VLDB 2026 Research / reviewers in the wild / expert
Zakaria Abou El Houda
dblp:236/2959
· DBLP profile ↗
31ranked-venue papers
18as first author
26since 2021 · last 2026
0000-0002-2893-1101ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 21 · 14 first-author · 16 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mitigating Gradient Inversion Attacks in Federated Learning over Tabular IoT Data
Imene Bessaa, Lyes Khoukhi, Zakaria Abou El Houda |
ICC | 3 |
| 2026 | SelfAdv-DA: Unsupervised Domain Adaptation Framework for Robust Intrusion Detection in IoT Networks
Ines Guerziz, Zakaria Abou El Houda, Long Bao Le |
ICC | 2 |
| 2026 | Game-Theoretic Security Orchestration for Cross-RIC Policy Conflicts in O-RAN
Ali Mehrban, Hajar Moudoud, Bouziane Brik, Lyes Khoukhi, Zakaria Abou El Houda |
ICC | 5 |
| 2026 | QSFL-ID: Quantum-Split Federated Learning for Intrusion Detection in IIoT Networks
Aymene Selamnia, Hajar Moudoud, Lyes Khoukhi, Bouziane Brik, Zakaria Abou El Houda |
ICC | 5 |
| 2025 | Domain Adversarial Neural Networks with Adversarial Robustness Evaluation for Intrusion Detection Systems
Ines Guerziz, Tiago H. Falk, Long Bao Le, Zakaria Abou El Houda |
CRiSIS | 4 |
| 2025 | Blockchain-Based Federated Learning for Enhanced Cyber-Threats Detection in Connected VehiclesabstractOver the past few years, there have been made significant strides in advancing the Internet of Vehicles (IoV), recognizing its strategic importance in Intelligent Transport Systems. The proliferation of connected and autonomous vehicles on the roads has propelled the IoV into the spotlight. However, addressing the specific demands of vehicular networks, such as low latency, high mobility, extensive connectivity of 5G/6G networks, and robust security, remains a substantial challenge. Therefore, there is a critical need for substantial progress in implementing a resilient Intrusion Detection System within the IoV ecosystem. This paper introduces VFed-IDS, a decentralized, secure, flexible, scalable, and robust Blockchain and Federated Learning-based intrusion detection system. VFed-IDS is designed to identify cyber threats in the IoV while preserving privacy in connected vehicles. The proposed architecture consists of three main layers: the central layer, the local layer, and the Blockchain layer. The central layer includes the SDN Controller, responsible for training and aggregating the global model. The local layer comprises vehicles training individual models based on their private local datasets. The Blockchain layer introduces the Smart Contract VFed-SC, which manages the list of authenticated and collaborating vehicles in the Federated Learning process. It also hashes trained local model updates before transmitting them as transactions between the central and local layers. Simulation results demonstrate that VFed-IDS achieves a high accuracy rate of 99%, effectively enhancing the autonomous behavior of connected vehicles against cyber threats. Houda Amari, Zakaria Abou El Houda, Hajar Moudoud, Lyes Khoukhi, Lamia Hadrich Belguith |
ICC | 2 |
| 2025 | An SDN-based Adaptive Ensemble Learning Framework for Intrusion Mitigation in Wireless NetworksabstractJamming attacks are among the most critical security threats to Wireless Sensor Networks (WSNs), as they can severely disrupt normal network operations, leading to data loss, network downtime, and reduced system performance. Intrusion Detection Systems (IDSs) have therefore become essential to protect WSNs. However, conventional IDSs often struggle to detect zero-day attacks, creating a significant security gap. To address this, Artificial Intelligence (AI)-based IDSs have been introduced, offering improved detection capabilities but frequently encountering high bias or variance issues, which reduce their reliability. Recently, ensemble learning (EL) has emerged as a promising approach to build more adaptable and data-resilient models by combining multiple learning algorithms. In this context, we propose AdaptiveBoost, an SDN-based Adaptive Ensemble Learning Framework, specifically designed for effective jamming attack detection in WSNs. The SDN integration allows AdaptiveBoost to optimize network traffic flow, identify anomalies in real-time, and adaptively fine-tune detection mechanisms based on current network conditions. We conduct several experiments to evaluate AdaptiveBoost using real-world WSN attacks; using the well-known public network security dataset, WSN-DS, show that AdaptiveBoost outperforms AI-based algorithms in terms of accuracy, precision, recall, and F1 score, while achieving a remarkable reduction in training time by a factor of 235, making it an efficient, scalable solution for securing WSNs against jamming attacks. Hajar Moudoud, Zakaria Abou El Houda, Lyes Khoukhi, Hussein T. Mouftah |
ICC | 2 |
| 2025 | Vehicular Edge Computing: An Enhanced Vehicle Participant Selection System for Federated LearningabstractFederated learning is a pivotal technique in vehicular edge computing (VEC), which allows distributed machine learning across vehicles while preserving data privacy. However, it is critical to select the vehicles to participate in the learning process effectively. In this context, the problem related to finding optimized vehicles to participate in the learning task is discussed. An optimized vehicle selection mechanism is needed in vehicular networks, as traffic flow occurs in a real environment, influenced by different conditions such as security, vehicle capacities, data freshness, weather conditions, etc. The primary key contributions of this research are as follows: (i) formulation of vehicle selection in vehicular edge computing as an optimization problem, and (ii) the development of a new approach using the Tabu search algorithm named TS-EVS, specifically designed for the problem, as it is shown to be NP-hard. We evaluated TS-EVS using a Python implementation, considering the outcome of the proposal in two scenarios taking into account the MEC applications and the number of deployed vehicles. Compared to the untrusted version of the proposal, the numerical results demonstrate how the suggested approach significantly improves accuracy and reduces learning time. Sofiane Dahmane, Abdelmadjid Benarfa, Bouziane Brik, Zakaria Abou El Houda |
IWCMC | 4 |
| 2025 | A Blockchain-Enabled Multi-Layered Zero-Trust Security Framework for O-RANabstractO-RAN (Open Radio Access Network) is a set of open and interoperable radio access technologies, guided by the O-RAN Alliance, that, despite an open ecosystem, introduces significant security risks, expanding the threat surface in 6G networks. Traditional perimeter-based security approaches are inadequate for O-RAN’s highly distributed, multi-vendor environments, where Zero Trust Architecture (ZTA) becomes essential for robust security. To address these challenges, we propose a novel blockchain-based, decentralized Zero-Trust Framework specifically designed for O-RAN security. Our proposed framework comprises two key layers: the first layer utilizes Federated Learning (FL) and Transfer Learning (TL) for advanced attack detection, enabling distributed, privacy-preserving threat analysis across O-RAN nodes. The second layer enforces Zero Trust access control through a blockchain-based identity management system, ensuring tamper-resistant, real-time policy updates. This multi-layered framework provides adaptive threat detection and resilient access control, validated through simulations demonstrating high detection accuracy and robust access management with minimal impact on network performance, offering a scalable security solution for next-generation O-RAN deployments. Ali Mehrban, Zakaria Abou El Houda, Hajar Moudoud, Bouziane Brik, Lyes Khoukhi |
IWCMC | 2 |
| 2025 | Securing O-RAN Equipment Using Blockchain-Based Supply Chain VerificationabstractThe Open Radio Access Network (O-RAN) architecture has enabled the integration of multi-vendor equipment, yielding a significant enhancement in the flexibility and interoperability of telecommunications networks. However, this openness has also introduced new security vulnerabilities, particularly in supply chain integrity. Malicious actors may exploit weaknesses at various stages of production, distribution, or integration, leading to critical threats such as data tampering, unauthorized access, and denial-of-service (DOS) attacks. To address these challenges, this paper proposes a novel blockchain-based framework designed to secure the O-RAN supply chain. The proposed solution leverages a private permissioned blockchain ledger and cryptographic firmware authentication to ensure the integrity and authenticity of network equipment throughout its lifecycle. Specifically, the framework consists of: (1) a decentralized architecture integrating blockchain network components, equipment node validators, and secure firmware authentication mechanisms; and (2) a consensus-based verification model to enhance trust and transparency within the supply chain. To the best of our knowledge, this is one of the first approaches to use blockchain for O-RAN supply chain security, and also addressing emerging security threats in a scalable and tamper-resistant manner. Experimental validation and security assessments demonstrate the effectiveness of the proposed framework in mitigating supply chain risks, making it a promising solution for ensuring trust and robustness in next-generation O-RAN ecosystems. Ali Mehrban, Zakaria Abou El Houda, Hajar Moudoud, Bouziane Brik, Lyes Khoukhi |
IWCMC | 2 |
| 2025 | Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial AttacksabstractAdversarial examples can represent a serious threat to machine learning (ML) algorithms. If used to manipulate the behaviour of ML-based Network Intrusion Detection Systems (NIDS), they can jeopardize network security. In this work, we aim to mitigate such risks by increasing the robustness of NIDS towards adversarial attacks. To that end, we explore two adversarial methods for generating malicious network traffic. The first method is based on Generative Adversarial Networks (GAN) and the second one is the Fast Gradient Sign Method (FGSM). The adversarial examples generated by these methods are then used to evaluate a novel multilayer defense mechanism, specifically designed to mitigate the vulnerability of ML-based NIDS. Our solution consists of one layer of stacking classifiers and a second layer based on an autoencoder. If the incoming network data are classified as benign by the first layer, the second layer is activated to ensure that the decision made by the stacking classifier is correct. We also incorporated adversarial training to further improve the robustness of our solution. Experiments on two datasets, namely UNSW-NB15 and NSL-KDD, demonstrate that the proposed approach increases resilience to adversarial attacks. Nasim Soltani, Shayan Nejadshamsi, Zakaria Abou El Houda, Raphaël Khoury, Kelton A. P. Costa, Tiago H. Falk, Anderson R. Avila |
SMC | 3 |
| 2025 | Enhanced Adversarial Domain Adaptation for Intrusion Detection SystemsabstractThe increasing sophistication of cyber threats demands robust and adaptive Intrusion Detection Systems (IDS) capable of generalizing across diverse network environments. However, traditional AI-driven IDS models suffer from performance degradation when deployed in unseen domains due to domain shift discrepancies in data distributions caused by varying network configurations, attack patterns, or data collection methods. While unsupervised domain adaptation has recently been applied to address domain shift, its use in IDS remains limited and often lacks adaptation to the unique challenges of network data. To bridge this gap, we propose an Enhanced Adversarial Domain Adaptation (E-ADDA) Framework for IDS, designed to align feature representations between source and target domains, enhancing model generalizability. Our framework is rigorously evaluated on three publicly available IDS datasets, demonstrating significant improvements in key metrics such as accuracy, F1 score, and loss compared to existing domain adaptation methods. The results highlight the viability of adversarial domain adaptation in improving IDS resilience against zero-day attacks and evolving threats, offering a promising direction for real-world cybersecurity applications. Ines Guerziz, Zakaria Abou El Houda, Long Bao Le |
WiMob | 2 |
| 2025 | Advancing Privacy and Fairness in Healthcare Using Federated Edge Learning and BlockchainabstractArtificial intelligence (AI) has revolutionized many fields, including healthcare. The adoption of AI techniques in critical healthcare tasks, such as cancer diagnosis, holds great promise for revolutionizing the healthcare system. AI algorithms can be trained on vast datasets to recognize patterns, detect anomalies, and provide accurate assessments. However, the lack of realistic and up-to-date medical data poses a significant challenge to the widespread adoption of AI techniques. Additionally, privacy concerns surrounding sensitive medical data, particularly Patient Health Records (PHR), hinder data sharing among healthcare practitioners. This paper aims to address these challenges by proposing a novel framework, entitled SecureMed, that uses Federated Learning (FL) and Blockchain to preserve privacy in the healthcare system. In particular, SecureMed consists of (1) A novel distributed architecture that enables secure collaboration among multiple Mobile Edge Computing (MEC)-based Internet of Medical Things (IoMT) devices, while ensuring the privacy of healthcare systems; (2) A fairness-aware Federated Learning (FL) solution to ensure that model performance is balanced across all participating healthcare institutions, addressing the issue of imbalanced data contributions; (3) A Secure Multiparty Computation (SMPC) protocol to ensure secure aggregation of local model updates; and (4) A blockchain-based reputation model for collaborative FL training. The proposed framework leverages smart contracts to ensure trustworthiness, decentralization, and transparency in the FL process. The experimental results using the CIC IoMT dataset 2024 highlight the promising potential of SecureMed in revolutionizing healthcare systems. Hajar Moudoud, Zakaria Abou El Houda, Bouziane Brik |
IEEE Internet Things J. | 2 |
| 2024 | Securing IIoT applications in 6G and beyond using adaptive ensemble learning and zero-touch multi-resource provisioning
Zakaria Abou El Houda, Bouziane Brik, Adlen Ksentini |
Comput. Commun. | 1 |
| 2024 | A Privacy-Preserving Collaborative Jamming Attacks Detection Framework Using Federated LearningabstractJamming attacks are becoming increasingly common and pose a significant threat to the security and reliability of wireless sensor networks (WSNs). These attacks can be difficult to detect, as they often operate in a stealthy manner, disrupting communication between sensors. Artificial intelligence (AI) techniques have the potential to be highly effective in detecting jamming attacks. However, the adoption of AI-based techniques for detecting jamming attacks has been limited due to the scarcity of up-to-date and accurate data of these attacks. Privacy-aware collaboration among agents is expected to be essential in building robust AI-based models for detecting jamming attacks in WSNs. In this context, we propose a novel framework that uses collaborative federated learning (FL) to enable privacy-aware distributed learning among multiple agents without sharing their sensitive data. This can be particularly important in jamming attack detection, where data may contain sensitive information that should not be shared. In addition, we design a novel secure aggregation scheme to protect the FL aggregation service from reverse-engineering attacks. The effectiveness of our proposed framework was tested using the public Wireless Sensor Networks Dataset (WSN-DS) that includes four types of well-known jamming attacks (i.e., constant jamming, reactive jamming, random jamming, and deceptive jamming). The results of a thorough experiment using the WSN-DS data set demonstrate the effectiveness and high accuracy/F1-score (99%) in detecting jamming attacks while also maintaining participant privacy. Zakaria Abou El Houda, Diala Naboulsi, Georges Kaddoum |
IEEE Internet Things J. | 1 |
| 2024 | Blockchain-Enabled Federated Learning for Enhanced Collaborative Intrusion Detection in Vehicular Edge ComputingabstractIntelligent Transportation Systems (ITSs) are transforming the global monitoring of road safety. These systems, including vehicular networks and transportation infrastructure, are vulnerable to several security issues, which could disrupt services and potentially cause harm to the users. It is crucial to establish robust security measures to protect against evolving attacks and ensure the safe and reliable operation of ITS. Artificial Intelligence (AI)-based Intrusion Detection Systems (IDS) are mainly used to enhance the security of ITS. The adoption of AI-based techniques to secure ITS against new emerging threats has been limited due to a lack of realistic and recent data on these types of attacks ($i.e.,$zero-day attacks). In this context, we introduce a novel Edge-based Framework that uses Federated Learning (FL) and blockchain to secure ITS against new emerging threats. In particular, our proposed framework consists of (1) a novel distributed Edge-based architecture that allows multiple Edge nodes to securely collaborate while preserving their privacy; and (2) a decentralized and secure reputation system based on blockchain technology to maintain the reliability and trustworthiness of the FL process within the ITS; This system manages reputation data for individual nodes (such as vehicles), guaranteeing the integrity of the FL training process. Experiment results using the UNSW-NB15 dataset show that our proposed framework achieves high accuracy and F1 score (99%) in detecting new threats while ensuring the privacy and reliability of the whole ITS. These results demonstrate the effectiveness of our proposed framework in securing ITS. Zakaria Abou El Houda, Hajar Moudoud, Bouziane Brik, Lyes Khoukhi |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2023 | Secure and Efficient Federated Learning for Robust Intrusion Detection in IoT NetworksabstractThe rapid expansion of the Internet of Things (IoT) has increased the demand for robust intrusion detection systems. Federated learning (FL) has appeared as a potential solution to improve the security of IoT networks by facilitating collaboration between multiple devices in training a unified model while keeping their data secure. As the training process of FL occurs locally on individual devices, preserving data privacy becomes crucial. Additionally, combining model updates from multiple devices into a unified model can be challenging. Therefore, addressing these issues is critical to effective and private FL-based intrusion detection in IoT networks. In this paper, we propose a novel approach for ensuring privacy and efficiency in FL for robust intrusion detection in the IoT. Our approach combines secure aggregation and blockchain technology to protect the privacy of IoT data while enabling efficient and accurate model training. We first introduce a secure aggregation algorithm that can be used to combine the model updates from multiple devices in a privacy-preserving manner. This algorithm uses multi-party computation to prevent any single party from seeing the data of the other parties, thereby ensuring that the privacy of IoT data is maintained throughout the model training process. Then, we incorporate the use of blockchain technology to ensure data integrity and prevent tampering. Finally, we perform experiments on real-world IoT datasets to demonstrate the effectiveness of our approach. Our results show that our approach achieves high accuracy in intrusion detection while preserving the privacy of the IoT data. Zakaria Abou El Houda, Hajar Moudoud, Lyes Khoukhi |
GLOBECOM | 1 |
| 2023 | Towards a Secure and Scalable Access Control System Using BlockchainabstractAccess control, both physical and virtual, has always been a crucial aspect in maintaining the security of corporate information systems. Recently, several solutions have been proposed to address physical and virtual access control, including the use of electronic badges that can be costly to produce and easily misplaced. Additionally, numerous, sometimes expensive, cloud-based solutions have also been adopted. However, these solutions are often provided by third-party organizations, which require entities to place trust in these providers, a risk that is unacceptable for industries such as the military and banking. To solve this issue, we propose a novel Blockchain-based solution to establish a scalable and secure system for managing access controls. Blockchain offers a secure, decentralized, and most importantly, immutable alternative that eliminates the need for trust in third-party providers. We have implemented, tested, and deployed our Blockchain-based access control architecture on the Avalanche official network. The results demonstrate that this solution offers strong security, flexibility, efficiency, and cost-effectiveness, making it a promising approach to mitigate Distributed Denial of Service (DDoS) attacks in the Internet of Things (IoT). Our deployment on the Avalanche network confirms the feasibility and robustness of our approach in a real-world setting. Zakaria Abou El Houda, Jérémy Beaugeard, Quentin Sauvêtre, Lyes Khoukhi |
ICBC | 1 |
| 2023 | Advancing Security and Efficiency in Federated Learning Service Aggregation for Wireless NetworksabstractFederated Learning (FL) is a distributed machine learning technique where multiple devices can collaboratively train a model without sharing their data. As a result, FL ensures distinct privacy benefits compared to centralized training approaches. However, despite its benefits, FL remains susceptible to reverse-engineering attacks that can uncover sensitive information about the training data from the local updates sent by each participant. To address this issue, we propose a framework for securely and efficiently aggregating the results of FL on multiple devices. We compare and evaluate the performance of two techniques, Homomorphic Encryption (HE) and Secure Multiparty Computation (SMPC), to determine the best method that allows devices to share their learning results without revealing their raw local data. Ultimately, we propose using SMPC protocol as the most effective solution to secure FL. Our framework is experimentally evaluated, and its effectiveness in terms of security, efficiency, and accuracy is demonstrated. Zakaria Abou El Houda, Diala Naboulsi, Georges Kaddoum |
PIMRC | 1 |
| 2023 | Next-power: Next-generation framework for secure and sustainable energy trading in the metaverse
Zakaria Abou El Houda, Bouziane Brik |
Ad Hoc Networks | 1 |
| 2022 | A Hierarchical Fog Computing Framework for Network Attack Detection in SDNabstractIn recent years, there has been a huge demand to secure Internet of Things (IoT) applications against the new emerging threats and attacks; these attacks are becoming increasingly sophisticated and have caused tremendous damage to academic and business organizations. Intrusion detection systems (IDS) have an essential role in ensuring network security. As new types of security threats emerge, conventional IDSs that rely on pattern matching are constrained by their need for new attack patterns. To address this problem, machine learning and deep learning (ML/DL) techniques have been proposed in the literature to improve the detection capability of traditional IDS. In this paper, we study a new problem of using a lightweight adaptive boosting technique (the AdaBoost algorithm) for intrusion detection in software defined networks (SDNs). In particular, we propose a hierarchical Fog Computing Framework, called ML-FoG, that uses both advanced ML techniques with a new feature selection scheme to efficiently detect security threats in SDNs; ML-FoG consists of: (1) a Network data Flow Collection module (NFC) that gathers network features in a scalable way; (2) a Gradient Boosting Feature Selection Module (GBSM) that selects the most informative and relevant features; and (3) a novel lightweight adaptive boosting scheme that uses AdaBoost to detect network security threats in a timely and effective manner. Experimental results using UNSW-NB15 demonstrate that ML-FoG outperforms state-of-the-art contributions in accuracy and detection rate, while greatly decreasing the computational complexity. Zakaria Abou El Houda, Lyes Khoukhi |
ICC | 1 |
| 2022 | Ensemble Learning for Intrusion Detection in SDN-Based Zero Touch Smart Grid SystemsabstractSoftware-defined network (SDN) is widely deployed on Smart Grid (SG) systems. It consists in decoupling control and data planes, to automate the monitoring and management of the communication network, and thus enabling zero touch management of SG systems. However, SDN-based SG is prone to several security threats and varios type of new attacks. To alleviate these issues, various Machine/Deep learning (ML/DL)-based intrusion detection systems (IDS) were designed to improve the detection accuracy of conventional IDS. However, they suffer from high variance and/or bias, which may lead to an inaccurate security threat detection. In this context, ensemble learning is an emerging ML technique that aims at combining several ML models; the objective is to generate less data-sensitive (i.e., less variance) and more flexible (i.e., less bias) machine learning models. In this paper, we design a novel framework, called BoostIDS, that leverages ensemble learning to efficiently detect and mitigate security threats in SDN-based SG system. BoostIDS comprises two main modules: (1) A data monitoring and feature selection module that makes use of an efficient Boosting Feature Selection Algorithm to select the best/relevant SG-based features; and (2) An ensemble learning-based threats detection moel that implements a Lightweight Boosting Algorithm (LBA) to timely and effectively detects SG-based attacks in a SDN environment. We conduct extensive experiments to validate BoostIDS on top of multiple real attacks; the obtained results using NSL-KDD and UNSW-NB15 datasets, confirm that BoostIDS can effectively detect/mitigate security threats in SDN-based SG systems, while optimizing training/test time complexity. Zakaria Abou El Houda, Bouziane Brik, Lyes Khoukhi |
LCN | 1 |
| 2022 | A Low-Latency Fog-based Framework to secure IoT Applications using Collaborative Federated LearningabstractAttacks against the IoT network are increasing rapidly, leading to an exponential growth in the number of unsecured IoT devices. Existing security mechanisms are facing several issues due to the lack of real-time decisions, high energy consumption, and high time delays. In this context, we propose a novel Low-Latency Fog-based Framework, called FogFed, to secure IoT applications using Fog computing and Federated Learning (FL). The fog brings security mechanisms near IoT devices reducing delays in communication, while FL enables a privacy-aware collaborative learning between IoT while preserving their privacy. FogFed combines two levels of detection, Fog-based IoT attack detection using a binary FL classifier and cloud-based IoT attack detection using a Multiclass FL classifier. The in-depth experiments results with well-known IoT attack/malware using, the UNSW-NB15 datastet, show the significant accuracy (99%) and detection rate (99%), which outperforms centralized ML/DL models, while significantly reducing delays and preserving the privacy. Zakaria Abou El Houda, Lyes Khoukhi, Bouziane Brik |
LCN | 1 |
| 2022 | When Federated Learning Meets Game Theory: A Cooperative Framework to Secure IIoT Applications on Edge ComputingabstractIndustry 5.0 is rapidly growing as the next industrial evolution, aiming to improve production efficiency in the 21stcentury. This evolution relies mainly on advanced digital technologies, including Industrial Internet of Things (IIoT), by deploying multiple IIoT devices within industrial systems. Such a setup increases the possibility of threats, especially with the emergence of IIoT botnets. This can provide attackers with more sophisticated tools to conduct devastating IIoT attacks. Besides, machine learning (ML) and deep learning (DL) are considered as powerful techniques to efficiently detect IIoT attacks. However, the centralized way in building learning models and the lack of up-to-date datasets that contain the main attacks are still ongoing challenges. In this context, multiaccess edge computing (MEC) and federated learning (FL) are two promising complementary technologies. MEC brings computing capabilities at the edge of the industrial systems, while FL leverages the edge resources to enable a privacy-aware collaborative learning, especially in multiindustrial systems context. In this article, we design a novel MEC-based framework to secure IIoT applications leveraging FL, called FedGame. Specifically, FedGame enables multiple MEC domains to collaborate securely to deal with an IIoT attack, while preserving the privacy of IIoT devices. Moreover, a noncooperative game is formulated on the top of FedGame, to enable MEC nodes acquiring the needed virtual resources from the centralized MEC orchestrator, to deal with each type of IIoT attacks. We evaluate FedGame using real-world IIoT attacks; the experimental results show not only the accuracy of FedGame against centralized ML/DL schemes while preserving the privacy of Industrial systems but also its efficiency in providing required MECs resources and, thus, dealing with IIoT attacks. Zakaria Abou El Houda, Bouziane Brik, Adlen Ksentini, Lyes Khoukhi, Mohsen Guizani |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | A Novel Machine Learning Framework for Advanced Attack Detection using SDNabstractRecently, software defined networks (SDN) has emerged as novel technology that leverages network programmability to facilitate network management. SDN provides a global view of the network, through a logically centralized component, called SDN controller, to strengthen network security. SDN separates the control plane from the data plane, which allows for a more control over the network and brings new capabilities to cope with the new emerging security threats (i.e., zero-day attacks). Existing attack detection schemes are facing obstacles due to high false positive rates, low detection performances, and high computational costs. To address these issues, we propose a multi-module Machine Learning (ML) framework that combines unsupervised ML techniques with a scalable feature collection and selection scheme to effectively/timely detect network security threats in the context of SDN. In particular, our proposed framework consists of: (1) a data flow collection module (DFC) to gather the features of network data in a scalable and efficient way using sFlow protocol; (2) an Information gain Feature Selection (IGF) module to select the most informative/relevant features to reduce training and testing time complexity; and (3) a novel unsupervised ML module that uses a novel outlier detection scheme, called Isolation Forest (ML-IF), to effectively/timely detect network security threats in SDN. The experimental results using the well-known public network security dataset UNSW-NB15, show that our proposed framework outperforms state-of-the-art contributions in terms of accuracy and detection rate while significantly reducing computational complexity; making it a promising framework to mitigate the new emerging network security threats in SDN. Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi |
GLOBECOM | 1 |
| 2021 | Blockchain-based Reverse Auction for V2V charging in smart grid environmentabstractThe emergence of Internet of Energy (IoE) paves the way for sustainable and green energy environments that reduce energy costs and integrate Renewable Energy Sources (RESs) as new sources of energy. Electric vehicles (EVs) are one of the main actors of IoE future. The emergence of EVs promises to reduce the environmental crisis (e.g., carbon emissions); however, their charging process will consume massive amounts of electricity and may affect the reliability of the Smart Grid (SG). Recently, vehicle-to-vehicle (V2V) electricity trading approach has gained momentum as a novel strategy that reduces the peak power consumption in SG. In this context, EVs compete to provide electricity with lower prices, while maintaining the V2V electricity trading system secure. However, they lack flexibility, transparency, and authenticity. More importantly, they are based on centralized models (i.e., EV aggregators) which introduce single-point-of-failure and may cause the collapse of the system. In this paper, we propose a fully decentralized blockchain-based system that allows for an automated, fair, and trustworthy V2V electricity trading system; it uses Ethereum’s smart contracts to realize the V2V electricity trading system in a fully distributed, transparent, secure, tamper-proof and trustworthy manner. The proposed system is implemented, tested, and deployed on the Ethereum official test network Ropsten. The experiment results show that the proposed solution achieves security, flexibility, efficiency, and cost effectiveness making it a promising solution to new decentralized V2V electricity trading systems in SG. Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi |
ICC | 1 |
| 2020 | BrainChain - A Machine learning Approach for protecting Blockchain applications using SDNabstractNowadays, blockchain technology is seen as one of the main technological innovations to emerge since the advent of the internet. Many applications can benefit from blockchain to protect their exchanges. Nonetheless, applications with more restricted interests cannot use public blockchains. Permissioned blockchains promise to combine effectiveness of blockchains with stricter permissions to join blockchain's network. In permissioned blockchain, the number of participating entities is limited compared to public blockchain. However, by targeting the peers of the blockchain, the attackers can easily take control of consensus process and halt the blockchain operations. In this paper, we propose BrainChain, a scalable and efficient scheme to protect permissioned blockchain nodes from the largest ever Distributed Denial of Service (DDoS) attack (i.e., Domain Name System (DNS) amplification attack) in the context of software defined networks (SDN). BrainChain consists of 4 schemes: (1) Flow statistics collection scheme (FS) to gather the features of flows in an efficient way using sFlow; (2) Entropy based scheme (ES) to measure disorder of network features; (3) Bayes Network based Filtering scheme (BF) to classify, based on entropy values, illegitimate DNS requests; and (4) DNS Mitigation (DM) scheme to mitigate in an effective way the illegitimate flows (i.e., illegitimate DNS requests). Experimental results show that BrainChain can quickly and effectively detect and mitigate the attacks (i.e., DNS amplification attacks) with a high accuracy and a small false positive rate making it a promising scheme to protect blockchain applications from DNS Amplification attacks. Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi |
ICC | 1 |
| 2020 | Blockchain Meets AMI: Towards Secure Advanced Metering InfrastructuresabstractSmart grids (SGs) and advanced metering infrastructures (AMIs) are considered as the new evolution of classical electrical grids. The recent emergence of smart meters is paving the way for the proliferation of smart grids, where billions of smart meters are interconnected to provide novel pervasive services (e.g., real time pricing application and real time energy consumption), and automate diagnostic and daily energy metering (i.e., gas, electric) tasks (e.g., billing, monitoring, planning and predicting of energy usage). The recent explosion in the number of insecure smart meters is changing the view towards SG from enabler of smart homes into a powerful amplifying tool that creates new vectors for cyberattacks (i.e., smart-homes Distributed Denial-of-Service (DDoS) attacks) at large scale. This motivated us to design a new flexible, secure, efficient and trustworthy access control scheme based on blockchain and smart contract. Although access control exists in AMI, it is based on a centralized model (i.e., router/gateway, firewall) which introduces a bottleneck (i.e., single point of failure) and causes the collapse of the system. In this paper, we propose a new decentralized-based access control architecture for SG based on blockchain; it uses smart contracts (i.e., Ethereum's smart contracts) in order to manage permissions in a fully distributed and trustworthy manner. The architecture is implemented, tested and deployed on the Ethereum official test network Ropsten [1]. The results confirm that the proposed blockchain based access control scheme achieves security, flexibility, efficiency, and cost effectiveness making it a promising solution to mitigate DDoS attacks in SGs. Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi |
ICC | 1 |
| 2020 | Bringing Intelligence to Software Defined Networks: Mitigating DDoS AttacksabstractAs one of the most devastating types of Distributed Denial of Service (DDoS) attacks, Domain Name System (DNS) amplification attack represents a big threat and one of the main Internet security problems to nowadays networks. Many protocols that form the Internet infrastructure expose a set of vulnerabilities that can be exploited by attackers to carry out a set of attacks. DNS, one of the most critical elements of the Internet, is among these protocols. It is vulnerable to DDoS attacks mainly because all exchanges in this protocol use User Datagram Protocol (UDP). These attacks are difficult to defeat because attackers spoof the IP address of the victim and flood him with valid DNS responses coming from legitimate DNS servers. In this paper, we propose an efficient and scalable solution, called WisdomSDN, to effectively mitigate DNS amplification attack in the context of software defined networks (SDN). WisdomSDN covers both detection and mitigation of illegitimate DNS requests and responses. WisdomSDN consists of: (1) a novel proactive and stateful scheme (PAS) to perform one-to-one mapping between DNS requests and DNS responses; it operates proactively by sending only legitimate responses, excluding amplified illegitimate DNS responses; (2) a machine learning DDoS detection module to detect, in real-time, illegitimate DNS requests. This module consists of (a) Flow statistics collection scheme (FSC) to gather the features of flows in an efficient and scalable way using sFlow protocol; (b) Entropy calculation scheme (ECS) to measure randomness of network traffic; and (c) Bayes Network based Filtering scheme (BNF) to classify, based on entropy values, illegitimate DNS requests; and (3) DNS Mitigation scheme (DM) to effectively mitigate illegitimate DNS requests. The experimental results show that, compared to state-of-art, WisdomSDN can effectively detect/mitigate DNS amplification attack quickly with high detection rate, less false positive rate, and low overhead making it a promising solution to mitigate DNS amplification attack in a SDN environment. Zakaria Abou El Houda, Lyes Khoukhi, Abdelhakim Hafid |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2019 | Co-IoT: A Collaborative DDoS Mitigation Scheme in IoT Environment Based on Blockchain Using SDNabstractThe recent proliferation of Internet of Things (IoT) is paving the way for the emergence of smart cities, where billions of IoT devices are interconnected to provide novel pervasive services and automate our daily lives tasks (e.g., smart healthcare, smart home). However, as the number of insecure IoT devices continues to grow at a rapid rate, the impact of Distributed Denial-of-Service (DDoS) attacks is growing rapidly. With the advent of IoT botnets such as Mirai, the view towards IoT has changed from enabler of smart cities into a powerful amplifying tool for cyberattacks. This motivates the development of new techniques to provide flexibility and efficiency of decision making on the attack collaboration in a software defined networks (SDN) context. The new emerging technologies, such as SDN and blockchain, introduce new opportunities for low-cost, efficient and flexible DDoS attacks collaboration for the IoT based environment. In this paper, we propose Co-IoT, a blockchain-based framework for collaborative DDoS mitigation; it uses the concept of smart contracts (i.e., Ethereum's smart contracts) to facilitate the collaboration among SDN-based domains and transfer attacks information in a decentralized manner. The implementation of Co-IoT is deployed on Ethereum official test network Ropsten [1]. The experimental results confirm that Co-IoT achieves flexibility, efficiency, security and cost effectiveness making it a promising approach to mitigate large scale DDoS attacks. Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi |
GLOBECOM | 1 |
| 2018 | ChainSecure - A Scalable and Proactive Solution for Protecting Blockchain Applications Using SDNabstractNowadays, blockchain is seen as one of the main technological innovations. Many applications can rely on the blockchain to secure their exchanges. However, applications with private interest cannot rely on public blockchains. First, in a public blockchain, anyone can read the whole data of the blockchain. Second, anyone can participate to the "consensus process"; the process for determining the validity of each transaction. Consortium and fully private blockchains aim to combine forcefulness of blockchains with controlled consensus process and stricter permissions for deploying a node and joining the blockchain network. In both consortium and fully private blockchains, the number of peers on the blockchain network is very small in comparison with public blockchain. Nonetheless, by targeting the nodes of blockchains, an attacker can easily manage the whole blockchain and takes control of the consensus process to validate his illegitimate transactions. In this paper, to defend blockchain nodes from DNS amplification attacks, we propose a scalable and proactive solution in the context of software defined networks (SDN), named ChainSecure. ChainSecure consists of 3 schemes: (1) StateMap, a novel stateful mapping scheme (SMS) to perform a mapping one-to-one between DNS request and response; (2) Entropy calculation scheme (ECS) to measure the disorder / randomness of data using sFlow in order to detect illegitimate flows; (3) DNS DDoS Mitigation (DDM) module to effectively mitigate illegitimate DNS requests. The experimental results show that ChainSecure protects blockchain nodes and can detect/mitigate the attack quickly to achieve high accuracy in detecting illegitimate DNS traffic making it a promising solution to protect blockchain nodes from DNS amplification attacks. Zakaria Abou El Houda, Lyes Khoukhi, Abdelhakim Hafid |
GLOBECOM | 1 |