit the impact of anonymization techniques on ML fairness, evaluating both individual and group fairness. Our quantitative study reveals that anonymization can degrade group fairness metrics by up to fourfold. Conversely, similarity-based individual fairness metrics tend to improve under stronger anonymization, largely as a result of increased input homogeneity. By analyzing varying levels of anonymization across diverse privacy settings and data distributions, this study provides critical insights into the trade-offs between privacy, fairness, and utility, offering actionable guidelines for responsible AI development. Our code is publicly available at: https://github.com/hharcolezi/anonymity-impact-fairness. Héber Hwang Arcolezi, Mina Alishahi, Adda-Akram Bendoukha, Nesrine Kaaniche |
ECAI | 4 |
| 2025 | FairCognizer: A Model for Accurate Predictions with Inherent Fairness Evaluation (Extended Abstract)abstractAlgorithmic fairness is a critical challenge in building trustworthy Machine Learning (ML) models. ML classifiers strive to make predictions that closely match real-world observations (ground truth). However, if the ground truth data itself reflects biases against certain sub-populations, a dilemma arises: prioritize fairness and potentially reduce accuracy, or emphasize accuracy at the expense of fairness. This work proposes a novel training framework that goes beyond achieving high accuracy. Our framework trains a classifier to not only deliver optimal predictions but also to identify potential fairness risks associated with each prediction. To do so, we specify a dual-labeling strategy where the second label contains a per-prediction fairness evaluation, referred to as an unfairness risk evaluation. In addition, we identify a subset of samples as highly vulnerable to group-unfair classifiers. Our experiments demonstrate that our classifiers attain optimal accuracy levels on both the Adult-Census-Income and Compas-Recidivism datasets. Moreover, they identify unfair predictions with nearly 75% accuracy at the cost of expanding the size of the classifier by 45%. Adda-Akram Bendoukha, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey |
IJCAI | 2 |
| 2025 | AI-Based Anomaly Detection and Classification of Traffic Using NetflowabstractInternational audience Gustavo Gonzalez Granadillo, Nesrine Kaaniche |
SECRYPT | 2 |
| 2025 | Towards Privacy-preserving and Fairness-aware Federated Learning FrameworkabstractFederated Learning (FL) enables the distributed training of a model across multiple data owners under the orchestration of a central server responsible for aggregating the models generated by the different clients. However, the original approach of FL has significant shortcomings related to privacy and fairness requirements. Specifically, the observation of the model updates may lead to privacy issues, such as membership inference attacks, while the use of imbalanced local datasets can introduce or amplify classification biases, especially for minority groups. In this work, we show that these biases can be exploited to increase the likelihood of privacy attacks against these groups. To do so, we propose a novel inference attack exploiting the knowledge of group fairness metrics during the training of the global model. Then to thwart this attack, we define a fairness-aware encrypted-domain aggregation algorithm that is differentially-private by design thanks to the approximate precision loss of the threshold multi-key CKKS homomorphic encryption scheme. Finally, we demonstrate the good performance of our proposal both in terms of fairness and privacy through experiments conducted over three real datasets. Adda-Akram Bendoukha, Didem Demirag, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey, Sébastien Gambs |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | FairCognizer: A Model for Accurate Predictions with Inherent Fairness EvaluationabstractAlgorithmic fairness is a critical challenge in building trustworthy Machine Learning (ML) models. ML classifiers strive to make predictions that closely match real-world observations (ground truth). However, if the ground truth data itself reflects biases against certain sub-populations, a dilemma arises: prioritize fairness and potentially reduce accuracy, or emphasize accuracy at the expense of fairness. This work proposes a novel training framework that goes beyond achieving high accuracy. Our framework trains a classifier to not only deliver optimal predictions but also to identify potential fairness risks associated with each prediction. To do so, we specify a dual-labeling strategy where the second label contains a per-prediction fairness evaluation, referred to as an unfairness risk evaluation. In addition, we identify a subset of samples as highly vulnerable to group-unfair classifiers. Our experiments demonstrate that our classifiers attain optimal accuracy levels on both the Adult-Census-Income and Compas-Recidivism datasets. Moreover, they identify unfair predictions with nearly 75% accuracy at the cost of expanding the size of the classifier by a mere 45%. Adda-Akram Bendoukha, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey |
ECAI | 2 |
| 2024 | chiku: Efficient Probabilistic Polynomial Approximations Library
Devharsh Trivedi, Nesrine Kaaniche, Aymen Boudguiga, Nikos Triandopoulos |
SECRYPT | 2 |
| 2022 | Cooperative and smart attacks detection systems in 6G-enabled Internet of ThingsabstractThe Sixth Generation (6G) of mobile networks offers the promise of a global interconnected system, serving a large set of applications across multiple fields such as satellite, air, ground, and underwater networks. It will evolve towards a unified network compute fabric that facilitates convergence across ecosystems, fostering design and innovation of new Internet of Things (IoT) applications and services, further leading to an exponential growth of IoT use cases in the post-6G era. This profound evolution will also impact the threat landscape, adding new threat actors, and leading to a new set of cyber security challenges. This paper reviews 6G applications and analyzes their security challenges and existing solutions, covering both the network, application and data layers. It introduces a new concept to security monitoring and attack detection in 6G-enabled IoT systems, leveraging on hierarchical and collaborative approaches, while also satisfying the main 6G’s Key Performance Indicators (KPIs) such as trustworthiness, latency, connectivity, data rate and energy consumption. The proposed solution implements a multi-level Federated Learning (FL) approach between IoT devices and edge computing applications. As compared to current centralized security monitoring and detection solutions, it conciliates better between the attack detection accuracy and the network overhead for implementing this model. We demonstrate the use of the proposed solution through an example scenario involving an Internet of Vehicles that communicate over a 6G network. Hichem Sedjelmaci, Nizar Kheir, Aymen Boudguiga, Nesrine Kaaniche |
ICC | 4 |
| 2022 | Efficient Hybrid Model for Intrusion Detection SystemsabstractInternational audience Nesrine Kaaniche, Aymen Boudguiga, Gustavo Gonzalez Granadillo |
SECRYPT | 1 |
| 2022 | SEVIL: Secure and Efficient VerifIcation over Massive Proofs of KnowLedgeabstractInternational audience Souha Masmoudi, Maryline Laurent, Nesrine Kaaniche |
SECRYPT | 3 |
| 2022 | PIMA: A Privacy-preserving Identity management system based on an unlinkable MAlleable signature
Souha Masmoudi, Maryline Laurent, Nesrine Kaaniche |
J. Netw. Comput. Appl. | 3 |
| 2022 | Authorized Keyword Search over Outsourced Encrypted Data in Cloud EnvironmentabstractFor better data availability and accessibility while ensuring data secrecy, end-users often tend to outsource their data to the cloud servers in an encrypted form. However, this brings a major challenge to perform the search for some keywords over encrypted content without disclosing any information to unintended entities. This paper proposes a novel expressive authorized keyword search scheme relying on the concept of ciphertext-policy attribute-based encryption. The originality of the proposed scheme is multifold. First, it supports the generic and convenient multi-owner and multi-user scenario, where the encrypted data are outsourced by several data owners and searchable by multiple users. Second, the formal security analysis proves that the proposed scheme is semantically secure against chosen keyword and outsiders keyword guessing attacks. Third, an interactive protocol is introduced which avoids the need of any secure-channels between users and service provider. Fourth, due to the concept of bilinear-map accumulator, the system can efficiently revoke users and/or their attributes, and authenticate them prior to launching any expensive search operations. Fifth, conjunctive keyword search is provided thus enabling to search for multiple keywords simultaneously, with minimal cost. Sixth, the performance analysis shows that the proposed scheme outperforms closely-related works. Nazatul Haque Sultan, Nesrine Kaaniche, Maryline Laurent, Ferdous A. Barbhuiya |
IEEE Trans. Cloud Comput. | 2 |
| 2021 | An Efficient User-Centric Consent Management Design for Multiservices PlatformsabstractThis paper presents an efficient user-centric consent management system to access online services of the Territorial Collectivities and Public Administration (TCPA) as well as user-authorized third parties. It defines a novel PII manager that supports a set of sources obeying to different authorization and PII retrieval protocols. This contribution is motivated by the necessity to interface TCPA services with remote sources that provide Personally Identifiable Information (PII). Hence, the originality of our solution is multifold. First, the burden for enforcing the interoperability between the sources and the TCPA services collecting the PII is reduced from the point of view of the user, the administrator of the User-Relationship Management (URM) platform, and the territorial agent responsible for processing the user’s queries. Second, it defines a unified consent model supporting four types of sources. Third, it goes into details of practical implementations. Fourth, the relevance of the proposed PII manager for a relevant TCPA use case is demonstrated through a functional analysis. Paul Marillonnet, Mikaël Ates, Maryline Laurent, Nesrine Kaaniche |
Secur. Commun. Networks | 4 |
| 2021 | Cooperative Set Homomorphic Proofs for Data Possession Checking in CloudsabstractOutsourcing an increasing amount of data to a third party raises a number of security and privacy challenges, namely remote data integrity verification. Indeed, proofs for data possession checking address the verification that some previously outsourced data blocks across multiple storing nodes are correctly stored and fully available. In this paper, we propose a new set homomorphic proof of data possession, referred to as SHoPS, supporting several operations like aggregation of proofs. SHoPS is a deterministic Proof of Data Possession (PDP) scheme, based on an interactive proof protocol. Our approach has several advantages. First, it enables several proofs to be aggregated and a subset of data files' proofs to be verified, while providing an attractive communication overhead. Second, it supports public verifiability where the verification process can be delegated to another entity, thus releasing the data owner from the cumbersome task of periodical verifications. Third, SHoPS is efficient and provably secure, as it is resistant to the fraudulence of the prover and the leakage of verified data. Finally, a theoretical performances' analysis shows that SHoPS performs better in terms of functionality, communication and computation overhead compared to closely related works and experimental results point out the applicability of the proposed scheme in real world scenarios. Nesrine Kaaniche, Maryline Laurent, Sébastien Canard |
IEEE Trans. Cloud Comput. | 1 |
| 2020 | PROUD: Verifiable Privacy-preserving Outsourced Attribute Based SignCryption supporting access policy Update for cloud assisted IoT applications
Sana Belguith, Nesrine Kaaniche, Mohammad Hammoudeh, Tooska Dargahi |
Future Gener. Comput. Syst. | 2 |
| 2020 | Privacy enhancing technologies for solving the privacy-personalization paradox: Taxonomy and survey
Nesrine Kaaniche, Maryline Laurent, Sana Belguith |
J. Netw. Comput. Appl. | 1 |
| 2020 | Accountable privacy preserving attribute based framework for authenticated encrypted access in clouds
Sana Belguith, Nesrine Kaaniche, Maryline Laurent, Abderrazak Jemai, Rabah Attia |
J. Parallel Distributed Comput. | 2 |
| 2019 | AuthLedger: A Novel Blockchain-based Domain Name Authentication SchemeabstractInternational audience Zhi Guan, Abba Garba, Anran Li 0006, Zhong Chen 0001, Nesrine Kaaniche |
ICISSP | 5 |
| 2018 | PU-ABE: Lightweight Attribute-Based Encryption Supporting Access Policy Update for Cloud Assisted IoTabstractCloud-assisted IoT applications are gaining an expanding interest, such that IoT devices are deployed in different distributed environments to collect and outsource sensed data to remote servers for further processing and sharing among users. On the one hand, in several applications, collected data are extremely sensitive and need to be protected before outsourcing. Generally, encryption techniques are applied at the data producer side to protect data from adversaries as well as curious cloud provider. On the other hand, sharing data among users requires fine grained access control mechanisms. To ensure both requirements, Attribute Based Encryption (ABE) has been widely applied to ensure encrypted access control to outsourced data. Although, ABE ensures fine grained access control and data confidentiality, updates of used access policies after encryption and outsourcing of data remains an open challenge. In this paper, we design PU-ABE, a new variant of key policy attribute based encryption supporting efficient access policy update that captures attributes addition to access policies. PU-ABE contributions are multifold. First, access policies involved in the encryption can be updated without requiring sharing secret keys between the cloud server and the data owners neither re-encrypting data. Second, PU-ABE ensures privacy preserving and fine grained access control to outsourced data. Third, ciphertexts received by the end-user are constant sized and independent from the number of attributes used in the access policy which affords low communication and storage costs. Sana Belguith, Nesrine Kaaniche, Giovanni Russello |
IEEE CLOUD | 2 |
| 2018 | Privacy-Preserving Multi-User Encrypted Access Control Scheme for Cloud-Assisted IoT ApplicationsabstractIn this paper, we present a privacy preserving encrypted access control scheme to aggregate data for Cloud assisted IoT applications. Our scheme is based on attribute based encryption mechanisms and consists in enciphering a set of data contents, with respect to sub-sets of a general access policy. As such, the gateway is able to decrypt the resulting aggregated data only if it holds the matching certified attributes and it has received a sufficient number of partial ciphertexts. Our construction has several advantages. First, it provides a fine-grained access to aggregated data contents that are enciphered by different multiple encrypting entities. Second, it provides a privacy preserving encryption process, such that a curious gateway can neither identify the enciphering IoT device nor decipher single data chunks. Third, our concrete construction provides low computation and communication costs, adapted to resource-constrained devices, compared to most closely related schemes. Nesrine Kaaniche, Maryline Laurent |
IEEE CLOUD | 1 |
| 2018 | BDUA: Blockchain-Based Data Usage AuditingabstractPersonal data are often collected and processed in a decentralized fashion, within different contexts. For instance, with the emergence of distributed applications, several providers are used to correlate their records, to provide personalized services to their clients. As such, to protect users' privacy, different pseudonyms are generally used for different contexts. These pseudonyms have to be unlinkable to prevent identifying records to be associated to the same user. Although unlinkable, these pseudonyms have to be processed and exchanged according to their owners' consent and in a privacy-preserving fashion. In this paper, we propose BDUA, a new Blockchain-based Data Usage Auditing system, that ensures a controlled yet privacy preserving exchange of distributed data, such that a set of authorized auditing entities are able to conduct an accurate auditing relying on registered blockchains' transactions. Nesrine Kaaniche, Maryline Laurent |
IEEE CLOUD | 1 |
| 2018 | EMA-LAB: Efficient Multi Authorisation Level Attribute Based Access Control
Nesrine Kaaniche, Sana Belguith, Giovanni Russello |
NSS | 1 |
| 2018 | PHOABE: Securely outsourcing multi-authority attribute based encryption with policy hidden for cloud assisted IoT
Sana Belguith, Nesrine Kaaniche, Maryline Laurent, Abderrazak Jemai, Rabah Attia |
Comput. Networks | 2 |
| 2017 | A blockchain-based data usage auditing architecture with enhanced privacy and availabilityabstractRecent years have witnessed the trend of increasingly relying on distributed infrastructures. This increased the number of reported incidents of security breaches compromising users' privacy, where third parties massively collect, process and manage users' personal data. Towards these security and privacy challenges, we combine hierarchical identity based cryptographic mechanisms with emerging blockchain infrastructures and propose a blockchain-based data usage auditing architecture ensuring availability and accountability in a privacy-preserving fashion. Our approach relies on the use of auditable contracts deployed in blockchain infrastructures. Thus, it offers transparent and controlled data access, sharing and processing, so that unauthorized users or untrusted servers cannot process data without client's authorization. Moreover, based on cryptographic mechanisms, our solution preserves privacy of data owners and ensures secrecy for shared data with multiple service providers. It also provides auditing authorities with tamper-proof evidences for data usage compliance. Nesrine Kaaniche, Maryline Laurent |
NCA | 1 |
| 2017 | Constant-size Threshold Attribute based SignCryption for Cloud ApplicationsabstractIn this paper, we propose a novel constant-size threshold attribute-based signcryption scheme for securely \nsharing data through public clouds. Our proposal has several advantages. First, it provides flexible cryptographic access control, while preserving users’ privacy as the identifying information for satisfying the access \ncontrol policy are not revealed. Second, the proposed scheme guarantees both data origin authentication and \nanonymity thanks to the novel use of attribute based signcryption mechanism, while ensuring the unlinkability \nbetween the different access sessions. Third, the proposed signcryption scheme has efficient computation cost \nand constant communication overhead whatever the number of involved attributes. Finally, our scheme satisfies strong security properties in the random oracle model, namely Indistinguishability against the Adaptive \nChosen Ciphertext Attacks (IND-CCA2), Existential Unforgeability against Chosen Message Attacks (EUFCMA) and privacy preservation of the attributes involved in the signcryption process, based on the assumption \nthat the augmented Multi-Sequence of Exponents Decisional Diffie-Hellman (aMSE-DDH) problem and the \nComputational Diffie Hellman Assumption (CDH) are hard. Sana Belguith, Nesrine Kaaniche, Maryline Laurent, Abderrazak Jemai, Rabah Attia |
SECRYPT | 2 |
| 2017 | Attribute based Encryption for Multi-level Access Control PoliciesabstractInternational audience Nesrine Kaaniche, Maryline Laurent |
SECRYPT | 1 |
| 2017 | Data security and privacy preservation in cloud storage environments based on cryptographic mechanisms
Nesrine Kaaniche, Maryline Laurent |
Comput. Commun. | 1 |
| 2016 | Attribute-Based Signatures for Supporting Anonymous Certification
Nesrine Kaaniche, Maryline Laurent |
ESORICS (1) | 1 |
| 2016 | PAbAC: A Privacy Preserving Attribute based Framework for Fine Grained Access Control in CloudsabstractInternational audience Sana Belguith, Nesrine Kaaniche, Abderrazak Jemai, Maryline Laurent, Rabah Attia |
SECRYPT | 2 |
| 2015 | SHoPS: Set Homomorphic Proof of Data Possession Scheme in Cloud Storage ApplicationsabstractThe prospect of outsourcing an increasing amount of data to a third party and the abstract nature of the cloud promote the proliferation of security and privacy challenges, namely, the remote data possession checking. This paper addresses this security concern, while supporting the verification of several data blocks outsourced across multiple storing nodes. We propose a new set homomorphic proof of data possession, called SHoPS, supporting the verification of aggregated proofs. It proposes a deterministic Proof of Data Possession (PDP) scheme based on interactive proof protocols. Our approach has several advantages. First, it supports public verifiability where the data owner delegates the verification process to another entity, thus releasing him from the burden of periodical verifications. Second, it allows the aggregation of several proofs and the verification of a subset of data files' proofs while providing an attractive communication overhead. Nesrine Kaaniche, Maryline Laurent |
SERVICES | 1 |
| 2014 | A Novel Zero-Knowledge Scheme for Proof of Data Possession in Cloud Storage ApplicationsabstractRecent technological advances have given rise to the popularity and success of cloud storage. However, the prospect of outsourcing an increasing amount of data to a third party and the abstract nature of the cloud foster the proliferation of security and privacy challenges, namely, the remote data possession checking. This paper addresses this critical security concern, when storing sensitive data in a cloud storage service, and the need for users to trust commercial cloud providers. It proposes a deterministic Proof of Data Possession (PDP) scheme based on Interactive Proof System(IPS) and an original usage of the GPS scheme. Our approach has several advantages. First, it supports public verifiability which releases data owners from the burden of a periodical verification. Second, it provides constant communication complexity, where the exchanged messages between the storage server and the client are composed of constant number of group elements. Third, our solution is efficient and provably secure, as it is resistant to the fraudulence of the prover and the leakage of verified data. Nesrine Kaaniche, Ethmane El Moustaine, Maryline Laurent |
CCGRID | 1 |
| 2014 | CloudaSec: A Novel Public-key Based Framework to Handle Data Sharing Security in CloudsabstractInternational audience Nesrine Kaaniche, Maryline Laurent, Mohammed El-Barbori |
SECRYPT | 1 |
| 2013 | ID Based Cryptography for Cloud Data StorageabstractThis paper addresses the security issues of storing sensitive data in a cloud storage service and the need for users to trust the commercial cloud providers. It proposes a cryptographic scheme for cloud storage, based on an original usage of ID-Based Cryptography. Our solution has several advantages. First, it provides secrecy for encrypted data which are stored in public servers. Second, it offers controlled data access and sharing among users, so that unauthorized users or untrusted servers cannot access or search over data without client's authorization. Nesrine Kaaniche, Aymen Boudguiga, Maryline Laurent |
IEEE CLOUD | 1 |