Mohamed-Lamine Messai

dblp:20/9245 · DBLP profile ↗
← Back
18ranked-venue papers
5as first author
16since 2021 · last 2026
0000-0003-0376-0657ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 5 since 2021Computer networks · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Empowering cybersecurity analysis: Unifying CVE, CWE, and CPE through knowledge graphs
Kamal Benzekki, Mohamed-Lamine Messai
Comput. Secur.2
2025 SHIELD: Self-Healing IoT Networks with Automated Response and AI-Driven Detection of Node Compromising Attacks
abstract
The increasing prevalence of node-compromising attacks in Internet of Things (IoT) networks threatens the integrity, availability and reliability of data-driven decision-making. To address this, we propose SHIELD, an AI-driven self-healing framework that ensures robust detection and automatic mitigation of compromised nodes in large-scale IoT environments. SHIELD relies on the Isolation Forest algorithm for unsupervised anomaly detection, enabling accurate identification of malicious behavior without the need for labeled datasets. Beyond detection, SHIELD integrates a fully autonomous self-healing mechanism that revokes compromised nodes and dynamically reconfigures the network to maintain resilience and performance. Experimental evaluations demonstrate the effectiveness of SHIELD: it achieves a detection accuracy of 99.00%, surpassing traditional models such as MLP, SVM, and CNN. Notably, after an attack, SHIELD’s self-healing process significantly enhances detection performance — increasing recall from 35.29% to 82.35%, F1 score from 52.17% to 90.32%, and AUC-ROC from 67.64% to 91.17%. Moreover, SHIELD significantly enhances network efficiency by reducing overall energy consumption by 20.36%. These findings highlight SHIELD’s dual capability to deliver robust security and energy-efficient self-healing, positioning it as an ideal solution for resource-constrained IoT infrastructures.
Floribert Katembo Vuseghesa, Mohamed-Lamine Messai, Fadila Bentayeb
IWCMC2
2025 MOMRFO-SC: a multi-objective framework for large-scale IoT service composition
Macilia Boukhama, Zoubeyr Farah, Lynda Alkama, Mohamed-Lamine Messai
J. Supercomput.4
2024 FedHE-Graph: Federated Learning with Hybrid Encryption on Graph Neural Networks for Advanced Persistent Threat Detection
abstract
Intrusion Detection Systems (IDS) play a crucial role in safeguarding systems and networks from different types of attacks. However, IDSes face significant hurdles in detecting Advanced Persistent Threats (APTs), which are sophisticated cyber-attacks characterised by their stealth, duration, and advanced techniques. Recent research has explored the effectiveness of Graph Neural Networks (GNNs) in APT detection, leveraging their ability to analyse intricate-relationships within graph data. However, existing approaches often rely on local models, limiting their adaptability to evolving APT-tactics and raising privacy-concerns. In response to these challenges, this paper proposes integrating Federated-Learning (FL) into the architectures of GNN-based Intrusion Detection Systems. Moreover, our solution includes an enhanced encryption-system of the clients’ weights to safely send them to the server through the system’s network. This solution prevents man-in-the-middle (MitM) attacks from intercepting the weights and reconstructing clients data using reverse engineering. We evaluate our approach on several datasets, demonstrating promising results in reducing false-positive rates compared to state-of-the-art Provenance-based IDSes (PIDS).
Atmane Ayoub Mansour Bahar, Kamel Soaïd Ferrahi, Mohamed-Lamine Messai, Hamida Seba, Karima Amrouche
ARES3
2024 Node Compromising Detection to Mitigate Poisoning Attacks in IoT Networks
abstract
The emergence of the Internet of Things (IoT) networks as a source of large amount of data has paved the way for the adoption of machine learning models. Divers datasets, used in the training phase, are issued by collected data from deployed IoT networks. This has attracted the attention of adversaries seeking to exploit these models for their gain. The adversaries compromise IoT/sensor nodes to manipulate these models through poisoning attacks wherein they introduce carefully malicious data into the model’s training dataset. In this paper, we propose a framework, namely NoComP for Node Compromising detection, to defend against poisoning attacks by detecting compromised nodes and delete their readings from the collected data. NoComP prevents datasets to be mixed poisonous collected sensed data. To this end, we use as machine learning algorithm the neural network to detect compromised nodes. This algorithm offer significant advantages in terms of efficiency and accuracy in detecting anomalies. We carry out experiments to evaluate NoComP and compare it with two existing proposals. The accuracy and efficiency results shows that NoComP outperforms the existing ones and improves the robustness against poisoning attacks.
Floribert Katembo Vuseghesa, Mohamed-Lamine Messai, Fadila Bentayeb
IWCMC2
2024 Blockchain-inspired Incentive Mechanism for Trust-aware Offloading in Mobile Edge Computing
abstract
This paper tackles the pressing concern of establishing trust within the context of Mobile Edge Computing (MEC) to enhance security in task-offloading interactions. MEC’s potential to optimize service performance is contingent on seamless and secure interactions among its diverse entities, comprising mobile terminals and edge servers. To bridge this trust gap, we propose a robust trust management system that exploits the capabilities of blockchain technology. This system encompasses a trust management mechanism founded on a reputation metric, serving as the cornerstone for engendering trust in MEC transactions. In addition, the proposed solution is completed by an incentive approach embedded within game theory, meticulously designed to augment block mining efficiency. We adopt a Stackelberg game to model the intricate dynamics of interaction within this context, aptly capturing the verification incentive problem. This game orchestrates the actions of a leader (edge server) and subsequent followers (mobile terminals), leveraging a trustworthy offloading strategy formulation that culminates in optimal block validation decision-making. Our proposal guarantees the reliability of the offloading process and establishes a favorable relationship of confidence between the offloading system entities.
Ahmed Alioua, Nesrine Bouchemal, Randa Mati, Mohamed-Lamine Messai
LCN4
2024 Deep Reinforcement Learning-Based Moving Target Defense Approach to Secure Network Slicing in 5G and Beyond
abstract
Network slicing security in 5G and beyond 5G (B5G) networks is critical due to the wide range of supported services and applications. Existing literature focuses on reactive AI-based security that can detect and respond to threats after occurrence. In contrast, proactive security solutions, such as moving target defense (MTD), possess great promise. MTD involves constantly altering system configurations to increase uncertainty for attackers. Despite its potential, existing work that incorporates MTD often overlooks the intricate balance between enhancing security and maintaining network operational effi-ciency. This work proposes a novel approach to integrating Deep Reinforcement Learning (DRL) with MTD for network slicing security, our approach creates a moving target by dynamically reconfiguring IP addresses, complicating reconnaissance efforts, and thwarting potential attacks. Experimental results show that our solution achieves approximately 98 % effectiveness against Distributed Denial of Service (DDoS) attacks, demonstrating its efficacy in proactively mitigating threats.
Roumaissa Lallouche, Ahmed Alioua, Abdelwahab Boualouache, Mohamed-Lamine Messai
WiMob4
2023 IoT Network Attack Detection: Leveraging Graph Learning for Enhanced Security
abstract
IoT networks are the favorite target of cybercriminals. With more and more connected IoT devices, IoT networks offer large attack surface. There are many potential entry points for cybercriminals in these networks. Hence, attack detection is an essential part of securing IoT networks and protecting them against the potential harm or damage that can result from successful attacks. In this paper, we propose a graph-based framework for detecting attacks in IoT networks. Our approach involves constructing an activity graph to represent the networking events occurring during a monitoring window. This graph is a rich attributed graph capturing both structure and semantic features from the network traffic. Then, we train a neural network on this graph to distinguish between normal activities and attacks. Our preliminary experiments show that our approach is able to accurately detect a large range of attacks when the size of the monitoring window is correctly set.
Mohamed-Lamine Messai, Hamida Seba
ARES1
2023 A Self-Healing Pairwise Key Pre-Distribution Scheme in IoT-based WSNs
abstract
Wireless Sensor Networks (WSNs) are becoming integral to Internet of Things (IoT) applications. This emergence of the WSNs requires greater awareness of the security of IoT, which makes it inevitable to secure the communication medium of the WSNs. One way of securing the communication medium is to encrypt the data sent over the WSNs, requiring the usage of cryptographic materials to achieve the secrecy of the exchanged data between the sensor nodes. The main component of the cryptographic materials needed is the keys used to encrypt and decrypt the data. Symmetric pairwise keys are particularly convenient for resource-constrained networks like IoT-based WSNs as they ensure security while conserving resources. However, existing key management solutions based on symmetric cryptosystems are vulnerable to node compromising attacks. Another important aspect of WSNs is the addition of new sensor nodes (postdeployment) either periodically or depending on the use case, which means new symmetric pairwise keys must be provided to communicate with newly added sensor nodes. For this purpose, a new key pre-distribution scheme named POK (adaPtive and rObust Key pre-distribution) is presented in this paper. POK improves the way keys are generated and pre-loaded in the sensor nodes. The main idea of the POK is that newly added sensor nodes will be pre-loaded with pairwise keys computed by using a hash function and having knowledge of the number of future postdeployments. Comparison study with related works concludes that POK offers less communication overhead and doesn’t require time synchronization leading to an energy-efficient scheme. Also, POK decreases the impact of node compromising attacks and ensures the self-healing property where compromised nodes have a short time effect on the network and newly deployed nodes are not affected.
Mohamed-Lamine Messai
IWCMC1
2023 BKRSC-IoT: Blockchain-Based Key Revocation Using Smart Contracts for IoT Networks
Sami Bettayeb, Mohamed-Lamine Messai, Sofiane Mounine Hemam
MEDES2
2023 Study on Poisoning Attacks: Application Through an IoT Temperature Dataset
abstract
The past decade presents a massive adoption of machine learning in divers domains. This fact has been greatly facilitated by cloud computing, which has made high-performance computing capabilities and data storage accessible to organizations of all sizes. This article provides an in-depth examination of data poisoning attacks and their impact on the security of machine learning methods. To achieve our objective, four types of attacks were tested on a dataset obtained from connected devices in an Internet of Things (IoT) application that collects temperature readings. These attacks include data modification, data deletion, label flipping and sponge poisoning attack. These four types of attacks primarily aim to compromise the integrity and availability of the learning models. In this study, we create a Python script that randomly selects a set of nodes from the IoT network as nodes controlled by an attacker. These compromised nodes send corrupted data to initiate a poisoning attack. The results of the model trained on the attacked data were then compared with those of the model trained on normal data assumed to be unharmed.
Floribert Katembo Vuseghesa, Mohamed-Lamine Messai
WETICE2
2023 POSTER: Activity Graph Learning for Attack Detection in IoT Networks
abstract
IoT networks are the favorite target of cybercriminals. With more and more connected IoT devices, IoT networks offer large attack surface. There are many potential entry points for cybercriminals in these networks. Hence, attack detection is an essential part of securing IoT networks and protecting against the potential harm or damage that can result from successful attacks. In this paper, we propose a graph-based framework for detecting attacks in IoT networks. Our approach involves constructing an activity graph to represent the networking events occurring during a monitoring window. This graph is a rich attributed graph capturing both structure and semantic features from the network traffic. Then, we train a neural network on this graph to distinguish between normal activities and attacks. Our preliminary experiments show that our approach is able to accurately detect a large range of attacks when the size of the monitoring window is correctly set.
Mohamed-Lamine Messai, Hamida Seba
WoWMoM1
2023 A robust and efficient vector-based key management scheme for IoT networks
Sami Bettayeb, Mohamed-Lamine Messai, Sofiane Mounine Hemam
Ad Hoc Networks2
2023 A survey on implementations of homomorphic encryption schemes
Thi Van Thao Doan, Mohamed-Lamine Messai, Gérald Gavin, Jérôme Darmont
J. Supercomput.2
2022 Using Machine Learning in WSNs for Performance Prediction MAC Layer
abstract
To monitor environments, Wireless Sensor Networks (WSNs) are used for collecting data in divers domains such as smart factories, smart buildings, etc. In such environments, different medium access control (MAC) protocols are available to sensor nodes for wireless communications and are of a paramount importance to enhance the network performance. Proposed MAC layer protocols for WSNs are generally designed to achieve a good performance in packet reception rate. Once chosen, the MAC protocol is used and remains the same throughout the network lifetime even if its performance decreases over time. In this paper, we adopt supervised machine learning techniques to predict the performance of CSMA/CA MAC protocol based on the packet reception rate. Our approach consists of three steps: experiments for data collection, offline modeling and performance evaluation. Our analysis shows that XGBoost prediction model is the better supervised machine learning technique to enhance network performance at the MAC layer level. In addition, we use SHAP method to explain predictions.
El Arbi Abdellaoui Alaoui, Mohamed-Lamine Messai, Anand Nayyar
Int. J. Inf. Secur. Priv.2
2022 IFKMS: Inverse Function-based Key Management Scheme for IoT networks
Mohammed Nafi, Mohamed-Lamine Messai, Samia Bouzefrane 0001, Mawloud Omar
J. Inf. Secur. Appl.2
2016 A survey of key management schemes in multi-phase wireless sensor networks
Mohamed-Lamine Messai, Hamida Seba
Comput. Networks1
2015 A lightweight key management scheme for wireless sensor networks
Mohamed-Lamine Messai, Hamida Seba, Makhlouf Aliouat
J. Supercomput.1