Julien Francq

dblp:37/5001 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0002-4604-4522ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 2 first-author · 3 since 2021Security and privacy · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Modular HRL Agent for Automated Pentesting with Specialized Policies: A Maritime use case
abstract
The increasing convergence of IT and OT in maritime infrastructure has amplified the cyber-physical threat landscape, exposing vessels to sophisticated, multi-stage attacks. Given the scarcity of specialized experts and the prohibitive cost of manual assessments, proactive automated penetration testing has become a critical necessity. However, Deep Reinforcement Learning (DRL) solutions struggle with the combinatorial explosion of state-action spaces and the inability of monolithic models to generalize across hybrid domains without catastrophic forgetting.
Marc-Antoine Faillon, Julien Francq, Nora Cuppens, Frédéric Cuppens, Reda Yaich
CODASPY2
2025 A survey on versatile embedded Machine Learning hardware acceleration
Pierre Garreau, Pascal Cotret, Julien Francq, Jean-Christophe Cexus, Loïc Lagadec
J. Syst. Archit.3
2024 SECL: A Zero-Day Attack Detector and Classifier based on Contrastive Learning and Strong Regularization
abstract
Intrusion Detection Systems (IDSs) always had difficulties in detecting Zero-Day Attacks (ZDAs). One of the advantages of Machine Learning (ML)-based IDSs, which is their superiority in detecting ZDAs, remains largely unexplored, especially when considering multiple ZDAs. This is mainly due to the fact that ML-based IDSs are mainly using supervised ML methods. Although they exhibit better performance in detecting known attacks, they are by design unable to detect unknown attacks because they are limited to detecting the classes present in the dataset they were trained on. This paper introduces SECL, a method that combines Contrastive Learning (CL) and a new regularization method composed of dropout, Von Neumann Entropy (VNE) and Sepmix (a regularization inspired from mixup). SECL is close to, or even better than supervised ML methods in detecting known attacks, while gaining the ability to detect and differentiate multiple ZDAs. Experiments were performed on three datasets, UNSW-NB15, CIC-IDS2017 and WADI, effectively showing that this method is able to detect multiple ZDAs while achieving performance similar to supervised methods on known attacks. Notably, the proposed method even has an overall better performance than a supervised method knowing all attacks on the WADI dataset. These results pave the way for better detection of ZDAs, without reduction of performance on known attacks.
Robin Duraz, David Espes, Julien Francq, Sandrine Vaton
ARES3
2024 How to Better Fit Reinforcement Learning for Pentesting: A New Hierarchical Approach
Marc-Antoine Faillon, Baptiste Bout, Julien Francq, Christopher Neal, Nora Cuppens, Frédéric Cuppens, Reda Yaich
ESORICS (4)3
2024 Behavior-Based Intrusion Detection Approach Deployed on a Naval Testbed
abstract
This paper presents an application of an intrusion detection approach onto a naval physical testbed. The deployed approach is tailored for complex Industrial Control Systems (ICSs). Such systems play a critical role in managing complex industrial processes and ensuring their security against cyber threats is a major concern. Our work concerns Process-Aware Attacks (PAAs) which are sophisticated attacks aiming at disrupting ICS physical processes. The methodology instantiates a specification-based and process-aware Network Intrusion Detection System (NIDS). The specifications are systematically extracted from international and industry standards. In order to be monitored, such specifications are translated into security requirements which are verified during the execution of the system. Our IDS relies on network traffic capture on fieldbuses as well as Ethernet networks. In addition to our previous work, deploying our approach on a realistic naval testbed allows us to demonstrate its extensibility to different environments. Furthermore, the evaluation of our approach shows both its good detection capabilities and scalability.
Estelle Hotellier, Nahi Boukhobza, Franck Sicard, Julien Francq, Stéphane Mocanu
ETFA4
2024 Standard specification-based intrusion detection for hierarchical industrial control systems
Estelle Hotellier, Franck Sicard, Julien Francq, Stéphane Mocanu
Inf. Sci.3
2022 Non-Triangular Self-Synchronizing Stream Ciphers
abstract
In this article, we propose an instantiation, called${\sf Stanislas}$, of a dedicated Self-Synchronizing Stream Cipher (SSSC) involving an automaton with finite input memory using non-triangular state transition functions. Previous existing SSSC are based on automata with shifts or triangular functions ($T$–functions) as state transition functions. Our algorithm${\sf Stanislas}$admits a matrix representation deduced from a general and systematic methodology called Linear Parameter Varying (LPV). This particular representation comes from the automatic theory and from a special property of dynamical systems called flatness. Hardware implementations and comparisons with some state-of-the-art stream ciphers on Xilinx FPGAs are presented. It turns out that${\sf Stanislas}$provides bigger throughput than the considered stream ciphers (synchronous and self-synchronizing) when straightforward implementations are considered. Moreover, its synchronization delay is much smaller than the SSSC Moustique (40 clock cycles instead of 105) and the standard approach CFB1-AES128 (40 clock cycles instead of 128).
Julien Francq, Loïc Besson, Paul Huynh, Philippe Guillot, Gilles Millerioux, Marine Minier
IEEE Trans. Computers1
2016 Extended Generalized Feistel Networks Using Matrix Representation to Propose a New Lightweight Block Cipher: Lilliput
abstract
While Generalized Feistel Networks (GFNs) have been widely studied in the literature as a building block of a block cipher, we recall in this paper the results of [1] where a unified vision to easily represent them through a matrix representation is proposed. We also introduce a new class of such schemes called Extended Generalized Feistel Networks well suited for cryptographic applications. We instantiate this particular construction into a lightweight block cipher called Lilliput analyzing its security and its hardware performances.
Thierry P. Berger, Julien Francq, Marine Minier, Gaël Thomas 0002
IEEE Trans. Computers2
2015 Introduction to hardware trojan detection methods
Julien Francq, Florian Frick
DATE1
2008 Error Detection for Borrow-Save Adders Dedicated to ECC Unit
abstract
Differential Fault Analysis (DFA) is a real threat for elliptic curve cryptosystems. This paper describes an elliptic curve cryptoprocessor unit resistant against fault injection. This resistance is provided by the use of parity preserving logic gates in the operating structure of the ECC unit, which is based on borrow-save adders. The proposed countermeasure provides a high coverage fault detection and induces an acceptable area overhead (+ 38 %).
Julien Francq, Jean-Baptiste Rigaud, Pascal Manet, Assia Tria, Arnaud Tisserand
FDTC1