Sami Zhioua

dblp:01/723 · DBLP profile ↗
← Back
20ranked-venue papers
7as first author
5since 2021 · last 2025
0000-0003-2029-175XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-authorDatabases, data management, data science and information retrieval · 7 · 1 first-author · 4 since 2021Theory of computation · 4 · 2 first-authorSoftware engineering, systems software and programming languages · 3 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Fair Client Selection in Federated Learning: Enhancing Fairness in Collaborative AI Systems
Ranim Bouzamoucha, Farah Barika Ktata, Sami Zhioua
DATA3
2024 On the impact of multi-dimensional local differential privacy on fairness
Karima Makhlouf, Héber Hwang Arcolezi, Sami Zhioua, Ghassen Ben Brahim, Catuscia Palamidessi
Data Min. Knowl. Discov.3
2024 When causality meets fairness: A survey
Karima Makhlouf, Sami Zhioua, Catuscia Palamidessi
J. Log. Algebraic Methods Program.2
2023 Gender and sex bias in COVID-19 epidemiological data through the lens of causality
abstract
The COVID-19 pandemic has spurred a large amount of experimental and observational studies reporting clear correlation between the risk of developing severe COVID-19 (or dying from it) and whether the individual is male or female. This paper is an attempt to explain the supposed male vulnerability to COVID-19 using a causal approach. We proceed by identifying a set of confounding and mediating factors, based on the review of epidemiological literature and analysis of sex-dis-aggregated data. Those factors are then taken into consideration to produce explainable and fair prediction and decision models from observational data. The paper outlines how non-causal models can motivate discriminatory policies such as biased allocation of the limited resources in intensive care units (ICUs). The objective is to anticipate and avoid disparate impact and discrimination, by considering causal knowledge and causal-based techniques to compliment the collection and analysis of observational big-data. The hope is to contribute to more careful use of health related information access systems for developing fair and robust predictive models.
Natalia Díaz Rodríguez, Ruta Binkyte, Wafae Bakkali, Sannidhi Bookseller, Paola Tubaro, Andrius Bacevicius, Sami Zhioua, Raja Chatila 0001
Inf. Process. Manag.7
2021 Machine learning fairness notions: Bridging the gap with real-world applications
Karima Makhlouf, Sami Zhioua, Catuscia Palamidessi
Inf. Process. Manag.2
2019 Finding a Needle in a Haystack: The Traffic Analysis Version
abstract
Abstract Traffic analysis is the process of extracting useful/sensitive information from observed network traffic. Typical use cases include malware detection and website fingerprinting attacks. High accuracy traffic analysis techniques use machine learning algorithms (e.g. SVM, kNN) and require to split the traffic into correctly separated blocks. Inspired by digital forensics techniques, we propose a new network traffic analysis approach based on similarity digest. The approach features several advantages compared to existing techniques, namely, fast signature generation, compact signature representation using Bloom filters, efficient similarity detection between packet traces of arbitrary sizes, and in particular dropping the traffic splitting requirement altogether. Experimental results show very promising results on VPN and malware traffic, but low results on Tor traffic due mainly to the single-size cells feature.
Abdullah Qasem, Sami Zhioua, Karima Makhlouf
Proc. Priv. Enhancing Technol.2
2015 Analyzing anonymity attacks through noisy channels
Sami Zhioua
Inf. Comput.1
2015 The web browser factor in traffic analysis attacks
abstract
Abstract Website fingerprinting is a known type of traffic analysis attacks that aims to identify which websites are visited in encrypted traffic traces. Recent work showed that some classifiers can successfully identify 90% of visited websites. Because web browsers use different rendering engines and networking application program interfaces (APIs), they tend to resist differently to website fingerprinting attacks. In this paper, we study to which extent popular web browsers can resist such attacks by analyzing the shape of their network traffic when fetching websites. To this end, five fine‐grained measures are used to point out very subtle differences in the network traffic of each web browser. Empirical analysis showed that, among six studied web browsers (Chrome, Firefox, Internet Explorer, Safari, Opera, and Tor Browser), Opera and Safari offer the highest resistance to website fingerprinting. Because most of existing fingerprinting techniques have been evaluated using Firefox web browser, we expect the accuracy results of existing work to be reduced in case Opera or Safari browser is used. Copyright © 2015 John Wiley & Sons, Ltd.
Sami Zhioua
Secur. Commun. Networks1
2014 Detecting Malicious Sessions Through Traffic Fingerprinting Using Hidden Markov Models
Sami Zhioua, Adnene Ben Jabeur, Mahjoub Langar, Wael Ilahi
SecureComm (1)1
2013 Testing probabilistic equivalence through Reinforcement Learning
Josée Desharnais, François Laviolette, Sami Zhioua
Inf. Comput.3
2013 Bootstrapping trust of Web services based on trust patterns and Hidden Markov Models
Hamdi Yahyaoui, Sami Zhioua
Knowl. Inf. Syst.2
2013 Tor traffic analysis using Hidden Markov Models
abstract
ABSTRACT Tor protocol has been designed primarily to defend against traffic analysis, which threatens privacy while using Internet. In this paper, we consider a very common threat model where an attacker can observe only the local traffic between the target Tor client and the first Tor relay. We show that even with this restricted threat model, the attacker can infer relevant information about the client's traffic, in particular when exactly new circuits are constructed. This is achieved by analyzing the Tor traffic using Hidden Markov Models (HMMs). The experimental analysis shows that the proposed HMM‐based approach has a high precision (93 % on average) and F‐measure (75 % on average). The more interesting part of the paper discusses how a local attacker can identify the hops forming circuits initiated by the Tor client victim. The attack is based on sampling the timing patterns of the most “probable” paths and then estimating the likelihood of each one of them given a circuit construction packets sequence. The experimental analysis shows that the proposed approach has an acceptable precision (around 50 %) as long as the time delay between HMM learning and the actual traffic analysis is relatively small. Copyright © 2012 John Wiley & Sons, Ltd.
Sami Zhioua
Secur. Commun. Networks1
2011 Bootstrapping Trust of Web Services through Behavior Observation
Hamdi Yahyaoui, Sami Zhioua
ICWE2
2010 A geometric view of mutual information: Application to anonymity protocols
abstract
Anonymity protocols are a special type of security protocols that focus on protecting the identities of communicating entities in a network communication. In this research we explore the notion of anonymity from an information-theoretic point of view. We see a protocol as a noisy channel that links a set of anonymous events (inputs) to a set of observables (outputs). The degree of anonymity of the protocol can then be expressed in terms of how much information is being leaked by the channel. In information theory, the information leaked by a noisy channel is given by the notion of mutual information. We propose an alternative measure of information leakage based on the vector configuration of the noisy channel's matrix. We show that a variant of this new measure coincides with mutual information which gives an interesting geometric interpretation to mutual information.
Sami Zhioua
ISITA1
2010 A New Information Leakage Measure for Anonymity Protocols
Sami Zhioua
SecureComm1
2009 Learning the Difference between Partially Observable Dynamical Systems
Sami Zhioua, Doina Precup, François Laviolette, Josée Desharnais
ECML/PKDD (2)1
2006 Testing Probabilistic Equivalence Through Reinforcement Learning
Josée Desharnais, François Laviolette, Sami Zhioua
FSTTCS3
2006 Common Criteria Approach to J2ME CLDC Security Requirements
Mourad Debbabi, Mohamed Mostafa Saleh, Chamseddine Talhi, Sami Zhioua
SoMeT4
2005 Java for Mobile Devices: A Security Study
abstract
Java 2 Micro-Edition connected limited device configuration (J2ME CLDC) is the platform of choice when it comes to running mobile applications on resource-constrained devices (cell phones, set-top boxes, etc.). The large deployment of this platform makes it a target for security attacks. The intent of this paper is twofold: first, we study the security architecture of J2ME CLDC; and second, we provide a vulnerability analysis of this Java platform. The analyzed components are: virtual machine, CLDC API and MIDP (mobile information device profile) API. The analysis covers the specifications, the reference implementation (RI) as well as several other widely deployed implementations of this platform. The aspects targeted by this security analysis encompass: networking, record management system, virtual machine, multi-threading and digital right management. This work identifies security weaknesses in J2ME CLDC that may represent sources of security exploits. Moreover, the results reported in this paper are valuable for any attempt to test or harden the security of this platform
Mourad Debbabi, Mohamed Mostafa Saleh, Chamseddine Talhi, Sami Zhioua
ACSAC4
2005 Security Analysis of Wireless Java
Mourad Debbabi, Mohamed Mostafa Saleh, Chamseddine Talhi, Sami Zhioua
PST4