Charles-Henry Bertrand Van Ouytsel

dblp:292/2958 · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
9since 2021 · last 2025
0000-0001-5720-6569ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Evaluating Behavior Graph Reduction Strategies for Machine Learning-Based Malware Detection
abstract
Graph-based representations of program behavior are a powerful foundation for machine learning-based malware detection. However, the large size and complexity of these behavior graphs pose scalability challenges. This paper presents a systematic evaluation of five graph reduction strategies—covering both coarsening and sparsification—designed to simplify graphs while preserving meaningful behavioral features. Using dynamic analysis data from Windows PE32 binaries, we analyze the impact of these reductions on computational efficiency, detection performance, and model robustness against adversarial mimicry attacks. Our results show that several strategies substantially reduce graph size and extraction time without significant accuracy loss. We also find that coarsening based on API calls’ action maintains stronger robustness to adversarial manipulation.
Samy Bettaieb, Serena Lucca, Charles-Henry Bertrand Van Ouytsel, Etienne Rivière
TrustCom3
2024 Highlighting the Impact of Packed Executable Alterations with Unsupervised Learning
Alexandre D'Hondt, Charles-Henry Bertrand Van Ouytsel, Axel Legay
CRiSIS2
2024 Extended Abstract: Evading Packing Detection: Breaking Heuristic-Based Static Detectors
Alexandre D'Hondt, Charles-Henry Bertrand Van Ouytsel, Axel Legay
DIMVA2
2024 A vision on a methodology for the application of an Intrusion Detection System for satellites
abstract
The security of satellites has become critical in recent years due to their important role in modern society. However, numerous challenges, including limited computing resources, evolving cyber threats, and the isolated nature of satellites, hinder the development of effective security solutions. Different solutions should be implemented and combined to protect space assets: encryption, access control, zero-trust architecture, etc. This vision presents the challenges and aspects to consider for implementing an Intrusion Detection System (IDS) tailored to improve the security of satellite systems. Our approach uses a multi-level structure to define rule-based and machine-learning security approaches that address the challenges associated with different mission types. By strategically placing IDS components and considering the trade-offs of each location, we improve detection reliability. Additionally, we present an ontology-based method for visualizing the IDS configuration, which provides clear insight into system capabilities, enhances situational awareness, and facilitates identification and response to potential threats. We also provide strategies for updating the IDS while maintaining efficiency and security. This vision helps improve the cybersecurity measures of satellite operations and increase their resilience to cyberattacks.
Sébastien Gios, Charles-Henry Bertrand Van Ouytsel, Mark Diamantino Caribé, Axel Legay
ASE2
2024 Analysis of machine learning approaches to packing detection
Charles-Henry Bertrand Van Ouytsel, Khanh-Huu-The Dam, Axel Legay
Comput. Secur.1
2024 Feature selection for packer classification based on association rule mining
Rosana Veroneze, Charles-Henry Bertrand Van Ouytsel, Khanh-Huu-The Dam, Axel Legay
Eng. Appl. Artif. Intell.2
2023 Experimental Toolkit for Manipulating Executable Packing
Alexandre D'Hondt, Charles-Henry Bertrand Van Ouytsel, Axel Legay
CRiSIS2
2022 Symbolic analysis meets federated learning to enhance malware identifier
abstract
The manual methods to create detection rules are no longer practical in the anti-malware product since the number of malware threats has been growing over past years. Thus, the turn to machine learning approaches is a promising way to make malware recognition more efficient. The traditional centralized machine learning requires a large amount of data to train a model with excellent performance. To boost the malware detection, the training data might be on various kind of data sources such as data on the host, network, and cloud-based anti-malware components, or even, data from different enterprises. To avoid the expenses of data collection as well as the leakage of private data, we present a federated learning system to identify malware through behavioral graphs, i.e., system call dependency graphs. It is based on a deep learning model including a graph autoencoder and a multiclass classifier module. This model is trained by a secure learning protocol among clients to preserve the private data against inference attacks. Using the model to identify malware, we achieve the accuracy of for homogeneous graph data and for inhomogeneous graph data.
Charles-Henry Bertrand Van Ouytsel, Khanh-Huu-The Dam, Axel Legay
ARES1
2022 Tool Paper - SEMA: Symbolic Execution Toolchain for Malware Analysis
Charles-Henry Bertrand Van Ouytsel, Christophe Crochet, Khanh-Huu-The Dam, Axel Legay
CRiSIS1