EDBT 2026 Demo / reviewers in the wild / expert
Razvan Beuran
dblp:36/3622
· DBLP profile ↗
26ranked-venue papers
8as first author
14since 2021 · last 2026
0000-0002-4109-3763ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 4 first-author · 12 since 2021Computer networks · 5 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CodeEnhancer: LLM-generated Python code enhancement through SAST integration and fine-tuningabstractDespite the rapid adoption of Large Language Models (LLMs) for automatic code generation, their output often exhibits syntax errors, security vulnerabilities, and functional inconsistencies. To address these issues, we present CodeEnhancer, a two-stage framework that tightly integrates LLMs with static application security testing (SAST) tools and targeted fine-tuning. The goal is to produce more secure and functionally correct Python code. In the first stage, our iterative validation pipeline couples LLM-generated code with tools such as Pylint and Bandit. These tools automatically identify and remediate issues through structured feedback loops. When applied to the GPT-4o model, this process eliminated 82.8% of the initial vulnerabilities and resolved all the detected functional correctness issues when tested on the LLMSecEval dataset. In the second stage, we fine-tune the LLMs using two types of secure code examples: expert-written samples and code refined by our framework. Comparative experiments demonstrate that the framework-tuned model outperforms the baseline and expert-tuned models. The framework-tuned model generates only 18.4% vulnerable code snippets on the LLMSecEval dataset, whereas the baseline and expert-tuned models produce 43.6% and 54.7% vulnerable code snippets, respectively. The framework-tuned model reduces final vulnerability rates to 6.7% on LLMSecEval and 3.5% on the SecurityEval dataset. Our results highlight the synergistic effect of integrating static analysis with feedback-informed fine-tuning. They also reveal limitations in current evaluation metrics and dataset representativeness. These findings suggest a scalable, robust approach to achieving more secure, trustworthy, and practical AI-assisted code generation. • Combines language models with SAST Tools to enhance Syntax, security and functional correctness Python code. • First approach to address syntax, security, and functional correctness in LLM-generated code. • Automated feedback and learning process helps LLMs generate more secure, correct code. • Fine-tuning on framework-refined code leads to better security than training on expert-written code. • Scalable approach enables robust and trustworthy AI-assisted code generation and refinement with minimal manual effort. Khang Mai, Nakul Ghate, Tomohiko Yagyu, Razvan Beuran, Yasuo Tan |
Knowl. Based Syst. | 5 |
| 2025 | CyLLM-DAP: Cybersecurity Domain-Adaptive Pre-Training Framework of Large Language Models
Khang Mai, Razvan Beuran, Naoya Inoue |
ICISSP (2) | 2 |
| 2025 | LLM-Based Fine-Grained ABAC Policy Generation
Khang Mai, Nakul Ghate, Razvan Beuran |
ICISSP (2) | 4 |
| 2025 | Network Intrusion Detection System Based on Reinforcement Learning Technique Optimization
Sukkarin Ruensukont, Karin Sumonkayothin, Prarinya Siritanawan, Narit Hnoohom, Setthawhut Saennam, Razvan Beuran |
ProvSec | 6 |
| 2025 | RAF-AG: Report analysis framework for attack path generationabstractInformation sharing is a key practice in cybersecurity for coping with the ever-changing cyberattacks that are targeting computer systems. Thus, when cyber incidents happen, cyber threat intelligence (CTI) reports are prepared and shared among cybersecurity practitioners to help them get up-to-date information about those incidents. However, reading and analyzing the report text to comprehend the included information is a cumbersome process. Although techniques based on deep learning were proposed to speed up report analysis in order to obtain the enclosed essential information, such as attack path, training data insufficiency makes these methods inefficient in practical circumstances. This paper presents RAF-AG, a report analysis framework for attack path generation. To analyze CTI reports, RAF-AG utilizes the sentence dependency tree for entity and relation extraction, and a weak supervision approach for entity labeling. This is followed by graph building and graph alignment for generating the attack paths. Our approach resolves the data insufficiency problem in the cybersecurity domain by lowering the need for expert involvement. We evaluated RAF-AG by comparing the generated attack paths with those produced by AttacKG, a state-of-the-art automatic report analysis framework. RAF-AG was able to identify cyberattack steps by matching their appearance order inside the report, and link them with techniques from the MITRE ATT&CK knowledge base with an improved F1 score compared to AttacKG (0.708 versus 0.393). Khang Mai, Razvan Beuran, Ryosuke Hotchi, Ooi Sian En, Takayuki Kuroda, Yasuo Tan |
Comput. Secur. | 3 |
| 2025 | FedMSE: Semi-supervised federated learning approach for IoT network intrusion detection
Razvan Beuran |
Comput. Secur. | 2 |
| 2025 | PenGym: Realistic training environment for reinforcement learning pentesting agentsabstractPenetration testing, or pentesting, refers to assessing network system security by trying to identify and exploit any existing vulnerabilities. Reinforcement Learning (RL) has recently become an effective method for creating autonomous pentesting agents. However, RL agents are typically trained in a simulated network environment. This can be challenging when deploying them in a real network infrastructure due to the lack of realism of the simulation-trained agents. In this paper, we present PenGym, a framework for training pentesting RL agents in realistic network environments. The most significant features of PenGym are its support for real pentesting actions, full automation of the network environment creation, and good execution performance. The results of our experiments demonstrated the advantages and effectiveness of using PenGym as a realistic training environment in comparison with a simulation approach (NASim). For the largest scenario, agents trained in the original NASim environment behaved poorly when tested in a real environment, having a high failure rate. In contrast, agents trained in PenGym successfully reached the pentesting goal in all our trials. Even after fixing logical modeling issues in simulation to create the revised version NASim(rev.), experiment results with the largest scenario indicated that agents trained in PenGym slightly outperformed, and were more stable, than those trained in NASim(rev.). Thus, the average number of steps required to reach the pentesting goal was 1.4 to 8 steps better for PenGym. Consequently, PenGym provides a reliable and realistic training environment for pentesting RL agents, eliminating the need to model agent actions via simulation. Huynh Phuong Thanh Nguyen, Kento Hasegawa, Kazuhide Fukushima, Razvan Beuran |
Comput. Secur. | 4 |
| 2025 | Quality-Focused Active Adversarial Policy for Safe Grasping in Human-Robot Interaction
Razvan Beuran, Nak Young Chong |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2024 | Eunomia: A Real-time Privacy Compliance Firewall for Alexa SkillsabstractVoice assistants (VAs), such as Amazon Alexa, are integrated with numerous smart home devices to process user requests using apps called skills. With their growing popularity, VAs also pose serious privacy concerns. Sensitive user data captured by VAs may be transmitted to third-party skills without users’ consent or knowledge about how their data is handled. Privacy policies are a standard medium to inform the users of the skills’ data practices. However, privacy policy compliance verification of such skills is challenging, since the source code is controlled by the skill developers, who can make arbitrary changes to the behaviors of the skill without being audited; hence, conventional defense mechanisms using static/dynamic code analysis can be easily evaded. In this paper, we present Eunomia, the first real-time privacy compliance firewall for Alexa skills. As the skills interact with the users, Eunomia hijacks and examines their communications from the skills to the users, and validates them against the published privacy policies that are parsed using a BERT-based policy analysis module. When non-compliant skill behaviors are detected, Eunomia stops the interaction and warns the user about the non-compliance. We evaluate Eunomia with 55,898 skills on Amazon skills store to demonstrate its effectiveness and to provide a privacy compliance landscape of Alexa skills. Javaria Ahmad, Fengjun Li, Razvan Beuran, Bo Luo |
ACSAC | 3 |
| 2024 | PenGym: Pentesting Training Framework for Reinforcement Learning Agents
Huynh Phuong Thanh Nguyen, Kento Hasegawa, Kazuhide Fukushima, Razvan Beuran |
ICISSP | 5 |
| 2024 | Smart Building Control System Emulation Platform for Security TestingabstractSmart buildings play a crucial role in advancing the smartness of cities, with technologies like automated control, smart sensors, and communication networks becoming increasingly complex. In addition, ensuring the effectiveness and reliability of these technologies requires continuous testing and improvement. However, evaluating them in real buildings is costly, risky, and resource constrained. Furthermore, as cyberattack techniques evolve and digital transformation accelerates, the security threats to smart buildings are also growing. To tackle these challenges, in this paper we introduce the Smart Building Control System Emulator (SBCSE). Developed based on real building log data, this platform emulates control systems, IoT devices, and communication protocols for thorough testing and evaluation purposes. SBCSE can also be used to analyze potential threats in various security scenarios, and to validate effective countermeasures. Consequently, our platform can improve testing efficiency and safety, reduce costs, and support system design and maintenance. Moreover, by simulating different network risk scenarios, it helps identify security threats and provides actionable solutions. Xiaoqi Weng, Razvan Beuran |
PRDC | 2 |
| 2023 | Capability Assessment Methodology and Comparative Analysis of Cybersecurity Training PlatformsabstractCybersecurity training is a key endeavour for ensuring that the IT workforce possess the knowledge and practical skills required to counter the ever-increasing cybersecurity threats that our society is faced with. While some related systems, such as Capture The Flag platforms, have been available for almost one decade, platforms that support full-fledged cybersecurity training exercises have only been released as open source in recent years. Given the complexity of such cybersecurity training platforms, the question that arises is how to meaningfully evaluate and compare their capabilities in order to identify the most suitable solution for a given type of organization and/or training activity. In this paper, we introduce a capability assessment methodology for cybersecurity training platforms that focuses on the three key aspects of training: content representation, environment management, and training facilitation. The assessment tool that we developed is used to evaluate two open-source cybersecurity training platforms, CyTrONE and KYPO. We then conduct a comparative analysis of these two platforms based on our first-hand developer experience with them, and discuss the lessons learned from implementing, deploying and using these platforms. The assessment tool and the detailed technical comparative analysis that we conducted are intended as instruments and references for anyone who plans to deploy or develop cybersecurity training platforms. Razvan Beuran, Jan Vykopal, Daniela Belajová, Pavel Celeda, Yasuo Tan, Yoichi Shinoda |
Comput. Secur. | 1 |
| 2023 | Intent-Driven Secure System Design: Methodology and Implementation
Ooi Sian En, Razvan Beuran, Takayuki Kuroda, Takuya Kuwahara, Ryosuke Hotchi, Norihito Fujita, Yasuo Tan |
Comput. Secur. | 2 |
| 2022 | IoT System Trustworthiness AssuranceabstractAs the Internet of Things (IoT) becomes more and more pervasive, encompassing many aspects of our daily life, the issue of how much the IoT systems can be trusted is critical. However, the multitude of recent incidents that were caused by or somehow involved such systems, often with dire consequences, makes it obvious that IoT system trustworthiness is not yet attained. Razvan Beuran, Ooi Sian En, Abbie O. Barbir, Yasuo Tan |
AsiaCCS | 1 |
| 2020 | A Quantitative Study of Vulnerabilities in the Internet of Medical Things
Hervé Debar, Razvan Beuran, Yasuo Tan |
ICISSP | 2 |
| 2018 | Integrated framework for hands-on cybersecurity training: CyTrONE
Razvan Beuran, Dat Tang, Cuong Pham 0004, Ken-ichi Chinen, Yasuo Tan, Yoichi Shinoda |
Comput. Secur. | 1 |
| 2017 | CyTrONE: An Integrated Cybersecurity Training FrameworkabstractIn a world in which cyber-attacks occur on a daily basis, cybersecurity education and training are indispensable. Current training programs rely on manual setup and configuration for hands-on activities, which is a tedious and error-prone task. In this paper we present CyTrONE, an integrated cybersecurity training framework that we designed and implemented to address such shortcomings. The key insight is automating the training content generation and environment setup tasks. The advantages of this approach are: (i) improve the accuracy of the training setup; (ii) decrease the setup time and cost; (iii) make training possible repeatedly, and for a large number of participants. In the paper we thoroughly discuss the architecture and implementation of the framework, and we evaluate it from several perspectives in order to demonstrate that CyTrONE meets the aforementioned objectives. Razvan Beuran, Cuong Pham 0004, Dat Tang, Ken-ichi Chinen, Yasuo Tan, Yoichi Shinoda |
ICISSP | 1 |
| 2017 | Design and Evaluation of a Cybersecurity Awareness Training Game
Duy Huynh, Phuc Luong, Hiroyuki Iida, Razvan Beuran |
ICEC | 4 |
| 2013 | Network emulation testbed for DTN applications and protocolsabstractWireless devices are widely used today to access the Internet, despite the intermittent network connectivity they often provide, especially in mobile circumstances. The paradigm of Delay/Disruption Tolerant Networks (DTN) can be applied in such cases to improve the user experience. In this paper we present a network testbed for DTN applications and protocols that we developed based on the generic-purpose wireless network emulation testbed named QOMB. Our testbed is intended for quantitative performance assessments of DTN application and protocol implementations in realistic scenarios. We illustrate the practicality of our emulation testbed through a series of experiments with the DTN2 and IBR-DTN implementations, focusing on mobility in urban environments. The scalability issues that we have identified for DTN2 emphasize the need to perform large-scale repeatable evaluations of DTN applications and protocols for functionality validation and performance optimization. Razvan Beuran, Shinsuke Miwa, Yoichi Shinoda |
INFOCOM | 1 |
| 2011 | IEEE 802.15.4 Network Emulation TestbedabstractIEEE 802.15.4 networks are promising solutions for wireless personal area networks, and in particular for wireless home area networks. IEEE 802.15.4 has numerous applications in fields such as energy management and home automation. However, real-world trials with 802.15.4 devices are difficult because of the characteristics of these devices (small dimensions, wireless communication), and the potentially large size of the network. We present in this paper an IEEE 802.15.4 network emulation testbed that makes possible repeatable and controllable live experiments with 802.15.4-based devices. The testbed is built by extending the functionality of the wireless network emulation testbed named QOMB with 802.15.4 PHY and MAC layer capabilities, as well as 802.15.4 device processor emulation. We illustrate the usability of the 802.15.4 network emulation testbed with a case study of home networking used for automation related to environment control. Razvan Beuran, Junya Nakata, Yasuo Tan, Yoichi Shinoda |
AINA | 1 |
| 2010 | AEROMAN: A Novel Architecture to Evaluate Routing Protocols for Multi-Hop Ad-Hoc NetworksabstractIn this paper, we present AEROMAN (Architecture to Evaluate Routing Protocols for Multi-hop Ad-hoc Networks) which is designed and implemented for evaluation of routing protocols for multi-hop wireless networks. AEROMAN uses QOMET, a wireless link emulation tool, to compute parameters of wireless links, such as bandwidth, delay, packet loss rate, in contention-free conditions. In order to take into account the properties of contention-based media access for wireless channel, AEROMAN uses an Adaptive Traffic (AT) model to emulate the sharing feature of CSMA/CA mechanism in IEEE 802.11. The evaluations show that the AEROMAN with AT model effectively captures the characteristics of wireless communications. Several experiments using OLSR as routing protocol with different routing metrics are performed in order to illustrate the main features and usability of AEROMAN. Lan Tien Nguyen, Razvan Beuran, Yoichi Shinoda |
ICCCN | 2 |
| 2009 | QOMB: A Wireless Network Emulation TestbedabstractIn this paper we present QOMB, a testbed we designed and implemented for the evaluation of wireless network systems, protocols and applications. The testbed uses the wireless network emulation set of tools QOMET so as to reproduce in a wired network, in real time, the wireless network conditions corresponding to a given scenario. In this context QOMET also provides support for features such as realistic virtual 3D environments, and node mobility generation. The infrastructure of QOMB is StarBED, the large-scale network experiment testbed at the National Institute of Information and Communications Technology, Hokuriku Research Center, in Ishikawa, Japan. The multi-hop wireless network emulation experimental results related to OLSR performance analysis in mesh networks and MANETs illustrate the main features and the usability of QOMB. Razvan Beuran, Lan Tien Nguyen, Toshiyuki Miyachi, Junya Nakata, Ken-ichi Chinen, Yasuo Tan, Yoichi Shinoda |
GLOBECOM | 1 |
| 2008 | A load-aware routing metric for wireless mesh networksabstractRouting metrics play a critical role in wireless mesh networks (WMNs). Several metrics have already been proposed but none of them can effectively capture both local traffic load and hidden node issues. This paper proposes a load and interference-aware routing metric for wireless mesh networks, named Contention Window Based (CWB) metric. Our metric assigns weights to individual links based on both channel utilization and the average Contention Window used on these links. The individual link weights are combined into path metric that accounts for load balancing and interference between links that use the same channel. Thus the CWB metric helps the routing protocol to balance traffic and improve network capacity by avoiding routing traffic through congested areas. The preliminary quantitative experiments show significant improvement over hop-count based method when using the proposed metric. Lan Tien Nguyen, Razvan Beuran, Yoichi Shinoda |
ISCC | 2 |
| 2007 | QOMET: A Versatile WLAN EmulatorabstractIn this paper we present the design of QOMET, the wireless LAN (WLAN) emulator that we develop. Our approach to WLAN emulation is a versatile two-stage scenario-driven design. In the first stage a real-world scenario representation provided by the user is converted successively into physical, data link and network layer effects that correspond to the emulated WLAN scenario. The output of the first stage is a description of the network states at successive moments of time, which is used in the second stage to accurately reproduce the wireless environment conditions by means of a wired-network emulator. We give here the details of the overall model that makes it possible to accomplish this conversion in QOMET. We then present our test methodology and illustrate our approach by several experimental results. Razvan Beuran, Lan Tien Nguyen, Khin Thida Latt, Junya Nakata, Yoichi Shinoda |
AINA | 1 |
| 2007 | Collaborative motion planning of autonomous robotsabstractIn disaster areas, office buildings, or at home, multiple autonomous networked mobile robots may act instead of human beings. These robots have to move to their destiantion so as to perform their function. For this purpose they need to be able to recognize the changes in the surrounding environment. They are equipped with a motion-planning method in order to avoid in real time collisions with other robots or obtacles. In this paper we propose a motion planning method based on PRM (Probabilistic Roadmap) algorithm. To evaluate our method, we constructed an experiment platform based on StarBED, which is a large-scale network testbed. By using the virtual environment manager Map Manager, the WLAN emulator QOMET, and the experiment-support software RUNE we are able to perform emulation of large-scale autonomous networked mobile robot systems. The experimental results confirm the usefulness of collaborative motion planning, which results in reaching faster the estimation and in less frequent re-planning. Takashi Okada, Razvan Beuran, Junya Nakata, Yasuo Tan, Yoichi Shinoda |
CollaborateCom | 2 |
| 2007 | Performance Analysis of IEEE 802.11 in Multi-hop Wireless Networks
Lan Tien Nguyen, Razvan Beuran, Yoichi Shinoda |
MSN | 2 |