Slim Trabelsi

dblp:47/3793 · DBLP profile ↗
← Back
18ranked-venue papers
8as first author
6since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 6 first-author · 6 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2022 BlindSpot: Watermarking Through Fairness
abstract
With the increasing development of machine learning models in daily businesses, a strong need for intellectual property protection arised. For this purpose, current works suggest to leverage backdoor techniques to embed a watermark into the model, by overfitting to a set of particularly crafted and secret input-output pairs called triggers. By sending verification queries containing triggers, the model owner can analyse the behavior of any suspect model on the queries to claim its ownership. However, when it comes to scenarios where frequent monitoring is needed, the computational overhead of these verification queries in terms of volume demonstrates that backdoor-based watermarking appears to be too sensitive to outlier detection attacks and cannot guarantee the secrecy of the triggers.
Sofiane Lounici, Melek Önen, Orhan Ermis, Slim Trabelsi
IH&MMSec4
2021 Yes We can: Watermarking Machine Learning Models beyond Classification
abstract
Since machine learning models have become a valuable asset for companies, watermarking techniques have been developed to protect the intellectual property of these models and prevent model theft. We observe that current watermarking frameworks solely target image classification tasks, neglecting a considerable part of machine learning techniques. In this paper, we propose to address this lack and study the watermarking process of various machine learning techniques such as machine translation, regression, binary image classification and reinforcement learning models. We adapt current definitions to each specific technique and we evaluate the main characteristics of the watermarking process, in particular the robustness of the models against a rational adversary. We show that watermarking models beyond classification is possible while preserving their overall performance. We further investigate various attacks and discuss the importance of the performance metric in the verification process and its impact on the success of the adversary.
Sofiane Lounici, Mohamed Njeh, Orhan Ermis, Melek Önen, Slim Trabelsi
CSF5
2021 Sociocultural Influences for Password Definition: An AI-based Study
Carlos Ocanto Dávila, Rocío Cabrera Lozoya, Slim Trabelsi
ICISSP3
2021 An Asynchronous Federated Learning Approach for a Security Source Code Scanner
Sabrina Kall, Slim Trabelsi
ICISSP2
2021 Optimizing Leak Detection in Open-source Platforms with Machine Learning Techniques
Sofiane Lounici, Marco Rosa, Carlo Maria Negri, Slim Trabelsi, Melek Önen
ICISSP4
2021 Preventing Watermark Forging Attacks in a MLaaS Environment
Sofiane Lounici, Mohamed Njeh, Orhan Ermis, Melek Önen, Slim Trabelsi
SECRYPT5
2016 Predictive Model for Exploit Kit based Attacks
abstract
Exploit kits are becoming frequently used to generate attacks against systems and software components. These exploit kits are really popular among the non-expert community (script kiddies) and are publicly available on Social Medias. In this paper we demonstrate how this popularity of such exploit kits on social media can impact the severity of the attacks generated from these tools. We propose we propose a new predictive model to estimate in advance the possible attacks that could be generated from trendy kits.
Slim Trabelsi, Skander Ben Mahmoud, Anis Zouaoui
SECRYPT1
2015 Monitoring Software Vulnerabilities through Social Networks Analysis
abstract
Monitoring software vulnerability information requires an important financial and human effort in order to track all the scattered sources publishing the last news about software vulnerabilities, patches and exploits. We noticed that in some social networks like Twitter we can aggregate a lot of information related to software vulnerabilities in a single channel. In this paper, we analyse the Twitter feed in order to monitor most of the information related to software vulnerabilities including zero-day publications.
Slim Trabelsi, Henrik Plate, Amine Abida, M. Marouane Ben Aoun, Anis Zouaoui, Chedy Missaoui, Sofien Gharbi, Alaeddine Ayari
SECRYPT1
2015 Security Certification for Service-Based Business Ecosystems
abstract
Modern applications can be easily developed and operated by discovering and consuming cloud services that provide the desired functionality. We observe the emergence of ‘Service ecosystems’, i.e. combinations of services which are offered by different providers and which interoperate seamlessly behind the curtains to build applications generating added value compared with single components. However, security and trustworthiness concerns constitute an obstacle for uptake, as trust relations that were in place in traditional component acquisition and operation phases cannot be established in the same forms due to the high number of service providers available and shorter time-to-market requirements. This paper presents our view about how security certification could address these issues, going beyond existing schemes, which mostly address static systems and environments. We show how the combination of recent innovations can lead to the introduction of new security certification schemes that adapt to service-based ecosystems. Such schemes are based on explicit representation of service security features, their machine readability, and an advanced processing and composition support. We present a security-aware service marketplace, allowing consumers to build secure business applications through advanced search and discovery capabilities that consider functional requirements together with certified security features.
Volkmar Lotz, Francesco Di Cerbo, Michele Bezzi, Samuel Paul Kaluvuri, Antonino Sabetta, Slim Trabelsi
Comput. J.6
2014 Optimizing Access Control Performance for the Cloud
abstract
Cloud computing is synonym of high performance computing. It offers a very scalable infrastructure to deploy a huge number of systems and services without any impact of the performance. Such a wide distributed infrastructure, as for the traditional systems, requires authorization and access control mechanisms to ensure the basic security requirements to restrict the access to resources. To satisfy these requirements cloud providers still rely on the traditional authorization and access control systems that in some critical cases can generate performance issues. More the access control structure is complex (many authorization levels, many users and resources to protect), more the enforcement of the access control policies is slow. In this paper we propose a performance study for these traditional access control mechanisms demonstrating the overhead generated by the authorizations checking that can appear in extreme usage conditions. We propose a new approach to make access control systems more scalable and adapted to cloud computing high performance requirements. This approach is based on a high speed caching access control tree that accelerates the decision without impacting on the consistency of the rules. We compare the performance test results obtained by our solution to a traditional Access control system deployed in the cloud.
Slim Trabelsi, Adrien Ecuyer, Paul Cervera y Alvarez, Francesco Di Cerbo
CLOSER1
2013 Sticky policies for mobile devices
abstract
Mobile devices consume significant amounts of information, from different sources. Thus they often deal also with sensitive or confidential data, in places or situations that could be not appropriate, or not compliant with a corporate policy: context-aware access/usage control solutions can counter such situations. We propose a prototype, called ProtectMe, that exploits "Sticky Policies" (SP) that are attached to resources and prescribe usage conditions.
Francesco Di Cerbo, Slim Trabelsi, Thomas Steingruber, Gabriella Dodero, Michele Bezzi
SACMAT2
2013 Abusing Social Networks with Abuse Reports - A Coalition Attack for Social Networks
Slim Trabelsi, Hana Bouafif
SECRYPT1
2012 Sticky policies for data control in the cloud
abstract
One of the main security concerns related to the cloud hosting and virtualization, is the lack of Trust in the infrastructure. This lack of trust is due to the absence of transparency concerning the data handling and storage conditions. There are no concrete technical guarantees that can convince a potential cloud customer that he is fully controlling his data. In this paper we propose a security service (called SPACE) in the cloud that provides all the tools to data owner to impose his privacy preferences during the virtualization phase. SPACE is based on the sticky policy technology and offers access and usage control functionalities to the data anywhere in the cloud. In addition to the main security features offered by SPACE, new visualization and control functionalities are proposed to make the user fully aware on the storage condition of his private information.
Slim Trabelsi, Jakub Sendor
PST1
2011 Deriving business processes with service level agreements from early requirements
abstract
When designing a service-based business process employing loosely coupled services, one is not only interested in guaranteeing a certain flow of work, but also in how the work will be performed. This involves the consideration of non-functional properties which go from execution time and costs, to trust and security. Ideally, a designer would like to have guarantees over the behavior of the services involved in the process. These guarantees are the object of Service Level Agreements. We propose a methodology to design service-based business processes together with Service Level Agreements that guarantee a certain quality of execution, with particular emphasis on security. Starting from an early requirements analysis modeled in the Secure Tropos formalism, we provide a set of user-guided transformations and reasoning tools the final output of which is a set of processes in the form of Secure BPELs together with a set of Service Level Agreements to be signed by participating services. To show the potential impact of the approach, we illustrate the functioning of the methodology on a collaborative procurement scenario derived from the application domain of a research project.
Ganna Frankova, Magali Seguran, Florian Gilcher, Slim Trabelsi, Jörg Dörflinger, Marco Aiello 0001
J. Syst. Softw.4
2010 Privacy-aware policy matching
abstract
Security policies exchanged between applications are typically huge, complex and private. A server must publish these policies to permit any client that wants to use the service to match it with its own preferences and assess whether it complies with its security policy. This matching process consists of first verifying whether the client can access the service and then checks if the security policy of the server is compliant with the client's privacy preferences. In this paper we propose a privacy-aware policy matching model, where security policies and user's preferences are represented as binary vectors using bloom filter vectors. These vectors can be published by the server without any risk of disclosing its security policy. When the client wants to match this vector to its preferences vector it just compares the two binary arrays, without disclosing its policy. The binary comparison is also much faster and cost effective than parsing two XML files.
Slim Trabelsi, Eric Weil, Alessandro Sorniotti, Stuart Short, Michele Bezzi
ISCC1
2009 Data disclosure risk evaluation
abstract
Many companies have to share various types of information containing private data without being aware about the threats related to such non-controlled disclosure. Therefore we propose a solution to support these companies to evaluate the disclosure risk for all their types of data; by recommending the safest configurations using a smart bootstrapping system.
Slim Trabelsi, Vincent Salzgeber, Michele Bezzi, Gilles Montagnon
CRiSIS1
2007 Secure Service Publishing with Untrusted Registries - Securing Service Discovery
Slim Trabelsi, Yves Roudier
SECRYPT1
2005 Extended Erlang-B law for performance evaluation of radio resources sharing in GSM/(E)GPRS networks
abstract
In this paper, we derive a simple and accurate Erlang-like law for the dimensioning of radio resources in GSM/GPRS/EDGE networks taking into account the voice and data traffic mix in a cell. Resources are assumed to be shared according to the so-called partial partitioning scheme whereby some circuits are dedicated to voice, others to data, and the remaining are shared but voice traffic can preempt them.
Bruno Baynat, Khaled Boussetta, Pierre Eisenmann, Slim Trabelsi
PIMRC4