EDBT 2026 Demo / reviewers in the wild / expert
Hyame Assem Alameddine
dblp:180/3053 · also Hyame Assem Alamedine
· DBLP profile ↗
19ranked-venue papers
6as first author
11since 2021 · last 2026
0000-0002-6307-0036ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 3 first-author · 4 since 2021Security and privacy · 6 · 5 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RAN-GUARD: A Hybrid Multi-Model Approach for Early Detection of IP-based DDoS Attacks in O-RAN
Yousef Khalil, Hyame Assem Alameddine, Chadi Assi |
WISEC | 2 |
| 2026 | HTTP/2 DoS Attacks in 5G Networks: Impact Analysis and Anomaly DetectionabstractFifth Generation (5 G) and beyond networks rely on the HTTP/2 protocol for signaling between core Network Functions (NFs). While HTTP/2 vulnerabilities have been exploited to perform various types of Denial of Service (DoS) attacks in web environments, their impact on telecommunication networks remains under-studied. Though secure by design, the 5 G Service-Based Architecture (SBA) can be vulnerable to misconfigurations and virtualization exploits, particularly with Mobile Network Operators (MNOs) using hyper-scale technologies. This work addresses the lack of practical studies and analyses on the impact of HTTP/2 attacks on 5 G networks, especially given the absence of a 5G-compliant dataset for anomaly detection. Utilizing the open-source free5GC testbed and UERANSIM emulator, we emulate six different HTTP/2 attacks on various NFs within the 5 G SBA. We analyze their impact on the network and demonstrate that many of them cause cascading effects on other NFs involved in related jeopardized 5 G procedures. Our emulations include both malicious and normal network behavior, resulting in the first 5 G anomaly detection dataset that we are aware of. Using CICFlowmeter, we extract flow-based features known for their anomaly detection capabilities and train multiple machine learning models. These models can serve as benchmarks for detecting HTTP/2 attacks in 5 G networks. Nathalie Wehbe, Hyame Assem Alameddine, Chadi Assi |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | BTS-Band: An Explainable AI Detection Solution for Base Transceiver Station Resource Depletion Attack in O-RAN
Assrar Maamary, Hyame Assem Alameddine, Chadi Assi, Mourad Debbabi |
CNSM | 2 |
| 2025 | Empowering 5G SBA security: Time series transformer for HTTP/2 anomaly detection
Nathalie Wehbe, Hyame Assem Alameddine, Makan Pourzandi, Chadi Assi |
Comput. Secur. | 2 |
| 2025 | PUL-Inter-Slice Defender: An Anomaly Detection Solution for Distributed Slice Mobility AttacksabstractNetwork Slices (NSs) are virtual networks operating over a shared physical infrastructure, each designed to meet specific application requirements while maintaining consistent Quality of Service (QoS). In Fifth Generation (5G) networks, User Equipment (UE) can connect to and seamlessly switch between multiple NSs to access diverse services. However, this flexibility, known as Inter-Slice Switching (ISS), introduces a potential vulnerability that can be exploited to launch Distributed Slice Mobility (DSM) attacks, a form of Distributed Denial of Service (DDoS) attack. To secure 5G networks and their NSs against DSM attacks, we present in this work, PUL-Inter-Slice Defender; an anomaly detection solution that leverages Positive Unlabeled Learning (PUL) and incorporates a combination of Long Short-Term Memory Autoencoders and K-Means clustering. PUL-Inter-Slice Defender leverages the Third Generation Partnership Project (3GPP) key performance indicators and performance measurement counters as features for its machine learning models to detect DSM attack variants while maintaining robustness in the presence of contaminated training data. When evaluated on data collected from our 5G testbed based on the open-source free 5GC and UERANSIM, a UE/ Radio Access Network (RAN) simulator; PUL-Inter-Slice Defender achieved F1-scores exceeding 98.50% on training datasets with 10% to 40% attack contamination, consistently outperforming its counterpart Inter-Slice Defender and other PUL based solutions combining One-Class Support Vector Machine (OCSVM) with Random Forest and XGBoost. Ricardo Misael Ayala Molina, Hyame Assem Alameddine, Makan Pourzandi, Chadi Assi |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Spotting Anomalies at the Edge: Outlier Exposure-Based Cross-Silo Federated Learning for DDoS DetectionabstractDistributed Denial-of-Service (DDoS) attacks are expected to continue plaguing service availability in emerging networks which rely on distributed edge clouds to offer critical, latency-sensitive applications. However, edge servers increase the network attack surface, which is exacerbated with the massive number of connected Internet of Things (IoT) devices that can be weaponized to launch DDoS attacks. Therefore, it is crucial to detect DDoS attacks early, i.e., at the network edge. In this paper, we empower the network edge with intelligent DDoS detection by learning from similarities between different data and DDoS attacks available across the edge servers. To this end, we develop a novel Outlier Exposure (OE)-enabled cross-silo Federated Learning framework, namely FedOE. FedOE enables distributed training of OE-based ML models using a limited number of labeled outliers (i.e., attack flows) experienced at edge servers. We propose a novel OE-based Autoencoder (oAE) that can better discriminate anomalies in comparison to the widely adopted traditional Autoencoder, using a tailored, OE-based loss function. We evaluate oAE in FedOE and demonstrate its ability to generalize to zero-day attacks, with just 50 labeled attack flows per edge server. The results show that oAE achieves a high F1-score for most DDoS attacks, outclassing its non-OE counterpart. Vahid Pourahmadi, Hyame Assem Alameddine, Mohammad Ali Salahuddin 0001, Raouf Boutaba |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Chronos: DDoS Attack Detection Using Time-Based AutoencoderabstractCognitive network management is becoming quintessential to realize autonomic networking. However, the wide spread adoption of the Internet of Things (IoT) devices, increases the risk of cyber attacks. Adversaries can exploit vulnerabilities in IoT devices, which can be harnessed to launch massive Distributed Denial of Service (DDoS) attacks. Therefore, intelligent security mechanisms are needed to harden network security against these threats. In this paper, we propose Chronos, a novel time-based anomaly detection system. The anomaly detector, primarily an Autoencoder, leverages time-based features over multiple time windows to efficiently detect anomalous DDoS traffic. We develop a threshold selection heuristic that maximizes the F1-score across various DDoS attacks. Further, we compare the performance of Chronos against state-of-the-art approaches. We show that Chronos marginally outperforms another time-based system using a less complex anomaly detection pipeline, while out classing flow-based approaches with superior precision. In addition, we showcase the robustness of Chronos in the face of zero-day attacks, noise in training data, and a small number of training packets, asserting its suitability for online deployment. Mohammad Ali Salahuddin 0001, Vahid Pourahmadi, Hyame Assem Alameddine, Md. Faizul Bari, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | AutoGuard: A Dual Intelligence Proactive Anomaly Detection at Application-Layer in 5G Networks
Taous Madi, Hyame Assem Alameddine, Makan Pourzandi, Amine Boukhtouta, Moataz Samir 0001, Chadi Assi |
ESORICS (1) | 2 |
| 2021 | NFV security survey in 5G networks: A three-dimensional threat taxonomy
Taous Madi, Hyame Assem Alameddine, Makan Pourzandi, Amine Boukhtouta |
Comput. Networks | 2 |
| 2021 | Scheduling of Low Latency Services in Softwarized NetworksabstractThe fifth generation (5G) networks are expected to support diverse business verticals (i.e., manufacturing, health care, etc.) with varying quality of service requirements. While today’s mobile networks are a one size fits all architecture, tomorrow’s 5G mobile networks are envisioned to encourage agility, programmability and elasticity through enabling a software-based architecture promoted by network slicing. Network slicing is a new paradigm consisting of partitioning the underlying network infrastructure into different logical network slices, each dedicated to address the requirements (i.e., ultra-low latency, ultra-reliability, etc.) of a group of services. Network Function Virtualization (NFV) and Software Defined Networking (SDN) technologies have been identified as main enablers of network slicing, facilitating the fulfillment of the aforementioned services’ requirements. In this paper, we study the Latency-Aware service scheduling (LASS) problem to solve the network function mapping, the traffic routing and the network service scheduling in the context of an ultra-low latency network slice to consider services with stringent deadlines. We propose the LASS-Game, a novel game-theoretic approach presenting a scalable solution for the LASS problem that accounts for the centralized aspect of the problem while leveraging a decentralized mapping, routing and scheduling decisions. Hyame Assem Alameddine, Mosaddek Hossain Kamal Tushar, Chadi Assi |
IEEE Trans. Cloud Comput. | 1 |
| 2021 | UAV-Aided Ultra-Reliable Low-Latency Computation Offloading in Future IoT NetworksabstractModern 5G services with stringent reliability and latency requirements such as smart healthcare and industrial automation have become possible through the advancement of Multi-access Edge Computing (MEC). However, the rigidity of ground MEC and its susceptibility to infrastructure failure would prevent satisfying the resiliency and strict requirements of those services. Unmanned Aerial Vehicles (UAVs) have been proposed for providing flexible edge computing capability through UAV-mounted cloudlets, harnessing their advantages such as mobility, low-cost, and line-of-sight communication. However, UAV-mounted cloudlets may have failure rates that would impact mission-critical applications, necessitating a novel study for the provisioned reliability considering UAV node reliability and task redundancy. In this paper, we investigate the novel problem of UAV-aided ultra-reliable low-latency computation offloading which would enable future IoT services with strict requirements. We aim at maximizing the rate of served requests, by optimizing the UAVs’ positions, the offloading decisions, and the allocated resources while respecting the stringent latency and reliability requirements. To do so, the problem is divided into two phases, the first being a planning problem to optimize the placement of UAVs and the second an operational problem to make optimized offloading and resource allocation decisions with constrained UAVs’ energy. We formulate both problems associated with each phase as non-convex mixed-integer programs, and due to their non-convexity, we propose a two-stage approximate algorithm where the two problems are transformed into approximate convex programs. Further, we approach the problem considering the task partitioning model which will be prevalent in 5G networks. Through numerical analysis, we demonstrate the efficiency of our solution considering various scenarios, and compare it to other baseline approaches. Elie El Haber, Hyame Assem Alameddine, Chadi Assi, Sanaa Sharafeddine |
IEEE Trans. Commun. | 2 |
| 2020 | Time-based Anomaly Detection using AutoencoderabstractDistributed Denial of Service (DDoS) attacks continue to draw significant attention, especially with the recent surge in cyber attacks that targeted the healthcare, education and financial sectors, during the COVID-19 pandemic. The expansion of virtualization and softwarization technologies, and the surge in Internet of Things (IoT) devices, increase the attack surface and the impact of attacks on networks. In this paper, we present a novel time-based anomaly detection system that leverages an Autoencoder. We explore the impact of different time-windows on detecting multiple DDoS attacks that are difficult to detect via the widely used flow-based features. We train and evaluate our Autoencoder on the recent CICDDoS2019 dataset, and show that our approach achieves an anomaly detection F1-score of over 99% for most attacks and greater than 95% for all attacks. Mohammad Ali Salahuddin 0001, Md. Faizul Bari, Hyame Assem Alameddine, Vahid Pourahmadi, Raouf Boutaba |
CNSM | 3 |
| 2020 | LURK: Server-Controlled TLS DelegationabstractThe following topics are dealt with: security of data; data privacy; learning (artificial intelligence); telecommunication security; Internet; cryptography; mobile computing; computer network security; authorisation; Internet of Things. Ioana Boureanu, Daniel Migault, Stere Preda, Hyame Assem Alameddine, Sanjay Mishra, Frederic Fieau, Mohammad Mannan |
TrustCom | 4 |
| 2019 | Low-Latency Service Schedule Orchestration in NFV-based NetworksabstractThe Fifth Generation (5G) era is bringing tremendous new network capabilities enabling diverse services belonging to different business verticals (i.e., manufacturing, automotive, etc.) and provided with top-notch Quality of Service (QoS) (i.e., ultra-low latency, ultra-reliability, etc.). Empowered by soft-warization technologies such as Network Function Virtualization (NFV), 5G networks are envisioned to be agile, sustainable and self-organized. NFV promotes the automated provisioning of Network Services (NSs) through processing their traffic by a chain of Virtual Network Functions (VNFs). As VNFs are shared between multiple NSs, a clear approach to map and schedule the carried traffic of these services is required. Hence, in this paper, we solve the Latency-Aware Service Schedule Orchestration problem (LASSO) that jointly addresses the mapping and scheduling of services to VNFs. We formulate the problem as a Mixed Integer Linear Program (MILP) and we present ENCHAIN, a novel game-theoretic approach exploiting a scalable solution for the LASSO problem while providing each NS the freedom to decide on its own mapping and scheduling solution. Hyame Assem Alameddine, Chadi Assi, Mosaddek Hossain Kamal Tushar, Jia Yuan Yu |
NetSoft | 1 |
| 2019 | Dynamic Task Offloading and Scheduling for Low-Latency IoT Services in Multi-Access Edge ComputingabstractMulti-access edge computing (MEC) has recently emerged as a novel paradigm to facilitate access to advanced computing capabilities at the edge of the network, in close proximity to end devices, thereby enabling a rich variety of latency sensitive services demanded by various emerging industry verticals. Internet-of-Things (IoT) devices, being highly ubiquitous and connected, can offload their computational tasks to be processed by applications hosted on the MEC servers due to their limited battery, computing, and storage capacities. Such IoT applications providing services to offloaded tasks of IoT devices are hosted on edge servers with limited computing capabilities. Given the heterogeneity in the requirements of the offloaded tasks (different computing requirements, latency, and so on) and limited MEC capabilities, we jointly decide on the task offloading (tasks to application assignment) and scheduling (order of executing them), which yields a challenging problem of combinatorial nature. Furthermore, we jointly decide on the computing resource allocation for the hosted applications, and we refer this problem as the Dynamic Task Offloading and Scheduling problem, encompassing the three subproblems mentioned earlier. We mathematically formulate this problem, and owing to its complexity, we design a novel thoughtful decomposition based on the technique of the Logic-Based Benders Decomposition. This technique solves a relaxed master, with fewer constraints, and a subproblem, whose resolution allows the generation of cuts which will, iteratively, guide the master to tighten its search space. Ultimately, both the master and the sub-problem will converge to yield the optimal solution. We show that this technique offers several order of magnitude (more than 140 times) improvements in the run time for the studied instances. One other advantage of this method is its capability of providing solutions with performance guarantees. Finally, we use this method to highlight the insightful performance trends for different vertical industries as a function of multiple system parameters with a focus on the delay-sensitive use cases. Hyame Assem Alameddine, Sanaa Sharafeddine, Samir Sebbah, Sara Ayoubi, Chadi Assi |
IEEE J. Sel. Areas Commun. | 1 |
| 2019 | Optimized Provisioning of Edge Computing Resources With Heterogeneous Workload in IoT NetworksabstractThe proliferation of smart connected Internet of Things (IoT) devices is bringing tremendous challenges in meeting the performance requirement of their supported real-time applications due to their limited resources in terms of computing, storage, and battery life. In addition, the considerable amount of data they generate brings extra burden to the existing wireless network infrastructure. By enabling distributed computing and storage capabilities at the edge of the network, multi-access edge computing (MEC) serves delay sensitive, computationally intensive applications. Managing the heterogeneity of the workload generated by IoT devices, especially in terms of computing and delay requirements, while being cognizant of the cost to network operators, requires an efficient dimensioning of the MEC-enabled network infrastructure. Hence, in this paper, we study and formulate the problem of MEC resource provisioning and workload assignment for IoT services (RPWA) as a mixed integer program to jointly decide on the number and the location of edge servers and applications to deploy, in addition to the workload assignment. Given its complexity, we propose a decomposition approach to solve it which consists of decomposing RPWA into the delay aware load assignment sub-problem and the mobile edge servers dimensioning sub-problem. We analyze the effectiveness of the proposed algorithm through extensive simulations and highlight valuable performance trends and trade-offs as a function of various system parameters. Nouha Kherraf, Hyame Assem Alameddine, Sanaa Sharafeddine, Chadi Assi, Ali Ghrayeb |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2017 | Scheduling service function chains for ultra-low latency network servicesabstractThe fifth generation (5G) of cellular networks is emerging as the key enabler of killer real-time applications, such as tactile Internet, augmented and virtual reality, tele-driving, autonomous driving, etc., providing them with the much needed ultra-reliable and ultra-low latency services. Such applications are expected to take full advantages of recent developments in the areas of cloud and edge computing, and exploit emerging industrial initiatives such as Software Defined Networks (SDN) and Network Function Virtualization (NFV). Often, these 5G applications require network functions (e.g., IDSs, load balancers, etc.) to cater for their end-to-end services. This paper focuses on chaining network functions and services for these applications, and in particular considers those delay sensitive ones. Here, we account for services with deadlines and formulate the joint problem of network function mapping, routing and scheduling mathematically and highlight its complexity. Then, we present an efficient method for solving these sub-problems sequentially and validate its performance numerically. We also propose and characterize the performance of a Tabu search-based approach that we design to solve the problem. Our numerical evaluation reveals the efficiency of our sequential method and the scalability of our Tabu-based algorithm. Hyame Assem Alameddine, Long Qu, Chadi Assi |
CNSM | 1 |
| 2017 | An Efficient Survivable Design With Bandwidth Guarantees for Multi-Tenant Cloud NetworksabstractIn cloud data centers (DCs), where hosted applications share the underlying network resources, network bandwidth guarantees have shown to improve predictability of application performance and cost. However, recent empirical studies have also shown that often DC devices and links are not all that reliable and that failures may cause service outages, rendering significant revenue loss for the affected tenants, as well as the cloud operator. Accordingly, cloud operators are pressed to offer both reliable and predictable performance for the hosted applications. While much work has been done on solving both problems separately, this paper seeks to develop a joint framework by which cloud operators can offer both performance and availability guarantees for the hosted tenants. In particular, this paper considers a simple model to abstract the bandwidth guarantees requirement for the tenant and presents a protection plan design which consists of backup virtual machines (VMs) placement and bandwidth provisioning to optimize the internal DC traffic. We show through solid motivational examples that finding the optimal protection plan design is highly perplexing, and encompasses several constituent challenges. Owing to its complexity, we decompose it into two subproblems, and solve them separately. First, we invoke a placement subproblem of the minimum number of backup VMs and then we explore the most efficient correspondence between backup and primary VMs (i.e., protection plan) which minimizes the bandwidth redundancy. Further, we study the design of various facets of such a plan by exploiting bandwidth sharing opportunities in multi-tenant cloud networks. Hyame Assem Alameddine, Sara Ayoubi, Chadi Assi |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2017 | On the Interplay Between Network Function Mapping and Scheduling in VNF-Based Networks: A Column Generation ApproachabstractMiddleboxes (i.e., firewall, cache, proxy, etc.) are hardware appliances designed to enforce security and performance policies. Being an integral part of today's cloud and enterprise networks, these middleboxes are expensive, hard to manage and to maintain. Network function virtualization has emerged as a promising technology that replaces these hardware appliances by software ones known as virtual network functions (VNFs). Unlike hardware middleboxes, VNFs can be instantiated and deployed on virtual machines running on commodity servers which ensures their flexibility, manageability, cost-efficiency, and reduce their time-to-market. However, efficiently processing services through an ordered chain of VNFs, called service function chaining (SFC), is not trivial. It requires solving three inter-related sub-problems; the network functions (NFs) mapping sub-problem, the traffic routing sub-problem and the service scheduling sub-problem. This paper first highlights the existing interplay between the three sub-problems and then presents a formulation of the SFC scheduling (SFCS) which exploits interactions between NFs mapping onto VNFs, service scheduling and traffic routing. Given the complexity of the SFCS problem, we present a novel primal-dual decomposition using column generation that solves exactly a relaxed version of the problem and can serve as a benchmark approach. We enhance our solution methodology with a diversification technique to help improve the quality of the obtained solutions. We evaluate numerically our method and show that it can attain optimal solutions substantially faster. Finally, we present several engineering insights for improving the network performance. Hyame Assem Alameddine, Samir Sebbah, Chadi Assi |
IEEE Trans. Netw. Serv. Manag. | 1 |