VLDB 2026 Research / reviewers in the wild / expert
Léo Lavaur
dblp:331/2422
· DBLP profile ↗
7ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0002-0379-7946ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Key-Parametrized Embeddings for Access Control in Retrieval-Augmented Generation
Théo Thuillier, Léo Lavaur, Jérôme François, Radu State, William Ferguson |
COMPSAC | 2 |
| 2026 | Investigating Neuro-Symbolic AI for Context-Aware Process Classification with MITRE ATT&CK® TechniquesabstractSystem logs contain rich information about system activity, but correctly identifying malicious events is difficult without contextual information. While sequential models like Transformers or LSTMs can process sequences of events and extract information from that context, they are neither interpretable nor explicit. In this paper, we use a neural-symbolic framework to classify process-level auditd events into the appropriate techniques of the MITRE ATT&CK® framework. We apply our approach to multiple model architectures and show that contextual logic can improve the overall F1-score, while providing interpretable per-technique corrections. Omar Anser, Léo Lavaur, Jérôme François |
SIGCOMM | 2 |
| 2025 | Investigating the Impact of Label-flipping Attacks against Federated Learning for Collaborative Intrusion Detection
Léo Lavaur, Yann Busnel, Fabien Autrel |
Comput. Secur. | 1 |
| 2024 | Systematic Analysis of Label-flipping Attacks against Federated Learning in Collaborative Intrusion Detection SystemsabstractWith the emergence of federated learning (FL) and its promise of privacy-preserving knowledge sharing, the field of intrusion detection systems (IDSs) has seen a renewed interest in the development of collaborative models. However, the distributed nature of FL makes it vulnerable to malicious contributions from its participants, including data poisoning attacks. The specific case of label-flipping attacks, where the labels of a subset of the training data are flipped, has been overlooked in the context of IDSs that leverage FL primitives. This study aims to close this gap by providing a systematic and comprehensive analysis of the impact of label-flipping attacks on FL for IDSs. We show that such attacks can still have a significant impact on the performance of FL models, especially targeted ones, depending on parameters and dataset characteristics. Additionally, the provided tools and methodology can be used to extend our findings to other models and datasets, and benchmark the efficiency of existing countermeasures. Léo Lavaur, Yann Busnel, Fabien Autrel |
ARES | 1 |
| 2024 | Demo: Highlighting the Limits of Federated Learning in Intrusion DetectionabstractFederated learning (FL) is a distributed learning paradigm enabling participants to collaboratively train a machine learning (ML) model. In security-oriented tasks, FL can be used to share attack knowledge, without sharing participants' local data. Recent research results reveal that highly heterogeneous data distributions can prevent federations from converging towards an appropriate global model. Moreover, maintaining trustworthiness is challenging, as FL-based collaborative intrusion detection systems (CIDSs) are vulnerable to malicious updates. In this demonstration paper, we present critical examples of these challenges using a set of standardized public datasets and a dedicated automation tool. We review the impact of heterogeneity using different data-distribution, before looking at a scenario with malicious actors. Léo Lavaur, Yann Busnel, Fabien Autrel |
ICDCS | 1 |
| 2024 | RADAR: Model Quality Assessment for Reputation-aware Collaborative Federated LearningabstractCross-silo federated learning (CS-FL) is a distributed learning setting which allows an identified set of organizations to collaboratively train a single global model. Since CS-FL use cases are often heterogeneous, it may be more appropriate to dynamically provide different models to more homogeneous sub-federations. In addition, such systems can be undermined by contributions of poor quality, making negligent or even malicious participants critical to consider. However, distinguishing such participants in a heterogeneous context is especially difficult. We present RADAR, a novel architecture for CS-FL able to assess the quality of the participants' contributions, regardless of data similarity. RADAR leverages client-side evaluation to directly collect feedbacks from the participants. The same evaluations allow grouping participants according to their perceived similarity and weighting the model aggregation based on their reputation. To evaluate our approach on concrete experiments, we implement a collaborative intrusion detection system (CIDS) scenario and test our architecture in various data-quality settings using label-flipping. Our results confirm that combining clustering and a reputation system succeeds in detecting a wide range of Byzantine behaviors, including colluding attackers, which highlights RADAR's versatility. Léo Lavaur, Pierre-Marie Lechevalier, Yann Busnel, Romaric Ludinard, Marc-Oliver Pahl, Géraldine Texier |
SRDS | 1 |
| 2022 | The Evolution of Federated Learning-Based Intrusion Detection and Mitigation: A SurveyabstractIn 2016, Google introduced the concept of Federated Learning (FL), enabling collaborative Machine Learning (ML). FL does not share local data but ML models, offering applications in diverse domains. This paper focuses on the application of FL to Intrusion Detection Systems (IDSs). There, common criteria to compare existing solutions are missing. In particular, this survey shows: (i) how FL-based IDSs are used in different domains; (ii) what differences exist between architectures; (iii) the state of the art of FL-based IDS. With a structured literature survey, this work identifies the relevant state of the art in FL–based intrusion detection from its creation in 2016 until 2021. It provides a reference architecture and a taxonomy to serve as guidelines to compare and design FL-based IDSs. Both are validated with the existing works. Finally, it identifies research directions for the application of FL to intrusion detection systems. Léo Lavaur, Marc-Oliver Pahl, Yann Busnel, Fabien Autrel |
IEEE Trans. Netw. Serv. Manag. | 1 |