Yair Meidan

dblp:200/5777 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0003-4865-2334ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 3 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 SecMate: Multi-agent Adaptive Cybersecurity Troubleshooting with Tri-Context Personalization
Yair Meidan, Omri Haller, Yulia Moshan, Shahaf David, Dudu Mimran, Yuval Elovici, Asaf Shabtai
DBSec1
2026 ImpReSS: Designing and Evaluating a Lightweight Implicit Recommender System in Conversational Support Agents
abstract
Large language model (LLM)-powered AI agents have transformed customer support, yet little research has addressed the integration of product recommendations into problem-solving dialogues. We introduce ImpReSS, a lightweight implicit recommender system for conversational support agents based on small language and embedding models, making it suitable for on-premise deployment where data privacy is critical. Unlike traditional conversational recommender systems (CRSs), ImpReSS does not assume purchasing intent. Instead, it identifies relevant solution product categories (SPCs) from the conversational context to assist in problem resolution. Our offline evaluation on three real-world datasets demonstrates strong performance, achieving an MRR@1 of up to 0.477 and outperforming five competing methods, including a state-of-the-art CRS. Algorithmic relevance alone is insufficient for effective adoption. A controlled user study with 144 participants shows that the perceived naturalness of recommendations depends strongly on their delivery. Conventional UI patterns such as pop-ups were rated as more appropriate than in-conversation insertions. Optimal timing varied by context, suggesting that recommendations should adapt dynamically to user needs. Thematic analysis of participant feedback further highlights a need for greater user agency, including the ability to interact with, question, and explore alternatives. We present the first comprehensive study of integrating implicitly-inferred recommendations in support dialogues. Our findings highlight the challenges of balancing accuracy with interaction design and yield empirically grounded implications for integrating recommender systems into conversational support agents.
Omri Haller, Yair Meidan, Dudu Mimran, Yuval Elovici, Asaf Shabtai
IUI2
2023 D-Score: An expert-based method for assessing the detectability of IoT-related cyber-attacks
Yair Meidan, Daniel Benatar, Ron Biton, Dan Avraham, Asaf Shabtai
Comput. Secur.1
2023 CADeSH: Collaborative Anomaly Detection for Smart Homes
abstract
Although home Internet of Things (IoT) devices are typically plain and task oriented, the context of their daily use may affect their traffic patterns. That is, a given IoT device will probably not generate the exact same traffic data when operated by different people in different environments and when connected to different networks with different topologies and communication components. For this reason, anomaly-based intrusion detection systems tend to suffer from a high false positive rate (FPR). To overcome this, we propose a two-step collaborative anomaly detection method which first uses an autoencoder to differentiate frequent (“benign”) and infrequent (possibly “malicious”) traffic flows. Clustering is then used to analyze only the infrequent flows and classify them as either known (“rare yet benign”) or unknown (malicious). Our method is collaborative, in that 1) normal behaviors are characterized more robustly, as they take into account a variety of user interactions and network topologies and 2) several features are computed based on a pool of identical devices rather than just the inspected device. We evaluated our method empirically, using 21 days of real-world traffic data that emanated from eight identical IoT devices deployed on various networks, one of which was located in our controlled lab where we implemented two popular IoT-related cyber-attacks. Our collaborative anomaly detection method achieved a macro-average area under the precision–recall curve of 0.841, an F1 score of 0.929, and an FPR of only 0.014. These promising results were obtained by using labeled traffic data from our lab as the test set, while training the models on the traffic of devices deployed outside the lab, and thus demonstrate a high level of generalizability. In addition to its high generalizability and promising performance, our proposed method also offers benefits, such as privacy preservation, resource savings, and model poisoning mitigation. On top of that, as a contribution to the scientific community, our novel data set is available online.
Yair Meidan, Dan Avraham, Hanan Libhaber, Asaf Shabtai
IEEE Internet Things J.1
2021 DeepStream: Autoencoder-based stream temporal clustering and anomaly detection
Shimon Harush, Yair Meidan, Asaf Shabtai
Comput. Secur.2
2020 A novel approach for detecting vulnerable IoT devices connected behind a home NAT
abstract
Telecommunication service providers (telcos) are exposed to cyber-attacks executed by compromised IoT devices connected to their customers’ networks. Such attacks might have severe effects on the attack target, as well as the telcos themselves. To mitigate those risks, we propose a machine learning-based method that can detect specific vulnerable IoT device models connected behind a domestic NAT, thereby identifying home networks that pose a risk to the telcos infrastructure and service availability. To evaluate our method, we collected a large quantity of network traffic data from various commercial IoT devices in our lab and compared several classification algorithms. We found that (a) the LGBM algorithm produces excellent detection results, and (b) our flow-based method is robust and can handle situations for which existing methods used to identify devices behind a NAT are unable to fully address, e.g., encrypted, non-TCP or non-DNS traffic. To promote future research in this domain we share our novel labeled benchmark dataset.
Yair Meidan, Vinay Sachidananda, Hongyi Peng, Racheli Sagron, Yuval Elovici, Asaf Shabtai
Comput. Secur.1
2019 Security Testbed for Internet-of-Things Devices
abstract
The Internet of Things (IoT) is a global ecosystem of information and communication technologies aimed at connecting any type of object (thing), at any time, and in any place, to each other and to the Internet. One of the major problems associated with the IoT is the heterogeneous nature of such deployments; this heterogeneity poses many challenges, particularly, in the areas of security and privacy. Specifically, security testing and analysis of IoT devices is considered a very complex task, as different security testing methodologies, including software and hardware security testing approaches, are needed. In this paper, we propose an innovative security testbed framework targeted at IoT devices. The security testbed is aimed at testing all types of IoT devices, with different software/hardware configurations, by performing standard and advanced security testing. Advanced analysis processes based on machine learning algorithms are employed in the testbed in order to monitor the overall operation of the IoT device under test. The architectural design of the proposed security testbed along with a detailed description of the testbed implementation is discussed. The testbed operation is demonstrated on different IoT devices using several specific IoT testing scenarios. The results obtained demonstrate that the testbed is effective at detecting vulnerabilities and compromised IoT devices.
Shachar Siboni, Vinay Sachidananda, Yair Meidan, Michael Bohadana, Yael Mathov, Suhas Bhairav, Asaf Shabtai, Yuval Elovici
IEEE Trans. Reliab.3