EDBT 2026 Demo / reviewers in the wild / expert
Valerio Selis
dblp:132/7436
· DBLP profile ↗
6ranked-venue papers
1as first author
3since 2021 · last 2025
0000-0002-1856-4707ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | TrustIoT: Building Trust in Human-Thing Interactions for Healthcare Systems Using Machine LearningabstractInternet of Things (IoT) health monitoring devices allow the collection of data while performing various daily physical activities. These devices are not only affordable but also capable of collecting a wide variety of data, such as physiological data and environmental information. In the case of IoT healthcare systems, it is important to know which activity is performed to determine if there is any abnormality in a person’s physical behaviour during the activity, which may ultimately provide an indication of the person’s health condition. Human Activity Recognition (HAR) methods can be used to recognise activities. HAR is a field of identifying and categorising activities using Artificial Intelligence (AI), which uses raw data collected from different devices equipped with sensors such as cameras, accelerometers, gyroscopes, etc. The unique patterns and characteristics exhibited in human physical behaviours, such as gait, enable the identification of individuals with the use of a technology known as behavioural biometrics. This paper presents and evaluates HAR and user detection models, which serve as the foundation for constructing a trust model. The HAR binary classification proposed method achieved an accuracy of 97.5%, a precision of 97.7%, a recall of 97.5% and an F1 score of 97.6%. Additionally, the user detection model achieved an accuracy and a recall of 82.1% a precision of 91.6% and an F1 score of 85.7%. We then detail the methodology for calculating and updating trust scores over time and defining trust levels in the IoT system. Once trust is established, the system can provide reliable information regarding the individual’s health condition. Abir Al-Ansari, Kristiaan D'Août, Valerio Selis |
TrustCom | 3 |
| 2025 | AlignAD-VAE: A Variational Autoencoder with MMD-Based Dataset Alignment for Network Anomaly DetectionabstractThis study addresses the persistent challenge of cross-dataset generalisability in intrusion detection systems by both assessing whether concatenating datasets improves generalisability and proposing AlignAD-VAE, a new unsupervised variational autoencoder model augmented with maximum mean discrepancy (MMD)-based alignment. The model aims to reduce the distribution shift between datasets by aligning their latent representations in a common feature space. We systematically evaluate AlignAD-VAE against modern architectures such as autoencoder and variational autoencoder baselines across multiple cross-dataset configurations using the CIC-IDS2017, CSE-CIC-IDS2018, and CIC-DDoS2019 datasets. Our experiments cover both single-dataset training and concatenated multidataset training, assessing model performance on completely unseen datasets. Concatenating training datasets improves generalisability by up to 10%, as it exposes models to a broader range of normal patterns and traffic variations, thereby reducing overfitting to dataset-specific artefacts. While all models benefit from the richer training data, AlignAD-VAE outperforms the VAE baseline by up to 2%, indicating that the integration of MMD-based domain alignment provides additional, although modest, improvements in cross-domain adaptation, as reflected in AUC-ROC, F1-score, and accuracy metrics. These findings highlight that combining diverse datasets with domain alignment can make IDS more robust to unseen network environments, a critical requirement for real-world deployment. Samed Saka, Valerio Selis, Alan Marshall 0001 |
TrustCom | 2 |
| 2023 | Generating Synthetic Tabular Data for DDoS Detection Using Generative ModelsabstractDistributed denial-of-service (DDoS) attacks are a type of cyber attack that overwhelms a target server, service or network with a flood of malicious traffic, making it unavailable to legitimate users. These attacks have become a major threat to the security of computer networks and systems, and effective intrusion detection systems (IDSs) are essential for detecting and mitigating these attacks. IDSs are used to monitor network traffic for malicious activity and can help detect and prevent DDoS attacks. Most IDSs are often designed to identify diverse types of attacks, but their efficacy can be limited when faced with attacks that exhibit extensive variations and sophisticated techniques, such as DDoS. In order to establish an effective IDS capable of identifying DDoS attacks, the acquisition of substantial volumes of labelled network data becomes crucial. This study aims to evaluate the performance of recent generative models in synthesising realistic tabular data to accurately emulate DDoS attack patterns. To achieve this, we used the CIC-DDOS2019 dataset, a comprehensive and modern collection of real-world DDoS attack scenarios. Leveraging state-of-the-art generative models, namely CTGAN, TVAE, and CopulaGAN, we synthesised realistic tabular data that emulated the characteristics and patterns observed in DDoS attack flow. We utilised various statistical metrics such as correlation scores, similarity and distance metrics, along with machine learning performance metrics, to quantitatively measure the performance of the generative models. The findings indicate that all three models have the ability to accurately emulate the patterns found in the real database, resulting in the generation of useful synthetic data. Specifically, among the classification methods used, the Random Forest method showed the most successful performance in detecting attacks with an accuracy of 99% when applied to the original dataset. In comparison, it achieved accuracy levels of 98%, 99%, and 93% when applied to datasets generated using the CTGAN, CopulaGAN, and TVAE models respectively. It can be concluded that generative networks have the potential to be useful in synthesising tabular data and may contribute to the overall performance of existing and future IDS. However, it is crucial to acknowledge that to cover a wider spectrum of attacks, more specific adjustments may need to be applied both in the data preprocessing stage and in the model architectures. Samed Saka, Ali Al-Ataby, Valerio Selis |
TrustCom | 3 |
| 2015 | MEDA: A Machine Emulation Detection AlgorithmabstractSecurity in the Internet of Things (IoT) is now considered a priority, and trust in machine-to-machine (M2M) communications is expected to play a key role. This paper presents a mechanism to detect an emerging threat in M2M systems whereby an attacker may create multiple fake embedded machines using virtualized or emulated systems, in order to compromise either a targeted IoT device, or the M2M network. A new trust method is presented that is based on a characterisation of the behaviours of real embedded machines, and operates independently of their architectures and operating systems, in order to detect virtual and emulated systems. A range of tests designed to characterise embedded and virtual devices are presented, and the results underline the efficiency of the proposed solution for detecting these systems easily and quickly. Valerio Selis, Alan Marshall 0001 |
SECRYPT | 1 |
| 2013 | Development of Device Identity using WiFi Layer 2 Management Frames for Combating Rogue APs
Jonny Milliken, Valerio Selis, Kian Meng Yap, Alan Marshall 0001 |
SECRYPT | 2 |
| 2013 | Detection and analysis of the Chameleon WiFi access point virusabstractThis paper analyses and proposes a novel detection strategy for the 'Chameleon’ WiFi AP-AP virus. Previous research has considered virus construction, likely virus behaviour and propagation methods. The research here describes development of an objective measure of virus success, the impact of product susceptibility, the acceleration of infection and the growth of the physical area covered by the virus. An important conclusion of this investigation is that the connectivity between devices in the victim population is a more significant influence on virus propagation than any other factor. The work then proposes and experimentally verifies the application of a detection method for the virus. This method utilises layer 2 management frame information which can detect the attack while maintaining user privacy and user confidentiality, a key requirement in many security solutions. Jonny Milliken, Valerio Selis, Alan Marshall 0001 |
EURASIP J. Inf. Secur. | 2 |