VLDB 2026 Research / reviewers in the wild / expert
Fabien Autrel
dblp:90/5042
· DBLP profile ↗
14ranked-venue papers
1as first author
7since 2021 · last 2025
0000-0002-8403-515XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Investigating the Impact of Label-flipping Attacks against Federated Learning for Collaborative Intrusion Detection
Léo Lavaur, Yann Busnel, Fabien Autrel |
Comput. Secur. | 3 |
| 2024 | Systematic Analysis of Label-flipping Attacks against Federated Learning in Collaborative Intrusion Detection SystemsabstractWith the emergence of federated learning (FL) and its promise of privacy-preserving knowledge sharing, the field of intrusion detection systems (IDSs) has seen a renewed interest in the development of collaborative models. However, the distributed nature of FL makes it vulnerable to malicious contributions from its participants, including data poisoning attacks. The specific case of label-flipping attacks, where the labels of a subset of the training data are flipped, has been overlooked in the context of IDSs that leverage FL primitives. This study aims to close this gap by providing a systematic and comprehensive analysis of the impact of label-flipping attacks on FL for IDSs. We show that such attacks can still have a significant impact on the performance of FL models, especially targeted ones, depending on parameters and dataset characteristics. Additionally, the provided tools and methodology can be used to extend our findings to other models and datasets, and benchmark the efficiency of existing countermeasures. Léo Lavaur, Yann Busnel, Fabien Autrel |
ARES | 3 |
| 2024 | Demo: Highlighting the Limits of Federated Learning in Intrusion DetectionabstractFederated learning (FL) is a distributed learning paradigm enabling participants to collaboratively train a machine learning (ML) model. In security-oriented tasks, FL can be used to share attack knowledge, without sharing participants' local data. Recent research results reveal that highly heterogeneous data distributions can prevent federations from converging towards an appropriate global model. Moreover, maintaining trustworthiness is challenging, as FL-based collaborative intrusion detection systems (CIDSs) are vulnerable to malicious updates. In this demonstration paper, we present critical examples of these challenges using a set of standardized public datasets and a dedicated automation tool. We review the impact of heterogeneity using different data-distribution, before looking at a scenario with malicious actors. Léo Lavaur, Yann Busnel, Fabien Autrel |
ICDCS | 3 |
| 2024 | Intent-Based Attack Mitigation through Opportunistic Synchronization of Micro-ServicesabstractThe escalating number of cyberattacks poses a significant threat to digital infrastructures. Defining and deploying accurate countermeasures is challenging because of (1) the variety of threats and their possible evolution over time and (2) the need to enforce them as fast as possible, especially for fast-propagating attacks. Intent-Based Networking (IBN) stands for a promising solution for security management, especially to mitigate attacks through the specification of reaction intents, saving time and avoiding error-prone tasks. Nevertheless, most current IBN solutions rely on centralized architectures performing time-consuming operations, which makes them inappropriate to timely deploy countermeasures, especially in the case of fast-propagating attacks spreading large-scale systems. As a solution to shorten the reaction time while supporting scalability, we first consider fast micro-services technologies (e.g., Unikernels) as the substrate of security functions acting as Policy Enforcement Points (PEP). Second, we propose to enable an opportunistic synchronization of those PEPs to react, at least partially but autonomously, against the ongoing attacks in a decentralized fashion. Such a solution raises challenges related to the consistency and performance of the overall enforced reaction policies. This paper presents the early stage of the PhD, outlining the specific challenges, limitations, and research required to leverage decentralized reaction using opportunistic synchronization of micro-services in an IBN framework for security. Do Duc Anh Nguyen, Pierre Alain, Fabien Autrel, Ahmed Bouabdallah, Jérôme François |
NetSoft | 3 |
| 2024 | How Fast Does Malware Leveraging EternalBlue Propagate? The case of WannaCry and NotPetyaabstractMalware attacks pose a critical threat to digital infrastructures particularly given their potential for widespread and fast propagation. Mitigating them involves limiting their expansion, which requires a thorough understanding of their propagation mechanisms. However, few studies have been conducted on their propagation behaviors in large-scale networks. In this paper, we present the results of an empirical study focusing on the propagation strategy of WannaCry and NotPetya, two malware instances leveraging EternalBlue, an exploit developed by the NSA and stolen by The Shadow Brokers hacker group, which has been used to implement rapid spreading in some mal-ware instances. Our experiments qualify the speed of infection, epidemic behavior, and spreading strategies in a local network of 50 VMs. We have especially measured for WannyCry that (1) nearly 20% of infections are processed in less than 50 seconds, and (2) up to 16 hosts are infected in a 100-second period. Our results provide meaningful insights on malware propagation to support the design of effective countermeasures. Do Duc Anh Nguyen, Pierre Alain, Fabien Autrel, Ahmed Bouabdallah, Jérôme François, Guillaume Doyen |
NetSoft | 3 |
| 2023 | A Robust Approach for the Detection and Prevention of Conflicts in I2NSF Security PoliciesabstractIn order to maintain a sufficient protection level of their infrastructure, automating security management is at the core of current operators issues. The Interface to Network Security Function (I2NSF) is a framework that takes part of the Intent-Based Networking (IBN) paradigm. It consists of automating the translation of high-level policies into low-level configurations of Network Security Functions (NSF) and appears as a promising way to overcome the complexity of this challenging task. However, if the I2NSF framework provides a comprehensive architectural and data model for such an automation, it provides neither detection nor prevention mechanisms against conflicting security requirements. In this paper, we assess to what extent state-of-the-art mechanisms can shift the initial I2NSF proposal toward a robust framework. As such, we extend (1) the reference architecture to integrate some checking components and (2) the consumer-facing data model to enforce separation constraints and partial ordering relationships. By considering a large set of rules and conflicting situations, we evaluate the performance of our solution within an early implementation of I2NSF achieved in an IETF Hackathon. Do Duc Anh Nguyen, Fabien Autrel, Ahmed Bouabdallah, Guillaume Doyen |
NOMS | 2 |
| 2022 | The Evolution of Federated Learning-Based Intrusion Detection and Mitigation: A SurveyabstractIn 2016, Google introduced the concept of Federated Learning (FL), enabling collaborative Machine Learning (ML). FL does not share local data but ML models, offering applications in diverse domains. This paper focuses on the application of FL to Intrusion Detection Systems (IDSs). There, common criteria to compare existing solutions are missing. In particular, this survey shows: (i) how FL-based IDSs are used in different domains; (ii) what differences exist between architectures; (iii) the state of the art of FL-based IDS. With a structured literature survey, this work identifies the relevant state of the art in FL–based intrusion detection from its creation in 2016 until 2021. It provides a reference architecture and a taxonomy to serve as guidelines to compare and design FL-based IDSs. Both are validated with the existing works. Finally, it identifies research directions for the application of FL to intrusion detection systems. Léo Lavaur, Marc-Oliver Pahl, Yann Busnel, Fabien Autrel |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2015 | Context Aware Intrusion Response Based on Argumentation Logic
Tarek Bouyahia, Fabien Autrel, Nora Cuppens, Frédéric Cuppens |
CRiSIS | 2 |
| 2014 | ISER: A Platform for Security Interoperability of Multi-source Systems
Khalifa Toumi, Fabien Autrel, Ana R. Cavalli, Sammy Haddad |
CRiSIS | 2 |
| 2009 | Reaction Policy Model Based on Dynamic Organizations and Threat Context
Fabien Autrel, Nora Cuppens, Frédéric Cuppens |
DBSec | 1 |
| 2009 | An ontology-based approach to react to network attacksabstractIntrusion detection requirements enforced by Intrusions Detection Systems (IDSs) are generally considered independently from the remainder of the security policy. Our approach is to consider that intrusion detection requirements are actually a part of the access control policy. This provides means to formally specify in a reaction policy what should happen in case of intrusion. It is then possible to integrate these requirements into a deploying process in order to automatically configure security components. In this paper, we propose a contextual and ontology-based approach to express and instantiate this reaction policy. We then define a reaction process based on the concepts of dynamic threat organisation and threat contexts and a set of rules used to map alerts onto threat contexts to perform the instantiation of the policy-based reaction in response to the detected intrusion. Nora Cuppens, Frédéric Cuppens, Fabien Autrel, Hervé Debar |
Int. J. Inf. Comput. Secur. | 3 |
| 2007 | Advanced Reaction Using Risk Assessment in Intrusion Detection Systems
Wael Kanoun, Nora Cuppens, Frédéric Cuppens, Fabien Autrel |
CRITIS | 4 |
| 2004 | Decentralized Publish-Subscribe System to Prevent Coordinated Attacks via Alert Correlation
Joaquín García 0001, Fabien Autrel, Joan Borrell, Sergio Castillo-Perez, Frédéric Cuppens, Guillermo Navarro-Arribas |
ICICS | 2 |
| 2002 | Recognizing Malicious Intention in an Intrusion Detection Process
Frédéric Cuppens, Fabien Autrel, Alexandre Miège, Salem Benferhat |
HIS | 2 |