VLDB 2026 Research / reviewers in the wild / expert
Sara Imene Boucetta
dblp:259/8888
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Semantic and Graph-Based Unsupervised Learning for Insider Threat Detection Using User Activity SequencesabstractInsider threats, where legitimate users misuse their access for malicious purposes, remain challenging to detect due to their contextual and behavioral subtleties. This paper presents a novel machine learning framework that captures user activity sequences through a user-centric representation named the User Daily Activity Sentence (UDAS). Unlike prior work that informally uses daily sequences, we formalize UDAS as a behavioral encoding technique using Word2Vec embeddings and extensively evaluate it across multiple unsupervised anomaly detection methods.To enrich this representation with relational context, we propose a graph-based extension that constructs a user interaction graph based on co-device usage and domain access. A Graph Convolutional Network (GCN) is applied to enhance semantic user embeddings, and anomaly detection is performed using Kmeans clustering.To the best of our knowledge, this is the first work to systematically combine semantic sequence embeddings with graph-based relational learning for insider threat detection. Experiments on the CERT Insider Threat v4.2 dataset show that our method outperforms prior unsupervised models in accuracy and robustness. The proposed framework requires no feature engineering or labeled data, making it applicable to real-world monitoring environments. Neda Baghalizadeh-Moghadam, Christopher Neal, Sara Imene Boucetta, Frédéric Cuppens, Nora Cuppens |
PST | 3 |
| 2025 | A Privilege Creep-Aware Role Mining Method for Enhanced Access Control SecurityabstractRole Mining (RM) extracts Role-Based Access Control (RBAC) structures from user-permission assignments to reduce administrative overhead. However, existing approaches usually make the assumption of clean datasets, while real-world systems suffer from anomalies like privilege creep, the gradual accumulation of unnecessary permissions.The proposed approach aims to detect potential privilege crept users who should be reviewed first, and identify legitimate permissions assignments to be expressed in RBAC, reducing management complexity. It consists of a two-step procedure: clean the User-Permission Assignment matrix (UPA) using a clustering and statistical analysis, then build an RBAC state using a regular role mining algorithm.The proposed approach yields an average of 90% in privilege creep detection accuracy and over 95% privilege creep correction, evaluated on synthetically made datasets. Evaluation on real-world datasets demonstrates an average 4-fold reduction in required roles while maintaining at least 80% UPA coverage. Vincent Bittard, Rim Ben Salem, Ahmed Bouzid, Sara Imene Boucetta, Frédéric Cuppens, Nora Cuppens |
TrustCom | 4 |