Saad El Jaouhari

dblp:197/6985 · DBLP profile ↗
← Back
20ranked-venue papers
11as first author
14since 2021 · last 2026
0000-0002-1938-9963ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 7 · 5 first-author · 3 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 3 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Computer networks · 2 · 2 first-author · 1 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Is Your AI Model Secure? A Study of Data Poisoning Attacks on AI Models
Saad El Jaouhari, Nouredine Tamani, Lina Ferial Benassou
ICAART (5)1
2026 Parallelized derivation algorithm for anomaly detection in internet of things environments
Abdul-Qadir Khan, Nouredine Tamani, Saad El Jaouhari
Expert Syst. Appl.3
2025 MIDPS: A Multi-agent Host Intrusion Detection and Prevention System
Saad El Jaouhari, Andrei Vavilov, Julia Soloveva, Alexandru Archip, Nour El Madhoun
AINA (4)1
2025 A ML-Driven Pipeline for Automated YARA Rule Extraction and Malware Detection
Souhayla Touk, Saad El Jaouhari, Maurras Togbe
NSS2
2024 Addressing Security Challenges in Copyright Management Applications: The Blockchain Perspective
Nour El Madhoun, Badis Hammi, Saad El Jaouhari, Djamel Mesbah, Elsi Ahmadieh
AINA (6)3
2024 Improving ML/DL Solutions for Anomaly Detection in IoT Environments
Nouredine Tamani, Saad El Jaouhari, Abdul-Qadir Khan, Bastien Pauchet
AINA (6)2
2024 Improving ML-based Solutions for Linking of CVE to MITRE ATT &CK Techniques
abstract
As our reliance on digital technologies continues to grow, so does the urgency of bolstering our cyber-defenses against the rising threats posed by malicious entities. Existing cybersecurity frameworks and databases such as MITRE ATT&CK and Common Vulnerabilities and Exposures (CVE) offer valuable insights that can assist in mitigating these threats effectively. However, the aforementioned CVE and MITRE ATT &CK solutions operate in silos. We argue that automatically linking the vulnerabilities listed in CVE database to MITRE ATT &CK adversarial techniques and tactics, and in particular the updated ones, will offer crucial and valuable information for blue teams seeking to enhance their cybersecurity defense against cyberattacks. The main objective of this paper is to offer a proactive insight into an attacker's next move by studying ex-isting ML/DL approaches developed to predicting the association between MITRE techniques and CVE in terms of reproducibility, performance analysis, and possible improvements. For the latter aspect, data augmentation and hyperparameter tuning techniques have been used and the obtained results showed significant improvements.
Saad El Jaouhari, Nouredine Tamani, Rohan Isaac Jacob
COMPSAC1
2024 GuardLink: Dynamic Linking of CVE to MITRE ATT&CK Techniques using Machine Learning
abstract
As our dependence on digital technologies continues to expand, the need to strengthen our cyber defenses against the increasing threats posed by malicious entities becomes more critical. While existing cybersecurity frameworks and databases like MITRE ATT&CK and Common Vulnerabilities and Exposures (CVE) offer valuable insights for effective threat mitigation, they often operate independently, leading to siloed information. We assert that the automatic linking of vulnerabilities from the CVE database to MITRE ATT&CK adversarial techniques and tactics, particularly focusing on new ones, can provide essential information to empower blue teams in enhancing their cybersecurity defenses against cyberattacks. Gaining proactive insight into an attacker’s potential next moves is pivotal for effective defense strategies. Therefore, we introduce in this paper GuardLink, a dynamic approach for linking CVE identifiers (IDs) to MITRE ATT&CK techniques. We first studied, reproduced, evaluated, and improved state of the art models in the field. Furthermore, we proposed a new multi-label classification model that outperforms the existing ones and achieves an accuracy of 97.83%. To ensure transparency and reproducibility, the source code for GuardLink is made openly accessible on GitHub.
Saad El Jaouhari, Nouredine Tamani, Rohan Isaac Jacob
GLOBECOM1
2024 CTIoT: A Cyber Threat Intelligence Tool for IoT
abstract
The Internet of Things (IoT) has enabled intelligent services and revolutionized industries due to its sensing, actuating, and connectivity capabilities. However, this rapid expansion has also led to a surge of various types of vulnerabilities, posing significant challenges to the security and integrity of IoT ecosystems. The increasing number of vulnerabilities in IoT is explained by factors such as limited processing power and constrained resources, making them easy targets for cyberattacks. In this context, Cyber Threat Intelligence (CTI) plays a crucial role in providing actionable intelligence to identify, detect, and respond to threats targeting IoT infrastructure. Through threat intelligence feeds, analysis of indicators of compromise (IoCs), and proactive threat hunting, CTI enables organizations to enhance their situational awareness and strengthen their defenses against IoT-related threats. This paper proposes Cyber Threat Intelligence for IoT (CTIoT), a solution that effectively leverages CTI information to enhance IoT security. It actively and automatically collects and processes CTI data from heterogeneous sources, using Natural Language Processing (NLP) to identify vulnerabilities and threats related to IoT. The information is then presented in graph format that can be used by Graph Machine Learning to predict and detect cyberattacks. The proof of concept demonstrates the ability of our solution to monitor CTI data related to multiple IoT smart spaces with multiple IoT devices.
Saad El Jaouhari, Shaikh Ahmed
IWCMC1
2024 Knowledge-based anomaly detection: Survey, challenges, and future directions
Abdul-Qadir Khan, Saad El Jaouhari, Nouredine Tamani, Lina Mroueh
Eng. Appl. Artif. Intell.2
2023 StreamMLOps: Operationalizing Online Learning for Big Data Streaming & Real-Time Applications
abstract
Continuously learning and serving from evolving streaming data and serving in real-time is a challenging problem. Traditionally, data is partitioned and processed in batches to train machine learning (ML) models. In industrial applications, static models’ performance drops over time (model degradation, concept drift), requiring new models to be trained with recent data and redeployed in production. The scientific community has been studying online and adaptive methods to address batch-learning limitations and continuously train AI tasks for industrial applications such as cyber-security, AIOps, anomaly scoring, and drift detection in stock markets. This paper deals with the MLOps aspects of deploying such online and dynamic models to address the requirements in the production systems for real-time applications. Our architectures - based on open-source tools such as Kafka and River - demonstrated how online learning methods could be scaled horizontally in production to meet the demands of a high-velocity streaming pipeline. We demonstrate an MLOps strategy to perform incremental learning from streaming data and continuously deploy the online learning model without pausing the inference pipeline. Indeed, the design satisfies requirements such as model versioning, monitoring, audibility and reproducibility of prediction in both a supervised and semi-supervised setting. Our experiments - for malicious URLs detection task - performed on high-dimensional and feature-evolving streaming data (more than 3 million features) establish the effectiveness and efficiency of online learning models compared to batch (static) machine learning regarding both time and space complexity. Finally, we provide some best practices on data engineering for deploying online models to process a real-time feature stream in production environments. Code is publicly available for reproducibility.
Mariam Barry, Jacob Montiel, Albert Bifet, Sameer Wadkar, Nikolay Manchev, Max Halford, Raja Chiky, Saad El Jaouhari, Katherine B. Shakman, Joudi Al Fehaily, Fabrice Le Deit, Vinh-Thuy Tran, Eric Guerizec
ICDE8
2023 A Contextual Derivation Algorithm for Cybersecurity in IoT Environments
abstract
The increase in the number of IoT devices invading both private and professional spaces opens the way for different cyberattacks. Facing such threats requires new approaches capable of reading the context of a given situation and acting accordingly to protect the users’ data and applications. Logical-based approaches can be harnessed in this case because of the semantic dimension they model and implement. In this paper, we make use of an existential rule-based knowledge base to model an IoT environment and detect anomalies as inconsistencies inside the obtained logical system. Accordingly, we first introduce an algorithm for knowledge base rewriting into a context-based knowledge base. Then, we detail our contextualized derivation algorithm for inconsistency detection in such a logical system.
Abdul-Qadir Khan, Nouredine Tamani, Saad El Jaouhari, Lina Mroueh
TrustCom3
2022 Stream2Graph: Dynamic Knowledge Graph for Online Learning Applied in Large-scale Network
abstract
Knowledge Graphs (KG) are valuable information sources that store knowledge in a domain (healthcare, finance, e-commerce, cyber-security.). Most industrial KGs are dynamic by nature as they are updated regularly with streaming data (customer activity, network traffic, application logs, IT process). However, extracting insights from continuously updated data comes with major challenges, particularly in big data settings. In this paper, we address the following challenges: 1) ingesting heterogeneous data, 2) training and deployment of predictive models on continuously evolving data, and 3) implementation of data pipelines for updating and maintaining the KG in production. We cover multiple aspects of this process, from knowledge collection to its operationalization. We propose Stream2Graph, a stream-based system for building and updating the knowledge base dynamically in real time. Then we show how graph features can be used in downstream online machine learning models. The solution speeds up big data stream learning and knowledge extraction to enhance Graph-based AI applications. Experimental results show the effectiveness of our solution for knowledge base construction and improvement of big data learning capabilities. Using data from Stream2Graph resulted in speedups for training and inference time in the range from 547x to 2000x in downstream ML models. Finally, we provide the lessons learned from applying graph-based online learning on large-scale network processing high-velocity streaming data.
Mariam Barry, Albert Bifet, Raja Chiky, Saad El Jaouhari, Jacob Montiel, Aissa El Ouafi, Eric Guerizec
IEEE Big Data4
2022 StreamFlow: A System for Summarizing and Learning Over Industrial Big Data Streams
abstract
The growing need for predictive analytics over streaming data in the industry requires a flexible and continuously scalable big data system. In real-time big data applications (cybersecurity, AIOps, anomaly detection, predictive maintenance, IoT etc.), efficient machine learning models must be trained and industrialized within existing data processing plat-forms and industrial tools. This requires interoperability between various components: data collection, processing, summarization, modelling and analytics. Existing works focus on building AI models for big data, neglecting real-world challenges when integrating such models into an existing industrial production framework. In this paper, we propose StreamFlow, an operational data pipeline to address industrial challenges for continuous learning over big data streams. We also propose an online method using sliding windows to summarize high-velocity data. The final result of the framework is a feature vector that describes the underlying processes and is ready to use in machine learning tasks. Moreover, we showcase real-world applications such as automated feature engineering for real-time monitoring and online machine learning for event classification. The proposed system has been deployed within production in a banking system, processing billions of daily traffic operations. Our experiments demonstrate the effectiveness and performance of our approach by evaluating it at different levels: processing, summarization, improvement of machine learning performance and effectiveness in an industrial setting. In the case of downstream machine learning tasks, using summarized data generated by StreamFlow results in up to 2 orders of magnitude speedups in training time without compromising predictive performance.
Mariam Barry, Saad El Jaouhari, Albert Bifet, Jacob Montiel, Eric Guerizec, Raja Chiky
IEEE Big Data2
2019 World First Retransmission of Medical Images in an Operating Room via DICOM-RTV: Technical Details
abstract
This paper provides technical details regarding the worldwide premiere implementation of the DICOM Real-Time Video (DICOM-RTV), in which an experimental setup was deployed at the Rennes University Hospital in France during five Urological surgeries. The solution allows the real-time retransmission of medical images from different equipment in the operating room in a perfectly synchronized way. In this paper, we show how we have been able to transport and synchronize the video signal from a camera recording the hand gestures of the surgeon, and from an endoscope used by the same surgeon. This paper also demonstrates the interest of using the new DICOM-RTV standard in order to improve the surgical gestures precision and to provide precise, real-time and synchronized instructions to the different operators during a surgery, toward the next generation operation rooms.
Saad El Jaouhari, Patrick Hardy, Guillaume Pasquier, Pierrick Guitter, Eric Poiseau, Cédric Moubri-Tournes, Stéphane Leduc, Sebastien Vincendeau, Laurent Bourgeois, Bernard Gibaud, Emmanuel Cordonnier
COMPSAC (2)1
2019 Streaming DICOM Real-Time Video and Metadata Flows outside the Operating Room
abstract
With the current advancement in the medical world, surgeons are faced with the challenge of handling many sources of medical information in more and more complex and technological Operating Rooms (ORs). Obviously, in the next generation ones, there will be an increasing number of video flows during the surgery (e.g. endoscopes, cameras, ultrasounds, etc.), which can be also displayed all over the OR in order to facilitate the task for the surgeon and to avoid any adverse events or problems related to inadequate communication in the OR. Additionally, other information needs to be shared, pre/post/during an operation, such as the history of the digital images related to the patient in the PACS and the metadata coming from medical sensors. Moreover, these medical videos captured from the OR can be either displayed on a large screen in the OR in order to provide the surgeon with more visibility, in this case via DICOM-RTV, or streamed outside the OR via a P2P solution. The latter one can serve various purposes such as for teaching medical student in real-time or for remote- expertise with a remote senior surgeons. Hence, this paper addresses the challenges of streaming DICOM-RTV video and metadata flows live from the operating room, typically during an ongoing surgery, in real-time to the outside world. A Proof of Concept is also presented in order to demonstrate the feasibility of our solution.
Saad El Jaouhari, Guillaume Pasquier, Amelie Serrand, Bernard Gibaud, Patrick Hardy, Emmanuel Cordonnier
GLOBECOM1
2019 Introduction to DICOM-RTV: a new standard for real-time video communication in hospitals
abstract
In order to overcome the challenges of managing real-time transfer of video, and/or audio, and associated medical metadata inside the medical theaters (e.g., operating room), a new DICOM communication service standard emerged. Its main objective is to deliver synchronized videos (potentially synchronized with their corresponding metadata) in real-time to surgeons during a surgery inside an operating room. Moreover, it allows, on one side, the transmission of real-time videos to subscribers with a quality of service comparable to the one inside the operating room, and on the other side, provides a standard that will allow the interoperability between the different medical equipment that produce/consume the media essences. This new DICOM extension is called DICOM Real-Time Video (DICOM-RTV). This paper is an introduction to this extension. It mainly presents the different challenges solved by this extension, illustrates it with relevant use cases, and provides the global architecture of the DICOM-RTV system.
Saad El Jaouhari, Bernard Gibaud, Philippe Lemonnier, Guillaume Pasquier, Eric Poiseau, Eric Guiffard, Patrick Hardy, Emmanuel Cordonnier
HealthCom1
2018 A Privacy Safeguard Framework for a WebRTC/WoT-Based Healthcare Architecture
abstract
In this paper, an e-health architecture offering secure remote medical services using WebRTC (Web Real-Time Communication) enhanced with contextual health information coming from medical connected sensors, is proposed and analyzed. The goal is to allow patients (injured, elderly, disabled, etc.) to benefit from a medical assistance just by calling a remote medical support (doctors, nurses, etc.) using a real-time communication technology such as WebRTC. Moreover, the advancement of the medical devices, on one side, and the emergence of the Web of Things (WoT), on the other side, makes this approach possible. Hence, granting the users the ability of monitoring their own health status and an awareness of their health condition. However, in such architectures, in order for the users to access these services, they need to provide and exchange personal data, and in particular the health related ones. Therefore, user's private information may be exposed to privacy violation and disclosure. Understanding the privacy holes regarding the protection of the personal health related data, identifying the privacy leakage points and studying the privacy requirements are important in order to propose a privacy safeguard for the proposed healthcare architecture, which is the aim of this paper. Additionally, a risk analysis, the sources of these risks and the possible countermeasures are also conducted during this process.
Saad El Jaouhari, Ahmed Bouabdallah
COMPSAC (2)1
2018 Dynamic Security Management of Smart WoT Infrastructures Using SDN
abstract
The next generation of infrastructures (hospitals, factories, buildings, etc.) will be deeply impacted by the introduction of a huge number of IoT devices which will contribute to a significant improvement of their operations. This follows the trend of the Web of Things (WoT) which projects to seamlessly connect an incredible diversity of IoT devices and IoT frameworks in a novel way, enabling exciting new services and opportunities due to its flexible nature. However, it also means that more and more data need to be protected from external threats and unauthorized accesses. Additional security, privacy and monitoring mechanisms need to be deployed, together with an efficient management of those IoT devices for the new vision of smart infrastructure. This issue becomes more convoluted and hardly tractable when dealing with several smart objects of the infrastructure dispatched over different network locations that we call Smart Spaces (SS), along with evolving management rules which may be specific to each SS. This paper proposes to solve this issue by introducing an architecture based on an Software Defined Networking (SDN) controller for managing the secure access to the different SSs of a smart infrastructure. We argue that a centralized view can greatly simplify and improve the security management of such infrastructures. We illustrate our approach with a use case from the e-Health domain involving the management of the security of different rooms of an hospital where each room is considered as an SS. A Proof of Concept is also provided, with a concrete implementation of all the components together with an analysis of the performance and the security of the new architecture.
Saad El Jaouhari, Ahmed Bouabdallah
VTC Fall1
2017 Toward a Smart Health-Care Architecture Using WebRTC and WoT
Saad El Jaouhari, Ahmed Bouabdallah, Jean-Marie Bonnin, Tayeb Lemlouma
WorldCIST (3)1