VLDB 2026 Research / reviewers in the wild / expert
Tal Shapira
dblp:221/2216
· DBLP profile ↗
14ranked-venue papers
6as first author
12since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 4 first-author · 9 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Accurate Route Encoding for IP Hijack Detection and GeoIP Database Error Detection
Yonatan Sigal, Tal Shapira, Yuval Shavitt |
INFOCOM | 2 |
| 2025 | Non-uniformity is All You Need: Efficient and Timely Encrypted Traffic Classification With ECHOabstractWith 95% of Internet traffic now encrypted, an effective approach to classifying this traffic is crucial for network security and management. This paper introduces ECHO—a novel optimization process for ML/DL-based encrypted traffic classification that can significantly improve many suggested classification schemes. ECHO targets both classification time and memory utilization and incorporates two innovative techniques.The first component, HO (Hyperparameter Optimization of binnings), aims at creating efficient traffic representations. While previous research often uses representations that map packet sizes and packet arrival times to fixed-sized bins, we show that non-uniform binnings are significantly more efficient. These non-uniform binnings are derived by employing a hyperparameter optimization algorithm in the training stage. HO significantly improves accuracy given a required representation size, or, equivalently, achieves comparable accuracy using smaller representations.Then, we explore EC (Early Classification of traffic), which enables faster classification using a cascade of classifiers adapted for different exit times, where classification is based on the level of confidence. EC reduces the average classification latency by up to 90%. Remarkably, this method not only maintains classification accuracy but also, in certain cases, improves it.Using three publicly available datasets, we demonstrate that the combined method, Early Classification with Hyperparameter Optimization (ECHO), leads to a significant improvement in classification efficiency. Shilo Daum, Tal Shapira, Anat Bremler-Barr, David Hay |
ICNP | 2 |
| 2025 | ZEAL in the Cloud: IoT Labeling SystemabstractZEAL (Zero-shot Engine for IoT Asset Labeling) is an open-source system that labels never-seen IoT devices by finding their vendor (e.g., Xiaomi, TP-Link) and function (e.g., Light, Plug) based on textual features extracted from the device network traffic, such as domains and hostnames. The system gets as an input features and enriches them using online searches. Then, it applies a string-matching algorithm to label its vendor and large language model (LLM) to label its function. The system is implemented as a serverless architecture on AWS, ZEAL utilizes services such as Lambda, Elastic File System (EFS), and S3, ensuring scalability but economic implementation. This demonstration showcases ZEAL's ability to enhance network visibility and asset management by accurately labeling devices with minimal prior knowledge. The system is open-source publicly accessible via API and GUI for research and business applications (https://labelmydevice.com), licensed under the Apache License 2.0. Bar Meyuhas, Anat Bremler-Barr, Tal Shapira |
NOMS | 3 |
| 2025 | FlowPicClip: Improving Network Traffic Classification Using Language SupervisionabstractTraffic classification has gained much attention in the past decade, and deep learning proved to exhibit good classification performance. However, the lack of large labeled datasets pushed research to explore few-shots learning approaches, where only a few labeled samples per class are available. Augmentation techniques tailored to the domain of network traffic were proved as a viable solution. In this paper, we demonstrate a new approach to obtain better classification accuracy. Our solution simplifies preprocessing and reduces training time, while effectively utilizing small amounts of training data. Furthermore, it proves to be highly effective in few-shot scenarios, demonstrating robust results when tested on disjoint datasets, specifically the UCDAVIS19 and ISCX datasets. Inspired by the recent breakthroughs in integrating image and text data, particularly the OpenAI CLIP model, we introduce FlowPicClip. This model harnesses the power of contrastive learning with FlowPics and their labels as text sentences. By leveraging Large Language Model (LLM) encoders, FlowPicClip aligns network traffic representations with their textual descriptions. We demonstrate 2.75% and 1.4% improvements over the best published results on the UCDavis19-Human and ISCX datasets for classification tasks, along with$\mathbf{1. 5 \%}$and$\mathbf{6. 2 \%}$improvements in few-shot classification achieved in a disjoint dataset scenario. Daniel Shalev, Tal Shapira, Yuval Shavitt |
WiMob | 2 |
| 2024 | Self-Supervised Traffic Classification: Flow Embedding and Few-Shot SolutionsabstractInternet traffic classification has been intensively studied over the past decade due to its importance for traffic engineering and cyber security. A promising approach to several traffic classification problems is the FlowPic approach, where histograms of packet sizes in consecutive time slices are transformed into a picture that is fed into a Convolution Neural Network (CNN) model for classification. However, CNNs (and the FlowPic approach included) require a relatively large labeled flow dataset, which is not always easy to obtain. In this paper, we show that we can overcome this obstacle by using Contrastive Representation Learning in order to learn from an unlabeled flow dataset a flow representation that can be embedded in a latent space, enabling clustering of flows belonging to the same class together. We then show that by using just a few labeled flows (a few shots) from each class, we can achieve high accuracy in flow classification. We show that common picture augmentation techniques can help, but accuracy improves further when introducing augmentation techniques that mimic network behavior, such as changes in the RTT (Round-trip time). Finally, we show that we can replace the large FlowPics suggested in the past with much smaller mini-FlowPics and achieve two advantages: improved model performance and easier engineering. Interestingly, this even improves accuracy in some cases. Eyal Horowicz, Tal Shapira, Yuval Shavitt |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | Next-Generation Security Entity Linkage: Harnessing the Power of Knowledge Graphs and Large LanguageabstractWith the continuous increase in reported Common Vulnerabilities and Exposures (CVEs), security teams are overwhelmed by vast amounts of data, which are often analyzed manually, leading to a slow and inefficient process. To address cybersecurity threats effectively, it is essential to establish connections across multiple security entity databases, including CVEs, Common Weakness Enumeration (CWEs), and Common Attack Pattern Enumeration and Classification (CAPECs). In this study, we introduce a new approach that leverages the RotatE [4] knowledge graph embedding model, initialized with embeddings from Ada language model developed by OpenAI [3]. Additionally, we extend this approach by initializing the embeddings for the relations. Daniel Alfasi, Tal Shapira, Anat Bremler-Barr |
SYSTOR | 2 |
| 2022 | A few shots traffic classification with mini-FlowPic augmentationsabstractInternet traffic classification has been intensively studied over the past decade due to its importance for traffic engineering and cyber security. One of the best solutions to several traffic classification problems is the FlowPic approach, where histograms of packet sizes in consecutive time slices are transformed into a picture that is fed into a Convolution Neural Network (CNN) model for classification. Eyal Horowicz, Tal Shapira, Yuval Shavitt |
IMC | 2 |
| 2022 | Fast and lean encrypted Internet traffic classification
Sangita Roy, Tal Shapira, Yuval Shavitt |
Comput. Commun. | 2 |
| 2022 | AP2Vec: An Unsupervised Approach for BGP Hijacking DetectionabstractBGP hijack attacks deflect traffic between endpoints through the attacker network, leading to man-in-the-middle attacks. Thus its detection is an important security challenge. In this paper, we introduce a novel approach for BGP hijacking detection that is based on the observation that during a hijack attack, the functional roles of ASNs along the route change. To identify a functional change, we build on previous work that embeds ASNs to vectors based on BGP routing announcements and embed each IP address prefix (AP) to a vector representing its latent characteristics, we call it AP2Vec. Then, we compare the embedding of a new route with the AP embedding that is based on the old routes to identify large differences. We compare our unsupervised approach to several other new and previous approaches and show that it strikes the best balance between a high detection rate of hijack events and a low number of flagged events. In particular, for a two-hour route collection with 10-90,000 route changes, our algorithm typically flags 1-11 suspected events (0.01-0.05% FP). Our algorithm also detected most of the previously published hijack events. Tal Shapira, Yuval Shavitt |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | BGP2Vec: Unveiling the Latent Characteristics of Autonomous SystemsabstractBGP announcements hold latent information about the Internet Autonomous Systems (ASes) and their functional position within the Internet eco-system. This information can aid us in understanding the Internet structure and also in solving many practical problems. In this paper, we present BGP2Vec, a novel approach to revealing the latent characteristics of ASes using neural-network-based embedding. We show that our embedding indeed captures important characteristics of ASes, and then show how the embedding can be used to solve two problems: ASN business-type classification and AS Type of Relationships (ToRs) inference. ToRs inference has been heavily studied in the past two decades and is important for studying Internet routing and identifying IP hijack attacks. We use the BGP2Vec vectors as an input to artificial neural networks and achieve excellent results: an accuracy of 95.8% for ToR classification and an accuracy of 79.2% for AS classification. Tal Shapira, Yuval Shavitt |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | SASA: Source-Aware Self-Attention for IP Hijack DetectionabstractIP hijack attacks deflect traffic between endpoints through the attacker network, leading to man-in-the-middle attacks. Current detection solutions are only based on AS-level path analysis, while attacks that include data-plane manipulations may exhibit only geographic anomalies and preserve the AS-level route, or hide the problematic AS in the path. Thus, there is a need to develop data-plane analysis frameworks that examine the actual route packets traverse. We introduce here a deep learning system that examines the geography of traceroute measurements to detect malicious routes. We use multiple geolocation services, with various levels of confidence; each also suffers from location errors. Moreover, identifying a hijacked route is not sufficient since an operator presented with a hijack alert needs an indication of the cause for flagging out the problematic route. Thus, we introduce a novel deep learning layer, called Source-Aware Self-Attention (SASA), which is an extension of the attention mechanism.SASAlearns each data source’s confidence and combines this score with the attention of each router in the route to point out the most problematic one. We validate our IP hijacking classification method using two router data types: coordinates and country location, and show thatSASAoutperforms the regular self-attention layer, using the same neural network architecture, and achieves extremely high accuracy. Tal Shapira, Yuval Shavitt |
IEEE/ACM Trans. Netw. | 1 |
| 2021 | FlowPic: A Generic Representation for Encrypted Traffic Classification and Applications IdentificationabstractIdentifying the type of a network flow or a specific application has many advantages, such as, traffic engineering, or to detect and prevent application or application types that violate the organization’s security policy. The use of encryption, such as VPN, makes such identification challenging. Current solutions rely mostly on handcrafted features and then apply supervised learning techniques for the classification. We introduce a novel approach for encrypted Internet traffic classification and application identification by transforming basic flow data into an intuitive picture, aFlowPic, and then using known image classification deep learning techniques, CNNs, to identify the flow category (browsing, chat, video, etc.) and the application in use. We show that our approach can classify traffic with high accuracy, both for a specific application, or a flow category, even for VPN and Tor traffic. Our classifier can even identify with high success new applications that were not part of the training phase for a category, thus, new versions or applications can be categorized without additional training. Tal Shapira, Yuval Shavitt |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | Unveiling the Type of Relationship Between Autonomous Systems Using Deep LearningabstractThe ToR inference problem had been widely investigated in the last two decades, mostly using heuristic algorithms. In this problem, we attempt to reveal the economic relationships between ASes, data with applications in network routing management and routing security.In this paper, we introduce a novel approach for ToR classification, which is based on embedding the AS numbers (ASN) in high dimensional space using neural networks. Similar to natural language processing (NLP) models, the embedding represents latent characteristics of the ASN and its interactions on the Internet. The embedding coordinates of each AS are represented by a vector; thus, we call our method BGP2VEC. In order to solve the supervised learning problem presented, we use these vectors as an input to an artificial neural network and achieve a state of the art accuracy of 95.2% for ToR classification. Tal Shapira, Yuval Shavitt |
NOMS | 1 |
| 2018 | Investigation of the Coin Snapping Phenomenon in Linearly Compliant Robot GraspsabstractCompliant grasping systems offer a wide range of robot hand designs. Understanding the stability behavior of compliant grasps can enhance the reliability and security of such hands. A classical result in compliant grasp mechanics states that a stable multifinger grasp can suddenly lose its stability when the finger force magnitudes exceed a critical threshold determined by the grasp's geometry. This event is known as coin snapping. This paper provides a full analysis of the coin snapping phenomenon for planar grasps governed by linear compliance laws. The analysis leads to important insights concerning compliant grasp security. For instance, does a grasping system give warning signs before an object snaps out of the fingers' grip? Is this an inevitable phenomenon in linearly compliant grasps? By systematically studying the bifurcation patterns of compliant multifinger grasps, this paper provides analytic characterization of the stability behavior of these systems, as well as answers to the mentioned questions under certain simplifying assumptions. Graphical examples and experimental measurements illustrate and validate the results. Tal Shapira, Elon D. Rimon, Amir Shapiro |
IEEE Trans. Robotics | 1 |