VLDB 2026 Research / reviewers in the wild / expert
David Espes
dblp:69/3143 · also David Espès
· DBLP profile ↗
26ranked-venue papers
1as first author
10since 2021 · last 2025
0000-0003-3445-947XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 2 since 2021Systems, architecture and hardware · 5 · 5 since 2021Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Exploration Framework for IDS Optimization on FPGAabstractMany devices communicate externally in today's technologydriven world, creating cyber-attack vulnerabilities. To safeguard against these threats, utilizing an Intrusion Detection System (IDS) incorporating AI for effective anomaly detection is crucial. However, it is important to manage power consumption and latency carefully. Optimization of machine learning (ML) models can be achieved through three primary approaches: tuning hyperparameters and ML architecture via Neural Architecture Search (NAS) [1], enhancing existing ML architectures to improve robustness while reducing complexity [2], and optimizing for hardware implementation to strike a balance between Quality of Service (QoS) and Quality of Results (QoR) [3]. To address these challenges, we design a multi-level optimization approach that directly takes hardware and software constraints (such as QoS and QoR) into account during the optimization process with a hardware estimator (HE), greatly reducing the required number of actual ML architecture implementations. The main contributions are the fast exploration and evaluation of solutions based on a proposed hardware estimation regressor and the second is the ability to select and compare the most appropriate ML model architectures according to objectives and hardware constraints. Kevin Druart, David Espes, Catherine Dezan, Alain Deturche |
ASAP | 2 |
| 2025 | DisPEED: Distributing Packet flow analyses in a swarm of heterogeneous EmbEddeD platformsabstractSecurity is a major challenge in swarm of drones. Network intrusion detection systems (IDS) are deployed to analyze and detect suspicious packet flows. Traditionally, they are implemented independently on each drone. However, due to heterogeneity and resource limitations of drones, IDS algorithms can fall short in satisfying Quality of Service (Qo$S$) metrics, such as latency and accuracy. We argue that a drone can make profit from the swarm by delegating part of the analysis of their packet flows to neighbor drones that have more processing power to enforce security. In this paper, we propose two solving methods to distribute the packet flows to analyze among drones in a way to ensure that it is processed with a minimum communication overhead to limit the attack surface, while ensuring Qo$S$metrics imposed by the drone mission. First, we propose a formulation of the distribution problem using both an Integer Linear Programming (ILP) and a Maximum-Flow Minimum-Cost (MFMC). Furthermore, we propose two specific solving methods for the distribution problem: (1) a Greedy Heuristic (GH), a non-exact solving method, but with small time overhead, and (2) an Adapted Edmonds-Karp (AEK) algorithm, an exact method, but with a higher time overhead. GH proved to be a very fast solution (up to more than 2000x faster than ILP with Branch and Bound), while AEK solution proved to find the exact solution even when the problem is very difficult. Louis Morge-Rollet, Camélia Slimani, Laurent Lemarchand, Frédéric Le Roy, David Espes, Jalil Boukhobza |
DATE | 5 |
| 2025 | Data Transformation for IDS: Leveraging Symbolic and Temporal Aspects
Enzo Zamaï, David Espes, Audrey C. Therrien, Catherine Dezan |
SEC (1) | 2 |
| 2025 | A study on characterizing energy, latency and security for Intrusion Detection Systems on heterogeneous embedded platforms
Camélia Slimani, Louis Morge-Rollet, Laurent Lemarchand, David Espes, Frédéric Le Roy, Jalil Boukhobza |
Future Gener. Comput. Syst. | 4 |
| 2024 | SECL: A Zero-Day Attack Detector and Classifier based on Contrastive Learning and Strong RegularizationabstractIntrusion Detection Systems (IDSs) always had difficulties in detecting Zero-Day Attacks (ZDAs). One of the advantages of Machine Learning (ML)-based IDSs, which is their superiority in detecting ZDAs, remains largely unexplored, especially when considering multiple ZDAs. This is mainly due to the fact that ML-based IDSs are mainly using supervised ML methods. Although they exhibit better performance in detecting known attacks, they are by design unable to detect unknown attacks because they are limited to detecting the classes present in the dataset they were trained on. This paper introduces SECL, a method that combines Contrastive Learning (CL) and a new regularization method composed of dropout, Von Neumann Entropy (VNE) and Sepmix (a regularization inspired from mixup). SECL is close to, or even better than supervised ML methods in detecting known attacks, while gaining the ability to detect and differentiate multiple ZDAs. Experiments were performed on three datasets, UNSW-NB15, CIC-IDS2017 and WADI, effectively showing that this method is able to detect multiple ZDAs while achieving performance similar to supervised methods on known attacks. Notably, the proposed method even has an overall better performance than a supervised method knowing all attacks on the WADI dataset. These results pave the way for better detection of ZDAs, without reduction of performance on known attacks. Robin Duraz, David Espes, Julien Francq, Sandrine Vaton |
ARES | 2 |
| 2024 | IDS-DEEP: a strategy for selecting the best IDS for Drones with heterogeneous EmbEdded PlatformsabstractDrone swarms are increasingly being used to perform critical missions, such as inspection of ports and industrial installations. Each drone can embed heterogeneous execution platforms to successfully perform various computing tasks. As security threats may disrupt the progression of the drone mission, network intrusion detection systems (IDSs) are used. They analyze network traffic to detect malicious behaviors, but generally rely on resource-hungry machine learning models. To adapt to the dynamic nature of the mission, it is necessary to embed several IDS implementations leveraging heterogeneous computing resources of the drone and presenting a trade-off between security, throughput, and energy consumption. To address this issue, we propose, in this paper, an end-to-end flow composed of an offline phase to choose the IDS implementations to embed on the drone platform and an online phase to select the best implementation online considering the mission conditions at a given time. We devised a MILP formulation for the offline phase that proved to provide a 89.41% better Inverted Generational Distance (IGD) than a random choice. For the online phase, we investigated several solutions and designed a novel optimized strategy that proved to be around 16.76 times faster than TOPSIS while having comparable QoS metrics. Louis Morge-Rollet, Camélia Slimani, Laurent Lemarchand, Frédéric Le Roy, David Espes, Jalil Boukhobza |
SBAC-PAD | 5 |
| 2023 | Characterizing Intrusion Detection Systems On Heterogeneous Embedded PlatformsabstractSwarms of drones are more and more used for critical missions and need to be protected against malicious users. Intrusion Detection Systems (IDS) are used to analyze network traffic in order to detect possible threats. Modern IDSs rely on machine learning models for such a sake. Because of the absence of central management in swarms of drones, IDSs constitute a good second-line protective measure. Investigating the execution of IDS (resource-hungry) algorithms on drone (resource-constrained) devices is crucial when it comes to optimizing energy, response time, memory footprint and algorithm precision. In addition, embedded platforms used in drones often incorporate heterogeneous computing platforms on which IDSs could be executed. In this paper, we present a methodology and results about characterizing the execution of different IDS models on various platform (CPUs, GPUs). In effect, as swarm of drones operate in different mission contexts (e.g. criticity level) and states (e.g. energy budget, memory footprint), it is important to explore which IDS model to run on which platforms for a given mission in a given context. For this sake, we evaluated several metrics on different platforms: energy and resource consumption, accuracy for malicious traffic detection and response time. The models tested (RF, CNN, DNN) have shown different performance according to the measured metrics and the chosen platform and proved to be relevant in different mission states. Camélia Slimani, Louis Morge-Rollet, Laurent Lemarchand, Frédéric Le Roy, David Espes, Jalil Boukhobza |
DSD | 5 |
| 2023 | A novel bi-anomaly-based intrusion detection system approach for industry 4.0abstractToday, industry 4.0 is becoming a major target for cybercriminals due to its hyper-connectivity. Fortunately, there are several advanced means of securing industrial systems such as Intrusion Detection Systems (IDS). However, one of the main limitations of industrial IDS is the high rate of false positives and how to distinguish a real attack from an industrial failure. This paper deals precisely with the two latter points and proposes a way to reduce the rate of false positives and to distinguish attacks from industrial failures. The proposed approach combines two kinds of IDS using Neural Network (NN) through a Decision Making System (DMS). It was tested on a real industrial environment. The performance results are promising with a high percentage of accuracy and a low false positive rate. Salwa Alem, David Espes, Laurent Nana, Florent de Lamotte |
Future Gener. Comput. Syst. | 2 |
| 2022 | Optimal Access Control Deployment in Network Function VirtualizationabstractNetwork function virtualization (NFV) yields numerous advantages, specifically the ability to provide a cost-efficient alternative to hardware-based functionalities on software platforms to break the vendor lock-in problem. However, these advantages come at the cost of several security issues. These threats can be leveraged by controlling the information that flows between the different components that compose NFV services. We propose an approach allowing an optimal deployment of access control policies on NFV services. The proposed approach allows to find the best possible trade-offs between the impact in terms of latency resulting from the deployment of the access control policy and the used resources. In contrast to existing approaches, our solution prevents an insider adversary who compromises one or more unknown VNF(s) to go around the access control policy. We experimentally evaluate the return solutions according to the size of the NFV service, the size of the policy to be deployed and the number of physical servers that host the VNF service. Manel Smine, David Espes, Marc-Oliver Pahl |
NOMS | 2 |
| 2021 | Impacts of Service Decomposition Models on Security Attributes: A Case Study with 5G Network Repository FunctionabstractMicroservices-based architectures gain more and more attention in industry and academia due to their tremendous advantages such as providing resiliency, scalability, composability, etc. To benefit from these advantages, a proper architectural design is very important. The decomposition model of services into microservices and the granularity of these microservices affect the different aspects of the system such as flexibility, maintainability, performance, and security. An inappropriate service decomposition into microservices (improper granularity) may increase the attack surface of the system and lower its security level. In this paper, first, we study the probability of compromising services before and after decomposition. Then we formulate the impacts of possible service decomposition models on confidentiality, integrity, and availability attributes of the system. To do so, we provide equations for measuring confidentiality, integrity, and availability risks of the decomposed services in the system. It is also shown that the number of entry points to the decomposed services and the size of the microservices affect the security attributes of the system. As a use case, we propose three different service decomposition models for the 5G NRF (Network Repository Function) and calculate the impacts of these decomposition models on the confidentiality, integrity, and availability of the system using the provided equations. Shanay Behrad, David Espes, Philippe Bertin, Cao-Thanh Phan |
NetSoft | 2 |
| 2020 | New Dataset for Industry 4.0 to Address the Change in Threat Landscape
Salwa Alem, David Espes, Laurent Nana, Florent de Lamotte |
CRiSIS | 2 |
| 2020 | Network Functions Virtualization Access Control as a Service
Manel Smine, David Espes, Nora Cuppens, Frédéric Cuppens |
DBSec | 2 |
| 2020 | Managing Secure Inter-slice Communication in 5G Network Slice Chains
Luis Carlos Suárez, David Espes, Frédéric Cuppens, Cao-Thanh Phan, Philippe Bertin, Philippe Le Parc |
DBSec | 2 |
| 2020 | STUART: ReSilient archiTecture to dynamically manage Unmanned aeriAl vehicle networks under atTackabstractThe growing demand for Unmanned Aerial Vehicles (UAV) has the potential to increase productivity and economy in the industry, due to its use in various fields, such as health, security, aerial photography, surveillance, military missions, agriculture, etc. The production and use of the UAV have increased lately, and there is a demand for the improvement of decision-making, security, safety, and knowledge about relevant technologies. Thus, these vehicles must continually adapt to complex missions where they face unpredictable issues. In this context, the aim of this paper is to advance the state of the art through the definition and development of a resilient architecture for UAV that dynamically manages the network, even when subjected to an attack during a mission, integrating security methods and safety. The architecture will be composed by three modules: (1) decision-making module, (2) diagnosis module, and (3) resilient module. This work also investigates the incorporation of safety and security as a unified concept in the development of UAV. Isadora Garcia Ferrão, Daniel F. Pigatto, João V. C. Fontes, Natassya B. F. Silva, David Espes, Catherine Dezan, Kalinka Regina Lucas Jaquie Castelo Branco |
ISCC | 5 |
| 2019 | DTE Access Control Model for Integrated ICS SystemsabstractIntegrating Industrial Control Systems (ICS) with Corporate System (IT) is one of the most important industrial orientations. With recent cybersecurity attacks, the security of integrated ICS systems has become the priority of industrial world. Access control technologies such as firewalls are very important for Integrated ICS (IICS) systems to control communication across different networks to protect valuable resources. However, conventional firewalls are not always fully compatible with Industrial Control Systems. In fact, firewalls can introduce significant latency while ICS systems usually are very demanding in terms of timing requirements. Besides, most of existing firewalls do not support all industrial protocols. This paper proposes a new access control model for integrated ICS systems based on Domain and Type Enforcement (DTE). This new model allows to define and apply enforced access controls with respect of ICS timing requirements. Access controls definition is based on a high level language that can be used by ICS administrators with ease. This paper also proposes an initial generic ruleset based on the ISA95 functional model. This generic ruleset simplifies the deployment of DTE access controls and provides a good introduction to the DTE concepts for administrators. Khaoula Es-Salhi, David Espes, Nora Cuppens |
ARES | 2 |
| 2019 | A Hybrid Intrusion Detection System in Industry 4.0 Based on ISA95 StandardabstractToday with the emergence of an industrial information system in industry of the future which includes the connection between all trades, applications and the converged technologies between information technology and operational technology, cybersecurity has become urgent. Industrial Intrusion Detection System are no longer sufficient to counter cyberattacks because of their natures, which is usually misuse, and are unable to detect attacks that target the application layer of the Open Systems Interconnection model. Therefore, cybersecurity in industrial systems adopts known information technology security solutions, such as an Intrusion Detection System which has to be modified, completed and adapted to work in industrial field. We propose to deepen this approach by developing an adapted IDS to monitor industrial systems against illegitimate access and detect abnormal activities. For this purpose, we expose in this paper our efficient hybrid intrusion detection solution based on International Society of Automation 95 standard and neural network. Our research work is focused on Manufacturing Executive System which represents the central and main element in industry. Salwa Alem, David Espes, Laurent Nana, Florent de Lamotte |
AICCSA | 2 |
| 2018 | A Prediction-Based Method for False Data Injection Attacks Detection in Industrial Control Systems
Lyes Bayou, David Espes, Nora Cuppens, Frédéric Cuppens |
CRiSIS | 2 |
| 2018 | RIICS: Risk Based IICS Segmentation Method
Khaoula Es-Salhi, David Espes, Nora Cuppens |
CRiSIS | 2 |
| 2017 | Firewall Policies Provisioning Through SDN in the Cloud
Nora Cuppens, Salaheddine Zerkane, Yanhuang Li, David Espes, Philippe Le Parc, Frédéric Cuppens |
DBSec | 4 |
| 2017 | A New Segmentation Method for Integrated ICS (Short Paper)abstractThe paper presents a new segmentation method for Integrated ICS (Industrial Control Systems) with Corporate system. This new method aims at simplifying security zones identification by focusing only on the system's aspects that are really relevant for segmentation taking into account the system's constraints. Multiple research works have studied IICS (Integrated ICS) segmentation but their solutions are unfortunately not generic enough and do not sufficiently take into account all of the Integrated ICS specificity. Our new method tries to address the problem more efficiently by providing realistic and pragmatic answers to the issue while remaining sufficiently generic to be applied to different types of Integrated ICS. Khaoula Es-Salhi, David Espes, Nora Cuppens |
PST | 2 |
| 2016 | Towards a CDS-based Intrusion Detection Deployment Scheme for Securing Industrial Wireless Sensor NetworksabstractThe use of wireless communication is a major trend in the so called Supervisory Control and Data Acquisition systems (SCADA). Consequently, Wireless Industrial Sensor Networks (WISN) were developed to meet real time and security requirements needed by SCADA systems. In term of security, WISN suffer from the same threats that those targeting classical WSN. Indeed, attackers mainly use wireless communication as a medium to launch these attacks. But as these networks are used to manage critical systems, consequences of such attacks can be more harmful. Therefore, additionally to the use of cryptographic and authentication mechanisms, Intrusion Detection Systems (IDS) are also used as a second line of defense. In this paper we propose an efficient IDS deployment scheme specially tailored to fit WISN characteristics. It builds a virtual wireless backbone that adds security purposes to the WISN. We also show that the proposed deployment scheme provides a good traffic monitoring capability with an acceptable number of monitoring nodes. It particularly allows detecting that a packet has been forged, deleted, modified or delayed during its transmission. Lyes Bayou, Nora Cuppens, David Espes, Frédéric Cuppens |
ARES | 3 |
| 2016 | A Proactive Stateful Firewall for Software Defined Networking
Salaheddine Zerkane, David Espes, Philippe Le Parc, Frédéric Cuppens |
CRiSIS | 2 |
| 2016 | Modular approach for expert system toward anomaly: N-layersabstractSmart cities and smart homes are booming fields of development of pervasive systems. With the high stakes these systems have to manage, and their sheer complexity, anomalies have to be considered. In these complex systems are many connected components with computing capacities. They can manage anomalies, even if partially, and can act as some kind of expert systems. These expert systems can be relied upon to provide anomaly management. The complexity to manage generic expert systems brings us to suggest another approach. In this paper, the N-layers is discussed. It layers the various existing expert systems to organize them as a more generic expert system. It also aims to correct some difficulties to develop and integrate generic expert systems into various scales complex systems, such as smart cities or smart homes. Etienne Pardo, David Espes, Philippe Le Parc |
ISNCC | 2 |
| 2016 | Software Defined Networking Reactive Stateful Firewall
Salaheddine Zerkane, David Espes, Philippe Le Parc, Frédéric Cuppens |
SEC | 2 |
| 2015 | Security Issue of WirelessHART Based SCADA Systems
Lyes Bayou, David Espes, Nora Cuppens, Frédéric Cuppens |
CRiSIS | 2 |
| 2007 | Improvement of AODV Routing in Dense networksabstractMobile Ad Hoc networks (MANETs) consist of wireless hosts that may move often. They don't use some existing infrastructure so they are very useful in crisis conditions as earthquakes, or military actions. However, MANETs have low bandwidth. The well-known Ad Hoc On-demand Distance Vector (AODV) protocol broadcasts control packets to determine new paths or reinitialize paths when they're broken. Consequently, it is important to reduce the number of control packets. We propose an algorithm which reduces the search area of AODV protocol. Source broadcasts a route request that other nodes can transmit only if they are in an area whose form is a quadrilateral. The quadrilateral has a symmetry axis passing through the source and the destination. Reducing the search area reduces the number of control packets. To show the efficiency of our protocol, simulations have been carried out under NS-2 simulator. David Espes, Zoubir Mammeri |
WOWMOM | 1 |