EDBT 2026 Demo / reviewers in the wild / expert
Ahmad Fadlallah
dblp:12/5471
· DBLP profile ↗
10ranked-venue papers
0as first author
9since 2021 · last 2026
0000-0002-2284-5034ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Trust-based attack detection model for connected cars using a Subjective Logic based framework
Ahmad Ismail, Ahmad Fadlallah, Francesca Bassi, Rida Khatoun |
IWCMC | 2 |
| 2025 | Enhancing IoT Network Intrusion Detection with a New GraphSAGE Embedding Algorithm Using Centrality MeasuresabstractInternational audience Mortada Termos, Zakariya Ghalmane, Mohamed-el-Amine Brahmia, Ahmad Fadlallah, Ali Jaber, Mourad Zghal |
IoTBDS | 4 |
| 2025 | Integrating Centrality Measures in Federated Learning-Based Intrusion Detection SystemsabstractNetwork Intrusion Detection Systems (NIDS) are mechanisms designed to improve security by monitoring networks for signs of potential intrusions. While data-driven deep learning-based NIDSs have been popular for their superior performance, they are limited by their reliance on large amounts of data, often processed in a centralized manner. Federated Learning (FL) has thus emerged as a distributed paradigm to preserve privacy and data confidentiality, reduce communication costs, and promote collaborative learning. However, FL solutions require a high degree of generalization and adaptation to data and system heterogeneity. In this paper, we introduce a new approach to enhance the generalization of deep learning models in FL-based NIDS by integrating centrality measures. These centrality measures assess the importance of nodes in a cyber-physical system, providing valuable insights into network structures. By adopting these measures within the graph constructed from source and destination devices of network flows, we aim to enhance the model's understanding of how network dynamics correlate with intrusion patterns. For our experiments, we used two public datasets: CIC-IDS-2017 and CIC-ToN-IoT. To reflect real-world network variability, we utilized a realistic federated learning setup by distributing distinct parts of the datasets among FL clients. Our approach demonstrates an improvement of over 6 % in F1-score with the use of centrality measures, surpassing the traditional baseline approach. Our findings underscore the effectiveness of integrating centrality measures in FL-based NIDS, offering enhanced intrusion detection capabilities in heterogeneous network environments. Mortada Termos, Zakariya Ghalmane, Mohamed-el-Amine Brahmia, Ahmad Fadlallah, Ali Jaber, Mourad Zghal |
WCNC | 4 |
| 2025 | Tracking Vehicles in Cooperative Intelligent Transportation Systems: Attacks, Defense Solutions, and Future DirectionsabstractThe Cooperative Intelligent Transportation System (C-ITS) is vital in enhancing road safety, improving traffic efficiency, and increasing user comfort for pedestrians and drivers. However, as vehicle communications evolve, security threats that aim to undermine critical security services, such as data confidentiality, integrity, and privacy, have become crucial issues that must be addressed. Privacy, the freedom from interference or intrusion, is also considered one of the most significant challenges in computer networks and connected vehicles. Privacy in C-ITS can be protected by preventing both the collection of personal information and the tracking of vehicles by malicious users. Tracking is often achieved through the periodic transmission of Cooperative Awareness Messages (CAMs), which contain spatio-temporal information such as position and speed. We investigate key tracking-related critical issues in intelligent connected vehicles. We highlight current security challenges and attacks that lead to the unauthorized tracking of connected cars. We discuss various defense solutions proposed in the literature to address these challenges. We classify these solutions into two groups: general (addressing eavesdropping, Sybil, etc.) and pseudonym change (addressing correlation, swap, silent periods, and mix-zones). Finally, we explore robust future strategies to prevent tracking attacks on the C-ITS. Fadlallah Chbib, Sherali Zeadally, Ahmad Fadlallah, Rida Khatoun, Ali El Attar |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2024 | How Does Distributed Denial of Service Affect the Connected Cars Environment?abstractDistributed Denial-of-Service (DDoS) attacks are among the most insidious cyberattacks targeting any networking system. In the Internet domain, these attacks have demonstrated the capability of bringing down most systems for extended periods. In recent years, researchers have been exploring and simulating DDoS attacks against connected car systems. However, these simulated attacks have primarily employed messages from the Internet domain rather than leveraging the messages exchanged between connected vehicles. This paper presents a novel study that investigates the impact of DDoS attacks employing Cooperative Awareness Messages (CAMs), which serve as fundamental safety messages for establishing awareness in the connected car environment. The results obtained reveal that our attack exerts a significant, silent, and stealthy impact on connected cars. While the system remains operational, the quality of the services it provides (e.g., data collection and vehicle cooperation) is severely compromised. This highlights the vulnerability of connected cars to these attacks and underscores the need for robust mitigation strategies. Ayoub Wehby, Sherali Zeadally, Rida Khatoun, Mohammed Lamine Bouchouia, Ahmad Fadlallah |
CoDIT | 5 |
| 2024 | DNS flooding attack detection scheme through Machine LearningabstractDomain Name System (DNS) servers are considered registers that enable internet devices to quickly look up specific web servers and access web pages. DNS flooding is a type of distributed denial of service (DDoS) attack in which an attacker overwhelms DNS servers with a huge number of resolution requests. Such an attack can prevent DNS servers from responding to legitimate traffic. In this paper, we propose a new approach that relies on monitoring and analyzing incoming DNS requests to identify flooding attacks against DNS servers. The detection is carried out using a Machine Learning-based Intrusion Detection System at the entry point of networks. We analyze the performance of different machine learning methods (decision tree, random forest, XGBoost, SVM, K-nearest neighbors, logistic regression, and Multi-Layer Perceptron) for detecting DNS flooding attacks. The evaluation was conducted in the context of emulated attacks. The obtained results reveal that all six methods exhibit the capability to effectively detect DNS attacks, even when dealing with low attack rates. This highlights the robustness of these methods and their potential to maintain high accuracy levels in identifying DNS attack patterns. Ali El Attar, Rida Khatoun, Fadlallah Chbib, Ahmad Fadlallah, Ahmed Serhrouchni |
IWCMC | 4 |
| 2024 | Shielding the Connected Cars: A Dataset-Powered Defense Against DDoSabstractThe connected car is no longer a theoretical concept and is now in the application phase. This puts a burden on the infrastructure of the connected cars since it is at the heart of this technology. The research is now focused on how to protect this infrastructure against the well-known serious attacks, among which is the Distributed Denial of Service (DDoS) attack. The messages exchanged between the cars and the infrastructure are secured by digital certificates, this protects the network from external attacks only. Therefore, there is a need for an extra layer of security that protects the system from insider attacks in the form of an Intrusion Detection System (IDS). While researchers have made efforts to simulate such an attack in a near-realistic setup, the work still lacks its true representation. To contribute to this research gap, we present in this paper the generation of a publicly available dataset representing a DDoS attack simulated using Cooperative Awareness Messages in a well-known vehicular traffic simulation to be used to develop an IDS. The data collection is done on the Road Side Unit reflecting real data collection. Also, we propose an ensemble learning-driven approach as a potential framework for creating connected cars Vehicle-to-Everything IDS. Where we delve into the propositions of its deployment and the architecture of it. The obtained results show a Matthews correlation coefficient of 98% by the proposed models countering the attacks. Ayoub Wehby, Rida Khatoun, Ahmad Fadlallah |
WINCOM | 3 |
| 2023 | Detecting DDoS attacks using adversarial neural network
Ali Mustapha, Rida Khatoun, Sherali Zeadally, Fadlallah Chbib, Ahmad Fadlallah, Walid Fahs, Ali El Attar |
Comput. Secur. | 5 |
| 2021 | A taxonomy of PUF Schemes with a novel Arbiter-based PUF resisting machine learning attacks
Mohammad El-Hajj 0001, Ahmad Fadlallah, Maroun Chamoun, Ahmed Serhrouchni |
Comput. Networks | 2 |
| 2019 | Ethereum for Secure Authentication of IoT using Pre-Shared Keys (PSKs)abstractEnterprises are no doubt interested in reaching data collected from billions of Internet of Things (IoT) devices which opens a huge potential business. The main concern remains the security challenges from the distribution of key while using public key cryptography. To ensure that IOT connected devices can be trusted to be what they are supposed to be, robust IoT device authentication is mandated. Each IoT device therefore requires a unique identity which can be verified when the device tries to link to an intermediate device. One of the early solutions used to secure data transmission among parties in public networks is the Public Key Infrastructure (PKI) which is used to distribute and manage public keys (digital certificates) among different parties and these certificates are generated upon request by Certificate Authorities (CA). Nevertheless, for billions of devices connected to IoT and mobile phones, the distribution management of certificates for each client proved to be inefficient. In this research, we propose a decentralized authentication platform based on PKI and Ethereum Blockchain. The public key certificates are stored in a decentralized fashion and the private keys are stored inside the devices themselves. It also includes a protocol for Pre-Shared Keys (PSK) distribution. PSK keys are then used by PSK-based security protocols for securing the communication channel between two devices. This platform includes a client-side module, a server-side Wallet Management Function, and a smart contract deployed on the Ethereum Blockchain network. This platform can be used by applications for end devices and/or intermediate devices authentication and a secure Machine-to-Machine (M2M) communication. The proposed platform is validated by the implementation of a Secure Session Establishment between IoT devices. Results show that the solution implementation has minimal impact on the existing networks, and the secure session setup time between two devices is negligible compared to the existing security methods. Eventually, this scheme can help removing the trust requirement placed on clients by the current PKI/CAs infrastructure. Mohammad El-Hajj 0001, Ahmad Fadlallah, Maroun Chamoun, Ahmed Serhrouchni |
WINCOM | 2 |