EDBT 2026 Demo / reviewers in the wild / expert
Reda Yaich
dblp:54/10716
· DBLP profile ↗
15ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0001-7294-5909ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 1 first-author · 8 since 2021Artificial intelligence and machine learning · 3 · 3 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Modular HRL Agent for Automated Pentesting with Specialized Policies: A Maritime use caseabstractThe increasing convergence of IT and OT in maritime infrastructure has amplified the cyber-physical threat landscape, exposing vessels to sophisticated, multi-stage attacks. Given the scarcity of specialized experts and the prohibitive cost of manual assessments, proactive automated penetration testing has become a critical necessity. However, Deep Reinforcement Learning (DRL) solutions struggle with the combinatorial explosion of state-action spaces and the inability of monolithic models to generalize across hybrid domains without catastrophic forgetting. Marc-Antoine Faillon, Julien Francq, Nora Cuppens, Frédéric Cuppens, Reda Yaich |
CODASPY | 5 |
| 2025 | Diffusion-Based Adversarial Purification for Intrusion Detection
Mohamed Amine Merzouk, Erwan Beurier, Reda Yaich, Nora Cuppens, Frédéric Cuppens, Foutse Khomh |
DBSec | 3 |
| 2025 | A Post-Quantum Privacy-Enhanced Federated Learning Model for Driver Behavior ProfilingabstractAs vehicle systems become increasingly connected and intelligent, insurance providers are turning to machine learning techniques to personalize billing based on individual driving behavior. This shift raises important questions about how to balance predictive performance with user privacy. In this paper, we present PrivFedProfiling, a decentralized privacy-preserving learning framework designed for use-based insurance (UBI) systems. Our method leverages Federated Learning (FL) to collaboratively train behavior models across distributed driver devices without transferring raw data. To further strengthen privacy, we integrate Differential Privacy (DP) and Homomorphic Encryption (HE) within the training process, protecting sensitive patterns in shared model updates. The proposed approach uses a Multilayer Perceptron (MLP) architecture and is validated using synthetic driving behavior data generated from the SUMO simulator. It offers a realistic yet controllable environment for testing. Results indicate that our method maintains high model accuracy while ensuring strong privacy guarantees, making it suitable for real-world deployment. Badreddine Chah, Anis Bkakria, Alexandre Lombard, Abdeljalil Abbas-Turki, Alexandre Brunoud, Yazan Mualla, Reda Yaich |
HSI | 7 |
| 2024 | How to Better Fit Reinforcement Learning for Pentesting: A New Hierarchical Approach
Marc-Antoine Faillon, Baptiste Bout, Julien Francq, Christopher Neal, Nora Cuppens, Frédéric Cuppens, Reda Yaich |
ESORICS (4) | 7 |
| 2023 | Real-Time Defensive Strategy Selection via Deep Reinforcement LearningabstractAs computer networks face increasingly sophisticated attacks there is a need to create adaptive defensive systems that can select appropriate countermeasures to thwart attacks. The use of Deep Reinforcement Learning to train defensive agents is an avenue to study to meet this demand. In this paper we describe a simulated computer network environment wherein we conduct attacks and train defensive agents that employ Moving Target Defense and Deception strategies. We train an attacking agent, using Proximal Policy Optimization, to learn a policy to extract sensitive network data as quickly as possible from the environment. We then train a defending agent to prevent the attacker from reaching its objective. Our results demonstrate how the defender is able to learn a policy to inhibit the attacker. Axel Charpentier, Christopher Neal, Nora Cuppens, Frédéric Cuppens, Reda Yaich |
ARES | 5 |
| 2023 | Parameterizing poisoning attacks in federated learning-based intrusion detectionabstractFederated learning is a promising research direction in network intrusion detection. It enables collaborative training of machine learning models without revealing sensitive data. However, the lack of transparency in federated learning creates a security threat. Since the server cannot ensure the clients’ reliability by analyzing their data, malicious clients have the opportunity to insert a backdoor in the model and activate it to evade detection. To maximize their chances of success, adversaries must fine-tune the attack parameters. Here we evaluate the impact of four attack parameters on the effectiveness, stealthiness, consistency, and timing of data poisoning attacks. Our results show that each parameter is decisive for the success of poisoning attacks, provided they are carefully adjusted to avoid damaging the model’s accuracy or the data’s consistency. Our findings serve as guidelines for the security evaluation of federated learning systems and insights for defense strategies. Our experiments are carried out on the UNSW-NB15 dataset, and their implementation is available in a public code repository. Mohamed Amine Merzouk, Frédéric Cuppens, Nora Cuppens, Reda Yaich |
ARES | 4 |
| 2023 | Robustness Assessment of Biometric AuthenticatorsabstractBiometric authenticators aim to provide a safe, secure, and accurate authentication process in restricted areas. Despite their advantages, biometric authenticators are vulnerable to cyber-attacks, such as spoofing attacks. Spoofing attacks enable malicious actors to masquerade as someone else to gain illegitimate access or privilege. To proceed, the attacker forges fake biometric data or duplicates existing ones. In such a context, the evaluation of the robustness of biometric authenticators is paramount to assessing their resilience potential and derive deployment strategies. Through this work, we propose a generic assessment method, based on a metric which quantifies the robustness of biometrics against cyber-attacks. Our methodology can be adapted to different families of cyber-attacks targeting biometric authentication techniques. We demonstrate our approach by considering spoofing-attacks. To achieve this objective, we present an extended state-of-the-art of biometrics (physiological and behavioural), including emerging biometric technologies. We also provide an overview of spoofing-attacks for each identified biometric mechanism in the literature. Based on this knowledge, we quantify and we combine the characteristics of such attacks into a quantitative robustness metric which can be applied to both a single and a combination of authenticators. Romain Dagnas, Anis Bkakria, Reda Yaich |
TrustCom | 3 |
| 2022 | Deep Reinforcement Learning-Based Defense Strategy SelectionabstractDeception and Moving Target Defense techniques are two types of approaches that aim to increase the cost of the attacks by providing false information or uncertainty to the attacker’s perception. Given the growing number of these strategies and the fact that they are not all effective against the same types of attacks, it is essential to know how to select the best one to use depending on the environment and the attacker. We therefore propose a model of attacker/defender confrontation in a computer system that takes into account the asymmetry of the players’ perceptions. To simulate attacks on our model, a basic attacker scenario based on the main phases of the Cyber Kill Chain is proposed. Analytically determining an optimal solution is difficult due to the model’s complexity. Moreover, because of the large number of possible states in the model, Deep Q-Learning algorithm is used to train a defensive agent to choose the best defensive strategy according to the observed attacker’s actions. Axel Charpentier, Nora Cuppens, Frédéric Cuppens, Reda Yaich |
ARES | 4 |
| 2022 | Evading Deep Reinforcement Learning-based Network Intrusion Detection with Adversarial AttacksabstractAn Intrusion Detection System (IDS) aims to detect attacks conducted over computer networks by analyzing traffic data. Deep Reinforcement Learning (Deep-RL) is a promising lead in IDS research, due to its lightness and adaptability. However, the neural networks on which Deep-RL is based can be vulnerable to adversarial attacks. By applying a well-computed modification to malicious traffic, adversarial examples can evade detection. In this paper, we test the performance of a state-of-the-art Deep-RL IDS agent against the Fast Gradient Sign Method (FGSM) and Basic Iterative Method (BIM) adversarial attacks. We demonstrate that the performance of the Deep-RL detection agent is compromised in the face of adversarial examples and highlight the need for future Deep-RL IDS work to consider mechanisms for coping with adversarial examples. Mohamed Amine Merzouk, Joséphine Delas, Christopher Neal, Frédéric Cuppens, Nora Cuppens, Reda Yaich |
ARES | 6 |
| 2020 | Secure Data Processing for Industrial Remote Diagnosis and Maintenance
Walid Arabi, Reda Yaich, Aymen Boudguiga, Mawloud Omar |
CRiSIS | 2 |
| 2020 | A Deeper Analysis of Adversarial Examples in Intrusion Detection
Mohamed Amine Merzouk, Frédéric Cuppens, Nora Cuppens, Reda Yaich |
CRiSIS | 4 |
| 2017 | Enabling Trust Assessment In Clouds-of-Clouds: A Similarity-Based ApproachabstractIn multi-cloud paradigm, cloud providers collaborate to form ad-hoc and ephemeral groups to fulfill the request of a single customer. In such settings, malevolent cloud providers may be tempted to provide cloud services that are below the expected quality. This temptation is further exacerbated by the inability of customers to effectively identify the responsible of service outage or degradation. Furthermore, the highly competitive nature of cloud marketplaces leads each provider to propose regularly innovative new services, making the system open and highly dynamic. The introduction of new cloud services into the system challenges the established trust order as customers and providers must accept the risk of taking decisions under uncertainty. This problem, known as the cold-start problem, have been studied in the literature from the perspective of the individuals (providers/customers) but to the best of our knowledge, no prior work tried to address it from the perspective of the exchanged services and resources. To that aim, we propose in this paper a similarity-based trust model that tackles both multi-cloud (i.e., group-repution) and services high turnover (i.e., cold-start). In our model, past similar experiences are transferred to the providers proposing new services to enable and boost decision making and collaboration. We propose also a schema to derive multi-cloud trust using both customers and providers feedback experiences. We present also evaluations results to show the benefit of using our proposal and their impact on the simulated cloud-marketplace. Reda Yaich, Nora Cuppens, Frédéric Cuppens |
ARES | 1 |
| 2017 | Impact of social influence on trust management within communities of agentsabstractIn the real world as in the virtual one, trust is a fundamental concept. Without it, humans can neither act nor interact. So unsurprisingly, this concept received in the last years a growing interest from researchers in security and distributed artificial intelligence that gave rise to numerous mod els. The principal aim of these models was to assist users in making safe decisions at the individual level. However, studies have shown that the behavior of an individual within collective structures (e.g., a group, a community, a coalition or an organization) is affected (directly or indirectly) by the behavior of other members, creating a social influence dynamics within these structures. In this article, we study the impact of social influence phenomena when they are applied to trust management within open distributed communities of self-organized and self-governed agents. Reda Yaich, Olivier Boissier, Gauthier Picard, Philippe Jaillon |
Web Intell. | 1 |
| 2016 | Managing Evolving Trust Policies within Open and Decentralized CommunitiesabstractOnline communities promise a new era of flexible and dynamic collaborations. However, these features also raise new security challenges, especially regarding how trust is managed. In this paper, we focus on situations wherein communities participants collaborate with each others via software agents that take trust decisions on their behalf based on policies. Due to the open and dynamic nature of Online Communities, participants can neither anticipate all possible interactions nor have foreknowledge of sensitive resources and potentially malicious partners. This makes the specification of trust policies complex and risky, especially for collective (i.e., community-level) policies, motivating the need for policies evolution. The aim of this paper is to introduce an approach in order to manage the evolution of trust policies within online communities. Our scenario allows any member of the community to trigger the evolution of the community-level policy and make the other members of the community converge towards it. Reda Yaich |
WI | 1 |
| 2013 | Adaptiveness and social-compliance in trust management within virtual communitiesabstractThe success of virtual communities (VCs) relies on collaboration and resource sharing principles, making trust a priority for each member. The work presented in this paper addresses the problem of trust management in open and decentralised virtual co Reda Yaich, Olivier Boissier, Gauthier Picard, Philippe Jaillon |
Web Intell. Agent Syst. | 1 |