VLDB 2026 Research / reviewers in the wild / expert
Simon Queyrut
dblp:354/7388
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0002-1354-9604ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DroidHunter: A Robust Vision-Based Detection Against Hidden Android MalwareabstractDue to their large popularity, Android smartphones are often targeted by malware attacks. Several strategies exist to detect malware code. However, we show that they are insufficient when dealing with obfuscation techniques. DroidHunter is our novel method for detecting Android malwares. DroidHunter leverages opcodes and their parameters, transforming those into RGB images and specific encoding techniques. The generated images are then used to train two different classification models based on support vector machines, convolutional neural networks, and a vision-based transformer. We evaluate DroidHunter on several datasets with up to 476,937 APKs from multiple sources. With detection rates from 98.65% to 99.94%, DroidHunter overcomes nine state-of-the-art malware detection techniques, including Drebin, MaMadroid, DexRay. Moreover, DroidHunter demonstrates strong resilience against hidden malware with detection rates up to 98.98%, and shows robustness on newly emerging threats, achieving an AUT of 0.89 on recent malware samples. We release our code to the research community, with instructions to reproduce our evaluation available at: https://zenodo.org/doi/10.5281/zenodo.10977166. Victoire Nganfang, Simon Queyrut, Yérom-David Bromberg, Valerio Schiavoni, Djob Mvondo, Kengne Tchendji Vianney |
AsiaCCS | 2 |
| 2025 | PhishingHook: Catching Phishing Ethereum Smart Contracts leveraging EVM OpcodesabstractThe Ethereum Virtual Machine (EVM) is a decentralized computing engine. It enables the Ethereum blockchain to execute smart contracts and decentralized applications (dApps). The increasing adoption of Ethereum sparked the rise of phishing activities. Phishing attacks often target users through deceptive means, e.g., fake websites, wallet scams, or malicious smart contracts, aiming to steal sensitive information or funds. A timely detection of phishing activities in the EVM is therefore crucial to preserve the user trust and network integrity. Some state-of-the art approaches to phishing detection in smart contracts rely on the online analysis of transactions and their traces. However, replaying transactions often exposes sensitive user data and interactions, with several security concerns. In this work, we present PhishingHook, a framework that applies machine learning techniques to detect phishing activities in smart contracts by directly analyzing the contract’s bytecode and its constituent opcodes. We evaluate the efficacy of such techniques in identifying malicious patterns, suspicious function calls, or anomalous behaviors within the contract’s code itself before it is deployed or interacted with. We experimentally compare 16 techniques, belonging to four main categories (Histogram Similarity Classifiers, Vision Models, Language Models and Vulnerability Detection Models), using 7,000 real-world malware smart contracts. Our results demonstrate the efficiency of PhishingHook in performing phishing classification systems, with about 90% average accuracy among all the models. We support experimental reproducibility, and we release our code and datasets to the research community. Pasquale De Rosa, Simon Queyrut, Yérom-David Bromberg, Pascal Felber, Valerio Schiavoni |
DSN | 2 |
| 2024 | CLUES: Collusive Theft of Conditional Generative Adversarial NetworksabstractConditional Generative Adversarial Networks (cGANs) are increasingly popular web-based synthesis services accessed through a query API, e.g., cGANs generate a cat image based on a “cat” query. However, cGAN-based synthesizers can be stolen via adversaries' queries, i.e., model thieves. The prevailing adversarial assumption is that thieves act independently: they query the deployed cGAN (i.e., the victim), and train a stolen cGAN using the images obtained from the victim. A popular anti-theft defense consists in throttling down the number of queries from any given user. We consider a more realistic adversarial scenario: model thieves collude to query the victim, and then train the stolen cGAN. Clues is a new collusive model stealing framework, enabling thieves to bypass throttle-based defenses and steal cGANs more efficiently than through individual efforts. Thieves collect queried images and train a stolen cGAN in a federated manner. We evaluate Clues on three image datasets, e.g., MNIST, FashionMNIST and CelebA. We experimentally show the scalability of the proposed attack strategies against the number of thieves and the queried images, the impact of a classical noise-based defense, a passive watermarking defense and a JPEG-based countermeasure. Our evaluation shows that such a collusive stealing strategy gets close to 4 units of Frechet Inception Distance from a victim model. Our code is readily available to the research community: https://zenodo.org/records/10224340. Simon Queyrut, Valerio Schiavoni, Lydia Y. Chen, Pascal Felber, Robert Birke |
SRDS | 1 |
| 2023 | Mitigating Adversarial Attacks in Federated Learning with Trusted Execution EnvironmentsabstractThe main premise of federated learning (FL) is that machine learning model updates are computed locally to preserve user data privacy. This approach avoids by design user data to ever leave the perimeter of their device. Once the updates aggregated, the model is broadcast to all nodes in the federation. However, without proper defenses, compromised nodes can probe the model inside their local memory in search for adversarial examples, which can lead to dangerous real-world scenarios. For instance, in image-based applications, adversarial examples consist of images slightly perturbed to the human eye getting misclassified by the local model. These adversarial images are then later presented to a victim node's counterpart model to replay the attack. Typical examples harness dissemination strategies such as altered traffic signs (patch attacks) no longer recognized by autonomous vehicles or seemingly unaltered samples that poison the local dataset of the FL scheme to undermine its robustness. PELTA is a novel shielding mechanism leveraging Trusted Execution Environments (TEEs) that reduce the ability of attackers to craft adversarial samples. PELTA masks inside the TEE the first part of the back-propagation chain rule, typically exploited by attackers to craft the malicious samples. We evaluate PELTA on state-of-the-art accurate models using three well-established datasets: CIFAR-10, CIFAR-100 and ImageNet. We show the effectiveness of PELTA in mitigating six white-box state-of-the-art adversarial attacks, such as Projected Gradient Descent, Momentum Iterative Method, Auto Projected Gradient Descent, the Carlini & Wagner attack. In particular, PELTA constitutes the first attempt at defending an ensemble model against the Self-Attention Gradient attack to the best of our knowledge. Our code is available to the research community at https://github.com/queyrusi/Pelta Simon Queyrut, Valerio Schiavoni, Pascal Felber |
ICDCS | 1 |