EDBT 2026 Demo / reviewers in the wild / expert
Anis Bkakria
dblp:127/3314
· DBLP profile ↗
14ranked-venue papers
8as first author
8since 2021 · last 2025
0000-0002-9758-4617ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 8 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Framework for Supporting PET Selection Based on GDPR Principles
Sebastian Pape 0001, Anis Bkakria, Badreddine Chah, Maurice Heymann, Sarah Syed-Winkler |
ARES (1) | 2 |
| 2025 | A Post-Quantum Privacy-Enhanced Federated Learning Model for Driver Behavior ProfilingabstractAs vehicle systems become increasingly connected and intelligent, insurance providers are turning to machine learning techniques to personalize billing based on individual driving behavior. This shift raises important questions about how to balance predictive performance with user privacy. In this paper, we present PrivFedProfiling, a decentralized privacy-preserving learning framework designed for use-based insurance (UBI) systems. Our method leverages Federated Learning (FL) to collaboratively train behavior models across distributed driver devices without transferring raw data. To further strengthen privacy, we integrate Differential Privacy (DP) and Homomorphic Encryption (HE) within the training process, protecting sensitive patterns in shared model updates. The proposed approach uses a Multilayer Perceptron (MLP) architecture and is validated using synthetic driving behavior data generated from the SUMO simulator. It offers a realistic yet controllable environment for testing. Results indicate that our method maintains high model accuracy while ensuring strong privacy guarantees, making it suitable for real-world deployment. Badreddine Chah, Anis Bkakria, Alexandre Lombard, Abdeljalil Abbas-Turki, Alexandre Brunoud, Yazan Mualla, Reda Yaich |
HSI | 2 |
| 2025 | From static to dynamic risk indicators in predicting and detecting insider attacksabstractCyber insider threats represent one of the most complex and insidious challenges to modern cybersecurity, as they originate from legitimate users whose behaviors may turn malicious over time. Traditional approaches often fail due to their reliance on static risk indicators, necessitating dynamic modeling of human behavior to capture evolving risks. In this paper, we propose a novel framework for detecting insider threats by continuously and dynamically inferring personality-based risk indicators from employees’ writing data using a publicly accessible large language model (Meta AI’s Llama-3.2). These indicators are modeled as time series and processed through AutoRegressive Integrated Moving Average (ARIMA) models to forecast behavioral deviations. Predicted anomalies are subsequently classified using a hybrid ensemble combining Artificial Neural Networks (ANN) and Random Forest (RF) to distinguish benign variations from genuine insider threats. Our framework identifies behavioral anomalies, provides interpretable detection windows, and achieves the following results on CMU-CERT datasets (r4.2/r5.2): recall (90.0%/86.0%), precision (92.6%/87.7%), ROC-AUC (94.7%/92.6%), MSE (0.231/0.304), MTTD (21.3 days/31.72 days) and a median latency under 230 ms for real-time operation. These results demonstrate significant improvements over baseline static approaches in both detection accuracy and temporal prediction capability. This work advances human-centric and proactive insider threat detection by integrating personality-based risk indicators with predictive modeling, providing a scalable and interpretable solution for real-time dynamic risk assessment in enterprise environments. N'Famoussa Kounon Nanamou, Rim Ben Salem, Anis Bkakria, Nora Cuppens, Frédéric Cuppens |
TrustCom | 3 |
| 2024 | A Privacy-Preserving Graph Encryption Scheme Based on Oblivious RAM
Seyni Kane, Anis Bkakria |
DBSec | 2 |
| 2023 | A Framework for Privacy Policy Enforcement for Connected Automotive SystemsabstractThe GDPR is a set of regulations designed to give users control over their personal data and applies to any connected object that processes such data. One of the most complex environments covered by the GDPR is the connected car, which has brought attention to the sensitive data processed by these vehicles. This data includes information about the driver or owner, the vehicle’s environment, and the vehicle itself. Given the varying sensitivity levels of this data, it is important to offer users control over their data and privacy. To address this, we propose an end-to-end privacy preserving framework that ensures the integrity, confidentiality, and traceability of data related to user privacy within a connected vehicle. This framework combines data tainting for data traceability, lightweight signature for data integrity, and attribute-based encryption for confidentiality and access control to effectively enforce privacy policies set by both vehicle users and manufacturers. This approach is the first to offer end-to-end privacy and confidentiality policy enforcement for connected vehicles, covering data generation by sensors to the Transmission Control Unit. Anis Bkakria, Lydia Brika |
TrustCom | 1 |
| 2023 | Robustness Assessment of Biometric AuthenticatorsabstractBiometric authenticators aim to provide a safe, secure, and accurate authentication process in restricted areas. Despite their advantages, biometric authenticators are vulnerable to cyber-attacks, such as spoofing attacks. Spoofing attacks enable malicious actors to masquerade as someone else to gain illegitimate access or privilege. To proceed, the attacker forges fake biometric data or duplicates existing ones. In such a context, the evaluation of the robustness of biometric authenticators is paramount to assessing their resilience potential and derive deployment strategies. Through this work, we propose a generic assessment method, based on a metric which quantifies the robustness of biometrics against cyber-attacks. Our methodology can be adapted to different families of cyber-attacks targeting biometric authentication techniques. We demonstrate our approach by considering spoofing-attacks. To achieve this objective, we present an extended state-of-the-art of biometrics (physiological and behavioural), including emerging biometric technologies. We also provide an overview of spoofing-attacks for each identified biometric mechanism in the literature. Based on this knowledge, we quantify and we combine the characteristics of such attacks into a quantitative robustness metric which can be applied to both a single and a combination of authenticators. Romain Dagnas, Anis Bkakria, Reda Yaich |
TrustCom | 2 |
| 2023 | Robust, revocable, forward and backward adaptively secure attribute-based encryption with outsourced decryptionabstractAttribute based encryption (ABE) is a cryptographic technique allowing fine-grained access control by enabling one-to-many encryption. Existing ABE constructions suffer from at least one of the following limitations. First, single point of failure on security meaning that, once an authority is compromised, an adversary can either easily break the confidentiality of the encrypted data or effortlessly prevent legitimate users from accessing data; second, the lack of user and/or attribute revocation mechanism achieving forward and backward secrecy; third, a heavy computation workload is placed on data user; last but not least, the lack of adaptive security in standard models. In this paper, we propose the first single-point-of-failure free multi-authority ciphertext-policy ABE that simultaneously (1) ensures robustness for both decryption key issuing and access revocation while achieving both backward and forward secrecy; (2) enables outsourced decryption to reduce the decryption overhead for data users that have limited computational resources; and (3) achieves adaptive (full) security in standard models. The provided theoretical complexity comparison as well as the conducted experiments show that our construction introduces linear storage and computation overheads that occurs only once during its setup phase, which we believe to be a reasonable price to pay to achieve all previous features. Anis Bkakria |
J. Comput. Secur. | 1 |
| 2022 | Robust and Provably Secure Attribute-Based Encryption Supporting Access Revocation and Outsourced Decryption
Anis Bkakria |
DBSec | 1 |
| 2020 | Privacy-Preserving Pattern Matching on Encrypted Data
Anis Bkakria, Nora Cuppens, Frédéric Cuppens |
ASIACRYPT (2) | 1 |
| 2018 | Optimal Distribution of Privacy Budget in Differential Privacy
Anis Bkakria, Aimilia Tasidou, Nora Cuppens, Frédéric Cuppens, Fatma Bouattour, Feten Ben Fredj |
CRiSIS | 1 |
| 2018 | Linking Differential Identifiability with Differential Privacy
Anis Bkakria, Nora Cuppens, Frédéric Cuppens |
ICICS | 1 |
| 2017 | Real-Time Detection and Reaction to Activity Hijacking Attacks in Android Smartphones (Short Paper)abstractMost Android users are required to communicate sensitive data (passwords, usernames, security codes, and credit card numbers) with applications. Hacker can launch phishing attacks to compromise user data confidentiality. He/She stealthily injects into the foreground a hijacking Activity at the right timing to acquire private information. In this paper, we propose an effective approach that uses the similarity between launched Activities in order to detect and reacts to hijacking attacks during runtime time. We demonstrate the effectiveness of our solution by quantifying the number of false positives that can be generated by our system. We observe that, in the worst case, our solution generates 4.2% of false positives and incurs only 0.39% performance overhead on a CPU-bound micro-benchmark. Anis Bkakria, Mariem Graa, Nora Cuppens, Frédéric Cuppens, Jean-Louis Lanet |
PST | 1 |
| 2014 | Specification and Deployment of Integrated Security Policies for Outsourced Data
Anis Bkakria, Frédéric Cuppens, Nora Cuppens, David Gross-Amblard |
DBSec | 1 |
| 2014 | Optimized and controlled provisioning of encrypted outsourced dataabstractRecent advances in encrypted outsourced databases support the direct processing of queries on encrypted data. Depend- ing on functionality (i.e. operators) required in the queries the database has to use different encryption schemes with different security properties. Next to these functional re-quirements a security administrator may have to address security policies that may equally determine the used en-cryption schemes. We present an algorithm and tool set that determines an optimal balance between security and functionality as well as helps to identify and resolve possible conflicts. We test our solution on a database benchmark and business-driven security policies. Andreas Schaad, Anis Bkakria, Florian Kerschbaum, Frédéric Cuppens, Nora Cuppens, David Gross-Amblard |
SACMAT | 2 |