Helmi Rais

dblp:209/5150 · DBLP profile ↗
← Back
11ranked-venue papers
0as first author
10since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021
YearPublicationVenuePosition
2026 ELISAR: A Multi-Agent cybersecurity framework integrating retrieval-augmented generation for Blue, Red, and GRC operations
Sabri Allani, Karam Bou Chaaya, Helmi Rais
World Wide Web (WWW)3
2025 Decentralized Post-Quantum Authentication Protocol for Drone Communication Networks
abstract
This paper introduces a novel post-quantum mutual authentication scheme for drones, leveraging Physical Unclonable Functions (PUFs) and cryptographic accumulators. By integrating PUFs, the scheme effectively mitigates drone cloning risks, while lattice-based cryptography ensures resilience against quantum computing attacks. The proposed approach enables secure, direct mutual authentication between drones without intermediaries. Cryptographic accumulators compress the entire drone identity database into a single element, significantly reducing storage demands on individual drones. The proposed scheme achieves superior communication efficiency compared to existing PUF-based post-quantum protocols for drones. Formal security verification using ProVerif confirms the robustness of the proposed scheme.
Edoukou Berenger Ayebie, Elie Noumon Allini, Karam Bou Chaaya, Helmi Rais
AICCSA4
2025 Challenges of Attack Automation in AI Models: Toward a Red Teaming Strategy
abstract
Artificial Intelligence (AI) models differ from traditional software targets because stochastic training, data drift, and continual updates make their decision boundaries a moving target. We study how such randomness undermines the stability and automation of red-team attacks. First, we map where variability arises along the data, training, and deployment phases, embed it as a fourth dimension in a unified threat model, and measure its effect with three model-similarity metrics. Building on these observations, we introduce a concise five-level variability scale ($\rho$) that links the degree of randomness to the feasibility of scripted, semi-automated, or human-driven exploits. The experiments indeed show exploit transferability dropping as randomness increases; however, “modest increases in $\rho$ “ causing sharp drops is mostly true in higher-dimensional or multi-class settings. The proposed model, metrics, and scale give red teams a principled basis for planning, quantifying, and adapting attacks against continually evolving AI pipelines.
Hassan Chaitou, Karam Bou Chaaya, H. A. Njaka, Helmi Rais
AICCSA4
2025 ForenSys: Semantic Assistant for Expressive Cyber Forensics in Connected Vehicles
abstract
Connected and autonomous vehicles (CAVs) rely on complex, interconnected communication systems, making them vulnerable to cybersecurity threats. Digital forensics offers vital tools for investigating cyberattacks, yet investigators encounter substantial obstacles. A key challenge is the hesitation of manufacturers and component suppliers to provide critical logs, restricting access to essential data. Moreover, analyzing incidents is complicated by the need to gather and process heterogeneous data from sources like Electronic Control Units (ECUs), sensors, user interactions, and contextual knowledge. Investigators also face challenges due to the heterogeneity of forensic data, the need for real-time reasoning, and the limited interpretability of black-box AI models. To tackle these issues, we introduce ForenSys, a semantic rule-based reasoning system tailored for cyberattack investigations in CAVs. ForenSys integrates varied data sources through an Information Management Module and employs a semantic reasoning engine aligned with MITRE ATT&CK techniques for automated analysis. Powered by AI, it supports dynamic, real-time forensic operations, revealing hidden data connections to reconstruct events despite limited access. ForenSys also correlates cyberattacks with tactics, techniques, timing, and location, delivering transparent and explainable analysis. Its efficacy is validated through implementation and testing in vehicle cyberattack scenarios.
Amani Abou Rida, Hamza Khemissa, Karam Bou Chaaya, Helmi Rais
AICCSA4
2024 Q-Auth: Decentralized and Quantum-Secure Authentication Protocol for Vehicular Networks
Marwa Chaieb, Karam Bou Chaaya, Helmi Rais
CRiSIS3
2024 ECU-KM: An Efficient Key Management for In-Vehicle Networks
Hamza Khemissa, Karam Bou Chaaya, Helmi Rais
CRiSIS3
2024 ELISAR: An Adaptive Framework for Cybersecurity Risk Assessment Powered by GenAI
Sabri Allani, Karam Bou Chaaya, Helmi Rais
MEDES3
2023 A New Efficient PUF-Based Mutual Authentication Scheme for Drones
Edoukou Berenger Ayebie, Karam Bou Chaaya, Helmi Rais
CRiSIS3
2023 EHRVault: A Secure, Patient-Centric, Privacy-Preserving and Blockchain-Based Platform for EHR Management
Marwa Chaieb, Karam Bou Chaaya, Helmi Rais
CRiSIS3
2023 zk-BeSC: Confidential Blockchain Enabled Supply Chain Based on Polynomial Zero-Knowledge Proofs
abstract
Blockchain technology promises a disruptive enhancement in trust establishment among supply chain actors. In particular, transparency and traceability can significantly get improved by a blockchain based data exchange platform which provides an immutable source of truth driven by a multi-stakeholder consensus. This also helps authenticate the provenance of products which is an added value that can be monetized by the supply chain participants. Nonetheless, due to the transparent nature of the blockchain, privacy and confidentiality are still a major concern for industries. In this paper, we present zk-BeSC, a blockchain enabled supply chain scheme based on zero-knowledge proofs of polynomials. The scheme allows transactions between supply chain participants in a privacy preserving fashion. It also offers tamper-resistance and replication due to the intrinsic nature of the blockchain. ZK-BeSC is fully implemented using an ethereum testnet and a web3 application. The scheme performs efficient proofs and has reduced gas consumption during verification.
Jaouaher Zouari Nasri, Helmi Rais
IWCMC2
2018 A survey on technical threat intelligence in the age of sophisticated cyber attacks
Wiem Tounsi, Helmi Rais
Comput. Secur.2