EDBT 2026 Demo / reviewers in the wild / expert
Nir Nissim
dblp:92/6610
· DBLP profile ↗
43ranked-venue papers
12as first author
18since 2021 · last 2026
0000-0003-0652-8861ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 26 · 5 first-author · 13 since 2021Security and privacy · 10 · 4 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DLLicious: detection and explainability of malicious DLL files using novel static feature extraction methods
Alexander Yevsikov, Nir Nissim |
Expert Syst. Appl. | 2 |
| 2025 | Improving Generalization Capabilities of Models Trained on Time Series Data Using Novel Downsampling MethodsabstractLearning from time series data, particularly univariate time series data (UTSD), is important in various fields. Learning accurately from UTSD is challenging, since the data may be very granular and noisy and thus may contain time points which do not necessarily contribute to, and may even prevent, the ability to attain high generalization capabilities. Downsampling, in which a pared down version of the original UTSD that contains its most valuable parts is preserved, is commonly performed to cope with highly granular or noisy UTSD. However, there is a lack of effective downsampling methods, along with the appropriate evaluation metrics for them. We propose four new UTSD downsampling methods and evaluate their performance on nine commonly used and publicly available datasets. To enable proper evaluation of the downsampling methods, we have proposed three new evaluation metrics. Our evaluation demonstrates that our downsampling methods outperform state-of-the-art (SOT A) methods in two aspects: (1) our methods better preserve the original UTSD; and (2) more importantly, downsampled UTSD provided by our methods allow machine learning (ML) models to attain higher generalization capabilities compared to UTSD that SOTA downsampled. Particularly, our methods obtained better results in almost all the examined datasets (nearly 90%) in comparison to SOTA. Ofir Landau, Nir Nissim |
ICDM | 2 |
| 2025 | Mining multi-electrode and multi-wave electroencephalogram based time-interval temporal patterns for improved classification capabilities and explainability
Ofir Landau, Nir Nissim |
Artif. Intell. Medicine | 2 |
| 2024 | Bon-APT: Detection, attribution, and explainability of APT malware using temporal segmentation of API calls
Gil Shenderovitz, Nir Nissim |
Comput. Secur. | 2 |
| 2024 | Patterns of time-interval based patterns for improved multivariate time series data classification
Gil Shenderovitz, Eitam Sheetrit, Nir Nissim |
Eng. Appl. Artif. Intell. | 3 |
| 2024 | CADefender: Detection of unknown malicious AutoLISP computer-aided design files using designated feature extraction and machine learning methods
Alexander Yevsikov, Trivikram Muralidharan, Tomer Panker, Nir Nissim |
Eng. Appl. Artif. Intell. | 4 |
| 2024 | MinCloud: Trusted and transferable MinHash-based framework for unknown malware detection for Linux cloud environments
Tomer Panker, Aviad Cohen 0002, Tom Landman, Chen Bery, Nir Nissim |
J. Inf. Secur. Appl. | 5 |
| 2023 | Can NeuroIS improve executive employee recruitment? Classifying levels of executive functions using resting state EEG and data science methods
Dor Zazon, Lior Fink, Shirley Gordon, Nir Nissim |
Decis. Support Syst. | 4 |
| 2023 | Efficient feature extraction methodologies for unknown MP4-Malware detection using Machine learning algorithms
Tal Tsafrir, Aviad Cohen 0002, Etay Nir, Nir Nissim |
Expert Syst. Appl. | 4 |
| 2023 | Improving malicious email detection through novel designated deep-learning architectures utilizing entire email
Trivikram Muralidharan, Nir Nissim |
Neural Networks | 2 |
| 2022 | A time-interval-based active learning framework for enhanced PE malware acquisition and detection
Ido Finder, Eitam Sheetrit, Nir Nissim |
Comput. Secur. | 3 |
| 2022 | Personalized insulin dose manipulation attack and its detection using interval-based temporal patterns and machine learning algorithms
Tamar Levy-Loboda, Eitam Sheetrit, Idit F. Liberty, Alon Haim, Nir Nissim |
J. Biomed. Informatics | 5 |
| 2022 | Time-interval temporal patterns can beat and explain the malware
Ido Finder, Eitam Sheetrit, Nir Nissim |
Knowl. Based Syst. | 3 |
| 2022 | The infinite race between steganography and steganalysis in images
Trivikram Muralidharan, Aviad Cohen 0002, Assaf Cohen, Nir Nissim |
Signal Process. | 4 |
| 2021 | Pay Attention: Improving Classification of PE Malware Using Attention Mechanisms Based on System Call AnalysisabstractMalware poses a threat to computing systems worldwide, and security experts work tirelessly to detect and classify malware as accurately and quickly as possible. Since malware can use evasion techniques to bypass static analysis and security mechanisms, dynamic analysis methods are more useful for accurately analyzing the behavioral patterns of malware. Previous studies showed that malware behavior can be represented by sequences of executed system calls and that machine learning algorithms can leverage such sequences for the task of malware classification (a.k.a. malware categorization). Accurate malware classification is helpful for malware signature generation and is thus beneficial to antivirus vendors; this capability is also valuable to organizational security experts, enabling them to mitigate malware attacks and respond to security incidents. In this paper, we propose an improved methodology for malware classification, based on analyzing sequences of system calls invoked by malware in a dynamic analysis environment. We show that adding an attention mechanism to a LSTM model improves accuracy for the task of malware classification, thus outperforming the state-of-the-art algorithm by up to 6%. We also show that the transformer architecture can be used to analyze very long sequences with significantly lower time complexity for training and prediction. Our proposed method can serve as the basis for a decision support system for security experts, for the task of malware categorization. Ori Or-Meir, Aviad Cohen 0002, Yuval Elovici, Lior Rokach, Nir Nissim |
IJCNN | 5 |
| 2021 | Cardio-ML: Detection of malicious clinical programmings aimed at cardiac implantable electronic devices based on machine learning and a missing values resemblance framework
Tamar Levy-Loboda, Moshe Rav-Acha, Amos Katz, Nir Nissim |
Artif. Intell. Medicine | 4 |
| 2021 | Leveraging malicious behavior traces from volatile memory using machine learning methods for trusted unknown malware detection in Linux cloud environments
Tomer Panker, Nir Nissim |
Knowl. Based Syst. | 2 |
| 2021 | Deep-Hook: A trusted deep learning-based framework for unknown malware detection and classification in Linux cloud environments
Tom Landman, Nir Nissim |
Neural Networks | 2 |
| 2020 | Mind your privacy: Privacy leakage through BCI applications using machine learning methods
Ofir Landau, Aviad Cohen 0002, Shirley Gordon, Nir Nissim |
Knowl. Based Syst. | 4 |
| 2020 | ASSAF: Advanced and Slim StegAnalysis Detection Framework for JPEG images based on deep convolutional denoising autoencoder and Siamese networks
Assaf Cohen, Aviad Cohen 0002, Nir Nissim |
Neural Networks | 3 |
| 2020 | Deep feature transfer learning for trusted and automated malware signature generation in private cloud environments
Daniel Nahmias, Aviad Cohen 0002, Nir Nissim, Yuval Elovici |
Neural Networks | 3 |
| 2019 | TrustSign: Trusted Malware Signature Generation in Private Clouds Using Deep Feature Transfer LearningabstractThis paper presents TrustSign, a novel, trusted automatic malware signature generation method based on high-level deep features transferred from a VGG-19 neural network model pre-trained on the ImageNet dataset. While traditional automatic malware signature generation techniques rely on static or dynamic analysis of the malware's executable, our method overcomes the limitations associated with these techniques by producing signatures based on the presence of the malicious process in the volatile memory. Signatures generated using TrustSign well represent the real malware behavior during runtime. By leveraging the cloud's virtualization technology, TrustSign analyzes the malicious process in a trusted manner, since the malware is unaware and cannot interfere with the inspection procedure. Additionally, by removing the dependency on the malware's executable, our method is capable of signing fileless malware. Thus, we focus our research on in-browser cryptojacking attacks, which current antivirus solutions have difficulty to detect. However, TrustSign is not limited to cryptojacking attacks, as our evaluation included various ransomware samples. TrustSign's signature generation process does not require feature engineering or any additional model training, and it is done in a completely unsupervised manner, obviating the need for a human expert. Therefore, our method has the advantage of dramatically reducing signature generation and distribution time. The results of our experimental evaluation demonstrate TrustSign's ability to generate signatures invariant to the process state over time. By using the signatures generated by TrustSign as input for various supervised classifiers, we achieved 99.5% classification accuracy. Daniel Nahmias, Aviad Cohen 0002, Nir Nissim, Yuval Elovici |
IJCNN | 3 |
| 2019 | Temporal Probabilistic Profiles for Sepsis Prediction in the ICUabstractSepsis is a condition caused by the body's overwhelming and life-threatening response to infection, which can lead to tissue damage, organ failure, and finally death. Today, sepsis is one of the leading causes of mortality among populations in intensive care units (ICUs). Sepsis is difficult to predict, diagnose, and treat, as it involves analyzing different sets of multivariate time-series, usually with problems of missing data, different sampling frequencies, and random noise. Here, we propose a new dynamic-behavior-based model, which we call a Temporal Probabilistic proFile (TPF), for classification and prediction tasks of multivariate time series. In the TPF method, the raw, time-stamped data are first abstracted into a series of higher-level, meaningful concepts, which hold over intervals characterizing time periods. We then discover frequently repeating temporal patterns within the data. Using the discovered patterns, we create a probabilistic distribution of the temporal patterns of the overall entity population, of each target class in it, and of each entity. We then exploit TPFs as meta-features to classify the time series of new entities, or to predict their outcome, by measuring their TPF distance, either to the aggregated TPF of each class, or to the individual TPFs of each of the entities, using negative cross entropy. Our experimental results on a large benchmark clinical data set show that TPFs improve sepsis prediction capabilities, and perform better than other machine learning approaches. Eitam Sheetrit, Nir Nissim, Denis Klimov, Yuval Shahar |
KDD | 2 |
| 2019 | Malboard: A novel user keystroke impersonation attack and trusted detection framework based on side-channel analysis
Nitzan Farhi, Nir Nissim, Yuval Elovici |
Comput. Secur. | 2 |
| 2019 | Volatile memory analysis using the MinHash method for efficient and secured detection of malware in private cloud
Nir Nissim, Omri Lahav, Aviad Cohen 0002, Yuval Elovici, Lior Rokach |
Comput. Secur. | 1 |
| 2019 | Keep an eye on your personal belongings! The security of personal medical devices and their ecosystems
Matan Kintzlinger, Nir Nissim |
J. Biomed. Informatics | 2 |
| 2018 | Trusted detection of ransomware in a private cloud using machine learning methods leveraging meta-features from volatile memory
Aviad Cohen 0002, Nir Nissim |
Expert Syst. Appl. | 2 |
| 2018 | Novel set of general descriptive features for enhanced detection of malicious emails using machine learning methods
Aviad Cohen 0002, Nir Nissim, Yuval Elovici |
Expert Syst. Appl. | 2 |
| 2018 | Trusted system-calls analysis methodology aimed at detection of compromised virtual machines using sequential mining
Nir Nissim, Yuval Lapidot, Aviad Cohen 0002, Yuval Elovici |
Knowl. Based Syst. | 1 |
| 2017 | Inter-labeler and intra-labeler variability of condition severity classification models using active and passive learning methods
Nir Nissim, Yuval Shahar, Yuval Elovici, George Hripcsak, Robert Moskovitch |
Artif. Intell. Medicine | 1 |
| 2017 | USB-based attacks
Nir Nissim, Ran Yahalom, Yuval Elovici |
Comput. Secur. | 1 |
| 2017 | ALDOCX: Detection of Unknown Malicious Microsoft Office Documents Using Designated Active Learning Methods Based on New Structural Feature Extraction MethodologyabstractAttackers increasingly take advantage of innocent users who tend to casually open email messages assumed to be benign, carrying malicious documents. Recent targeted attacks aimed at organizations utilize the new Microsoft Word documents (*.docx). Anti-virus software fails to detect new unknown malicious files, including malicious docx files. In this paper, we present ALDOCX, a framework aimed at accurate detection of new unknown malicious docx files that also efficiently enhances the framework's detection capabilities over time. Detection relies upon our new structural feature extraction methodology (SFEM), which is performed statically using meta-features extracted from docx files. Using machine-learning algorithms with SFEM, we created a detection model that successfully detects new unknown malicious docx files. In addition, because it is crucial to maintain the detection model's updatability and incorporate new malicious files created daily, ALDOCX integrates our active-learning (AL) methods, which are designed to efficiently assist anti-virus vendors by better focusing their experts' analytical efforts and enhance detection capability. ALDOCX identifies and acquires new docx files that are most likely malicious, as well as informative benign files. These files are used for enhancing the knowledge stores of both the detection model and the anti-virus software. The evaluation results show that by using ALDOCX and SFEM, we achieved a high detection rate of malicious docx files (94.44% TPR) compared with the anti-virus software (85.9% TPR)-with very low FPR rates (0.19%). ALDOCX's AL methods used only 14% of the labeled docx files, which led to a reduction of 95.5% in security experts' labeling efforts compared with the passive learning and the support vector machine (SVM)-Margin (existing active-learning method). Our AL methods also showed a significant improvement of 91% in number of unknown docx malware acquired, compared with the passive learning and the SVM-Margin, thus providing an improved updating solution for the detection model, as well as the anti-virus software widely used within organizations. Nir Nissim, Aviad Cohen 0002, Yuval Elovici |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | SFEM: Structural feature extraction methodology for the detection of malicious office documents using machine learning methods
Aviad Cohen 0002, Nir Nissim, Lior Rokach, Yuval Elovici |
Expert Syst. Appl. | 2 |
| 2016 | Improving condition severity classification with an efficient active learning based framework
Nir Nissim, Mary Regina Boland, Nicholas P. Tatonetti, Yuval Elovici, George Hripcsak, Yuval Shahar, Robert Moskovitch |
J. Biomed. Informatics | 1 |
| 2016 | ALDROID: efficient update of Android anti-virus software using designated active learning methods
Nir Nissim, Robert Moskovitch, Oren Bar-Ad, Lior Rokach, Yuval Elovici |
Knowl. Inf. Syst. | 1 |
| 2015 | An Active Learning Framework for Efficient Condition Severity Classification
Nir Nissim, Mary Regina Boland, Robert Moskovitch, Nicholas P. Tatonetti, Yuval Elovici, Yuval Shahar, George Hripcsak |
AIME | 1 |
| 2015 | Boosting the Detection of Malicious Documents Using Designated Active Learning MethodsabstractMost organizations usually create, send and receive huge amounts of documents daily, Attackers increasingly take advantage of innocent users who tend to casually open email massages assumed to be benign, carrying malicious documents. Recent targeted attacks aimed at organizations, utilize the new Microsoft Word documents (*.docx). Anti-virus software fails to detect new unknown malicious files, including malicious docx files. In this study, we present SFEM feature extraction methodology and designated Active Learning (AL) methods, aimed at accurate detection of new unknown malicious docx files that also efficiently enhances the detection's model capabilities over time. Our AL methods identify and acquire only small set of new docx files that are most likely malicious, as well as informative benign files, these files are used for enhancing the knowledge stores of both the detection model and the anti-virus software. Results show that our active learning methods used only 14% of the labeled docx files within organization which led to a reduction of 95.5% in labeling efforts compared to passive learning and SVM-Margin (existing active learning method). Our AL methods also showed a significant improvement of 91% in unknown docx malware acquisition compared to passive learning and SVM-Margin, thus providing an improved updating solution for detection model, as well as the anti-virus software widely used within organizations. Nir Nissim, Aviad Cohen 0002, Yuval Elovici |
ICMLA | 1 |
| 2015 | Detection of malicious PDF files and directions for enhancements: A state-of-the art survey
Nir Nissim, Aviad Cohen 0002, Chanan Glezer, Yuval Elovici |
Comput. Secur. | 1 |
| 2014 | Novel active learning methods for enhanced PC malware detection in windows OS
Nir Nissim, Robert Moskovitch, Lior Rokach, Yuval Elovici |
Expert Syst. Appl. | 1 |
| 2012 | Detecting unknown computer worm activity via support vector machines and active learning
Nir Nissim, Robert Moskovitch, Lior Rokach, Yuval Elovici |
Pattern Anal. Appl. | 1 |
| 2008 | Active learning to improve the detection of unknown computer worms activity
Robert Moskovitch, Nir Nissim, Roman Englert, Yuval Elovici |
FUSION | 2 |
| 2008 | Unknown malcode detection via text categorization and the imbalance problemabstractTodaypsilas signature-based anti-viruses are very accurate, but are limited in detecting new malicious code. Currently, dozens of new malicious codes are created every day, and this number is expected to increase in the coming years. Recently, classification algorithms were used successfully for the detection of unknown malicious code. These studies used a test collection with a limited size where the same malicious-benign-file ratio in both the training and test sets, which does not reflect real-life conditions. In this paper we present a methodology for the detection of unknown malicious code, based on text categorization concepts. We performed an extensive evaluation using a test collection that contains more than 30,000 malicious and benign files, in which we investigated the imbalance problem. In real-life scenarios, the malicious file content is expected to be low, about 10% of the total files. For practical purposes, it is unclear as to what the corresponding percentage in the training set should be. Our results indicate that greater than 95% accuracy can be achieved through the use of a training set that contains below 20% malicious file content. Robert Moskovitch, Dima Stopel, Clint Feher, Nir Nissim, Yuval Elovici |
ISI | 4 |
| 2007 | Malicious Code Detection and Acquisition Using Active LearningabstractDetection of known malicious code is commonly performed by anti-virus tools. These tools detect the known malicious code using signature detection methods. Each time a new malicious code is found the anti-virus vendors create a new signature and update their clients. During the period between the appearance of a new unknown malicious code and the update of the signature base of the anti-virus clients, millions of computers might be infected. In order to cope with this problem, new solutions must be found for detecting unknown malicious code at the entrance of a client's computer. We presented here the use of active learning in the acquisition of unknown malicious code. Preliminary Results are encouraging. We are currently in the process of creating a wide test collection of more than 30,000 benign and malicious files to evaluate several active learning criterions. Robert Moskovitch, Nir Nissim, Yuval Elovici |
ISI | 2 |