EDBT 2026 Demo / reviewers in the wild / expert
Ahmed Lekssays
dblp:271/1394
· DBLP profile ↗
10ranked-venue papers
6as first author
9since 2021 · last 2025
0000-0001-5783-8638ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | StructTransform: A Scalable Attack Surface for Safety-Aligned Large Language Models
Shehel Yoosuf, Temoor Ali, Ahmed Lekssays, Mashael Al Sabah, Issa M. Khalil |
ESORICS (1) | 3 |
| 2025 | From Text to Actionable Intelligence: Automating STIX Entity and Relationship ExtractionabstractSharing methods of attack and their effectiveness is a cornerstone of building robust defensive systems. Threat analysis reports, produced by various individuals and organizations, play a critical role in supporting security operations and combating emerging threats. To enhance the timeliness and automation of threat intelligence sharing, several standards have been established, with the Structured Threat Information Expression (STIX) framework emerging as one of the most widely adopted. However, generating STIX-compatible data from unstructured security text remains a largely manual, expertdriven process. To address this challenge, we introduce AZERG, a tool designed to assist security analysts in automatically generating structured STIX representations. To achieve this, we adapt general-purpose large language models for the specific task of extracting STIX-formatted threat data. To manage the complexity, the task is divided into four subtasks: entity detection (T1), entity type identification (T2), related pair detection (T3), and relationship type identification (T4). We apply task-specific fine-tuning to accurately extract relevant entities and infer their relationships in accordance with the STIX specification. To address the lack of training data, we compiled a comprehensive dataset with 4,011 entities and 2,075 relationships extracted from 141 full threat analysis reports, all annotated in alignment with the STIX standard. Our models achieved F1-scores of 84.43% for T1, 88.49% for T2, 95.47% for T3, and 84.60% for T4 in real-world scenarios. We validated their performance against a range of open- and closed-parameter models, as well as state-of-the-art methods, demonstrating improvements of 2–25% across tasks. Ahmed Lekssays, Husrev T. Sencar, Ting Yu 0001 |
RAID | 1 |
| 2025 | LLMxCPG: Context-Aware Vulnerability Detection Through Code Property Graph-Guided Large Language Models
Ahmed Lekssays, Hamza Mouhcine, Khang Tran, Ting Yu 0001, Issa M. Khalil |
USENIX Security Symposium | 1 |
| 2024 | Semantic Ranking for Automated Adversarial Technique Annotation in Security TextabstractWe introduce a novel approach for mapping attack behaviors described in threat analysis reports to entries in an adversarial techniques knowledge base. Our method leverages a multi-stage ranking architecture to efficiently rank the most related techniques based on their semantic relevance to the input text. Each ranker in our pipeline uses a distinct design for text representation. To enhance relevance modeling, we leverage pretrained language models, which we fine-tune for the technique annotation task. While generic large language models are not yet capable of fully addressing this challenge, we obtain very promising results. We achieve a recall rate improvement of +35% compared to the previous state-of-the-art results. We further create new public benchmark datasets for training and validating methods in this domain, which we release to the research community aiming to promote future research in this important direction. Udesh Kumarasinghe, Ahmed Lekssays, Husrev T. Sencar, Sabri Boughorbel, Charith Elvitigala, Preslav Nakov |
AsiaCCS | 2 |
| 2023 | Early-Stage Ransomware Detection Based on Pre-attack Internal API Calls
Filippo Coglio, Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001 |
AINA (2) | 2 |
| 2023 | MalCon: A blockchain-based malware containment framework for Internet of ThingsabstractIoT devices have become a primary medium for malware (e.g., botnets) to launch Distributed Denial of Service (DDoS) attacks. Such malware exploit low-security measures in IoT devices to spread in networks and recruit new victims. Thus, there is a need for malware countermeasures that consider both the security and operability of the network. Indeed, some IoT devices might run critical processes that do not tolerate interruptions. This paper proposes MalCon, a blockchain-based malware containment framework for IoT. It aims to stop malware from spreading in a network by a set of containment strategies encoded into smart contracts to be executed by the infected devices. Moreover, MalCon provides a monitoring service that ensures trustworthy behavior in the network and reports to the system administrator any fraudulent activity of the monitored devices. MalCon was tested extensively with real-life malware and use cases. It quickly and drastically reduces the number of infected devices in a network, even in an extreme case of a fully connected network. Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001 |
Comput. Networks | 1 |
| 2022 | MalRec: A Blockchain-based Malware Recovery Framework for Internet of ThingsabstractIoT devices have been considered an attractive target for malware (e.g., botnets) due to their low computational resources and lack of security measures. The literature focuses on detecting malware, but less attention is given to recovery solutions. In addition, with the development of data processing regulations in different countries, a need for transparent recovery systems that can help organizations present their due diligence arises. This work proposes a blockchain-based backup policy enforcement framework for IoT where an organization can formalize backup policies and enforce them. We have run our solution under extensive tests that show that it can be deployed in real-life IoT environments, despite the limited computational resources of IoT devices. Ahmed Lekssays, Giorgia Sirigu, Barbara Carminati, Elena Ferrari 0001 |
ARES | 1 |
| 2021 | LiMNet: Early-Stage Detection of IoT Botnets with Lightweight Memory Networks
Lodovico Giaretta, Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001, Sarunas Girdzijauskas |
ESORICS (1) | 2 |
| 2021 | PAutoBotCatcher: A blockchain-based privacy-preserving botnet detector for Internet of Things
Ahmed Lekssays, Luca Landa, Barbara Carminati, Elena Ferrari 0001 |
Comput. Networks | 1 |
| 2020 | A Novel Approach for Android Malware Detection and Classification using Convolutional Neural Networks
Ahmed Lekssays, Bouchaib Falah, Sameer Abufardeh |
ICSOFT | 1 |