EDBT 2026 Demo / reviewers in the wild / expert
Gregory Blanc
dblp:89/10040 · also Grégory Blanc
· DBLP profile ↗
27ranked-venue papers
3as first author
13since 2021 · last 2026
0000-0001-8150-6617ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 3 first-author · 11 since 2021Artificial intelligence and machine learning · 3Computer networks · 2Software engineering, systems software and programming languages · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Robustness Evaluation of Graph Neural Network-Based Network Intrusion Detection Systems against Adversarial Flow InjectionabstractInternational audience Matthieu Mouzaoui, Yufei Han 0001, Gregory Blanc, Gabriel Rilling, Michel Hurfin |
SECRYPT (1) | 3 |
| 2025 | Privacy Benchmarking of Intrusion Detection Sytems
Solayman Ayoubi, Gregory Blanc, Houda Jmila, Sébastien Tixeuil |
AINA (4) | 2 |
| 2025 | ARTMAN '25: Third Workshop on Recent Advances in Resilient and Trustworthy MAchine learning-driveN systemsabstractThe ARTMAN workshop aims to bring together academic researchers and industry practitioners from diverse domains, primarily security & privacy and machine learning, but also various application fields, to collaboratively explore and discuss resilient and trustworthy machine learning-powered applications and systems. This workshop focuses on AI/ML application domains and welcomes contributions on both foundational and applied aspects of ML across various industries, including transportation, aerospace, healthcare, energy, and finance, among others, showcasing AI-driven advances in performance and efficiency. This workshop also seeks contributions on the application of reliable and secure AI/ML algorithms, especially knowledge-informed approaches, to improve resilience and trust, particularly in human-machine partnerships and interactions within such scenarios. Gregory Blanc, Takeshi Takahashi 0001, Zonghua Zhang |
CCS | 1 |
| 2025 | PROTEAN: Federated Intrusion Detection in Non-IID Environments Through Prototype-Based Knowledge Sharing
Sara Chennoufi, Yufei Han 0001, Gregory Blanc, Emiliano De Cristofaro, Christophe Kiennert |
ESORICS (1) | 3 |
| 2025 | How Dataset Diversity Affects Generalization in ML-Based NIDS
Bénoît Nougnanke, Gregory Blanc, Thomas Robert 0003 |
ESORICS (1) | 2 |
| 2024 | A Model-based Approach for Assessing the Security of Cyber-Physical SystemsabstractCyber-Physical Systems (CPSs) complexity has been continuously increasing to support new life-impacting applications, such as Internet of Things (IoT) devices or Industrial Control Systems (ICSs). These characteristics introduce new critical security challenges to both industrial practitioners and academics. This work investigates how Model-Based System Engineering (MBSE) and attack graph approaches could be leveraged to model secure Cyber-Physical System solutions and identify high-impact attacks early in the system development life cycle. To achieve this, we propose a new framework that comprises (1) an easily adoptable modeling paradigm for Cyber-Physical System representation, (2) an attack-graph-based solution for Cyber-Physical System automatic quantitative security analysis, based on the MulVAL security tool, (3) a set of Model-To-Text (MTT) transformation rules to bridge the gap between SysML and MulVAL. We illustrated the validity of our proposed framework through an autonomous ventilation system example. A Denial of Service (DoS) attack targeting an industrial communication protocol was identified and displayed as attack graphs. In future work, we intend to connect the approach to dynamic security databases for automatic countermeasure selection. Hugo Teixeira De Castro, Ahmed Hussain 0002, Gregory Blanc, Jamal El Hachem, Dominique Blouin, Jean Leneutre, Panagiotis Papadimitratos |
ARES | 3 |
| 2024 | SoK: Federated Learning based Network Intrusion Detection in 5G: Context, State of the Art and Challengesabstract5G brings significant advancement, offering lower latency, and improved connectivity. Yet, its complexity, stemming from factors such as integrating advanced technologies like Software Defined Networking (SDN) and slicing, introduces challenges in implementing strong security measures against emerging threats. Although Intrusion Detection Systems (IDSs) can successfully detect attacks, the novelty of 5G creates an expanded attack surface. Collaboration is essential for detecting novel, distributed attacks, and ensuring comprehensive observability in multiparty networks. However, such collaboration raises privacy concerns due to the sensitivity of shared data. Federated Learning (FL), a collaborative Machine Learning (ML) approach, is a promising solution to preserve privacy as the model is trained locally without exchanging raw data. Sara Chennoufi, Gregory Blanc, Houda Jmila, Christophe Kiennert |
ARES | 2 |
| 2024 | Demo: Towards Reproducible Evaluations of ML-Based IDS Using Data-Driven ApproachesabstractNetwork-based Intrusion Detection Systems (NIDS) are crucial in cybersecurity, but evaluation methodologies are outdated and lack standardization, resulting in incomplete and unreliable assessments. To address these issues, we first proposed a comprehensive evaluation framework for Machine Learning-based Intrusion Detection Systems [1]. This framework accounts for the unique aspects, strengths, and weaknesses of ML algorithms. However, the initial proposition lacked practicality, as it presented an abstract methodology without a substantive solution. In this paper, we present a demo of FREIDA a precise and concrete implementation of our framework, featuring an easy-to-use graphical interface. We also outline FREIDA's evaluation methodology and demonstrate its application in evaluating IDS using a dataset from the literature. Solayman Ayoubi, Sébastien Tixeuil, Gregory Blanc, Houda Jmila |
CCS | 3 |
| 2024 | FREIDA: A Concrete Tool for Reproducible Evaluation of IDS Using a Data-Driven Approach
Solayman Ayoubi, Gregory Blanc, Houda Jmila, Sébastien Tixeuil |
CRiSIS | 2 |
| 2024 | DDoS Mitigation while Preserving QoS: A Deep Reinforcement Learning-Based ApproachabstractThe deployment of 5G networks has significantly improved connectivity, providing remarkable speed and capacity. These networks rely on Software-Defined Networking (SDN) to enhance control and flexibility. However, this advancement poses critical challenges including expanded attack surface due to network virtualization and the risk of unauthorized access to critical infrastructure. Since traditional cybersecurity methods are inadequate in addressing the dynamic nature of modern cyber attacks, employing artificial intelligence (AI), and deep reinforcement learning (DRL) in particular, was investigated to enhance 5G networks security. This interest arises from the ability of these techniques to dynamically respond and adapt their defense strategies according to encountered situations and real-time threats. Our proposed mitigation system uses a DRL framework, enabling an intelligent agent to dynamically adjust its defense strategies against a range of DDoS attacks, exploiting ICMP, TCP SYN, and UDP, within an SDN environment designed to mirror real-life user behaviors. This approach aims to maintain the network’s performance while concurrently mitigating the impact of the real-time attacks, by providing adaptive and automated countermeasures according to the network’s situation. Shurok Khozam, Gregory Blanc, Sébastien Tixeuil, Eric Totel |
NetSoft | 2 |
| 2024 | OIPM: Access Control Method to Prevent ID/Session Token Abuse on OpenID ConnectabstractInternational audience Junki Yuasa, Taisho Sasada, Christophe Kiennert, Gregory Blanc, Yuzo Taenaka, Youki Kadobayashi |
SECRYPT | 4 |
| 2023 | ARTMAN '23: First Workshop on Recent Advances in Resilient and Trustworthy ML Systems in Autonomous NetworksabstractThe increasing integration of machine learning (ML) approaches into the operation and management (O&M) of modern networks has led researchers to address various problems such as performance optimization, anomaly detection, traffic prediction, root-cause analysis and incident troubleshooting. Autonomous networks leverage the wealth of both business and operations data to achieve fully intelligent and automated O&M for various telecommunications applications. However, their high level of service requires the closest scrutiny as such applications depend on their resilience and trustworthiness, especially in the face of motivated attackers that aim at abusing their underlying ML models. This workshop fosters the close collaboration between researchers and practitioners at the intersection of security, networks and ML communities to improve the security of ML applications in autonomous networks together. Gregory Blanc, Takeshi Takahashi 0001, Zonghua Zhang |
CCS | 1 |
| 2021 | Towards security-Aware 5G slice embedding
Houda Jmila, Gregory Blanc |
Comput. Secur. | 2 |
| 2020 | Automated Saturation Mitigation Controlled by Deep Reinforcement LearningabstractRecent developments in orchestration and machine learning have made network automation more feasible, allowing the transition from error-prone and time-consuming manual manipulations to fast and refined automated responses in areas such as security and management. This article investigates the capabilities of a deep reinforcement learning agent to learn how to automatically share prefix announcements of an Autonomous System to its neighbors, in order to mitigate undesired network behaviors and therefore increase network resiliency and security. Our work focuses on network saturation, tackling the problem of network responsiveness in today's massive content delivery context. Results not only prove feasibility of such an agent, but also demonstrate its ability to minimize traffic loss as well as the number of actions to be performed by the automation process. Elkin Aguas, Anthony Lambert, Gregory Blanc, Hervé Debar |
ICNP | 3 |
| 2020 | Generative Deep Learning for Internet of Things Network Traffic GenerationabstractThe rapid development of the Internet of Things (IoT) has prompted a recent interest into realistic IoT network traffic generation. Security practitioners need IoT network traffic data to develop and assess network-based intrusion detection systems (NIDS). Emulating realistic network traffic will avoid the costly physical deployment of thousands of smart devices. From an attacker's perspective, generating network traffic that mimics the legitimate behavior of a device can be useful to evade NIDS. As network traffic data consist of sequences of packets, the problem is similar to the generation of sequences of categorical data, like word by word text generation. Many solutions in the field of natural language processing have been proposed to adapt a Generative Adversarial Network (GAN) to generate sequences of categorical data. In this paper, we propose to combine an autoencoder with a GAN to generate sequences of packet sizes that correspond to bidirectional flows. First, the autoencoder is trained to learn a latent representation of the real sequences of packet sizes. A GAN is then trained on the latent space, to learn to generate latent vectors that can be decoded into realistic sequences. For experimental purposes, bidirectional flows produced by a Google Home Mini are used, and the autoencoder is combined with a Wassertein GAN. Comparison of different network characteristics shows that our proposed approach is able to generate sequences of packet sizes that behave closely to real bidirectional flows. We also show that the synthetic bidirectional flows are close enough to the real ones that they can fool anomaly detectors into labeling them as legitimate. Mustafizur R. Shahid, Gregory Blanc, Houda Jmila, Zonghua Zhang, Hervé Debar |
PRDC | 2 |
| 2020 | Solving security constraints for 5G slice embedding: A proof-of-concept
François Boutigny, Stéphane Betgé-Brezetz, Gregory Blanc, Antoine Lavignotte, Hervé Debar, Houda Jmila |
Comput. Secur. | 3 |
| 2019 | Designing Security-Aware Service Requests for NFV-Enabled NetworksabstractNetwork Function Virtualization (NFV) is a recent concept where virtualization enables the shift from network functions (e.g., routers, switches, load-balancers, proxies) on specialized hardware appliances to software images running on all-purpose, high-volume servers. The resource allocation problem in the NFV environment has received considerable attention in the past years. However, little attention was paid to the security aspects of the problem in spite of the increasing number of vulnerabilities faced by cloud-based applications. Securing the services is an urgent need to completely benefit from the advantages offered by NFV. In this paper, we show how a network service request, composed of a set of service function chains (SFC) should be modified and enriched to take into consideration the security requirements of the supported service. We examine the well-known security best practices and propose a two-step algorithm that extends the initial SFC requests to a more complex chaining model that includes the security requirements of the service. Houda Jmila, Gregory Blanc |
ICCCN | 2 |
| 2019 | Siamese Network Based Feature Learning for Improved Intrusion Detection
Houda Jmila, Mohamed Ibn Khedher, Gregory Blanc, Mounim A. El-Yacoubi |
ICONIP (1) | 3 |
| 2019 | Optimizing Resource Allocation for Secure SDN-based Virtual Network MigrationabstractRecent evolutions in cloud infrastructures allowed service providers to tailor new services for demanding customers. Providing these services confronts the infrastructure providers with costs and constraints considerations. In particular, security constraints are a major concern for today's businesses as the leak of personal information would tarnish their reputation. Recent works provide examples on how an attacker may leverage the infrastructure's weaknesses to steal sensitive information from the users. Specifically, an attacker can leverage maintenance processes inside the infrastructure to conduct an attack. In this paper, we consider the migration of a virtual network as the maintenance process. Then we determine the optimal monitoring resources allocation in this context with a Markov Decision Process. This model takes into account the impact of monitoring the infrastructure, the migration process and finally how the attacker may chose particular targets in the infrastructure. We provide a working prototype implemented in Python1. Fabien Charmet, Gregory Blanc, Christophe Kiennert |
NCA | 2 |
| 2019 | Anomalous Communications Detection in IoT Networks Using Sparse AutoencodersabstractNowadays, IoT devices have been widely deployed for enabling various smart services, such as, smart home or e-healthcare. However, security remains as one of the paramount concern as many IoT devices are vulnerable. Moreover, IoT malware are constantly evolving and getting more sophisticated. IoT devices are intended to perform very specific tasks, so their networking behavior is expected to be reasonably stable and predictable. Any significant behavioral deviation from the normal patterns would indicate anomalous events. In this paper, we present a method to detect anomalous network communications in IoT networks using a set of sparse autoencoders. The proposed approach allows us to differentiate malicious communications from legitimate ones. So that, if a device is compromised only malicious communications can be dropped while the service provided by the device is not totally interrupted. To characterize network behavior, bidirectional TCP flows are extracted and described using statistics on the size of the first N packets sent and received, along with statistics on the corresponding inter-arrival times between packets. A set of sparse autoencoders is then trained to learn the profile of the legitimate communications generated by an experimental smart home network. Depending on the value of N, the developed model achieves attack detection rates ranging from 86.9% to 91.2%, and false positive rates ranging from 0.1% to 0.5%. Mustafizur R. Shahid, Gregory Blanc, Zonghua Zhang, Hervé Debar |
NCA | 2 |
| 2018 | Towards a 5G Security Architecture: Articulating Software-Defined Security and Security as a Serviceabstract5G is envisioned as a transformation of the communications architecture towards multi-tenant, scalable and flexible infrastructure, which heavily relies on virtualised network functions and programmable networks. In particular, orchestration will advance one step further in blending both compute and data resources, usually dedicated to virtualisation technologies, and network resources into so-called slices. Although 5G security is being developed in current working groups, slice security is seldom addressed. Gregory Blanc, Nizar Kheir, Dhouha Ayed, Vincent Lefebvre, Edgardo Montes de Oca, Pascal Bisson |
ARES | 1 |
| 2018 | IoT Devices Recognition Through Network Traffic AnalysisabstractThe growing Internet of Things (IoT) market introduces new challenges for network activity monitoring. Legacy network monitoring is not tailored to cope with the huge diversity of smart devices. New network discovery techniques are necessary in order to find out what IoT devices are connected to the network. In this context, data analysis techniques can be leveraged to find out specific patterns that can help to recognize device types. Indeed, contrary to desktop computers, IoT devices perform very specific tasks making their networking behavior very predictable. In this paper, we present a machine learning based approach in order to recognize the type of IoT devices connected to the network by analyzing streams of packets sent and received. We built an experimental smart home network to generate network traffic data. From the generated data, we have designed a model to describe IoT device network behaviors. By leveraging the t-SNE technique to visualize our data, we are able to differentiate the network traffic generated by different IoT devices. The data describing the network behaviors are then used to train six different machine learning classifiers to predict the IoT device that generated the network traffic. The results are promising with an overall accuracy as high as 99.9% on our test set achieved by Random Forest classifier. Mustafizur R. Shahid, Gregory Blanc, Zonghua Zhang, Hervé Debar |
IEEE BigData | 2 |
| 2017 | Preserving confidentiality during the migration of virtual SDN topologies: A formal approachabstractNetwork virtualization provides a flexible solution to reduce costs, share network resources and improve recovery time upon failure. An important part of virtual network management consists in migrating them in order to optimize resource allocation and react to link failures. However, the migration process might entail the loss of security properties in the virtual network, such as confidentiality. In this paper, we present the first approach combining formal models and virtualization to prove confidentiality preservation during the migration process. We describe the network environment, the migration process and the confidentiality with a set of logical predicates that will be used by SNARK to obtain the formal proof of the preservation. We validate our theoretical approach by exhibiting confidentiality violation detection on an illustrative use case. Fabien Charmet, Richard J. Waldinger, Gregory Blanc, Christophe Kiennert, Khalifa Toumi |
NCA | 3 |
| 2017 | ArOMA: An SDN based autonomic DDoS mitigation framework
Rishikesh Sahay, Gregory Blanc, Zonghua Zhang, Hervé Debar |
Comput. Secur. | 2 |
| 2015 | Eye Can Tell: On the Correlation Between Eye Movement and Phishing Identification
Daisuke Miyamoto, Gregory Blanc, Youki Kadobayashi |
ICONIP (3) | 2 |
| 2015 | Automated Classification of C&C Connections Through Malware URL Clustering
Nizar Kheir, Gregory Blanc, Hervé Debar, Joaquín García 0001, Dingqi Yang |
SEC | 2 |
| 2014 | Policy Enforcement Point Model
Yosra Ben Mustapha, Hervé Debar, Gregory Blanc |
SecureComm (1) | 3 |