VLDB 2026 Research / reviewers in the wild / expert
Neda Baghalizadeh-Moghadam
dblp:402/8216
· DBLP profile ↗
6ranked-venue papers
4as first author
6since 2021 · last 2026
—ORCID · unresolved
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Explainable multi-modal unsupervised learning for insider threat detection in enterprise environments
Neda Baghalizadeh-Moghadam, Frédéric Cuppens, Nora Cuppens |
J. Inf. Secur. Appl. | 1 |
| 2025 | Real-Time Anomaly Detection for Event-Based Insider Threat Hunting
Thibault Leblanc, Neda Baghalizadeh-Moghadam, Frédéric Cuppens, Nora Cuppens |
NSS | 2 |
| 2025 | Semantic and Graph-Based Unsupervised Learning for Insider Threat Detection Using User Activity SequencesabstractInsider threats, where legitimate users misuse their access for malicious purposes, remain challenging to detect due to their contextual and behavioral subtleties. This paper presents a novel machine learning framework that captures user activity sequences through a user-centric representation named the User Daily Activity Sentence (UDAS). Unlike prior work that informally uses daily sequences, we formalize UDAS as a behavioral encoding technique using Word2Vec embeddings and extensively evaluate it across multiple unsupervised anomaly detection methods.To enrich this representation with relational context, we propose a graph-based extension that constructs a user interaction graph based on co-device usage and domain access. A Graph Convolutional Network (GCN) is applied to enhance semantic user embeddings, and anomaly detection is performed using Kmeans clustering.To the best of our knowledge, this is the first work to systematically combine semantic sequence embeddings with graph-based relational learning for insider threat detection. Experiments on the CERT Insider Threat v4.2 dataset show that our method outperforms prior unsupervised models in accuracy and robustness. The proposed framework requires no feature engineering or labeled data, making it applicable to real-world monitoring environments. Neda Baghalizadeh-Moghadam, Christopher Neal, Sara Imene Boucetta, Frédéric Cuppens, Nora Cuppens |
PST | 1 |
| 2025 | An NLP-Based Framework Leveraging Email and Multimodal User Data
Neda Baghalizadeh-Moghadam, Frédéric Cuppens, Nora Cuppens |
SECRYPT | 1 |
| 2024 | Classifying Insider Threat Scenarios Through Explainable Articial Intelligence
Rémi Grzeczkowicz, Christopher Neal, Neda Baghalizadeh-Moghadam, Nora Cuppens, Frédéric Cuppens |
CRiSIS | 3 |
| 2024 | NLP and Neural Networks for Insider Threat DetectionabstractInsider threats in cybersecurity are notoriously difficult to detect due to their covert nature, often evading traditional security measures. In this paper, we propose an unsupervised method for insider threat detection, where we leverage advanced Natural Language Processing (NLP) techniques to enhance the detection of abnormal user activities indicative of insider threats. We represent user behaviors in a vector space using Word2Vec, which in turn are analyzed using state-of-the-art NLP models, including BERT, SciBERT, RoBERTa, GPT-2, and LLaMA. These models are integrated with Long Short-Term Memory (LSTM) and Gated Recurrent Unit (GRU) networks to analyze the temporal behavior of user actions. We evaluate the proposed method using the CMU-CERT dataset version 4.2. Our implemented approaches based on NLP achieve better results than previous state-of-the-art approaches that use traditional unsupervised learning. Neda Baghalizadeh-Moghadam, Christopher Neal, Frédéric Cuppens, Nora Cuppens |
TrustCom | 1 |