VLDB 2026 Research / reviewers in the wild / expert
Jean-Philippe Monteuuis
dblp:192/5948 · also Jean Philippe Monteuuis
· DBLP profile ↗
9ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-7712-1132ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CP-FREEZER: Latency Attacks Against Vehicular Cooperative PerceptionabstractCooperative perception (CP) enhances situational awareness of connected and autonomous vehicles by exchanging and combining messages from multiple agents. While prior work has explored adversarial integrity attacks that degrade detection accuracy, little is known about CP's robustness against attacks on timeliness (or availability), a safety-critical requirement for autonomous driving. In this paper, we present CP-FREEZER, the first latency attack that maximizes the computation delay of CP algorithms by injecting adversarial perturbation via V2V messages. Our attack resolves several unique challenges, including the non-differentiability of point cloud preprocessing, asynchronous knowledge of the victim’s input due to transmission delays, and uses a novel loss function that effectively maximizes the execution time of the CP pipeline. Extensive experiments show that CP-FREEZER increases end-to-end CP latency by over 90×, pushing per-frame processing time beyond 3 seconds with a 100% success rate on our real-world vehicle testbed. Our findings reveal a critical threat to the availability of CP systems, highlighting the urgent need for robust defenses. Chenyi Wang 0005, Ruoyu Song 0001, Raymond Muller, Jean-Philippe Monteuuis, Z. Berkay Celik, Jonathan Petit, Ryan M. Gerdes, Ming Li 0003 |
AAAI | 4 |
| 2025 | Latency NMS Attacks: Is It Real Life or Is It Just Fantasy?abstract``Caught in a landslide, no escape from reality" summarizes the state of the research in AI offense: an attack might work on paper but does not necessarily in practice. In the last 5 years, we have seen the rise of latency attacks against computer vision systems. Most of them targeted 2D object detection, especially its Non-Max-Suppression (NMS) block, via adversarial images. However, we uncovered that, when tested in realistic deployment settings, the NMS latency attacks, accepted to top conferences, have very limited negative effects. In this paper, we define an evaluation framework (EVADE) to assess the practicality of attacks, and apply it to state-of-the-art NMS latency attacks. Attacks were tested on different hardware platforms, and different model formats and quantization. Results show that these attacks are not able to generate the claimed latency increase, nor transfer to other models (from the same family or not).
Moreover, the latency increases remain within the latency requirements of downstream tasks in our evaluation, suggesting limited practical impact under these conditions. We also tested three defenses, which were successful in mitigating the NMS latency attacks. Therefore, in their current form, NMS latency attacks are just fantasy. Jean-Philippe Monteuuis, Jonathan Petit |
NeurIPS | 1 |
| 2025 | Investigating Physical Latency Attacks Against Camera-Based PerceptionabstractCamera-based perception is a central component to the visual perception of autonomous systems. Recent works have investigated latency attacks against perception pipelines, which can lead to a Denial-of-Service against the autonomous system. Unfortunately, these attacks lack real-world applicability, either relying on digital perturbations or requiring large, unscalable, and highly visible patches that cover up the victim's view. In this paper, we propose Detstorm, a novel physically realizable latency attack against camera-based perception. Detstorm uses projector perturbations to cause delays in perception by creating a large number of adversarial objects. These objects are optimized on four objectives to evade filtering by multiple Non-Maximum Suppression (NMS) approaches. To maximize the number of created objects in a dynamic physical environment, Detstorm takes a unique greedy approach, segmenting the environment into “zones” containing distinct object classes and maximizing the number of created objects per zone. Detstorm adapts to changes in the environment in real time, recombining perturbation patterns via our zone stitching process into a contiguous, physically projectable image. Evaluations in both simulated and real-world experiments show that Detstorm causes a 506% increase in detected objects on average, delaying perception results by up to 8.1 seconds, and capable of causing physical consequences on real-world autonomous driving systems. Raymond Muller, Ruoyu Song 0001, Chenyi Wang 0005, Yuxia Zhan, Jean-Philippe Monteuuis, Yanmao Man, Ming Li 0003, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik |
SP | 5 |
| 2025 | From Threat to Trust: Exploiting Attention Mechanisms for Attacks and Defenses in Cooperative Perception
Chenyi Wang 0005, Raymond Muller, Ruoyu Song 0001, Jean-Philippe Monteuuis, Jonathan Petit, Yanmao Man, Ryan M. Gerdes, Z. Berkay Celik, Ming Li 0003 |
USENIX Security Symposium | 4 |
| 2025 | VehiGAN: Generative Adversarial Networks for Adversarially Robust V2X Misbehavior Detection SystemsabstractVehicle-to-Everything (V2X) communication enables vehicles to communicate with other vehicles and roadside infrastructure, enhancing traffic management and improving road safety. However, the open and decentralized nature of V2X networks exposes them to various security threats, especially misbehaviors, necessitating a robust Misbehavior Detection System (MBDS). While Machine Learning (ML) has proved effective in different anomaly detection applications, the existing ML-based MBDSs have shown limitations in generalizing due to the dynamic nature of V2X and insufficient and imbalanced training data. Moreover, they are known to be vulnerable to adversarial ML attacks. On the other hand, Generative Adversarial Networks (GAN) possess the potential to mitigate the aforementioned issues and improve detection performance by synthesizing unseen samples of minority classes and utilizing them during their model training. Therefore, we propose the first application of GAN to design an MBDS that detects any misbehavior and ensures robustness against adversarial perturbation. In this article, we present several key contributions. First, we propose an advanced threat model for stealthy V2X misbehavior where the attacker can transmit malicious data and mask it using adversarial attacks to avoid detection by ML-based MBDS. We formulate two categories of adversarial attacks against the anomaly-based MBDS. Later, in the pursuit of a generalized and robust GAN-based MBDS, we train and evaluate a diverse set of Wasserstein GAN (WGAN) models and present Ve hicular GAN ( VehiGAN ), an ensemble of multiple top-performing WGANs, which transcends the limitations of individual models and improves detection performance. We present a physics-guided data preprocessing technique that generates effective features for ML-based MBDS. In the evaluation, we leverage the state-of-the-art V2X attack simulation tool VASP to create a comprehensive dataset of V2X messages with diverse misbehaviors. Evaluation results show that in 20 out of 35 misbehaviors, VehiGAN outperforms the baseline and exhibits comparable detection performance in other scenarios. Particularly, VehiGAN excels in detecting advanced misbehaviors that manipulate multiple fields in V2X messages simultaneously, replicating unique maneuvers. Moreover, VehiGAN provides approximately 92% improvement in false positive rate under powerful adaptive adversarial attacks, and possesses intrinsic robustness against other adversarial attacks that target the false negative rate. Finally, we make the data and code available for reproducibility and future benchmarking, available at https://github.com/shahriar0651/VehiGAN . Md Hasan Shahriar, Mohammad Raashid Ansari, Jean-Philippe Monteuuis, Md Shahedul Haque, Jonathan Petit, Y. Thomas Hou 0001, Wenjing Lou |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2024 | Vehigan:Generative Adversarial Networks for Adversarially Robust V2X Misbehavior Detection SystemsabstractVehicle-to-Everything (V2X) communication enables vehicles to communicate with other vehicles and roadside infrastructure, enhancing traffic management and improving road safety. However, the open and decentralized nature of V2X networks exposes them to various security threats, necessitating a robust misbehavior detection system (MBDS). While machine learning (ML) has proved effective in different anomaly detection applications, the existing ML-based MBDSs have shown limitations in generalizing due to the dynamic nature of V2X and insufficient and imbalanced training data. Moreover, they are known to be vulnerable to adversarial ML attacks. On the other hand, generative adversarial networks (GAN) possess the potential to mitigate such issues and improve detection performance by synthesizing unseen samples of minority classes and utilizing them during their model training. Therefore, we propose the first application of GAN to design an MBDS. Our contributions are manifold. In the pursuit of an effective GAN-based MBDS, we train and evaluate a diverse set of Wasserstein GAN (WGAN) models and present VEhicular GAN (VEHIGAN), an ensemble of multiple top-performing WGANs, which transcends the limitations of individual models and improves detection performance and adversarial robustness. We present a physics-guided data preprocessing technique that generates effective features for ML-based misbehavior detection. To evaluate the adversarial robustness, we formulate two categories of adversarial attacks against the WGAN-based MBDS. In the evaluation, we leverage the state-of-the-art V2X attack simulation tool VASP to create a comprehensive dataset of V2X messages with diverse misbehaviors. Evaluation results show that in 20 out of 35 misbehaviors, VehigAnoutperforms the baselines and exhibits comparable detection performance in other scenarios. Particularly, VehigAnexcels in detecting advanced misbehaviors that manipulate multiple fields in V2X messages simultaneously, replicating unique maneuvers. Moreover, VehigAnprovides approximately 92% improvement in false positive rates under powerful adaptive adversarial attacks and possesses intrinsic robustness against other adversarial attacks that target false negative rates. Finally, we make the data and code available for reproducibility and future benchmarking, available at https://eithub.com/shahriar0651/VehiGAN. Md Hasan Shahriar, Mohammad Raashid Ansari, Jean-Philippe Monteuuis, Jonathan Petit, Y. Thomas Hou 0001, Wenjing Lou |
ICDCS | 3 |
| 2021 | Spatial and Temporal Cross-Validation Approach for Misbehavior Detection in C-ITS
Mohammed Lamine Bouchouia, Jean-Philippe Monteuuis, Ons Jelassi, Houda Labiod, Wafa Ben Jaballah, Jonathan Petit |
RCIS | 2 |
| 2017 | Securing PKI Requests for C-ITS SystemsabstractCooperative Intelligent Transportation Systems are rapidly gaining momentum in the scenario of modern wireless communications. Within these environments, messages are exchanged continuously. The latter should be secure and ensure users' privacy. Public Key Infrastructures (PKIs) represent the major solution to meet security needs. On the other hand, communications between the PKI and the vehicle stations or the Road Side Unit stations should also be secure. Main current security standards do not address and define a complete detailed secure end-to-end mechanism to send requests to the PKI and receive the associated responses. In this paper, we propose a detailed security protocol, based on ETSI security standards, that ensures confidentiality, integrity and authentication. The evaluation of the latter shows its ability in meeting security needs. Jean-Philippe Monteuuis, Badis Hammi, Eduardo Salles Daniel, Houda Labiod, Remi Blancher, Erwan Abalea, Brigitte Lonc |
ICCCN | 1 |
| 2017 | ASN.1 Specification for ETSI Certificates and Encoding Performance StudyabstractCooperative Intelligent Transportation Systems (C-ITS) are gaining ground and are almost part of our everyday life. Within these environments, huge amounts of messages are exchanged. Besides, these messages should be secure in order to ensure users' privacy. Public Key Infrastructures (PKI) represent the most common security solution. Due to the vehicles speed, the communication with the PKI should be fully optimized. The European Telecommunications Standards Institute (ETSI) proposes a PKI architecture for C-ITS environments. However, unlike most of security standards as IEEE 1609.2, there is no Abstract Syntax Notation One (ASN.1) specification for the used certificates. For this reason, in this paper, we propose an ASN.1 definition for the ETSI certificate to help developers in its implementation. In addition, we provide an extensive comparative study of the different encoding schemes, applied to this proposal. Badis Hammi, Jean-Philippe Monteuuis, Eduardo Salles Daniel, Houda Labiod |
MDM | 2 |