Ahmed Lekssays

dblp:271/1394 · DBLP profile ↗
← Back
10ranked-venue papers
6as first author
9since 2021 · last 2025
0000-0001-5783-8638ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 6 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2025 StructTransform: A Scalable Attack Surface for Safety-Aligned Large Language Models
Shehel Yoosuf, Temoor Ali, Ahmed Lekssays, Mashael Al Sabah, Issa M. Khalil
ESORICS (1)3
2025 From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction
abstract
Sharing methods of attack and their effectiveness is a cornerstone of building robust defensive systems. Threat analysis reports, produced by various individuals and organizations, play a critical role in supporting security operations and combating emerging threats. To enhance the timeliness and automation of threat intelligence sharing, several standards have been established, with the Structured Threat Information Expression (STIX) framework emerging as one of the most widely adopted. However, generating STIX-compatible data from unstructured security text remains a largely manual, expertdriven process. To address this challenge, we introduce AZERG, a tool designed to assist security analysts in automatically generating structured STIX representations. To achieve this, we adapt general-purpose large language models for the specific task of extracting STIX-formatted threat data. To manage the complexity, the task is divided into four subtasks: entity detection (T1), entity type identification (T2), related pair detection (T3), and relationship type identification (T4). We apply task-specific fine-tuning to accurately extract relevant entities and infer their relationships in accordance with the STIX specification. To address the lack of training data, we compiled a comprehensive dataset with 4,011 entities and 2,075 relationships extracted from 141 full threat analysis reports, all annotated in alignment with the STIX standard. Our models achieved F1-scores of 84.43% for T1, 88.49% for T2, 95.47% for T3, and 84.60% for T4 in real-world scenarios. We validated their performance against a range of open- and closed-parameter models, as well as state-of-the-art methods, demonstrating improvements of 2–25% across tasks.
Ahmed Lekssays, Husrev T. Sencar, Ting Yu 0001
RAID1
2025 LLMxCPG: Context-Aware Vulnerability Detection Through Code Property Graph-Guided Large Language Models
Ahmed Lekssays, Hamza Mouhcine, Khang Tran, Ting Yu 0001, Issa M. Khalil
USENIX Security Symposium1
2024 Semantic Ranking for Automated Adversarial Technique Annotation in Security Text
abstract
We introduce a novel approach for mapping attack behaviors described in threat analysis reports to entries in an adversarial techniques knowledge base. Our method leverages a multi-stage ranking architecture to efficiently rank the most related techniques based on their semantic relevance to the input text. Each ranker in our pipeline uses a distinct design for text representation. To enhance relevance modeling, we leverage pretrained language models, which we fine-tune for the technique annotation task. While generic large language models are not yet capable of fully addressing this challenge, we obtain very promising results. We achieve a recall rate improvement of +35% compared to the previous state-of-the-art results. We further create new public benchmark datasets for training and validating methods in this domain, which we release to the research community aiming to promote future research in this important direction.
Udesh Kumarasinghe, Ahmed Lekssays, Husrev T. Sencar, Sabri Boughorbel, Charith Elvitigala, Preslav Nakov
AsiaCCS2
2023 Early-Stage Ransomware Detection Based on Pre-attack Internal API Calls
Filippo Coglio, Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001
AINA (2)2
2023 MalCon: A blockchain-based malware containment framework for Internet of Things
abstract
IoT devices have become a primary medium for malware (e.g., botnets) to launch Distributed Denial of Service (DDoS) attacks. Such malware exploit low-security measures in IoT devices to spread in networks and recruit new victims. Thus, there is a need for malware countermeasures that consider both the security and operability of the network. Indeed, some IoT devices might run critical processes that do not tolerate interruptions. This paper proposes MalCon, a blockchain-based malware containment framework for IoT. It aims to stop malware from spreading in a network by a set of containment strategies encoded into smart contracts to be executed by the infected devices. Moreover, MalCon provides a monitoring service that ensures trustworthy behavior in the network and reports to the system administrator any fraudulent activity of the monitored devices. MalCon was tested extensively with real-life malware and use cases. It quickly and drastically reduces the number of infected devices in a network, even in an extreme case of a fully connected network.
Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001
Comput. Networks1
2022 MalRec: A Blockchain-based Malware Recovery Framework for Internet of Things
abstract
IoT devices have been considered an attractive target for malware (e.g., botnets) due to their low computational resources and lack of security measures. The literature focuses on detecting malware, but less attention is given to recovery solutions. In addition, with the development of data processing regulations in different countries, a need for transparent recovery systems that can help organizations present their due diligence arises. This work proposes a blockchain-based backup policy enforcement framework for IoT where an organization can formalize backup policies and enforce them. We have run our solution under extensive tests that show that it can be deployed in real-life IoT environments, despite the limited computational resources of IoT devices.
Ahmed Lekssays, Giorgia Sirigu, Barbara Carminati, Elena Ferrari 0001
ARES1
2021 LiMNet: Early-Stage Detection of IoT Botnets with Lightweight Memory Networks
Lodovico Giaretta, Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001, Sarunas Girdzijauskas
ESORICS (1)2
2021 PAutoBotCatcher: A blockchain-based privacy-preserving botnet detector for Internet of Things
Ahmed Lekssays, Luca Landa, Barbara Carminati, Elena Ferrari 0001
Comput. Networks1
2020 A Novel Approach for Android Malware Detection and Classification using Convolutional Neural Networks
Ahmed Lekssays, Bouchaib Falah, Sameer Abufardeh
ICSOFT1