Maxime Compastié

dblp:194/1490 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
3since 2021 · last 2026
0000-0001-7399-709XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2026 MTS-GAN: Synthetic multivariate time series generation with the Mamba architecture
abstract
The availability of high-quality data is fundamental to the development of robust machine learning workflows. Nevertheless, in complex real-world settings, acquiring qualitative datasets is often both costly and time-consuming. This limitation frequently necessitates the generation of synthetic data, not only to address data scarcity issues but also to provide a mechanism for information sharing while preserving privacy. This paper presents a novel method for multivariate synthetic time-series generation based on a Mamba architecture, namely MTS-GAN, that generates realistic and long-span multivariate time series. Our approach outperforms existing GAN-based methods in generative quality while overcoming the significant computational and inference-time limitations inherent in state-of-the-art diffusion models such as Diffusion-TS. Through a comparative analysis, we demonstrate that MTS-GAN achieves slightly superior results to Diffusion-TS across the majority of tested scenarios, but with a much more efficient architecture that scales linearly with sequence length. We validate our approach using both open-source datasets as a foundational benchmark and a real-world case study centered on predictive maintenance for a milling machine, confirming its practical efficacy and superior efficiency in handling long-sequence data.
Santiago Escuder Folch, Oriol Graupera-Serra, Albert Calvo, Borja Tornos, Gorka Gutiérrez, Josep Escrig, Maxime Compastié
Knowl. Based Syst.7
2025 RBD24 : A labelled dataset with risk activities using log application data
abstract
This paper introduces the Risk Activities Dataset 2024 (RBD24), an open-source dataset designed to facilitate the identification and analysis of risk activities within the cybersecurity domain. The RBD24 Dataset is derived from multimodal application logs collected over a two-week period at a Spanish state university, identifying activities aligned with the early stages of the attack scenario. This dataset paves the way for novel User and Entity behaviour Analytics (UEBA) and risk assessment frameworks within the cybersecurity domain. In detail, the dataset offers a fully user-centric approach by providing ground-truth data for various risk behaviours, including cryptocurrency activities, outdated software usage, P2P file sharing, and phishing incidents. These ground-truth data, identified through intrusion detection systems (IDS) and experimental campaigns, are represented as a set of indicators extracted from DNS, HTTP, SSL, and SMTP protocol logs. This dataset is expected to be a valuable resource for developing and benchmarking cybersecurity models, particularly in the realm of risk behaviour assessment.
Albert Calvo, Santiago Escuder, Nil Ortiz, Josep Escrig, Maxime Compastié
Comput. Secur.5
2024 Proxy Re-Encryption for Enhanced Data Security in Healthcare: A Practical Implementation
abstract
In the rapidly evolving digital healthcare landscape, the imperative for robust, flexible, and scalable data protection solutions has never been more critical. The advent of sophisticated cyber threats, coupled with the increasing complexity of healthcare IT infrastructures, underscores the necessity for advanced security mechanisms that can adapt to a wide range of challenges without compromising the accessibility or integrity of sensitive healthcare data. Within this context, our work introduces the SECANT Privacy Toolkit, a pioneering approach that harnesses the power of Proxy Re-Encryption (PRE) to redefine healthcare data security. We present an implementation prototype that not only serves as a baseline for the quantitative evaluation of healthcare data protection but also exemplifies the SECANT Toolkit’s capability to enhance interoperability across disparate healthcare systems, strengthen authentication mechanisms, and ensure scalability amidst the growing data demands of modern healthcare networks. This prototype underscores our commitment to addressing the multifaceted security needs of the healthcare sector by providing a solution that is both comprehensive and adaptable to the dynamic landscape of digital health information security.By integrating cutting-edge cryptographic technologies, including Attribute-Based Encryption (ABE) and Searchable Encryption (SE), with the flexibility and control offered by PRE, the SECANT Privacy Toolkit stands at the forefront of secure and efficient healthcare data management. This integration facilitates not only the secure exchange of data across decentralized networks but also empowers healthcare providers with tools for fine-grained access control and privacy-preserving data searches, thereby addressing key challenges such as data interoperability, cybersecurity threats, and regulatory compliance.Our exploration reveals the toolkit’s potential to revolutionize the way healthcare data is protected, shared, and accessed, providing a scalable, efficient, and user-friendly platform for healthcare providers, patients, and stakeholders. The SECANT Privacy Toolkit not only aligns with current healthcare data security requirements but also anticipates future challenges, ensuring that it remains a vital asset in the ongoing effort to safeguard sensitive healthcare information. This work contributes significantly toward enhancing the security and privacy of healthcare data, offering a robust framework for interoperability, authentication, and scalability that responds to the evolving needs of the healthcare industry. Through the deployment of our prototype and the subsequent evaluation, we aim to demonstrate the practicality, effectiveness, and transformative potential of the SECANT Privacy Toolkit in advancing healthcare data protection.
Saber Mhiri, Alfonso Egio, Maxime Compastié, Pablo Cosio
ARES3
2020 From virtualization security issues to cloud protection opportunities: An in-depth analysis of system virtualization models
Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He
Comput. Secur.1
2019 A TOSCA-Oriented Software-Defined Security Approach for Unikernel-Based Protected Clouds
abstract
Cloud infrastructures provide new facilities to build elaborated added-value services by composing and configuring a large variety of computing resources, from virtualized hardware devices to software products. In the meantime, they are further exposed to security attacks than traditional environments. The complexity of security management tasks has been increased by the multi-tenancy, heterogeneity and geographical distribution of these resources. They introduce critical issues for cloud service providers and their customers, with respect to security programmability and scenarios of adaptation to contextual changes. In this paper, we propose a software-defined security approach based on the TOSCA language, to enable unikernel-based protected clouds. We first introduce extensions of this language to describe unikernels and specify security constraints for their orchestrations. We then describe an architecture exploiting this extended version of TOSCA for automatically generating, deploying and adjusting cloud resources in the form of protected unikernels with a low attack surface. We finally detail a proof-of-concept prototype, and evaluate the proposed solution through extensive series of experiments.
Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He
NetSoft1
2018 Demo: On-the-fly generation of unikernels for software-defined security in cloud infrastructures
abstract
The programmability of security mechanisms through software-defined security permits the outsourcing of security management to a dedicated plan. Unikernels offer new perspectives for supporting this programmability, and addressing the challenges with respect to the heterogeneity and the dynamics of cloud resources. In this demo, we demonstrate how unikernel properties may enable an adequate security enforcement at the resource level. We present a framework for integrating security mechanisms into unikernel virtual machines, and align them to a given security policy, through the on-the-fly unikernel VM generation. We showcase an implementation prototype and confront it to cloud exploitation scenarios.
Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He
NOMS1
2018 Unikernel-based approach for software-defined security in cloud infrastructures
abstract
The heterogeneity of cloud resources implies substantial overhead to deploy and configure adequate security mechanisms. In that context, we propose a software-defined security strategy based on unikernels to support the protection of cloud infrastructures. This approach permits to address management issues by uncoupling security policy from their enforcement through programmable security interfaces. It also takes benefits from unikernel virtualization properties to support this enforcement and provide resources with low attack surface. These resources correspond to highly constrained configurations with the strict minimum for a given period. We describe the management framework supporting this software-defined security strategy, formalizing the generation of unikernel images that are dynamically built to comply with security requirements over time. Through an implementation based on MirageOS, and extensive experiments, we show that the cost induced by our security integration mechanisms is small while the gains in limiting the security exposure are high.
Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He, Mohamed Kassi-Lahlou
NOMS1
2016 A Software-Defined Security Strategy for Supporting Autonomic Security Enforcement in Distributed Cloud
abstract
We propose in this paper a software-defined security framework, for supporting the enforcement of security policies in distributed cloud environments. These ones require security mechanisms able to cape with their multi-tenancy and multi-cloud properties. This framework relies on the autonomic paradigm to dynamically configure and adjust these mechanisms to distributed cloud constraints, and exploit the software-defined logic to express and propagate security policies to the considered cloud resources. The proposed framework is evaluated through a set of validation scenarios corresponding to a realistic use cases including cloud resource allocation/deallocation, cloud resource state change, and dynamic access control.
Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He, Mohamed Kassi-Lahlou
CloudCom1