Hithem Lamri

dblp:345/7780 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
4since 2021 · last 2026
0009-0008-5269-8718ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ICSBoM: Uncovering Hidden Supply Chain Vulnerabilities in ICS Firmware
Yongyu Xie, Daniel Khoshkhoo, Hithem Lamri, Constantine Doumanidis, Brian Davidson, Burak Sahin, Ryan Pickren, Raheem A. Beyah, Katherine R. Davis 0001, Michail Maniatakos, Saman Zonouz
ACNS (3)3
2025 ReVeil: Unconstrained Concealed Backdoor Attack on Deep Neural Networks using Machine Unlearning
abstract
Backdoor attacks embed hidden functionalities in deep neural networks (DNN), triggering malicious behavior with specific inputs. Advanced defenses monitor anomalous DNN inferences to detect such attacks. However, concealed backdoors evade detection by maintaining a low pre-deployment attack success rate (ASR) and restoring high ASR post-deployment via machine unlearning. Existing concealed backdoors are often constrained by requiring white-box or black-box access or auxiliary data, limiting their practicality when such access or data is unavailable. This paper introduces ReVeil, a concealed backdoor attack targeting the data collection phase of the DNN training pipeline, requiring no model access or auxiliary data. ReVeil maintains low pre-deployment ASR across four datasets and four trigger patterns, successfully evades three popular backdoor detection methods, and restores high ASR postdeployment through machine unlearning.
Manaar Alam, Hithem Lamri, Michail Maniatakos
DAC2
2025 LLMPot: Dynamically Configured LLM-based Honeypot for Industrial Protocol and Physical Process Emulation
abstract
Industrial Control Systems (ICS) are extensively used in critical infrastructures ensuring efficient, reliable, and continuous operations. However, their increasing connectivity and addition of advanced features make them vulnerable to cyber threats, potentially leading to severe disruptions in essential services. In this context, honeypots play a vital role by acting as decoy targets within ICS networks, or on the Internet, helping to detect, log, analyze, and develop mitigations for ICS-specific cyber threats. Deploying ICS honeypots, however, is challenging due to the necessity of accurately replicating industrial protocols and device characteristics, a crucial requirement for effectively mimicking the unique operational behavior of different industrial systems. Additionally, the difficulty is increased by the substantial manual effort involved in replicating the PLC’s control logic. This is necessary to capture attacker traffic that seeks to interfere with critical infrastructure operations. In this paper, we propose LLMPot, a novel approach for designing honeypots in ICS networks harnessing the potency of Large Language Models (LLMs). LLMPot aims to provide a dynamic framework that can be used to optimize the creation of realistic honeypots with vendor-agnostic configurations and for various control logic, aiming to eliminate the manual effort and specialized knowledge traditionally required by existing strategies. We conducted extensive experiments focusing on a wide array of parameters, demonstrating that LLMPot can effectively create honeypot devices implementing different industrial protocols, PLC configurations, and diverse control logic.
Christoforos Vasilatos, Dunia J. Mahboobeh, Hithem Lamri, Manaar Alam, Michail Maniatakos
EuroS&P3
2025 ICSQuartz: Scan Cycle-Aware and Vendor-Agnostic Fuzzing for Industrial Control Systems
Corban Villa, Constantine Doumanidis, Hithem Lamri, Prashant Hari Narayan Rajput, Michail Maniatakos
NDSS3