EDBT 2026 Demo / reviewers in the wild / expert
Guillaume Auriol
dblp:23/6043
· DBLP profile ↗
14ranked-venue papers
0as first author
8since 2021 · last 2025
0009-0001-2775-5345ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 7 since 2021Software engineering, systems software and programming languages · 4 · 1 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SIROCCO: A Dry Wind to Warn you from Bluetooth AttacksabstractBluetooth Low Energy (BLE) has become ubiquitous in Internet of Things (IoT) devices, yet it remains vulnerable to sophisticated over-the-air attacks that can compromise data security. This paper introduces Sirocco, a novel host-based intrusion detection system that leverages the open source Zephyr RTOS to address critical security challenges in BLE communications. Sirocco provides a flexible and lightweight detection framework that integrates with the BLE protocol stack. It targets sophisticated and low-level attacks such as spoofing, signal injection, and key sharing vulnerabilities. By inserting lightweight metric collection functions directly into the BLE stack's interrupt service routines and employing a dedicated kernel thread for analysis, Sirocco minimizes performance overhead while maintaining real-time attack detection capabilities across different device roles. Experimental evaluation demonstrates the system's effectiveness, with the framework introducing minimal performance and power consumption overhead. Paul L. R. Olivier, Florent Galtier, Guillaume Auriol, Vincent Nicomette, Romain Cayre |
PRDC | 3 |
| 2024 | OASIS: An Intrusion Detection System Embedded in Bluetooth Low Energy ControllersabstractBluetooth Low Energy has established itself as one of the central protocols of the Internet of Things. Its many features (mobility, low energy consumption) make it an attractive protocol for smart devices. However, numerous critical vulnerabilities affecting BLE have been made public in recent years, some of which are linked to the protocol's design itself. The impossibility of correcting these vulnerabilities without affecting the specification requires the development of effective intrusion detection systems, enabling the detection and prevention of these threats. Unfortunately, the protocol relies on peer-to-peer communications and introduces many complex and dynamic mechanisms (e.g., channel hopping), making monitoring complex, costly and limited. Existing intrusion detection approaches lack flexibility, are limited in scope and introduce high deployment costs. Romain Cayre, Vincent Nicomette, Guillaume Auriol, Mohamed Kaâniche, Aurélien Francillon |
AsiaCCS | 3 |
| 2024 | Wireless Modulation Identification: Filling the Gap in IoT Networks Security Audit
Florent Galtier, Guillaume Auriol, Vincent Nicomette, Paul L. R. Olivier, Romain Cayre, Mohamed Kaâniche |
DIMVA | 2 |
| 2021 | WazaBee: attacking Zigbee networks by diverting Bluetooth Low Energy chipsabstractThis paper discusses the security of wireless communication protocols of the Internet of Things (IoT) and presents a new attack targeting these protocols, called WazaBee, which could have a critical impact and be difficult to detect. Specifically, WazaBee is a pivotal attack aimed at hijacking BLE devices, commonly used in IoT networks, in order to communicate with and possibly attack through a different wireless network technology, considering protocols based on 802.15.4, in particular Zigbee. We present the key principles of the attack and describe some real-world experiments that allowed us to demonstrate its practical feasibility. The attack takes advantage of the compatibility that exists between the two modulation techniques used by these two protocols. Finally, the paper briefly discusses possible countermeasures to mitigate the impact of this attack. Romain Cayre, Florent Galtier, Guillaume Auriol, Vincent Nicomette, Mohamed Kaâniche, Géraldine Vache Marconato |
DSN | 3 |
| 2021 | InjectaBLE: Injecting malicious traffic into established Bluetooth Low Energy connectionsabstractBluetooth Low Energy (BLE) is nowadays one of the most popular wireless communication protocols for Internet of Things (IoT) devices. As a result, several attacks have targeted this protocol or its implementations in recent years, illustrating the growing interest for this technology. However, some major challenges remain from an offensive perspective, such as injecting arbitrary frames, hijacking the Slave role or performing a Manin-The-Middle in an already established connection. In this paper, we describe a novel attack called InjectaBLE, allowing to inject malicious traffic into an existing connection. This attack is highly critical as the vulnerability exploited is inherent to the BLE specification itself, which means that any BLE connection can be possibly vulnerable, regardless of the BLE devices involved in the connection. We describe the theoretical foundations of the attack, how to implement it in practice, and we explore four critical attack scenarios allowing to maliciously trigger a specific feature of the target device, hijack the Slave and Master role or to perform a Man-in-the-Middle attack. Finally, we discuss the impact of this attack and outline some mitigation measures. Romain Cayre, Florent Galtier, Guillaume Auriol, Vincent Nicomette, Mohamed Kaâniche, Géraldine Vache Marconato |
DSN | 3 |
| 2021 | A defensive man-in-middle approach to filter BLE packetsabstractIn this paper, we propose an original defensive strategy in which we benefit from the use of Man-in-The-Middle attacks in order to protect some vulnerable BLE devices. More precisely, we describe a tool that uses a Man-in-The-Middle attack to implement a wireless firewall for BLE communications, that is able to block specific commands, make some services invisible on BLE devices, or to force out weak pairing mechanisms. Ahmed Aboukora, Guillaume Bonnet, Florent Galtier, Romain Cayre, Vincent Nicomette, Guillaume Auriol |
WISEC | 6 |
| 2021 | Cross-protocol attacks: weaponizing a smartphone by diverting its bluetooth controllerabstractIn this paper, we focus on a new type of wireless attacks, named cross-technology pivoting attacks. The main objective of these attacks is to divert the transceivers of compromised devices dedicated to a given protocol to allow them to communicate through another protocol, taking advantage of some similarities in their modulation schemes. The main contribution of this work consists in demonstrating the practical feasibility of pivoting attacks from off-the-shelf devices implementing the Bluetooth 5.0 specification. To our knowledge, this attack has not been explored so far in the state of the art. Romain Cayre, Géraldine Vache Marconato, Florent Galtier, Mohamed Kaâniche, Vincent Nicomette, Guillaume Auriol |
WISEC | 6 |
| 2021 | RIDS: Radio Intrusion Detection and Diagnosis System for Wireless Communications in Smart EnvironmentabstractThe expansion of the Internet-of-Things (IoT) market is visible in homes, factories, public places, and smart cities. While the massive deployment of connected devices offers opportunities to improve quality of life and to develop new services, the impact of such devices on the security of the users in a context where the level of malicious threat continues to increase is a major concern. One of the challenges is the heterogeneity and constant evolution of wireless technologies and protocols used. To overcome this problem, we propose RIDS, a Radio Intrusion Detection System that is based on the monitoring and profiling of radio communications at the physical layer level using autoencoder neural networks. RIDS is independent of the wireless protocols and modulation technologies used. Besides, it is designed to provide a threefold diagnosis of the detected anomalies: temporal (start and end date of the detected anomaly), frequential (main frequency of the anomaly), and spatial (location of the origin of the anomaly). To demonstrate the relevance and the efficiency of our approach, we collected a large dataset of radio-communications recorded with three different probes deployed in an experimental room. Multiple real-world attacks involving a wide variety of communication technologies are also injected to assess the detection and diagnosis efficiency. The results demonstrate the efficiency of RIDS in detecting and diagnosing anomalies that occurred in the 400–500 Mhz and 800–900 Mhz frequency bands. It is noteworthy that compromised devices and attacks using these communication bands are generally not easily covered by traditional solutions. Pierre-François Gimenez, Jonathan Roux, Eric Alata, Guillaume Auriol, Mohamed Kaâniche, Vincent Nicomette |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2020 | A PSD-based fingerprinting approach to detect IoT device spoofingabstractSpoofing attacks are generally difficult to detect and can have potentially harmful consequences on computer networks and applications. Wireless IoT networks, in the context of smart buildings or smart factories, are particularly vulnerable to these attacks. In this paper, we present a new physical device fingerprinting approach aiming at detecting spoofing attacks in wireless IoT environments. The proposed approach is based on the analysis of some properties of the physical signals emitted by connected devices, using their Power Spectral Density (PSD) to extract a frequency profile of their communications. This approach does not require any expensive equipment, is easy to deploy, and is resilient to non predictable phenomena in transmissions. The detection of spoofing attacks consists in comparing the fingerprint of a transmitting device with previously stored fingerprints of legitimate devices, by measuring the similarity of the corresponding PSDs and applying a community detection algorithm. The efficiency of this approach has been successfully tested using various experimental setups with connected devices supporting different wireless protocols (BLE, Zigbee). We also discuss the practical applicability of our approach, e.g. in an industrial environment by analysing its scalability and proposing solutions to tune and optimize its deployment at a large scale. Florent Galtier, Romain Cayre, Guillaume Auriol, Mohamed Kaâniche, Vincent Nicomette |
PRDC | 3 |
| 2019 | Mirage: Towards a Metasploit-Like Framework for IoTabstractInternet of Things (IoT) devices are nowadays widely used in individual homes and factories. Securing these new systems becomes a priority. However, conducting security audits of these connected objects based on experimental evaluation is a challenging task: it requires the use of heterogeneous hardware components leading to a set of specialised software tools, generally incompatible with each other and often complex to use. In this paper, we present a security audit and penetration testing framework called Mirage. This framework, written in Python, is dedicated to the analysis of wireless communications commonly used by IoT devices, and provides a generic, modular, unified and low level audit environment that is easy to adapt to new protocols. The paper describes the software architecture of Mirage, its goals and main features, and presents a concrete example of security audit performed with this framework. Romain Cayre, Vincent Nicomette, Guillaume Auriol, Eric Alata, Mohamed Kaâniche, Géraldine Vache Marconato |
ISSRE | 3 |
| 2018 | RadIoT: Radio Communications Intrusion Detection for IoT - A Protocol Independent ApproachabstractInternet-of-Things (IoT) devices are nowadays massively integrated in daily life: homes, factories, or public places. This technology offers attractive services to improve the quality of life as well as new economic markets through the exploitation of the collected data. However, these connected objects have also become attractive targets for attackers because their current security design is often weak or flawed, as illustrated by several vulnerabilities such as Mirai, Blueborne, etc. This paper presents a novel approach for detecting intrusions in smart spaces such as smarthomes, or smartfactories, that is based on the monitoring and profiling of radio communications at the physical layer using machine learning techniques. The approach is designed to be independent of the large and heterogeneous set of wireless communication protocols typically implemented by connected objects such as WiFi, Bluetooth, Zigbee, Bluetooth-Low-Energy (BLE) or proprietary communication protocols. The main concepts of the proposed approach are presented together with an experimental case study illustrating its feasibility based on data collected during the deployment of the intrusion detection approach in a smart home under real-life conditions. Jonathan Roux, Eric Alata, Guillaume Auriol, Mohamed Kaâniche, Vincent Nicomette, Romain Cayre |
NCA | 3 |
| 2010 | Understanding Customer Expectations for System DevelopmentabstractMeaning of expectations and differences among needs, expectations and requirements are ambiguous in literatures and practice. In this paper, we contribute to give a possible clarification of this ambiguity. The relationships among needs, expectations and requirements are examined together with characterization of customer expectations. We also introduce the expectations elicitation process based on engineering approach, which provides an explicit and controllable elicitation with a corresponding expectations elicitation quality model. Our goal is finally to connect expectations with value dimensions to enable value based requirements engineering. Xinwei Zhang 0003, Guillaume Auriol, Claude Baron |
ICSEA | 2 |
| 2006 | A user-based approach for the choice of the IP services in the multi domains DiffServ InternetabstractThis paper deals with the design of a distributed architecture and of mechanisms that are able to guarantee quality of service (QoS) in a set of DiffServ domains. The design includes the proposal of a signaling protocol to accept or reject the transmission of flows in a set of adequately controlled domains. More particularly, it provides a proposal for (1) selecting the end-to-end QoS paths resulting from concatenations of the IP services provided by the domains involved in the data path and (2) ensuring that the chosen concatenations fulfil the requested user QoS requirements. With respect to other work, this paper first tries to minimise the use of network resources by discovering the real performance of each domain. Second, the signaling protocol is designed to bring as less constraints as possible on the architecture. It defines the end-to-end concatenations only as a set of transfer bridges, or inter-domain links, and leaves all internal domain paths fully open to any implementation by the domain providers. The architecture, based on the use of bandwidth brokers, provides an answer to the two main problems related to such approaches, i.e. how to identify and build the sequence of the needed bandwidth brokers and how to select the ingress and egress routers of each of these domains to construct the end-to-end paths. Christophe Chassot, André Lozes, Florin Racaru, Guillaume Auriol |
AINA (2) | 4 |
| 2002 | Performance analysis for an IP Differentiated Services networkabstractResearch reported here deals with a communication architecture with guaranteed end-to-end quality of service (QoS) in an IPv6 environment providing differentiated services within a single DiffServ domain. The article successively presents the design principles and services of the proposed architecture, their implementation over a national platform, and experimental measurements evaluating the QoS provided at the user level. Christophe Chassot, Guillaume Auriol, André Lozes, Emmanuel Lochin, Pascal Anelli |
ICC | 3 |