VLDB 2026 Research / reviewers in the wild / expert
Siamak Layeghy
dblp:67/10957
· DBLP profile ↗
18ranked-venue papers
3as first author
17since 2021 · last 2027
0000-0002-1229-2368ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 8 · 1 first-author · 8 since 2021Computer networks · 6 · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Probing post-hoc reasoning in LLMs over multi-step pathfinding tasksabstractLarge language models (LLMs) are increasingly evaluated not only on the correctness of their outputs but also on the explanations they provide for their answers. To study LLM output behaviour in a controlled setting, including both final answers and post-hoc explanations, we use shortest-path routing as a testbed: it provides unambiguous ground truth while allowing systematic variation in topology and edge-weight distributions. We construct a large suite of graphs spanning five canonical topologies, grid, fat-tree, jellyfish, Erdős-Rényi, and Barabási-Albert, with fixed, uniform, discrete, and lognormal weights and evaluate both answer accuracy and the linguistic form of post-hoc explanations across multiple models. Two post-hoc explanation styles emerge consistently. An analytical style approximates algorithmic exploration, produces concise explanations, and remains accurate across graph families. A verbose explanation style narrates step-by-step simulations of procedures such as Dijkstra. In our results, this style is often associated with suboptimal paths or invalid edges, especially under irregular structure and non-uniform weights. We further identify recurring failure modes, including hallucinated edges that break path continuity, loops with repeated nodes, and paths that fail to connect the correct source and destination, that characterise this breakdown. All answers and explanations are produced without code execution; the observed behaviours therefore reflect text-only problem solving and retrospective verbalisation. Our findings show that post-hoc explanation style, not only final-answer accuracy, is associated with robustness within the evaluated model set, and they support shortest-path routing as a controlled diagnostic probe for evaluating LLM outputs and post-hoc explanations on structured graph tasks. Yaying Chen, Siamak Layeghy, Mahsa Baktash, Marius Portmann |
Expert Syst. Appl. | 2 |
| 2026 | LLMs can pass the CCNA certification exam but do they understand networking?abstractLarge language models (LLMs) have recently demonstrated significant success across a wide range of domains. Their extensive pre-training on vast quantities of information available on the internet endows them with a broad and general understanding of many areas. This presents an opportunity to apply LLMs to the networking domain, such as assisting human operators in maintaining data centers or helping security analysts respond to network attacks in time-sensitive environments. However, it remains unclear if LLMs possess the necessary understanding of the networking domain. To evaluate this, we assess LLMs’ ability to reason about networking by testing their performance on the Cisco Certified Network Associate ( CCNA ), Cisco Certified Support Technician (CCST) and the Microsoft Networking Foundations (N.F) certifications, industry-leading exam. Our findings reveal that various open and closed weights models can pass the CCNA certification but encounter difficulties when answering questions that require advanced reasoning. Liam Daly Manocchio, Siamak Layeghy, Paul R. B. Houssel, Marius Portmann |
Comput. Networks | 2 |
| 2025 | Quantised Neural Network NIDS on SmartNIC: Balancing Accuracy and Efficiency in P4abstractThis paper presents the implementation of various quantised neural network-based Network Intrusion Detection Systems on a SmartNIC using the P4 programming language. SmartNICs impose significant memory and computational constraints, making deep learning integration particularly challenging. Prior work has been restricted to shallow networks and 1-bit quantisation due to these limitations. In contrast, we deploy a binary neural network with a 64–16–8–1 architecture, along with several other quantised models not previously implemented on SmartNICs. To overcome the limited support for quantisation-aware training, which is restricted to 8-bit, we introduce a variable quantiser scheme for neural networks that allows adaptable quantisation levels during training. We further deploy and evaluate 2-bit and 4-bit models on the SmartNIC, made feasible by optimising resource utilisation. The model achieves a 91.65% accuracy and a 91.46% F1 score while achieving throughputs above 6Mpps. Yaying Chen, Siamak Layeghy, Marius Portmann |
LCN | 2 |
| 2025 | Multimodal LLMs for Zero-Shot Intrusion Detection Using NetFlow VisualisationsabstractThis paper presents a proof-of-concept framework integrating time-windowed NetFlow traffic visualisations with zero-shot inference from multimodal LLMs for network intrusion detection. Real-world network traffic, augmented with manually injected attacks such as IP sweep, DoS, and DDoS, is transformed into scatter plots representing host communication structure and traffic volume for each 1-minute window. These visualisations are assessed by GPT-4o and LLaVA in a zero-shot setting, without task-specific fine-tuning or prior examples. Results show that multimodal LLMs, particularly GPT-4o, effectively detect structural anomalies in network traffic using visual patterns alone, especially when prompts are enhanced with detailed explanations of attack appearances in the visualisations. These findings underscore the potential of LLM-based visual intrusion detection for NetFlow data and encourage further research into domain-specific visual encodings, optimised prompt design, and multimodal LLM adaptations for network intrusion detection applications. Majed Luay, Siamak Layeghy, Yash Pandey, Gayan K. Kulatilleke, Marius Portmann |
LCN | 2 |
| 2025 | An empirical evaluation of preprocessing methods for machine learning based network intrusion detection systemsabstractDespite extensive efforts in developing machine learning-based Network Intrusion Detection Systems, inconsistencies in the choice of pre-processing of training data exists across the literature. This study surveys both seminal and recent works, identifying that while the same benchmark datasets and model classes are frequently used, the data pre-processing methods vary significantly, often without in-depth discussion and justification, limiting performance and hindering fair comparison. This work aims to address this problem, by exploring the possibility of a standardised pre-processing for Network Intrusion Detection Systems benchmark datasets We perform a detailed experimental evaluation on the most common machine learning models and four prevalent Network Intrusion Detection Systems benchmark datasets, considering a total of 72 combinations of pre-processing methods for both numerical and categorical fields in the network flow data. Based on our experimental evaluation, we propose a uniform (or ’standardised’) data pre-processing approach, which consistently performs well across the considered datasets and machine learning models. We demonstrate that our proposed method can achieve up to a 11% increase in detection accuracy over commonly applied pre-processing techniques for a shallow neural network (for the purposes of this work, we deem networks with fewer than 3 hidden layers as shallow), versus less-optimal pre-processing approaches. To facilitate future research, we make our code publicly available 1 . Liam Daly Manocchio, Siamak Layeghy, Marcus Gallagher, Marius Portmann |
Eng. Appl. Artif. Intell. | 2 |
| 2025 | EcoShower: Estimating shower duration using non-intrusive multi-modal sensor data via LSTM and Gated Transformer modelsabstractThis paper tackles the challenge of accurately estimating shower duration from non-intrusive multi-modal sensor data to facilitate efficient water management. Efficient water usage is a critical environmental challenge, and showering contributes significantly to domestic water consumption. Developing accurate, accessible monitoring solutions is essential for promoting sustainability . Utilizing data from humidity, temperature, sound average, and sound peak sensors, we explore suitable data processing steps and the application of machine learning models to estimate shower duration. Our approach includes the design of a bidirectional Long Short-Term Memory model and the application of an existing Gated Transformer Network model to address the multivariate time series classification task . Our analysis reveals that both models are highly effective in this context, also compared to baseline models, and humidity emerges as a particularly powerful predictor either on its own or when combined with the temperature sensor . This work not only showcases the potential of using machine learning methods for multivariate time series classification in the domain of water consumption but also underscores the implications for adopting such technologies in promoting sustainable water use. Lukas Sablica, Bettina Grün, Siamak Layeghy, Sara Dolnicar, Marius Portmann |
Expert Syst. Appl. | 3 |
| 2025 | P4-Secure: In-Band DDoS Detection in Software Defined NetworksabstractEfficient detection of Distributed Denial of Service (DDoS) attacks in datacentres and corporate networks is an active research domain. This paper introduces, P4-Secure, an efficient approach for in-band detection of DDoS attacks, without using the controller resources and channel. The pure in-band implementation of DDoS detection, makes it a practical and viable solution for real-world network security applications, including large-scale backbone networks. The proposed DDoS detection uses an axis-aligned classifier based on the packet asymmetry metric, trained through the negative selection approach. The trained axis-aligned classifier was then implemented in the data plane using P4 programming and managed to classify network flows with a configurable false-positive ratio. Through experiments on two independent real-world network datasets (UQ and ISP) and the CAIDA DDoS attack dataset, the robustness of the proposed approach was evaluated across varying network characteristics. The approach demonstrated a notably superior performance in minimising false positives compared to alternative methods, with a rate of only 0.5%. This achievement was coupled with a 90% F1 score, highlighting its effectiveness in addressing DDoS attacks while avoiding unnecessary false alarms. The evaluation on real-world hardware demonstrates that P4-Secure incurs minimal overhead even at high packet rates, such as 8 Mpps, making it highly suitable for datacentres and backbone network security applications. Liam Daly Manocchio, Yaying Chen, Siamak Layeghy, David Gwynne, Marius Portmann |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Towards Explainable Network Intrusion Detection using Large Language ModelsabstractLarge Language Models (LLMs) have revolutionised natural language processing tasks, particularly as chat agents. However, their applicability to threat detection problems remains unclear. This paper examines the feasibility of employing LLMs as a Network Intrusion Detection System (NIDS), despite their high computational requirements, primarily for the sake of explain-ability. Furthermore, considerable resources have been invested in developing LLMs, and they may offer utility for NIDS. Current state-of-the-art NIDS rely on artificial benchmarking datasets, resulting in skewed performance when applied to real-world networking environments. Therefore, we compare the GPT-4 and LLama3 models against traditional architectures and transformer-based models to assess their ability to detect malicious NetFlows without depending on artificially skewed datasets, but solely on their vast pre-trained acquired knowledge. Our results reveal that, although LLMs struggle with precise attack detection, they hold significant potential for a path towards explainable NIDS. Our preliminary exploration shows that LLMs are unfit for the detection of Malicious NetFlows. Most promisingly, however, these exhibit significant potential as complementary agents in NIDS, particularly in providing explanations and aiding in threat response when integrated with Retrieval Augmented Generation (RAG) and function calling capabilities. Paul R. B. Houssel, Priyanka Singh 0001, Siamak Layeghy, Marius Portmann |
BDCAT | 3 |
| 2024 | FlowTransformer: A transformer framework for flow-based network intrusion detection systemsabstractThis paper presents the FlowTransformer framework, a novel approach for implementing transformer-based Network Intrusion Detection Systems (NIDSs). FlowTransformer leverages the strengths of transformer models in identifying the long-term behaviour and characteristics of networks, which are often overlooked by most existing NIDSs. By capturing these complex patterns in network traffic, FlowTransformer offers a flexible and efficient tool for researchers and practitioners in the cybersecurity community who are seeking to implement NIDSs using transformer-based models. FlowTransformer allows the direct substitution of various transformer components, including the input encoding, transformer, classification head, and the evaluation of these across any flow-based network dataset. To demonstrate the effectiveness and efficiency of the FlowTransformer framework, we utilise it to provide an extensive evaluation of various common transformer architectures, such as GPT 2.0 and BERT, on three commonly used public NIDS benchmark datasets. We provide results for accuracy, model size and speed. A key finding of our evaluation is that the choice of classification head has the most significant impact on the model performance. Surprisingly, Global Average Pooling, which is commonly used in text classification, performs very poorly in the context of NIDS. In addition, we show that model size can be reduced by over 50%, and inference and training times improved, with no loss of accuracy, by making specific choices of input encoding and classification head instead of other commonly used alternatives. Liam Daly Manocchio, Siamak Layeghy, Wai Weng Lo, Gayan K. Kulatilleke, Mohanad Sarhan, Marius Portmann |
Expert Syst. Appl. | 2 |
| 2024 | Benchmarking the benchmark - Comparing synthetic and real-world Network IDS datasetsabstractNetwork Intrusion Detection Systems (NIDSs) are an increasingly important tool for the prevention and mitigation of cyber attacks. Over the past years, a lot of research efforts have aimed at leveraging the increasingly powerful models of Machine Learning (ML) for this purpose. A number of labelled synthetic datasets have been generated and made publicly available by researchers, and they have become the benchmarks via which new ML-based NIDS classifiers are being evaluated. Recently published results show excellent classification performance with these datasets, increasingly approaching 100 percent performance across key evaluation metrics such as Accuracy, F1 score, AUC, etc. Unfortunately, we have not yet seen these excellent academic research results translated into practical NIDS systems with such near-perfect performance. This motivated our research presented in this paper, where we analyse the statistical properties of the benign traffic in three of the more recent and relevant NIDS datasets, (CIC_IDS, UNSW_NB15, TON_IOT), by converting them into a common flow format. As a comparison, we consider two datasets obtained from real-world production networks, one from a university network and one from a medium size Internet Service Provider (ISP). Our results show that the two real-world datasets are quite similar among themselves in regards to most of the considered statistical features. Equally, the three synthetic datasets are also relatively similar within their group. However, and most importantly, our results show a distinct difference of most of the considered statistical features between the three synthetic datasets and the two real-world datasets. Since ML relies on the basic assumption of training and test datasets being sampled from the same distribution, this raises the question of how well the performance results of ML-classifiers trained on the considered synthetic datasets can translate and generalise to real-world networks. We believe this is an interesting and relevant question which provides motivation for further research in this space. Siamak Layeghy, Marcus Gallagher, Marius Portmann |
J. Inf. Secur. Appl. | 1 |
| 2023 | Inspection-L: self-supervised GNN node embeddings for money laundering detection in bitcoin
Wai Weng Lo, Gayan K. Kulatilleke, Mohanad Sarhan, Siamak Layeghy, Marius Portmann |
Appl. Intell. | 4 |
| 2023 | Exploring edge TPU for network intrusion detection in IoT
Seyedehfaezeh Hosseininoorbin, Siamak Layeghy, Mohanad Sarhan, Raja Jurdak, Marius Portmann |
J. Parallel Distributed Comput. | 2 |
| 2023 | DI-NIDS: Domain invariant network intrusion detection systemabstractThe performance of machine learning based network intrusion detection systems (NIDSs) severely degrades when deployed on a network with significantly different feature distributions from the ones of the training dataset. In various applications, such as computer vision, domain adaptation techniques have been successful in mitigating the gap between the distributions of the training and test data. In the case of network intrusion detection however, the state-of-the-art domain adaptation approaches have had limited success. According to recent studies, as well as our own results, the performance of an NIDS considerably deteriorates when the ‘unseen’ test dataset does not follow the training dataset distribution. In order to enhance the generalisability of machine learning based network intrusion detection systems, we propose to extract domain invariant features using adversarial domain adaptation from multiple network domains, and then apply an unsupervised technique for recognising abnormalities, i.e., intrusions. More specifically, we train a domain adversarial neural network on labelled source domains, extract the domain invariant features, and train a One-Class SVM (OSVM) model to detect anomalies. At test time, we feedforward the unlabelled test data to the feature extractor network to project it into a domain invariant space, and then apply OSVM on the extracted features to achieve our final goal of detecting intrusions. Our extensive experiments on the NIDS benchmark datasets of NFv2-CIC-2018 and NFv2-UNSW-NB15 show that our proposed setup demonstrates superior cross-domain performance in comparison to the previous approaches. Siamak Layeghy, Mahsa Baktash, Marius Portmann |
Knowl. Based Syst. | 1 |
| 2022 | E-GraphSAGE: A Graph Neural Network based Intrusion Detection System for IoTabstractThis paper presents a new Network Intrusion Detection System (NIDS) based on Graph Neural Networks (GNNs). GNNs are a relatively new sub-field of deep neural networks, which can leverage the inherent structure of graph-based data. Training and evaluation data for NIDSs are typically represented as flow records, which can naturally be represented in a graph format. In this paper, we propose E-GraphSAGE, a GNN approach that allows capturing both the edge features of a graph as well as the topological information for network intrusion detection in IoT networks. To the best of our knowledge, our proposal is the first successful, practical, and extensively evaluated approach of applying GNNs on the problem of network intrusion detection for IoT using flow-based data. Our extensive experimental evaluation on four recent NIDS benchmark datasets shows that our approach outperforms the state-of-the-art in terms of key classification metrics, which demonstrates the potential of GNNs in network intrusion detection, and provides motivation for further research. Wai Weng Lo, Siamak Layeghy, Mohanad Sarhan, Marcus Gallagher, Marius Portmann |
NOMS | 2 |
| 2022 | Anomal-E: A self-supervised network intrusion detection system based on graph neural networks
Evan Caville, Wai Weng Lo, Siamak Layeghy, Marius Portmann |
Knowl. Based Syst. | 3 |
| 2022 | Towards a Standard Feature Set for Network Intrusion Detection System Datasets
Mohanad Sarhan, Siamak Layeghy, Marius Portmann |
Mob. Networks Appl. | 2 |
| 2021 | P-SCOR: Integration of Constraint Programming Orchestration and Programmable Data PlaneabstractIn this manuscript we present an original implementation of network management functions in the context of Software Defined Networking. We demonstrate a full integration of an artificial intelligence driven management, an SDN control plane, and a programmable data plane. Constraint Programming is used to implement a management operating system that accepts high level specifications, via a northbound interface, in terms of operational objective and directives. These are translated in technology-specific constraints and directives for the SDN control plane, leveraging the programmable data plane, which is enriched with functionalities suited to feed data that enable the most effective operation of the “intelligent” control plane, by exploiting the P4 language. Andrea Melis 0001, Siamak Layeghy, Davide Berardi, Marius Portmann, Marco Prandini, Franco Callegati |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2014 | Non-invasivemonitoring of fetal movements using time-frequency features of accelerometryabstractThis paper presents a time-frequency approach for fetal movement monitoring which is based on the instantaneous amplitude (IA) and instantaneous frequency (IF) of signals collected using 3axial accelerometers placed over the maternal abdomen. Results of a feature selection method based on receiver operating characteristic analysis shows that the mean of the IAs and deviation of the Ifs outperform other features. A support vector machine based classifier which uses these 2 features exhibits a total accuracy of 96.6% with reasonably high sensitivity and specificity. Siamak Layeghy, Ghasem Azemi, Paul B. Colditz, Boualem Boashash |
ICASSP | 1 |