EDBT 2026 Demo / reviewers in the wild / expert
Zied Ben-Houidi
dblp:64/2520
· DBLP profile ↗
20ranked-venue papers
7as first author
10since 2021 · last 2025
0000-0002-7258-0919ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 6 first-author · 8 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Episodic Memories Generation and Evaluation Benchmark for Large Language ModelsabstractEpisodic memory -- the ability to recall specific events grounded in time and space -- is a cornerstone of human cognition, enabling not only coherent storytelling, but also planning and decision-making. Despite their remarkable capabilities, Large Language Models (LLMs) lack a robust mechanism for episodic memory: we argue that integrating episodic memory capabilities into LLM is essential for advancing AI towards human-like cognition, increasing their potential to reason consistently and ground their output in real-world episodic events, hence avoiding confabulations. To address this challenge, we introduce a comprehensive framework to model and evaluate LLM episodic memory capabilities. Drawing inspiration from cognitive science, we develop a structured approach to represent episodic events, encapsulating temporal and spatial contexts, involved entities, and detailed descriptions. We synthesize a unique episodic memory benchmark, free from contamination, and release open source code and datasets to assess LLM performance across various recall and episodic reasoning tasks. Our evaluation of state-of-the-art models, including GPT-4 and Claude variants, Llama 3.1, and o1-mini, reveals that even the most advanced LLMs struggle with episodic memory tasks, particularly when dealing with multiple related events or complex spatio-temporal relationships -- even in contexts as short as 10k-100k tokens. Alexis Huet, Zied Ben-Houidi, Dario Rossi 0001 |
ICLR | 2 |
| 2024 | LogPrécis: Unleashing language models for automated malicious log analysisabstractSecurity logs are the key to understanding attacks and diagnosing vulnerabilities. Often coming in the form of text logs, their analysis remains a daunting challenge. Language Models (LMs) have demonstrated unmatched potential in understanding natural and programming languages. The question arises as to whether and how LMs could be also used to automatise the analysis of security logs. We here systematically study how to benefit from the state-of-the-art LM to support the analysis of text-like Unix shell attack logs automatically. For this, we thoroughly designed LogPrécis. LogPrécis receives as input malicious shell sessions. It then automatically identifies and assigns the attacker tactic to each portion of the session, i.e., unveiling the sequence of the attacker's goals. This creates a unique attack fingerprint. We demonstrate LogPrécis capability to support the analysis of two large datasets containing about 400,000 unique Unix shell attacks recorded in a 2-year-long honeypot deployment. LogPrécis reduces the analysis to about 3,000 unique fingerprints. Such abstraction lets us better understand attacks, extract attack prototypes, detect novelties, and track families and mutations. Overall, LogPrécis, released as open source, demonstrates the potential of adopting LMs for security analysis and paves the way for better and more responsive defence against cyberattacks. Matteo Boffa, Idilio Drago, Marco Mellia, Luca Vassio, Danilo Giordano, Rodolfo V. Valentim, Zied Ben-Houidi |
Comput. Secur. | 7 |
| 2024 | Cross-Network Embeddings Transfer for Traffic AnalysisabstractArtificial Intelligence (AI) approaches have emerged as powerful tools to improve traffic analysis for network monitoring and management. However, the lack of large labeled datasets and the ever-changing networking scenarios make a fundamental difference compared to other domains where AI is thriving. We believe the ability to transfer the specific knowledge acquired in one network (or dataset) to a different network (or dataset) would be fundamental to speed up the adoption of AI-based solutions for traffic analysis and other networking applications (e.g., cybersecurity). We here propose and evaluate different options to transfer the knowledge built from a provider network, owning data and labels, to a customer network that desires to label its traffic but lacks labels. We formulate this problem as a domain adaptation problem that we solve with embedding alignment techniques and canonical transfer learning approaches. We present a thorough experimental analysis to assess the performance considering both supervised (e.g., classification) and unsupervised (e.g., novelty detection) downstream tasks related to darknet and honeypot traffic. Our experiments show the proper transfer techniques to use the models obtained from a network in a different network. We believe our contribution opens new opportunities and business models where network providers can successfully share their knowledge and AI models with customers. Luca Gioacchini, Marco Mellia, Luca Vassio, Idilio Drago, Giulia Milan, Zied Ben-Houidi, Dario Rossi 0001 |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2023 | Enlightening the Darknets: Augmenting Darknet Visibility With Active ProbesabstractDarknets collect unsolicited traffic reaching unused address spaces. They provide insights into malicious activities, such as the rise of botnets and DDoS attacks. However, darknets provide a shallow view, as traffic is never responded. Here we quantify how their visibility increases by responding to traffic with interactive responders with increasing levels of interaction. We consider four deployments: Darknets, simple, vertical bound to specific ports, and, a honeypot that responds to all protocols on any port. We contrast these alternatives by analyzing the traffic attracted by each deployment and characterizing how traffic changes throughout the responder lifecycle on the darknet. We show that the deployment of responders increases the value of darknet data by revealing patterns that would otherwise be unobservable. We measure Side-Scan phenomena where once a host starts responding, it attracts traffic to other ports and neighboring addresses. uncovers attacks that darknets and would not observe, e.g. large-scale activity on non-standard ports. And we observe how quickly senders can identify and attack new responders. The “enlightened” part of a darknet brings several benefits and offers opportunities to increase the visibility of sender patterns. This information gain is worth taking advantage of, and we, therefore, recommend that organizations consider this option. Francesca Soro, Thomas Favale, Danilo Giordano, Idilio Drago, Tommaso Rescio, Marco Mellia, Zied Ben-Houidi, Dario Rossi 0001 |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2023 | i-DarkVec: Incremental Embeddings for Darknet Traffic AnalysisabstractDarknets are probes listening to traffic reaching IP addresses that host no services. Traffic reaching a darknet results from the actions of internet scanners, botnets, and possibly misconfigured hosts. Such peculiar nature of the darknet traffic makes darknets a valuable instrument to discover malicious online activities, e.g., identifying coordinated actions performed by bots or scanners. However, the massive amount of packets and sources that darknets observe makes it hard to extract meaningful insights, calling for scalable tools to automatically identify and group sources that share similar behaviour. We here present i-DarkVec, a methodology to learn meaningful representations of Darknet traffic. i-DarkVec leverages Natural Language Processing techniques (e.g., Word2Vec) to capture the co-occurrence patterns that emerge when scanners or bots launch coordinated actions. As in NLP problems, the embeddings learned with i-DarkVec enable several new machine learning tasks on the darknet traffic, such as identifying clusters of senders engaged in similar activities. We extensively test i-DarkVec and explore its design space in a case study using real darknets. We show that with a proper definition of services , the learned embeddings can be used to (i) solve the classification problem to associate unknown sources’ IP addresses to the correct classes of coordinated actors and (ii) automatically identify clusters of previously unknown sources performing similar attacks and scans, easing the security analyst’s job. i-DarkVec leverages a novel incremental embedding learning approach that is scalable and robust to traffic changes, making it applicable to dynamic and large-scale scenarios. Luca Gioacchini, Luca Vassio, Marco Mellia, Idilio Drago, Zied Ben-Houidi, Dario Rossi 0001 |
ACM Trans. Internet Techn. | 5 |
| 2022 | Towards a systematic multi-modal representation learning for network dataabstractLearning the right representations from complex input data is the key ability of successful machine learning (ML) models. The latter are often tailored to a specific data modality. For example, recurrent neural networks (RNNs) were designed having sequential data in mind, while convolutional neural networks (CNNs) were designed to exploit spatial correlation in images. Unlike computer vision (CV) and natural language processing (NLP), each of which targets a single well-defined modality, network ML problems often have a mixture of data modalities as input. Yet, instead of exploiting such abundance, practitioners tend to rely on sub-features thereof, reducing the problem to single modality for the sake of simplicity. In this paper, we advocate for exploiting all the modalities naturally present in network data. As a first step, we observe that network data systematically exhibits a mixture of quantities (e.g., measurements), and entities (e.g., IP addresses, names, etc.). Whereas the former are generally well exploited, the latter are often underused or poorly represented (e.g., with one-hot encoding). We propose to systematically leverage language models to learn entity representations, whenever significant sequences of such entities are historically observed. Through two diverse use-cases, we show that such entity encoding can benefit and naturally augment classic quantity-based features. Zied Ben-Houidi, Raphaël Azorin, Massimo Gallo, Alessandro Finamore, Dario Rossi 0001 |
HotNets | 1 |
| 2022 | Neural language models for network configuration: Opportunities and reality check
Zied Ben-Houidi, Dario Rossi 0001 |
Comput. Commun. | 1 |
| 2021 | DarkVec: automatic analysis of darknet traffic with word embeddingsabstractDarknets are passive probes listening to traffic reaching IP addresses that host no services. Traffic reaching them is unsolicited by nature and often induced by scanners, malicious senders and misconfigured hosts. Its peculiar nature makes it a valuable source of information to learn about malicious activities. However, the massive amount of packets and sources that reach darknets makes it hard to extract meaningful insights. In particular, multiple senders contact the darknet while performing similar and coordinated tasks, which are often commanded by common controllers (botnets, crawlers, etc.). How to automatically identify and group those senders that share similar behaviors remains an open problem. Luca Gioacchini, Luca Vassio, Marco Mellia, Idilio Drago, Zied Ben-Houidi, Dario Rossi 0001 |
CoNEXT | 5 |
| 2021 | Real-Time Channel Management in WLANs: Deep Reinforcement Learning versus HeuristicsabstractToday's WLANs rely on a centralized Access Controller (AC) entity for managing distributed wireless Access Points (APs) to which user devices connect. The availability of real-time analytics at the AC opens the possibility to automate the allocation of scarce radio resources, continuously adapting to changes in traffic demands. Often, the allocation problem is formulated in terms of weighted graph coloring, which is NP-hard, and custom heuristics are used to find satisfactory solutions. In this paper, we contrast solutions that are based on (and even improve) state of the art heuristics to a data-driven solution that leverages Deep Reinforcement Learning (DRL). Based on both simulation results as well as experiments in a real deployment, we show that our DRL-based scheme not only learns to solve the complex combinatorial problem in bounded time, outperforming heuristics, but it also exhibits appealing generalization properties, e.g. to different network sizes and densities. Ovidiu Iacoboaiea, Jonatan Krolikowski, Zied Ben-Houidi, Dario Rossi 0001 |
Networking | 3 |
| 2021 | Deployable Models for Approximating Web QoE Metrics From Encrypted TrafficabstractBeing on endpoints, Content Providers can easily evaluate end users' Web browsing quality of experience (Web QoE) by accessing in-browser computed application-level metrics. Because of end-to-end traffic encryption, it is becoming considerably harder for Internet Service Providers (ISPs) to evaluate the Web QoE of their customers, which is important for management purposes. In this paper, we propose data-driven machine learning techniques and exact flow-level algorithmic methods to infer well-known application-level Web performance metrics (such as SpeedIndex and Page Load Time) from raw encrypted streams of network traffic. We prove the efficiency of our approach taking as input a unique dataset of more than 200,000 experiments, targeting a large set of popular pages (Alexa top-500), from probes from several ISPs networks, with different browsers (Chrome, Firefox) and viewport combinations. Results show that our data-driven models are not only accurate for several Web performance metrics, but also feature the ability to generalize to previously unseen conditions. Furthermore, we discuss how our extremely lightweight flow-level method has a provable accuracy on a specific metric, and is thus of particular appeal from a deployment viewpoint. Alexis Huet, Antoine Saverimoutou, Zied Ben-Houidi, Hao Shi 0002, Shengming Cai, Jinchun Xu, Bertrand Mathieu, Dario Rossi 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | Detecting Degradation of Web Browsing Quality of ExperienceabstractQuality of Experience (QoE) inference, and particularly the detection of its degradation is an important management tool for ISPs. Yet, this task is made difficult due to widespread use of encryption on the data-plane on the one hand so that measuring QoE is hard, and to the ephemeral properties of the web content on the other hand so that changes in QoE indicators may be rooted in changes in properties of the content itself, more than being caused by network-related events. In this paper, we phrase the QoE degradation detection issue as a change point detection problem, that we tackle by leveraging a unique dataset consisting on several hundreds thousands browsing sessions spanning multiple months. Our results, beyond showing feasibility, warn about the exclusive use of QoE indicators that are very close to content, as changes in the content space can lead to false alarms that are not tied to network-related problems. Alexis Huet, Zied Ben-Houidi, Bertrand Mathieu, Dario Rossi 0001 |
CNSM | 2 |
| 2020 | Are you on Mobile or Desktop? On the Impact of End-User Device on Web QoE Inference from Encrypted TrafficabstractWeb browsing is one of the key applications of the Internet, if not the most important one. We address the problem of Web Quality-of-Experience (QoE) monitoring from the ISP perspective, relying on in-network, passive measurements. As a proxy to Web QoE, we focus on the analysis of the well-known SpeedIndex (SI) metric. Given the lack of application-level-data visibility introduced by the wide adoption of end-to-end encryption, we resort to machine-learning models to infer the SI and the QoE level of individual web-page loading sessions, using as input only packet- and flow-level data. In this paper, we study the impact of different end-user device types (e.g., smartphone, desktop, tablet) on the performance of such models. Empirical evaluations on a large, multi-device, heterogeneous corpus of Web-QoE measurements for the most popular websites demonstrate that the proposed solution can infer the SI as well as estimate QoE ranges with high accuracy, using either packet-level or flow-level measurements. In addition, we show that the device type adds a strong bias to the feasibility of these Web-QoE models, putting into question the applicability of previously conceived approaches on single-device measurements. To improve the state of the art, we conceive cross-device generalizable models operating at both packet and flow levels, offering a feasible solution for Web-QoE monitoring in operational, multi-device networks. To the best of our knowledge, this is the first study tackling the analysis of Web QoE from encrypted network traffic in multi-device scenarios. Sarah Wassermann, Pedro Casas, Zied Ben-Houidi, Alexis Huet, Michael Seufert, Nikolas Wehner, Joshua Schüler, Shengming Cai, Hao Shi 0002, Jinchun Xu, Tobias Hoßfeld, Dario Rossi 0001 |
CNSM | 3 |
| 2020 | Revealing QoE of Web Users from Encrypted Network Traffic
Alexis Huet, Antoine Saverimoutou, Zied Ben-Houidi, Hao Shi 0002, Shengming Cai, Jinchun Xu, Bertrand Mathieu, Dario Rossi 0001 |
Networking | 3 |
| 2019 | The News We Like Are Not the News We Visit: News Categories Popularity in Usage Data
Zied Ben-Houidi, Giuseppe Scavo, Stefano Traverso, Renata Teixeira, Marco Mellia, Soumen Ganguly |
ICWSM | 1 |
| 2018 | You, the Web, and Your Device: Longitudinal Characterization of Browsing HabitsabstractUnderstanding how people interact with the web is key for a variety of applications, e.g., from the design of effective web pages to the definition of successful online marketing campaigns. Browsing behavior has been traditionally represented and studied by means of clickstreams , i.e., graphs whose vertices are web pages, and edges are the paths followed by users. Obtaining large and representative data to extract clickstreams is, however, challenging. The evolution of the web questions whether browsing behavior is changing and, by consequence, whether properties of clickstreams are changing. This article presents a longitudinal study of clickstreams from 2013 to 2016. We evaluate an anonymized dataset of HTTP traces captured in a large ISP, where thousands of households are connected. We first propose a methodology to identify actual URLs requested by users from the massive set of requests automatically fired by browsers when rendering web pages. Then, we characterize web usage patterns and clickstreams, taking into account both the temporal evolution and the impact of the device used to explore the web. Our analyses precisely quantify various aspects of clickstreams and uncover interesting patterns, such as the typical short paths followed by people while navigating the web, the fast increasing trend in browsing from mobile devices, and the different roles of search engines and social networks in promoting content. Finally, we contribute a dataset of anonymized clickstreams to the community to foster new studies.1 Luca Vassio, Idilio Drago, Marco Mellia, Zied Ben-Houidi, Mohamed Lamine Lamali |
ACM Trans. Web | 4 |
| 2017 | WeBrowse: Leveraging User Clicks for Content Discovery in Communities of a PlaceabstractOne of the limits of web content discovery tools, let them be recommender systems or content curation tools such as social rating, social bookmarking and other social media, is the scarcity of user input (e.g. rate, submit, share). This problem is even worse in the case of what we call communities of a place: people who study, live or work at the same place. Such people often share common interests but either do not know each other or fail to actively engage in submitting and relaying information. In this paper, we investigate the feasibility of using the aggregated clicks of entire communities of users to passively emulate a content curation service a la Reddit. To this end, we prototype and deploy WeBrowse, a content curation service based on the processing of raw HTTP logs. Evaluation based on our deployments demonstrates feasibility at scale while respecting user privacy. The majority of WeBrowse's users welcome the quality of content it promotes. Giuseppe Scavo, Zied Ben-Houidi, Stefano Traverso, Renata Teixeira, Marco Mellia |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2016 | A Knowledge-Based Systems Approach to Reason About NetworkingabstractMost unwritten languages today have no known grammar, and are rather governed by ``unspoken rules''. Similarly, we think that the young discipline of networking is still a practice that lacks a deep understanding of the rules that govern it. This situation results in a loss of time and efforts. First, since the rules are unspoken, they are not systematically reused. Second, since there is no grammar, it is impossible to assert if a sentence is correct. Comparing two networking approaches or solutions is sometimes a synonym of endless religious debates. Drawing the proper conclusion from this claim, we advocate that networking research should spend more efforts on better understanding its rules as a first step to automatically reuse them. To illustrate our claim, we focus in this paper on one broad family of networking connectivity problems. We show how different instances of this problem, which were solved in parallel with no explicit knowledge reuse, can be derived from a small set of facts and rules implemented in a knowledge-based system. Zied Ben-Houidi |
HotNets | 1 |
| 2010 | A new VPN routing approach for large scale networksabstractOne of the most common provider provisioned VPN technologies uses MPLS as a data plane for customer flow isolation and BGP as a control plane for routing between VPN sites. From a data plane perspective, such networks can provision hundreds of thousands of VPN sites. However, the BGP control plane is prone to scalability concerns. Some BGP routers in VPN backbones must handle routes for all the VPN sites that the provider connects. The number of sites can generate two million BGP routes in large VPN backbones, almost ten times the number of routes in a core Internet router. Prior work proposed solutions to evolve such networks. Yet, we argue that they fail to address the root cause of VPN routing performance issues. In this paper, we show that VPN routing scheme's poor scalability stems from the application to VPNs of a protocol originally designed for full routing, specifically the Internet. Rather than evolving the current standard based on BGP, we take a principled approach to rethink routing in large VPNs. We propose Two-Step VPN Routing, a new approach for scalable VPN routing. We validate our design choices and compare our approach to existing ones, using both BGP updates and router configurations collected from a large VPN provider. Zied Ben-Houidi, Mickael Meulle |
ICNP | 1 |
| 2009 | Understanding slow BGP routing table transfersabstractResearchers and network operators often say that BGP table transfers are slow. Despite this common knowledge, the reasons for slow BGP transfers are not well understood. This paper explains BGP table transfer delays by combining BGP messages collected at a large VPN provider backbone and controlled experiments with routers of three different vendors as well as a software BGP speaker. Our results show that table transfers both in the provider network and in the controlled experiments contain gaps, i.e., periods in which both the sending and receiving routers are idle, but no BGP routes are exchanged. Gaps can represent more than 90% of the table transfer time. Our analysis of a software router and discussions with router vendors indicate that gaps happen because of the timer-driven implementation of sending of BGP updates. Hence, gaps represent an undocumented design choice that gives preference to more controlled router load over faster table transfers. Zied Ben-Houidi, Mickael Meulle, Renata Teixeira |
Internet Measurement Conference | 1 |
| 2007 | Origin of route explosion in virtual private networksabstractEnterprises often have sites that are spread in distant locations. These sites need to interconnect with the same level of privacy as in a local-area network. Virtual Private Networks (VPNs) were introduced to serve this need. A common VPN technology uses Multiprotocol extensions for the Border Gateway Protocol (MP-BGP) and Multiprotocol Label Switching (MPLS). This technology allows a service provider to share its IP backbone among multiple VPN clients while preserving privacy. MPLS tunnels provide traffic isolation, whereas MP-BGP distributes VPN routes. Despite the wide deployment of BGP/MPLS VPNs[1], there have been only few studies to understand their behavior, mostly because of the lack of public data. Prior work focused on BGP convergence [3] and on integrity constraints to ensure connectivity [2]. Zied Ben-Houidi, Renata Teixeira, Marc Capelle |
CoNEXT | 1 |