EDBT 2026 Demo / reviewers in the wild / expert
Marthe Kassouf
dblp:98/8231
· DBLP profile ↗
13ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0002-3007-2350ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 5 · 4 since 2021Security and privacy · 4 · 3 since 2021Computer networks · 3 · 3 first-authorSystems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Quantum-Enhanced Deep Learning for Resilient Cyberattack Detection in Smart Grids
Ahmad Mohammad Saber, Saeed Jafari, Marthe Kassouf, Deepa Kundur |
IEEE Trans. Ind. Informatics | 3 |
| 2025 | Quantum Computing Threats to Management and Operational Safeguards of IEC 62351abstractAs quantum computing technology continues to advance towards a cryptographically relevant scale, cybersecurity for critical infrastructure such as electrical power systems must prepare for an existential threat. A crucial step to mitigating the potential damage a quantum computer-aided attack may cause is identifying quantum-vulnerable algorithms that are currently used in the standards for the security of power system control centres and communication networks. The IEC 62351 is a series of standards for protecting data in power automation systems and includes several quantum-vulnerable cryptographic primitives. Parts 7, 8, and 9 of the IEC 62351 are dedicated to network and system management, role-based access control, and key management. In this work, we conduct a comprehensive vulnerability assessment of the cryptographic algorithms selected in these parts of IEC 62351. Brian Goncalves, Arash Mahari, Atefeh Mashatan, Reza Arani, Marthe Kassouf |
PST | 5 |
| 2025 | Measuring the Security Posture of IEC 61850 Smart Grid Substations Against Supply Chain AttacksabstractRecently, there has been a surge of interest in analyzing and modeling emerging cyberattacks resulting from supply chain vulnerabilities in smart grids. These vulnerabilities are deliberately injected into devices before shipment by a malicious or trustworthy but compromised vendor during supply chain attacks. As a result, those vulnerabilities possess unique characteristics, such as stealthiness. Such characteristics, together with the limited number of vendors, demand new techniques for measuring the security posture of smart grids in the presence of those vulnerabilities. On this basis, this article first defines a supply chain risk metric to measure the risks of different devices containing those vulnerabilities based on several risk factors. Afterward, we enhance the previously defined$kSupply$metric and propose a new metric, namely$kSupplier$to include vendors in the risk assessment. Finally, we evaluate the proposed metrics and models through simulations conducted on IEEE 14 and 39-bus systems. Onur Duman, Mohsen Ghafouri, Lingyu Wang 0001, Marthe Kassouf, Ribal Atallah, Mourad Debbabi |
IEEE Trans. Ind. Informatics | 4 |
| 2024 | A Real-time Monitoring Architecture for Enhanced Cybersecurity in the EV EcosystemabstractElectric Vehicles (EV) have experienced a tremendous rise in popularity as they offer a sustainable alternative to conventional vehicles. However, the EV ecosystem is a complex system consisting of many interconnected components such as the EV Charging Station (CS) and the EV Charging Station Management System (CSMS). Given its connection to the smart grid and its direct impact on the transportation sector, securing the EV ecosystem is essential and requires the design of novel monitoring solutions. Previous studies proposed single-component detection mechanisms that cannot detect all potential anomalies across the system. Our work addresses this issue through the combination and correlation of monitoring data collected from the different EV ecosystem components. Our objective is to develop a real-time monitoring platform for attack detection in the public EV charging ecosystem that is based on the extension of the IEC 62351-7:2017 Network and System Management (NSM) standard. By adopting an international security standard, we ensure the monitoring platform is compatible with international power systems. To validate the utility of the approach, we integrate the monitoring framework with a real-time EV charging cosimulation testbed and discuss how it can be used to detect EV-based cyberattacks. Rinith Reghunath, M. A. Sayed, Khaled Sarieddine, Ribal Atallah, Danial Jafarigiv, Marthe Kassouf, Chadi Assi, Mohsen Ghafouri |
IECON | 6 |
| 2024 | Spatial-Temporal Data-Driven Model for Load Altering Attack Detection in Smart Power Distribution NetworksabstractThe widespread deployment of information and communication technologies in smart power distribution networks (SPDNs) exposes them to cyber threats. Among different types of cyber-attacks in such ICT-based SPDNs, load-altering attacks (LAAs) against high-wattage devices have received significant attention in recent years. In this context, this article proposes a data-driven detection model tailored for identifying and localizing LAAs in SPDNs. In this pursuit, first, the graph structure of an SPDN, which is obtained from the grid topology, and node features, i.e., measurements of the load's power, are fed to a graph attention network (GAT), and the spatial correlations among the nodes are captured. Alongside, the temporal correlations are captured using a long short-term memory model trained based on the graph representation obtained from the GAT. These spatial and temporal correlations are used by prediction and reconstruction models, i.e., a fully connected neural network and an auto-encoder. Finally, based on the error of the prediction and reconstruction blocks, an attack score for each load is calculated, and the compromised loads are detected and localized. To evaluate the performance of the proposed model, a co-simulation framework, which simulates the power system and emulates the communication network using real industrial protocols, i.e., IEC 60870-5-104, has been developed. The robustness of the model's performance against noisy data and non-attack outliers is confirmed with respect to different noise levels and data outliers. Also, the developed model's superior performance over existing models is demonstrated through various LAA scenarios applied to the IEEE 33- and the 123-Bus benchmarks. Afshin Ebtia, Dhiaa Elhak Rebbah, Mourad Debbabi, Marthe Kassouf, Mohsen Ghafouri, Arash Mohammadi 0001, Andrei Soeanu |
IEEE Trans. Ind. Informatics | 4 |
| 2023 | Binary Function Clone Search in the Presence of Code Obfuscation and Optimization over Multi-CPU ArchitecturesabstractBinary function clone search is an essential capability that enables multiple applications and use cases, including reverse engineering, patch security inspection, threat analysis, vulnerable function detection, etc. As such, a surge of interest has been expressed in designing and implementing techniques to address function similarity on binary executables and firmware images. Although existing approaches have merit in fingerprinting function clones, they present limitations when the target binary code has been subjected to significant code transformation resulting from obfuscation, compiler optimization, and/or cross-compilation to multiple-CPU architectures. In this regard, we design and implement a system named BinFinder, which employs a neural network to learn binary function embeddings based on a set of extracted features that are resilient to both code obfuscation and compiler optimization techniques. Our experimental evaluation indicates that BinFinder outperforms state-of-the-art approaches for multi-CPU architectures by a large margin, with 46% higher Recall against Gemini, 55% higher Recall against SAFE, and 28% higher Recall against GMN. With respect to obfuscation and compiler optimization clone search approaches, BinFinder outperforms the asm2vec (single CPU architecture approach) with higher Recall and BinMatch (multi-CPU architecture approach) with higher Recall. Finally, our work is the first to provide noteworthy results with respect to binary clone search over the tigress obfuscator, which is a well-established open-source obfuscator. Abdullah Qasem, Mourad Debbabi, Bernard Lebel, Marthe Kassouf |
AsiaCCS | 4 |
| 2022 | Security Monitoring of IEC 61850 Substations Using IEC 62351-7 Network and System ManagementabstractAccording to the IEC 62351-7 standard, data collection using network and system management (NSM) can be used to support the security monitoring of the smart grid. In this article, an NSM security monitoring platform for a realistic IEC 61850 substation model is developed using the specifications provided in IEC 62351-7. In the developed model, grid measurements are ready to take operative decisions, whereas collected NSM data are leveraged to detect cyberattacks and/or identify anomalies. The model includes power components (e.g., transformers, lines, and generators), controllers (e.g., voltage control), protection devices (e.g., overcurrent, distance, differential, and under/overvoltage), communication protocols (e.g., sampled value and generic object-oriented substation event), and NSM (e.g., agents and managers) applications. Moreover, a two-step deep learning framework is proposed for anomaly detection and cyberattack identification with enhanced accuracy. The first step can apply long short-term memory, recurrent neural network, and gated recurrent units, each in combination with an autoencoder. Then, the ensemble learning technique is used in the second step to augment the outputs of these deep learning models. To evaluate the effectiveness of the proposed cyberattack and anomaly detection framework, we detail and simulate potential cyberattacks targeting the performance of the IEEE 9-bus system. The proposed anomaly detection scheme can identify these threats using NSM data in a hardware-in-the-loop testbed. Finally, based on our assessment results, recommendations are provided for cybersecurity guidelines concerning IEC 62351-7. Abdullah Albarakati, Chantale Robillard, Mark Karanfil, Marthe Kassouf, Mourad Debbabi, Amr M. Youssef, Mohsen Ghafouri, Rachid Hadjidj |
IEEE Trans. Ind. Informatics | 4 |
| 2021 | Threat Intelligence Generation Using Network Telescope Data for Industrial Control SystemsabstractIndustrial Control Systems (ICSs) are cyber-physical systems that offer attractive targets to threat actors due to the scale of damages, both physical and cyber, that successful exploitation can cause. As such, ICSs often find themselves victims to reconnaissance campaigns - coordinated scanning activity that targets a wide subset of the Internet - that aim to discover vulnerable systems. As these campaigns likely scan broad netblocks of the Internet, some traffic is directed to network telescopes, which are routable, allocated, and unused IP space. In this paper, we explore the threat landscape of ICS devices by analyzing and investigating network telescope traffic. Our network traffic analysis tool takes darknet traffic and generates threat intelligence on scanning campaigns targeting ICSs in the form of campaign fragments, which we leverage in new ways to get more in-depth knowledge of the cybersecurity threats. We investigate the payloads of the identified campaigns using a custom Deep Packet Inspection (DPI) technique to dissect and analyze the packets. We found 13 distinct payload templates and deduced their purpose, and by extension the campaign goals. We use machine learning to classify the sources behind the campaigns and identify threat actors such as botnets, malicious attackers, or researchers, and establish a methodology to rank our campaigns to prioritize our analysis. To conduct our analysis of the threats targeting ICSs, we have leveraged 12.85 TB (330 days) of network traffic received by our observed darknet IP space. Combining these investigative threads, we provide a thorough overview of the threat landscape targeting ICS systems. Olivier Cabana, Amr M. Youssef, Mourad Debbabi, Bernard Lebel, Marthe Kassouf, Ribal Atallah, Basile L. Agba |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | An Extension to the Precision Time Protocol (PTP) to Enable the Detection of Cyber AttacksabstractThe precision time protocol (PTP) is considered as one of the most favorable mechanisms for providing unified and precise time at the substation level in the smart grid. Nevertheless, PTP was shown to be vulnerable to cyber-attacks targeting its components and synchronization services. In this article, we capitalize on the theory and outcome of our previous work to contribute a more complete solution that addresses PTP cyber security. We propose to close the PTP loop through an extension that introduces new functionality and messages. This extension covers the PTP attack surface and enables the detection of attacks on PTP time synchronization. We formally model and verify the proposed extension using UPPAAL model checker. In addition, we validate the proposed extension using Omnet++ simulation. The evaluation demonstrates that our approach preserves PTP functionality, while successfully detecting cyber attacks against PTP components in a timely manner. Bassam Moussa, Marthe Kassouf, Rachid Hadjidj, Mourad Debbabi, Chadi Assi |
IEEE Trans. Ind. Informatics | 2 |
| 2019 | Detecting, Fingerprinting and Tracking Reconnaissance Campaigns Targeting Industrial Control Systems
Olivier Cabana, Amr M. Youssef, Mourad Debbabi, Bernard Lebel, Marthe Kassouf, Basile L. Agba |
DIMVA | 5 |
| 2011 | DPC Rates and Multiplexing Gains for MIMO Broadcast Systems with Multi-Dimensional Space-Time ModulationabstractThis paper considers multiple-antenna broadcast channels (BCs) with multi-dimensional space-time modulation schemes, created by various allocations of signal dimensions to transmit antennas. The signal dimensions are divided into disjoint subsets, where one is shared between all users, and each of the others are assigned to different users. This model encompasses several practical single point to multi-point wireless communication systems employing multiple antennas. Assuming space and time dispersive channels, we consider the transmission rates that are achieved by applying dirty paper coding (DPC) at the transmitter, present inner and outer bounds for the DPC rate region, and study the effects of space-time modulation formats. At high SNR, we consider the limit form of these bounds, derive an achievable multiplexing gain region, and study the effects of sharing signal dimensions between users. Marthe Kassouf, Harry Leib |
IEEE Trans. Commun. | 1 |
| 2004 | Shannon capacity regions for orthogonally multiplexed MIMO broadcast channels with informed transmittersabstractThis paper considers the Shannon capacity region of a space and time dispersive multiple-input multiple-output (MIMO) broadcast channel with multi-dimensional space-time modulation. We assume no inter-user cooperation and consider a non-fading environment with orthogonally multiplexed users. With the single user capacity being achieved by water-filling power allocation and eigen-beamforming transmission, we investigate the capacity region when each user channel is known at both the transmitter and receiver. Furthermore, the high and low SNR asymptotic behaviour of the capacity region is studied along with the transmit power allocation that maximizes the sum capacity. Numerical results show that the capacity region expands with the number of signal propagation paths, and also with the number of antennas. The effect of space-time modulation is also pointed out. Marthe Kassouf, Harry Leib |
WCNC | 1 |
| 2003 | Shannon capacity and eigen-beamforming for space dispersive multipath MIMO channelsabstractThis paper considers the information transfer capacity of a space dispersive multipath channel with multiple antenna at the transmitter and receiver. The Shannon capacity is evaluated for such multiple-input multiple-output (MIMO) channels with multi-dimensional space-time modulation. Assuming a non-fading environment and a known channel at the transmitter and receiver, we derive the Shannon capacity under a transmit average power constraint. It is shown that the signal structure achieving capacity corresponds to eigen-beamforming. Capacity is shown to increase with the number of signal propagation paths. The effect of the space-time modulation format on the information-theoretic capacity is also pointed out. Marthe Kassouf, Harry Leib |
WCNC | 1 |