VLDB 2026 Research / reviewers in the wild / expert
Chamseddine Talhi
dblp:63/6619
· DBLP profile ↗
46ranked-venue papers
2as first author
20since 2021 · last 2025
0000-0003-2264-8265ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 15 · 12 since 2021Security and privacy · 8 · 1 first-authorSoftware engineering, systems software and programming languages · 5 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 2 · 2 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Privacy-Preserving Continuous User Authentication Using Federated LearningabstractIn today’s increasingly digital landscape, continuous user authentication on smartphones has become crucial for safeguarding sensitive information. Behavioral biometrics, particularly facial recognition, is emerging as a powerful tool to enhance security, leveraging advanced machine learning and deep learning models. However, traditional approaches often involve sharing personal data for training, raising significant privacy concerns. Federated Learning (FL) addresses this issue by enabling decentralized model training directly on users’ devices, thus preserving privacy. Despite its promise, FL faces unique challenges in continuous user authentication, particularly due to the non-IID (non-Independent and Identically Distributed) nature of the data where every client has access only to one label data samples. While Convolutional Neural Networks (CNNs) are commonly employed in facial recognition, they struggle with the complexities of localized features and data distribution variance. This article explores all the possible architectures in order to tackle the CNNs weaknesses, we leverage the Vision Transformers (ViTs) and MLP-Mixers as a promising alternative to CNNs in the context of facial recognition. ViTs and MLP-Mixers excel in capturing global context and hierarchical representations, making them better suited to handle the complexities of continuous user authentication in FL. Through a case study, we demonstrate how integrating ViTs and MLP-Mixers into FL frameworks for facial recognition can enhance prediction accuracy and reduce weight divergence, offering a more robust and secure solution compared to other models. Oussama Bouldjedri, Mohamad Wazzeh, Hani Sami, Chamseddine Talhi, Hakima Ould-Slimane |
IWCMC | 4 |
| 2025 | Multi-Agent Deep Reinforcement Learning for Resource Management in On-Demand Environments
Mario Chahoud, Hani Sami, Rabeb Mizouni, Hadi Otrok, Jamal Bentahar, Azzam Mourad, Chamseddine Talhi |
IWCMC | 7 |
| 2025 | Dynamic Split Federated Learning for resource-constrained IoT systems
Mohamad Wazzeh, Ahmad Hammoud, Azzam Mourad, Hadi Otrok, Chamseddine Talhi, Zbigniew Dziong, Chang-Dong Wang 0001, Mohsen Guizani |
Comput. Commun. | 5 |
| 2025 | Reward shaping in DRL: A novel framework for adaptive resource management in dynamic environmentsabstractIn edge computing environments, efficient computation resource management is crucial for optimizing service allocation to hosts in the form of containers. These environments experience dynamic user demands and high mobility, making traditional static and heuristic-based methods inadequate for handling such complexity and variability. Deep Reinforcement Learning (DRL) offers a more adaptable solution, capable of responding to these dynamic conditions. However, existing DRL methods face challenges such as high reward variability, slow convergence, and difficulties in incorporating user mobility and rapidly changing environmental configurations. To overcome these challenges, we propose a novel DRL framework for computation resource optimization at the edge layer. This framework leverages a customized Markov Decision Process (MDP) and Proximal Policy Optimization (PPO), integrating a Graph Convolutional Transformer (GCT). By combining Graph Convolutional Networks (GCN) with Transformer encoders, the GCT introduces a spatio-temporal reward-shaping mechanism that enhances the agent's ability to select hosts and assign services efficiently in real time while minimizing the overload. Our approach significantly enhances the speed and accuracy of resource allocation, achieving, on average across two datasets, a 30% reduction in convergence time, a 25% increase in total accumulated rewards, and a 35% improvement in service allocation efficiency compared to standard DRL methods and existing reward-shaping techniques. Our method was validated using two real-world datasets, MOBILE DATA CHALLENGE (MDC) and Shanghai Telecom, and was compared against standard DRL models, reward-shaping baselines, and heuristic methods. • Proposing a DRL framework that integrates reward shaping for resource management. • Introducing a novel MDP design that considers the dynamic nature of the users. • Presenting a novel reward shaping mechanism, incorporating GCN and transformers. Mario Chahoud, Hani Sami, Rabeb Mizouni, Jamal Bentahar, Azzam Mourad, Hadi Otrok, Chamseddine Talhi |
Inf. Sci. | 7 |
| 2025 | Efficient privacy-preserving ML for IoT: Cluster-based split federated learning scheme for non-IID data
Mohamad Arafeh, Mohamad Wazzeh, Hani Sami, Hakima Ould-Slimane, Chamseddine Talhi, Azzam Mourad, Hadi Otrok |
J. Netw. Comput. Appl. | 5 |
| 2024 | FL-EGM: Decentralized Federated Learning using Aggregator Selection with Enhanced Global ModelabstractFederated Learning (FL) has emerged as a promising solution to address data privacy concerns, but it also faces ob-stacles, including biased centralized aggregation. In this paper, we propose a novel decentralized FL architecture with round-based aggregator selection that enhances the accuracy of the global model while preserving data privacy for the users. Our proposed model consists of three distinct phases. Firstly, we address the issue of a central aggregator by introducing a model where we periodically select the aggregator as the best-performing client from participant nodes. Secondly, we train all clients using their respective data but excluding the client selected as an aggregator. In the third phase, we further refine the global model by training it on the raw data of the selected aggregator, leading to an enhanced global model. These three modules empower the proposed model to offer improved accuracy and decentralization. Our implementation yielded promising results, demonstrating that the proposed mode achieves an accuracy of 98.54 % along with enhanced decentralization. The proposed model has also validated different datasets and network conditions, such as the number of participant nodes. Furthermore, the performance of the proposed model is validated in the presence of a biased aggregator. The results demonstrate that the proposed model achieves 98.43 % accuracy and shows more robustness in the presence of a biased aggregator. Finally, the proposed model converges fast compared to other baseline models. Muhammad KaleemUllah Khan, Kaiwen Zhang 0001, Chamseddine Talhi |
ICMLA | 3 |
| 2024 | Utility-Preserving Face Anonymization via Differentially Private Feature OperationsabstractFacial images play a crucial role in many web and security applications, but their uses come with notable privacy risks. Despite the availability of various face anonymization algorithms, they often fail to withstand advanced attacks while struggling to maintain utility for subsequent applications. We present two novel face anonymization algorithms that utilize feature operations to overcome these limitations. The first algorithm utilizes perturbation and matching of high-level features, whereas the second algorithm enhances this approach by also incorporating perturbation of low-level features along with regularization. These algorithms significantly enhance the utility of anonymized images while ensuring differential privacy. Additionally, we introduce a task-based benchmark to enable fair and comprehensive evaluations of privacy and utility across different algorithms. Through experiments, we demonstrate that our algorithms outperform others in preserving the utility of anonymized facial images in classification tasks while effectively protecting against a wide range of attacks. Chengqi Li, Sarah Simionescu, Sanzheng Qiao, Nadjia Kara, Chamseddine Talhi |
INFOCOM | 6 |
| 2024 | Resource-Aware Split Federated Learning for Fall Detection in the MetaverseabstractAs the Metaverse develops, it is becoming more crucial to prioritize the safety of users, especially regarding the potential risks, such as users experiencing dizziness or making incorrect movements that may lead to falls. With more virtual environments becoming increasingly available and immersive, detecting and preventing falls within the Metaverse is required. Given the constrained resources of wearable sensors, precise fall prediction models are critical to efficiently analyzing data gathered by these devices. Traditional fall detection systems require centralizing data collection, which raises privacy concerns over the collected data. Resource-aware Split Federated Learning (RSFL) enables collaboration among multiple devices within the Metaverse to train a fall detection model, all while preserving individual data privacy. The approach also leverages parallelism in Federated Learning (FL) and Split Learning (SL) by decomposing training tasks between clients and servers. Moreover, we devise an efficient client selection mechanism to ensure timely training and model convergence performance. We implemented our architecture and assessed its performance using a sensory dataset. The evaluation results with the baseline demonstrate our architecture's superiority in terms of convergence time. Our approach mitigates data heterogeneity and privacy concerns, creating secure and efficient fall detection systems for the Metaverse. Mohamad Wazzeh, Ahmad Hammoud, Mohsen Guizani, Azzam Mourad, Hadi Otrok, Chamseddine Talhi, Zbigniew Dziong, Chang-Dong Wang 0001 |
WiMob | 6 |
| 2024 | CRSFL: Cluster-based Resource-aware Split Federated Learning for Continuous Authentication
Mohamad Wazzeh, Mohamad Arafeh, Hani Sami, Hakima Ould-Slimane, Chamseddine Talhi, Azzam Mourad, Hadi Otrok |
J. Netw. Comput. Appl. | 5 |
| 2023 | Federated Learning-Based Jamming Detection for Tactical Terrestrial and Non-Terrestrial NetworksabstractIn this paper, we propose federated learning (FL)-based jamming detection algorithms for a stochastic, distributed, tactical terrestrial and non-terrestrial (SDT-TNT) network. Specifically, we consider an SDT-TNT network with multiple clusters, in which multiple unknown jammers might be present. Moreover, we employ the spectral correlation function (SCF) on local servers to estimate the cyclostationary properties of the received waveforms. We then use the SCF to train local convolutional autoencoders (CAEs). In the inference phase, we jointly use the latent representation of the trained CAE and the kernel density estimation (KDE) to detect the existence of jammers. Our proposed methods show very promising results in jamming detection and outperform non-FL approaches. We further demonstrate that using the SCF feature provides higher accuracy than using In-phase/Quadrature-phase (I/Q) features. Aida Meftah, Georges Kaddoum, Tri Nhu Do, Chamseddine Talhi |
GLOBECOM | 4 |
| 2023 | Adaptive Upgrade of Client Resources for Improving the Quality of Federated Learning ModelabstractConventional systems are usually constrained to store data in a centralized location. This restriction has either precluded sensitive data from being shared or put its privacy on the line. Alternatively, federated learning (FL) has emerged as a promising privacy-preserving paradigm for exchanging model parameters instead of private data of Internet of Things (IoT) devices known as clients. FL trains a global model by communicating local models generated by selected clients throughout many communication rounds until ensuring high learning performance. In these settings, the FL performance highly depends on selecting the best available clients. This process is strongly related to the quality of their models and their training data. Such selection-based schemes have not been explored yet, particularly regarding participating clients having high-quality data yet with limited resources. To address these challenges, we propose in this article FedAUR, a novel approach for an adaptive upgrade of clients resources in FL. We first introduce a method to measure how a locally generated model affects and improves the global model if selected for aggregation without revealing raw data. Next, based on the significance of each client parameters and the resources of their devices, we design a selection scheme that manages and distributes available resources on the server among the appropriate subset of clients. This client selection and resource allocation problem is thus formulated as an optimization problem, where the purpose is to discover and train in each round the maximum number of samples with the highest quality in order to target the desired performance. Moreover, we present a Kubernetes-based prototype that we implemented to evaluate the performance of the proposed approach. Sawsan Abdul Rahman, Hakima Ould-Slimane, Rasel Chowdhury, Azzam Mourad, Chamseddine Talhi, Mohsen Guizani |
IEEE Internet Things J. | 5 |
| 2023 | Data independent warmup scheme for non-IID federated learning
Mohamad Arafeh, Hakima Ould-Slimane, Hadi Otrok, Azzam Mourad, Chamseddine Talhi, Ernesto Damiani |
Inf. Sci. | 5 |
| 2023 | Federated Learning-Enabled Jamming Detection and Waveform Classification for Distributed Tactical Wireless NetworksabstractIn this paper, we propose a federated learning (FL)-based jammer detection and waveform classification algorithm for distributed tactical wireless networks (TWNs). More specifically, we consider a distributed TWN with multiple clusters and various types of waveforms used in the presence of a mobile jammer. We analyze the frequency domain of the waveforms received on local servers to extract the unique cyclic frequency from each waveform’s spectral correlation function (SCF). The method is used to detect the peak values in the frequency-cyclic frequency plane. The primary signal’s SCF exhibits peaks at the unique cyclic frequency and the zero cyclic frequency. These features are then used to train local convolutional neural networks (CNNs) to detect the jamming attacks and classify the waveforms. Moreover, a practical distributed TWN is considered in which each cluster head has a partial observation of the TWN with insufficient data samples, and the proposed algorithm exploits the distributed learning feature of FL, i.e., global learning aggregation to detect the existence of jammers and distinguish the types of waveforms received throughout the TWN. We implement a rigorous TWN simulation using MATLAB toolboxes and our proposed algorithm in TensorFlow Federated. The numerical results show that our proposed algorithm outperforms the standalone local SCF-CNN algorithm. We further demonstrate that the SCF feature yields more accuracy than the In-phase and Quadrature features. Aida Meftah, Tri Nhu Do, Georges Kaddoum, Chamseddine Talhi |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | Guest Editorial: Special Section on the Latest Developments in Federated Learning for the Management of Networked Systems and ResourcesabstractDriven by privacy concerns and the promise of Deep Learning, researchers have devoted significant effort to exploring the applicability of Machine Learning (ML). In the domains of communication, network, and service management, ML-based decision-making solutions are eagerly sought to replace traditional model-driven approaches, addressing the growing complexity and heterogeneity of modern systems. In this context, Federated Learning (FL) has gained increasing interest as a decentralized approach that overcomes the limitations of centralized systems for data analysis. Azzam Mourad, Hadi Otrok, Ernesto Damiani, Mérouane Debbah, Nadra Guizani, Guangjie Han, Rabeb Mizouni, Jamal Bentahar, Chamseddine Talhi |
IEEE Trans. Netw. Serv. Manag. | 10 |
| 2022 | Independent and Identically Distributed (IID) Data Assessment in Federated LearningabstractFederated learning extends the centralized machine learning architecture by enabling data privacy for its providers. The distributed structure of the emerged federated architecture imposes a problem of the data being not independent and identically distributed (non-IID), which drastically affects the performance of the learning process. While the majority of the recent works in the federated learning domain have accepted this limitation, only a few scholars addressed the non-IID problem straightforwardly. Nevertheless, these works lack the fundamental analysis of the data’ IIDness, and/or contradict the privacy feature of the federated learning paradigm. In this paper, we focus on evaluating the harmony of the participants by studying their data distribution and calculating their level of compatibility. The devised tool, in this work, is an assessment technique integrated within the federated learning framework to analyze the data distribution among the trainers. Our proposed method is proven by experimenting with several scenarios, and results show that our utility can fairly assess the selected participants before initiating the learning process. Mohamad Arafeh, Ahmad Hammoud, Hadi Otrok, Azzam Mourad, Chamseddine Talhi, Zbigniew Dziong |
GLOBECOM | 5 |
| 2022 | Multi-Tenant Intrusion Detection Framework as a Service for SaaSabstractInformation technology (IT) service providers are nowadays moving toward cloud computing. Software-as-a-service (SaaS) refers to cloud service-oriented web applications. As a result of computation outsourcing, a customer (tenant) can subscribe to a self-service SaaS and use it on a pay-per-use basis. To reduce resource costs, a single instance of SaaS serves multiple tenants (multi-tenancy). However, outsourcing and multi-tenancy bring about new security issues. Indeed, tenants lose control over the source code, databases and infrastructure and cannot deploy their own intrusion detection system (IDS). In this context, the provider must not only integrate their preferred IDS into a public cloud, but also protect the tenants according to their individual security requirements. We put forth a multi-tenant intrusion detection framework as a service for SaaS (MTIDaaS) to allow the provider to undertake such integration. Our MTIDaaS has been integrated and tested in a real public cloud environment. It provides security-as-a-service (SecaaS) for both provider and tenant with high levels of portability, flexibility and cost-effectiveness. The experimental results demonstrate that our MTIDaaS offers easy integration of IDS with little virtualization overhead and insignificant impact on HTTP response time. Mohamed Yassin, Hakima Ould-Slimane, Chamseddine Talhi, Hanifa Boucheneb |
IEEE Trans. Serv. Comput. | 3 |
| 2021 | Federated Learning for Anomaly-Based Intrusion DetectionabstractWe are attending a severe zero-day cyber attacks. Machine learning based anomaly detection is definitely the most efficient defence in depth approach. It consists to analyzing the network traffic in order to distinguish the normal behaviour from the abnormal one. This approach is usually implemented in a central server where all the network traffic is analyzed which can rise privacy issues. In fact, with the increasing adoption of Cloud infrastructures, it is important to reduce as much as possible the outsourcing of such sensitive information to the several network nodes. A better approach is to ask each node to analyze its own data and then to exchange its learning finding (model) with a coordinator. In this paper, we investigate the application of federated learning for network-based intrusion detection. Our experiment was conducted based on the C ICIDS2017 dataset. We present a f ederated learning on a deep learning algorithm C NN based on model averaging. It is a self-learning system for detecting anomalies caused by malicious adversaries without human intervention and can cope with new and unknown attacks without decreasing performance. These experimentation demonstrate that this approach is effective in detecting intrusion. Mohamed Ali Ayed, Chamseddine Talhi |
ISNCC | 2 |
| 2021 | FedMCCS: Multicriteria Client Selection Model for Optimal IoT Federated LearningabstractAs an alternative centralized systems, which may prevent data to be stored in a central repository due to its privacy and/or abundance, federated learning (FL) is nowadays a game changer addressing both privacy and cooperative learning. It succeeds in keeping training data on the devices, while sharing locally computed then globally aggregated models throughout several communication rounds. The selection of clients participating in FL process is currently at complete/quasi randomness. However, the heterogeneity of the client devices within Internet-of-Things environment and their limited communication and computation resources might fail to complete the training task, which may lead to many discarded learning rounds affecting the model accuracy. In this article, we propose FedMCCS, a multicriteria-based approach for client selection in FL. All of the CPU, memory, energy, and time are considered for the clients resources to predict whether they are able to perform the FL task. Particularly, in each round, the number of clients in FedMCCS is maximized to the utmost, while considering each client resources and its capability to successfully train and send the needed updates. The conducted experiments show that FedMCCS outperforms the other approaches by: 1) reducing the number of communication rounds to reach the intended accuracy; 2) maximizing the number of clients; 3) handling the least number of discarded rounds; and 4) optimizing the network traffic. Sawsan Abdul Rahman, Hanine Tout, Azzam Mourad, Chamseddine Talhi |
IEEE Internet Things J. | 4 |
| 2021 | A Survey on Federated Learning: The Journey From Centralized to Distributed On-Site Learning and BeyondabstractDriven by privacy concerns and the visions of deep learning, the last four years have witnessed a paradigm shift in the applicability mechanism of machine learning (ML). An emerging model, called federated learning (FL), is rising above both centralized systems and on-site analysis, to be a new fashioned design for ML implementation. It is a privacy-preserving decentralized approach, which keeps raw data on devices and involves local ML training while eliminating data communication overhead. A federation of the learned and shared models is then performed on a central server to aggregate and share the built knowledge among participants. This article starts by examining and comparing different ML-based deployment architectures, followed by in-depth and in-breadth investigation on FL. Compared to the existing reviews in the field, we provide in this survey a new classification of FL topics and research fields based on thorough analysis of the main technical challenges and current related work. In this context, we elaborate comprehensive taxonomies covering various challenging aspects, contributions, and trends in the literature, including core system models and designs, application areas, privacy and security, and resource management. Furthermore, we discuss important challenges and open research directions toward more robust FL systems. Sawsan Abdul Rahman, Hanine Tout, Hakima Ould-Slimane, Azzam Mourad, Chamseddine Talhi, Mohsen Guizani |
IEEE Internet Things J. | 5 |
| 2021 | Multi-Persona Mobility: Joint Cost-Effective and Resource-Aware Mobile-Edge Computation OffloadingabstractMulti-persona mobile computing has begun to make its way to determine the battle about practical strategy for adopting personal devices in workplace. Though its competency, multi-persona performance and viability are critically threatened by the limited resources of mobile devices. In recent years, mobile edge computing (MEC) has risen as promising paradigm within the internet of things era bringing benefits to the proximity of mobile terminals, leveraging intelligent computations offloading services to address the severity of their resource scarcity. Yet, embracing mobile edge-based services to augment personas resources and performance raises new concerns including determining what computations to offload for serving the highest number of mobile devices and reducing the remote execution fees imposed on the institution. In this context, we propose new cost-effective MEC-based solution to address these issues. We develop two-level multi-objective optimization realized through an intelligent offloading decision model able to settle both concerns, by minimizing processing, memory and energy while augmenting virtual mobile instances performance on a wide range of physical devices with minimal offloading service fees. We also propose a redesigned smart genetic-based method able to accelerate and reduce the overhead of offloading decision evaluation. Extensive analysis is performed and the results show that our proposition can get more quickly the offloading strategy than other schemes. The results also demonstrate the ability to enforce the virtual mobile devices by reducing local processing, memory usage, energy consumption and execution time along with acceptable minimal additional fees compared to other techniques. Hanine Tout, Azzam Mourad, Nadjia Kara, Chamseddine Talhi |
IEEE/ACM Trans. Netw. | 4 |
| 2020 | A Framework for Automated Monitoring and Orchestration of Cloud-Native applicationsabstractIn the age of cloud-native implementation both monitoring and automated orchestration plays an important role for managing these applications' life cycle. There are lot of available monitoring tools which are able to monitor these implementations but they lack the application related metrics and also the automated orchestration is still at a premature stage. In this article we are proposing a framework that takes application related metrics along with the absolute and relative metrics and pro-actively performs automated orchestration using machine learning for scalability. Rasel Chowdhury, Chamseddine Talhi, Hakima Ould-Slimane, Azzam Mourad |
ISNCC | 2 |
| 2020 | P-Code Based Classification to Detect Malicious VBA MacroabstractVBA macro malware has seen a resurgence of use in recent years by malicious actors as a vector to perpetrate cyber attacks. Anti-virus and analysis tools use heuristics of the VBA source code in an effort to detect such attacks. Although efficient, anti-virus and analysis tools are not able to detect macro malware based on VBA opcode (p-code). This gap requires further research in using p-code for macro malware detection. In this paper, we discuss the extraction of p-code within macro based documents and present the classification of benign and malicious p-code using five learning classifiers. Our method selects 12 specific p-code features and use them to train the classifiers. Our approach obtained a high accuracy (98.8%) and is promising for macro malware detection in real-world applications. We have discussed the challenges our approach could face and their potential solutions. To promote future studies in this field, we have made our dataset available to the community. Simon Huneault-LeBlanc, Chamseddine Talhi |
ISNCC | 2 |
| 2020 | LCA-ABE: Lightweight Context-Aware Encryption for Android ApplicationsabstractThe evolving of context-aware applications are becoming more readily available as a major driver of the growth of future connected smart, autonomous environments. However, with the increasing of security risks in critical shared massive data capabilities and the increasing regulation requirements on privacy, there is a significant need for new paradigms to manage security and privacy compliances. These challenges call for context-aware and fine-grained security policies to be enforced in such dynamic environments in order to achieve efficient real-time authorization between applications and connected devices. We propose in this work a novel solution that aims to provide context-aware security model for Android applications. Specifically, our proposition provides automated context-aware access control model and leverages Attribute-Based Encryption (ABE) to secure data communications. Thorough experiments have been performed and the evaluation results demonstrate that the proposed solution provides an effective lightweight adaptable context-aware encryption model. Saad Inshi, Rasel Chowdhury, Mahdi Elarbi, Hakima Ould-Slimane, Chamseddine Talhi |
ISNCC | 5 |
| 2019 | ITADP: An inter-tenant attack detection and prevention framework for multi-tenant SaaS
Mohamed Yassin, Chamseddine Talhi, Hanifa Boucheneb |
J. Inf. Secur. Appl. | 2 |
| 2019 | Selective Mobile Cloud Offloading to Augment Multi-Persona Performance and ViabilityabstractFueled by changes in professional application models, personal interests and desires and technological advances in mobile devices, multi-persona has emerged recently to keep balance between different aspects, in our daily life, on a single mobile terminal. In this context, mobile virtualization technology has turned the corner and currently heading towards widespread adoption to realize multi-persona. Although recent lightweight virtualization techniques were able to maintain balance between security and scalability of personas, the limited CPU power and insufficient memory and battery capacities, still threaten personas performance and viability. Throughout the last few years, cloud computing has cultivated and refined the concept of outsourcing computing resources, and nowadays, in the coming age of smartphones and tablets, the prerequisites are met for importing cloud computing to support resource constrained mobiles. From these premises, we propose in this paper a novel offloading-based approach that based on global resource usage monitoring, generic and adaptable problem formulation and heuristic decision making, is capable of augmenting personas performance and viability on mobile terminals. The experiments show its capability of reducing the resource usage overhead and energy consumption of the applications running in each persona, accelerating their execution and improving their scalability, allowing better adoption of multi-persona solution. Hanine Tout, Chamseddine Talhi, Nadjia Kara, Azzam Mourad |
IEEE Trans. Cloud Comput. | 2 |
| 2019 | A Novel Ad-Hoc Mobile Edge Cloud Offering Security Services Through Intelligent Resource-Aware OffloadingabstractWhile the usage of smart devices is increasing, security attacks and malware affecting such terminals are briskly evolving as well. Mobile security suites exist to defend devices against malware and other intrusions. However, they require extensive resources not continuously available on mobile terminals, hence affecting their relevance, efficiency and sustainability. In this paper, we address the aforementioned problem while taking into account the devices limited resources such as energy and CPU usage as well as the mobile connectivity and latency. In this context, we propose an ad-hoc mobile edge cloud that takes advantage of Wi-Fi Direct as means of achieving connectivity, sharing resources, and integrating security services among nearby mobile devices. The proposed scheme embeds a multi-objective resource-aware optimization model and genetic-based solution that provide smart offloading decision based on dynamic profiling of contextual and statistical data from the ad-hoc mobile edge cloud devices. The carried experiments illustrate the relevance and efficiency of exchanging security services while maintaining their sustainability with or without the availability of Internet connection. Moreover, the results provide optimal offloading decision and distribution of security services while significantly reducing energy consumption, execution time, and number of selected computational nodes without sacrificing security. Toufic Dbouk, Azzam Mourad, Hadi Otrok, Hanine Tout, Chamseddine Talhi |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2018 | Combining heterogeneous anomaly detectors for improved software security
Wael Khreich, Syed Shariyar Murtaza, Abdelwahab Hamou-Lhadj, Chamseddine Talhi |
J. Syst. Softw. | 4 |
| 2018 | Multi-tenant intrusion detection system for public cloud (MTIDS)
Mohamed Hawedi, Chamseddine Talhi, Hanifa Boucheneb |
J. Supercomput. | 2 |
| 2017 | SQLIIDaaS: A SQL Injection Intrusion Detection Framework as a Service for SaaS ProvidersabstractRecently, we are attending to the proliferation of Cloud Computing (CC) as the new trending internet-based-Platform. Thanks to the outsourcing paradigm, CC is enabling many services. Software as a Service (SaaS) is one of those cloud-based-services. Indeed, SaaS model allows providers to reduce the cost of maintenance and management by transferring traditional on premise deployment to public Cloud. Clients can subscribe, in self-service, to SaaS services based on a pay-per-use model. However, since user data are outsourced to the Cloud, serious security breaches are rising and could harm the reputation of providers and slow down the subscription of clients. SQL injection attack (SQLIA) is one of the most critical SaaS vulnerabilities that allows attackers to violate the availability, confidentiality and integrity of user data. In this paper, we propose SQL injection intrusion detection framework as a service for SaaS providers, SQLIIDaaS, which allows a SaaS provider to detect SQLIAs targeting several SaaS applications without reading, analyzing or modifying the source code. To achieve SQL query/HTTP request mapping, we propose an event correlation based on the similarity between literals in SQL queries and parameters in HTTP requests. SQLIIDaaS is integrated and validated in Amazon Web Services (AWS). A SaaS provider can subscribe to this framework and launch its own set of virtual machines, which holds on-demand self-service, resource pooling, rapid elasticity, and measured service properties. Mohamed Yassin, Hakima Ould-Slimane, Chamseddine Talhi, Hanifa Boucheneb |
CSCloud | 3 |
| 2017 | Attribute-Based Encryption for Preserving Smart Home Data Privacy
Rasel Chowdhury, Hakima Ould-Slimane, Chamseddine Talhi, Mohamed Cheriet |
ICOST | 3 |
| 2017 | Smart mobile computation offloading: Centralized selective and multi-objective approach
Hanine Tout, Chamseddine Talhi, Nadjia Kara, Azzam Mourad |
Expert Syst. Appl. | 2 |
| 2017 | An anomaly detection system based on variable N-gram features and one-class SVM
Wael Khreich, Babak Khosravifar, Abdelwahab Hamou-Lhadj, Chamseddine Talhi |
Inf. Softw. Technol. | 4 |
| 2016 | Towards ad-hoc cloud based approach for mobile intrusion detectionabstractAs the usage of smart devices is increasing, malware affecting such devices is rapidly evolving as well. Security risks affecting the confidentiality, integrity, and privacy of smart devices are rapidly emerging. Mobile security suites exist to defend the device against malware and other intrusions. However, they require extensive resources which is a constraint of the device itself. In this paper, we address the problem of intrusion detection for smart devices taking into account the devices' limited resources such as energy, CPU usage, and internet connectivity. We provide an ad-hoc mobile cloud based intrusion detection framework that takes advantage of Wi-Fi Direct as means of achieving connectivity and sharing resources and services for providing security. The proposed framework allows exchange of data with or without the availability of internet connection. The paper also provides experiments, carried out using real devices, showing various improvements of using our approach. Up to 61% and 40% enhancement in energy consumption and response time respectively is reached compared to local execution. Toufic Dbouk, Azzam Mourad, Hadi Otrok, Chamseddine Talhi |
WiMob | 4 |
| 2016 | Generative versus discriminative classifiers for android anomaly-based detection system using system calls filtering and abstraction processabstractAnomaly-based detection techniques have been widely studied in recent years. Most of these efforts have focused to improve the accuracy of these techniques. The poor accuracy performance is caused by two factors: i the data used for the analysis is insufficient and/or unrepresentative of the application behavior, or ii inappropriate algorithms are used to model the behavior of the application. In this paper, we attempt to improve anomaly-based detection techniques by examining these two factors. First, we use system call filtering and abstraction process. This process refines the system call traces. The refined traces are compact and should be more representative of the application main behavior. Second, we use machine learning classifiers to characterize the benign behavior. Generally, there are two main categories of machine learning classifiers: generative classifiers and discriminative classifiers. In their initial training phases, the classifiers build models characterizing the benign behavior. Later on, these models are used to distinguish between different classes of data. They are simply defined by their parameters. The k-means classifier is considered as a representative of the generative classifier category, and the support vector machine classifier as a representative of the discriminative classifier category. The efficiency of these classifiers are reviewed and compared, as well as the impact of the filtering and abstraction process on their performances is evaluated. The experimental results show that the support vector machine model outperforms the k-means model, and the filtering and abstraction process has positive impacts on the performance of both models. Copyright © 2016 John Wiley & Sons, Ltd. Abdelfattah Amamra, Jean-Marc Robert 0001, Andrien Abraham, Chamseddine Talhi |
Secur. Commun. Networks | 4 |
| 2015 | Towards an offloading approach that augments multi-persona performance and viabilityabstractMobile virtualization is a key technology that is witnessing widespread adoption to realize multi-persona functionality capable of accommodating work, personal, and mobility needs on a single mobile terminal. Yet, unlike virtualization on servers and desktop machines, mobile virtualization is more challenging due to the limited resources on mobiles platforms in terms of CPU, memory and battery. The evolution of mobile virtualization ranged from heavy to more lightweight techniques capable of running virtual environments on mobile devices with lower overhead. Even though the latest proposed lightweight approaches were able to realize multi-persona, yet none of them is capable of efficiently managing personas performance or ensuring their viability. In parallel, to address the resource limitations of mobile platforms, many researchers have proposed offloading techniques to migrate computation intensive components out of the mobile device to be executed on resourceful mobile cloud computing infrastructure. Motivated by their promising results, we propose in this paper the integration of offloading in the virtual environments on the mobile device toward augmenting personas performance and ensuring their viability. Our experiments show very promising results in this regard. Hanine Tout, Chamseddine Talhi, Nadjia Kara, Azzam Mourad |
CCNC | 2 |
| 2015 | Towards flexible, scalable and autonomic virtual tenant slicesabstractMulti-tenant flexible, scalable and autonomic virtual networks isolation has long been a goal of the network research and industrial community. For today's Software-Defined Networking (SDN) platforms, providing cloud tenants requirements for scalability, elasticity, and transparency is far from straightforward. SDN programmers typically enforce strict and inflexible traffic isolation resorting to low-level encapsulations mechanisms which help and facilitate network programmer reasoning about their complex slices behavior. In this paper, we propose SD-NMS, a novel software-defined architecture overcoming SDN and encapsulation techniques limitations. SD-NMS lifts several network virtualization roadblocks by combining these two separate approaches into an unified design. SD-NMS design leverages the benefits of SDN to provide Layer 2 (L2) isolation coupled with network overlay protocols with simple and flexible virtual tenant slices abstractions. This yields a network virtualization architecture that is both flexible, scalable and secure on one side, and self-manageable on the other. The experiment results showed that the proposed design offers negligible overhead and guarantees the network performance while achieving the desired isolation goals. Mohamed Fekih Ahmed, Chamseddine Talhi, Mohamed Cheriet |
IM | 2 |
| 2015 | Optimal placement of sequentially ordered virtual security appliances in the cloudabstractTraditional enterprise network security is based on the deployment of security appliances placed on some specific locations filtering, monitoring the traffic going through them. In this perspective, security appliances are chained in specific order to perform different security functions on the traffic. In the cloud, the same approach is often adopted using virtual security appliances to protect traffic for different virtual applications with the challenge of dealing with the flexible and elastic nature of the cloud. In this paper, we investigate the problem of placing virtual security appliances within the data center in order to minimize network latency and computing costs for security functions while maintaining the required sequential order of traversing virtual security appliances. We propose a new algorithm computing the best place to deploy these virtual security appliances in the data center. We further integrated our placement algorithm in an open source cloud framework, i.e. Openstack, in our test laboratory. The preliminary results show that we are placing the virtual security appliances in the required sequential order while improving the efficiency compared to the current default placement algorithm in Openstack. Alireza Shameli-Sendi, Yosr Jarraya, Mohamed Fekih Ahmed, Makan Pourzandi, Chamseddine Talhi, Mohamed Cheriet |
IM | 5 |
| 2015 | Enhancing malware detection for Android systems using a system call filtering and abstraction processabstractAbstract Improving anomaly‐based malware detection techniques has been widely studied in recent years. Most of these efforts have focused on the dataset available for analysis and/or the algorithms used to distinguish between normal or abnormal behavior. These factors have major impacts on the accuracy performance of the detection techniques as well as on their time and space complexities. In this paper, we revisit a classical anomaly‐based malware detection approach (i.e., database of normal behavior) analyzing Android system calls with two conflicting objectives: reducing the time and space complexities of the selected approach without decreasing its accuracy performance. To achieve this goal, we introduce a filtering and abstraction process, which (i) removes irrelevant system calls to describe the main behavior of an Android application and (ii) unifies system calls having the same functionality but different names. This process is used to build a database describing a canonical normal behavior model of Android applications. This model is based on the 200 most popular free Android applications available in the Android market. It represents the last line of defense of an in‐depth protection strategy for smartphone systems. The results of our experimentations show that our filtering and abstraction process has positive impacts on the performance and the accuracy of the selected malware detection approach. Copyright © 2014 John Wiley & Sons, Ltd. Abdelfattah Amamra, Jean-Marc Robert 0001, Chamseddine Talhi |
Secur. Commun. Networks | 3 |
| 2014 | A Software-Defined Scalable and Autonomous Architecture for Multi-tenancyabstractScalability for distributed Data Center Networks (DCNs) has long been a goal of the network research and industrial community. To support dynamically increasing demands from multi-tenants, the network providers have to duplicate or share virtual resources for satisfying tenants' requests. However, current Software-Defined Networking (SDN) architectures have major drawbacks including lack of scalability and cross Virtual Tenant Network (VTN) communication. They rely only on the flexibility of control plane and neglect management plane important role. SDN scalability bottleneck affects directly the network/VTN scalability. In front of the fast growing network, it is widely accepted that the network of the future will require more capabilities such as self-awareness, self-control and self-management. At the core of these challenges is providing elastic isolation for multi-tenancy and involving tenant in management and control to reach the scalability objective and reduce the complexity of management operations of large DCNs. To address these challenges, the Open virtual Network Management and Security (Open vNMS) is proposed for supporting transparent multi-tenancy while both network and VTN scalability is solved. Basing on elastic L2 isolation using SDN components' flexibility, we design an autonomic architecture to provide self-control, self-management and self-adaptive capabilities for the network. The experiment results showed that the proposed design offers negligible overhead and guarantees the network performance. Mohamed Fekih Ahmed, Chamseddine Talhi, Makan Pourzandi, Mohamed Cheriet |
IC2E | 2 |
| 2012 | Towards a BPEL model-driven approach for Web services securityabstractBy handling the orchestration, composition and interaction of Web services, the Business Process Execution Language (BPEL) has gained tremendous interest. However, such process-based language does not assure a secure environment for Web services composition. The key solution cannot be seen as a simple embed of security properties in the source code of the business logic since the dynamism of the BPEL process will be affected when the security measures get updated. In this context, several approaches have emerged to tackle such issue by offering the ability to specify the security properties independently from the business logic based on policy languages. Nevertheless, these languages are complex, verbose and require programming expertise. Owing to these difficulties, specifying and the enforcing BPEL security policies become very tedious tasks. To mitigate these challenges, we propose in this paper, a novel approach that takes advantage of both the Unified Modeling Language (UML) and the Aspect Oriented Paradigm (AOP). By elaborating a UML extension mechanism, called UML Profile, our approach provides the users with model-based capabilities to specify aspects that enforce the required security policies. On the other hand, it offers a high level of flexibility when enforcing security hardening solutions in the BPEL process by exploiting the AOP approach. We illustrate our approach through an example of the dynamic generation and integration of model-based security aspects in a BPEL process. Hanine Tout, Azzam Mourad, Hamdi Yahyaoui, Chamseddine Talhi, Hadi Otrok |
PST | 4 |
| 2009 | An Aspect-Oriented Approach for Software Security Hardening: from Design to ImplementationabstractSecurity is a very challenging task in software engineering. Enforcing security policies should be taken care of during the early phases of the software development life cycle to prevent security breaches in the final product. Since security is a crosscutting concern that pervades the entire software, integrating security solutions at the software design level may result in scattering and tangling security features throughout the entire design. To address this issue, we propose in this paper an aspect-oriented approach for specifying and enforcing security hardening solutions. This approach provides software designers with UML-based capabilities to perform security hardening in a clear and organized way, at the UML design level, without the need to be security experts. We also present the SHP profile, a UML-based security hardening language to describe and specify security hardening solutions at the UML design level. Finally, we explore the efficiency and the relevance of our approach by applying it to a real world case study and present the experimental results. Djedjiga Mouheb, Chamseddine Talhi, Azzam Mourad, Vitor Lima, Mourad Debbabi, Lingyu Wang 0001, Makan Pourzandi |
SoMeT | 2 |
| 2008 | Execution monitoring enforcement under memory-limitation constraints
Chamseddine Talhi, Nadia Tawbi, Mourad Debbabi |
Inf. Comput. | 1 |
| 2006 | Execution monitoring enforcement for limited-memory systemsabstractRecently, attention has been given to formally characterize security policies that are enforceable by different kinds of security mechanisms. Since execution monitoring (EM) is a ubiquitous technique for enforcing security policies, this class of enforcement mechanisms has attracted the attention of the majority of authors characterizing security enforcement. A very important research problem is the characterization of security policies that are enforceable by execution monitors constrained by memory limitations. This paper contributes to give more precise answers to this research problem. To represent execution monitors constrained by memory limitations, we introduce a new class of automata that we call Bounded History Automata. Characterizing memory limitations gives rise to a precise taxonomy of security policies enforceable under such constraints.This work is in the same line as the research work advanced by Schneider [31], Ligatti et. al [1, 21] and Fong [12] on security enforcement. Our main contribution consists in (1) instantiating Fong's abstraction idea to deal with memory-limitations, (2) defining Bounded History Automata by applying our abstraction to both security automata and edit automata [1], and (3) Reasoning about the enforcement power of bounded history automata by investigating the enforcement of locally testable properties; a well studied class of languages that are recognizable by investigating local information. Our approach gives rise to a realistic evaluation of the enforcement power of execution monitoring. This evaluation is based on bounding the memory size used by the monitor to save execution history, and identifying the security policies enforceable under such constraint. Chamseddine Talhi, Nadia Tawbi, Mourad Debbabi |
PST | 1 |
| 2006 | Common Criteria Approach to J2ME CLDC Security Requirements
Mourad Debbabi, Mohamed Mostafa Saleh, Chamseddine Talhi, Sami Zhioua |
SoMeT | 3 |
| 2005 | Java for Mobile Devices: A Security StudyabstractJava 2 Micro-Edition connected limited device configuration (J2ME CLDC) is the platform of choice when it comes to running mobile applications on resource-constrained devices (cell phones, set-top boxes, etc.). The large deployment of this platform makes it a target for security attacks. The intent of this paper is twofold: first, we study the security architecture of J2ME CLDC; and second, we provide a vulnerability analysis of this Java platform. The analyzed components are: virtual machine, CLDC API and MIDP (mobile information device profile) API. The analysis covers the specifications, the reference implementation (RI) as well as several other widely deployed implementations of this platform. The aspects targeted by this security analysis encompass: networking, record management system, virtual machine, multi-threading and digital right management. This work identifies security weaknesses in J2ME CLDC that may represent sources of security exploits. Moreover, the results reported in this paper are valuable for any attempt to test or harden the security of this platform Mourad Debbabi, Mohamed Mostafa Saleh, Chamseddine Talhi, Sami Zhioua |
ACSAC | 3 |
| 2005 | Security Analysis of Wireless Java
Mourad Debbabi, Mohamed Mostafa Saleh, Chamseddine Talhi, Sami Zhioua |
PST | 3 |