VLDB 2026 Research / reviewers in the wild / expert
Aristide T.-J. Akem
dblp:284/3961 · also Aristide Tanyi-Jong Akem
· DBLP profile ↗
11ranked-venue papers
11as first author
11since 2021 · last 2026
0000-0002-4359-0173ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 5 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 4 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fast-Path in-Network Inference on Intel Infrastructure Processing Units
Aristide T.-J. Akem |
NetSoft | 1 |
| 2026 | HyNIC: Hybrid In-Network Inference for Line-Rate Anomaly Detection on SmartNICsabstractSmartNICs have emerged as a promising platform for in-network machine learning inference, yet existing approaches largely rely on stateless packet-level inference, off-path stateful inference or offloading flow-level analysis to the host, limiting performance. This creates a performance gap between line-rate inference capabilities in the data plane and the need for flow-aware context in security and monitoring applications. In this paper, we bridge this gap by exploiting the coexistence of programmable data planes and on-NIC processing cores on SmartNICs. We propose HyNIC, a hybrid in-network inference system that performs line-rate packet classification for intrusion and anomaly detection in the data plane while subsequently enriching inference with stateful flow-level context computed on SmartNIC cores and integrated back at runtime. HyNIC enables a seamless transition from stateless to flow-aware inference without diverting packets from the fast path. We implement HyNIC in P4 on an industry-grade SmartNIC and evaluate it on realistic IoT intrusion detection datasets, demonstrating significant accuracy improvements of up to 22% over a stateless-only baseline while preserving line-rate performance. Aristide T.-J. Akem, Noa Zilberman |
NetSoft | 1 |
| 2026 | Real-Time Intrusion Detection for IoMT with in-Network Inference on SmartNICsabstractInternet of Medical Things (IoMT) systems constitute safety-critical networking environments that remain vulnerable to cyber threats. Existing intrusion detection systems typically rely on off-path processing at the edge, fog, or cloud, resulting in increased detection latency and delayed response, which can adversely impact timely intervention in patient-critical scenarios. P4-programmable SmartNICs enable placing machine learning inference directly in the network data path for low-latency, on-path inference without reliance on external processing. In this paper, we present a SmartNIC-based intrusion detection system based on machine learning inference, running entirely on the NIC data plane. Our design builds on a stateless binary decision tree mapped onto the SmartNIC match-action pipeline, enabling per-packet classification entirely in the fast path. We implement our solution in P4 on an Intel IPU and evaluate it using two IoMT datasets. Results show that our approach reduces latency by 10× compared to a host-based system, providing end-to-end latency similar to L2 forwarding, while achieving up to 99% detection accuracy and enabling timely in-network intrusion detection. Aristide T.-J. Akem, Noa Zilberman |
NetSoft | 1 |
| 2026 | In-Network Machine Learning for Real-Time Patient Monitoring on IoMT Edge GatewaysabstractThe Internet of Medical Things is transforming healthcare from reactive, hospital-based care to preventive and continuous remote monitoring. However, current solutions often depend on cloud or mobile platforms for data aggregation and analysis, introducing latency, privacy risks, and financial burden. In-network machine learning offers an opportunity to address these challenges by enabling real-time analytics directly within the network infrastructure. In this work, we present VISTA, an in-network computing framework for health analytics that enables real-time patient monitoring through in-network machine learning within edge gateways. VISTA integrates P4-based data plane modules that asynchronously aggregate heterogeneous sensor data and execute machine learning inference locally within the gateway, eliminating the reliance on cloud offloading. Implemented on a Dell Edge Gateway and evaluated on a 2000-patient dataset for early detection of sepsis and heart failure, VISTA achieves up to 95% detection accuracy, 2 milliseconds average latency, and 90% reduction in communication overhead, compared with cloud-based baselines. These results demonstrate the potential of in-network machine learning for scalable, low-latency, and privacy-preserving remote patient monitoring. Aristide T.-J. Akem, Huiqi Y. Lu, Noa Zilberman |
IEEE Internet Things J. | 1 |
| 2025 | Practical and General-Purpose Flow-Level Inference With Random Forests in Programmable SwitchesabstractIntegrating machine learning (ML) models directly in the network user plane enables inference on data traffic at line rate, and can dramatically reduce the latency and improve the scalability of key functionalities like traffic classification or intrusion detection. Yet, the hardware that can be used for this purpose, in particular programmable switches, present stringent constraints in terms of limited memory and little support for mathematical operations or data types that render ML model deployment a substantial technical challenge. In this paper, we make a step forward in user-plane ML by introducingFlowrest, a solution that redefines the state of the art in flow-level inference for programmable switches.Flowrestallows implementing general-purpose Random Forest (RF) models in industry-grade switches by ($\boldsymbol {i}$) suitably handling stateful flow-level (FL) features in the switch ASIC, ($\boldsymbol {ii}$) achieving low-collision flow management, and ($\boldsymbol {iii}$) customizing RF models right from the design phase for in-switch operation. We developFlowrestas an open-source software using the P4 language and evaluate its performance in an experimental testbed with Intel Tofino switches. Experiments with inference tasks of varying complexity prove that our solution improves accuracy by over 10 percent points on average with respect to the second-best competitor out of five recent approaches for RF-based in-switch inference, while maintaining sub-microsecond latency. Aristide T.-J. Akem, Beyza Bütün, Michele Gucciardo, Marco Fiore 0001 |
IEEE Trans. Netw. | 1 |
| 2024 | Towards Real-Time Intrusion Detection in P4-Programmable 5G User Plane FunctionsabstractRecent works have shown that Machine Learning (ML) models can be deployed in P4-programmable user planes for line rate inference on live traffic and that these user planes can also be used to accelerate the 5G User Plane Function (UPF). This work builds on these capabilities to explore how ML inference in the user plane can facilitate real-time intrusion detection in 5G networks. As a proof-of-concept, we describe how an ML model could be deployed into the UPF as a special Packet Detection Rule (PDR). We then train and deploy a tree-based classifier into a P4programmable switch acting as the UPF and conduct experiments on a testbed with off-the-shelf hardware using experimental data from a 5 G test network on a university campus. Our results confirm that running ML-based intrusion detection on P4-based UPFs ensures line-rate attack detection and classification with an accuracy of up to$98 \%$in terms of F1 score, while keeping switch resource consumption increase under control. Aristide T.-J. Akem, Marco Fiore 0001 |
ICNP | 1 |
| 2024 | Jewel: Resource-Efficient Joint Packet and Flow Level Inference in Programmable SwitchesabstractEmbedding machine learning (ML) models in programmable switches realizes the vision of high-throughput and low-latency inference at line rate. Recent works have made breakthroughs in embedding Random Forest (RF) models in switches for either packet-level inference or flow-level inference. The former relies on simple features from packet headers that are simple to implement but limit accuracy in challenging use cases; the latter exploits richer flow features to improve accuracy, but leaves early packets in each flow unclassified. We propose Jewel, an in-switch ML model based on a fully joint packet-and flow-level design, which takes the best of both worlds by classifying early flow packets individually and shifting to flow-level inference when possible. Our proposal involves (i) a single RF model trained to classify both packets and flows, and (ii) hardware-aware model selection and training techniques for resource footprint minimization. We implement Jewel in P4 and deploy it in a testbed with Intel Tofino switches, where we run extensive experiments with a variety of real-world use cases. Results reveal how our solution outperforms four state-of-the-art benchmarks, with accuracy gains in the 2.0%–5.3% range. Aristide T.-J. Akem, Beyza Bütün, Michele Gucciardo, Marco Fiore 0001 |
INFOCOM | 1 |
| 2024 | Towards Data-Driven Management of Mobile Networks through User Plane InferenceabstractGrowing network complexity has rendered human-in-the-loop network management approaches obsolete. The advent of Software-Defined Networking (SDN) has enabled network automation, with Machine Learning (ML) models running in the control plane. However, such control plane models do not run at line rate and would not satisfy the stringent latency requirements of time-sensitive next-generation applications. In this PhD project, we exploit recent advances in programmable switches and associated languages like P4 to enable data-driven management of networks by running ML models for inference in programmable switches at line rate, with high throughput and low latency. Resulting contributions include solutions for in-switch classification at packet level, flow level, or both, with use cases in network security, service identification, and device fingerprinting in commercial off-the-shelf switches. Aristide T.-J. Akem, Marco Fiore 0001 |
NOMS | 1 |
| 2024 | Encrypted Traffic Classification at Line Rate in Programmable Switches with Machine LearningabstractEncrypted Traffic Classification (ETC) has become an important area of research with Machine Learning (ML) methods being the state-of-the-art. However, most existing solutions either rely on offline ETC based on collected network data or on online ETC with models running in the control plane of Software-Defined Networks (SDN), all of which do not run at line rate and would not meet latency requirements of time-sensitive applications in modern networks. This work leverages recent advances in data plane programmability to achieve real-time ETC in programmable switches at line rate, with high throughput and low latency. The proposed solution comprises (i) an ETC-aware Random Forest (RF) modelling process where only features based on packet size and packet arrival times are used, and (ii) an encoding of the trained RF model into production-grade P4-programmable switches. The performance of the proposed in-switch ETC framework is evaluated using 3 encrypted traffic datasets with experiments in a real-world testbed with Intel Tofino switches, in the presence of background traffic at 40 Gbps. Results show how the solution achieves high classification accuracy of up to 95%, with sub-microsecond delay, while consuming on average less than 10% of total available switch hardware resources. Aristide T.-J. Akem, Guillaume Fraysse, Marco Fiore 0001 |
NOMS | 1 |
| 2023 | Flowrest: Practical Flow-Level Inference in Programmable Switches with Random Forests
Aristide T.-J. Akem, Michele Gucciardo, Marco Fiore 0001 |
INFOCOM | 1 |
| 2023 | Showcasing In-Switch Machine Learning InferenceabstractRecent endeavours have enabled the integration of trained machine learning models like Random Forests in resource-constrained programmable switches for line rate inference. In this work, we first show how packet-level information can be used to classify individual packets in production-level hardware with very low latency. We then demonstrate how the newly proposed Flowrest framework improves classification performance relative to the packet-level approach by exploiting flow-level statistics to instead classify traffic flows entirely within the switch without considerably increasing latency. We conduct experiments using measurement data in a real-world testbed with an Intel Tofino switch and shed light on how Flowrest achieves an F1-score of 99% in a service classification use case, outperforming its packet-level counterpart by 8%. Aristide T.-J. Akem, Beyza Bütün, Michele Gucciardo, Marco Fiore 0001 |
NetSoft | 1 |