Houda Jmila

dblp:156/8757 · DBLP profile ↗
← Back
16ranked-venue papers
8as first author
6since 2021 · last 2025
0000-0002-4864-5380ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 4 · 2 first-authorComputer networks · 3 · 3 first-author · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2025 Privacy Benchmarking of Intrusion Detection Sytems
Solayman Ayoubi, Gregory Blanc, Houda Jmila, Sébastien Tixeuil
AINA (4)3
2024 SoK: Federated Learning based Network Intrusion Detection in 5G: Context, State of the Art and Challenges
abstract
5G brings significant advancement, offering lower latency, and improved connectivity. Yet, its complexity, stemming from factors such as integrating advanced technologies like Software Defined Networking (SDN) and slicing, introduces challenges in implementing strong security measures against emerging threats. Although Intrusion Detection Systems (IDSs) can successfully detect attacks, the novelty of 5G creates an expanded attack surface. Collaboration is essential for detecting novel, distributed attacks, and ensuring comprehensive observability in multiparty networks. However, such collaboration raises privacy concerns due to the sensitivity of shared data. Federated Learning (FL), a collaborative Machine Learning (ML) approach, is a promising solution to preserve privacy as the model is trained locally without exchanging raw data.
Sara Chennoufi, Gregory Blanc, Houda Jmila, Christophe Kiennert
ARES3
2024 Demo: Towards Reproducible Evaluations of ML-Based IDS Using Data-Driven Approaches
abstract
Network-based Intrusion Detection Systems (NIDS) are crucial in cybersecurity, but evaluation methodologies are outdated and lack standardization, resulting in incomplete and unreliable assessments. To address these issues, we first proposed a comprehensive evaluation framework for Machine Learning-based Intrusion Detection Systems [1]. This framework accounts for the unique aspects, strengths, and weaknesses of ML algorithms. However, the initial proposition lacked practicality, as it presented an abstract methodology without a substantive solution. In this paper, we present a demo of FREIDA a precise and concrete implementation of our framework, featuring an easy-to-use graphical interface. We also outline FREIDA's evaluation methodology and demonstrate its application in evaluating IDS using a dataset from the literature.
Solayman Ayoubi, Sébastien Tixeuil, Gregory Blanc, Houda Jmila
CCS4
2024 FREIDA: A Concrete Tool for Reproducible Evaluation of IDS Using a Data-Driven Approach
Solayman Ayoubi, Gregory Blanc, Houda Jmila, Sébastien Tixeuil
CRiSIS3
2022 Adversarial machine learning for network intrusion detection: A comparative study
Houda Jmila, Mohamed Ibn Khedher
Comput. Networks1
2021 Towards security-Aware 5G slice embedding
Houda Jmila, Gregory Blanc
Comput. Secur.1
2020 Generative Deep Learning for Internet of Things Network Traffic Generation
abstract
The rapid development of the Internet of Things (IoT) has prompted a recent interest into realistic IoT network traffic generation. Security practitioners need IoT network traffic data to develop and assess network-based intrusion detection systems (NIDS). Emulating realistic network traffic will avoid the costly physical deployment of thousands of smart devices. From an attacker's perspective, generating network traffic that mimics the legitimate behavior of a device can be useful to evade NIDS. As network traffic data consist of sequences of packets, the problem is similar to the generation of sequences of categorical data, like word by word text generation. Many solutions in the field of natural language processing have been proposed to adapt a Generative Adversarial Network (GAN) to generate sequences of categorical data. In this paper, we propose to combine an autoencoder with a GAN to generate sequences of packet sizes that correspond to bidirectional flows. First, the autoencoder is trained to learn a latent representation of the real sequences of packet sizes. A GAN is then trained on the latent space, to learn to generate latent vectors that can be decoded into realistic sequences. For experimental purposes, bidirectional flows produced by a Google Home Mini are used, and the autoencoder is combined with a Wassertein GAN. Comparison of different network characteristics shows that our proposed approach is able to generate sequences of packet sizes that behave closely to real bidirectional flows. We also show that the synthetic bidirectional flows are close enough to the real ones that they can fool anomaly detectors into labeling them as legitimate.
Mustafizur R. Shahid, Gregory Blanc, Houda Jmila, Zonghua Zhang, Hervé Debar
PRDC3
2020 Solving security constraints for 5G slice embedding: A proof-of-concept
François Boutigny, Stéphane Betgé-Brezetz, Gregory Blanc, Antoine Lavignotte, Hervé Debar, Houda Jmila
Comput. Secur.6
2020 Automatic processing of Historical Arabic Documents: A comprehensive Survey
Mohamed Ibn Khedher, Houda Jmila, Mounim A. El-Yacoubi
Pattern Recognit.2
2019 Designing Security-Aware Service Requests for NFV-Enabled Networks
abstract
Network Function Virtualization (NFV) is a recent concept where virtualization enables the shift from network functions (e.g., routers, switches, load-balancers, proxies) on specialized hardware appliances to software images running on all-purpose, high-volume servers. The resource allocation problem in the NFV environment has received considerable attention in the past years. However, little attention was paid to the security aspects of the problem in spite of the increasing number of vulnerabilities faced by cloud-based applications. Securing the services is an urgent need to completely benefit from the advantages offered by NFV. In this paper, we show how a network service request, composed of a set of service function chains (SFC) should be modified and enriched to take into consideration the security requirements of the supported service. We examine the well-known security best practices and propose a two-step algorithm that extends the initial SFC requests to a more complex chaining model that includes the security requirements of the service.
Houda Jmila, Gregory Blanc
ICCCN1
2019 Siamese Network Based Feature Learning for Improved Intrusion Detection
Houda Jmila, Mohamed Ibn Khedher, Gregory Blanc, Mounim A. El-Yacoubi
ICONIP (1)1
2018 Fusion of Interest Point/Image based descriptors for efficient person re-identification
abstract
The paper proposes a novel video-based person re-identification system that consists of describing a person using both Interest Points (IP) and Image-based features. The Image-based descriptor extracts global image representation that includes the silhouette but also possibly extra objects (i.e animal, stroller, etc) while the IP-based descriptor extracts salient points associated each with a local region of one of the objects. Two reidentification systems are proposed: an IP-based system using SURF interest points matched via sparse representation, and Image-based system using a Convolutional Neural Network. To harness both representations, we propose a fusing strategy based on the scores product rule, the scores being vote vectors associated with each descriptor for each person. Our proposal is evaluated on the large public dataset PRID-2011 and the results show its effectiveness compared to the state of the art.
Mohamed Ibn Khedher, Houda Jmila, Mounim A. El-Yacoubi
IJCNN2
2017 Estimating VNF Resource Requirements Using Machine Learning Techniques
Houda Jmila, Mohamed Ibn Khedher, Mounim A. El-Yacoubi
ICONIP (1)1
2016 A self-stabilizing framework for dynamic bandwidth allocation in virtual networks
abstract
This paper addresses dynamic bandwidth allocation for virtual network (VN) resources to respond to increasing or decreasing applications requirements in cloud environments. A distributed and local-view framework, composed of a controller and three algorithms running in substrate nodes, is proposed to deal with all types of bandwidth demand fluctuations in embedded virtual networks. The framework is based on the Self-Stabilization concept to drive the system back to a “stable state” when new bandwidth demands drift the system away into an “unstable state”. Performance evaluation results demonstrate the effectiveness of our proposal in handling bandwidth demand fluctuations in convergence speed and cost.
Houda Jmila, Kaouther Drira, Djamal Zeghlache
NOMS1
2015 An adaptive load balancing scheme for evolving virtual networks
abstract
An algorithm to adapt dynamically virtual networks to additional resource requirements is proposed and evaluated. The optimization is achieved while balancing load and avoiding fragmentation in the infrastructure (often referred as substrate or physical network). The algorithm focuses on virtual nodes requiring more resources by extending their allocations and maintaining their connectivity (even if the node is migrated) to other resources while tidying up (or consolidating) the infrastructure. The algorithm outperforms existing approaches.
Houda Jmila, Djamal Zeghlache
CCNC1
2014 RSforEVN: Node reallocation algorithm for virtual networks adaptation
abstract
This paper addresses the dynamic adaptation of already embedded virtual network (VN) resources to respond to increasing network services demands and load on network nodes. The proposed algorithm focuses on the virtual nodes, of the embedded VN, requiring more resources. The adaptation scheme goes beyond the reallocation of the virtual nodes by considering their topological neighborhood. The proposed algorithm outperforms existing approaches in reallocation cost and in execution time (or convergence time) for larger graphs.
Houda Jmila, Ines Houidi, Djamal Zeghlache
ISCC1