Aymen Boudguiga

dblp:24/8061 · DBLP profile ↗
← Back
26ranked-venue papers
5as first author
13since 2021 · last 2025
0000-0001-6717-8848ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 2 first-author · 10 since 2021Computer networks · 5 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Unveiling the (in)Security of Threshold FHE-Based Federated Learning: The Practical Impact of Recent CPAD Attacks
abstract
The security of Fully Homomorphic Encryption (FHE) has received a lot of attention in recent years with new security notions emerging to better understand the practical attacks that may threaten the real-world deployments of passively secure FHE schemes. One such new notions is CPAD a slight extension of CPA security modelling a passive adversary who is granted access to a decryption oracle accepting only well-formed ciphertexts. While successful CPAD attacks have initially been performed on approximate FHE schemes such as CKKS, recent works have also demonstrated practical CPAD attacks on all mainstream non-approximate FHE, such as BFV, BGV or TFHE. Despite their clear computational practicality, these latter attacks however focus on the abstract security game defining CPAD security. In this paper, we show how to concretely build on these to mount successful FHE key recovery attacks in the Federated Learning (FL) setting, an application scenario of choice for FHE techniques. In FL, participating entities or workers encrypt successive model updates based on their local training data, enabling a central server to aggregate them in order to homomorphically update a global model. As this paper demonstrates, this environment provides a playground for an attacker to launch key recovery attacks against the FHE underlying the secure aggregation mechanism. As such, our findings reveal substantial stealthy key-recovery threats from both the server and a single worker, with very limited impact on the FL training progression or final model quality.
Adda-Akram Bendoukha, Renaud Sirdey, Aymen Boudguiga, Nesrine Kaaniche
CSF3
2025 FairCognizer: A Model for Accurate Predictions with Inherent Fairness Evaluation (Extended Abstract)
abstract
Algorithmic fairness is a critical challenge in building trustworthy Machine Learning (ML) models. ML classifiers strive to make predictions that closely match real-world observations (ground truth). However, if the ground truth data itself reflects biases against certain sub-populations, a dilemma arises: prioritize fairness and potentially reduce accuracy, or emphasize accuracy at the expense of fairness. This work proposes a novel training framework that goes beyond achieving high accuracy. Our framework trains a classifier to not only deliver optimal predictions but also to identify potential fairness risks associated with each prediction. To do so, we specify a dual-labeling strategy where the second label contains a per-prediction fairness evaluation, referred to as an unfairness risk evaluation. In addition, we identify a subset of samples as highly vulnerable to group-unfair classifiers. Our experiments demonstrate that our classifiers attain optimal accuracy levels on both the Adult-Census-Income and Compas-Recidivism datasets. Moreover, they identify unfair predictions with nearly 75% accuracy at the cost of expanding the size of the classifier by 45%.
Adda-Akram Bendoukha, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey
IJCAI3
2025 Towards Privacy-preserving and Fairness-aware Federated Learning Framework
abstract
Federated Learning (FL) enables the distributed training of a model across multiple data owners under the orchestration of a central server responsible for aggregating the models generated by the different clients. However, the original approach of FL has significant shortcomings related to privacy and fairness requirements. Specifically, the observation of the model updates may lead to privacy issues, such as membership inference attacks, while the use of imbalanced local datasets can introduce or amplify classification biases, especially for minority groups. In this work, we show that these biases can be exploited to increase the likelihood of privacy attacks against these groups. To do so, we propose a novel inference attack exploiting the knowledge of group fairness metrics during the training of the global model. Then to thwart this attack, we define a fairness-aware encrypted-domain aggregation algorithm that is differentially-private by design thanks to the approximate precision loss of the threshold multi-key CKKS homomorphic encryption scheme. Finally, we demonstrate the good performance of our proposal both in terms of fairness and privacy through experiments conducted over three real datasets.
Adda-Akram Bendoukha, Didem Demirag, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey, Sébastien Gambs
Proc. Priv. Enhancing Technol.4
2024 On the Practical CPAD Security of "exact" and Threshold FHE Schemes and Libraries
Marina Checri, Renaud Sirdey, Aymen Boudguiga, Jean-Paul Bultel
CRYPTO (3)3
2024 FairCognizer: A Model for Accurate Predictions with Inherent Fairness Evaluation
abstract
Algorithmic fairness is a critical challenge in building trustworthy Machine Learning (ML) models. ML classifiers strive to make predictions that closely match real-world observations (ground truth). However, if the ground truth data itself reflects biases against certain sub-populations, a dilemma arises: prioritize fairness and potentially reduce accuracy, or emphasize accuracy at the expense of fairness. This work proposes a novel training framework that goes beyond achieving high accuracy. Our framework trains a classifier to not only deliver optimal predictions but also to identify potential fairness risks associated with each prediction. To do so, we specify a dual-labeling strategy where the second label contains a per-prediction fairness evaluation, referred to as an unfairness risk evaluation. In addition, we identify a subset of samples as highly vulnerable to group-unfair classifiers. Our experiments demonstrate that our classifiers attain optimal accuracy levels on both the Adult-Census-Income and Compas-Recidivism datasets. Moreover, they identify unfair predictions with nearly 75% accuracy at the cost of expanding the size of the classifier by a mere 45%.
Adda-Akram Bendoukha, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey
ECAI3
2024 A Decentralized Federated Learning Using Reputation
Olive Chakraborty, Aymen Boudguiga
ICISSP2
2024 chiku: Efficient Probabilistic Polynomial Approximations Library
Devharsh Trivedi, Nesrine Kaaniche, Aymen Boudguiga, Nikos Triandopoulos
SECRYPT3
2023 Optimized Stream-Cipher-Based Transciphering by Means of Functional-Bootstrapping
Adda-Akram Bendoukha, Pierre-Emmanuel Clet, Aymen Boudguiga, Renaud Sirdey
DBSec3
2023 Lightweight FHE-based Protocols Achieving Results Consistency for Data Encrypted Under Different Keys
abstract
International audience
Marina Checri, Jean-Paul Bultel, Renaud Sirdey, Aymen Boudguiga
SECRYPT4
2022 Cooperative and smart attacks detection systems in 6G-enabled Internet of Things
abstract
The Sixth Generation (6G) of mobile networks offers the promise of a global interconnected system, serving a large set of applications across multiple fields such as satellite, air, ground, and underwater networks. It will evolve towards a unified network compute fabric that facilitates convergence across ecosystems, fostering design and innovation of new Internet of Things (IoT) applications and services, further leading to an exponential growth of IoT use cases in the post-6G era. This profound evolution will also impact the threat landscape, adding new threat actors, and leading to a new set of cyber security challenges. This paper reviews 6G applications and analyzes their security challenges and existing solutions, covering both the network, application and data layers. It introduces a new concept to security monitoring and attack detection in 6G-enabled IoT systems, leveraging on hierarchical and collaborative approaches, while also satisfying the main 6G’s Key Performance Indicators (KPIs) such as trustworthiness, latency, connectivity, data rate and energy consumption. The proposed solution implements a multi-level Federated Learning (FL) approach between IoT devices and edge computing applications. As compared to current centralized security monitoring and detection solutions, it conciliates better between the attack detection accuracy and the network overhead for implementing this model. We demonstrate the use of the proposed solution through an example scenario involving an Internet of Vehicles that communicate over a 6G network.
Hichem Sedjelmaci, Nizar Kheir, Aymen Boudguiga, Nesrine Kaaniche
ICC3
2022 Efficient Hybrid Model for Intrusion Detection Systems
abstract
International audience
Nesrine Kaaniche, Aymen Boudguiga, Gustavo Gonzalez Granadillo
SECRYPT2
2022 A Secure Federated Learning: Analysis of Different Cryptographic Tools
abstract
International audience
Oana Stan, Vincent Thouvenot, Aymen Boudguiga, Katarzyna Kapusta, Martin Zuber, Renaud Sirdey
SECRYPT3
2021 Privacy Preserving Services for Intelligent Transportation Systems with Homomorphic Encryption
abstract
International audience
Aymen Boudguiga, Oana Stan, Abdessamad Fazzat, Houda Labiod, Pierre-Emmanuel Clet
ICISSP1
2020 Secure Data Processing for Industrial Remote Diagnosis and Maintenance
Walid Arabi, Reda Yaich, Aymen Boudguiga, Mawloud Omar
CRiSIS3
2020 Homomorphic Encryption at Work for Private Analysis of Security Logs
abstract
International audience
Aymen Boudguiga, Oana Stan, Hichem Sedjelmaci, Sergiu Carpov
ICISSP1
2019 Privacy-Preserving k-means Clustering: an Application to Driving Style Recognition
Othmane El Omri, Aymen Boudguiga, Malika Izabachène, Witold Klaudel
NSS2
2019 An efficient cyber defense framework for UAV-Edge computing network
Hichem Sedjelmaci, Aymen Boudguiga, Inès Ben Jemaa, Sidi-Mohammed Senouci
Ad Hoc Networks2
2018 A generic cyber defense scheme based on stackelberg game for vehicular network
abstract
The main purpose of the vehicular networks is ensuring road safety while providing passengers comfort. Thus, information security is one of the most important issues, which attracts researchers attention. Thereby, in this paper we propose a generic cyber defense scheme based on Stackelberg game to secure the vehicular network against cyber-attackers. In this game, we define two different players, the leader agent and follower agents which collaborate between each other to secure the vehicle node. The follower agents are Intrusion Detection System (IDS), Intrusion Prevention System (IPS) and Intrusion Reaction System (IRS) which aim to detect, predict and react respectively against the suspected node. The leader agent is the Intrusion Decision Agent (IDA), which has the capability to launch the IDS, IPS and IRS by taking into account the overhead and processing delay. Simulation resultants show that, our security scheme exhibits a low false positive and false negative rates, while generating a low overhead and delay as compared to the current detection and predication frameworks.
Hichem Sedjelmaci, Imane Horiya Brahmi, Aymen Boudguiga, Witold Klaudel
CCNC3
2018 Cooperative Security Framework for CBTC Network
abstract
Railway networks could be subject to cyberattacks due to security breaches of their communication systems. The Communications-Based Train Control (CBTC) is considered as the main organ of a railway network. CBTC controls movements of trains and manages messages exchanged between the different systems of railways. In this paper, we propose a cooperative detection framework to secure the CBTC against attackers that execute locally a malicious software (i.e., internal threats) and/or spread and deliver an attack from an external network (i.e., external threats). The present detection framework has two main security systems: host and network detection system, and human-machine interaction system. When these security systems run in a cooperative way, the attack detection and false alarm rates are improved, while the expected attack damage rate is reduced. The framework is integrated in a real sub-systems of railway network and according to experiments results, we show that it is capable to detect accurately sophisticated cyber-attacks, such as fault data injection and flooding attacks.
Hichem Sedjelmaci, Fateh Guenab, Aymen Boudguiga, Yohann Petiot
ICC3
2016 A simple intrusion detection method for controller area network
abstract
The Controller Area Network (CAN) is established as the main communication channel inside vehicles. CAN relies on frame broadcast to share data between different microcontrollers managing critical or comfort functions such as cruise control or air conditioning. CAN is distinguished by its simplicity, its real-time application compatibility and its low deployment cost. However, CAN major drawback is its lack of security support. That is, CAN fails to provide protections against attacks such as intrusion, denial of service or impersonation. We propose in this work a simple intrusion detection method for CAN. Our main idea is to make each microcontroller monitor the CAN bus to detect malicious frames.
Aymen Boudguiga, Witold Klaudel, Antoine Boulanger, Pascale Chiron
ICC1
2015 Light Blind: Why Encrypt If You Can Share?
abstract
The emergence of cloud computing makes the use of remote storage more and more common. Clouds provide cheap and virtually unlimited storage capacity. Moreover, thanks to replication, clouds offer high availability of stored data. The use of public clouds storage make data confidentiality more critical as the user has no control on the physical storage device nor on the communication channel. The common solution is to ensure data confidentiality by encryption. Encryption gives strong confidentiality guarantees but comes with a price. The time needed to encrypt and decrypt data increases with respect to the size of input data, making encryption expensive. Due to its overhead, encryption is not universally used and a non-negligible amount of data is insecurely stored in the cloud. In this paper, we propose a new mechanism, called Light Blind, that allows confidentiality of data stored in the cloud at a lower time overhead than classical cryptographic techniques. The key idea of our work is to partition unencrypted data across multiple clouds in such a way that none of them can reconstruct the original information. In this paper we describe this new approach and we propose a partition algorithm with constant time complexity tailored for modern multi/many-core architectures.
Pierpaolo Cincilla, Aymen Boudguiga, Makhlouf Hadji, Arnaud Kaiser
SECRYPT2
2013 ID Based Cryptography for Cloud Data Storage
abstract
This paper addresses the security issues of storing sensitive data in a cloud storage service and the need for users to trust the commercial cloud providers. It proposes a cryptographic scheme for cloud storage, based on an original usage of ID-Based Cryptography. Our solution has several advantages. First, it provides secrecy for encrypted data which are stored in public servers. Second, it offers controlled data access and sharing among users, so that unauthorized users or untrusted servers cannot access or search over data without client's authorization.
Nesrine Kaaniche, Aymen Boudguiga, Maryline Laurent
IEEE CLOUD2
2013 Pseudonymous communications in secure industrial wireless sensor networks
abstract
Wireless sensor networks are becoming widely deployed in the industry. They are used to provide contextual information about the industrial environment being surveyed, to control and monitor the industrial processes, and even for workers who can be augmented with sensors. In these wireless networks, an adversary can easily eavesdrop communications with the aim to collect private information about sensors, because of the open nature of the wireless medium. A usual solution to prevent privacy violation relies on the use of pseudonyms as sensor identities; however, pseudonyms may deter authentication and access control enforcement in the network. This paper introduces an efficient pseudonym-based scheme that provides privacy protection to sensors without compromising network access security.
Nouha Oualha, Alexis Olivereau, Aymen Boudguiga
PST3
2011 Key-escrow resistant ID-based authentication scheme for IEEE 802.11s mesh networks
abstract
Nowadays, ID-based cryptography is reported as an alternative to Public Key Infrastructures (PKI). It proposes to derive the public key from the node's identity directly. As such, there is no need for public key certifcates, and direct beneft of this is to remove the burdensome management of certifcates. However, the drawback is the need for a Private Key Generator (PKG) entity which can perform a key escrow attack. In this article, we present an ID-based authentication scheme that is adapted to the IEEE 802.11s mesh networks and resistant against key escrow attacks.
Aymen Boudguiga, Maryline Laurent
WCNC1
2010 An ID-based authentication scheme for the IEEE 802.11s Mesh Network
abstract
Nowadays authentication in Wireless Mesh Networks (WMN) refers to the 802.1X authentication methods or a Preshared key authentication, and makes use of certificates or shared secrets. In wireless environments, management of certificates is disadvantageous. Certificates require deploying a Public Key Infrastructure (PKI) and Certification Authorities (CA) and they require defining a certificate management policy to control the generation, transmission and revocation of certificates. Management of certificates is a cumbersome task and does not match the limited (power and memory) resources available at wireless nodes. Moreover it does not match the non permanent connectivity to CA. In this paper, we propose an ID-based method, as an alternative to the PKI, to provide nodes with private and public keys, and we present an authentication scheme that uses the ID-based cryptographic concepts. As illustrated in the paper, the authentication scheme is shown as suitable to the WMN networks.
Aymen Boudguiga, Maryline Laurent
WiMob1
2010 Significantly improved performances of the cryptographically generated addresses thanks to ECC and GPGPU
Tony Cheneau, Aymen Boudguiga, Maryline Laurent
Comput. Secur.2