EDBT 2026 Demo / reviewers in the wild / expert
Habib Louafi
dblp:131/1711
· DBLP profile ↗
20ranked-venue papers
5as first author
12since 2021 · last 2026
0000-0002-3247-3115ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 10 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-authorComputer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Explainable Multi-Objective Hybrid Metaheuristic Feature Selection for IoMT Intrusion Detection
Selma Bououdina, Habib Louafi, Meriem Zerkouk, Neila Mezghani, Richard Hotte |
SECRYPT (1) | 2 |
| 2025 | A Customizable Security Risk Assessment Framework Using Multi-Attribute Decision Making for IoT Systems
Mofareh Waqdan, Habib Louafi, Malek Mouhoub |
ICISSP (1) | 2 |
| 2025 | A Hybrid-Based Transfer Learning Approach for IoT Device Identification
Stephanie M. Opoku, Habib Louafi, Malek Mouhoub |
SECRYPT | 2 |
| 2025 | Security risk assessment in IoT environments: A taxonomy and surveyabstractInternet of Things (IoT) applications have become an integral part of our daily lives. However, due to the rising number of cybercrimes, ensuring cyberspace security has become essential. The security and privacy of IoT applications are fundamental as they are used in critical sectors, like healthcare, transportation systems, and energy production. As a result, many studies are focusing on the security and privacy of the IoT revolution. The need for assessing IoT security risks is increasing. This paper presents a survey and taxonomy of risk management, analysis, and evaluation methods applied to systems involving IoT devices. In particular, the paper reviews and categorizes existing IoT risk management and assessment frameworks, and the different assessments techniques, risk perspectives, and methodologies. The paper concludes with a deep analysis of these frameworks, solutions, and guidelines, and discusses future research directions. Mofareh Waqdan, Habib Louafi, Malek Mouhoub |
Comput. Secur. | 2 |
| 2024 | IoT Device Identification based on Network Traffic Analysis and Machine LearningabstractAs Internet of Things (IoT) technology rapidly evolves, the widespread use and diversity of IoT devices present new challenges for device identification (often called finger-printing). Nevertheless, traditional methods for identifying IoT devices face several problems. This paper presents an identification solution capable of detecting the IoT device identities by analyzing the network traffic they generate and machine learning approaches. The solution we propose is tested on three well-known IoT traffic datasets, and showed higher prediction performance in identifying IoT device types. It is also compared against existing solutions and showed far better results, in terms of both prediction accuracy and temporal complexity. Stephanie M. Opoku, Habib Louafi, Malek Mouhoub |
ISNCC | 2 |
| 2024 | An Uncertain Reasoning-Based Intrusion Detection System for DoS/DDoS Detection
Habib Louafi, Yiyu Yao |
SECRYPT | 2 |
| 2023 | An IoT Security Risk Assessment Framework for Healthcare EnvironmentabstractRisk Assessment for IoT is important for analyzing the risks associated with deploying and using IoT technologies. A risk assessment framework helps organizations identify, assess, and manage the risks of IoT, which can range from data privacy and confidentiality to system integrity, availability, and performance. The significance of risk assessment in medical sectors, particularly in emergency rooms, is more imperative due to the criticality of the service. This paper presents an IoT risk assessment framework for the healthcare environment, in which we have improved upon existing methodologies. The proposed framework dynamically calculates the risk score for different device profiles, considering their population and other parameters, such as network protocols, device heterogeneity, device security updates, device physical security status, device history status, layer history status, and device criticality. We validate our proposed framework by simulating an emergency room environment, considering a variety of devices and parameters. The results show that our framework provides more insight into the overall risk assessment, as it takes into account the number of IoT devices and their relation to a threshold we introduce, which can be tuned by the security expert. Mofareh Waqdan, Habib Louafi, Malek Mouhoub |
ISNCC | 2 |
| 2023 | An Instance-based Transfer Learning Approach, Applied to Intrusion DetectionabstractTo detect malicious activities in the network, Intrusion Detection Systems (IDS) are deployed. One way to build IDS is through Machine Learning (ML) techniques. Using ML techniques for building IDS models has a few shortcomings. The performance of these models is affected when new attacks emerge, such as zero-day attacks. That is because the traditional techniques assume that training and testing data come from the same distribution, therefore, when new attacks emerge, the underlying distribution changes also and affects the performance of the model. Also, the attack samples of new attacks may be scarce.In this paper, we present a solution to train an IDS model, where scarce data is available, using an instance-based Transfer Learning (TL) approach. This approach allows for increasing the sample size in the Target Domain by using similar instances from a related Source Domain. We conducted our experiments using the UNSW-NB15 dataset and the obtained results are appealing. Indeed, we obtained 92.5%, 88.4%, 86.5%, and 86.8%, using the widely used performance metrics Accuracy, Recall, Precision and F1-Score, respectively. These results are obtained even though the distribution difference between the Source and Target Domains is significantly higher, as measured with the Maximum Mean Discrepancy (MMD) metric. Sonia Kawish, Habib Louafi, Yiyu Yao |
PST | 2 |
| 2023 | A Comprehensive Risk Assessment Framework for IoT-Enabled Healthcare Environment
Mofareh Waqdan, Habib Louafi, Malek Mouhoub |
SECRYPT | 2 |
| 2022 | A Feistel Network-based Prefix-Preserving Anonymization Approach, Applied To Network TracesabstractNetwork traces represent a critical piece of data for network security. Due to lack of expertise, companies are forced to outsource their network traces to third parties to perform analytics on the traces and provide security feedback and recommendations. However, these companies are reluctant to share their network traces, as they comprise sensitive information (e.g., IP addresses). Therefore, the network traces are anonymized to ensure the privacy of the data and preserve its utility. The latter guarantees that the essence of the data remains valid after anonymization, otherwise the analytics are useless. Existing solutions, such as CryptoPAN, preserves the data utility (by preserving the IP prefixes), but are vulnerable to semantic attacks.In this paper, we propose an anonymization solution, which is based on the Feistel, which is widely used in encryption systems, such as DES and Twofish. Our solution preserves both data privacy and its utility at the same time. We validate our solution using the Kddcup99 dataset and measure the data leakage (dual of privacy) provided by our solution. We evaluate the security of our solution using the avalanche property, which is widely used to measure the security of encryption systems. Moreover, the efficacy of our solution is evaluated against Injection attacks. Overall, the obtained results, avalanche property and resistance to Injection attacks, are appealing. Shaveta Dandyan, Habib Louafi, Samira Sadaoui |
PST | 2 |
| 2022 | Efficient IoT Device Fingerprinting Approach using Machine Learning
Richmond Osei, Habib Louafi, Malek Mouhoub, Zhongwen Zhu |
SECRYPT | 2 |
| 2021 | A Multi-view Approach to Preserve Privacy and Utility in Network Trace AnonymizationabstractAs network security monitoring grows more sophisticated, there is an increasing need for outsourcing such tasks to third-party analysts. However, organizations are usually reluctant to share their network traces due to privacy concerns over sensitive information, e.g., network and system configuration, which may potentially be exploited for attacks. In cases where data owners are convinced to share their network traces, the data are typically subjected to certain anonymization techniques, e.g., CryptoPAn, which replaces real IP addresses with prefix-preserving pseudonyms. However, most such techniques either are vulnerable to adversaries with prior knowledge about some network flows in the traces or require heavy data sanitization or perturbation, which may result in a significant loss of data utility. In this article, we aim to preserve both privacy and utility through shifting the trade-off from between privacy and utility to between privacy and computational cost. The key idea is for the analysts to generate and analyze multiple anonymized views of the original network traces: Those views are designed to be sufficiently indistinguishable even to adversaries armed with prior knowledge, which preserves the privacy, whereas one of the views will yield true analysis results privately retrieved by the data owner, which preserves the utility. We formally analyze the privacy of our solution and experimentally evaluate it using real network traces provided by a major ISP. The experimental results show that our approach can significantly reduce the level of information leakage (e.g., less than 1% of the information leaked by CryptoPAn) with comparable utility. Meisam Mohammady, Momen Oqaily, Lingyu Wang 0001, Yuan Hong 0001, Habib Louafi, Makan Pourzandi, Mourad Debbabi |
ACM Trans. Priv. Secur. | 5 |
| 2018 | Preserving Both Privacy and Utility in Network Trace AnonymizationabstractAs network security monitoring grows more sophisticated, there is an increasing need for outsourcing such tasks to third-party analysts. However, organizations are usually reluctant to share their network traces due to privacy concerns over sensitive information, e.g., network and system configuration, which may potentially be exploited for attacks. In cases where data owners are convinced to share their network traces, the data are typically subjected to certain anonymization techniques, e.g., CryptoPAn, which replaces real IP addresses with prefix-preserving pseudonyms. However, most such techniques either are vulnerable to adversaries with prior knowledge about some network flows in the traces, or require heavy data sanitization or perturbation, both of which may result in a significant loss of data utility. In this paper, we aim to preserve both privacy and utility through shifting the trade-off from between privacy and utility to between privacy and computational cost. The key idea is for the analysts to generate and analyze multiple anonymized views of the original network traces; those views are designed to be sufficiently indistinguishable even to adversaries armed with prior knowledge, which preserves the privacy, whereas one of the views will yield true analysis results privately retrieved by the data owner, which preserves the utility. We formally analyze the privacy of our solution and experimentally evaluate it using real network traces provided by a major ISP. The results show that our approach can significantly reduce the level of information leakage (e.g., less than 1% of the information leaked by CryptoPAn) with comparable utility. Meisam Mohammady, Lingyu Wang 0001, Yuan Hong 0001, Habib Louafi, Makan Pourzandi, Mourad Debbabi |
CCS | 4 |
| 2018 | A TOPSIS-based QoE model for adapted content selection of slide documents
Habib Louafi, Stéphane Coulombe, Mohamed Cheriet |
Multim. Tools Appl. | 1 |
| 2018 | Dynamic Optimal Countermeasure Selection for Intrusion Response SystemabstractDesigning an efficient defense framework is challenging with respect to a network's complexity, widespread sophisticated attacks, attackers' ability, and the diversity of security appliances. The Intrusion Response System (IRS) is intended to respond automatically to incidents by attuning the attack damage and countermeasure costs. The existing approaches inherit some limitations, such as using static countermeasure effectiveness, static countermeasure deployment cost, or neglecting the countermeasures' negative impact on service quality (QoS). These limitations may lead the IRS to select inappropriate countermeasures and deployment locations, which in turn may reduce network performance and disconnect legitimate users. In this paper, we propose a dynamic defense framework that selects an optimal countermeasure against different attack damage costs. To measure the attack damage cost, we propose a novel defense-centric model based on a service dependency graph. To select the optimal countermeasure dynamically, we formulate the problem at hand using a multi-objective optimization concept that maximizes the security benefit, minimizes the negative impact on users and services, and minimizes the security deployment cost with respect to the attack damage cost. Alireza Shameli-Sendi, Habib Louafi, Wenbo He 0003, Mohamed Cheriet |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2017 | Payless Monitoring Service for Tenants in Cloud with Traffic and Energy-Aware Function DeploymentabstractMany applications are distributed in cloud as they consist of different modules and tiers. Cloud tenant must be able to monitor the deployed applications to ensure that it is operating correctly, meeting its SLAs, and fulfilling business requirements. Activating all type of monitoring functions for all tenant's applications at the same time is costly. The more required monitoring functions the more allocated cloud resources. Moreover, it incurs monetary cost for tenants. In this paper, the problem of virtual monitoring function (vMF) placement for service chains is modeled by maximizing both the network and computing resource utilization. Beside that, we propose a set of tenant policies, which are either monetary-driven or performance-driven, translated as constrains in optimal placement algorithm. Simulation results show that the proposed model can reduce the total incurred cost by up to 10% compared to the best non-optimal heuristic. Moreover, the proposed model can decrease the execution time about 84% compared to the basic solution. Alireza Shameli-Sendi, Habib Louafi, Mohamed Cheriet |
CloudCom | 2 |
| 2017 | Multi-Objective Optimization in Dynamic Content Adaptation of Slide DocumentsabstractIn mobile web conferencing, slide decks should be optimized before delivery to meet the constraints and environments of target mobile devices. To deliver optimally adapted slides, a trade-off between the visual aspect and delivery time must be reached. Static adaptation methods are CPU-intensive, and require large storage space. The dynamic approach is attractive as the optimal version is created on the fly when the actual slide is to be shared. Existing dynamic solutions are optimized for the resolution of the target mobile device and use good visual quality settings. However, they do not control the resulting data size, which creates serious usability issues, such as increasing the delivery time. Prediction-based methods require much less memory and processing resources than static approaches while yielding an excellent user experience. In this paper, we propose a multi-objective dynamic content adaptation framework, in which we maximize the visual quality and minimize the delivery time simultaneously. We compare our solution with an ideal optimal point, called utopia, and with all the optimal solutions (Pareto front) provided by a static exhaustive system. The obtained results show that our framework yields solutions very close to the utopia and, for the majority of the documents tested, the obtained solutions are on the Pareto front. Habib Louafi, Stéphane Coulombe, Mohamed Cheriet |
IEEE Trans. Serv. Comput. | 1 |
| 2015 | Robust QoE-aware prediction-based dynamic content adaptation framework applied to slides documents in mobile Web conferencing
Habib Louafi, Stéphane Coulombe, Umesh Chandra |
Multim. Tools Appl. | 1 |
| 2013 | Efficient Near-Optimal Dynamic Content Adaptation Applied to JPEG Slides Presentations in Mobile Web ConferencingabstractIn the context of mobile Web conferencing, slide documents are generally transcoded into JPEG format and wrapped into a Web page prior to delivery. Given the diversity of these devices and their networks, dynamically identifying the optimal transcoding parameters is very challenging, as the number of transcoding parameters combinations could be very high. Current solutions use the resolution of the target mobile device and a fixed quality factor as transcoding parameters. However, this technique allows no control over the resulting file size, which, if too large, might increase the delivery time and negatively affect users' experience. Another solution (content selection) which leads to better quality consists in creating several versions and, at delivery time, selecting the best one. However, such a solution is computationally expensive. In this paper, we propose a prediction-based framework which computes near-optimal transcoding parameters dynamically with far less computations. We propose five methods based on this framework. The first predicts near-optimal transcoding parameters, while the others improve their accuracy. From the set of documents tested, two of the proposed methods reach optimality 14% and 30% of the time, respectively. Moreover, the average deviation from optimality for the proposed methods varies from 6% to 3%, with a complexity varying from 1 to 5 transcoding operations. Habib Louafi, Stéphane Coulombe, Umesh Chandra |
AINA | 1 |
| 2013 | Quality Prediction-Based Dynamic Content Adaptation Framework Applied to Collaborative Mobile PresentationsabstractToday, professional documents, created in applications such as PowerPoint and Word, can be shared using ubiquitous mobile terminals connected to the Internet. GoogleDocs and EasyMeet are good examples of such collaborative web applications dedicated to professional documents. The static adaptation of professional documents has been studied extensively. Dynamic adaptation can be very useful and practical for interactive multimedia applications, because it allows the delivery of highly customized content to the end user without the need to generate and store multiple transcoded versions. In this paper, we propose a dynamic framework that enables us to estimate transcoding parameters on the fly to generate near-optimal adapted content for each user. The framework is compared to current dynamic methods as well as to static adaptation solutions. We show that the proposed framework provides a better tradeoff between quality and storage compared to other static and dynamic approaches. To quantify the quality of the adapted content, we introduce a measure of the quality of the experience based on the visual quality of the adapted content, as well as on the impact of its total delivery time. The framework has been tested on (but is not limited to) OpenOffice Impress presentations. Habib Louafi, Stéphane Coulombe, Umesh Chandra |
IEEE Trans. Mob. Comput. | 1 |