VLDB 2026 Research / reviewers in the wild / expert
Miel Verkerken
dblp:280/0644
· DBLP profile ↗
9ranked-venue papers
3as first author
9since 2021 · last 2026
0000-0002-1781-900XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021Computer networks · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | "What is the Problem Space?" Defining Host-space Adversarial Perturbations against Network Intrusion Detection SystemsabstractNetwork Intrusion Detection Systems (NIDS) are now increasingly leveraging Machine Learning (ML) techniques to detect malicious network activities. Numerous papers have scrutinized the security of ML-based NIDS (ML-NIDS) by testing them against various attacks involving adversarial perturbations. The findings were oftentimes worrying: by making imperceptible changes to a given input, powerful ML models would be bypassed. In this context, we took a step back and wondered: where (i.e., in what “space”) have these perturbations been applied? Miel Verkerken, Laurens D'hooge, Bruno Volckaert, Filip De Turck, Giovanni Apruzzese |
AsiaCCS | 1 |
| 2024 | ChronosGuards: A Hierarchical Machine Learning Intrusion Detection System for Modern CloudsabstractTraditional Intrusion Detection Systems (IDSs) have been a cornerstone of network security for many years. Nevertheless, with the advent of containerized applications in the last few years, there is a growing need to understand how intrusion detection can adapt to these dynamic environments. This paper presents ChronosGuard, a hierarchical machine learning (ML) IDS designed for containerized environments. ChronosGuard’s adaptable architecture consists of multiple components, each optimized for deployment in varying configurations ranging from monolithic to micro-service architectures. The performance impact of various factors such as network topology, work-load orchestration, and deployment strategies has been assessed through extensive experiments concerning the scalability and resource utilization of ChronosGuard. Results show the effective prioritization of benign traffic of up to 85% compared to malicious traffic, the negligible impact of small network delays on performance metrics, and up to 10% decrease in response times with network-aware orchestration for complex deployment configurations. This study introduces a robust, containerized IDS that can be easily adapted to meet various operational needs, ranging from a full privacy-preserving local deployment to a scalable cloud deployment but also provides foundational insights for future research into optimizing containerized security solutions. Miel Verkerken, José Santos 0001, Laurens D'hooge, Tim Wauters, Bruno Volckaert, Filip De Turck |
CNSM | 1 |
| 2023 | Performance Impact of Queue Sorting in Container-Based Application SchedulingabstractContainerization has revolutionized application deployments in current cloud platforms, enabling the flexible instantiation of loosely-coupled microservices and enhancing operational efficacy. However, optimizing the performance of container-based applications remains a challenge and a major topic in cloud research. This paper studies the impact of queue sorting in application scheduling, focused on complex inter-dependencies among microservices. Queue sorting determines the deployment order of containers in the infrastructure, typically based on container priorities and resource requests. Optimizing these algorithms directly influences scheduling efficiency and overall application performance. This paper compares several schedulers and sorting algorithms, leveraging extensive benchmark tests conducted on the widely-used Kubernetes (K8s) platform. The evaluation includes a novel sorting algorithm named Topological-Sort, designed to prioritize containers for application scheduling focused on microservice inter-dependencies. Results show the significant impact of queue sorting on application performance, with TopologicalSort algorithms outperforming default mechanisms, yielding an average increase of 20 % in throughput and reducing response time by at least 15 %. These results highlight the importance of considering microservice inter-dependencies for effective application deployment in modern container-based environments. José Santos 0001, Miel Verkerken, Laurens D'hooge, Tim Wauters, Bruno Volckaert, Filip De Turck |
CNSM | 2 |
| 2023 | Castles Built on Sand: Observations from Classifying Academic Cybersecurity Datasets with Minimalist MethodsabstractMachine learning (ML) has been a staple of academic research into pattern recognition in many fields, including cybersecurity.The momentum of ML continues to speed up alongside the advances in hardware capabilities and the methods they unlock, primarily (deep) neural networks.However, this article aims to demonstrate that the non-judicious use of ML in two prominent domains of data-based cybersecurity consistently misleads researchers into believing that their proposed methods constitute actual improvements.Armed with 17 stateof-the-art datasets in traffic and malware classification and the simplest possible machine learning model this article will show that the lack of variability in most of these datasets immediately leads to excellent models, even if that model is only one comparison per feature. Laurens D'hooge, Miel Verkerken, Tim Wauters, Filip De Turck, Bruno Volckaert |
IoTBDS | 2 |
| 2023 | Task Assignment and Capacity Allocation for ML-Based Intrusion Detection as a Service in a Multi-Tier ArchitectureabstractIntrusion Detection Systems (IDS) play an important role in detecting network intrusions. Because intrusions have many variants and zero-day attacks, traditional signature- and anomaly-based IDS often fail to detect them. On the other hand, solutions based on Machine Learning (ML), have better capabilities for detecting variants. In this work, we adopt an ML-based IDS which uses three in-sequence tasks, pre-processing, binary detection, and multi-class detection, with a multi-tier architecture with one-, two-, and three-tier architectural configurations. We then mapped three in-sequence tasks into these architectures, resulting in ten task assignments. We evaluated these with queueing theory to determine which tasks assignments were more appropriate for particular service providers. With simulated annealing, we obtained the computation capacity by allocating the total cost appropriate to each tier, based on the fixed parameter set with the objective of minimizing overall delay. These investigations showed that using only the edge and allocating all tasks to it gave the best performance. Furthermore, a two-tier architecture with edge and cloud components was also sufficient for IDS as a Service with the delay that was three times better than for other task assignments. Our results also indicate that more than 85% of the total capacity was allocated and spread across nodes in the lowest tier for pre-processing to reduce delays. Yuan-Cheng Lai, Didik Sudyana, Ying-Dar Lin, Miel Verkerken, Laurens D'hooge, Tim Wauters, Bruno Volckaert, Filip De Turck |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | A Novel Multi-Stage Approach for Hierarchical Intrusion DetectionabstractAn intrusion detection system (IDS), traditionally an example of an effective security monitoring system, is facing significant challenges due to the ongoing digitization of our modern society. The growing number and variety of connected devices are not only causing a continuous emergence of new threats that are not recognized by existing systems, but the amount of data to be monitored is also exceeding the capabilities of a single system. This raises the need for a scalable IDS capable of detecting unknown, zero-day, attacks. In this paper, a novel multi-stage approach for hierarchical intrusion detection is proposed. The proposed approach is validated on the public benchmark datasets, CIC-IDS-2017 and CSE-CIC-IDS-2018. Results demonstrate that our proposed approach besides effective and robust zero-day detection, outperforms both the baseline and existing approaches, achieving high classification performance, up to 96% balanced accuracy. Additionally, the proposed approach is easily adaptable without any retraining and takes advantage of n-tier deployments to reduce bandwidth and computational requirements while preserving privacy constraints. The best-performing models with a balanced set of thresholds correctly classified 87% or 41 out of 47 zero-day attacks, while reducing the bandwidth requirements up to 69%. Miel Verkerken, Laurens D'hooge, Didik Sudyana, Ying-Dar Lin, Tim Wauters, Bruno Volckaert, Filip De Turck |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | Establishing the Contaminating Effect of Metadata Feature Inclusion in Machine-Learned Network Intrusion Detection Models
Laurens D'hooge, Miel Verkerken, Bruno Volckaert, Tim Wauters, Filip De Turck |
DIMVA | 2 |
| 2022 | Discovering Non-Metadata Contaminant Features in Intrusion Detection DatasetsabstractMost newly proposed detection methods in intrusion detection incorporate machine learning models to distinguish between benign and malicious traffic. The models are validated on a handful of academic datasets and ranked based on their classification performance. This article aims to demonstrate that unbeknownst to the new models' authors, there are features in these datasets which heavily bias the results and obscure a realistic, reliable estimate of the separability of the datasets. This paper proposes a methodology to estimate the contaminating influence of a dataset’s features based on the concept of blind generalization. The novel methodology is subsequently used to assess the features of six widely adopted intrusion detection datasets. In each dataset, several features show a pattern where regardless of training attack class, the models blindly generalize towards all available attack classes with nearly identical classification metrics. These features provide undeserved boosts in the baseline classification scores for each dataset. By themselves, some contaminant features even push these baselines upwards of 90% accuracy (balanced). Laurens D'hooge, Miel Verkerken, Tim Wauters, Bruno Volckaert, Filip De Turck |
PST | 2 |
| 2021 | Hierarchical feature block ranking for data-efficient intrusion detection modeling
Laurens D'hooge, Miel Verkerken, Tim Wauters, Bruno Volckaert, Filip De Turck |
Comput. Networks | 2 |