VLDB 2026 Research / reviewers in the wild / expert
Ahmed Meddahi
dblp:69/5640
· DBLP profile ↗
25ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0002-9255-2114ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 2 first-author · 3 since 2021Security and privacy · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SIP-DDoS framework based on federated learning for collaborative anomaly detectionabstractAbstract With their inherent capacity for massive connectivity, ultra-low latency and high reliability, B5G networks provide an ideal infrastructure to support the diverse and dynamic requirements of IoT (Internet of Things) communication. Originally designed to initiate, modify and terminate multimedia sessions over IP networks, the Session Initiation Protocol (SIP), a standardized protocol developed by the 3GPP, has emerged as a promising protocol for enabling communication and coordination in IoT environments. Nonetheless, SIP encounters a multitude of Distributed Denial of Service (DDoS) threats, with INVITE flooding attacks emerging as a notable challenge. Traditional IoT-IDS (Intrusion Detection System) relies on machine learning models trained on local data of their deployment context. However, such a model may not detect some attack patterns observed in other deployment contexts. We propose a design approach based on federated learning, and in which different IDS collaborate to achieve early detection of any INVITE flooding attack faced by any of them. The results show the effectiveness of the framework in detecting and mitigating INVITE flooding attacks across a various of flow intensities under realistic SIP operational conditions. Performance evaluations under different relevant scenarios demonstrate the robustness of the proposed framework. Experiments show that federated learning (FL) enhances the analysis of SIP flooding attacks, improving accuracy from 47 to 99% through knowledge sharing. The FL model with a GRU architecture and a FedAvgM aggregation function delivers the best performance, even in varied scenarios. Oussama Sbai, Benjamin Allaert, Patrick Sondi, Ahmed Meddahi |
Cybersecur. | 4 |
| 2025 | Optimal Provisioning of Hybrid Service Function Chains with Guaranteed Disaster ResilienceabstractNetwork Function Virtualization (NFV) provides a flexible mechanism for deploying Virtual Network Functions (VNFs) within Service Function Chains (SFCs), thereby streamlining data transfers between end-users and edge/cloud resources. The distinct requirements for forward and backward traffic—each carrying different types of content—give rise to Hybrid SFCs (HSFCs), which must be carefully designed to address unique deployment and performance concerns. However, achieving robust disaster resilience in HSFC-based NFV environments poses significant challenges, as natural or hardware-induced disruptions within Disaster Zones (DZs) can degrade service quality or even cause outages. This paper describes the Resilient Hybrid Service Function Chain Resource Optimization (R-HSFC-RO) approach to ensure both efficient resource utilization and sustained service delivery under disaster conditions. Our model considers bandwidth consumption, computational resource allocation for VNF execution, VNF instantiation overheads, and end-to-end latency requirements. For resolution, we propose a Mixed-Integer Linear Programming (MILP) model and Constraint Programming (CP), thereby enabling optimal solutions. Simulation results demonstrate that R-HSFC-RO reduces total costs by up to 50%, enhances disaster resilience, and maintains high operational efficiency. Mohamed Abderrahmane Madani, Fen Zhou 0001, Ahmed Meddahi |
ISCC | 3 |
| 2025 | Evaluation of Multi-Relay D2D Communication for Cooperative SLAM in Metaverse ContextabstractIn conventional deployments, infrastructure-based communication routes all traffic through the gNB and core network, providing centralized orchestration and global persistence. However, in indoor scenarios such as museums, where users are physically co-located, this mode may introduce unnecessary delay and backhaul congestion. Device-To-Device (D2D) relaying emerges as a promising alternative, enabling nearby devices to exchange data directly, either in single-hop or multi-hop configurations. While existing studies on D2D multicast mainly focus on resource allocation for VR content sharing, the role of relay-based D2D multicast in supporting latency-sensitive Metaverse services has not been fully addressed. To this end, this paper extends the Simu5G platform with loosely coupled relay functionality and provides a comparative analysis of infrastructure and D2D multicast communication modes for cooperative Simultaneous Localization And Mapping (SLAM) in an indoor museum scenario. Simulation results show that relay-based D2D multicast can serve as a complementary solution to infrastructure-based communication, particularly when museum visitors move toward the cell edge. Wajdi Elleuch, Patrick Sondi, Ahmed Meddahi |
PEMWN | 3 |
| 2025 | An Enhanced Authentication Solution for Infrastructureless Vehicle EnvironmentsabstractRobust vehicle authentication is essential in order to ensure an effective audit of vehicle-to-vehicle (V2V) communications. However, most existing approaches rely on a centralized infrastructure to access both authorities' certificates andrevocation lists, thus making them ineffective in dynamic and infrastructureless environments. In this paper, we highlight this critical limitation, and propose a method which enables the vehicles to update their local authentication databases independently from infrastructure availability. Our approach aim to allow vehicles to perform V2V authentication using locally stored data, in order to ensure continuity of secure communications even when disconnected from the Infrastructure. We further analyze the probability of successful authentication under two scenarios, which are the first with up-to-date databases, and the second with outdated ones. The analytical results show that the authentication probability decreases to below$\mathbf{7 5 \%}$after$\mathbf{3 0}$hours of disconnection with long-lived certificates, while updates keep it above 90% in highway scenarios, even with short-lived certificates. These findings demonstrate the feasibility of maintaining reliable V2V authentication outside the infrastructure coverage, and point out the necessary improvements for evolving towards secure and auditable V2V communications. Marwa Slimene, Nathalie Mitton, Patrick Sondi, Ahmed Meddahi |
WiMob | 4 |
| 2025 | A Comparative Survey of Authentication Schemes Suitable for the Audit of V2X CommunicationsabstractThe rise of connected vehicles has transformed transportation by enhancing mobility, safety, and driving comfort. However, ensuring secure and trustworthy communications in vehicular networks remains a challenge due to the risks of malicious activities, privacy breaches, and unauthorized access. This paper aims to address these challenges by evaluating and comparing existing authentication schemes used in vehicular communications. Specifically, the article focuses on analyzing their efficiency, security, and applicability for audit systems in Vehicle-to-Everything (V2X) communications. The main objectives of this study are to provide a clear taxonomy of authentication strategies, evaluate their ability to preserve anonymity and integrity while ensuring accountability, and identify protocols suitable for robust audit mechanisms. Through qualitative and quantitative analysis, this paper highlights the strengths and limitations of current solutions, emphasizing aspects like scalability, privacy preservation, and infrastructure dependency. Findings indicate that combining Public Key Infrastructure (PKI)-based methods with Blockchain technology can yield secure and transparent communication solutions. Nevertheless, significant hurdles remain in scenarios lacking infrastructure support. The key contribution of this work consists in identifying authentication protocols that successfully balance security, efficiency, and privacy–while still enabling effective audits–thereby laying the groundwork for designing reliable, trust-oriented audit systems in tomorrow’s vehicular networks, including outside the infrastructure coverage. Marwa Slimene, Amira Chriki, Nathalie Mitton, Patrick Sondi, Ahmed Meddahi |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2025 | Deploying Disaster-Resilient Service Function Chains Using Adaptive Multi-Path RoutingabstractNetwork Function Virtualization (NFV) is a new technology that deploys network services and functions as software components in data centers and cloud environments. One of its key applications is Service Function Chain (SFC), which chains a set of Virtual Network Functions (VNFs) in a specific order to deliver a desired service. However, deploying NFV and SFC networks faces challenges, particularly in terms of disaster resiliency. This encompasses natural disasters and hardware failures, which can disrupt network operations and lead to service interruption or degradation across an entire disaster zone (DZ). Therefore, designing NFV and SFC networks that can withstand disasters while providing high levels of service availability and reliability is important. This paper presents a new method for protecting SFCs using adaptive multi-path routing. The proposed Multi-path Protection (MP) method has the advantage of reducing the amount of reserved bandwidth on backup paths by distributing SFC traffic over multiple DZ-disjoint working paths. The problem being addressed involves VNFs placement, routing SFCs, and implementing protection mechanisms. The objective is to minimize network resource consumption, including both the bandwidth used by request routing paths and the computing resources for VNF execution. To solve this multi-dimensional optimization problem, a path-adaptive and flow-based integer linear program (ILP) is proposed to provide the optimal solution in sall-size network settings. We also propose a heuristic approach that offers the near-optimal solution in a time-efficient way. Comprehensive simulation results show that the proposed MP strategy outperforms traditional Dedicated Protection (DP) in terms of bandwidth and processing resource consumption, resulting in a significant gain up to 20%. Mohamed Abderrahmane Madani, Fen Zhou 0001, Ahmed Meddahi |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Deploying Disaster-Resilient Service Function Chains Using Adaptive Multi-Path RoutingabstractNetwork Function Virtualization (NFV) is a technology that deploys network services and functions as software components in data centers and cloud environments. One of its key applications is Service Function Chain (SFC), which chains Virtual Network Functions (VNFs) in a specific order to deliver a desired service. However, disaster resiliency is a critical challenge when deploying NFV and SFC, as natural disasters and hardware failures can disrupt network operations and lead to service interruption or degradation across an entire disaster zone (DZ). This paper presents a new method for protecting SFCs using multi-path routing, which enables to split an SFC on multiple DZ-disjoint working paths and leverage a shared backup path for protection. The proposed Multi-path Protection (MP) minimizes network resource consumption, including both the bandwidth for request routing and the computing resources for VNF execution. We propose a heuristic approach that offers a near-optimal SFC MP solution in a time-efficient way. Numerical results show that the proposed MP strategy outperforms traditional Dedicated Protection (DP) in terms of resource consumption, resulting in significant gain up to 20%. Mohamed Abderrahmane Madani, Fen Zhou 0001, Ahmed Meddahi |
CNSM | 3 |
| 2023 | Leveraging Blockchain for a Robust and Scalable Device Identification in LoRaWANabstractIn Long Range wide Area Network (LoRaWAN) 1.1 networks, end devices must be activated via Over-The-Air Activation (OTAA) to securely send and receive data. Activation involves a two-step process: identification using a unique identifier (DevEUI) and authentication through a Message Integrity Code computed with a pre-shared key. Both DevEUI and pre-shared keys must be provisioned beforehand. We propose a scalable blockchain-based decentralized model to improve the identification of untrusted end devices during LoRaWAN's OTAA without altering the protocol, thus allowing immediate deployment in existing networks. Our approach accommodates corrupted devices and stores data in a distributed, permanent, and publicly auditable manner while facilitating rapid detection and identification of untrusted devices. Adapting blockchain technology to LoRaWAN resource-constrained environment, we design a specific data block structure combined with a “Proof of Identification” (PoI), while maintaining distributed consensus. This approach ensures a robust and scalable LoRaWAN join procedure while enhancing device identification and traceability. Through simulation models that combine our blockchain proposal with LoRaWAN 1.1 OTAA specification, we show improved performance for various metrics, e.g., for 10,000 devices, identification is two times faster using the blockchain. Lounès Meddahi, Ahmed Meddahi, Patrick Sondi, Fen Zhou 0001 |
ISNCC | 2 |
| 2022 | Evaluating the cost of beyond AES-128 LoRaWAN securityabstractLoRaWAN is one of the most popular Internet of Things radio communication technologies since it allows data to be transmitted over long distances with low power consumption on unlicensed ISM bands. Devices used with LoRaWAN are often constrained for reasons of manufacturing cost and to save energy as they are most often battery-powered. As a consequence, security mechanisms chosen for such devices must be lightweight. The LoRaWAN standard relies on AES-128 for encryption and authentication, using a pre-shared key. With the increasing amount of computational power at hand and the advent of quantum cryptography, the use of short AES keys without renewal for long periods of time is a potential weakness. However, using longer keys in LoRaWAN impacts end devices in terms of processing time and energy consumption. It might also require adaptations in the protocol design. This paper investigates the cost of using different AES key sizes with different payload sizes on an off-the-shelf LoRaWAN platform. Our results show that costs in terms of delay and energy consumption are moderate and using longer key sizes is a practical solution to increase the security of LoRaWAN. Phithak Thaenkaew, Bruno Quoitin, Ahmed Meddahi |
ISNCC | 3 |
| 2021 | SIP-GAN: Generative Adversarial Networks for SIP traffic generationabstractGenerative adversarial networks (GANs) are one of the major ML techniques for data augmentation and classification, in the field of image processing, computer vision and natural language processing. However, in the field of data networks and protocols the use of GANs for data generation and classification (at packet level) is very limited or relatively new. Although, GANs specific properties and characteristics can be highly relevant in this context (unsupervised technique). This limitation, is even more critical if we consider network protocols or communication oriented protocols such as SIP VoIP To address this problem, we propose “SIP-GAN” an extension and adaptation of GANs model for SIP, aiming to process and generate SIP traffic at packet level. The proposed generic model includes an encoder, a generator, and a decoder The encoder extracts information from pcap data, associates and converts these SIP data into a GAN image representation. The generator is based on a DCGAN model, that generates new SIP dataset from each extracted image. The decoder combines the generated images and reconstruct a valid pcap file (SIP file). A specific testbed, with a formal and practical analysis, demonstrate the validity of the generated data, from the SIP-GAN model. Also, the experimental and performance results are globally satisfactory, showing the relevance of our proposed SIP-GAN based traffic generator in this context. Amar Meddahi, Hassen Drira, Ahmed Meddahi |
ISNCC | 3 |
| 2021 | Security and Privacy in Smart CitiesabstractInternational audience Chalee Vorakulpipat, Ryan Kok Leong Ko, Qi Li 0002, Ahmed Meddahi |
Secur. Commun. Networks | 4 |
| 2021 | Leveraging Network Functions Virtualization Orchestrators to Achieve Software-Defined Access Control in the CloudsabstractNetwork Functions Virtualization (NFV) has been widely recognized as an effective way to implement and consolidate hardware-based network functions by using software-based approaches, with a potential to significantly reducing CAPEX and OPEX. In particular, NFV orchestrators (e.g., Tacker, Cloudify, and ONAP) play a vital role in managing and orchestrating various virtualized network resources (e.g., VMs, Virtualized Network Functions), and TOSCA is one of the standard data models to fulfil such a role. However, it remains unclear how the security mechanisms can be seamlessly integrated into the entire lifecycle of those virtualized network assets. Starting with a comparative analysis on the available NFV orchestrators, we extend the TOSCA model to incorporate security attributes of interest, and leverage the extended model to create access control policies at cloud scale. Specifically, a security orchestrator is developed, which contains a TOSCA-parser and a novel tenant-specific access control paradigm. One of the salient features of our security orchestrator is that it allows to dynamically generate access control models and policies for different tenant domains, resulting in a flexible and scalable protection coverage that is across different NFV layers and multiple data centers. To validate its feasibility and effectiveness, we develop a security orchestrator prototype and test its performance with respect to throughput, scalability, and adaptability. The experimental results demonstrate that all the desirable properties can be achieved, and the throughput of our security orchestrator can be maintained at a satisfactory level regardless of the varying number of tenants, users, or objects that are deployed in the cloud. Montida Pattaranantakul, Ruan He, Zonghua Zhang, Ahmed Meddahi, Ping Wang 0003 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | On Achieving Trustworthy Service Function ChainingabstractService Function Chaining (SFC) has recently received considerable attentions from both industry and academia, due to its potential for improving the flexibility of provisioning and composition of Virtualized Network Functions (VNFs) to suit application-specific needs. From a security perspective, there is a gap between high-level SFC policy specification and its enforcement in the data plane. It cannot guarantee that the deployed VNFs are always chained in an expected manner, or the packet flows of a particular service chain are sequentially forwarded to the intended and legitimate VNFs strictly compliant with the specified SFC policy. This lack of assurance leaves the door open for attackers to maliciously manipulate the service chain by evading from security functions such as firewall, Deep Packet Inspection (DPI), etc., or deviating the packet flows from their original service function path, ultimately leading to the violation of SFC policy. It is therefore important to have an efficient self-checking mechanism in place, ensuring the SFC to be implemented in a secure and dependable way. This paper presents a new security primitive - Lite Identity-based Ordered Multisignature scheme (ChainSign in short), which enforces all intended VNFs in a particular service chain to sequentially sign the packet received. Then the last hop of the chain will verify the signature, so as to validate whether all of them work as expected and have not been compromised, while satisfying the security properties of concern (i.e., the consistency in VNF chaining, their authenticities and sequences in a service chain). In addition to the implementation, we leverage the IETF Network Service Header (NSH) to carry the signature generated from our proposed scheme. The experiments show that ChainSign can preserve all identified security properties with minimal overhead. Montida Pattaranantakul, Qipeng Song, Yanmei Tian, Zonghua Zhang, Ahmed Meddahi, Chalee Vorakulpipat |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2019 | Footprints: Ensuring Trusted Service Function Chaining in the World of SDN and NFV
Montida Pattaranantakul, Qipeng Song, Yanmei Tian, Zonghua Zhang, Ahmed Meddahi |
SecureComm (2) | 6 |
| 2018 | Pancake graphs for lookup acceleration and optimization in P2P networksabstractLookup services is still a key challenge in all distributed systems and particularly for P2P based services (e.g. distributed SDN node controllers, social networking…). In these networks, node searching for a specific service or resource has to discover the “best” path to the node offering the requ ested resource or service. Since P2P networking is implemented at application layer, the given optimized path from a source node to a destination one, in terms of number of hops is not necessarily the best path in terms of physical parameters (e.g. delay, physical proximity). For this, the lookup process optimization is still a real challenge in some environments, particularly for delay sensitive services. In this context, various topologies have been proposed in the literature such as: ring, tore, star, hypercub, De Bruijn graph, and skip graph. In this paper, we propose a new approach using Pancake graphs, for structuring the P2P topology in order to optimize the lookup process. The proposed solution is compared to some main existing solutions. Under certain conditions, the simulation results show better performance compared to existing approaches. Mourad Amad, Djamil Aïssani, Ahmed Meddahi, Aimed Merabet, Noureddine Sekhriou |
Web Intell. | 3 |
| 2013 | A weighted QoS aware multipath routing process in Mobile Ad hoc networksabstractIn this paper, we address the quality aware routing issue in MANET: Mobile Ad hoc networks. The MANET network is based on dynamic radio links. Our contribution improves the multipath routing in Mobile Ad hoc networks based on the path quality, path stability and QoS awareness. Prediction methods are used in order to estimate the path quality. The paths will be sorted and weighted according to the application class. Route selection process is based on multi-criteria selection method. Interactions between routing layer and MAC layer are exploited to get the path quality. To take into account the application class in the routing process, cross layer interactions between routing layer and upper layers are needed. Application' classes will be defined according to the user's requirement thresholds defined by the ITU G-1010 recommendation [1]. A simulation study under NS2 will be conducted in this paper in order to validate our contribution. Mariem Thaalbi, Nabil Tabbane, Tarek Bejaoui, Ahmed Meddahi |
ISCC | 4 |
| 2012 | HPM: A novel hierarchical Peer-to-Peer model for lookup acceleration with provision of physical proximity
Mourad Amad, Ahmed Meddahi, Djamil Aïssani, Zonghua Zhang |
J. Netw. Comput. Appl. | 2 |
| 2008 | A scalable P2P model for optimizing application layer multicastabstractMulticast avoids sending repeated packets over the same network links and thus offers the promise of supporting multimedia streaming over wide-area networks. Previously, two opposite multicast schemes forward-path forwarding and reverse-path forwarding have been proposed on top of structured peer-to-peer (p2p) overlay networks. In this paper, we propose a new model for optimizing application layer multicast in the context of Peer-to-Peer networks (structured and unstructured). In this contribution, we consider two approaches for multicast tree construction: a "primitive " approach, and an optimized one based on a distributed algorithm. The proposed model inherits from main P2P attributes such as: scalability, fault tolerance, while taking into consideration the respective characteristics of "one to many" and "many to many" applications. We also give a performance evaluation for validation and comparison purposes. For this we consider some main existing application layer multicast protocols. Mourad Amad, Ahmed Meddahi |
AICCSA | 2 |
| 2008 | A P2P Framework for Decentralized Xconferencing and Its JXTA ImplementationabstractIETF Xcon working group and ITU-T SG 16 specify a generic framework for centralized multipoint conferencing applications. The centralized architecture adopted by these specifications are not well adapted to today open and dynamic networks and have well-know drawbacks. In this paper, we present a P2P approach for supporting conference type services in a decentralized architecture. This approach provides new signaling mechanisms and components for coordinating, managing and controlling a conference system, in a dynamic network of peers. The implementation based on a JXTA middleware, shows that P2P model through its self-organizing characteristic can improve conferencing applications performance by providing a maximal autonomy for a minimal service configuration. Ahmed Meddahi, Gilles Vanwormhoudt, Amro Malkawi |
CISIS | 1 |
| 2008 | A Scalable Approach for Application Layer Multicast in P2P NetworksabstractApplication layer multicast (ALM) is considered as an attractive approach for implementing wide area multicast services. In ALM, multicast functionality is implemented at the edge instead of the core network (routers). As opposed to network-layer multicast, application layer multicast requires no infrastructure support and can be easily deployed in the Internet. In this paper, we propose a new generic and scalable approach for optimizing application layer multicast in the context of Peer-to-Peer networks (structured and unstructured). This approach benefits from P2P properties and characteristics. In this contribution, we consider two approaches for multicast tree construction: a primitive approach, and an optimized one based on a distributed algorithm. The proposed protocol inherits from main P2P attributes such as: scalability, fault tolerance. Performance evaluation shows that results are globally satisfactory compared to the main existing application layer multicast protocols. Mourad Amad, Ahmed Meddahi |
PerCom | 2 |
| 2006 | "P4L": A Four Layers P2P Model for Optimizing Resources Discovery and Localization
Mourad Amad, Ahmed Meddahi |
APNOMS | 2 |
| 2006 | "MOSQoS": Subjective VoIP Quality for Feedback Control and Dynamic QoS AdaptationabstractSupporting QoS for VoIP is a topic that clearly remain of importance. Existing QoS mechanisms for voice over IP need to be adapted. This is essentially due to the high dynamicity and variability of subjective voice quality perception, particularly in some critical conditions (ex. mobile networks). In this paper, we present an architecture, called "MOSQoS", that integrates subjective voice quality assessment into a dynamic QoS loop control. This QoS loop control is based on a subjective and dynamic voice quality evaluation (MOS score). It maintains as constant as possible, a predefined target MOS score during the entire voice session. To achieve this approach, we implement "PE-Model" for subjective voice quality evaluation and combine it with a signaling protocol to dynamically control and optimize network resources such as: queuing allocation and congestion thresholds. Tests and measures obtained through an implementation of the "MOSQoS" approach, show that results in terms of feasibility and performance, are globally satisfactory. Ahmed Meddahi, Hossam Afifi, Gilles Vanwormhoudt |
ICC | 1 |
| 2006 | "Packet-E-Model": E-Model for VoIP quality evaluation
Ahmed Meddahi, Hossam Afifi |
Comput. Networks | 1 |
| 2005 | Toward Feasibility and Scalability of Session Initiation and Dynamic QoS Provisioning in Policy-Enabled Networks
Kamel Haddadou, Yacine Ghamri-Doudane, Marc Girod-Genet, Ahmed Meddahi, Laurent Bernard, Gilles Vanwormhoudt, Hossam Afifi, Nazim Agoulmine |
NETWORKING | 4 |
| 2003 | "Packet-e-model": e-model for wireless VoIP quality evaluationabstractQuality of service for Voice over IP on wireless links (WiFi) has to be measured by the perceptual speech quality. How can this subjective measures be "captured" by models that rely on objective measures based on transmission delays and packet losses monitoring. These parameters which are common on such links can affect dramatically speech quality. In this paper, The ITU-T legacy e-Model, recently proposed to qualify audio and well adapted to circuit switched networks is adapted for packet switched networks. A new model to automatically quantify or measure the speech quality perception for voice/audio communications over IP. named here "packet-e-Model", adapts the e-Model to packet networks in general with a special emphasis on WiFi. Ahmed Meddahi, Hossam Afifi, Djamal Zeghlache |
PIMRC | 1 |