VLDB 2026 Research / reviewers in the wild / expert
Wafa Ben Jaballah
dblp:81/10000
· DBLP profile ↗
19ranked-venue papers
10as first author
5since 2021 · last 2025
0000-0002-6699-6846ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 4 since 2021Computer networks · 5 · 5 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | CyberNEMO: Enhancing End-to-End Cybersecurity and Privacy in the IoT-Edge-Cloud ContinuumabstractAccording to the EU State of Cybersecurity report by the European Union Agency for Cybersecurity (ENISA), the number of cybersecurity-related incidents will increase by 24 percent by 2025, with ransomware and DoS/DDoS attacks being the most common. The emergence of new threats [1] and the consolidation of existing ones require doubling of efforts in proactive prevention and a decisive increase in research dedicated to cybersecurity. CyberNEMO (End-to-end Cybersecurity to NEMO meta-OS) project emerges as an evolution of the NEMO (Next Generation Meta Operating System) platform, designed to provide a secure, trustworthy, and robust execution environment across the IoT-Edge-Cloud computing continuum. Leveraging NEMO modular meta-operating system (mOS) framework, CyberNEMO introduces advanced cybersecurity and privacy-preserving mechanisms, emphasizing Zero Trust principles. This paper presents the CyberNEMO architecture, details its core innovative technologies, and describes its validation strategy through diverse living labs-including Smart Energy, Smart Water, Smart Manufacturing, Healthcare, Multimedia Distribution, and Smart Farming scenarios-demonstrating end-to-end cybersecurity and real-time threat mitigation capabilities, aligned with Europe's strategic cybersecurity goals. Theodore B. Zahariadis, Artemis C. Voulkidis, Ilias Nektarios Seitanidis, Andreas E. Papadakis, Alberto del Río, Javier Serrano 0003, David Jiménez, Antonio Pastor 0001, Diego R. López, Alejandro Muñiz, Mattin Antartiko Elorza Forcada, Ana Méndez, Wafa Ben Jaballah, Rosaria Rossini, Maria Belesioti, Ioannis P. Chochliouros, Marco Angelini, Vasileios Megalooikonomou, Carmela Occhipinti, Luigi Briguglio, Alexandru Plesa, Vladut Dinu, Mohammad Ghoreishi, Mostafa Jabari, Dimitrios Skias, Konstantinos Sakatis, Ioannis Papaefstathiou |
SRDS | 13 |
| 2023 | SoK: Secure Aggregation Based on Cryptographic Schemes for Federated LearningabstractSecure aggregation consists of computing the sum of data collected from multiple sources without disclosing these individual inputs. Secure aggregation has been found useful for various applications ranging from electronic voting to smart grid measurements. Recently, federated learning emerged as a new collaborative machine learning technology to train machine learning models. In this work, we study the suitability of secure aggregation based on cryptographic schemes to federated learning. We first provide a formal definition of the problem and suggest a systematic categorization of existing solutions. We further investigate the specific challenges raised by federated learning and analyze the recent dedicated secure aggregation solutions based on cryptographic schemes. We finally share some takeaway messages that would help a secure design of federated learning and identify open research directions in this topic. Based on the takeaway messages, we propose an improved definition of secure aggregation that better fits federated learning. Mohamad Mansouri, Melek Önen, Wafa Ben Jaballah, Mauro Conti |
Proc. Priv. Enhancing Technol. | 3 |
| 2022 | Learning from Failures: Secure and Fault-Tolerant Aggregation for Federated LearningabstractFederated learning allows multiple parties to collaboratively train a global machine learning (ML) model without sharing their private datasets. To make sure that these local datasets are not leaked, existing works propose to rely on a secure aggregation scheme that allows parties to encrypt their model updates before sending them to the central server that aggregates the encrypted inputs. In this work, we design and evaluate a new secure and fault-tolerant aggregation scheme for federated learning that is robust against client failures. We first develop a threshold-variant of the secure aggregation scheme proposed by Joye and Libert. Using this new building block together with a dedicated decentralized key management scheme and an input encoding solution, we design a privacy-preserving federated learning protocol that, when executed among n clients, can recover from up to failures. Our solution is secure against a malicious aggregator who can manipulate messages to learn clients’ individual inputs. We show that our solution outperforms the state-of-the-art fault-tolerant secure aggregation schemes in terms of computation cost on the client. For example, with an ML model of 100,000 parameters, trained with 600 clients, our protocol is 5.5x faster (1.6x faster in case of 180 clients drop). Mohamad Mansouri, Melek Önen, Wafa Ben Jaballah |
ACSAC | 3 |
| 2021 | Spatial and Temporal Cross-Validation Approach for Misbehavior Detection in C-ITS
Mohammed Lamine Bouchouia, Jean-Philippe Monteuuis, Ons Jelassi, Houda Labiod, Wafa Ben Jaballah, Jonathan Petit |
RCIS | 5 |
| 2021 | FADIA: fairness-driven collaborative remote attestationabstractInternet of Things (IoT) technology promises to bring new value creation opportunities across all major industrial sectors. This will yield industries to deploy more devices into their networks. A key pillar to ensure the safety and security of the running services on these devices is remote attestation. Unfortunately,existing solutions fail to cope with the recent challenges raised by large IoT networks. In particular, the heterogeneity of the devices used in the network affects the performance of a remote attestation protocol. Another challenge in these networks is their dynamic nature: More IoT devices may be added gradually over time. This poses a problem in terms of key management in remote attestation. Mohamad Mansouri, Wafa Ben Jaballah, Melek Önen, Md Masoom Rabbani, Mauro Conti |
WISEC | 2 |
| 2020 | Security and design requirements for software-defined VANETs
Wafa Ben Jaballah, Mauro Conti, Chhagan Lal |
Comput. Networks | 1 |
| 2020 | LiDL: Localization with early detection of sybil and wormhole attacks in IoT Networks
Pallavi Kaliyar, Wafa Ben Jaballah, Mauro Conti, Chhagan Lal |
Comput. Secur. | 2 |
| 2018 | The position cheating attack on inter-vehicular online gamingabstractNew in-car communications and entertainment systems have emerged, enabling interconnection of various components in vehicles (e.g., TVs, CD/DVD players, media players, and cell phones). With the new advances of automotive industry, car passengers embody the next consumers that will be targeted by online game providers. In this context, researchers on online games demonstrated the importance of the network's performance in determining the quality level perceived by consumers. Enabling games over Vehicular Ad hoc Networks (VANET) will require the design of secure architectures against threats, in order to not jeopardize the effectiveness of online gaming over VANET. These threats could increase the delivery delay of game events, leading to the unsatisfaction of passengers. In this paper, we address security threats for online gaming over VANET. In particular, we focus on a representative vehicular broadcast algorithm, and we discuss a cheating threat. Indeed, the attacker could use the location-aware game message exchange to cheat about his position, thus enforcing game events to be delayed, and reduce the quality of service. Finally, we run a thorough set of simulations to assess the impact of the position cheating attack to the online gaming over VANET. Wafa Ben Jaballah, Mauro Conti, Claudio E. Palazzi |
CCNC | 1 |
| 2018 | Whac-A-Mole: Smart node positioning in clone attack in wireless sensor networks
Wafa Ben Jaballah, Mauro Conti, Gilberto Filé, Mohamed Mosbah 0001, Akka Zemmari |
Comput. Commun. | 1 |
| 2017 | Android inter-app communication threats and detection techniques
Shweta Bhandari, Wafa Ben Jaballah, Vineeta Jain, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur, Mohamed Mosbah 0001, Mauro Conti |
Comput. Secur. | 2 |
| 2016 | A broadcast authentication scheme in IoT environmentsabstractBroadcast authentication has been widely investigated in the context of wireless sensor networks, Internet, RFIDs, and other scenarios. With the emergence of the Internet of Things that allows to connect different wireless technologies to provide services, broadcast authentication is crucial. Broadcast authentication aims to confirm that the sender of the message is the pretended source. In this direction, different state of the art proposals address this problem either by reducing the communication and overhead burden of security solutions, or by reducing the impact of attacks that aim to jeopordize the effectiveness of the service. In this paper, we propose an improved authentication scheme that is efficient for resource constrained devices. In particular, we shed the light into the security vulnerabilities of lightweight authentication mechanisms and their inability to tackle memory DoS attacks. Hence, we propose an improved scheme derived from the streamlined μTESLA, referred to as X-μTESLA. We demonstrate through our analytical and simulation results that X-μTESLA reduces communication overhead and yields a better performance in terms of energy consumption, memory overhead, and authentication delay than its previous counterparts. Bacem Mbarek, Aref Meddeb, Wafa Ben Jaballah, Mohamed Mosbah 0001 |
AICCSA | 3 |
| 2016 | The impact of malicious nodes positioning on vehicular alert messaging system
Wafa Ben Jaballah, Mauro Conti, Mohamed Mosbah 0001, Claudio E. Palazzi |
Ad Hoc Networks | 1 |
| 2015 | A secure authentication mechanism for resource constrained devicesabstractThe Internet of Things (IoT) is formed by smart objects and services to interact in real time, and that are deployed in various applications such as home monitoring, healthcare, and smart cities. However, security concerns should not be overlooked since an adversary could exploit the vulnerabilities in the design of some secure protocols. To this aim, in this paper we focus in particular on broadcast authentication in resource constrained devices. This security service is still in its infancy when devices are deployed in unattended environments. We propose a new authentication mechanism based on the state of the art protocol μTESLA, that aims to reduce the delay of forged packets in the receivers buffer, by efficiently computing the key disclosure delay. Then, we integrate this mechanism to two protocols of state of the art LEAP and LEAP++. Furthermore, we assess the feasibility of our solution with a thorough simulation study, taking into account the energy consumption, the delay of forged packets, and the authentication delay. Bacem Mbarek, Aref Meddeb, Wafa Ben Jaballah, Mohamed Mosbah 0001 |
AICCSA | 3 |
| 2014 | A secure alert messaging system for safe driving
Wafa Ben Jaballah, Mauro Conti, Mohamed Mosbah 0001, Claudio E. Palazzi |
Comput. Commun. | 1 |
| 2014 | Fast and Secure Multihop Broadcast Solutions for Intervehicular CommunicationabstractIntervehicular communication (IVC) is an important emerging research area that is expected to considerably contribute to traffic safety and efficiency. In this context, many possible IVC applications share the common need for fast multihop message propagation, including information such as position, direction, and speed. However, it is crucial for such a data exchange system to be resilient to security attacks. Conversely, a malicious vehicle might inject incorrect information into the intervehicle wireless links, leading to life and money losses or to any other sort of adversarial selfishness (e.g., traffic redirection for the adversarial benefit). In this paper, we analyze attacks to the state-of-the-art IVC-based safety applications. Furthermore, this analysis leads us to design a fast and secure multihop broadcast algorithm for vehicular communication, which is proved to be resilient to the aforementioned attacks. Wafa Ben Jaballah, Mauro Conti, Mohamed Mosbah 0001, Claudio E. Palazzi |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2013 | Lightweight Source Authentication Mechanisms for Group Communications in Wireless Sensor NetworksabstractThe problem of providing source authentication in Wireless Sensor Networks (WSNs) has been a roadblock to their large scale deployment, and is still in its infancy. In this paper, we present novel symmetric-key-based authentication schemes which exhibit low computation and communication authentication overhead. Our schemes are built upon the integration of a reputation mechanism, a Bloom filter, and a key binary tree for the distribution and updating of the authentication keys. Analytical evaluation of the proposed authentication schemes shows that the estimated average number of concatenated message authentication code in a packet from time 0 till time t is 4pt, with p is the probability that a key is corrupted. Our schemes are lightweight and efficient with respect to computation, communication and energy overhead. Wafa Ben Jaballah, Mohamed Mosbah 0001, Habib Youssef, Akka Zemmari |
AINA | 1 |
| 2013 | MASS: An efficient and secure broadcast authentication scheme for resource constrained devicesabstractMessage authentication for resource constrained devices is a challenging topic. Indeed, given the scarceness of on-board resources, solutions that do not rely on asymmetric key cryptography are in demand. A few solutions to address this issue have been proposed, and some have gained the status of state of the art thanks to their effectiveness and efficiency. However, even if state of the art solutions do provide sender-receiver on-the-fly message authentication, they are not able to tackle a few relevant attacks on received messages when the time dimension is taken into account. In particular, we first introduce two types of attacks: the switch command attack (where an adversary pretends to “switch” two messages over time-that is, altering the relative time ordering), and the drop command attack (where an adversary could pretend not having received a message previously sent from the legitimate sender). We then propose a new solution for broadcast authentication that copes with the above introduced attacks: MASS. Our analysis shows that MASS is effective in detecting both switch command and drop command attacks. Wafa Ben Jaballah, Mauro Conti, Roberto Di Pietro, Mohamed Mosbah 0001, Nino Vincenzo Verde |
CRiSIS | 1 |
| 2013 | Secure Verification of Location Claims on a Vehicular Safety ApplicationabstractTraffic safety through inter-vehicular communication is one of the most promising and challenging applications of Vehicular Ad-hoc Networks. In this context, information such as position, direction, and speed, is often broadcast by vehicles so as to facilitate fast multi-hop propagation of possible alert messages. Unfortunately, a malicious vehicle can inject bogus information or cheat about its position. In this work, we analyze the impact of a position cheating attack on an alert message application. We show that this weakness we found could be leveraged by an adversary in a very effective way. Furthermore, our analysis leads us to design a countermeasure to this threat. Finally, we run a set of simulations which confirm our findings. Wafa Ben Jaballah, Mauro Conti, Mohamed Mosbah 0001, Claudio E. Palazzi |
ICCCN | 1 |
| 2010 | An efficient source authentication scheme in wireless sensor networksabstractWireless sensor networks (WSN) are being widely deployed in military, healthcare and commercial environments. Since sensor networks pose unique challenges, traditional security methods, commonly used in enterprise networks, cannot be directly applied. In particular, broadcast source authentication is a critical security service in wireless sensor networks since it allows senders to broadcast messages to multiple receivers in a secure way. Public-key cryptography based solutions such as Elliptic Curve Cryptography (ECC) and Identity Based Cryptography (IBC) have been proposed but they all suffer from severe energy depletion attacks, resulting from a high computational and communication overheads. In this paper, we present a novel symmetric-key-based authentication scheme that exhibits low broadcast authentication overhead and thus avoiding the problem flaws inherent to the public key cryptography based schemes. Our scheme is built upon the integration of multi-level μTesla protocol, staggered authentication and the Bloom Filter. We show that our authentication scheme is very efficient in terms of energy consumption related to both computation and communication. Wafa Ben Jaballah, Aref Meddeb, Habib Youssef |
AICCSA | 1 |