VLDB 2026 Research / reviewers in the wild / expert
Rim Ben Salem
dblp:281/3502
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2025
0000-0001-6938-0097ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Federated Intrusion Detection System Based on Unsupervised Machine Learning
Maxime Gourceyraud, Rim Ben Salem, Christopher Neal, Frédéric Cuppens, Nora Cuppens |
CRiSIS | 2 |
| 2025 | A Privilege Creep-Aware Role Mining Method for Enhanced Access Control SecurityabstractRole Mining (RM) extracts Role-Based Access Control (RBAC) structures from user-permission assignments to reduce administrative overhead. However, existing approaches usually make the assumption of clean datasets, while real-world systems suffer from anomalies like privilege creep, the gradual accumulation of unnecessary permissions.The proposed approach aims to detect potential privilege crept users who should be reviewed first, and identify legitimate permissions assignments to be expressed in RBAC, reducing management complexity. It consists of a two-step procedure: clean the User-Permission Assignment matrix (UPA) using a clustering and statistical analysis, then build an RBAC state using a regular role mining algorithm.The proposed approach yields an average of 90% in privilege creep detection accuracy and over 95% privilege creep correction, evaluated on synthetically made datasets. Evaluation on real-world datasets demonstrates an average 4-fold reduction in required roles while maintaining at least 80% UPA coverage. Vincent Bittard, Rim Ben Salem, Ahmed Bouzid, Sara Imene Boucetta, Frédéric Cuppens, Nora Cuppens |
TrustCom | 2 |
| 2025 | From static to dynamic risk indicators in predicting and detecting insider attacksabstractCyber insider threats represent one of the most complex and insidious challenges to modern cybersecurity, as they originate from legitimate users whose behaviors may turn malicious over time. Traditional approaches often fail due to their reliance on static risk indicators, necessitating dynamic modeling of human behavior to capture evolving risks. In this paper, we propose a novel framework for detecting insider threats by continuously and dynamically inferring personality-based risk indicators from employees’ writing data using a publicly accessible large language model (Meta AI’s Llama-3.2). These indicators are modeled as time series and processed through AutoRegressive Integrated Moving Average (ARIMA) models to forecast behavioral deviations. Predicted anomalies are subsequently classified using a hybrid ensemble combining Artificial Neural Networks (ANN) and Random Forest (RF) to distinguish benign variations from genuine insider threats. Our framework identifies behavioral anomalies, provides interpretable detection windows, and achieves the following results on CMU-CERT datasets (r4.2/r5.2): recall (90.0%/86.0%), precision (92.6%/87.7%), ROC-AUC (94.7%/92.6%), MSE (0.231/0.304), MTTD (21.3 days/31.72 days) and a median latency under 230 ms for real-time operation. These results demonstrate significant improvements over baseline static approaches in both detection accuracy and temporal prediction capability. This work advances human-centric and proactive insider threat detection by integrating personality-based risk indicators with predictive modeling, providing a scalable and interpretable solution for real-time dynamic risk assessment in enterprise environments. N'Famoussa Kounon Nanamou, Rim Ben Salem, Anis Bkakria, Nora Cuppens, Frédéric Cuppens |
TrustCom | 2 |
| 2023 | User modelling for privacy-aware self-disclosureabstractInformation and Communications Technology (ICT) is proliferating exponentially and has undoubtedly become an intrinsic part of our daily lives. However, its fast-paced growth has brought upon multiple challenges amongst which are the human-centric threats to cybersecurity and privacy. One of the main reasons for this is the shift in individuals’ behaviour towards carelessly disclosing private information, especially on social media.This work builds on the existing literature that identifies the motivations leading to oversharing in order to predict and mitigate self-disclosure. This paper aims to tackle this first by proposing a user model for the individual’s disclosure motivations. The aim is to measure how driven the user is to share personal information given a specific context. This is paramount to second objective, which is designing personalized privacy-preserving interventions known as nudges based on the user model. A visual aid is provided to further attract the user’s attention and persuade them to alter their behaviour. Study participants (N=800) were recruited via Mechanical Turk and responded to realistic scenarios to assess their motivations for sharing personal data. Then, persuasive nudges were pushed in the context of the evaluation. Rim Ben Salem, Esma Aïmeur, Hicham Hage |
PST | 1 |
| 2022 | Aegis: An Agent for Multi-party Privacy PreservationabstractThe proliferation of social media set the foundation for the culture of over-disclosure where many people document every single event, incident, trip, etc. for everyone to see. Raising the individual's awareness of the privacy issues that they are subjecting themselves to can be challenging. This becomes more complex when the post being shared includes data "owned" by others. The existing approaches aiming to assist users in multi-party disclosure situations need to be revised to go beyond preferences to the "good" of the collective. Rim Ben Salem, Esma Aïmeur, Hicham Hage |
AIES | 1 |