VLDB 2026 Research / reviewers in the wild / expert
Aymen Boudguiga
dblp:24/8061
· DBLP profile ↗
26ranked-venue papers
5as first author
13since 2021 · last 2025
0000-0001-6717-8848ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 2 first-author · 10 since 2021Computer networks · 5 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unveiling the (in)Security of Threshold FHE-Based Federated Learning: The Practical Impact of Recent CPAD AttacksabstractThe security of Fully Homomorphic Encryption (FHE) has received a lot of attention in recent years with new security notions emerging to better understand the practical attacks that may threaten the real-world deployments of passively secure FHE schemes. One such new notions is CPAD a slight extension of CPA security modelling a passive adversary who is granted access to a decryption oracle accepting only well-formed ciphertexts. While successful CPAD attacks have initially been performed on approximate FHE schemes such as CKKS, recent works have also demonstrated practical CPAD attacks on all mainstream non-approximate FHE, such as BFV, BGV or TFHE. Despite their clear computational practicality, these latter attacks however focus on the abstract security game defining CPAD security. In this paper, we show how to concretely build on these to mount successful FHE key recovery attacks in the Federated Learning (FL) setting, an application scenario of choice for FHE techniques. In FL, participating entities or workers encrypt successive model updates based on their local training data, enabling a central server to aggregate them in order to homomorphically update a global model. As this paper demonstrates, this environment provides a playground for an attacker to launch key recovery attacks against the FHE underlying the secure aggregation mechanism. As such, our findings reveal substantial stealthy key-recovery threats from both the server and a single worker, with very limited impact on the FL training progression or final model quality. Adda-Akram Bendoukha, Renaud Sirdey, Aymen Boudguiga, Nesrine Kaaniche |
CSF | 3 |
| 2025 | FairCognizer: A Model for Accurate Predictions with Inherent Fairness Evaluation (Extended Abstract)abstractAlgorithmic fairness is a critical challenge in building trustworthy Machine Learning (ML) models. ML classifiers strive to make predictions that closely match real-world observations (ground truth). However, if the ground truth data itself reflects biases against certain sub-populations, a dilemma arises: prioritize fairness and potentially reduce accuracy, or emphasize accuracy at the expense of fairness. This work proposes a novel training framework that goes beyond achieving high accuracy. Our framework trains a classifier to not only deliver optimal predictions but also to identify potential fairness risks associated with each prediction. To do so, we specify a dual-labeling strategy where the second label contains a per-prediction fairness evaluation, referred to as an unfairness risk evaluation. In addition, we identify a subset of samples as highly vulnerable to group-unfair classifiers. Our experiments demonstrate that our classifiers attain optimal accuracy levels on both the Adult-Census-Income and Compas-Recidivism datasets. Moreover, they identify unfair predictions with nearly 75% accuracy at the cost of expanding the size of the classifier by 45%. Adda-Akram Bendoukha, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey |
IJCAI | 3 |
| 2025 | Towards Privacy-preserving and Fairness-aware Federated Learning FrameworkabstractFederated Learning (FL) enables the distributed training of a model across multiple data owners under the orchestration of a central server responsible for aggregating the models generated by the different clients. However, the original approach of FL has significant shortcomings related to privacy and fairness requirements. Specifically, the observation of the model updates may lead to privacy issues, such as membership inference attacks, while the use of imbalanced local datasets can introduce or amplify classification biases, especially for minority groups. In this work, we show that these biases can be exploited to increase the likelihood of privacy attacks against these groups. To do so, we propose a novel inference attack exploiting the knowledge of group fairness metrics during the training of the global model. Then to thwart this attack, we define a fairness-aware encrypted-domain aggregation algorithm that is differentially-private by design thanks to the approximate precision loss of the threshold multi-key CKKS homomorphic encryption scheme. Finally, we demonstrate the good performance of our proposal both in terms of fairness and privacy through experiments conducted over three real datasets. Adda-Akram Bendoukha, Didem Demirag, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey, Sébastien Gambs |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | On the Practical CPAD Security of "exact" and Threshold FHE Schemes and Libraries
Marina Checri, Renaud Sirdey, Aymen Boudguiga, Jean-Paul Bultel |
CRYPTO (3) | 3 |
| 2024 | FairCognizer: A Model for Accurate Predictions with Inherent Fairness EvaluationabstractAlgorithmic fairness is a critical challenge in building trustworthy Machine Learning (ML) models. ML classifiers strive to make predictions that closely match real-world observations (ground truth). However, if the ground truth data itself reflects biases against certain sub-populations, a dilemma arises: prioritize fairness and potentially reduce accuracy, or emphasize accuracy at the expense of fairness. This work proposes a novel training framework that goes beyond achieving high accuracy. Our framework trains a classifier to not only deliver optimal predictions but also to identify potential fairness risks associated with each prediction. To do so, we specify a dual-labeling strategy where the second label contains a per-prediction fairness evaluation, referred to as an unfairness risk evaluation. In addition, we identify a subset of samples as highly vulnerable to group-unfair classifiers. Our experiments demonstrate that our classifiers attain optimal accuracy levels on both the Adult-Census-Income and Compas-Recidivism datasets. Moreover, they identify unfair predictions with nearly 75% accuracy at the cost of expanding the size of the classifier by a mere 45%. Adda-Akram Bendoukha, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey |
ECAI | 3 |
| 2024 | A Decentralized Federated Learning Using Reputation
Olive Chakraborty, Aymen Boudguiga |
ICISSP | 2 |
| 2024 | chiku: Efficient Probabilistic Polynomial Approximations Library
Devharsh Trivedi, Nesrine Kaaniche, Aymen Boudguiga, Nikos Triandopoulos |
SECRYPT | 3 |
| 2023 | Optimized Stream-Cipher-Based Transciphering by Means of Functional-Bootstrapping
Adda-Akram Bendoukha, Pierre-Emmanuel Clet, Aymen Boudguiga, Renaud Sirdey |
DBSec | 3 |
| 2023 | Lightweight FHE-based Protocols Achieving Results Consistency for Data Encrypted Under Different KeysabstractInternational audience Marina Checri, Jean-Paul Bultel, Renaud Sirdey, Aymen Boudguiga |
SECRYPT | 4 |
| 2022 | Cooperative and smart attacks detection systems in 6G-enabled Internet of ThingsabstractThe Sixth Generation (6G) of mobile networks offers the promise of a global interconnected system, serving a large set of applications across multiple fields such as satellite, air, ground, and underwater networks. It will evolve towards a unified network compute fabric that facilitates convergence across ecosystems, fostering design and innovation of new Internet of Things (IoT) applications and services, further leading to an exponential growth of IoT use cases in the post-6G era. This profound evolution will also impact the threat landscape, adding new threat actors, and leading to a new set of cyber security challenges. This paper reviews 6G applications and analyzes their security challenges and existing solutions, covering both the network, application and data layers. It introduces a new concept to security monitoring and attack detection in 6G-enabled IoT systems, leveraging on hierarchical and collaborative approaches, while also satisfying the main 6G’s Key Performance Indicators (KPIs) such as trustworthiness, latency, connectivity, data rate and energy consumption. The proposed solution implements a multi-level Federated Learning (FL) approach between IoT devices and edge computing applications. As compared to current centralized security monitoring and detection solutions, it conciliates better between the attack detection accuracy and the network overhead for implementing this model. We demonstrate the use of the proposed solution through an example scenario involving an Internet of Vehicles that communicate over a 6G network. Hichem Sedjelmaci, Nizar Kheir, Aymen Boudguiga, Nesrine Kaaniche |
ICC | 3 |
| 2022 | Efficient Hybrid Model for Intrusion Detection SystemsabstractInternational audience Nesrine Kaaniche, Aymen Boudguiga, Gustavo Gonzalez Granadillo |
SECRYPT | 2 |
| 2022 | A Secure Federated Learning: Analysis of Different Cryptographic ToolsabstractInternational audience Oana Stan, Vincent Thouvenot, Aymen Boudguiga, Katarzyna Kapusta, Martin Zuber, Renaud Sirdey |
SECRYPT | 3 |
| 2021 | Privacy Preserving Services for Intelligent Transportation Systems with Homomorphic EncryptionabstractInternational audience Aymen Boudguiga, Oana Stan, Abdessamad Fazzat, Houda Labiod, Pierre-Emmanuel Clet |
ICISSP | 1 |
| 2020 | Secure Data Processing for Industrial Remote Diagnosis and Maintenance
Walid Arabi, Reda Yaich, Aymen Boudguiga, Mawloud Omar |
CRiSIS | 3 |
| 2020 | Homomorphic Encryption at Work for Private Analysis of Security LogsabstractInternational audience Aymen Boudguiga, Oana Stan, Hichem Sedjelmaci, Sergiu Carpov |
ICISSP | 1 |
| 2019 | Privacy-Preserving k-means Clustering: an Application to Driving Style Recognition
Othmane El Omri, Aymen Boudguiga, Malika Izabachène, Witold Klaudel |
NSS | 2 |
| 2019 | An efficient cyber defense framework for UAV-Edge computing network
Hichem Sedjelmaci, Aymen Boudguiga, Inès Ben Jemaa, Sidi-Mohammed Senouci |
Ad Hoc Networks | 2 |
| 2018 | A generic cyber defense scheme based on stackelberg game for vehicular networkabstractThe main purpose of the vehicular networks is ensuring road safety while providing passengers comfort. Thus, information security is one of the most important issues, which attracts researchers attention. Thereby, in this paper we propose a generic cyber defense scheme based on Stackelberg game to secure the vehicular network against cyber-attackers. In this game, we define two different players, the leader agent and follower agents which collaborate between each other to secure the vehicle node. The follower agents are Intrusion Detection System (IDS), Intrusion Prevention System (IPS) and Intrusion Reaction System (IRS) which aim to detect, predict and react respectively against the suspected node. The leader agent is the Intrusion Decision Agent (IDA), which has the capability to launch the IDS, IPS and IRS by taking into account the overhead and processing delay. Simulation resultants show that, our security scheme exhibits a low false positive and false negative rates, while generating a low overhead and delay as compared to the current detection and predication frameworks. Hichem Sedjelmaci, Imane Horiya Brahmi, Aymen Boudguiga, Witold Klaudel |
CCNC | 3 |
| 2018 | Cooperative Security Framework for CBTC NetworkabstractRailway networks could be subject to cyberattacks due to security breaches of their communication systems. The Communications-Based Train Control (CBTC) is considered as the main organ of a railway network. CBTC controls movements of trains and manages messages exchanged between the different systems of railways. In this paper, we propose a cooperative detection framework to secure the CBTC against attackers that execute locally a malicious software (i.e., internal threats) and/or spread and deliver an attack from an external network (i.e., external threats). The present detection framework has two main security systems: host and network detection system, and human-machine interaction system. When these security systems run in a cooperative way, the attack detection and false alarm rates are improved, while the expected attack damage rate is reduced. The framework is integrated in a real sub-systems of railway network and according to experiments results, we show that it is capable to detect accurately sophisticated cyber-attacks, such as fault data injection and flooding attacks. Hichem Sedjelmaci, Fateh Guenab, Aymen Boudguiga, Yohann Petiot |
ICC | 3 |
| 2016 | A simple intrusion detection method for controller area networkabstractThe Controller Area Network (CAN) is established as the main communication channel inside vehicles. CAN relies on frame broadcast to share data between different microcontrollers managing critical or comfort functions such as cruise control or air conditioning. CAN is distinguished by its simplicity, its real-time application compatibility and its low deployment cost. However, CAN major drawback is its lack of security support. That is, CAN fails to provide protections against attacks such as intrusion, denial of service or impersonation. We propose in this work a simple intrusion detection method for CAN. Our main idea is to make each microcontroller monitor the CAN bus to detect malicious frames. Aymen Boudguiga, Witold Klaudel, Antoine Boulanger, Pascale Chiron |
ICC | 1 |
| 2015 | Light Blind: Why Encrypt If You Can Share?abstractThe emergence of cloud computing makes the use of remote storage more and more common. Clouds provide cheap and virtually unlimited storage capacity. Moreover, thanks to replication, clouds offer high availability of stored data. The use of public clouds storage make data confidentiality more critical as the user has no control on the physical storage device nor on the communication channel. The common solution is to ensure data confidentiality by encryption. Encryption gives strong confidentiality guarantees but comes with a price. The time needed to encrypt and decrypt data increases with respect to the size of input data, making encryption expensive. Due to its overhead, encryption is not universally used and a non-negligible amount of data is insecurely stored in the cloud. In this paper, we propose a new mechanism, called Light Blind, that allows confidentiality of data stored in the cloud at a lower time overhead than classical cryptographic techniques. The key idea of our work is to partition unencrypted data across multiple clouds in such a way that none of them can reconstruct the original information. In this paper we describe this new approach and we propose a partition algorithm with constant time complexity tailored for modern multi/many-core architectures. Pierpaolo Cincilla, Aymen Boudguiga, Makhlouf Hadji, Arnaud Kaiser |
SECRYPT | 2 |
| 2013 | ID Based Cryptography for Cloud Data StorageabstractThis paper addresses the security issues of storing sensitive data in a cloud storage service and the need for users to trust the commercial cloud providers. It proposes a cryptographic scheme for cloud storage, based on an original usage of ID-Based Cryptography. Our solution has several advantages. First, it provides secrecy for encrypted data which are stored in public servers. Second, it offers controlled data access and sharing among users, so that unauthorized users or untrusted servers cannot access or search over data without client's authorization. Nesrine Kaaniche, Aymen Boudguiga, Maryline Laurent |
IEEE CLOUD | 2 |
| 2013 | Pseudonymous communications in secure industrial wireless sensor networksabstractWireless sensor networks are becoming widely deployed in the industry. They are used to provide contextual information about the industrial environment being surveyed, to control and monitor the industrial processes, and even for workers who can be augmented with sensors. In these wireless networks, an adversary can easily eavesdrop communications with the aim to collect private information about sensors, because of the open nature of the wireless medium. A usual solution to prevent privacy violation relies on the use of pseudonyms as sensor identities; however, pseudonyms may deter authentication and access control enforcement in the network. This paper introduces an efficient pseudonym-based scheme that provides privacy protection to sensors without compromising network access security. Nouha Oualha, Alexis Olivereau, Aymen Boudguiga |
PST | 3 |
| 2011 | Key-escrow resistant ID-based authentication scheme for IEEE 802.11s mesh networksabstractNowadays, ID-based cryptography is reported as an alternative to Public Key Infrastructures (PKI). It proposes to derive the public key from the node's identity directly. As such, there is no need for public key certifcates, and direct beneft of this is to remove the burdensome management of certifcates. However, the drawback is the need for a Private Key Generator (PKG) entity which can perform a key escrow attack. In this article, we present an ID-based authentication scheme that is adapted to the IEEE 802.11s mesh networks and resistant against key escrow attacks. Aymen Boudguiga, Maryline Laurent |
WCNC | 1 |
| 2010 | An ID-based authentication scheme for the IEEE 802.11s Mesh NetworkabstractNowadays authentication in Wireless Mesh Networks (WMN) refers to the 802.1X authentication methods or a Preshared key authentication, and makes use of certificates or shared secrets. In wireless environments, management of certificates is disadvantageous. Certificates require deploying a Public Key Infrastructure (PKI) and Certification Authorities (CA) and they require defining a certificate management policy to control the generation, transmission and revocation of certificates. Management of certificates is a cumbersome task and does not match the limited (power and memory) resources available at wireless nodes. Moreover it does not match the non permanent connectivity to CA. In this paper, we propose an ID-based method, as an alternative to the PKI, to provide nodes with private and public keys, and we present an authentication scheme that uses the ID-based cryptographic concepts. As illustrated in the paper, the authentication scheme is shown as suitable to the WMN networks. Aymen Boudguiga, Maryline Laurent |
WiMob | 1 |
| 2010 | Significantly improved performances of the cryptographically generated addresses thanks to ECC and GPGPU
Tony Cheneau, Aymen Boudguiga, Maryline Laurent |
Comput. Secur. | 2 |