VLDB 2026 Research / reviewers in the wild / expert
Boussad Ait Salem
dblp:28/1403
· DBLP profile ↗
9ranked-venue papers
1as first author
6since 2021 · last 2026
0000-0002-3768-603XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhancing Data Privacy in Alzheimer's Research: Leveraging Gaussian Noise for Reliable Defense in Transformer ModelsabstractInternational audience Sameh Ben Hamida, Boussad Ait Salem, Faten Chaieb, Hichem Mrabet, Abderrazak Jemai |
ICAART (3) | 2 |
| 2026 | Unsupervised CoAP-based anomaly detection in private 5G core network for Industrial-IoTabstractIn the ever-evolving Industry 4.0 landscape, logs and events play a critical role in maintaining the reliability and security of complex systems. This is especially true for 5G networks, where lightweight protocols such as CoAP and LwM2M produce massive volumes of structured but often unlabeled log data. Although machine learning and deep learning methods have become common tools for anomaly detection in such environments, they are frequently hindered by practical limitations: scarce labeled data, high-dimensionality, long log sequences, and the lack of realistic attack scenarios in available datasets. To address the above challenges, we adopt a deep clustering framework that learns low-dimensional structured latent representations without requiring labels. TF-IDF statistical analysis excels at detecting repetitive attack patterns and anomalous term frequencies characteristic of threats like distributed denial-of-service attacks and message flooding, while enabling rapid compression and interpretation of large-scale log data. However, TF-IDF alone fails to capture semantic context—for instance, distinguishing between benign timeouts and attack-induced timeout cascades. Conversely, while pre-trained models like sentence-transformer capture rich semantics, their latent spaces are optimized for classification and are often unsuitable for clustering, due to their entangled and non-topological structure. In this paper, we propose a novel hybrid architecture that fuses a TF-IDF–based autoencoder with a sentence-transformer encoder through a cross-attention mechanism. This combination leverages TF-IDF’s statistical sensitivity to repetitive attack signatures while enriching it with semantic understanding, allowing the latent representation to selectively incorporate both statistical anomalies and contextual semantic signals, thereby preserving the interpretability and clusterability of the learned space. We implement this architecture through a Wazuh-based SIEM deployment at the 5G network edge, demonstrating that unsupervised hybrid clustering can deliver effective CoAP anomaly detection in industrial IoT environments without labeled data, intrusive agents, or cloud-dependent processing addressing critical gaps in operational security for private 5G networks. Kevin Yaker, Boussad Ait Salem, Dave Appadoo, Nadjib Aitsaadi, Vivien Raynal |
Comput. Commun. | 2 |
| 2024 | A Novel AI/ML SIEM as Application Function within Private 5G Core Network for Industrial-IoTabstractThe adoption of private 5G networks and the proliferation of Industrial Internet of Things (IIoT) devices utilizing low-power protocols (such as CoAP, LWM2M, MQTT) have unveiled challenging new security vulnerabilities. The latters are particularly significant at private industrial edge servers, which are directly connected to the 5G core network via the N6 interface. Traditional security solutions fall short in effectively monitoring and analyzing industrial protocols, rendering critical systems vulnerable to cyber threats. The consequences of successful attacks on IIoT devices in these environments can result in severe operational disruptions, financial losses, safety compromises, and environmental hazards. Existing measures are inadequate for protecting the N6 interface and edge environment. In this article, we introduce a 3GPP-compliant Application Function SIEM Alerting Agent. This specialized security solution is designed to detect and mitigate malicious IIoT traffic on private 5G networks at the edge, specifically targeting low-powered industrial protocols. Our proposal makes of advanced AI/ML anomaly detection and protocol analysis algorithms adhering to 3GPP R17 standards for seamless 5G integration. Through a private 5G experimental platform replicating an industrial setting, we collect traffic and system event and logs using only industrial protocols such as CoAP, LWM2M, and MQTT. Based on extensive experimentation with private 5G AMARISOFT platform, our proposal excels at detecting threats at the N6 interface. Kevin Yaker, Boussad Ait Salem, Dave Appadoo, Nadjib Aitsaadi, Vivien Raynal |
GLOBECOM | 2 |
| 2024 | AI/ML-Based IDS as 5G Core Network Function in the Control Plane for IP/non-IP CIoT TrafficabstractIn this paper, we design and implement an Intrusion Detection System (IDS) within the 5G core network, which is capable of inspecting both IP and non-IP data flows. By leveraging the Access and Mobility Management Function (AMF) Network Function (NF) communication service, our IDS can analyze all Cellular Internet of Things (CIoT) data traffic flowing across both the User and Control Planes (UP and CP), enabling the detection of malicious activities originating from or targeting IoT networks. Our proposal is aligned with the 3GPP Release 17 (R17) standard and makes use of predefined functionalities to ensure compliance. Our proposal is non-intrusive and does not interfere with the core network’s usual processes based on existing Service Based Interfaces (SBI). Additionally, we demonstrate that the classification of a data packet as malicious or benign is context-dependent using AI/ML Transformer Encoder architectures. We implement and integrate our proposed 5G-CIoT IDS as a Network Function inside the 5G Amarisoft platform for extensive experimentation. To evaluate the models’ performance, we train our models with different categories of safe and malicious generated traffic and apply them to an emulated realistic scenario. We obtained a very promising result. Tan Nhat Linh Le, Boussad Ait Salem, Dave Appadoo, Nadjib Aitsaadi, Xiaojiang Du |
LCN | 2 |
| 2023 | VNFO-DCSC: A Novel Secure End-to-End NFV Marketplace Using Dynamic Composite Smart ContractsabstractRecently, the integration of Network Function Virtualization (NFV) with the blockchain has been gaining a lot of attention. This combination aims to avoid traditional NFV issues such as trust, payment, and security. Several works have been proposed to orchestrate, buy, execute, and manage the life cycle of a Virtual Network Function (VNF). Thus, they came as NFV marketplaces and orchestration platforms. In this paper, we provide a novel secure End-to-End NFV marketplace called “VNFO-DCSC”, that uses dynamic composite smart contracts. This platform provides full orchestration, management, execution, and monitoring of VNFs in a secure way. “VNFO-DCSC” is implemented following the European Telecommunications Standards Institute (ETSI) standards [1] for NFV management and it is available on GitHub. Mouhamad Almakhour, Layth Sliman, Abed Ellatif Samhat, Boussad Ait Salem, Abdelhamid Mellouk |
GLOBECOM | 4 |
| 2023 | 5G-IoT-IDS: Intrusion Detection System for CIoT as Network Function in 5G Core NetworkabstractIn this paper, our objective is to design, develop and deploy a novel 5G-IoT IDS as a 5G core network function compliant with 3GPP R17. 5G-IoT IDS provides protection against malicious behaviors targeting IoT networks. To satisfy the 3GPP standard, our proposal respects the design architecture of the 5G system and only uses functionalities defined by the 3GPP technical specifications. Using Open5GS emulating the 5G core network, we implemented and integrated the 5G-IoT IDS as an NF to inspect IoT MQTT traffic on the user plane with common ML algorithms to demonstrate feasibility and effectiveness of our proposal. We explored a different way of handling MQTT packets, delving deeper into the structure of the packet. Based on extensive emulations, we compared our results with analogous studies focused on the MQTT protocol, and it revealed that our emulations exhibit strong performance, which aligns with those highlighted in the related studies, when up against a variant attack of the same flood-based principle. We believe our method of packet handling demonstrates a more comprehensive consideration of MQTT packet characteristics. Tan Nhat Linh Le, Boussad Ait Salem, Emile Abdel Ahad, Nadjib Aitsaadi, Xiaojiang Du |
GLOBECOM | 2 |
| 2012 | A hybrid multiagent routing approach for wireless ad hoc networks
Boussad Ait Salem, Mohamed Amine Riahla, Karim Tamine |
Wirel. Networks | 1 |
| 2009 | A Collusion-Resistant Distributed Scalar Product Protocol with Application to Privacy-Preserving Computation of TrustabstractPrivate scalar product protocols have proved to be interesting in various applications such as data mining, data integration, trust computing, etc. In 2007, Yao et al. proposed a distributed scalar product protocol with application to privacy-preserving computation of trust [1]. This protocol is split in two phases: an homorphic encryption computation; and a private multi-party summation protocol. The summation protocol has two drawbacks: first, it generates a non-negligible communication overhead; and second, it introduces a security flaw. The contribution of this present paper is two-fold. We first prove that the protocol of [1] is not secure in the semi-honest model by showing that it is not resistant to collusion attacks and we give an example of a collusion attack, with only four participants. Second, we propose to use a superposed sending round as an alternative to the multi-party summation protocol, which results in better security properties and in a reduction of the communication costs. In particular, regarding security, we show that the previous scheme was vulnerable to collusions of three users whereas in our proposal we can t isin [1..n - 1] and define a protocol resisting to collusions of up to t users. Carlos Aguilar Melchor, Boussad Ait Salem, Philippe Gaborit |
NCA | 2 |
| 2008 | AntTrust: A Novel Ant Routing Protocol for Wireless Ad-hoc Network Based on Trust between NodesabstractA wireless ad-hoc network is a network which does not use any infrastructure such as access points or base station. Instead, the mobile nodes forward packets to each others, allowing communication among nodes outside wireless transmission range. In this dynamic network, each node is considered as a mobile router but in an energy-conserving manner. This fact makes node an active element in the network which is able of the best and of the worst. Actually, a malicious node can easily disrupt the proper functioning of the routing by simply refusing to forward routing message (misbehavior node), inject the wrong routing packets, modifying others, etc. In this paper, we propose a new routing protocol for wireless ad-hoc network based on multi-agent systems and particularly on ant behavior. The novelty of our protocol relies in the fact that, apparently for the first time, a protocol combines at the same time routing on one side and trust level and reputation between nodes on the other side. This combination permits to increase the security of route establishment. More generally, this protocol opens the door to the use of different agents for obtaining different mixed functionalities, routing and trust level in this paper but also other functionalities like key-distribution. Carlos Aguilar Melchor, Boussad Ait Salem, Philippe Gaborit, Karim Tamine |
ARES | 2 |